BFD has been broken before without related topic in the changelog. Either the BFD maintainer does not keep changelog entries very well, or it gets broken by totally unrelated changes.
What is still worrying is that there apparently is no regression test suite. @mrz claimed there was no problem and he could make BGP connects without issue, but apparently the setup where he tests that has no BFD. Seems easy to enable that at least on a link in a test network used to validate new versions before release…
When @kleshki had not pointed this out, 7.22 would probably have gone into release with this serious and dangerous breakage…. well, it can still happen of course.
When using a "normal" ACME client (e.g. certbot on linux), it pulls 3 files when getting new/refreshed certificate: private key, certificate file and "full chain" certificate file. One should use key file and full chain certificate file in server environment, not the "simple" certificate file.
I see from the updated documentation that the default rules will be gone, and the order would be specified by /routing settings set policy-rules=. This is much better and solves the export/import problem.
It seems that user defined rules can be inserted at only one position in the list. Which probably means that users can still create routing rules with the new actions and flags (that's why WinBox compatibility was updated in rc2), so that when they want custom routing rules inserted at different locations (two lookup rules surrounding mangle for example), they would remove some of the pre-defined items from policy-rules, and insert them back as rules under /routing rule?
That seems to be a bad solution even compared to what we have now, as it defeats flexibility previously given. It is probably better to go on with what is now and accept the breaking change, rather than stop a good feature to be released
Probably what currently available in rc2 can easily be replicated by setting policy-rules=user (and nothing else), then manually adding back the beta/rc1/2's default rules to /routing rule in whatever order you wish? I don't think there is any loss of flexibility.
EDIT: of course, the rules must be populated first before switching to policy-rules=user, otherwise IP connection to the router will be loss .
How is everyone’s wiregaurd speeds after upstream updates? I noticed that speeds droped for me in half but only in one direction, so im getting 1000/500, it was 1000/1000 before just fine.
I like to new approach to exposing the "builtin route rules".
I notice the docs also were updated to use "Marvell Presta" instead of long (sometime partial) list of models. This seems like a good change for doc readability. But tiny suggestion on this... is the table of Marvell Presta features include whether it has PTPv2 support, since not all models (AFAIK) support PTPv2. Similar with QoS on switches. There still too many tables to cross-reference on the switch chip differences. See Marvell Prestera switch chip features - RouterOS - MikroTik Documentation with link to other pages:
@mrz any insight on IPsec VTI if this would see the light of the day in this release or future release and also do you guys consider sdwan in the future most of the tech is already available in ROS afaics