... with 7.8 my core router (CRS326-24S+2Q+RM) did 3 times spontaneous reboots initiated from watchdog in the last 12 days ... back to 7.7 solves the problem.
Sorry, but the last netinstall was 7.4, or 7.5 (I can´t remember...) and it can´t be the way to netinstall every new stable version, to eliminate problems we didn´t have with the previous version.... with 7.8 my core router (CRS326-24S+2Q+RM) did 3 times spontaneous reboots initiated from watchdog in the last 12 days ... back to 7.7 solves the problem.
Could you try a Netinstall and see if that changes anything?
Check the list of switch chips that supports hardware offloading - https://help.mikrotik.com/docs/display/ ... OffloadingHardware offload does not work in bridge - ports on hAP ax3
In my case its affection only RB1100AHx4 model as took one of my RB5009 upgraded to 7.8 all switching works nothing breaks all good.Hello guys, I have set up RB1100AHx4 switching so some vlans, some ports tagged some untagged, all works file on 6.49.7 but once i upgrade to 7.8 all vlans stops working , I have to disable vlan filtering on the bridge and to re-enable to start it working but after reboot of the router all stops working again. Downgraded back to version 6 all works fine. Have similar setup on other RB4011 router OS 7.6 all works fine. Its it something wrong with 7.8?
... the last netinstall was 7.4, or 7.5 ... it can´t be the way to netinstall every new stable version ...
Unfortunately I even had to netinstall my RB5009, which is ROS7 only, after upgrading from ROS7.6 to ROS7.7.Sorry, but the last netinstall was 7.4, or 7.5 (I can´t remember...) and it can´t be the way to netinstall every new stable version, to eliminate problems we didn´t have with the previous version.
/ip ipsec mode-config
add name="modeconf s2s" responder=no src-address-list=192.168.21.0/24
/ip ipsec policy group
add name="group s2s"
/ip ipsec profile
add dh-group=ecp256 dpd-interval=1m enc-algorithm=aes-256 hash-algorithm=sha256 name="profile s2s"
/ip ipsec peer
add address=SERVER-ADDRESS.COM exchange-mode=ike2 name="peer s2s" profile="profile s2s"
/ip ipsec proposal
add auth-algorithms="" enc-algorithms=aes-256-gcm lifetime=20m name="proposal s2s" pfs-group=modp4096
/ip ipsec identity
add auth-method=digital-signature certificate=CLIENT-CERT-NAME generate-policy=port-strict my-id=user-fqdn:CLIENT-NAME peer="peer s2s" policy-template-group="group s2s" remote-id=fqdn:SERVER-NAME
/ip ipsec policy
add dst-address=192.168.20.0/24 level=unique peer="peer s2s" proposal="proposal s2s" src-address=192.168.21.0/24 tunnel=yes
add dst-address=192.168.22.0/24 level=unique peer="peer s2s" proposal="proposal s2s" src-address=192.168.21.0/24 tunnel=yes
21:51:15 system,info changed script settings by admin
21:51:18 script,warning Reset IKE2 peer
21:51:18 system,info ipsec peer PEERNAME changed by admin
21:51:18 system,info ipsec peer PEERNAME changed by admin
21:51:19 ipsec acquire for policy: LOCAL2.NET <=> LOCAL1.NET
21:51:19 ipsec policy group mismatch, ignoring.
21:51:19 ipsec ike2 starting for: SERVER.IP
21:51:19 ipsec adding payload: SA
21:51:19 ipsec,debug => (size 0x30)
21:51:19 ipsec,debug 00000030 0000002c 01010004 0300
ok more and more people reporting problems so 7.8 is not that stable :) needs a lot of fixes
we are having same issue ovpn chokes a cpu core to 100% randomly whenever tunnel gets interrupted and router becomes unusable this issue is on v7 only on all models we have..This update completely broke my RB3011UiAS.
Both cpu cores are at a constant 100%
I believe the issue is with the OpenVPN client interface, it requires a profile but doesn't have one, yet is still enabled. Can't disable or remove it, always results in a timeout error.
Creating a new profile results in timeout too.
Anyone any ideas..?
edit: my PPPoe interface responsible for the WAN connection has a similar problem. Also no profile configured yet enabled.
edit 2:
tried adding it via the terminal usingbut after entering a name it once again resulted in a timeoutCode: Select allppp profile add
triedtoo but once I typed the asterisk the terminal froze, this happens every time I try itCode: Select allppp profile set *0
supout.rif has been generating for about 15 minutes now too, and is stuck at 98%
edit 3: after a reboot the PPP profiles show briefly, then quickly all disappear
edit 4:
I managed after the reboot to quickly disable both the OVPN client interface and PPPoe interface after which the CPU was normal and profiles stayed visible.
Then enabled PPPoe, everything still normal.
Once I enabled the OVPN client interface all the issues returned. So this seems specifically related to my OVPN Client interface configuration
edit 5:
sent mikrotik support an email with all information and details. Hopefully this can help them figure out a fix.
While I mostly agree with you, it is also a matter of perception.I dislike the use of the word "stable" in release names.
yes, add "slot=DATA" parameter to your disk setting. has to be done from commandline at the moment.Anyone else having this thingy with USB storage that keeps changing with each reboot from usb1-part1 to usb2-part1 etc ? Basically breaking containers etc between reboots.
Was it possible to refer to a "label" in the container-settings ?
And now it gets completely weird ...Yeah, was driving me crazy until I noticed it.
Been rearranging stuff in the house yesterday (moving RB5009 down as main router, AX3 up to office): 2 reboots of RB5009 without a problem, 3th one wiped everything. Sweet ...
I have the very same problem. Upgraded from 7.6 to 7.8 and I wasn't able to log in, every port in VLAN bridge were completely dead. I've noticed the bridge has same address like ether1, connected the cable to different port and it seems it helped. No STP is enabled, even tried disable it on switches.Hi,
I have problem with:
board-name: RB1100AHx4
model: RB1100x4
revision: r2
serial-number: xxxxxxx90618B
firmware-type: al2
factory-firmware: 6.45.9
current-firmware: 7.8
It was working OK, with 7.7:
- 3 vlans interface
- 3 ether ports as trunk ports for the same vlans on each port
- IP address on each vlan interface
After upgrade to 7.8:
- ping from the device A(non-mikrotik) to device B(non Mikrotik) in the same vlan is OK(it was OK also in 7.7)
- ping from device A(non-mikrotik) to IP of the vlan interface(the same vlan) of the RB1100x4 is NOT OK
- the same is for any other vlan IP of RB1100x4
- if I remove this 3 vlan interface(including bridge vlans rules), AND I recreate them again(copy / paste), all the vlans are working, but at the next restart, it is the same problem
- on any vlan interface I see only TX traffic, and no traffic on RX(0 bytes), even after 30 min of tests in STATUS tab
I have make 3 different test, and after the reboot I see the same problem for each test.
I also try for 3 times, to downgrade to v 7.7(all vlans are OK), and upgrade at v 7.8 with the same BAD result
To me, it seem to be a BUG ;)
How can I solve this?
Thx. in advance, and good luck to all!
*) bridge - improved HW offloading logic;
And you do not have done any test (for some months at least...) separately before upgrade to latest OS, that have just a month, one device on production????hope it's my fault, had an entire company blocked due to this issue.
It may be easier to just change "Data Directory" in Dude > Setting in winbox to just use /usb1-part1. If you disable/renable Dude, it should just pick up the change. The "bus-part" naming scheme is relatively new and by design. You may be able to change the "slot" in the CLI /disk to rename it to disk1 too.After upgrading from V7.7 to V7.8 on RB3011, external USB disk root directory changed name from /disk1 to /usb1-part1, rendering DUDE disabled. What needs to be changed to return the main partition to /disk1 ?
We had simillar problem on CCR1009-8G-1S-1S+ with RouterOS 7.8 (we upgraded from 6.X to 7.X last week).I'm having the same problem here, on an RB4011. After updating to 7.8, the system has a kernel error and restarts before completing 5 minutes of uptime. I have about 150 ovpn connections.The OVPN service is unstable, and it will cause a Kernel crashes after 2,3 hours of uptime.
SUP-96432
no but to stay at v6 if BGP is in serious demand.May I ask, if anybody is using BGP route reflector and route reflector client roles. I have problems distributing l2vpn and vpnv4 routes. It looks like with normal (no role) iBGP these kind of routes are distributed, once switched to rr and rr client, they are gone. Are any special filters that should be used with those roles to pass the routes?
I don't know if this will help with RB1100, but on RB4011 with a recent version (7.6?), with the way HW offload works with multiple chips, you have to make the bridge a part of all VLANs that cross the chips (and to SFP/SFP+), because that has to be done in software.You mean "Protocol Mode" in bridge set to "None"?
I have this set to None on all my devices including the RB1100, all my reported 7.8 problems were with it set to None.
I also tried disabling Fast Track as this was also mentioned somewhere up this thread and changelog. Didn't help, although I am tempted to say that when I had it disabled the problem happend more often (but didn't try to reproduce/confirm).
Didn't yet try disabling HW offload, even if the changes in 7.8 shouldn't affect RB1100 switch chip.
I don't know if this will help with RB1100, ....
Issue confirmed by Support, SUP-110494;In my case, the SFP port is working well due to not being connected to the switch. Coming from v7.7, everything was fine.
Make a few reboots and good luck!
/ip firewall filter
add action=accept chain=input connection-state=established,related,untracked
add action=drop chain=input connection-state=invalid
add action=accept chain=input protocol=icmp
add action=drop chain=input in-interface=!ether13
Does not work. I've added it and started creating some container under the /DATA/... reference. All went well as long as the RB5009 kept running.yes, add "slot=DATA" parameter to your disk setting. has to be done from commandline at the moment.Anyone else having this thingy with USB storage that keeps changing with each reboot from usb1-part1 to usb2-part1 etc ? Basically breaking containers etc between reboots.
Was it possible to refer to a "label" in the container-settings ?
Netinstall is repaired or not ??? viewtopic.php?p=911370#p911370
Can you point me to the location of the document that countains this?Do not support any 4MAC mode (WDS / bridge & Co.)
Yes, this also applies if you used the AC2 or AC3 and just bought the AX2 or AX3 as an obvious upgrade and suddenly you can't use it as a replacement because the previous device with the same software version did support bridge and 4mac but the new one doesn't yet support it.True, they do document it. But it's fair point if someone used V6 before and "upgraded" to latest hardware... it would seem more like a bug... And the reading the docs doesn't exactly "solve" the underlying problem.
The following notable features of the bundled wireless package do not yet have equivalents in the wifiwave2 package
Station-bridging or other 4-address modes
Nstreme and Nv2 wireless protocols
Lost features
The following notable features of the bundled wireless package do not yet have equivalents in the wifiwave2 package
Station-bridging or other 4-address modes
Nstreme and Nv2 wireless protocols
for the switch v6->v7 you need to choose the "upgrade" channel on "check for updates" windowHi. My rb750gr3 and 2x hap lite haven’t got the update yet. They are all currently at 6.49.7 stable (firmware too). Do i need to wait for the update to come up? I saw other people using v7.x on rb750gr3, could region be the reason? Im in Europe/Cyprus.
Thanks alot. Is there any chance that upgrading to v7.8 will slow down any of those devices?for the switch v6->v7 you need to choose the "upgrade" channel on "check for updates" windowHi. My rb750gr3 and 2x hap lite haven’t got the update yet. They are all currently at 6.49.7 stable (firmware too). Do i need to wait for the update to come up? I saw other people using v7.x on rb750gr3, could region be the reason? Im in Europe/Cyprus.
It's the secondary router for the second floor. There are only PCs, Access point and a Linux server which is connected via EoIP/L2TP/IPSec on the main router (first floor, RB5009) to avoid double natting. The hap lite ones are already kinda slow, i think i will keep them on 6.49.7.Hex, not that much depending on your use case.
Hap lite, that can be tricky resource wise.
hEX (S) should be fine. keep in mind, most of the time it is depending on your setup but as little as you described it, this should be fine on the hEX.Thanks alot. Is there any chance that upgrading to v7.8 will slow down any of those devices?
for the switch v6->v7 you need to choose the "upgrade" channel on "check for updates" window
for the time being ... if you do not need a certain function only available in v7, there is no big deal staying with v6 atm.Thanks alot guys for the recomendations and guidance. Will upgrade the hex and keep the lites on v6.
[admin@test] > /certificate add name=test.vpn.ca common-name=test.vpn.ca key-usage=key-cert-sign,crl-sign trusted=yes days-valid=3650
[admin@test] > /certificate/print detail
Flags: K - private-key; L - crl; C - smart-card-key; A - authority; I - issued, R - revoked; E - expired; T - trusted
0 name="test.vpn.ca" key-type=rsa common-name="test.vpn.ca" key-size=2048 subject-alt-name="" days-valid=3650 key-usage=key-cert-sign,crl-sign akid="" skid="" invalid-before=jan/01/1970 03:00:00 invalid-after=jan/01/1970 03:00:00
This happens because someone or a software is changing the contents of the container folders.Constantly getting my containers screwed up after some time.
After adding some additional container, its tag gets transferred to previous containers, after that they cant start.
And the tag thing is not to be changed by the user, so the only fix is to delete the damaged one and create a new container.
Well, i'm pretty sure that no one changed any container files. I do have an SMB share, but it's read only - just for remote access to tramsmission's downloads folder.This happens because someone or a software is changing the contents of the container folders.
Create a folder for each container's data, not a shared folder for all containers.
Files and data in the Container Root Dir must not be accessible to everyone or shared via SMB.
Anyone can confirm this claim? I have no success. Static DNS entry (type=FWD) here with very simple regexp, but still it forwards the request to upstream dns.*) dns - do not query upstream DNS servers for matched regex records;
Something strange - I had to clean up full FF...Sometimes you have to force refresh your browser's cache. There are subtle differences between the versions of Webfig. Other times I've found with certain devices on my network (for whatever unknown reason), I have to reload/refresh the page to get routes (or DHCP leases, or other large tables) to load.
/ip/firewall/nat> print
Flags: X - disabled, I - invalid; D - dynamic
0 ;;; SSH
chain=dstnat action=dst-nat to-addresses=10.0.11.206 to-ports=22 protocol=tcp dst-address={IP.PUBLIC.1} dst-port=1047 log=yes log-prefix="SSH-1"
1 ;;; SSH
chain=dstnat action=dst-nat to-addresses=10.0.11.206 to-ports=22 protocol=tcp dst-address={IP.PUBLIC.2} dst-port=1047 log=yes log-prefix="SSH-2"
2 ;;; VM223
chain=dstnat action=dst-nat to-addresses=10.0.3.223 protocol=udp dst-address={IP.PUBLIC.1} dst-port=1048 log=yes log-prefix="VM223-1"
3 ;;; VM223
chain=dstnat action=dst-nat to-addresses=10.0.3.223 protocol=udp dst-address={IP.PUBLIC.2} dst-port=1048 log=yes log-prefix="VM223-2"
4 ;;; VM226
chain=dstnat action=dst-nat to-addresses=10.0.2.226 protocol=udp dst-address={IP.PUBLIC.1} dst-port=1049 log=no log-prefix=""
5 ;;; VM226
chain=dstnat action=dst-nat to-addresses=10.0.2.226 protocol=udp dst-address={IP.PUBLIC.2} dst-port=1049 log=no log-prefix=""
6 ;;; PUBLIC-1
chain=srcnat action=masquerade src-address-list=LAN-Masquerade out-interface=BRIDGE-WAN1 log=no log-prefix=""
7 ;;; PUBLIC-2
chain=srcnat action=masquerade src-address-list=LAN-Masquerade out-interface=BRIDGE-WAN2 log=no log-prefix=""
Yes, it is more interesting to see the CPU load figures under typical load than the "speed test maximum speed"...The route caching from 6 is gone in 7, so any traffic that would benefit from that (speed tests) will suffer as a result.
take a look using tools profiling using ALL cores option to view individual core Load, you will see similar consumption like 6.x"Considerably slower" is relative to the hardware. My ARM, ARM64, and Tile boxes have seen significant improvements. Under 6.48.x my CCR1036 was showing 2-3% on 2Gbps of traffic. Now it shows 0% on the same traffic.
Try to netinstall your router and then add config groupe by group.I have problem with mikrotik hex 750gr3
When i update from 6.48.6 to v 7.8
my cpu is 25-45% v 6.48.6
my cpu is very busy 80%-100%. v 7.8
Why this happen? i dont have any rules only masqarade and 200-300mbps throughput.
now i have to use fasttrack to get the router to push 300mbps.
Will mikrotik fix this or is it time to buy a new router?
Do you use OVPN? This can happen because of the very unstable OpenVPN implementation right now.Try to netinstall your router and then add config groupe by group.I have problem with mikrotik hex 750gr3
When i update from 6.48.6 to v 7.8
my cpu is 25-45% v 6.48.6
my cpu is very busy 80%-100%. v 7.8
Why this happen? i dont have any rules only masqarade and 200-300mbps throughput.
now i have to use fasttrack to get the router to push 300mbps.
Will mikrotik fix this or is it time to buy a new router?
My 750gr3 are runing at 30-40%CPU. I do only have 200Mbps line.
Ok, my assumption was wrong. Now I did everything very carefully, and faced that issue again, fourth time in a row. Just after adding ~5th container it starts like overriding previous ones...Well, i'm pretty sure that no one changed any container files. I do have an SMB share, but it's read only - just for remote access to tramsmission's downloads folder.
And for sure it couldn't have been done by another containers as their scopes are limited to their own folders.
I do have separate folders for containers.
It seems i've found the origins of the problem. It starts to happen right after I try to add a container with a veth already used by another container.
My mistake for sure, but shouldn't it be somehow restricted by routeros to 1 veth = 1 container?
For low end routers like "hap lite" I've tested with version 7.6 and above, and CPU stucks at 100% very often and even reboot occured due to some hang up state.Ok, my assumption was wrong. Now I did everything very carefully, and faced that issue again, fourth time in a row. Just after adding ~5th container it starts like overriding previous ones...Well, i'm pretty sure that no one changed any container files. I do have an SMB share, but it's read only - just for remote access to tramsmission's downloads folder.
And for sure it couldn't have been done by another containers as their scopes are limited to their own folders.
I do have separate folders for containers.
It seems i've found the origins of the problem. It starts to happen right after I try to add a container with a veth already used by another container.
My mistake for sure, but shouldn't it be somehow restricted by routeros to 1 veth = 1 container?
Quite a weird behaviour... One container is stopped and its tag messed.
Fixed by: reboot, find that the messed container is absent from containers list but it's files are in place, pull it once again to the same dir with the same envs and everything... profit.
But the problem is persistent, waiting for a fix.
networking is most usedIf you use tool/profile, all, what shows as top resource consumer ?
How can I obtain the post url to send?Best to send mail to support.
Provide link to this post.
*) webfig - fixed editing of multi-field parameters with "not" checkbox;
*) webfig - improved skin file parsing;
I will get AX again when first long-term ROS 7.x is released :)yes, it make sence to return all AX3 devices buy 4xAC deices and after one year to throw 4xAC devices and buy 4xAX devices...you must be very smart :) is not better to wait till next beta ROS come? :)
No problems with reboots, my is running many days nonstop already.is there any problem with rebooting with v7.8 ?
my new router C53UiG+5HPaxD2HPaxD is rebooting non stop ??
Yes it's original. I forget to tell that I have one USB drive Kingston on it 64GB. I have remove it and plug it again and the problem is gone for now. Flash Drive is absolutely 100% good.No problems with reboots, my is running many days nonstop already.is there any problem with rebooting with v7.8 ?
my new router C53UiG+5HPaxD2HPaxD is rebooting non stop ??
Are you using original power supply delivered with your hAP ax³?