v7.14.3 [stable] is released!

I have a total of ten devices I manage (mixed) with some examples being a CCR, CRS, hAP ac and ax models, a single Audience. All of these devices with the exception of the CCR and CRS are very simple configurations (no QoS, no VLANs, etc.) All of the devices are configured to auto-update by checking weekly for new ROS releases in the stable branch.

Everything has successfully updated to v7.14 except for the hAP ac2 and lower models. I had one hAP ac2 brick itself after the upgrade and resetting it didn’t bring it back to life. Fortunately I had a hAP ax3 on-hand spare to swap it with. The other hAP ac2 and lower models I’m managing I’ve had to pause auto-updates on (and just in time.) Bottom-line in my opinion, the ac2 and lower models will never be upgraded again and I’m considering them EOL after 7.13.x.

The way I see it, the hAP ac2 and lower models have what, 16MB of memory? And we’re now on ROS releases that are only going to grow in overall size since we now have ROS and QCOM Wi-Fi packages to contend with. On mine, I now have ROS, QCOM and ZeroTier packages needing to be installed/upgraded.

This can be configured in system/routerboard from memory.

Good day,

IKEv2/IPSec PSK Android native VPN connection : ipsec identity not fund error

Android 14 (maybe 13 too) initialliy sends IPsec-ID as configured in the phone connection (In ROS: ID_I) but an empty remote id (ID_R).
Later it requests ID_R to check if configured vpn server matches ROS id. It closes the connection if it doesnt match.

Problem:

a) if i configure the identity in ROS to have both ID’s (my id type:fqdn, my id: my.public.dns and remote id type: fqdn, id: ipsec.vpn for example)
ROS will not find that identity because it seems that it checks both id’s (but ID_R from android is emtpy)

b) if i configure the identity in ROS to have empty value for my id, ROS will pick up that identity but report that empty value later when requseted
Finally android will send a DELETE to abort the connection.

i dont know if android behaves correctly, however it is possible to bypass checking “my id” value when selecting identity in case of empty value?

Good day,

feature request: ipsecprofiles / ipsec peers
ipsec/profile (phase1) multiple values for hash and prf algorithms
–and / or–
mutilple identical ipsec peers (with the exception of profile selection)

feature request:

ipsec/profile (phase1) multiple values for hash and prf algorithms
–and / or–
mutilple identical ipsec peers (with the exception of profile selection)

Windows demands the same algo for both hash and prf. for example i can set up SHA256/SHA256 or SHA1/SHA1,
but e.g android 11 accepts only hash:SH256 and prf:SHA1 for IKEv2/PSK VPN.

It is impossible to handle both types of clients here.
Auto setting for prf seems to use SHA1.

It is possible to create multiple profiles with different settings,
but only one of them can be selected in the corresponding peer definition.

Maybe it will be possible in the future to extend profile config to accept more than one value for hash/prf
or/and
to handle all peers which only differ in the profile definition without the error: this entry is unreachable?

many thanks

@pedkoschi - Use PS to update your Windows IKEv2 configuration to the encryption level that suits for both clients:

PS C:\Users\user> Set-VpnConnectionIPsecConfiguration -ConnectionName “xxxx” -AuthenticationTransformConstants SHA256128 -CipherTransformConstants AES256 -EncryptionMethod AES256 -IntegrityCheckMethod SHA256 -PfsGroup PFS2048 -DHGroup Group14 -PassThru -Force

AuthenticationTransformConstants : SHA256128
CipherTransformConstants : AES256
DHGroup : Group14
IntegrityCheckMethod : SHA256
PfsGroup : PFS2048
EncryptionMethod : AES256

This is also possible for Mac clients with .mobileconfig profiles using Apple Configurator.

What’s new in 7.14.1 (2024-Mar-08 14:50):
*) bgp-vpn - use VRF interface as gateway for leaked connected routes;
*) chr - fixed Xen and Vultr missing ethernet (introduced in v7.14);
*) chr - fixed bogus messages printed out while booting up the system (introduced in v7.14);
*) console - fixed do/while implementation not working with variables (introduced in v7.14);
*) ethernet - fixed default names for CRS310-8G+2S+ device (introduced in v7.14);
*) lte - fixed R11e-LTE-US modem dial-up;
*) sfp - improved system stability for CR2004-1G-2XS-PCIe (introduced in v7.14);
*) vrf - fixed VRF interfaces being moved to main table after reboot (introduced in v7.14);
*) wireguard - do not attempt to connect to peer without specified endpoint-address;

Bug in 7.14.1 on CRS328-24P-4S+: Blink button and blink cli command does not work
blink.png

Nice update. Good to see the improvement for wireguard peers which will fix a lot of the log spam, and of course the Chr ethernet fix which was quite serious/urgent :+1:viva la MikroTik.. ROS v7 ftw

Now we just need smaller packages for 15/16 MB devices please :wink: or at least some function or way to reclaim bogus used space without needing to netinstall it?

I wish for this ever since. Completely non-understandable why there no such command exists. ROS hides the “real” filesystem behind a facade and gives us no option to get rid of crappy tempfiles.

It worked in 7.14?

Bricked in 7.14.1 also even with this,
*) sfp - improved system stability for CR2004-1G-2XS-PCIe (introduced in v7.14);

I guess I’m waiting for the “*) We actually mean stable this time. And it really works for CR2004-1G-2XS-PCIe” according to your logic.

don’t know, just wanted to let know it does not work in the current version

What is the latest version you know it still worked?

You need to watch out for changelog entry like:

  • sfp - improved system stability for CR2004-1G-2XS-PCIe (introduced in v7.14.1)

I’m still seeing failures with the VRF’s being assigned to main. In the new Testing release it appears to be fixed but in this 14.1 release its still broken for me anyway. I rolled back my RB5009 after updating this mornign.

Hi,

Access to CHANGELOG information via CLI does not work:

[admin@MikroTik] > :put ([/tool fetch “https://upgrade.mikrotik.com/7.14.1/CHANGELOG” output=user as-value] → “data”)
failure: Fetch failed with status 404

Thx.

Probably because there is no changelog on the provided URL, @diamuxin. Also from the browser it results in a 404.

Missing “routeros” directory:

https://upgrade.mikrotik.com/routeros/7.14.1/CHANGELOG

Right, sorry!

BR.

hap ac3 7.14.1 I have the same problem as on 7.14. Container pihole does not work. Сomplete reinstallation of the container does not help. Downgrade 7.13.5 helps get the container working again