v6.39rc [release candidate] is released

I have a problem with ipsec and xauth. If the xauth user name is longer than 30 characters, in the log you can see “Trimming Xauth user name”. The Xauth login fail. If I cut the Xauth name to 30 characters or less, the Xauth login succeed. The original Xauth user name was “Luedenscheid_luedenscheid-aussenstellen”.
With RouterOS 6.37.4 there is no problem.

11:15:58 ipsec,info respond new phase 1 (Identity Protection): 111.11.56.87[500]<=>99.231.204.198[500]
11:15:58 ipsec,info ISAKMP-SA established 111.11.56.87[4500]-99.231.204.198[4500] spi:6a36407b8d013957:e691c0e0be04100d
11:15:58 ipsec,error Trimming Xauth user name
11:15:58 ipsec,info No mode-cfg configured
11:15:58 ipsec,info XAuth login failed for user: Luedenscheid_luedenscheid-auss
11:16:02 ipsec,info respond new phase 1 (Identity Protection): 111.11.56.87[500]<=>99.231.204.198[500]
11:16:02 ipsec,info ISAKMP-SA established 111.11.56.87[4500]-99.231.204.198[4500] spi:436a58d94cf6c650:75a152295ad122d1
11:16:02 ipsec,info XAuth login succeeded for user: Luedenscheid_luedenscheid-a
11:21:18 system,info device added by admin

Here you can read about the lead up to this “trimming”:

http://forum.mikrotik.com/t/v6-38-current-is-released/104797/80

Thanks, but I have the problem with the Xauth user and not with the password!

Confirming PPPoE went down on RC40. Cannot test torch trick atm.

Version 6.39rc41 has been released.

Changes since previous version:
!) pppoe - added fastpath support when MRRU and MLPPP are enabled;
*) tr069-client - added basic support for “/ip firewall filters”;

If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while router is not working as suspected or after crash.

Thanks strods, that was quick.

Just tested, 6.39rc41 fixes both the environment vars and pppoe-client problems.

Tnx for quick fix. Confirming PPPoE is working as expected.

6.39rc40 working
6.39rc41 no working

power off/on no test

Somebody with performance problems on 6.39RC38? Neither updates it’s possible to do :frowning:
I think that netinstall is needed.

https://drive.google.com/file/d/0B1G8TB3Aa9PpTzNQRVJ6VUhBYjQ/view?usp=sharing

  • I’m using hap lite and system resources are ok. CPU at 2% and RAM at 50%.

Thanks! Can’t yet try it; is the dhcp-server already configured by the time the script runs?

Thanks for the hint, Chupaka, used it to make the code that actually works for the usecase.

:local gatewayAddress [/ip dhcp-client get [find dhcp-server=$"server-address"] gateway]

@Mikrotik team
Paste is not working in the terminal window.
macOs , Chrome Version 56.0.2924.87 (64-bit)

Is the RSTP problem fixed? http://forum.mikrotik.com/t/mikrotik-vlan-switching-without-bridging-and-wlan/106240/1

RB2011UAS-2HnD-IN ROS v6.39rc41

Can’t copy & paste in WebFig Terminal. Tested on Mac OS X 10.8.4, Chrome 49.0.2623.112 (64-bit) & Firefox 48.0.2.

Unable to login to WebFig using Safari on iPad 1 iOS 5.1.1. ERROR: Internal Server Error after clicking Login.

Huh, my bad, I was thinking about dhcp-server when I was writing the answer. Glad you still found it useful :slight_smile:

In RouterOS 6.39rc41 we have still the problem with ipsec and xauth. If the xauth user name is longer than 30 characters, in the log you can see “Trimming Xauth user name”. The Xauth login fail. If I cut the Xauth name to 30 characters or less, the Xauth login succeed. The original Xauth user name was “Luedenscheid_luedenscheid-aussenstellen”.
With RouterOS 6.37.4 and before there is no problem.

11:15:58 ipsec,info respond new phase 1 (Identity Protection): 111.11.56.87[500]<=>99.231.204.198[500]
11:15:58 ipsec,info ISAKMP-SA established 111.11.56.87[4500]-99.231.204.198[4500] spi:6a36407b8d013957:e691c0e0be04100d
11:15:58 ipsec,error Trimming Xauth user name
11:15:58 ipsec,info No mode-cfg configured
11:15:58 ipsec,info XAuth login failed for user: Luedenscheid_luedenscheid-auss
11:16:02 ipsec,info respond new phase 1 (Identity Protection): 111.11.56.87[500]<=>99.231.204.198[500]
11:16:02 ipsec,info ISAKMP-SA established 111.11.56.87[4500]-99.231.204.198[4500] spi:436a58d94cf6c650:75a152295ad122d1
11:16:02 ipsec,info XAuth login succeeded for user: Luedenscheid_luedenscheid-a
11:21:18 system,info device added by admin

“If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while router is not working as suspected or after crash.”

Please report your issue to support, no need to repost here every N days. Support usually responds within a few business days.

Version 6.39rc45 has been released.

Changes since previous version:
!) firewall - discontinued support for p2p matcher (old rules will become invalid);
*) hotspot - fixed redirect to URL where escape characters are used (requires newly generated HTML files);
*) l2tp-client - fixed IPSec policy generation after reboot;
*) l2tp-client - require working IPSec encryption if “use-ipsec=yes”;
*) l2tp-server - added “use-ipsec=required” option;
*) lcd - show fan2 speed only if it is available;
*) tr069-client - added basic support for “/ip firewall filters”;
*) tr069-client - fixed “AddObjectResponse” “InstanceNumber†value;
*) tr069-client - set CHR license ID as “.SerialNumber” value to avoid “no serial number” error in ACS;

If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while router is not working as suspected or after crash.

Any news on the DFS issues? Haven’t heard back from my ticket either…

!) firewall - discontinued support for p2p matcher (old rules will become invalid);

What is the reason to drop it ?

I think that is because it not so much efficient in this days any more

Enviado de meu XT1580 usando Tapatalk