Community discussions

MikroTik App
 
EdPa
MikroTik Support
MikroTik Support
Topic Author
Posts: 340
Joined: Fri Sep 15, 2017 10:05 am
Location: Riga
Contact:

v7.12beta [testing] is released!

Thu Aug 17, 2023 12:37 pm

RouterOS version 7.12beta has been released on the "v7 testing" channel!

Before an upgrade:
1) Remember to make backup/export files before an upgrade and save them on another storage device;
2) Make sure the device will not lose power during upgrade process;
3) Device has enough free storage space for all RouterOS packages to be downloaded.

What's new in 7.12beta9 (2023-Sep-25 15:19):

!) ethernet - changed "advertise" and "speed" arguments, and removed "half-duplex" setting under "/interface ethernet" menu;
!) health - removed "temperature" health entry from boards, where it was the same as "sfp-temperature";
!) sfp - convert configuration to support new link modes for SFP and QSFP type of interfaces;
*) bfd - improved system stability;
*) bgp - fixed "input.filter-chain" argument selection in VPN configuration;
*) bgp - improved logging;
*) bluetooth - added basic support for connecting to BLE peripheral devices;
*) console - export required properties with default values;
*) console - improved system stability;
*) console - restrict permissions to "read,write,reboot,ftp,romon,test" for scripts executed by DHCP, Hotspot, PPP and Traffic-Monitor services;
*) l3hw - fixed IPv6 route suppression;
*) led - fixed "interface-status" configuration for virtual interfaces;
*) lora - added LNS protocol support;
*) lte - changed R11e-LTE ARP behavior to NoArp;
*) lte - fixed sub-interface auto-removal in multiple APN setups;
*) lte - show correct data class when connected to 5G SA network;
*) mqtt - added on-message feature for subscribed topics;
*) mqtt - added parallel-scripts-limit parameter to set maximum allowed number of scripts executed at the same time;
*) mqtt - added wildcard topic subscription support;
*) netinstall - added option to discard branding package;
*) netinstall - display package filename in GUI Descption column if package description is not specified;
*) netinstall-cli - added option to discard branding package;
*) netinstall-cli - allow ".rsc" script filenames;
*) poe-out - driver optimization for AF/AT controlled boards;
*) poe-out - fixed rare CRS328 poe-out menu and poe-out port config loss after reboot;
*) route - added "single-process" configuration setting, enabled by default on devices with 64MB or less RAM memory (CLI only);
*) route - added "suppress-hw-offload" setting for IPv6 routes;
*) route - reverse community "delete" and "filter" command behavior;
*) routerboard - added "reset-button" support for RB800, RB1100 and RB1100AHx2 devices;
*) sfp - fixed 25Gbps link with FEC91 (introduced in v7.12beta7);
*) snmp - changed "mtxrGaugeValue" type to integer;
*) switch - fixed packet forwarding between Ethernet ports for CRS354 switches (introduced in v7.12beta7);
*) webfig - fixed timezone for interface "Last Link Down/Up Time";
*) wifiwave2 - correctly add interface to specified "datapath.interface-list";
*) wifiwave2 - fixed re-connection failures for 802.11ax interfaces in station mode;
*) wifiwave2 - limit L2MTU to 1560 until a fix is available for a bug causing interfaces to fail transmitting larger frames than that;
*) wifiwave2 - log more information regarding authentication failures;
*) winbox - added "Host Key Type" setting under "IP/SSH" menu;
*) winbox - added "Key Owner" setting under "System/User/SSH Keys" and "System/User/SSH Private Keys" menus;
*) winbox - added "Remote Min Tx" parameter under "Routing/BFD/Session" menu;
*) winbox - added "Startup Delay" setting under "Tools/Netwatch" menu;
*) winbox - added "Use BFD" setting under "Routing/RIP/Interface-Template" menu;
*) winbox - added MQTT subscription menu;
*) winbox - allow to specify server as DNS name under "Tools/Email" menu;
*) winbox - rename "DSCP" setting to "DSCP (+ECN)" under "Tools/Traffic-Generator/Packet-Templates" menu;
*) winbox - rename "Name" setting to "List" under "IP,IPv6/Firewall/Address-List" menu;
*) winbox - rename "Password" button to "Change Now" under "System/Password" menu;
*) wireguard - added "auto" parameter for "private-key" and "presharde-key" parameters;
*) wireguard - request public or private key to be specified in order to create peer;
*) x86 - igb updated driver to 5.14.16 version;
*) x86 - igbvf updated driver from in-tree Linux kernel;
*) x86 - updated latest available pci.ids;

What's new in 7.12beta7 (2023-Sep-13 09:58):

!) ethernet - changed "advertise" and "speed" arguments, and removed "half-duplex" setting under "/interface ethernet" menu;
!) sfp - convert configuration to support new link modes for SFP and QSFP type of interfaces;
*) api - fixed fetching objects with warning option from REST API;
*) bgp - implemented IGP metric sending in BGP messages;
*) bluetooth - use "g" units when decoding MikroTik beacon acceleration on peripheral devices menu;
*) certificate - allow to remove issued certificates when CRL is not used;
*) certificate - fixed certificate auto renewal via SCEP;
*) chr - iavf updated driver to 4.9.1 version;
*) console - improved randomness for ":rndstr" and ":rndnum" commands;
*) console - improved stability when using "special-login";
*) console - improved system stability through RoMON session;
*) console - improved system stability when using autocomplete;
*) dhcp - fixed DHCP server "authoritative" and "delay-threshold" settings (introduced in v7.12beta3);
*) ike2 - improved rekey collision handling;
*) ipsec - fixed Diffie-Hellman public value encoding size;
*) ipsec - fixed minor typo in logs;
*) ipsec - reduce disk writes when started without active configuration;
*) ipv6 - send RA and RA deprecate messages out three times instead of just once;
*) l3hw - improved system stability during IPv6 route offloading;
*) leds - added "dark-mode" functionality for RBwAPG-5HacD2HnD;
*) leds - added "wireless-status" and "wireless-signal-strength" configuration types for wifiwave2 interfaces;
*) log - improved logging for user actions;
*) lte - fixed 5G data-class reporting for Chateau 5G;
*) lte - fixed APN authentification in multi APN setup for R11e-LTE6;
*) lte - fixed IPv6 prefix for MBIM modems in multi-apn setup when IPv6 APN used as not first APN;
*) lte - fixed RSSI for FG621-EA modem to show the correct value;
*) lte - fixed startup race condition when SIM card is in "up" slot for LtAP mini;
*) mpls - improved FastPath next-hop selection hash algorithm;
*) netinstall-cli - added empty configuration option "-e";
*) netwatch - decreased "thr-tcp-conn-time" maximum limit to 30 seconds;
*) ovpn - improved system stability;
*) pimsm - improved system stability;
*) qsfp - added 50Gbps rate support for QSFP28 interfaces;
*) qsfp - fixed sub-interface EEPROM monitor data output (introduced in v7.12beta3);
*) qsfp - improved auto link detection for 100G CWDM4 modules and AOC cables (introduced in v7.12beta3);
*) qsfp - use sub-interface configuration for establishing link (for 40Gbps and 100Gbps links, all sub-interfaces must be enabled);
*) routerboard - added "reset-button" support for RB800 and RB1100 devices;
*) ssh - improved connection stability when pasting large chunks of text into console;
*) supout - added interface list members section;
*) switch - improved resource allocation for 98DX224S, 98DX226S, and 98DX3236 switch chips;
*) traffic-generator - fixed traffic-generator on CHR and x86;
*) usb - added support for RTL8153 USB ethernet on ARM, ARM64 and x86;
*) vrf - limit maximum VRFs to 1024;
*) vxlan - improved system stability for Tile devices;
*) webfig - fixed "Days" property configuration change under "IP/Firewall" menu;
*) webfig - fixed timezone for interface "Last Link Down/Up Time";
*) webfig - improved Webfig performance and responsiveness;
*) webfig - try to re-establish connection after disconnect;
*) wifiwave2 - added an alternative QoS priority assignment mechanism based on IP DSCP (CLI only);
*) wifiwave2 - added station-bridge interface mode (CLI only);
*) wifiwave2 - do not show default "l2mtu" on compact export;
*) wifiwave2 - fixed PTK renewal for interfaces in station mode;
*) wifiwave2 - fixed sniffer command not receiving any QoS null function frames when using 802.11ax radios;
*) wifiwave2 - fixed untagged VLAN 1 entry when using "vlan-id" setting together with vlan-filtering bridge;
*) wifiwave2 - fixed warning on CAP devices when radar detected;
*) wifiwave2 - implemented an option to transmit IP multicast packets as unicasts (CLI only);
*) wifiwave2 - improved compliance with regulatory requirements;
*) wifiwave2 - make 4-way handshake procedure more robust when acting as supplicant (client);
*) winbox - added "Comment" under "Routing/BFD/Configuration" menu;
*) winbox - added "g" flag under "IPv6/Routes" menu;
*) winbox - added "Name Format" property under "WifiWave2/Provisioning" menu;
*) winbox - changed "MBR Partition Table" checkbox to unchecked by default under "System/Disks/Format-Drive" menu;
*) winbox - fixed "Address" property under "WifiWave2/Remote-CAP" menu;
*) winbox - fixed "Group Key Update" maximum value under "WifiWave2/Security" menu;
*) winbox - fixed entry numbering and ordering under "WifiWave2/Provisioning" menu;
*) winbox - fixed minor typos;
*) wireguard - allow to specify client settings under peer menu which will be included in configuration file and QR code;
*) wireguard - generate Wireguard peer keys and preshared-key automatically, if value is specified but is not base64 string;
*) wireguard - removed "wg-add-client" configuration wizard (introduced in v7.12beta3);
*) wireless - added more "radius-mac-format" options (CLI only);
*) www - fixed allowed address setting for REST API users;
*) www - fixed fragmented POST data for SCEP service;
*) x86 - i40e updated driver to 2.23.17 version;
*) x86 - igc updated driver to 5.10.194 version;
*) x86 - ixgbe updated driver to 5.19.6 version;
*) x86 - Realtek r8169 updated driver;

What's new in 7.12beta3 (2023-Aug-24 12:15):

!) ethernet - changed "advertise" and "speed" arguments, and removed "half-duplex" setting under "/interface ethernet" menu;
!) sfp - convert configuration to support new link modes for SFP and QSFP type of interfaces;
*) bgp - fixed "atomic-aggregate" always set in output;
*) bgp - fixed local and remote port settings for BGP connections;
*) bgp - increase "hold-time" limit to 65000;
*) bridge - fixed fast-path forwarding with HW offloaded vlan-filtering (introduced in v7.11);
*) bridge - fixed untagged VLAN entry disable;
*) bridge - fixed vlan-filtering stability with HW and non-HW offloaded ports (introduced in v7.10);
*) bridge - improved vlan-filtering bridge stability with CAPsMAN (introduced in v7.11);
*) bth - added "Back To Home" VPN service for ARM, ARM64, and TILE devices;
*) calea - improved system stability when trying to add rules without the CALEA package;
*) console - added "transform" property for ":convert" command;
*) console - fixed scheduler "on-event" script highlighting when editing;
*) console - improved multi-argument property parsing into array;
*) console - improved stability when editing long scripts;
*) console - show full date and time in scheduler "next-run" property;
*) dhcp - fixed DHCP server and relay related response delays;
*) ethernet - added "supported" and "sfp-supported" values for "monitor" command;
*) interface - added "macvlan" interface support;
*) ipsec - fixed IPSec policy when using modp3072;
*) ipv6 - fixed IPv6 RA delay time from 5s to 500ms according to RFC;
*) ipv6 - send RA and RA deprecate messages out three times instead of just once;
*) log - improved logging for user actions;
*) lte - added at-chat support and increased wait time on modem at-chat for Dell DW5821e, DW5821e-eSIM, DW5829e and DW5829e-eSIM;
*) lte - added SINR reporting for FG621-EA modem;
*) lte - fixed Sierra modem detection for modems with vendor-specific USB descriptors;
*) lte - fixed startup race condition when SIM card is in "up" slot for LtAP mini;
*) netinstall-cli - prioritise interface option over address option;
*) ospf - fixed adding ECMP routes;
*) ospf - fixed OSPFv3 not working with NSSA areas;
*) ospf - fixed parsing of opaque LSAs used by TE;
*) ospf - fixed translated NSSA routes not showing in backbone;
*) port - add support for Huawei MS237h-517;
*) port - expose NMEA/DIAG ports for Dell DW5821e and DW5821e-eSIM;
*) quickset - fixed "LAN" interface list members if configuration does not contain bridge;
*) rip - added BFD support;
*) rip - fixed session not working in VRF;
*) route - fixed gateway after link restart;
*) route - removed deprecated "received-from" property;
*) sfp - improved interface stability for SFP and QSFP types of interfaces;
*) switch - improved switch chip stability for CCR2004-16g-2s+ devices;
*) tile - improved system stability when using queues;
*) traffic-generator - added "priority" property for "inject" command;
*) wifiwave2 - added comment property for registration-table;
*) wifiwave2 - enable changing interface MTU and L2MTU;
*) wifiwave2 - fixed malformed Interworking packet elements;
*) winbox - allow to set multiple addresses and added IPv6 support under "Interface/VETH" menu;
*) wireguard - added "wg-add-client" configuration wizard (CLI only);
*) wireguard - added "wg-export" and "wg-import" functionality (CLI only);
*) wireless - fixed malformed Interworking packet elements;
*) x86 - added support for Mellanox ConnectX-6 Dx NIC;

What's new in 7.12beta1 (2023-Aug-15 16:14):

*) bgp - fixed typos and missing spaces in log messages;
*) bridge - improved system stability;
*) bth - added "Back To Home" VPN service for ARM, ARM64, and TILE devices;
*) certificate - allow to get and maintain Let's Encrypt certificate in IPv6 environment;
*) certificate - fixed "subject-alt-name" duplicating itself when SCEP is used;
*) certificate - improved certificate validation logging error messages;
*) certificate - log CRL HTTP errors under the "error" logging topic;
*) chr - increased OVA default RAM amount from 160MB to 256MB;
*) console - added ":jobname" command;
*) console - added "as-string" and "as-string-value" properties for "get" command;
*) console - added "terminal/ask" command;
*) console - improved ":totime" and ":tonum" commands and added ":tonsec" command for time value manipulation;
*) console - improved stability and responsiveness;
*) console - improved stability when using "special-login";
*) firewall - added "ein-snat" and "ein-dnat" connection NAT state matchers for filter and mangle rules;
*) ike1 - log an error when non-RSA keys are being used;
*) iot - fixed an issue where applying a script to GPIO pin caused GPIO to stop working;
*) iot - fixed behavior where GPIO output state would change on boot;
*) lte - fixed Sierra modem initialization;
*) lte - use more compact logging messages;
*) modbus - added additional security settings for Modbus TCP;
*) mpls - added option to match and set MPLS EXP with bridge and mangle rules;
*) mpls - fixed "propagate-ttl=no" setting;
*) netinstall - added option to discard branding package;
*) ospf - fixed BFD on virtual-link with configured VRF;
*) ovpn - added "tls-auth" option support for imported .ovpn profiles;
*) sfp - fixed missing "rx-power" monitor with certain modules (introduced in v7.10);
*) ssh - added support for user ed25519 public keys;
*) ssh - allow to specify key owner on import;
*) ssh - fixed SSH tunnel performance (introduced in v7.10);
*) supout - added LLDP power to supout.rif;
*) supout - fixed BFD section;
*) system - improved system stability when MD5 checksums are used;
*) tile - improved system stability when using IPv6 queues;
*) wifiwave2 - list APs with a higher maximum data rate as more preferable roaming candidates;
*) winbox - allow to change port numbers for SCTP, DCCP, and UDP-LITE protocols under "IP/Firewall" menus;

To upgrade, click "Check for updates" at /system package in your RouterOS configuration interface, or head to our download page: http://www.mikrotik.com/download

If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while a router is not working as suspected or after some problem has appeared on the device

Please keep this forum topic strictly related to this particular RouterOS release.

Changelog edit:
- changed from ":tosec" to ":tonsec".
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1611
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 12:44 pm

*) firewall - added "ein-snat" and "ein-dnat" connection NAT state matchers for filter and mangle rules

Any info/docs on ein-dnat and ein-snat?
Last edited by Larsa on Thu Aug 17, 2023 1:04 pm, edited 1 time in total.
 
ToTheFull
Member
Member
Posts: 402
Joined: Fri Mar 24, 2023 3:24 pm

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 12:46 pm

Is this the same as 7.12alpha74 ?
 
User avatar
loloski
Member
Member
Posts: 420
Joined: Mon Mar 15, 2021 9:10 pm

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 12:55 pm

ovpn - added "tls-auth" option support for imported .ovpn profiles;
mpls - added option to match and set MPLS EXP with bridge and mangle rules;
been waiting this for a couple of years now :)
 
mducharme
Trainer
Trainer
Posts: 1777
Joined: Tue Jul 19, 2016 6:45 pm
Location: Vancouver, BC, Canada

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 12:57 pm

*) mpls - added option to match and set MPLS EXP with bridge and mangle rules;
Any info/docs for this? We want to test as soon as possible.

How are you able to "match" MPLS EXP for incoming packets with mangle rules when MPLS packets bypass the firewall - are these packets no longer bypassing the firewall?

EDIT: I just upgraded my home device to this new version and I'm not seeing these new options at the moment in the CLI.
 
EdPa
MikroTik Support
MikroTik Support
Topic Author
Posts: 340
Joined: Fri Sep 15, 2017 10:05 am
Location: Riga
Contact:

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 1:29 pm

The behavior is the same as in v6 - when an MPLS packet is received, EXP bits are copied to the ingress-priority field and can be matched where ingress-priority matching is available (e.g. bridge or ip firewall). MPLS forwarding process does not traverse any firewalls, so matching can only be done on MPLS egress routers.

Note that MPLS forwarding implicitly performs copying of ingress-priority to priority (as if MPLS had some firewall with one rule that did action=set-priority new-priority=from-ingress for all packets). This way when MPLS switched packet is sent out over the wifi link, WMM AC will be chosen based on MPLS EXP bits.
 
mducharme
Trainer
Trainer
Posts: 1777
Joined: Tue Jul 19, 2016 6:45 pm
Location: Vancouver, BC, Canada

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 1:40 pm

Thanks for the details. Yes, I am familiar with the entire ingress-priority and priority process and the automatic copying from v6, but the wording of the change made it sound like it was implemented differently using a separate matcher for EXP instead of being folded under ingress-priority and priority like in v6.

On v6 it also works (even though an unsupported configuration) to have a bridge filter matching ingress-priority for a packet that comes from another router, as long as MPLS fast path is turned off. For example, for a packet going from router [ PE1 ] to [ P1 ] to [ P2 ] to (whatever):

[ PE1 ] ---- (packet with MPLS exp bits) ----> [ P1 regular ethernet interface --> P1 bridge with queue trees and output-chain bridge filter marking packet based on ingress-priority from MPLS EXP bits --> bridge port on ethernet interface ] --> [ P2 ] --> etc.

ex. on the P1 router, on the interface the packet comes in from (facing PE1) it is just a regular ethernet interface, then the packet goes to a single-port bridge with bridge filters (output chain) marking the packet based on ingress priority, and then it passes through the heirarchy of queue trees and goes out the single bridge port, the other ethernet interface going to router P2. It passes through the proper queue tree based on the MPLS EXP value of the incoming packet. Thus it is possible to do priority queueing of MPLS traffic on v6 through this unsupported config, and we've been doing this for years now.

That setup is unsupported on v6 but works, I'd like to make sure it still works on v7. (The part that is unsupported on v6 is that it is not supposed to be possible to read ingress-priority in an output-chain bridge filter for a packet that arrived through other means, such as an interface that is not on the bridge - the "P1 regular ethernet interface" in my example above)
 
User avatar
woland
Member
Member
Posts: 310
Joined: Mon Aug 16, 2021 4:49 pm

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 2:33 pm

 
User avatar
mantouboji
Frequent Visitor
Frequent Visitor
Posts: 58
Joined: Mon Aug 01, 2022 2:21 pm
Location: Shanghai

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 2:36 pm

Very good for these:

*) certificate - allow to get and maintain Let's Encrypt certificate in IPv6 environment;
*) ssh - added support for user ed25519 public keys;

wait for ed25519 private key support。
Last edited by mantouboji on Thu Aug 17, 2023 4:16 pm, edited 1 time in total.
 
User avatar
clambert
Member Candidate
Member Candidate
Posts: 161
Joined: Wed Jun 12, 2019 5:04 am

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 2:55 pm

No IS-IS, no 6VPE. The wait continues...
 
dadaniel
Member Candidate
Member Candidate
Posts: 221
Joined: Fri May 14, 2010 11:51 pm

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 3:07 pm

ovpn - added "tls-auth" option support for imported .ovpn profiles;
Great work!

I'm getting the following error messages in log, but the connection seems to work.
Can anyone please comment if they are essential?

unsupported configuration parameter 'ns-cert-type server'
unsupported configuration parameter 'setenv CLIENT_CERT 0'
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1611
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 3:14 pm

@Larsa: Endpoint-Independent NAT: https://help.mikrotik.com/docs/pages/vi ... pendentNAT

Thanks! Care to give a brief usage example?
 
User avatar
pothi
newbie
Posts: 47
Joined: Fri Sep 14, 2018 7:48 pm
Location: Srivilliputhur, Tamil Nadu, India
Contact:

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 3:27 pm

ssh - added support for user ed25519 public keys;
Thanks. Been waiting for long.
 
Ulypka
Frequent Visitor
Frequent Visitor
Posts: 57
Joined: Wed Jan 09, 2013 8:26 am

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 3:30 pm

Endpoint-Independent NAT
all world call it Full Cone NAT
 
bommi
Frequent Visitor
Frequent Visitor
Posts: 51
Joined: Fri Jan 24, 2014 9:13 am
Location: Germany
Contact:

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 3:45 pm

*) ssh - added support for user ed25519 public keys;

Great to see this one!
I use my openpgp key based on ed25519 on my Yubikey for SSH logins.
 
bommi
Frequent Visitor
Frequent Visitor
Posts: 51
Joined: Fri Jan 24, 2014 9:13 am
Location: Germany
Contact:

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 4:07 pm

I have some more feature requests regarding encryption topics :-)

Since RouterOS 7.7 we can use diffie-hellmann group 31:
*) ike2 - added support for DH Group 31 (EC25519) (CLI only);

But the support is just implemented in ike2 / phase-1, could you please also bring this to ipsec / phase-2?
Is your crypto stack already able to support DH-32 (Curve448)? This would also be a great addition.
 
User avatar
woland
Member
Member
Posts: 310
Joined: Mon Aug 16, 2021 4:49 pm

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 4:13 pm

@Larsa: sry, I did not try it yet, I have seen the strange terminology and it made me curious.
I think it is the same as the thing called in RFCs EIM NAT (Endpoint-Independent Mapping).
AFAIK this is relevant for UDP NAT Traversal (STUN) for SIP (RTP, voice calls).
Here is more info: https://wiki.unify.com/wiki/Network_Con ... _Providers
Maybe other P2P Protocols need it as well.

@Mikrotik, maybe the misleading ein-nat should be changed to eim-nat ? Maybe I got it wrong and this is the Mikrotik special EIN NAT (TM) ?
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1611
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 4:38 pm

Okay, we simply have to wait for a clarification from MikroTik when they decide to update the online manual..
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 5:03 pm

Feature request: implement matching on packet-priority in queue tree child items, as an alternative to the present matching on packet-mark.
OR: implement multiple packet-marks per packet (e.g. via some new construct of "packet mark groups" to preserve backward compatibility)

Reason: as it is now, you can use packet marks only for a single purpose. When you decide to use them for priority and queueing, you cannot use them for another purpose anymore.
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 5:40 pm

*) console - added "terminal/ask" command;
Ask and ye shall receive...
:put [/terminal/ask "Is there going to be BTH for xMIPSx?"]
Minor issue: the F1 help implies there is a sensitive=, but it's not in the command completion.
 
User avatar
Jotne
Forum Guru
Forum Guru
Posts: 3343
Joined: Sat Dec 24, 2016 11:17 am
Location: Magrathean

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 5:52 pm

No IS-IS, no 6VPE. The wait continues...
A protocol from 1992. Why not change to OSPF
 
User avatar
Ullinator
just joined
Posts: 17
Joined: Tue Jun 08, 2021 12:53 pm
Location: North-West Germany

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 5:57 pm

Hi,
*) sfp - fixed missing "rx-power" monitor with certain modules (introduced in v7.10);

after the update from 7.11 stable to 7.12Beta1 my SFP+ module S+RJ10 reports high temperature and is temporary disabled.
(attachted to a CRS326-24G-2S+)
This happens never bevore, the temperature was around 70° Celsius, after the update it´s up to 95° celsious.
hc_023.jpg
On the other side of the cable the same module (S+RJ10) is attached to a CRS328-24G-4S+ without any problems regarding the temperature.
hc_022.jpg
Bug-ticket created: SUP-125388
You do not have the required permissions to view the files attached to this post.
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 6:21 pm

*) console - improved ":totime" and ":tonum" commands and added ":tosec" command for time value manipulation;
In the build it's :tonsec NOT ":tosec", but seems to work:
:put [:tonsec [:timestamp]]                           
1692285621621769359


Now it's this one...
*) console - added ":jobname" command;
I have no clue about.
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 12980
Joined: Thu Mar 03, 2016 10:23 pm

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 6:29 pm

after the update from 7.11 stable to 7.12Beta1 my SFP+ module S+RJ10 reports high temperature and is temporary disabled.
ROS v7.11, upon which this beta is based, came with "improved fan control on CRS3xx" ... so do verify fan speed. With RJ45 SFP modules it's critical to maintain adequate air flow to ensure cooling, so in your case no fan slowdowns should be accepted. If needed, set minimum fan speed to (fairly) high value to maintain SFP temperature below critical thresholds.

Due to excessive heat, produced by RJ45 SFP modules, Mikrotik issued S+RJ10 general guidance, which specifies recomended placement of such modules.
 
kalamaja
Member Candidate
Member Candidate
Posts: 114
Joined: Wed May 23, 2018 3:13 pm

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 6:38 pm

Any luck to see any progesss on NAT64 support, so to move to IPv6-only internal networks and have less dual-stack?
 
User avatar
Ullinator
just joined
Posts: 17
Joined: Tue Jun 08, 2021 12:53 pm
Location: North-West Germany

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 6:41 pm

Due to excessive heat, produced by RJ45 SFP modules, Mikrotik issued S+RJ10 general guidance, which specifies recomended placement of such modules.
Thanks for the tip , but the CRS326-24G-2S+ doesn't have any fans, it's fanless.
And as I described the temperature was before 7.12Beta1 never higher than max. 75°Celsius.
The problem came up imediatly after the update and was seen never before.
Last edited by tangent on Thu Aug 17, 2023 7:23 pm, edited 1 time in total.
Reason: quote fix, trim
 
crondrift
just joined
Posts: 2
Joined: Sat Jul 21, 2018 2:32 am

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 7:35 pm

*) ssh - added support for user ed25519 public keys

I must confess, I got tears in my eyes reading this! :)
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 8:11 pm

*) bridge - improved system stability;
Does this meaningless change line refer to the problem introduced late in the 7.11 release (VLAN-filtering bridge problems with 2 switch chips)??
 
User avatar
eworm
Forum Guru
Forum Guru
Posts: 1092
Joined: Wed Oct 22, 2014 9:23 am
Location: Oberhausen, Germany
Contact:

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 8:30 pm

I think no. It is related to dynamic interfaces.
 
User avatar
clambert
Member Candidate
Member Candidate
Posts: 161
Joined: Wed Jun 12, 2019 5:04 am

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 11:19 pm


A protocol from 1992. Why not change to OSPF
I prefer mature protocols :)
 
User avatar
nichky
Forum Guru
Forum Guru
Posts: 1389
Joined: Tue Jun 23, 2015 2:35 pm

Re: v7.12beta [testing] is released!

Thu Aug 17, 2023 11:20 pm

*) mpls - added option to match and set MPLS EXP with bridge and mangle rules; - need more info pls
 
mducharme
Trainer
Trainer
Posts: 1777
Joined: Tue Jul 19, 2016 6:45 pm
Location: Vancouver, BC, Canada

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 1:53 am

*) mpls - added option to match and set MPLS EXP with bridge and mangle rules; - need more info pls
They already answered this question higher in the thread. This isn't really a new feature. They've just restored a missing feature that was there in RouterOS v6 but was missing from v7. The behaviour is now the same as it was in v6. The description made me excited thinking it included some new features we didn't have before, instead it is the bug fix that I already knew was coming because MikroTik sent me an automated email letting me know the bug was fixed.
 
glueck05
newbie
Posts: 44
Joined: Fri Jan 26, 2018 12:49 pm

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 8:52 am

Is there a timeframe (a year would be enough for me) for MPLS in HW (the status from ROS6 would also be enough for me). Thanks
 
User avatar
pekr
Member Candidate
Member Candidate
Posts: 170
Joined: Tue Feb 22, 2005 9:05 pm
Location: Czech Republic
Contact:

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 9:11 am

How long are my 10+ months old hAP ax2s going to be stored in a drawer, because ROS 7 still does not support repeater mode? Tonnes of new features, but still not fully on parity with ROS 6.
 
rpingar
Long time Member
Long time Member
Posts: 593
Joined: Fri May 28, 2004 2:46 pm
Location: Italy

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 9:16 am

MT, do you have any plan to add Mellanox ConnectX6 to x86 driver??
thanks
 
holvoetn
Forum Guru
Forum Guru
Posts: 6762
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 9:24 am

How long are my 10+ months old hAP ax2s going to be stored in a drawer, because ROS 7 still does not support repeater mode? Tonnes of new features, but still not fully on parity with ROS 6.
If you have 2 Mikrotiks on each end, it is possible using EOIP on top of the link.
Workaround ? Yes.
But a solution.

Search forum for post from, I think, Amm0 who describes the steps.
 
User avatar
pekr
Member Candidate
Member Candidate
Posts: 170
Joined: Tue Feb 22, 2005 9:05 pm
Location: Czech Republic
Contact:

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 11:44 am

How long are my 10+ months old hAP ax2s going to be stored in a drawer, because ROS 7 still does not support repeater mode? Tonnes of new features, but still not fully on parity with ROS 6.
If you have 2 Mikrotiks on each end, it is possible using EOIP on top of the link.
Workaround ? Yes.
But a solution.

Search forum for post from, I think, Amm0 who describes the steps.
What I have found was not EOIP solution, but creating a VXLAN interface on both sides, adding those to local bridges, doing few twists to filtering, etc. Will experiment with that - viewtopic.php?t=180369#p990815

Thanks for pointers ....
 
msatter
Forum Guru
Forum Guru
Posts: 2941
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 12:13 pm

In the build it's :tonsec NOT ":tosec", but seems to work:
:put [:tonsec [:timestamp]]                           
1692285621621
Why they did not name it just :toepoch then if it is sec or nsec would be covered.
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1611
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 1:46 pm

Cause they try to avoid the linux naming convention whenever possible! ;-)
 
User avatar
fischerdouglas
Frequent Visitor
Frequent Visitor
Posts: 71
Joined: Thu Mar 07, 2019 6:38 pm
Location: Brazil
Contact:

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 2:27 pm

Endpoint-Independent NAT
all world call it Full Cone NAT
I believe there is much more in "full-cone" definition then just Endpoint-Independent NAT.

- Endpoint-Independent Mapping.
- Endpoint-Independent Filtering.
- Application Level Gateway or ALGs, that MikroTik calls /ip/firewall/service-port/ .
- PCP listeners of UPnP.

And maybe much more that I'm not remembering just now.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 2:44 pm

What I have found was not EOIP solution, but creating a VXLAN interface on both sides, adding those to local bridges, doing few twists to filtering, etc.
Well, VXLAN and EOIP are different ways to achieve the same thing: packaging a raw ethernet frame into an IP packet, so you can transfer it over the nontransparent WiFi link and still maintain full functionality like broadcast and VLANs at ethernet level.
Only VXLAN is even more inefficient than EOIP (in terms of header overhead).
 
User avatar
pekr
Member Candidate
Member Candidate
Posts: 170
Joined: Tue Feb 22, 2005 9:05 pm
Location: Czech Republic
Contact:

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 3:12 pm

What I have found was not EOIP solution, but creating a VXLAN interface on both sides, adding those to local bridges, doing few twists to filtering, etc.
Well, VXLAN and EOIP are different ways to achieve the same thing: packaging a raw ethernet frame into an IP packet, so you can transfer it over the nontransparent WiFi link and still maintain full functionality like broadcast and VLANs at ethernet level.
Only VXLAN is even more inefficient than EOIP (in terms of header overhead).
According to original authoer, EOIP required change to MTU, which transport over wifiwave2 did not allow. I am not an expert on that, in fact EOIP solution came to my mind earlier too, just was lazy to try it out. Might experiment with both, but still wondering, how difficult it might be to add 4 address frame support, especially if it was part of ROS already (although a different wireless stack).
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 12980
Joined: Thu Mar 03, 2016 10:23 pm

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 3:33 pm

... still wondering, how difficult it might be to add 4 address frame support.
I guess not so easy ... it requires tinkering with (almost) raw wireless frames ... which normally does wireless driver (and MT is using "stock" wireless driver in wifiwave2). If they went with chipset vendor's reference driver because they don't want to tinker with wireless drivers any more, then implementing 4-address mode would effectively revert their decision.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 3:51 pm

4-address mode is not standard in 801.11. each manufacturer that offers it has implemented their own hacks to negotiate and support it, and even when the Qualcomm driver they have imported has some form of 4-address support, it is almost guaranteed to be not compatible with devices running the classic wireless driver. Maybe in the future we will see 4-address support that only works between devices with wifiwave2.
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 5:04 pm

Why they did not name it just :toepoch then if it is sec or nsec would be covered.
The current name ":tonsec" is "number of seconds since epoch" – so they could have pick any part of that ;)

:tonsec makes sense to me. :tosec implies you get just the seconds part from a time – which NOT what this does – so that I'd say :tosec is the only wrong choice (and that's only a type in RN). While I really don't care... :toepoch seems a bit esoteric, and "nsec" kinda implies it's a num type.

FWIW, :totime now takes a "nsec" (or any number type) to convert seconds to a time time – essentially the reverse.
:put [:totime 60]     
00:01:00

And alternatively, :totime now takes a string type, to get a "time" type.
:put ([:totime "2023-08-18"] - [:timestamp]) 
-13:46:04.114613691
which diff from midnight in GMT to "now" (at ~time of posting)... It be 06:46:04 in PDT – but ISO dates assume GMT – so this is right.

Anyway changes are pretty guessable from the just the RN... so must somewhat intuitive. Good work here.

Only thing is... the "T" in the middle is a valid ISO-8601 string, but :totime doesn't like the "T" part...
:put [:totime "2023-08-18T00:00:00"]
# blank / nothing is output with a T, but a space works...
:put [:totime "2023-08-18 00:00:00"]
2798w1d00:00:00
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 5:31 pm

4-address mode is not standard in 801.11. each manufacturer that offers it has implemented their own hacks to negotiate and support it,
That why I'm not sure using a tunnel isn't such a bad option. It does let you treat wireless same as wired, vs using Wi-Fi specific WDS-like things.

The bigger issue today with doing tunneling over wifiwave2 is the interface won't sent packets larger than 1500*, even if the MTU is set higher – so tunnels get fragmented.

* I don't have any wifiwave2 devices here to check specific in 7.12, so maybe it's fix, but been open 2 years.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 5:57 pm

A nice workaround would be when to have support for an "ethernet over ethernet" protocol that allows you to make a fully transparent ethernet tunnel over an ethernet connection that does silly MAC and VLAN translations, without incurring the overhead of IP. Just package ethernet frames in another ethernet protocol, with fragmentation/reassembly support (maybe the latter would not be required when the MTU on the actual link could be increased to 1520). That would incur only ~16 bytes of overhead instead of 40-70 bytes.
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 7:44 pm

Interesting. But you have 1500 MTU, exactly, today...so even 16 bytes is too many ;)
I'm surprised you didn't mention the lack of BFD on a static /ip/route via check-gateway=bfd on a wifiwave2/etc interface. ;)
 
Guscht
Member Candidate
Member Candidate
Posts: 263
Joined: Thu Jul 01, 2010 5:32 pm

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 7:56 pm

*) firewall - added "ein-snat" and "ein-dnat" connection NAT state matchers for filter and mangle rules;

@Mikrotik, will be there a dedicated Flag in the Connection-Tracking for EIN-Flows too?
At the moment I see for the outgoing flow(s) Cs and for incoming flow(s) Cd. If there is a own NAT-state-matcher, there should be a dedicated flag too?!
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 8:03 pm

Interesting. But you have 1500 MTU, exactly, today...so even 16 bytes is too many ;)
No, you can set a higher MTU on a wireless interface (limit in old wireless is 1600, don't know what it is in wifiwave2) to have some headroom to allow 1500 byte MTU for the tunneled traffic...
I'm surprised you didn't mention the lack of BFD on a static /ip/route via check-gateway=bfd on a wifiwave2/etc interface. ;)
We do not use that. We have use-bfd=yes on BGP peers (that are over wireless). That would still work with a tunnel over wireless or wifiwave2.
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 8:06 pm

No, you can set a higher MTU on a wireless interface (limit in old wireless is 1600, don't know what it is in wifiwave2) to have some headroom to allow 1500 byte MTU for the tunneled traffic...
Oh you can set MTU no problem on wifiwave2, that ain't the problem. It does nothing if you look in sniffer, still 1500. Regardless if you set tunnel and interface higher. The wifiwave2 maxes at 1500.

And I'd be happy if I was wrong, but did a bunch of testing a while back on this one...
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 8:24 pm

Ok I cannot test that here because I have no device that realistically can be used with wifiwave2...
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 8:53 pm

Ok I cannot test that here because I have no device that realistically can be used with wifiwave2...
Me too.. All the wifiwave2 things are in the field right now. I got a RB1100AHx4, wAPacRs and CHRs right now, and all work with the v7.12beta ;)
And on a positive note, good news is not had any complaints about "regular" Wi-Fi on Audience/ax2/ax3's either in field. Although there not at 7.11/7.12 yet.

But wireless bridging two of AX devices is a long standing problem... And I've had a bug open on wifiwave2's MTU and hasn't been closed – so presume it's not fixed.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Fri Aug 18, 2023 10:12 pm

Ok I cannot test that here because I have no device that realistically can be used with wifiwave2...
Me too.. All the wifiwave2 things are in the field right now. I got a RB1100AHx4, wAPacRs and CHRs right now, and all work with the v7.12beta ;)
My pet peeve is that my RB4011iGS+5HacQ2HnD, the flagship home router, which has a supported 5GHz radio and all the storage and RAM required for wifiwave2, cannot use wifiwave2 because installing that driver stupidly disables the wireless driver so the 2GHz radio isn't recognized anymore...
 
leonardogyn
just joined
Posts: 18
Joined: Wed Dec 04, 2019 4:47 pm

Re: v7.12beta [testing] is released!

Sat Aug 19, 2023 4:12 am

And here I am, once again, begging on my knees, for Mikrotik Dev team to reconsider the inline comments on the webfig. Please give us AT LEAST the option to choose among inline comments or the "newline" old behavior. Forced inline comments, for those not using very wide monitors, totally trashed the use of comments. It's indeed useless with inline comments.

Please get the webfig AT LEAST on par with winbox, in which you can choose inline of "newline" comments. Please do not force inline comments without giving us the option to choose which one fits best our use case.
 
bratislav
Frequent Visitor
Frequent Visitor
Posts: 69
Joined: Mon May 05, 2014 10:36 am

Re: v7.12beta [testing] is released!

Sat Aug 19, 2023 1:30 pm

Endpoint-Independent NAT
all world call it Full Cone NAT
Actually Cisco calls it Restricted Cone NAT, but for example Juniper, Fortinet and many BSD variants call it Endpoint Independent mapping NAT...
Here is one explanation that describes it pretty well...
https://docs.netgate.com/tnsr/en/latest/nat/modes.html
 
marlab
newbie
Posts: 25
Joined: Sun Mar 15, 2015 2:48 pm
Location: EU

Re: v7.12beta [testing] is released!

Sat Aug 19, 2023 11:23 pm

ovpn - added "tls-auth" option support for imported .ovpn profiles
Wow, it feels like Christmas... :D
 
xkubus
just joined
Posts: 5
Joined: Sun Dec 11, 2011 7:49 pm

Re: v7.12beta [testing] is released!

Sun Aug 20, 2023 8:46 pm

viewtopic.php?t=172400 please fix this.
 
K0NCTANT1N
Frequent Visitor
Frequent Visitor
Posts: 77
Joined: Thu Jun 08, 2023 9:35 pm

Re: v7.12beta [testing] is released!

Mon Aug 21, 2023 2:04 am

How long are my 10+ months old hAP ax2s going to be stored in a drawer, because ROS 7 still does not support repeater mode? Tonnes of new features, but still not fully on parity with ROS 6.
Are you sure?! My doubts
 
User avatar
Jotne
Forum Guru
Forum Guru
Posts: 3343
Joined: Sat Dec 24, 2016 11:17 am
Location: Magrathean

Re: v7.12beta [testing] is released!

Mon Aug 21, 2023 7:57 am

viewtopic.php?t=172400 please fix this.
You have posted this to support@mikrotik.com and got a sup number, if not, nothing will happen.
 
mducharme
Trainer
Trainer
Posts: 1777
Joined: Tue Jul 19, 2016 6:45 pm
Location: Vancouver, BC, Canada

Re: v7.12beta [testing] is released!

Mon Aug 21, 2023 10:31 am

What I have found was not EOIP solution, but creating a VXLAN interface on both sides, adding those to local bridges, doing few twists to filtering, etc. Will experiment with that - viewtopic.php?t=180369#p990815
Yes, VXLAN is the way I work around this at the moment, and it is working very well for me. I would recommend that approach until such a time as they have real four-address-mode support.
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1465
Joined: Thu Nov 12, 2020 12:07 pm

Re: v7.12beta [testing] is released!

Mon Aug 21, 2023 11:07 am

*) console - improved ":totime" and ":tonum" commands and added ":tosec" command for time value manipulation;
Heureka! Finally I can do timstamp-based comparison in scripts (without all these huge custom helper-functions). Thanks MT
 
DeGlucker
just joined
Posts: 14
Joined: Tue Apr 12, 2011 4:35 pm
Location: Moscow, Russia

Re: v7.12beta [testing] is released!

Mon Aug 21, 2023 7:02 pm

MT, are you going to fix WiFi on x86 platform ? It was broken since ROS 7.7
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Mon Aug 21, 2023 7:29 pm

MT, are you going to fix WiFi on x86 platform ? It was broken since ROS 7.7
For remarks that broad you should at least reference a SUP number.
 
DeGlucker
just joined
Posts: 14
Joined: Tue Apr 12, 2011 4:35 pm
Location: Moscow, Russia

Re: v7.12beta [testing] is released!

Mon Aug 21, 2023 9:31 pm

MT, are you going to fix WiFi on x86 platform ? It was broken since ROS 7.7
For remarks that broad you should at least reference a SUP number.
No problem. That's it: SUP-104565
It was opened already since ROS 7.7 was released.
And all this time MT feeds me unsubscribes that the fix is not ready yet.
 
parham
Frequent Visitor
Frequent Visitor
Posts: 62
Joined: Sun Feb 15, 2015 11:35 pm

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 2:11 pm

Hi Dev,

Thanks for your all hard work, I have two request:

1- update the Zerotier package to latest 1.12.1 (https://www.zerotier.com/blog/zerotier- ... se-1-12-0/)

2- add the ping to any ip in the route (ip route add gateway=x.x.x.x check-gateway=ping host=1.1.1.1 )

Thanks
Parham
 
EdPa
MikroTik Support
MikroTik Support
Topic Author
Posts: 340
Joined: Fri Sep 15, 2017 10:05 am
Location: Riga
Contact:

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 3:58 pm

What's new in 7.12beta3 (2023-Aug-24 12:15):

!) ethernet - changed "advertise" and "speed" arguments, and removed "half-duplex" setting under "/interface ethernet" menu;
!) sfp - convert configuration to support new link modes for SFP and QSFP type of interfaces;
*) bgp - fixed "atomic-aggregate" always set in output;
*) bgp - fixed local and remote port settings for BGP connections;
*) bgp - increase "hold-time" limit to 65000;
*) bridge - fixed fast-path forwarding with HW offloaded vlan-filtering (introduced in v7.11);
*) bridge - fixed untagged VLAN entry disable;
*) bridge - fixed vlan-filtering stability with HW and non-HW offloaded ports (introduced in v7.10);
*) bridge - improved vlan-filtering bridge stability with CAPsMAN (introduced in v7.11);
*) bth - added "Back To Home" VPN service for ARM, ARM64, and TILE devices;
*) calea - improved system stability when trying to add rules without the CALEA package;
*) console - added "transform" property for ":convert" command;
*) console - fixed scheduler "on-event" script highlighting when editing;
*) console - improved multi-argument property parsing into array;
*) console - improved stability when editing long scripts;
*) console - show full date and time in scheduler "next-run" property;
*) dhcp - fixed DHCP server and relay related response delays;
*) ethernet - added "supported" and "sfp-supported" values for "monitor" command;
*) interface - added "macvlan" interface support;
*) ipsec - fixed IPSec policy when using modp3072;
*) ipv6 - fixed IPv6 RA delay time from 5s to 500ms according to RFC;
*) ipv6 - send RA and RA deprecate messages out three times instead of just once;
*) log - improved logging for user actions;
*) lte - added at-chat support and increased wait time on modem at-chat for Dell DW5821e, DW5821e-eSIM, DW5829e and DW5829e-eSIM;
*) lte - added SINR reporting for FG621-EA modem;
*) lte - fixed Sierra modem detection for modems with vendor-specific USB descriptors;
*) lte - fixed startup race condition when SIM card is in "up" slot for LtAP mini;
*) netinstall-cli - prioritise interface option over address option;
*) ospf - fixed adding ECMP routes;
*) ospf - fixed OSPFv3 not working with NSSA areas;
*) ospf - fixed parsing of opaque LSAs used by TE;
*) ospf - fixed translated NSSA routes not showing in backbone;
*) port - add support for Huawei MS237h-517;
*) port - expose NMEA/DIAG ports for Dell DW5821e and DW5821e-eSIM;
*) quickset - fixed "LAN" interface list members if configuration does not contain bridge;
*) rip - added BFD support;
*) rip - fixed session not working in VRF;
*) route - fixed gateway after link restart;
*) route - removed deprecated "received-from" property;
*) sfp - improved interface stability for SFP and QSFP types of interfaces;
*) switch - improved switch chip stability for CCR2004-16g-2s+ devices;
*) tile - improved system stability when using queues;
*) traffic-generator - added "priority" property for "inject" command;
*) wifiwave2 - added comment property for registration-table;
*) wifiwave2 - enable changing interface MTU and L2MTU;
*) wifiwave2 - fixed malformed Interworking packet elements;
*) winbox - allow to set multiple addresses and added IPv6 support under "Interface/VETH" menu;
*) wireguard - added "wg-add-client" configuration wizard (CLI only);
*) wireguard - added "wg-export" and "wg-import" functionality (CLI only);
*) wireless - fixed malformed Interworking packet elements;
*) x86 - added support for Mellanox ConnectX-6 Dx NIC;
 
User avatar
loloski
Member
Member
Posts: 420
Joined: Mon Mar 15, 2021 9:10 pm

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 4:28 pm

Interface - added "macvlan" interface support;
Wow this is quite a surprise
 
User avatar
sergiobeltrao
just joined
Posts: 1
Joined: Sat Jan 21, 2023 4:53 am
Location: Brazil

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 4:35 pm

The new release shouldn't be 7.12beta2?
 
User avatar
eworm
Forum Guru
Forum Guru
Posts: 1092
Joined: Wed Oct 22, 2014 9:23 am
Location: Oberhausen, Germany
Contact:

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 4:37 pm

The new release shouldn't be 7.12beta2?
Probably did not pass internal quality testing...
 
parham
Frequent Visitor
Frequent Visitor
Posts: 62
Joined: Sun Feb 15, 2015 11:35 pm

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 4:40 pm

Nice job Devs Please add the two request in the next beta:

1- update the Zerotier package to latest 1.12.1 (https://www.zerotier.com/blog/zerotier- ... se-1-12-0/)

2- add the ping to any ip in the route (ip route add gateway=x.x.x.x check-gateway=ping host=1.1.1.1 )

Thanks
Last edited by BartoszP on Thu Aug 24, 2023 4:57 pm, edited 1 time in total.
Reason: removed full quote
 
User avatar
BartoszP
Forum Guru
Forum Guru
Posts: 2978
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 5:03 pm

EdPa

Is it possible and could we ask to elaborate "a little bit more" on changes describing at least what was the main cause of change.
It could let to avoid mistakes and track problems in our configurations easier.

E.g.:
*) switch - improved switch chip stability for CCR2004-16g-2s+ devices; what caused problem with ..... and there one or two sentences of the crucial problem
Please push a liitle life into these dry facts :)
 
User avatar
loloski
Member
Member
Posts: 420
Joined: Mon Mar 15, 2021 9:10 pm

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 5:05 pm

console died so far i can reproduce this on a spare CCR1036 and CRS317 so this is not architecture specific
2.png
You do not have the required permissions to view the files attached to this post.
 
User avatar
loloski
Member
Member
Posts: 420
Joined: Mon Mar 15, 2021 9:10 pm

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 5:22 pm

RB4011 is also affected :( but hapac2 is working
Last edited by loloski on Thu Aug 24, 2023 5:57 pm, edited 1 time in total.
 
stich86
just joined
Posts: 8
Joined: Mon Oct 31, 2022 8:44 pm

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 5:54 pm

@EdPa

why no one of your support reply to tickets?
You have an issue with flow control but looks like you are not so much interested on resolve it.
RB5009, CCR2004 (and also X86 build), CRS3xx are useless when need to use flow control in the right way (10G to 2.5G with an asymmetric interface configuration).
Only thing that is working is a CHR virtulised, but in this case all ethernet (like flow control) stuff is done by the hypervisor.
Hope someone here from the support want to investigate and find a solution, I am available for any test :)
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 5:59 pm

*) console - added "transform" property for ":convert" command;
Like the approach.
:put [:convert [:convert "long live the emperor" transform=rot13 to=hex] transform=rot13 from=hex]
 # long live the emperor
 

Maybe SHA256 should be a transform= as well?
Last edited by Amm0 on Thu Aug 24, 2023 6:02 pm, edited 1 time in total.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 6:01 pm

console died so far i can reproduce this on a spare CCR1036 and CRS317 so this is not architecture specific
Is that on a physical console? (serial port and terminal program)
As I cannot reproduce that on a terminal window...
 
rpingar
Long time Member
Long time Member
Posts: 593
Joined: Fri May 28, 2004 2:46 pm
Location: Italy

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 6:05 pm

many thanks!!!
*) x86 - added support for Mellanox ConnectX-6 Dx NIC;
 
User avatar
loloski
Member
Member
Posts: 420
Joined: Mon Mar 15, 2021 9:10 pm

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 7:39 pm

console died so far i can reproduce this on a spare CCR1036 and CRS317 so this is not architecture specific
Is that on a physical console? (serial port and terminal program)
As I cannot reproduce that on a terminal window...
Terminal inside winbox, prior to upgrade both my 1036 and 317 devices is from v7.11
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 7:46 pm

Ok, works for me... (RB4011, hAP ac2, CCR1009, CHR)
 
User avatar
CTassisF
newbie
Posts: 36
Joined: Thu Jun 11, 2020 10:26 pm
Location: São Paulo, Brazil
Contact:

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 8:35 pm

What is layer-dir in /container/config?

Edit: Looks like it's persistent storage for container layers to be reused (in case different containers share some/all layers).
 
kiloon
just joined
Posts: 16
Joined: Sat Jul 09, 2022 2:14 pm

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 9:02 pm

RouterOS version 7.12beta has been released on the "v7 testing" channel!

Before an upgrade:
1) Remember to make backup/export files before an upgrade and save them on another storage device;
2) Make sure the device will not lose power during upgrade process;
3) Device has enough free storage space for all RouterOS packages to be downloaded.

What's new in 7.12beta3 (2023-Aug-24 12:15):

!) ethernet - changed "advertise" and "speed" arguments, and removed "half-duplex" setting under "/interface ethernet" menu;
!) sfp - convert configuration to support new link modes for SFP and QSFP type of interfaces;
*) bgp - fixed "atomic-aggregate" always set in output;
*) bgp - fixed local and remote port settings for BGP connections;
*) bgp - increase "hold-time" limit to 65000;
*) bridge - fixed fast-path forwarding with HW offloaded vlan-filtering (introduced in v7.11);
*) bridge - fixed untagged VLAN entry disable;
*) bridge - fixed vlan-filtering stability with HW and non-HW offloaded ports (introduced in v7.10);
*) bridge - improved vlan-filtering bridge stability with CAPsMAN (introduced in v7.11);
*) bth - added "Back To Home" VPN service for ARM, ARM64, and TILE devices;
*) calea - improved system stability when trying to add rules without the CALEA package;
*) console - added "transform" property for ":convert" command;
*) console - fixed scheduler "on-event" script highlighting when editing;
*) console - improved multi-argument property parsing into array;
*) console - improved stability when editing long scripts;
*) console - show full date and time in scheduler "next-run" property;
*) dhcp - fixed DHCP server and relay related response delays;
*) ethernet - added "supported" and "sfp-supported" values for "monitor" command;
*) interface - added "macvlan" interface support;
*) ipsec - fixed IPSec policy when using modp3072;
*) ipv6 - fixed IPv6 RA delay time from 5s to 500ms according to RFC;
*) ipv6 - send RA and RA deprecate messages out three times instead of just once;
*) log - improved logging for user actions;
*) lte - added at-chat support and increased wait time on modem at-chat for Dell DW5821e, DW5821e-eSIM, DW5829e and DW5829e-eSIM;
*) lte - added SINR reporting for FG621-EA modem;
*) lte - fixed Sierra modem detection for modems with vendor-specific USB descriptors;
*) lte - fixed startup race condition when SIM card is in non-default slot for LtAP mini;
*) netinstall-cli - prioritise interface option over address option;
*) ospf - fixed adding ECMP routes;
*) ospf - fixed OSPFv3 not working with NSSA areas;
*) ospf - fixed parsing of opaque LSAs used by TE;
*) ospf - fixed translated NSSA routes not showing in backbone;
*) port - add support for Huawei MS237h-517;
*) port - expose NMEA/DIAG ports for Dell DW5821e and DW5821e-eSIM;
*) quickset - fixed "LAN" interface list members if configuration does not contain bridge;
*) rip - added BFD support;
*) rip - fixed session not working in VRF;
*) route - fixed gateway after link restart;
*) route - removed deprecated "received-from" property;
*) sfp - improved interface stability for SFP and QSFP types of interfaces;
*) switch - improved switch chip stability for CCR2004-16g-2s+ devices;
*) tile - improved system stability when using queues;
*) traffic-generator - added "priority" property for "inject" command;
*) wifiwave2 - added comment property for registration-table;
*) wifiwave2 - enable changing interface MTU and L2MTU;
*) wifiwave2 - fixed malformed Interworking packet elements;
*) winbox - allow to set multiple addresses and added IPv6 support under "Interface/VETH" menu;
*) wireguard - added "wg-add-client" configuration wizard (CLI only);
*) wireguard - added "wg-export" and "wg-import" functionality (CLI only);
*) wireless - fixed malformed Interworking packet elements;
*) x86 - added support for Mellanox ConnectX-6 Dx NIC;

What's new in 7.12beta1 (2023-Aug-15 16:14):

*) bgp - fixed typos and missing spaces in log messages;
*) bridge - improved system stability;
*) bth - added "Back To Home" VPN service for ARM, ARM64, and TILE devices;
*) certificate - allow to get and maintain Let's Encrypt certificate in IPv6 environment;
*) certificate - fixed "subject-alt-name" duplicating itself when SCEP is used;
*) certificate - improved certificate validation logging error messages;
*) certificate - log CRL HTTP errors under the "error" logging topic;
*) chr - increased OVA default RAM amount from 160MB to 256MB;
*) console - added ":jobname" command;
*) console - added "as-string" and "as-string-value" properties for "get" command;
*) console - added "terminal/ask" command;
*) console - improved ":totime" and ":tonum" commands and added ":tonsec" command for time value manipulation;
*) console - improved stability and responsiveness;
*) console - improved stability when using "special-login";
*) firewall - added "ein-snat" and "ein-dnat" connection NAT state matchers for filter and mangle rules;
*) ike1 - log an error when non-RSA keys are being used;
*) iot - fixed an issue where applying a script to GPIO pin caused GPIO to stop working;
*) iot - fixed behavior where GPIO output state would change on boot;
*) lte - fixed Sierra modem initialization;
*) lte - use more compact logging messages;
*) modbus - added additional security settings for Modbus TCP;
*) mpls - added option to match and set MPLS EXP with bridge and mangle rules;
*) mpls - fixed "propagate-ttl=no" setting;
*) netinstall - added option to discard branding package;
*) ospf - fixed BFD on virtual-link with configured VRF;
*) ovpn - added "tls-auth" option support for imported .ovpn profiles;
*) sfp - fixed missing "rx-power" monitor with certain modules (introduced in v7.10);
*) ssh - added support for user ed25519 public keys;
*) ssh - allow to specify key owner on import;
*) ssh - fixed SSH tunnel performance (introduced in v7.10);
*) supout - added LLDP power to supout.rif;
*) supout - fixed BFD section;
*) system - improved system stability when MD5 checksums are used;
*) tile - improved system stability when using IPv6 queues;
*) wifiwave2 - list APs with a higher maximum data rate as more preferable roaming candidates;
*) winbox - allow to change port numbers for SCTP, DCCP, and UDP-LITE protocols under "IP/Firewall" menus;

To upgrade, click "Check for updates" at /system package in your RouterOS configuration interface, or head to our download page: http://www.mikrotik.com/download

If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while a router is not working as suspected or after some problem has appeared on the device

Please keep this forum topic strictly related to this particular RouterOS release.

Changelog edit:
- changed from ":tosec" to ":tonsec".
I believe there is a mistake "port - add support for Huawei MS237h-517" it should be MS2372h-517
 
User avatar
mantouboji
Frequent Visitor
Frequent Visitor
Posts: 58
Joined: Mon Aug 01, 2022 2:21 pm
Location: Shanghai

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 9:23 pm

wg-add-client is amazing, but leak MTU and Keepalive arguments.

And “endpoint-address” is the domain name of local MikroTik device and will in [peer] section of client configuration , OK.
 
User avatar
nithinkumar2000
Member Candidate
Member Candidate
Posts: 167
Joined: Wed Sep 11, 2019 7:42 am
Location: Coimbatore
Contact:

Re: v7.12beta [testing] is released!

Thu Aug 24, 2023 9:31 pm

I think We can expect IS-IS in Mikrotik Very Soon!!!
ISIS.png
Happy to Fast Developments from Mikrotik Team............
You do not have the required permissions to view the files attached to this post.
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 12:09 am

*) wireguard - added "wg-add-client" configuration wizard (CLI only);
*) wireguard - added "wg-export" and "wg-import" functionality (CLI only);
That's handy. Tiny/minor inconsistencies:
- The /interface/wireguard/wg-add-client prints the QR with an optional file= after generating the peer. But the wg-export requires a file= but does not print the QR.
- The "wg-" in the name also seem redundant, since it's already under /interface/wireguard.
 
User avatar
spippan
Member
Member
Posts: 464
Joined: Wed Nov 12, 2014 1:00 pm

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 3:25 am

No IS-IS, no 6VPE. The wait continues...
A protocol from 1992. Why not change to OSPF
maybe because is-is performes a bit better
[ https://ipwithease.com/ospf-vs-isis/ ]
2023-08-25 02_26_23-OSPF vs ISIS _ Detailed Comparison - IP With Ease — Mozilla Firefox.png
You do not have the required permissions to view the files attached to this post.
 
User avatar
loloski
Member
Member
Posts: 420
Joined: Mon Mar 15, 2021 9:10 pm

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 4:26 am

This is how it look like, same for 1036,RB4011 i'll try to netinstall them later if i can reproduce the issue
2.PNG
You do not have the required permissions to view the files attached to this post.
 
User avatar
loloski
Member
Member
Posts: 420
Joined: Mon Mar 15, 2021 9:10 pm

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 5:50 am

Same with our CCR1072 spare in the lab :(
2.PNG
You do not have the required permissions to view the files attached to this post.
 
User avatar
Jotne
Forum Guru
Forum Guru
Posts: 3343
Joined: Sat Dec 24, 2016 11:17 am
Location: Magrathean

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 8:08 am

maybe because is-is performans is a bit better
Betamax was better than VHS ;)
 
User avatar
mantouboji
Frequent Visitor
Frequent Visitor
Posts: 58
Joined: Mon Aug 01, 2022 2:21 pm
Location: Shanghai

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 9:32 am

It seems the stability of WireGuard in 7.12beta3 is better than 7.11. In 7.11 the link often break in 2-3 hours.
IMG_3268.jpeg
You do not have the required permissions to view the files attached to this post.
Last edited by mantouboji on Fri Aug 25, 2023 4:35 pm, edited 1 time in total.
 
whatever
Member
Member
Posts: 366
Joined: Thu Jun 21, 2018 9:29 pm

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 9:46 am

maybe because is-is performans is a bit better
Betamax was better than VHS ;)
No it wasn't, see https://www.youtube.com/watch?v=hGVVAQVdEOs ;)
 
nkourtzis
Member Candidate
Member Candidate
Posts: 225
Joined: Tue Dec 11, 2012 12:56 am
Location: Greece

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 9:49 am

A CRS354-48P-4S+2Q+ connected to a CCR2004-1G-12S+2XS via S+RJ10 modules on both devices (10Gbps link), failed to negotiate a link after upgrading to 7.12beta3. The connection started flapping slowly (every around 30 seconds or so) and after a while stopped working completely. The ethernet ports of the devices worked fine.

Setting speed manual on the CCR side did not work. Downgrading the CCR to 7.11 did not make any difference either. Downgrading the CRS to 7.11 fixed the problem. The problem seemed to be in the swtch though, because the CCR port could successfully connect to a laptop. I will retry the upgrade and post more details at a later time.
 
jhbarrantes
Frequent Visitor
Frequent Visitor
Posts: 56
Joined: Wed Aug 21, 2019 2:56 pm

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 10:10 am

7.11 Introudces a vlan polution in bridge vlan table. Default vlan was still there even with frame types = admit only vlan tagged on the bridge. 7.12beta3 still with the same issue. Reported as SUP-125982.

Regards.
 
donkeyKong
just joined
Posts: 7
Joined: Sat Aug 13, 2022 1:13 am

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 11:22 am

*) console - added "transform" property for ":convert" command;
What conversions are/will be made available?

I'm looking for MD5 to simplify some scripts.
 
glueck05
newbie
Posts: 44
Joined: Fri Jan 26, 2018 12:49 pm

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 11:24 am

I think We can expect IS-IS in Mikrotik Very Soon!!!

ISIS.png

Happy to Fast Developments from Mikrotik Team............
It would be desirable if mikrotik first restored the same range of functions as in ros 6 and only then implemented new features. I'm mainly waiting for MPLS in HW at least at the same level as in ROS6.

thanks, glueck
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 3:11 pm

I'm looking for MD5 to simplify some scripts.

:put [:convert "text to hash to MD5" transform=md5 to=hex]
The to= is "hex" for a hexstring. Although you could use the default "to=raw" instead, but MD5 is normally expressed in hex.

What's available is show with <tab> on the CLI... but possible to change since it's a beta...

:convert transform=
ed25519-private-to-ed25519-public
reverse
ed25519-private-to-x25519-private
rot13
ed25519-public-to-x25519-public
sha512
md5
x25519-private-to-x25519-public
none

:convert to=
base32 base64 hex raw url

:convert from=
base32 base64 hex raw url
 
User avatar
nz_monkey
Forum Guru
Forum Guru
Posts: 2182
Joined: Mon Jan 14, 2008 1:53 pm
Location: Over the Rainbow
Contact:

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 4:22 pm


It would be desirable if mikrotik first restored the same range of functions as in ros 6 and only then implemented new features. I'm mainly waiting for MPLS in HW at least at the same level as in ROS6.
What MPLS Hardware functionality was in RouterOS v6 that is not in v7 ?
 
User avatar
own3r1138
Forum Veteran
Forum Veteran
Posts: 727
Joined: Sun Feb 14, 2021 12:33 am
Location: Pleiades
Contact:

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 4:38 pm

*) wireguard - added "wg-add-client" configuration wizard (CLI only);
*) wireguard - added "wg-export" and "wg-import" functionality (CLI only);

Thank you very much.
 
User avatar
spippan
Member
Member
Posts: 464
Joined: Wed Nov 12, 2014 1:00 pm

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 4:39 pm

*) wireguard - added "wg-add-client" configuration wizard (CLI only);
*) wireguard - added "wg-export" and "wg-import" functionality (CLI only);

Thank you very much.
yes. that is a welcome addition - hopefully this will come to winbox (and maybe webgui) too
 
User avatar
own3r1138
Forum Veteran
Forum Veteran
Posts: 727
Joined: Sun Feb 14, 2021 12:33 am
Location: Pleiades
Contact:

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 4:44 pm

It will be just like this one.
*) Winbox - allows to set multiple addresses and added IPv6 support under the "Interface/VETH" menu;
 
User avatar
osc86
Member Candidate
Member Candidate
Posts: 203
Joined: Wed Aug 09, 2017 1:15 pm

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 6:15 pm

yes. that is a welcome addition - hopefully this will come to winbox (and maybe webgui) too
..with support for QR-codes like BTH has.
 
mducharme
Trainer
Trainer
Posts: 1777
Joined: Tue Jul 19, 2016 6:45 pm
Location: Vancouver, BC, Canada

Re: v7.12beta [testing] is released!

Fri Aug 25, 2023 9:22 pm

What MPLS Hardware functionality was in RouterOS v6 that is not in v7 ?
If I recall correctly the CRS317 supported MPLS hardware offload when acting as a P router in RouterOS v6. I'm not sure if this has been brought to v7 yet.
 
User avatar
afink
newbie
Posts: 35
Joined: Wed May 29, 2013 7:16 pm
Location: Basel & Freetown
Contact:

Re: v7.12beta [testing] is released!

Sat Aug 26, 2023 1:42 am

Warning:

Watch out with 7.12beta3 if you have 100G ports on a CCR2216 and you use QSFP28 which are attached to a cable (DAC or AOC or so).
We had several links going out of service after upgrading to 7.12beta3. Going back to 7.11 restored the ports. Other nodes who had a optical LR4 transceiver in them did not show this effect.
 
rplant
Long time Member
Long time Member
Posts: 537
Joined: Fri Sep 29, 2017 11:42 am

Re: v7.12beta [testing] is released!

Sat Aug 26, 2023 3:05 am

*) dhcp - fixed DHCP server and relay related response delays;

Caused me some grief, had it on Authoritative after 2 Seconds, and things other than windows no longer got an IP address.
 
glueck05
newbie
Posts: 44
Joined: Fri Jan 26, 2018 12:49 pm

Re: v7.12beta [testing] is released!

Sat Aug 26, 2023 8:19 am

What MPLS Hardware functionality was in RouterOS v6 that is not in v7 ?
If I recall correctly the CRS317 supported MPLS hardware offload when acting as a P router in RouterOS v6. I'm not sure if this has been brought to v7 yet.
that's exactly what I meant. We have decided to exclusively use CRS504 and CRS518 as P-Routers in all new networks (we have also already started to convert old ones). Then the first 10 PoPs were ready and should go into operation and the feature was removed. Currently we have 23 PoPs equipped with the systems (CCR2004 working as PE routers in front of the OLTs) and we are waiting to get started with MPLS. At the moment we switch the whole thing in HW. Against this background, it is a pity that now new features like IS-IS are being implemented although the full range of functions of ros 6 is not yet available again.
Last edited by glueck05 on Sat Aug 26, 2023 2:19 pm, edited 1 time in total.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Sat Aug 26, 2023 11:03 am

Watch out with 7.12beta3 if you have 100G ports on a CCR2216 and you use QSFP28 which are attached to a cable (DAC or AOC or so).
This apparently is rocket science! MikroTik simply cannot get it working right.
Every new release there are changes in SFP, which fix some problem and it breaks somewhere else.
If it is not DAC cables working right, it is the temperature reading that is wrong, or the speed negotiation failing, or other parameter reading failing.

Well, to be a bit more positive: other manufacturers usually publish a short list of working modules and configurations, and support nothing else.
Maybe after all that is what is required in the world of SFP?
 
rpingar
Long time Member
Long time Member
Posts: 593
Joined: Fri May 28, 2004 2:46 pm
Location: Italy

Re: v7.12beta [testing] is released!

Sat Aug 26, 2023 6:26 pm

Warning:

Watch out with 7.12beta3 if you have 100G ports on a CCR2216 and you use QSFP28 which are attached to a cable (DAC or AOC or so).
We had several links going out of service after upgrading to 7.12beta3. Going back to 7.11 restored the ports. Other nodes who had a optical LR4 transceiver in them did not show this effect.

on ccr2216 the 7.12beta1&3 (up to alpha126) break the functionality of our modules qsfp-100-SR4 and qsfp-100-LR4 (tested several kind of manufactures about sr4).
be very carefull!!!!!

We see the light on sfp, but the interface doesn't go up with same configuration it goes up on 7.11 (we see also the sfp modules seem restarting. we lose sfp dates for a second and then they are back).

regards
 
msatter
Forum Guru
Forum Guru
Posts: 2941
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: v7.12beta [testing] is released!

Sat Aug 26, 2023 9:01 pm

Miktotik seems to have a special "Testing department" for this and they update the lists on a regular basis as you can see in the Docs history:

https://help.mikrotik.com/docs/pages/vi ... d=13500447

Sadly the SFP sections are not recently being tested or updated.

In the Wiki you can see QSFP...why that is not transferred to the Docs is not know

https://wiki.mikrotik.com/wiki/MikroTik ... patibility
 
User avatar
pekr
Member Candidate
Member Candidate
Posts: 170
Joined: Tue Feb 22, 2005 9:05 pm
Location: Czech Republic
Contact:

Re: v7.12beta [testing] is released!

Sun Aug 27, 2023 11:30 am

*) wifiwave2 - added comment property for registration-table;
Somehow can't make it working. No Winbox gui button, no luck in terminal either? I have tried to edit particular item, value=comment, editor opens up, put the comment there Ctrl + o, but it's not there ....

Any clues of how to comment a registration table items?

Edit: OK, managed to do it via an access list, setting a simple rule for the particular MAC address. But then - I miss the context menu action "Copy to access list", while at the registration table tab.
 
User avatar
stmx38
Long time Member
Long time Member
Posts: 650
Joined: Thu Feb 14, 2008 4:03 pm
Location: Moldova, Chisinau

Re: v7.12beta [testing] is released!

Sun Aug 27, 2023 11:48 am

Edit: OK, managed to do it via an access list, setting a simple rule for the particular MAC address. But then - I miss the context menu action "Copy to access list", while at the registration table tab.
A way to do it via ACL works in 7.11(wifiwave2) and worked in 6.x.

Maybe it is something different?
 
rpingar
Long time Member
Long time Member
Posts: 593
Joined: Fri May 28, 2004 2:46 pm
Location: Italy

Re: v7.12beta [testing] is released!

Sun Aug 27, 2023 12:27 pm

Miktotik seems to have a special "Testing department" for this and they update the lists on a regular basis as you can see in the Docs history:

https://help.mikrotik.com/docs/pages/vi ... d=13500447

Sadly the SFP sections are not recently being tested or updated.

In the Wiki you can see QSFP...why that is not transferred to the Docs is not know

https://wiki.mikrotik.com/wiki/MikroTik ... patibility
the weird thing is that also the mikrotik qsfp28-sr4 module works on 7.11 and doesn't on 7.12beta..............
 
msatter
Forum Guru
Forum Guru
Posts: 2941
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: v7.12beta [testing] is released!

Sun Aug 27, 2023 12:46 pm

And then, you are on a Beta version. Thing get broken all the time by developers so that not weird at all.

Report it support and they will try to fix that...and try also to not break someting else doing that. ;-)
 
User avatar
eworm
Forum Guru
Forum Guru
Posts: 1092
Joined: Wed Oct 22, 2014 9:23 am
Location: Oberhausen, Germany
Contact:

Re: v7.12beta [testing] is released!

Sun Aug 27, 2023 5:05 pm

Edit: OK, managed to do it via an access list, setting a simple rule for the particular MAC address. But then - I miss the context menu action "Copy to access list", while at the registration table tab.
A way to do it via ACL works in 7.11(wifiwave2) and worked in 6.x.
The registration table did display the comment, but but you could not filter (print where ...) or access via scripting (find, get, ...).
 
stevester
just joined
Posts: 8
Joined: Wed Feb 22, 2023 3:53 am

Re: v7.12beta [testing] is released!

Sun Aug 27, 2023 6:45 pm

Thank you for the macvlan support! Works great, now I can finally get multiple public IP's from my ISP using DHCP - without needing to resort to the VRRP hack.
 
EdPa
MikroTik Support
MikroTik Support
Topic Author
Posts: 340
Joined: Fri Sep 15, 2017 10:05 am
Location: Riga
Contact:

Re: v7.12beta [testing] is released!

Mon Aug 28, 2023 10:30 am

@rpingar, afink - thanks for the feedback. Can you also share the output from "/interface ethernet monitor" for thouse QSFP modules that do not work?
 
User avatar
afink
newbie
Posts: 35
Joined: Wed May 29, 2013 7:16 pm
Location: Basel & Freetown
Contact:

Re: v7.12beta [testing] is released!

Mon Aug 28, 2023 12:22 pm

this is the type which does work with 7.11 but not with 7.12beta3
We have multiple instances where this shows up as a problem
https://www.fs.com/products/51709.html? ... &id=431173
The same module also exist with different names.
Q28-AO01
Q28-AO02
Q28-AO03
Q28-AO05 etc

the difference is only the length of the cable.

in 7.11 it shows
/interface/ethernet> monitor 13
name: qsfp28-1-1
status: link-ok
auto-negotiation: done
rate: 100Gbps
full-duplex: yes
tx-flow-control: no
rx-flow-control: no
fec: fec91
advertising:
link-partner-advertising:
sfp-module-present: yes
sfp-type: QSFP28
sfp-connector-type: no-separable-connector
sfp-link-length-copper-active-om4: 1m
sfp-vendor-name: FS
sfp-vendor-part-number: Q28-AO01
sfp-vendor-revision: 00
sfp-vendor-serial: S2106283149-2
sfp-manufacturing-date: 21-06-26
sfp-wavelength: 850nm
sfp-temperature: 37C
sfp-supply-voltage: 3.282V
sfp-tx-bias-current: 5mA
eeprom-checksum: good
eeprom: 0000: 11 07 02 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
0010: 00 00 00 00 00 00 25 29 00 00 80 34 00 00 00 00 ......%) ...4....
0020: 00 00 24 a8 25 d9 25 41 24 a8 0b 1b 0b 28 0b 25 ..$.%.%A $....(.%
0030: 0b 21 22 f7 23 20 23 17 23 0a 00 00 00 00 00 00 .!".# #. #.......
0040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
0050: 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 ........ ........
0060: 00 00 ff 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
0070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
0080: 11 cc 23 80 00 00 00 40 00 02 00 00 ff 00 00 00 ..#....@ ........
0090: 00 00 01 00 46 53 20 20 20 20 20 20 20 20 20 20 ....FS
00a0: 20 20 20 20 1f 00 00 00 51 32 38 2d 41 4f 30 31 .... Q28-AO01
00b0: 20 20 20 20 20 20 20 20 30 30 42 68 03 52 46 b8 00Bh.RF.
00c0: 01 07 ff 9a 53 32 31 30 36 32 38 33 31 34 39 2d ....S210 6283149-
00d0: 32 20 20 20 32 31 30 36 32 36 20 20 00 10 67 9f 2 2106 26 ..g.
00e0: 00 00 08 5c 79 93 94 15 23 86 a4 af 85 2a 58 55 ...\y... #....*XU
00f0: 11 10 ca 00 00 00 00 00 00 00 00 00 d2 c9 1c 92 ........ ........

this is the same on a 7.12beta3 router

/interface/ethernet> monitor 13
name: qsfp28-1-1
status: no-link
auto-negotiation: done
supported: 10M-baseT-half,10M-baseT-full,100M-baseT-half,100M-baseT-full,1000M-baseT-half,1000M-baseT-full,1000M-baseX,2.5G-baseT,
2.5G-baseX,5G-baseT,10G-baseT,10G-baseSR,10G-baseLR,10G-baseLRM,10G-baseER,10G-baseCR,40G-baseSR4,40G-baseLR4,
40G-baseCR4,25G-baseSR,25G-baseCR,100G-baseSR4,100G-baseLR4-ER4,100G-baseCR4
sfp-supported: 1000M-baseT-full,1000M-baseX,2.5G-baseT,2.5G-baseX,5G-baseT,10G-baseCR,40G-baseLR4,25G-baseCR
advertising: 1000M-baseT-full,1000M-baseX,2.5G-baseT,2.5G-baseX,5G-baseT,10G-baseCR,40G-baseLR4,25G-baseCR
link-partner-advertising:
sfp-module-present: yes
sfp-type: QSFP28/QSFP56
sfp-connector-type: no-separable-connector
sfp-link-length-copper-active-om4: 1m
sfp-vendor-name: FS
sfp-vendor-part-number: Q28-AO01
sfp-vendor-revision: A
sfp-vendor-serial: C2204277219-2
sfp-manufacturing-date: 22-04-21
eeprom-checksum: good
eeprom: 0000: 11 07 00 00 00 f0 00 00 00 00 00 00 00 00 00 00 ........ ........
0010: 00 00 00 00 00 00 21 11 00 00 7f e4 00 00 00 00 ......!. ........
0020: 00 00 2a 0c 2a 0c 2a 0c 2a 0c 00 00 0b b5 0b b1 ..*.*.*. *.......
0030: 0b ae 00 01 24 dc 24 cf 24 c6 00 00 00 00 00 00 ....$.$. $.......
0040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
0050: 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 ........ ........
0060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
*
0080: 11 00 23 00 00 00 00 00 00 00 08 00 ff 00 00 00 ..#..... ........
0090: 00 00 01 a0 46 53 20 20 20 20 20 20 20 20 20 20 ....FS
00a0: 20 20 20 20 1f 00 02 c9 51 32 38 2d 41 4f 30 31 .... Q28-AO01
00b0: 20 20 20 20 20 20 20 20 41 20 06 0a 00 00 46 af A ....F.
00c0: 01 07 00 00 43 32 32 30 34 32 37 37 32 31 39 2d ....C220 4277219-
00d0: 32 20 20 20 32 32 30 34 32 31 20 20 0c 00 00 85 2 2204 21 ....
00e0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
00f0: df 10 01 a3 01 20 00 00 00 00 00 00 00 00 00 00 ..... .. ........


see also SUP-126151
 
rpingar
Long time Member
Long time Member
Posts: 593
Joined: Fri May 28, 2004 2:46 pm
Location: Italy

Re: v7.12beta [testing] is released!

Mon Aug 28, 2023 3:33 pm

these are with 7.11 where interfaces are up:
/interface/ethernet> monitor 1
name: qsfp28-1-1
status: link-ok
auto-negotiation: done
rate: 100Gbps
full-duplex: yes
tx-flow-control: no
rx-flow-control: no
fec: off
advertising:
link-partner-advertising:
sfp-module-present: yes
sfp-type: QSFP28
sfp-connector-type: multifiber-parallel-optic-1x12
sfp-link-length-om3: 70m
sfp-link-length-copper-active-om4: 100m
sfp-vendor-name: CISCO-OEM
sfp-vendor-part-number: F24-CI-QSFP-100G
sfp-vendor-revision: 10
sfp-vendor-serial: 3213414606
sfp-manufacturing-date: 21-08-25
name: qsfp28-1-1
status: link-ok
auto-negotiation: done
rate: 100Gbps
full-duplex: yes
tx-flow-control: no
rx-flow-control: no
fec: off
advertising:
link-partner-advertising:
sfp-module-present: yes
sfp-type: QSFP28
sfp-connector-type: multifiber-parallel-optic-1x12
sfp-link-length-om3: 70m
sfp-link-length-copper-active-om4: 100m
sfp-vendor-name: CISCO-OEM
sfp-vendor-part-number: F24-CI-QSFP-100G
sfp-vendor-revision: 10
sfp-vendor-serial: 3213414606
sfp-manufacturing-date: 21-08-25
sfp-wavelength: 850nm
sfp-temperature: 25C
sfp-supply-voltage: 3.277V
sfp-tx-bias-current: 7mA
sfp-tx-power: 0.067dBm
sfp-rx-power: 0.256dBm
eeprom-checksum: good
eeprom: 0000: 11 07 02 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
0010: 00 00 00 00 00 00 19 e5 00 00 80 07 00 00 00 00 ........ ........
0020: 00 00 29 71 26 a6 27 62 28 79 0d ac 0d ac 0d ac ..)q&.'b (y......
0030: 0d ac 27 ac 29 74 22 08 26 ce 00 00 00 00 00 00 ..'.)t". &.......
0040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
*
0060: 00 00 00 00 00 00 00 00 00 00 1f 00 00 00 00 00 ........ ........
0070: 00 ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
0080: 11 8c 0c 80 00 00 00 40 40 02 00 07 ff 00 00 23 .......@ @......#
0090: 00 00 32 00 43 49 53 43 4f 2d 4f 45 4d 20 20 20 ..2.CISC O-OEM
00a0: 20 20 20 20 00 00 00 00 46 32 34 2d 43 49 2d 51 .... F24-CI-Q
00b0: 53 46 50 2d 31 30 30 47 31 30 42 68 07 d0 46 5e SFP-100G 10Bh..F^
00c0: 02 00 30 9a 33 32 31 33 34 31 34 36 30 36 20 20 ..0.3213 414606
00d0: 20 20 20 20 32 31 30 38 32 35 20 20 0c 00 67 6f 2108 25 ..go
00e0: 00 00 11 a4 10 ba 0e 88 54 80 a3 e0 04 3a 91 af ........ T....:..
00f0: c1 56 40 00 00 00 00 00 00 00 00 00 59 ba b1 4a .V@..... ....Y..J


/interface/ethernet> monitor 5
name: qsfp28-2-1
status: link-ok
auto-negotiation: done
rate: 100Gbps
full-duplex: yes
tx-flow-control: no
rx-flow-control: no
fec: off
advertising:
link-partner-advertising:
sfp-module-present: yes
sfp-type: QSFP28
sfp-connector-type: LC
sfp-link-length-sm: 10km
sfp-vendor-name: FS
sfp-vendor-part-number: QSFP28-LR4-100G
sfp-vendor-revision: 01
sfp-vendor-serial: G1908173981
sfp-manufacturing-date: 20200615
sfp-wavelength: 1310nm
sfp-temperature: 50C
sfp-supply-voltage: 3.227V
sfp-tx-bias-current: 46mA
sfp-tx-power: 1.913dBm
sfp-rx-power: 0.16dBm
eeprom-checksum: good
eeprom: 0000: 11 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
0010: 00 00 00 00 00 00 32 26 00 00 7e 0f 00 00 00 00 ......2& ..~.....
0020: 00 00 28 88 29 9c 38 58 27 c7 5a d1 5d d3 5e 7b ..(.).8X '.Z.].^{
0030: 62 03 3c af 40 ea 42 83 2b ec 00 00 00 00 00 00 b.<.@.B. +.......
0040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
*
0060: 00 00 ff 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
0070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
0080: 11 ce 07 80 00 00 00 00 00 00 00 03 ff 02 0a 00 ........ ........
0090: 00 00 00 64 46 53 20 20 20 20 20 20 20 20 20 20 ...dFS
00a0: 20 20 20 20 00 00 00 00 51 53 46 50 32 38 2d 4c .... QSFP28-L
00b0: 52 34 2d 31 30 30 47 20 30 31 66 58 01 c1 46 20 R4-100G 01fX..F
00c0: 03 00 3f f2 47 31 39 30 38 31 37 33 39 38 31 20 ..?.G190 8173981
00d0: 20 20 20 20 32 30 32 30 30 36 31 35 0c 08 67 35 2020 0615..g5
00e0: 00 00 08 2f bc 3e 30 bf e8 0c 30 51 be a3 6f 89 .../.>0. ..0Q..o.
00f0: 0c 27 02 00 00 00 00 00 00 00 00 00 c7 a7 20 13 .'...... ...... .




these with 7.12beta3 where interfaces are down:
/interface/ethernet> monitor 1
name: qsfp28-1-1
status: no-link
auto-negotiation: done
supported: 10M-baseT-half,10M-baseT-full,100M-baseT-half,100M-baseT-full,1000M-baseT-half,1000M-baseT-full,1000M-baseX,2.5G-baseT,
2.5G-baseX,5G-baseT,10G-baseT,10G-baseSR,10G-baseLR,10G-baseLRM,10G-baseER,10G-baseCR,40G-baseSR4,40G-baseLR4,40G-baseCR4,
25G-baseSR,25G-baseCR,100G-baseSR4,100G-baseLR4-ER4,100G-baseCR4
sfp-supported: 10G-baseLR,10G-baseER,25G-baseSR,100G-baseSR4
advertising: 10G-baseLR,10G-baseER,25G-baseSR,100G-baseSR4
link-partner-advertising:
sfp-module-present: yes
sfp-type: QSFP28/QSFP56
sfp-connector-type: multifiber-parallel-optic-1x12
sfp-link-length-om3: 70m
sfp-link-length-copper-active-om4: 100m
sfp-vendor-name: CISCO-OEM
sfp-vendor-part-number: F24-CI-QSFP-100G
sfp-vendor-revision: 10
sfp-vendor-serial: 3213414606
sfp-manufacturing-date: 21-08-25
sfp-wavelength: 850nm
sfp-temperature: 32C
sfp-supply-voltage: 3.276V
sfp-tx-bias-current: 7mA
sfp-tx-power: 0.067dBm
sfp-rx-power: 0.451dBm
eeprom-checksum: good
eeprom: 0000: 11 07 00 00 00 0e 00 00 00 00 00 00 00 00 00 00 ........ ........
0010: 00 00 00 00 00 00 20 75 00 00 7f fb 00 00 00 00 ...... u ........
0020: 00 00 2b 57 16 ce 16 ed 19 a8 0d de 00 00 00 00 ..+W.... ........
0030: 00 00 27 ac 00 00 00 00 00 00 00 00 00 00 00 00 ..'..... ........
0040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
0050: 00 00 00 00 00 00 0e 00 00 00 00 00 00 00 00 00 ........ ........
0060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
*
0080: 11 8c 0c 80 00 00 00 40 40 02 00 07 ff 00 00 23 .......@ @......#
0090: 00 00 32 00 43 49 53 43 4f 2d 4f 45 4d 20 20 20 ..2.CISC O-OEM
00a0: 20 20 20 20 00 00 00 00 46 32 34 2d 43 49 2d 51 .... F24-CI-Q
00b0: 53 46 50 2d 31 30 30 47 31 30 42 68 07 d0 46 5e SFP-100G 10Bh..F^
00c0: 02 00 30 9a 33 32 31 33 34 31 34 36 30 36 20 20 ..0.3213 414606
00d0: 20 20 20 20 32 31 30 38 32 35 20 20 0c 00 67 6f 2108 25 ..go
00e0: 00 00 11 a4 10 ba 0e 88 54 80 a3 e0 04 3a 91 af ........ T....:..
00f0: c1 56 40 00 00 00 00 00 00 00 00 00 59 ba b1 4a .V@..... ....Y..J

/interface/ethernet> monitor 5
name: qsfp28-2-1
status: no-link
auto-negotiation: done
supported: 10M-baseT-half,10M-baseT-full,100M-baseT-half,100M-baseT-full,1000M-baseT-half,1000M-baseT-full,1000M-baseX,2.5G-baseT,2.5G-baseX,
5G-baseT,10G-baseT,10G-baseSR,10G-baseLR,10G-baseLRM,10G-baseER,10G-baseCR,40G-baseSR4,40G-baseLR4,40G-baseCR4,25G-baseSR,
25G-baseCR,100G-baseSR4,100G-baseLR4-ER4,100G-baseCR4
sfp-supported: 10G-baseLR,10G-baseER,25G-baseSR,100G-baseLR4-ER4
advertising: 10G-baseLR,10G-baseER,25G-baseSR,100G-baseLR4-ER4
link-partner-advertising:
sfp-module-present: yes
sfp-type: QSFP28/QSFP56
sfp-connector-type: LC
sfp-link-length-sm: 10km
sfp-vendor-name: FS
sfp-vendor-part-number: QSFP28-LR4-100G
sfp-vendor-revision: 01
sfp-vendor-serial: G1908173981
sfp-manufacturing-date: 20200615
sfp-wavelength: 1310nm
sfp-temperature: 46C
sfp-supply-voltage: 3.26V
sfp-tx-bias-current: 46mA
sfp-tx-power: 1.9dBm
sfp-rx-power: 0.061dBm
eeprom-checksum: good
eeprom: 0000: 11 00 00 00 00 0e 00 00 00 00 00 00 00 00 00 00 ........ ........
0010: 00 00 00 00 00 00 2e 31 00 00 7f 5b 00 00 00 00 .......1 ...[....
0020: 00 00 27 9f 28 b6 34 cf 27 dd 5a d1 00 00 00 00 ..'.(.4. '.Z.....
0030: 00 00 3c 81 00 01 00 01 00 01 00 00 00 00 00 00 ..<..... ........
0040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
0050: 00 00 00 00 00 00 0e 00 00 00 00 00 00 00 00 00 ........ ........
0060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
*
0080: 11 ce 07 80 00 00 00 00 00 00 00 03 ff 02 0a 00 ........ ........
0090: 00 00 00 64 46 53 20 20 20 20 20 20 20 20 20 20 ...dFS
00a0: 20 20 20 20 00 00 00 00 51 53 46 50 32 38 2d 4c .... QSFP28-L
00b0: 52 34 2d 31 30 30 47 20 30 31 66 58 01 c1 46 20 R4-100G 01fX..F
00c0: 03 00 3f f2 47 31 39 30 38 31 37 33 39 38 31 20 ..?.G190 8173981
00d0: 20 20 20 20 32 30 32 30 30 36 31 35 0c 08 67 35 2020 0615..g5
00e0: 00 00 08 2f bc 3e 30 bf e8 0c 30 51 be a3 6f 89 .../.>0. ..0Q..o.
00f0: 0c 27 02 00 00 00 00 00 00 00 00 00 c7 a7 20 13 .'...... ...... .
 
User avatar
loloski
Member
Member
Posts: 420
Joined: Mon Mar 15, 2021 9:10 pm

Re: v7.12beta [testing] is released!

Tue Aug 29, 2023 8:30 am

This is how it look like, same for 1036,RB4011 i'll try to netinstall them later if i can reproduce the issue
2.PNG
netinstall solved the terminal issue
 
txfz
Frequent Visitor
Frequent Visitor
Posts: 66
Joined: Tue Mar 10, 2020 9:02 am

Re: v7.12beta [testing] is released!

Tue Aug 29, 2023 10:20 am

Anyone elaborate on exactly what the terminal/ask parameters are? I can kinda figure it out, but it seems a little strange. prompt is simply a text line that's printed before the rest, preinput is a string that's preprended and fixed/prefilled to the input and included in the resulting value, and value-name is what I actually would call the prompt; the input (including preinput) goes directly after it. So using the command similarly to how other prompt commands work should involve only value-name.
> :local addr [/terminal/ask value-name="Enter IP address: "]; :put "Your IP address is $addr."
Enter IP address: 10.25.0.13
Your IP address is 10.25.0.13.
It was mentioned that a sensitive parameter also exists, but I can't see how that is used.
 
rpingar
Long time Member
Long time Member
Posts: 593
Joined: Fri May 28, 2004 2:46 pm
Location: Italy

Re: v7.12beta [testing] is released!

Tue Aug 29, 2023 5:13 pm

@rpingar, afink - thanks for the feedback. Can you also share the output from "/interface ethernet monitor" for thouse QSFP modules that do not work?
alpha137 doesn't fix the qsfp issue.

regards
 
rpingar
Long time Member
Long time Member
Posts: 593
Joined: Fri May 28, 2004 2:46 pm
Location: Italy

Re: v7.12beta [testing] is released!

Wed Aug 30, 2023 10:51 am

@rpingar, afink - thanks for the feedback. Can you also share the output from "/interface ethernet monitor" for thouse QSFP modules that do not work?
I have found the root cause of this behavior on 7.12beta or 7.12alpha.
It is related to sub-interfaces qsfp28-x-2/3/4 if they are disabled the main interface is not working propely, it is not able to come up.
To let the qsfp28-x-1 works you must have the subinterface enabled.

This thing is a redical change from 7.11 were subinterfaces were completely not influent on behavior of main interface.

hope to help other users about it.
regards
 
User avatar
afink
newbie
Posts: 35
Joined: Wed May 29, 2013 7:16 pm
Location: Basel & Freetown
Contact:

Re: v7.12beta [testing] is released!

Wed Aug 30, 2023 10:55 am

they are enabled in my case.
Last edited by afink on Wed Aug 30, 2023 11:16 am, edited 1 time in total.
 
rpingar
Long time Member
Long time Member
Posts: 593
Joined: Fri May 28, 2004 2:46 pm
Location: Italy

Re: v7.12beta [testing] is released!

Wed Aug 30, 2023 11:00 am

they are enabled on my case
check if fec are disabled on both side.

regards
 
User avatar
afink
newbie
Posts: 35
Joined: Wed May 29, 2013 7:16 pm
Location: Basel & Freetown
Contact:

Re: v7.12beta [testing] is released!

Wed Aug 30, 2023 11:18 am

fec is configured on switch and mikrotik using fec92 / rs . this is mandatory for link to come up in 7.11. Auto negotiation failed otherwise.
 
rpingar
Long time Member
Long time Member
Posts: 593
Joined: Fri May 28, 2004 2:46 pm
Location: Italy

Re: v7.12beta [testing] is released!

Wed Aug 30, 2023 11:21 am

fec is configured on switch and mikrotik using fec92 / rs . this is mandatory for link to come up in 7.11. Auto negotiation failed otherwise.
try to disable auto negotiation and fix the proper speed/mux at least on ccr2216
 
User avatar
afink
newbie
Posts: 35
Joined: Wed May 29, 2013 7:16 pm
Location: Basel & Freetown
Contact:

Re: v7.12beta [testing] is released!

Wed Aug 30, 2023 11:42 am

Switching off auto negotiation and configuring it for 100G-baseLR4-ER4 brought the interface up.
Interesting...
 
rpingar
Long time Member
Long time Member
Posts: 593
Joined: Fri May 28, 2004 2:46 pm
Location: Italy

Re: v7.12beta [testing] is released!

Wed Aug 30, 2023 11:45 am

Switching off auto negotiation and configuring it for 100G-baseLR4-ER4 brought the interface up.
Interesting...
welcome to the 100g qsfp world!! :DDDDDDDDDDDDDDDDD
 
msatter
Forum Guru
Forum Guru
Posts: 2941
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: v7.12beta [testing] is released!

Wed Aug 30, 2023 12:11 pm

...nothing changed. This is the FIRST thing to try when a (x)SFP's is not coming up in a Mikrotik.

I recommended in the past, to disable auto negotiation by default.
 
User avatar
afink
newbie
Posts: 35
Joined: Wed May 29, 2013 7:16 pm
Location: Basel & Freetown
Contact:

Re: v7.12beta [testing] is released!

Wed Aug 30, 2023 12:14 pm

except that you expect this on a new installation, not on something which worked before...
 
msatter
Forum Guru
Forum Guru
Posts: 2941
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: v7.12beta [testing] is released!

Wed Aug 30, 2023 4:19 pm

Yeah, but then it is still at the top of the checklist when working with SFP equipment in Mikrotik devices.
 
snowdogging
just joined
Posts: 22
Joined: Tue Dec 20, 2016 6:23 pm

Re: v7.12beta [testing] is released!

Wed Aug 30, 2023 5:29 pm

Thank you so much for fixing the bridge fast-path issue! I spent a whole day troubleshooting why no stateful sessions would work.

But now I am seeing a V2 OSPF problem. Connected NSSA records from a ptp interface are not being propagated to the routing table. They exist in the LSA table. I have to manually them as routes. Routes were automatically created in 7.11 so I think this is a new bug.
 
DeviceLocksmith
just joined
Posts: 24
Joined: Sat Jan 15, 2022 8:21 am

Re: v7.12beta [testing] is released!

Wed Aug 30, 2023 10:10 pm

I can confirm that FastTrack, which was broken for me on CCR2116 in 7.11 is fixed in 7.12beta3
 
killersoft
Member Candidate
Member Candidate
Posts: 263
Joined: Mon Apr 11, 2011 2:34 pm
Location: Victoria, Australia

Re: v7.12beta [testing] is released!

Thu Aug 31, 2023 1:31 am

*) wifiwave2 - enable changing interface MTU and L2MTU;
Now if you can only adjust the wireless MTU to 9000+ Bytes for bridging l2 networks for jumbo frame support(e.g MEF 3 carrier grade connections ) in ptp wireless setups :)
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Thu Aug 31, 2023 1:42 am

*) wifiwave2 - enable changing interface MTU and L2MTU;
Now if you can only adjust the wireless MTU to 9000+ Bytes for bridging l2 networks for jumbo frame support(e.g MEF 3 carrier grade connections ) in ptp wireless setups :)
It may let you set that... But still limited by 802.11 specs, so 2290 is max L2MTU.

RouterOS with wifiwave2 has let you set the MTU higher in config for a while — it just didn't do anything – and actual MTU used to max out at 1500 prior to this change.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Thu Aug 31, 2023 12:08 pm

I think the main use for >1500 byte MTU is not to bridge jumbo frames but to allow tunneling protocols to have some headroom to transport a 1500 byte MTU frame without fragmentation.
(e.g. EoIP, VXLAN etc can be used to work around the problem of missing 4-address mode)
 
User avatar
afink
newbie
Posts: 35
Joined: Wed May 29, 2013 7:16 pm
Location: Basel & Freetown
Contact:

Re: v7.12beta [testing] is released!

Thu Aug 31, 2023 12:16 pm

bigger MTUs can also help in having encrypted traffic being transported over longer distances in fewer packets.
If you have a endpoint which encrypts and can put multiple packets into a jumboframe, there will be less but bigger packet being sent. Hence the transit network has fewer routing decisions to take.
 
killersoft
Member Candidate
Member Candidate
Posts: 263
Joined: Mon Apr 11, 2011 2:34 pm
Location: Victoria, Australia

Re: v7.12beta [testing] is released!

Thu Aug 31, 2023 12:42 pm

I need to transport carrier grade ethernet(9000 byte frames) layer-2 traffic that is encrypted at layer2(macsec 802.11AE) as a backhaul using mikrotik's NV2 or NStream modes etc, not classic Wi-Fi mode(which everyone defaults to in these conversations) in a point to point bridge mode only...

Currently I have 2x NetMetal-5's with 30dBi's doing the L2 point to point bridge work in NV2 mode, but a new requirement has come up and now I need to transport jumbo frames, so I need to bin the netmetals and replace with either Cambium or Siklu equipment ( and sort band licensing with the local auth :( ).
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Thu Aug 31, 2023 2:35 pm

Yes, jumbo frames over 802.11 is a no-go. You will need to either fragment/reassemble them or find another wireless solution.
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Thu Aug 31, 2023 11:29 pm

In the build it's :tonsec NOT ":tosec", but seems to work:
:put [:tonsec [:timestamp]]                           
1692285621621
Why they did not name it just :toepoch then if it is sec or nsec would be covered.
It's in nanoseconds. So the "n" is nano, not number, of seconds.
:put ([:tonsec 1s]/1000000000)                                  
1    

And seconds from epoch is in:
:put [:tonum 1s]            
1
:put [:tonum [:timestamp]]
1693515184
 
User avatar
bpwl
Forum Guru
Forum Guru
Posts: 3124
Joined: Mon Apr 08, 2019 1:16 am

Re: v7.12beta [testing] is released!

Sat Sep 02, 2023 9:15 pm

4-address mode is not standard in 801.11. each manufacturer that offers it has implemented their own hacks to negotiate and support it,
That why I'm not sure using a tunnel isn't such a bad option. It does let you treat wireless same as wired, vs using Wi-Fi specific WDS-like things.

The bigger issue today with doing tunneling over wifiwave2 is the interface won't sent packets larger than 1500*, even if the MTU is set higher – so tunnels get fragmented.

* I don't have any wifiwave2 devices here to check specific in 7.12, so maybe it's fix, but been open 2 years.
I know it is old, very old, but the BCP allows for full 1500byte MTU in a tunneled connection which runs over links with smaller MTU. It is fragmented in transit, but the connection is delivered unfragmented between the bridges. Even the NetFlix algoritms didn't see that the traffic did pass a VPN tunnel, and their content can be forwarded, what could not be done over the normal VPN connection.. BCP is explained in the wiki for PPTP only, but it works with SSTP,L2TP and PPTP. Set MRRU to a higher value (eg 1600) to have the full unfragmented 1500bytes MTU. BCP is Intended for wireless, but I used it also over ethernet as tunnel, to forward NetFlix between different networks. (Netflix tries to detect a tunnel, and then says "something went wrong".) PPTP was faster than SSTP. It was internal in the local network, so security is not facing the public internet.

https://wiki.mikrotik.com/wiki/Manual:B ... _bridging)

HINT: setting the RSTP on the bridges was mandatory, or the BCP link did not appear.

PS ... who knows ... even jumbo frames ??? "MRRU allows to enable multi-link support over single link, it divides the packet to multiple channels therefore increasing possible MTU and MRU (up to 65535 bytes)"
 
buset1974
Frequent Visitor
Frequent Visitor
Posts: 86
Joined: Wed Sep 13, 2006 12:12 pm
Location: Jakarta

Re: v7.12beta [testing] is released!

Mon Sep 04, 2023 5:41 am

Can anyone in MT fix the VPLS de fragment on 7.12 please?

please see this topic for detail viewtopic.php?p=1022490#p1022490

thx
 
rplant
Long time Member
Long time Member
Posts: 537
Joined: Fri Sep 29, 2017 11:42 am

Re: v7.12beta [testing] is released!

Mon Sep 04, 2023 7:46 am

Another option for 9k frames over wifi is to use eoip.
You can make its frame size big and it becomes fairly efficient when they are big.

Then perhaps a bit of bridge filtering/policy routing, so the larger frames go over the wifi via the eoip tunnel,
while the smaller frames don't.
 
User avatar
afink
newbie
Posts: 35
Joined: Wed May 29, 2013 7:16 pm
Location: Basel & Freetown
Contact:

Re: v7.12beta [testing] is released!

Mon Sep 04, 2023 8:23 am

eoip and other tunneling protocols would only work if transporting routers along the path fragment packets on the way instead of rejecting and dropping it. on the fly fragmentation is cpu intensive and thus the method of dont fragment packets but inform the sender of a smaller mtu is mostly used (see path mtu discovery). The only exception where tunneling works is if you use tcp as transport where vpn packet boundaries dont reflect payload packet boundaries
 
jeetlal
just joined
Posts: 13
Joined: Mon Oct 08, 2018 8:14 pm

Re: v7.12beta [testing] is released!

Wed Sep 06, 2023 2:23 pm

macvlan documentation with example required
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Wed Sep 06, 2023 2:38 pm

eoip and other tunneling protocols would only work if transporting routers along the path fragment packets on the way instead of rejecting and dropping it.
This was mainly about transparent bridging across Wi-Fi point-to-point links. Issues with 3rd parties refusing to transport or fragment them do not apply in that case. You can see the point-to-point link as a /30 IP network with your own routers at the endpoints and a limited-MTU link in between. It is your own decision to use your routers to do fragment/reassemble. (or not to have the functionality)
 
killersoft
Member Candidate
Member Candidate
Posts: 263
Joined: Mon Apr 11, 2011 2:34 pm
Location: Victoria, Australia

Re: v7.12beta [testing] is released!

Thu Sep 07, 2023 1:34 am

Why in IPv6 DHCP server POOL option do I get a double static-only entry's listed:
ipv6 dhcp server pool issue.png
You do not have the required permissions to view the files attached to this post.
 
mducharme
Trainer
Trainer
Posts: 1777
Joined: Tue Jul 19, 2016 6:45 pm
Location: Vancouver, BC, Canada

Re: v7.12beta [testing] is released!

Thu Sep 07, 2023 4:57 am

Why in IPv6 DHCP server POOL option do I get a double static-only entry's listed:
That's been showing up that way for a while and isn't related specifically to this beta.
 
User avatar
Jotne
Forum Guru
Forum Guru
Posts: 3343
Joined: Sat Dec 24, 2016 11:17 am
Location: Magrathean

Re: v7.12beta [testing] is released!

Thu Sep 07, 2023 7:44 am

If no one make a support case out of it, it will possible stay like this.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Thu Sep 07, 2023 11:14 am

If no one make a support case out of it, it will possible stay like this.
It happens here too, so it will probably be easy to reproduce (my config has a pool from DHCPv6 client but in addition it lists static-only twice).
 
Kevdevon
just joined
Posts: 13
Joined: Fri Jul 07, 2023 12:55 pm

Re: v7.12beta [testing] is released!

Sat Sep 09, 2023 2:54 pm

Mikrotik Audience, WAN2 stops working randomly, could be days or weeks.
Disabling and re-enabling resolves the issues until the next occurrence.
 
User avatar
Cha0s
Forum Guru
Forum Guru
Posts: 1160
Joined: Tue Oct 11, 2005 4:53 pm

Re: v7.12beta [testing] is released!

Sun Sep 10, 2023 10:50 pm

Today, after 17days of uptime, snmp started acting up on a CCR2004.
iso.3.6.1.2.1.4.24.4.1.1.185.X.Y.Z.255.255.255.255.0.10.26.35.2 = IpAddress: 185.X.Y.Z
iso.3.6.1.2.1.4.24.4.1.1.185.X.Y.Z.255.255.255.255.0.0.0.0.0 = IpAddress: 185.X.Y.Z
Error: OID not increasing: iso.3.6.1.2.1.4.24.4.1.1.185.X.Y.Z.255.255.255.255.0.10.26.35.2
 >= iso.3.6.1.2.1.4.24.4.1.1.185.X.Y.Z.255.255.255.255.0.0.0.0.0
After a reboot, the issue persists.

When running snmpwalk, it is really slow when processing the routing table (~650routes in total).
At the same time, the routing process takes up 100% of a CPU core until it reaches to the above error.

If I run snmpwalk with -Cc to ignore the oid not increasing, it slowly reaches the problematic prefix, and then it spews out countless times per second the same line
iso.3.6.1.2.1.4.24.4.1.1.185.X.Y.Z.255.255.255.255.0.0.0.0.0 = IpAddress: 185.X.Y.Z
iso.3.6.1.2.1.4.24.4.1.1.185.X.Y.Z.255.255.255.255.0.0.0.0.0 = IpAddress: 185.X.Y.Z
iso.3.6.1.2.1.4.24.4.1.1.185.X.Y.Z.255.255.255.255.0.0.0.0.0 = IpAddress: 185.X.Y.Z
iso.3.6.1.2.1.4.24.4.1.1.185.X.Y.Z.255.255.255.255.0.0.0.0.0 = IpAddress: 185.X.Y.Z
At the same time, the snmp process does ~2mbps traffic and takes up 60-70% CPU on one core.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Mon Sep 11, 2023 11:16 am

Well, maybe you noticed it only now because you were debugging things, but that "OID not increasing" is a bug that has been present for a long time.
Maybe there are other problems now as well...?
 
holvoetn
Forum Guru
Forum Guru
Posts: 6762
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: v7.12beta [testing] is released!

Mon Sep 11, 2023 11:34 am

Cha0s,
can you please create supout.rif and shoot ticket to support with all accompanying info required to reproduce this behavior ?
Otherwise it might still be a known bug in version 7.25.6...
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Mon Sep 11, 2023 12:13 pm

One way of reproducing this is to have multiple route tables. The SNMP OID does not really provide for that, and it seems RouterOS just merges the output for the different tables which disturbs the sorting and thus the increasing of the OID in walk.
 
holvoetn
Forum Guru
Forum Guru
Posts: 6762
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: v7.12beta [testing] is released!

Tue Sep 12, 2023 12:36 pm

mAP - 7.12beta3
when trying to open terminal via winbox connected via ROMON
terminal is not a TTY
died with signal 11 on Tue Sep 12 09:33:36 2023
Connecting via Winbox / WG does allow terminal to be opened.
It worked before on 7.11.2.

Supout created, support contacted (SUP-127788).
 
holvoetn
Forum Guru
Forum Guru
Posts: 6762
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: v7.12beta [testing] is released!

Tue Sep 12, 2023 3:31 pm

Additional info:
no such problem on RB5009, AX2, AX3.
mAP and cAP Lite do have this problem, both are mipsbe. Coincidence ?
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 21904
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: v7.12beta [testing] is released!

Tue Sep 12, 2023 4:31 pm

Additional info:
no such problem on RB5009, AX2, AX3.
mAP and cAP Lite do have this problem, both are mipsbe. Coincidence ?
We dont have insight into the testers lab but you may have provided a clue to what they dont use for testing ;-)
MTs way of passively aggressively discontinuing support for products but not stating it clearly, be it anything !ARM LOL.
Otherwise of course, we would get zerotrust cloudflare as an options package for all routers!!
Last edited by holvoetn on Wed Sep 13, 2023 8:59 am, edited 1 time in total.
Reason: Corrected title
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Tue Sep 12, 2023 5:45 pm

The "new devices" listing on the hardware page has a MIPSBE device, with 16MB flash even.
 
holvoetn
Forum Guru
Forum Guru
Posts: 6762
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 8:58 am

mAP - 7.12beta3
when trying to open terminal via winbox connected via ROMON
terminal is not a TTY
died with signal 11 on Tue Sep 12 09:33:36 2023
Connecting via Winbox / WG does allow terminal to be opened.
It worked before on 7.11.2.

Supout created, support contacted (SUP-127788).
Feedback from support:
issue has been identified and already solved in next 7.12beta version (not yet released).
 
EdPa
MikroTik Support
MikroTik Support
Topic Author
Posts: 340
Joined: Fri Sep 15, 2017 10:05 am
Location: Riga
Contact:

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 3:43 pm

What's new in 7.12beta7 (2023-Sep-13 09:58):

!) ethernet - changed "advertise" and "speed" arguments, and removed "half-duplex" setting under "/interface ethernet" menu;
!) sfp - convert configuration to support new link modes for SFP and QSFP type of interfaces;
*) api - fixed fetching objects with warning option from REST API;
*) bgp - implemented IGP metric sending in BGP messages;
*) bluetooth - use "g" units when decoding MikroTik beacon acceleration on peripheral devices menu;
*) certificate - allow to remove issued certificates when CRL is not used;
*) certificate - fixed certificate auto renewal via SCEP;
*) chr - iavf updated driver to 4.9.1 version;
*) console - improved randomness for ":rndstr" and ":rndnum" commands;
*) console - improved stability when using "special-login";
*) console - improved system stability through RoMON session;
*) console - improved system stability when using autocomplete;
*) dhcp - fixed DHCP server "authoritative" and "delay-threshold" settings (introduced in v7.12beta3);
*) ike2 - improved rekey collision handling;
*) ipsec - fixed Diffie-Hellman public value encoding size;
*) ipsec - fixed minor typo in logs;
*) ipsec - reduce disk writes when started without active configuration;
*) ipv6 - send RA and RA deprecate messages out three times instead of just once;
*) l3hw - improved system stability during IPv6 route offloading;
*) leds - added "dark-mode" functionality for RBwAPG-5HacD2HnD;
*) leds - added "wireless-status" and "wireless-signal-strength" configuration types for wifiwave2 interfaces;
*) log - improved logging for user actions;
*) lte - fixed 5G data-class reporting for Chateau 5G;
*) lte - fixed APN authentification in multi APN setup for R11e-LTE6;
*) lte - fixed IPv6 prefix for MBIM modems in multi-apn setup when IPv6 APN used as not first APN;
*) lte - fixed RSSI for FG621-EA modem to show the correct value;
*) lte - fixed startup race condition when SIM card is in "up" slot for LtAP mini;
*) mpls - improved FastPath next-hop selection hash algorithm;
*) netinstall-cli - added empty configuration option "-e";
*) netwatch - decreased "thr-tcp-conn-time" maximum limit to 30 seconds;
*) ovpn - improved system stability;
*) pimsm - improved system stability;
*) qsfp - added 50Gbps rate support for QSFP28 interfaces;
*) qsfp - fixed sub-interface EEPROM monitor data output (introduced in v7.12beta3);
*) qsfp - improved auto link detection for 100G CWDM4 modules and AOC cables (introduced in v7.12beta3);
*) qsfp - use sub-interface configuration for establishing link (for 40Gbps and 100Gbps links, all sub-interfaces must be enabled);
*) routerboard - added "reset-button" support for RB800 and RB1100 devices;
*) ssh - improved connection stability when pasting large chunks of text into console;
*) supout - added interface list members section;
*) switch - improved resource allocation for 98DX224S, 98DX226S, and 98DX3236 switch chips;
*) traffic-generator - fixed traffic-generator on CHR and x86;
*) usb - added support for RTL8153 USB ethernet on ARM, ARM64 and x86;
*) vrf - limit maximum VRFs to 1024;
*) vxlan - improved system stability for Tile devices;
*) webfig - fixed "Days" property configuration change under "IP/Firewall" menu;
*) webfig - fixed timezone for interface "Last Link Down/Up Time";
*) webfig - improved Webfig performance and responsiveness;
*) webfig - try to re-establish connection after disconnect;
*) wifiwave2 - added an alternative QoS priority assignment mechanism based on IP DSCP (CLI only);
*) wifiwave2 - added station-bridge interface mode (CLI only);
*) wifiwave2 - do not show default "l2mtu" on compact export;
*) wifiwave2 - fixed PTK renewal for interfaces in station mode;
*) wifiwave2 - fixed sniffer command not receiving any QoS null function frames when using 802.11ax radios;
*) wifiwave2 - fixed untagged VLAN 1 entry when using "vlan-id" setting together with vlan-filtering bridge;
*) wifiwave2 - fixed warning on CAP devices when radar detected;
*) wifiwave2 - implemented an option to transmit IP multicast packets as unicasts (CLI only);
*) wifiwave2 - improved compliance with regulatory requirements;
*) wifiwave2 - make 4-way handshake procedure more robust when acting as supplicant (client);
*) winbox - added "Comment" under "Routing/BFD/Configuration" menu;
*) winbox - added "g" flag under "IPv6/Routes" menu;
*) winbox - added "Name Format" property under "WifiWave2/Provisioning" menu;
*) winbox - changed "MBR Partition Table" checkbox to unchecked by default under "System/Disks/Format-Drive" menu;
*) winbox - fixed "Address" property under "WifiWave2/Remote-CAP" menu;
*) winbox - fixed "Group Key Update" maximum value under "WifiWave2/Security" menu;
*) winbox - fixed entry numbering and ordering under "WifiWave2/Provisioning" menu;
*) winbox - fixed minor typos;
*) wireguard - allow to specify client settings under peer menu which will be included in configuration file and QR code;
*) wireguard - generate Wireguard peer keys and preshared-key automatically, if value is specified but is not base64 string;
*) wireguard - removed "wg-add-client" configuration wizard (introduced in v7.12beta3);
*) wireless - added more "radius-mac-format" options (CLI only);
*) www - fixed allowed address setting for REST API users;
*) www - fixed fragmented POST data for SCEP service;
*) x86 - i40e updated driver to 2.23.17 version;
*) x86 - igc updated driver to 5.10.194 version;
*) x86 - ixgbe updated driver to 5.19.6 version;
*) x86 - Realtek r8169 updated driver;
 
Simonej
Frequent Visitor
Frequent Visitor
Posts: 60
Joined: Sun Aug 22, 2021 3:34 am

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 4:12 pm

What's new in 7.12beta7 (2023-Sep-13 09:58):

*) wifiwave2 - added station-bridge interface mode (CLI only);
OMG!!!
 
holvoetn
Forum Guru
Forum Guru
Posts: 6762
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 4:20 pm

What's new in 7.12beta7 (2023-Sep-13 09:58):

*) wifiwave2 - added station-bridge interface mode (CLI only);
OMG!!!
Indeed. That was also the first thing which catched my eye ...
 
gigabyte091
Forum Guru
Forum Guru
Posts: 1523
Joined: Fri Dec 31, 2021 11:44 am
Location: Croatia

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 4:25 pm

That's a lot of changes... good job Mikrotik
 
User avatar
pekr
Member Candidate
Member Candidate
Posts: 170
Joined: Tue Feb 22, 2005 9:05 pm
Location: Czech Republic
Contact:

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 4:34 pm

Can we say, that Station bridge, having two hAP ax2, can serve a repeater purpose?
 
yottabit
Member Candidate
Member Candidate
Posts: 198
Joined: Thu Feb 21, 2013 5:56 am

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 4:48 pm

How long are my 10+ months old hAP ax2s going to be stored in a drawer, because ROS 7 still does not support repeater mode? Tonnes of new features, but still not fully on parity with ROS 6.
I have been waiting for this too, so that I can use the Audience with wifiwave2 and wireless mesh. It looks like it has been added finally with this beta!
* wifiwave2 - added station-bridge interface mode (CLI only);
I am not at the location where I have the Audience devices in use, but I will try it out when I get there in a couple weeks.

MikroTik: is this expected to work in an upgrade from the regular wireless package to the wifiwave2 package? In other words, if I upgrade to this beta first, will the Audience wireless mesh config automatically work if I upgrade to wifiwave2?
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 12980
Joined: Thu Mar 03, 2016 10:23 pm

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 4:59 pm

Can we say, that Station bridge, having two hAP ax2, can serve a repeater purpose?

I'd say that not just yet. We still need ap-bridge mode ... But you can use one ax2 as station-bridge when AP is running legacy wireless driver (e.g. ac2).
 
markonen
newbie
Posts: 31
Joined: Tue Aug 11, 2020 4:28 pm

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 5:01 pm

qsfp - use sub-interface configuration for establishing link (for 40Gbps and 100Gbps links, all sub-interfaces must be enabled);
This looks like something that will affect me. Currently I've only enabled the -1 interface for each QSFP28 port and explicitly disabled -2, -3 and -4. Sounds like my config would no longer link up at 100G, is that right? The other subinterfaces must just be left enabled, with no other configuration necessary?
 
Guntis
MikroTik Support
MikroTik Support
Posts: 203
Joined: Fri Jul 20, 2018 1:40 pm

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 5:01 pm

The station-bridge mode works together with the AP mode, there is no need for a new type of AP mode. The WifiWave2 station-bridge is only compatible with WifiWave2 APs.
Audience configuration won't be automatically converted in this case.
 
Kevdevon
just joined
Posts: 13
Joined: Fri Jul 07, 2023 12:55 pm

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 5:24 pm

The station-bridge mode works together with the AP mode, there is no need for a new type of AP mode. The WifiWave2 station-bridge is only compatible with WifiWave2 APs.
Audience configuration won't be automatically converted in this case.
Is this the preferred setup for Capsman? Or do we still connect as a station?
I'm about to set this up today, would be nice to have a play and experiment.
 
yottabit
Member Candidate
Member Candidate
Posts: 198
Joined: Thu Feb 21, 2013 5:56 am

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 5:45 pm

The station-bridge mode works together with the AP mode, there is no need for a new type of AP mode. The WifiWave2 station-bridge is only compatible with WifiWave2 APs.
Audience configuration won't be automatically converted in this case.
That's a bummer on two fronts.

1. I don't see why the upgrade to wifiwave2 couldn't automatically convert the working mesh config already present.

2. I also use old netmetal 5 and hap ac in station-bridge mode to connect to the Audience, but those don't support wifiwave2. So I guess I'm screwed and have to use legacy wireless package on Audience forever?
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 7:16 pm

Audience configuration won't be automatically converted in this case.
So I guess I'm screwed and have to use legacy wireless package on Audience forever?
Well, your hAPac and cAPac owners with the hardware, got screwed by the wifiwave2 package size long ago ;)
And CAPsMAN is already incompatible between wifiwave2 and older..

So bridging drivers... seems a bridge too far.
 
marekm
Member
Member
Posts: 416
Joined: Tue Feb 01, 2011 11:27 pm

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 7:37 pm

Please, any chance to make the station-bridge mode compatible over the air between different generations of devices?
In both directions - connect older N/AC station-bridge to new AX ap-bridge, or connect new AX station-bridge to older N/AC ap-bridge.
Even if sub-optimal (using only N/AC data rates), it would help to migrate existing networks - no need to replace everything at the same time.
I can see it may be too difficult to implement nstreme/nv2 protocols with wifiwave2, but just 802.11 (with bridge/WDS extensions) will do.
Bonus points if you can make it compatible with UBNT M5 series (802.11n) stations - they work fine with old MT N/AC APs with WDS static mesh mode.
Not asking about UBNT AC stations as then they started the proprietary vendor lock-in game and can only talk to UBNT APs, nothing else.
Also not asking for compatibility with old A/G devices, most of them long gone but N/AC are still widely used.
Historically, MT has always been very good at such over the air compatibility - please continue this tradition with wifiwave2 too.
 
yottabit
Member Candidate
Member Candidate
Posts: 198
Joined: Thu Feb 21, 2013 5:56 am

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 7:46 pm

I'm getting very close to selling all my MikroTik APs and going to Ruckus for wireless. I'll still use MikroTik for routing, though.

MikroTik wireless is flexible, but just not performant. And this wifiwave2 business is looking to be the last nail in the coffin for me. I've been waiting for years, and now we finally have station-bridge, only for me to find out here that we can't interop wireless station-bridge to wifiwave2 ap mode? So now my capsman wireless bridge setup between 2x Audience, 1x hap ac, and 1x netmetal 5 will be hindered to use the legacy wireless package on the Audience forever. Correct me if I'm wrong, but otherwise I'm in the market to dump MikroTik wireless for something else known to be much more performant since I would have to replace two of my MikroTik APs just to get wifiwave2.
 
blacksnow
Frequent Visitor
Frequent Visitor
Posts: 56
Joined: Wed Feb 15, 2023 4:46 pm

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 8:03 pm

Definitely appreciate the hard work on this testing release. Unfortunately, DHCP IPv4 client fails to find or bind (remains in the searching state permanently) after upgrading, this is on my CCR-2216. Had to downgrade back to beta3 version.
 
Simonej
Frequent Visitor
Frequent Visitor
Posts: 60
Joined: Sun Aug 22, 2021 3:34 am

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 9:07 pm

@yottabit this is little bit OT but, MT is pushing hard on Wifiwave2, like station-bridge was unexpected implementation, it's clear from a long time that legacy and new driver are incompatible (or they don't have enough resources to make it working).
Based on my recent experience, wireless devices are OK for enthusiasts and decent for business, if you always take care of keep up to date with changelog and fixing issues with clients.
Want something that simply works? MT devices are not for you, at least for now.

Complain will not help, appreciate the improvements, it is what it is...
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 9:11 pm

Please, any chance to make the station-bridge mode compatible over the air between different generations of devices?
bridge mode is already incompatible between manufacturers. basically you have to see wifiwave2 devices as a different manufacturer.
when you require transparent bridging over different models/manufacturers devices, look at the possibility of adding a tunnel layer on top of a normal wifi connection, as explained elsewhere in this and other topics.
 
holvoetn
Forum Guru
Forum Guru
Posts: 6762
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 9:17 pm

*) wifiwave2 - added station-bridge interface mode (CLI only);
... it simply works 8)

AX Lite (LTE, but disabled that itf for this test), connected in station mode to AX3 with SSID on VLAN.
Via CLI changed mode to station-bridge.
AX Lite interfaces in bridge, DHCP client on bridge.
Bridge gets IP lease in correct subnet.
PC connected via ethernet to AX Lite gets correct IP.
Iperf3 test from PC to NAS with iperf container: +-400 Mbps (which is the expected result for AX Lite wifi)

Didn't touch AX3 config at all.
It simply works.
 
holvoetn
Forum Guru
Forum Guru
Posts: 6762
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 9:21 pm

Complain will not help, appreciate the improvements, it is what it is...
Agree.
There was a time we only had 2.4GHz wifi.
Is everyone also going to complain when wifi7 comes out because wifi6/5/4/... can not be used anymore then in combination with those devices ?

Deal with the cards which have been given.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 9:44 pm

Again I had the problem that my RB4011 hangs during update. It appears to happen "after some uptime" only. It was running 7.12beta3 for 20 days, I did the update, and it shuts down but does not perform the update. Of the 10 ethernet ports, only the LED on port 10 remains on. That one is doing PoE to a LHG XL.
After powercycling the router reboots but is still at the previous version, repeating the procedure makes it work OK.
The log (there is logging to a file) shows absolutely nothing between the last log lines before the reboot and "router rebooted", when it works OK the package install log is shown there.
No idea how to debug this, maybe next time I'll disable ether10 before upgrade.
 
marekm
Member
Member
Posts: 416
Joined: Tue Feb 01, 2011 11:27 pm

Re: v7.12beta [testing] is released!

Wed Sep 13, 2023 11:01 pm

bridge mode is already incompatible between manufacturers. basically you have to see wifiwave2 devices as a different manufacturer.
when you require transparent bridging over different models/manufacturers devices, look at the possibility of adding a tunnel layer on top of a normal wifi connection, as explained elsewhere in this and other topics.
There is some compatibility "over the air" between MT and UBNT, and MT should certainly be able to make their own products compatible with itself. Tunnels have their own issues, such as MTU overhead. In my small WISP network (mix of UBNT, MT and Cambium radios) I can easily bridge even slightly larger "mini jumbo" frames - RFC4638 PPPoE over VLAN just works, no fragmentation. It's a pity that WDS/bridge has not been made an official WiFi standard even after all these years, it's an useful feature in widespread use.
 
User avatar
FToms
MikroTik Support
MikroTik Support
Posts: 90
Joined: Fri Jul 24, 2020 3:28 pm

Re: v7.12beta [testing] is released!

Thu Sep 14, 2023 8:28 am

I also use old netmetal 5 and hap ac in station-bridge mode to connect to the Audience, but those don't support wifiwave2. So I guess I'm screwed and have to use legacy wireless package on Audience forever?
You can configure an L2 tunnel (EoIP, for example) to run on the wireless link, then bridge that tunnel on the AP and the station.
It's more complicated to set up and the performance won't be as good, but doable in principle.
 
serogo
just joined
Posts: 2
Joined: Thu Aug 10, 2023 8:53 pm

Failed to create the L2TP Server Binding interface

Thu Sep 14, 2023 10:59 am

Failed to create the L2TP Server Binding interface

Router OS version: 7.12beta7
Steps for reproduce:
1) Open router webfig web interface. Lead to menu: Interfaces > [Add New] - select option L2TP Server Binding.
2) Set "name" and "username" (optional)
3) Click to save.
4) It show an error: "Couldn't add New Interface - unsupported device type (6)"

Expect the interface to be created and it can bed used it in IP > Routes
Last edited by serogo on Thu Sep 14, 2023 12:26 pm, edited 2 times in total.
 
User avatar
Ullinator
just joined
Posts: 17
Joined: Tue Jun 08, 2021 12:53 pm
Location: North-West Germany

Re: v7.12beta [testing] is released!

Thu Sep 14, 2023 12:27 pm

Update from 7.12Beta3 to Beta7 went smooth on all my devices. Uptime now >20h.
No new problems detected.
hc_049.jpg
@new AP and Bridge mode: I can´t understand when MT implements a new feature in the WifiWave2 package some of your guys start grumbling why this new feature can´t do this and that also.
Instead to be glad that MT hasn´t finished the journey in development. :-)
You do not have the required permissions to view the files attached to this post.
 
User avatar
pekr
Member Candidate
Member Candidate
Posts: 170
Joined: Tue Feb 22, 2005 9:05 pm
Location: Czech Republic
Contact:

Re: v7.12beta [testing] is released!

Thu Sep 14, 2023 2:23 pm

I'm getting very close to selling all my MikroTik APs and going to Ruckus for wireless. I'll still use MikroTik for routing, though.

MikroTik wireless is flexible, but just not performant. And this wifiwave2 business is looking to be the last nail in the coffin for me. I've been waiting for years, and now we finally have station-bridge, only for me to find out here that we can't interop wireless station-bridge to wifiwave2 ap mode? So now my capsman wireless bridge setup between 2x Audience, 1x hap ac, and 1x netmetal 5 will be hindered to use the legacy wireless package on the Audience forever. Correct me if I'm wrong, but otherwise I'm in the market to dump MikroTik wireless for something else known to be much more performant since I would have to replace two of my MikroTik APs just to get wifiwave2.
Will you install completly different generations of Ruckus, to be on pair with your MT complaints? If you are ready to buy new Ruckus-everything, go scrap your old MT stuff and go wifiwave ax full-force too?
 
yottabit
Member Candidate
Member Candidate
Posts: 198
Joined: Thu Feb 21, 2013 5:56 am

Re: v7.12beta [testing] is released!

Thu Sep 14, 2023 3:38 pm

Will you install completly different generations of Ruckus, to be on pair with your MT complaints? If you are ready to buy new Ruckus-everything, go scrap your old MT stuff and go wifiwave ax full-force too?
My point was that if I'm going to have to buy new MikroTik APs to get better performance, I may as well buy Ruckus instead since they dramatically outperform MikroTik in speed and coverage.

In one location I already replaced 3 MikroTik full-power/gain APs with a single Ruckus and I have the same coverage and faster speeds. It's well known in the industry that Ruckus has the best coverage of all vendors, and nearly the fastest (I think Aruba was faster at short range, iirc).

Ruckus supports wireless bridge, which is what I really need at the other location where I'm currently using 4 MikroTik APs. And they allow setting DTIM to help with mobile power saving, which almost all vendors except MikroTik have supported for ages. This particular feature has been requested from MikroTik as far back as I can remember, and I started using MikroTik around 15 years ago. I've installed hundreds of MikroTik routers and APs in homes and businesses, but I think it's time to move on from the wireless side unless cost is the most important factor. But I digress.
 
User avatar
pekr
Member Candidate
Member Candidate
Posts: 170
Joined: Tue Feb 22, 2005 9:05 pm
Location: Czech Republic
Contact:

Re: v7.12beta [testing] is released!

Thu Sep 14, 2023 6:06 pm

Will you install completly different generations of Ruckus, to be on pair with your MT complaints? If you are ready to buy new Ruckus-everything, go scrap your old MT stuff and go wifiwave ax full-force too?
My point was that if I'm going to have to buy new MikroTik APs to get better performance, I may as well buy Ruckus instead since they dramatically outperform MikroTik in speed and coverage.

In one location I already replaced 3 MikroTik full-power/gain APs with a single Ruckus and I have the same coverage and faster speeds. It's well known in the industry that Ruckus has the best coverage of all vendors, and nearly the fastest (I think Aruba was faster at short range, iirc).

Ruckus supports wireless bridge, which is what I really need at the other location where I'm currently using 4 MikroTik APs. And they allow setting DTIM to help with mobile power saving, which almost all vendors except MikroTik have supported for ages. This particular feature has been requested from MikroTik as far back as I can remember, and I started using MikroTik around 15 years ago. I've installed hundreds of MikroTik routers and APs in homes and businesses, but I think it's time to move on from the wireless side unless cost is the most important factor. But I digress.
Once again - you are using crapload of mixed generation of devices and complain. Throw it out and stick to wifivave2, as it will improve over time. Noone's going to fix the old stuff.

And btw - we use Aruba at work, 11 locations. Don't get me even started upon multiple generations of those devices not being operable together with various firmware generations.
 
buset1974
Frequent Visitor
Frequent Visitor
Posts: 86
Joined: Wed Sep 13, 2006 12:12 pm
Location: Jakarta

Re: v7.12beta [testing] is released!

Fri Sep 15, 2023 5:30 am

version 7 was an anti-climax for Mikrotik, not as expected.
 
Network5
newbie
Posts: 30
Joined: Sat Mar 22, 2014 11:42 pm

Re: v7.12beta [testing] is released!

Fri Sep 15, 2023 8:57 am

I have some TCP performance issue on a CCR2004 (Router B) running 7.12beta3 and beta7, but just on forwarding plane.

This is the result of a simple speed test to and from the router itself:
Router A (CCR2216) <-> Router B (CCR2004)
status: done
time-remaining: 0s
ping-min-avg-max: 9.44ms / 9.49ms / 9.81ms
jitter-min-avg-max: 0s / 33us / 343us
loss: 0% (0/200)
tcp-download: 801Mbps local-cpu-load:19%
tcp-upload: 947Mbps local-cpu-load:18% remote-cpu-load:9%
udp-upload: 959Mbps local-cpu-load:15% remote-cpu-load:8%

Router B (CCR2004) <-> Router C (CCR2004)
status: done
time-remaining: 0s
ping-min-avg-max: 366us / 420us / 911us
jitter-min-avg-max: 0s / 48us / 523us
loss: 0% (0/200)
tcp-download: 583Mbps local-cpu-load:14%
tcp-upload: 690Mbps local-cpu-load:15% remote-cpu-load:57%
udp-download: 639Mbps local-cpu-load:6% remote-cpu-load:59%
udp-upload: 695Mbps local-cpu-load:12% remote-cpu-load:59%

And finally Router A (CCR2216) <-> Router C (CCR2004)
status: done
time-remaining: 0s
ping-min-avg-max: 9.78ms / 9.87ms / 10.4ms
jitter-min-avg-max: 0s / 96us / 609us
loss: 0% (0/200)
tcp-download: 501Mbps local-cpu-load:37%
tcp-upload: 23.0Mbps local-cpu-load:21% remote-cpu-load:8%
udp-download: 590Mbps local-cpu-load:8% remote-cpu-load:11%
udp-upload: 660Mbps local-cpu-load:22% remote-cpu-load:11%

Anyone having similar issues?
 
User avatar
Jotne
Forum Guru
Forum Guru
Posts: 3343
Joined: Sat Dec 24, 2016 11:17 am
Location: Magrathean

Re: v7.12beta [testing] is released!

Fri Sep 15, 2023 9:52 am

version 7 was an anti-climax for Mikrotik, not as expected.
Stupid comment without telling why.
I do find this thread about your problem, but do not see any support number on the problem.
viewtopic.php?t=194895
Forum only will not solve it.

For me and many other v7 works fine.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Fri Sep 15, 2023 10:25 am

I have some TCP performance issue on a CCR2004 (Router B) running 7.12beta3 and beta7, but just on forwarding plane.
You say forwarding but then you are testing from router to router?
To test forwarding performance, put an end-system (e.g. a PC) at each end behind the routers, and test between the PCs.
E.g. running iperf3 on each of them.
 
ToTheFull
Member
Member
Posts: 402
Joined: Fri Mar 24, 2023 3:24 pm

Re: v7.12beta [testing] is released!

Fri Sep 15, 2023 11:18 am

I have some TCP performance issue on a CCR2004 (Router B) running 7.12beta3 and beta7, but just on forwarding plane.



Anyone having similar issues?
No, how far away is that router 10ms?

status: done
time-remaining: 0s
ping-min-avg-max: 192us / 242us / 524us
jitter-min-avg-max: 0s / 29us / 279us
loss: 0% (0/200)
tcp-download: 927Mbps local-cpu-load:93%
tcp-upload: 920Mbps local-cpu-load:62% remote-cpu-load:57%
udp-download: 944Mbps local-cpu-load:41% remote-cpu-load:42%
udp-upload: 957Mbps local-cpu-load:55% remote-cpu-load:29%

cAP ax >> Hap ax


status: done
time-remaining: 0s
ping-min-avg-max: 168us / 227us / 509us
jitter-min-avg-max: 0s / 38us / 295us
loss: 0% (0/200)
tcp-download: 932Mbps local-cpu-load:64%
tcp-upload: 934Mbps local-cpu-load:42% remote-cpu-load:84%
udp-download: 943Mbps local-cpu-load:26% remote-cpu-load:58%
udp-upload: 955Mbps local-cpu-load:36% remote-cpu-load:48%
 
ToTheFull
Member
Member
Posts: 402
Joined: Fri Mar 24, 2023 3:24 pm

Re: v7.12beta [testing] is released!

Fri Sep 15, 2023 11:19 am

...
Last edited by ToTheFull on Fri Sep 15, 2023 11:22 am, edited 2 times in total.
 
dazmatic
just joined
Posts: 15
Joined: Fri May 05, 2023 9:25 pm

Re: v7.12beta [testing] is released!

Fri Sep 15, 2023 11:20 am

FYI - Fibocom NL952 modem stopped working in 7.12 beta.

going back to stable appears to have resolved it.
 
mszru
Frequent Visitor
Frequent Visitor
Posts: 92
Joined: Wed Aug 10, 2016 10:42 am

Re: v7.12beta [testing] is released!

Fri Sep 15, 2023 1:16 pm

hAPac2 failed to boot normally after the RouterBOOT upgrade from 7.11.2 to 7.12beta7.

I had to reset it via Reset button and then it booted without any default configuration. At the end I've downgraded to 7.11.2 and restored the backup.
 
Network5
newbie
Posts: 30
Joined: Sat Mar 22, 2014 11:42 pm

Re: v7.12beta [testing] is released!

Fri Sep 15, 2023 8:30 pm

I have some TCP performance issue on a CCR2004 (Router B) running 7.12beta3 and beta7, but just on forwarding plane.
You say forwarding but then you are testing from router to router?
To test forwarding performance, put an end-system (e.g. a PC) at each end behind the routers, and test between the PCs.
E.g. running iperf3 on each of them.
The router that I'm having issues with is router B, the one in the middle, which is running 7.12beta7. The other two are running 7.10.2. I was testing from router to router to actually see if there are issues on links. The last measurement is end to end, and the CCR (Router B) is the only router in the middle. These are two segments of our core network.

The link with 10ms is a L2 link, approximately 500km long.
 
User avatar
afink
newbie
Posts: 35
Joined: Wed May 29, 2013 7:16 pm
Location: Basel & Freetown
Contact:

Re: v7.12beta [testing] is released!

Sat Sep 16, 2023 12:45 pm

What's new in 7.12beta7 (2023-Sep-13 09:58):

!) sfp - convert configuration to support new link modes for SFP and QSFP type of interfaces;
*) qsfp - added 50Gbps rate support for QSFP28 interfaces;
*) qsfp - fixed sub-interface EEPROM monitor data output (introduced in v7.12beta3);
*) qsfp - improved auto link detection for 100G CWDM4 modules and AOC cables (introduced in v7.12beta3);
*) qsfp - use sub-interface configuration for establishing link (for 40Gbps and 100Gbps links, all sub-interfaces must be enabled);
Forgotten line:

*) sfp - broke negotiation of working SFP28 completly. Now we can not even find any combination of setting to get SFP28 to work. We had several CCR2004 which we could only revive by doing a downgrade to 7.11.2. Downgrading to 7.12beta3 would also have worked but you can't download that release anymore.

*) qsfp - didnt fix auto-negotiation of QSFP28 transceiver and AOC cables. While in 7.11.2, autonegotiation works, in 7.12beta3 it needed manual settings. In 7.12beta7 this is still the case, despite above claim.
 
User avatar
Cha0s
Forum Guru
Forum Guru
Posts: 1160
Joined: Tue Oct 11, 2005 4:53 pm

Re: v7.12beta [testing] is released!

Sat Sep 16, 2023 2:36 pm

Downgrading to 7.12beta3 would also have worked but you can't download that release anymore.
https://download.mikrotik.com/routeros/ ... a3-arm.npk
 
User avatar
afink
newbie
Posts: 35
Joined: Wed May 29, 2013 7:16 pm
Location: Basel & Freetown
Contact:

Re: v7.12beta [testing] is released!

Sat Sep 16, 2023 3:22 pm

doesnt help. I need arm64 and the other packages as well. but thanks for sharing... Ill try again with 7.12 release when mikrotik finally figured out all its (Q)SFP negotiation mysteries.
 
User avatar
Kanzler
Member Candidate
Member Candidate
Posts: 135
Joined: Wed Oct 05, 2022 6:55 pm
Location: Ukraine

Re: v7.12beta [testing] is released!

Sat Sep 16, 2023 3:37 pm

 
User avatar
Cha0s
Forum Guru
Forum Guru
Posts: 1160
Joined: Tue Oct 11, 2005 4:53 pm

Re: v7.12beta [testing] is released!

Sat Sep 16, 2023 3:40 pm

doesnt help. I need arm64 and the other packages as well. but thanks for sharing... Ill try again with 7.12 release when mikrotik finally figured out all its (Q)SFP negotiation mysteries.
Just change the URL to whatever version/arch you need.
The files are all there. You take the official latest link and modify it.
 
User avatar
afink
newbie
Posts: 35
Joined: Wed May 29, 2013 7:16 pm
Location: Basel & Freetown
Contact:

Re: v7.12beta [testing] is released!

Sat Sep 16, 2023 4:42 pm

i tied that before but couldnt fiure out what was wrong. directory listing shows "forbidden". not helpful neither
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Tue Sep 19, 2023 9:33 pm

i tied that before but couldnt fiure out what was wrong. directory listing shows "forbidden". not helpful neither
For stable release, you can see the "directory listing"
https://mikrotik.com/download/archive

If you want to download it directly using a version name from RouterOS, this may help:
    :global dlros do={
    :local lver "7.11.2"
    :local larch "arm64"
    :if ([:typeof $1]="str") do={
        :set lver $1
        :if ([:typeof $arch]="str") do={
            :set larch $arch
        }
    } 
    :local curl "https://download.mikrotik.com/routeros/$lver/routeros-$lver-$larch.npk"
    :put $curl
    
    /tool fetch url=$curl  
}
$dlros 7.12beta1 arch=arm
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Tue Sep 19, 2023 9:38 pm

In the new /terminal/ask, I've notice the preinput= is included in the returned value. I'm not sure when this changed... I get preinput= is the what appears on same line before input (and prompt= is above the input). But the "question" (e.g. what's in preinput=) should not be in the response string IMO. e.g.
:global askbug [/terminal/ask "Should the preinput= be included in return?" preinput="I think no. Bug? "]                                           
Should the preinput= be included in return?
I think no. Bug? YES
:put $askbug 
I think no. Bug? YES
Here just the "YES" should be returned, but I get the entire preinput= too...

Or more simply:
:put [/terminal/ask preinput="> "]
> something
> something

The value return in this case should be just "something", not "> something".
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Wed Sep 20, 2023 11:22 am

It looks like the issue is more that the "preinput" name is unclear, it should have been something like "default".
In the example you suggest that the preinput is a "prompt" on the same line, but in fact it is the initial content of the input buffer, that you can backspace away and then change.
So it seems natural that it is returned.
 
txfz
Frequent Visitor
Frequent Visitor
Posts: 66
Joined: Tue Mar 10, 2020 9:02 am

Re: v7.12beta [testing] is released!

Wed Sep 20, 2023 11:31 am

The behaviour has not changed since I wrote this post, as far as I can tell. Didn't realise you can actually erase the preinput text, though. (maybe that was changed)
viewtopic.php?t=198723#p1022002

value-name is what most people will want to use. prompt seems wholly redundant, and I was gonna say so is preinput, but in light of being able to erase it, I guess it might be useful.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Wed Sep 20, 2023 11:39 am

Yeah, value-name should have been named "prompt", and pre-input should have been named "default".
What is now "prompt" is redundant because a parameter without name is also considered a prompt (probably for backward compatibility?) and because a linefeed is issued after it (so you could just use a :put command instead).
 
andriys
Forum Guru
Forum Guru
Posts: 1543
Joined: Thu Nov 24, 2011 1:59 pm
Location: Kharkiv, Ukraine

Re: v7.12beta [testing] is released!

Wed Sep 20, 2023 12:36 pm

Well, to me, it actually sound logical. If there were a parameter named default I'd expect it to mean "return this if the input buffer is empty", whereas preinput sounds more like "pre-fill the input buffer with this string, please".
 
msatter
Forum Guru
Forum Guru
Posts: 2941
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: v7.12beta [testing] is released!

Wed Sep 20, 2023 12:41 pm

@amm0 do you remember my implementation of this. I added a help/info line that was displayed underneath and the next input field was shifted down and displayed directly under that help/info.

So if you want to use pre-input as help/info then better ask for that extra line being displayed.
 
User avatar
Jotne
Forum Guru
Forum Guru
Posts: 3343
Joined: Sat Dec 24, 2016 11:17 am
Location: Magrathean

Re: v7.12beta [testing] is released!

Wed Sep 20, 2023 8:51 pm

This is a test
Courier-This is a test
-This is a test
Veranda-This is a test
Tahoma-This is a test
Georgia-This is a test

Thanks to Andriys, I learned that I can use different fonts (BBCode) in post. Not all looks good.
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Wed Sep 20, 2023 9:19 pm

@amm0 do you remember my implementation of this. I added a help/info line that was displayed underneath and the next input field was shifted down and displayed directly under that help/info.

So if you want to use pre-input as help/info then better ask for that extra line being displayed.
Well "value-name" does what I want: keep question on same line. I swear this was changed someplace...

But "value-name" is very poor choice for the functionality. I ignored it since "value-name=" is normally what the "default attribute" is. e.g.
/ip/address/print
:put [/ip/address/get 0 address]
111.211.111.61/29
:put [/ip/address/get 0 value-name=address]
111.211.111.61/29

So...
/terminal/ask "my question"
. should be same as
/terminal/ask value-name="my question"

At least, to be consistent with undocumented language reference. e.g. value-name= is normally same "unnamed" default attribute most place (e.g. in ~1300 other cmds).
 
User avatar
nichky
Forum Guru
Forum Guru
Posts: 1389
Joined: Tue Jun 23, 2015 2:35 pm

Re: v7.12beta [testing] is released!

Thu Sep 21, 2023 9:57 am

when can we expect OpenVPN to be fixed permanently?
 
curtdept
just joined
Posts: 2
Joined: Wed Nov 17, 2021 8:00 am

Re: v7.12beta [testing] is released!

Fri Sep 22, 2023 7:29 pm

anyone else have an issue with s-rj01 SFPs and auto flow control being on causing no link to be established after a brief iface down period? (on an rb5009)
 
holvoetn
Forum Guru
Forum Guru
Posts: 6762
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: v7.12beta [testing] is released!

Fri Sep 22, 2023 8:36 pm

Also have S-RJ01 and RB5009, it's even my WAN link so I would know pretty soon if something goes wrong there.
How do you define brief itf down periods ? How does that happen?
 
curtdept
just joined
Posts: 2
Joined: Wed Nov 17, 2021 8:00 am

Re: v7.12beta [testing] is released!

Mon Sep 25, 2023 9:06 pm

Also have S-RJ01 and RB5009, it's even my WAN link so I would know pretty soon if something goes wrong there.
How do you define brief itf down periods ? How does that happen?
I have it hooked to a laptop I use for work so at night it goes to sleep and when I come back the next day the connection will not establish without disabling interface and enabling it or other intrusive of stuff like that.
 
holvoetn
Forum Guru
Forum Guru
Posts: 6762
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: v7.12beta [testing] is released!

Mon Sep 25, 2023 9:15 pm

Hmm ... I don't really power off my ISP modem so maybe there is something odd there when you really shut down that connection.
(that's what I use SFP for right now since I use ether1 as 2.5G trunk to AX3 and most of the other ports are also occupied).
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 12980
Joined: Thu Mar 03, 2016 10:23 pm

Re: v7.12beta [testing] is released!

Mon Sep 25, 2023 10:26 pm

Does S-RJ01 support full auto negotiation mode? If it doesn't, then it's expected to see problems. Most NICs, while in sleep mode, auto negotiate slower speeds (10Mbps half-duplex is pretty common mode) and if the other end (S-RJ01) doesn't do its job properly, then the link goes AWOL.
 
guipoletto
Member Candidate
Member Candidate
Posts: 201
Joined: Mon Sep 19, 2011 5:31 am

Re: v7.12beta [testing] is released!

Mon Sep 25, 2023 10:45 pm

!) ethernet - changed "advertise" and "speed" arguments, and removed "half-duplex" setting under "/interface ethernet" menu;
!) sfp - convert configuration to support new link modes for SFP and QSFP type of interfaces;
1- what are the implications of this removal in scenarios where we have to match a device with fixed speed on the other side?
(plenty of home automation stuff i know of is hard-set to 10/half or 100/half)
Also, eventually i limit the advertised rates to avoid the interface trying to speak 1000/full and failing, on problematic cable runs

2- will this change the naming scheme for existing interface types/products?
 
EdPa
MikroTik Support
MikroTik Support
Topic Author
Posts: 340
Joined: Fri Sep 15, 2017 10:05 am
Location: Riga
Contact:

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 9:32 am

HI,

We have removed the setting "half-duplex=yes | no", because it got replaced with new "speed" arguments. For example:
/interface ethernet set ether1 speed=10M-baseT-half auto-negotiation=no

Speed settings were changed to represent all the link-modes, since the previous speed setting was too ambiguous.

These new link-modes are now identical for "speed" and "advertise". The difference is whether auto-negotiation is enabled or not. Speed is used with disabled auto-negotiation and accepts only one link-mode. Advertise is used with enabled auto-negotiation and accepts multiple link-modes.

Thanks for the feedback!
 
EdPa
MikroTik Support
MikroTik Support
Topic Author
Posts: 340
Joined: Fri Sep 15, 2017 10:05 am
Location: Riga
Contact:

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 12:58 pm

What's new in 7.12beta9 (2023-Sep-25 15:19):

!) ethernet - changed "advertise" and "speed" arguments, and removed "half-duplex" setting under "/interface ethernet" menu;
!) health - removed "temperature" health entry from boards, where it was the same as "sfp-temperature";
!) sfp - convert configuration to support new link modes for SFP and QSFP type of interfaces;
*) bfd - improved system stability;
*) bgp - fixed "input.filter-chain" argument selection in VPN configuration;
*) bgp - improved logging;
*) bluetooth - added basic support for connecting to BLE peripheral devices;
*) console - export required properties with default values;
*) console - improved system stability;
*) console - restrict permissions to "read,write,reboot,ftp,romon,test" for scripts executed by DHCP, Hotspot, PPP and Traffic-Monitor services;
*) l3hw - fixed IPv6 route suppression;
*) led - fixed "interface-status" configuration for virtual interfaces;
*) lora - added LNS protocol support;
*) lte - changed R11e-LTE ARP behavior to NoArp;
*) lte - fixed sub-interface auto-removal in multiple APN setups;
*) lte - show correct data class when connected to 5G SA network;
*) mqtt - added on-message feature for subscribed topics;
*) mqtt - added parallel-scripts-limit parameter to set maximum allowed number of scripts executed at the same time;
*) mqtt - added wildcard topic subscription support;
*) netinstall - added option to discard branding package;
*) netinstall - display package filename in GUI Descption column if package description is not specified;
*) netinstall-cli - added option to discard branding package;
*) netinstall-cli - allow ".rsc" script filenames;
*) poe-out - driver optimization for AF/AT controlled boards;
*) poe-out - fixed rare CRS328 poe-out menu and poe-out port config loss after reboot;
*) route - added "single-process" configuration setting, enabled by default on devices with 64MB or less RAM memory (CLI only);
*) route - added "suppress-hw-offload" setting for IPv6 routes;
*) route - reverse community "delete" and "filter" command behavior;
*) routerboard - added "reset-button" support for RB800, RB1100 and RB1100AHx2 devices;
*) sfp - fixed 25Gbps link with FEC91 (introduced in v7.12beta7);
*) snmp - changed "mtxrGaugeValue" type to integer;
*) switch - fixed packet forwarding between Ethernet ports for CRS354 switches (introduced in v7.12beta7);
*) webfig - fixed timezone for interface "Last Link Down/Up Time";
*) wifiwave2 - correctly add interface to specified "datapath.interface-list";
*) wifiwave2 - fixed re-connection failures for 802.11ax interfaces in station mode;
*) wifiwave2 - limit L2MTU to 1560 until a fix is available for a bug causing interfaces to fail transmitting larger frames than that;
*) wifiwave2 - log more information regarding authentication failures;
*) winbox - added "Host Key Type" setting under "IP/SSH" menu;
*) winbox - added "Key Owner" setting under "System/User/SSH Keys" and "System/User/SSH Private Keys" menus;
*) winbox - added "Remote Min Tx" parameter under "Routing/BFD/Session" menu;
*) winbox - added "Startup Delay" setting under "Tools/Netwatch" menu;
*) winbox - added "Use BFD" setting under "Routing/RIP/Interface-Template" menu;
*) winbox - added MQTT subscription menu;
*) winbox - allow to specify server as DNS name under "Tools/Email" menu;
*) winbox - rename "DSCP" setting to "DSCP (+ECN)" under "Tools/Traffic-Generator/Packet-Templates" menu;
*) winbox - rename "Name" setting to "List" under "IP,IPv6/Firewall/Address-List" menu;
*) winbox - rename "Password" button to "Change Now" under "System/Password" menu;
*) wireguard - added "auto" parameter for "private-key" and "presharde-key" parameters;
*) wireguard - request public or private key to be specified in order to create peer;
*) x86 - igb updated driver to 5.14.16 version;
*) x86 - igbvf updated driver from in-tree Linux kernel;
*) x86 - updated latest available pci.ids;
 
User avatar
fischerdouglas
Frequent Visitor
Frequent Visitor
Posts: 71
Joined: Thu Mar 07, 2019 6:38 pm
Location: Brazil
Contact:

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 1:10 pm

What would be the difference between itens beginning with "!)" and beginning "*)" on the release notes?
 
EdPa
MikroTik Support
MikroTik Support
Topic Author
Posts: 340
Joined: Fri Sep 15, 2017 10:05 am
Location: Riga
Contact:

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 1:17 pm

The list of changes might be overwhelming, but some of them are more important than others in our opinion. The "!)" are emphasized changes.
 
User avatar
irrwitzer
just joined
Posts: 24
Joined: Mon Apr 11, 2022 11:54 pm

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 2:31 pm

*) route - reverse community "delete" and "filter" command behavior;
Thanks for fixing this so quickly! it's working! (viewtopic.php?p=1027265#p1027265)
 
holvoetn
Forum Guru
Forum Guru
Posts: 6762
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 2:37 pm

Some devices at home upgraded:
RB5009 / AX3 / AX2 / Ax Lite
No immediate issues seen so far.
 
gigabyte091
Forum Guru
Forum Guru
Posts: 1523
Joined: Fri Dec 31, 2021 11:44 am
Location: Croatia

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 3:06 pm

RB5009, AX3, AX2, cAP AX, AX Lite LTE, RB4011, hAP AC3, Hex S no problems so far.
 
User avatar
eworm
Forum Guru
Forum Guru
Posts: 1092
Joined: Wed Oct 22, 2014 9:23 am
Location: Oberhausen, Germany
Contact:

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 4:14 pm

*) console - restrict permissions to "read,write,reboot,ftp,romon,test" for scripts executed by DHCP, Hotspot, PPP and Traffic-Monitor services;
Oh! 😳 So I can not access sensitive data, use
/tool/fetch
, and more? I guess that will break some of my scripts. 😢 Is there a way to opt-out and have the full permissions back?
 
User avatar
eworm
Forum Guru
Forum Guru
Posts: 1092
Joined: Wed Oct 22, 2014 9:23 am
Location: Oberhausen, Germany
Contact:

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 4:21 pm

Ah,
/tool/fetch
is granted by test policy. Will have to check for sensitive data...
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 5:26 pm

A user with no "sensitive" could write one of these "on-action" scripts to do "/log [/user/get XXX password]".
So /tool/fetch should work, but it too be blocked from retrieving the various sensitive/"password attributes".

But this begs the question, does a user with only "write,read" need to have "reboot,ftp,romon,test" to be able to save one of the "on-action" scripts?
Last edited by Amm0 on Wed Sep 27, 2023 1:46 pm, edited 1 time in total.
 
User avatar
eworm
Forum Guru
Forum Guru
Posts: 1092
Joined: Wed Oct 22, 2014 9:23 am
Location: Oberhausen, Germany
Contact:

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 5:50 pm

I think CVE-2023-30799 is unrelated, as stated in the linked blog post:
This issue is fixed in all RouterOS releases available on our download page (v7.7 and v6.49.7 and newer).
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 6:02 pm

I think CVE-2023-30799 is unrelated, as stated in the linked blog post:
Perhaps not exactly, but same family of "policy escalation".
 
CWDylan
just joined
Posts: 15
Joined: Wed Nov 25, 2015 4:24 pm

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 6:27 pm

*) wifiwave2 - limit L2MTU to 1560 until a fix is available for a bug causing interfaces to fail transmitting larger frames than that;
Is this present in 7.11.2 and previous or is it isolated to 7.12 versions?
 
ToTheFull
Member
Member
Posts: 402
Joined: Fri Mar 24, 2023 3:24 pm

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 6:50 pm

If it helps I had 2290 on my wifi which reset to 1560 when I updated from 7.12.beta7.
It's now 1560 on 7.12beta9
 
buset1974
Frequent Visitor
Frequent Visitor
Posts: 86
Joined: Wed Sep 13, 2006 12:12 pm
Location: Jakarta

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 7:28 pm

Dear Mikrotik,
Please reply our TIket SUP-128175
regarding failing when upgrading production router with many bgp peering from v6.49.8 to v7.11.2 above (7.12.beta.x)
router got freeze

thx
 
User avatar
Ullinator
just joined
Posts: 17
Joined: Tue Jun 08, 2021 12:53 pm
Location: North-West Germany

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 8:25 pm

After updating my CCR2004-1G-12S+2XS from 7.12Beta7 to Beta9 my SFP module S-RJ01, which is connected to my cable modem, fails to initiate a LINK via RJ45 copper.
(yes, it IS supported by the CCR ;-) )
Nothing worked, even disabling Auto Negotiation changed nothing.
It worked with Beta7 (LINK up with 1GBit/s).
After switching back to a S+RJ10 module the LINK came back.
@MT: please check all of YOUR SFP(+) models on compatibility with a new ROS version!
 
holvoetn
Forum Guru
Forum Guru
Posts: 6762
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 8:28 pm

I have S-RJ01 in RB5009 at home, works just fine using latest beta.
You do not have the required permissions to view the files attached to this post.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 8:31 pm

@MT: please check all of YOUR SFP(+) models on compatibility with a new ROS version!
It seems that SFP support is the "rocket science" of today. Unlike in their early days, rockets today often work on the first try and failures are quite rare. SFP changes usually fail every time (something is fixed, another problem is introduced).
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 8:47 pm

"/log [/user/get XXX password]"
For how many years now has this not been working? It was years before the end of v6 that passwords were no longer retrievable (only stored encrypted)...
 
User avatar
Jotne
Forum Guru
Forum Guru
Posts: 3343
Joined: Sat Dec 24, 2016 11:17 am
Location: Magrathean

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 10:24 pm

What would be the difference between itens beginning with "!)" and beginning "*)" on the release notes?
Mayor/Importante changes vs normal/minor changes
 
blacksnow
Frequent Visitor
Frequent Visitor
Posts: 56
Joined: Wed Feb 15, 2023 4:46 pm

Re: v7.12beta [testing] is released!

Tue Sep 26, 2023 11:35 pm

Awesome job on 7.12beta9. Works perfectly fine on my CCR2216. I realized the DHCP issue I was having on 7.12beta7 was actually due to the FEC91 issue with 25GB links on SFP, as I had my WAN lease coming from that affected link. Everything else seems to be running very smoothly, out of curisoity are the RX/TX counters at the top of webfig supposed to represent the traffic being sent to/from the router generated from you accessing the webpages or what are they supposed to be for?
 
User avatar
mantouboji
Frequent Visitor
Frequent Visitor
Posts: 58
Joined: Mon Aug 01, 2022 2:21 pm
Location: Shanghai

Re: v7.12beta [testing] is released!

Wed Sep 27, 2023 10:21 am

RB4011 AX2 and a J1900 box upgrade to beta9 sucessfully .

Wait for ED25519 private key
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12557
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: v7.12beta [testing] is released!

Wed Sep 27, 2023 11:10 am

It's the "fix"* for https://blog.mikrotik.com/security/cve-2023-30799.html — a user with no "sensitive" could write one of these "on-action" scripts to do "/log [/user/get XXX password]".
So /tool/fetch should work, but it too be blocked from retrieving the various sensitive/"password attributes".

But this begs the question, does a user with only "write,read" need to have "reboot,ftp,romon,test" to be able to save one of the "on-action" scripts?
No, probably is for this....
viewtopic.php?t=199378
 
User avatar
CTassisF
newbie
Posts: 36
Joined: Thu Jun 11, 2020 10:26 pm
Location: São Paulo, Brazil
Contact:

Re: v7.12beta [testing] is released!

Thu Sep 28, 2023 12:11 am

Since updating to 7.12beta9 I'm having issues with my hAP ac3 that works as WifiWave2 CAP. After a few hours of uptime, some of the devices connected to hAP ac3 stopped having internet connectivity. This issue does not happen to devices connected to my hAP ax3 that is CAP to the same CAPsMAN.

Ticket: SUP-129410
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Thu Sep 28, 2023 6:06 am

*) mqtt - added on-message feature for subscribed topics;
*) mqtt - added wildcard topic subscription support;

Great work! It works* and there are docs for it, too! "on-message" script works, even UTF-8 encoding passes through okay. "#" wildcard seem to work in quick test.

*minor issues:
- In some quick test (script below), it always seems to lose the first received message. /iot/mqtt/publish side works, since I get those on another host, just the /iot/mqtt/subscribe seem lost the very first one – then fine. Adding delays etc doesn't seem to change the "first lost" issue.
- Winbox shows the new settings, but seem if you delete at CLI, it doesn't always get reflected in winbox. Closing windows/reopen shows any removes.
- Perhaps reasonable. But the variable "msgTopic" and "msgData" in the "on-message="are a departure in y'all naming conventions — but the docs has example, and showed camelCase – just example $topic :).
- Related, MQTT subscription message's broker=/$msgBroker and time=/$msgTime aren't included in "on-message" While those can be inferred... time= might be different if MQTT was queue'd someplace...
- Log topic is "script" which is normal for the "on-" scripts, but be nice it was under "mqtt" topic for filtering from /system/script etc...
- There is no "disable", only remove – so no way to for a disconnect/reconnect.



Here was some test code that use the Eclipse's test server, see https://test.mosquitto.org:

/iot mqtt { 
    :local mytopic "mikrotik/mqtt"
    :local myhost "test.mosquitto.org"
    
    # clear existing message
    # /iot mqtt subscriptions recv clear

    # setup new broker
    brokers add address=$myhost name=mosquitto-test port=1883
    
    # add subscription with "on-message"
    subscriptions add broker=mosquitto-test topic=$mytopic on-message=":log info \"test \$msgTopic \$msgData\""
    :delay 1s
    
    # create 10 message with different "seq:" with UTF-8 encoded emoji.
    :for i from=1 to=10 do={ 
        publish topic=$mytopic broker=mosquitto-test message="{ \"seq\": $i;  \"msg\": \"\F0\9F\A7\90\"}"
        :delay 1s
    }

    # show them on screen
    subscriptions recv print

    # remove out broker (to force a disconnect since test server has timeouts)
    broker remove [find name="mosquitto-test"]
}
which shows the logged messages, except the /subscribe hook doesn't find the first one.
09-27 19:24:54 script,info test mikrotik/mqtt { "seq": 10; "msg": "F09FA790"}
09-27 19:31:16 script,info test mikrotik/mqtt { "seq": 2; "msg": "F09FA790"}
09-27 19:31:17 script,info test mikrotik/mqtt { "seq": 3; "msg": "F09FA790"}
09-27 19:31:18 script,info test mikrotik/mqtt { "seq": 4; "msg": "F09FA790"}
09-27 19:31:19 script,info test mikrotik/mqtt { "seq": 5; "msg": "F09FA790"}
09-27 19:31:20 script,info test mikrotik/mqtt { "seq": 6; "msg": "F09FA790"}
09-27 19:31:21 script,info test mikrotik/mqtt { "seq": 7; "msg": "F09FA790"}
09-27 19:31:22 script,info test mikrotik/mqtt { "seq": 8; "msg": "F09FA790"}
09-27 19:31:23 script,info test mikrotik/mqtt { "seq": 9; "msg": "F09FA790"}
09-27 19:31:24 script,info test mikrotik/mqtt { "seq": 10; "msg": "F09FA790"}
** never notice but the non-printable ASCII gets removed in normal "print" but "print detail" has the \F0\9F\A7\90 still...

But RouterOS did send it:
> mosquitto_sub -t "#" -v             
mikrotik/mqtt { "seq": 1;  "msg": "🧐"}
mikrotik/mqtt { "seq": 2;  "msg": "🧐"}
...
mikrotik/mqtt { "seq": 10;  "msg": "🧐"}
 
denissMT
MikroTik Support
MikroTik Support
Posts: 55
Joined: Wed May 26, 2021 12:00 pm

Re: v7.12beta [testing] is released!

Thu Sep 28, 2023 10:53 am

*) mqtt - added on-message feature for subscribed topics;
*) mqtt - added wildcard topic subscription support;

Great work! It works* and there are docs for it, too! "on-message" script works, even UTF-8 encoding passes through okay. "#" wildcard seem to work in quick test.

*minor issues:
- In some quick test (script below), it always seems to lose the first received message. /iot/mqtt/publish side works, since I get those on another host, just the /iot/mqtt/subscribe seem lost the very first one – then fine. Adding delays etc doesn't seem to change the "first lost" issue.
- Winbox shows the new settings, but seem if you delete at CLI, it doesn't always get reflected in winbox. Closing windows/reopen shows any removes.
- Perhaps reasonable. But the variable "msgTopic" and "msgData" in the "on-message="are a departure in y'all naming conventions — but the docs has example, and showed camelCase – just example $topic :).
- Related, MQTT subscription message's broker=/$msgBroker and time=/$msgTime aren't included in "on-message" While those can be inferred... time= might be different if MQTT was queue'd someplace...
- Log topic is "script" which is normal for the "on-" scripts, but be nice it was under "mqtt" topic for filtering from /system/script etc...
- There is no "disable", only remove – so no way to for a disconnect/reconnect.



Here was some test code that use the Eclipse's test server, see https://test.mosquitto.org:

/iot mqtt { 
    :local mytopic "mikrotik/mqtt"
    :local myhost "test.mosquitto.org"
    
    # clear existing message
    # /iot mqtt subscriptions recv clear

    # setup new broker
    brokers add address=$myhost name=mosquitto-test port=1883
    
    # add subscription with "on-message"
    subscriptions add broker=mosquitto-test topic=$mytopic on-message=":log info \"test \$msgTopic \$msgData\""
    :delay 1s
    
    # create 10 message with different "seq:" with UTF-8 encoded emoji.
    :for i from=1 to=10 do={ 
        publish topic=$mytopic broker=mosquitto-test message="{ \"seq\": $i;  \"msg\": \"\F0\9F\A7\90\"}"
        :delay 1s
    }

    # show them on screen
    subscriptions recv print

    # remove out broker (to force a disconnect since test server has timeouts)
    broker remove [find name="mosquitto-test"]
}
which shows the logged messages, except the /subscribe hook doesn't find the first one.
09-27 19:24:54 script,info test mikrotik/mqtt { "seq": 10; "msg": "F09FA790"}
09-27 19:31:16 script,info test mikrotik/mqtt { "seq": 2; "msg": "F09FA790"}
09-27 19:31:17 script,info test mikrotik/mqtt { "seq": 3; "msg": "F09FA790"}
09-27 19:31:18 script,info test mikrotik/mqtt { "seq": 4; "msg": "F09FA790"}
09-27 19:31:19 script,info test mikrotik/mqtt { "seq": 5; "msg": "F09FA790"}
09-27 19:31:20 script,info test mikrotik/mqtt { "seq": 6; "msg": "F09FA790"}
09-27 19:31:21 script,info test mikrotik/mqtt { "seq": 7; "msg": "F09FA790"}
09-27 19:31:22 script,info test mikrotik/mqtt { "seq": 8; "msg": "F09FA790"}
09-27 19:31:23 script,info test mikrotik/mqtt { "seq": 9; "msg": "F09FA790"}
09-27 19:31:24 script,info test mikrotik/mqtt { "seq": 10; "msg": "F09FA790"}
** never notice but the non-printable ASCII gets removed in normal "print" but "print detail" has the \F0\9F\A7\90 still...

But RouterOS did send it:
> mosquitto_sub -t "#" -v             
mikrotik/mqtt { "seq": 1;  "msg": "🧐"}
mikrotik/mqtt { "seq": 2;  "msg": "🧐"}
...
mikrotik/mqtt { "seq": 10;  "msg": "🧐"}
The "first" script initiation failure happens because of the "different" MQTT packet sequence. You can inspect it using the WireShark.
Basically, what happens, is that when you do "subscribe" and then "publish" immediately after, RouterOS sends:
1) MQTT "connect" packet - to establish MQTT connection.
2) MQTT "publish" packet - to send the message.
3) And only then MQTT "subscribe" - to subscribe to the topic (which is too late, as the "publish" was already sent before the "subscription" happened).

The correct way would be, to do "subscribe", then do a manual connect "/iot mqtt connect broker=broker_name", and then "publish" the message. In this case, the sequence would be:
1) MQTT "connect" packet is sent.
2) MQTT "subscribe" packet is sent.
3) And only then the "publish".

We will look into Winbox, broker/time variables, and your other suggestions! Thank you for the feedback!

Can you please elaborate on the "There is no "disable", only remove – so no way to for a disconnect/reconnect."?
There are:
https://help.mikrotik.com/docs/display/ ... TT-Connect
and
https://help.mikrotik.com/docs/display/ ... Disconnect
options.
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Thu Sep 28, 2023 4:35 pm

Can you please elaborate on the "There is no "disable", only remove – so no way to for a disconnect/reconnect."?
Well I didn't read the WHOLE page. ;). Adding a "/iot/mqtt/connect broker=" after subscription before publish fixed the "lost first message" problem. Thanks!

But, in my defense, using root /iot/mqtt with a broker= for CLI is kinda odd... I only looked in /iot/mqtt/broker, which is where "connected=yes" is shown – but was documented :).

It also be nice if "connected" status showed as a field in winbox in IoT>MQTT>Broker list. I guess winbox could have connect/disconnect button & show the /iot/mqtt/subscription/recv queue in a tab — but just showing if a broker is connected in winbox that be handy.
 
denissMT
MikroTik Support
MikroTik Support
Posts: 55
Joined: Wed May 26, 2021 12:00 pm

Re: v7.12beta [testing] is released!

Fri Sep 29, 2023 8:39 am

Can you please elaborate on the "There is no "disable", only remove – so no way to for a disconnect/reconnect."?
Well I didn't read the WHOLE page. ;). Adding a "/iot/mqtt/connect broker=" after subscription before publish fixed the "lost first message" problem. Thanks!

But, in my defense, using root /iot/mqtt with a broker= for CLI is kinda odd... I only looked in /iot/mqtt/broker, which is where "connected=yes" is shown – but was documented :).

It also be nice if "connected" status showed as a field in winbox in IoT>MQTT>Broker list. I guess winbox could have connect/disconnect button & show the /iot/mqtt/subscription/recv queue in a tab — but just showing if a broker is connected in winbox that be handy.
Glad to hear it worked!
We will be improving GUI to match CLI configuration options! As of this moment, most of the new MQTT features are just CLI only (for now).
 
User avatar
sirbryan
Member
Member
Posts: 400
Joined: Fri May 29, 2020 6:40 pm
Location: Utah
Contact:

Re: v7.12beta [testing] is released!

Fri Sep 29, 2023 11:25 am

I opened a support ticket [SUP-129558], but I'm going to post it here, too.

On both builds 7 and 9, when attempting to add any kind of dynamic interface (bridge, VLAN, bonds, IPIP/EOIP tunnels, etc.) from within Webfig, I get an error that the interface type is not supported.
Screenshot 2023-09-29 at 2.23.07 AM.png
This is happening on hAP AX3 and CCR2116, with completely different base configurations.
You do not have the required permissions to view the files attached to this post.
 
User avatar
Kanzler
Member Candidate
Member Candidate
Posts: 135
Joined: Wed Oct 05, 2022 6:55 pm
Location: Ukraine

Re: v7.12beta [testing] is released!

Fri Sep 29, 2023 12:21 pm

@sirbryan hAP ac3 (ww2) also has this issue.
 
blacksnow
Frequent Visitor
Frequent Visitor
Posts: 56
Joined: Wed Feb 15, 2023 4:46 pm

Re: v7.12beta [testing] is released!

Sun Oct 01, 2023 10:36 pm

I opened a support ticket [SUP-129558], but I'm going to post it here, too.

On both builds 7 and 9, when attempting to add any kind of dynamic interface (bridge, VLAN, bonds, IPIP/EOIP tunnels, etc.) from within Webfig, I get an error that the interface type is not supported.

Screenshot 2023-09-29 at 2.23.07 AM.png

This is happening on hAP AX3 and CCR2116, with completely different base configurations.
I can confirm it is the same on CCR2216, although the CLI command still works, so it looks like it's some sort of web ui specific issue.
 
User avatar
sirbryan
Member
Member
Posts: 400
Joined: Fri May 29, 2020 6:40 pm
Location: Utah
Contact:

Re: v7.12beta [testing] is released!

Mon Oct 02, 2023 12:51 am

I can confirm it is the same on CCR2216, although the CLI command still works, so it looks like it's some sort of web ui specific issue.
Yeah, support acknowledged it as well. I did what I needed to with the CLI, but wanted to report it here.
 
iustin
newbie
Posts: 25
Joined: Mon Mar 06, 2023 12:11 am

Re: v7.12beta [testing] is released!

Mon Oct 02, 2023 2:20 am

Just dared to install the beta (9) on a CRS309, and sad to report that Ubiquity 10GbE SFP modules are still not recognized correct (model UACC-CM-RJ45-MG, still reported as "RX Loss", support case open for many months…).
 
User avatar
spippan
Member
Member
Posts: 464
Joined: Wed Nov 12, 2014 1:00 pm

Re: v7.12beta [testing] is released!

Mon Oct 02, 2023 5:29 pm

i tied that before but couldnt fiure out what was wrong. directory listing shows "forbidden". not helpful neither
For stable release, you can see the "directory listing"
https://mikrotik.com/download/archive

If you want to download it directly using a version name from RouterOS, this may help:
    :global dlros do={
    :local lver "7.11.2"
    :local larch "arm64"
    :if ([:typeof $1]="str") do={
        :set lver $1
        :if ([:typeof $arch]="str") do={
            :set larch $arch
        }
    } 
    :local curl "https://download.mikrotik.com/routeros/$lver/routeros-$lver-$larch.npk"
    :put $curl
    
    /tool fetch url=$curl  
}
$dlros 7.12beta1 arch=arm
this should be put into the wiki/help pages under "system > packages" :)
 
forteller
just joined
Posts: 20
Joined: Tue Jun 13, 2023 9:58 am

Re: v7.12beta [testing] is released!

Mon Oct 02, 2023 10:41 pm

Just logged in to report that after upgrading to latest 7.12b9 my SFP module refuses to work. It's like it is not plugged in at all. All is fine after reverting back to 7.11 stable. Not sure if it has been reported before, too many occurences of "sfp" word in this thread to read it all :P
                    name: sfp-sfpplus1
                  status: link-ok
                    rate: 2.5Gbps
             full-duplex: yes
         tx-flow-control: no
         rx-flow-control: no
      sfp-module-present: yes
             sfp-rx-loss: no
            sfp-tx-fault: no
                sfp-type: SFP/SFP+/SFP28
      sfp-connector-type: SC
      sfp-link-length-sm: 20km
         sfp-vendor-name: Hisense-Leox
  sfp-vendor-part-number: LXT-010S-H
     sfp-vendor-revision: 1.0
  sfp-manufacturing-date: 22-08-27
          sfp-wavelength: 1310nm
         sfp-temperature: 54C
      sfp-supply-voltage: 3.357V
     sfp-tx-bias-current: 16mA
 
EdPa
MikroTik Support
MikroTik Support
Topic Author
Posts: 340
Joined: Fri Sep 15, 2017 10:05 am
Location: Riga
Contact:

Re: v7.12beta [testing] is released!

Tue Oct 03, 2023 10:17 am

@forteller, thanks for the feedback!

But we need more details to reproduce this issue in our labs. The sfp-sfpplus monitor actually shows that "status: link-ok". Can you share supout.rif file when the issue is active and send it to support@mikrotik.com? If not, can you specify what device are you using, show the full output of the monitor command and printout from "/interface ethernet export"?
 
uCZBpmK6pwoZg7LR
Frequent Visitor
Frequent Visitor
Posts: 58
Joined: Mon Jun 15, 2015 12:23 pm

Re: v7.12beta [testing] is released!

Tue Oct 03, 2023 12:30 pm

Please fix bug SUP-125227 and SUP-129944 (traffic from interface unknown to interface unknown) . It is not possible to use firewall due to it.
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: v7.12beta [testing] is released!

Tue Oct 03, 2023 6:08 pm

FWIW, I could not find any docs on this one...
*) interface - added "macvlan" interface support;
 
forteller
just joined
Posts: 20
Joined: Tue Jun 13, 2023 9:58 am

Re: v7.12beta [testing] is released!

Tue Oct 03, 2023 11:37 pm

@forteller, thanks for the feedback!

But we need more details to reproduce this issue in our labs. The sfp-sfpplus monitor actually shows that "status: link-ok". Can you share supout.rif file when the issue is active and send it to support@mikrotik.com? If not, can you specify what device are you using, show the full output of the monitor command and printout from "/interface ethernet export"?
The output comes from the 7.11 firmware and I posted it to show what SFP module I am using. My device is RB5009Upr+S+In. Using 7.12b9 there is no obvious reaction when inserting SFP module. No light, no indication in the winbox that something has been plugged in - there is no checkbox next to "Module Present" in SFP interface status.

Sorry I didn't make it clear in the first post - I was posting that in a rush :)

If supout.rif file is going to provide something useful in this scenario, I need to find convenient time to break internet at home again :)
 
EdPa
MikroTik Support
MikroTik Support
Topic Author
Posts: 340
Joined: Fri Sep 15, 2017 10:05 am
Location: Riga
Contact:

Re: v7.12beta [testing] is released!

Wed Oct 04, 2023 9:29 am

The supout.rif would be useful, also from the working setup with 7.11. Thanks!
 
massinia
Member Candidate
Member Candidate
Posts: 184
Joined: Thu Jun 09, 2022 7:20 pm

Re: v7.12beta [testing] is released!

Wed Oct 04, 2023 10:30 am

Please someone can take a look to these?
SUP-110463 (viewtopic.php?t=194451) and SUP-108546 (viewtopic.php?t=193846)

Thanks
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Wed Oct 04, 2023 11:19 am

Frankly I would prefer when features like SMB or PROXY were just removed from RouterOS... get a NAS!
 
iustin
newbie
Posts: 25
Joined: Mon Mar 06, 2023 12:11 am

Re: v7.12beta [testing] is released!

Thu Oct 05, 2023 12:21 am

Hello, how can I help move forward support of specific transceivers? I have SUP-110942 open for many months for supporting UACC-CM-RJ45-MG, but no reply after initial interaction. And none of the beta/rc final versions since then helped on CRS309/310.

I think I have found some potential cause why this doesn't work in RouterOS, or only on some platforms. The module doesn't support the RX_LOS from the SFF-8472 standard (page A0h, byte 65, bit 1 is set to zero - actually both options bytes are zero, which means that neither TX_FAULT nor TX_DISABLE are supported), but on the CRS309/310 the module is listed as always "RX Loss".

Could it be that the hardware driver for these models always polls/checks the RX loss hardware line, even if the transceiver doesn't support it, so thus it never detects link up? This should be a half an hour investigation on the driver side (the fix will take of course more, but at least would move investigation forward), so could you please please forward it to whomever is responsible for this hardware?

Happy to provide more info either via RouterOS debugging or via Linux ethtool. Many thanks in advance!
 
DeviceLocksmith
just joined
Posts: 24
Joined: Sat Jan 15, 2022 8:21 am

Re: v7.12beta [testing] is released!

Thu Oct 05, 2023 2:50 am

Try covering rx_los pin with nail polish. Not the most elegant solution, but floating this pin on module may get it online
 
fems
just joined
Posts: 3
Joined: Tue Mar 31, 2009 11:56 pm

Re: v7.12beta [testing] is released!

Thu Oct 05, 2023 4:15 pm

ROS do not reply SOA DNS record by default, even if the SOA record has been obtained from the upstream DNS server and has been displayed in the ROS DNS cache.

For example: Cloudflare tunnel cannot be started because the returned (argotunnel.com) domain record does not contain an SOA record.

This issue exists in both 7.11.2 and 7.12beta9

I have seen some discussion on the 7.7rc post.
viewtopic.php?p=976344&hilit=SOA+record#p975926
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: v7.12beta [testing] is released!

Thu Oct 05, 2023 4:42 pm

For example: Cloudflare tunnel cannot be started because the returned (argotunnel.com) domain record does not contain an SOA record.
Interesting that you found an actual problem resulting from that behavior. But did you really confirm it to be the reason?
As you mentioned I encountered a problem with the DNS resolver in 7.7rc and went to great lengths debugging it, found the same thing you mention above, but in the end it was a "red herring", it was not the reason why I had problems. That was caused by other misbehavior in the DNS resolver that was fixed.
 
EdPa
MikroTik Support
MikroTik Support
Topic Author
Posts: 340
Joined: Fri Sep 15, 2017 10:05 am
Location: Riga
Contact:

Re: v7.12beta [testing] is released!

Fri Oct 06, 2023 12:00 pm

Version 7.12rc1 has been released.
viewtopic.php?t=200328

Who is online

Users browsing this forum: No registered users and 12 guests