Community discussions

  • 1
  • 2
  • 3
  • 4
  • 5
  • 9
 
User avatar
emils
MikroTik Support
MikroTik Support
Topic Author
Posts: 453
Joined: Thu Dec 11, 2014 8:53 am

v6.45.1 [stable] is released!

Mon Jul 01, 2019 10:11 am

RouterOS version 6.45.1 has been released in public "stable" channel!

Before an upgrade:
1) Remember to make backup/export files before an upgrade and save them on another storage device;
2) Make sure the device will not lose power during upgrade process;
3) Device has enough free storage space for all RouterOS packages to be downloaded.

What's new in 6.45.1 (2019-Jun-27 10:23):

Important note!!!
Due to removal of compatibility with old version passwords in this version, downgrading to any version prior to v6.43 (v6.42.12 and older) will clear all user passwords and allow password-less authentication. Please secure your router after downgrading.
Old API authentication method will also no longer work, see documentation for new login procedure:
https://wiki.mikrotik.com/wiki/Manual:API#Initial_login


MAJOR CHANGES IN v6.45.1:
----------------------
!) dot1x - added support for IEEE 802.1X Port-Based Network Access Control;
!) ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap, eap-mschapv2) as initiator;
!) security - fixed vulnerabilities CVE-2018-1157, CVE-2018-1158;
!) security - fixed vulnerabilities CVE-2019-11477, CVE-2019-11478, CVE-2019-11479;
!) security - fixed vulnerability CVE-2019-13074;
!) user - removed insecure password storage;
----------------------

Changes in this release:

*) bridge - correctly display bridge FastPath status when vlan-filtering or dhcp-snooping is used;
*) bridge - correctly handle bridge host table;
*) bridge - fixed log message when hardware offloading is being enabled;
*) bridge - improved stability when receiving traffic over USB modem with bridge firewall enabled;
*) capsman - fixed CAP system upgrading process for MMIPS;
*) capsman - fixed interface-list usage in access list;
*) ccr - improved packet processing after overloading interface;
*) certificate - added "key-type" field;
*) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1);
*) certificate - fixed self signed CA certificate handling by SCEP client;
*) certificate - made RAM the default CRL storage location;
*) certificate - removed DSA (D) flag;
*) certificate - removed "set-ca-passphrase" parameter;
*) chr - legacy adapters require "disable-running-check=yes" to be set;
*) cloud - added "replace" parameter for backup "upload-file" command;
*) conntrack - fixed GRE protocol packet connection-state matching (CVE-2014-8160);
*) conntrack - significant stability and performance improvements;
*) crs317 - fixed known multicast flooding to the CPU;
*) crs3xx - added ethernet tx-drop counter;
*) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
*) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
*) crs3xx - fixed "tx-drop" counter;
*) crs3xx - improved switch-chip resource allocation on CRS326, CRS328, CRS305;
*) defconf - added "custom-script" field that prints custom configuration installed by Netinstall;
*) defconf - automatically set "installation" parameter for outdoor devices;
*) defconf - changed default configuration type to AP for cAP series devices;
*) defconf - fixed channel width selection for RU locked devices;
*) dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
*) dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
*) dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
*) dhcpv4-server - added "client-mac-limit" parameter;
*) dhcpv4-server - added IP conflict logging;
*) dhcpv4-server - added RADIUS accounting support with queue based statistics;
*) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
*) dhcpv4-server - improved stability when performing "check-status" command;
*) dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
*) dhcpv6-client - added option to disable rapid-commit;
*) dhcpv6-client - fixed status update when leaving "bound" state;
*) dhcpv6-server - added additional RADIUS parameters for Prefix delegation, "rate-limit" and "life-time";
*) dhcpv6-server - added "address-list" support for bindings;
*) dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters;
*) dhcpv6-server - added RADIUS accounting support with queue based statistics;
*) dhcpv6-server - added "route-distance" parameter;
*) dhcpv6-server - fixed dynamic IPv6 binding without proper reference to the server;
*) dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
*) discovery - correctly create neighbors from VLAN tagged discovery messages;
*) discovery - fixed CDP packets not including address on slave ports (introduced in v6.44);
*) discovery - improved neighbour's MAC address detection;
*) discovery - limit max neighbour count per interface based on total RAM memory;
*) discovery - show neighbors on actual mesh ports;
*) e-mail - include "message-id" identification field in e-mail header;
*) e-mail - properly release e-mail sending session if the server's domain name can not be resolved;
*) ethernet - added support for 25Gbps and 40Gbps rates;
*) ethernet - fixed running (R) flag not present on x86 interfaces and CHR legacy adapters;
*) ethernet - increased loop warning threshold to 5 packets per second;
*) fetch - added SFTP support;
*) fetch - improved user policy lookup;
*) firewall - fixed fragmented packet processing when only RAW firewall is configured;
*) firewall - process packets by firewall when accepted by RAW with disabled connection tracking;
*) gps - fixed missing minus close to zero coordinates in dd format;
*) gps - make sure "direction" parameter is upper case;
*) gps - strip unnecessary trailing characters from "longtitude" and "latitude" values;
*) gps - use "serial0" as default port on LtAP mini;
*) hotspot - added "interface-mac" variable to HTML pages;
*) hotspot - moved "title" HTML tag after "meta" tags;
*) ike1 - adjusted debug packet logging topics;
*) ike2 - added support for ECDSA certificate authentication (rfc4754);
*) ike2 - added support for IKE SA rekeying for initiator;
*) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
*) ike2 - improved certificate verification when multiple CA certificates received from responder;
*) ike2 - improved child SA rekeying process;
*) ike2 - improved XAuth identity conversion on upgrade;
*) ike2 - prefer SAN instead of DN from certificate for ID payload;
*) ippool - improved logging for IPv6 Pool when prefix is already in use;
*) ipsec - added dynamic comment field for "active-peers" menu inherited from identity;
*) ipsec - added "ph2-total" counter to "active-peers" menu;
*) ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods;
*) ipsec - added traffic statistics to "active-peers" menu;
*) ipsec - disallow setting "src-address" and "dst-address" for transport mode policies;
*) ipsec - do not allow adding identity to a dynamic peer;
*) ipsec - fixed policies becoming invalid after changing priority;
*) ipsec - general improvements in policy handling;
*) ipsec - properly drop already established tunnel when address change detected;
*) ipsec - renamed "remote-peers" to "active-peers";
*) ipsec - renamed "rsa-signature" authentication method to "digital-signature";
*) ipsec - replaced policy SA address parameters with peer setting;
*) ipsec - use tunnel name for dynamic IPsec peer name;
*) ipv6 - improved system stability when receiving bogus packets;
*) ltap - renamed SIM slots "up" and "down" to "2" and "3";
*) lte - added initial support for Vodafone R216-Z;
*) lte - added passthrough interface subnet selection;
*) lte - added support for manual operator selection;
*) lte - allow setting empty APN;
*) lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
*) lte - do not show error message for info commands that are not supported;
*) lte - fixed session reactivation on R11e-LTE in UMTS mode;
*) lte - improved firmware upgrade process;
*) lte - improved "info" command query;
*) lte - improved R11e-4G modem operation;
*) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
*) lte - show alphanumeric value for operator info;
*) lte - show correct firmware revision after firmware upgrade;
*) lte - use default APN name "internet" when not provided;
*) lte - use secondary DNS for DNS server configuration;
*) m33g - added support for additional Serial Console port on GPIO headers;
*) ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
*) ospf - fixed opaque LSA type checking in OSPFv2;
*) ospf - improved "unknown" LSA handling in OSPFv3;
*) ovpn - added "verify-server-certificate" parameter for OVPN client (CVE-2018-10066);
*) ppp - added initial support for Quectel BG96;
*) proxy - increased minimal free RAM that can not be used for proxy services;
*) rb3011 - improved system stability when receiving bogus packets;
*) rb4011 - fixed MAC address duplication between sfp-sfpplus1 and wlan1 interfaces (wlan1 configuration reset required);
*) rb921 - improved system stability ("/system routerboard upgrade" required);
*) routerboard - renamed 'sim' menu to 'modem';
*) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
*) sms - added USSD message functionality under "/tool sms" (CLI only);
*) sms - allow specifying multiple "allowed-number" values;
*) sms - improved delivery report logging;
*) snmp - added "dot1dStpPortTable" OID;
*) snmp - added OID for neighbor "interface";
*) snmp - added "write-access" column to community print;
*) snmp - allow setting interface "adminStatus";
*) snmp - fixed "send-trap" not working when "trap-generators" does not contain "temp-exception";
*) snmp - fixed "send-trap" with multiple "trap-targets";
*) snmp - improved reliability on SNMP service packet validation;
*) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
*) ssh - accept remote forwarding requests with empty hostnames;
*) ssh - added new "ssh-exec" command for non-interactive command execution;
*) ssh - fixed non-interactive multiple command execution;
*) ssh - improved remote forwarding handling (introduced in v6.44.3);
*) ssh - improved session rekeying process on exchanged data size threshold;
*) ssh - keep host keys when resetting configuration with "keep-users=yes";
*) ssh - use correct user when "output-to-file" parameter is used;
*) sstp - improved stability when received traffic hits tarpit firewall;
*) supout - added IPv6 ND section to supout file;
*) supout - added "kid-control devices" section to supout file;
*) supout - added "pwr-line" section to supout file;
*) supout - changed IPv6 pool section to output detailed print;
*) switch - properly reapply settings after switch chip reset;
*) tftp - added "max-block-size" parameter under TFTP "settings" menu (CLI only);
*) tile - improved link fault detection on SFP+ ports;
*) tr069-client - added LTE CQI and IMSI parameter support;
*) tr069-client - fixed potential memory corruption;
*) tr069-client - improved error reporting with incorrect firware upgrade XML file;
*) traceroute - improved stability when sending large ping amounts;
*) traffic-generator - improved stability when stopping traffic generator;
*) tunnel - removed "local-address" requirement when "ipsec-secret" is used;
*) userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
*) w60g - do not show unused "dmg" parameter;
*) w60g - prefer AP with strongest signal when multiple APs with same SSID present;
*) w60g - show running frequency under "monitor" command;
*) winbox - added "System/SwOS" menu for all dual-boot devices;
*) winbox - do not allow setting "dns-lookup-interval" to "0";
*) winbox - show "LCD" menu only on boards that have LCD screen;
*) wireless - fixed frequency duplication in the frequency selection menu;
*) wireless - fixed incorrect IP header for RADIUS accounting packet;
*) wireless - improved 160MHz channel width stability on rb4011;
*) wireless - improved DFS radar detection when using non-ETSI regulated country;
*) wireless - improved installation mode selection for wireless outdoor equipment;
*) wireless - set default SSID and supplicant-identity the same as router's identity;
*) wireless - updated "china" regulatory domain information;
*) wireless - updated "new zealand" regulatory domain information;
*) www - improved client-initiated renegotiation within the SSL and TLS protocols (CVE-2011-1473);

What's new in 6.45 (2019-Jun-21 09:00):

(factory only release)

What's new in 6.44.4 (2019-May-09 12:14):

(factory only release)

To upgrade, click "Check for updates" at /system package in your RouterOS configuration interface, or head to our download page: http://www.mikrotik.com/download

If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while router is not working as suspected or after some problem has appeared on device

Please keep this forum topic strictly related to this particular RouterOS release.
 
User avatar
amt
Long time Member
Long time Member
Posts: 524
Joined: Fri Jan 16, 2015 2:05 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 10:27 am

many thanks Mikrotik Team...
 
Kindis
Member Candidate
Member Candidate
Posts: 241
Joined: Tue Nov 01, 2011 6:54 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 10:32 am

Wow 9 CVE fixed! Very nice will try this one on the test systems asap!
 
User avatar
ErfanDL
Member Candidate
Member Candidate
Posts: 266
Joined: Thu Sep 29, 2016 9:13 am
Location: IRAN
Contact:

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 10:59 am

thanks for this Big Update!!! updated RB2011UiAS2HnD and RB951Ui and hAP Lite without any problem.
 
roe1974
newbie
Posts: 43
Joined: Mon Dec 31, 2018 2:14 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 11:14 am

found this in change log:

*) rb4011 - fixed MAC address duplication between sfp-sfpplus1 and wlan1 interfaces (wlan1 configuration reset required);

how todo "wlan1 configuration reset required" ???

regards, Richard
 
freemannnn
Long time Member
Long time Member
Posts: 648
Joined: Sun Oct 13, 2013 7:29 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 11:15 am

- cloud - added "replace" parameter for backup "upload-file" command;

what is the correct syntax to replace file? wiki is not updated yet.
please add backup and restore function in winbox.
 
User avatar
strods
MikroTik Support
MikroTik Support
Posts: 1405
Joined: Wed Jul 16, 2014 7:22 am
Location: Riga, Latvia

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 11:24 am

ros1974 - Command is "/interface wireless reset-configuration"
freemannnn - Here is an example "/system backup cloud upload-file action=create-and-upload replace=cloud-XXXXXXXX-XXXXXX password=123"
 
paulct
Member Candidate
Member Candidate
Posts: 284
Joined: Fri Jul 12, 2013 5:38 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 11:32 am

*) ethernet - added support for 25Gbps and 40Gbps rates

soon, mmmm
 
ludvik
Frequent Visitor
Frequent Visitor
Posts: 57
Joined: Mon May 26, 2008 4:36 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 11:34 am

What bug exactly is solved by: *) ccr - improved packet processing after overloading interface;
thanks
 
ndbjorne
just joined
Posts: 22
Joined: Sat Dec 15, 2012 5:06 pm
Location: Italy

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 11:41 am

!) security - fixed vulnerabilities CVE-2018-1157, CVE-2018-1158;
https://blog.mikrotik.com/security/secu ... nable.html: All of the above issues are fixed in the following RouterOS releases: 6.42.7, 6.40.9, 6.43
Fixed again?
!) security - fixed vulnerabilities CVE-2019-11477, CVE-2019-11478, CVE-2019-11479;
!) security - fixed vulnerability CVE-2019-13074;
!) user - removed insecure password storage;
*) conntrack - fixed GRE protocol packet connection-state matching (CVE-2014-8160);
*) ovpn - added "verify-server-certificate" parameter for OVPN client (CVE-2018-10066);
*) www - improved client-initiated renegotiation within the SSL and TLS protocols (CVE-2011-1473);
When in the bugfix?
Andrea
 
roe1974
newbie
Posts: 43
Joined: Mon Dec 31, 2018 2:14 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 12:08 pm

@strods
when i perfom a "/interface wireless reset-configuration" then all my wireless settings are gone?

I have same MAC adress on SFP+ and WLAN Interface 5G (QCA9984) ..... the 2.4GHz Interface has another MAC Adress.
The SFP+ Port is disabled, so do i need to do any changes/resets ?

regards, Richard

PS: can i only reset the config from WLAN 5G ?
 
User avatar
grusu
Frequent Visitor
Frequent Visitor
Posts: 94
Joined: Tue Aug 13, 2013 7:35 am
Location: Bucharest, Romania

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 12:30 pm

You can try: /interface wireless reset-configuration wlanX where "wlanX" is your 5 GHz wlan interface.
 
roe1974
newbie
Posts: 43
Joined: Mon Dec 31, 2018 2:14 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 12:33 pm

wlanX is then the "name" of the interface ?
 
User avatar
eworm
Member
Member
Posts: 334
Joined: Wed Oct 22, 2014 9:23 am
Location: Oberhausen, Germany
Contact:

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 12:36 pm

I have serve issues with all my IPSec responders. As far as I can tell about half of my IPSec initiator devices do not get addresses from mode-config.
Not sure about the details. Anybody else seen this?

Edit 1:
Initiator devices log:
ipsec,error MikroTik: bad state: 7
Edit 2:
Looking in /ip ipsec active-peers I noticed those missing dynamic-address also miss ph2-total.
Manage RouterOS scripts and extend your devices' functionality: RouterOS Scripts
 
roe1974
newbie
Posts: 43
Joined: Mon Dec 31, 2018 2:14 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 12:58 pm

new change for OVPN:
"ovpn - added "verify-server-certificate" parameter for OVPN client"

how ist he config line for the client ?

regards, Richard
 
pacman88
newbie
Posts: 28
Joined: Mon Aug 22, 2016 7:08 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 1:00 pm

does "improved switch chip allocation" fix the port flapping mentioned in this topic viewtopic.php?f=2&t=141633 ?

BR
Alex
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 5891
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 1:00 pm

@roe1974 Simple:
verify-server-certificate=yes
 
roe1974
newbie
Posts: 43
Joined: Mon Dec 31, 2018 2:14 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 1:04 pm

that's an config option for the client OVPN config file ??
there is notthing about here of such a config option:

https://openvpn.net/community-resources/how-to/

or is this an option to be set at the OVPN Server on the mikrotik router ?

regards Richard
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 5891
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 1:06 pm

That is an option for RouterOS OVPN clients, for which this exact change apply. It has nothing to do with non-RouterOS OVPN client.
 
kobuki
Member Candidate
Member Candidate
Posts: 134
Joined: Sat Apr 02, 2011 5:59 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 1:36 pm

Will CVE fixes get into the 6.43 LTS version?
 
nmt1900
just joined
Posts: 24
Joined: Wed Feb 01, 2017 12:36 am

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 1:40 pm

Upgrade 6.44.3 -> 6.45.1

ARP in reply-only mode was used and static ARP entries had to be removed and added back to regain L3 access to other Mikrotik devices on the network (static IP addresses and these same static ARP entries).

RB750Gr3
 
User avatar
raystream
newbie
Posts: 43
Joined: Tue Mar 20, 2018 6:56 pm
Location: Germany

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 2:04 pm

Upgrade 6.44.3 -> 6.45.1

on my hAP ac lite and on RB2011iL all went fine.

but i have a problem with my RB3011.
I can not login anymore with winbox ("wrong username or password").
All other services are disabled so only connection with winbox possible.
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8280
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 2:06 pm

WinBox version?
Russian-speaking forum: https://forum.mikrotik.by/. Welcome!

For every complex problem, there is a solution that is simple, neat, and wrong.

MikroTik. Your life. Your routing.
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 5891
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 2:06 pm

What winbox version?
 
User avatar
raystream
newbie
Posts: 43
Joined: Tue Mar 20, 2018 6:56 pm
Location: Germany

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 2:09 pm

actual winbox version 3.18

i connected with that winbox version to start the upgrade and after the upgrade the failure happens
 
User avatar
grusu
Frequent Visitor
Frequent Visitor
Posts: 94
Joined: Tue Aug 13, 2013 7:35 am
Location: Bucharest, Romania

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 2:15 pm

wlanX is then the "name" of the interface ?
Yes. In my case wlan 5GHz interface is called "wlan5":
wlan.PNG
You do not have the required permissions to view the files attached to this post.
 
User avatar
raystream
newbie
Posts: 43
Joined: Tue Mar 20, 2018 6:56 pm
Location: Germany

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 2:21 pm

i have found the failure.
connecting with the android app over vpn (i am not at home) is fine.
connecting with winbox from my windows laptop over vpn is fone too.

only winbox running with wine on my macbook shows this failure
and after deleting the cache in winbox it connects again on my macbook
Last edited by raystream on Mon Jul 01, 2019 2:32 pm, edited 1 time in total.
 
User avatar
nichky
Long time Member
Long time Member
Posts: 505
Joined: Tue Jun 23, 2015 2:35 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 2:34 pm

i upgrade my RB433AH after that...i couldn't access with current user and password and with admin????
Nikola Shuminoski
Network Engineer
E-Mail: nikola.suminoski@outlook.com
MikroTik Consultan
MTCNA l MTCRE

!) Safe Mode is your friend;
 
LetMeRepair
just joined
Posts: 19
Joined: Mon Jan 31, 2011 5:23 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 2:40 pm

Same here, hAP ac² ...upgrade from 6.43.2 to 6.45.1 .. .wrong username/password!!


EDIT: clearing Winbox cache (regular Windows 10 / 1903 ) solved issue. Phewww ... that was close.
Last edited by LetMeRepair on Mon Jul 01, 2019 2:43 pm, edited 1 time in total.
 
proximus
Member Candidate
Member Candidate
Posts: 107
Joined: Tue Oct 04, 2011 1:46 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 2:42 pm

i upgrade my RB433AH after that...i couldn't access with current user and password and with admin????
.
My observation is that after a reboot, the first login attempt fails ... subsequent logins are successful. This behavior has been reproducible after every reboot, of the single device I'm testing on (hAP Lite).
 
User avatar
nichky
Long time Member
Long time Member
Posts: 505
Joined: Tue Jun 23, 2015 2:35 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 2:46 pm

it is my remote site!!!!!
any bug make sense....this one...hhhhhh
Nikola Shuminoski
Network Engineer
E-Mail: nikola.suminoski@outlook.com
MikroTik Consultan
MTCNA l MTCRE

!) Safe Mode is your friend;
 
User avatar
matiaszon
Member
Member
Posts: 300
Joined: Mon Jul 09, 2012 9:26 am

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 2:51 pm

After swtiching from 6.43.16 to 6.54.1 I am not able to use my LTE connection. My main router (RB2011) is getting an IP from BaseBox2 + R11e-LTE (passthorugh, using only Band 3, T-Mobile Poland). Modem shows status connected and everything seems to be OK. However, there is no traffic coming through LTE modem. I have upgraded Routerbord too and it hasn't helped. After coming back to 6.43.16 it works fine again.
 
User avatar
Cha0s
Forum Veteran
Forum Veteran
Posts: 875
Joined: Tue Oct 11, 2005 4:53 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 2:55 pm

i upgrade my RB433AH after that...i couldn't access with current user and password and with admin????
.
My observation is that after a reboot, the first login attempt fails ... subsequent logins are successful. This behavior has been reproducible after every reboot, of the single device I'm testing on (hAP Lite).
I confirm this behavior. Tested on over 10 installations so far. All had the exact behavior you described.
 
reiniss2
MikroTik Support
MikroTik Support
Posts: 38
Joined: Wed Jan 02, 2019 12:14 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 3:00 pm

!) security - fixed vulnerabilities CVE-2018-1157, CVE-2018-1158;
Fixed again?
Both CVE's were fixed in the previous versions, but they could be reproduced differently if you had access to the www service and user account with "full" rights. We have removed this possibility as well.
 
User avatar
nichky
Long time Member
Long time Member
Posts: 505
Joined: Tue Jun 23, 2015 2:35 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 3:01 pm

!) security - fixed vulnerabilities CVE-2018-1157, CVE-2018-1158;
Fixed again?
Both CVE's were fixed in the previous versions, but they could be reproduced differently if you had access to the www service and user account with "full" rights. We have removed this possibility as well.

and how can we get access?
Nikola Shuminoski
Network Engineer
E-Mail: nikola.suminoski@outlook.com
MikroTik Consultan
MTCNA l MTCRE

!) Safe Mode is your friend;
 
toxmost
just joined
Posts: 3
Joined: Tue Jun 18, 2019 7:25 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 3:13 pm

PLEASE HELP!!!

I have RB4011iGS+5HacQ2HnD with dlink DPN-100 (TW2362H-CDEL-CLX) GPON SFP module (WAN).
IP address receive via DHCP. ALL WORK GREAT! ---> firmware 6.44.3

If im update firmware to 6.45.1, SFP module have status "link ok", but DHCP address not received, DHCP client all time in status "searching", packet (in module window) TXed, but not RXed.

Help me PLEASE!

Thank you.
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 23998
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 3:15 pm



and how can we get access?
You can't :D That is the point of this issue. Only the admin himself could trigger the problem. it's not a serious issue, but we still fixed it.
No answer to your question? How to write posts
 
Stanleyssm
just joined
Posts: 7
Joined: Mon Aug 21, 2017 1:38 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 3:21 pm

Hi Guys

I am having problem to update my device,

it complete and reboot , but when i go to check the currentversion, is still 6.42 and not 6.45

Please Help
 
User avatar
nichky
Long time Member
Long time Member
Posts: 505
Joined: Tue Jun 23, 2015 2:35 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 3:21 pm



and how can we get access?
You can't :D That is the point of this issue. Only the admin himself could trigger the problem. it's not a serious issue, but we still fixed it.
So we have to replace the router? so fany :)
Nikola Shuminoski
Network Engineer
E-Mail: nikola.suminoski@outlook.com
MikroTik Consultan
MTCNA l MTCRE

!) Safe Mode is your friend;
 
Stanleyssm
just joined
Posts: 7
Joined: Mon Aug 21, 2017 1:38 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 3:22 pm

Hy Guys

I try Update , itdomy device downlo and install, then reboot the device...but when i went to check if theCurrent Version of the Update is still 6.42.6. any help
 
User avatar
nichky
Long time Member
Long time Member
Posts: 505
Joined: Tue Jun 23, 2015 2:35 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 3:25 pm

The only access i can get is via SSH. and i downgrade to 6.44.3,nothing happens
Nikola Shuminoski
Network Engineer
E-Mail: nikola.suminoski@outlook.com
MikroTik Consultan
MTCNA l MTCRE

!) Safe Mode is your friend;
 
SimWhite
just joined
Posts: 22
Joined: Tue Jul 02, 2013 5:05 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 3:35 pm

GRE tunnels won't start anymore between 6.45.1 versions. But 6.44.3 <--> 6.45.1 are working fine.
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 23998
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 3:43 pm



and how can we get access?
You can't :D That is the point of this issue. Only the admin himself could trigger the problem. it's not a serious issue, but we still fixed it.
So we have to replace the router? so fany :)
What are you even talking about ? No, you don't have to replace anything. You have no risk here unless you plan to hack your own devices. Please read carefully.
No answer to your question? How to write posts
 
3bs
newbie
Posts: 48
Joined: Tue Aug 09, 2011 12:33 am
Location: Irkutsk, Russia

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 3:54 pm

After upgrade map receive "ERROR: wrong username or password" when connect with winbox. But connect with webfig, ssh without errors. Clear winbox cache don't helped.
WBR, 3bs =)
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 23998
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 4:08 pm

Upgrade Winbox too
No answer to your question? How to write posts
 
3bs
newbie
Posts: 48
Joined: Tue Aug 09, 2011 12:33 am
Location: Irkutsk, Russia

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 4:11 pm

winbox version 3.18
WBR, 3bs =)
 
User avatar
eworm
Member
Member
Posts: 334
Joined: Wed Oct 22, 2014 9:23 am
Location: Oberhausen, Germany
Contact:

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 4:17 pm

GRE tunnels won't start anymore between 6.45.1 versions. But 6.44.3 <--> 6.45.1 are working fine.
Is this just GRE or GRE over IPSec? Possibly an IPSec issue?
Manage RouterOS scripts and extend your devices' functionality: RouterOS Scripts
 
SimWhite
just joined
Posts: 22
Joined: Tue Jul 02, 2013 5:05 pm

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 4:25 pm

Is this just GRE or GRE over IPSec? Possibly an IPSec issue?
Both.
 
User avatar
Vlad2
just joined
Posts: 6
Joined: Thu Jun 02, 2016 2:39 pm
Location: the Kamchatka Peninsula

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 4:37 pm

After upgrade map receive "ERROR: wrong username or password" when connect with winbox. But connect with webfig, ssh without errors. Clear winbox cache don't helped.
Connect through Winbox again and the second time should already log in normally.
I only have 2 routers so it was, clicked Connect and logged in to the router
Am using at works and home
3 x CCR1016-12G
RB2011,RB3011
RB951/952,RB760
hAP lite and other devices
 
3bs
newbie
Posts: 48
Joined: Tue Aug 09, 2011 12:33 am
Location: Irkutsk, Russia

Re: v6.45.1 [stable] is released!

Mon Jul 01, 2019 4:58 pm

Connect through Winbox again and the second time should already log in normally.
I only have 2 routers so it was, clicked Connect and logged in to the router
Tried many times from several machines (win10, winxp), same error. I have more than 15 mikrotik routers, problem only with map2n.
WBR, 3bs =)
  • 1
  • 2
  • 3
  • 4
  • 5
  • 9

Who is online

Users browsing this forum: No registered users and 6 guests