v7.6rc is released!

RouterOS version 7.6rc1 has been released “v7 testing” channel!

Before an upgrade:

  1. Remember to make backup/export files before an upgrade and save them on another storage device;
  2. Make sure the device will not lose power during upgrade process;
  3. Device has enough free storage space for all RouterOS packages to be downloaded.

What’s new in 7.6rc1 (2022-Oct-04 18:54):

Changes in this release:

*) certificate - improved certificate management, signing and storing processes;
*) dns - fixed resolving of cached CNAME records (introduced in v7.6beta10);
*) lte - added support for Neoway N75-EA;
*) snmp - improved stability when receiving bogus packets;
*) vxlan - fixed multicast group address validation (introduced in v7.6beta10);
*) wifiwave2 - fixed RADIUS accounting after fast-transition;
*) winbox - added “Reset Traffic Counters” button for all interfaces;

Other changes since v7.5:

*) bgp - added support for BGP advertisement displaying (CLI only);
*) bgp - fixed reporting of session uptime;
*) bgp - improved session establishment speed after bootup;
*) bonding - fixed ARP monitor packets with bond’s MAC address;
*) bonding - improved interface stability on slave configuration changes;
*) bonding - reduce “actual-mtu” according to interface “l2mtu”;
*) branding - execute “autorun.scr” file when installing branding package;
*) capsman - fixed RADIUS accounting when EAP is used;
*) certificate - fixed SHA1 certificate name lookup;
*) certificate - improved certificate management, signing and storing processes;
*) certificate - restricted maximum retry attempt window for Let’s Encrypt certificate to 60 minutes;
*) container - added “start-on-boot” parameter for automatic container startup;
*) container - allow changing container related parameters while it is running;
*) container - fixed usage of non-authenticated registries;
*) dhcpv4-server - fixed matcher functionality;
*) dhcpv4-server - fixed RADIUS accounting for local leases;
*) dhcpv4-server - improved service stability when removing dynamic leases;
*) dhcpv6-client - fixed false error status reporting when server offers T1 or T2 value as 0;
*) dns - added “match-subdomain” option for static entries (CLI only);
*) dot1x - fixed incorrect error when using “mac-auth”;
*) ethernet - added “5Gbps” option for speed setting;
*) firewall - added “src/dst-address-type” parameter under “IPv6/Firewall/Mangle” menu;
*) firewall - disable IRC NAT helper on upgrade;
*) firewall - fixed IPv6 filtering with “in/out-interface” matcher that is in VRF;
*) firewall - fixed IRC NAT helper (CVE-2022-2663);
*) firewall - fixed usage of “netmap” action for IPv6 source NAT (CLI only);
*) health - fixed fan speed and temperature reporting on CCR1072;
*) health - improved voltage reading on RBmAP-2nD;
*) hotspot - fixed service initialization when HTML directory configured on an external disk;
*) hotspot - fixed SSL usage on all HotSpot pages;
*) hotspot - improved stability when receiving bogus packets;
*) hotspot - limit maximum allowed connections based on free RAM resources;
*) hotspot - removed “routerboard.com” URL from default HotSpot advertise;
*) interface - added warning when interface has configured “mtu” higher than “l2mtu”;
*) ipsec - added “invalid-packets” counter for Installed SA’s menu;
*) ipsec - fixed packet processing by hardware encryption engine on MMIPS devices;
*) l3hw - added “l3hw-settings” sub menu under the switch menu (CLI only);
*) l3hw - added support for IPv6 route offloading (disabled by default);
*) l3hw - fixed “H” flag presence for accelerated connection tracking entries;
*) l3hw - fixed possible packet loss when using HW offloaded NAT;
*) l3hw - improved connected host offloading on startup;
*) l3hw - improved connected IPv6 host offloading when routing table is nearly full for 98DX224S, 98DX226S, and 98DX3236 switch chips;
*) l3hw - improved system stability;
*) l3hw - made route offloading selection work only on unicast;
*) lte - added interface name in MTU debug logging message;
*) lte - added periodic IPv6 RS to trigger IPv6 adress acquisition for non-MBIM modems;
*) lte - added support for Neoway N75-EA;
*) lte - added support to perform FOTA upgrade from local file for EG12-EA, EG18-EA, RG502Q-AE, EG06-A, EP06-A modems;
*) lte - disabled RPLMN on Chateau 5G;
*) lte - fixed at-chat on Telit FN980m;
*) lte - fixed re-attaching on PS detach for MBIM modems;
*) macsec - added configuration support with VLAN, ARP, DHCP and bridge tagging/untagging;
*) macsec - added logging support with “debug” and “dot1x” topics;
*) macsec - added support for MTU and L2MTU;
*) macsec - fixed interface after Ethernet link down;
*) macsec - fixed interface statistics and missing properties;
*) macsec - fixed interface status;
*) macsec - fixed multiple interface creation on different Ethernet ports
*) macsec - improved interface stability;
*) macsec - improved system stability for TILE and RB5009 devices;
*) macsec - removed interface from SMIPS devices;
*) mac-telnet - respect interface MTU setting when sending packets for MAC-Telnet and MAC-WinBox;
*) netwatch - fixed string variable values in script;
*) ntp - improved initial synchronization speed after bootup;
*) ospf - added SHA hashing for authentication;
*) ospf - fixed area “no-summary” setting;
*) ospf - fixed checksum calculation;
*) ospf - fixed displaying of VRF interface in related logs;
*) ospf - fixed transmit of LSA/ACK’s on p2p interfaces;
*) ospf - improved logging when invalid configuration is detected;
*) ospf - refresh OSPFv3 interface configuration when IPv6 network becomes available;
*) ovpn - added IPv6 support;
*) ovpn - added IPv6 support for ethernet mode;
*) ovpn - added VRF support for client;
*) ppp - fixed memory leak;
*) ppp - improved service stability when multiple users disconnect simultaneously;
*) pppoe - fixed MRU negotiation even when it is set to 1500;
*) qsfp - added interface temperature warnings and shutdown;
*) queue - improved stability for CAKE type queues;
*) radius - require “policy” policy for “login” service configuration;
*) rip - fixed passwordless MD5 authentication;
*) route-filter - fixed filtering for multiple community routes;
*) route-filter - fixed memory allocation when moving entries;
*) route - fixed disappearance of inactive static routes after upgrade;
*) route - fixed memory leak;
*) routerboard - return router’s short name in “model” parameter;
*) routerboard - set “Delete” as default key to enter booter menu (“/system routerboard upgrade” required);
*) serial - added support for newer PL2303 serial controllers;
*) sfp - improved QSFP/SFP interface stability for 98DXxxxx and 98PX1012 switches;
*) sms - added “status-report-request” parameter for “send” command;
*) sms - fixed handling of SMS send attempts on unsupported modems;
*) snmp - improved retrieval of routing related OID’s;
*) ssh - increased key generation timeout;
*) sstp - added IPv6 support (CLI only);
*) sstp - added VRF support for client;
*) supout - added tr069-client section;
*) supout - removed duplicate “bridge-controller” section;
*) switch - improved traffic forwarding at 5Gbps rate for 98DX8525, 98DX4310 switches;
*) system - renamed error messages when trying to edit or remove dynamic entries;
*) tile - improved system stability when processing packets;
*) tr069-client - do not allow “:” symbols in username;
*) user-manager - accept any username for outer authentication;
*) user-manager - added “comment” parameter for batch user creation;
*) user-manager - added support for multiple accounting sessions;
*) user-manager - added variables to print profile name and end time in voucher templates;
*) user-manager - allow specifying router’s address as subnet;
*) user-manager - fixed “migrate-legacy-db” command;
*) user-manager - fixed session expiry when it is stopped by Disconnect-Request;
*) user-manager - forced username verification against client’s certificate for EAP-TLS;
*) user-manager - use “Class” attribute to associate user’s accounting session;
*) user - removed unused “dude” policy;
*) vrrp - fixed connection tracking synchronization on MMIPS and MIPSBE devices;
*) vxlan - added IPv6 support for remote VTEPs (only IPv4 or IPv6 will be used at the same time, use “vteps-ip-version” property on VXLAN interface to change the version);
*) w60g - improved system stability (introduced in v7.5);
*) webfig - fixed creation of new IPv6 routes;
*) webfig - fixed displaying of “Last Seen” parameter under “IP/DHCP Server/Leases” menu;
*) webfig - fixed hex input for “Host Uniq” field;
*) webfig - fixed unsetting of “endpoint-address” parameter under “WireGuard/Peers” menu;
*) wifiwave2 - fixed “WPA Key Data Length” value in EAPOL frame when FT-EAP-SHA384 AKM is used;
*) winbox - added “Active” prefix for current remote and local session ID fields for L2TP-Ether interfaces;
*) winbox - added “address-list” parameter under “IP/DNS/Static” menu;
*) winbox - added “File Name” option for “Load Config” parameter under “System/SwOS” menu;
*) winbox - added icon for TR069-client menu;
*) winbox - added “L3 HW Settings” under “Switch” menu;
*) winbox - added MACsec support;
*) winbox - added quick filtering option for route list;
*) winbox - added “Rapid Commit” parameter support under “IPv6/DHCP-Server” menu;
*) winbox - added “Reset Traffic Counters” button for all interfaces;
*) winbox - added “to-ports” and “to-addresses” parameters for “netmap” action under “IPv6/Firewall/NAT” menu;
*) winbox - added “type” and “status-report-request” parameters under “Tools/SMS” menu;
*) winbox - allow “timeout” value to be less than 1 under “Tools/Netwatch” menu;
*) winbox - allow to rename mounted disks;
*) winbox - changed order of tabs under “User Manager” menu;
*) winbox - changed “uptime” parameter format when using the wifiwave2 package;
*) winbox - do not show unavailable features on SMIPS devices;
*) winbox - fixed interface traffic graph drawing on RB5009;
*) winbox - fixed maximum allowed value for VRRP’s “priority” parameter;
*) winbox - fixed “Session Uptime” value for not established sessions under “Routing/BGP” menu;
*) winbox - fixed “Session Uptime” value under “Routing/BGP” menu;
*) winbox - fixed “System/SwOS” window refreshing after changes are detected;
*) winbox - fixed “User Manager/User Profiles” window refreshing after changes are detected;
*) winbox - made “backup.swb” the default value for SwOS backup;
*) winbox - made sessions removable in “User Manager” menu;
*) winbox - show “F” flag for failed entries under “Interfaces/VRRP” menu;
*) winbox - show “Switch” menu on Chateau LTE18 ax;
*) winbox - show “System/Health” only on boards that have health monitoring;
*) winbox - show “System/RouterBOARD/Mode Button” on devices that have such feature;
*) wireguard - strip whitespaces from keys;
*) wireless - disallowed using “default” as scan list or channel names;
*) wireless - fixed incorrectly applied ingress priority to non-wireless packets;
*) wireless - fixed missing wireless interface on some RB921GS-5HPacD devices;
*) www - improved stability when receiving bogus packets;
*) x86 - improved ixgbe driver support;

To upgrade, click “Check for updates” at /system package in your RouterOS configuration interface, or head to our download page: http://www.mikrotik.com/download

If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while router is not working as suspected or after some problem has appeared on device

Please keep this forum topic strictly related to this particular RouterOS release.

Yes, it seems like it is working again (tested from my TV app that failed to work in beta10).
However, I am extremely disappointed that yet again we go into release candidate status without BFD support!

you are complining about a not available feature…
I am complaining that bgp is yet not stable and a new hardware CCR2XXX and new software v7 has shared memory limit that doesn’t allow a stable work.

*) bgp - added support for BGP advertisement displaying (CLI only);

Who knows how to display bgp session advertisement ?

*) container - added “start-on-boot” parameter for automatic container startup;
Doesn’t work on multi-container boot on startup.


/container/set 0,1 start-on-boot=yes
/container print
0 name="96a1d400-542f-462e-9f17-06bc9e30bafa" tag="latest" os="linux" arch="amd64" interface=veth1 start-on-boot=yes status=running 
1 name="4d768d27-831c-4bec-93bb-50661758d6b6" tag="latest" os="linux" arch="amd64" interface=veth2 start-on-boot=yes status=running

system reboot yes

/container print
0 name="96a1d400-542f-462e-9f17-06bc9e30bafa" tag="latest" os="linux" arch="amd64" interface=veth1 start-on-boot=yes status=stopped
1 name="4d768d27-831c-4bec-93bb-50661758d6b6" tag="latest" os="linux" arch="amd64" interface=veth2 start-on-boot=yes status=running

/container/set 0,1,2 start-on-boot=yes
system reboot yes
0 name="96a1d400-542f-462e-9f17-06bc9e30bafa" tag="latest" interface=veth1 start-on-boot=yes status=stopped
1 name="4d768d27-831c-4bec-93bb-50661758d6b6"  interface=veth2 start-on-boot=yes status=runned for 2 sec / then it stopped
2 name="4ef2ec35-c69a-46bc-985f-045342003e28" tag="latest" interface=veth3 start-on-boot=yes status=running

@ Vaka /routing/stats/adverts print

CCR2116-12G-4S+ on pre-production
from netinstalled 7.6beta7,
previously updated via drag&drop npk from 7.6beta7 to 7.6beta8,
updated again via drag&drop npk from 7.6beta8 to 7.6rc1

Apparently everything works as expected…

Updated RB5099 from 7.6 beta 10 without issues. DNS was not resolving so manually had to add the packages.

Well, I tend to use BGP on internal networks with a limited number of routes, not for internet routing with multiple full-route peers. The stability is OK for me.
But I need it to switch over quickly when a path fails, because that is what I use it for. E.g. multiple tunnels to the same place (over IPv4, over IPv6, over LTE) and having BFD and BGP deciding on the path to use.
This was a feature available in RouterOS v6 and it worked well, I also think in this form it is trivial to implement. I have read some times that the v6 BFD was not a complete implementation and there was some usage known from other manufacturer’s routers that was not supported in RouterOS, but for me it was just fine: have a quick ping forward and back over a TTL=1 path (a WiFi link, a tunnel) and quick information towards BGP that the path is down.

I am disappointed that this still is not available in v7, I had hoped the first attention in v7 development would be to be feature-complete relative to v6 before extending it with lots of new features. Even “netwatch” has been extended, I would likely even be happy when there would be a BFD-compatible mode in netwatch.

So.. IP Services www and www-ssl don’t work on ipv6. The ports just gets answered and closed. I think these used to work, but not sure..

Is there something wrong with mangle routing marks?
I can not make a device (by src.mac address) go to secondary WAN.
Used to work on 7.5 stable

Update:
After Disabling fastpath in IP settings the mangle rules work again

@pe1chl

How often do you get path failures? I apologize if this is an ignorant question I don’t use BGP in my simple setups.

Best regards,

Routing marks work for me, but I use src IP address/network.

Several times per day. There are WiFi links to places several km away, in a country where everyone uses wireless.
Also in case of tunnels, the whole reason to have multiple tunnels and automatic failover is to have people connected all the time without interruptions. It is not acceptable to have a link failover after it has been dead for 3 minutes (BGP default), with BFD the default is 1 second which is sort of OK.
In my v7 test setup I have set BGP hold time to 15 seconds, but even that is too slow when a winbox session runs over the link. The winbox session fails when the link disconnects.
With BFD in place that worked fine! (routes changed to use another working fallback connection quickly enough for winbox to survive)

It’s also not a matter of how often, but when. Any time you have a path failure (could be wireless or fiber, weather or man-made) and you have dozens, hundreds, or thousands of people with live connections, 4-15 seconds is enough to terminate phone and video calls, gaming sessions, and causes everything else to buffer. If you have a link that starts to flap, for whatever reason, the problem is exacerbated.

We have a large number of 60/70/80GHz links with 5GHz or secondary 60GHz links for redundancy, and those high-speed, high-frequency links are prone to rain fade. With a proper design, we can seamlessly transition to the preferred backup path(s) and keep traffic moving. BFD is a crucial part of that design for me, so most of my hub sites have RB4011’s with v6 on them.

I use OSPF between sites, with iBGP layered on top of that. OSPF has shorter timers, but 4 seconds is still a lot.

I finally decided to test ipv6 l3hw offloading on my crs317 with l3hw ipv4 already enabled. It was a few quick changes and now I get full 10gbps ipv6 on my internal vlans.

Well, I tend to use BGP on internal networks with a limited number of routes, not for internet routing with multiple full-route peers. The stability is OK for me.
But I need it to switch over quickly

@pe1chl. I thought that OSPF was designed for the internal network and speedy switching. In v6 we are using OSPF for both IPv4 and IPv6 and it seems to just work. Curious, as we have been reluctant to go to v7 due to all the BGP noise in this forum (messing with the routing is scary). I don’t see much comments about OSPF; is that because few networks are using it? Is there a particular reason that OSPF is not suitable for you?

I have no experience with OSPF. Early on in the decision between BGP and OSPF I got affected by “what others already were using”, and “OSPF reputation of heavy CPU use”.
I don’t know if that is true or not, but at the moment it isn’t practical anymore to switch over and try.
Also, as sirbryan wrote, for some services you really need (sub)second switchover times and BFD would be required with OSPF just as well.

7.6rc1 broke my LTE on a LTAP Mini with Quectel EP06E modem. Interface wouldn’t run even though it was enabled, and when I tried to disable it, it would enable itself back. Weird. If you’re running a similar config avoid RC1.

7.6rc1 broke Netflix and Amazon Prime from TV. After trying to identify root cause for an hour, I finally assumed it was DNS related (like 7.6beta10) so reverted back to 7.5 and all was immediately working again. ATM I don’t have a spare MT to test, so sorry I can’t offer root cause ATM :frowning: