I have a total of ten devices I manage (mixed) with some examples being a CCR, CRS, hAP ac and ax models, a single Audience. All of these devices with the exception of the CCR and CRS are very simple configurations (no QoS, no VLANs, etc.) All of the devices are configured to auto-update by checking weekly for new ROS releases in the stable branch.
Everything has successfully updated to v7.14 except for the hAP ac2 and lower models. I had one hAP ac2 brick itself after the upgrade and resetting it didn’t bring it back to life. Fortunately I had a hAP ax3 on-hand spare to swap it with. The other hAP ac2 and lower models I’m managing I’ve had to pause auto-updates on (and just in time.) Bottom-line in my opinion, the ac2 and lower models will never be upgraded again and I’m considering them EOL after 7.13.x.
The way I see it, the hAP ac2 and lower models have what, 16MB of memory? And we’re now on ROS releases that are only going to grow in overall size since we now have ROS and QCOM Wi-Fi packages to contend with. On mine, I now have ROS, QCOM and ZeroTier packages needing to be installed/upgraded.
IKEv2/IPSec PSK Android native VPN connection : ipsec identity not fund error
Android 14 (maybe 13 too) initialliy sends IPsec-ID as configured in the phone connection (In ROS: ID_I) but an empty remote id (ID_R).
Later it requests ID_R to check if configured vpn server matches ROS id. It closes the connection if it doesnt match.
Problem:
a) if i configure the identity in ROS to have both ID’s (my id type:fqdn, my id: my.public.dns and remote id type: fqdn, id: ipsec.vpn for example)
ROS will not find that identity because it seems that it checks both id’s (but ID_R from android is emtpy)
b) if i configure the identity in ROS to have empty value for my id, ROS will pick up that identity but report that empty value later when requseted
Finally android will send a DELETE to abort the connection.
i dont know if android behaves correctly, however it is possible to bypass checking “my id” value when selecting identity in case of empty value?
feature request: ipsecprofiles / ipsec peers
ipsec/profile (phase1) multiple values for hash and prf algorithms
–and / or–
mutilple identical ipsec peers (with the exception of profile selection)
feature request:
ipsec/profile (phase1) multiple values for hash and prf algorithms
–and / or–
mutilple identical ipsec peers (with the exception of profile selection)
Windows demands the same algo for both hash and prf. for example i can set up SHA256/SHA256 or SHA1/SHA1,
but e.g android 11 accepts only hash:SH256 and prf:SHA1 for IKEv2/PSK VPN.
It is impossible to handle both types of clients here.
Auto setting for prf seems to use SHA1.
It is possible to create multiple profiles with different settings,
but only one of them can be selected in the corresponding peer definition.
Maybe it will be possible in the future to extend profile config to accept more than one value for hash/prf
or/and
to handle all peers which only differ in the profile definition without the error: this entry is unreachable?
What’s new in 7.14.1 (2024-Mar-08 14:50):
*) bgp-vpn - use VRF interface as gateway for leaked connected routes;
*) chr - fixed Xen and Vultr missing ethernet (introduced in v7.14);
*) chr - fixed bogus messages printed out while booting up the system (introduced in v7.14);
*) console - fixed do/while implementation not working with variables (introduced in v7.14);
*) ethernet - fixed default names for CRS310-8G+2S+ device (introduced in v7.14);
*) lte - fixed R11e-LTE-US modem dial-up;
*) sfp - improved system stability for CR2004-1G-2XS-PCIe (introduced in v7.14);
*) vrf - fixed VRF interfaces being moved to main table after reboot (introduced in v7.14);
*) wireguard - do not attempt to connect to peer without specified endpoint-address;
Nice update. Good to see the improvement for wireguard peers which will fix a lot of the log spam, and of course the Chr ethernet fix which was quite serious/urgent viva la MikroTik.. ROS v7 ftw
Now we just need smaller packages for 15/16 MB devices please or at least some function or way to reclaim bogus used space without needing to netinstall it?
I wish for this ever since. Completely non-understandable why there no such command exists. ROS hides the “real” filesystem behind a facade and gives us no option to get rid of crappy tempfiles.
I’m still seeing failures with the VRF’s being assigned to main. In the new Testing release it appears to be fixed but in this 14.1 release its still broken for me anyway. I rolled back my RB5009 after updating this mornign.
hap ac3 7.14.1 I have the same problem as on 7.14. Container pihole does not work. Сomplete reinstallation of the container does not help. Downgrade 7.13.5 helps get the container working again