Docker isn't really important to me. Glad it has lower priority than all the other improvements.Mikrotik is totally bonkers!!!!
I don't give a fuck about containers.Docker isn't really important to me. Glad it has lower priority than all the other improvements.Mikrotik is totally bonkers!!!!
But you can still run test, can't you!?
if you talk about a bug fix then you are right.So stuff that was inside a release candidate is withdrawn.
Mikrotik is totally bonkers!!!!
When it involves changing actual code of RC version - i would agree with you.So stuff that was inside a release candidate is withdrawn.
Mikrotik is totally bonkers!!!!
That change list should be the last post in corresponding RC thread. Doesn't really belong here as it's titled "vX.Y [stable] ir released!" and to avoid confusion, change list should be against previous stable (which in this case was 7.3.1 I believe).Please post a change list relative to 7.4rc2 as well.
jul/20/2022 12:11:14 system,error,critical error while running customized default configuration script: bad command name wireless (line 985 column 25)
jul/20/2022 12:11:14 system,error,critical
Yes that would be a good idea, but it does not appear there either.That change list should be the last post in corresponding RC thread. Doesn't really belong here as it's titled "vX.Y [stable] ir released!" and to avoid confusion, change list should be against previous stable (which in this case was 7.3.1 I believe).Please post a change list relative to 7.4rc2 as well.
Anyone alse already tried this "STABLE" version?i have upgraded hap ac2 , and the router just die, that is second time last time was on 7.3.1
Does this have to do with the LTE interface totally missing in some occasions ?*) lte - improved LTE interface detection for LtAP-2HnD devices;
Anyone alse already tried this "STABLE" version?
After upgrading from what version ?Anyone alse already tried this "STABLE" version?
i need to hard reset to make it work
v7.3.1After upgrading from what version ?
I guess there's a strong emphasis on the word "some", here, because even on this version my RBmAP-2nD shows no voltage or temperature. I guess it has neither of the sensors, or what?*) health - fixed voltage reporting on some RBmAP-2nD devices;
This is welcome as I seem to suffer from these a bit (still didn't pinpoint exact reason and patiently testing while checking version, firmware, uptime etc..) However, this made me look on specs (which say it is single-core device) and compare that with my switches (which say it has two cores in 7.2.1 and 7.3.1).*) switch - disabled second CPU core for CRS328-24P-4S+ device in order to improve SFP+ link stability;
RB5009 still reports: Warning CPU not running at default frequency.
On the RBD52G-5HACD2Hnd it gives me the same default frequency error in red
Need a 7.x long term version.
Ok perfect, can I see the real working frequency of the CPU?On the RBD52G-5HACD2Hnd it gives me the same default frequency error in red
Should be set to auto on hAP ac2 as well.
Some of us have CRS328s with flapping SFP+s impacting connectivity for 6+ months, or are impacted by other major issues fixed in this release. Waiting for a stable release for container support indefinitely until all the container-related issues got resolved would have been silly. It's not like the work on containers suddenly was deleted; it'll be released in the future when it's ready. I assume Mikrotik pushed this out in order to satisfy those with production-breaking problems/needs (and speaking for myself, I am quite relieved).So stuff that was inside a release candidate is withdrawn.
Mikrotik is totally bonkers!!!!
Very much concur and is obvious to anyone that has software development experience. Its good to see QA processes are alive and well!!if you talk about a bug fix then you are right.So stuff that was inside a release candidate is withdrawn.
Mikrotik is totally bonkers!!!!
But if you talk about a new feature i believe is good to remove it as long as they are not stable.
Stability is the most important for me, so any removal in order to improve stability is welcome.
ROS v7.4, running on Audience (requires auto setting as well) shows it when executing command /system/resource/print ... I don't recal seeing any value other than 448MHz though. That's the lowest value available to set on my device, but cpu-load is sitting at 0% as well, that might explain it.Ok perfect, can I see the real working frequency of the CPU?Should be set to auto on hAP ac2 as well.
@emils, can you point out which fix either in this or previous version addressed the Ops concern, or do you like mystery in life LOL.Just upgraded my RB5009: Under 7.3.1 it was not able to pick up a DHCP address from a UK Virgin Media HUB4 (in modem mode), so had to revert to 7.2.3. This applied whether I was used a bonded pair of interfaces (balance-rr) or a single interface.
Mikrotik support advised me it had been fixed in one of the 7.4 betas, but I did not try that.
However, I've upgraded to the 7.4 release and it now works as per 7.2.3 and a bonded interface can correctly initiate and accept a DHCP client request.
Interesting that there is no mention of any dhcp client fixes in the release notes... only dhcp relay/server....
come over to testing, at least you know that you may have to netinstall.i have upgraded hap ac2 , and the router just die, that is second time last time was on 7.3.1
Wow, every day we check the stable release, in order to start a project via containers. All I had to do was check again ...Important note!!!
- Container package is not available in v7.4. Development and testing continues in "testing" channel.
The stuff that was not included, most likely isnt considered "stable"So stuff that was inside a release candidate is withdrawn.
Mikrotik is totally bonkers!!!!
That these features are (still) not implemented is holding me back from deploying v7 as well.- "Prefix Count" for BGP running session?
- BFD (for OSPF and BGP) ?
It should, I reported this last year and have been back and forward about it since (it started with 7.x). I’ve been running 7.4 since b2, and the issue has been gone since. I was seeing flaps on all NAND activity, sometimes every five minutes with some configs doing writes often. Zero flaps since. I’m on 7.4 stable and the issue does appear to be gone on it, as well, as you’d expect. It does blow my mind how long it took to get this fixed, but I am very glad it is resolved now.If this finally fixes the port flapping issues I've been having since I bought this switch I'm going to cry.
This is welcome as I seem to suffer from these a bit (still didn't pinpoint exact reason and patiently testing while checking version, firmware, uptime etc..) However, this made me look on specs (which say it is single-core device) and compare that with my switches (which say it has two cores in 7.2.1 and 7.3.1).
So my question is: what the heck happened here? Did we get accidental HW upgrade (as with 256MB batch of hAP ac2)? 98DX3236 is meant to be dual core so why sell it as a single core product? Does that mean the CPU performance will get even worse?
Thanks for pointing that out! I don't regularly go through test/rc channels so I missed that discussion. To answer your questions:Oh no, don't start that again. Read starting from here: viewtopic.php?t=186583#p939187
And I'll ask here too, since nobody answered in the other topic, did you ever see CPU usage on the 2nd core? And did you see some measurable performance penalty after the 2nd core got disabled?
[rb1100ahx2] > sys routerboard pri
routerboard: yes
model: 1100AHx2
serial-number: 319E02414743
firmware-type: p2020
factory-firmware: 2.38
current-firmware: 7.3.1
upgrade-firmware: 7.3.1
[rb1100ahx2] > sys resource pri
uptime: 3m51s
version: 7.3.1 (stable)
build-time: Jun/09/2022 08:58:15
free-memory: 1438.5MiB
total-memory: 1536.0MiB
cpu: e500v2
cpu-count: 2
cpu-frequency: 1066MHz
cpu-load: 1%
free-hdd-space: 19.5MiB
total-hdd-space: 64.0MiB
architecture-name: powerpc
board-name: RB1100AHx2
platform: MikroTik
the ppc npk file has 21mb, free space on device is 19.5mb. any chance to upgrade without a fresh netinstall?
already removed everything there, which is accessable via winbox, missing just one mbyte :(the ppc npk file has 21mb, free space on device is 19.5mb. any chance to upgrade without a fresh netinstall?
See if you can free up some space ... in /file ... perhaps there are some backup files, export files, dangling npk files that can be removed.
Have you ever netinstalled the device before, or is it the first try?Upgraded my RB5009 from 7.2.3 to 7.4 and looks like it's bricked. Can't even get it to show up in Netinstall.
Apparently something has gone wrong earlier and it kept some file it should have deleted. You should have way more space than that.already removed everything there, which is accessable via winbox, missing just one mbyte :(
See if you can free up some space ... in /file ... perhaps there are some backup files, export files, dangling npk files that can be removed.
Does the FTP server send that response "The local time is: " without numeric prefix (220)?fetch has been broken with ftp connect in 7.3.1 and 7.4:
failure: Unrecognized FTP server response: The local time is:
230 User user logged in
Can you provide a screenshot of such a report? or copy-paste?Still seeing lots of DHCP issues with various devices[...]
Windows reports IP Configuration invalid on affected machines
still i'm not filing confutable to update the remote devices to any v7.xRB760iGS upgraded from 7.4rc1 -> works :)
RB912R-2ND-LTM-KIT upgraded via netinstall just to check if missing LTE interface deigns to come back ... no cooperation :(
in the example i removed the timestampDoes the FTP server send that response "The local time is: " without numeric prefix (220)?fetch has been broken with ftp connect in 7.3.1 and 7.4:
failure: Unrecognized FTP server response: The local time is:
230 User user logged in
Then it is the FTP server that is broken. A proftp server that I can access does not do that, so maybe someone has fiddled with it?
No, that is NOT a correct FTP server response!in the example i removed the timestamp
Real Proftp response is correct:
failure: Unrecognized FTP server response: The local time is: Thu 21 14:01:28 2022
It works perfectly for me 🤔Let's Encrypt does not work , unlike 7.3.1
Please paste exactly what a commandline ftp client shows when you logon to that server.But what about other ftp client that connect without issue? This problem appeared after upgrade to version 7.3.1
When you have it running in a 7.x release, do a /export show-sensitive file=name and download the .rsc file. Also make a .backup file just in case.Every upgrade went well from 7.1.0 through 7.1.5 and I just can't seem to get it to reliably play ball beyond it, I also lose logging to syslog hosts when upgrading, even though the host is configured and I can SSH from said host to the router.
Thoughts?
Maybe you should clear WinBox session in WinBox folder as it could be WinBox problem, not 7.4 upgrade.It bricked my 951ui-2hnd. The router seems to be working fine but when I connect via WinBox I get only blank screens (For example if I go to interfaces it doesn't show any interfaces). and WinBox drops me every 20 seconds. Totally not "STABLE"
Please see attachments.Please paste exactly what a commandline ftp client shows when you logon to that server.But what about other ftp client that connect without issue? This problem appeared after upgrade to version 7.3.1
/ip dhcp-server vendor-class-id add address-pool=Lan-200-UEFI name=UEFI-200 server=Lan-200 vid=PXEClient:Arch:00007:UNDI:003016
/ip dhcp-server vendor-class-id add address-pool=Lan-1000-UEFI name=UEFI-1000 server=Lan-1000 vid=PXEClient:Arch:00007:UNDI:003016
/ip dhcp-server vendor-class-id add address-pool=Lan-1000-UEFI name=UEFI-1000-VBOX server=Lan-1000 vid=PXEClient:Arch:00007:UNDI:003000
/ip dhcp-server vendor-class-id add address-pool=Lan-200-UEFI name=UEFI-200-VBOX server=Lan-200 vid=PXEClient:Arch:00007:UNDI:003000
/ip dhcp-server vendor-class-id add address-pool=block name=Andr11 server=Lan-200 vid=android-dhcp-11
/ip dhcp-server vendor-class-id add address-pool=block name=Andr10 server=Lan-200 vid=android-dhcp-10
/ip dhcp-server vendor-class-id add address-pool=block name=Andr9 server=Lan-200 vid=android-dhcp-9
/ip dhcp-server vendor-class-id add address-pool=block name=Andr12 server=Lan-200 vid=android-dhcp-12
/ip dhcp-server vendor-class-id add address-pool=block name=HUAWEI:android:MRD-L21A server=Lan-200 vid=HUAWEI:android:MRD-L21A
/ip dhcp-server vendor-class-id add address-pool=block name=HUAWEI:android:CLT server=Lan-200 vid=HUAWEI:android:CLT
/ip dhcp-server vendor-class-id add address-pool=block name=dhcpcd-5.5.6 server=Lan-200 vid=dhcpcd-5.5.6
Yes, I have. But what I've observed in the past, is that the RB5009 (or RB4011, my previous) would show certain activity via the LEDs when powered on, and getting into Netboot via the RESET button, the activity changes.@ObliteRon
Have you ever netinstalled the device before, or is it the first try?Upgraded my RB5009 from 7.2.3 to 7.4 and looks like it's bricked. Can't even get it to show up in Netinstall.
I've searched the forum for "rb5009" netinstall.
So:
1. I used a switch to connect RB5009. I used ETH1 as port.
2. I set the address for BOOTP server (setting in netinstall) to 192.168.88.199
3. On the windows machine, i set the IP to 192.168.88.2
4. Open windows firewall ( windows asked me to do that)
viewtopic.php?t=180233
When that " The local time is" line indeed has a CR/LF in front of it, this certainlu is a fault of the FTP server!Please see attachments.
Please paste exactly what a commandline ftp client shows when you logon to that server.
Proftpd 1.3.7a
Thank you BartoszP, I have tried it but unfortunately did not help, also tried getting the latest WinBox off MT's website. I did figure that login via MAC locally works fine but login via IP is having the disconnection problem every 20 seconds. Strange is, the connection via IP has been working for the last 3 years without any issues and just now got bricked with the 7.4 releaseMaybe you should clear WinBox session in WinBox folder as it could be WinBox problem, not 7.4 upgrade.It bricked my 951ui-2hnd. The router seems to be working fine but when I connect via WinBox I get only blank screens (For example if I go to interfaces it doesn't show any interfaces). and WinBox drops me every 20 seconds. Totally not "STABLE"
That's exactly what mine looks like.if it looks like that, it's probably dead. I had to rma my RB5009, just 4 days after I got it. Died during fw update.
IMG_0755.jpeg
I don't think that's right:When that " The local time is" line indeed has a CR/LF in front of it, this certainlu is a fault of the FTP server!
There should be "230-" in front of that line, just like the "230-Welcome user" line.
Thus the format for multi-line replies is that the first line will begin with the exact required reply code, followed immediately by a Hyphen, "-" (also known as Minus), followed by text. The last line will begin with the same code, followed immediately by Space <SP>, optionally some text, and the Telnet end-of-line code.
For example:
123-First line
Second line
234 A line beginning with numbers (<-- quote ate the space at the beginning of this line)
123 The last line
The user-process then simply needs to search for the second occurrence of the same reply code, followed by <SP> (Space), at the beginning of a line, and ignore all intermediary lines. If an intermediary line begins with a 3-digit number, the Server must pad the front to avoid confusion.
Connected to ftp.nluug.nl.
220-Welcome to the FTP archive of
220-The Netherlands Unix Users Group (NLUUG).
220-
220-This server is located in The Netherlands, Europe.
220-If you are abroad, please find an ftp site near you.
220-Most information on this site is mirrored.
220-
220-Information about your login and any transfers you do are logged.
220-If you don't like this, disconnect now.
220-
220-For statistics, see http://ftp.nluug.nl/.statistics/
220-Problems? Mail ftp-admin @ nluug.nl
220-
220-You may login as "ftp" or "anonymous".
220-
220
1- hap lite might be too "light" on resources to run ROS7 properly, depending on what else you configure on itI have a pair of hAP lites that I upgraded to 7.2rc4 a few months ago - I don't remember using Netinstall but maybe I just suppressed the memory. I just purchased another one, running 6.47.9, and it appears there isn't enough free disk space to upload the package via Winbox. The /files area is empty - but I don't have 8M available. Is the only upgrade option a Netinstall?
For more flexibility, I've create a ZT-ZONE (Zerotier) and WG-ZONE (Wireguard) lists/zones in which my service interfaces resides. It makes things more granular. As a best-practice, any user coming in through either VPN "services" does not deserve the same level of trust by default.Only 'issue' that I have is that the WireGuard interface (wireguard1) is placed by internet-detect in the WAN interface list; and it is supposed to be in the LAN interface list.
According to the manual: https://help.mikrotik.com/docs/display/ROS/WireGuard
This is working correct, but the interface is due to internet-detect also placed in the WAN list... this results in some not that unexpected behavior :)Or simply add the WireGuard interface to "LAN" interface list.
/interface list member
add interface=wireguard1 list=LAN
At the moment I've disabled the WAN entry by issuing: /interface/list/member/disable numbers=<use-correct-number>
And I've created a ticket for this.
Just curious, why not ? I would assume someone entering via VPN should be super-trusted ?For more flexibility, I've create a ZT-ZONE (Zerotier) and WG-ZONE (Wireguard) lists/zones in which my service interfaces resides. It makes things more granular. As a best-practice, any user coming in through either VPN "services" does not deserve the same level of trust by default.
Please take some time to write in this topic here: viewtopic.php?t=187814 What purpose does detect-internet serve for you?[...]
This is working correct, but the interface is due to internet-detect also placed in the WAN list... this results in some not that unexpected behavior :)
[...]
Anyone that knows a ZeroTier "id" can join the cloud-switch and suddenly be part of your network, luckily by default "Private" flag is set requiring an "OK" from you, but once changed to "Public" and the network-ID is all that is needed to join.Just curious, why not ? I would assume someone entering via VPN should be super-trusted ?For more flexibility, I've create a ZT-ZONE (Zerotier) and WG-ZONE (Wireguard) lists/zones in which my service interfaces resides. It makes things more granular. As a best-practice, any user coming in through either VPN "services" does not deserve the same level of trust by default.
Otherwise it COMPLETELY negates the use for that VPN service ...
My view.
Yes, the ticket has been opened. waiting...For obscurus: note that likely nothing further will happen unless you make a ticket about this (either by mailing it or by directly creating the ticket in the support system). Bugs reported in the release topics are usually not picked up by MikroTik staff, unless a developer of a particular piece of code sees it and creates the ticket himself.
I don't understand, why is v7 so different in code...I understand it is different in router mode, but why is gone functionality of SD card, or other normal functions? Why is so difficult copy and paste some functions code from v6..?The SD card not working is a known issue... I have an open ticket on this for a long time.
I don't understand. On my Hex, SD card works just fine (microSD, to be correct)Because significant jump in linux kernel version. That means old drivers and functions are useless and have to be completely rewritten.
Same here.Upgraded my RB5009 from 7.2.3 to 7.4 and looks like it's bricked. Can't even get it to show up in Netinstall.
I feel your pain. It was really "itching" to update my RB5009 from 7.3.1 (which works well) to 7.4 "stable" (which is probably Latvian for something else....)Same here.Upgraded my RB5009 from 7.2.3 to 7.4 and looks like it's bricked. Can't even get it to show up in Netinstall.
Updated RB5009 to 7.4 and it never came back.
Netinstall is not working.
Great Work!
You may need to run Netinstall 5 or 6 times ... and switch Netinstall to 1 version lower ..... that's been my experience with Netinstall on some version of Tik devices.Netinstall is not working.
And use Linux to start. Less hassle then Windows...You may need to run Netinstall 5 or 6 times ... and switch Netinstall to 1 version lower ..... that's been my experience with Netinstall on some version of Tik devices.Netinstall is not working.
Great news: After many tries and finally using Netinstall on Linux, i was able to reinstall it and restore my backup.Same here.Upgraded my RB5009 from 7.2.3 to 7.4 and looks like it's bricked. Can't even get it to show up in Netinstall.
Updated RB5009 to 7.4 and it never came back.
Netinstall is not working.
Great Work!
confirm, work login via MAC locallyThank you BartoszP, I have tried it but unfortunately did not help, also tried getting the latest WinBox off MT's website. I did figure that login via MAC locally works fine but login via IP is having the disconnection problem every 20 seconds. Strange is, the connection via IP has been working for the last 3 years without any issues and just now got bricked with the 7.4 release
Just curious... was your RB5009 still showing activity (LEDs blinking / turning on and off) after power on, or was it just the Blue LED1 (solid) and Ether2 Green LED (solid but faint)?Great news: After many tries and finally using Netinstall on Linux, i was able to reinstall it and restore my backup.
Same here.
Updated RB5009 to 7.4 and it never came back.
Netinstall is not working.
Great Work!
It had LED activity on eth1, reset button and it was responding to holding the reset button.@j0n1th4n
Just curious... was your RB5009 still showing activity (LEDs blinking / turning on and off) after power on, or was it just the Blue LED1 (solid) and Ether2 Green LED (solid but faint)?
Great news: After many tries and finally using Netinstall on Linux, i was able to reinstall it and restore my backup.
Same here with a hap ac2 from 7.2.3 to 7.4.Upgraded my RB5009 from 7.2.3 to 7.4 and looks like it's bricked. Can't even get it to show up in Netinstall.
What happens if you netinstall 7.4 ? Just curious ...Same here with a hap ac2 from 7.2.3 to 7.4.
Had to netinstall 7.2.3
Well it's not considered stable yet. Would you rather they shoved it in there before it was considered stable or held back 7.4 all together?Wow, every day we check the stable release, in order to start a project via containers. All I had to do was check again ...Important note!!!
- Container package is not available in v7.4. Development and testing continues in "testing" channel.
Honestly, something has changed in your company and I don't see it going in a really good direction ... Or you get into too many products on the market and it seems that you are losing control ... That's how it seems to me.
A super black ball from me. Cius!
That is "a known problem". I don't know if they plan to eventually fix it.After upgrading a CCR1009 from 6.49.6 to 7.4, I found that the new-routing-mark entries in all mangle rules were reset to "main" instead of the previously configured route marks.
LTE appears after power-on with power plug and than vanishes after restart.RB912R-2ND-LTM-KIT upgraded via netinstall just to check if missing LTE interface deigns to come back ... no cooperation
I'm going to test on two other ac2 and report back.What happens if you netinstall 7.4 ? Just curious ...Same here with a hap ac2 from 7.2.3 to 7.4.
Had to netinstall 7.2.3
Is this fix related to SUP-86916?*) switch - fixed multicast flooding when HW offloaded bridge port gets disabled;
How is route aggregation working for you? And what about BFD?had 7.3.1 in production of bgp router ccr1009 for couple of weeks without issue, now upgraded to 7.4.
i like the way this v7 of route print that so fast. whatever you guys call it not stable, blabla. i dont wan't to go back v6 lol
my case is not as complex as you have but at least in my scenario it is stable.How is route aggregation working for you? And what about BFD?had 7.3.1 in production of bgp router ccr1009 for couple of weeks without issue, now upgraded to 7.4.
i like the way this v7 of route print that so fast. whatever you guys call it not stable, blabla. i dont wan't to go back v6 lol
Do you monitor your BGP peers for being active? And for number of advertised prefixes? How?
I just ordered an SXT LTE6 Kit and would like to know if I can safely run this release on it. I have no experience with any lte products from mikrotik. Usually I connect everything using dsl or fibre but this time the isp can't provide such a connection in time, so I have to use lte for a few weeks. I'd like to use V7 because of easy remote management using wireguard, but if the modem / lte connection somehow is not stable with this release, there's no other option for me to use V6 and ikev2 instead. Interested in your opinion.
Winbox issue, it seems.hAP ac^2 updated to 7.4 and Winbox to 3.37. I see there are some bugs when I open the rules list in Filter Rules in Firewall. The list doesn't load completely, but when I switch to the NAT tab and return to Filter Rules, the list loads completely.
I have this bug only on x86 platforms. After 36/48h i got the ping tool not working. So all the route with check-gateway=ping are disabled.
Well, we could easily go far beyond 7.100. So... I wouldn't worry too much about lack of numbers. Now, worrying about BGP is another thing...With recent release numbering scheme, I wonder if there is enough numbers left to get stable before we get to 8.0 ;-)
And it will be a new router series will released CCR3xxxxWith recent release numbering scheme, I wonder if there is enough numbers left to get stable before we get to 8.0 ;-)
hard reset, or hard reset with netinstall? My experience was the same. Upgraded from 7.3.1 to 7.4 and unit is unresponsive since. in my case, suspect not enough memory, very old HW...Anyone alse already tried this "STABLE" version?
i need to hard reset to make it work
Read a couple of posts above, has been reported before on multiple occasions.After upgrading my hap ac 2 from 7.3.1 to 7.4 via Winbox upgrade packages it is now bricked.
Mine isn't. Did it have a long upgrade history? It is better to netinstall at least once with a v7.x version as described many times.After upgrading my hap ac 2 from 7.3.1 to 7.4 via Winbox upgrade packages it is now bricked.
My personal view on what's happening:Yeah, I guess so pe1chl. Long stable upgrade history on ROS 6 and then a lot of issues trying to get it stable on 7 :)
I think more important than a new kernel: it has a completely new config database as well. Which is converted during the first run of v7. There is no command to remove the v6 database, it remains on the device.My personal view on what's happening:
somewhere in the process during upgrades from ROS6 to version - version - version - ROS7 - version - version ... "something" is left behind which completely messes up the install which at that point bricks everything.
A clean netinstall and then import of previous config, gets rid of that left-over rogue setting (or multiple ?).
We may not forget moving from ROS6 to ROS7 means a complete new kernel under the hood.
Yes that seems to be a topic related to kernel patches etc that they do not really have under control.DOM/DDM still not work on my RB760iGS. With ROS6 it works fine!!
Yes netinstall just works, anyway where's the new testing release?It just works :)
What happens if you netinstall 7.4 ? Just curious ...
Netinstalled 8 of those without any issue.
That's not practical though for the hundreds of devices in the field I'd love to get onto ROS 7 once stable.I think more important than a new kernel: it has a completely new config database as well. Which is converted during the first run of v7. There is no command to remove the v6 database, it remains on the device.My personal view on what's happening:
somewhere in the process during upgrades from ROS6 to version - version - version - ROS7 - version - version ... "something" is left behind which completely messes up the install which at that point bricks everything.
A clean netinstall and then import of previous config, gets rid of that left-over rogue setting (or multiple ?).
We may not forget moving from ROS6 to ROS7 means a complete new kernel under the hood.
That is why I think it is best to install v7 and load the config from a /export (not a load of a backup), to build the v7 config database from commands, not from that converted v6 database.
I had issues at almost every v7.x upgrade until I did this, and never after that.
Yes, as I wrote before (e.g. above in viewtopic.php?p=947288#p947288 ) I hope these issues will eventually be fixed. But it appears the current stat is still "denial" so we first need to have "confirmation" and "debugging"... even a (also often mentioned) improvement of import of /export config (so you can export your config, then do a "/system reset-configuration no-defaults=yes run-after-reset=exportfile" without the many problems that now causes), would be good. I never see a "yes that is right, we will be working on that!" reply on those messages, so little hope for that as well.That's not practical though for the hundreds of devices in the field I'd love to get onto ROS 7 once stable.
🤣 Never I guess.when do you plan to do BGP on SMPIS?
As usual, under development.anyway where's the new testing release?
+1Does this have to do with the LTE interface totally missing in some occasions ?*) lte - improved LTE interface detection for LtAP-2HnD devices;
That's me being stupid, sorry. I, for some reason thought, that After 7.9, there is 8.0 naturally, simply versions being a single digits. I would welcome more 7.x.y release schema.Well, we could easily go far beyond 7.100. So... I wouldn't worry too much about lack of numbers. Now, worrying about BGP is another thing...With recent release numbering scheme, I wonder if there is enough numbers left to get stable before we get to 8.0 ;-)
Checked following setup and it worked: ovpn-server 7.4. ovpn-client 7.3.1. Both tcp and udp.Hi.
OpenVPN client (and/or server) is broken.
OpenVPN client to a remote OpenVPN server on the Mikrotik with same 7.4 version stopped to work, both udp and tcp.
Looks like the client spams lot of requests, the server does not have any errors. Many connections are visible in the server firewall.
The client logs are following: connecting... initializing... disconnected, terminating... - peer disconnected.
Connection to the same OpenVPN server from the Android works good.
Hi there,*) e-mail - added VRF support;
*) ntp - added VRF support for client and server;
*) radius - added VRF support for RADIUS client;
It is a bit unfortunate that for NTP server and client, of which there can be only one instance, the VRF is set globally.
To assure that this will remain like that, I would still advise to do a full export (/export show-sensitive file=name) and do a clean netinstall and import the exported config.After much hesitation, I upgraded my RB4011 from 6.48.6 to 7.4 using "Check for updates" at /system package and the upgrade went very, very smoothly.
Fortunately, a netinstall was not necessary.
Everything is running fine.
Is this a new problem (i.e. it worked fine in previous versions) or entirely new observation? Because TLS and L7 don't play particularly well together due to fact most of communication is encrypted.hap ac2 v7.4 , TLS Host and L7 protocol is not catching any traffic.
Yes, from v3 to v4 change software id from XYZ-ABC to JKLM-NOPR[...] for some reason this story rings a bell somewhere [...]
/ip firewall mangle
add action=mark-connection chain=prerouting comment="Route blocked sites over VPN" dst-address-list=blocked_sites dst-address-type="" \
in-interface-list=LAN new-connection-mark=via-personal-vpn passthrough=yes
add action=mark-connection chain=prerouting comment="TODO: Mark IRC Bouncer Traffic " connection-mark=no-mark connection-state=new \
dst-address=172.105.47.175 dst-address-type=!local dst-port=40000 new-connection-mark=via-personal-vpn passthrough=yes protocol=tcp
add action=mark-connection chain=prerouting comment="Mark SSH Traffic on 4556 port over VPN" connection-mark=no-mark connection-state=new \
dst-port=4556 new-connection-mark=via-personal-vpn passthrough=yes protocol=tcp
add action=mark-connection chain=prerouting comment="Mark incoming ISP1 Traffic" in-interface=pppoe-out1 new-connection-mark=isp1-conn \
passthrough=no
add action=mark-connection chain=prerouting comment="Mark incoming ISP2 traffic" in-interface=pppoe-out2 new-connection-mark=isp2-conn \
passthrough=no
add action=mark-connection chain=prerouting comment="Mark incoming LTE Traffic" in-interface=ether3 new-connection-mark=isp3-conn \
passthrough=no
add action=mark-connection chain=prerouting comment="Mark Non-HTTP traffic for ISP1 with Nth" connection-mark=no-mark dst-address-list=\
!not_in_internet dst-address-type=!local in-interface-list=LAN new-connection-mark=isp1-conn nth=2,1 passthrough=yes
add action=mark-connection chain=prerouting comment="Mark Non-HTTP traffic for ISP2 with Nth" connection-mark=no-mark dst-address-list=\
!not_in_internet dst-address-type=!local in-interface-list=LAN new-connection-mark=isp2-conn nth=2,2 passthrough=yes
add action=mark-routing chain=prerouting comment="Mark ISP1 Traffic" connection-mark=isp1-conn in-interface-list=LAN new-routing-mark=isp1 \
passthrough=no
add action=mark-routing chain=prerouting comment="Mark ISP2 Traffic" connection-mark=isp2-conn in-interface-list=LAN new-routing-mark=isp2 \
passthrough=no
add action=mark-routing chain=prerouting comment="Mark LTE Traffic" connection-mark=isp3-conn in-interface-list=LAN new-routing-mark=\
lte-failover passthrough=no
add action=mark-routing chain=prerouting comment="Connnection with VPN traffic mark to VPN" connection-mark=via-personal-vpn \
in-interface-list=LAN new-routing-mark=via-personal-vpn passthrough=no
add action=mark-routing chain=output comment="Connnection with VPN traffic mark to VPN" connection-mark=via-personal-vpn new-routing-mark=\
via-personal-vpn passthrough=no
add action=mark-routing chain=output comment="Mark ISP1 Traffic" connection-mark=isp1-conn new-routing-mark=isp1 passthrough=no
add action=mark-routing chain=output comment="Mark ISP2 Traffic" connection-mark=isp2-conn new-routing-mark=isp2 passthrough=no
add action=mark-routing chain=output comment="Mark LTE Traffic" connection-mark=isp3-conn new-routing-mark=lte-failover passthrough=no
You can also use the following SNMP-OID to get the current cpu-frequency:ROS v7.4, running on Audience (requires auto setting as well) shows it when executing command /system/resource/print ... I don't recal seeing any value other than 448MHz though. That's the lowest value available to set on my device, but cpu-load is sitting at 0% as well, that might explain it.
Ok perfect, can I see the real working frequency of the CPU?
Things are pretty much the same on my hAP ac2 running v6.49.6 (488MHz is the lowest settable value and shown whenever I care to look at).
.1.3.6.1.4.1.14988.1.1.3.14.0
Maybe check if ip/dns has allow-remote-requests=yes...Yes, stays at 5-6% total CPU load with one core always at 100%.
Same bad things with openvpn. It is not working with with this version.those who runs Site to Site IPSEC VPN with Microtik device as their edge device, please stay away from this version. I had quite a numbers of old RB2011, HEX and some Fortigate firewall used to connected to my CCR1009 running on v6.48, everything is running fine without a single issue for ages, once upgraded my CCR1009 to v7.4, the VPN still shows P1 & P2 all connected but no data would flow in between most the sites. Same happened to those S2S connected with Fortigate devices, it works for a day then suddenly data ceased to flow.
Had spent hours digging through forum for solutions, even attempted those solutions e.g. changing the MSS, changing the NAT rules, etc, none of those work and the only way I resolved this is to roll back my CCR1009 to version 6.80, suddenly, everything is moving again.
I seriously hope Mikrotik can continue to produce firmware without such serious bugs within in future.
PS. Pity those that purchased the 2004 and forced to endure this.
*) route - added option to join static IGMP and MLD groups (available in "/routing/gmp" menu);
Thanks will try againTo my knowledge (but I don't know that much ;) ) there are no documented cases of a completely bricked RB5009.
So you may want to dust off those netinstall skills. It has to work.
My preference is going via Linux.
Others prefer Windows.
For both make sure to disable ALL network interfaces except for that one ethernet port.
Putting a stupid switch in between may also help.
Keep pressing that reset button on the device until it appears in netinstall.
I once had the same thinking and want to upgrade my rb5009 after a few weeks since the release,Now 18 days after release i thought, it is safe to flash my rb5009...
It is bricked now... only eth1 flashes for a seconds and nothing more.
Couldnt achieve a netinstall ...
I suppose in your laziness you did not read the post above completely ? ;)I once had the same thinking and want to upgrade my rb5009 after a few weeks since the release,
but "luckily" I was busy and lazy and didn't do that.