Mikrotik hap ax3 and updating the OS to version 7.20 does not work with remote access and there is no connection to the Synology cloud

Greetings to all. Tell me what the problem might be-yesterday I updated hAP AX3 to version 7.20, after rebooting there is no connection via remote access ****mynetmane.net and there is no FTP connection to Synology's home storage. Rolling back to version 7.19.6 didn't help, and restoring settings from a backup didn't help either. The hEX gr3 running in the office has also been updated to 7.20. There are no such problems with it. I don't understand what has been changed that the remote access has disappeared. There is nothing in the router logs either. I will be grateful for any ideas...

Hi, you haven't provided any details or configuration. I doubt the information provided will be enough for anyone to help.

Unfortunately, I won't be able to until a few hours later, since access to the router is only possible from the local network.

export compact

[Admin_S@MikroTik hAP AX^3] > /export 
# 2025-10-03 08:51:43 by RouterOS 7.20
# software id = DUKC-5YI2
#
# model = C53UiG+5HPaxD2HPaxD
# serial number = *********
/interface bridge
add name=bridge1
/interface ethernet
set [ find default-name=ether1 ] comment=WAN poe-out=off
set [ find default-name=ether2 ] comment=Ethernet2
set [ find default-name=ether3 ] comment=Ethernet3
set [ find default-name=ether4 ] comment=Ethernet4
set [ find default-name=ether5 ] comment=Ethernet5
/interface pppoe-client
add add-default-route=yes disabled=no interface=ether1 name=pppoe-out1 use-peer-dns=yes user=***
/interface ethernet switch
set 0 cpu-flow-control=yes
/interface list
add name=WAN
add name=LAN
/interface wifi channel
add band=5ghz-ax disabled=no frequency=5180,5320,5240,5725,5850,5955,6115,6295,6575,6815,7015,7100,7155,7195 name=channel1_5 skip-dfs-channels=all width=20/40/80mhz
add band=2ghz-n disabled=no frequency=2412,2432,2452,2472 name=channel2_2.4 skip-dfs-channels=all width=20/40mhz
/interface wifi configuration
add channel=channel2_2.4 country="United States" disabled=no mode=ap name=cfg2_2.4 security.ft=yes ssid=MikroTik_2.4 tx-power=15
/interface wifi datapath
add bridge=bridge1 disabled=no name=datapath1
/interface wifi configuration
add country="United States" datapath=datapath1 datapath.bridge=bridge1 disabled=no mode=ap name=cfg1_5 security.ft=yes ssid=MikroTik_5 tx-power=15
/interface wifi security
add authentication-types=wpa2-psk,wpa3-psk disable-pmkid=no disabled=no encryption="" ft=yes group-encryption=ccmp group-key-update=30m management-protection=allowed name=sec1_5
add authentication-types=wpa-psk,wpa2-psk disable-pmkid=no disabled=no encryption="" ft=no group-encryption=ccmp group-key-update=30m management-protection=disabled name=sec2_2
/interface wifi
# operated by CAP 48:A9:8A:C5:3B:78%bridge1, traffic processing on CAP
add channel=channel2_2.4 configuration=cfg2_2.4 configuration.mode=ap .tx-power=10 datapath=datapath1 disabled=no name=cap-wifi2_2.4 radio-mac=48:A9:8A:C5:3B:7B security=sec2_2 \
    security.ft=yes
# operated by CAP 48:A9:8A:C5:3B:78%bridge1, traffic processing on CAP
add channel=channel1_5 configuration=cfg1_5 configuration.mode=ap .tx-power=10 datapath=datapath1 disabled=no name=cap-wifi2_5 radio-mac=48:A9:8A:C5:3B:7A security=sec1_5 security.ft=\
    yes
# operated by CAP 192.168.1.3, traffic processing on CAP
add channel=channel2_2.4 configuration=cfg2_2.4 configuration.mode=ap datapath=datapath1 disabled=no name=cap-wifi3_2.4 radio-mac=04:F4:1C:4F:F5:E8 security=sec2_2 security.ft=yes
# operated by CAP 192.168.1.3, traffic processing on CAP
add channel=channel1_5 channel.frequency=5180,5320,5240,5725,5850,5955,6115,6295,6575,6815,7015,7100,7155,7195 configuration=cfg1_5 configuration.mode=ap datapath=datapath1 disabled=no \
    name=cap-wifi3_5 radio-mac=04:F4:1C:4F:F5:E7 security=sec1_5 security.ft=yes
set [ find default-name=wifi1 ] channel=channel1_5 configuration=cfg1_5 configuration.mode=ap datapath=datapath1 disabled=no name=wifi1_5 security=sec1_5 security.ft=yes
set [ find default-name=wifi2 ] channel=channel2_2.4 configuration=cfg2_2.4 configuration.mode=ap datapath=datapath1 disabled=no name=wifi2_2.4 security=sec2_2 security.ft=yes
/ip pool
add name=dhcp_pool1 ranges=192.168.1.2-192.168.1.60
add name=vpn ranges=192.168.89.2-192.168.89.255
/ip dhcp-server
add add-arp=yes address-pool=dhcp_pool1 interface=bridge1 lease-time=1h name=dhcp1
/ip smb users
set [ find default=yes ] disabled=yes
/ppp profile
set *FFFFFFFE local-address=192.168.89.1 remote-address=vpn
/system logging action
add disk-file-name=usb1/log disk-lines-per-file=2000 name=usb1 target=disk
/certificate settings
set builtin-trust-anchors=not-trusted
/ip smb
set enabled=no
/interface bridge port
add bridge=bridge1 disabled=yes interface=ether1
add bridge=bridge1 interface=ether2
add bridge=bridge1 interface=ether3
add bridge=bridge1 interface=ether4
add bridge=bridge1 interface=ether5
add bridge=bridge1 interface=wifi1_5
add bridge=bridge1 interface=wifi2_2.4
/ip firewall connection tracking
set tcp-established-timeout=15m
/interface l2tp-server server
set use-ipsec=yes
/interface list member
add interface=bridge1 list=LAN
add interface=pppoe-out1 list=WAN
/interface ovpn-server server
add mac-address=FE:EB:58:69:29:03 name=ovpn-server1
/interface wifi access-list
add action=accept comment="Honor magic 7 Pro" disabled=no interface=any mac-address=28:44:F4:8A:17:2B
add action=accept comment="Yandex Station 1" disabled=no interface=any mac-address=B8:87:6E:83:41:00
add action=accept comment="Polaris PWK 1725CGLD" disabled=no interface=any mac-address=82:64:6F:A9:2D:8F
add action=accept comment="Lamp 1" disabled=no interface=cap-wifi2_2.4 mac-address=38:A5:C9:C3:45:9C
add action=accept comment="Lamp 2" disabled=no interface=cap-wifi2_2.4 mac-address=A0:92:08:37:8E:55
add action=accept comment="Grundig TV" disabled=no interface=cap-wifi3_5 mac-address=BC:6B:FF:D8:74:E3
add action=accept comment="HONOR Choice Robot Cleaner R2+" disabled=no interface=any mac-address=20:67:E0:76:A8:9C
add action=accept comment="Rozetka Smart Life" disabled=no interface=any mac-address=C4:82:E1:2C:93:AC
add action=accept comment="Yandex Station 2" disabled=no interface=any mac-address=3C:0B:4F:E6:A7:B4
add action=accept comment="Xiaomi Mi Box S Gen 2" disabled=no interface=any mac-address=4C:31:2D:ED:85:FB
add action=accept comment="OnePlus Nord CE 2 Lite 5G" disabled=no interface=any mac-address=48:74:12:E6:27:5D
add action=accept comment="Realme C25S" disabled=no interface=any mac-address=E4:B5:03:2F:A9:EF
add action=accept comment="Lenovo pad" disabled=no interface=any mac-address=CC:07:E4:34:68:D7
add action=accept comment="Notebook MSI" disabled=no interface=any mac-address=48:5D:60:66:34:C6
add action=accept comment="OnePlus 13 \D2\E0\ED\E5\F7\EA\E0 " disabled=no interface=any mac-address=7C:F0:E5:5B:A5:95
add action=accept comment="My comp (WIFI)" disabled=no interface=any mac-address=DC:97:BA:5D:54:35
add action=accept comment="Xiaomi Camera" disabled=no interface=cap-wifi3_5 mac-address=50:7B:91:22:8D:0E
add action=accept comment=Zont disabled=no interface=any mac-address=EC:64:C9:8D:05:1C
add action=accept comment=Olga_Iphone disabled=no interface=any mac-address=2A:AC:97:1D:FF:5B
add action=accept comment="\C6\E5\ED\FE\EB\FC\EA\E0 \EF\EB\E0\ED\F8\E5\F2" disabled=no interface=any mac-address=24:E9:CA:30:B7:79
add action=accept comment=TP-Link_Adapter disabled=no interface=any mac-address=90:F6:52:12:B7:D4
add action=accept comment="Samsung \C6\E5\ED\FE\EB\FC\EA\E0" disabled=no interface=any mac-address=3C:31:8A:48:05:69
add action=reject comment="Blocking access to the WIFI network" disabled=yes interface=any
/interface wifi capsman
set ca-certificate=auto certificate=auto enabled=yes package-path="" require-peer-certificate=no upgrade-policy=require-same-version
/interface wifi provisioning
add action=create-enabled disabled=no master-configuration=cfg2_2.4 name-format=cAP_2_2.4 radio-mac=00:00:00:00:00:00 supported-bands=2ghz-n
add action=create-enabled disabled=no master-configuration=cfg1_5 name-format=cAP_1_5 radio-mac=00:00:00:00:00:00 supported-bands=5ghz-ax
/ip address
add address=192.168.1.1/24 interface=bridge1 network=192.168.1.0
/ip cloud
set ddns-enabled=yes ddns-update-interval=1h
/ip dhcp-server lease
add address=192.168.1.12 client-id=1:48:5d:60:66:34:c6 comment="MSI notebook" mac-address=48:5D:60:66:34:C6 server=dhcp1
add address=192.168.1.16 client-id=1:0:11:32:1a:28:cb comment="Synology DS 212J" mac-address=00:11:32:1A:28:CB server=dhcp1
add address=192.168.1.18 client-id=1:b4:52:7d:68:d0:1b comment="Sony Xperia Z" mac-address=B4:52:7D:68:D0:1B server=dhcp1
add address=192.168.1.19 client-id=1:40:61:86:bb:db:38 comment="MSI \ED\EE\F3\F2 (LAN)" mac-address=40:61:86:BB:DB:38 server=dhcp1
add address=192.168.1.21 client-id=1:48:3f:e9:66:62:eb comment="Huawei mate 20X" mac-address=48:3F:E9:66:62:EB server=dhcp1
add address=192.168.1.14 client-id=1:d4:8a:3b:5:a1:59 comment="Xiaomi Mi Box S Gen 1" mac-address=D4:8A:3B:05:A1:59 server=dhcp1
add address=192.168.1.23 client-id=1:f8:e4:3b:c7:dd:b5 comment="Xiaomi Mi Box S (USB-LAN Adapter)" mac-address=F8:E4:3B:C7:DD:B5 server=dhcp1
add address=192.168.1.25 comment=Lamp_2 mac-address=A0:92:08:37:8E:55 server=dhcp1
add address=192.168.1.17 client-id=1:e8:48:b8:f:96:f0 comment="TP-Link Smart Swith" mac-address=E8:48:B8:0F:96:F0 server=dhcp1
add address=192.168.1.24 client-id=ff:6e:83:41:0:0:1:0:1:c7:92:bc:88:b8:87:6e:83:41:0 comment="Yandex Station 1" mac-address=B8:87:6E:83:41:00 server=dhcp1
add address=192.168.1.29 comment="Polaris PWK 1725CGLD" mac-address=82:64:6F:A9:2D:8F server=dhcp1
add address=192.168.1.9 comment="Rozetka Smart life" mac-address=C4:82:E1:2C:93:AC server=dhcp1
add address=192.168.1.7 client-id=1:bc:6b:ff:d8:74:e3 comment="Grundig TV (WI-FI)" mac-address=BC:6B:FF:D8:74:E3 server=dhcp1
add address=192.168.1.2 client-id=1:48:a9:8a:c5:3b:78 comment="Mikrotik cAP AX" mac-address=48:A9:8A:C5:3B:78 server=dhcp1 use-src-mac=yes
add address=192.168.1.28 comment="HONOR Choice Robot Cleaner R2 Plus " mac-address=20:67:E0:76:A8:9C server=dhcp1
add address=192.168.1.6 client-id=ff:4f:e6:a7:b4:0:1:0:1:c7:92:bc:86:3c:b:5f:e6:a7:b4 comment="Yandex Station 2" mac-address=3C:0B:4F:E6:A7:B4 server=dhcp1
add address=192.168.1.8 client-id=1:4c:31:2d:ed:85:fb comment="Xiaomi Mi Box S Gen 2" mac-address=4C:31:2D:ED:85:FB server=dhcp1
add address=192.168.1.22 client-id=1:e4:b5:3:2f:a9:ef comment="Realme C25S" mac-address=E4:B5:03:2F:A9:EF server=dhcp1
add address=192.168.1.15 client-id=1:48:74:12:e6:27:5d comment="OnePlus Nord CE 2 Lite 5G" mac-address=48:74:12:E6:27:5D server=dhcp1
add address=192.168.1.30 comment="Lenovo pad" mac-address=CC:07:E4:34:68:D7 server=dhcp1
add address=192.168.1.13 client-id=1:7c:f0:e5:5b:a5:95 comment="OnePlus 13 \D2\E0\ED\E5\F7\EA\E0 " mac-address=7C:F0:E5:5B:A5:95 server=dhcp1
add address=192.168.1.5 client-id=1:28:44:f4:8a:17:2b comment="Honor magic 7 Pro" mac-address=28:44:F4:8A:17:2B server=dhcp1
add address=192.168.1.31 client-id=1:ec:64:c9:8d:5:1c comment="ZONT " mac-address=EC:64:C9:8D:05:1C server=dhcp1
add address=192.168.1.20 client-id=1:50:7b:91:22:8d:e comment="\CA\E0\EC\E5\F0\E0 Xiaomi" mac-address=50:7B:91:22:8D:0E server=dhcp1
add address=192.168.1.10 client-id=1:dc:97:ba:5d:54:35 comment="My comp (WIFI)" mac-address=DC:97:BA:5D:54:35 server=dhcp1
add address=192.168.1.27 client-id=1:0:11:e1:ac:91:76 comment="Grundig TV (LAN)" mac-address=00:11:E1:AC:91:76 server=dhcp1
add address=192.168.1.32 client-id=1:2a:ac:97:1d:ff:5b comment=Olga_Iphone mac-address=2A:AC:97:1D:FF:5B server=dhcp1
add address=192.168.1.33 client-id=1:24:e9:ca:30:b7:79 comment="\C6\E5\ED\FE\EB\FC\EA\E0 \EF\EB\E0\ED\F8\E5\F2" mac-address=24:E9:CA:30:B7:79 server=dhcp1
add address=192.168.1.26 comment="Lamp 1" mac-address=38:A5:C9:C3:45:9C server=dhcp1
add address=192.168.1.4 client-id=1:90:f6:52:12:b7:d4 comment=TP-Link_adapter mac-address=90:F6:52:12:B7:D4 server=dhcp1
add address=192.168.1.11 client-id=1:b8:69:f4:1b:9e:4a comment="MikroTik mAP Lite" mac-address=B8:69:F4:1B:9E:4A server=dhcp1
add address=192.168.1.34 client-id=1:3c:31:8a:48:5:69 comment="Samsung_\C6\E5\ED\FE\EB\FC\EA\E0" mac-address=3C:31:8A:48:05:69 server=dhcp1
add address=192.168.1.3 client-id=1:4:f4:1c:4f:f5:e2 comment=MikroTik_AX^2 mac-address=04:F4:1C:4F:F5:E2 server=dhcp1
/ip dhcp-server network
add address=192.168.1.0/24 gateway=192.168.1.1 ntp-server=192.168.1.1
/ip dns
set allow-remote-requests=yes cache-max-ttl=1d
/ip firewall filter
add action=fasttrack-connection chain=forward comment="FastTrack Connection" connection-state=established,related hw-offload=yes
add action=fasttrack-connection chain=forward hw-offload=yes in-interface=bridge1 out-interface=pppoe-out1
add action=accept chain=input comment="Allow IGMP" in-interface=pppoe-out1 protocol=igmp
add action=accept chain=forward comment="IPTV UDP forwarding" disabled=yes dst-port=1234 protocol=udp
add action=drop chain=input comment="Drop hackers" disabled=yes in-interface-list=WAN src-address-list=BlackList
add action=drop chain=input disabled=yes dst-port=53 in-interface=ether1 protocol=udp src-address-list="dns spoofing"
add action=drop chain=input comment="drop ftp brute forcers" disabled=yes dst-port=21,55536-55537 protocol=tcp src-address-list=ftp_blacklist
add action=drop chain=input disabled=yes src-address-list="Scanner Port"
add action=accept chain=input protocol=icmp
add action=accept chain=input connection-state=established
add action=accept chain=input connection-state=related
add action=accept chain=input comment="Dostup snarugy" dst-port=8291 protocol=tcp
add action=accept chain=input comment="allow IPsec NAT" dst-port=4500 protocol=udp
add action=accept chain=input comment="allow IKE" dst-port=500 protocol=udp
add action=accept chain=input comment="allow l2tp" dst-port=1701 protocol=udp
add action=accept chain=input comment="allow pptp" dst-port=1723 protocol=tcp
add action=accept chain=input comment="allow sstp" dst-port=443 protocol=tcp
add action=accept chain=input connection-state=established,related
add action=accept chain=forward connection-state=established,related
add action=accept chain=input in-interface=pppoe-out1 limit=50/5s,2:packet protocol=icmp
add action=accept chain=forward dst-port=80 in-interface=pppoe-out1 protocol=tcp
add action=accept chain=output content="530 Login incorrect" dst-limit=1/1m,9,dst-address/1m protocol=tcp
add action=drop chain=forward connection-state=established,related in-interface=pppoe-out1 out-interface=bridge1
add action=drop chain=forward connection-state=invalid
add action=drop chain=input connection-state=invalid
add action=drop chain=forward connection-state=invalid
add action=add-dst-to-address-list address-list=ftp_blacklist address-list-timeout=4w2d chain=output content="530 Login incorrect" protocol=tcp
add action=add-src-to-address-list address-list="dns spoofing" address-list-timeout=2h chain=input dst-port=53 in-interface=pppoe-out1 protocol=udp
add action=add-src-to-address-list address-list=BlackList address-list-timeout=none-dynamic chain=input comment="DDoS DNS" disabled=yes in-interface-list=WAN protocol=udp \
    src-address-list=!DNSServers src-port=53
add action=add-src-to-address-list address-list=BlackList address-list-timeout=none-dynamic chain=input comment="Drop external DNS connections" disabled=yes dst-port=53 \
    in-interface-list=WAN protocol=udp
add action=add-src-to-address-list address-list=BlackList chain=input comment="Drop external DNS connections" dst-port=53 in-interface-list=WAN protocol=tcp
add action=accept chain=input comment=NTP-Allow dst-port=123 protocol=udp
add action=accept chain=input comment=NTP-Allow dst-port=123 protocol=udp
add action=accept chain=input protocol=ipv6-encap
add action=accept chain=output protocol=ipv6-encap
/ip firewall mangle
add action=jump chain=output content="invalid user name or password" disabled=yes jump-target=FB-WB protocol=tcp src-port=8291
add action=add-dst-to-address-list address-list=FB-WB-BAN address-list-timeout=1w chain=FB-WB dst-address-list=FB-WB-3
add action=add-dst-to-address-list address-list=FB-WB-3 address-list-timeout=2m chain=FB-WB dst-address-list=FB-WB-2
add action=add-dst-to-address-list address-list=FB-WB-2 address-list-timeout=1m chain=FB-WB dst-address-list=FB-WB-1
add action=add-dst-to-address-list address-list=FB-WB-1 address-list-timeout=1m chain=FB-WB
/ip firewall nat
add action=masquerade chain=srcnat out-interface=pppoe-out1 out-interface-list=WAN
add action=dst-nat chain=dstnat connection-type=ftp dst-port=55536-55537 in-interface=pppoe-out1 log=yes protocol=tcp to-addresses=192.168.1.16 to-ports=55536-55537
add action=dst-nat chain=dstnat connection-type=ftp dst-port=212 in-interface=pppoe-out1 log=yes protocol=tcp to-addresses=192.168.1.16 to-ports=212
add action=masquerade chain=srcnat comment="masq. vpn traffic" src-address=192.168.89.0/24
/ip firewall raw
add action=drop chain=prerouting src-address-list=FB-WB-BAN
/ip ipsec profile
set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5
/ip service
set ssh disabled=yes
set telnet disabled=yes
set www disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/ip smb shares
set [ find default=yes ] directory=/pub
/ip upnp interfaces
add interface=bridge1 type=internal
add interface=pppoe-out1 type=external
/ipv6 firewall mangle
add action=change-mss chain=forward disabled=yes new-mss=clamp-to-pmtu out-interface=cap-wifi3_5 passthrough=no protocol=tcp tcp-flags=syn tcp-mss=1300-65535
add action=change-mss chain=forward disabled=yes in-interface=cap-wifi3_5 new-mss=clamp-to-pmtu passthrough=no protocol=tcp tcp-flags=syn tcp-mss=1300-65535
/routing igmp-proxy
set quick-leave=yes
/routing igmp-proxy interface
add
/system clock
set time-zone-name=Asia/Yekaterinburg
/system identity
set name="MikroTik hAP AX^3"
/system logging
set 0 action=usb1
set 1 action=usb1
set 2 action=usb1
set 3 action=usb1
/system ntp client
set enabled=yes
/system ntp server
set enabled=yes manycast=yes use-local-clock=yes
/system ntp client servers
add address=ntp0.ntp-servers.net
add address=ntp2.ntp-servers.net
add address=ntp6.ntp-servers.net
/system routerboard settings
set auto-upgrade=yes
/tool romon
set enabled=yes
[Admin_S@MikroTik hAP AX^3] > 

Hi,

please edit your post and use proper code tag < / > to post code.

I'm sorry, I fixed it.

How fixed?

Mine hang too. It does not respond anymore!!! The wifi LED is not lit anymore. hapax3 does not respond on IP. On MAC address it does not accept its default password nor its current user/password!

Why this mikrotik change kills my router???

Fixed the formatting of the provided config. How do you think this topic is related to your issue that you post here? ArtisE provided only vague description of a problem. "remote access has disappeared", "no connection via remote access"; this is very general. I see ovpn server configured, maybe that connection is not working anymore. In 7.20 topic some people reported ovpn issues IIRC. But unlikely that a downgrade to 7.19.6 did no resolve it. Sounds like an external factor.

The problem was that on version 7.20, the service for dynamically updating the ip address assigned by the provider via PPPoE (Ip->Cloud) stopped working, Resetting settings, formatting via Netuninstall and returning to version 7.19.6 and restoring settings from a backup that I do once a month. So far, everything is working. It feels like 7.20 is one big bug.

Yep, it is strange, as the OP reported trying not only to downgrade the RoS version, but also to restore a backup, so it could be a coincidence, and something external happened at the same time as the upgrade.
In any case the posted configuration is the 7.20 one, it would make morte sense to re-downgrade and re-restore the backup and post that configuration, since OVPN is involved and there were other reports of OVPN issues with 7.20, I would try to exclude this possibility and go back to what used to work before.

OK, so it is working now. If I were you I would now also do an /export and perform a diff of the config you posted above and the now working exported config. e.g. using https://text-compare.com/

Shameless plug, just in case, simple spreadsheet:

I think, that this upgrade kills not only remote access. It killed all access to my router. It just went crazy.

Luckily, i made a configuration backup BEFORE the upgrade, and somehow managed to save it. So, i had to reset the configuration using the reset button, and then i got MAC access using the default password, and managed to restore the configuration. Looks like it works back again now. :downcast_face_with_sweat:

I also tried to revive it through the reset button, but it didn't help, so I think you also need to downgrade the version via netuninstall, no one knows (and neither do the developers) how many more problems there are in the new firmware. Apparently, I'll be updating now in 2-3 releases.

Lucky me, the downgrade was not necessary. In contrast, today they have released a new version 7.20.1, so i have made a second upgrade, which went smoothly.