KeeneticOS 5.0
KeeneticOS release notes for Keenetic Carrier (KN-1721) in the Development Channel
KeeneticOS releases in this channel show what we're working on right now. We update roughly weekly. N.B.: While releases in this channel do undergo testing, they are still sometimes bugs present, as we want you, our community, to share in what's new as soon as possible. Your input is really valued.
Keenetic Carrier (KN-1721) is currently in the Standard Updates support period and receives regular software updates, including security enhancements, new features, operating system updates, and bug fixes.
KeeneticOS 5.0 Beta 3
10/10/2025
New
- Implemented a CLI option to override the DNS server for clients of the built-in VPN servers. [NDM-4032] - crypto map virtual-ip dns-servers {dns1} [dns2]— add DNS servers for clients of the IKEv1/IPsec VPN Server and IKEv2/IPsec VPN Server applications;
- crypto map l2tp-server dns-servers {dns1} [dns2]— add DNS servers for clients of the L2TP/IPsec VPN Server application;
- sstp-server dns-servers {dns1} [dns2]— add DNS servers for clients of the SSTP VPN Server application;
- vpn-server dns-servers {dns1} [dns2]— add DNS servers for clients of the PPTP VPN Server application;
- oc-server dns-servers {dns1} [dns2]— add DNS servers for clients of the OpenConnect VPN Server application.
 
Improved
- Added support for including IP subnets in the Domain Name Lists, using the - object-group fqdn includecommand in the CLI or via the DNS-Based Routes tab on the Routing page. [NDM-4078]- Command example: - object-group fqdn TEST include 10.0.0.1/24
- Adjusted the intensity of recurring name resolutions for the currently unclaimed names in the FQDN Object group ( - object-group fqdn). [NDM-4082]
- Enabled external access to the IPv6 addresses of backup WAN connections. [NDM-4067] 
Fixed
- Fixed an issue that caused multiple - Dns::Route::ResolveQueuemessages to appear in the System Log when using FQDN object groups with many entries. [NDM-4086]
- The following fixes have been applied to the Web Interface. - Fixed an issue where the hint button icon shifted position on mobile screens, including on certain elements. [NWI-4447] 
- Corrected the display of each application’s Blacklist status on the Application Traffic Analyser page. [NDM-4051] 
- Fixed the display of the WireGuard VPN Server Statistics pop-up. [NWI-4425] 
- Fixed the blocking of Wireless Network toggles in network segment settings on Mesh Wi-Fi System extenders. [NWI-4450] 
- Fixed an issue with the display of drop-down lists on mobile screens. [NWI-4448] 
- Fixed the display of - TunnelSixInFourinterfaces when editing static routes. [NWI-4456]
 
- Resolved an issue with L2TP traffic handling when the L2TP/IPsec VPN Server application is enabled. [NDM-4068] 
- Resolved an issue with forwarding - servfail.invalidDNS queries to upstream DNS servers. [NDM-4069]
- Fixed an issue that could cause the system to crash when connecting clients using Wi-Fi OWE (Opportunistic Wireless Encryption) authentication. [SYS-1461] 
- Fixed an issue on the Routing page that prevented disabling individual static route entries without affecting others. [NDM-4076] 
KeeneticOS 5.0 Beta 2
26/09/2025
New
- Implemented a new Enable IPv6 checkbox and an IPv6 configuration section for Home and additional local network segments, providing advanced control over IPv6 parameters and allowing IPv6 to be disabled per segment. [NWI-4373]  
- Introduced a new design for the Internet card on the System Dashboard page, featuring an updated layout and buttons to manage the display of connection statistics and traffic chart blocks. [NWI-4377]  
Improved
- The following improvements have been applied to the Web Interface. - The KeenDNS tab on the Domain Name page now features a single checkbox to enable both IPv6 and IPv4, simplifying setup and improving dual-stack compatibility. Added support for direct access via the IPv6 protocol and fixed an issue with incorrectly processed KeenDNS mode configurations. [NWI-4427] 
- Added support for USSD requests starting with - #, improving correct processing of these commands. [NWI-4401]
- Improved the naming of WireGuard VPN Server client peer configuration files for better compatibility with the official WireGuard® application. [NWI-4424] 
 
- Added Basic authentication support for the OpenConnect VPN client via the command line interface (CLI). [NDM-4037] - interface {name} openconnect allow-basic-auth— enable the basic authentication for the- {name}OpenConnect connection.
 
Fixed
- The following fixes have been applied to the Web Interface. - Corrected parameter validation in the iPerf3 network connection test utility on the Diagnostics page. [NWI-4402] 
- Corrected sorting for the Profile column on the Content Filter tab of the Internet Safety page and the Ports column on the Port Forwarding page. [NWI-4386] 
- Corrected the layout when printing Wi-Fi connection information from the My Networks and Wi-Fi card on the System Dashboard page. [NWI-4387] 
- Fixed the DNS profile editing issue when the Cloud-based content filtering and ad blocking component was not installed. [NWI-4396] 
- Fixed the incorrect display of the Interface selector when editing Routing Rules on the DNS-based Routes tab. [NWI-4405] 
- Fixed the issue where Wi-Fi access points from a deleted segment were still displayed on the Firewall tab. [NWI-4407] 
- Fixed several configuration issues related to user-defined routes in the Routing page. [NWI-4428] 
 
- Resolved an issue where the - DNS proxyservice could enter a busy loop when processing malformed DNS responses, improving stability and performance. [NDM-4034]
- Fixed an issue with the Exclusive Route option in DNS-based Routes. [NDM-4046] 
- Fixed inbound Web Interface access via IPv6 on interfaces configured with the - privateor- protectedsecurity level. [NDM-4061]
- Fixed the display of remote IP addresses and ports for clients in the WireGuard VPN Server Statistics popup window. [NDM-4064] 
KeeneticOS 5.0 Beta 1
11/09/2025
New
- Further improvements to the Mesh Wi-Fi System allow an Extender’s built-in 4G/3G modem to be used as the primary or a backup Internet connection. When a compatible Extender is detected, the Controller automatically creates a dedicated - MwsMobileinterface and manages the connection like any other, including its use in Connection Policies. SMS and USSD modem options are available directly in the Extender’s Web Interface, which can be opened via a link on the Controller’s Wi-Fi System page. [NDM-4027]  
- The Port Forwarding page now supports IPv6 Pinholing, letting you open TCP and UDP ports to provide external access from the Internet to devices on your home network that use IPv6 addresses. [NWI-4213]  
- Added support for the Virtual Router Redundancy Protocol (VRRP) v2 and v3, configurable via the command line interface (CLI). This enables redundant routing across multiple routers. To use it, install the VRRP support system component. [SYS-1443] - interface {name} vrrp group {group} ip {ip}— set virtual IP address for the group;
- interface {name} vrrp group {group} priority {priority}— set priority (integer in the range 0 to 255), the device with the numerically highest priority becomes the master in the group;
- interface {name} vrrp group {group} advertise {advertise}— set advertisement interval in seconds (integer in the range 1 to 255, the default is 1);
- interface {name} vrrp version {version}— set protocol version, supported values:- default— use version 2 for IPv4 and version 3 for IPv6;
- v2— strict compliance to VRRP version 2:- zero VIPs are not allowed; 
- unicast peers are not allowed; 
- IPv6 addresses are not allowed; 
- state MASTER can be configured strictly when priority is 255; 
 
- v3— compliance to VRRP version 3 for both IPv4 and IPv6;
- v3-compat— VRRPv3 compatibility mode for interoperability with implementations (such as Cisco and Juniper) that treat RFC 5798 §5.2.8 as applying only to IPv6. When enabled, the router includes the IPv4 pseudo-header but omits it from the IPv4 checksum calculation;
 
- show interface {name} vrrp— display the VRRP status.
 
Fixed
- The following fixes have been applied to the Web Interface. - Fixed several issues with the WireGuard VPN Server configuration. [NWI-4372] 
- Fixed display issues affecting the Clients tooltip in the nodes list on the Mesh Wi-Fi System page. [NWI-4379] 
- Corrected the Latest handshake values displayed in the WireGuard connections list on the Other Connections page. [NWI-4384] 
 
- Fixed an issue where the - identity-localparameter was reset when reconfiguring the IPsec VPN Server. [NDM-4036]
KeeneticOS 5.0 Beta 0
01/09/2025
New
- The new DNS-Based Routes tab on the Static Routes page allows creating custom routing rules via a specified connection or gateway for user-defined lists of domain names and IP addresses. [NWI-4186]    
- The Diagnostics page now includes an iPerf utility in the Network Connection Test section, enabling bandwidth and performance testing directly from the web interface. To use it, install the iPerf3 system component on your device. [NWI-4371]  
Improved
- Improved the DNS Configuration tab on the Internet Safety page to provide a more convenient layout on mobile devices. [NWI-4375] 
- Added support for specifying IP sub-networks with the - object-group fqdn excludeCLI command. [NDM-4013]- Command example: - object-group fqdn TEST exclude ::/0
Fixed
- The OS Kernel has been patched to resolve the following CVE security vulnerabilities: - CVE-2024-36971. [SYS-1436] 
- CVE-2024-41012. [SYS-1430] 
- CVE-2024-50302. [SYS-1431] 
 
- Fixed an issue where the SSH server was not accessible from the Internet over IPv6 in certain conditions. [NDM-4010] 
KeeneticOS 5.0 Alpha 13
23/08/2025
Improved
- Added the Average speed information to the Traffic Monitor page. [NWI-4212] 
- Added the date and time to the filenames of downloaded firmware and startup-config configuration files. [NDM-3999] 
- Added an option to exclude sub-domain names for Object Groups via the command line interface (CLI). [NDM-4001] - object-group fqdn {name} exclude {address}— exclude the- {address}sub-domain from the- {name}object group.
 
Fixed
- The following fixes have been applied to the Web Interface. - Fixed the validation in the DNS server URL field when selecting DNS-over-HTTPS server type on the DNS Configuration page. [NWI-4350] [Forum topic] 
 
- Fixed an error causing the - ResolveQueue: system failed [0xcffd0046]records to appear in the System log when using the Public DNS resolvers option for content filtering. [NDM-4002]
KeeneticOS 5.0 Alpha 12
19/08/2025
New
- New USB modems are now supported, including: - Olax F90 4G LTE Cat4 USB modem. [NDM-3983] 
- Fibocom FM101-GL LTE Cat6 USB ( - UsbQmi-type) modem module. [NDM-3970]- Tip- To connect an LTE module to your Keenetic device, you can purchase a third-party USB adapter with a SIM card slot for the Mini PCI-E LTE module or M.2 LTE module. 
 
- Implemented - Originheader enforcement for the KeenDNS Web application proxies. [NDM-3988]- ip http proxy {name} force-origin {origin}— force the addition of the specified- {origin}header to the- {name}HTTP(s) proxy.
 
Fixed
- Fixed the End User License Agreement title spacing in the Web Interface. [NWI-4344] 
- Fixed a regression introduced with the new - manageruser role that prevented seamless access to Wi-Fi System Extenders via HTTPS token. [NDM-3981]
KeeneticOS 5.0 Alpha 11
09/08/2025
New
- The Internet Safety page now features an Application Filter tab with controls to block traffic from specific applications and categories for individual clients or entire network segments. To use this feature, you must install the Traffic classification engine system component and enable the Application Classification option on the IntelliQoS page. [NWI-4232]   
- The new WireGuard VPN Server application makes it easier to set up various remote connection scenarios. It enables quick installation on client devices, providing secure access to any part of your network. [NWI-4206]  
- Implemented UPnP IGDv2 PCP support for the IPv6 protocol. [NDM-3859] 
- Added a new Manager user role featuring limited administrative rights for ISP deployment scenarios. [NDM-3945] 
Improved
- The following improvements have been applied to the Web Interface. - Reduced the response time of Wi-Fi toggles on the segment settings pages. [NWI-4363] 
- Added the Network access setting for IKEv1/IPsec VPN and IKEv2/IPsec VPN servers. [NWI-4328] 
- Added the data transfer statistics to the Site-To-Site IPsec VPN Connections table. [NWI-4318] 
 
Fixed
- The following fixes have been applied to the Web Interface. - Fixed the on-click behavior for the drop-down lists. [NWI-4365] 
- Fixed the Web UI search functionality for the word ' - graph' keyword. [NWI-4327]
- Fixed the incorrect Allowed v6 IPs field validator on the WireGuard VPN connection settings page. [NWI-4355] 
- Fixed a number of issues that were occurring when editing user rights and passwords on the user credential popup. [NWI-4131] 
- Refined the display of the WireGuard connections list on the Other Connections page. [NWI-4337] 
- Fixed the display of the custom logo on the Connection Information for the Wi-Fi network popup on the System Dashboard. [NDM-3969] 
 
- Fixed configuration issues of the iperf3 system component. [NDM-3972] 
KeeneticOS 5.0 Alpha 10
02/08/2025
New
- The iperf3 system component now includes server mode functionality, enabling users to test the bandwidth between nodes on their home network. However, test speeds may be limited by the performance of certain device models. [NDM-3786] - iperf3 interface {interface}— bind to a specific interface (default: bind to all interfaces according to the security level);
- iperf3 port {port}— set port (default: 5201);
- iperf3 security-level (public | protected | private)— set security level (default: private);
- service iperf3— run the server.
 
- Implemented a virtual - Dummynetwork interface for ISP-managed routing applications, simulations, testing, and other uses. [NDM-3958]- interface Dummy0— create- Dummy0interface.
 
- The new Duny service is now available for the Dynamic DNS (DDNS) client system component. [NDM-3959] 
Improved
- The client part of the iperf3 system component has been extended to support the - reverseand- streamsarguments, enabling download bandwidth testing and the use of parallel network streams. [NDM-3963]- tools iperf3 {host} [ipv4 | ipv6] [tcp | udp] [reverse] [port {port}] [bitrate {bitrate}] [streams {streams}] [time {time} | bytes {bytes}] [source-interface {source-interface}];
 - Example command: - tools iperf3 ping.online.net reverse port 5202 streams 2 time 5. 
- Moved the - acq,- apn, and- wwan-force-connectedcommand-line configuration commands from the- usbsub-tree to the- mobilesub-tree; see details below. [NDM-3950]- Deprecated - interface {name} usb acq→ current- interface {name} mobile acq;
- Deprecated - interface {name} usb apn→ current- interface {name} mobile apn;
- Deprecated - interface {name} usb wwan-force-connected→ current- interface {name} mobile force-connected.
 
- Implemented - user:password@authentication credentials support for URLs in the- opkg diskCLI command. [NDM-3960]- Example command: - opkg disk storage:/ https://user:password@router.keenetic.pro/webdav/mipsel-installer.tar.gz.
 
Fixed
- Fixed an issue where configuration changes to network segments in the Web Interface were not retained and were being reset. [NWI-4353] 
- Fixed several bugs in the operation of FQDN-based routing rules. [NDM-3956] 
- Fixed an issue where the OpenConnect client failed to establish a connection with the - system failed [0xcffd0085]error caused by IPv6 DNS usage. [NDM-3962]
KeeneticOS 5.0 Alpha 9
26/07/2025
New
- Introduced a new routing option based on FQDN object-groups, enabling more precise and flexible control over traffic directed to specific domain names. [NDM-3946] - dns-proxy route object-group {group} [{interface} | {gateway} [interface]] [auto] [reject]— set routing destination- {interface}or- {gateway}for domain names listed in the object-group- {group}.
 
Improved
- Improved the loading speed of dialogue popups on the Client Lists page when the Knowledge Base article links cannot be obtained or unavailable. [NWI-4326] 
Fixed
- The following fixes have been applied to the Web Interface. - Removed the Delete segment button from the Home segment settings page to prevent accidental deletions. [NWI-4340] 
- Fixed the display of the drop-down list on the Internet Safety page. [NWI-4306] 
- Fixed an issue where the Save button for a Modify TTL value on the Mobile connection settings page did not appear correctly. [NWI-4322] 
- Resolved a display issue with the Clients tooltip in the nodes list on the Mesh Wi‑Fi System page. [NWI-4323] 
 
- Fixed an issue where user-defined static DNS records ( - ip host) lost priority over dynamically obtained records after the device restarted. [NDM-3947]
- The - PersistentKeepalivevalue is now automatically set to 15 seconds when importing a WireGuard configuration file that lacks this parameter, ensuring correct connection establishment. [NDM-3948]
- Fixed the address resolution issue that occurred during dynamic reconfiguration in OpenConnect, Proxy, and ZeroTier VPN connections when the server address is specified as an URL. [NDM-3951] 
- Fixed the incorrect behaviour of the DDNS service when using IPv4 and IPv6 addressing simultaneously or relying solely on the IPv6 protocol. [NDM-3952] 
- Fixed the MAP-T handling of IPv6 UDP packets with a zero checksum by RFC 6935, improving compatibility with the IPsec protocol. [SYS-1404] 
- Fixed the incorrect saving of the - no system log reductionCLI command to the running configuration. [NDM-3953]
- Resolved an issue where clients of IKEv1/IPsec VPN and IKEv2/IPsec VPN servers did not receive static routes correctly. [NDM-3954] 
KeeneticOS 5.0 Alpha 8
19/07/2025
New
- The new iperf3 system component has been implemented, enabling the measurement of bandwidth of a specified network connection via the command line interface (CLI). However, test speeds may be constrained by the performance of specific router models. [NDM-3785] - tools iperf3 {host} [ipv4 | ipv6] [tcp | udp] [port {port}] [bitrate {bitrate}] [time {time} | bytes {bytes}] [source-interface {source-interface}]
 - Example command: - tools iperf3 ping.online.net port 5202 time 10 
- Support for the Local Profile Assistant (LPA) and embedded Subscriber Identification Module (eSIM) has been added to the - UsbLteand- UsbQmimodem interfaces via the command line (CLI). The eSIM chip can be built into the 5G/4G modem or accessed via an external eSIM adapter. [NDM-3850]- show interface {name} esim— get eSIM status (incl. EID),
- interface {name} esim profile download {qrcode}— download eSIM profiles,
- interface {name} esim profile list— list eSIM profiles,
- interface {name} esim profile activate {iccid}— activate eSIM profile,
- interface {name} esim profile deactivate {iccid}— deactivate eSIM profile,
- interface {name} esim profile delete {iccid}— delete eSIM profile,
- interface {name} esim profile rename {iccid} {newname}— rename eSIM profile.
 
Improved
- An interface selection option has been added when exporting user-defined routes to a - .batfile, enabling customised route export per interface. [NWI-4288]
- The IPv6 system component was removed, as IPv6 functionality has been integrated into the base OS. [NDM-3935] 
Fixed
- Fixed an issue that caused the error message - socks5 client read authto appear when using a Proxy connection with- socks5protocol under certain conditions. [NDM-3942]
- Fixed various issues related to importing WireGuard configurations from a file, improving reliability and compatibility. [NDM-3943] 
KeeneticOS 5.0 Alpha 7
14/07/2025
New
- Added support for the Signalinks M806B LTE Cat 4 USB modem and the Signalinks D525C LTE Cat 4 USB mobile router. [NDM-3933] 
Improved
- Added SNMP metrics support for wireless broadband connections on 4G/3G modem connections. [NDM-3934] - RSSI OID: - .1.3.6.1.4.1.9.9.661.1.3.4.1.1.1.7006
- RSRP OID: - .1.3.6.1.4.1.9.9.817.1.1.1.1.1.1.7006
- RSRQ OID: - .1.3.6.1.4.1.9.9.817.1.1.1.1.1.2.7006
- SNR OID: - .1.3.6.1.4.1.9.9.817.1.1.1.1.1.3.7006
 
- The following improvements have been applied to the Web Interface. - Corrected the Auto-update status display on Wi-Fi System Extenders. When Automatic Updates are enabled on the Controller, the status now correctly shows Controller operated. [NWI-4205] 
 
Fixed
- Resolved multiple translation issues in the Web Interface related to Extender Mode. [NWI-4281] 
KeeneticOS 5.0 Alpha 6
05/07/2025
Improved
- Added tooltips to blocked fields when Fail-Safe Configuration Mode is enabled, providing users with clearer guidance on disabled settings. [NWI-4252] 
Fixed
- Fixed the tooltip display on the Wi-Fi Monitor tile of the System Dashboard page. [NWI-4298] 
- Fixed an issue where rekeying during an IKEv2 VPN connection initiated from a client to a server could cause the client to disconnect. [NDM-3922] 
- Resolved the binding of an IKEv2/IPsec VPN Server policy to a home network segment. [NDM-3925] 
- Addressed an issue that caused the - ban remote host 127.0.0.1message to appear in the System log when using the mobile application. [NDM-3926]
- Fixed an issue with the DDNS service incorrectly reporting - IPv6 update disableddespite the router having an IPv6 address. [NDM-3927]
- Fixed an issue where importing WireGuard connection settings from a file with rearranged - [Peer]and- [Interface]blocks caused the- system failed [0xcffd009e]error message to appear in the System log. [NDM-3930]
KeeneticOS 5.0 Alpha 5
29/06/2025
New
- Added an option to support the - nc(Juniper®) protocol in the OpenConnect VPN client, which is selectable via the command line interface (CLI). [NDM-3908]- interface {name} openconnect protocol (anyconnect | fortinet | nc)— Enables- nc(Juniper) support for OpenConnect interface- {name}.
 
Improved
- Implemented batch removal of User-Defined Routes per interface through the command line (CLI), allowing the destination arguments - {network} {mask} | {host}to be optional. [NDM-3911]- no ip route [{network} {mask} | {host} | default] [{gateway} | {interface}] [metric]— Deletes IPv4 routes.
- no ipv6 route [{prefix} | default] ({interface} [{gateway}] | {gateway})— Deletes IPv6 routes.
- no ip policy {name} route [{network} {mask} | {host}] [{interface} | {gateway}] [ {metric}]— Deletes IPv4 routes in policy- {name}.
- no ip policy {name} ipv6 route [{prefix} | default] ({interface} [{gateway}] | {gateway})— Deletes IPv6 routes in policy- {name}.
 - Example command: - no ip route ISP— Deletes all IPv4 static routes from the- ISPinterface.
- The following improvements have been applied to the Web Interface. - Enabled the use of - VLAN 0for Ethernet cable connections, improving compatibility with certain Internet service providers. [NWI-4315]
- Added a new Automatic theme option that adapts to the system’s light or dark colour scheme preferences for a seamless user experience. [NWI-4242] 
 
- Reduced the - "ZeroTier0": install accepted routelog message flow. [NDM-3903]
- Removed excess debug messages from the log. [SYS-1384] 
- Improved handling of routes without a specified outgoing interface. [NDM-3907] 
- Implemented support for configuring the WireGuard Peer obfuscation key in WireGuard connections via the command line interface (CLI). [NDM-3917] - interface {name} wireguard peer obfs-key {obfs-key}— Set an obfuscation key- {obfs-key}for WireGuard Peer connection- {name}.
 
- Enabled mDNS announcements for the Web Interface (HTTP) service, making it discoverable in the Home segment. [NDM-3919] 
Fixed
- The following fixes have been applied to the Web Interface. - Fixed an issue where the registration pop-up for unregistered clients could not be closed properly. [NWI-4244] 
- Fixed the table scrolling on the Application Traffic Analyser page. [NWI-4283] 
- Fixed the table display on the Wi-Fi System → Transition Log page. [NWI-4284] 
- Returned table borders around drag and drop elements. [NWI-4299] 
 
- Fixed an issue that caused the error message - Io::Serial: terminal options verification failedto appear when using a- UsbLte-type modem. [NDM-3905]
- Fixed an issue that caused - WifiStationXinterfaces to incorrectly reset their MAC address to the default state. [NDM-3906]
- Fixed the usage of the - authgroupparameter with the- anyconnectprotocol in OpenConnect VPN connections. [NDM-3918]
KeeneticOS 5.0 Alpha 4
22/06/2025
Improved
- Enabled the display of customised page title prefix on System Dashboard and WebCLI pages. [NWI-4240] 
Fixed
- The following fixes have been applied to the Web Interface. - Fixed the appearance of row borders in tables. [NWI-4250] 
- Fixed the behaviour of the left-side navigation menu items in the expanded view to ensure correct interaction and display. [NWI-4198] 
- Fixed the saving of the - ICMPand- TCP/UDP (all ports) and ICMPport forwarding rules. [NWI-4253]
- Corrected the tooltip behaviour for the desktop and mobile versions of the Mesh Wi-Fi System tile on System Dashboard. [NWI-4275] 
 
- Fixed the forwarding of negative DNS responses from the DNS proxy bound to 127.0.0.1, ensuring that local clients now receive these responses correctly. [SYS-1382] 
KeeneticOS 5.0 Alpha 3
14/06/2025
Improved
- Added ability to specify the 802.1p Priority Code Point (PCP) mapping to ISP VLANs on the Ethernet Cable Connections to Internet page for compatibility with certain ISPs. [NWI-3726]  
- The strict prevention of overlapping network configurations in the Allowed IPs field of the WireGuard peer settings has been replaced with a log notification. [NDM-3888] 
- Improved static route import/export by adding support for comments or remarks in Windows® batch files; lines ending with - :: remand- & remare now correctly identified as comments and preserved during import/export. [NDM-3889]- Routes example: - route add 5.5.5.0 mask 255.255.255.0 0.0.0.0 :: rem route-to-5-network- route add 4.4.4.4 mask 255.255.255.255 0.0.0.0 & rem route-to-4-net
Fixed
- The following fixes have been applied to the Web Interface. - Fixed colour notations for the single client tabs on the Traffic Monitor page. [NWI-4243] 
- Removed redundant notice on shared user account permissions on the IKEv2/IPsec VPN Server application page. [NWI-4245] 
 
- Fixed the issue with accessing VPN servers when connecting via the IPv6 protocol. [NDM-3886] 
- Fixed inbound IPv6 connections to the built-in SSH server. [NDM-3891] 
- Fixed the - WGOBFSnetfilter chains for correct handling of WireGuard connections configured with the- obfs-keysetting. [NDM-3890]
KeeneticOS 5.0 Alpha 2
07/06/2025
New
- Implemented the DD-WRT-compatible obfuscation key usage for WireGuard connections via the command line interface (CLI). [NDM-3883] - interface {name} wireguard obfs-key {obfs-key}— Set an obfuscation key- {obfs-key}for WireGuard connection- {name}.
 
- Implemented support for specifying a domain name (FQDN) in the IKEv2/IPsec VPN Server certificate via the command-line interface (CLI). [NDM-3884] - crypto ipsec profile VirtualIPServerIKE2 identity-local fqdn {fqdn}— Set- {fqdn}certificate for use in the IKEv2/IPsec VPN Server.
- crypto ipsec profile VirtualIPServerIKE2 identity-local fqdn ndns— Set the default KeenDNS certificate in the IKEv2/IPsec VPN Server.
 
Improved
- Removed unnecessary debug messages - Proxy0: 0x7f9ba28be0 socks5 client res.repfrom the System log when using Proxy Connections to improve log clarity. [NDM-3875]
Fixed
- Fixed the issue for Windows clients connecting to WPA/WPA2/WPA3 Enterprise-secured networks with Allow WPS option enabled. [SYS-1361] 
- Corrected traffic accounting issues causing unintended disconnections for remote clients of the IKEv2/IPsec VPN Server. [NDM-3876] 
- Resolved issues during the simultaneous operation of IKEv1/IPsec VPN Server and Site-to-Site IPsec VPN connections under specific conditions. [NDM-3878] 
- Fixed an issue potentially causing system restarts under particular conditions when using the IKEv2/IPsec VPN Server. [NDM-3880] 
- The following fixes have been applied to the Web Interface. - Fixed the issue with the Host dropdown on the Access settings card of the Domain Name page. [NWI-4204] 
 
KeeneticOS 5.0 Alpha 1
01/06/2025
New
- We are broadening our endorsement programme for Internet Operators by introducing support for the TR‑098 data model under the CPE WAN Management Protocol (CWMP). The feature is available on request. Contact our support (support@keenetic.de) for further details. [NDM-3870] 
- Added support for seamless integration with ZeroTier virtual networks on the Other Connections page. Create a Permit firewall rule to allow incoming traffic. [NWI-4164]  
- Implemented CLI commands to configure static IPv6 address and port translation rules, enhancing IPv6 NAT management via the command line. See the Command Reference Guide for full syntax. [NDM-3819] - ipv6 static [protocol] ({interface} {mac} | {mac}) [{port} [through {end-port}] ]— defines a translation rule;
- ipv6 static rule {index} (disable | schedule {schedule})— disables a rule or limits its operation by schedule.
 
Improved
- Implemented the capability to include a - UsbQmiconnection in- BridgeXconfigurations, allowing cellular links to join network bridges. [NDM-3707]
- Enhanced the - allow‑ipsvalidator to prevent overlapping networks across multiple WireGuard peers, ensuring proper routing and peer isolation. [NDM-3868]
Fixed
- Fixed an issue in which a - UsbLtemodem connection failed to restart when Ping Check was enabled in certain scenarios. [NDM-3848]