Eheheheh...So i guess the leaked date was right after all....
Just to clarify, does this mean that RB4011 & RB1100AHx4 will be added as exception here:*) added bridge HW offload support for vlan-filtering on RTL8367 switch chip (RB4011, RB1100AHx4);
Hi,RouterOS version 7.1rc1 has been released in public "development" channel!
What's new in 7.1rc1 (2021-Aug-19 13:06):
!) added support for IPv6 NAT (CLI only);
!) added support for L2TPv3 (CLI only);
*) added "expired" user status with suggestion to change password (WinBox v3.29 required);
*) added bridge HW offload support for vlan-filtering on RTL8367 switch chip (RB4011, RB1100AHx4);
*) added password strength requirement settings;
*) added skin support for WinBox (WinBox v3.29 required);
*) fixed support for RIP (Routing Information Protocol);
*) improved general stability and performance;
*) other minor fixes and improvements;
All released RouterOS v7 changelogs are available here:
https://mikrotik.com/download/changelog ... lease-tree
So when can we see the stable version?I was right then to put it in my signature...
(Be ready, 23 August is coming...)
This is not a question, the 7 is perennial "beta", like 6 is perennial "rc"....So when can we see the stable version?I was right then to put it in my signature...
(Be ready, 23 August is coming...)
Any device on production: not compatibleall device are compatible or compatible device list available somewhere?
Holy sh*t, these are pleasant surprises.
!) added support for IPv6 NAT (CLI only);
[...]
*) added bridge HW offload support for vlan-filtering on RTL8367 switch chip (RB4011, RB1100AHx4);
Indeed, it is set by the PPPoE Client.Each route has a flag showing which protocol added the route, from your screenshots default route is added by the VPN (PPPoe)
That's unfortunate, thanks for checking. IPv6 connection tracking also seems to be still broken.And to the people wondering: yes, Cake is still broken and causes a kernel panic.
Does this version support IGMP-Proxy?We believe this "release candidate" version is pretty much ready for "stable" release on all devices. If you experience any issue, please open a support ticket with as much details as possible and supout.rif file attached. Faster we can acknowledge all active issues, faster we can resolve them and release a "stable" version.
wireguard1: =(peer): Handshake for peer did not complete after 5 seconds, retrying (try 16)
No, seems rc1 to be a step forward because Winbox seems now supporting routing/filter!
#[SUP-44860]: v7.1beta5 x86 still crashesWe believe this "release candidate" version is pretty much ready for "stable" release on all devices. If you experience any issue, please open a support ticket with as much details as possible and supout.rif file attached. Faster we can acknowledge all active issues, faster we can resolve them and release a "stable" version.
Thanks, I can confirm the reboot on a RB4011 too.And to the people wondering: yes, Cake is still broken and causes a kernel panic.
No going to GA with no igmp proxy? that's a show stopper for meRouterOS version 7.1rc1 has been released in public "development" channel!
What's new in 7.1rc1 (2021-Aug-19 13:06):
!) added support for IPv6 NAT (CLI only);
!) added support for L2TPv3 (CLI only);
*) added "expired" user status with suggestion to change password (WinBox v3.29 required);
*) added bridge HW offload support for vlan-filtering on RTL8367 switch chip (RB4011, RB1100AHx4);
*) added password strength requirement settings;
*) added skin support for WinBox (WinBox v3.29 required);
*) fixed support for RIP (Routing Information Protocol);
*) improved general stability and performance;
*) other minor fixes and improvements;
All released RouterOS v7 changelogs are available here:
https://mikrotik.com/download/changelog ... lease-tree
Seconding this.Will routing filters ever get a traditional winbox gui, or are we stuck with manually writing "if ( [matchers] ) { [actions] } else { [actions] }" rules?
I can't confirm this. I have tried routing filters on winbox in beta6 and I see no difference as to what they are in rc1.No, seems rc1 to be a step forward because Winbox seems now supporting routing/filter!
in 7.1beta7 it was not supported.
regards
Ros
Also it seems like it forgot my routing filter config from beta6 to rc1.Seconding this.Will routing filters ever get a traditional winbox gui, or are we stuck with manually writing "if ( [matchers] ) { [actions] } else { [actions] }" rules?
Mikrotik please give us a Winbox routing filters experience similar to what it was in v6.
fq codel also rebooted the router after 2 hours, falling back to sfq..Thanks, I can confirm the reboot on a RB4011 too.And to the people wondering: yes, Cake is still broken and causes a kernel panic.
Trying out codel right now.
Same here, without igmp-proxy i cannot use this versionNo going to GA with no igmp proxy? that's a show stopper for me
Where a can find skins in winbox?What's new in 7.1rc1 (2021-Aug-19 13:06):
*) added skin support for WinBox (WinBox v3.29 required);
I hope MT can fix it on RC2 or at least before moving 7.1 from development to testing channel.And to the people wondering: yes, Cake is still broken and causes a kernel panic.
Yep, I had to recreate backbone area and interface-templates.Be careful the update breaks OSPF, again...
And you still have to create interface-templates by hand because the GUI adds networks="" automatically and breaks things.
can anyone confirm following fetures also hardware ofload on rb4011Yes, you can set PVID and still have HW offload.
STP, RSTP and MSTP are supported as well.
I tried IGMP and DHCP and those aren't offloaded, only VLAN filtering, port PVIDs, and STP/RSTP/MSTP.can anyone confirm following fetures also hardware ofload on rb4011
IGMP Snooping
DHCP Snooping
bonding
Same here.Yep, I had to recreate backbone area and interface-templates.
You can set networks=0.0.0.0/0 (in winbox as well) instead of unsetting it.Yes, WinBox adds networks="" to them, needs to be unset via CLI.
How do you know your GR3 isn't time-traveling? After all, with all the new features v7 is bringing, time warping isn't out of the question.Netflow now reports an incorrect date of 1970-01-01
IMO this is not good behavior and should be reconsidered. The issue is that when using automated config backup systems (ex. RANCID, Oxidized, etc.) it will not use this command since RouterOS v6 does not have this show-sensitive. When moving a network from RouterOS v6 to v7 we either would not get a complete backup (Oxidized would be backing up v7 with the default hide-sensitive), or we would have to remember to reconfigure the backup one device at a time for the RouterOS v7 export command with show-sensitive instead of the RouterOS v6 export command. There is a huge opportunity here to screw things up by forgetting a device and then backups are no longer happening.- hide-sensitive in exports is now default and has to be explicitly disabled with show-sensitive. A good idea in my opinion, but should be mentioned somwhere in bold letters! This broke my WireGuard, RoMON and CAPsMAN setup on export -> reset -> import without any error message.
IPv6 NAT can give you the ipv4 style design you are used to from ipv4. but ipv6 have much better solutions as well.omg .. IPv6 NAT? Now I'm kind of hyped.
Always had IPv6 turned off in my main vlan because I couldn't make failover possible. So now it should be possible or am I wrong?
I reported this also for beta 6 (SUP-51582). Support told me they could not repro... I provided all of the needed info (several traces and debug logs from netflow from a Linux box...).Upgraded my test RB750GR3
Netflow now reports an incorrect date of 1970-01-01
Netflow v9 with NFSEN target
Do you know what module leaks memory?Memory leak is still a thing - just slower but still unusable.
RB4011 and RB1100AHx4 have more than one RTL8367 chip (one for ports 1-5 and 6-10 on RB4011). HW acceleration for VLAN filtering is obviously only possible on ether ports on the same chip.*) added bridge HW offload support for vlan-filtering on RTL8367 switch chip (RB4011, RB1100AHx4);
ip route menu will not show any dynamic routing protocol specific info, all routing protocol info is available in /routing/route menuMissing bgp-as-path information when /ip/route/print detail
I would like to request a separate wifiwave2 package for IPQ4018/IPQ4019 devices with 16MB of ROM and 128M of RAM. With such a package a lot of more users could test this it, send feedbacks and bug reports which will result in an earlier available bugfree stable release.RouterOS version 7.1beta5 has been released in public "development" channel!
*) wifiwave2 - improved interface stability with multiple WPA3 authenticated clients;
I don't think that would happen since dual ath10k radios are RAM hungry even with OpenWrt's small buffers patches 128MB devices can go OOM under certain conditions, also Mikrotik may release ath11k based WiFi 6 products the next year.I would like to request a separate wifiwave2 package for IPQ4018/IPQ4019 devices with 16MB of ROM and 128M of RAM. With such a package a lot of more users could test this it, send feedbacks and bug reports which will result in an earlier available bugfree stable release.
21:31:11 system,error broken package routing-7.1rc1-arm.npk
21:31:11 system,error broken package ipv6-7.1rc1-arm.npk
21:31:11 system,error broken package wireless-7.1rc1-arm.npk
21:31:11 system,error broken package security-7.1rc1-arm.npk
21:31:11 system,error broken package ppp-7.1rc1-arm.npk
21:31:11 system,error broken package dhcp-7.1rc1-arm.npk
21:31:11 system,error broken package advanced-tools-7.1rc1-arm.npk
21:31:11 system,info installed system-7.1rc1
21:31:11 system,error not enough space for upgrade
21:31:11 system,info router rebooted
free-hdd-space: 2152.0KiB
total-hdd-space: 15.3MiB
I noticed this as well; it seems related to the wireguard peers "Persistent Keepalive" value being present. If I remove the persistent keepalive entry and then disable/enable my wireguard interface the "handshake for peer did not complete" log spam stops.After upgrade on one HEX S which i use only for Wireguard i get spamm of this for all peers constantly in log.But everything works fine, i also tried closing the WG port because i was thinking it may be invalid attempts from net, but spam continues.Code: Select allwireguard1: =(peer): Handshake for peer did not complete after 5 seconds, retrying (try 16)
Any idea whats this about?
Wave 2 on audience can't do vlan tagging. srsly.....
ccr2004 crashes evertime bad HWcapsman crashes immediately on ccr2004
can anyone confirm following fetures also hardware ofload on rb4011
IGMP Snooping
DHCP Snooping
bonding
RB4011 and RB1100AHx4 have more than one RTL8367 chip (one for ports 1-5 and 6-10 on RB4011). HW acceleration for VLAN filtering is obviously only possible on ether ports on the same chip.
Question is: If a bridge spans among ports off different chips (for ex ports 3-8) will HW filtering only be available between ports of the same chip (3-5 and 6-8) or completly disabled? What about STP/RSTP in such a configuration?
/interface bridge
add name=bridge1 vlan-filtering=yes
/interface bridge port
add bridge=bridge1 interface=ether1 pvid=10
add bridge=bridge1 interface=ether6 pvid=10
/interface bridge vlan
add bridge=bridge1 tagged=bridge1 vlan-ids=10
Thanks, will be fixed as well as currently missing OSPF redistribution settings and routing table parameter. Report if you spot any other inconsistency with winbox and cli.Yes, WinBox adds networks="" to them, needs to be unset via CLI.
And interface cost is now hidden from WinBox, available only via CLI.
Hit F5 to refresh Winbox pools dialogDoes this count?
when will you fix the [SUP-35291]: bug about udp pps in dst-limit? (it works up to 9999 packets/s)We believe this "release candidate" version is pretty much ready for "stable" release on all devices. If you experience any issue, please open a support ticket with as much details as possible and supout.rif file attached. Faster we can acknowledge all active issues, faster we can resolve them and release a "stable" version.
aug/24/2021 09:24:04 system,info,critical Firmware upgraded successfully, please reboot for changes to take effect!
aug/24/2021 09:24:10 system,error,critical error while running customized default configuration script: bad command name wireless (line 977 column
25)
aug/24/2021 09:24:10 system,error,critical
[bat@audience] /interface/l2tp-ether> add
allow-fast-path connect-to digest-hash l2tp-proto-version local-tunnel-id name remote-tunnel-id use-ipsec
circuit-id cookie-length disabled local-address mac-address peer-cookie send-cookie use-l2-specific-sublayer
comment copy-from ipsec-secret local-session-id max-mtu remote-session-id unmanaged-mode
[bat@audience] /interface/l2tp-ether> add connect-to=2001:4c48::1
failure: bad address or dns name
You can probably do that using a bridge...Is there a plan to support macvlan or set mac address for the pppoe interface?
Where are you targeting the CAKE queue? At the LTE connection? Has it been stable? I wanted to try our CAKE + Autorate Ingress (given my LTE connection bandwidth is quite random).So far all is working fine on my CRS317, RB4011 and LtAP-Mini (+R11e-LTE6). Noteworthy features in use are IPv6 to Internet, IPv6 over Wireguard (multiple tunnels), CAKE using queue tree. Lets see how stable it is ...
As noted by the terminal when You open it up:Also, question mark (?) in CLI doesn't seem to work on my end. it supposes to show the available input options, but all i get is a red '?'
ros7.1rc1.png
this is true for new features and previously existing things things.
MMM MMM KKK TTTTTTTTTTT KKK
MMMM MMMM KKK TTTTTTTTTTT KKK
MMM MMMM MMM III KKK KKK RRRRRR OOOOOO TTT III KKK KKK
MMM MM MMM III KKKKK RRR RRR OOO OOO TTT III KKKKK
MMM MMM III KKK KKK RRRRRR OOO OOO TTT III KKK KKK
MMM MMM III KKK KKK RRR RRR OOOOOO TTT III KKK KKK
MikroTik RouterOS 7.1rc1 (c) 1999-2021 http://www.mikrotik.com/
Press F1 for help
Do you mean bridge+nat?You can probably do that using a bridge...Is there a plan to support macvlan or set mac address for the pppoe interface?
No. You can add a VLAN to your ethernet port to get the VLAN tag, then create a bridge and add the VLAN interface to that as a port, set the admin MAC on the bridge, and add the PPPoE client to the bridge.Do you mean bridge+nat?
You can probably do that using a bridge...
I think it's too complicated, and may be it will affect performance.
bummer, missed that. thanks for pointing it out, albeit it doesn't make me any happier. there are certain platforms where the so called function keys don't mix really well with terminal. while it's not impossible to hold 'fn' while pressing F1, please at least make this configurable so old school folks like me can keep on working as before. switching between multiple network platforms is alone a PITA, but rendering '?' inoperable is a whole new level of inconvenience.As noted by the terminal when You open it up:
/console set help-key=\?
Kindly update https://help.mikrotik.com/docs/display/ ... col+StatusRouterOS version 7.1rc1 has been released in public "development" channel!
It's ok if you only have a little pppoe clients. But if you have 20+,50+ or even 100+ pppoe clients, and each one needs unique mac address, then i don't think it's acceptable.No. You can add a VLAN to your ethernet port to get the VLAN tag, then create a bridge and add the VLAN interface to that as a port, set the admin MAC on the bridge, and add the PPPoE client to the bridge.
Do you mean bridge+nat?
I think it's too complicated, and may be it will affect performance.
That should result in VLAN-tagged PPPoE packets with your specified MAC address, I think.
Maybe you should consider adding relevant informations to the questions you post... it is not even clear if you are a PPPoE client or PPPoE server.It's ok if you only have a little pppoe clients. But if you have 20+,50+ or even 100+ pppoe clients, and each one needs unique mac address, then i don't think it's acceptable.
++bummer, missed that. thanks for pointing it out, albeit it doesn't make me any happier. there are certain platforms where the so called function keys don't mix really well with terminal. while it's not impossible to hold 'fn' while pressing F1, please at least make this configurable so old school folks like me can keep on working as before. switching between multiple network platforms is alone a PITA, but rendering '?' inoperable is a whole new level of inconvenience.As noted by the terminal when You open it up:
i'm not the one to stop progress, but can we have a settable option in /console ? like so:
Code: Select all/console set help-key=\?
It's working as ovpn client, I was able to establish connection to my CCR1036 in production, I haven't test though as a serveropenvpn didn’t work and it doesn’t work
same hererb750 gr3
system/health
temperature is missing
voltage is 0.5v
both, winbox & SNMP
/system/backup/cloud/upload-file action=create-and-upload password=mikrotik
i'm not the one to stop progress, but can we have a settable option in /console ? like so:As noted by the terminal when You open it up:
Code: Select all/console set help-key=\?
i'm not the one to stop progress, but can we have a settable option in /console ? like so:
Code: Select all/console set help-key=\?
PLEASE allow the help key to be bound to alternative mappings, or just return it to ?
Great idea, btw!Or at the very least, backport the show-sensitive option to v6 so that we can use it on v6 devices without them throwing errors.
Also, since we're here: can "CTRL+V" be un-mapped from autocomplete? I've seen so many people think thei'r router is cursed/haunted, it's not funny anymore.Code: Select all/console set help-key=\?
No, that is the result of you using Ctrl-V to paste something, then see that it does not work and paste with right-mouse menu instead.Edit: While pasting a multilined command (containing "\") into the terminal, WinBox produces a lot of output, because a preview of all lines is shown for every character.
Also, since we're here: can "CTRL+V" be un-mapped from autocomplete? I've seen so many people think thei'r router is cursed/haunted, it's not funny anymore.
Can you please have a look at SUP-56377 or at post viewtopic.php?f=1&t=177803... (free to post here or write to us to support@mikrotik.com).
.
.
.
.
.
.
.
.
.
.
.
.
"Extreme Performances" ARM64 Series:
CCR-eOW-12x100G-36x25Gw
CCR-eOW-1x25Gw-2x10G
CCR-eOW-1Gw-1G
ARM64:
CCR2116-12G-4S+
CRS520-4xS-16xQ
What is "Gw" anyway? If there's a CCR with two 1G ports, then that would be interesting.CCR-eOW-12x100G-36x25Gw
CCR-eOW-1x25Gw-2x10G
CCR-eOW-1Gw-1G
[Interface]
PrivateKey = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx=
Address = 10.7.0.1/24
MTU = 1420
ListenPort = 51821
PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -t nat -A POSTROUTING -o wlp58s0 -j MASQUERADE
PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -t nat -D POSTROUTING -o wlp58s0 -j MASQUERADE
### begin mikrotik ###
[Peer]
PublicKey = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx=
PresharedKey = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx=
AllowedIPs = 10.7.0.3/32
### end mikrotik ###
The eOW models are a joke from MikroTik. Something about Ethernet over Water or something like that. You can find it with a Google fairly easily. The other two models will be legit but they have been in the code for a while.Under the hood there is also...
SPOILER!!! Do not scroll!!!
Code: Select all. . . . . . . . . . . . "Extreme Performances" ARM64 Series: CCR-eOW-12x100G-36x25Gw CCR-eOW-1x25Gw-2x10G CCR-eOW-1Gw-1G ARM64: CCR2116-12G-4S+ CRS520-4xS-16xQ
No, it's on my pppoe Internet connection. I didn't think there was a point in using CAKE on LTE since I don't know the available uplink speed. Or do I?Where are you targeting the CAKE queue? At the LTE connection? Has it been stable? I wanted to try our CAKE + Autorate Ingress (given my LTE connection bandwidth is quite random).So far all is working fine on my CRS317, RB4011 and LtAP-Mini (+R11e-LTE6). Noteworthy features in use are IPv6 to Internet, IPv6 over Wireguard (multiple tunnels), CAKE using queue tree. Lets see how stable it is ...
/ip dhcp-server
add address-pool=dhcp interface=bridge-lan name=dhcp-lan
#error exporting /mpls/traffic-eng/path
#interrupted
[admin@MikroTik] >
This is not the same as RB mEOW. CCR-eOW is a new improved model.The eOW models are a joke from MikroTik. Something about Ethernet over Water or something like that. You can find it with a Google fairly easily. The other two models will be legit but they have been in the code for a while.
Frankly I am surprised that v7 even boots on a hAP lite...Sadly, the issue I've reported several times that's preventing me from testing v7 on my hAP lite was not fixed or ignored. Reporting it again in hope that it will be fixed in the next rc.
Most of the time it is working with no problems, but I couldn't touch anything and test different features. I wasn't reverted to v6, so I'll be waiting for any updates from devs.Frankly I am surprised that v7 even boots on a hAP lite...
bgp-as-path
{regexp}
AFAIU, that's what autorate-ingress is for.No, it's on my pppoe Internet connection. I didn't think there was a point in using CAKE on LTE since I don't know the available uplink speed. Or do I?
Where are you targeting the CAKE queue? At the LTE connection? Has it been stable? I wanted to try our CAKE + Autorate Ingress (given my LTE connection bandwidth is quite random).
how can you show me an example?Isn't that what you're looking for?..https://help.mikrotik.com/docs/pages/vi ... d=74678285Code: Select allbgp-as-path {regexp}
I also have the same issue with RB4011. Did you get a reply on your support ticket about this one?Hi,
I can't update an RB3011 to the latest rc1 from beta6.
RIght after reboot, the router starts on beta6 again. Opening up a terminal it gives me an error about a kernel panic. Any ideas about this?
I've also made a support ticket: SUP-58027.
/certificate enable-ssl-certificate dns-name=your.domain.tld
[admin@thyone] /routing/ospf/interface-template> add networks=2001:db8::/64 area=backbone-v3
[admin@thyone] /routing/ospf/interface-template> print where area=backbone-v3
Flags: X - disabled, I - inactive
1 area=backbone-v3 instance-id=0 networks=/64 type=broadcast retransmit-interval=5s transmit-delay=1s hello-interval=10s dead-interval=40s priority=128 cost=1
[brg3466@LtAP] > interface/lte/firmware-upgrade lte1 once
installed: R11eL_v05.03.183961
latest: R11eL_v05.04.193841
/queue type
add cake-diffserv=besteffort kind=cake name=cake
/queue simple
add bucket-size=0.01/0.01 dst=vlan999 max-limit=90M/90M name=wan queue=cake/cake target=192.168.88.0/24
Which winbox version is that? Routing -> Filters gives me a text representation of filters, and editing one is a freeform text box, not winbox-style editingwhat is the syntax to use BGP AS-PATH in the ROSv7 filter ?
Yes, it seems that limit and target-address are required.Looks like CAKE doesn't cause a kernel panic if the target of your simple queue is an IP address instead of an interface, I setup mine like this where vlan999 is my WAN and 192.168.88.0/24 my LAN.
(notice that leaving the destination empty will throttle your LAN speeds which is really bad)
Code: Select all/queue type add cake-diffserv=besteffort kind=cake name=cake /queue simple add bucket-size=0.01/0.01 dst=vlan999 max-limit=90M/90M name=wan queue=cake/cake target=192.168.88.0/24
I don't think this should be the intended behavior, Mikrotik users (and guides on the internet) have been applying simple queues directly to interfaces for years without issues.Yes, it seems that limit and target-address are required.Looks like CAKE doesn't cause a kernel panic if the target of your simple queue is an IP address instead of an interface, I setup mine like this where vlan999 is my WAN and 192.168.88.0/24 my LAN.
(notice that leaving the destination empty will throttle your LAN speeds which is really bad)
Code: Select all/queue type add cake-diffserv=besteffort kind=cake name=cake /queue simple add bucket-size=0.01/0.01 dst=vlan999 max-limit=90M/90M name=wan queue=cake/cake target=192.168.88.0/24
We have not admitted that it is expected behavior. Currently we heavily researching the issue and looking for the fix!I don't think this should be the intended behavior, Mikrotik users (and guides on the internet) have been applying simple queues directly to interfaces for years without issues.
Yes, it seems that limit and target-address are required.
It works great with the V6 queue types but V7 ones such as CAKE, Codel or fq_codel are causing kernel panic and bootloop issues with this setup.
I have codel directly on my wifi interface queue and no crashes so far, didnt try cake yet but I'm sure that one would crash.I don't think this should be the intended behavior, Mikrotik users (and guides on the internet) have been applying simple queues directly to interfaces for years without issues.
Yes, it seems that limit and target-address are required.
It works great with the V6 queue types but V7 ones such as CAKE, Codel or fq_codel are causing kernel panic and bootloop issues with this setup.
You can tag wifiwave2 wireless traffic by following the generic bridge vlan configuration example shown here.Wave 2 on audience can't do vlan tagging. srsly.....
Why you ruin the joke so fast...???The eOW models are a joke from MikroTik. Something about Ethernet over Water or something like that.
Thanks for the heads up. Indeed in both cases when I tried FQ Codel and Cake Winbox was open to monitor the logs.This might sound bizarre, but anyone experiencing kernel crashes with cake/fq_codel, can you confirm the router is stable if there is no active WinBox session to the device? We currently think the crashes are caused by WinBox management session shaping.
Of course with any shaping that is done to provide QoS it would be nice when it could be done directly at the point where the bottleneck occurs.Will there be a way to have CAKE without a bandwidth limit? I'd like to see a version where it detects packet loss and automatically enables queueing.
No BSD Syslog flag ->
Aug 25 11:11:12 tik-vpn-1-lan.hellasdirect.gr system,info log action changed by admin
Aug 25 11:11:13 warning denied winbox/dude connect from 118.174.111.6
Aug 25 11:11:47 warning denied message repeated 12 times: [ winbox/dude connect from 118.174.111.6]
Enable BSD Syslog flag ->
Aug 25 11:11:49 tik-vpn-1-lan.hellasdirect.gr #000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000
Aug 25 11:11:50 tik-vpn-1-lan.hellasdirect.gr #000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000
Cake is rebooting the router after an hour, no Winbox session opened, trying now with fq codel...Thanks for the heads up. Indeed in both cases when I tried FQ Codel and Cake Winbox was open to monitor the logs.This might sound bizarre, but anyone experiencing kernel crashes with cake/fq_codel, can you confirm the router is stable if there is no active WinBox session to the device? We currently think the crashes are caused by WinBox management session shaping.
Trying with Winbox closed on a RB4011.
I will report back later
/ip firewall mangle
add action=mark-connection chain=postrouting comment=wan connection-state=new new-connection-mark=wan-conn out-interface-list=WAN passthrough=yes
add action=mark-connection chain=prerouting comment=wan connection-state=new in-interface-list=WAN new-connection-mark=wan-conn passthrough=yes
add action=mark-packet chain=postrouting comment=wan connection-mark=wan-conn new-packet-mark=wan-out-pk out-interface-list=WAN passthrough=no
add action=mark-packet chain=prerouting comment=wan connection-mark=wan-conn in-interface-list=WAN new-packet-mark=wan-in-pk passthrough=no
/queue type
add kind=sfq name=fair
/queue tree
add bucket-size=0.002 max-limit=95M name=wan-in packet-mark=wan-in-pk parent=global queue=fair
add bucket-size=0.002 max-limit=47500k name=wan-out packet-mark=wan-out-pk parent=global queue=fair
wAP R with Sierra MC7430 works fine, but it also worked fine with 7.1beta6.Did anyone tried MBIM based cards like Sierra MC7455? last working version is 7.1beta2
Using winbox GUI not in the terminal were able to backup and upload the config, but can't delete thoughresults in kernel panicCode: Select all/system/backup/cloud/upload-file action=create-and-upload password=mikrotik
`system,error,critical router was rebooted without proper shutdown, probably kernel failure`
Airtime fairness is enabled by default for wifiwave2 interfaces.Wifi LED on Hap ac^3 doesn't seem to work after installing the wifiwave2 package and there's no way to configure it in the system/LEDs panel.
By the way, does the wifiwave2 on ROS support airtime fairness?
time=17:35:10 topics=pppoe,ppp,info message=pppoe-wan: disconnected
time=17:35:10 topics=script,warning message=ivicask ppp profile on-down test, if you see this, it works.
time=17:35:15 topics=pppoe,ppp,info message=pppoe-wan: initializing...
time=17:35:15 topics=pppoe,ppp,info message=pppoe-wan: connecting...
time=17:35:18 topics=pppoe,ppp,info message=pppoe-wan: authenticated
time=17:35:18 topics=pppoe,ppp,info message=pppoe-wan: connected
time=17:35:18 topics=system,info message=address list entry removed
time=17:35:18 topics=script,warning message=ivicask ppp profile on-up test, if you see this, it also works.
time=17:35:28 topics=system,info message=address list entry added
Iv put only this for test in both up and down, and its default profile and assigned to only pppoe connection i have..Check your scripts for whatever is broken.Code: Select alltime=17:35:10 topics=pppoe,ppp,info message=pppoe-wan: disconnected time=17:35:10 topics=script,warning message=ivicask ppp profile on-down test, if you see this, it works. time=17:35:15 topics=pppoe,ppp,info message=pppoe-wan: initializing... time=17:35:15 topics=pppoe,ppp,info message=pppoe-wan: connecting... time=17:35:18 topics=pppoe,ppp,info message=pppoe-wan: authenticated time=17:35:18 topics=pppoe,ppp,info message=pppoe-wan: connected time=17:35:18 topics=system,info message=address list entry removed time=17:35:18 topics=script,warning message=ivicask ppp profile on-up test, if you see this, it also works. time=17:35:28 topics=system,info message=address list entry added
Isn't this what autorate-ingress is all about? I'm waiting to have CAKE stable to test this on my LHGGR LTE6, mainly for bufferbloat management and naturally making sure that no one here at home kills the entire connection ).Will there be a way to have CAKE without a bandwidth limit? I'd like to see a version where it detects packet loss and automatically enables queueing.
/ipv6 route
add disabled=no distance=1 dst-address=/0 gateway=fc00:bbbb:bbbb:bb01::1 routing-table=vpn scope=30 target-scope=10
add disabled=no distance=1 dst-address=/0 gateway=fc00:bbbb:bbbb:bb01::1 routing-table=vpn scope=30 target-scope=10
I thought so, but the Mik Wiki doesn't say how to enable autorate-ingress.Isn't this what autorate-ingress is all about?
So, "set priority from DSCP" copies priority value from IP packet to pppoe frame with that packet?..Hooray! now there is no more need to do queueing on the MikroTik for QoS, I just need to do a mangle "set priority from DSCP", the priority is copied into the VLAN header sent to the modem, and the modem has 8 queues to sort the priority at the moment the packets are transmitted!
Hi,I also have the same issue with RB4011. Did you get a reply on your support ticket about this one?Hi,
I can't update an RB3011 to the latest rc1 from beta6.
RIght after reboot, the router starts on beta6 again. Opening up a terminal it gives me an error about a kernel panic. Any ideas about this?
I've also made a support ticket: SUP-58027.
I had the Mikrotik Android app open on my phone to measure the CPU usage of the router when downloading large files from my laptop, then it crashed after some minutes.This might sound bizarre, but anyone experiencing kernel crashes with cake/fq_codel, can you confirm the router is stable if there is no active WinBox session to the device? We currently think the crashes are caused by WinBox management session shaping.
What if you try FastTrack winbox packets, will they avoid queue and maybe fix the issue until proper fix is done?I had the Mikrotik Android app open on my phone to measure the CPU usage of the router when downloading large files from my laptop, then it crashed after some minutes.This might sound bizarre, but anyone experiencing kernel crashes with cake/fq_codel, can you confirm the router is stable if there is no active WinBox session to the device? We currently think the crashes are caused by WinBox management session shaping.
Target interface was vlan999 (WAN) and queue type CAKE.
Maybe it can do the trick but the simple queue setup I described some posts above it's working great for me.What if you try FastTrack winbox packets, will they avoid queue and maybe fix the issue until proper fix is done?
This is an issue on boards with country locks. It will be fixed in rc2.Creating a new WIFI Wave 2 interface and assigning the same country code as the physical interfaces reports "Country not allowed"
I cannot create a sub interface whatsoever.
Not yet, no.Does wifiwave2 have four address mode support yet?
set the skin on webfigWhere a can find skins in winbox?What's new in 7.1rc1 (2021-Aug-19 13:06):
*) added skin support for WinBox (WinBox v3.29 required);
these items were in the code for a while. but the 12x100GE + 36x25GE is nothing too far fetched. there are a dozen of SoCs out there that aren't too expensive, pack a significant punch and the 25/50/100G geared capabilities can essentially totally back the name: you can break down a single 100GE into 4x25GE, so this would be handled by 21 x 100GE which is not unheard of.The eOW models are a joke from MikroTik. Something about Ethernet over Water or something like that. You can find it with a Google fairly easily. The other two models will be legit but they have been in the code for a while.
My RouterOS v7 test lab consists of 3x RB3011.Rb3011 uias-rm
after 23h, it is frozen
Will it be added in time for 7.1 Release ?Not yet, no.Does wifiwave2 have four address mode support yet?
@nz_monkeyMy RouterOS v7 test lab consists of 3x RB3011.
They are all happily running with OSPF + LDP with no lockups or reboots.
That takes quite some space, which is at a premium in some devices.IMO ROS should have all major Root-CAs included by default. Saves a lot of headache with LE and DoH.
Hi, since we don't have access to internal shell.We have not admitted that it is expected behavior. Currently we heavily researching the issue and looking for the fix!
tc qdisc list
tc filter list
tc class list
This might sound bizarre, but anyone experiencing kernel crashes with cake/fq_codel, can you confirm the router is stable if there is no active WinBox session to the device? We currently think the crashes are caused by WinBox management session shaping.
Same here 3 totally different devices, I set fq codel mixed configs, from wifi interfaces, pppoe and queues and they all have 3 days uptime now.Interestingly, my RB4011 has fq_codel on all interfaces and never crashes because of fq_codel.
I've faced the same when I tried to upgrade from beta6 to rc1.Hi,
I can't update an RB3011 to the latest rc1 from beta6.
RIght after reboot, the router starts on beta6 again. Opening up a terminal it gives me an error about a kernel panic. Any ideas about this?
I've also made a support ticket: SUP-58027.
have u simulate vrf / L3 vpn on your mpls? BGP vpn4My RouterOS v7 test lab consists of 3x RB3011.Rb3011 uias-rm
after 23h, it is frozen
They are all happily running with OSPF + LDP with no lockups or reboots.
Weird, because in beta6, Torch was showing IPv6 traffic for me.This behaviour was also in previous betas.
Yes there is a possibility that the router rebooted for another reason than fq codel. I'll try sfq and see if the router reboots. Then I'll try codel againSame here 3 totally different devices, I set fq codel mixed configs, from wifi interfaces, pppoe and queues and they all have 3 days uptime now.Interestingly, my RB4011 has fq_codel on all interfaces and never crashes because of fq_codel.
I'm also interested to know how ROS handles qdiscs internally from the Linux perspective.Hi, since we don't have access to internal shell.
Could you set simple or queue tree with cake/fq_codel scheduler and share output from this command?
Code: Select alltc qdisc list tc filter list tc class list
I've faced the same when I tried to upgrade from beta6 to rc1.Hi,
I can't update an RB3011 to the latest rc1 from beta6.
RIght after reboot, the router starts on beta6 again. Opening up a terminal it gives me an error about a kernel panic. Any ideas about this?
I've also made a support ticket: SUP-58027.
Are you using the wifiwave2 drivers nor CAKE/fq_codel/CoDel queues in your Audience?Audience is crashing regularly- like every 10-20h.
No support file created weirdly.
Changed to persist logs so will update you soon.
RB4011 is ok however.
What about WMM support in wifiwave2?
Airtime fairness is enabled by default for wifiwave2 interfaces.
ip firewall filter add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related hw-offload=yes
Thank you so much, now everything has become clear. Can you tell me where can I find more information about the Firewall hardware offloading implementation in RouterOS?hw-offload=yes means that this rule can be offloaded to hardware, as long as it supports offloading.
I hope soBy the way, there's AX option in the wireless band settings of wifiwave2 interfaces. Does this mean that we will see WiFi 6 devices from Mikrotik soon? Maybe a wireless version of RB5009?
[mjraiha@dibbler] /system package> print
Flags: X - disabled
# NAME VERSION
0 ipv6 6.48.4
1 mpls 6.48.4
2 routing 6.48.4
3 ppp 6.48.4
4 advanced-tools 6.48.4
5 system 6.48.4
6 hotspot 6.48.4
7 dhcp 6.48.4
8 security 6.48.4
9 wireless 6.48.4
[mjraiha@dibbler] /system routerboard> print
routerboard: yes
board-name: RBM33G
model: RouterBOARD M33G
serial-number: xxxxxxxxxxxx
firmware-type: mt7621L
factory-firmware: 3.41
current-firmware: 6.48.4
upgrade-firmware: 6.48.4
not sure whether you noticed this in one of the sheets on the hw offloading page... CRS326-4C+20XG-2Q+
I tried to upgrade from 6.48.4 to 7.1rc1 via WebGUI and via CLI – both fails.
Also on the 5009? Why is there no IPsec performance data on the webpage, I thought that normally means "no hw accel encryption"?IPsec hw offloading has been supported since the first releases of v7beta.
Using wave2 and simple vlans. Can’t paste my config as I am away and have mobile only.Are you using the wifiwave2 drivers nor CAKE/fq_codel/CoDel queues in your Audience?
Godo point, thanks. I found these.Anything in log after device reboots (and fails to upgrade)?I tried to upgrade from 6.48.4 to 7.1rc1 via WebGUI and via CLI – both fails.
Since there's only bundle package available for ROSv7, you might have to netinstall your device to resolve (or rather skip) package dependency problem.
11:52:03 system,error broken package wireless-7.1rc1-mmips.npk
11:52:03 system,error broken package security-7.1rc1-mmips.npk
11:52:03 system,error broken package dhcp-7.1rc1-mmips.npk
11:52:03 system,error broken package hotspot-7.1rc1-mmips.npk
11:52:03 system,error broken package advanced-tools-7.1rc1-mmips.npk
11:52:03 system,error broken package ppp-7.1rc1-mmips.npk
11:52:03 system,error broken package routing-7.1rc1-mmips.npk
11:52:03 system,error broken package mpls-7.1rc1-mmips.npk
11:52:03 system,error broken package ipv6-7.1rc1-mmips.npk
11:52:03 system,info installed system-7.1rc1
11:52:03 system,error not enough space for upgrade
11:52:03 system,info router rebooted
What about conditional vlan tagging based on ACL?You can tag wifiwave2 wireless traffic by following the generic bridge vlan configuration example shown here.
The vlan tagging settings in the regular wireless package were redundant and so have not been ported to wifiwave2.
hopefully a lot of users like me will order 5009 only whenNo, 5009 does not have IPsec hw acceleration yet (hopefully). I was referring to devices that has hw offloading in v6.
This makes me very happy, can't wait for the igmp-proxy to be there.....
PIM is already available in rc1. IGMP Proxy will be available in rc2.
Well, I can sort of understand that when you announce a new router with roaring statements like "Double the usual performance: we took your feedback from the MikroTik User Meetings to create the perfect home lab router" and "Boards come with 1GB of DDR4 RAM and 1GB NAND storage. This combination of ports and components, compared to our other products in a similar form factor, provides almost double the performance in configurations with heavy CPU loads", prospective buyers can get the idea that it will be able to do fast IPsec.What? Nowhere in the product description does it mention it has hardware accelerated IPsec. I do not see any reason why would you believe it is supported in the first place. We can not write all the features the devices does not have in the product description. We write about features it supports.
/ipv6/address> export
/ipv6 address
add address=::cxxd:e0xx:fexx:xx66 eui-64=yes from-pool=ULA interface=bridge
add address=::cxxd:e0xx:fexx:xx66 eui-64=yes from-pool=wan-PD interface=bridge
/ipv6/address> print
Flags: D - DYNAMIC; G, L - LINK-LOCAL
Columns: ADDRESS, FROM-POOL, INTERFACE, ADVERTISE
# ADDRESS FROM-POOL INTERFACE
0 G fded:xxff:xxf5:x:cxxd:e0xx:fexx:xx66/64 ULA bridge
7 G 2a02:xx0d:xx0:x:cxxd:e0xx:fexx:xx66/64 wan-PD bridge
I like the F1 option and hiding of the "help text" on terminal startup. I only know about the "?" help because in /interface/lte/at-chat this avoids having to escape the ? in AT commands which is a real PITA in scripting AT commands.bummer, missed that. thanks for pointing it out, albeit it doesn't make me any happier. there are certain platforms where the so called function keys don't mix really well with terminal. while it's not impossible to hold 'fn' while pressing F1, please at least make this configurable so old school folks like me can keep on working as before. switching between multiple network platforms is alone a PITA, but rendering '?' inoperable is a whole new level of inconvenience.As noted by the terminal when You open it up:
i'm not the one to stop progress, but can we have a settable option in /console ? like so:
Code: Select all/console set help-key=\?
What about SMIPS?Please add both root certificate for DigiCert Global Root CA and GTS Root R1 to the Kernel then we have DOH working too.
Dude, count me in pleaseMikrotik support kindly helped me with the download link of ROS 7.1 rc2, can confirm that CAKE simple queues no longer crash my hAP ac2.
Good job MT
umm great except for alot of people who are literally never going to see they have to email for a fix. Please use your brains and publish a fix that's easily obtainable instead of emailing generic support for the new release that you apparently already have compiled.We have fixed "cake" reboots, in case you want to try prerelease rc2 version on your setup. Please contact us directly (support@mikrotik.com). We will provide you with packages to test.
Here's a copy of rc2, but only the ARM32 version: https://streetlights.info/nc/s/t7zctZXirrnk2xjPlease use your brains and publish a fix that's easily obtainable instead of emailing generic support for the new release that you apparently already have compiled.
Woah, someone with a brain! Thank you very much for everyone that comes here for some reason looking for rc2.Here's a copy of rc2, but only the ARM32 version: https://streetlights.info/nc/s/t7zctZXirrnk2xjPlease use your brains and publish a fix that's easily obtainable instead of emailing generic support for the new release that you apparently already have compiled.
If it's not too complicated for you, you can check the current endpoint address and port from CLI.is it too complicated for MT to implement this ?
/interface/wireguard/peers/print detail
/interface/wireguard/peers/print proplist=public-key,current-endpoint-address,current-endpoint-port
So people that get RC2 early will have to update to RC2?
There will be two different RC2 floating around with the same version number? Are you sure you are making sense?
I guess so, as a software developer you can release RC2 with build number 107 for internal testing and then re-release RC2 with build number 115 to the general public.So people that get RC2 early will have to update to RC2?
There will be two different RC2 floating around with the same version number? Are you sure you are making sense?
My hAP ac2 can be updated just fine to any ROS version, I only need Netinstall when coming back from OpenWrt.anyone who successfuly updated hAP ac2 118mb edition? i always ended up with brick with any beta version. any netinstall version, but beta recovers it luckily.
do u have 128 mb?My hAP ac2 can be updated just fine to any ROS version, I only need Netinstall when coming back from OpenWrt.anyone who successfuly updated hAP ac2 118mb edition? i always ended up with brick with any beta version. any netinstall version, but beta recovers it luckily.
Currently it's running the 7.1 rc2 firmware provided by Mikrotik support through email.
[admin@rbm33g] > /interface lte at-chat 0 input="AT"
Console has crashed; please log in again.
Shared connection to 192.168.4.2 closed.
The F1 key is a PITA. I was connected via Ajaxterm to one of my routers. Like most applications F1 does indeed bring up the help application but it's the one for the browser. It might be unusual not to use Putty or any *NIX terminal but there are others like me who might use something different and the F1 key just doesn't work.I like the F1 option and hiding of the "help text" on terminal startup. I only know about the "?" help because in /interface/lte/at-chat this avoids having to escape the ? in AT commands which is a real PITA in scripting AT commands.
Doesn't the <tab> key provide the same information as "?" in most/all cases (other than the initial "help screen")?
Hi @ZnevnaIf it's not too complicated for you, you can check the current endpoint address and port from CLI.
is it too complicated for MT to implement this ?
Actually, GUI is not the traditional OpenWRT way. Years ago the OpenWRT base images did not even include LUCI. And most Wiki articles were solely showing off UCI commands.when i said "like in OpenWRT" ... here i mean, GUI way
Yes, only the first batches came with 256MB RAM.do u have 128 mb?
My hAP ac2 can be updated just fine to any ROS version, I only need Netinstall when coming back from OpenWrt.
Currently it's running the 7.1 rc2 firmware provided by Mikrotik support through email.
This is actually something I always wonder about when seeing new RouterOS developments.I guess MT will implement this. However ROS and Winbox are two separate projects and since ROSv7 is in heavy development stage with changes in UI/API it's very much a moving target.is it too complicated for MT to implement this ?
My router won't update either from v7.1beta6 to v7.1rc1. It's an RB2011UiAS-2HnDHi,
I can't update an RB3011 to the latest rc1 from beta6.
RIght after reboot, the router starts on beta6 again. Opening up a terminal it gives me an error about a kernel panic. Any ideas about this?
I've also made a support ticket: SUP-58027.
My router won't update either from v7.1beta6 to v7.1rc1. It's an RB2011UiAS-2HnD
You think they would have fixed it for V7. I don't have to jump out of ASDM for cisco just to manage my ASA."Only available from commandline" has been around for years. It's not v7 specific.
Indeed. But don't you also think it is strange? I would think there is not much work (certainly not coding, maybe entering some sequence/placement info) to add features that are already done for commandline to the webfig/winbox environment. Especially windows that just show a table of status information."Only available from commandline" has been around for years. It's not v7 specific.
You think they would have fixed it for V7. I don't have to jump out of ASDM for cisco just to manage my ASA."Only available from commandline" has been around for years. It's not v7 specific.
Indeed. But don't you also think it is strange?"Only available from commandline" has been around for years. It's not v7 specific.
Not have to, but they may need to update to a final version of rc2 to apply some changes introduced later.So people that get RC2 early will have to update to RC2?
Not floating around unless "people with brain" ((c) paintballer4lfe) make internal versions public before the actual release. That internal version is just to test one specific fix by limited number of people, everyone else should wait for rc2 official release.There will be two different RC2 floating around with the same version number? Are you sure you are making sense?
yes, it actually does!My router won't update either from v7.1beta6 to v7.1rc1. It's an RB2011UiAS-2HnD
Does log have anything about it?
There were and still are a lot of things in stable/lt that can only be configured using cli.I don't think any of "stable" let alone "long-term" releases ever had any CLI-only item.
Send an email to Mikrotik support.hi. maby anybody have a wave2 rc2 for arm32? Thank you.
/ipv6 firewall filter
add action=accept chain=forward comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop everything else not coming from LAN" disabled=yes in-interface-list=!LAN
/log/print
time=17:21:41 topics=wireguard,info,debug message=wireguard-server1: <key removed>: Handshake for peer did not complete after 5 seconds, retrying (try 20)
time=17:21:46 topics=wireguard,info,debug message=wireguard-server1: <key removed>: Handshake for peer did not complete after 20 attempts, giving up
That's "topic", not "level". They are not equivalent. I don't think there's such thing as log level in RouterOS.Log level should be either info or debug, but not both at same time.
https://mikrotik.com/download/changelogsI don't think any of "stable" let alone "long-term" releases ever had any CLI-only item.
Aside from the many topics for components, programs, you have these topics: debug, info, warning, error, critical. In fact these are log levels no matter how MikroTik calls them.That's "topic", not "level". They are not equivalent. I don't think there's such thing as log level in RouterOS.Log level should be either info or debug, but not both at same time.
You can only specify severity for a certain combination of topics when sending log records to a remote syslog server, but that's it.
You didn't have to embarrass him in front of everyone, but I'm glad you did.https://mikrotik.com/download/changelogsI don't think any of "stable" let alone "long-term" releases ever had any CLI-only item.
Stable > Expand > Search "CLI Only"
Screenshot_3.png
I think you misunderstood me. I'm not complaining about logging in general. Wireguard is a v7 feature and that does not use the logging facility correctly, i think. These are the default logging rules@Buster2, logging topics have always worked like that.
Next time you want to complain about something similar, please do that in a separate topic as it is in no way 7.1rc1 specific.
/system logging
set 0 action=memory disabled=no prefix="" topics=info
set 1 action=memory disabled=no prefix="" topics=error
set 2 action=memory disabled=no prefix="" topics=warning
set 3 action=echo disabled=no prefix="" topics=critical
My discussion is not about running Release Candidate versions and who should or should not do that (in another topic MikroTik recommend running 7.1rc1 on hardware delivered with 7.0.3 because it should solve problems).
Indeed. But don't you also think it is strange?
No it's not strange. ROSv7 is more than simple replacement of kernel, it's also change in ABI and sometimes API has to reflect that.
This is a Release Candidate for Christ sake, if you are such faint of heart, stick to long-term (and use stable in lab environments). If you really want to test cutting edge stuff, expect incomplete things and stop crying. One thing is to report it's not working, completely different thing is to fuss about it for days.