MikroTik RouterOS ARM64 Firmware 6.47 RC 2

Manufacturer:

Description

DOWNLOAD NOW

Important note!!!

- The Dude server must be updated to monitor v6.46.4 and v6.47beta30+ RouterOS type devices.
- The Dude client must be manually upgraded after upgrading The Dude server.
- Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used.
- The Dude requires "winbox" policy instead of "dude" to monitor v6.46.4 and v6.47beta30+ RouterOS type devices.

MAJOR CHANGES IN v6.47:

- dns - added client side support for DNS over HTTPS (DoH) (RFC8484);
- socks - added support for SOCKS5 (RFC 1928);
- user - enable "winbox" policy for groups with "dude" policy;

Changes in this release:

- api - added ECDHE cipher support for "api-ssl" service;
- bonding - fixed ALB and TLB bonding modes after interface disable/enable (introduced in v6.47beta19);
- bonding - fixed packet receiving on bonding slave ports (introduced in v6.47beta19);
- bridge - added warning message when a bridge port gets dynamically added to VLAN range;
- chr - added support for hardware watchdog on ESXI;
- crs3xx - fixed tagged VLAN packet receiving on Ethernet interfaces for CRS354 devices (introduced in v6.47beta49);
- crs3xx - improved 10G interface initialization on CRS312 devices;
- dhcpv4-server - disallow zero lease-time setting;
- dhcpv6-server - do not require "server" parameter for bindings;
- dns - added support for multiple type static entries;
- dot1x - added "radius-mac-format" parameter;
- dot1x - improved Dot1X service stability when receiving bogus packets;
- dot1x - improved value validation for dynamically created switch rules;
- email - added support for multiple "to" recipients;
- ethernet - fixed interface stopping responding after blink command execution on CCR2004-1G-12S+2XS;
- filesystem - fixed NAND memory going into read-only mode or becoming unstable over time;
- health - improved stability for system health monitor on CCR2004-1G-12S+2XS;
- ike2 - added support for RFC8598;
- ike2 - allow initiator address change before authentication;
- ike2 - fixed authentication handling when initiator disconnects before RADIUS response;
- interface - improved system stability when receiving bogus packets;
- ipsec - added "split-dns" parameter support for mode configuration;
- ipsec - added "use-responder-dns" parameter support;
- ipsec - allow specifying two peers for a single policy for failover;
- ipsec - place dynamically created IPsec policies at the begining of the table;
- l2tp - added "src-address" parameter for L2TP client;
- l2tp - added "use-peer-dns" parameter for L2TP client;
- l2tp - improved dynamically created IPsec configuration updating;
- l2tp - use L2TP interface when adding dynamic IPsec peer;
- lcd - improved general system stability when LCD is not present;
- log - added logging entry when changing user's password;
- log - added tunnel endpoint address to establishment and disconnect logging entries;
- log - fixed logging topic for MAC address learning on a different bridge port events;
- log - made startup script failures log as critical errors;
- lte - fixed "band" parameter persistence after disable/enable;
- lte - fixed "ecno" and "rscp" value reporting on R11e-LTE6;
- lte - fixed VLAN interface passthrough support;
- lte - improved stability during firmware upgrade;
- netwatch - improved Netwatch service stability when invalid configuration values are passed;
- ovpn - added "use-peer-dns" parameter for OVPN client;
- poe - fixed missing PoE out settings on CRS354-48P-4S+2Q (introduced in v6.47beta49);
- port - removed serial console port on hEX S;
- ppp - removed "comment", "set" and "edit" commands from "PPP->Active" menu;
- pptp - added "use-peer-dns" parameter for PPTP client;
- profile - added support for CCR2004-1G-12S+2XS;
- qsfp - added support for FEC mode (fec74), with the FEC mode disabled by default
- quickset - fixed invalid configuration applying when performing changes during LTE modem initialization process;
- routerboard - added "hold-time" parameter to mode-button menu;
- routerboard - added "reset-button" menu - custom command execution with reset button;
- routing - improved routing service stability when receiving bogus packets;
- sfp28 - added support for FEC modes (fec74 and fec91), with fec91 mode already enabled by default;
- sfp28 - fixed interface linking after power cycle on CCR2004-1G-12S+2XS (introduced in v6.47beta49);
- switch - correctly enable and disable CPU Flow Control on RB3011UiAS;
- tr069-client - added LTE firmware update functionality support;
- tr069-client - added additional LTE information parameters;
- tr069-client - added additional wireless registration table parameters;
- tr069-client - added interface type parameter support;
- tr069-client - added multiple simultaneous session support for diagnostics test;
- tr069-client - added total connection tracking entries parameter;
- ups - added battery info for APC SmartUPS 2200;
- webfig - fixed 5GHz wireless interface "frequency" parameter value list on Audience;
- winbox - added "auth-info" parameter under "Dot1X->Active" menu;
- winbox - added "auth-types", "comment", "mac-auth-mode" and "reject-vlan-id" parameters for Dot1X server;
- winbox - added "bus" parameter for "USB Power Reset" command on NetMetal ac^2;
- winbox - added "comment" parameter and "dynamic" flag support under "Switch->Rule" table;
- winbox - added "comment" parameter for Dot1X client;
- winbox - added "region" parameter for W60G interfaces;
- winbox - added "skip-dfs-channels" parameter to wireless interface menu;
- winbox - added enable and disable buttons for "MPLS->MPLS Interface" table;
- winbox - do not allow to enter empty strings in "caps-man-names" and "common-name" parameters;
- winbox - fixed WDS usage when connecting to RouterOS access point using QuickSet;
- winbox - fixed dates and times in interface link up/down properties (WinBox v3.24 required);
- winbox - fixed wireless sniffer parameter setting;
- wireless - fixed Nstreme wireless protocol performance decrease;
- wireless - updated "egypt" regulatory domain information;

Other changes since v6.46.6:

- bonding - improved slave interface MAC address handling;
- bonding - prefer primary slave MAC address for bonding interface;
- branding - do not ask to confirm configuration applied from branding package;
- branding - fixed identity setting from branding package;
- branding - improved branding package installation process when another branding package is already installed;
- branding - properly use HTML files for Hotspot (introduced in v6.47beta);
- bridge - added logging message when a host MAC address is learned on a different bridge port;
- bridge - added warning message when port is dynamically added to entry with VLAN range (CLI only);
- bridge - correctly remove disabled MSTI;
- bridge - improved hardware offloading enabling/disabling;
- certificate - added "skid" and "akid" values for detailed print;
- certificate - allow dynamic CRL removal;
- certificate - disabled CRL usage by default;
- certificate - do not use SSL for first CRL update;
- chr - added support for file system quiescing;
- chr - enabled support for VMBus protocol version 4.1;
- chr - improved system stability when running CHR on Hyper-V;
- crs3xx - correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices;
- crs3xx - do not change bridge host ID's when updating host table (introduced in v6.47beta32);
- crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
- crs3xx - fixed QSFP interface linking after removing/inserting QSFP module (introduced in v6.47beta49);
- crs3xx - fixed QSFP+ interface linking for CRS326-24S+2Q+ device (introduced in v6.47beta19);
- crs3xx - fixed hardware offloaded bonding on Ethernet interfaces for CRS354 devices;
- crs3xx - improved switch host table updating;
- crs3xx - improved system stability when creating multiple hardware offloaded bonding interfaces (introduced in v6.47beta49);
- crs3xx - show correct switch model for netPower 15FR device;
- defconf - fixed "no-defaults=yes" applying default configuration (introduced in v6.47beta);
- defconf - fixed default configuration initialization if power loss occurred during the process;
- dhcpv4 - added end option (255) validation for both server and client;
- dhcpv4-client - improved stability when changing client while still receiving advertisements;
- dhcpv4-server - disallow zero lease-time setting;
- dhcpv6-client - improved error logging when when renewed address differs;
- dhcpv6-server - fixed MAC address retrieving from DUID when timestamp is present;
- discovery - do not send discovery packets on inactive bonding slave interfaces;
- discovery - do not send discovery packets on interfaces that are blocked by STP;
- disk - improved disk management service stability when receiving bogus packets;
- disk - improved recently created file survival after reboots;
- dns - added support for exclusive dynamic DNS server usage from IPsec;
- dns - added support for forwarding DNS queries of static entries to specific server (CLI only);
- dns - added support for multiple type static entries (CLI only);
- dot1x - added "radius-mac-format" parameter (CLI only);
- dot1x - added hex value support for RADIUS switch rules;
- dot1x - added range "dst-port" support for RADIUS switch rules;
- dot1x - added support for lower case "mac-auth" RADIUS formats;
- dot1x - fixed "reject-vlan-id" value range;
- dot1x - fixed dynamically created switch rule removal when client disconnects;
- dot1x - fixed port blocking when interface changes state from disabled to enabled;
- dot1x - improved debug logging output to "dot1x" topic;
- dot1x - improved value validation for dynamically created switch rules;
- email - added support for multiple "to" recipients (CLI only);
- fetch - fixed "User-Agent" usage if provided by "http-header-field";
- filesystem - fixed NAND memory going into read-only mode or becoming unstable over time;
- graphing - improved graphing service stability when receiving bogus packets;
- health - added "gauges" submenu with SNMP OID reporting;
- hotspot - updated splash page design ('/ip hotspot reset-html' required);
- ike1 - added error message when specifying "my-id" for XAuth Identity;
- ike1 - added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes;
- ike1 - do not try to keep phase 2 when purging phase 1;
- ike1 - improved policy lookup with specific protocol;
- ike1 - improved stability when performing policy lookup on non-existant peer;
- ike2 - added support for "INTERNAL_DNS_DOMAIN" payload attribute;
- ike2 - added support for RADIUS Disconnect-Request message handling;
- interface - increased loopback interface MTU to 65536;
- ipsec - added "split-dns" parameter support for mode configuration (CLI only);
- ipsec - added "use-responder-dns" parameter support (CLI only);
- ipsec - allow specifying two peers for a single policy for failover (CLI only);
- ipsec - control CRL validation with global "use-crl" setting;
- ipsec - do full certificate validation for identities with explicit certificate;
- ipsec - fixed minor spelling mistake in logs;
- ipsec - improved IPsec service stability when receiving bogus packets;
- kidcontrol - ignore IPv6 multicast MAC addresses;
- lcd - fixed LCD service becoming unavailable on devices without LCD screen;
- led - fixed minor typo in LED warning message;
- lte - added support for Huawei K5161 modem;
- lte - added support for NEOWAY N720;
- lte - added support for multiple passthrough APN configuration;
- lte - do not allow running "scan" on R11e-4G;
- lte - fixed "allow-roaming" setting when using LTE network mode on R11e-LTE;
- lte - fixed multiple APN reactivation after deactivation by operator;
- lte - improved stability during firmware upgrade process;
- lte - made "mac-address" parameter read-only;
- lte - show "phy-cellid" value only in LTE mode;
- netinstall - removed "Flashfig" from Netinstall;
- netinstall - removed "Make Floppy" from Netinstall;
- netinstall - signed netinstall.exe with Digital Signature;
- ppp - added support for ZTE MF90;
- ppp - fixed minor typo when running "info" command;
- proxy - increased minimal free RAM that can not be used for proxy services;
- quickset - do not show "SINR" field in Quick Set when there is no data;
- quickset - removed "EARFCN" field from Quick Set;
- quickset - removed "LTE band" setting from Quick Set;
- quickset - show "Antenna Gain" setting on devices without built-in antennas;
- quickset - use "station-wds" mode when connecting to AP with RouterOS flag;
- route - improved system stability after reboot with large amount of VLAN interfaces with PPPoE servers attached;
- routerboard - added "hold-time" parameter to mode-button menu (CLI only);
- routerboard - added "reset-button" menu - custom command execution with reset button (CLI only);
- routing - improved IGMP-Proxy service stability when receiving bogus packets;
- sniffer - allow setting port for "streaming-server";
- snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB;
- snmp - changed "upsEstimatedMinutesRemaining" reported value from seconds to minutes;
- snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
- snmp - improved OID policy checking and error reporting on "set" command;
- snmp - improved stability when polling MAC address related OID;
- ssh - improved SSH service stability when receiving bogus packets;
- supout - added "dot1x" section to supout files;
- supout - improved UPS information reporting;
- switch - correctly display switch statistics when all switch ports are disabled on RTL8367 switch chip;
- switch - fixed missing switch statistics (introduced in v6.47beta49);
- switch - made "auto" the default value for "vlan-id" parameter when creating a new static host entry;
- system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic;
- system - improved driver loading speed on startup;
- tr069-client - removed warning log message when not using HTTPS;
- traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9;
- upgrade - fixed space handling in package file names;
- ups - improved compatibility with APC Smart UPS 1000 and 1500;
- user - improved user management service stability when receiving bogus packets;
- w60g - fixed link status logging;
- w60g - improved rate selection in low traffic conditions;
- w60g - use "arp" and "mtu" parameters from master interface when creating a new station;
- webfig - fixed WinBox download link;
- webfig - fixed skin usage from branding package;
- webfig - updated icon design;
- winbox - added "Rate" parameter for switch ACL rules;
- winbox - added "auto-erase" option to "Tool/SMS" menu;
- winbox - added "bus" parameter for "USB Power Reset" command on RBM33G;
- winbox - added comment support for "Switch->VLAN" menu;
- winbox - added support for inline bar graphs for LTE signal values;
- winbox - aligned all "IP->Traffic Flow->IPFIX" check boxes in single line (WinBox v3.22 required);
- winbox - allow setting "Primary" parameter for "balance-tlb" bonding interfaces;
- winbox - allow to specify any ethernet like interface under "Tool/WoL" menu;
- winbox - fixed "BGP Origin" value display under "IPv6->Routes" menu;
- winbox - fixed "Data Rate" checkbox alignment (WinBox v3.22 required);
- winbox - fixed "Tx/Rx Signal Strength" value presence for 4 chain interfaces;
- winbox - fixed bonding type interface support for "Switch->Host" table;
- winbox - fixed wireless interface "HT" tab setting presence when "band=5ghz-n/ac";
- winbox - limit number of simultaneous WinBox sessions to 5 for users without "write" permission;
- winbox - made "yes" the default value for "Inject Summary LSAs" parameter when creating a new NSSA or STUB area;
- winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic";
- winbox - renamed "Routerboard" to "RouterBOARD" under "System/RouterBOARD" menu;
- winbox - show "Hardware Offload" parameter for bonding interfaces;
- winbox - updated icon design;
- wireless - added "russia 6ghz" regulatory domain information;
- wireless - allow using "russia4" regulatory domain on RU locked devices;
- wireless - enabled unicast flood for DHCP traffic on ARM architecture access points;
- wireless - improved management service stability when receiving bogus packets;
- wireless - updated "russia4" regulatory domain information;
- www - added "tls-version" parameter in "IP->Services" menu (CLI only);

About Router Firmware:

Before you consider downloading this firmware, go to the system information page of the router and make sure that the currently installed version isn't either newer or matching this release.

Due to the large variety of router models and different methods for upgrading the device, it is highly recommended that you read and, above all, understand the installation steps before you apply the new firmware, even if you are a power user.

In theory, these steps shouldn't be much of a hassle for anyone, because manufacturers try to make them as easy as possible, even if they don't always succeed. Basically, you must upload the new firmware to the router through its administration page and allow it to upgrade.

If you install a new version, you can expect increased security levels, different vulnerability issues to be resolved, improved overall performance and transfer speeds, enhanced compatibility with other devices, added support for newly developed technologies, as well as several other changes.

If you're looking for certain safety measures, remember that it would be best if you perform the upload using an Ethernet cable rather than a wireless connection, which can be interrupted easily. Also, make sure you don't power off the router or use its buttons during the installation, if you wish avoid any malfunctions.

If this firmware meets your current needs, get the desired version and apply it to your router unit; if not, check with our website as often as possible so that you don't miss the update that will improve your device.

MikroTik RouterOS Firmware MikroTik ARM Architecture Firmware MikroTik Router Firmware Router RouterOS Firmware MikroTik