What do you mean exactly? Currently "upgrade" channel should show this 7.1.1 release.And when upgrading from v6, you need to pick 'upgrade' channel, right? Looks like it falls back to stable
Should be fixed in 7.2rc1Wireguard IPv6 peer bug is still present... how hard is to check what changed from 7.1rc4?
I mean, 'testing' was an old way of upgrading from v6 to v7, now you need to use 'upgrade' channel. And there's no 'upgrade' in v7, so looks like everything works just like russelld expects, except he upgraded to v7 quite long time agoWhat do you mean exactly? Currently "upgrade" channel should show this 7.1.1 release.
No, I can´t find it anymore.Does v7 have UPS package?
Just tested the 7.2rc1, not fixedWhat do you mean exactly? Currently "upgrade" channel should show this 7.1.1 release.And when upgrading from v6, you need to pick 'upgrade' channel, right? Looks like it falls back to stable
Should be fixed in 7.2rc1Wireguard IPv6 peer bug is still present... how hard is to check what changed from 7.1rc4?
Will probably be part of future release. Didn't see it yet in any of the other 7.x releases (Dev/Test) as well.Does v7 have UPS package?
Let's be more specific here, as we have two issues:Should be fixed in 7.2rc1Wireguard IPv6 peer bug is still present... how hard is to check what changed from 7.1rc4?
All my IPSec connections were down on a CCR1009... A reboot sorted this. No idea what happened, sadly I missed to generate a support output file.Any update / input / remark / comment on the IPSec issues lots of people are having ?
I do use packet mark (based on DSCP value) and it appears to work for me.I still have problem with mark packet in ipv6.
When it is enable all traffic pass from input and drop to forward as invalid.
The connections show tab is empty.
When i disable mark packet, all work perfect but i have not QoS.
or fetch from a specific IP. Like a loopback while you use private IP's on the point to point links...Feature request: fetch via specific interface (curl --interface ...)
I have run into this multiple times. from 6.X to 7.1bet and from 7.1beta to 7.1 release I ended up with /ip ipsec identity being completely blank.Upgraded my RB4011 from 7.1 to 7.1.1 and it appears to work ok, also IPsec.
There is an IPsec issue with statically configured /ip ipsec identity which disappears after reboot, but it turns out that already existed in 7.1
(after re-adding it manually from export made before the upgrade IPsec works OK for me)
+1Connecting several peers just leaves the last one touched with a functional IPv6 connection. I think this is what is still broken. (Did not yet test myself.)
This behavior is described in SUP-67181. Please have a look and fix this, it hurts me as well.
Could not mount ubifs/yaffs filesystem: No such device
[ 10.000322] Kernel panic - not syncing: Attempted to kill init! exitcode=0x00000000
[ 10.000437] CPU: 1 PID: 1 Comm: init Not tainted 5.6.3 #1
[ 10.000494] frame 0: __schedule+0x12288/0x7e0fb8 (sp 0xfffffe007a70fb20)
[ 10.002498] frame 1: __schedule+0x7bb290/0x7e0fb8 (sp 0xfffffe007a70fb90)
[ 10.010159] frame 2: __schedule+0x3ca50/0x7e0fb8 (sp 0xfffffe007a70fbc0)
[ 10.017725] frame 3: __schedule+0x40ca0/0x7e0fb8 (sp 0xfffffe007a70fc80)
[ 10.025290] frame 4: __schedule+0x431a8/0x7e0fb8 (sp 0xfffffe007a70fd20)
[ 10.032856] frame 5: __schedule+0x43270/0x7e0fb8 (sp 0xfffffe007a70fd60)
[ 10.040422] frame 6: __schedule+0x7de800/0x7e0fb8 (sp 0xfffffe007a70fd80)
[ 10.048081] <syscall 94 while in user mode>
[ 10.052926] frame 7: 0x45040 (sp 0x7f9cfb30)
[ 10.057768] Rebooting in 5 seconds..
Resetting chip and restarting.
logo.bmp not found or data is corrupted
Why would you like to add an additional bridge that is not necessary?How i can fix this please?
[admin@mikrotik.bla bla] > ip address/print
Flags: X, I, D - DYNAMIC
Columns: ADDRESS, NETWORK, INTERFACE
# ADDRESS NETWORK INTERFACE
0 192.168.1.1/24 192.168.1.0 br-vlan101
1 192.168.2.1/24 192.168.2.0 br-vlan102
2 10.128.63.1/24 10.128.63.0 br-vlan110
3 192.168.11.1/24 192.168.11.0 br-vlan111
4 X 84.242.114.116/29 84.242.114.112 ether1
5 192.168.3.1/24 192.168.3.0 br-vlan103
6 192.168.4.1/24 192.168.4.0 br-vlan104
7 192.168.15.1/24 192.168.15.0 br-vlan115
8 192.168.14.133/30 192.168.14.132 wireguard-bla
9 192.168.14.137/30 192.168.14.136 wireguard-bla1
10 I 192.168.14.141/30 192.168.14.140 wireguard-bla2
11 D 192.168.99.145/24 192.168.99.0 ether1
12 D 192.168.14.123/32 192.168.14.124 <ovpn-1>
13 D 192.168.14.125/32 192.168.14.126 <ovpn-2>
14 D 192.168.14.121/32 192.168.14.122 <ovpn-3r>
(10:31:17)(193G) [root@raspberrypi-003:~] # /usr/lib/nagios/plugins/check_ntp_time -H 192.168.1.1
NTP OK: Offset -0.0007329285145 secs|offset=-0.000733s;60.000000;120.000000;
(10:31:28)(193G) [root@raspberrypi-003:~] # /usr/lib/nagios/plugins/check_ntp_time -H 192.168.11.1
NTP CRITICAL: No response from NTP server
It works OK for me. Sure it is not a firewall issue?NTP server is still issue :( NTP server is responding only on one interface.
I would recommend running a BGP session for IPv4 and one for IPv6. With the many peerings I have over dozens of Internet exchanges, I have not seen a single peer which uses BGP with IPv4 not in a separate session from BGP with IPv6. So it's kind of the standard way of doing it.I would like to report an issue with multiprotocol bgp, carrying both ipv4 and ipv6 af routes.
Tested this on wireguard interfaces, not sure about regular ethernet.
- when the session is ipv4-based: ipv4 routes work fine, and for ipv6 routes mikrotik builds ipv4-mapped ipv6 next-hop based on ipv4 interface address (eg ::ffff:192.168.0.1), ignoring interface ipv6 address set explicitly.
- when the session is ipv6-based: ipv6 routes work fine, and for ipv4 routes mikrotik puts 0.0.0.0 as next-hop.
so there is no option to run both v4 and v6 in one bgp session.
Unfortunately the "modern devices" are not ideal to experiment with versions. It may be easier to try a classic one (RB2011, old hEX) or a higher end modern one (RB3011,RB4011) because they have enough flash space to have two or more versions on the router at the same time (partitioning).@pe1chl in my case I had this hEX-S running LT and never tried v7.x, so no possibility that some trace of v7 was in it.
Yes this was working on ROS6 I wasn't changing any FW rules and I have this issue on all ROS7 boxes.It works OK for me. Sure it is not a firewall issue?NTP server is still issue :( NTP server is responding only on one interface.
I see some "funny behavior" of the NTP server, e.g. when I try to add an external server that happens to be already present as a dynamic server (obtained from DHCP) it goes bonkers. The new server is not accepted and another one is deleted.
But replying to requests seems to work OK here (I also have several networks).
It is default config after reset router and change to add bridge-Client and change other params on the screen for acessing to internet.Why would you like to add an additional bridge that is not necessary?How i can fix this please?
What does your firewall (including NAT) look like?
Interesting. I checked again and for me it works fine.Yes this was working on ROS6 I wasn't changing any FW rules and I have this issue on all ROS7 boxes.
Are you sure the IPIP tunnels are not somehow looping (tunnel traffic routed back into the tunnel instead of to internet)?Disable 2 IPIP tunnels to mikrotik 6.49.2 solved the problem. But I need them, so problem is somewhere in it.
How did You upgrade 16 MB device, which is having only few MB free space, with the 12,9 MB image?Updated 4xCAP AC, 1 CAP XL AC successfull to 7.1.1 (ROS and FW) without problems.
I may have upgraded one of the devices using the 'testing' channel, but I'm pretty sure I used the 'upgrade' channel for the other devices. I did a further upgrade to a CRS317, RB3011 and RB4011. One of those was also left on the 'testing' channel, whilst the other two remained set to the 'stable' channel. I have never installed anything from the development channel and had never installed any 7.x pre-release - so it was a direct upgrade from 6.48.x or 6.49.x.I see. 7.1.1 is available in "testing" channel from v6 as well. So I get what russelld is talking about, but to be fair, when you update to "testing" channel, you still agree to install other "testing" versions as well, which 7.2rc2 is.
Have you updated the routerboard firmware?4011 loop reboot after upgrade from 6.49.2 every 2-5 min. At one moment 1 core was 100% load for a minute and reboot again. Disable 2 IPIP tunnels to mikrotik 6.49.2 solved the problem. But I need them, so problem is somewhere in it.
@ksuuk: It was done automaticaly via CAPsMAN (which is my RB4011iGS+5HacQ2HnD) after I´ve upgraded this device to 7.1.1 I didn´t tried it in another way.. :-/How did You upgrade 16 MB device, which is having only few MB free space, with the 12,9 MB image?Updated 4xCAP AC, 1 CAP XL AC successfull to 7.1.1 (ROS and FW) without problems.
You are using queues, no? This is a known issue, at lease here in the forum. (I hope Mikrotik is aware...)IPv6 Firewall Connection Tracking is still not available on HAP ac²
These are not release specific issues, you are describing common suprises people will have when migrating from v6 to v7. You will have to re-learn a few things.Upgraded CCR1036-12G-4S to v7.1.1. Latest Winbox version is used. First impressions, well...
2. Routing Filters didn't appear in the "classic" way in Winbox, they were looking more like scripts, not very user friendly, especially when it was impossible to look through the options any more.
3. Couldn't find Routing BGP Networks. BGB still seamed to continue working but I couldn't find where the networks and aggregations gone, sorry.
Of course I always make a backup and export before upgrades. And I have read a couple of times about loss of config. So after an upgrade I do a new export and diff them, to see what I might have lost in the process. That had already alerted me about problems before, especially in the config conversion.I have run into this multiple times. from 6.X to 7.1bet and from 7.1beta to 7.1 release I ended up with /ip ipsec identity being completely blank.
So if you have ipsec stuff, save your passwords. you probably will need them later...
Well you have to understand how it works internally: all the config info you see in /export is stored in a "database". That is what /system backup saves.The interesting thing was that on one router where I had issues after upgrade, i downgraded to release 6 and everything worked again.
So the identity config is not lost, its just hidden, disregarded in 7.
Yes I use simple queue.You are using queues, no? This is a known issue, at lease here in the forum. (I hope Mikrotik is aware...)
SUP-69071
Ipv6 works for me with a queue tree (and packet marking based on DSCP). Probably you mean a simple queue?Yes, ipv6 connection tracking works if you disable queues. Well, just make sure the ipv6 traffic does not go through a queue.
I have simple queues with pcq, yes.Ipv6 works for me with a queue tree (and packet marking based on DSCP). Probably you mean a simple queue?
Thank you for your answer. That is exactly what I'm talking about with the exception I wouldn't call that surprises, I'd call that "problems", as nothing currently working should stop doing so with an upgrade. No one is against re-leaning something nor I said your product is bad. As I said that wasn't a complaint but a feedback from the Mikrotik users in a commercial environment not in a lab where everything is working. I'd love to migrate (and I've tried to do so) but simple migration from v6 to v7 doesn't work and overall, it looks like v7 is still a "test" version, which has issues even with Winbox.you are describing common suprises people will have when migrating from v6 to v7. You will have to re-learn a few things.
(and also the BGP implementation is not complete)
See the documentation on help.mikrotik.com
Welcome to the club :) Quick fix is downgrading, sorry. I had to do the same, so waiting for 7.x.x version, which works.Hi,
I updated a RB1100AHx4 from 6.49.2 to 7.1 then 7.1.1 and ended up in a strange situation: The router works fine, but asa I reboot it all is screwed up: All bridges are gone, so all IPs are missing, no access via MAC-Telnet. After resetting it and restoring the 7.1 backup with 7.1.1 all works fine again, but a reboot srews it all up.
Any suggestions how I coud fix this situation besides downgrading to 6.49.2 and waiting for a more stable 7.x Version?
- Joachim.
mrz,
/routing ospf network
add area=backbone network=1.1.1.0/29
/routing ospf interface-template
add network=1.1.1.0/29 area=backbone_v2
/routing ospf interface-template
add area=backbone_v2 prefix-list=1.1.1.0/29
Connect Rommon -> RB750Gr3 6.48.4 -> Rommon to SXT 5HPnDr2 7.2rc1 OKromon doesn't work btw v6 and v7
I have only 1 router migrated to v7.1.1, but either if I set RoMON agent to be one of v6 or the v7 router, I can log into all the others with no issues, including the v7 one.romon doesn't work btw v6 and v7
I’ll keep 6.48.6, thanks for sharing.Welcome to the club :) Quick fix is downgrading, sorry. I had to do the same, so waiting for 7.x.x version, which works.
You are right, RouterOS v7 is not ready for production in cases where BGP or OSPF is involved. MikroTik is pushing it as "stable" and that suggests to some people that it is stable and reliable software, but it isn't complete. You certainly cannot migrate a BGP setup from v6 to v7 without problems yet.As I said that wasn't a complaint but a feedback from the Mikrotik users in a commercial environment not in a lab where everything is working. I'd love to migrate (and I've tried to do so) but simple migration from v6 to v7 doesn't work and overall, it looks like v7 is still a "test" version, which has issues even with Winbox.
I think becauseWhy is version 7.1.1 still released as stable when it has quite a many issues?
Rather than downgrading (I need wireguard), I restored the 7.1 backup again under 7.1.1, then I deactived and in turn activated all interfaces and bridges. Now I can reboot.Welcome to the club :) Quick fix is downgrading, sorry. I had to do the same, so waiting for 7.x.x version, which works.Hi,
I updated a RB1100AHx4 from 6.49.2 to 7.1 then 7.1.1 and ended up in a strange situation: The router works fine, but asa I reboot it all is screwed up: All bridges are gone, so all IPs are missing, no access via MAC-Telnet. After resetting it and restoring the 7.1 backup with 7.1.1 all works fine again, but a reboot srews it all up.
Any suggestions how I coud fix this situation besides downgrading to 6.49.2 and waiting for a more stable 7.x Version?
- Joachim.
Well, that is now the main elephant in the room. We have many routers on remote locations (difficult physical access) and we really need bullet-proof upgrade procedures that never result in bricked devices or bootloops, or other failures that result in problems remotely accessing the device (including BGP migration).I reached my goal and RouterOS 7.x works now, but the process was not very pleasant and surely not something that will scale well ...
If only RB5009 can use v6! I would not care if v7 got bugs or not.Unless you require something very specific from v7 in all your devices, you can safely stay on latest v6, it is secure and stable. There is no need to do mass upgrades to v7. You can simply upgrade over time, or introduce v7 only when adding new devices.
I was answering about difficulty performing mass upgrade from v6.If only RB5009 can use v6! I would not care if v7 got bugs or not.Unless you require something very specific from v7 in all your devices, you can safely stay on latest v6, it is secure and stable. There is no need to do mass upgrades to v7. You can simply upgrade over time, or introduce v7 only when adding new devices.
:)))))))) I even couldn't think of what to say :))))))) But yes, I know exactly what you're talking about. Well, thank you for your thoughts and let's hope that'll happen sooner rather than later.But remember, when e.g. Microsoft releases a new Windows version...
Reading an earlier reply to that, I fear that in some version this value will just disappear.when the routing/bgp/session prefix count will be fixed?
or maybe you think that it's not so important?
That is not really a bug, it is just a cosmetic issue (explainable from the internal workings). The routes still work OK.Hello, colleagues!
On hap ac2 I noticed this bug in ip/routes (WebFig):
Why?Make a separate topic about your wifi woes and include some more info, like screenshots from your router registration table and your computer wifi signal stats.
Just try this - the device turns off and stay off, doesn't turn back on.Yesterday updated my home hAP AC from 6.49.2 to 7.1.1. Now I get very low wifi speeds over both wifi networks. Anyone else with the same issue ?
Try to turn off your hap by the option in system, mine when I turn off in version 7 it turns on again.
Ok, found by myself :-), channel needs to be "upgrade".Why "Check for Update" does not see v7 automatically?
Is this feature or bug?
I have read majority of it, in the process, seems like not so many complains...When you need to ask these questions, it probably is not yet the time for you to upgrade.
At least read the 116 messages above to see if there is any reported problem that would apply to your usage of the device.
As you can see, 6.49.2 is the "stable" release for your device.
I have wanted to test wave2 properly at home, but am unable to with the lack of support for 4 address mode (i.e. WDS or station-bridge). I hope MikroTik will be addressing this at some point soon.I have several WiFi devices that have stayed connected for over 2 days to my Audience, running the new WAVE2 wifi drivers.
I get offline reports from these things several times a day on the regular. So this is an improvement!
If look more carefully %) - on one screenshot above you can see profile open for 7.1.1 (I attached it again here) - networking module causes 100% load. Looks like some "software produced internal network loop". On interfaces tab you can see that in/out traffic is low. Right now I'm on the same config on 6.49.2. - still about zero CPU load... Strange that being on 7.1 before upgrading to 7.1.1 CPU load was low but after upgrading (and afterward downgrade to 7.1) - CPU load is 100%. Looks like upgrade 7.1. to 7.1.1 changed some structure(s) inside firmware which left the same after downgrade to 7.1. Now I'm not intending to upgrade my CCRs (~10 pcs) to 7.x nearest few months until major bugs fixed (I hope they will be fixed, incl.broken mangle chain for CCR1xxx).You dont have a picture of "Profile" while CPU running high try to see what module cause the problem?
I only see picture while all are ok.
Not a bug, you have sorting on last column, but you need the first one (with #).Bug on Route List Rules where I cannot drag the rules. Please check!
Sorry about that, I'll stop, to keep the topic clean.Why?Make a separate topic about your wifi woes and include some more info, like screenshots from your router registration table and your computer wifi signal stats.
I have a separate thread about how Zerotier bridging works different on 7.1 vs 7.1RC4. I don't see any posts in it. Yet you seem to read this one.
Oh my bad, maybe my colleague did some sorting before. I have not noticed. Thank you again sir.Not a bug, you have sorting on last column, but you need the first one (with #).Bug on Route List Rules where I cannot drag the rules. Please check!
From latest picture, it seems that 7.1.1 uses one CPU compare to the 6.49 that uses 8?If look more carefully %) - on one screenshot above you can see profile open for 7.1.1
OMG, in resource tab you can see that total load is 89% i.e. not "uses one CPU". I did one screenshot for one CPU due to profile window just allows to choose only one CPU for details. But just little bit above was screenshot with 7.1.1, were show all 9 CPUs, 8 of 9 are 100% load, IRQ is 90..97%.From latest picture, it seems that 7.1.1 uses one CPU compare to the 6.49 that uses 8?If look more carefully %) - on one screenshot above you can see profile open for 7.1.1
If you read the may comments in the 7.x threads, you see the following comments.So 7.1.1 and 7.2rc1 are versions to stay away from?
Not sure what is causing it exactly, some say its larger address lists, i did send supout to support i hope they figure it.Dude, so far it looks like a bug in 7.1.1 and 7.2rc1, these topics are for problems related to these specific versions, please don't spam the forums with offtopic talk. Wasted 3 posts for nothing.
For general "don't use v7, v7 bad" please open another topic.
Thank you.
So, on topic, did you encounter abnormal high CPU usage on 7.1.1 and 7.2rc1? or not? How did you fix it? did you find what causes it?
I have a RB4011 with WiFi as well, and it is running two L2TP+IPsec clients, but there is no problem. It has another IPsec tunnel as well.My device is RB4011 with wi-fi. Before update i had Ros ver. 6.49.2, After update to Ros 7.1.1 my router became a brick (after 30 minutes uptime ). I see that i have l2tp+ipsec client, but after disable ipsec in l2tp client- my router work fine! I think my case can help users for upgrade to Ros7
/ip ipsec proposalCan you write me your IP-IP sec- Proposals and Profiles?
Yes, no problem at all. I use these L2TP tunnels to make connections between private networks (using BGP for autorouting) and it just works. They all are connecting to routers running v6.49 at the moment.Not work with your sethings. Can you initiate a trafic thru your l2tp+ipsec tunel? for example rdp connection from your
pc on RB4011 to remote host on vpn? After that your router works fine?
/sys watchdog/set watchdog-timer=yes automatic-supout=yes
Same here, after the upgrade 5ghz wifi will not work properly.Upgrade 7.1.1 vers. wAP Ac (architecture mipsbe). There are still problems with Upload speed. This is critically low. There was no such problem with version 6.49.2!
Yes this is the issue I reported two posts above with the hAP ac (mipsbe) and hAP ac lite (mipsbe). It is not only that the throughput drops to zero, the client actually gets disconnected, if you look in the registration table.But when transfer speeds reach > 100mbit the throughput drops to 0 and stays there for several seconds.
Every 10 seconds or so it tries to restart the transfer and fails almost immediately.
> /system/package/print
Columns: NAME, VERSION
# NAME VERSION
0 routeros 7.1.1
> /ip route/print where 7.7.7.7/32 in dst-address
Flags: D - dynamic; X - disabled, I - inactive, A - active; c - connect, s - static, r - rip, b - bgp, o - ospf, d - dhcp, v - vpn, m - modem, y - copy; H - hw-offloaded; + - ecmp
# DST-ADDRESS GATEWAY DISTANCE
...cut...
3 As + 7.7.7.7/32 IFACE-WARP 1
4 As + 7.7.7.7/32 IFACE-WARP 1
5 As + 7.7.7.7/32 IFACE-WARP 1
1 As + 7.7.7.7/32 IFACE-WARP 1
/ip/route> remove [find dst-address =7.7.7.7/32]
no such item (4)
/ip/route> /ip route/print where 7.7.7.7/32 in dst-address
Flags: D - dynamic; X - disabled, I - inactive, A - active; c - connect, s - static, r - rip, b - bgp, o - ospf, d - dhcp, v - vpn, m - modem, y - copy; H - hw-offloaded; + - ecmp
# DST-ADDRESS GATEWAY DISTANCE
4 As + 7.7.7.7/32 IFACE-WARP 1
1 As + 7.7.7.7/32 IFACE-WARP 1
/ip/route> remove numbers=4,1
no such item (4)
This config I have already in place. I guess it is default-config already.@infabolook for a file named autosupout.rif in the root directory after the router has locked up / rebooted by watchdog timer.Code: Select all/sys watchdog/set watchdog-timer=yes automatic-supout=yes
Getting Kernal Failure....
Capture.JPG
Hello,
I have installed routeros 7.1.1 on a CCR1009-7G-1C-1S+ (tile) but I don't see packages listed; on terminal too:
Immagine 2021-12-27 122604.jpg
I have the same problems. SUP-68278 is there if you want to submit a report and reference it. Setting the modules to 1G fixes it, but I hope Mikrotik will fix this soon, as it's a serious problem impacting a lot of users. 7.1 and 7.1.1 both cause it for me, primarily at 5 minute intervals.I have two CRS328-24P-4S+ and both are randomly losing links on SFP+ (different modules .. fibre, dac and 10gbase-t. On one of the switches fibre and 10gbase-t always losing its connection at the exact same time) with 7.1.1.
I had to go back to 6.49.2.
Had to reisntall using Netinstall sad had to do it but was a great experience how to recover device from such a problem.updated my ccr 1009 now its bricked not booting not loading kernel
Let us know the status after few hours or days. ;-)updated my
ccr1036
2x ccr1009
2x ccr1016
rb5009
rb4011 and couple of different models too and....
no problemo
OK and how can I uninstall wireless package ?Hello,
I have installed routeros 7.1.1 on a CCR1009-7G-1C-1S+ (tile) but I don't see packages listed; on terminal too:
Immagine 2021-12-27 122604.jpg
In ROSv7 only a few non-essential things come as packages, everything else is in a single monolithic intallation package.
You cannot. This is no longer possible in v7 (same for MPLS, Hotspot, CapsMan etc).OK and how can I uninstall wireless package ?
This has been covered many many times. target-scope now has to be greater than scope instead of being greater than or equal to scope. Increase your target-scope by 1 and it should work.I have tried to implement a recursive route (like in ros v6), but I don't see it working, unless the syntax has completely changed.
Thanks for the heads up, I was missing this info.This has been covered many many times. target-scope now has to be greater than scope instead of being greater than or equal to scope. Increase your target-scope by 1 and it should work.
You could have read both of these things above. It really pays off to read the release topic before attempting to upgrade!not sure why but after update as I have said my ccr 1009 didnt boot anymore had to use netinstall to reimage and now its not recognising mikrosd car tried 2 of them no luck
It gives a warning in the manual that on the RB4011 using wifiwave2 will result in not having a 2.4ghz interface. Remove wifiwave2 and the interface will appear again.Did netinstall, it also does not help to reset all settings, 1 wireless interface does not appear. ( 7.1.1 Stable | 7.2rc1 Testing)
what release its considered to be stable version free of bugs isnt?You could have read both of these things above. It really pays off to read the release topic before attempting to upgrade!not sure why but after update as I have said my ccr 1009 didnt boot anymore had to use netinstall to reimage and now its not recognising mikrosd car tried 2 of them no luck
for me the same on 7.1.1Looks like SD cards still do not mount on CCR1009-7G-1C-1S+, same on 7.2rc1.
"Free of bugs"? No, that's not what MikroTik's definition of "stable" means. You won't find any vendor where a "stable" release is 100% free of bugs, it just doesn't happen. "Stable" in MikroTik's case means that they felt that it worked well enough for about 90% of users and use cases.what release its considered to be stable version free of bugs isnt?
it might have a minor bugs , minor is acceptable but not then device gets in to bricked mode were you have to re-image it. Other thing device shouldn't have a a problem like not seeing microSD card while device has only funny 128mb of storage ( we can start argue why I should need more storage, bur its plenty of reasons for this). So bugs like these are critical and should not happen in stable release."Free of bugs"? No, that's not what MikroTik's definition of "stable" means. You won't find any vendor where a "stable" release is 100% free of bugs, it just doesn't happen. "Stable" in MikroTik's case means that they felt that it worked well enough for about 90% of users and use cases.what release its considered to be stable version free of bugs isnt?
Do you also upgrade to Windows 11 a week or two after it came out and complain about bugs and say it must also be bug free? RouterOS v7 is a complete rewrite of probably about half the code. It isn't some little upgrade. They will be ironing out bugs for months.
What version was it on before you upgraded?it might have a minor bugs , minor is acceptable but not then device gets in to bricked mode were you have to re-image it.
question do you have upgrade or clean install ? is you hardware fully supported?What version was it on before you upgraded?it might have a minor bugs , minor is acceptable but not then device gets in to bricked mode were you have to re-image it.
Re: Win11 I am on Windows 11 and am experiencing some extremely annoying bugs, mostly to do with 4K scaling and the start menu stops working until I restart explorer. Also it happened last week where all the menu bars started opening *behind* the windows instead of in front of them so I couldn't see the menu options for anything and had to reboot to fix it. So I haven't been impressed by it so far.
Yes, it is fully supported, and I did an upgrade.question do you have upgrade or clean install ? is you hardware fully supported?
I have re-imaged to 7.1.1 from this point it worked ok, but as i got a problem with SD card I have downgraded to 7.1 and still had the same sd card issue, so nothing stopped me to update back to 7.1.1 and this time all went ok no problems , exempt not working SD card and dccp, sctp and udp lite firewall service ports showing as invalid apart of this all works fine. I saw somebody else has reported the same issue with service ports on the same device after upgrade to 7.1Yes, it is fully supported, and I did an upgrade.question do you have upgrade or clean install ? is you hardware fully supported?
7.1 to 7.1.1 I would not expect to give major issues like that. I do not have a tilera based system to test on, but everything I have upgraded has gone fine from 7.1 to 7.1.1.
These service ports have shown as invalid since the first v7 beta on all devices. I think that these helpers have been removed from the newer Linux kernels as they aren't used anymore, but MikroTik hasn't removed the helpers from the list yet. It probably isn't very high up on their list of priorities since it doesn't cause any actual issues.dccp, sctp and udp lite firewall service ports showing as invalid
/ip route
add distance=1 gateway=1.0.0.1 routing-mark=to_WAN2
add distance=1 gateway=1.1.1.1 routing-mark=to_WAN1
add check-gateway=ping distance=1 gateway=1.1.1.1
add check-gateway=ping distance=2 gateway=1.0.0.1
add check-gateway=ping distance=1 dst-address=1.0.0.1/32 gateway=192.168.2.1 scope=10
add check-gateway=ping distance=1 dst-address=1.1.1.1/32 gateway=192.168.0.1 scope=10
"what kind of VPN is this":This kind of report is not very useful without information like "what kind of VPN is this" (preferably show the export of the configuration with account info masked), and what type of router you use. Some recent VPN issues really depend on the architecture of the router (TILE, ARM, MIPS etc).
I am experiencing the same issue! I upgraded hAP ac3 to latest 7.1.1 from 7.1 - all was OKHello,
I have some problem from last update.
mikrotik.png
The Hap ac lite is connected to RB4011 by 5GHz interfaces where RB4011 is ap(wifi wave2) and hap ac lite is a station.
When I add the EOIP to bridge, where I have also lan1-5 and 2.4GHz (the eoip is between RB4011 and hap ac lite).
My wifi on hap ac lite is not stable for example doing speedtest the connection is getting lost.
I got error like this:74:4D:28:D9:DC:98@5ghz: lost connection, received deauth: class 2 frame received (6)
The rest of devices connected to RB4011 by Wifi works great.
And now the most funny thing. Deleting the eoip, creating simple masquerade and seting ip and dhcp sever on bridge is helpful, cause the problem is solved. The connection is stable and fast.
But I want to bridge station and bridge, the station bridge doesn't work for 802.11 and the station-pseudobridge doesn't work like I would like to.
This is a really strange situation and I do not see any relation.
Could someone help me?
The hap ac lite replaces me 2.4GHz in rb4011 where the 2.4ghz(in this model) is not supported for wifi wave2.
Sorry For My English.
Yes, this issue seems to happen with at least hAP ac (mipsbe), wAP ac (mipsbe), hAP ac lite (mipsbe)I am experiencing the same issue! I upgraded hAP ac3 to latest 7.1.1 from 7.1 - all was OK
However, soon as I upgraded wAP AC (mipsbe) to 7.1.1 or even 7.1.2rc - unstable and disconnects after a few mins. Same setup for AP station and bridge-station.
Reverted the wAP AC back to routerOS 6 - long term and no issues. Back to being stable
we have restricted the issue about icmp that stop working after several hours of operation on x86.
It is related to bonding MTU >1500.
To reproduce, on a v.7.1.1 router configure two bond interface, one with mtu=1500 and the second with mtu=1600
Do an heavy and costant forward of traffic through the bond interfaces and after 36/48 hours the router:
- is not able to ping ecternal hosts
- is not able to ping-check the static routes
- respond correctly to ping from external hosts
Using the same hardware, same config changing only mtu=1500 on all bonding interfaces the router remains stable!
We think it is not a platform (x86) related issue, but a general issue.
regards
Ros
means?backup - added "force-v6-to-v7-configuration-upgrade" option on backup load to clear RouterOS v7 configuration and trigger reimport of RouterOS v6 route configuration (CLI only);
Sry, i am Not your DNS Administrator. So i cant give you More than the Info, that the Error you See is probably because of the Missing Zone param.Infabo, can you explain to me how to use it in the script i am using?
So MT didn't know that?And under load it overclocks, sadly.
This is apparently true. I reported some instability of Chateau to MT support and they suggested to set a fixed CPU frequency. That indeed improved the stability a lot. Still some unknown conditions cause a lockup. But not using CPU auto frequency helped a lot.And under load it overclocks, sadly.
[buraglio@gw] /routing bgp> /routing bgp advertisements print
PEER PREFIX NEXTHOP AS-PATH ORIGIN LOCAL-PREF
peer1. 3ffe:9440::/32 2001:db8:c00... igp
That doesn't work... the bug is actually in the 6.xx version which does not allow update from separate to bundle package and it affects both the upgrade to v7 and the change to bundle package within v6.Another thing to try before netinstalling: upload bundle (main) package for some recent v6 version (e.g. 6.48.6), set it to downgrade ROS (if uploaded version is lower than curently installed) and reboot. It should turn into bundled installation of ROS v6, which might allow for normal upgrade to v7
Same for me. if i disable ipsec, all is working.After upgrade to 7.1.1 from v6 i have an issue with l2tp+ipsec with error
<ip>: authentication failed: peer didn't respond to CHAP challenge
actually, I have two rules, like this:That kind of condition "if (bgp-communities includes 11111:111 )" works for me. Or do you mean the action "set blackhole yes" does not work? (I did not test that)
0 chain=filter-in rule="if (bgp-communities includes 11111:111 ) { set blackhole yes; accept; }"
1 chain=filter-in rule="reject;"
DIb dst-address=23.135.225.0/24 routing-table=main gateway=1.1.1.1 immediate-gw=2.2.2.2%ether5_832 distance=20 scope=40 target-scope=30 suppress-hw-offload=no
0 chain=filter-in rule="if ( dst == 23.135.225.0/24) { set blackhole yes; accept; }"
1 chain=filter-in rule="reject;"
DAb dst-address=23.135.225.0/24 routing-table=main gateway=1.1.1.1 blackhole immediate-gw="" distance=20 scope=40 target-scope=30 suppress-hw-offload=no
There must be a lot more going on than just running an L2TP/IPsec server when you can "join the whole network" of a client.My router woks as a L2TP/IPSec server. Sometimes my customers are able to connect with IPSec enabled, but I cannot join anything in their network. If I disable IPSec, I can join the whole network.
is there a way to see what announces are received ?I use rules like this:
"if (bgp-communities includes 44137:10050) { set bgp-local-pref 50; }"
and they work OK.
This is two different topics:although I have noted the missing
Wireless PSKs in the configuration export, and previous comments on the forum about IPSec identities being missing.
is there a way to see what announces are received ?
i'd like to check if it detects the right communities, but I can find it anywhere
Thanks,
Mathieu
routing route print detail
It is like that since DoH and FWD exist in RouterOS... Sadly.Seems like Split-DNS regex matching for FWD functional doesn't work with enabled "Use DoH Server", all request immediately passed to DoH server. But for static records (TYPE A) with regex matching everything is ok, device reply regex matched answer.
It is like that for most of the new commands related to routing. Apparently someone still has to go over the logging functionality.With 7.1.1. log entry is missing details what changed when adding/deleting/changing routing table entries :
+1 for using both at the same time.Seems like Split-DNS regex matching for FWD functional doesn't work with enabled "Use DoH Server", all request immediately passed to DoH server. But for static records (TYPE A) with regex matching everything is ok, device reply regex matched answer.
is there a way to see what announces are received ?
i'd like to check if it detects the right communities, but I can find it anywhere
Thanks,
MathieuWill show all BGP attributes after input filters.Code: Select allrouting route print detail
Fb afi=ip4 contribution=filtered dst-address=23.135.225.0/24 routing-table=main gateway=1.1.1.1 immediate-gw=2.2.2.2%ether5_832 distance=20 scope=40
target-scope=30 belongs-to="BGP IP routes from 1.1.1.1"
bgp.peer-cache-id=*B000005 .as-path="11111" .communities=11111:111,no-export .atomic-aggregate=yes .origin=igp
debug.fwp-ptr=0x20302360
unfortunately its production environment, no lab testing... so I just was f....d, yes, I had old backup.That's how it is. You did nothing wrong.
So you have a Backup from before upgrading? If yes, you Can you downgrade to 6.x, restore Backup and Upgrade again. If the Upgrade fails again, you have a reproducible upgrade-failure you can report to MT Support. This would help many people.
I would say that v7 is not ready for a production environment without lab testing, and where downtime is important.unfortunately its production environment, no lab testing... so I just was f....d, yes, I had old backup.
well, I learned at last, that Mikrotik is not as good at quality management, as it assumed to be.I would say that v7 is not ready for a production environment without lab testing, and where downtime is important.unfortunately its production environment, no lab testing... so I just was f....d, yes, I had old backup.
Also it is always important to make a backup and this is listed as the first item in the start post of this topic.
"I hope you learned something" as Louis Rossmann would say.
I made some test with bandwidth test v.0.1.I have a RB4011.
When i download a torrent file i have ether down in PC which downloads.
The cpu/mem is normal.
I cant capture if done at the time of up or down full load
or when drop packets.
I tried to change the queue type but the problem is the same.
The log file catch
interface, info ether4 link down
interface, info ether4 link up (speed 1G, full duplex).
I searched the log file for previous records (prior 7.1 update) and i have not any in 6.X.
Will RouterOS v7 get more frequent Linux Kernel updates than RouterOS v6?
[admin@mt] > /system/ssh 10.110.12.253 user=admin
connectHandler: Operation timed out
couldn't change watchdog - failed to enable watchdog timer (6)
I have tried to implement a recursive route (like in ros v6), but I don't see it working, unless the syntax has completely changed.
The route gets IUSH as invalid and unreachable.
Is this not implemented yet in ros v7.1.1 ?
I have this error but it seem Winbox bug things. If u see the list with using terminal, it wont get double.Hello
There is problem in PPPOE section. In interface all users are showing correctlybut in PPP active connection it showing double. Screenshot is attached. Checked in various time on RB4011.
MKT.jpg
I have had issues with double or invalid information shown in winbox and I was told to press F5 in such cases.I have this error but it seem Winbox bug things. If u see the list with using terminal, it wont get double.
+1Seems like Split-DNS regex matching for FWD functional doesn't work with enabled "Use DoH Server", all request immediately passed to DoH server. But for static records (TYPE A) with regex matching everything is ok, device reply regex matched answer.
Atom 270N does not work
It definitely would help if you provide more details to describe problems.Hairpin Nat Broken.
I typically only report problems anymore because I'm around 0-10 of getting a fix, but here is the forum post.Atom 270N does not workIt definitely would help if you provide more details to describe problems.Hairpin Nat Broken.
Do you ask your doctor for help saying "I'm feeling ill"? :)
Still writing "Calculating download size ..."Atom 270N does not workIt definitely would help if you provide more details to describe problems.Hairpin Nat Broken.
Do you ask your doctor for help saying "I'm feeling ill"? :)
You need to remove any extra packages installed before upgrading. This has been mentioned in nearly every 7.x release post.Still writing "Calculating download size ..."
It definitely would help if you provide more details to describe problems.
Do you ask your doctor for help saying "I'm feeling ill"? :)
I did a lot of tests on openvpn (udp)
The results are definite.
openvpn udp protocol: (It has many bugs)
max connect time per client ( 1 hours or 01:01:00)
os client: windows , android , ios
all client (ovpn udp) They are disconnect after 61 minutes
After 1 hour and 1 minute openvpn disconnected.
I emphasize that the problems are only in udp protocol.
create ticket in mikrotik support (SUP-57401)
But the mikrotik support team did not care
emils , mrz or normis please answer.
I would like some more info on cake / fq_codel queueing as well. For instance, isn't it about time some of the defaults are using those queue types by now? The upgrade to 7.* does not seem to have changed any of them in my devices; I would very much like to know which I can change to cake and/or fq_codel now. Any advice on this? It's not in the wiki (yet)..Nevertheless, I notice that that CAKE / FQ_Codel Queueing Disciplines don't appear to be offered in either the Web GUI or /queue/types/print.
> /queue/type/add kind=[TAB]
bfifo cake codel fq-codel mq-pfifo none pcq pfifo red sfq
That's not the question, I see it listed among the types. I'm curious why it's not being used..Just define new type...Code: Select all> /queue/type/add kind=[TAB] bfifo cake codel fq-codel mq-pfifo none pcq pfifo red sfq
The same problem with hAP ac3. I tried on versions 7.1, 7.1.1, 7.2rc1. Version 6.49.2 turns off successfully. (SUP-71006)I have a hap ac2 with version 7.1.1 when i turn it off via winbox then it turns on again in this version
I used system and dhcp.You need to remove any extra packages installed before upgrading. This has been mentioned in nearly every 7.x release post.
Still writing "Calculating download size ..."
Hmm.. I strongly disagree there. I've been part of the bufferbloat testers for over a decade now. fq_codel can be enabled for everything you'd like to try it on, and would probably already yield better results than the older current queue types. CAKE has also been widely tested and usually ends up better than sfq for wifi, even with CAKE defaults, but hey. If you mean to say you have not tested them with mikrotik hardware, I'd say go ahead and try. Try default to fq_codel for the internet port and run some tests. Switch all Flow Control to Off for that port (Interfaces > Ethernet > Tx and Rx Flow Control > Off), and maybe default to CAKE for wireless facing interface(s) and run some tests and compare.1. it isn't stable and finished
2. it is likely not the optimal type for the usage scenarios hinted by the type name you would use such queues
But you can do that, right? The existing queue type names are for purposes like a plain (local) ethernet interface, a WiFi interface, etc.Hmm.. I strongly disagree there. I've been part of the bufferbloat testers for over a decade now. fq_codel can be enabled for everything you'd like to try it on, and would probably already yield better results than the older current queue types.
You have to download the npk and upgrade that way. There is no "dhcp" or "system" package in RouterOS v7 and so it can't find those package to download, which is why it is stuck at "calculating download size". You can only upgrade normally to RouterOS v7 when the bundle package was used in RouterOS v6. You have used the individual packages instead of the bundle.I used system and dhcp.
It still writes "Calculating download size ..."
So that's what that is. When I was working in wireless I saw an entry for the AP 2 times. It showed as the old routerOS and New. Closed windobx and reopened. Duplicates gone.I have had issues with double or invalid information shown in winbox and I was told to press F5 in such cases.I have this error but it seem Winbox bug things. If u see the list with using terminal, it wont get double.
A bit strange because I never had comparable issues with RouterOS v6, but it appears that the constant automatic refresh of information in (most) winbox windows was removed in v7.
Sure there is one.Also, quick set, now there is no check for updates buton?
Thanksthey are just tables, you can use IPv4 and IPv6 routes with them. For adding IPv6 routes to a table other than main, you currently have to use the cli, winbox still doesn't show the routing-table parameter.