Из интересных фич, которые ожидаются в следующих релизах #RouterOS 7
RouterOS 7.25rc1 (2026-10-01):
BGP / EVPN
*) bgp - show interface names and VRF names in BGP logs;
*) bgp - add the always-compare-med setting;
*) bgp - fix BGP unnumbered connections within a VRF;
*) evpn - publish MAC-IP routes (RT-2) for neighbors;
IPv6
*) dhcpv4-server - add ipv6-only-preferred parameter to respect option 108;
*) ipv6 - fix a failure when releasing DHCPv6 prefix delegation pools;
*) ipv6 - fix cases when address is lost after reboot if prefix was taken from pool;
*) ipv6 - fix the DNS timer in router advertisements;
*) ipv6 - ignore router advertisements received on interfaces not in the accepting list;
Monitoring
*) snmp - add an OID and logging for blacklisted program access;
*) snmp - add CAPsMAN radio data to SNMP;
*) snmp - add dynamic SNMP engine ID assignment;
*) snmp - add interface table with mtu and l2mtu OIDs;
*) snmp - add IP pool OIDs;
*) snmp - add IPv6 address and interface name to the MNDP neighbour table;
*) snmp - add OID blacklisting;
*) snmp - add OIDs for Netwatch probes;
*) snmp - add OSPF MIB tables;
*) snmp - add SHA-2 authentication for SNMPv3;
*) snmp - add transmit drop counters;
*) snmp - add VRRP status OIDs for monitoring;
*) snmp - fix the reported capability flags in LLDP-MIB;
*) snmp - fix the snmp tools timing out when authentication is used;
*) snmp - log a warning when the src-address family does not match the request;
*) snmp - remove an interface OID that should not be accessible;
*) system - remove the channel label from the RouterOS version;
HW / Firmware
*) poe-out - firmware update for 802.3at capable boards (the update will cause a brief power interruption to poe-out interfaces);
*) poe-out - firmware update for 802.3bt capable boards (the update will cause a brief power interruption to poe-out interfaces);
*) ethernet - fix link flap and unexpected reboots on RB5009;
*) ethernet - fix SFP compatibility on hAP ax S and hEX S (2025) devices;
SSH / Security
*) ssh - add a connection id to SSH log entries;
*) ssh - add host key verification for the SSH client;
*) ssh - limit server output to the client's window size;
*) ssh - show router host key fingerprint;
*) ssh - switch the default host key type to Ed25519;
*) ssh - warn users when weak RSA key is being used;
*) system - improve stability (includes CVE-2026-31431, CVE-2026-67280);
Certs
*) certificate - fix ACME certificate issuance for wildcard domains;
*) certificate - refactor certificate internal processes;
Tunnels
*) winbox - show WireGuard peer information;
*) wireguard - add the client-mtu parameter;
*) wireguard - allow referencing a peer by its name;
*) wireguard - allow unsetting the client-listen-port;
*) wireguard - improve error message reporting when adding a new peer;
*) wireguard - keep peer rx/tx counters when the peer is disabled and enabled;
*) wireguard - support comment lines in wg-import configuration files;
*) wireguard - treat empty private-key and preshared-key values as none;
*) wireguard - use the MTU value when importing a configuration;
*) wireguard - warn when an allowed-address overlaps another peer;
Other
*) tftp - add VRF support;
*) bridge - add dynamic ARP inspection;
*) bridge - add IP source guard;
*) bridge - warn about VLAN entries when vlan-filtering is disabled;
*) firewall - add NAT-related fields to CEF format logging;
RouterOS 7.25rc1 (2026-10-01):
BGP / EVPN
*) bgp - show interface names and VRF names in BGP logs;
*) bgp - add the always-compare-med setting;
*) bgp - fix BGP unnumbered connections within a VRF;
*) evpn - publish MAC-IP routes (RT-2) for neighbors;
IPv6
*) dhcpv4-server - add ipv6-only-preferred parameter to respect option 108;
*) ipv6 - fix a failure when releasing DHCPv6 prefix delegation pools;
*) ipv6 - fix cases when address is lost after reboot if prefix was taken from pool;
*) ipv6 - fix the DNS timer in router advertisements;
*) ipv6 - ignore router advertisements received on interfaces not in the accepting list;
Monitoring
*) snmp - add an OID and logging for blacklisted program access;
*) snmp - add CAPsMAN radio data to SNMP;
*) snmp - add dynamic SNMP engine ID assignment;
*) snmp - add interface table with mtu and l2mtu OIDs;
*) snmp - add IP pool OIDs;
*) snmp - add IPv6 address and interface name to the MNDP neighbour table;
*) snmp - add OID blacklisting;
*) snmp - add OIDs for Netwatch probes;
*) snmp - add OSPF MIB tables;
*) snmp - add SHA-2 authentication for SNMPv3;
*) snmp - add transmit drop counters;
*) snmp - add VRRP status OIDs for monitoring;
*) snmp - fix the reported capability flags in LLDP-MIB;
*) snmp - fix the snmp tools timing out when authentication is used;
*) snmp - log a warning when the src-address family does not match the request;
*) snmp - remove an interface OID that should not be accessible;
*) system - remove the channel label from the RouterOS version;
HW / Firmware
*) poe-out - firmware update for 802.3at capable boards (the update will cause a brief power interruption to poe-out interfaces);
*) poe-out - firmware update for 802.3bt capable boards (the update will cause a brief power interruption to poe-out interfaces);
*) ethernet - fix link flap and unexpected reboots on RB5009;
*) ethernet - fix SFP compatibility on hAP ax S and hEX S (2025) devices;
SSH / Security
*) ssh - add a connection id to SSH log entries;
*) ssh - add host key verification for the SSH client;
*) ssh - limit server output to the client's window size;
*) ssh - show router host key fingerprint;
*) ssh - switch the default host key type to Ed25519;
*) ssh - warn users when weak RSA key is being used;
*) system - improve stability (includes CVE-2026-31431, CVE-2026-67280);
Certs
*) certificate - fix ACME certificate issuance for wildcard domains;
*) certificate - refactor certificate internal processes;
Tunnels
*) winbox - show WireGuard peer information;
*) wireguard - add the client-mtu parameter;
*) wireguard - allow referencing a peer by its name;
*) wireguard - allow unsetting the client-listen-port;
*) wireguard - improve error message reporting when adding a new peer;
*) wireguard - keep peer rx/tx counters when the peer is disabled and enabled;
*) wireguard - support comment lines in wg-import configuration files;
*) wireguard - treat empty private-key and preshared-key values as none;
*) wireguard - use the MTU value when importing a configuration;
*) wireguard - warn when an allowed-address overlaps another peer;
Other
*) tftp - add VRF support;
*) bridge - add dynamic ARP inspection;
*) bridge - add IP source guard;
*) bridge - warn about VLAN entries when vlan-filtering is disabled;
*) firewall - add NAT-related fields to CEF format logging;