v7.11rc is released!

bth is removed. hmm

yes yes, because if nothing else critical pops up as reproducible by support staff they’ll just slap a stable tag on this rc4 and rebuild it calling it a stable release.

Obviously BTH is not release-ready yet. And probably stabilizing BTH would take longer time than MT devs would like. Specially as many users are eagerly awaiting for wifiwave2 stability … which is IMO waaay more important than some random new feature.

I would put in another fact… Probably Mikrotik needs to scale up the infrastructure before this can be released for anybody to be used in a stable release.

We had three options - release BTH as is, delay 7.11 stable just due to the BTH or remove BTH. We did choose to remove BTH as we can not call it “stable” yet and move a step closer to 7.11 (stable) for those who do not care about BTH. We would like to call it a win-win. BTH will be back on 7.12, no worries.

Strods this is good aproach…when it is not stable just do not include it in stable version. BTH can wait we have Wireguard anyway…

As MikroTIk fan, this move is 100% approved, BTH is a nice have but pretty sure there is a looong list of things to fix/improve!
Nice job MT, waiting for Stable.

Nice move. I wait for Stable.
Thanks.

*) ike1 - fixed Phase 1 when using aggressive exchange mode (introduced in v7.10);

Minor detail, but I’d argue this was introduced in 7.11beta2 not 7.10 (SUP-122289). Thank you very much for thoroughly diagnosing and fixing the issue.

I have a feeling that in some cases the renewal of an IPsec ike1 association kills some other associations and triggers a renewal.
Did you observe that? It happens in “main” mode so it may not be related to this. What I observe is when a GRE/IPsec tunnel’s IPsec is renewed, the L2TP/IPsec from the same remote peer is renewed at the same time. The local address is different for these.

In this case, a peer with aggressive mode set would continuously trigger a rekey for all other peers/policies (different remote addresses).
Not sure if both issues are related. Would recommend finding a reproducible scenario and submit the case to support.

Ok that is interesting, I will try to find an opportunity to upgrade the software on that router and see if it is the same issue. Thanks!

Noted that if I choose 2,4 network instead of 5 G - the SA Query Timeout is gone. My 2,4G network has WPA/WPA2 only since I have old devices not supporting WPA 3. Can this be related to WPA3 security?

use disable-pmkid=yes

So are you keeping up your relay ? Or it will be offline until 7.12beta ?

I have set disable pmkid since before. And now removed WPA3. Seems more stable.

RouterOS v7.11rc4 has been promoted to 7.11 stable:
http://forum.mikrotik.com/t/v7-11-2-stable-is-released/168778/1

Yo MikroTik fam, need help! I’ve got 3 mANTBox 15s fresh out the box, trying to log in for config. Used default username and password — no luck. Any tips to access them via WinBox or WebFig? MAC login? Reset tricks? Appreciate the guidance!