Community discussions

MikroTik App
 
User avatar
strods
MikroTik Support
MikroTik Support
Topic Author
Posts: 1684
Joined: Wed Jul 16, 2014 7:22 am
Location: Riga, Latvia

v7.19rc [testing] is released!

Tue Apr 29, 2025 2:41 pm

RouterOS version 7.19rc has been released on the "v7 testing" channel!

Before an upgrade:
1) Remember to make backup/export files before an upgrade and save them on another storage device;
2) Make sure the device will not lose power during the upgrade process;
3) Device has enough free storage space to download all RouterOS packages.

What's new in 7.19rc2 (2025-May-07 10:32):

*) device-mode - fixed print command (introduced in v7.19rc1);
*) ip-service - show all TCP/UDP ports on system, including ports in containers (additional fixes);
*) lte - deactivate current eSIM profile before activating new profile;
*) lte - fixed default APN for configless modems;
*) route - fixed route rule "min-prefix" unset;
*) route - show "routing-table" by default on console print output;
*) switch - properly match IPv6 packets with empty ACL rule on CRS3xx, CRS5xx, CCR2004, CCR2116, CCR2216, RDS devices;
*) timezone - updated timezone information from "tzdata2025b" release;
*) winbox - properly show/hide OSPF, RIP and BGP tabs for IPv6 routes;

What's new in 7.19rc1 (2025-Apr-28 16:02):

*) arm64 - fixed possible transmit queue timeout on CCR2216, CCR2116, RDS2216;
*) bth - properly specify "in-interface" when adding dynamic firewall NAT rule;
*) conntrack - improved stability on busy systems;
*) console - print large number argument values in proper format in export output;
*) defconf - added DHCP Client on RDS2216 MGMT interface;
*) defconf - increased PPP interface wait time;
*) disk - renamed "eject-drive" command to "eject" (CLI only);
*) disk - renamed "format-drive" command to "format" (CLI only);
*) ip-service - show all TCP/UDP connections on the system (additional fixes);
*) ip-service - show all TCP/UDP ports on system, including ports in containers (additional fixes);
*) ipsec - fixed system failure on MMIPS devices when using IPsec services;
*) l3hw - fixed FastTrack/NAT packet routing over VLAN directly assigned to a switch port (introduced in v7.19beta3)
*) lte - automatically enable roaming for known roaming only SIM/eSIM profiles;
*) lte - fixed EC200A-EU APN authentication;
*) lte - fixed LTE passthrough activation issue when IPv6 APN is used;
*) lte - fixed MBIM modem recovery after modem unexpected restart;
*) lte - fixed possible crash or missing IPv6 address on first APN activation when IPv6 capable APN is used;
*) lte - initialize Quectel modems as soon as they are ready after unexpected restart;
*) lte - show correct value for 5G SA "current-cellid";
*) ovpn-server - fixed server start-up after a reboot;
*) ovpn-server - properly show "username" in log when authentication fails;
*) ptp - fixed PTP on 2.5G links;
*) ptp - fixed PTP on QSFP ports for CRS326, CRS510, CRS520, CCR2216 devices;
*) rose-storage - added degraded Btrfs mount option (CLI only);
*) rose-storage - improved system stability when removing NVMe disks;
*) rose-storage - rename default RAID device name from "raid" to "raid-array;
*) queue - speed-up queue addition/removal process;
*) snmp - fixed v2 getnext noSuchName error when OID with requested key does not exist;
*) upgrade - improved free disk space calculation;
*) upgrade - improved upgrade procedure reliability;
*) vxlan -improved system stability when using IPv6 VTEP;
*) wifi - fixed 5GHz chain enumeration on Chateau PRO ax;
*) winbox - added comment fields for WiFi "Multi Passphrase Group" menu;
*) winbox - added missing "Switch" menu for RDS;
*) winbox - added missing file systems for disk formatting;
*) winbox - added missing parameters for BTRFS related action functions;
*) winbox - added mount-point parameter under "Disk/Settings" menu;
*) winbox - allow opening BTRFS menu entries;
*) winbox - fixed "registry-url" field under "Containers" configuration menu;
*) winbox - fixed several statistics counters not being read only;
*) winbox - fixed time interval type fields precision under "Disks" menu;
*) winbox - make BTRFS "Parent" and "Send Parent" options optional;
*) winbox - renamed "raid-member" to "raid member" flag for consistency;
*) winbox - show eSIM profiles under eSIM menu without manual refresh;

Other changes since v7.18:

*) arp - added warning, when "Published" ARP entry used on an interface with "reply-only" ARP mode enabled;
*) bgp - added input.filter-community;
*) bgp - fixed excessive CPU usage;
*) bgp - fixed input.accept-community;
*) bgp - fixed memory leak on receiving notify and closing session;
*) bgp - improved performance on BGP input;
*) bonding - added setting for LACP active/passive modes;
*) bridge - added new STP monitoring fields for bridge and ports (Tx/Rx BPDU, Tx/Rx TC, forward/discard transitions, last topology change, message-age, max-age, remaining-hops, bridge-id);
*) bridge - fixed bridge port hang when using invalid port IDs;
*) bridge - fixed dhcp-snooping in QinQ setups (additional fixes);
*) bridge - fixed issue when local MACs were removed unnecessarily;
*) bridge - fixed minor memory leak on link down;
*) bridge - fixed multicast packet flow on hardware offloaded bridge which acts as "multicast-router";
*) bridge - improved default bridge and port layout on console and GUI;
*) bridge - improved stability in case of configuration error (introduced in v7.15);
*) bridge - moved "TCHANGE" logs from bridge,stp to bridge,stp,debug;
*) bridge - offload VXLAN only if another HW offloaded port exists in the bridge;
*) bridge - properly flush bridge hosts when bonding is used as bridge port and loses hw-offloading status;
*) bridge - rename "ports" to "interface" under MDB table for configuration consistency with other menus;
*) bridge - renamed STP monitor fields (port-number to port-id, designated-port-number to designated-port-id, designated-bridge to designated-bridge-id);
*) bridge - show designated-* monitor field for all port roles;
*) bridge - show warning instead of causing error when using multicast MAC as admin-mac (introduced in v7.17);
*) capsman - fixed "undo" command for cap interfaces;
*) certificate - added built-in root certificate authorities store (additional fixes);
*) certificate - do not include CA identity in SCEP POST requests;
*) certificate - fixed cloud-dns challenge validation for sn.mynetname.net (CLI only);
*) certificate - improve error message when trying to use certificate;
*) certificate - optimize trust store;
*) cloud - fixed issues when BTH is toggled fast between enable/disable;
*) cloud - improved "BTH Files" web page design;
*) console - added on-error to "for" and "foreach" loops;
*) console - added proplist to monitor command;
*) console - disallow incomplete double-quoted arguments (allows multiline string pasting);
*) console - do not treat return values as errors in scripts run from scheduler;
*) console - enabled verbose error logging for non-scripted/non-verbose imports;
*) console - fixed issue with file-name completion (introduced in v7.18);
*) console - fixed issue with files when using scripts (introduced in v7.18);
*) console - fixed misaligned multiline in brief print mode;
*) console - improve time value handling;
*) console - improved file add/remove process stability;
*) console - set "/system/note show-at-login=yes" the default value after configuration reset;
*) console - validate script arguments (do, on-error, etc.) and reject invalid values;
*) container - allow changing container name;
*) container - fixed repository name handling to prevent redirect issues when basic authentication is used;
*) container - try to derive a user readable container name from remote image or file;
*) device-mode - added new "rose" mode where "container" feature is enabled by default;
*) dhcp-server - improved stability when dual stack is used and one of the servers is removed (introduced in v7.19beta2);
*) dhcpv4 - improved outgoing packet logging;
*) dhcpv4-client/server - added support for DHCPv4 reconfigure messages;
*) dhcpv4-server - "Relay-Agent-Information" (82) option moved at the end of option list in response packets;
*) dhcpv4-server - accept packets with htype 6;
*) dhcpv4/v6-client - added check-gateway parameter;
*) dhcpv4/v6-client - fixed default route when DHCP client interface is in VRF;
*) dhcpv6-client - allow selecting to which routing tables add default route;
*) dhcpv6-relay - clear saved routes on DHCP release;
*) dhcpv6-relay - show client address;
*) dhcpv6-server - allow unsetting prefix-pool for static bindings and show warning if prefix is not in selected prefix-pool;
*) dhcpv6-server - change bound status to waiting on binding disable;
*) dhcpv6-server - change static binding bound status to waiting on server disable;
*) dhcpv6-server - fix when expired static binding is declined with false "binding belogs to another server" reason;
*) dhcpv6-server - improved stability when disabled server have static bindings;
*) dhcpv6-server - improved stability when disabling server with active bindings;
*) disk - add "sector-size" property in print detail;
*) disk - add reset-counters to /disk btrfs filesystem;
*) dlna - improved folder indexing behavior;
*) dns - improved DNS server service stability;
*) dot1x - fixed dynamic switch ACL rules on boards with a lot of ports (e.g. CRS520);
*) ethernet - improved Ethernet and PoE port mapping to ensure a consistent and reliable interface order;
*) fetch - fixed false successful messages in FTP mode;
*) file - added show-hidden parameter to /file/print, allowing referencing and deleting hidden files;
*) file - fixed missing files from The Dude (introduced in v7.18);
*) file - improved responsiveness on slow filesystems;
*) firewall - always show "passthrough" when exporting mangle table;
*) firewall - detect VRF addresses as local;
*) firewall - fixed IP/Settings "ipv4-fasttrack-active" status showing as inactive when it is active;
*) health - hide settings in CLI if there is nothing to show;
*) health - improved performance on devices with simple voltage sensors;
*) hotspot - improvements to memory usage;
*) igmp-proxy - do not try to send leave message for multicast groups that the device itself has joined on the upstream interface (cosmetic fix for proxy error logs);
*) ike2 - improved initial key exchange process on slow or unreliable connections;
*) iot - improvement to lora dev-addr-validation behavior;
*) iot - improvement to lora join eui/net id filtering behavior;
*) ip-service - show error message when service enable fails;
*) ippool6 - properly free IPv6 pool used prefix when it is not used any more;
*) ipsec - lower standalone cipher, hash priority when using ctr aead;
*) ipv6 - avoid watchdog reboot due to link-local IPv6 address reconfiguration on thousand of interfaces at once;
*) ipv6 - fixed EUI-64 false error message on address update when "from-pool" option is used;
*) isis - properly validate 3-way hello handshake;
*) l2tp-ether - improved stability when trying to connect to disabled L2TP server with IPsec;
*) l3hw - remove VLAN tag before VXLAN encapsulation (fixes pvid behavior for bridged VXLAN);
*) log - added additional CEF fields from firewall and login logs;
*) log - fixed remote logging after reboot when hostname is forwarded to a DNS server;
*) log - populate in/out fields in firewall CEF logs with correct data;
*) lte - AT modems, improved redialing when modem lost connectivity without notifying host about APN status change;
*) lte - Chateau 5G R16 fix DHCP relay packet forwarding using LTE interface;
*) lte - added UICC parameter in LTE monitor for R11e-4G modem;
*) lte - additional fixes for eSIM management support;
*) lte - fixed LTE status update or possible crash when modem is unexpectedly removed from system;
*) lte - fixed Router Advertisement processing issue for AT modems when an APN with "ip-type=ipv6" was configured;
*) lte - fixed initialization for Neoway N75 modem;
*) lte - fixed initialization for R11e-LTE6 modem;
*) lte - fixed modem recovery after firmware upgrade for R11e-LTE modem;
*) lte - improved dialer for EC200A-EU modem;
*) lte - initial support for user settable modem redial timer;
*) lte - reset internal link-recovery-timer on sim slot change;
*) lte - set apn profile name the same as apn if no name specified when creating the profile;
*) net - remove support for automatic multicast tunneling (AMT) interface (introduced in v7.18);
*) netinstall - fixed issue with launching the app (introduced in v7.19beta2);
*) netinstall - improved network socket re-opening when NIC status changes while running the server (additional fixes);
*) netinstall - provide warning if memory on installed router is full after installation;
*) netinstall - show warning when network configuration on PC might not be appropriate for installation;
*) netinstall-cli - check for other running Netinstall servers on startup;
*) netinstall-cli - clear old configuration before user script using "-s";
*) netinstall-cli - fixed issue with applying the branding package;
*) ospf - fixed "mismatch" typo in logs;
*) ovpn - properly match GCM hardware acceleration capabilities (introduced in v7.17);
*) ovpn-server - do not reset active connections when changing comment or name;
*) pimsm - fixed issue where own query caused querier detection;
*) poe-out - upgraded firmware for 802.3at/bt PSE controlled boards (the update will cause brief power interruption to PoE-out interfaces);
*) port - added USB mode switch support for "huawei-alt-mode";
*) port - added support for Huawei E3372-325 variant (vendor-id="0x3566" device-id="0x2001");
*) port - improvements to KNOT BG77 modem port channel handling;
*) ppc - fixed VLAN TCP packet transmit on PPC devices;
*) profiler - improved process classification;
*) ptp - added "ptp" logging topic;
*) ptp - allow multiple instances;
*) queue - fixed system failure when CAKE kind queue was configured but queue type definition does not exist anymore (introduced in v7.18);
*) quickset - improved system stability;
*) rose-storage - added Btrfs disk balance command (CLI only);
*) rose-storage - fixed mounting Btrfs subvolumes using macOS SMB client;
*) rose-storage - fixes for btrfs;
*) rose-storage - show btrfs balance and scrub errors if any;
*) route - added options to set dynamic-in and connected-in chains in /routing/settings;
*) route - fixed stuck output when calling prints from multiple routing menus;
*) route - improve stability on BGP reconnect;
*) route - make AFI naming consistent;
*) route - show BGP session name instead of cache-id;
*) route-filter - fixed the "blackhole" option setting process;
*) route-filter - improved performance;
*) sfp - added sfp-encoding data output from EEPROM;
*) sfp - improved QSFP link stability for CRS354 devices;
*) sniffer - add max-packet-size (2k-64k) setting to be able to sniffer more than 2k data per packet;
*) ssh - fixed authorization with SSH key when multiple user SSH public keys are imported;
*) ssl/tls - respond with more precise alert error messages;
*) ssl/tls - send certificate authority in Certificate message even if it is not trusted;
*) switch - do not count rx-too-long multiple times on 100Gbps QSFP28;
*) switch - fixed egress mirroring for packets coming from external CPU port (e.g. CRS520, CCR2216, CCR2116);
*) switch - flush CPU port FDB entries on switch disable;
*) switch - improve rate limit accuracy for MT7531, MT7621, EN7562CT;
*) switch - improved boot stability on devices with Alpine CPU and switch chip;
*) switch - improved stability when enabling IGMP snooping with VXLAN (introduced in v7.18);
*) system - fixed "/system reboot" when the system disk is completely full;
*) system - improved internal "flash/" prefix handling for different file path related settings;
*) system - improved system stability when sending TCP data from the router;
*) torch - improved data reporting;
*) webfig - allow table column resize over side toolbar;
*) webfig - don't reorder rows when selecting header cells with Alt+click;
*) webfig - fixed graphs appearance under "Tools/Graphing" menu (introduced in 7.19beta2);
*) webfig - show IPv6 firewall connections;
*) webfig - show missing data in "IP/DNS/Cache" records;
*) wifi - add channel.reselect-time parameter which allows to perform channel re-sellection at given time of day (CLI only);
*) wifi - add information on CAP uptime and connection uptime in "Remote CAP" list;
*) wifi - added "eap-identity" to registration table;
*) wifi - added SSID to logs;
*) wifi - display error when trying to run snooper on interface which does not support wireless packet capture (sniffer);
*) wifi - fix authentication of clients which omit some RSN information at association;
*) wifi - fix incorrect info about current channel for station interfaces after AP has switched channel (introduced in v7.17);
*) wifi - fix possible snooper crash when parsing frames with malformed headers;
*) wifi - fixed incorrect attribution of 802.11be capability to 802.11ax APs in output of scan command (introduced in v7.19beta2);
*) wifi - fixed sending of reassociation response frames (introduced in v7.19beta2);
*) wifi - implement WPA2 PSK authentication with key derivation using SHA256 (CLI only);
*) wifi - improve parsing of captured frames which have nested flags in radiotap header;
*) wifi - improved stability for wifi interfaces;
*) wifi - improved wifi connection stability when used as a station for "b" mode access point;
*) wifi - re-word log entries about disconnections which are likely caused by peer using a wrong passphrase;
*) wifi - use at least TLS 1.2 for securing connection between CAPsMAN manager and CAPs (additional fixes);
*) wifi-qcom - fix OWE authentication for 802.11ac interfaces in station mode;
*) wifi-qcom - fix inability of interfaces in station mode to connect if they do not support full bandwidth of AP;
*) winbox - added "MAC Telnet" under "Wifi/Registration" menu;
*) winbox - added "Multi Passphrase Group" for wifi;
*) winbox - added "Reset MAC address" for legacy wireless and wifi;
*) winbox - added comment under "User Manager/Routers" menu;
*) winbox - added country to wireless setup-repeater;
*) winbox - added netmask support for switch rule Src/Dst IPv6 Address settings;
*) winbox - changed default wireless wds-cost-range values;
*) winbox - do not show not relevant values for certificate template;
*) winbox - fixed "Multi Passphrase Group" setting for wifi;
*) winbox - fixed missing SMB client on non-ROSE devices;
*) winbox - fixed switch menu for Chateau 5G;
*) winbox - improve graphing efficiency when communicating with WinBox;
*) wireguard - add wg-import config-string parameter to import config directly from terminal;
*) wireguard - update peer info on "get" command;
*) wireless - added "eap-identity" to registration table;
*) wireless - implement handling of RADIUS disconnect messages by CAPsMAN;
*) wireless - suggest all legitimate frequencies for interfaces with 20/40mhz-XX channel width in GUI;
*) x86 - added support for Emulex NIC;
*) x86 - i40e updated driver to 2.27.8 version;
*) x86 - remove unnecessary console output on shutdown;

To upgrade, click "Check for updates" at /system package in your RouterOS configuration interface, or head to our download page: http://www.mikrotik.com/download

If you experience version related issues, please send a supout file from your router to support@mikrotik.com. File must be generated while a router is not working as suspected or after some problem has appeared on the device

Please keep this forum topic strictly related to this particular RouterOS release.
 
User avatar
eworm
Forum Guru
Forum Guru
Posts: 1101
Joined: Wed Oct 22, 2014 9:23 am
Location: Oberhausen, Germany
Contact:

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 2:43 pm

Edit... Scratch that, already removed. 👍

Why does this have changes from 7.18rc2? Copied too much?
 
m4rk3J
Frequent Visitor
Frequent Visitor
Posts: 55
Joined: Thu Jan 27, 2022 2:41 pm

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 3:21 pm

Any plans to add “eap-identity” to Winbox as well? :)
 
TrevinLC1997
newbie
Posts: 32
Joined: Mon Jan 06, 2025 7:51 am

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 3:30 pm

Any plans to add “eap-identity” to Winbox as well? :)
Oh is the eap-identity/remote cap info for cli only? That would make more sense why I can’t see it in winbox.
 
User avatar
loloski
Member
Member
Posts: 480
Joined: Mon Mar 15, 2021 9:10 pm
Location: Philippines

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 3:43 pm

What are the MT product that support e-Sim? or this is just preparation for the future release?
 
itimo01
Member Candidate
Member Candidate
Posts: 278
Joined: Thu Jun 29, 2023 2:55 am
Location: Germany
Contact:

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 3:54 pm

What are the MT product that support e-Sim? or this is just preparation for the future release?
Check this viewtopic.php?t=213245
 
User avatar
loloski
Member
Member
Posts: 480
Joined: Mon Mar 15, 2021 9:10 pm
Location: Philippines

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 4:19 pm

Ok thanks it means i was under the rock these days, it's good that they have an official product now that support e-Sim I hope even the cheaper once will have this in the future
 
User avatar
mantouboji
Frequent Visitor
Frequent Visitor
Posts: 59
Joined: Mon Aug 01, 2022 2:21 pm
Location: Shanghai

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 4:28 pm

e50ug can't accessed after upgrade from 7.19beta8
 
User avatar
grusu
Member Candidate
Member Candidate
Posts: 152
Joined: Tue Aug 13, 2013 7:35 am
Location: Bucharest, Romania

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 4:28 pm

*) wifi - add information on CAP uptime and connection uptime in "Remote CAP" list;

It seems to only appear in CLI :(
 
blacksnow
Frequent Visitor
Frequent Visitor
Posts: 63
Joined: Wed Feb 15, 2023 4:46 pm

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 6:15 pm

The wireguard implementation needs some TLC. Confirmed regression in this release with bridge/vlan/wireguard not exactly sure which new modification did it though. Also incidental finding about temporarily crashing the router.

TLDR:
1) You can essentially ddos the router and cause it to crash network traffic on all WG interfaces by overloading a single unique tunnel which shouldn't be possible. Yes, you must be an authorized client so this is not a critical security concern but what would be expected is maybe 1 core pegged to 100% and that particular tunnel to be unstable. But not all WG interfaces to crash, and all other tunnels to become unavailable/down, especially when you still have CPU resources to burn. AFAIK each unique WG interface creates 2 threads (1 for crypt, 1 for decrypt), so you can kill 1 WG interface with DDOS but as long as you have CPU resources the other tunnels should be fine and on CCR2216 you have plenty of CPU.

EDIT: It actually kills network traffic for all interfaces on the bridge, WG or not. I suspect this is related to something in bridge handling/routing of VLAN packets?

2) When you have a client on the local network (not connected via wireguard) sending packets to a client behind a wireguard connection there is significant packet loss and extremely variable connection performance. However, if you send packets the other way (from the WG client routed through the tunnel to a client on the local lan) there is no packet loss, and everything works normally.

DDoS/Crashing the router only occurs in 1 direction, from a client on local lan sending more bandwidth than the router can process through a WG tunnel to a target on the other end of the tunnel. If you send from the WG tunnel to a local lan, you can send as much as you want and nothing happens, extra packets are simply dropped (expected result as the queue is overflowing).

Setup (CCR2216) - v7.19rc:
1) Local LAN client Y on VLAN 100 (single bridge setup).
2) WG Tunnel on the Router, for client X
3) Fasttrack enabled/disabled doesn't make a difference, no L3HW offload enabled (disabled by setting the no L3HW on the packets) -- Also tested w/Torch, so it isn't a L3HW issue, unless there is a bug in disabling L3HW offload.
4) iperf3 running on local lan client.
5) iperf3 from client X -> client Y, results normal (roughly 1.5GB/s top speeds on a single thread [-P = 1], up to 2GB/s on 4 threads [-P = 4])
6) iperf3 from client Y -> client X, results abnormal, heavily fluctuating performance, packet loss etc. This is both with tcp and udp tests. On udp tests you can kill the router temporarily.


v7.18.2 Stable Results:
  • You can still kill the router (all links on the bridge will go down and then come back)
  • Performance in both directions is stable. (Client X <-> Client Y)
 
User avatar
Kentzo
Forum Veteran
Forum Veteran
Posts: 700
Joined: Mon Jan 27, 2014 3:35 pm
Location: California

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 8:34 pm

*) ip-service - show all TCP/UDP connections on the system (additional fixes);
*) ip-service - show all TCP/UDP ports on system, including ports in containers (additional fixes);
Where do I see these values?
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1363
Joined: Mon Sep 23, 2019 1:04 pm

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 8:38 pm

*) ip-service - show all TCP/UDP connections on the system (additional fixes);
*) ip-service - show all TCP/UDP ports on system, including ports in containers (additional fixes);
Where do I see these values?
In IP/Services.
 
User avatar
Kentzo
Forum Veteran
Forum Veteran
Posts: 700
Joined: Mon Jan 27, 2014 3:35 pm
Location: California

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 8:42 pm

In IP/Services.
Is there something special on enterprise devices? My `/ip/service` shows RouterOS's access services (winbox, www, api, etc). I struggle to connect what "all TCP/UDP connections on the system" and "all TCP/UDP ports on system, including ports in containers" have to do with that.
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1363
Joined: Mon Sep 23, 2019 1:04 pm

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 8:47 pm

2025-04-29-001.PNG
The listening ports of other services were not shown there before, the ones that have the D flag (dynamic).
You do not have the required permissions to view the files attached to this post.
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4868
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 9:21 pm

In IP/Services.
The issue is RN says "connections", not "listeners"... There is a difference.
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1363
Joined: Mon Sep 23, 2019 1:04 pm

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 10:04 pm

You can choose to understand what they meant to say or you can choose to get lost in translation.
 
mstanciu
just joined
Posts: 1
Joined: Mon Mar 18, 2024 7:39 pm

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 10:26 pm

Got a random kernel panic on hAP ax3 used as a slave in CAP.
2025-04-29 16:26:34 system,error,critical kernel failure in previous boot
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4868
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.19rc [testing] is released!

Tue Apr 29, 2025 10:56 pm

You can choose to understand what they meant to say or you can choose to get lost in translation.
why not be accurate and fix the RN?
 
User avatar
strods
MikroTik Support
MikroTik Support
Topic Author
Posts: 1684
Joined: Wed Jul 16, 2014 7:22 am
Location: Riga, Latvia

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 8:26 am

*) ip-service - show all TCP/UDP connections on the system (additional fixes);
*) ip-service - show all TCP/UDP ports on system, including ports in containers (additional fixes);

Please re-read changelog - one entry is about "connections" and one about "ports" or, as you prefer - "listeners".
 
User avatar
strods
MikroTik Support
MikroTik Support
Topic Author
Posts: 1684
Joined: Wed Jul 16, 2014 7:22 am
Location: Riga, Latvia

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 8:56 am

Anyone, ever, experiencing system reboots - please send supout files to support@mikrotik.com. Such problems can be debugged only by MikroTik staff. Logs show just the fact that "there was a problem". Logs do not say anything about its nature and cause.
 
oskarsk
MikroTik Support
MikroTik Support
Posts: 75
Joined: Mon May 13, 2019 9:41 am

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 9:02 am

e50ug can't accessed after upgrade from 7.19beta8
Send us supout rif file and details on the issue.
 
User avatar
strods
MikroTik Support
MikroTik Support
Topic Author
Posts: 1684
Joined: Wed Jul 16, 2014 7:22 am
Location: Riga, Latvia

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 9:38 am

Support for eSIM functionality has been added in this RouterOS release, and you can already try it out, if you have some physical eSIM already available.
What are the MT product that support e-Sim? or this is just preparation for the future release?
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1363
Joined: Mon Sep 23, 2019 1:04 pm

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 9:39 am

What's a physical eSIM?
 
ivicask
Member
Member
Posts: 455
Joined: Tue Jul 07, 2015 2:40 pm
Location: Croatia, Zagreb

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 10:03 am

What's a physical eSIM?
A piece of cardboard with QR code on it i guess:)
 
User avatar
woland
Member
Member
Posts: 339
Joined: Mon Aug 16, 2021 4:49 pm

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 10:09 am

What's a physical eSIM?
A piece of cardboard with QR code on it i guess:)
Not exactly: https://esim.me/
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1697
Joined: Thu Nov 12, 2020 12:07 pm

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 10:23 am

This is actually pretty nice. Did not know physical eSIM is a thing!
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1363
Joined: Mon Sep 23, 2019 1:04 pm

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 10:27 am

*) ip-service - show all TCP/UDP connections on the system (additional fixes);
*) ip-service - show all TCP/UDP ports on system, including ports in containers (additional fixes);

Please re-read changelog - one entry is about "connections" and one about "ports" or, as you prefer - "listeners".
For the ones still wondering:
"connections" :
2025-04-30-0001-01-conn.png
"ports":
2025-04-30-0001-01-ports.png
You do not have the required permissions to view the files attached to this post.
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1697
Joined: Thu Nov 12, 2020 12:07 pm

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 10:39 am

Thank you Znevna! Maybe I am naive but I still believe some day Mikrotik does a kind of extended changelog which explains changes in detail like this.
 
Njumaen
Frequent Visitor
Frequent Visitor
Posts: 99
Joined: Wed Feb 24, 2016 8:41 pm
Location: Bielefeld, Germany
Contact:

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 10:42 am

This is actually pretty nice. Did not know physical eSIM is a thing!
Maybe give https://sysmocom.de/products/sim/sysmoc ... index.html a try as well ;)
 
e4sy
just joined
Posts: 5
Joined: Tue Nov 18, 2008 1:15 pm

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 10:58 am

On CCR2116 with large number of peers(~1000) ipsec becomes unresponsive after reboot. Single IPSec process saturates single core and neither site to site tunnels nor road-warrior users are able to connect. IPSec tabs in Winbox also experience significant delays when it comes to refreshing information.
The workaround is to kill all IPSec connections, disable all peers and then re-enable in batches of 100-150 every 30-45s. After that, IPSec works as expected.
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1943
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 11:19 am

Looks like you pushed a release candidate (beta) to production. Probably not the smartest move.
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1363
Joined: Mon Sep 23, 2019 1:04 pm

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 11:27 am

Nobody tests these releases in real world scenarios, so we have beta testers that risk bricking their production routers for that.
They receive a T-Shirt every two years. (With the classic "We couldn't reproduce the issue on our side" , obviously.)
 
e4sy
just joined
Posts: 5
Joined: Tue Nov 18, 2008 1:15 pm

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 11:43 am

Looks like you pushed a release candidate (beta) to production. Probably not the smartest move.
Just reporting. That issue has been present in RouterOS on CCR2116 since at least 7.12.1 along with few others (like for example ipsec crashing after opening installed-sa tab in winbox).
 
blacksnow
Frequent Visitor
Frequent Visitor
Posts: 63
Joined: Wed Feb 15, 2023 4:46 pm

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 12:05 pm

Looks like you pushed a release candidate (beta) to production. Probably not the smartest move.
Just reporting. That issue has been present in RouterOS on CCR2116 since at least 7.12.1 along with few others (like for example ipsec crashing after opening installed-sa tab in winbox).
Yeah the tunnelling aspects Wireguard/IPSec/OpenVPN in RouterOS need some serious attention. While they work (generally to some degree), they have all had bugs, performance regressions and other issues since early 7.x series and continue to this day. If your doing anything other than slight connectivity through those tunnels to your router its a pain in the ass. It's forced me to stop terminating things on the router and instead use a dedicated x86 host to terminate tunnels on and then route the traffic via the firewall so I still have granular control.
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1943
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 12:21 pm

We’ve had no stability issues whatsoever with either WireGuard or IPsec for a long time now. IPsec parallel throughput with hardware offload on the high-end models is really solid, with no noticeable drop in performance as long as you stay within the recommended connection limits. The only limitation is the lack of VTI support, though that’s mostly a matter of configuration.
 
oskarsk
MikroTik Support
MikroTik Support
Posts: 75
Joined: Mon May 13, 2019 9:41 am

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 1:38 pm

Looks like you pushed a release candidate (beta) to production. Probably not the smartest move.
Just reporting. That issue has been present in RouterOS on CCR2116 since at least 7.12.1 along with few others (like for example ipsec crashing after opening installed-sa tab in winbox).
Please contact us and send your supout rif file after the issue. Does the same happens if you monitor installed sa using cli ?
 
Traveller
newbie
Posts: 35
Joined: Thu Apr 05, 2018 10:12 am

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 2:51 pm

*) ipsec - fixed system failure on MMIPS devices when using IPsec services;
Thank you :).
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 23614
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 2:52 pm

Looks like you pushed a release candidate (beta) to production. Probably not the smartest move.
Larsa, dont they teach that at IT school. Use the latest beta firmware for production!
Maybe they took that advice when running the Spanish electrical grid ;-)
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1363
Joined: Mon Sep 23, 2019 1:04 pm

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 3:48 pm

*) ip-service - show all TCP/UDP connections on the system (additional fixes);
*) ip-service - show all TCP/UDP ports on system, including ports in containers (additional fixes);

Please re-read changelog - one entry is about "connections" and one about "ports" or, as you prefer - "listeners".
On an AP running nothing but wireless, dhcp keeps popping up as a dynamic port (server), what's the reason there if it's not configured?
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4868
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 4:22 pm

*) ip-service - show all TCP/UDP connections on the system (additional fixes);
*) ip-service - show all TCP/UDP ports on system, including ports in containers (additional fixes);

Please re-read changelog - one entry is about "connections" and one about "ports" or, as you prefer - "listeners".
On an AP running nothing but wireless, dhcp keeps popping up as a dynamic port (server), what's the reason there if it's not configured?
It's part of "all" in RN sentence, and it's a "connection", not dynamic port (server)/"listener" in this scheme. ;)

Essentially its "netstat" rendered in RouterOS
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1363
Joined: Mon Sep 23, 2019 1:04 pm

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 4:37 pm

No smartypants, connections have the connection flag, this one doesn't.
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4868
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 4:42 pm

No smartypants, connections have the connection flag, this one doesn't.
My point was it's not clear and there is more subtlety here... Might be the DHCP client polling? Now whether that's a connection in this terminology, IDK.

But I like feature.
 
federalbr
just joined
Posts: 1
Joined: Fri Nov 17, 2023 4:44 pm
Location: Natal, Brazil
Contact:

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 4:48 pm

We’ve had no stability issues whatsoever with either WireGuard or IPsec for a long time now. IPsec parallel throughput with hardware offload on the high-end models is really solid, with no noticeable drop in performance as long as you stay within the recommended connection limits. The only limitation is the lack of VTI support, though that’s mostly a matter of configuration.
I thought I was the only one noticing a performance drop in Wireguard
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 5:30 pm

Has the "possible SYN flooding on tcp port 53" issue been solved?
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1943
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 5:35 pm

I thought I was the only one noticing a performance drop in Wireguard

Since WireGuard relies entirely on software-based encryption (ChaCha20), speed is limited by the endpoint with the weakest CPU. It’s good for home setups and out-of-band management for a single connection, but for VPN concentrators where high throughput and scalability are required, IPsec with hardware offload is still the only practical option.
 
blacksnow
Frequent Visitor
Frequent Visitor
Posts: 63
Joined: Wed Feb 15, 2023 4:46 pm

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 6:37 pm

I thought I was the only one noticing a performance drop in Wireguard

Since WireGuard relies entirely on software-based encryption (ChaCha20), speed is limited by the endpoint with the weakest CPU. It’s good for home setups and out-of-band management for a single connection, but for VPN concentrators where high throughput and scalability are required, IPsec with hardware offload is still the only practical option.
I don't agree with this. If you want to say, "vpn concentrators where high throughput and scalability are required, ipsec with offload is the only practical solution on RouterOS" maybe that is true. But if we are talking hardware/software solutions outside of what Mikrotik provides etc, then this certainly isn't the case. Additionally, I believe @federalbr is indicating there IS a performance drop similar to what I have tested and shown in my post above whereas you were saying that you have not seen any Wireguard performance regressions.
 
User avatar
mozerd
Forum Veteran
Forum Veteran
Posts: 974
Joined: Thu Oct 05, 2017 3:39 pm
Location: Canada
Contact:

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 6:40 pm


Since WireGuard relies entirely on software-based encryption (ChaCha20), speed is limited by the endpoint with the weakest CPU. It’s good for home setups and out-of-band management for a single connection, but for VPN concentrators where high throughput and scalability are required, IPsec with hardware offload is still the only practical option.
WireGuard Performance Tuning
 
User avatar
Kentzo
Forum Veteran
Forum Veteran
Posts: 700
Joined: Mon Jan 27, 2014 3:35 pm
Location: California

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 6:53 pm

Not exactly: https://esim.me/
So… a programable SIM card?
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1943
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 7:32 pm

I don't agree with this. If you want to say, "vpn concentrators where high throughput and scalability are required, ipsec with offload is the only practical solution on RouterOS" maybe that is true. But if we are talking hardware/software solutions outside of what Mikrotik provides etc, then this certainly isn't the case. Additionally, I believe @federalbr is indicating there IS a performance drop similar to what I have tested and shown in my post above whereas you were saying that you have not seen any Wireguard performance regressions.

My comment was specifically in the context of Mikrotik ROS, where IPsec provides hardware offload. WireGuard on the same platform and with the same number of connections will have has scalability issues due to being CPU-bound, and that applies also to all platforms and architectures on the market.

To make WireGuard perform well with a large number of connections, you need massive CPU power (just look at the VPN providers). So yeah, performance will obviously vary depending on hardware, software and traffic patterns.

Bottom line: WireGuard is perfect for the advanced home user and OOB management, but not really an option when it comes to scalability. Anyone suggesting otherwise hasn’t run it in production or high-demand environments. But that’s another discussion.

As for @federalbr’s point, I'm not denying that performance issues actually can occur, just noting that in our case we haven’t observed any regressions at all, and we have plenty of OOB connections that are monitored 24/7.

So if you’re sure about the performance regressions, gather some facts and open a ticket with support. Just saying it feels slow isn’t going to cut it.
 
blacksnow
Frequent Visitor
Frequent Visitor
Posts: 63
Joined: Wed Feb 15, 2023 4:46 pm

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 7:57 pm

I don't agree with this. If you want to say, "vpn concentrators where high throughput and scalability are required, ipsec with offload is the only practical solution on RouterOS" maybe that is true. But if we are talking hardware/software solutions outside of what Mikrotik provides etc, then this certainly isn't the case. Additionally, I believe @federalbr is indicating there IS a performance drop similar to what I have tested and shown in my post above whereas you were saying that you have not seen any Wireguard performance regressions.

My comment was specifically in the context of Mikrotik ROS, where IPsec provides hardware offload. WireGuard with multiple connections on the same platform is very limited since it's CPU-bound, and that applies also to all platforms and architectures on the market.

To make WireGuard perform well with multiple connections, you need massive CPU power (just look at the VPN providers). So yeah, performance will obviously vary depending on hardware, software and traffic patterns.

Bottom line: WireGuard is perfect for the advanced home user and OOB management, but not really an option when it comes to scalability. Anyone suggesting otherwise hasn’t run it in production or high-demand environments. But that’s another discussion.

As for @federalbr’s point, I'm not denying that performance issues actually can occur, just noting that in our use cases we haven’t observed any regressions at all, and we have plenty of OOB connections that are monitored 24/7.

So if you’re sure about the performance regressions, gather some facts and open a ticket with support. Just saying it feels slow isn’t going to cut it.
I agree that with Mikrotik's current offerings w.r.t Wireguard are not the best choice if your looking for high throughout and massive scalability. In regards to the performance regression, I did multiple tests and submitted a ticket already.

On the topic of broader applications of Wireguard using what is available in the market, you absolutely can (and with relative ease) deploy a high throughout and scalable VPN concentrator based on Wireguard alone. Sure one can nitpick the details of managing keys (even though multiple tools exist for this) or the fact that some of the tooling built into other VPNs like OpenVPN (DHCP etc etc) doesn't exist natively with Wireguard. At the end of the day, Wireguard is absolutely a reasonable and performant option for any kind of production environment regardless of the demand.

Now, if the truth is that you don't have the budget to buy the necessary equipment to support your use case or the time/manpower to implement a Wireguard based solution that is understandable. What can be done with IPSec is much cheaper from a cost and support perspective compared to Wireguard currently. And although you mentioned Wireguard requires strong single-thread CPU performance (generic x86 CPUs from 2023+ are capable of 3-4GB/s out of the box without tuning), for great results you want a fast CPU but there are advancements such as Intel QAT Gen3 which greatly accelerates Wireguard and without the cost of "expensive" CPU compute (https://www.intel.com/content/www/us/en ... guide.html). At the end of the day it's up to the operator to determine which path works best for their use case but saying Wireguard by default isn't suitable for production needs that require high performance or maximum scalability is blatantly incorrect.
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1943
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 8:31 pm

@blacksnow, OT – please start a separate thread on the subject. This one's about ROS v7.19rc.
 
User avatar
Paternot
Forum Guru
Forum Guru
Posts: 1098
Joined: Thu Jun 02, 2016 4:01 am
Location: Niterói / Brazil

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 9:31 pm

Since WireGuard relies entirely on software-based encryption (ChaCha20), speed is limited by the endpoint with the weakest CPU. It’s good for home setups and out-of-band management for a single connection, but for VPN concentrators where high throughput and scalability are required, IPsec with hardware offload is still the only practical option.
I really disagree with this one (within an RoS context). Let me explain:

Consider these Mikrotik routers:
hEX (https://mikrotik.com/product/RB750Gr3#fndtn-testresults)
hAP ac2 (https://mikrotik.com/product/hap_ac2#fndtn-testresults)
RB1100AHx4 (https://mikrotik.com/product/rb1100ahx4 ... estresults)
CCR2004 (https://mikrotik.com/product/ccr2004_16 ... estresults)
CCR2116 (https://mikrotik.com/product/ccr2116_12 ... estresults)

Consider the info, here on forum, that hAP ac2 made about 700Mbps on Wireguard. And remember that Mikrotik table says it does 385,3 Mbps hardware IPSEC).
Now, answer me that: if (and only if) You agree with the statement that hAP ax2 made 700Mbps on Wireguard:
Would You agree that the RB5009 would fare FAR better than the stated 1409 Mbps 256 tunnels IPSec results?
Would You agree that one RB1100AHx4 would have a far worse result than the stated 1283,5Mbps IPSec results - comparing it to the RB5009 CPU?
Would You agree that the monster CCR2116 would fare something much higher than the 4104,4 Mbps (not even 3 times faster than the RB5009, with 4 times more cores, using a better CPU design)?

My point is this: "hardware acceleration" does wonders - but it doesn't necessarily scales linearly with CPU capacity/core count. It's quite common to implement it in a subset if circuits (GPUs do this, with video hardware encoding - they have ZERO relationship with GPU power), that have no direct relationship with the CPU itself.

SO
I agree with You that these "hardware implementations" do save CPU cycles. I don't agree that they are always faster - because they are independent from CPU design, and have no bearing with its speed. We can do a slow IPSEC hardware implementation, and shove it in one really fast CPU. The same way Sun did a crappy floating point implementation, and shove it on their 16 core 64 thread monsters of the time. The SPARCs were really strange beasts...

Why is this relevant to us? Because it isn't necessarily true that hardware IPSEC will be faster than software Wireguard. The answer is "it depends".
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1943
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 10:40 pm

Again, OT! Please start a separate thread and I’ll respond there, alright?

Anyway, just to spice up the debate before the new thread: 256 full-speed IPsec tunnels with almost no CPU impact equal, at most, 5–10 full-speed WireGuard tunnels with 100% CPU consumption on a CCR2216. And that’s a fact!
Last edited by Larsa on Wed Apr 30, 2025 10:48 pm, edited 1 time in total.
 
itimo01
Member Candidate
Member Candidate
Posts: 278
Joined: Thu Jun 29, 2023 2:55 am
Location: Germany
Contact:

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 10:48 pm

Just for information:

Ive found a bug concerning provisioning of local wifi interfacing using provisioning rules (dynamic enabled)
If you double provision or even triple provision local interfaces on an ax3 (might just be my ax3) the interfaces will enter an "unclear" state and refuse to work until a reboot.

Support is already working to resolve the issue.
This appears to be an issue since some beta version as i reported this issue before but it was less likely to appear so i closed the ticket.
 
User avatar
Paternot
Forum Guru
Forum Guru
Posts: 1098
Joined: Thu Jun 02, 2016 4:01 am
Location: Niterói / Brazil

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 11:09 pm

Again, OT! Please start a separate thread and I’ll respond there, alright?

Anyway, just to spice up the debate before the new thread: 256 full-speed IPsec tunnels with almost no CPU impact equal, at most, 5–10 full-speed WireGuard tunnels with 100% CPU consumption on a CCR2216. And that’s a fact!
You can't complain about OT when I'm answering YOUR post!
And it isn't with almost no CPU impact. I tested it with one hEX, and there is plenty of CPU impact. It gets the stated speeds, but the CPU get hammered all right. And yes, it was marked as "hardware offloaded", before You ask. Tested it years ago, on RoS 6.x

Just pointing out that this "hardware accelerated "Y" is always faster than software accelerated "X" " isn't necessarily true. It may very well be - but isn't a given.
 
blacksnow
Frequent Visitor
Frequent Visitor
Posts: 63
Joined: Wed Feb 15, 2023 4:46 pm

Re: v7.19rc [testing] is released!

Wed Apr 30, 2025 11:51 pm

Here is a new thread @Larsa

viewtopic.php?t=216556
 
User avatar
nichky
Forum Guru
Forum Guru
Posts: 1408
Joined: Tue Jun 23, 2015 2:35 pm

Re: v7.19rc [testing] is released!

Thu May 01, 2025 9:24 am

Hi @MikroTik

How we go with the VRF imelmatiations ? Still from the VRF1 we cant get access to the Main table.

VRF1 -> VRF2....works
Main -> VRF1....works
VRF1 -> Main....does not works
 
User avatar
mantouboji
Frequent Visitor
Frequent Visitor
Posts: 59
Joined: Mon Aug 01, 2022 2:21 pm
Location: Shanghai

Re: v7.19rc [testing] is released!

Thu May 01, 2025 9:57 am

e50ug can't accessed after upgrade from 7.19beta8
Send us supout rif file and details on the issue.
It is located in a remote place and I can’t access it now, sorry.
 
millenium7
Long time Member
Long time Member
Posts: 618
Joined: Wed Mar 16, 2016 6:12 am

Re: v7.19rc [testing] is released!

Thu May 01, 2025 2:07 pm

7.19 has finally moved to RC? Great news!
now can we finally throw it in the bin and work on 7.20 where some actual improvements and features will make the pain worthwhile until stability is achieved
 
User avatar
loloski
Member
Member
Posts: 480
Joined: Mon Mar 15, 2021 9:10 pm
Location: Philippines

Re: v7.19rc [testing] is released!

Thu May 01, 2025 2:20 pm

As per normis they are working hard on ROSE features/stability on 7.19 and 7.20 so I guess no progress on routing,switching and hwoffload features I hope I'm mistaken
 
User avatar
sirbryan
Member
Member
Posts: 478
Joined: Fri May 29, 2020 6:40 pm
Location: Utah
Contact:

Re: v7.19rc [testing] is released!

Thu May 01, 2025 5:13 pm

As per normis they are working hard on ROSE features/stability on 7.19 and 7.20 so I guess no progress on routing,switching and hwoffload features I hope I'm mistaken
This is a silly comment. It's not like they only have five guys that work on all of RouterOS.

Some developers work on ROSE and containers. Some work on BGP, OSPF, ISIS, MPLS, etc. Some work on VPN tech, and others are specialists in the switching/hardware offload arena. And yet others are likely embedded/hardware/design specialists.

I'm sure there may be some overlap or borrowing of resources from one team to another depending on individual's skill and product development timelines, but talking like the whole dev team is moving back and forth is ridiculous.
 
User avatar
loloski
Member
Member
Posts: 480
Joined: Mon Mar 15, 2021 9:10 pm
Location: Philippines

Re: v7.19rc [testing] is released!

Thu May 01, 2025 5:40 pm

no offense I hope what you are saying is true because from my perspective evidently more and more people is getting frustrated on how thing is going in terms of development which matters (for our use case), even though we moved most of our gear to other platform MT has sizable portion of our network and our hands our tied we can't decommissioned them for obvious reason, If what MT is doing is acceptable to you and you are happy the way things are then Ok good for you bad for us :)
 
User avatar
sirbryan
Member
Member
Posts: 478
Joined: Fri May 29, 2020 6:40 pm
Location: Utah
Contact:

Re: v7.19rc [testing] is released!

Thu May 01, 2025 6:00 pm

I upgraded my RDS2216 to 7.19rc1 for some disk testing. Built-in SMB is still bad for some reason. It works fine on 7.17, but throughput on 7.18-7.19 are horrifically slow.

M1 Mac Studio, Sonoma, 25Gbps card -> RDS2216 (2x M.2 SATA drives in MDRAID1 configuration, ext4 format).

Built-in SMB, 8-20MB/s write, 6-11MB/s read:
Screenshot 2025-05-01 at 8.59.54 AM.png

Samba Container, same disks, same shared directory. 2Gbps write, 6Gbps read (full SATA speeds):
Screenshot 2025-05-01 at 8.39.14 AM.png
You do not have the required permissions to view the files attached to this post.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Thu May 01, 2025 6:11 pm

This is a silly comment. It's not like they only have five guys that work on all of RouterOS.

Some developers work on ROSE and containers. Some work on BGP, OSPF, ISIS, MPLS, etc.
Well, I hope that second "some" is more than zero. But it does not really look like it.
Either those have left the company, or they have been moved over to the storage and home usage projects.
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4868
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.19rc [testing] is released!

Thu May 01, 2025 7:11 pm

This is MikroTik. Just because there are not user-visible changes, does not mean they are not "working on it". But since everyone talks about wanting a newer data plane, they could be working on that to modernize it... THEN add some X feature AFTER that architectural work. Who knows. But I'm pretty sure there are no clocks in Latvia.
 
ToTheFull
Member
Member
Posts: 429
Joined: Fri Mar 24, 2023 3:24 pm

Re: v7.19rc [testing] is released!

Thu May 01, 2025 8:49 pm

Not sure if anybody else is seeing this behaviour, but since updating to this release from 7.18.2 my devices that as a rule connect to 5g on the same SSID are now only connecting to 2.4g across the same SSID. After downgrading and reloading the previous saved config, all is well again. stuff is prefering the faster 5g again.

yes using FT and steering
 
itimo01
Member Candidate
Member Candidate
Posts: 278
Joined: Thu Jun 29, 2023 2:55 am
Location: Germany
Contact:

Re: v7.19rc [testing] is released!

Thu May 01, 2025 9:10 pm

Not sure if anybody else is seeing this behaviour, but since updating to this release from 7.18.2 my devices that as a rule connect to 5g on the same SSID are now only connecting to 2.4g across the same SSID. After downgrading and reloading the previous saved config, all is well again. stuff is prefering the faster 5g again.

yes using FT and steering
any specific devices, or just all of them?
The only 2 devices i ever had issues with (with Multiple Vendors Wi-Fi) was my Xiaomi 12 Pro and Samsung Galaxy S8+
 
User avatar
Kentzo
Forum Veteran
Forum Veteran
Posts: 700
Joined: Mon Jan 27, 2014 3:35 pm
Location: California

Re: v7.19rc [testing] is released!

Thu May 01, 2025 9:11 pm

I upgraded my RDS2216 to 7.19rc1 for some disk testing. Built-in SMB is still bad for some reason. It works fine on 7.17, but throughput on 7.18-7.19 are horrifically slow.
Interesting, I saw a major improvement in 7.18.x. I have an m2 ssd in a case attached over usb.
 
biki73
just joined
Posts: 6
Joined: Fri Jun 23, 2023 11:06 pm

Re: v7.19rc [testing] is released!

Thu May 01, 2025 10:25 pm

on 7.19rc1 something called 'fileman' is reading everything on the disk for some reason (i didn't even open file manager) slowing everything down quite a lot (25% on rb5009 and around 200Mbps constant read from usb attached ssd)
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Thu May 01, 2025 10:51 pm

on 7.19rc1 something called 'fileman' is reading everything on the disk for some reason
RouterOS is becoming more and more like Windows...
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1363
Joined: Mon Sep 23, 2019 1:04 pm

Re: v7.19rc [testing] is released!

Thu May 01, 2025 10:54 pm

@MikroTik could you somehow update the wireguard sources? based on your GPL handed out ̶f̶o̶r̶ ̶7̶.̶1̶9̶r̶c̶ you're using code untouched from 5 years ago. more exactly it's stuck at this point: https://github.com/WireGuard/wireguard- ... 49e940b479
A fast look over the changes in those years I've found this: https://github.com/WireGuard/wireguard- ... c6214ccf7a
Among other changes it had in FIVE YEARS.
Shame.
That is, if you actually provided the recent sources, and not some old archive that you just hand out on request. That would be another can of worms.
 
blacksnow
Frequent Visitor
Frequent Visitor
Posts: 63
Joined: Wed Feb 15, 2023 4:46 pm

Re: v7.19rc [testing] is released!

Thu May 01, 2025 11:16 pm

I think the biggest thing that needs to be worked on is keeping RouterOS close to the current kernel. So much has been done in the recent 6.10+ kernels, performance optimizations, NIC buffering/optimization, crypto enhancements etc. And not everything can be backported to older kernels. Being able to keep the underlying kernel up to date seems like something that is continously biting the Mikrotik team. Especially as they want to delve into other none networking-centric areas like storage filesystems, nfs/smb and other use-cases. Otherwise make the platform just a modular container host, make RouterOS just do routing/switching, and then have it host containers for all the other feature add-ons that people want to develop. I mean isn't that basically what @sirbryan is doing, comparing against samba in a container. I mean at this point just use the container....
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4868
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.19rc [testing] is released!

Thu May 01, 2025 11:23 pm

Built-in SMB is still bad for some reason. It works fine on 7.17, but throughput on 7.18-7.19 are horrifically slow.
One of my test routes is RB1100AHx4, and since 7.18beta2, SMB connections from macOS will cause a hard crash of RB1100.
I opened a ticket about, SMB is not critical for me, but it still crashes in v7.19rc1.... Now "slow" is different... but 7.17.x worked fine in my case too.
 
mblfone
newbie
Posts: 36
Joined: Sun Feb 02, 2014 2:22 am

Re: v7.19rc [testing] is released!

Thu May 01, 2025 11:40 pm

I am sure many of us are anxious to hear if the BGP changes made in 7.19 put this release as a candidate for folks still holding at 7.15.3. I know pe1chl has mentioned the various BGP problems within 7.16 and forward ROS versions. He has been patiently encouraging developers to address them. I continue to wait on the sidelines. BGP stability is crucial to our network and many others, I suspect.
 
ToTheFull
Member
Member
Posts: 429
Joined: Fri Mar 24, 2023 3:24 pm

Re: v7.19rc [testing] is released!

Thu May 01, 2025 11:59 pm

Not sure if anybody else is seeing this behaviour, but since updating to this release from 7.18.2 my devices that as a rule connect to 5g on the same SSID are now only connecting to 2.4g across the same SSID. After downgrading and reloading the previous saved config, all is well again. stuff is prefering the faster 5g again.

yes using FT and steering
any specific devices, or just all of them?
The only 2 devices i ever had issues with (with Multiple Vendors Wi-Fi) was my Xiaomi 12 Pro and Samsung Galaxy S8+
All of the devices that used to connect to 5g now seem to prefer 2.4g for some strange reason.
Rolling back to 7.18.2 has resolved the issue.

For the record we are talking about iphones and google pixel.
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1363
Joined: Mon Sep 23, 2019 1:04 pm

Re: v7.19rc [testing] is released!

Fri May 02, 2025 12:37 am

For the record we are talking about iphones and google pixel.
The last one in the list is an iPhone, pretty stubborn to sit on the 5GHz band considering the signal I'd say.
2025-05-02-0001.png
You do not have the required permissions to view the files attached to this post.
 
ToTheFull
Member
Member
Posts: 429
Joined: Fri Mar 24, 2023 3:24 pm

Re: v7.19rc [testing] is released!

Fri May 02, 2025 12:49 am

Well mine do as a rule on 7.18.2
You do not have the required permissions to view the files attached to this post.
 
blacksnow
Frequent Visitor
Frequent Visitor
Posts: 63
Joined: Wed Feb 15, 2023 4:46 pm

Re: v7.19rc [testing] is released!

Fri May 02, 2025 1:02 am

Another issue on 7.19rc1, device mode does not work properly. You can't update the mode as the command is broken. Device-mode print only works if you CTRL-C after running the command.
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1363
Joined: Mon Sep 23, 2019 1:04 pm

Re: v7.19rc [testing] is released!

Fri May 02, 2025 9:55 am

Can confirm that.
 
xrlls
Member Candidate
Member Candidate
Posts: 108
Joined: Sun Jan 13, 2019 4:43 pm
Location: Copenhagen, DK

Re: v7.19rc [testing] is released!

Fri May 02, 2025 10:42 am

The iot-bt-extra package is somehow lost and needs to be reinstalled every time I upgrade my L009UiGS-2HaxD. To get it back, I need to reinstall manually. Anyone else have the same experience?
 
roggles
just joined
Posts: 9
Joined: Wed Mar 06, 2019 4:54 pm

Re: v7.19rc [testing] is released!

Fri May 02, 2025 11:07 am

Hello,
thank you for adding the missing comment fields for winbox in the multi-password-group settings.
But when i change a comment, the wifi client reconnects.

Some more questions:
Should or could i use both an access list entry and multi-password-group for the same client?
And when yes, in wich order is this processed?
And wich comment it used or could you combine the comments in the registration list?

regards
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Fri May 02, 2025 11:35 am

That is just a generic problem in RouterOS... in some cases, changing an irrelevant property (like a comment) will effectively reset the entire item.
It used to happen more often, in some places it has been fixed over the years, but apparently there is no generic code harness for all settings management where this would be fixed once and for all.
(I sometimes wonder how the configuration layer in RouterOS has been implemented - has anyone ever tried to reverse-engineer that?)
 
redbullsteve
just joined
Posts: 22
Joined: Wed Feb 02, 2011 12:37 am

Re: v7.19rc [testing] is released!

Fri May 02, 2025 11:42 am

Upgrade for CRS112-8P-4S works fine and no issues until you enable IGMP Snooping on the Bridge, this was disabled before the upgrade.

When you enable the feature the switch crashes and reboots without the change, there is no way to enable IGMP Snooping on the bridge.

Bug report and supout sent to Microtik.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Fri May 02, 2025 3:40 pm

After upgrade, over 100MB of HDD space is "lost" on CHR installs.
It requires 2 reboots to recover that space. On the first reboot, about 18MB is recovered, the remainder on the second reboot.
 
DjM
Member Candidate
Member Candidate
Posts: 116
Joined: Sun Dec 27, 2009 2:44 pm

Re: v7.19rc [testing] is released!

Fri May 02, 2025 6:14 pm

Some more questions:
Should or could i use both an access list entry and multi-password-group for the same client?
And when yes, in wich order is this processed?
And wich comment it used or could you combine the comments in the registration list?

regards
SUP-181069 opened with this question from 03/2025.
 
User avatar
chrismfz
just joined
Posts: 16
Joined: Sat Apr 07, 2007 6:27 am

Re: v7.19rc [testing] is released!

Tue May 06, 2025 2:10 am

I am sure many of us are anxious to hear if the BGP changes made in 7.19 put this release as a candidate for folks still holding at 7.15.3. I know pe1chl has mentioned the various BGP problems within 7.16 and forward ROS versions. He has been patiently encouraging developers to address them. I continue to wait on the sidelines. BGP stability is crucial to our network and many others, I suspect.
it seems that iot-related-features and "adlists" is more important than bgp which is fundamentally broken in 7.x and we keep waiting like ...let's dont say like what.
we consider switching to a VM with bird of opnsense and frr package for our AS, since we can't keep up with 7.x anymore.
It's a pity when mikrotik announces rose and enterprise hardware and giving more attention to silly features and not in features related to the hardware they are producing.
no meaning anymore on to this.
I can't understand your priorities but I am disappointed by far with your feature schedule.
 
MatiasMK88
just joined
Posts: 4
Joined: Tue Jan 21, 2025 10:56 pm

Re: v7.19rc [testing] is released!

Tue May 06, 2025 7:39 am

I am sure many of us are anxious to hear if the BGP changes made in 7.19 put this release as a candidate for folks still holding at 7.15.3. I know pe1chl has mentioned the various BGP problems within 7.16 and forward ROS versions. He has been patiently encouraging developers to address them. I continue to wait on the sidelines. BGP stability is crucial to our network and many others, I suspect.
it seems that iot-related-features and "adlists" is more important than bgp which is fundamentally broken in 7.x and we keep waiting like ...let's dont say like what.
we consider switching to a VM with bird of opnsense and frr package for our AS, since we can't keep up with 7.x anymore.
It's a pity when mikrotik announces rose and enterprise hardware and giving more attention to silly features and not in features related to the hardware they are producing.
no meaning anymore on to this.
I can't understand your priorities but I am disappointed by far with your feature schedule.
I agree with you that I don't like at all the NAS in Mikrotik, but I read a lot of BGP, but in my network with BGP I don't see any problems, help to identify those problems that cause so much noise
 
lubomirs
just joined
Posts: 7
Joined: Tue Feb 05, 2019 4:07 pm

Re: v7.19rc [testing] is released!

Tue May 06, 2025 10:32 am

. . . I would also like a print server there :-)
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 27080
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Re: v7.19rc [testing] is released!

Tue May 06, 2025 10:35 am

What is completely broken in BGP?
 
User avatar
mantouboji
Frequent Visitor
Frequent Visitor
Posts: 59
Joined: Mon Aug 01, 2022 2:21 pm
Location: Shanghai

Re: v7.19rc [testing] is released!

Tue May 06, 2025 12:06 pm

Another issue on 7.19rc1, device mode does not work properly. You can't update the mode as the command is broken. Device-mode print only works if you CTRL-C after running the command.
me too, both on E5UG and hAP-AX3
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Tue May 06, 2025 12:30 pm

What is completely broken in BGP?
See SUP-159987, for example. And also the several times I have brought BGP up in release topics after 7.16.x
It is most apparent when BGP is used as a routing protocol in a partial to full tunnel mesh for head-office to branch connectivity.
(not the internet routing use case)
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7212
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: v7.19rc [testing] is released!

Tue May 06, 2025 12:35 pm

That does not qualify as "completely broken".
 
buset1974
Frequent Visitor
Frequent Visitor
Posts: 87
Joined: Wed Sep 13, 2006 12:12 pm
Location: Jakarta

Re: v7.19rc [testing] is released!

Tue May 06, 2025 12:49 pm

That does not qualify as "completely broken".
Have u fix bgp-path-len mrz?

Thx
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Tue May 06, 2025 2:15 pm

That does not qualify as "completely broken".
Well, for us it is!
We used this network setup to have routing between our premises, with main tunnels over fiber or DSL and additional tunnels over 4G/5G, and that worked fine until 7.15 and as it is now that often does not work properly.
Also, when it does work, the recovery time is much longer (1 minute) than it was before.
We had a nice automatically routed network and now it requires manual intervention when a link fails, in my opinion that is "completely broken".
(we have the same situation as with static routing)
 
User avatar
loloski
Member
Member
Posts: 480
Joined: Mon Mar 15, 2021 9:10 pm
Location: Philippines

Re: v7.19rc [testing] is released!

Tue May 06, 2025 2:54 pm

@mrz most of the people here buy high-end devices from you guys from switch to router and we expect that it will work properly if there was a bug we expect that each bug was fairly treated even though it was hard to fix don't assume always that it was a config issue or user error, we notice that your developer want to fix those area that only interest them, we buy RouterOS to forward or switch packet not as a Storage device, with this direction you are forcing us out and let us dry but our hands our tied because we can't simply throw investment we have in the device and people that's my sour graping at least on my end

I already said this here many times don't take this as negative instead use this as an opportunity to fix or enhance your product try to address the issue of your customers instead of evading them. By not addressing this or continue to deny the existence of the bug it would be a deterrent on MikroTik good name
 
User avatar
loloski
Member
Member
Posts: 480
Joined: Mon Mar 15, 2021 9:10 pm
Location: Philippines

Re: v7.19rc [testing] is released!

Tue May 06, 2025 3:08 pm

Make routing and switching as your priority and lastly whatever your heart desires you will see it makes a lot of difference, make RouterOS great again ahahhahahaaha
 
User avatar
mantouboji
Frequent Visitor
Frequent Visitor
Posts: 59
Joined: Mon Aug 01, 2022 2:21 pm
Location: Shanghai

Re: v7.19rc [testing] is released!

Tue May 06, 2025 3:35 pm

My E50UG runs OSPF with upstream RB4011, after powerup several minutes , run "/log/print" will frozen console , but I can ssh into e50ug by a new terminal.
 
nmt1900
Frequent Visitor
Frequent Visitor
Posts: 89
Joined: Wed Feb 01, 2017 12:36 am

Re: v7.19rc [testing] is released!

Tue May 06, 2025 3:44 pm

@mrz most of the people here buy high-end devices from you guys from switch to router and we expect that it will work properly if there was a bug we expect that each bug was fairly treated even though it was hard to fix don't assume always that it was a config issue or user error, we notice that your developer want to fix those area that only interest them, we buy RouterOS to forward or switch packet not as a Storage device, with this direction you are forcing us out and let us dry but our hands our tied because we can't simply throw investment we have in the device and people that's my sour graping at least on my end

I already said this here many times don't take this as negative instead use this as an opportunity to fix or enhance your product try to address the issue of your customers instead of evading them. By not addressing this or continue to deny the existence of the bug it would be a deterrent on MikroTik good name
If "enterprise storage" development will be as opaque with "known issues" and bug handling as everything else is, then it would be hard to imagine how this would get any traction on the market. Network problems can be worked around, storage data loss due to bugs on "enterprise storage" can not.
 
User avatar
Cha0s
Forum Guru
Forum Guru
Posts: 1166
Joined: Tue Oct 11, 2005 4:53 pm

Re: v7.19rc [testing] is released!

Tue May 06, 2025 4:17 pm

That does not qualify as "completely broken".
Semantics.
 
User avatar
loloski
Member
Member
Posts: 480
Joined: Mon Mar 15, 2021 9:10 pm
Location: Philippines

Re: v7.19rc [testing] is released!

Tue May 06, 2025 4:26 pm

Before ROSE came to life there were lot of V6 features still not ported to ros v7 from simple to the hardest one e.g proper routing filters comparable to V6 I can keep on and on, what I personally want to say make v7 comparable to V6 first or even better no feature left behind from V6 then after that they can introduce whatever new stuff like this NAS they want to push. Finish first what matter most to people here make Routing and Switching a priority because this is their bread and butter product I don't came here because of their wireless and storage product I'm here for their CCR line and CRS line of product waiting someday that we can maximize what we paid for, I just want to be direct as possible and I mean no harm to Mikrotik it just so happen that I'm also one of a few people here got frustrated on which direction is mikrotik is heading to
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Tue May 06, 2025 4:43 pm

Well, when v7 first appeared many features were missing from autorouting, e.g. BFD took very long. But at about 7.10 things were stable and usable.
My main gripe is that with 7.16 several things broke, but nothing is fixed despite it being reported here and in a ticket, and MikroTik apparently does not consider it a priority because it is not "completely broken".
Well, it is broken for the purpose. Which is to have automatic failover of failing routes within a second. That is why we had BGP, that is why we required BFD, etc.
And it all worked fine in 6.x and in 7.10-7.15, so why can't we have it working now in 7.18 or 7.19?
 
User avatar
sirbryan
Member
Member
Posts: 478
Joined: Fri May 29, 2020 6:40 pm
Location: Utah
Contact:

Re: v7.19rc [testing] is released!

Tue May 06, 2025 5:09 pm

What is completely broken in BGP?
Its stability.

I cannot run anything higher than 7.15.x on my border and aggregation routers with more than two peers and thousands of routes, or else routes get "stuck". Traffic goes out the wrong interface despite the FIB showing routes going to the desired destination. Sometimes it requires resetting the BGP session(s). Other times a full router reboot is required because the router locks up when trying to look at routes or interfaces.

Maybe it's not BGP itself that is broken, perhaps something in the routing code underneath it, but 7.16.x and higher (so far) have been problematic on all of my border 2116's. They have been solid as a rock on 7.15.x.

(The only exception is I'm running 7.16.x on my CRS300's that are doing L3HW offload inside the network, and that seems to work fine.They only have two sessions to BGP RR's and a small number of routes internally. With the same config under 7.15.3, they would randomly reboot due to memory overflow issues.)
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Tue May 06, 2025 5:25 pm

Have you seen that problem where in the session the number of prefixes remains at 0 even though the number of received messages increases as normal?
Here that only happens after some uptime (and restart of a session), not immediately after boot.

When the content of the route table is incorrect (in winbox), I have found that it is sometimes fixed when winbox is closed and re-opened. That also helps when garbage is displayed in the "Immediate Gateway" column.
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7212
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: v7.19rc [testing] is released!

Tue May 06, 2025 5:29 pm

I am not saying that there are no bugs. In most cases, BGP is usable, but in some specific cases bugs are crawling out of the holes.

Stability issues should be already solved in v7.19rc, if you still have stability issues with this version contact support.
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7212
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: v7.19rc [testing] is released!

Tue May 06, 2025 5:32 pm

When the content of the route table is incorrect (in winbox), I have found that it is sometimes fixed when winbox is closed and re-opened. That also helps when garbage is displayed in the "Immediate Gateway" column.
It was mentioned several times, there is an issue that winbox may not refresh tables. Hit F5 or use CLI for monitoring.
 
User avatar
sirbryan
Member
Member
Posts: 478
Joined: Fri May 29, 2020 6:40 pm
Location: Utah
Contact:

Re: v7.19rc [testing] is released!

Tue May 06, 2025 5:45 pm

Have you seen that problem where in the session the number of prefixes remains at 0 even though the number of received messages increases as normal?
Here that only happens after some uptime (and restart of a session), not immediately after boot.

I had not noticed that before, but I pulled up one of my borders and found this interesting. For all of my peers with redundant connections, the secondary router (that has most recently reconnected) shows a dissimilar number of prefixes received, despite being configured identically.

Screenshot 2025-05-06 at 8.33.11 AM.png

(This is from webfig on 7.15.3. I rarely use Winbox, and if I do, it's version 4 on macOS.)
You do not have the required permissions to view the files attached to this post.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Tue May 06, 2025 6:20 pm

It was mentioned several times, there is an issue that winbox may not refresh tables. Hit F5 or use CLI for monitoring.
Hit F5 does not fix this. Or, sometimes it causes crash of winbox.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Tue May 06, 2025 6:24 pm

I had not noticed that before, but I pulled up one of my borders and found this interesting. For all of my peers with redundant connections, the secondary router (that has most recently reconnected) shows a dissimilar number of prefixes received, despite being configured identically.
Yes, that is what I mean.
And it is not cosmetic. When the other connection fails, you are without failover routes and need to close/re-open the second session to get them back (which when the other side is MikroTik takes 1 minute due to another bug).

Alltogether it means that the automatic routing fails to work when links fail, and I cannot classify that as "it is usable".
It is usable yes it gets some routes, but so does static routing. We run BGP precisely to overcome failing paths, so it is unusable when that function does not work.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Tue May 06, 2025 6:26 pm

Stability issues should be already solved in v7.19rc,
What do you mean with "stability issues"? Is that the bugs I am describing above in this topic, or in SUP-159987?
(which started out as "BGP sessions close when another session closes, and are then re-opened immediately")
 
User avatar
sirbryan
Member
Member
Posts: 478
Joined: Fri May 29, 2020 6:40 pm
Location: Utah
Contact:

Re: v7.19rc [testing] is released!

Tue May 06, 2025 6:45 pm

I had not noticed that before, but I pulled up one of my borders and found this interesting. For all of my peers with redundant connections, the secondary router (that has most recently reconnected) shows a dissimilar number of prefixes received, despite being configured identically.
Yes, that is what I mean.
And it is not cosmetic. When the other connection fails, you are without failover routes and need to close/re-open the second session to get them back (which when the other side is MikroTik takes 1 minute due to another bug).

That helps explain why the router listed as bgp-core-2 has been twiddling its thumbs this past year, especially during a failover event.
 
buset1974
Frequent Visitor
Frequent Visitor
Posts: 87
Joined: Wed Sep 13, 2006 12:12 pm
Location: Jakarta

Re: v7.19rc [testing] is released!

Tue May 06, 2025 7:17 pm

As long as I know, RouterOS v7 has been introduced for almost 10 years, and people have been hoping and promising so much about it. Now, it's become an anticlimax. v7 isn't exactly better than v6, and now the magic of v7 is suddenly being used for ROSE, which is quite disappointing. Mikrotik has a "Routing the World" motto, right?

The CCR is already in its 2nd generation. Even in the 1st generation, I was running my business with some issues, and now in the 2nd generation with v7, the situation isn't exactly better. Not all my routers can successfully migrate to v7. I have dozens of 1072 and 2216 models, though.

I'm also running a project with more than 3-4 thousand Mikrotik devices as CPEs used for WiFi bridges. Yes, it's very rare to have a problem, and if there is a problem, it's probably just a matter of rebooting the CPE or a hardware/adapter issue. I've never reported these issues because it's not worth it to report and bring them up. It's just a WiFi bridge, maybe that's what you mean about millions of Mikrotik devices running without problems all over the world? By the way, we're gradually replacing them, and for new ones, we're using other brands now, such as Ubiquity and Grandstream.
Last edited by buset1974 on Tue May 06, 2025 7:26 pm, edited 1 time in total.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Tue May 06, 2025 9:35 pm

The CCR is already in its 2nd generation. Even in the 1st generation, I was running my business with some issues, and now in the 2nd generation with v7, the situation isn't exactly better.
Well, my experience with v6 was very good, and I still have it running on a lot of routers in the hobby network.
I never would have switched the company network to v7 when the currently used hardware (CCR2004 and RB5009) would not require it...
I would be very happy when there was an optional package to have the original v6 auto-routing in v7.
For my use-cases (not full table internet routing but routing in a smaller network with 20 (work) to 1000 (hobby) routes on a partial mesh network) the old routing was fine and at least it was fully stable without those 'That does not qualify as "completely broken"' bugs... and there was no performance problem. The "new routing engine" has brought us nothing useful, and the configuration is "more complicated" as well (no problem for the company network but not so good for the hobby network).
 
mblfone
newbie
Posts: 36
Joined: Sun Feb 02, 2014 2:22 am

Re: v7.19rc [testing] is released!

Tue May 06, 2025 9:43 pm

That does not qualify as "completely broken".
I believe Normis was the first to use "completely broken"; I do not think it was by a forum user specific to BGP in this thread. A more accurate phrase would be "completely unusable". BGP is a function that should either work perfectly or be fixed as it has ramifications for not just a router, but an entire commercially offered network affecting thousands of clients.

For us, BGP firmware after 7.15.3 is "completely unusable" due to the comments we have seen mostly from pe1chl, but also from others with whom we communicate and vendors that help to support our network. I have been warned many times to not upgrade past 7.15.3.

The larger concern is why this is just now coming to light with developers as these problems were broached in every version since 7.15.


I hope that MT reaches out to pe1chl directly to try to get BGP back to working perfectly. I will not upgrade until I know that it is absolutely working 100% perfectly. Our extremely competitive business environment does not allow us to go offline due to BGP bugs.

I salute pe1chl for his persistence and continued posts on this forum related to these BGP problems.
 
User avatar
bajodel
Long time Member
Long time Member
Posts: 553
Joined: Sun Nov 24, 2013 8:30 am
Location: Italy

Re: v7.19rc [testing] is released!

Tue May 06, 2025 10:20 pm

..CUT..
I salute pe1chl for his persistence and continued posts on this forum related to these BGP problems.
+1
 
wispmikrotik
Member Candidate
Member Candidate
Posts: 161
Joined: Tue Apr 25, 2017 10:43 am

Re: v7.19rc [testing] is released!

Tue May 06, 2025 11:43 pm

..CUT..
I salute pe1chl for his persistence and continued posts on this forum related to these BGP problems.
+1
+10000000
 
User avatar
sirbryan
Member
Member
Posts: 478
Joined: Fri May 29, 2020 6:40 pm
Location: Utah
Contact:

Re: v7.19rc [testing] is released!

Wed May 07, 2025 7:33 am

Have you seen that problem where in the session the number of prefixes remains at 0 even though the number of received messages increases as normal?
Here that only happens after some uptime (and restart of a session), not immediately after boot.

I had not noticed that before, but I pulled up one of my borders and found this interesting. For all of my peers with redundant connections, the secondary router (that has most recently reconnected) shows a dissimilar number of prefixes received, despite being configured identically.

To address this further:

It appears that if the router is already receiving routes from another router in the same AS, that it won't even count and list any of those same routes as received from a second router in that source AS (hence the "0" or "1"). The second router is most definitely advertising them. This isn't an iBGP issue as you can see that one of the peers with two routers is an eBGP peer.

I would think the receiving router should list all of them, even if it adds an "Fb" for filtered or just "b" for BGP.
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1697
Joined: Thu Nov 12, 2020 12:07 pm

Re: v7.19rc [testing] is released!

Wed May 07, 2025 8:55 am

That does not qualify as "completely broken".
I believe Normis was the first to use "completely broken"; I do not think it was by a forum user specific to BGP in this thread. A more accurate phrase would be "completely unusable".
It was the post by chrismfz where he said "fundamentally broken". But normis the first to say "completely broken" in his question. But this seems to be a language misunderstanding. There is a huge difference between "fundamentally" and "completely". Completely means "100%/fully/totally" broken. Fundamentally on the other side means here like "important parts / essential parts / core parts". And I follow the discussion and the reports by pe1chl and I have to agree: their BGP issues are fundamental. But not "completely broken".
Last edited by infabo on Wed May 07, 2025 12:19 pm, edited 1 time in total.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Wed May 07, 2025 11:05 am

It appears that if the router is already receiving routes from another router in the same AS, that it won't even count and list any of those same routes as received from a second router in that source AS (hence the "0" or "1"). The second router is most definitely advertising them.
Yes, that certainly seems part of the issue. We run our network with different AS on each router (eBGP) and when there is a mesh of tunnels between the routers, at some point routes are not being accepted.
At work we basically have 4 routers participating in the mesh (with a couple of others that have only a single link) and what I see is that immediately after boot the prefix counts are all correct and the route tables all have multiple routes to each destination, one of them active, but after some uptime and some link down/up events (part of our tunnels are over regularly changing dynamic internet IPs) some of the prefix counts become zero, and when the other links go down there is NO route in the table that can be made active, so routing is lost.

And that does not fix itself, also not after a keepalive interval. Only taking the BGP peer down and re-enabling it, forcing a re-connect and route exchange, will make the routing come back (after one minute, another bug since 7.16 is that routes are not immediately exchanges but only on the next keepalive).

I have tried to reduce the number of tunnels to see if that would fix the problem (because of a maximal number of routes to each destination or AS to be stored), but it really doesn't.
Still, I would like to see a BGP parameter that allows to explicitly set the number of routes you want to keep, to rule out this possibility.
(so we could set that to e.g. 5)
 
oreggin
Member Candidate
Member Candidate
Posts: 203
Joined: Fri Oct 16, 2009 9:21 pm

Re: v7.19rc [testing] is released!

Wed May 07, 2025 12:36 pm

  • First of all, BGP is not a typical "hobby" routing protocol.
  • Second, stable BGP is a must have in a serious routing product.
  • Third, we need good configuration examples, or help from support if there is a configuration issue. If there is no correct configuration examples then nobody can help on the forum either.
  • If we have good/usable config examples, we can have better works with less mistakes.
  • It is not necessary to cover all of config possibilities, but we need basic building blocks, especially for BGP where a lot of things changed in the last few major versions.
Last edited by oreggin on Wed May 07, 2025 2:19 pm, edited 1 time in total.
 
wispmikrotik
Member Candidate
Member Candidate
Posts: 161
Joined: Tue Apr 25, 2017 10:43 am

Re: v7.19rc [testing] is released!

Wed May 07, 2025 12:53 pm

BGP must be the absolute priority. The world/internet runs on BGP! Please... fix the problems documented over and over by pechl1. To reproduce the problems, please contact him through the various support tickets.

Unfortunately, we are gradually abandoning MikroTik in favor of other brands that don't have routing issues... we can't provide a public administration or government with equipment that doesn't work.
 
jaclaz
Forum Guru
Forum Guru
Posts: 2887
Joined: Tue Oct 03, 2023 4:21 pm

Re: v7.19rc [testing] is released!

Wed May 07, 2025 1:01 pm

... we can't provide a public administration or government with equipment that doesn't work.
Sure, devices used in productive environments should be absolutely reliable.
 
User avatar
Cha0s
Forum Guru
Forum Guru
Posts: 1166
Joined: Tue Oct 11, 2005 4:53 pm

Re: v7.19rc [testing] is released!

Wed May 07, 2025 1:23 pm

The CCR is already in its 2nd generation. Even in the 1st generation, I was running my business with some issues, and now in the 2nd generation with v7, the situation isn't exactly better.
Well, my experience with v6 was very good, and I still have it running on a lot of routers in the hobby network.
I never would have switched the company network to v7 when the currently used hardware (CCR2004 and RB5009) would not require it...
I would be very happy when there was an optional package to have the original v6 auto-routing in v7.
For my use-cases (not full table internet routing but routing in a smaller network with 20 (work) to 1000 (hobby) routes on a partial mesh network) the old routing was fine and at least it was fully stable without those 'That does not qualify as "completely broken"' bugs... and there was no performance problem. The "new routing engine" has brought us nothing useful, and the configuration is "more complicated" as well (no problem for the company network but not so good for the hobby network).
+++

The only reason I use v7 is because newer devices only work with v7.
Even devices that predate v7 (ie RB4011) is being shipped with v7 now and cannot downgrade to v6.

v6 was stable (enough), BGP was a breeze to configure (especially with lot and complicated filters) and easier troubleshoot. Mainly because it was stable and when troubleshooting you didn't have to wonder if it was a misconfiguration or yet another obscure bug.
In the of the day, it just worked.

When using a commercial product I want it to just work, not do experiments and beta testing for it. Otherwise I could just install plain linux and experiment with the myriad of BGP implementations out there (which ironically are more stable and have more features).

BGP on v7 is just a big flop. Nothing that was promised 10+ years ago when 1st gen CCRs showed the issues with large routing tables with v6 BGP, was actually delivered IMHO.

Instead of focusing on core routing functionality, we get ROSE...
And no, just because other developers may be working on ROSE does not mean that it doesn't affect routing. It does. Resources (human and money) are being spent on frivolous stuff instead of networking.
 
User avatar
dag
just joined
Posts: 7
Joined: Mon Dec 16, 2019 8:48 pm
Location: Dallas, TX

Re: v7.19rc [testing] is released!

Wed May 07, 2025 2:41 pm

Instead of focusing on core routing functionality, we get ROSE...
And no, just because other developers may be working on ROSE does not mean that it doesn't affect routing. It does. Resources (human and money) are being spent on frivolous stuff instead of networking.
I doubt that's an accurate assessment of Mikrotik's state of affairs--to be fair, one can walk and chew gum at the same time. And given how bare-bones the capabilities of ROSE are vs. what's available out there, I seriously doubt they have devoted that many resources to it. Let's face it, the RDS2216 feels more like a "let's test the waters and see how the market reacts" effort more than anything else. It's essentially a CCR2216 with a less capable switch chip and less ports to lower costs, with md and smbd running in the background to do some basic storage stuff.

And at the risk of rubbing you the wrong way even further, for many of us, 7.x has proven to be vastly superior to 6.x in many ways. YMMV I guess.
 
millenium7
Long time Member
Long time Member
Posts: 618
Joined: Wed Mar 16, 2016 6:12 am

Re: v7.19rc [testing] is released!

Wed May 07, 2025 3:11 pm

V7 is a side-step at best. Wireguard and wifiwave2 drivers are the only 2 things I consider a viable upgrade for, but there is nothing worth changing from V6 to V7 for in terms of a core routing device. Many things are still 'beta quality' at best. Both OSPF and BGP are less reliable in V7, MPLS is still not fixed and has the exact same issues as V6, IS-IS implementation is a joke and practically stalled in development

Routing filters are SUBSTANTIALLY more annoying to write. I understand the theoretical benefit of an if:then type of syntax, but I do absolutely nothing in V7 that warrants it and had no problem with V6 which is a lot easier/simpler to read and implement. I cringe if I have to replace a V6 router that died with a V7 one and have to manually port the routing filters across, it's a flapping PITA

At this point in time if I could have a choice of running V6 on any mikrotik hardware, i'd do it on every single one and only ever touch V7 for consumer wifi devices
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1697
Joined: Thu Nov 12, 2020 12:07 pm

Re: v7.19rc [testing] is released!

Wed May 07, 2025 3:18 pm

I'd suggest to continue these general discussion on ROS v7 capabilities in a dedicated topic. None of this is going to be improved in 7.19. It's in RC already.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Wed May 07, 2025 4:09 pm

Discussing things in a separate topic is effectively writing them to /dev/null
That has been discussed often enough.
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1697
Joined: Thu Nov 12, 2020 12:07 pm

Re: v7.19rc [testing] is released!

Wed May 07, 2025 4:27 pm

Indeed, discussed often. But IMHO these release topics are some variant of /dev/null. You can write until this topic gets locked for discussion. What a waste of words.
 
User avatar
Cha0s
Forum Guru
Forum Guru
Posts: 1166
Joined: Tue Oct 11, 2005 4:53 pm

Re: v7.19rc [testing] is released!

Wed May 07, 2025 4:31 pm

Instead of focusing on core routing functionality, we get ROSE...
And no, just because other developers may be working on ROSE does not mean that it doesn't affect routing. It does. Resources (human and money) are being spent on frivolous stuff instead of networking.
I doubt that's an accurate assessment of Mikrotik's state of affairs--to be fair, one can walk and chew gum at the same time. And given how bare-bones the capabilities of ROSE are vs. what's available out there, I seriously doubt they have devoted that many resources to it. Let's face it, the RDS2216 feels more like a "let's test the waters and see how the market reacts" effort more than anything else. It's essentially a CCR2216 with a less capable switch chip and less ports to lower costs, with md and smbd running in the background to do some basic storage stuff.

And at the risk of rubbing you the wrong way even further, for many of us, 7.x has proven to be vastly superior to 6.x in many ways. YMMV I guess.
Even if a single developer was allocated to implementing the storage features on ROS, is still a single developer less allocated to networking.

You probably do very basic stuff in v7 if you think that's vastly superior to v6.
The only actual feature worth using v7 for, is Wireguard.
 
toxicfusion
Member
Member
Posts: 326
Joined: Mon Jan 14, 2013 6:02 pm

Re: v7.19rc [testing] is released!

Wed May 07, 2025 5:23 pm

I agree 10000% with you all, my sentiment remains the same. If Normis and team want to take this serious, they need better management and direction within.

MikroTik needs to be back to their core of "routing the world". I agree that v6 was significantly better, I see no benefit in V7 - besides Wave2 and Wireguard -- same as others have mentioned.

Myself and others are also telling MikroTik.... that we're abandoning and moving toward other vendors. It's just not worth the headache, trial and error and beta testing; we need the software and hardware to "just work". Or when it doesnt work.... we have real support and issues being addressed.

If MikroTIk opened up real support, or paid support like other vendors -- this can help. Ubiqu*F* is now offering paid support..... also their release of v9 is very nice and forward progress. This all might be a precursor to them leaving the consumer market and focusing on pro/enterprise. There is no significant money in consumer hardware [too many other vendors saturating market].

We're left to figure it out on our own, be on our own island. Otherwise, turn to some other MikroTik certified professional; who probably also have their hands tied with no answer or fix. MikroTik has all the answers internally - but leave us stranded.

- Roadmaps
- Better documentation
- Fix existing known issues, focus on the core networking
- Publish standard & validated configurations
- Where is a MikroTik controller...??? Winbox is a do-it-all tool, stuck in the 2000s.

- Segment storage to another division

Or.... MikroTik leave "Routing the world" behind and pivot to being a storage company.

They're refusing to take consultants, enthusiasts, professionals input and advice seriously. If they would, they would have already segmented their "consumer -home" type hardware from their pro/enterprise.

The entire notion behind "you own the hardware" and not bound by licensing is moot. As it is, there are still License level types on various hardware; so what's the difference? Even considering this entire roll-out of device-mode.....
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4868
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.19rc [testing] is released!

Wed May 07, 2025 5:47 pm

*) dhcpv4/v6-client - added check-gateway parameter;
Using WInBox4, the DHCP client "check-gateway" option is a static control, but should be drop-down.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Wed May 07, 2025 7:16 pm

Indeed, discussed often. But IMHO these release topics are some variant of /dev/null. You can write until this topic gets locked for discussion. What a waste of words.
Well now at least we had both normis and mrz commenting on the topic "problems with BGP", we can hope that they had a chat at the coffee machine and walked by the routing guy to ask what he is working on and if he has an idea what happened in the 7.16 release...
That never would have happened when we were discussing it in a separate topic!
 
User avatar
dag
just joined
Posts: 7
Joined: Mon Dec 16, 2019 8:48 pm
Location: Dallas, TX

Re: v7.19rc [testing] is released!

Wed May 07, 2025 8:03 pm


You probably do very basic stuff in v7 if you think that's vastly superior to v6.
The only actual feature worth using v7 for, is Wireguard.
Never said it was vastly superior, no need to get personal here. But since you're asking, for instance, 7.x took the CCR2004 from an unstable/unfinished piece of crap impossible to deploy and maintain in the field due to its lack of reliability, to a pretty damn good router, from both cost and performance perspectives. The 6.x kernel just never played well with the Annapurna-based line. And yes, wireguard is a big plus. Like I said, ymmv.
 
User avatar
dag
just joined
Posts: 7
Joined: Mon Dec 16, 2019 8:48 pm
Location: Dallas, TX

Re: v7.19rc [testing] is released!

Wed May 07, 2025 8:11 pm


If MikroTIk opened up real support, or paid support like other vendors -- this can help. Ubiqu*F* is now offering paid support..... also their release of v9 is very nice and forward progress. This all might be a precursor to them leaving the consumer market and focusing on pro/enterprise.
UI and routing is like oil and water, they just don’t mix. UDM/Unifi is painful and catered to “prosumers” who also think skibidi ohio rizz sigma are the coolest things to say, and UISP, while initially promising, quickly proved to be crippled/DoA. The Edge line was great at the time, but it’s old and feature-poor now, and UI quietly let it die anyway, one of their biggest mistakes if you ask me (I guess they had no desire to maintain their own branch of vyatta after brocade bought it).
 
jackrabbit
just joined
Posts: 11
Joined: Tue Jul 07, 2020 1:28 pm

Re: v7.19rc [testing] is released!

Wed May 07, 2025 11:06 pm

@MikroTik could you somehow update the wireguard sources? based on your GPL handed out ̶f̶o̶r̶ ̶7̶.̶1̶9̶r̶c̶ you're using code untouched from 5 years ago. more exactly it's stuck at this point: https://github.com/WireGuard/wireguard- ... 49e940b479
A fast look over the changes in those years I've found this: https://github.com/WireGuard/wireguard- ... c6214ccf7a
Among other changes it had in FIVE YEARS.
Shame.
That is, if you actually provided the recent sources, and not some old archive that you just hand out on request. That would be another can of worms.
Yes, it would really help to have RouterOS v7 use more recent wireguard sources - it would improve performance considerably.
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4868
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.19rc [testing] is released!

Thu May 08, 2025 1:56 am

*) route - added options to set dynamic-in and connected-in chains in /routing/settings;
FWIW, these are not in the docs yet (or at least I cannot find them):
/routing/settings/set <tab>
connected-in-chain     dynamic-in-chain     single-process   
The "dynamic-in-chain" works fine, but none of the /routing/settings are mentioned in help.mikrotik.com.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Thu May 08, 2025 10:35 am

UI and routing is like oil and water, they just don’t mix.
I think MikroTik had it pretty well sorted in v6. Routing was a breeze to configure via the UI.
Apparently there was performance to be gained at the bare routing level and they wanted to re-write that from generic Linux.
However what I will probably never understand is why the routing engine configuration was totally overhauled.
The concept of templates was new to RouterOS and was never properly implemented in winbox, the filter change from a list of parameters to a "language" that has to be entered by the user is completely alien to the entire RouterOS system.
 
bratislav
Frequent Visitor
Frequent Visitor
Posts: 69
Joined: Mon May 05, 2014 10:36 am

Re: v7.19rc [testing] is released!

Thu May 08, 2025 11:43 am

@MikroTik could you somehow update the wireguard sources?
Yes, it would really help to have RouterOS v7 use more recent wireguard sources - it would improve performance considerably.
RouterOS is stuck at Linux Kernel 5.6.3 as far as I know which was the first release to have wireguard and wireguard is a part of the kernel source tree ever since so porting it back to 5.6.3 which isn't supported from 2020 may not be as easy task...

Sticking with 5.6.3 seemed funny decision even back than because LTS 5.10 (which is still supported by the way) came out only a couple months later and before ROS 7 was released as "stable", and using LTS 5.10 version should have made maintaining much easier for Mikrotik IMHO because kernel patches are applied and tested by Linux Kernel maintainers, even for example wireguard was last updated 9 months ago...
 
User avatar
strods
MikroTik Support
MikroTik Support
Topic Author
Posts: 1684
Joined: Wed Jul 16, 2014 7:22 am
Location: Riga, Latvia

Re: v7.19rc [testing] is released!

Thu May 08, 2025 12:30 pm

What's new in 7.19rc2 (2025-May-07 10:32):

*) device-mode - fixed print command (introduced in v7.19rc1);
*) ip-service - show all TCP/UDP ports on system, including ports in containers (additional fixes);
*) lte - deactivate current eSIM profile before activating new profile;
*) lte - fixed default APN for configless modems;
*) route - fixed route rule "min-prefix" unset;
*) route - show "routing-table" by default on console print output;
*) switch - properly match IPv6 packets with empty ACL rule on CRS3xx, CRS5xx, CCR2004, CCR2116, CCR2216, RDS devices;
*) timezone - updated timezone information from "tzdata2025b" release;
*) winbox - properly show/hide OSPF, RIP and BGP tabs for IPv6 routes;
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1943
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: v7.19rc [testing] is released!

Thu May 08, 2025 1:31 pm

Yes, it would really help to have RouterOS v7 use more recent wireguard sources - it would improve performance considerably.

Notable WireGuard changes since kernel 5.6.3, which was released on 2020-04-15:

Summary code

| Date       | Kernel | Summary
+------------+--------+------------------------------------------------------------
| 2021-02-14 | 5.11   | Lock-free p/p single-list queues with ~90% lower memory p/p,
|            |        | reduced CPU contention, latency and improved p/p scaling
| 2021-02-14 | 5.11   | Improved crypto support for ARM with/without NEON/SIMD and
|            |        | for x86 SSE2/SSSE3/AVX
| 2021-06-27 | 5.13   | Switched compiler flags from -O3 to -O2 for improved stability
| 2023-08-27 | 6.5    | CPU affinity fix for encryption threads. Faster round-robin
|            |        | across cores with better latency and load balance
| 2025-01-21 | 6.13   | Adding Big TCP (GSO) with ~15% throughput boost on TCP streams
| 2025 WIP   | 6.15   | GRO-based NIC offload similar to IPsec ESP hardware offload (beta)

Various fixes 2021–2023
- Checksum and UDP stack optimizations for faster UDP handling and lower checksum overhead
- Better TX packet batching lets WireGuard process multiple packets per loop iteration
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1697
Joined: Thu Nov 12, 2020 12:07 pm

Re: v7.19rc [testing] is released!

Thu May 08, 2025 1:47 pm

The ROS sources provided in another topic seem not to reflect a current/recent release and are maybe 2+ years old. We dont actually know, maybe Mikrotik cherry-picked all these Wireguard commits manually on their Kernel? Regarding the 5.10 LTS argument: As far as I am aware of and looked at the sources they did heavily patch the kernel. So I think they did not want to get surprised by upstream Kernel changes. Changes that could introduce unpredictable behaviour changes as well. So they stick at this particular version and maybe happily applying individual commits from upstream manually. At least I hope so.
 
FezzFest
Member Candidate
Member Candidate
Posts: 104
Joined: Wed Jun 03, 2015 12:03 am

Re: v7.19rc [testing] is released!

Thu May 08, 2025 2:06 pm

To address this further:

It appears that if the router is already receiving routes from another router in the same AS, that it won't even count and list any of those same routes as received from a second router in that source AS (hence the "0" or "1"). The second router is most definitely advertising them. This isn't an iBGP issue as you can see that one of the peers with two routers is an eBGP peer.

I would think the receiving router should list all of them, even if it adds an "Fb" for filtered or just "b" for BGP.
Weirdly enough I do not seem to have this issue. I have an RB4011 with an LHG60 and NB19 link to the same tower, each with their own BGP session (but same local/remote ASN) and prefix counts are identical for both sessions.
Image
Both BGP sessions terminate on the same local and remote router though, maybe it's only triggered when it receives routes from a different router with the same ASN? Or only after one of the links flap? I had an issue recently on v7.14.3 where after a link flapped about 20% of the routes were missing in the routing table even though they were being advertised by the peer.
 
User avatar
BrateloSlava
Member Candidate
Member Candidate
Posts: 201
Joined: Mon Aug 09, 2021 10:33 am
Location: Ukraine, Kharkiv

Re: v7.19rc [testing] is released!

Thu May 08, 2025 2:30 pm

Question about DNS Adlist.
I use a file for blocking addresses, that is created by a script. The script downloads data from several sources and removes repeated addresses. This file is then uploaded to the router and added to the blocking list.
Screenshot_Adlist.png
or
Screenshot_Adlist_noSSL.png

There are two problems with this:
1. after the router is rebooted, this file of data for blocking is not automatically read. you must manually perform an action to upload from the file.
2. an error line appears periodically. even though I don't have any line with http data download.
Screenshot_Error.png
You do not have the required permissions to view the files attached to this post.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Thu May 08, 2025 3:38 pm

Both BGP sessions terminate on the same local and remote router though, maybe it's only triggered when it receives routes from a different router with the same ASN? Or only after one of the links flap? I had an issue recently on v7.14.3 where after a link flapped about 20% of the routes were missing in the routing table even though they were being advertised by the peer.
We have a central router and 3 branch routers. Each branch router has two tunnels to the central router (one over GRE and one over L2TP/IPsec), and the branch routers have tunnels to eachother over GRE6.
The routes over L2TP/IPsec are set to local-pref 90 using filters.
Usually after boot the pref 90 routes appear in the table, all prefix counts are the same on the 4 tunnels at each branch, but after a route flap they often do not come back.
But unfortunately when the main internet connection that transports the GRE and GRE6 tunnel goes down, the backup is via L2TP and its routes are not installed in the table.
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1697
Joined: Thu Nov 12, 2020 12:07 pm

Re: v7.19rc [testing] is released!

Thu May 08, 2025 5:02 pm

I hope MikroTik will be able to slow down the growth of the RouterOS package size. Compared to version 7.18.2 (ARM), the size has increased again by almost 100 KB. With 7.18.2, I already had to recover my Chateau LTE12 using Netinstall, and have since downgraded to 7.16.2.

It seems that version 7.19 may no longer be usable for me - unless I remove something like wifi-qcom-ac package. That’s unfortunate. I understand that 16 MB of flash storage is limited, but I recently found this post: viewtopic.php?t=106195#p539439 - and it seems that, eventually, even RouterOS with wireless package might no longer fit some day.
 
ToTheFull
Member
Member
Posts: 429
Joined: Fri Mar 24, 2023 3:24 pm

Re: v7.19rc [testing] is released!

Thu May 08, 2025 5:09 pm

Have they not released the Chateau LTE12 (2025) with 32MB ?
 
User avatar
Paternot
Forum Guru
Forum Guru
Posts: 1098
Joined: Thu Jun 02, 2016 4:01 am
Location: Niterói / Brazil

Re: v7.19rc [testing] is released!

Thu May 08, 2025 5:22 pm

The routes over L2TP/IPsec are set to local-pref 90 using filters.
Usually after boot the pref 90 routes appear in the table, all prefix counts are the same on the 4 tunnels at each branch, but after a route flap they often do not come back.
But unfortunately when the main internet connection that transports the GRE and GRE6 tunnel goes down, the backup is via L2TP and its routes are not installed in the table.
Have You tested without the filters? May help to narrow down WHERE the problem is.
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1697
Joined: Thu Nov 12, 2020 12:07 pm

Re: v7.19rc [testing] is released!

Thu May 08, 2025 5:27 pm

Have they not released the Chateau LTE12 (2025) with 32MB ?
Yes, Mikrotik released a Chateau LTE12 (2025). https://mikrotik.com/product/chateau_lte12_2025
What do you want to tell me? I should replace my existing Chateau with the "2025 refresh"? This can only be a cost factor - but why should anyone buy Chateau LTE12 (2025) with legacy wireless (instead of Chateau LTE18 AX)? Or does this ship with wifi-qcom-ac already? But even then: it is 2025. Nobody should buy new devices with 802.11ac only. At least in Western Europe.

But the flash issue applies to my cap ac as well. There is no "cap ac (2025)" with 32MB flash right now. But my cap ac still has some "room" as it is acting as a dumb CAP.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Thu May 08, 2025 5:31 pm

Have You tested without the filters? May help to narrow down WHERE the problem is.
That isn't possible. The filters are required to force the routing over the fiber/vdsl connection instead of over 4G with limited bundle.
But the filter is simple:
/routing filter rule
add chain=pref-90 comment="low pref for backup paths" disabled=no rule="set bgp-local-pref 90;"
add chain=pref-90 disabled=no rule="jump input;"
(chain input is what is used on the fiber/vdsl peers)
When that disturbs the BGP functioning there is a bug.
 
User avatar
Paternot
Forum Guru
Forum Guru
Posts: 1098
Joined: Thu Jun 02, 2016 4:01 am
Location: Niterói / Brazil

Re: v7.19rc [testing] is released!

Thu May 08, 2025 5:42 pm

That isn't possible. The filters are required to force the routing over the fiber/vdsl connection instead of over 4G with limited bundle.
When that disturbs the BGP functioning there is a bug.
I use this exactly thing on my DN42 filters. Never noticed a problem, but then again it's a very particular one - and getting different number of routes from different peers is the expected behavior there.
I'll take a look here, with my setup. Maybe I'm affected and never noticed? Maybe I'm not affected, and we can run a differential to narrow it down?

EDIT: Although I don't use two connections from the same router... may be a factor too.
 
User avatar
sirbryan
Member
Member
Posts: 478
Joined: Fri May 29, 2020 6:40 pm
Location: Utah
Contact:

Re: v7.19rc [testing] is released!

Thu May 08, 2025 5:46 pm

Weirdly enough I do not seem to have this issue. I have an RB4011 with an LHG60 and NB19 link to the same tower, each with their own BGP session (but same local/remote ASN) and prefix counts are identical for both sessions.
Image
Both BGP sessions terminate on the same local and remote router though, maybe it's only triggered when it receives routes from a different router with the same ASN? Or only after one of the links flap? I had an issue recently on v7.14.3 where after a link flapped about 20% of the routes were missing in the routing table even though they were being advertised by the peer.

In my case, I have two [mostly identical] routers talking to one router. The lone router has two BGP sessions that should be receiving the same prefixes from the two redundant routers. We're both seeing that, after some uptime and some link bounces, one of the two BGP sessions is showing nothing received.

For me, the lone router is one of my border routers at a data center, and it has one BGP session each to two routers in my core, as well as one BGP session each to two border routers of one of my customers. Both of the BGP sessions to the secondary router in each pair are showing 0 (or 1) route(s) received, which is wrong. A full reset of the BGP session does not fix it, but apparently a reboot does.
Last edited by sirbryan on Thu May 08, 2025 5:50 pm, edited 1 time in total.
 
wispmikrotik
Member Candidate
Member Candidate
Posts: 161
Joined: Tue Apr 25, 2017 10:43 am

Re: v7.19rc [testing] is released!

Thu May 08, 2025 5:47 pm

That isn't possible. The filters are required to force the routing over the fiber/vdsl connection instead of over 4G with limited bundle.
When that disturbs the BGP functioning there is a bug.
I use this exactly thing on my DN42 filters. Never noticed a problem, but then again it's a very particular one - and getting different number of routes from different peers is the expected behavior there.
I'll take a look here, with my setup. Maybe I'm affected and never noticed? Maybe I'm not affected, and we can run a differential to narrow it down?

EDIT: Although I don't use two connections from the same router... may be a factor too.
This would be ideal.

Even if you both could share the configuration (removing sensitive parts like peer IPs), I could set up a "home lab" myself to validate its operation.

I wouldn't want to run into this problem in the future.

In a few months, we're planning a "similar" network and are considering whether to rule out installing a full MikroTik router.

Best regards,
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Thu May 08, 2025 6:26 pm

That isn't possible. The filters are required to force the routing over the fiber/vdsl connection instead of over 4G with limited bundle.
When that disturbs the BGP functioning there is a bug.
I use this exactly thing on my DN42 filters. Never noticed a problem, but then again it's a very particular one - and getting different number of routes from different peers is the expected behavior there.
Sometimes I think that it just won't store more than a certain number of routes to each destination, but I cannot find a consistent number for that. Sometimes it accepts 2, sometimes 3, but I need at least 4 but preferably 5.
(this is because the primary paths that are at pref 100 are likely to fail all at the same time, and when that happens I still need the pref 90 path as a backup. so there should be no "well, we already have 3 paths at pref 100 so let's just ignore that pref 90 path, it is lower anyway")
It would be nice when that number could be configured so there is at least clarity what the limit is.

Typical session display here:
You do not have the required permissions to view the files attached to this post.
 
ToTheFull
Member
Member
Posts: 429
Joined: Fri Mar 24, 2023 3:24 pm

Re: v7.19rc [testing] is released!

Thu May 08, 2025 9:01 pm

Have they not released the Chateau LTE12 (2025) with 32MB ?
Yes, Mikrotik released a Chateau LTE12 (2025). https://mikrotik.com/product/chateau_lte12_2025
What do you want to tell me? I should replace my existing Chateau with the "2025 refresh"? This can only be a cost factor - but why should anyone buy Chateau LTE12 (2025) with legacy wireless (instead of Chateau LTE18 AX)? Or does this ship with wifi-qcom-ac already? But even then: it is 2025. Nobody should buy new devices with 802.11ac only. At least in Western Europe.

But the flash issue applies to my cap ac as well. There is no "cap ac (2025)" with 32MB flash right now. But my cap ac still has some "room" as it is acting as a dumb CAP.
I think your flogging a dead horse is what I'm trying to say.
In other news, my WiFi problem with RC1 appears to be fixed in RC2.
 
User avatar
Paternot
Forum Guru
Forum Guru
Posts: 1098
Joined: Thu Jun 02, 2016 4:01 am
Location: Niterói / Brazil

Re: v7.19rc [testing] is released!

Thu May 08, 2025 9:57 pm


Sometimes I think that it just won't store more than a certain number of routes to each destination, but I cannot find a consistent number for that. Sometimes it accepts 2, sometimes 3, but I need at least 4 but preferably 5.
I have, usually, 6 or 7 possibilities for a given destination.
Here my routes for the DN42 DNS servers:
 > /ipv6/route/print where dst-address=fd42:d42:d42:53::/64 
Flags: D - DYNAMIC; A - ACTIVE; b - BGP
Columns: DST-ADDRESS, GATEWAY, DISTANCE
    DST-ADDRESS           GATEWAY                 DISTANCE
DAb fd42:d42:d42:53::/64  fd86:bad:11b7:23::1           20
D b fd42:d42:d42:53::/64  fd22:ad17:8e8d:10::111        20
D b fd42:d42:d42:53::/64  fd22:ad17:8e8d:10::105        20
D b fd42:d42:d42:53::/64  fdb1:e72a:343d::9             20
D b fd42:d42:d42:53::/64  fd22:ad17:8e8d:10::11d        20

 > /ipv6/route/print where dst-address=fd42:d42:d42:54::/64  
Flags: D - DYNAMIC; A - ACTIVE; b - BGP
Columns: DST-ADDRESS, GATEWAY, DISTANCE
    DST-ADDRESS           GATEWAY                 DISTANCE
D b fd42:d42:d42:54::/64  fd86:bad:11b7:23::1           20
D b fd42:d42:d42:54::/64  fd22:ad17:8e8d:10::111        20
D b fd42:d42:d42:54::/64  fd22:ad17:8e8d:10::117        20
D b fd42:d42:d42:54::/64  fd22:ad17:8e8d:10::105        20
DAb fd42:d42:d42:54::/64  fdb1:e72a:343d::9             20
D b fd42:d42:d42:54::/64  fd22:ad17:8e8d:10::11d        20
I was just thinkering with my BGP connections, after my last post. This is why all but one of them are with a small uptime. They, usually, keep up more than a week each.
You do not have the required permissions to view the files attached to this post.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Thu May 08, 2025 10:20 pm

Yes, as I wrote the number is not consistent. After boot I can easily have all 4 paths to the same destination in the table, but after a while (after a route flap) more and more disappear, the ones with the lower local-pref first.
Do you have a different local-pref on some of the routes?
 
User avatar
Paternot
Forum Guru
Forum Guru
Posts: 1098
Joined: Thu Jun 02, 2016 4:01 am
Location: Niterói / Brazil

Re: v7.19rc [testing] is released!

Thu May 08, 2025 11:48 pm

Do you have a different local-pref on some of the routes?
local-pref, no. I use bgp-local-pref only.
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1697
Joined: Thu Nov 12, 2020 12:07 pm

Re: v7.19rc [testing] is released!

Fri May 09, 2025 12:29 am



Yes, Mikrotik released a Chateau LTE12 (2025). https://mikrotik.com/product/chateau_lte12_2025
What do you want to tell me? I should replace my existing Chateau with the "2025 refresh"? This can only be a cost factor - but why should anyone buy Chateau LTE12 (2025) with legacy wireless (instead of Chateau LTE18 AX)? Or does this ship with wifi-qcom-ac already? But even then: it is 2025. Nobody should buy new devices with 802.11ac only. At least in Western Europe.

But the flash issue applies to my cap ac as well. There is no "cap ac (2025)" with 32MB flash right now. But my cap ac still has some "room" as it is acting as a dumb CAP.
I think your flogging a dead horse is what I'm trying to say.
In other news, my WiFi problem with RC1 appears to be fixed in RC2.
And I am trying to say: why replace my "dead horse" with more or less the same 2025 horse edition? I am not ready to give up my horse.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Fri May 09, 2025 1:29 am

Do you have a different local-pref on some of the routes?
local-pref, no. I use bgp-local-pref only.
bgp-local-pref is used in bgp filters to apply it to a route received via BGP, but once it ends up in the routing table it is called local-pref.
 
User avatar
Paternot
Forum Guru
Forum Guru
Posts: 1098
Joined: Thu Jun 02, 2016 4:01 am
Location: Niterói / Brazil

Re: v7.19rc [testing] is released!

Fri May 09, 2025 1:59 am

bgp-local-pref is used in bgp filters to apply it to a route received via BGP, but once it ends up in the routing table it is called local-pref.
In that case, lots of them. I use it to choose the BGP peer based on the region of the internal host I will connect to.

One block of filters - this one used by peers that are on the North America, East.
add chain=DN42PeerAmericaDoNorteLeste comment="Pega-tudo dos sem-regiao (14)" disabled=no rule="if (not bgp-communities any-list RegiaoOrigem) {set bgp-local-pref 500; jump DN42EntradaSanidade}"
add chain=DN42PeerAmericaDoNorteLeste comment="Am\E9rica do Norte Leste -> Pacifico (13)" disabled=no rule="if (bgp-communities any 64511:53) {set bgp-local-pref 5838; jump DN42EntradaSanidade}"
add chain=DN42PeerAmericaDoNorteLeste comment="Am\E9rica do Norte Leste -> Asia Sudeste (11)" disabled=no rule="if (bgp-communities any 64511:51) {set bgp-local-pref 6238; jump DN42EntradaSanidade}"
add chain=DN42PeerAmericaDoNorteLeste comment="Am\E9rica do Norte Leste -> Asia Leste (12)" disabled=no rule="if (bgp-communities any 64511:52) {set bgp-local-pref 6238; jump DN42EntradaSanidade}"
add chain=DN42PeerAmericaDoNorteLeste comment="Am\E9rica do Norte Leste -> Asia Sul (10)" disabled=no rule="if (bgp-communities any 64511:50) {set bgp-local-pref 6738; jump DN42EntradaSanidade}"
add chain=DN42PeerAmericaDoNorteLeste comment="Am\E9rica do Norte Leste -> Africa do Sul (09)" disabled=no rule="if (bgp-communities any 64511:49) {set bgp-local-pref 6863; jump DN42EntradaSanidade}"
add chain=DN42PeerAmericaDoNorteLeste comment="Am\E9rica do Norte Leste -> Africa do Norte (08)" disabled=no rule="if (bgp-communities any 64511:48) {set bgp-local-pref 7913; jump DN42EntradaSanidade}"
add chain=DN42PeerAmericaDoNorteLeste comment="Am\E9rica do Norte Leste -> Am\E9rica do Sul Oeste (07)" disabled=no rule="if (bgp-communities any 64511:47) {set bgp-local-pref 8288; jump DN42EntradaSanidade}"
add chain=DN42PeerAmericaDoNorteLeste comment="Am\E9rica do Norte Leste -> Europa (01)" disabled=no rule="if (bgp-communities any 64511:41) {set bgp-local-pref 8438; jump DN42EntradaSanidade}"
add chain=DN42PeerAmericaDoNorteLeste comment="Am\E9rica do Norte Leste -> Am\E9rica do Sul Leste (06)" disabled=no rule="if (bgp-communities any 64511:46) {set bgp-local-pref 8513; jump DN42EntradaSanidade}"
add chain=DN42PeerAmericaDoNorteLeste comment="Am\E9rica do Norte Leste -> Am\E9rica do Norte Oeste (05)" disabled=no rule="if (bgp-communities any 64511:44) {set bgp-local-pref 8988; jump DN42EntradaSanidade}"
add chain=DN42PeerAmericaDoNorteLeste comment="Am\E9rica do Norte Leste -> Am\E9rica Central" disabled=no rule="if (bgp-communities any 64511:45) {set bgp-local-pref 9263; jump DN42EntradaSanidade}"
add chain=DN42PeerAmericaDoNorteLeste comment="Am\E9rica do Norte Leste -> Am\E9rica do Norte Centro (04)" disabled=no rule="if (bgp-communities any 64511:43) {set bgp-local-pref 9488; jump DN42EntradaSanidade}"
add chain=DN42PeerAmericaDoNorteLeste comment="Am\E9rica do Norte Leste -> Am\E9rica do Norte Leste (02)" disabled=no rule="if (bgp-communities any 64511:42) {set bgp-local-pref 9988; jump DN42EntradaSanidade}"
 
Milecus
just joined
Posts: 2
Joined: Thu Oct 17, 2019 9:14 am

Re: v7.19rc [testing] is released!

Fri May 09, 2025 8:07 am

@MT
Minor issue (RB5009UPr+S+):

/interface/ethernet> monitor ether1 once
name: ether1
status: link-ok
auto-negotiation: done
rate: 2.5Gbps
full-duplex: yes
tx-flow-control: no
rx-flow-control: no
supported: 10M-baseT-half
10M-baseT-full
100M-baseT-half
100M-baseT-full
1G-baseT-half
1G-baseT-full
2.5G-baseT
advertising: 10M-baseT-half
10M-baseT-full
100M-baseT-half
100M-baseT-full
1G-baseT-half
1G-baseT-full
2.5G-baseT
link-partner-advertising: 10M-baseT-half
10M-baseT-full
100M-baseT-half
100M-baseT-full
1G-baseT-full
this line doesn't appear "2.5G-baseT"
with this connection 2.5Gbps
 
matiss
MikroTik Support
MikroTik Support
Posts: 48
Joined: Fri Dec 30, 2016 10:13 am

Re: v7.19rc [testing] is released!

Fri May 09, 2025 9:05 am

Question about DNS Adlist.
I use a file for blocking addresses, that is created by a script. The script downloads data from several sources and removes repeated addresses. This file is then uploaded to the router and added to the blocking list.
Screenshot_Adlist.png or Screenshot_Adlist_noSSL.png


There are two problems with this:
1. after the router is rebooted, this file of data for blocking is not automatically read. you must manually perform an action to upload from the file.
2. an error line appears periodically. even though I don't have any line with http data download.
Screenshot_Error.png
Adlist from file or from URL is loaded after each startup.
Please send us the supout.rif file to support@mikrotik.com from your device made right after it encounters the problem.
 
User avatar
Cha0s
Forum Guru
Forum Guru
Posts: 1166
Joined: Tue Oct 11, 2005 4:53 pm

Re: v7.19rc [testing] is released!

Fri May 09, 2025 10:43 am

7.x has proven to be vastly superior to 6.x in many ways.
Never said it was vastly superior
🤦‍♂️
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1697
Joined: Thu Nov 12, 2020 12:07 pm

Re: v7.19rc [testing] is released!

Fri May 09, 2025 11:13 am

I dont know why the "Canvas" forum theme does not show the quote-author. The polsilver theme does it correctly. I always found this so confusing not knowing who is quoted actually. Can Mikrotik forum admins fix this?
2025-05-09_10-12.png
2025-05-09_10-13.png
You do not have the required permissions to view the files attached to this post.
 
matiss
MikroTik Support
MikroTik Support
Posts: 48
Joined: Fri Dec 30, 2016 10:13 am

Re: v7.19rc [testing] is released!

Fri May 09, 2025 11:57 am

@MT
Minor issue (RB5009UPr+S+):

/interface/ethernet> monitor ether1 once
name: ether1
status: link-ok
auto-negotiation: done
rate: 2.5Gbps
full-duplex: yes
tx-flow-control: no
rx-flow-control: no
supported: 10M-baseT-half
10M-baseT-full
100M-baseT-half
100M-baseT-full
1G-baseT-half
1G-baseT-full
2.5G-baseT
advertising: 10M-baseT-half
10M-baseT-full
100M-baseT-half
100M-baseT-full
1G-baseT-half
1G-baseT-full
2.5G-baseT
link-partner-advertising: 10M-baseT-half
10M-baseT-full
100M-baseT-half
100M-baseT-full
1G-baseT-full
this line doesn't appear "2.5G-baseT"
with this connection 2.5Gbps
Due to hardware limitations, RB5009 series, hAP ax3 and Chateau ax series devices cannot display whether link partner advertises 2.5G-baseT.
 
User avatar
Jotne
Forum Guru
Forum Guru
Posts: 3372
Joined: Sat Dec 24, 2016 11:17 am
Location: Magrathean

Re: v7.19rc [testing] is released!

Fri May 09, 2025 1:47 pm

I dont know why the "Canvas" forum theme does not show the quote-author. The polsilver theme does it correctly. I always found this so confusing not knowing who is quoted actually. Can Mikrotik forum admins fix this?

2025-05-09_10-12.png

2025-05-09_10-13.png
Canvas seems to just miss most of the basic function of the phpBB compare to Prosilver. Canvas is so bad, that I can not use the forum with it.
Here are just some example. Canvas takes up much more space. I Prosilver I can see what thread I have posted in by look at the small red star in the circle in front of the post. File attachement is also missing. I do wish that Mikrotik either remove Canvas or update it so it works with all function.
.
prosilver.png
You do not have the required permissions to view the files attached to this post.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Fri May 09, 2025 2:04 pm

There sure is something very strange going on... I use prosilver but when inline images are added as attachments I cannot see them.
When I switch to Canvas I do see the attachments, and when I then switch back to prosilver they remain there, but probably only because they are cached locally in the browser. When I do a shift-refresh they are gone again.
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1697
Joined: Thu Nov 12, 2020 12:07 pm

Re: v7.19rc [testing] is released!

Fri May 09, 2025 2:06 pm

Most people use Canvas as it is the forum preset.
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1363
Joined: Mon Sep 23, 2019 1:04 pm

Re: v7.19rc [testing] is released!

Fri May 09, 2025 2:43 pm

This is not very release related.
 
User avatar
dag
just joined
Posts: 7
Joined: Mon Dec 16, 2019 8:48 pm
Location: Dallas, TX

Re: v7.19rc [testing] is released!

Fri May 09, 2025 3:31 pm

7.x has proven to be vastly superior to 6.x in many ways.
Never said it was vastly superior
🤦‍♂️
I said it was vastly superior *for many of us*, *in many ways* and I made it clear *ymmv*, multiple times. You shortened my quote, italicized vastly, and purposely took my words out of context to make it sound I was making a generic/universal statement, which was not the intent. I even provided examples as to why it was better from my standpoint.

But hey, I’ll restate what I wrote to keep all the closeted keyboard warriors on this forum happy => 7.x may not be for everyone, but it proved to be vastly superior for many of us. Again, ymmv. And if you don’t like it, 6.49 is still kicking and alive, and on LTS.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Fri May 09, 2025 6:46 pm

Note that the procedure to update the backup bootloader at https://help.mikrotik.com/docs/spaces/R ... bootloader has now been updated to support version 7.18.2 (ONLY!) so when you get those warnings about NAND stability after an upgrade, now is the time to upgrade the bootloader to fix that.
(before, it required version 7.6 which is of course ancient and nobody wants to downgrade to that)
 
User avatar
Cha0s
Forum Guru
Forum Guru
Posts: 1166
Joined: Tue Oct 11, 2005 4:53 pm

Re: v7.19rc [testing] is released!

Sat May 10, 2025 11:49 am

I said it was vastly superior *for many of us*, *in many ways* and I made it clear *ymmv*, multiple times. You shortened my quote, italicized vastly, and purposely took my words out of context to make it sound I was making a generic/universal statement, which was not the intent. I even provided examples as to why it was better from my standpoint.

But hey, I’ll restate what I wrote to keep all the closeted keyboard warriors on this forum happy => 7.x may not be for everyone, but it proved to be vastly superior for many of us. Again, ymmv. And if you don’t like it, 6.49 is still kicking and alive, and on LTS.
Tomayto tomahto.

And no, you cannot use v6. I guess you haven't bought a MikroTik product since the first CCR2004, for which you could apparently accept a downgrade in functionality (ie v7) for it to just work without crashing every two minutes. In that sense if you squint your eyes enough, v7 maybe superior to some hurt wallets, yes.
 
jaclaz
Forum Guru
Forum Guru
Posts: 2887
Joined: Tue Oct 03, 2023 4:21 pm

Re: v7.19rc [testing] is released!

Sat May 10, 2025 2:53 pm

And no, you cannot use v6. I guess you haven't bought a MikroTik product since the first CCR2004, for which you could apparently accept a downgrade in functionality (ie v7) for it to just work without crashing every two minutes. In that sense if you squint your eyes enough, v7 maybe superior to some hurt wallets, yes.
What has Ros7 ever done for us?

Apart from ...
 
User avatar
dag
just joined
Posts: 7
Joined: Mon Dec 16, 2019 8:48 pm
Location: Dallas, TX

Re: v7.19rc [testing] is released!

Sat May 10, 2025 3:17 pm

And no, you cannot use v6. I guess you haven't bought a MikroTik product since the first CCR2004
Plenty of v6-based gear out there up for grabs, esp. if you know a reseller that still carries older stock, or if you're willing to use second hand gear. We have dozens of 2004s in the field that will be happy to go all the way back to 6.46.4 via a simple netinstall (note that based on other comments, the 2004 appears to be stable with the later revisions of 6.49, though we have absolutely no reason to try).
I guess you haven't bought a MikroTik product since the first CCR2004
This one cuts deep (not). Several r3 2004s, but they won't let you go back to 6.x, obviously. Quite a few 2116's and 2216's out there, and even a rose flavor in the lab--the one you seem to despise so much. For the latter, I'll reiterate my initial comment, if you really think Mikrotik spent oodles of time on the rose package, then you just haven't played with it--it's absolutely barebone at the moment.

Anyway, beggars can't be choosers, if you want the latest and greatest Annapurna-based stuff, yes, you have to settle for v7, which again works great for many of us, even if you're convinced your experience applies to all 8.2B human beings out there. Or you can always look at other stuff like UDM/EFG/UISP as suggested by others--best of luck with that.
 
mickdoev
just joined
Posts: 18
Joined: Fri Mar 17, 2023 2:44 am

Re: v7.19rc [testing] is released!

Mon May 12, 2025 10:10 am

PIM-SM RP candidate selection still not working (the candidate priority is completely ignored and has no impact upon RP selection) - hoping this is to be addressed soon :(
 
redbullsteve
just joined
Posts: 22
Joined: Wed Feb 02, 2011 12:37 am

Re: v7.19rc [testing] is released!

Wed May 14, 2025 1:15 pm

Wireless seems to be broken is this version, CAP ax and WAP ax with RB5009 running CAPsMAN.

Some devices refuse to connect at all, some connect for 30 mins then disconnect and refuse to connect again. 5Ghz seems to stop for no reason and reboot AP's fix issues for a short period.

Intel(R) Wi-Fi 6 AX201 160MHz really struggle

Anyone else having issues with this version and wireless, no noticeable issue with 7.16.2
 
m4rk3J
Frequent Visitor
Frequent Visitor
Posts: 55
Joined: Thu Jan 27, 2022 2:41 pm

Re: v7.19rc [testing] is released!

Wed May 14, 2025 1:17 pm

hAP ax2 and ax3 - everything seems fine (wifi).
 
redbullsteve
just joined
Posts: 22
Joined: Wed Feb 02, 2011 12:37 am

Re: v7.19rc [testing] is released!

Wed May 14, 2025 1:29 pm

hAP ax2 and ax3 - everything seems fine (wifi).
Using CAPsMAN?
 
m4rk3J
Frequent Visitor
Frequent Visitor
Posts: 55
Joined: Thu Jan 27, 2022 2:41 pm

Re: v7.19rc [testing] is released!

Wed May 14, 2025 1:42 pm

On one AP - yes, no on the 2nd.
I don't have other routers to play with, so I don't beta test there.
 
nclmrc
just joined
Posts: 22
Joined: Sat Aug 24, 2019 2:33 am

Re: v7.19rc [testing] is released!

Wed May 14, 2025 2:13 pm

in 7.19rc2 upload target limit, in simple queue on interface in vrf different from main, doesn't work
 
erlinden
Forum Guru
Forum Guru
Posts: 3063
Joined: Wed Jun 12, 2013 1:59 pm
Location: Netherlands

Re: v7.19rc [testing] is released!

Wed May 14, 2025 2:16 pm

Using CAPsMAN?
My RB4011 and 3x wAP AX managed by CAPsMAN is working flawless with V7.19RC2.
Can you share your CAPsMAN config together with the CAPS?
 
TrevinLC1997
newbie
Posts: 32
Joined: Mon Jan 06, 2025 7:51 am

Re: v7.19rc [testing] is released!

Wed May 14, 2025 6:33 pm

Wireless seems to be broken is this version, CAP ax and WAP ax with RB5009 running CAPsMAN.

Some devices refuse to connect at all, some connect for 30 mins then disconnect and refuse to connect again. 5Ghz seems to stop for no reason and reboot AP's fix issues for a short period.

Intel(R) Wi-Fi 6 AX201 160MHz really struggle

Anyone else having issues with this version and wireless, no noticeable issue with 7.16.2
My AX also works fine, one thing I did notice have you checked the channel it was broadcasting on when the 5ghz dropped? I’ve noticed sometimes it’ll choose something in the UNII-4 range (channel 5885) which 99% of devices don’t see and it will appear that 5g isn’t there until you restart your WiFi and it chooses a new channel. (You can manually pick a new channel but that’s why restarting the AP appears to fix the problem)


If this is the case then just set a filter that blocks those channels from being chosen. Once I did that it’s been smooth sailing.
Last edited by TrevinLC1997 on Wed May 14, 2025 9:36 pm, edited 1 time in total.
 
nclmrc
just joined
Posts: 22
Joined: Sat Aug 24, 2019 2:33 am

Re: v7.19rc [testing] is released!

Wed May 14, 2025 7:52 pm

in 7.19r2 doesn't work romon discovery on interface list
 
User avatar
bajodel
Long time Member
Long time Member
Posts: 553
Joined: Sun Nov 24, 2013 8:30 am
Location: Italy

Re: v7.19rc [testing] is released!

Wed May 14, 2025 11:24 pm

 
User avatar
Jotne
Forum Guru
Forum Guru
Posts: 3372
Joined: Sat Dec 24, 2016 11:17 am
Location: Magrathean

Re: v7.19rc [testing] is released!

Thu May 15, 2025 7:51 am

This page need username and password to see.
 
User avatar
bajodel
Long time Member
Long time Member
Posts: 553
Joined: Sun Nov 24, 2013 8:30 am
Location: Italy

Re: v7.19rc [testing] is released!

Thu May 15, 2025 8:48 am

This page need username and password to see.
You're right, it was accessible last night.
(some initial draft of EVPN documentation, so make your own guesses..)
 
pe1chl
Forum Guru
Forum Guru
Posts: 10650
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.19rc [testing] is released!

Thu May 15, 2025 10:54 am

It would have been useful when it was VTI.
 
User avatar
bajodel
Long time Member
Long time Member
Posts: 553
Joined: Sun Nov 24, 2013 8:30 am
Location: Italy

Re: v7.19rc [testing] is released!

Thu May 15, 2025 12:51 pm

Yep, VTI would be quite welcome.
Still I don't understand why it has not been a priority at any time, almost all the competitor have it.
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1697
Joined: Thu Nov 12, 2020 12:07 pm

Re: v7.19rc [testing] is released!

Thu May 15, 2025 12:58 pm

I'm eagerly awaiting a stable release.
 
itimo01
Member Candidate
Member Candidate
Posts: 278
Joined: Thu Jun 29, 2023 2:55 am
Location: Germany
Contact:

Re: v7.19rc [testing] is released!

Thu May 15, 2025 3:03 pm

I'm eagerly awaiting a stable release.
I got the Info that there will be an rc3
 
dav26
just joined
Posts: 2
Joined: Wed May 03, 2023 5:19 pm

Re: v7.19rc [testing] is released!

Thu May 15, 2025 6:34 pm

Hi everyone,

[admin@MK2] > ip service/set ipsec vrf=public
failure: this is configured elsewhere

I need to set ipsec to work with another vrf different from main. How can I do that?
I'm just testing on the 7.19rc2 and hope to fix that issue in the stable release.

Mikrotik Admins do you think you can add that feature on the stable release?
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7212
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: v7.19rc [testing] is released!

Thu May 15, 2025 11:16 pm

You can't ipsec can work only in "main".
 
millenium7
Long time Member
Long time Member
Posts: 618
Joined: Wed Mar 16, 2016 6:12 am

Re: v7.19rc [testing] is released!

Fri May 16, 2025 1:13 am

This page need username and password to see.
Wayback machine managed to grab it

I'm hopeful, but also HIGHLY skeptical. Would not be surprised if MikroTik gets some initial buggy cli-only barely working release out to appease the 10+ years of people asking for it, then essentially abandons it because "well no ones using it so why bother developing it further" like they're done with IS-IS

Still no mention of Segment Routing which I would get far more value out of it, but hey, it's something.... maybe........
 
User avatar
loloski
Member
Member
Posts: 480
Joined: Mon Mar 15, 2021 9:10 pm
Location: Philippines

Re: v7.19rc [testing] is released!

Fri May 16, 2025 5:03 am

I'm one of the hopeful on this EVPN stuff I hope one day we can build spine and leaf architecture for DC at cheaper cost, this will bring a lot of value to MT if it was done right at the first time I sincerely hope this time that they will implement this as complete and robust solution, not like with the state affair we have on v7 MPLS
 
merkkg
newbie
Posts: 32
Joined: Thu Jan 19, 2017 11:50 am

Re: v7.19rc [testing] is released!

Fri May 16, 2025 9:02 am

Section for EVPN was added to help document yesterday.

https://help.mikrotik.com/docs/pages/di ... ersions=77
 
bratislav
Frequent Visitor
Frequent Visitor
Posts: 69
Joined: Mon May 05, 2014 10:36 am

Re: v7.19rc [testing] is released!

Fri May 16, 2025 11:08 am

I need to set ipsec to work with another vrf different from main. How can I do that?
You can use a tunnel for example ipip over ipsec and than assign that ipip interface to another vrf...
 
User avatar
clambert
Member Candidate
Member Candidate
Posts: 163
Joined: Wed Jun 12, 2019 5:04 am

Re: v7.19rc [testing] is released!

Fri May 16, 2025 11:38 am

I hope they implement MPLS data plane for EVPN.