# 2026-04-27 14:18:51 by RouterOS 7.20.8 # software id = Y1CT-1WB1 # # model = CCR2004-16G-2S+ # serial number = HF109012G8D /interface bridge add fast-forward=no name=cpe_vlan_10 port-cost-mode=short add name=loopback port-cost-mode=short add fast-forward=no mtu=1500 name=public_vlan_100 port-cost-mode=short \ protocol-mode=none add name=temp port-cost-mode=short add add-dhcp-option82=yes dhcp-snooping=yes mtu=1500 name=verona \ port-cost-mode=short protocol-mode=none /interface ethernet set [ find default-name=ether1 ] l2mtu=1500 set [ find default-name=ether2 ] l2mtu=1500 set [ find default-name=ether3 ] l2mtu=1500 name=ether3-climax-11ghz \ rx-flow-control=auto tx-flow-control=auto set [ find default-name=ether4 ] l2mtu=9582 name=ether4-verona-tower set [ find default-name=ether5 ] l2mtu=9582 mtu=9000 set [ find default-name=ether6 ] l2mtu=9582 name=ether6-switch set [ find default-name=ether7 ] l2mtu=9582 mtu=9000 set [ find default-name=ether8 ] l2mtu=9582 mtu=9000 set [ find default-name=ether9 ] l2mtu=9582 mtu=9000 set [ find default-name=ether10 ] l2mtu=1500 name=ether10-powerswitch set [ find default-name=ether11 ] l2mtu=9582 mtu=9000 set [ find default-name=ether12 ] l2mtu=9582 mtu=9000 set [ find default-name=ether13 ] l2mtu=9582 mtu=9000 set [ find default-name=ether14 ] l2mtu=9582 mtu=9000 set [ find default-name=ether15 ] l2mtu=9582 mtu=9000 name=ether15_wave_n set [ find default-name=ether16 ] l2mtu=9582 mtu=9000 set [ find default-name=sfp-sfpplus1 ] l2mtu=9586 name=\ sfp-sfpplus1-verona-tower-switch set [ find default-name=sfp-sfpplus2 ] l2mtu=9586 name=sfp-sfpplus2-switch /interface eoip add disabled=yes local-address=10.254.254.101 mac-address=02:22:FE:AB:DA:38 \ mtu=1530 name=eoip-380 remote-address=204.110.191.252 tunnel-id=101 /interface vpls add mac-address=02:E4:27:10:14:C6 name=vpls-pppoe-to-virtual peer=\ 204.110.191.252 vpls-id=101:252 /interface vxlan add dont-fragment=disabled local-address=10.254.254.101 mac-address=\ 26:46:20:4A:56:C4 name=vxlan-380 port=8472 vni=1 /interface vlan add interface=sfp-sfpplus1-verona-tower-switch name=vlan9_sfpplus1 vlan-id=9 add interface=ether15_wave_n name=vlan10_ether15 vlan-id=10 add interface=sfp-sfpplus2-switch name=vlan10_sfpplus2 vlan-id=10 add interface=verona name=vlan_10_ether6 vlan-id=10 add interface=ether6-switch name=vlan_19_ether6 vlan-id=19 /interface lte apn set [ find default=yes ] ip-type=ipv4 use-network-apn=no /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik /ip dhcp-server add add-arp=yes disabled=yes interface=ether10-powerswitch lease-time=10m \ name=radiustest relay=204.110.191.248 /ip hotspot profile add dns-name=verona.tx.vntx.net hotspot-address=100.64.3.254 login-by="" \ name=hsprof1 add dns-name=verona.tx.vntx.net hotspot-address=192.168.99.254 login-by=mac \ name=radiustest use-radius=yes /ip hotspot user profile set [ find default=yes ] add-mac-cookie=no /ip pool add name=verona-cpe ranges=10.10.0.1-10.10.14.254 add name=altoga-old ranges=10.100.80.1-10.100.94.254 add name=altoga-cpe ranges=10.10.80.1-10.10.94.254 add name=verona-cgnat ranges=100.64.0.1-100.64.3.249 add name=altoga-cgnat ranges=100.64.12.1-100.64.15.253 add name=verona-tower-pool ranges=10.0.101.1-10.0.101.249 add name=radiustest ranges=192.168.99.1-192.168.99.249 /ip dhcp-server add address-pool=altoga-cpe authoritative=after-2sec-delay disabled=yes \ interface=vlan_10_ether6 lease-script=":global username \"6aYoFE5Pw8ky1JyO\ \"\r\ \n:global password \"aZLnmeROsUYfUNGw\"\r\ \n:global url \"204.110.191.244\"\r\ \n:global mode \"http\"\r\ \n\r\ \n:if (\$leaseBound = 0) do={\r\ \n /tool fetch url=\"\$mode://\$url/api/dhcp_assignments\?ip_address=\$l\ easeActIP&leased_mac_address=\$leaseActMAC&expired=1\" mode=\$mode keep-re\ sult=no user=\$username password=\$password\r\ \n} else={\r\ \n { :delay 1 };\r\ \n :local remoteID\r\ \n :set remoteID [/ip dhcp-server lease get [find where address=\$leaseA\ ctIP] agent-remote-id]\r\ \n /tool fetch url=\"\$mode://\$url/api/dhcp_assignments\?ip_address=\$l\ easeActIP&leased_mac_address=\$leaseActMAC&remote_id=\$remoteID&expired=0\ \" mode=\$mode keep-result=no user=\$username password=\$password\r\ \n};" lease-time=1h name=altoga-cpe add add-arp=yes address-pool=verona-tower-pool interface=\ sfp-sfpplus1-verona-tower-switch lease-time=1h name=verona-tower add add-arp=yes address-pool=verona-cgnat interface=verona lease-script="{\ \n:local url \"https://xtjlpnubrg.execute-api.us-east-1.amazonaws.com/prod\ uction/on-start-workflow-execution/6f19a48f-04f7-40c1-a4e0-8cb66df99213/cd\ c24944-c947-4e01-9c54-07a1653d2e3e\"\ \n:local url2 \"https://iptrack.vntx.net/api/dhcp\"\ \n:local max 1\ \n\ \n:local attempts 0\ \n:local success1 0\ \n:local success2 0\ \n:do {\ \n :set attempts (\$attempts+1);\ \n :if (\$leaseBound = 0) do {\ \n # Try url2 (iptrack.vntx.net) - deassignment\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=pos\ t http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\ und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\ \\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\"}\"\ \n :set success1 1;\ \n :log info \"DHCP deassignment successfully sent to iptrack.vntx.ne\ t for \$leaseActMAC / \$leaseActIP\";\ \n } on-error={\ \n :log error \"DHCP FAILED to send deassignment to iptrack.vntx.net \ on attempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP\";\ \n }\ \n\ \n # Try url (gaiia) - deassignment\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post\ \_http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\ und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\ \\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\",\\\"remoteId\ \\\":\\\"\\\"}\"\ \n :set success2 1;\ \n :log info \"DHCP deassignment successfully sent to gaiia AWS API f\ or \$leaseActMAC / \$leaseActIP\";\ \n } on-error={\ \n :log error \"DHCP FAILED to send deassignment to gaiia AWS API on \ attempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP\";\ \n }\ \n\ \n :if (\$success1 != 1 || \$success2 != 1) do={\ \n :delay 3s;\ \n }\ \n } else {\ \n :delay 1s;\ \n :local remoteID [/ip dhcp-server lease get [find where address=\$lea\ seActIP] agent-remote-id];\ \n\ \n # Try url2 (iptrack.vntx.net) - assignment\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=pos\ t http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\ und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\ \\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\",\\\"remoteId\ \\\":\\\"\$remoteID\\\"}\"\ \n :set success1 1;\ \n :log info \"DHCP assignment successfully sent to iptrack.vntx.net \ for \$leaseActMAC / \$leaseActIP / \$remoteID\";\ \n } on-error={\ \n :log error \"DHCP FAILED to send assignment to iptrack.vntx.net on\ \_attempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP / \$remoteID\"\ ;\ \n }\ \n\ \n # Try url (gaiia) - assignment\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post\ \_http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\ und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\ \\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\",\\\"remoteId\ \\\":\\\"\$remoteID\\\"}\"\ \n :set success2 1;\ \n :log info \"DHCP assignment successfully sent to gaiia AWS API for\ \_\$leaseActMAC / \$leaseActIP / \$remoteID\";\ \n } on-error={\ \n :log error \"DHCP FAILED to send assignment to gaiia AWS API on at\ tempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP / \$remoteID\";\ \n }\ \n\ \n :if (\$success1 != 1 || \$success2 != 1) do={\ \n :delay 30s;\ \n }\ \n }\ \n :if (\$success1 = 1 && \$success2 = 1) do {\ \n :set attempts \$max;\ \n }\ \n} while ( \$attempts < \$max )\ \n}\ \n" lease-time=1h name="verona cgnat" use-radius=accounting /ip hotspot add address-pool=verona-cgnat addresses-per-mac=unlimited disabled=no \ interface=verona name=hotspot1 profile=hsprof1 add address-pool=radiustest addresses-per-mac=unlimited interface=\ ether10-powerswitch name=radiustest profile=radiustest /ip smb users set [ find default=yes ] disabled=yes /ipv6 dhcp-server add interface=verona lease-time=10m name=server1 prefix-pool=\ verona-v6-pd-pool /ipv6 pool add name=verona-v6-pd-pool prefix=2606:1c80:100::/40 prefix-length=56 /port set 0 name=serial0 set 1 name=serial1 /ppp profile add change-tcp-mss=yes dhcpv6-pd-pool=verona-v6-pd-pool dns-server=\ 204.110.191.240,204.110.191.250 idle-timeout=1h local-address=\ 100.64.15.253 name=pppoe-verona on-down="{\ \n:local url \"https://xtjlpnubrg.execute-api.us-east-1.amazonaws.com/prod\ uction/on-start-workflow-execution/6f19a48f-04f7-40c1-a4e0-8cb66df99213/0a\ 7f4443-fc8a-4fe0-807c-f535d2aa1865\"\ \n:local url2 \"https://iptrack.vntx.net/api/pppoe\"\ \n:local max 1\ \n\ \n:local localAddr \$\"local-address\"\ \n:local remoteAddr \$\"remote-address\"\ \n:local callerId \$\"caller-id\"\ \n:local calledId \$\"called-id\"\ \n:local interfaceName [/interface get \$interface name]\ \n\ \n:local attempts 0\ \n:local success1 0\ \n:local success2 0\ \n:do {\ \n :set attempts (\$attempts+1);\ \n\ \n # Try url2 (iptrack.vntx.net)\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=post \ http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"boun\ d\\\":\\\"0\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\ \\\"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\ \n :set success1 1;\ \n :log info \"PPPoE deassignment successfully sent to iptrack.vntx.net\ \_for \$user / \$remoteAddr\";\ \n } on-error={\ \n :log error \"PPPoE FAILED to send deassignment to iptrack.vntx.net o\ n attempt \$attempts out of \$max for \$user / \$remoteAddr\";\ \n }\ \n\ \n # Try url (AWS API)\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post h\ ttp-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bound\ \\\":\\\"0\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\\\ \"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\ \n :set success2 1;\ \n :log info \"PPPoE deassignment successfully sent to gaiia AWS API fo\ r \$user / \$remoteAddr\";\ \n } on-error={\ \n :log error \"PPPoPoE FAILED to send deassignment to gaiia AWS API on\ \_attempt \$attempts out of \$max for \$user / \$remoteAddr\";\ \n }\ \n\ \n :if (\$success1 = 1 && \$success2 = 1) do {\ \n :set attempts \$max;\ \n } else {\ \n :delay 3s;\ \n }\ \n} while ( \$attempts < \$max )\ \n}\ \n" on-up="{\ \n:local url \"https://xtjlpnubrg.execute-api.us-east-1.amazonaws.com/prod\ uction/on-start-workflow-execution/6f19a48f-04f7-40c1-a4e0-8cb66df99213/0a\ 7f4443-fc8a-4fe0-807c-f535d2aa1865\"\ \n:local url2 \"https://iptrack.vntx.net/api/pppoe\"\ \n:local max 5\ \n\ \n:local localAddr \$\"local-address\"\ \n:local remoteAddr \$\"remote-address\"\ \n:local callerId \$\"caller-id\"\ \n:local calledId \$\"called-id\"\ \n:local interfaceName [/interface get \$interface name]\ \n\ \n:local attempts 0\ \n:local success1 0\ \n:local success2 0\ \n:do {\ \n :set attempts (\$attempts+1);\ \n\ \n # Try url2 (iptrack.vntx.net)\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=post \ http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"boun\ d\\\":\\\"1\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\ \\\"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\ \n :set success1 1;\ \n :log info \"PPPoE assignment successfully sent to iptrack.vntx.net f\ or \$user / \$remoteAddr\";\ \n } on-error={\ \n :log error \"PPPoE FAILED to send assignment to iptrack.vntx.net on \ attempt \$attempts out of \$max for \$user / \$remoteAddr\";\ \n }\ \n\ \n # Try url (gaiia)\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post h\ ttp-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bound\ \\\":\\\"1\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\\\ \"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\ \n :set success2 1;\ \n :log info \"PPPoE assignment successfully sent to gaiia AWS API for \ \$user / \$remoteAddr\";\ \n } on-error={\ \n :log error \"PPPoE FAILED to send assignment to gaiia AWS API on att\ empt \$attempts out of \$max for \$user / \$remoteAddr\";\ \n }\ \n\ \n :if (\$success1 = 1 && \$success2 = 1) do {\ \n :set attempts \$max;\ \n } else {\ \n :delay 3s;\ \n }\ \n} while ( \$attempts < \$max )\ \n}\ \n" remote-address=verona-cgnat remote-ipv6-prefix-pool=verona-v6-pd-pool \ use-upnp=no add change-tcp-mss=yes dns-server=204.110.191.240,204.110.191.250 \ idle-timeout=1h local-address=100.64.15.253 name=pppoe-altoga on-down="{\ \n:local url \"https://xtjlpnubrg.execute-api.us-east-1.amazonaws.com/prod\ uction/on-start-workflow-execution/6f19a48f-04f7-40c1-a4e0-8cb66df99213/0a\ 7f4443-fc8a-4fe0-807c-f535d2aa1865\"\ \n:local url2 \"https://iptrack.vntx.net/api/pppoe\"\ \n:local max 1\ \n\ \n:local localAddr \$\"local-address\"\ \n:local remoteAddr \$\"remote-address\"\ \n:local callerId \$\"caller-id\"\ \n:local calledId \$\"called-id\"\ \n:local interfaceName [/interface get \$interface name]\ \n\ \n:local attempts 0\ \n:local success1 0\ \n:local success2 0\ \n:do {\ \n :set attempts (\$attempts+1);\ \n\ \n # Try url2 (iptrack.vntx.net)\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=post \ http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"boun\ d\\\":\\\"0\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\ \\\"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\ \n :set success1 1;\ \n :log info \"PPPoE deassignment successfully sent to iptrack.vntx.net\ \_for \$user / \$remoteAddr\";\ \n } on-error={\ \n :log error \"PPPoE FAILED to send deassignment to iptrack.vntx.net o\ n attempt \$attempts out of \$max for \$user / \$remoteAddr\";\ \n }\ \n\ \n # Try url (AWS API)\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post h\ ttp-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bound\ \\\":\\\"0\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\\\ \"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\ \n :set success2 1;\ \n :log info \"PPPoE deassignment successfully sent to gaiia AWS API fo\ r \$user / \$remoteAddr\";\ \n } on-error={\ \n :log error \"PPPoPoE FAILED to send deassignment to gaiia AWS API on\ \_attempt \$attempts out of \$max for \$user / \$remoteAddr\";\ \n }\ \n\ \n :if (\$success1 = 1 && \$success2 = 1) do {\ \n :set attempts \$max;\ \n } else {\ \n :delay 3s;\ \n }\ \n} while ( \$attempts < \$max )\ \n}\ \n" on-up="{\ \n:local url \"https://xtjlpnubrg.execute-api.us-east-1.amazonaws.com/prod\ uction/on-start-workflow-execution/6f19a48f-04f7-40c1-a4e0-8cb66df99213/0a\ 7f4443-fc8a-4fe0-807c-f535d2aa1865\"\ \n:local url2 \"https://iptrack.vntx.net/api/pppoe\"\ \n:local max 5\ \n\ \n:local localAddr \$\"local-address\"\ \n:local remoteAddr \$\"remote-address\"\ \n:local callerId \$\"caller-id\"\ \n:local calledId \$\"called-id\"\ \n:local interfaceName [/interface get \$interface name]\ \n\ \n:local attempts 0\ \n:local success1 0\ \n:local success2 0\ \n:do {\ \n :set attempts (\$attempts+1);\ \n\ \n # Try url2 (iptrack.vntx.net)\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=post \ http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"boun\ d\\\":\\\"1\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\ \\\"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\ \n :set success1 1;\ \n :log info \"PPPoE assignment successfully sent to iptrack.vntx.net f\ or \$user / \$remoteAddr\";\ \n } on-error={\ \n :log error \"PPPoE FAILED to send assignment to iptrack.vntx.net on \ attempt \$attempts out of \$max for \$user / \$remoteAddr\";\ \n }\ \n\ \n # Try url (gaiia)\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post h\ ttp-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bound\ \\\":\\\"1\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\\\ \"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\ \n :set success2 1;\ \n :log info \"PPPoE assignment successfully sent to gaiia AWS API for \ \$user / \$remoteAddr\";\ \n } on-error={\ \n :log error \"PPPoE FAILED to send assignment to gaiia AWS API on att\ empt \$attempts out of \$max for \$user / \$remoteAddr\";\ \n }\ \n\ \n :if (\$success1 = 1 && \$success2 = 1) do {\ \n :set attempts \$max;\ \n } else {\ \n :delay 3s;\ \n }\ \n} while ( \$attempts < \$max )\ \n}\ \n" remote-address=altoga-cgnat use-upnp=no /queue type add kind=fq-codel name=FQ_Codel /queue interface set ether1 queue=FQ_Codel set ether2 queue=FQ_Codel set ether3-climax-11ghz queue=FQ_Codel set ether4-verona-tower queue=FQ_Codel set ether5 queue=FQ_Codel set ether6-switch queue=FQ_Codel set ether7 queue=FQ_Codel set ether8 queue=FQ_Codel set ether9 queue=FQ_Codel set ether10-powerswitch queue=FQ_Codel set ether11 queue=FQ_Codel set ether12 queue=FQ_Codel set ether13 queue=FQ_Codel set ether14 queue=FQ_Codel set ether15_wave_n queue=FQ_Codel set ether16 queue=FQ_Codel set sfp-sfpplus1-verona-tower-switch queue=FQ_Codel set sfp-sfpplus2-switch queue=FQ_Codel /routing bgp template set default disabled=no output.network=bgp-networks /routing id add disabled=no id=10.254.254.101 name=id-1 select-dynamic-id="" /routing ospf instance add disabled=no in-filter-chain=ospf-in name=default-v2 originate-default=\ never out-filter-chain=ospf-out redistribute=connected router-id=id-1 add disabled=no in-filter-chain=ospf-in name=default-v3 out-filter-chain=\ ospf-out router-id=id-1 version=3 /routing ospf area add disabled=no instance=default-v2 name=backbone-v2 add disabled=no instance=default-v3 name=backbone-v3 /routing rip instance add afi=ip disabled=no in-filter-chain=ospf-in name=rip-instance-1 \ out-filter-chain=ospf-out vrf=main /snmp community set [ find default=yes ] name=kdyyJrT0Mm /system logging action set 3 remote=204.110.191.208 src-address=10.254.254.101 add name=logs remote=204.110.191.229 remote-port=1514 src-address=\ 10.254.254.101 target=remote /zerotier set zt1 disabled=no disabled=no /zerotier interface add allow-default=no allow-global=no allow-managed=yes disabled=no instance=\ zt1 name=zerotier1 network=a84ac5c10a229236 /interface bridge port add bridge=verona ingress-filtering=no interface=ether6-switch \ internal-path-cost=10 path-cost=10 add bridge=verona interface=sfp-sfpplus2-switch internal-path-cost=10 \ path-cost=10 add bridge=temp disabled=yes interface=eoip-380 internal-path-cost=10 \ path-cost=10 add bridge=verona interface=ether15_wave_n internal-path-cost=10 path-cost=10 add bridge=cpe_vlan_10 interface=vlan_10_ether6 internal-path-cost=10 \ path-cost=10 add bridge=cpe_vlan_10 interface=vlan10_sfpplus2 internal-path-cost=10 \ path-cost=10 add bridge=temp interface=vxlan-380 internal-path-cost=10 path-cost=10 add bridge=cpe_vlan_10 interface=vlan10_ether15 add bridge=cpe_vlan_10 interface=ether10-powerswitch /ip firewall connection tracking set tcp-established-timeout=4h tcp-fin-wait-timeout=2m tcp-time-wait-timeout=\ 2m /ip neighbor discovery-settings set discover-interface-list=all /interface ovpn-server server add auth=sha1,md5 mac-address=FE:7F:37:F6:80:C4 name=ovpn-server1 /interface pppoe-server server add default-profile=pppoe-verona disabled=no interface=verona max-mru=1500 \ max-mtu=1500 one-session-per-host=yes service-name=verona add default-profile=pppoe-altoga disabled=no interface=vlan_19_ether6 \ max-mru=1500 max-mtu=1500 one-session-per-host=yes service-name=altoga add authentication=mschap2 default-profile=pppoe-verona interface=ether1 \ max-mru=1492 max-mtu=1492 one-session-per-host=yes service-name=\ veronatest /interface vxlan vteps add interface=vxlan-380 remote-ip=10.254.254.252 /ip address add address=10.250.1.25/29 interface=ether3-climax-11ghz network=10.250.1.24 add address=10.254.254.101 interface=loopback network=10.254.254.101 add address=100.64.3.254/22 interface=verona network=100.64.0.0 add address=204.110.188.254/27 interface=verona network=204.110.188.224 add address=100.64.15.254/22 interface=ether6-switch network=100.64.12.0 add address=10.10.95.254/20 interface=vlan_10_ether6 network=10.10.80.0 add address=10.10.15.254/20 interface=vlan_10_ether6 network=10.10.0.0 add address=10.0.101.254/24 interface=sfp-sfpplus1-verona-tower-switch \ network=10.0.101.0 add address=10.250.1.145/29 interface=ether6-switch network=10.250.1.144 add address=204.110.191.30/27 interface=vlan9_sfpplus1 network=204.110.191.0 add address=10.25.1.254/24 interface=ether1 network=10.25.1.0 add address=192.168.1.23/24 disabled=yes interface=verona network=192.168.1.0 /ip dhcp-server add add-arp=yes address-pool=verona-cpe authoritative=after-2sec-delay \ dhcp-option-set=vntx interface=cpe_vlan_10 lease-script="{\ \n:local url \"https://xtjlpnubrg.execute-api.us-east-1.amazonaws.com/prod\ uction/on-start-workflow-execution/6f19a48f-04f7-40c1-a4e0-8cb66df99213/cd\ c24944-c947-4e01-9c54-07a1653d2e3e\"\ \n:local url2 \"https://iptrack.vntx.net/api/dhcp\"\ \n:local max 1\ \n\ \n:local attempts 0\ \n:local success1 0\ \n:local success2 0\ \n:do {\ \n :set attempts (\$attempts+1);\ \n :if (\$leaseBound = 0) do {\ \n # Try url2 (iptrack.vntx.net) - deassignment\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=pos\ t http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\ und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\ \\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\"}\"\ \n :set success1 1;\ \n :log info \"DHCP deassignment successfully sent to iptrack.vntx.ne\ t for \$leaseActMAC / \$leaseActIP\";\ \n } on-error={\ \n :log error \"DHCP FAILED to send deassignment to iptrack.vntx.net \ on attempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP\";\ \n }\ \n\ \n # Try url (gaiia) - deassignment\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post\ \_http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\ und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\ \\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\",\\\"remoteId\ \\\":\\\"\\\"}\"\ \n :set success2 1;\ \n :log info \"DHCP deassignment successfully sent to gaiia AWS API f\ or \$leaseActMAC / \$leaseActIP\";\ \n } on-error={\ \n :log error \"DHCP FAILED to send deassignment to gaiia AWS API on \ attempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP\";\ \n }\ \n\ \n :if (\$success1 != 1 || \$success2 != 1) do={\ \n :delay 3s;\ \n }\ \n } else {\ \n :delay 1s;\ \n :local remoteID [/ip dhcp-server lease get [find where address=\$lea\ seActIP] agent-remote-id];\ \n\ \n # Try url2 (iptrack.vntx.net) - assignment\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=pos\ t http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\ und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\ \\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\",\\\"remoteId\ \\\":\\\"\$remoteID\\\"}\"\ \n :set success1 1;\ \n :log info \"DHCP assignment successfully sent to iptrack.vntx.net \ for \$leaseActMAC / \$leaseActIP / \$remoteID\";\ \n } on-error={\ \n :log error \"DHCP FAILED to send assignment to iptrack.vntx.net on\ \_attempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP / \$remoteID\"\ ;\ \n }\ \n\ \n # Try url (gaiia) - assignment\ \n :do {\ \n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post\ \_http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\ und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\ \\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\",\\\"remoteId\ \\\":\\\"\$remoteID\\\"}\"\ \n :set success2 1;\ \n :log info \"DHCP assignment successfully sent to gaiia AWS API for\ \_\$leaseActMAC / \$leaseActIP / \$remoteID\";\ \n } on-error={\ \n :log error \"DHCP FAILED to send assignment to gaiia AWS API on at\ tempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP / \$remoteID\";\ \n }\ \n\ \n :if (\$success1 != 1 || \$success2 != 1) do={\ \n :delay 30s;\ \n }\ \n }\ \n :if (\$success1 = 1 && \$success2 = 1) do {\ \n :set attempts \$max;\ \n }\ \n} while ( \$attempts < \$max )\ \n}\ \n" lease-time=1h name=verona-cpe use-radius=accounting /ip dhcp-server config set interim-update=5m /ip dhcp-server lease add address=10.0.101.2 mac-address=94:C6:91:14:84:44 server=verona-tower add address=10.0.101.4 mac-address=94:C6:91:A1:FE:15 server=verona-tower add address=10.0.101.6 mac-address=00:00:00:00:00:01 server=verona-tower add address=10.0.101.11 client-id=1:58:8a:5a:ef:f:a0 comment="temp exclusion" \ mac-address=58:8A:5A:EF:0F:AA server=verona-tower add address=10.0.101.8 comment="exclusion for dell server" mac-address=\ 00:00:00:00:00:08 server=verona-tower add address=10.0.101.7 client-id=1:dc:2c:6e:dd:87:54 mac-address=\ DC:2C:6E:DD:87:54 server=verona-tower add address=100.64.3.250 client-id=1:48:a9:8a:9d:9b:8a mac-address=\ 48:A9:8A:9D:9B:8A server="verona cgnat" add address=10.0.101.253 client-id=1:c4:ad:34:1a:ca:96 disabled=yes \ mac-address=C4:AD:34:1A:CA:96 server=verona-tower add address=10.0.101.253 client-id=1:c4:ad:34:1a:ca:98 disabled=yes \ mac-address=C4:AD:34:1A:CA:98 server=verona-tower add address=10.0.101.12 client-id=1:c4:ad:34:1a:ca:96 mac-address=\ C4:AD:34:1A:CA:96 server=verona-tower add address=10.0.101.22 client-id=\ ff:d8:13:97:9e:0:1:0:1:30:63:25:c7:e0:51:d8:13:97:9e mac-address=\ E0:51:D8:13:97:9E server=verona-tower add address=10.0.101.21 client-id=\ ff:d8:13:36:6d:0:1:0:1:30:72:cb:b2:e0:51:d8:13:36:6d mac-address=\ E0:51:D8:13:36:6D server=verona-tower /ip dhcp-server network add address=10.0.101.0/24 dns-server=204.110.191.240,204.110.191.250 gateway=\ 10.0.101.254 ntp-server=204.110.191.19 add address=10.10.0.0/20 dns-server=204.110.191.240,204.110.191.20 domain=\ vntx.net gateway=10.10.15.254 ntp-server=204.110.191.19 add address=10.10.80.0/20 dns-server=204.110.191.240,204.110.191.250 domain=\ vntx.net gateway=10.10.95.254 ntp-server=204.110.191.19 add address=100.64.0.0/22 dns-server=204.110.191.240,204.110.191.20 domain=\ vntx.net gateway=100.64.3.254 ntp-server=204.110.191.19 add address=100.64.12.0/22 dns-server=204.110.191.240,204.110.191.250 domain=\ vntx.net gateway=100.64.15.254 ntp-server=204.110.191.19 add address=192.168.99.0/24 dns-server=204.110.191.240,204.110.191.250 \ gateway=192.168.99.254 add address=204.110.188.224/27 dns-server=204.110.191.240,204.110.191.250 \ domain=vntx.net gateway=204.110.188.254 ntp-server=204.110.191.19 /ip dhcp-server option sets add name=vntx options=*1 /ip dns set servers=9.9.9.9,8.8.8.8 /ip firewall address-list add address=204.110.188.225 comment="Graham McIntire (1)" list=VeronaEmployee add address=204.110.188.231 comment="James Hardin (1475)" list=VeronaEmployee add address=100.64.0.38 comment="Brad Wilson (1491)" list=VeronaEmployee add address=100.64.0.62 comment="James Hardin (1475)" list=VeronaEmployee add address=100.64.0.19 comment="TJ Banschbach (1676)" list=50 add address=100.64.0.8 comment="Alma Acosta (28)" list=ResidentialBasic add address=100.64.0.31 comment="Scott Armstrong (315)" list=ResidentialBasic add address=100.64.0.29 comment="Beverly Erwin (48)" list=ResidentialBasic add address=100.64.0.18 comment="Karen Stewart (2050)" list=ResidentialBasic add address=100.64.0.17 comment="Nathan McTee (273)" list=ResidentialBasic add address=100.64.0.16 comment="Doug Stowe (1807)" list=ResidentialBasic add address=100.64.0.45 comment="Debra Vega (112)" list=ResidentialBasic add address=100.64.0.50 comment="Steven Spurgers (1211)" list=\ ResidentialBasic add address=100.64.0.46 comment="Chrissy Eagle 2 (1530)" list=\ ResidentialBasic add address=100.64.0.22 comment="Steve Christiaens (329)" list=\ ResidentialBasic add address=100.64.0.23 comment="Ryan McTee (306)" list=ResidentialBasic add address=100.64.0.9 comment="Krysta Bates (218)" list=ResidentialBasic add address=10.10.0.63 comment="Alicia Torres (1938)" list=ResidentialBasic add address=10.10.0.47 comment="Alma Acosta (28)" list=ResidentialBasic add address=10.10.0.17 comment="Judy Devine (277)" list=ResidentialBasic add address=10.10.0.24 comment="Scott Armstrong (315)" list=ResidentialBasic add address=100.64.0.14 comment="Teresa Robinson (376)" list=BusinessBasic add address=10.10.0.59 comment="Teresa Robinson (376)" list=BusinessBasic add address=204.110.188.226 comment="James Genneken (160)" list=\ ResidentialAdvanced add address=204.110.188.233 comment="Joey Whitfield (187)" list=\ ResidentialAdvanced add address=204.110.188.229 comment="Vance Peltonen (356)" list=\ ResidentialAdvanced add address=204.110.188.234 comment="Sonya McTee (324)" list=\ ResidentialAdvanced add address=204.110.188.235 comment="Austin Watkins (769)" list=\ ResidentialAdvanced add address=100.64.0.48 comment="Pablo Hernandez (2083)" list=\ ResidentialAdvanced add address=204.110.188.237 comment="Ron Lewis (302)" list=\ ResidentialAdvanced add address=100.64.0.39 comment="Dana Nance (89)" list=ResidentialAdvanced add address=100.64.0.30 comment="Chand Parvathaneni (2396)" list=\ ResidentialAdvanced add address=100.64.0.28 comment="Mark Fisher (242)" list=ResidentialAdvanced add address=100.64.0.13 comment="CLAY GILBERT (1839)" list=\ ResidentialAdvanced add address=100.64.0.2 comment="JoleneDon Nance (118)" list=\ ResidentialAdvanced add address=100.64.0.44 comment="Brad Sherry Slate (1334)" list=\ ResidentialAdvanced add address=100.64.0.47 comment="Eric Barrett (2386)" list=\ ResidentialAdvanced add address=100.64.0.49 comment="David Lanman (2486)" list=\ ResidentialAdvanced add address=100.64.0.37 comment="Rebekah Moore (386)" list=\ ResidentialAdvanced add address=100.64.0.69 comment="Yolanda Medrano (2461)" list=\ ResidentialAdvanced add address=100.64.0.6 comment="Jennifer Little (1343)" list=\ ResidentialAdvanced add address=100.64.0.5 comment="Amber Krings (1273)" list=ResidentialAdvanced add address=100.64.0.4 comment="Cherie Eshelman (1153)" list=\ ResidentialAdvanced add address=100.64.0.61 comment="Rachel Fuller (286)" list=\ ResidentialAdvanced add address=100.64.0.25 comment="Maria Trejo (2284)" list=ResidentialAdvanced add address=100.64.0.7 comment="Carla Kimberling (1959)" list=\ ResidentialAdvanced add address=100.64.0.33 comment="Carmen Lopez (2409)" list=\ ResidentialAdvanced add address=100.64.0.51 comment="Kimberly Richards (1726)" list=\ ResidentialAdvanced add address=100.64.0.21 comment="Jacqueline Wilder (892)" list=\ ResidentialAdvanced add address=100.64.0.3 comment="Derek Rodriguez (2402)" list=\ ResidentialAdvanced add address=100.64.0.52 comment="Jonny Taylor (190)" list=ResidentialAdvanced add address=204.110.188.236 comment="Deja Dodson (2320)" list=\ ResidentialAdvanced add address=10.10.0.6 comment="Pablo Hernandez (2083)" list=\ ResidentialAdvanced add address=10.10.0.49 comment="Cherie Eshelman (1153)" list=\ ResidentialAdvanced add address=10.10.0.54 comment="Jennifer Little (1343)" list=\ ResidentialAdvanced add address=10.10.0.58 comment="Rebekah Moore (386)" list=ResidentialAdvanced add address=10.10.0.70 comment="Vance Peltonen (356)" list=\ ResidentialAdvanced add address=10.10.0.62 comment="Carla Kimberling (1959)" list=\ ResidentialAdvanced add address=10.10.0.25 comment="Yolanda Medrano (2461)" list=\ ResidentialAdvanced add address=10.10.0.15 comment="Maria Trejo (2284)" list=ResidentialAdvanced add address=10.10.0.69 comment="Rachel Fuller (286)" list=ResidentialAdvanced add address=10.10.0.73 comment="Carmen Lopez (2409)" list=ResidentialAdvanced add address=10.10.0.68 comment="Amber Krings (1273)" list=ResidentialAdvanced add address=10.10.0.91 comment="Anthony Schmoker (1577)" list=\ ResidentialAdvanced add address=204.110.188.226 comment="James Genneken (160)" list=Inactive add address=204.110.188.227 comment="Mike Villa (269)" list=Inactive add address=204.110.188.232 comment="Tammy Kinser (738)" list=Inactive add address=204.110.188.234 comment="Sonya McTee (324)" list=Inactive add address=100.64.0.23 comment="Ryan McTee (306)" list=Inactive add address=10.10.0.91 comment="Anthony Schmoker (1577)" list=Inactive add address=100.64.0.60 comment="Allen Taylor (26)" list=BusinessUltra add address=204.110.188.230 comment="Kirk Vanmeter (216)" list=BusinessUltra add address=10.10.0.64 comment="Allen Taylor (26)" list=BusinessUltra add address=100.64.0.12 comment="Penney Warner (70)" list=\ ResidentialBasic6months add address=100.64.0.40 comment="Chrissy Eagle (74)" list=\ ResidentialBasic6months add address=100.64.0.41 comment="Keith Crank (209)" list=\ ResidentialBasic6months add address=100.64.0.36 comment="Mary Hopper (245)" list=\ ResidentialBasic6months add address=100.64.0.32 comment="Michael Talbot (262)" list=\ ResidentialBasic6months add address=100.64.0.27 comment="Whitey White (303)" list=\ ResidentialBasic6months add address=100.64.0.1 comment="Sherrye Richardson (321)" list=\ ResidentialBasic6months add address=10.10.0.75 comment="Mary Hopper (245)" list=\ ResidentialBasic6months add address=100.64.0.26 comment="Sri Reddy (514)" list=ResidentialCore add address=204.110.188.225 comment="Graham McIntire (1)" list=Active add address=204.110.188.230 comment="Kirk Vanmeter (216)" list=Active add address=204.110.188.233 comment="Joey Whitfield (187)" list=Active add address=204.110.188.229 comment="Vance Peltonen (356)" list=Active add address=204.110.188.231 comment="James Hardin (1475)" list=Active add address=100.64.0.53 comment="William Armstrong (362)" list=Active add address=204.110.188.235 comment="Austin Watkins (769)" list=Active add address=100.64.0.48 comment="Pablo Hernandez (2083)" list=Active add address=204.110.188.237 comment="Ron Lewis (302)" list=Active add address=100.64.0.8 comment="Alma Acosta (28)" list=Active add address=100.64.0.41 comment="Keith Crank (209)" list=Active add address=100.64.0.39 comment="Dana Nance (89)" list=Active add address=100.64.0.36 comment="Mary Hopper (245)" list=Active add address=100.64.0.32 comment="Michael Talbot (262)" list=Active add address=100.64.0.31 comment="Scott Armstrong (315)" list=Active add address=100.64.0.30 comment="Chand Parvathaneni (2396)" list=Active add address=100.64.0.29 comment="Beverly Erwin (48)" list=Active add address=100.64.0.28 comment="Mark Fisher (242)" list=Active add address=100.64.0.20 comment="Pam Banschbach (383)" list=Active add address=100.64.0.18 comment="Karen Stewart (2050)" list=Active add address=100.64.0.17 comment="Nathan McTee (273)" list=Active add address=100.64.0.16 comment="Doug Stowe (1807)" list=Active add address=100.64.0.13 comment="CLAY GILBERT (1839)" list=Active add address=100.64.0.12 comment="Penney Warner (70)" list=Active add address=100.64.0.2 comment="JoleneDon Nance (118)" list=Active add address=100.64.0.44 comment="Brad Sherry Slate (1334)" list=Active add address=100.64.0.45 comment="Debra Vega (112)" list=Active add address=100.64.0.47 comment="Eric Barrett (2386)" list=Active add address=100.64.0.49 comment="David Lanman (2486)" list=Active add address=100.64.0.26 comment="Sri Reddy (514)" list=Active add address=100.64.0.50 comment="Steven Spurgers (1211)" list=Active add address=100.64.0.37 comment="Rebekah Moore (386)" list=Active add address=100.64.0.14 comment="Teresa Robinson (376)" list=Active add address=100.64.0.69 comment="Yolanda Medrano (2461)" list=Active add address=100.64.0.6 comment="Jennifer Little (1343)" list=Active add address=100.64.0.5 comment="Amber Krings (1273)" list=Active add address=100.64.0.4 comment="Cherie Eshelman (1153)" list=Active add address=100.64.0.61 comment="Rachel Fuller (286)" list=Active add address=100.64.0.25 comment="Maria Trejo (2284)" list=Active add address=100.64.0.7 comment="Carla Kimberling (1959)" list=Active add address=100.64.0.60 comment="Allen Taylor (26)" list=Active add address=100.64.0.33 comment="Carmen Lopez (2409)" list=Active add address=100.64.0.46 comment="Chrissy Eagle 2 (1530)" list=Active add address=100.64.0.22 comment="Steve Christiaens (329)" list=Active add address=100.64.0.1 comment="Sherrye Richardson (321)" list=Active add address=100.64.0.51 comment="Kimberly Richards (1726)" list=Active add address=100.64.0.21 comment="Jacqueline Wilder (892)" list=Active add address=100.64.0.38 comment="Brad Wilson (1491)" list=Active add address=100.64.0.3 comment="Derek Rodriguez (2402)" list=Active add address=100.64.0.27 comment="Whitey White (303)" list=Active add address=100.64.0.9 comment="Krysta Bates (218)" list=Active add address=100.64.0.52 comment="Jonny Taylor (190)" list=Active add address=100.64.0.40 comment="Chrissy Eagle (74)" list=Active add address=204.110.188.236 comment="Deja Dodson (2320)" list=Active add address=100.64.0.19 comment="TJ Banschbach (1676)" list=Active add address=10.10.0.63 comment="Alicia Torres (1938)" list=Active add address=10.10.0.6 comment="Pablo Hernandez (2083)" list=Active add address=10.10.0.49 comment="Cherie Eshelman (1153)" list=Active add address=10.10.0.59 comment="Teresa Robinson (376)" list=Active add address=10.10.0.47 comment="Alma Acosta (28)" list=Active add address=10.10.0.17 comment="Judy Devine (277)" list=Active add address=10.10.0.75 comment="Mary Hopper (245)" list=Active add address=10.10.0.54 comment="Jennifer Little (1343)" list=Active add address=10.10.0.58 comment="Rebekah Moore (386)" list=Active add address=10.10.0.70 comment="Vance Peltonen (356)" list=Active add address=10.10.0.62 comment="Carla Kimberling (1959)" list=Active add address=10.10.0.25 comment="Yolanda Medrano (2461)" list=Active add address=10.10.0.15 comment="Maria Trejo (2284)" list=Active add address=10.10.0.69 comment="Rachel Fuller (286)" list=Active add address=10.10.0.73 comment="Carmen Lopez (2409)" list=Active add address=10.10.0.68 comment="Amber Krings (1273)" list=Active add address=10.10.0.24 comment="Scott Armstrong (315)" list=Active add address=10.10.0.64 comment="Allen Taylor (26)" list=Active add address=100.64.0.62 comment="James Hardin (1475)" list=Active add address=100.64.0.34 comment="America Trejo (1693)" list=\ ResidentialAdvanced add address=100.64.0.34 comment="America Trejo (1693)" list=Active add address=100.64.0.15 comment="Bill McTee (373)" list=Active add address=100.64.0.35 comment="Judy Devine (277)" list=ResidentialBasic add address=100.64.0.35 comment="Judy Devine (277)" list=Active /ip firewall filter add action=accept chain=forward in-interface=zerotier1 add action=accept chain=input in-interface=zerotier1 add action=passthrough chain=unused-hs-chain comment=\ "place hotspot rules here" disabled=yes add action=fasttrack-connection chain=forward comment=\ "fasttrack established/related" connection-state=established,related \ hw-offload=yes add action=accept chain=forward comment="accept established/related" \ connection-state=established,related add action=fasttrack-connection chain=forward connection-state=\ established,related hw-offload=yes add action=fasttrack-connection chain=forward connection-state=new \ hw-offload=yes /ip firewall nat add action=passthrough chain=unused-hs-chain comment=\ "place hotspot rules here" disabled=yes /ip hotspot ip-binding add address=10.250.1.146 type=bypassed add mac-address=48:A9:8A:9D:9B:8A type=bypassed add address=204.110.188.224/27 type=bypassed add address=100.64.0.70 disabled=yes mac-address=5C:62:8B:10:0D:5F server=\ hotspot1 to-address=100.64.0.70 type=bypassed add address=0.0.0.0/0 disabled=yes add address=100.64.0.0/22 add address=204.110.188.0/22 add address=100.64.0.70 comment="test router" disabled=yes mac-address=\ 5C:62:8B:10:0D:5F server=hotspot1 to-address=100.64.0.70 type=bypassed add address=0.0.0.0/0 type=blocked /ip hotspot walled-garden add dst-host=use1-tauc-mqtt-broker.tplinkcloud.com server=hotspot1 add dst-host=*tplinknbu.com server=hotspot1 add dst-host=*tplinkcloud.com server=hotspot1 add dst-host=*tp-link.com server=hotspot1 add dst-host=vntx.unmsapp.com server=hotspot1 add dst-port=123 add dst-port=8883 add comment="place hotspot rules here" disabled=yes /ip hotspot walled-garden ip add action=accept disabled=no dst-address=204.110.191.240 !dst-address-list \ !dst-port !protocol !src-address !src-address-list add action=accept disabled=no dst-address=204.110.191.250 !dst-address-list \ !dst-port !protocol !src-address !src-address-list add action=accept disabled=no !dst-address !dst-address-list dst-port=8883 \ protocol=tcp !src-address !src-address-list /ip ipsec profile set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5 /ip proxy set enabled=yes port=23435 /ip proxy access add src-address=204.110.188.0/22 add src-address=10.0.0.0/8 add src-address=100.64.0.0/10 add action=deny src-address=0.0.0.0/0 /ip route add disabled=no dst-address=0.0.0.0/0 gateway=10.250.1.30 add disabled=no dst-address=10.43.0.0/16 gateway=204.110.191.1 add disabled=no dst-address=10.0.16.1/32 gateway=204.110.188.225 add disabled=no dst-address=10.0.16.10/32 gateway=204.110.188.225 add disabled=no dst-address=10.0.16.84/32 gateway=204.110.188.225 /ip service set ftp address=204.110.188.0/22,10.0.0.0/8 disabled=yes set telnet address=204.110.188.0/22,10.0.0.0/8 disabled=yes set www address=204.110.188.0/22,10.0.0.0/8 disabled=yes set www-ssl address=204.110.188.0/22,10.0.0.0/8 set ssh address=204.110.188.0/22,10.0.0.0/8 port=1022 set api address=204.110.188.0/22,10.0.0.0/8,100.64.0.0/10 set api-ssl certificate=myCa /ip smb shares set [ find default=yes ] directory=/pub /ip ssh set always-allow-password-login=yes host-key-type=ed25519 strong-crypto=yes /ipv6 address add address=2606:1c80:0:1010::2 interface=ether3-climax-11ghz /ipv6 nd add interface=verona managed-address-configuration=yes other-configuration=\ yes /ipv6 nd prefix add autonomous=no interface=verona /mpls interface add disabled=no interface=ether3-climax-11ghz mpls-mtu=1500 add interface=ether4-verona-tower mpls-mtu=1500 add interface=ether6-switch mpls-mtu=1500 add interface=ether7 mpls-mtu=1500 add interface=ether8 mpls-mtu=1500 add interface=ether9 mpls-mtu=1500 add interface=ether11 mpls-mtu=1500 add interface=ether12 mpls-mtu=1500 add interface=ether13 mpls-mtu=1500 add interface=ether14 mpls-mtu=1500 add interface=ether15_wave_n mpls-mtu=1500 add interface=ether16 mpls-mtu=1500 add interface=sfp-sfpplus1-verona-tower-switch mpls-mtu=1500 add interface=sfp-sfpplus2-switch mpls-mtu=1500 /mpls ldp add afi=ip,ipv6 disabled=no loop-detect=yes lsr-id=10.254.254.101 \ transport-addresses=10.254.254.101 vrf=main /mpls ldp advertise-filter add advertise=yes disabled=yes prefix=10.10.0.0/20 vrf=main add advertise=yes disabled=yes prefix=204.110.188.224/27 vrf=main /mpls ldp interface add accept-dynamic-neighbors=yes afi=ip disabled=no interface=\ ether3-climax-11ghz transport-addresses=10.254.254.101 add interface=ether4-verona-tower transport-addresses=10.254.254.101 add interface=ether6-switch transport-addresses=10.254.254.101 add interface=ether7 transport-addresses=10.254.254.101 add interface=ether8 transport-addresses=10.254.254.101 add interface=ether9 transport-addresses=10.254.254.101 add interface=ether11 transport-addresses=10.254.254.101 add interface=ether12 transport-addresses=10.254.254.101 add interface=ether13 transport-addresses=10.254.254.101 add interface=ether14 transport-addresses=10.254.254.101 add interface=ether15_wave_n transport-addresses=10.254.254.101 add interface=ether16 transport-addresses=10.254.254.101 add interface=sfp-sfpplus1-verona-tower-switch transport-addresses=\ 10.254.254.101 add interface=sfp-sfpplus2-switch transport-addresses=10.254.254.101 /ppp aaa set interim-update=15m use-radius=yes /radius add address=204.110.191.248 require-message-auth=no service=ppp,hotspot,dhcp \ src-address=204.110.188.254 timeout=3s add accounting-backup=yes address=104.238.144.172 disabled=yes \ require-message-auth=no service=ppp,hotspot,dhcp src-address=\ 204.110.188.254 timeout=3s add address=204.110.191.2 disabled=yes require-message-auth=no service=\ ppp,hotspot,dhcp src-address=204.110.188.254 timeout=3s /radius incoming set accept=yes /routing bfd configuration add disabled=no interfaces=all min-rx=200ms min-tx=200ms multiplier=5 /routing filter rule add chain=ospf-in disabled=no rule="accept;" add chain=ospf-out disabled=no rule="accept;" /routing ospf interface-template add area=backbone-v2 auth=sha512 auth-id=1 cost=10 disabled=no interfaces=\ ether3-climax-11ghz priority=1 type=ptp use-bfd=no add area=backbone-v3 cost=10 disabled=no passive use-bfd=no add area=backbone-v2 disabled=no passive /routing ospf static-neighbor add address=10.250.1.30%ether3-climax-11ghz area=backbone-v2 disabled=no \ poll-interval=10s /routing rip interface-template add disabled=no instance=rip-instance-1 interfaces=ether3-climax-11ghz /snmp set contact="Graham McIntire" enabled=yes location=Verona /system clock set time-zone-name=America/Chicago /system identity set name=Verona /system logging add action=remote topics=info add disabled=yes topics=ospf add action=disk prefix=gtemp topics=firewall /system note set show-at-login=no /system ntp client set enabled=yes /system ntp client servers add address=ntp.vntx.net add address=0.us.pool.ntp.org /system package update set channel=long-term /system routerboard settings set auto-upgrade=yes enter-setup-on=delete-key /system scheduler add name=reboot on-event="/system reboot" policy=\ ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \ start-date=2025-02-16 start-time=03:00:00 add interval=1d name=upgrade policy=\ ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \ start-date=2024-02-22 start-time=03:30:00 /system script add dont-require-permissions=no name=upgrade owner=graham policy=\ ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="#\ \_Script name: BackupAndUpdate\r\ \n#\r\ \n#----------SCRIPT INFORMATION-------------------------------------------\ --------\r\ \n#\r\ \n# Script: Mikrotik RouterOS automatic backup & update\r\ \n# Version: 23.11.25\r\ \n# Created: 07/08/2018\r\ \n# Updated: 25/11/2023\r\ \n# Author: Alexander Tebiev\r\ \n# Website: https://github.com/beeyev\r\ \n# You can contact me by e-mail at tebiev@mail.com\r\ \n#\r\ \n# IMPORTANT!\r\ \n# Minimum supported RouterOS version is v6.43.7\r\ \n#\r\ \n#----------MODIFY THIS SECTION AS NEEDED--------------------------------\ --------\r\ \n## Notification e-mail\r\ \n## (Make sure you have configurated Email settings in Tools -> Email)\r\ \n:local emailAddress \"graham@vntx.net\";\r\ \n\r\ \n## Script mode, possible values: backup, osupdate, osnotify.\r\ \n# backup - Only backup will be performed. (default value, if none p\ rovided)\r\ \n#\r\ \n# osupdate - The script will install a new RouterOS version if it is \ available.\r\ \n# It will also create backups before and after update proc\ ess (it does not matter what value `forceBackup` is set to)\r\ \n# Email will be sent only if a new RouterOS version is ava\ ilable.\r\ \n# Change parameter `forceBackup` if you need the script to\ \_create backups every time when it runs (even when no updates were found)\ .\r\ \n#\r\ \n# osnotify - The script will send email notifications only (without b\ ackups) if a new RouterOS update is available.\r\ \n# Change parameter `forceBackup` if you need the script to\ \_create backups every time when it runs.\r\ \n:local scriptMode \"osupdate\";\r\ \n\r\ \n## Additional parameter if you set `scriptMode` to `osupdate` or `osnoti\ fy`\r\ \n# Set `true` if you want the script to perform backup every time it's fi\ red, whatever script mode is set.\r\ \n:local forceBackup false;\r\ \n\r\ \n## Backup encryption password, no encryption if no password.\r\ \n:local backupPassword \"\"\r\ \n\r\ \n## If true, passwords will be included in exported config.\r\ \n:local sensitiveDataInConfig true;\r\ \n\r\ \n## Update channel. Possible values: stable, long-term, testing, developm\ ent\r\ \n:local updateChannel \"stable\";\r\ \n\r\ \n## Install only patch versions of RouterOS updates.\r\ \n## Works only if you set scriptMode to \"osupdate\"\r\ \n## Means that new update will be installed only if MAJOR and MINOR versi\ on numbers remained the same as currently installed RouterOS.\r\ \n## Example: v6.43.6 => major.minor.PATCH\r\ \n## Script will send information if new version is greater than just patc\ h.\r\ \n:local installOnlyPatchUpdates false;\r\ \n\r\ \n## If true, device public IP address information will be included into t\ he email message\r\ \n:local detectPublicIpAddress true;\r\ \n\r\ \n## Allow anonymous statistics collection. (script mode, device model, OS\ \_version)\r\ \n:local allowAnonymousStatisticsCollection true;\r\ \n\r\ \n##----------------------------------------------------------------------\ --------------------##\r\ \n# !!!! DO NOT CHANGE ANYTHING BELOW THIS LINE, IF YOU ARE NOT SURE WHAT\ \_YOU ARE DOING !!!! #\r\ \n##----------------------------------------------------------------------\ --------------------##\r\ \n\r\ \n#Script messages prefix\r\ \n:local SMP \"Bkp&Upd:\"\r\ \n\r\ \n:log info \"\\r\\n\$SMP script \\\"Mikrotik RouterOS automatic backup & \ update\\\" started.\";\r\ \n:log info \"\$SMP Script Mode: \$scriptMode, forceBackup: \$forceBackup\ \";\r\ \n\r\ \n# Check email settings\r\ \n:if ([:len \$emailAddress] = 0) do={\r\ \n :log error (\"\$SMP \\\$emailAddress variable is empty. Script stopp\ ed.\");\r\ \n :error \"\$SMP bye!\";\r\ \n}\r\ \n:local emailServer \"\"\r\ \n:do {\r\ \n :set emailServer [/tool e-mail get server];\r\ \n} on-error={\r\ \n # Old of getting email server before the RouterOS v7.12\r\ \n :log info \"\$SMP Checking email server using old command `/tool e-m\ ail get address`\";\r\ \n :set emailServer [/tool e-mail get address];\r\ \n}\r\ \n:if (\$emailServer = \"0.0.0.0\") do={\r\ \n :log error (\"\$SMP Email server address is not correct, please chec\ k Tools -> Email. Script stopped.\");\r\ \n :error \"\$SMP bye!\";\r\ \n}\r\ \n:if ([:len [/tool e-mail get from]] = 0 or [/tool e-mail get from] = \"<\ >\") do={\r\ \n :log error (\"\$SMP Email configuration FROM address is not correct,\ \_please check Tools -> Email. Script stopped.\");\r\ \n :error \"\$SMP bye!\";\r\ \n}\r\ \n\r\ \n\r\ \n#Check if proper identity name is set\r\ \nif ([:len [/system identity get name]] = 0 or [/system identity get name\ ] = \"MikroTik\") do={\r\ \n :log warning (\"\$SMP Please set identity name of your device (Syste\ m -> Identity), keep it short and informative.\");\r\ \n};\r\ \n\r\ \n############### vvvvvvvvv GLOBALS vvvvvvvvv ###############\r\ \n# Function converts standard mikrotik build versions to the number.\r\ \n# Possible arguments: paramOsVer\r\ \n# Example:\r\ \n# :put [\$buGlobalFuncGetOsVerNum paramOsVer=[/system routerboard get cu\ rrent-RouterOS]];\r\ \n# Result will be: 64301, because current RouterOS version is: 6.43.1\r\ \n:global buGlobalFuncGetOsVerNum do={\r\ \n :local osVer \$paramOsVer;\r\ \n :local osVerNum;\r\ \n :local osVerMicroPart;\r\ \n :local zro 0;\r\ \n :local tmp;\r\ \n\r\ \n # Replace word `beta` with dot\r\ \n :local isBetaPos [:tonum [:find \$osVer \"beta\" 0]];\r\ \n :if (\$isBetaPos > 1) do={\r\ \n :set osVer ([:pick \$osVer 0 \$isBetaPos] . \".\" . [:pick \$osV\ er (\$isBetaPos + 4) [:len \$osVer]]);\r\ \n }\r\ \n # Replace word `rc` with dot\r\ \n :local isRcPos [:tonum [:find \$osVer \"rc\" 0]];\r\ \n :if (\$isRcPos > 1) do={\r\ \n :set osVer ([:pick \$osVer 0 \$isRcPos] . \".\" . [:pick \$osVer\ \_(\$isRcPos + 2) [:len \$osVer]]);\r\ \n }\r\ \n\r\ \n :local dotPos1 [:find \$osVer \".\" 0];\r\ \n\r\ \n :if (\$dotPos1 > 0) do={\r\ \n\r\ \n # AA\r\ \n :set osVerNum [:pick \$osVer 0 \$dotPos1];\r\ \n\r\ \n :local dotPos2 [:find \$osVer \".\" \$dotPos1];\r\ \n #Taking minor version, everything after first dot\r\ \n :if ([:len \$dotPos2] = 0) do={:set tmp [:pick \$osVer (\$dotPos\ 1+1) [:len \$osVer]];}\r\ \n #Taking minor version, everything between first and second dots\ \r\ \n :if (\$dotPos2 > 0) do={:set tmp [:pick \$osVer (\$dotPos1+1) \$\ dotPos2];}\r\ \n\r\ \n # AA 0B\r\ \n :if ([:len \$tmp] = 1) do={:set osVerNum \"\$osVerNum\$zro\$tmp\ \";}\r\ \n # AA BB\r\ \n :if ([:len \$tmp] = 2) do={:set osVerNum \"\$osVerNum\$tmp\";}\r\ \n\r\ \n :if (\$dotPos2 > 0) do={\r\ \n :set tmp [:pick \$osVer (\$dotPos2+1) [:len \$osVer]];\r\ \n # AA BB 0C\r\ \n :if ([:len \$tmp] = 1) do={:set osVerNum \"\$osVerNum\$zro\$\ tmp\";}\r\ \n # AA BB CC\r\ \n :if ([:len \$tmp] = 2) do={:set osVerNum \"\$osVerNum\$tmp\"\ ;}\r\ \n } else={\r\ \n # AA BB 00\r\ \n :set osVerNum \"\$osVerNum\$zro\$zro\";\r\ \n }\r\ \n } else={\r\ \n # AA 00 00\r\ \n :set osVerNum \"\$osVer\$zro\$zro\$zro\$zro\";\r\ \n }\r\ \n\r\ \n :return \$osVerNum;\r\ \n}\r\ \n\r\ \n\r\ \n# Function creates backups (system and config) and returns array with na\ mes\r\ \n# Possible arguments:\r\ \n# `backupName` | string | backup file name, without \ extension!\r\ \n# `backupPassword` | string |\r\ \n# `sensitiveDataInConfig` | boolean |\r\ \n# Example:\r\ \n# :put [\$buGlobalFuncCreateBackups name=\"daily-backup\"];\r\ \n:global buGlobalFuncCreateBackups do={\r\ \n :log info (\"\$SMP Global function \\\"buGlobalFuncCreateBackups\\\"\ \_was fired.\");\r\ \n\r\ \n :local backupFileSys \"\$backupName.backup\";\r\ \n :local backupFileConfig \"\$backupName.rsc\";\r\ \n :local backupNames {\$backupFileSys;\$backupFileConfig};\r\ \n\r\ \n ## Make system backup\r\ \n :if ([:len \$backupPassword] = 0) do={\r\ \n /system backup save dont-encrypt=yes name=\$backupName;\r\ \n } else={\r\ \n /system backup save password=\$backupPassword name=\$backupName;\ \r\ \n }\r\ \n :log info (\"\$SMP System backup created. \$backupFileSys\");\r\ \n\r\ \n ## Export config file\r\ \n :if (\$sensitiveDataInConfig = true) do={\r\ \n # Since RouterOS v7 it needs to be explicitly set that we want t\ o export sensitive data\r\ \n :if ([:pick [/system package update get installed-version] 0 1] \ < 7) do={\r\ \n :execute \"/export compact terse file=\$backupName\";\r\ \n } else={\r\ \n :execute \"/export compact show-sensitive terse file=\$backu\ pName\";\r\ \n }\r\ \n } else={\r\ \n /export compact hide-sensitive terse file=\$backupName;\r\ \n }\r\ \n :log info (\"\$SMP Config file was exported. \$backupFileConfig, the\ \_script execution will be paused for a moment.\");\r\ \n\r\ \n #Delay after creating backups\r\ \n :delay 20s;\r\ \n :return \$backupNames;\r\ \n}\r\ \n\r\ \n:global buGlobalVarUpdateStep;\r\ \n############### ^^^^^^^^^ GLOBALS ^^^^^^^^^ ###############\r\ \n\r\ \n:local scriptVersion \"23.11.25\";\r\ \n\r\ \n# Current time `hh-mm-ss`\r\ \n:local currentTime ([:pick [/system clock get time] 0 2] . \"-\" . [:pic\ k [/system clock get time] 3 5] . \"-\" . [:pick [/system clock get time] \ 6 8]);\r\ \n\r\ \n:local currentDateTime (\"-\" . \$currentTime);\r\ \n\r\ \n# Detect old date format, Example: `nov/11/2023`\r\ \n:if ([:len [:tonum [:pick [/system clock get date] 0 1]]] = 0) do={\r\ \n :set currentDateTime ([:pick [/system clock get date] 7 11] . [:pick\ \_[/system clock get date] 0 3] . [:pick [/system clock get date] 4 6] . \ \"-\" . \$currentTime);\r\ \n} else={\r\ \n # New date format, Example: `2023-11-11`\r\ \n :set currentDateTime ([/system clock get date] . \"-\" . \$currentTi\ me);\r\ \n};\r\ \n\r\ \n:local isSoftBased false;\r\ \n:if ([/system resource get board-name] = \"CHR\" or [/system resource ge\ t board-name] = \"x86\") do={\r\ \n :set isSoftBased true;\r\ \n};\r\ \n\r\ \n:local deviceOsVerInst [/system package update get installed-ve\ rsion];\r\ \n:local deviceOsVerInstNum [\$buGlobalFuncGetOsVerNum paramOsVer=\$\ deviceOsVerInst];\r\ \n:local deviceOsVerAvail \"\";\r\ \n:local deviceOsVerAvailNum 0;\r\ \n:local deviceIdentityName [/system identity get name];\r\ \n:local deviceIdentityNameShort [:pick \$deviceIdentityName 0 18]\r\ \n:local deviceUpdateChannel [/system package update get channel];\r\ \n\r\ \n\r\ \n:local deviceRbModel \"CloudHostedRouter\";\r\ \n:local deviceRbSerialNumber \"--\";\r\ \n:local deviceRbCurrentFw \"--\";\r\ \n:local deviceRbUpgradeFw \"--\";\r\ \n\r\ \n:if (\$isSoftBased = false) do={\r\ \n :set deviceRbModel [/system routerboard get model];\r\ \n :set deviceRbSerialNumber [/system routerboard get serial-number];\ \r\ \n :set deviceRbCurrentFw [/system routerboard get current-firmwar\ e];\r\ \n :set deviceRbUpgradeFw [/system routerboard get upgrade-firmwar\ e];\r\ \n};\r\ \n\r\ \n:local isOsUpdateAvailable false;\r\ \n:local isOsNeedsToBeUpdated false;\r\ \n\r\ \n:local isSendEmailRequired true;\r\ \n\r\ \n:local mailSubject \"\$SMP Device - \$deviceIdentityNameShort.\";\r\ \n:local mailBody \"\";\r\ \n\r\ \n:local mailBodyDeviceInfo \"\\r\\n\\r\\nDevice information: \\r\\nIden\ tity: \$deviceIdentityName \\r\\nModel: \$deviceRbModel \\r\\nSerial numbe\ r: \$deviceRbSerialNumber \\r\\nCurrent RouterOS: \$deviceOsVerInst (\$[/s\ ystem package update get channel]) \$[/system resource get build-time] \\r\ \\nCurrent routerboard FW: \$deviceRbCurrentFw \\r\\nDevice uptime: \$[/sy\ stem resource get uptime]\";\r\ \n:local mailBodyCopyright \"\\r\\n\\r\\nMikrotik RouterOS automatic ba\ ckup & update (ver. \$scriptVersion) \\r\\nhttps://github.com/beeyev/Mikro\ tik-RouterOS-automatic-backup-and-update\";\r\ \n:local changelogUrl (\"Check RouterOS changelog: https://mikroti\ k.com/download/changelogs/\" . \$updateChannel . \"-release-tree\");\r\ \n\r\ \n:local backupName \"v\$deviceOsVerInst_\$deviceUpdateChannel_\ \$currentDateTime\";\r\ \n:local backupNameBeforeUpd \"backup_before_update_\$backupName\";\r\ \n:local backupNameAfterUpd \"backup_after_update_\$backupName\";\r\ \n\r\ \n:local backupNameFinal \$backupName;\r\ \n:local mailAttachments [:toarray \"\"];\r\ \n\r\ \n\r\ \n:local ipAddressDetectServiceDefault \"https://ipv4.mikrotik.ovh/\"\r\ \n:local ipAddressDetectServiceFallback \"https://api.ipify.org/\"\r\ \n:local publicIpAddress \"not detected\";\r\ \n:local telemetryDataQuery \"\";\r\ \n\r\ \n:local updateStep \$buGlobalVarUpdateStep;\r\ \n:do {/system script environment remove buGlobalVarUpdateStep;} on-error=\ {}\r\ \n:if ([:len \$updateStep] = 0) do={\r\ \n :set updateStep 1;\r\ \n}\r\ \n\r\ \n## IP address detection & anonymous statistics collection\r\ \n:if (\$updateStep = 1 or \$updateStep = 3) do={\r\ \n :if (\$updateStep = 3) do={\r\ \n :log info (\"\$SMP Waiting for one minute before continuing to t\ he final step.\");\r\ \n :delay 1m;\r\ \n }\r\ \n\r\ \n :if (\$detectPublicIpAddress = true or \$allowAnonymousStatisticsCol\ lection = true) do={\r\ \n :if (\$allowAnonymousStatisticsCollection = true) do={\r\ \n :set telemetryDataQuery (\"\\\?mode=\" . \$scriptMode . \"&o\ sver=\" . \$deviceOsVerInst . \"&model=\" . \$deviceRbModel);\r\ \n }\r\ \n\r\ \n :do {:set publicIpAddress ([/tool fetch http-method=\"get\" url=\ (\$ipAddressDetectServiceDefault . \$telemetryDataQuery) output=user as-va\ lue]->\"data\");} on-error={\r\ \n\r\ \n :if (\$detectPublicIpAddress = true) do={\r\ \n :log warning \"\$SMP Could not detect public IP address \ using default detection service.\"\r\ \n :log warning \"\$SMP Trying to detect public ip using fa\ llback detection service.\"\r\ \n\r\ \n :do {:set publicIpAddress ([/tool fetch http-method=\"ge\ t\" url=\$ipAddressDetectServiceFallback output=user as-value]->\"data\");\ } on-error={\r\ \n :log warning \"\$SMP Could not detect public IP addr\ ess using fallback detection service.\"\r\ \n }\r\ \n }\r\ \n }\r\ \n\r\ \n :if (\$detectPublicIpAddress = true) do={\r\ \n # Always truncate the string for safety measures\r\ \n :set publicIpAddress ([:pick \$publicIpAddress 0 15])\r\ \n :set mailBodyDeviceInfo (\$mailBodyDeviceInfo . \"\\r\\nPubl\ ic IP address: \" . \$publicIpAddress);\r\ \n }\r\ \n }\r\ \n}\r\ \n\r\ \n\r\ \n## STEP ONE: Creating backups, checking for new RouterOs version and sen\ ding email with backups,\r\ \n## Steps 2 and 3 are fired only if script is set to automatically update\ \_device and if a new RouterOs version is available.\r\ \n:if (\$updateStep = 1) do={\r\ \n :log info (\"\$SMP Performing the first step.\");\r\ \n\r\ \n # Checking for new RouterOS version\r\ \n if (\$scriptMode = \"osupdate\" or \$scriptMode = \"osnotify\") do={\ \r\ \n log info (\"\$SMP Checking for new RouterOS version. Current ver\ sion is: \$deviceOsVerInst\");\r\ \n /system package update set channel=\$updateChannel;\r\ \n /system package update check-for-updates;\r\ \n :delay 5s;\r\ \n :set deviceOsVerAvail [/system package update get latest-version\ ];\r\ \n\r\ \n # If there is a problem getting information about available Rout\ erOS versions from server\r\ \n :if ([:len \$deviceOsVerAvail] = 0) do={\r\ \n :log warning (\"\$SMP There is a problem getting information\ \_about new RouterOS from server.\");\r\ \n :set mailSubject (\$mailSubject . \" Error: No data about\ \_new RouterOS!\")\r\ \n :set mailBody (\$mailBody . \"Error occured! \\r\\nM\ ikrotik couldn't get any information about new RouterOS from server! \\r\\\ nWatch additional information in device logs.\")\r\ \n } else={\r\ \n #Get numeric version of OS\r\ \n :set deviceOsVerAvailNum [\$buGlobalFuncGetOsVerNum paramOsV\ er=\$deviceOsVerAvail];\r\ \n\r\ \n # Checking if OS on server is greater than installed one.\r\ \n :if (\$deviceOsVerAvailNum > \$deviceOsVerInstNum) do={\r\ \n :set isOsUpdateAvailable true;\r\ \n :log info (\"\$SMP New RouterOS is available! \$deviceOs\ VerAvail\");\r\ \n } else={\r\ \n :set isSendEmailRequired false;\r\ \n :log info (\"\$SMP System is already up to date.\");\r\ \n :set mailSubject (\$mailSubject . \" No new OS updates.\ \");\r\ \n :set mailBody (\$mailBody . \"Your system is up to \ date.\");\r\ \n }\r\ \n };\r\ \n } else={\r\ \n :set scriptMode \"backup\";\r\ \n };\r\ \n\r\ \n if (\$forceBackup = true) do={\r\ \n # In this case the script will always send email, because it has\ \_to create backups\r\ \n :set isSendEmailRequired true;\r\ \n }\r\ \n\r\ \n # If a new OS version is available to install\r\ \n if (\$isOsUpdateAvailable = true and \$isSendEmailRequired = true) d\ o={\r\ \n # If we only need to notify about a new available version\r\ \n if (\$scriptMode = \"osnotify\") do={\r\ \n :set mailSubject (\$mailSubject . \" New RouterOS is avai\ lable! v.\$deviceOsVerAvail.\")\r\ \n :set mailBody (\$mailBody . \"New RouterOS version is \ available to install: v.\$deviceOsVerAvail (\$updateChannel) \\r\\n\$chang\ elogUrl\")\r\ \n }\r\ \n\r\ \n # If we need to initiate RouterOS update process\r\ \n if (\$scriptMode = \"osupdate\") do={\r\ \n :set isOsNeedsToBeUpdated true;\r\ \n # If we need to install only patch updates\r\ \n :if (\$installOnlyPatchUpdates = true) do={\r\ \n #Check if Major and Minor builds are the same.\r\ \n :if ([:pick \$deviceOsVerInstNum 0 ([:len \$deviceOsVerI\ nstNum]-2)] = [:pick \$deviceOsVerAvailNum 0 ([:len \$deviceOsVerAvailNum]\ -2)]) do={\r\ \n :log info (\"\$SMP New patch version of RouterOS fir\ mware is available.\");\r\ \n } else={\r\ \n :log info (\"\$SMP New major or minor vers\ ion of RouterOS firmware is available. You need to update it manually.\");\ \r\ \n :set mailSubject (\$mailSubject . \" New RouterOS\ : v.\$deviceOsVerAvail needs to be installed manually.\");\r\ \n :set mailBody (\$mailBody . \"New major or min\ or RouterOS version is available to install: v.\$deviceOsVerAvail (\$updat\ eChannel). \\r\\nYou chose to automatically install only patch updates, so\ \_this major update you need to install manually. \\r\\n\$changelogUrl\");\ \r\ \n :set isOsNeedsToBeUpdated false;\r\ \n }\r\ \n }\r\ \n\r\ \n #Check again, because this variable could be changed during \ checking for installing only patch updats\r\ \n if (\$isOsNeedsToBeUpdated = true) do={\r\ \n :log info (\"\$SMP New RouterOS is going to be\ \_installed! v.\$deviceOsVerInst -> v.\$deviceOsVerAvail\");\r\ \n :set mailSubject (\$mailSubject . \" New RouterOS is \ going to be installed! v.\$deviceOsVerInst -> v.\$deviceOsVerAvail.\");\r\ \n :set mailBody (\$mailBody . \"Your Mikrotik will b\ e updated to the new RouterOS version from v.\$deviceOsVerInst to v.\$devi\ ceOsVerAvail (Update channel: \$updateChannel) \\r\\nA final report with d\ etailed information will be sent once the update process is completed. \\r\ \\nIf you do not receive a second email within the next 10 minutes, there \ may be an issue. Please check your device logs for further information.\")\ ;\r\ \n #!! There is more code connected to this part and first \ step at the end of the script.\r\ \n }\r\ \n\r\ \n }\r\ \n }\r\ \n\r\ \n ## Checking If the script needs to create a backup\r\ \n :log info (\"\$SMP Checking If the script needs to create a backup.\ \");\r\ \n if (\$forceBackup = true or \$scriptMode = \"backup\" or \$isOsNeeds\ ToBeUpdated = true) do={\r\ \n :log info (\"\$SMP Creating system backups.\");\r\ \n if (\$isOsNeedsToBeUpdated = true) do={\r\ \n :set backupNameFinal \$backupNameBeforeUpd;\r\ \n };\r\ \n if (\$scriptMode != \"backup\") do={\r\ \n :set mailBody (\$mailBody . \"\\r\\n\\r\\n\");\r\ \n };\r\ \n\r\ \n :set mailSubject (\$mailSubject . \" Backup was created.\");\ \r\ \n :set mailBody (\$mailBody . \"System backups were created \ and attached to this email.\");\r\ \n\r\ \n :set mailAttachments [\$buGlobalFuncCreateBackups backupName=\$b\ ackupNameFinal backupPassword=\$backupPassword sensitiveDataInConfig=\$sen\ sitiveDataInConfig];\r\ \n } else={\r\ \n :log info (\"\$SMP There is no need to create a backup.\");\r\ \n }\r\ \n\r\ \n # Combine first step email\r\ \n :set mailBody (\$mailBody . \$mailBodyDeviceInfo . \$mailBodyCopyrig\ ht);\r\ \n}\r\ \n\r\ \n## STEP TWO: (after first reboot) routerboard firmware upgrade\r\ \n## Steps 2 and 3 are fired only if script is set to automatically update\ \_device and if new RouterOs is available.\r\ \n:if (\$updateStep = 2) do={\r\ \n :log info (\"\$SMP Performing the second step.\");\r\ \n ## RouterOS is the latest, let's check for upgraded routerboard firm\ ware\r\ \n if (\$deviceRbCurrentFw != \$deviceRbUpgradeFw) do={\r\ \n :set isSendEmailRequired false;\r\ \n :delay 10s;\r\ \n :log info \"\$SMP Upgrading routerboard firmware from v.\$device\ RbCurrentFw to v.\$deviceRbUpgradeFw\";\r\ \n ## Start the upgrading process\r\ \n /system routerboard upgrade;\r\ \n ## Wait until the upgrade is completed\r\ \n :delay 5s;\r\ \n :log info \"\$SMP routerboard upgrade process was completed, goi\ ng to reboot in a moment!\";\r\ \n ## Set scheduled task to send final report on the next boot, tas\ k will be deleted when is is done. (That is why you should keep original s\ cript name)\r\ \n /system scheduler add name=BKPUPD-FINAL-REPORT-ON-NEXT-BOOT on-e\ vent=\":delay 5s; /system scheduler remove BKPUPD-FINAL-REPORT-ON-NEXT-BOO\ T; :global buGlobalVarUpdateStep 3; :delay 10s; /system script run BackupA\ ndUpdate;\" start-time=startup interval=0;\r\ \n ## Reboot system to boot with new firmware\r\ \n /system reboot;\r\ \n } else={\r\ \n :log info \"\$SMP It appers that your routerboard is already up \ to date, skipping this step.\";\r\ \n :set updateStep 3;\r\ \n };\r\ \n}\r\ \n\r\ \n## STEP THREE: Last step (after second reboot) sending final report\r\ \n## Steps 2 and 3 are fired only if script is set to automatically update\ \_device and if new RouterOs is available.\r\ \n## This step is executed after some delay\r\ \n:if (\$updateStep = 3) do={\r\ \n :log info (\"\$SMP Performing the third step.\");\r\ \n :log info \"Bkp&Upd: RouterOS and routerboard upgrade process was co\ mpleted. New RouterOS version: v.\$deviceOsVerInst, routerboard firmware: \ v.\$deviceRbCurrentFw.\";\r\ \n ## Small delay in case mikrotik needs some time to initialize connec\ tions\r\ \n :log info \"\$SMP Sending the final email with report and backups.\"\ ;\r\ \n :set mailSubject (\$mailSubject . \" RouterOS Upgrade is complete\ d, new version: v.\$deviceOsVerInst!\");\r\ \n :set mailBody \"RouterOS and routerboard upgrade process was c\ ompleted. \\r\\nNew RouterOS version: v.\$deviceOsVerInst, routerboard fir\ mware: v.\$deviceRbCurrentFw. \\r\\n\$changelogUrl \\r\\n\\r\\nBackups of \ the upgraded system are in the attachment of this email. \$mailBodyDevice\ Info \$mailBodyCopyright\";\r\ \n :set mailAttachments [\$buGlobalFuncCreateBackups backupName=\$backu\ pNameAfterUpd backupPassword=\$backupPassword sensitiveDataInConfig=\$sens\ itiveDataInConfig];\r\ \n}\r\ \n\r\ \n# Remove functions from global environment to keep it fresh and clean.\r\ \n:do {/system script environment remove buGlobalFuncGetOsVerNum;} on-erro\ r={}\r\ \n:do {/system script environment remove buGlobalFuncCreateBackups;} on-er\ ror={}\r\ \n\r\ \n##\r\ \n## SENDING EMAIL\r\ \n##\r\ \n# Trying to send email with backups as attachments.\r\ \n\r\ \n:if (\$isSendEmailRequired = true) do={\r\ \n :log info \"\$SMP Sending email message, it will take around half a \ minute...\";\r\ \n :do {/tool e-mail send to=\$emailAddress subject=\$mailSubject body=\ \$mailBody file=\$mailAttachments;} on-error={\r\ \n :delay 5s;\r\ \n :log error \"\$SMP could not send email message (\$[/tool e-mail\ \_get last-status]). Going to try it again in a while.\"\r\ \n\r\ \n :delay 5m;\r\ \n\r\ \n :do {/tool e-mail send to=\$emailAddress subject=\$mailSubject b\ ody=\$mailBody file=\$mailAttachments;} on-error={\r\ \n :delay 5s;\r\ \n :log error \"\$SMP could not send email message (\$[/tool e-\ mail get last-status]) for the second time.\"\r\ \n\r\ \n if (\$isOsNeedsToBeUpdated = true) do={\r\ \n :set isOsNeedsToBeUpdated false;\r\ \n :log warning \"\$SMP script is not going to initialise u\ pdate process due to inability to send backups to email.\"\r\ \n }\r\ \n }\r\ \n }\r\ \n\r\ \n :delay 30s;\r\ \n\r\ \n :if ([:len \$mailAttachments] > 0 and [/tool e-mail get last-status]\ \_= \"succeeded\") do={\r\ \n :log info \"\$SMP File system cleanup.\"\r\ \n /file remove \$mailAttachments;\r\ \n :delay 2s;\r\ \n }\r\ \n\r\ \n}\r\ \n\r\ \n\r\ \n# Fire RouterOS update process\r\ \nif (\$isOsNeedsToBeUpdated = true) do={\r\ \n\r\ \n :if (\$isSoftBased = false) do={\r\ \n ## Set scheduled task to upgrade routerboard firmware on the nex\ t boot, task will be deleted when upgrade is done. (That is why you should\ \_keep original script name)\r\ \n /system scheduler add name=BKPUPD-UPGRADE-ON-NEXT-BOOT on-event=\ \":delay 5s; /system scheduler remove BKPUPD-UPGRADE-ON-NEXT-BOOT; :global\ \_buGlobalVarUpdateStep 2; :delay 10s; /system script run BackupAndUpdate;\ \" start-time=startup interval=0;\r\ \n } else= {\r\ \n ## If the script is executed on CHR, step 2 will be skipped\r\ \n /system scheduler add name=BKPUPD-UPGRADE-ON-NEXT-BOOT on-event=\ \":delay 5s; /system scheduler remove BKPUPD-UPGRADE-ON-NEXT-BOOT; :global\ \_buGlobalVarUpdateStep 3; :delay 10s; /system script run BackupAndUpdate;\ \" start-time=startup interval=0;\r\ \n };\r\ \n\r\ \n\r\ \n :log info \"\$SMP everything is ready to install new RouterOS, going\ \_to reboot in a moment!\"\r\ \n ## Command is reincarnation of the \"upgrade\" command - doing exact\ ly the same but under a different name\r\ \n /system package update install;\r\ \n}\r\ \n\r\ \n:log info \"\$SMP script \\\"Mikrotik RouterOS automatic backup & update\ \\\" completed it's job.\\r\\n\";\r\ \n" add dont-require-permissions=no name=debug_netbox_api owner=graham policy=\ ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="#\ \_Minimal Interface Test for NetBox API\ \n# Absolute bare minimum to isolate 400 error cause\ \n\ \n:local netboxUrl \"https://netbox.vntx.net\"\ \n:local netboxToken \"d7d1086aa69b3dff46207e4f1b44d99de4188c04\"\ \n:local routerName [/system identity get name]\ \n\ \n:log info \"Starting minimal interface test for \$routerName\"\ \n\ \n# Step 1: Get device ID - this must work first\ \n:local deviceId \"\"\ \n:do {\ \n /tool fetch url=\"\$netboxUrl/api/dcim/devices/\?name=\$routerName\"\ \_http-method=get http-header-field=\"Authorization: Token \$netboxToken\"\ \_dst-path=device.json\ \n :local content [/file get device.json contents]\ \n :log info \"Device lookup response: \$content\"\ \n\ \n # Simple ID extraction\ \n :local start [:find \$content \"\\\"id\\\":\"]\ \n :if (\$start >= 0) do={\ \n :set start (\$start + 5)\ \n :local end [:find \$content \",\" \$start]\ \n :if (\$end < 0) do={ :set end [:find \$content \"}\" \$start] }\ \n :set deviceId [:pick \$content \$start \$end]\ \n }\ \n /file remove device.json\ \n} on-error={\ \n :log error \"Device lookup failed\"\ \n}\ \n\ \n:if ([:len \$deviceId] = 0) do={\ \n :log error \"No device ID - cannot test interfaces\"\ \n} else={\ \n :log info \"Using device ID: \$deviceId\"\ \n\ \n # Step 2: Test absolute minimal interface\ \n :log info \"Testing minimal interface creation\"\ \n :local minimalJson \"{\\\"device\\\":\$deviceId,\\\"name\\\":\\\"tes\ t1\\\",\\\"type\\\":\\\"other\\\"}\"\ \n :log info \"JSON: \$minimalJson\"\ \n :local jsonLen [:len \$minimalJson]\ \n :log info \"JSON length: \$jsonLen\"\ \n\ \n :do {\ \n /tool fetch url=\"\$netboxUrl/api/dcim/interfaces/\" http-method\ =post http-header-field=\"Authorization: Token \$netboxToken,Content-Type:\ \_application/json\" http-data=\$minimalJson dst-path=result.json\ \n :local result [/file get result.json contents]\ \n :log info \"SUCCESS: \$result\"\ \n /file remove result.json\ \n } on-error={\ \n :log error \"FAILED - checking error response\"\ \n :do {\ \n :local errorResp [/file get result.json contents]\ \n :log error \"Error response: \$errorResp\"\ \n /file remove result.json\ \n } on-error={\ \n :log error \"Could not read error response file\"\ \n }\ \n }\ \n}\ \n\ \n:log info \"Minimal interface test completed\"\ \n" /tool e-mail set from=mikrotik@vntx.net server=10.0.0.250 /tool romon set enabled=yes id=08:55:31:E5:F8:C1 /tool sniffer set file-name=vilo filter-ip-address=100.64.0.52/32 /user aaa set default-group=full use-radius=yes