v5.6 released

It looks like they managed to replace periodical router crash with similar log message (at least for me).

Regarding the L7 problem:

For some time it was known that some specific layer7 filters in combination with specific traffic may cause router to crash.

We were able to narrow down the problem and introduced a first version of the fix - as soon as specific conditions for possible crash was met firewall will add a log entry to inform about situation and will avoid the crash.

The current “fix” actually contained a bug, so it produces unnecessary log entries.

We are still working on final solution, in fact it is already known that version 5.7 will have more precise fix that will significantly reduce blocked regexps as we narrow the problem even more (thanks to your reports)

Hello Normis,

Thank you!
Any adicional info you need just let me know.

Hello Normis,

Is ticket #2011072166000401 fixed in this release?

Thanks,
Dzieva

5.6 version include improvements for wireless and NV2.
Have you tried v5.6 on problematic link?
Do you experience the same disconnect problems?

Yes, they can’t be trusted. I’m aware of that, that’s why you have certificate authorities to validate. If someone is running a large web server and hasn’t yet gone to load balancing hardware it’s pretty routine to balance the load by having the domain name resolve to multiple IPs. The servers could be distributed around the world and local requests would get resolved to a local server. You’d have to generate and validate certificates for every IP you use? Then you’re paying the certificate authority to sign each one? No thanks.

Is it a useful feature to be able to lock it to a single IP should you need to? Yes, absolutely.
Is it useful to anyone running domains with more than one IP? Nope

IPs change too.

It’s more secure to have one master certificate. If you have a new one for every IP then someone can hijack DNS and have fake certificates for their own site. If they get the ‘hey the site certificate has changed’ message all the time because each IP has it’s own certificate they’re going to ignore the warning as it’s become routine.

Nothing is secure, get use to it, but don’t break established systems that everyone uses.

If you want to be paranoid then come to Blackhat USA and DEFCON. There’s a talk later on a flaw in OSPF that allows an attacker to take over network routing. Cisco routers which are generally known to be solid and secure enough that classified information is trusted to run on them? Well there’s another talk on exploiting unified images on Cisco. Cisco has millions to spend on security hardening. You think Mikrotik would fare any better? I know it wouldn’t as I’ve looked over the system and seen things that tell me the people writing the code haven’t had enough training on secure coding practices.

Note: Mikrotik, I’m quite willing to sign a (reasonable, and mutual) non-disclosure agreement and help make it more secure.

If you took away the option to use something that could be attacked with a vulnerability then we’d never use anything. There is actually an unpatched PHP vulnerability right now that can give remote execution, you want to shut off most of the internet because someone could potentially use it?

Hello Sergejs,

Yes, Yes, with v5.6 build jul/28…
I will update to v5.6 build aug/02 and test it.

Thanks,
Dzieva

The release notes show no changes to wireless package at all so why would he think that it would make a difference? (Sarcasm intended)

We are still having disconnects with version 5.6, I have been sending in support output files. Hopefully it will help you guys get it taken care of.

I’ve updated remote SXT and after reboot I lost it. Then I tried to update testing SXT which I have here - I lost it as well. No single packet from them - I tried to discover using WinBox, I tried to watch traffic using Wireshark, nothing. What’s going on? :frowning:

Edit: I’m talking about ethernet (cable) connection, I didn’t try wireless.

Updated 5.6

jan/02 00:00:10 system,info verified routerboard-5.6-mipsbe.npk
jan/02 00:00:11 system,info verified ntp-5.6-mipsbe.npk
jan/02 00:00:11 system,info verified wireless-5.6-mipsbe.npk
jan/02 00:00:11 system,info verified advanced-tools-5.6-mipsbe.npk
jan/02 00:00:11 system,info verified security-5.6-mipsbe.npk
jan/02 00:00:11 system,info verified system-5.6-mipsbe.npk
jan/02 00:00:11 system,info installed system-5.6
jan/02 00:00:11 system,info installed security-5.6
jan/02 00:00:11 system,info installed advanced-tools-5.6
jan/02 00:00:11 system,info installed wireless-5.6
jan/02 00:00:11 system,info installed ntp-5.6
jan/02 00:00:11 system,info installed routerboard-5.6
jan/02 00:00:11 system,info router rebooted
jan/02 00:00:14 interface,info ether1 link up (speed 100M, full duplex)
jan/02 00:00:19 wireless,info 00:0C:42:B5:XX:XX@wlan1 established connection on XXXX, SSID XXXXXXXX
jan/02 01:00:45 interface,info ether1 link down
jan/02 01:00:47 interface,info ether1 link up (speed 100M, full duplex)
jan/02 01:03:10 interface,info ether1 link down
jan/02 01:03:11 interface,info ether1 link up (speed 100M, full duplex)
jan/02 19:01:16 interface,info ether1 link down
jan/02 19:01:18 interface,info ether1 link up (speed 100M, full duplex)
jan/02 19:01:22 interface,info ether1 link down
jan/02 19:01:24 interface,info ether1 link up (speed 100M, full duplex)
jan/02 19:01:40 interface,info ether1 link down
jan/02 19:01:41 interface,info ether1 link up (speed 100M, full duplex)
01:31:21 interface,info ether1 link down
01:31:22 interface,info ether1 link up (speed 100M, full duplex)
01:47:18 interface,info ether1 link down
01:47:20 interface,info ether1 link up (speed 100M, full duplex)

I have had the same issue with one board since I have upgraded, so I am not sure what the deal is but again I am only seeing it on one 411.

csallor,

please send support output file from your router to support (support@mikrotik.com).

chadd
Thank you very much. We have received support output files and now researching them. As soon as we will have any information or feedback, we will let you know!

My RB1200 reboot when enable or disable auto-negotiation on any interface.

Message log:
system error critical router was rebooted without proper shutdown (cause1)

Is there any output on serial console while rebooting? It is recommended to send supout.rif file from this router to support@mikrotik.com

hello Dzieva, did you implementing nv2 wireless protocol?

so what the result, is disconnect problem solved in 5.6?

thanks.

NV2 bridge 56 км ки 411 r52hn (baza)
aug/05 21:57:24 wireless,debug wlan1: 00:0C:42:64:52:7B in local ACL, accept
aug/05 21:57:24 wireless,info 00:0C:42:64:52:7B@wlan1: connected
aug/05 21:58:22 wireless,info 00:0C:42:64:52:7B@wlan1: reconnecting
aug/05 21:58:22 wireless,debug wlan1: 00:0C:42:64:52:7B in local ACL, accept
aug/05 21:58:22 wireless,info 00:0C:42:64:52:7B@wlan1: connected
aug/05 22:11:46 system,info,account user admin logged in from 178.49.73.94 via win
box


NV2 station bridge 56 km r52hn (klient)

16:06:17 wireless 00:0C:42:62:DA:48@wlan1: lost connection, synchronization timeout
16:06:18 wireless 00:0C:42:62:DA:48@wlan1 established connection on 2312, SSID gorn
16:06:37 wireless 00:0C:42:62:DA:48@wlan1: lost connection, synchronization timeout
16:06:39 wireless 00:0C:42:62:DA:48@wlan1 established connection on 2312, SSID gorn
16:58:50 wireless 00:0C:42:62:DA:48@wlan1: lost connection, synchronization timeout
16:58:51 wireless 00:0C:42:62:DA:48@wlan1 established connection on 2312, SSID gorn
16:59:21 wireless 00:0C:42:62:DA:48@wlan1: lost connection, synchronization timeout
16:59:22 wireless 00:0C:42:62:DA:48@wlan1 established connection on 2312, SSID gorn

Mirror bug, in registration table P throughput for N link is calculated wrong.

What about the others? Do you have such problem with SXT as well? I am going away for a week so I will try to solve that later.

I was comparing exported configurations before and after the upgrade from 5.5 to 5.6 and noticed a new option that I can’t find anything about on the wiki, “sip-direct-media”. It showed up here:

/ip firewall service-port
set ftp disabled=no ports=21
set tftp disabled=no ports=69
set irc disabled=no ports=6667
set h323 disabled=no
set sip disabled=no ports=5060,5061 sip-direct-media=yes
set pptp disabled=no

Clues?

I almost finished upgrading all my 250+ rb’s from 5.x to v5.6. (rb’s 122, 133c3, 532, 411, 433, 333, 711’s SXT’s etc.) most done remote (wireless).

For some of these forum users that report sometimes they lost the unit after an upgrade: After upload of the package of wish check that all packages are really upgraded and mentioned in black in the file list. When only in light grey text, something had gone wrong (checksum is not correct?) and you need to upload that package again.
If one or more of the packages are not uploaded to the routerboard, or some data of the package is corrupt it might that an essential package is not loaded during the reboot and you loose control over that unit. Sometimes control is lost because dhcp package is corrupt while device is dhcp-client. Or if updated client is wireless and the wireless package is corrupt the wireless connection is lost.
It is therefore VERY IMPORTANT to check if the desired package are indeed uploaded in proper condition before the router is to be rebooted!

Wireless disconnects:
I have been very active on this forum amongst some others about this issue.
I have 220+ wireless units in an environment where all available spectrum is used, sometimes twice. (All 5Ghz upper band)
All my P2P ant P2MP are 802.11a with NV2 or 802.11n with NV2.
P2MP are typical 10Mhz bandwidth.
Although 5.6 is a bit better than previous releases, it is still more important than the pre NV2 era to separate radios as much as possible from signals they should not receive.
But my network is now 98% stable when it comes to wireless disconnects. The last 2% can be of any source, not necessarily related to NV2 or interference.

Ethernet port flapping:
The issue is still there, 5.6 did not bring any improvement on that.
But:
All my units that have the Ethernet port flap are connected with their Ethernet port via a power-shot to 3rd party units (wifi router, PC or laptop, switch)
I had one Ethernet port flap many times a day. I fit one mini-router (rb150) in-between the cable with all ports bridged, and the flapping has gone between the two router-boards. So the unit that reported some 20 to 30 Ethernet port flaps a day is now rock solid!
The Ethernet port of the rb150 that now connects to the client shows now a port flapping, but less as before (?)

I am developing a ´feeling´ the Ethernet port flap issue is more related to ESD which makes the ROS sense if like a port is down. So far I could not proof that a Ethernet port flap is actually ´breaking´ the connection. Clients don’t seem to notice any disconnects.
But more tests and longer investigation is needed to get to the bottom of this issue.

I started a new topic on this Ethernet port flap issue with some question to report more detailed from us users that still have the issue. http://forum.mikrotik.com/t/new-ethernet-port-flap-issue-enquiery-pls-join/49200/1

Furthermore so far no issues with v5.6