v7.19rc [testing] is released!

Send us supout rif file and details on the issue.

Support for eSIM functionality has been added in this RouterOS release, and you can already try it out, if you have some physical eSIM already available.

What’s a physical eSIM?

A piece of cardboard with QR code on it i guess:)

Not exactly: https://esim.me/

This is actually pretty nice. Did not know physical eSIM is a thing!

For the ones still wondering:
“connections” :
2025-04-30-0001-01-conn.png
“ports”:
2025-04-30-0001-01-ports.png

Thank you Znevna! Maybe I am naive but I still believe some day Mikrotik does a kind of extended changelog which explains changes in detail like this.

Maybe give https://sysmocom.de/products/sim/sysmocom-euicc/index.html a try as well :wink:

On CCR2116 with large number of peers(~1000) ipsec becomes unresponsive after reboot. Single IPSec process saturates single core and neither site to site tunnels nor road-warrior users are able to connect. IPSec tabs in Winbox also experience significant delays when it comes to refreshing information.
The workaround is to kill all IPSec connections, disable all peers and then re-enable in batches of 100-150 every 30-45s. After that, IPSec works as expected.

Looks like you pushed a release candidate (beta) to production. Probably not the smartest move.

Nobody tests these releases in real world scenarios, so we have beta testers that risk bricking their production routers for that.
They receive a T-Shirt every two years. (With the classic “We couldn’t reproduce the issue on our side” , obviously.)

Just reporting. That issue has been present in RouterOS on CCR2116 since at least 7.12.1 along with few others (like for example ipsec crashing after opening installed-sa tab in winbox).

Yeah the tunnelling aspects Wireguard/IPSec/OpenVPN in RouterOS need some serious attention. While they work (generally to some degree), they have all had bugs, performance regressions and other issues since early 7.x series and continue to this day. If your doing anything other than slight connectivity through those tunnels to your router its a pain in the ass. It’s forced me to stop terminating things on the router and instead use a dedicated x86 host to terminate tunnels on and then route the traffic via the firewall so I still have granular control.

We’ve had no stability issues whatsoever with either WireGuard or IPsec for a long time now. IPsec parallel throughput with hardware offload on the high-end models is really solid, with no noticeable drop in performance as long as you stay within the recommended connection limits. The only limitation is the lack of VTI support, though that’s mostly a matter of configuration.

Please contact us and send your supout rif file after the issue. Does the same happens if you monitor installed sa using cli ?

Thank you :).

Larsa, dont they teach that at IT school. Use the latest beta firmware for production!
Maybe they took that advice when running the Spanish electrical grid :wink:

On an AP running nothing but wireless, dhcp keeps popping up as a dynamic port (server), what’s the reason there if it’s not configured?

It’s part of “all” in RN sentence, and it’s a “connection”, not dynamic port (server)/“listener” in this scheme. :wink:

Essentially its “netstat” rendered in RouterOS