Router OS


Operating system

RouterOS is the operating system of RouterBOARD. It can also be installed on a PC and will turn it into a router with all the necessary features - routing, firewall, bandwidth management, wireless access point, backhaul link, hotspot gateway, VPN server and more. You can compare the different license Level features on this page in our manual.

Online demo

Try RouterOS now by using our online demo routers. Connect via SSH or download our graphical application WinBox (latest version). When connecting in either way, use the address demo.mt.lv or demo2.mt.lv. Username is "demo" and there is no password. You can also open the web configuration interface in your web browser: demo.mt.lv and demo2.mt.lv

Installing RouterOS

Installing RouterOS on an x86 machine is very simple

PC:

Download the ISO image, burn it to CD and boot from it. Your new router will run for 24 hours without a license (turn it off to stop the timer). During this time you can try all the features of RouterOS.

Other x86

Netinstall will write RouterOS to any secondary drive you have attached to your Windows PC. Move the drive to your Router PC and boot it.

Both installation methods, plus upgrade files and more - on our download page.

Virtual environments now have special treatment: CHR

CHR, short for Cloud Hosted Router, is a new approach specifically made for Virtual Machines both locally and in the cloud. Optimised drivers, a new and more affordable licensing scheme, transferable licenses and more.

CHR is a special installation image, which is available for free on our download page, or directly in the Amazon AWS marketplace. Read more in our CHR manual.

Learning more about our software

RouterOS has extensive documentation and a Forum. Additionally we conduct Training and User Meetings.

Also our technical support team will try to answer your questions, and our trained consultants will help you configure your routers.

Purchasing a license for RouterOS

To use RouterOS after the free trial, a license key is required. You can obtain license keys in the MikroTik Account server. If you don't have an account yet, click on "New Account" there in the top-right corner of this page.

When purchasing the license, a SoftID number will be asked - this can be copied from the router's License menu.

To view license key level differences, see the comparison table.


Download

Upgrading RouterOS

If you are already running RouterOS, upgrading to the latest version can be done by clicking on "Check For Updates" in QuickSet or System > Packages menu in WebFig or WinBox. See the documentation for more information about upgrading and release types.

To manage your router, use the web interface, or download the maintenance utilities. Winbox to connect to your device, Dude to monitor your network and Netinstall for recovery and re-installation.

WinBox Download

7.14.3 Stable 7.15rc1 Testing
ARM
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
ARM64 / AMPERE
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
ISO image for AMPERE DownloadSHA256
MIPSBE
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
MMIPS
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
SMIPS
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
TILE
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
PPC
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
X86
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
CD Image DownloadSHA256 DownloadSHA256
Install image DownloadSHA256 DownloadSHA256
GENERAL
Netinstall (Windows) DownloadSHA256 DownloadSHA256
Netinstall (Windows 64bit) DownloadSHA256 DownloadSHA256
Netinstall (CLI Linux) DownloadSHA256 DownloadSHA256
The Dude client DownloadSHA256 DownloadSHA256
Bandwidth test DownloadSHA256 DownloadSHA256
Mikrotik.mib DownloadSHA256 DownloadSHA256
FlashFig DownloadSHA256 DownloadSHA256
Changelog Changelog Changelog

6.49.13 Long-Term 6.49.14 Stable
ARM
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
ARM64
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
MIPSBE
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
MMIPS
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
SMIPS
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
TILE
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
PPC
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
X86
Main package DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256
CD Image DownloadSHA256 DownloadSHA256
Install image DownloadSHA256 DownloadSHA256
GENERAL
Netinstall (Windows) DownloadSHA256 DownloadSHA256
Netinstall (Windows 64bit) DownloadSHA256 DownloadSHA256
Netinstall (CLI Linux) DownloadSHA256 DownloadSHA256
The Dude client DownloadSHA256 DownloadSHA256
Bandwidth test DownloadSHA256 DownloadSHA256
Mikrotik.mib DownloadSHA256 DownloadSHA256
FlashFig DownloadSHA256 DownloadSHA256
Changelog Changelog Changelog

6.49.13 Long-Term 6.49.14 Stable 7.14.3 Stable 7.15rc1 Testing
Images vmdk, vhdx, vdi, ova, img
Main package DownloadSHA256 DownloadSHA256 DownloadSHA256 DownloadSHA256
VHDX image DownloadSHA256 DownloadSHA256 DownloadSHA256 DownloadSHA256
VMDK image DownloadSHA256 DownloadSHA256 DownloadSHA256 DownloadSHA256
VDI image DownloadSHA256 DownloadSHA256 DownloadSHA256 DownloadSHA256
VirtualPC image DownloadSHA256 DownloadSHA256 DownloadSHA256 DownloadSHA256
OVA template DownloadSHA256 DownloadSHA256 DownloadSHA256 DownloadSHA256
Raw disk image DownloadSHA256 DownloadSHA256 DownloadSHA256 DownloadSHA256
Extra packages DownloadSHA256 DownloadSHA256 DownloadSHA256 DownloadSHA256
The Dude client DownloadSHA256 DownloadSHA256 DownloadSHA256 DownloadSHA256
VDI image (arm64) DownloadSHA256
Raw disk image (arm64) DownloadSHA256
Changelog Changelog Changelog Changelog Changelog

Switches
Changelog 1.17 Changelog
version 1.17 for RB250GS Download
version 1.17 for RB260GS, RB260GSP Download
version 2.16 for new RB260GS(CSS106-5G-1S), new RB260GSP(CSS106-1G-4P-1S) Download
version 2.16 for CRS305-1G-4S+ Download
version 2.16 for CRS305-1G-4S+OUT Download
version 2.16 for CRS309-1G-8S+ Download
version 2.16 for CRS310-1G-5S-4S+IN, CRS310-1G-5S-4S+OUT Download
version 2.16 for CRS310-8G+2S+IN Download
version 2.16 for CRS312-4C+8XG Download
version 2.16 for CRS317-1G-16S+ Download
version 2.16 for CRS318-1Fi-15Fr-2S Download
version 2.16 for CRS318-16P-2S+ Download
version 2.16 for CRS326-24G-2S+, CSS326-24G-2S+ Download
version 2.16 for CRS326-24S+2Q+ Download
version 2.16 for CRS326-4C+20G+2Q+RM Download
version 2.16 for CRS328-4C-20S-4S+ Download
version 2.16 for CRS328-24P-4S+ Download
version 2.16 for CRS354-48G-4S+2Q+, CRS354-48P-4S+2Q+ Download
Changelog 2.16 Changelog

Switches
version 2.18 for netPower Lite 7R (CSS610-1Gi-7R-2S+) Download
version 2.18 for CSS610-8G-2S+ Download
version 2.18 for CSS610-8P-2S+IN Download
version 2.18 for GPEN21 Download
version 2.18 for FTC11XG Download
Changelog 2.18 Changelog

MikroTik RouterOS Stable and Long-Term releases

update : April 19, 2024, 10:22 a.m.

The newest MikroTik RouterOS releases.

All current and historical changelogs

What's new in 7.14.3 (2024-Apr-17 15:47):

*) bgp - correctly synchronize input.accept-nlri address list;
*) bridge - use default "edge=auto" for dynamically bridged interfaces (PPP, VPLS, WDS);
*) disk - improved system stability;
*) fetch - fixed slow throughput due to "raw" logging which occurred even when not listening to the topic (introduced in v7.13);
*) queue - improved system stability (introduced in v7.6);
*) wifi-qcom - added configuration.distance setting to enable operation over multi-kilometer distances (CLI only);

What's new in 6.49.13 (2024-Apr-04 12:57):

*) defconf - fixed firewall rule for IPv6 UDP traceroute;
Long-term release tree

What's new in 6.49.13 (2024-Apr-04 12:57):

*) defconf - fixed firewall rule for IPv6 UDP traceroute;
Stable release tree

What's new in 7.14.3 (2024-Apr-17 15:47):

*) bgp - correctly synchronize input.accept-nlri address list;
*) bridge - use default "edge=auto" for dynamically bridged interfaces (PPP, VPLS, WDS);
*) disk - improved system stability;
*) fetch - fixed slow throughput due to "raw" logging which occurred even when not listening to the topic (introduced in v7.13);
*) queue - improved system stability (introduced in v7.6);
*) wifi-qcom - added configuration.distance setting to enable operation over multi-kilometer distances (CLI only);
Testing release tree

What's new in 7.15rc1 (2024-Apr-18 12:17):

!) system - added support for AMPERE (R) and ARM64 CHR installations (new ARM64 CHR image available);
*) bgp - added initial vpnv6 support;
*) bgp - correctly synchronize input.accept-nlri address list;
*) bgp - fixed selecting local.default-address from wrong VRF;
*) bgp - use IPv6 as default address-family for IPv6 sessions;
*) bridge - added error message if MLAG peer-port is configured with "mlag-id";
*) bridge - added MLAG peer-port events to logs;
*) bridge - added MVRP support;
*) bridge - do not allow multiple bonds with same "mlag-id";
*) bridge - use default "edge=auto" for dynamically bridged interfaces (PPP, VPLS, WDS);
*) certificate - allow replacing certificate with internal import;
*) certificate - delete certificate related files automatically from storage after import;
*) console - added "byte-array" option to ":convert" command;
*) console - added "rows" property for sniffer quick mode;
*) console - added link from "/iot/lora" to "/lora";
*) console - covert spaces, CR, LF in ":convert to=url" command;
*) console - fixed bogus console ports on ARM64 devices (introduced in v7.15beta6);
*) console - improved stability;
*) defconf - fixed unknown topics in log messages;
*) defconf - minor configuration script updates;
*) dhcpv4-relay - added VRF support;
*) discovery - added LLDP MAC/PHY Configuration/Status TLV support;
*) discovery - always send LLDP MED Power TLV if MED was received;
*) disk - improved support for file systems with non-ascii characters in file names;
*) disk - improved system stability;
*) disk - the "scan" command will now detect and include USB drives that were previously ejected;
*) dns - added VRF support;
*) fetch - added "idle-timeout" parameter;
*) file - avoid refreshing whole file system during file modification;
*) file - improved external storage detection;
*) install - cdrom and hdd install images contain additional packages that can be interactively selected;
*) lora - removed LoRa WinBox and console functionality duplication (moved to IoT package since v7.11);
*) lte - added "at-chat" support for DELL T99W175 (PID: 0x05c6 VID: 0x90d5);
*) lte - added support for concatenated AT commands in "modem-init" string;
*) lte - added support to set "modem-init" string for "dialer-less" modems;
*) lte - dropped support for R11e-LTE-US FOTA firmware update;
*) media - added support for DLNA;
*) ovpn - fixed minor typo in error message;
*) poe-out - added LLDP power management support for devices with single PoE-out port;
*) poe-out - moved "PoE LLDP" property from "/interface/ethernet/poe" to "/ip/neighbor/discovery-settings" and enable it by default;
*) ppp - added "enable-ipv6-accounting" option under PPP AAA menu (CLI only);
*) ppp - added addition support to monitor modem registration state, RSRP, RSRQ, SINR, PCI, CellID for BG77 modem;
*) ppp - allow underscores in domain names;
*) ptp - added PTP support for CCR2116 device;
*) qos-hw - added "profile" and "map" support for CPU port;
*) qos-hw - added per-queue traffic shapers (CLI only);
*) qos-hw - added Priority Flow Control for compatible switches (CLI only);
*) qos-hw - replaced buffer with bytes in QoS monitor;
*) queue - improved system stability (introduced in v7.6);
*) route - do not redistribute loopback address as connected route;
*) route - rework of route attributes;
*) sfp - added "100M-baseFX" link mode support for compatible devices;
*) smb - added logs for share connection requests;
*) smb - do not allow setting empty "comment" or "domain" properties;
*) snmp - added missing PoE-out status codes to MIKROTIK-MIB;
*) snmp - added new "mtxrOpticalVendorSerial" OID to MIKROTIK-MIB;
*) ssh - fixed bogus output;
*) sstp - added SNI support;
*) switch - added support for RSPAN mirroring on 98DXxxxx switches;
*) system - general work on optimizing the size of RouterOS packages;
*) vlan - limit "vlan-id" range from 1-4095 to 1-4094;
*) webfig - show inherited properties for wifi interfaces;
*) wifi-qcom - added configuration.distance setting to enable operation over multi-kilometer distances;
*) wifi-qcom - updated driver;
*) wifi-qcom-ac - fix interfaces getting stuck in "stopping" state after radar detection (introduced in v7.15beta9);
*) winbox - added "FT Preserve VLAN ID" setting under "WiFi/Configuration/FT" menu;
*) winbox - added drop down menu for "User" property when importing SSH key under "System/User/SSH Keys" and "System/User/SSH Private Keys" menus;
*) winbox - use correct values for "Jump Target" property under "IPv6/Firewall/Filter Rules" menu;
*) x86 - fixed VLAN tagged packet transmit for ice driver;

Other changes since v7.14:

!) system - added support for AMPERE (R) hardware (new ARM64 ISO file, new ARM64 extra-nics.npk package);
*) bgp - fixed prefix count when BGP sessions run with multiple AFIs;
*) bgp-vpn - use VRF interface as gateway for leaked connected routes;
*) branding - added option to hide default configuration prompt;
*) branding - added option to hide or replace default caps-mode-script;
*) bridge - improved protocol-mode STP, RSTP and MSTP stability;
*) bridge - rename monitor property "path-cost" to "actual-path-cost";
*) bridge - reworked dynamic VLAN creation;
*) certificate - added support for different ACME servers for ssl-certificate (CLI only);
*) certificate - added support for importing pbes2 encrypted private keys with aes128;
*) certificate - added trusted parameter for certificate import;
*) chr - allow to "generate-new-id" only while CHR is running on level "free" license;
*) chr - fixed bogus messages printed out while booting up the system (introduced in v7.14);
*) chr - fixed Xen and Vultr missing ethernet (introduced in v7.14);
*) console - added "proplist" parameter to interactive commands;
*) console - added "sanitize-names" property under "/console/settings" menu (option for replacing reserved characters with underscores for files, disabled by default);
*) console - added "type" parameter to ":resolve" command;
*) console - added "use-script-permissions" option when running scripts from CLI;
*) console - added hotkey "F8" to print entire multiline input;
*) console - added log for script execution failures;
*) console - added multi-line print in "/file" menu;
*) console - added option to get "about" value (dynamically created text field by RouterOS services like CAPsMAN);
*) console - added option to read and change file line endings in full-screen editor;
*) console - added warning log for modified filenames due to reserved characters;
*) console - do not convert string to array in ":deserialize" command;
*) console - fixed ":onerror" behavior when "do" block is missing;
*) console - fixed "export where" functionality in certain menus;
*) console - fixed console prompt when entering hot lock mode with "F7";
*) console - fixed DHCP server "authoritative=no" configuration export;
*) console - fixed do/while implementation not working with variables (introduced in v7.14);
*) console - fixed filtering by "dhcp" flag in "/ip/arp" menu;
*) console - fixed multiple typos in help;
*) console - optimized configuration export to prevent startup of processes without any configuration;
*) console - remove unnecessary serial ports for Alpine CPUs;
*) console - show system note before serial login if enabled;
*) console - use user permissions when running scripts from WinBox and WebFig;
*) container - do not allow negative number for "ram-high" setting;
*) defconf - do not override default DHCP server lease time;
*) defconf - fixed 5ghz-ax channel width for L11, L22 devices;
*) discovery - added LLDP Maximum Frame Size TLV support;
*) discovery - added LLDP Port Description TLV support;
*) discovery - advertise only physical interface name for LLDP PortID TLV;
*) discovery - fixed high CPU utilization when "tx-only" mode is set;
*) discovery - optimized LLDP information update;
*) disk - added option to auto configure media sharing;
*) disk - added support for formatting exfat file-system;
*) disk - improved support for formatting ext4 file-system;
*) disk - improved system stability when adding partition with no parent;
*) dns - added support for "adlist";
*) dns - improved system stability when caching entries;
*) eap - improved eap-peap, eap-mschap2 client authentication (dot1x/wireless/ipsec);
*) ethernet - fixed default names for CRS310-8G+2S+ device (introduced in v7.14);
*) ethernet - fixed interface disable for CRS326-4C+20G+2Q;
*) ethernet - fixed management port disable/enable on CCR2004-1G-12S+2XS, CCR2004-1G-2XS-PCIe, CCR2216, CCR2116 devices;
*) ethernet - improved port speed downshift functionality for CRS326-4C+20G+2Q;
*) fetch - changed topic "info" to "error" for permission denied logs;
*) fetch - fixed slow throughput due to "raw" logging which occurred even when not listening to the topic (introduced in v7.13);
*) file - allow adding and renaming files and directories;
*) file - fixed moving files to/from external storage (introduced in v7.15beta4);
*) health - added "cpu-temperature" for IPQ50xx devices;
*) health - added log for fan state changes on CRS3xx, CRS5xx, CCR2xxx, CCR1016r2, CCR1036r2 devices;
*) health - fixed fan behavior for CRS310-1G-5S-4S+ (introduced in v7.14);
*) health - fixed missing "cpu-temperature" on IPQ-60xx devices (introduced in v7.15beta8);
*) health - fixed rogue voltage on CRS510-8XS-2XQ-IN;
*) ipv6 - properly initialize default ND "interface=all" entry;
*) leds - fixed LEDs for L22 device;
*) lte - apply the same configuration for Microsoft branded EM12-G modem (Surface Mobile Broadband) as for Quectel EM12-G;
*) lte - fixed firmware upgrade not found issue for Chateau LTE12 (introduced in v7.15beta4);
*) lte - fixed R11e-LTE-US modem dial-up;
*) lte - make interface persistent (unused interface configs can be removed, allow to export and examine current configuration without the device present);
*) metarouter - removed support;
*) modem - send APN authentication for BG77 modem also if ppp-client interface created manually;
*) netinstall - improved stability;
*) ovpn - fixed import ovpn config when remote port is missing;
*) poe-out - fixed powering devices if input voltage is lower than 12V for hEX PoE (introduced in v7.9);
*) poe-out - improved firmware upgrade stability for AF/AT controlled boards;
*) ppp - added log when disconnecting a client due to "WISPr-Session-Terminate-Time" RADIUS attribute;
*) ppp - fixed "Framed-IPv6-Pool" usage when received from RADIUS;
*) ppp - fixed "on-down" script running even when tunnel was not up;
*) ppp - fixed reporting of frame error rate (introduced in v7.15beta8);
*) profiler - added "neighbor-discovery" task;
*) qos-hw - added congestion avoidance support for 98DX8xxx, 98DX4xxx, 98DX325x switch chips (CLI only);
*) qos-hw - added ECN marking support for compatible switches;
*) qos-hw - added support for QoS profile assignment via ACL rules;
*) qos-hw - added WRED support for compatible switches;
*) qos-hw - fixed port "print stats/usage" when using "from" property;
*) quickset - only show LTE mode for devices without other wireless interfaces;
*) radius - added "require-message-auth" option that requires "Message-Authenticator" in received Access-Accept/Challenge/Reject messages;
*) radius - include "Message-Authenticator" in any RADIUS communication messages besides accounting for all services;
*) route - do not allow routes with empty "dst-address";
*) route - fixed bgp-vpn prefix import with the same route distinguisher (RD);
*) route - improved system stability;
*) route - show route-distinguisher (RD) in route print;
*) route-filter - allow setting different AFI gateways;
*) route-filter - fixed ext community list matcher;
*) sfp - added "sfp-ignore-rx-los" setting;
*) sfp - fixed "sfp-tx-fault" state indication for CRS510;
*) sfp - fixed link establishment with 100Mbps optical modules (requires "/interface ethernet reset" or adding "100M-baseFX" modes for advertise or speed properties);
*) sfp - fixed missing Tx traffic at 10Gbps rate on CCR2004-16G-2S+ in rare cases;
*) sfp - ignore SFP RX LOS signal for modules with bad EEPROM;
*) sfp - improved "sfp-tx-power" value monitoring in certain cases;
*) sfp - improved auto-negotiation linking for some MikroTik cables and modules;
*) sfp - improved system stability for CR2004-1G-2XS-PCIe (introduced in v7.14);
*) sfp - improved system stability with some GPON modules for CCR2004 and CCR2116 devices;
*) sms - added option to select SMS storage;
*) sms - added SMS PDU to SMS inbox "print detail";
*) sms - added workaround for modems which do not notify regarding new SMS arrival (missing URC);
*) sms - improved SMS handling;
*) sms - removed SMS for SMIPS;
*) sms - use "gsm" logging topic for serial modem SMS logs;
*) socks - attempt to parse domain name as IP before resolving;
*) ssh - added support for user Ed25519 private keys;
*) ssh - export host Ed25519 public key;
*) ssh - fixed permissions to run ".auto.rsc" scripts;
*) ssh - require "policy" user policy when adding public key;
*) sstp - disconnect clients when server is disabled;
*) switch - added support for multiple ingress and egress port mirroring on 98DXxxxx switches;
*) switch - fixed L3HW and QoS monitor during switch reset;
*) system - added resource values (Product name, File name and File version) for Windows executable files;
*) system - fixed upgrade for CCR2004-1G-12S+2XS (introduced in v7.15beta6);
*) system - show "cpu-frequency" for Alpine CPUs;
*) system - updated office address in RouterOS license;
*) system - updated online manual links from "wiki" to the help documentation;
*) timezone - updated timezone information from "tzdata2024a" release;
*) traffic-flow - detect IPv4 source address if not set;
*) traffic-flow - improved system stability;
*) userman - added "require-message-auth" option that requires "Message-Authenticator" in received Access-Request messages;
*) userman - include "Message-Authenticator" in any RADIUS communication messages besides accounting for all services;
*) vlan - added MVRP (applicant) configuration option;
*) vlan - ensure that VLAN MTU remains unchanged when adjustments are made to the parent interface MTU, only modifications to the L2MTU might impact VLAN MTU;
*) vlan - fixed MTU reset on bridge after reboot;
*) vrf - fixed VRF interfaces being moved to main table after reboot (introduced in v7.14);
*) webfig - allow pasting with ctrl+v into terminal;
*) webfig - fixed column preferences for ordered tables;
*) wifi - added "reselect-interval" support;
*) wifi - changed interface default to "disabled=yes";
*) wifi - do not report disabled state for CAPsMAN managed interface;
*) wifi - fixed configuration export for "disabled" property;
*) wifi - improve channel selection after radar detection events;
*) wifi - improve regulatory compliance for L11, L22 devices;
*) wifi - improved stability of DFS check in the 5GHz-A band;
*) wifi - improved system stability when provisioning CAPs in certain cases;
*) wifi - rename "available-channels" parameter to "channel-priorities" and include desirability rating for each channel;
*) wifi - report current CAPsMAN address and identity on CAP;
*) wifi - show inherited properties with "print" command (replaces "actual-configuration") and added "print config" for showing only configured values;
*) winbox - added "Download" and "Flush" buttons under "System/Certificates/CRL" menu;
*) winbox - added "Flat Snoop" button under "WiFi" menu;
*) winbox - added "Request logout" button under "System/Users/Active Users" menu;
*) winbox - added "Trusted" checkbox under "System/Certificates/Import" menu;
*) winbox - added invalid flag under "IP/DHCP Relay" menu;
*) winbox - added key type and key length column for user SSH keys;
*) winbox - added missing SFP monitoring properties under "Interface/SFP" menu;
*) winbox - added passphrase option for SSH host key export;
*) winbox - added passphrase option for SSH host key import;
*) winbox - allow specifying size and rtmpfs size with M, G units under "System/Disks" menu;
*) winbox - allow to specify "M" or "G" postfix for download, upload or total limits under "User Manager/Limitations" menu;
*) winbox - do not show "Host Key Size" when using ed25519 key under "IP/SSH" menu;
*) winbox - fixed the issue where the skin file fails to appear in the user group menu after creation;
*) winbox - renamed "Channel" column to "Current Channel" under "Wifi" menu;
*) winbox - show "Valid Servers" and "Unknown Servers" column by default under "IP/DHCP Server/Alerts" menu;
*) winbox - show inherited properties for wifi interfaces;
*) winbox - show SIM settings for SXTR device under "Interfaces/LTE/Modem" menu;
*) winbox - updated icons for certain menus;
*) wireguard - added option to mark peer as responder only;
*) wireguard - added peer "name" field and display it in logs;
*) wireguard - do not attempt to connect to peer without specified endpoint-address;
*) wireguard - fixed "auto" argument usage for "private-key" and "preshared-key" settings;
*) wireguard - fixed performance issues showing QR code;
*) wireless - perform shorter channel availability check for 5600-5650MHz if regulatory domain permits it;
*) x86 - fixed ixgbe Tx hang by disabling TSO;
*) x86 - ice driver update to v1.13.7;
*) x86 - improved stability for RTL8125 driver;
*) x86 - ixgbe driver update to 5.19.9;
*) x86/chr - improved panic saving (increased minimal RAM requirements to 256MB);
Development release tree

--