Page 1 of 1

v6.43.13 [long-term] is released!

Posted: Wed Mar 20, 2019 2:51 pm
by emils
RouterOS version 6.43.13 has been released in public "long-term" channel!

Before an upgrade:
1) Remember to make backup/export files before an upgrade and save them on another storage device;
2) Make sure the device will not lose power during upgrade process;
3) Device has enough free storage space for all RouterOS packages to be downloaded.

What's new in 6.43.13 (2019-Mar-13 11:27):

*) bridge - count routed FastPath packets between bridge ports under FastPath bridge statistics;
*) bridge - fixed BOOTP packet forwarding when DHCP Snooping is enabled;
*) bridge - fixed packet forwarding with enabled DHCP Snooping and Option 82;
*) bridge - fixed possible memory leak when using "ingress-filtering=yes" on bridge interface;
*) bridge - fixed system's identity change when DHCP Snooping is enabled (introduced in v6.43);
*) capsman - always accept connections from loopback address;
*) certificate - force 3DES encryption for P12 certificate export;
*) dhcp - fixed dual stack queue addition;
*) dhcpv6-server - allow to add DHCPv6 server with pool that does not exist;
*) dhcpv6-server - fixed missing gateway for binding's network if RADIUS authentication was used;
*) ethernet - added "tx-rx-1024-max" counter to Ethernet stats;
*) ethernet - fixed packet forwarding when SFP interface is disabled on hEX S;
*) fetch - improved file downloading to slow memory;
*) gps - increase precision for dd format;
*) gps - removed unnecessary leading "0" for dd format;
*) ipsec - fixed all policies not getting installed after startup (introduced in v6.43.8);
*) ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);
*) ipv6 - do not allow setting "preferred-lifetime" longer than "valid-lifetime";
*) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters;
*) kidcontrol - fixed validation checks for time intervals;
*) led - fixed default LED configuration for RBSXTsq-60ad;
*) lldp - fixed missing capabilities fields on some devices;
*) lte - do not show "session-uptime" if session is not up;
*) lte - improved SIM7600 initialization after reset;
*) netinstall - do not show kernel failure critical messages in the log after fresh install;
*) ntp-client - fixed "dst-active" and "gmt-offset" being updated after synchronization with server;
*) ppp - fixed dynamic route creation towards VPN server when "add-default-route" is used;
*) rb4011 - fixed ether10 failing to auto negotiate link speed to 1Gbps;
*) smb - added commenting option for SMB users (CLI only);
*) smb - fixed macOS clients not showing share contents;
*) smb - fixed Windows 10 clients not able to establish connection to share;
*) ssh - close active SSH connections before IPsec connections on shutdown;
*) supout - fixed "poe-out" output not showing all interfaces;
*) supout - fixed Profile output on single core devices;
*) winbox - added "conflict-detection" parameter in "IP/DHCP Server" menu;
*) winbox - added "coordinate-format" parameter in LTE interface settings;
*) winbox - added "use-local-address" parameter in "IP/Cloud" menu;
*) winbox - allow specifying interface lists in "CAPsMAN/Access List" menu;
*) winbox - fixed "IPv6/Firewall" "Connection limit" parameter not allowing complete IPv6 prefix lengths;
*) winbox - fixed "LCD" menu not shown on RB2011UiAS-2HnD;
*) winbox - moved "Too Long" statistics counter to Ethernet "Rx Stats" tab;
*) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
*) wireless - fixed antenna gain setting on RBSXT5nDr2;
*) wireless - improved antenna gain setting for devices with built in antennas;
*) wireless - improved AR5212 response to incoming ACK frames;
*) wireless - improved connection stability for new model Apple devices;

To upgrade, click "Check for updates" at /system package in your RouterOS configuration interface, or head to our download page: http://www.mikrotik.com/download

If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while router is not working as suspected or after some problem has appeared on device

Please keep this forum topic strictly related to this specific RouterOS release.

Re: v6.43.13 [long-term] is released!

Posted: Wed Mar 20, 2019 6:01 pm
by whatever
Is it safe to downgrade from 6.44?
Edit: Did it, appears to work fine.

Re: v6.43.13 [long-term] is released!

Posted: Thu Mar 21, 2019 1:59 am
by 105547111
Is it safe to downgrade from 6.44?
I downgraded 1 x CCR 1016 12G, 3 x CRS 125s, 5 x RB951G and 2 x WaP60Gs to 6.42.12 no issues at all on downgrade, I'd assume 6.43.13 be the same...

No issues at all either with 6.42.12 to 6.43.13

Cheers!

Re: v6.43.13 [long-term] is released!

Posted: Thu Mar 21, 2019 8:48 am
by Traveller
New DDNS cloud server - it's good :) .

Re: v6.43.13 [long-term] is released!

Posted: Thu Mar 21, 2019 6:05 pm
by BrianHiggins
Unable to change default username for admin account (or any account), command line gives error "failure: user name can't be changed" and winbox options are disabled.

/user set admin name=somethingelse password=mypass comment="changed default account"
failure: user name can't be changed

Re: v6.43.13 [long-term] is released!

Posted: Thu Mar 21, 2019 6:08 pm
by Jotne
I guess you are logged inn with the user you try to change.
Create a new user, log inn with new user, then change admin user.

Re: v6.43.13 [long-term] is released!

Posted: Thu Mar 21, 2019 6:29 pm
by macgaiver
You can't change username anymore, if you need different username create new, and delete old one.
This is feature, not a bug.

Re: v6.43.13 [long-term] is released!

Posted: Thu Mar 21, 2019 7:40 pm
by BrianHiggins
You can't change username anymore, if you need different username create new, and delete old one.
This is feature, not a bug.
I disagree, it's a bug. Proof: where is this in any changelog? (because I looked before posting, twice)

Re: v6.43.13 [long-term] is released!

Posted: Thu Mar 21, 2019 7:52 pm
by nescafe2002
viewtopic.php?f=2&t=139091&p=685725#p685742

Make a new user, then re-login. There are big security changes in last versions, rename is no longer possible.

Re: v6.43.13 [long-term] is released!

Posted: Fri Mar 22, 2019 8:42 am
by macgaiver
You can't change username anymore, if you need different username create new, and delete old one.
This is feature, not a bug.
I disagree, it's a bug. Proof: where is this in any changelog? (because I looked before posting, twice)
v6.43 changelog
*) user - all passwords are now hashed and encrypted, plaintext passwords are kept for downgrade (will be removed in later upgrades); 

Re: v6.43.13 [long-term] is released!

Posted: Fri Mar 22, 2019 10:34 am
by djdrastic
Hmmmm

It's good that these steps have been taken to encrypt local user passwords the only issue is we had jinja2 scripts creating config that essentially renamed the local admin to a site/customer specific username for rollout.

Will have to play around and see what to do now . Probably create a new user account and delete/disable the old admin account ?


Thanks for the heads up @macgaiver

Re: v6.43.13 [long-term] is released!

Posted: Fri Mar 22, 2019 10:51 am
by VipITBE
Hmmmm

It's good that these steps have been taken to encrypt local user passwords the only issue is we had jinja2 scripts creating config that essentially renamed the local admin to a site/customer specific username for rollout.

Will have to play around and see what to do now . Probably create a new user account and delete/disable the old admin account ?


Thanks for the heads up @macgaiver
because reading an entire thread is too hard: viewtopic.php?f=2&t=139091&p=685725#p685742

Re: v6.43.13 [long-term] is released!

Posted: Fri Mar 22, 2019 11:19 am
by djdrastic
Just read that thanks

Will have to radically alter that script of vecernik87 for the build environment.

Re: v6.43.13 [long-term] is released!

Posted: Fri Mar 22, 2019 11:44 am
by vecernik87
That was just an example :) but at least you can see it is possible and not that complicated :)

Re: v6.43.13 [long-term] is released!

Posted: Fri Mar 22, 2019 12:11 pm
by djdrastic
That was just an example :) but at least you can see it is possible and not that complicated :)
Thx for the script mate.Helps a bunch.

Re: v6.43.13 [long-term] is released!

Posted: Fri Mar 22, 2019 4:26 pm
by Swordforthelord
I have a 450G and a 750Gr3 that have had this error since upgrading:

"backup,critical error creating backup file: could not read all configuration files"

It happens with both encrypted and unencrypted backups; both were upgraded from 6.42.12. My 951G that was upgraded from 6.43.12 does not have this issue. Is anyone else experiencing this?

Re: v6.43.13 [long-term] is released!

Posted: Fri Mar 22, 2019 4:29 pm
by eworm
I have a 450G and a 750Gr3 that have had this error since upgrading:

"backup,critical error creating backup file: could not read all configuration files"

It happens with both encrypted and unencrypted backups; both were upgraded from 6.42.12. My 951G that was upgraded from 6.43.12 does not have this issue. Is anyone else experiencing this?
Try to regenerate the ssh host keys:
/ ip ssh regenerate-host-key

Re: v6.43.13 [long-term] is released!

Posted: Fri Mar 22, 2019 5:01 pm
by Swordforthelord
I have a 450G and a 750Gr3 that have had this error since upgrading:

"backup,critical error creating backup file: could not read all configuration files"

It happens with both encrypted and unencrypted backups; both were upgraded from 6.42.12. My 951G that was upgraded from 6.43.12 does not have this issue. Is anyone else experiencing this?
Try to regenerate the ssh host keys:
/ ip ssh regenerate-host-key
Thanks, that fixed it!

Re: v6.43.13 [long-term] is released!

Posted: Sat Mar 23, 2019 9:12 am
by DJGlooM
Is everything okay there with winbox-router communication? When I open winbox session on previous RouterOS versions it takes like 1-2 seconds to establish session, now with 6.43.13 it happens instantly. It feels like there could be broken encryption or something. So I wonder if bug or feature.

Re: v6.43.13 [long-term] is released!

Posted: Sat Mar 23, 2019 2:28 pm
by Chupaka
Is "previous" version 6.43.12 or some other one?

Re: v6.43.13 [long-term] is released!

Posted: Sat Mar 23, 2019 7:46 pm
by storp
Is "previous" version 6.43.12 or some other one?
You mean previous long-term? That should be 6.42.11 I think.

Re: v6.43.13 [long-term] is released!

Posted: Sat Mar 23, 2019 9:48 pm
by DJGlooM
You mean previous long-term? That should be 6.42.11 I think.
6.42.12

Re: v6.43.13 [long-term] is released!

Posted: Sat Mar 23, 2019 9:50 pm
by DJGlooM
Is "previous" version 6.43.12 or some other one?
Any previous version. Is there only myself who noticed that winbox connection became instant which it wasn't before?

Re: v6.43.13 [long-term] is released!

Posted: Sun Mar 24, 2019 9:44 am
by Kindis
The fast connection of winbox was part of a release where they improved and secured the connection. Might have been 6.43 release. I do not remember but I do remember a lot of happy people talking about how quick it is now 😊
So the connection of both faster and more secure now.

Re: v6.43.13 [long-term] is released!

Posted: Mon Mar 25, 2019 9:08 am
by DJGlooM
The fast connection of winbox was part of a release where they improved and secured the connection. Might have been 6.43 release. I do not remember but I do remember a lot of happy people talking about how quick it is now 😊
So the connection of both faster and more secure now.
Oh nice! Finally something was improved and not broken!

Re: v6.43.13 [long-term] is released!

Posted: Mon Mar 25, 2019 7:22 pm
by BrianHiggins
You can't change username anymore, if you need different username create new, and delete old one.
This is feature, not a bug.
I disagree, it's a bug. Proof: where is this in any changelog? (because I looked before posting, twice)
v6.43 changelog
*) user - all passwords are now hashed and encrypted, plaintext passwords are kept for downgrade (will be removed in later upgrades);
ok, I now see the post I missed before where Normis says this, but the hashed & encrypted changelog does NOT say anything about changing usernames, so I still stand by the fact that it's "officially/technically" a bug, since there is still NO official reference to this anywhere but a blog post :roll: ....

As with others this came up as part of a deployment script that expected to rename the admin account, where it needs to now remove and replace the admin account. Easy enough if you're working with devices locally, but this script gets pushed out automatically to devices across the country, so any failure in these scripts results in a RMA warranty claim and shipping costs to repair / replace the device.

Re: v6.43.13 [long-term] is released!

Posted: Mon Mar 25, 2019 7:34 pm
by deanMKD1
Is it safe to downgrade from 6.44?
Edit: Did it, appears to work fine.
Tryed to downgrade from 6.44 stable to this release, but after reboot still show me 6.44 stable.. Seems like its not posible to downgrade to this longterm version.

Re: v6.43.13 [long-term] is released!

Posted: Mon Mar 25, 2019 9:23 pm
by andriys
Tryed to downgrade from 6.44 stable to this release, but after reboot still show me 6.44 stable.. Seems like its not posible to downgrade to this longterm version.
What's in the log? What is the factory firmware version?

Re: v6.43.13 [long-term] is released!

Posted: Tue Mar 26, 2019 1:34 am
by yacsap
Is it safe to downgrade from 6.44?
Edit: Did it, appears to work fine.
I downgraded 2 of my CCR1009-7G-1C-1S+, RB2011RMUi-AS, RB3011RMUi-AS, and heaps of RB951G-2HnD, all of them are working perfectly fine :)

Re: v6.43.13 [long-term] is released!

Posted: Tue Mar 26, 2019 11:57 am
by Deantwo
So are there actually any changes between this long-term version and the v6.43.12 stable version? Really hard to tell from the changes, since as mentioned by others in this thread, there are even changes missing that were made in the v6.43 release thread.

PS: Emailed support about adding the missing user change to the changes list.

EDIT: Got reply from support that all the changes in this release are changes between v6.43.12 and v6.43.13. So that would explain the missing entries on the changes list. Don't remember this being how bugfig/long-term patch notes are written, but whatever.

Re: v6.43.13 [long-term] is released!

Posted: Tue Mar 26, 2019 3:49 pm
by fback
As 6.43 just recently replaced 6.42 long-term.

radius - use MS-CHAPv2 for "login" service authentication;

Please revert this change, or at least make this configurable.

Rationale:
This is great when you use your radius to authenticate both wireless clients and admin access. But with a network, where radius is used just to authorize admin access to devices (or with separate radius service for network admin access), this is a very bad change. You basically have to move from simple, eg. PAM-based password verification (and group membership) to something AD based (either real MS AD or SAMBA4) so you can provide RC4 / NTLM infrastructure.

Regards,
b.

Re: v6.43.13 [long-term] is released!

Posted: Tue Mar 26, 2019 4:19 pm
by Deantwo
As 6.43 just recently replaced 6.42 long-term.

radius - use MS-CHAPv2 for "login" service authentication;

Please revert this change, or at least make this configurable.
That is true, and yet another thing people upgrading from v6.42.12 to v6.43.13 will be unprepared for.
But all is not lost. If you upgrade your RADIUS server first, it will be backward compatible for older RouterOS version (for WinBox at least, weirdly not for Telnet).

See: viewtopic.php?f=2&t=144726

Re: v6.43.13 [long-term] is released!

Posted: Tue Mar 26, 2019 6:12 pm
by deanMKD1
Tryed to downgrade from 6.44 stable to this release, but after reboot still show me 6.44 stable.. Seems like its not posible to downgrade to this longterm version.
What's in the log? What is the factory firmware version?
Factory is 6.42.3. Current is 6.44 Stable.

This is message from log..

Image

Re: v6.43.13 [long-term] is released!

Posted: Tue Mar 26, 2019 6:30 pm
by eworm
Tryed to downgrade from 6.44 stable to this release, but after reboot still show me 6.44 stable.. Seems like its not posible to downgrade to this longterm version.
What's in the log? What is the factory firmware version?
Factory is 6.42.3. Current is 6.44 Stable.

This is message from log..

Image
Did you actually run
/system package downgrade
to downgrade? RouterOS will not downgrade on its own when just rebooting.

Re: v6.43.13 [long-term] is released!

Posted: Tue Mar 26, 2019 8:59 pm
by deanMKD1
Tryed to downgrade from 6.44 stable to this release, but after reboot still show me 6.44 stable.. Seems like its not posible to downgrade to this longterm version.
What's in the log? What is the factory firmware version?
Factory is 6.42.3. Current is 6.44 Stable.

This is message from log..

Image
Did you actually run
/system package downgrade
to downgrade? RouterOS will not downgrade on its own when just rebooting.
No i used method to upload firmware to rooter root dir, and then tryed to reboot. I have upgraded all my routers in the past via that way.

EDIT: When upload long-term firmware and run your command from terminal, finally downgraded to long-term version. Works perfectly now !
No i used method to upload firmware to rooter root dir, and then tryed to reboot. I have upgraded all my routers in the past via that way.

To upgrade, simply upliading new package files is fine. To downgrade, one has to follow procedure described by @eworm
yes that makes the magic. i dont knowed that. Just learned something new. Many thanks !!!

Re: v6.43.13 [long-term] is released!

Posted: Tue Mar 26, 2019 9:05 pm
by mkx
No i used method to upload firmware to rooter root dir, and then tryed to reboot. I have upgraded all my routers in the past via that way.

To upgrade, simply upliading new package files is fine. To downgrade, one has to follow procedure described by @eworm

Re: v6.43.13 [long-term] is released!

Posted: Fri Mar 29, 2019 12:54 pm
by cmdorexe
RB3011 Long-term release 6.43.13 dhcp-server not working! CPU load 100% all times. WinBox droped me many times. Only when I stop all WAN connections downgrade it. 6.42.10 stable on RB3011.
Das 6.43.13 longterm?

Re: v6.43.13 [long-term] is released!

Posted: Fri Mar 29, 2019 3:27 pm
by Chupaka
CPU load 100% all times.
Which facility? Tools -> Profile. Because it can be DNS :)

Re: v6.43.13 [long-term] is released!

Posted: Fri Mar 29, 2019 5:01 pm
by cmdorexe
Which facility?
Can't test it again. DNS using white list with drop RAW.

Re: v6.43.13 [long-term] is released!

Posted: Fri Mar 29, 2019 6:19 pm
by sindudas
I think there is a Bug that wasn't in 6.42.12:

Running that command on 6.42.12 works:
:log info ([/interface pppoe-client monitor pppoe-WAN as-value]->"status")
but when running the same on 6.43.13 it doens't end executing that command.
But if you try this it works:
/interface pppoe-client monitor pppoe-WAN
There's something wrong in 6.43.13 ? (I don't know if other 6.43.x does the same, using long-term and jumped from 6.42.12 to 6.43.13)

Re: v6.43.13 [long-term] is released!

Posted: Fri Mar 29, 2019 10:33 pm
by McSee
I think there is a Bug that wasn't in 6.42.12:

Running that command on 6.42.12 works:
:log info ([/interface pppoe-client monitor pppoe-WAN as-value]->"status")
It's not a bug it's a feature :)
Now you need to add "once" after an interface name.

Re: v6.43.13 [long-term] is released!

Posted: Fri Mar 29, 2019 11:02 pm
by Aberanta
Maybe always was this way but I just notice that, in winbox, the comment column in ipv6 firewall is missing. The comments shows if I disable "Inline Comments" in winbox settings and in terminal "/ipv6 firewall filter print" works fine.

Re: v6.43.13 [long-term] is released!

Posted: Mon Apr 01, 2019 11:30 am
by sindudas
I think there is a Bug that wasn't in 6.42.12:

Running that command on 6.42.12 works:
:log info ([/interface pppoe-client monitor pppoe-WAN as-value]->"status")
It's not a bug it's a feature :)
Now you need to add "once" after an interface name.
This seems like some kind of joke. This change has broken our brand customization package. It was working since v6.27.

Re: v6.43.13 [long-term] is released!

Posted: Mon Apr 01, 2019 12:39 pm
by Deantwo
I think there is a Bug that wasn't in 6.42.12:

Running that command on 6.42.12 works:
:log info ([/interface pppoe-client monitor pppoe-WAN as-value]->"status")
It's not a bug it's a feature :)
Now you need to add "once" after an interface name.
This seems like some kind of joke. This change has broken our brand customization package. It was working since v6.27.
Not a joke. It is mentioned in the v6.43 change log.
Here: viewtopic.php?f=21&t=138995
*) console - made "once" parameter mandatory when using "as-value" on "monitor" commands;

Re: v6.43.13 [long-term] is released!

Posted: Thu Apr 04, 2019 10:55 am
by emils
New version 6.43.14 has been released in long-term RouterOS channel:

viewtopic.php?f=21&t=147278