Community discussions

 
User avatar
emils
MikroTik Support
MikroTik Support
Topic Author
Posts: 463
Joined: Thu Dec 11, 2014 8:53 am

v6.44.3 [stable] is released!

Wed Apr 24, 2019 10:07 am

RouterOS version 6.44.3 has been released in public "stable" channel!

Before an upgrade:
1) Remember to make backup/export files before an upgrade and save them on another storage device;
2) Make sure the device will not lose power during upgrade process;
3) Device has enough free storage space for all RouterOS packages to be downloaded.

What's new in 6.44.3 (2019-Apr-23 12:37):

Changes in this release:

*) certificate - fixed SAN being duplicated on status change (introduced in v6.44);
*) conntrack - fixed "loose-tcp-tracking" parameter not taken in action (introduced in v6.44);
*) dhcpv4-server - fixed commenting option for alerts;
*) dhcpv6-server - fixed binding setting update from RADIUS;
*) ike1 - improved stability for transport mode policies on initiator side;
*) ipsec - fixed freshly created identity not taken in action (introduced in v6.44);
*) ipsec - fixed possible configuration corruption after import (introduced in v6.44);
*) ipv6 - adjusted IPv6 route cache max size;
*) ipv6 - improved IPv6 neighbor table updating process;
*) lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
*) rb2011 - removed "sfp-led" from "System/LEDs" menu;
*) smb - fixed possible buffer overflow;
*) snmp - added "radio-name" (mtxrWlRtabRadioName) OID support;
*) ssh - added "both", "local" and "remote" options for "forwarding-enabled" parameter;
*) ssh - do not generate host key on configuration export;
*) ssh - fixed multiline non-interactive command execution;
*) switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
*) userman - updated authorize.net gateway DNS name;
*) wireless - added support for US FCC UNII-2 and Canada country profiles for LHG-5HPnD-US, RBLHG-5HPnD-XL-US and SXTsq5HPnD-US devices;
*) wireless - improved wireless country settings for EU countries;

To upgrade, click "Check for updates" at /system package in your RouterOS configuration interface, or head to our download page: http://www.mikrotik.com/download

If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while router is not working as suspected or after some problem has appeared on device

Please keep this forum topic strictly related to this particular RouterOS release.
 
pe1chl
Forum Guru
Forum Guru
Posts: 5559
Joined: Mon Jun 08, 2015 12:09 pm

Re: v6.44.3 [stable] is released!

Wed Apr 24, 2019 12:40 pm

*) conntrack - fixed "loose-tcp-tracking" parameter not taken in action (introduced in v6.44);
Yes, it looks like it is working again!
 
User avatar
eworm
Member
Member
Posts: 358
Joined: Wed Oct 22, 2014 9:23 am
Location: Oberhausen, Germany
Contact:

Re: v6.44.3 [stable] is released!

Wed Apr 24, 2019 12:44 pm

I had hoped for this:
*) lte - fixed session reactivation on R11e-LTE in UMTS mode;
Will we see it in another stable update?

Other than that everything looks good, already updated ~ 30 devices of different type.
Manage RouterOS scripts and extend your devices' functionality: RouterOS Scripts
 
ofer
newbie
Posts: 48
Joined: Wed May 23, 2018 11:45 am

Re: v6.44.3 [stable] is released!

Wed Apr 24, 2019 1:56 pm

Upgraded 3xHAP AC 6.44.1, 6.44.2 -> 6.44.3 - no issues.

Thank you!
 
cipriancraciun
just joined
Posts: 3
Joined: Thu Feb 22, 2018 9:15 pm

Re: v6.44.3 [stable] is released!

Wed Apr 24, 2019 4:43 pm

I have just upgraded an hAP AC 2 `RBD52G-5HacD2HnD` from `6.44.2` to `6.44.3` and for some reason my iPhone 5s doesn't seem to "detect" the 5GHz wireless network which worked just fine before upgrading.

My configuration regarding wireless is:
/interface wireless
set [ find default-name=wlan1 ] antenna-gain=3 band=2ghz-g/n channel-width=20/40mhz-XX country=romania disabled=no disconnect-timeout=15s distance=\
    indoors frequency=auto frequency-mode=regulatory-domain guard-interval=long hw-protection-mode=rts-cts hw-retries=15 mode=ap-bridge \
    preamble-mode=long security-profile=XXXX ssid=XXXX/2 wireless-protocol=802.11 wps-mode=disabled
add disabled=no mac-address=XXX master-interface=wlan1 name=wlan1/XXYY security-profile=XXYY ssid=\
    XXYY/2 wps-mode=disabled
add disabled=no mac-address=XXXX master-interface=wlan1 name=wlan1/XXZZ security-profile=XXZZ ssid=\
    XXZZ/2 wps-mode=disabled
set [ find default-name=wlan2 ] antenna-gain=3 band=5ghz-n/ac channel-width=20/40/80mhz-XXXX country=romania disabled=no disconnect-timeout=15s \
    distance=indoors frequency=auto frequency-mode=regulatory-domain guard-interval=long hw-protection-mode=rts-cts hw-retries=15 mode=ap-bridge \
    preamble-mode=long security-profile=XXXX ssid=XXXX/5 wireless-protocol=802.11 wmm-support=required wps-mode=disabled
add disabled=no mac-address=XXXX master-interface=wlan2 name=wlan2/XXYY security-profile=XXYY ssid=\
    XXYY/5 wmm-support=required wps-mode=disabled
add disabled=no mac-address=XXXX master-interface=wlan2 name=wlan2/XXZZ security-profile=XXZZ ssid=\
    XXZZ/5 wmm-support=required wps-mode=disabled
Of special interest is `wmm-support=required` which some time ago I've determined to be the only setting that combined with `channel-width=20/40/80mhz-XXXX` allows it to work with iPhone 5s and other smart phones.

Thanks,
Ciprian.
 
User avatar
strods
MikroTik Support
MikroTik Support
Posts: 1406
Joined: Wed Jul 16, 2014 7:22 am
Location: Riga, Latvia

Re: v6.44.3 [stable] is released!

Wed Apr 24, 2019 5:15 pm

cipriancraciun - What is the status on your 5 GHz AP? Sounds like it might be detecting radar and you simply need to wait for a few minutes.
 
cipriancraciun
just joined
Posts: 3
Joined: Thu Feb 22, 2018 9:15 pm

Re: v6.44.3 [stable] is released!

Wed Apr 24, 2019 5:28 pm

cipriancraciun - What is the status on your 5 GHz AP? Sounds like it might be detecting radar and you simply need to wait for a few minutes.
Indeed it seems that "waiting for a few minutes" did the trick... Although before reporting this issue I "waited" for about half an hour...

Anyway, perhaps it was an iOS / iPhone fluke... Sorry for the false alarm. :)

----

What do you mean by "status on your AP"? Inside the WLAN interface view, under the `Status` section I only have values for the following properties:
# for the "main" WLAN interface
Channel		5620/20-eeCe/ac/DP(24dBm)
Overall Tx CCQ		83 %
Noise Floor		-105 dBm
# for the "alias" WLAN interface
Last Link Down Time		Apr/24/2019 16:28:11
Last Link Up Time		Apr/24/2019 16:46:18
Link Downs		5
Registered Clients		3
Authenticated Clients		3
 
eddieb
Member Candidate
Member Candidate
Posts: 130
Joined: Thu Aug 28, 2014 10:53 am
Location: Netherlands

Re: v6.44.3 [stable] is released!

Wed Apr 24, 2019 5:34 pm

updating to 6.44.3 went smooth ... from 6.44.2 to 6.44.3 with some help from the dude ;-)
No problems so far
Running 6.45.3 (stable) on :
CCR1009-8G-1S (2x ipsec/l2tp site-to-site, ipsec/l2tp roadwarrior, dhcpd, dns), CRS125-24G-1S, RB1100, RB962UiGS-5HacT2HnT (10pc), RB931-2nD, RB951, RB750GL ,RB2011UAS-RM, CHR running dude (CHR running in VirtualBox on OSX)
 
pe1chl
Forum Guru
Forum Guru
Posts: 5559
Joined: Mon Jun 08, 2015 12:09 pm

Re: v6.44.3 [stable] is released!

Wed Apr 24, 2019 7:03 pm

Indeed it seems that "waiting for a few minutes" did the trick... Although before reporting this issue I "waited" for about half an hour...
The waiting times for DFS channels vary by channel and country, and it appears that sometimes manufacturers (who are in discussion with authorities)
implement the longest wait times when the situation is not completely clear (e.g. local authorities and EU have different requirements).

When you want troublefree operation in the presence of radar and DFS, 5620 is about the worst frequency you can select...
(maybe you selected it because it was the most quiet channel in terms of number of other APs and traffic from others, then now you know why that is!!)
 
User avatar
strods
MikroTik Support
MikroTik Support
Posts: 1406
Joined: Wed Jul 16, 2014 7:22 am
Location: Riga, Latvia

Re: v6.44.3 [stable] is released!

Wed Apr 24, 2019 10:16 pm

cipriancraciun - You would be able to see this under wireless monitor command ("/interface wireless monitor wlan2 once" would return "status: radar-detecting"), on CAPsMAN CAP interface if you use CAPsMAN (":put [/caps-man interface get 5GHz-guest current-state] would return "detecting-radar") and on wireless debug logs ("wireless,debug wlan2: search for radars on 5260000").
 
TimurA
Member Candidate
Member Candidate
Posts: 144
Joined: Sat Dec 15, 2018 6:13 am
Location: Tashkent
Contact:

Re: v6.44.3 [stable] is released!

Wed Apr 24, 2019 11:38 pm

I have just upgraded an hAP AC 2 `RBD52G-5HacD2HnD` from `6.44.2` to `6.44.3` and for some reason my iPhone 5s doesn't seem to "detect" the 5GHz wireless network which worked just fine before upgrading.

My configuration regarding wireless is:
/interface wireless
set [ find default-name=wlan1 ] antenna-gain=3 band=2ghz-g/n channel-width=20/40mhz-XX country=romania disabled=no disconnect-timeout=15s distance=\
    indoors frequency=auto frequency-mode=regulatory-domain guard-interval=long hw-protection-mode=rts-cts hw-retries=15 mode=ap-bridge \
    preamble-mode=long security-profile=XXXX ssid=XXXX/2 wireless-protocol=802.11 wps-mode=disabled
add disabled=no mac-address=XXX master-interface=wlan1 name=wlan1/XXYY security-profile=XXYY ssid=\
    XXYY/2 wps-mode=disabled
add disabled=no mac-address=XXXX master-interface=wlan1 name=wlan1/XXZZ security-profile=XXZZ ssid=\
    XXZZ/2 wps-mode=disabled
set [ find default-name=wlan2 ] antenna-gain=3 band=5ghz-n/ac channel-width=20/40/80mhz-XXXX country=romania disabled=no disconnect-timeout=15s \
    distance=indoors frequency=auto frequency-mode=regulatory-domain guard-interval=long hw-protection-mode=rts-cts hw-retries=15 mode=ap-bridge \
    preamble-mode=long security-profile=XXXX ssid=XXXX/5 wireless-protocol=802.11 wmm-support=required wps-mode=disabled
add disabled=no mac-address=XXXX master-interface=wlan2 name=wlan2/XXYY security-profile=XXYY ssid=\
    XXYY/5 wmm-support=required wps-mode=disabled
add disabled=no mac-address=XXXX master-interface=wlan2 name=wlan2/XXZZ security-profile=XXZZ ssid=\
    XXZZ/5 wmm-support=required wps-mode=disabled
Of special interest is `wmm-support=required` which some time ago I've determined to be the only setting that combined with `channel-width=20/40/80mhz-XXXX` allows it to work with iPhone 5s and other smart phones.

Thanks,
Ciprian.
Hello

do not set frequency=auto, use my example.

set
1. frequency=5180, disconnect-timeout=00:00:03, guard-interval=any, hw-retries=5(or max 7), channel-width=20/40/80mhz-Ceee, band=5ghz-a/n/ac

or

2. frequency=5200, disconnect-timeout=00:00:03, guard-interval=any, hw-retries=5(or max 7), channel-width=20/40/80mhz-eCee, band=5ghz-a/n/ac

or

3. frequency=5220, disconnect-timeout=00:00:03, guard-interval=any, hw-retries=5(or max 7), channel-width=20/40/80mhz-eeCe, band=5ghz-a/n/ac

or

4.frequency=5240, disconnect-timeout=00:00:03, guard-interval=any, hw-retries=5(or max 7), channel-width=20/40/80mhz-eeeC, band=5ghz-a/n/ac

Good luck Ciprian.!

Hello Strods, by the way - what about RB4011 duplicate mac address on sfpplus and wlan1? and wlan1 disabling itself.

Can you honestly say when solve this problem? or we will not solve it.
Image
 
User avatar
typicalwisp
just joined
Posts: 10
Joined: Fri Jan 05, 2018 8:45 pm

Re: v6.44.3 [stable] is released!

Thu Apr 25, 2019 7:00 am

I just updated some test devices to 6.44.3 from 6.44.1. SSH port forwarding was working fine before the upgrade, but did not work after.

It looks like the default setting for "/ip ssh forwarding-enabled" has been changed from "both" to "remote". To fix this:

Code: Select all

/ip ssh set forwarding-enabled=both

While you are there, this seems like a good idea:

Code: Select all

/ip ssh set strong-crypto=yes allow-none-crypto=no
 
mkx
Forum Guru
Forum Guru
Posts: 2603
Joined: Thu Mar 03, 2016 10:23 pm

Re: v6.44.3 [stable] is released!

Thu Apr 25, 2019 4:55 pm

I just updated some test devices to 6.44.3 from 6.44.1. SSH port forwarding was working fine before the upgrade, but did not work after.

It looks like the default setting for "/ip ssh forwarding-enabled" has been changed from "both" to "remote". To fix this:

Code: Select all

/ip ssh set forwarding-enabled=both
It seems that the list of possible values has changed ... on my 6.44.2 it's like this:

Code: Select all

/ip ssh set forwarding-enabled=?

ForwardingEnabled ::= yes | no
BR,
Metod
 
User avatar
krisjanisj
MikroTik Support
MikroTik Support
Posts: 33
Joined: Wed Feb 20, 2019 2:53 pm
Contact:

Re: v6.44.3 [stable] is released!

Thu Apr 25, 2019 4:57 pm

It seems that the list of possible values has changed ... on my 6.44.2 it's like this:

Code: Select all

/ip ssh set forwarding-enabled=?

ForwardingEnabled ::= yes | no
From 6.44.3 changelog:
*) ssh - added "both", "local" and "remote" options for "forwarding-enabled" parameter;
 
mkx
Forum Guru
Forum Guru
Posts: 2603
Joined: Thu Mar 03, 2016 10:23 pm

Re: v6.44.3 [stable] is released!

Thu Apr 25, 2019 5:04 pm

From 6.44.3 changelog:
*) ssh - added "both", "local" and "remote" options for "forwarding-enabled" parameter;
On behalf of @typicalwisp: when upgrading ROS 6.44.2 setting of forwarding-enabled=yes to ROS 6.44.3 ... which value does this setting get? remote?
BR,
Metod
 
User avatar
willianwrm
just joined
Posts: 5
Joined: Mon Jun 06, 2016 8:54 pm
Location: -21.2330138,-44.9962488
Contact:

Re: v6.44.3 [stable] is released!

Thu Apr 25, 2019 8:51 pm

Update not working with 952Ui-5ac2nD; downloads file to memory but doesn't apply after reboot
Current version is 6.44.1 with packages:
- advanced-tools
- dhcp
- ntp
- ppp
- routing
- security
- system
- wireless

The log is empty, nothing reported there. Any ideas?

PS: system backup is now broken (gets error message and an empty file).
 
pe1chl
Forum Guru
Forum Guru
Posts: 5559
Joined: Mon Jun 08, 2015 12:09 pm

Re: v6.44.3 [stable] is released!

Thu Apr 25, 2019 9:00 pm

sounds like your storage is full. clean it out.
if not, the filesystem is corrupted and you need to do a netinstall.
first connect using telnet/ssh and do a /export and cut it from the screen into a file.
 
User avatar
willianwrm
just joined
Posts: 5
Joined: Mon Jun 06, 2016 8:54 pm
Location: -21.2330138,-44.9962488
Contact:

Re: v6.44.3 [stable] is released!

Thu Apr 25, 2019 9:16 pm

sounds like your storage is full. clean it out.
if not, the filesystem is corrupted and you need to do a netinstall.
first connect using telnet/ssh and do a /export and cut it from the screen into a file.
Thanks, I'll do it later :)
 
xbar7networks
just joined
Posts: 4
Joined: Sun Feb 18, 2018 4:47 pm

Re: v6.44.3 [stable] is released!

Fri Apr 26, 2019 1:15 am

Since Tue 4/22, we have a main / core router which crashes regularly at 6-7 hour intervals.

We have upgraded to the latest firmware and OS and replaced the device w/ a new / out of the box model, this is not fixing the problem.

I suspect some sort of DOS attack whether intentional or unintended. I have seen posts in MT Forums regarding IPV6 memory exhaustion issues which I think would be similar to what we are seeing.

I am monitoring the router for used memory via SNMP as of today. Unfortunately it was not properly monitored before today so I don’t have historical info on the memory utilization to relate to the timing of the crashes.

The basic info regarding the device is as follows:


[user@routername] /system resource<SAFE> print
uptime: 2h29m52s
version: 6.44.3 (stable)
build-time: Apr/23/2019 12:37:03
factory-software: 6.38.5
free-memory: 1740.4MiB
total-memory: 1984.0MiB
cpu: tilegx
cpu-count: 9
cpu-frequency: 1000MHz
cpu-load: 2%
free-hdd-space: 82.4MiB
total-hdd-space: 128.0MiB
architecture-name: tile
board-name: CCR1009-7G-1C-1S+
platform: MikroTik



Each time the router crashes the only log messages recorded are like these:

05:04:18 system,error,critical router rebooted without proper shutdown, probably power outage
05:04:24 interface,info sfpp-vlan3 link up
05:04:24 interface,info sfpp-vlan524 link up
05:04:24 interface,info sfpp-vlan532 link up
05:04:24 interface,info sfpp-vlan540 link up
05:04:24 bridge,info "192-168-3-0-24" mac address changed to 64:D1:54:E9:67:95
05:04:24 bridge,info "192-168-5-40-29" mac address changed to 64:D1:54:E9:67:99
05:04:24 bridge,info "192-168-5-24-29" mac address changed to 64:D1:54:E9:67:93
05:04:24 bridge,info "192-168-5-32-29" mac address changed to 64:D1:54:E9:67:93
05:04:25 interface,info sfp-sfpplus1 link up (speed 1G, full duplex)
05:04:26 interface,info ether2 link up (speed 100M, full duplex)
05:04:30 interface,info combo1 link up (speed 100M, full duplex)
05:04:38 interface,info ether3 link up (speed 100M, full duplex)
11:36:26 system,info sntp change time Apr/25/2019 05:05:22 => Apr/25/2019 11:36:26


Watchdog reset is enabled w/ option to send the support file. Email is configured and verified as working by sending email from /tool e-mail send.


[user@routername] /system watchdog<SAFE> print
watch-address: A.B.C.D (replaced to remove sensitive info)
watchdog-timer: yes
no-ping-delay: 30m
ping-timeout: 3m
automatic-supout: yes
auto-send-supout: yes


The watchdog process does not appear to be activated in each crash.

I should have mentioned that the device is dual powered (poe and direct dc via the barrel connector via different feeds). We have double checked power on both sources several times. The original source for both is a DC system which powers the entire tower and cabinet at the base of roughly 20 devices. No other devices exhibit any loss of power or other symptoms when the router reboots.

This is causing a tremendous amount of disruption to our customers. Can you help?
 
BRMateus2
Frequent Visitor
Frequent Visitor
Posts: 70
Joined: Thu Oct 26, 2017 11:18 pm

Re: v6.44.3 [stable] is released!

Fri Apr 26, 2019 4:21 am

@xbar7networks
You might want to send supout to MikroTik support, as this kind of debugging might be out of the scope.

You sure the voltage is ok?
 
xbar7networks
just joined
Posts: 4
Joined: Sun Feb 18, 2018 4:47 pm

Re: v6.44.3 [stable] is released!

Fri Apr 26, 2019 7:48 am

@xbar7networks
You might want to send supout to MikroTik support, as this kind of debugging might be out of the scope.

You sure the voltage is ok?
Well assuming the power isn't failing. As I mentioned the DC system power is stable because there are 19 other devices which would fail if system power failed. System voltage and routerboard voltage are monitored w/ snmp. They are always between 24.5 and 28. It is of course possible that the power to the router is failing while the system power is stable but that seems pretty unlikely since there are 2 independent feeds from the man power buss and we have tested both independently. What is the probability that the wire or buss connectors would fail in two spots simultaneous and only for a few min, every 6-7 hours? Seems hard to believe.

Regarding the supout file, yes I will send it to MT support but if I read their docs right, they said they want the file which is generated when the device crashes. Probably I'm missing something but the only way I know how to do that is w/ the system watchdog process and so far the watchdog process has not been invoked in all of the crashes.
 
IvanChisca
just joined
Posts: 3
Joined: Wed Oct 25, 2017 9:47 am
Location: Moldova, Chisinau

Re: v6.44.3 [stable] is released!

Fri Apr 26, 2019 10:09 am

Hi, tonight I gave myself a wonderful time of debugging and reverse engineering :) Just because I didn't make backup before software update.
My RB1100AHx2 (powerpc) after update lost all it's IPsec configuration and that was just beginning. It is not a problem to restore a few tens of IPsec policies, but it gives me an error:

could not add IPsec policy: std failure: timeout (13)

Successfully I found a few month old backup and restored my router and then spent two hours adding changes. So what I want to say :) 1.Do backup your router before update. 2. Mikrotik guys, please check that version for this error. I downgraded to 6.44.2, it seems to be STABLE. :) Thank you all and have a nice day.
 
User avatar
krisjanisj
MikroTik Support
MikroTik Support
Posts: 33
Joined: Wed Feb 20, 2019 2:53 pm
Contact:

Re: v6.44.3 [stable] is released!

Fri Apr 26, 2019 10:17 am

From 6.44.3 changelog:
*) ssh - added "both", "local" and "remote" options for "forwarding-enabled" parameter;
On behalf of @typicalwisp: when upgrading ROS 6.44.2 setting of forwarding-enabled=yes to ROS 6.44.3 ... which value does this setting get? remote?
As mentioned in wiki the default value for it is "no". If before upgrade "forwarding-enabled=no", after upgrade it will be "forwarding-enabled=remote", if before upgrade "forwarding-enabled=yes", after upgrade it will be "forwarding-enabled=both".
Last edited by krisjanisj on Fri Apr 26, 2019 10:51 am, edited 1 time in total.
 
dvm
just joined
Posts: 12
Joined: Thu Feb 01, 2018 9:54 am

Re: v6.44.3 [stable] is released!

Fri Apr 26, 2019 10:48 am

As mentioned in wiki the default value for it now is "remote".
Default values should not be displayed in /export compact, but "remote" value does.
 
User avatar
krisjanisj
MikroTik Support
MikroTik Support
Posts: 33
Joined: Wed Feb 20, 2019 2:53 pm
Contact:

Re: v6.44.3 [stable] is released!

Fri Apr 26, 2019 10:52 am

Default values should not be displayed in /export compact, but "remote" value does.
There was a mistake in wiki, edited my previous post to clear it. Since default value is "no" - any other value (both, remote, local) should appear in "/export".
 
TimurA
Member Candidate
Member Candidate
Posts: 144
Joined: Sat Dec 15, 2018 6:13 am
Location: Tashkent
Contact:

Re: v6.44.3 [stable] is released!

Fri Apr 26, 2019 4:47 pm

RB4011, if I turn on the RSTP, the switch chip stops working.
Image
 
User avatar
krisjanisj
MikroTik Support
MikroTik Support
Posts: 33
Joined: Wed Feb 20, 2019 2:53 pm
Contact:

Re: v6.44.3 [stable] is released!

Fri Apr 26, 2019 4:58 pm

RB4011, if I turn on the RSTP, the switch chip stops working.
By switch chip You mean hardware offload?
Hardware offload for switch chip that RB4011 uses (RTL8367), while STP/RSTP is enabled, is not supported. use "protocol-mode=none" on bridge for offloading to work again. See this wiki page for more info.
 
TimurA
Member Candidate
Member Candidate
Posts: 144
Joined: Sat Dec 15, 2018 6:13 am
Location: Tashkent
Contact:

Re: v6.44.3 [stable] is released!

Fri Apr 26, 2019 5:07 pm

RB4011, if I turn on the RSTP, the switch chip stops working.
By switch chip You mean hardware offload?
Hardware offload for switch chip that RB4011 uses (RTL8367), while STP/RSTP is enabled, is not supported. use "protocol-mode=none" on bridge for offloading to work again. See this wiki page for more info.
thanks a lot.
Image
 
MichalPospichal
just joined
Posts: 9
Joined: Sun Feb 04, 2018 11:27 pm
Location: Czech Republic

Re: v6.44.3 [stable] is released!

Fri Apr 26, 2019 7:15 pm


.... and wlan1 disabling itself.

Can you honestly say when solve this problem? or we will not solve it.
I have been running RB4011 for more than a month and never had this reported issue on wlan. Not even when there was no client connected to it for a few days. So it seems it is not happening on all units.
 
User avatar
pcunite
Forum Veteran
Forum Veteran
Posts: 945
Joined: Sat May 25, 2013 5:13 am
Location: USA

Re: v6.44.3 [stable] is released!

Fri Apr 26, 2019 8:49 pm

I have been running RB4011 for more than a month and never had this reported issue on wlan. Not even when there was no client connected to it for a few days. So it seems it is not happening on all units.

Can you export your config (between code tags) for this thread to see what you might be doing differently?
 
pavlov
just joined
Posts: 2
Joined: Mon Dec 31, 2018 3:32 pm

Re: v6.44.3 [stable] is released!

Sat Apr 27, 2019 2:32 am

I have just upgraded an hAP AC 2 `RBD52G-5HacD2HnD` from `6.44.2` to `6.44.3` and for some reason my iPhone 5s doesn't seem to "detect" the 5GHz wireless network which worked just fine before upgrading.

My configuration regarding wireless is:
/interface wireless
set [ find default-name=wlan1 ] antenna-gain=3 band=2ghz-g/n channel-width=20/40mhz-XX country=romania disabled=no disconnect-timeout=15s distance=\
    indoors frequency=auto frequency-mode=regulatory-domain guard-interval=long hw-protection-mode=rts-cts hw-retries=15 mode=ap-bridge \
    preamble-mode=long security-profile=XXXX ssid=XXXX/2 wireless-protocol=802.11 wps-mode=disabled
add disabled=no mac-address=XXX master-interface=wlan1 name=wlan1/XXYY security-profile=XXYY ssid=\
    XXYY/2 wps-mode=disabled
add disabled=no mac-address=XXXX master-interface=wlan1 name=wlan1/XXZZ security-profile=XXZZ ssid=\
    XXZZ/2 wps-mode=disabled
set [ find default-name=wlan2 ] antenna-gain=3 band=5ghz-n/ac channel-width=20/40/80mhz-XXXX country=romania disabled=no disconnect-timeout=15s \
    distance=indoors frequency=auto frequency-mode=regulatory-domain guard-interval=long hw-protection-mode=rts-cts hw-retries=15 mode=ap-bridge \
    preamble-mode=long security-profile=XXXX ssid=XXXX/5 wireless-protocol=802.11 wmm-support=required wps-mode=disabled
add disabled=no mac-address=XXXX master-interface=wlan2 name=wlan2/XXYY security-profile=XXYY ssid=\
    XXYY/5 wmm-support=required wps-mode=disabled
add disabled=no mac-address=XXXX master-interface=wlan2 name=wlan2/XXZZ security-profile=XXZZ ssid=\
    XXZZ/5 wmm-support=required wps-mode=disabled
Of special interest is `wmm-support=required` which some time ago I've determined to be the only setting that combined with `channel-width=20/40/80mhz-XXXX` allows it to work with iPhone 5s and other smart phones.

Thanks,
Ciprian.
i have the same problem with hap ac and iphone x in 5ghz
 
TimurA
Member Candidate
Member Candidate
Posts: 144
Joined: Sat Dec 15, 2018 6:13 am
Location: Tashkent
Contact:

Re: v6.44.3 [stable] is released!

Sat Apr 27, 2019 6:03 am

i have the same problem with hap ac and iphone x in 5ghz
Hi pavlov,

channel frequency set auto? set the initial range, starting frequency at 5180
Image
 
TimurA
Member Candidate
Member Candidate
Posts: 144
Joined: Sat Dec 15, 2018 6:13 am
Location: Tashkent
Contact:

Re: v6.44.3 [stable] is released!

Sat Apr 27, 2019 6:11 am


.... and wlan1 disabling itself.

Can you honestly say when solve this problem? or we will not solve it.
I have been running RB4011 for more than a month and never had this reported issue on wlan. Not even when there was no client connected to it for a few days. So it seems it is not happening on all units.
And you start connecting to wlan1 Macbook pro 2016-2018, iPad pro 2018, MSI LeopardPro, and try to work constantly on wlan1, load it with traffic, transfer clients from it to another point and back. He starts losing packets and turns off. If the support keeps silence, after so many sent debugs, there is a reason to think.
PS
Here there is a device RB962(hAp AC) - it works perfectly on it 5G. RB4011 - some problems.
Image
 
pe1chl
Forum Guru
Forum Guru
Posts: 5559
Joined: Mon Jun 08, 2015 12:09 pm

Re: v6.44.3 [stable] is released!

Sat Apr 27, 2019 11:08 am

Those Apple devices are partly guilty, I think. There have been reports before that some Apple devices cause spurious radar detection, and the AP changes to another
channel and listens for a while before it gets on air again. When the same device is still present, the same problem may re-occur. And in case of some software
bug it may even be the cause of the permanent shutdown.

It does not affect only MikroTik! At work we have Ubiquiti accesspoints and sometimes the same thing happens (radar detect on a channel where there definitely is ni radar
but where a couple of Apple devices are nearby).
But those accesspoints do not change to a random other channel, they always change to a channel in the range 36-48 where radar detection is not required, and stay there
for the remainder of the day. During the night they change back to their configured channel and the same thing may happen the next day when the users come in.
(never during night or weekends! confirming that it indeed is a problem caused by the client devices)

Now, to solve this is kind of tricky. The regulating authorities put pressure on the manufacturers to make their radar detection work well, and in the past years there
were many incidents where new firmware from several different manufacturers caused new problems in this area. Not only with MikroTik!
 
TimurA
Member Candidate
Member Candidate
Posts: 144
Joined: Sat Dec 15, 2018 6:13 am
Location: Tashkent
Contact:

Re: v6.44.3 [stable] is released!

Sat Apr 27, 2019 1:08 pm

Those Apple devices are partly guilty, I think. There have been reports before that some Apple devices cause spurious radar detection, and the AP changes to another
channel and listens for a while before it gets on air again. When the same device is still present, the same problem may re-occur. And in case of some software
bug it may even be the cause of the permanent shutdown.

It does not affect only MikroTik! At work we have Ubiquiti accesspoints and sometimes the same thing happens (radar detect on a channel where there definitely is ni radar
but where a couple of Apple devices are nearby).
But those accesspoints do not change to a random other channel, they always change to a channel in the range 36-48 where radar detection is not required, and stay there
for the remainder of the day. During the night they change back to their configured channel and the same thing may happen the next day when the users come in.
(never during night or weekends! confirming that it indeed is a problem caused by the client devices)

Now, to solve this is kind of tricky. The regulating authorities put pressure on the manufacturers to make their radar detection work well, and in the past years there
were many incidents where new firmware from several different manufacturers caused new problems in this area. Not only with MikroTik!
In my case, RB962 with the same firmware version is working, RB4011 is buggy for the crap. RB4011 falls on channels 36-48, in general, the radar is not being. In the same situation, RB962 works. Let's go without these epuses about radar.
Image
 
MichalPospichal
just joined
Posts: 9
Joined: Sun Feb 04, 2018 11:27 pm
Location: Czech Republic

Re: v6.44.3 [stable] is released!

Sat Apr 27, 2019 9:25 pm

I have been running RB4011 for more than a month and never had this reported issue on wlan. Not even when there was no client connected to it for a few days. So it seems it is not happening on all units.

Can you export your config (between code tags) for this thread to see what you might be doing differently?
Here is the Wireless config I use:
/interface wireless
set [ find default-name=wlan2 ] antenna-gain=3 band=2ghz-onlyn bridge-mode=disabled channel-width=20/40mhz-eC country="czech republic" default-authentication=no disabled=no distance=indoors frequency=2472 frequency-mode=regulatory-domain installation=indoor \
    keepalive-frames=disabled max-station-count=50 mode=ap-bridge multicast-buffering=disabled multicast-helper=disabled name=WLAN-2.4GHz security-profile= ssid=2.4G wireless-protocol=802.11 wmm-support=enabled wps-mode=\
    disabled
set [ find default-name=wlan1 ] antenna-gain=3 band=5ghz-n/ac bridge-mode=disabled channel-width=20/40/80mhz-eeCe country="czech republic" default-authentication=no disabled=no distance=indoors frequency=5220 frequency-mode=regulatory-domain installation=indoor \
    keepalive-frames=disabled max-station-count=50 mode=ap-bridge multicast-buffering=disabled multicast-helper=disabled name=WLAN-5GHz secondary-channel=auto security-profile= ssid=5G wireless-protocol=802.11 wmm-support=enabled \
    wps-mode=disabled
add default-forwarding=no keepalive-frames=disabled mac-address= master-interface=5GHz max-station-count=10 multicast-buffering=disabled multicast-helper=disabled name= security-profile= ssid=\
    Guest wds-cost-range=0 wds-default-cost=0 wmm-support=enabled wps-mode=disabled
Both WLANs are bridged with some ether ports in bridge-LAN.

I do not own Apple devices, but my parents and brother do own iPhones and they come and are connected regularly with no issues. No Macbooks or iPads though.
I was really afraid it would misbehave when I was considering upgrade from RB2011 and saw these reports about WiFi issues, but RB4011 is working flawlessly for me so far.
 
User avatar
gyropilot
newbie
Posts: 47
Joined: Sat Sep 10, 2016 10:49 pm
Location: Seaview, WA

Re: v6.44.3 [stable] is released!

Sat Apr 27, 2019 11:48 pm

Update not working with 952Ui-5ac2nD; downloads file to memory but doesn't apply after reboot

Willian,

Curious if you've fixed this?

John
 
TimurA
Member Candidate
Member Candidate
Posts: 144
Joined: Sat Dec 15, 2018 6:13 am
Location: Tashkent
Contact:

Re: v6.44.3 [stable] is released!

Sun Apr 28, 2019 7:31 am

I have been running RB4011 for more than a month and never had this reported issue on wlan. Not even when there was no client connected to it for a few days. So it seems it is not happening on all units.

Can you export your config (between code tags) for this thread to see what you might be doing differently?
Here is the Wireless config I use:
/interface wireless
set [ find default-name=wlan2 ] antenna-gain=3 band=2ghz-onlyn bridge-mode=disabled channel-width=20/40mhz-eC country="czech republic" default-authentication=no disabled=no distance=indoors frequency=2472 frequency-mode=regulatory-domain installation=indoor \
    keepalive-frames=disabled max-station-count=50 mode=ap-bridge multicast-buffering=disabled multicast-helper=disabled name=WLAN-2.4GHz security-profile= ssid=2.4G wireless-protocol=802.11 wmm-support=enabled wps-mode=\
    disabled
set [ find default-name=wlan1 ] antenna-gain=3 band=5ghz-n/ac bridge-mode=disabled channel-width=20/40/80mhz-eeCe country="czech republic" default-authentication=no disabled=no distance=indoors frequency=5220 frequency-mode=regulatory-domain installation=indoor \
    keepalive-frames=disabled max-station-count=50 mode=ap-bridge multicast-buffering=disabled multicast-helper=disabled name=WLAN-5GHz secondary-channel=auto security-profile= ssid=5G wireless-protocol=802.11 wmm-support=enabled \
    wps-mode=disabled
add default-forwarding=no keepalive-frames=disabled mac-address= master-interface=5GHz max-station-count=10 multicast-buffering=disabled multicast-helper=disabled name= security-profile= ssid=\
    Guest wds-cost-range=0 wds-default-cost=0 wmm-support=enabled wps-mode=disabled
Both WLANs are bridged with some ether ports in bridge-LAN.

I do not own Apple devices, but my parents and brother do own iPhones and they come and are connected regularly with no issues. No Macbooks or iPads though.
I was really afraid it would misbehave when I was considering upgrade from RB2011 and saw these reports about WiFi issues, but RB4011 is working flawlessly for me so far.
is ipv6 present on RB4011?
Image
 
MichalPospichal
just joined
Posts: 9
Joined: Sun Feb 04, 2018 11:27 pm
Location: Czech Republic

Re: v6.44.3 [stable] is released!

Sun Apr 28, 2019 7:37 am

is ipv6 present on RB4011?
Nope. Also, I did not know about the duplicated MAC with SFP mentioned in the other thread, so it is running ok with the same MAC, but SFP is disabled.
 
TimurA
Member Candidate
Member Candidate
Posts: 144
Joined: Sat Dec 15, 2018 6:13 am
Location: Tashkent
Contact:

Re: v6.44.3 [stable] is released!

Sun Apr 28, 2019 7:55 am

is ipv6 present on RB4011?
Nope. Also, I did not know about the duplicated MAC with SFP mentioned in the other thread, so it is running ok with the same MAC, but SFP is disabled.
I will try to cut down ipv6, and conduct tests again.
Image
 
TimurA
Member Candidate
Member Candidate
Posts: 144
Joined: Sat Dec 15, 2018 6:13 am
Location: Tashkent
Contact:

Re: v6.44.3 [stable] is released!

Sun Apr 28, 2019 8:45 am

I disabled the ipv6 interface, checked roaming from RB4011 to RB962 and back (RB4011 channel 48, RB962 channel 36), there are no packet losses, it works.

It turns out the problem on RB4011 with ipv6, as soon as ipad pro 2018, mixes up with RB4011 on RB962 and then back from ipv6, wlan1 on RB4011 drops.

if RB4011 and RB962 are on the same channel 36, then wlan1 on RB4011 with ipv6 interface turned on does not fall.
Image
 
MichalPospichal
just joined
Posts: 9
Joined: Sun Feb 04, 2018 11:27 pm
Location: Czech Republic

Re: v6.44.3 [stable] is released!

Sun Apr 28, 2019 9:08 am

Interesting find, good work.
 
TimurA
Member Candidate
Member Candidate
Posts: 144
Joined: Sat Dec 15, 2018 6:13 am
Location: Tashkent
Contact:

Re: v6.44.3 [stable] is released!

Sun Apr 28, 2019 8:07 pm

Interesting find, good work.
Today I tested the hAP ac scheme (RB962) and wAP AC with ipv6, everything worked fine. Why so with RB4011 - I do not understand: (
Image
 
TimurA
Member Candidate
Member Candidate
Posts: 144
Joined: Sat Dec 15, 2018 6:13 am
Location: Tashkent
Contact:

Re: v6.44.3 [stable] is released!

Mon Apr 29, 2019 7:37 am

Interesting find, good work.
I did another experiment with ipv6, turned off the access list in wifi and checked the reconnection from RB4011 to RB962 and back. While working stably. Miracles and only.

PS
RB4011 wlan1 fell again after 10 minutes. :(
Image
 
russman
Frequent Visitor
Frequent Visitor
Posts: 53
Joined: Thu May 20, 2010 7:23 pm

Re: v6.44.3 [stable] is released!

Mon Apr 29, 2019 7:33 pm

I just updated some test devices to 6.44.3 from 6.44.1. SSH port forwarding was working fine before the upgrade, but did not work after.

It looks like the default setting for "/ip ssh forwarding-enabled" has been changed from "both" to "remote". To fix this:

Code: Select all

/ip ssh set forwarding-enabled=both

While you are there, this seems like a good idea:

Code: Select all

/ip ssh set strong-crypto=yes allow-none-crypto=no
Thanks we were just troubleshooting this issue with 6.44.3, it seems they changed the default behavior in this update but then didn't give you the option to change it back in winbox and no further detail provided in release notes... Not cool!
 
User avatar
typicalwisp
just joined
Posts: 10
Joined: Fri Jan 05, 2018 8:45 pm

Re: v6.44.3 [stable] is released!

Mon Apr 29, 2019 10:04 pm

As mentioned in wiki the default value for it is "no". If before upgrade "forwarding-enabled=no", after upgrade it will be "forwarding-enabled=remote", if before upgrade "forwarding-enabled=yes", after upgrade it will be "forwarding-enabled=both".

The behavior above is what I would expect. It looks like there was a bug in previous versions that allowed SSH forwarding even though "/ip ssh forwarding-enabled=no". I assumed that they went from "forwarding-enabled=yes" to "forwarding-enabled=remote" because I could no longer connect to devices on the other side of the router through SSH forwarding after the update. Thanks for pointing this out.
 
zoltan1980
just joined
Posts: 2
Joined: Sun Apr 22, 2018 10:19 pm

Re: v6.44.3 [stable] is released!

Mon Apr 29, 2019 11:04 pm

[This problem report turned out to be due to a misconfiguration unrelated to the release. Shortening irrelevant long post as I can't delete it.]
Last edited by zoltan1980 on Tue Apr 30, 2019 12:16 am, edited 1 time in total.
 
sindy
Forum Guru
Forum Guru
Posts: 3769
Joined: Mon Dec 04, 2017 9:19 pm

Re: v6.44.3 [stable] is released!

Mon Apr 29, 2019 11:22 pm

The problem may be with connection tracking, but I don't know how to debug that. The Neato worked fine before the upgrade and even after the upgrade all other devices work fine except the Neato. Any advice?
At first place the responses from the DNS should not get to input chain of the firewall if it is really Neato who sends the queries and not your Mikrotik itself. Please create a new topic on that and post there the configuration export as my automated signature suggests. Even though it may actually be a version related issue, it will need some communication for which this topic is not the right one; however, place here a link to the new topic.
Instead of writing novels, post /export hide-sensitive. Use find&replace in your favourite text editor to systematically replace all occurrences of each public IP address potentially identifying you by a distinctive pattern such as my.public.ip.1.
 
zoltan1980
just joined
Posts: 2
Joined: Sun Apr 22, 2018 10:19 pm

Re: v6.44.3 [stable] is released!

Tue Apr 30, 2019 12:04 am

Please create a new topic on that and post there the configuration export as my automated signature suggests. Even though it may actually be a version related issue, it will need some communication for which this topic is not the right one; however, place here a link to the new topic.
With your help I already found the problem, thanks a lot! :) While following the instructions from your signature and going through the output of
/export hide-sensitive
sanity-checking it for any remanining sensitive information, I found the misconfiguration. You were right, it was not related to the upgrade, just an old misconfiguration coincidentally surfaced at the same time. I plan to delete my unrelevant post (and this update as well) within an hour to keep this thread focused on the release, but didn't want to do it without first stating that the issue was not caused by the release and also taking the opportunity to say thanks.
 
sysnotdown
just joined
Posts: 14
Joined: Tue Apr 30, 2019 3:21 pm

Re: v6.44.3 [stable] is released!

Wed May 01, 2019 11:12 am

6.44.x have many bugs! far from stable, it breakdown 5G wifi.

Who is online

Users browsing this forum: No registered users and 15 guests