KeeneticOS 3.9
KeeneticOS 3.9.2
23/12/2022
New
The new country option for
Israel
is now available in the 5 GHz Wireless Network settings. [SYS-687]
Fixed
The Keenetic mobile app no longer shows the
New network client: ...
message when a wireless client fails to connect to the Wi-Fi. [NDM-2510]The pop-up for VPN statistics now displays correctly on mobile phone screens. [NWI-1481]
The Scan the network option on the Wi-Fi monitor page now displays the scanning result correctly. [SYS-679] [Forum topic]
Changing settings of a wired interface no longer excludes it from the connection policy in the Connection priorities menu. [NWI-1488] [Forum topic]
The L2TP/IPsec VPN connection reconnects correctly after an Internet connection recovery. [NDM-2507]
KeeneticOS 3.9.1
09/12/2022
New
The new Multi-AP backhaul compatibility option for Range Extender mode allows extension of the wireless coverage of a non-Keenetic Mesh enabled device that requires transmission of Wi-Fi data frames in the 4-address format. [NWI-1468]
Fixed
The validation of occupied IP addresses on the Device lists page now works as before. [NWI-1456]
The link position of the edit schedule displays appropriately on mobile screens. [NWI-1463] [Forum topic]
The network topology picture from the Extender mode now displays correctly on mobile screens. [NWI-1477]
The L2TP/IPsec VPN server configuration now applies as expected. [NDM-2495]
KeeneticOS 3.9.0
25/11/2022
New
There are no changes for Keenetic City (KN-1510).
Improved
The
MiniUPnPd
service no longer restarts after a DHCP lease update on a WAN connection. [NDM-2459] [Forum topic]
Fixed
The authorization of Windows clients has been fixed for the captive portal Spot4 service. [NDM-2383]
Changing the state of the underlying interface for WireGuard VPN no longer causes a system reboot. [NDM-2424]
Restored L2TP/IPsec VPN server interoperability with common smartphone and desktop clients. [NDM-2433, NDM-2468] [Forum topic]
In the case of switching from backup to the primary WAN connection, network sessions are cleared, ensuring correct routing via the primary connection. [NDM-2456]
DNS content filter assignments now apply correctly after the device restart. [NDM-2457]
The Transit requests option now works as expected. [NDM-2479]
KeeneticOS 3.9 Beta 2
07/11/2022
New
There are no changes for Keenetic City (KN-1510).
Improved
The OpenSSL library is updated to the latest version
3.0.7
, fixing the CVE-2022-3602 and CVE-2022-3786 vulnerabilities. [SYS-669]
Fixed
The logo alignment has been fixed for the Login page on mobile screens. [NWI-1387] [Forum topic]
Fixed the inline position of the Update channel information section on the System dashboard page. [NWI-1388] [Forum topic]
The Transit requests option now operates correctly for all available DNS resolution profiles. [NDM-2403]
The cause of periodic VPN IKEv2 tunnel disconnection has been fixed. [NDM-2413]
The text style of the Confirm button is changed so that the text description is better placed for all languages in mobile view. [NWI-1449] [Forum topic]
The OpenVPN client and server system component with the new
2.6
version no longer requires an installed IPv6 system component for operation. [NDM-2441]
KeeneticOS 3.9 Beta 1
12/10/2022
New
The new Fail-safe configuration mode lets you change Keenetic's settings from anywhere without worrying that you'll lose control by choosing the wrong settings. If a remote management session terminates abnormally, the device will automatically reboot in three minutes, and undo the changes. [NWI-1429, NDM-1945, NDM-1844]
Improved
Internal Firewall rules have been updated to allow usage of the DHCPv6 relay agent. [NDM-2410]
Fixed
The connection toggles On/Off on the Other connections page have been fixed, providing better responsiveness. [NWI-1419]
The
LLDP
service does not cause theService: "Link-layer discovery observer": unexpectedly stopped. unknown option "a".
error message in the System log. [NDM-2409] [Forum topic]
KeeneticOS 3.9 Beta 0.6
25/09/2022
Improved
The new relay multicast DNS (mDNS) option is now available in segment settings allowing transmission of mDNS messages between all segments. [NWI-1368]
Fixed
There are no changes for Keenetic City (KN-1510).
KeeneticOS 3.9 Beta 0
18/09/2022
Improved
The Wi-Fi channels used by Keenetic itself are highlighted now on the diagram and table on the Wi-Fi monitor page. [NWI-1389]
Fixed
The menu titles are now visible in the mobile Web Interface. [NWI-1377] [Forum topic]
The Save button was missing when editing the speed limit setting; this has been fixed. [NWI-1390]
The Wake-on-LAN (WoL) option now works properly in network segments with
security-level protected
settings. [NDM-2385] [Forum topic]Resolves the issue of duplicate entries in the system's routing table. [NDM-2391]
KeeneticOS 3.9 Alpha 9
10/09/2022
New
There are no changes for Keenetic City (KN-1510).
Fixed
When an active dual-stack IPv6 connection is present, KeenDNS IPv4 access in the Direct mode operates correctly. [NDM-2378]
The root CA (Certificate authority) certificate validation has been fixed for legacy Keenetic devices. [SYS-632] [Forum topic]
KeeneticOS 3.9 Alpha 8
06/09/2022
New
The Fast Leave option provides a quick switch between IPTV channels via an IGMP proxy when supported by the ISP. [NDM-2375] [Forum topic]
You can use the following command in the CLI:
igmp-proxy fast-leave
— enable IGMPv2 Fast Leave.
Improved
The OpenSSL library has been updated to version
3.0.5
. [SYS-628]
Fixed
The IPsec service management has been revised to improve stability and operation under heavy system load. This should prevent the
system failed [0xcffd00ac], code = 255
error from appearing in the System log. [NDM-624]
KeeneticOS 3.9 Alpha 7
27/08/2022
New
On the Connection priorities page, the new colour-coded states option will display the current state for each connection. There are three colours available: [NWI-1326]
Grey — connection is disabled;
Red — no connection or failure to connect;
Green — connection is established.
The new Enable multipath option is now available on the Connection priorities page. You can automatically balance the throughput among included connections by switching the custom Connection Policy to the Multipath mode. [NWI-1328]
On the General system settings page, there is now a checkbox that allows you to enable the SNTP service for the local network. [NWI-1330]
Improved
The Wi-Fi monitor page has received several design improvements and changes. [NWI-1325]
Backward compatibility with the
Europe/Kiev
time zone was added after it was renamed toEurope/Kyiv
. See Release 2022b - 2022-08-10 notes. [NDM-2362]
Fixed
The positioning of tooltips and tables in the Web Interface has been changed to provide a better view on screens with
1366x768
resolution. [NWI-1365]We have addressed the broken Wi-Fi LED indication, which was present in the previous 3.9 Alpha 6 firmware. [SYS-615] [Forum topic]
The DHCPv6 stateless mode now operates correctly and propagates DNS server information to DHCPv6 clients. [NDM-2363] [Forum topic]
KeeneticOS 3.9 Alpha 6
14/08/2022
New
The new SNTP (Simple Network Time Protocol) server feature provides time synchronization for your LAN applications. [NDM-2338]
Use the following CLI command:
ntp master
— enable SNTP server inprivate
andprotected
segments
Improved
Both DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH) now support the IPv6 protocol. [NDM-2344]
NextDNS content filtering now uses the IPv6 protocol when available. [NDM-2345]
The Internet Checker service (
show internet status
) now inspects the Internet availability via both IPv6 and IPv4 protocols. [NDM-2348]The
RU/US
country code substitution on the 5 GHz Wireless Network has been disabled as an outdated workaround. [SYS-613]
KeeneticOS 3.9 Alpha 5
06/08/2022
New
The new Transit requests option of the DNS profile allows profile-linked devices to resolve domain names via the DNS servers requested by the device instead of forcing the resolution via DNS servers specified in the profile. [NWI-1130]
The Software Network Accelerator now offloads IPv6 traffic, including MAP-T and DS-Lite IPv4 over IPv6 traffic, helping to reduce processor load and speed up traffic transfer. [SYS-611]
Improved
System and user-defined DNS profiles are now available for assignment from the content filtering profiles drop-down list, along with public DNS presets or commercial services, depending on your configuration. [NWI-1129]
Assigned unconditional priority to user-defined DNS profiles over public DNS presets and cloud DNS profiles. [NDM-2323]
Fixed
The device schedule assignment is now applying as expected. [NWI-1306]
The subnet mask validator now acts appropriately with the
255.255.255.255 (/32)
network mask. [NWI-1310]Fixed the Use for accessing the Internet checkbox for WireGuard connections. [NWI-1319] [Forum topic]
KeeneticOS 3.9 Alpha 4
31/07/2022
New
The new Scan for networks feature provides detailed and graphical information about the networks in the air at the Wi-Fi monitor page. [NWI-1280]
Improved
Improved security: the DNS requests from blocked devices are now disabled via the DNS-proxy service of the KeeneticOS. [NDM-2321]
Fixed
The empty Traffic Monitor page has been fixed. [NWI-1290] [Forum topic]
The button to import PPPoE-settings from previous routers now displays correctly in all the languages of the Web Interface. [NWI-1293]
The Enter button acts as the Next string action instead of the Save action during editing of the OpenVPN connection. [NWI-1286] [Forum topic]
The legend captions for the Spectrum analyser and Wi-Fi monitor have been corrected. [NWI-1285]
Fixed the font size of the IPsec VPN input fields in the Safari browser. [NWI-1287] [Forum topic]
KeeneticOS 3.9 Alpha 3
24/07/2022
Improved
The OpenSSL library is updated to the latest version
1.1.1q
, fixing the CVE-2022-2097 vulnerability. [NDM-2308]The
source IP address
is appended to the HTTP/HTTPS serverauthentication failure
message, providing advanced network maintenance information. The logging of failed authentication to the Web Interface is disabled by default. Use the following CLI command to enable:ip http log auth
[NDM-2317][E] Jul 25 16:16:30 ndm: Core::Scgi::Auth: authentication failed for user "admin" from "92.162.143.77".
Fixed
Fixed the DNS proxy service error causing
do_page_fault(): sending SIGSEGV
error message in the System log. [SYS-592] [Forum topic]Fixed the OpenVPN service error causing
enable extended error passing on TCP/UDP socket failed (IPV6_RECVERR)
error message in the System log. [NDM-2304]
KeeneticOS 3.9 Alpha 2
16/07/2022
Fixed
Fixed DoT (DNS over TLS) operation after reconnection of a PPPoE session. [NDM-2215]
The Logout button is visible now on mobile screens. [NWI-1243]
The message telling that the ISP is managing the Keenetic device appeared in the wrong context under certain conditions. [NWI-1246]
The Connection priority dropdown menu displays a correct list of connections. [NWI-1256] [Forum topic]
Restored DNS over TLS (DoT) operation with custom Domain setting. [NDM-2286]
KeeneticOS 3.9 Alpha 1
05/07/2022
New
The new Proxy client is available now as a KeeneticOS system component providing Internet access via proxy servers using HTTP, HTTPS and SOCKS v5 protocols. [NDM-2195]
The following CLI commands are available to configure the Proxy client component:
interface Proxy0 proxy protocol (socks5 | http)
— choose the protocol type for the proxy connection;interface Proxy0 proxy upstream {host} [{port}]
— set address and port for proxy service, enter{host}
value as<fqdn>
or<IP>
;interface Proxy0 authentication identity {identity}
— set proxy authentication username;interface Proxy0 authentication password {password}
— set proxy authentication password;interface Proxy0 proxy connect [via {via}]
— choose interface for proxy connection.
The Proxy connection section is available in the Other connections menu for Internet access via HTTP/HTTPS/SOCKS5 proxy. [NWI-1108]
DS-Lite (IPv6 dual-stack lite) support is now available via automatic IPv4 over IPv6 provisioning, allowing access to IPv4-only enabled resources while the ISP provides a connection with the modern IPv6 protocol. [NDM-2060]
The new TCP/TLS port check mode enhances the Ping Check feature to provide verified protection against Internet access failures. This mode will prevent false-positive results if an ISP redirects traffic to a captive portal, for example, a billing service. [NDM-2094, NWI-1109]
Use the following CLI commands to set:
ping-check profile {name} mode tls
— enable TLS mode for Ping Check profile{name}
Or set up via the Web Interface for a required interface:
The new Wi-Fi monitor in the Status section provides a graphical utilization display for the Wi-Fi radio frequency channel currently in use. [NWI-1179]
Improved
Fixed
Renaming an Extender no longer causes unnecessary reconfiguration of the Wi-Fi System. [NWI-1188]
Fixed the TLS domain name and Domain fields mixing up in DNS configuration settings under certain conditions. [NWI-1222]
Restored the Speed limit saving for unregistered devices in the Device lists menu. [NWI-1239]
The DNS servers assigned by the ISP remain operatable when custom DNS servers are in use. [NDM-2265]
Keenetic mobile application no longer sends the alert about an empty administrator password after the initial setup. [SYS-583]