Software-update: RouterOS 7.24
MikroTik heeft versie 7.24 van RouterOS uitgebracht, een besturingssysteem dat zich richt op het uitvoeren van routertaken en meer. Denk daarbij natuurlijk aan het routeren van netwerkverkeer, maar ook aan een firewall, bandbreedtemanagement, het aansturen van accesspoints, een vpn-server en een hotspotgateway. Het kan zowel op de hardware van MikroTik als op x86- of virtuele machines zijn werk doen. Voor het gebruik is een licentie nodig, die bij de aankoop van MikroTik-hardware is inbegrepen. De changelog voor deze uitgave kan hieronder worden gevonden.
What's new in 7.24:adlist - improved service stability when adjusting adlist configurationapp - added "HF_TOKEN" env to openwebuiapp - added "network-outgoing-access" parameter which does not allow app to make outgoing connectionsapp - added hermes-agent, inventree, opencloud, opencloud-extended appsapp - added PAPERLESS_SECRET_KEY env to paperless-nginxapp - allow "reset" even if disk not configuredapp - allow HTTP for Gitea when "check-certificate=no"app - allow setting "working_dir" in app YAMLapp - changed pmacct-netflow YAMLapp - disable UI in Hermes, access through /container/shellapp - fixed apps not updating firewall redirects when changed in YAMLapp - fixed apps sometimes getting stuck on "waiting for layer"app - make secrets sensitive to avoid polluting configuration exportapp - removed healthcheck from opencloud-extended-collaboraapp - reserve the app's VETH IP when stopped to eliminate IP address changes on every start/stopapp - show CHR's address instead of the container'sapp - use randomly generated secrets in new appsbgp - fixed EVPN label corruption and corrected EVPN type-5 outputbgp - improved stability when receiving malformed packetsbgp - removed "save-to" from "resend" commandbgp-vpn - fixed blackhole route exportbridge - added "querier-uses-bridge-address" setting to use bridge source IP address for IGMP querierbridge - added DHCPv4 snooping IP binding tablebridge - added scheduling point during VLAN processing to prevent soft lockups when flushing FDB over large VLAN rangesbridge - fixed forwarding through peer-port after disabling MLAGbridge - fixed local static host entriesbridge - fixed MLAG MAC address handling issues related to aging, flushing and movingbridge - fixed stability issue when using DHCPv4 snoopingbridge - fixed stuck MLAG session when using mismatched L2MTU (introduced in v7.23)bridge - improved bridge and port STP "priority" setting (warn when a non-compliant value is used and allow selecting a value from a list)bridge - improved STP, BPDU and topology change handling with MLAG, ensure dual-connected port STP state is in sync with MLAG peerbtest - added VRF support for bandwidth-test and speed-testcertificate - added "acme-renew" commandcertificate - general improvements in certificate handlingcertificate - use AES encryption when exporting certificates in PKCS#12 formatconsole - added "days" to schedulerconsole - added "in" and "has" operators for array typesconsole - added "order-by" parameter to "print" command, allowing sorting by up to three arguments in ascending or descending orderconsole - added comparison operators for array typeconsole - added log tracing when scripts fail to start due to permissionsconsole - do not terminate self-removing scriptsconsole - fixed "print follow on-event" script runner command not showing all argument values in some casesconsole - fixed argument mappings in "do" block for monitor commandsconsole - fixed proplist order in monitor commandsconsole - fixed script import/export with empty "policy" settingconsole - fixed stability issue in full-screen editorconsole - fixed UTF-8 comparisons on some architecturesconsole - improved "print detail" modeconsole - improved script handling and error logging when running scripts from external sources (e.g. DHCP, SNMP, Netwatch, etc.)console - make "mac-auth-password" sensitive in "/ip/hotspot/profile"console - make "password" sensitive in "/system/package/local-update/mirror"console - produce runtime errors for bad command parametersconsole - prompt about and offer to stop already existing serial terminal session when opening new oneconsole - renamed "address" to "available-from" in "/ip/service" (backwards compatible via deprecation)console - renamed "reauth-timeout" to "reauth-period" in "/interface/dot1x/server" (backwards compatible via deprecation)console - restrict editing comments in WiFi registration tablecontainer - added "save" command to allow saving container imagescontainer - added "swap-current" usagecontainer - added "swap-max" global and per-container limitcontainer - added ability to run containers in privileged modecontainer - added initial support for RKE2container - do not allow starting with empty default DNS list and no DNS overridecontainer - do not print environment variables in log on container startupcontainer - fixed "start-on-boot" not retrying on certain startup errorscontainer - fixed container "devices" override to appear under "/dev"container - improved layer size calculation to avoid potential loopscontainer - improved support for containerscontainer - reduced writes to flash when running health checkcontainer - use env "TERM=xterm" if no TERM variable provided when running shellcrypto - fixed hardware accelerator for GCM cipher in TLS connection on Alpine CPUsdefconf - set "configuration.dtim-period=3" for WiFidefconf - use "add-dns-entries=yes" on devices with DHCP serverdhcp - fixed processing of DHCP options that are longer than 255 bytesdhcpv4-relay - fixed stability issue when creating duplicate relaysdhcpv4-server - do not reset "class-id" parameter when lease loses "bound" statusdhcpv4-server - set "ciaddr" in forcerenew messages so a relay, if used, can unicast such messagesdhcpv6-relay - fixed non-working relay when adding from WinBoxdhcpv6-server - fixed invalid flagdiscovery - added "address6" column to default "/ip/neighbor" print viewdiscovery - added "discovery" logging topicdiscovery - added "dying-gasp" feature for LLDP, MNDP, CDP that sends packet with "TTL=0" before graceful reboot/shutdown/upgradediscovery - clear neighbor entry when receiving "dying-gasp" packetdiscovery - improved service stability when sending discovery packets on interfaces that have hundreds of IP addressesdisk - added "last-seen" property that displays disk model and serial when removeddisk - added "raid-scrub-cancel" commanddisk - added error message when disk state transitions from good to baddisk - do not consider USB drives as self-encryption capabledisk - fixed "smart-info" not showing information on certain storage devicesdisk - limited maximum swap size to be no more than 10x of device RAMdisk - resolved issue where storage device might change information upon rebootethernet - disable EEE on hAP be3 Mediaethernet - fixed stability issue for Chateau PRO ax devicesethernet - fixed stability issue for devices with Alpine CPUethernet - removed "1G-baseT-half" link mode on RTL8367 switchfetch - added "ip-type" parameterfetch - added option to force HTTP/2 only (only for ARM64 and x86/CHR devices)fetch - fixed false "bad request" response when trying to fetch URL with IPv6 address in itfetch - hint file list for "src-path" and "dst-path" parametershardware - renamed "max-power" to "manufacturer-reported-max-power"iot - added LoRa keep alive logic for UDP protocoliot - added missing LoRa US radio plansiot - added Wiliot USB dongle supportiot - allow maximum Modbus "timeout" property to be 10 secondsiot - monitor LoRa worker state (watchdog)iot - pass Wiliot certificationip-service - remove reverse-proxy for SMIPSip-service - show service name for "l2tp"ipsec - fixed expired SA handling to prevent “no such item” errors during listingipsec,ike1 - dropped base mode exchangeipsec,ike1 - fixed negotiated PFS validationipsec,ike1 - improved SA, transform, fragment parsing and malformed packet validationipsec,ike2 - fixed ppk child key generation during rekeyipsec,ike2 - improved KE generation validation during initial setup and child SA creationipsec,ike2 - improved PPK handling by always using it when authorized, including additional Child SAs, and moved PPK processing to the Child SA taskipsec,ike2 - use first child KE selection only during IKE_AUTH exchangeipsec,qkd - moved QKD to "/system/keymat-provider" menu and made it a generic key material provideripv6 - added "status" column to default "/ipv6/neighbor" print viewipv6,ra - changed default "router-advertisement-route-distance" to 1ipv6,ra - correctly process RAs advertising previously expired prefixipv6,ra - fixed prefix invalidationipv6,ra - use lowest value between IPv6/Pool and IPv6/ND/Prefix/Default as dynamic prefix lifetimeisis - fixed ECMP route removall2tp - allow fragmentation of large IPv6 packetsl3hw - added HW offloaded support for VLAN interfaces created directly on Ethernet for CRS8xx series switchesl3hw - added HW offloaded VRF support on 98DX8208, 98DX8216, 98DX8212, 98DX8332, 98DX3257, 98DX4310, 98DX8525, 98DX3255, 98CX8410 switchesl3hw - added VRF assignment via switch ACL rules for devices with Marvell Prestera switch chipl3hw - allow VLAN tagged traffic inside VXLAN tunnell3hw - fixed VRF-related issues for CRS8xx series switchesl3hw - fixed VTEP offload on IPv4 /32 route changesleds - added dark mode support for L009, hAP ax2, hAP ax3, hEX refresh, hEX S (2025), hAP ax S and Chateau ax devicesleds - fixed Ethernet activity LED for Chateau LTE18 ax (introduced in v7.23)leds - improved interface stats activity for devices with Marvell Prestera switch chiplte - added force-confirmation parameter for eSIM provision commandlte - cap IPv6 prefix lifetime for ipv6-interfacelte - do not add extra /128 IPv6 address for ipv6-interfacelte - do not query 5G neighbor cell info until RG650E-EU FW fixedlte - enabled AT registration unsolicited event reporting for EG25-G and EC25-EU boardslte - fixed cases where R11l-LTE7 modem would not display correct cell info after handoverlte - fixed EC/IO scale in CLI and GUIlte - fixed EC25-EU, EG25-G traffic to 67 UDPlte - fixed IPv6 RA handling for multiapn non-primary interfacelte - fixed third-party modems ICCID decoding for eSIMlte - improved Cinterion PLS8-E roaminglte - improved deregistration handling for AT modemslte - improved system stability when no APN specifiedlte - improved USB mode handling for BG770A-GLlte - limit IPv6 prefix lifetime only when lifetime is advertised as infinitylte - make modem MAC persistent for R11e-LTE6 and R11l-LTE7 modemslte - remove site local DNS for ipv6-interfacelte - removed extra restart after firmware upgrade for EC200A-EU modemlte - report short cell ID in 3G network mode also for AT modemslte - restrict incoming calls for FG621-EUlte - show "+CME ERROR: 10" as "SIM not present"lte - show "data-class" in LTE monitor instead of "access-technology" also for 5G AT modemslte - show "primary-band" instead of "earfcn" in LTE monitor also for modems without CA supportlte - show RSCP and EC/IO parameter in 3G network mode for R11e-LTE6, R11l-LTE7 and FG621-EA modemsmesh - fixed missing FDB entries from wireless portsmpls - added ICMP time exceeded handler for IPv6mpls - make FastPath work with expl-nullnetinstall - added Netinstall packagenetinstall - improved architecture detectionnetinstall-cli - added "help" parameternetinstall-cli - added "reboot" and "shutdown" flags to control reboot after installationnetwatch - fixed an issue with DNS probe "timeout" parameternetwatch - fixed HTTP GET probe over IPv6netwatch - fixed inaccurate "rtt-stdev" valuenetwatch - fixed issue where ICMP probes did not accept TTL exceeded packets when "accept-icmp-time-exceeded" was enablednetwatch - increased maximum packet size to 65535ospf - fixed stability issue during interface flapsospf - force passive for VRF interfacepimsm - make "hash-mask-length" parameter naming consistent and fixed typospoe-in - added PoE-in monitoring and LLDP-based PoE negotiation support for newer devices (e.g. CRS504, CRS510, hEX S 2025, hAP be3 Media)poe-out - firmware update for 802.3at capable boards (the update will cause a brief power interruption to poe-out interfaces)poe-out - firmware update for 802.3bt capable boards (the update will cause a brief power interruption to poe-out interfaces)ppp - added "MT-Address-List" to IPv6 address list when received from RADIUS and using DHCP for IPv6 configurationppp - added iccid field to ppp info command for BG77 and BG770 modemsppp - always show current FW version when running firmware-upgradeppp - disable/enable modem radio state depending on ppp interface stateppp - fixed cases where BG77 or BG770 firmware upgrade was not availableppp - fixed ppp-out stability issueppp - get IPv6 configuration via RA for modems using PPP emulation modeppp - improved "info" command for BG77 and BG770 modemsppp - improved OVPN underlying SSL connection managementppp - only show pin in export with "show-sensitive" flagppp - report actual network data usage statistics instead of "0" for all IPv6 RADIUS accounting parameters on accounting "Stop" packetppp - toggle radio state on interface disable/enablequeue - fixed "undo" command for simple queuesreverse-proxy - improved stabilityrip - do not export authentication keys by defaultroute - allow to add route with link-local destination addressroute - fixed memory leak when flapping addresses or interfaces with routing protocols runningroute - fixed potential race conditionroute - respect the "interface" property when pinging IPv6 addresses over ECMPsfp - fixed linking for hAP ax S and hEX S (2025) with "1G-baseX" link-modesfp - removed unsupported "2.5G-baseX" speed on CRS312-4C+8XG and CRS326-4C+20G+2Q+sftp - fixed branding package uploadsms - added some GSM7 symbols to SMS toolsnmp - added hotspot active-user-count and host-count OIDs to MIKROTIK-MIBsnmp - added missing SFP OIDs to MIKROTIK-MIBsnmp - added WiFi current channel "mtxrWifiInterfacesCurrentChannel" OID to MIKROTIK-MIBssh - added mlkem768x25519-sha256 key exchange supportssh - do not attempt automatic empty password login when RADIUS is usedssh - fixed SSH tunnel with IPv6 link-local address on non-ethernet interfacesssh - make SSH packet validation more strictsupout - added interface monitor-trafficsupout - added LTE eSIM sectionswitch - fixed IEEE reserved MAC handling for CRS1xx, CRS2xx switchessystem - improved stabilitysystem - renamed "factory-software" to "minimum-version" and "factory-firmware" to "minimum-firmware"system - restrict RouterOS processes using swapsystem - show who is using "/system serial-terminal"traffic-generator - fixed injecting pcap/pcapng files on MIPSBE architecturetunnel - fixed stability issue caused by a misconfigured routing loop under bridge (introduced in v7.22)upgrade - removed sensitive policy for "apply-changes" commandusb - allow overriding the power-reset durationusb - fixed USB Ethernet interface default-namevpls - added transmit loop detectionvrrp - added "v3-checksum-as-v2" settingvrrp - fixed stability issue when "sync-connection-tracking" is enabledvxlan - fixed missing L2MTU property when VRF is specifiedvxlan - ignore disabled interfaces when checking for configuration conflictswebfig - fixed issue with increasing keep-alive trafficwebfig - improved underlying encryption and stability processingwebfig - improvements to graphswifi - added "Preamble Puncturing" under "WiFi/Channel" menuwifi - added dash when CAPsMAN generates interface name and prefix ends with digitwifi - improved roaming/steering behavior for WiFi 7 MLOwifi - improved stabilitywifi - improved station-bridge modewifi - updated radio regulatory informationwifi - upgraded wifi-qcom driverwifi-mediatek - fixed broken interfaces on startupwifi-mediatek - fixed some channel definitions for certain countrieswifi-mediatek - improved channel switchingwifi-mediatek - improved stability during MLO channel switchingwinbox - added "Network" configuration menu for WiFiwinbox - added "Preferred Architecture" setting for L009winbox - added "SIM PIN" under "Tools/SMS"winbox - fixed "Connection Bytes" field under "IP/Firewall" menuwinbox - fixed "EC/IO" scaling for LTE interfacewinbox - fixed "Use Ipsec" and "Ipsec Secret" under "Interfaces/L2TP Ether" menuwinbox - fixed empty value in "Immediate Gateway" under "IP/Routes" menuwinbox - fixed sort for "Address List" under "IPv6/Firewall" menuwinbox - make LoRa "Auth key" and MQTT "Password" sensitivewinbox - move "EAP" under "Security" tab for WiFiwinbox - show "Any. Port" column by default under "IP/Firewall" menuwinbox - show preferred and valid lifetime of IPv6 address also on static IPswinbox - show priority bits in "VLAN ID" field under "Tools/Packet Sniffer" menuwireguard - added support for domain names in client-dnswireguard - added warning when allowed-address overlaps with another peer on the same interfacewireguard - fixed peer recreation on interface changewireguard - fixed peer Tx/Rx counterswireguard - fixed wg-export comments output and case when endpoint is not setwireguard - fixed whitespace handling in AllowedIPs during wg-importwireguard - generate port number when specified as zerowireguard - improved wg-export to print endpoint domain namewireguard - improved wg-import to quietly ignore wg-quick specific keyswireguard - reconfigure peer only when meaningful changes are detectedwireguard - reinitialize socket on VRF changex86 - fixed IRQ displaying per CPU on Intel 700 series NIC
adlist - improved service stability when adjusting adlist configurationapp - added "HF_TOKEN" env to openwebuiapp - added "network-outgoing-access" parameter which does not allow app to make outgoing connectionsapp - added hermes-agent, inventree, opencloud, opencloud-extended appsapp - added PAPERLESS_SECRET_KEY env to paperless-nginxapp - allow "reset" even if disk not configuredapp - allow HTTP for Gitea when "check-certificate=no"app - allow setting "working_dir" in app YAMLapp - changed pmacct-netflow YAMLapp - disable UI in Hermes, access through /container/shellapp - fixed apps not updating firewall redirects when changed in YAMLapp - fixed apps sometimes getting stuck on "waiting for layer"app - make secrets sensitive to avoid polluting configuration exportapp - removed healthcheck from opencloud-extended-collaboraapp - reserve the app's VETH IP when stopped to eliminate IP address changes on every start/stopapp - show CHR's address instead of the container'sapp - use randomly generated secrets in new appsbgp - fixed EVPN label corruption and corrected EVPN type-5 outputbgp - improved stability when receiving malformed packetsbgp - removed "save-to" from "resend" commandbgp-vpn - fixed blackhole route exportbridge - added "querier-uses-bridge-address" setting to use bridge source IP address for IGMP querierbridge - added DHCPv4 snooping IP binding tablebridge - added scheduling point during VLAN processing to prevent soft lockups when flushing FDB over large VLAN rangesbridge - fixed forwarding through peer-port after disabling MLAGbridge - fixed local static host entriesbridge - fixed MLAG MAC address handling issues related to aging, flushing and movingbridge - fixed stability issue when using DHCPv4 snoopingbridge - fixed stuck MLAG session when using mismatched L2MTU (introduced in v7.23)bridge - improved bridge and port STP "priority" setting (warn when a non-compliant value is used and allow selecting a value from a list)bridge - improved STP, BPDU and topology change handling with MLAG, ensure dual-connected port STP state is in sync with MLAG peerbtest - added VRF support for bandwidth-test and speed-testcertificate - added "acme-renew" commandcertificate - general improvements in certificate handlingcertificate - use AES encryption when exporting certificates in PKCS#12 formatconsole - added "days" to schedulerconsole - added "in" and "has" operators for array typesconsole - added "order-by" parameter to "print" command, allowing sorting by up to three arguments in ascending or descending orderconsole - added comparison operators for array typeconsole - added log tracing when scripts fail to start due to permissionsconsole - do not terminate self-removing scriptsconsole - fixed "print follow on-event" script runner command not showing all argument values in some casesconsole - fixed argument mappings in "do" block for monitor commandsconsole - fixed proplist order in monitor commandsconsole - fixed script import/export with empty "policy" settingconsole - fixed stability issue in full-screen editorconsole - fixed UTF-8 comparisons on some architecturesconsole - improved "print detail" modeconsole - improved script handling and error logging when running scripts from external sources (e.g. DHCP, SNMP, Netwatch, etc.)console - make "mac-auth-password" sensitive in "/ip/hotspot/profile"console - make "password" sensitive in "/system/package/local-update/mirror"console - produce runtime errors for bad command parametersconsole - prompt about and offer to stop already existing serial terminal session when opening new oneconsole - renamed "address" to "available-from" in "/ip/service" (backwards compatible via deprecation)console - renamed "reauth-timeout" to "reauth-period" in "/interface/dot1x/server" (backwards compatible via deprecation)console - restrict editing comments in WiFi registration tablecontainer - added "save" command to allow saving container imagescontainer - added "swap-current" usagecontainer - added "swap-max" global and per-container limitcontainer - added ability to run containers in privileged modecontainer - added initial support for RKE2container - do not allow starting with empty default DNS list and no DNS overridecontainer - do not print environment variables in log on container startupcontainer - fixed "start-on-boot" not retrying on certain startup errorscontainer - fixed container "devices" override to appear under "/dev"container - improved layer size calculation to avoid potential loopscontainer - improved support for containerscontainer - reduced writes to flash when running health checkcontainer - use env "TERM=xterm" if no TERM variable provided when running shellcrypto - fixed hardware accelerator for GCM cipher in TLS connection on Alpine CPUsdefconf - set "configuration.dtim-period=3" for WiFidefconf - use "add-dns-entries=yes" on devices with DHCP serverdhcp - fixed processing of DHCP options that are longer than 255 bytesdhcpv4-relay - fixed stability issue when creating duplicate relaysdhcpv4-server - do not reset "class-id" parameter when lease loses "bound" statusdhcpv4-server - set "ciaddr" in forcerenew messages so a relay, if used, can unicast such messagesdhcpv6-relay - fixed non-working relay when adding from WinBoxdhcpv6-server - fixed invalid flagdiscovery - added "address6" column to default "/ip/neighbor" print viewdiscovery - added "discovery" logging topicdiscovery - added "dying-gasp" feature for LLDP, MNDP, CDP that sends packet with "TTL=0" before graceful reboot/shutdown/upgradediscovery - clear neighbor entry when receiving "dying-gasp" packetdiscovery - improved service stability when sending discovery packets on interfaces that have hundreds of IP addressesdisk - added "last-seen" property that displays disk model and serial when removeddisk - added "raid-scrub-cancel" commanddisk - added error message when disk state transitions from good to baddisk - do not consider USB drives as self-encryption capabledisk - fixed "smart-info" not showing information on certain storage devicesdisk - limited maximum swap size to be no more than 10x of device RAMdisk - resolved issue where storage device might change information upon rebootethernet - disable EEE on hAP be3 Mediaethernet - fixed stability issue for Chateau PRO ax devicesethernet - fixed stability issue for devices with Alpine CPUethernet - removed "1G-baseT-half" link mode on RTL8367 switchfetch - added "ip-type" parameterfetch - added option to force HTTP/2 only (only for ARM64 and x86/CHR devices)fetch - fixed false "bad request" response when trying to fetch URL with IPv6 address in itfetch - hint file list for "src-path" and "dst-path" parametershardware - renamed "max-power" to "manufacturer-reported-max-power"iot - added LoRa keep alive logic for UDP protocoliot - added missing LoRa US radio plansiot - added Wiliot USB dongle supportiot - allow maximum Modbus "timeout" property to be 10 secondsiot - monitor LoRa worker state (watchdog)iot - pass Wiliot certificationip-service - remove reverse-proxy for SMIPSip-service - show service name for "l2tp"ipsec - fixed expired SA handling to prevent “no such item” errors during listingipsec,ike1 - dropped base mode exchangeipsec,ike1 - fixed negotiated PFS validationipsec,ike1 - improved SA, transform, fragment parsing and malformed packet validationipsec,ike2 - fixed ppk child key generation during rekeyipsec,ike2 - improved KE generation validation during initial setup and child SA creationipsec,ike2 - improved PPK handling by always using it when authorized, including additional Child SAs, and moved PPK processing to the Child SA taskipsec,ike2 - use first child KE selection only during IKE_AUTH exchangeipsec,qkd - moved QKD to "/system/keymat-provider" menu and made it a generic key material provideripv6 - added "status" column to default "/ipv6/neighbor" print viewipv6,ra - changed default "router-advertisement-route-distance" to 1ipv6,ra - correctly process RAs advertising previously expired prefixipv6,ra - fixed prefix invalidationipv6,ra - use lowest value between IPv6/Pool and IPv6/ND/Prefix/Default as dynamic prefix lifetimeisis - fixed ECMP route removall2tp - allow fragmentation of large IPv6 packetsl3hw - added HW offloaded support for VLAN interfaces created directly on Ethernet for CRS8xx series switchesl3hw - added HW offloaded VRF support on 98DX8208, 98DX8216, 98DX8212, 98DX8332, 98DX3257, 98DX4310, 98DX8525, 98DX3255, 98CX8410 switchesl3hw - added VRF assignment via switch ACL rules for devices with Marvell Prestera switch chipl3hw - allow VLAN tagged traffic inside VXLAN tunnell3hw - fixed VRF-related issues for CRS8xx series switchesl3hw - fixed VTEP offload on IPv4 /32 route changesleds - added dark mode support for L009, hAP ax2, hAP ax3, hEX refresh, hEX S (2025), hAP ax S and Chateau ax devicesleds - fixed Ethernet activity LED for Chateau LTE18 ax (introduced in v7.23)leds - improved interface stats activity for devices with Marvell Prestera switch chiplte - added force-confirmation parameter for eSIM provision commandlte - cap IPv6 prefix lifetime for ipv6-interfacelte - do not add extra /128 IPv6 address for ipv6-interfacelte - do not query 5G neighbor cell info until RG650E-EU FW fixedlte - enabled AT registration unsolicited event reporting for EG25-G and EC25-EU boardslte - fixed cases where R11l-LTE7 modem would not display correct cell info after handoverlte - fixed EC/IO scale in CLI and GUIlte - fixed EC25-EU, EG25-G traffic to 67 UDPlte - fixed IPv6 RA handling for multiapn non-primary interfacelte - fixed third-party modems ICCID decoding for eSIMlte - improved Cinterion PLS8-E roaminglte - improved deregistration handling for AT modemslte - improved system stability when no APN specifiedlte - improved USB mode handling for BG770A-GLlte - limit IPv6 prefix lifetime only when lifetime is advertised as infinitylte - make modem MAC persistent for R11e-LTE6 and R11l-LTE7 modemslte - remove site local DNS for ipv6-interfacelte - removed extra restart after firmware upgrade for EC200A-EU modemlte - report short cell ID in 3G network mode also for AT modemslte - restrict incoming calls for FG621-EUlte - show "+CME ERROR: 10" as "SIM not present"lte - show "data-class" in LTE monitor instead of "access-technology" also for 5G AT modemslte - show "primary-band" instead of "earfcn" in LTE monitor also for modems without CA supportlte - show RSCP and EC/IO parameter in 3G network mode for R11e-LTE6, R11l-LTE7 and FG621-EA modemsmesh - fixed missing FDB entries from wireless portsmpls - added ICMP time exceeded handler for IPv6mpls - make FastPath work with expl-nullnetinstall - added Netinstall packagenetinstall - improved architecture detectionnetinstall-cli - added "help" parameternetinstall-cli - added "reboot" and "shutdown" flags to control reboot after installationnetwatch - fixed an issue with DNS probe "timeout" parameternetwatch - fixed HTTP GET probe over IPv6netwatch - fixed inaccurate "rtt-stdev" valuenetwatch - fixed issue where ICMP probes did not accept TTL exceeded packets when "accept-icmp-time-exceeded" was enablednetwatch - increased maximum packet size to 65535ospf - fixed stability issue during interface flapsospf - force passive for VRF interfacepimsm - make "hash-mask-length" parameter naming consistent and fixed typospoe-in - added PoE-in monitoring and LLDP-based PoE negotiation support for newer devices (e.g. CRS504, CRS510, hEX S 2025, hAP be3 Media)poe-out - firmware update for 802.3at capable boards (the update will cause a brief power interruption to poe-out interfaces)poe-out - firmware update for 802.3bt capable boards (the update will cause a brief power interruption to poe-out interfaces)ppp - added "MT-Address-List" to IPv6 address list when received from RADIUS and using DHCP for IPv6 configurationppp - added iccid field to ppp info command for BG77 and BG770 modemsppp - always show current FW version when running firmware-upgradeppp - disable/enable modem radio state depending on ppp interface stateppp - fixed cases where BG77 or BG770 firmware upgrade was not availableppp - fixed ppp-out stability issueppp - get IPv6 configuration via RA for modems using PPP emulation modeppp - improved "info" command for BG77 and BG770 modemsppp - improved OVPN underlying SSL connection managementppp - only show pin in export with "show-sensitive" flagppp - report actual network data usage statistics instead of "0" for all IPv6 RADIUS accounting parameters on accounting "Stop" packetppp - toggle radio state on interface disable/enablequeue - fixed "undo" command for simple queuesreverse-proxy - improved stabilityrip - do not export authentication keys by defaultroute - allow to add route with link-local destination addressroute - fixed memory leak when flapping addresses or interfaces with routing protocols runningroute - fixed potential race conditionroute - respect the "interface" property when pinging IPv6 addresses over ECMPsfp - fixed linking for hAP ax S and hEX S (2025) with "1G-baseX" link-modesfp - removed unsupported "2.5G-baseX" speed on CRS312-4C+8XG and CRS326-4C+20G+2Q+sftp - fixed branding package uploadsms - added some GSM7 symbols to SMS toolsnmp - added hotspot active-user-count and host-count OIDs to MIKROTIK-MIBsnmp - added missing SFP OIDs to MIKROTIK-MIBsnmp - added WiFi current channel "mtxrWifiInterfacesCurrentChannel" OID to MIKROTIK-MIBssh - added mlkem768x25519-sha256 key exchange supportssh - do not attempt automatic empty password login when RADIUS is usedssh - fixed SSH tunnel with IPv6 link-local address on non-ethernet interfacesssh - make SSH packet validation more strictsupout - added interface monitor-trafficsupout - added LTE eSIM sectionswitch - fixed IEEE reserved MAC handling for CRS1xx, CRS2xx switchessystem - improved stabilitysystem - renamed "factory-software" to "minimum-version" and "factory-firmware" to "minimum-firmware"system - restrict RouterOS processes using swapsystem - show who is using "/system serial-terminal"traffic-generator - fixed injecting pcap/pcapng files on MIPSBE architecturetunnel - fixed stability issue caused by a misconfigured routing loop under bridge (introduced in v7.22)upgrade - removed sensitive policy for "apply-changes" commandusb - allow overriding the power-reset durationusb - fixed USB Ethernet interface default-namevpls - added transmit loop detectionvrrp - added "v3-checksum-as-v2" settingvrrp - fixed stability issue when "sync-connection-tracking" is enabledvxlan - fixed missing L2MTU property when VRF is specifiedvxlan - ignore disabled interfaces when checking for configuration conflictswebfig - fixed issue with increasing keep-alive trafficwebfig - improved underlying encryption and stability processingwebfig - improvements to graphswifi - added "Preamble Puncturing" under "WiFi/Channel" menuwifi - added dash when CAPsMAN generates interface name and prefix ends with digitwifi - improved roaming/steering behavior for WiFi 7 MLOwifi - improved stabilitywifi - improved station-bridge modewifi - updated radio regulatory informationwifi - upgraded wifi-qcom driverwifi-mediatek - fixed broken interfaces on startupwifi-mediatek - fixed some channel definitions for certain countrieswifi-mediatek - improved channel switchingwifi-mediatek - improved stability during MLO channel switchingwinbox - added "Network" configuration menu for WiFiwinbox - added "Preferred Architecture" setting for L009winbox - added "SIM PIN" under "Tools/SMS"winbox - fixed "Connection Bytes" field under "IP/Firewall" menuwinbox - fixed "EC/IO" scaling for LTE interfacewinbox - fixed "Use Ipsec" and "Ipsec Secret" under "Interfaces/L2TP Ether" menuwinbox - fixed empty value in "Immediate Gateway" under "IP/Routes" menuwinbox - fixed sort for "Address List" under "IPv6/Firewall" menuwinbox - make LoRa "Auth key" and MQTT "Password" sensitivewinbox - move "EAP" under "Security" tab for WiFiwinbox - show "Any. Port" column by default under "IP/Firewall" menuwinbox - show preferred and valid lifetime of IPv6 address also on static IPswinbox - show priority bits in "VLAN ID" field under "Tools/Packet Sniffer" menuwireguard - added support for domain names in client-dnswireguard - added warning when allowed-address overlaps with another peer on the same interfacewireguard - fixed peer recreation on interface changewireguard - fixed peer Tx/Rx counterswireguard - fixed wg-export comments output and case when endpoint is not setwireguard - fixed whitespace handling in AllowedIPs during wg-importwireguard - generate port number when specified as zerowireguard - improved wg-export to print endpoint domain namewireguard - improved wg-import to quietly ignore wg-quick specific keyswireguard - reconfigure peer only when meaningful changes are detectedwireguard - reinitialize socket on VRF changex86 - fixed IRQ displaying per CPU on Intel 700 series NIC
Source:
Tweakers.net