v6.38.1 [current]

To upgrade, click “Check for updates” at /system package in your RouterOS configuration interface, or head to our download page: http://www.mikrotik.com/download

If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while router is not working as suspected or after crash.

What’s new in 6.38.1 (2017-Jan-13 05:51):

*) bridge - disallow manual removal of dynamic bridge ports;
*) bridge - fixed MAC address learning from switch master-port;
*) bridge - fixed access loss to device through bridge if master port had a loop (introduced in v6.38);
*) certificate - added year cap (invalid-after date will not exceed year 2039);
*) certificate - fixed fail on import from CAPs when both key and name already exist;
*) dhcpv6-client - fixed DHCPv6 rebind on startup;
*) dhcpv6-server - fixed server removal crash if static binding was present;
*) dns - fixed typo in regexp error message;
*) dude - (changes discussed here: http://forum.mikrotik.com/t/the-dude-v6-38-current-release/104799/1);
*) fan - improved RPM monitor on CCR1009;
*) firewall - nat action “netmap” now requires to-addresses to be specified;
*) health - report fan speed for RB800 and RB1100 when 3-pin fan is being used;
*) ike1 - fixed ph1 rekey in setups with mode-cfg;
*) ike2 - allow empty selectors to reach policy handler;
*) ike2 - auto-negotiate split nets;
*) ike2 - default to tunnel mode in setups without policy;
*) ike2 - fixed error packet from initiator on responder reply;
*) ike2 - fixed initiator TS updating;
*) ike2 - fixed ph1 initial-contact rare desync;
*) ike2 - fixed policy setting for /0 selector with different address families;
*) ike2 - fixed split policy active flag;
*) ike2 - fixed traffic selector prefix calculation;
*) ike2 - fixed xauth add check;
*) ike2 - include identity in peer address info;
*) ike2 - log empty TS payload;
*) ike2 - minor logging update;
*) ike2 - show peer identity of connected peers;
*) ike2 - traffic selector improvements;
*) ike2 - update also local port when peer changes port;
*) ike2 - use first split net for empty TS;
*) ike2 - use standard retransmission timers for DPD;
*) ike2 - xauth like auth method with user support;
*) ipsec - added ability to kill particular remote-peer;
*) ipsec - fixed flush speed and SAs on startup;
*) ipsec - fixed peer port export;
*) ipsec - port is used only for initiators;
*) ipv6 - added warning about having interface MTU less than minimal IPv6 packet fragment (1280);
*) license - fixed demo license expiration after installation on x86;
*) log - improved firewall log messages when NAT has changed only connection ports;
*) logs - work on false CPU/RAM overclocked alarms;
*) mpls - fixed crash on active tunnel loss in MPLS TE setups;
*) ovpn - fixed address acquisition when ovpn-in interface becomes slave;
*) proxy - fixed “max-cache-object-size” export;
*) proxy - speed-up almost empty disk cache clean-up;
*) quickset - various small changes;
*) rb751u - fixed ethernet LEDs (broken since 6.38rc16);
*) ssh - fixed high memory consumption when transferring file over ssh tunnel;
*) webfig - show properly large BGP AS numbers;
*) winbox - added “make-static” to IPv6 DHCP server bindings;
*) winbox - added “prefix-pool” to DHCPv6 server binding;
*) winbox - added IPsec to radius services;
*) winbox - added upstream flag to IGMP proxy interfaces;
*) winbox - allow to specify “connection-bytes” & “connection-rate” for any protocol in “/ip firewall†rules;
*) winbox - allow to specify “sip-timeout” under ip firewall service-ports;
*) winbox - do not create empty rates.vht-basic/supported-mcs if not specified in CAPsMAN;
*) winbox - hide “nat-traversal” setting in IPsec peer if IKEv2 is selected;
*) winbox - show dynamic IPv6 pools properly;
*) winbox - show errors on IPv6 addresses;
*) winbox - specify metric for “/ip dns cache-used†setting;
*) wireless - show comment on “security-profile” if it is set;

I have strange excitement about version that was build on the Friday 13th and with full moon (at least where i’m from).

Just upgraded my home network CRS226, RB750Gr2 and few WAP ac, so far so good. Tomorrow will play with test network @ work.

Awesome for releasing this release so soon. Will see if I can test it out later tonight on my RB750Gr3’s and will report back once its done and tested. I really hope the 6.38 bugs are squashed :slight_smile:

hehehe, beware!!!

Disable and Enable not worked in winbox
Please fix this issue

Sent from my C6833 using Tapatalk

Disable/enable issue is already fix in Winbox 3.9

Latest for Mac hasn’t been done yet…

http://joshaven.com/resources/tools/winbox-for-mac/

Still stuck on 3.7.. wonder if joshaven hides out here somewhere, if so, would you be so kind and give us a 3.9 version when you get a few minutes. Thank you.

Update

I have just dropped joshaven a quick email to see if he can upgrade winbox for us macOS users to 3.9 as a temp fix until Mikrotik one day decides to give us a native version. Fingers crossed he is willing to do it.

No, 6.38.1 also bugged, as 6.38 (ipsec tunnel dont work)
Only downgrade to 6.37.3 can help.

Upgrade from 6.37.2 to 6.38.1 bricked rb751u-2hnd … simple setup, pppoe+nat+wifi …

Edit: Had to netinstall it … it works OK now.

The PPPoE speed issue seems to be solved, at least for me.

The Bridge not using the FP with IPsec and EOIP is solved for me too. Speed is back :slight_smile:

Just upgrade from within winbox using the check for updates under tools. Works fine for me, although I am using my own wrapped version. It’s pretty easy to do yourself if you want to learn. I use WineBottler with the separate Wine app as it keeps disk space usage down and Wine can be shared with other apps. Either way, with Winbox there’s really no extra stuff you need, so it’s easy to wrap.



O RLY? :open_mouth:

problem with speed is fixed on hap ac

Unfortunately the bug with IPSec - “pre shared key xauth” introduced in 6.38 was not fixed in 6.38.1

When testing VPN with Android phone VPN type “IPSec Xauth PSK” (Nexus 5X Android version 7.1.1) RouterOS incorrectly recognizes XAUTH password length.

Jan/16/2017 21:23:42 ipsec,debug Configuration exchange type mode config REPLY
Jan/16/2017 21:23:42 ipsec,debug Short attribute XAUTH_TYPE = 0
Jan/16/2017 21:23:42 ipsec,debug Attribute XAUTH_USER_NAME len 6
Jan/16/2017 21:23:42 ipsec,debug Attribute XAUTH_USER_PASSWORD len 11
Jan/16/2017 21:23:42 ipsec,info Xauth login failed for user: ******

Password for above user attempt is in reality 10 characters long (both in “/ip ipsec user” and in Android phone).

IPSec peer config:

 /ip ipsec peer> print
Flags: X - disabled, D - dynamic, R - responder 
 0   R address=0.0.0.0/0 passive=yes auth-method=pre-shared-key-xauth secret="**********" generate-policy=port-override policy-template-group=RoadWarrior 
       exchange-mode=main mode-config=RW-cfg send-initial-contact=yes nat-traversal=yes proposal-check=obey hash-algorithm=sha1 enc-algorithm=aes-256 
       dh-group=modp1024 lifetime=1d dpd-interval=2m dpd-maximum-failures=5

With the same config RouterOS version 6.37.3 succesfully established IPSec tunnel (Phase 1 and Phase 2).

Can anyone repeat the above problem?

This seems to have sorted the fan reporting issue on my 1009-8G-1S-1S+ that I reported after 6.37.3/6.38:

system health print
fan-mode: auto
use-fan: main
active-fan: main
cpu-overtemp-check: yes
cpu-overtemp-threshold: 70C
cpu-overtemp-startup-delay: 1m
voltage: 24V
current: 829mA
temperature: 32C
cpu-temperature: 54C
power-consumption: 19.8W
psu1-state: ok
psu2-state: ok
fan1-speed: 4284RPM

Thanks guys!

Just did this – it got me 3.8, but not 3.9 (am I misinterpreting announcement by strods, above?)

Its definitely winbox 3.9!

Click “tools → check for updates” and upgrade your Winbox Mac version! You do not have to wait for somebody to re-compile it.
screen 13.jpg

GMT time :wink: