Changelog 6.47beta49 (testing)
Mikrotik version checkerImportant note!!!
- The Dude server must be updated to monitor v6.46.4 and v6.47beta30+ RouterOS type devices.
- The Dude client must be manually upgraded after upgrading The Dude server.
- Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used.
- The Dude requires "winbox" policy instead of "dude" to monitor v6.46.4 and v6.47beta30+ RouterOS type devices.
⚠️ dns: added client side support for DNS over HTTPS (DoH) (RFC8484)
⚠️ socks: added support for SOCKS5 (RFC 1928)
⚠️ socks: added support for SOCKS5 (RFC 1928)
⚠️ user: enable "winbox" policy for groups with "dude" policy
⚠️ dns: added client side support for DNS over HTTPS (DoH) (RFC8484)
⚠️ socks: added support for SOCKS5 (RFC 1928)
⚠️ user: enable "winbox" policy for groups with "dude" policy
- branding: fixed identity setting from branding package
- branding: properly use HTML files for Hotspot (introduced in v6.47beta)
- bridge: added warning message when port is dynamically added to entry with VLAN range (CLI only)
- bridge: correctly remove disabled MSTI
- bridge: improved hardware offloading enabling/disabling
- capsman: fixed "certificate" parameter updating on CAP
- certificate: disabled CRL usage by default
- certificate: do not use SSL for first CRL update
- chr: added support for file system quiescing
- crs3xx: do not change bridge host ID's when updating host table (introduced in v6.47beta32)
- crs3xx: fixed interface statistics for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices
- crs3xx: fixed traffic forwarding after disabling/enabling bridge hardware offloading for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices
- dhcpv4: added end option (255) validation for both server and client
- dhcpv4-client: improved stability when changing client while still receiving advertisements
- dhcpv6-server: fixed MAC address retrieving from DUID when timestamp is present
- dude: fixed connection to other RouterOS type devices through The Dude agents (introduced in v6.46.4)
- filesystem: fixed NAND memory going into read-only mode or becoming unstable over time
- hotspot: updated splash page design ('/ip hotspot reset-html' required)
- ike1: added error message when specifying "my-id" for XAuth Identity
- ike1: improved stability when performing policy lookup on non-existant peer
- ipsec: control CRL validation with global "use-crl" setting
- ipsec: do full certificate validation for identities with explicit certificate
- lcd: fixed LCD service becoming unavailable on devices without LCD screen
- led: added "dark-mode" functionality for CRS105-5S-FB
- led: fixed minor typo in LED warning message
- lora: added IPv6 support for LoRa packet forwarder
- lora: added value limits for "freq-off" parameter
- lora: properly update source address for packets when routing table is changed
- lte: added support for NEOWAY N720
- lte: fixed "allow-roaming" setting when using LTE network mode on R11e-LTE
- lte: made "mac-address" parameter read-only
- ppp: added support for ZTE MF90
- ppp: fixed minor typo when running "info" command
- proxy: increased minimal free RAM that can not be used for proxy services
- quickset: do not show "SINR" field in Quick Set when there is no data
- quickset: removed "EARFCN" field from Quick Set
- route: improved system stability after reboot with large amount of VLAN interfaces with PPPoE servers attached
- sniffer: fixed minor typo in "host" menu
- snmp: changed "upsEstimatedMinutesRemaining" reported value from seconds to minutes
- ssh: fixed SHA256 user authentication algorithm checking (introduced in v6.46.4)
- supout: added "gps" section to supout files
- switch: made "auto" the default value for "vlan-id" parameter when creating a new static host entry
- system: improved driver loading speed on startup
- system: improved system stability when forwarding traffic from switch chip to CPU (introduced in v6.43)
- traffic-generator: improved statistics reporting
- w60g: fixed link status logging
- w60g: improved rate selection in low traffic conditions
- winbox: added "Options" parameter support for DHCPv6 client and server
- winbox: added "Rate" parameter for switch ACL rules
- winbox: added 160Mhz extension channel support for CAPsMAN
- winbox: added comment support for "Switch->VLAN" menu
- winbox: added support for "Tools->WoL" menu
- winbox: aligned all "IP->Traffic Flow->IPFIX" check boxes in single line (WinBox v3.22 required)
- winbox: allow setting "20/40/80/160Mhz-eeeeeeCe" channel under "Channel Width" parameter
- winbox: allow setting "Primary" parameter for "balance-tlb" bonding interfaces
- winbox: do not show "Revision" parameter under "System/RouterBOARD" menu on devices that have only one revision
- winbox: fixed "ARP" parameter inheritance from "CAPs Configuration" configuration
- winbox: fixed "BGP Origin" value display under "IPv6->Routes" menu
- winbox: fixed "Bands" parameter display for LTE interfaces
- winbox: fixed "DSCP" parameter value setting
- winbox: fixed "Data Rate" checkbox alignment (WinBox v3.22 required)
- winbox: fixed "Frequency" and "Secondary Frequency" parameter inheritance from "CAPs Channel" configuration
- winbox: fixed "Passthr. MAC Address" parameter display "LTE APNs" menu
- winbox: fixed "Switch" menu on CRS354-48P-4S+2Q+
- winbox: fixed "dst-port" unsetting in "IP->Hotspot->Walled Garden" menu
- winbox: fixed automatic "IPv6->Firewall->Address List" table update
- winbox: fixed bonding type interface support for "Switch->Host" table
- winbox: made "none" the default value for "Security Profile" parameter when creating a new "Wirelees->Connect list" entry
- winbox: made "yes" the default value for "Inject Summary LSAs" parameter when creating a new NSSA or STUB area
- winbox: properly show "Hw. Offload Group" value for each interface under "Bridge->Ports" menu
- winbox: renamed "Memory used" to "HDD used" for HDD type under "Tools->Graphing->Resource Graphs"
- winbox: renamed "Routerboard" to "RouterBOARD" under "System/RouterBOARD" menu
- winbox: show "Hardware Offload" parameter for bonding interfaces
- winbox: show "System/RouterBOARD/Mode Button" on devices that have such feature
- winbox: updated icon design
- wireless: added "U-NII-2" support for hAP ac2 and RBwAPGR series devices
- wireless: enabled unicast flood for DHCP traffic on ARM architecture access points
- wireless: fixed default "antenna-gain" setting on SXT 2 and LtAP series devices
- wireless: updated "indonesia4" regulatory domain information
⚠️ socks: added support for SOCKS5 (RFC 1928)
- bonding: improved slave interface MAC address handling
- bonding: prefer primary slave MAC address for bonding interface
- bridge: added logging message when a host MAC address is learned on a different bridge port
- crs3xx: correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices
- crs3xx: fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices
- crs3xx: fixed QSFP+ interface linking for CRS326-24S+2Q+ device (introduced in v6.47beta19)
- crs3xx: improved SFP+ DAC cable initialization for CRS326-24S+2Q+ device
- crs3xx: improved switch host table updating
- defconf: fixed "no-defaults=yes" applying default configuration (introduced in v6.47beta)
- defconf: fixed default configuration initialization if power loss occurred during the process
- dhcpv6-client: improved error logging when when renewed address differs
- discovery: do not send CDP and LLDP packets on interfaces that does not have MAC address
- discovery: do not send discovery packets on inactive bonding slave interfaces
- discovery: do not send discovery packets on interfaces that are blocked by STP
- disk: improved recently created file survival after reboots
- dns: added support for exclusive dynamic DNS server usage from IPsec
- dot1x: added "radius-mac-format" parameter (CLI only)
- dot1x: added hex value support for RADIUS switch rules
- dot1x: added range "dst-port" support for RADIUS switch rules
- dot1x: added support for lower case "mac-auth" RADIUS formats
- dot1x: fixed "reject-vlan-id" value range
- dot1x: fixed dynamically created switch rule removal when client disconnects
- dot1x: fixed port blocking when interface changes state from disabled to enabled
- dot1x: improved debug logging output to "dot1x" topic
- dot1x: improved value validation for dynamically created switch rules
- fetch: fixed "User-Agent" usage if provided by "http-header-field"
- health: added "gauges" submenu with SNMP OID reporting
- ike1: added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes
- ike2: added support for "INTERNAL_DNS_DOMAIN" payload attribute
- ipsec: added "split-dns" parameter support for mode configuration (CLI only)
- ipsec: added "use-responder-dns" parameter support (CLI only)
- ipsec: fixed minor spelling mistake in logs
- ipsec: improved IPsec service stability when receiving bogus packets
- lte: added support for multiple passthrough APN configuration
- lte: do not allow running "scan" on R11e-4G
- lte: fixed "band" value setting when configuration is reset on R11e-4G
- lte: fixed multiple APN reactivation after deactivation by operator
- lte: show "phy-cellid" value only in LTE mode
- netinstall: removed "Flashfig" from Netinstall
- netinstall: removed "Make Floppy" from Netinstall
- netinstall: signed netinstall.exe with Digital Signature
- quickset: removed "LTE band" setting from Quick Set
- quickset: show "Antenna Gain" setting on devices without built-in antennas
- quickset: use "station-wds" mode when connecting to AP with RouterOS flag
- routing: improved IGMP-Proxy service stability when receiving bogus packets
- sniffer: allow setting port for "streaming-server"
- snmp: added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB
- snmp: fixed "dot1dBasePort" index offset for BRIDGE-MIB
- snmp: improved OID policy checking and error reporting on "set" command
- snmp: improved stability when polling MAC address related OID
- supout: added "dot1x" section to supout files
- supout: improved PoE-out information reporting
- supout: improved UPS information reporting
- system: correctly handle Generic Receive Offloading (GRO) for MPLS traffic
- tr069-client: removed warning log message when not using HTTPS
- traceroute: improved stability when invalid packet is received
- traffic-flow: added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9
- traffic-flow: added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9
- upgrade: fixed space handling in package file names
- ups: improved compatibility with APC Smart UPS 1000 and 1500
- w60g: improved stability after multiple disconnections
- w60g: use "arp" and "mtu" parameters from master interface when creating a new station
- webfig: updated icon design
- winbox: added "auto-erase" option to "Tool/SMS" menu
- winbox: added support for inline bar graphs for LTE signal values
- winbox: removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic"
- winbox: updated icon design
- wireless: allow using "russia4" regulatory domain on RU locked devices
- www: added "tls-version" parameter in "IP->Services" menu (CLI only)
Important note!!!
- The Dude server must be updated to monitor 6.46.4 and v6.47beta30+ RouterOS type devices.
- The Dude client must be manually upgraded after upgrading The Dude server.
- To get RouterOS data from the devices, The Dude now requires RouterOS to be 6.46.4 or v6.47beta30+.
- arm: improved watchdog and kernel panic reporting in log after reboots on RB3011 and IPQ4018/IPQ4019 devices ("/system routerboard upgrade" required)
- branding: allow forcing configuration script as default configuration (new branding packet required)
- branding: fixed "company-url" and "router-default-name" survival after system upgrade
- branding: fixed WEB HTML page survival after system upgrade
- certificate: fixed certificate verification when flushing CRL's
- chr: fixed graceful shutdown execution on Hyper-V (introduced in v6.46)
- console: fixed script with "dont-require-permissions=yes" execution without sufficient permissions
- crs3xx: fixed frame forwarding after disabling/enabling bridge hardware offloading for CRS354-48G-4S+2Q+ device
- defconf: added welcome note with common first steps for new users
- dude: updated The Dude to use new style authentication method
- health: fixed maximum SFP temperature reading under '/system health' menu
- ike2: fixed DHCP Inform package handling when received on PPPoE interface
- lte: added interface name prefix for logging events
- lte: added "phy-cellid" value support for R11e-LTE-US
- lte: do not allow using empty APN Profile names
- lte: improved all APN session activation after disconnect on R11e-LTE
- lte: use APN from network when blank APN used on R11e-4G
- snmp: fixed "routeros-version" value returning from registration table
- snmp: fixed UPS battery voltage value scaling
- ssh: added support for RSA keys with SHA256 hash (RFC8332)
- system: improved system stability when receiving/sending TCP traffic on multicore devices
- telnet: improved telnet compatibility with other client implementations
- user-manager: fixed signup enabling (introduced in v6.46)
- webfig: added default configuration confirmation window to WebFig
- webfig: do not show WebFig menu when opening 'Check For Updates' in Quick Set
- winbox: completely removed old style authentication method
- winbox: fixed "invalid" flag presence under "System/Certificates/CRL" menu
- wireless: improved compatibility for "ETSI" wireless country profile
---