V7.20beta [testing] is released!

ETH1, running at 2,5Gbps? If yes, try either another port or limit eth1 to 1Gbps. See if makes some difference.

On eth1 there’s PPPoE wan at 2.5Gbps, eth1 out of bridge

On eth1 there’s PPPoE wan at 2.5Gbps, eth1 out of bridge

No queues, 7.19 stable same problem, simple conf from eth2 to eth8 and sfp in the bridge

Do a test: limit the autonegotiation to 1Gbps. I saw some weird things with this eth1 at 2,5Gbps, but never had the time - or hardware - to debug further. Just to see what happens.

I did a test by doing a btest directly from a hap connected via ethernet and it seems that only the TCP is affected by the problem, when I can I will set the port to 1G.

Edit I have also container with a veth in bridge, make a speedtest without problem

*) container - support for direct access to hardware devices;

Awesome!!! Thank you for implementing this feature :slight_smile:

“@“ is ASCII 64, so it looks like someone used the wrong function in the output.

Nice seeing support for “BGP advertise IPv4 prefix with IPv6 nexthop” (RFC 5549, RFC 8950) being added to the ROS 7.20 release. :slight_smile: Looking forward the upcoming beta and RC’s.

With all the /container changes in this release, perhaps it could use a TAB in WinBox for Status — or something. It has way too many fields now. Worse some “more immutable” config items are mixed with changeable configuration.

Further, when you create a new container… I’m not sure “Remote Image” half down is going to indicate to newbie that’s where a Docker image tag would go. Along with empty status information adding more clutter.

Anyway all the new features get lost in the, now, even worse UI.

At least in WinBox4

*) container - allow to mount individual files, not just directories;

I could not get this to work. I tried this with Caddy server since there instruction tell you to map /etc/caddy/Caddyfile to a file in their docker instructions. So with the new “file-level mount”, that should be possible. But it did not pick it up and used the file already at location. I delete the default file on container - still it did not pick up the single-file mounted version. Only when I mounted the directory did it work.

Update - I re-rested using a fresh image - at first startup - the file is linked if src and dst both map filename), maybe using “file-level mounts” is not possible after image has been created. But I saw it working, with fresh image/container at least.

Related…
In WinBox4 at least, it does not let you set a mount. Well, it sets one, but the clears it on OK/Apply. CLI works to set the mount.

waiting for RFC 4659, BGP-MPLS IP Virtual Private Network (VPN) Extension for IPv6 ( 6VPE )

I moved the wan to eth8, and enabled vlan filtering, no problem at the moment

https://eolo.speedtestcustom.com/result/0d437dc0-4c10-11f0-b6e6-5da1ee06cf86

where ? couldnt find it in NAT action ?

CLI:

What’s new in 7.20beta4 (2025-Jun-13 11:38):

*) bfd - fixed socket leak;
*) bgp - fixed origin cleanup for mpls-vpn (introduced in v7.20beta2);
*) bgp - fixed warning when instance is not active (introduced in v7.20beta2);
*) bgp - fixed withdraw when input.accept-nlri is non-existent;
*) bgp - migrate correctly router-id and ASN to instance (introduced in v7.20beta2);
*) bridge - added dynamic tagged entry named "switch-cpu" in scenarios where the same VLAN spans multiple switch chips or is used on both HW and SW ports (additional fixes);
*) btest - properly close unsuccessful TCP test sockets;
*) certificate - added "Amazon Root CA 1" to built-in root certificate authorities store;
*) console - added prompt to /disk/format command;
*) console - fixed /file/find not recursive by default (introduced in v7.20beta2);
*) console - fixed /file/read command (introduced in v7.20beta2);
*) console - improved visuals for hexadecimal strings;
*) console - prioritize directory specific parameters and hide rarely used ones in print autocomplete (additional fixes);
*) container - added repull command;
*) container - can use KVM (x86 and arm64) in container QEMU for faster virtualization;
*) container - fixed QEMU VM to host bridge;
*) container - stability improvements (additional fixes);
*) dhcp-client - show warning if DHCP client is configured on dot1x server port;
*) dhcpv4-client - allow specifying DSCP of outgoing packets;
*) dhcpv4-client - show "custom-hostname-suffix" and "custom-source-mac-address" properties if set;
*) dhcpv4-server - added "add dns" step to setup wizard;
*) discovery - improved LLDP Power via MDI TLV with 802.3bt specific field support;
*) discovery - report router as "CAPsMAN" on MNDP under "running" parameter;
*) disk - show error when file based block-device uses a mountpoint to be unmounted;
*) dns - fixed memory leak when static CNAME record was matched;
*) evpn - fixed auto ID setting (introduced in v7.20beta2);
*) evpn - fixed enable/disable handling (introduced in v7.20beta2);
*) evpn - fixed instance handling (introduced in v7.20beta2);
*) evpn - fixed MACIP address decode (introduced in v7.20beta2);
*) evpn - fixed missing RD (introduced in v7.20beta2);
*) evpn - fixed route print query by EVPN AFI (introduced in v7.20beta2);
*) file - fixed console completion not showing all files (introduced in v7.20beta2);
*) file - fixed duplicate in WinBox Files menu when sharing a file in a folder (introduced in v7.20beta2);
*) iot - LoRa netid filters now can be configured as a "range";
*) iot - LoRa stability improvement (additional fixes);
*) iot - LR8G/9G firmware update (additional fixes);
*) ip-service - fixed "print count-only interval" when dynamic entries are added (introduced in v7.19);
*) ip-service - fixed setting services by name (introduced in v7.19);
*) ip-service - show service name "nfs" for port 2049;
*) ipsec - move raw RSA keys to /ip/ipsec/key/rsa;
*) ipv6 - fixed "auto-link-local" feature on WireGuard interface;
*) isis - added passive parameter for interface templates;
*) l2tp-ether - fixed interface creation/removal process;
*) lte - added "remove-sent-sms-after-send" option to automatically delete sent SMS messages;
*) lte - added modem-init string response to system log;
*) lte - added show-capabilities eSIM presence detection for MBIM modems;
*) lte - added support for R11e-LTE6 v039 firmware release;
*) lte - do not dial further if modem detects eSIM without profiles;
*) lte - exit LTE scan if modem reconfigured;
*) lte - fallback to RA for global IPv6 if unattained via AT channel (resets on config change);
*) lte - fixed eSIM management function for mmips and mipsbe architecture CPUs;
*) lte - fixed eSIM provisioning for servers that do not send content-length in the HTTP response;
*) lte - fixed inappropriate LTE interface inactive flag shown during modem initialization;
*) lte - fixed progress message for R11e-LTE modem firmware-upgrade;
*) lte - improved EC200A-EU firmware-upgrade stability;
*) lte - improved SMS sending stability over MBIM protocol;
*) macvlan - allow creating macvlan interfaces on all interfaces with a MAC address;
*) mpls - improved stability when handling VPLS packets;
*) netinstall-cli - improved client device architecture detection;
*) netwatch - added "early-success-detection" and "early-failure-detection" properties for ICMP probe;
*) port - improved port status handling at unexpected device removal;
*) ppp - added "dhcpv6-use-radius" PPP profile feature that enables "use-radius" option on dynamically created DHCPv6 servers;
*) ppp - added "remote-ipv6-prefix-reuse" PPP profile feature that allows to advertise same prefix on multiple VPN clients at the same time;
*) romon - changed default "disabled=yes" to "disabled=no" under /tool/romon/port;
*) romon - improved error message;
*) route - fixed destination ordering for SNMP;
*) route - fixed SNMP probing of IPv6 routes;
*) route - improved stability;
*) route - update router ID when disabled address is removed;
*) routing-filter - added sync command;
*) sfp - added sfp-power-class and sfp-max-power monitor values for QSFP (additional fixes);
*) smips - reduced package size, removed hotspot feature and provide it as a separate package;
*) ssh - show user public key fingerprint under /user/ssh-keys;
*) switch - fixed advertise and speed settings for ether1 on RB5009 (introduced in v7.20beta2);
*) switch - fixed egress-rate on QSFP ports;
*) switch - reset all Ethernet counters on reset-counters command on QoS Port menu;
*) system - fixed certain notifications (e.g. kid-control activity, connection tracking table) (introduced in v7.17);
*) veth - added dhcp=yes/no property to be able to easily run a container in LAN, runs a special dynamic dhcp-client on interface and sets acquired address/gateway/dns to in-container interface;
*) veth - added mac-address property;
*) veth - make veth interface MAC address stable in both RouterOS and container (container-side MAC incremented by +1 from RouterOS-side interface);
*) vrrp - added "conntrack-port" and "mode" settings for "sync-connection-tracking";
*) vxlan - improve stability when learning enabled interface used with EVPN (introduced in v7.20beta2);
*) webfig - fixed issue where legacy WebFig login page was used;
*) webfig - improved screen reader support for wifi fields in Quickset;
*) wifi - increased wifi scan list;
*) wifi-qcom - accept VLAN-tagged packets from clients with vlan-id;
*) wifi-qcom - fixed beacon loss issues and improved stability for IPQ-6018;
*) wifi-qcom - improved regulatory compliance;
*) winbox - added "Reselect Time" for wifi;
*) winbox - added "Digest Algorithm" under "System/Certificates" menu (additional fixes);
*) winbox - added "Note" field in LTE Firmware Upgrade;
*) winbox - fixed "Last Topology Change" for bridge port monitor;
*) winbox - fixed crash when opening entry in switch rule menu (introduced in v7.20beta2);
*) winbox - improved byte type field representation;
*) winbox - removed duplicate mounts option;
*) wireless - changed CLI snooper column name "freq" to "channel";

It’s been a while since Normis announced wifi-qcom fixes. I did not expect a stable release soon, does this beta4 already including those fixes?

Are those tags to imply fixes since 7.20beta2
Beta2 wifi section!
*) wifi - added tr069 support for wifi interfaces;
*) wifi - avoid picking 5GHz channels by default which are unlikely to be supported by clients, can be overridden with channel.deprioritize-unii-3-4 (CLI only);
*) wifi - restart CAPsMAN only on significant configuration changes;

Sorry my bad, I read the above line which was attributing to the previous line.

how does this work ? veth still needs to be as port in bridge and DHCP-server needs to be running on bridge interface ?

Ah, nice… Some of my issues (and a really old feature request) fixed. Thanks!

Still wondering though - what was @druvis referencing here with “High Definition”?