i just disabled the neighbor completely, as i couldn't understand what use it had other then showing other mikrotik routers/switchesA fix for SIP related issue is not included in this release, but it is available in the 6.49beta11.
If an upgrade to the testing version is not available, try disabling MNDP in neighbor discovery settings, see command below:
/ip neighbor discovery-settings set protocol=cdp,lldp
It's this oneWhat about RB3011 port flapping re-introduced in 6.48?
) switch - fixed interface toggling for devices with multiple QCA8337, Atheros8327 or RTL8367 switch chips (introduced in v6.48);
Ou, I missed that. Thanks!It's this oneWhat about RB3011 port flapping re-introduced in 6.48?) switch - fixed interface toggling for devices with multiple QCA8337, Atheros8327 or RTL8367 switch chips (introduced in v6.48);
I use it to be enable to connect with Winbox to a router that is not in the same network segment when only MAC initiated traffic is possible.i just disabled the neighbor completely, as i couldn't understand what use it had other then showing other mikrotik routers/switchesA fix for SIP related issue is not included in this release, but it is available in the 6.49beta11.
If an upgrade to the testing version is not available, try disabling MNDP in neighbor discovery settings, see command below:
/ip neighbor discovery-settings set protocol=cdp,lldp
and a few of our cisco spa voip phones
Use a separate device. I use a Pi, with dnscrypt-proxy running for DoH and Pi-Hole as the DNS Sinkhole. Uptime more than 8 months excluding updates/firmware patches/reboots.Problem with DoH was not fixed ?! omg
yes i know, this is an solution, i'm able to do that only at my home. But i have also 10 devices where i need it too.Use a separate device. I use a Pi, with dnscrypt-proxy running for DoH and Pi-Hole as the DNS Sinkhole. Uptime more than 8 months excluding updates/firmware patches/reboots.Problem with DoH was not fixed ?! omg
And, after all, the 48 -> 49b11 -> 48.1 was workedcould not upgrade from 48 to 48.1
kernel failure in previous boot
rb3011
Upgrading production systems 3.5 hours after new release at Friday afternoon.. what can go wrong and who would be guilty.No issues and full production has been moved to these units. Will see during the weekend how all looks.
I'm sorry, but I've no idea which moderator made this edit so I can't ask directly, so: Could you please tell me when and how was I being warned? I think I wasn't informed at all so I was thinking I forgot to post it! So I reposted it! That's it! I've made this set of quotes to not leave any information behind.Problem also remains in this version.
Edit by moderator:
Please DO stop posting and quoting same set of quotes of quotes.
You have been already warned.
It is users' forum, not Mikrotik's stuff one. Send e-mails directly to support.
MikroTik support isn't any better, factually. Proof here: viewtopic.php?f=2&t=171390#p838707I'm sorry, but I've no idea which moderator made this edit so I can't ask directly, so: Could you please tell me when and how was I being warned? I think I wasn't informed at all so I was thinking I forgot to post it! So I reposted it! That's it! I've made this set of quotes to not leave any information behind.Problem also remains in this version.
Edit by moderator:
Please DO stop posting and quoting same set of quotes of quotes.
You have been already warned.
It is users' forum, not Mikrotik's stuff one. Send e-mails directly to support.
Of course you can delete this message here after reading but please message me the way you've warned me so I'll catch it next time ..
http://ap-test/webfig/#Interfaces.VLAN
http://ap-test/webfig/#Interfaces.VLAN.new
...and on Chrome 88Uncaught TypeError: map.setDefaultConf is not a function
createPane http://ap-test/webfig/master-min-d4f93cc8bdee.js:1190
updateContent http://ap-test/webfig/master-min-d4f93cc8bdee.js:1200
generateContent http://ap-test/webfig/master-min-d4f93cc8bdee.js:1204
openContent http://ap-test/webfig/master-min-d4f93cc8bdee.js:1205
onclick http://ap-test/webfig/master-min-d4f93cc8bdee.js:1137
create http://ap-test/webfig/master-min-d4f93cc8bdee.js:1137
open http://ap-test/webfig/master-min-d4f93cc8bdee.js:1125
updateContent http://ap-test/webfig/master-min-d4f93cc8bdee.js:1200
generateContent http://ap-test/webfig/master-min-d4f93cc8bdee.js:1204
onload http://ap-test/webfig/:1
master-min-d4f93cc8bdee.js:1190:323
createPane http://ap-test/webfig/master-min-d4f93cc8bdee.js:1190
updateContent http://ap-test/webfig/master-min-d4f93cc8bdee.js:1200
generateContent http://ap-test/webfig/master-min-d4f93cc8bdee.js:1204
openContent http://ap-test/webfig/master-min-d4f93cc8bdee.js:1205
onclick http://ap-test/webfig/master-min-d4f93cc8bdee.js:1137
(Async: EventHandlerNonNull)
create http://ap-test/webfig/master-min-d4f93cc8bdee.js:1137
open http://ap-test/webfig/master-min-d4f93cc8bdee.js:1125
updateContent http://ap-test/webfig/master-min-d4f93cc8bdee.js:1200
generateContent http://ap-test/webfig/master-min-d4f93cc8bdee.js:1204
onload http://ap-test/webfig/:1
Uncaught TypeError: map.setDefaultConf is not a function
at Object.container.map.createPane (master-min-d4f93cc8bdee.js:1190)
at updateContent (master-min-d4f93cc8bdee.js:1200)
at generateContent (master-min-d4f93cc8bdee.js:1204)
at openContent (master-min-d4f93cc8bdee.js:1205)
at HTMLAnchorElement.b.onclick (master-min-d4f93cc8bdee.js:1137)
http://ap-test/webfig/#Interfaces.Interface.new.VLAN
Did you do any reboots with 6.48 before this upgrade?could not upgrade from 48 to 48.1
kernel failure in previous boot
rb3011
Hi @CrayDid you do any reboots with 6.48 before this upgrade?could not upgrade from 48 to 48.1
kernel failure in previous boot
rb3011
The reboot failures with various models (RB3011 and CRS9x) is issue related to the first 6.48 release.
I have not yet tested if fresh install of 6.48.1 reboot bricks these devices - and if so - what percentage of them. 6.48 reboot bricked ~50% of the devices I tested.
I raised a support ticket for this and ended up getting told to do a Netinstall. I closed the ticket.Installed 6.48.1 to test device and first thing I noticed is that this Web UI bug introduced in 6.48 is still present in 6.48.1:
- By default /webfig/ URL (default after fresh login) always forwards to "QuickSet / Port Mapping" configuration options.
This happens even if Quick Set has been disabled and menu entries hidden in the UI.
Bug does not seem to affect functionality but is very annoying.
When you have a router like that in production, you should partition it so you can always go back to a stable situation without problem.no, i don't dare to make reboots. It is in production, and that was my mistake to rush on 6.48
i wanted PPP->Remote IPv6 prefix/IPv6 Routes features to finaly replace old scripts and without thinking pushed Upgrade button
what an idiot
From this point, my rock solid 3011 started to flap ports, and instead of rebooting i played with enable/disable to make them back to life
but now, 6.48.1 seem to solve this problem, only strange thing was upgrade path :D
48 -> 49b11 -> 48.1 was worked
could not go straight from 48 to 48.1
What do you mean shouldn't ???you should not use that as only defense,
you should use firewall rules to protect your management interfaces
You should not trust it, alt least not from public internet.What is this option for then ???
MikroTik RouterOS 6.48.1 (c) 1999-2020 http://www.mikrotik.com/
Well, here we go again ...When you have a router like that in production, you should partition it so you can always go back to a stable situation without problem.
Of course enabling partitioning in a device in production is a risk as well, it will require at least one reboot and it may further disturb the device, so it is best done BEFORE you put it in production.
But at least, when you have clicked upgrade and it was a mistake, you can go back (when you have done a partition 0->1 copy before you clicked upgrade).
Completely irrelevant! It is your own responsibility to ensure that you can operate your equipment at sufficient availability for your network.Well, here we go again ...
it is my ? fault to not partition RB in advance ?
Very observant worm!! +30 points for House of Invertebrate! ;-)BTW, the copyright needs to be updated for 2021... It still reads:
(And when you are at it... How about changing the url to https?)Code: Select allMikroTik RouterOS 6.48.1 (c) 1999-2020 http://www.mikrotik.com/
...Completely irrelevant! It is your own responsibility to ensure that you can operate your equipment at sufficient availability for your network.
That includes being responsible for backups, rollback possibilities, spare hardware in case it breaks, and also if software is suitable for your purpose.
You cannot shift that responsibility to someone else, and certainly not to a supplier.
All the points pelchi made are quite valid for any business setup. For a homeowner, however I have tons of sympathy and can only recommend use the LONGTERM firmware as your best option.look @pe1chl
lets try to make things clear
my native language is not English, but i know well what word "stable" mean
but maybe i am wrong, who know
now, would you be so kind to explain what "stable" mean in your world ? port flapping ? kernel faults ?
and, no, i don't want any other answer
straight one, meaning of word stable is ...
Stable is don't be a pussy man! Stop complaining, you'll better send a bug report.and, no, i don't want any other answer
straight one, meaning of word stable is ...
They have enabled HTTPS overwrite on their domain, technically it wouldn't matter. But you'd expect a "networking" company to know their shit and the difference between HTTP and HTTPS.BTW, the copyright needs to be updated for 2021... It still reads:
(And when you are at it... How about changing the url to https?)Code: Select allMikroTik RouterOS 6.48.1 (c) 1999-2020 http://www.mikrotik.com/
Send a bug report? Are you new to MikroTik, users both home and professionals have been reporting various bugs for decades and MikroTik refuses to fix them.Stable is don't be a pussy man! Stop complaining, you'll better send a bug report.and, no, i don't want any other answer
straight one, meaning of word stable is ...
That's not quite right, it does matter!They have enabled HTTPS overwrite on their domain, technically it wouldn't matter. But you'd expect a "networking" company to know their shit and the difference between HTTP and HTTPS.BTW, the copyright needs to be updated for 2021... It still reads:
(And when you are at it... How about changing the url to https?)Code: Select allMikroTik RouterOS 6.48.1 (c) 1999-2020 http://www.mikrotik.com/
Wouldn't matter if MikroTik configured their domain host/CDN correctly like this:That's not quite right, it does matter!They have enabled HTTPS overwrite on their domain, technically it wouldn't matter. But you'd expect a "networking" company to know their shit and the difference between HTTP and HTTPS.BTW, the copyright needs to be updated for 2021... It still reads:
(And when you are at it... How about changing the url to https?)Code: Select allMikroTik RouterOS 6.48.1 (c) 1999-2020 http://www.mikrotik.com/
An attacker will make use of the fact that the first request is unencrypted. He/she can redirect you to his/her site, you will never receive the redirect from Mikrotik's http server and thus you will never see the encrypted version of Mikrotik's site.
When ever possible links should contain https instead of just http. Do not trust that the first unencrypted request will redirect you where you expect it.
No. There's nothing Mikrotik can do on their servers. If the attacker is successful no request will ever reach Mikrotik's servers.Wouldn't matter if MikroTik configured their domain host/CDN correctly like this:
![]()
I do see the same on my RB 750G v3it's better?
[admin@Master] > export
# feb/10/2021 17:27:15 by RouterOS 6.48.1
# software id = GZ2B-V28G
#
# model = RB962UiGS-5HacT2HnT
# serial number = XXXX
/interface bridge
add admin-mac=74:4D:28:CF:8C:AC auto-mac=no comment=defconf name=bridge
/interface wireless
set [ find default-name=wlan2 ] band=5ghz-n/ac channel-width=20/40/80mhz-eeCe country="united states" disabled=no frequency=5540 installation=indoor mode=ap-bridge name=\
5ghz ssid=Majki wireless-protocol=802.11 wps-mode=disabled
set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-eC country=no_country_set disabled=no frequency=auto frequency-mode=superchannel hide-ssid=yes \
installation=indoor mode=ap-bridge name=24ghz ssid=Majki2 wireless-protocol=802.11 wps-mode=disabled
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk mode=dynamic-keys supplicant-identity=MikroTik wpa-pre-shared-key=mypassword wpa2-pre-shared-key=\
mypassword
add authentication-types=wpa2-psk management-protection=allowed mode=dynamic-keys name=wpa2 supplicant-identity=MikroTik wpa2-pre-shared-key=mypassword
/ip pool
add name=dhcp ranges=192.168.88.10-192.168.88.254
/ip dhcp-server
add address-pool=dhcp disabled=no interface=bridge lease-time=1h10m name=defconf
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=sfp1
add bridge=bridge comment=defconf interface=24ghz
add bridge=bridge comment=defconf interface=5ghz
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
/ip address
add address=192.168.88.1/24 comment=defconf interface=bridge network=192.168.88.0
/ip dhcp-client
add comment=defconf disabled=no interface=ether1
/ip dhcp-server lease
add address=192.168.88.15 client-id=1:f4:92:bf:a0:c6:33 mac-address=F4:92:BF:A0:C6:33 server=defconf
add address=192.168.88.22 client-id=1:48:5f:99:cb:93:a6 comment="Brother DCW-1610W" mac-address=48:5F:99:CB:93:A6 server=defconf
/ip dhcp-server network
add address=192.168.88.0/24 comment=defconf dns-server=8.8.8.8,1.1.1.1,9.9.9.9 gateway=192.168.88.1
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan
/ip firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN
/ipv6 firewall address-list
add address=::/128 comment="defconf: unspecified address" list=bad_ipv6
add address=::1/128 comment="defconf: lo" list=bad_ipv6
add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6
add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6
add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6
add address=100::/64 comment="defconf: discard only " list=bad_ipv6
add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6
add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6
add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6
add address=::224.0.0.0/100 comment="defconf: other" list=bad_ipv6
add address=::127.0.0.0/104 comment="defconf: other" list=bad_ipv6
add address=::/104 comment="defconf: other" list=bad_ipv6
add address=::255.0.0.0/104 comment="defconf: other" list=bad_ipv6
/ipv6 firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMPv6" protocol=icmpv6
add action=accept chain=input comment="defconf: accept UDP traceroute" port=33434-33534 protocol=udp
add action=accept chain=input comment="defconf: accept DHCPv6-Client prefix delegation." dst-port=546 protocol=udp src-address=fe80::/10
add action=accept chain=input comment="defconf: accept IKE" dst-port=500,4500 protocol=udp
add action=accept chain=input comment="defconf: accept ipsec AH" protocol=ipsec-ah
add action=accept chain=input comment="defconf: accept ipsec ESP" protocol=ipsec-esp
add action=accept chain=input comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=input comment="defconf: drop everything else not coming from LAN" in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop packets with bad src ipv6" src-address-list=bad_ipv6
add action=drop chain=forward comment="defconf: drop packets with bad dst ipv6" dst-address-list=bad_ipv6
add action=drop chain=forward comment="defconf: rfc4890 drop hop-limit=1" hop-limit=equal:1 protocol=icmpv6
add action=accept chain=forward comment="defconf: accept ICMPv6" protocol=icmpv6
add action=accept chain=forward comment="defconf: accept HIP" protocol=139
add action=accept chain=forward comment="defconf: accept IKE" dst-port=500,4500 protocol=udp
add action=accept chain=forward comment="defconf: accept ipsec AH" protocol=ipsec-ah
add action=accept chain=forward comment="defconf: accept ipsec ESP" protocol=ipsec-esp
add action=accept chain=forward comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=forward comment="defconf: drop everything else not coming from LAN" in-interface-list=!LAN
/system clock
set time-zone-name=Europe/Warsaw
/system identity
set name=Master
/system routerboard settings
set auto-upgrade=yes
/tool graphing interface
add allow-address=192.168.88.0/24
/tool graphing queue
add allow-address=192.168.88.0/24
/tool graphing resource
add allow-address=192.168.88.0/24
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
/tool traffic-monitor
add interface=24ghz name=Test
add interface=5ghz name=test2
I'm running into the same thing with my hAP_AC2 . I don't understand why i'm getting some many sector re-writes. I was using 6.48.1 as the previous message but i'm still seeing them with the latest long term version.Tried new stable 6.48.1 on my hAP ac2 after long-term 6.46.8.
The same situation with new long-term 6.47.9.
I don't like this difference in sector write quantity with the same config.
That's why had to downgraded to the 6.46.8.
6.48.1_cr.png6.46.8_cr.png
I had the same issue. It works again after I clicked "OK" on the empty settings page. (I use the web interface.)Why do not not see Temperature/Voltage?
#Added later
Please welcome RZD Russia on Mikrotik forum!webproxy on hAP lite still doesn't work. Since versions 6.45.x
That is correct. You can do "auto proxy config" e.g. on Windows machines but it requires a webserver to store a file with the proxy config (the URL of that file is sent as a DHCP option).So if you have no control of the client, webproxy is useless.
Hi Emils,RouterOS version 6.48.1 has been released in public "stable" channel!
[...]
If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while router is not working as suspected or after some problem has appeared on device
Please keep this forum topic strictly related to this particular RouterOS release.
That is not the only "32-bit counter" issue in RouterOS v6. I have previously reported such issues and it seems the fix for that is planned only in v7.as reported on 6.48, queue tree packets counter seems to be a 32 unsigned integer and is overflowing at 2 million and something packets.
.That is not the only "32-bit counter" issue in RouterOS v6. I have previously reported such issues and it seems the fix for that is planned only in v7.
The reported SIP phone issue is fixed with this change:
*) fastpath - fixed IP packet receive on bridge and bonding interfaces when destination MAC address match with slave port MAC;
The suggestion to disable MNDP is because in the 6.48 version MNDP had some changes and it now uses an individual slave port MAC address instead of bridge/bond MAC. The same thing is done with other neighbor protocols, but MNDP is the only one that uses IP packets. It turns out, this can affect the ARP table on certain devices and they might start to use this other MAC from MNDP as a destination. On the RouterOS side with an active bridge/bond fast-path, these packets were dropped.
You might not notice the issue because MNDP is sent only once in a minute, the bridge did not use a fast-path or your phone simply ignored the MNDP.
Interesting. I wonder if this is related to the issue I had found? viewtopic.php?f=21&t=171035&p=836796#p836789But when you reboot the phone, until ROS loses neighbor information (the phone is still present in neighbor cache), ROS does not respond to LLDP-MED probe immediately, instead it is sending LLDP frame every minute. As the phone does not see immediate reponse (in a few seconds) to the LLDP-MED probe, it abandons VLAN assignment via LLDP-MED and tries to connect untagged (in native VLAN).
When looking at the behavior it seems there are three different problems with LLDP:Interesting. I wonder if this is related to the issue I had found? viewtopic.php?f=21&t=171035&p=836796#p836789