Cambios en RouterOS v6.39rc

Cambios en RouterOS v6.39rc

Para el próximo release del RouterOS, la v6.39 tendremos algunos cambios y nuevas incorporaciones al sistema operativo.

Entre algunas de las lineas del changelog (que luego fueron removidas) se puede apreciar que a partir de ésta versión se tiene soporte para nuevos productos RouterBOARD y funcionalidades que serán presentadas en el MUM de Milán, Italia, a fin de mes.

!) routeros – added support for new products and RouterOS features which will be announced at MUM EU (;

También se ha removido el matcher all-p2p del firewall. Entre los fundamentos que brinda MikroTik es que hoy en día se utilizan muy poco los protocolos de p2p como Kazaa o Limeware. A su vez el matcher suele causar problemas de interrupción de comunicaciones no-p2p cuando se lo utiliza.

El gran changelog que lleva por ahora es el siguiente:

What's new in 6.39rc45 (2017-Mar-06 14:29):

!) firewall - discontinued support for p2p matcher (old rules will become invalid);
*) hotspot - fixed redirect to URL where escape characters are used (requires newly generated HTML files);
*) l2tp-client - fixed IPSec policy generation after reboot;
*) l2tp-client - require working IPSec encryption if "use-ipsec=yes";
*) l2tp-server - added "use-ipsec=required" option;
*) lcd - show fan2 speed only if it is available;
*) tr069-client - added basic support for "/ip firewall filters";
*) tr069-client - fixed "AddObjectResponse" “InstanceNumber” value;
*) tr069-client - set CHR license ID as ".SerialNumber" value to avoid "no serial number" error in ACS;

Other changes since 6.38.3:

!) bridge - added "fast-forward" setting and counters (enabled by default only for new bridges) (CLI only);
!) bridge - added support for special and faster case of fastpath called "fast-forward" (available only on bridges with 2 interfaces);
!) filesystem - fixed rare situation when filesystem failed to read all configuration on startup;
!) filesystem - fixed rare situation when filesystem went into read-only mode (some configuration might have gotten lost on reboot);
!) l2tp - added fastpath support when MRRU is enabled;
!) ppp - completely rewritten internal fragmentation algorithm (when MRRU is used), optimized for multicore;
!) ppp - implemented internal algorithm for "change-mss", no mangle rules necessary;
!) pppoe - added fastpath support when MRRU and MLPPP are enabled;
!) quickset - configuration changes are now applied only on "OK" and "Apply" (not on mode change);
!) winbox - minimal required version is v3.11;
*) address - fixed crash when address is assigned to another bridge port;
*) capsman - added CAP discovery interface list support;
*) capsman - added save-channel option to speed up frequency selection on CAPsMAN restart;
*) capsman - added support for static virtual interfaces on CAP;
*) capsman - fixed "/caps-man manager interface" compact export;
*) capsman - support for communicating frame priority between CAP and CAPsMAN;
*) certificate - allow CRL address to be specified as DNS name;
*) chr - fixed problem when transmit speed was reduced by interface queues;
*) defconf - fixed Groove 52 ac band settings;
*) dhcp-client - added "script" option which executes script on state changes;
*) dhcpv4-server - added "lease-hostname" script parameter;
*) dhcpv4-server - do some lease checks only on enabled object;
*) dhcpv6-server - require "address-pool" to be specified;
*) dude - (changes discussed here:;
*) email - check for errors during SMTP exchange process;
*) ethernet - renamed "rx-lose" to "rx-loss" in ethernet statistics;
*) export - do not show "read-only" IRQ entries;
*) firewall - do not allow to set "time" parameter to 0s for "limit" option;
*) gps - added "fix-quality" and "horizontal-dilution" parameters;
*) graphing - fixed graph disappearance after power outage;
*) hotspot - added access to HTTP headers using $(http-header-name);
*) hotspot - show Host table commentaries also in Active tab and vice versa;
*) ike1 - added more Radius accounting attributes - "event-timestamp", "acct-session-id", "acct-authentic", "acct-session-time";
*) ike1 - fixed unnecessary Radius accounting requests;
*) ike1 - fixed “xauth” Radius login;
*) ike2 - also kill IKEv2 connections on proposal change;
*) ike2 - always limit empty remote selector;
*) ike2 - always replace empty TSi with configured address if it is available;
*) ike2 - default to /32 peer address mask;
*) ike2 - fixed EAP message length;
*) ike2 - fixed ISA handler object removal on SA delete;
*) ike2 - fixed ph2 state when sending notify;
*) ike2 - fixed proposal change crash;
*) ike2 - fixed responder subsequent new child creation when PFS is used;
*) ike2 - fixed responder TS updating on wild match;
*) ike2 - fixed state when sending delete packet;
*) ike2 - update calling_station_id radius attribute;
*) ike2 - update peer identity after successful EAP authentication;
*) ike2 - update radius attributes;
*) ippool - return proper error message when trying to create duplicate name;
*) ipsec - added last-seen parameter to active connection list;
*) ipsec - better responder flag calculator for console;
*) ipsec - deducted policy SA src/dst address from src/dst address;
*) ipsec - do not require "sa-dst-address" if "action=none" or "action=discard";
*) ipsec - fixed "/ip ipsec policy group export verbose";
*) ipsec - fixed "mode-cfg" verbose export;
*) ipsec - fixed SA address check in policy lookup;
*) ipsec - hide sa-addrs for transport policies;
*) ipsec - keep policy in kernel even with bad proposal;
*) ipsec - kill ph2 on policy removal;
*) ipsec - updated tilera classifier for UDP encapsulated ESP;
*) irq - properly detect all IRQ entries;
*) leds - added LTE modem access technology trigger;
*) leds - changed error message on unsupported board;
*) leds - do not update single LED state when it is not changed; 
*) leds - show warning on print when "modem-signal-threshold" is not available;
*) log - added "gps" topic;
*) log - added tr069 topic;
*) log - added warning when Winbox/Dude sessions were denied;
*) log - make SNMP logs more compact;
*) lte - added error handling for remote AT execute;
*) lte - added initial support for Quectel ec25;
*) lte - added support for Vodafone R216 (Huawei);
*) lte - buffer AT events while info command is active;
*) lte - fixed "/interface lte info X once";
*) lte - fixed IPv6 address prefix on interface
*) lte - fixed network mode selection for me909u, mu609;
*) lte - fixed older standard CEREG parsing;
*) lte - fixed support for Huawai R216;
*) lte - fixed user-command;
*) ppp - fixed rare kernel failure on PPP client connection;
*) ppp-client - added support for Datacard 750UL and DWR-730;
*) pppoe - make default keepalive 10s for PPPoE clients;
*) profile - classify ethernet driver activity properly in ARM architecture;
*) rb1100ahx2 - fixed random counter resets for ether12,13;
*) snmp - "No Such Instance" error message is replaced with "No Such Object";
*) snmp - added back MAC address OID in "/caps-man registration-table" (introduced in 6.39rc33);
*) snmp - added SSID to CAPsMAN registration table;
*) snmp - fixed "/tool snmp-get" crash on session timeout;
*) snmp - fixed CAPsMAN registration table OID print;
*) snmp - fixed CAPsMAN registration table SSID type;
*) snmp - fixed situation when SNMP could not read "/system health" values after reboot;
*) snmp - improved response speed when multiple requests are received within short period of time;
*) snmp - optimized bridge table processing;
*) tile - added initial support for NVMe SSD disk drives;
*) tr069-client - added "Ethernet.Interface.{i}.MACAddress" parameter;
*) tr069-client - added architecture name parameter (X_MIKROTIK_ArchName - vendor specific);
*) tr069-client - added basic stats parameters for some interface types;
*) tr069-client - added connection request authentication; 
*) tr069-client - added DHCP server support;
*) tr069-client - added parameters for DNS client management support;
*) tr069-client - added ping diagnostics support;
*) tr069-client - added support for escaped entity references (& < > ' ");
*) tr069-client - added support for managing "/system/identity/" value;
*) tr069-client - added support for memory and CPU load parameters;
*) tr069-client - added traceroute diagnostics support;
*) tr069-client - close connection if CPE considers XML as invalid;
*) tr069-client - fixed special escape characters on XML data send;
*) tr069-client - fixed “traceroute” parameter IDs;
*) tr069-client - general improvements on reducing storage space;
*) tr069-client - generate random connection request target path;
*) tr069-client - increased performance on GetParameterValues;
*) traceroute - small fix;
*) usb - added support for more CP210X devices;
*) userman - allow access to User Manager users page only through "/user" URL;
*) userman - show warning when no users are selected for CSV file generation;
*) wAP ac - improved 2.4GHz wireless performance;
*) webfig - added menu bar to quickly select between Webfig, Quickset and Terminal;
*) webfig - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
*) webfig - fixed delays on key press in terminal;
*) webfig - fixed tab ordering on Google Chrome;
*) webfig - improved field layout;
*) webfig - make Terminal window work within Webfig window;
*) winbox - added "group-key-update" to CAPsMAN security settings;
*) winbox - added GPS menu;
*) winbox - added save-selected setting under CAPsMAN channels;
*) winbox - added static-virtual to wireless CAP;
*) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
*) winbox - allow to change user password to empty one;
*) winbox - allow to not specify certificate in IPSec peer settings;
*) winbox - allow to specify certificate type when exporting it;
*) winbox - allow to specify interfaces that CAPsMAN can use for management;
*) winbox - allow unhide SNMP passwords;
*) winbox - do not create time field when copying CAPsMAN access list entry;
*) winbox - do not hide "power-cycle-after" option;
*) winbox - do not show empty LTE fields in Info menu;
*) winbox - do not try to disable dynamic items from firewall tables;
*) winbox - fixed misleading error when trying to export certificate;
*) winbox - hide advertise tab in Hotspot user profile configuration if "transparent-proxy" is not enabled;
*) winbox - increased maximal number of Winbox sessions 20->100;
*) winbox - make "power-cycle-interval" not to depend on "power-cycle-ping-enabled" in PoE settings;
*) winbox - properly name CAP Interface on new interface creation;
*) winbox - properly show BGP communities in routing filters table filter;
*) winbox - removed "sfp-rate-select" setting from ethernet interface;
*) wireless - added Egypt 5.8 country settings;
*) wireless - apply broadcast bit to DHCP requests when using station-pseudobridge mode;
*) wireless - do not allow equal MAC addresses between multiple Virtual APs when same master interface is used;
*) wireless - fixed issue when wireless interfaces might not show up in cap mode;
*) wireless - fixed occasional crash on interface disabling;
*) wireless - fixed rare crash on nv2 configurations;
*) wireless - fixed rare wireless ac interface lockup;
*) wireless - fixed scan tool stuck in background;
*) wireless - improved compatibility with Intel 2200BG wireless card;
*) x86 - added support for NVMe SSD disk drives; 

Puede ser descargado desde el sitio de MikroTik en la sección descargas o desde el Winbox en System > Packges.