6.33 version released!

6.32.3 has been moved to bugfix channel.

What’s new in 6.33 (2015-Nov-06 12:49):

*) dns - initial fix for situation when dynamic dns servers could disappear;
*) winbox - dropped support for winbox v3.0beta and v3.0rc (use winbox v3.0);
*) dhcpv6 - various improvement and fixes for dhcp-pd client and ippool6;
*) defconf - fixed rare situation where configuration was only partially loaded;
*) net - fix possible never ending loop when bad CDP discovery packet is received;
*) log - make default disk file name to reside in flash dir if it exists;
*) romon - change port list to be not ordered in export;
*) capsman - limit number of simultaneous DTLS handshakes;
*) capsman - fixed memory leak on CAP joining CAPsMAN when ssld is used;
*) winbox - added allow-fast-path to eoip, gre & ipip;
*) winbox - do not show power-cycle properties on non poe ports;
*) l2tp: implemented PPPoE over L2TP in LNS mode, RFC3817;
*) webfig - some of the setting were shifted to the right;
*) packages - allow to reinstall from bundle to separate packages & vice versa;
*) packages - prefer out of bundle packages when both of them are installed;
*) packages - fix a problem of upgrading bundle package to non bundled ones;
*) ipsec - force flow cache validation once in 1h;
*) winbox - make sure that all setting names get shown in full;
*) winbox - added poe power-cycle-ping settings to ethernet interfaces;
*) ppp - handle properly case were ppp client is given same address for local & remote end;
*) winbox - added vlan-mode & vlan-id to virtual-ap interface;
*) winbox - added timeout column to ipv6 address lists;
*) winbox - show SFP Tx/Rx Power properly;
*) winbox - added min-links to bonding interface;
*) winbox - do not show health menu on RB951Ui-2HnD;
*) winbox - added support for Login-Timeout & MAC-Auth-Mode in hotspot;
*) cerm - added option to disable crl download in ‘/certificate settings’;
*) winbox - make user ssh key import work again;
*) webfig - make “Copy to Access List” work in CAPsMAN Registration Table;
*) userman - fix report generation problem which could result in some users being skipped from it;
*) winbox - fix to allow cpu-port as mirror-target
*) proxy - error.html parsing enhancement to improve performance
*) CCR1072 - improve ether1 performance under heavy load
*) routerboard - indicate RouterBOOT type in /system routerboard print;
*) mpls - properly use mpls mtu for routes;
*) cerm - fix key description for signed certificates;
*) trafflow - report flow addresses in v1 and v5 without NAT awareness;
*) hotspot - add mac-auth-mode setting for mac-as-passwd option;
*) hotspot - add login-timeout setting to force login for unauth hosts;
*) auto-upgrade - fixed auto upgrade for smipsbe;
*) dns - do not create duplicate entries for same dynamic dns server addresses;
*) ipsec - fix set on multiple policies which could result in adding non existent dynamic policies to the list;
*) email - allow server to be specified as fqdn which is resolved on each send;
*) fastpath - eoip,gre,ipip tunnels support fastpath (new per tunnel setting “allow-fast-path”);
*) ppp, pptp, l2tp, pppoe - fix ppp compression related crashes;
*) cerm - also accept downloaded CRLs in PEM format;
*) userman - added ‘history clear’ to allow flushing undo history, which may take up significant amount of memory for huge databases with hundreds of users;
*) health - fix voltage for CRS109, CRS112 and CRS210 if powered from external adapter;
*) userman - added phone number support to signup form;
*) ip pool6 - try to acquire the same prefix if info matches recently freed;
*) ipsec - fix transport mode ph2 ID ports when policy selects specific ip protocol on initiator;
*) ipsec - use local-address for phase 1 matching and initiation;
*) route - fixed crash on removing route that was aggregated;
*) ipsec - fix replay window, was accidentally disabled since version 6.30;
*) ssh - allow host key import/export;
*) ssh - use 2048bit RSA host key when strong-crypto enabled;
*) ssh - support RSA keys for user authentication;
*) wlan - improved WMM-PowerSave support in wireless-cm2 package;
*) pptp & l2tp - fixed problem where android client could not connect if both dns names were not provided (was broken since v6.30);
*) auto-upgrade - added ability to select which versions to select when upgrading;
*) quickset - fixed HomeAP mode;
*) lte - improved modem identification to better support multiple identical modems;
*) snmp - fix system scripts table;
*) tunnels - eoip,eoipv6,gre,gre6,ipip,ipipv6,6to4 tunnels now support dns name as remote address;
*) fastpath - active mac-winbox or mac-telnet session no longer suspends fastpath;
*) fastpath - added per interface fastpath counters;
*) fastpath - added trafflow support in basic ipv4 and fasttrack ipv4 fastpath;
*) ppp - added on-up & on-down scripts to ppp profile;
*) winbox - allow to specify dns name in all the tunnels;
*) pppoe - added support for MTU > 1492 on PPPoE;
*) cerm - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
*) ppp-client - added default channels for Alcatel OneTouch L100V;
*) defconf - fix for boards that had bridge with only wlan ports;
*) ovpn: support OpenWRT ovpn clients (or any other with enable-small option enabled);
*) cerm - use certificate file name for imported cert name;
*) fetch - fixed error message when error code 200 was received;
*) cerm - rebuild crl for local ca if crl file does not exist;
*) winbox - make directed broadcasts work for neighbor discovery;
*) upnp: automatically adjust mappings to new external ip change;
*) ppp - added ppp interface to upnp internals/externals if requested;
*) ppp - when adding ipv6 default route use user provided distance;
*) userman - allow to correctly enable CoA on router;
*) cerm - show crl nextupdate time;
*) ppp - added CoA support to PPPoE, PPTP & L2TP (Mikrotik-Recv-Limit, Mikrotik-Xmit-Limit, Mikrotik-Rate-Limit, Ascend-Data-Rate, Ascend-XMit-Rate, Session-Timeout);
*) ppp - added new option under “ppp aaa” - “use-circuit-id-in-nas-port-id”;
*) userman - refresh active sessions/users view dynamically;
*) package - added version tag and show everywhere alongside of version number;
*) wlan - improved 802.11 protocol single connection TCP performance for ac chipset with cm2 package.

“hotspot - add mac-auth-mode setting for mac-as-passwd option”
so what exactly does this? why is different from ip binding?

I am running 6.33rc14 on a RB711GA-5HnD. I try to to winbox autoupdate on the “Current” channel. I’m told that the latest version is 6.33 as expected. I click on either download or download & install. In either case nothing gets downloaded and the message at the bottom of the winbox “check for updates” window says: “New version is available”. Why does it not download and update?

The same thing happens on an STX HG5 radio.

In either case if I manually download and then copy to the files folder on the device and reboot the upgrade takes place.

It allows to use mac address both as user-name and password. Old one allowed it be used just as user-name. In some situations it might make things easier for various devices to login if mac login is enabled.

/ip hotspot profile set mac-auth-mode=                
MacAuthMode ::= mac-as-username | mac-as-username-and-password

Did it try to reboot? Reboot manually and see the LOG

so if i understand, if you have a hotspot you can tell a friend to login with his device (laptop,phone,tablet) mac address.

  1. of course he needs to find mac address by going to device settings. right?
  2. its an easy way for hotspot so you dont have to add usernames and passwords each time you want to give away a free access account. right?

@freemannnn

You still need to add that mac-address as user in your hotspot or radius, before that persons phone can get authenticated with system. but essentially, yes. This might be useful for all kind of mobile POS systems and things like that in environment where all devices are behind a hotspot server.

It did not try to reboot. Nothing was in the log. I updated my original post to indicate that I could (and did) manually download and manually upgraded successfully.

*) l2tp: implemented PPPoE over L2TP in LNS mode, RFC3817;

Thank you !!!

*) l2tp: implemented PPPoE over L2TP in LNS mode, RFC3817;
Thanks a million :wink:

WinBox is missing from build.
Ther is an 404 when clicked on winbox link in web interface.

Upgraded our CCR1072 to 6.33 and got an interesting error when trying to login

Looks like WInBox 3.0 is not a release candidate anymore :smiley: Was able to get in after downloading Winbox 3.0.

That’s actually mentioned in ChangeLog…

hotspot - add login-timeout setting to force login for unauth hosts

and what is this doing exactly…

I would want to know that as well! Probably it is not what i need but still it would be interesting to have new features explained. Manual is not updated with info as far as i can see.

M

I found out, Add login-timeout is the timeout a device stays in hosts tab list . After that time it is deleted.

What was broken?

Given the single stream TCP/IP speed up is in wireless-cm2, if we are not using Capsman v1 should we all start using wireless-cm2 instead of wireless-fp by default?

Speaking about that, if I would make my users to use wireless-cm2 on their CPEs, is this package mature enough also on point to multipoint?
The last time I changed my users wireless package was from “wireless” to “wireless-fp”, but 6.30 did this automatically, so I simply upgraded all users to 6.30.
Are there any improvement to nv2 point to multipoint on wireless-cm2?

Thanks!

Really dont see the benefit, but then again, not used to the hotspot yet, but getting there.


M