6.31 released

What’s new in 6.31 (2015-Aug-14 15:42):

*) check-for-update - added ability to select versions channel to check
(bugfix, current, RC or development)
*) demo mode of Cloud Hosted Router (CHR) added
*) chr - added x86_64 image for use in virtual environments
*) chr - added support for VMware SCSI virtual disks
*) chr - added support for VMware vmxnet3 network card
*) chr - added support for HyperV SCSI disks
*) chr - added support for HyperV Ethernet interfaces
*) chr - added support for virtio disks
*) fixed occasional interface resetting on CRS switches
*) fixed ethernet stopping on RB NetMetal / SXTG-5HPacD 10Mbit and 100Mbit links
*) ipsec - fixed crash in when gcm encryption was used
*) ipsec - allow to set peer address as “::/0”
*) ipsec - fixed empty sa-src address on acquire in tun mode
*) ipsec - show proposal info in export ipsec section
*) ipsec - preserve port wildcard when generating policy without port override
*) ipsec - fixed replay window, was accidentally disabled since version 6.30;
*) certificate manager - fixed memory leak
*) ssh - allow host key import/export
*) ssh - use 2048bit RSA host key when strong-crypto enabled
*) ssh - support RSA keys for user authentication
*) conntrack - fixed problem with manual connection removal
*) conntrack - added tcp-max-retrans-timeout and tcp-unacked-timeout
*) wireless - implemented l2mtu update if wireless-cm2 is enabled
*) wireless - improved WMM-PowerSave support in wireless-cm2 package
*) mpls - better multicore support for VPLS ingress/egress
*) ovpn - better multicore support for interface initialization/authentication/creation.
*) mesh - performance improvement
*) pptp & l2tp - fixed problem where android client could not connect if both dns names were not provided (was broken since v6.30)
*) user-manager - fixed username was not shown in /tool user-manager user
*) user-manager - fixed zoom for user-manager homepage when mobile devices used
*) winbox - restrict change dynamic interface fields
*) winbox - also hide passphrase in CAPsMAN with “Hide Password”
*) winbox - restrict reversed ranges in dst-port under firewall
*) quickset - fixed HomeAP mode
*) lcd - added LCD package for all architectures (for serial port LCD modules)
*) lcd - fixed crash (and 100% cpu usage) when interface gets removed from “stats-all” screen
*) tool fetch - fixed incomplete ftp download
*) tool fetch - don’t trim [t]ftp leading slashes
*) proxy - adjust time according to time-zone settings in proxy cache contents.
*) bridge fastpath - fixed updating bridge FDB on receive (could cause TX traffic flooding on all bridge ports)
*) bonding fastpath - fixed possible crash when bonding master was also a bridge port
*) route - fixed crash on removing route that was aggregated
*) romon - fixed crash on SACKed tx segments
*) lte - improved modem identification to better support multiple identical modems
*) snmp - fixed system scripts table
*) traffic flow - fixed dynamic input/output interface reporting
*) ipv6 dhcp-relay - fixed problem loading configuration

known issue:
*) Dynamic DNS servers can disappear when “allow-remote-requests” are not enabled

Thx for fix this problem on 6.31
*) proxy - adjust time according to time-zone settings in proxy cache contents.
I have tested it and is working correctly.

Bigfoot

Thanks for the update!

*) conntrack - fixed problem with manual connection removal

Perfect timing, I need to debug an issue this weekend and this was preventing me from doing so.


*) wireless - improved WMM-PowerSave support in wireless-cm2 package

Does this need to be enabled in any way?


Have bridges been fixed on the CHR?

@normis, Thanks for the announcement, I just opened the CCR1009 I got from you after my presentation at the MUM and I’ll test 6.31 ASAP.

I’ll leave my CRS with the reliable 6.28 as it’s serving some clients after I test with CCR, I’ll switch and let you know.

Finally it’s great to know that the CHR is now available, I’ll test.and share my thoughts on it.

Thumbs up!. Thanks Mikrotik

Thank You ,

i wonder if there is any upcoming updates regarding to hotspot ?? in security specially like preventing Mac cloning

Just upgraded one of my RBs, and I can already point a first (minor) issue:

In Winbox, if you then check for updates again against the “current” channel, you always get “Download” and “Download & Install” buttons, but never “Check for updates”. This would be OK if there was 6.32, but right now, 6.31 is the latest current, so effectively, Winbox is telling me to download and install the release that I already have installed… which it shouldn’t.

After updating to 6.31 on a pair of RB750 routers, I now have Issues with the ovpn connection between them.

The branch office router that connects to the main router will connect enough that I can send ping traffic over it, but as soon as I try to use the connection for useful data such as connecting to a computer on the other side of the connection, I see in the log “ovpn-out1: terminating… - TLS failed”

I don’t know if it is the slightly larger amount of data being transferred that is relating to the issue or what the problem is. It worked well on version 6.27 which we were running before this.

Is anyone else seeing this?

I appreciate any of your help. I currently have a branch office without a useful connection.

If I set Update channel to Bugfix and execute /system package update download, it will download the latest Bugfix, instead of nothing.

On webfig you can see that if you set the channel to bugfix, the proposed update is a downgrade version.

This also seemed wrong to me, if you are already on 6.31, the bug fix channel is 6.31.x

In any case, I upgraded my RB2011 from webfig and it seems fine so far. My TV got the right time for now.

Yes. It should show a message like “no update available”, instead of showing / downloading a previous version.

Except of this, I didn’t find any other problems.

2hrs 22 minutes uptime - stable looks real good :wink:

Not working on my 450g, it restarts every few minutes.
On second router 2011 works fine.

OpenVPN Error:
ovpn,debug,error,l2tp,info,debug,critical,warning: duplicate packet, dropping

any idea about this?
Version 6.30.2 Works fine

Same here, rebooting on 450g, stable on 850g.

This is not acceptable, even at home I could not run a Mikrotik setup without redundancy preferably with different models.

Err, this is why they released a ‘stable, bug-fix branch’ and then the ‘updates’ branch.

Will these firewall fasttrack dummy rules be allowed to be switched off?

You are missing the point here. As was explained before, you should consider “Bugfix only” branch as stable. “Current” is where new features are added first, and (since new features often break existing features in some way) is not initially considered stable.

It is rather good Mikrotik now provides an easy way to switch between bugfix (stable) and current. Whether it should or should not allow redownloading/reinstalling the version that is currently installed on your device, is arguable. I’d rather leave it as it is now.

Upgraded two of my RB450G and both of them run for 15 hours now … no reboots, no issuses… both of them run ipsec, l2tp, ipip, ospf, capsmanv2, about 15 queues and about 60 firewall rules … Also upgraded 850, 2011, 751, 951, 800, 711, 912 and crs125 devices without problems to 6.31.

JF.

RB951G-2ND and RB750G had a NTP client running before the upgrade. After the upgrade, in profiler NTP process was always on 0.5% ( i have waited 10-15 min). After disabling then enabling NTP client, process appears then disappears from profiler after 10-15 seconds (as expected).

I’m missing nothing. If I’m on 6.31 and set it to “bugfix only”, it should NOT download 6.30.2 (we are in the upgrade menu, not downgrad). It should download bugfix updates of the CURRENT INSTALLED release, that would be 6.31.1. So since this version is not available, it shouldn’t download anything.