v7.2rc2 and v7.2rc3 is released!

RouterOS version 7.2rc3 has been released “v7 testing” channel!

Before an upgrade:

  1. Remember to make backup/export files before an upgrade and save them on another storage device;
  2. Make sure the device will not lose power during upgrade process;
  3. Device has enough free storage space for all RouterOS packages to be downloaded.

What’s new in 7.2rc3 (2022-Jan-28 16:33):

*) bridge - fixed filter and NAT “set-priority” action;
*) queue - fixed traffic processing (introduced in v7.2rc2);

What’s new in 7.2rc2 (2022-Jan-28 11:00):

*) arm - fixed “shutdown” command on hAP ac^2;
*) bgp - fixed routing table and BGP configuration order in export;
*) bluetooth - disable scanning by default;
*) bridge - added fast-path and inter-VLAN routing FastTrack support when vlan-filtering is enabled;
*) bridge - fixed bridge filter and NAT rules on ARM64 and TILE devices;
*) capsman - improved stability when running background scan on CAP;
*) clock - properly notify all instances about time changes;
*) conntrack - properly detect helper status;
*) console - improved console responsiveness when processing received characters;
*) console - updated copyright notice;
*) crs3xx - fixed QSFP+ interface LEDs;
*) crs3xx - fixed optical SFP+ linking (introduced in v7.2rc1);
*) crs3xx - improved SFP+ interface linking after reboot for CRS312 device;
*) crs3xx - improved SFP+/QSFP+ link stability for CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (introduced in v7.2rc1);
*) defconf - made “192.168.188.1/24” the default LAN IP address for LTE CPE devices;
*) dhcpv4-server - remove dynamic leases when server configuration is removed;
*) dot1x - added “server-fail-vlan-id”, “guest-vlan-id” and “reauth-timeout” settings for dot1x server;
*) dot1x - added “src-address”, “src-mac-address” and “src-port” settings for dynamic switch rules;
*) dot1x - added NAS-Port-ID attribute for RADIUS Access-Request;
*) firewall - improved system stability when using address lists (introduced in v7.2rc1);
*) hotspot - fixed memory leak on every web page loading;
*) hotspot - fixed web page loading using HTTPS;
*) ike2 - ignore “INITIAL-CONTACT” payload on responder when “send-initial-contact” is disabled;
*) interface - fixed minor memory leak when interface or connected route is changed;
*) l3hw - added HW offloaded FastTrack support for inter-VLAN routing;
*) l3hw - fixed HW offloaded NAT;
*) leds - fixed user LED on RB750Gr3;
*) log - include message also in e-mail body;
*) lora - fixed “antenna-gain” parameter unit;
*) lte - added 3 APN profile support and APN name re-using on R11e-LTE6;
*) lte - added MAC address and IPv6 LL address persistence after reboot on EG12 and EG18 modems;
*) lte - added class based support for configless RNDIS LTE modems;
*) lte - do not show external antenna selector on devices that does not support it;
*) lte - fixed IPv6 address addition after startup on R11e-LTE6;
*) lte - fixed possible timeouts when sending SMS in LTE only mode on R11e-LTE;
*) lte - fixed support for Sierra MC7710;
*) lte - fixed support for Telit 960;
*) lte - improved stability on “+EGMR” response in MBIM mode;
*) lte - improved support for sending/receiving SMS in LTE only mode on R11e-LTE6;
*) lte - properly recognize MBIM modem in USB port as LTE on Chateau 5G;
*) ospf - added “ptmp-broadcast” interface type (compatible with RouterOSv6 PTMP type);
*) ospf - convert ospf “static” redistribute to “static,dhcp,modem,vpn” after update from RouterOS v6;
*) ospf - fixed MD5 authentication;
*) ospf - fixed NBMA hello’s not being sent if priority is set to 0;
*) ospf - fixed default type-3 LSA’s not being injected to stub area;
*) ospf - fixed incorrect LSA types when changing area types;
*) ospf - fixed neighbor election failure;
*) ospf - improved logging;
*) ospf - improved stability on OSPFv3 instance disabling;
*) ovpn - improved UDP session handling;
*) ppp - fixed AT+CPIN chat when SIM PIN is specified;
*) pptp - show insecure connection warning on dynamic interfaces;
*) qsfp - correctly display auto-negotiation status;
*) queue - improved system stability when processing traffic;
*) route - fixed “suppress-hw-offload” update;
*) route - fixed router’s LSA for PTP networks;
*) route - fixed routing configuration export on SMIPS devices;
*) route - improved routing table print speed;
*) route - show OSPF and RIP specific attributes in “/routing route” table;
*) route-filter - fixed “return” action;
*) route-filter - fixed complex matchers with “|| or and &&”;
*) route-filter - fixed incorrect invert-match configuration upgrade from RouterOS v6;
*) route-filter - fixed range conversion after update from RouterOS v6;
*) rpki - made RPKI verify non-strict, introduces new state “unverified”;
*) rpki - show expire timer;
*) smb - fixed SMB2.0 disk size reporting;
*) snmp - added SFP vendor name to optical table;
*) snmp - added support for “ipv6AddrPrefixTable” and “ipv6RouteNumber” OID’s;
*) snmp - allow two level nesting for vlan, bonding speed query;
*) system - fixed license loss on some RB1100Dx4 and RB4011 devices;
*) traffic-flow - do not handle NAT events when “nat-events” is disabled;
*) traffic-generator - fixed transmit speed for multiple asymmetric streams;
*) usb - fixed display of incorrect port count for USB serial ports;
*) vlan - fixed improper VLAN priority addition for routed packets;
*) vxlan - allow unsetting “group” and “interface” properties;
*) webfig - do not show side menu if WebFig is disabled by skin;
*) winbox - added “Disconnect Notify” checkbox to “Interface/OVPN Client” menu;
*) winbox - added “Freq. Usage” and “Scan” buttons for WifiWave2 interfaces;
*) winbox - added “Ignore Missing” selector to “System/Packages” menu;
*) winbox - added “Routing Table” parameter for IPv6 routes;
*) winbox - added “VPN” tab to “Routing/BGP” menu;
*) winbox - added “VRF” parameter to “IP/Services” menu;
*) winbox - added “comment” parameter to “User Manager/Users” menu;
*) winbox - added MLAG support;
*) winbox - added SHA256 and SHA512 “Auth” values for OVPN menu’s;
*) winbox - added ZeroTier support;
*) winbox - added explicit “Upload” and “Download” names for “Bucket Size” parameters under “Queues” menu;
*) winbox - allow setting “Interface” parameter for 100G LED types;
*) winbox - do not show “Antenna Scan” button on devices that do not support it;
*) winbox - fixed “action” field in “IP/Web Proxy/Access” menu;
*) winbox - fixed CHR License renewing process;
*) winbox - fixed content filtering in “Tools/Packet Sniffer/Packets” menu;
*) winbox - fixed entry order in “Tools/Packet Sniffer/Packets” menu;
*) winbox - made OSPF interface type names consistent between CLI and GUI;
*) winbox - properly save “IPv6/Settings” menu in session file;
*) winbox - renamed “MBPS” to “Mbps” value unit name in “Tools/Traffic Generator” menu;
*) winbox - show “H” flag for offloaded connections in “IP/Firewall/Connections” menu;
*) winbox - show “System/SwOS” menu only on boards that have dual boot;
*) winbox - sort “Address List” parameter values alphabetically in “IP/DHCP Server/Leases” menu;
*) wireless - improved wireless connection stability during background scans;
*) wireless - fixed interface initialization on Metal 2SHPn;
*) x86 - added support for Intel E810 NIC;
*) x86 - made “no” the default value for “disable-running-check” ethernet parameter;
*) x86 - properly distinguish multiple NICs that share the same PCI bus number;
*) zerotier - made MAC and MTU values read-only;

To upgrade, click “Check for updates” at /system package in your RouterOS configuration interface, or head to our download page: http://www.mikrotik.com/download

If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while router is not working as suspected or after some problem has appeared on device

Please keep this forum topic strictly related to this particular RouterOS release.

*) vxlan - allow unsetting “group” and “interface” properties;

The “group” and “interface” properties are (unexpectedly) unset on upgrade from 7.2rc1 to 7.2rc2.

Before upgrade:

/interface vxlan add group=224.0.0.188 interface=bridge-lan name=vxlan-iot port=8472 vni=123

After upgrade:

/interface vxlan add mtu=1400 name=vxlan-iot port=8472 vni=123

Please fix the IPv6 firewall connection tracking problems with the queues enabled, there have been reports on the forum for months about this problem.
All 7.1+ are affected by this problem and it prevents us from using the queues together with the IPv6 firewall, all IPv6 packets are dropped because they result in connection state invalid

Upgraded from 7.1.1 and my wireguard connections no l longer worked. No connection was being made and disabling and reenabling the interface had no effect. Rolled back to 7.1.1 and all was well again. Literally nothing in the config changed between both versions.

EDIT: realized I didn’t state what platform I am using. I am running an RB5009.

Still no ZeroTier for mips…

On my CCR1009 — Just loaded 7.2rc2 and that went very smoothly
so far everything is working as I expect ---- CPU is stable … WireGuard is functioning and to my surprise its a bit faster now

Queues are totally broken in this release (for me)

  • RB4011


  • PPPoE over VLAN


  • Bridge vlan filtering enabled

Had 2 queues in the queue tree, one for inboud, one for outboud. I get no Internet when they’re enabled. Ping from the router tells me: “rejected packet” or something like that. LAN traffic works.

Creating a simple queue seems to work but as soon as I set Max Limit, Internet connection drops. Removing Max Limits makes it work again.

I tried other queue types besides Cake and I have the same behavior.

Here’s my original queue config which was working for several BETAs and RCs:

/queue type
add cake-atm=atm cake-bandwidth=50.0Mbps cake-flowmode=dual-srchost cake-overhead=46 kind=cake name=cake-out
add cake-atm=atm cake-bandwidth=100.0Mbps cake-flowmode=dual-dsthost cake-overhead=46 cake-wash=yes kind=cake name=cake-in

/queue tree
add bucket-size=0.002 name=wan-in packet-mark=wan-in-pk parent=global queue=cake-in
add bucket-size=0.002 name=wan-out packet-mark=wan-out-pk parent=global queue=cake-out

The same issue with wireguard/
RB5009

Lots of fixes but still no BFD :frowning:
That means no chance to test it in our network.

*) vlan - fixed improper VLAN priority addition for routed packets;

Confirmed. My VoIP registrations no longer fail.

Still has the IPv6 over Wireguard issue as described in http://forum.mikrotik.com/t/wireguard-client-minimally-android-ios-ipv6-traffic-not-passing-through-tunnel/153452/29

*) bridge - added fast-path and inter-VLAN routing FastTrack support when vlan-filtering is enabled;

That could explain http://forum.mikrotik.com/t/fast-track-not-working-was-how-to-test-bandwidth-properly/154902/20

Having problems to connect winbox and no internet access.
Connected to webfig through wifi, where i made the rollback to 7.1.1 and upgrade to 7.2rc1.

Short question, how do you roll back? Netinstall or just dumping a old npk on the device?

both would technically work. Easiest way is to change your update repo back to stable and then download and install 7.1.1.

FWIW:
Hex on 7.1.1
mAP on 7.2rc2
wireguard active between both and running

*) bridge - added fast-path and inter-VLAN routing FastTrack support when vlan-filtering is enabled;
*) l3hw - added HW offloaded FastTrack support for inter-VLAN routing;

I have some difficulties to have this working.
On which devices should this work ?
RB4011 ? RB5009 ?
Many thanks !

On my crs3xx devices seems to have broken access to my management interfaces (dhcp client on the bridge). The switches work but I can’t manage them except through a console cable. ccr1009, cap ac, crs112, and chr working fine.

I think this has to do with some of the changes to vlan filtering. **maybe not - disabling it made no difference **

When you have a device with more than the 16MB flash found on low-end devices, always partiton the flash in 2 partitions so you can copy your existing install to the other partition before doing any upgrade.
Then you can switch back (and forth) between those versions in case of problems, to compare things (did it work in the previous version?) etc.

Winbox-Zerotier Instance is called “Wireguard” in the Window-Capture