Software
 

All current and historical changelogs

Release candidate release tree

  • Release 6.43rc19 2018-05-25

    What's new in 6.43rc19 (2018-May-25 08:48):

    *) api - changed authentication process (https://wiki.mikrotik.com/wiki/Manual:API#Initial_login);
    *) bridge - fixed FastPath for bridge master interfaces (introduce in v6.42);
    *) chr - fixed adding MSTI entries;
    *) dhcpv6-client - added missing "Server identifier" parameter in release message;
    *) kidcontrol - fixed dynamically created firewall rules order;
    *) lte - added extended signal information for Quectel LTE EC25 and EP06 modem;
    *) lte - added ICCID reading for info command R11e-LTE and R11e-LTE-US (CLI only);
    *) user - all passwords are now hashed and encrypted, plaintext passwords are kept for downgrade (will be removed in later upgrades);
    *) w60g - added distance measurement (CLI only);

    Other changes since v6.42.3:

    *) backup - do not encrypt backup file unless password is provided;
    *) bridge - add dynamic CAP interface to tagged ports if "vlan-mode=use-tag" is enabled;
    *) bridge - added ingress filtering options to bridge interface (CLI only);
    *) bridge - added initial Q-in-Q support (CLI only);
    *) bridge - allow to make changes for bridge port when it is interface list;
    *) bridge - fixed bridge hw-offloading on MMIPS devices (introduced in v6.43rc10);
    *) bridge - fixed dynamic VLAN table entries when using ingress filtering;
    *) btest - requires at least v6.43 Bandwidth Test client when connecting to v6.43 or later version server except when authentication is not required;
    *) capsman - allow to change "radio-name" (CLI only);
    *) certificate - add "expires-after" parameter (CLI only);
    *) chr - added checksum offload support for Hyper-V installations;
    *) chr - added large send offload support for Hyper-V installations;
    *) chr - added multiqueue support on Xen installations;
    *) chr - added support for multiqueue feature on "virtio-net";
    *) chr - added virtual Receive Side Scaling support for Hyper-V installations;
    *) chr - do not show IRQ entries from removed devices;
    *) chr - fixed NIC hotplug for "virtio-net";
    *) chr - improved boot time for Hyper-V installations;
    *) crs3xx - added initial Q-in-Q hardware offloading support (CLI only);
    *) crs3xx - fixed ACL rate rules (introduced in v6.41rc27);
    *) crs3xx - fixed packet forwarding on SFP+ interfaces (introduced in v6.43rc11);
    *) crs3xx - fixed VLAN filtering when there is no tagged interface specified;
    *) defconf - fixed missing bridge ports after configuration reset;
    *) dhcpv4-server - do not allow override lease "always-broadcast" value based on offer type;
    *) dhcpv4-server - fixed DHCP server functionality (introduced in v6.43rc);
    *) dhcpv4-server - improved performance when "rate-limit" and/or "address-list" setting is present;
    *) dhcpv6-server - added initial dynamic simple queue support;
    *) filesystem - improved software crash handling on devices with FLASH type memory;
    *) interface - improved reliability on dynamic interface handling;
    *) ipsec - added "responder" parameter for "mode-config" to allow multiple initiator configurations (CLI only);
    *) ipsec - added "src-address-list" parameter for "mode-config" that generates dynamic "src-nat" rule (CLI only);
    *) ipsec - added warning messages for incorrect peer configuration;
    *) ipsec - do not allow removal of "proposal" and "mode-config" entries that are in use;
    *) ipsec - improved reliability on generated policy addition when IKEv1 or IKEv2 used;
    *) ipsec - install all DNS server addresses provided by "mode-config" server;
    *) ipsec - separate phase1 proposal configuration from peer menu (CLI only);
    *) kidcontrol - allow to edit discovered devices;
    *) led - fixed CCR1016-12S-1S+ LED behaviour after Netinstall (introduced in v6.41rc58);
    *) led - improved w60g alignment trigger;
    *) log - show interface name on OSPF "different MTU" info log messages;
    *) lte - added extended LTE signal info for SIM7600 modules;
    *) lte - added roaming status reading for info command (CLI only);
    *) lte - added support for Novatel USB730LN modem with new ID;
    *) lte - allow to execute concurrent internal AT commands;
    *) lte - allow to use multiple PLS modems at the same time;
    *) lte - do not allow to send "at-chat" commands for configless modems;
    *) lte - expose GPS channel for PLS modems;
    *) lte - fixed SIM7600 registration info;
    *) lte - improved r11e-LTE and r11e-LTE-US dialling process;
    *) lte - improved r11e-LTE configuration exchange process;
    *) lte - improved reading of SMS message after entering running state;
    *) lte - renamed LTE scan tool field "scan-code" to "mcc-mnc" (CLI only);
    *) lte - use "/32" address for the Passthrough feature when R11e-LTE module is used;
    *) lte - use alphanumeric operator format in info command;
    *) mac-telnet - require at least v6.43 MAC Telnet client when connecting to v6.43 or later version server;
    *) radius - use MS-CHAPv2 for "login" service authentication;
    *) romon - require at least v6.43 RoMON agent when connecting to v6.43 or later RoMON client device;
    *) routerboard - allow to fill up to half of the RAM memory with files on devices with FLASH storage;
    *) routerboard - fixed "protected-routerboot" feature (introduced in v6.42);
    *) smb - fixed valid request handling when additional options are used;
    *) ssh - disconnect all active connections when router gets rebooted or turned off;
    *) switch - added support for port isolation by switch chip (CLI only);
    *) tr069-client - fixed setting of "DeviceInfo.ProvisioningCode" parameter;
    *) w60g - added 4th 802.11ad channel (CLI only);
    *) w60g - general stability and performance improvements;
    *) w60g - improved maximal achievable distance;
    *) w60g - removed distance lock for wAP 60G devices;
    *) webfig - improved authentication process;
    *) winbox - added bridge Fast Forward statistics counters;
    *) winbox - fixed bridge port MAC learning parameter values;
    *) winbox - improved authentication process excluding man-in-the-middle possibility (Winbox v3.14 required);
    *) winbox - show "Switch" menu on hAP ac^2 devices;
    *) winbox - show HT MCS tab when "5ghz-n/ac" band is used;
    *) wireless - added option for RADUS "called-station-id" format selection (CLI only);
    *) wireless - do not disconnect clients when WDS master connects with MAC address "00:00:00:00:00:00";
    *) wireless - fixed wireless interface lockup after period of inactivity;
    *) wireless - improved Nv2 stability for 802.11n interfaces on RB953, hAP ac and wAP ac devices;

  • Release 6.43rc17 2018-05-23

    What's new in 6.43rc17 (2018-May-23 11:52):

    *) backup - do not encrypt backup file unless password is provided;
    *) bridge - add dynamic CAP interface to tagged ports if "vlan-mode=use-tag" is enabled;
    *) bridge - added initial Q-in-Q support (CLI only);
    *) btest - requires at least v6.43 Bandwidth Test client when connecting to v6.43 or later version server except when authentication is not required;
    *) crs3xx - fixed VLAN filtering when there is no tagged interface specified;
    *) lte - added ICCID reading for info command R11e-LTE (CLI only);
    *) lte - added roaming status reading for info command (CLI only);
    *) lte - improved r11e-LTE configuration exchange process;
    *) lte - renamed LTE scan tool field "scan-code" to "mcc-mnc" (CLI only);
    *) lte - use alphanumeric operator format in info command;
    *) mac-telnet - require at least v6.43 MAC Telnet client when connecting to v6.43 or later version server;
    *) radius - use MS-CHAPv2 for "login" service authentication;
    *) romon - require at least v6.43 RoMON agent when connecting to v6.43 or later RoMON client device;
    *) smb - fixed valid request handling when additional options are used;
    *) user - all passwords are now hashed and encrypted, plaintext passwords are kept for downgrade (will be removed in later upgrades);
    *) w60g - added 4th 802.11ad channel (CLI only);
    *) w60g - general stability and performance improvements;
    *) w60g - improved maximal achievable distance;
    *) w60g - removed distance lock for wAP 60G devices;
    *) webfig - improved authentication process;
    *) winbox - improved authentication process excluding man-in-the-middle possibility (Winbox v3.14 required);
    *) wireless - fixed wireless interface lockup after period of inactivity;
    *) wireless - increased stability on hAP ac^2 and cAP ac with legacy data rates;
    *) wireless - improved client "channel-width" detection;

    Other changes since v6.42.2:

    *) bridge - add dynamic CAP interface to tagged ports if "vlan-mode=use-tag" is enabled;
    *) bridge - added ingress filtering options to bridge interface (CLI only);
    *) bridge - allow to make changes for bridge port when it is interface list;
    *) bridge - fixed bridge hw-offloading on MMIPS devices (introduced in v6.43rc10);
    *) bridge - fixed dynamic VLAN table entries when using ingress filtering;
    *) capsman - allow to change "radio-name" (CLI only);
    *) certificate - add "expires-after" parameter (CLI only);
    *) chr - added checksum offload support for Hyper-V installations;
    *) chr - added large send offload support for Hyper-V installations;
    *) chr - added multiqueue support on Xen installations;
    *) chr - added support for multiqueue feature on "virtio-net";
    *) chr - added virtual Receive Side Scaling support for Hyper-V installations;
    *) chr - do not show IRQ entries from removed devices;
    *) chr - fixed NIC hotplug for "virtio-net";
    *) chr - improved boot time for Hyper-V installations;
    *) crs3xx - added initial Q-in-Q hardware offloading support (CLI only);
    *) crs3xx - fixed ACL rate rules (introduced in v6.41rc27);
    *) crs3xx - fixed packet forwarding on SFP+ interfaces (introduced in v6.43rc11);
    *) defconf - fixed missing bridge ports after configuration reset;
    *) dhcpv4-server - do not allow override lease "always-broadcast" value based on offer type;
    *) dhcpv4-server - fixed DHCP server functionality (introduced in v6.43rc);
    *) dhcpv4-server - improved performance when "rate-limit" and/or "address-list" setting is present;
    *) dhcpv6-server - added initial dynamic simple queue support;
    *) filesystem - improved software crash handling on devices with FLASH type memory;
    *) interface - improved reliability on dynamic interface handling;
    *) ipsec - added "responder" parameter for "mode-config" to allow multiple initiator configurations (CLI only);
    *) ipsec - added "src-address-list" parameter for "mode-config" that generates dynamic "src-nat" rule (CLI only);
    *) ipsec - added warning messages for incorrect peer configuration;
    *) ipsec - do not allow removal of "proposal" and "mode-config" entries that are in use;
    *) ipsec - improved reliability on generated policy addition when IKEv1 or IKEv2 used;
    *) ipsec - install all DNS server addresses provided by "mode-config" server;
    *) ipsec - separate phase1 proposal configuration from peer menu (CLI only);
    *) kidcontrol - allow to edit discovered devices;
    *) led - fixed CCR1016-12S-1S+ LED behaviour after Netinstall (introduced in v6.41rc58);
    *) led - improved w60g alignment trigger;
    *) log - show interface name on OSPF "different MTU" info log messages;
    *) lte - added extended LTE signal info for SIM7600 modules;
    *) lte - added extended signal information for Quectel LTE EP06 modem;
    *) lte - added support for Novatel USB730LN modem with new ID;
    *) lte - allow to execute concurrent internal AT commands;
    *) lte - allow to use multiple PLS modems at the same time;
    *) lte - do not allow to send "at-chat" commands for configless modems;
    *) lte - expose GPS channel for PLS modems;
    *) lte - fixed SIM7600 registration info;
    *) lte - improved r11e-LTE and r11e-LTE-US dialling process;
    *) lte - improved reading of SMS message after entering running state;
    *) lte - use "/32" address for the Passthrough feature when R11e-LTE module is used;
    *) routerboard - allow to fill up to half of the RAM memory with files on devices with FLASH storage;
    *) routerboard - fixed "protected-routerboot" feature (introduced in v6.42);
    *) ssh - disconnect all active connections when router gets rebooted or turned off;
    *) switch - added support for port isolation by switch chip (CLI only);
    *) tr069-client - fixed setting of "DeviceInfo.ProvisioningCode" parameter;
    *) winbox - added bridge Fast Forward statistics counters;
    *) winbox - fixed bridge port MAC learning parameter values;
    *) winbox - show "Switch" menu on hAP ac^2 devices;
    *) winbox - show HT MCS tab when "5ghz-n/ac" band is used;
    *) wireless - added option for RADUS "called-station-id" format selection (CLI only);
    *) wireless - do not disconnect clients when WDS master connects with MAC address "00:00:00:00:00:00";
    *) wireless - improved Nv2 PtMP performance;
    *) wireless - improved Nv2 stability for 802.11n interfaces on RB953, hAP ac and wAP ac devices;

  • Release 6.43rc14 2018-05-18

    What's new in 6.43rc14 (2018-May-18 07:09):

    *) bridge - add dynamic CAP interface to tagged ports if "vlan-mode=use-tag" is enabled;
    *) bridge - added ingress filtering options to bridge interface (CLI only);
    *) bridge - added initial Q-in-Q support (CLI only);
    *) bridge - allow to make changes for bridge port when it is interface list;
    *) crs3xx - added initial Q-in-Q hardware offloading support (CLI only);
    *) crs3xx - fixed ACL rate rules (introduced in v6.41rc27);
    *) defconf - fixed missing bridge ports after configuration reset;
    *) ipsec - improved reliability on generated policy addition when IKEv1 or IKEv2 used;
    *) led - fixed CCR1016-12S-1S+ LED behaviour after Netinstall (introduced in v6.41rc58);
    *) lte - added support for Novatel USB730LN modem with new ID;
    *) routerboard - fixed "protected-routerboot" feature (introduced in v6.42);
    *) wireless - improved Nv2 stability for 802.11n interfaces on RB953, hAP ac and wAP ac devices;

    Other changes since v6.42.2:

    *) bridge - fixed bridge hw-offloading on MMIPS devices (introduced in v6.43rc10);
    *) bridge - fixed dynamic VLAN table entries when using ingress filtering;
    *) capsman - allow to change "radio-name" (CLI only);
    *) certificate - add "expires-after" parameter (CLI only);
    *) chr - added checksum offload support for Hyper-V installations;
    *) chr - added large send offload support for Hyper-V installations;
    *) chr - added multiqueue support on Xen installations;
    *) chr - added support for multiqueue feature on "virtio-net";
    *) chr - added virtual Receive Side Scaling support for Hyper-V installations;
    *) chr - do not show IRQ entries from removed devices;
    *) chr - fixed NIC hotplug for "virtio-net";
    *) chr - improved boot time for Hyper-V installations;
    *) crs3xx - fixed packet forwarding on SFP+ interfaces (introduced in v6.43rc11);
    *) dhcpv4-server - do not allow override lease "always-broadcast" value based on offer type;
    *) dhcpv4-server - fixed DHCP server functionality (introduced in v6.43rc);
    *) dhcpv4-server - improved performance when "rate-limit" and/or "address-list" setting is present;
    *) dhcpv6-server - added initial dynamic simple queue support;
    *) filesystem - improved software crash handling on devices with FLASH type memory;
    *) interface - improved reliability on dynamic interface handling;
    *) ipsec - added "responder" parameter for "mode-config" to allow multiple initiator configurations (CLI only);
    *) ipsec - added "src-address-list" parameter for "mode-config" that generates dynamic "src-nat" rule (CLI only);
    *) ipsec - added warning messages for incorrect peer configuration;
    *) ipsec - do not allow removal of "proposal" and "mode-config" entries that are in use;
    *) ipsec - install all DNS server addresses provided by "mode-config" server;
    *) ipsec - separate phase1 proposal configuration from peer menu (CLI only);
    *) kidcontrol - allow to edit discovered devices;
    *) led - improved w60g alignment trigger;
    *) log - show interface name on OSPF "different MTU" info log messages;
    *) lte - added extended LTE signal info for SIM7600 modules;
    *) lte - added extended signal information for Quectel LTE EP06 modem;
    *) lte - allow to execute concurrent internal AT commands;
    *) lte - allow to use multiple PLS modems at the same time;
    *) lte - do not allow to send "at-chat" commands for configless modems;
    *) lte - expose GPS channel for PLS modems;
    *) lte - fixed SIM7600 registration info;
    *) lte - improved r11e-LTE and r11e-LTE-US dialling process;
    *) lte - improved reading of SMS message after entering running state;
    *) lte - use "/32" address for the Passthrough feature when R11e-LTE module is used;
    *) routerboard - allow to fill up to half of the RAM memory with files on devices with FLASH storage;
    *) ssh - disconnect all active connections when router gets rebooted or turned off;
    *) switch - added support for port isolation by switch chip (CLI only);
    *) tr069-client - fixed setting of "DeviceInfo.ProvisioningCode" parameter;
    *) winbox - added bridge Fast Forward statistics counters;
    *) winbox - fixed bridge port MAC learning parameter values;
    *) winbox - show "Switch" menu on hAP ac^2 devices;
    *) winbox - show HT MCS tab when "5ghz-n/ac" band is used;
    *) wireless - added option for RADUS "called-station-id" format selection (CLI only);
    *) wireless - do not disconnect clients when WDS master connects with MAC address "00:00:00:00:00:00";
    *) wireless - improved Nv2 PtMP performance;

  • Release 6.43rc12 2018-05-15

    What's new in 6.43rc12 (2018-May-11 09:08):

    *) bridge - fixed bridge hw-offloading on MMIPS devices (introduced in v6.43rc10);
    *) crs3xx - fixed packet forwarding on SFP+ interfaces (introduced in v6.43rc11);
    *) dhcpv4-server - fixed situation when router did reboot due to critical program crash (introduced in v6.43rc);
    *) ipsec - improved reliability on IPsec hardware encryption for ARM devices except RB1100Dx4;
    *) lte - use "/32" address for the Passthrough feature when R11e-LTE module is used;
    *) wireless - added option for RADIUS "called-station-id" format selection (CLI only);

    Other changes since v6.42.1:

    *) bridge - added ingress filtering options to bridge interface (CLI only);
    *) bridge - do not allow to add same interface list to bridge more than once;
    *) bridge - fixed dynamic VLAN table entries when using ingress filtering;
    *) bridge - fixed LLDP packet receiving;
    *) bridge - fixed processing of fragmented packets when hardware offloading is enabled;
    *) capsman - allow to change "radio-name" (CLI only);
    *) certificate - add "expires-after" parameter (CLI only);
    *) chr - added checksum offload support for Hyper-V installations;
    *) chr - added large send offload support for Hyper-V installations;
    *) chr - added multiqueue support on Xen installations;
    *) chr - added support for multiqueue feature on "virtio-net";
    *) chr - added virtual Receive Side Scaling support for Hyper-V installations;
    *) chr - do not show IRQ entries from removed devices;
    *) chr - fixed NIC hotplug for "virtio-net";
    *) chr - improved boot time for Hyper-V installations;
    *) console - fixed type "on" and "wireless-status" LED trigger value setting (introduced in v6.43rc1);
    *) crs317 - fixed link flapping when inserted S+RJ10 module without any cable;
    *) dhcpv4 - prevent sending out ICMP port unreachable packets;
    *) dhcpv4-server - do not allow override lease "always-broadcast" value based on offer type;
    *) dhcpv4-server - improved performance when "rate-limit" and/or "address-list" setting is present;
    *) dhcpv6-relay - fixed missing configuration after reboot;
    *) dhcpv6-server - added initial dynamic simple queue support;
    *) dhvpv4-client - fixed DHCP client stuck in renewing state;
    *) filesystem - fixed situation when filesystem goes into read-only mode on device with NAND type memory;
    *) filesystem - improved software crash handling on devices with FLASH type memory;
    *) hotspot - fixed user authentication when queue from old session is not removed yet;
    *) interface - fixed "built-in=no" parameter for manually created interface lists;
    *) interface - fixed "dynamic" built-in interface list behavior;
    *) interface - fixed interface list which include disabled member;
    *) interface - fixed interface list which include/exclude another list;
    *) interface - fixed situation when router did reboot due to critical program crash (introduced in v6.42);
    *) interface - improved reliability on dynamic interface handling;
    *) ipsec - added "responder" parameter for "mode-config" to allow multiple initiator configurations (CLI only);
    *) ipsec - added "src-address-list" parameter for "mode-config" that generates dynamic "src-nat" rule (CLI only);
    *) ipsec - added warning messages for incorrect peer configuration;
    *) ipsec - do not allow removal of "proposal" and "mode-config" entries that are in use;
    *) ipsec - fixed policies becoming invalid if added after a disabled policy;
    *) ipsec - install all DNS server addresses provided by "mode-config" server;
    *) ipsec - separate phase1 proposal configuration from peer menu (CLI only);
    *) kidcontrol - allow to edit discovered devices;
    *) led - added "dark-mode" functionality for hAP ac and hAP ac^2 devices;
    *) led - improved w60g alignment trigger;
    *) log - show interface name on OSPF "different MTU" info log messages;
    *) lte - added extended LTE signal info for SIM7600 modules;
    *) lte - added extended signal information for Quectel LTE EP06 modem;
    *) lte - allow to execute concurrent internal AT commands;
    *) lte - allow to use multiple PLS modems at the same time;
    *) lte - do not allow to send "at-chat" commands for configless modems;
    *) lte - expose GPS channel for PLS modems;
    *) lte - fixed SIM7600 registration info;
    *) lte - improved LTE communication process on MMIPS platform devices;
    *) lte - improved r11e-LTE and r11e-LTE-US dialling process;
    *) lte - improved reading of SMS message after entering running state;
    *) quickset - fixed dual radio mode detection process;
    *) routerboard - allow to fill up to half of the RAM memory with files on devices with FLASH storage;
    *) routerboard - properly represent board name for hAP ac^2;
    *) ssh - disconnect all active connections when router gets rebooted or turned off;
    *) switch - added support for port isolation by switch chip (CLI only);
    *) tile - fixed Ethernet interfaces becoming unresponsive;
    *) tr069-client: - fixed setting of "DeviceInfo.ProvisioningCode" parameter;
    *) winbox - added bridge Fast Forward statistics counters;
    *) winbox - allow to specify "any" as wireless "access-list" interface;
    *) winbox - fixed "/ip dhcp-server network set dns-none" parameter;
    *) winbox - fixed bridge port MAC learning parameter values;
    *) winbox - show "Switch" menu on hAP ac^2 devices;
    *) winbox - show HT MCS tab when "5ghz-n/ac" band is used;
    *) wireless - do not disconnect clients when WDS master connects with MAC address "00:00:00:00:00:00";
    *) wireless - enable all chains by default on devices without external antennas after configuration reset;
    *) wireless - fixed packet processing when "static-algo-0=40bit-wep" is being used (introduced in v6.42);
    *) wireless - fixed usage of allowed signal strength values received from RADIUS;
    *) wireless - improved Nv2 PtMP performance;
    *) wireless - improved wireless throughput on hAP ac^2 and cAP ac;

  • Release 6.43rc11 2018-05-10

    What's new in 6.43rc11 (2018-May-10 10:13):

    *) bridge - do not allow to add same interface list to bridge more than once;
    *) console - fixed type "on" and "wireless-status" LED trigger value setting (introduced in v6.43rc1);
    *) dhcpv4-server - do not allow override lease "always-broadcast" value based on offer type;
    *) dhcpv4-server - improved performance when "rate-limit" and/or "address-list" setting is present;
    *) dhcpv6-server - added initial dynamic simple queue support;
    *) filesystem - fixed situation when filesystem goes into read-only mode on device with NAND type memory;
    *) filesystem - improved software crash handling on devices with FLASH type memory;
    *) interface - fixed "built-in=no" parameter for manually created interface lists;
    *) interface - fixed "dynamic" built-in interface list behavior;
    *) interface - fixed interface list which include/exclude another list;
    *) interface - fixed interface list which include disabled member;
    *) interface - fixed situation when router did reboot due to critical program crash (introduced in v6.42);
    *) interface - improved reliability on dynamic interface handling;
    *) lte - added extended signal information for Quectel LTE EP06 modem;
    *) lte - improved LTE communication process on MMIPS platform devices;
    *) routerboard - properly represent board name for hAP ac^2;
    *) switch - added support for port isolation by switch chip (CLI only);
    *) tile - fixed Ethernet interfaces becoming unresponsive;
    *) wireless - do not disconnect clients when WDS master connects with MAC address "00:00:00:00:00:00";

    Other changes since v6.42.1:

    *) bridge - added ingress filtering options to bridge interface (CLI only);
    *) bridge - fixed dynamic VLAN table entries when using ingress filtering;
    *) bridge - fixed LLDP packet receiving;
    *) bridge - fixed processing of fragmented packets when hardware offloading is enabled;
    *) capsman - allow to change "radio-name" (CLI only);
    *) certificate - add "expires-after" parameter (CLI only);
    *) chr - added checksum offload support for Hyper-V installations;
    *) chr - added large send offload support for Hyper-V installations;
    *) chr - added multiqueue support on Xen installations;
    *) chr - added support for multiqueue feature on "virtio-net";
    *) chr - added virtual Receive Side Scaling support for Hyper-V installations;
    *) chr - do not show IRQ entries from removed devices;
    *) chr - fixed NIC hotplug for "virtio-net";
    *) chr - improved boot time for Hyper-V installations;
    *) crs317 - fixed link flapping when inserted S+RJ10 module without any cable;
    *) dhcpv4 - prevent sending out ICMP port unreachable packets;
    *) dhcpv6-relay - fixed missing configuration after reboot;
    *) dhvpv4-client - fixed DHCP client stuck in renewing state;
    *) hotspot - fixed user authentication when queue from old session is not removed yet;
    *) ipsec - added "responder" parameter for "mode-config" to allow multiple initiator configurations (CLI only);
    *) ipsec - added "src-address-list" parameter for "mode-config" that generates dynamic "src-nat" rule (CLI only);
    *) ipsec - added warning messages for incorrect peer configuration;
    *) ipsec - do not allow removal of "proposal" and "mode-config" entries that are in use;
    *) ipsec - fixed policies becoming invalid if added after a disabled policy;
    *) ipsec - install all DNS server addresses provided by "mode-config" server;
    *) ipsec - separate phase1 proposal configuration from peer menu (CLI only);
    *) kidcontrol - allow to edit discovered devices;
    *) led - added "dark-mode" functionality for hAP ac and hAP ac^2 devices;
    *) led - improved w60g alignment trigger;
    *) log - show interface name on OSPF "different MTU" info log messages;
    *) lte - added extended LTE signal info for SIM7600 modules;
    *) lte - allow to execute concurrent internal AT commands;
    *) lte - allow to use multiple PLS modems at the same time;
    *) lte - do not allow to send "at-chat" commands for configless modems;
    *) lte - expose GPS channel for PLS modems;
    *) lte - fixed SIM7600 registration info;
    *) lte - improved r11e-LTE and r11e-LTE-US dialling process;
    *) lte - improved reading of SMS message after entering running state;
    *) quickset - fixed dual radio mode detection process;
    *) routerboard - allow to fill up to half of the RAM memory with files on devices with FLASH storage;
    *) ssh - disconnect all active connections when router gets rebooted or turned off;
    *) tr069-client: - fixed setting of "DeviceInfo.ProvisioningCode" parameter;
    *) winbox - added bridge Fast Forward statistics counters;
    *) winbox - allow to specify "any" as wireless "access-list" interface;
    *) winbox - fixed "/ip dhcp-server network set dns-none" parameter;
    *) winbox - fixed bridge port MAC learning parameter values;
    *) winbox - show "Switch" menu on hAP ac^2 devices;
    *) winbox - show HT MCS tab when "5ghz-n/ac" band is used;
    *) wireless - enable all chains by default on devices without external antennas after configuration reset;
    *) wireless - fixed packet processing when "static-algo-0=40bit-wep" is being used (introduced in v6.42);
    *) wireless - fixed usage of allowed signal strength values received from RADIUS;
    *) wireless - improved Nv2 PtMP performance;
    *) wireless - improved wireless throughput on hAP ac^2 and cAP ac;

  • Release 6.43rc7 2018-05-08

    What's new in 6.43rc7 (2018-May-08 06:08):

    *) capsman - allow to change "radio-name" (CLI only);
    *) dhcpv4 - prevent sending out ICMP port unreachable packets;
    *) dhvpv4-client - fixed DHCP client stuck in renewing state;
    *) kidcontrol - allow to edit discovered devices;
    *) lte - do not allow to send "at-chat" commands for configless modems;

    Other changes since v6.42.1:

    *) bridge - added ingress filtering options to bridge interface (CLI only);
    *) bridge - fixed dynamic VLAN table entries when using ingress filtering;
    *) bridge - fixed LLDP packet receiving;
    *) bridge - fixed processing of fragmented packets when hardware offloading is enabled;
    *) certificate - add "expires-after" parameter (CLI only);
    *) chr - added checksum offload support for Hyper-V installations;
    *) chr - added large send offload support for Hyper-V installations;
    *) chr - added multiqueue support on Xen installations;
    *) chr - added support for multiqueue feature on "virtio-net";
    *) chr - added virtual Receive Side Scaling support for Hyper-V installations;
    *) chr - do not show IRQ entries from removed devices;
    *) chr - fixed NIC hotplug for "virtio-net";
    *) chr - improved boot time for Hyper-V installations;
    *) crs317 - fixed link flapping when inserted S+RJ10 module without any cable;
    *) dhcpv6-relay - fixed missing configuration after reboot;
    *) hotspot - fixed user authentication when queue from old session is not removed yet;
    *) ipsec - added "responder" parameter for "mode-config" to allow multiple initiator configurations (CLI only);
    *) ipsec - added "src-address-list" parameter for "mode-config" that generates dynamic "src-nat" rule (CLI only);
    *) ipsec - added warning messages for incorrect peer configuration;
    *) ipsec - do not allow removal of "proposal" and "mode-config" entries that are in use;
    *) ipsec - fixed policies becoming invalid if added after a disabled policy;
    *) ipsec - install all DNS server addresses provided by "mode-config" server;
    *) ipsec - separate phase1 proposal configuration from peer menu (CLI only);
    *) led - added "dark-mode" functionality for hAP ac and hAP ac^2 devices;
    *) led - improved w60g alignment trigger;
    *) log - show interface name on OSPF "different MTU" info log messages;
    *) lte - added extended LTE signal info for SIM7600 modules;
    *) lte - allow to execute concurrent internal AT commands;
    *) lte - allow to use multiple PLS modems at the same time;
    *) lte - expose GPS channel for PLS modems;
    *) lte - fixed SIM7600 registration info;
    *) lte - improved r11e-LTE and r11e-LTE-US dialling process;
    *) lte - improved reading of SMS message after entering running state;
    *) quickset - fixed dual radio mode detection process;
    *) routerboard - allow to fill up to half of the RAM memory with files on devices with FLASH storage;
    *) ssh - disconnect all active connections when router gets rebooted or turned off;
    *) tr069-client: - fixed setting of "DeviceInfo.ProvisioningCode" parameter;
    *) winbox - added bridge Fast Forward statistics counters;
    *) winbox - allow to specify "any" as wireless "access-list" interface;
    *) winbox - fixed "/ip dhcp-server network set dns-none" parameter;
    *) winbox - fixed bridge port MAC learning parameter values;
    *) winbox - show "Switch" menu on hAP ac^2 devices;
    *) winbox - show HT MCS tab when "5ghz-n/ac" band is used;
    *) wireless - enable all chains by default on devices without external antennas after configuration reset;
    *) wireless - fixed packet processing when "static-algo-0=40bit-wep" is being used (introduced in v6.42);
    *) wireless - fixed usage of allowed signal strength values received from RADIUS;
    *) wireless - improved Nv2 PtMP performance;
    *) wireless - improved wireless throughput on hAP ac^2 and cAP ac;

  • Release 6.43rc6 2018-05-03

    What's new in 6.43rc6 (2018-May-02 12:28):

    *) bridge - fixed LLDP packet receiving;
    *) bridge - fixed processing of fragmented packets when hardware offloading is enabled;
    *) dhcpv6-relay - fixed missing configuration after reboot;
    *) hotspot - fixed user authentication when queue from old session is not removed yet;
    *) quickset - fixed dual radio mode detection process;
    *) wireless - fixed usage of allowed signal strength values received from RADIUS;
    *) wireless - improved Nv2 PtMP performance;

    Other changes since v6.42.1:

    *) bridge - added ingress filtering options to bridge interface (CLI only);
    *) bridge - fixed dynamic VLAN table entries when using ingress filtering;
    *) certificate - add "expires-after" parameter (CLI only);
    *) chr - added checksum offload support for Hyper-V installations;
    *) chr - added large send offload support for Hyper-V installations;
    *) chr - added multiqueue support on Xen installations;
    *) chr - added support for multiqueue feature on "virtio-net";
    *) chr - added virtual Receive Side Scaling support for Hyper-V installations;
    *) chr - do not show IRQ entries from removed devices;
    *) chr - fixed NIC hotplug for "virtio-net";
    *) chr - improved boot time for Hyper-V installations;
    *) crs317 - fixed link flapping when inserted S+RJ10 module without any cable;
    *) ipsec - added "responder" parameter for "mode-config" to allow multiple initiator configurations (CLI only);
    *) ipsec - added "src-address-list" parameter for "mode-config" that generates dynamic "src-nat" rule (CLI only);
    *) ipsec - added warning messages for incorrect peer configuration;
    *) ipsec - do not allow removal of "proposal" and "mode-config" entries that are in use;
    *) ipsec - fixed policies becoming invalid if added after a disabled policy;
    *) ipsec - install all DNS server addresses provided by "mode-config" server;
    *) ipsec - separate phase1 proposal configuration from peer menu (CLI only);
    *) led - added "dark-mode" functionality for hAP ac and hAP ac^2 devices;
    *) led - improved w60g alignment trigger;
    *) log - show interface name on OSPF "different MTU" info log messages;
    *) lte - added extended LTE signal info for SIM7600 modules;
    *) lte - allow to execute concurrent internal AT commands;
    *) lte - allow to use multiple PLS modems at the same time;
    *) lte - expose GPS channel for PLS modems;
    *) lte - fixed SIM7600 registration info;
    *) lte - improved r11e-LTE and r11e-LTE-US dialling process;
    *) lte - improved reading of SMS message after entering running state;
    *) routerboard - allow to fill up to half of the RAM memory with files on devices with FLASH storage;
    *) ssh - disconnect all active connections when router gets rebooted or turned off;
    *) tr069-client: - fixed setting of "DeviceInfo.ProvisioningCode" parameter;
    *) winbox - added bridge Fast Forward statistics counters;
    *) winbox - allow to specify "any" as wireless "access-list" interface;
    *) winbox - fixed "/ip dhcp-server network set dns-none" parameter;
    *) winbox - fixed bridge port MAC learning parameter values;
    *) winbox - show "Switch" menu on hAP ac^2 devices;
    *) winbox - show HT MCS tab when "5ghz-n/ac" band is used;
    *) wireless - enable all chains by default on devices without external antennas after configuration reset;
    *) wireless - fixed packet processing when "static-algo-0=40bit-wep" is being used (introduced in v6.42);
    *) wireless - improved wireless throughput on hAP ac^2 and cAP ac;

  • Release 6.43rc5 2018-04-26

    What's new in 6.43rc5 (2018-Apr-25 12:11):

    *) ipsec - fixed policies becoming invalid if added after a disabled policy;
    *) led - added "dark-mode" functionality for hAP ac and hAP ac^2 devices;
    *) lte - allow to execute concurrent internal AT commands;
    *) lte - improved r11e-LTE and r11e-LTE-US dialling process;
    *) lte - improved reading of SMS message after entering running state;
    *) ssh - disconnect all active connections when router gets rebooted or turned off;
    *) tr069-client: - fixed setting of "DeviceInfo.ProvisioningCode" parameter;
    *) wireless - fixed packet processing when "static-algo-0=40bit-wep" is being used (introduced in v6.42);
    *) wireless - improved wireless throughput on hAP ac^2 and cAP ac;

    Other changes since v6.42.1:

    *) bridge - added ingress filtering options to bridge interface (CLI only);
    *) bridge - fixed dynamic VLAN table entries when using ingress filtering;
    *) certificate - add "expires-after" parameter (CLI only);
    *) chr - added checksum offload support for Hyper-V installations;
    *) chr - added large send offload support for Hyper-V installations;
    *) chr - added multiqueue support on Xen installations;
    *) chr - added support for multiqueue feature on "virtio-net";
    *) chr - added virtual Receive Side Scaling support for Hyper-V installations;
    *) chr - do not show IRQ entries from removed devices;
    *) chr - fixed NIC hotplug for "virtio-net";
    *) chr - improved boot time for Hyper-V installations;
    *) crs317 - fixed link flapping when inserted S+RJ10 module without any cable;
    *) crs317 - fixed link flapping when inserted S+RJ10 module without any cable;
    *) ipsec - added "responder" parameter for "mode-config" to allow multiple initiator configurations (CLI only);
    *) ipsec - added "src-address-list" parameter for "mode-config" that generates dynamic "src-nat" rule (CLI only);
    *) ipsec - added warning messages for incorrect peer configuration;
    *) ipsec - do not allow removal of "proposal" and "mode-config" entries that are in use;
    *) ipsec - install all DNS server addresses provided by "mode-config" server;
    *) ipsec - separate phase1 proposal configuration from peer menu (CLI only);
    *) led - improved w60g alignment trigger;
    *) log - show interface name on OSPF "different MTU" info log messages;
    *) lte - added extended LTE signal info for SIM7600 modules;
    *) lte - allow to use multiple PLS modems at the same time;
    *) lte - expose GPS channel for PLS modems;
    *) lte - fixed SIM7600 registration info;
    *) routerboard - allow to fill up to half of the RAM memory with files on devices with FLASH storage;
    *) winbox - added bridge Fast Forward statistics counters;
    *) winbox - allow to specify "any" as wireless "access-list" interface;
    *) winbox - fixed "/ip dhcp-server network set dns-none" parameter;
    *) winbox - fixed bridge port MAC learning parameter values;
    *) winbox - show "Switch" menu on hAP ac^2 devices;
    *) winbox - show HT MCS tab when "5ghz-n/ac" band is used;
    *) wireless - enable all chains by default on devices without external antennas after configuration reset;

  • Release 6.43rc4 2018-04-23

    What's new in 6.43rc4 (2018-Apr-23 10:59):

    !) winbox - fixed vulnerability that allowed to gain access to an unsecured router;
    *) bridge - added ingress filtering options to bridge interface (CLI only);
    *) bridge - fixed dynamic VLAN table entries when using ingress filtering;
    *) crs317 - fixed link flapping when inserted S+RJ10 module without any cable;
    *) ipsec - added "responder" parameter for "mode-config" to allow multiple initiator configurations (CLI only);
    *) ipsec - added "src-address-list" parameter for "mode-config" that generates dynamic "src-nat" rule (CLI only);
    *) ipsec - install all DNS server addresses provided by "mode-config" server;
    *) winbox - fixed "/ip dhcp-server network set dns-none" parameter;
    *) winbox - show "Switch" menu on hAP ac^2 devices;
    *) winbox - show HT MCS tab when "5ghz-n/ac" band is used;

    Other changes since v6.42:

    *) bridge - fixed hardware offloading for MMIPS and PPC devices;
    *) bridge - fixed LLDP packet receiving;
    *) certificate - add "expires-after" parameter (CLI only);
    *) chr - added checksum offload support for Hyper-V installations;
    *) chr - added large send offload support for Hyper-V installations;
    *) chr - added multiqueue support on Xen installations;
    *) chr - added support for multiqueue feature on "virtio-net";
    *) chr - added virtual Receive Side Scaling support for Hyper-V installations;
    *) chr - do not show IRQ entries from removed devices;
    *) chr - fixed NIC hotplug for "virtio-net";
    *) chr - improved boot time for Hyper-V installations;
    *) crs317 - fixed link flapping when inserted S+RJ10 module without any cable;
    *) crs3xx - fixed failing connections through bonding in bridge;
    *) ike2 - use "policy-template-group" parameter when picking proposal as initiator;
    *) ipsec - added warning messages for incorrect peer configuration;
    *) ipsec - do not allow removal of "proposal" and "mode-config" entries that are in use;
    *) ipsec - separate phase1 proposal configuration from peer menu (CLI only);
    *) led - added "dark-mode" functionality for hAP ac and hAP ac^2 devices;
    *) led - improved w60g alignment trigger;
    *) log - show interface name on OSPF "different MTU" info log messages;
    *) lte - added extended LTE signal info for SIM7600 modules;
    *) lte - allow to send "at-chat" command over disabled LTE interface;
    *) lte - allow to use multiple PLS modems at the same time;
    *) lte - expose GPS channel for PLS modems;
    *) lte - fixed SIM7600 registration info;
    *) routerboard - allow to fill up to half of the RAM memory with files on devices with FLASH storage;
    *) routerboard - fixed "mode-button" support on hAP lite r2 devices;
    *) w60g - allow to manually set "tx-sector" value;
    *) w60g - fixed incorrect RSSI readings;
    *) w60g - show phy rate on "/interface w60g monitor" (CLI only);
    *) winbox - added bridge Fast Forward statistics counters;
    *) winbox - allow to specify "any" as wireless "access-list" interface;
    *) winbox - fixed bridge port MAC learning parameter values;
    *) winbox - show "Switch" menu on cAP ac devices;
    *) winbox - show correct "Switch" menus on CRS328-24P-4S+;
    *) wireless - enable all chains by default on devices without external antennas after configuration reset;
    *) wireless - improved compatibility with BCM chipset devices;

  • Release 6.43rc3 2018-04-20

    What's new in 6.43rc3 (2018-Apr-20 08:46):

    *) bridge - fixed hardware offloading for MMIPS and PPC devices;
    *) bridge - fixed LLDP packet receiving;
    *) certificate - add "expires-after" parameter (CLI only);
    *) chr - added checksum offload support for Hyper-V installations;
    *) chr - added large send offload support for Hyper-V installations;
    *) chr - added multiqueue support on Xen installations;
    *) chr - added support for multiqueue feature on "virtio-net";
    *) chr - added virtual Receive Side Scaling support for Hyper-V installations;
    *) chr - do not show IRQ entries from removed devices;
    *) chr - fixed NIC hotplug for "virtio-net";
    *) chr - improved boot time for Hyper-V installations;
    *) crs317 - fixed link flapping when inserted S+RJ10 module without any cable;
    *) crs3xx - fixed failing connections through bonding in bridge;
    *) ike2 - use "policy-template-group" parameter when picking proposal as initiator;
    *) ipsec - added "responder" parameter for "mode-config" to allow multiple initiator configurations (CLI only);
    *) ipsec - added "src-address-list" parameter for "mode-config" that generates dynamic "src-nat" rule (CLI only);
    *) ipsec - added warning messages for incorrect peer configuration;
    *) ipsec - do not allow removal of "proposal" and "mode-config" entries that are in use;
    *) ipsec - separate phase1 proposal configuration from peer menu (CLI only);
    *) led - added "dark-mode" functionality for hAP ac and hAP ac^2 devices;
    *) led - improved w60g alignment trigger;
    *) log - show interface name on OSPF "different MTU" info log messages;
    *) lte - added extended LTE signal info for SIM7600 modules;
    *) lte - allow to send "at-chat" command over disabled LTE interface;
    *) lte - allow to use multiple PLS modems at the same time;
    *) lte - expose GPS channel for PLS modems;
    *) lte - fixed SIM7600 registration info;
    *) routerboard - allow to fill up to half of the RAM memory with files on devices with FLASH storage;
    *) routerboard - fixed "mode-button" support on hAP lite r2 devices;
    *) w60g - allow to manually set "tx-sector" value;
    *) w60g - fixed incorrect RSSI readings;
    *) w60g - show phy rate on "/interface w60g monitor" (CLI only);
    *) winbox - added bridge Fast Forward statistics counters;
    *) winbox - allow to specify "any" as wireless "access-list" interface;
    *) winbox - fixed "/ip dhcp-server network set dns-none" parameter;
    *) winbox - fixed bridge port MAC learning parameter values;
    *) winbox - show "Switch" menu on cAP ac devices;
    *) winbox - show correct "Switch" menus on CRS328-24P-4S+;
    *) wireless - enable all chains by default on devices without external antennas after configuration reset;
    *) wireless - improved compatibility with BCM chipset devices;

  • Release 6.42rc56 2018-04-09

    What's new in 6.42rc56 (2018-Apr-09 08:18):

    *) crs3xx - added initial “hw-offload” support for 802.3ad and “balance-xor” bonding;
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dns - do not generate "Undo" messages on changes to dynamic servers;
    *) ike2 - fixed framed IP address received from RADIUS server;
    *) ippool6 - added pool name to "no more addresses left" error message;
    *) ipv6 - fixed IPv6 behavior when slave leaves bridge;
    *) ipv6 - update IPv6 DNS from RA only when it is changed;
    *) led - added "Dark Mode" support for wAP 60G;
    *) led - added w60g alignment trigger;
    *) rb1100ahx4 - improved reliability on hardware encryption;
    *) w60g - added "tx-power" setting (CLI only);
    *) w60g - added RSSI information (CLI only);
    *) w60g - added TX sector alignment information (CLI only);
    *) winbox - fixed Neighbor Discovery and MAC Winbox (introduced in v6.42rc);
    *) wireless - fixed RB911-5HnD low transmit power issue;
    *) wireless - fixed wsAP wrong 5 GHz interface MAC address;

    Other changes since 6.41.3:

    !) tile - improved overall system performance and stability ("/system routerboard upgrade" required);
    !) w60g - increased supported distance for wAP 60G to 200+ meters;
    *) bridge - added host aging timer for crs3xx and Atheros hw-bridges;
    *) bridge - added per-port forwarding options for broadcasts, unknown-multicasts and unknown-unicasts (CLI only);
    *) bridge - added per-port learning options (CLI only);
    *) bridge - added support for static hosts;
    *) bridge - fixed "master-port" configuration conversion from pre-v6.41 RouterOS versions (introduced in 6.42rc);
    *) bridge - fixed bridge port interface parameter under "/interface bridge host print detail";
    *) bridge - fixed false MAC address learning on hAP ac2 and cAP ac devices;
    *) bridge - fixed incorrect "fast-forward" enabling when ports were switched;
    *) bridge - fixed MAC learning for VRRP interfaces on bridge;
    *) bridge - fixed reliability on software bridges when used on devices without switch chip;
    *) bridge - hide options for disabled bridge features in CLI;
    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - added "allow-signal-out-of-range" option for Access List entries;
    *) capsman - added support for "interface-list" in Access List and Datapath entries;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) capsman - log "signal-strength" when successfully connected to AP;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) certificate - fixed incorrect SCEP URL after an upgrade;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" and "virtio-scsi" driver on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - added support for "multi-queue" feature for "virtio-net" driver;
    *) chr - added support for Amazon Elastic Network Adapter (ENA) driver;
    *) chr - added support for booting from NVMe disks;
    *) chr - added support for Hyper-V ballooning, guest quiescing, host-guest file transfer, integration services and static IP injection;
    *) chr - added support for NIC hot-plug on VMware and Xen installations;
    *) chr - fixed additional disk detaching on Xen installations;
    *) chr - fixed interface matching by name on VMware installations;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) chr - run startup scripts also on the first boot on AWS and Google Cloud installations;
    *) console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38;
    *) console - improved console stability after it has not been used for a long time;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs212 - fixed Ethernet boot through CRS326 devices;
    *) crs326 - fixed known multicast flooding to the CPU;
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced in v6.41);
    *) dhcp - improved DHCP service reliability when it is configured on bridge interface;
    *) dhcp - reduced resource usage of DHCP services;
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) email - set maximum number of sessions to 100;
    *) fetch - added "http-content-type" option to allow setting MIME type of the data in free text form;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) fetch - increased maximum number of sessions to 100;
    *) filesystem - implemented additional system storage maintenance checks on ARM CPU based devices;
    *) flashfig - properly apply configuration provided by Flashfig;
    *) gps - improved NMEA sentence handling;
    *) health - fixed empty measurements on CRS328-24P-4S+RM;
    *) health - log warning when switching between redundant power supplies;
    *) hotspot - improved HTTPS matching in Walled Garden rules;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) ike1 - fixed wildcard policy lookup on responder;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) ipsec - improved single tunnel hardware acceleration performance on MMIPS platform devices;
    *) ipsec - properly detect interface for "mode-config" client IP address assignment;
    *) kidcontrol - initial work on "/ip kid-control" feature;
    *) led - fixed unused "link-act-led" LED trigger on RBLHG 2nD, RBLHG 2nD-XL and RBSXTsq 2nD;
    *) led - removed unused "link-act-led" trigger for devices which does not use it;
    *) lte - added initial support for Quectel LTE EP06-E;
    *) lte - added initial support for SIM7600 LTE modem interface;
    *) lte - added support for the user and password authentication for wAP-LTE-kit-US (R11e-LTE-US);
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) lte - fixed LTE band setting for SXT LTE;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) netinstall - sign Netinstall executable with an Extended Validation Code Signing Certificate;
    *) netwatch - limit to read, write, test and reboot policies for Netwatch script execution;
    *) poe - hide PoE related properties on interfaces which does not provide power output;
    *) poe - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - by default use "/24" subnet for local network;
    *) quickset - fixed NAT if PPPoE client is used for Internet access;
    *) quickset - properly detect IP address when one of the bridge modes is used;
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) r11e-lte - improved LTE connection initialization process;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) routerboard - properly detect hAP ac^2 RAM size;
    *) routerboot - fixed RouterBOOT upgrade process (introduced in v6.42rc);
    *) sniffer - fixed situation when "/tool sniffer packet" returned packets in incorrect order;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added "/interface w60g print oid";
    *) snmp - added "board-name" OID;
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - fixed SSH service becoming unavailable;
    *) ssh - generate SSH keys only on the first connect attempt instead of the first boot;
    *) ssh - improved key import error messages;
    *) ssh - remove imported public SSH keys when their owner user is removed;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - correctly return “TransferComplete” after vendor configuration file transfer;
    *) tr069-client - fixed "/tool fetch" commands executed with ".alter" script;
    *) tr069-client - fixed HTTPS authentication process;
    *) traffic-flow - fixed IPv6 destination address value when IPFIX protocol is used;
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) ups - improved communication between router and UPS;
    *) ups - improved disconnect message handling between RouterOS and UPS;
    *) userman - added support for ARM and MMIPS platform;
    *) watchdog - retry to send "autosupout.rif" file to an e-mail if initial delivery failed up to 3 times within 20 second interval;
    *) winbox - added "antenna" setting under GPS settings for MIPS platform devices;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added "use-dn" setting in OSPF instance General menu;
    *) winbox - added 160 MHz "channel-width" to wireless settings;
    *) winbox - added broadcast and flood settings to bridge ports;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added missing protocol numbers to IPv4 and IPv6 firewall;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed name for "out-bridge-list" parameter under bridge firewall rules;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - made UDP local and remote TX size parameters optional in Bandwidth Test tool;
    *) winbox - moved "ageing-time" setting from STP to General tab;
    *) winbox - moved OSPF instance "routing-table" setting in OSPF instance General menu;
    *) winbox - removed “VLAN” section from “Switch” menu for CRS3xx devices;
    *) winbox - show Bridge Port PVID column by default;
    *) winbox - show CQI in LTE info;
    *) winbox - show dual SIM options only for RouterBOARDS which does have two SIM slots;
    *) winbox - show only master CAP interfaces under CAPsMAN wireless scan tool;
    *) winbox - use proper graph name for HDD graphs;
    *) wireless - added "realm-raw" setting for "/interface wireless interworking-profiles" (CLI only);
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added support for "band=5ghz-n/ac";
    *) wireless - added support for "interface-list" for Access List entries;
    *) wireless - added support for legacy AR9485 chipset;
    *) wireless - enable all chains by default on devices without external antennas after configuration reset;
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed long "scan-list" entries not working for ARM based wireless interfaces;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - fixed RTS/CTS option for the ARM based wireless devices;
    *) wireless - improved compatibility with specific wireless AC standard clients;
    *) wireless - improved Nv2 PtMP performance;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality;
    *) wireless - improved wireless stability on hAP ac2 devices while USB is being used;

  • Release 6.42rc52 2018-03-27

    What's new in 6.42rc52 (2018-Mar-26 12:41):

    *) bridge - fixed "master-port" configuration conversion from pre-v6.41 RouterOS versions (introduced in 6.42rc);
    *) certificate - fixed incorrect SCEP URL after an upgrade;
    *) chr - added support for "multi-queue" feature for "virtio-net" driver;
    *) chr - added support for Amazon Elastic Network Adapter (ENA) driver;
    *) chr - added support for booting from NVMe disks;
    *) chr - fixed interface matching by name on VMware installations;
    *) chr - run startup scripts also on the first boot on AWS and Google Cloud installations;
    *) crs3xx - added initial “hw-offload” support for 802.3ad and “balance-xor” bonding;
    *) led - fixed unused "link-act-led" LED trigger on RBLHG 2nD, RBLHG 2nD-XL and RBSXTsq 2nD;
    *) lte - added initial support for Quectel LTE EP06-E;
    *) lte - fixed LTE band setting for SXT LTE;
    *) routerboard - properly detect hAP ac^2 RAM size;
    *) ssh - fixed SSH service becoming unavailable;
    *) traffic-flow - fixed IPv6 destination address value when IPFIX protocol is used;
    *) watchdog - retry to send "autosupout.rif" file to an e-mail if initial delivery failed up to 3 times within 20 second interval;

    Other changes since 6.41.3:

    !) tile - improved overall system performance and stability ("/system routerboard upgrade" required);
    !) w60g - increased supported distance for wAP 60G to 200+ meters;
    *) bridge - added host aging timer for crs3xx and Atheros hw-bridges;
    *) bridge - added per-port forwarding options for broadcasts, unknown-multicasts and unknown-unicasts (CLI only);
    *) bridge - added per-port learning options (CLI only);
    *) bridge - added support for static hosts;
    *) bridge - fixed bridge port interface parameter under "/interface bridge host print detail";
    *) bridge - fixed false MAC address learning on hAP ac2 and cAP ac devices;
    *) bridge - fixed incorrect "fast-forward" enabling when ports were switched;
    *) bridge - fixed MAC learning for VRRP interfaces on bridge;
    *) bridge - fixed reliability on software bridges when used on devices without switch chip;
    *) bridge - hide options for disabled bridge features in CLI;
    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - added "allow-signal-out-of-range" option for Access List entries;
    *) capsman - added support for "interface-list" in Access List and Datapath entries;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) capsman - log "signal-strength" when successfully connected to AP;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" and "virtio-scsi" driver on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - added support for Hyper-V ballooning, guest quiescing, host-guest file transfer, integration services and static IP injection;
    *) chr - added support for NIC hot-plug on VMware and Xen installations;
    *) chr - fixed additional disk detaching on Xen installations;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38;
    *) console - improved console stability after it has not been used for a long time;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs212 - fixed Ethernet boot through CRS326 devices;
    *) crs326 - fixed known multicast flooding to the CPU;
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced in v6.41);
    *) dhcp - improved DHCP service reliability when it is configured on bridge interface;
    *) dhcp - reduced resource usage of DHCP services;
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) email - set maximum number of sessions to 100;
    *) fetch - added "http-content-type" option to allow setting MIME type of the data in free text form;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) fetch - increased maximum number of sessions to 100;
    *) filesystem - implemented additional system storage maintenance checks on ARM CPU based devices;
    *) flashfig - properly apply configuration provided by Flashfig;
    *) gps - improved NMEA sentence handling;
    *) health - fixed empty measurements on CRS328-24P-4S+RM;
    *) health - log warning when switching between redundant power supplies;
    *) hotspot - improved HTTPS matching in Walled Garden rules;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) ike1 - fixed wildcard policy lookup on responder;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) ipsec - improved single tunnel hardware acceleration performance on MMIPS platform devices;
    *) ipsec - properly detect interface for "mode-config" client IP address assignment;
    *) kidcontrol - initial work on "/ip kid-control" feature;
    *) led - removed unused "link-act-led" trigger for devices which does not use it;
    *) lte - added initial support for SIM7600 LTE modem interface;
    *) lte - added support for the user and password authentication for wAP-LTE-kit-US (R11e-LTE-US);
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) netinstall - sign Netinstall executable with an Extended Validation Code Signing Certificate;
    *) netwatch - limit to read, write, test and reboot policies for Netwatch script execution;
    *) poe - hide PoE related properties on interfaces which does not provide power output;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - by default use "/24" subnet for local network;
    *) quickset - fixed NAT if PPPoE client is used for Internet access;
    *) quickset - properly detect IP address when one of the bridge modes is used;
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) r11e-lte - improved LTE connection initialization process;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) routerboot - fixed RouterBOOT upgrade process (introduced in v6.42rc);
    *) sniffer - fixed situation when "/tool sniffer packet" returned packets in incorrect order;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added "/interface w60g print oid";
    *) snmp - added "board-name" OID;
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - generate SSH keys only on the first connect attempt instead of the first boot;
    *) ssh - improved key import error messages;
    *) ssh - remove imported public SSH keys when their owner user is removed;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - correctly return “TransferComplete” after vendor configuration file transfer;
    *) tr069-client - fixed "/tool fetch" commands executed with ".alter" script;
    *) tr069-client - fixed HTTPS authentication process;
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) ups - improved communication between router and UPS;
    *) ups - improved disconnect message handling between RouterOS and UPS;
    *) userman - added support for ARM and MMIPS platform;
    *) winbox - added "antenna" setting under GPS settings for MIPS platform devices;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added "use-dn" setting in OSPF instance General menu;
    *) winbox - added 160 MHz "channel-width" to wireless settings;
    *) winbox - added broadcast and flood settings to bridge ports;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added missing protocol numbers to IPv4 and IPv6 firewall;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed name for "out-bridge-list" parameter under bridge firewall rules;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - made UDP local and remote TX size parameter optional in Bandwidth Test tool;
    *) winbox - moved "ageing-time" setting from STP to General tab;
    *) winbox - moved OSPF instance "routing-table" setting in OSPF instance General menu;
    *) winbox - removed “VLAN” section from “Switch” menu for CRS3xx devices;
    *) winbox - show Bridge Port PVID column by default;
    *) winbox - show CQI in LTE info;
    *) winbox - show only master CAP interfaces under CAPsMAN wireless scan tool;
    *) winbox - use proper graph name for HDD graphs;
    *) wireless - added "realm-raw" setting for "/interface wireless interworking-profiles" (CLI only);
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added support for "band=5ghz-n/ac";
    *) wireless - added support for "interface-list" for Access List entries;
    *) wireless - added support for legacy AR9485 chipset;
    *) wireless - enable all chains by default on devices without external antennas after configuration reset;
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed long "scan-list" entries not working for ARM based wireless interfaces;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - fixed RTS/CTS option for the ARM based wireless devices;
    *) wireless - improved compatibility with specific wireless AC standard clients;
    *) wireless - improved Nv2 PtMP performance;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality;
    *) wireless - improved wireless stability on hAP ac2 devices while USB is being used;

  • Release 6.42rc49 2018-03-21

    What's new in 6.42rc49 (2018-Mar-21 12:34):

    *) w60g/Wireless-Wire - increased supported distance for wAP 60G to 200+ meters;

    Other changes since 6.41.3:

    !) tile - improved overall system performance and stability ("/system routerboard upgrade" required);
    *) bridge - added host aging timer for crs3xx and Atheros hw-bridges;
    *) bridge - added per-port forwarding options for broadcasts, unknown-multicasts and unknown-unicasts (CLI only);
    *) bridge - added per-port learning options (CLI only);
    *) bridge - added support for static hosts;
    *) bridge - fixed bridge port interface parameter under "/interface bridge host print detail";
    *) bridge - fixed false MAC address learning on hAP ac2 and cAP ac devices;
    *) bridge - fixed incorrect "fast-forward" enabling when ports were switched;
    *) bridge - fixed MAC learning for VRRP interfaces on bridge;
    *) bridge - fixed reliability on software bridges when used on devices without switch chip;
    *) bridge - hide options for disabled bridge features in CLI;
    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - added "allow-signal-out-of-range" option for Access List entries;
    *) capsman - added support for "interface-list" in Access List and Datapath entries;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) capsman - log "signal-strength" when successfully connected to AP;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" and "virtio-scsi" driver on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - added support for Hyper-V ballooning, guest quiescing, host-guest file transfer, integration services and static IP injection;
    *) chr - added support for NIC hot-plug on VMware and Xen installations;
    *) chr - fixed additional disk detaching on Xen installations;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38;
    *) console - improved console stability after it has not been used for a long time;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs212 - fixed Ethernet boot through CRS326 devices;
    *) crs326 - fixed known multicast flooding to the CPU;
    *) crs3xx - added initial “hw-offload” support for 802.3ad and “balance-xor” bonding;
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced in v6.41);
    *) dhcp - improved DHCP service reliability when it is configured on bridge interface;
    *) dhcp - reduced resource usage of DHCP services;
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) email - set maximum number of sessions to 100;
    *) fetch - added "http-content-type" option to allow setting MIME type of the data in free text form;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) fetch - increased maximum number of sessions to 100;
    *) filesystem - implemented additional system storage maintenance checks on ARM CPU based devices;
    *) flashfig - properly apply configuration provided by Flashfig;
    *) gps - improved NMEA sentence handling;
    *) health - fixed empty measurements on CRS328-24P-4S+RM;
    *) health - log warning when switching between redundant power supplies;
    *) hotspot - improved HTTPS matching in Walled Garden rules;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) ike1 - fixed wildcard policy lookup on responder;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) ipsec - improved single tunnel hardware acceleration performance on MMIPS platform devices;
    *) ipsec - properly detect interface for "mode-config" client IP address assignment;
    *) kidcontrol - initial work on "/ip kid-control" feature;
    *) led - removed unused "link-act-led" trigger for devices which does not use it;
    *) lte - added initial support for SIM7600 LTE modem interface;
    *) lte - added support for the user and password authentication for wAP-LTE-kit-US (R11e-LTE-US);
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) netinstall - sign Netinstall executable with an Extended Validation Code Signing Certificate;
    *) netwatch - limit to read, write, test and reboot policies for Netwatch script execution;
    *) poe - hide PoE related properties on interfaces which does not provide power output;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - by default use "/24" subnet for local network;
    *) quickset - fixed NAT if PPPoE client is used for Internet access;
    *) quickset - properly detect IP address when one of the bridge modes is used;
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) r11e-lte - improved LTE connection initialization process;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) routerboot - fixed RouterBOOT upgrade process (introduced in v6.42rc);
    *) sniffer - fixed situation when "/tool sniffer packet" returned packets in incorrect order;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added "/interface w60g print oid";
    *) snmp - added "board-name" OID;
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - generate SSH keys only on the first connect attempt instead of the first boot;
    *) ssh - improved key import error messages;
    *) ssh - remove imported public SSH keys when their owner user is removed;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - correctly return “TransferComplete” after vendor configuration file transfer;
    *) tr069-client - fixed "/tool fetch" commands executed with ".alter" script;
    *) tr069-client - fixed HTTPS authentication process;
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) ups - improved communication between router and UPS;
    *) ups - improved disconnect message handling between RouterOS and UPS;
    *) userman - added support for ARM and MMIPS platform;
    *) winbox - added "antenna" setting under GPS settings for MIPS platform devices;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added "use-dn" setting in OSPF instance General menu;
    *) winbox - added 160 MHz "channel-width" to wireless settings;
    *) winbox - added broadcast and flood settings to bridge ports;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added missing protocol numbers to IPv4 and IPv6 firewall;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed name for "out-bridge-list" parameter under bridge firewall rules;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - made UDP local and remote TX size parameter optional in Bandwidth Test tool;
    *) winbox - moved "ageing-time" setting from STP to General tab;
    *) winbox - moved OSPF instance "routing-table" setting in OSPF instance General menu;
    *) winbox - removed “VLAN” section from “Switch” menu for CRS3xx devices;
    *) winbox - show Bridge Port PVID column by default;
    *) winbox - show CQI in LTE info;
    *) winbox - show only master CAP interfaces under CAPsMAN wireless scan tool;
    *) winbox - use proper graph name for HDD graphs;
    *) wireless - added "realm-raw" setting for "/interface wireless interworking-profiles" (CLI only);
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added support for "band=5ghz-n/ac";
    *) wireless - added support for "interface-list" for Access List entries;
    *) wireless - added support for legacy AR9485 chipset;
    *) wireless - enable all chains by default on devices without external antennas after configuration reset;
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed long "scan-list" entries not working for ARM based wireless interfaces;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - fixed RTS/CTS option for the ARM based wireless devices;
    *) wireless - improved compatibility with specific wireless AC standard clients;
    *) wireless - improved Nv2 PtMP performance;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality;
    *) wireless - improved wireless stability on hAP ac2 devices while USB is being used;

  • Release 6.42rc48 2018-03-21

    What's new in 6.42rc48 (2018-Mar-21 11:13):

    *) health - fixed empty measurements on CRS328-24P-4S+RM;
    *) led - removed unused "link-act-led" trigger for devices which does not use it;
    *) ups - improved communication between router and UPS;
    *) wireless - improved Nv2 PtMP performance;

    Other changes since 6.41.3:

    !) tile - improved overall system performance and stability ("/system routerboard upgrade" required);
    *) bridge - added host aging timer for crs3xx and Atheros hw-bridges;
    *) bridge - added per-port forwarding options for broadcasts, unknown-multicasts and unknown-unicasts (CLI only);
    *) bridge - added per-port learning options (CLI only);
    *) bridge - added support for static hosts;
    *) bridge - fixed bridge port interface parameter under "/interface bridge host print detail";
    *) bridge - fixed false MAC address learning on hAP ac2 and cAP ac devices;
    *) bridge - fixed incorrect "fast-forward" enabling when ports were switched;
    *) bridge - fixed MAC learning for VRRP interfaces on bridge;
    *) bridge - fixed reliability on software bridges when used on devices without switch chip;
    *) bridge - hide options for disabled bridge features in CLI;
    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - added "allow-signal-out-of-range" option for Access List entries;
    *) capsman - added support for "interface-list" in Access List and Datapath entries;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) capsman - log "signal-strength" when successfully connected to AP;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" and "virtio-scsi" driver on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - added support for Hyper-V ballooning, guest quiescing, host-guest file transfer, integration services and static IP injection;
    *) chr - added support for NIC hot-plug on VMware and Xen installations;
    *) chr - fixed additional disk detaching on Xen installations;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38;
    *) console - improved console stability after it has not been used for a long time;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs212 - fixed Ethernet boot through CRS326 devices;
    *) crs326 - fixed known multicast flooding to the CPU;
    *) crs3xx - added initial “hw-offload” support for 802.3ad and “balance-xor” bonding;
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced in v6.41);
    *) dhcp - improved DHCP service reliability when it is configured on bridge interface;
    *) dhcp - reduced resource usage of DHCP services;
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) email - set maximum number of sessions to 100;
    *) fetch - added "http-content-type" option to allow setting MIME type of the data in free text form;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) fetch - increased maximum number of sessions to 100;
    *) filesystem - implemented additional system storage maintenance checks on ARM CPU based devices;
    *) flashfig - properly apply configuration provided by Flashfig;
    *) gps - improved NMEA sentence handling;
    *) health - log warning when switching between redundant power supplies;
    *) hotspot - improved HTTPS matching in Walled Garden rules;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) ike1 - fixed wildcard policy lookup on responder;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) ipsec - improved single tunnel hardware acceleration performance on MMIPS platform devices;
    *) ipsec - properly detect interface for "mode-config" client IP address assignment;
    *) kidcontrol - initial work on "/ip kid-control" feature;
    *) lte - added initial support for SIM7600 LTE modem interface;
    *) lte - added support for the user and password authentication for wAP-LTE-kit-US (R11e-LTE-US);
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) netinstall - sign Netinstall executable with an Extended Validation Code Signing Certificate;
    *) netwatch - limit to read, write, test and reboot policies for Netwatch script execution;
    *) poe - hide PoE related properties on interfaces which does not provide power output;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - by default use "/24" subnet for local network;
    *) quickset - fixed NAT if PPPoE client is used for Internet access;
    *) quickset - properly detect IP address when one of the bridge modes is used;
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) r11e-lte - improved LTE connection initialization process;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) routerboot - fixed RouterBOOT upgrade process (introduced in v6.42rc);
    *) sniffer - fixed situation when "/tool sniffer packet" returned packets in incorrect order;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added "/interface w60g print oid";
    *) snmp - added "board-name" OID;
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - generate SSH keys only on the first connect attempt instead of the first boot;
    *) ssh - improved key import error messages;
    *) ssh - remove imported public SSH keys when their owner user is removed;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - correctly return “TransferComplete” after vendor configuration file transfer;
    *) tr069-client - fixed "/tool fetch" commands executed with ".alter" script;
    *) tr069-client - fixed HTTPS authentication process;
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) ups - improved disconnect message handling between RouterOS and UPS;
    *) userman - added support for ARM and MMIPS platform;
    *) winbox - added "antenna" setting under GPS settings for MIPS platform devices;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added "use-dn" setting in OSPF instance General menu;
    *) winbox - added 160 MHz "channel-width" to wireless settings;
    *) winbox - added broadcast and flood settings to bridge ports;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added missing protocol numbers to IPv4 and IPv6 firewall;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed name for "out-bridge-list" parameter under bridge firewall rules;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - made UDP local and remote TX size parameter optional in Bandwidth Test tool;
    *) winbox - moved "ageing-time" setting from STP to General tab;
    *) winbox - moved OSPF instance "routing-table" setting in OSPF instance General menu;
    *) winbox - removed “VLAN” section from “Switch” menu for CRS3xx devices;
    *) winbox - show Bridge Port PVID column by default;
    *) winbox - show CQI in LTE info;
    *) winbox - show only master CAP interfaces under CAPsMAN wireless scan tool;
    *) winbox - use proper graph name for HDD graphs;
    *) wireless - added "realm-raw" setting for "/interface wireless interworking-profiles" (CLI only);
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added support for "band=5ghz-n/ac";
    *) wireless - added support for "interface-list" for Access List entries;
    *) wireless - added support for legacy AR9485 chipset;
    *) wireless - enable all chains by default on devices without external antennas after configuration reset;
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed long "scan-list" entries not working for ARM based wireless interfaces;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - fixed RTS/CTS option for the ARM based wireless devices;
    *) wireless - improved compatibility with specific wireless AC standard clients;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality;
    *) wireless - improved wireless stability on hAP ac2 devices while USB is being used;

  • Release 6.42rc46 2018-03-20

    What's new in 6.42rc46 (2018-Mar-20 05:53):

    *) dhcp - improved DHCP service reliability when it is configured on bridge interface;
    *) dhcp - reduced resource usage of DHCP services;
    *) netinstall - sign Netinstall executable with an Extended Validation Code Signing Certificate;
    *) quickset - by default use "/24" subnet for local network;
    *) quickset - properly detect IP address when one of the bridge modes is used;
    *) routerboot - fixed RouterBOOT upgrade process (introduced in v6.42rc);
    *) winbox - added "use-dn" setting in OSPF instance General menu;
    *) winbox - moved OSPF instance "routing-table" setting in OSPF instance General menu;
    *) winbox - use proper graph name for HDD graphs;
    *) wireless - improved Nv2 PtMP performance;

    Other changes since 6.41.3:

    !) tile - improved overall system performance and stability ("/system routerboard upgrade" required);
    *) bridge - added host aging timer for crs3xx and Atheros hw-bridges;
    *) bridge - added per-port forwarding options for broadcasts, unknown-multicasts and unknown-unicasts (CLI only);
    *) bridge - added per-port learning options (CLI only);
    *) bridge - added support for static hosts;
    *) bridge - fixed bridge port interface parameter under "/interface bridge host print detail";
    *) bridge - fixed false MAC address learning on hAP ac2 and cAP ac devices;
    *) bridge - fixed incorrect "fast-forward" enabling when ports were switched;
    *) bridge - fixed MAC learning for VRRP interfaces on bridge;
    *) bridge - fixed reliability on software bridges when used on devices without switch chip;
    *) bridge - hide options for disabled bridge features in CLI;
    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - added "allow-signal-out-of-range" option for Access List entries;
    *) capsman - added support for "interface-list" in Access List and Datapath entries;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) capsman - log "signal-strength" when successfully connected to AP;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" and "virtio-scsi" driver on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - added support for Hyper-V ballooning, guest quiescing, host-guest file transfer, integration services and static IP injection;
    *) chr - added support for NIC hot-plug on VMware and Xen installations;
    *) chr - fixed additional disk detaching on Xen installations;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38;
    *) console - improved console stability after it has not been used for a long time;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs212 - fixed Ethernet boot through CRS326 devices;
    *) crs326 - fixed known multicast flooding to the CPU;
    *) crs3xx - added initial “hw-offload” support for 802.3ad and “balance-xor” bonding;
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced in v6.41);
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) email - set maximum number of sessions to 100;
    *) fetch - added "http-content-type" option to allow setting MIME type of the data in free text form;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) fetch - increased maximum number of sessions to 100;
    *) filesystem - implemented additional system storage maintenance checks on ARM CPU based devices;
    *) flashfig - properly apply configuration provided by Flashfig;
    *) gps - improved NMEA sentence handling;
    *) health - log warning when switching between redundant power supplies;
    *) hotspot - improved HTTPS matching in Walled Garden rules;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) ike1 - fixed wildcard policy lookup on responder;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) ipsec - improved single tunnel hardware acceleration performance on MMIPS platform devices;
    *) ipsec - properly detect interface for "mode-config" client IP address assignment;
    *) kidcontrol - initial work on "/ip kid-control" feature;
    *) lte - added initial support for SIM7600 LTE modem interface;
    *) lte - added support for the user and password authentication for wAP-LTE-kit-US (R11e-LTE-US);
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) netwatch - limit to read, write, test and reboot policies for Netwatch script execution;
    *) poe - hide PoE related properties on interfaces which does not provide power output;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - fixed NAT if PPPoE client is used for Internet access;
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) r11e-lte - improved LTE connection initialization process;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) sniffer - fixed situation when "/tool sniffer packet" returned packets in incorrect order;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added "/interface w60g print oid";
    *) snmp - added "board-name" OID;
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - generate SSH keys only on the first connect attempt instead of the first boot;
    *) ssh - improved key import error messages;
    *) ssh - remove imported public SSH keys when their owner user is removed;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - correctly return “TransferComplete” after vendor configuration file transfer;
    *) tr069-client - fixed "/tool fetch" commands executed with ".alter" script;
    *) tr069-client - fixed HTTPS authentication process;
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) ups - improved disconnect message handling between RouterOS and UPS;
    *) userman - added support for ARM and MMIPS platform;
    *) winbox - added "antenna" setting under GPS settings for MIPS platform devices;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added 160 MHz "channel-width" to wireless settings;
    *) winbox - added broadcast and flood settings to bridge ports;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added missing protocol numbers to IPv4 and IPv6 firewall;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed name for "out-bridge-list" parameter under bridge firewall rules;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - made UDP local and remote TX size parameter optional in Bandwidth Test tool;
    *) winbox - moved "ageing-time" setting from STP to General tab;
    *) winbox - removed “VLAN” section from “Switch” menu for CRS3xx devices;
    *) winbox - show Bridge Port PVID column by default;
    *) winbox - show CQI in LTE info;
    *) winbox - show only master CAP interfaces under CAPsMAN wireless scan tool;
    *) wireless - added "realm-raw" setting for "/interface wireless interworking-profiles" (CLI only);
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added support for "band=5ghz-n/ac";
    *) wireless - added support for "interface-list" for Access List entries;
    *) wireless - added support for legacy AR9485 chipset;
    *) wireless - enable all chains by default on devices without external antennas after configuration reset;
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed long "scan-list" entries not working for ARM based wireless interfaces;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - fixed RTS/CTS option for the ARM based wireless devices;
    *) wireless - improved compatibility with specific wireless AC standard clients;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality;
    *) wireless - improved wireless stability on hAP ac2 devices while USB is being used;

  • Release 6.42rc43 2018-03-15

    What's new in 6.42rc43 (2018-Mar-14 10:45):

    !) tile - improved overall system performance and stability ("/system routerboard upgrade" required);
    *) crs326 - fixed known multicast flooding to the CPU;
    *) dhcp - improved DHCP service reliability when it is configured on bridge interface;
    *) ssh - generate SSH keys only on the first connect attempt instead of the first boot;
    *) ups - improved disconnect message handling between RouterOS and UPS;
    *) wireless - enable all chains by default on devices without external antennas after configuration reset;

    Other changes since 6.41.3:

    *) bridge - added host aging timer for crs3xx and Atheros hw-bridges;
    *) bridge - added per-port forwarding options for broadcasts, unknown-multicasts and unknown-unicasts (CLI only);
    *) bridge - added per-port learning options (CLI only);
    *) bridge - added support for static hosts;
    *) bridge - fixed bridge port interface parameter under "/interface bridge host print detail";
    *) bridge - fixed false MAC address learning on hAP ac2 and cAP ac devices;
    *) bridge - fixed incorrect "fast-forward" enabling when ports were switched;
    *) bridge - fixed MAC learning for VRRP interfaces on bridge;
    *) bridge - fixed reliability on software bridges when used on devices without switch chip;
    *) bridge - hide options for disabled bridge features in CLI;
    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - added "allow-signal-out-of-range" option for Access List entries;
    *) capsman - added support for "interface-list" in Access List and Datapath entries;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) capsman - log "signal-strength" when successfully connected to AP;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" and "virtio-scsi" driver on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - added support for Hyper-V ballooning, guest quiescing, host-guest file transfer, integration services and static IP injection;
    *) chr - added support for NIC hot-plug on VMware and Xen installations;
    *) chr - fixed additional disk detaching on Xen installations;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38;
    *) console - improved console stability after it has not been used for a long time;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs212 - fixed Ethernet boot through CRS326 devices;
    *) crs3xx - added initial “hw-offload” support for 802.3ad and “balance-xor” bonding;
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced in v6.41);
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) email - set maximum number of sessions to 100;
    *) fetch - added "http-content-type" option to allow setting MIME type of the data in free text form;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) fetch - increased maximum number of sessions to 100;
    *) filesystem - implemented additional system storage maintenance checks on ARM CPU based devices;
    *) flashfig - properly apply configuration provided by Flashfig;
    *) gps - improved NMEA sentence handling;
    *) health - log warning when switching between redundant power supplies;
    *) hotspot - improved HTTPS matching in Walled Garden rules;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) ike1 - fixed wildcard policy lookup on responder;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) ipsec - improved single tunnel hardware acceleration performance on MMIPS platform devices;
    *) ipsec - properly detect interface for "mode-config" client IP address assignment;
    *) kidcontrol - initial work on "/ip kid-control" feature;
    *) lte - added initial support for SIM7600 LTE modem interface;
    *) lte - added support for the user and password authentication for wAP-LTE-kit-US (R11e-LTE-US);
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) netwatch - limit to read, write, test and reboot policies for Netwatch script execution;
    *) poe - hide PoE related properties on interfaces which does not provide power output;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - fixed NAT if PPPoE client is used for Internet access;
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) r11e-lte - improved LTE connection initialization process;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) sniffer - fixed situation when "/tool sniffer packet" returned packets in incorrect order;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added "/interface w60g print oid";
    *) snmp - added "board-name" OID;
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - improved key import error messages;
    *) ssh - remove imported public SSH keys when their owner user is removed;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - correctly return “TransferComplete” after vendor configuration file transfer;
    *) tr069-client - fixed "/tool fetch" commands executed with ".alter" script;
    *) tr069-client - fixed HTTPS authentication process;
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) userman - added support for ARM and MMIPS platform;
    *) winbox - added "antenna" setting under GPS settings for MIPS platform devices;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added 160 MHz "channel-width" to wireless settings;
    *) winbox - added broadcast and flood settings to bridge ports;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added missing protocol numbers to IPv4 and IPv6 firewall;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed name for "out-bridge-list" parameter under bridge firewall rules;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - made UDP local and remote TX size parameter optional in Bandwidth Test tool;
    *) winbox - moved "ageing-time" setting from STP to General tab;
    *) winbox - removed “VLAN” section from “Switch” menu for CRS3xx devices;
    *) winbox - show Bridge Port PVID column by default;
    *) winbox - show CQI in LTE info;
    *) winbox - show only master CAP interfaces under CAPsMAN wireless scan tool;
    *) wireless - added "realm-raw" setting for "/interface wireless interworking-profiles" (CLI only);
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added support for "band=5ghz-n/ac";
    *) wireless - added support for "interface-list" for Access List entries;
    *) wireless - added support for legacy AR9485 chipset;
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed long "scan-list" entries not working for ARM based wireless interfaces;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - fixed RTS/CTS option for the ARM based wireless devices;
    *) wireless - improved compatibility with specific wireless AC standard clients;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality;
    *) wireless - improved wireless stability on hAP ac2 devices while USB is being used;

  • Release 6.42rc41 2018-03-12

    What's new in 6.42rc41 (2018-Mar-09 08:01):

    *) ipsec - improved single tunnel hardware acceleration performance on MMIPS platform devices;
    *) snmp - added "board-name" OID;

    Other changes since 6.41.3:

    *) bridge - added host aging timer for crs3xx and Atheros hw-bridges;
    *) bridge - added per-port forwarding options for broadcasts, unknown-multicasts and unknown-unicasts (CLI only);
    *) bridge - added per-port learning options (CLI only);
    *) bridge - added support for static hosts;
    *) bridge - fixed bridge port interface parameter under "/interface bridge host print detail";
    *) bridge - fixed false MAC address learning on hAP ac2 and cAP ac devices;
    *) bridge - fixed incorrect "fast-forward" enabling when ports were switched;
    *) bridge - fixed MAC learning for VRRP interfaces on bridge;
    *) bridge - fixed reliability on software bridges when used on devices without switch chip;
    *) bridge - hide options for disabled bridge features in CLI;
    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - added "allow-signal-out-of-range" option for Access List entries;
    *) capsman - added support for "interface-list" in Access List and Datapath entries;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) capsman - log "signal-strength" when successfully connected to AP;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" and "virtio-scsi" driver on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - added support for Hyper-V ballooning, guest quiescing, host-guest file transfer, integration services and static IP injection;
    *) chr - added support for NIC hot-plug on VMware and Xen installations;
    *) chr - fixed additional disk detaching on Xen installations;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38;
    *) console - improved console stability after it has not been used for a long time;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs212 - fixed Ethernet boot through CRS326 devices;
    *) crs3xx - added initial “hw-offload” support for 802.3ad and “balance-xor” bonding;
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced in v6.41);
    *) dhcp - improved DHCP service reliability when it is configured on bridge interface;
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) email - set maximum number of sessions to 100;
    *) fetch - added "http-content-type" option to allow setting MIME type of the data in free text form;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) fetch - increased maximum number of sessions to 100;
    *) filesystem - implemented additional system storage maintenance checks on ARM CPU based devices;
    *) flashfig - properly apply configuration provided by Flashfig;
    *) gps - improved NMEA sentence handling;
    *) health - log warning when switching between redundant power supplies;
    *) hotspot - improved HTTPS matching in Walled Garden rules;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) ike1 - fixed wildcard policy lookup on responder;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) ipsec - properly detect interface for "mode-config" client IP address assignment;
    *) kidcontrol - initial work on "/ip kid-control" feature;
    *) lte - added initial support for SIM7600 LTE modem interface;
    *) lte - added support for the user and password authentication for wAP-LTE-kit-US (R11e-LTE-US);
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) netwatch - limit to read, write, test and reboot policies for Netwatch script execution;
    *) poe - hide PoE related properties on interfaces which does not provide power output;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - fixed NAT if PPPoE client is used for Internet access;
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) r11e-lte - improved LTE connection initialization process;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) sniffer - fixed situation when "/tool sniffer packet" returned packets in incorrect order;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added "/interface w60g print oid";
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - improved key import error messages;
    *) ssh - remove imported public SSH keys when their owner user is removed;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - correctly return “TransferComplete” after vendor configuration file transfer;
    *) tr069-client - fixed "/tool fetch" commands executed with ".alter" script;
    *) tr069-client - fixed HTTPS authentication process;
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) userman - added support for ARM and MMIPS platform;
    *) winbox - made UDP local and remote TX size parameter optional in Bandwidth Test tool;
    *) winbox - moved "ageing-time" setting from STP to General tab;
    *) winbox - added "antenna" setting under GPS settings for MIPS platform devices;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added 160 MHz "channel-width" to wireless settings;
    *) winbox - added broadcast and flood settings to bridge ports;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added missing protocol numbers to IPv4 and IPv6 firewall;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed name for "out-bridge-list" parameter under bridge firewall rules;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - removed “VLAN” section from “Switch” menu for CRS3xx devices;
    *) winbox - show Bridge Port PVID column by default;
    *) winbox - show CQI in LTE info;
    *) winbox - show only master CAP interfaces under CAPsMAN wireless scan tool;
    *) wireless - added "realm-raw" setting for "/interface wireless interworking-profiles" (CLI only);
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added support for "band=5ghz-n/ac";
    *) wireless - added support for "interface-list" for Access List entries;
    *) wireless - added support for legacy AR9485 chipset;
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed long "scan-list" entries not working for ARM based wireless interfaces;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - fixed RTS/CTS option for the ARM based wireless devices;
    *) wireless - improved compatibility with specific wireless AC standard clients;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality;
    *) wireless - improved wireless stability on hAP ac2 devices while USB is being used;

  • Release 6.42rc39 2018-03-07

    What's new in 6.42rc39 (2018-Mar-07 07:01):

    *) bridge - added per-port forwarding options for broadcasts, unknown-multicasts and unknown-unicasts;
    *) bridge - added per-port learning options;
    *) bridge - added support for static hosts;
    *) bridge - fixed reliability on software bridges when used on devices without switch chip;
    *) capsman - added "allow-signal-out-of-range" option for Access List entries;
    *) capsman - added support for "interface-list" in Access List and Datapath entries;
    *) console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38;
    *) crs3xx - added initial “hw-offload” support for 802.3ad and “balance-xor” bonding;
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) dhcp - improved DHCP service reliability when it is configured on bridge interface;
    *) email - set maximum number of sessions to 100;
    *) fetch - increased maximum number of sessions to 100;
    *) ike1 - fixed wildcard policy lookup on responder;
    *) quickset - fixed NAT if PPPoE client is used for Internet access;
    *) winbox - made UDP local and remote TX size parameter optional in Bandwidth Test tool;
    *) winbox - moved "ageing-time" setting from STP to General tab;
    *) winbox - added "antenna" setting under GPS settings for MIPS platform devices;
    *) winbox - added 160 MHz "channel-width" to wireless settings;
    *) winbox - added broadcast and flood settings to bridge ports;
    *) winbox - added missing protocol numbers to IPv4 and IPv6 firewall;
    *) winbox - removed “VLAN” section from “Switch” menu for CRS3xx devices;
    *) winbox - fixed maximal ID for Traffic Generator stream;
    *) winbox - fixed name for "out-bridge-list" parameter under bridge firewall rules;
    *) winbox - removed Enable and Disable buttons from IPsec "mode-config" list;
    *) winbox - show "D" flag under "/ip dhcp-client" menu;
    *) winbox - show CQI in LTE info;
    *) winbox - show only master CAP interfaces under CAPsMAN wireless scan tool;
    *) wireless - added support for "band=5ghz-n/ac";
    *) wireless - added support for "interface-list" for Access List entries;
    *) wireless - added support for legacy AR9485 chipset;
    *) wireless - improved wireless scan functionality;

    Other changes since 6.41.2:

    !) tile - improved overall system performance and stability ("/system routerboard upgrade" required);
    *) bridge - added host aging timer for crs3xx and Atheros hw-bridges;
    *) bridge - fixed bridge port interface parameter under "/interface bridge host print detail";
    *) bridge - fixed false MAC address learning on hAP ac2 and cAP ac devices;
    *) bridge - fixed incorrect "fast-forward" enabling when ports were switched;
    *) bridge - fixed MAC learning for VRRP interfaces on bridge;
    *) bridge - hide options for disabled bridge features in CLI;
    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) capsman - log "signal-strength" when successfully connected to AP;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" and "virtio-scsi" driver on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - added support for Hyper-V ballooning, guest quiescing, host-guest file transfer, integration services and static IP injection;
    *) chr - added support for NIC hot-plug on VMware and Xen installations;
    *) chr - automatically generate new system ID on first startup;
    *) chr - fixed additional disk detaching on Xen installations;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) console - do not allow variables that start with digit to be referenced without $ sign;
    *) console - improved console stability after it has not been used for a long time;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs212 - fixed Ethernet boot through CRS326 devices;
    *) defconf - fixed DISC Lite5 LED default configuration;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced in v6.41);
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) export - fixed "/system routerboard mode-button" compact export;
    *) fetch - added "http-content-type" option to allow setting MIME type of the data in free text form;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) filesystem - implemented additional system storage maintenance checks on ARM CPU based devices;
    *) filesystem - improved error correcting process on RB1100AHx4 storage;
    *) firewall - fixed "tls-host" firewall feature (introduced in v6.41);
    *) flashfig - properly apply configuration provided by Flashfig;
    *) gps - added GPS port support for Quectel EC25-E modem when used in LTE mode;
    *) gps - improved NMEA sentence handling;
    *) health - log warning when switching between redundant power supplies;
    *) hotspot - improved HTTPS matching in Walled Garden rules;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) ipsec - properly detect interface for "mode-config" client IP address assignment;
    *) kidcontrol - initial work on "/ip kid-control" feature;
    *) lte - added initial support for SIM7600 LTE modem interface;
    *) lte - added support for the user and password authentication for wAP-LTE-kit-US (R11e-LTE-US);
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) lte - fixed rare situation when r11-LTE interface is missing after reboot;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) netwatch - limit to read, write, test and reboot policies for Netwatch script execution;
    *) poe - hide PoE related properties on interfaces which does not provide power output;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) r11e-lte - improved LTE connection initialization process;
    *) romon - make secret field sensitive in console;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) smb - improved NetBIOS name handling and stability;
    *) sniffer - fixed situation when "/tool sniffer packet" returned packets in incorrect order;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added "/interface w60g print oid";
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - improved key import error messages;
    *) ssh - remove imported public SSH keys when their owner user is removed;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tile - fixed occasional reporting of bogus voltage;
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - correctly return “TransferComplete” after vendor configuration file transfer;
    *) tr069-client - fixed "/tool fetch" commands executed with ".alter" script;
    *) tr069-client - fixed HTTPS authentication process;
    *) tr069-client - fixed TR069 service becoming unavailable when related service package is not available;
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) usb - improved packet processing over USB modems;
    *) userman - added support for ARM and MMIPS platform;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed "/tool e-mail send" attachment behavior;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - show Bridge Port PVID column by default;
    *) wireless - added "realm-raw" setting for "/interface wireless interworking-profiles" (CLI only);
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed long "scan-list" entries not working for ARM based wireless interfaces;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - fixed RTS/CTS option for the ARM based wireless devices;
    *) wireless - improved compatibility with specific wireless AC standard clients;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless stability on hAP ac2 devices while USB is being used;

  • Release 6.42rc37 2018-03-01

    What's new in 6.42rc37 (2018-Mar-01 09:29):

    *) bridge - fixed bridge port interface parameter under "/interface bridge host print detail";
    *) console - do not allow variables that start with digit to be referenced without $ sign;
    *) romon - make secret field sensitive in console;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;

    Other changes since 6.41.2:

    !) tile - improved overall system performance and stability ("/system routerboard upgrade" required);
    *) bridge - added host aging timer for crs3xx and Atheros hw-bridges;
    *) bridge - added per-port forwarding options for broadcasts, unknown-multicasts and unknown-unicasts (CLI only);
    *) bridge - added per-port learning options (CLI only);
    *) bridge - added static host support (CLI only);
    *) bridge - fixed false MAC address learning on hAP ac2 and cAP ac devices;
    *) bridge - fixed incorrect "fast-forward" enabling when ports were switched;
    *) bridge - fixed MAC learning for VRRP interfaces on bridge;
    *) bridge - hide options for disabled bridge features in CLI;
    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - added "allow-signal-out-of-range" option for Access List entries (CLI only);
    *) capsman - added support for "interface-list" in Access List and Datapath entries (CLI only);
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) capsman - log "signal-strength" when successfully connected to AP;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" and "virtio-scsi" driver on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - added support for Hyper-V ballooning, guest quiescing, host-guest file transfer, integration services and static IP injection;
    *) chr - added support for NIC hot-plug on VMware and Xen installations;
    *) chr - automatically generate new system ID on first startup;
    *) chr - fixed additional disk detaching on Xen installations;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38 (CLI only);
    *) console - improved console stability after it has not been used for a long time;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs212 - fixed Ethernet boot through CRS326 devices;
    *) crs3xx - added initial “hw-offload” support for 802.3ad and “balance-xor” bonding;
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) defconf - fixed DISC Lite5 LED default configuration;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced in v6.41);
    *) dhcp - improved DHCP service reliability when it is configured on bridge interface;
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) export - fixed "/system routerboard mode-button" compact export;
    *) fetch - added "http-content-type" option to allow setting MIME type of the data in free text form;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) filesystem - implemented additional system storage maintenance checks on ARM CPU based devices;
    *) filesystem - improved error correcting process on RB1100AHx4 storage;
    *) firewall - fixed "tls-host" firewall feature (introduced in v6.41);
    *) flashfig - properly apply configuration provided by Flashfig;
    *) gps - added GPS port support for Quectel EC25-E modem when used in LTE mode;
    *) gps - improved NMEA sentence handling;
    *) health - log warning when switching between redundant power supplies;
    *) hotspot - improved HTTPS matching in Walled Garden rules;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) ike1 - fixed wildcard policy lookup on responder;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) ipsec - properly detect interface for "mode-config" client IP address assignment;
    *) kidcontrol - initial work on "/ip kid-control" feature;
    *) lte - added initial support for SIM7600 LTE modem interface;
    *) lte - added support for the user and password authentication for wAP-LTE-kit-US (R11e-LTE-US);
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) lte - fixed rare situation when r11-LTE interface is missing after reboot;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) netwatch - limit to read, write, test and reboot policies for Netwatch script execution;
    *) poe - hide PoE related properties on interfaces which does not provide power output;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) r11e-lte - improved LTE connection initialization process;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) smb - improved NetBIOS name handling and stability;
    *) sniffer - fixed situation when "/tool sniffer packet" returned packets in incorrect order;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added "/interface w60g print oid";
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - improved key import error messages;
    *) ssh - remove imported public SSH keys when their owner user is removed;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tile - fixed occasional reporting of bogus voltage;
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - correctly return “TransferComplete” after vendor configuration file transfer;
    *) tr069-client - fixed "/tool fetch" commands executed with ".alter" script;
    *) tr069-client - fixed HTTPS authentication process;
    *) tr069-client - fixed TR069 service becoming unavailable when related service package is not available;
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) usb - improved packet processing over USB modems;
    *) userman - added support for ARM and MMIPS platform;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed "/tool e-mail send" attachment behavior;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - show Bridge Port PVID column by default;
    *) wireless - added "realm-raw" setting for "/interface wireless interworking-profiles" (CLI only);
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added support for "band=5ghz-n/ac" (CLI only);
    *) wireless - added support for "interface-list" in Access List entries (CLI only);
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed long "scan-list" entries not working for ARM based wireless interfaces;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - fixed RTS/CTS option for the ARM based wireless devices;
    *) wireless - improved compatibility with specific wireless AC standard clients;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless stability on hAP ac2 devices while USB is being used;

  • Release 6.42rc35 2018-02-26

    What's new in 6.42rc35 (2018-Feb-26 10:46):

    *) bridge - added host aging timer for crs3xx and Atheros hw-bridges;
    *) bridge - added per-port learning options (CLI only);
    *) bridge - added static host support (CLI only);
    *) bridge - added per-port forwarding options for broadcasts, unknown-multicasts and unknown-unicasts (CLI only);
    *) bridge - fixed MAC learning for VRRP interfaces on bridge;
    *) crs212 - fixed Ethernet boot through CRS326 devices;
    *) crs3xx - added initial “hw-offload” support for 802.3ad and “balance-xor” bonding;
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) dhcp - improved DHCP service reliability when it is configured on bridge interface;
    *) fetch - added "http-content-type" option to allow setting MIME type of the data in free text form;
    *) flashfig - properly apply configuration provided by Flashfig;
    *) health - log warning when switching between redundant power supplies;
    *) hotspot - improved HTTPS matching in Walled Garden rules;
    *) ike1 - fixed wildcard policy lookup on responder;
    *) ipsec - properly detect interface for "mode-config" client IP address assignment;
    *) kidcontrol - initial work on "/ip kid-control" feature;
    *) lte - added support for the user and password authentication for wAP-LTE-kit-US (R11e-LTE-US);
    *) poe - hide PoE related properties on interfaces which does not provide power output;
    *) ssh - remove imported public SSH keys when their owner user is removed;
    *) wireless - fixed RTS/CTS option for the ARM based wireless devices;
    *) tr069-client - fixed TR069 service becoming unavailable when related service package is not available;
    *) tr069-client - fixed "/tool fetch" commands executed with ".alter" script;

    Other changes since 6.41.2:

    !) tile - improved overall system performance and stability ("/system routerboard upgrade" required);
    *) bridge - fixed false MAC address learning on hAP ac2 and cAP ac devices;
    *) bridge - fixed incorrect "fast-forward" enabling when ports were switched;
    *) bridge - hide options for disabled bridge features in CLI;
    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - added "allow-signal-out-of-range" option for Access List entries (CLI only);
    *) capsman - added support for "interface-list" in Access List and Datapath entries (CLI only);
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) capsman - log "signal-strength" when successfully connected to AP;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" and "virtio-scsi" driver on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - added support for Hyper-V ballooning, guest quiescing, host-guest file transfer, integration services and static IP injection;
    *) chr - added support for NIC hot-plug on VMware and Xen installations;
    *) chr - automatically generate new system ID on first startup;
    *) chr - fixed additional disk detaching on Xen installations;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38 (CLI only);
    *) console - improved console stability after it has not been used for a long time;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) defconf - fixed DISC Lite5 LED default configuration;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced in v6.41);
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) export - fixed "/system routerboard mode-button" compact export;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) filesystem - implemented additional system storage maintenance checks on ARM CPU based devices;
    *) filesystem - improved error correcting process on RB1100AHx4 storage;
    *) firewall - fixed "tls-host" firewall feature (introduced in v6.41);
    *) gps - added GPS port support for Quectel EC25-E modem when used in LTE mode;
    *) gps - improved NMEA sentence handling;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) lte - added initial support for SIM7600 LTE modem interface;
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) lte - fixed rare situation when r11-LTE interface is missing after reboot;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) netwatch - limit to read, write, test and reboot policies for Netwatch script execution;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) r11e-lte - improved LTE connection initialization process;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) smb - improved NetBIOS name handling and stability;
    *) sniffer - fixed situation when "/tool sniffer packet" returned packets in incorrect order;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added "/interface w60g print oid";
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - improved key import error messages;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tile - fixed occasional reporting of bogus voltage;
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - correctly return “TransferComplete” after vendor configuration file transfer;
    *) tr069-client - fixed HTTPS authentication process;
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) usb - improved packet processing over USB modems;
    *) userman - added support for ARM and MMIPS platform;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed "/tool e-mail send" attachment behavior;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - show Bridge Port PVID column by default;
    *) wireless - added "realm-raw" setting for "/interface wireless interworking-profiles" (CLI only);
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added support for "band=5ghz-n/ac" (CLI only);
    *) wireless - added support for "interface-list" in Access List entries (CLI only);
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed long "scan-list" entries not working for ARM based wireless interfaces;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - improved compatibility with specific wireless AC standard clients;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;
    *) wireless - improved wireless stability on hAP ac2 devices while USB is being used;

  • Release 6.42rc30 2018-02-21

    What's new in 6.42rc30 (2018-Feb-20 10:44):

    *) console - improved console stability after it has not been used for a long time;
    *) filesystem - implemented additional system storage maintenance checks on ARM CPU based devices;
    *) filesystem - improved error correcting process on RB1100AHx4 storage;
    *) gps - added GPS port support for Quectel EC25-E modem when used in LTE mode;
    *) ipsec - properly detect interface for "mode-config" client IP address assignment;
    *) kidcontrol - initial work on "/ip kid-control" feature;
    *) lte - fixed rare situation when r11-LTE interface is missing after reboot;
    *) lte - improved IP configuration request process for r11e-LTE-US card;
    *) netwatch - limit to read, write, test and reboot policies for Netwatch script execution;
    *) tr069-client - correctly return “TransferComplete” after vendor configuration file transfer;
    *) usb - improved packet processing over USB modems;
    *) wireless - improved wireless stability on hAP ac2 devices while USB is being used;

    Other changes since 6.41.2:

    !) tile - improved overall system performance and stability ("/system routerboard upgrade" required);
    *) bridge - fixed false MAC address learning on hAP ac2 and cAP ac devices;
    *) bridge - fixed incorrect "fast-forward" enabling when ports were switched;
    *) bridge - hide options for disabled bridge features in CLI;
    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - added "allow-signal-out-of-range" option for Access List entries (CLI only);
    *) capsman - added support for "interface-list" in Access List and Datapath entries (CLI only);
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) capsman - log "signal-strength" when successfully connected to AP;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" and "virtio-scsi" driver on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - added support for Hyper-V ballooning, guest quiescing, host-guest file transfer, integration services and static IP injection;
    *) chr - added support for NIC hot-plug on VMware and Xen installations;
    *) chr - automatically generate new system ID on first startup;
    *) chr - fixed additional disk detaching on Xen installations;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38 (CLI only);
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs3xx - added initial hw-offload support for 802.3ad and balance-xor bonding
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced in v6.41);
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) export - fixed "/system routerboard mode-button" compact export;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) firewall - fixed "tls-host" firewall feature (introduced in v6.41);
    *) gps - improved NMEA sentence handling;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) lte - added initial support for SIM7600 LTE modem interface;
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) r11e-lte - improved LTE connection initialization process;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) smb - improved NetBIOS name handling and stability;
    *) sniffer - fixed situation when "/tool sniffer packet" returned packets in incorrect order;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added "/interface w60g print oid";
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - improved key import error messages;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tile - fixed occasional reporting of bogus voltage;
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - fixed HTTPS authentication process;
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) userman - added support for ARM and MMIPS platform;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed "/tool e-mail send" attachment behavior;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - show Bridge Port PVID column by default;
    *) wireless - added "realm-raw" setting for "/interface wireless interworking-profiles" (CLI only);
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added support for "band=5ghz-n/ac" (CLI only);
    *) wireless - added support for "interface-list" in Access List entries (CLI only);
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed long "scan-list" entries not working for ARM based wireless interfaces;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - improved compatibility with specific wireless AC standard clients;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;

  • Release 6.42rc28 2018-02-16

    What's new in 6.42rc28 (2018-Feb-16 07:02):

    *) chr - added "virtio-scsi" driver on KVM installations;
    *) chr - added support for Hyper-V ballooning;
    *) chr - added support for Hyper-V guest quiescing;
    *) chr - added support for Hyper-V host-guest file transfer;
    *) chr - added support for Hyper-V integration services;
    *) chr - added support for Hyper-V static IP injection;
    *) chr - added support for NIC hot-plug on VMware and Xen installations;
    *) chr - fixed additional disk detaching on Xen installations;
    *) ipsec - properly detect interface for "mode-config" client IP address assignment;
    *) gps - improved NMEA sentence handling;
    *) r11e-lte - improved LTE connection initialization process;

    Other changes since 6.41.2:

    !) tile - improved overall system performance and stability ("/system routerboard upgrade" required);
    *) bridge - fixed false MAC address learning on hAP ac2, cAP ac;
    *) bridge - fixed incorrect "fast-forward" enabling when ports were switched;
    *) bridge - hide options for disabled bridge features in CLI;
    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - added "allow-signal-out-of-range" option for Access List entries (CLI only);
    *) capsman - added support for "interface-list" in Access List entries (CLI only);
    *) capsman - added support for "interface-list" in datapath (CLI only);
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) capsman - log "signal-strength" when successfully connected to AP;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - automatically generate new system ID on first startup;
    *) chr - fixed fresh installations (including ISO images) (introduced in v6.42rc24);
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38 (CLI only);
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs3xx - added initial hw-offload support for 802.3ad and balance-xor bonding
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced v6.41);
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) export - fixed "/system routerboard mode-button" compact export;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) firewall - fixed "tls-host" firewall feature (introduced v6.41);
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) kidcontrol - initial work on "/ip kid-control" feature;
    *) lte - added initial support for SIM7600 LTE modem interface;
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) smb - improved NetBIOS name handling and stability;
    *) sniffer - fixed situation when "/tool sniffer packet" returned packets in incorrect order;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added "/interface w60g print oid";
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - improved key import error messages;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tile - fixed occasional reporting of bogus voltage;
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - fixed HTTPS authentication process;
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) userman - added support for ARM and MMIPS platform;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed "/tool e-mail send" attachment behavior;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - show Bridge Port PVID column by default;
    *) wireless - added "realm-raw" setting for "/interface wireless interworking-profiles" (CLI only);
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added support for "band=5ghz-n/ac" (CLI only);
    *) wireless - added support for "interface-list" in Access List entries (CLI only);
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed long "scan-list" entries not working for ARM based wireless interfaces;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - improved compatibility with specific wireless AC standard clients;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;

  • Release 6.42rc27 2018-02-15

    What's new in 6.42rc27 (2018-Feb-14 11:53):

    *) bridge - fixed false MAC address learning on hAP ac2, cAP ac;
    *) bridge - fixed incorrect "fast-forward" enabling when ports were switched;
    *) bridge - hide options for disabled bridge features in CLI;
    *) capsman - added "allow-signal-out-off-range" option for Access List entries (CLI only);
    *) capsman - added support for "interface-list" in Access List entries (CLI only);
    *) capsman - added support for "interface-list" in datapath (CLI only);
    *) capsman - log "signal-strength" when successfully connected to AP;
    *) chr - fixed fresh installations (including ISO images) (introduced in v6.42rc24);
    *) kidcontrol - initial work on "/ip kid-control" feature;
    *) lte - added initial support for SIM7600 LTE modem interface;
    *) smb - improved NetBIOS name handling and stability;
    *) snmp - added "/interface w60g print oid";
    *) tile - fixed occasional reporting of bogus voltage;
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) wireless - added "realm-raw" setting for "/interface wireless interworking-profiles" (CLI only);
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - added support for "band=5ghz-n/ac" (CLI only);
    *) wireless - added support for "interface-list" in Access List entries (CLI only);
    *) wireless - fixed long "scan-list" entries not working for ARM based wireless interfaces;

    Other changes since 6.41.2:

    !) tile - improved overall system performance and stability ("/system routerboard upgrade" required);
    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - automatically generate new system ID on first startup;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38 (CLI only);
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs3xx - added initial hw-offload support for 802.3ad and balance-xor bonding
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced v6.41);
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) export - fixed "/system routerboard mode-button" compact export;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) firewall - fixed "tls-host" firewall feature (introduced v6.41);
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) sniffer - fixed situation when "/tool sniffer packet" returned packets in incorrect order;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - improved key import error messages;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - fixed HTTPS authentication process;
    *) userman - added support for ARM and MMIPS platform;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed "/tool e-mail send" attachment behavior;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - show Bridge Port PVID column by default;
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - improved compatibility with specific wireless AC standard clients;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;

  • Release 6.42rc24 2018-02-08

    What's new in 6.42rc24 (2018-Feb-08 09:42):

    *) crs3xx - added initial hw-offload support for 802.3ad and balance-xor bonding
    *) export - fixed "/system routerboard mode-button" compact export;
    *) firewall - fixed "tls-host" firewall feature (introduced v6.41);

    Other changes since 6.41.1:

    !) tile - improved overall system performance and stability ("/system routerboard upgrade" required);
    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - automatically generate new system ID on first startup;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38 (CLI only);
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced v6.41);
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) disk - fixed disk related processes becoming unresponsive after unplugging used disk;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) filesystem - fixed situations when "/flash" directory lost files after upgrade;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) kidcontrol - added initial support for "/ip kid-control" feature;
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed AT communication with modem (introduced in v6.42rc12);
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) ppp - do not lose "/ppp profile" script configuration after other profile parameters are edited;
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) routerboard - properly report warnings under "/system routerboard" menu;
    *) sniffer - fixed situation when "/tool sniffer packet" returned packets in incorrect order;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added w60g support;
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - improved key import error messages;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - fixed HTTPS authentication process;
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) userman - added support for ARM and MMIPS platform;
    *) w60g - fixed "/interface w60g reset-configuration";
    *) webfig - fixed backup loading from Webfig on RouterBOARD running default configuration;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - changed default bridge port PVID value to 1;
    *) winbox - fixed "/tool e-mail send" attachment behavior;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - show Bridge Port PVID column by default;
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed nv2 (introduced in v6.42rc);
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - fixed wireless protocol mode restrictions if lockapck is installed and has limits for it;
    *) wireless - improved compatibility with specific wireless AC standard clients;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;

  • Release 6.42rc23 2018-02-08

    What's new in 6.42rc23 (2018-Feb-07 09:41):

    *) console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38 (CLI only);
    *) crs3xx - added initial hw-offload support for 802.3ad and balance-xor bonding
    *) disk - fixed disk related processes becoming unresponsive after unplugging used disk;
    *) kidcontrol - added initial support for "/ip kid-control" feature;
    *) ppp - do not lose "/ppp profile" script configuration after other profile parameters are edited;
    *) routerboard - properly report warnings under "/system routerboard" menu;
    *) sniffer - fixed situation when "/tool sniffer packet" returned packets in incorrect order;
    *) snmp - added w60g support;
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) w60g - fixed "/interface w60g reset-configuration";
    *) winbox - changed default bridge port PVID value to 1;
    *) wireless - added initial support for "nstreme-plus";
    *) wireless - improved compatibility with specific wireless AC standard clients;

    Other changes since 6.41.1:

    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - automatically generate new system ID on first startup;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced v6.41);
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) filesystem - fixed situations when "/flash" directory lost files after upgrade;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed AT communication with modem (introduced in v6.42rc12);
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) snmp - added "/caps-man interface print oid";
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - improved key import error messages;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tile - improved stability in high throughput HW accelerated IPsec setups ("/system routerboard upgrade" required);
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - fixed HTTPS authentication process;
    *) userman - added support for ARM and MMIPS platform;
    *) webfig - fixed backup loading from Webfig on RouterBOARD running default configuration;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed "/tool e-mail send" attachment behavior;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - show Bridge Port PVID column by default;
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed nv2 (introduced in v6.42rc);
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - fixed wireless protocol mode restrictions if lockapck is installed and has limits for it;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;

  • Release 6.42rc20 2018-02-02

    What's new in 6.42rc20 (2018-Feb-02 10:50):

    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;

    Other changes since 6.41.1:

    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - automatically generate new system ID on first startup;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced v6.41);
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) filesystem - fixed situations when "/flash" directory lost files after upgrade;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) kidcontrol - added initial support for "/ip kid-control" feature;
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed AT communication with modem (introduced in v6.42rc12);
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added w60g support;
    *) snmp - fixed SNMP for w60g interfaces;
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - improved key import error messages;
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tile - improved stability in high throughput HW accelerated IPsec setups ("/system routerboard upgrade" required);
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - fixed HTTPS authentication process;
    *) userman - added support for ARM and MMIPS platform;
    *) webfig - fixed backup loading from Webfig on RouterBOARD running default configuration;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to comment new object without committing it;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed "/tool e-mail send" attachment behavior;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - show Bridge Port PVID column by default;
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed nv2 (introduced in v6.42rc);
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - fixed wireless protocol mode restrictions if lockapck is installed and has limits for it;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;

  • Release 6.42rc18 2018-02-02

    What's new in 6.42rc18 (2018-Feb-02 07:27):

    *) bridge - show "hw" flags only on Ethernet interfaces and interface lists;
    *) crs3xx - added switch port "storm-rate" limiting options;
    *) kidcontrol - added initial support for "/ip kid-control" feature;
    *) lte - fixed AT communication with modem (introduced in v6.42rc12);
    *) switch - hide "ingress-rate" and "egress-rate" for non-crs3xx switches;
    *) tile - improved stability in high throughput HW accelerated IPsec setups ("/system routerboard upgrade" required);
    *) upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
    *) webfig - fixed backup loading from Webfig on RouterBOARD running default configuration;
    *) winbox - allow to comment new object without committing it;
    *) wireless - fixed incompatibility with macOS clients;
    *) wireless - fixed wireless protocol mode restrictions if lock package is installed and has limits for it;

    Other changes since 6.41.1:

    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - automatically generate new system ID on first startup;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced v6.41);
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) filesystem - fixed situations when "/flash" directory lost files after upgrade;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added w60g support;
    *) snmp - fixed SNMP for w60g interfaces;
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - improved key import error messages;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - fixed HTTPS authentication process;
    *) userman - added support for ARM and MMIPS platform;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to open bridge host entry;
    *) winbox - fixed "/tool e-mail send" attachment behavior;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - show Bridge Port PVID column by default;
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed nv2 (introduced in v6.42rc);
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;

  • Release 6.42rc15 2018-01-26

    What's new in 6.42rc15 (2018-Jan-26 08:21):

    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6 - make sure that time is set before restoring bindings;
    *) dhcpv6-client - added possibility to specify options;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
    *) ippool - added ability to specify comment;
    *) radius - added warning if PPP authentication over RADIUS is enabled;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
    *) sfp - improved SFP module compatibility;
    *) userman - added support for ARM and MMIPS platform;
    *) webfig - do not show "hw" option on non-ethernet interfaces;
    *) winbox - added "crl-store" setting to certficate settings;
    *) winbox - fixed typo from "UPtime" to "Uptime";
    *) winbox - fixed Winbox closing when viewing graph which does not contain any data;

    Other changes since 6.41:

    *) bridge - fixed "mst-override" export;
    *) bridge - fixed allowed MSTI priority values;
    *) bridge - fixed ARP option changing on bridge (introduced v6.41);
    *) bridge - fixed hw-offload disabling for Mediatek and Realtek switches when STP/RSTP configured;
    *) bridge - fixed hw-offload disabling when adding a port with "horizon" set;
    *) bridge - fixed IGMP Snooping after disabling/enabling bridge;
    *) bridge - fixed interface list moving in "/interface bridge port" menu;
    *) bridge - fixed repetitive port "priority" set;
    *) bridge - fixed situation when packet could be sent with local MAC as dst-mac;
    *) bridge - fixed VLAN filtering when "use-ip-firewall" is enabled (introduced in v6.41);
    *) bridge - properly update "actual-mtu" after MTU value changes (introduced v6.41);
    *) btest - fixed TCP test accuracy when low TX/RX rates are used;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) certificate - added PKCS#10 version check;
    *) certificate - do not use utf8 for SCEP challange password;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) certificate - fixed PKCS#10 version;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - automatically generate new systemID on first startup;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs317 - improved transmit performance between 10G and 1G ports;
    *) crs326 - fixed possible packet leaking from CPU to switch ports;
    *) crs3xx - hide deprecated VLAN related settings in "/interface ethernet switch port" menu;
    *) detnet - additional work on "detect-internet" implementation;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced v6.41);
    *) dhcpv4-server - fixed framed and classless route received from RADIUS server;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) discovery - fixed discovery related settings conversation during upgrade from pre-v6.41 discovery implementation (introduced v6.41);
    *) dude - fixed e-mail notifications when default port is not used;
    *) filesystem - fixed situations when "/flash" directory lost files after upgrade;
    *) firewall - fixed "tls-host" firewall matcher (introduced v6.41);
    *) firewall - limited maximum "address-list-timeout" value to 35w3d13h13m56s;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) ike1 - fixed "aes-ctr" and "aes-gcm" encryption algorithms (introduced v6.41);
    *) ike2 - delay rekeyed peer outbound SA installation;
    *) ike2 - improve half-open connection handling;
    *) interface - improved interface configuration responsiveness;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) ipsec - properly update IPsec secret for IPIP/EoIP/GRE dynamic peer;
    *) kidcontrol - added initial support for "/ip kid-control" feature;
    *) log - properly report bridge interface MAC address changes;
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) netinstall - improved LTE package description;
    *) ovpn - fixed resource leak on systems with high CPU usage;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) ppp - changed default value of "route-distance" to 1;
    *) ppp - fixed change-mss functionality in some specific traffic (introduced in v6.41);
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) radius - increase allowed RADIUS server timeout to 60s;
    *) rb1100ahx4 - fixed reset button responsiveness when regular firmware is used;
    *) rb433/rb450 - fixed port flapping on bridged Ethernet interfaces if hw-offload is enabled (introduced in v6.41);
    *) routerboot - fixed missing upgrade firmware for "ar7240" devices;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added w60g support;
    *) snmp - allow also IPv6 on default public community;
    *) snmp - fixed SNMP for w60g interfaces;
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - improved key import error messages;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tile - fixed USB device speed detection after reboot;
    *) tile - improved stability in high throughput HW accelerated IPsec setups ("/system routerboard upgrade" required);
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - fixed HTTPS authentication process;
    *) traffic-flow - do not count single extra packet per each flow;
    *) webfig - added support for proper default policies when adding script or scheduler job;
    *) webfig - fixed bridge port sorting order by name;
    *) webfig - fixed MAC address ordering;
    *) webfig - fixed wireless snooper address, SSID and other column ordering;
    *) winbox - added "dhcp-option-set" to DHCP server;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to open bridge host entry;
    *) winbox - allow to specify "to-ports" for "action=masquerade";
    *) winbox - do not show "hw" option on non-ethernet interfaces;
    *) winbox - do not show VLAN related settings in switch port menu on CRS3xx boards;
    *) winbox - fixed "/tool e-mail send" attachment behavior;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - show Bridge Port PVID column by default;
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed nv2 (introduced in v6.42rc);
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;
    *) wireless - updated "Czech Republic" country 5.8 GHz frequency range;

  • Release 6.42rc14 2018-01-24

    What's new in 6.42rc14 (2018-Jan-24 12:35):

    *) bridge - fixed ARP option changing on bridge (introduced v6.41);
    *) bridge - fixed VLAN filtering when "use-ip-firewall" is enabled (introduced in v6.41);
    *) certificate - added PKCS#10 version check;
    *) certificate - dropped DES support and added AES instead for SCEP;
    *) certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
    *) certificate - fixed PKCS#10 version;
    *) netinstall - improved LTE package description;
    *) ovpn - fixed resource leak on systems with high CPU usage;
    *) ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
    *) rb433/rb450 - fixed port flapping on bridged Ethernet interfaces if hw-offload is enabled (introduced in v6.41);
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required) (CLI only);
    *) userman - added support for ARM and MMIPS platforms;
    *) wireless - improved packet processing on ARM platform devices;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;

    Other changes since 6.41:

    *) bridge - fixed "mst-override" export;
    *) bridge - fixed allowed MSTI priority values;
    *) bridge - fixed hw-offload disabling for Mediatek and Realtek switches when STP/RSTP configured;
    *) bridge - fixed hw-offload disabling when adding a port with "horizon" set;
    *) bridge - fixed IGMP Snooping after disabling/enabling bridge;
    *) bridge - fixed interface list moving in "/interface bridge port" menu;
    *) bridge - fixed repetitive port "priority" set;
    *) bridge - fixed situation when packet could be sent with local MAC as dst-mac;
    *) bridge - properly update "actual-mtu" after MTU value changes (introduced v6.41);
    *) btest - fixed TCP test accuracy when low TX/RX rates are used;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) certificate - do not use utf8 for SCEP challange password;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - automatically generate new systemID on first startup;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs317 - improved transmit performance between 10G and 1G ports;
    *) crs326 - fixed possible packet leaking from CPU to switch ports;
    *) crs3xx - hide deprecated VLAN related settings in "/interface ethernet switch port" menu;
    *) detnet - additional work on "detect-internet" implementation;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced v6.41);
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv4-server - fixed framed and classless route received from RADIUS server;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options (CLI only);
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) dhcpv6-server - added DHCPv4 style user options (CLI only);
    *) discovery - fixed discovery related settings conversation during upgrade from pre-v6.41 discovery implementation (introduced v6.41);
    *) dude - fixed e-mail notifications when default port is not used;
    *) filesystem - fixed situations when "/flash" directory lost files after upgrade;
    *) firewall - fixed "tls-host" firewall matcher (introduced v6.41);
    *) firewall - limited maximum "address-list-timeout" value to 35w3d13h13m56s;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) ike1 - fixed "aes-ctr" and "aes-gcm" encryption algorithms (introduced v6.41);
    *) ike2 - delay rekeyed peer outbound SA installation;
    *) ike2 - improve half-open connection handling;
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment (CLI only);
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) ipsec - properly update IPsec secret for IPIP/EoIP/GRE dynamic peer;
    *) kidcontrol - added initial support for "/ip kid-control" feature;
    *) log - properly report bridge interface MAC address changes;
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) ppp - changed default value of "route-distance" to 1;
    *) ppp - fixed change-mss functionality in some specific traffic (introduced in v6.41);
    *) quickset - properly detect LTE interface on startup;
    *) quickset - show "G" flag for guest users;
    *) radius - added warning if PPP authentication over RADIUS is enabled;
    *) radius - increase allowed RADIUS server timeout to 60s;
    *) rb1100ahx4 - fixed reset button responsiveness when regular firmware is used;
    *) routerboot - fixed missing upgrade firmware for "ar7240" devices;
    *) snmp - added "/caps-man interface print oid";
    *) snmp - added w60g support;
    *) snmp - allow also IPv6 on default public community;
    *) snmp - fixed SNMP for w60g interfaces;
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) ssh - improved key import error messages;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tile - fixed USB device speed detection after reboot;
    *) tile - improved stability in high throughput HW accelerated IPsec setups ("/system routerboard upgrade" required);
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - fixed HTTPS authentication process;
    *) traffic-flow - do not count single extra packet per each flow;
    *) webfig - added support for proper default policies when adding script or scheduler job;
    *) webfig - fixed bridge port sorting order by name;
    *) webfig - fixed MAC address ordering;
    *) webfig - fixed wireless snooper address, SSID and other column ordering;
    *) winbox - added "dhcp-option-set" to DHCP server;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to open bridge host entry;
    *) winbox - allow to specify "to-ports" for "action=masquerade";
    *) winbox - do not show "hw" option on non-ethernet interfaces;
    *) winbox - do not show VLAN related settings in switch port menu on CRS3xx boards;
    *) winbox - fixed "/tool e-mail send" attachment behavior;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - show Bridge Port PVID column by default;
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;
    *) wireless - fixed nv2 (introduced in v6.42rc);
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - updated "Czech Republic" country 5.8 GHz frequency range;

  • Release 6.42rc12 2018-01-23

    What's new in 6.42rc12 (2018-Jan-22 13:34):

    *) bridge - fixed "mst-override" export;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) dhcpv6-server - added DHCPv4 style user options (CLI only);
    *) interface - improved interface configuration responsiveness;
    *) ippool - added ability to specify comment (CLI only);
    *) kidcontrol - added initial support for "/ip kid-control" feature;
    *) ppp - fixed change-mss functionality in some specific traffic (introduced in v6.41);
    *) quickset - properly detect LTE interface on startup;
    *) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required) (CLI only);
    *) snmp - added "/caps-man interface print oid";
    *) snmp - improved request processing performance for wireless and CAP interfaces;
    *) wireless - fixed "wds-slave" channel selection when single frequency is specified;

    Other changes since 6.41:

    *) bridge - fixed allowed MSTI priority values;
    *) bridge - fixed bridge related settings conversation during upgrade from pre-v6.41 bridge implementation (introduced v6.41);
    *) bridge - fixed hw-offload disabling for Mediatek and Realtek switches when STP/RSTP configured;
    *) bridge - fixed hw-offload disabling when adding a port with "horizon" set;
    *) bridge - fixed IGMP Snooping after disabling/enabling bridge;
    *) bridge - fixed interface list moving in "/interface bridge port" menu;
    *) bridge - fixed repetitive port "priority" set;
    *) bridge - fixed situation when packet could be sent with local MAC as dst-mac;
    *) bridge - properly update "actual-mtu" after MTU value changes (introduced v6.41);
    *) btest - fixed TCP test accuracy when low TX/RX rates are used;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) certificate - do not use utf8 for SCEP challange password;
    *) chr - automatically generate new systemID on first startup;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs317 - improved transmit performance between 10G and 1G ports;
    *) crs326 - fixed possible packet leaking from CPU to switch ports;
    *) crs3xx - hide deprecated VLAN related settings in "/interface ethernet switch port" menu;
    *) detnet - additional work on "detect-internet" implementation;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced v6.41);
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv4-server - fixed framed and classless route received from RADIUS server;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options (CLI only);
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-client - implement confirm after reboot;
    *) discovery - fixed discovery related settings conversation during upgrade from pre-v6.41 discovery implementation (introduced v6.41);
    *) dude - fixed e-mail notifications when default port is not used;
    *) filesystem - fixed situations when "/flash" directory lost files after upgrade;
    *) firewall - fixed "tls-host" firewall matcher (introduced v6.41);
    *) firewall - limited maximum "address-list-timeout" value to 35w3d13h13m56s;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) ike1 - fixed "aes-ctr" and "aes-gcm" encryption algorithms (introduced v6.41);
    *) ike2 - delay rekeyed peer outbound SA installation;
    *) ike2 - improve half-open connection handling;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) ipsec - properly update IPsec secret for IPIP/EoIP/GRE dynamic peer;
    *) log - properly report bridge interface MAC address changes;
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) ppp - changed default value of "route-distance" to 1;
    *) quickset - show "G" flag for guest users;
    *) radius - added warning if PPP authentication over RADIUS is enabled;
    *) radius - increase allowed RADIUS server timeout to 60s;
    *) rb1100ahx4 - fixed reset button responsiveness when regular firmware is used;
    *) routerboot - fixed missing upgrade firmware for "ar7240" devices;
    *) snmp - added w60g support;
    *) snmp - allow also IPv6 on default public community;
    *) snmp - fixed SNMP for w60g interfaces;
    *) ssh - improved key import error messages;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tile - fixed USB device speed detection after reboot;
    *) tile - improved stability in high throughput HW accelerated IPsec setups ("/system routerboard upgrade" required);
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - fixed HTTPS authentication process;
    *) traffic-flow - do not count single extra packet per each flow;
    *) webfig - added support for proper default policies when adding script or scheduler job;
    *) webfig - fixed bridge port sorting order by name;
    *) webfig - fixed MAC address ordering;
    *) webfig - fixed wireless snooper address, SSID and other column ordering;
    *) winbox - added "dhcp-option-set" to DHCP server;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - added possibility to delete SMS from inbox;
    *) winbox - allow to open bridge host entry;
    *) winbox - allow to specify "to-ports" for "action=masquerade";
    *) winbox - do not show "hw" option on non-ethernet interfaces;
    *) winbox - do not show VLAN related settings in switch port menu on CRS3xx boards;
    *) winbox - fixed "/tool e-mail send" attachment behavior;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) winbox - show Bridge Port PVID column by default;
    *) wireless - fixed nv2 (introduced in v6.42rc);
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;
    *) wireless - updated "Czech Republic" country 5.8 GHz frequency range;

  • Release 6.42rc11 2018-01-18

    What's new in 6.42rc11 (2018-Jan-18 12:42):

    *) bridge - fixed IGMP Snooping after disabling/enabling bridge;
    *) bridge - fixed allowed MSTI priority values;
    *) certificate - do not use utf8 for SCEP challenge password;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - automatically generate new systemID on first startup;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) crs326 - fixed possible packet leaking from CPU to switch ports;
    *) dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
    *) dhcpv6-client - implement confirm after reboot;
    *) filesystem - fixed situations when "/flash" directory lost files after upgrade;
    *) ipsec - fixed AES-CTR and AES-GCM support on RB1200;
    *) kidcontrol - added initial support for "/ip kid-control" feature;
    *) ppp - changed default value of "route-distance" to 1;
    *) ppp - fixed change-mss funcionality in some specific traffic (introduced in v6.41);
    *) webfig - fixed MAC address ordering;
    *) webfig - fixed wireless snooper address, SSID and other column ordering;
    *) winbox - added "dhcp-option-set" to DHCP server;
    *) winbox - added "insert-queue-before" to DHCP server;
    *) winbox - added DHCPv6 client info request type and updated statuses;
    *) winbox - show Bridge Port PVID column by default;
    *) wireless - fixed nv2 (introduced in v6.42rc);

    Other changes since 6.41:

    *) bridge - fixed bridge related settings conversation during upgrade from pre-v6.41 bridge implementation (introduced v6.41);
    *) bridge - fixed hw-offload disabling for Mediatek and Realtek switches when STP/RSTP configured;
    *) bridge - fixed hw-offload disabling when adding a port with "horizon" set;
    *) bridge - fixed interface list moving in "/interface bridge port" menu;
    *) bridge - fixed repetitive port "priority" set;
    *) bridge - fixed situation when packet could be sent with local MAC as dst-mac;
    *) bridge - properly update "actual-mtu" after MTU value changes (introduced v6.41);
    *) btest - fixed TCP test accuracy when low TX/RX rates are used;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs317 - improved transmit performance between 10G and 1G ports;
    *) crs3xx - hide deprecated VLAN related settings in "/interface ethernet switch port" menu;
    *) detnet - additional work on "detect-internet" implementation;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced v6.41);
    *) dhcpv4-server - fixed framed and classless route received from RADIUS server;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added possibility to specify options (CLI only);
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) discovery - fixed discovery related settings conversation during upgrade from pre-v6.41 discovery implementation (introduced v6.41);
    *) dude - fixed e-mail notifications when default port is not used;
    *) firewall - fixed "tls-host" firewall matcher (introduced v6.41);
    *) firewall - limited maximum "address-list-timeout" value to 35w3d13h13m56s;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) ike1 - fixed "aes-ctr" and "aes-gcm" encryption algorithms (introduced v6.41);
    *) ike2 - delay rekeyed peer outbound SA installation;
    *) ike2 - improve half-open connection handling;
    *) interface - improved interface configuration responsiveness;
    *) ipsec - properly update IPsec secret for IPIP/EoIP/GRE dynamic peer;
    *) log - properly report bridge interface MAC address changes;
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) quickset - show "G" flag for guest users;
    *) radius - added warning if PPP authentication over RADIUS is enabled;
    *) radius - increase allowed RADIUS server timeout to 60s;
    *) rb1100ahx4 - fixed reset button responsiveness when regular firmware is used;
    *) routerboot - fixed missing upgrade firmware for "ar7240" devices;
    *) snmp - added w60g support;
    *) snmp - allow also IPv6 on default public community;
    *) snmp - fixed SNMP for W60G interfaces;
    *) ssh - improved key import error messages;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tile - fixed USB device speed detection after reboot;
    *) tile - improved stability in high throughput HW accelerated IPsec setups ("/system routerboard upgrade" required);
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) tr069-client - fixed HTTPS authentication process;
    *) traffic-flow - do not count single extra packet per each flow;
    *) webfig - added support for proper default policies when adding script or scheduler job;
    *) webfig - fixed bridge port sorting order by name;
    *) winbox - added possibility to delete SMS from Inbox;
    *) winbox - allow to open bridge host entry;
    *) winbox - allow to specify "to-ports" for "action=masquerade";
    *) winbox - do not show "hw" option on non-ethernet interfaces;
    *) winbox - do not show VLAN related settings in switch port menu on CRS3xx boards;
    *) winbox - fixed "/tool e-mail send" attachment behaviour;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;
    *) wireless - updated "Czech Republic" country 5.8 GHz frequency range;

  • Release 6.42rc9 2018-01-15

    What's new in 6.42rc9 (2018-Jan-15 09:07):

    *) bridge - fixed interface list moving in "/interface bridge port" menu;
    *) bridge - fixed hw-offload disabling for Mediatek and Realtek switches when STP/RSTP configured;
    *) bridge - fixed hw-offload disabling when adding a port with "horizon" set;
    *) bridge - fixed repetitive port "priority" set;
    *) bridge - fixed situation when packet could be sent with local MAC as dst-mac;
    *) chr - added "open-vm-tools" on VMware installations;
    *) chr - added "qemu-guest-agent" on KVM installations;
    *) chr - added "xe-daemon" on Xen installations;
    *) chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
    *) chr - fixed suspend on Xen installations;
    *) chr - make additional disks visible under "/disk" on Xen installations;
    *) chr - make virtio disks visible under "/disk" on KVM installations;
    *) crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
    *) crs3xx - hide deprecated VLAN related settings in "/interface ethernet switch port" menu;
    *) dhcpv4-server - fixed framed and classless route received from RADIUS server;
    *) dhcpv6-client - added info exchange support;
    *) dhcpv6-client - added support for options 15 and 16;
    *) dhcpv6-server - added DHCPv4 style user options;
    *) ike1 - do not accept "mode-config" reply more than once;
    *) ike2 - delay rekeyed peer outbound SA installation;
    *) ipsec - properly update IPsec secret for IPIP/EoIP/GRE dynamic peer;
    *) kidcontrol - added initial support for "/ip kid-control" feature (CLI only);
    *) lte - do not add DHCP client on LTE modems that doesn't use DHCP;
    *) lte - fixed DHCP client adding for MF823 modem;
    *) mac-ping - fixed duplicate responses;
    *) modem - added initial support for AC340U;
    *) ppp - allow to override remote user PPP profile via "Mikrotik-Group";
    *) ppp - changed default value of "route-distance" to 1;
    *) quickset - show "G" flag for guest users;
    *) radius - added warning if PPP authentication over RADIUS is enabled;
    *) radius - increase allowed RADIUS server timeout to 60s;
    *) snmp - allow also IPv6 on default public community;
    *) snmp - fixed SNMP for W60G interfaces;
    *) tile - improved stability in high throughput HW accelerated IPsec setups ("/system routerboard upgrade" required);
    *) tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
    *) webfig - added support for proper default policies when adding script or scheduler job;
    *) webfig - fixed bridge port sorting order by name;
    *) winbox - added possibility to delete SMS from Inbox;
    *) winbox - allow to open bridge host entry;
    *) winbox - allow to specify "to-ports" for "action=masquerade";
    *) winbox - do not show "hw" option on non-ethernet interfaces;
    *) winbox - do not show VLAN related settings in switch port menu on CRS3xx boards;
    *) winbox - fixed "/tool e-mail send" attachment behaviour;
    *) winbox - improved stability when using trackpad scrolling in large lists;
    *) wireless - fixed frequency-monitor/sniffer/snooper; (introduced in v6.42rc);
    *) wireless - fixed nv2 (introduced in v6.42rc);
    *) wireless - updated "Czech Republic" country 5.8 GHz frequency range;

    Other changes since 6.41:

    *) bridge - fixed bridge related settings conversation during upgrade from pre-v6.41 bridge implementation (introduced v6.41);
    *) bridge - properly update "actual-mtu" after MTU value changes (introduced v6.41);
    *) btest - fixed TCP test accuracy when low TX/RX rates are used;
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) crs317 - improved transmit performance between 10G and 1G ports;
    *) detnet - additional work on "detect-internet" implementation;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced v6.41);
    *) dhcpv6-client - added possibility to specify options (CLI only);
    *) discovery - fixed discovery related settings conversation during upgrade from pre-v6.41 discovery implementation (introduced v6.41);
    *) dude - fixed e-mail notifications when default port is not used;
    *) firewall - fixed "tls-host" firewall matcher (introduced v6.41);
    *) firewall - limited maximum "address-list-timeout" value to 35w3d13h13m56s;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - fixed "aes-ctr" and "aes-gcm" encryption algorithms (introduced v6.41);
    *) ike2 - improve half-open connection handling;
    *) interface - improved interface configuration responsiveness;
    *) log - properly report bridge interface MAC address changes;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) rb1100ahx4 - fixed reset button responsiveness when regular firmware is used;
    *) routerboot - fixed missing upgrade firmware for "ar7240" devices;
    *) snmp - added w60g support;
    *) ssh - improved key import error messages;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tile - fixed USB device speed detection after reboot;
    *) tr069-client - fixed HTTPS authentication process;
    *) traffic-flow - do not count single extra packet per each flow;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;

  • Release 6.42rc6 2018-01-04

    What's new in 6.42rc6 (2018-Jan-04 13:52):

    *) btest - fixed TCP test accuracy when low TX/RX rates are used;
    *) crs317 - improved transmit performance between 10G and 1G ports;
    *) dhcpv6-client - added possibility to specify options (CLI only);
    *) snmp - added w60g support;
    *) wireless - fixed device becoming unresponsive (introduced in v6.42rc5);

    Other changes since 6.41:

    *) bridge - fixed bridge related settings conversation during upgrade from pre-v6.41 bridge implementation (introduced v6.41);
    *) bridge - properly update "actual-mtu" after MTU value changes (introduced v6.41);
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) detnet - additional work on "detect-internet" implementation;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced v6.41);
    *) discovery - fixed discovery related settings conversation during upgrade from pre-v6.41 discovery implementation (introduced v6.41);
    *) dude - fixed e-mail notifications when default port is not used;
    *) firewall - fixed "tls-host" firewall matcher (introduced v6.41);
    *) firewall - limited maximum "address-list-timeout" value to 35w3d13h13m56s;
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - fixed “aes-ctr” and “aes-gcm” encryption algorithms (introduced v6.41);
    *) ike2 - improve half-open connection handling;
    *) interface - improved interface configuration responsiveness;
    *) log - properly report bridge interface MAC address changes;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) rb1100ahx4 - fixed reset button responsiveness when regular firmware is used;
    *) routerboot - fixed missing upgrade firmware for "ar7240" devices;
    *) ssh - improved key import error messages;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tile - fixed USB device speed detection after reboot;
    *) tr069-client - fixed HTTPS authentication process;
    *) traffic-flow - do not count single extra packet per each flow;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;

  • Release 6.42rc5 2018-01-03

    What's new in 6.42rc5 (2018-Jan-03 10:51):

    *) bridge - fixed bridge related settings conversation during upgrade from pre-v6.41 bridge implementation (introduced v6.41);
    *) bridge - properly update "actual-mtu" after MTU value changes (introduced v6.41);
    *) capsman - improved CAPsMAN responsiveness on systems with large amount of CAP interfaces;
    *) detnet - additional work on "detect-internet" implementation;
    *) detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced v6.41);
    *) discovery - fixed discovery related settings conversation during upgrade from pre-v6.41 discovery implementation (introduced v6.41);
    *) firewall - fixed "tls-host" firewall matcher (introduced v6.41);
    *) ike1 - display error message when peer requests "mode-config" when it is not configured;
    *) ike1 - fixed “aes-ctr” and “aes-gcm” encryption algorithms (introduced v6.41);
    *) ike2 - improve half-open connection handling;
    *) interface - improved interface configuration responsiveness;
    *) log - properly report bridge interface MAC address changes;
    *) poe-out - do not show "poe-out-current" on devices which can not determine it;
    *) rb1100ahx4 - fixed reset button responsiveness when regular firmware is used;
    *) ssh - improved key import error messages;
    *) tile - added "aes-ctr" hardware acceleration support;
    *) tr069-client - fixed HTTPS authentication process;
    *) wireless - fixed nv2 protocol on ARM platform SXTsq devices;
    *) wireless - improved wireless scan functionality for devices with multiple wireless interfaces;

    Other changes since 6.41:

    *) dude - fixed e-mail notifications when default port is not used;
    *) firewall - limited maximum "address-list-timeout" value to 35w3d13h13m56s;
    *) routerboot - fixed missing upgrade firmware for "ar7240" devices;
    *) tile - fixed USB device speed detection after reboot;
    *) traffic-flow - do not count single extra packet per each flow;

  • Release 6.42rc2 2017-12-27

    What's new in 6.42rc2 (2017-Dec-27 07:37):

    *) dude - fixed e-mail notifications when default port is not used;
    *) firewall - fixed "tls-host" firewall matcher;
    *) firewall - limited maximum "address-list-timeout" value to 35w3d13h13m56s;
    *) routerboot - fixed missing upgrade firmware for "ar7240" devices;
    *) tile - fixed USB device speed detection after reboot;
    *) traffic-flow - do not count single extra packet per each flow;

  • Release 6.41rc66 2017-12-15

    What's new in 6.41rc66 (2017-Dec-14 13:53):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) routerboot - RouterBOOT version numbering system merged with RouterOS;
    *) capsman - added possibility to downgrade CAP with upgrade command from CAPsMAN;
    *) crs326 - improved transmit performance from SFP+ to Ethernet ports;
    *) dhcp-server - added basic RADIUS accounting;
    *) ike1 - disallow peer creation using base mode;
    *) ike2 - added support for multiple split networks;
    *) ike2 - do not allow to configure nat-traversal;
    *) ipsec - improved hardware accelerated IPSec performance on 750Gr3;
    *) ppp - fixed "change-mss" functionality when MSS option is missing on forwarded packets;
    *) ppp - fixed L2TP and PPTP encryption negotiation process on configuration changes;
    *) pppoe-client - properly re-establish MLPPP session when one of the lines stopped transmitting packets;
    *) quickset - fixed LTE quickset mode APN field;
    *) route - improved reliability on routing table update;
    *) snmp - fixed bulk requests when non-repeaters are used;
    *) wireless - added support for CHARGEABLE_USER_ID in EAP Accounting;
    *) wireless - updated "UK 5.8 Fixed" and "Australia" regulatory domain information;

    Other changes since 6.40.5:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) detnet - implemented "/interface detect-internet" feature;
    https://wiki.mikrotik.com/wiki/Manual:Detect_internet
    !) bridge - general implementation of hw-offload bridge (introduced in v6.40rc36);
    !) w60g - added Point to Multipoint support;
    !) wireless - new driver with initial support for 160 and 80+80 MHz channel width;
    *) arm - minor improvements on CPU load distribution for RB1100 series devices;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bgp - added 32-bit private ASN support;
    *) bridge - added comment support for VLANs;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - added support for "/interface list" as a bridge port;
    *) bridge - assume "point-to-point=yes" for all Full Duplex Ethernet interfaces when STP is used (as per standard);
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - disable "hw-offload" when "horizon" or "external-fdb" is set;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed hw-offloaded IGMP Snooping service getting stopped;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - set "igmp-snooping=no" by default on new bridges;
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) capsman - use "adaptive-noise-immunity" value from CAP local configuration;
    *) certificate - added option to store CRL in RAM (CLI only);
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - improved CRL update after system startup;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) certificate - show invalid flag when local CRL file does not exist;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) console - removed "/setup";
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) crs317 - fixed reliability on FAN controller;
    *) crs326 - fixed packet processing speed on switch chip if individual port link speed differs;
    *) crs3xx - added ingress/egress rate input limits;
    *) crs3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcp-client - limit and enforce DHCP client "default-route-distance" minimal value to 1;
    *) dhcp-server - added "option-set" argument (CLI only);
    *) dhcpv4-client - add dynamic DHCP client for mobile clients which require it;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) dhcpv4-server - added "NETWORK_GATEWAY" option variable;
    *) dhcpv4-server - strip trailing "\0" in "hostname" if present;
    *) discovery - use "/interface list" instead of interface name under neighbor discovery settings;
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) ethernet - removed "master-port" parameter;
    *) export - fixed interface list export;
    *) fetch - accept all HTTP 2xx status codes;
    *) filesystem - implemented additional system integrity checks on reboots;
    *) firewall - added "tls-host" firewall matcher;
    *) health - fixed bogus voltage readings on CCR1009;
    *) hotspot - fixed "dst-port" to require valid "protocol" in "walled-garden ip";
    *) hotspot - fixed Walled Garden IP functionality when address-list is used;
    *) ike1 - fixed crash on xauth if user does not exist;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - fixed PH1 lifetime reset on boot;
    *) ike2 - fixed initiator DDoS cookie processing;
    *) ike2 - fixed responder DDoS cookie first notify type check;
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added default "/interface list" "dynamic" which contains dynamic interfaces;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2;
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - fixed incorrect esp proposal key size usage;
    *) ipsec - fixed policy enable/disable;
    *) ipsec - improved reliability on certificate usage;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipsec - skip invalid policies for phase2;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) l2tp - improved reliability on packet processing in FastPath;
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) log - added "bridge" topic;
    *) log - fixed interface name in log messages;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration);
    *) lte - added Passthrough support;
    *) lte - added Yota non-configurable modem support;
    *) lte - added support for ZTE ME3630 E1C with additional "/port" for GPS usage;
    *) lte - automatically add "/ip dhcp-client" configuration on interface;
    *) lte - changed default values to "add-default-route=yes", "use-peer-dns=yes" and "default-route-distance=2";
    *) lte - fixed Passthrough support;
    *) lte - fixed authentication for non LTE modes;
    *) lte - fixed error when trying to add APN profile without name;
    *) lte - fixed rare crash when initializing LTE modem after reset;
    *) lte - fixed user authentication for R11e-LTE when new firmware is used;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - limited minimal default route distance to 1;
    *) lte - update info command with "location area code" and "physical cell id" values;
    *) m11g - improved ethernet performance on high load;
    *) mac-server - use "/interface list" instead of interface name under MAC server settings;
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) neighbor - show neighbors on actual bridge port instead of bridge itself
    *) netinstall - fixed missing "/flash/etc" on first bootup;
    *) netinstall - fixed missing default configuration prompt on first startup after reset/netinstall;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ovpn-server - do not periodically change automatically generated server MAC address;
    *) poe - added new "poe-out" status "controller-error";
    *) poe - fixed false positive excessive logs in auto-on mode when connected to 100 Mbps device powered from another power source;
    *) poe - log PoE status related messages under debug topic;
    *) ppp - added initial support for PLE902;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - do not disconnect PPP connection after "idle-timeout" even if traffic is being processed;
    *) ppp - fixed situation when part of PPP configuration was reset to default values after reboot;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) quickset - added support for "/interface list" in firewall, neighbor discovery, MAC-Telnet and MAC-Winbox;
    *) quickset - fixed situation when Quickset automatically changes mode to CPE;
    *) quickset - renamed router IP static DNS name to "router.lan";
    *) radius - limited RADIUS timeout maximum value to 3 seconds;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sms - fixed minor problem for SMS delivery;
    *) sms - log decoded USSD responses;
    *) snmp - fixed "ifHighSpeed" value of VLAN, VRRP and Bonding interfaces;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) snmp - fixed consecutive OID bulk get from the same table;
    *) snmp - show only available OIDs under "/system health print oid";
    *) ssh - do not use DH group1 with strong-crypto enabled;
    *) ssh - enforced 2048bit DH group on tile and x86 architectures;
    *) system - show USB topology for the device info;
    *) tile - improved hardware encryption processes;
    *) tr069-client - fixed "/interface lte apn" configuration parameters;
    *) traceroute - improved "/tool traceroute" results processing;
    *) upnp - add "src-address" parameter on NAT rule if it is specified on UPnP request;
    *) upnp - deny UPnP request if port is already used by the router;
    *) ups - fixed duplicate "failed" UPS logs;
    *) userman - allow to generate more than 999 users;
    *) w60g - added "put-slaves-in-bridge" and "isolate-slaves" options to manage connected clients;
    *) w60g - connected stations are treated as separate interfaces;
    *) w60g - general work on PtMP implementation for 60 GHz connections;
    *) w60g - renamed modes - "master" to "ap-bridge", "slave" to "station-bridge";
    *) webfig - added favicon file;
    *) webfig - fixed router getting reset to default configuration;
    *) webfig - fixed terminal graphic user interface under Safari browser;
    *) winbox - added "W60G station" tab in Wireless menu;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - added support for "_" symbol in terminal window;
    *) winbox - added switch menu on RB1100AHx4;
    *) winbox - do not show MetaROUTER stuff on RB1100AHx4;
    *) winbox - do not show duplicate "Switch" menus for CRS326;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - do not show unnecessary tabs from "Switch" menu;
    *) winbox - fixed "/certificate sign" process;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "allow-signal-out-off-range" option for Access List entries;
    *) wireless - added "indonesia3" regulatory domain information;
    *) wireless - added passive scan option for wireless scan mode;
    *) wireless - check APs against connect-list rules starting with strongest signal;
    *) wireless - do not show background scan frequencies in the monitor command channel field;
    *) wireless - fixed channel selection when special channels used (introduced in v6.41rc);
    *) wireless - improved reliability on "rx-rate" selection process;
    *) wireless - increased the EAP message retransmit count;
    *) wireless - log "signal-strength" when successfully connected to AP;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated "united kingdom" regulatory domain information;

  • Release 6.41rc61 2017-12-06

    What's new in 6.41rc61 (2017-Dec-06 08:15):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - general implementation of hw-offload bridge (introduced in v6.40rc36);
    *) bridge - disable "hw-offload" when "horizon" or "external-fdb" is set;
    *) bridge - fixed hw-offloaded IGMP Snooping service getting stopped;
    *) capsman - use "adaptive-noise-immunity" value from CAP local configuration;
    *) certificate - added option to store CRL in RAM (CLI only);
    *) certificate - improved CRL update after system startup;
    *) certificate - show invalid flag when local CRL file does not exist;
    *) crs317 - fixed reliability on FAN controller;
    *) dhcpv4-server - added "NETWORK_GATEWAY" option variable;
    *) filesystem - implemented additional system integrity checks on reboots;
    *) firewall - added "tls-host" firewall matcher;
    *) lte - fixed Passthrough support;
    *) lte - update info command with "location area code" (LAC);
    *) lte - provide lte info "physical cell id" values (R11e-LTE only);
    *) ppp - added initial support for PLE902;
    *) sms - log decoded USSD responses;
    *) snmp - fixed consecutive OID bulk get from the same table when non-repeaters are > 0;
    *) system - show USB topology for the device info;
    *) webfig - fixed router getting reset to default configuration;
    *) winbox - added switch menu on RB1100AHx4;
    *) winbox - do not show MetaROUTER stuff on RB1100AHx4;
    *) wireless - check APs against connect-list rules starting with strongest signal;
    *) wireless - do not show background scan frequencies in the monitor command channel field;
    *) wireless - fixed channel selection when special channels used (introduced in v6.41rc);
    *) wireless - increased the EAP message retransmit count;

    Other changes since 6.40.5:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) detnet - implemented "/interface detect-internet" feature;
    https://wiki.mikrotik.com/wiki/Manual:Detect_internet
    !) w60g - added Point to Multipoint support;
    !) routerboot - RouterBOOT version numbering system merged with RouterOS;
    !) wireless - new driver with initial support for 160 and 80+80 MHz channel width;
    *) arm - minor improvements on CPU load distribution for RB1100 series devices;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bgp - added 32-bit private ASN support;
    *) bridge - added comment support for VLANs (CLI only);
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - added support for "/interface list" as a bridge port;
    *) bridge - assume "point-to-point=yes" for all Full Duplex Ethernet interfaces when STP is used (as per standard);
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - set "igmp-snooping=no" by default on new bridges;
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) console - removed "/setup";
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) crs326 - fixed packet processing speed on switch chip if individual port link speed differs;
    *) crs3xx - added ingress/egress rate input limits;
    *) crs3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcp-client - limit and enforce DHCP client "default-route-distance" minimal value to 1;
    *) dhcp-server - added "option-set" argument (CLI only);
    *) dhcpv4-client - add dynamic DHCP client for mobile clients which require it;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) dhcpv4-server - strip trailing "\0" in "hostname" if present;
    *) discovery - use "/interface list" instead of interface name under neighbor discovery settings;
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) ethernet - removed "master-port" parameter;
    *) export - fixed interface list export;
    *) fetch - accept all HTTP 2xx status codes;
    *) health - fixed bogus voltage readings on CCR1009;
    *) hotspot - fixed "dst-port" to require valid "protocol" in "walled-garden ip";
    *) hotspot - fixed Walled Garden IP functionality when address-list is used;
    *) ike1 - fixed crash on xauth if user does not exist;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - fixed PH1 lifetime reset on boot;
    *) ike2 - fixed initiator DDoS cookie processing;
    *) ike2 - fixed responder DDoS cookie first notify type check;
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added default "/interface list" "dynamic" which contains dynamic interfaces;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2;
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - fixed incorrect esp proposal key size usage;
    *) ipsec - fixed policy enable/disable;
    *) ipsec - improved reliability on certificate usage;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipsec - skip invalid policies for phase2;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) l2tp - improved reliability on packet processing in FastPath;
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) log - added "bridge" topic;
    *) log - fixed interface name in log messages;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration);
    *) lte - added Passthrough support (CLI only);
    *) lte - added Passthrough support;
    *) lte - added Yota non-configurable modem support;
    *) lte - added support for ZTE ME3630 E1C with additional "/port" for GPS usage;
    *) lte - automatically add "/ip dhcp-client" configuration on interface;
    *) lte - changed default values to "add-default-route=yes", "use-peer-dns=yes" and "default-route-distance=2";
    *) lte - fixed authentication for non LTE modes;
    *) lte - fixed error when trying to add APN profile without name;
    *) lte - fixed rare crash when initializing LTE modem after reset;
    *) lte - fixed user authentication for R11e-LTE when new firmware is used;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - limited minimal default route distance to 1;
    *) m11g - improved ethernet performance on high load;
    *) mac-server - use "/interface list" instead of interface name under MAC server settings;
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) neighbor - show neighbors on actual bridge port instead of bridge itself
    *) netinstall - fixed missing "/flash/etc" on first bootup;
    *) netinstall - fixed missing default configuration prompt on first startup after reset/netinstall;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ovpn-server - do not periodically change automatically generated server MAC address;
    *) poe - added new "poe-out" status "controller-error";
    *) poe - fixed false positive excessive logs in auto-on mode when connected to 100 Mbps device powered from another power source;
    *) poe - log PoE status related messages under debug topic;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - do not disconnect PPP connection after "idle-timeout" even if traffic is being processed;
    *) ppp - fixed situation when part of PPP configuration was reset to default values after reboot;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) quickset - added support for "/interface list" in firewall, neighbor discovery, MAC-Telnet and MAC-Winbox;
    *) quickset - fixed situation when Quickset automatically changes mode to CPE;
    *) quickset - renamed router IP static DNS name to "router.lan";
    *) radius - limited RADIUS timeout maximum value to 3 seconds;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sms - fixed minor problem for SMS delivery;
    *) snmp - fixed "ifHighSpeed" value of VLAN, VRRP and Bonding interfaces;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) snmp - show only available OIDs under "/system health print oid";
    *) ssh - do not use DH group1 with strong-crypto enabled;
    *) ssh - enforced 2048bit DH group on tile and x86 architectures;
    *) tile - improved hardware encryption processes;
    *) tr069-client - fixed "/interface lte apn" configuration parameters;
    *) traceroute - improved "/tool traceroute" results processing;
    *) upnp - add "src-address" parameter on NAT rule if it is specified on UPnP request;
    *) upnp - deny UPnP request if port is already used by the router;
    *) ups - fixed duplicate "failed" UPS logs;
    *) userman - allow to generate more than 999 users;
    *) w60g - added "put-slaves-in-bridge" and "isolate-slaves" options to manage connected clients;
    *) w60g - connected stations are treated as separate interfaces;
    *) w60g - general work on PtMP implementation for 60 GHz connections;
    *) w60g - renamed modes - "master" to "ap-bridge", "slave" to "station-bridge";
    *) webfig - added favicon file;
    *) webfig - fixed terminal graphic user interface under Safari browser;
    *) winbox - added "W60G station" tab in Wireless menu;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - added support for "_" symbol in terminal window;
    *) winbox - do not show duplicate "Switch" menus for CRS326;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - do not show unnecessary tabs from "Switch" menu;
    *) winbox - fixed "/certificate sign" process;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "allow-signal-out-off-range" option for Access List entries;
    *) wireless - added "indonesia3" regulatory domain information;
    *) wireless - added passive scan option for wireless scan mode;
    *) wireless - improved reliability on "rx-rate" selection process;
    *) wireless - log "signal-strength" when successfully connected to AP;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated "united kingdom" regulatory domain information;

  • Release 6.41rc56 2017-11-24

    What's new in 6.41rc56 (2017-Nov-24 10:03):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - general implementation of hw-offload bridge (introduced in v6.40rc36);
    *) dhcp-client - limit and enforce DHCP client "default-route-distance" minimal value to 1;
    *) dhcpv4-server - strip trailing "\0" in "hostname" if present;
    *) filesystem - implemented additional system integrity checks on reboots;
    *) firewall - added "tls-host" firewall matcher (CLI only);
    *) hotspot - fixed "dst-port" to require valid "protocol" in "walled-garden ip";
    *) ike2 - fixed PH1 lifetime reset on boot;
    *) lte - fixed authentication for non LTE modes;
    *) tr069-client - fixed "/interface lte apn" configuration parameters;
    *) userman - allow to generate more than 999 users;
    *) wireless - added passive scan option for wireless scan mode;

    Other changes since 6.40.5:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) detnet - implemented "/interface detect-internet" feature;
    https://wiki.mikrotik.com/wiki/Manual:Detect_internet
    !) routerboot - RouterBOOT version numbering system merged with RouterOS;
    !) wireless - new driver with initial support for 160 and 80+80 MHz channel width;
    *) arm - minor improvements on CPU load distribution for RB1100 series devices;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bgp - added 32-bit private ASN support;
    *) bridge - added comment support for VLANs (CLI only);
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - added support for "/interface list" as a bridge port;
    *) bridge - assume "point-to-point=yes" for all Full Duplex Ethernet interfaces when STP is used (as per standard);
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - set "igmp-snooping=no" by default on new bridges;
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) console - removed "/setup";
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) crs326 - fixed packet processing speed on switch chip if individual port link speed differs;
    *) crs3xx - added ingress/egress rate input limits;
    *) crs3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcp-server - added "option-set" argument (CLI only);
    *) dhcpv4-client - add dynamic DHCP client for mobile clients which require it;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) discovery - use "/interface list" instead of interface name under neighbor discovery settings;
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) ethernet - removed "master-port" parameter;
    *) export - fixed interface list export;
    *) fetch - accept all HTTP 2xx status codes;
    *) health - fixed bogus voltage readings on CCR1009;
    *) hotspot - fixed Walled Garden IP functionality when address-list is used;
    *) ike1 - fixed crash on xauth if user does not exist;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - fixed initiator DDoS cookie processing;
    *) ike2 - fixed responder DDoS cookie first notify type check;
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added default "/interface list" "dynamic" which contains dynamic interfaces;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2;
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - fixed incorrect esp proposal key size usage;
    *) ipsec - fixed policy enable/disable;
    *) ipsec - improved reliability on certificate usage;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipsec - skip invalid policies for phase2;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) l2tp - improved reliability on packet processing in FastPath;
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) log - added "bridge" topic;
    *) log - fixed interface name in log messages;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration);
    *) lte - added Passthrough support (CLI only);
    *) lte - added Passthrough support;
    *) lte - added Yota non-configurable modem support;
    *) lte - added support for ZTE ME3630 E1C with additional "/port" for GPS usage;
    *) lte - automatically add "/ip dhcp-client" configuration on interface;
    *) lte - changed default values to "add-default-route=yes", "use-peer-dns=yes" and "default-route-distance=2";
    *) lte - fixed error when trying to add APN profile without name;
    *) lte - fixed rare crash when initializing LTE modem after reset;
    *) lte - fixed user authentication for R11e-LTE when new firmware is used;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - limited minimal default route distance to 1;
    *) m11g - improved ethernet performance on high load;
    *) mac-server - use "/interface list" instead of interface name under MAC server settings;
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) neighbor - show neighbors on actual bridge port instead of bridge itself
    *) netinstall - fixed missing "/flash/etc" on first bootup;
    *) netinstall - fixed missing default configuration prompt on first startup after reset/netinstall;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ovpn-server - do not periodically change automatically generated server MAC address;
    *) poe - added new "poe-out" status "controller-error";
    *) poe - fixed false positive excessive logs in auto-on mode when connected to 100 Mbps device powered from another power source;
    *) poe - log PoE status related messages under debug topic;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - do not disconnect PPP connection after "idle-timeout" even if traffic is being processed;
    *) ppp - fixed situation when part of PPP configuration was reset to default values after reboot;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) quickset - added support for "/interface list" in firewall, neighbor discovery, MAC-Telnet and MAC-Winbox;
    *) quickset - fixed situation when Quickset automatically changes mode to CPE;
    *) quickset - renamed router IP static DNS name to "router.lan";
    *) radius - limited RADIUS timeout maximum value to 3 seconds;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sms - fixed minor problem for SMS delivery;
    *) snmp - fixed "ifHighSpeed" value of VLAN, VRRP and Bonding interfaces;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) snmp - show only available OIDs under "/system health print oid";
    *) ssh - do not use DH group1 with strong-crypto enabled;
    *) ssh - enforced 2048bit DH group on tile and x86 architectures;
    *) tile - improved hardware encryption processes;
    *) traceroute - improved "/tool traceroute" results processing;
    *) upnp - add "src-address" parameter on NAT rule if it is specified on UPnP request;
    *) upnp - deny UPnP request if port is already used by the router;
    *) ups - fixed duplicate "failed" UPS logs;
    *) w60g - general work on PtMP implementation for 60 GHz connections;
    *) webfig - added favicon file;
    *) webfig - fixed terminal graphic user interface under Safari browser;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - added support for "_" symbol in terminal window;
    *) winbox - do not show duplicate "Switch" menus for CRS326;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - do not show unnecessary tabs from "Switch" menu;
    *) winbox - fixed "/certificate sign" process;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "allow-signal-out-off-range" option for Access List entries;
    *) wireless - added "indonesia3" regulatory domain information;
    *) wireless - improved reliability on "rx-rate" selection process;
    *) wireless - log "signal-strength" when successfully connected to AP;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated "united kingdom" regulatory domain information;

  • Release 6.41rc52 2017-11-22

    What's new in 6.41rc52 (2017-Nov-07 08:48):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - general implementation of hw-offload bridge (introduced in v6.40rc36);
    *) discovery - use "/interface list" instead of interface name under neighbor discovery settings;
    *) hotspot - fixed Walled Garden IP functionality when address-list is used;
    *) ovpn-server - do not periodically change automatically generated server MAC address;
    *) poe - added new "poe-out" status "controller-error";
    *) poe - fixed false positive excessive logs in auto-on mode when connected to 100 Mbps device powered from another power source;
    *) poe - log PoE status related messages under debug topic;
    *) ppp - do not disconnect PPP connection after "idle-timeout" even if traffic is being processed;
    *) quickset - added support for "/interface list" in firewall, neighbor discovery, MAC-Telnet and MAC-Winbox;
    *) quickset - fixed situation when Quickset automatically changes mode to CPE;
    *) w60g - general work on PtMP implementation for 60 GHz connections;
    *) wireless - added "indonesia3" regulatory domain information;
    *) wireless - added passive scan functionality (CLI only);

    Other changes since 6.40.5:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) detnet - implemented "/interface detect-internet" feature;
    https://wiki.mikrotik.com/wiki/Manual:Detect_internet
    !) routerboot - RouterBOOT version numbering system merged with RouterOS;
    *) arm - minor improvements on CPU load distribution for RB1100 series devices;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bgp - added 32-bit private ASN support;
    *) bridge - added comment support for VLANs (CLI only);
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - added support for "/interface list" as a bridge port;
    *) bridge - assume "point-to-point=yes" for all Full Duplex Ethernet interfaces when STP is used (as per standard);
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - set "igmp-snooping=no" by default on new bridges;
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) console - removed "/setup";
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) crs326 - fixed packet processing speed on switch chip if individual port link speed differs;
    *) crs3xx - added ingress/egress rate input limits;
    *) crs3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcp-client - limited DHCP client "default-route-distance" minimal value to 1;
    *) dhcp-server - added "option-set" argument (CLI only);
    *) dhcpv4-client - add dynamic DHCP client for mobile clients which require it;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) ethernet - removed "master-port" parameter;
    *) export - fixed interface list export;
    *) fetch - accept all HTTP 2xx status codes;
    *) health - fixed bogus voltage readings on CCR1009;
    *) ike1 - fixed crash on xauth if user does not exist;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - fixed initiator DDoS cookie processing;
    *) ike2 - fixed responder DDoS cookie first notify type check;
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added default "/interface list" "dynamic" which contains dynamic interfaces;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2;
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - fixed incorrect esp proposal key size usage;
    *) ipsec - fixed policy enable/disable;
    *) ipsec - improved reliability on certificate usage;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipsec - skip invalid policies for phase2;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) l2tp - improved reliability on packet processing in FastPath;
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) log - added "bridge" topic;
    *) log - fixed interface name in log messages;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration);
    *) lte - added Passthrough support (CLI only);
    *) lte - added Passthrough support;
    *) lte - added support for ZTE ME3630 E1C with additional "/port" for GPS usage;
    *) lte - added Yota non-configurable modem support;
    *) lte - automatically add "/ip dhcp-client" configuration on interface;
    *) lte - changed default values to "add-default-route=yes", "use-peer-dns=yes" and "default-route-distance=2";
    *) lte - fixed error when trying to add APN profile without name;
    *) lte - fixed rare crash when initializing LTE modem after reset;
    *) lte - fixed user authentication for R11e-LTE when new firmware is used;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - limited minimal default route distance to 1;
    *) m11g - improved ethernet performance on high load;
    *) mac-server - use "/interface list" instead of interface name under MAC server settings;
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) neighbor - show neighbors on actual bridge port instead of bridge itself
    *) netinstall - fixed missing "/flash/etc" on first bootup;
    *) netinstall - fixed missing default configuration prompt on first startup after reset/netinstall;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - fixed situation when part of PPP configuration was reset to default values after reboot;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) quickset - renamed router IP static DNS name to "router.lan";
    *) radius - limited RADIUS timeout maximum value to 3 seconds;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sms - fixed minor problem for SMS delivery;
    *) snmp - fixed "ifHighSpeed" value of VLAN, VRRP and Bonding interfaces;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) snmp - show only available OIDs under "/system health print oid";
    *) ssh - do not use DH group1 with strong-crypto enabled;
    *) ssh - enforced 2048bit DH group on tile and x86 architectures;
    *) tile - improved hardware encryption processes;
    *) traceroute - improved "/tool traceroute" results processing;
    *) upnp - add "src-address" parameter on NAT rule if it is specified on UPnP request;
    *) upnp - deny UPnP request if port is already used by the router;
    *) ups - fixed duplicate "failed" UPS logs;
    *) webfig - added favicon file;
    *) webfig - fixed terminal graphic user interface under Safari browser;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - added support for "_" symbol in terminal window;
    *) winbox - do not show duplicate "Switch" menus for CRS326;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - do not show unnecessary tabs from "Switch" menu;
    *) winbox - fixed "/certificate sign" process;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "allow-signal-out-off-range" option for Access List entries;
    *) wireless - improved reliability on "rx-rate" selection process;
    *) wireless - log "signal-strength" when successfully connected to AP;
    *) wireless - new driver with initial support for 160 and 80+80 MHz channel width;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated "united kingdom" regulatory domain information;

  • Release 6.41rc50 2017-11-01

    What's new in 6.41rc50 (2017-Oct-30 10:13):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - general implementation of hw-offload bridge (introduced in v6.40rc36);
    !) detnet - implemented "/interface detect-internet" feature;
    https://wiki.mikrotik.com/wiki/Manual:Detect_internet
    *) bridge - set "igmp-snooping=no" by default on new bridges;
    *) crs3xx - added ingress/egress rate input limits;
    *) dhcp-client - limited DHCP client "default-route-distance" minimal value to 1;
    *) dhcp-server - added "option-set" argument (CLI only);
    *) discovery - use "/interface list" instead of interface name under neighbor discovery settings;
    *) health - fixed bogus voltage readings on CCR1009;
    *) ike1 - fixed crash after downgrade if DH groups 19,20,21 were used for phase1;
    *) ike1 - fixed crash on xauth if user does not exist;
    *) ipv6 - fixed IPv6 addresses constructed from prefix and static address entry;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration);
    *) lte - added Passthrough support;
    *) lte - fixed user authentication for R11e-LTE when new firmware is used;
    *) m11g - improved ethernet performance on high load;
    *) netinstall - fixed missing "/flash/etc" on first bootup;
    *) quickset - renamed router IP static DNS name to "router.lan";
    *) radius - limited RADIUS timeout maximum value to 3 seconds;
    *) sms - fixed minor problem for SMS delivery;
    *) webfig - added favicon file;
    *) webfig - fixed terminal graphic user interface under Safari browser;
    *) winbox - do not show unnecessary tabs from "Switch" menu;
    *) wireless - new driver with initial support for 160 and 80+80 MHz channel width;

    Other changes since 6.40.4:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) routerboot - RouterBOOT version numbering system merged with RouterOS;
    *) arm - minor improvements on CPU load distribution for RB1100 series devices;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bgp - added 32-bit private ASN support;
    *) bridge - added comment support for VLANs (CLI only);
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - added support for "/interface list" as a bridge port;
    *) bridge - assume "point-to-point=yes" for all Full Duplex Ethernet interfaces when STP is used (as per standard);
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) console - removed "/setup";
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) crs326 - fixed packet processing speed on switch chip if individual port link speed differs;
    *) crs3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv4-client - add dynamic DHCP client for mobile clients which require it;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) ethernet - removed "master-port" parameter;
    *) export - fixed interface list export;
    *) fetch - accept all HTTP 2xx status codes;
    *) firewall - do not NAT address to 0.0.0.0 after reboot if to-address is used but not specified;
    *) ike1 - fixed RSA authentication for Windows clients behind NAT;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - fixed initiator DDoS cookie processing;
    *) ike2 - fixed responder DDoS cookie first notify type check;
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added default "/interface list" "dynamic" which contains dynamic interfaces;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2;
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - fixed incorrect esp proposal key size usage;
    *) ipsec - fixed lost value for "remote-certificate" parameter after disable/enable;
    *) ipsec - fixed policy enable/disable;
    *) ipsec - improved reliability on certificate usage;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipsec - skip invalid policies for phase2;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) l2tp - improved reliability on packet processing in FastPath;
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) log - added "bridge" topic;
    *) log - fixed interface name in log messages;
    *) log - optimized "poe-out" logging topic logs;
    *) log - properly recognize MikroTik specific RADIUS attributes;
    *) lte - added Passthrough support (CLI only);
    *) lte - added Yota non-configurable modem support;
    *) lte - added support for ZTE ME3630 E1C with additional "/port" for GPS usage;
    *) lte - automatically add "/ip dhcp-client" configuration on interface;
    *) lte - changed default values to "add-default-route=yes", "use-peer-dns=yes" and "default-route-distance=2";
    *) lte - do not reset modem when it is not possible to access SMS storage;
    *) lte - fixed PIN option after setting up the band;
    *) lte - fixed error when trying to add APN profile without name;
    *) lte - fixed modem initialization after reboot;
    *) lte - fixed rare crash when initializing LTE modem after reset;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - limited minimal default route distance to 1;
    *) mac-server - use "/interface list" instead of interface name under MAC server settings;
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) neighbor - show neighbors on actual bridge port instead of bridge itself
    *) netinstall - fixed missing default configuration prompt on first startup after reset/netinstall;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - fixed situation when part of PPP configuration was reset to default values after reboot;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sms - include timestamps in SMS delivery reports;
    *) sms - properly initialize SMS storage;
    *) snmp - fixed "/system license" parameters for CHR;
    *) snmp - fixed "ifHighSpeed" value of VLAN, VRRP and Bonding interfaces;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) snmp - show only available OIDs under "/system health print oid";
    *) ssh - do not use DH group1 with strong-crypto enabled;
    *) ssh - enforced 2048bit DH group on tile and x86 architectures;
    *) tile - improved hardware encryption processes;
    *) traceroute - improved "/tool traceroute" results processing;
    *) upnp - add "src-address" parameter on NAT rule if it is specified on UPnP request;
    *) upnp - deny UPnP request if port is already used by the router;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - added support for "_" symbol in terminal window;
    *) winbox - allow shorten bytes to k,M,G in Hotspot user limits;
    *) winbox - do not show duplicate "Switch" menus for CRS326;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed "/certificate sign" process;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "allow-signal-out-off-range" option for Access List entries;
    *) wireless - fixed rate selection process when "rate-set=configured" and NV2 protocol is used;
    *) wireless - improved reliability on "rx-rate" selection process;
    *) wireless - log "signal-strength" when successfully connected to AP;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated "united kingdom" regulatory domain information;

  • Release 6.41rc47 2017-10-18

    What's new in 6.41rc47 (2017-Oct-18 10:38):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - general implementation of hw-offload bridge (introduced in v6.40rc36);
    !) detnet - implemented "/interface detect-internet" feature;
    https://wiki.mikrotik.com/wiki/Manual:Detect_internet
    !) routerboot - RouterBOOT version numbering system merged with RouterOS;
    *) bridge - assume "point-to-point=yes" for all Full Duplex Ethernet interfaces when STP is used (as per standard);
    *) console - removed "/setup";
    *) crs3xx - added ingress/egress rate input limits;
    *) discovery - use "/interface list" instead of interface name under neighbour discovery settings;
    *) ethernet - fixed missing "sfp-tx-power" option (introduced in v6.41rc14);
    *) ipsec - fixed incorrect esp proposal key size usage;
    *) lte - temporarily disabled user authentication using user/password PAP/CHAP support for R11e-LTE (introduced in v6.41rc44);
    *) lte - fixed PIN option after setting up the band;
    *) lte - fixed error when trying to add APN profile without name;
    *) lte - fixed rare crash when initializing LTE modem after reset;
    *) netinstall - fixed missing default configuration prompt on first startup after reset/netinstall;
    *) ssh - do not use DH group1 with strong-crypto enabled;
    *) ssh - enforced 2048bit DH group on tile and x86 architectures;
    *) winbox - added support for "_" symbol in terminal window;

    Other changes since 6.40.4:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    *) arm - minor improvements on CPU load distribution for RB1100 series devices;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bgp - added 32-bit private ASN support;
    *) bridge - added comment support for VLANs (CLI only);
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - added support for "/interface list" as a bridge port;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) crs326 - fixed packet processing speed on switch chip if individual port link speed differs;
    *) crs3xx - added port ingress and egress rate limiting;
    *) crs3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv4-client - add dynamic DHCP client for mobile clients which require it;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) ethernet - removed "master-port" parameter;
    *) export - fixed interface list export;
    *) fetch - accept all HTTP 2xx status codes;
    *) firewall - do not NAT address to 0.0.0.0 after reboot if to-address is used but not specified;
    *) ike1 - fixed RSA authentication for Windows clients behind NAT;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - fixed initiator DDoS cookie processing;
    *) ike2 - fixed responder DDoS cookie first notify type check;
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added default "/interface list" "dynamic" which contains dynamic interfaces;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2;
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - fixed lost value for "remote-certificate" parameter after disable/enable;
    *) ipsec - fixed policy enable/disable;
    *) ipsec - improved reliability on certificate usage;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipsec - skip invalid policies for phase2;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) l2tp - improved reliability on packet processing in FastPath;
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) log - added "bridge" topic;
    *) log - fixed interface name in log messages;
    *) log - optimized "poe-out" logging topic logs;
    *) log - properly recognize MikroTik specific RADIUS attributes;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration);
    *) lte - added Passthrough support (CLI only);
    *) lte - added Yota non-configurable modem support;
    *) lte - added support for ZTE ME3630 E1C with additional "/port" for GPS usage;
    *) lte - automatically add "/ip dhcp-client" configuration on interface;
    *) lte - changed default values to "add-default-route=yes", "use-peer-dns=yes" and "default-route-distance=2";
    *) lte - do not reset modem when it is not possible to access SMS storage;
    *) lte - fixed modem initialization after reboot;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - limited minimal default route distance to 1;
    *) mac-server - use "/interface list" instead of interface name under MAC server settings;
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) neighbor - show neighbors on actual bridge port instead of bridge itself
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - fixed situation when part of PPP configuration was reset to default values after reboot;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sms - include timestamps in SMS delivery reports;
    *) sms - properly initialize SMS storage;
    *) snmp - fixed "/system license" parameters for CHR;
    *) snmp - fixed "ifHighSpeed" value of VLAN, VRRP and Bonding interfaces;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) snmp - show only available OIDs under "/system health print oid";
    *) tile - improved hardware encryption processes;
    *) traceroute - improved "/tool traceroute" results processing;
    *) upnp - add "src-address" parameter on NAT rule if it is specified on UPnP request;
    *) upnp - deny UPnP request if port is already used by the router;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - allow shorten bytes to k,M,G in Hotspot user limits;
    *) winbox - do not show duplicate "Switch" menus for CRS326;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed "/certificate sign" process;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "allow-signal-out-off-range" option for Access List entries;
    *) wireless - fixed rate selection process when "rate-set=configured" and NV2 protocol is used;
    *) wireless - improved reliability on "rx-rate" selection process;
    *) wireless - log "signal-strength" when successfully connected to AP;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated "united kingdom" regulatory domain information;

  • Release 6.41rc44 2017-10-11

    What's new in 6.41rc44 (2017-Oct-11 08:21):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) detnet - implemented "/interface detect-internet" feature;
    https://wiki.mikrotik.com/wiki/Manual:Detect_internet
    *) bridge - added comment support for VLANs;
    *) bridge - added support for "/interface list" as a bridge port;
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) crs3xx - fixed 100% CPU usage after interface related changes (introduced in v6.41rc31);
    *) dhcpv4-client - add dynamic DHCP client for mobile clients which require it;
    *) fetch - accept all HTTP 2xx status codes;
    *) firewall - do not NAT address to 0.0.0.0 after reboot if to-address is used but not specified;
    *) ike1 - fixed RSA authentication for Windows clients behind NAT;
    *) interface - added default "/interface list" "dynamic" which contains dynamic interfaces;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2;
    *) ipsec - fixed lost value for "remote-certificate" parameter after disable/enable;
    *) ipsec - fixed policy enable/disable;
    *) ipsec - improved reliability on certificate usage;
    *) ipsec - skip invalid policies for phase2;
    *) l2tp - improved reliability on packet processing in FastPath;
    *) log - fixed interface name in log messages;
    *) log - properly recognize MikroTik specific RADIUS attributes;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration);
    *) lte - added Passthrough support (CLI only);
    *) lte - fixed modem initialization after reboot;
    *) lte - limited minimal default route distance to 1;
    *) mac-server - use "/interface list" instead of interface name under MAC server settings;
    *) neighbor - show neighbors on actual bridge port instead of bridge itself
    *) sms - include timestamps in SMS delivery reports;
    *) sms - properly initialize SMS storage;
    *) snmp - show only available OIDs under "/system health print oid";
    *) winbox - allow shorten bytes to k,M,G in Hotspot user limits;
    *) winbox - do not show duplicate "Switch" menus for CRS326;
    *) winbox - fixed "/certificate sign" process;
    *) wireless - added "allow-signal-out-off-range" option for Access List entries;

    Other changes since 6.40.4:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arm - minor improvements on CPU load distribution for RB1100 series devices;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bgp - added 32-bit private ASN support;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) crs326 - fixed packet processing speed on switch chip if individual port link speed differs;
    *) crs3xx - added port ingress and egress rate limiting;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) ethernet - removed "master-port" parameter;
    *) export - fixed interface list export;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - fixed initiator DDoS cookie processing;
    *) ike2 - fixed responder DDoS cookie first notify type check;
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - added "bridge" topic;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added support for ZTE ME3630 E1C with additional "/port" for GPS usage;
    *) lte - added Yota non-configurable modem support;
    *) lte - automatically add "/ip dhcp-client" configuration on interface;
    *) lte - changed default values to "add-default-route=yes", "use-peer-dns=yes" and "default-route-distance=2";
    *) lte - do not reset modem when it is not possible to access SMS storage;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in v6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - fixed missing PPP client interface after reboot (introduced in v6.41rc);
    *) ppp - fixed serial port loading (introduced in v6.41rc);
    *) ppp - fixed situation when part of PPP configuration was reset to default values after reboot;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) snmp - fixed "/system license" parameters for CHR;
    *) snmp - fixed "ifHighSpeed" value of VLAN, VRRP and Bonding interfaces;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) tile - improved hardware encryption processes;
    *) traceroute - improved "/tool traceroute" results processing;
    *) upnp - add "src-address" parameter on NAT rule if it is specified on UPnP request;
    *) upnp - deny UPnP request if port is already used by the router;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - fixed rate selection process when "rate-set=configured" and NV2 protocol is used;
    *) wireless - improved reliability on "rx-rate" selection process;
    *) wireless - log "signal-strength" when successfully connected to AP;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated "united kingdom" regulatory domain information;

  • Release 6.41rc38 2017-10-03

    What's new in 6.41rc38 (2017-Oct-03 11:51):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) arm - minor improvements on CPU load distribution for RB1100 series devices;
    *) bgp - added 32-bit private ASN support;
    *) lte - added Passthrough support (CLI only);
    *) snmp - fixed "/system license" parameters for CHR;
    *) upnp - add "src-address" parameter on NAT rule if it is specified on UPnP request;
    *) upnp - deny UPnP request if port is already used by the router;

    Other changes since 6.40.4:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - initial support for "/interface list" as a bridge port (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) crs326 - fixed packet processing speed on switch chip if individual port link speed differs;
    *) crs3xx - added port ingress and egress rate limiting;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) ethernet - removed "master-port" parameter;
    *) export - fixed interface list export;
    *) fetch - accept all HTTP 2xx status codes;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - fixed initiator DDoS cookie processing;
    *) ike2 - fixed responder DDoS cookie first notify type check;
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - added "bridge" topic;
    *) log - fixed "unknown" interface name in log messages;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration) (CLI only);
    *) lte - added support for ZTE ME3630 E1C with additional "/port" for GPS usage;
    *) lte - added Yota non-configurable modem support;
    *) lte - automatically add "/ip dhcp-client" configuration on interface;
    *) lte - changed default values to "add-default-route=yes", "use-peer-dns=yes" and "default-route-distance=2";
    *) lte - do not reset modem when it is not possible to access SMS storage;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in v6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - fixed missing PPP client interface after reboot (introduced in v6.41rc);
    *) ppp - fixed serial port loading (introduced in v6.41rc);
    *) ppp - fixed situation when part of PPP configuration was reset to default values after reboot;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) snmp - fixed "ifHighSpeed" value of VLAN, VRRP and Bonding interfaces;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) tile - improved hardware encryption processes;
    *) traceroute - improved "/tool traceroute" results processing;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "allow-signal-out-off-range" option for Access List entries (CLI only);
    *) wireless - fixed rate selection process when "rate-set=configured" and NV2 protocol is used;
    *) wireless - improved reliability on "rx-rate" selection process;
    *) wireless - log "signal-strength" when successfully connected to AP;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated "united kingdom" regulatory domain information;

  • Release 6.41rc37 2017-10-02

    What's new in 6.41rc37 (2017-Oct-02 06:47):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) bridge - initial support for "/interface list" as a bridge port (CLI only);
    *) fetch - accept all HTTP 2xx status codes;
    *) ike2 - fixed initiator DDoS cookie processing;
    *) ike2 - fixed responder DDoS cookie first notify type check;
    *) lte - fixed modem initialization after reboot;
    *) ntp-client - properly start NTP client after reboot if manual server IP is not configured;
    *) sfp - fixed OPTON module DDM information readings;
    *) wireless - added "etsi1" regulatory domain information;
    *) wireless - improved WPA2 key exchange reliability;
    *) wireless - updated "norway" regulatory domain information;

    Other changes since 6.40.3:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    *) address - show warning on IPv6 address when acquire from pool has failed;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) arp - properly update dynamic ARP entries after interface related changes;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) crs1xx/2xx - fixed 1 Gbps forced mode for several SFP modules;
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) crs317 - added L2MTU support;
    *) crs326 - fixed packet processing speed on switch chip if individual port link speed differs;
    *) crs3xx - added port ingress and egress rate limiting;
    *) crs3xx - improved packet processing in slowpath;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) defconf - fixed RouterOS default configuration (introduced in v6.40.3);
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "rapid-commit" is enabled;
    *) dhcpv6-client - ignore unknown IA;
    *) dhcpv6-client - require pool name to be unique;
    *) e-mail - auto complete file name on "file" parameter (introduced in v6.40);
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) ethernet - removed "master-port" parameter;
    *) export - fixed interface list export;
    *) export - fixed wireless "ssid" and "supplicant-identity" compact export;
    *) hotspot - fixed missing "/ip hotspot server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike1 - remove PH1 and PH2 when "mode-config" exchange fails;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in v6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - added "bridge" topic;
    *) log - fixed "unknown" interface name in log messages;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration) (CLI only);
    *) lte - added Passthrough support (CLI only);
    *) lte - added support for ZTE ME3630 E1C with additional "/port" for GPS usage;
    *) lte - added Yota non-configurable modem support;
    *) lte - automatically add "/ip dhcp-client" configuration on interface;
    *) lte - changed default values to "add-default-route=yes", "use-peer-dns=yes" and "default-route-distance=2";
    *) lte - do not reset modem when it is not possible to access SMS storage;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in v6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - fixed missing PPP client interface after reboot (introduced in v6.41rc);
    *) ppp - fixed serial port loading (introduced in v6.41rc);
    *) ppp - fixed situation when part of PPP configuration was reset to default values after reboot;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb931-2nd - fixed startup problems (requires additional reboot after upgrade);
    *) routerboard - fixed "/system routerboard upgrade" for CRS212-8G-4S;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sfp - fixed temperature readings for various SFP modules;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) snmp - fixed "/system license" parameters for CHR;
    *) snmp - fixed "ifHighSpeed" value of VLAN, VRRP and Bonding interfaces;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) snmp - fixed "/caps-man registration-table" uptime values;
    *) tile - improved reliability on MPLS package processing;
    *) tile - improved hardware encryption processes;
    *) traceroute - improved "/tool traceroute" results processing;
    *) ups - fixed duplicate "failed" UPS logs;
    *) userman - fixed unresponsive RADIUS server (introduced in v6.40.3);
    *) vlan - do not allow VLAN MTU to be higher than L2MTU;
    *) webfig - improved reliability of login process;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "allow-signal-out-off-range" option for Access List entries (CLI only);
    *) wireless - fixed rate selection process when "rate-set=configured" and NV2 protocol is used;
    *) wireless - improved reliability on "rx-rate" selection process;
    *) wireless - log "signal-strength" when successfully connected to AP;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated "united kingdom" regulatory domain information;

  • Release 6.41rc34 2017-09-27

    What's new in 6.41rc34 (2017-Sep-27 10:05):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) crs3xx - improved packet processing in slowpath;
    *) defconf - fixed RouterOS default configuration (introduced in v6.40.3);
    *) ethernet - removed "master-port" parameter;
    *) log - fixed "unknown" interface name in log messages;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration) (CLI only);
    *) lte - do not reset modem when it is not possible to access SMS storage;
    *) snmp - fixed "ifHighSpeed" value of VLAN, VRRP and Bonding interfaces;
    *) snmp - fixed "/caps-man registration-table" uptime values;
    *) tile - improved hardware encryption processes;
    *) vlan - do not allow VLAN MTU to be higher than L2MTU;
    *) wireless - fixed rate selection process when "rate-set=configured" and NV2 protocol is used;

    Other changes since 6.40.3:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) address - show warning on IPv6 address when acquire from pool has failed;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) arp - properly update dynamic ARP entries after interface related changes;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) crs1xx/2xx - fixed 1 Gbps forced mode for several SFP modules;
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) crs317 - added L2MTU support;
    *) crs326 - fixed packet processing speed on switch chip if individual port link speed differs;
    *) crs3xx - added port ingress and egress rate limiting;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "rapid-commit" is enabled;
    *) dhcpv6-client - ignore unknown IA;
    *) dhcpv6-client - require pool name to be unique;
    *) e-mail - auto complete file name on "file" parameter (introduced in v6.40);
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) export - fixed interface list export;
    *) export - fixed wireless "ssid" and "supplicant-identity" compact export;
    *) hotspot - fixed missing "/ip hotspot server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike1 - remove PH1 and PH2 when "mode-config" exchange fails;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in v6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - added "bridge" topic;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added Passthrough support (CLI only);
    *) lte - added support for ZTE ME3630 E1C with additional "/port" for GPS usage;
    *) lte - added Yota non-configurable modem support;
    *) lte - automatically add "/ip dhcp-client" configuration on interface;
    *) lte - changed default values to "add-default-route=yes", "use-peer-dns=yes" and "default-route-distance=2";
    *) lte - fixed mode initialization after reboot;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in v6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - fixed missing PPP client interface after reboot (introduced in v6.41rc);
    *) ppp - fixed serial port loading (introduced in v6.41rc);
    *) ppp - fixed situation when part of PPP configuration was reset to default values after reboot;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb931-2nd - fixed startup problems (requires additional reboot after upgrade);
    *) routerboard - fixed "/system routerboard upgrade" for CRS212-8G-4S;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sfp - fixed temperature readings for various SFP modules;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) snmp - fixed "/system license" parameters for CHR;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) tile - improved reliability on MPLS package processing;
    *) traceroute - improved "/tool traceroute" results processing;
    *) ups - fixed duplicate "failed" UPS logs;
    *) userman - fixed unresponsive RADIUS server (introduced in v6.40.3);
    *) webfig - improved reliability of login process;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "allow-signal-out-off-range" option for Access List entries (CLI only);
    *) wireless - improved reliability on "rx-rate" selection process;
    *) wireless - log "signal-strength" when successfully connected to AP;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated United Kingdom regulatory domain information;

  • Release 6.41rc32 2017-09-22

    What's new in 6.41rc32 (2017-Sep-21 13:51):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - implemented software based "igmp-snooping";
    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration) (CLI only);
    *) traceroute - improved "/tool traceroute" results processing;
    *) wireless - log "signal-strength" when successfully connected to AP;

    Other changes since 6.40.3:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    *) address - show warning on IPv6 address when acquire from pool has failed;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) arp - properly update dynamic ARP entries after interface related changes;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter;
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) crs1xx/2xx - fixed 1 Gbps forced mode for several SFP modules;
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) crs317 - added L2MTU support;
    *) crs326 - fixed packet processing speed on switch chip if individual port link speed differs;
    *) crs3xx - added port ingress and egress rate limiting;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "rapid-commit" is enabled;
    *) dhcpv6-client - ignore unknown IA;
    *) dhcpv6-client - require pool name to be unique;
    *) e-mail - auto complete file name on "file" parameter (introduced in v6.40);
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) export - fixed interface list export;
    *) export - fixed wireless "ssid" and "supplicant-identity" compact export;
    *) hotspot - fixed missing "/ip hotspot server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike1 - remove PH1 and PH2 when "mode-config" exchange fails;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in v6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - added "bridge" topic;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added Passthrough support (CLI only);
    *) lte - added support for ZTE ME3630 E1C with additional "/port" for GPS usage;
    *) lte - added Yota non-configurable modem support;
    *) lte - automatically add "/ip dhcp-client" configuration on interface;
    *) lte - changed default values to "add-default-route=yes", "use-peer-dns=yes" and "default-route-distance=2";
    *) lte - fixed mode initialization after reboot;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in v6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - fixed missing PPP client interface after reboot (introduced in v6.41rc);
    *) ppp - fixed serial port loading (introduced in v6.41rc);
    *) ppp - fixed situation when part of PPP configuration was reset to default values after reboot;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb931-2nd - fixed startup problems (requires additional reboot after upgrade);
    *) routerboard - fixed "/system routerboard upgrade" for CRS212-8G-4S;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sfp - fixed temperature readings for various SFP modules;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) snmp - fixed "/system license" parameters for CHR;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) tile - improved reliability on MPLS package processing;
    *) ups - fixed duplicate "failed" UPS logs;
    *) userman - fixed unresponsive RADIUS server (introduced in v6.40.3);
    *) webfig - improved reliability of login process;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "allow-signal-out-off-range" option for Access List entries (CLI only);
    *) wireless - improved reliability on "rx-rate" selection process;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated United Kingdom regulatory domain information;

  • Release 6.41rc31 2017-09-20

    What's new in 6.41rc31 (2017-Sep-20 06:56):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration) (CLI only);
    *) lte - added Passthrough support (CLI only);
    *) lte - added support for ZTE ME3630 E1C with additional "/port" for GPS usage;
    *) lte - automatically add "/ip dhcp-client" configuration on interface;
    *) lte - changed default values to "add-default-route=yes", "use-peer-dns=yes" and "default-route-distance=2";
    *) ppp - fixed serial port loading (introduced in v6.41rc);
    *) sfp - fixed temperature readings for various SFP modules;
    *) snmp - fixed "/system license" parameters for CHR;
    *) wireless - improved reliability on "rx-rate" selection process;

    Other changes since 6.40.3:

    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    *) address - show warning on IPv6 address when acquire from pool has failed;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) arp - properly update dynamic ARP entries after interface related changes;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter;
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) crs1xx/2xx - fixed 1 Gbps forced mode for several SFP modules;
    *) crs317 - added L2MTU support;
    *) crs326 - fixed packet processing speed on switch chip if individual port link speed differs;
    *) crs3xx - added port ingress and egress rate limiting;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "rapid-commit" is enabled;
    *) dhcpv6-client - ignore unknown IA;
    *) dhcpv6-client - require pool name to be unique;
    *) e-mail - auto complete file name on "file" parameter (introduced in v6.40);
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) export - fixed interface list export;
    *) export - fixed wireless "ssid" and "supplicant-identity" compact export;
    *) hotspot - fixed missing "/ip hotspot server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike1 - remove PH1 and PH2 when "mode-config" exchange fails;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in v6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - added "bridge" topic;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added Yota non-configurable modem support;
    *) lte - fixed mode initialization after reboot;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in v6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - fixed missing PPP client interface after reboot (introduced in v6.41rc);
    *) ppp - fixed situation when part of PPP configuration was reset to default values after reboot;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb931-2nd - fixed startup problems (requires additional reboot after upgrade);
    *) routerboard - fixed "/system routerboard upgrade" for CRS212-8G-4S;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) tile - improved reliability on MPLS package processing;
    *) ups - fixed duplicate "failed" UPS logs;
    *) userman - fixed unresponsive RADIUS server (introduced in v6.40.3);
    *) webfig - improved reliability of login process;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "allow-signal-out-off-range" option for Access List entries (CLI only);
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated United Kingdom regulatory domain information;

  • Release 6.41rc30 2017-09-19

    What's new in 6.41rc30 (2017-Sep-15 11:50):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) crs317 - added L2MTU support;
    *) crs326 - fixed packet processing speed on switch chip if individual port link speed differs;
    *) crs3xx - added port ingress and egress rate limiting;
    *) export - fixed wireless "ssid" and "supplicant-identity" compact export;
    *) ppp - fixed situation when part of PPP configuration was reset to default values after reboot;
    *) wireless - added "allow-signal-out-of-range" option for Access List entries (CLI only);

    Other changes since 6.40.3:

    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    *) address - show warning on IPv6 address when acquire from pool has failed;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) arp - properly update dynamic ARP entries after interface related changes;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter;
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) crs1xx/2xx - fixed 1 Gbps forced mode for several SFP modules;
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "rapid-commit" is enabled;
    *) dhcpv6-client - ignore unknown IA;
    *) dhcpv6-client - require pool name to be unique;
    *) e-mail - auto complete file name on "file" parameter (introduced in v6.40);
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspot server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike1 - remove PH1 and PH2 when "mode-config" exchange fails;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in v6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - added "bridge" topic;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration) (CLI only);
    *) lte - added Passthrough support (CLI only);
    *) lte - added support for ZTE ME3630 E1C;
    *) lte - added Yota non-configurable modem support;
    *) lte - fixed mode initialization after reboot;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in v6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - fixed missing PPP client interface after reboot (introduced in v6.41rc);
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb931-2nd - fixed startup problems (requires additional reboot after upgrade);
    *) routerboard - fixed "/system routerboard upgrade" for CRS212-8G-4S;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) tile - improved reliability on MPLS package processing;
    *) ups - fixed duplicate "failed" UPS logs;
    *) userman - fixed unresponsive RADIUS server (introduced in v6.40.3);
    *) webfig - improved reliability of login process;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated United Kingdom regulatory domain information;

  • Release 6.41rc28 2017-09-12

    What's new in 6.41rc28 (2017-Sep-11 12:37):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) crs317 - added L2MTU support;
    *) crs3xx - added port ingress and egress rate limiting;
    *) log - added "bridge" topic;
    *) lte - added Passthrough support (CLI only);

    Other changes since 6.40.3:

    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    *) address - show warning on IPv6 address when acquire from pool has failed;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) arp - properly update dynamic ARP entries after interface related changes;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter;
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) crs1xx/2xx - fixed 1 Gbps forced mode for several SFP modules;
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "rapid-commit" is enabled;
    *) dhcpv6-client - ignore unknown IA;
    *) dhcpv6-client - require pool name to be unique;
    *) e-mail - auto complete file name on "file" parameter (introduced in v6.40);
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspot server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike1 - remove PH1 and PH2 when "mode-config" exchange fails;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in v6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration) (CLI only);
    *) lte - added support for ZTE ME3630 E1C;
    *) lte - added Yota non-configurable modem support;
    *) lte - fixed mode initialization after reboot;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in v6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - fixed missing PPP client interface after reboot (introduced in v6.41rc);
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb931-2nd - fixed startup problems (requires additional reboot after upgrade);
    *) routerboard - fixed "/system routerboard upgrade" for CRS212-8G-4S;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) tile - improved reliability on MPLS package processing;
    *) ups - fixed duplicate "failed" UPS logs;
    *) userman - fixed unresponsive RADIUS server (introduced in v6.40.3);
    *) webfig - improved reliability of login process;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated United Kingdom regulatory domain information;

  • Release 6.41rc26 2017-09-08

    What's new in 6.41rc26 (2017-Sep-07 13:26):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) crs1xx/2xx - fixed 1 Gbps forced mode for several SFP modules;
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) e-mail - auto complete file name on "file" parameter (introduced in v6.40);
    *) eoip - made L2MTU parameter read-only;
    *) hotspot - fixed missing "/ip hotspot server profile" if invalid "dns-name" was specified;
    *) lte - added Passthrough support (CLI only);
    *) lte - added support for ZTE ME3630 E1C;
    *) lte - fixed mode initialization after reboot;
    *) ppp - fixed missing PPP client interface after reboot (introduced in v6.41rc);
    *) rb931-2nd - fixed startup problems (requires additional reboot after upgrade);
    *) userman - fixed unresponsive RADIUS server (introduced in v6.40.3);
    *) webfig - improved reliability of login process;

    Other changes since 6.40.3:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    *) address - show warning on IPv6 address when acquire from pool has failed;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) arp - properly update dynamic ARP entries after interface related changes;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter;
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "rapid-commit" is enabled;
    *) dhcpv6-client - ignore unknown IA;
    *) dhcpv6-client - require pool name to be unique;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed interface list export;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike1 - remove PH1 and PH2 when "mode-config" exchange fails;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in v6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration) (CLI only);
    *) lte - added Yota non-configurable modem support;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in v6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) routerboard - fixed "/system routerboard upgrade" for CRS212-8G-4S;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) tile - improved reliability on MPLS package processing;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated United Kingdom regulatory domain information;

  • Release 6.41rc23 2017-09-04

    What's new in 6.41rc23 (2017-Sep-04 09:07):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) address - show warning on IPv6 address when acquire from pool has failed;
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - show bridge interface local addresses in the host table;
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcpv4-client - allow to use DUID for client ID;
    *) dhcpv6-client - require pool name to be unique;
    *) routerboard - fixed "/system routerboard upgrade" for CRS212-8G-4S;

    Other changes since 6.40.3:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) arp - properly update dynamic ARP entries after interface related changes;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter;
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "raoud-commit" is enabled;
    *) dhcpv6-client - ignore unknown IA;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike1 - remove PH1 and PH2 when "mode-config" exchange fails;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration) (CLI only);
    *) lte - added Passthrough support (CLI only);
    *) lte - added Yota non-configurable modem support;
    *) lte - fixed mode initialization after reboot;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) tile - improved reliability on MPLS package processing;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated United Kingdom regulatory domain information;

  • Release 6.41rc21 2017-09-01

    What's new in 6.41rc21 (2017-Sep-01 08:56):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - properly update dynamic ARP entries after interface related changes;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "master-port" parameter;
    *) ike1 - remove PH1 and PH2 when "mode-config" exchange fails;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration) (CLI only);
    *) lte - added Yota non-configurable modem support;
    *) lte - fixed mode initialization after reboot;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) tile - improved reliability on MPLS package processing;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated United Kingdom regulatory domain information;

    Other changes since 6.40.3:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "raoud-commit" is enabled;
    *) dhcpv6-client - ignore unknown IA;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added Passthrough support (CLI only);
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;

  • Release 6.41rc20 2017-08-29

    What's new in 6.41rc20 (2017-Aug-29 06:41):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "master-port" parameter;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "raoud-commit" is enabled;
    *) dhcpv6-server - do not release address of static binding from pool after server removal;
    *) export - fixed export for PoE-OUT related settings;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) led - fixed RB711UA ether1 LED (introduced in v6.38rc16);
    *) lte - added Passthrough support (CLI only);
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) userman - fixed "limitation" and "profile-limitation" update;
    *) userman - fixed CoA packet processing after changes in "/tool user-manager router" configuration;

    Other changes since 6.40.2:

    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6-client - ignore unknown IA;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed "/system routerboard" export (introduced in 6.40.1);
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - fixed initiator ID comparison to NAT-OA;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) led - fixed "on" and "off" triggers when multiple LEDs are selected;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - do not show USB LTE modem under "/port" menu (introduced in 6.41rc);
    *) lte - improved reliability of USB LTE modems;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) poe-out - fixed router reboot after "poe-out-status" changes;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb1100ahx4 - fixed HW acceleration fragmented packet decryption when fragment is smaller than 64 bytes;
    *) rb750gr3 - show warning and do not allow to use "protected-bootloader" feature if "factory-firmware" older than 3.34.4 version;
    *) routerboard - added "mode-button" support for RB750Gr3 (CLI only);
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) ssh - do not execute command if it starts with "-" symbol;
    *) traffic-flow - fixed reboots when IPv6 address has been set as target address without active IPv6 package;
    *) ups - fixed duplicate "failed" UPS logs;
    *) webfig - allow to open table entry even if table is not sorted by # (introduced in v6.40);
    *) webfig - allow to unset "rate-limit" for DHCP leases;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - added possibility to define "comment" for "/routing bgp network" entries;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - do not show FAN related information under "/system health" menu for devices which does not have it;
    *) winbox - do not show LCD menu for devices which does not have it;
    *) winbox - fixed ARP table update after entry changes state to incomplete;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "russia3" country settings;
    *) wireless - added New Zealand regulatory domain information for P2P links;
    *) wireless - updated China and New Zealand regulatory domain information;
    *) www - fixed unresponsive Web services (introduced in v6.40);

  • Release 6.41rc18 2017-08-24

    What's new in 6.41rc18 (2017-Aug-24 07:52):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) bridge - changed "Host" and "MDB" table column order;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added Passthrough support (CLI only);
    *) poe-out - fixed router reboot after "poe-out-status" changes;
    *) userman - fixed "limitation" and "profile-limitation" update;
    *) webfig - allow to open table entry even if table is not sorted by # (introduced in v6.40);
    *) webfig - allow to unset "rate-limit" for DHCP leases;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show FAN related information under "/system health" menu for devices which does not have it;
    *) winbox - fixed ARP table update after entry changes state to incomplete;

    Other changes since 6.40.2:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx (CLI only);
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter (CLI only);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6-client - ignore unknown IA;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed "/system routerboard" export (introduced in 6.40.1);
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - fixed initiator ID comparison to NAT-OA;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) led - fixed "on" and "off" triggers when multiple LEDs are selected;
    *) lte - do not show USB LTE modem under "/port" menu (introduced in 6.41rc);
    *) lte - improved reliability of USB LTE modems;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb1100ahx4 - fixed HW acceleration fragmented packet decryption when fragment is smaller than 64 bytes;
    *) rb750gr3 - show warning and do not allow to use "protected-bootloader" feature if "factory-firmware" older than 3.34.4 version;
    *) routerboard - added "mode-button" support for RB750Gr3 (CLI only);
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) ssh - do not execute command if it starts with "-" symbol;
    *) traffic-flow - fixed reboots when IPv6 address has been set as target address without active IPv6 package;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added possibility to define "comment" for "/routing bgp network" entries;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - do not show LCD menu for devices which does not have it;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "russia3" country settings;
    *) wireless - added New Zealand regulatory domain information for P2P links;
    *) wireless - updated China and New Zealand regulatory domain information;
    *) www - fixed unresponsive Web services (introduced in v6.40);

  • Release 6.41rc17 2017-08-23

    What's new in 6.41rc17 (2017-Aug-22 11:58):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) capsman - added "vlan-mode=no-tag" option;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) lte - added Passthrough support (CLI only);
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) winbox - added possibility to define "comment" for "/routing bgp network" entries;
    *) winbox - do not show LCD menu for devices which does not have it;
    *) www - fixed unresponsive Web services (introduced in v6.40);

    Other changes since 6.40.1:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx (CLI only);
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter (CLI only);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6-client - fixed IA evaluation order;
    *) dhcpv6-client - ignore unknown IA;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed "/system routerboard" export (introduced in 6.40.1);
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - fixed initiator ID comparison to NAT-OA;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) led - fixed "modem-signal" LEDs (introduced in 6.40);
    *) led - fixed "on" and "off" triggers when multiple LEDs are selected;
    *) lte - do not show USB LTE modem under "/port" menu (introduced in 6.41rc);
    *) lte - improved reliability of USB LTE modems;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe-client - fixed wrong auto MRU detection over VLAN interfaces;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb1100ahx4 - fixed HW acceleration fragmented packet decryption when fragment is smaller than 64 bytes;
    *) rb2011 - fixed possible LCD blinking along with ethernet LED (introduced in 6.40);
    *) rb750gr3 - show warning and do not allow to use "protected-bootloader" feature if "factory-firmware" older than 3.34.4 version;
    *) routerboard - added "mode-button" support for RB750Gr3 (CLI only);
    *) sfp - fixed invalid temperature readings when ambient temperature is below 0C;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) ssh - do not execute command if it starts with "-" symbol;
    *) traffic-flow - fixed reboots when IPv6 address has been set as target address without active IPv6 package;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added certificate settings;
    *) winbox - added support fro certificate CRL list;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - hide "level" and "tunnel" parameters for IPSec policy templates;
    *) winbox - hide FAN speed if it is 0RPM;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "russia3" country settings;
    *) wireless - added New Zealand regulatory domain information for P2P links;
    *) wireless - updated China and New Zealand regulatory domain information;

  • Release 6.41rc16 2017-08-18

    What's new in 6.41rc16 (2017-Aug-18 13:44):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) lcd - fixed unresponsive LCD (introduced in 6.41rc15);
    *) lte - added passthrough support (CLI only);
    *) traffic-flow - fixed reboots when IPv6 address has been set as target address without active IPv6 package;

    Other changes since 6.40.1:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx (CLI only);
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter (CLI only);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option (CLI only);
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6-client - fixed IA evaluation order;
    *) dhcpv6-client - ignore unknown IA;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed "/system routerboard" export (introduced in 6.40.1);
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - fixed initiator ID comparison to NAT-OA;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - allow to specify remote peer address as DNS name (CLI only);
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) led - fixed "modem-signal" LEDs (introduced in 6.40);
    *) led - fixed "on" and "off" triggers when multiple LEDs are selected;
    *) lte - do not show USB LTE modem under "/port" menu (introduced in 6.41rc);
    *) lte - improved reliability of USB LTE modems;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe-client - fixed wrong auto MRU detection over VLAN interfaces;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb1100ahx4 - fixed HW acceleration fragmented packet decryption when fragment is smaller than 64 bytes;
    *) rb2011 - fixed possible LCD blinking along with ethernet LED (introduced in 6.40);
    *) rb750gr3 - show warning and do not allow to use "protected-bootloader" feature if "factory-firmware" older than 3.34.4 version;
    *) routerboard - added "mode-button" support for RB750Gr3 (CLI only);
    *) sfp - fixed invalid temperature readings when ambient temperature is below 0C;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) ssh - do not execute command if it starts with "-" symbol;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added certificate settings;
    *) winbox - added support fro certificate CRL list;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - hide "level" and "tunnel" parameters for IPSec policy templates;
    *) winbox - hide FAN speed if it is 0RPM;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "russia3" country settings;
    *) wireless - added New Zealand regulatory domain information for P2P links;
    *) wireless - updated China and New Zealand regulatory domain information;

  • Release 6.41rc15 2017-08-18

    What's new in 6.41rc15 (2017-Aug-18 07:33):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) capsman - added "vlan-mode=no-tag" option (CLI only);
    *) capsman - return complete CA chain when issuing new certificate;
    *) export - fixed "/system routerboard" export (introduced in 6.40.1);
    *) ike1 - fixed initiator ID comparison to NAT-OA;
    *) led - fixed "on" and "off" triggers when multiple LEDs are selected;
    *) lte - added passthrough support (CLI only);
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) rb1100ahx4 - fixed HW acceleration fragmented packet decryption when fragment is smaller than 64 bytes;
    *) routerboard - added "mode-button" support for RB750Gr3 (CLI only);
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) ssh - do not execute command if it starts with "-" symbol;
    *) wireless - added New Zealand regulatory domain information for P2P links;
    *) wireless - updated China and New Zealand regulatory domain information;

    Other changes since 6.40.1:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx (CLI only);
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter (CLI only);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6-client - fixed IA evaluation order;
    *) dhcpv6-client - ignore unknown IA;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - allow to specify remote peer address as DNS name (CLI only);
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) led - fixed "modem-signal" LEDs (introduced in 6.40);
    *) lte - do not show USB LTE modem under "/port" menu (introduced in 6.41rc);
    *) lte - improved reliability of USB LTE modems;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe-client - fixed wrong auto MRU detection over VLAN interfaces;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb2011 - fixed possible LCD blinking along with ethernet LED (introduced in 6.40);
    *) rb750gr3 - show warning and do not allow to use "protected-bootloader" feature if "factory-firmware" older than 3.34.4 version;
    *) sfp - fixed invalid temperature readings when ambient temperature is below 0C;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added certificate settings;
    *) winbox - added support fro certificate CRL list;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - hide "level" and "tunnel" parameters for IPSec policy templates;
    *) winbox - hide FAN speed if it is 0RPM;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "russia3" country settings;

  • Release 6.41rc13 2017-08-16

    What's new in 6.41rc13 (2017-Aug-15 13:09):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx (CLI only);
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - removed "master-port" parameter (CLI only);
    *) certificate - fixed import of certificates with empty SKID;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6-client - ignore unknown IA;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) lte - improved FastPath support for SXT LTE;
    *) lte - added multi APN passthrough support for wAP LTE;
    *) lte - do not show USB LTE modem under "/port" menu (introduced in 6.41rc);
    *) lte - improved reliability of USB LTE modems;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) rb750gr3 - show warning and do not allow to use "protected-bootloader" feature if "factory-firmware" older than 3.34.4 version;

    Other changes since 6.40.1:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcpv6-client - fixed IA evaluation order;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed interface list export;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - allow to specify remote peer address as DNS name (CLI only);
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) led - fixed "modem-signal" LEDs (introduced in 6.40);
    *) lte - allow to specify the MAC address for passthrough mode;
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe-client - fixed wrong auto MRU detection over VLAN interfaces;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb2011 - fixed possible LCD blinking along with ethernet LED (introduced in 6.40);
    *) sfp - fixed invalid temperature readings when ambient temperature is below 0C;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added certificate settings;
    *) winbox - added support fro certificate CRL list;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - hide "level" and "tunnel" parameters for IPSec policy templates;
    *) winbox - hide FAN speed if it is 0RPM;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "russia3" country settings;

  • Release 6.41rc11 2017-08-09

    What's new in 6.41rc11 (2017-Aug-08 09:32):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx (CLI only);
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) export - fixed interface list export;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ipsec - allow to specify remote peer address as DNS name (CLI only);
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) led - fixed "modem-signal" LEDs (introduced in 6.40);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) rb2011 - fixed possible LCD blinking along with ethernet LED (introduced in 6.40);
    *) rb750gr3 - show warning and do not allow to use "protected-bootloader" feature if "factory-firmware" older than 3.34.4 version;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added certificate settings;
    *) winbox - added support fro certificate CRL list;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - hide "level" and "tunnel" parameters for IPSec policy templates;
    *) winbox - hide FAN speed if it is 0RPM;
    *) wireless - added "russia3" country settings;

    Other changes since 6.40.1:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcpv6-client - fixed IA evaluation order;
    *) e-mail - do not show errors when sending e-mail from script;
    *) hotspot - improved user statistics collection process;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lte - added initial passthrough support for wAP LTE;
    *) lte - added support for Novatel (Verizon) USB730L;
    *) lte - allow to specify the MAC address for passthrough mode;
    *) ppp - added support for Sierra MC7750;
    *) pppoe-client - fixed wrong auto MRU detection over VLAN interfaces;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) sfp - fixed invalid temperature readings when ambient temperature is below 0C;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - show warnings under "/system routerboard settings" menu;

  • Release 6.41rc9 2017-08-03

    What's new in 6.41rc9 (2017-Aug-03 12:02):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) certificate - fixed SCEP "get" request URL encoding;
    *) dhcpv6-client - fixed IA evaluation order;
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed LCD blinking on RB2011 (introduced in 6.40);
    *) lte - added initial passthrough support for wAP LTE;
    *) pppoe-client - fixed wrong auto MRU detection over VLAN interfaces;
    *) pppoe-server - fixed situation when PPPoE servers become invalid after reboot;
    *) sfp - fixed invalid temperature readings when ambient temperature is below 0C;

    Other changes since 6.40:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bonding - improved relialibility on bonding interface removal;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcpv6-client - do not run DHCPv6 client when IPv6 package is disabled;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed export for different parameters where numerical range or constant string is expected;
    *) firewall - properly remove "address-list" entry after timeout ends;
    *) hotspot - improved user statistics collection process;
    *) interface - improved interface state change handling when multiple interfaces are affected at the same time;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) lte - allow to specify the MAC address for passthrough mode;
    *) lte - added support for Novatel (Verizon) USB730L;
    *) lte - fixed LTE not passing any traffic while in running state;
    *) ovpn-client - fixed incorrect netmask usage for pushed routes;
    *) ppp - added support for Sierra MC7750;
    *) pppoe-client - fixed incorrectly formed PADT packet;
    *) rb2011 - fixed possible LCD blinking along with Ethernet LED;
    *) rb922 - restored missing wireless interface on some boards;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) torch - fixed Torch on PPP tunnels (introduced in 6.40);
    *) trafficgen - fixed "lost-ratio" showing incorrect statistics after multiple sequences;
    *) winbox - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter under NAT, Mangle and RAW rules;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - show warnings under "/system routerboard settings" menu;

  • Release 6.41rc6 2017-08-01

    What's new in 6.41rc6 (2017-Aug-01 11:30):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) dhcpv6-client - do not run DHCPv6 client when IPv6 package is disabled;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) lte - added support for Novatel (Verizon) USB730L;
    *) lte - fixed LTE not passing any traffic while in running state;
    *) ppp - added support for Sierra MC7750;
    *) torch - fixed Torch on PPP tunnels (introduced in 6.40);

    Other changes since 6.40:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bonding - improved relialibility on bonding interface removal;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) e-mail - do not show errors when sending e-mail from script;
    *) firewall - properly remove "address-list" entry after timeout ends;
    *) hotspot - improved user statistics collection process;
    *) interface - improved interface state change handling when multiple interfaces are affected at the same time;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) lte - allow to specify the MAC address for passthrough mode;
    *) rb2011 - fixed possible LCD blinking along with Ethernet LED;
    *) rb922 - restored missing wireless interface on some boards;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) trafficgen - fixed "lost-ratio" showing incorrect statistics after multiple sequences;

  • Release 6.41rc4 2017-07-31

    What's new in 6.41rc4 (2017-Jul-28 06:48):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) rb922 - restored missing wireless interface on some boards;

    Other changes since 6.40:

    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bonding - improved relialibility on bonding interface removal;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) e-mail - do not show errors when sending e-mail from script;
    *) firewall - properly remove "address-list" entry after timeout ends;
    *) hotspot - improved user statistics collection process;
    *) interface - improved interface state change handling when multiple interfaces are affected at the same time;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) lte - allow to specify the MAC address for passthrough mode;
    *) ppp - added client support for Sierra MC7750;
    *) rb2011 - fixed possible LCD blinking along with Ethernet LED;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) trafficgen - fixed "lost-ratio" showing incorrect statistics after multiple sequences;

  • Release 6.41rc3 2017-07-26

    What's new in 6.41rc3 (2017-Jul-26 09:32):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bonding - improved relialibility on bonding interface removal;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) e-mail - do not show errors when sending e-mail from script;
    *) firewall - properly remove "address-list" entry after timeout ends;
    *) hotspot - improved user statistics collection process;
    *) interface - improved interface state change handling when multiple interfaces are affected at the same time;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) lte - allow to specify the MAC address for passthrough mode;
    *) ppp - added client support for Sierra MC7750;
    *) rb2011 - fixed possible LCD blinking along with Ethernet LED;
    *) rb922 - restored missing wireless interface on some boards;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) trafficgen - fixed "lost-ratio" showing incorrect statistics after multiple sequences;

  • Release 6.40rc41 2018-02-26

    What's new in 6.40rc41 (2017-Jul-17 09:03):

    !) bridge hw-offload implementation reverted back to pre-6.40rc36 state (testing will continue in v6.41rc);
    !) wireless - added Nv2 AP synchronization feature "nv2-modes" and "nv2-sync-secret" option;
    *) bonding - fixed 802.3ad mode on RB1100AHx4;
    *) export - fixed export to a file (introduced in v6.40rc39);
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - fixed firewall accept rules created by "/ip hotspot walled garden ip" (introduced in v6.40rc18);
    *) ike1 - create tunnel policy when no split net provided;
    *) ike1 - wait for cfg set reply before ph2 creation with xAuth;
    *) ipsec - allow to specify chain in "firewall" peer option;
    *) ppp - fixed non-standard PAP or CHAP packet handling;
    *) pppoe-server - fixed situation when some of 100+ pppoe-servers can become invalid on reboot;
    *) routerboard - added "caps-mode" option for "reset-configuration";
    *) sfp - fixed invalid temperature reporting when ambient temperature is less than 0;
    *) winbox - make IPSec policies table an order list;
    *) winbox - show "/interface wireless cap print" warnings;

    Other changes since 6.39.2:

    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) certificate - update and reload old certificate with new one if SKID matches;
    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) console - fixed different command auto complete on ;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-client - added "gateway-address" script parameter;
    *) dhcpv4-server - fixed lease renew for DHCP clients that sends renewal with "ciaddr = 0.0.0.0";
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) email - added support for multiple attachments;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed occasional broken interface order after reset/first boot;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) export - added router model and serial number to configuration export;
    *) export - fixed "/interface list" verbose export;
    *) export - fixed "/ipv6 route" compact export;
    *) export - fixed MPLS "dynamic-label-range" export;
    *) export - fixed SNMP "src-address" for compact export;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fastpath - improved removing process of dynamic interface;
    *) fasttrack - fixed fasttrack over interfaces with dynamic MAC address;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) filesystem - improved error correcting process on tilera and RB1100Dx4 storage;
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter;
    *) firewall - fixed bridge "action=log" rules;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - fixed crash on fasttrack dummy rule manual change attempt;
    *) firewall - removed unique address list name limit;
    *) hAP ac lite - removed nonexistent "wlan-led";
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added log error message if netmask was not provided by "mode-config" server;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - fixed duplicate policy checking with "0.0.0.0/0" policies;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - added support for "key-id" peer identification type;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added info command support for the Jaton LTE modem;
    *) lte - added initial fastpath support (except SXT LTE and Sierra modems);
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - added support for Huawei E3531-6;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) mmips - added support for NVME disks;
    *) modem - added support for ZTE TE W120;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - added initial support for ZTE K4203-Z;
    *) ppp - added initial support for ZTE ME3630-E;
    *) ppp - added output values for "info" command for finding the GSM base station's location ("LAC" and "IMSI");
    *) ppp - fixed "user-command" output;
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - simplified LTE status monitoring;
    *) quickset - use active user name and permissions when applying changes;
    *) rb1100ahx4 - fixed startup problems (requires additional reboot after upgrade);
    *) rb3011 - fixed packet passthrough on switch2 while booting;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
    *) sms - decode reports in readable format;
    *) sniffer - do not skip L2 packets when "all" interface mode was used;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed "/system resource cpu print oid" menu;
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) ssl - added Wildcard support for "left-most" DNS label (will allow to use signed Wildcard certificate on VPN servers);
    *) supout - fixed IPv6 firewall section;
    *) switch - fixed "loop-protect" on CRS SFP/SFP+ ports;
    *) tile - fixed copying large amount of text over serial console;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) trafficgen - added "lost-ratio" to statistics;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - added "/tool user-manager user clear-profiles" command;
    *) userman - do not send disconnect request for user when "simultaneous session limit reached";
    *) userman - lookup language files also in "/flash" directory;
    *) vlan - do not delete existing VLAN interface on "failure: already have such vlan";
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - do not autoscale graphs outside known maximums;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - hide LCD menu on CRS112-8G-4S;
    *) winbox - moved LTE info fields to status tab;
    *) winbox - show "/system health" only on boards that have health monitoring;
    *) winbox - show "D" flag under "/interface mesh port" menu;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc38 2017-07-12

    What's new in 6.40rc38 (2017-Jul-11 12:28):

    Important note!!! Backup before upgrade!
    RouterOS v6.40rc36 contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) certificate - update and reload old certificate with new one if SKID matches;
    *) email - added support for multiple attachments;
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter;
    *) firewall - fixed crash on fasttrack dummy rule manual change attempt;
    *) ikev2 - fixed duplicate policy checking with "0.0.0.0/0" policies;
    *) lte - added initial fastpath support (except SXT LTE and Sierra modems);
    *) mmips - added support for NVME disks;
    *) ppp - added output values for "info" command for finding the GSM base station's location ("LAC" and "IMSI");
    *) ppp - fixed "user-command" output;
    *) quickset - simplified LTE status monitoring;
    *) rb1100ahx4 - fixed startup problems (requires additional reboot after upgrade);
    *) ssl - added Wildcard support for "left-most" DNS label (will allow to use signed Wildcard certificate on VPN servers);
    *) userman - do not send disconnect request for user when "simultaneous session limit reached";
    *) userman - added "/tool user-manager user clear-profiles" command;

    Other changes since 6.39.2:

    !) bridge - implemented software based "igmp-snooping" (untested, undocumented, CLI only);
    !) bridge - implemented software based MSTP (untested, undocumented, CLI only);
    !) bridge - implemented software based vlan-aware bridges;
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (undocumented, CLI only);
    !) switch - CRS3xx switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) console - fixed different command auto complete on ;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-client - added "gateway-address" script parameter;
    *) dhcpv4-server - fixed lease renew for DHCP clients that sends renewal with "ciaddr = 0.0.0.0";
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed occasional broken interface order after reset/first boot;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) export - added router model and serial number to configuration export;
    *) export - fixed "/interface list" verbose export;
    *) export - fixed "/ipv6 route" compact export;
    *) export - fixed MPLS "dynamic-label-range" export;
    *) export - fixed SNMP "src-address" for compact export;
    *) fastpath - fixed router rebooting itself (introduced in 6.40rc24);
    *) fastpath - improved performance when packets for slowpath are received;
    *) fastpath - improved removing process of dynamic interface;
    *) fasttrack - fixed fasttrack over interfaces with dynamic MAC address;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) filesystem - improved error correcting process on tilera and RB1100Dx4 storage;
    *) firewall - fixed bridge "action=log" rules;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - removed unique address list name limit;
    *) hAP ac lite - removed nonexistent "wlan-led";
    *) health - fixed memory leak on devices that have "/system health" menu (introduced in 6.40rc30);
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ikev1 - added log error message if netmask was not provided by "mode-config" server;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - added support for "key-id" peer identification type;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added info command support for the Jaton LTE modem;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - added support for Huawei E3531-6;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - added initial support for ZTE K4203-Z;
    *) ppp - added initial support for ZTE ME3630-E;
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - use active user name and permissions when applying changes;
    *) rb3011 - fixed packet passthrough on switch2 while booting;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
    *) sms - decode reports in readable format;
    *) sniffer - do not skip L2 packets when "all" interface mode was used;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed "/system resource cpu print oid" menu;
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) supout - fixed IPv6 firewall section;
    *) switch - fixed "loop-protect" on CRS SFP/SFP+ ports;
    *) tile - fixed copying large amount of text over serial console;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) trafficgen - added "lost-ratio" to statistics;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) vlan - do not delete existing VLAN interface on "failure: already have such vlan";
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - do not autoscale graphs outside known maximums;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - hide LCD menu on CRS112-8G-4S;
    *) winbox - moved LTE info fields to status tab;
    *) winbox - show "/system health" only on boards that have health monitoring;
    *) winbox - show "D" flag under "/interface mesh port" menu;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc36 2017-07-07

    What's new in 6.40rc36 (2017-Jul-07 10:44):

    Important note!!! Backup before upgrade!
    RouterOS v6.40rc36 contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - implemented software based "igmp-snooping" (untested, undocumented, CLI only);
    !) bridge - implemented software based MSTP (untested, undocumented, CLI only);
    !) bridge - implemented software based vlan-aware bridges;
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (undocumented, CLI only);
    !) switch - CRS3xx switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) filesystem - improved error correcting process on tilera and RB1100Dx4 storage;
    *) firewall - fixed bridge "action=log" rules;
    *) health - fixed memory leak on devices that have "/system health" menu (introduced in 6.40rc30);
    *) ikev1 - added log error message if netmask was not provided by "mode-config" server;
    *) ipsec - added support for "key-id" peer identification type;
    *) rb3011 - fixed packet passthrough on switch2 while booting;
    *) sniffer - do not skip L2 packets when "all" interface mode was used;
    *) snmp - fixed "/system resource cpu print oid" menu;
    *) switch - fixed "loop-protect" on CRS SFP/SFP+ ports;
    *) trafficgen - added "lost-ratio" to statistics;
    *) vlan - do not delete existing VLAN interface on "failure: already have such vlan";
    *) winbox - do not autoscale graphs outside known maximums;
    *) winbox - hide LCD menu on CRS112-8G-4S;
    *) winbox - show "/system health" only on boards that have health monitoring;
    *) winbox - show "D" flag under "/interface mesh port" menu;

    Other changes since 6.39.2:

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) console - fixed different command auto complete on ;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-client - added "gateway-address" script parameter;
    *) dhcpv4-server - fixed lease renew for DHCP clients that sends renewal with "ciaddr = 0.0.0.0";
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed occasional broken interface order after reset/first boot;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) export - added router model and serial number to configuration export;
    *) export - fixed "/interface list" verbose export;
    *) export - fixed "/ipv6 route" compact export;
    *) export - fixed MPLS "dynamic-label-range" export;
    *) export - fixed SNMP "src-address" for compact export;
    *) fastpath - fixed router rebooting itself (introduced in 6.40rc24);
    *) fastpath - improved performance when packets for slowpath are received;
    *) fastpath - improved removing process of dynamic interface;
    *) fasttrack - fixed fasttrack over interfaces with dynamic MAC address;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter (CLI only);
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - removed unique address list name limit;
    *) hAP ac lite - removed nonexistent "wlan-led";
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added info command support for the Jaton LTE modem;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - added support for Huawei E3531-6;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - added initial support for ZTE K4203-Z;
    *) ppp - added initial support for ZTE ME3630-E;
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - use active user name and permissions when applying changes;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
    *) sms - decode reports in readable format;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) supout - fixed IPv6 firewall section;
    *) tile - fixed copying large amount of text over serial console;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - moved LTE info fields to status tab;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc32 2017-07-04

    What's new in 6.40rc32 (2017-Jul-04 07:38):

    *) dhcpv4-client - added "gateway-address" script parameter;
    *) dhcpv4-server - fixed lease renew for DHCP clients that sends renewal with "ciaddr = 0.0.0.0";
    *) fasttrack - fixed fasttrack over interfaces with dynamic MAC address;

    Other changes since 6.39.2:

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) console - fixed different command auto complete on ;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed occasional broken interface order after reset/first boot;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) export - added router model and serial number to configuration export;
    *) export - fixed "/interface list" verbose export;
    *) export - fixed "/ipv6 route" compact export;
    *) export - fixed MPLS "dynamic-label-range" export;
    *) export - fixed SNMP "src-address" for compact export;
    *) fastpath - fixed router rebooting itself (introduced in 6.40rc24);
    *) fastpath - improved performance when packets for slowpath are received;
    *) fastpath - improved removing process of dynamic interface;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter (CLI only);
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - removed unique address list name limit;
    *) hAP ac lite - removed nonexistent "wlan-led";
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added info command support for the Jaton LTE modem;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - added support for Huawei E3531-6;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - added initial support for ZTE K4203-Z;
    *) ppp - added initial support for ZTE ME3630-E;
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - use active user name and permissions when applying changes;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
    *) sms - decode reports in readable format;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) supout - fixed IPv6 firewall section;
    *) tile - fixed copying large amount of text over serial console;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) trafficgen - added "lost-ratio" to statistics;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - moved LTE info fields to status tab;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc28 2017-06-30

    What's new in 6.40rc28 (2017-Jun-30 12:08:26):

    *) console - fixed different command auto complete on ;
    *) ethernet - fixed occasional broken interface order after reset/first boot;
    *) export - added router model and serial number to configuration export;
    *) export - fixed "/interface list" verbose export;
    *) export - fixed "/ipv6 route" compact export;
    *) export - fixed MPLS "dynamic-label-range" export;
    *) export - fixed SNMP "src-address" for compact export;
    *) fastpath - improved removing process of dynamic interface;
    *) hAP ac lite - removed nonexistent "wlan-led";
    *) lte - added info command support for the Jaton LTE modem;
    *) ppp - added initial support for ZTE K4203-Z;
    *) ppp - added initial support for ZTE ME3630-E;
    *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
    *) supout - fixed IPv6 firewall section;

    Other changes since 6.39.2:

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces (CLI only);
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) fastpath - fixed router rebooting itself (introduced in 6.40rc24);
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter (CLI only);
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - removed unique address list name limit;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - added support for Huawei E3531-6;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - use active user name and permissions when applying changes;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sms - decode reports in readable format;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tile - fixed copying large amount of text over serial console;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) trafficgen - added "lost-ratio" to statistics;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - moved LTE info fields to status tab;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc25 2017-06-27

    What's new in 6.40rc25 (2017-Jun-27 06:26):

    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) fastpath - fixed router rebooting itself (introduced in 6.40rc24);
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter (CLI only);
    *) firewall - removed unique address list name limit;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) lte - added support for Huawei E3531-6;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) tile - fixed copying large amount of text over serial console;
    *) trafficgen - added "lost-ratio" to statistics;
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;

    Other changes since 6.39.2:

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces (CLI only);
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - use active user name and permissions when applying changes;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sms - decode reports in readable format;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - moved LTE info fields to status tab;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc24 2017-06-20

    What's new in 6.40rc24 (2017-Jun-20 09:38):

    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - added support for "push-continuation";
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) sms - decode reports in readable format;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - fixed wireless interface walk table id ordering;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - moved LTE info fields to status tab;

    Other changes since 6.39.2:

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces (CLI only);
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) ovpn - improved performance when receiving too many options;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - improved MLPPP packet forwarding performance;
    *) proxy - fixed potential crash;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - use active user name and permissions when applying changes;
    *) rb750gr3 - fixed USB power;
    *) routing - allow to disable "all" interface entry in BFD;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed crash on interface table get;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added TR069 support;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc21 2017-06-14

    What's new in 6.40rc21 (2017-Jun-14 09:05):

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces (CLI only);
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) dude - fixed server crash;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) rb750gr3 - fixed USB power;
    *) userman - lookup language files also in "/flash" directory;

    Other changes since 6.39.2:

    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) ovpn - improved performance when receiving too many options;
    *) ppp - improved MLPPP packet forwarding performance;
    *) proxy - fixed potential crash;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - use active user name and permissions when applying changes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) snmp - fixed crash on interface table get;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added TR069 support;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc20 2017-06-13

    What's new in 6.40rc20 (2017-Jun-12 12:08):

    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - improved reliability on SXT LTE;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

    Other changes since 6.39.2:

    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved SMS delivery report;
    *) ovpn - improved performance when receiving too many options;
    *) ppp - improved MLPPP packet forwarding performance;
    *) proxy - fixed potential crash;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - use active user name and permissions when applying changes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) snmp - fixed crash on interface table get;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added TR069 support;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;

  • Release 6.40rc19 2017-06-08

    What's new in 6.40rc19 (2017-Jun-07 13:30):

    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) l2tp-server - added "one-session-per-host" option;
    *) ovpn - improved performance when receiving too many options;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

    Other changes since 6.39.2:

    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved SMS delivery report;
    *) ppp - improved MLPPP packet forwarding performance;
    *) proxy - fixed potential crash;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - use active user name and permissions when applying changes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) snmp - fixed crash on interface table get;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added TR069 support;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;

  • Release 6.40rc18 2017-06-06

    What's new in 6.40rc18 (2017-Jun-06 10:04):

    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) fastpath - improved performance when packets for slowpath are received;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) lte - improved SMS delivery report;
    *) ppp - improved MLPPP packet forwarding performance;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;

  • Release 6.40rc15 2018-02-21

    What's new in 6.40rc15 (2017-May-30 08:52):

    !) ipsec - added support for dynamic "action=notrack" RAW rules for policies;
    *) defconf - added accept ICMPv6 in forward and DHCP discover in RAW prerouting;
    *) ike2 - added pfkey kernel return checks;
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - removed policy priority;
    *) ppp - fixed MLPPP over multiple channels/interfaces (introduced in v6.39);

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) bonding - do not add bonding interface if "could not set MTU" error is received;
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) defconf - added IPv6 firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) defconf - replaced IPv4 firewall configuration with improved one;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) export - removed spare "caller-id-type" value from compact export;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) firewall - do not allow to set "rate" value to 0 for "limit" parameter;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) gps - removed duplicate logs;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - removed xauth login length limitation;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - fixed rare kernel failure on address acquire;
    *) ike2 - fixed situation when traffic selector prefix was parsed incorrectly;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed generated policy priority;
    *) ipsec - fixed peer "my-id" address reset;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - renamed "remote-dynamic-address" to "dynamic-address";
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) led - fixed ethernet LEDs on CCR1009 and RB1100AHx2 (introduced in v6.40rc1);
    *) led - fixed turning off LED when interface is lost;
    *) log - added "poe-out" topic;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - fixed configless modem running state (introduced in 6.40rc);
    *) lte - improved info channel background polling;
    *) lte - replaced "user-command" with "at-chat" command;
    *) ppp - fixed "change-mss" functionality (introduced in 6.39);
    *) ppp - send correct IP address in RADIUS "accounting-stop" messages (introduced in 6.39);
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) pppoe-client - removed false warning from client interface if it starts running on non-slave interface;
    *) pppoe-server - fixed "one-session-per-host" issue where 2 simultaneous sessions were possible from the same host;
    *) proxy - fixed potential crash;
    *) queue - fixed queuing when at least one child queue has "default-small" and other/s is/are different (introduced in 6.35);
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - fixed LTE "signal-strength" graphs;
    *) quickset - use active user name and permissions when applying changes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - fixed crash on interface table get;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) tile - fixed rare encryption kernel failure when small packets are processed;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) winbox - fixed LTE info button;
    *) winbox - fixed firewall port selection with Winbox v2;
    *) winbox - removed spare values from "loop-protect" setting for EoIPv6 tunnels;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - reduced load on CPU for high speed wireless links;

  • Release 6.40rc14 2017-05-30

    What's new in 6.40rc14 (2017-May-29 11:16):

    *) chr - maximal system disk size now limited to 16GB;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) pppoe-server - fixed "one-session-per-host" issue where 2 simultaneous sessions were possible from the same host;
    *) snmp - fixed crash on interface table get;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - fixed firewall port selection with Winbox v2;

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) bonding - do not add bonding interface if "could not set MTU" error is received;
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) defconf - added IPv6 firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) defconf - replaced IPv4 firewall configuration with improved one;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) export - removed spare "caller-id-type" value from compact export;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) firewall - do not allow to set "rate" value to 0 for "limit" parameter;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) gps - removed duplicate logs;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - removed xauth login length limitation;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - fixed rare kernel failure on address acquire;
    *) ike2 - fixed situation when traffic selector prefix was parsed incorrectly;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed generated policy priority;
    *) ipsec - fixed peer "my-id" address reset;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - renamed "remote-dynamic-address" to "dynamic-address";
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) led - fixed ethernet LEDs on CCR1009 and RB1100AHx2 (introduced in v6.40rc1);
    *) led - fixed turning off LED when interface is lost;
    *) log - added "poe-out" topic;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - fixed configless modem running state (introduced in 6.40rc);
    *) lte - improved info channel background polling;
    *) lte - replaced "user-command" with "at-chat" command;
    *) ppp - fixed "change-mss" functionality (introduced in 6.39);
    *) ppp - send correct IP address in RADIUS "accounting-stop" messages (introduced in 6.39);
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) pppoe-client - removed false warning from client interface if it starts running on non-slave interface;
    *) proxy - fixed potential crash;
    *) queue - fixed queuing when at least one child queue has "default-small" and other/s is/are different (introduced in 6.35);
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - fixed LTE "signal-strength" graphs;
    *) quickset - use active user name and permissions when applying changes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) tile - fixed rare encryption kernel failure when small packets are processed;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) winbox - fixed LTE info button;
    *) winbox - removed spare values from "loop-protect" setting for EoIPv6 tunnels;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - reduced load on CPU for high speed wireless links;

  • Release 6.40rc13 2017-05-26

    What's new in 6.40rc13 (2017-May-25 12:53):

    *) bonding - do not add bonding interface if "could not set MTU" error is received;
    *) defconf - added IPv6 firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) export - removed spare "caller-id-type" value from compact export;
    *) firewall - do not allow to set "rate" value to 0 for "limit" parameter;
    *) gps - removed duplicate logs;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - removed xauth login length limitation;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - fixed situation when traffic selector prefix was parsed incorrectly;
    *) ipsec - fixed generated policy priority;
    *) ipsec - fixed peer "my-id" address reset;
    *) ipsec - renamed "remote-dynamic-address" to "dynamic-address";
    *) lte - fixed configless modem running state (introduced in 6.40rc);
    *) ppp - fixed "change-mss" functionality (introduced in 6.39);
    *) ppp - send correct IP address in RADIUS "accounting-stop" messages (introduced in 6.39);
    *) pppoe-client - removed false warning from client interface if it starts running on non-slave interface;
    *) proxy - fixed potential crash;
    *) queue - fixed queuing when at least one child queue has "default-small" and other/s is/are different (introduced in 6.35);
    *) quickset - fixed LTE "signal-strength" graphs;
    *) quickset - use active user name and permissions when applying changes;
    *) snmp - added ability to set "src-address";
    *) tile - fixed rare encryption kernel failure when small packets are processed;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - fixed LTE info button;
    *) winbox - removed spare values from "loop-protect" setting for EoIPv6 tunnels;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - reduced load on CPU for high speed wireless links;

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) defconf - replaced IPv4 firewall configuration with improved one;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike2 - fixed rare kernel failure on address acquire;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) led - fixed ethernet LEDs on CCR1009 and RB1100AHx2 (introduced in v6.40rc1);
    *) led - fixed turning off LED when interface is lost;
    *) log - added "poe-out" topic;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved info channel background polling;
    *) lte - replaced "user-command" with "at-chat" command;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;

  • Release 6.40rc8 2017-05-19

    What's new in 6.40rc8 (2017-May-19 07:00):

    *) btest - fixed crash when packet size has been changed during test;
    *) defconf - added IPv6 firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - replaced IPv4 firewall configuration with improved one;
    *) export - added "terse" option;
    *) firewall - do not allow to set "rate" value to 0 for "limit" parameter (CLI only);
    *) wireless - do not skip >2462 channels if interface is WDS slave;

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike2 - fixed rare kernel failure on address acquire;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) led - fixed ethernet LEDs on CCR1009 and RB1100AHx2 (introduced in v6.40rc1);
    *) led - fixed turning off LED when interface is lost;
    *) log - added "poe-out" topic;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved info channel background polling;
    *) lte - replaced "user-command" with "at-chat" command;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol (CLI only);
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol (CLI only);
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;

  • Release 6.40rc6 2017-05-16

    What's new in 6.40rc6 (2017-May-11 12:53):

    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) led - fixed ethernet LEDs on CCR1009 and RB1100AHx2 (introduced in v6.40rc1);
    *) led - fixed turning off LED when interface is lost;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - improved info channel background polling;
    *) lte - replaced "user-command" with "at-chat" command;
    *) snmp - added "ifindex" on interface traps;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol (CLI only);
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol (CLI only);

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike2 - fixed rare kernel failure on address acquire;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) log - added "poe-out" topic;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;

  • Release 6.40rc5 2017-05-09

    What's new in 6.40rc5 (2017-May-08 09:20):

    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) ike2 - fixed rare kernel failure on address acquire;
    *) log - added "poe-out" topic;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;

  • Release 6.40rc4 2018-02-21

    What's new in 6.40rc4 (2017-May-03 05:15):

    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) defconf - discard default configuration startup query with RouterOS upgrade;
    *) defconf - discard default configuration startup query with configuration change from Webfig;
    *) dns - made loading thousands of static entries faster;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) smb - fixed external drive folder sharing when "/flash" folder existed;
    *) smb - fixed invalid default share after reboot when "/flash" folder existed;
    *) upnp - fixed firewall nat rule update when external IP address changes;

    Other changes since 6.39:

    *) 6to4 - fixed wrong IPv6 “link-local” address generation;
    *) arp - fixed “make-static”;
    *) capsman - fixed EAP identity reporting in “registration-table”;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) firewall - fixed “address-list” entry changing from IP to DNS and vice versa;
    *) firewall - “address-list” entry “creation-time” adjusted to timezone;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;

  • Release 6.40rc2 2018-02-21

    What's new in 6.40rc2 (2017-Apr-28 05:24):

    *) 6to4 - fixed wrong IPv6 “link-local” address generation;
    *) arp - fixed “make-static”;
    *) capsman - fixed EAP identity reporting in “registration-table”;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) firewall - fixed “address-list” entry changing from IP to DNS and vice versa;
    *) firewall - “address-list” entry “creation-time” adjusted to timezone;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) log - work on false CPU/RAM overclocked alarms;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;

  • Release 6.38rc46 2016-12-09

    What's new in 6.38rc46 (2016-Dec-07 06:53):

    *) dhcp-server - fixed when wizard was unable to create pool >dhcp_pool99;
    *) ipsec - allow empty policy SA dst-address in tunnel mode;
    *) ipsec - always listen to port TCP/4500 (fixes some IKEv2 setups without NAT-T);
    *) ipsec - various additional work on IKEv1/IKEv2 support;
    *) vrrp - do not show unrelated log warning messages about version mismatch;
    *) webfig - added extra protection against XSS exploits;
    *) webfig - show properly interface last-link-up/down times;

    Other changes since 6.37.3:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes";
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder;
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods;
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package) (cli only);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed pkcs12 export crash;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dns - added "max-concurrent-queries" and "max-concurrent-tcp-sessions" settings;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) firewall - significantly improved large firewall rule set import performance;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option;
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count";
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - fixed peer configuration my-id IPv4 address endianness;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipsec - split "mode-config" "send-dns" argument;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - added routing-table setting (cli only);
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) time - updated time zones;
    *) traceroute - fixed memory leak;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) users - added minimal required permission set for full user group;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - show ipv6 addresses correctly;
    *) winbox - added "Complete" flag to arp table;
    *) winbox - added "untracked" option to firewall "connection-state" setting;
    *) winbox - added Dude icon to Dude menu;
    *) winbox - allow to enable/disable traffic flow targets;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed crash when legacy Winbox version was used;
    *) winbox - fixed default values for interface "loop-protect-disable-time" & "loop-protect-send-interval";
    *) winbox - fixed missing "ipv6/settings" menu;
    *) winbox - fixed typo in "propagate-ttl" setting;
    *) winbox - make cert signing include provided ca-crl-host;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) winbox - show proper ipv6 connection timeout;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc45 2016-12-08

    What's new in 6.38rc45 (2016-Dec-07 14:40):

    *) certificates - fixed pkcs12 export crash;
    *) ipsec - fixed peer configuration my-id IPv4 address endianness;
    *) ipsec - various additional work on IKEv1/IKEv2 support;
    *) winbox - added new ipsec feature (IKEv1/IKEv2/etc.) support (introduced in v6.38rc);
    *) winbox - fixed crash when legacy Winbox version was used;
    *) winbox - fixed icons in disabled state (introduced in v6.38rc44);

    Other changes since 6.37.3:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes";
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder;
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods;
    *) ipsec - added ability to specify static IP address at send-dns option;
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count";
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package) (cli only);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dns - added "max-concurrent-queries" and "max-concurrent-tcp-sessions" settings;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) firewall - significantly improved large firewall rule set import performance;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipsec - split "mode-config" "send-dns" argument;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - added routing-table setting (cli only);
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) time - updated time zones;
    *) traceroute - fixed memory leak;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) users - added minimal required permission set for full user group;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - show ipv6 addresses correctly;
    *) winbox - added "Complete" flag to arp table;
    *) winbox - added "untracked" option to firewall "connection-state" setting;
    *) winbox - added Dude icon to Dude menu;
    *) winbox - allow to enable/disable traffic flow targets;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed default values for interface "loop-protect-disable-time" & "loop-protect-send-interval";
    *) winbox - fixed missing "ipv6/settings" menu;
    *) winbox - fixed typo in "propagate-ttl" setting;
    *) winbox - make cert signing include provided ca-crl-host;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) winbox - show proper ipv6 connection timeout;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc44 2016-12-07

    What's new in 6.38rc44 (2016-Dec-07 08:08):

    *) crs - added comment ability in more switch menus;
    *) dns - added "max-concurrent-queries" and "max-concurrent-tcp-sessions" settings;
    *) ipsec - split "mode-config" "send-dns" argument;
    *) ipsec - various additional work in IKEv1/IKEv2 support;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) tr069-client - various additional work;
    *) traceroute - fixed memory leak;
    *) users - added minimal required permission set for full user group;
    *) webfig - fixed preview of values bigger than 2 billion and lower than 4 billion (introduced in v6.38rc);
    *) webfig - show ipv6 addresses correctly;
    *) winbox - added "Complete" flag to arp table;
    *) winbox - added "untracked" option to firewall "connection-state" setting;
    *) winbox - added Dude icon to Dude menu;
    *) winbox - allow to enable/disable traffic flow targets;
    *) winbox - fixed default values for interface "loop-protect-disable-time" & "loop-protect-send-interval";
    *) winbox - fixed missing "ipv6/settings" menu;
    *) winbox - fixed typo in "propagate-ttl" setting;
    *) winbox - make cert signing include provided ca-crl-host;
    *) winbox - show proper ipv6 connection timeout;

    Other changes since 6.37.3:

    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) firewall - significantly improved large firewall rule set import performance;
    *) time - updated time zones;
    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package) (cli only);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - added routing-table setting (cli only);
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc37 2016-11-25

    What's new in 6.38rc37 (2016-Nov-25 11:03):

    !) tr069-client - initial implementation (as separate package);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) firewall - fixed filter rule "limit" parameter by making it visible again;
    *) hAP lite - fixed bootup (broken in v6.38rc35);

    Other changes since 6.37.2:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bgp - do not match all prefixes tagged with community 0:0 by routing filters;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed crash on "/interface print" (introduced in 6.36.4);
    *) chr - fixed crash on "/system shutdown" and "/system shutdown";
    *) chr - fixed reboot;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) disk - fixed issue when disk was renamed after reboot on devices with flash disks;
    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed rare crash;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - fixed timeout option on address lists with domain name;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) log - ignore email topic if action is email;
    *) lte - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - fixed Pantech UML296 support;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mipsbe - improved memory allocation on devices with nand when file transfer and tcp traffic processing is on progress;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) smb - fixed crash on connect (introduced in 6.38rc1);
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) tile - fixed rare kernel failure when IPv6 neighbor discovery packet is received;
    *) traceroute - fixed crash when too many sessions are active;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - allow to force mtu value when actual-mtu is already the same;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - recognise properly tcp in traffic-generator packet-template header type;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show HT MCS tab if 2GHz-G/N band is used;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc35 2016-11-23

    What's new in 6.38rc35 (2016-Nov-23 09:55):

    *) disk - fixed issue when disk was renamed after reboot on devices with flash disks;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) tunnel - allow to force mtu value when actual-mtu is already the same;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;

    Other changes since 6.37.2:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bgp - do not match all prefixes tagged with community 0:0 by routing filters;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed crash on "/interface print" (introduced in 6.36.4);
    *) chr - fixed crash on "/system shutdown" and "/system shutdown";
    *) chr - fixed reboot;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed rare crash;
    *) firewall - added creation-time to address list entries;
    *) firewall - fixed timeout option on address lists with domain name;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) log - ignore email topic if action is email;
    *) lte - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - fixed Pantech UML296 support;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) profiler - added ability to monitor cpu usage per core;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) smb - fixed crash on connect (introduced in 6.38rc1);
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) tile - fixed rare kernel failure when IPv6 neighbor discovery packet is received;
    *) traceroute - fixed crash when too many sessions are active;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - recognise properly tcp in traffic-generator packet-template header type;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show HT MCS tab if 2GHz-G/N band is used;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc34 2016-11-22

    What's new in 6.38rc34 (2016-Nov-22 10:40):

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) tr069-client - initial implementation (as separate package);
    *) bonding - added "forced-mac-address" option;
    *) certificates - added support for PKCS#12 export;
    *) chr - fixed crash on "/interface print" (introduced in 6.36.4);
    *) chr - fixed crash on "/system shutdown" and "/system shutdown";
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) firewall - new faster "connection-limit" option implementation;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) smb - fixed crash on connect (introduced in 6.38rc1);
    *) tile - fixed rare kernel failure when IPv6 neighbor discovery packet is received;
    *) traceroute - fixed crash when too many sessions are active;
    *) winbox - recognise properly tcp in traffic-generator packet-template header type;
    *) winbox - show HT MCS tab if 2GHz-G/N band is used;
    *) wireless - added CRL checking for eap-tls;

    Other changes since 6.37.2:

    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bgp - do not match all prefixes tagged with community 0:0 by routing filters;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed reboot;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed rare crash;
    *) firewall - added creation-time to address list entries;
    *) firewall - fixed timeout option on address lists with domain name;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) log - ignore email topic if action is email;
    *) lte - added support for PANTECH UML295;
    *) lte - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed Pantech UML296 support;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) profiler - added ability to monitor cpu usage per core;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc31 2016-11-15

    What's new in 6.38rc31 (2016-Nov-15 12:51):

    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    *) bgp - do not match all prefixes tagged with community 0:0 by routing filters;
    *) certificate - fixed crash when crl is removed while it is being fetched;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) log - ignore email topic if action is email;

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set radius=yes" (cli only);
    !) ipsec - added support unique policy generation which will allow multiple peers behind the same NAT (cli only);
    !) queues - significantly improved hashing algorithm in dynamic simple queue setups (fixes CPU load spikes on queue removal);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arm - improved watchdog reliability;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option (cli only);
    *) bonding - fixed 802.3ad load balancing over routed VLANs with fastpath enabled;
    *) bonding - fixed mac address selection after upgrade;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed reboot;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed port mirroring halt after L2MTU change;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) ethernet - fixed potential loopprotect crash;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed kernel failure when fastpath traffic goes into loop;
    *) fastpath - fixed rare crash;
    *) fastpath - improved connection tracking timeout updates;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - fixed "connection-state" value disappearance in rules that were created before v6.22;
    *) firewall - fixed compact export (introduced in 6.37rc14);
    *) firewall - fixed timeout option on address lists with domain name;
    *) firewall - improved "time" option (ranges like 22h-10h now are acceptable);
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipv6 - increased default max-neighbor-entries value to 8192, same as ipv4;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - fixed Pantech UML296 support;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) mmips - improved watchdog reliability;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed rare crash on statistic gathering in "/queue tree";
    *) queue - improved "time" option (ranges like 22h-10h are now usable);
    *) rb2011 - fixed crash on l2mtu changes;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) ssl - fixed potential memory leak ( when using dude for example);
    *) system - reboot device on critical program crash;
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vlan - fixed CRS switch egress-vlan-tag export;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - added led settings menu;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed missing switch menu for mmips devices;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc30 2016-11-14

    What's new in 6.38rc30 (2016-Nov-14 13:20):

    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) firewall - fixed timeout option on address lists with domain name;
    *) system - reboot device on critical program crash;

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set radius=yes" (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation which will allow multiple peers behind the same NAT (cli only);
    !) queues - significantly improved hashing algorithm in dynamic simple queue setups (fixes CPU load spikes on queue removal);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arm - improved watchdog reliability;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option (cli only);
    *) bonding - fixed 802.3ad load balancing over routed VLANs with fastpath enabled;
    *) bonding - fixed mac address selection after upgrade;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed reboot;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed port mirroring halt after L2MTU change;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) ethernet - fixed potential loopprotect crash;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed kernel failure when fastpath traffic goes into loop;
    *) fastpath - fixed rare crash;
    *) fastpath - improved connection tracking timeout updates;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - fixed "connection-state" value disappearance in rules that were created before v6.22;
    *) firewall - fixed compact export (introduced in 6.37rc14);
    *) firewall - improved "time" option (ranges like 22h-10h now are acceptable);
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipv6 - increased default max-neighbor-entries value to 8192, same as ipv4;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - fixed Pantech UML296 support;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) mmips - improved watchdog reliability;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed rare crash on statistic gathering in "/queue tree";
    *) queue - improved "time" option (ranges like 22h-10h are now usable);
    *) rb2011 - fixed crash on l2mtu changes;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) ssl - fixed potential memory leak ( when using dude for example);
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vlan - fixed CRS switch egress-vlan-tag export;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - added led settings menu;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed missing switch menu for mmips devices;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc19 2016-10-31

    What's new in 6.38rc19 (2016-Oct-24 11:19):

    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    *) chr - fixed "/interface print";
    *) chr - fixed reboot;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) fastpath - fixed kernel failure when fastpath traffic goes into loop;
    *) fastpath - fixed rare crash;
    *) interface - changed loopback interface mtu to 1500;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - send xauth password without trailing null;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) lte - fixed Pantech UML296 support;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified;
    *) profiler - added ability to monitor cpu usage per core;
    *) resolver - ignore cache entries if specific server is used;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vlan - fixed CRS switch egress-vlan-tag export;
    *) winbox - added led settings menu;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - fixed missing switch menu for mmips devices;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - take in account channel width when returning supported channels;

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) ethernet - fixed potential loopprotect crash;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - fixed compact export (introduced in 6.37rc14);
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) rb2011 - fixed crash on l2mtu changes;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;

  • Release 6.38rc15 2016-10-14

    What's new in 6.38rc15 (2016-Oct-14 09:11):

    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) firewall - fixed compact export (introduced in 6.37rc14);
    *) rb2011 - fixed crash on l2mtu changes;

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) ethernet - fixed potential loopprotect crash;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified (CLI only);
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;

  • Release 6.38rc9 2016-10-05

    What's new in 6.38rc9 (2016-Oct-05 10:23):

    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) package – show minimal supported RouterOS version under “/system resource” menu if it is specified (CLI only);
    *) sms – fixed crash after modem has failed to start;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;

    Other changes since 6.37.1:

    *) arp - added local-proxy-arp feature;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) discovery - added LLDP support;
    *) firewall - added creation-time to address list entries;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) torch - fixed aggregate statistics appearance;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;

  • Release 6.37rc42 2016-09-22

    What's new in 6.37rc42 (2016-Sep-22 11:07):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country settings (/interface wireless info country-info), and applies corresponding DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc40:

    !) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) certificate - do not allow to remove certificate template while signing certificate;
    *) dhcpv6 - fixed interface status update on client add (introduced in v6.37rc);
    *) firewall - fixed time based rules on time/timezone changes (again);
    *) ipsec - fixed crash with enabled fragmentation;
    *) ipsec - fixed fragmentation use negotiation;
    *) lte - added hauwei me909s variant;
    *) lte - fixed setting correct lte band for sxt lte;
    *) traffic-flow - fixed IPFIX packet timestamp;
    *) traffic-flow - fixed IPFIX wrong flow sequence;

    Other changes since 6.36.3:

    *) dhcpv6 - reworked DHCP-PD server interface and route management;
    *) tunnel - fixed communication via tunnel to router itself if fastpath was active;
    *) wireless - fixed interface disappearance on upgrade to 6.37 (introduced in v6.37rc);
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - fixed kernel crash on cap while changing client-to-client forwarding;
    *) capsman - report radio-name in registration table;
    *) console - hotspot setup show wrong certificate name;
    *) defconf - fixed default configuration restore if virtual wireless interface were present;
    *) defconf - fixed default configuration when wireless package is used;
    *) defconf - using caps button now forces all wireless interfaces in caps mode;
    *) dhcpv6 - improved interface status tracking;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) gps - always check NMEA checksum if available;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - fixed RA and RS processing on new interfaces after many interfaces have lost link during prolonged operation;
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added switch for Huawei K5160;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed memory leak;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) packages - fixed situation when it was impossible to disable ipv6 package (introduced in v6.37rc3x);
    *) partitions - added ability to add comments;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) ppp,lte - pin is now converted to string argument;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) supout - improved crash report generation for tile architecture;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) users - fixed script policy checking against user policies when running scripts;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed unset button for L2MTU field;
    *) winbox - show firmware-type in routerboard window;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc40 2016-09-20

    What's new in 6.37rc40 (2016-Sep-20 10:55):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country settings (/interface wireless info country-info), and applies corresponding DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc38:

    *) dhcpv6 - reworked DHCP-PD server interface and route management;
    *) tunnel - fixed communication via tunnel to router itself if fastpath was active;
    *) wireless - fixed interface disappearance on upgrade to 6.37 (introduced in v6.37rc);

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - fixed kernel crash on cap while changing client-to-client forwarding;
    *) capsman - report radio-name in registration table;
    *) console - hotspot setup show wrong certificate name;
    *) defconf - fixed default configuration restore if virtual wireless interface were present;
    *) defconf - fixed default configuration when wireless package is used;
    *) defconf - using caps button now forces all wireless interfaces in caps mode;
    *) dhcpv6 - improved interface status tracking;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) gps - always check NMEA checksum if available;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - fixed RA and RS processing on new interfaces after many interfaces have lost link during prolonged operation;
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added switch for Huawei K5160;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed memory leak;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) packages - fixed situation when it was impossible to disable ipv6 package (introduced in v6.37rc3x);
    *) partitions - added ability to add comments;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) ppp,lte - pin is now converted to string argument;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) supout - improved crash report generation for tile architecture;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) users - fixed script policy checking against user policies when running scripts;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed unset button for L2MTU field;
    *) winbox - show firmware-type in routerboard window;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc38 2016-09-19

    What's new in 6.37rc38 (2016-Sep-19 09:42):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc36:

    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    *) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - fixed kernel crash on cap while changing client-to-client forwarding;
    *) capsman - report radio-name in registration table;
    *) console - hotspot setup show wrong certificate name;
    *) defconf - fixed default configuration restore if virtual wireless interface were present;
    *) defconf - fixed default configuration when wireless package is used;
    *) defconf - using caps button now forces all wireless interfaces in caps mode;
    *) dhcpv6 - improved interface status tracking;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) gps - always check NMEA checksum if available;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - fixed RA and RS processing on new interfaces after many interfaces have lost link during prolonged operation;
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added switch for Huawei K5160;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed memory leak;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) packages - fixed situation when it was impossible to disable ipv6 package (introduced in v6.37rc3x);
    *) partitions - added ability to add comments;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) ppp,lte - pin is now converted to string argument;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) supout - improved crash report generation for tile architecture;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) users - fixed script policy checking against user policies when running scripts;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed unset button for L2MTU field;
    *) winbox - show firmware-type in routerboard window;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc36 2016-09-15

    What's new in 6.37rc36 (2016-Sep-14 10:12):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc34:

    *) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) defconf - fixed default configuration restore if virtual wireless interface were present;
    *) defconf - using caps button now forces all wireless interfaces in caps mode;
    *) console - hotspot setup show wrong certificate name;

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - fixed kernel crash on cap while changing client-to-client forwarding;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - improved interface status tracking;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) gps - always check NMEA checksum if available;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - fixed RA and RS processing on new interfaces after many interfaces have lost link during prolonged operation;
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added switch for Huawei K5160;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed memory leak;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) packages - fixed situation when it was impossible to disable ipv6 package (introduced in v6.37rc3x);
    *) partitions - added ability to add comments;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) ppp,lte - pin is now converted to string argument;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) supout - improved crash report generation for tile architecture;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) users - fixed script policy checking against user policies when running scripts;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed unset button for L2MTU field;
    *) winbox - show firmware-type in routerboard window;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc34 2016-09-13

    What's new in 6.37rc34 (2016-Sep-12 13:06):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc32:

    *) capsman - fixed kernel crash on cap while changing client-to-client forwarding;
    *) dhcpv6 - improved interface status tracking;
    *) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) gps - always check NMEA checksum if available;
    *) ipv6 - fixed RA and RS processing on new interfaces after many interfaces have lost link during prolonged operation;
    *) mpls - fixed memory leak;
    *) packages - fixed situation when it was impossible to disable ipv6 package (introduced in v6.37rc3x);
    *) ppp,lte - pin is now converted to string argument;
    *) supout - improved crash report generation for tile architecture;

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added switch for Huawei K5160;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) users - fixed script policy checking against user policies when running scripts;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed unset button for L2MTU field;
    *) winbox - show firmware-type in routerboard window;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc32 2016-09-07

    What's new in 6.37rc32 (2016-Sep-07 10:55):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc30:

    *) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) lte - added switch for Huawei K5160;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) users - fixed script policy checking against user policies when running scripts;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - show firmware-type in routerboard window;

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed unset button for L2MTU field;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc30 2016-09-06

    What's new in 6.37rc30 (2016-Sep-06 06:59):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc27:

    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed never-ending loop in CDP packet processing;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added switch for Huawei K5160;
    *) lte - fixed band unsetting;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) trafficgen - add per stream packet count setting;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed unset button for L2MTU field;

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) kvm - fix add/remove of disabled interfaces;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) wireless - updated brazil country settings.

  • Release 6.37rc27 2016-09-02

    What's new in 6.37rc27 (2016-Sep-02 06:18):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc26:

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) kvm - fix add/remove of disabled interfaces;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) usermanager - fixed rare crash on paypal payment;

    Other changes since 6.36.2:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) fastpath - fixed kernel crash on interface disable/remove;
    *) fetch - fixed bug with incomplete files in https mode;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - don't log authtype mismatch as critical;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipsec - fixed xauth parameter printing in terminal;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added zte K5008-Z back;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) pppoe - fixed master interface l2mtu check, could result in assumption that master interface can handle 14 byte bigger packet than it actually can (broken in 6.36);
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) simple queues - fixed issue which caused additional/unnecessary CPU load;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) switch - added comment field for CRS switch VLANs;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vlan - do not allow to add new vlan interface with mtu higher than l2mtu;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc26 2016-08-31

    What's new in 6.37rc26 (2016-Aug-31 11:25):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc24:

    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces (http://wiki.mikrotik.com/wiki/Manual:Loop_Protect);
    *) fastpath - fixed kernel crash on interface disable/remove;
    *) fetch - fixed bug with incomplete files in https mode;
    *) routing - improved kernel performance in setups with large routing tables;
    *) snmp - require write permitions for script run table access;
    *) sstp - now supports TLS_ECDHE algorithms;

    Other changes since 6.36.2:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - don't log authtype mismatch as critical;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipsec - fixed xauth parameter printing in terminal;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added zte K5008-Z back;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) pppoe - fixed master interface l2mtu check, could result in assumption that master interface can handle 14 byte bigger packet than it actually can (broken in 6.36);
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) simple queues - fixed issue which caused additional/unnecessary CPU load;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) switch - added comment field for CRS switch VLANs;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vlan - do not allow to add new vlan interface with mtu higher than l2mtu;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc24 2016-08-30

    What's new in 6.37rc24 (2016-Aug-30 11:57):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc22:

    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) ipsec - don't log authtype mismatch as critical;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipsec - fixed xauth parameter printing in terminal;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added zte K5008-Z back;
    *) lte - fixed default channels for dlink dwm-157;
    *) pppoe - fixed master interface l2mtu check, could result in assumption that master interface can handle 14 byte bigger packet than it actually can (broken in 6.36);
    *) snmp - skip forbidden oids on getnext completion;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) usb - fixed usb port reset on ether1 link changes on mAP 2n;

    Other changes since 6.36.2:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) simple queues - fixed issue which caused additional/unnecessary CPU load;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) sstp - allow to specify proxy by dns name;
    *) switch - added comment field for CRS switch VLANs;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vlan - do not allow to add new vlan interface with mtu higher than l2mtu;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc22 2016-08-25

    What's new in 6.37rc22 (2016-Aug-25 09:01):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc21:

    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) simple queues - fixed issue which caused additional/unnecessary CPU load;

    Other changes since 6.36.2:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) sstp - allow to specify proxy by dns name;
    *) switch - added comment field for CRS switch VLANs;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vlan - do not allow to add new vlan interface with mtu higher than l2mtu;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc21 2016-08-25

    What's new in 6.37rc21 (2016-Aug-25 06:15):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info ), and apply corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with correcponding DFS settings before upgrade.

    Changes since 6.37rc20:

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) hotspot - show comments from user menu also in active menu;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) vlan - do not allow to add new vlan interface with mtu higher than l2mtu;
    *) wireless - updated brazil country settings;

    Other changes since 6.36.2:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) sstp - allow to specify proxy by dns name;
    *) switch - added comment field for CRS switch VLANs;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.

  • Release 6.37rc20 2016-08-19

    What's new in 6.37rc20 (2016-Aug-19 06:35):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc19:

    *) address-list - fixed crash (introduced in 6.37rc17);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) export - updated default values in /system routerboard settings menu;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) trafficgen - fixed crash (introduced in 6.37rc17);

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) arm - show cpu frequency under resources menu;
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) capsman - fixed upgrade policy;
    *) capsman - report radio-name in registration table;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) defconf - fixed default configuration when wireless package is used;
    *) disk - do not do unnecessary sector writes;
    *) dns - allow to set query-server-timeout and query-total-timeout only greater than 0s;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dns - fixed lockup when dynamic dns server address 0.0.0.0 was received;
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - added additional matchers for firewall raw rules;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) health - do not show psu and fan information for passive cooling devices;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) partitions - fixed crash on repartition when there is not enough free space;
    *) ping - fixed freezing on "not running" interfaces;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - fixed disconnects on transmit for multicore systems;
    *) switch - added comment field for CRS switch VLANs;
    *) switch - fixed configuration reload on CRS switches;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) webfig - allowed user password changing (broken in v6.36);
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - make queue tree default queue type default-small;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc19 2016-08-18

    What's new in 6.37rc19 (2016-Aug-18 06:46):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc16:

    *) arm - show cpu frequency under resources menu;
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;


    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) capsman - fixed upgrade policy;
    *) capsman - report radio-name in registration table;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) defconf - fixed default configuration when wireless package is used;
    *) disk - do not do unnecessary sector writes;
    *) dns - allow to set query-server-timeout and query-total-timeout only greater than 0s;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dns - fixed lockup when dynamic dns server address 0.0.0.0 was received;
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - added additional matchers for firewall raw rules;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) health - do not show psu and fan information for passive cooling devices;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) partitions - fixed crash on repartition when there is not enough free space;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - fixed disconnects on transmit for multicore systems;
    *) switch - added comment field for CRS switch VLANs;
    *) switch - fixed configuration reload on CRS switches;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) webfig - allowed user password changing (broken in v6.36);
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - make queue tree default queue type default-small;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc16 2016-08-15

    What's new in 6.37rc16 (2016-Aug-15 07:48):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc15:

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) switch - added comment field for CRS switch VLANs;
    *) switch - fixed configuration reload on CRS switches;

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) capsman - fixed upgrade policy;
    *) capsman - report radio-name in registration table;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) defconf - fixed default configuration when wireless package is used;
    *) disk - do not do unnecessary sector writes;
    *) dns - allow to set query-server-timeout and query-total-timeout only greater than 0s;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dns - fixed lockup when dynamic dns server address 0.0.0.0 was received;
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - added additional matchers for firewall raw rules;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) health - do not show psu and fan information for passive cooling devices;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) partitions - fixed crash on repartition when there is not enough free space;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - fixed disconnects on transmit for multicore systems;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) webfig - allowed user password changing (broken in v6.36);
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - make queue tree default queue type default-small;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc15 2016-08-11

    What's new in 6.37rc15 (2016-Aug-11 09:14):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc13:

    *) capsman - fixed upgrade policy;
    *) capsman - report radio-name in registration table;
    *) dns - allow to set query-server-timeout and query-total-timeout only greater than 0s;
    *) dns - fixed lockup when dynamic dns server address 0.0.0.0 was received;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - fixed disconnects on transmit for multicore systems;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - make queue tree default queue type default-small;

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) defconf - fixed default configuration when wireless package is used;
    *) disk - do not do unnecessary sector writes;
    *) dns - avoid unnecessary static entry saving in storage;
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) partitions - fixed crash on repartition when there is not enough free space;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) webfig - allowed user password changing (broken in v6.36);
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc13 2016-08-10

    What's new in 6.37rc13 (2016-Aug-08 07:39):

    >>> IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    >>> IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc12:

    *) disk - do not do unnecessary sector writes;
    *) lte - added initial deregistration only for bandrich modems;
    *) partitions - added ability to add comments;
    *) partitions - fixed crash on repartition when there is not enough free space;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) webfig - allowed user password changing (broken in v6.36);

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) defconf - fixed default configuration when wireless package is used;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc12 2016-08-05

    What's new in 6.37rc12 (2016-Aug-05 05:31):

    >>> IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    >>> IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc11:

    *) defconf - fixed default configuration when wireless package is used;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) ping - fixed freezing on "not running" interfaces;
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) wireless - display DFS flag in country info;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc11 2016-08-01

    What's new in 6.37rc11 (2016-Aug-01 09:00):

    >>> IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    >>> IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc10:

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - fixed band setting for sxt lte;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added d-link dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) dns - avoid unnecessary static entry saving in storage;
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) modem - added dlink dwm-157 D support;
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) wireless - display DFS flag in country info;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc10 2016-07-29

    What's new in 6.37rc10 (2016-Jul-29 06:44):

    >>> IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using “routeros” bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one “wireless” package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    >>> IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to “dfs=radar-detect” for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc5:

    !) dude - from now on dude will use winbox port and it will be changed automatically both
    in client loader and agent configuration.
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    !) console - dfs-mode setting does not exist any more and all scripts with such setting
    will not be executed;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) firewall - check for duplicates when domain name is used in address field;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered
    state;
    *) modem - added dlink dwm-157 D support;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) wireless - display DFS flag in country info;

    Other changes since 6.36:

    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) check-for-updates - with bundle "routeros" package, will replace wireless package
    automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package
    automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no
    wireless packages installed, uninstall extra packages first;
    *) address-list - allow DNS names with "_" symbol;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - fixed time based rules on time/timezone changes;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on
    regular intervals;
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc5 2016-07-22

    What's new in 6.37rc5 (2016-Jul-22 09:17):

    New features and important changes:

    From now on there will be only one "wireless" package!
    Update on some package configurations is dangerous!!!

    *) wireless - "wireless-rep" renamed to "wireless";
    *) wireless - "wireless-cm2" discontinued, uninstall it before update;
    *) wireless - "wireless" package included in bundle "routeros" package;
    *) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    *) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    *) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;

    Fixes in last RC:

    *) address-list - allow DNS names with "_" symbol;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424 );
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - fixed time based rules on time/timezone changes;

    Fixes:

    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc4 2016-07-22

    What's new in 6.37rc4 (2016-Jul-21 07:17):

    Wireless is now unified to a single "wireless" package.
    Update on some package configurations is dangerous!!!

    *) wireless - "wireless-rep" renamed to "wireless";
    *) wireless - "wireless-cm2" discontinued, uninstall it before update;
    *) wireless - "wireless" package included in bundle "routeros" package;
    *) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    *) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    *) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals.
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424 );
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.36rc40 2016-07-13

    What's new in 6.36rc40 (2016-Jul-13 08:11):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083);
    *) lte - fixed modem network configuration version checks;
    *) nat - fixed nat rule disappearance after reboot if interface-list was used (introduced in 6.36rc39);
    *) pppoe - allow to set MTU and MRU higher than 1500 for PPPoE;
    *) tunnel - fixed rare crash by specifying minimal header length immediately at tunnel initialization;
    *) winbox - added 2ghz-g/n band for wireless-rep;
    *) winbox - added icons to bridge filter actions similar to ip firewall;
    *) winbox - do not show filter for combined fields like bgp-vpn4 RD;
    *) winbox - improve filtering on list fields;
    *) winbox - show action column as first in bridge firewall;
    *) winbox - show error when telnet is not allowed because of permissions;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding primary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - do not exit after card-verify;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed CHR seeing its own system disk mounted as additional data disk;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - fixed time keeping for SXT ac, 911L, cAP, mAP lite, wAP;
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - fixed get false function;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) email - removed subject and body length limit;
    *) email - fixed send from winbox;
    *) ethernet - fixed incorrect ether1 link speed after reboot on rb4xx series routers;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed interface list matcher showing incorrect name for NAT rules;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompliance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - fixed windows msgid check on x86 devices;
    *) ipsec - show remote peer address in error messages when possible;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) l2tp - fixed crash when rebooting or disabling l2tp while there are still active connections;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) log - make logging process less aggressive on startup;
    *) log - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - added support for Huawei E3531;
    *) lte - added support for ZTE ZM8620;
    *) lte - added use-peer-dns option (will work only combined with add-default-route);
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - display message in lte,error log if no response received;
    *) lte - display message in lte,error log when PIN is required;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - fixed modem init when pin request present;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for Alcatel OneTouch X600;
    *) modem - added support for SpeedUP SU-900U modem;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) netinstall - fixed netinstall and cd install for x86 (broken since 6.36rc27);
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) pppoe - do not allow to send out bigger packets than l2mtu if mrru is provided;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb2011 - fixed ether6-ether10 flapping when two ports from both switch chips are in the same bridge;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) rb3011 - fixed usb storage mounting;
    *) rb3011 - improved performance on high cpu usage;
    *) route - added suppport for more than 8 bits of options;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - do not exit while there still are active sessions;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) timezone - updated timezone information from tzdata2016e release;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) upnp - fixed firewall rules not being dynamic;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required);
    *) webfig - reduced refresh time for wireless registration table to 1 second;
    *) winbox - added arp-timeout setting to all ethernet like interfaces;
    *) winbox - added domain name support for IPv6 address list;
    *) winbox - do not allow to specify vlan-mode=no-tag in capsman datapath config;
    *) winbox - do not show mode setting for WDS interfaces;
    *) winbox - fixed crash when using ctrl+d;
    *) winbox - make local-address optional for eoipv6, 6to4, ipip, ipipv6 & grev6;
    *) winbox - renamed IPv6 "Raw rules" section to "Raw";
    *) winbox - report correctly dude users in active users list;
    *) winbox - set default sa-learning value to "yes" for CRS Ingress VLAN Translation rules;
    *) wireless - fixed multiple wireless packages enabled at the same time after upgrade;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc39 2016-07-12

    What's new in 6.36rc39 (2016-Jul-12 08:10):

    *) chr - fixed CHR seeing its own system disk mounted as additional data disk;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083);
    *) ethernet - fixed incorrect ether1 link speed after reboot on rb4xx series routers;
    *) firewall - fixed interface list matcher showing incorrect name for NAT rules;
    *) lte - added support for ZTE ZM8620;
    *) lte - added use-peer-dns option (will work only combined with add-default-route);
    *) netinstall - fixed netinstall and cd install for x86 (broken since 6.36rc27);
    *) pppoe - do not allow to send out bigger packets than l2mtu if mrru is provided;
    *) rb2011 - fixed ether6-ether10 flapping when two ports from both switch chips are in the same bridge;
    *) winbox - added arp-timeout setting to all ethernet like interfaces;
    *) winbox - added domain name support for IPv6 address list;
    *) winbox - do not allow to specify vlan-mode=no-tag in capsman datapath config;
    *) winbox - do not show mode setting for WDS interfaces;
    *) winbox - fixed crash when using ctrl+d;
    *) winbox - make local-address optional for eoipv6, 6to4, ipip, ipipv6 & grev6;
    *) winbox - renamed IPv6 "Raw rules" section to "Raw";
    *) winbox - set default sa-learning value to "yes" for CRS Ingress VLAN Translation rules;
    *) wireless - fixed multiple wireless packages enabled at the same time after upgrade;
    *) l2tp - fixed crash when rebooting or disabling l2tp while there are still active connections;
    *) rb3011 - fixed usb storage mounting;
    *) webfig - reduced refresh time for wireless registration table to 1 second;
    *) clock - fixed time keeping for SXT ac, 911L, cAP, mAP lite, wAP;
    *) ipsec - show remote peer address in error messages when possible;
    *) lte - display message in lte,error log if no response received;
    *) lte - display message in lte,error log when PIN is required;
    *) modem - added support for Alcatel OneTouch X600;
    *) upnp - fixed firewall rules not being dynamic;
    *) email - fixed send from winbox;
    *) log - make logging process less aggressive on startup;
    *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required);
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding primary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - do not exit after card-verify;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - fixed get false function;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompliance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - fixed windows msgid check on x86 devices;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - added support for Huawei E3531;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - fixed modem init when pin request present;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for SpeedUP SU-900U modem;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) rb3011 - improved performance on high cpu usage;
    *) route - added suppport for more than 8 bits of options;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - do not exit while there still are active sessions;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) timezone - updated timezone information from tzdata2016e release;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc37 2016-07-08

    What's new in 6.36rc37 (2016-Jul-07 11:13):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083);
    *) l2tp - fixed crash when rebooting or disabling l2tp while there are still active connections;
    *) rb3011 - fixed usb storage mounting;
    *) webfig - reduced refresh time for wireless registration table to 1 second;
    *) clock - fixed time keeping for SXT ac, 911L, cAP, mAP lite, wAP;
    *) ipsec - show remote peer address in error messages when possible;
    *) lte - display message in lte,error log if no response received;
    *) lte - display message in lte,error log when PIN is required;
    *) modem - added support for Alcatel OneTouch X600;
    *) upnp - fixed firewall rules not being dynamic;
    *) email - fixed send from winbox;
    *) log - make logging process less aggressive on startup;
    *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required);
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding primary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - do not exit after card-verify;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - fixed get false function;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompliance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - fixed windows msgid check on x86 devices;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - added support for Huawei E3531;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - fixed modem init when pin request present;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for SpeedUP SU-900U modem;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) rb3011 - improved performance on high cpu usage;
    *) route - added suppport for more than 8 bits of options;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - do not exit while there still are active sessions;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) timezone - updated timezone information from tzdata2016e release;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc36 2016-07-06

    What's new in 6.36rc36 (2016-Jul-06 09:51):

    *) clock - fixed time keeping for SXT ac, 911L, cAP, mAP lite, wAP;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083);
    *) ipsec - show remote peer address in error messages when possible;
    *) lte - display message in lte,error log if no response received;
    *) lte - display message in lte,error log when PIN is required;
    *) modem - added support for Alcatel OneTouch X600;
    *) upnp - fixed firewall rules not being dynamic;
    *) email - fixed send from winbox;
    *) log - make logging process less aggressive on startup;
    *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required);
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding primary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - do not exit after card-verify;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - fixed get false function;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompliance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - fixed windows msgid check on x86 devices;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - added support for Huawei E3531;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - fixed modem init when pin request present;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for SpeedUP SU-900U modem;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) rb3011 - improved performance on high cpu usage;
    *) route - added suppport for more than 8 bits of options;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - do not exit while there still are active sessions;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) timezone - updated timezone information from tzdata2016e release;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc33 2016-06-29

    What's new in 6.36rc33 (2016-Jun-28 11:04):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) email - fixed send from winbox;
    *) log - make logging process less aggressive on startup;
    *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required);
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding primary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - do not exit after card-verify;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - fixed get false function;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompliance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - fixed windows msgid check on x86 devices;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - added support for Huawei E3531;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - fixed modem init when pin request present;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for SpeedUP SU-900U modem;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) rb3011 - improved performance on high cpu usage;
    *) route - added suppport for more than 8 bits of options;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - do not exit while there still are active sessions;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) timezone - updated timezone information from tzdata2016e release;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc30 2016-06-22

    What's new in 6.36rc30 (2016-Jun-21 13:12):

    *) certificate - do not exit after card-verify;
    *) console - fixed get false function;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ipsec - fixed windows msgid check on x86 devices;
    *) lte - added support for Huawei E3531;
    *) lte - fixed modem init when pin request present;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for SpeedUP SU-900U modem;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) route - added suppport for more than 8 bits of options;
    *) ssl - do not exit while there still are active sessions;
    *) timezone - updated timezone information from tzdata2016e release;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) wireless-rep - fixed nstreme reset on poll timeout;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding privmary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompilance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - improved performance on high cpu usage;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc28 2016-06-13

    What's new in 6.36rc28 (2016-Jun-10 12:12):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ipsec - add dead ph2 detection exception for windows msgid noncompilance with rfc;
    *) lte - added cinterion pls8 support;
    *) lte - fixed connection for huawei without cell info;
    *) supout - erase panic data properly on Netinstall;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding privmary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - improved performance on high cpu usage;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) switch - fixed switch compact export;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc27 2016-06-09

    What's new in 6.36rc27 (2016-Jun-08 12:21):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) address-list - make "dynamic=yes" as read-only option;
    *) bonding - fixed bonding privmary slave assignment for ovpn interfaces after startup;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) userman - fixed crash on database upload;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - use only creg result codes as network status indications;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) rb3011 - fixed reset button functionality;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) rb3011 - improved performance on high cpu usage;
    *) snmp - report ram memory as ram instead of other;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - force scep renewal on system clock updates;
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) fetch - support tls host name extension;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) certificate - display issuer and subject on check failure;
    *) cloud - fixed export order;
    *) dhcpv6-server - fixed binding last-seen update;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - store udp encapsulation type in proposal;
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - treat missing SSID element as hidden SSID;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc21 2016-05-31

    What's new in 6.36rc21 (2016-May-31 10:45):

    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - use only creg result codes as network status indications;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) rb3011 - fixed reset button functionality;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) rb3011 - improved performance on high cpu usage;
    *) snmp - report ram memory as ram instead of other;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - force scep renewal on system clock updates;
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) fetch - support tls host name extension;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) certificate - display issuer and subject on check failure;
    *) cloud - fixed export order;
    *) dhcpv6-server - fixed binding last-seen update;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - store udp encapsulation type in proposal;
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - treat missing SSID element as hidden SSID;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc20 2016-05-30

    What's new in 6.36rc20 (2016-May-30 05:56):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) rb3011 - improved performance on high cpu usage;
    *) snmp - report ram memory as ram instead of other;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - force scep renewal on system clock updates;
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) fetch - support tls host name extension;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) certificate - display issuer and subject on check failure;
    *) cloud - fixed export order;
    *) dhcpv6-server - fixed binding last-seen update;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - store udp encapsulation type in proposal;
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - treat missing SSID element as hidden SSID;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc19 2016-05-27

    What's new in 6.36rc19 (2016-May-27 06:20):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - force scep renewal on system clock updates;
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) fetch - support tls host name extension;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) rb3011 - improved performance on high cpu usage;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) certificate - display issuer and subject on check failure;
    *) cloud - fixed export order;
    *) dhcpv6-server - fixed binding last-seen update;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - store udp encapsulation type in proposal;
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - treat missing SSID element as hidden SSID;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc16 2016-05-24

    What's new in 6.36rc16 (2016-May-24 07:04):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) address - allow multiple euqla ip addresses to be added if neither or only one is enabled;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) certificate - display issuer and subject on check failure;
    *) cloud - fixed export order;
    *) dhcpv6-server - fixed binding last-seen update;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - store udp encapsulation type in proposal;
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - treat missing SSID element as hidden SSID;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc13 2016-05-18

    What's new in 6.36rc13 (2016-May-17 12:20):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking and packet defragmentation (CLI only);
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc12 2016-05-11

    What's new in 6.36rc12 (2016-May-11 06:27):

    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking and packet defragmentation (CLI only);
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade.

  • Release 6.36rc11 2016-05-05

    What's new in 6.36rc11 (2016-May-05 07:40):

    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking and packet defragmentation (CLI only);
    *) firewall - fixed policy routing configurations (introduced in 6.35rc38);
    *) queue - fixed interface queue type for ovpn tunnels;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) discovery - fixed identity discovery (introduced in 6.36rc5 and 6.35.1);
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) log - fixed time zone adjustment (introduced in 6.36rc5 and 6.35.1);
    *) lte - added cinterion pls8 support;
    *) snmp - fixed snmp timeout (introduced in 6.36rc5 and 6.35.1);
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) vrrp - fixed missing vrrp interfaces after upgrade (introduced in 6.36rc5 and 6.35.1);
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc10 2016-04-29

    What's new in 6.36rc10 (2016-Apr-29 11:14):

    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking and packet defragmentation (CLI only);
    *) firewall - fixed policy routing configurations (introduced in 6.35rc38);
    *) queue - fixed interface queue type for ovpn tunnels;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) discovery - fixed identity discovery (introduced in 6.36rc5 and 6.35.1);
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) log - fixed time zone adjustment (introduced in 6.36rc5 and 6.35.1);
    *) lte - added cinterion pls8 support;
    *) snmp - fixed snmp timeout (introduced in 6.36rc5 and 6.35.1);
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) vrrp - fixed missing vrrp interfaces after upgrade (introduced in 6.36rc5 and 6.35.1);
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc9 2016-04-29

    What's new in 6.36rc9 (2016-Apr-29 08:04):

    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) discovery - fixed identity discovery (introduced in 6.36rc5 and 6.35.1);
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) log - fixed time zone adjustment (introduced in 6.36rc5 and 6.35.1);
    *) lte - added cinterion pls8 support;
    *) snmp - fixed snmp timeout (introduced in 6.36rc5 and 6.35.1);
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) vrrp - fixed missing vrrp interfaces after upgrade (introduced in 6.36rc5 and 6.35.1);
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking (CLI only);
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc8 2016-04-28

    What's new in 6.36rc8 (2016-Apr-28 06:57):

    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking (CLI only);
    *) lte - added cinterion pls8 support;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc6 2016-04-25

    What's new in 6.36rc6 (2016-Apr-25 06:25):

    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) watchdog - fixed reboot loop on startup (introduced in 6.36rc5);
    *) arp - added arp-timeout option per interface;
    *) log - fixed reboot log messages;
    *) lte - do not allow to set multiple modes when it is not supported;
    *) lte - fixed address acquisition on Huaweii LTE interfaces;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) winbox - show voltage in Health only if there actually is voltage monitor;
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless - fixed issue when CAPsMAN could lock CAPs interface;
    *) wireless-rep - fixed scan-list unset;
    *) bonding - do not corrupt bonding statistics on configuration changes;
    *) bonding - fixed crash when vlan parent mtu is higher than bonding mtu;
    *) ethernet - do not allow mtu to be higher than l2mtu and l2mtu to be higher than max-l2mtu (reduce automatically on upgrade if it was wrong before);
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc5 2016-04-22

    What's new in 6.36rc5 (2016-Apr-22 06:28):

    *) arp - added arp-timeout option per interface;
    *) log - fixed reboot log messages;
    *) lte - do not allow to set multiple modes when it is not supported;
    *) lte - fixed address acquisition on Huaweii LTE interfaces;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) winbox - show voltage in Health only if there actually is voltage monitor;
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless - fixed issue when CAPsMAN could lock CAPs interface;
    *) wireless-rep - fixed scan-list unset;
    *) bonding - do not corrupt bonding statistics on configuration changes;
    *) bonding - fixed crash when vlan parent mtu is higher than bonding mtu;
    *) ethernet - do not allow mtu to be higher than l2mtu and l2mtu to be higher than max-l2mtu (reduce automatically on upgrade if it was wrong before);
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc4 2016-04-21

    What's new in 6.36rc4 (2016-Apr-20 12:46):

    *) arp - added arp-timeout option per interface;
    *) log - fixed reboot log messages;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless - fixed issue when CAPsMAN could lock CAPs interface;
    *) wireless-rep - fixed scan-list unset;
    *) bonding - do not corrupt bonding statistics on configuration changes;
    *) bonding - fixed crash when vlan parent mtu is higher than bonding mtu;
    *) ethernet - do not allow mtu to be higher than l2mtu and l2mtu to be higher than max-l2mtu (reduce automatically on upgrade if it was wrong before);
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc3 2016-04-19

    What's new in 6.36rc3 (2016-Apr-19 11:33):

    *) bonding - do not corrupt bonding statistics on configuration changes;
    *) bonding - fixed crash when vlan parent mtu is higher than bonding mtu;
    *) ethernet - do not allow mtu to be higher than l2mtu and l2mtu to be higher than max-l2mtu (reduce automatically on upgrade if it was wrong before);
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.35rc49 2016-04-12

    What's new in 6.35rc49 (2016-Apr-12 7:20):

    *) dhcpv6 client - fix ia expiration and lifetime validation;
    *) dhcpv6 server - acquire binding on renew if it does not exist;
    *) export - exclude default values from export in "/interface l2tp-server server" menu;
    *) export - fixed rare situations when not whole config was exported;
    *) leds - fixed AP-CAP led blinking after successful association to CAPsMAN;
    *) lte - fixed crash on early initialization;
    *) lte - use timer for modem info;
    *) ntp - fixed ntp client hangs in reached state;
    *) rb3011 - fixed sfp compatibility with CCR when using direct attached cables;
    *) tunnels - fixed performance slowdown on any other tunnel disable/enable;
    *) winbox - added "pw-type" to "/interface vpls bgp-vpls" menu;
    *) winbox - added "use-control-word" and "pw-mtu" to "/interface vpls cisco-bgp-vpls" menu;
    *) winbox - added mtu=auto support to eoipv6 tunnel;
    *) wireless-rep - use full identity where possible;
    *) wireless-rep - fixed latency issues with Intel wireless clients;
    *) mipsbe - (excluding RB4xx and CRS series) fixed rare ethernet tx buffer corruption;
    *) dhcp6-client - fixed wrong error message;
    *) address-list - fixed crash in low memory situations;
    *) tile - fixed performance regression on switch chip (introduced in 6.33rc18);
    *) tile - fixed l2mtu change (introduced in 6.35rc);
    *) lcd - fixed branding packet logo drawing on startup;
    *) lte - replaced signal-strength with rssi in info command;
    *) nand - fixed reboot loop after upgrade to >v6.35rc43;
    *) ppp - fixed some clients can not connect due to LCP restart;
    *) tool fetch - fixed https cleanup on user stop while handshaking;
    *) winbox - make build with latest lte changes;
    *) hotspot - make video tag work properly on hotspot login.html page
    *) ipsec - fixed crash on policy update;
    *) ppp - fixed ppp crash if lcp packets were lost and authentication got delayed;
    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc48 2016-04-06

    What's new in 6.35rc48 (2016-Apr-05 15:10):

    *) wireless-rep - fixed latency issues with Intel wireless clients;
    *) mipsbe - (excluding RB4xx and CRS series) fixed rare ethernet tx buffer corruption;
    *) dhcp6-client - fixed wrong error message;
    *) address-list - fixed crash in low memory situations;
    *) tile - fixed performance regression on switch chip (introduced in 6.33rc18);
    *) tile - fixed l2mtu change (introduced in 6.35rc);
    *) lcd - fixed branding packet logo drawing on startup;
    *) lte - replaced signal-strength with rssi in info command;
    *) nand - fixed reboot loop after upgrade to >v6.35rc43;
    *) ppp - fixed some clients can not connect due to LCP restart;
    *) tool fetch - fixed https cleanup on user stop while handshaking;
    *) winbox - make build with latest lte changes;
    *) hotspot - make video tag work properly on hotspot login.html page
    *) ipsec - fixed crash on policy update;
    *) ppp - fixed ppp crash if lcp packets were lost and authentication got delayed;
    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc47 2016-04-06

    What's new in 6.35rc47 (2016-Apr-05 08:12):

    *) tile - fixed performance regression on switch chip (introduced in 6.33rc18);
    *) tile - fixed l2mtu change (introduced in 6.35rc);
    *) lcd - fixed branding packet logo drawing on startup;
    *) lte - replaced signal-strength with rssi in info command;
    *) nand - fixed reboot loop after upgrade to >v6.35rc43;
    *) ppp - fixed some clients can not connect due to LCP restart;
    *) tool fetch - fixed https cleanup on user stop while handshaking;
    *) winbox - make build with latest lte changes;
    *) wireless-rep - fixed latency issues with Intel 2.4GHz wireless clients;
    *) hotspot - make video tag work properly on hotspot login.html page
    *) ipsec - fixed crash on policy update;
    *) ppp - fixed ppp crash if lcp packets were lost and authentication got delayed;
    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc46 2016-04-05

    What's new in 6.35rc46 (2016-Apr-05 08:12):

    *) lcd - fixed branding packet logo drawing on startup;
    *) lte - replaced signal-strength with rssi in info command;
    *) nand - fixed reboot loop after upgrade to >v6.35rc43;
    *) ppp - fixed some clients can not connect due to LCP restart;
    *) tool fetch - fixed https cleanup on user stop while handshaking;
    *) winbox - make build with latest lte changes;
    *) wireless-rep - fixed latency issues with Intel 2.4GHz wireless clients;
    *) hotspot - make video tag work properly on hotspot login.html page
    *) ipsec - fixed crash on policy update;
    *) ppp - fixed ppp crash if lcp packets were lost and authentication got delayed;
    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-del