*) bridge - default protocol-mode changed to RSTP for new bridges,
fixed bridge mac address changing when port (with lowest mac address) goes down
*) userman - improve startup time;
*) sstp client - support server name verification from certificate;
*) wireless - improved 11n and nv2 stability;
*) dhcp client - support interfaces in bridge;
*) dhcp - parse decimal strings and IP addreses in options value;
*) bgp - don’t show community ‘internet’ in BGP advertisements;
*) ipsec - enable hardware acceleration for aes-cbc + md5|sha1|sha256 aead on tilera cpus;
*) ospf - fixed checksum calculation for OSPFv3 AS-external-LSAs;
*) default configuration - changed dhcp server lease time to 10 minutes;
*) fixed port isolation on CRSs (bug introduced in v6.6);
*) smb - added support for SMB 2.002
*) timezone information updated;
*) ppp - fixed ppp bridging (did not work since v6.6);
*) improved speed of PPP, PPPoE, PPTP & L2TP on multicore routers;
*) address-list - fix crash when adding two identical address list entries (not allowed any more);
*) fixed multicast forwarding on CCRs;
*) firewall - improved address-type matcher, and added it for ipv6 aswell;
If I’m reading correctly, from now on any bridge I create will have RSTP enabled by default?
If that’s the case, I certainly hope the priority has been defaulted to F000 than as well. I can see problems with this implementation on xSTP enabled networks. IMO, this was fine the way it was before and should be a setting we choose to enable.
*) ppp - fixed ppp bridging (did not work since v6.6);
This is now working for me again. It would be nice however if the PPP interface added to the bridge didn’t show as ‘(unknown)’ in /interface bridge ports however. This did used to work a few version back.
GUI support for IPsec users, mode-cfg and policy groups/templates seems to have been added to both WinBox and WebFig. Why is it not mentioned in the ChangeLog?
I have updated our CCR1036-12G-4EM from 6.7 to 6.9.
Al was working fine except for a lot of our VPN tunnels.
The standard ipsec tunnels with AES-256 in phase 2 (proposal) all send packages but did not receive.
After changing from AES-256 to AES-128 they went fine. All SA where correct but only outbound data not inbound.
So I do think there is a bug in the AES-256 implementation.
The other side of the tunnels were no Mikrotik devices but for example a SonicWall SRA 3500.
After changing from AES-256 to AES-128 in Phase 2 things were working OK. Also the tunnels seem much (factor 2x).
There is nothing to stop one thing rather than another does not run from one of the version, I offered here that do not could be Denial of Service thing to develop in.
However, the increase in the cpu, why this version of the RB2011UAS-the 2Hnd-IN for more than a RB951-AN on this.
Nonsense
I do not want to cash out ahead of a new router for a new version if the blow goes just after the
After upgrade SXT 5HnD from 6.7 to 6.9 graph lines (Rx signal/Tx signal )is not rendering at index page.
I have 2 SXT’s, configured in briged mode, but none of them rendering graph lines!
In first SXT with wireless bridge mode, there is no ‘wireless’ section at all.
Upgraded the following routerboards to 6.9 + firmware (a few of each): rb751u-2hnd, rb751g-2hnd, rb711u-2hnd, rb951g-2hnd, rb800, rb493g, rb2011uas-rm, rb450g
6.9 installed smoothly on the Dell 1950, with LSI / Perc6i (2 x 15K drives) and onboard Broadcom NIC’s. I have not been able to thoroughly test many functions, but so far it looks very good. I put a 1GB file on it, and then FTP downloaded at 650 Mb/s.
The only odd behaviour I’ve noticed so far, is that it will not reboot on command, via winbox.