V7.25beta [development] is released!

It would make sense for it to be a beta with ONLY the fix,
but so much has changed, it wouldn't make the slightest sense.
It wouldn't be clear if the malfunction was due to the fix
or the other hundred things that have changed.

A terrible example.

It was Statler or Waldorf?

Well, can I at least complain?
Since I'll be forced to use WinBox 4 in the future,
at least don't take away the need of complaining about serious things.

And I'll stop HERE about WB4, I'll report everything in the WinBox 4 topic in due time.

I see it this way: the more people need to use WB4 - the more feedback is going to come in Winbox release topics - and help to improve WB4.

Stable is out 7.24.2 [stable] is released!

Can we have a little more detail regarding this? A channel switch occurs at every radar detection event as far as I know.

IPsec XFRM interface support?! So much for my free time this weekend. Time to spin up the lab!

Well this clarifies it:

https://mrncciew.com/2014/10/29/cwap-channel-switch-announcement/

Very Good!

Now this is the spirit!

Don't want to spoil the "fun", but;
*) ipsec - add XFRM interface support;

does exactly what it says and nothing more.

very useful, thanks!

It applies to all mlx4/5 based NICs?

We've already seen, where this feedback goes...

Hi, @normis, where is a feedback with 50+ WB4 issues?

As you can see in Winbox changelogs, issues are being fixed since 4.0beta1, not all issues can be fixed easily. This is the wrong topic for that. Please discuss Winbox in the appropriate place.

It was in fact, over 3 hours, not literal minutes. 3 hours that you gave bad actors for free.

The real question is, have you upgraded? All good?

And there is only very rudimentary documentation, no idea how that would have to be configured...

And for everyone who's been asking for route-based VPN (aka "VTI") support, here it finally is (Yeaaah! :smiley: ):

What's new in 7.25beta3 (2026-09-02):
*) ipsec - add XFRM interface support;

The main difference compared to old-style VTI is really just how the local interface is handled and tied to the IPsec policies/SAs. On the wire it's still standard IPsec, so both approaches are fully interoperable and the remote side doesn't need to care whether you're using VTI or XFRM locally.

XFRM is basically just a more flexible way of doing route-based IPsec on Linux.

Good overview here:

ipsec - add XFRM interface support;

How use?

Probably together with the new/ip/ipsec/policy/group section. Someone has to try out.