Mikrotik
Интернет-магазин представительского класса
Каталог
Для дома и офиса
hEX
Домашнее решение
Роутеры
LTE роутеры
Mesh-роутер
Для транспорта
Wi-Fi оборудование
hAP
mAP
RB2011
Маршрутизаторы
Для крупного офиса
Для провайдера
USB адаптеры
Радиосвязь WISP
Магистральные радиомосты
Сотовая связь
Wi-Fi антенны
Программное обеспечение
Оборудование PowerLine
Аксессуары и комплектующие
GPON
Грозозащита
Комплектующие
Кабель, витая пара и коннекторы
SFP-модули и кабели
CWDM
Питание
Корпуса
Крепления
Маршрутизаторы без модулей Wi-Fi
IPSec
Для улиц
PoE
Точки доступа для помещений
Радиомост точка — много-точка с PoE
Точка доступа для офиса или улицы
Радиомост точка — много-точка
Офисные точки доступа
Мобильные точки доступа
Точки доступа для улиц
Wi-Fi устройства
Роутер
Точка доступа Wi-Fi/роутер
Клиентская точка доступа
Роутеры с поддержкой LTE
Коммутаторы
CRS
netPower
Акции
Помощь покупателям
Условия оплаты
Условия доставки
Гарантия на товар
Компания
О компании
Новости
Контакты
Контакты
+7 (495) 320-69-22
+7 (495) 320-69-22
Заказать звонок
Задать вопрос
Войти
  • Корзина0
  • Отложенные0
  • Сравнение товаров0
info@microtik.su
г. Москва, ул. Бакунинская, 84с21
  • Viber
  • Viber
  • WhatsApp
  • Новинки
  • Хиты продаж
  • Как купить
  • Компания
  • Новости
  • Загрузки
  • Контакты
  • ...
    Войти
    Сравнение0
    Отложенные 0
    Корзина 0
    +7 (495) 320-69-22
    +7 (495) 320-69-22
    Mikrotik
    • Для дома и офиса
      • hEX hEX
      • Домашнее решение Домашнее решение
      • Роутеры Роутеры
      • LTE роутеры LTE роутеры
      • Mesh-роутер Mesh-роутер
      • Для транспорта Для транспорта
    • Wi-Fi оборудование
      • hAP hAP
      • mAP mAP
      • RB2011 RB2011
      • Маршрутизаторы Маршрутизаторы
        • Для крупного офиса
        • Для провайдера
      • USB адаптеры
    • Радиосвязь WISP
    • Магистральные радиомосты
    • Сотовая связь
    • Wi-Fi антенны
    • Программное обеспечение
    • Оборудование PowerLine
    • Аксессуары и комплектующие
      • GPON GPON
      • Грозозащита Грозозащита
      • Комплектующие Комплектующие
      • Кабель, витая пара и коннекторы Кабель, витая пара и коннекторы
      • SFP-модули и кабели SFP-модули и кабели
      • CWDM CWDM
      • Питание Питание
      • Корпуса Корпуса
      • Крепления
    • Маршрутизаторы без модулей Wi-Fi
      • IPSec IPSec
      • Для улиц Для улиц
      • PoE PoE
    • Точки доступа для помещений
      • Радиомост точка — много-точка с PoE Радиомост точка — много-точка с PoE
      • Точка доступа для офиса или улицы Точка доступа для офиса или улицы
      • Радиомост точка — много-точка Радиомост точка — много-точка
      • Офисные точки доступа Офисные точки доступа
      • Мобильные точки доступа Мобильные точки доступа
    • Точки доступа для улиц
      • Wi-Fi устройства Wi-Fi устройства
      • Роутер Роутер
      • Точка доступа Wi-Fi/роутер Точка доступа Wi-Fi/роутер
      • Клиентская точка доступа Клиентская точка доступа
    • Роутеры с поддержкой LTE
    • Коммутаторы
      • CRS CRS
      • netPower netPower
    • Акции
    Каталог
    • Для дома и офиса
      Для дома и офиса
      • hEX
      • Домашнее решение
      • Роутеры
      • LTE роутеры
      • Mesh-роутер
      • Для транспорта
    • Wi-Fi оборудование
      Wi-Fi оборудование
      • hAP
      • mAP
      • RB2011
      • Маршрутизаторы
        • Для крупного офиса
        • Для провайдера
      • USB адаптеры
    • Радиосвязь WISP
      Радиосвязь WISP
    • Магистральные радиомосты
      Магистральные радиомосты
    • Сотовая связь
      Сотовая связь
    • Wi-Fi антенны
      Wi-Fi антенны
    • Программное обеспечение
      Программное обеспечение
    • Оборудование PowerLine
      Оборудование PowerLine
    • Аксессуары и комплектующие
      Аксессуары и комплектующие
      • GPON
      • Грозозащита
      • Комплектующие
      • Кабель, витая пара и коннекторы
      • SFP-модули и кабели
      • CWDM
      • Питание
      • Корпуса
      • Крепления
    • Маршрутизаторы без модулей Wi-Fi
      Маршрутизаторы без модулей Wi-Fi
      • IPSec
      • Для улиц
      • PoE
    • Точки доступа для помещений
      Точки доступа для помещений
      • Радиомост точка — много-точка с PoE
      • Точка доступа для офиса или улицы
      • Радиомост точка — много-точка
      • Офисные точки доступа
      • Мобильные точки доступа
    • Точки доступа для улиц
      Точки доступа для улиц
      • Wi-Fi устройства
      • Роутер
      • Точка доступа Wi-Fi/роутер
      • Клиентская точка доступа
    • Роутеры с поддержкой LTE
      Роутеры с поддержкой LTE
    • Коммутаторы
      Коммутаторы
      • CRS
      • netPower
    Акции
    Помощь покупателям
    • Условия оплаты
    • Условия доставки
    • Гарантия на товар
    Компания
    • О компании
    • Новости
    • Контакты
    Контакты
    +  ЕЩЕ
      Сравнение0 Отложенные 0 Корзина 0
      Mikrotik
      Сравнение0 Отложенные 0 Корзина 0
      Телефоны
      +7 (495) 320-69-22
      • Каталог
        • Назад
        • Каталог
        • Для дома и офиса
          • Назад
          • Для дома и офиса
          • hEX
          • Домашнее решение
          • Роутеры
          • LTE роутеры
          • Mesh-роутер
          • Для транспорта
        • Wi-Fi оборудование
          • Назад
          • Wi-Fi оборудование
          • hAP
          • mAP
          • RB2011
          • Маршрутизаторы
            • Назад
            • Маршрутизаторы
            • Для крупного офиса
            • Для провайдера
          • USB адаптеры
        • Радиосвязь WISP
        • Магистральные радиомосты
        • Сотовая связь
        • Wi-Fi антенны
        • Программное обеспечение
        • Оборудование PowerLine
        • Аксессуары и комплектующие
          • Назад
          • Аксессуары и комплектующие
          • GPON
          • Грозозащита
          • Комплектующие
          • Кабель, витая пара и коннекторы
          • SFP-модули и кабели
          • CWDM
          • Питание
          • Корпуса
          • Крепления
        • Маршрутизаторы без модулей Wi-Fi
          • Назад
          • Маршрутизаторы без модулей Wi-Fi
          • IPSec
          • Для улиц
          • PoE
        • Точки доступа для помещений
          • Назад
          • Точки доступа для помещений
          • Радиомост точка — много-точка с PoE
          • Точка доступа для офиса или улицы
          • Радиомост точка — много-точка
          • Офисные точки доступа
          • Мобильные точки доступа
        • Точки доступа для улиц
          • Назад
          • Точки доступа для улиц
          • Wi-Fi устройства
          • Роутер
          • Точка доступа Wi-Fi/роутер
          • Клиентская точка доступа
        • Роутеры с поддержкой LTE
        • Коммутаторы
          • Назад
          • Коммутаторы
          • CRS
          • netPower
      • Акции
      • Помощь покупателям
        • Назад
        • Помощь покупателям
        • Условия оплаты
        • Условия доставки
        • Гарантия на товар
      • Компания
        • Назад
        • Компания
        • О компании
        • Новости
        • Контакты
      • Контакты
      • Личный кабинет
      • Корзина0
      • Отложенные0
      • Сравнение товаров0
      • +7 (495) 320-69-22
      Контактная информация
      г. Москва, ул. Бакунинская, 84с21
      info@microtik.su
      • Viber
      • Viber
      • WhatsApp

      ChangeLogs

      Главная
      —
      Загрузки
      —ChangeLogs
      Загрузки ChangeLog
      • Testing release tree
      • Long-term release tree
      • Stable release tree
      • Legacy release tree
      • Development release tree
      • Release 6.48.4
      • 6.48.3
      • Changes since 6.47.8:
      • Release v6.47.10
      *) bridge - fixed external flag in the host table for wireless clients;
      *) capsman - use Bits instead of Bytes for "ap-tx-limit" and "client-tx-limit" parameters;
      *) crs3xx - fixed jumbo frame forwarding for CRS354 devices (introduced in v6.49beta36);
      *) crs3xx - fixed unknown multicast flood to CPU when IGMP snooping is used;
      *) crs3xx - improved system stability when increasing interface L2MTU for CRS318 devices;
      *) defconf - apply default configuration from branding package when performing reset with button;
      *) defconf - fixed default configuration loading on LHG R;
      *) health - fixed voltage monitor on BaseBox5 devices;
      *) ike2 - added "MS-CHAP-Domain" attribute to RADIUS requests;
      *) ike2 - added support for ASN.1 DN "my-id" value setting for initiators;
      *) ike2 - check if TS is still valid after obtaining SPI;
      *) ipsec - improved SA update by SPI;
      *) leds - fixed "/system leds" menu on RBLHG-2nD;
      *) lora - added channel plan "il-917" for Israel;
      *) lte - added support for Sharp 809SH;
      *) m33g - improved support for "/system gpio" menu ("/system routerboard upgrade" required);
      *) sfp - improved 25Gbps optical module stability and linking;
      *) snmp - added "engine-id" OID support;
      *) snmp - fixed "ipNetToMediaType" OID for incomplete entries;
      *) ssh - fixed "undo" functionality;
      *) system - improved stability when receiving bogus packets;
      *) telnet - fixed "routing-table" parameter usage;
      *) tr069-client - added support for Ethernet link speed reporting;
      *) tr069-client - added support for interface comment reporting and editing;
      *) tr069-client - added support for supout file upload;
      *) tr069-client - improved stability for download/upload diagnostics;
      *) ups - added battery info for APC Back-UPS BX750MI;
      *) w60g - general stability and performance improvements;
      *) webfig - added support for logo image from branding package;
      *) winbox - added "Cloud Backup" options under "Files" menu;
      *) winbox - added "interworking-profile" parameter under "Wireless" menu;
      *) winbox - added "name" and "file-name" parameter when importing and exporting certificates;
      *) winbox - added "sfp-shutdown-temperature" setting to SFP interfaces;
      *) winbox - added SSH settings under "IP/SSH" menu;
      *) winbox - added TFTP settings under "IP/TFTP/Settings" menu;
      *) winbox - allow setting MCS (24-31) to 4x4 Wireless interfaces;
      *) winbox - do not allow to set empty "init-string" field under "System/GPS" menu;
      *) winbox - do not show "Functionality" field for LTE interface if it is not provided;
      *) winbox - do not show "GPS antenna" selection for devices without selection support;
      *) winbox - fixed "Secondary Frequency" parameter setting under "CAPsMAN/Channel" menu;
      *) winbox - fixed "Switch" menu on RBwAPG;
      *) winbox - fixed DNS "cache-size" parameter setting;
      *) winbox - fixed order of weekdays under "IP/Firewall" menu;
      *) winbox - match "MAC Protocol-Num" predefined values under "Bridge/Filters" menu;
      *) winbox - properly show "CRL Signature" field under "System/Certificate" menu;
      *) winbox - show "System/Health" only on boards that have health monitoring;
      *) winbox - show IPv6 address in separate field under "IP/Cloud" menu;
      *) wireless - added override for multicast-to-unicast translation of DHCP traffic;
      *) wireless - added U-NII-2 support for US and Canada country profiles for hAP ac^3;

      Other changes since v6.48.3:

      *) bridge - added IGMP and MLD querier monitoring (CLI only);
      *) bridge - added IGMP snooping log when multicast table gets full;
      *) bridge - added MAC and IP source addresses information for DHCP snooping log;
      *) bridge - fixed "vlan-encap" setting for filter and NAT rules;
      *) bridge - improved system stability when disabling IGMP/MLD querier port (introduced in v6.49beta22);
      *) bridge - improved system stability when using IGMP snooping and changing bridge MAC address;
      *) chr - fixed OS provisioning on Azure;
      *) chr - improved stability when changing "flow-control" settings on interfaces with e1000 drivers;
      *) conntrack - increased total connection tracking table size based on installed RAM size;
      *) console - require "write+ftp" permissions for executing script to file;
      *) console - require "write+ftp" permissions for printing to file;
      *) crs3xx - correctly filter packets by L2MTU on 1Gbps Ethernet interfaces for CRS354 devices;
      *) crs3xx - fixed LEDs for QSFP+ interface on CRS326-24S+2Q+ device;
      *) crs3xx - fixed SFP and SFP+ link rate reporting (introduced in v6.48beta11);
      *) crs3xx - fixed interface flow control;
      *) crs3xx - fixed packet forwarding on 1Gbps Ethernet interfaces for CRS354 devices (introduced in v6.49beta44);
      *) crs3xx - improved QSFP+ linking and mode changing for CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - improved packet transmit on SFP+ interfaces;
      *) crs3xx - improved switch resource allocation for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) defconf - fixed minor typo in configuration description;
      *) defconf - removed overlapping IPv6 firewall rules;
      *) defconf - use router as DNS server for DHCP hosts;
      *) dhcpv6-server - check if pool name has changed from RADIUS on renew;
      *) dhcpv6-server - improved dynamic server entry update;
      *) dns - fixed CNAME query when target record is not in cache;
      *) firewall - fixed "ingress-priority" matcher;
      *) firewall - fixed GRE protocol packets considered invalid when PPTP helper is disabled;
      *) health - added "phy-temperature" sensor monitoring for CRS312 device;
      *) ike2 - added "MS-CHAP-Domain" attribute to RADIUS requests;
      *) ike2 - added support for ASN.1 DN "my-id" value setting for initiators;
      *) ike2 - fixed initiator packet retransmit with DDOS cookie;
      *) ipsec - improved system stability on CHR;
      *) ipsec - improved system stability on MMIPS devices;
      *) m33g - removed 12..16 pins from "/system gpio" menu;
      *) mipsbe - improved booting speed on non-NAND devices ("/system routerboard upgrade" required);
      *) netinstall - fixed lock file persistence after reinstall;
      *) netinstall - improved bootp packet handling on Linux netinstall-cli version when multiple NIC's are present;
      *) ntp - use correct IPv6 multicast group for SNTP client;
      *) package - always allow to uninstall package even if there is no free disk space left;
      *) poe - fixed PoE out functionality on CRS354 (introduced in v6.49beta22);
      *) ppp - improved stability when receiving bogus response on modem channel;
      *) rb922 - fixed miniPCI-e card detection (introduced in v6.49beta11);
      *) sfp - added "sfp-rate-select" setting (CLI only);
      *) sfp - fixed GPON module linking (introduced in v6.47);
      *) sfp - improved link stability for 10G, 25G and 40G modules on CRS309, CRS312, CRS326-24S+2Q+ CRS354 and CCR2004 devices;
      *) supout - print detailed list of active user sessions;
      *) switch - fixed (R/M)STP port blocking right before switching them in HW bridge (fixes possible packet loop when changing bridge settings);
      *) switch - improved packet transmit between CPU and 98PX1012 for CCR2004-1G-12S+2XS device;
      *) swos - fixed "static-ip-address" parameter;
      *) tr069-client - added "X_MIKROTIK_LinkDowns" parameter for interface "link-downs" value reporting;
      *) upgrade - fixed free space checking on flash type memories when installing new packages;
      *) w60g - improved stability in low temperature environments;
      *) webfig - do not show value units twice;
      *) webfig - fixed "Wireless/CAP" menu opening;
      *) webfig - fixed interface sorting by name;
      *) webfig - show only "Close" button under "Wireless/Wireless Sniffer/Sniffed Packets" menu;
      *) winbox - added "interface-speed-100G" LED type to "System/LEDs" menu;
      *) winbox - fixed health reporting on RB960, hEX, hEX S and hAP ac3 devices;
      *) winbox - fixed support for "Delegated-IPv6-Prefix" for PPP services;
      *) wireless - do not send packet back to station-bridge it was received from;
      *) wireless - fixed minor typo in debug logging messages;
      *) wireless - improve WMM priority assignment for packets with internal priority greater than 7;
      *) wireless - improve regulatory compliance with DFS requirements;
      *) wireless - improve signaling of QCA9984 interface capabilities when using 160/80+80MHz channel width;
      *) wireless - improved system stability on several 802.11ac devices (introduced in v6.49beta36);
      *) wireless - renamed "secondary-channel" to "secondary-frequency";
      *) wireless - updated "united kingdom" regulatory domain information;
      !) wireless - fixed all affecting 'FragAttacks' vulnerabilities (CVE-2020-24587, CVE-2020-24588, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147);
      *) crs3xx - fixed packet forwarding on 1Gbps Ethernet interfaces for CRS354 devices (introduced in v6.49beta44);
      *) dns - fixed CNAME query when target record is not in cache;
      *) winbox - fixed health reporting on RB960, hEX, hEX S and hAP ac3 devices;

      Other changes since v6.48.2:

      *) bridge - added IGMP and MLD querier monitoring (CLI only);
      *) bridge - added IGMP snooping log when multicast table gets full;
      *) bridge - added MAC and IP source addresses information for DHCP snooping log;
      *) bridge - fixed "vlan-encap" setting for filter and NAT rules;
      *) bridge - improved system stability when disabling IGMP/MLD querier port (introduced in v6.49beta22);
      *) bridge - improved system stability when using IGMP snooping and changing bridge MAC address;
      *) chr - fixed OS provisioning on Azure;
      *) chr - improved stability when changing "flow-control" settings on interfaces with e1000 drivers;
      *) conntrack - increased total connection tracking table size based on installed RAM size;
      *) console - require "write+ftp" permissions for executing script to file;
      *) console - require "write+ftp" permissions for printing to file;
      *) crs3xx - correctly filter packets by L2MTU on 1Gbps Ethernet interfaces for CRS354 devices;
      *) crs3xx - fixed Ethernet LEDs after reboot for CRS354 devices;
      *) crs3xx - fixed LEDs for QSFP+ interface on CRS326-24S+2Q+ device;
      *) crs3xx - fixed SFP and SFP+ link rate reporting (introduced in v6.48beta11);
      *) crs3xx - fixed VLAN priority removal for CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - fixed interface flow control;
      *) crs3xx - fixed port-isolation on bonding interfaces for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - improved LACP linking between CRS3xx series switches;
      *) crs3xx - improved QSFP+ linking and mode changing for CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - improved packet transmit on SFP+ interfaces;
      *) crs3xx - improved switch resource allocation for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - improved system stability when receiving large frames on CPU for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) defconf - fixed default configuration loading on RBOmniTikPG-5HacD;
      *) defconf - fixed minor typo in configuration description;
      *) defconf - removed overlapping IPv6 firewall rules;
      *) defconf - use router as DNS server for DHCP hosts;
      *) dhcpv6-server - check if pool name has changed from RADIUS on renew;
      *) dhcpv6-server - improved dynamic server entry update;
      *) dot1x - fixed "reject-vlan-id" for MAC authentication (introduced in v6.48);
      *) dot1x - fixed MAC authentication fallback (introduced in v6.48);
      *) firewall - fixed "ingress-priority" matcher;
      *) firewall - fixed GRE protocol packets considered invalid when PPTP helper is disabled;
      *) health - added "phy-temperature" sensor monitoring for CRS312 device;
      *) ike2 - added "MS-CHAP-Domain" attribute to RADIUS requests;
      *) ike2 - added support for ASN.1 DN "my-id" value setting for initiators;
      *) ike2 - fixed initiator packet retransmit with DDOS cookie;
      *) ipsec - fixed SA address parameter exporting;
      *) ipsec - improved system stability on CHR;
      *) ipsec - improved system stability on MMIPS devices;
      *) lte - fixed "earfcn" to band translation for "cell-monitor";
      *) m33g - removed 12..16 pins from "/system gpio" menu;
      *) mipsbe - improved booting speed on non-NAND devices ("/system routerboard upgrade" required);
      *) netinstall - fixed lock file persistence after reinstall;
      *) netinstall - improved bootp packet handling on Linux netinstall-cli version when multiple NIC's are present;
      *) ntp - use correct IPv6 multicast group for SNTP client;
      *) package - always allow to uninstall package even if there is no free disk space left;
      *) poe - fixed PoE out functionality on CRS354 (introduced in v6.49beta22);
      *) ppp - improved stability when receiving bogus response on modem channel;
      *) rb4011 - fixed SFP+ port MTU setting after link state change;
      *) rb4011 - improved SFP+ port stability after boot-up;
      *) rb922 - fixed miniPCI-e card detection (introduced in v6.49beta11);
      *) route - improved stability when connected route is modified;
      *) sfp - added "sfp-rate-select" setting (CLI only);
      *) sfp - fixed GPON module linking (introduced in v6.47);
      *) sfp - improved cable length monitoring as defined per SFF-8472 and SFF-8636;
      *) sfp - improved link stability for 10G, 25G and 40G modules on CRS309, CRS312, CRS326-24S+2Q+ CRS354 and CCR2004 devices;
      *) ssh - return proper error code from executed command;
      *) supout - print detailed list of active user sessions;
      *) switch - fixed (R/M)STP port blocking right before switching them in HW bridge (fixes possible packet loop when changing bridge settings);
      *) swos - fixed "static-ip-address" parameter;
      *) system - improved resource allocation (improves several service stability e.g. HTTPS, PPPoE, VPN);
      *) tile - fixed bridge performance degradation (introduced in v6.47);
      *) tr069-client - added "X_MIKROTIK_LinkDowns" parameter for interface "link-downs" value reporting;
      *) upgrade - fixed free space checking on flash type memories when installing new packages;
      *) w60g - improved stability in low temperature environments;
      *) webfig - do not show value units twice;
      *) webfig - fixed "PortMapping" button (introduced in v6.48.2);
      *) webfig - fixed "Wireless/CAP" menu opening;
      *) webfig - fixed interface sorting by name;
      *) webfig - show only "Close" button under "Wireless/Wireless Sniffer/Sniffed Packets" menu;
      *) winbox - added "interface-speed-100G" LED type to "System/LEDs" menu;
      *) winbox - fixed support for "Delegated-IPv6-Prefix" for PPP services;
      *) winbox - show "System/Health" only on boards that have health monitoring;
      *) wireless - do not send packet back to station-bridge it was received from;
      *) wireless - fixed issue with multicast traffic delivery to client devices using power-save;
      *) wireless - fixed minor typo in debug logging messages;
      *) wireless - improve WMM priority assignment for packets with internal priority greater than 7;
      *) wireless - improve regulatory compliance with DFS requirements;
      *) wireless - improve signaling of QCA9984 interface capabilities when using 160/80+80MHz channel width;
      *) wireless - improved system stability on several 802.11ac devices (introduced in v6.49beta36);
      *) wireless - renamed "secondary-channel" to "secondary-frequency";
      *) wireless - updated "united kingdom" regulatory domain information;
      *) www - added "X-Frame-Options" header information to disallow website embedding in other pages;
      *) bridge - fixed "vlan-encap" setting for filter and NAT rules;
      *) crs3xx - fixed Ethernet LEDs after reboot for CRS354 devices;
      *) health - added "phy-temperature" sensor monitoring for CRS312 device;
      *) ike2 - added "MS-CHAP-Domain" attribute to RADIUS requests;
      *) lte - fixed "earfcn" to band translation for "cell-monitor";
      *) switch - fixed (R/M)STP port blocking right before switching them in HW bridge (fixes possible packet loop when changing bridge settings);
      *) tile - fixed bridge performance degradation (introduced in v6.47);
      *) winbox - show "System/Health" only on boards that have health monitoring;
      *) wireless - improved system stability on several 802.11ac devices (introduced in v6.49beta36);
      *) wireless - improve signaling of QCA9984 interface capabilities when using 160/80+80MHz channel width;
      *) www - added "X-Frame-Options" header information to disallow website embedding in other pages;

      Other changes since v6.48.2:

      *) bridge - added IGMP and MLD querier monitoring (CLI only);
      *) bridge - added IGMP snooping log when multicast table gets full;
      *) bridge - added MAC and IP source addresses information for DHCP snooping log;
      *) bridge - improved system stability when disabling IGMP/MLD querier port (introduced in v6.49beta22);
      *) bridge - improved system stability when using IGMP snooping and changing bridge MAC address;
      *) chr - fixed OS provisioning on Azure;
      *) chr - improved stability when changing "flow-control" settings on interfaces with e1000 drivers;
      *) conntrack - increased total connection tracking table size based on installed RAM size;
      *) console - require "write+ftp" permissions for executing script to file;
      *) console - require "write+ftp" permissions for printing to file;
      *) crs3xx - correctly filter packets by L2MTU on 1Gbps Ethernet interfaces for CRS354 devices;
      *) crs3xx - fixed interface flow control;
      *) crs3xx - fixed LEDs for QSFP+ interface on CRS326-24S+2Q+ device;
      *) crs3xx - fixed port-isolation on bonding interfaces for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - fixed SFP and SFP+ link rate reporting (introduced in v6.48beta11);
      *) crs3xx - fixed VLAN priority removal for CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - improved LACP linking between CRS3xx series switches;
      *) crs3xx - improved packet transmit on SFP+ interfaces;
      *) crs3xx - improved QSFP+ linking and mode changing for CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - improved switch resource allocation for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - improved system stability when receiving large frames on CPU for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) defconf - fixed default configuration loading on RBOmniTikPG-5HacD;
      *) defconf - fixed minor typo in configuration description;
      *) defconf - removed overlapping IPv6 firewall rules;
      *) defconf - use router as DNS server for DHCP hosts;
      *) dhcpv6-server - check if pool name has changed from RADIUS on renew;
      *) dhcpv6-server - improved dynamic server entry update;
      *) dot1x - fixed MAC authentication fallback (introduced in v6.48);
      *) dot1x - fixed "reject-vlan-id" for MAC authentication (introduced in v6.48);
      *) firewall - fixed GRE protocol packets considered invalid when PPTP helper is disabled;
      *) firewall - fixed "ingress-priority" matcher;
      *) ike2 - added support for ASN.1 DN "my-id" value setting for initiators;
      *) ike2 - fixed initiator packet retransmit with DDOS cookie;
      *) ipsec - fixed SA address parameter exporting;
      *) ipsec - improved system stability on CHR;
      *) ipsec - improved system stability on MMIPS devices;
      *) m33g - removed 12..16 pins from "/system gpio" menu;
      *) mipsbe - improved booting speed on non-NAND devices ("/system routerboard upgrade" required);
      *) netinstall - fixed lock file persistence after reinstall;
      *) netinstall - improved bootp packet handling on Linux netinstall-cli version when multiple NIC's are present;
      *) ntp - use correct IPv6 multicast group for SNTP client;
      *) package - always allow to uninstall package even if there is no free disk space left;
      *) poe - fixed PoE out functionality on CRS354 (introduced in v6.49beta22);
      *) ppp - improved stability when receiving bogus response on modem channel;
      *) rb4011 - fixed SFP+ port MTU setting after link state change;
      *) rb922 - fixed miniPCI-e card detection (introduced in v6.49beta11);
      *) route - improved stability when connected route is modified;
      *) sfp - added "sfp-rate-select" setting (CLI only);
      *) sfp - fixed GPON module linking (introduced in v6.47);
      *) sfp - improved cable length monitoring as defined per SFF-8472 and SFF-8636;
      *) sfp - improved link stability for 10G, 25G and 40G modules on CRS309, CRS312, CRS326-24S+2Q+ CRS354 and CCR2004 devices;
      *) ssh - return proper error code from executed command;
      *) supout - print detailed list of active user sessions;
      *) switch - improved packet transmit between CPU and 98PX1012 for CCR2004-1G-12S+2XS device;
      *) swos - fixed "static-ip-address" parameter;
      *) system - improved resource allocation (improves several service stability e.g. HTTPS, PPPoE, VPN);
      *) tr069-client - added "X_MIKROTIK_LinkDowns" parameter for interface "link-downs" value reporting;
      *) upgrade - fixed free space checking on flash type memories when installing new packages;
      *) w60g - improved stability in low temperature environments;
      *) webfig - do not show value units twice;
      *) webfig - fixed interface sorting by name;
      *) webfig - fixed "PortMapping" button (introduced in v6.48.2);
      *) webfig - fixed "Wireless/CAP" menu opening;
      *) webfig - show only "Close" button under "Wireless/Wireless Sniffer/Sniffed Packets" menu;
      *) winbox - added "interface-speed-100G" LED type to "System/LEDs" menu;
      *) winbox - fixed support for "Delegated-IPv6-Prefix" for PPP services;
      *) wireless - do not send packet back to station-bridge it was received from;
      *) wireless - fixed issue with multicast traffic delivery to client devices using power-save;
      *) wireless - fixed minor typo in debug logging messages;
      *) wireless - improve regulatory compliance with DFS requirements;
      *) wireless - improve WMM priority assignment for packets with internal priority greater than 7;
      *) wireless - renamed "secondary-channel" to "secondary-frequency";
      *) wireless - updated "united kingdom" regulatory domain information;
      *) system - improved resource allocation (improves several service stability e.g. HTTPS, PPPoE, VPN);

      Other changes since v6.48.2:

      *) bridge - added IGMP and MLD querier monitoring (CLI only);
      *) bridge - added IGMP snooping log when multicast table gets full;
      *) bridge - added MAC and IP source addresses information for DHCP snooping log;
      *) bridge - improved system stability when disabling IGMP/MLD querier port (introduced in v6.49beta22);
      *) bridge - improved system stability when using IGMP snooping and changing bridge MAC address;
      *) chr - fixed OS provisioning on Azure;
      *) chr - improved stability when changing "flow-control" settings on interfaces with e1000 drivers;
      *) conntrack - increased total connection tracking table size based on installed RAM size;
      *) console - require "write+ftp" permissions for executing script to file;
      *) console - require "write+ftp" permissions for printing to file;
      *) crs3xx - correctly filter packets by L2MTU on 1Gbps Ethernet interfaces for CRS354 devices;
      *) crs3xx - fixed LEDs for QSFP+ interface on CRS326-24S+2Q+ device;
      *) crs3xx - fixed SFP and SFP+ link rate reporting (introduced in v6.48beta11);
      *) crs3xx - fixed VLAN priority removal for CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - fixed interface flow control;
      *) crs3xx - fixed port-isolation on bonding interfaces for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - improved LACP linking between CRS3xx series switches;
      *) crs3xx - improved QSFP+ linking and mode changing for CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - improved packet transmit on SFP+ interfaces;
      *) crs3xx - improved switch resource allocation for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - improved system stability when receiving large frames on CPU for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) defconf - fixed default configuration loading on RBOmniTikPG-5HacD;
      *) defconf - fixed minor typo in configuration description;
      *) defconf - removed overlapping IPv6 firewall rules;
      *) defconf - use router as DNS server for DHCP hosts;
      *) dhcpv6-server - check if pool name has changed from RADIUS on renew;
      *) dhcpv6-server - improved dynamic server entry update;
      *) dot1x - fixed "reject-vlan-id" for MAC authentication (introduced in v6.48);
      *) dot1x - fixed MAC authentication fallback (introduced in v6.48);
      *) firewall - fixed "ingress-priority" matcher;
      *) firewall - fixed GRE protocol packets considered invalid when PPTP helper is disabled;
      *) ike2 - added support for ASN.1 DN "my-id" value setting for initiators;
      *) ike2 - fixed initiator packet retransmit with DDOS cookie;
      *) ipsec - fixed SA address parameter exporting;
      *) ipsec - improved system stability on CHR;
      *) ipsec - improved system stability on MMIPS devices;
      *) m33g - removed 12..16 pins from "/system gpio" menu;
      *) mipsbe - improved booting speed on non-NAND devices ("/system routerboard upgrade" required);
      *) netinstall - fixed lock file persistence after reinstall;
      *) netinstall - improved bootp packet handling on Linux netinstall-cli version when multiple NIC's are present;
      *) ntp - use correct IPv6 multicast group for SNTP client;
      *) package - always allow to uninstall package even if there is no free disk space left;
      *) poe - fixed PoE out functionality on CRS354 (introduced in v6.49beta22);
      *) ppp - improved stability when receiving bogus response on modem channel;
      *) rb4011 - fixed SFP+ port MTU setting after link state change;
      *) rb4011 - improved SFP+ port stability after boot-up;
      *) rb922 - fixed miniPCI-e card detection (introduced in v6.49beta11);
      *) route - improved stability when connected route is modified;
      *) sfp - added "sfp-rate-select" setting (CLI only);
      *) sfp - fixed GPON module linking (introduced in v6.47);
      *) sfp - improved cable length monitoring as defined per SFF-8472 and SFF-8636;
      *) sfp - improved link stability for 10G, 25G and 40G modules on CRS309, CRS312, CRS326-24S+2Q+ CRS354 and CCR2004 devices;
      *) ssh - return proper error code from executed command;
      *) supout - print detailed list of active user sessions;
      *) switch - improved packet transmit between CPU and 98PX1012 for CCR2004-1G-12S+2XS device;
      *) swos - fixed "static-ip-address" parameter;
      *) tr069-client - added "X_MIKROTIK_LinkDowns" parameter for interface "link-downs" value reporting;
      *) upgrade - fixed free space checking on flash type memories when installing new packages;
      *) w60g - improved stability in low temperature environments;
      *) webfig - do not show value units twice;
      *) webfig - fixed "PortMapping" button (introduced in v6.48.2);
      *) webfig - fixed "Wireless/CAP" menu opening;
      *) webfig - fixed interface sorting by name;
      *) webfig - show only "Close" button under "Wireless/Wireless Sniffer/Sniffed Packets" menu;
      *) winbox - added "interface-speed-100G" LED type to "System/LEDs" menu;
      *) winbox - fixed support for "Delegated-IPv6-Prefix" for PPP services;
      *) wireless - do not send packet back to station-bridge it was received from;
      *) wireless - fixed issue with multicast traffic delivery to client devices using power-save;
      *) wireless - fixed minor typo in debug logging messages;
      *) wireless - improve WMM priority assignment for packets with internal priority greater than 7;
      *) wireless - improve regulatory compliance with DFS requirements;
      *) wireless - renamed "secondary-channel" to "secondary-frequency";
      *) wireless - updated "united kingdom" regulatory domain information;
      *) chr - improved stability when changing "flow-control" settings on interfaces with e1000 drivers;
      *) crs312 - fixed missing SwOS firmware on revision 2 devices;
      *) crs3xx - fixed packet duplication when multiple bonding interfaces are created for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - fixed packet transmit in 5Gbps link rate for CRS312 device;
      *) crs3xx - fixed port-isolation on bonding interfaces for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - fixed port-isolation on ether37-ether48 ports for CRS354 device;
      *) crs3xx - improved LACP linking between CRS3xx series switches;
      *) crs3xx - improved QSFP+ linking and mode changing for CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - improved load balancing on bonding interfaces for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - improved packet transmit on SFP+ interfaces;
      *) crs3xx - improved system stability when bonding and IGMP snooping is used (introduced in v6.48);
      *) defconf - fixed minor typo in configuration description;
      *) dot1x - fixed "reject-vlan-id" for MAC authentication (introduced in v6.48);
      *) dot1x - fixed MAC authentication fallback (introduced in v6.48);
      *) ethernet - fixed cable-test for some devices (e.g. RB2011, RB951G-2HnD);
      *) fastpath - fixed IP packet receive on bridge and bonding interfaces when destination MAC address match with slave port MAC;
      *) hotspot - fixed "idle-timeout" usage with RADIUS authentication;
      *) hotspot - fixed special character parsing in "target" variable (CVE-2021-3014);
      *) ike2 - added support for ASN.1 DN "my-id" value setting for initiators;
      *) ike2 - fixed EAP MSK length validation (introduced in v6.48);
      *) ike2 - fixed phase 2 rekeying with enabled PFS (introduced in v6.48);
      *) ike2 - improved stability when invalid certificate is configured (introduced in v6.48);
      *) ike2 - properly register packet time after expensive CPU operations;
      *) interface - fixed pwr-line interface linking (introduced in v6.48);
      *) ipsec - improved stability when processing IPv6 packets larger than interface MTU;
      *) led - fixed default LED configuration for RB911-5HnD;
      *) netinstall - improved bootp packet handling on Linux netinstall-cli version when multiple NIC's are present;
      *) ntp - use correct IPv6 multicast group for SNTP client;
      *) package - always allow to uninstall package even if there is no free disk space left;
      *) package - do not include multiple The Dude packages in HDD installer;
      *) sfp - added "sfp-rate-select" setting (CLI only);
      *) sfp - fixed GPON module linking (introduced in v6.47);
      *) sfp - improved cable length monitoring as defined per SFF-8472 and SFF-8636;
      *) snmp - fixed "send-trap" functionality (introduced in v6.48);
      *) snmp - fixed SNMP trap agent address;
      *) switch - fixed interface toggling for devices with multiple QCA8337, Atheros8327 or RTL8367 switch chips (introduced in v6.48);
      *) switch - improved packet transmit between CPU and 98PX1012 for CCR2004-1G-12S+2XS device;
      *) tr069-client - added "X_MIKROTIK_LinkDowns" parameter for interface "link-downs" value reporting;
      *) upgrade - fixed free space checking on flash type memories when installing new packages;
      *) webfig - fixed new interface addition;
      *) winbox - do not show empty "CPU Frequency" parameter under "System/Resources" menu;
      *) winbox - fixed enable/disable button presence for "Bridge/Hosts" menu;
      *) winbox - renamed IP protocol 41 to "ipv6-encap";
      *) wireless - renamed "macedonia" regulatory domain information to "north macedonia";
      What's new in 6.48rc1 (2020-Dec-11 12:38):

      Changes in this release:

      *) arm - improved system stability;
      *) bgp - fixed VPNV4 RD byte order;
      *) bonding - added LACP monitoring;
      *) branding - fixed LCD logo loading from new style branding package;
      *) bridge - added "multicast-router" monitoring value for bridge interface (CLI only);
      *) bridge - added fixes and improvements for IGMP and MLD snooping;
      *) bridge - fixed "multicast-router" setting on bridge enable;
      *) capsman - fixed authentication when using CAPsMAN forwarding (introduced in v6.48beta48);
      *) certificate - properly flush expired SCEP OTP entries;
      *) chr - fixed VLAN tagged packet transmit on bridge for Hyper-V installations;
      *) crs3xx - added initial Bridge Port Extender support;
      *) crs3xx - fixed "switch-cpu" VLAN membership on bridge disable;
      *) crs3xx - fixed "tag-stacking" for CRS305, CRS318, CRS326-24G-2S+ and CRS328 devices (introduced in v6.48beta58);
      *) crs3xx - fixed bridge "port-extender" for CRS318 devices;
      *) crs3xx - fixed ingress rate policer for CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (introduced in v6.48beta35);
      *) discovery - added "lldp-med-net-policy-vlan" property for assigning VLAN ID;
      *) ethernet - fixed IP connectivity on SFP/SFP+ interfaces for CCR2004-1G-12S+2XS device (introduced in v6.48beta58);
      *) ike1 - fixed 'rsa-signature-hybrid' authentication method;
      *) ike1 - fixed memory leak on multiple CR payloads;
      *) ipsec - added SHA384 hash algorithm support for phase 1;
      *) lte - increased "at+cops" reply timeout to 90 seconds;
      *) profile - added "lcd" process classificator;
      *) tr069-client - fixed TotalBytesReceived parameter value;
      *) winbox - added "src-mac-address" parameter under "IP/DHCP-Server/Leases" menu;
      *) winbox - added missing IGMP Snooping settings to "Bridge" menu;
      *) winbox - added missing MSTP settings to "Bridge" menu;
      *) winbox - added support for LTE Cell Monitor;
      *) wireless - increased "group-key-update" maximum value to 1 day;
      *) wireless - updated "indonesia5" regulatory domain information;

      Other changes since v6.47.8:

      *) arm - added support for automatic CPU frequency stepping for IPQ4018/IPQ4019 devices;
      *) arm - improved watchdog and kernel panic reporting in log after reboots on IPQ4018/IPQ4019 devices;
      *) arm64 - improved reboot reason reporting in log;
      *) bonding - added LACP monitoring;
      *) bonding - removed "sys-id" and "sys-priority" from monitor-slaves command;
      *) bridge - added minor fixes and improvements for IGMP snooping with HW offloading;
      *) bridge - added warning message when port is disabled by the BPDU guard;
      *) bridge - allow to exclude interfaces from extended ports (CLI only);
      *) bridge - automatically remove extended interfaces when deleting PE device from CB;
      *) bridge - correctly remove dynamic VLAN assignment for bridge ports;
      *) bridge - fixed MDB entry removal when using bridge port "fast-leave" property;
      *) bridge - fixed dynamic VLAN assignment when changing port "frame-type" property (introduced in v6.46);
      *) bridge - fixed dynamic VLAN assignment when changing port to tagged VLAN member;
      *) bridge - fixed link-local multicast forwarding when IGMP snooping and HW offloading is enabled;
      *) bridge - fixed local MAC address removal from host table when deleting bridge interface;
      *) bridge - fixed multicast table printing;
      *) bridge - fixed packet forwarding for CAP and BCP controlled interfaces (introduced in v6.48beta12);
      *) bridge - improved BPDU guard logging;
      *) bridge - increased multicast table size to 4K entries;
      *) bridge - show "H" flag for extended bridge ports;
      *) bridge - show error when switch do not support controlling bridge or port extension (CLI only);
      *) bridge - use "frame-types=admit-all" by default for extended bridge ports;
      *) cap - fixed L2MTU setting from CAPsMAN;
      *) certificate - clear challenge password on renew;
      *) certificate - fixed CRL URL length limit;
      *) certificate - fixed private key verification for CA certificate during signing process;
      *) certificate - generate CRL even when CRL URL not specified;
      *) certificate - properly flush expired SCEP OTP entries;
      *) chr - fixed SSH key import on Azure;
      *) chr - improved interface loading on startup on XEN;
      *) chr - improved system stability when changing flow control settings on e1000;
      *) cloud - improved backup generation process;
      *) conntrack - automatically reduce connection tracking timeouts when table is full;
      *) console - allow "once" parameter for bonding monitoring;
      *) crs3xx - added initial Bridge Port Extender support (CLI only);
      *) crs3xx - added initial Controlling Bridge support for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (CLI only);
      *) crs3xx - added switch-cpu port VLAN filtering (switch-cpu port is now mapped with bridge interface VLAN membership when vlan-filtering is enabled);
      *) crs3xx - fixed "custom-drop-packet" and "not-learned" switch stats for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - fixed "mirror-source" property on switch port disable for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices;
      *) crs3xx - fixed "storm-rate" traffic limiting for switch-cpu port on CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - fixed CDP packet forwarding for CRS305, CRS318, CRS326-24G-2S+, CRS328 devices;
      *) crs3xx - fixed VLAN tagged packet forwarding on "switch-cpu" port for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices (introduced in v6.48beta12);
      *) crs3xx - fixed booting issues on CRS354 devices (introduced in v6.48beta48);
      *) crs3xx - fixed bridge port-extender for CRS318 devices;
      *) crs3xx - fixed duplicate host entries when creating static switch hosts;
      *) crs3xx - fixed port isolation for "switch-cpu" port for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices;
      *) crs3xx - fixed port isolation removal for "switch-cpu" port on CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - fixed port-isolation for CRS305, CRS318, CRS326-24G-2S+, CRS328 devices (introduced in v6.48beta35);
      *) crs3xx - fixed switch "copy-to-cpu" property for CRS305, CRS318, CRS326-24G-2S+, CRS328 devices;
      *) crs3xx - fixed switch "not-learned" stats for CRS305, CRS326-24G-2S+, CRS328-24P-4S+, CRS328-4C-20S-4S+, CRS318 devices;
      *) crs3xx - fixed switch-cpu VLAN membership removal (introduced in v6.48beta40);
      *) crs3xx - improved system stability on CRS354 devices;
      *) defconf - fixed default configuration loading on RBcAP-2nD and RBwAP-2nD;
      *) defconf - fixed static IP address setting in case default configuration loading fails;
      *) defconf - improved CAP interface bridging;
      *) defconf - improved default configuration generation on devices with non-default wireless interface names;
      *) detnet - fixed malformed dummy DHCP User Class option;
      *) detnet - use MAC address from bridge interface instead of slave port;
      *) dhcp - fixed DHCP packet forwarding to IPsec policies;
      *) dhcpv4-server - improved "client-id" value parsing;
      *) dhcpv6 server - added support for "Delegated-IPv6-Prefix" for PPP services;
      *) dhcpv6-server - added ability to generate binding on first request;
      *) dhcpv6-server - added support for "option18" and "option37" for RADIUS managed clients;
      *) dhcpv6-server - allow loose static binding "pool" parameter (introduced in v6.46.8);
      *) dhcpv6-server - make sure that calling station ID always contains DUID;
      *) discovery - added "lldp-med-net-policy-vlan" property for assigning VLAN ID;
      *) discovery - allow choosing which discovery protocol is used;
      *) discovery - fixed discovery on mesh ports;
      *) discovery - fixed discovery packet sending on newly bridged port with "protocol-mode=none";
      *) discovery - fixed discovery when enabled only on master port;
      *) discovery - fixed occasional wrong Chassis-ID for LLDP packets (introduced in v6.48beta35);
      *) discovery - send the same "Chassis ID" on all interfaces for LLDP packets;
      *) discovery - use interface MAC address when sending MNDP from slave port;
      *) disk - fixed external EXT3 disk mounting on x86 systems;
      *) dns - added IPv6 support for DoH;
      *) dns - do not use type "A" for static entries with unspecified type;
      *) dns - end ongoing queries when changing DoH configuration;
      *) dns - fixed listening for DNS queries when only dynamic static entries exist (introduced in v6.47);
      *) dot1x - accept priority tagged (VLAN 0) EAP packets on dot1x client;
      *) dot1x - fixed reauthentication after server rejects a client into VLAN;
      *) dot1x - fixed unicast destination EAP packet receiving when a client is running on a bridge port;
      *) dude - fixed configuration menu presence on ARM64 devices;
      *) export - fixed RouterBOARD USB "type" parameter export;
      *) filesystem - fixed repartition on RB4011 series devices;
      *) filesystem - fixed repartition on non-first partition;
      *) filesystem - improved long-term filesystem stability and data integrity;
      *) gps - fixed "init-channel" release when not used;
      *) health - changed PSU state parameter type to read-only;
      *) health - removed unused "heater-control" and "heater-threshold" parameters;
      *) hotspot - added "vlan-id" parameter support for hosts and HTML pages;
      *) hotspot - added support for captive portal advertising using DHCP (RFC7710);
      *) hotspot - fixed "html-directory" parameter export;
      *) hotspot - improved management service stability when receiving bogus packets;
      *) ike1 - fixed "my-id=address" parameter usage together with certificate authentication;
      *) ike1 - fixed policy update with and without mode configuration;
      *) ike1 - rekey phase 1 as responder for Windows initiators;
      *) ike2 - added "prf-algorithm" support for phase 1;
      *) ike2 - added support for IKEv2 Message Fragmentation (RFC7383);
      *) ike2 - fixed EAP MSK length validation;
      *) ike2 - fixed too small payload parsing;
      *) ike2 - improved EAP message integrity checking;
      *) ike2 - improved child SA rekeying process;
      *) interface - added temperature warning and interface disable on overheat for SFP and SFP+ interfaces (CLI only);
      *) interface - fixed pwr-line running state (introduced in v6.45);
      *) ipsec - added SHA384 hash algorithm support for phase 1 (CLI only);
      *) ipsec - do not kill connection when peer's "name" or "comment" is changed;
      *) ipsec - fixed client certificate usage when certificate is renewed with SCEP;
      *) ipsec - fixed multiple warning message display for peers;
      *) ipsec - inactivate peer's policy on disconnect;
      *) ipsec - refresh peer's DNS only when phase 1 is down;
      *) kidcontrol - allow creating static device entries without assigned user;
      *) led - fixed state persistence after device reboot on NetMetal 5 ac devices;
      *) lora - fixed device going into "ERROR" state caused by FSK modulated downlinks;
      *) lora - limited output power in RU region for range 868.7 MHz - 869.2 MHz according to regulations;
      *) lte - added "age" column and "max-age" parameter to "cell-monitor" (CLI only);
      *) lte - added "comment" parameter for APN profiles;
      *) lte - added support for Alcatel IK41VE1;
      *) lte - fixed "band" value reporting;
      *) lte - increased "at+cops" reply timeout to 1 minute;
      *) m33g - added support for "/system gpio" menu (CLI only);
      *) metarouter - allow creating RouterOS metarouter instances on devices with 16MB flash storage;
      *) metarouter - fixed memory leak when tearing down metarouter instance;
      *) ppp - added "bridge-learning" parameter support;
      *) ppp - added "ipv6-routes" parameter to "secrets" menu;
      *) ppp - added support for "Framed-IPv6-Route" RADIUS attribute;
      *) ppp - store "last-caller-id" for PPP secrets;
      *) ppp - store "last-disconnect-reason" for PPP secrets;
      *) profile - improved idle process detection on x86 processors;
      *) profile - improved process classification on ARM devices;
      *) quickset - added "Port Mapping" to QuickSet;
      *) quickset - fixed local IP address setting on master interface;
      *) route - improved stability when 6to4 interface is configured with disabled IPv6 package;
      *) routerboard - fixed PCIe bus reset during power-on on MMIPS devices ("/system routerboard upgrade" required);
      *) routerboard - force power-down on PCIe bus during reboot on LHGR devices ("/system routerboard upgrade" required);
      *) script - added error message in the logs if startup script runtime limit was exceeded;
      *) snmp - added information from IPsec "active-peers" menu to MIKROTIK-MIB;
      *) snmp - added new LTE monitoring OID's to MIKROTIK-MIB;
      *) snmp - fixed value types for "dot1dStp";
      *) snmp - fixed value types for "dot1qPvid";
      *) ssh - fixed returned output saving to file when "output-to-file" parameter is used;
      *) ssh - skip interactive authentication when not running in interactive mode;
      *) supout - added bonding interface monitor information;
      *) supout - improved autosupout.rif file generation process;
      *) timezone - updated timezone information from "tzdata2020d" release;
      *) tr069-client - added "X_MIKROTIK_MimoRSRP" parameter for LTE RSRP value reporting;
      *) tr069-client - added LTE model and revision parameters;
      *) tr069-client - added additional wireless registration table parameters;
      *) tr069-client - added branding package version parameter;
      *) tr069-client - added wireless "noise-floor" and "overall-tx-ccq" information parameters;
      *) tr069-client - allow passing LTE firmware update URL as XML;
      *) tr069-client - fixed RouterOS downgrade procedure;
      *) tr069-client - send correct "ConnectionRequestURL" when using IPv6;
      *) traffic-flow - added "sys-init-time" parameter support;
      *) traffic-flow - added NAT event logging support for IPFIX;
      *) traffic-generator - fixed 32Gbps limitation;
      *) user-manager - do not allow creating limitation that crosses midnight;
      *) user-manager - updated PayPal's root certificate authorities;
      *) webfig - allow hiding QuickSet mode selector;
      *) webfig - allow hiding and renaming inline buttons;
      *) webfig - fixed default value presence when creating new entries under "IP->Kid Control";
      *) webfig - properly stop background processes when switching away from QuickSet tab;
      *) winbox - allow adding bonding interface with one slave interface;
      *) winbox - allow performing "USB Power Reset" on "0" bus on RBM33G;
      *) winbox - do not show "network-mode" parameter for LTE interfaces that do not support it;
      *) winbox - fixed "IP->Kid Control->Devices" table automatic refreshing;
      *) winbox - fixed "interface" and "on-interface" parameter presence under "Bridge/Hosts" menu;
      *) winbox - fixed "receive-errors" setting persistence under "Wireless/Wireless Sniffer/Settings" menu;
      *) winbox - fixed "tls-version" parameter setting under "IP/Services" menu;
      *) winbox - fixed minor typo in "Users" menu;
      *) winbox - provide sane default values for bridge "VLAN IDs" parameter;
      *) winbox - use health values reported by gauges for "System/Health" menu;
      *) wireless - added U-NII-2 support for US and Canada country profiles for mANTBox series devices;
      *) wireless - create "connect-list" rule when address specified for "setup-repeater";
      *) wireless - do not override MTU and ARP values from CAPsMAN with local forwarding;
      *) wireless - improved WPS process stability;
      *) wireless - increased "group-key-update" maximum value to 1 day;
      *) wireless - updated "no_country_set" regulatory domain information;
      *) arm - improved system stability; *) bgp - fixed VPNV4 RD byte order; *) bonding - added LACP monitoring; *) branding - fixed LCD logo loading from new style branding package; *) bridge - added "multicast-router" monitoring value for bridge interface (CLI only); *) bridge - added fixes and improvements for IGMP and MLD snooping; *) bridge - fixed "multicast-router" setting on bridge enable; *) capsman - fixed authentication when using CAPsMAN forwarding (introduced in v6.48beta48); *) certificate - properly flush expired SCEP OTP entries; *) chr - fixed VLAN tagged packet transmit on bridge for Hyper-V installations; *) crs3xx - added initial Bridge Port Extender support; *) crs3xx - fixed "switch-cpu" VLAN membership on bridge disable; *) crs3xx - fixed "tag-stacking" for CRS305, CRS318, CRS326-24G-2S+ and CRS328 devices (introduced in v6.48beta58); *) crs3xx - fixed bridge "port-extender" for CRS318 devices; *) crs3xx - fixed ingress rate policer for CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (introduced in v6.48beta35); *) discovery - added "lldp-med-net-policy-vlan" property for assigning VLAN ID; *) ethernet - fixed IP connectivity on SFP/SFP+ interfaces for CCR2004-1G-12S+2XS device (introduced in v6.48beta58); *) ike1 - fixed 'rsa-signature-hybrid' authentication method; *) ike1 - fixed memory leak on multiple CR payloads; *) ipsec - added SHA384 hash algorithm support for phase 1; *) lte - increased "at+cops" reply timeout to 90 seconds; *) profile - added "lcd" process classificator; *) tr069-client - fixed TotalBytesReceived parameter value; *) winbox - added "src-mac-address" parameter under "IP/DHCP-Server/Leases" menu; *) winbox - added missing IGMP Snooping settings to "Bridge" menu; *) winbox - added missing MSTP settings to "Bridge" menu; *) winbox - added support for LTE Cell Monitor; *) wireless - increased "group-key-update" maximum value to 1 day; *) wireless - updated "indonesia5" regulatory domain information; Other changes since v6.47.8: *) arm - added support for automatic CPU frequency stepping for IPQ4018/IPQ4019 devices; *) arm - improved watchdog and kernel panic reporting in log after reboots on IPQ4018/IPQ4019 devices; *) arm64 - improved reboot reason reporting in log; *) bonding - added LACP monitoring; *) bonding - removed "sys-id" and "sys-priority" from monitor-slaves command; *) bridge - added minor fixes and improvements for IGMP snooping with HW offloading; *) bridge - added warning message when port is disabled by the BPDU guard; *) bridge - allow to exclude interfaces from extended ports (CLI only); *) bridge - automatically remove extended interfaces when deleting PE device from CB; *) bridge - correctly remove dynamic VLAN assignment for bridge ports; *) bridge - fixed MDB entry removal when using bridge port "fast-leave" property; *) bridge - fixed dynamic VLAN assignment when changing port "frame-type" property (introduced in v6.46); *) bridge - fixed dynamic VLAN assignment when changing port to tagged VLAN member; *) bridge - fixed link-local multicast forwarding when IGMP snooping and HW offloading is enabled; *) bridge - fixed local MAC address removal from host table when deleting bridge interface; ) bridge - fixed packet forwarding for CAP and BCP controlled interfaces (introduced in v6.48beta12); *) bridge - improved BPDU guard logging; *) bridge - increased multicast table size to 4K entries; *) bridge - show "H" flag for extended bridge ports; *) bridge - show error when switch do not support controlling bridge or port extension (CLI only); *) bridge - use "frame-types=admit-all" by default for extended bridge ports; *) cap - fixed L2MTU setting from CAPsMAN; *) certificate - clear challenge password on renew; *) certificate - fixed CRL URL length limit; *) certificate - fixed private key verification for CA certificate during signing process; *) certificate - generate CRL even when CRL URL not specified; *) certificate - properly flush expired SCEP OTP entries; *) chr - fixed SSH key import on Azure; *) chr - improved interface loading on startup on XEN; *) chr - improved system stability when changing flow control settings on e1000; *) cloud - improved backup generation process; *) conntrack - automatically reduce connection tracking timeouts when table is full; *) console - allow "once" parameter for bonding monitoring; *) crs3xx - added initial Bridge Port Extender support (CLI only); *) crs3xx - added initial Controlling Bridge support for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (CLI only); *) crs3xx - added switch-cpu port VLAN filtering (switch-cpu port is now mapped with bridge interface VLAN membership when vlan-filtering is enabled); *) crs3xx - fixed "custom-drop-packet" and "not-learned" switch stats for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed "mirror-source" property on switch port disable for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices; *) crs3xx - fixed "storm-rate" traffic limiting for switch-cpu port on CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed CDP packet forwarding for CRS305, CRS318, CRS326-24G-2S+, CRS328 devices; *) crs3xx - fixed VLAN tagged packet forwarding on "switch-cpu" port for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices (introduced in v6.48beta12); *) crs3xx - fixed bridge port-extender for CRS318 devices; *) crs3xx - fixed duplicate host entries when creating static switch hosts; *) crs3xx - fixed port isolation for "switch-cpu" port for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices; *) crs3xx - fixed port isolation removal for "switch-cpu" port on CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed port-isolation for CRS305, CRS318, CRS326-24G-2S+, CRS328 devices (introduced in v6.48beta35); *) crs3xx - fixed switch "copy-to-cpu" property for CRS305, CRS318, CRS326-24G-2S+, CRS328 devices; *) crs3xx - fixed switch "not-learned" stats for CRS305, CRS326-24G-2S+, CRS328-24P-4S+, CRS328-4C-20S-4S+, CRS318 devices; *) crs3xx - fixed switch-cpu VLAN membership removal (introduced in v6.48beta40); *) crs3xx - improved system stability on CRS354 devices; *) defconf - fixed default configuration loading on RBcAP-2nD and RBwAP-2nD; *) defconf - fixed static IP address setting in case default configuration loading fails; *) defconf - improved CAP interface bridging; *) defconf - improved default configuration generation on devices with non-default wireless interface names; *) detnet - fixed malformed dummy DHCP User Class option; *) detnet - use MAC address from bridge interface instead of slave port; *) dhcp - fixed DHCP packet forwarding to IPsec policies; *) dhcpv4-server - improved "client-id" value parsing; *) dhcpv6 server - added support for "Delegated-IPv6-Prefix" for PPP services; *) dhcpv6-server - added ability to generate binding on first request; *) dhcpv6-server - added support for "option18" and "option37" for RADIUS managed clients; *) dhcpv6-server - allow loose static binding "pool" parameter (introduced in v6.46.8); *) dhcpv6-server - make sure that calling station ID always contains DUID; *) discovery - added "lldp-med-net-policy-vlan" property for assigning VLAN ID; *) discovery - allow choosing which discovery protocol is used; *) discovery - fixed discovery on mesh ports; *) discovery - fixed discovery packet sending on newly bridged port with "protocol-mode=none"; *) discovery - fixed discovery when enabled only on master port; *) discovery - fixed occasional wrong Chassis-ID for LLDP packets (introduced in v6.48beta35); *) discovery - send the same "Chassis ID" on all interfaces for LLDP packets; *) discovery - use interface MAC address when sending MNDP from slave port; *) disk - fixed external EXT3 disk mounting on x86 systems; *) dns - added IPv6 support for DoH; *) dns - do not use type "A" for static entries with unspecified type; *) dns - end ongoing queries when changing DoH configuration; *) dns - fixed listening for DNS queries when only dynamic static entries exist (introduced in v6.47); *) dot1x - fixed reauthentication after server rejects a client into VLAN; *) dot1x - fixed unicast destination EAP packet receiving when a client is running on a bridge port; *) dude - fixed configuration menu presence on ARM64 devices; *) export - fixed RouterBOARD USB "type" parameter export; *) filesystem - fixed repartition on RB4011 series devices; *) filesystem - fixed repartition on non-first partition; *) filesystem - improved long-term filesystem stability and data integrity; *) gps - fixed "init-channel" release when not used; *) health - changed PSU state parameter type to read-only; *) health - removed unused "heater-control" and "heater-threshold" parameters; *) hotspot - added "vlan-id" parameter support for hosts and HTML pages; *) hotspot - added support for captive portal advertising using DHCP (RFC7710); *) hotspot - fixed "html-directory" parameter export; *) hotspot - improved management service stability when receiving bogus packets; *) ike1 - fixed "my-id=address" parameter usage together with certificate authentication; *) ike1 - fixed policy update with and without mode configuration; *) ike1 - rekey phase 1 as responder for Windows initiators; *) ike2 - added "prf-algorithm" support for phase 1; *) ike2 - added support for IKEv2 Message Fragmentation (RFC7383); *) ike2 - fixed EAP MSK length validation; *) ike2 - fixed too small payload parsing; *) ike2 - improved EAP message integrity checking; *) ike2 - improved child SA rekeying process; *) interface - added temperature warning and interface disable on overheat for SFP and SFP+ interfaces (CLI only); *) interface - fixed pwr-line running state (introduced in v6.45); *) ipsec - added SHA384 hash algorithm support for phase 1 (CLI only); *) ipsec - do not kill connection when peer's "name" or "comment" is changed; *) ipsec - fixed client certificate usage when certificate is renewed with SCEP; *) ipsec - fixed multiple warning message display for peers; *) ipsec - inactivate peer's policy on disconnect; *) ipsec - refresh peer's DNS only when phase 1 is down; *) kidcontrol - allow creating static device entries without assigned user; *) led - fixed state persistence after device reboot on NetMetal 5 ac devices; *) lora - fixed device going into "ERROR" state caused by FSK modulated downlinks; *) lora - limited output power in RU region for range 868.7 MHz - 869.2 MHz according to regulations; *) lte - added "age" column and "max-age" parameter to "cell-monitor" (CLI only); *) lte - added "comment" parameter for APN profiles; *) lte - added support for Alcatel IK41VE1; *) lte - fixed "band" value reporting; *) lte - increased "at+cops" reply timeout to 1 minute; *) m33g - added support for "/system gpio" menu (CLI only); *) metarouter - allow creating RouterOS metarouter instances on devices with 16MB flash storage; *) metarouter - fixed memory leak when tearing down metarouter instance; *) ppp - added "bridge-learning" parameter support; *) ppp - added "ipv6-routes" parameter to "secrets" menu; *) ppp - added support for "Framed-IPv6-Route" RADIUS attribute; *) ppp - store "last-caller-id" for PPP secrets; *) ppp - store "last-disconnect-reason" for PPP secrets; *) profile - improved idle process detection on x86 processors; *) profile - improved process classification on ARM devices; *) quickset - added "Port Mapping" to QuickSet; *) quickset - fixed local IP address setting on master interface; *) route - improved stability when 6to4 interface is configured with disabled IPv6 package; *) routerboard - fixed PCIe bus reset during power-on on MMIPS devices ("/system routerboard upgrade" required); *) routerboard - force power-down on PCIe bus during reboot on LHGR devices ("/system routerboard upgrade" required); *) script - added error message in the logs if startup script runtime limit was exceeded; *) snmp - added information from IPsec "active-peers" menu to MIKROTIK-MIB; *) snmp - added new LTE monitoring OID's to MIKROTIK-MIB; *) snmp - fixed value types for "dot1dStp"; *) snmp - fixed value types for "dot1qPvid"; *) ssh - fixed returned output saving to file when "output-to-file" parameter is used; *) ssh - skip interactive authentication when not running in interactive mode; *) supout - added bonding interface monitor information; *) supout - improved autosupout.rif file generation process; *) timezone - updated timezone information from "tzdata2020d" release; *) tr069-client - added "X_MIKROTIK_MimoRSRP" parameter for LTE RSRP value reporting; *) tr069-client - added LTE model and revision parameters; *) tr069-client - added additional wireless registration table parameters; *) tr069-client - added branding package version parameter; *) tr069-client - added wireless "noise-floor" and "overall-tx-ccq" information parameters; *) tr069-client - allow passing LTE firmware update URL as XML; *) tr069-client - fixed RouterOS downgrade procedure; *) traffic-flow - added "sys-init-time" parameter support; *) traffic-flow - added NAT event logging support for IPFIX; *) traffic-generator - fixed 32Gbps limitation; *) user-manager - do not allow creating limitation that crosses midnight; *) user-manager - updated PayPal's root certificate authorities; *) webfig - allow hiding QuickSet mode selector; *) webfig - allow hiding and renaming inline buttons; *) webfig - fixed default value presence when creating new entries under "IP->Kid Control"; *) webfig - properly stop background processes when switching away from QuickSet tab; *) winbox - allow adding bonding interface with one slave interface; *) winbox - allow performing "USB Power Reset" on "0" bus on RBM33G; *) winbox - do not show "network-mode" parameter for LTE interfaces that do not support it; *) winbox - fixed "IP->Kid Control->Devices" table automatic refreshing; *) winbox - fixed "interface" and "on-interface" parameter presence under "Bridge/Hosts" menu; *) winbox - fixed "receive-errors" setting persistence under "Wireless/Wireless Sniffer/Settings" menu; *) winbox - fixed "tls-version" parameter setting under "IP/Services" menu; *) winbox - fixed minor typo in "Users" menu; *) winbox - provide sane default values for bridge "VLAN IDs" parameter; *) winbox - use health values reported by gauges for "System/Health" menu; *) wireless - added U-NII-2 support for US and Canada country profiles for mANTBox series devices; *) wireless - create "connect-list" rule when address specified for "setup-repeater"; *) wireless - do not override MTU and ARP values from CAPsMAN with local forwarding; *) wireless - improved WPS process stability; *) wireless - increased "group-key-update" maximum value to 1 day; *) wireless - updated "no_country_set" regulatory domain information;
      *) arm - improved system stability; *) bgp - treat route target with AS 65535 as two byte AS; *) bonding - added LACP monitoring; *) branding - fixed imported skin presence; *) bridge - use "frame-types=admit-all" by default for extended bridge ports; *) certificate - fixed CRL URL length limit; *) certificate - generate CRL even when CRL URL not specified; *) certificate - properly flush expired SCEP OTP entries; *) chr - fixed SSH key import on Azure; *) crs3xx - fixed booting issues on CRS354 devices (introduced in v6.48beta48); *) crs3xx - fixed bridge port-extender for CRS318 devices; *) crs3xx - fixed switch-cpu VLAN membership removal (introduced in v6.48beta40); *) crs3xx - improved system stability on CRS354 devices; *) defconf - fixed default configuration loading on RBcAP-2nD and RBwAP-2nD; *) defconf - fixed static IP address setting in case default configuration loading fails; *) dhcp - fixed DHCP packet forwarding to IPsec policies; *) dhcpv6 server - added support for "Delegated-IPv6-Prefix" for PPP services; *) dhcpv6-server - added support for "option18" and "option37" for RADIUS managed clients; *) dhcpv6-server - allow loose static binding "pool" parameter (introduced in v6.46.8); *) dhcpv6-server - make sure that calling station ID always contains DUID; *) discovery - added "lldp-med-net-policy-vlan" property for assigning VLAN ID; *) discovery - allow choosing which discovery protocol is used; *) disk - fixed external EXT3 disk mounting on x86 systems; *) disk - improved disk management service stability when receiving bogus packets; *) dns - end ongoing queries when changing DoH configuration; *) dns - improved stability with large table of static records; *) dot1x - fixed reauthentication after server rejects a client into VLAN; *) dot1x - fixed unicast destination EAP packet receiving when a client is running on a bridge port; *) dude - fixed configuration menu presence on ARM64 devices; *) filesystem - improved long-term filesystem stability and data integrity; *) hotspot - fixed "html-directory" parameter export; *) ike2 - improved EAP message integrity checking; *) interface - fixed pwr-line running state (introduced in v6.45); *) lora - limited output power in RU region for range 868.7 MHz - 869.2 MHz according to regulations; *) lte - increased "at+cops" reply timeout to 1 minute; *) metarouter - allow creating RouterOS metarouter instances on devices with 16MB flash storage; *) metarouter - fixed directory entry reporting; *) metarouter - fixed memory leak when tearing down metarouter instance; *) ppp - added "bridge-learning" parameter support; *) ppp - store "last-caller-id" for PPP secrets; *) ppp - store "last-disconnect-reason" for PPP secrets; *) profile - fixed process classification on x86 systems (introduced in v6.47); *) quickset - fixed wireless client "uptime" counter in "Home Mesh" mode; *) sstp - fixed "idle-timeout" on TILE and CHR devices; *) supout - improved autosupout.rif file generation process; *) timezone - updated timezone information from "tzdata2020d" release; *) tr069-client - added branding package version parameter; *) upgrade - do not try installing packages if download was not completed; *) webfig - allow hiding and renaming inline buttons; *) webfig - allow hiding QuickSet mode selector; *) webfig - properly stop background processes when switching away from QuickSet tab; *) winbox - added "operator" parameter under "Interface/LTE" menu; *) winbox - added "reformat-hold-button-max" parameter under "System/RouterBOARD/Settings" menu; *) winbox - added "tls-mode" parameter under "CAPsMAN/Security Cfg." menu; *) winbox - added "tx-rx-1024-max" counter under "Interface/Overall-Stats" for CRS3xx devices; *) winbox - allow adding bonding interface with one slave interface; *) winbox - do not allow MAC address changes on LTE interfaces; *) winbox - do not show "network-mode" parameter for LTE interfaces that do not support it; *) winbox - fixed "interface" and "on-interface" parameter presence under "Bridge/Hosts" menu; *) winbox - provide sane default values for bridge "VLAN IDs" parameter; *) winbox - show "System/Health" only on boards that have health monitoring; *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature; *) winbox - show "usb-bus" option on all boards that have it; *) winbox - show "usb-type" option on all boards that have it; *) winbox - sort IPv6 firewall "chain" parameter entries alphabetically; *) wireless - added U-NII-2 support for US and Canada country profiles for mANTBox series devices; *) wireless - increased "group-key-update" maximum value to 1 day; Other changes since v6.47.7: *) arm64 - improved reboot reason reporting in log; *) arm - added support for automatic CPU frequency stepping for IPQ4018/IPQ4019 devices; *) arm - improved watchdog and kernel panic reporting in log after reboots on IPQ4018/IPQ4019 devices; *) bonding - added LACP monitoring (CLI only); *) bonding - removed "sys-id" and "sys-priority" from monitor-slaves command; *) bridge - added minor fixes and improvements for IGMP snooping with HW offloading; *) bridge - added warning message when port is disabled by the BPDU guard; *) bridge - allow to exclude interfaces from extended ports (CLI only); *) bridge - automatically remove extended interfaces when deleting PE device from CB; *) bridge - correctly remove dynamic VLAN assignment for bridge ports; *) bridge - fixed BPDU guard port disable/enable on HW offloaded interfaces; *) bridge - fixed dynamic VLAN assignment when changing port "frame-type" property (introduced in v6.46); *) bridge - fixed dynamic VLAN assignment when changing port to tagged VLAN member; *) bridge - fixed link-local multicast forwarding when IGMP snooping and HW offloading is enabled; *) bridge - fixed local MAC address removal from host table when deleting bridge interface; *) bridge - fixed MDB entry removal when using bridge port "fast-leave" property; *) bridge - fixed multicast table printing; *) bridge - fixed packet forwarding for CAP and BCP controlled interfaces (introduced in v6.48beta12); *) bridge - improved BPDU guard logging; *) bridge - increased multicast table size to 4K entries; *) bridge - show error when switch do not support controlling bridge or port extension (CLI only); *) bridge - show "H" flag for extended bridge ports; *) cap - fixed L2MTU setting from CAPsMAN; *) certificate - clear challenge password on renew; *) certificate - fixed private key verification for CA certificate during signing process; *) chr - improved interface loading on startup on XEN; *) chr - improved system stability when changing flow control settings on e1000; *) cloud - improved backup generation process; *) conntrack - automatically reduce connection tracking timeouts when table is full; *) console - allow "once" parameter for bonding monitoring; *) crs3xx - added initial Bridge Port Extender support (CLI only); *) crs3xx - added initial Controlling Bridge support for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (CLI only); *) crs3xx - added switch-cpu port VLAN filtering (switch-cpu port is now mapped with bridge interface VLAN membership when vlan-filtering is enabled); *) crs3xx - fixed CDP packet forwarding for CRS305, CRS318, CRS326-24G-2S+, CRS328 devices; *) crs3xx - fixed "custom-drop-packet" and "not-learned" switch stats for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed duplicate host entries when creating static switch hosts; *) crs3xx - fixed "mirror-source" property on switch port disable for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices; *) crs3xx - fixed port-isolation for CRS305, CRS318, CRS326-24G-2S+, CRS328 devices (introduced in v6.48beta35); *) crs3xx - fixed port isolation for "switch-cpu" port for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices; *) crs3xx - fixed port isolation removal for "switch-cpu" port on CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed "storm-rate" traffic limiting for switch-cpu port on CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed switch "copy-to-cpu" property for CRS305, CRS318, CRS326-24G-2S+, CRS328 devices; *) crs3xx - fixed switch "not-learned" stats for CRS305, CRS326-24G-2S+, CRS328-24P-4S+, CRS328-4C-20S-4S+, CRS318 devices; *) crs3xx - fixed VLAN tagged packet forwarding on "switch-cpu" port for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices (introduced in v6.48beta12); *) defconf - improved CAP interface bridging; *) defconf - improved default configuration generation on devices with non-default wireless interface names; *) detnet - fixed malformed dummy DHCP User Class option; *) detnet - use MAC address from bridge interface instead of slave port; *) dhcpv4-server - improved "client-id" value parsing; *) dhcpv6-server - added ability to generate binding on first request; *) discovery - added "lldp-med-net-policy-vlan" property for assigning VLAN ID (CLI only); *) discovery - allow choosing which discovery protocol is used (CLI only); *) discovery - fixed discovery on mesh ports; *) discovery - fixed discovery packet sending on newly bridged port with "protocol-mode=none"; *) discovery - fixed discovery when enabled only on master port; *) discovery - fixed occasional wrong Chassis-ID for LLDP packets (introduced in v6.48beta35); *) discovery - send the same "Chassis ID" on all interfaces for LLDP packets; *) discovery - use interface MAC address when sending MNDP from slave port; *) dns - added IPv6 support for DoH; *) dns - do not use type "A" for static entries with unspecified type; *) dns - fixed listening for DNS queries when only dynamic static entries exist (introduced in v6.47); *) dot1x - accept priority tagged (VLAN 0) EAP packets on dot1x client; *) export - fixed RouterBOARD USB "type" parameter export; *) filesystem - fixed repartition on non-first partition; *) filesystem - fixed repartition on RB4011 series devices; *) filesystem - improved long-term filesystem stability and data integrity; *) gps - fixed "init-channel" release when not used; *) health - changed PSU state parameter type to read-only; *) health - removed unused "heater-control" and "heater-threshold" parameters; *) hotspot - added support for captive portal advertising using DHCP (RFC7710); *) hotspot - added "vlan-id" parameter support for hosts and HTML pages; *) hotspot - improved management service stability when receiving bogus packets; *) ike1 - fixed "my-id=address" parameter usage together with certificate authentication; *) ike1 - fixed policy update with and without mode configuration; *) ike1 - rekey phase 1 as responder for Windows initiators; *) ike2 - added "prf-algorithm" support for phase 1; *) ike2 - added support for IKEv2 Message Fragmentation (RFC7383); *) ike2 - fixed EAP MSK length validation; *) ike2 - fixed too small payload parsing; *) ike2 - improved child SA rekeying process; *) interface - added temperature warning and interface disable on overheat for SFP and SFP+ interfaces (CLI only); *) ipsec - added SHA384 hash algorithm support for phase 1 (CLI only); *) ipsec - do not kill connection when peer's "name" or "comment" is changed; *) ipsec - fixed client certificate usage when certificate is renewed with SCEP; *) ipsec - fixed multiple warning message display for peers; *) ipsec - inactivate peer's policy on disconnect; *) ipsec - refresh peer's DNS only when phase 1 is down; *) kidcontrol - allow creating static device entries without assigned user; *) led - fixed state persistence after device reboot on NetMetal 5 ac devices; *) lora - fixed device going into "ERROR" state caused by FSK modulated downlinks; *) lte - added "age" column and "max-age" parameter to "cell-monitor" (CLI only); *) lte - added "comment" parameter for APN profiles; *) lte - added support for Alcatel IK41VE1; *) lte - fixed "band" value reporting; *) m33g - added support for "/system gpio" menu (CLI only); *) ppp - added "ipv6-routes" parameter to "secrets" menu; *) ppp - added support for "Framed-IPv6-Route" RADIUS attribute; *) profile - improved idle process detection on x86 processors; *) profile - improved process classification on ARM devices; *) quickset - added "Port Mapping" to QuickSet; *) quickset - fixed local IP address setting on master interface; *) route - improved stability when 6to4 interface is configured with disabled IPv6 package; *) routerboard - fixed PCIe bus reset during power-on on MMIPS devices ("/system routerboard upgrade" required); *) routerboard - force power-down on PCIe bus during reboot on LHGR devices ("/system routerboard upgrade" required); *) script - added error message in the logs if startup script runtime limit was exceeded; *) snmp - added information from IPsec "active-peers" menu to MIKROTIK-MIB; *) snmp - added new LTE monitoring OID's to MIKROTIK-MIB; *) snmp - fixed value types for "dot1dStp"; *) snmp - fixed value types for "dot1qPvid"; *) ssh - fixed returned output saving to file when "output-to-file" parameter is used; *) ssh - skip interactive authentication when not running in interactive mode; *) supout - added bonding interface monitor information; *) system - replace "3" in superscript to "^3" on RBD53GR devices; *) tr069-client - added additional wireless registration table parameters; *) tr069-client - added LTE model and revision parameters; *) tr069-client - added wireless "noise-floor" and "overall-tx-ccq" information parameters; *) tr069-client - added "X_MIKROTIK_MimoRSRP" parameter for LTE RSRP value reporting; *) tr069-client - allow passing LTE firmware update URL as XML; *) tr069-client - fixed RouterOS downgrade procedure; *) tr069-client - send correct "ConnectionRequestURL" when using IPv6; *) traffic-flow - added NAT event logging support for IPFIX; *) traffic-flow - added "sys-init-time" parameter support; *) traffic-generator - fixed 32Gbps limitation; *) user-manager - do not allow creating limitation that crosses midnight; *) user-manager - updated PayPal's root certificate authorities; *) webfig - fixed default value presence when creating new entries under "IP->Kid Control"; *) winbox - allow performing "USB Power Reset" on "0" bus on RBM33G; *) winbox - fixed "IP->Kid Control->Devices" table automatic refreshing; *) winbox - fixed minor typo in "Users" menu; *) winbox - fixed "receive-errors" setting persistence under "Wireless/Wireless Sniffer/Settings" menu; *) winbox - fixed "tls-version" parameter setting under "IP/Services" menu; *) winbox - use health values reported by gauges for "System/Health" menu; *) wireless - create "connect-list" rule when address specified for "setup-repeater"; *) wireless - do not override MTU and ARP values from CAPsMAN with local forwarding; *) wireless - improved WPS process stability; *) wireless - updated "no_country_set" regulatory domain information;
      Important note!!! Using this version on CRS354-48G-4S+2Q+RM or CRS354-48P-4S+2Q+RM will cause booting issues and device may need to be reinstalled. Changes in this release: *) bridge - automatically remove extended interfaces when deleting PE device from CB; *) cap - fixed L2MTU path discovery; *) cap - fixed L2MTU setting from CAPsMAN; *) certificate - fixed private key verification for CA certificate during signing process; *) cloud - improved backup generation process; *) crs3xx - fixed CDP packet forwarding for CRS305, CRS318, CRS326-24G-2S+, CRS328 devices; *) crs3xx - fixed port-isolation for CRS305, CRS318, CRS326-24G-2S+, CRS328 devices (introduced in v6.48beta35); *) defconf - fixed default configuration loading on RBmAP-2nD; *) dhcpv4-client - fixed DHCP offer packet parsing with overload option present; *) discovery - fixed occasional wrong Chassis-ID for LLDP packets (introduced in v6.48beta35); *) dot1x - accept priority tagged (VLAN 0) EAP packets on dot1x client; *) fetch - improved SSL handshake processing; *) filesystem - improved long-term filesystem stability and data integrity; *) ike1 - fixed "my-id=address" parameter usage together with certificate authentication; *) ike2 - added support for IKEv2 Message Fragmentation (RFC7383); *) ike2 - fixed EAP MSK length validation; *) ike2 - fixed too small payload parsing; *) interface - added temperature warning and interface disable on overheat for SFP and SFP+ interfaces (CLI only); *) led - fixed state persistence after device reboot on NetMetal 5 ac devices; *) lora - fixed device going into "ERROR" state caused by FSK modulated downlinks; *) lte - fixed "band" value reporting; *) lte - fixed multiple APN passthrough on R11e-4G; *) lte - improved EARFCN reporting in 3G and LTE modes on Sierra modems; *) lte - limit allowed APN count to 3 on R11e-LTE; *) m33g - added support for "/system gpio" menu (CLI only); *) mpls - fixed duplicate "LabelRelease" message sending; *) profile - improved idle process detection on x86 processors; *) profile - improved process classification on ARM devices; *) quickset - added "Port Mapping" to QuickSet; *) quickset - fixed local IP address setting on master interface; *) radius - added "Service-Type" attribute to Access-Request for IPv4 and IPv6 DHCP servers; *) routerboard - fixed PCIe bus reset during power-on on MMIPS devices ("/system routerboard upgrade" required); *) routerboard - force power-down on PCIe bus during reboot on LHGR devices ("/system routerboard upgrade" required); *) script - added error message in the logs if startup script runtime limit was exceeded; *) snmp - added information from IPsec "active-peers" menu to MIKROTIK-MIB; *) snmp - added new LTE monitoring OID's to MIKROTIK-MIB; *) switch - fixed Ethernet padding for small packets; *) tr069-client - fixed RouterOS downgrade procedure; *) traffic-flow - added NAT event logging support for IPFIX; *) traffic-generator - fixed 32Gbps limitation; *) user - improved WinBox and The Dude authenticated session handling; *) user-manager - do not allow creating limitation that crosses midnight; *) user-manager - updated PayPal's root certificate authorities; *) vrrp - made "password" parameter sensitive; *) w60g - general stability and performance improvements; *) wireless - added support for US FCC UNII-2 and Canada country profiles for NetMetal series devices; *) wireless - do not override MTU and ARP values from CAPsMAN with local forwarding; *) wireless - fixed incorrect wireless capability information in association response frames; *) wireless - updated "no_country_set" regulatory domain information; Other changes since v6.47.4: *) arm64 - improved reboot reason reporting in log; *) arm - added support for automatic CPU frequency stepping for IPQ4018/IPQ4019 devices; *) arm - improved watchdog and kernel panic reporting in log after reboots on IPQ4018/IPQ4019 devices; *) bonding - added LACP monitoring (CLI only); *) bonding - removed "sys-id" and "sys-priority" from monitor-slaves command; *) bridge - added minor fixes and improvements for IGMP snooping with HW offloading; *) bridge - added warning message when port is disabled by the BPDU guard; *) bridge - allow to exclude interfaces from extended ports (CLI only); *) bridge - correctly remove dynamic VLAN assignment for bridge ports; *) bridge - fixed BPDU guard port disable/enable on HW offloaded interfaces; *) bridge - fixed dynamic VLAN assignment when changing port "frame-type" property (introduced in v6.46); *) bridge - fixed dynamic VLAN assignment when changing port to tagged VLAN member; *) bridge - fixed link-local multicast forwarding when IGMP snooping and HW offloading is enabled; *) bridge - fixed local MAC address removal from host table when deleting bridge interface; *) bridge - fixed MDB entry removal when using bridge port "fast-leave" property; *) bridge - fixed multicast table printing; *) bridge - fixed packet forwarding for CAP and BCP controlled interfaces (introduced in v6.48beta12); *) bridge - improved BPDU guard logging; *) bridge - increased multicast table size to 4K entries; *) bridge - show error when switch do not support controlling bridge or port extension (CLI only); *) bridge - show "H" flag for extended bridge ports; *) certificate - clear challenge password on renew; *) chr - improved interface loading on startup on XEN; *) chr - improved system stability when changing flow control settings on e1000; *) conntrack - automatically reduce connection tracking timeouts when table is full; *) console - allow "once" parameter for bonding monitoring; *) crs3xx - added initial Bridge Port Extender support (CLI only); *) crs3xx - added initial Controlling Bridge support for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (CLI only); *) crs3xx - added switch-cpu port VLAN filtering (switch-cpu port is now mapped with bridge interface VLAN membership when vlan-filtering is enabled); *) crs3xx - fixed "custom-drop-packet" and "not-learned" switch stats for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed duplicate host entries when creating static switch hosts; *) crs3xx - fixed "mirror-source" property on switch port disable for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices; *) crs3xx - fixed port isolation for "switch-cpu" port for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices; *) crs3xx - fixed port isolation removal for "switch-cpu" port on CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed "storm-rate" traffic limiting for switch-cpu port on CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed switch "copy-to-cpu" property for CRS305, CRS318, CRS326-24G-2S+, CRS328 devices; *) crs3xx - fixed switch "not-learned" stats for CRS305, CRS326-24G-2S+, CRS328-24P-4S+, CRS328-4C-20S-4S+, CRS318 devices; *) crs3xx - fixed VLAN tagged packet forwarding on "switch-cpu" port for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices (introduced in v6.48beta12); *) defconf - improved CAP interface bridging; *) defconf - improved default configuration generation on devices with non-default wireless interface names; *) defconf - improved default configuration generation on devices without wireless package installed; *) detnet - fixed malformed dummy DHCP User Class option; *) detnet - use MAC address from bridge interface instead of slave port; *) dhcpv4-server - improved "client-id" value parsing; *) dhcpv6-server - added ability to generate binding on first request; *) discovery - added "lldp-med-net-policy-vlan" property for assigning VLAN ID (CLI only); *) discovery - allow choosing which discovery protocol is used (CLI only); *) discovery - fixed discovery on mesh ports; *) discovery - fixed discovery packet sending on newly bridged port with "protocol-mode=none"; *) discovery - fixed discovery when enabled only on master port; *) discovery - send the same "Chassis ID" on all interfaces for LLDP packets; *) discovery - use interface MAC address when sending MNDP from slave port; *) dns - added IPv6 support for DoH; *) dns - do not use type "A" for static entries with unspecified type; *) dns - fixed listening for DNS queries when only dynamic static entries exist (introduced in v6.47); *) export - fixed RouterBOARD USB "type" parameter export; *) filesystem - fixed repartition on non-first partition; *) filesystem - fixed repartition on RB4011 series devices; *) gps - fixed "init-channel" release when not used; *) health - changed PSU state parameter type to read-only; *) health - removed unused "heater-control" and "heater-threshold" parameters; *) hotspot - added support for captive portal advertising using DHCP (RFC7710); *) hotspot - added "vlan-id" parameter support for hosts and HTML pages; *) hotspot - improved management service stability when receiving bogus packets; *) ike1 - allow using "my-id" parameter with XAuth; *) ike1 - fixed policy update with and without mode configuration; *) ike1 - rekey phase 1 as responder for Windows initiators; *) ike2 - added "prf-algorithm" support for phase 1; *) ike2 - improved child SA rekeying process; *) ipsec - added SHA384 hash algorithm support for phase 1 (CLI only); *) ipsec - do not kill connection when peer's "name" or "comment" is changed; *) ipsec - fixed client certificate usage when certificate is renewed with SCEP; *) ipsec - fixed multiple warning message display for peers; *) ipsec - inactivate peer's policy on disconnect; *) ipsec - refresh peer's DNS only when phase 1 is down; *) kidcontrol - allow creating static device entries without assigned user; *) leds - fixed LED type setting; *) lora - expose "joinEui" un "devEui" values in the log; *) lte - added "age" column and "max-age" parameter to "cell-monitor" (CLI only); *) lte - added "comment" parameter for APN profiles; *) lte - added support for Alcatel IK41VE1; *) ospf - optimized LSA printing for smaller message sizes; *) ppp - added "ipv6-routes" parameter to "secrets" menu; *) ppp - added support for "Framed-IPv6-Route" RADIUS attribute; *) route - improved stability when 6to4 interface is configured with disabled IPv6 package; *) snmp - added information from IPsec "active-peers" menu to MIKROTIK-MIB; *) snmp - fixed value types for "dot1dStp"; *) snmp - fixed value types for "dot1qPvid"; *) ssh - fixed returned output saving to file when "output-to-file" parameter is used; *) ssh - skip interactive authentication when not running in interactive mode; *) supout - added bonding interface monitor information; *) switch - fixed Ethernet padding for small packets; *) system - replace "3" in superscript to "^3" on RBD53GR devices; *) tr069-client - added additional wireless registration table parameters; *) tr069-client - added LTE model and revision parameters; *) tr069-client - added wireless "noise-floor" and "overall-tx-ccq" information parameters; *) tr069-client - added "X_MIKROTIK_MimoRSRP" parameter for LTE RSRP value reporting; *) tr069-client - allow passing LTE firmware update URL as XML; *) tr069-client - send correct "ConnectionRequestURL" when using IPv6; *) traffic-flow - added NAT event logging support for IPFIX; *) traffic-flow - added "sys-init-time" parameter support; *) user-manager - do not allow creating limitation that crosses midnight; *) webfig - fixed default value presence when creating new entries under "IP->Kid Control"; *) winbox - allow performing "USB Power Reset" on "0" bus on RBM33G; *) winbox - fixed "IP->Kid Control->Devices" table automatic refreshing; *) winbox - fixed minor typo in "Users" menu; *) winbox - fixed "receive-errors" setting persistence under "Wireless/Wireless Sniffer/Settings" menu; *) winbox - fixed "tls-version" parameter setting under "IP/Services" menu; *) winbox - use health values reported by gauges for "System/Health" menu; *) wireless - create "connect-list" rule when address specified for "setup-repeater"; *) wireless - improved WPS process stability; *) wireless - updated "no_country_set" regulatory domain information;
      *) arm64 - improved reboot reason reporting in log; *) bridge - added minor fixes and improvements for IGMP snooping with HW offloading; *) bridge - fixed link-local multicast forwarding when IGMP snooping and HW offloading is enabled; *) bridge - fixed MDB entry removal when using bridge port "fast-leave" property; *) conntrack - automatically reduce connection tracking timeouts when table is full; *) console - allow "once" parameter for bonding monitoring; *) crs3xx - added initial Bridge Port Extender support (CLI only); *) crs3xx - added initial Controlling Bridge support for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (CLI only); *) crs3xx - added switch-cpu port VLAN filtering (switch-cpu port is now mapped with bridge interface VLAN membership when vlan-filtering is enabled); *) crs3xx - fixed IGMP snooping for CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed switch "copy-to-cpu" property for CRS305, CRS318, CRS326-24G-2S+, CRS328 devices; *) detnet - fixed malformed dummy DHCP User Class option; *) detnet - use MAC address from bridge interface instead of slave port; *) dhcpv4-server - improved "client-id" value parsing; *) ipsec - refresh peer's DNS only when phase 1 is down; *) leds - fixed LED type setting; *) smb - fixed possible memory leak; *) sms - fixed SMS sending when both "interface" and "smsc" parameters are specified; *) snmp - added information from IPsec "active-peers" menu to MIKROTIK-MIB; *) snmp - fixed "/tool snmp-get" functionality (introduced in v 6.46beta43); *) snmp - fixed value types for "dot1qPvid"; *) supout - added bonding interface monitor information; *) switch - fixed Ethernet padding for small packets; *) tr069-client - allow passing LTE firmware update URL as XML; *) user-manager - do not allow creating limitation that crosses midnight; *) user-manager - updated PayPal's root certificate authorities; *) wireless - improved WPS process stability; Other changes since v6.47.3: *) arm - added support for automatic CPU frequency stepping for IPQ4018/IPQ4019 devices; *) arm - improved watchdog and kernel panic reporting in log after reboots on IPQ4018/IPQ4019 devices; *) bonding - added LACP monitoring (CLI only); *) bonding - removed "sys-id" and "sys-priority" from monitor-slaves command; *) bridge - added warning message when port is disabled by the BPDU guard; *) bridge - allow to exclude interfaces from extended ports (CLI only); *) bridge - correctly remove dynamic VLAN assignment for bridge ports; *) bridge - fixed BPDU guard port disable/enable on HW offloaded interfaces; *) bridge - fixed dynamic VLAN assignment when changing port "frame-type" property (introduced in v6.46); *) bridge - fixed dynamic VLAN assignment when changing port to tagged VLAN member; *) bridge - fixed local MAC address removal from host table when deleting bridge interface; *) bridge - fixed multicast table printing; *) bridge - fixed packet forwarding for CAP and BCP controlled interfaces (introduced in v6.48beta12); *) bridge - fixed STP alternate and backup port states for devices with switch chip (introduced in v6.47); *) bridge - improved BPDU guard logging; *) bridge - increased multicast table size to 4K entries; *) bridge - show error when switch do not support controlling bridge or port extension (CLI only); *) bridge - show "H" flag for extended bridge ports; *) certificate - clear challenge password on renew; *) chr - improved interface loading on startup on XEN; *) chr - improved system stability when changing flow control settings on e1000; *) crs3xx - added initial Bridge Port Extender support (CLI only); *) crs3xx - added initial Controlling Bridge support for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (CLI only); *) crs3xx - fixed "custom-drop-packet" and "not-learned" switch stats for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed duplicate host entries when creating static switch hosts; *) crs3xx - fixed "mirror-source" property on switch port disable for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices; *) crs3xx - fixed port isolation for "switch-cpu" port for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices; *) crs3xx - fixed port isolation removal for "switch-cpu" port on CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed "storm-rate" traffic limiting for switch-cpu port on CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed switch "not-learned" stats for CRS305, CRS326-24G-2S+, CRS328-24P-4S+, CRS328-4C-20S-4S+, CRS318 devices; *) crs3xx - fixed switch port "egress-rate" removal for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices; *) crs3xx - fixed VLAN tagged packet forwarding on "switch-cpu" port for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices (introduced in v6.48beta12); *) defconf - improved CAP interface bridging; *) defconf - improved default configuration generation on devices with non-default wireless interface names; *) defconf - improved default configuration generation on devices without wireless package installed; *) dhcpv6-server - added ability to generate binding on first request; *) discovery - added "lldp-med-net-policy-vlan" property for assigning VLAN ID (CLI only); *) discovery - allow choosing which discovery protocol is used (CLI only); *) discovery - fixed discovery on mesh ports; *) discovery - fixed discovery packet sending on newly bridged port with "protocol-mode=none"; *) discovery - fixed discovery when enabled only on master port; *) discovery - send the same "Chassis ID" on all interfaces for LLDP packets; *) discovery - use interface MAC address when sending MNDP from slave port; *) dns - added IPv6 support for DoH; *) dns - do not use type "A" for static entries with unspecified type; *) dns - fixed listening for DNS queries when only dynamic static entries exist (introduced in v6.47); *) export - fixed RouterBOARD USB "type" parameter export; *) fetch - fixed "src-address" usage for SFTP; *) filesystem - fixed repartition on non-first partition; *) filesystem - fixed repartition on RB4011 series devices; *) filesystem - improved long-term filesystem stability and data integrity; *) gps - fixed "init-channel" release when not used; *) health - changed PSU state parameter type to read-only; *) health - removed unused "heater-control" and "heater-threshold" parameters; *) hotspot - added support for captive portal advertising using DHCP (RFC7710); *) hotspot - added "vlan-id" parameter support for hosts and HTML pages; *) hotspot - ignore packets from host while MAC authentication is in progress; *) hotspot - improved management service stability when receiving bogus packets; *) ike1 - allow using "my-id" parameter with XAuth; *) ike1 - fixed policy update with and without mode configuration; *) ike1 - rekey phase 1 as responder for Windows initiators; *) ike2 - added "prf-algorithm" support for phase 1; *) ike2 - improved child SA rekeying process; *) ipsec - added SHA384 hash algorithm support for phase 1 (CLI only); *) ipsec - do not kill connection when peer's "name" or "comment" is changed; *) ipsec - fixed client certificate usage when certificate is renewed with SCEP; *) ipsec - fixed multiple warning message display for peers; *) ipsec - inactivate peer's policy on disconnect; *) ipsec - refresh peer's DNS only when phase 1 is down; *) kidcontrol - allow creating static device entries without assigned user; *) kidcontrol - fixed "time-unlimited-rate" to engage in correct time; *) lora - expose "joinEui" un "devEui" values in the log; *) lte - added "age" column and "max-age" parameter to "cell-monitor" (CLI only); *) lte - added "comment" parameter for APN profiles; *) lte - added support for Alcatel IK41VE1; *) ospf - optimized LSA printing for smaller message sizes; *) ppp - added "ipv6-routes" parameter to "secrets" menu; *) ppp - added support for "Framed-IPv6-Route" RADIUS attribute; *) route - improved stability when 6to4 interface is configured with disabled IPv6 package; *) snmp - fixed value types for "dot1dStp"; *) ssh - fixed returned output saving to file when "output-to-file" parameter is used; *) ssh - skip interactive authentication when not running in interactive mode; *) system - replace "3" in superscript to "^3" on RBD53GR devices; *) tr069-client - added additional wireless registration table parameters; *) tr069-client - added LTE model and revision parameters; *) tr069-client - added wireless "noise-floor" and "overall-tx-ccq" information parameters; *) tr069-client - added "X_MIKROTIK_MimoRSRP" parameter for LTE RSRP value reporting; *) tr069-client - allow passing LTE firmware update URL as XML; *) tr069-client - send correct "ConnectionRequestURL" when using IPv6; *) traffic-flow - added NAT event logging support for IPFIX; *) traffic-flow - added "sys-init-time" parameter support; *) webfig - fixed default value presence when creating new entries under "IP->Kid Control"; *) winbox - allow performing "USB Power Reset" on "0" bus on RBM33G; *) winbox - fixed "IP->Kid Control->Devices" table automatic refreshing; *) winbox - fixed minor typo in "Users" menu; *) winbox - fixed "receive-errors" setting persistence under "Wireless/Wireless Sniffer/Settings" menu; *) winbox - fixed "tls-version" parameter setting under "IP/Services" menu; *) winbox - use health values reported by gauges for "System/Health" menu; *) wireless - added support for U-NII-2 for wAP ac; *) wireless - create "connect-list" rule when address specified for "setup-repeater"; *) wireless - updated "canada" regulatory domain information; *) wireless - updated "no_country_set" regulatory domain information; *) wireless - updated "united states" regulatory domain information;
      *) arm - added support for automatic CPU frequency stepping for IPQ4018/IPQ4019 devices; *) arm - improved stability when forcing 25G speed on unsupported interface; *) bridge - allow to exclude interfaces from extended ports (CLI only); *) bridge - fixed host table update on SNMP query; *) bridge - show error when switch do not support controlling bridge or port extension (CLI only); *) bridge - show "H" flag for extended bridge ports; *) certificate - clear challenge password on renew; *) crs3xx - added initial Bridge Port Extender support (CLI only); *) crs3xx - added initial Controlling Bridge support for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (CLI only); *) crs3xx - fixed "custom-drop-packet" and "not-learned" switch stats for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed hardware offloaded MPLS forwarding when using bonding interfaces; *) crs3xx - fixed QSFP+ interface LEDs when using break-out cable for CRS326-24S+2Q+; *) crs3xx - fixed QSFP+ interface linking after reboot for CRS326-24S+2Q+ (introduced in v6.47); *) crs3xx - fixed switch "not-learned" stats for CRS305, CRS326-24G-2S+, CRS328-24P-4S+, CRS328-4C-20S-4S+, CRS318 devices; *) crs3xx - improved Ethernet port group traffic forwarding for CRS354 devices; *) crs3xx - improved system stability when using hardware offloaded MPLS; *) defconf - improved default configuration generation on devices with non-default wireless interface names; *) discovery - send the same "Chassis ID" on all interfaces for LLDP packets; *) discovery - use "static" interface list by default instead of "!dynamic"; *) dot1x - fixed duplicate EAP request packets for server; *) dot1x - fixed EAP packet version numbering; *) fetch - show status "uploaded" instead of "downloaded" when uploading a file; *) filesystem - fixed repartition on non-first partition; *) filesystem - fixed repartition on RB4011 series devices; *) filesystem - improved long-term filesystem stability and data integrity; *) gps - fixed "init-channel" release when not used; *) health - changed PSU state parameter type to read-only; *) health - removed unused "heater-control" and "heater-threshold" parameters; *) hotspot - added "vlan-id" parameter support for hosts and HTML pages; *) hotspot - do not verify Hotspot interface status when detecting if HTTP/HTTPS login method is allowed; *) hotspot - ignore packets from host while MAC authentication is in progress; *) interface - added new builtin "static" interface list; *) ipsec - fixed client certificate usage when certificate is renewed with SCEP; *) kidcontrol - fixed "time-unlimited-rate" to engage in correct time; *) l2tp - fixed multiple tunnel establishment from the same remote IP address (introduced in v6.47); *) lora - expose "joinEui" un "devEui" values in the log; *) lora - fixed "spoof-gps" parameter padding (introduced in v6.47.1); *) lte - added "comment" parameter for APN profiles; *) lte - fixed dynamic DHCP client creation when editing APN profile; *) lte - fixed multiple passthrough APN default route installation; *) lte - fixed RSCP value reporting; *) lte - validate interface existence on initiation; *) ospf - fixed case when changing one distribution metric changed metrics for other distribution options; *) ospf - fixed disappearing NSSA default route; *) ospf - fixed processing of "unknown" LSA type; *) ospf - optimized LSA printing for smaller message sizes; *) poe - fixed "power-cycle" functionality on RB960GSP; *) ppp - fixed PPP interface editing for the first time after reboot or after 20 seconds; *) routerboot - fixed etherboot FCS errors with 100Mbps rate for CRS309, CRS317 devices ("/system routerboard upgrade" required); *) routerboot - fixed memory test on CCR2004-1G-12S+2XS ("/system routerboard upgrade" required); *) sfp - stabilized CRS212 SFP port functionality and improved monitoring of optical modules; *) sftp - fixed "flash" directory access (introduced in v6.46); *) smb - fixed file path validation (introduced in v6.46); *) snmp - fixed "current" value reporting on CCR series devices; *) snmp - fixed "fan-speed" value reporting on CCR series devices; *) ssh - skip interactive authentication when not running in interactive mode; *) tr069-client - added additional wireless registration table parameters; *) tr069-client - added wireless "noise-floor" and "overall-tx-ccq" information parameters; *) traffic-flow - added NAT event logging support for IPFIX; *) webfig - fixed default value presence when creating new entries under "IP->Kid Control"; *) webfig - fixed negative value usage in "spoof-gps" parameter (introduced in v6.47.1); *) wireless - added support for U-NII-2 for cAP ac; *) wireless - added support for U-NII-2 for wAP ac; *) wireless - updated "canada" regulatory domain information; *) wireless - updated "indonesia5" regulatory domain information; *) wireless - updated "no_country_set" regulatory domain information; *) wireless - updated "united states" regulatory domain information; *) www - improved WWW service stability when receiving bogus packets; Other changes since v6.47.1: *) arm - added support for automatic CPU frequency stepping for IPQ4018/IPQ4019 devices; *) arm - improved watchdog and kernel panic reporting in log after reboots on IPQ4018/IPQ4019 devices; *) bonding - added LACP monitoring (CLI only); *) bridge - added warning message when port is disabled by the BPDU guard; *) bridge - correctly remove dynamic VLAN assignment for bridge ports; *) bridge - fixed dynamic VLAN assignment when changing port "frame-type" property (introduced in v6.46); *) bridge - fixed dynamic VLAN assignment when changing port to tagged VLAN member; *) bridge - fixed local MAC address removal from host table when deleting bridge interface; *) bridge - improved BPDU guard logging; *) chr - improved interface loading on startup on XEN; *) chr - improved system stability when changing flow control settings on e1000; *) crs3xx - added initial Bridge Port Extender support (CLI only); *) crs3xx - added initial Controlling Bridge support for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (CLI only); *) crs3xx - fixed duplicate host entries when creating static switch hosts; *) dhcpv6-server - added ability to generate binding on first request; *) dns - do not use type "A" for static entries with unspecified type; *) dns - fixed listening for DNS queries when only dynamic static entries exist (introduced in v6.47); *) export - fixed RouterBOARD USB "type" parameter export; *) fetch - show status "uploaded" instead of "downloaded" when uploading a file; *) filesystem - improved long-term filesystem stability and data integrity; *) ike1 - allow using "my-id" parameter with XAuth; *) ike1 - fixed policy update with and without mode configuration; *) ike1 - rekey phase 1 as responder for Windows initiators; *) ike2 - added "prf-algorithm" support for phase 1; *) ike2 - improved child SA rekeying process; *) ipsec - added SHA384 hash algorithm support for phase 1 (CLI only); *) ipsec - fixed multiple warning message display for peers; *) ipsec - inactivate peer's policy on disconnect; *) kidcontrol - allow creating static device entries without assigned user; *) lte - added "age" column and "max-age" parameter to "cell-monitor" (CLI only); *) lte - added "comment" parameter for APN profiles (CLI only); *) ppp - added "ipv6-routes" parameter to "secrets" menu; *) ppp - added support for "Framed-IPv6-Route" RADIUS attribute; *) qsfp - fixed break-out cable linking after reboot (introduced in v6.47); *) route - improved stability when 6to4 interface is configured with disabled IPv6 package; *) smb - fixed possible memory leak; *) smb - fixed SMB server (introduced in v6.47); *) smb - limit active session count to 5 per connection; *) ssh - fixed returned output saving to file when "output-to-file" parameter is used; *) system - replace "3" in superscript to "^3" on RBD53GR devices; *) tr069-client - added LTE model and revision parameters; *) tr069-client - added "X_MIKROTIK_MimoRSRP" parameter for LTE RSRP value reporting; *) tr069-client - allow passing LTE firmware update URL as XML; *) winbox - allow performing "USB Power Reset" on "0" bus on RBM33G; *) winbox - fixed "IP->Kid Control->Devices" table automatic refreshing; *) winbox - fixed minor typo in "Users" menu; *) winbox - fixed "receive-errors" setting persistence under "Wireless/Wireless Sniffer/Settings" menu; *) winbox - fixed "tls-version" parameter setting under "IP/Services" menu; *) winbox - use health values reported by gauges for "System/Health" menu; *) wireless - create "connect-list" rule when address specified for "setup-repeater";
      *) arm - added support for automatic CPU frequency stepping for IPQ4018/IPQ4019 devices; *) arm - improved watchdog and kernel panic reporting in log after reboots on IPQ4018/IPQ4019 devices; *) bonding - added LACP monitoring (CLI only); *) bridge - added warning message when port is disabled by the BPDU guard; *) bridge - correctly remove dynamic VLAN assignment for bridge ports; *) bridge - fixed dynamic VLAN assignment when changing port "frame-type" property (introduced in v6.46); *) bridge - fixed dynamic VLAN assignment when changing port to tagged VLAN member; *) bridge - fixed local MAC address removal from host table when deleting bridge interface; *) bridge - improved BPDU guard logging; *) chr - improved interface loading on startup on XEN; *) chr - improved system stability when changing flow control settings on e1000; *) crs3xx - added initial Bridge Port Extender support (CLI only); *) crs3xx - added initial Controlling Bridge support for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (CLI only); *) crs3xx - fixed duplicate host entries when creating static switch hosts; *) crs3xx - fixed HW offloading for netPower 15FR and netPower 16P devices (introduced in v6.47); *) crs3xx - fixed increased CPU temperature for CRS354-48G-4S+2Q+ device (introduced in v6.47); *) crs3xx - improved Ethernet port group traffic forwarding for CRS354 devices; *) defconf - fixed default configuration loading on RBmAPL-2nD; *) defconf - improved default configuration generation on devices with changed wireless interface names; *) dhcpv6-server - added ability to generate binding on first request; *) dhcpv6-server - disallow changing binding's "prefix-pool"; *) dhcpv6-server - improved stability when changing server for static bindings; *) dns - do not allow setting "forward-to" same as "name" or "regex"; *) dns - do not allow setting zero value IP addresses for "A" and "AAAA" records; *) dns - do not use DoH for local queries when a server is specified; *) dns - do not use type "A" for static entries with unspecified type; *) dns - fixed listening for DNS queries when only dynamic static entries exist (introduced in v6.47); *) export - fixed HotSpot "address-per-mac" parameter export; *) export - fixed RouterBOARD USB "type" parameter export; *) fetch - show status "uploaded" instead of "downloaded" when uploading a file; *) filesystem - fixed increased "sector writes" reporting (introduced in v6.47); *) filesystem - improved long-term filesystem stability and data integrity; *) ftp - fixed possible buffer overflow; *) ike1 - allow using "my-id" parameter with XAuth; *) ike1 - fixed policy update with and without mode configuration; *) ike1 - rekey phase 1 as responder for Windows initiators; *) ike2 - added "prf-algorithm" support for phase 1; *) ike2 - fixed initiator child SA init without policy; *) ike2 - fixed policy reference for pending acquire; *) ike2 - improved child SA rekeying process; *) ike2 - retry RSA signature validation with deduced digest from certificate; *) ipsec - added SHA384 hash algorithm support for phase 1 (CLI only); *) ipsec - do not update peer endpoints for generated policy entries (introduced in v6.47); *) ipsec - fixed multiple warning message display for peers; *) ipsec - inactivate peer's policy on disconnect; *) kidcontrol - allow creating static device entries without assigned user; *) lora - added "spoof-gps" parameter for fake GPS coordinate sending; *) lora - fixed JSON statistics inaccuracies; *) lte - added "age" column and "max-age" parameter to "cell-monitor" (CLI only); *) lte - added "comment" parameter for APN profiles (CLI only); *) lte - added support for MTS 8810FT; *) lte - fixed modem initialization when multiple modems are used simultaneously; *) lte - fixed PDP authentication configuration for SIM7600; *) metarouter - fixed image importing (introduced in v6.46); *) ospf - improved route tag processing for OSPFv3; *) ppp - added "ipv6-routes" parameter to "secrets" menu; *) ppp - added support for "Framed-IPv6-Route" RADIUS attribute; *) ppp - allow specifying pool name for "remote-ipv6-prefix-pool" parameter; *) profile - fixed "unclassified" load reporting on PowerPC devices (introduced in v6.47); *) qsfp - fixed auto-negotiation status; *) qsfp - fixed break-out cable linking after reboot (introduced in v6.47); *) qsfp - ignore FEC mode when set to fec91, only fec74 mode is supported (introduced in v6.47); *) route - improved stability when 6to4 interface is configured with disabled IPv6 package; *) routerboard - fixed "mode-button" support on SMIPS devices (introduced in v6.47); *) routerboard - fixed "reset-button" menu presence on all devices; *) smb - fixed possible memory leak; *) smb - fixed SMB server (introduced in v6.47); *) smb - limit active session count to 5 per connection; *) ssh - fixed returned output saving to file when "output-to-file" parameter is used; *) supout - added "LoRa" section to supout file; *) switch - fixed MAC address learning on switch-cpu port for Atheros8316, Atheros8227 and Atheros7240 switch chips; *) system - replace "3" in superscript to "^3" on RBD53GR devices; *) tr069-client - added LTE model and revision parameters; *) tr069-client - added "X_MIKROTIK_MimoRSRP" parameter for LTE RSRP value reporting; *) tr069-client - allow passing LTE firmware update URL as XML; *) w60g - added "mdmg-fix" parameter for RBwAP60Gx3 (CLI only); *) winbox - allow performing "USB Power Reset" on "0" bus on RBM33G; *) winbox - fixed flag displaying under "IP/DNS/Static" table; *) winbox - fixed "IP->Kid Control->Devices" table automatic refreshing; *) winbox - fixed minor typo in "BGP/Peer" menu; *) winbox - fixed minor typo in "Users" menu; *) winbox - fixed "receive-errors" setting persistence under "Wireless/Wireless Sniffer/Settings" menu; *) winbox - fixed "tls-version" parameter setting under "IP/Services" menu; *) winbox - hide irrelevant switch port parameters; *) winbox - use health values reported by gauges for "System/Health" menu; *) wireless - changed "station-roaming" default setting from "enabled" to "disabled"; *) wireless - create "connect-list" rule when address specified for "setup-repeater"; *) wireless - updated "bangladesh" regulatory domain information; *) wireless - updated "egypt" regulatory domain information;
      Important note!!! - The Dude server must be updated to monitor v6.46.4 and v6.47beta30+ RouterOS type devices. - The Dude client must be manually upgraded after upgrading The Dude server. - Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used. - The Dude requires "winbox" policy instead of "dude" to monitor v6.46.4 and v6.47beta30+ RouterOS type devices. MAJOR CHANGES IN v6.47: ---------------------- !) dns - added client side support for DNS over HTTPS (DoH) (RFC8484); !) socks - added support for SOCKS5 (RFC 1928); !) user - enable "winbox" policy for groups with "dude" policy; ---------------------- Changes in this release: *) api - added ECDHE cipher support for "api-ssl" service; *) bonding - fixed ALB and TLB bonding modes after interface disable/enable (introduced in v6.47beta19); *) bonding - fixed packet receiving on bonding slave ports (introduced in v6.47beta19); *) bridge - added warning message when a bridge port gets dynamically added to VLAN range; *) chr - added support for hardware watchdog on ESXI; *) crs3xx - fixed tagged VLAN packet receiving on Ethernet interfaces for CRS354 devices (introduced in v6.47beta49); *) crs3xx - improved 10G interface initialization on CRS312 devices; *) dhcpv4-server - disallow zero lease-time setting; *) dhcpv6-server - do not require "server" parameter for bindings; *) dns - added support for multiple type static entries; *) dot1x - added "radius-mac-format" parameter; *) dot1x - improved Dot1X service stability when receiving bogus packets; *) dot1x - improved value validation for dynamically created switch rules; *) email - added support for multiple "to" recipients; *) ethernet - fixed interface stopping responding after blink command execution on CCR2004-1G-12S+2XS; *) filesystem - fixed NAND memory going into read-only mode or becoming unstable over time; *) health - improved stability for system health monitor on CCR2004-1G-12S+2XS; *) ike2 - added support for RFC8598; *) ike2 - allow initiator address change before authentication; *) ike2 - fixed authentication handling when initiator disconnects before RADIUS response; *) interface - improved system stability when receiving bogus packets; *) ipsec - added "split-dns" parameter support for mode configuration; *) ipsec - added "use-responder-dns" parameter support; *) ipsec - allow specifying two peers for a single policy for failover; *) ipsec - place dynamically created IPsec policies at the begining of the table; *) l2tp - added "src-address" parameter for L2TP client; *) l2tp - added "use-peer-dns" parameter for L2TP client; *) l2tp - improved dynamically created IPsec configuration updating; *) l2tp - use L2TP interface when adding dynamic IPsec peer; *) lcd - improved general system stability when LCD is not present; *) log - added logging entry when changing user's password; *) log - added tunnel endpoint address to establishment and disconnect logging entries; *) log - fixed logging topic for MAC address learning on a different bridge port events; *) log - made startup script failures log as critical errors; *) lte - fixed "band" parameter persistence after disable/enable; *) lte - fixed "ecno" and "rscp" value reporting on R11e-LTE6; *) lte - fixed VLAN interface passthrough support; *) lte - improved stability during firmware upgrade; *) netwatch - improved Netwatch service stability when invalid configuration values are passed; *) ovpn - added "use-peer-dns" parameter for OVPN client; *) poe - fixed missing PoE out settings on CRS354-48P-4S+2Q (introduced in v6.47beta49); *) port - removed serial console port on hEX S; *) ppp - removed "comment", "set" and "edit" commands from "PPP->Active" menu; *) pptp - added "use-peer-dns" parameter for PPTP client; *) profile - added support for CCR2004-1G-12S+2XS; *) qsfp - added support for FEC mode (fec74), with the FEC mode disabled by default *) quickset - fixed invalid configuration applying when performing changes during LTE modem initialization process; *) routerboard - added "hold-time" parameter to mode-button menu; *) routerboard - added "reset-button" menu - custom command execution with reset button; *) routing - improved routing service stability when receiving bogus packets; *) sfp28 - added support for FEC modes (fec74 and fec91), with fec91 mode already enabled by default; *) sfp28 - fixed interface linking after power cycle on CCR2004-1G-12S+2XS (introduced in v6.47beta49); *) switch - correctly enable and disable CPU Flow Control on RB3011UiAS; *) tr069-client - added LTE firmware update functionality support; *) tr069-client - added additional LTE information parameters; *) tr069-client - added additional wireless registration table parameters; *) tr069-client - added interface type parameter support; *) tr069-client - added multiple simultaneous session support for diagnostics test; *) tr069-client - added total connection tracking entries parameter; *) ups - added battery info for APC SmartUPS 2200; *) webfig - fixed 5GHz wireless interface "frequency" parameter value list on Audience; *) winbox - added "auth-info" parameter under "Dot1X->Active" menu; *) winbox - added "auth-types", "comment", "mac-auth-mode" and "reject-vlan-id" parameters for Dot1X server; *) winbox - added "bus" parameter for "USB Power Reset" command on NetMetal ac^2; *) winbox - added "comment" parameter and "dynamic" flag support under "Switch->Rule" table; *) winbox - added "comment" parameter for Dot1X client; *) winbox - added "region" parameter for W60G interfaces; *) winbox - added "skip-dfs-channels" parameter to wireless interface menu; *) winbox - added enable and disable buttons for "MPLS->MPLS Interface" table; *) winbox - do not allow to enter empty strings in "caps-man-names" and "common-name" parameters; *) winbox - fixed WDS usage when connecting to RouterOS access point using QuickSet; *) winbox - fixed dates and times in interface link up/down properties (WinBox v3.24 required); *) winbox - fixed wireless sniffer parameter setting; *) wireless - fixed Nstreme wireless protocol performance decrease; *) wireless - updated "egypt" regulatory domain information; Other changes since v6.46.6: *) bonding - improved slave interface MAC address handling; *) bonding - prefer primary slave MAC address for bonding interface; *) branding - do not ask to confirm configuration applied from branding package; *) branding - fixed identity setting from branding package; *) branding - improved branding package installation process when another branding package is already installed; *) branding - properly use HTML files for Hotspot (introduced in v6.47beta); *) bridge - added logging message when a host MAC address is learned on a different bridge port; *) bridge - added warning message when port is dynamically added to entry with VLAN range (CLI only); *) bridge - correctly remove disabled MSTI; *) bridge - improved hardware offloading enabling/disabling; *) certificate - added "skid" and "akid" values for detailed print; *) certificate - allow dynamic CRL removal; *) certificate - disabled CRL usage by default; *) certificate - do not use SSL for first CRL update; *) chr - added support for file system quiescing; *) chr - enabled support for VMBus protocol version 4.1; *) chr - improved system stability when running CHR on Hyper-V; *) crs3xx - correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices; *) crs3xx - do not change bridge host ID's when updating host table (introduced in v6.47beta32); *) crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices; *) crs3xx - fixed QSFP interface linking after removing/inserting QSFP module (introduced in v6.47beta49); *) crs3xx - fixed QSFP+ interface linking for CRS326-24S+2Q+ device (introduced in v6.47beta19); *) crs3xx - fixed hardware offloaded bonding on Ethernet interfaces for CRS354 devices; *) crs3xx - improved switch host table updating; *) crs3xx - improved system stability when creating multiple hardware offloaded bonding interfaces (introduced in v6.47beta49); *) crs3xx - show correct switch model for netPower 15FR device; *) defconf - fixed "no-defaults=yes" applying default configuration (introduced in v6.47beta); *) defconf - fixed default configuration initialization if power loss occurred during the process; *) dhcpv4 - added end option (255) validation for both server and client; *) dhcpv4-client - improved stability when changing client while still receiving advertisements; *) dhcpv4-server - disallow zero lease-time setting; *) dhcpv6-client - improved error logging when when renewed address differs; *) dhcpv6-server - fixed MAC address retrieving from DUID when timestamp is present; *) discovery - do not send discovery packets on inactive bonding slave interfaces; *) discovery - do not send discovery packets on interfaces that are blocked by STP; *) disk - improved disk management service stability when receiving bogus packets; *) disk - improved recently created file survival after reboots; *) dns - added support for exclusive dynamic DNS server usage from IPsec; *) dns - added support for forwarding DNS queries of static entries to specific server (CLI only); *) dns - added support for multiple type static entries (CLI only); *) dot1x - added "radius-mac-format" parameter (CLI only); *) dot1x - added hex value support for RADIUS switch rules; *) dot1x - added range "dst-port" support for RADIUS switch rules; *) dot1x - added support for lower case "mac-auth" RADIUS formats; *) dot1x - fixed "reject-vlan-id" value range; *) dot1x - fixed dynamically created switch rule removal when client disconnects; *) dot1x - fixed port blocking when interface changes state from disabled to enabled; *) dot1x - improved debug logging output to "dot1x" topic; *) dot1x - improved value validation for dynamically created switch rules; *) email - added support for multiple "to" recipients (CLI only); *) fetch - fixed "User-Agent" usage if provided by "http-header-field"; *) filesystem - fixed NAND memory going into read-only mode or becoming unstable over time; *) graphing - improved graphing service stability when receiving bogus packets; *) health - added "gauges" submenu with SNMP OID reporting; *) hotspot - updated splash page design ('/ip hotspot reset-html' required); *) ike1 - added error message when specifying "my-id" for XAuth Identity; *) ike1 - added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes; *) ike1 - do not try to keep phase 2 when purging phase 1; *) ike1 - improved policy lookup with specific protocol; *) ike1 - improved stability when performing policy lookup on non-existant peer; *) ike2 - added support for "INTERNAL_DNS_DOMAIN" payload attribute; *) ike2 - added support for RADIUS Disconnect-Request message handling; *) interface - increased loopback interface MTU to 65536; *) ipsec - added "split-dns" parameter support for mode configuration (CLI only); *) ipsec - added "use-responder-dns" parameter support (CLI only); *) ipsec - allow specifying two peers for a single policy for failover (CLI only); *) ipsec - control CRL validation with global "use-crl" setting; *) ipsec - do full certificate validation for identities with explicit certificate; *) ipsec - fixed minor spelling mistake in logs; *) ipsec - improved IPsec service stability when receiving bogus packets; *) kidcontrol - ignore IPv6 multicast MAC addresses; *) lcd - fixed LCD service becoming unavailable on devices without LCD screen; *) led - fixed minor typo in LED warning message; *) lte - added support for Huawei K5161 modem; *) lte - added support for NEOWAY N720; *) lte - added support for multiple passthrough APN configuration; *) lte - do not allow running "scan" on R11e-4G; *) lte - fixed "allow-roaming" setting when using LTE network mode on R11e-LTE; *) lte - fixed multiple APN reactivation after deactivation by operator; *) lte - improved stability during firmware upgrade process; *) lte - made "mac-address" parameter read-only; *) lte - show "phy-cellid" value only in LTE mode; *) netinstall - removed "Flashfig" from Netinstall; *) netinstall - removed "Make Floppy" from Netinstall; *) netinstall - signed netinstall.exe with Digital Signature; *) ppp - added support for ZTE MF90; *) ppp - fixed minor typo when running "info" command; *) proxy - increased minimal free RAM that can not be used for proxy services; *) quickset - do not show "SINR" field in Quick Set when there is no data; *) quickset - removed "EARFCN" field from Quick Set; *) quickset - removed "LTE band" setting from Quick Set; *) quickset - show "Antenna Gain" setting on devices without built-in antennas; *) quickset - use "station-wds" mode when connecting to AP with RouterOS flag; *) route - improved system stability after reboot with large amount of VLAN interfaces with PPPoE servers attached; *) routerboard - added "hold-time" parameter to mode-button menu (CLI only); *) routerboard - added "reset-button" menu - custom command execution with reset button (CLI only); *) routing - improved IGMP-Proxy service stability when receiving bogus packets; *) sniffer - allow setting port for "streaming-server"; *) snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB; *) snmp - changed "upsEstimatedMinutesRemaining" reported value from seconds to minutes; *) snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB; *) snmp - improved OID policy checking and error reporting on "set" command; *) snmp - improved stability when polling MAC address related OID; *) ssh - improved SSH service stability when receiving bogus packets; *) supout - added "dot1x" section to supout files; *) supout - improved UPS information reporting; *) switch - correctly display switch statistics when all switch ports are disabled on RTL8367 switch chip; *) switch - fixed missing switch statistics (introduced in v6.47beta49); *) switch - made "auto" the default value for "vlan-id" parameter when creating a new static host entry; *) system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic; *) system - improved driver loading speed on startup; *) tr069-client - removed warning log message when not using HTTPS; *) traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9; *) upgrade - fixed space handling in package file names; *) ups - improved compatibility with APC Smart UPS 1000 and 1500; *) user - improved user management service stability when receiving bogus packets; *) w60g - fixed link status logging; *) w60g - improved rate selection in low traffic conditions; *) w60g - use "arp" and "mtu" parameters from master interface when creating a new station; *) webfig - fixed WinBox download link; *) webfig - fixed skin usage from branding package; *) webfig - updated icon design; *) winbox - added "Rate" parameter for switch ACL rules; *) winbox - added "auto-erase" option to "Tool/SMS" menu; *) winbox - added "bus" parameter for "USB Power Reset" command on RBM33G; *) winbox - added comment support for "Switch->VLAN" menu; *) winbox - added support for inline bar graphs for LTE signal values; *) winbox - aligned all "IP->Traffic Flow->IPFIX" check boxes in single line (WinBox v3.22 required); *) winbox - allow setting "Primary" parameter for "balance-tlb" bonding interfaces; *) winbox - allow to specify any ethernet like interface under "Tool/WoL" menu; *) winbox - fixed "BGP Origin" value display under "IPv6->Routes" menu; *) winbox - fixed "Data Rate" checkbox alignment (WinBox v3.22 required); *) winbox - fixed "Tx/Rx Signal Strength" value presence for 4 chain interfaces; *) winbox - fixed bonding type interface support for "Switch->Host" table; *) winbox - fixed wireless interface "HT" tab setting presence when "band=5ghz-n/ac"; *) winbox - limit number of simultaneous WinBox sessions to 5 for users without "write" permission; *) winbox - made "yes" the default value for "Inject Summary LSAs" parameter when creating a new NSSA or STUB area; *) winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic"; *) winbox - renamed "Routerboard" to "RouterBOARD" under "System/RouterBOARD" menu; *) winbox - show "Hardware Offload" parameter for bonding interfaces; *) winbox - updated icon design; *) wireless - added "russia 6ghz" regulatory domain information; *) wireless - allow using "russia4" regulatory domain on RU locked devices; *) wireless - enabled unicast flood for DHCP traffic on ARM architecture access points; *) wireless - improved management service stability when receiving bogus packets; *) wireless - updated "russia4" regulatory domain information; *) www - added "tls-version" parameter in "IP->Services" menu (CLI only);
      Important note!!! - The Dude server must be updated to monitor v6.46.4 and v6.47beta30+ RouterOS type devices. - The Dude client must be manually upgraded after upgrading The Dude server. - Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used. - The Dude requires "winbox" policy instead of "dude" to monitor v6.46.4 and v6.47beta30+ RouterOS type devices. MAJOR CHANGES IN v6.47: ---------------------- !) dns - added client side support for DNS over HTTPS (DoH) (RFC8484); !) socks - added support for SOCKS5 (RFC 1928); !) user - enable "winbox" policy for groups with "dude" policy; ---------------------- Changes in this release: !) dns - added client side support for DNS over HTTPS (DoH) (RFC8484); !) socks - added support for SOCKS5 (RFC 1928); *) branding - improved branding package installation process when another branding package is already installed; *) chr - enabled support for VMBus protocol version 4.1; *) chr - improved system stability when running CHR on Hyper-V; *) crs3xx - fixed hardware offloaded bonding on Ethernet interfaces for CRS354 devices; *) crs3xx - fixed switch rule "dst-port" parameter for IPv6 traffic on CRS305-1G-4S+, CRS326-24G-2S+, CRS328-24P-4S+, CRS328-4C-20S-4S+, netPower 15FR devices; *) crs3xx - improved system stability when creating multiple hardware offloaded bonding interfaces (introduced in v6.47beta49); *) crs3xx - show correct switch model for netPower 15FR device; *) defconf - fixed default IP address assigning on non-paired 60 GHz devices; *) disk - improved disk management service stability when receiving bogus packets; *) dns - added support for forwarding DNS queries of static entries to specific server (CLI only); *) dns - added support for multiple type static entries (CLI only); *) email - added support for multiple "to" recipients (CLI only); *) graphing - improved graphing service stability when receiving bogus packets; *) ike1 - do not try to keep phase 2 when purging phase 1; *) ike2 - added support for RADIUS Disconnect-Request message handling; *) interface - increased loopback interface MTU to 65536; *) ipsec - allow specifying two peers for a single policy for failover (CLI only); *) lora - added "altitude", "latitude" and "longitude" to stat json if GPS is available; *) lte - improved stability during firmware upgrade process; *) routerboard - added "hold-time" parameter to mode-button menu (CLI only); *) routerboard - added "reset-button" menu - custom command execution with reset button (CLI only); *) snmp - fixed "ifSpeed" reporting for tunnel interfaces; *) ssh - improved SSH service stability when receiving bogus packets; *) switch - correctly display switch statistics when all switch ports are disabled on RTL8367 switch chip; *) switch - fixed missing switch statistics (introduced in v6.47beta49); *) user - improved user management service stability when receiving bogus packets; *) webfig - fixed WinBox download link; *) webfig - fixed skin usage from branding package; *) winbox - added "bus" parameter for "USB Power Reset" command on RBM33G; *) winbox - allow to specify any ethernet like interface under "Tool/WoL" menu; *) winbox - fixed "Tx/Rx Signal Strength" value presence for 4 chain interfaces; *) winbox - fixed memory leak (introduced in v6.46.4); *) winbox - fixed wireless interface "HT" tab setting presence when "band=5ghz-n/ac"; *) winbox - increased limit of multi-entry fields to 100; *) winbox - limit number of simultaneous WinBox sessions to 5 for users without "write" permission; *) wireless - improved management service stability when receiving bogus packets; *) wireless - updated "south africa" regulatory domain information; Other changes since v6.46.5: *) bonding - improved slave interface MAC address handling; *) bonding - prefer primary slave MAC address for bonding interface; *) branding - do not ask to confirm configuration applied from branding package; *) branding - fixed identity setting from branding package; *) branding - properly use HTML files for Hotspot (introduced in v6.47beta); *) bridge - added logging message when a host MAC address is learned on a different bridge port; *) bridge - added warning message when port is dynamically added to entry with VLAN range (CLI only); *) bridge - correctly remove disabled MSTI; *) bridge - improved hardware offloading enabling/disabling; *) certificate - added "skid" and "akid" values for detailed print; *) certificate - allow dynamic CRL removal; *) certificate - disabled CRL usage by default; *) certificate - do not use SSL for first CRL update; *) chr - added support for file system quiescing; *) crs3xx - correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices; *) crs3xx - do not change bridge host ID's when updating host table (introduced in v6.47beta32); *) crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices; *) crs3xx - fixed QSFP interface linking after removing/inserting QSFP module (introduced in v6.47beta49); *) crs3xx - fixed QSFP+ interface linking for CRS326-24S+2Q+ device (introduced in v6.47beta19); *) crs3xx - improved switch host table updating; *) defconf - fixed "no-defaults=yes" applying default configuration (introduced in v6.47beta); *) defconf - fixed default configuration initialization if power loss occurred during the process; *) dhcpv4 - added end option (255) validation for both server and client; *) dhcpv4-client - improved stability when changing client while still receiving advertisements; *) dhcpv4-server - disallow zero lease-time setting; *) dhcpv6-client - improved error logging when when renewed address differs; *) dhcpv6-server - fixed MAC address retrieving from DUID when timestamp is present; *) discovery - do not send discovery packets on inactive bonding slave interfaces; *) discovery - do not send discovery packets on interfaces that are blocked by STP; *) disk - improved recently created file survival after reboots; *) dns - added support for exclusive dynamic DNS server usage from IPsec; *) dot1x - added "radius-mac-format" parameter (CLI only); *) dot1x - added hex value support for RADIUS switch rules; *) dot1x - added range "dst-port" support for RADIUS switch rules; *) dot1x - added support for lower case "mac-auth" RADIUS formats; *) dot1x - fixed "reject-vlan-id" value range; *) dot1x - fixed dynamically created switch rule removal when client disconnects; *) dot1x - fixed port blocking when interface changes state from disabled to enabled; *) dot1x - improved debug logging output to "dot1x" topic; *) dot1x - improved value validation for dynamically created switch rules; *) fetch - fixed "User-Agent" usage if provided by "http-header-field"; *) filesystem - fixed NAND memory going into read-only mode or becoming unstable over time; *) health - added "gauges" submenu with SNMP OID reporting; *) hotspot - updated splash page design ('/ip hotspot reset-html' required); *) ike1 - added error message when specifying "my-id" for XAuth Identity; *) ike1 - added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes; *) ike1 - improved policy lookup with specific protocol; *) ike1 - improved stability when performing policy lookup on non-existant peer; *) ike2 - added support for "INTERNAL_DNS_DOMAIN" payload attribute; *) ipsec - added "split-dns" parameter support for mode configuration (CLI only); *) ipsec - added "use-responder-dns" parameter support (CLI only); *) ipsec - control CRL validation with global "use-crl" setting; *) ipsec - do full certificate validation for identities with explicit certificate; *) ipsec - fixed minor spelling mistake in logs; *) ipsec - improved IPsec service stability when receiving bogus packets; *) kidcontrol - ignore IPv6 multicast MAC addresses; *) lcd - fixed LCD service becoming unavailable on devices without LCD screen; *) led - fixed minor typo in LED warning message; *) lte - added support for Huawei K5161 modem; *) lte - added support for NEOWAY N720; *) lte - added support for multiple passthrough APN configuration; *) lte - do not allow running "scan" on R11e-4G; *) lte - fixed "allow-roaming" setting when using LTE network mode on R11e-LTE; *) lte - fixed "band" value setting when configuration is reset on R11e-4G; *) lte - fixed multiple APN reactivation after deactivation by operator; *) lte - made "mac-address" parameter read-only; *) lte - show "phy-cellid" value only in LTE mode; *) netinstall - removed "Flashfig" from Netinstall; *) netinstall - removed "Make Floppy" from Netinstall; *) netinstall - signed netinstall.exe with Digital Signature; *) ppp - added support for ZTE MF90; *) ppp - fixed minor typo when running "info" command; *) proxy - increased minimal free RAM that can not be used for proxy services; *) quickset - do not show "SINR" field in Quick Set when there is no data; *) quickset - removed "EARFCN" field from Quick Set; *) quickset - removed "LTE band" setting from Quick Set; *) quickset - show "Antenna Gain" setting on devices without built-in antennas; *) quickset - use "station-wds" mode when connecting to AP with RouterOS flag; *) route - improved system stability after reboot with large amount of VLAN interfaces with PPPoE servers attached; *) routing - improved IGMP-Proxy service stability when receiving bogus packets; *) sniffer - allow setting port for "streaming-server"; *) snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB; *) snmp - changed "upsEstimatedMinutesRemaining" reported value from seconds to minutes; *) snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB; *) snmp - fixed multiple LTE interface OID reporting; *) snmp - improved OID policy checking and error reporting on "set" command; *) snmp - improved stability when polling MAC address related OID; *) ssh - fixed SHA256 user authentication algorithm checking (introduced in v6.46.4); *) supout - added "dot1x" section to supout files; *) supout - improved UPS information reporting; *) switch - made "auto" the default value for "vlan-id" parameter when creating a new static host entry; *) system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic; *) system - improved driver loading speed on startup; *) tr069-client - removed warning log message when not using HTTPS; *) traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9; *) upgrade - fixed space handling in package file names; *) ups - improved compatibility with APC Smart UPS 1000 and 1500; *) w60g - fixed link status logging; *) w60g - improved rate selection in low traffic conditions; *) w60g - use "arp" and "mtu" parameters from master interface when creating a new station; *) webfig - updated icon design; *) winbox - added "Rate" parameter for switch ACL rules; *) winbox - added "auto-erase" option to "Tool/SMS" menu; *) winbox - added comment support for "Switch->VLAN" menu; *) winbox - added support for inline bar graphs for LTE signal values; *) winbox - aligned all "IP->Traffic Flow->IPFIX" check boxes in single line (WinBox v3.22 required); *) winbox - allow setting "Primary" parameter for "balance-tlb" bonding interfaces; *) winbox - fixed "BGP Origin" value display under "IPv6->Routes" menu; *) winbox - fixed "Data Rate" checkbox alignment (WinBox v3.22 required); *) winbox - fixed bonding type interface support for "Switch->Host" table; *) winbox - made "yes" the default value for "Inject Summary LSAs" parameter when creating a new NSSA or STUB area; *) winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic"; *) winbox - renamed "Routerboard" to "RouterBOARD" under "System/RouterBOARD" menu; *) winbox - show "Hardware Offload" parameter for bonding interfaces; *) winbox - updated icon design; *) wireless - added "russia 6ghz" regulatory domain information; *) wireless - allow using "russia4" regulatory domain on RU locked devices; *) wireless - enabled unicast flood for DHCP traffic on ARM architecture access points; *) wireless - improved 5GHz interface stability on RB4011iGS+5HacQ2HnD and Audience; *) wireless - improved system stability on hAP ac^2; *) wireless - updated "russia4" regulatory domain information; *) www - added "tls-version" parameter in "IP->Services" menu (CLI only);
      Important note!!! - The Dude server must be updated to monitor v6.46.4 and v6.47beta30+ RouterOS type devices. - The Dude client must be manually upgraded after upgrading The Dude server. - Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used. - The Dude requires "winbox" policy instead of "dude" to monitor v6.46.4 and v6.47beta30+ RouterOS type devices. MAJOR CHANGES IN v6.47: ---------------------- !) dns - added client side support for DNS over HTTPS (DoH) (RFC8484); !) socks - added support for SOCKS5 (RFC 1928); !) user - enable "winbox" policy for groups with "dude" policy; ---------------------- Changes in this release: !) socks - added support for SOCKS5 (RFC 1928); *) branding - do not ask to confirm configuration applied from branding package; *) certificate - added "skid" and "akid" values for detailed print; *) certificate - allow dynamic CRL removal; *) console - prevent incorrect type interfaces appearing in command hints; *) crs3xx - fixed QSFP interface linking after removing/inserting QSFP module (introduced in v6.47beta49); *) dhcpv4-server - disallow zero lease-time setting; *) filesystem - fixed NAND memory going into read-only mode or becoming unstable over time; *) ike1 - improved policy lookup with specific protocol; *) ike1 - rekey phase 1 rekeying as responder for Windows initiators; *) ipsec - improved system stability when handling fragmented packets; *) kidcontrol - ignore IPv6 multicast MAC addresses; *) lora - added IPv6 support for LoRa packet forwarder; *) lora - added UTC timestamp for RX events in "rxpk" json; *) lte - added support for Huawei K5161 modem; *) lte - fixed IP type selection from APN on RBSXTLTE3-7; *) snmp - fixed multiple LTE interface OID reporting; *) system - improved kernel panic reporting in logs after reboot; *) wireless - added "russia 6ghz" regulatory domain information; *) wireless - added "skip-dfs-channels" parameter; *) wireless - updated "bangladesh" regulatory domain information; *) wireless - updated "russia4" regulatory domain information; Other changes since v6.46.4: *) bonding - improved slave interface MAC address handling; *) bonding - prefer primary slave MAC address for bonding interface; *) branding - fixed identity setting from branding package; *) branding - properly use HTML files for Hotspot (introduced in v6.47beta); *) bridge - added logging message when a host MAC address is learned on a different bridge port; *) bridge - added warning message when port is dynamically added to entry with VLAN range (CLI only); *) bridge - correctly remove disabled MSTI; *) bridge - improved hardware offloading enabling/disabling; *) capsman - fixed "certificate" parameter updating on CAP; *) certificate - disabled CRL usage by default; *) certificate - do not use SSL for first CRL update; *) chr - added support for file system quiescing; *) crs3xx - correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices; *) crs3xx - do not change bridge host ID's when updating host table (introduced in v6.47beta32); *) crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices; *) crs3xx - fixed QSFP+ interface linking for CRS326-24S+2Q+ device (introduced in v6.47beta19); *) crs3xx - fixed interface statistics for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices; *) crs3xx - fixed traffic forwarding after disabling/enabling bridge hardware offloading for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices; *) crs3xx - improved SFP+ DAC cable initialization for CRS326-24S+2Q+ device; *) crs3xx - improved switch host table updating; *) defconf - fixed "no-defaults=yes" applying default configuration (introduced in v6.47beta); *) defconf - fixed default configuration initialization if power loss occurred during the process; *) dhcpv4 - added end option (255) validation for both server and client; *) dhcpv4-client - improved stability when changing client while still receiving advertisements; *) dhcpv6-client - improved error logging when when renewed address differs; *) dhcpv6-server - fixed MAC address retrieving from DUID when timestamp is present; *) discovery - do not send CDP and LLDP packets on interfaces that does not have MAC address; *) discovery - do not send discovery packets on inactive bonding slave interfaces; *) discovery - do not send discovery packets on interfaces that are blocked by STP; *) disk - improved recently created file survival after reboots; *) dns - added support for exclusive dynamic DNS server usage from IPsec; *) dot1x - added "radius-mac-format" parameter (CLI only); *) dot1x - added hex value support for RADIUS switch rules; *) dot1x - added range "dst-port" support for RADIUS switch rules; *) dot1x - added support for lower case "mac-auth" RADIUS formats; *) dot1x - fixed "reject-vlan-id" value range; *) dot1x - fixed dynamically created switch rule removal when client disconnects; *) dot1x - fixed port blocking when interface changes state from disabled to enabled; *) dot1x - improved debug logging output to "dot1x" topic; *) dot1x - improved value validation for dynamically created switch rules; *) dude - fixed connection to other RouterOS type devices through The Dude agents (introduced in v6.46.4); *) fetch - fixed "User-Agent" usage if provided by "http-header-field"; *) filesystem - fixed NAND memory going into read-only mode or becoming unstable over time; *) health - added "gauges" submenu with SNMP OID reporting; *) hotspot - updated splash page design ('/ip hotspot reset-html' required); *) ike1 - added error message when specifying "my-id" for XAuth Identity; *) ike1 - added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes; *) ike1 - improved stability when performing policy lookup on non-existant peer; *) ike2 - added support for "INTERNAL_DNS_DOMAIN" payload attribute; *) ipsec - added "split-dns" parameter support for mode configuration (CLI only); *) ipsec - added "use-responder-dns" parameter support (CLI only); *) ipsec - control CRL validation with global "use-crl" setting; *) ipsec - do full certificate validation for identities with explicit certificate; *) ipsec - fixed minor spelling mistake in logs; *) ipsec - improved IPsec service stability when receiving bogus packets; *) lcd - fixed LCD service becoming unavailable on devices without LCD screen; *) led - added "dark-mode" functionality for CRS105-5S-FB; *) led - fixed minor typo in LED warning message; *) lora - added IPv6 support for LoRa packet forwarder; *) lora - added value limits for "freq-off" parameter; *) lora - properly update source address for packets when routing table is changed; *) lte - added support for NEOWAY N720; *) lte - added support for multiple passthrough APN configuration; *) lte - do not allow running "scan" on R11e-4G; *) lte - fixed "allow-roaming" setting when using LTE network mode on R11e-LTE; *) lte - fixed "band" value setting when configuration is reset on R11e-4G; *) lte - fixed multiple APN reactivation after deactivation by operator; *) lte - made "mac-address" parameter read-only; *) lte - show "phy-cellid" value only in LTE mode; *) netinstall - removed "Flashfig" from Netinstall; *) netinstall - removed "Make Floppy" from Netinstall; *) netinstall - signed netinstall.exe with Digital Signature; *) ppp - added support for ZTE MF90; *) ppp - fixed minor typo when running "info" command; *) proxy - increased minimal free RAM that can not be used for proxy services; *) quickset - do not show "SINR" field in Quick Set when there is no data; *) quickset - removed "EARFCN" field from Quick Set; *) quickset - removed "LTE band" setting from Quick Set; *) quickset - show "Antenna Gain" setting on devices without built-in antennas; *) quickset - use "station-wds" mode when connecting to AP with RouterOS flag; *) route - improved system stability after reboot with large amount of VLAN interfaces with PPPoE servers attached; *) routing - improved IGMP-Proxy service stability when receiving bogus packets; *) sniffer - allow setting port for "streaming-server"; *) sniffer - fixed minor typo in "host" menu; *) snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB; *) snmp - changed "upsEstimatedMinutesRemaining" reported value from seconds to minutes; *) snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB; *) snmp - improved OID policy checking and error reporting on "set" command; *) snmp - improved stability when polling MAC address related OID; *) ssh - fixed SHA256 user authentication algorithm checking (introduced in v6.46.4); *) supout - added "dot1x" section to supout files; *) supout - added "gps" section to supout files; *) supout - improved PoE-out information reporting; *) supout - improved UPS information reporting; *) switch - made "auto" the default value for "vlan-id" parameter when creating a new static host entry; *) system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic; *) system - improved driver loading speed on startup; *) system - improved system stability when forwarding traffic from switch chip to CPU (introduced in v6.43); *) tr069-client - removed warning log message when not using HTTPS; *) traceroute - improved stability when invalid packet is received; *) traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9; *) traffic-generator - improved statistics reporting; *) upgrade - fixed space handling in package file names; *) ups - improved compatibility with APC Smart UPS 1000 and 1500; *) w60g - fixed link status logging; *) w60g - improved rate selection in low traffic conditions; *) w60g - improved stability after multiple disconnections; *) w60g - use "arp" and "mtu" parameters from master interface when creating a new station; *) webfig - updated icon design; *) winbox - added "Options" parameter support for DHCPv6 client and server; *) winbox - added "Rate" parameter for switch ACL rules; *) winbox - added "auto-erase" option to "Tool/SMS" menu; *) winbox - added 160Mhz extension channel support for CAPsMAN; *) winbox - added comment support for "Switch->VLAN" menu; *) winbox - added support for "Tools->WoL" menu; *) winbox - added support for inline bar graphs for LTE signal values; *) winbox - aligned all "IP->Traffic Flow->IPFIX" check boxes in single line (WinBox v3.22 required); *) winbox - allow setting "20/40/80/160Mhz-eeeeeeCe" channel under "Channel Width" parameter; *) winbox - allow setting "Primary" parameter for "balance-tlb" bonding interfaces; *) winbox - do not show "Revision" parameter under "System/RouterBOARD" menu on devices that have only one revision; *) winbox - fixed "ARP" parameter inheritance from "CAPs Configuration" configuration; *) winbox - fixed "BGP Origin" value display under "IPv6->Routes" menu; *) winbox - fixed "Bands" parameter display for LTE interfaces; *) winbox - fixed "DSCP" parameter value setting; *) winbox - fixed "Data Rate" checkbox alignment (WinBox v3.22 required); *) winbox - fixed "Frequency" and "Secondary Frequency" parameter inheritance from "CAPs Channel" configuration; *) winbox - fixed "Passthr. MAC Address" parameter display "LTE APNs" menu; *) winbox - fixed "Switch" menu on CRS354-48P-4S+2Q+; *) winbox - fixed "dst-port" unsetting in "IP->Hotspot->Walled Garden" menu; *) winbox - fixed automatic "IPv6->Firewall->Address List" table update; *) winbox - fixed bonding type interface support for "Switch->Host" table; *) winbox - made "none" the default value for "Security Profile" parameter when creating a new "Wirelees->Connect list" entry; *) winbox - made "yes" the default value for "Inject Summary LSAs" parameter when creating a new NSSA or STUB area; *) winbox - properly show "Hw. Offload Group" value for each interface under "Bridge->Ports" menu; *) winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic"; *) winbox - renamed "Memory used" to "HDD used" for HDD type under "Tools->Graphing->Resource Graphs"; *) winbox - renamed "Routerboard" to "RouterBOARD" under "System/RouterBOARD" menu; *) winbox - show "Hardware Offload" parameter for bonding interfaces; *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature; *) winbox - updated icon design; *) wireless - added "U-NII-2" support for hAP ac2 and RBwAPGR series devices; *) wireless - allow using "russia4" regulatory domain on RU locked devices; *) wireless - enabled unicast flood for DHCP traffic on ARM architecture access points; *) wireless - fixed default "antenna-gain" setting on SXT 2 and LtAP series devices; *) wireless - updated "indonesia4" regulatory domain information; *) www - added "tls-version" parameter in "IP->Services" menu (CLI only);
      Important note!!! - The Dude server must be updated to monitor v6.46.4 and v6.47beta30+ RouterOS type devices. - The Dude client must be manually upgraded after upgrading The Dude server. - Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used. - The Dude requires "winbox" policy instead of "dude" to monitor v6.46.4 and v6.47beta30+ RouterOS type devices. MAJOR CHANGES IN v6.47: ---------------------- !) dns - added client side support for DNS over HTTPS (DoH) (RFC8484); !) socks - added support for SOCKS5 (RFC 1928); !) user - enable "winbox" policy for groups with "dude" policy; ---------------------- Changes in this release: *) wireless - improved 5GHz interface stability on RB4011iGS+5HacQ2HnD and Audience; *) wireless - improved system stability on hAP ac^2; Other changes since v6.46.4: *) bonding - improved slave interface MAC address handling; *) bonding - prefer primary slave MAC address for bonding interface; *) branding - do not ask to confirm configuration applied from branding package; *) branding - fixed identity setting from branding package; *) branding - properly use HTML files for Hotspot (introduced in v6.47beta); *) bridge - added logging message when a host MAC address is learned on a different bridge port; *) bridge - added warning message when port is dynamically added to entry with VLAN range (CLI only); *) bridge - correctly remove disabled MSTI; *) bridge - improved hardware offloading enabling/disabling; *) capsman - fixed "certificate" parameter updating on CAP; *) certificate - added "skid" and "akid" values for detailed print; *) certificate - allow dynamic CRL removal; *) certificate - disabled CRL usage by default; *) certificate - do not use SSL for first CRL update; *) chr - added support for file system quiescing; *) console - prevent incorrect type interfaces appearing in command hints; *) crs3xx - correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices; *) crs3xx - do not change bridge host ID's when updating host table (introduced in v6.47beta32); *) crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices; *) crs3xx - fixed QSFP interface linking after removing/inserting QSFP module (introduced in v6.47beta49); *) crs3xx - fixed QSFP+ interface linking for CRS326-24S+2Q+ device (introduced in v6.47beta19); *) crs3xx - fixed interface statistics for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices; *) crs3xx - fixed traffic forwarding after disabling/enabling bridge hardware offloading for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices; *) crs3xx - improved SFP+ DAC cable initialization for CRS326-24S+2Q+ device; *) crs3xx - improved switch host table updating; *) defconf - fixed "no-defaults=yes" applying default configuration (introduced in v6.47beta); *) defconf - fixed default configuration initialization if power loss occurred during the process; *) dhcpv4 - added end option (255) validation for both server and client; *) dhcpv4-client - improved stability when changing client while still receiving advertisements; *) dhcpv4-server - disallow zero lease-time setting; *) dhcpv6-client - improved error logging when when renewed address differs; *) dhcpv6-server - fixed MAC address retrieving from DUID when timestamp is present; *) discovery - do not send CDP and LLDP packets on interfaces that does not have MAC address; *) discovery - do not send discovery packets on inactive bonding slave interfaces; *) discovery - do not send discovery packets on interfaces that are blocked by STP; *) disk - improved recently created file survival after reboots; *) dns - added support for exclusive dynamic DNS server usage from IPsec; *) dot1x - added "radius-mac-format" parameter (CLI only); *) dot1x - added hex value support for RADIUS switch rules; *) dot1x - added range "dst-port" support for RADIUS switch rules; *) dot1x - added support for lower case "mac-auth" RADIUS formats; *) dot1x - fixed "reject-vlan-id" value range; *) dot1x - fixed dynamically created switch rule removal when client disconnects; *) dot1x - fixed port blocking when interface changes state from disabled to enabled; *) dot1x - improved debug logging output to "dot1x" topic; *) dot1x - improved value validation for dynamically created switch rules; *) dude - fixed connection to other RouterOS type devices through The Dude agents (introduced in v6.46.4); *) fetch - fixed "User-Agent" usage if provided by "http-header-field"; *) filesystem - fixed NAND memory going into read-only mode or becoming unstable over time; *) health - added "gauges" submenu with SNMP OID reporting; *) hotspot - updated splash page design ('/ip hotspot reset-html' required); *) ike1 - added error message when specifying "my-id" for XAuth Identity; *) ike1 - added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes; *) ike1 - improved policy lookup with specific protocol; *) ike1 - improved stability when performing policy lookup on non-existant peer; *) ike1 - rekey phase 1 rekeying as responder for Windows initiators; *) ike2 - added support for "INTERNAL_DNS_DOMAIN" payload attribute; *) ipsec - added "split-dns" parameter support for mode configuration (CLI only); *) ipsec - added "use-responder-dns" parameter support (CLI only); *) ipsec - control CRL validation with global "use-crl" setting; *) ipsec - do full certificate validation for identities with explicit certificate; *) ipsec - fixed minor spelling mistake in logs; *) ipsec - improved IPsec service stability when receiving bogus packets; *) ipsec - improved system stability when handling fragmented packets; *) kidcontrol - ignore IPv6 multicast MAC addresses; *) lcd - fixed LCD service becoming unavailable on devices without LCD screen; *) led - added "dark-mode" functionality for CRS105-5S-FB; *) led - fixed minor typo in LED warning message; *) lora - added IPv6 support for LoRa packet forwarder; *) lora - added UTC timestamp for RX events in "rxpk" json; *) lora - added value limits for "freq-off" parameter; *) lora - properly update source address for packets when routing table is changed; *) lte - added support for Huawei K5161 modem; *) lte - added support for NEOWAY N720; *) lte - added support for multiple passthrough APN configuration; *) lte - do not allow running "scan" on R11e-4G; *) lte - fixed "allow-roaming" setting when using LTE network mode on R11e-LTE; *) lte - fixed "band" value setting when configuration is reset on R11e-4G; *) lte - fixed IP type selection from APN on RBSXTLTE3-7; *) lte - fixed multiple APN reactivation after deactivation by operator; *) lte - made "mac-address" parameter read-only; *) lte - show "phy-cellid" value only in LTE mode; *) netinstall - removed "Flashfig" from Netinstall; *) netinstall - removed "Make Floppy" from Netinstall; *) netinstall - signed netinstall.exe with Digital Signature; *) ppp - added support for ZTE MF90; *) ppp - fixed minor typo when running "info" command; *) proxy - increased minimal free RAM that can not be used for proxy services; *) quickset - do not show "SINR" field in Quick Set when there is no data; *) quickset - removed "EARFCN" field from Quick Set; *) quickset - removed "LTE band" setting from Quick Set; *) quickset - show "Antenna Gain" setting on devices without built-in antennas; *) quickset - use "station-wds" mode when connecting to AP with RouterOS flag; *) route - improved system stability after reboot with large amount of VLAN interfaces with PPPoE servers attached; *) routing - improved IGMP-Proxy service stability when receiving bogus packets; *) sniffer - allow setting port for "streaming-server"; *) sniffer - fixed minor typo in "host" menu; *) snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB; *) snmp - changed "upsEstimatedMinutesRemaining" reported value from seconds to minutes; *) snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB; *) snmp - fixed multiple LTE interface OID reporting; *) snmp - improved OID policy checking and error reporting on "set" command; *) snmp - improved stability when polling MAC address related OID; *) ssh - fixed SHA256 user authentication algorithm checking (introduced in v6.46.4); *) supout - added "dot1x" section to supout files; *) supout - added "gps" section to supout files; *) supout - improved PoE-out information reporting; *) supout - improved UPS information reporting; *) switch - made "auto" the default value for "vlan-id" parameter when creating a new static host entry; *) system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic; *) system - improved driver loading speed on startup; *) system - improved kernel panic reporting in logs after reboot; *) system - improved system stability when forwarding traffic from switch chip to CPU (introduced in v6.43); *) tr069-client - removed warning log message when not using HTTPS; *) traceroute - improved stability when invalid packet is received; *) traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9; *) traffic-generator - improved statistics reporting; *) upgrade - fixed space handling in package file names; *) ups - improved compatibility with APC Smart UPS 1000 and 1500; *) w60g - fixed link status logging; *) w60g - improved rate selection in low traffic conditions; *) w60g - improved stability after multiple disconnections; *) w60g - use "arp" and "mtu" parameters from master interface when creating a new station; *) webfig - updated icon design; *) winbox - added "Options" parameter support for DHCPv6 client and server; *) winbox - added "Rate" parameter for switch ACL rules; *) winbox - added "auto-erase" option to "Tool/SMS" menu; *) winbox - added 160Mhz extension channel support for CAPsMAN; *) winbox - added comment support for "Switch->VLAN" menu; *) winbox - added support for "Tools->WoL" menu; *) winbox - added support for inline bar graphs for LTE signal values; *) winbox - aligned all "IP->Traffic Flow->IPFIX" check boxes in single line (WinBox v3.22 required); *) winbox - allow setting "20/40/80/160Mhz-eeeeeeCe" channel under "Channel Width" parameter; *) winbox - allow setting "Primary" parameter for "balance-tlb" bonding interfaces; *) winbox - do not show "Revision" parameter under "System/RouterBOARD" menu on devices that have only one revision; *) winbox - fixed "ARP" parameter inheritance from "CAPs Configuration" configuration; *) winbox - fixed "BGP Origin" value display under "IPv6->Routes" menu; *) winbox - fixed "Bands" parameter display for LTE interfaces; *) winbox - fixed "DSCP" parameter value setting; *) winbox - fixed "Data Rate" checkbox alignment (WinBox v3.22 required); *) winbox - fixed "Frequency" and "Secondary Frequency" parameter inheritance from "CAPs Channel" configuration; *) winbox - fixed "Passthr. MAC Address" parameter display "LTE APNs" menu; *) winbox - fixed "Switch" menu on CRS354-48P-4S+2Q+; *) winbox - fixed "dst-port" unsetting in "IP->Hotspot->Walled Garden" menu; *) winbox - fixed automatic "IPv6->Firewall->Address List" table update; *) winbox - fixed bonding type interface support for "Switch->Host" table; *) winbox - made "none" the default value for "Security Profile" parameter when creating a new "Wirelees->Connect list" entry; *) winbox - made "yes" the default value for "Inject Summary LSAs" parameter when creating a new NSSA or STUB area; *) winbox - properly show "Hw. Offload Group" value for each interface under "Bridge->Ports" menu; *) winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic"; *) winbox - renamed "Memory used" to "HDD used" for HDD type under "Tools->Graphing->Resource Graphs"; *) winbox - renamed "Routerboard" to "RouterBOARD" under "System/RouterBOARD" menu; *) winbox - show "Hardware Offload" parameter for bonding interfaces; *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature; *) winbox - updated icon design; *) wireless - added "U-NII-2" support for hAP ac2 and RBwAPGR series devices; *) wireless - added "russia 6ghz" regulatory domain information; *) wireless - added "skip-dfs-channels" parameter; *) wireless - allow using "russia4" regulatory domain on RU locked devices; *) wireless - enabled unicast flood for DHCP traffic on ARM architecture access points; *) wireless - updated "bangladesh" regulatory domain information; *) wireless - updated "russia4" regulatory domain information; *) wireless - fixed default "antenna-gain" setting on SXT 2 and LtAP series devices; *) wireless - updated "indonesia4" regulatory domain information; *) www - added "tls-version" parameter in "IP->Services" menu (CLI only);
      Important note!!! - The Dude server must be updated to monitor v6.46.4 and v6.47beta30+ RouterOS type devices. - The Dude client must be manually upgraded after upgrading The Dude server. - Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used. - The Dude requires "winbox" policy instead of "dude" to monitor v6.46.4 and v6.47beta30+ RouterOS type devices. MAJOR CHANGES IN v6.47: ---------------------- !) dns - added client side support for DNS over HTTPS (DoH) (RFC8484); !) socks - added support for SOCKS5 (RFC 1928); !) socks - added support for SOCKS5 (RFC 1928); !) user - enable "winbox" policy for groups with "dude" policy; ---------------------- Changes in this release: !) dns - added client side support for DNS over HTTPS (DoH) (RFC8484); !) socks - added support for SOCKS5 (RFC 1928); !) user - enable "winbox" policy for groups with "dude" policy; *) branding - fixed identity setting from branding package; *) branding - properly use HTML files for Hotspot (introduced in v6.47beta); *) bridge - added warning message when port is dynamically added to entry with VLAN range (CLI only); *) bridge - correctly remove disabled MSTI; *) bridge - improved hardware offloading enabling/disabling; *) capsman - fixed "certificate" parameter updating on CAP; *) certificate - disabled CRL usage by default; *) certificate - do not use SSL for first CRL update; *) chr - added support for file system quiescing; *) crs3xx - do not change bridge host ID's when updating host table (introduced in v6.47beta32); *) crs3xx - fixed interface statistics for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices; *) crs3xx - fixed traffic forwarding after disabling/enabling bridge hardware offloading for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices; *) dhcpv4 - added end option (255) validation for both server and client; *) dhcpv4-client - improved stability when changing client while still receiving advertisements; *) dhcpv6-server - fixed MAC address retrieving from DUID when timestamp is present; *) dude - fixed connection to other RouterOS type devices through The Dude agents (introduced in v6.46.4); *) filesystem - fixed NAND memory going into read-only mode or becoming unstable over time; *) hotspot - updated splash page design ('/ip hotspot reset-html' required); *) ike1 - added error message when specifying "my-id" for XAuth Identity; *) ike1 - improved stability when performing policy lookup on non-existant peer; *) ipsec - control CRL validation with global "use-crl" setting; *) ipsec - do full certificate validation for identities with explicit certificate; *) lcd - fixed LCD service becoming unavailable on devices without LCD screen; *) led - added "dark-mode" functionality for CRS105-5S-FB; *) led - fixed minor typo in LED warning message; *) lora - added IPv6 support for LoRa packet forwarder; *) lora - added value limits for "freq-off" parameter; *) lora - properly update source address for packets when routing table is changed; *) lte - added support for NEOWAY N720; *) lte - fixed "allow-roaming" setting when using LTE network mode on R11e-LTE; *) lte - made "mac-address" parameter read-only; *) ppp - added support for ZTE MF90; *) ppp - fixed minor typo when running "info" command; *) proxy - increased minimal free RAM that can not be used for proxy services; *) quickset - do not show "SINR" field in Quick Set when there is no data; *) quickset - removed "EARFCN" field from Quick Set; *) route - improved system stability after reboot with large amount of VLAN interfaces with PPPoE servers attached; *) sniffer - fixed minor typo in "host" menu; *) snmp - changed "upsEstimatedMinutesRemaining" reported value from seconds to minutes; *) ssh - fixed SHA256 user authentication algorithm checking (introduced in v6.46.4); *) supout - added "gps" section to supout files; *) switch - made "auto" the default value for "vlan-id" parameter when creating a new static host entry; *) system - improved driver loading speed on startup; *) system - improved system stability when forwarding traffic from switch chip to CPU (introduced in v6.43); *) traffic-generator - improved statistics reporting; *) w60g - fixed link status logging; *) w60g - improved rate selection in low traffic conditions; *) winbox - added "Options" parameter support for DHCPv6 client and server; *) winbox - added "Rate" parameter for switch ACL rules; *) winbox - added 160Mhz extension channel support for CAPsMAN; *) winbox - added comment support for "Switch->VLAN" menu; *) winbox - added support for "Tools->WoL" menu; *) winbox - aligned all "IP->Traffic Flow->IPFIX" check boxes in single line (WinBox v3.22 required); *) winbox - allow setting "20/40/80/160Mhz-eeeeeeCe" channel under "Channel Width" parameter; *) winbox - allow setting "Primary" parameter for "balance-tlb" bonding interfaces; *) winbox - do not show "Revision" parameter under "System/RouterBOARD" menu on devices that have only one revision; *) winbox - fixed "ARP" parameter inheritance from "CAPs Configuration" configuration; *) winbox - fixed "BGP Origin" value display under "IPv6->Routes" menu; *) winbox - fixed "Bands" parameter display for LTE interfaces; *) winbox - fixed "DSCP" parameter value setting; *) winbox - fixed "Data Rate" checkbox alignment (WinBox v3.22 required); *) winbox - fixed "Frequency" and "Secondary Frequency" parameter inheritance from "CAPs Channel" configuration; *) winbox - fixed "Passthr. MAC Address" parameter display "LTE APNs" menu; *) winbox - fixed "Switch" menu on CRS354-48P-4S+2Q+; *) winbox - fixed "dst-port" unsetting in "IP->Hotspot->Walled Garden" menu; *) winbox - fixed automatic "IPv6->Firewall->Address List" table update; *) winbox - fixed bonding type interface support for "Switch->Host" table; *) winbox - made "none" the default value for "Security Profile" parameter when creating a new "Wirelees->Connect list" entry; *) winbox - made "yes" the default value for "Inject Summary LSAs" parameter when creating a new NSSA or STUB area; *) winbox - properly show "Hw. Offload Group" value for each interface under "Bridge->Ports" menu; *) winbox - renamed "Memory used" to "HDD used" for HDD type under "Tools->Graphing->Resource Graphs"; *) winbox - renamed "Routerboard" to "RouterBOARD" under "System/RouterBOARD" menu; *) winbox - show "Hardware Offload" parameter for bonding interfaces; *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature; *) winbox - updated icon design; *) wireless - added "U-NII-2" support for hAP ac2 and RBwAPGR series devices; *) wireless - enabled unicast flood for DHCP traffic on ARM architecture access points; *) wireless - fixed default "antenna-gain" setting on SXT 2 and LtAP series devices; *) wireless - updated "indonesia4" regulatory domain information; Other changes since v6.46.4: !) socks - added support for SOCKS5 (RFC 1928); *) bonding - improved slave interface MAC address handling; *) bonding - prefer primary slave MAC address for bonding interface; *) bridge - added logging message when a host MAC address is learned on a different bridge port; *) crs3xx - correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices; *) crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices; *) crs3xx - fixed QSFP+ interface linking for CRS326-24S+2Q+ device (introduced in v6.47beta19); *) crs3xx - improved SFP+ DAC cable initialization for CRS326-24S+2Q+ device; *) crs3xx - improved switch host table updating; *) defconf - fixed "no-defaults=yes" applying default configuration (introduced in v6.47beta); *) defconf - fixed default configuration initialization if power loss occurred during the process; *) dhcpv6-client - improved error logging when when renewed address differs; *) discovery - do not send CDP and LLDP packets on interfaces that does not have MAC address; *) discovery - do not send discovery packets on inactive bonding slave interfaces; *) discovery - do not send discovery packets on interfaces that are blocked by STP; *) disk - improved recently created file survival after reboots; *) dns - added support for exclusive dynamic DNS server usage from IPsec; *) dot1x - added "radius-mac-format" parameter (CLI only); *) dot1x - added hex value support for RADIUS switch rules; *) dot1x - added range "dst-port" support for RADIUS switch rules; *) dot1x - added support for lower case "mac-auth" RADIUS formats; *) dot1x - fixed "reject-vlan-id" value range; *) dot1x - fixed dynamically created switch rule removal when client disconnects; *) dot1x - fixed port blocking when interface changes state from disabled to enabled; *) dot1x - improved debug logging output to "dot1x" topic; *) dot1x - improved value validation for dynamically created switch rules; *) fetch - fixed "User-Agent" usage if provided by "http-header-field"; *) health - added "gauges" submenu with SNMP OID reporting; *) ike1 - added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes; *) ike2 - added support for "INTERNAL_DNS_DOMAIN" payload attribute; *) ipsec - added "split-dns" parameter support for mode configuration (CLI only); *) ipsec - added "use-responder-dns" parameter support (CLI only); *) ipsec - fixed minor spelling mistake in logs; *) ipsec - improved IPsec service stability when receiving bogus packets; *) lte - added support for multiple passthrough APN configuration; *) lte - do not allow running "scan" on R11e-4G; *) lte - fixed "band" value setting when configuration is reset on R11e-4G; *) lte - fixed multiple APN reactivation after deactivation by operator; *) lte - show "phy-cellid" value only in LTE mode; *) netinstall - removed "Flashfig" from Netinstall; *) netinstall - removed "Make Floppy" from Netinstall; *) netinstall - signed netinstall.exe with Digital Signature; *) quickset - removed "LTE band" setting from Quick Set; *) quickset - show "Antenna Gain" setting on devices without built-in antennas; *) quickset - use "station-wds" mode when connecting to AP with RouterOS flag; *) routing - improved IGMP-Proxy service stability when receiving bogus packets; *) sniffer - allow setting port for "streaming-server"; *) snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB; *) snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB; *) snmp - improved OID policy checking and error reporting on "set" command; *) snmp - improved stability when polling MAC address related OID; *) supout - added "dot1x" section to supout files; *) supout - improved PoE-out information reporting; *) supout - improved UPS information reporting; *) system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic; *) tr069-client - removed warning log message when not using HTTPS; *) traceroute - improved stability when invalid packet is received; *) traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9; *) traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9; *) upgrade - fixed space handling in package file names; *) ups - improved compatibility with APC Smart UPS 1000 and 1500; *) w60g - improved stability after multiple disconnections; *) w60g - use "arp" and "mtu" parameters from master interface when creating a new station; *) webfig - updated icon design; *) winbox - added "auto-erase" option to "Tool/SMS" menu; *) winbox - added support for inline bar graphs for LTE signal values; *) winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic"; *) winbox - updated icon design; *) wireless - allow using "russia4" regulatory domain on RU locked devices; *) www - added "tls-version" parameter in "IP->Services" menu (CLI only);
      Что нового в версии 6.47beta35 (2020-Feb-17 13:56):


      Важная заметка!!!

      - The Dude server must be updated to monitor v6.47beta30+ RouterOS type devices.
      - The Dude client must be manually upgraded after upgrading The Dude server.
      - Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used.

      MAJOR CHANGES IN v6.47:
      ----------------------
      !) socks - added support for SOCKS5 (RFC 1928);
      ----------------------

      Изменения в этом выпуске:

      !) socks - added support for SOCKS5 (RFC 1928);
      *) chr - fixed graceful shutdown execution on Hyper-V (introduced in v6.46);
      *) crs3xx - fixed frame forwarding after disabling/enabling bridge hardware offloading for CRS354-48G-4S+2Q+ device;
      *) crs3xx - improved SFP+ DAC cable initialization for CRS326-24S+2Q+ device;
      *) dns - added support for exclusive dynamic DNS server usage from IPsec;
      *) health - fixed maximum SFP temperature reading under '/system health' menu;
      *) ipsec - added "use-responder-dns" parameter support (CLI only);
      *) ssh - added support for RSA keys with SHA256 hash (RFC8332);
      *) supout - improved PoE-out information reporting;
      *) system - improved system stability when receiving/sending TCP traffic on multicore devices;
      *) traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9;
      *) webfig - updated icon design;
      *) winbox - updated icon design;
      *) wireless - allow using "russia4" regulatory domain on RU locked devices;

      Другие изменения v6.46.3:

      *) arm - improved watchdog and kernel panic reporting in log after reboots on RB3011 and IPQ4018/IPQ4019 devices ("/system routerboard upgrade" required);
      *) bonding - improved slave interface MAC address handling;
      *) bonding - prefer primary slave MAC address for bonding interface;
      *) branding - allow forcing configuration script as default configuration (new branding packet required);
      *) branding - fixed "company-url" and "router-default-name" survival after system upgrade;
      *) branding - fixed WEB HTML page survival after system upgrade;
      *) bridge - added logging message when a host MAC address is learned on a different bridge port;
      *) certificate - fixed certificate verification when flushing CRL's;
      *) crs3xx - correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices;
      *) crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
      *) crs3xx - fixed QSFP+ interface linking for CRS326-24S+2Q+ device (introduced in v6.47beta19);
      *) crs3xx - improved switch host table updating;
      *) defconf - added welcome note with common first steps for new users;
      *) defconf - fixed default configuration initialization if power loss occurred during the process;
      *) defconf - fixed "no-defaults=yes" applying default configuration (introduced in v6.47beta);
      *) dhcpv6-client - improved error logging when when renewed address differs;
      *) discovery - do not send CDP and LLDP packets on interfaces that does not have MAC address;
      *) discovery - do not send discovery packets on inactive bonding slave interfaces;
      *) discovery - do not send discovery packets on interfaces that are blocked by STP;
      *) disk - improved recently created file survival after reboots;
      *) dot1x - added hex value support for RADIUS switch rules;
      *) dot1x - added "radius-mac-format" parameter (CLI only);
      *) dot1x - added range "dst-port" support for RADIUS switch rules;
      *) dot1x - added support for lower case "mac-auth" RADIUS formats;
      *) dot1x - fixed dynamically created switch rule removal when client disconnects;
      *) dot1x - fixed port blocking when interface changes state from disabled to enabled;
      *) dot1x - fixed "reject-vlan-id" value range;
      *) dot1x - improved debug logging output to "dot1x" topic;
      *) dot1x - improved value validation for dynamically created switch rules;
      *) dude - updated The Dude to use new style authentication method;
      *) fetch - fixed "User-Agent" usage if provided by "http-header-field";
      *) health - added "gauges" submenu with SNMP OID reporting;
      *) ike1 - added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes;
      *) ike2 - added support for "INTERNAL_DNS_DOMAIN" payload attribute;
      *) ike2 - fixed DHCP Inform package handling when received on PPPoE interface;
      *) ipsec - added "split-dns" parameter support for mode configuration (CLI only);
      *) ipsec - fixed minor spelling mistake in logs;
      *) ipsec - improved IPsec service stability when receiving bogus packets;
      *) lte - added interface name prefix for logging events;
      *) lte - added "phy-cellid" value support for LTE-US;
      *) lte - added support for multiple passthrough APN configuration;
      *) lte - do not allow running "scan" on R11e-4G;
      *) lte - do not allow using empty APN Profile names;
      *) lte - fixed "band" value setting when configuration is reset on R11e-4G;
      *) lte - fixed multiple APN reactivation after deactivation by operator;
      *) lte - improved all APN session activation after disconnect on R11e-LTE;
      *) lte - show "phy-cellid" value only in LTE mode;
      *) lte - use APN from network when blank APN used on R11e-4G;
      *) netinstall - removed "Flashfig" from Netinstall;
      *) netinstall - removed "Make Floppy" from Netinstall;
      *) netinstall - signed netinstall.exe with Digital Signature;
      *) quickset - removed "LTE band" setting from Quick Set;
      *) quickset - show "Antenna Gain" setting on devices without built-in antennas;
      *) quickset - use "station-wds" mode when connecting to AP with RouterOS flag;
      *) routing - improved IGMP-Proxy service stability when receiving bogus packets;
      *) sniffer - allow setting port for "streaming-server";
      *) snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB;
      *) snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
      *) snmp - fixed "routeros-version" value returning from registration table;
      *) snmp - fixed UPS battery voltage value scaling;
      *) snmp - improved OID policy checking and error reporting on "set" command;
      *) snmp - improved stability when polling MAC address related OID;
      *) supout - added "dot1x" section to supout files;
      *) supout - improved UPS information reporting;
      *) system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic;
      *) telnet - improved telnet compatibility with other client implementations;
      *) tr069-client - removed warning log message when not using HTTPS;
      *) traceroute - improved stability when invalid packet is received;
      *) traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9;
      *) upgrade - fixed space handling in package file names;
      *) ups - improved compatibility with APC Smart UPS 1000 and 1500;
      *) user-manager - fixed signup enabling (introduced in v6.46);
      *) w60g - improved stability after multiple disconnections;
      *) w60g - use "arp" and "mtu" parameters from master interface when creating a new station;
      *) webfig - added default configuration confirmation window to WebFig;
      *) webfig - do not show WebFig menu when opening 'Check For Updates' in Quick Set;
      *) winbox - added "auto-erase" option to "Tool/SMS" menu;
      *) winbox - added support for inline bar graphs for LTE signal values;
      *) winbox - completely removed old style authentication method;
      *) winbox - fixed "invalid" flag presence under "System/Certificates/CRL" menu;
      *) winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic";
      *) wireless - improved compatibility for "ETSI" wireless country profile;
      *) www - added "tls-version" parameter in "IP->Services" menu (CLI only);
      Important note!!! - The Dude server must be updated to monitor v6.47beta30+ RouterOS type devices. - The Dude client must be manually upgraded after upgrading The Dude server. - Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used. MAJOR CHANGES IN v6.47: ---------------------- !) socks - added support for SOCKS5 (RFC 1928); ---------------------- Changes in this release: *) arm - improved watchdog and kernel panic reporting in log after reboots on RB3011 and IPQ4018/IPQ4019 devices ("/system routerboard upgrade" required); *) branding - allow forcing configuration script as default configuration (new branding packet required); *) branding - fixed "company-url" and "router-default-name" survival after system upgrade; *) branding - fixed WEB HTML page survival after system upgrade; *) certificate - fixed certificate verification when flushing CRL's; *) crs3xx - correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices; *) crs3xx - fixed QSFP+ interface linking for CRS326-24S+2Q+ device (introduced in v6.47beta19); *) crs3xx - improved switch host table updating; *) defconf - added welcome note with common first steps for new users; *) defconf - fixed default configuration initialization if power loss occurred during the process; *) defconf - fixed "no-defaults=yes" applying default configuration (introduced in v6.47beta); *) disk - improved recently created file survival after reboots; *) dns - use only servers received from IKEv2 server when present; *) dot1x - added hex value support for RADIUS switch rules; *) dot1x - added range "dst-port" support for RADIUS switch rules; *) dot1x - added support for lower case "mac-auth" RADIUS formats; *) dot1x - fixed dynamically created switch rule removal when client disconnects; *) dot1x - fixed port blocking when interface changes state from disabled to enabled; *) dot1x - fixed "reject-vlan-id" value range; *) dot1x - improved debug logging output to "dot1x" topic; *) dot1x - improved value validation for dynamically created switch rules; *) dude - updated The Dude to use new style authentication method; *) ike1 - added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes; *) ike2 - added support for "INTERNAL_DNS_DOMAIN" payload attribute; *) ike2 - fixed DHCP Inform package handling when received on PPPoE interface; *) ipsec - added "split-dns" parameter support for mode configuration (CLI only); *) ipsec - fixed minor spelling mistake in logs; *) ipsec - improved IPsec service stability when receiving bogus packets; *) lte - added interface name prefix for logging events; *) lte - added "phy-cellid" value support for LTE-US; *) lte - added support for multiple passthrough APN configuration; *) lte - do not allow using empty APN Profile names; *) lte - show "phy-cellid" value only in LTE mode; *) quickset - removed "LTE band" setting from Quick Set; *) quickset - show "Antenna Gain" setting on devices without built-in antennas; *) quickset - use "station-wds" mode when connecting to AP with RouterOS flag; *) routing - improved IGMP-Proxy service stability when receiving bogus packets; *) snmp - fixed "routeros-version" value returning from registration table; *) snmp - fixed UPS battery voltage value scaling; *) supout - improved UPS information reporting; *) telnet - improved telnet compatibility with other client implementations; *) tr069-client - removed warning log message when not using HTTPS; *) traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9; *) upgrade - fixed space handling in package file names; *) ups - improved compatibility with APC Smart UPS 1000 and 1500; *) user-manager - fixed signup enabling (introduced in v6.46); *) w60g - improved stability after multiple disconnections; *) webfig - added default configuration confirmation window to WebFig; *) webfig - do not show WebFig menu when opening 'Check For Updates' in Quick Set; *) winbox - added support for inline bar graphs for LTE signal values; *) winbox - completely removed old style authentication method; *) winbox - fixed "invalid" flag presence under "System/Certificates/CRL" menu; *) wireless - improved compatibility for "ETSI" wireless country profile; *) www - added "tls-version" parameter in "IP->Services" menu (CLI only); Other changes since v6.46.3: !) socks - added support for SOCKS5 (RFC 1928); *) bonding - improved slave interface MAC address handling; *) bonding - prefer primary slave MAC address for bonding interface; *) bridge - added logging message when a host MAC address is learned on a different bridge port; *) crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices; *) dhcpv6-client - improved error logging when when renewed address differs; *) discovery - do not send CDP and LLDP packets on interfaces that does not have MAC address; *) discovery - do not send discovery packets on inactive bonding slave interfaces; *) discovery - do not send discovery packets on interfaces that are blocked by STP; *) dot1x - added "radius-mac-format" parameter (CLI only); *) fetch - fixed "User-Agent" usage if provided by "http-header-field"; *) health - added "gauges" submenu with SNMP OID reporting; *) lte - do not allow running "scan" on R11e-4G; *) lte - fixed "band" value setting when configuration is reset on R11e-4G; *) lte - fixed multiple APN reactivation after deactivation by operator; *) lte - improved all APN session activation after disconnect on R11e-LTE; *) lte - use APN from network when blank APN used on R11e-4G; *) netinstall - removed "Flashfig" from Netinstall; *) netinstall - removed "Make Floppy" from Netinstall; *) netinstall - signed netinstall.exe with Digital Signature; *) sniffer - allow setting port for "streaming-server"; *) snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB; *) snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB; *) snmp - improved OID policy checking and error reporting on "set" command; *) snmp - improved stability when polling MAC address related OID; *) supout - added "dot1x" section to supout files; *) system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic; *) traceroute - improved stability when invalid packet is received; *) w60g - use "arp" and "mtu" parameters from master interface when creating a new station; *) winbox - added "auto-erase" option to "Tool/SMS" menu; *) winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic";
      *) bonding - removed "sys-id" and "sys-priority" from monitor-slaves command; *) bridge - fixed BPDU guard port disable/enable on HW offloaded interfaces; *) bridge - fixed host table update on SNMP query; *) bridge - fixed multicast table printing; *) bridge - fixed packet forwarding for CAP and BCP controlled interfaces (introduced in v6.48beta12); *) bridge - fixed STP alternate and backup port states for devices with switch chip (introduced in v6.47); *) bridge - increased multicast table size to 4K entries; *) crs3xx - fixed "mirror-source" property on switch port disable for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices; *) crs3xx - fixed port isolation for "switch-cpu" port for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices; *) crs3xx - fixed port isolation removal for "switch-cpu" port on CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed "storm-rate" traffic limiting for switch-cpu port on CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed switch ACL rules for CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed switch port "egress-rate" removal for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices; *) crs3xx - fixed VLAN tagged packet forwarding on "switch-cpu" port for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices (introduced in v6.48beta12); *) defconf - improved CAP interface bridging; *) defconf - improved default configuration generation on devices without wireless package installed; *) discovery - added "lldp-med-net-policy-vlan" property for assigning VLAN ID (CLI only); *) discovery - allow choosing which discovery protocol is used (CLI only); *) discovery - fixed discovery on mesh ports; *) discovery - fixed discovery packet sending on newly bridged port with "protocol-mode=none"; *) discovery - fixed discovery when enabled only on master port; *) discovery - use interface MAC address when sending MNDP from slave port; *) dns - added IPv6 support for DoH; *) dns - fixed multiple TXT string replies; *) dns - hide default static entry "type" from export; *) fetch - fixed "src-address" usage for SFTP; *) filesystem - improved long-term filesystem stability and data integrity; *) health - removed unused "heater-control" and "heater-threshold" parameters; *) hotspot - added support for captive portal advertising using DHCP (RFC7710); *) hotspot - improved management service stability when receiving bogus packets; *) ike2 - fixed local side NAT detection; *) ipsec - do not kill connection when peer's "name" or "comment" is changed; *) ipsec - refresh peer's DNS only when phase 1 is down; *) lte - added support for Alcatel IK41VE1; *) snmp - fixed value types for "dot1dStp"; *) tr069-client - send correct "ConnectionRequestURL" when using IPv6; *) traffic-flow - added "sys-init-time" parameter support; *) wireless - allow setting "tx-power" up to 40; Other changes since v6.47.2: *) arm - added support for automatic CPU frequency stepping for IPQ4018/IPQ4019 devices; *) arm - improved watchdog and kernel panic reporting in log after reboots on IPQ4018/IPQ4019 devices; *) bonding - added LACP monitoring (CLI only); *) bridge - added warning message when port is disabled by the BPDU guard; *) bridge - allow to exclude interfaces from extended ports (CLI only); *) bridge - correctly remove dynamic VLAN assignment for bridge ports; *) bridge - fixed dynamic VLAN assignment when changing port "frame-type" property (introduced in v6.46); *) bridge - fixed dynamic VLAN assignment when changing port to tagged VLAN member; *) bridge - fixed host table update on SNMP query; *) bridge - fixed local MAC address removal from host table when deleting bridge interface; *) bridge - improved BPDU guard logging; *) bridge - show error when switch do not support controlling bridge or port extension (CLI only); *) bridge - show "H" flag for extended bridge ports; *) certificate - clear challenge password on renew; *) chr - improved interface loading on startup on XEN; *) chr - improved system stability when changing flow control settings on e1000; *) crs3xx - added initial Bridge Port Extender support (CLI only); *) crs3xx - added initial Controlling Bridge support for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (CLI only); *) crs3xx - fixed "custom-drop-packet" and "not-learned" switch stats for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed duplicate host entries when creating static switch hosts; *) crs3xx - fixed hardware offloaded MPLS forwarding when using bonding interfaces; *) crs3xx - fixed switch "not-learned" stats for CRS305, CRS326-24G-2S+, CRS328-24P-4S+, CRS328-4C-20S-4S+, CRS318 devices; *) crs3xx - improved Ethernet port group traffic forwarding for CRS354 devices; *) crs3xx - improved system stability when using hardware offloaded MPLS; *) defconf - improved default configuration generation on devices with non-default wireless interface names; *) dhcpv6-server - added ability to generate binding on first request; *) discovery - send the same "Chassis ID" on all interfaces for LLDP packets; *) dns - do not use type "A" for static entries with unspecified type; *) dns - fixed listening for DNS queries when only dynamic static entries exist (introduced in v6.47); *) dot1x - fixed duplicate EAP request packets for server; *) dot1x - fixed EAP packet version numbering; *) export - fixed RouterBOARD USB "type" parameter export; *) filesystem - fixed repartition on non-first partition; *) filesystem - fixed repartition on RB4011 series devices; *) filesystem - improved long-term filesystem stability and data integrity; *) gps - fixed "init-channel" release when not used; *) health - changed PSU state parameter type to read-only; *) health - removed unused "heater-control" and "heater-threshold" parameters; *) hotspot - added "vlan-id" parameter support for hosts and HTML pages; *) hotspot - ignore packets from host while MAC authentication is in progress; *) ike1 - allow using "my-id" parameter with XAuth; *) ike1 - fixed policy update with and without mode configuration; *) ike1 - rekey phase 1 as responder for Windows initiators; *) ike2 - added "prf-algorithm" support for phase 1; *) ike2 - improved child SA rekeying process; *) ipsec - added SHA384 hash algorithm support for phase 1 (CLI only); *) ipsec - fixed client certificate usage when certificate is renewed with SCEP; *) ipsec - fixed multiple warning message display for peers; *) ipsec - inactivate peer's policy on disconnect; *) kidcontrol - allow creating static device entries without assigned user; *) kidcontrol - fixed "time-unlimited-rate" to engage in correct time; *) lora - expose "joinEui" un "devEui" values in the log; *) lte - added "age" column and "max-age" parameter to "cell-monitor" (CLI only); *) lte - added "comment" parameter for APN profiles; *) lte - added "comment" parameter for APN profiles (CLI only); *) lte - fixed multiple passthrough APN default route installation; *) lte - fixed RSCP value reporting; *) lte - validate interface existence on initiation; *) ospf - fixed disappearing NSSA default route; *) ospf - fixed processing of "unknown" LSA type; *) ospf - optimized LSA printing for smaller message sizes; *) poe - fixed "power-cycle" functionality on RB960GSP; *) ppp - added "ipv6-routes" parameter to "secrets" menu; *) ppp - added support for "Framed-IPv6-Route" RADIUS attribute; *) route - improved stability when 6to4 interface is configured with disabled IPv6 package; *) routerboot - fixed etherboot FCS errors with 100Mbps rate for CRS309, CRS317 devices ("/system routerboard upgrade" required); *) ssh - fixed returned output saving to file when "output-to-file" parameter is used; *) ssh - skip interactive authentication when not running in interactive mode; *) system - replace "3" in superscript to "^3" on RBD53GR devices; *) tr069-client - added additional wireless registration table parameters; *) tr069-client - added LTE model and revision parameters; *) tr069-client - added wireless "noise-floor" and "overall-tx-ccq" information parameters; *) tr069-client - added "X_MIKROTIK_MimoRSRP" parameter for LTE RSRP value reporting; *) tr069-client - allow passing LTE firmware update URL as XML; *) traffic-flow - added NAT event logging support for IPFIX; *) webfig - fixed default value presence when creating new entries under "IP->Kid Control"; *) webfig - fixed negative value usage in "spoof-gps" parameter (introduced in v6.47.1); *) winbox - allow performing "USB Power Reset" on "0" bus on RBM33G; *) winbox - fixed "IP->Kid Control->Devices" table automatic refreshing; *) winbox - fixed minor typo in "Users" menu; *) winbox - fixed "receive-errors" setting persistence under "Wireless/Wireless Sniffer/Settings" menu; *) winbox - fixed "tls-version" parameter setting under "IP/Services" menu; *) winbox - use health values reported by gauges for "System/Health" menu; *) wireless - added support for U-NII-2 for wAP ac; *) wireless - create "connect-list" rule when address specified for "setup-repeater"; *) wireless - updated "canada" regulatory domain information; *) wireless - updated "no_country_set" regulatory domain information; *) wireless - updated "united states" regulatory domain information;
      MAJOR CHANGES IN v6.47: ---------------------- !) socks - added support for SOCKS5 (RFC 1928); ---------------------- Changes in this release: !) socks - added support for SOCKS5 (RFC 1928); *) bonding - improved slave interface MAC address handling; *) bonding - prefer primary slave MAC address for bonding interface; *) bridge - added logging message when a host MAC address is learned on a different bridge port; *) chr - improved stability when changing ARP modes on e1000 type adapters; *) console - prevent "flash" directory from being removed (introduced in v6.46); *) console - updated copyright notice; *) crs305 - disable optical SFP/SFP+ module Tx power after disabling SFP+ interface; *) defconf - fixed "caps-mode" not initialized properly after resetting; *) defconf - fixed default configuration loading on RBwAPG-60adkit (introduced in v6.46); *) discovery - do not send CDP and LLDP packets on interfaces that does not have MAC address; *) discovery - do not send discovery packets on inactive bonding slave interfaces; *) discovery - do not send discovery packets on interfaces that are blocked by STP; *) dot1x - added "radius-mac-format" parameter (CLI only); *) health - added "gauges" submenu with SNMP OID reporting; *) lora - added "ru-864-mid" channel plan; *) lora - fixed packet sending when using "antenna-gain" higher than 5dB; *) lora - improved immediate packet delivery; *) lte - do not allow running "scan" on R11e-4G; *) lte - fixed "band" value setting when configuration is reset on R11e-4G; *) lte - fixed "cell-monitor" on R11e-LTE in 3G mode; *) lte - fixed "earfcn" reporting on R11e-LTE6 in UMTS and GSM modes; *) lte - improved all APN session activation after disconnect on R11e-LTE; *) lte - report only valid info parameters on R11e-LTE6; *) lte - use APN from network when blank APN used on R11e-4G; *) ppp - fixed minor typo in "ppp-client" monitor; *) qsfp - do not report bogus monitoring readouts on modules without DDMI support; *) qsfp - improved module monitoring readouts for DAC and break-out cables; *) routerboard - added "mode-button" support for RBcAP2nD; *) sniffer - allow setting port for "streaming-server"; *) snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB; *) snmp - improved OID policy checking and error reporting on "set" command; *) supout - added "dot1x" section to supout files; *) system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic; *) system - fixed "*.auto.rsc" file execution (introduced in v6.46); *) system - fixed "check-installation" on PowerPC devices (introduced in v6.46); *) traceroute - improved stability when invalid packet is received; *) traffic-generator - improved memory handling on CHR; *) webfig - allow skin designing without "ftp" and "sensitive" policies; *) webfig - fixed "skins" saving to "flash" directory if it exists (introduced in v6.46); *) winbox - automatically refresh "Packets" table when new packets are captured by "Tools/Packet Sniffer"; *) winbox - fixed "Default Route Distance" default value when creating new LTE APN; *) winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic"; Other changes since v6.46.1: *) crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices; *) dhcpv6-client - improved error logging when when renewed address differs; *) fetch - fixed "User-Agent" usage if provided by "http-header-field"; *) lte - fixed multiple APN reactivation after deactivation by operator; *) netinstall - removed "Flashfig" from Netinstall; *) netinstall - removed "Make Floppy" from Netinstall; *) netinstall - signed netinstall.exe with Digital Signature; *) snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB; *) snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB; *) snmp - improved stability when polling MAC address related OID; *) w60g - use "arp" and "mtu" parameters from master interface when creating a new station; *) winbox - added "auto-erase" option to "Tool/SMS" menu;
      Что нового в версии 6.47beta8 (2019-Dec-10 10:33):

      Изменения в этом выпуске:

      *) console - fixed "clear-history" restoring historic actions after power cycle;
      *) console - removed "edit" and "set" actions from "System/History" menu;
      *) crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
      *) defconf - fixed default configuration loading after fresh install (introduced in v6.46);
      *) dhcpv6-client - improved error logging when when renewed address differs;
      *) fetch - fixed "User-Agent" usage if provided by "http-header-field";
      *) health - fixed health reporting on OmniTIK 5 PoE ac;
      *) health - improved health reporting on CCR1072-1G-8S+;
      *) ipsec - improved system stability when processing decrypted packet on unregistred interface;
      *) l2tp - improved system stability when disconnecting many clients at once;
      *) lora - improved confirmed downlink forwarding;
      *) lte - do not reset modem when setting the same SIM slot on LtAP;
      *) lte - fixed multiple APN reactivation after deactivation by operator;
      *) lte - show SIM error when no card is present;
      *) netinstall - removed "Flashfig" from Netinstall;
      *) netinstall - removed "Make Floppy" from Netinstall;
      *) netinstall - signed netinstall.exe with Digital Signature;
      *) ppp - prioritize "remote-ipv6-prefix-pool" from PPP secret over PPP profile;
      *) snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB;
      *) snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
      *) snmp - fixed health related OID polling (introduced in v6.46);
      *) snmp - improved stability when polling MAC address related OID;
      *) supout - fixed autosupout.rif file generation (introduced in v6.46);
      *) w60g - use "arp" and "mtu" parameters from master interface when creating a new station;
      *) winbox - added "auto-erase" option to "Tool/SMS" menu;
      *) winbox - fixed "allowed-number" parameter setting invalid value in "Tool/SMS" menu;
      *) winbox - show "LCD" menu only on boards that have LCD screen;
      *) wireless - improved compatibility by adding default installation mode and gain for devices with integrated antennas;
      *) wireless - improved compatibility for Switzerland wireless country profile to improve compliance with ETSI regulations;
      Что нового в версии 6.46rc1 (2019-Nov-26 13:19):

      MAJOR CHANGES IN v6.46:
      ----------------------
      !) lora - added support for LoRaWAN low-power wide-area network technology for MIPSBE, MMIPS and ARM;
      !) package - accept only packages with original filenames (CVE-2019-3976);
      !) package - improved package signature verification (CVE-2019-3977);
      !) security - fixed improper handling of DNS responses (CVE-2019-3978, CVE-2019-3979);
      ----------------------

      Изменения в этом выпуске:

      !) ptp - disabled support for IEEE 1588 Precision Clock Synchronization Protocol until further notice;
      *) bridge - do not add dynamically VLAN entry when changing "pvid" property for non-vlan aware bridge;
      *) capsman - fixed MAC address detection for "common-name" parameter in certificate requests;
      *) certificate - added progress bar when creating certificate request;
      *) certificate - allow specifying "name" parameter for import (CLI only);
      *) crs3xx - improved system stability when initializing SFP modules;
      *) export - always export "ssid" value for w60g interfaces;
      *) fetch - do not allocate extra 500KiB on SMIPS;
      *) ipsec - fixed IPsec policy checking on RB4011 (introduced in v6.46beta68);
      *) switch - added "comment" property for switch vlan menu (CLI only);
      *) w60g - do not reset link when changing comment on station;
      *) w60g - fixed "monitor" command on disabled interfaces;
      *) w60g - move stations to new bridge when "put-in-bridge" parameter is changed;
      *) winbox - added enable/disable and comment buttons for "IP->SNMP->Communities" menu;
      *) winbox - fixed field validation with negative integers (introduced in v6.46beta);
      *) wireless - added "ETSI" regulatory domain information;

      Другие изменения v6.45.7:

      *) backup - fixed automatic backup file generation when configuration reset by button;
      *) backup - store automatically created backup file in "flash" directory;
      *) bonding - correctly remove HW offloaded bonding with ARP monitoring;
      *) bonding - properly handle MAC addresses when bonding WLAN interfaces;
      *) bridge - disable/enable bridge port when setting bpdu-guard;
      *) bridge - do not add bridge as untagged VLAN member when frame-types=admit-only-vlan-tagged;
      *) bridge - include whole VLAN-id in DHCP Option 82 message;
      *) btest - removed duplicate "duration" parameter;
      *) capsman - fixed background scan showing incorrect regulatory domain mismatch error (CAP upgrade required);
      *) capsman - fixed channel auto reselection;
      *) capsman - improved DFS channel switching when radar detected;
      *) capsman - improved radar detection algorithm;
      *) ccr - improved general system stability;
      *) certificate - added progress bar when creating certificate request (CLI only);
      *) certificate - added support for certificate request signing with EC keys;
      *) certificate - allow specifying "file-name" parameter for export (CLI only);
      *) certificate - allow specifying "name" parameter for import (CLI only);
      *) certificate - improved CRL updating process;
      *) certificate - removed "key-size" parameter for "create-certificate-request" command;
      *) chr - added support for Azure guest agent;
      *) console - added bitwise operator support for "ip6" data type;
      *) console - fixed "address" column width when printing DHCPv4 leases;
      *) console - fixed IP conversion to "num" data type;
      *) console - fixed "tobool" conversion;
      *) console - properly detect IPv6 address as "ip6" data type;
      *) crs1xx/2xx - allow to set trunk port as mirroring target;
      *) crs305 - fixed sfp-sfpplus2 - sfp-sfpplus4 interface linking (introduced in v6.46beta28);
      *) crs3xx - correctly handle L2MTU change;
      *) crs3xx - do not send pause frames when ethernet "tx-flow-control" is disabled on CRS326/CRS328/CRS305 devices;
      *) crs3xx - improved interface initialization;
      *) crs3xx - improved switch-chip resource allocation on CRS317-1G-16S+, CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
      *) crs3xx - improved system stability on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
      *) crs3xx - remove previously set mirror-source property before changing it;
      *) defconf - fixed default configuration generation on SXT R (introduced in v6.46beta28);
      *) defconf - fixed default configuration loading on RBmAPL-2nD (introduced in v6.45);
      *) defconf - require "policy" permission to print default configuration;
      *) dhcpv4-client - allow empty "dhcp-options" parameter when adding new client;
      *) dhcpv4-client - fixed "dhcp-options" parameter setting when adding new client;
      *) dhcpv4-server - improved stability when RADIUS Interim update is sent;
      *) dhcpv6-client - properly update bind time when unused prefix received from the server;
      *) dhcpv6-client - properly update IPv6 address on rebind;
      *) dhcpv6-server - fixed logged error message when using "address-pool=static-only";
      *) dhcpv6-server - include "User-Name" parameter in accounting requests;
      *) dhcpv6-server - made "calling-station-id" contain MAC address if DUID contains it;
      *) dhcvp6-client - fixed timeout when doing rebind;
      *) dot1x - added "reject-vlan-id" server parameter (CLI only);
      *) dot1x - added support for dynamic switch rules from RADIUS;
      *) dot1x - added support for "mac-auth" authentication type (CLI only);
      *) dude - fixed data retrieval over SNMP (introduced in v6.46beta44);
      *) ethernet - automatically detect interface when using IP address for power-cycle-ping;
      *) ethernet - do not enable interface after reboot that is already disabled;
      *) ethernet - send requests only from ethernet interface when using MAC address for power-cycle-ping;
      *) fetch - fixed "dst-path" not allowed to create new directories (introduced in v6.46beta34);
      *) fetch - improved stability when processing large output data;
      *) gps - use "serial1" as default port on RBLtAP-2HnD;
      *) hotspot - fixed "html-directory" not allowed to create new directories (introduced in v6.46beta34);
      *) hotspot - fixed non-local NAT redirection to port TCP/64873;
      *) hotspot - fixed RADIUS CoA "address-list" update;
      *) ike1 - fixed minor spelling mistake in logs;
      *) ike2 - fixed IPv6 policy generation (introduced in v6.46beta28);
      *) ike2 - improved CHILD SA rekey process with Apple iOS 13;
      *) ike2 - improved stability when retransmitting first packet as responder;
      *) ipsec - added "error" topic for identity check failure logging messages;
      *) ipsec - fixed DNS resolving when domain has only AAAA entries;
      *) ipsec - fixed policy "sa-src-address" detection from "local-address" (introduced in v6.45);
      *) ipv6 - changed "advertise-dns" default value to "yes";
      *) led - fixed default LED configuration for RBLHG-2nD and RBLHG-5HPnD;
      *) log - increased log message length limit to 1024 characters;
      *) lte - added support for D402 modem;
      *) lte - added support for LM960A18;
      *) lte - added support for Telit LM960 and LE910C1 modems;
      *) lte - do not allow setting 3G and GSM modes on LTE only modems;
      *) lte - fixed band setting on R11e-4G;
      *) lte - fixed network registration on R11e-LTE-US;
      *) lte - fixed Sierra WP7601 driver loading;
      *) lte - fixed USB network device driver initialization (introduced in v6.46beta9);
      *) lte - fix "operator" names not being displayed properly;
      *) lte - improved modem initialization;
      *) lte - show "primary-band" only for LTE modems;
      *) lte - use /128 prefix for IPv6 address on LTE interface;
      *) lte - use interface from RA when "ipv6-interface=none" and IPv6 enabled;
      *) ppp - added 3GPP IoT "access-technology" definitions;
      *) ppp - added support for Sierra WP7601;
      *) ppp - disable DTR send when using at-chat;
      *) quickset - added "LTE AP Dual" mode support;
      *) quickset - added "LTE APN" dropdown support;
      *) quickset - fixed "LTE Band" checkbox display;
      *) route - fixed area range summary route installation in VRF;
      *) routerboard - fixed default CPU frequency on RB750r2 ("/system routerboard upgrade" required);
      *) routerboard - fixed USB configuration export on RBLtAP-2HnD;
      *) routerboard - hide "memory-frequency" parameter for RBLtAP-2HnD;
      *) sfp - correctly read EEPROM data from SFP modules (introduced in v6.46beta38);
      *) sniffer - allow filtering by packet size;
      *) snmp - added "disabled" and "comment" parameters for communities (CLI only);
      *) snmp - added option to monitor "link-downs" parameter using MIKROTIK-MIB;
      *) snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
      *) snmp - fixed "ifLastChange" OID reporting for IF-MIB;
      *) snmp - fixed "radio-name" (mtxrWlRtabRadioName) OID support;
      *) snmp - improved interface status reporting for IfOperStatus OID;
      *) snmp - improved LLDP interface returned index and type;
      *) snmp - return only interfaces with MAC addresses for LLDP;
      *) snmp - use "src-address" also for traps;
      *) ssh - fixed output printing when "command" parameter used;
      *) supout - include information from all LTE interfaces;
      *) supout - removed "file" option from "/system sup-output" command;
      *) switch - correctly update dynamic switch rule when dhcp-snooping is enabled;
      *) switch - ignore "default-vlan-id" property after switch reset on RTL8367 switch chip;
      *) switch - show "external" flag for bridge hosts on MT7621, RTL8367 switch chips;
      *) system - fixed branding package installation (introduced in v6.46beta34);
      *) telnet - fixed successful connection establishment output in console (introduced in v6.46beta28);
      *) timezone - updated time zone database to version 2019c;
      *) tr069-client - added CellDiagnostics parameter support;
      *) tr069-client - added LTE band and cellular technology selection parameters;
      *) tr069-client - added LTE RSCP, ECNO and ICCID parameter support;
      *) tr069-client - added multiple LTE monitoring parameters;
      *) tr069-client - fixed firmware update (introduced in v6.46beta34);
      *) tr069-client - reconnect to ACS when "ConnectionRequestURL" is updated;
      *) upgrade - improved auto package updating using "check-for-updates";
      *) ups - improved compatibility with APC UPS's;
      *) usb - general USB modem stability improvements;
      *) userman - fixed customer referencing on WEB (introduced in v6.46beta9);
      *) userman - updated Authorize.Net to use SHA512 hashing;
      *) w60g - added "region" setting to limit allowed frequencies (CLI only);
      *) webfig - fixed link to Winbox download;
      *) winbox - added "ip-address" and stats columns in "IP/Kid-Control/Devices" menu;
      *) winbox - added "public-address-ipv6" parameter to "IP/Cloud" menu;
      *) winbox - added "reset-counters" button to "IP/Kid Control/Devices" menu;
      *) winbox - added "tx-info-field" parameter to "Wireless/W60G" menu;
      *) winbox - added "Vendor Classes" tab in "IP/DHCP Server" menu;
      *) winbox - added wireless alignment LED types to "System/LEDs" menu;
      *) winbox - fixed allowed range for bridge filter "new-priority" parameter;
      *) winbox - fixed "CAPs Scanner" stopping;
      *) winbox - fixed "cluster-id" parameter setting in "Routing/BGP/Instances" menu;
      *) winbox - fixed file locking when uploading multiple files at once;
      *) winbox - fixed firewall limit parameter support for rates more than 4G;
      *) winbox - fixed invalid flag presence in "IP/SMB/Shares" menu;
      *) winbox - fixed "Routing" menu icon presence when there is no routing package installed;
      *) winbox - improved stability when transfering multiple files between multiple windows;
      *) winbox - properly show timestamp in file "Creation Time" field;
      *) winbox - removed "Set CA Passphrase" button from "Certificate" menu;
      *) winbox - renamed "Queue Limit" to "Queue Size" for "pcq-upload-default" and "pcq-download-default" parameters;
      *) winbox - replaced "kb" with "KiB" in "Tools/Packet Sniffer" menu;
      *) winbox - show "Switch" menu on RBwAPGR-5HacD2HnD;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) wireless - added 4 chain MCS support for 802.11n wireless protocol (CLI only);
      *) wireless - added "indonesia4" regulatory domain information;
      *) wireless - added "push-button-5s" value for "wps-mode" parameter;
      *) wireless - added U-NII-2 support forRBSXTsqG-5acD, RBLHGG-5acD-XL, RBLHGG-5acD, RBLDFG-5acD, RBDiscG-5acD;
      *) wireless - allow using "canada2" regulatory domain on US lock devices;
      *) wireless - fixed 802.11n rate selection when managed by CAPsMAN;
      *) wireless - fixed RX chain selection;
      *) wireless - fixed sensor MAC address reporting in TZSP header;
      *) wireless - improved 802.11ac stability for all ARM devices with wireless;
      *) wireless - improved IPQ4019, QCA9984, QCA9888 wireless interface stability;
      *) wireless - updated "ukraine" regulatory domain information;
      *) wireless - updated "united-states" regulatory domain information;
      Что нового в версии 6.46beta68 (2019-Nov-21 09:13):

      MAJOR CHANGES IN v6.46:
      ----------------------
      !) lora - added support for LoRaWAN low-power wide-area network technology for MIPSBE, MMIPS and ARM;
      !) package - accept only packages with original filenames (CVE-2019-3976);
      !) package - improved package signature verification (CVE-2019-3977);
      !) security - fixed improper handling of DNS responses (CVE-2019-3978, CVE-2019-3979);
      ----------------------

      Изменения в этом выпуске:

      !) lora - added support for LoRaWAN low-power wide-area network technology for MIPSBE, MMIPS and ARM;
      *) backup - store automatically created backup file in "flash" directory;
      *) capsman - improved radar detection algorithm;
      *) certificate - added progress bar when creating certificate request (CLI only);
      *) certificate - added support for certificate request signing with EC keys;
      *) certificate - allow specifying "file-name" parameter for export (CLI only);
      *) certificate - allow specifying "name" parameter for import (CLI only);
      *) certificate - removed "key-size" parameter for "create-certificate-request" command;
      *) defconf - fixed default configuration generation on SXT R (introduced in v6.46beta28);
      *) dhcpv4-client - allow empty "dhcp-options" parameter when adding new client;
      *) dhcpv4-server - improved stability when RADIUS Interim update is sent;
      *) ike2 - improved stability when retransmitting first packet as responder;
      *) ipsec - fixed policy "sa-src-address" detection from "local-address" (introduced in v6.45);
      *) led - fixed default LED configuration for RBLHG-2nD and RBLHG-5HPnD;
      *) lte - added support for D402 modem;
      *) ptp - added support for IEEE 1588 Precision Clock Synchronization Protocol on CRS317-1G-16S+ (CLI only);
      *) route - fixed area range summary route installation in VRF;
      *) snmp - added option to monitor "link-downs" parameter using MIKROTIK-MIB;
      *) snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
      *) snmp - fixed "ifLastChange" OID reporting for IF-MIB;
      *) snmp - improved interface status reporting for IfOperStatus OID;
      *) ssh - fixed output printing when "command" parameter used;
      *) supout - include information from all LTE interfaces;
      *) switch - ignore "default-vlan-id" property after switch reset on RTL8367 switch chip;
      *) telnet - fixed successful connection establishment output in console (introduced in v6.46beta28);
      *) timezone - updated time zone database to version 2019c;
      *) ups - improved compatibility with APC UPS's;
      *) winbox - fixed "CAPs Scanner" stopping;
      *) wireless - added "indonesia4" regulatory domain information;
      *) wireless - added "push-button-5s" value for "wps-mode" parameter;
      *) wireless - added U-NII-2 support forRBSXTsqG-5acD, RBLHGG-5acD-XL, RBLHGG-5acD, RBLDFG-5acD, RBDiscG-5acD;

      Другие изменения v6.45.7:

      *) backup - fixed automatic backup file generation when configuration reset by button;
      *) bonding - correctly remove HW offloaded bonding with ARP monitoring;
      *) bonding - properly handle MAC addresses when bonding WLAN interfaces;
      *) bridge - disable/enable bridge port when setting bpdu-guard;
      *) bridge - do not add bridge as untagged VLAN member when frame-types=admit-only-vlan-tagged;
      *) bridge - include whole VLAN-id in DHCP Option 82 message;
      *) btest - removed duplicate "duration" parameter;
      *) capsman - fixed background scan showing incorrect regulatory domain mismatch error (CAP upgrade required);
      *) capsman - fixed channel auto reselection;
      *) capsman - improved DFS channel switching when radar detected;
      *) ccr - improved general system stability;
      *) certificate - improved CRL updating process;
      *) chr - added support for Azure guest agent;
      *) console - added bitwise operator support for "ip6" data type;
      *) console - fixed "address" column width when printing DHCPv4 leases;
      *) console - fixed IP conversion to "num" data type;
      *) console - fixed "tobool" conversion;
      *) console - properly detect IPv6 address as "ip6" data type;
      *) crs1xx/2xx - allow to set trunk port as mirroring target;
      *) crs305 - fixed sfp-sfpplus2 - sfp-sfpplus4 interface linking (introduced in v6.46beta28);
      *) crs3xx - correctly handle L2MTU change;
      *) crs3xx - do not send pause frames when ethernet "tx-flow-control" is disabled on CRS326/CRS328/CRS305 devices;
      *) crs3xx - improved interface initialization;
      *) crs3xx - improved switch-chip resource allocation on CRS317-1G-16S+, CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
      *) crs3xx - improved system stability on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
      *) crs3xx - remove previously set mirror-source property before changing it;
      *) defconf - fixed default configuration loading on RBmAPL-2nD (introduced in v6.45);
      *) defconf - require "policy" permission to print default configuration;
      *) dhcpv4-client - fixed "dhcp-options" parameter setting when adding new client;
      *) dhcpv6-client - properly update bind time when unused prefix received from the server;
      *) dhcpv6-client - properly update IPv6 address on rebind;
      *) dhcpv6-server - fixed logged error message when using "address-pool=static-only";
      *) dhcpv6-server - include "User-Name" parameter in accounting requests;
      *) dhcpv6-server - made "calling-station-id" contain MAC address if DUID contains it;
      *) dhcvp6-client - fixed timeout when doing rebind;
      *) dot1x - added "reject-vlan-id" server parameter (CLI only);
      *) dot1x - added support for dynamic switch rules from RADIUS;
      *) dot1x - added support for "mac-auth" authentication type (CLI only);
      *) dude - fixed data retrieval over SNMP (introduced in v6.46beta44);
      *) ethernet - automatically detect interface when using IP address for power-cycle-ping;
      *) ethernet - do not enable interface after reboot that is already disabled;
      *) ethernet - send requests only from ethernet interface when using MAC address for power-cycle-ping;
      *) fetch - fixed "dst-path" not allowed to create new directories (introduced in v6.46beta34);
      *) fetch - improved stability when processing large output data;
      *) gps - use "serial1" as default port on RBLtAP-2HnD;
      *) hotspot - fixed "html-directory" not allowed to create new directories (introduced in v6.46beta34);
      *) hotspot - fixed non-local NAT redirection to port TCP/64873;
      *) hotspot - fixed RADIUS CoA "address-list" update;
      *) ike1 - fixed minor spelling mistake in logs;
      *) ike2 - fixed IPv6 policy generation (introduced in v6.46beta28);
      *) ike2 - improved CHILD SA rekey process with Apple iOS 13;
      *) ipsec - added "error" topic for identity check failure logging messages;
      *) ipsec - fixed DNS resolving when domain has only AAAA entries;
      *) ipv6 - changed "advertise-dns" default value to "yes";
      *) log - increased log message length limit to 1024 characters;
      *) lte - added support for LM960A18;
      *) lte - added support for Telit LM960 and LE910C1 modems;
      *) lte - do not allow setting 3G and GSM modes on LTE only modems;
      *) lte - fixed band setting on R11e-4G;
      *) lte - fixed network registration on R11e-LTE-US;
      *) lte - fixed Sierra WP7601 driver loading;
      *) lte - fixed USB network device driver initialization (introduced in v6.46beta9);
      *) lte - fix "operator" names not being displayed properly;
      *) lte - improved modem initialization;
      *) lte - show "primary-band" only for LTE modems;
      *) lte - use /128 prefix for IPv6 address on LTE interface;
      *) lte - use interface from RA when "ipv6-interface=none" and IPv6 enabled;
      *) ppp - added 3GPP IoT "access-technology" definitions;
      *) ppp - added support for Sierra WP7601;
      *) ppp - disable DTR send when using at-chat;
      *) ptp - added support for IEEE 1588 Precision Clock Synchronization Protocol on CRS317-1G-16S+ (CLI only);
      *) quickset - added "LTE AP Dual" mode support;
      *) quickset - added "LTE APN" dropdown support;
      *) quickset - fixed "LTE Band" checkbox display;
      *) routerboard - fixed default CPU frequency on RB750r2 ("/system routerboard upgrade" required);
      *) routerboard - fixed USB configuration export on RBLtAP-2HnD;
      *) routerboard - hide "memory-frequency" parameter for RBLtAP-2HnD;
      *) sfp - correctly read EEPROM data from SFP modules (introduced in v6.46beta38);
      *) sniffer - allow filtering by packet size;
      *) snmp - added "disabled" and "comment" parameters for communities (CLI only);
      *) snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
      *) snmp - fixed "radio-name" (mtxrWlRtabRadioName) OID support;
      *) snmp - improved LLDP interface returned index and type;
      *) snmp - return only interfaces with MAC addresses for LLDP;
      *) snmp - use "src-address" also for traps;
      *) supout - removed "file" option from "/system sup-output" command;
      *) switch - correctly update dynamic switch rule when dhcp-snooping is enabled;
      *) switch - show "external" flag for bridge hosts on MT7621, RTL8367 switch chips;
      *) system - fixed branding package installation (introduced in v6.46beta34);
      *) tr069-client - added CellDiagnostics parameter support;
      *) tr069-client - added LTE band and cellular technology selection parameters;
      *) tr069-client - added LTE RSCP, ECNO and ICCID parameter support;
      *) tr069-client - added multiple LTE monitoring parameters;
      *) tr069-client - fixed firmware update (introduced in v6.46beta34);
      *) tr069-client - reconnect to ACS when "ConnectionRequestURL" is updated;
      *) upgrade - improved auto package updating using "check-for-updates";
      *) usb - general USB modem stability improvements;
      *) userman - fixed customer referencing on WEB (introduced in v6.46beta9);
      *) userman - updated Authorize.Net to use SHA512 hashing;
      *) w60g - added "region" setting to limit allowed frequencies (CLI only);
      *) webfig - fixed link to Winbox download;
      *) winbox - added "ip-address" and stats columns in "IP/Kid-Control/Devices" menu;
      *) winbox - added "public-address-ipv6" parameter to "IP/Cloud" menu;
      *) winbox - added "reset-counters" button to "IP/Kid Control/Devices" menu;
      *) winbox - added "tx-info-field" parameter to "Wireless/W60G" menu;
      *) winbox - added "Vendor Classes" tab in "IP/DHCP Server" menu;
      *) winbox - added wireless alignment LED types to "System/LEDs" menu;
      *) winbox - fixed allowed range for bridge filter "new-priority" parameter;
      *) winbox - fixed "cluster-id" parameter setting in "Routing/BGP/Instances" menu;
      *) winbox - fixed file locking when uploading multiple files at once;
      *) winbox - fixed firewall limit parameter support for rates more than 4G;
      *) winbox - fixed invalid flag presence in "IP/SMB/Shares" menu;
      *) winbox - fixed "Routing" menu icon presence when there is no routing package installed;
      *) winbox - improved stability when transfering multiple files between multiple windows;
      *) winbox - properly show timestamp in file "Creation Time" field;
      *) winbox - removed "Set CA Passphrase" button from "Certificate" menu;
      *) winbox - renamed "Queue Limit" to "Queue Size" for "pcq-upload-default" and "pcq-download-default" parameters;
      *) winbox - replaced "kb" with "KiB" in "Tools/Packet Sniffer" menu;
      *) winbox - show "Switch" menu on RBwAPGR-5HacD2HnD;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) wireless - added 4 chain MCS support for 802.11n wireless protocol (CLI only);
      *) wireless - allow using "canada2" regulatory domain on US lock devices;
      *) wireless - fixed 802.11n rate selection when managed by CAPsMAN;
      *) wireless - fixed RX chain selection;
      *) wireless - fixed sensor MAC address reporting in TZSP header;
      *) wireless - improved 802.11ac stability for all ARM devices with wireless;
      *) wireless - improved IPQ4019, QCA9984, QCA9888 wireless interface stability;
      *) wireless - updated "ukraine" regulatory domain information;
      *) wireless - updated "united-states" regulatory domain information;
      Что нового в версии 6.46beta9 (2019-Jul-11 09:04):

      Изменения в этом выпуске:

      *) bonding - fixed bonding running status after reboot when using other bonds as slave interfaces (introduced in v6.45);
      *) bonding - properly handle MAC addresses when bonding WLAN interfaces;
      *) dhcpv6-server - include "User-Name" parameter in accounting requests;
      *) ipsec - added "connection-mark" parameter for mode-config initiator;
      *) ipsec - allow peer argument only for "encrypt" policies (introduced in v6.45);
      *) ipsec - fixed peer configuration migration from versions older than v6.43 (introduced in v6.45);
      *) ipsec - show warning for policies with "unknown" peer;
      *) ospf - fixed possible busy loop condition when accessing OSPF LSAs;
      *) ppp - disable DTR send when using at-chat;
      *) ssh - do not enable "none-crypto" if "strong-crypto" is enabled on upgrade (introduced in v6.45);
      *) ssh - fixed executed command output printing (introduced in v6.45);
      *) supout - fixed supout file generation outside of internal storage with insufficient space;
      *) upgrade - fixed "auto-upgrade" to use new style authentication (introduced in v6.45);
      *) usb - general USB modem stability improvements;
      *) userman - updated Authorize.Net to use SHA512 hashing;
      *) vlan - fixed "slave" flag for non-running interfaces (introduced in v6.45);
      *) winbox - properly show timestamp in file "Creation Time" field;

      Другие изменения v6.45.1:

      *) cloud - properly stop "time-zone-autodetect" after disable;
      *) conntrack - properly start manually enabled connection tracking;
      *) dhcpv6-server - made "calling-station-id" contain MAC address if DUID contains it;
      *) fetch - improved stability when processing large output data;
      *) hotspot - fixed non-local NAT redirection to port TCP/64873;
      *) ipsec - improved stability for peer initialization (introduced in v6.45);
      *) lte - do not allow setting 3G and GSM modes on LTE only modems;
      *) lte - show "primary-band" only for LTE modems;
      *) radius - fixed "User-Password" encoding (introduced in v6.45);
      *) tr069-client - reconnect to ACS when "ConnectionRequestURL" is updated;
      *) w60g - added "region" setting to limit allowed frequencies (CLI only);
      Что нового в версии 6.46beta59 (2019-Oct-25 07:44):

      MAJOR CHANGES IN v6.46:
      ----------------------
      !) lora - added support for LoRaWAN low-power wide-area network technology for MIPSBE, MMIPS and ARM;
      !) package - accept only packages with original filenames (CVE-2019-3976);
      !) package - improved package signature verification (CVE-2019-3977);
      !) security - fixed improper handling of DNS responses (CVE-2019-3978, CVE-2019-3979);
      ----------------------

      Изменения в этом выпуске:

      !) lora - added support for LoRaWAN low-power wide-area network technology for MIPSBE, MMIPS and ARM;
      *) backup - fixed automatic backup file generation when configuration reset by button;
      *) capsman - fixed background scan showing incorrect regulatory domain mismatch error (CAP upgrade required);
      *) ccr - improved general system stability;
      *) crs3xx - improved interface initialization;
      *) dhcpv4-client - fixed "dhcp-options" parameter setting when adding new client;
      *) dhcpv6-client - properly update bind time when unused prefix received from the server;
      *) dhcpv6-client - properly update IPv6 address on rebind;
      *) dhcvp6-client - fixed timeout when doing rebind;
      *) ethernet - do not enable interface after reboot that is already disabled;
      *) export - fixed "bootp-support" parameter export;
      *) ike2 - improved CHILD SA rekey process with Apple iOS 13;
      *) ipv6 - changed "advertise-dns" default value to "yes";
      *) ptp - added support for IEEE 1588 Precision Clock Synchronization Protocol on CRS317-1G-16S+ (CLI only);
      *) snmp - added "disabled" and "comment" parameters for communities (CLI only);
      *) snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
      *) switch - show "external" flag for bridge hosts on MT7621, RTL8367 switch chips;
      *) wireless - added "canada2" regulatory domain information;
      *) wireless - allow using "canada2" regulatory domain on US lock devices;
      *) wireless - fixed sensor MAC address reporting in TZSP header;
      *) wireless - improved IPQ4019, QCA9984, QCA9888 wireless interface stability;

      Другие изменения v6.45.6:

      *) bonding - correctly remove HW offloaded bonding with ARP monitoring;
      *) bonding - properly handle MAC addresses when bonding WLAN interfaces;
      *) bridge - disable/enable bridge port when setting bpdu-guard;
      *) bridge - do not add bridge as untagged VLAN member when frame-types=admit-only-vlan-tagged;
      *) bridge - include whole VLAN-id in DHCP Option 82 message;
      *) btest - removed duplicate "duration" parameter;
      *) capsman - fixed channel auto reselection;
      *) capsman - fixed frequency setting requiring multiple frequencies;
      *) capsman - fixed newline character missing on some logging messages;
      *) capsman - improved DFS channel switching when radar detected;
      *) certificate - improved CRL updating process;
      *) chr - added support for Azure guest agent;
      *) conntrack - properly start manually enabled connection tracking;
      *) console - added bitwise operator support for "ip6" data type;
      *) console - fixed "address" column width when printing DHCPv4 leases;
      *) console - fixed IP conversion to "num" data type;
      *) console - fixed "tobool" conversion;
      *) console - properly detect IPv6 address as "ip6" data type;
      *) crs1xx/2xx - allow to set trunk port as mirroring target;
      *) crs305 - fixed sfp-sfpplus2 - sfp-sfpplus4 interface linking (introduced in v6.46beta28);
      *) crs312 - fixed combo SFP port toggling (introduced in v6.44.5);
      *) crs3xx - correctly display link rate when 10/100/1000BASE-T SFP modules are used in SFP+ interfaces;
      *) crs3xx - correctly handle L2MTU change;
      *) crs3xx - do not send pause frames when ethernet "tx-flow-control" is disabled on CRS326/CRS328/CRS305 devices;
      *) crs3xx - fixed management access when using switch rule "new-vlan-priority" property;
      *) crs3xx - improved switch-chip resource allocation on CRS317-1G-16S+, CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
      *) crs3xx - improved system stability on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
      *) crs3xx - remove previously set mirror-source property before changing it;
      *) defconf - fixed default configuration loading on RBmAPL-2nD (introduced in v6.45);
      *) defconf - require "policy" permission to print default configuration;
      *) dhcpv6-server - fixed logged error message when using "address-pool=static-only";
      *) dhcpv6-server - include "User-Name" parameter in accounting requests;
      *) dhcpv6-server - made "calling-station-id" contain MAC address if DUID contains it;
      *) dot1x - added "reject-vlan-id" server parameter (CLI only);
      *) dot1x - added support for dynamic switch rules from RADIUS;
      *) dot1x - added support for "mac-auth" authentication type (CLI only);
      *) dude - fixed data retrieval over SNMP (introduced in v6.46beta44);
      *) ethernet - automatically detect interface when using IP address for power-cycle-ping;
      *) ethernet - send requests only from ethernet interface when using MAC address for power-cycle-ping;
      *) fetch - fixed "dst-path" not allowed to create new directories (introduced in v6.46beta34);
      *) fetch - improved stability when processing large output data;
      *) gps - use "serial1" as default port on RBLtAP-2HnD;
      *) hotspot - fixed "html-directory" not allowed to create new directories (introduced in v6.46beta34);
      *) hotspot - fixed non-local NAT redirection to port TCP/64873;
      *) hotspot - fixed RADIUS CoA "address-list" update;
      *) ike1 - fixed minor spelling mistake in logs;
      *) ike2 - fixed IPv6 policy generation (introduced in v6.46beta28);
      *) ike2 - fixed phase 1 rekeying (introduced in v6.45);
      *) ipsec - added "error" topic for identity check failure logging messages;
      *) ipsec - fixed DNS resolving when domain has only AAAA entries;
      *) led - fixed default LED configuration for RBLHG5nD;
      *) log - increased log message length limit to 1024 characters;
      *) lte - added support for LM960A18;
      *) lte - added support for Telit LM960 and LE910C1 modems;
      *) lte - do not allow setting 3G and GSM modes on LTE only modems;
      *) lte - fixed band setting on R11e-4G;
      *) lte - fixed modem not receiving IP configuration when roaming (introduced in v6.45);
      *) lte - fixed network registration on R11e-LTE-US;
      *) lte - fixed Sierra WP7601 driver loading;
      *) lte - fixed USB network device driver initialization (introduced in v6.46beta9);
      *) lte - fix "operator" names not being displayed properly;
      *) lte - improved modem initialization;
      *) lte - show "primary-band" only for LTE modems;
      *) lte - use /128 prefix for IPv6 address on LTE interface;
      *) lte - use interface from RA when "ipv6-interface=none" and IPv6 enabled;
      *) ppp - added 3GPP IoT "access-technology" definitions;
      *) ppp - added support for Sierra WP7601;
      *) ppp - disable DTR send when using at-chat;
      *) ptp - added support for IEEE 1588 Precision Clock Synchronization Protocol on CRS317-1G-16S+ (CLI only);
      *) quickset - added "LTE AP Dual" mode support;
      *) quickset - added "LTE APN" dropdown support;
      *) quickset - fixed "LTE Band" checkbox display;
      *) radius - fixed open socket leak when invalid packet is received (introduced in v6.44);
      *) routerboard - fixed default CPU frequency on RB750r2 ("/system routerboard upgrade" required);
      *) routerboard - fixed USB configuration export on RBLtAP-2HnD;
      *) routerboard - hide "memory-frequency" parameter for RBLtAP-2HnD;
      *) sfp - correctly read EEPROM data from SFP modules (introduced in v6.46beta38);
      *) sfp - fixed "sfp-rx-power" value for some transceivers;
      *) sniffer - allow filtering by packet size;
      *) snmp - fixed "radio-name" (mtxrWlRtabRadioName) OID support;
      *) snmp - improved LLDP interface returned index and type;
      *) snmp - return only interfaces with MAC addresses for LLDP;
      *) snmp - use "src-address" also for traps;
      *) supout - removed "file" option from "/system sup-output" command;
      *) switch - correctly update dynamic switch rule when dhcp-snooping is enabled;
      *) system - fixed branding package installation (introduced in v6.46beta34);
      *) system - improved system stability for devices with AR9342;
      *) tr069-client - added CellDiagnostics parameter support;
      *) tr069-client - added LTE band and cellular technology selection parameters;
      *) tr069-client - added LTE RSCP, ECNO and ICCID parameter support;
      *) tr069-client - added multiple LTE monitoring parameters;
      *) tr069-client - fixed firmware update (introduced in v6.46beta34);
      *) tr069-client - reconnect to ACS when "ConnectionRequestURL" is updated;
      *) upgrade - improved auto package updating using "check-for-updates";
      *) usb - general USB modem stability improvements;
      *) userman - fixed customer referencing on WEB (introduced in v6.46beta9);
      *) userman - updated Authorize.Net to use SHA512 hashing;
      *) w60g - added "region" setting to limit allowed frequencies (CLI only);
      *) webfig - fixed link to Winbox download;
      *) winbox - added "ip-address" and stats columns in "IP/Kid-Control/Devices" menu;
      *) winbox - added "public-address-ipv6" parameter to "IP/Cloud" menu;
      *) winbox - added "reset-counters" button to "IP/Kid Control/Devices" menu;
      *) winbox - added "tx-info-field" parameter to "Wireless/W60G" menu;
      *) winbox - added "Vendor Classes" tab in "IP/DHCP Server" menu;
      *) winbox - added wireless alignment LED types to "System/LEDs" menu;
      *) winbox - fixed allowed range for bridge filter "new-priority" parameter;
      *) winbox - fixed "cluster-id" parameter setting in "Routing/BGP/Instances" menu;
      *) winbox - fixed file locking when uploading multiple files at once;
      *) winbox - fixed firewall limit parameter support for rates more than 4G;
      *) winbox - fixed invalid flag presence in "IP/SMB/Shares" menu;
      *) winbox - fixed "Routing" menu icon presence when there is no routing package installed;
      *) winbox - improved stability when transfering multiple files between multiple windows;
      *) winbox - properly show timestamp in file "Creation Time" field;
      *) winbox - removed "Set CA Passphrase" button from "Certificate" menu;
      *) winbox - renamed "Queue Limit" to "Queue Size" for "pcq-upload-default" and "pcq-download-default" parameters;
      *) winbox - replaced "kb" with "KiB" in "Tools/Packet Sniffer" menu;
      *) winbox - show "Switch" menu on RBwAPGR-5HacD2HnD;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) wireless - added 4 chain MCS support for 802.11n wireless protocol (CLI only);
      *) wireless - fixed 802.11n rate selection when managed by CAPsMAN;
      *) wireless - fixed RX chain selection;
      *) wireless - improved 802.11ac stability for all ARM devices with wireless;
      *) wireless - improved stability when setting fixed primary and secondary channels on RB4011iGS+5HacQ2HnD-IN;
      *) wireless - updated "ukraine" regulatory domain information;
      *) wireless - updated "united-states" regulatory domain information;
      Что нового в версии 6.46beta55 (2019-Oct-15 06:08):

      MAJOR CHANGES IN v6.46:
      ----------------------
      !) lora - added support for LoRaWAN low-power wide-area network technology for MIPSBE, MMIPS and ARM;
      ----------------------

      Изменения в этом выпуске:

      !) lora - added support for LoRaWAN low-power wide-area network technology for MIPSBE, MMIPS and ARM;
      *) bridge - include whole VLAN-id in DHCP Option 82 message;
      *) capsman - fixed background scan showing incorrect regulatory domain mismatch error;
      *) capsman - fixed frequency setting requiring multiple frequencies;
      *) capsman - fixed newline character missing on some logging messages;
      *) console - fixed "address" column width when printing DHCPv4 leases;
      *) crs1xx/2xx - allow to set trunk port as mirroring target;
      *) crs3xx - correctly display link rate when 10/100/1000BASE-T SFP modules are used in SFP+ interfaces;
      *) crs3xx - fixed management access when using switch rule "new-vlan-priority" property;
      *) crs3xx - improved switch-chip resource allocation on CRS317-1G-16S+, CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
      *) crs3xx - improved system stability on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
      *) dhcpv6-server - fixed logged error message when using "address-pool=static-only";
      *) dude - fixed data retrieval over SNMP (introduced in v6.46beta44);
      *) fetch - fixed "dst-path" not allowed to create new directories (introduced in v6.46beta34);
      *) hotspot - fixed "html-directory" not allowed to create new directories (introduced in v6.46beta34);
      *) led - fixed default LED configuration for RBLHG5nD;
      *) lte - added support for LM960A18;
      *) lte - fixed modem not receiving IP configuration when roaming (introduced in v6.45);
      *) lte - fixed Sierra WP7601 driver loading;
      *) lte - fix "operator" names not being displayed properly;
      *) ptp - added support for IEEE 1588 Precision Clock Synchronization Protocol on CRS317-1G-16S+ (CLI only);
      *) quickset - added "LTE APN" dropdown support;
      *) quickset - fixed "LTE Band" checkbox display;
      *) sfp - fixed "sfp-rx-power" value for some transceivers;
      *) sniffer - allow filtering by packet size;
      *) snmp - improved LLDP interface returned index and type;
      *) snmp - return only interfaces with MAC addresses for LLDP;
      *) system - fixed branding package installation (introduced in v6.46beta34);
      *) system - improved system stability for devices with AR9342;
      *) tr069-client - added CellDiagnostics parameter support;
      *) tr069-client - fixed firmware update (introduced in v6.46beta34);
      *) upgrade - improved auto package updating using "check-for-updates";
      *) userman - fixed customer referencing on WEB (introduced in v6.46beta9);
      *) wireless - updated "united-states" regulatory domain information;

      Другие изменения v6.45.6:

      *) bonding - correctly remove HW offloaded bonding with ARP monitoring;
      *) bonding - properly handle MAC addresses when bonding WLAN interfaces;
      *) bridge - disable/enable bridge port when setting bpdu-guard;
      *) bridge - do not add bridge as untagged VLAN member when frame-types=admit-only-vlan-tagged;
      *) btest - removed duplicate "duration" parameter;
      *) capsman - fixed channel auto reselection;
      *) capsman - improved DFS channel switching when radar detected;
      *) certificate - improved CRL updating process;
      *) chr - added support for Azure guest agent;
      *) conntrack - properly start manually enabled connection tracking;
      *) console - added bitwise operator support for "ip6" data type;
      *) console - fixed IP conversation to "num" data type;
      *) console - fixed "tobool" conversion;
      *) console - properly detect IPv6 address as "ip6" data type;
      *) crs305 - fixed sfp-sfpplus2 - sfp-sfpplus4 interface linking (introduced in v6.46beta28);
      *) crs312 - fixed combo SFP port toggling (introduced in v6.44.5);
      *) crs3xx - correctly display link rate when 10/100/1000BASE-T SFP modules are used in SFP+ interfaces;
      *) crs3xx - correctly handle L2MTU change;
      *) crs3xx - do not send pause frames when ethernet "tx-flow-control" is disabled on CRS326/CRS328/CRS305 devices;
      *) crs3xx - remove previously set mirror-source property before changing it;
      *) defconf - fixed default configuration loading on RBmAPL-2nD (introduced in v6.45);
      *) defconf - require "policy" permission to print default configuration;
      *) dhcpv6-server - include "User-Name" parameter in accounting requests;
      *) dhcpv6-server - made "calling-station-id" contain MAC address if DUID contains it;
      *) dot1x - added "reject-vlan-id" server parameter (CLI only);
      *) dot1x - added support for dynamic switch rules from RADIUS;
      *) dot1x - added support for "mac-auth" authentication type (CLI only);
      *) ethernet - automatically detect interface when using IP address for power-cycle-ping;
      *) ethernet - send requests only from ethernet interface when using MAC address for power-cycle-ping;
      *) fetch - improved stability when processing large output data;
      *) gps - use "serial1" as default port on RBLtAP-2HnD;
      *) hotspot - fixed non-local NAT redirection to port TCP/64873;
      *) hotspot - fixed RADIUS CoA "address-list" update;
      *) ike1 - fixed minor spelling mistake in logs;
      *) ike2 - fixed IPv6 policy generation (introduced in v6.46beta28);
      *) ike2 - fixed phase 1 rekeying (introduced in v6.45);
      *) ipsec - added "error" topic for identity check failure logging messages;
      *) ipsec - fixed DNS resolving when domain has only AAAA entries;
      *) log - increased log message length limit to 1024 characters;
      *) lte - added support for Telit LM960 and LE910C1 modems;
      *) lte - do not allow setting 3G and GSM modes on LTE only modems;
      *) lte - fixed band setting on R11e-4G;
      *) lte - fixed network registration on R11e-LTE-US;
      *) lte - fixed USB network device driver initialization (introduced in v6.46beta9);
      *) lte - improved modem initialization;
      *) lte - show "primary-band" only for LTE modems;
      *) lte - use /128 prefix for IPv6 address on LTE interface;
      *) lte - use interface from RA when "ipv6-interface=none" and IPv6 enabled;
      *) ppp - added 3GPP IoT "access-technology" definitions;
      *) ppp - added support for Sierra WP7601;
      *) ppp - disable DTR send when using at-chat;
      *) quickset - added "LTE AP Dual" mode support;
      *) radius - fixed open socket leak when invalid packet is received (introduced in v6.44);
      *) routerboard - fixed default CPU frequency on RB750r2 ("/system routerboard upgrade" required);
      *) routerboard - fixed USB configuration export on RBLtAP-2HnD;
      *) routerboard - hide "memory-frequency" parameter for RBLtAP-2HnD;
      *) sfp - correctly read EEPROM data from SFP modules (introduced in v6.46beta38);
      *) snmp - fixed "radio-name" (mtxrWlRtabRadioName) OID support;
      *) snmp - use "src-address" also for traps;
      *) supout - removed "file" option from "/system sup-output" command;
      *) switch - correctly update dynamic switch rule when dhcp-snooping is enabled;
      *) tr069-client - added LTE band and cellular technology selection parameters;
      *) tr069-client - added LTE RSCP, ECNO and ICCID parameter support;
      *) tr069-client - added multiple LTE monitoring parameters;
      *) tr069-client - reconnect to ACS when "ConnectionRequestURL" is updated;
      *) usb - general USB modem stability improvements;
      *) userman - updated Authorize.Net to use SHA512 hashing;
      *) w60g - added "region" setting to limit allowed frequencies (CLI only);
      *) webfig - fixed link to Winbox download;
      *) winbox - added "ip-address" and stats columns in "IP/Kid-Control/Devices" menu;
      *) winbox - added "public-address-ipv6" parameter to "IP/Cloud" menu;
      *) winbox - added "reset-counters" button to "IP/Kid Control/Devices" menu;
      *) winbox - added "tx-info-field" parameter to "Wireless/W60G" menu;
      *) winbox - added "Vendor Classes" tab in "IP/DHCP Server" menu;
      *) winbox - added wireless alignment LED types to "System/LEDs" menu;
      *) winbox - fixed allowed range for bridge filter "new-priority" parameter;
      *) winbox - fixed "cluster-id" parameter setting in "Routing/BGP/Instances" menu;
      *) winbox - fixed file locking when uploading multiple files at once;
      *) winbox - fixed firewall limit parameter support for rates more than 4G;
      *) winbox - fixed invalid flag presence in "IP/SMB/Shares" menu;
      *) winbox - fixed "Routing" menu icon presence when there is no routing package installed;
      *) winbox - improved stability when transfering multiple files between multiple windows;
      *) winbox - properly show timestamp in file "Creation Time" field;
      *) winbox - removed "Set CA Passphrase" button from "Certificate" menu;
      *) winbox - renamed "Queue Limit" to "Queue Size" for "pcq-upload-default" and "pcq-download-default" parameters;
      *) winbox - replaced "kb" with "KiB" in "Tools/Packet Sniffer" menu;
      *) winbox - show "Switch" menu on RBwAPGR-5HacD2HnD;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) wireless - added 4 chain MCS support for 802.11n wireless protocol (CLI only);
      *) wireless - fixed 802.11n rate selection when managed by CAPsMAN;
      *) wireless - fixed RX chain selection;
      *) wireless - improved 802.11ac stability for all ARM devices with wireless;
      *) wireless - improved stability when setting fixed primary and secondary channels on RB4011iGS+5HacQ2HnD-IN;
      *) wireless - updated "ukraine" regulatory domain information;
      Что нового в версии 6.46beta44 (2019-Sep-19 05:54):

      Изменения в этом выпуске:

      *) capsman - fixed channel auto reselection;
      *) chr - added support for Azure guest agent;
      *) console - fixed "tobool" conversion;
      *) crs305 - fixed sfp-sfpplus2 - sfp-sfpplus4 interface linking (introduced in v6.46beta28);
      *) crs3xx - correctly display link rate when 10/100/1000BASE-T SFP modules are used in SFP+ interfaces;
      *) crs3xx - do not send pause frames when ethernet "tx-flow-control" is disabled on CRS326/CRS328/CRS305 devices;
      *) defconf - fixed default configuration loading on RBmAPL-2nD (introduced in v6.45);
      *) dot1x - added support for dynamic switch rules from RADIUS;
      *) ike2 - fixed phase 1 rekeying (introduced in v6.45);
      *) lte - added support for Telit LM960 and LE910C1 modems;
      *) lte - improved modem initialization;
      *) routerboard - fixed USB configuration export on RBLtAP-2HnD;
      *) routerboard - hide "memory-frequency" parameter for RBLtAP-2HnD;
      *) sfp - correctly read EEPROM data from SFP modules (introduced in v6.46beta38);
      *) snmp - use "src-address" also for traps;
      *) wireless - improved stability when setting fixed primary and secondary channels on RB4011iGS+5HacQ2HnD-IN;

      Другие изменения v6.45.6:

      *) bonding - correctly remove HW offloaded bonding with ARP monitoring;
      *) bonding - properly handle MAC addresses when bonding WLAN interfaces;
      *) bridge - disable/enable bridge port when setting bpdu-guard;
      *) bridge - do not add bridge as untagged VLAN member when frame-types=admit-only-vlan-tagged;
      *) btest - removed duplicate "duration" parameter;
      *) capsman - improved DFS channel switching when radar detected;
      *) certificate - improved CRL updating process;
      *) conntrack - properly start manually enabled connection tracking;
      *) console - added bitwise operator support for "ip6" data type;
      *) console - fixed IP conversation to "num" data type;
      *) console - properly detect IPv6 address as "ip6" data type;
      *) crs312 - fixed combo SFP port toggling (introduced in v6.44.5);
      *) crs3xx - correctly handle L2MTU change;
      *) crs3xx - remove previously set mirror-source property before changing it;
      *) defconf - require "policy" permission to print default configuration;
      *) dhcpv6-server - include "User-Name" parameter in accounting requests;
      *) dhcpv6-server - made "calling-station-id" contain MAC address if DUID contains it;
      *) dot1x - added "reject-vlan-id" server parameter (CLI only);
      *) dot1x - added support for "mac-auth" authentication type (CLI only);
      *) dot1x - added support for "mac-auth" authentication type (CLI only);
      *) ethernet - automatically detect interface when using IP address for power-cycle-ping;
      *) ethernet - send requests only from ethernet interface when using MAC address for power-cycle-ping;
      *) fetch - improved stability when processing large output data;
      *) gps - use "serial1" as default port on RBLtAP-2HnD;
      *) hotspot - fixed non-local NAT redirection to port TCP/64873;
      *) hotspot - fixed RADIUS CoA "address-list" update;
      *) ike1 - fixed minor spelling mistake in logs;
      *) ike2 - fixed IPv6 policy generation (introduced in v6.46beta28);
      *) ipsec - added "error" topic for identity check failure logging messages;
      *) ipsec - fixed DNS resolving when domain has only AAAA entries;
      *) log - increased log message length limit to 1024 characters;
      *) lte - do not allow setting 3G and GSM modes on LTE only modems;
      *) lte - fixed band setting on R11e-4G;
      *) lte - fixed network registration on R11e-LTE-US;
      *) lte - fixed USB network device driver initialization (introduced in v6.46beta9);
      *) lte - show "primary-band" only for LTE modems;
      *) lte - use /128 prefix for IPv6 address on LTE interface;
      *) lte - use interface from RA when "ipv6-interface=none" and IPv6 enabled;
      *) ppp - added 3GPP IoT "access-technology" definitions;
      *) ppp - added support for Sierra WP7601;
      *) ppp - disable DTR send when using at-chat;
      *) quickset - added "LTE AP Dual" mode support;
      *) radius - fixed open socket leak when invalid packet is received (introduced in v6.44);
      *) routerboard - fixed default CPU frequency on RB750r2 ("/system routerboard upgrade" required);
      *) snmp - fixed "radio-name" (mtxrWlRtabRadioName) OID support;
      *) supout - removed "file" option from "/system sup-output" command;
      *) switch - correctly update dynamic switch rule when dhcp-snooping is enabled;
      *) tr069-client - added LTE band and cellular technology selection parameters;
      *) tr069-client - added LTE RSCP, ECNO and ICCID parameter support;
      *) tr069-client - added multiple LTE monitoring parameters;
      *) tr069-client - reconnect to ACS when "ConnectionRequestURL" is updated;
      *) usb - general USB modem stability improvements;
      *) userman - updated Authorize.Net to use SHA512 hashing;
      *) w60g - added "region" setting to limit allowed frequencies (CLI only);
      *) webfig - fixed link to Winbox download;
      *) winbox - added "ip-address" and stats columns in "IP/Kid-Control/Devices" menu;
      *) winbox - added "public-address-ipv6" parameter to "IP/Cloud" menu;
      *) winbox - added "reset-counters" button to "IP/Kid Control/Devices" menu;
      *) winbox - added "tx-info-field" parameter to "Wireless/W60G" menu;
      *) winbox - added "Vendor Classes" tab in "IP/DHCP Server" menu;
      *) winbox - added wireless alignment LED types to "System/LEDs" menu;
      *) winbox - fixed allowed range for bridge filter "new-priority" parameter;
      *) winbox - fixed "cluster-id" parameter setting in "Routing/BGP/Instances" menu;
      *) winbox - fixed file locking when uploading multiple files at once;
      *) winbox - fixed firewall limit parameter support for rates more than 4G;
      *) winbox - fixed invalid flag presence in "IP/SMB/Shares" menu;
      *) winbox - fixed "Routing" menu icon presence when there is no routing package installed;
      *) winbox - improved stability when transfering multiple files between multiple windows;
      *) winbox - properly show timestamp in file "Creation Time" field;
      *) winbox - removed "Set CA Passphrase" button from "Certificate" menu;
      *) winbox - renamed "Queue Limit" to "Queue Size" for "pcq-upload-default" and "pcq-download-default" parameters;
      *) winbox - replaced "kb" with "KiB" in "Tools/Packet Sniffer" menu;
      *) winbox - show "Switch" menu on RBwAPGR-5HacD2HnD;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) wireless - added 4 chain MCS support for 802.11n wireless protocol (CLI only);
      *) wireless - fixed 802.11n rate selection when managed by CAPsMAN;
      *) wireless - fixed RX chain selection;
      *) wireless - improved 802.11ac stability for all ARM devices with wireless;
      *) wireless - updated "ukraine" regulatory domain information;
      Что нового в версии 6.46beta38 (2019-Aug-29 07:29):

      Изменения в этом выпуске:

      *) btest - removed duplicate "duration" parameter;
      *) console - added bitwise operator support for "ip6" data type;
      *) console - fixed IP conversation to "num" data type;
      *) console - properly detect IPv6 address as "ip6" data type;
      *) crs312 - fixed combo SFP port toggling (introduced in v6.44.5);
      *) crs3xx - fixed "egress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
      *) dot1x - added "reject-vlan-id" server parameter (CLI only);
      *) dot1x - added support for "mac-auth" authentication type (CLI only);
      *) qsfp - clear SFP monitoring data on port enable;
      *) qsfp - correctly display SFP monitoring data;
      *) qsfp - fixed EEPROM checksum validation;
      *) radius - fixed open socket leak when invalid packet is received (introduced in v6.44);
      *) supout - removed "file" option from "/system sup-output" command;
      *) wireless - added 4 chain MCS support for 802.11n wireless protocol (CLI only);
      *) wireless - fixed RX chain selection;
      *) wireless - include last frequency when manually setting frequency step in "scan-list";

      Другие изменения v6.45.5:

      *) bonding - correctly remove HW offloaded bonding with ARP monitoring;
      *) bonding - properly handle MAC addresses when bonding WLAN interfaces;
      *) bridge - disable/enable bridge port when setting bpdu-guard;
      *) bridge - do not add bridge as untagged VLAN member when frame-types=admit-only-vlan-tagged;
      *) capsman - improved DFS channel switching when radar detected;
      *) certificate - improved CRL updating process;
      *) conntrack - properly start manually enabled connection tracking;
      *) crs3xx - correctly handle L2MTU change;
      *) crs3xx - remove previously set mirror-source property before changing it;
      *) defconf - require "policy" permission to print default configuration;
      *) dhcpv6-server - include "User-Name" parameter in accounting requests;
      *) dhcpv6-server - made "calling-station-id" contain MAC address if DUID contains it;
      *) dot1x - added support for "mac-auth" authentication type (CLI only);
      *) ethernet - automatically detect interface when using IP address for power-cycle-ping;
      *) ethernet - send requests only from ethernet interface when using MAC address for power-cycle-ping;
      *) fetch - improved stability when processing large output data;
      *) gps - use "serial1" as default port on RBLtAP-2HnD;
      *) hotspot - fixed non-local NAT redirection to port TCP/64873;
      *) hotspot - fixed RADIUS CoA "address-list" update;
      *) ike1 - fixed minor spelling mistake in logs;
      *) ike2 - fixed IPv6 policy generation (introduced in v6.46beta28);
      *) ipsec - added "error" topic for identity check failure logging messages;
      *) ipsec - fixed DNS resolving when domain has only AAAA entries;
      *) log - increased log message length limit to 1024 characters;
      *) lte - do not allow setting 3G and GSM modes on LTE only modems;
      *) lte - fixed band setting on R11e-4G;
      *) lte - fixed network registration on R11e-LTE-US;
      *) lte - fixed USB network device driver initialization (introduced in v6.46beta9);
      *) lte - show "primary-band" only for LTE modems;
      *) lte - use /128 prefix for IPv6 address on LTE interface;
      *) lte - use interface from RA when "ipv6-interface=none" and IPv6 enabled;
      *) ppp - added 3GPP IoT "access-technology" definitions;
      *) ppp - added support for Sierra WP7601;
      *) ppp - disable DTR send when using at-chat;
      *) qsfp - show more QSFP module diagnostics;
      *) quickset - added "LTE AP Dual" mode support;
      *) routerboard - fixed default CPU frequency on RB750r2 ("/system routerboard upgrade" required);
      *) snmp - fixed "radio-name" (mtxrWlRtabRadioName) OID support;
      *) switch - correctly update dynamic switch rule when dhcp-snooping is enabled;
      *) tr069-client - added LTE band and cellular technology selection parameters;
      *) tr069-client - added LTE RSCP, ECNO and ICCID parameter support;
      *) tr069-client - added multiple LTE monitoring parameters;
      *) tr069-client - reconnect to ACS when "ConnectionRequestURL" is updated;
      *) usb - general USB modem stability improvements;
      *) userman - updated Authorize.Net to use SHA512 hashing;
      *) w60g - added "region" setting to limit allowed frequencies (CLI only);
      *) webfig - fixed link to Winbox download;
      *) winbox - added "ip-address" and stats columns in "IP/Kid-Control/Devices" menu;
      *) winbox - added "public-address-ipv6" parameter to "IP/Cloud" menu;
      *) winbox - added "reset-counters" button to "IP/Kid Control/Devices" menu;
      *) winbox - added "tx-info-field" parameter to "Wireless/W60G" menu;
      *) winbox - added "Vendor Classes" tab in "IP/DHCP Server" menu;
      *) winbox - added wireless alignment LED types to "System/LEDs" menu;
      *) winbox - fixed allowed range for bridge filter "new-priority" parameter;
      *) winbox - fixed "cluster-id" parameter setting in "Routing/BGP/Instances" menu;
      *) winbox - fixed file locking when uploading multiple files at once;
      *) winbox - fixed firewall limit parameter support for rates more than 4G;
      *) winbox - fixed invalid flag presence in "IP/SMB/Shares" menu;
      *) winbox - fixed "Routing" menu icon presence when there is no routing package installed;
      *) winbox - improved stability when transfering multiple files between multiple windows;
      *) winbox - properly show timestamp in file "Creation Time" field;
      *) winbox - removed "Set CA Passphrase" button from "Certificate" menu;
      *) winbox - renamed "Queue Limit" to "Queue Size" for "pcq-upload-default" and "pcq-download-default" parameters;
      *) winbox - replaced "kb" with "KiB" in "Tools/Packet Sniffer" menu;
      *) winbox - show "Switch" menu on RBwAPGR-5HacD2HnD;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) wireless - fixed 802.11n rate selection when managed by CAPsMAN;
      *) wireless - improved 802.11ac stability for all ARM devices with wireless;
      *) wireless - updated "ukraine" regulatory domain information;
      Что нового в версии 6.46beta34 (2019-Aug-22 06:24):

      Изменения в этом выпуске:

      *) dhcpv4-server - fixed "Acct-Output-Octets" reporting to RADIUS;
      *) dot1x - added support for "mac-auth" authentication type (CLI only);
      *) hotspot - fixed RADIUS CoA "address-list" update;
      *) ike2 - fixed IPv6 policy generation (introduced in v6.46beta28);
      *) ike2 - fixed traffic selector address family selection when using IPv6;
      *) ike2 - properly start all initiators to the same remote address;
      *) ipsec - fixed DNS resolving when domain has only AAAA entries;
      *) ipsec - fixed "eap-radius" authentication method (introduced in v6.45);
      *) ipsec - fixed minor spelling mistakes in logs;
      *) log - increased log message length limit to 1024 characters;
      *) lte - fixed network registration on R11e-LTE-US;
      *) lte - use /128 prefix for IPv6 address on LTE interface;
      *) lte - use interface from RA when "ipv6-interface=none" and IPv6 enabled;
      *) qsfp - show more QSFP module diagnostics;
      *) quickset - added "LTE AP Dual" mode support;
      *) snmp - fixed encrypted data sequence (introduced in v6.44.5);
      *) ssh - fixed carriage return presence in subsequent sessions;
      *) system - accept only valid string for "name" parameter in "disk" menu (CVE-2019-15055);
      *) tr069-client - added LTE band and cellular technology selection parameters;
      *) tr069-client - added LTE RSCP, ECNO and ICCID parameter support;
      *) watchdog - renamed "no-ping-delay" parameter to "ping-start-after-boot";


      Другие изменения v6.45.3:

      *) bonding - correctly remove HW offloaded bonding with ARP monitoring;
      *) bonding - properly handle MAC addresses when bonding WLAN interfaces;
      *) bridge - disable/enable bridge port when setting bpdu-guard;
      *) bridge - do not add bridge as untagged VLAN member when frame-types=admit-only-vlan-tagged;
      *) capsman - improved DFS channel switching when radar detected;
      *) certificate - improved CRL updating process;
      *) conntrack - properly start manually enabled connection tracking;
      *) crs3xx - correctly handle L2MTU change;
      *) crs3xx - remove previously set mirror-source property before changing it;
      *) defconf - require "policy" permission to print default configuration;
      *) dhcpv6-server - include "User-Name" parameter in accounting requests;
      *) dhcpv6-server - made "calling-station-id" contain MAC address if DUID contains it;
      *) ethernet - automatically detect interface when using IP address for power-cycle-ping;
      *) ethernet - send requests only from ethernet interface when using MAC address for power-cycle-ping;
      *) fetch - improved stability when processing large output data;
      *) gps - use "serial1" as default port on RBLtAP-2HnD;
      *) hotspot - fixed non-local NAT redirection to port TCP/64873;
      *) ike1 - fixed minor spelling mistake in logs;
      *) ike2 - don't release policy on rekey when child not found;
      *) ike2 - fixed ID validation with multiple SAN;
      *) ike2 - fixed policy port selection for responder with natted initiator;
      *) ike2 - improved rekeying process with Windows initiators;
      *) ipsec - added "error" topic for identity check failure logging messages;
      *) ipsec - allow inline "passphrase" parameter when importing keys;
      *) lte - do not allow setting 3G and GSM modes on LTE only modems;
      *) lte - fixed band setting on R11e-4G;
      *) lte - fixed cell information monitoring on R11e-LTE-US (introduced in v6.45.2);
      *) lte - fixed USB network device driver initialization (introduced in v6.46beta9);
      *) lte - show "primary-band" only for LTE modems;
      *) ppp - added 3GPP IoT "access-technology" definitions;
      *) ppp - added support for Sierra WP7601;
      *) ppp - disable DTR send when using at-chat;
      *) routerboard - fixed default CPU frequency on RB750r2 ("/system routerboard upgrade" required);
      *) snmp - fixed "radio-name" (mtxrWlRtabRadioName) OID support;
      *) switch - correctly update dynamic switch rule when dhcp-snooping is enabled;
      *) switch - fix port isolation for non-CRS series switch chips;
      *) tr069-client - added multiple LTE monitoring parameters;
      *) tr069-client - reconnect to ACS when "ConnectionRequestURL" is updated;
      *) usb - general USB modem stability improvements;
      *) userman - updated Authorize.Net to use SHA512 hashing;
      *) w60g - added "region" setting to limit allowed frequencies (CLI only);
      *) webfig - fixed link to Winbox download;
      *) winbox - added "auto-erase" parameter to "Tools/SMS" menu;
      *) winbox - added "https-redirect" parameter to "IP/Hotspot/Profiles menu";
      *) winbox - added "ip-address" and stats columns in "IP/Kid-Control/Devices" menu;
      *) winbox - added "public-address-ipv6" parameter to "IP/Cloud" menu;
      *) winbox - added "reset-counters" button to "IP/Kid Control/Devices" menu;
      *) winbox - added "revision" parameter to "System/Routerboard" menu;
      *) winbox - added "tx-info-field" parameter to "Wireless/W60G" menu;
      *) winbox - added "Vendor Classes" tab in "IP/DHCP Server" menu;
      *) winbox - added wireless alignment LED types to "System/LEDs" menu;
      *) winbox - fixed allowed range for bridge filter "new-priority" parameter;
      *) winbox - fixed "cluster-id" parameter setting in "Routing/BGP/Instances" menu;
      *) winbox - fixed file locking when uploading multiple files at once;
      *) winbox - fixed firewall limit parameter support for rates more than 4G;
      *) winbox - fixed invalid flag presence in "IP/SMB/Shares" menu;
      *) winbox - fixed "Routing" menu icon presence when there is no routing package installed;
      *) winbox - improved stability when transfering multiple files between multiple windows;
      *) winbox - properly show timestamp in file "Creation Time" field;
      *) winbox - removed "max-sms" parameter from "Tools/SMS" menu;
      *) winbox - removed "Set CA Passphrase" button from "Certificate" menu;
      *) winbox - renamed "Queue Limit" to "Queue Size" for "pcq-upload-default" and "pcq-download-default" parameters;
      *) winbox - replaced "kb" with "KiB" in "Tools/Packet Sniffer" menu;
      *) winbox - show "Switch" menu on RBwAPGR-5HacD2HnD;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) wireless - fixed 802.11n rate selection when managed by CAPsMAN;
      *) wireless - fixed basic rate reporting in snooper;
      *) wireless - improved 802.11ac stability for all ARM devices with wireless;
      *) wireless - updated "ukraine" regulatory domain information;
      Что нового в версии 6.46beta28 (2019-Aug-08 07:26):

      Изменения в этом выпуске:

      *) certificate - improved CRL updating process;
      *) defconf - require "policy" permission to print default configuration;
      *) gps - use "serial1" as default port on RBLtAP-2HnD;
      *) ike1 - fixed minor spelling mistake in logs;
      *) ike2 - don't release policy on rekey when child not found;
      *) ike2 - fixed ID validation with multiple SAN;
      *) ike2 - fixed policy port selection for responder with natted initiator;
      *) ike2 - improved rekeying process with Windows initiators;
      *) ipsec - allow inline "passphrase" parameter when importing keys;
      *) lte - fixed band setting on R11e-4G;
      *) lte - fixed cell information monitoring on R11e-LTE-US (introduced in v6.45.2);
      *) ppp - added 3GPP IoT "access-technology" definitions;
      *) ppp - added support for Sierra WP7601;
      *) routerboard - fixed default CPU frequency on RB750r2 ("/system routerboard upgrade" required);
      *) snmp - fixed "radio-name" (mtxrWlRtabRadioName) OID support;
      *) webfig - fixed link to Winbox download;
      *) winbox - added "auto-erase" parameter to "Tools/SMS" menu;
      *) winbox - added "https-redirect" parameter to "IP/Hotspot/Profiles menu";
      *) winbox - added "ip-address" and stats columns in "IP/Kid-Control/Devices" menu;
      *) winbox - added "public-address-ipv6" parameter to "IP/Cloud" menu;
      *) winbox - added "reset-counters" button to "IP/Kid Control/Devices" menu;
      *) winbox - added "revision" parameter to "System/Routerboard" menu;
      *) winbox - added "tx-info-field" parameter to "Wireless/W60G" menu;
      *) winbox - added "Vendor Classes" tab in "IP/DHCP Server" menu;
      *) winbox - added wireless alignment LED types to "System/LEDs" menu;
      *) winbox - fixed allowed range for bridge filter "new-priority" parameter;
      *) winbox - fixed "cluster-id" parameter setting in "Routing/BGP/Instances" menu;
      *) winbox - fixed file locking when uploading multiple files at once;
      *) winbox - fixed firewall limit parameter support for rates more than 4G;
      *) winbox - fixed invalid flag presence in "IP/SMB/Shares" menu;
      *) winbox - fixed "Routing" menu icon presence when there is no routing package installed;
      *) winbox - improved stability when transfering multiple files between multiple windows;
      *) winbox - removed "max-sms" parameter from "Tools/SMS" menu;
      *) winbox - removed "Set CA Passphrase" button from "Certificate" menu;
      *) winbox - renamed "Queue Limit" to "Queue Size" for "pcq-upload-default" and "pcq-download-default" parameters;
      *) winbox - replaced "kb" with "KiB" in "Tools/Packet Sniffer" menu;
      *) winbox - show "Switch" menu on RBwAPGR-5HacD2HnD;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) wireless - fixed basic rate reporting in snooper;

      Другие изменения v6.45.3:

      *) bonding - correctly remove HW offloaded bonding with ARP monitoring;
      *) bonding - properly handle MAC addresses when bonding WLAN interfaces;
      *) bridge - disable/enable bridge port when setting bpdu-guard;
      *) bridge - do not add bridge as untagged VLAN member when frame-types=admit-only-vlan-tagged;
      *) capsman - improved DFS channel switching when radar detected;
      *) conntrack - properly start manually enabled connection tracking;
      *) crs3xx - correctly handle L2MTU change;
      *) crs3xx - remove previously set mirror-source property before changing it;
      *) dhcpv6-server - include "User-Name" parameter in accounting requests;
      *) dhcpv6-server - made "calling-station-id" contain MAC address if DUID contains it;
      *) ethernet - automatically detect interface when using IP address for power-cycle-ping;
      *) ethernet - send requests only from ethernet interface when using MAC address for power-cycle-ping;
      *) fetch - improved stability when processing large output data;
      *) hotspot - fixed non-local NAT redirection to port TCP/64873;
      *) ipsec - added "error" topic for identity check failure logging messages;
      *) lte - do not allow setting 3G and GSM modes on LTE only modems;
      *) lte - fixed USB network device driver initialization (introduced in v6.46beta9);
      *) lte - show "primary-band" only for LTE modems;
      *) ppp - disable DTR send when using at-chat;
      *) switch - correctly update dynamic switch rule when dhcp-snooping is enabled;
      *) switch - fix port isolation for non-CRS series switch chips;
      *) tr069-client - added multiple LTE monitoring parameters;
      *) tr069-client - reconnect to ACS when "ConnectionRequestURL" is updated;
      *) usb - general USB modem stability improvements;
      *) userman - updated Authorize.Net to use SHA512 hashing;
      *) w60g - added "region" setting to limit allowed frequencies (CLI only);
      *) winbox - properly show timestamp in file "Creation Time" field;
      *) wireless - fixed 802.11n rate selection when managed by CAPsMAN;
      *) wireless - improved 802.11ac stability for all ARM devices with wireless;
      *) wireless - updated "ukraine" regulatory domain information;
      Что нового в версии 6.46beta16 (2019-Jul-23 06:44):

      Изменения в этом выпуске:

      *) bonding - correctly remove HW offloaded bonding with ARP monitoring;
      *) bridge - disable/enable bridge port when setting bpdu-guard;
      *) bridge - do not add bridge as untagged VLAN member when frame-types=admit-only-vlan-tagged;
      *) capsman - improved DFS channel switching when radar detected;
      *) crs3xx - correctly handle L2MTU change;
      *) crs3xx - remove previously set mirror-source property before changing it;
      *) ethernet - automatically detect interface when using IP address for power-cycle-ping;
      *) ethernet - send requests only from ethernet interface when using MAC address for power-cycle-ping;
      *) ipsec - added "error" topic for identity check failure logging messages;
      *) lte - fixed USB network device driver initialization (introduced in v6.46beta9);
      *) smips - reduced RouterOS main package size (disabled LTE modem, dot1x and SwOS support);
      *) switch - correctly update dynamic switch rule when dhcp-snooping is enabled;
      *) switch - fix port isolation for non-CRS series switch chips;
      *) tr069-client - added multiple LTE monitoring parameters;
      *) wireless - fixed 802.11n rate selection when managed by CAPsMAN;
      *) wireless - improved 802.11ac stability for all ARM devices with wireless;
      *) wireless - improved U-APSD (WMM Power Save) support for 802.11e;
      *) wireless - updated "ukraine" regulatory domain information;

      Другие изменения v6.45.2:

      *) bonding - properly handle MAC addresses when bonding WLAN interfaces;
      *) conntrack - properly start manually enabled connection tracking;
      *) dhcpv6-server - include "User-Name" parameter in accounting requests;
      *) dhcpv6-server - made "calling-station-id" contain MAC address if DUID contains it;
      *) fetch - improved stability when processing large output data;
      *) hotspot - fixed non-local NAT redirection to port TCP/64873;
      *) lte - do not allow setting 3G and GSM modes on LTE only modems;
      *) lte - show "primary-band" only for LTE modems;
      *) ppp - disable DTR send when using at-chat;
      *) tr069-client - reconnect to ACS when "ConnectionRequestURL" is updated;
      *) usb - general USB modem stability improvements;
      *) userman - updated Authorize.Net to use SHA512 hashing;
      *) w60g - added "region" setting to limit allowed frequencies (CLI only);
      *) winbox - properly show timestamp in file "Creation Time" field;
      Что нового в версии 6.46beta6 (2019-Jul-04 11:53):

      Изменения в этом выпуске:

      *) cloud - properly stop "time-zone-autodetect" after disable;
      *) conntrack - properly start manually enabled connection tracking;
      *) dhcpv6-server - made "calling-station-id" contain MAC address if DUID contains it;
      *) fetch - improved stability when processing large output data;
      *) hotspot - fixed non-local NAT redirection to port TCP/64873;
      *) ipsec - improved stability for peer initialization (introduced in v6.45);
      *) lte - do not allow setting 3G and GSM modes on LTE only modems;
      *) lte - show "primary-band" only for LTE modems;
      *) radius - fixed "User-Password" encoding (introduced in v6.45);
      *) tr069-client - reconnect to ACS when "ConnectionRequestURL" is updated;
      *) w60g - added "region" setting to limit allowed frequencies (CLI only);
      Что нового в версии 6.45beta62 (2019-Jun-13 10:13):

      Важная заметка!!!
      Downgrading to any version prior to v6.43 (v6.42.12 and older) will clear all user passwords and allow password-less authentication. Please secure your router after downgrading.

      MAJOR CHANGES IN v6.45:
      ----------------------
      !) dot1x - added support for IEEE 802.1X Port-Based Network Access Control;
      !) ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap, eap-mschapv2) as initiator;
      !) user - removed insecure password storage;
      ----------------------

      Изменения в этом выпуске:

      !) dot1x - added support for IEEE 802.1X Port-Based Network Access Control;
      !) ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap, eap-mschapv2) as initiator;
      *) bridge - correctly handle bridge host table;
      *) capsman - fixed CAP system upgrading process for MMIPS;
      *) certificate - added "key-type" field;
      *) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1);
      *) crs3xx - fixed "tx-drop" counter;
      *) defconf - fixed channel width selection for RU locked devices;
      *) dhcpv4-server - added "client-mac-limit" parameter;
      *) dhcpv6-client - added option to disable rapid-commit;
      *) dhcpv6-server - added additional RADIUS parameters for Prefix delegation, "rate-limit" and "life-time";
      *) dhcpv6-server - added "address-list" support for bindings;
      *) dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters;
      *) dhcpv6-server - added RADIUS accounting support with queue based statistics;
      *) dhcpv6-server - added "route-distance" parameter;
      *) e-mail - properly release e-mail sending session if the server's domain name can not be resolved;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity;
      *) ipsec - added "ph2-total" counter to "active-peers" menu;
      *) ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods;
      *) ipsec - added traffic statistics to "active-peers" menu;
      *) ipsec - disallow setting "src-address" and "dst-address" for transport mode policies;
      *) ipsec - renamed "remote-peers" to "active-peers";
      *) ltap - renamed SIM slots "up" and "down" to "2" and "3";
      *) lte - added passthrough interface subnet selection;
      *) lte - fixed LTE interface running state on RBSXTLTE3-7 (introduced in v6.45beta);
      *) m33g - added support for additional Serial Console port on GPIO headers;
      *) routerboard - renamed 'sim' menu to 'modem';
      *) snmp - fixed "send-trap" not working when "trap-generators" does not contain "temp-exception";
      *) snmp - improved reliability on SNMP service packet validation;
      *) winbox - added "System/SwOS" menu for all dual-boot devices;
      *) winbox - do not allow setting "dns-lookup-interval" to "0";

      Другие изменения v6.44.3:

      *) bridge - correctly add interface list as bridge port (introduced in v6.45beta34);
      *) bridge - correctly display bridge FastPath status when vlan-filtering or dhcp-snooping is used;
      *) bridge - fixed log message when hardware offloading is being enabled;
      *) bridge - fixed port running state for non-ethernet interfaces (introduced in v6.45beta33);
      *) capsman - fixed interface-list usage in access list;
      *) ccr - improved packet processing after overloading interface;
      *) certificate - added "key-type" field (CLI only);
      *) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
      *) certificate - made RAM the default CRL storage location;
      *) certificate - removed DSA (D) flag;
      *) cloud - added "replace" parameter for backup "upload-file" command;
      *) conntrack - fixed GRE protocol packet connection-state matching (CVE-2014-8160);
      *) conntrack - significant stability and performance improvements;
      *) crs317 - fixed known multicast flooding to the CPU;
      *) crs3xx - added ethernet tx-drop counter;
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - correctly handle switch reset (introduced in v6.45beta31);
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) crs3xx - improved switch-chip resource allocation on CRS326, CRS328, CRS305;
      *) defconf - added "custom-script" field that prints custom configuration installed by Netinstall;
      *) defconf - automatically set "installation" parameter for outdoor devices;
      *) defconf - changed default configuration type to AP for cAP series devices;
      *) dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
      *) dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
      *) dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
      *) dhcpv4-server - added "client-mac-limit" parameter (CLI only);
      *) dhcpv4-server - added RADIUS accounting support with queue based statistics;
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv4-server - improved stability when performing "check-status" command;
      *) dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
      *) dhcpv6-client - added option to disable rapid-commit (CLI only);
      *) dhcpv6-client - fixed status update when leaving "bound" state;
      *) dhcpv6-server - added "address-list" support for bindings (CLI only);
      *) dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
      *) dhcpv6-server - added RADIUS accounting support with queue based statistics;
      *) dhcpv6-server - added "route-distance" parameter (CLI only);
      *) dhcpv6-server - fixed dynamic IPv6 binding without proper reference to the server;
      *) dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
      *) discovery - correctly create neighbors from VLAN tagged discovery messages;
      *) discovery - fixed CDP packets not including address on slave ports (introduced in v6.44);
      *) discovery - improved neighbour's MAC address detection;
      *) discovery - limit max neighbour count per interface based on total RAM memory;
      *) discovery - show neighbors on actual mesh ports;
      *) e-mail - include "message-id" identification field in e-mail header;
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) ethernet - increased loop warning threshold to 5 packets per second;
      *) export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
      *) fetch - added SFTP support;
      *) fetch - improved user policy lookup;
      *) firewall - fixed fragmented packet processing when only RAW firewall is configured;
      *) firewall - process packets by firewall when accepted by RAW with disabled connection tracking;
      *) gps - fixed missing minus close to zero coordinates in dd format;
      *) gps - make sure "direction" parameter is upper case;
      *) gps - strip unnecessary trailing characters from "longtitude" and "latitude" values;
      *) hotspot - moved "title" HTML tag after "meta" tags;
      *) ike1 - adjusted debug packet logging topics;
      *) ike1 - fixed rekeying process when NAT is detected (introduced in v6.45beta16);
      *) ike1 - general stability improvements (introduced in v6.45beta);
      *) ike2 - added support for ECDSA certificate authentication (rfc4754);
      *) ike2 - added support for IKE SA rekeying for initiator;
      *) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
      *) ike2 - fixed first child SA generation (introduced in v6.45beta34);
      *) ike2 - fixed pre-shared-key authentication failure (introduced in v6.45beta34);
      *) ike2 - improved certificate verification when multiple CA certificates received from responder;
      *) ike2 - improved child SA rekeying process;
      *) ike2 - improved XAuth identity conversion on upgrade;
      *) ike2 - prefer SAN instead of DN from certificate for ID payload;
      *) ippool - improved logging for IPv6 Pool when prefix is already in use;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
      *) ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
      *) ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
      *) ipsec - added traffic statistics to "active-peers" menu (CLI only);
      *) ipsec - do not allow adding identity to a dynamic peer;
      *) ipsec - fixed policies becoming invalid after changing priority;
      *) ipsec - general improvements in policy handling;
      *) ipsec - properly drop already established tunnel when address change detected;
      *) ipsec - renamed "remote-peers" to "active-peers" (CLI only);
      *) ipsec - renamed "rsa-signature" authentication method to "digital-signature";
      *) ipsec - replaced policy SA address parameters with peer setting;
      *) ipsec - use tunnel name for dynamic IPsec peer name;
      *) ipv6 - improved system stability when receiving bogus packets;
      *) lte - added initial support for Vodafone R216-Z;
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - allow setting empty APN;
      *) lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - fixed session reactivation on R11e-LTE in UMTS mode;
      *) lte - improved firmware upgrade process;
      *) lte - improved "info" command query;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use default APN name "internet" when not provided;
      *) lte - use secondary DNS for DNS server configuration;
      *) ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
      *) ospf - fixed opaque LSA type checking in OSPFv2;
      *) ospf - improved "unknown" LSA handling in OSPFv3;
      *) ovpn - added "verify-server-certificate" parameter for OVPN client (CVE-2018-10066);
      *) ppp - added initial support for Quectel BG96;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) rb3011 - improved system stability when receiving bogus packets;
      *) rb4011 - fixed MAC address duplication between sfp-sfpplus1 and wlan1 interfaces (wlan1 configuration reset required);
      *) rb4011 - fixed SFP linking (introduced in v6.45beta6);
      *) rb921 - improved system stability ("/system routerboard upgrade" required);
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) sms - added USSD message functionality under "/tool sms" (CLI only);
      *) sms - allow specifying multiple "allowed-number" values;
      *) sms - fixed long message parsing (introduced in v6.45beta19);
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) snmp - added OID for neighbor "interface";
      *) snmp - added "write-access" column to community print;
      *) snmp - allow setting interface "adminStatus";
      *) snmp - improved reliability on SNMP service packet validation;
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) ssh - accept remote forwarding requests with empty hostnames;
      *) ssh - added new "ssh-exec" command for non-interactive command execution;
      *) ssh - fixed non-interactive multiple command execution;
      *) ssh - improved remote forwarding handling (introduced in v6.44.3);
      *) ssh - improved session rekeying process on exchanged data size threshold;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) supout - added IPv6 ND section to supout file;
      *) supout - added "kid-control devices" section to supout file;
      *) supout - added "pwr-line" section to supout file;
      *) supout - changed IPv6 pool section to output detailed print;
      *) switch - properly reapply settings after switch chip reset;
      *) tftp - added "max-block-size" parameter under TFTP "settings" menu (CLI only);
      *) tile - improved link fault detection on SFP+ ports;
      *) tr069-client - added LTE CQI and IMSI parameter support;
      *) tr069-client - fixed potential memory corruption;
      *) tr069-client - improved error reporting with incorrect firware upgrade XML file;
      *) traceroute - improved stability when sending large ping amounts;
      *) traffic-generator - improved stability when stopping traffic generator;
      *) tunnel - removed "local-address" requirement when "ipsec-secret" is used;
      *) userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
      *) w60g - do not show unused "dmg" parameter;
      *) w60g - prefer AP with strongest signal when multiple APs with same SSID present;
      *) w60g - show running frequency under "monitor" command;
      *) winbox - added "System/SwOS" menu for all dual-boot devices;
      *) winbox - fixed crash when opening CAPsMAN menu (introduced in v6.45beta27);
      *) winbox - show "LCD" menu only on boards that have LCD screen;
      *) wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
      *) wireless - fixed "country-info" printing (introduced in v6.45beta27);
      *) wireless - fixed frequency duplication in the frequency selection menu;
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - improved 160MHz channel width stability on rb4011;
      *) wireless - improved DFS radar detection when using non-ETSI regulated country;
      *) wireless - improved installation mode selection for wireless outdoor equipment;
      *) wireless - set default SSID and supplicant-identity the same as router's identity;
      *) wireless - updated "china" regulatory domain information;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      *) www - improved client-initiated renegotiation within the SSL and TLS protocols (CVE-2011-1473);
      Что нового в версии 6.45beta54 (2019-May-24 07:51):

      Важная заметка!!!
      Downgrading to any version prior to v6.43 (v6.42.12 and older) will clear all user passwords and allow password-less authentication. Please secure your router after downgrading.

      MAJOR CHANGES IN v6.45:
      ----------------------
      !) dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
      !) ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap, eap-mschapv2) as initiator (CLI only);
      !) user - removed insecure password storage;
      ----------------------

      Изменения в этом выпуске:

      !) user - removed insecure password storage;
      *) bridge - correctly display bridge FastPath status when vlan-filtering or dhcp-snooping is used;
      *) conntrack - fixed GRE protocol packet connection-state matching (CVE-2014-8160);
      *) crs317 - fixed known multicast flooding to the CPU;
      *) ike1 - general stability improvements (introduced in v6.45beta);
      *) ike2 - added support for IKE rekeying for initiator;
      *) ike2 - improved child SA rekeying process;
      *) lte - added initial support for Vodafone R216-Z;
      *) ovpn - added "verify-server-certificate" parameter for OVPN client (CVE-2018-10066);
      *) winbox - added "System/SwOS" menu for all dual-boot devices;
      *) www - improved client-initiated renegotiation within the SSL and TLS protocols (CVE-2011-1473);

      Другие изменения v6.44.3:

      *) bridge - correctly add interface list as bridge port (introduced in v6.45beta34);
      *) bridge - fixed log message when hardware offloading is being enabled;
      *) bridge - fixed port running state for non-ethernet interfaces (introduced in v6.45beta33);
      *) capsman - fixed interface-list usage in access list;
      *) ccr - improved packet processing after overloading interface;
      *) certificate - added "key-type" field (CLI only);
      *) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
      *) certificate - made RAM the default CRL storage location;
      *) certificate - removed DSA (D) flag;
      *) cloud - added "replace" parameter for backup "upload-file" command;
      *) conntrack - significant stability and performance improvements;
      *) crs3xx - added ethernet tx-drop counter;
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - correctly handle switch reset (introduced in v6.45beta31);
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) crs3xx - improved switch-chip resource allocation on CRS326, CRS328, CRS305;
      *) defconf - added "custom-script" field that prints custom configuration installed by Netinstall;
      *) defconf - automatically set "installation" parameter for outdoor devices;
      *) defconf - changed default configuration type to AP for cAP series devices;
      *) dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
      *) dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
      *) dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
      *) dhcpv4-server - added "client-mac-limit" parameter (CLI only);
      *) dhcpv4-server - added RADIUS accounting support with queue based statistics;
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv4-server - improved stability when performing "check-status" command;
      *) dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
      *) dhcpv6-client - added option to disable rapid-commit (CLI only);
      *) dhcpv6-client - fixed status update when leaving "bound" state;
      *) dhcpv6-server - added "address-list" support for bindings (CLI only);
      *) dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
      *) dhcpv6-server - added RADIUS accounting support;
      *) dhcpv6-server - added RADIUS accounting support with queue based statistics;
      *) dhcpv6-server - added "route-distance" parameter (CLI only);
      *) dhcpv6-server - fixed dynamic IPv6 binding without proper reference to the server;
      *) dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
      *) discovery - correctly create neighbors from VLAN tagged discovery messages;
      *) discovery - fixed CDP packets not including address on slave ports (introduced in v6.44);
      *) discovery - improved neighbour's MAC address detection;
      *) discovery - limit max neighbour count per interface based on total RAM memory;
      *) discovery - show neighbors on actual mesh ports;
      *) e-mail - include "message-id" identification field in e-mail header;
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) ethernet - increased loop warning threshold to 5 packets per second;
      *) export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
      *) fetch - added SFTP support;
      *) fetch - improved user policy lookup;
      *) firewall - fixed fragmented packet processing when only RAW firewall is configured;
      *) firewall - process packets by firewall when accepted by RAW with disabled connection tracking;
      *) gps - fixed missing minus close to zero coordinates in dd format;
      *) gps - make sure "direction" parameter is upper case;
      *) gps - strip unnecessary trailing characters from "longtitude" and "latitude" values;
      *) hotspot - moved "title" HTML tag after "meta" tags;
      *) ike1 - adjusted debug packet logging topics;
      *) ike1 - fixed rekeying process when NAT is detected (introduced in v6.45beta16);
      *) ike2 - added support for ECDSA certificate authentication (rfc4754);
      *) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
      *) ike2 - fixed first child SA generation (introduced in v6.45beta34);
      *) ike2 - fixed pre-shared-key authentication failure (introduced in v6.45beta34);
      *) ike2 - improved certificate verification when multiple CA certificates received from responder;
      *) ike2 - improved XAuth identity conversion on upgrade;
      *) ike2 - prefer SAN instead of DN from certificate for ID payload;
      *) ippool - improved logging for IPv6 Pool when prefix is already in use;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
      *) ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
      *) ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
      *) ipsec - added traffic statistics to "active-peers" menu (CLI only);
      *) ipsec - do not allow adding identity to a dynamic peer;
      *) ipsec - fixed policies becoming invalid after changing priority;
      *) ipsec - general improvements in policy handling;
      *) ipsec - properly drop already established tunnel when address change detected;
      *) ipsec - renamed "remote-peers" to "active-peers" (CLI only);
      *) ipsec - renamed "rsa-signature" authentication method to "digital-signature";
      *) ipsec - replaced policy SA address parameters with peer setting;
      *) ipsec - use tunnel name for dynamic IPsec peer name;
      *) ipv6 - improved system stability when receiving bogus packets;
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - allow setting empty APN;
      *) lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - fixed session reactivation on R11e-LTE in UMTS mode;
      *) lte - improved firmware upgrade process;
      *) lte - improved "info" command query;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use default APN name "internet" when not provided;
      *) lte - use secondary DNS for DNS server configuration;
      *) ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
      *) ospf - fixed opaque LSA type checking in OSPFv2;
      *) ospf - improved "unknown" LSA handling in OSPFv3;
      *) ppp - added initial support for Quectel BG96;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) rb3011 - improved system stability when receiving bogus packets;
      *) rb4011 - fixed MAC address duplication between sfp-sfpplus1 and wlan1 interfaces (wlan1 configuration reset required);
      *) rb4011 - fixed SFP linking (introduced in v6.45beta6);
      *) rb921 - improved system stability ("/system routerboard upgrade" required);
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) sms - added USSD message functionality under "/tool sms" (CLI only);
      *) sms - allow specifying multiple "allowed-number" values;
      *) sms - fixed long message parsing (introduced in v6.45beta19);
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) snmp - added OID for neighbor "interface";
      *) snmp - added "write-access" column to community print;
      *) snmp - allow setting interface "adminStatus";
      *) snmp - improved reliability on SNMP service packet validation;
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) ssh - accept remote forwarding requests with empty hostnames;
      *) ssh - added new "ssh-exec" command for non-interactive command execution;
      *) ssh - fixed non-interactive multiple command execution;
      *) ssh - improved remote forwarding handling (introduced in v6.44.3);
      *) ssh - improved session rekeying process on exchanged data size threshold;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) supout - added IPv6 ND section to supout file;
      *) supout - added "kid-control devices" section to supout file;
      *) supout - added "pwr-line" section to supout file;
      *) supout - changed IPv6 pool section to output detailed print;
      *) switch - properly reapply settings after switch chip reset;
      *) tftp - added "max-block-size" parameter under TFTP "settings" menu (CLI only);
      *) tile - improved link fault detection on SFP+ ports;
      *) tr069-client - added LTE CQI and IMSI parameter support;
      *) tr069-client - fixed potential memory corruption;
      *) tr069-client - improved error reporting with incorrect firware upgrade XML file;
      *) traceroute - improved stability when sending large ping amounts;
      *) traffic-generator - improved stability when stopping traffic generator;
      *) tunnel - removed "local-address" requirement when "ipsec-secret" is used;
      *) userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
      *) w60g - do not show unused "dmg" parameter;
      *) w60g - prefer AP with strongest signal when multiple APs with same SSID present;
      *) w60g - show running frequency under "monitor" command;
      *) winbox - fixed crash when opening CAPsMAN menu (introduced in v6.45beta27);
      *) winbox - show "LCD" menu only on boards that have LCD screen;
      *) wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
      *) wireless - fixed "country-info" printing (introduced in v6.45beta27);
      *) wireless - fixed frequency duplication in the frequency selection menu;
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - improved 160MHz channel width stability on rb4011;
      *) wireless - improved DFS radar detection when using non-ETSI regulated country;
      *) wireless - improved installation mode selection for wireless outdoor equipment;
      *) wireless - set default SSID and supplicant-identity the same as router's identity;
      *) wireless - updated "china" regulatory domain information;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      Что нового в версии 6.45beta50 (2019-May-20 09:30):

      MAJOR CHANGES IN v6.45:
      ----------------------
      !) dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
      !) ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap, eap-mschapv2) as initiator (CLI only);
      ----------------------

      Изменения в этом выпуске:

      !) dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
      *) bridge - fixed port running state for non-ethernet interfaces (introduced in v6.45beta33);
      *) ccr - improved packet processing after overloading interface;
      *) crs3xx - added ethernet tx-drop counter;
      *) crs3xx - improved switch-chip resource allocation on CRS326, CRS328, CRS305;
      *) defconf - changed default configuration type to AP for cAP series devices;
      *) dhcpv6-client - added option to disable rapid-commit (CLI only);
      *) dhcpv6-server - added RADIUS accounting support with queue based statistics;
      *) discovery - fixed CDP packets not including address on slave ports (introduced in v6.44);
      *) firewall - process packets by firewall when accepted by RAW with disabled connection tracking;
      *) ike2 - fixed pre-shared-key authentication failure (introduced in v6.45beta34);
      *) ike2 - improved certificate verification when multiple CA certificates received from responder;
      *) ippool - improved logging for IPv6 Pool when prefix is already in use;
      *) ipv6 - improved system stability when receiving bogus packets;
      *) lte - improved firmware upgrade process;
      *) ospf - fixed opaque LSA type checking in OSPFv2;
      *) rb3011 - improved system stability when receiving bogus packets;
      *) rb4011 - fixed MAC address duplication between sfp-sfpplus1 and wlan1 interfaces (wlan1 configuration reset required);
      *) snmp - improved reliability on SNMP service packet validation;
      *) ssh - fixed non-interactive multiple command execution;
      *) supout - added "pwr-line" section to supout file;
      *) traceroute - improved stability when sending large ping amounts;
      *) traffic-generator - improved stability when stopping traffic generator;

      Другие изменения v6.44.3:

      *) bridge - correctly add interface list as bridge port (introduced in v6.45beta34);
      *) bridge - fixed log message when hardware offloading is being enabled;
      *) capsman - fixed interface-list usage in access list;
      *) certificate - added "key-type" field (CLI only);
      *) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
      *) certificate - made RAM the default CRL storage location;
      *) certificate - removed DSA (D) flag;
      *) cloud - added "replace" parameter for backup "upload-file" command;
      *) conntrack - significant stability and performance improvements;
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - correctly handle switch reset (introduced in v6.45beta31);
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) defconf - added "custom-script" field that prints custom configuration installed by Netinstall;
      *) defconf - automatically set "installation" parameter for outdoor devices;
      *) dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
      *) dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
      *) dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
      *) dhcpv4-server - added "client-mac-limit" parameter (CLI only);
      *) dhcpv4-server - added RADIUS accounting support with queue based statistics;
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv4-server - improved stability when performing "check-status" command;
      *) dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
      *) dhcpv6-client - fixed status update when leaving "bound" state;
      *) dhcpv6-server - added "address-list" support for bindings (CLI only);
      *) dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
      *) dhcpv6-server - added RADIUS accounting support;
      *) dhcpv6-server - added "route-distance" parameter (CLI only);
      *) dhcpv6-server - fixed dynamic IPv6 binding without proper reference to the server;
      *) dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
      *) discovery - correctly create neighbors from VLAN tagged discovery messages;
      *) discovery - improved neighbour's MAC address detection;
      *) discovery - limit max neighbour count per interface based on total RAM memory;
      *) discovery - show neighbors on actual mesh ports;
      *) e-mail - include "message-id" identification field in e-mail header;
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) ethernet - increased loop warning threshold to 5 packets per second;
      *) export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
      *) fetch - added SFTP support;
      *) fetch - improved user policy lookup;
      *) firewall - fixed fragmented packet processing when only RAW firewall is configured;
      *) gps - fixed missing minus close to zero coordinates in dd format;
      *) gps - make sure "direction" parameter is upper case;
      *) gps - strip unnecessary trailing characters from "longtitude" and "latitude" values;
      *) hotspot - moved "title" HTML tag after "meta" tags;
      *) ike1 - adjusted debug packet logging topics;
      *) ike1 - fixed rekeying process when NAT is detected (introduced in v6.45beta16);
      *) ike2 - added support for ECDSA certificate authentication (rfc4754);
      *) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
      *) ike2 - fixed first child SA generation (introduced in v6.45beta34);
      *) ike2 - improved XAuth identity conversion on upgrade;
      *) ike2 - prefer SAN instead of DN from certificate for ID payload;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
      *) ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
      *) ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
      *) ipsec - added traffic statistics to "active-peers" menu (CLI only);
      *) ipsec - do not allow adding identity to a dynamic peer;
      *) ipsec - fixed policies becoming invalid after changing priority;
      *) ipsec - general improvements in policy handling;
      *) ipsec - properly drop already established tunnel when address change detected;
      *) ipsec - renamed "remote-peers" to "active-peers" (CLI only);
      *) ipsec - renamed "rsa-signature" authentication method to "digital-signature";
      *) ipsec - replaced policy SA address parameters with peer setting;
      *) ipsec - use tunnel name for dynamic IPsec peer name;
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - allow setting empty APN;
      *) lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - fixed session reactivation on R11e-LTE in UMTS mode;
      *) lte - improved "info" command query;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use default APN name "internet" when not provided;
      *) lte - use secondary DNS for DNS server configuration;
      *) ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
      *) ospf - improved "unknown" LSA handling in OSPFv3;
      *) ppp - added initial support for Quectel BG96;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) rb4011 - fixed SFP linking (introduced in v6.45beta6);
      *) rb921 - improved system stability ("/system routerboard upgrade" required);
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) sms - added USSD message functionality under "/tool sms" (CLI only);
      *) sms - allow specifying multiple "allowed-number" values;
      *) sms - fixed long message parsing (introduced in v6.45beta19);
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) snmp - added OID for neighbor "interface";
      *) snmp - added "write-access" column to community print;
      *) snmp - allow setting interface "adminStatus";
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) ssh - accept remote forwarding requests with empty hostnames;
      *) ssh - added new "ssh-exec" command for non-interactive command execution;
      *) ssh - improved remote forwarding handling (introduced in v6.44.3);
      *) ssh - improved session rekeying process on exchanged data size threshold;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) supout - added IPv6 ND section to supout file;
      *) supout - added "kid-control devices" section to supout file;
      *) supout - changed IPv6 pool section to output detailed print;
      *) switch - properly reapply settings after switch chip reset;
      *) tftp - added "max-block-size" parameter under TFTP "settings" menu (CLI only);
      *) tile - improved link fault detection on SFP+ ports;
      *) tr069-client - added LTE CQI and IMSI parameter support;
      *) tr069-client - fixed potential memory corruption;
      *) tr069-client - improved error reporting with incorrect firware upgrade XML file;
      *) tunnel - removed "local-address" requirement when "ipsec-secret" is used;
      *) userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
      *) w60g - do not show unused "dmg" parameter;
      *) w60g - prefer AP with strongest signal when multiple APs with same SSID present;
      *) w60g - show running frequency under "monitor" command;
      *) winbox - fixed crash when opening CAPsMAN menu (introduced in v6.45beta27);
      *) winbox - show "LCD" menu only on boards that have LCD screen;
      *) wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
      *) wireless - fixed "country-info" printing (introduced in v6.45beta27);
      *) wireless - fixed frequency duplication in the frequency selection menu;
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - improved 160MHz channel width stability on rb4011;
      *) wireless - improved DFS radar detection when using non-ETSI regulated country;
      *) wireless - improved installation mode selection for wireless outdoor equipment;
      *) wireless - set default SSID and supplicant-identity the same as router's identity;
      *) wireless - updated "china" regulatory domain information;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      Что нового в версии 6.45beta45 (2019-May-13 09:22):

      MAJOR CHANGES IN v6.45:
      ----------------------
      !) dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
      !) ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap, eap-mschapv2) as initiator (CLI only);
      ----------------------

      Изменения в этом выпуске:

      !) ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap, eap-mschapv2) as initiator (CLI only);
      *) conntrack - significant stability and performance improvements;
      *) dhcpv6-server - fixed dynamic IPv6 binding without proper reference to the server;
      *) firewall - fixed fragmented packet processing when only RAW firewall is configured;
      *) gps - fixed missing minus close to zero coordinates in dd format;
      *) wireless - improved installation mode selection for wireless outdoor equipment;

      Другие изменения v6.44.3:

      *) bridge - correctly add interface list as bridge port (introduced in v6.45beta34);
      *) bridge - fixed log message when hardware offloading is being enabled;
      *) capsman - fixed interface-list usage in access list;
      *) certificate - added "key-type" field (CLI only);
      *) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
      *) certificate - made RAM the default CRL storage location;
      *) certificate - removed DSA (D) flag;
      *) cloud - added "replace" parameter for backup "upload-file" command;
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - correctly handle switch reset (introduced in v6.45beta31);
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) defconf - added "custom-script" field that prints custom configuration installed by Netinstall;
      *) defconf - automatically set "installation" parameter for outdoor devices;
      *) dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
      *) dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
      *) dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
      *) dhcpv4-server - added "client-mac-limit" parameter (CLI only);
      *) dhcpv4-server - added RADIUS accounting support with queue based statistics;
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv4-server - improved stability when performing "check-status" command;
      *) dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
      *) dhcpv6-client - fixed status update when leaving "bound" state;
      *) dhcpv6-server - added "address-list" support for bindings (CLI only);
      *) dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
      *) dhcpv6-server - added RADIUS accounting support;
      *) dhcpv6-server - added "route-distance" parameter (CLI only);
      *) dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
      *) discovery - correctly create neighbors from VLAN tagged discovery messages;
      *) discovery - improved neighbour's MAC address detection;
      *) discovery - limit max neighbour count per interface based on total RAM memory;
      *) discovery - show neighbors on actual mesh ports;
      *) e-mail - include "message-id" identification field in e-mail header;
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) ethernet - increased loop warning threshold to 5 packets per second;
      *) export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
      *) fetch - added SFTP support;
      *) fetch - improved user policy lookup;
      *) gps - make sure "direction" parameter is upper case;
      *) gps - strip unnecessary trailing characters from "longtitude" and "latitude" values;
      *) hotspot - moved "title" HTML tag after "meta" tags;
      *) ike1 - adjusted debug packet logging topics;
      *) ike1 - fixed rekeying process when NAT is detected (introduced in v6.45beta16);
      *) ike2 - added support for ECDSA certificate authentication (rfc4754);
      *) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
      *) ike2 - fixed first child SA generation (introduced in v6.45beta34);
      *) ike2 - improved XAuth identity conversion on upgrade;
      *) ike2 - prefer SAN instead of DN from certificate for ID payload;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
      *) ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
      *) ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
      *) ipsec - added traffic statistics to "active-peers" menu (CLI only);
      *) ipsec - do not allow adding identity to a dynamic peer;
      *) ipsec - fixed policies becoming invalid after changing priority;
      *) ipsec - general improvements in policy handling;
      *) ipsec - properly drop already established tunnel when address change detected;
      *) ipsec - renamed "remote-peers" to "active-peers" (CLI only);
      *) ipsec - renamed "rsa-signature" authentication method to "digital-signature";
      *) ipsec - replaced policy SA address parameters with peer setting;
      *) ipsec - use tunnel name for dynamic IPsec peer name;
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - allow setting empty APN;
      *) lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - fixed session reactivation on R11e-LTE in UMTS mode;
      *) lte - improved "info" command query;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use default APN name "internet" when not provided;
      *) lte - use secondary DNS for DNS server configuration;
      *) ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
      *) ospf - improved "unknown" LSA handling in OSPFv3;
      *) ppp - added initial support for Quectel BG96;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) rb4011 - fixed SFP linking (introduced in v6.45beta6);
      *) rb921 - improved system stability ("/system routerboard upgrade" required);
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) sms - added USSD message functionality under "/tool sms" (CLI only);
      *) sms - allow specifying multiple "allowed-number" values;
      *) sms - fixed long message parsing (introduced in v6.45beta19);
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) snmp - added OID for neighbor "interface";
      *) snmp - added "write-access" column to community print;
      *) snmp - allow setting interface "adminStatus";
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) ssh - accept remote forwarding requests with empty hostnames;
      *) ssh - added new "ssh-exec" command for non-interactive command execution;
      *) ssh - improved remote forwarding handling (introduced in v6.44.3);
      *) ssh - improved session rekeying process on exchanged data size threshold;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) supout - added IPv6 ND section to supout file;
      *) supout - added "kid-control devices" section to supout file;
      *) supout - changed IPv6 pool section to output detailed print;
      *) switch - properly reapply settings after switch chip reset;
      *) tftp - added "max-block-size" parameter under TFTP "settings" menu (CLI only);
      *) tile - improved link fault detection on SFP+ ports;
      *) tr069-client - added LTE CQI and IMSI parameter support;
      *) tr069-client - fixed potential memory corruption;
      *) tr069-client - improved error reporting with incorrect firware upgrade XML file;
      *) tunnel - removed "local-address" requirement when "ipsec-secret" is used;
      *) userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
      *) w60g - do not show unused "dmg" parameter;
      *) w60g - prefer AP with strongest signal when multiple APs with same SSID present;
      *) w60g - show running frequency under "monitor" command;
      *) winbox - fixed crash when opening CAPsMAN menu (introduced in v6.45beta27);
      *) winbox - show "LCD" menu only on boards that have LCD screen;
      *) wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
      *) wireless - fixed "country-info" printing (introduced in v6.45beta27);
      *) wireless - fixed frequency duplication in the frequency selection menu;
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - improved 160MHz channel width stability on rb4011;
      *) wireless - improved DFS radar detection when using non-ETSI regulated country;
      *) wireless - improved installation mode selection for wireless outdoor equipment;
      *) wireless - set default SSID and supplicant-identity the same as router's identity;
      *) wireless - updated "china" regulatory domain information;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      Что нового в версии 6.45beta42 (2019-May-08 12:44):

      MAJOR CHANGES IN v6.45:
      ----------------------
      !) dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
      !) ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap) as initiator (CLI only);
      ----------------------

      Изменения в этом выпуске:

      !) dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
      *) capsman - fixed interface-list usage in access list;
      *) cloud - added "replace" parameter for backup "upload-file" command;
      *) crs3xx - correctly handle switch reset (introduced in v6.45beta31);
      *) defconf - added "custom-script" field that prints custom configuration installed by Netinstall;
      *) defconf - automatically set "installation" parameter for outdoor devices;
      *) dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
      *) dhcpv4-server - added RADIUS accounting support with queue based statistics;
      *) dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
      *) discovery - correctly create neighbors from VLAN tagged discovery messages;
      *) discovery - show neighbors on actual mesh ports;
      *) ethernet - increased loop warning threshold to 5 packets per second;
      *) gps - make sure "direction" parameter is upper case;
      *) gps - strip unnecessary trailing characters from "longtitude" and "latitude" values;
      *) hotspot - moved "title" HTML tag after "meta" tags;
      *) ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
      *) rb921 - improved system stability ("/system routerboard upgrade" required);
      *) ssh - accept remote forwarding requests with empty hostnames;
      *) ssh - improved remote forwarding handling (introduced in v6.44.3);
      *) tr069-client - improved error reporting with incorrect firware upgrade XML file;
      *) w60g - do not show unused "dmg" parameter;
      *) w60g - show running frequency under "monitor" command;
      *) winbox - show "LCD" menu only on boards that have LCD screen;
      *) wireless - fixed frequency duplication in the frequency selection menu;
      *) wireless - improved 160MHz channel width stability on rb4011;
      *) wireless - improved installation mode selection for wireless outdoor equipment;
      *) wireless - set default SSID and supplicant-identity the same as router's identity;
      *) wireless - updated "china" regulatory domain information;

      Другие изменения v6.44.3:

      *) bridge - correctly add interface list as bridge port (introduced in v6.45beta34);
      *) bridge - fixed log message when hardware offloading is being enabled;
      *) certificate - added "key-type" field (CLI only);
      *) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
      *) certificate - made RAM the default CRL storage location;
      *) certificate - removed DSA (D) flag;
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - correctly handle switch reset (introduced in v6.45beta34);
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
      *) dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
      *) dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
      *) dhcpv4-server - added "client-mac-limit" parameter (CLI only);
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv4-server - improved stability when performing "check-status" command;
      *) dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
      *) dhcpv6-client - fixed status update when leaving "bound" state;
      *) dhcpv6-server - added "address-list" support for bindings (CLI only);
      *) dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
      *) dhcpv6-server - added RADIUS accounting support;
      *) dhcpv6-server - added "route-distance" parameter (CLI only);
      *) dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
      *) discovery - improved neighbour's MAC address detection;
      *) discovery - limit max neighbour count per interface based on total RAM memory;
      *) e-mail - include "message-id" identification field in e-mail header;
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
      *) fetch - added SFTP support;
      *) fetch - improved user policy lookup;
      *) ike1 - adjusted debug packet logging topics;
      *) ike1 - fixed rekeying process when NAT is detected (introduced in v6.45beta16);
      *) ike2 - added support for ECDSA certificate authentication (rfc4754);
      *) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
      *) ike2 - fixed first child SA generation (introduced in v6.45beta34);
      *) ike2 - improved XAuth identity conversion on upgrade;
      *) ike2 - prefer SAN instead of DN from certificate for ID payload;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
      *) ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
      *) ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
      *) ipsec - added traffic statistics to "active-peers" menu (CLI only);
      *) ipsec - do not allow adding identity to a dynamic peer;
      *) ipsec - fixed policies becoming invalid after changing priority;
      *) ipsec - general improvements in policy handling;
      *) ipsec - properly drop already established tunnel when address change detected;
      *) ipsec - renamed "remote-peers" to "active-peers" (CLI only);
      *) ipsec - renamed "rsa-signature" authentication method to "digital-signature";
      *) ipsec - replaced policy SA address parameters with peer setting;
      *) ipsec - use tunnel name for dynamic IPsec peer name;
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - allow setting empty APN;
      *) lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - fixed session reactivation on R11e-LTE in UMTS mode;
      *) lte - improved "info" command query;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use default APN name "internet" when not provided;
      *) lte - use secondary DNS for DNS server configuration;
      *) ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
      *) ospf - improved "unknown" LSA handling in OSPFv3;
      *) ppp - added initial support for Quectel BG96;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) rb4011 - fixed SFP linking (introduced in v6.45beta6);
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) sms - added USSD message functionality under "/tool sms" (CLI only);
      *) sms - allow specifying multiple "allowed-number" values;
      *) sms - fixed long message parsing (introduced in v6.45beta19);
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) snmp - added OID for neighbor "interface";
      *) snmp - added "write-access" column to community print;
      *) snmp - allow setting interface "adminStatus";
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) ssh - added new "ssh-exec" command for non-interactive command execution;
      *) ssh - improved session rekeying process on exchanged data size threshold;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) supout - added IPv6 ND section to supout file;
      *) supout - added "kid-control devices" section to supout file;
      *) supout - changed IPv6 pool section to output detailed print;
      *) switch - properly reapply settings after switch chip reset;
      *) tftp - added "max-block-size" parameter under TFTP "settings" menu (CLI only);
      *) tile - improved link fault detection on SFP+ ports;
      *) tr069-client - added LTE CQI and IMSI parameter support;
      *) tr069-client - fixed potential memory corruption;
      *) tunnel - removed "local-address" requirement when "ipsec-secret" is used;
      *) userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
      *) w60g - prefer AP with strongest signal when multiple APs with same SSID present;
      *) winbox - fixed crash when opening CAPsMAN menu (introduced in v6.45beta27);
      *) wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
      *) wireless - fixed "country-info" printing (introduced in v6.45beta27);
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - improved DFS radar detection when using non-ETSI regulated country;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      Что нового в версии 6.45beta37 (2019-Apr-25 12:20):

      MAJOR CHANGES IN v6.45:
      ----------------------
      !) dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
      !) ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap) as initiator (CLI only);
      ----------------------

      Изменения в этом выпуске:

      !) dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
      !) ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap) as initiator (CLI only);
      *) bridge - correctly add interface list as bridge port (introduced in v6.45beta34);
      *) crs3xx - correctly handle switch reset (introduced in v6.45beta34);
      *) ike2 - fixed first child SA generation (introduced in v6.45beta34);
      *) ipsec - general improvements in policy handling;
      *) lte - allow setting empty APN;
      *) supout - added IPv6 ND section to supout file;
      *) tftp - added "max-block-size" parameter under TFTP "settings" menu (CLI only);

      Другие изменения v6.44.3:

      *) bridge - fixed log message when hardware offloading is being enabled;
      *) certificate - added "key-type" field (CLI only);
      *) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
      *) certificate - made RAM the default CRL storage location;
      *) certificate - removed DSA (D) flag;
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
      *) dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
      *) dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
      *) dhcpv4-server - added "client-mac-limit" parameter (CLI only);
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv4-server - improved stability when performing "check-status" command;
      *) dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
      *) dhcpv6-client - fixed status update when leaving "bound" state;
      *) dhcpv6-server - added "address-list" support for bindings (CLI only);
      *) dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
      *) dhcpv6-server - added RADIUS accounting support;
      *) dhcpv6-server - added "route-distance" parameter (CLI only);
      *) dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
      *) discovery - improved neighbour's MAC address detection;
      *) discovery - limit max neighbour count per interface based on total RAM memory;
      *) e-mail - include "message-id" identification field in e-mail header;
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
      *) fetch - added SFTP support;
      *) fetch - improved user policy lookup;
      *) ike1 - adjusted debug packet logging topics;
      *) ike1 - fixed rekeying process when NAT is detected (introduced in v6.45beta16);
      *) ike2 - added support for ECDSA certificate authentication (rfc4754);
      *) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
      *) ike2 - improved XAuth identity conversion on upgrade;
      *) ike2 - prefer SAN instead of DN from certificate for ID payload;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
      *) ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
      *) ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
      *) ipsec - added traffic statistics to "active-peers" menu (CLI only);
      *) ipsec - do not allow adding identity to a dynamic peer;
      *) ipsec - fixed policies becoming invalid after changing priority;
      *) ipsec - general improvements in policy handling;
      *) ipsec - properly drop already established tunnel when address change detected;
      *) ipsec - renamed "remote-peers" to "active-peers" (CLI only);
      *) ipsec - renamed "rsa-signature" authentication method to "digital-signature";
      *) ipsec - replaced policy SA address parameters with peer setting;
      *) ipsec - use tunnel name for dynamic IPsec peer name;
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - fixed session reactivation on R11e-LTE in UMTS mode;
      *) lte - improved "info" command query;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use default APN name "internet" when not provided;
      *) lte - use secondary DNS for DNS server configuration;
      *) ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
      *) ospf - improved "unknown" LSA handling in OSPFv3;
      *) ppp - added initial support for Quectel BG96;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) rb4011 - fixed SFP linking (introduced in v6.45beta6);
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) sms - added USSD message functionality under "/tool sms" (CLI only);
      *) sms - allow specifying multiple "allowed-number" values;
      *) sms - fixed long message parsing (introduced in v6.45beta19);
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) snmp - added OID for neighbor "interface";
      *) snmp - added "write-access" column to community print;
      *) snmp - allow setting interface "adminStatus";
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) ssh - added new "ssh-exec" command for non-interactive command execution;
      *) ssh - improved session rekeying process on exchanged data size threshold;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) supout - added "kid-control devices" section to supout file;
      *) supout - changed IPv6 pool section to output detailed print;
      *) switch - properly reapply settings after switch chip reset;
      *) tile - improved link fault detection on SFP+ ports;
      *) tr069-client - added LTE CQI and IMSI parameter support;
      *) tr069-client - fixed potential memory corruption;
      *) tunnel - removed "local-address" requirement when "ipsec-secret" is used;
      *) userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
      *) w60g - prefer AP with strongest signal when multiple APs with same SSID present;
      *) winbox - fixed crash when opening CAPsMAN menu (introduced in v6.45beta27);
      *) wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
      *) wireless - fixed "country-info" printing (introduced in v6.45beta27);
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - improved DFS radar detection when using non-ETSI regulated country;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      Что нового в версии 6.45beta34 (2019-Apr-18 08:59):

      MAJOR CHANGES IN v6.45:
      ----------------------
      !) dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
      ----------------------

      Изменения в этом выпуске:

      !) dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
      *) dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
      *) dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
      *) dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
      *) dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
      *) dhcpv6-client - fixed status update when leaving "bound" state;
      *) dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
      *) e-mail - include "message-id" identification field in e-mail header;
      *) ike1 - fixed rekeying process when NAT is detected (introduced in v6.45beta16);
      *) ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
      *) ospf - improved "unknown" LSA handling in OSPFv3;
      *) supout - changed IPv6 pool section to output detailed print;
      *) tr069-client - added LTE CQI and IMSI parameter support;
      *) tr069-client - fixed potential memory corruption;
      *) winbox - fixed crash when opening CAPsMAN menu (introduced in v6.45beta27);
      *) wireless - fixed "country-info" printing (introduced in v6.45beta27);

      Другие изменения v6.44.2:

      *) bridge - fixed log message when hardware offloading is being enabled;
      *) certificate - added "key-type" field (CLI only);
      *) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
      *) certificate - fixed SAN being duplicated on status change (introduced in v6.44);
      *) certificate - made RAM the default CRL storage location;
      *) certificate - removed DSA (D) flag;
      *) conntrack - fixed "loose-tcp-tracking" parameter not taken in action (introduced in v6.44);
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
      *) dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
      *) dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
      *) dhcpv4-server - added "client-mac-limit" parameter (CLI only);
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv4-server - fixed commenting option for alerts;
      *) dhcpv4-server - improved stability when performing "check-status" command;
      *) dhcpv6-server - added "address-list" support for bindings (CLI only);
      *) dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
      *) dhcpv6-server - added RADIUS accounting support;
      *) dhcpv6-server - added "route-distance" parameter (CLI only);
      *) dhcpv6-server - fixed binding setting update from RADIUS;
      *) discovery - improved neighbour's MAC address detection;
      *) discovery - limit max neighbour count per interface based on total RAM memory;
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
      *) fetch - added SFTP support;
      *) fetch - improved user policy lookup;
      *) ike1 - adjusted debug packet logging topics;
      *) ike1 - improved stability for transport mode policies on initiator side;
      *) ike2 - added support for ECDSA certificate authentication (rfc4754);
      *) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
      *) ike2 - improved XAuth identity conversion on upgrade;
      *) ike2 - prefer SAN instead of DN from certificate for ID payload;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
      *) ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
      *) ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
      *) ipsec - added traffic statistics to "active-peers" menu (CLI only);
      *) ipsec - do not allow adding identity to a dynamic peer;
      *) ipsec - fixed freshly created identity not taken in action;
      *) ipsec - fixed policies becoming invalid after changing priority;
      *) ipsec - fixed possible configuration corruption after import;
      *) ipsec - general improvements in policy handling;
      *) ipsec - properly drop already established tunnel when address change detected;
      *) ipsec - renamed "remote-peers" to "active-peers" (CLI only);
      *) ipsec - renamed "rsa-signature" authentication method to "digital-signature";
      *) ipsec - replaced policy SA address parameters with peer setting;
      *) ipsec - use tunnel name for dynamic IPsec peer name;
      *) ipv6 - adjusted IPv6 route cache max size;
      *) ipv6 - improved IPv6 neighbor table updating process;
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - fixed session reactivation on R11e-LTE in UMTS mode;
      *) lte - improved "info" command query;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use default APN name "internet" when not provided;
      *) lte - use secondary DNS for DNS server configuration;
      *) ppp - added initial support for Quectel BG96;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) rb2011 - removed "sfp-led" from "System/LEDs" menu;
      *) rb4011 - fixed SFP linking (introduced in v6.45beta6);
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) smb - fixed possible buffer overflow;
      *) sms - added USSD message functionality under "/tool sms" (CLI only);
      *) sms - allow specifying multiple "allowed-number" values;
      *) sms - fixed long message parsing (introduced in v6.45beta19);
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) snmp - added OID for neighbor "interface";
      *) snmp - added "radio-name" (mtxrWlRtabRadioName) OID support;
      *) snmp - added "write-access" column to community print;
      *) snmp - allow setting interface "adminStatus";
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) ssh - added "both", "local" and "remote" options for "forwarding-enabled" parameter;
      *) ssh - added new "ssh-exec" command for non-interactive command execution;
      *) ssh - do not generate host key on configuration export;
      *) ssh - fixed multiline non-interactive command execution;
      *) ssh - improved session rekeying process on exchanged data size threshold;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) supout - added "kid-control devices" section to supout file;
      *) switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
      *) switch - properly reapply settings after switch chip reset;
      *) tile - improved link fault detection on SFP+ ports;
      *) tunnel - removed "local-address" requirement when "ipsec-secret" is used;
      *) userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
      *) userman - updated authorize.net gateway DNS name;
      *) w60g - prefer AP with strongest signal when multiple APs with same SSID present;
      *) wireless - added support for US FCC UNII-2 and Canada country profiles for LHG-5HPnD-US, RBLHG-5HPnD-XL-US and SXTsq5HPnD-US devices;
      *) wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - improved DFS radar detection when using non-ETSI regulated country;
      *) wireless - improved wireless country settings for EU countries;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      Что нового в версии 6.45beta31 (2019-Apr-12 10:29):

      MAJOR CHANGES IN v6.45:
      ----------------------
      !) dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
      ----------------------

      Изменения в этом выпуске:

      !) dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
      *) conntrack - fixed "loose-tcp-tracking" parameter not taken in action (introduced in v6.44);
      *) dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
      *) dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
      *) dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
      *) dhcpv4-server - added "client-mac-limit" parameter (CLI only);
      *) dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
      *) dhcpv6-server - added "route-distance" parameter (CLI only);
      *) dhcpv6-server - fixed binding setting update from RADIUS;
      *) fetch - added SFTP support;
      *) ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
      *) ipsec - added traffic statistics to "active-peers" menu (CLI only);
      *) ipsec - general improvements in policy handling;
      *) ipsec - replaced policy SA address parameters with peer setting;
      *) ipsec - use tunnel name for dynamic IPsec peer name;
      *) ipv6 - adjusted IPv6 route cache max size;
      *) lte - fixed session reactivation on R11e-LTE in UMTS mode;
      *) snmp - added "radio-name" (mtxrWlRtabRadioName) OID support;
      *) ssh - added "both", "local" and "remote" options for "forwarding-enabled" parameter;
      *) tunnel - removed "local-address" requirement when "ipsec-secret" is used;
      *) userman - added support for "Delegated-IPv6-Pool";
      *) userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
      *) wireless - improved wireless country settings for EU countries;

      Другие изменения v6.44.2:

      *) bridge - fixed log message when hardware offloading is being enabled;
      *) certificate - added "key-type" field (CLI only);
      *) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
      *) certificate - fixed SAN being duplicated on status change (introduced in v6.44);
      *) certificate - made RAM the default CRL storage location;
      *) certificate - removed DSA (D) flag;
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv4-server - fixed commenting option for alerts;
      *) dhcpv4-server - improved stability when performing "check-status" command;
      *) dhcpv6-server - added "address-list" support for bindings (CLI only);
      *) dhcpv6-server - added RADIUS accounting support;
      *) discovery - improved neighbour's MAC address detection;
      *) discovery - limit max neighbour count per interface based on total RAM memory;
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
      *) fetch - added SFTP support;
      *) fetch - improved user policy lookup;
      *) ike1 - adjusted debug packet logging topics;
      *) ike1 - improved stability for transport mode policies on initiator side;
      *) ike2 - added support for ECDSA certificate authentication (rfc4754);
      *) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
      *) ike2 - improved XAuth identity conversion on upgrade;
      *) ike2 - prefer SAN instead of DN from certificate for ID payload;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
      *) ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
      *) ipsec - added support for RADIUS accounting;
      *) ipsec - added traffic statistics to "active-peers" menu (CLI only);
      *) ipsec - do not allow adding identity to a dynamic peer;
      *) ipsec - fixed freshly created identity not taken in action;
      *) ipsec - fixed policies becoming invalid after changing priority;
      *) ipsec - fixed possible configuration corruption after import;
      *) ipsec - properly drop already established tunnel when address change detected;
      *) ipsec - renamed "remote-peers" to "active-peers" (CLI only);
      *) ipsec - renamed "rsa-signature" authentication method to "digital-signature";
      *) ipv6 - improved IPv6 neighbor table updating process;
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - improved "info" command query;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use default APN name "internet" when not provided;
      *) lte - use secondary DNS for DNS server configuration;
      *) ppp - added initial support for Quectel BG96;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) rb2011 - removed "sfp-led" from "System/LEDs" menu;
      *) rb4011 - fixed SFP linking (introduced in v6.45beta6);
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) smb - fixed possible buffer overflow;
      *) sms - added USSD message functionality under "/tool sms" (CLI only);
      *) sms - allow specifying multiple "allowed-number" values;
      *) sms - fixed long message parsing (introduced in v6.45beta19);
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) snmp - added OID for neighbor "interface";
      *) snmp - added "write-access" column to community print;
      *) snmp - allow setting interface "adminStatus";
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) ssh - added new "ssh-exec" command for non-interactive command execution;
      *) ssh - do not generate host key on configuration export;
      *) ssh - fixed multiline non-interactive command execution;
      *) ssh - improved session rekeying process on exchanged data size threshold;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) supout - added "kid-control devices" section to supout file;
      *) switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
      *) switch - properly reapply settings after switch chip reset;
      *) tile - improved link fault detection on SFP+ ports;
      *) userman - updated authorize.net gateway DNS name;
      *) w60g - prefer AP with strongest signal when multiple APs with same SSID present;
      *) wireless - added support for US FCC UNII-2 and Canada country profiles for LHG-5HPnD-US, RBLHG-5HPnD-XL-US and SXTsq5HPnD-US devices;
      *) wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - improved DFS radar detection when using non-ETSI regulated country;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      Что нового в версии 6.45beta27 (2019-Apr-03 13:53):

      Изменения в этом выпуске:

      *) dhcpv4-server - fixed commenting option for alerts;
      *) dhcpv6-server - added "address-list" support for bindings (CLI only);
      *) discovery - limit max neighbour count per interface based on total RAM memory;
      *) discovery - improved neighbour's MAC address detection;
      *) fetch - added SFTP support;
      *) ipsec - fixed possible configuration corruption after import;
      *) ipv6 - improved IPv6 neighbor table updating process;
      *) rb2011 - removed "sfp-led" from "System/LEDs" menu;
      *) ssh - added new "ssh-exec" command for non-interactive command execution;
      *) ssh - fixed multiline non-interactive command execution;
      *) wireless - added support for US FCC UNII-2 and Canada country profiles for LHG-5HPnD-US, RBLHG-5HPnD-XL-US and SXTsq5HPnD-US devices;

      Другие изменения v6.44.2:

      *) bridge - fixed log message when hardware offloading is being enabled;
      *) certificate - added "key-type" field (CLI only);
      *) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
      *) certificate - fixed SAN being duplicated on status change (introduced in v6.44);
      *) certificate - made RAM the default CRL storage location;
      *) certificate - removed DSA (D) flag;
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv4-server - improved stability when performing "check-status" command;
      *) dhcpv6-server - added "address-list" support for bindings (CLI only);
      *) dhcpv6-server - added RADIUS accounting support;
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
      *) fetch - added SFTP support;
      *) fetch - improved user policy lookup;
      *) ike1 - adjusted debug packet logging topics;
      *) ike1 - improved stability for transport mode policies on initiator side;
      *) ike2 - added support for ECDSA certificate authentication (rfc4754);
      *) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
      *) ike2 - improved XAuth identity conversion on upgrade;
      *) ike2 - prefer SAN instead of DN from certificate for ID payload;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
      *) ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
      *) ipsec - added support for RADIUS accounting;
      *) ipsec - added traffic statistics to "active-peers" menu (CLI only);
      *) ipsec - do not allow adding identity to a dynamic peer;
      *) ipsec - fixed freshly created identity not taken in action;
      *) ipsec - fixed policies becoming invalid after changing priority;
      *) ipsec - properly drop already established tunnel when address change detected;
      *) ipsec - renamed "remote-peers" to "active-peers" (CLI only);
      *) ipsec - renamed "rsa-signature" authentication method to "digital-signature";
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - improved "info" command query;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use default APN name "internet" when not provided;
      *) lte - use secondary DNS for DNS server configuration;
      *) ppp - added initial support for Quectel BG96;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) rb4011 - fixed SFP linking (introduced in v6.45beta6);
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) smb - fixed possible buffer overflow;
      *) sms - added USSD message functionality under "/tool sms" (CLI only);
      *) sms - allow specifying multiple "allowed-number" values;
      *) sms - fixed long message parsing (introduced in v6.45beta19);
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) snmp - added OID for neighbor "interface";
      *) snmp - added "write-access" column to community print;
      *) snmp - allow setting interface "adminStatus";
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) ssh - do not generate host key on configuration export;
      *) ssh - fixed multiline non-interactive command execution;
      *) ssh - improved session rekeying process on exchanged data size threshold;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) supout - added "kid-control devices" section to supout file;
      *) switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
      *) switch - properly reapply settings after switch chip reset;
      *) tile - improved link fault detection on SFP+ ports;
      *) userman - updated authorize.net gateway DNS name;
      *) w60g - prefer AP with strongest signal when multiple APs with same SSID present;
      *) wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - improved DFS radar detection when using non-ETSI regulated country;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      Что нового в версии 6.45beta23 (2019-Apr-01 05:51):

      MAJOR CHANGES IN v6.45:
      ----------------------
      !) ipv6 - fixed soft lockup when forwarding IPv6 packets;
      !) ipv6 - fixed soft lockup when processing large IPv6 Neighbor table;
      ----------------------

      Изменения в этом выпуске:

      *) ipsec - properly drop already established tunnel when address change detected;
      *) ipv6 - adjust IPv6 route cache max size based on total RAM memory;
      *) smb - fixed possible buffer overflow;

      Другие изменения v6.44.1:

      *) bridge - fixed log message when hardware offloading is being enabled;
      *) certificate - added "key-type" field (CLI only);
      *) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
      *) certificate - fixed SAN being duplicated on status change (introduced in v6.44);
      *) certificate - made RAM the default CRL storage location;
      *) certificate - removed DSA (D) flag;
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv4-server - improved stability when performing "check-status" command;
      *) dhcpv6-server - added "address-list" support for bindings (CLI only);
      *) dhcpv6-server - added RADIUS accounting support;
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
      *) fetch - added SFTP support;
      *) fetch - improved user policy lookup;
      *) ike1 - adjusted debug packet logging topics;
      *) ike1 - improved stability for transport mode policies on initiator side;
      *) ike2 - added support for ECDSA certificate authentication (rfc4754);
      *) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
      *) ike2 - improved XAuth identity conversion on upgrade;
      *) ike2 - prefer SAN instead of DN from certificate for ID payload;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
      *) ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
      *) ipsec - added support for RADIUS accounting;
      *) ipsec - added traffic statistics to "active-peers" menu (CLI only);
      *) ipsec - do not allow adding identity to a dynamic peer;
      *) ipsec - fixed freshly created identity not taken in action;
      *) ipsec - fixed policies becoming invalid after changing priority;
      *) ipsec - renamed "remote-peers" to "active-peers" (CLI only);
      *) ipsec - renamed "rsa-signature" authentication method to "digital-signature";
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - improved "info" command query;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use default APN name "internet" when not provided;
      *) lte - use secondary DNS for DNS server configuration;
      *) ppp - added initial support for Quectel BG96;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) rb4011 - fixed SFP linking (introduced in v6.45beta6);
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) smb - fixed possible buffer overflow;
      *) sms - added USSD message functionality under "/tool sms" (CLI only);
      *) sms - allow specifying multiple "allowed-number" values;
      *) sms - fixed long message parsing (introduced in v6.45beta19);
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) snmp - added OID for neighbor "interface";
      *) snmp - added "write-access" column to community print;
      *) snmp - allow setting interface "adminStatus";
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) ssh - do not generate host key on configuration export;
      *) ssh - fixed multiline non-interactive command execution;
      *) ssh - improved session rekeying process on exchanged data size threshold;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) supout - added "kid-control devices" section to supout file;
      *) switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
      *) switch - properly reapply settings after switch chip reset;
      *) tile - improved link fault detection on SFP+ ports;
      *) userman - updated authorize.net gateway DNS name;
      *) w60g - prefer AP with strongest signal when multiple APs with same SSID present;
      *) wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - improved DFS radar detection when using non-ETSI regulated country;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      Что нового в версии 6.45beta22 (2019-Mar-29 08:37):

      Изменения в этом выпуске:

      !) ipv6 - fixed soft lockup when forwarding IPv6 packets;
      !) ipv6 - fixed soft lockup when processing large IPv6 Neighbor table;
      *) certificate - added "key-type" field (CLI only);
      *) certificate - fixed SAN being duplicated on status change (introduced in v6.44);
      *) dhcpv6-server - added "address-list" support for bindings (CLI only);
      *) export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
      *) fetch - added SFTP support;
      *) ike2 - prefer SAN instead of DN from certificate for ID payload;
      *) ipsec - added support for RADIUS accounting;
      *) ipsec - fixed policies becoming invalid after changing priority;
      *) snmp - added OID for neighbor "interface";
      *) snmp - added "write-access" column to community print;
      *) snmp - allow setting interface "adminStatus";
      *) ssh - fixed multiline non-interactive command execution;
      *) ssh - improved session rekeying process on exchanged data size threshold;
      *) supout - added "kid-control devices" section to supout file;
      *) userman - updated authorize.net gateway DNS name;
      *) w60g - prefer AP with strongest signal when multiple APs with same SSID present;

      Другие изменения v6.44.1:

      *) bridge - fixed log message when hardware offloading is being enabled;
      *) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
      *) certificate - made RAM the default CRL storage location;
      *) certificate - removed DSA (D) flag;
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv4-server - improved stability when performing "check-status" command;
      *) dhcpv6-server - added RADIUS accounting support;
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) fetch - improved user policy lookup;
      *) ike1 - adjusted debug packet logging topics;
      *) ike1 - improved stability for transport mode policies on initiator side;
      *) ike2 - added support for ECDSA certificate authentication (rfc4754);
      *) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
      *) ike2 - improved XAuth identity conversion on upgrade;
      *) ike2 - prefer SAN instead of DN from certificate for ID payload;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
      *) ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
      *) ipsec - added support for RADIUS accounting;
      *) ipsec - added traffic statistics to "active-peers" menu (CLI only);
      *) ipsec - do not allow adding identity to a dynamic peer;
      *) ipsec - fixed freshly created identity not taken in action;
      *) ipsec - renamed "remote-peers" to "active-peers" (CLI only);
      *) ipsec - renamed "rsa-signature" authentication method to "digital-signature";
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - improved "info" command query;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use default APN name "internet" when not provided;
      *) lte - use secondary DNS for DNS server configuration;
      *) ppp - added initial support for Quectel BG96;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) rb4011 - fixed SFP linking (introduced in v6.45beta6);
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) smb - fixed possible buffer overflow;
      *) sms - added USSD message functionality under "/tool sms" (CLI only);
      *) sms - allow specifying multiple "allowed-number" values;
      *) sms - fixed long message parsing (introduced in v6.45beta19);
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) ssh - do not generate host key on configuration export;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
      *) switch - properly reapply settings after switch chip reset;
      *) tile - improved link fault detection on SFP+ ports;
      *) wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - improved DFS radar detection when using non-ETSI regulated country;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      Что нового в версии 6.45beta20 (2019-Mar-25 10:07):

      Изменения в этом выпуске:

      *) certificate - made RAM the default CRL storage location;
      *) ike1 - adjusted debug packet logging topics;
      *) ipsec - fixed freshly created identity not taken in action;
      *) lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
      *) sms - fixed long message parsing (introduced in v6.45beta19);
      *) wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);

      Другие изменения v6.44.1:

      *) bridge - fixed log message when hardware offloading is being enabled;
      *) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
      *) certificate - removed DSA (D) flag;
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv4-server - improved stability when performing "check-status" command;
      *) dhcpv6-server - added RADIUS accounting support;
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) fetch - improved user policy lookup;
      *) ike1 - improved stability for transport mode policies on initiator side;
      *) ike2 - added support for ECDSA certificate authentication (rfc4754);
      *) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
      *) ike2 - improved XAuth identity conversion on upgrade;
      *) ike2 - prefer SAN instead of DN from certificate for ID payload;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
      *) ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
      *) ipsec - added support for RADIUS accounting;
      *) ipsec - added traffic statistics to "active-peers" menu (CLI only);
      *) ipsec - do not allow adding identity to a dynamic peer;
      *) ipsec - renamed "remote-peers" to "active-peers" (CLI only);
      *) ipsec - renamed "rsa-signature" authentication method to "digital-signature";
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - improved "info" command query;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use default APN name "internet" when not provided;
      *) lte - use secondary DNS for DNS server configuration;
      *) ppp - added initial support for Quectel BG96;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) rb4011 - fixed SFP linking (introduced in v6.45beta6);
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) smb - fixed possible buffer overflow;
      *) sms - added USSD message functionality under "/tool sms" (CLI only);
      *) sms - allow specifying multiple "allowed-number" values;
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) ssh - do not generate host key on configuration export;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
      *) switch - properly reapply settings after switch chip reset;
      *) tile - improved link fault detection on SFP+ ports;
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - improved DFS radar detection when using non-ETSI regulated country;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      Что нового в версии 6.45beta19 (2019-Mar-22 07:30):

      Изменения в этом выпуске:

      *) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
      *) certificate - removed DSA (D) flag;
      *) ike1 - improved stability for transport mode policies on initiator side;
      *) ike2 - added support for ECDSA certificate authentication (rfc4754);
      *) ike2 - prefer SAN instead of DN from certificate for ID payload;
      *) ipsec - renamed "rsa-signature" authentication method to "digital-signature";
      *) smb - fixed possible buffer overflow;
      *) sms - added USSD message functionality under "/tool sms" (CLI only);
      *) ssh - do not generate host key on configuration export;
      *) wireless - improved DFS radar detection when using non-ETSI regulated country;

      Другие изменения v6.44.1:

      *) bridge - fixed log message when hardware offloading is being enabled;
      *) certificate - added support for ECC (Elliptic Curve Cryptography);
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv4-server - improved stability when performing "check-status" command;
      *) dhcpv6-server - added RADIUS accounting support;
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) fetch - improved user policy lookup;
      *) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
      *) ike2 - improved XAuth identity conversion on upgrade;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
      *) ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
      *) ipsec - added support for RADIUS accounting;
      *) ipsec - added traffic statistics to "active-peers" menu (CLI only);
      *) ipsec - do not allow adding identity to a dynamic peer;
      *) ipsec - renamed "remote-peers" to "active-peers" (CLI only);
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - improved "info" command query;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use default APN name "internet" when not provided;
      *) lte - use secondary DNS for DNS server configuration;
      *) ppp - added initial support for Quectel BG96;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) rb4011 - fixed SFP linking (introduced in v6.45beta6);
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) sms - allow specifying multiple "allowed-number" values;
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
      *) switch - properly reapply settings after switch chip reset;
      *) tile - improved link fault detection on SFP+ ports;
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      Что нового в версии 6.45beta16 (2019-Mar-18 07:49):

      Изменения в этом выпуске:

      *) dhcpv4-server - improved stability when performing "check-status" command;
      *) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
      *) ike2 - improved XAuth identity conversion on upgrade;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
      *) ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
      *) ipsec - added support for RADIUS accounting;
      *) ipsec - added traffic statistics to "active-peers" menu (CLI only);
      *) ipsec - do not allow adding identity to a dynamic peer;
      *) ipsec - renamed "remote-peers" to "active-peers" (CLI only);
      *) lte - use default APN name "internet" when not provided;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) switch - properly reapply settings after switch chip reset;

      Другие изменения v6.44.1:

      *) bridge - fixed log message when hardware offloading is being enabled;
      *) certificate - added support for ECC (Elliptic Curve Cryptography);
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv6-server - added RADIUS accounting support;
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) fetch - improved user policy lookup;
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - improved "info" command query;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use secondary DNS for DNS server configuration;
      *) ppp - added initial support for Quectel BG96;
      *) rb4011 - fixed SFP linking (introduced in v6.45beta6);
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) sms - allow specifying multiple "allowed-number" values;
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
      *) tile - improved link fault detection on SFP+ ports;
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      Что нового в версии 6.45beta11 (2019-Mar-08 13:24):

      Изменения в этом выпуске:

      *) bridge - fixed log message when hardware offloading is being enabled;
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv6-server - added RADIUS accounting support;
      *) e-mail - fixed missing "from" address for sent e-mails (introduced in v6.44);
      *) gps - removed unnecessary leading "0" for dd format;
      *) ipsec - allow identities with empty XAuth login and password if RADIUS is enabled (introduced in v6.44);
      *) lte - fixed LTE interface band setting on RBSXTLTE3-7 (introduced in v6.44);
      *) lte - improved "info" command query;
      *) rb4011 - fixed SFP linking (introduced in v6.45beta6);
      *) sms - allow specifying multiple "allowed-number" values;
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) wireless - fixed antenna gain setting on RBSXT5nDr2;

      Другие изменения v6.44:

      *) bridge - fixed possible memory leak when using "ingress-filtering=yes" on bridge interface;
      *) certificate - added support for ECC (Elliptic Curve Cryptography);
      *) certificate - force 3DES encryption for P12 certificate export;
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) dhcp - fixed dual stack queue addition;
      *) dhcpv6-server - use MAC address for RADIUS user when "allow-dual-stack-queue=yes";
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) fetch - improved user policy lookup;
      *) gps - increase precision for dd format;
      *) ipsec - fixed dynamic L2TP peer and identity configuration missing after reboot (introduced in v6.44);
      *) ipsec - use "remote-id=ignore" for dynamic L2TP configuration (introduced in v6.44);
      *) ipv6 - do not allow setting "preferred-lifetime" longer than "valid-lifetime";
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - do not show "session-uptime" if session is not up;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use secondary DNS for DNS server configuration;
      *) ppp - added initial support for Quectel BG96;
      *) rb4011 - fixed ether10 failing to auto negotiate link speed to 1Gbps;
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
      *) tile - improved link fault detection on SFP+ ports;
      *) winbox - added "use-local-address" parameter in "IP/Cloud" menus;
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      Что нового в версии 6.45beta6 (2019-Mar-05 08:51):

      Изменения в этом выпуске:

      *) bridge - fixed possible memory leak when using "ingress-filtering=yes" on bridge interface;
      *) certificate - added support for ECC (Elliptic Curve Cryptography);
      *) certificate - force 3DES encryption for P12 certificate export;
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) dhcp - fixed dual stack queue addition;
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv6-server - use MAC address for RADIUS user when "allow-dual-stack-queue=yes";
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) fetch - improved user policy lookup;
      *) gps - increase precision for dd format;
      *) ipsec - fixed dynamic L2TP peer and identity configuration missing after reboot (introduced in v6.44);
      *) ipsec - use "remote-id=ignore" for dynamic L2TP configuration (introduced in v6.44);
      *) ipv6 - do not allow setting "preferred-lifetime" longer than "valid-lifetime";
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - do not show "session-uptime" if session is not up;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use secondary DNS for DNS server configuration;
      *) ppp - added initial support for Quectel BG96;
      *) rb4011 - fixed ether10 failing to auto negotiate link speed to 1Gbps;
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
      *) tile - improved link fault detection on SFP+ ports;
      *) winbox - added "use-local-address" parameter in "IP/Cloud" menus;
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - updated "india" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      Что нового в версии 6.44rc4 (2019-Feb-22 10:11):

      Важная заметка!!! Backup before upgrade!
      Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done.


      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.44:
      ----------------------
      !) cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);
      !) ipsec - added new "identity" menu with common peer distinguishers;
      !) ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;
      !) ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;
      !) radius - initial implementation of RadSec (Radius communication over TLS);
      !) speedtest - added "/tool speed-test" for ping latency, jitter, loss and TCP and UDP download, upload speed measurements (CLI only);
      !) telnet - do not allow to set "tracefile" parameter;
      !) upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";
      !) upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;
      ----------------------

      Изменения в этом выпуске:

      !) ipsec - added new "identity" menu with common peer distinguishers;
      *) ike1 - do not allow using RSA-key and RSA-signature authentication methods simultaneously on single peer;
      *) interface - added "pwr-line" interface support (more information will follow in next newsletter);
      *) rb4011 - improved SFP+ interface linking to 1Gbps;
      *) ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);
      *) winbox - organized wireless parameters between simple and advanced modes;
      *) wireless - improved NV2 performance for all ARM devices;

      Другие изменения v6.43.12:

      *) dhcpv4-server - use ARP for conflict detection;
      *) discovery - use source MAC address from master interface for MNDP packets (introduced in v6.44beta50);
      *) fetch - improved file downloading to slow memory;
      *) hotspot - added per-user NAT rule generation based on "incoming-filter" and "outgoing-filter" parameters;
      *) ike1 - fixed memory leak;
      *) ipsec - allow to specify single address instead of IP pool under "mode-config";
      *) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters;
      *) lte - added initial support for Telit LN940;
      *) lte - added option to lock the LTE operator;
      *) smb - added commenting option for SMB users (CLI only);
      *) supout - fixed Profile output on single core devices;
      *) userman - added first and last name fields for signup form;
      *) webfig - improved file handling;
      *) winbox - improved file handling;
      *) wireless - improved AR5212 response to incoming ACK frames;
      *) wireless - improved system stability for all ARM devices with wireless;
      *) wireless - improved system stability for all devices with 802.11ac wireless;
      *) bgp - properly update keepalive time after peer restart;
      *) bridge - added option to monitor fast-forward status;
      *) bridge - count routed FastPath packets between bridge ports under FastPath bridge statistics;
      *) bridge - disable fast-forward when using SlowPath features;
      *) bridge - fixed BOOTP packet forwarding when DHCP Snooping is enabled;
      *) bridge - fixed DHCP Option 82 parsing when using DHCP Snooping;
      *) bridge - fixed log message when hardware offloading is being enabled;
      *) bridge - fixed packet forwarding when changing MSTI VLAN mappings;
      *) bridge - fixed packet forwarding with enabled DHCP Snooping and Option 82;
      *) bridge - fixed possible memory leak when using MSTP;
      *) bridge - fixed system's identity change when DHCP Snooping is enabled (introduced in v6.43);
      *) bridge - improved packet handling when hardware offloading is being disabled;
      *) bridge - improved packet processing when bridge port changes states;
      *) btest - added multithreading support for both UDP and TCP tests;
      *) btest - added warning message when CPU load exceeds 90% (CLI only);
      *) capsman - always accept connections from loopback address;
      *) certificate - added support for multiple "Subject Alt. Names";
      *) certificate - enabled RC2 cipher to allow P12 certificate decryption;
      *) certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;
      *) certificate - show digest algorithm used in signature;
      *) chr - assign interface names based on underlying PCI device order on KVM;
      *) chr - distribute NIC queue IRQ's evenly across all CPUs;
      *) chr - fixed IRQ balancing when using more than 32 CPUs;
      *) chr - improved system stability when insufficient resources are allocated to the guest;
      *) cloud - added "ddns-update-interval" parameter;
      *) cloud - do not reuse old UDP socket if routing changes are detected;
      *) cloud - ignore "force-update" command if DDNS is disabled;
      *) cloud - improved DDNS service disabling;
      *) cloud - made address updating faster when new public address detected;
      *) conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter);
      *) console - renamed IP protocol 41 to "ipv6-encap";
      *) console - updated copyright notice;
      *) crs317 - fixed packet forwarding when LACP is used with hw=no;
      *) crs317 - fixed TX not working on sfp-sfpplus9 interface (introduced in v6.40beta12);
      *) crs328 - fixed SFP+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);
      *) crs3xx - fixed packet forwarding through SFP+ ports when using 100Mbps link speed;
      *) crs3xx - fixed SFP+ linking using 1.25G SFP modules (introduced in v6.44beta39);
      *) crs3xx - fixed slow bootup, upgrade and SFP status read (introduced in v6.44beta20);
      *) crs3xx - improved fan control stability;
      *) crs3xx - improved stability when adding ACL rules on CRS326 and CRS328 devices (introduced in 6.44beta39);
      *) defconf - fixed configuration not generating properly on upgrade;
      *) defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;
      *) defconf - fixed IPv6 link-local address range in firewall rules;
      *) dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 DHCP servers to control dynamic lease/binding behaviour;
      *) dhcp - properly load DHCP configuration if options are configured;
      *) dhcpv4-server - added "parent-queue" parameter (CLI only);
      *) dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;
      *) dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;
      *) dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;
      *) dhcpv6-server - allow to add DHCPv6 server with pool that does not exist;
      *) dhcpv6-server - fixed missing gateway for binding's network if RADIUS authentication was used;
      *) dhcpv6-server - improved DHCPv6 server stability when using "print" command;
      *) dhcpv6-server - show "client-address" parameter for bindings;
      *) discovery - detect proper slave interface on bounded interfaces;
      *) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;
      *) discovery - send master port in "interface-name" parameter;
      *) discovery - show neighbors on actual bridge port instead of bridge itself for LLDP;
      *) e-mail - added info log message when e-mail is sent successfully;
      *) ethernet - added "tx-rx-1024-max" counter to Ethernet stats;
      *) ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;
      *) ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);
      *) ethernet - fixed packet forwarding when SFP interface is disabled on hEX S;
      *) ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;
      *) ethernet - improved per core ethernet traffic classificator on mmips devices;
      *) export - fixed "silent-boot" compact export;
      *) fetch - added "http-header-field" parameter;
      *) fetch - added option to specify multiple headers under "http-header-field", including content type;
      *) fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);
      *) fetch - fixed "without-paging" option;
      *) fetch - improved stability when using HTTP mode;
      *) fetch - removed "http-content-type" parameter;
      *) gps - increase precision for dd format;
      *) gps - moved "coordinate-format" from "monitor" command to "set" parameter;
      *) health - improved fan control stability on CRS328-24P-4S+RM;
      *) hotspot - added "https-redirect" under server profiles;
      *) ike1 - fixed "rsa-key" authentication (introduced in v6.44beta);
      *) ike2 - added option to specify certificate chain;
      *) ike2 - added peer identity validation for RSA auth (disabled after upgrade);
      *) ike2 - allow to match responder peer by "my-id=fqdn" field;
      *) ike2 - fixed local address lookup when initiating new connection;
      *) ike2 - improved subsequent phase 2 initialization when no childs exist;
      *) ike2 - properly handle certificates with empty "Subject";
      *) ike2 - retry RSA signature validation with deduced digest from certificate;
      *) ike2 - send split networks over DHCP (option 249) to Windows initiators if DHCP Inform is received;
      *) ike2 - show weak pre-shared-key warning;
      *) ipsec - added account log message when user is successfully authenticated;
      *) ipsec - added basic pre-shared-key strength checks;
      *) ipsec - added new "remote-id" peer matcher;
      *) ipsec - allow to specify single address instead of IP pool under "mode-config";
      *) ipsec - fixed active connection killing when changing peer configuration;
      *) ipsec - fixed all policies not getting installed after startup (introduced in v6.43.8);
      *) ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);
      *) ipsec - hide empty prefixes on "peer" menu;
      *) ipsec - improved invalid policy handling when a valid policy is uninstalled;
      *) ipsec - made dynamic "src-nat" rule more specific;
      *) ipsec - made peers autosort themselves based on reachability status;
      *) ipsec - moved "profile" menu outside "peer" menu;
      *) ipsec - properly detect AES-NI extension as hardware AEAD;
      *) ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;
      *) ipsec - require write policy for key generation;
      *) kidcontrol - added IPv6 support;
      *) kidcontrol - added "reset-counters" command for "device" menu (CLI only);
      *) kidcontrol - added statistics web interface for kids (http://router.lan/kid-control);
      *) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);
      *) kidcontrol - dynamically discover devices from DNS activity;
      *) kidcontrol - fixed validation checks for time intervals;
      *) kidcontrol - properly detect time zone changes;
      *) kidcontrol - use "/128" prefix-length for IPv6 addresses;
      *) l2tp - fixed IPsec secret not being updated when "ipsec-secret" is changed under L2TP client configuration;
      *) lcd - made "pin" parameter sensitive;
      *) led - fixed default LED configuration for RBSXTsq-60ad;
      *) led - fixed default LED configuration for wAP 60G AP devices;
      *) led - fixed PWR-LINE AP Ethernet LED polarity ("/system routerboard upgrade" required);
      *) lldp - fixed missing capabilities fields on some devices;
      *) lte - added additional ID support for Novatel USB730L modem;
      *) lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);
      *) lte - added "ecno" field for "info" command;
      *) lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);
      *) lte - added initial support for multiple APN for R11e-4G (new modem firmware required);
      *) lte - added multiple APN support for R11e-4G;
      *) lte - added support for JioFi JMR1040 modem;
      *) lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;
      *) lte - fixed DHCP IP acquire in 3G mode for r11e-lte (introduced in v6.44beta54);
      *) lte - fixed DHCP IP acquire (introduced in v6.43.7);
      *) lte - fixed DHCP relay packet forwarding when in passthrough mode;
      *) lte - fixed IPv6 activation for R11e-LTE-US modems;
      *) lte - fixed Jaton/SQN modems preventing router from booting properly;
      *) lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;
      *) lte - fixed missing running (R) flag for Jaton LTE modems;
      *) lte - fixed passthrough DHCP address forward when other address is acquired from operator;
      *) lte - fixed reported "rsrq" precision (introduced in v6.43.8);
      *) lte - improved compatibility for Alt38xx modems;
      *) lte - improved SIM7600 initialization after reset;
      *) lte - improved SimCom 7100e support;
      *) lte - query "cfun" on initialization;
      *) lte - require write policy for at-chat;
      *) lte - update firmware version information after R11e-LTE/R11e-4G firmware upgrade;
      *) netinstall - do not show kernel failure critical messages in the log after fresh install;
      *) ntp-client - fixed "dst-active" and "gmt-offset" being updated after synchronization with server;
      *) port - improved "remote-serial" TCP performance in RAW mode;
      *) ppp - added "at-chat" command;
      *) ppp - fixed dynamic route creation towards VPN server when "add-default-route" is used;
      *) profiler - classify kernel crypto processing as "encrypting";
      *) profile - removed obsolete "file-name" parameter;
      *) proxy - removed port list size limit;
      *) radius - implemented Proxy-State attribute handling in CoA and disconnect requests;
      *) rb3011 - implemented multiple engine IPsec hardware acceleration support;
      *) rb4011 - fixed SFP+ interface full duplex and speed parameter behavior;
      *) rbm33g - improved stability when used with some USB devices;
      *) romon - improved reliability when processing RoMON packets on CHR;
      *) routerboard - removed "RB" prefix from PWR-LINE AP devices;
      *) routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";
      *) sfp - fixed possible reboot loop when inserting SFP modules in CRS328-4C-20S-4S+ (introduced in v6.44beta61);
      *) smb - fixed macOS clients not showing share contents;
      *) smb - fixed Windows 10 clients not able to establish connection to share;
      *) sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;
      *) snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;
      *) snmp - changed fan speed value type to Gauge32;
      *) snmp - fixed "rsrq" reported precision;
      *) snmp - fixed w60g station table;
      *) snmp - removed "rx-sector" ("Wl60gRxSector") value;
      *) snmp - report bridge ifSpeed as "0";
      *) snmp - report ifSpeed 0 for sub-layer interfaces;
      *) ssh - added error log message when key exchange fails;
      *) ssh - close active SSH connections before IPsec connections on shutdown;
      *) ssh - fixed non-interactive shell not returning all output (introduced in v6.44);
      *) ssh - fixed public key format compatibility with RFC4716;
      *) ssh - fixed single command execution (introduced in v6.44beta9);
      *) supout - fixed "poe-out" output not showing all interfaces;
      *) switch - added comment field to switch ACL rules;
      *) switch - fixed ACL rules on IPQ4018 devices;
      *) system - accept only valid path for "log-file" parameter in "port" menu;
      *) system - removed obsolete "/driver" command;
      *) tr069-client - added "check-certificate" parameter to allow communication without certificates;
      *) tr069-client - added "connection-request-port" parameter (CLI only);
      *) tr069-client - added support for InformParameter object;
      *) tr069-client - fixed certificate verification for certificates with IP address;
      *) tr069-client - fixed HTTP cookie getting duplicated with the same key;
      *) tr069-client - increased reported "rsrq" precision;
      *) traceroute - improved stability when sending large ping amounts;
      *) traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;
      *) tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with DNS as "remote-address";
      *) upgrade - made security package depend on DHCP package;
      *) usb - improved power-reset error message when no bus specified on CCR1072-8G-1S+;
      *) usb - improved USB device powering on startup for hAP ac^2 devices;
      *) usb - increased default power-reset timeout to 5 seconds;
      *) userman - added first and last name fields for signup form;
      *) userman - show redirect location in error messages;
      *) user - require "write" permissions for LTE firmware update;
      *) vrrp - made "password" parameter sensitive;
      *) w60g - added "10s-average-rssi" parameter to align mode (CLI only);
      *) w60g - added align mode "/interface w60g align" (CLI only);
      *) w60g - fixed scan in bridge mode;
      *) w60g - improved PtMP performance;
      *) w60g - improved reconnection detection;
      *) w60g - improved "tx-packet-error-rate" reading;
      *) w60g - renamed disconnection message when license level did not allow more connected clients;
      *) w60g - renamed "frequency-list" to "scan-list";
      *) watchdog - allow specifying DNS name for "send-smtp-server" parameter;
      *) winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;
      *) winbox - added "allow-dual-stack-queue" parameter in "IP/DHCP Server" and "IPv6/DHCP Server" menus;
      *) winbox - added "challenge-password" field when signing certificate with SCEP;
      *) winbox - added "conflict-detection" parameter in "IP/DHCP Server" menu;
      *) winbox - added "conflict-detection" parameter in "IP/DHCP server" menu;
      *) winbox - added "coordinate-format" parameter in LTE interface settings;
      *) winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;
      *) winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;
      *) winbox - added src/dst address and in/out interface list columns to default firewall menu view;
      *) winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab;
      *) winbox - allow setting "network-mode" to "auto" under LTE interface settings;
      *) winbox - allow specifying interface lists in "CAPsMAN/Access List" menu;
      *) winbox - fixed "IPv6/Firewall" "Connection limit" parameter not allowing complete IPv6 prefix lengths;
      *) winbox - fixed L2MTU parameter setting on "W60G" type interfaces;
      *) winbox - fixed "LCD" menu not shown on RB2011UiAS-2HnD;
      *) winbox - fixed missing w60g interface status values;
      *) winbox - moved "Too Long" statistics counter to Ethernet "Rx Stats" tab;
      *) winbox - renamed "Default AP Tx Rate" to "Default AP Tx Limit";
      *) winbox - renamed "Default Client Tx Rate" to "Default Client Tx Limit";
      *) winbox - show "R" flag under "IPv6/DHCP Server/Bindings" tab;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) winbox - show "W60G" wireless tab on wAP 60G AP;
      *) wireless - added new "installation" parameter to specify router's location;
      *) wireless - improved connection stability for new model Apple devices;
      *) wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);
      *) wireless - improved system stability for all ARM devices with wireless;
      *) wireless - improved system stability when scanning for other networks;
      *) wireless - removed G/N support for 2484MHz in "japan" regulatory domain;
      *) wireless - report last seen IP address in RADIUS accounting messages;
      *) wireless - show "installation" parameter when printing configuration;
      Что нового 6.47.9 (2021-Feb-05 15:22):

      Изменения 6.47.8:

      *) bgp - fixed VPNV4 RD byte order;
      *) branding - fixed LCD logo loading from new style branding package;
      *) crs312 - fixed missing SwOS firmware on revision 2 devices;
      *) crs3xx - correctly filter packets by L2MTU size;
      *) crs3xx - improved system stability when receiving large frames for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (introduced in v6.47.5);
      *) defconf - fixed default configuration loading on RBcAP-2nD and RBwAP-2nD;
      *) hotspot - fixed "idle-timeout" usage with RADIUS authentication;
      *) hotspot - fixed special character parsing in "target" variable (CVE-2021-3014);
      *) package - do not include multiple The Dude packages in HDD installer;
      *) snmp - fixed "send-trap" functionality;
      *) webfig - fixed new interface addition;
      *) winbox - fixed enable/disable button presence for "Bridge/Hosts" menu;
      *) winbox - renamed IP protocol 41 to "ipv6-encap";
      *) winbox - show "System/Health" only on boards that have health monitoring;
      *) winbox - use health values reported by gauges for "System/Health" menu;
      *) wireless - renamed "macedonia" regulatory domain information to "north macedonia";
      *) wireless - updated "indonesia5" regulatory domain information;
      Что нового в версии 6.46.8 (2020-Oct-29 8:29):

      Изменения 6.46.7:

      *) cap - fixed L2MTU path discovery;
      *) chr - fixed file system quiescing;
      *) crs3xx - fixed IGMP snooping for CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - fixed switch rules for CRS309 and CRS317 devices (introduced in v6.46.7);
      *) crs3xx - improved system stability on CRS354 devices;
      *) defconf - fixed default configuration loading on RBmAP-2nD;
      *) defconf - improved default configuration generation on devices with changed wireless interface names;
      *) dhcpv6-server - improved stability when changing server for static bindings;
      *) dhcpv6-server - properly save bindings when executing "make-static" command;
      *) fetch - fixed "src-address" usage for SFTP;
      *) fetch - improved SSL handshake processing;
      *) hotspot - do not verify Hotspot interface status when detecting if HTTP/HTTPS login method is allowed;
      *) leds - fixed LED type setting;
      *) lte - fixed multiple APN passthrough on R11e-4G;
      *) lte - limit allowed APN count to 3 on R11e-LTE;
      *) mpls - fixed duplicate "LabelRelease" message sending;
      *) ospf - optimized LSA printing for smaller message sizes;
      *) poe - fixed automatic PoE firmware upgrade procedure;
      *) poe - improved PoE-out status detection;
      *) ppp - allow specifying pool name for "remote-ipv6-prefix-pool" parameter;
      *) radius - added "Service-Type" attribute to Access-Request for IPv4 and IPv6 DHCP servers;
      *) smips - reduced RouterOS main package size;
      *) sms - fixed SMS sending when both "interface" and "smsc" parameters are specified;
      *) snmp - fixed "/tool snmp-get" functionality (introduced in v 6.46beta43);
      *) switch - fixed Ethernet padding for small packets;
      *) user - improved WinBox and The Dude authenticated session handling;
      *) user-manager - updated PayPal's root certificate authorities;
      *) vrrp - made "password" parameter sensitive;
      *) w60g - general stability and performance improvements;
      *) wireless - added support for US FCC UNII-2 and Canada country profiles for NetMetal series devices;
      *) wireless - fixed incorrect wireless capability information in association response frames;
      *) wireless - updated "kazakhstan" regulatory domain information;
      Что нового в версии 6.46.7 (2020-Sep-07 07:38):

      Важная заметка!!!

      - The Dude server must be updated to monitor v6.46.4+ and v6.47beta30+ RouterOS type devices.
      - The Dude client must be manually upgraded after upgrading The Dude server.
      - The Dude requires "winbox" policy instead of "dude" to monitor v6.46.4+ and v6.47beta30+ RouterOS type devices.

      Изменения 6.46.6:

      *) arm - improved stability when forcing 25G speed on unsupported interface;
      *) bridge - fixed host table update on SNMP query;
      *) bridge - fixed STP alternate and backup port states for devices with switch chip;
      *) crs3xx - fixed hardware offloaded MPLS forwarding when using bonding interfaces;
      *) crs3xx - fixed QSFP+ interface LEDs when using break-out cable for CRS326-24S+2Q+;
      *) crs3xx - fixed switch ACL rules for CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - fixed switch port "egress-rate" removal for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices;
      *) crs3xx - improved 10G interface initialization on CRS312 devices;
      *) crs3xx - improved Ethernet port group traffic forwarding on CRS354 devices;
      *) crs3xx - improved system stability when using hardware offloaded MPLS;
      *) defconf - fixed default configuration loading on RBmAPL-2nD;
      *) dhcpv6-server - disallow changing binding's "prefix-pool";
      *) dhcpv6-server - do not require "server" parameter for bindings;
      *) discovery - do not send discovery packets on inactive bonding slave interfaces;
      *) discovery - do not send discovery packets on interfaces that are blocked by STP;
      *) dot1x - fixed duplicate EAP request packets for server;
      *) dot1x - fixed EAP packet version numbering;
      *) email - added support for multiple "to" recipients;
      *) export - fixed HotSpot "address-per-mac" parameter export;
      *) fetch - show status "uploaded" instead of "downloaded" when uploading a file;
      *) ftp - fixed possible buffer overflow;
      *) hotspot - ignore packets from host while MAC authentication is in progress;
      *) ike1 - improved stability when performing policy lookup on non-existant peer;
      *) ike2 - fixed local side NAT detection;
      *) ike2 - fixed policy reference for pending acquire;
      *) ike2 - retry RSA signature validation with deduced digest from certificate;
      *) interface - added new builtin "static" interface list;
      *) kidcontrol - fixed "time-unlimited-rate" to engage in correct time;
      *) lcd - improved general system stability when LCD is not present;
      *) lte - fixed modem initialization when multiple modems are used simultaneously;
      *) lte - fixed PDP authentication configuration for SIM7600;
      *) lte - improved stability during firmware upgrade;
      *) metarouter - fixed image importing (introduced in v6.46);
      *) ospf - fixed disappearing NSSA default route;
      *) ospf - fixed processing of "unknown" LSA type;
      *) ospf - improved route tag processing for OSPFv3;
      *) poe - fixed "power-cycle" functionality on hEX PoE, PowerBox Pro and OmniTIK 5 PoE ac;
      *) port - removed serial console port on hEX S;
      *) ppp - removed "comment", "set" and "edit" commands from "PPP->Active" menu;
      *) profile - added support for CCR2004-1G-12S+2XS;
      *) qsfp - fixed auto-negotiation status;
      *) quickset - fixed invalid configuration applying when performing changes during LTE modem initialization process;
      *) quickset - show "Antenna Gain" setting on devices without built-in antennas;
      *) route - improved stability when 6to4 interface is configured with disabled IPv6 package;
      *) routerboard - fixed "reset-button" menu presence on all devices;
      *) routerboot - fixed etherboot FCS errors with 100Mbps rate for CRS305, CRS309 and CRS317 devices ("/system routerboard upgrade" required);
      *) sfp - stabilized CRS212 SFP port functionality and improved monitoring of optical modules;
      *) smb - fixed file path validation (introduced in v6.46);
      *) smb - fixed possible memory leak (CVE-2020-11881);
      *) smb - limit active session count to 5 per connection;
      *) sniffer - allow setting port for "streaming-server";
      *) snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB;
      *) switch - correctly enable and disable CPU Flow Control on RB3011UiAS;
      *) switch - fixed MAC address learning on switch-cpu port for Atheros8316, Atheros8227 and Atheros7240 switch chips;
      *) upgrade - fixed space handling in package file names;
      *) w60g - added "mdmg-fix" parameter for RBwAP60Gx3 (CLI only);
      *) w60g - improved rate selection in low traffic conditions;
      *) webfig - fixed 5 GHz wireless interface "frequency" parameter value list on Audience;
      *) winbox - added "region" parameter for W60G interfaces;
      *) winbox - allow to specify any Ethernet like interface under "Tool/WoL" menu;
      *) winbox - do not allow to enter empty strings in "caps-man-names" and "common-name" parameters;
      *) winbox - fixed "Tx/Rx Signal Strength" value presence for 4 chain interfaces;
      *) winbox - fixed wireless interface "HT" tab setting presence when "band=5ghz-n/ac";
      *) winbox - fixed wireless sniffer parameter setting;
      *) winbox - hide irrelevant switch port parameters;
      *) wireless - added support for U-NII-2 for cAP ac;
      *) wireless - added support for U-NII-2 for wAP ac;
      *) wireless - allow setting "tx-power" up to 40;
      *) wireless - changed "station-roaming" default setting from "enabled" to "disabled";
      *) wireless - fixed potential wireless driver issue related to CVE-2020-3702;
      *) wireless - improved management service stability when receiving bogus packets;
      *) wireless - updated "bangladesh" regulatory domain information;
      *) wireless - updated "canada" regulatory domain information;
      *) wireless - updated "egypt" regulatory domain information;
      *) wireless - updated "indonesia5" regulatory domain information;
      *) wireless - updated "united states" regulatory domain information;
      *) www - added "tls-version" parameter in "IP->Services" menu;
      Что нового в версии 6.45.9 (2020-Apr-30 10:25):

      Изменения 6.45.8:

      *) arm - improved watchdog and kernel panic reporting in log after reboots on RB3011 and IPQ4018/IPQ4019 devices ("/system routerboard upgrade" required);
      *) capsman - fixed "certificate" parameter updating on CAP;
      *) certificate - fixed certificate verification when flushing CRL's;
      *) chr - added support for file system quiescing;
      *) chr - enabled support for VMBus protocol version 4.1;
      *) chr - improved system stability when running CHR on Hyper-V;
      *) console - prevent incorrect type interfaces appearing in command hints;
      *) crs3xx - fixed frame forwarding after disabling/enabling bridge hardware offloading for CRS354-48G-4S+2Q+ device;
      *) crs3xx - fixed interface statistics for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices;
      *) crs3xx - fixed switch rule "dst-port" parameter for IPv6 traffic on CRS305-1G-4S+, CRS326-24G-2S+, CRS328-24P-4S+, CRS328-4C-20S-4S+, netPower 15FR devices;
      *) crs3xx - improved SFP+ DAC cable initialization for CRS326-24S+2Q+ device;
      *) defconf - added welcome note with common first steps for new users;
      *) discovery - do not send CDP and LLDP packets on interfaces that does not have MAC address;
      *) health - fixed maximum SFP temperature reading under '/system health' menu;
      *) hotspot - fixed redirect to log in page (introduced in v6.45);
      *) ike1 - rekey phase 1 rekeying as responder for Windows initiators;
      *) ipsec - improved system stability when handling fragmented packets;
      *) led - added "dark-mode" functionality for CRS105-5S-FB;
      *) lte - added "phy-cellid" value support for LTE-US;
      *) lte - fixed IP type selection from APN on RBSXTLTE3-7;
      *) lte - improved system stability when performing firmware update on R11e-LTE6;
      *) sniffer - fixed minor typo in "host" menu;
      *) snmp - fixed "ifSpeed" reporting for tunnel interfaces;
      *) snmp - fixed "routeros-version" value returning from registration table;
      *) snmp - fixed UPS battery voltage value scaling;
      *) ssh - added support for RSA keys with SHA256 hash (RFC8332);
      *) system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic;
      *) system - improved system stability when forwarding traffic from switch chip to CPU (introduced in v6.43);
      *) system - improved system stability when receiving/sending TCP traffic on multicore devices;
      *) traceroute - improved stability when invalid packet is received;
      *) webfig - added default configuration confirmation window to WebFig;
      *) webfig - allow skin designing without "ftp" and "sensitive" policies;
      *) webfig - do not show WebFig menu when opening 'Check For Updates' in Quick Set;
      *) winbox - added "Options" parameter support for DHCPv6 client and server;
      *) winbox - added 160Mhz extension channel support for CAPsMAN;
      *) winbox - added support for "Tools->WoL" menu;
      *) winbox - do not show "Revision" parameter under "System/RouterBOARD" menu on devices that have only one revision;
      *) winbox - fixed "ARP" parameter inheritance from "CAPs Configuration" configuration;
      *) winbox - fixed "Bands" parameter display for LTE interfaces;
      *) winbox - fixed "DSCP" parameter value setting;
      *) winbox - fixed "Frequency" and "Secondary Frequency" parameter inheritance from "CAPs Channel" configuration;
      *) winbox - fixed "Passthr. MAC Address" parameter display "LTE APNs" menu;
      *) winbox - fixed "Switch" menu on CRS354-48P-4S+2Q+;
      *) winbox - fixed "dst-port" unsetting in "IP->Hotspot->Walled Garden" menu;
      *) winbox - fixed "invalid" flag presence under "System/Certificates/CRL" menu;
      *) winbox - fixed automatic "IPv6->Firewall->Address List" table update;
      *) winbox - increased limit of multi-entry fields to 100;
      *) winbox - made "none" the default value for "Security Profile" parameter when creating a new "Wirelees->Connect list" entry;
      *) winbox - renamed "Memory used" to "HDD used" for HDD type under "Tools->Graphing->Resource Graphs";
      *) winbox - renamed "Routerboard" to "RouterBOARD" under "System/RouterBOARD" menu;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) wireless - added "skip-dfs-channels" parameter;
      *) wireless - allow using FCC "U-NII-2" frequency range for hAP ac2 and RBwAPGR series devices;
      *) wireless - fixed default "antenna-gain" setting on SXT 2 devices;
      *) wireless - improved 5GHz interface stability on RB4011iGS+5HacQ2HnD and Audience;
      *) wireless - improved compatibility for "ETSI" wireless country profile;
      *) wireless - improved system stability on hAP ac^2;
      *) wireless - updated "bangladesh" regulatory domain information;
      *) wireless - updated "indonesia4" regulatory domain information;
      *) wireless - updated "south africa" regulatory domain information;
      Что нового в версии 6.45.8 (2020-Jan-23 07:19):

      Изменения 6.45.7:

      *) capsman - fixed background scan showing incorrect regulatory domain mismatch error (CAP upgrade required);
      *) capsman - improved radar detection algorithm;
      *) chr - improved stability when changing ARP modes on e1000 type adapters;
      *) console - fixed "clear-history" restoring historic actions after power cycle;
      *) console - removed "edit" and "set" actions from "System/History" menu;
      *) console - updated copyright notice;
      *) crs305 - disable optical SFP/SFP+ module Tx power after disabling SFP+ interface;
      *) dhcpv4-server - improved stability when RADIUS interim update is sent;
      *) dhcpv6-client - fixed timeout when doing rebind;
      *) dhcpv6-client - properly update bind time when unused prefix received from the server;
      *) dhcpv6-client - properly update IPv6 address on rebind;
      *) dhcpv6-server - fixed logged error message when using "address-pool=static-only";
      *) dhcpv6-server - ignore prefix-hint from client's DHCPDISCOVER if static prefix received from RADIUS;
      *) health - fixed health reporting on OmniTIK 5 PoE ac;
      *) ipsec - improved system stability when processing decrypted packet on unregistered interface;
      *) l2tp - improved system stability when disconnecting many clients at once;
      *) led - fixed default LED configuration for RBLHG-2nD and RBLHG-5HPnD;
      *) lte - show SIM error when no card is present;
      *) ppp - fixed connection establishment when receiving "0.0.0.0" DNS;
      *) ppp - fixed minor typo in "ppp-client" monitor;
      *) ppp - prioritize "remote-ipv6-prefix-pool" from PPP secret over PPP profile;
      *) qsfp - do not report bogus monitoring readouts on modules without DDMI support;
      *) qsfp - improved module monitoring readouts for DAC and break-out cables;
      *) routerboard - added "mode-button" support for RBcAP2nD;
      *) security - fixed vulnerability for routers with default password (limited to Wireless Wire), admin could login on startup with empty password before default configuration script was fully loaded;
      *) ssh - fixed output printing when "command" parameter used;
      *) timezone - updated time zone database to version 2019c;
      *) traffic-generator - improved memory handling on CHR;
      *) w60g - fixed "monitor" command on disabled interfaces;
      *) winbox - automatically refresh "Packets" table when new packets are captured by "Tools/Packet Sniffer";
      *) winbox - show "LCD" menu only on boards that have LCD screen;
      *) wireless - added "ETSI" regulatory domain information;
      *) wireless - added "indonesia4" regulatory domain information;
      *) wireless - added U-NII-2 support forRBSXTsqG-5acD, RBLHGG-5acD-XL, RBLHGG-5acD, RBLDFG-5acD, RBDiscG-5acD;
      *) wireless - allow using "canada2" regulatory domain on US lock devices;
      *) wireless - fixed sensor MAC address reporting in TZSP header;
      *) wireless - improved compatibility by adding default installation mode and antenna gain for devices with integrated antennas;
      *) wireless - improved compatibility for Switzerland wireless country profile to improve compliance with ETSI regulations;
      *) wireless - improved IPQ4019, QCA9984, QCA9888 wireless interface stability;
      Что нового в версии 6.44.6 (2019-Oct-24 09:37):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.44.6:
      ----------------------
      !) package - accept only packages with original filenames (CVE-2019-3976);
      !) package - improved package signature verification (CVE-2019-3977);
      !) security - fixed improper handling of DNS responses (CVE-2019-3978, CVE-2019-3979);
      ----------------------

      Изменения в этом выпуске:

      *) capsman - fixed frequency setting requiring multiple frequencies;
      *) capsman - fixed newline character missing on some logging messages;
      *) ccr - improved packet processing after overloading interface;
      *) crs312 - fixed combo SFP port toggling (introduced in v6.44.5);
      *) crs328 - adjust fan speed based on SFP and CPU temperature;
      *) crs3xx - correctly display link rate when 10/100/1000BASE-T SFP modules are used in SFP+ interfaces;
      *) crs3xx - fixed management access when using switch rule "new-vlan-priority" property;
      *) export - fixed "bootp-support" parameter export;
      *) health - improved fan control on CRS3xx and CCR1016-12S-1S+r2;
      *) ike2 - fixed policy port selection for responder with natted initiator;
      *) ike2 - fixed traffic selector address family selection when using IPv6;
      *) interface - fixed missing PWR-LINE section on PL7411-2nD and PL6411-2nD (introduced v6.44);
      *) ipsec - allow inline "passphrase" parameter when importing keys;
      *) ipsec - fixed minor spelling mistakes in logs;
      *) led - fixed default LED configuration for RBLHG5nD;
      *) ospf - fixed opaque LSA type checking in OSPFv2;
      *) ospf - fixed possible busy loop condition when accessing OSPF LSAs;
      *) ospf - improved "unknown" LSA handling in OSPFv3;
      *) profile - added "internet-detect" process classificator;
      *) radius - fixed open socket leak when invalid packet is received (introduced in v6.44);
      *) sfp - fixed "sfp-rx-power" value for some transceivers;
      *) smb - improved stability on x86 and CHR;
      *) snmp - fixed encrypted data sequence (introduced in v6.44.5);
      *) snmp - improved reliability on SNMP service packet validation;
      *) ssh - accept remote forwarding requests with empty hostnames;
      *) ssh - fixed carriage return presence in subsequent sessions;
      *) ssh - improved remote forwarding handling (introduced in v6.44.3);
      *) supout - fixed supout file generation outside of internal storage with insufficient space;
      *) switch - fix port isolation for non-CRS series switch chips;
      *) system - accept only valid string for "name" parameter in "disk" menu (CVE-2019-15055);
      *) system - improved system stability for devices with AR9342 SoC;
      *) upgrade - fixed "auto-upgrade" to use new style authentication;
      *) upnp - fixed XML parsing (FG-VD-19-110);
      *) watchdog - renamed "no-ping-delay" parameter to "ping-start-after-boot";
      *) winbox - added "auto-erase" parameter to "Tools/SMS" menu;
      *) winbox - added "https-redirect" parameter to "IP/Hotspot/Profiles menu";
      *) winbox - added "revision" parameter to "System/Routerboard" menu;
      *) winbox - removed "max-sms" parameter from "Tools/SMS" menu;
      *) wireless - fixed basic rate reporting in snooper;
      *) wireless - improved 802.11ac stability for all ARM devices with wireless;
      *) wireless - improved range selection when distance set to "dynamic";
      *) wireless - improved stability when setting fixed primary and secondary channels on RB4011iGS+5HacQ2HnD-IN;
      Что нового в версии 6.44.5 (2019-Jul-04 10:32):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.44.5:
      ----------------------
      !) security - fixed vulnerabilities CVE-2019-13954, CVE-2019-13955;
      !) security - fixed vulnerabilities CVE-2019-11477, CVE-2019-11478, CVE-2019-11479;
      !) security - fixed vulnerability CVE-2019-13074;
      ----------------------

      Изменения в этом выпуске:

      *) bridge - correctly handle bridge host table;
      *) capsman - fixed CAP system upgrading process for MMIPS;
      *) capsman - fixed interface-list usage in access list;
      *) certificate - removed "set-ca-passphrase" parameter;
      *) cloud - properly stop "time-zone-autodetect" after disable;
      *) conntrack - fixed GRE protocol packet connection-state matching (CVE-2014-8160);
      *) defconf - automatically set "installation" parameter for outdoor devices;
      *) dhcpv6-client - fixed status update when leaving "bound" state;
      *) dhcpv6-server - fixed dynamic IPv6 binding without proper reference to the server;
      *) dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
      *) discovery - fixed CDP packets not including address on slave ports (introduced in v6.44);
      *) e-mail - properly release e-mail sending session if the server's domain name can not be resolved;
      *) firewall - fixed fragmented packet processing when only RAW firewall is configured;
      *) firewall - process packets by firewall when accepted by RAW with disabled connection tracking;
      *) gps - strip unnecessary trailing characters from "longtitude" and "latitude" values;
      *) hotspot - moved "title" HTML tag after "meta" tags;
      *) ipv6 - improved system stability when receiving bogus packets;
      *) ovpn - added "verify-server-certificate" parameter for OVPN client (CVE-2018-10066);
      *) rb3011 - improved system stability when receiving bogus packets;
      *) rb921 - improved system stability ("/system routerboard upgrade" required);
      *) snmp - improved reliability on SNMP service packet validation;
      *) ssh - fixed non-interactive multiple command execution;
      *) supout - added IPv6 ND section to supout file;
      *) supout - added "pwr-line" section to supout file;
      *) supout - changed IPv6 pool section to output detailed print;
      *) winbox - do not allow setting "dns-lookup-interval" to "0";
      *) wireless - improved DFS radar detection when using non-ETSI regulated country;
      *) wireless - improved installation mode selection for wireless outdoor equipment;
      *) wireless - updated "china" regulatory domain information;
      *) www - improved client-initiated renegotiation within the SSL and TLS protocols (CVE-2011-1473);
      Что нового в версии 6.43.16 (2019-May-14 11:40):

      *) w60g - fixed memory leak (introduced in v6.43.15);
      Что нового в версии 6.43.15 (2019-May-10 12:44):

      *) dhcpv4-server - fixed commenting option for alerts;
      *) dhcpv6-server - fixed binding setting update from RADIUS;
      *) ike1 - improved stability for transport mode policies on initiator side;
      *) ipv6 - adjusted IPv6 route cache max size;
      *) ipv6 - adjust IPv6 route cache max size based on total RAM memory;
      *) ipv6 - improved IPv6 neighbor table updating process;
      *) lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
      *) lte - use default APN name "internet" when not provided;
      *) rb2011 - removed "sfp-led" from "System/LEDs" menu;
      *) rb4011 - fixed SFP+ interface full duplex and speed parameter behaviour;
      *) rb4011 - improved SFP+ interface linking to 1Gbps;
      *) smb - fixed possible buffer overflow;
      *) snmp - added "radio-name" (mtxrWlRtabRadioName) OID support;
      *) ssh - do not generate host key on configuration export;
      *) switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
      *) system - accept only valid path for "log-file" parameter in "port" menu;
      *) userman - updated authorize.net gateway DNS name;
      *) webfig - improved file handling;
      *) winbox - improved file handling;
      *) winbox - show "R" flag under "IPv6/DHCP Server/Bindings" tab;
      *) wireless - added support for US FCC UNII-2 and Canada country profiles for LHG-5HPnD-US, RBLHG-5HPnD-XL-US and SXTsq5HPnD-US devices;
      *) wireless - improved wireless country settings for EU countries, outdoor models will use outdoor frequency range by default;
      *) wireless - improved system stability for all devices with 802.11ac wireless;
      *) wireless - improved wireless country settings for EU countries;
      Что нового в версии 6.43.14 (2019-Apr-02 09:12):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.43.14:
      ----------------------
      !) ipv6 - fixed soft lockup when forwarding IPv6 packets;
      !) ipv6 - fixed soft lockup when processing large IPv6 Neighbor table;
      ----------------------

      Изменения в этом выпуске:

      *) ipv6 - adjust IPv6 route cache max size based on total RAM memory;
      Что нового в версии 6.43.13 (2019-Mar-13 11:27):

      *) bridge - count routed FastPath packets between bridge ports under FastPath bridge statistics;
      *) bridge - fixed BOOTP packet forwarding when DHCP Snooping is enabled;
      *) bridge - fixed packet forwarding with enabled DHCP Snooping and Option 82;
      *) bridge - fixed possible memory leak when using "ingress-filtering=yes" on bridge interface;
      *) bridge - fixed system's identity change when DHCP Snooping is enabled (introduced in v6.43);
      *) capsman - always accept connections from loopback address;
      *) certificate - force 3DES encryption for P12 certificate export;
      *) dhcp - fixed dual stack queue addition;
      *) dhcpv6-server - allow to add DHCPv6 server with pool that does not exist;
      *) dhcpv6-server - fixed missing gateway for binding's network if RADIUS authentication was used;
      *) ethernet - added "tx-rx-1024-max" counter to Ethernet stats;
      *) ethernet - fixed packet forwarding when SFP interface is disabled on hEX S;
      *) fetch - improved file downloading to slow memory;
      *) gps - increase precision for dd format;
      *) gps - removed unnecessary leading "0" for dd format;
      *) ipsec - fixed all policies not getting installed after startup (introduced in v6.43.8);
      *) ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);
      *) ipv6 - do not allow setting "preferred-lifetime" longer than "valid-lifetime";
      *) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters;
      *) kidcontrol - fixed validation checks for time intervals;
      *) led - fixed default LED configuration for RBSXTsq-60ad;
      *) lldp - fixed missing capabilities fields on some devices;
      *) lte - do not show "session-uptime" if session is not up;
      *) lte - improved SIM7600 initialization after reset;
      *) netinstall - do not show kernel failure critical messages in the log after fresh install;
      *) ntp-client - fixed "dst-active" and "gmt-offset" being updated after synchronization with server;
      *) ppp - fixed dynamic route creation towards VPN server when "add-default-route" is used;
      *) rb4011 - fixed ether10 failing to auto negotiate link speed to 1Gbps;
      *) smb - added commenting option for SMB users (CLI only);
      *) smb - fixed macOS clients not showing share contents;
      *) smb - fixed Windows 10 clients not able to establish connection to share;
      *) ssh - close active SSH connections before IPsec connections on shutdown;
      *) supout - fixed "poe-out" output not showing all interfaces;
      *) supout - fixed Profile output on single core devices;
      *) winbox - added "conflict-detection" parameter in "IP/DHCP Server" menu;
      *) winbox - added "coordinate-format" parameter in LTE interface settings;
      *) winbox - added "use-local-address" parameter in "IP/Cloud" menu;
      *) winbox - allow specifying interface lists in "CAPsMAN/Access List" menu;
      *) winbox - fixed "IPv6/Firewall" "Connection limit" parameter not allowing complete IPv6 prefix lengths;
      *) winbox - fixed "LCD" menu not shown on RB2011UiAS-2HnD;
      *) winbox - moved "Too Long" statistics counter to Ethernet "Rx Stats" tab;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) wireless - fixed antenna gain setting on RBSXT5nDr2;
      *) wireless - improved antenna gain setting for devices with built in antennas;
      *) wireless - improved AR5212 response to incoming ACK frames;
      *) wireless - improved connection stability for new model Apple devices;
      Что нового в версии 6.42.12 (2019-Feb-12 08:23):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.42.12:
      ----------------------
      !) winbox - improvements in connection handling to router with open winbox service (CVE-2019–3924);
      ----------------------

      *) ipsec - accept only valid path for "export-pub-key" parameter in "key" menu;
      *) quickset - fixed "country" parameter not properly setting regulatory domain configuration;
      *) smb - fixed possible buffer overflow;
      *) w60g - fixed disconnection issues in PtMP setups;
      *) wireless - improved antenna gain setting for devices with built in antennas;
      *) wireless - show indoor/outdoor frequency limitations under "/interface wireless info country-info" command;
      Что нового в версии 6.42.11 (2018-Dec-21 09:17):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.42.11:
      ----------------------
      !) telnet - do not allow to set "tracefile" parameter;
      ----------------------

      *) capsman - fixed "group-key-update" parameter not using correct units;
      *) certificate - properly flush old CRLs when changing store location;
      *) console - properly remove system note after configuration reset;
      *) dhcpv6-server - properly handle DHCP requests that include prefix hint;
      *) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;
      *) discovery - fixed neighbor discovery for PPP interfaces;
      *) export - fixed "silent-boot" compact export;
      *) gps - added "coordinate-format" parameter;
      *) interface - improved system stability when including/excluding a list to itself;
      *) kidcontrol - do not allow users with "read" policy to pause and resume kids;
      *) led - fixed default LED configuration for RBMetalG-52SHPacn;
      *) log - properly handle long echo messages;
      *) lte - added support for more ZTE MF90 modems;
      *) lte - disallow setting LTE interface as passthrough target;
      *) package - use bundled package by default if standalone packages are installed as well;
      *) resource - fixed "total-memory" reporting on ARM devices;
      *) snmp - added "tx-ccq" ("mtxrWlStatTxCCQ") and "rx-ccq" ("mtxrWlStatRxCCQ") values;
      *) snmp - do not initialise interface traps on bootup if they are not enabled;
      *) switch - fixed MAC learning when disabling interfaces on devices with Atheros8327 and QCA8337 switch chips;
      *) system - fixed situation when all configuration was not properly loaded on bootup;
      *) timezone - fixed "Europe/Dublin" time zone;
      *) upgrade - automatically uninstall standalone package if already installed in bundle;
      *) webfig - do not show bogus VHT field in wireless interface advanced mode;
      *) winbox - allow to change VHT rates when 5ghz-n/ac band is used;
      *) winbox - renamed "Radius" to "RADIUS";
      *) winbox - show "Switch" menu on RB4011iGS+5HacQ2HnD and RB4011iGS+;
      *) wireless - added new "installation" parameter to specify router's location;
      *) wireless - improved stability for 802.11ac;
      *) wireless - improvements in wireless frequency selection;
      Что нового в версии 6.42.10 (2018-Nov-14 15:04):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.42.10:
      ----------------------
      !) upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";
      !) upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;
      ----------------------

      *) bridge - do not learn untagged frames when filtering only tagged packets;
      *) bridge - fixed possible memory leak when VLAN filtering is used;
      *) bridge - improved packet handling when hardware offloading is being disabled;
      *) bridge - properly disable dynamic CAP interfaces;
      *) certificate - fixed time zone adjustment for SCEP requests;
      *) crs328 - improved link status update on disabled SFP and SFP+ interfaces;
      *) crs328 - improved link status update on disabled SFP+ interface when using DAC;
      *) crs3xx - fixed possible memory leak when disabling bridge interface;
      *) defconf - automatically accept default configuration if reset done by holding button;
      *) defconf - properly load default configuration after reset (introduced in v6.42.9);
      *) health - fixed bad voltage readings on RB493G;
      *) ipsec - fixed hw-aead (H) flag presence under Installed SAs on startup;
      *) ipsec - improved stability when uninstalling multiple SAs at once;
      *) ipsec - properly update warnings under peer menu;
      *) led - added "dark-mode" functionality for LHG and LDF series devices;
      *) led - fixed default LED configuration for SXT LTE kit and wAP 60G AP devices;
      *) led - fixed power LED turning on after reboot when "dark-mode" is used;
      *) ntp - fixed possible NTP server stuck in "started" state;
      *) ospf - improved stability while handling type-5 LSAs;
      *) romon - improved packet processing when MTU in path is lower than 1500;
      *) routerboard - renamed SIM slots to "a" and "b" on SXT LTE kit;
      *) routerboard - show "boot-os" and "force-backup-booter" options only on devices that have such feature;
      *) timezone - updated timezone information from tzdata2018g release;
      *) traffic-flow - fixed post NAT port reporting;
      *) traffic-flow - fixed "src-mac-address" and added "post-src-mac-address" fields;
      *) tunnel - made "ipsec-secret" parameter sensitive;
      *) usb - fixed power-reset for hAP ac^2 devices;
      *) w60g - fixed misleading license level requirement log message;
      *) w60g - fixed "scan" functionality when in bridge mode;
      *) w60g - renamed "frequency-list" to "scan-list";
      *) winbox - allow to specify SIM slot on LtAP mini;
      *) winbox - enabled "fast-forward" by default when adding new bridge;
      *) winbox - show "System/Health" only on boards that have health monitoring;
      *) winbox - show "W60G" wireless tab on wAP 60G AP;
      Что нового в версии 6.42.9 (2018-Sep-27 05:19):

      Важная заметка!!! Сделайте резервную копию перед обновлением!
      RouterOS v6.41 and above contains new bridge implementation that supports hardware offloading (hw-offload).
      This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
      Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
      The rest of RouterOS Switch specific configuration remains untouched in usual menus.
      Please, note that downgrading below RouterOS v6.41 will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

      *) bridge - ignore tagged BPDUs when bridge VLAN filtering is used;
      *) bridge - improved packet handling when hardware offloading is being disabled;
      *) crs317 - fixed packet forwarding on bonded interfaces without hardware offloading;
      *) crs326/crs328 - fixed packet forwarding when port changes states with IGMP Snooping enabled;
      *) defconf - properly clear global variables when generating default configuration after RouterOS upgrade;
      *) dns - fixed DNS cache service becoming unresponsive when active Hotspot server is present on the router (introduced in 6.42);
      *) filesystem - fixed NAND memory going into read-only mode (requires "factory-firmware" >= 3.41.1 and "current-firmware" >= 6.43);
      *) health - added missing parameters from export;
      *) health - fixed voltage measurements for RB493G devices;
      *) hotspot - properly update dynamic "walled-garden" entries when changing "dst-host";
      *) ike2 - fixed rare authentication and encryption key mismatches after rekey with PFS enabled;
      *) ike2 - improved subsequent phase 2 initialization when no child exist;
      *) ipsec - improved invalid policy handling when a valid policy is uninstalled;
      *) ipsec - improved stability when using IPsec with disabled route cache;
      *) led - added "dark-mode" functionality for wsAP ac lite, RB951Ui-2nD, hAP, hAP ac lite and LtAP mini devices;
      *) lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;
      *) lte - fixed LTE registration in 2G/3G mode;
      *) ospf - improved link-local LSA flooding;
      *) ospf - improved stability when originating LSAs with OSPFv3;
      *) routerboard - fixed memory tester reporting false errors on IPQ4018 devices ("/system routerboard upgrade" required);
      *) routerboard - show "boot-os" option only on devices that have such feature;
      *) routerboot - fixed RouterOS booting on devices with particular NAND memory;
      *) sniffer - made "connection", "host", "packet" and "protocol" sections read-only;
      *) supout - added "files" section to supout file;
      *) upgrade - fixed RouterOS upgrade process from RouterOS v5 on PowerPC;
      *) upnp - improved UPnP service stability when handling HTTP requests;
      *) userman - fixed "shared-secret" parameter requiring "sensitive" policy;
      *) w60g - added "frequency-list" setting;
      *) w60g - fixed interface LED status update on connection;
      *) w60g - fixed random disconnects;
      *) w60g - general stability and performance improvements;
      *) webfig - fixed time interval settings not applied properly under "IP/Kid Control/Kids" menu;
      *) webfig - fixed www service becoming unresponsive;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that has such feature;
      *) wireless - accept only valid path for sniffer output file parameter;
      *) wireless - fixed "/interface wireless sniffer packet print follow" output;

      What's new in 6.42.8 (2018-Sep-21 13:30):

      (factory only release)
      Что нового в версии 6.40.9 (2018-Aug-20 07:46):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.40.9:
      ----------------------
      !) security - fixed vulnerabilities CVE-2018-1156, CVE-2018-1157, CVE-2018-1158, CVE-2018-1159;
      ----------------------

      *) certificate - fixed "add-scep" template existence check when signing certificate;
      *) defconf - fixed wAP LTE kit default configuration;
      *) ethernet - improved large packet handling on ARM devices with wireless;
      *) ethernet - removed obsolete slave flag from "/interface vlan" menu;
      *) filesystem - fixed NAND memory going into read-only mode;
      *) hotspot - fixed user authentication when queue from old session is not removed yet;
      *) interface - fixed interface configuration responsiveness;
      *) ipsec - fixed policies becoming invalid if added after a disabled policy;
      *) ldp - properly load LDP configuration;
      *) ppp - fixed "hunged up" grammar to "hung up" within PPP log messages;
      *) sfp - hide "sfp-wavelength" parameter for RJ45 transceivers;
      *) snmp - added remote CAP count OID for CAPsMAN;
      *) supout - added "partitions" section to supout file;
      *) tile - fixed Ethernet interfaces becoming unresponsive;
      *) tr069-client - fixed unresponsive tr069 service when blackhole route is present;
      *) userman - fixed compatibility with PayPal TLS 1.2;
      *) userman - improved unique username generation process when adding batch of users;
      *) winbox - added missing "dscp" and "clamp-tcp-mss" settings to IPv6 tunnels;
      *) winbox - allow to specify full URL in SCEP certificate signing process;
      *) winbox - by default specify keepalive timeout value for tunnel type interfaces;
      *) winbox - show firmware upgrade message at the bottom of "System/RouterBOARD" menu;
      *) winbox - show "scep-url" for certificates;
      *) winbox - show "sector-writes" on ARM devices that have such counters;
      *) winbox - show "sector-writes" on devices that have such counters;
      *) winbox - show "System/Health" only on boards that have health monitoring;
      *) wireless - added option to disable PMKID for WPA2;
      *) wireless - enable all chains by default on devices without external antennas after configuration reset;
      *) wireless - fixed packet processing after removing wireless interface from CAP settings;
      *) wireless - improved client "channel-width" detection;
      *) wireless - improved Nv2 PtMP performance;
      *) wireless - increased stability on hAP ac^2 and cAP ac with legacy data rates;
      *) wireless - updated "united-states" regulatory domain information;
      Что нового в версии 6.40.8 (2018-Apr-23 11:34):

      !) winbox - fixed vulnerability that allowed to gain access to an unsecured router;
      *) certificate - fixed incorrect SCEP URL after an upgrade;
      *) health - fixed empty measurements on CRS328-24P-4S+RM;
      *) ike2 - use "policy-template-group" parameter when picking proposal as initiator;
      *) ipv6 - fixed IPv6 behaviour when bridge port leaves bridge;
      *) routerboard - fixed "mode-button" support on hAP lite r2 devices;
      *) ssh - fixed SSH service becoming unavailable;
      *) traffic-flow - fixed IPv6 destination address value when IPFIX protocol is used;
      *) winbox - show "Switch" menu on cAP ac devices;
      *) wireless - improved compatibility with BCM chipset devices;
      Что нового в версии 6.40.7 (2018-Mar-29 13:29):

      !) smb - fixed buffer overflow vulnerability, everyone using this feature is urged to upgrade;
      *) console - do not allow variables that start with digit to be referenced without "$" sign;
      *) led - fixed unused "link-act-led" LED trigger on RBLHG 2nD, RBLHG 2nD-XL and RBSXTsq 2nD;
      *) netinstall - sign Netinstall executable with an Extended Validation Code Signing Certificate;
      *) romon - make "secret" field sensitive in console;
      *) tr069-client - fixed TR069 service becoming unavailable when related service package is not installed;
      *) winbox - fixed "/tool e-mail send" attachment behavior;
      *) winbox - fixed maximal ID for Traffic Generator stream;
      *) winbox - made UDP local and remote TX size parameter optional in Bandwidth Test tool;
      *) winbox - removed "Enable" and "Disable" buttons from IPsec "mode-config" list;
      *) winbox - show "D" flag under "/ip dhcp-client" menu;
      *) winbox - use proper graph name for HDD graphs;
      *) wireless - enable all chains by default on devices without external antennas after configuration reset;
      Что нового в версии 6.40.6 (2018-Feb-20 11:04):

      *) btest - fixed TCP test accuracy when low TX/RX rates are used;
      *) certificate - do not use UTF-8 for SCEP challenge password;
      *) certificate - fixed PKCS#10 version;
      *) chr - generate new system ID on first boot;
      *) crs317 - fixed reliability on FAN controller;
      *) defconf - fixed DISC Lite5 LED default configuration;
      *) dhcpv4-server - fixed framed and classless route received from RADIUS server;
      *) disk - fixed disk detach process;
      *) dude - fixed e-mail notifications when default port is not used;
      *) export - fixed "/system routerboard mode-button" compact export;
      *) filesystem - implemented additional system integrity checks on reboots;
      *) firewall - limited maximum "address-list-timeout" value to “35w3d13h13m56s”;
      *) hotspot - fixed "dst-port" to require valid "protocol" in "walled-garden ip";
      *) hotspot - fixed Walled Garden IP functionality when address-list is used;
      *) ike1 - fixed crash on XAUTH if user does not exist;
      *) ike1 - fixed memory corruption when IPv6 is used;
      *) ike1 - improved stability on phase1 rekeying;
      *) ike2 - added support for multiple split networks;
      *) ike2 - delay rekeyed peer outbound SA installation;
      *) ike2 - improve half-open connection handling;
      *) ike2 - kill connection when peer changes address;
      *) ike2 - use peer configuration address when available on empty TSi;
      *) ipsec - fixed incorrect esp proposal key size usage;
      *) ipsec - properly update IPsec secret for IPIP/EoIP/GRE dynamic peer;
      *) l2tp - improved reliability on packet processing in FastPath;
      *) netinstall - improved LTE package description;
      *) netinstall - properly generate skins folder when branding package is installed;
      *) ovpn - fixed resource leak on systems with high CPU usage;
      *) ovpn-server - do not periodically change automatically generated server MAC address;
      *) ppp - do not disconnect active PPP connection after "idle-timeout";
      *) ppp - do not lose "/ppp profile" script configuration after other profile parameters are edited;
      *) ppp - fixed "change-mss" functionality when MSS is not set on forwarded packets;
      *) ppp - fixed L2TP and PPTP encryption negotiation process on configuration changes;
      *) pppoe-client - properly re-establish MLPPP session when one of the lines stopped transmitting packets;
      *) quickset - do not automatically change mode to CPE;
      *) quickset - renamed router IP static DNS name to "router.lan";
      *) route - fixed DHCP/PPP “add-default-route” “distance” minimal value to 1;
      *) route - improved reliability on routing table update;
      *) routerboard - properly report warnings under "/system routerboard" menu;
      *) scheduler - properly display long scheduler configuration;
      *) sfp - improved SFP module compatibility;
      *) sms - fixed minor problem for SMS delivery;
      *) snmp - added IPv6 addresses support on default "public" community;
      *) snmp - fixed bulk requests when non-repeaters are used;
      *) snmp - fixed consecutive OID bulk get from the same table;
      *) traceroute - fixed "/tool traceroute" results print;
      *) traffic-flow - do not count single extra packet per each flow;
      *) webfig - added support for proper default policies when adding script or scheduler job;
      *) webfig - fixed backup loading from Webfig on RouterBOARD running default configuration;
      *) webfig - fixed bridge port sorting order by name;
      *) webfig - fixed MAC address ordering;
      *) webfig - fixed router getting reset to default configuration;
      *) webfig - fixed column ordering;
      *) winbox - allow to specify "to-ports" for "action=masquerade";
      *) wireless - fixed wireless protocol mode restrictions if lockpack is installed and has limits for it;
      *) wireless - removed unused monitor command from CLI;
      *) wireless - updated "Australia", "Czech Republic", "UK 5.8 Fixed" and "United Kingdom" regulatory domain information;
      Что нового в версии 6.39.3 (2017-Oct-12 11:24):

      *) arp - properly update dynamic ARP entries after interface related changes;
      *) bonding - fixed 802.3ad mode on RB1100AHx4;
      *) bonding - improved reliability on bonding interface removal;
      *) console - fixed different command auto complete;
      *) crs1xx/2xx - fixed 1 Gbps forced mode for several SFP modules;
      *) crs317 - added L2MTU support;
      *) crs3xx - improved packet processing in slowpath;
      *) dhcp - fixed downgrade from RouterOS v6.41 or higher;
      *) dhcpv4-server - fixed lease renew for DHCP clients that sends renewal with "ciaddr = 0.0.0.0";
      *) dhcpv6-client - do not run DHCPv6 client when IPv6 package is disabled;
      *) dhcpv6-client - fixed IA evaluation order;
      *) dhcpv6-client - require pool name to be unique;
      *) dhcpv6-server - do not release address of static binding from pool after server removal;
      *) discovery - fixed timeouts for LLDP neighbours;
      *) ethernet - fixed occasional broken interface order after reset/first boot;
      *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
      *) export - fixed export for PoE-OUT related settings;
      *) export - fixed wireless "ssid" and "supplicant-identity" compact export;
      *) fasttrack - fixed fasttrack over interfaces with dynamic MAC address;
      *) firewall - fixed bridge "action=log" rules;
      *) firewall - fixed crash on fasttrack dummy rule manual change attempt;
      *) firewall - properly remove "address-list" entry after timeout ends;
      *) firewall - removed unique address list name limit;
      *) hAP ac lite - removed nonexistent "wlan-led";
      *) hotspot - improved user statistics collection process;
      *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
      *) ike1 - fixed initiator ID comparison to NAT-OA;
      *) interface - improved interface state change handling when multiple interfaces are affected at the same time;
      *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
      *) ipv6 - fixed IPv6 address request from pool;
      *) metarouter - fixed display of bogus error message on startup;
      *) ntp-client - properly start NTP client after reboot if manual server IP is not configured;
      *) ovpn - added support for "push-continuation";
      *) ovpn - added support for topology subnet for IP mode;
      *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
      *) ovpn - improved performance when receiving too many options;
      *) ping - fixed ping getting stuck (after several thousands of ping attempts);
      *) ppp - fixed non-standart PAP or CHAP packet handling;
      *) pppoe-client - fixed incorrectly formed PADT packet;
      *) pppoe-client - fixed wrong MRU detection over VLAN interfaces;
      *) proxy - fixed rare program crash after closing client connection;
      *) quickset - fixed incorrect VPN address value on arm and tilera;
      *) rb1100ahx4 - fixed HW acceleration fragmented packet decryption when fragment is smaller than 64 bytes;
      *) rb1100ahx4 - fixed startup problems (requires additional reboot after upgrade);
      *) rb2011 - fixed possible LCD blinking along with ethernet LED;
      *) rb3011 - fixed packet passthrough on switch2 while booting;
      *) rb922 - restored missing wireless interface on some boards;
      *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
      *) sfp - fixed invalid temperature readings when ambient temperature is below 0C;
      *) sfp - fixed OPTON module DDM information readings;
      *) sfp - fixed temperature readings for various SFP modules;
      *) sniffer - do not skip L2 packets when "all" interface mode was used;
      *) snmp - fixed "/caps-man registration-table" uptime values;
      *) snmp - fixed "/system license" parameters for CHR;
      *) snmp - fixed "/system resource cpu print oid";
      *) snmp - fixed crash on interface table get;
      *) ssh - do not execute command if it starts with "-" symbol;
      *) supout - fixed IPv6 firewall section;
      *) switch - fixed multicast forwarding on CRS326;
      *) tile - fixed copying large amount of text over serial console;
      *) tile - improved reliability on MPLS package processing;
      *) traffic-flow - fixed reboots when IPv6 address has been set as target address without active IPv6 package;
      *) trafficgen - fixed "lost-ratio" showing incorrect statistics after multiple sequences;
      *) userman - do not send disconnect request for user when "simultaneous session limit reached";
      *) userman - fixed "limitation" and "profile-limitation" update;
      *) userman - fixed CoA packet processing after changes in "/tool user-manager router" configuration;
      *) userman - lookup language files also in "/flash" directory;
      *) vlan - do not allow VLAN MTU to be higher than L2MTU;
      *) vlan - do not delete existing VLAN interface on "failure: already have such vlan";
      *) webfig - allow to unset "rate-limit" for DHCP leases;
      *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
      *) webfig - improved reliability of login process;
      *) winbox - added possibility to define "comment" for "/routing bgp network" entries;
      *) winbox - added support for certificate CRL list;
      *) winbox - do not show LCD menu for devices which does not have it;
      *) winbox - fixed ARP table update after entry changes state to incomplete;
      *) winbox - hide "level" and "tunnel" parameters for IPSec policy templates;
      *) winbox - hide FAN speed if it is 0RPM;
      *) winbox - make IPSec policies table an ordered list;
      *) winbox - properly show "dhcp-server" warnings;
      *) winbox - show "/interface wireless cap print" warnings;
      *) winbox - show "/system health" only on boards that have health monitoring;
      *) winbox - show "D" flag under "/interface mesh port" menu;
      *) wireless - added "etsi1" and "russia3" regulatory domain information;
      *) wireless - fixed compatibility with "AR5212" wireless chips;
      *) wireless - improved WPA2 key exchange reliability;
      *) wireless - updated "china", "norway" and "new-zealand" regulatory domain information;
      Что нового в версии 6.38.7 (2017-Jun-20 10:55):

      !) bridge - fixed BPDU rx/tx when “protocol-mode=none”;
      !) bridge - reverted bridge BPDU processing back to pre-v6.38 behaviour (v6.40 will have another separate VLAN-aware bridge implementation);
      *) 6to4 - fixed wrong IPv6 "link-local" address generation;
      *) arp - fixed "make-static";
      *) bonding - do not add bonding interface if "could not set MTU" error is received;
      *) console - fixed "/ip neighbor discovery" export;
      *) console - fixed unexpected console crash when using variables as functions;
      *) console - instead of true/false report yes/no as LCD enabled state;
      *) defconf - discard default configuration startup query with configuration change from Webfig;
      *) defconf - discard default configuration startup query with RouterOS upgrade;
      *) defconf - fixed default configuration generation when wireless package is disabled;
      *) defconf - fixed Groove 52 ac band settings;
      *) dns - made loading thousands of static entries faster;
      *) ethernet - fixed "loop-protect" on "master-port";
      *) ethernet - fixed rare switch chip hang (could cause port flapping);
      *) fetch - fixed download issue over HTTPS;
      *) firewall - do not allow to set "rate" value to 0 for "limit" parameter;
      *) firewall - fixed "address-list" entry "creation-time" adjustment to timezone;
      *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
      *) firewall - fixed cosmetic "invalid" flag when item was disabled;
      *) ike1 - fixed crash on xauth message;
      *) ike2 - allow multiple child SA traffic selectors on re-key;
      *) ike2 - fixed last EAP authentication payload type;
      *) ike2 - fixed policy release during SA negotiation;
      *) ike2 - fixed RSA authentication without EAP;
      *) ike2 - fixed situation when traffic selector prefix was parsed incorrectly;
      *) ipsec - do not deduct policy src/dst address for tunnel policies;
      *) ipsec - fixed generated policy priority;
      *) ipsec - fixed peer "my-id" address reset;
      *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
      *) led - fixed turning off LED when interface is lost;
      *) log - added missing "license limit exceeded" log entry;
      *) log - work on false CPU/RAM overclocked alarms;
      *) netinstall - fixed typos in Netinstall status messages;
      *) ntp - restart NTP client when it is stuck in error state;
      *) ppp - fixed IPv6 address receiving on PPP interface;
      *) pppoe - added warning on PPPoE client/server, if it is configured on slave interface;
      *) pppoe-server - fixed "one-session-per-host" issue where 2 simultaneous sessions were possible from the same host;
      *) queue - fixed queuing when at least one child queue has "default-small" and other/s is/are different (introduced in 6.35);
      *) quickset - fixed LTE "signal-strength" graphs;
      *) smb - fixed share path on devices with "/flash" directory;
      *) sniffer - fixed VLAN tags when sniffing all interfaces;
      *) snmp - added fan-speed OIDs in "/system health print oid";
      *) snmp - fixed limited walk;
      *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
      *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
      *) traffic-flow - fixed IPFIX IPv6 data reporting;
      *) upnp - fixed firewall NAT rule update when external IP address changes;
      *) userman - allow "name-for-user" to be empty and not unique;
      *) userman - fixed rare GUI crash when User Manager files are not accessible;
      *) webfig - allow to enter frequency ranges in wireless “scan-list”;
      *) webfig - allow to select "default-encryption" profile on PPP tunnels;
      *) webfig - correctly specify routing filter prefix;
      *) webfig - do not allow to reorder items if table is sorted by some column;
      *) webfig - fixed "last-link-up" & "last-link-down" time information;
      *) webfig - fixed Bridge Filter properties display when there are more than one Filter available;
      *) webfig - show all available options under "Advanced Mode" for wireless interfaces;
      *) winbox - added "Flush" button under “unicast-fdb” menu;
      *) winbox - added "memory-scroll", "filter-cpu", "filter-ipv6-address", "filter-operation-between-entries" Sniffer parameters;
      *) winbox - added “protected-routerboard” parameters under RouterBOARD settings menu;
      *) winbox - allow shorten bytes to k,M,G in firewall "connection-bytes" and "connection-rates";
      *) winbox - do not allow Packet Sniffer "memory-limit" and "file-limit" lower than 10KiB;
      *) winbox - do not allow to open multiple same sub-menus at the same time;
      *) winbox - do not show "dpd-max-failures" on IKEv2;
      *) winbox - do not start Traffic Generator automatically when opening "Quick Start";
      *) winbox - fixed "Montly" typo to "Monthly" in Graphing menu;
      *) winbox - fixed firewall port selection with Winbox v2;
      *) winbox - fixed IPSec "mode-config" DNS settings;
      *) winbox - fixed issue when working IPSec policies were shown as invalid;
      *) winbox - fixed switch ACL Policer statistics;
      *) winbox - fixed typo in BGP advertisements menu Aggragator->Aggregator;
      *) winbox - hide "wps-mode" & "security-profile" in wireless nv2 mode;
      *) winbox - properly show "dhcp-server" warnings;
      *) winbox - removed spare values from "loop-protect" setting for EoIPv6 tunnels;
      *) winbox - removed unnecessary "/system health" menu on "hAP ac lite" and “RB450”;
      *) winbox - show "A" flag for IPSec policies;
      *) wireless - reduced load on CPU for high speed wireless links;
      Что нового в версии 6.37.5 (2017-Mar-09 11:54):

      !) www - fixed http server vulnerability;
      *) chr - fixed problem when transmit speed was reduced by interface queues;
      *) dhcp - do not listen on IPv4/IPv6 client to IPv6 MLD packets;
      *) dude - (changes discussed here: https://wiki.mikrotik.com/wiki/Manual:The_Dude_v6/dude_v6.xx_changelog);
      *) export - do not show "read-only" IRQ entries;
      *) filesystem - implemented procedures to verify and restore internal file structure integrity upon upgrading;
      *) firewall - do not allow to set "time" parameter to 0s for "limit" option;
      *) firewall - fixed import of exported configuration that had updated "limit" setting;
      *) graphing - fixed graphing crash when high amount of traffic is processed;
      *) hotspot - fixed rare kernel crash on multicore systems;
      *) hotspot - fixed redirect to URL where escape characters are used (requires newly generated HTML files);
      *) hotspot - show Host table commentaries also in Active tab and vice versa;
      *) interface - do not treat multiple zeros as single zero on name comparison;
      *) irq - properly detect all IRQ entries;
      *) l2tp-client - fixed IPSec policy generation after reboot;
      *) lcd - show fan2 speed only if it is available;
      *) leds - fixed defaults for RBSXT5HacD2nr2;
      *) mmips - improved general stability;
      *) rb3011 - fixed noise from buzzer after silent boot;
      *) switch - fixed crash when trying to configure second master port on the same chipset (RB3011, RB2011, CCR1009-8G-1S+);
      *) userman - allow access to User Manager users page only through "/user" URL;
      *) userman - show warning when no users are selected for CSV file generation;
      *) winbox - added "add-relay-info" and "relay-info-remote-id" to DHCP relay;
      *) winbox - added H flag to "/ip arp" ;
      *) winbox - added missing "use-fan2" and "active-fan2" to "/system health";
      *) winbox - allow shorten bytes to k,M,G in bridge firewall just like in “/ip firewall”;
      *) winbox - do not hide "power-cycle-after" option;
      *) winbox - do not hide 00:00:00:00:00:00 MAC address in unpublished ARPs;
      *) winbox - fixed matching "connection-state=untracked" connections;
      *) winbox - fixed typo in “/system resources pci” list;
      *) winbox - hide advertise tab in Hotspot user profile configuration if "transparent-proxy" is not enabled;
      *) winbox - make "power-cycle-after" show correct value;
      *) winbox - make "power-cycle-interval" not to depend on "power-cycle-ping-enabled" in PoE settings;
      *) winbox - properly show BGP communities in routing filters table filter;
      *) wireless - fixed scan tool stuck in background;
      *) wireless - improved compatibility with Intel 2200BG wireless card;
      *) wireless - update Thailand country frequency settings;
      Что нового в версии 6.37.4 (2017-Jan-13 06:52):

      *) bonding - fixed "tx-drop" on VLAN over bonding on x86;
      *) certificates - added year cap (invalid-after date will not exceed year 2039);
      *) certificates - fixed crash when crl is removed while it is being fetched;
      *) certificates - fixed fail on import from CAPs when both key and name already exist;
      *) crs - added comment ability in more switch menus;
      *) dhcpv6-client - fixed DHCPv6 rebind on startup;
      *) dhcpv6-server - fixed server removal crash if static binding was present;
      *) dns - fixed typo in regexp error message;
      *) dude - (changes here: http://wiki.mikrotik.com/wiki/Manual:The_Dude_v6/dude_v6.xx_changelog);
      *) export - updated default values to clean up export compact;
      *) fan - improved RPM monitor on CCR1009;
      *) firewall - do not defragment packets which are marked with "notrack" in raw firewall;
      *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
      *) firewall - fixed dynamic raw rule behaviour;
      *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
      *) firewall - nat action "netmap" now requires to-addresses to be specified;
      *) health - report fan speed for RB800 and RB1100 when 3-pin fan is being used;
      *) hotspot - fixed nat rule port setting in "hs-unauth-to" chain by changing it from "dst-port" to "src-port" on Walled Garden ip "return" rules;
      *) ipsec - fixed kernel failure on tile with sha256 when hardware encryption is not being used;
      *) ipv6 - added warning about having interface MTU less than minimal IPv6 packet fragment (1280);
      *) ipv6 - moved empty IPv6 pool error message to error topic;
      *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
      *) license - fixed demo license expiration after installation on x86;
      *) log - improved firewall log messages when NAT has changed only connection ports;
      *) lte - increased delay when setting sms send mode;
      *) metarouter - fixed startup process (introduced in 6.37.2);
      *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
      *) ppp - significantly improved shutdown speed on servers with many active tunnels;
      *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
      *) profile - added "bfd" and "remote-access" processes;
      *) profile - added ability to monitor cpu usage per core;
      *) profile - make profile work on mmips devices;
      *) profile - properly classify "wireless" processes;
      *) proxy - fixed "max-cache-object-size" export;
      *) proxy - speed-up almost empty disk cache clean-up;
      *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
      *) quickset - various small changes;
      *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
      *) rb751u - fixed ethernet LEDs;
      *) snmp - always report bonding speed as speed from first bonding slave;
      *) snmp - fixed rare crash when incorrectly formatted packet was received;
      *) ssh - fixed high memory consumption when transferring file over ssh tunnel;
      *) switch - fix BPDU dynamic Host table entry on Atheros Gigabit switch chips;
      *) time - updated time zones;
      *) traceroute - fixed memory leak;
      *) trafficgen - fixed compact export when "header-stack" includes tcp;
      *) vlan - allow to add multiple VLANs which name starts with same number and has same length;
      *) vrrp - do not show unrelated log warning messages about version mismatch;
      *) watchdog - do not send supout file if "auto-send-supout" is disabled;
      *) webfig - added extra protection against XSS exploits;
      *) webfig - show properly interface last-link-up/down times;
      *) webfig - show properly large BGP AS numbers;
      *) winbox - added "Complete" flag to arp table;
      *) winbox - added "make-static" to IPv6 DHCP server bindings;
      *) winbox - added "prefix-pool" to DHCPv6 server binding;
      *) winbox - added upstream flag to IGMP proxy interfaces;
      *) winbox - allow to enable/disable traffic flow targets;
      *) winbox - allow to specify "connection-bytes" & "connection-rate" for any protocol in “/ip firewall” rules;
      *) winbox - allow to specify "sip-timeout" under ip firewall service-ports;
      *) winbox - do not allow to set "loop-protect-send-interval" to 0s;
      *) winbox - do not create empty rates.vht-basic/supported-mcs if not specified in CAPsMAN;
      *) winbox - fixed crash when legacy Winbox version was used;
      *) winbox - fixed default values for interface "loop-protect-disable-time" and "loop-protect-send-interval";
      *) winbox - fixed missing "IPv6/Settings" menu;
      *) winbox - fixed typo in "propagate-ttl" setting;
      *) winbox - properly show VHT basic and supported rates in CAPsMAN;
      *) winbox - show all related HT tab settings in 2GHz-g/n mode;
      *) winbox - show dynamic IPv6 pools properly;
      *) winbox - show errors on IPv6 addresses;
      *) winbox - show proper ipv6 connection timeout;
      *) winbox - specify metric for “/ip dns cache-used” setting;
      *) wireless - fixed full "spectral-history" header print on AP modes;
      *) wireless - fixed upgrade from older wireless packages when AP interface had empty SSID;
      *) wireless - show comment on "security-profile" if it is set;
      Что нового в версии 6.36.4 (2016-Oct-05 11:24):

      !) ssl - fixed peer address/dns verification from certificate (affects sstp, fetch, capsman);
      *) console - hotspot setup show wrong certificate name;
      *) ethernet - added support for LAN9514 ethernet dongle;
      *) ethernet - allow to force mtu value when actual-mtu is already the same;
      *) firewall - fixed dynamic dummy firewall rules appearance in raw tables;
      *) firewall - fixed time based rules on time/timezone changes (again);
      *) hotspot - fixed nat rule dst-port by making it visible again;
      *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
      *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
      *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
      *) led - fixed default led settings for wAP2nDr2;
      *) lte - added dlink dwm-157 D, dwm-222, Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
      *) lte - added rndis for ZTE MF8xx;
      *) lte - added ZTE K5008-Z back;
      *) lte - fixed setting correct lte band for sxt lte;
      *) mpls - fixed memory leak;
      *) pppoe - fixed disconnects by idle timeout when fastpath is used;
      *) rb3011 - fixed rare occasions when router would hang while loading kernel;
      *) sstp - allow to specify proxy by dns name;
      *) tile - do not reboot device after watchdog disable/enable;
      *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
      *) userman - always re-fetch table data when switching between different menus;
      *) userman - fixed memory leak on user limitation calculations;
      *) userman - fixed timezone adjustment in reports;
      *) webfig - fixed certificate signing;
      *) webfig - fixed channel selection in check-for-update menu in Firefox;
      *) winbox - added auto refresh for BFD neighbors;
      *) winbox - adjust on-event field dynamically depending on window size;
      *) winbox - adjusted allowed values for http-proxy field;
      *) winbox - allow to unset http-proxy field for sstp client;
      *) winbox - fixed typo in dhcpv6 relay (DCHP to DHCP);
      *) winbox - removed health menu from devices that do not support it;
      *) winbox - removed unset button for L2MTU field;
      *) wireless - show DFS flag in country-info command output;
      Что нового в версии 6.34.6 (2016-Jun-06 08:37):

      *) discovery - fixed identity discovery (introduced in 6.34.5);
      *) log - fixed time zone adjustment (introduced in 6.34.5);
      *) snmp - fixed snmp timeout (introduced in 6.34.5);
      *) vrrp - fixed missing vrrp interfaces after upgrade (introduced in 6.34.5).
      Что нового в версии 6.34.5 (2016-May-27 11:52):

      *) dude - (http://wiki.mikrotik.com/wiki/Manual:The_Dude_v6/dude_v6.xx_changelog);
      *) dude - in order to connect to dude server user requires dude policy to be enabled;
      *) bonding - do not corrupt bonding statistics on configuration changes;
      *) bonding - fixed crash when vlan parent mtu is higher than bonding mtu;
      *) cloud - do not write minor status changes to storage;
      *) ethernet - do not allow mtu to be higher than l2mtu and l2mtu to be higher than max-l2mtu (reduce automatically on upgrade if it was wrong before);
      *) ipsec - better flush on proposal change;
      *) ipsec - fixed crash on policy update;
      *) log - fixed reboot log messages;
      *) lte - do not allow to set multiple modes when it is not supported;
      *) queue - fixed interface queue type for ovpn tunnels;
      *) rb3011 - fixed port flapping on ether6-ether10;
      *) rb3011 - fixed time keeping;
      *) switch - fixed compact export;
      *) tile - fixed performance regression on switch chip (introduced in 6.33rc18);
      *) winbox - show voltage in Health only if there actually is voltage monitor;
      *) wireless - fixed issue when CAPsMAN could lock CAPs interface;
      Что нового в версии 6.32.4 (2016-Feb-09 09:17):

      Содержит все соответствующие исправления, которые были подтверждены до v6.34 release.

      *) address-list - properly remove unused address-lists from drop-downs;
      *) arp - show incomplete ARP entries;
      *) bridge - fixed power-cycle-ping for bridge ports (was affecting all bridge);
      *) bridge firewall - fixed crash when jump rule points to disabled custom chain;
      *) btest - fix potential crash after btest release;
      *) btest - improve UDP tx rate precision;
      *) crypto - fixed kernel failure in talitos HW encryption;
      *) dhcpv6-client - fix DNS address assignement;
      *) dhcpv6-client - set correct parameters when rapid commit is used
      *) e-mail - do not reset server address after changing configuration;
      *) email - make password field sensitive in console.
      *) ethernet - fixed link resetting on power-cycle-ping value change;
      *) fastpath - fixed possible kernel failure on multi core systems;
      *) fastpath - show fp counters in /interface monitor aggregate;
      *) fetch - added 30 second connection time-out;
      *) fetch - fixed closure after 30 seconds;
      *) hotspot - added missing favicon.ico in hotspot html pages;
      *) hotspot - fixed missing image at login;
      *) ipsec - fixed kernel failure after underlying tunnel has been disabled/enabled;
      *) kernel - general improvement for core process scheduling;
      *) lcd - fixed LCD crash on fast disable/enable;
      *) lcd - refresh LCD after display command is executed;
      *) led - add WLAN led to RB951Ui
      *) log - log link up/down events only when link actually has changed its state;
      *) log - reopen log file if deleted;
      *) lte - improve support Sierra Wireless 320U;
      *) lte - speed up first time connection to LTE network on SXT LTE;
      *) net - apply slave config only if master config has been changed;
      *) net - do not show L2MTU in VLAN compact export;
      *) netinstall - fix branding pack parsing;
      *) netwatch - make work with ping time-out more precise;
      *) packages - show version tag when no bundle is installed.
      *) packing - fix tcp/udp checksums when simple packing is used;
      *) ppp - do not allow empty name ppp secrets;
      *) ppp - fixed dynamic filter rule adding on some firewall filter configurations;
      *) ppp - make PPP active print radius & !radius conditions work;
      *) romon - allow to see device identity if it is longer than 31 character;
      *) romon - do not accept multicast id;
      *) romon - fixed crash on RoMON if fast-path was active;
      *) smb - fix crash when changing user which has open session;
      *) smb - fixed SMB share crash when connection was cancelled;
      *) smb - show correct interface name in SMB debug logs;
      *) ssh - avoid double session clean-up;
      *) ssh - fix active user accounting;
      *) ssh - fix key exchange when first kex packet follows.
      *) ssh - fix session clean-up;
      *) sshd - resolved shared secret mismatch issue;
      *) tile - fix ipsec freeze after SA updates;
      *) tile - fixed kernel failure on HW encryption;
      *) upnp - fixed memory leak;
      *) upnp - fixed missing in-interface option for dynamic dst-nat rules;
      *) vrrp - allow VRRP to work behind firewall and NAT rules;
      *) vrrp - do not warn about version mismatch if VRID does not match;
      *) vrrp - fix arp=reply-only;
      *) vrrp - fix enabling disabled vrrp interface when vrrp program has exited;
      *) vrrp - fixed on-backup script;
      *) vrrp - make sure that VRRP gets state on bootup;
      *) webfig - didn't show zero values in CRS ingress/egress VLAN translation rules;
      *) webfig - fixed firewall connection-bytes option;
      *) webfig - show correctly SFP Tx/Rx;
      *) winbox - added + & - to IGMP proxy MFC;
      *) winbox - allow to specify traffic-monitor threshold in k & M units + specify that those are bits;
      *) winbox - do not send any changes on OK button press if nothing has been changed;
      *) winbox - fixed tab names to correspond to console;
      *) winbox - fixed tab names to correspond to console;
      *) winbox - renamed power-cycle-ping-interval to power-cycle-ping-timeout;
      *) winbox - show dhcp server name in dhcp leases;
      *) winbox - show fast-path per interface counters;
      *) winbox - show only actual switch-cpu ports in switch setting combobox;
      *) winbox - show properly route-distinguisher for bgp vpn4;
      *) winbox/webfig - fixed version column ordering in ip neighbors list.
      Что нового в версии 6.32.3 (2015-Oct-19 11:13):

      *) switch - fixed CRS settings set back to defaults after a reboot;
      *) netinstall - include missing RB1200 drivers;
      *) firewall - fixed connection-rate matcher;
      *) ppp, pptp, l2tp, pppoe: fixed router dead locked if compression was enabled on link;
      *) quickset - create proper firewall rules when PPPoE is used for address acquisition;
      *) sstp - fixed kernel crash when other party started to fragment ppp packets in the middle;
      *) ippool6 - optimize same prefix acquisition;
      *) winbox - Shift+Ins & Shift+Del did not work in multi entry fields;
      *) winbox - allow to specify ipv6 address in traffic flow target;
      *) winbox - allow to specify eap-radius-accounting in CAPsMAN;
      *) winbox - allow to enter dns name in email server;
      *) ups - fix console oid print;
      *) tunnel - fix loopback keepalives on gre and ipip;
      *) pptp,l 2tp, sstp, pppoe: do not send data packets before we have negotiated connection with other
      side (happens on dial-on-demand interfaces), this brakes when connecting to other party servers;
      *) pptp, l2tp, sstp - make it work when add-default-route & dial-on-demand both are enabled;
      *) pptp, l2tp, sstp, pppoe clients - fixed problem where they failed to connect
      at startup and only reboot helped;
      *) nv2 - fixed kernel failure with frame size accounting;
      *) ovpn client - fixed crash when ovpn didn't receive it's ip address;
      *) lcd - fix slideshow for CCR1072, and possible sign issues for temperatures;
      *) winbox - make console notice correct screen size;
      *) ssh - allow to specify pass as argument for private key import;
      *) winbox - refetch hotspot walled garden hit counter;
      *) winbox - added client-connections & server-connections to web proxy status;
      *) cerm - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
      *) bgp - specific BGP networks were changed to different ones;
      *) cerm - allow export for all types except templates;
      *) wlan - update brazil-anatel country;
      *) winbox - fixed context menu actions to apply to all selected items;
      Что нового в версии 6.30.4 (Aug.25.15-12:59:46)

      *) bridge fastpath - fixed updating bridge FDB on receive (could cause TX traffic flooding on all bridge ports)
      *) bonding fastpath - fixed possible crash when bonding master was also a bridge port
      *) user-manager - fixed zoom for user-manager homepage when mobile devices used
      *) tool fetch - don't trim [t]ftp leading slashes
      *) conntrack - fixed problem with manual connection removal
      *) winbox - restrict change dynamic interface fields
      *) romon - fixed crash on SACKed tx segments
      *) route - fixed crash on removing route that was aggregated;
      *) ipsec - fixed crash in when gcm encryption was used
      *) ipsec - allow to set peer address as "::/0"
      *) ipsec - fixed empty sa-src address on acquire in tun mode
      *) ipsec - show proposal info in export ipsec section
      *) ipsec - preserve port wildcard when generating policy without port override
      *) ipsec - fix replay window, was accidently disabled since version 6.30;

      Что нового в версии 6.30.3 (2015-Jul-24 08:06):

      заводской выпуск

      known issue:
      *) Dynamic DNS servers can disappear when "allow-remote-requests" are not enabled
      Что нового в версии 6.30.2 (2015-Jul-22 11:17):

      *) pptp & l2tp - fixed problem where android client could not connect if
      both dns names were not provided (was broken since v6.30);
      *) lcd - fix crash (and 100% cpu usage) when interface gets removed from "stats-all" screen
      *) tool fetch - fix incomplete ftp download
      *) ipsec - fixed crash in when gcm encryption was used
      *) certificate manager - fixed memory leak
      *) traffic flow - fixed dynamic input/output interface reporting
      *) user-manager - fixed username was not shown in /tool user-manager user
      *) user-manager - fixed zoom for user-manager homepage when mobile devices used
      *) winbox - restrict reversed ranges in dst-port under firewall
      *) snmp - fix system scripts table
      *) quickset - fixed HomeAP mode

      известная проблема:
      *) Dynamic DNS servers can disappear when "allow-remote-requests" are not enabled
      Что нового в версии 6.30.1 (2015-Jul-14 11:22):

      *) quickset - fixed HomeAP mode;
      *) lte - Fixes bug that causes Sierra Wireless modems with LTE interface to change interface name;
      *) trafflow: fix in-interface reporting in flow;
      *) ipsec - disallow changing dynamic peer;
      *) quickset - crashes introduced in 6.30 fixed
      *) fixed :execute file=
      *) bonding: fix arp monitoring in active backup mode
      MAJOR CHANGES IN v6.47.10:
      ----------------------
      !) wireless - fixed all affecting 'FragAttacks' vulnerabilities (CVE-2020-24587, CVE-2020-24588, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147);
      ----------------------

      *) bonding - improved system stability when disabling/enabling bonding ports;
      *) branding - added option to upload custom files (newly generated branding package required);
      *) capsman - use proper units for "ap-tx-limit" and "client-tx-limit" parameters;
      *) console - do not clear environment values if any global variable is set;
      *) console - require "write+ftp" permissions for exporting configuration to file;
      *) console - updated copyright notice;
      *) crs3xx - added "/system swos" menu for CRS354 devices, should only be used after SwOS 2.13 release;
      *) crs3xx - fixed interface LEDs for QSFP+ and SFP+ interfaces on CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - improved 1Gbps Ethernet port group traffic forwarding for CRS354 devices;
      *) crs3xx - improved system stability when receiving large frames on CPU for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) defconf - fixed default configuration loading on LHG R;
      *) defconf - fixed default configuration loading on RBOmniTikPG-5HacD;
      *) dhcp - fixed link state checking for DHCP client;
      *) dude - fixed configuration menu presence on ARM64 devices;
      *) ethernet - improved system stability when receiving large VLAN tagged packets on IPQ4018/IPQ4019 devices;
      *) ipsec - fixed SA address parameter exporting;
      *) lte - fixed "earfcn" to band translation for "cell-monitor";
      *) ovpn - fixed route cache entry leak when establishing a new session;
      *) poe - do not perform PoE firmware upgrade procedure on RB960 and OmniTik devices without PoE out;
      *) ppp - do not fail "at-chat" command when issued on disabled PPP interface;
      *) ptp - improved management service stability when receiving bogus packets;
      *) quickset - prefer 5GHz interface for WiFi scan in CPE mode;
      *) rb4011 - fixed SFP+ port MTU setting after link state change;
      *) rb4011 - improved SFP+ port stability after boot-up;
      *) route - improved stability when connected route is modified;
      *) sfp - improved cable length monitoring as defined per SFF-8472 and SFF-8636;
      *) supout - fixed "topic" column presence in "Log" section;
      *) switch - improved system stability with 98PX1012 switch chip for CCR2004-1G-12S+2XS device;
      *) system - improved resource allocation (improves several service stability e.g. HTTPS, PPPoE, VPN);
      *) telnet - do not send options if connecting to non standard port;
      *) telnet - fixed server when run on non standard port;
      *) tile - fixed bridge performance degradation (introduced in v6.47);
      *) tr069-client - improved management service stability when receiving bogus packets;
      *) upgrade - improved "long-term" upgrade procedure on SMIPS devices;
      *) webfig - allow to specify "prefix" parameter under "IPv6/ND/Prefixes" menu;
      *) webfig - do not corrupt settings when starting "Wireless Sniffer";
      *) webfig - do not move top right menu in opposite direction when scrolling horizontally;
      *) webfig - show "network-mode" for LTE modems that support it;
      *) winbox - do not show "network-mode" parameter for LTE interfaces that do not support it;
      *) winbox - do not show empty "CPU Frequency" parameter under "System/Resources" menu;
      *) winbox - fixed "reachable-time" value unit under "IPv6/ND" menu;
      *) winbox - fixed QCA-8511 switch chip type reporting under "Switch/Settings" menu;
      *) winbox - fixed health reporting on RB960, hEX and hEX S devices;
      *) winbox - hide "Allow Roaming" parameter on LTE modems that do not support it;
      *) winbox - increased "target" field limit to 128 under "Queues" menu;
      *) winbox - show "LCD" only on boards that have LCD;
      *) winbox - show "System/Health" only on boards that have health monitoring;
      *) winbox - show "activity" column by default under "IP/Kid Control/Devices" menu;
      *) wireless - fixed issue with multicast traffic delivery to client devices using power-save;
      *) wireless - improved iOS compatibility with HotSpot 2.0 networks;
      *) www - added "X-Frame-Options" header information to disallow website embedding in other pages
      Changes since 6.47.8:

      *) bgp - fixed VPNV4 RD byte order;
      *) branding - fixed LCD logo loading from new style branding package;
      *) crs312 - fixed missing SwOS firmware on revision 2 devices;
      *) crs3xx - correctly filter packets by L2MTU size;
      *) crs3xx - improved system stability when receiving large frames for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (introduced in v6.47.5);
      *) defconf - fixed default configuration loading on RBcAP-2nD and RBwAP-2nD;
      *) hotspot - fixed "idle-timeout" usage with RADIUS authentication;
      *) hotspot - fixed special character parsing in "target" variable (CVE-2021-3014);
      *) package - do not include multiple The Dude packages in HDD installer;
      *) snmp - fixed "send-trap" functionality;
      *) webfig - fixed new interface addition;
      *) winbox - renamed IP protocol 41 to "ipv6-encap";
      *) winbox - show "System/Health" only on boards that have health monitoring;
      *) winbox - use health values reported by gauges for "System/Health" menu;
      *) wireless - renamed "macedonia" regulatory domain information to "north macedonia";
      *) wireless - updated "indonesia5" regulatory domain information;
      *) crs312 - fixed missing SwOS firmware on revision 2 devices; *) crs3xx - fixed packet duplication when multiple bonding interfaces are created for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - fixed port-isolation on ether37-ether48 ports for CRS354 device; *) crs3xx - improved load balancing on bonding interfaces for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices; *) crs3xx - improved system stability when bonding and IGMP snooping is used (introduced in v6.48); *) hotspot - fixed "idle-timeout" usage with RADIUS authentication; *) hotspot - fixed special character parsing in "target" variable (CVE-2021-3014); *) ike2 - fixed phase 2 rekeying with enabled PFS (introduced in v6.48); *) ike2 - improved stability when invalid certificate is configured (introduced in v6.48); *) ike2 - properly register packet time after expensive CPU operations; *) interface - fixed pwr-line interface linking (introduced in v6.48); *) ipsec - improved stability when processing IPv6 packets larger than interface MTU; *) led - fixed default LED configuration for RB911-5HnD; *) package - do not include multiple The Dude packages in HDD installer; *) snmp - fixed "send-trap" functionality (introduced in v6.48); *) switch - fixed interface toggling for devices with multiple QCA8337, Atheros8327 or RTL8367 switch chips (introduced in v6.48); *) winbox - fixed enable/disable button presence for "Bridge/Hosts" menu; *) wireless - renamed "macedonia" regulatory domain information to "north macedonia";
      Что нового в версии 6.48 (2020-Dec-22 11:20):

      *) arm - added support for automatic CPU frequency stepping for IPQ4018/IPQ4019 devices;
      *) arm - improved system stability;
      *) arm - improved watchdog and kernel panic reporting in log after reboots on IPQ4018/IPQ4019 devices;
      *) arm64 - improved reboot reason reporting in log;
      *) bgp - fixed VPNV4 RD byte order;
      *) bonding - added LACP monitoring;
      *) branding - fixed LCD logo loading from new style branding package;
      *) bridge - added "multicast-router" monitoring value for bridge interface;
      *) bridge - added fixes and improvements for IGMP and MLD snooping;
      *) bridge - added minor fixes and improvements for IGMP snooping with HW offloading;
      *) bridge - added warning message when port is disabled by the BPDU guard;
      *) bridge - allow to exclude interfaces from extended ports;
      *) bridge - automatically remove extended interfaces when deleting PE device from CB;
      *) bridge - correctly filter packets by L2MTU size;
      *) bridge - correctly remove dynamic VLAN assignment for bridge ports;
      *) bridge - fixed "multicast-router" setting on bridge enable;
      *) bridge - fixed MDB entry removal when using bridge port "fast-leave" property;
      *) bridge - fixed dynamic VLAN assignment when changing port "frame-type" property (introduced in v6.46);
      *) bridge - fixed dynamic VLAN assignment when changing port to tagged VLAN member;
      *) bridge - fixed link-local multicast forwarding when IGMP snooping and HW offloading is enabled;
      *) bridge - fixed local MAC address removal from host table when deleting bridge interface;
      *) bridge - fixed multicast table printing;
      *) bridge - improved BPDU guard logging;
      *) bridge - increased multicast table size to 4K entries;
      *) bridge - show "H" flag for extended bridge ports;
      *) bridge - show error when switch do not support controlling bridge or port extension;
      *) bridge - use "frame-types=admit-all" by default for extended bridge ports;
      *) cap - fixed L2MTU setting from CAPsMAN;
      *) certificate - clear challenge password on renew;
      *) certificate - fixed CRL URL length limit;
      *) certificate - fixed private key verification for CA certificate during signing process;
      *) certificate - generate CRL even when CRL URL not specified;
      *) certificate - properly flush expired SCEP OTP entries;
      *) chr - fixed SSH key import on Azure;
      *) chr - fixed VLAN tagged packet transmit on bridge for Hyper-V installations;
      *) chr - improved interface loading on startup on XEN;
      *) chr - improved system stability when changing flow control settings on e1000;
      *) cloud - improved backup generation process;
      *) conntrack - automatically reduce connection tracking timeouts when table is full;
      *) console - allow "once" parameter for bonding monitoring;
      *) crs3xx - added initial Bridge Port Extender support;
      *) crs3xx - added initial Controlling Bridge support for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - added switch-cpu port VLAN filtering (switch-cpu port is now mapped with bridge interface VLAN membership when vlan-filtering is enabled);
      *) crs3xx - correctly filter packets by L2MTU size;
      *) crs3xx - fixed "custom-drop-packet" and "not-learned" switch stats for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - fixed "mirror-source" property on switch port disable for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices;
      *) crs3xx - fixed "storm-rate" traffic limiting for switch-cpu port on CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - fixed "switch-cpu" VLAN membership on bridge disable;
      *) crs3xx - fixed CDP packet forwarding for CRS305, CRS318, CRS326-24G-2S+, CRS328 devices;
      *) crs3xx - fixed duplicate host entries when creating static switch hosts;
      *) crs3xx - fixed port isolation for "switch-cpu" port for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices;
      *) crs3xx - fixed port isolation removal for "switch-cpu" port on CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - fixed switch "copy-to-cpu" property for CRS305, CRS318, CRS326-24G-2S+, CRS328 devices;
      *) crs3xx - fixed switch "not-learned" stats for CRS305, CRS326-24G-2S+, CRS328-24P-4S+, CRS328-4C-20S-4S+, CRS318 devices;
      *) crs3xx - improved system stability on CRS354 devices;
      *) crs3xx - improved system stability when receiving large frames for CRS317, CRS309, CRS312, CRS326-24S+2Q+ and CRS354 devices (introduced in v6.47.5);
      *) defconf - fixed default configuration loading on RBcAP-2nD and RBwAP-2nD;
      *) defconf - fixed static IP address setting in case default configuration loading fails;
      *) defconf - improved CAP interface bridging;
      *) defconf - improved default configuration generation on devices with non-default wireless interface names;
      *) detnet - fixed malformed dummy DHCP User Class option;
      *) detnet - use MAC address from bridge interface instead of slave port;
      *) dhcp - fixed DHCP packet forwarding to IPsec policies;
      *) dhcpv4-server - improved "client-id" value parsing;
      *) dhcpv6 server - added support for "Delegated-IPv6-Prefix" for PPP services;
      *) dhcpv6-server - added ability to generate binding on first request;
      *) dhcpv6-server - added support for "option18" and "option37" for RADIUS managed clients;
      *) dhcpv6-server - allow loose static binding "pool" parameter (introduced in v6.46.8);
      *) dhcpv6-server - make sure that calling station ID always contains DUID;
      *) discovery - added "lldp-med-net-policy-vlan" property for assigning VLAN ID;
      *) discovery - allow choosing which discovery protocol is used;
      *) discovery - fixed discovery on mesh ports;
      *) discovery - fixed discovery packet sending on newly bridged port with "protocol-mode=none";
      *) discovery - fixed discovery when enabled only on master port;
      *) discovery - send the same "Chassis ID" on all interfaces for LLDP packets;
      *) discovery - use interface MAC address when sending MNDP from slave port;
      *) disk - fixed external EXT3 disk mounting on x86 systems;
      *) dns - added IPv6 support for DoH;
      *) dns - do not use type "A" for static entries with unspecified type;
      *) dns - end ongoing queries when changing DoH configuration;
      *) dns - fixed listening for DNS queries when only dynamic static entries exist (introduced in v6.47);
      *) dot1x - accept priority tagged (VLAN 0) EAP packets on dot1x client;
      *) dot1x - fixed reauthentication after server rejects a client into VLAN;
      *) dot1x - fixed unicast destination EAP packet receiving when a client is running on a bridge port;
      *) dude - fixed configuration menu presence on ARM64 devices;
      *) export - fixed RouterBOARD USB "type" parameter export;
      *) filesystem - fixed repartition on RB4011 series devices;
      *) filesystem - fixed repartition on non-first partition;
      *) filesystem - improved long-term filesystem stability and data integrity;
      *) gps - fixed "init-channel" release when not used;
      *) health - changed PSU state parameter type to read-only;
      *) health - removed unused "heater-control" and "heater-threshold" parameters;
      *) hotspot - added "vlan-id" parameter support for hosts and HTML pages;
      *) hotspot - added support for captive portal advertising using DHCP (RFC7710);
      *) hotspot - fixed "html-directory" parameter export;
      *) hotspot - improved management service stability when receiving bogus packets;
      *) ike1 - fixed "my-id=address" parameter usage together with certificate authentication;
      *) ike1 - fixed 'rsa-signature-hybrid' authentication method;
      *) ike1 - fixed memory leak on multiple CR payloads;
      *) ike1 - fixed policy update with and without mode configuration;
      *) ike1 - rekey phase 1 as responder for Windows initiators;
      *) ike2 - added "prf-algorithm" support for phase 1;
      *) ike2 - added support for IKEv2 Message Fragmentation (RFC7383);
      *) ike2 - fixed EAP MSK length validation;
      *) ike2 - fixed too small payload parsing;
      *) ike2 - improved EAP message integrity checking;
      *) ike2 - improved child SA rekeying process;
      *) interface - added temperature warning and interface disable on overheat for SFP and SFP+ interfaces (CLI only);
      *) interface - fixed pwr-line running state (introduced in v6.45);
      *) ipsec - added SHA384 hash algorithm support for phase 1;
      *) ipsec - do not kill connection when peer's "name" or "comment" is changed;
      *) ipsec - fixed client certificate usage when certificate is renewed with SCEP;
      *) ipsec - fixed multiple warning message display for peers;
      *) ipsec - inactivate peer's policy on disconnect;
      *) ipsec - refresh peer's DNS only when phase 1 is down;
      *) kidcontrol - allow creating static device entries without assigned user;
      *) led - fixed state persistence after device reboot on NetMetal 5 ac devices;
      *) lora - fixed device going into "ERROR" state caused by FSK modulated downlinks;
      *) lora - limited output power in RU region for range 868.7 MHz - 869.2 MHz according to regulations;
      *) lte - added "age" column and "max-age" parameter to "cell-monitor" (CLI only);
      *) lte - added "comment" parameter for APN profiles;
      *) lte - added support for Alcatel IK41VE1;
      *) lte - fixed "band" value reporting;
      *) lte - increased "at+cops" reply timeout to 90 seconds;
      *) m33g - added support for "/system gpio" menu (CLI only);
      *) metarouter - allow creating RouterOS metarouter instances on devices with 16MB flash storage;
      *) metarouter - fixed memory leak when tearing down metarouter instance;
      *) ppp - added "bridge-learning" parameter support;
      *) ppp - added "ipv6-routes" parameter to "secrets" menu;
      *) ppp - added support for "Framed-IPv6-Route" RADIUS attribute;
      *) ppp - store "last-caller-id" for PPP secrets;
      *) ppp - store "last-disconnect-reason" for PPP secrets;
      *) profile - added "lcd" process classificator;
      *) profile - improved idle process detection on x86 processors;
      *) profile - improved process classification on ARM devices;
      *) quickset - added "Port Mapping" to QuickSet;
      *) quickset - fixed local IP address setting on master interface;
      *) route - improved stability when 6to4 interface is configured with disabled IPv6 package;
      *) routerboard - fixed PCIe bus reset during power-on on MMIPS devices ("/system routerboard upgrade" required);
      *) routerboard - force power-down on PCIe bus during reboot on LHGR devices ("/system routerboard upgrade" required);
      *) script - added error message in the logs if startup script runtime limit was exceeded;
      *) snmp - added information from IPsec "active-peers" menu to MIKROTIK-MIB;
      *) snmp - added new LTE monitoring OID's to MIKROTIK-MIB;
      *) snmp - fixed value types for "dot1dStp";
      *) snmp - fixed value types for "dot1qPvid";
      *) ssh - fixed returned output saving to file when "output-to-file" parameter is used;
      *) ssh - skip interactive authentication when not running in interactive mode;
      *) supout - added bonding interface monitor information;
      *) supout - improved autosupout.rif file generation process;
      *) timezone - updated timezone information from "tzdata2020d" release;
      *) tr069-client - added "X_MIKROTIK_MimoRSRP" parameter for LTE RSRP value reporting;
      *) tr069-client - added LTE model and revision parameters;
      *) tr069-client - added additional wireless registration table parameters;
      *) tr069-client - added branding package build time parameter;
      *) tr069-client - added wireless "noise-floor" and "overall-tx-ccq" information parameters;
      *) tr069-client - allow passing LTE firmware update URL as XML;
      *) tr069-client - fixed RouterOS downgrade procedure;
      *) tr069-client - fixed TotalBytesReceived parameter value;
      *) tr069-client - send correct "ConnectionRequestURL" when using IPv6;
      *) traffic-flow - added "sys-init-time" parameter support;
      *) traffic-flow - added NAT event logging support for IPFIX;
      *) traffic-generator - fixed 32Gbps limitation;
      *) user-manager - do not allow creating limitation that crosses midnight;
      *) user-manager - updated PayPal's root certificate authorities;
      *) webfig - allow hiding QuickSet mode selector;
      *) webfig - allow hiding and renaming inline buttons;
      *) webfig - fixed default value presence when creating new entries under "IP/Kid Control";
      *) webfig - properly stop background processes when switching away from QuickSet tab;
      *) winbox - added "src-mac-address" parameter under "IP/DHCP-Server/Leases" menu;
      *) winbox - added missing IGMP Snooping settings to "Bridge" menu;
      *) winbox - added missing MSTP settings to "Bridge" menu;
      *) winbox - added support for LTE Cell Monitor;
      *) winbox - allow adding bonding interface with one slave interface;
      *) winbox - allow performing "USB Power Reset" on "0" bus on RBM33G;
      *) winbox - do not show "network-mode" parameter for LTE interfaces that do not support it;
      *) winbox - fixed "IP->Kid Control->Devices" table automatic refreshing;
      *) winbox - fixed "interface" and "on-interface" parameter presence under "Bridge/Hosts" menu;
      *) winbox - fixed "receive-errors" setting persistence under "Wireless/Wireless Sniffer/Settings" menu;
      *) winbox - fixed "tls-version" parameter setting under "IP/Services" menu;
      *) winbox - fixed minor typo in "Users" menu;
      *) winbox - provide sane default values for bridge "VLAN IDs" parameter;
      *) winbox - use health values reported by gauges for "System/Health" menu;
      *) wireless - added U-NII-2 support for US and Canada country profiles for mANTBox series devices;
      *) wireless - create "connect-list" rule when address specified for "setup-repeater";
      *) wireless - do not override MTU and ARP values from CAPsMAN with local forwarding;
      *) wireless - improved WPS process stability;
      *) wireless - increased "group-key-update" maximum value to 1 day;
      *) wireless - updated "indonesia5" regulatory domain information;
      *) wireless - updated "no_country_set" regulatory domain information;
      Что нового в версии 6.47.8 (2020-Nov-25 10:10):

      *) arm - improved system stability;
      *) bgp - treat route target with AS 65535 as two byte AS;
      *) branding - fixed imported skin presence;
      *) bridge - fixed BPDU guard port disable/enable on HW offloaded interfaces;
      *) disk - improved disk management service stability when receiving bogus packets;
      *) dns - improved stability with large table of static records;
      *) ike1 - allow using "my-id" parameter with XAuth;
      *) leds - fixed LED type setting;
      *) metarouter - fixed directory entry reporting;
      *) profile - fixed process classification on x86 systems (introduced in v6.47);
      *) quickset - fixed wireless client "uptime" counter in "Home Mesh" mode;
      *) sstp - fixed "idle-timeout" on TILE and CHR devices;
      *) system - replace "3" in superscript to "^3" on RBD53GR devices;
      *) upgrade - do not try installing packages if download was not completed;
      *) winbox - added "operator" parameter under "Interface/LTE" menu;
      *) winbox - added "reformat-hold-button-max" parameter under "System/RouterBOARD/Settings" menu;
      *) winbox - added "tls-mode" parameter under "CAPsMAN/Security Cfg." menu;
      *) winbox - added "tx-rx-1024-max" counter under "Interface/Overall-Stats" for CRS3xx devices;
      *) winbox - do not allow MAC address changes on LTE interfaces;
      *) winbox - show "System/Health" only on boards that have health monitoring;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) winbox - show "usb-bus" option on all boards that have it;
      *) winbox - show "usb-type" option on all boards that have it;
      *) winbox - sort IPv6 firewall "chain" parameter entries alphabetically;
      *) wireless - added support for U-NII-2 US and Canada country profiles for mANTBox series devices;
      Что нового в версии 6.47.7 (2020-Oct-27 13:27):

      *) crs3xx - improved system stability on CRS354 devices;
      *) defconf - improved default configuration generation on devices without wireless package installed;
      *) poe - fixed automatic PoE firmware upgrade procedure;
      *) poe - improved PoE-out status detection;
      *) wireless - updated "kazakhstan" regulatory domain information;
      Что нового в версии 6.47.6 (2020-Oct-21 10:41):

      *) cap - fixed L2MTU path discovery;
      *) crs3xx - fixed hardware offloaded LACP bonding on Ethernet interfaces for CRS354 devices;
      *) crs3xx - fixed switch rules for CRS309 and CRS317 devices (introduced in v6.47.3);
      *) defconf - fixed default configuration loading on RBmAP-2nD;
      *) dhcpv4-client - fixed DHCP offer packet parsing with overload option present;
      *) dhcpv6-server - properly save bindings when executing "make-static" command;
      *) fetch - improved SSL handshake processing;
      *) ike1 - allow using "my-id" parameter with XAuth;
      *) leds - fixed LED type setting;
      *) lora - expose "joinEui" un "devEui" values in the log;
      *) lte - fixed multiple APN passthrough on R11e-4G;
      *) lte - improved EARFCN reporting in 3G and LTE modes on Sierra modems;
      *) lte - limit allowed APN count to 3 on R11e-LTE;
      *) mpls - fixed duplicate "LabelRelease" message sending;
      *) ospf - optimized LSA printing for smaller message sizes;
      *) radius - added "Service-Type" attribute to Access-Request for IPv4 and IPv6 DHCP servers;
      *) smips - reduced RouterOS main package size;
      *) switch - fixed Ethernet padding for small packets;
      *) user - improved WinBox and The Dude authenticated session handling;
      *) vrrp - made "password" parameter sensitive;
      *) w60g - general stability and performance improvements;
      *) wireless - added support for US FCC UNII-2 and Canada country profiles for NetMetal series devices;
      *) wireless - fixed incorrect wireless capability information in association response frames;
      Что нового в версии 6.47.5 (2020-Oct-08 06:48):

      (factory only release)
      Что нового в версии 6.47.4 (2020-Sep-16 11:32):

      *) bridge - fixed STP alternate and backup port states for devices with switch chip (introduced in v6.47);
      *) crs3xx - fixed IGMP snooping for CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - fixed switch port "egress-rate" removal for CRS305, CRS326-24G-2S+, CRS328, CRS318 devices;
      *) fetch - fixed "src-address" usage for SFTP;
      *) filesystem - improved long-term filesystem stability and data integrity;
      *) hotspot - ignore packets from host while MAC authentication is in progress;
      *) kidcontrol - fixed "time-unlimited-rate" to engage in correct time;
      *) smb - fixed possible memory leak (CVE-2020-11881);
      *) sms - fixed SMS sending when both "interface" and "smsc" parameters are specified;
      *) snmp - fixed "/tool snmp-get" functionality (introduced in v 6.46beta43);
      *) user-manager - updated PayPal's root certificate authorities;
      *) wireless - added support for U-NII-2 for wAP ac;
      *) wireless - updated "canada" regulatory domain information;
      *) wireless - updated "united states" regulatory domain information;
      Что нового в версии 6.47.3 (2020-Sep-01 05:24):

      *) bridge - fixed host table update on SNMP query;
      *) crs3xx - fixed hardware offloaded bonding on Ethernet interfaces for CRS354 devices;
      *) crs3xx - fixed hardware offloaded MPLS forwarding when using bonding interfaces;
      *) crs3xx - fixed switch ACL rules for CRS312, CRS326-24S+2Q+ and CRS354 devices;
      *) crs3xx - improved Ethernet port group traffic forwarding for CRS354 devices;
      *) crs3xx - improved system stability when using hardware offloaded MPLS;
      *) dns - fixed multiple TXT string replies;
      *) dns - hide default static entry "type" from export;
      *) dot1x - fixed duplicate EAP request packets for server;
      *) dot1x - fixed EAP packet version numbering;
      *) ike2 - fixed local side NAT detection;
      *) lte - fixed multiple passthrough APN default route installation;
      *) lte - fixed RSCP value reporting;
      *) lte - validate interface existence on initiation;
      *) ospf - fixed disappearing NSSA default route;
      *) ospf - fixed processing of "unknown" LSA type;
      *) poe - fixed "power-cycle" functionality on RB960GSP;
      *) routerboot - fixed etherboot FCS errors with 100Mbps rate for CRS305, CRS309 and CRS317 devices ("/system routerboard upgrade" required);
      *) webfig - fixed negative value usage in "spoof-gps" parameter (introduced in v6.47.1);
      *) wireless - allow setting "tx-power" up to 40;
      *) wireless - fixed potential wireless driver issue related to CVE-2020-3702;
      Что нового в версии 6.47.2 (2020-Aug-13 06:39):

      *) arm - improved stability when forcing 25G speed on unsupported interface;
      *) crs3xx - fixed QSFP+ interface LEDs when using break-out cable for CRS326-24S+2Q+;
      *) crs3xx - fixed QSFP+ interface linking after reboot for CRS326-24S+2Q+ (introduced in v6.47);
      *) discovery - use "static" interface list by default instead of "!dynamic";
      *) fetch - show status "uploaded" instead of "downloaded" when uploading a file;
      *) hotspot - do not verify Hotspot interface status when detecting if HTTP/HTTPS login method is allowed;
      *) interface - added new builtin "static" interface list;
      *) l2tp - fixed multiple tunnel establishment from the same remote IP address (introduced in v6.47);
      *) lora - fixed "spoof-gps" parameter padding (introduced in v6.47.1);
      *) lte - fixed dynamic DHCP client creation when editing APN profile;
      *) ospf - fixed case when changing one distribution metric changed metrics for other distribution options;
      *) ppp - fixed PPP interface editing for the first time after reboot or after 20 seconds;
      *) qsfp - fixed break-out cable linking after reboot (introduced in v6.47);
      *) routerboot - fixed memory test on CCR2004-1G-12S+2XS ("/system routerboard upgrade" required);
      *) sfp - stabilized CRS212 SFP port functionality and improved monitoring of optical modules;
      *) sftp - fixed "flash" directory access (introduced in v6.46);
      *) smb - fixed file path validation (introduced in v6.46);
      *) smb - fixed possible memory leak;
      *) smb - fixed SMB server (introduced in v6.47);
      *) smb - limit active session count to 5 per connection;
      *) snmp - fixed "current" value reporting on CCR series devices;
      *) snmp - fixed "fan-speed" value reporting on CCR series devices;
      *) wireless - added support for U-NII-2 for cAP ac;
      *) wireless - updated "indonesia5" regulatory domain information;
      *) www - improved WWW service stability when receiving bogus packets;
      Что нового в версии 6.47.1 (2020-Jul-08 12:34):

      *) crs3xx - fixed HW offloading for netPower 15FR and netPower 16P devices (introduced in v6.47);
      *) crs3xx - fixed increased CPU temperature for CRS354-48G-4S+2Q+ device (introduced in v6.47);
      *) crs3xx - improved Ethernet port group traffic forwarding for CRS354 devices;
      *) defconf - fixed default configuration generation on devices without "wireless" package installed;
      *) defconf - fixed default configuration loading on RBmAPL-2nD;
      *) defconf - improved default configuration generation on devices with changed wireless interface names;
      *) dhcpv6-server - disallow changing binding's "prefix-pool";
      *) dhcpv6-server - improved stability when changing server for static bindings;
      *) dns - do not allow setting "forward-to" same as "name" or "regex";
      *) dns - do not allow setting zero value IP addresses for "A" and "AAAA" records;
      *) dns - do not use DoH for local queries when a server is specified;
      *) export - fixed HotSpot "address-per-mac" parameter export;
      *) filesystem - fixed increased "sector writes" reporting (introduced in v6.47);
      *) ftp - fixed possible buffer overflow;
      *) ike2 - fixed initiator child SA init without policy;
      *) ike2 - fixed policy reference for pending acquire;
      *) ike2 - retry RSA signature validation with deduced digest from certificate;
      *) ipsec - do not update peer endpoints for generated policy entries (introduced in v6.47);
      *) lora - added "spoof-gps" parameter for fake GPS coordinate sending;
      *) lora - fixed JSON statistics inaccuracies;
      *) lte - added support for MTS 8810FT;
      *) lte - fixed modem initialization when multiple modems are used simultaneously;
      *) lte - fixed PDP authentication configuration for SIM7600;
      *) metarouter - fixed image importing (introduced in v6.46);
      *) ospf - improved route tag processing for OSPFv3;
      *) ppp - allow specifying pool name for "remote-ipv6-prefix-pool" parameter;
      *) profile - fixed "unclassified" load reporting on PowerPC devices (introduced in v6.47);
      *) qsfp - fixed auto-negotiation status;
      *) qsfp - ignore FEC mode when set to fec91, only fec74 mode is supported (introduced in v6.47);
      *) routerboard - fixed "mode-button" support on SMIPS devices (introduced in v6.47);
      *) routerboard - fixed "reset-button" menu presence on all devices;
      *) supout - added "LoRa" section to supout file;
      *) switch - fixed MAC address learning on switch-cpu port for Atheros8316, Atheros8227 and Atheros7240 switch chips;
      *) w60g - added "mdmg-fix" parameter for RBwAP60Gx3 (CLI only);
      *) winbox - fixed flag displaying under "IP/DNS/Static" table;
      *) winbox - fixed minor typo in "BGP/Peer" menu;
      *) winbox - hide irrelevant switch port parameters;
      *) wireless - changed "station-roaming" default setting from "enabled" to "disabled";
      *) wireless - updated "bangladesh" regulatory domain information;
      *) wireless - updated "egypt" regulatory domain information;
      Что нового в версии 6.47 (2020-Jun-02 07:38):

      Важная заметка!!!

      - The Dude server must be updated to monitor v6.46.4 and v6.47beta30+ RouterOS type devices.
      - The Dude client must be manually upgraded after upgrading The Dude server.
      - The Dude requires "winbox" policy instead of "dude" to monitor v6.46.4 and v6.47beta30+ RouterOS type devices.
      - Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used.

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.47:
      ----------------------
      !) dns - added client side support for DNS over HTTPS (DoH) (RFC8484);
      !) socks - added support for SOCKS5 (RFC 1928);
      !) user - enable "winbox" policy for groups with "dude" policy automatically on upgrade;
      ----------------------

      Изменения в этом выпуске:

      *) api - added ECDHE cipher support for "api-ssl" service;
      *) bonding - improved slave interface MAC address handling;
      *) bonding - prefer primary slave MAC address for bonding interface;
      *) branding - do not ask to confirm configuration applied from branding package;
      *) branding - fixed identity setting from branding package;
      *) branding - improved branding package installation process when another branding package is already installed;
      *) bridge - added logging debug message when a host MAC address is learned on a different bridge port;
      *) bridge - added warning message when a bridge port gets dynamically added to VLAN range;
      *) bridge - correctly remove disabled MSTI;
      *) bridge - improved hardware offloading enabling/disabling;
      *) certificate - added "skid" and "akid" values for detailed print;
      *) certificate - allow dynamic CRL removal;
      *) certificate - disabled CRL usage by default;
      *) certificate - do not use SSL for first CRL update;
      *) chr - added support for file system quiescing;
      *) chr - added support for hardware watchdog on ESXI;
      *) chr - enabled support for VMBus protocol version 4.1;
      *) chr - improved system stability when running CHR on Hyper-V;
      *) crs3xx - correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices;
      *) crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
      *) crs3xx - fixed hardware offloaded bonding on Ethernet interfaces for CRS354 devices;
      *) crs3xx - improved 10G interface initialization on CRS312 devices;
      *) crs3xx - improved switch host table updating;
      *) crs3xx - show correct switch model for netPower 15FR device;
      *) defconf - fixed default configuration initialization if power loss occurred during the process;
      *) dhcpv4 - added end option (255) validation for both server and client;
      *) dhcpv4-client - improved stability when changing client while still receiving advertisements;
      *) dhcpv4-server - disallow zero lease-time setting;
      *) dhcpv6-client - improved error logging when when renewed address differs;
      *) dhcpv6-server - do not require "server" parameter for bindings;
      *) dhcpv6-server - fixed MAC address retrieving from DUID when timestamp is present;
      *) discovery - do not send discovery packets on inactive bonding slave interfaces;
      *) discovery - do not send discovery packets on interfaces that are blocked by STP;
      *) disk - improved disk management service stability when receiving bogus packets;
      *) disk - improved recently created file survival after reboots;
      *) dns - added support for exclusive dynamic DNS server usage from IPsec;
      *) dns - added support for forwarding DNS queries of static entries to specific server;
      *) dns - added support for multiple type static entries;
      *) dot1x - added "radius-mac-format" parameter;
      *) dot1x - added hex value support for RADIUS switch rules;
      *) dot1x - added range "dst-port" support for RADIUS switch rules;
      *) dot1x - added support for lower case "mac-auth" RADIUS formats;
      *) dot1x - fixed "reject-vlan-id" value range;
      *) dot1x - fixed dynamically created switch rule removal when client disconnects;
      *) dot1x - fixed port blocking when interface changes state from disabled to enabled;
      *) dot1x - improved Dot1X service stability when receiving bogus packets;
      *) dot1x - improved debug logging output to "dot1x" topic;
      *) dot1x - improved value validation for dynamically created switch rules;
      *) email - added support for multiple "to" recipients;
      *) ethernet - fixed interface stopping responding after blink command execution on CCR2004-1G-12S+2XS;
      *) fetch - fixed "User-Agent" usage if provided by "http-header-field";
      *) graphing - improved graphing service stability when receiving bogus packets;
      *) health - added "gauges" submenu with SNMP OID reporting;
      *) health - improved stability for system health monitor on CCR2004-1G-12S+2XS;
      *) hotspot - updated splash page design ('/ip hotspot reset-html' required);
      *) ike1 - added error message when specifying "my-id" for XAuth identity;
      *) ike1 - added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes;
      *) ike1 - do not try to keep phase 2 when purging phase 1;
      *) ike1 - improved policy lookup with specific protocol;
      *) ike1 - improved stability when performing policy lookup on non-existant peer;
      *) ike2 - added support for "INTERNAL_DNS_DOMAIN" payload attribute;
      *) ike2 - added support for RADIUS Disconnect-Request message handling;
      *) ike2 - added support for RFC8598;
      *) ike2 - allow initiator address change before authentication;
      *) ike2 - fixed authentication handling when initiator disconnects before RADIUS response;
      *) interface - improved system stability when receiving bogus packets;
      *) interface - increased loopback interface MTU to 65536;
      *) ipsec - added "split-dns" parameter support for mode configuration;
      *) ipsec - added "use-responder-dns" parameter support;
      *) ipsec - allow specifying two peers for a single policy for failover;
      *) ipsec - control CRL validation with global "use-crl" setting;
      *) ipsec - do full certificate validation for identities with explicit certificate;
      *) ipsec - fixed minor spelling mistake in logs;
      *) ipsec - improved IPsec service stability when receiving bogus packets;
      *) ipsec - place dynamically created IPsec policies by L2TP client at the begining of the table;
      *) kidcontrol - ignore IPv6 multicast MAC addresses;
      *) l2tp - added "src-address" parameter for L2TP client;
      *) l2tp - added "use-peer-dns" parameter for L2TP client;
      *) l2tp - improved dynamically created IPsec configuration updating;
      *) l2tp - use L2TP interface when adding dynamic IPsec peer;
      *) lcd - fixed LCD service becoming unavailable on devices without LCD screen;
      *) lcd - improved general system stability when LCD is not present;
      *) led - fixed minor typo in LED warning message;
      *) log - added logging entry when changing user's password;
      *) log - added tunnel endpoint address to establishment and disconnect logging entries;
      *) log - made startup script failures log as critical errors;
      *) lte - added support for Huawei K5161 modem;
      *) lte - added support for NEOWAY N720;
      *) lte - added support for multiple passthrough APN configuration;
      *) lte - do not allow running "scan" on R11e-4G;
      *) lte - fixed "allow-roaming" setting when using LTE network mode on R11e-LTE;
      *) lte - fixed "band" parameter persistence after disable/enable;
      *) lte - fixed "ecno" and "rscp" value reporting on R11e-LTE6;
      *) lte - fixed VLAN interface passthrough support;
      *) lte - fixed multiple APN reactivation after deactivation by operator;
      *) lte - improved stability during firmware upgrade;
      *) lte - made "mac-address" parameter read-only;
      *) lte - show "phy-cellid" value only in LTE mode;
      *) netinstall - removed "Flashfig" from Netinstall;
      *) netinstall - removed "Make Floppy" from Netinstall;
      *) netinstall - signed netinstall.exe with Digital Signature;
      *) netwatch - improved Netwatch service stability when invalid configuration values are passed;
      *) ovpn - added "use-peer-dns" parameter for OVPN client;
      *) port - removed serial console port on hEX S;
      *) ppp - added "Acct-Session-Id" attribute to "Access-Request" messages;
      *) ppp - added support for ZTE MF90;
      *) ppp - fixed minor typo when running "info" command;
      *) ppp - removed "comment", "set" and "edit" commands from "PPP->Active" menu;
      *) pptp - added "use-peer-dns" parameter for PPTP client;
      *) profile - added support for CCR2004-1G-12S+2XS;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) qsfp - added support for FEC mode (fec74), with the FEC mode disabled by default;
      *) quickset - do not show "SINR" field in Quick Set when there is no data;
      *) quickset - fixed invalid configuration applying when performing changes during LTE modem initialization process;
      *) quickset - removed "EARFCN" field from Quick Set;
      *) quickset - removed "LTE band" setting from Quick Set;
      *) quickset - show "Antenna Gain" setting on devices without built-in antennas;
      *) quickset - use "station-wds" mode when connecting to AP with RouterOS flag;
      *) route - improved system stability after reboot with large amount of VLAN interfaces with PPPoE servers attached;
      *) routerboard - added "hold-time" parameter to mode-button menu;
      *) routerboard - added "reset-button" menu - custom command execution with reset button;
      *) routing - improved IGMP-Proxy service stability when receiving bogus packets;
      *) routing - improved routing service stability when receiving bogus packets;
      *) sfp28 - added support for FEC modes (fec74 and fec91), with fec91 mode already enabled by default;
      *) sniffer - allow setting port for "streaming-server";
      *) snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB;
      *) snmp - changed "upsEstimatedMinutesRemaining" reported value from seconds to minutes;
      *) snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
      *) snmp - improved OID policy checking and error reporting on "set" command;
      *) snmp - improved stability when polling MAC address related OID;
      *) ssh - improved SSH service stability when receiving bogus packets;
      *) supout - added "dot1x" section to supout files;
      *) supout - improved UPS information reporting;
      *) switch - correctly display switch statistics when all switch ports are disabled on RTL8367 switch chip;
      *) switch - correctly enable and disable CPU Flow Control on RB3011UiAS;
      *) switch - made "auto" the default value for "vlan-id" parameter when creating a new static host entry;
      *) system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic;
      *) system - improved driver loading speed on startup;
      *) tr069-client - added LTE firmware update functionality support;
      *) tr069-client - added additional LTE information parameters;
      *) tr069-client - added additional wireless registration table parameters;
      *) tr069-client - added interface type parameter support;
      *) tr069-client - added multiple simultaneous session support for diagnostics test;
      *) tr069-client - added total connection tracking entries parameter;
      *) tr069-client - removed warning log message when not using HTTPS;
      *) traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and NetFlow v9;
      *) upgrade - fixed space handling in package file names;
      *) ups - added battery info for APC SmartUPS 2200;
      *) ups - improved compatibility with APC Smart UPS 1000 and 1500;
      *) user - improved user management service stability when receiving bogus packets;
      *) w60g - fixed link status logging;
      *) w60g - improved rate selection in low traffic conditions;
      *) w60g - use "arp" and "mtu" parameters from master interface when creating a new station;
      *) webfig - fixed 5 GHz wireless interface "frequency" parameter value list on Audience;
      *) webfig - fixed WinBox download link;
      *) webfig - fixed skin usage from branding package;
      *) webfig - updated icon design;
      *) winbox - added "Rate" parameter for switch ACL rules;
      *) winbox - added "auth-info" parameter under "Dot1X->Active" menu;
      *) winbox - added "auth-types", "comment", "mac-auth-mode" and "reject-vlan-id" parameters for Dot1X server;
      *) winbox - added "auto-erase" option to "Tool/SMS" menu;
      *) winbox - added "bus" parameter for "USB Power Reset" command on NetMetal ac^2;
      *) winbox - added "bus" parameter for "USB Power Reset" command on RBM33G;
      *) winbox - added "comment" parameter and "dynamic" flag support under "Switch->Rule" table;
      *) winbox - added "comment" parameter for Dot1X client;
      *) winbox - added "region" parameter for W60G interfaces;
      *) winbox - added "skip-dfs-channels" parameter to wireless interface menu;
      *) winbox - added comment support for "Switch->VLAN" menu;
      *) winbox - added enable and disable buttons for "MPLS->MPLS Interface" table;
      *) winbox - added support for inline bar graphs for LTE signal values;
      *) winbox - aligned all "IP->Traffic Flow->IPFIX" check boxes in single line (WinBox v3.22 required);
      *) winbox - allow setting "Primary" parameter for "balance-tlb" bonding interfaces;
      *) winbox - allow to specify any Ethernet like interface under "Tool/WoL" menu;
      *) winbox - do not allow to enter empty strings in "caps-man-names" and "common-name" parameters;
      *) winbox - fixed "BGP Origin" value display under "IPv6->Routes" menu;
      *) winbox - fixed "Data Rate" checkbox alignment (WinBox v3.22 required);
      *) winbox - fixed "Tx/Rx Signal Strength" value presence for 4 chain interfaces;
      *) winbox - fixed WDS usage when connecting to RouterOS access point using QuickSet;
      *) winbox - fixed bonding type interface support for "Switch->Host" table;
      *) winbox - fixed dates and times in interface link up/down properties (WinBox v3.24 required);
      *) winbox - fixed wireless interface "HT" tab setting presence when "band=5ghz-n/ac";
      *) winbox - fixed wireless sniffer parameter setting;
      *) winbox - limit number of simultaneous WinBox sessions to 5 for users without "write" permission;
      *) winbox - made "yes" the default value for "Inject Summary LSAs" parameter when creating a new NSSA or STUB area;
      *) winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "LoRa/Traffic";
      *) winbox - renamed "Routerboard" to "RouterBOARD" under "System/RouterBOARD" menu;
      *) winbox - show "Hardware Offload" parameter for bonding interfaces;
      *) winbox - updated icon design;
      *) wireless - added "russia 6ghz" regulatory domain information;
      *) wireless - enabled unicast flood for DHCP traffic on ARM architecture access points;
      *) wireless - fixed Nstreme wireless protocol performance decrease;
      *) wireless - improved management service stability when receiving bogus packets;
      *) wireless - updated "egypt" regulatory domain information;
      *) wireless - updated "russia4" regulatory domain information;
      *) www - added "tls-version" parameter in "IP->Services" menu;
      Что нового в версии 6.46.6 (2020-Apr-27 10:32):

      Важная заметка!!!

      - The Dude server must be updated to monitor v6.46.4+ and v6.47beta30+ RouterOS type devices.
      - The Dude client must be manually upgraded after upgrading The Dude server.
      - The Dude requires "winbox" policy instead of "dude" to monitor v6.46.4+ and v6.47beta30+ RouterOS type devices.

      Изменения в этом выпуске:

      *) crs3xx - fixed switch rule "dst-port" parameter for IPv6 traffic on CRS305-1G-4S+, CRS326-24G-2S+, CRS328-24P-4S+, CRS328-4C-20S-4S+, netPower 15FR devices;
      *) defconf - fixed default IP address assigning on non-paired 60 GHz devices;
      *) lora - added "altitude", "latitude" and "longitude" to stat json if GPS is available;
      *) lte - fixed "band" value setting when configuration is reset on R11e-4G;
      *) snmp - fixed "ifSpeed" reporting for tunnel interfaces;
      *) snmp - fixed multiple LTE interface OID reporting;
      *) ssh - fixed SHA256 user authentication algorithm checking (introduced in v6.46.4);
      *) winbox - fixed memory leak (introduced in v6.46.4);
      *) winbox - increased limit of multi-entry fields to 100;
      *) wireless - improved 5GHz interface stability on RB4011iGS+5HacQ2HnD and Audience;
      *) wireless - improved system stability on hAP ac^2;
      *) wireless - updated "south africa" regulatory domain information;
      Что нового в версии 6.46.5 (2020-Apr-07 08:28):

      Важная заметка!!!

      - The Dude server must be updated to monitor v6.46.4+ and v6.47beta30+ RouterOS type devices.
      - The Dude client must be manually upgraded after upgrading The Dude server.
      - The Dude requires "winbox" policy instead of "dude" to monitor v6.46.4+ and v6.47beta30+ RouterOS type devices.

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.46.5:
      ----------------------
      !) user - enable "winbox" policy for groups with "dude" policy;
      ----------------------

      Изменения в этом выпуске:

      *) capsman - fixed "certificate" parameter updating on CAP;
      *) console - prevent incorrect type interfaces appearing in command hints;
      *) crs3xx - fixed interface statistics for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices;
      *) crs3xx - fixed traffic forwarding after disabling/enabling bridge hardware offloading for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices;
      *) crs3xx - improved SFP+ DAC cable initialization for CRS326-24S+2Q+ device;
      *) discovery - do not send CDP and LLDP packets on interfaces that does not have MAC address;
      *) dude - fixed connection to other RouterOS type devices through The Dude agents (introduced in v6.46.4);
      *) ike1 - rekey phase 1 rekeying as responder for Windows initiators;
      *) ipsec - improved system stability when handling fragmented packets;
      *) led - added "dark-mode" functionality for CRS105-5S-FB;
      *) lora - added IPv6 support for LoRa packet forwarder;
      *) lora - added UTC timestamp for RX events in "rxpk" json;
      *) lora - added value limits for "freq-off" parameter;
      *) lora - properly update source address for packets when routing table is changed;
      *) lte - fixed IP type selection from APN on RBSXTLTE3-7;
      *) sniffer - fixed minor typo in "host" menu;
      *) supout - added "gps" section to supout files;
      *) supout - improved PoE-out information reporting;
      *) system - improved kernel panic reporting in logs after reboot;
      *) system - improved system stability when forwarding traffic from switch chip to CPU (introduced in v6.43);
      *) traceroute - improved stability when invalid packet is received;
      *) traffic-generator - improved statistics reporting;
      *) w60g - improved stability after multiple disconnections;
      *) winbox - added "Options" parameter support for DHCPv6 client and server;
      *) winbox - added 160Mhz extension channel support for CAPsMAN;
      *) winbox - added support for "Tools->WoL" menu;
      *) winbox - allow setting "20/40/80/160Mhz-eeeeeeCe" channel under "Channel Width" parameter;
      *) winbox - do not show "Revision" parameter under "System/RouterBOARD" menu on devices that have only one revision;
      *) winbox - fixed "ARP" parameter inheritance from "CAPs Configuration" configuration;
      *) winbox - fixed "Bands" parameter display for LTE interfaces;
      *) winbox - fixed "DSCP" parameter value setting;
      *) winbox - fixed "Frequency" and "Secondary Frequency" parameter inheritance from "CAPs Channel" configuration;
      *) winbox - fixed "Passthr. MAC Address" parameter display "LTE APNs" menu;
      *) winbox - fixed "Switch" menu on CRS354-48P-4S+2Q+;
      *) winbox - fixed "dst-port" unsetting in "IP->Hotspot->Walled Garden" menu;
      *) winbox - fixed automatic "IPv6->Firewall->Address List" table update;
      *) winbox - made "none" the default value for "Security Profile" parameter when creating a new "Wirelees->Connect list" entry;
      *) winbox - properly show "Hw. Offload Group" value for each interface under "Bridge->Ports" menu;
      *) winbox - renamed "Memory used" to "HDD used" for HDD type under "Tools->Graphing->Resource Graphs";
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) wireless - added "U-NII-2" support for hAP ac2 and RBwAPGR series devices;
      *) wireless - added "skip-dfs-channels" parameter;
      *) wireless - fixed default "antenna-gain" setting on SXT 2 and LtAP series devices;
      *) wireless - updated "bangladesh" regulatory domain information;
      *) wireless - updated "indonesia4" regulatory domain information;
      Что нового в версии 6.46.4 (2020-Feb-21 11:26):

      Важная заметка!!!

      - The Dude server must be updated to monitor 6.46.4 and v6.47beta30+ RouterOS type devices.
      - The Dude client must be manually upgraded after upgrading The Dude server.
      - To get RouterOS data from the devices, The Dude now requires RouterOS to be 6.46.4 or v6.47beta30+.

      Изменения в этом выпуске:

      *) arm - improved watchdog and kernel panic reporting in log after reboots on RB3011 and IPQ4018/IPQ4019 devices ("/system routerboard upgrade" required);
      *) branding - allow forcing configuration script as default configuration (new branding packet required);
      *) branding - fixed "company-url" and "router-default-name" survival after system upgrade;
      *) branding - fixed WEB HTML page survival after system upgrade;
      *) certificate - fixed certificate verification when flushing CRL's;
      *) chr - fixed graceful shutdown execution on Hyper-V (introduced in v6.46);
      *) console - fixed script with "dont-require-permissions=yes" execution without sufficient permissions;
      *) crs3xx - fixed frame forwarding after disabling/enabling bridge hardware offloading for CRS354-48G-4S+2Q+ device;
      *) defconf - added welcome note with common first steps for new users;
      *) dude - updated The Dude to use new style authentication method;
      *) health - fixed maximum SFP temperature reading under '/system health' menu;
      *) ike2 - fixed DHCP Inform package handling when received on PPPoE interface;
      *) lte - added interface name prefix for logging events;
      *) lte - added "phy-cellid" value support for R11e-LTE-US;
      *) lte - do not allow using empty APN Profile names;
      *) lte - improved all APN session activation after disconnect on R11e-LTE;
      *) lte - use APN from network when blank APN used on R11e-4G;
      *) snmp - fixed "routeros-version" value returning from registration table;
      *) snmp - fixed UPS battery voltage value scaling;
      *) ssh - added support for RSA keys with SHA256 hash (RFC8332);
      *) system - improved system stability when receiving/sending TCP traffic on multicore devices;
      *) telnet - improved telnet compatibility with other client implementations;
      *) user-manager - fixed signup enabling (introduced in v6.46);
      *) webfig - added default configuration confirmation window to WebFig;
      *) webfig - do not show WebFig menu when opening 'Check For Updates' in Quick Set;
      *) winbox - completely removed old style authentication method;
      *) winbox - fixed "invalid" flag presence under "System/Certificates/CRL" menu;
      *) wireless - improved compatibility for "ETSI" wireless country profile;
      Что нового в версии 6.46.3 (2020-Jan-28 10:46):

      *) hotspot - fixed redirect to log in page (introduced in v6.45);
      *) lora - added "ru-864-mid" channel plan;
      *) lora - improved immediate packet delivery;
      *) lte - added GPS port support for Quectel EP06 modem;
      *) lte - added "psc" (Primary Scrambling Code) parameter for "cell-monitor" function on R11e-LTE6 and R11e-LTE;
      *) lte - do not show invalid "phy-cellid" when it is not yet received on "R11e-LTE";
      *) lte - do not show unrelated info parameters after network mode failover;
      *) port - fixed multiple identical USB serial device detection (introduced in v6.46);
      *) ppp - fixed connection establishment when receiving "0.0.0.0" DNS;
      *) snmp - fixed "ifOperStatus" reporting for combo ports;
      *) winbox - removed duplicate "counter", "chain", "size" and "payload" parameters under "LoRa/Traffic";
      Что нового в версии 6.46.2 (2020-Jan-14 07:17):

      *) chr - improved stability when changing ARP modes on e1000 type adapters;
      *) console - prevent "flash" directory from being removed (introduced in v6.46);
      *) console - updated copyright notice;
      *) crs305 - disable optical SFP/SFP+ module Tx power after disabling SFP+ interface;
      *) defconf - fixed "caps-mode" not initialized properly after resetting;
      *) defconf - fixed default configuration loading on RBwAPG-60adkit (introduced in v6.46);
      *) lora - fixed packet sending when using "antenna-gain" higher than 5dB;
      *) lte - fixed "cell-monitor" on R11e-LTE in 3G mode;
      *) lte - fixed "earfcn" reporting on R11e-LTE6 in UMTS and GSM modes;
      *) lte - report only valid info parameters on R11e-LTE6;
      *) ppp - fixed minor typo in "ppp-client" monitor;
      *) qsfp - do not report bogus monitoring readouts on modules without DDMI support;
      *) qsfp - improved module monitoring readouts for DAC and break-out cables;
      *) routerboard - added "mode-button" support for RBcAP2nD;
      *) security - fixed vulnerability for routers with default password (limited to Wireless Wire), admin could login on startup with empty password before default configuration script was fully loaded;
      *) system - fixed "*.auto.rsc" file execution (introduced in v6.46);
      *) system - fixed "check-installation" on PowerPC devices (introduced in v6.46);
      *) traffic-generator - improved memory handling on CHR;
      *) webfig - allow skin designing without "ftp" and "sensitive" policies;
      *) webfig - fixed "skins" saving to "flash" directory if it exists (introduced in v6.46);
      *) winbox - automatically refresh "Packets" table when new packets are captured by "Tools/Packet Sniffer";
      *) winbox - fixed "Default Route Distance" default value when creating new LTE APN;
      *) winbox - removed duplicate "join-eui" and "dev-eui" parameters under "Lora/Traffic";
      Что нового в версии 6.43.8 (2018-Dec-21 07:10):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.43.8:
      ----------------------
      !) telnet - do not allow to set "tracefile" parameter;
      ----------------------

      Изменения в этом выпуске:

      *) bridge - fixed IPv6 link-local address generation when auto-mac=yes;
      *) capsman - fixed "group-key-update" parameter not using correct units;
      *) crs3xx - improved data transmission between 10G and 1G ports;
      *) console - properly remove system note after configuration reset;
      *) dhcpv4-server - fixed dynamic lease reuse after expiration;
      *) dhcpv6-server - properly handle DHCP requests that include prefix hint;
      *) ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;
      *) gps - added "coordinate-format" parameter;
      *) led - fixed default LED configuration for RBMetalG-52SHPacn;
      *) led - fixed PWR-LINE AP ethernet led polarity ("/system routerboard upgrade" required);
      *) lte - disallow setting LTE interface as passthrough target;
      *) lte - fixed DHCP IP acquire (introduced in v6.43.7);
      *) lte - fixed passthrough functionality when interface is removed;
      *) lte - increased reported "rsrq" precision;
      *) lte - reset USB when non-default slot is used;
      *) package - use bundled package by default if standalone packages are installed as well;
      *) resource - fixed "total-memory" reporting on ARM devices;
      *) snmp - added "tx-ccq" ("mtxrWlStatTxCCQ") and "rx-ccq" ("mtxrWlStatRxCCQ") values;
      *) switch - fixed MAC learning when disabling interfaces on devices with Atheros8327 and QCA8337 switch chips;
      *) system - fixed situation when all configuration was not properly loaded on bootup;
      *) timezone - fixed "Europe/Dublin" time zone;
      *) upgrade - automatically uninstall standalone package if already installed in bundle;
      *) webfig - do not show bogus VHT field in wireless interface advanced mode;
      *) winbox - added "allow-roaming" parameter in "Interface/LTE" menu;
      *) winbox - allow to change VHT rates when 5ghz-n/ac band is used;
      *) winbox - renamed "Radius" to "RADIUS";
      *) winbox - show "Switch" menu on RB4011iGS+5HacQ2HnD and RB4011iGS+;
      *) wireless - added new "installation" parameter to specify router's location;
      *) wireless - improved stability for 802.11ac;
      *) wireless - improvements in wireless frequency selection;
      Что нового в версии 6.46.1 (2019-Dec-13 12:44):

      *) capsman - fixed CAP upgrading (introduced in v6.46);
      *) console - fixed "clear-history" restoring historic actions after power cycle;
      *) console - removed "edit" and "set" actions from "System/History" menu;
      *) defconf - fixed default configuration loading after fresh install (introduced in v6.46);
      *) dhcpv6-server - use lease time from RADIUS;
      *) dude - fixed image and font file accessing (introduced in v6.46);
      *) gps - only adjust system time after GPS signal is established;
      *) health - fixed health reporting on OmniTIK 5 PoE ac;
      *) ipsec - improved system stability when processing decrypted packet on unregistered interface;
      *) l2tp - improved system stability when disconnecting many clients at once;
      *) log - fixed "disk-file-name" parameter validation (introduced in v6.46);
      *) lora - added support for MIPSBE, PPC, TILE and x86 architectures;
      *) lora - improved confirmed downlink forwarding;
      *) lte - do not reset modem when setting the same SIM slot on LtAP;
      *) lte - show SIM error when no card is present;
      *) ppp - fixed session establishment with high amount of tunnels (introduced in v6.46);
      *) ppp - prioritize "remote-ipv6-prefix-pool" from PPP secret over PPP profile;
      *) qsfp - do not show "sfp-wavelength" for cables that do not support it;
      *) snmp - fixed health related OID polling (introduced in v6.46);
      *) supout - fixed autosupout.rif file generation (introduced in v6.46);
      *) system - fixed "*.auto.rsc" file execution (introduced in v6.46);
      *) user-manager - fixed "db-path" parameter validation (introduced in v6.46);
      *) webfig - fixed skin folder presence (introduced in v6.46);
      *) winbox - fixed "allowed-number" parameter setting invalid value in "Tool/SMS" menu;
      *) winbox - show "LCD" menu only on boards that have LCD screen;
      *) wireless - added "russia4" regulatory domain information;
      *) wireless - improved compatibility by adding default installation mode and gain for devices with integrated antennas;
      *) wireless - improved compatibility for Switzerland wireless country profile to improve compliance with ETSI regulations;
      Что нового в версии 6.46 (2019-Dec-02 11:16):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.46:
      ----------------------
      !) lora - added support for LoRaWAN low-power wide-area network technology for MIPSBE, MMIPS and ARM;
      !) package - accept only packages with original filenames (CVE-2019-3976);
      !) package - improved package signature verification (CVE-2019-3977);
      !) security - fixed improper handling of DNS responses (CVE-2019-3978, CVE-2019-3979);
      ----------------------

      Изменения в этом выпуске:

      *) backup - fixed automatic backup file generation when configuration reset by button;
      *) backup - store automatically created backup file in "flash" directory;
      *) bonding - correctly remove HW offloaded bonding with ARP monitoring;
      *) bonding - properly handle MAC addresses when bonding WLAN interfaces;
      *) bridge - disable/enable bridge port when setting bpdu-guard;
      *) bridge - do not add bridge as untagged VLAN member when frame-types=admit-only-vlan-tagged;
      *) bridge - do not add dynamically VLAN entry when changing "pvid" property for non-vlan aware bridge;
      *) bridge - include whole VLAN-id in DHCP Option 82 message;
      *) btest - removed duplicate "duration" parameter;
      *) capsman - fixed background scan showing incorrect regulatory domain mismatch error (CAP upgrade required);
      *) capsman - fixed channel auto reselection;
      *) capsman - fixed MAC address detection for "common-name" parameter in certificate requests;
      *) capsman - improved DFS channel switching when radar detected;
      *) capsman - improved radar detection algorithm;
      *) ccr - improved general system stability;
      *) certificate - added progress bar when creating certificate request;
      *) certificate - added support for certificate request signing with EC keys;
      *) certificate - allow specifying "file-name" parameter for export (CLI only);
      *) certificate - allow specifying "name" parameter for import (CLI only);
      *) certificate - improved CRL updating process;
      *) certificate - removed "key-size" parameter for "create-certificate-request" command;
      *) chr - added support for Azure guest agent;
      *) console - added bitwise operator support for "ip6" data type;
      *) console - fixed "address" column width when printing DHCPv4 leases;
      *) console - fixed IP conversion to "num" data type;
      *) console - fixed "tobool" conversion;
      *) console - properly detect IPv6 address as "ip6" data type;
      *) crs1xx/2xx - allow to set trunk port as mirroring target;
      *) crs3xx - correctly handle L2MTU change;
      *) crs3xx - do not send pause frames when ethernet "tx-flow-control" is disabled on CRS326/CRS328/CRS305 devices;
      *) crs3xx - improved interface initialization;
      *) crs3xx - improved switch-chip resource allocation on CRS317-1G-16S+, CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
      *) crs3xx - improved system stability on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
      *) crs3xx - remove previously set mirror-source property before changing it;
      *) defconf - fixed default configuration loading on RBmAPL-2nD (introduced in v6.45);
      *) defconf - require "policy" permission to print default configuration;
      *) dhcpv4-client - allow empty "dhcp-options" parameter when adding new client;
      *) dhcpv4-client - fixed "dhcp-options" parameter setting when adding new client;
      *) dhcpv4-server - improved stability when RADIUS Interim update is sent;
      *) dhcpv6-client - fixed timeout when doing rebind;
      *) dhcpv6-client - properly update bind time when unused prefix received from the server;
      *) dhcpv6-client - properly update IPv6 address on rebind;
      *) dhcpv6-server - fixed logged error message when using "address-pool=static-only";
      *) dhcpv6-server - ignore prefix-hint from client's DHCPDISCOVER if static prefix received from RADIUS;
      *) dhcpv6-server - include "User-Name" parameter in accounting requests;
      *) dhcpv6-server - made "calling-station-id" contain MAC address if DUID contains it;
      *) dot1x - added "reject-vlan-id" server parameter (CLI only);
      *) dot1x - added support for dynamic switch rules from RADIUS;
      *) dot1x - added support for "mac-auth" authentication type (CLI only);
      *) ethernet - automatically detect interface when using IP address for power-cycle-ping;
      *) ethernet - do not enable interface after reboot that is already disabled;
      *) ethernet - send requests only from ethernet interface when using MAC address for power-cycle-ping;
      *) export - always export "ssid" value for w60g interfaces;
      *) fetch - do not allocate extra 500KiB on SMIPS;
      *) fetch - improved stability when processing large output data;
      *) gps - use "serial1" as default port on RBLtAP-2HnD;
      *) hotspot - fixed non-local NAT redirection to port TCP/64873;
      *) hotspot - fixed RADIUS CoA "address-list" update;
      *) ike1 - fixed minor spelling mistake in logs;
      *) ike2 - improved CHILD SA rekey process with Apple iOS 13;
      *) ike2 - improved stability when retransmitting first packet as responder;
      *) ipsec - added "error" topic for identity check failure logging messages;
      *) ipsec - fixed DNS resolving when domain has only AAAA entries;
      *) ipsec - fixed policy "sa-src-address" detection from "local-address" (introduced in v6.45);
      *) ipv6 - changed "advertise-dns" default value to "yes";
      *) led - fixed default LED configuration for RBLHG-2nD and RBLHG-5HPnD;
      *) log - increased log message length limit to 1024 characters;
      *) lte - added support for D402 modem;
      *) lte - added support for LM960A18;
      *) lte - added support for Telit LM960 and LE910C1 modems;
      *) lte - do not allow setting 3G and GSM modes on LTE only modems;
      *) lte - fixed band setting on R11e-4G;
      *) lte - fixed network registration on R11e-LTE-US;
      *) lte - fixed Sierra WP7601 driver loading;
      *) lte - fix "operator" names not being displayed properly;
      *) lte - improved modem initialization;
      *) lte - show "primary-band" only for LTE modems;
      *) lte - use /128 prefix for IPv6 address on LTE interface;
      *) lte - use interface from RA when "ipv6-interface=none" and IPv6 enabled;
      *) ppp - added 3GPP IoT "access-technology" definitions;
      *) ppp - added support for Sierra WP7601;
      *) ppp - disable DTR send when using at-chat;
      *) quickset - added "LTE AP Dual" mode support;
      *) quickset - added "LTE APN" dropdown support;
      *) quickset - fixed "LTE Band" checkbox display;
      *) route - fixed area range summary route installation in VRF;
      *) routerboard - fixed default CPU frequency on RB750r2 ("/system routerboard upgrade" required);
      *) routerboard - fixed USB configuration export on RBLtAP-2HnD;
      *) routerboard - hide "memory-frequency" parameter for RBLtAP-2HnD;
      *) sniffer - allow filtering by packet size;
      *) snmp - added "disabled" and "comment" parameters for communities;
      *) snmp - added option to monitor "link-downs" parameter using MIKROTIK-MIB;
      *) snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
      *) snmp - fixed "ifLastChange" OID reporting for IF-MIB;
      *) snmp - fixed "radio-name" (mtxrWlRtabRadioName) OID support;
      *) snmp - improved interface status reporting for IfOperStatus OID;
      *) snmp - improved LLDP interface returned index and type;
      *) snmp - return only interfaces with MAC addresses for LLDP;
      *) snmp - use "src-address" also for traps;
      *) ssh - fixed output printing when "command" parameter used;
      *) supout - include information from all LTE interfaces;
      *) supout - removed "file" option from "/system sup-output" command;
      *) switch - added "comment" property for switch vlan menu (CLI only);
      *) switch - correctly update dynamic switch rule when dhcp-snooping is enabled;
      *) switch - ignore "default-vlan-id" property after switch reset on RTL8367 switch chip;
      *) switch - show "external" flag for bridge hosts on MT7621, RTL8367 switch chips;
      *) timezone - updated time zone database to version 2019c;
      *) tr069-client - added CellDiagnostics parameter support;
      *) tr069-client - added LTE band and cellular technology selection parameters;
      *) tr069-client - added LTE RSCP, ECNO and ICCID parameter support;
      *) tr069-client - added multiple LTE monitoring parameters;
      *) tr069-client - reconnect to ACS when "ConnectionRequestURL" is updated;
      *) upgrade - improved auto package updating using "check-for-updates";
      *) ups - improved compatibility with APC UPS's;
      *) usb - general USB modem stability improvements;
      *) userman - updated Authorize.Net to use SHA512 hashing;
      *) w60g - added "region" setting to limit allowed frequencies (CLI only);
      *) w60g - do not reset link when changing comment on station;
      *) w60g - fixed "monitor" command on disabled interfaces;
      *) w60g - move stations to new bridge when "put-in-bridge" parameter is changed;
      *) webfig - fixed link to Winbox download;
      *) winbox - added "ip-address" and stats columns in "IP/Kid-Control/Devices" menu;
      *) winbox - added "public-address-ipv6" parameter to "IP/Cloud" menu;
      *) winbox - added "reset-counters" button to "IP/Kid Control/Devices" menu;
      *) winbox - added "tx-info-field" parameter to "Wireless/W60G" menu;
      *) winbox - added "Vendor Classes" tab in "IP/DHCP Server" menu;
      *) winbox - added wireless alignment LED types to "System/LEDs" menu;
      *) winbox - fixed allowed range for bridge filter "new-priority" parameter;
      *) winbox - fixed "CAPs Scanner" stopping;
      *) winbox - fixed "cluster-id" parameter setting in "Routing/BGP/Instances" menu;
      *) winbox - fixed file locking when uploading multiple files at once;
      *) winbox - fixed firewall limit parameter support for rates more than 4G;
      *) winbox - fixed invalid flag presence in "IP/SMB/Shares" menu;
      *) winbox - fixed "Routing" menu icon presence when there is no routing package installed;
      *) winbox - improved stability when transfering multiple files between multiple windows;
      *) winbox - properly show timestamp in file "Creation Time" field;
      *) winbox - removed "Set CA Passphrase" button from "Certificate" menu;
      *) winbox - renamed "Queue Limit" to "Queue Size" for "pcq-upload-default" and "pcq-download-default" parameters;
      *) winbox - replaced "kb" with "KiB" in "Tools/Packet Sniffer" menu;
      *) winbox - show "Switch" menu on RBwAPGR-5HacD2HnD;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) wireless - added 4 chain MCS support for 802.11n wireless protocol (CLI only);
      *) wireless - added "ETSI" regulatory domain information;
      *) wireless - added "indonesia4" regulatory domain information;
      *) wireless - added "push-button-5s" value for "wps-mode" parameter;
      *) wireless - added U-NII-2 support forRBSXTsqG-5acD, RBLHGG-5acD-XL, RBLHGG-5acD, RBLDFG-5acD, RBDiscG-5acD;
      *) wireless - allow using "canada2" regulatory domain on US lock devices;
      *) wireless - fixed 802.11n rate selection when managed by CAPsMAN;
      *) wireless - fixed RX chain selection;
      *) wireless - fixed sensor MAC address reporting in TZSP header;
      *) wireless - improved 802.11ac stability for all ARM devices with wireless;
      *) wireless - improved IPQ4019, QCA9984, QCA9888 wireless interface stability;
      *) wireless - updated "ukraine" regulatory domain information;
      *) wireless - updated "united-states" regulatory domain information;
      Что нового в версии 6.45.7 (2019-Oct-24 08:44):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.45.7:
      ----------------------
      !) lora - added support for LoRaWAN low-power wide-area network technology for MIPSBE, MMIPS and ARM;
      !) package - accept only packages with original filenames (CVE-2019-3976);
      !) package - improved package signature verification (CVE-2019-3977);
      !) security - fixed improper handling of DNS responses (CVE-2019-3978, CVE-2019-3979);
      ----------------------

      Изменения в этом выпуске:

      *) capsman - fixed frequency setting requiring multiple frequencies;
      *) capsman - fixed newline character missing on some logging messages;
      *) conntrack - properly start manually enabled connection tracking;
      *) crs312 - fixed combo SFP port toggling (introduced in v6.44.5);
      *) crs3xx - correctly display link rate when 10/100/1000BASE-T SFP modules are used in SFP+ interfaces;
      *) crs3xx - fixed management access when using switch rule "new-vlan-priority" property;
      *) export - fixed "bootp-support" parameter export;
      *) ike2 - fixed phase 1 rekeying (introduced in v6.45);
      *) led - fixed default LED configuration for RBLHG5nD;
      *) lte - fixed modem not receiving IP configuration when roaming (introduced in v6.45);
      *) radius - fixed open socket leak when invalid packet is received (introduced in v6.44);
      *) sfp - fixed "sfp-rx-power" value for some transceivers;
      *) snmp - improved reliability on SNMP service packet validation;
      *) system - improved system stability for devices with AR9342 SoC;
      *) winbox - show SFP tab for QSFP interfaces;
      *) wireless - added "canada2" regulatory domain information;
      *) wireless - improved stability when setting fixed primary and secondary channels on RB4011iGS+5HacQ2HnD-IN;
      Что нового в версии 6.45.6 (2019-Sep-10 09:06):

      Важная заметка!!!
      Due to removal of compatibility with old version passwords in this version, downgrading to any version prior to v6.43 (v6.42.12 and older) will clear all user passwords and allow password-less authentication. Please secure your router after downgrading.
      Old API authentication method will also no longer work, see documentation for new login procedure:
      https://wiki.mikrotik.com/wiki/Manual:API#Initial_login

      *) capsman - fixed regulatory domain information checking when doing background scan;
      *) conntrack - improved system stability when using h323 helper (introduced in v6.45);
      *) crs3xx - fixed "egress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
      *) qsfp - clear SFP monitoring data on port enable;
      *) qsfp - correctly display SFP monitoring data;
      *) qsfp - fixed EEPROM checksum validation;
      *) qsfp - show more QSFP module diagnostics;
      *) wireless - include last frequency when manually setting frequency step in "scan-list";
      Что нового в версии 6.45.5 (2019-Aug-26 10:56):

      Важная заметка!!!
      Due to removal of compatibility with old version passwords in this version, downgrading to any version prior to v6.43 (v6.42.12 and older) will clear all user passwords and allow password-less authentication. Please secure your router after downgrading.
      Old API authentication method will also no longer work, see documentation for new login procedure:
      https://wiki.mikrotik.com/wiki/Manual:API#Initial_login

      *) crs328 - adjust fan speed based on SFP and CPU temperature;
      *) dhcpv4-server - fixed "Acct-Output-Octets" reporting to RADIUS;
      *) health - improved fan control on CRS3xx and CCR1016-12S-1S+r2;
      *) ike2 - don't release policy on rekey when child not found;
      *) ike2 - fixed ID validation with multiple SAN;
      *) ike2 - fixed policy port selection for responder with natted initiator;
      *) ike2 - fixed traffic selector address family selection when using IPv6;
      *) ike2 - improved rekeying process with Windows initiators;
      *) ike2 - properly start all initiators to the same remote address;
      *) ipsec - allow inline "passphrase" parameter when importing keys;
      *) ipsec - fixed "eap-radius" authentication method (introduced in v6.45);
      *) ipsec - fixed minor spelling mistakes in logs;
      *) lte - fixed cell information monitoring on R11e-LTE-US (introduced in v6.45.2);
      *) lte - fixed LTE interface disappearing on RBSXTLTE3-7;
      *) smb - improved stability on x86 and CHR (CVE-2019-16160);
      *) snmp - fixed encrypted data sequence (introduced in v6.44.5);
      *) ssh - fixed carriage return presence in subsequent sessions;
      *) switch - fix port isolation for non-CRS series switch chips;
      *) system - accept only valid string for "name" parameter in "disk" menu (CVE-2019-15055);
      *) upnp - fixed XML parsing (FG-VD-19-110);
      *) watchdog - renamed "no-ping-delay" parameter to "ping-start-after-boot";
      *) winbox - added "auto-erase" parameter to "Tools/SMS" menu;
      *) winbox - added "https-redirect" parameter to "IP/Hotspot/Profiles menu";
      *) winbox - added "revision" parameter to "System/Routerboard" menu;
      *) winbox - removed "max-sms" parameter from "Tools/SMS" menu;
      *) wireless - fixed basic rate reporting in snooper;
      Что нового в версии 6.45.4 (2019-Aug-13 09:04):

      (factory only release)
      Что нового в версии 6.45.3 (2019-Jul-29 12:11):

      Важная заметка!!!
      Due to removal of compatibility with old version passwords in this version, downgrading to any version prior to v6.43 (v6.42.12 and older) will clear all user passwords and allow password-less authentication. Please secure your router after downgrading.
      Old API authentication method will also no longer work, see documentation for new login procedure:
      https://wiki.mikrotik.com/wiki/Manual:API#Initial_login

      *) certificate - renew certificates via SCEP when 3/4 of lifetime reached;
      *) crs317 - fixed multicast packet receiving (introduced in v6.45);
      *) hotspot - fixed default profile values not being used (introduced in v6.45);
      *) rb4011 - fixed SFP+ interface linking (introduced in v6.45.2);
      *) smips - reduced RouterOS main package size (disabled LTE modem, dot1x and SwOS support);
      *) supout - fixed SIM slot printing (introduced in v6.45);
      *) wireless - improved U-APSD (WMM Power Save) support for 802.11e;
      Что нового в версии 6.45.2 (2019-Jul-17 10:04):

      Важная заметка!!!
      Due to removal of compatibility with old version passwords in this version, downgrading to any version prior to v6.43 (v6.42.12 and older) will clear all user passwords and allow password-less authentication. Please secure your router after downgrading.
      Old API authentication method will also no longer work, see documentation for new login procedure:
      https://wiki.mikrotik.com/wiki/Manual:API#Initial_login

      *) bonding - fixed bonding running status after reboot when using other bonds as slave interfaces (introduced in v6.45);
      *) cloud - properly stop "time-zone-autodetect" after disable;
      *) interface - fixed missing PWR-LINE section on PL7411-2nD and PL6411-2nD (introduced v6.44);
      *) ipsec - added "connection-mark" parameter for mode-config initiator;
      *) ipsec - allow peer argument only for "encrypt" policies (introduced in v6.45);
      *) ipsec - fixed peer configuration migration from versions older than v6.43 (introduced in v6.45);
      *) ipsec - improved stability for peer initialization (introduced in v6.45);
      *) ipsec - show warning for policies with "unknown" peer;
      *) ospf - fixed possible busy loop condition when accessing OSPF LSAs;
      *) profile - added "internet-detect" process classificator;
      *) radius - fixed "User-Password" encoding (introduced in v6.45);
      *) ssh - do not enable "none-crypto" if "strong-crypto" is enabled on upgrade (introduced in v6.45);
      *) ssh - fixed executed command output printing (introduced in v6.45);
      *) supout - fixed supout file generation outside of internal storage with insufficient space;
      *) upgrade - fixed "auto-upgrade" to use new style authentication (introduced in v6.45);
      *) vlan - fixed "slave" flag for non-running interfaces (introduced in v6.45);
      *) wireless - improved 802.11ac stability for all ARM devices with wireless;
      *) wireless - improved range selection when distance set to "dynamic";
      Что нового в версии 6.45.1 (2019-Jun-27 10:23):

      Важная заметка!!!
      Due to removal of compatibility with old version passwords in this version, downgrading to any version prior to v6.43 (v6.42.12 and older) will clear all user passwords and allow password-less authentication. Please secure your router after downgrading.
      Old API authentication method will also no longer work, see documentation for new login procedure:
      https://wiki.mikrotik.com/wiki/Manual:API#Initial_login

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.45.1:
      ----------------------
      !) dot1x - added support for IEEE 802.1X Port-Based Network Access Control;
      !) ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap, eap-mschapv2) as initiator;
      !) security - fixed vulnerabilities CVE-2019-13954, CVE-2019-13955;
      !) security - fixed vulnerabilities CVE-2019-11477, CVE-2019-11478, CVE-2019-11479;
      !) security - fixed vulnerability CVE-2019-13074;
      !) user - removed insecure password storage;
      ----------------------

      Изменения в этом выпуске:

      *) bridge - correctly display bridge FastPath status when vlan-filtering or dhcp-snooping is used;
      *) bridge - correctly handle bridge host table;
      *) bridge - fixed log message when hardware offloading is being enabled;
      *) bridge - improved stability when receiving traffic over USB modem with bridge firewall enabled;
      *) capsman - fixed CAP system upgrading process for MMIPS;
      *) capsman - fixed interface-list usage in access list;
      *) ccr - improved packet processing after overloading interface;
      *) certificate - added "key-type" field;
      *) certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1);
      *) certificate - fixed self signed CA certificate handling by SCEP client;
      *) certificate - made RAM the default CRL storage location;
      *) certificate - removed DSA (D) flag;
      *) certificate - removed "set-ca-passphrase" parameter;
      *) chr - legacy adapters require "disable-running-check=yes" to be set;
      *) cloud - added "replace" parameter for backup "upload-file" command;
      *) conntrack - fixed GRE protocol packet connection-state matching (CVE-2014-8160);
      *) conntrack - significant stability and performance improvements;
      *) crs317 - fixed known multicast flooding to the CPU;
      *) crs3xx - added ethernet tx-drop counter;
      *) crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
      *) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
      *) crs3xx - fixed "tx-drop" counter;
      *) crs3xx - improved switch-chip resource allocation on CRS326, CRS328, CRS305;
      *) defconf - added "custom-script" field that prints custom configuration installed by Netinstall;
      *) defconf - automatically set "installation" parameter for outdoor devices;
      *) defconf - changed default configuration type to AP for cAP series devices;
      *) defconf - fixed channel width selection for RU locked devices;
      *) dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
      *) dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
      *) dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
      *) dhcpv4-server - added "client-mac-limit" parameter;
      *) dhcpv4-server - added IP conflict logging;
      *) dhcpv4-server - added RADIUS accounting support with queue based statistics;
      *) dhcpv4-server - added "vendor-class-id" matcher (CLI only);
      *) dhcpv4-server - improved stability when performing "check-status" command;
      *) dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
      *) dhcpv6-client - added option to disable rapid-commit;
      *) dhcpv6-client - fixed status update when leaving "bound" state;
      *) dhcpv6-server - added additional RADIUS parameters for Prefix delegation, "rate-limit" and "life-time";
      *) dhcpv6-server - added "address-list" support for bindings;
      *) dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters;
      *) dhcpv6-server - added RADIUS accounting support with queue based statistics;
      *) dhcpv6-server - added "route-distance" parameter;
      *) dhcpv6-server - fixed dynamic IPv6 binding without proper reference to the server;
      *) dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
      *) discovery - correctly create neighbors from VLAN tagged discovery messages;
      *) discovery - fixed CDP packets not including address on slave ports (introduced in v6.44);
      *) discovery - improved neighbour's MAC address detection;
      *) discovery - limit max neighbour count per interface based on total RAM memory;
      *) discovery - show neighbors on actual mesh ports;
      *) e-mail - include "message-id" identification field in e-mail header;
      *) e-mail - properly release e-mail sending session if the server's domain name can not be resolved;
      *) ethernet - added support for 25Gbps and 40Gbps rates;
      *) ethernet - fixed running (R) flag not present on x86 interfaces and CHR legacy adapters;
      *) ethernet - increased loop warning threshold to 5 packets per second;
      *) fetch - added SFTP support;
      *) fetch - improved user policy lookup;
      *) firewall - fixed fragmented packet processing when only RAW firewall is configured;
      *) firewall - process packets by firewall when accepted by RAW with disabled connection tracking;
      *) gps - fixed missing minus close to zero coordinates in dd format;
      *) gps - make sure "direction" parameter is upper case;
      *) gps - strip unnecessary trailing characters from "longtitude" and "latitude" values;
      *) gps - use "serial0" as default port on LtAP mini;
      *) hotspot - added "interface-mac" variable to HTML pages;
      *) hotspot - moved "title" HTML tag after "meta" tags;
      *) ike1 - adjusted debug packet logging topics;
      *) ike2 - added support for ECDSA certificate authentication (rfc4754);
      *) ike2 - added support for IKE SA rekeying for initiator;
      *) ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
      *) ike2 - improved certificate verification when multiple CA certificates received from responder;
      *) ike2 - improved child SA rekeying process;
      *) ike2 - improved XAuth identity conversion on upgrade;
      *) ike2 - prefer SAN instead of DN from certificate for ID payload;
      *) ippool - improved logging for IPv6 Pool when prefix is already in use;
      *) ipsec - added dynamic comment field for "active-peers" menu inherited from identity;
      *) ipsec - added "ph2-total" counter to "active-peers" menu;
      *) ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods;
      *) ipsec - added traffic statistics to "active-peers" menu;
      *) ipsec - disallow setting "src-address" and "dst-address" for transport mode policies;
      *) ipsec - do not allow adding identity to a dynamic peer;
      *) ipsec - fixed policies becoming invalid after changing priority;
      *) ipsec - general improvements in policy handling;
      *) ipsec - properly drop already established tunnel when address change detected;
      *) ipsec - renamed "remote-peers" to "active-peers";
      *) ipsec - renamed "rsa-signature" authentication method to "digital-signature";
      *) ipsec - replaced policy SA address parameters with peer setting;
      *) ipsec - use tunnel name for dynamic IPsec peer name;
      *) ipv6 - improved system stability when receiving bogus packets;
      *) ltap - renamed SIM slots "up" and "down" to "2" and "3";
      *) lte - added initial support for Vodafone R216-Z;
      *) lte - added passthrough interface subnet selection;
      *) lte - added support for manual operator selection;
      *) lte - allow setting empty APN;
      *) lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
      *) lte - do not show error message for info commands that are not supported;
      *) lte - fixed session reactivation on R11e-LTE in UMTS mode;
      *) lte - improved firmware upgrade process;
      *) lte - improved "info" command query;
      *) lte - improved R11e-4G modem operation;
      *) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
      *) lte - show alphanumeric value for operator info;
      *) lte - show correct firmware revision after firmware upgrade;
      *) lte - use default APN name "internet" when not provided;
      *) lte - use secondary DNS for DNS server configuration;
      *) m33g - added support for additional Serial Console port on GPIO headers;
      *) ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
      *) ospf - fixed opaque LSA type checking in OSPFv2;
      *) ospf - improved "unknown" LSA handling in OSPFv3;
      *) ovpn - added "verify-server-certificate" parameter for OVPN client (CVE-2018-10066);
      *) ppp - added initial support for Quectel BG96;
      *) proxy - increased minimal free RAM that can not be used for proxy services;
      *) rb3011 - improved system stability when receiving bogus packets;
      *) rb4011 - fixed MAC address duplication between sfp-sfpplus1 and wlan1 interfaces (wlan1 configuration reset required);
      *) rb921 - improved system stability ("/system routerboard upgrade" required);
      *) routerboard - renamed 'sim' menu to 'modem';
      *) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
      *) sms - added USSD message functionality under "/tool sms" (CLI only);
      *) sms - allow specifying multiple "allowed-number" values;
      *) sms - improved delivery report logging;
      *) snmp - added "dot1dStpPortTable" OID;
      *) snmp - added OID for neighbor "interface";
      *) snmp - added "write-access" column to community print;
      *) snmp - allow setting interface "adminStatus";
      *) snmp - fixed "send-trap" not working when "trap-generators" does not contain "temp-exception";
      *) snmp - fixed "send-trap" with multiple "trap-targets";
      *) snmp - improved reliability on SNMP service packet validation;
      *) snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
      *) ssh - accept remote forwarding requests with empty hostnames;
      *) ssh - added new "ssh-exec" command for non-interactive command execution;
      *) ssh - fixed non-interactive multiple command execution;
      *) ssh - improved remote forwarding handling (introduced in v6.44.3);
      *) ssh - improved session rekeying process on exchanged data size threshold;
      *) ssh - keep host keys when resetting configuration with "keep-users=yes";
      *) ssh - use correct user when "output-to-file" parameter is used;
      *) sstp - improved stability when received traffic hits tarpit firewall;
      *) supout - added IPv6 ND section to supout file;
      *) supout - added "kid-control devices" section to supout file;
      *) supout - added "pwr-line" section to supout file;
      *) supout - changed IPv6 pool section to output detailed print;
      *) switch - properly reapply settings after switch chip reset;
      *) tftp - added "max-block-size" parameter under TFTP "settings" menu (CLI only);
      *) tile - improved link fault detection on SFP+ ports;
      *) tr069-client - added LTE CQI and IMSI parameter support;
      *) tr069-client - fixed potential memory corruption;
      *) tr069-client - improved error reporting with incorrect firware upgrade XML file;
      *) traceroute - improved stability when sending large ping amounts;
      *) traffic-generator - improved stability when stopping traffic generator;
      *) tunnel - removed "local-address" requirement when "ipsec-secret" is used;
      *) userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
      *) w60g - do not show unused "dmg" parameter;
      *) w60g - prefer AP with strongest signal when multiple APs with same SSID present;
      *) w60g - show running frequency under "monitor" command;
      *) winbox - added "System/SwOS" menu for all dual-boot devices;
      *) winbox - do not allow setting "dns-lookup-interval" to "0";
      *) winbox - show "LCD" menu only on boards that have LCD screen;
      *) wireless - fixed frequency duplication in the frequency selection menu;
      *) wireless - fixed incorrect IP header for RADIUS accounting packet;
      *) wireless - improved 160MHz channel width stability on rb4011;
      *) wireless - improved DFS radar detection when using non-ETSI regulated country;
      *) wireless - improved installation mode selection for wireless outdoor equipment;
      *) wireless - set default SSID and supplicant-identity the same as router's identity;
      *) wireless - updated "china" regulatory domain information;
      *) wireless - updated "new zealand" regulatory domain information;
      *) www - improved client-initiated renegotiation within the SSL and TLS protocols (CVE-2011-1473);
      Что нового в версии 6.45 (2019-Jun-21 09:00):

      (factory only release)
      Что нового в версии 6.44.4 (2019-May-09 12:14):

      (factory only release)
      Что нового в версии 6.44.3 (2019-Apr-23 12:37):

      *) certificate - fixed SAN being duplicated on status change (introduced in v6.44);
      *) conntrack - fixed "loose-tcp-tracking" parameter not taken in action (introduced in v6.44);
      *) dhcpv4-server - fixed commenting option for alerts;
      *) dhcpv6-server - fixed binding setting update from RADIUS;
      *) ike1 - improved stability for transport mode policies on initiator side;
      *) ipsec - fixed freshly created identity not taken in action (introduced in v6.44);
      *) ipsec - fixed possible configuration corruption after import (introduced in v6.44);
      *) ipv6 - adjusted IPv6 route cache max size;
      *) ipv6 - improved IPv6 neighbor table updating process;
      *) lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
      *) rb2011 - removed "sfp-led" from "System/LEDs" menu;
      *) smb - fixed possible buffer overflow;
      *) snmp - added "radio-name" (mtxrWlRtabRadioName) OID support;
      *) ssh - added "both", "local" and "remote" options for "forwarding-enabled" parameter;
      *) ssh - do not generate host key on configuration export;
      *) ssh - fixed multiline non-interactive command execution;
      *) switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
      *) userman - updated authorize.net gateway DNS name;
      *) wireless - added support for US FCC UNII-2 and Canada country profiles for LHG-5HPnD-US, RBLHG-5HPnD-XL-US and SXTsq5HPnD-US devices;
      *) wireless - improved wireless country settings for EU countries;
      Что нового в версии 6.44.2 (2019-Apr-01 12:47):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.44.2:
      ----------------------
      !) ipv6 - fixed soft lockup when forwarding IPv6 packets;
      !) ipv6 - fixed soft lockup when processing large IPv6 Neighbor table;
      ----------------------

      Изменения в этом выпуске:

      *) ipv6 - adjust IPv6 route cache max size based on total RAM memory;
      Что нового в версии 6.44.1 (2019-Mar-13 08:38):

      Изменения в этом выпуске:

      *) bridge - fixed possible memory leak when using "ingress-filtering=yes" on bridge interface;
      *) certificate - force 3DES encryption for P12 certificate export;
      *) dhcp - fixed dual stack queue addition;
      *) dhcpv6-server - use MAC address for RADIUS user when "allow-dual-stack-queue=yes";
      *) e-mail - fixed missing "from" address for sent e-mails (introduced in v6.44);
      *) gps - increase precision for dd format;
      *) gps - removed unnecessary leading "0" for dd format;
      *) ipsec - allow identities with empty XAuth login and password if RADIUS is enabled (introduced in v6.44);
      *) ipsec - fixed dynamic L2TP peer and identity configuration missing after reboot (introduced in v6.44);
      *) ipsec - use "remote-id=ignore" for dynamic L2TP configuration (introduced in v6.44);
      *) ipv6 - do not allow setting "preferred-lifetime" longer than "valid-lifetime";
      *) lte - do not show "session-uptime" if session is not up;
      *) lte - fixed LTE interface band setting on RBSXTLTE3-7 (introduced in v6.44);
      *) rb4011 - fixed ether10 failing to auto negotiate link speed to 1Gbps;
      *) winbox - added "use-local-address" parameter in "IP/Cloud" menu;
      *) wireless - fixed antenna gain setting on RBSXT5nDr2;
      Что нового в версии 6.44 (2019-Feb-25 14:11):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.44:
      ----------------------
      !) cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);
      !) ipsec - added new "identity" menu with common peer distinguishers;
      !) ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;
      !) ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;
      !) radius - initial implementation of RadSec (RADIUS communication over TLS);
      !) speedtest - added "/tool speed-test" for ping latency, jitter, loss and TCP and UDP download, upload speed measurements (CLI only);
      ----------------------

      Изменения в этом выпуске:

      *) bgp - properly update keepalive time after peer restart;
      *) bridge - added option to monitor fast-forward status;
      *) bridge - count routed FastPath packets between bridge ports under FastPath bridge statistics;
      *) bridge - disable fast-forward when using SlowPath features;
      *) bridge - fixed BOOTP packet forwarding when DHCP Snooping is enabled;
      *) bridge - fixed DHCP Option 82 parsing when using DHCP Snooping;
      *) bridge - fixed log message when hardware offloading is being enabled;
      *) bridge - fixed packet forwarding when changing MSTI VLAN mappings;
      *) bridge - fixed packet forwarding with enabled DHCP Snooping and Option 82;
      *) bridge - fixed possible memory leak when using MSTP;
      *) bridge - fixed system's identity change when DHCP Snooping is enabled (introduced in v6.43);
      *) bridge - improved packet handling when hardware offloading is being disabled;
      *) bridge - improved packet processing when bridge port changes states;
      *) btest - added multithreading support for both UDP and TCP tests;
      *) btest - added warning message when CPU load exceeds 90% (CLI only);
      *) capsman - always accept connections from loopback address;
      *) certificate - added support for multiple "Subject Alt. Names";
      *) certificate - enabled RC2 cipher to allow P12 certificate decryption;
      *) certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;
      *) certificate - show digest algorithm used in signature;
      *) chr - assign interface names based on underlying PCI device order on KVM;
      *) chr - distribute NIC queue IRQ's evenly across all CPUs;
      *) chr - fixed IRQ balancing when using more than 32 CPUs;
      *) chr - improved system stability when insufficient resources are allocated to the guest;
      *) cloud - added "ddns-update-interval" parameter;
      *) cloud - do not reuse old UDP socket if routing changes are detected;
      *) cloud - ignore "force-update" command if DDNS is disabled;
      *) cloud - improved DDNS service disabling;
      *) cloud - made address updating faster when new public address detected;
      *) conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter);
      *) console - renamed IP protocol 41 to "ipv6-encap";
      *) console - updated copyright notice;
      *) crs317 - fixed packet forwarding when LACP is used with hw=no;
      *) crs3xx - fixed packet forwarding through SFP+ ports when using 100Mbps link speed;
      *) crs3xx - improved fan control stability;
      *) defconf - fixed configuration not generating properly on upgrade;
      *) defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;
      *) defconf - fixed IPv6 link-local address range in firewall rules;
      *) dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 DHCP servers to control dynamic lease/binding behaviour;
      *) dhcp - properly load DHCP configuration if options are configured;
      *) dhcpv4-server - added "parent-queue" parameter (CLI only);
      *) dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;
      *) dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;
      *) dhcpv4-server - use ARP for conflict detection;
      *) dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;
      *) dhcpv6-server - allow to add DHCPv6 server with pool that does not exist;
      *) dhcpv6-server - fixed missing gateway for binding's network if RADIUS authentication was used;
      *) dhcpv6-server - improved DHCPv6 server stability when using "print" command;
      *) dhcpv6-server - show "client-address" parameter for bindings;
      *) discovery - detect proper slave interface on bounded interfaces;
      *) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;
      *) discovery - send master port in "interface-name" parameter;
      *) discovery - show neighbors on actual bridge port instead of bridge itself for LLDP;
      *) e-mail - added info log message when e-mail is sent successfully;
      *) e-mail - added support for multiple transactions on single connection;
      *) ethernet - added "tx-rx-1024-max" counter to Ethernet stats;
      *) ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;
      *) ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);
      *) ethernet - fixed packet forwarding when SFP interface is disabled on hEX S;
      *) ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;
      *) ethernet - improved per core ethernet traffic classificator on mmips devices;
      *) export - fixed "silent-boot" compact export;
      *) fetch - added "http-header-field" parameter;
      *) fetch - added option to specify multiple headers under "http-header-field", including content type;
      *) fetch - fixed "without-paging" option;
      *) fetch - improved file downloading to slow memory;
      *) fetch - improved stability when using HTTP mode;
      *) fetch - removed "http-content-type" parameter;
      *) gps - increase precision for dd format;
      *) gps - moved "coordinate-format" from "monitor" command to "set" parameter;
      *) health - improved fan control stability on CRS328-24P-4S+RM;
      *) hotspot - added "https-redirect" under server profiles;
      *) hotspot - added per-user NAT rule generation based on "incoming-filter" and "outgoing-filter" parameters;
      *) ike1 - do not allow using RSA-key and RSA-signature authentication methods simultaneously on single peer;
      *) ike1 - fixed memory leak;
      *) ike2 - added option to specify certificate chain;
      *) ike2 - added peer identity validation for RSA auth (disabled after upgrade);
      *) ike2 - allow to match responder peer by "my-id=fqdn" field;
      *) ike2 - fixed local address lookup when initiating new connection;
      *) ike2 - improved subsequent phase 2 initialization when no childs exist;
      *) ike2 - properly handle certificates with empty "Subject";
      *) ike2 - retry RSA signature validation with deduced digest from certificate;
      *) ike2 - send split networks over DHCP (option 249) to Windows initiators if DHCP Inform is received;
      *) ike2 - show weak pre-shared-key warning;
      *) interface - added "pwr-line" interface support (more information will follow in next newsletter);
      *) ipsec - added account log message when user is successfully authenticated;
      *) ipsec - added basic pre-shared-key strength checks;
      *) ipsec - added new "remote-id" peer matcher;
      *) ipsec - allow to specify single address instead of IP pool under "mode-config";
      *) ipsec - fixed active connection killing when changing peer configuration;
      *) ipsec - fixed all policies not getting installed after startup (introduced in v6.43.8);
      *) ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);
      *) ipsec - hide empty prefixes on "peer" menu;
      *) ipsec - improved invalid policy handling when a valid policy is uninstalled;
      *) ipsec - made dynamic "src-nat" rule more specific;
      *) ipsec - made peers autosort themselves based on reachability status;
      *) ipsec - moved "profile" menu outside "peer" menu;
      *) ipsec - properly detect AES-NI extension as hardware AEAD;
      *) ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;
      *) ipsec - require write policy for key generation;
      *) kidcontrol - added IPv6 support;
      *) kidcontrol - added "reset-counters" command for "device" menu (CLI only);
      *) kidcontrol - added statistics web interface for kids (http://router.lan/kid-control);
      *) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters;
      *) kidcontrol - dynamically discover devices from DNS activity;
      *) kidcontrol - fixed validation checks for time intervals;
      *) kidcontrol - properly detect time zone changes;
      *) kidcontrol - use "/128" prefix-length for IPv6 addresses;
      *) l2tp - fixed IPsec secret not being updated when "ipsec-secret" is changed under L2TP client configuration;
      *) lcd - made "pin" parameter sensitive;
      *) led - fixed default LED configuration for RBSXTsq-60ad;
      *) led - fixed default LED configuration for wAP 60G AP devices;
      *) led - fixed PWR-LINE AP Ethernet LED polarity ("/system routerboard upgrade" required);
      *) lldp - fixed missing capabilities fields on some devices;
      *) log - accumulate multiple e-mail messages before sending;
      *) lte - added additional ID support for Novatel USB730L modem;
      *) lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);
      *) lte - added "ecno" field for "info" command;
      *) lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);
      *) lte - added initial support for multiple APN for R11e-4G (new modem firmware required);
      *) lte - added initial support for Telit LN940;
      *) lte - added multiple APN support for R11e-4G;
      *) lte - added option to lock the LTE operator;
      *) lte - added support for JioFi JMR1040 modem;
      *) lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;
      *) lte - fixed DHCP IP acquire (introduced in v6.43.7);
      *) lte - fixed DHCP relay packet forwarding when in passthrough mode;
      *) lte - fixed IPv6 activation for R11e-LTE-US modems;
      *) lte - fixed Jaton/SQN modems preventing router from booting properly;
      *) lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;
      *) lte - fixed missing running (R) flag for Jaton LTE modems;
      *) lte - fixed passthrough DHCP address forward when other address is acquired from operator;
      *) lte - fixed reported "rsrq" precision (introduced in v6.43.8);
      *) lte - improved compatibility for Alt38xx modems;
      *) lte - improved SIM7600 initialization after reset;
      *) lte - improved SimCom 7100e support;
      *) lte - query "cfun" on initialization;
      *) lte - require write policy for at-chat;
      *) lte - update firmware version information after R11e-LTE/R11e-4G firmware upgrade;
      *) netinstall - do not show kernel failure critical messages in the log after fresh install;
      *) ntp-client - fixed "dst-active" and "gmt-offset" being updated after synchronization with server;
      *) port - improved "remote-serial" TCP performance in RAW mode;
      *) ppp - added "at-chat" command;
      *) ppp - fixed dynamic route creation towards VPN server when "add-default-route" is used;
      *) profiler - classify kernel crypto processing as "encrypting";
      *) profile - removed obsolete "file-name" parameter;
      *) proxy - removed port list size limit;
      *) radius - implemented Proxy-State attribute handling in CoA and disconnect requests;
      *) rb3011 - implemented multiple engine IPsec hardware acceleration support;
      *) rb4011 - fixed SFP+ interface full duplex and speed parameter behavior;
      *) rb4011 - improved SFP+ interface linking to 1Gbps;
      *) rbm33g - improved stability when used with some USB devices;
      *) romon - improved reliability when processing RoMON packets on CHR;
      *) routerboard - removed "RB" prefix from PWR-LINE AP devices;
      *) routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";
      *) smb - added commenting option for SMB users (CLI only);
      *) smb - fixed macOS clients not showing share contents;
      *) smb - fixed Windows 10 clients not able to establish connection to share;
      *) sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;
      *) snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;
      *) snmp - changed fan speed value type to Gauge32;
      *) snmp - fixed "rsrq" reported precision;
      *) snmp - fixed w60g station table;
      *) snmp - removed "rx-sector" ("Wl60gRxSector") value;
      *) snmp - report bridge ifSpeed as "0";
      *) snmp - report ifSpeed 0 for sub-layer interfaces;
      *) ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);
      *) ssh - added error log message when key exchange fails;
      *) ssh - close active SSH connections before IPsec connections on shutdown;
      *) ssh - fixed public key format compatibility with RFC4716;
      *) supout - fixed "poe-out" output not showing all interfaces;
      *) supout - fixed Profile output on single core devices;
      *) switch - added comment field to switch ACL rules;
      *) switch - fixed ACL rules on IPQ4018 devices;
      *) system - accept only valid path for "log-file" parameter in "port" menu;
      *) system - removed obsolete "/driver" command;
      *) tr069-client - added "check-certificate" parameter to allow communication without certificates;
      *) tr069-client - added "connection-request-port" parameter (CLI only);
      *) tr069-client - added support for InformParameter object;
      *) tr069-client - fixed certificate verification for certificates with IP address;
      *) tr069-client - fixed HTTP cookie getting duplicated with the same key;
      *) tr069-client - increased reported "rsrq" precision;
      *) traceroute - improved stability when sending large ping amounts;
      *) traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;
      *) tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with DNS as "remote-address";
      *) upgrade - made security package depend on DHCP package;
      *) usb - improved power-reset error message when no bus specified on CCR1072-8G-1S+;
      *) usb - improved USB device powering on startup for hAP ac^2 devices;
      *) usb - increased default power-reset timeout to 5 seconds;
      *) userman - added first and last name fields for signup form;
      *) userman - show redirect location in error messages;
      *) user - require "write" permissions for LTE firmware update;
      *) vrrp - made "password" parameter sensitive;
      *) w60g - added "10s-average-rssi" parameter to align mode (CLI only);
      *) w60g - added align mode "/interface w60g align" (CLI only);
      *) w60g - fixed scan in bridge mode;
      *) w60g - improved PtMP performance;
      *) w60g - improved reconnection detection;
      *) w60g - improved "tx-packet-error-rate" reading;
      *) w60g - renamed disconnection message when license level did not allow more connected clients;
      *) w60g - renamed "frequency-list" to "scan-list";
      *) watchdog - allow specifying DNS name for "send-smtp-server" parameter;
      *) webfig - improved file handling;
      *) winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;
      *) winbox - added "allow-dual-stack-queue" parameter in "IP/DHCP Server" and "IPv6/DHCP Server" menus;
      *) winbox - added "challenge-password" field when signing certificate with SCEP;
      *) winbox - added "conflict-detection" parameter in "IP/DHCP Server" menu;
      *) winbox - added "coordinate-format" parameter in LTE interface settings;
      *) winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;
      *) winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;
      *) winbox - added src/dst address and in/out interface list columns to default firewall menu view;
      *) winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab;
      *) winbox - allow setting "network-mode" to "auto" under LTE interface settings;
      *) winbox - allow specifying interface lists in "CAPsMAN/Access List" menu;
      *) winbox - fixed "IPv6/Firewall" "Connection limit" parameter not allowing complete IPv6 prefix lengths;
      *) winbox - fixed L2MTU parameter setting on "W60G" type interfaces;
      *) winbox - fixed "LCD" menu not shown on RB2011UiAS-2HnD;
      *) winbox - fixed missing w60g interface status values;
      *) winbox - improved file handling;
      *) winbox - moved "Too Long" statistics counter to Ethernet "Rx Stats" tab;
      *) winbox - organized wireless parameters between simple and advanced modes;
      *) winbox - renamed "Default AP Tx Rate" to "Default AP Tx Limit";
      *) winbox - renamed "Default Client Tx Rate" to "Default Client Tx Limit";
      *) winbox - show "R" flag under "IPv6/DHCP Server/Bindings" tab;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) winbox - show "W60G" wireless tab on wAP 60G AP;
      *) wireless - added new "installation" parameter to specify router's location;
      *) wireless - improved AR5212 response to incoming ACK frames;
      *) wireless - improved connection stability for new model Apple devices;
      *) wireless - improved NV2 performance for all ARM devices;
      *) wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);
      *) wireless - improved system stability for all ARM devices with wireless;
      *) wireless - improved system stability for all devices with 802.11ac wireless;
      *) wireless - improved system stability when scanning for other networks;
      *) wireless - removed G/N support for 2484MHz in "japan" regulatory domain;
      *) wireless - report last seen IP address in RADIUS accounting messages;
      *) wireless - show "installation" parameter when printing configuration;
      Что нового в версии 6.43.12 (2019-Feb-08 11:46):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.43.12:
      ----------------------
      !) winbox - improvements in connection handling to router with open winbox service (CVE-2019–3924);
      Что нового в версии 6.43.11 (2019-Feb-04 12:24):

      *) ipsec - accept only valid path for "export-pub-key" parameter in "key" menu;
      *) quickset - fixed "country" parameter not properly setting regulatory domain configuration;
      *) smb - fixed possible buffer overflow;
      *) w60g - fixed disconnection issues in PtMP setups;
      *) wireless - improved antenna gain setting for devices with built in antennas;
      *) wireless - show indoor/outdoor frequency limitations under "/interface wireless info country-info" command;
      Что нового в версии 6.43.10 (2019-Jan-24 07:09):

      (factory only release)
      Что нового в версии 6.43.9 (2019-Jan-10 07:11):

      (factory only release)
      Что нового в версии 6.43.7 (2018-Nov-30 09:01):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.43.7:
      ----------------------
      !) upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";
      !) upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;
      ----------------------

      Изменения в этом выпуске:

      *) bridge - properly disable dynamic CAP interfaces;
      *) certificate - fixed "expires-after" parameter calculation;
      *) certificate - fixed time zone adjustment for SCEP requests;
      *) certificate - properly flush old CRLs when changing store location;
      *) chr - fixed possible memory allocation failure when using multiple CPUs or interfaces on Xen installations;
      *) crs328 - fixed SFP ports not reporting auto-negotiation status;
      *) crs328 - improved link status update on disabled SFP and SFP+ interfaces;
      *) defconf - automatically accept default configuration if reset done by holding button;
      *) defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;
      *) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;
      *) discovery - fixed neighbor discovery for PPP interfaces;
      *) discovery - properly use System ID for "software-id" value on CHR;
      *) export - fixed "silent-boot" compact export;
      *) health - fixed bad voltage readings on RB493G;
      *) interface - improved system stability when including/excluding a list to itself;
      *) ipsec - fixed hw-aead (H) flag presence under Installed SAs on startup;
      *) ipsec - improved stability when uninstalling multiple SAs at once;
      *) ipsec - properly handle peer profiles on downgrade;
      *) ipsec - properly update warnings under peer menu;
      *) kidcontrol - do not allow users with "read" policy to pause and resume kids;
      *) log - properly handle long echo messages;
      *) lte - added support for more ZTE MF90 modems;
      *) ospf - improved stability while handling type-5 LSAs;
      *) routerboard - renamed SIM slots to "a" and "b" on SXT LTE kit;
      *) routerboard - show "boot-os" and "force-backup-booter" options only on devices that have such feature;
      *) snmp - do not initialise interface traps on bootup if they are not enabled;
      *) timezone - updated timezone information from tzdata2018g release;
      *) traffic-flow - fixed post NAT port reporting;
      *) traffic-flow - fixed "src-mac-address" and added "post-src-mac-address" fields;
      *) tunnel - made "ipsec-secret" parameter sensitive;
      *) usb - fixed power-reset for hAP ac^2 devices;
      *) user - speed up first time login process after upgrade from version older than v6.43;
      *) winbox - allow to specify SIM slot on LtAP mini;
      *) winbox - enabled "fast-forward" by default when adding new bridge;
      *) winbox - fixed neighbor discovery for IPv6 neighbors;
      *) winbox - show "System/Health" only on boards that have health monitoring;
      Что нового в версии 6.43.6 (2018-Nov-07 10:40):

      (factory only release)
      Что нового в версии 6.43.5 (2018-Oct-25 12:37):

      (factory only release)
      Что нового в версии 6.43.4 (2018-Oct-17 06:37):

      Изменения в этом выпуске:

      *) bridge - do not learn untagged frames when filtering only tagged packets;
      *) bridge - fixed possible memory leak when VLAN filtering is used;
      *) bridge - improved packet handling when hardware offloading is being disabled;
      *) bridge - properly forward unicast DHCP messages when using DHCP Snooping with hardware offloading;
      *) crs328 - improved link status update on disabled SFP+ interface when using DAC;
      *) crs3xx - fixed possible memory leak when disabling bridge interface;
      *) crs3xx - properly read "eeprom" data after different module inserted in disabled interface;
      *) dhcpv4-server - use client MAC address for dual stack queue when "client-id" is not received;
      *) dhcpv6-server - fixed dynamic binding addition on solicit when IA_PD does not contain prefix (introduced in v6.43);
      *) dhcpv6-server - recreate DHCPv6 server binding if it is no longer within prefix pool when rebinding/renewing;
      *) ipsec - allow multiple peers to the same address with different local-address (introduced in v6.43);
      *) led - added "dark-mode" functionality for LHG and LDF series devices;
      *) led - added "dark-mode" functionality for wsAP ac lite, RB951Ui-2nD, hAP and hAP ac lite devices;
      *) led - fixed default LED configuration for SXT LTE kit devices;
      *) led - fixed power LED turning on after reboot when "dark-mode" is used;
      *) ntp - fixed possible NTP server stuck in "started" state;
      *) romon - improved packet processing when MTU in path is lower than 1500;
      *) routerboard - show "boot-os" option only on devices that have such feature;
      *) traffic-flow - fixed post NAT port reporting;
      *) w60g - added "frequency-list" setting;
      *) w60g - added interface stats;
      *) w60g - fixed interface LED status update on connection;
      *) w60g - general stability and performance improvements;
      *) w60g - improved stability for short distance links;
      *) w60g - renamed "mcs" to "tx-mcs" and "phy-rate" to "tx-phy-rate";
      Что нового в версии 6.43.3 (2018-Oct-05 13:12):

      (factory only release)
      Что нового в версии 6.43.2 (2018-Sep-18 12:12):

      Изменения в этом выпуске:

      *) routerboot - fixed RouterOS booting on devices with particular NAND memory (introduced in v6.43);
      Что нового в версии 6.43.1 (2018-Sep-17 06:53):

      Изменения в этом выпуске:

      *) crs317 - fixed packet forwarding on bonded interfaces without hardware offloading;
      *) defconf - properly clear global variables when generating default configuration after RouterOS upgrade;
      *) dhcpv6-client - log only failed pool additions;
      *) hotspot - properly update dynamic "walled-garden" entries when changing "dst-host";
      *) ike2 - fixed rare authentication and encryption key mismatches after rekey with PFS enabled;
      *) lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;
      *) rb3011 - added IPsec hardware acceleration support;
      *) routerboard - fixed memory tester reporting false errors on IPQ4018 devices ("/system routerboard upgrade" required);
      *) sniffer - made "connection", "host", "packet" and "protocol" sections read-only;
      *) switch - fixed port mirroring on devices that do not support CPU Flow Control;
      *) upnp - improved UPnP service stability when handling HTTP requests;
      *) webfig - allow to change user name when creating a new system user (introduced in v6.43);
      *) webfig - fixed time interval settings not applied properly under "IP/Kid Control/Kids" menu;
      *) winbox - added "allow-dual-stack-queue" setting to "IP/DHCP Server/Leases" menu;
      *) winbox - added "allow-dual-stack-queue" setting to "IPv6/DHCPv6 Server/Bindings" menu;
      *) winbox - fixed corrupt user database after specifying allowed address range (introduced in v6.43);
      *) winbox - make bridge port "untrusted" by default when creating new port;
      *) winbox - show "IP/Cloud" menu on CHR;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
      *) wireless - removed "czech republic 5.8" regulatory domain information as it overlaps with "ETSI 5.7-5.8";
      Что нового в версии 6.43 (2018-Sep-06 12:44):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.43:
      ----------------------
      !) api - changed authentication process (https://wiki.mikrotik.com/wiki/Manual:API#Initial_login);
      !) backup - do not encrypt backup file unless password is provided;
      !) btest - requires at least v6.43 Bandwidth Test client when connecting to v6.43 or later version server except when authentication is not required;
      !) cloud - added IPv6 support;
      !) cloud - added support for licensed CHR instances (including trial);
      !) cloud - reworked "/ip cloud ddns-enabled" implementation (suggested to disable service and re-enable after installation process);
      !) radius - use MS-CHAPv2 for "login" service authentication;
      !) romon - require at least v6.43 RoMON agent when connecting to v6.43 or later RoMON client device;
      !) webfig - improved authentication process;
      !) winbox - improved authentication process excluding man-in-the-middle possibility;
      !) winbox - minimal required version is v3.15;
      ----------------------

      Изменения в этом выпуске:

      *) backup - added support for new backup file encryption (AES128-CTR) with signatures (SHA256);
      *) backup - generate proper file name when devices identity is longer than 32 symbols;
      *) bridge - add dynamic CAP interface to tagged ports if "vlan-mode=use-tag" is enabled;
      *) bridge - added an option to manually specify ports that have a multicast router (CLI only);
      *) bridge - added a warning when untrusted port receives a DHCP Server message when DCHP Snooping is enabled;
      *) bridge - added ingress filtering options to bridge interface;
      *) bridge - added initial Q-in-Q support;
      *) bridge - added more options to fine-tune IGMP Snooping enabled bridges (CLI only);
      *) bridge - added per-port based "tag-stacking" feature;
      *) bridge - added support for BPDU Guard;
      *) bridge - added support for DHCP Option 82;
      *) bridge - added support for DHCP Snooping;
      *) bridge - added support for IGMP Snooping fast-leave feature (CLI only);
      *) bridge - fixed dynamic VLAN table entries when using ingress filtering;
      *) bridge - fixed "ingress-filtering", "frame-types" and "tag-stacking" value storing;
      *) bridge - forward LACPDUs when "protocol-mode=none";
      *) bridge - ignore tagged BPDUs when bridge VLAN filtering is used;
      *) bridge - improved packet handling;
      *) bridge - improved packet processing when bridge port changes states;
      *) bridge - improved performance when bridge VLAN filtering is used without hardware offloading;
      *) bridge - renamed option "vlan-protocol" to "ether-type";
      *) capsman - added ability to use chain 3 for "HT TX chains" and "HT RX chains" selections (CLI only);
      *) capsman - allow to change "radio-name" (CLI only);
      *) capsman - increase timeout for the CAP to CAPsMAN communication;
      *) certificate - added "expires-after" parameter;
      *) certificate - do not allow to perform "undo" on certificate changes;
      *) certificate - fixed RA "server-url" setting;
      *) check-installation - improved system integrity checking;
      *) chr - added checksum offload support for Hyper-V installations;
      *) chr - added large send offload support for Hyper-V installations;
      *) chr - added multiqueue support on Xen installations;
      *) chr - added support for multiqueue feature on "virtio-net";
      *) chr - added virtual Receive Side Scaling support for Hyper-V installations (might require more RAM assigned than in previous versions);
      *) chr - by default enable link state tracking for virtual drivers with "/interface ethernet disable-running-check=no";
      *) chr - do not show IRQ entries from removed devices;
      *) chr - fixed interface name assign process when running CHR on Hyper-V;
      *) chr - fixed interface name order when "virtio-net is not being used on KVM installations;
      *) chr - fixed MTU changing process when running CHR on Hyper-V;
      *) chr - fixed NIC hotplug for "virtio-net";
      *) chr - improved balooning process;
      *) chr - improved boot time for Hyper-V installations;
      *) chr - provide part of network interface GUID at the beginning of "bindstr2" value when running CHR on Hyper-V;
      *) chr - reduced RAM memory required per interface;
      *) cloud - added simultaneous IPv4/IPv6 support;
      *) cloud - close local UDP port if no activity;
      *) console - added "dont-require-permissions" parameter for scripts;
      *) console - added error log message when netwatch tries to execute script with insufficient permissions;
      *) console - added error log message when scheduler tries to execute script with insufficient permissions;
      *) console - do not show spare parameters on ping command;
      *) console - made "once" parameter mandatory when using "as-value" on "monitor" commands;
      *) console - removed automatic swapping of "from=" and "to=" in "for" loops;
      *) crs317 - fixed Ethernet inteface stuck on 100 Mbps speed;
      *) crs326/crs328 - fixed packet forwarding when port changes states with IGMP Snooping enabled;
      *) crs328 - fixed transmit on sfp-sfpplus1 and sfp-sfpplus2 interfaces;
      *) crs3xx - added hardware support for DHCP Snooping and Option 82;
      *) crs3xx - added Q-in-Q hardware offloading support;
      *) crs3xx - do not report SFP interface as running when interface on opposite side is disabled;
      *) crs3xx - fixed ACL rate rules (introduced in v6.41rc27);
      *) crs3xx - fixed flow control;
      *) crs3xx - fixed SwOS config import;
      *) defconf - fixed default configuration for RBSXTsq5nD;
      *) defconf - fixed missing bridge ports after configuration reset;
      *) dhcp - added dynamic IPv4/IPv6 "dual-stack" simple queue support, based on client's MAC address;
      *) dhcp - reduced resource usage of DHCP services;
      *) dhcpv4-client - fixed DHCP client that was stuck on invalid state;
      *) dhcpv4-client - fixed double ACK packet handling;
      *) dhcpv4-server - added "allow-dual-stack-queue" implementation (CLI only);
      *) dhcpv4-server - do not allow override lease "always-broadcast" value based on offer type;
      *) dhcpv4-server - improved performance when "rate-limit" and/or "address-list" setting is present;
      *) dhcpv6-client - added missing "Server identifier" parameter in release message;
      *) dhcpv6-client - fixed "add-default-route" parameter;
      *) dhcpv6-client - fixed option handling;
      *) dhcpv6-client - improved dynamic IPv6 pool addition process;
      *) dhcpv6-server - added additional RADIUS parameters for Prefix delegation, "rate-limit" and "life-time";
      *) dhcpv6-server - added "allow-dual-stack-queue" implementation (CLI only);
      *) dhcpv6-server - added initial dynamic simple queue support;
      *) dhcpv6-server - do not allow to run DHCPv6 server on slave interface;
      *) dhcpv6-server - fixed dynamic simple queue creation for RADIUS bindings;
      *) dns - fixed DNS cache service becoming unresponsive when active Hotspot server is present on the router (introduced in 6.42);
      *) dude - fixed client auto upgrade (broken since 6.43rc17);
      *) ethernet - do not show "combo-state" field if interface is not SFP or copper;
      *) ethernet - properly handle Ethernet interface default configuration;
      *) export - do not show w60g password on "hide-sensitive" type of export;
      *) fetch - added "as-value" output format;
      *) fetch - fixed address and DNS verification in certificates;
      *) filesystem - fixed NAND memory going into read-only mode (requires "factory-firmware" >= 3.41.1 and "current-firmware" >= 6.43);
      *) filesystem - improved software crash handling on devices with FLASH type memory;
      *) health - added missing parameters from export;
      *) health - fixed voltage measurements for RB493G devices;
      *) health - improved speed of health measurement readings;
      *) hotspot - allow to properly configure Hotspot directory on external disk for devices that have flash type storage;
      *) hotspot - fixed RADIUS CoA & PoD by allowing to accept "NAS-Port-Id";
      *) ike1 - added unsafe configuration warning for main mode with pre-shared-key authentication;
      *) ike1 - purge both SAs when timer expires;
      *) ike1 - zero out reserved bytes in NAT-OA payload;
      *) ike2 - fixed initiator first policy selection;
      *) ike2 - fixed rekeyed child deletion during another exchange;
      *) ike2 - improved basic exchange logging readability;
      *) ike2 - use "/32" netmask by default on initiator if not provided by responder;
      *) interface - improved interface "last-link-down-time" and "last-link-up-time" values;
      *) interface - improved reliability on dynamic interface handling;
      *) ippool - improved used address error message;
      *) ipsec - added "responder" parameter for "mode-config" to allow multiple initiator configurations;
      *) ipsec - added "src-address-list" parameter for "mode-config" that generates dynamic "src-nat" rule;
      *) ipsec - added warning messages for incorrect peer configuration;
      *) ipsec - do not allow removal of "proposal" and "mode-config" entries that are in use;
      *) ipsec - fixed AES-192-CTR fallback to software AEAD on ARM devices with wireless and RB3011UiAS-RM;
      *) ipsec - fixed AES-CTR and AES-GCM key size proposing as initiator;
      *) ipsec - fixed "static-dns" value storing;
      *) ipsec - improved invalid policy handling when a valid policy is uninstalled;
      *) ipsec - improved reliability on generated policy addition when IKEv1 or IKEv2 used;
      *) ipsec - improved stability when using IPsec with disabled route cache;
      *) ipsec - install all DNS server addresses provided by "mode-config" server;
      *) ipsec - separate phase1 proposal configuration from peer menu;
      *) ipsec - separate phase1 proposal configuration from peer menu;
      *) ipsec - use monotonic timer for SA lifetime check;
      *) kidcontrol - allow to edit discovered devices;
      *) l2tp - allow setting "max-mtu" and "max-mru" bigger than 1500;
      *) led - improved w60g alignment trigger;
      *) leds - fixed LED behaviour when bonding is configured on SFP+ interfaces;
      *) log - fixed false log warnings about system status after power on for CRS328-4C-20S-4S+;
      *) log - show interface name on OSPF "different MTU" info log messages;
      *) lte - added additional D-Link PIDs;
      *) lte - added additional ID support for SIM7600 modem;
      *) lte - added additional low endpoint SIM7600 PIDs;
      *) lte - added eNB ID to info command;
      *) lte - added extended LTE signal info for SIM7600 modules;
      *) lte - added extended signal information for Quectel LTE EC25 and EP06 modem;
      *) lte - added ICCID reading for info command R11e-LTE and R11e-LTE-US;
      *) lte - added "registration-status" parameter under "/interface lte info" command;
      *) lte - added roaming status reading for info command;
      *) lte - added "sector-id" to info command;
      *) lte - added support for alternative SIM7600 PID;
      *) lte - added support for Novatel USB730LN modem with new ID;
      *) lte - added support for Quanta 1k6e modem;
      *) lte - allow to execute concurrent internal AT commands;
      *) lte - allow to use multiple PLS modems at the same time;
      *) lte - do not allow to remove default APN profile;
      *) lte - do not allow to send "at-chat" commands for configless modems;
      *) lte - expose GPS channel for PLS modems;
      *) lte - fixed LTE registration in 2G/3G mode;
      *) lte - fixed SIM7600 registration info;
      *) lte - fixed SIM7600 series module support with newer device IDs;
      *) lte - ignore empty MAC addresses during Passthrough discovery phase;
      *) lte - improved modem event processing;
      *) lte - improved r11e-LTE and r11e-LTE-US dialling process;
      *) lte - improved r11e-LTE configuration exchange process;
      *) lte - improved reading of SMS message after entering running state;
      *) lte - improved readings of info command results for the SXT LTE;
      *) lte - improved stability of USB LTE interface detection process;
      *) lte - properly detect interface state when running for IPv6 only connection for R11e-LTE modem;
      *) lte - renamed LTE scan tool field "scan-code" to "mcc-mnc";
      *) lte - show UICC in correct format for SXT LTE devices;
      *) lte - use "/32" address for the Passthrough feature when R11e-LTE module is used;
      *) lte - use alphanumeric operator format in info command;
      *) mac-telnet - improved reliability when connecting from RouterOS versions prior 6.43;
      *) multicast - allow to add more than one RP per IP address for PIM;
      *) ntp - allow to specify link-local address for NTP server;
      *) ospf - improved link-local LSA flooding;
      *) ospf - improved stability when originating LSAs with OSPFv3;
      *) package - renamed "current-version" to "installed-version" under "/system package install";
      *) ppp - added support for additional ID for E3531 modem;
      *) ppp - added support for Alfa Network U4G modem;
      *) ppp - added support for Telit LM940 modem;
      *) ppp - improved modem mode switching;
      *) ppp - show comments from "/ppp secrets" menu within "/ppp active" menu when client is connected;
      *) quickset - recognize 160 MHz channel as HomeAP mode;
      *) rb1100ahx4 - added DES and 3DES hardware acceleration support;
      *) romon - fixed RoMON services becoming unavailable after disabled once during active scanning process;
      *) romon - properly classify RoMON sessions in log and active users list;
      *) routerboard - allow to fill up to half of the RAM memory with files on devices with FLASH storage;
      *) routerboard - fixed "protected-routerboot" feature (introduced in v6.42);
      *) routerboard - fixed wrongly reported RAM size on ARM devices;
      *) routerboot - removed RAM test from TILE devices (routerboot upgrade required);
      *) sfp - fixed default advertised link speeds;
      *) smb - fixed valid request handling when additional options are used;
      *) sms - converted "keep-max-sms" feature to "auto-erase";
      *) sms - do not require "port" and "interface" parameters when sending SMS if already present in configuration;
      *) sms - improved reliability on SMS reader;
      *) snmp - added CAPsMAN "remote-cap" table;
      *) snmp - added EAP identity to CAPsMAN registration table;
      *) snmp - added "phy-rate" reading for "station-bridge" mode;
      *) snmp - added "temp-exception" trap;
      *) snmp - fixed interface speed reporting for predefined rates;
      *) snmp - fixed "remote-cap" peer MAC address format;
      *) ssh - disconnect all active connections when device gets rebooted or turned off;
      *) ssh - strengthen strong-crypto (add aes-128-ctr and disallow hmac sha1 and groups with sha1);
      *) supout - added "files" section to supout file;
      *) supout - added info log message when supout file is created;
      *) supout - added monitored bridge VLAN table to supout file;
      *) supout - added "w60g" section to supout file;
      *) switch - added CPU Flow Control settings for devices with a Atheros8227, QCA8337, Atheros8327, Atheros7240 or Atheros8316 switch chip;
      *) switch - added support for port isolation by switch chip;
      *) switch - fixed possible switch chip hangs after initialization on MediaTek and Atheros8327 switch chips;
      *) swos - implemented "/system swos" menu that allows to upgrade, reset, save or load configuration and change address for dual-boot CRS devices (CLI only);
      *) tile - added DES and 3DES hardware acceleration support;
      *) tile - fixed false HW offloading flag for MPLS;
      *) tr069-client - allow editing of "provisioning-code" attribute;
      *) tr069-client - fixed setting of "DeviceInfo.ProvisioningCode" parameter;
      *) tr069-client - use SNI extension for HTTPS;
      *) upgrade - fixed RouterOS upgrade process from RouterOS v5 on PowerPC;
      *) ups - improved UPS serial parsing stability;
      *) usb - fixed modem initialisation on LtAP mini;
      *) usb - fixed power-reset for hAP ac^2 devices;
      *) user - all passwords are now hashed and encrypted, plaintext passwords are kept for downgrade (will be removed in later upgrades);
      *) userman - fixed "shared-secret" parameter requiring "sensitive" policy;
      *) vrrp - improved reliability on VRRP interface configured as a bridge port when "use-ip-firewall" is enabled;
      *) w60g - added "beamforming-event" stats counter;
      *) w60g - fixed random disconnects;
      *) w60g - general stability and performance improvements;
      *) watchdog - added "ping-timeout" setting;
      *) webfig - do not automatically re-log in after logging out;
      *) webfig - fixed occasional authentication failure when logging in;
      *) webfig - fixed www service becoming unresponsive;
      *) webfig - properly display time interval within Kid Control menu;
      *) webfig - properly handle double clicking when logging in or out;
      *) webfig - properly show NTP clients "last-adjustment" value;
      *) winbox - added bridge Fast Forward statistics counters;
      *) winbox - added "poe-fault" LED trigger;
      *) winbox - added "tag-stacking" option to "Bridge/Ports";
      *) winbox - allow to specify LTE interface when sending SMS;
      *) winbox - fixed arrow key handling within table filter fields;
      *) winbox - fixed "bad-blocks" value presence under "System/Resources";
      *) winbox - fixed bridge port MAC learning parameter values;
      *) winbox - fixed "IP/IPsec/Peers" section sorting;
      *) winbox - fixed "write-sect-since-reboot" value presence under "System/Resources";
      *) winbox - properly close session when uploading multiple files to the device at the same time;
      *) winbox - removed duplicate "20/40/80MHz" value from "channel-width" setting options;
      *) winbox - renamed "VLAN Protocol" to "EtherType" under bridge interface "VLAN" tab;
      *) winbox - show HT MCS tab when "5ghz-n/ac" band is used;
      *) winbox - show "Switch" menu on hAP ac^2 devices;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that has such feature;
      *) wireless - accept only valid path for sniffer output file parameter;
      *) wireless - accept only valid path for sniffer output file parameter;
      *) wireless - added "czech republic 5.8" regulatory domain information;
      *) wireless - added "etsi2" regulatory domain information;
      *) wireless - added option for RADIUS "called-station-id" format selection;
      *) wireless - added option to disable PMKID for WPA2;
      *) wireless - do not disconnect clients when WDS master connects with MAC address "00:00:00:00:00:00";
      *) wireless - fixed "/interface wireless sniffer packet print follow" output;
      *) wireless - fixed wireless interface lockup after period of inactivity;
      *) wireless - improved Nv2 reliability on ARM devices;
      *) wireless - improved Nv2 stability for 802.11n interfaces on RB953, hAP ac and wAP ac devices;
      *) wireless - require "sniff" policy for wireless sniffer;
      *) wireless - updated "czech republic" regulatory domain information;
      *) wireless - updated "germany 5.8 ap" and "germany 5.8 fixed p-p" regulatory domain information;
      *) x86 - improved Ethernet driver for Davicom DM9x0x;
      Что нового в версии 6.42.7 (2018-Aug-17 09:48):

      ОСНОВНЫЕ ИЗМЕНЕНИЯ v6.42.7:
      ----------------------
      !) security - fixed vulnerabilities CVE-2018-1156, CVE-2018-1157, CVE-2018-1158, CVE-2018-1159;
      ----------------------

      *) bridge - improved bridge port state changing process;
      *) crs326/crs328 - fixed untagged packet forwarding through tagged ports when pvid=1;
      *) crs3xx - added command that forces fan detection on fan-equipped devices;
      *) crs3xx - fixed port disable on CRS326 and CRS328 devices;
      *) crs3xx - fixed tagged packet forwarding without VLAN filtering (introduced in 6.42.6);
      *) crs3xx - fixed VLAN filtering when there is no tagged interface specified;
      *) dhcpv4-relay - fixed false invalid flag presence;
      *) dhcpv6-client - allow to set "default-route-distance";
      *) dhcpv6 - improved reliability on IPv6 DHCP services;
      *) dhcpv6-server - properly update interface for dynamic DHCPv6 servers;
      *) ethernet - improved large packet handling on ARM devices with wireless;
      *) ethernet - removed obsolete slave flag from "/interface vlan" menu;
      *) ipsec - fixed "sa-src-address" deduction from "src-address" in tunnel mode;
      *) ipsec - improved invalid policy handling when a valid policy is uninstalled;
      *) ldp - properly load LDP configuration;
      *) led - fixed default LED configuration for RBLHGG-5acD-XL devices;
      *) lte - added signal readings under "/interface lte scan" for 3G and GSM modes;
      *) lte - fixed memory leak on USB disconnect;
      *) lte - fixed SMS send feature when not in LTE network;
      *) package - do not allow to install out of bundle package if it already exists within bundle;
      *) ppp - fixed interface enabling after a while if none of them where active;
      *) sfp - hide "sfp-wavelength" parameter for RJ45 transceivers;
      *) tr069-client - fixed unresponsive tr069 service when blackhole route is present;
      *) upgrade - fixed RouterOS upgrade process from RouterOS v5;
      *) userman - fixed compatibility with PayPal TLS 1.2;
      *) vrrp - fixed VRRP packet processing on VirtualBox and VMWare hypervisors;
      *) w60g - added distance measurement feature;
      *) w60g - fixed random disconnects;
      *) w60g - general stability and performance improvements;
      *) w60g - improved MCS rate detection process;
      *) w60g - improved MTU change handling;
      *) w60g - properly close connection with station on disconnect;
      *) w60g - stop doing distance measurements after first successful measurement;
      *) winbox - added "secondary-channel" setting to wireless interface if 80 MHz mode is selected;
      *) winbox - fixed "sfp-connector-type" value presence under "Interface/Ethernet";
      *) winbox - fixed warning presence for "IP/IPsec/Peers" menu;
      *) winbox - properly display all flags for bridge host entries;
      *) winbox - show "System/RouterBOARD/Mode Button" on devices that has such feature;
      *) wireless - added option to disable PMKID for WPA2;
      *) wireless - fixed memory leak when performing wireless scan on ARM;
      *) wireless - fixed packet processing after removing wireless interface from CAP settings;
      *) wireless - updated "united-states" regulatory domain information;
      Что нового в версии 6.42.6 (2018-Jul-06 11:56):

      *) bridge - improved packets processing when bridge port changes states;
      *) crs3xx - fixed bonding slave failover when packets are sent out of the bridge interface;
      *) crs3xx - fixed LACP member failover;
      *) crs3xx - improved link state detection when one side has disabled interface;
      *) defconf - fixed bridge default configuration for SOHO devices with more than 9 Ethernet interfaces;
      *) package - free up used storage space consumed by old RouterOS upgrades;
      *) snmp - fixed w60g "phy-rate" readings;
      *) supout - added "ip-cloud" section to supout file;
      *) w60g - fixed random disconnects;
      *) w60g - general stability and performance improvements;
      *) winbox - added 64,8 GHz frequency to w60g interface frequency settings;
      *) winbox - show "sector-writes" on devices that have such counters;
      Что нового в версии 6.42.5 (2018-Jun-26 12:12):

      *) api - properly classify API sessions in log;
      *) chr - enabled promiscuous mode (requires to be enabled on host as well) when running CHR on Hyper-V;
      *) kidcontrol - added dynamic accept firewall rules to allow bandwidth limit when FastTrack is enabled;
      *) led - fixed LED default configuration for LtAP mini;
      *) snmp - added "rssi" and "tx-sector-info" value support for w60g type interfaces;
      *) snmp - added station "distance", "phy-rate", "rssi" value support for w60g type interfaces;
      *) ssh - allow to use "diffie-hellman-group1-sha1" on TILE and x86 devices with "strong-crypto" disabled;
      *) w60g - added 4th 802.11ad channel (CLI only);
      *) w60g - added distance measurement;
      *) w60g - do not reset interface after adding comment;
      *) w60g - general stability and performance improvements;
      *) w60g - improved maximum achievable distance;
      *) w60g - properly report center status under "tx-sector-info";
      *) winbox - show "sector-writes" on ARM devices that have such counters;
      *) winbox - show "System/Health" only on devices that have health monitoring;
      Что нового в версии 6.42.4 (2018-Jun-15 14:14):

      *) bridge - allow to make changes for bridge port when it is interface list;
      *) bridge - fixed FastPath for bridge master interfaces (introduced in v6.42);
      *) certificate - fixed "add-scep" template existence check when signing certificate;
      *) chr - fixed adding MSTI entries;
      *) chr - fixed boot on hosts older than Windows Server 2012 when running CHR on Hyper-V;
      *) chr - fixed various network hang scenarios when running CHR on Hyper-V;
      *) console - fixed script permissions if script is executed by other RouterOS service;
      *) dhcpv4-server - fixed DHCP server that was stuck on invalid state;
      *) health - changed "PSU-Voltage" to "PSU-State" for CRS328-4C-20S-4S+;
      *) health - fixed incorrect PSU index for CRS328-4C-20S-4S+;
      *) ipsec - improved reliability on IPsec hardware encryption for RB1100Dx4;
      *) kidcontrol - fixed dynamically created firewall rules order;
      *) led - added "dark-mode" functionality for hEX S and SXTsq 5 ac devices;
      *) led - fixed CCR1016-12S-1S+ LED behaviour after Netinstall (introduced in v6.41rc58);
      *) led - use routers uptime as a starting point when turning off LEDs if option was not enabled on boot;
      *) ppp - fixed "hunged up" grammar to "hung up" within PPP log messages;
      *) quickset - added missing wireless "channel-width" settings;
      *) quickset - added support for "5ghz-a/n" band when CPE mode is used;
      *) snmp - added remote CAP count OID for CAPsMAN;
      *) snmp - fixed readings for CAPsMAN slave interfaces;
      *) supout - added "partitions" section to supout file;
      *) usb - properly detect USB 3.0 flash on RBM33G when jumper is removed;
      *) userman - improved unique username generation process when adding batch of users;
      *) w60g - improved RAM memoy allocation processes;
      *) winbox - added missing "dscp" and "clamp-tcp-mss" settings to IPv6 tunnels;
      *) winbox - allow to specify full URL in SCEP certificate signing process;
      *) winbox - by default specify keepalive timeout value for tunnel type interfaces;
      *) winbox - show "scep-url" for certificates;
      *) winbox - show "System/Health" only on boards that have health monitoring;
      *) winbox - show firmware upgrade message at the bottom of "System/RouterBOARD" menu;
      *) wireless - enable all chains by default on devices without external antennas after configuration reset;
      *) wireless - improved Nv2 reliability on ARM devices;
      Что нового в версии 6.42.3 (2018-May-24 09:20):

      *) lte - fixed automatic LTE band selection for R11e-LTE;
      *) wireless - improved client "channel-width" detection;
      *) wireless - improved Nv2 PtMP performance;
      *) wireless - increased stability on hAP ac^2 and cAP ac with legacy data rates;
      Что нового в версии 6.42.2 (2018-May-17 09:20):

      *) bridge - do not allow to add same interface list to bridge more than once;
      *) bridge - fixed LLDP packet receiving;
      *) bridge - fixed processing of fragmented packets when hardware offloading is enabled;
      *) console - fixed type "on" and "wireless-status" LED trigger value setting (introduced in v6.42.1);
      *) crs317 - fixed link flapping when inserted S+RJ10 module without any cable;
      *) defconf - fixed wAP LTE kit default configuration;
      *) dhcpv4 - prevent sending out ICMP port unreachable packets;
      *) dhcpv4-client - fixed DHCP client stuck in renewing state;
      *) dhcpv6-relay - fixed missing configuration after reboot;
      *) filesystem - fixed NAND memory going into read-only mode;
      *) hotspot - fixed user authentication when queue from old session is not removed yet;
      *) interface - fixed "built-in=no" parameter for manually created interface lists;
      *) interface - fixed "dynamic" built-in interface list behaviour;
      *) interface - fixed interface list which include disabled member;
      *) interface - fixed interface list which include/exclude another list;
      *) interface - fixed interface configuration responsiveness;
      *) ipsec - fixed policies becoming invalid if added after a disabled policy;
      *) ipsec - improved reliability on IPsec hardware encryption for ARM devices except RB1100Dx4;
      *) led - added "dark-mode" functionality for hAP ac and hAP ac^2 devices;
      *) lte - improved LTE communication process on MMIPS platform devices;
      *) quickset - fixed dual radio mode detection process;
      *) routerboard - properly represent board name for hAP ac^2;
      *) tile - fixed Ethernet interfaces becoming unresponsive;
      *) winbox - allow to specify "any" as wireless "access-list" interface;
      *) winbox - fixed "/ip dhcp-server network set dns-none" parameter;
      *) wireless - enable all chains by default on devices without external antennas after configuration reset;
      *) wireless - fixed packet processing when "static-algo-0=40bit-wep" is being used (introduced in v6.42);
      *) wireless - fixed usage of allowed signal strength values received from RADIUS;
      *) wireless - improved wireless throughput on hAP ac^2 and cAP ac;
      *) x86 - fixed reboot caused by MAC Winbox connection;
      Что нового в версии 5.26 (2013-Sep-04 15:01):

      *) ssh - fixed denial of service;

      Что нового в версии 5.25 (2013-Apr-25 15:59):

      *) web proxy - speed up startup;
      *) metarouter - fixed occasional lockups on mipsbe boards;
      *) wireless - update required when using small width channel RB2011 RB9xx
      caveat: update remote end/s before updating AP as both side are required to use new/same version for a link
      !) added support for Let's Encrypt certificate generation;
      !) added L3 HW support for all CRS3xx devices;
      !) added MLAG support for CRS3xx devices (CLI only);
      !) ported features and fixes introduced in v6.49;
      *) other minor fixes and improvements;
      !) added support for IPv6 NAT (CLI only);
      !) added support for L2TPv3 (CLI only);
      *) added "expired" user status with suggestion to change password (WinBox v3.29 required);
      *) added bridge HW offload support for vlan-filtering on RTL8367 switch chip (RB4011, RB1100AHx4);
      *) added password strength requirement settings;
      *) added skin support for WinBox (WinBox v3.29 required);
      *) fixed support for RIP (Routing Information Protocol);
      *) improved general stability and performance;
      *) other minor fixes and improvements;
      !) added new "iot" package with initial Bluetooth (KNOT only) and MQTT publisher support;
      !) ported features and fixes introduced in v6.48.1;
      !) enabled initial MPLS support (CLI only);
      *) export - fixed "export" command hanging;
      *) wifiwave2 - improved interface stability with multiple WPA3 authenticated clients;
      *) other minor fixes and improvements;
      *) api - added support for REST API; *) crs3xx - fixed Layer3 hardware offloading; *) route - routing rules improvements; *) winbox - added support for wifiwave2; *) winbox - updated User Manager, OSPF and BGP menus; *) wifiwave2 - authentication and functionality improvements; *) other fixes and improvements;
      Что нового 7.1beta4 (2021-Feb-03 09:39):

      *) api - added support for REST API;
      *) crs3xx - fixed Layer3 hardware offloading;
      *) route - routing rules improvements;
      *) winbox - added support for wifiwave2;
      *) winbox - updated User Manager, OSPF and BGP menus;
      *) wifiwave2 - authentication and functionality improvements;
      *) other fixes and improvements;
      Что нового в версии 7.1beta3 (2020-Dec-02 15:59):

      !) added support for "Cake" and "FQ_Codel" type queues;
      !) added new experimental wireless package "wifiwave2" for ARM devices with more than 256 MB of RAM (CLI only);
      *) bgp - template parameters are now exposed in connection;
      *) chr - added support for SR-IOV
      *) routing - added "route", "routing table", "route rules" and BGP configuration migration from RouterOS v6 after upgrade;
      *) routing - renamed "instance" menu to "id";
      *) other fixes and improvements;
      Что нового в версии 7.1beta2 (2020-Aug-21 12:29):

      !) added "bgp-network" output filter flag;
      !) added bonding interface support for Layer3 hardware offloading;
      !) added IPv6 nexthop support for IPv4 routes;
      !) added Layer3 hardware offloading support for CRS309-1G-8S+IN, CRS312-4C+8XG-RM and CRS326-24S+2Q+RM;
      !) added WireGuard support;
      *) disk - improved external disk read/write speed;
      *) ospf - fixed point to point routes becoming inactive;
      *) route - fixed source address selection of outgoing packets;
      *) other minor fixes and improvements;
      Что нового в версии 7.1beta1 (2020-Jul-21 08:58):

      !) added FastTrack and NAT hardware offloading support for CRS317-1G-16S+RM;
      !) ported features and fixes introduced in v6.47.1;
      *) route - added rpki-check;
      *) route - bgp improvements;
      *) route - do not allow modifying/deleting "main" table;
      *) route - fixed incorrectly interpreted prefix states received from RTR;
      *) route - fixed IPv6 ECMP connected routes;
      *) route - fixed IPv6 policy routing;
      *) route - routing rules improvements;
      *) wireless - fixed wireless performance for 802.11b/g/n and 802.11a/n interfaces on non-ARM architecture devices;
      *) other minor fixes and improvements;
      Что нового в версии 7.0beta8 (2020-Jun-4 15:04):

      *) fixed CLI dependencies for routing menu;
      Что нового в версии 7.0beta7 (2020-Jun-3 16:31):

      !) added Layer3 hardware offloading support for CRS317-1G-16S+RM more info here: https://wiki.mikrotik.com/wiki/Manual:CRS3xx_series_switches#L3_Hardware_Offloading
      !) enabled BGP support with multicore peer processing (CLI only);
      !) enabled RPKI support (CLI only);
      !) ported features and fixes introduced in v6.47;
      !) routing updates, complete status report: https://help.mikrotik.com/docs/display/ROS/v7+Routing+Protocol+Status
      !) system kernel has been updated to version 5.6.3;
      *) other minor fixes and improvements;
      Что нового в версии 7.0beta5 (2020-Feb-7 11:56):

      Introduced issues:

      - RB850Gx2 and RB911 does not boot

      Новые функции в этом выпуске:

      !) x86 - introduced UEFI boot mode support;
      !) vxlan - added support for Virtual eXtensible Local Area Network (VXLAN);
      !) vrrp - added connection tracking data replication from VRRP master to backup;
      !) vrrp - added support for VRRP grouping;
      !) winbox - minimal required version is v3.21;
      *) other minor fixes and improvements;
      Что нового в версии 7.0beta4 (2019-Dec-06 13:21):

      !) included all features and fixes from 6.46 version;
      !) implemented completely new User Manager package;
      *) dhcpv4-server - added "option-set" parameter for each "vendor-class-id";
      *) dhcpv4-server - added "radius-password' parameter under "config" menu;
      *) dhcpv6-client - allow reading passed options in script;
      *) dhcpv6-relay - include client's Link-Layer address in option 79;
      *) interface - improved support for Intel, Mellanox and other generic network cards;
      *) ipsec - fixed action=none policies;
      *) ipv6 - added "disable-ipv6" parameter;
      *) lte - added support for Quectel EC25-E;
      *) lte - added support for Sierra Wireless MC7304;
      *) lte - improved system stability when resetting modem;
      *) package - fixed USB and CD-ROM installs;
      *) ssh - improved key exchange algorithm support;
      *) system - fixed port duplication on each system reboot;
      ## Общая информация

      +) Based on Kernel 4.14.131
      +) New CLI style which is more similar to API commands (v6 commands still supported)
      +) OpenVPN UDP protocol support added
      +) New NTP client and server implementation, both now included in RouterOS main package
      +) removed individual packages, only bundle and a few extra packages will remain
      +) ipv6 is now built into RouterOS main package and is always enabled
      -) BGP is disabled right now, until further notice
      -) MPLS is disabled right now, until further notice
      -) Not all packages have been published at the moment
      -) Winbox does not show all features, use CLI for most functionality

      ## Журнал изменений 7.0beta2

      *) capsman - fixed UDP communication between CAPsMAN and CAP;
      *) certificate - fixed ECDSA certificate parsing;
      *) crs3xx - fixed SFP/SFP+ module detection;
      *) ike2 - fixed EAP payload processing on initiator;
      *) package - added RouterOS system packages for all current architectures;
      *) poe - fixed single PoE out port initialization on RB760, RB3011 and RB4011;
      *) snmp - fixed SNMP MIB database;
      *) torrent - removed Torrent feature from RouterOS;
      Будьте в курсе наших акций и новостей
      Каталог
      Акции
      Компания
      О компании
      Новости
      Контакты
      Загрузки
      Загрузки
      ChangeLog
      Информация
      Политика конфиденциальности
      Помощь
      Условия оплаты
      Условия доставки
      Гарантия на товар
      Вопрос-ответ
      +7 (495) 320-69-22
      +7 (495) 320-69-22
      info@microtik.su
      г. Москва, ул. Бакунинская, 84с21
      • Viber
      • Viber
      • WhatsApp
      2025 © Mikrotik - официальный дистрибьютор