Software
 

All current and historical changelogs

Release candidate release tree

  • Release 6.40rc41 2017-07-17

    What's new in 6.40rc41 (2017-Jul-17 09:03):

    !) bridge hw-offload implementation reverted back to pre-6.40rc36 state (testing will continue in v6.41rc);
    !) wireless - added Nv2 AP synchronization feature "nv2-modes" and "nv2-sync-secret" option;
    *) bonding - fixed 802.3ad mode on RB1100AHx4;
    *) export - fixed export to a file (introduced in v6.40rc39);
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - fixed firewall accept rules created by "/ip hotspot walled garden ip" (introduced in v6.40rc18);
    *) ike1 - create tunnel policy when no split net provided;
    *) ike1 - wait for cfg set reply before ph2 creation with xAuth;
    *) ipsec - allow to specify chain in "firewall" peer option;
    *) ppp - fixed non-standard PAP or CHAP packet handling;
    *) pppoe-server - fixed situation when some of 100+ pppoe-servers can become invalid on reboot;
    *) routerboard - added "caps-mode" option for "reset-configuration";
    *) sfp - fixed invalid temperature reporting when ambient temperature is less than 0;
    *) winbox - make IPSec policies table an order list;
    *) winbox - show "/interface wireless cap print" warnings;

    Other changes since 6.39.2:

    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) certificate - update and reload old certificate with new one if SKID matches;
    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) console - fixed different command auto complete on ;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-client - added "gateway-address" script parameter;
    *) dhcpv4-server - fixed lease renew for DHCP clients that sends renewal with "ciaddr = 0.0.0.0";
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) email - added support for multiple attachments;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed occasional broken interface order after reset/first boot;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) export - added router model and serial number to configuration export;
    *) export - fixed "/interface list" verbose export;
    *) export - fixed "/ipv6 route" compact export;
    *) export - fixed MPLS "dynamic-label-range" export;
    *) export - fixed SNMP "src-address" for compact export;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fastpath - improved removing process of dynamic interface;
    *) fasttrack - fixed fasttrack over interfaces with dynamic MAC address;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) filesystem - improved error correcting process on tilera and RB1100Dx4 storage;
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter;
    *) firewall - fixed bridge "action=log" rules;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - fixed crash on fasttrack dummy rule manual change attempt;
    *) firewall - removed unique address list name limit;
    *) hAP ac lite - removed nonexistent "wlan-led";
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added log error message if netmask was not provided by "mode-config" server;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - fixed duplicate policy checking with "0.0.0.0/0" policies;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - added support for "key-id" peer identification type;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added info command support for the Jaton LTE modem;
    *) lte - added initial fastpath support (except SXT LTE and Sierra modems);
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - added support for Huawei E3531-6;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) mmips - added support for NVME disks;
    *) modem - added support for ZTE TE W120;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - added initial support for ZTE K4203-Z;
    *) ppp - added initial support for ZTE ME3630-E;
    *) ppp - added output values for "info" command for finding the GSM base station's location ("LAC" and "IMSI");
    *) ppp - fixed "user-command" output;
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - simplified LTE status monitoring;
    *) quickset - use active user name and permissions when applying changes;
    *) rb1100ahx4 - fixed startup problems (requires additional reboot after upgrade);
    *) rb3011 - fixed packet passthrough on switch2 while booting;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
    *) sms - decode reports in readable format;
    *) sniffer - do not skip L2 packets when "all" interface mode was used;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed "/system resource cpu print oid" menu;
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) ssl - added Wildcard support for "left-most" DNS label (will allow to use signed Wildcard certificate on VPN servers);
    *) supout - fixed IPv6 firewall section;
    *) switch - fixed "loop-protect" on CRS SFP/SFP+ ports;
    *) tile - fixed copying large amount of text over serial console;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) trafficgen - added "lost-ratio" to statistics;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - added "/tool user-manager user clear-profiles" command;
    *) userman - do not send disconnect request for user when "simultaneous session limit reached";
    *) userman - lookup language files also in "/flash" directory;
    *) vlan - do not delete existing VLAN interface on "failure: already have such vlan";
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - do not autoscale graphs outside known maximums;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - hide LCD menu on CRS112-8G-4S;
    *) winbox - moved LTE info fields to status tab;
    *) winbox - show "/system health" only on boards that have health monitoring;
    *) winbox - show "D" flag under "/interface mesh port" menu;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc38 2017-07-12

    What's new in 6.40rc38 (2017-Jul-11 12:28):

    Important note!!! Backup before upgrade!
    RouterOS v6.40rc36 contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) certificate - update and reload old certificate with new one if SKID matches;
    *) email - added support for multiple attachments;
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter;
    *) firewall - fixed crash on fasttrack dummy rule manual change attempt;
    *) ikev2 - fixed duplicate policy checking with "0.0.0.0/0" policies;
    *) lte - added initial fastpath support (except SXT LTE and Sierra modems);
    *) mmips - added support for NVME disks;
    *) ppp - added output values for "info" command for finding the GSM base station's location ("LAC" and "IMSI");
    *) ppp - fixed "user-command" output;
    *) quickset - simplified LTE status monitoring;
    *) rb1100ahx4 - fixed startup problems (requires additional reboot after upgrade);
    *) ssl - added Wildcard support for "left-most" DNS label (will allow to use signed Wildcard certificate on VPN servers);
    *) userman - do not send disconnect request for user when "simultaneous session limit reached";
    *) userman - added "/tool user-manager user clear-profiles" command;

    Other changes since 6.39.2:

    !) bridge - implemented software based "igmp-snooping" (untested, undocumented, CLI only);
    !) bridge - implemented software based MSTP (untested, undocumented, CLI only);
    !) bridge - implemented software based vlan-aware bridges;
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (undocumented, CLI only);
    !) switch - CRS3xx switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) console - fixed different command auto complete on ;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-client - added "gateway-address" script parameter;
    *) dhcpv4-server - fixed lease renew for DHCP clients that sends renewal with "ciaddr = 0.0.0.0";
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed occasional broken interface order after reset/first boot;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) export - added router model and serial number to configuration export;
    *) export - fixed "/interface list" verbose export;
    *) export - fixed "/ipv6 route" compact export;
    *) export - fixed MPLS "dynamic-label-range" export;
    *) export - fixed SNMP "src-address" for compact export;
    *) fastpath - fixed router rebooting itself (introduced in 6.40rc24);
    *) fastpath - improved performance when packets for slowpath are received;
    *) fastpath - improved removing process of dynamic interface;
    *) fasttrack - fixed fasttrack over interfaces with dynamic MAC address;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) filesystem - improved error correcting process on tilera and RB1100Dx4 storage;
    *) firewall - fixed bridge "action=log" rules;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - removed unique address list name limit;
    *) hAP ac lite - removed nonexistent "wlan-led";
    *) health - fixed memory leak on devices that have "/system health" menu (introduced in 6.40rc30);
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ikev1 - added log error message if netmask was not provided by "mode-config" server;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - added support for "key-id" peer identification type;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added info command support for the Jaton LTE modem;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - added support for Huawei E3531-6;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - added initial support for ZTE K4203-Z;
    *) ppp - added initial support for ZTE ME3630-E;
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - use active user name and permissions when applying changes;
    *) rb3011 - fixed packet passthrough on switch2 while booting;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
    *) sms - decode reports in readable format;
    *) sniffer - do not skip L2 packets when "all" interface mode was used;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed "/system resource cpu print oid" menu;
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) supout - fixed IPv6 firewall section;
    *) switch - fixed "loop-protect" on CRS SFP/SFP+ ports;
    *) tile - fixed copying large amount of text over serial console;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) trafficgen - added "lost-ratio" to statistics;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) vlan - do not delete existing VLAN interface on "failure: already have such vlan";
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - do not autoscale graphs outside known maximums;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - hide LCD menu on CRS112-8G-4S;
    *) winbox - moved LTE info fields to status tab;
    *) winbox - show "/system health" only on boards that have health monitoring;
    *) winbox - show "D" flag under "/interface mesh port" menu;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc36 2017-07-07

    What's new in 6.40rc36 (2017-Jul-07 10:44):

    Important note!!! Backup before upgrade!
    RouterOS v6.40rc36 contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - implemented software based "igmp-snooping" (untested, undocumented, CLI only);
    !) bridge - implemented software based MSTP (untested, undocumented, CLI only);
    !) bridge - implemented software based vlan-aware bridges;
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (undocumented, CLI only);
    !) switch - CRS3xx switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) filesystem - improved error correcting process on tilera and RB1100Dx4 storage;
    *) firewall - fixed bridge "action=log" rules;
    *) health - fixed memory leak on devices that have "/system health" menu (introduced in 6.40rc30);
    *) ikev1 - added log error message if netmask was not provided by "mode-config" server;
    *) ipsec - added support for "key-id" peer identification type;
    *) rb3011 - fixed packet passthrough on switch2 while booting;
    *) sniffer - do not skip L2 packets when "all" interface mode was used;
    *) snmp - fixed "/system resource cpu print oid" menu;
    *) switch - fixed "loop-protect" on CRS SFP/SFP+ ports;
    *) trafficgen - added "lost-ratio" to statistics;
    *) vlan - do not delete existing VLAN interface on "failure: already have such vlan";
    *) winbox - do not autoscale graphs outside known maximums;
    *) winbox - hide LCD menu on CRS112-8G-4S;
    *) winbox - show "/system health" only on boards that have health monitoring;
    *) winbox - show "D" flag under "/interface mesh port" menu;

    Other changes since 6.39.2:

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) console - fixed different command auto complete on ;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-client - added "gateway-address" script parameter;
    *) dhcpv4-server - fixed lease renew for DHCP clients that sends renewal with "ciaddr = 0.0.0.0";
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed occasional broken interface order after reset/first boot;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) export - added router model and serial number to configuration export;
    *) export - fixed "/interface list" verbose export;
    *) export - fixed "/ipv6 route" compact export;
    *) export - fixed MPLS "dynamic-label-range" export;
    *) export - fixed SNMP "src-address" for compact export;
    *) fastpath - fixed router rebooting itself (introduced in 6.40rc24);
    *) fastpath - improved performance when packets for slowpath are received;
    *) fastpath - improved removing process of dynamic interface;
    *) fasttrack - fixed fasttrack over interfaces with dynamic MAC address;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter (CLI only);
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - removed unique address list name limit;
    *) hAP ac lite - removed nonexistent "wlan-led";
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added info command support for the Jaton LTE modem;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - added support for Huawei E3531-6;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - added initial support for ZTE K4203-Z;
    *) ppp - added initial support for ZTE ME3630-E;
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - use active user name and permissions when applying changes;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
    *) sms - decode reports in readable format;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) supout - fixed IPv6 firewall section;
    *) tile - fixed copying large amount of text over serial console;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - moved LTE info fields to status tab;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc32 2017-07-04

    What's new in 6.40rc32 (2017-Jul-04 07:38):

    *) dhcpv4-client - added "gateway-address" script parameter;
    *) dhcpv4-server - fixed lease renew for DHCP clients that sends renewal with "ciaddr = 0.0.0.0";
    *) fasttrack - fixed fasttrack over interfaces with dynamic MAC address;

    Other changes since 6.39.2:

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) console - fixed different command auto complete on ;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed occasional broken interface order after reset/first boot;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) export - added router model and serial number to configuration export;
    *) export - fixed "/interface list" verbose export;
    *) export - fixed "/ipv6 route" compact export;
    *) export - fixed MPLS "dynamic-label-range" export;
    *) export - fixed SNMP "src-address" for compact export;
    *) fastpath - fixed router rebooting itself (introduced in 6.40rc24);
    *) fastpath - improved performance when packets for slowpath are received;
    *) fastpath - improved removing process of dynamic interface;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter (CLI only);
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - removed unique address list name limit;
    *) hAP ac lite - removed nonexistent "wlan-led";
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added info command support for the Jaton LTE modem;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - added support for Huawei E3531-6;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - added initial support for ZTE K4203-Z;
    *) ppp - added initial support for ZTE ME3630-E;
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - use active user name and permissions when applying changes;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
    *) sms - decode reports in readable format;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) supout - fixed IPv6 firewall section;
    *) tile - fixed copying large amount of text over serial console;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) trafficgen - added "lost-ratio" to statistics;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - moved LTE info fields to status tab;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc28 2017-06-30

    What's new in 6.40rc28 (2017-Jun-30 12:08:26):

    *) console - fixed different command auto complete on ;
    *) ethernet - fixed occasional broken interface order after reset/first boot;
    *) export - added router model and serial number to configuration export;
    *) export - fixed "/interface list" verbose export;
    *) export - fixed "/ipv6 route" compact export;
    *) export - fixed MPLS "dynamic-label-range" export;
    *) export - fixed SNMP "src-address" for compact export;
    *) fastpath - improved removing process of dynamic interface;
    *) hAP ac lite - removed nonexistent "wlan-led";
    *) lte - added info command support for the Jaton LTE modem;
    *) ppp - added initial support for ZTE K4203-Z;
    *) ppp - added initial support for ZTE ME3630-E;
    *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
    *) supout - fixed IPv6 firewall section;

    Other changes since 6.39.2:

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces (CLI only);
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) fastpath - fixed router rebooting itself (introduced in 6.40rc24);
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter (CLI only);
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - removed unique address list name limit;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - added support for Huawei E3531-6;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - use active user name and permissions when applying changes;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sms - decode reports in readable format;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tile - fixed copying large amount of text over serial console;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) trafficgen - added "lost-ratio" to statistics;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - moved LTE info fields to status tab;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc25 2017-06-27

    What's new in 6.40rc25 (2017-Jun-27 06:26):

    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) fastpath - fixed router rebooting itself (introduced in 6.40rc24);
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter (CLI only);
    *) firewall - removed unique address list name limit;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) lte - added support for Huawei E3531-6;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) tile - fixed copying large amount of text over serial console;
    *) trafficgen - added "lost-ratio" to statistics;
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;

    Other changes since 6.39.2:

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces (CLI only);
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - use active user name and permissions when applying changes;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sms - decode reports in readable format;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - moved LTE info fields to status tab;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc24 2017-06-20

    What's new in 6.40rc24 (2017-Jun-20 09:38):

    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - added support for "push-continuation";
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) sms - decode reports in readable format;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - fixed wireless interface walk table id ordering;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - moved LTE info fields to status tab;

    Other changes since 6.39.2:

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces (CLI only);
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) ovpn - improved performance when receiving too many options;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - improved MLPPP packet forwarding performance;
    *) proxy - fixed potential crash;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - use active user name and permissions when applying changes;
    *) rb750gr3 - fixed USB power;
    *) routing - allow to disable "all" interface entry in BFD;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed crash on interface table get;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added TR069 support;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc21 2017-06-14

    What's new in 6.40rc21 (2017-Jun-14 09:05):

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces (CLI only);
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) dude - fixed server crash;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) rb750gr3 - fixed USB power;
    *) userman - lookup language files also in "/flash" directory;

    Other changes since 6.39.2:

    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) ovpn - improved performance when receiving too many options;
    *) ppp - improved MLPPP packet forwarding performance;
    *) proxy - fixed potential crash;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - use active user name and permissions when applying changes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) snmp - fixed crash on interface table get;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added TR069 support;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc20 2017-06-13

    What's new in 6.40rc20 (2017-Jun-12 12:08):

    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - improved reliability on SXT LTE;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

    Other changes since 6.39.2:

    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved SMS delivery report;
    *) ovpn - improved performance when receiving too many options;
    *) ppp - improved MLPPP packet forwarding performance;
    *) proxy - fixed potential crash;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - use active user name and permissions when applying changes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) snmp - fixed crash on interface table get;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added TR069 support;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;

  • Release 6.40rc19 2017-06-08

    What's new in 6.40rc19 (2017-Jun-07 13:30):

    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) l2tp-server - added "one-session-per-host" option;
    *) ovpn - improved performance when receiving too many options;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

    Other changes since 6.39.2:

    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved SMS delivery report;
    *) ppp - improved MLPPP packet forwarding performance;
    *) proxy - fixed potential crash;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - use active user name and permissions when applying changes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) snmp - fixed crash on interface table get;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added TR069 support;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;

  • Release 6.40rc18 2017-06-06

    What's new in 6.40rc18 (2017-Jun-06 10:04):

    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) fastpath - improved performance when packets for slowpath are received;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) lte - improved SMS delivery report;
    *) ppp - improved MLPPP packet forwarding performance;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;

  • Release 6.40rc15 2017-05-31

    What's new in 6.40rc15 (2017-May-30 08:52):

    !) ipsec - added support for dynamic "action=notrack" RAW rules for policies;
    *) defconf - added accept ICMPv6 in forward and DHCP discover in RAW prerouting;
    *) ike2 - added pfkey kernel return checks;
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - removed policy priority;
    *) ppp - fixed MLPPP over multiple channels/interfaces (introduced in v6.39);

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) bonding - do not add bonding interface if "could not set MTU" error is received;
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) defconf - added IPv6 firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) defconf - replaced IPv4 firewall configuration with improved one;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) export - removed spare "caller-id-type" value from compact export;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) firewall - do not allow to set "rate" value to 0 for "limit" parameter;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) gps - removed duplicate logs;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - removed xauth login length limitation;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - fixed rare kernel failure on address acquire;
    *) ike2 - fixed situation when traffic selector prefix was parsed incorrectly;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed generated policy priority;
    *) ipsec - fixed peer "my-id" address reset;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - renamed "remote-dynamic-address" to "dynamic-address";
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) led - fixed ethernet LEDs on CCR1009 and RB1100AHx2 (introduced in v6.40rc1);
    *) led - fixed turning off LED when interface is lost;
    *) log - added "poe-out" topic;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - fixed configless modem running state (introduced in 6.40rc);
    *) lte - improved info channel background polling;
    *) lte - replaced "user-command" with "at-chat" command;
    *) ppp - fixed "change-mss" functionality (introduced in 6.39);
    *) ppp - send correct IP address in RADIUS "accounting-stop" messages (introduced in 6.39);
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) pppoe-client - removed false warning from client interface if it starts running on non-slave interface;
    *) pppoe-server - fixed "one-session-per-host" issue where 2 simultaneous sessions were possible from the same host;
    *) proxy - fixed potential crash;
    *) queue - fixed queuing when at least one child queue has "default-small" and other/s is/are different (introduced in 6.35);
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - fixed LTE "signal-strength" graphs;
    *) quickset - use active user name and permissions when applying changes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - fixed crash on interface table get;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) tile - fixed rare encryption kernel failure when small packets are processed;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) winbox - fixed LTE info button;
    *) winbox - fixed firewall port selection with Winbox v2;
    *) winbox - removed spare values from "loop-protect" setting for EoIPv6 tunnels;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - reduced load on CPU for high speed wireless links;

  • Release 6.40rc14 2017-05-30

    What's new in 6.40rc14 (2017-May-29 11:16):

    *) chr - maximal system disk size now limited to 16GB;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) pppoe-server - fixed "one-session-per-host" issue where 2 simultaneous sessions were possible from the same host;
    *) snmp - fixed crash on interface table get;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - fixed firewall port selection with Winbox v2;

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) bonding - do not add bonding interface if "could not set MTU" error is received;
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) defconf - added IPv6 firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) defconf - replaced IPv4 firewall configuration with improved one;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) export - removed spare "caller-id-type" value from compact export;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) firewall - do not allow to set "rate" value to 0 for "limit" parameter;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) gps - removed duplicate logs;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - removed xauth login length limitation;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - fixed rare kernel failure on address acquire;
    *) ike2 - fixed situation when traffic selector prefix was parsed incorrectly;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed generated policy priority;
    *) ipsec - fixed peer "my-id" address reset;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - renamed "remote-dynamic-address" to "dynamic-address";
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) led - fixed ethernet LEDs on CCR1009 and RB1100AHx2 (introduced in v6.40rc1);
    *) led - fixed turning off LED when interface is lost;
    *) log - added "poe-out" topic;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - fixed configless modem running state (introduced in 6.40rc);
    *) lte - improved info channel background polling;
    *) lte - replaced "user-command" with "at-chat" command;
    *) ppp - fixed "change-mss" functionality (introduced in 6.39);
    *) ppp - send correct IP address in RADIUS "accounting-stop" messages (introduced in 6.39);
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) pppoe-client - removed false warning from client interface if it starts running on non-slave interface;
    *) proxy - fixed potential crash;
    *) queue - fixed queuing when at least one child queue has "default-small" and other/s is/are different (introduced in 6.35);
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - fixed LTE "signal-strength" graphs;
    *) quickset - use active user name and permissions when applying changes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) tile - fixed rare encryption kernel failure when small packets are processed;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) winbox - fixed LTE info button;
    *) winbox - removed spare values from "loop-protect" setting for EoIPv6 tunnels;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - reduced load on CPU for high speed wireless links;

  • Release 6.40rc13 2017-05-26

    What's new in 6.40rc13 (2017-May-25 12:53):

    *) bonding - do not add bonding interface if "could not set MTU" error is received;
    *) defconf - added IPv6 firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) export - removed spare "caller-id-type" value from compact export;
    *) firewall - do not allow to set "rate" value to 0 for "limit" parameter;
    *) gps - removed duplicate logs;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - removed xauth login length limitation;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - fixed situation when traffic selector prefix was parsed incorrectly;
    *) ipsec - fixed generated policy priority;
    *) ipsec - fixed peer "my-id" address reset;
    *) ipsec - renamed "remote-dynamic-address" to "dynamic-address";
    *) lte - fixed configless modem running state (introduced in 6.40rc);
    *) ppp - fixed "change-mss" functionality (introduced in 6.39);
    *) ppp - send correct IP address in RADIUS "accounting-stop" messages (introduced in 6.39);
    *) pppoe-client - removed false warning from client interface if it starts running on non-slave interface;
    *) proxy - fixed potential crash;
    *) queue - fixed queuing when at least one child queue has "default-small" and other/s is/are different (introduced in 6.35);
    *) quickset - fixed LTE "signal-strength" graphs;
    *) quickset - use active user name and permissions when applying changes;
    *) snmp - added ability to set "src-address";
    *) tile - fixed rare encryption kernel failure when small packets are processed;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - fixed LTE info button;
    *) winbox - removed spare values from "loop-protect" setting for EoIPv6 tunnels;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - reduced load on CPU for high speed wireless links;

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) defconf - replaced IPv4 firewall configuration with improved one;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike2 - fixed rare kernel failure on address acquire;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) led - fixed ethernet LEDs on CCR1009 and RB1100AHx2 (introduced in v6.40rc1);
    *) led - fixed turning off LED when interface is lost;
    *) log - added "poe-out" topic;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved info channel background polling;
    *) lte - replaced "user-command" with "at-chat" command;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;

  • Release 6.40rc8 2017-05-19

    What's new in 6.40rc8 (2017-May-19 07:00):

    *) btest - fixed crash when packet size has been changed during test;
    *) defconf - added IPv6 firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - replaced IPv4 firewall configuration with improved one;
    *) export - added "terse" option;
    *) firewall - do not allow to set "rate" value to 0 for "limit" parameter (CLI only);
    *) wireless - do not skip >2462 channels if interface is WDS slave;

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike2 - fixed rare kernel failure on address acquire;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) led - fixed ethernet LEDs on CCR1009 and RB1100AHx2 (introduced in v6.40rc1);
    *) led - fixed turning off LED when interface is lost;
    *) log - added "poe-out" topic;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved info channel background polling;
    *) lte - replaced "user-command" with "at-chat" command;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol (CLI only);
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol (CLI only);
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;

  • Release 6.40rc6 2017-05-16

    What's new in 6.40rc6 (2017-May-11 12:53):

    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) led - fixed ethernet LEDs on CCR1009 and RB1100AHx2 (introduced in v6.40rc1);
    *) led - fixed turning off LED when interface is lost;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - improved info channel background polling;
    *) lte - replaced "user-command" with "at-chat" command;
    *) snmp - added "ifindex" on interface traps;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol (CLI only);
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol (CLI only);

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike2 - fixed rare kernel failure on address acquire;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) log - added "poe-out" topic;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;

  • Release 6.40rc5 2017-05-09

    What's new in 6.40rc5 (2017-May-08 09:20):

    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) ike2 - fixed rare kernel failure on address acquire;
    *) log - added "poe-out" topic;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;

  • Release 6.40rc4 2017-05-03

    What's new in 6.40rc4 (2017-May-03 05:15):

    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) defconf - discard default configuration startup query with RouterOS upgrade;
    *) defconf - discard default configuration startup query with configuration change from Webfig;
    *) dns - made loading thousands of static entries faster;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) smb - fixed external drive folder sharing when "/flash" folder existed;
    *) smb - fixed invalid default share after reboot when "/flash" folder existed;
    *) upnp - fixed firewall nat rule update when external IP address changes;

    Other changes since 6.39:

    *) 6to4 - fixed wrong IPv6 “link-local” address generation;
    *) arp - fixed “make-static”;
    *) capsman - fixed EAP identity reporting in “registration-table”;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) firewall - fixed “address-list” entry changing from IP to DNS and vice versa;
    *) firewall - “address-list” entry “creation-time” adjusted to timezone;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;

  • Release 6.40rc2 2017-04-28

    What's new in 6.40rc2 (2017-Apr-28 05:24):

    *) 6to4 - fixed wrong IPv6 “link-local” address generation;
    *) arp - fixed “make-static”;
    *) capsman - fixed EAP identity reporting in “registration-table”;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) firewall - fixed “address-list” entry changing from IP to DNS and vice versa;
    *) firewall - “address-list” entry “creation-time” adjusted to timezone;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) log - work on false CPU/RAM overclocked alarms;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;

  • Release 6.39rc80 2017-04-25

    What's new in 6.39rc80 (2017-Apr-25 09:23):

    !) bridge - reverted bridge BPDU processing back to pre-v6.38 behaviour; (v6.40 will have another separate VLAN-aware bridge implementation);

    Other changes since 6.38.5:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) firewall - discontinued support for p2p matcher (old rules will become invalid);
    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) tile - fixed IPSec hardware acceleration out-of-order packet problem, significantly improved performance;
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) api - fixed double dynamic flags for "/ip firewall address-list print";
    *) capsman - added "extension-channel" XX and XXXX auto matching modes;
    *) capsman - added "keepalive-frames" setting;
    *) capsman - added "skip-dfs-channels" setting;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added DFS support;
    *) capsman - added EAP identity to registration table;
    *) capsman - added ability to specify multiple channels in frequency field;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for "background-scan" and channel "reselect-interval";
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - changed channel "width" name to "control-channel-width" and changed default values;
    *) capsman - improved CAP status querying;
    *) capsman - improved support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - SCEP client now supports FQDN URL and port;
    *) certificate - allow CRL address to be specified as DNS name;
    *) console - fixed "/ip neighbor discovery" export;
    *) console - fixed DHCP/PPP add-default-route distance minimal value to 1;
    *) console - fixed crash;
    *) console - fixed incorrect ":put [/lcd get enabled]" value;
    *) ddns - improved "dns-update" authentication validation;
    *) defconf - fixed Groove 52 ac band settings;
    *) defconf - fixed default configuration generation when wireless package is disabled;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4 - fixed string option parser;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - by default make server “authoritative”;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) discovery - fixed LLDP discovery, IPv6 address was not parsed correctly;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - added "voltage-too-low" status for single port power injector devices;
    *) ethernet - fixed "loop-protect" on "master-port";
    *) ethernet - fixed rare switch chip hang (could cause port flapping);
    *) ethernet - fixed unnecessary power cycle of powered device when changing any poe-out related setting on single port power injector devices;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) ethernet - reversed poe-priority on hEX PoE and OmniTIK 5 PoE to make "poe-priority" consistent to all other RouterOS priorities;
    *) fastpath - fixed rare crash on devices with dynamic interfaces;
    *) fetch - added "http-data" and "http-method" parameters to allow delete, get, post, put methods (content-type=application/x-www-form-urlencoded by default);
    *) fetch - fixed authentication failure;
    *) fetch - fixed download issue over HTTPS;
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike1 - fixed ph2 ID logging;
    *) ike2 - allow multiple child SA traffic selectors on re-key;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - check child state before allowing rekey;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed CTR mode;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed RSA authentication without EAP;
    *) ike2 - fixed ctr mode;
    *) ike2 - fixed disabled DPD;
    *) ike2 - fixed last EAP auth payload type;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed policy release during SA negotion;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - improved logging;
    *) ike2 - kill only child SAs which are not re-keyed by remote peer;
    *) ike2 - log RADIUS timeout message under error topic;
    *) ike2 - remove old SA after rekey;
    *) ike2 - send EAP identity as user-name RADIUS attribute;
    *) ike2 - update "calling_station_id" RADIUS attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added "last-seen" parameter to active connection list;
    *) ipsec - allow mixing aead algorithms in proposal;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - disallow AH+ESP combined policies ;
    *) ipsec - do not loose "use-ipsec=yes" parameter after downgrade;
    *) ipsec - enable aes-ni on i386 and x64 for cbc, ctr and gcm modes;
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - fixed SA authentication flag;
    *) ipsec - renamed "hw-authenc" flag to "hw-aead";
    *) ipsec - show hardware accelerated authenticated SAs;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) l2tp - added support for multiple L2TP tunnels (not to be confused with sessions) between same endpoints (required in some LNS configurations);
    *) l2tp - fixed hidden attribute decryption in forwarded CHAP responses for LNS;
    *) l2tp-server - added "caller-id-type" to forward calling station number to RADIUS on authentication;
    *) l2tp-server - added "use-ipsec=required" option;
    *) l2tp-server - fixed upgrade to keep "use-ipsec=yes" in L2TP server;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added "tr069" topic;
    *) log - added missing "license limit exceeded" log entry;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - do not show changes in packet if NAT has not been used;
    *) log - make SNMP logs more compact;
    *) lte - added "session-uptime" in info command;
    *) lte - added LTE signal level reading for Cinterion modems;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for DWR-910 modem;
    *) lte - added initial support for Quectel ec25;
    *) lte - added initialization for Cinterion;
    *) lte - added log entry for SMS delivery report;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) lte - reset interface stats on "link-down";
    *) netinstall - fixed typos;
    *) ntp - restart NTP client when it is stuck in error state;
    *) ppp - added "bridge-horizon" option under PPP/Profile;
    *) ppp - added option to specify "interface-list" in PPP/Profile;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp - fixed rare kernel failure when receiving IPv6 address on PPP interface;
    *) ppp - include rates, limits and address-lists parameters in RADIUS accounting requests;
    *) ppp-client - added support for Datacard 750UL, DWR-730 and K4607-Zr;
    *) pppoe - added warning on PPPoE client/server, if it is configured on slave interface;
    *) pppoe - added warning on PPPoE client/server, if it is configured on slave interface;
    *) pppoe - set default keepalive 10s for newly created PPPoE clients;
    *) quickset - added initial LTE AP mode support;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - added partitioning support;
    *) smb - fixed different memory leaks and crashes;
    *) smb - fixed share path on devices with "/flash" directory;
    *) smips - reduced RouterOS main package size;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - added fan-speed OIDs in "/system health print oid";
    *) snmp - added optical table;
    *) snmp - fixed rare crash;
    *) snmp - improved getall filter;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - increase “engineBoots” value on reboot;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tile - fixed IPSec crash (introduced in 6.39rc64);
    *) tile - optimized hardware encryption;
    *) tr069-client - added "Device.Hosts.Host.{i}." support;
    *) tr069-client - added "Device.WiFi.NeighboringWiFiDiagnostic." support;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added Upload RPC "2 Vendor Log File" support;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - added connection request authentication;
    *) tr069-client - added firewall NAT support using vendor Parameters;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added support for uploading/downloading factory script;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed "AddObjectResponse" “InstanceNumber” value;
    *) tr069-client - fixed "Device.ManagementServer." value update;
    *) tr069-client - fixed XML special character parsing;
    *) tr069-client - fixed crash on =acs-url change special case;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - fixed write for "Device.ManagementServer.URL";
    *) tr069-client - general improvements on reducing storage space;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - hide "Device.PPP.Interface.{i}.Password" value;
    *) tr069-client - improved LTE monitoring process;
    *) tr069-client - increased performance on GetParameterValues;
    *) tr069-client - made any Download RPC overwrite configuration except ".alter";
    *) tr069-client - make more Parameters deny active notifications;
    *) tr069-client - set CHR license ID as ".SerialNumber" value to avoid "no serial number" error in ACS;
    *) traceroute - small fix;
    *) tunnels - fixed reboot loop on configurations with IPIP and EoIP tunnels (introduced in 6.39rc68);
    *) usb - added support for more CP210X devices;
    *) userman - allow "name-for-user" to be empty and not unique;
    *) userman - automatically select all newly created users to generate vouchers;
    *) userman - fixed rare crash when User Manager requested file does not exist on router;
    *) userman - fixed rare web interface crash while using Users section;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - allow to change global variable contents;
    *) webfig - allow to enter frequency ranges in wireless scan list;
    *) webfig - allow to select "default-encryption" profile on PPP tunnels;
    *) webfig - correctly specify routing filter prefix;
    *) webfig - do not allow to reorder items if table is sorted by some column;
    *) webfig - fixed bridge property display;
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - fixed “last-link-up” & “last-link-down” time information;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) webfig - show all available options under “Advanced Mode” for wireless interfaces;
    *) webfig - show proper error messages for optional erroneous text fields;
    *) winbox - added "Flush" button under unicast-fdb menu;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added "k" and "M" unit support to PPP secret limit-bytes parameters;
    *) winbox - added "memory-scroll", "filter-cpu", "filter-ipv6-address", "filter-operation-between-entries" parameters;
    *) winbox - added "save-selected" setting under CAPsMAN channels;
    *) winbox - added "static-virtual" to wireless CAP;
    *) winbox - added GPS menu;
    *) winbox - added protected routerboard parameters under routerboard settings menu;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify "route-distance" in "dhcp-client" if "special-classless" mode is selected;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - allowed to specify static-dns as list;
    *) winbox - do not allow Packet Sniffer "memory-limit" and "file-limit" lower than 10KiB;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not show "dpd-max-failures" on IKEv2;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not start Traffic Generator automatically when opening "Quick Start";
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed "Montly" typo to "Monthly" in Graphing menu;
    *) winbox - fixed CAPsMAN channels frequency (allow to specify a list of them);
    *) winbox - fixed IPSec "mode-config" DNS settings;
    *) winbox - fixed issue when working IPSec policies were shown as invalid;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - fixed typo in BGP advertisements menu Aggragator->Aggregator;
    *) winbox - hide "wps-mode" & "security-profile" in wireless nv2 mode;
    *) winbox - hide health menu on RB450;
    *) winbox - improved "/tool torch";
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - properly show "dhcp-server" warnings;
    *) winbox - properly show IPSec "installed-sa" "enc-algorithm" when it is aes-gcm;
    *) winbox - properly show wireless registration table stat counters;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - removed unnecessary "/system health" menu on "hAP ac lite";
    *) winbox - set default "dhcp-client" "default-route-distance" value to 1;
    *) winbox - show "A" flag for IPSec policies;
    *) winbox - show "H" flag for IPSec installed SAs;
    *) winbox - show PoE-OUT current, voltage and power only on devices which can report these values;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - added PEAP authentication support for wireless station mode;
    *) wireless - apply broadcast bit to DHCP requests when using "station-pseudobridge" mode;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same "master-interface" is used;
    *) wireless - fixed RBSXT5HacD2nr2 small channel support;
    *) wireless - fixed crash while running "spectral-scan";
    *) wireless - fixed dynamic wireless interface removal from bridge ports when changing wireless mode;
    *) wireless - fixed false positive DFS radar detection caused by iPhone 6s devices;
    *) wireless - fixed issue when wireless interfaces might not show up in CAP mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare crash on nv2 configurations;
    *) wireless - fixed rare wireless ac interface lockup;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc79 2017-04-24

    What's new in 6.39rc79 (2017-Apr-24 08:42):

    *) fastpath - fixed traffic blocking when fasttrack-connection filter rule is enabled (introduced in 6.39rc62);
    *) fetch - fixed authentication failure;
    *) fetch - fixed download issue over HTTPS;
    *) lte - added initial support for DWR-910 modem;
    *) quickset - added initial LTE AP mode support;
    *) winbox - fixed typo in BGP advertisements menu Aggragator->Aggregator;
    *) winbox - removed unnecessary "/system health" menu on "hAP ac lite";

    Other changes since 6.38.5:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) bridge - fixed BPDU rx/tx when protocol-mode=none;
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) firewall - discontinued support for p2p matcher (old rules will become invalid);
    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) tile - fixed IPSec hardware acceleration out-of-order packet problem, significantly improved performance;
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) api - fixed double dynamic flags for "/ip firewall address-list print";
    *) capsman - added "extension-channel" XX and XXXX auto matching modes;
    *) capsman - added "keepalive-frames" setting;
    *) capsman - added "skip-dfs-channels" setting;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added DFS support;
    *) capsman - added EAP identity to registration table;
    *) capsman - added ability to specify multiple channels in frequency field;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for "background-scan" and channel "reselect-interval";
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - changed channel "width" name to "control-channel-width" and changed default values;
    *) capsman - improved CAP status querying;
    *) capsman - improved support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - SCEP client now supports FQDN URL and port;
    *) certificate - allow CRL address to be specified as DNS name;
    *) console - fixed "/ip neighbor discovery" export;
    *) console - fixed DHCP/PPP add-default-route distance minimal value to 1;
    *) console - fixed crash;
    *) console - fixed incorrect ":put [/lcd get enabled]" value;
    *) ddns - improved "dns-update" authentication validation;
    *) defconf - fixed Groove 52 ac band settings;
    *) defconf - fixed default configuration generation when wireless package is disabled;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4 - fixed string option parser;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - by default make server “authoritative”;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) discovery - fixed LLDP discovery, IPv6 address was not parsed correctly;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - added "voltage-too-low" status for single port power injector devices;
    *) ethernet - fixed "loop-protect" on "master-port";
    *) ethernet - fixed rare switch chip hang (could cause port flapping);
    *) ethernet - fixed unnecessary power cycle of powered device when changing any poe-out related setting on single port power injector devices;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) ethernet - reversed poe-priority on hEX PoE and OmniTIK 5 PoE to make "poe-priority" consistent to all other RouterOS priorities;
    *) fastpath - fixed rare crash on devices with dynamic interfaces;
    *) fetch - added "http-data" and "http-method" parameters to allow delete, get, post, put methods (content-type=application/x-www-form-urlencoded by default);
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike1 - fixed ph2 ID logging;
    *) ike2 - allow multiple child SA traffic selectors on re-key;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - check child state before allowing rekey;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed CTR mode;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed RSA authentication without EAP;
    *) ike2 - fixed ctr mode;
    *) ike2 - fixed disabled DPD;
    *) ike2 - fixed last EAP auth payload type;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed policy release during SA negotion;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - improved logging;
    *) ike2 - kill only child SAs which are not re-keyed by remote peer;
    *) ike2 - log RADIUS timeout message under error topic;
    *) ike2 - remove old SA after rekey;
    *) ike2 - send EAP identity as user-name RADIUS attribute;
    *) ike2 - update "calling_station_id" RADIUS attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added "last-seen" parameter to active connection list;
    *) ipsec - allow mixing aead algorithms in proposal;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - disallow AH+ESP combined policies ;
    *) ipsec - do not loose "use-ipsec=yes" parameter after downgrade;
    *) ipsec - enable aes-ni on i386 and x64 for cbc, ctr and gcm modes;
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - fixed SA authentication flag;
    *) ipsec - renamed "hw-authenc" flag to "hw-aead";
    *) ipsec - show hardware accelerated authenticated SAs;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) l2tp - added support for multiple L2TP tunnels (not to be confused with sessions) between same endpoints (required in some LNS configurations);
    *) l2tp - fixed hidden attribute decryption in forwarded CHAP responses for LNS;
    *) l2tp-server - added "caller-id-type" to forward calling station number to RADIUS on authentication;
    *) l2tp-server - added "use-ipsec=required" option;
    *) l2tp-server - fixed upgrade to keep "use-ipsec=yes" in L2TP server;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added "tr069" topic;
    *) log - added missing "license limit exceeded" log entry;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - do not show changes in packet if NAT has not been used;
    *) log - make SNMP logs more compact;
    *) lte - added "session-uptime" in info command;
    *) lte - added LTE signal level reading for Cinterion modems;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added initialization for Cinterion;
    *) lte - added log entry for SMS delivery report;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) lte - reset interface stats on "link-down";
    *) netinstall - fixed typos;
    *) ntp - restart NTP client when it is stuck in error state;
    *) ppp - added "bridge-horizon" option under PPP/Profile;
    *) ppp - added option to specify "interface-list" in PPP/Profile;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp - fixed rare kernel failure when receiving IPv6 address on PPP interface;
    *) ppp - include rates, limits and address-lists parameters in RADIUS accounting requests;
    *) ppp-client - added support for Datacard 750UL, DWR-730 and K4607-Zr;
    *) pppoe - added warning on PPPoE client/server, if it is configured on slave interface;
    *) pppoe - added warning on PPPoE client/server, if it is configured on slave interface;
    *) pppoe - set default keepalive 10s for newly created PPPoE clients;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - added partitioning support;
    *) smb - fixed different memory leaks and crashes;
    *) smb - fixed share path on devices with "/flash" directory;
    *) smips - reduced RouterOS main package size;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - added fan-speed OIDs in "/system health print oid";
    *) snmp - added optical table;
    *) snmp - fixed rare crash;
    *) snmp - improved getall filter;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - increase “engineBoots” value on reboot;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tile - fixed IPSec crash (introduced in 6.39rc64);
    *) tile - optimized hardware encryption;
    *) tr069-client - added "Device.Hosts.Host.{i}." support;
    *) tr069-client - added "Device.WiFi.NeighboringWiFiDiagnostic." support;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added Upload RPC "2 Vendor Log File" support;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - added connection request authentication;
    *) tr069-client - added firewall NAT support using vendor Parameters;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added support for uploading/downloading factory script;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed "AddObjectResponse" “InstanceNumber” value;
    *) tr069-client - fixed "Device.ManagementServer." value update;
    *) tr069-client - fixed XML special character parsing;
    *) tr069-client - fixed crash on =acs-url change special case;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - fixed write for "Device.ManagementServer.URL";
    *) tr069-client - general improvements on reducing storage space;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - hide "Device.PPP.Interface.{i}.Password" value;
    *) tr069-client - improved LTE monitoring process;
    *) tr069-client - increased performance on GetParameterValues;
    *) tr069-client - made any Download RPC overwrite configuration except ".alter";
    *) tr069-client - make more Parameters deny active notifications;
    *) tr069-client - set CHR license ID as ".SerialNumber" value to avoid "no serial number" error in ACS;
    *) traceroute - small fix;
    *) tunnels - fixed reboot loop on configurations with IPIP and EoIP tunnels (introduced in 6.39rc68);
    *) usb - added support for more CP210X devices;
    *) userman - allow "name-for-user" to be empty and not unique;
    *) userman - automatically select all newly created users to generate vouchers;
    *) userman - fixed rare crash when User Manager requested file does not exist on router;
    *) userman - fixed rare web interface crash while using Users section;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - allow to change global variable contents;
    *) webfig - allow to enter frequency ranges in wireless scan list;
    *) webfig - allow to select "default-encryption" profile on PPP tunnels;
    *) webfig - correctly specify routing filter prefix;
    *) webfig - do not allow to reorder items if table is sorted by some column;
    *) webfig - fixed bridge property display;
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - fixed “last-link-up” & “last-link-down” time information;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) webfig - show all available options under “Advanced Mode” for wireless interfaces;
    *) webfig - show proper error messages for optional erroneous text fields;
    *) winbox - added "Flush" button under unicast-fdb menu;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added "k" and "M" unit support to PPP secret limit-bytes parameters;
    *) winbox - added "memory-scroll", "filter-cpu", "filter-ipv6-address", "filter-operation-between-entries" parameters;
    *) winbox - added "save-selected" setting under CAPsMAN channels;
    *) winbox - added "static-virtual" to wireless CAP;
    *) winbox - added GPS menu;
    *) winbox - added protected routerboard parameters under routerboard settings menu;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify "route-distance" in "dhcp-client" if "special-classless" mode is selected;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - allowed to specify static-dns as list;
    *) winbox - do not allow Packet Sniffer "memory-limit" and "file-limit" lower than 10KiB;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not show "dpd-max-failures" on IKEv2;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not start Traffic Generator automatically when opening "Quick Start";
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed "Montly" typo to "Monthly" in Graphing menu;
    *) winbox - fixed CAPsMAN channels frequency (allow to specify a list of them);
    *) winbox - fixed IPSec "mode-config" DNS settings;
    *) winbox - fixed issue when working IPSec policies were shown as invalid;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - hide "wps-mode" & "security-profile" in wireless nv2 mode;
    *) winbox - hide health menu on RB450;
    *) winbox - improved "/tool torch";
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - properly show "dhcp-server" warnings;
    *) winbox - properly show IPSec "installed-sa" "enc-algorithm" when it is aes-gcm;
    *) winbox - properly show wireless registration table stat counters;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - set default "dhcp-client" "default-route-distance" value to 1;
    *) winbox - show "A" flag for IPSec policies;
    *) winbox - show "H" flag for IPSec installed SAs;
    *) winbox - show PoE-OUT current, voltage and power only on devices which can report these values;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - added PEAP authentication support for wireless station mode;
    *) wireless - apply broadcast bit to DHCP requests when using "station-pseudobridge" mode;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same "master-interface" is used;
    *) wireless - fixed RBSXT5HacD2nr2 small channel support;
    *) wireless - fixed crash while running "spectral-scan";
    *) wireless - fixed dynamic wireless interface removal from bridge ports when changing wireless mode;
    *) wireless - fixed false positive DFS radar detection caused by iPhone 6s devices;
    *) wireless - fixed issue when wireless interfaces might not show up in CAP mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare crash on nv2 configurations;
    *) wireless - fixed rare wireless ac interface lockup;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc76 2017-04-22

    What's new in 6.39rc76 (2017-Apr-21 07:24):

    *) capsman - added EAP identity to registration table;
    *) capsman - added support for "background-scan" and channel "reselect-interval";
    *) ike2 - fixed RSA authentication without EAP;
    *) ike2 - fixed policy release during SA negotion;
    *) l2tp - fixed hidden attribute decryption in forwarded CHAP responses for LNS;
    *) ppp - include rates, limits and address-lists parameters in RADIUS accounting requests;
    *) pppoe - added warning on PPPoE client/server, if it is configured on slave interface;
    *) tile - fixed IPSec crash (introduced in 6.39rc64);
    *) webfig - allow to change global variable contents;
    *) webfig - allow to enter frequency ranges in wireless scan list;
    *) webfig - do not allow to reorder items if table is sorted by some column;
    *) webfig - fixed bridge property display;
    *) webfig - show proper error messages for optional erroneous text fields;
    *) winbox - added "k" and "M" unit support to PPP secret limit-bytes parameters;
    *) winbox - added "Flush" button under unicast-fdb menu;
    *) winbox - added "memory-scroll", "filter-cpu", "filter-ipv6-address", "filter-operation-between-entries" parameters;
    *) winbox - added protected routerboard parameters under routerboard settings menu;
    *) winbox - hide "wps-mode" & "security-profile" in wireless nv2 mode;
    *) winbox - properly show wireless registration table stat counters;
    *) wireless - fixed dynamic wireless interface removal from bridge ports when changing wireless mode;

    Other changes since 6.38.5:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) bridge - fixed BPDU rx/tx when protocol-mode=none;
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) firewall - discontinued support for p2p matcher (old rules will become invalid);
    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) tile - fixed IPSec hardware acceleration out-of-order packet problem, significantly improved performance;
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) api - fixed double dynamic flags for "/ip firewall address-list print";
    *) capsman - added "extension-channel" XX and XXXX auto matching modes;
    *) capsman - added "keepalive-frames" setting;
    *) capsman - added "skip-dfs-channels" setting;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added DFS support;
    *) capsman - added ability to specify multiple channels in frequency field;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for "background-scan" (CLI only) and channel "reselect-interval";
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - changed channel "width" name to "control-channel-width" and changed default values;
    *) capsman - improved CAP status querying;
    *) capsman - improved support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - SCEP client now supports FQDN URL and port;
    *) certificate - allow CRL address to be specified as DNS name;
    *) console - fixed "/ip neighbor discovery" export;
    *) console - fixed DHCP/PPP add-default-route distance minimal value to 1;
    *) console - fixed crash;
    *) console - fixed incorrect ":put [/lcd get enabled]" value;
    *) ddns - improved "dns-update" authentication validation;
    *) defconf - fixed Groove 52 ac band settings;
    *) defconf - fixed default configuration generation when wireless package is disabled;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4 - fixed string option parser;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - by default make server “authoritative”;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) discovery - fixed LLDP discovery, IPv6 address was not parsed correctly;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - added "voltage-too-low" status for single port power injector devices;
    *) ethernet - fixed "loop-protect" on "master-port";
    *) ethernet - fixed rare switch chip hang (could cause port flapping);
    *) ethernet - fixed unnecessary power cycle of powered device when changing any poe-out related setting on single port power injector devices;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) ethernet - reversed poe-priority on hEX PoE and OmniTIK 5 PoE to make "poe-priority" consistent to all other RouterOS priorities;
    *) fastpath - fixed rare crash on devices with dynamic interfaces;
    *) fetch - added "http-data" and "http-method" parameters to allow delete, get, post, put methods (content-type=application/x-www-form-urlencoded by default);
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike1 - fixed ph2 ID logging;
    *) ike2 - allow multiple child SA traffic selectors on re-key;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - check child state before allowing rekey;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed CTR mode;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ctr mode;
    *) ike2 - fixed disabled DPD;
    *) ike2 - fixed last EAP auth payload type;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - improved logging;
    *) ike2 - kill only child SAs which are not re-keyed by remote peer;
    *) ike2 - log RADIUS timeout message under error topic;
    *) ike2 - remove old SA after rekey;
    *) ike2 - send EAP identity as user-name RADIUS attribute;
    *) ike2 - update "calling_station_id" RADIUS attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added "last-seen" parameter to active connection list;
    *) ipsec - allow mixing aead algorithms in proposal;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - disallow AH+ESP combined policies ;
    *) ipsec - do not loose "use-ipsec=yes" parameter after downgrade;
    *) ipsec - enable aes-ni on i386 and x64 for cbc, ctr and gcm modes;
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - fixed SA authentication flag;
    *) ipsec - renamed "hw-authenc" flag to "hw-aead";
    *) ipsec - show hardware accelerated authenticated SAs;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) l2tp - added support for multiple L2TP tunnels (not to be confused with sessions) between same endpoints (required in some LNS configurations);
    *) l2tp-server - added "caller-id-type" to forward calling station number to RADIUS on authentication;
    *) l2tp-server - added "use-ipsec=required" option;
    *) l2tp-server - fixed upgrade to keep "use-ipsec=yes" in L2TP server;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added "tr069" topic;
    *) log - added missing "license limit exceeded" log entry;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - do not show changes in packet if NAT has not been used;
    *) log - make SNMP logs more compact;
    *) lte - added "session-uptime" in info command;
    *) lte - added LTE signal level reading for Cinterion modems;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added initialization for Cinterion;
    *) lte - added log entry for SMS delivery report;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) lte - reset interface stats on "link-down";
    *) netinstall - fixed typos;
    *) ntp - restart NTP client when it is stuck in error state;
    *) ppp - added "bridge-horizon" option under PPP/Profile;
    *) ppp - added option to specify "interface-list" in PPP/Profile;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp - fixed rare kernel failure when receiving IPv6 address on PPP interface;
    *) ppp-client - added support for Datacard 750UL, DWR-730 and K4607-Zr;
    *) pppoe - added warning on PPPoE client/server, if it is configured on slave interface;
    *) pppoe - set default keepalive 10s for newly created PPPoE clients;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - added partitioning support;
    *) smb - fixed different memory leaks and crashes;
    *) smb - fixed share path on devices with "/flash" directory;
    *) smips - reduced RouterOS main package size;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - added fan-speed OIDs in "/system health print oid";
    *) snmp - added optical table;
    *) snmp - fixed rare crash;
    *) snmp - improved getall filter;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - increase “engineBoots” value on reboot;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tile - optimized hardware encryption;
    *) tr069-client - added "Device.Hosts.Host.{i}." support;
    *) tr069-client - added "Device.WiFi.NeighboringWiFiDiagnostic." support;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added Upload RPC "2 Vendor Log File" support;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - added connection request authentication;
    *) tr069-client - added firewall NAT support using vendor Parameters;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added support for uploading/downloading factory script;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed "AddObjectResponse" “InstanceNumber” value;
    *) tr069-client - fixed "Device.ManagementServer." value update;
    *) tr069-client - fixed XML special character parsing;
    *) tr069-client - fixed crash on =acs-url change special case;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - fixed write for "Device.ManagementServer.URL";
    *) tr069-client - general improvements on reducing storage space;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - hide "Device.PPP.Interface.{i}.Password" value;
    *) tr069-client - improved LTE monitoring process;
    *) tr069-client - increased performance on GetParameterValues;
    *) tr069-client - made any Download RPC overwrite configuration except ".alter";
    *) tr069-client - make more Parameters deny active notifications;
    *) tr069-client - set CHR license ID as ".SerialNumber" value to avoid "no serial number" error in ACS;
    *) traceroute - small fix;
    *) tunnels - fixed reboot loop on configurations with IPIP and EoIP tunnels (introduced in 6.39rc68);
    *) usb - added support for more CP210X devices;
    *) userman - allow "name-for-user" to be empty and not unique;
    *) userman - automatically select all newly created users to generate vouchers;
    *) userman - fixed rare crash when User Manager requested file does not exist on router;
    *) userman - fixed rare web interface crash while using Users section;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - allow to select "default-encryption" profile on PPP tunnels;
    *) webfig - correctly specify routing filter prefix;
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - fixed “last-link-up” & “last-link-down” time information;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) webfig - show all available options under “Advanced Mode” for wireless interfaces;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added "save-selected" setting under CAPsMAN channels;
    *) winbox - added "static-virtual" to wireless CAP;
    *) winbox - added GPS menu;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify "route-distance" in "dhcp-client" if "special-classless" mode is selected;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - allowed to specify static-dns as list;
    *) winbox - do not allow Packet Sniffer "memory-limit" and "file-limit" lower than 10KiB;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not show "dpd-max-failures" on IKEv2;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not start Traffic Generator automatically when opening "Quick Start";
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed "Montly" typo to "Monthly" in Graphing menu;
    *) winbox - fixed CAPsMAN channels frequency (allow to specify a list of them);
    *) winbox - fixed IPSec "mode-config" DNS settings;
    *) winbox - fixed issue when working IPSec policies were shown as invalid;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - hide health menu on RB450;
    *) winbox - improved "/tool torch";
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - properly show "dhcp-server" warnings;
    *) winbox - properly show IPSec "installed-sa" "enc-algorithm" when it is aes-gcm;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - set default "dhcp-client" "default-route-distance" value to 1;
    *) winbox - show "A" flag for IPSec policies;
    *) winbox - show "H" flag for IPSec installed SAs;
    *) winbox - show PoE-OUT current, voltage and power only on devices which can report these values;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - added PEAP authentication support for wireless station mode;
    *) wireless - apply broadcast bit to DHCP requests when using "station-pseudobridge" mode;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same "master-interface" is used;
    *) wireless - fixed RBSXT5HacD2nr2 small channel support;
    *) wireless - fixed crash while running "spectral-scan";
    *) wireless - fixed false positive DFS radar detection caused by iPhone 6s devices;
    *) wireless - fixed issue when wireless interfaces might not show up in CAP mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare crash on nv2 configurations;
    *) wireless - fixed rare wireless ac interface lockup;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc72 2017-04-13

    What's new in 6.39rc72 (2017-Apr-12 11:56):

    *) discovery - fixed LLDP discovery, IPv6 address was not parsed correctly;
    *) l2tp - added support for multiple L2TP tunnels (not to be confused with sessions) between same endpoints (required in some LNS configurations);
    *) l2tp-server - added "caller-id-type" to forward calling station number to RADIUS on authentication;
    *) l2tp-server - added "use-ipsec=required" option;
    *) l2tp-server - fixed upgrade to keep "use-ipsec=yes" in L2TP server;
    *) log - added missing "license limit exceeded" log entry;
    *) ppp - added option to specify "interface-list" in PPP/Profile;
    *) pppoe - added warning on PPPoE client/server, if it is configured on slave interface;

    Other changes since 6.38.5:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) bridge - fixed BPDU rx/tx when protocol-mode=none;
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) firewall - discontinued support for p2p matcher (old rules will become invalid);
    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) tile - fixed IPSec hardware acceleration out-of-order packet problem, significantly improved performance;
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) api - fixed double dynamic flags for "/ip firewall address-list print";
    *) capsman - added "extension-channel" XX and XXXX auto matching modes;
    *) capsman - added "keepalive-frames" setting;
    *) capsman - added "skip-dfs-channels" setting;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added DFS support;
    *) capsman - added ability to specify multiple channels in frequency field;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for "background-scan" (CLI only) and channel "reselect-interval";
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - changed channel "width" name to "control-channel-width" and changed default values;
    *) capsman - improved CAP status querying;
    *) capsman - improved support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - SCEP client now supports FQDN URL and port;
    *) certificate - allow CRL address to be specified as DNS name;
    *) console - fixed "/ip neighbor discovery" export;
    *) console - fixed DHCP/PPP add-default-route distance minimal value to 1;
    *) console - fixed crash;
    *) console - fixed incorrect ":put [/lcd get enabled]" value;
    *) ddns - improved "dns-update" authentication validation;
    *) defconf - fixed Groove 52 ac band settings;
    *) defconf - fixed default configuration generation when wireless package is disabled;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4 - fixed string option parser;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - by default make server “authoritative”;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - added "voltage-too-low" status for single port power injector devices;
    *) ethernet - fixed "loop-protect" on "master-port";
    *) ethernet - fixed rare switch chip hang (could cause port flapping);
    *) ethernet - fixed unnecessary power cycle of powered device when changing any poe-out related setting on single port power injector devices;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) ethernet - reversed poe-priority on hEX PoE and OmniTIK 5 PoE to make "poe-priority" consistent to all other RouterOS priorities;
    *) fastpath - fixed rare crash on devices with dynamic interfaces;
    *) fetch - added "http-data" and "http-method" parameters to allow delete, get, post, put methods (content-type=application/x-www-form-urlencoded by default);
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike1 - fixed ph2 ID logging;
    *) ike2 - allow multiple child SA traffic selectors on re-key;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - check child state before allowing rekey;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed CTR mode;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ctr mode;
    *) ike2 - fixed disabled DPD;
    *) ike2 - fixed last EAP auth payload type;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - improved logging;
    *) ike2 - kill only child SAs which are not re-keyed by remote peer;
    *) ike2 - log RADIUS timeout message under error topic;
    *) ike2 - remove old SA after rekey;
    *) ike2 - send EAP identity as user-name RADIUS attribute;
    *) ike2 - update "calling_station_id" RADIUS attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added "last-seen" parameter to active connection list;
    *) ipsec - allow mixing aead algorithms in proposal;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - disallow AH+ESP combined policies ;
    *) ipsec - do not loose "use-ipsec=yes" parameter after downgrade;
    *) ipsec - enable aes-ni on i386 and x64 for cbc, ctr and gcm modes;
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - fixed SA authentication flag;
    *) ipsec - renamed "hw-authenc" flag to "hw-aead";
    *) ipsec - show hardware accelerated authenticated SAs;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added "tr069" topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - do not show changes in packet if NAT has not been used;
    *) log - make SNMP logs more compact;
    *) lte - added "session-uptime" in info command;
    *) lte - added LTE signal level reading for Cinterion modems;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added initialization for Cinterion;
    *) lte - added log entry for SMS delivery report;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) lte - reset interface stats on "link-down";
    *) netinstall - fixed typos;
    *) ntp - restart NTP client when it is stuck in error state;
    *) ppp - added "bridge-horizon" option under PPP/Profile;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp - fixed rare kernel failure when receiving IPv6 address on PPP interface;
    *) ppp-client - added support for Datacard 750UL, DWR-730 and K4607-Zr;
    *) pppoe - set default keepalive 10s for newly created PPPoE clients;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - added partitioning support;
    *) smb - fixed different memory leaks and crashes;
    *) smb - fixed share path on devices with "/flash" directory;
    *) smips - reduced RouterOS main package size;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - added fan-speed OIDs in "/system health print oid";
    *) snmp - added optical table;
    *) snmp - fixed rare crash;
    *) snmp - improved getall filter;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - increase “engineBoots” value on reboot;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tile - optimized hardware encryption;
    *) tr069-client - added "Device.Hosts.Host.{i}." support;
    *) tr069-client - added "Device.WiFi.NeighboringWiFiDiagnostic." support;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added Upload RPC "2 Vendor Log File" support;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - added connection request authentication;
    *) tr069-client - added firewall NAT support using vendor Parameters;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added support for uploading/downloading factory script;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed "AddObjectResponse" “InstanceNumber” value;
    *) tr069-client - fixed "Device.ManagementServer." value update;
    *) tr069-client - fixed XML special character parsing;
    *) tr069-client - fixed crash on =acs-url change special case;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - fixed write for "Device.ManagementServer.URL";
    *) tr069-client - general improvements on reducing storage space;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - hide "Device.PPP.Interface.{i}.Password" value;
    *) tr069-client - improved LTE monitoring process;
    *) tr069-client - increased performance on GetParameterValues;
    *) tr069-client - made any Download RPC overwrite configuration except ".alter";
    *) tr069-client - make more Parameters deny active notifications;
    *) tr069-client - set CHR license ID as ".SerialNumber" value to avoid "no serial number" error in ACS;
    *) traceroute - small fix;
    *) tunnels - fixed reboot loop on configurations with IPIP and EoIP tunnels (introduced in 6.39rc68);
    *) usb - added support for more CP210X devices;
    *) userman - allow "name-for-user" to be empty and not unique;
    *) userman - automatically select all newly created users to generate vouchers;
    *) userman - fixed rare crash when User Manager requested file does not exist on router;
    *) userman - fixed rare web interface crash while using Users section;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - allow to select "default-encryption" profile on PPP tunnels;
    *) webfig - correctly specify routing filter prefix;
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - fixed “last-link-up” & “last-link-down” time information;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) webfig - show all available options under “Advanced Mode” for wireless interfaces;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added "save-selected" setting under CAPsMAN channels;
    *) winbox - added "static-virtual" to wireless CAP;
    *) winbox - added GPS menu;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify "route-distance" in "dhcp-client" if "special-classless" mode is selected;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - allowed to specify static-dns as list;
    *) winbox - do not allow Packet Sniffer "memory-limit" and "file-limit" lower than 10KiB;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not show "dpd-max-failures" on IKEv2;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not start Traffic Generator automatically when opening "Quick Start";
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed "Montly" typo to "Monthly" in Graphing menu;
    *) winbox - fixed CAPsMAN channels frequency (allow to specify a list of them);
    *) winbox - fixed IPSec "mode-config" DNS settings;
    *) winbox - fixed issue when working IPSec policies were shown as invalid;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - hide health menu on RB450;
    *) winbox - improved "/tool torch";
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - properly show "dhcp-server" warnings;
    *) winbox - properly show IPSec "installed-sa" "enc-algorithm" when it is aes-gcm;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - set default "dhcp-client" "default-route-distance" value to 1;
    *) winbox - show "A" flag for IPSec policies;
    *) winbox - show "H" flag for IPSec installed SAs;
    *) winbox - show PoE-OUT current, voltage and power only on devices which can report these values;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - added PEAP authentication support for wireless station mode;
    *) wireless - apply broadcast bit to DHCP requests when using "station-pseudobridge" mode;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same "master-interface" is used;
    *) wireless - fixed RBSXT5HacD2nr2 small channel support;
    *) wireless - fixed crash while running "spectral-scan";
    *) wireless - fixed false positive DFS radar detection caused by iPhone 6s devices;
    *) wireless - fixed issue when wireless interfaces might not show up in CAP mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare crash on nv2 configurations;
    *) wireless - fixed rare wireless ac interface lockup;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc69 2017-04-12

    What's new in 6.39rc69 (2017-Apr-12 07:31):

    *) ike2 - allow multiple child SA traffic selectors on re-key;
    *) ike2 - log RADIUS timeout message under error topic;
    *) ipsec - do not loose "use-ipsec=yes" parameter after downgrade;
    *) lte - added "session-uptime" in info command;
    *) lte - reset interface stats on "link-down";
    *) ppp - added "bridge-horizon" option under PPP/Profile;
    *) snmp - increase “engineBoots” value on reboot;
    *) tunnels - fixed reboot loop on configurations with IPIP and EoIP tunnels (introduced in 6.39rc68);
    *) webfig - allow to select "default-encryption" profile on PPP tunnels;
    *) webfig - show all available options under “Advanced Mode” for wireless interfaces;
    *) webfig - fixed “last-link-up” & “last-link-down” time information;
    *) winbox - do not start Traffic Generator automatically when opening "Quick Start";

    Other changes since 6.38.5:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) bridge - fixed BPDU rx/tx when protocol-mode=none;
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) firewall - discontinued support for p2p matcher (old rules will become invalid);
    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) tile - fixed IPSec hardware acceleration out-of-order packet problem, significantly improved performance;
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) api - fixed double dynamic flags for "/ip firewall address-list print";
    *) capsman - added "extension-channel" XX and XXXX auto matching modes;
    *) capsman - added "keepalive-frames" setting;
    *) capsman - added "skip-dfs-channels" setting;
    *) capsman - added ability to specify multiple channels in frequency field;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added DFS support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for "background-scan" (CLI only) and channel "reselect-interval";
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - changed channel "width" name to "control-channel-width" and changed default values;
    *) capsman - improved CAP status querying;
    *) capsman - improved support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) certificate - SCEP client now supports FQDN URL and port;
    *) console - fixed "/ip neighbor discovery" export;
    *) console - fixed crash;
    *) console - fixed DHCP/PPP add-default-route distance minimal value to 1;
    *) console - fixed incorrect ":put [/lcd get enabled]" value;
    *) ddns - improved "dns-update" authentication validation;
    *) defconf - fixed default configuration generation when wireless package is disabled;
    *) defconf - fixed Groove 52 ac band settings;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4 - fixed string option parser;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - by default make server “authoritative”;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - added "voltage-too-low" status for single port power injector devices;
    *) ethernet - fixed "loop-protect" on "master-port";
    *) ethernet - fixed rare switch chip hang (could cause port flapping);
    *) ethernet - fixed unnecessary power cycle of powered device when changing any poe-out related setting on single port power injector devices;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) ethernet - reversed poe-priority on hEX PoE and OmniTIK 5 PoE to make "poe-priority" consistent to all other RouterOS priorities;
    *) fastpath - fixed rare crash on devices with dynamic interfaces;
    *) fetch - added "http-data" and "http-method" parameters to allow delete, get, post, put methods (content-type=application/x-www-form-urlencoded by default);
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike1 - fixed ph2 ID logging;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - check child state before allowing rekey;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed ctr mode;
    *) ike2 - fixed CTR mode;
    *) ike2 - fixed disabled DPD;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed last EAP auth payload type;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - improved logging;
    *) ike2 - kill only child SAs which are not re-keyed by remote peer;
    *) ike2 - remove old SA after rekey;
    *) ike2 - send EAP identity as user-name RADIUS attribute;
    *) ike2 - update "calling_station_id" RADIUS attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added "last-seen" parameter to active connection list;
    *) ipsec - allow mixing aead algorithms in proposal;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - disallow AH+ESP combined policies ;
    *) ipsec - enable aes-ni on i386 and x64 for cbc, ctr and gcm modes;
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - fixed SA authentication flag;
    *) ipsec - renamed "hw-authenc" flag to "hw-aead";
    *) ipsec - show hardware accelerated authenticated SAs;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) l2tp-server - added "use-ipsec=required" option;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added "tr069" topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - do not show changes in packet if NAT has not been used;
    *) log - make SNMP logs more compact;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added initialization for Cinterion;
    *) lte - added log entry for SMS delivery report;
    *) lte - added LTE signal level reading for Cinterion modems;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) netinstall - fixed typos;
    *) ntp - restart NTP client when it is stuck in error state;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp - fixed rare kernel failure when receiving IPv6 address on PPP interface;
    *) ppp-client - added support for Datacard 750UL, DWR-730 and K4607-Zr;
    *) pppoe - set default keepalive 10s for newly created PPPoE clients;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - added partitioning support;
    *) smb - fixed different memory leaks and crashes;
    *) smb - fixed share path on devices with "/flash" directory;
    *) smips - reduced RouterOS main package size;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - added fan-speed OIDs in "/system health print oid";
    *) snmp - added optical table;
    *) snmp - fixed rare crash;
    *) snmp - improved getall filter;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tile - optimized hardware encryption;
    *) tr069-client - added "Device.Hosts.Host.{i}." support;
    *) tr069-client - added "Device.WiFi.NeighboringWiFiDiagnostic." support;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - added connection request authentication;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added firewall NAT support using vendor Parameters;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added support for uploading/downloading factory script;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - added Upload RPC "2 Vendor Log File" support;
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed "AddObjectResponse" “InstanceNumber” value;
    *) tr069-client - fixed "Device.ManagementServer." value update;
    *) tr069-client - fixed crash on =acs-url change special case;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - fixed write for "Device.ManagementServer.URL";
    *) tr069-client - fixed XML special character parsing;
    *) tr069-client - general improvements on reducing storage space;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - hide "Device.PPP.Interface.{i}.Password" value;
    *) tr069-client - improved LTE monitoring process;
    *) tr069-client - increased performance on GetParameterValues;
    *) tr069-client - made any Download RPC overwrite configuration except ".alter";
    *) tr069-client - make more Parameters deny active notifications;
    *) tr069-client - set CHR license ID as ".SerialNumber" value to avoid "no serial number" error in ACS;
    *) traceroute - small fix;
    *) usb - added support for more CP210X devices;
    *) userman - allow "name-for-user" to be empty and not unique;
    *) userman - automatically select all newly created users to generate vouchers;
    *) userman - fixed rare crash when User Manager requested file does not exist on router;
    *) userman - fixed rare web interface crash while using Users section;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - correctly specify routing filter prefix;
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added "save-selected" setting under CAPsMAN channels;
    *) winbox - added "static-virtual" to wireless CAP;
    *) winbox - added GPS menu;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify "route-distance" in "dhcp-client" if "special-classless" mode is selected;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - allowed to specify static-dns as list;
    *) winbox - do not allow Packet Sniffer "memory-limit" and "file-limit" lower than 10KiB;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not show "dpd-max-failures" on IKEv2;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed "Montly" typo to "Monthly" in Graphing menu;
    *) winbox - fixed CAPsMAN channels frequency (allow to specify a list of them);
    *) winbox - fixed IPSec "mode-config" DNS settings;
    *) winbox - fixed issue when working IPSec policies were shown as invalid;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - hide health menu on RB450;
    *) winbox - improved "/tool torch";
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - properly show "dhcp-server" warnings;
    *) winbox - properly show IPSec "installed-sa" "enc-algorithm" when it is aes-gcm;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - set default "dhcp-client" "default-route-distance" value to 1;
    *) winbox - show "A" flag for IPSec policies;
    *) winbox - show "H" flag for IPSec installed SAs;
    *) winbox - show PoE-OUT current, voltage and power only on devices which can report these values;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - added PEAP authentication support for wireless station mode;
    *) wireless - apply broadcast bit to DHCP requests when using "station-pseudobridge" mode;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same "master-interface" is used;
    *) wireless - fixed crash while running "spectral-scan";
    *) wireless - fixed false positive DFS radar detection caused by iPhone 6s devices;
    *) wireless - fixed issue when wireless interfaces might not show up in CAP mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare crash on nv2 configurations;
    *) wireless - fixed rare wireless ac interface lockup;
    *) wireless - fixed RBSXT5HacD2nr2 small channel support;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc68 2017-04-11

    What's new in 6.39rc68 (2017-Apr-11 08:29):

    *) capsman - added "extension-channel" XX and XXXX auto matching modes;
    *) capsman - added "keepalive-frames" setting;
    *) capsman - added "skip-dfs-channels" setting;
    *) capsman - added ability to specify multiple channels in frequency field;
    *) capsman - added support for "background-scan" (CLI only) and channel "reselect-interval";
    *) capsman - changed channel "width" name to "control-channel-width" and changed default values;
    *) ddns - improved "dns-update" authentication validation;
    *) dhcpv4 - fixed string option parser;
    *) ike2 - fixed disabled DPD;
    *) ike2 - fixed last EAP authentication payload type;
    *) ike2 - improved logging;
    *) ike2 - kill only child SAs which are not re-keyed by remote peer;
    *) ipsec - disallow AH+ESP combined policies ;
    *) ppp - fixed rare kernel failure when receiving IPv6 address on PPP interface;
    *) tr069-client - made any Download RPC overwrite configuration except ".alter";
    *) tr069-client - improved LTE monitoring process;
    *) winbox - allowed to specify "static-dns" as list;
    *) winbox - do not show "dpd-max-failures" on IKEv2;
    *) winbox - fixed CAPsMAN channels frequency (allow to specify a list of them);
    *) winbox - fixed IPSec "mode-config" DNS settings;
    *) winbox - fixed issue when working IPSec policies were shown as invalid;
    *) winbox - improved "/tool torch";
    *) winbox - do not allow Packet Sniffer "memory-limit" and "file-limit" lower than 10KiB;
    *) winbox - show "A" flag for IPSec policies;
    *) winbox - show "H" flag for IPSec installed SAs;
    *) wireless - added PEAP authentication support for wireless station mode;

    Other changes since 6.38.5:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) bridge - fixed BPDU rx/tx when protocol-mode=none;
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) firewall - discontinued support for p2p matcher (old rules will become invalid);
    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) tile - fixed IPSec hardware acceleration out-of-order packet problem, significantly improved performance;
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) api - fixed double dynamic flags for "/ip firewall address-list print";
    *) capsman - added CAP discovery interface list support;
    *) capsman - added DFS support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - improved CAP status querying;
    *) capsman - improved support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - SCEP client now supports FQDN URL and port;
    *) certificate - allow CRL address to be specified as DNS name;
    *) console - fixed "/ip neighbor discovery" export;
    *) console - fixed DHCP/PPP add-default-route distance minimal value to 1;
    *) console - fixed crash;
    *) console - fixed incorrect ":put [/lcd get enabled]" value;
    *) defconf - fixed Groove 52 ac band settings;
    *) defconf - fixed default configuration generation when wireless package is disabled;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - by default make server “authoritative”;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - added "voltage-too-low" status for single port power injector devices;
    *) ethernet - fixed "loop-protect" on "master-port";
    *) ethernet - fixed rare switch chip hang (could cause port flapping);
    *) ethernet - fixed unnecessary power cycle of powered device when changing any poe-out related setting on single port power injector devices;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) ethernet - reversed poe-priority on hEX PoE and OmniTIK 5 PoE to make "poe-priority" consistent to all other RouterOS priorities;
    *) fastpath - fixed rare crash on devices with dynamic interfaces;
    *) fetch - added "http-data" and "http-method" parameters to allow delete, get, post, put methods (content-type=application/x-www-form-urlencoded by default);
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike1 - fixed ph2 ID logging;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - check child state before allowing rekey;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed CTR mode;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ctr mode;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - remove old SA after rekey;
    *) ike2 - send EAP identity as user-name RADIUS attribute;
    *) ike2 - update "calling_station_id" radius attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added "last-seen" parameter to active connection list;
    *) ipsec - allow mixing aead algorithms in proposal;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - enable aes-ni on i386 and x64 for cbc, ctr and gcm modes;
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - fixed SA authentication flag;
    *) ipsec - renamed "hw-authenc" flag to "hw-aead";
    *) ipsec - show hardware accelerated authenticated SAs;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) l2tp-server - added "use-ipsec=required" option;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added "tr069" topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - do not show changes in packet if NAT has not been used;
    *) log - make SNMP logs more compact;
    *) lte - added LTE signal level reading for Cinterion modems;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added initialization for Cinterion;
    *) lte - added log entry for SMS delivery report;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) netinstall - fixed typos;
    *) ntp - restart NTP client when it is stuck in error state;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp-client - added support for Datacard 750UL, DWR-730 and K4607-Zr;
    *) pppoe - set default keepalive 10s for newly created PPPoE clients;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - added partitioning support;
    *) smb - fixed different memory leaks and crashes;
    *) smb - fixed share path on devices with "/flash" directory;
    *) smips - reduced RouterOS main package size;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - added fan-speed OIDs in "/system health print oid";
    *) snmp - added optical table;
    *) snmp - fixed rare crash;
    *) snmp - improved getall filter;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tile - optimized hardware encryption;
    *) tr069-client - added "Device.Hosts.Host.{i}." support;
    *) tr069-client - added "Device.WiFi.NeighboringWiFiDiagnostic." support;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added Upload RPC "2 Vendor Log File" support;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - added connection request authentication;
    *) tr069-client - added firewall NAT support using vendor Parameters;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added support for uploading/downloading factory script;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed "AddObjectResponse" “InstanceNumber” value;
    *) tr069-client - fixed "Device.ManagementServer." value update;
    *) tr069-client - fixed XML special character parsing;
    *) tr069-client - fixed crash on =acs-url change special case;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - fixed write for "Device.ManagementServer.URL";
    *) tr069-client - general improvements on reducing storage space;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - hide "Device.PPP.Interface.{i}.Password" value;
    *) tr069-client - increased performance on GetParameterValues;
    *) tr069-client - make more Parameters deny active notifications;
    *) tr069-client - set CHR license ID as ".SerialNumber" value to avoid "no serial number" error in ACS;
    *) traceroute - small fix;
    *) usb - added support for more CP210X devices;
    *) userman - allow "name-for-user" to be empty and not unique;
    *) userman - automatically select all newly created users to generate vouchers;
    *) userman - fixed rare crash when User Manager requested file does not exist on router;
    *) userman - fixed rare web interface crash while using Users section;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - correctly specify routing filter prefix;
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added "save-selected" setting under CAPsMAN channels;
    *) winbox - added "static-virtual" to wireless CAP;
    *) winbox - added GPS menu;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify "route-distance" in "dhcp-client" if "special-classless" mode is selected;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed "Montly" typo to "Monthly" in Graphing menu;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - hide health menu on RB450;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - properly show "dhcp-server" warnings;
    *) winbox - properly show IPSec "installed-sa" "enc-algorithm" when it is aes-gcm;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - set default "dhcp-client" "default-route-distance" value to 1;
    *) winbox - show PoE-OUT current, voltage and power only on devices which can report these values;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - apply broadcast bit to DHCP requests when using "station-pseudobridge" mode;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same "master-interface" is used;
    *) wireless - fixed RBSXT5HacD2nr2 small channel support;
    *) wireless - fixed crash while running "spectral-scan";
    *) wireless - fixed false positive DFS radar detection caused by iPhone 6s devices;
    *) wireless - fixed issue when wireless interfaces might not show up in CAP mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare crash on nv2 configurations;
    *) wireless - fixed rare wireless ac interface lockup;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc62 2017-04-04

    What's new in 6.39rc62 (2017-Apr-04 14:09):

    !) firewall - discontinued support for p2p matcher (old rules will become invalid);
    *) capsman - added "extension-channel" XX and XXXX auto matching modes (CLI only);
    *) capsman - added "keepalive-frames" setting (CLI only);
    *) capsman - added "skip-dfs-channels" setting (CLI only);
    *) capsman - added ability to specify multiple channels in frequency field (CLI only);
    *) capsman - added DFS support;
    *) capsman - added support for "background-scan" and channel "reselect-interval" (CLI only);
    *) capsman - changed channel "width" name to "control-channel-width" and changed default values (CLI only);
    *) fastpath - fixed rare crash on devices with dynamic interfaces;
    *) smips - reduced RouterOS main package size;
    *) tile - optimized hardware encryption;
    *) tr069-client - added firewall NAT support using vendor Parameters;
    *) tr069-client - added support for uploading/downloading factory script;
    *) webfig - correctly specify routing filter prefix;
    *) winbox - allow to specify "route-distance" in "dhcp-client" if "special-classless" mode is selected;
    *) winbox - do not allow Packet Sniffer "memory-limit" lower than 10KiB;
    *) winbox - fixed "Montly" typo to "Monthly" in Graphing menu;
    *) winbox - hide health menu on RB450;
    *) winbox - properly show "dhcp-server" warnings;
    *) winbox - properly show IPSec "installed-sa" "enc-algorithm" when it is aes-gcm;
    *) winbox - set default "dhcp-client" "default-route-distance" value to 1;
    *) winbox - show PoE-OUT current, voltage and power only on devices which can report these values;
    *) wireless - added PEAP authentication support for wireless station mode (CLI only);

    Other changes since 6.38.5:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) bridge - fixed BPDU rx/tx when protocol-mode=none;
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) tile - fixed IPsec hardware acceleration out-of-order packet problem, significantly improved performance;
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) api - fixed double dynamic flags for "/ip firewall address-list print";
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - improved CAP status querying;
    *) capsman - improved support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) certificate - SCEP client now supports FQDN URL and port;
    *) console - fixed "/ip neighbor discovery" export;
    *) console - fixed crash;
    *) console - fixed DHCP/PPP add-default-route distance minimal value to 1;
    *) console - fixed incorrect ":put [/lcd get enabled]" value;
    *) defconf - fixed default configuration generation when wireless package is disabled;
    *) defconf - fixed Groove 52 ac band settings;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - by default make server “authoritative”;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - added "voltage-too-low" status for single port power injector devices;
    *) ethernet - fixed "loop-protect" on "master-port";
    *) ethernet - fixed rare switch chip hang (could cause port flapping);
    *) ethernet - fixed unnecessary power cycle of powered device when changing any poe-out related setting on single port power injector devices;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) ethernet - reversed poe-priority on hEX PoE and OmniTIK 5 PoE to make "poe-priority" consistent to all other RouterOS priorities;
    *) fetch - added "http-data" and "http-method" parameters to allow delete, get, post, put methods (content-type=application/x-www-form-urlencoded by default);
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike1 - fixed ph2 ID logging;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - check child state before allowing rekey;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed CTR mode;
    *) ike2 - fixed ctr mode;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - remove old SA after rekey;
    *) ike2 - send EAP identity as user-name RADIUS attribute;
    *) ike2 - update "calling_station_id" radius attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added "last-seen" parameter to active connection list;
    *) ipsec - allow mixing aead algorithms in proposal;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - enable aes-ni on i386 and x64 for cbc, ctr and gcm modes;
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - fixed SA authentication flag;
    *) ipsec - renamed "hw-authenc" flag to "hw-aead";
    *) ipsec - show hardware accelerated authenticated SAs;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) l2tp-server - added "use-ipsec=required" option;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added "tr069" topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - do not show changes in packet if NAT has not been used;
    *) log - make SNMP logs more compact;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added initialization for Cinterion;
    *) lte - added log entry for SMS delivery report;
    *) lte - added LTE signal level reading for Cinterion modems;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) netinstall - fixed typos;
    *) ntp - restart NTP client when it is stuck in error state;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp-client - added support for Datacard 750UL, DWR-730 and K4607-Zr;
    *) pppoe - set default keepalive 10s for newly created PPPoE clients;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - added partitioning support;
    *) smb - fixed different memory leaks and crashes;
    *) smb - fixed share path on devices with "/flash" directory;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - added fan-speed OIDs in "/system health print oid";
    *) snmp - added optical table;
    *) snmp - fixed rare crash;
    *) snmp - improved getall filter;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tr069-client - added "Device.Hosts.Host.{i}." support;
    *) tr069-client - added "Device.WiFi.NeighboringWiFiDiagnostic." support;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - added connection request authentication;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - added Upload RPC "2 Vendor Log File" support;
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed "AddObjectResponse" “InstanceNumber” value;
    *) tr069-client - fixed "Device.ManagementServer." value update;
    *) tr069-client - fixed crash on =acs-url change special case;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - fixed write for "Device.ManagementServer.URL";
    *) tr069-client - fixed XML special character parsing;
    *) tr069-client - general improvements on reducing storage space;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - hide "Device.PPP.Interface.{i}.Password" value;
    *) tr069-client - increased performance on GetParameterValues;
    *) tr069-client - make more Parameters deny active notifications;
    *) tr069-client - set CHR license ID as ".SerialNumber" value to avoid "no serial number" error in ACS;
    *) traceroute - small fix;
    *) usb - added support for more CP210X devices;
    *) userman - allow "name-for-user" to be empty and not unique;
    *) userman - automatically select all newly created users to generate vouchers;
    *) userman - fixed rare crash when User Manager requested file does not exist on router;
    *) userman - fixed rare web interface crash while using Users section;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added "save-selected" setting under CAPsMAN channels;
    *) winbox - added "static-virtual" to wireless CAP;
    *) winbox - added GPS menu;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - apply broadcast bit to DHCP requests when using "station-pseudobridge" mode;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same "master-interface" is used;
    *) wireless - fixed crash while running "spectral-scan";
    *) wireless - fixed false positive DFS radar detection caused by iPhone 6s devices;
    *) wireless - fixed issue when wireless interfaces might not show up in CAP mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare crash on nv2 configurations;
    *) wireless - fixed rare wireless ac interface lockup;
    *) wireless - fixed RBSXT5HacD2nr2 small channel support;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc60 2017-04-03

    What's new in 6.39rc60 (2017-Apr-03 07:59):

    *) dhcpv4-server - by default make server “authoritative”;
    *) ethernet - fixed "loop-protect" on "master-port";
    *) ethernet - fixed rare switch chip hang (could cause port flapping);
    *) ike2 - fixed ctr mode;
    *) ipsec - enable aes-ni on i386 and x64 for cbc, ctr and gcm modes;
    *) ipsec - renamed "hw-authenc" flag to "hw-aead";
    *) log - do not show changes in packet if NAT has not been used;
    *) tr069-client - fixed XML special character parsing;
    *) tr069-client - hide "Device.PPP.Interface.{i}.Password" value;
    *) tr069-client - make more Parameters deny active notifications;
    *) wireless - fixed crash while running "spectral-scan";
    *) wireless - fixed false positive DFS radar detection caused by iPhone 6s devices;

    Other changes since 6.38.5:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) bridge - fixed BPDU rx/tx when protocol-mode=none;
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) firewall - discontinued support for p2p matcher (old rules will become invalid);
    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) tile - fixed IPsec hardware acceleration out-of-order packet problem, significantly improved performance;
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) api - fixed double dynamic flags for "/ip firewall address-list print";
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - improved CAP status querying;
    *) capsman - improved support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) certificate - SCEP client now supports FQDN URL and port;
    *) console - fixed "/ip neighbor discovery" export;
    *) console - fixed crash;
    *) console - fixed DHCP/PPP add-default-route distance minimal value to 1;
    *) console - fixed incorrect ":put [/lcd get enabled]" value;
    *) defconf - fixed default configuration generation when wireless package is disabled;
    *) defconf - fixed Groove 52 ac band settings;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - added "voltage-too-low" status for single port power injector devices;
    *) ethernet - fixed unnecessary power cycle of powered device when changing any poe-out related setting on single port power injector devices;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) ethernet - reversed poe-priority on hEX PoE and OmniTIK 5 PoE to make "poe-priority" consistent to all other RouterOS priorities;
    *) fetch - added "http-data" and "http-method" parameters to allow delete, get, post, put methods (content-type=application/x-www-form-urlencoded by default);
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike1 - fixed ph2 ID logging;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - check child state before allowing rekey;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed CTR mode;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - remove old SA after rekey;
    *) ike2 - send EAP identity as user-name RADIUS attribute;
    *) ike2 - update "calling_station_id" radius attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added "last-seen" parameter to active connection list;
    *) ipsec - allow mixing aead algorithms in proposal;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - fixed SA authentication flag;
    *) ipsec - show hardware accelerated authenticated SAs;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) l2tp-server - added "use-ipsec=required" option;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added "tr069" topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - make SNMP logs more compact;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added initialization for Cinterion;
    *) lte - added log entry for SMS delivery report;
    *) lte - added LTE signal level reading for Cinterion modems;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) netinstall - fixed typos;
    *) ntp - restart NTP client when it is stuck in error state;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp-client - added support for Datacard 750UL, DWR-730 and K4607-Zr;
    *) pppoe - set default keepalive 10s for newly created PPPoE clients;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - added partitioning support;
    *) smb - fixed different memory leaks and crashes;
    *) smb - fixed share path on devices with "/flash" directory;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - added fan-speed OIDs in "/system health print oid";
    *) snmp - added optical table;
    *) snmp - fixed rare crash;
    *) snmp - improved getall filter;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tr069-client - added "Device.Hosts.Host.{i}." support;
    *) tr069-client - added "Device.WiFi.NeighboringWiFiDiagnostic." support;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - added connection request authentication;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - added Upload RPC "2 Vendor Log File" support;
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed "AddObjectResponse" “InstanceNumber” value;
    *) tr069-client - fixed "Device.ManagementServer." value update;
    *) tr069-client - fixed crash on =acs-url change special case;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - fixed write for "Device.ManagementServer.URL";
    *) tr069-client - general improvements on reducing storage space;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - increased performance on GetParameterValues;
    *) tr069-client - set CHR license ID as ".SerialNumber" value to avoid "no serial number" error in ACS;
    *) traceroute - small fix;
    *) usb - added support for more CP210X devices;
    *) userman - allow "name-for-user" to be empty and not unique;
    *) userman - automatically select all newly created users to generate vouchers;
    *) userman - fixed rare crash when User Manager requested file does not exist on router;
    *) userman - fixed rare web interface crash while using Users section;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added "save-selected" setting under CAPsMAN channels;
    *) winbox - added "static-virtual" to wireless CAP;
    *) winbox - added GPS menu;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - apply broadcast bit to DHCP requests when using "station-pseudobridge" mode;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same "master-interface" is used;
    *) wireless - fixed issue when wireless interfaces might not show up in CAP mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare crash on nv2 configurations;
    *) wireless - fixed rare wireless ac interface lockup;
    *) wireless - fixed RBSXT5HacD2nr2 small channel support;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc58 2017-03-24

    What's new in 6.39rc58 (2017-Mar-24 08:47):

    *) certificate - SCEP client now supports FQDN URL and port;
    *) ethernet - added "voltage-too-low" status for single port power injector devices;
    *) ethernet - fixed unnecessary power cycle of powered device when changing any poe-out related setting on single port power injector devices;
    *) ethernet - reversed poe-priority on hEX PoE and OmniTIK 5 PoE to make "poe-priority" consistent to all other RouterOS priorities;
    *) fetch - added "http-data" and "http-method" parameters to allow delete, get, post, put methods (content-type=application/x-www-form-urlencoded by default);
    *) ike2 - fixed CTR mode;
    *) ike2 - remove old SA after rekey;
    *) ipsec - fixed SA authentication flag;
    *) lte - added log entry for SMS delivery report;
    *) ntp - restart NTP client when it is stuck in error state;
    *) smb - fixed different memory leaks and crashes;
    *) smb - fixed share path on devices with "/flash" directory;
    *) userman - fixed rare web interface crash while using Users section;
    *) wireless - fixed false positive DFS radar detection caused by iPhone 6s devices;

    Other changes since 6.38.5:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) bridge - fixed BPDU rx/tx when protocol-mode=none;
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) firewall - discontinued support for p2p matcher (old rules will become invalid);
    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) tile - fixed IPsec hardware acceleration out-of-order packet problem, significantly improved performance;
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) api - fixed double dynamic flags for "/ip firewall address-list print";
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - improved CAP status querying;
    *) capsman - improved support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) console - fixed "/ip neighbor discovery" export;
    *) console - fixed DHCP/PPP add-default-route distance minimal value to 1;
    *) console - fixed crash;
    *) console - fixed incorrect ":put [/lcd get enabled]" value;
    *) defconf - fixed Groove 52 ac band settings;
    *) defconf - fixed default configuration generation when wireless package is disabled;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike1 - fixed ph2 ID logging;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - check child state before allowing rekey;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - send EAP identity as user-name RADIUS attribute;
    *) ike2 - update "calling_station_id" radius attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added "last-seen" parameter to active connection list;
    *) ipsec - allow mixing aead algorithms in proposal;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - show hardware accelerated authenticated SAs;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) l2tp-server - added "use-ipsec=required" option;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added "tr069" topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - make SNMP logs more compact;
    *) lte - added LTE signal level reading for Cinterion modems;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added initialization for Cinterion;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) netinstall - fixed typos;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp-client - added support for Datacard 750UL, DWR-730 and K4607-Zr;
    *) pppoe - set default keepalive 10s for newly created PPPoE clients;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - added partitioning support;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - added fan-speed OIDs in "/system health print oid";
    *) snmp - added optical table;
    *) snmp - fixed rare crash;
    *) snmp - improved getall filter;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tr069-client - added "Device.Hosts.Host.{i}." support;
    *) tr069-client - added "Device.WiFi.NeighboringWiFiDiagnostic." support;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added Upload RPC "2 Vendor Log File" support;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - added connection request authentication;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed "AddObjectResponse" “InstanceNumber” value;
    *) tr069-client - fixed "Device.ManagementServer." value update;
    *) tr069-client - fixed crash on =acs-url change special case;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - fixed write for "Device.ManagementServer.URL";
    *) tr069-client - general improvements on reducing storage space;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - increased performance on GetParameterValues;
    *) tr069-client - set CHR license ID as ".SerialNumber" value to avoid "no serial number" error in ACS;
    *) traceroute - small fix;
    *) usb - added support for more CP210X devices;
    *) userman - allow "name-for-user" to be empty and not unique;
    *) userman - automatically select all newly created users to generate vouchers;
    *) userman - fixed rare crash when User Manager requested file does not exist on router;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added "save-selected" setting under CAPsMAN channels;
    *) winbox - added "static-virtual" to wireless CAP;
    *) winbox - added GPS menu;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - apply broadcast bit to DHCP requests when using "station-pseudobridge" mode;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same "master-interface" is used;
    *) wireless - fixed RBSXT5HacD2nr2 small channel support;
    *) wireless - fixed issue when wireless interfaces might not show up in CAP mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare crash on nv2 configurations;
    *) wireless - fixed rare wireless ac interface lockup;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc55 2017-03-16

    What's new in 6.39rc55 (2017-Mar-16 08:58):

    !) bridge - fixed BPDU rx/tx when protocol-mode=none;
    *) api - fixed double dynamic flags for "/ip firewall address-list print";
    *) console - fixed DHCP/PPP add-default-route distance minimal value to 1;
    *) console - fixed "/ip neighbor discovery" export;
    *) console - fixed crash;
    *) console - fixed incorrect ":put [/lcd get enabled]" value;
    *) userman - automatically select all newly created users to generate vouchers;

    Other changes since 6.38.5:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) firewall - discontinued support for p2p matcher (old rules will become invalid);
    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) tile - fixed IPsec hardware acceleration out-of-order packet problem, significantly improved performance;
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - improved CAP status querying;
    *) capsman - improved support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) defconf - fixed Groove 52 ac band settings;
    *) defconf - fixed default configuration generation when wireless package is disabled;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike1 - fixed ph2 ID logging;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - check child state before allowing rekey;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - send EAP identity as user-name RADIUS attribute;
    *) ike2 - update "calling_station_id" radius attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added "last-seen" parameter to active connection list;
    *) ipsec - allow mixing aead algorithms in proposal;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - show hardware accelerated authenticated SAs;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) l2tp-server - added "use-ipsec=required" option;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added "tr069" topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - make SNMP logs more compact;
    *) lte - added LTE signal level reading for Cinterion modems;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added initialization for Cinterion;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) netinstall - fixed typos;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp-client - added support for Datacard 750UL, DWR-730 and K4607-Zr;
    *) pppoe - set default keepalive 10s for newly created PPPoE clients;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - added partitioning support;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - added fan-speed OIDs in "/system health print oid";
    *) snmp - added optical table;
    *) snmp - fixed rare crash;
    *) snmp - improved getall filter;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tr069-client - added "Device.Hosts.Host.{i}." support;
    *) tr069-client - added "Device.WiFi.NeighboringWiFiDiagnostic." support;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added Upload RPC "2 Vendor Log File" support;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - added connection request authentication;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed "AddObjectResponse" “InstanceNumber” value;
    *) tr069-client - fixed "Device.ManagementServer." value update;
    *) tr069-client - fixed crash on =acs-url change special case;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - fixed write for "Device.ManagementServer.URL";
    *) tr069-client - general improvements on reducing storage space;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - increased performance on GetParameterValues;
    *) tr069-client - set CHR license ID as ".SerialNumber" value to avoid "no serial number" error in ACS;
    *) traceroute - small fix;
    *) usb - added support for more CP210X devices;
    *) userman - allow "name-for-user" to be empty and not unique;
    *) userman - fixed rare crash when User Manager requested file does not exist on router;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added "save-selected" setting under CAPsMAN channels;
    *) winbox - added "static-virtual" to wireless CAP;
    *) winbox - added GPS menu;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - apply broadcast bit to DHCP requests when using "station-pseudobridge" mode;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same "master-interface" is used;
    *) wireless - fixed RBSXT5HacD2nr2 small channel support;
    *) wireless - fixed false positive DFS radar detection caused by iPhone 6s devices;
    *) wireless - fixed issue when wireless interfaces might not show up in CAP mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare crash on nv2 configurations;
    *) wireless - fixed rare wireless ac interface lockup;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc54 2017-03-15

    What's new in 6.39rc54 (2017-Mar-14 14:06):

    *) ike1 - fixed ph2 ID logging;
    *) ipsec - allow mixing aead algorithms in proposal;
    *) ipsec - show hardware accelerated authenticated SAs;
    *) lte - added initialization for Cinterion;
    *) netinstall - fixed typos;
    *) ppp-client - added support for Datacard 750UL, DWR-730 and K4607-Zr;
    *) snmp - added optical table;
    *) snmp - added fan-speed OIDs in "/system health print oid";
    *) snmp - fixed rare crash;
    *) snmp - improved getall filter;
    *) tr069-client - added "Device.WiFi.NeighboringWiFiDiagnostic." support;
    *) tr069-client - added Upload RPC "2 Vendor Log File" support;
    *) tr069-client - fixed "Device.ManagementServer." value update;
    *) tr069-client - fixed crash on =acs-url change special case;
    *) userman - allow "name-for-user" to be empty and not unique;
    *) wireless - fixed false positive DFS radar detection caused by iPhone 6s devices;

    Other changes since 6.38.5:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) firewall - discontinued support for p2p matcher (old rules will become invalid);
    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) tile - fixed IPsec hardware acceleration out-of-order packet problem, significantly improved performance;
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - improved CAP status querying;
    *) capsman - improved support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) defconf - fixed Groove 52 ac band settings;
    *) defconf - fixed default configuration generation when wireless package is disabled;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - check child state before allowing rekey;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - send EAP identity as user-name RADIUS attribute;
    *) ike2 - update "calling_station_id" radius attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added "last-seen" parameter to active connection list;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) l2tp-server - added "use-ipsec=required" option;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added "tr069" topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - make SNMP logs more compact;
    *) lte - added LTE signal level reading for Cinterion modems;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) pppoe - set default keepalive 10s for newly created PPPoE clients;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - added partitioning support;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tr069-client - added "Device.Hosts.Host.{i}." support;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - added connection request authentication;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed "AddObjectResponse" “InstanceNumber” value;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - fixed write for "Device.ManagementServer.URL";
    *) tr069-client - general improvements on reducing storage space;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - increased performance on GetParameterValues;
    *) tr069-client - set CHR license ID as ".SerialNumber" value to avoid "no serial number" error in ACS;
    *) traceroute - small fix;
    *) usb - added support for more CP210X devices;
    *) userman - fixed rare crash when User Manager requested file does not exist on router;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added "save-selected" setting under CAPsMAN channels;
    *) winbox - added "static-virtual" to wireless CAP;
    *) winbox - added GPS menu;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - apply broadcast bit to DHCP requests when using "station-pseudobridge" mode;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same "master-interface" is used;
    *) wireless - fixed RBSXT5HacD2nr2 small channel support;
    *) wireless - fixed issue when wireless interfaces might not show up in CAP mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare crash on nv2 configurations;
    *) wireless - fixed rare wireless ac interface lockup;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc51 2017-03-10

    What's new in 6.39rc51 (2017-Mar-10 12:50):

    !) tile - fixed IPsec hardware acceleration out-of-order packet problem, significantly improved performance;
    *) tr069-client - fixed write for "Device.ManagementServer.URL";

    Other changes since 6.38.5:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) firewall - discontinued support for p2p matcher (old rules will become invalid);
    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - improved CAP status querying;
    *) capsman - improved support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) defconf - fixed Groove 52 ac band settings;
    *) defconf - fixed default configuration generation when wireless package is disabled;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - check child state before allowing rekey;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - send EAP identity as user-name RADIUS attribute;
    *) ike2 - update "calling_station_id" radius attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added "last-seen" parameter to active connection list;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) l2tp-server - added "use-ipsec=required" option;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added "tr069" topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - make SNMP logs more compact;
    *) lte - added LTE signal level reading for Cinterion modems;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp-client - added support for Datacard 750UL and DWR-730;
    *) pppoe - set default keepalive 10s for newly created PPPoE clients;
    *) queue - fixed reboot loop when queues were used (introduced in 6.39rc42);
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - added partitioning support;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tr069-client - added "Device.Hosts.Host.{i}." support;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - added connection request authentication;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed "AddObjectResponse" “InstanceNumber” value;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - general improvements on reducing storage space;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - increased performance on GetParameterValues;
    *) tr069-client - set CHR license ID as ".SerialNumber" value to avoid "no serial number" error in ACS;
    *) traceroute - small fix;
    *) usb - added support for more CP210X devices;
    *) userman - fixed rare crash when User Manager requested file does not exist on router;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added "save-selected" setting under CAPsMAN channels;
    *) winbox - added "static-virtual" to wireless CAP;
    *) winbox - added GPS menu;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - apply broadcast bit to DHCP requests when using "station-pseudobridge" mode;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same "master-interface" is used;
    *) wireless - fixed RBSXT5HacD2nr2 small channel support;
    *) wireless - fixed issue when wireless interfaces might not show up in CAP mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare crash on nv2 configurations;
    *) wireless - fixed rare wireless ac interface lockup;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc49 2017-03-09

    What's new in 6.39rc49 (2017-Mar-09 12:33):

    !) www - fixed http server vulnerability;
    *) capsman - improved CAP status querying;
    *) defconf - fixed default configuration generation when wireless package is disabled;
    *) ike2 - check child state before allowing rekey;
    *) ike2 - send EAP identity as user-name RADIUS attribute;
    *) lte - added LTE signal level reading for Cinterion modems;
    *) queue - fixed reboot loop when queues were used (introduced in 6.39rc42);
    *) rb3011 - added partitioning support;
    *) tr069-client - added "Device.Hosts.Host.{i}." support;
    *) userman - fixed rare crash when User Manager requested file does not exist on router;
    *) wireless - fixed RBSXT5HacD2nr2 small channel support;

    Other changes since 6.38.5:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) firewall - discontinued support for p2p matcher (old rules will become invalid);
    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - improved support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) defconf - fixed Groove 52 ac band settings;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - update "calling_station_id" radius attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added "last-seen" parameter to active connection list;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) l2tp-server - added "use-ipsec=required" option;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added "tr069" topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - make SNMP logs more compact;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp-client - added support for Datacard 750UL and DWR-730;
    *) pppoe - set default keepalive 10s for newly created PPPoE clients;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - added connection request authentication;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed "AddObjectResponse" “InstanceNumber” value;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - general improvements on reducing storage space;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - increased performance on GetParameterValues;
    *) tr069-client - set CHR license ID as ".SerialNumber" value to avoid "no serial number" error in ACS;
    *) traceroute - small fix;
    *) usb - added support for more CP210X devices;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added GPS menu;
    *) winbox - added "save-selected" setting under CAPsMAN channels;
    *) winbox - added "static-virtual" to wireless CAP;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - apply broadcast bit to DHCP requests when using "station-pseudobridge" mode;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same "master-interface" is used;
    *) wireless - fixed issue when wireless interfaces might not show up in CAP mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare crash on nv2 configurations;
    *) wireless - fixed rare wireless ac interface lockup;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc45 2017-03-07

    What's new in 6.39rc45 (2017-Mar-06 14:29):

    !) firewall - discontinued support for p2p matcher (old rules will become invalid);
    *) hotspot - fixed redirect to URL where escape characters are used (requires newly generated HTML files);
    *) l2tp-client - fixed IPSec policy generation after reboot;
    *) l2tp-client - require working IPSec encryption if "use-ipsec=yes";
    *) l2tp-server - added "use-ipsec=required" option;
    *) lcd - show fan2 speed only if it is available;
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - fixed "AddObjectResponse" “InstanceNumber” value;
    *) tr069-client - set CHR license ID as ".SerialNumber" value to avoid "no serial number" error in ACS;

    Other changes since 6.38.3:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - fixed "/caps-man manager interface" compact export;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) chr - fixed problem when transmit speed was reduced by interface queues;
    *) defconf - fixed Groove 52 ac band settings;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dhcpv6-server - require "address-pool" to be specified;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) export - do not show "read-only" IRQ entries;
    *) firewall - do not allow to set "time" parameter to 0s for "limit" option;
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) hotspot - show Host table commentaries also in Active tab and vice versa;
    *) ike1 - added more Radius accounting attributes - "event-timestamp", "acct-session-id", "acct-authentic", "acct-session-time";
    *) ike1 - fixed unnecessary Radius accounting requests;
    *) ike1 - fixed “xauth” Radius login;
    *) ike2 - also kill IKEv2 connections on proposal change;
    *) ike2 - always limit empty remote selector;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed proposal change crash;
    *) ike2 - fixed responder subsequent new child creation when PFS is used;
    *) ike2 - fixed responder TS updating on wild match;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - update calling_station_id radius attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ike2 - update radius attributes;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added last-seen parameter to active connection list;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - deducted policy SA src/dst address from src/dst address;
    *) ipsec - do not require "sa-dst-address" if "action=none" or "action=discard";
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - fixed SA address check in policy lookup;
    *) ipsec - hide sa-addrs for transport policies;
    *) ipsec - keep policy in kernel even with bad proposal;
    *) ipsec - kill ph2 on policy removal;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) irq - properly detect all IRQ entries;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added tr069 topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - make SNMP logs more compact;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp-client - added support for Datacard 750UL and DWR-730;
    *) pppoe - make default keepalive 10s for PPPoE clients;
    *) profile - classify ethernet driver activity properly in ARM architecture;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - added back MAC address OID in "/caps-man registration-table" (introduced in 6.39rc33);
    *) snmp - added SSID to CAPsMAN registration table;
    *) snmp - fixed "/tool snmp-get" crash on session timeout;
    *) snmp - fixed CAPsMAN registration table OID print;
    *) snmp - fixed CAPsMAN registration table SSID type;
    *) snmp - fixed situation when SNMP could not read "/system health" values after reboot;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added connection request authentication;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - fixed “traceroute” parameter IDs;
    *) tr069-client - general improvements on reducing storage space;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - increased performance on GetParameterValues;
    *) traceroute - small fix;
    *) usb - added support for more CP210X devices;
    *) userman - allow access to User Manager users page only through "/user" URL;
    *) userman - show warning when no users are selected for CSV file generation;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added GPS menu;
    *) winbox - added save-selected setting under CAPsMAN channels;
    *) winbox - added static-virtual to wireless CAP;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not hide "power-cycle-after" option;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - hide advertise tab in Hotspot user profile configuration if "transparent-proxy" is not enabled;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - make "power-cycle-interval" not to depend on "power-cycle-ping-enabled" in PoE settings;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - properly show BGP communities in routing filters table filter;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - apply broadcast bit to DHCP requests when using station-pseudobridge mode;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same master interface is used;
    *) wireless - fixed issue when wireless interfaces might not show up in cap mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare crash on nv2 configurations;
    *) wireless - fixed rare wireless ac interface lockup;
    *) wireless - fixed scan tool stuck in background;
    *) wireless - improved compatibility with Intel 2200BG wireless card;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc41 2017-03-03

    What's new in 6.39rc41 (2017-Mar-03 09:35):

    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    *) tr069-client - added basic support for "/ip firewall filters";

    Other changes since 6.38.3:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - fixed "/caps-man manager interface" compact export;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) chr - fixed problem when transmit speed was reduced by interface queues;
    *) defconf - fixed Groove 52 ac band settings;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dhcpv6-server - require "address-pool" to be specified;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) export - do not show "read-only" IRQ entries;
    *) firewall - do not allow to set "time" parameter to 0s for "limit" option;
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) hotspot - show Host table commentaries also in Active tab and vice versa;
    *) ike1 - added more Radius accounting attributes - "event-timestamp", "acct-session-id", "acct-authentic", "acct-session-time";
    *) ike1 - fixed unnecessary Radius accounting requests;
    *) ike1 - fixed “xauth” Radius login;
    *) ike2 - also kill IKEv2 connections on proposal change;
    *) ike2 - always limit empty remote selector;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed proposal change crash;
    *) ike2 - fixed responder subsequent new child creation when PFS is used;
    *) ike2 - fixed responder TS updating on wild match;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - update calling_station_id radius attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ike2 - update radius attributes;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added last-seen parameter to active connection list;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - deducted policy SA src/dst address from src/dst address;
    *) ipsec - do not require "sa-dst-address" if "action=none" or "action=discard";
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - fixed SA address check in policy lookup;
    *) ipsec - hide sa-addrs for transport policies;
    *) ipsec - keep policy in kernel even with bad proposal;
    *) ipsec - kill ph2 on policy removal;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) irq - properly detect all IRQ entries;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added tr069 topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - make SNMP logs more compact;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp-client - added support for Datacard 750UL and DWR-730;
    *) pppoe - make default keepalive 10s for PPPoE clients;
    *) profile - classify ethernet driver activity properly in ARM architecture;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - added back MAC address OID in "/caps-man registration-table" (introduced in 6.39rc33);
    *) snmp - added SSID to CAPsMAN registration table;
    *) snmp - fixed "/tool snmp-get" crash on session timeout;
    *) snmp - fixed CAPsMAN registration table OID print;
    *) snmp - fixed CAPsMAN registration table SSID type;
    *) snmp - fixed situation when SNMP could not read "/system health" values after reboot;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - added connection request authentication;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - fixed “traceroute” parameter IDs;
    *) tr069-client - general improvements on reducing storage space;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - increased performance on GetParameterValues;
    *) traceroute - small fix;
    *) usb - added support for more CP210X devices;
    *) userman - allow access to User Manager users page only through "/user" URL;
    *) userman - show warning when no users are selected for CSV file generation;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added GPS menu;
    *) winbox - added save-selected setting under CAPsMAN channels;
    *) winbox - added static-virtual to wireless CAP;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not hide "power-cycle-after" option;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - hide advertise tab in Hotspot user profile configuration if "transparent-proxy" is not enabled;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - make "power-cycle-interval" not to depend on "power-cycle-ping-enabled" in PoE settings;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - properly show BGP communities in routing filters table filter;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - apply broadcast bit to DHCP requests when using station-pseudobridge mode;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same master interface is used;
    *) wireless - fixed issue when wireless interfaces might not show up in cap mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare crash on nv2 configurations;
    *) wireless - fixed rare wireless ac interface lockup;
    *) wireless - fixed scan tool stuck in background;
    *) wireless - improved compatibility with Intel 2200BG wireless card;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc40 2017-03-03

    What's new in 6.39rc40 (2017-Mar-02 09:11):

    !) l2tp - added fastpath support when MRRU is enabled;
    !) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
    !) pppoe - added fastpath support when MRRU and MLPPP are enabled;
    *) hotspot - show Host table commentaries also in Active tab and vice versa;
    *) ike2 - fixed responder subsequent new child creation when PFS is used;
    *) ipsec - deducted policy SA src/dst address from src/dst address;
    *) ipsec - fixed SA address check in policy lookup;
    *) ipsec - updated tilera classifier for UDP encapsulated ESP;
    *) snmp - added back MAC address OID in "/caps-man registration-table" (introduced in 6.39rc33);
    *) tr069-client - added basic support for "/ip firewall filters";
    *) tr069-client - added support for escaped entity references (& < > ' ");
    *) tr069-client - close connection if CPE considers XML as invalid;
    *) tr069-client - fixed special escape characters on XML data send;
    *) tr069-client - general improvements on reducing storage space;
    *) usb - added support for more CP210X devices;
    *) wireless - do not allow equal MAC addresses between multiple Virtual APs when same master interface is used;
    *) wireless - fixed rare crash on nv2 configurations;

    Other changes since 6.38.3:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - fixed "/caps-man manager interface" compact export;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) chr - fixed problem when transmit speed was reduced by interface queues;
    *) defconf - fixed Groove 52 ac band settings;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dhcpv6-server - require "address-pool" to be specified;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) export - do not show "read-only" IRQ entries;
    *) firewall - do not allow to set "time" parameter to 0s for "limit" option;
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike1 - added more Radius accounting attributes - "event-timestamp", "acct-session-id", "acct-authentic", "acct-session-time";
    *) ike1 - fixed unnecessary Radius accounting requests;
    *) ike1 - fixed “xauth” Radius login;
    *) ike2 - also kill IKEv2 connections on proposal change;
    *) ike2 - always limit empty remote selector;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed proposal change crash;
    *) ike2 - fixed responder TS updating on wild match;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - update calling_station_id radius attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ike2 - update radius attributes;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added last-seen parameter to active connection list;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - do not require "sa-dst-address" if "action=none" or "action=discard";
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - hide sa-addrs for transport policies;
    *) ipsec - keep policy in kernel even with bad proposal;
    *) ipsec - kill ph2 on policy removal;
    *) irq - properly detect all IRQ entries;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added tr069 topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - make SNMP logs more compact;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp-client - added support for Datacard 750UL and DWR-730;
    *) pppoe - make default keepalive 10s for PPPoE clients;
    *) profile - classify ethernet driver activity properly in ARM architecture;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - added SSID to CAPsMAN registration table;
    *) snmp - fixed "/tool snmp-get" crash on session timeout;
    *) snmp - fixed CAPsMAN registration table OID print;
    *) snmp - fixed CAPsMAN registration table SSID type;
    *) snmp - fixed situation when SNMP could not read "/system health" values after reboot;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added connection request authentication;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - fixed “traceroute” parameter IDs;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - increased performance on GetParameterValues;
    *) traceroute - small fix;
    *) userman - allow access to User Manager users page only through "/user" URL;
    *) userman - show warning when no users are selected for CSV file generation;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added GPS menu;
    *) winbox - added save-selected setting under CAPsMAN channels;
    *) winbox - added static-virtual to wireless CAP;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not hide "power-cycle-after" option;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - hide advertise tab in Hotspot user profile configuration if "transparent-proxy" is not enabled;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - make "power-cycle-interval" not to depend on "power-cycle-ping-enabled" in PoE settings;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - properly show BGP communities in routing filters table filter;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - apply broadcast bit to DHCP requests when using station-pseudobridge mode;
    *) wireless - fixed issue when wireless interfaces might not show up in cap mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare wireless ac interface lockup;
    *) wireless - fixed scan tool stuck in background;
    *) wireless - improved compatibility with Intel 2200BG wireless card;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc38 2017-02-24

    What's new in 6.39rc38 (2017-Feb-24 08:46):

    !) routeros - added support for new products and RouterOS features which will be announced at MUM EU (https://mum.mikrotik.com/2017/EU/info/EN);
    *) capsman - fixed "/caps-man manager interface" compact export;

    Other changes since 6.38.1:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) chr - fixed problem when transmit speed was reduced by interface queues;
    *) defconf - fixed Groove 52 ac band settings;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dhcpv6-server - require "address-pool" to be specified;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) export - do not show "read-only" IRQ entries;
    *) firewall - do not allow to set "time" parameter to 0s for "limit" option;
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike1 - added more Radius accounting attributes - "event-timestamp", "acct-session-id", "acct-authentic", "acct-session-time";
    *) ike1 - fixed unnecessary Radius accounting requests;
    *) ike1 - fixed “xauth” Radius login;
    *) ike2 - also kill IKEv2 connections on proposal change;
    *) ike2 - always limit empty remote selector;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed proposal change crash;
    *) ike2 - fixed responder TS updating on wild match;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - update calling_station_id radius attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ike2 - update radius attributes;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added last-seen parameter to active connection list;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - do not require "sa-dst-address" if "action=none" or "action=discard";
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - hide sa-addrs for transport policies;
    *) ipsec - keep policy in kernel even with bad proposal;
    *) ipsec - kill ph2 on policy removal;
    *) irq - properly detect all IRQ entries;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added tr069 topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - make SNMP logs more compact;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp-client - added support for Datacard 750UL and DWR-730;
    *) pppoe - make default keepalive 10s for PPPoE clients;
    *) profile - classify ethernet driver activity properly in ARM architecture;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - added SSID to CAPsMAN registration table;
    *) snmp - fixed "/tool snmp-get" crash on session timeout;
    *) snmp - fixed CAPsMAN registration table OID print;
    *) snmp - fixed CAPsMAN registration table SSID type;
    *) snmp - fixed situation when SNMP could not read "/system health" values after reboot;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) snmp - optimized bridge table processing;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added connection request authentication;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - fixed “traceroute” parameter IDs;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - increased performance on GetParameterValues;
    *) traceroute - small fix;
    *) userman - allow access to User Manager users page only through "/user" URL;
    *) userman - show warning when no users are selected for CSV file generation;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added GPS menu;
    *) winbox - added save-selected setting under CAPsMAN channels;
    *) winbox - added static-virtual to wireless CAP;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not hide "power-cycle-after" option;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - hide advertise tab in Hotspot user profile configuration if "transparent-proxy" is not enabled;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - make "power-cycle-interval" not to depend on "power-cycle-ping-enabled" in PoE settings;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - properly show BGP communities in routing filters table filter;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - apply broadcast bit to DHCP requests when using station-pseudobridge mode;
    *) wireless - fixed issue when wireless interfaces might not show up in cap mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare wireless ac interface lockup;
    *) wireless - fixed scan tool stuck in background;
    *) wireless - improved compatibility with Intel 2200BG wireless card;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc35 2017-02-22

    What's new in 6.39rc35 (2017-Feb-22 13:27):

    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) snmp - fixed CAPsMAN registration table OID print;
    *) snmp - fixed CAPsMAN registration table SSID type;
    *) snmp - optimized bridge table processing;
    *) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
    *) userman - allow access to User Manager users page only through "/user" URL;

    Other changes since 6.38.1:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.11;
    *) address - fixed crash when address is assigned to another bridge port;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) chr - fixed problem when transmit speed was reduced by interface queues;
    *) defconf - fixed Groove 52 ac band settings;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dhcpv6-server - require "address-pool" to be specified;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) export - do not show "read-only" IRQ entries;
    *) firewall - do not allow to set "time" parameter to 0s for "limit" option;
    *) graphing - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike1 - added more Radius accounting attributes - "event-timestamp", "acct-session-id", "acct-authentic", "acct-session-time";
    *) ike1 - fixed unnecessary Radius accounting requests;
    *) ike1 - fixed “xauth” Radius login;
    *) ike2 - also kill IKEv2 connections on proposal change;
    *) ike2 - always limit empty remote selector;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed proposal change crash;
    *) ike2 - fixed responder TS updating on wild match;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - update calling_station_id radius attribute;
    *) ike2 - update peer identity after successful EAP authentication;
    *) ike2 - update radius attributes;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added last-seen parameter to active connection list;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - do not require "sa-dst-address" if "action=none" or "action=discard";
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - hide sa-addrs for transport policies;
    *) ipsec - keep policy in kernel even with bad proposal;
    *) ipsec - kill ph2 on policy removal;
    *) irq - properly detect all IRQ entries;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added "gps" topic;
    *) log - added tr069 topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - make SNMP logs more compact;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - buffer AT events while info command is active;
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) ppp-client - added support for Datacard 750UL and DWR-730;
    *) pppoe - make default keepalive 10s for PPPoE clients;
    *) profile - classify ethernet driver activity properly in ARM architecture;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - added SSID to CAPsMAN registration table;
    *) snmp - fixed "/tool snmp-get" crash on session timeout;
    *) snmp - fixed situation when SNMP could not read "/system health" values after reboot;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added connection request authentication;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - fixed “traceroute” parameter IDs;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - increased performance on GetParameterValues;
    *) traceroute - small fix;
    *) userman - show warning when no users are selected for CSV file generation;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added GPS menu;
    *) winbox - added save-selected setting under CAPsMAN channels;
    *) winbox - added static-virtual to wireless CAP;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not hide "power-cycle-after" option;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - hide advertise tab in Hotspot user profile configuration if "transparent-proxy" is not enabled;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - make "power-cycle-interval" not to depend on "power-cycle-ping-enabled" in PoE settings;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - properly show BGP communities in routing filters table filter;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - apply broadcast bit to DHCP requests when using station-pseudobridge mode;
    *) wireless - fixed issue when wireless interfaces might not show up in cap mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare wireless ac interface lockup;
    *) wireless - fixed scan tool stuck in background;
    *) wireless - improved compatibility with Intel 2200BG wireless card;
    *) x86 - added support for NVMe SSD disk drives;

  • Release 6.39rc33 2017-02-17

    What's new in 6.39rc33 (2017-Feb-17 10:05):

    !) winbox - minimal required version is v3.11;
    *) capsman - added support for static virtual interfaces on CAP;
    *) chr - fixed problem when transmit speed was reduced by interface queues;
    *) defconf - fixed Groove 52 ac band settings;
    *) dhcp-client - added "script" option which executes script on state changes;
    *) dhcpv4-server - added "lease-hostname" script parameter;
    *) dhcpv6-server - require "address-pool" to be specified;
    *) export - do not show "read-only" IRQ entries;
    *) gps - added "fix-quality" and "horizontal-dilution" parameters;
    *) ike1 - fixed unnecessary Radius accounting requests;
    *) ike1 - fixed “xauth” Radius login;
    *) ike2 - update peer identity after successful EAP authentication;
    *) irq - properly detect all IRQ entries;
    *) log - added "gps" topic;
    *) log - make SNMP logs more compact;
    *) lte - buffer AT events while info command is active;
    *) ppp-client - added support for Datacard 750UL and DWR-730;
    *) snmp - "No Such Instance" error message is replaced with "No Such Object";
    *) snmp - fixed "/tool snmp-get" crash on session timeout;
    *) snmp - fixed CAPsMAN registration table OID print;
    *) snmp - fixed situation when SNMP could not read "/system health" values after reboot;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) tile - added initial support for NVMe SSD disk drives;
    *) tr069-client - fixed “traceroute” parameter IDs;
    *) userman - show warning when no users are selected for CSV file generation;
    *) winbox - added GPS menu;
    *) winbox - allow to not specify certificate in IPSec peer settings;
    *) winbox - allow unhide SNMP passwords;
    *) winbox - do not hide "power-cycle-after" option;
    *) winbox - do not show empty LTE fields in Info menu;
    *) winbox - hide advertise tab in Hotspot user profile configuration if "transparent-proxy" is not enabled;
    *) winbox - properly name CAP Interface on new interface creation;
    *) winbox - properly show BGP communities in routing filters table filter;
    *) wireless - added Egypt 5.8 country settings;
    *) wireless - fixed scan tool stuck in background;
    *) wireless - improved compatibility with Intel 2200BG wireless card;
    *) x86 - added support for NVMe SSD disk drives;

    Other changes since 6.38.1:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    *) address - fixed crash when address is assigned to another bridge port;
    *) bridge - do not add dynamic hardware STP ports if master port isn't capable of hardware STP;
    *) bridge - fixed rare crash when hardware STP capable interface gets new “master-port” which already is in bridge;
    *) bridge - fixed rare situation when port flapping occurs on bridge ports;
    *) bridge - fixed STP/RSTP packet receive on all types of bridge ports;
    *) bridge - minor improvements in performance when "master-port" is bridge port;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - fixed SGI (Short Guard Interval) support;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) dhcp - do not listen on IPv4/IPv6 client to IPv6 MLD packets;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) firewall - added "fasttrack" dummy rule to "/ip firewall raw" table;
    *) firewall - do not allow to set "time" parameter to 0s for "limit" option;
    *) firewall - do not show ipv4 fastpath as active if route cache is disabled;
    *) firewall - fixed import of exported configuration that had updated "limit" setting;
    *) graphing - fixed graphing crash when high amount of traffic is processed;
    *) graphs - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) hotspot - fixed rare kernel crash on multicore systems;
    *) ike1 - added more Radius accounting attributes - "event-timestamp", "acct-session-id", "acct-authentic", "acct-session-time";
    *) ike1 - fixed responder xauth trailing null;
    *) ike2 - also kill IKEv2 connections on proposal change;
    *) ike2 - always limit empty remote selector;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed proposal change crash;
    *) ike2 - fixed responder TS updating on wild match;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - update calling_station_id radius attribute;
    *) ike2 - update radius attributes;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added last-seen parameter to active connection list;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - do not require "sa-dst-address" if "action=none" or "action=discard";
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - hide sa-addrs for transport policies;
    *) ipsec - keep policy in kernel even with bad proposal;
    *) ipsec - kill ph2 on policy removal;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - fixed defaults for RBSXT5HacD2nr2;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added tr069 topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - fixed "/interface lte info X once";
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) mmips - improved general stability;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) pppoe - make default keepalive 10s for PPPoE clients;
    *) profile - classify ethernet driver activity properly in ARM architecture;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - fixed noise from buzzer after silent boot;
    *) snmp - added SSID to CAPsMAN registration table;
    *) switch - fixed crash when trying to configure second master port on the same chipset (RB3011, RB2011, CCR1009-8G-1S+);
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added connection request authentication;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - increased performance on GetParameterValues;
    *) traceroute - small fix;
    *) usb - added missing USB ethernet drivers to arm & tile architecture;
    *) userman - allow access to User Manager users page only through "/user" URL;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - improved field layout;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "add-relay-info" and "relay-info-remote-id" to DHCP relay;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added H flag to "/ip arp" ;
    *) winbox - added missing "use-fan2" and "active-fan2" to "/system health";
    *) winbox - added save-selected setting under CAPsMAN channels;
    *) winbox - added static-virtual to wireless CAP;
    *) winbox - allow shorten bytes to k,M,G in bridge firewall just like in “/ip firewall”;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not hide 00:00:00:00:00:00 MAC address in unpublished ARPs;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed matching "connection-state=untracked" connections;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - fixed typo in “/system resources pci” list;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - make "power-cycle-after" show correct value;
    *) winbox - make "power-cycle-interval" not to depend on "power-cycle-ping-enabled" in PoE settings;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - updated fan management menu;
    *) wireless - added "station-roaming" setting;
    *) wireless - apply broadcast bit to DHCP requests when using station-pseudobridge mode;
    *) wireless - fixed issue when wireless interfaces might not show up in cap mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare wireless ac interface lockup;
    *) wireless - update Thailand country frequency settings;

  • Release 6.39rc27 2017-02-09

    What's new in 6.39rc27 (2017-Feb-09 08:45):

    *) dhcp-client - added "script" option which executes script on state changes (CLI only);
    *) firewall - do not allow to set "time" parameter to 0s for "limit" option;
    *) ike2 - always replace empty TSi with configured address if it is available;
    *) ipsec - fixed "/ip ipsec policy group export verbose";
    *) lte - fixed "/interface lte info X once";
    *) ppp-client - added support for Datacard 750UL and DWR-730;
    *) snmp - added SSID to CAPsMAN registration table;
    *) snmp - improved response speed when multiple requests are received within short period of time;
    *) userman - allow access to User Manager users page only through "/user" URL;
    *) webfig - improved field layout;

    Other changes since 6.38.1:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.8 (because of new quickset);
    *) address - fixed crash when address is assigned to another bridge port;
    *) bridge - do not add dynamic hardware STP ports if master port isn't capable of hardware STP;
    *) bridge - fixed rare crash when hardware STP capable interface gets new “master-port” which already is in bridge;
    *) bridge - fixed rare situation when port flapping occurs on bridge ports;
    *) bridge - fixed STP/RSTP packet receive on all types of bridge ports;
    *) bridge - minor improvements in performance when "master-port" is bridge port;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - fixed SGI (Short Guard Interval) support;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) dhcp - do not listen on IPv4/IPv6 client to IPv6 MLD packets;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) email - check for errors during SMTP exchange process;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) firewall - added "fasttrack" dummy rule to "/ip firewall raw" table;
    *) firewall - do not show ipv4 fastpath as active if route cache is disabled;
    *) firewall - fixed import of exported configuration that had updated "limit" setting;
    *) graphing - fixed graphing crash when high amount of traffic is processed;
    *) graphs - fixed graph disappearance after power outage;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) hotspot - fixed rare kernel crash on multicore systems;
    *) ike1 - added more Radius accounting attributes - "event-timestamp", "acct-session-id", "acct-authentic", "acct-session-time";
    *) ike1 - fixed responder xauth trailing null;
    *) ike2 - also kill IKEv2 connections on proposal change;
    *) ike2 - always limit empty remote selector;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed proposal change crash;
    *) ike2 - fixed responder TS updating on wild match;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - update calling_station_id radius attribute;
    *) ike2 - update radius attributes;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added last-seen parameter to active connection list;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - do not require "sa-dst-address" if "action=none" or "action=discard";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) ipsec - hide sa-addrs for transport policies;
    *) ipsec - keep policy in kernel even with bad proposal;
    *) ipsec - kill ph2 on policy removal;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - fixed defaults for RBSXT5HacD2nr2;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added tr069 topic;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) mmips - improved general stability;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) pppoe - make default keepalive 10s for PPPoE clients;
    *) profile - classify ethernet driver activity properly in ARM architecture;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - fixed noise from buzzer after silent boot;
    *) switch - fixed crash when trying to configure second master port on the same chipset (RB3011, RB2011, CCR1009-8G-1S+);
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added connection request authentication;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - added traceroute diagnostics support;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - increased performance on GetParameterValues;
    *) traceroute - small fix;
    *) usb - added missing USB ethernet drivers to arm & tile architecture;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "add-relay-info" and "relay-info-remote-id" to DHCP relay;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added H flag to "/ip arp" ;
    *) winbox - added missing "use-fan2" and "active-fan2" to "/system health";
    *) winbox - added save-selected setting under CAPsMAN channels;
    *) winbox - added static-virtual to wireless CAP;
    *) winbox - allow shorten bytes to k,M,G in bridge firewall just like in “/ip firewall”;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not hide 00:00:00:00:00:00 MAC address in unpublished ARPs;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed matching "connection-state=untracked" connections;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - fixed typo in “/system resources pci” list;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - make "power-cycle-after" show correct value;
    *) winbox - make "power-cycle-interval" not to depend on "power-cycle-ping-enabled" in PoE settings;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - updated fan management menu;
    *) wireless - added "station-roaming" setting;
    *) wireless - apply broadcast bit to DHCP requests when using station-pseudobridge mode;
    *) wireless - fixed issue when wireless interfaces might not show up in cap mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare wireless ac interface lockup;
    *) wireless - update Thailand country frequency settings;

  • Release 6.39rc26 2017-02-09

    What's new in 6.39rc26 (2017-Feb-06 11:24):

    *) dhcp - do not listen on IPv4/IPv6 client to IPv6 MLD packets;
    *) email - check for errors during SMTP exchange process;
    *) hotspot - added access to HTTP headers using $(http-header-name);
    *) ike1 - added more Radius accounting attributes - "event-timestamp", "acct-session-id", "acct-authentic", "acct-session-time";
    *) ipsec - do not require "sa-dst-address" if "action=none" or "action=discard";
    *) ipsec - fixed "mode-cfg" verbose export;
    *) log - added tr069 topic;
    *) tr069-client - added traceroute diagnostics support;

    Other changes since 6.38.1:

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.8 (because of new quickset);
    *) address - fixed crash when address is assigned to another bridge port;
    *) bridge - do not add dynamic hardware STP ports if master port isn't capable of hardware STP;
    *) bridge - fixed rare crash when hardware STP capable interface gets new “master-port” which already is in bridge;
    *) bridge - fixed rare situation when port flapping occurs on bridge ports;
    *) bridge - fixed STP/RSTP packet receive on all types of bridge ports;
    *) bridge - minor improvements in performance when "master-port" is bridge port;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - fixed SGI (Short Guard Interval) support;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) firewall - added "fasttrack" dummy rule to "/ip firewall raw" table;
    *) firewall - do not show ipv4 fastpath as active if route cache is disabled;
    *) firewall - fixed import of exported configuration that had updated "limit" setting;
    *) graphing - fixed graphing crash when high amount of traffic is processed;
    *) graphs - fixed graph disappearance after power outage;
    *) hotspot - fixed rare kernel crash on multicore systems;
    *) ike1 - fixed responder xauth trailing null;
    *) ike2 - also kill IKEv2 connections on proposal change;
    *) ike2 - always limit empty remote selector;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed proposal change crash;
    *) ike2 - fixed responder TS updating on wild match;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - update calling_station_id radius attribute;
    *) ike2 - update radius attributes;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added last-seen parameter to active connection list;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - hide sa-addrs for transport policies;
    *) ipsec - keep policy in kernel even with bad proposal;
    *) ipsec - kill ph2 on policy removal;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - fixed defaults for RBSXT5HacD2nr2;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) mmips - improved general stability;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) pppoe - make default keepalive 10s for PPPoE clients;
    *) profile - classify ethernet driver activity properly in ARM architecture;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - fixed noise from buzzer after silent boot;
    *) switch - fixed crash when trying to configure second master port on the same chipset (RB3011, RB2011, CCR1009-8G-1S+);
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added connection request authentication;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - generate random connection request target path;
    *) tr069-client - increased performance on GetParameterValues;
    *) traceroute - small fix;
    *) usb - added missing USB ethernet drivers to arm & tile architecture;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed delays on key press in terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "add-relay-info" and "relay-info-remote-id" to DHCP relay;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added H flag to "/ip arp" ;
    *) winbox - added missing "use-fan2" and "active-fan2" to "/system health";
    *) winbox - added save-selected setting under CAPsMAN channels;
    *) winbox - added static-virtual to wireless CAP;
    *) winbox - allow shorten bytes to k,M,G in bridge firewall just like in “/ip firewall”;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not hide 00:00:00:00:00:00 MAC address in unpublished ARPs;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed matching "connection-state=untracked" connections;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - fixed typo in “/system resources pci” list;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - make "power-cycle-after" show correct value;
    *) winbox - make "power-cycle-interval" not to depend on "power-cycle-ping-enabled" in PoE settings;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - updated fan management menu;
    *) wireless - added "station-roaming" setting;
    *) wireless - apply broadcast bit to DHCP requests when using station-pseudobridge mode;
    *) wireless - fixed issue when wireless interfaces might not show up in cap mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare wireless ac interface lockup;
    *) wireless - update Thailand country frequency settings;

  • Release 6.39rc25 2017-02-02

    What's new in 6.39rc25 (2017-Feb-01 14:10):

    !) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
    !) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
    *) address - fixed crash when address is assigned to another bridge port;
    *) bridge - fixed rare crash when hardware STP capable interface gets new “master-port” which already is in bridge;
    *) bridge - fixed rare situation when port flapping occurs on bridge ports;
    *) bridge - minor improvements in performance when "master-port" is bridge port;
    *) graphing - fixed graphing crash when high amount of traffic is processed;
    *) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
    *) tr069-client - added ping diagnostics support;
    *) tr069-client - increased performance on GetParameterValues;
    *) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - fixed delays on key press in terminal;
    *) winbox - added missing "use-fan2" and "active-fan2" to "/system health";

    Other changes since 6.38.1:

    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.8 (because of new quickset);
    *) bridge - do not add dynamic hardware STP ports if master port isn't capable of hardware STP;
    *) bridge - fixed STP/RSTP packet receive on all types of bridge ports;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - fixed SGI (Short Guard Interval) support;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) firewall - added "fasttrack" dummy rule to "/ip firewall raw" table;
    *) firewall - do not show ipv4 fastpath as active if route cache is disabled;
    *) firewall - fixed import of exported configuration that had updated "limit" setting;
    *) graphs - fixed graph disappearance after power outage;
    *) hotspot - fixed rare kernel crash on multicore systems;
    *) ike1 - fixed responder xauth trailing null;
    *) ike2 - also kill IKEv2 connections on proposal change;
    *) ike2 - always limit empty remote selector;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed proposal change crash;
    *) ike2 - fixed responder TS updating on wild match;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - update calling_station_id radius attribute;
    *) ike2 - update radius attributes;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added last-seen parameter to active connection list;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - hide sa-addrs for transport policies;
    *) ipsec - keep policy in kernel even with bad proposal;
    *) ipsec - kill ph2 on policy removal;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - fixed defaults for RBSXT5HacD2nr2;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) mmips - improved general stability;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) pppoe - make default keepalive 10s for PPPoE clients;
    *) profile - classify ethernet driver activity properly in ARM architecture;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) rb3011 - fixed noise from buzzer after silent boot;
    *) switch - fixed crash when trying to configure second master port on the same chipset (RB3011, RB2011, CCR1009-8G-1S+);
    *) tr069-client - added basic stats parameters for some interface types;
    *) tr069-client - added connection request authentication;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - generate random connection request target path;
    *) traceroute - small fix;
    *) usb - added missing USB ethernet drivers to arm & tile architecture;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added "add-relay-info" and "relay-info-remote-id" to DHCP relay;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added H flag to "/ip arp" ;
    *) winbox - added save-selected setting under CAPsMAN channels;
    *) winbox - added static-virtual to wireless CAP;
    *) winbox - allow shorten bytes to k,M,G in bridge firewall just like in “/ip firewall”;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not hide 00:00:00:00:00:00 MAC address in unpublished ARPs;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed matching "connection-state=untracked" connections;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - fixed typo in “/system resources pci” list;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - make "power-cycle-after" show correct value;
    *) winbox - make "power-cycle-interval" not to depend on "power-cycle-ping-enabled" in PoE settings;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - updated fan management menu;
    *) wireless - added "station-roaming" setting;
    *) wireless - apply broadcast bit to DHCP requests when using station-pseudobridge mode;
    *) wireless - fixed issue when wireless interfaces might not show up in cap mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare wireless ac interface lockup;
    *) wireless - update Thailand country frequency settings;

  • Release 6.39rc20 2017-01-27

    What's new in 6.39rc20 (2017-Jan-27 08:53):

    !) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
    !) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
    *) rb3011 - fixed noise from buzzer after silent boot;
    *) tr069-client - added basic stats parameters for some interface types;
    *) usb - added missing USB ethernet drivers to arm & tile architecture;
    *) webfig - added menubar to quickly select between Webfig, Quickset and Terminal;
    *) webfig - fixed tab ordering on Google Chrome;
    *) webfig - make Terminal window work within Webfig window;
    *) winbox - added H flag to "/ip arp" ;
    *) winbox - added missing "use-fan2" and "active-fan2" to "/system health";
    *) winbox - added save-selected setting under CAPsMAN channels;
    *) winbox - added static-virtual to wireless CAP;
    *) winbox - do not hide 00:00:00:00:00:00 MAC address in unpublished ARPs;
    *) winbox - fixed matching "connection-state=untracked" connections;
    *) winbox - fixed misleading error when trying to export certificate;
    *) winbox - increased maximal number of Winbox sessions 20->100;
    *) winbox - make "power-cycle-after" show correct value;
    *) winbox - make "power-cycle-interval" not to depend on "power-cycle-ping-enabled" in PoE settings;

    Other changes since 6.38.1:

    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.8 (because of new quickset);
    *) bridge - do not add dynamic hardware STP ports if master port isn't capable of hardware STP;
    *) bridge - fixed STP/RSTP packet receive on all types of bridge ports;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - fixed SGI (Short Guard Interval) support;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) firewall - added "fasttrack" dummy rule to "/ip firewall raw" table;
    *) firewall - do not show ipv4 fastpath as active if route cache is disabled;
    *) firewall - fixed import of exported configuration that had updated "limit" setting;
    *) graphs - fixed graph disappearance after power outage;
    *) hotspot - fixed rare kernel crash on multicore systems;
    *) ike1 - fixed responder xauth trailing null;
    *) ike2 - also kill IKEv2 connections on proposal change;
    *) ike2 - always limit empty remote selector;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed proposal change crash;
    *) ike2 - fixed responder TS updating on wild match;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - update calling_station_id radius attribute;
    *) ike2 - update radius attributes;
    *) ippool - return proper error message when trying to create duplicate name;
    *) ipsec - added last-seen parameter to active connection list;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - hide sa-addrs for transport policies;
    *) ipsec - keep policy in kernel even with bad proposal;
    *) ipsec - kill ph2 on policy removal;
    *) leds - added LTE modem access technology trigger;
    *) leds - changed error message on unsupported board;
    *) leds - do not update single LED state when it is not changed;
    *) leds - fixed defaults for RBSXT5HacD2nr2;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) lte - fixed user-command;
    *) mmips - improved general stability;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) pppoe - make default keepalive 10s for PPPoE clients;
    *) profile - classify ethernet driver activity properly in ARM architecture;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) switch - fixed crash when trying to configure second master port on the same chipset (RB3011, RB2011, CCR1009-8G-1S+);
    *) tr069-client - added DHCP server support;
    *) tr069-client - added connection request authentication;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;
    *) tr069-client - generate random connection request target path;
    *) traceroute - small fix;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - added "add-relay-info" and "relay-info-remote-id" to DHCP relay;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - allow shorten bytes to k,M,G in bridge firewall just like in “/ip firewall”;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed typo in “/system resources pci” list;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - updated fan management menu;
    *) wireless - added "station-roaming" setting;
    *) wireless - apply broadcast bit to DHCP requests when using station-pseudobridge mode;
    *) wireless - fixed issue when wireless interfaces might not show up in cap mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare wireless ac interface lockup;
    *) wireless - update Thailand country frequency settings;

  • Release 6.39rc19 2017-01-25

    What's new in 6.39rc19 (2017-Jan-25 10:37):

    *) bridge - fixed STP/RSTP packet receive on all types of bridge ports;
    *) ike2 - fixed ISA handler object removal on SA delete;
    *) ippool - return proper error message when trying to create duplicate name;
    *) leds - changed error message on unsupported board;
    *) lte - fixed network mode selection for me909u, mu609;
    *) lte - fixed user-command;
    *) tr069-client - added DHCP server support;
    *) tr069-client - added support for managing "/system/identity/" value;
    *) tr069-client - added support for memory and CPU load parameters;

    Other changes since 6.38.1:

    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.8 (because of new quickset);
    *) bridge - do not add dynamic hardware STP ports if master port isn't capable of hardware STP;
    *) capsman - added CAP discovery interface list support;
    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) capsman - fixed SGI (Short Guard Interval) support;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) firewall - added "fasttrack" dummy rule to "/ip firewall raw" table;
    *) firewall - do not show ipv4 fastpath as active if route cache is disabled;
    *) firewall - fixed import of exported configuration that had updated "limit" setting;
    *) graphs - fixed graph disappearance after power outage;
    *) hotspot - fixed rare kernel crash on multicore systems;
    *) ike1 - fixed responder xauth trailing null;
    *) ike2 - also kill IKEv2 connections on proposal change;
    *) ike2 - always limit empty remote selector;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed proposal change crash;
    *) ike2 - fixed responder TS updating on wild match;
    *) ike2 - fixed state when sending delete packet;
    *) ike2 - update calling_station_id radius attribute;
    *) ike2 - update radius attributes;
    *) ipsec - added last-seen parameter to active connection list;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - hide sa-addrs for transport policies;
    *) ipsec - keep policy in kernel even with bad proposal;
    *) ipsec - kill ph2 on policy removal;
    *) leds - added LTE modem access technology trigger;
    *) leds - do not update single LED state when it is not changed;
    *) leds - fixed defaults for RBSXT5HacD2nr2;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) mmips - improved general stability;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) pppoe - make default keepalive 10s for PPPoE clients;
    *) profile - classify ethernet driver activity properly in ARM architecture;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) switch - fixed crash when trying to configure second master port on the same chipset (RB3011, RB2011, CCR1009-8G-1S+);
    *) tr069-client - added connection request authentication;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - generate random connection request target path;
    *) traceroute - small fix;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - added "add-relay-info" and "relay-info-remote-id" to DHCP relay;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - allow shorten bytes to k,M,G in bridge firewall just like in “/ip firewall”;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed typo in “/system resources pci” list;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - updated fan management menu;
    *) wireless - added "station-roaming" setting;
    *) wireless - apply broadcast bit to DHCP requests when using station-pseudobridge mode;
    *) wireless - fixed issue when wireless interfaces might not show up in cap mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare wireless ac interface lockup;
    *) wireless - update Thailand country frequency settings;

  • Release 6.39rc17 2017-01-23

    What's new in 6.39rc17 (2017-Jan-23 16:30):

    *) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
    *) capsman - added support for static virtual interfaces on CAP;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) hotspot - fixed rare kernel crash on multicore systems;
    *) ike2 - default to /32 peer address mask;
    *) ike2 - fixed EAP message length;
    *) ike2 - update calling_station_id radius attribute;
    *) ike2 - update radius attributes;
    *) ipsec - better responder flag calculator for console;
    *) ipsec - hide sa-addrs for transport policies;
    *) wireless - apply broadcast bit to DHCP requests when using station-pseudobridge mode;
    *) wireless - update Thailand country frequency settings;

    Other changes since 6.38.1:

    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.8 (because of new quickset);
    *) bridge - do not add dynamic hardware STP ports if master port isn't capable of hardware STP;
    *) capsman - added CAP discovery interface list support;
    *) capsman - fixed SGI (Short Guard Interval) support;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) firewall - added "fasttrack" dummy rule to "/ip firewall raw" table;
    *) firewall - do not show ipv4 fastpath as active if route cache is disabled;
    *) firewall - fixed import of exported configuration that had updated "limit" setting;
    *) graphs - fixed graph disappearance after power outage;
    *) ike1 - fixed responder xauth trailing null;
    *) ike2 - also kill IKEv2 connections on proposal change;
    *) ike2 - always limit empty remote selector;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed proposal change crash;
    *) ike2 - fixed responder TS updating on wild match;
    *) ike2 - fixed state when sending delete packet;
    *) ipsec - added last-seen parameter to active connection list;
    *) ipsec - keep policy in kernel even with bad proposal;
    *) ipsec - kill ph2 on policy removal;
    *) leds - added LTE modem access technology trigger;
    *) leds - do not update single LED state when it is not changed;
    *) leds - fixed defaults for RBSXT5HacD2nr2;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) lte - added error handling for remote AT execute;
    *) lte - added initial support for Quectel ec25;
    *) lte - added support for Vodafone R216 (Huawei);
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) mmips - improved general stability;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) pppoe - make default keepalive 10s for PPPoE clients;
    *) profile - classify ethernet driver activity properly in ARM architecture;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) switch - fixed crash when trying to configure second master port on the same chipset (RB3011, RB2011, CCR1009-8G-1S+);
    *) tr069-client - added connection request authentication;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - generate random connection request target path;
    *) traceroute - small fix;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - added "add-relay-info" and "relay-info-remote-id" to DHCP relay;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - allow shorten bytes to k,M,G in bridge firewall just like in “/ip firewall”;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed typo in “/system resources pci” list;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - updated fan management menu;
    *) wireless - added "station-roaming" setting;
    *) wireless - fixed issue when wireless interfaces might not show up in cap mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare wireless ac interface lockup;

  • Release 6.39rc15 2017-01-20

    What's new in 6.39rc15 (2017-Jan-18 13:24):

    *) bridge - do not add dynamic hardware STP ports if master port isn't capable of hardware STP;
    *) dhcpv4-server - do some lease checks only on enabled object;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) firewall - do not show ipv4 fastpath as active if route cache is disabled;
    *) ike1 - fixed responder xauth trailing null;
    *) ike2 - always limit empty remote selector;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed state when sending delete packet;
    *) ipsec - added last-seen parameter to active connection list;
    *) leds - fixed defaults for RBSXT5HacD2nr2;
    *) lte - added initial support for Quectel ec25;
    *) lte - fixed IPv6 address prefix on interface
    *) lte - fixed older standard CEREG parsing;
    *) lte - fixed support for Huawai R216;
    *) traceroute - small fix;

    Other changes since 6.38.1:

    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.8 (because of new quickset);
    *) capsman - added CAP discovery interface list support;
    *) capsman - fixed SGI (Short Guard Interval) support;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) firewall - added "fasttrack" dummy rule to "/ip firewall raw" table;
    *) firewall - fixed import of exported configuration that had updated "limit" setting;
    *) graphs - fixed graph disappearance after power outage;
    *) ike2 - also kill IKEv2 connections on proposal change;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed proposal change crash;
    *) ike2 - fixed responder TS updating on wild match;
    *) ipsec - keep policy in kernel even with bad proposal;
    *) ipsec - kill ph2 on policy removal;
    *) leds - added LTE modem access technology trigger;
    *) leds - do not update single LED state when it is not changed;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) lte - added error handling for remote AT execute;
    *) lte - added support for Vodafone R216 (Huawei);
    *) mmips - improved general stability;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) pppoe - make default keepalive 10s for PPPoE clients;
    *) profile - classify ethernet driver activity properly in ARM architecture;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) switch - fixed crash when trying to configure second master port on the same chipset (RB3011, RB2011, CCR1009-8G-1S+);
    *) tr069-client - added connection request authentication;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - generate random connection request target path;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - added "add-relay-info" and "relay-info-remote-id" to DHCP relay;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - allow shorten bytes to k,M,G in bridge firewall just like in “/ip firewall”;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed typo in “/system resources pci” list;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - updated fan management menu;
    *) wireless - added "station-roaming" setting;
    *) wireless - fixed issue when wireless interfaces might not show up in cap mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare wireless ac interface lockup;

  • Release 6.39rc13 2017-01-17

    What's new in 6.39rc13 (2017-Jan-16 08:48):

    *) capsman - fixed SGI (Short Guard Interval) support;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) firewall - added "fasttrack" dummy rule to "/ip firewall raw" table;
    *) ike2 - also kill IKEv2 connections on proposal change;
    *) ike2 - fixed ph2 state when sending notify;
    *) ike2 - fixed proposal change crash;
    *) ike2 - fixed responder TS updating on wild match;
    *) ipsec - keep policy in kernel even with bad proposal;
    *) ipsec - kill ph2 on policy removal;
    *) lte - added support for Vodafone R216 (Huawei);
    *) switch - fixed crash when trying to configure second master port on the same chipset (RB3011, RB2011, CCR1009-8G-1S+);

    Other changes since 6.38.1:

    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.8 (because of new quickset);
    *) capsman - added CAP discovery interface list support;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) certificate - allow CRL address to be specified as DNS name;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) firewall - fixed import of exported configuration that had updated "limit" setting;
    *) graphs - fixed graph disappearance after power outage;
    *) leds - show warning on print when "modem-signal-threshold" is not available;
    *) leds - added LTE modem access technology trigger;
    *) leds - do not update single LED state when it is not changed;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) lte - added error handling for remote AT execute;
    *) mmips - improved general stability;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) pppoe - make default keepalive 10s for PPPoE clients;
    *) profile - classify ethernet driver activity properly in ARM architecture;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) tr069-client - added connection request authentication;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - generate random connection request target path;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - added "add-relay-info" and "relay-info-remote-id" to DHCP relay;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - allow shorten bytes to k,M,G in bridge firewall just like in “/ip firewall”;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed typo in “/system resources pci” list;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - updated fan management menu;
    *) wireless - added "station-roaming" setting;
    *) wireless - fixed issue when wireless interfaces might not show up in cap mode;
    *) wireless - fixed occasional crash on interface disabling;
    *) wireless - fixed rare wireless ac interface lockup;

  • Release 6.39rc12 2017-01-13

    What's new in 6.39rc12 (2017-Jan-12 13:38):

    !) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
    !) winbox - minimal required version is v3.8 (because of new quickset);
    *) bridge - disallow manual removal of dynamic bridge ports;
    *) bridge - fixed access loss to device through bridge if master port had a loop (introduced in v6.38);
    *) bridge - fixed rare conflicts between hardware and software STP (introduced in v6.38);
    *) certificate - added year cap (invalid-after date will not exceed year 2039);
    *) certificate - allow CRL address to be specified as DNS name;
    *) certificate - fixed fail on import from CAPs when both key and name already exist;
    *) dhcpv6-server - fixed server removal crash if static binding was present;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) fan - improved RPM monitor on CCR1009;
    *) firewall - fixed import of exported configuration that had updated "limit" setting;
    *) graphs - fixed graph disappearance after power outage;
    *) ike1 - fixed ph1 rekey in setups with mode-cfg;
    *) ike2 - auto-negotiate split nets;
    *) ike2 - default to tunnel mode in setups without policy;
    *) ike2 - fixed initiator TS updating;
    *) ike2 - fixed policy setting for /0 selector with different address families;
    *) ike2 - fixed split policy active flag;
    *) ike2 - fixed xauth add check;
    *) ike2 - include identity in peer address info;
    *) ike2 - log empty TS payload;
    *) ike2 - minor logging update;
    *) ike2 - traffic selector improvements;
    *) ike2 - use first split net for empty TS;
    *) ike2 - use standard retransmission timers for DPD;
    *) ike2 - xauth like auth method with user support;
    *) ipsec - added ability to kill particular remote-peer;
    *) ipv6 - added warning about having interface MTU less than minimal IPv6 packet fragment (1280);
    *) leds - added LTE modem access technology trigger;
    *) leds - do not update single LED state when it is not changed;
    *) license - fixed demo license expiration after installation on x86;
    *) logs - work on false CPU/RAM overclocked alarms;
    *) mpls - fixed crash on active tunnel loss in MPLS TE setups;
    *) ppp - fixed rare kernel failure on PPP client connection;
    *) pppoe - make default keepalive 10s for PPPoE clients;
    *) profile - classify ethernet driver activity properly in ARM architecture;
    *) quickset - various small changes;
    *) rb751u - fixed ethernet LEDs (broken since 6.38rc16);
    *) tr069-client - added connection request authentication;
    *) tr069-client - added parameters for DNS client management support;
    *) tr069-client - generate random connection request target path;
    *) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) webfig - show properly large BGP AS numbers;
    *) winbox - added "add-relay-info" and "relay-info-remote-id" to DHCP relay;
    *) winbox - added "group-key-update" to CAPsMAN security settings;
    *) winbox - added "make-static" to IPv6 DHCP server bindings;
    *) winbox - added "prefix-pool" to DHCPv6 server binding;
    *) winbox - added IPsec to radius services;
    *) winbox - added upstream flag to IGMP proxy interfaces;
    *) winbox - allow shorten bytes to k,M,G in bridge firewall just like in “/ip firewall”;
    *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
    *) winbox - allow to change user password to empty one;
    *) winbox - allow to specify "connection-bytes" & "connection-rate" for any protocol in “/ip firewall” rules;
    *) winbox - allow to specify "sip-timeout" under ip firewall service-ports;
    *) winbox - allow to specify certificate type when exporting it;
    *) winbox - allow to specify interfaces that CAPsMAN can use for management;
    *) winbox - do not create empty rates.vht-basic/supported-mcs if not specified in CAPsMAN;
    *) winbox - do not create time field when copying CAPsMAN access list entry;
    *) winbox - do not try to disable dynamic items from firewall tables;
    *) winbox - fixed typo in “/system resources pci” list;
    *) winbox - hide "nat-traversal" setting in IPsec peer if IKEv2 is selected;
    *) winbox - removed "sfp-rate-select" setting from ethernet interface;
    *) winbox - show dynamic IPv6 pools properly;
    *) winbox - show errors on IPv6 addresses ;
    *) winbox - specify metric for “/ip dns cache-used” setting;
    *) winbox - updated fan management menu;
    *) wireless - added "station-roaming" setting;
    *) wireless - fixed rare wireless ac interface lockup;
    *) wireless - show comment on "security-profile" if it is set;

    Other changes since 6.38:

    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    *) bridge - fixed MAC address learning from switch master-port;
    *) capsman - added CAP discovery interface list support;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) dhcpv6-client - fixed DHCPv6 rebind on startup;
    *) dns - fixed typo in regexp error message;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) firewall - nat action "netmap" now requires to-addresses to be specified;
    *) health - report fan speed for RB800 and RB1100 when 3-pin fan is being used;
    *) ike2 - allow empty selectors to reach policy handler;
    *) ike2 - fixed error packet from initiator on responder reply;
    *) ike2 - fixed ph1 initial-contact rare desync;
    *) ike2 - fixed traffic selector prefix calculation;
    *) ike2 - show peer identity of connected peers;
    *) ike2 - update also local port when peer changes port;
    *) ipsec - fixed flush speed and SAs on startup;
    *) ipsec - fixed peer port export;
    *) ipsec - port is used only for initiators;
    *) led - show warning on print when "modem-signal-threshold" is not available;
    *) log - added warning when Winbox/Dude sessions were denied;
    *) log - improved firewall log messages when NAT has changed only connection ports;
    *) lte - added error handling for remote AT execute;
    *) mmips - improved general stability;
    *) ovpn - fixed address acquisition when ovpn-in interface becomes slave;
    *) proxy - fixed "max-cache-object-size" export;
    *) proxy - speed-up almost empty disk cache clean-up;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) ssh - fixed high memory consumption when transferring file over ssh tunnel;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) wireless - fixed issue when wireless interfaces might not show up in cap mode;
    *) wireless - fixed occasional crash on interface disabling;

  • Release 6.39rc7 2017-01-05

    What's new in 6.39rc7 (2017-Jan-05 12:24):

    *) bridge - fixed MAC address learning from switch master-port;
    *) capsman - support for communicating frame priority between CAP and CAPsMAN;
    *) dhcpv6-client - fixed dhcpv6 rebind on startup;
    *) dns - fixed typo in regexp error message;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116471);
    *) firewall - nat action "netmap" now requires to-addresses to be specified;
    *) ike2 - allow empty selectors to reach policy handler;
    *) ike2 - fixed error packet from initiator on responder reply;
    *) ike2 - fixed ph1 initial-contact rare desync;
    *) ike2 - fixed traffic selector prefix calculation;
    *) ike2 - show peer identity of connected peers;
    *) ike2 - update also local port when peer changes port;
    *) ipsec - fixed flush speed and SAs on startup;
    *) ipsec - fixed peer port export;
    *) ipsec - port is used only for initiators;
    *) leds - added lte modem access technology trigger;
    *) log - added warning when winbox/dude sessions was denied;
    *) log - improved firewall log messages when NAT has changed only connection ports;
    *) mmips - improved general stability;
    *) ovpn - fixed address acquisition when ovpn-in interface becomes slave;
    *) proxy - fixed "max-cache-object-size" export;
    *) proxy - speed-up almost empty disk cache clean-up;
    *) rb1100ahx2 - fixed random counter resets for ether12,13;
    *) ssh - fixed high memory consumption when transferring file over ssh tunnel;
    *) wireless - fixed issue when wireless interfaces might not show up in CAP mode;
    *) wireless - fixed occasional crash on interface disabling;

    Other changes since 6.38:

    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    *) capsman - added CAP discovery interface list support;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) health - report fan speed for RB800 and RB1100 when 3-pin fan is being used;
    *) led - show warning on print when "modem-signal-threshold" is not available;
    *) lte - added error handling for remote AT execute;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) wireless - added "station-roaming" setting (cli only);
    *) wireless - show comment on "security-profile" if it is set (cli only);

  • Release 6.39rc4 2017-01-02

    What's new in 6.39rc4 (2016-Dec-30 07:16):

    !) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
    *) capsman - added CAP discovery interface list support;
    *) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
    *) health - report fan speed for RB800 and RB1100 when 3-pin fan is being used;
    *) led - show warning on print when "modem-signal-threshold" is not available;
    *) lte - added error handling for remote AT execute;
    *) wAP ac - improved 2.4GHz wireless performance;
    *) wireless - added "station-roaming" setting (cli only);
    *) wireless - show comment on "security-profile" if it is set (cli only);

  • Release 6.38rc52 2016-12-21

    What's new in 6.38rc52 (2016-Dec-21 10:44):

    *) bonding - fixed "tx-drop" on VLAN over bonding on x86;
    *) bonding - fixed kernel failure when bonding slave interface receives BPDU (introduced in 6.38rc51);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - fixed "tx-fcs-error" on SFP+ interfaces when loop-protect is enabled ;
    *) ipsec - fixed kernel failure on tile with sha256 when hardware encryption is not being used;
    *) ipsec - fixed ph2 auto-negotiation by checking policies in correct order;
    *) ipsec - various additional work on IKEv1/IKEv2 support;
    *) ipv6 - fixed "accept-router-advertisements" behaviour;

    Other changes since 6.37.3:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes";
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder;
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods;
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware STP functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package) (cli only);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) bridge - fixed VLAN BPDU rx and tx when connected to non-RouterOS device with STP functionality;
    *) bridge - require admin-mac to be specified if auto-mac is disabled;
    *) bridge - show bridge port name in port monitor;
    *) capsman - added "group-key-update" parameter;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) capsman - fixed CAP upgrade when separate wireless package is used (introduced in 6.37);
    *) capsman - use correct source address in reply to unicast discovery requests;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed pkcs12 export crash;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) console - fixed multi argument value unset;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - fixed DNS server assignment to client if dynamic server exists and is from another IP family;
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) dhcp-server - fixed when wizard was unable to create pool >dhcp_pool99;
    *) discovery - added LLDP support;
    *) discovery - fixed crash on sending LLDP packet over IPv6 (introduced in 6.38rc3);
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dns - added "max-concurrent-queries" and "max-concurrent-tcp-sessions" settings;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) firewall - significantly improved large firewall rule set import performance;
    *) graphing - fixed queue graphs showing up in web interface if aggregate name size >57840 symbols;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule port setting in hs-unauth-to chain by changing it from dst-port to src-port on Walled Garden ip return rules;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option;
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count";
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - always listen to IPv4/IPv6 UDP port 4500 (fixes some IKEv2 setups without NAT-T);
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - do not auto-negotiate more SAs than needed;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - ensure generated policy refers to valid proposal;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - fixed IPv6 remote prefix;
    *) ipsec - fixed larval SA state update;
    *) ipsec - fixed peer configuration my-id IPv4 address endianness;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - make generated policies always as unique;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - optimized logging under ipsec topic;
    *) ipsec - send xauth password without trailing null;
    *) ipsec - show active flag when policy has active SA;
    *) ipsec - show SA "enc-key-size";
    *) ipsec - split "mode-config" "send-dns" argument;
    *) ipv6 - moved empty IPv6 pool error message to error topic;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) metarouter - fixed startup process (introduced in 6.37.2);
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) profile - added "bfd" and "remote-access" processes;
    *) profile - added ability to monitor cpu usage per core;
    *) profile - make profile work on mmips devices;
    *) profile - properly classify "wireless" processes;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) radius - added IPSec service to console;
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - always report bonding speed as speed from first bonding slave;
    *) snmp - fixed rare crash when incorrectly formatted packet was received;
    *) snmp - provide sinr in lte table;
    *) ssh - added routing-table setting (cli only);
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) time - updated time zones;
    *) traceroute - fixed memory leak;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed compact export when "header-stack" includes tcp;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added minimal required permission set for full user group;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vrrp - do not show unrelated log warning messages about version mismatch;
    *) webfig - added extra protection against XSS exploits;
    *) webfig - show ipv6 addresses correctly;
    *) webfig - show properly interface last-link-up/down times;
    *) winbox - added "Complete" flag to arp table;
    *) winbox - added "untracked" option to firewall "connection-state" setting;
    *) winbox - added Dude icon to Dude menu;
    *) winbox - allow to enable/disable traffic flow targets;
    *) winbox - allow to run profile from "/system resources" menu;
    *) winbox - allow to specify interface for leds with "interface-speed" trigger;
    *) winbox - do not allow to set "loop-protect-send-interval" to 0s;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - do not show ph2-state on policy templates;
    *) winbox - fixed crash when legacy Winbox version was used;
    *) winbox - fixed default values for interface "loop-protect-disable-time" & "loop-protect-send-interval";
    *) winbox - fixed missing "ipv6/settings" menu;
    *) winbox - fixed typo in "propagate-ttl" setting;
    *) winbox - make cert signing include provided ca-crl-host;
    *) winbox - moved ipsec peer "exchange-mode" to General tab;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show all related HT tab settings in 2GHz-g/n mode;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) winbox - show proper ipv6 connection timeout;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed action frame handling for WDS nodes;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed full "spectral-history" header print on AP modes;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - fixed upgrade from older wireless packages when AP interface had empty SSID;
    *) wireless - take in account channel width when returning supported channels;
    *) wireless - use vlan ID 0 in RADIUS message to disable vlan tagging;

  • Release 6.38rc51 2016-12-20

    What's new in 6.38rc51 (2016-Dec-20 10:21):

    !) switch - added hardware STP functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    *) bridge - fixed VLAN BPDU rx and tx when connected to non-RouterOS device with STP functionality;
    *) capsman - fixed CAP upgrade when separate wireless package is used (introduced in 6.37);
    *) console - fixed multi argument value unset;
    *) dhcp - fixed DNS server assignment to client if dynamic server exists and is from another IP family;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) hotspot - fixed nat rule port setting in hs-unauth-to chain by changing it from dst-port to src-port on Walled Garden ip return rules;
    *) ipsec - do not auto-negotiate more SAs than needed;
    *) ipsec - make generated policies always as unique;
    *) ipsec - show active flag when policy has active SA;
    *) ipsec - various additional work on IKEv1/IKEv2 support;
    *) ipv6 - moved empty IPv6 pool error message to error topic;
    *) radius - added IPSec service to console;
    *) snmp - always report bonding speed as speed from first bonding slave;
    *) wireless - fixed action frame handling for WDS nodes;
    *) wireless - fixed full "spectral-history" header print on AP modes;

    Other changes since 6.37.3:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes";
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder;
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods;
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) tr069-client - initial implementation (as separate package) (cli only);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) bridge - require admin-mac to be specified if auto-mac is disabled;
    *) bridge - show bridge port name in port monitor;
    *) capsman - added "group-key-update" parameter;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) capsman - use correct source address in reply to unicast discovery requests;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed pkcs12 export crash;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) dhcp-server - fixed when wizard was unable to create pool >dhcp_pool99;
    *) discovery - added LLDP support;
    *) discovery - fixed crash on sending LLDP packet over IPv6 (introduced in 6.38rc3);
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dns - added "max-concurrent-queries" and "max-concurrent-tcp-sessions" settings;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) firewall - significantly improved large firewall rule set import performance;
    *) graphing - fixed queue graphs showing up in web interface if aggregate name size >57840 symbols;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option;
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count";
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - always listen to IPv4/IPv6 UDP port 4500 (fixes some IKEv2 setups without NAT-T);
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - ensure generated policy refers to valid proposal;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - fixed IPv6 remote prefix;
    *) ipsec - fixed larval SA state update;
    *) ipsec - fixed peer configuration my-id IPv4 address endianness;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - optimized logging under ipsec topic;
    *) ipsec - send xauth password without trailing null;
    *) ipsec - show SA "enc-key-size";
    *) ipsec - split "mode-config" "send-dns" argument;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) metarouter - fixed startup process (introduced in 6.37.2);
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) profile - added "bfd" and "remote-access" processes;
    *) profile - added ability to monitor cpu usage per core;
    *) profile - make profile work on mmips devices;
    *) profile - properly classify "wireless" processes;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - fixed rare crash when incorrectly formatted packet was received;
    *) snmp - provide sinr in lte table;
    *) ssh - added routing-table setting (cli only);
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) time - updated time zones;
    *) traceroute - fixed memory leak;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed compact export when "header-stack" includes tcp;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added minimal required permission set for full user group;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vrrp - do not show unrelated log warning messages about version mismatch;
    *) webfig - added extra protection against XSS exploits;
    *) webfig - show ipv6 addresses correctly;
    *) webfig - show properly interface last-link-up/down times;
    *) winbox - added "Complete" flag to arp table;
    *) winbox - added "untracked" option to firewall "connection-state" setting;
    *) winbox - added Dude icon to Dude menu;
    *) winbox - allow to enable/disable traffic flow targets;
    *) winbox - allow to run profile from "/system resources" menu;
    *) winbox - allow to specify interface for leds with "interface-speed" trigger;
    *) winbox - do not allow to set "loop-protect-send-interval" to 0s;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - do not show ph2-state on policy templates;
    *) winbox - fixed crash when legacy Winbox version was used;
    *) winbox - fixed default values for interface "loop-protect-disable-time" & "loop-protect-send-interval";
    *) winbox - fixed missing "ipv6/settings" menu;
    *) winbox - fixed typo in "propagate-ttl" setting;
    *) winbox - make cert signing include provided ca-crl-host;
    *) winbox - moved ipsec peer "exchange-mode" to General tab;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show all related HT tab settings in 2GHz-g/n mode;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) winbox - show proper ipv6 connection timeout;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - fixed upgrade from older wireless packages when AP interface had empty SSID;
    *) wireless - take in account channel width when returning supported channels;
    *) wireless - use vlan ID 0 in RADIUS message to disable vlan tagging;

  • Release 6.38rc49 2016-12-15

    What's new in 6.38rc49 (2016-Dec-15 06:18):

    *) bridge - show bridge port name in port monitor;
    *) capsman - added "group-key-update" parameter;
    *) capsman - use correct source address in reply to unicast discovery requests;
    *) discovery - fixed crash on sending LLDP packet over IPv6 (introduced in 6.38rc3);
    *) graphing - fixed queue graphs showing up in web interface if aggregate name size >57840 symbols;
    *) ipsec - fixed IPv6 remote prefix;
    *) ipsec - fixed larval SA state update;
    *) ipsec - optimized logging under ipsec topic;
    *) ipsec - show SA "enc-key-size";
    *) ipsec - various additional work on IKEv1/IKEv2 support;
    *) trafficgen - fixed compact export when "header-stack" includes tcp;
    *) wireless - fixed upgrade from older wireless packages when AP interface had empty SSID by changing it to router identity;
    *) wireless - use vlan ID 0 in RADIUS message to disable vlan tagging;

    Other changes since 6.37.3:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes";
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder;
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods;
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package) (cli only);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) bridge - require admin-mac to be specified if auto-mac is disabled;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed pkcs12 export crash;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) dhcp-server - fixed when wizard was unable to create pool >dhcp_pool99;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dns - added "max-concurrent-queries" and "max-concurrent-tcp-sessions" settings;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) firewall - significantly improved large firewall rule set import performance;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option;
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count";
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - always listen to IPv4/IPv6 UDP port 4500 (fixes some IKEv2 setups without NAT-T);
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - ensure generated policy refers to valid proposal;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - fixed peer configuration my-id IPv4 address endianness;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipsec - split "mode-config" "send-dns" argument;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) metarouter - fixed startup process (introduced in 6.37.2);
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) profile - added "bfd" and "remote-access" processes;
    *) profile - added ability to monitor cpu usage per core;
    *) profile - make profile work on mmips devices;
    *) profile - properly classify "wireless" processes;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - fixed rare crash when incorrectly formatted packet was received;
    *) snmp - provide sinr in lte table;
    *) ssh - added routing-table setting (cli only);
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) time - updated time zones;
    *) traceroute - fixed memory leak;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added minimal required permission set for full user group;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vrrp - do not show unrelated log warning messages about version mismatch;
    *) webfig - added extra protection against XSS exploits;
    *) webfig - show ipv6 addresses correctly;
    *) webfig - show properly interface last-link-up/down times;
    *) winbox - added "Complete" flag to arp table;
    *) winbox - added "untracked" option to firewall "connection-state" setting;
    *) winbox - added Dude icon to Dude menu;
    *) winbox - allow to enable/disable traffic flow targets;
    *) winbox - allow to run profile from "/system resources" menu;
    *) winbox - allow to specify interface for leds with "interface-speed" trigger;
    *) winbox - do not allow to set "loop-protect-send-interval" to 0s;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - do not show ph2-state on policy templates;
    *) winbox - fixed crash when legacy Winbox version was used;
    *) winbox - fixed default values for interface "loop-protect-disable-time" & "loop-protect-send-interval";
    *) winbox - fixed missing "ipv6/settings" menu;
    *) winbox - fixed typo in "propagate-ttl" setting;
    *) winbox - make cert signing include provided ca-crl-host;
    *) winbox - moved ipsec peer "exchange-mode" to General tab;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show all related HT tab settings in 2GHz-g/n mode;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) winbox - show proper ipv6 connection timeout;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc48 2016-12-13

    What's new in 6.38rc48 (2016-Dec-13 06:53):

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) profile - added ability to monitor cpu usage per core;
    *) profile - added "bfd" and "remote-access" processes;
    *) profile - make profile work on mmips devices;
    *) profile - properly classify "wireless" processes;
    *) winbox - allow to specify interface for leds with "interface-speed" trigger;
    *) winbox - do not allow to set "loop-protect-send-interval" to 0s;
    *) winbox - do not show ph2-state on policy templates;
    *) winbox - moved ipsec peer "exchange-mode" to General tab;
    *) winbox - show all related HT tab settings in 2GHz-g/n mode;

    Other changes since 6.37.3:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes";
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder;
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods;
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package) (cli only);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) bridge - require admin-mac to be specified if auto-mac is disabled;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed pkcs12 export crash;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) dhcp-server - fixed when wizard was unable to create pool >dhcp_pool99;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dns - added "max-concurrent-queries" and "max-concurrent-tcp-sessions" settings;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) firewall - significantly improved large firewall rule set import performance;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option;
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count";
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - always listen to port IPv6 UDP/4500;
    *) ipsec - always listen to port TCP/4500 (fixes some IKEv2 setups without NAT-T);
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - ensure generated policy refers to valid proposal;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - fixed peer configuration my-id IPv4 address endianness;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipsec - split "mode-config" "send-dns" argument;
    *) ipsec - various additional work on IKEv1/IKEv2 support;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) metarouter - fixed startup process (introduced in 6.37.2);
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - fixed rare crash when incorrectly formatted packet was received;
    *) snmp - provide sinr in lte table;
    *) ssh - added routing-table setting (cli only);
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) time - updated time zones;
    *) traceroute - fixed memory leak;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added minimal required permission set for full user group;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vrrp - do not show unrelated log warning messages about version mismatch;
    *) webfig - added extra protection against XSS exploits;
    *) webfig - show ipv6 addresses correctly;
    *) webfig - show properly interface last-link-up/down times;
    *) winbox - added "Complete" flag to arp table;
    *) winbox - added "untracked" option to firewall "connection-state" setting;
    *) winbox - added Dude icon to Dude menu;
    *) winbox - allow to enable/disable traffic flow targets;
    *) winbox - allow to run profile from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed crash when legacy Winbox version was used;
    *) winbox - fixed default values for interface "loop-protect-disable-time" & "loop-protect-send-interval";
    *) winbox - fixed missing "ipv6/settings" menu;
    *) winbox - fixed typo in "propagate-ttl" setting;
    *) winbox - make cert signing include provided ca-crl-host;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) winbox - show proper ipv6 connection timeout;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc47 2016-12-12

    What's new in 6.38rc47 (2016-Dec-12 08:49):

    *) bridge - require admin-mac to be specified if auto-mac is disabled;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ipsec - ensure generated policy refers to valid proposal;
    *) ipsec - always listen to port IPv6 UDP/4500;
    *) ipsec - various additional work on IKEv1/IKEv2 support;
    *) metarouter - fixed startup process (introduced in 6.37.2);
    *) profiler - make profiler work on mmips devices;
    *) snmp - fixed rare crash when incorrectly formatted packet was received;

    Other changes since 6.37.3:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes";
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder;
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods;
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package) (cli only);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed pkcs12 export crash;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) dhcp-server - fixed when wizard was unable to create pool >dhcp_pool99;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dns - added "max-concurrent-queries" and "max-concurrent-tcp-sessions" settings;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets canceled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) firewall - significantly improved large firewall rule set import performance;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option;
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count";
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - always listen to port TCP/4500 (fixes some IKEv2 setups without NAT-T);
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - fixed peer configuration my-id IPv4 address endianness;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipsec - split "mode-config" "send-dns" argument;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for Novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - added routing-table setting (cli only);
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) time - updated time zones;
    *) traceroute - fixed memory leak;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added minimal required permission set for full user group;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vrrp - do not show unrelated log warning messages about version mismatch;
    *) webfig - added extra protection against XSS exploits;
    *) webfig - show ipv6 addresses correctly;
    *) webfig - show properly interface last-link-up/down times;
    *) winbox - added "Complete" flag to arp table;
    *) winbox - added "untracked" option to firewall "connection-state" setting;
    *) winbox - added Dude icon to Dude menu;
    *) winbox - allow to enable/disable traffic flow targets;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed crash when legacy Winbox version was used;
    *) winbox - fixed default values for interface "loop-protect-disable-time" & "loop-protect-send-interval";
    *) winbox - fixed missing "ipv6/settings" menu;
    *) winbox - fixed typo in "propagate-ttl" setting;
    *) winbox - make cert signing include provided ca-crl-host;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) winbox - show proper ipv6 connection timeout;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc46 2016-12-09

    What's new in 6.38rc46 (2016-Dec-07 06:53):

    *) dhcp-server - fixed when wizard was unable to create pool >dhcp_pool99;
    *) ipsec - allow empty policy SA dst-address in tunnel mode;
    *) ipsec - always listen to port TCP/4500 (fixes some IKEv2 setups without NAT-T);
    *) ipsec - various additional work on IKEv1/IKEv2 support;
    *) vrrp - do not show unrelated log warning messages about version mismatch;
    *) webfig - added extra protection against XSS exploits;
    *) webfig - show properly interface last-link-up/down times;

    Other changes since 6.37.3:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes";
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder;
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods;
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package) (cli only);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed pkcs12 export crash;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dns - added "max-concurrent-queries" and "max-concurrent-tcp-sessions" settings;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) firewall - significantly improved large firewall rule set import performance;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option;
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count";
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - fixed peer configuration my-id IPv4 address endianness;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipsec - split "mode-config" "send-dns" argument;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - added routing-table setting (cli only);
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) time - updated time zones;
    *) traceroute - fixed memory leak;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) users - added minimal required permission set for full user group;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - show ipv6 addresses correctly;
    *) winbox - added "Complete" flag to arp table;
    *) winbox - added "untracked" option to firewall "connection-state" setting;
    *) winbox - added Dude icon to Dude menu;
    *) winbox - allow to enable/disable traffic flow targets;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed crash when legacy Winbox version was used;
    *) winbox - fixed default values for interface "loop-protect-disable-time" & "loop-protect-send-interval";
    *) winbox - fixed missing "ipv6/settings" menu;
    *) winbox - fixed typo in "propagate-ttl" setting;
    *) winbox - make cert signing include provided ca-crl-host;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) winbox - show proper ipv6 connection timeout;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc45 2016-12-08

    What's new in 6.38rc45 (2016-Dec-07 14:40):

    *) certificates - fixed pkcs12 export crash;
    *) ipsec - fixed peer configuration my-id IPv4 address endianness;
    *) ipsec - various additional work on IKEv1/IKEv2 support;
    *) winbox - added new ipsec feature (IKEv1/IKEv2/etc.) support (introduced in v6.38rc);
    *) winbox - fixed crash when legacy Winbox version was used;
    *) winbox - fixed icons in disabled state (introduced in v6.38rc44);

    Other changes since 6.37.3:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes";
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder;
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods;
    *) ipsec - added ability to specify static IP address at send-dns option;
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count";
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package) (cli only);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dns - added "max-concurrent-queries" and "max-concurrent-tcp-sessions" settings;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) firewall - significantly improved large firewall rule set import performance;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipsec - split "mode-config" "send-dns" argument;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - added routing-table setting (cli only);
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) time - updated time zones;
    *) traceroute - fixed memory leak;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) users - added minimal required permission set for full user group;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - show ipv6 addresses correctly;
    *) winbox - added "Complete" flag to arp table;
    *) winbox - added "untracked" option to firewall "connection-state" setting;
    *) winbox - added Dude icon to Dude menu;
    *) winbox - allow to enable/disable traffic flow targets;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed default values for interface "loop-protect-disable-time" & "loop-protect-send-interval";
    *) winbox - fixed missing "ipv6/settings" menu;
    *) winbox - fixed typo in "propagate-ttl" setting;
    *) winbox - make cert signing include provided ca-crl-host;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) winbox - show proper ipv6 connection timeout;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc44 2016-12-07

    What's new in 6.38rc44 (2016-Dec-07 08:08):

    *) crs - added comment ability in more switch menus;
    *) dns - added "max-concurrent-queries" and "max-concurrent-tcp-sessions" settings;
    *) ipsec - split "mode-config" "send-dns" argument;
    *) ipsec - various additional work in IKEv1/IKEv2 support;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) tr069-client - various additional work;
    *) traceroute - fixed memory leak;
    *) users - added minimal required permission set for full user group;
    *) webfig - fixed preview of values bigger than 2 billion and lower than 4 billion (introduced in v6.38rc);
    *) webfig - show ipv6 addresses correctly;
    *) winbox - added "Complete" flag to arp table;
    *) winbox - added "untracked" option to firewall "connection-state" setting;
    *) winbox - added Dude icon to Dude menu;
    *) winbox - allow to enable/disable traffic flow targets;
    *) winbox - fixed default values for interface "loop-protect-disable-time" & "loop-protect-send-interval";
    *) winbox - fixed missing "ipv6/settings" menu;
    *) winbox - fixed typo in "propagate-ttl" setting;
    *) winbox - make cert signing include provided ca-crl-host;
    *) winbox - show proper ipv6 connection timeout;

    Other changes since 6.37.3:

    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) firewall - significantly improved large firewall rule set import performance;
    *) time - updated time zones;
    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package) (cli only);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - added routing-table setting (cli only);
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc43 2016-12-06

    What's new in 6.38rc43 (2016-Dec-06 06:25):

    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) firewall - significantly improved large firewall rule set import performance;
    *) time - updated time zones;

    Other changes since 6.37.3:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dns - added max-concurrent-queries and max-concurrent-tcp-sessions settings (cli only);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) ike1 - fixed natted transport mode port-strict policy generation;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipsec - various additional work in IKEv2 support;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - added routing-table setting (cli only);
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc41 2016-12-05

    What's new in 6.38rc41 (2016-Dec-05 11:08):

    *) bridge - ignore dynamic switch ports when selecting bridge MAC address (introduced in v6.38rc7);
    *) dns - added max-concurrent-queries and max-concurrent-tcp-sessions settings (CLI only);
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) ipsec - various additional work in IKEv2 support;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) ssh - added routing-table setting (CLI only);
    *) x86 - fixed "system,error,critical failed to enable panics driver" (introduced in v6.38rc30);

    Other changes since 6.37.3:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) ike1 - fixed natted transport mode port-strict policy generation;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc40 2016-12-02

    What's new in 6.38rc40 (2016-Dec-02 07:33):

    *) certificate - remove invalid CRLs after upgrade; (broken since v6.38rc32);
    *) export - updated default values to clean up export compact;
    *) firewall - fixed "time" option by recognizing weekday properly (broken in 6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) ike1 - fixed natted transport mode port-strict policy generation;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - various additional work in IKEv2 support;
    *) lte - added support for novatel USB620L;
    *) queue - fixed "time" option by recognizing weekday properly (broken in 6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;

    Other changes since 6.37.3:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc38 2016-12-01

    What's new in 6.38rc38 (2016-Dec-01 06:25):

    !) tr069-client - initial implementation (as separate package);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) lcd - improved performance, causes less cpu load;
    *) rb3011 - fixed lcd and health (broken in v6.38rc35);

    Other changes since 6.37.3:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed rare crash;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) hAP lite - fixed bootup (broken in v6.38rc35);
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) smb - fixed crash on connect (introduced in 6.38rc1);
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc37 2016-11-25

    What's new in 6.38rc37 (2016-Nov-25 11:03):

    !) tr069-client - initial implementation (as separate package);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) firewall - fixed filter rule "limit" parameter by making it visible again;
    *) hAP lite - fixed bootup (broken in v6.38rc35);

    Other changes since 6.37.2:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bgp - do not match all prefixes tagged with community 0:0 by routing filters;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed crash on "/interface print" (introduced in 6.36.4);
    *) chr - fixed crash on "/system shutdown" and "/system shutdown";
    *) chr - fixed reboot;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) disk - fixed issue when disk was renamed after reboot on devices with flash disks;
    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed rare crash;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - fixed timeout option on address lists with domain name;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) log - ignore email topic if action is email;
    *) lte - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - fixed Pantech UML296 support;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mipsbe - improved memory allocation on devices with nand when file transfer and tcp traffic processing is on progress;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) smb - fixed crash on connect (introduced in 6.38rc1);
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) tile - fixed rare kernel failure when IPv6 neighbor discovery packet is received;
    *) traceroute - fixed crash when too many sessions are active;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - allow to force mtu value when actual-mtu is already the same;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - recognise properly tcp in traffic-generator packet-template header type;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show HT MCS tab if 2GHz-G/N band is used;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc36 2016-11-24

    What's new in 6.38rc36 (2016-Nov-24 05:49):

    !) tr069-client - initial implementation (as separate package);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) mipsbe - improved memory allocation on devices with nand when file transfer and tcp traffic processing is on progress;
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;

    Other changes since 6.37.2:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bgp - do not match all prefixes tagged with community 0:0 by routing filters;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed crash on "/interface print" (introduced in 6.36.4);
    *) chr - fixed crash on "/system shutdown" and "/system shutdown";
    *) chr - fixed reboot;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) disk - fixed issue when disk was renamed after reboot on devices with flash disks;
    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed rare crash;
    *) firewall - added creation-time to address list entries;
    *) firewall - fixed timeout option on address lists with domain name;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) log - ignore email topic if action is email;
    *) lte - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - fixed Pantech UML296 support;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) profiler - added ability to monitor cpu usage per core;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) smb - fixed crash on connect (introduced in 6.38rc1);
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) tile - fixed rare kernel failure when IPv6 neighbor discovery packet is received;
    *) traceroute - fixed crash when too many sessions are active;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - allow to force mtu value when actual-mtu is already the same;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - recognise properly tcp in traffic-generator packet-template header type;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show HT MCS tab if 2GHz-G/N band is used;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc35 2016-11-23

    What's new in 6.38rc35 (2016-Nov-23 09:55):

    *) disk - fixed issue when disk was renamed after reboot on devices with flash disks;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) tunnel - allow to force mtu value when actual-mtu is already the same;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;

    Other changes since 6.37.2:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bgp - do not match all prefixes tagged with community 0:0 by routing filters;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed crash on "/interface print" (introduced in 6.36.4);
    *) chr - fixed crash on "/system shutdown" and "/system shutdown";
    *) chr - fixed reboot;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed rare crash;
    *) firewall - added creation-time to address list entries;
    *) firewall - fixed timeout option on address lists with domain name;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) log - ignore email topic if action is email;
    *) lte - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - fixed Pantech UML296 support;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) profiler - added ability to monitor cpu usage per core;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) smb - fixed crash on connect (introduced in 6.38rc1);
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) tile - fixed rare kernel failure when IPv6 neighbor discovery packet is received;
    *) traceroute - fixed crash when too many sessions are active;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - recognise properly tcp in traffic-generator packet-template header type;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show HT MCS tab if 2GHz-G/N band is used;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc34 2016-11-22

    What's new in 6.38rc34 (2016-Nov-22 10:40):

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) tr069-client - initial implementation (as separate package);
    *) bonding - added "forced-mac-address" option;
    *) certificates - added support for PKCS#12 export;
    *) chr - fixed crash on "/interface print" (introduced in 6.36.4);
    *) chr - fixed crash on "/system shutdown" and "/system shutdown";
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) firewall - new faster "connection-limit" option implementation;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) smb - fixed crash on connect (introduced in 6.38rc1);
    *) tile - fixed rare kernel failure when IPv6 neighbor discovery packet is received;
    *) traceroute - fixed crash when too many sessions are active;
    *) winbox - recognise properly tcp in traffic-generator packet-template header type;
    *) winbox - show HT MCS tab if 2GHz-G/N band is used;
    *) wireless - added CRL checking for eap-tls;

    Other changes since 6.37.2:

    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bgp - do not match all prefixes tagged with community 0:0 by routing filters;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed reboot;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed rare crash;
    *) firewall - added creation-time to address list entries;
    *) firewall - fixed timeout option on address lists with domain name;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) log - ignore email topic if action is email;
    *) lte - added support for PANTECH UML295;
    *) lte - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed Pantech UML296 support;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) profiler - added ability to monitor cpu usage per core;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc31 2016-11-15

    What's new in 6.38rc31 (2016-Nov-15 12:51):

    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    *) bgp - do not match all prefixes tagged with community 0:0 by routing filters;
    *) certificate - fixed crash when crl is removed while it is being fetched;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) log - ignore email topic if action is email;

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set radius=yes" (cli only);
    !) ipsec - added support unique policy generation which will allow multiple peers behind the same NAT (cli only);
    !) queues - significantly improved hashing algorithm in dynamic simple queue setups (fixes CPU load spikes on queue removal);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arm - improved watchdog reliability;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option (cli only);
    *) bonding - fixed 802.3ad load balancing over routed VLANs with fastpath enabled;
    *) bonding - fixed mac address selection after upgrade;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed reboot;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed port mirroring halt after L2MTU change;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) ethernet - fixed potential loopprotect crash;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed kernel failure when fastpath traffic goes into loop;
    *) fastpath - fixed rare crash;
    *) fastpath - improved connection tracking timeout updates;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - fixed "connection-state" value disappearance in rules that were created before v6.22;
    *) firewall - fixed compact export (introduced in 6.37rc14);
    *) firewall - fixed timeout option on address lists with domain name;
    *) firewall - improved "time" option (ranges like 22h-10h now are acceptable);
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipv6 - increased default max-neighbor-entries value to 8192, same as ipv4;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - fixed Pantech UML296 support;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) mmips - improved watchdog reliability;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed rare crash on statistic gathering in "/queue tree";
    *) queue - improved "time" option (ranges like 22h-10h are now usable);
    *) rb2011 - fixed crash on l2mtu changes;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) ssl - fixed potential memory leak ( when using dude for example);
    *) system - reboot device on critical program crash;
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vlan - fixed CRS switch egress-vlan-tag export;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - added led settings menu;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed missing switch menu for mmips devices;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc30 2016-11-14

    What's new in 6.38rc30 (2016-Nov-14 13:20):

    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) firewall - fixed timeout option on address lists with domain name;
    *) system - reboot device on critical program crash;

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set radius=yes" (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation which will allow multiple peers behind the same NAT (cli only);
    !) queues - significantly improved hashing algorithm in dynamic simple queue setups (fixes CPU load spikes on queue removal);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arm - improved watchdog reliability;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option (cli only);
    *) bonding - fixed 802.3ad load balancing over routed VLANs with fastpath enabled;
    *) bonding - fixed mac address selection after upgrade;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed reboot;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed port mirroring halt after L2MTU change;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) ethernet - fixed potential loopprotect crash;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed kernel failure when fastpath traffic goes into loop;
    *) fastpath - fixed rare crash;
    *) fastpath - improved connection tracking timeout updates;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - fixed "connection-state" value disappearance in rules that were created before v6.22;
    *) firewall - fixed compact export (introduced in 6.37rc14);
    *) firewall - improved "time" option (ranges like 22h-10h now are acceptable);
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipv6 - increased default max-neighbor-entries value to 8192, same as ipv4;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - fixed Pantech UML296 support;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) mmips - improved watchdog reliability;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed rare crash on statistic gathering in "/queue tree";
    *) queue - improved "time" option (ranges like 22h-10h are now usable);
    *) rb2011 - fixed crash on l2mtu changes;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) ssl - fixed potential memory leak ( when using dude for example);
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vlan - fixed CRS switch egress-vlan-tag export;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - added led settings menu;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed missing switch menu for mmips devices;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc29 2016-11-11

    What's new in 6.38rc29 (2016-Nov-11 13:04):

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set radius=yes" (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation which will allow multiple peers behind the same NAT (cli only);
    !) tr069-client - initial implementation (as separate package);
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) certificates - allow import multiple certs with the same key;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) discovery - added LLDP support;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) firewall - new faster "connection-limit" option implementation;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) traffic-flow - fixed flow sequence counter and length;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    !) queues - significantly improved hashing algorithm in dynamic simple queue setups (fixes CPU load spikes on queue removal);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arm - improved watchdog reliability;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option (cli only);
    *) bonding - fixed 802.3ad load balancing over routed VLANs with fastpath enabled;
    *) bonding - fixed mac address selection after upgrade;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) chr - fixed "/interface print";
    *) chr - fixed reboot;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed port mirroring halt after L2MTU change;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) ethernet - fixed potential loopprotect crash;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed kernel failure when fastpath traffic goes into loop;
    *) fastpath - fixed rare crash;
    *) fastpath - improved connection tracking timeout updates;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - fixed "connection-state" value disappearance in rules that were created before v6.22;
    *) firewall - fixed compact export (introduced in 6.37rc14);
    *) firewall - improved "time" option (ranges like 22h-10h now are acceptable);
    *) firewall - increased max size of connection tracking table to 1048576;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipv6 - increased default max-neighbor-entries value to 8192, same as ipv4;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed Pantech UML296 support;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) mmips - improved watchdog reliability;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed rare crash on statistic gathering in "/queue tree";
    *) queue - improved "time" option (ranges like 22h-10h are now usable);
    *) rb2011 - fixed crash on l2mtu changes;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) ssl - fixed potential memory leak ( when using dude for example);
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vlan - fixed CRS switch egress-vlan-tag export;
    *) winbox - added led settings menu;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed missing switch menu for mmips devices;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc25 2016-11-07

    What's new in 6.38rc25 (2016-Nov-07 08:34):

    !) queues - significantly improved hashing algorithm in dynamic simple queue setups (fixes CPU load spikes on queue removal);
    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set radius=yes" (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation which will allow multiple peers behind the same NAT (cli only);
    *) discovery - added LLDP support;
    *) routerboot - show log message if router CPU/RAM is overclocked;

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arm - improved watchdog reliability;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option (cli only);
    *) bonding - fixed 802.3ad load balancing over routed VLANs with fastpath enabled;
    *) bonding - fixed mac address selection after upgrade;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) chr - fixed "/interface print";
    *) chr - fixed reboot;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed port mirroring halt after L2MTU change;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) ethernet - fixed potential loopprotect crash;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed kernel failure when fastpath traffic goes into loop;
    *) fastpath - fixed rare crash;
    *) fastpath - improved connection tracking timeout updates;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - fixed "connection-state" value disappearance in rules that were created before v6.22;
    *) firewall - fixed compact export (introduced in 6.37rc14);
    *) firewall - improved "time" option (ranges like 22h-10h now are acceptable);
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipv6 - increased default max-neighbor-entries value to 8192, same as ipv4;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed Pantech UML296 support;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) mmips - improved watchdog reliability;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed rare crash on statistic gathering in "/queue tree";
    *) queue - improved "time" option (ranges like 22h-10h are now usable);
    *) rb2011 - fixed crash on l2mtu changes;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) ssl - fixed potential memory leak ( when using dude for example);
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vlan - fixed CRS switch egress-vlan-tag export;
    *) winbox - added led settings menu;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed missing switch menu for mmips devices;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc24 2016-11-04

    What's new in 6.38rc24 (2016-Nov-03 13:01):

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set radius=yes" (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation which will allow multiple peers behind the same NAT (cli only);
    !) tr069-client - initial implementation (as separate package);
    *) arm - improved watchdog reliability;
    *) bonding - added "forced-mac-address" option (cli only);
    *) bonding - fixed 802.3ad load balancing over routed VLANs with fastpath enabled;
    *) bonding - fixed mac address selection after upgrade;
    *) bridge - fixed rare crash on bridge port removal;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed port mirroring halt after L2MTU change;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) fastpath - improved connection tracking timeout updates;
    *) firewall - fixed "connection-state" value disappearance in rules that were created before v6.22;
    *) firewall - improved "time" option (ranges like 22h-10h now are acceptable);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) mmips - improved watchdog reliability;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed rare crash on statistic gathering in "/queue tree";
    *) queue - improved "time" option (ranges like 22h-10h are now usable);
    *) wireless - added CRL checking for eap-tls;
    *)ipv6 - increased default max-neighbor-entries value to 8192, same as ipv4;
    *)ssl - fixed potential memory leak ( when using dude for example);

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) chr - fixed "/interface print";
    *) chr - fixed reboot;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) ethernet - fixed potential loopprotect crash;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed kernel failure when fastpath traffic goes into loop;
    *) fastpath - fixed rare crash;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - fixed compact export (introduced in 6.37rc14);
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - send xauth password without trailing null;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed Pantech UML296 support;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified;
    *) rb2011 - fixed crash on l2mtu changes;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vlan - fixed CRS switch egress-vlan-tag export;
    *) winbox - added led settings menu;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed missing switch menu for mmips devices;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc19 2016-10-31

    What's new in 6.38rc19 (2016-Oct-24 11:19):

    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    *) chr - fixed "/interface print";
    *) chr - fixed reboot;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) fastpath - fixed kernel failure when fastpath traffic goes into loop;
    *) fastpath - fixed rare crash;
    *) interface - changed loopback interface mtu to 1500;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - send xauth password without trailing null;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) lte - fixed Pantech UML296 support;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified;
    *) profiler - added ability to monitor cpu usage per core;
    *) resolver - ignore cache entries if specific server is used;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vlan - fixed CRS switch egress-vlan-tag export;
    *) winbox - added led settings menu;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - fixed missing switch menu for mmips devices;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - take in account channel width when returning supported channels;

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) ethernet - fixed potential loopprotect crash;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - fixed compact export (introduced in 6.37rc14);
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) rb2011 - fixed crash on l2mtu changes;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;

  • Release 6.38rc15 2016-10-14

    What's new in 6.38rc15 (2016-Oct-14 09:11):

    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) firewall - fixed compact export (introduced in 6.37rc14);
    *) rb2011 - fixed crash on l2mtu changes;

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) ethernet - fixed potential loopprotect crash;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified (CLI only);
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;

  • Release 6.38rc14 2016-10-13

    What's new in 6.38rc14 (2016-Oct-13 04:52):

    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - fixed potential loopprotect crash;
    *) firewall - new faster "connection-limit" option implementation;
    *) lte - added support for PANTECH UML295;

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified (CLI only);
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;

  • Release 6.38rc12 2016-10-11

    What's new in 6.38rc12 (2016-Oct-11 10:35):

    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) lte - allow to execute concurrent info commands;
    *) lte - return info data when all the fields are populated;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed via snmp;
    *) snmp - provide sinr in lte table;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;

    Other changes since 6.37.1:

    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    *) arp - added local-proxy-arp feature;
    *) bridge - fixed LLDP packet receive over bridge interfaces;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) discovery - added LLDP support;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) firewall - added creation-time to address list entries;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package – show minimal supported RouterOS version under “/system resource” menu if it is specified (CLI only);
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) sms – fixed crash after modem has failed to start;
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;

  • Release 6.38rc10 2016-10-06

    What's new in 6.38rc10 (2016-Oct-06 11:28):

    *) bridge - fixed LLDP packet receive over bridge interfaces;
    *) dhcp - do not show slave interfaces in dhcp server interface menu at server setup;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) lte - increased delay when setting sms send mode;

    Other changes since 6.37.1:

    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    *) arp - added local-proxy-arp feature;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) discovery - added LLDP support;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) firewall - added creation-time to address list entries;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package – show minimal supported RouterOS version under “/system resource” menu if it is specified (CLI only);
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) sms – fixed crash after modem has failed to start;
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;

  • Release 6.38rc9 2016-10-05

    What's new in 6.38rc9 (2016-Oct-05 10:23):

    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) package – show minimal supported RouterOS version under “/system resource” menu if it is specified (CLI only);
    *) sms – fixed crash after modem has failed to start;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;

    Other changes since 6.37.1:

    *) arp - added local-proxy-arp feature;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) discovery - added LLDP support;
    *) firewall - added creation-time to address list entries;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) torch - fixed aggregate statistics appearance;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;

  • Release 6.38rc8 2016-10-04

    What's new in 6.38rc8 (2016-Oct-04 06:22):

    Changes since 6.38rc7:

    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) lte - improved dwm-222 support;
    *) torch - fixed aggregate statistics appearance;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) userman - fixed memory leak on user limitation calculations;
    *) winbox - removed spare values from loop-protect menu;
    *) wireless - fixed custom channel extension-channel appearance in console;

    Other changes since 6.37.1:

    !) switch - added hardware stp functionality for CRS devices (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    *) arp - added local-proxy-arp feature;
    *) discovery - added LLDP support;
    *) firewall - added creation-time to address list entries;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) lte - fixed init delay after power reset;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;

  • Release 6.38rc7 2016-09-30

    What's new in 6.38rc7 (2016-Sep-30 07:33):

    !) ssl - fixed peer address/dns verification from certificate (affects sstp, fetch, capsman);
    !) switch - added hardware stp functionality for CRS devices (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.6 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration (CLI only);
    *) console - fixed typo in web-proxy (passthru to passhtrough);
    *) discovery - added LLDP support;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) export - do not show mac-address in export when it is not necessary;
    *) firewall - added creation-time to address list entries;
    *) firewall - fixed dynamic dummy firewall rules appearance in raw tables;
    *) hotspot - fixed nat rule dst-port by making it visible again;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) led - fixed default led settings for wAP2nDr2;
    *) lte - fixed init delay after power reset;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package - fixed wireless package status after upgrade to 6.37;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) snmp - do not allow to execute script if user does not have write permission;
    *) tile - do not reboot device after watchdog disable/enable;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - always re-fetch table data when switching between different menus;
    *) userman - fixed timezone adjustment in reports;
    *) users - added TikApp policy;
    *) winbox - added loop-protect settings;
    *) winbox - added passthrough state to web-proxy;
    *) winbox - allow to unset http-proxy field on sstp client;
    *) winbox - do not show health menu on RB951-2n;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed typo in dhcpv6 relay (DCHP to DHCP);
    *) winbox - show address expiration time in dhcp client list;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - show DFS flag in country-info command output;

  • Release 6.37rc42 2016-09-22

    What's new in 6.37rc42 (2016-Sep-22 11:07):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country settings (/interface wireless info country-info), and applies corresponding DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc40:

    !) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) certificate - do not allow to remove certificate template while signing certificate;
    *) dhcpv6 - fixed interface status update on client add (introduced in v6.37rc);
    *) firewall - fixed time based rules on time/timezone changes (again);
    *) ipsec - fixed crash with enabled fragmentation;
    *) ipsec - fixed fragmentation use negotiation;
    *) lte - added hauwei me909s variant;
    *) lte - fixed setting correct lte band for sxt lte;
    *) traffic-flow - fixed IPFIX packet timestamp;
    *) traffic-flow - fixed IPFIX wrong flow sequence;

    Other changes since 6.36.3:

    *) dhcpv6 - reworked DHCP-PD server interface and route management;
    *) tunnel - fixed communication via tunnel to router itself if fastpath was active;
    *) wireless - fixed interface disappearance on upgrade to 6.37 (introduced in v6.37rc);
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - fixed kernel crash on cap while changing client-to-client forwarding;
    *) capsman - report radio-name in registration table;
    *) console - hotspot setup show wrong certificate name;
    *) defconf - fixed default configuration restore if virtual wireless interface were present;
    *) defconf - fixed default configuration when wireless package is used;
    *) defconf - using caps button now forces all wireless interfaces in caps mode;
    *) dhcpv6 - improved interface status tracking;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) gps - always check NMEA checksum if available;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - fixed RA and RS processing on new interfaces after many interfaces have lost link during prolonged operation;
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added switch for Huawei K5160;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed memory leak;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) packages - fixed situation when it was impossible to disable ipv6 package (introduced in v6.37rc3x);
    *) partitions - added ability to add comments;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) ppp,lte - pin is now converted to string argument;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) supout - improved crash report generation for tile architecture;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) users - fixed script policy checking against user policies when running scripts;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed unset button for L2MTU field;
    *) winbox - show firmware-type in routerboard window;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc40 2016-09-20

    What's new in 6.37rc40 (2016-Sep-20 10:55):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country settings (/interface wireless info country-info), and applies corresponding DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc38:

    *) dhcpv6 - reworked DHCP-PD server interface and route management;
    *) tunnel - fixed communication via tunnel to router itself if fastpath was active;
    *) wireless - fixed interface disappearance on upgrade to 6.37 (introduced in v6.37rc);

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - fixed kernel crash on cap while changing client-to-client forwarding;
    *) capsman - report radio-name in registration table;
    *) console - hotspot setup show wrong certificate name;
    *) defconf - fixed default configuration restore if virtual wireless interface were present;
    *) defconf - fixed default configuration when wireless package is used;
    *) defconf - using caps button now forces all wireless interfaces in caps mode;
    *) dhcpv6 - improved interface status tracking;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) gps - always check NMEA checksum if available;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - fixed RA and RS processing on new interfaces after many interfaces have lost link during prolonged operation;
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added switch for Huawei K5160;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed memory leak;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) packages - fixed situation when it was impossible to disable ipv6 package (introduced in v6.37rc3x);
    *) partitions - added ability to add comments;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) ppp,lte - pin is now converted to string argument;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) supout - improved crash report generation for tile architecture;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) users - fixed script policy checking against user policies when running scripts;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed unset button for L2MTU field;
    *) winbox - show firmware-type in routerboard window;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc38 2016-09-19

    What's new in 6.37rc38 (2016-Sep-19 09:42):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc36:

    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    *) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - fixed kernel crash on cap while changing client-to-client forwarding;
    *) capsman - report radio-name in registration table;
    *) console - hotspot setup show wrong certificate name;
    *) defconf - fixed default configuration restore if virtual wireless interface were present;
    *) defconf - fixed default configuration when wireless package is used;
    *) defconf - using caps button now forces all wireless interfaces in caps mode;
    *) dhcpv6 - improved interface status tracking;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) gps - always check NMEA checksum if available;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - fixed RA and RS processing on new interfaces after many interfaces have lost link during prolonged operation;
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added switch for Huawei K5160;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed memory leak;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) packages - fixed situation when it was impossible to disable ipv6 package (introduced in v6.37rc3x);
    *) partitions - added ability to add comments;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) ppp,lte - pin is now converted to string argument;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) supout - improved crash report generation for tile architecture;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) users - fixed script policy checking against user policies when running scripts;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed unset button for L2MTU field;
    *) winbox - show firmware-type in routerboard window;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc36 2016-09-15

    What's new in 6.37rc36 (2016-Sep-14 10:12):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc34:

    *) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) defconf - fixed default configuration restore if virtual wireless interface were present;
    *) defconf - using caps button now forces all wireless interfaces in caps mode;
    *) console - hotspot setup show wrong certificate name;

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - fixed kernel crash on cap while changing client-to-client forwarding;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - improved interface status tracking;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) gps - always check NMEA checksum if available;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - fixed RA and RS processing on new interfaces after many interfaces have lost link during prolonged operation;
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added switch for Huawei K5160;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed memory leak;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) packages - fixed situation when it was impossible to disable ipv6 package (introduced in v6.37rc3x);
    *) partitions - added ability to add comments;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) ppp,lte - pin is now converted to string argument;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) supout - improved crash report generation for tile architecture;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) users - fixed script policy checking against user policies when running scripts;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed unset button for L2MTU field;
    *) winbox - show firmware-type in routerboard window;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc34 2016-09-13

    What's new in 6.37rc34 (2016-Sep-12 13:06):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc32:

    *) capsman - fixed kernel crash on cap while changing client-to-client forwarding;
    *) dhcpv6 - improved interface status tracking;
    *) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) gps - always check NMEA checksum if available;
    *) ipv6 - fixed RA and RS processing on new interfaces after many interfaces have lost link during prolonged operation;
    *) mpls - fixed memory leak;
    *) packages - fixed situation when it was impossible to disable ipv6 package (introduced in v6.37rc3x);
    *) ppp,lte - pin is now converted to string argument;
    *) supout - improved crash report generation for tile architecture;

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added switch for Huawei K5160;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) users - fixed script policy checking against user policies when running scripts;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed unset button for L2MTU field;
    *) winbox - show firmware-type in routerboard window;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc32 2016-09-07

    What's new in 6.37rc32 (2016-Sep-07 10:55):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc30:

    *) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) lte - added switch for Huawei K5160;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) users - fixed script policy checking against user policies when running scripts;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - show firmware-type in routerboard window;

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed unset button for L2MTU field;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc30 2016-09-06

    What's new in 6.37rc30 (2016-Sep-06 06:59):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc27:

    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed never-ending loop in CDP packet processing;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added switch for Huawei K5160;
    *) lte - fixed band unsetting;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) trafficgen - add per stream packet count setting;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed unset button for L2MTU field;

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) kvm - fix add/remove of disabled interfaces;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) wireless - updated brazil country settings.

  • Release 6.37rc27 2016-09-02

    What's new in 6.37rc27 (2016-Sep-02 06:18):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc26:

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) kvm - fix add/remove of disabled interfaces;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) usermanager - fixed rare crash on paypal payment;

    Other changes since 6.36.2:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) fastpath - fixed kernel crash on interface disable/remove;
    *) fetch - fixed bug with incomplete files in https mode;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - don't log authtype mismatch as critical;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipsec - fixed xauth parameter printing in terminal;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added zte K5008-Z back;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) pppoe - fixed master interface l2mtu check, could result in assumption that master interface can handle 14 byte bigger packet than it actually can (broken in 6.36);
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) simple queues - fixed issue which caused additional/unnecessary CPU load;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) switch - added comment field for CRS switch VLANs;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vlan - do not allow to add new vlan interface with mtu higher than l2mtu;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc26 2016-08-31

    What's new in 6.37rc26 (2016-Aug-31 11:25):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc24:

    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces (http://wiki.mikrotik.com/wiki/Manual:Loop_Protect);
    *) fastpath - fixed kernel crash on interface disable/remove;
    *) fetch - fixed bug with incomplete files in https mode;
    *) routing - improved kernel performance in setups with large routing tables;
    *) snmp - require write permitions for script run table access;
    *) sstp - now supports TLS_ECDHE algorithms;

    Other changes since 6.36.2:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - don't log authtype mismatch as critical;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipsec - fixed xauth parameter printing in terminal;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added zte K5008-Z back;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) pppoe - fixed master interface l2mtu check, could result in assumption that master interface can handle 14 byte bigger packet than it actually can (broken in 6.36);
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) simple queues - fixed issue which caused additional/unnecessary CPU load;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) switch - added comment field for CRS switch VLANs;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vlan - do not allow to add new vlan interface with mtu higher than l2mtu;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc24 2016-08-30

    What's new in 6.37rc24 (2016-Aug-30 11:57):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc22:

    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) ipsec - don't log authtype mismatch as critical;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipsec - fixed xauth parameter printing in terminal;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added zte K5008-Z back;
    *) lte - fixed default channels for dlink dwm-157;
    *) pppoe - fixed master interface l2mtu check, could result in assumption that master interface can handle 14 byte bigger packet than it actually can (broken in 6.36);
    *) snmp - skip forbidden oids on getnext completion;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) usb - fixed usb port reset on ether1 link changes on mAP 2n;

    Other changes since 6.36.2:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) simple queues - fixed issue which caused additional/unnecessary CPU load;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) sstp - allow to specify proxy by dns name;
    *) switch - added comment field for CRS switch VLANs;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vlan - do not allow to add new vlan interface with mtu higher than l2mtu;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc22 2016-08-25

    What's new in 6.37rc22 (2016-Aug-25 09:01):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc21:

    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) simple queues - fixed issue which caused additional/unnecessary CPU load;

    Other changes since 6.36.2:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) sstp - allow to specify proxy by dns name;
    *) switch - added comment field for CRS switch VLANs;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vlan - do not allow to add new vlan interface with mtu higher than l2mtu;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc21 2016-08-25

    What's new in 6.37rc21 (2016-Aug-25 06:15):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info ), and apply corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with correcponding DFS settings before upgrade.

    Changes since 6.37rc20:

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) hotspot - show comments from user menu also in active menu;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) vlan - do not allow to add new vlan interface with mtu higher than l2mtu;
    *) wireless - updated brazil country settings;

    Other changes since 6.36.2:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) sstp - allow to specify proxy by dns name;
    *) switch - added comment field for CRS switch VLANs;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.

  • Release 6.37rc20 2016-08-19

    What's new in 6.37rc20 (2016-Aug-19 06:35):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc19:

    *) address-list - fixed crash (introduced in 6.37rc17);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) export - updated default values in /system routerboard settings menu;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) trafficgen - fixed crash (introduced in 6.37rc17);

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) arm - show cpu frequency under resources menu;
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) capsman - fixed upgrade policy;
    *) capsman - report radio-name in registration table;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) defconf - fixed default configuration when wireless package is used;
    *) disk - do not do unnecessary sector writes;
    *) dns - allow to set query-server-timeout and query-total-timeout only greater than 0s;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dns - fixed lockup when dynamic dns server address 0.0.0.0 was received;
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - added additional matchers for firewall raw rules;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) health - do not show psu and fan information for passive cooling devices;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) partitions - fixed crash on repartition when there is not enough free space;
    *) ping - fixed freezing on "not running" interfaces;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - fixed disconnects on transmit for multicore systems;
    *) switch - added comment field for CRS switch VLANs;
    *) switch - fixed configuration reload on CRS switches;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) webfig - allowed user password changing (broken in v6.36);
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - make queue tree default queue type default-small;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc19 2016-08-18

    What's new in 6.37rc19 (2016-Aug-18 06:46):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc16:

    *) arm - show cpu frequency under resources menu;
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;


    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) capsman - fixed upgrade policy;
    *) capsman - report radio-name in registration table;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) defconf - fixed default configuration when wireless package is used;
    *) disk - do not do unnecessary sector writes;
    *) dns - allow to set query-server-timeout and query-total-timeout only greater than 0s;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dns - fixed lockup when dynamic dns server address 0.0.0.0 was received;
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - added additional matchers for firewall raw rules;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) health - do not show psu and fan information for passive cooling devices;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) partitions - fixed crash on repartition when there is not enough free space;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - fixed disconnects on transmit for multicore systems;
    *) switch - added comment field for CRS switch VLANs;
    *) switch - fixed configuration reload on CRS switches;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) webfig - allowed user password changing (broken in v6.36);
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - make queue tree default queue type default-small;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc16 2016-08-15

    What's new in 6.37rc16 (2016-Aug-15 07:48):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc15:

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) switch - added comment field for CRS switch VLANs;
    *) switch - fixed configuration reload on CRS switches;

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) capsman - fixed upgrade policy;
    *) capsman - report radio-name in registration table;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) defconf - fixed default configuration when wireless package is used;
    *) disk - do not do unnecessary sector writes;
    *) dns - allow to set query-server-timeout and query-total-timeout only greater than 0s;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dns - fixed lockup when dynamic dns server address 0.0.0.0 was received;
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - added additional matchers for firewall raw rules;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) health - do not show psu and fan information for passive cooling devices;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) partitions - fixed crash on repartition when there is not enough free space;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - fixed disconnects on transmit for multicore systems;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) webfig - allowed user password changing (broken in v6.36);
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - make queue tree default queue type default-small;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc15 2016-08-11

    What's new in 6.37rc15 (2016-Aug-11 09:14):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc13:

    *) capsman - fixed upgrade policy;
    *) capsman - report radio-name in registration table;
    *) dns - allow to set query-server-timeout and query-total-timeout only greater than 0s;
    *) dns - fixed lockup when dynamic dns server address 0.0.0.0 was received;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - fixed disconnects on transmit for multicore systems;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - make queue tree default queue type default-small;

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) defconf - fixed default configuration when wireless package is used;
    *) disk - do not do unnecessary sector writes;
    *) dns - avoid unnecessary static entry saving in storage;
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) partitions - fixed crash on repartition when there is not enough free space;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) webfig - allowed user password changing (broken in v6.36);
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc13 2016-08-10

    What's new in 6.37rc13 (2016-Aug-08 07:39):

    >>> IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    >>> IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc12:

    *) disk - do not do unnecessary sector writes;
    *) lte - added initial deregistration only for bandrich modems;
    *) partitions - added ability to add comments;
    *) partitions - fixed crash on repartition when there is not enough free space;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) webfig - allowed user password changing (broken in v6.36);

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) defconf - fixed default configuration when wireless package is used;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc12 2016-08-05

    What's new in 6.37rc12 (2016-Aug-05 05:31):

    >>> IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    >>> IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc11:

    *) defconf - fixed default configuration when wireless package is used;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) ping - fixed freezing on "not running" interfaces;
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) wireless - display DFS flag in country info;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc11 2016-08-01

    What's new in 6.37rc11 (2016-Aug-01 09:00):

    >>> IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    >>> IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc10:

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - fixed band setting for sxt lte;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added d-link dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) dns - avoid unnecessary static entry saving in storage;
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) modem - added dlink dwm-157 D support;
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) wireless - display DFS flag in country info;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc10 2016-07-29

    What's new in 6.37rc10 (2016-Jul-29 06:44):

    >>> IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using “routeros” bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one “wireless” package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    >>> IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to “dfs=radar-detect” for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc5:

    !) dude - from now on dude will use winbox port and it will be changed automatically both
    in client loader and agent configuration.
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    !) console - dfs-mode setting does not exist any more and all scripts with such setting
    will not be executed;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) firewall - check for duplicates when domain name is used in address field;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered
    state;
    *) modem - added dlink dwm-157 D support;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) wireless - display DFS flag in country info;

    Other changes since 6.36:

    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) check-for-updates - with bundle "routeros" package, will replace wireless package
    automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package
    automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no
    wireless packages installed, uninstall extra packages first;
    *) address-list - allow DNS names with "_" symbol;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - fixed time based rules on time/timezone changes;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on
    regular intervals;
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc5 2016-07-22

    What's new in 6.37rc5 (2016-Jul-22 09:17):

    New features and important changes:

    From now on there will be only one "wireless" package!
    Update on some package configurations is dangerous!!!

    *) wireless - "wireless-rep" renamed to "wireless";
    *) wireless - "wireless-cm2" discontinued, uninstall it before update;
    *) wireless - "wireless" package included in bundle "routeros" package;
    *) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    *) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    *) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;

    Fixes in last RC:

    *) address-list - allow DNS names with "_" symbol;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424 );
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - fixed time based rules on time/timezone changes;

    Fixes:

    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc4 2016-07-22

    What's new in 6.37rc4 (2016-Jul-21 07:17):

    Wireless is now unified to a single "wireless" package.
    Update on some package configurations is dangerous!!!

    *) wireless - "wireless-rep" renamed to "wireless";
    *) wireless - "wireless-cm2" discontinued, uninstall it before update;
    *) wireless - "wireless" package included in bundle "routeros" package;
    *) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    *) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    *) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals.
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424 );
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.36rc40 2016-07-13

    What's new in 6.36rc40 (2016-Jul-13 08:11):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083);
    *) lte - fixed modem network configuration version checks;
    *) nat - fixed nat rule disappearance after reboot if interface-list was used (introduced in 6.36rc39);
    *) pppoe - allow to set MTU and MRU higher than 1500 for PPPoE;
    *) tunnel - fixed rare crash by specifying minimal header length immediately at tunnel initialization;
    *) winbox - added 2ghz-g/n band for wireless-rep;
    *) winbox - added icons to bridge filter actions similar to ip firewall;
    *) winbox - do not show filter for combined fields like bgp-vpn4 RD;
    *) winbox - improve filtering on list fields;
    *) winbox - show action column as first in bridge firewall;
    *) winbox - show error when telnet is not allowed because of permissions;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding primary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - do not exit after card-verify;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed CHR seeing its own system disk mounted as additional data disk;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - fixed time keeping for SXT ac, 911L, cAP, mAP lite, wAP;
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - fixed get false function;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) email - removed subject and body length limit;
    *) email - fixed send from winbox;
    *) ethernet - fixed incorrect ether1 link speed after reboot on rb4xx series routers;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed interface list matcher showing incorrect name for NAT rules;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompliance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - fixed windows msgid check on x86 devices;
    *) ipsec - show remote peer address in error messages when possible;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) l2tp - fixed crash when rebooting or disabling l2tp while there are still active connections;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) log - make logging process less aggressive on startup;
    *) log - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - added support for Huawei E3531;
    *) lte - added support for ZTE ZM8620;
    *) lte - added use-peer-dns option (will work only combined with add-default-route);
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - display message in lte,error log if no response received;
    *) lte - display message in lte,error log when PIN is required;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - fixed modem init when pin request present;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for Alcatel OneTouch X600;
    *) modem - added support for SpeedUP SU-900U modem;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) netinstall - fixed netinstall and cd install for x86 (broken since 6.36rc27);
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) pppoe - do not allow to send out bigger packets than l2mtu if mrru is provided;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb2011 - fixed ether6-ether10 flapping when two ports from both switch chips are in the same bridge;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) rb3011 - fixed usb storage mounting;
    *) rb3011 - improved performance on high cpu usage;
    *) route - added suppport for more than 8 bits of options;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - do not exit while there still are active sessions;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) timezone - updated timezone information from tzdata2016e release;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) upnp - fixed firewall rules not being dynamic;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required);
    *) webfig - reduced refresh time for wireless registration table to 1 second;
    *) winbox - added arp-timeout setting to all ethernet like interfaces;
    *) winbox - added domain name support for IPv6 address list;
    *) winbox - do not allow to specify vlan-mode=no-tag in capsman datapath config;
    *) winbox - do not show mode setting for WDS interfaces;
    *) winbox - fixed crash when using ctrl+d;
    *) winbox - make local-address optional for eoipv6, 6to4, ipip, ipipv6 & grev6;
    *) winbox - renamed IPv6 "Raw rules" section to "Raw";
    *) winbox - report correctly dude users in active users list;
    *) winbox - set default sa-learning value to "yes" for CRS Ingress VLAN Translation rules;
    *) wireless - fixed multiple wireless packages enabled at the same time after upgrade;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc39 2016-07-12

    What's new in 6.36rc39 (2016-Jul-12 08:10):

    *) chr - fixed CHR seeing its own system disk mounted as additional data disk;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083);
    *) ethernet - fixed incorrect ether1 link speed after reboot on rb4xx series routers;
    *) firewall - fixed interface list matcher showing incorrect name for NAT rules;
    *) lte - added support for ZTE ZM8620;
    *) lte - added use-peer-dns option (will work only combined with add-default-route);
    *) netinstall - fixed netinstall and cd install for x86 (broken since 6.36rc27);
    *) pppoe - do not allow to send out bigger packets than l2mtu if mrru is provided;
    *) rb2011 - fixed ether6-ether10 flapping when two ports from both switch chips are in the same bridge;
    *) winbox - added arp-timeout setting to all ethernet like interfaces;
    *) winbox - added domain name support for IPv6 address list;
    *) winbox - do not allow to specify vlan-mode=no-tag in capsman datapath config;
    *) winbox - do not show mode setting for WDS interfaces;
    *) winbox - fixed crash when using ctrl+d;
    *) winbox - make local-address optional for eoipv6, 6to4, ipip, ipipv6 & grev6;
    *) winbox - renamed IPv6 "Raw rules" section to "Raw";
    *) winbox - set default sa-learning value to "yes" for CRS Ingress VLAN Translation rules;
    *) wireless - fixed multiple wireless packages enabled at the same time after upgrade;
    *) l2tp - fixed crash when rebooting or disabling l2tp while there are still active connections;
    *) rb3011 - fixed usb storage mounting;
    *) webfig - reduced refresh time for wireless registration table to 1 second;
    *) clock - fixed time keeping for SXT ac, 911L, cAP, mAP lite, wAP;
    *) ipsec - show remote peer address in error messages when possible;
    *) lte - display message in lte,error log if no response received;
    *) lte - display message in lte,error log when PIN is required;
    *) modem - added support for Alcatel OneTouch X600;
    *) upnp - fixed firewall rules not being dynamic;
    *) email - fixed send from winbox;
    *) log - make logging process less aggressive on startup;
    *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required);
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding primary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - do not exit after card-verify;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - fixed get false function;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompliance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - fixed windows msgid check on x86 devices;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - added support for Huawei E3531;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - fixed modem init when pin request present;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for SpeedUP SU-900U modem;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) rb3011 - improved performance on high cpu usage;
    *) route - added suppport for more than 8 bits of options;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - do not exit while there still are active sessions;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) timezone - updated timezone information from tzdata2016e release;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc37 2016-07-08

    What's new in 6.36rc37 (2016-Jul-07 11:13):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083);
    *) l2tp - fixed crash when rebooting or disabling l2tp while there are still active connections;
    *) rb3011 - fixed usb storage mounting;
    *) webfig - reduced refresh time for wireless registration table to 1 second;
    *) clock - fixed time keeping for SXT ac, 911L, cAP, mAP lite, wAP;
    *) ipsec - show remote peer address in error messages when possible;
    *) lte - display message in lte,error log if no response received;
    *) lte - display message in lte,error log when PIN is required;
    *) modem - added support for Alcatel OneTouch X600;
    *) upnp - fixed firewall rules not being dynamic;
    *) email - fixed send from winbox;
    *) log - make logging process less aggressive on startup;
    *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required);
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding primary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - do not exit after card-verify;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - fixed get false function;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompliance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - fixed windows msgid check on x86 devices;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - added support for Huawei E3531;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - fixed modem init when pin request present;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for SpeedUP SU-900U modem;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) rb3011 - improved performance on high cpu usage;
    *) route - added suppport for more than 8 bits of options;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - do not exit while there still are active sessions;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) timezone - updated timezone information from tzdata2016e release;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc36 2016-07-06

    What's new in 6.36rc36 (2016-Jul-06 09:51):

    *) clock - fixed time keeping for SXT ac, 911L, cAP, mAP lite, wAP;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083);
    *) ipsec - show remote peer address in error messages when possible;
    *) lte - display message in lte,error log if no response received;
    *) lte - display message in lte,error log when PIN is required;
    *) modem - added support for Alcatel OneTouch X600;
    *) upnp - fixed firewall rules not being dynamic;
    *) email - fixed send from winbox;
    *) log - make logging process less aggressive on startup;
    *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required);
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding primary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - do not exit after card-verify;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - fixed get false function;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompliance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - fixed windows msgid check on x86 devices;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - added support for Huawei E3531;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - fixed modem init when pin request present;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for SpeedUP SU-900U modem;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) rb3011 - improved performance on high cpu usage;
    *) route - added suppport for more than 8 bits of options;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - do not exit while there still are active sessions;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) timezone - updated timezone information from tzdata2016e release;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc33 2016-06-29

    What's new in 6.36rc33 (2016-Jun-28 11:04):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) email - fixed send from winbox;
    *) log - make logging process less aggressive on startup;
    *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required);
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding primary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - do not exit after card-verify;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - fixed get false function;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompliance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - fixed windows msgid check on x86 devices;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - added support for Huawei E3531;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - fixed modem init when pin request present;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for SpeedUP SU-900U modem;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) rb3011 - improved performance on high cpu usage;
    *) route - added suppport for more than 8 bits of options;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - do not exit while there still are active sessions;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) timezone - updated timezone information from tzdata2016e release;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc30 2016-06-22

    What's new in 6.36rc30 (2016-Jun-21 13:12):

    *) certificate - do not exit after card-verify;
    *) console - fixed get false function;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ipsec - fixed windows msgid check on x86 devices;
    *) lte - added support for Huawei E3531;
    *) lte - fixed modem init when pin request present;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for SpeedUP SU-900U modem;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) route - added suppport for more than 8 bits of options;
    *) ssl - do not exit while there still are active sessions;
    *) timezone - updated timezone information from tzdata2016e release;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) wireless-rep - fixed nstreme reset on poll timeout;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding privmary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompilance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - improved performance on high cpu usage;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc28 2016-06-13

    What's new in 6.36rc28 (2016-Jun-10 12:12):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ipsec - add dead ph2 detection exception for windows msgid noncompilance with rfc;
    *) lte - added cinterion pls8 support;
    *) lte - fixed connection for huawei without cell info;
    *) supout - erase panic data properly on Netinstall;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding privmary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - improved performance on high cpu usage;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) switch - fixed switch compact export;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc27 2016-06-09

    What's new in 6.36rc27 (2016-Jun-08 12:21):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) address-list - make "dynamic=yes" as read-only option;
    *) bonding - fixed bonding privmary slave assignment for ovpn interfaces after startup;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) userman - fixed crash on database upload;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - use only creg result codes as network status indications;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) rb3011 - fixed reset button functionality;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) rb3011 - improved performance on high cpu usage;
    *) snmp - report ram memory as ram instead of other;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - force scep renewal on system clock updates;
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) fetch - support tls host name extension;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) certificate - display issuer and subject on check failure;
    *) cloud - fixed export order;
    *) dhcpv6-server - fixed binding last-seen update;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - store udp encapsulation type in proposal;
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - treat missing SSID element as hidden SSID;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc21 2016-05-31

    What's new in 6.36rc21 (2016-May-31 10:45):

    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - use only creg result codes as network status indications;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) rb3011 - fixed reset button functionality;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) rb3011 - improved performance on high cpu usage;
    *) snmp - report ram memory as ram instead of other;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - force scep renewal on system clock updates;
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) fetch - support tls host name extension;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) certificate - display issuer and subject on check failure;
    *) cloud - fixed export order;
    *) dhcpv6-server - fixed binding last-seen update;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - store udp encapsulation type in proposal;
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - treat missing SSID element as hidden SSID;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc20 2016-05-30

    What's new in 6.36rc20 (2016-May-30 05:56):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) rb3011 - improved performance on high cpu usage;
    *) snmp - report ram memory as ram instead of other;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - force scep renewal on system clock updates;
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) fetch - support tls host name extension;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) certificate - display issuer and subject on check failure;
    *) cloud - fixed export order;
    *) dhcpv6-server - fixed binding last-seen update;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - store udp encapsulation type in proposal;
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - treat missing SSID element as hidden SSID;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc19 2016-05-27

    What's new in 6.36rc19 (2016-May-27 06:20):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - force scep renewal on system clock updates;
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) fetch - support tls host name extension;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) rb3011 - improved performance on high cpu usage;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) certificate - display issuer and subject on check failure;
    *) cloud - fixed export order;
    *) dhcpv6-server - fixed binding last-seen update;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - store udp encapsulation type in proposal;
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - treat missing SSID element as hidden SSID;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc16 2016-05-24

    What's new in 6.36rc16 (2016-May-24 07:04):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) address - allow multiple euqla ip addresses to be added if neither or only one is enabled;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) certificate - display issuer and subject on check failure;
    *) cloud - fixed export order;
    *) dhcpv6-server - fixed binding last-seen update;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - store udp encapsulation type in proposal;
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - treat missing SSID element as hidden SSID;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc13 2016-05-18

    What's new in 6.36rc13 (2016-May-17 12:20):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking and packet defragmentation (CLI only);
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc12 2016-05-11

    What's new in 6.36rc12 (2016-May-11 06:27):

    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking and packet defragmentation (CLI only);
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade.

  • Release 6.36rc11 2016-05-05

    What's new in 6.36rc11 (2016-May-05 07:40):

    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking and packet defragmentation (CLI only);
    *) firewall - fixed policy routing configurations (introduced in 6.35rc38);
    *) queue - fixed interface queue type for ovpn tunnels;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) discovery - fixed identity discovery (introduced in 6.36rc5 and 6.35.1);
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) log - fixed time zone adjustment (introduced in 6.36rc5 and 6.35.1);
    *) lte - added cinterion pls8 support;
    *) snmp - fixed snmp timeout (introduced in 6.36rc5 and 6.35.1);
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) vrrp - fixed missing vrrp interfaces after upgrade (introduced in 6.36rc5 and 6.35.1);
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc10 2016-04-29

    What's new in 6.36rc10 (2016-Apr-29 11:14):

    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking and packet defragmentation (CLI only);
    *) firewall - fixed policy routing configurations (introduced in 6.35rc38);
    *) queue - fixed interface queue type for ovpn tunnels;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) discovery - fixed identity discovery (introduced in 6.36rc5 and 6.35.1);
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) log - fixed time zone adjustment (introduced in 6.36rc5 and 6.35.1);
    *) lte - added cinterion pls8 support;
    *) snmp - fixed snmp timeout (introduced in 6.36rc5 and 6.35.1);
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) vrrp - fixed missing vrrp interfaces after upgrade (introduced in 6.36rc5 and 6.35.1);
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc9 2016-04-29

    What's new in 6.36rc9 (2016-Apr-29 08:04):

    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) discovery - fixed identity discovery (introduced in 6.36rc5 and 6.35.1);
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) log - fixed time zone adjustment (introduced in 6.36rc5 and 6.35.1);
    *) lte - added cinterion pls8 support;
    *) snmp - fixed snmp timeout (introduced in 6.36rc5 and 6.35.1);
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) vrrp - fixed missing vrrp interfaces after upgrade (introduced in 6.36rc5 and 6.35.1);
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking (CLI only);
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc8 2016-04-28

    What's new in 6.36rc8 (2016-Apr-28 06:57):

    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking (CLI only);
    *) lte - added cinterion pls8 support;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc6 2016-04-25

    What's new in 6.36rc6 (2016-Apr-25 06:25):

    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) watchdog - fixed reboot loop on startup (introduced in 6.36rc5);
    *) arp - added arp-timeout option per interface;
    *) log - fixed reboot log messages;
    *) lte - do not allow to set multiple modes when it is not supported;
    *) lte - fixed address acquisition on Huaweii LTE interfaces;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) winbox - show voltage in Health only if there actually is voltage monitor;
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless - fixed issue when CAPsMAN could lock CAPs interface;
    *) wireless-rep - fixed scan-list unset;
    *) bonding - do not corrupt bonding statistics on configuration changes;
    *) bonding - fixed crash when vlan parent mtu is higher than bonding mtu;
    *) ethernet - do not allow mtu to be higher than l2mtu and l2mtu to be higher than max-l2mtu (reduce automatically on upgrade if it was wrong before);
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc5 2016-04-22

    What's new in 6.36rc5 (2016-Apr-22 06:28):

    *) arp - added arp-timeout option per interface;
    *) log - fixed reboot log messages;
    *) lte - do not allow to set multiple modes when it is not supported;
    *) lte - fixed address acquisition on Huaweii LTE interfaces;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) winbox - show voltage in Health only if there actually is voltage monitor;
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless - fixed issue when CAPsMAN could lock CAPs interface;
    *) wireless-rep - fixed scan-list unset;
    *) bonding - do not corrupt bonding statistics on configuration changes;
    *) bonding - fixed crash when vlan parent mtu is higher than bonding mtu;
    *) ethernet - do not allow mtu to be higher than l2mtu and l2mtu to be higher than max-l2mtu (reduce automatically on upgrade if it was wrong before);
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc4 2016-04-21

    What's new in 6.36rc4 (2016-Apr-20 12:46):

    *) arp - added arp-timeout option per interface;
    *) log - fixed reboot log messages;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless - fixed issue when CAPsMAN could lock CAPs interface;
    *) wireless-rep - fixed scan-list unset;
    *) bonding - do not corrupt bonding statistics on configuration changes;
    *) bonding - fixed crash when vlan parent mtu is higher than bonding mtu;
    *) ethernet - do not allow mtu to be higher than l2mtu and l2mtu to be higher than max-l2mtu (reduce automatically on upgrade if it was wrong before);
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc3 2016-04-19

    What's new in 6.36rc3 (2016-Apr-19 11:33):

    *) bonding - do not corrupt bonding statistics on configuration changes;
    *) bonding - fixed crash when vlan parent mtu is higher than bonding mtu;
    *) ethernet - do not allow mtu to be higher than l2mtu and l2mtu to be higher than max-l2mtu (reduce automatically on upgrade if it was wrong before);
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.35rc49 2016-04-12

    What's new in 6.35rc49 (2016-Apr-12 7:20):

    *) dhcpv6 client - fix ia expiration and lifetime validation;
    *) dhcpv6 server - acquire binding on renew if it does not exist;
    *) export - exclude default values from export in "/interface l2tp-server server" menu;
    *) export - fixed rare situations when not whole config was exported;
    *) leds - fixed AP-CAP led blinking after successful association to CAPsMAN;
    *) lte - fixed crash on early initialization;
    *) lte - use timer for modem info;
    *) ntp - fixed ntp client hangs in reached state;
    *) rb3011 - fixed sfp compatibility with CCR when using direct attached cables;
    *) tunnels - fixed performance slowdown on any other tunnel disable/enable;
    *) winbox - added "pw-type" to "/interface vpls bgp-vpls" menu;
    *) winbox - added "use-control-word" and "pw-mtu" to "/interface vpls cisco-bgp-vpls" menu;
    *) winbox - added mtu=auto support to eoipv6 tunnel;
    *) wireless-rep - use full identity where possible;
    *) wireless-rep - fixed latency issues with Intel wireless clients;
    *) mipsbe - (excluding RB4xx and CRS series) fixed rare ethernet tx buffer corruption;
    *) dhcp6-client - fixed wrong error message;
    *) address-list - fixed crash in low memory situations;
    *) tile - fixed performance regression on switch chip (introduced in 6.33rc18);
    *) tile - fixed l2mtu change (introduced in 6.35rc);
    *) lcd - fixed branding packet logo drawing on startup;
    *) lte - replaced signal-strength with rssi in info command;
    *) nand - fixed reboot loop after upgrade to >v6.35rc43;
    *) ppp - fixed some clients can not connect due to LCP restart;
    *) tool fetch - fixed https cleanup on user stop while handshaking;
    *) winbox - make build with latest lte changes;
    *) hotspot - make video tag work properly on hotspot login.html page
    *) ipsec - fixed crash on policy update;
    *) ppp - fixed ppp crash if lcp packets were lost and authentication got delayed;
    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc48 2016-04-06

    What's new in 6.35rc48 (2016-Apr-05 15:10):

    *) wireless-rep - fixed latency issues with Intel wireless clients;
    *) mipsbe - (excluding RB4xx and CRS series) fixed rare ethernet tx buffer corruption;
    *) dhcp6-client - fixed wrong error message;
    *) address-list - fixed crash in low memory situations;
    *) tile - fixed performance regression on switch chip (introduced in 6.33rc18);
    *) tile - fixed l2mtu change (introduced in 6.35rc);
    *) lcd - fixed branding packet logo drawing on startup;
    *) lte - replaced signal-strength with rssi in info command;
    *) nand - fixed reboot loop after upgrade to >v6.35rc43;
    *) ppp - fixed some clients can not connect due to LCP restart;
    *) tool fetch - fixed https cleanup on user stop while handshaking;
    *) winbox - make build with latest lte changes;
    *) hotspot - make video tag work properly on hotspot login.html page
    *) ipsec - fixed crash on policy update;
    *) ppp - fixed ppp crash if lcp packets were lost and authentication got delayed;
    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc47 2016-04-06

    What's new in 6.35rc47 (2016-Apr-05 08:12):

    *) tile - fixed performance regression on switch chip (introduced in 6.33rc18);
    *) tile - fixed l2mtu change (introduced in 6.35rc);
    *) lcd - fixed branding packet logo drawing on startup;
    *) lte - replaced signal-strength with rssi in info command;
    *) nand - fixed reboot loop after upgrade to >v6.35rc43;
    *) ppp - fixed some clients can not connect due to LCP restart;
    *) tool fetch - fixed https cleanup on user stop while handshaking;
    *) winbox - make build with latest lte changes;
    *) wireless-rep - fixed latency issues with Intel 2.4GHz wireless clients;
    *) hotspot - make video tag work properly on hotspot login.html page
    *) ipsec - fixed crash on policy update;
    *) ppp - fixed ppp crash if lcp packets were lost and authentication got delayed;
    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc46 2016-04-05

    What's new in 6.35rc46 (2016-Apr-05 08:12):

    *) lcd - fixed branding packet logo drawing on startup;
    *) lte - replaced signal-strength with rssi in info command;
    *) nand - fixed reboot loop after upgrade to >v6.35rc43;
    *) ppp - fixed some clients can not connect due to LCP restart;
    *) tool fetch - fixed https cleanup on user stop while handshaking;
    *) winbox - make build with latest lte changes;
    *) wireless-rep - fixed latency issues with Intel 2.4GHz wireless clients;
    *) hotspot - make video tag work properly on hotspot login.html page
    *) ipsec - fixed crash on policy update;
    *) ppp - fixed ppp crash if lcp packets were lost and authentication got delayed;
    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc45 2016-04-01

    What's new in 6.35rc45 (2016-Apr-01 11:04):

    *) hotspot - make video tag work properly on hotspot login.html page
    *) ipsec - fixed crash on policy update;
    *) ppp - fixed ppp crash if lcp packets were lost and authentication got delayed;
    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc44 2016-04-01

    What's new in 6.35rc44 (2016-Apr-01 05:38):

    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc43 2016-03-30

    What's new in 6.35rc43 (2016-Mar-29 10:29):

    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fas