v7.18rc [testing] is released!

Its totally basic setup in labs, both CHR and physical routerboards. There is a P router in the middle and 3 PE on that.
This is the MPLS and Routing config from first PE router (RB750Gr3):

[oreggin@rtr1.CPE] > /mpls/export 
/mpls interface
add interface=all mpls-mtu=1500
/mpls ldp
add afi=ip,ipv6 disabled=no lsr-id=10.0.10.11 preferred-afi=ipv6 transport-addresses=10.0.10.11,b00b::10:0:10:11
/mpls ldp interface
add accept-dynamic-neighbors=yes afi=ip,ipv6 disabled=no interface=ether2

[oreggin@rtr1.CPE] > /routing/export 
/routing bgp template
set default disabled=no router-id=10.0.10.11
/routing ospf instance
add disabled=no name=ospfv2 router-id=10.0.10.11
add disabled=no name=ospfv3 router-id=10.0.10.11 version=3
/routing ospf area
add disabled=no instance=ospfv2 name=backbone4
add disabled=no instance=ospfv3 name=backbone6
/routing bgp connection
add address-families=ip,l2vpn,l2vpn-cisco,vpnv4 as=65530 connect=no disabled=no listen=yes local.address=10.0.10.11 .role=ibgp-rr name=rrcl4 nexthop-choice=force-self \
    output.default-originate=if-installed .redistribute=connected remote.address=10.0.10.0/24 .as=65530 router-id=10.0.10.11 routing-table=main
add address-families=ipv6,vpnv6 as=65530 connect=no disabled=no listen=yes local.address=b00b::10:0:10:11 .role=ibgp-rr name=rrcl6 output.default-originate=always .redistribute=connected \
    remote.address=b00b::10:0:10:0/112 .as=65530 router-id=10.0.10.11 routing-table=main
/routing bgp vpls
add bridge=VPLS_B bridge-horizon=4 comment="BGP signaled VPLS" disabled=no export-route-targets=65530:4 import-route-targets=65530:4 name=VPLS_B pw-type=vpls rd=65530:4 site-id=11
add bridge=VPLS_A bridge-horizon=3 cisco-id=33.33.33.11 comment="LDP signaled VPLS" disabled=no export-route-targets=65530:3 import-route-targets=65530:3 name=VPLS_A pw-type=vpls rd=\
    65530:3
/routing bgp vpn
add disabled=no export.redistribute=connected .route-targets=65530:1 import.route-targets=65530:1 .router-id=VRF_A label-allocation-policy=per-vrf name=bgp-mpls-vpn-1 route-distinguisher=\
    65530:1 vrf=VRF_A
add disabled=no export.redistribute=connected .route-targets=65530:2 import.route-targets=65530:2 .router-id=VRF_B label-allocation-policy=per-prefix name=bgp-mpls-vpn-2 \
    route-distinguisher=65530:2 vrf=VRF_B
/routing filter rule
add chain=BGP_out rule=accept
/routing ospf interface-template
add area=backbone4 cost=1000 disabled=no interfaces=ether2 type=ptp
add area=backbone6 cost=1000 disabled=no interfaces=ether2 type=ptp
add area=backbone4 disabled=no interfaces=Loopback0 passive
add area=backbone6 disabled=no interfaces=Loopback0 passive
[oreggin@rtr1.CPE] >

Maybe misconfiguration, but I can’t figure out what or where. If you have any proposal, it would be appreciated.

[oreggin@rtr1.CPE] > /interface/vpls/print        
Flags: R - RUNNING; D - DYNAMIC
Columns: NAME, PEER, BGP-VPLS
#    NAME   PEER        BGP-VPLS
0 RD vpls1  10.0.10.13  VPLS_B  
1 RD vpls2  10.0.10.12  VPLS_B  
2  D vpls3  10.0.10.13  VPLS_A  
3  D vpls4  10.0.10.12  VPLS_A  
[oreggin@rtr1.CPE] > /mpls/forwarding-table/print 
Flags: L - LDP, P - VPN, V - VPLS
Columns: LABEL, VRF, PREFIX, NEXTHOPS, VPLS
 #   LABEL  VRF    PREFIX              NEXTHOPS                                                  VPLS 
 0 P    32  VRF_A                                                                                     
 1 P    33  VRF_B  10.0.12.0/29                                                                       
 2 P    34  VRF_B  b00b:10:11:12::/64                                                                 
 3 L    42  main   b00b::10:0:10:1     { nh=fe80::20c:42ff:fe53:1491%ether2; interface=ether2 }       
 4 L    39  main   10.0.10.1           { label=impl-null; nh=10.0.0.25; interface=ether2 }            
 5 L    40  main   10.0.10.12          { label=21; nh=10.0.0.25; interface=ether2 }                   
 6 L    41  main   10.0.10.13          { label=20; nh=10.0.0.25; interface=ether2 }                   
 7 L    37  main   10.0.0.0/30         { label=impl-null; nh=10.0.0.25; interface=ether2 }            
 8 L    38  main   10.0.1.0/30         { label=impl-null; nh=10.0.0.25; interface=ether2 }            
 9 V    29                                                                                       vpls1
10 V    28                                                                                       vpls2
11 L    43  main   b00b::10:0:10:12    { nh=fe80::20c:42ff:fe53:1491%ether2; interface=ether2 }       
12 L    44  main   b00b::10:0:10:13    { nh=fe80::20c:42ff:fe53:1491%ether2; interface=ether2 }       
[oreggin@rtr1.CPE] >

Thanks!

What’s new in 7.18rc2 (2025-Feb-21 12:50):
*) cloud - added “Back To Home Files” feature (additional fixes);
*) dhcpv6-relay - added option to create routes for bindings passing through relay (additional fixes);
*) disk - do not allow adding device in raid when major settings mismatch in superblock and config;
*) disk - fixed removing device from raid while resyncing;
*) ethernet - fixed issue with default-names for RB4011, RB1100Dx4, RB800 devices (additional fixes);
*) ethernet - fixed link-down on startup for ARM64 devices (introduced in v7.16);
*) l3hw - added initial HW offloading for VXLAN on compatible switches (additional fixes);
*) lte - added initial eSIM management support (additional fixes);
*) lte - fix R11e-4G modem initialization (introduced in v7.18beta4);
*) lte - fixed cases where the MBIM dialer could get stuck;
*) lte - fixed interface recovery in mixed multiapn setup for MBIM modems (additional fixes);
*) lte - improved initialization for external USB modems;
*) ptp - improved system stability;
*) qos-hw - fixed wred-threshold (introduced in v7.18beta2);
*) ssh - improved channel resumption after rekey and eof handling;
*) wifi-qcom - prevent AP from transmitting broadcast data unencrypted during authentication of first client;
*) winbox - added missing options under “System/Disk” menu (additional fixes);

Oh man, I started to upgrade my routers 5 minutes ago to RC1 :smiley:

Just 0.02$ … initial + fixes do not fit releasing stable version. That should be in 7.19beta.

It’s a blank install of CHR, so no rules, no filters, nothing. Simply doing bandwidth tests from the VM’s to my 2116 and to each other. I’ll have to see if I can get 7.16 or 7.15 to work, just for fun.

RPi5 is a Broadcom BCM2712 quad-core Arm Cortex A76 processor @ 2.4GHz. That’s better than the 1.4GHz quad-core processor in RB4011 and RB5009, the 1.7GHz processor in CCR2004, and the 2GHz processor in CRS526. The 2004 can bridge and route (fast path) 19Gbps (it obviously has more PCIe lanes to the switch from the CPU), so I would hope to get at least the full 6Gbps out of the CHR on the Pi and 10Gbps out of the Intel processor (4 cores at 3GHz).

And no device yet which supports this ?

I can’t find any LTE interface on my dozens of CCRs.
CCR owners don’t lose your hope and keep your spirits up

Of course not… until you plug in a LTE USB stick (when your CCR has an USB port).
Unfortunately there is no line with “*) bgp - improved stability;” in sight… that is what CCR users are hoping for.

@Mikrotik - since you just restored in this version the forgotten “/ip/route/check” feature for ipv4 (similar to “ip route get” in linux), why not complete the task and give ipv6 the same love ?
Thanks.

Hi mrz, any reason why MT still hide vpn6 afi from winbox?
If there any limitation should we know about?

My IPsec tunnels broke on my RB5009 with 7.18rc1. I had to disable the IPv4 forwarding fasttrack rule to fix it for now. I opened ticket SUP-180137.

Strange. There is not even any ipsec related change in rc1.

By the way, it is worth mentioning that the syntax between routing and routes is still incongruent:

[administrator@fischerdouglas] > /routing/bgp/connection/print where address-families=
ip     ipv6     l2vpn     l2vpn-cisco     vpnv4     vpnv6



[administrator@fischerdouglas] > /routing/route/print where afi=  
bad     ip4     ip6     l2vpn     l2vpn-cisco     l2vpn-link     link     mip4     mip6     vpn4     vpn6



  • “address-families=” vs “afi=”
  • “vpnv4” vs “vpn4”
  • “vpnv6” vs “vpn6”

If only Mikrotik would actually write in more than partial sentence or have a proper KB-like system for these questions… My only guess is the API changed are for internal use with REST API. I think REST API just proxies to API, but uses cached/pipelined connection (based on login in log)… in which case knowing a tagged API request was !empty might be useful. But just guessing.


I have ask several times about what modems this works with, no response, now half-dozen times. The lack of clarity around eSIM is quite annoying. From reading the docs, it seems like a working feature on something. If it’s nothing, then say that in docs! Since I read the docs, and eSIM came up in another thread, the eSIM docs don’t mention if the QR code had a $$1 at the end. Which, I think, means the

confirmation-code=

be required… and the $$1 part should NOT be in the

matching-id=
  • but it wasn’t clear at all… And working in theory here…


Now the bright spot is the new scripting changes are just wonderful. They made quick work of the theoretical problem eSIM activation codes use the $ dollar as the delimiter. So on the theoretical modem that support eSIM, you can cut-and-paste the eSIM code to CLI. This is possible by the new :deserialize delimiter=“$” specifically to deal with eSIM LPA format (with the new-ish /terminal/ask allowing cut-and-paste). See Interactively parsing eSIM Activation from LPA in QRCode... for example.

But there should be something like /ip/dhcp-server/setup for the eSIM. Or, Winbox4 could natively use camera to capture the QR code, too.

There it is
relay.png

Looks like this actually was a configuration error.
The “defconf: fasttrack” rule somehow ended up above the “defconf: accept in ipsec policy” and “defconf: accept out ipsec policy” rules. When I moved the fasttrack rule below those two rules (like they are in defconf) it started working again. Not sure if this is documented anywhere, but that’s what is required.

+1 , Yes i also notice this

Up

Up

Up