ATTENTION, DISASTER! V.6.17

On Saturday, update all my installation with the version 6.17 and then update the firmware of computers.
The result was in two adjoining cases. They were inaccessible.
Others were falling in these 3 days.
Observed loss of configuration in some cases.
In others, loss of system packages.
I went back to version 6.15 and / or 6.11 and the situation to be the next step
In all the records processed 100% utilization.
With profile shows that the IPSEC service processor takes all.
In some cases, the equipment is made ​​inaccessible.

The RB are: RB411 - RB433 - RB493 - RBMetal - RB1100 - RBSETXTAN

If someone comes up with something, to comment.
Tomorrow I’ll go one by doing cleaning and use flash to all units.

I my network all devices is updated to 6.16 main router to 6.17.
It is RB411AH, RB411, RB411U, RB433AH, RB433GL, Groove, SXTLite and main router x86, for now uptime is between 2 and 3 day I don’t see any problem in my configuration.
OpenVPN bug is solved I have open ticket for months for that bug now is ok, also wireless-fp is solved bug cause kernel failure for now I see only improvements and not forget IP Cloud now can update external address nice :smiley: waiting for this also.

jrecabeitia, so far you are the first with such bigger issues. please give us more info, maybe all of these devices have something in common? some specific configuration or feature that you use?

My 2011UAS-2HnD upgraded fine to 6.16 and then failed on upgrade (shortly after) to 6.17 with a message about loading kernel from NAND and then hanging. I got it going again using netinstall. No supout unfortunately.

I’m still using 6.17 from the day it come out on 30 devices and more of my production environment (various models), no one single problem till now.

Normis, I’ll go by.
Upgrade Device:
We went from 6.15 to 6.17
Most teams tear well, only in 3 I am forced to have to do a netinstall. Estimate that could be a current problem. (then discard it, because one of those teams is with UPS and surge)
In yesterday morning I see the fall of another link. The procedure is to power cycle the computer and starts. A half hour stops working and is inaccessible. Use netinstall to retrieve it.
At noon I observed 3 other team more than stop working and I have the same problem. Before this I resolve to return back to version 6.15

Device Recovery:
One of the problems identified is that when returning from version 6.17 to 6.15
the basic configuration or default ipsec is lost. This is what causes the saturation of the processor at 100%. Disabling packet recovers.
Resetting equipment and reconfiguring hand, are well in 6.15
Most of the equipment used for backbone. Its configuration is basic.
Bridge between ether and wlan
ip on the bridge
routering ospf, only net the bridge.
No other configuration.
In some cases, they have lost the installation packages and no choice but to use netinstall to recover the computer.
I must say that is the first time in years that passed me something.

Right now, I’m resetting each of the teams to reconfigure hand and I fear that finds a bug or error in the teams that make malfunction. It is hard work since I have an extensive network of more than 60km and you have to go to each tower.
Thank you!

I’m doing thtat on close link (and I’m STILL to not have problems), but you use just come out version on 60Km link?

It’s YOUR fault.

MikroTik has maded one error? Ok, admitting that, is clear, but the bigger error is made from you!
Test the new version on closer device is better than upgrade entire remote network…

No link 60Km.
My network has a length of 60 km from end to end, on geographic area.
The longest link I have is 32Km and most are in the 12Km.

My problem is two days after upgrading CCR1036 I’m locked - ERR: Wrong username or password.
Services and routing still works, but I can’t access neither by (mac)telnet nor ssh nor winbox…
ps. update/crosspost (sorry) here http://forum.mikrotik.com/viewtopic.php?f=1&t=86998&p=438341#p438341

Try access with no password. Maybe it is deleted

@jrecabeitia

I have the same issue after upgrade to 6.17, two SXTLite5 dead. Rest of my devices downgraded to 6.15 with CPU 100% :frowning:
Look at:
http://forum.mikrotik.com/t/dead-sxt-lite5/79226/9

Regards

If the micro processor is 100% remove the ipsec package.
Reincie and should function normally.

actually go into the “/tool profile” menu to check what is eating the CPU. Maybe it was IPsec for you, but something else for the others?

Normis, returning back at 100% of my devices, the IPsec packet takes all the processor.
What I could see is that to turn back the default setting disappears.
I believe that’s the cause, but I can not verify.
What I can say is working out down the IPsec packet

Normis,
Removing the IPsec packet only solves a problem that occurs when you turn back.
It does not solve the problem that gives rise to this issue, which remains a big question.

Hi,

/tool profile showing that ipsec is eating CPU

I run some tests and this is correct, default setting helps.

How can I remove IPsec package?

List of packages:

/system package print
Flags: X - disabled 
 #   NAME                     VERSION                     SCHEDULED              
 0   routeros-mipsbe          6.15                                               
 1   system                   6.15                                               
 2 X wireless-fp              6.15                                               
 3 X ipv6                     6.15                                               
 4   wireless                 6.15                                               
 5   hotspot                  6.15                                               
 6   dhcp                     6.15                                               
 7   mpls                     6.15                                               
 8   routing                  6.15                                               
 9   ppp                      6.15                                               
10   security                 6.15                                               
11   advanced-tools           6.15

/system/packages
mark ipsec
disable
reboot

What the hell you write? ipsec are not one single package which you can disable.

I don’t have ipsec package.

There never was an ‘ipsec’ package. Ipsec is part of ‘security’ package.