network/verona.rsc
2026-05-08 17:47:42 -05:00

1775 lines
82 KiB
Text

# 2026-04-27 14:18:51 by RouterOS 7.20.8
# software id = Y1CT-1WB1
#
# model = CCR2004-16G-2S+
# serial number = HF109012G8D
/interface bridge
add fast-forward=no name=cpe_vlan_10 port-cost-mode=short
add name=loopback port-cost-mode=short
add fast-forward=no mtu=1500 name=public_vlan_100 port-cost-mode=short \
protocol-mode=none
add name=temp port-cost-mode=short
add add-dhcp-option82=yes dhcp-snooping=yes mtu=1500 name=verona \
port-cost-mode=short protocol-mode=none
/interface ethernet
set [ find default-name=ether1 ] l2mtu=1500
set [ find default-name=ether2 ] l2mtu=1500
set [ find default-name=ether3 ] l2mtu=1500 name=ether3-climax-11ghz \
rx-flow-control=auto tx-flow-control=auto
set [ find default-name=ether4 ] l2mtu=9582 name=ether4-verona-tower
set [ find default-name=ether5 ] l2mtu=9582 mtu=9000
set [ find default-name=ether6 ] l2mtu=9582 name=ether6-switch
set [ find default-name=ether7 ] l2mtu=9582 mtu=9000
set [ find default-name=ether8 ] l2mtu=9582 mtu=9000
set [ find default-name=ether9 ] l2mtu=9582 mtu=9000
set [ find default-name=ether10 ] l2mtu=1500 name=ether10-powerswitch
set [ find default-name=ether11 ] l2mtu=9582 mtu=9000
set [ find default-name=ether12 ] l2mtu=9582 mtu=9000
set [ find default-name=ether13 ] l2mtu=9582 mtu=9000
set [ find default-name=ether14 ] l2mtu=9582 mtu=9000
set [ find default-name=ether15 ] l2mtu=9582 mtu=9000 name=ether15_wave_n
set [ find default-name=ether16 ] l2mtu=9582 mtu=9000
set [ find default-name=sfp-sfpplus1 ] l2mtu=9586 name=\
sfp-sfpplus1-verona-tower-switch
set [ find default-name=sfp-sfpplus2 ] l2mtu=9586 name=sfp-sfpplus2-switch
/interface eoip
add disabled=yes local-address=10.254.254.101 mac-address=02:22:FE:AB:DA:38 \
mtu=1530 name=eoip-380 remote-address=204.110.191.252 tunnel-id=101
/interface vpls
add mac-address=02:E4:27:10:14:C6 name=vpls-pppoe-to-virtual peer=\
204.110.191.252 vpls-id=101:252
/interface vxlan
add dont-fragment=disabled local-address=10.254.254.101 mac-address=\
26:46:20:4A:56:C4 name=vxlan-380 port=8472 vni=1
/interface vlan
add interface=sfp-sfpplus1-verona-tower-switch name=vlan9_sfpplus1 vlan-id=9
add interface=ether15_wave_n name=vlan10_ether15 vlan-id=10
add interface=sfp-sfpplus2-switch name=vlan10_sfpplus2 vlan-id=10
add interface=verona name=vlan_10_ether6 vlan-id=10
add interface=ether6-switch name=vlan_19_ether6 vlan-id=19
/interface lte apn
set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip dhcp-server
add add-arp=yes disabled=yes interface=ether10-powerswitch lease-time=10m \
name=radiustest relay=204.110.191.248
/ip hotspot profile
add dns-name=verona.tx.vntx.net hotspot-address=100.64.3.254 login-by="" \
name=hsprof1
add dns-name=verona.tx.vntx.net hotspot-address=192.168.99.254 login-by=mac \
name=radiustest use-radius=yes
/ip hotspot user profile
set [ find default=yes ] add-mac-cookie=no
/ip pool
add name=verona-cpe ranges=10.10.0.1-10.10.14.254
add name=altoga-old ranges=10.100.80.1-10.100.94.254
add name=altoga-cpe ranges=10.10.80.1-10.10.94.254
add name=verona-cgnat ranges=100.64.0.1-100.64.3.249
add name=altoga-cgnat ranges=100.64.12.1-100.64.15.253
add name=verona-tower-pool ranges=10.0.101.1-10.0.101.249
add name=radiustest ranges=192.168.99.1-192.168.99.249
/ip dhcp-server
add address-pool=altoga-cpe authoritative=after-2sec-delay disabled=yes \
interface=vlan_10_ether6 lease-script=":global username \"6aYoFE5Pw8ky1JyO\
\"\r\
\n:global password \"aZLnmeROsUYfUNGw\"\r\
\n:global url \"204.110.191.244\"\r\
\n:global mode \"http\"\r\
\n\r\
\n:if (\$leaseBound = 0) do={\r\
\n /tool fetch url=\"\$mode://\$url/api/dhcp_assignments\?ip_address=\$l\
easeActIP&leased_mac_address=\$leaseActMAC&expired=1\" mode=\$mode keep-re\
sult=no user=\$username password=\$password\r\
\n} else={\r\
\n { :delay 1 };\r\
\n :local remoteID\r\
\n :set remoteID [/ip dhcp-server lease get [find where address=\$leaseA\
ctIP] agent-remote-id]\r\
\n /tool fetch url=\"\$mode://\$url/api/dhcp_assignments\?ip_address=\$l\
easeActIP&leased_mac_address=\$leaseActMAC&remote_id=\$remoteID&expired=0\
\" mode=\$mode keep-result=no user=\$username password=\$password\r\
\n};" lease-time=1h name=altoga-cpe
add add-arp=yes address-pool=verona-tower-pool interface=\
sfp-sfpplus1-verona-tower-switch lease-time=1h name=verona-tower
add add-arp=yes address-pool=verona-cgnat interface=verona lease-script="{\
\n:local url \"https://xtjlpnubrg.execute-api.us-east-1.amazonaws.com/prod\
uction/on-start-workflow-execution/6f19a48f-04f7-40c1-a4e0-8cb66df99213/cd\
c24944-c947-4e01-9c54-07a1653d2e3e\"\
\n:local url2 \"https://iptrack.vntx.net/api/dhcp\"\
\n:local max 1\
\n\
\n:local attempts 0\
\n:local success1 0\
\n:local success2 0\
\n:do {\
\n :set attempts (\$attempts+1);\
\n :if (\$leaseBound = 0) do {\
\n # Try url2 (iptrack.vntx.net) - deassignment\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=pos\
t http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\
und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\
\\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\"}\"\
\n :set success1 1;\
\n :log info \"DHCP deassignment successfully sent to iptrack.vntx.ne\
t for \$leaseActMAC / \$leaseActIP\";\
\n } on-error={\
\n :log error \"DHCP FAILED to send deassignment to iptrack.vntx.net \
on attempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP\";\
\n }\
\n\
\n # Try url (gaiia) - deassignment\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post\
\_http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\
und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\
\\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\",\\\"remoteId\
\\\":\\\"\\\"}\"\
\n :set success2 1;\
\n :log info \"DHCP deassignment successfully sent to gaiia AWS API f\
or \$leaseActMAC / \$leaseActIP\";\
\n } on-error={\
\n :log error \"DHCP FAILED to send deassignment to gaiia AWS API on \
attempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP\";\
\n }\
\n\
\n :if (\$success1 != 1 || \$success2 != 1) do={\
\n :delay 3s;\
\n }\
\n } else {\
\n :delay 1s;\
\n :local remoteID [/ip dhcp-server lease get [find where address=\$lea\
seActIP] agent-remote-id];\
\n\
\n # Try url2 (iptrack.vntx.net) - assignment\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=pos\
t http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\
und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\
\\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\",\\\"remoteId\
\\\":\\\"\$remoteID\\\"}\"\
\n :set success1 1;\
\n :log info \"DHCP assignment successfully sent to iptrack.vntx.net \
for \$leaseActMAC / \$leaseActIP / \$remoteID\";\
\n } on-error={\
\n :log error \"DHCP FAILED to send assignment to iptrack.vntx.net on\
\_attempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP / \$remoteID\"\
;\
\n }\
\n\
\n # Try url (gaiia) - assignment\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post\
\_http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\
und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\
\\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\",\\\"remoteId\
\\\":\\\"\$remoteID\\\"}\"\
\n :set success2 1;\
\n :log info \"DHCP assignment successfully sent to gaiia AWS API for\
\_\$leaseActMAC / \$leaseActIP / \$remoteID\";\
\n } on-error={\
\n :log error \"DHCP FAILED to send assignment to gaiia AWS API on at\
tempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP / \$remoteID\";\
\n }\
\n\
\n :if (\$success1 != 1 || \$success2 != 1) do={\
\n :delay 30s;\
\n }\
\n }\
\n :if (\$success1 = 1 && \$success2 = 1) do {\
\n :set attempts \$max;\
\n }\
\n} while ( \$attempts < \$max )\
\n}\
\n" lease-time=1h name="verona cgnat" use-radius=accounting
/ip hotspot
add address-pool=verona-cgnat addresses-per-mac=unlimited disabled=no \
interface=verona name=hotspot1 profile=hsprof1
add address-pool=radiustest addresses-per-mac=unlimited interface=\
ether10-powerswitch name=radiustest profile=radiustest
/ip smb users
set [ find default=yes ] disabled=yes
/ipv6 dhcp-server
add interface=verona lease-time=10m name=server1 prefix-pool=\
verona-v6-pd-pool
/ipv6 pool
add name=verona-v6-pd-pool prefix=2606:1c80:100::/40 prefix-length=56
/port
set 0 name=serial0
set 1 name=serial1
/ppp profile
add change-tcp-mss=yes dhcpv6-pd-pool=verona-v6-pd-pool dns-server=\
204.110.191.240,204.110.191.250 idle-timeout=1h local-address=\
100.64.15.253 name=pppoe-verona on-down="{\
\n:local url \"https://xtjlpnubrg.execute-api.us-east-1.amazonaws.com/prod\
uction/on-start-workflow-execution/6f19a48f-04f7-40c1-a4e0-8cb66df99213/0a\
7f4443-fc8a-4fe0-807c-f535d2aa1865\"\
\n:local url2 \"https://iptrack.vntx.net/api/pppoe\"\
\n:local max 1\
\n\
\n:local localAddr \$\"local-address\"\
\n:local remoteAddr \$\"remote-address\"\
\n:local callerId \$\"caller-id\"\
\n:local calledId \$\"called-id\"\
\n:local interfaceName [/interface get \$interface name]\
\n\
\n:local attempts 0\
\n:local success1 0\
\n:local success2 0\
\n:do {\
\n :set attempts (\$attempts+1);\
\n\
\n # Try url2 (iptrack.vntx.net)\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=post \
http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"boun\
d\\\":\\\"0\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\
\\\"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\
\n :set success1 1;\
\n :log info \"PPPoE deassignment successfully sent to iptrack.vntx.net\
\_for \$user / \$remoteAddr\";\
\n } on-error={\
\n :log error \"PPPoE FAILED to send deassignment to iptrack.vntx.net o\
n attempt \$attempts out of \$max for \$user / \$remoteAddr\";\
\n }\
\n\
\n # Try url (AWS API)\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post h\
ttp-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bound\
\\\":\\\"0\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\\\
\"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\
\n :set success2 1;\
\n :log info \"PPPoE deassignment successfully sent to gaiia AWS API fo\
r \$user / \$remoteAddr\";\
\n } on-error={\
\n :log error \"PPPoPoE FAILED to send deassignment to gaiia AWS API on\
\_attempt \$attempts out of \$max for \$user / \$remoteAddr\";\
\n }\
\n\
\n :if (\$success1 = 1 && \$success2 = 1) do {\
\n :set attempts \$max;\
\n } else {\
\n :delay 3s;\
\n }\
\n} while ( \$attempts < \$max )\
\n}\
\n" on-up="{\
\n:local url \"https://xtjlpnubrg.execute-api.us-east-1.amazonaws.com/prod\
uction/on-start-workflow-execution/6f19a48f-04f7-40c1-a4e0-8cb66df99213/0a\
7f4443-fc8a-4fe0-807c-f535d2aa1865\"\
\n:local url2 \"https://iptrack.vntx.net/api/pppoe\"\
\n:local max 5\
\n\
\n:local localAddr \$\"local-address\"\
\n:local remoteAddr \$\"remote-address\"\
\n:local callerId \$\"caller-id\"\
\n:local calledId \$\"called-id\"\
\n:local interfaceName [/interface get \$interface name]\
\n\
\n:local attempts 0\
\n:local success1 0\
\n:local success2 0\
\n:do {\
\n :set attempts (\$attempts+1);\
\n\
\n # Try url2 (iptrack.vntx.net)\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=post \
http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"boun\
d\\\":\\\"1\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\
\\\"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\
\n :set success1 1;\
\n :log info \"PPPoE assignment successfully sent to iptrack.vntx.net f\
or \$user / \$remoteAddr\";\
\n } on-error={\
\n :log error \"PPPoE FAILED to send assignment to iptrack.vntx.net on \
attempt \$attempts out of \$max for \$user / \$remoteAddr\";\
\n }\
\n\
\n # Try url (gaiia)\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post h\
ttp-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bound\
\\\":\\\"1\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\\\
\"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\
\n :set success2 1;\
\n :log info \"PPPoE assignment successfully sent to gaiia AWS API for \
\$user / \$remoteAddr\";\
\n } on-error={\
\n :log error \"PPPoE FAILED to send assignment to gaiia AWS API on att\
empt \$attempts out of \$max for \$user / \$remoteAddr\";\
\n }\
\n\
\n :if (\$success1 = 1 && \$success2 = 1) do {\
\n :set attempts \$max;\
\n } else {\
\n :delay 3s;\
\n }\
\n} while ( \$attempts < \$max )\
\n}\
\n" remote-address=verona-cgnat remote-ipv6-prefix-pool=verona-v6-pd-pool \
use-upnp=no
add change-tcp-mss=yes dns-server=204.110.191.240,204.110.191.250 \
idle-timeout=1h local-address=100.64.15.253 name=pppoe-altoga on-down="{\
\n:local url \"https://xtjlpnubrg.execute-api.us-east-1.amazonaws.com/prod\
uction/on-start-workflow-execution/6f19a48f-04f7-40c1-a4e0-8cb66df99213/0a\
7f4443-fc8a-4fe0-807c-f535d2aa1865\"\
\n:local url2 \"https://iptrack.vntx.net/api/pppoe\"\
\n:local max 1\
\n\
\n:local localAddr \$\"local-address\"\
\n:local remoteAddr \$\"remote-address\"\
\n:local callerId \$\"caller-id\"\
\n:local calledId \$\"called-id\"\
\n:local interfaceName [/interface get \$interface name]\
\n\
\n:local attempts 0\
\n:local success1 0\
\n:local success2 0\
\n:do {\
\n :set attempts (\$attempts+1);\
\n\
\n # Try url2 (iptrack.vntx.net)\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=post \
http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"boun\
d\\\":\\\"0\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\
\\\"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\
\n :set success1 1;\
\n :log info \"PPPoE deassignment successfully sent to iptrack.vntx.net\
\_for \$user / \$remoteAddr\";\
\n } on-error={\
\n :log error \"PPPoE FAILED to send deassignment to iptrack.vntx.net o\
n attempt \$attempts out of \$max for \$user / \$remoteAddr\";\
\n }\
\n\
\n # Try url (AWS API)\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post h\
ttp-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bound\
\\\":\\\"0\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\\\
\"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\
\n :set success2 1;\
\n :log info \"PPPoE deassignment successfully sent to gaiia AWS API fo\
r \$user / \$remoteAddr\";\
\n } on-error={\
\n :log error \"PPPoPoE FAILED to send deassignment to gaiia AWS API on\
\_attempt \$attempts out of \$max for \$user / \$remoteAddr\";\
\n }\
\n\
\n :if (\$success1 = 1 && \$success2 = 1) do {\
\n :set attempts \$max;\
\n } else {\
\n :delay 3s;\
\n }\
\n} while ( \$attempts < \$max )\
\n}\
\n" on-up="{\
\n:local url \"https://xtjlpnubrg.execute-api.us-east-1.amazonaws.com/prod\
uction/on-start-workflow-execution/6f19a48f-04f7-40c1-a4e0-8cb66df99213/0a\
7f4443-fc8a-4fe0-807c-f535d2aa1865\"\
\n:local url2 \"https://iptrack.vntx.net/api/pppoe\"\
\n:local max 5\
\n\
\n:local localAddr \$\"local-address\"\
\n:local remoteAddr \$\"remote-address\"\
\n:local callerId \$\"caller-id\"\
\n:local calledId \$\"called-id\"\
\n:local interfaceName [/interface get \$interface name]\
\n\
\n:local attempts 0\
\n:local success1 0\
\n:local success2 0\
\n:do {\
\n :set attempts (\$attempts+1);\
\n\
\n # Try url2 (iptrack.vntx.net)\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=post \
http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"boun\
d\\\":\\\"1\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\
\\\"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\
\n :set success1 1;\
\n :log info \"PPPoE assignment successfully sent to iptrack.vntx.net f\
or \$user / \$remoteAddr\";\
\n } on-error={\
\n :log error \"PPPoE FAILED to send assignment to iptrack.vntx.net on \
attempt \$attempts out of \$max for \$user / \$remoteAddr\";\
\n }\
\n\
\n # Try url (gaiia)\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post h\
ttp-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bound\
\\\":\\\"1\\\",\\\"username\\\":\\\"\$user\\\",\\\"callingstationid\\\":\\\
\"\$callerId\\\",\\\"framedip\\\":\\\"\$remoteAddr\\\"}\"\
\n :set success2 1;\
\n :log info \"PPPoE assignment successfully sent to gaiia AWS API for \
\$user / \$remoteAddr\";\
\n } on-error={\
\n :log error \"PPPoE FAILED to send assignment to gaiia AWS API on att\
empt \$attempts out of \$max for \$user / \$remoteAddr\";\
\n }\
\n\
\n :if (\$success1 = 1 && \$success2 = 1) do {\
\n :set attempts \$max;\
\n } else {\
\n :delay 3s;\
\n }\
\n} while ( \$attempts < \$max )\
\n}\
\n" remote-address=altoga-cgnat use-upnp=no
/queue type
add kind=fq-codel name=FQ_Codel
/queue interface
set ether1 queue=FQ_Codel
set ether2 queue=FQ_Codel
set ether3-climax-11ghz queue=FQ_Codel
set ether4-verona-tower queue=FQ_Codel
set ether5 queue=FQ_Codel
set ether6-switch queue=FQ_Codel
set ether7 queue=FQ_Codel
set ether8 queue=FQ_Codel
set ether9 queue=FQ_Codel
set ether10-powerswitch queue=FQ_Codel
set ether11 queue=FQ_Codel
set ether12 queue=FQ_Codel
set ether13 queue=FQ_Codel
set ether14 queue=FQ_Codel
set ether15_wave_n queue=FQ_Codel
set ether16 queue=FQ_Codel
set sfp-sfpplus1-verona-tower-switch queue=FQ_Codel
set sfp-sfpplus2-switch queue=FQ_Codel
/routing bgp template
set default disabled=no output.network=bgp-networks
/routing id
add disabled=no id=10.254.254.101 name=id-1 select-dynamic-id=""
/routing ospf instance
add disabled=no in-filter-chain=ospf-in name=default-v2 originate-default=\
never out-filter-chain=ospf-out redistribute=connected router-id=id-1
add disabled=no in-filter-chain=ospf-in name=default-v3 out-filter-chain=\
ospf-out router-id=id-1 version=3
/routing ospf area
add disabled=no instance=default-v2 name=backbone-v2
add disabled=no instance=default-v3 name=backbone-v3
/routing rip instance
add afi=ip disabled=no in-filter-chain=ospf-in name=rip-instance-1 \
out-filter-chain=ospf-out vrf=main
/snmp community
set [ find default=yes ] name=kdyyJrT0Mm
/system logging action
set 3 remote=204.110.191.208 src-address=10.254.254.101
add name=logs remote=204.110.191.229 remote-port=1514 src-address=\
10.254.254.101 target=remote
/zerotier
set zt1 disabled=no disabled=no
/zerotier interface
add allow-default=no allow-global=no allow-managed=yes disabled=no instance=\
zt1 name=zerotier1 network=a84ac5c10a229236
/interface bridge port
add bridge=verona ingress-filtering=no interface=ether6-switch \
internal-path-cost=10 path-cost=10
add bridge=verona interface=sfp-sfpplus2-switch internal-path-cost=10 \
path-cost=10
add bridge=temp disabled=yes interface=eoip-380 internal-path-cost=10 \
path-cost=10
add bridge=verona interface=ether15_wave_n internal-path-cost=10 path-cost=10
add bridge=cpe_vlan_10 interface=vlan_10_ether6 internal-path-cost=10 \
path-cost=10
add bridge=cpe_vlan_10 interface=vlan10_sfpplus2 internal-path-cost=10 \
path-cost=10
add bridge=temp interface=vxlan-380 internal-path-cost=10 path-cost=10
add bridge=cpe_vlan_10 interface=vlan10_ether15
add bridge=cpe_vlan_10 interface=ether10-powerswitch
/ip firewall connection tracking
set tcp-established-timeout=4h tcp-fin-wait-timeout=2m tcp-time-wait-timeout=\
2m
/ip neighbor discovery-settings
set discover-interface-list=all
/interface ovpn-server server
add auth=sha1,md5 mac-address=FE:7F:37:F6:80:C4 name=ovpn-server1
/interface pppoe-server server
add default-profile=pppoe-verona disabled=no interface=verona max-mru=1500 \
max-mtu=1500 one-session-per-host=yes service-name=verona
add default-profile=pppoe-altoga disabled=no interface=vlan_19_ether6 \
max-mru=1500 max-mtu=1500 one-session-per-host=yes service-name=altoga
add authentication=mschap2 default-profile=pppoe-verona interface=ether1 \
max-mru=1492 max-mtu=1492 one-session-per-host=yes service-name=\
veronatest
/interface vxlan vteps
add interface=vxlan-380 remote-ip=10.254.254.252
/ip address
add address=10.250.1.25/29 interface=ether3-climax-11ghz network=10.250.1.24
add address=10.254.254.101 interface=loopback network=10.254.254.101
add address=100.64.3.254/22 interface=verona network=100.64.0.0
add address=204.110.188.254/27 interface=verona network=204.110.188.224
add address=100.64.15.254/22 interface=ether6-switch network=100.64.12.0
add address=10.10.95.254/20 interface=vlan_10_ether6 network=10.10.80.0
add address=10.10.15.254/20 interface=vlan_10_ether6 network=10.10.0.0
add address=10.0.101.254/24 interface=sfp-sfpplus1-verona-tower-switch \
network=10.0.101.0
add address=10.250.1.145/29 interface=ether6-switch network=10.250.1.144
add address=204.110.191.30/27 interface=vlan9_sfpplus1 network=204.110.191.0
add address=10.25.1.254/24 interface=ether1 network=10.25.1.0
add address=192.168.1.23/24 disabled=yes interface=verona network=192.168.1.0
/ip dhcp-server
add add-arp=yes address-pool=verona-cpe authoritative=after-2sec-delay \
dhcp-option-set=vntx interface=cpe_vlan_10 lease-script="{\
\n:local url \"https://xtjlpnubrg.execute-api.us-east-1.amazonaws.com/prod\
uction/on-start-workflow-execution/6f19a48f-04f7-40c1-a4e0-8cb66df99213/cd\
c24944-c947-4e01-9c54-07a1653d2e3e\"\
\n:local url2 \"https://iptrack.vntx.net/api/dhcp\"\
\n:local max 1\
\n\
\n:local attempts 0\
\n:local success1 0\
\n:local success2 0\
\n:do {\
\n :set attempts (\$attempts+1);\
\n :if (\$leaseBound = 0) do {\
\n # Try url2 (iptrack.vntx.net) - deassignment\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=pos\
t http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\
und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\
\\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\"}\"\
\n :set success1 1;\
\n :log info \"DHCP deassignment successfully sent to iptrack.vntx.ne\
t for \$leaseActMAC / \$leaseActIP\";\
\n } on-error={\
\n :log error \"DHCP FAILED to send deassignment to iptrack.vntx.net \
on attempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP\";\
\n }\
\n\
\n # Try url (gaiia) - deassignment\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post\
\_http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\
und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\
\\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\",\\\"remoteId\
\\\":\\\"\\\"}\"\
\n :set success2 1;\
\n :log info \"DHCP deassignment successfully sent to gaiia AWS API f\
or \$leaseActMAC / \$leaseActIP\";\
\n } on-error={\
\n :log error \"DHCP FAILED to send deassignment to gaiia AWS API on \
attempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP\";\
\n }\
\n\
\n :if (\$success1 != 1 || \$success2 != 1) do={\
\n :delay 3s;\
\n }\
\n } else {\
\n :delay 1s;\
\n :local remoteID [/ip dhcp-server lease get [find where address=\$lea\
seActIP] agent-remote-id];\
\n\
\n # Try url2 (iptrack.vntx.net) - assignment\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url2\" http-method=pos\
t http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\
und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\
\\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\",\\\"remoteId\
\\\":\\\"\$remoteID\\\"}\"\
\n :set success1 1;\
\n :log info \"DHCP assignment successfully sent to iptrack.vntx.net \
for \$leaseActMAC / \$leaseActIP / \$remoteID\";\
\n } on-error={\
\n :log error \"DHCP FAILED to send assignment to iptrack.vntx.net on\
\_attempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP / \$remoteID\"\
;\
\n }\
\n\
\n # Try url (gaiia) - assignment\
\n :do {\
\n /tool fetch duration=30s mode=https url=\"\$url\" http-method=post\
\_http-header-field=\"Content-Type: application/json\" http-data=\"{\\\"bo\
und\\\":\\\"\$leaseBound\\\",\\\"mac\\\":\\\"\$leaseActMAC\\\",\\\"ip\\\":\
\\\"\$leaseActIP\\\",\\\"server\\\":\\\"\$leaseServerName\\\",\\\"remoteId\
\\\":\\\"\$remoteID\\\"}\"\
\n :set success2 1;\
\n :log info \"DHCP assignment successfully sent to gaiia AWS API for\
\_\$leaseActMAC / \$leaseActIP / \$remoteID\";\
\n } on-error={\
\n :log error \"DHCP FAILED to send assignment to gaiia AWS API on at\
tempt \$attempts/\$max for \$leaseActMAC / \$leaseActIP / \$remoteID\";\
\n }\
\n\
\n :if (\$success1 != 1 || \$success2 != 1) do={\
\n :delay 30s;\
\n }\
\n }\
\n :if (\$success1 = 1 && \$success2 = 1) do {\
\n :set attempts \$max;\
\n }\
\n} while ( \$attempts < \$max )\
\n}\
\n" lease-time=1h name=verona-cpe use-radius=accounting
/ip dhcp-server config
set interim-update=5m
/ip dhcp-server lease
add address=10.0.101.2 mac-address=94:C6:91:14:84:44 server=verona-tower
add address=10.0.101.4 mac-address=94:C6:91:A1:FE:15 server=verona-tower
add address=10.0.101.6 mac-address=00:00:00:00:00:01 server=verona-tower
add address=10.0.101.11 client-id=1:58:8a:5a:ef:f:a0 comment="temp exclusion" \
mac-address=58:8A:5A:EF:0F:AA server=verona-tower
add address=10.0.101.8 comment="exclusion for dell server" mac-address=\
00:00:00:00:00:08 server=verona-tower
add address=10.0.101.7 client-id=1:dc:2c:6e:dd:87:54 mac-address=\
DC:2C:6E:DD:87:54 server=verona-tower
add address=100.64.3.250 client-id=1:48:a9:8a:9d:9b:8a mac-address=\
48:A9:8A:9D:9B:8A server="verona cgnat"
add address=10.0.101.253 client-id=1:c4:ad:34:1a:ca:96 disabled=yes \
mac-address=C4:AD:34:1A:CA:96 server=verona-tower
add address=10.0.101.253 client-id=1:c4:ad:34:1a:ca:98 disabled=yes \
mac-address=C4:AD:34:1A:CA:98 server=verona-tower
add address=10.0.101.12 client-id=1:c4:ad:34:1a:ca:96 mac-address=\
C4:AD:34:1A:CA:96 server=verona-tower
add address=10.0.101.22 client-id=\
ff:d8:13:97:9e:0:1:0:1:30:63:25:c7:e0:51:d8:13:97:9e mac-address=\
E0:51:D8:13:97:9E server=verona-tower
add address=10.0.101.21 client-id=\
ff:d8:13:36:6d:0:1:0:1:30:72:cb:b2:e0:51:d8:13:36:6d mac-address=\
E0:51:D8:13:36:6D server=verona-tower
/ip dhcp-server network
add address=10.0.101.0/24 dns-server=204.110.191.240,204.110.191.250 gateway=\
10.0.101.254 ntp-server=204.110.191.19
add address=10.10.0.0/20 dns-server=204.110.191.240,204.110.191.20 domain=\
vntx.net gateway=10.10.15.254 ntp-server=204.110.191.19
add address=10.10.80.0/20 dns-server=204.110.191.240,204.110.191.250 domain=\
vntx.net gateway=10.10.95.254 ntp-server=204.110.191.19
add address=100.64.0.0/22 dns-server=204.110.191.240,204.110.191.20 domain=\
vntx.net gateway=100.64.3.254 ntp-server=204.110.191.19
add address=100.64.12.0/22 dns-server=204.110.191.240,204.110.191.250 domain=\
vntx.net gateway=100.64.15.254 ntp-server=204.110.191.19
add address=192.168.99.0/24 dns-server=204.110.191.240,204.110.191.250 \
gateway=192.168.99.254
add address=204.110.188.224/27 dns-server=204.110.191.240,204.110.191.250 \
domain=vntx.net gateway=204.110.188.254 ntp-server=204.110.191.19
/ip dhcp-server option sets
add name=vntx options=*1
/ip dns
set servers=9.9.9.9,8.8.8.8
/ip firewall address-list
add address=204.110.188.225 comment="Graham McIntire (1)" list=VeronaEmployee
add address=204.110.188.231 comment="James Hardin (1475)" list=VeronaEmployee
add address=100.64.0.38 comment="Brad Wilson (1491)" list=VeronaEmployee
add address=100.64.0.62 comment="James Hardin (1475)" list=VeronaEmployee
add address=100.64.0.19 comment="TJ Banschbach (1676)" list=50
add address=100.64.0.8 comment="Alma Acosta (28)" list=ResidentialBasic
add address=100.64.0.31 comment="Scott Armstrong (315)" list=ResidentialBasic
add address=100.64.0.29 comment="Beverly Erwin (48)" list=ResidentialBasic
add address=100.64.0.18 comment="Karen Stewart (2050)" list=ResidentialBasic
add address=100.64.0.17 comment="Nathan McTee (273)" list=ResidentialBasic
add address=100.64.0.16 comment="Doug Stowe (1807)" list=ResidentialBasic
add address=100.64.0.45 comment="Debra Vega (112)" list=ResidentialBasic
add address=100.64.0.50 comment="Steven Spurgers (1211)" list=\
ResidentialBasic
add address=100.64.0.46 comment="Chrissy Eagle 2 (1530)" list=\
ResidentialBasic
add address=100.64.0.22 comment="Steve Christiaens (329)" list=\
ResidentialBasic
add address=100.64.0.23 comment="Ryan McTee (306)" list=ResidentialBasic
add address=100.64.0.9 comment="Krysta Bates (218)" list=ResidentialBasic
add address=10.10.0.63 comment="Alicia Torres (1938)" list=ResidentialBasic
add address=10.10.0.47 comment="Alma Acosta (28)" list=ResidentialBasic
add address=10.10.0.17 comment="Judy Devine (277)" list=ResidentialBasic
add address=10.10.0.24 comment="Scott Armstrong (315)" list=ResidentialBasic
add address=100.64.0.14 comment="Teresa Robinson (376)" list=BusinessBasic
add address=10.10.0.59 comment="Teresa Robinson (376)" list=BusinessBasic
add address=204.110.188.226 comment="James Genneken (160)" list=\
ResidentialAdvanced
add address=204.110.188.233 comment="Joey Whitfield (187)" list=\
ResidentialAdvanced
add address=204.110.188.229 comment="Vance Peltonen (356)" list=\
ResidentialAdvanced
add address=204.110.188.234 comment="Sonya McTee (324)" list=\
ResidentialAdvanced
add address=204.110.188.235 comment="Austin Watkins (769)" list=\
ResidentialAdvanced
add address=100.64.0.48 comment="Pablo Hernandez (2083)" list=\
ResidentialAdvanced
add address=204.110.188.237 comment="Ron Lewis (302)" list=\
ResidentialAdvanced
add address=100.64.0.39 comment="Dana Nance (89)" list=ResidentialAdvanced
add address=100.64.0.30 comment="Chand Parvathaneni (2396)" list=\
ResidentialAdvanced
add address=100.64.0.28 comment="Mark Fisher (242)" list=ResidentialAdvanced
add address=100.64.0.13 comment="CLAY GILBERT (1839)" list=\
ResidentialAdvanced
add address=100.64.0.2 comment="JoleneDon Nance (118)" list=\
ResidentialAdvanced
add address=100.64.0.44 comment="Brad Sherry Slate (1334)" list=\
ResidentialAdvanced
add address=100.64.0.47 comment="Eric Barrett (2386)" list=\
ResidentialAdvanced
add address=100.64.0.49 comment="David Lanman (2486)" list=\
ResidentialAdvanced
add address=100.64.0.37 comment="Rebekah Moore (386)" list=\
ResidentialAdvanced
add address=100.64.0.69 comment="Yolanda Medrano (2461)" list=\
ResidentialAdvanced
add address=100.64.0.6 comment="Jennifer Little (1343)" list=\
ResidentialAdvanced
add address=100.64.0.5 comment="Amber Krings (1273)" list=ResidentialAdvanced
add address=100.64.0.4 comment="Cherie Eshelman (1153)" list=\
ResidentialAdvanced
add address=100.64.0.61 comment="Rachel Fuller (286)" list=\
ResidentialAdvanced
add address=100.64.0.25 comment="Maria Trejo (2284)" list=ResidentialAdvanced
add address=100.64.0.7 comment="Carla Kimberling (1959)" list=\
ResidentialAdvanced
add address=100.64.0.33 comment="Carmen Lopez (2409)" list=\
ResidentialAdvanced
add address=100.64.0.51 comment="Kimberly Richards (1726)" list=\
ResidentialAdvanced
add address=100.64.0.21 comment="Jacqueline Wilder (892)" list=\
ResidentialAdvanced
add address=100.64.0.3 comment="Derek Rodriguez (2402)" list=\
ResidentialAdvanced
add address=100.64.0.52 comment="Jonny Taylor (190)" list=ResidentialAdvanced
add address=204.110.188.236 comment="Deja Dodson (2320)" list=\
ResidentialAdvanced
add address=10.10.0.6 comment="Pablo Hernandez (2083)" list=\
ResidentialAdvanced
add address=10.10.0.49 comment="Cherie Eshelman (1153)" list=\
ResidentialAdvanced
add address=10.10.0.54 comment="Jennifer Little (1343)" list=\
ResidentialAdvanced
add address=10.10.0.58 comment="Rebekah Moore (386)" list=ResidentialAdvanced
add address=10.10.0.70 comment="Vance Peltonen (356)" list=\
ResidentialAdvanced
add address=10.10.0.62 comment="Carla Kimberling (1959)" list=\
ResidentialAdvanced
add address=10.10.0.25 comment="Yolanda Medrano (2461)" list=\
ResidentialAdvanced
add address=10.10.0.15 comment="Maria Trejo (2284)" list=ResidentialAdvanced
add address=10.10.0.69 comment="Rachel Fuller (286)" list=ResidentialAdvanced
add address=10.10.0.73 comment="Carmen Lopez (2409)" list=ResidentialAdvanced
add address=10.10.0.68 comment="Amber Krings (1273)" list=ResidentialAdvanced
add address=10.10.0.91 comment="Anthony Schmoker (1577)" list=\
ResidentialAdvanced
add address=204.110.188.226 comment="James Genneken (160)" list=Inactive
add address=204.110.188.227 comment="Mike Villa (269)" list=Inactive
add address=204.110.188.232 comment="Tammy Kinser (738)" list=Inactive
add address=204.110.188.234 comment="Sonya McTee (324)" list=Inactive
add address=100.64.0.23 comment="Ryan McTee (306)" list=Inactive
add address=10.10.0.91 comment="Anthony Schmoker (1577)" list=Inactive
add address=100.64.0.60 comment="Allen Taylor (26)" list=BusinessUltra
add address=204.110.188.230 comment="Kirk Vanmeter (216)" list=BusinessUltra
add address=10.10.0.64 comment="Allen Taylor (26)" list=BusinessUltra
add address=100.64.0.12 comment="Penney Warner (70)" list=\
ResidentialBasic6months
add address=100.64.0.40 comment="Chrissy Eagle (74)" list=\
ResidentialBasic6months
add address=100.64.0.41 comment="Keith Crank (209)" list=\
ResidentialBasic6months
add address=100.64.0.36 comment="Mary Hopper (245)" list=\
ResidentialBasic6months
add address=100.64.0.32 comment="Michael Talbot (262)" list=\
ResidentialBasic6months
add address=100.64.0.27 comment="Whitey White (303)" list=\
ResidentialBasic6months
add address=100.64.0.1 comment="Sherrye Richardson (321)" list=\
ResidentialBasic6months
add address=10.10.0.75 comment="Mary Hopper (245)" list=\
ResidentialBasic6months
add address=100.64.0.26 comment="Sri Reddy (514)" list=ResidentialCore
add address=204.110.188.225 comment="Graham McIntire (1)" list=Active
add address=204.110.188.230 comment="Kirk Vanmeter (216)" list=Active
add address=204.110.188.233 comment="Joey Whitfield (187)" list=Active
add address=204.110.188.229 comment="Vance Peltonen (356)" list=Active
add address=204.110.188.231 comment="James Hardin (1475)" list=Active
add address=100.64.0.53 comment="William Armstrong (362)" list=Active
add address=204.110.188.235 comment="Austin Watkins (769)" list=Active
add address=100.64.0.48 comment="Pablo Hernandez (2083)" list=Active
add address=204.110.188.237 comment="Ron Lewis (302)" list=Active
add address=100.64.0.8 comment="Alma Acosta (28)" list=Active
add address=100.64.0.41 comment="Keith Crank (209)" list=Active
add address=100.64.0.39 comment="Dana Nance (89)" list=Active
add address=100.64.0.36 comment="Mary Hopper (245)" list=Active
add address=100.64.0.32 comment="Michael Talbot (262)" list=Active
add address=100.64.0.31 comment="Scott Armstrong (315)" list=Active
add address=100.64.0.30 comment="Chand Parvathaneni (2396)" list=Active
add address=100.64.0.29 comment="Beverly Erwin (48)" list=Active
add address=100.64.0.28 comment="Mark Fisher (242)" list=Active
add address=100.64.0.20 comment="Pam Banschbach (383)" list=Active
add address=100.64.0.18 comment="Karen Stewart (2050)" list=Active
add address=100.64.0.17 comment="Nathan McTee (273)" list=Active
add address=100.64.0.16 comment="Doug Stowe (1807)" list=Active
add address=100.64.0.13 comment="CLAY GILBERT (1839)" list=Active
add address=100.64.0.12 comment="Penney Warner (70)" list=Active
add address=100.64.0.2 comment="JoleneDon Nance (118)" list=Active
add address=100.64.0.44 comment="Brad Sherry Slate (1334)" list=Active
add address=100.64.0.45 comment="Debra Vega (112)" list=Active
add address=100.64.0.47 comment="Eric Barrett (2386)" list=Active
add address=100.64.0.49 comment="David Lanman (2486)" list=Active
add address=100.64.0.26 comment="Sri Reddy (514)" list=Active
add address=100.64.0.50 comment="Steven Spurgers (1211)" list=Active
add address=100.64.0.37 comment="Rebekah Moore (386)" list=Active
add address=100.64.0.14 comment="Teresa Robinson (376)" list=Active
add address=100.64.0.69 comment="Yolanda Medrano (2461)" list=Active
add address=100.64.0.6 comment="Jennifer Little (1343)" list=Active
add address=100.64.0.5 comment="Amber Krings (1273)" list=Active
add address=100.64.0.4 comment="Cherie Eshelman (1153)" list=Active
add address=100.64.0.61 comment="Rachel Fuller (286)" list=Active
add address=100.64.0.25 comment="Maria Trejo (2284)" list=Active
add address=100.64.0.7 comment="Carla Kimberling (1959)" list=Active
add address=100.64.0.60 comment="Allen Taylor (26)" list=Active
add address=100.64.0.33 comment="Carmen Lopez (2409)" list=Active
add address=100.64.0.46 comment="Chrissy Eagle 2 (1530)" list=Active
add address=100.64.0.22 comment="Steve Christiaens (329)" list=Active
add address=100.64.0.1 comment="Sherrye Richardson (321)" list=Active
add address=100.64.0.51 comment="Kimberly Richards (1726)" list=Active
add address=100.64.0.21 comment="Jacqueline Wilder (892)" list=Active
add address=100.64.0.38 comment="Brad Wilson (1491)" list=Active
add address=100.64.0.3 comment="Derek Rodriguez (2402)" list=Active
add address=100.64.0.27 comment="Whitey White (303)" list=Active
add address=100.64.0.9 comment="Krysta Bates (218)" list=Active
add address=100.64.0.52 comment="Jonny Taylor (190)" list=Active
add address=100.64.0.40 comment="Chrissy Eagle (74)" list=Active
add address=204.110.188.236 comment="Deja Dodson (2320)" list=Active
add address=100.64.0.19 comment="TJ Banschbach (1676)" list=Active
add address=10.10.0.63 comment="Alicia Torres (1938)" list=Active
add address=10.10.0.6 comment="Pablo Hernandez (2083)" list=Active
add address=10.10.0.49 comment="Cherie Eshelman (1153)" list=Active
add address=10.10.0.59 comment="Teresa Robinson (376)" list=Active
add address=10.10.0.47 comment="Alma Acosta (28)" list=Active
add address=10.10.0.17 comment="Judy Devine (277)" list=Active
add address=10.10.0.75 comment="Mary Hopper (245)" list=Active
add address=10.10.0.54 comment="Jennifer Little (1343)" list=Active
add address=10.10.0.58 comment="Rebekah Moore (386)" list=Active
add address=10.10.0.70 comment="Vance Peltonen (356)" list=Active
add address=10.10.0.62 comment="Carla Kimberling (1959)" list=Active
add address=10.10.0.25 comment="Yolanda Medrano (2461)" list=Active
add address=10.10.0.15 comment="Maria Trejo (2284)" list=Active
add address=10.10.0.69 comment="Rachel Fuller (286)" list=Active
add address=10.10.0.73 comment="Carmen Lopez (2409)" list=Active
add address=10.10.0.68 comment="Amber Krings (1273)" list=Active
add address=10.10.0.24 comment="Scott Armstrong (315)" list=Active
add address=10.10.0.64 comment="Allen Taylor (26)" list=Active
add address=100.64.0.62 comment="James Hardin (1475)" list=Active
add address=100.64.0.34 comment="America Trejo (1693)" list=\
ResidentialAdvanced
add address=100.64.0.34 comment="America Trejo (1693)" list=Active
add address=100.64.0.15 comment="Bill McTee (373)" list=Active
add address=100.64.0.35 comment="Judy Devine (277)" list=ResidentialBasic
add address=100.64.0.35 comment="Judy Devine (277)" list=Active
/ip firewall filter
add action=accept chain=forward in-interface=zerotier1
add action=accept chain=input in-interface=zerotier1
add action=passthrough chain=unused-hs-chain comment=\
"place hotspot rules here" disabled=yes
add action=fasttrack-connection chain=forward comment=\
"fasttrack established/related" connection-state=established,related \
hw-offload=yes
add action=accept chain=forward comment="accept established/related" \
connection-state=established,related
add action=fasttrack-connection chain=forward connection-state=\
established,related hw-offload=yes
add action=fasttrack-connection chain=forward connection-state=new \
hw-offload=yes
/ip firewall nat
add action=passthrough chain=unused-hs-chain comment=\
"place hotspot rules here" disabled=yes
/ip hotspot ip-binding
add address=10.250.1.146 type=bypassed
add mac-address=48:A9:8A:9D:9B:8A type=bypassed
add address=204.110.188.224/27 type=bypassed
add address=100.64.0.70 disabled=yes mac-address=5C:62:8B:10:0D:5F server=\
hotspot1 to-address=100.64.0.70 type=bypassed
add address=0.0.0.0/0 disabled=yes
add address=100.64.0.0/22
add address=204.110.188.0/22
add address=100.64.0.70 comment="test router" disabled=yes mac-address=\
5C:62:8B:10:0D:5F server=hotspot1 to-address=100.64.0.70 type=bypassed
add address=0.0.0.0/0 type=blocked
/ip hotspot walled-garden
add dst-host=use1-tauc-mqtt-broker.tplinkcloud.com server=hotspot1
add dst-host=*tplinknbu.com server=hotspot1
add dst-host=*tplinkcloud.com server=hotspot1
add dst-host=*tp-link.com server=hotspot1
add dst-host=vntx.unmsapp.com server=hotspot1
add dst-port=123
add dst-port=8883
add comment="place hotspot rules here" disabled=yes
/ip hotspot walled-garden ip
add action=accept disabled=no dst-address=204.110.191.240 !dst-address-list \
!dst-port !protocol !src-address !src-address-list
add action=accept disabled=no dst-address=204.110.191.250 !dst-address-list \
!dst-port !protocol !src-address !src-address-list
add action=accept disabled=no !dst-address !dst-address-list dst-port=8883 \
protocol=tcp !src-address !src-address-list
/ip ipsec profile
set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5
/ip proxy
set enabled=yes port=23435
/ip proxy access
add src-address=204.110.188.0/22
add src-address=10.0.0.0/8
add src-address=100.64.0.0/10
add action=deny src-address=0.0.0.0/0
/ip route
add disabled=no dst-address=0.0.0.0/0 gateway=10.250.1.30
add disabled=no dst-address=10.43.0.0/16 gateway=204.110.191.1
add disabled=no dst-address=10.0.16.1/32 gateway=204.110.188.225
add disabled=no dst-address=10.0.16.10/32 gateway=204.110.188.225
add disabled=no dst-address=10.0.16.84/32 gateway=204.110.188.225
/ip service
set ftp address=204.110.188.0/22,10.0.0.0/8 disabled=yes
set telnet address=204.110.188.0/22,10.0.0.0/8 disabled=yes
set www address=204.110.188.0/22,10.0.0.0/8 disabled=yes
set www-ssl address=204.110.188.0/22,10.0.0.0/8
set ssh address=204.110.188.0/22,10.0.0.0/8 port=1022
set api address=204.110.188.0/22,10.0.0.0/8,100.64.0.0/10
set api-ssl certificate=myCa
/ip smb shares
set [ find default=yes ] directory=/pub
/ip ssh
set always-allow-password-login=yes host-key-type=ed25519 strong-crypto=yes
/ipv6 address
add address=2606:1c80:0:1010::2 interface=ether3-climax-11ghz
/ipv6 nd
add interface=verona managed-address-configuration=yes other-configuration=\
yes
/ipv6 nd prefix
add autonomous=no interface=verona
/mpls interface
add disabled=no interface=ether3-climax-11ghz mpls-mtu=1500
add interface=ether4-verona-tower mpls-mtu=1500
add interface=ether6-switch mpls-mtu=1500
add interface=ether7 mpls-mtu=1500
add interface=ether8 mpls-mtu=1500
add interface=ether9 mpls-mtu=1500
add interface=ether11 mpls-mtu=1500
add interface=ether12 mpls-mtu=1500
add interface=ether13 mpls-mtu=1500
add interface=ether14 mpls-mtu=1500
add interface=ether15_wave_n mpls-mtu=1500
add interface=ether16 mpls-mtu=1500
add interface=sfp-sfpplus1-verona-tower-switch mpls-mtu=1500
add interface=sfp-sfpplus2-switch mpls-mtu=1500
/mpls ldp
add afi=ip,ipv6 disabled=no loop-detect=yes lsr-id=10.254.254.101 \
transport-addresses=10.254.254.101 vrf=main
/mpls ldp advertise-filter
add advertise=yes disabled=yes prefix=10.10.0.0/20 vrf=main
add advertise=yes disabled=yes prefix=204.110.188.224/27 vrf=main
/mpls ldp interface
add accept-dynamic-neighbors=yes afi=ip disabled=no interface=\
ether3-climax-11ghz transport-addresses=10.254.254.101
add interface=ether4-verona-tower transport-addresses=10.254.254.101
add interface=ether6-switch transport-addresses=10.254.254.101
add interface=ether7 transport-addresses=10.254.254.101
add interface=ether8 transport-addresses=10.254.254.101
add interface=ether9 transport-addresses=10.254.254.101
add interface=ether11 transport-addresses=10.254.254.101
add interface=ether12 transport-addresses=10.254.254.101
add interface=ether13 transport-addresses=10.254.254.101
add interface=ether14 transport-addresses=10.254.254.101
add interface=ether15_wave_n transport-addresses=10.254.254.101
add interface=ether16 transport-addresses=10.254.254.101
add interface=sfp-sfpplus1-verona-tower-switch transport-addresses=\
10.254.254.101
add interface=sfp-sfpplus2-switch transport-addresses=10.254.254.101
/ppp aaa
set interim-update=15m use-radius=yes
/radius
add address=204.110.191.248 require-message-auth=no service=ppp,hotspot,dhcp \
src-address=204.110.188.254 timeout=3s
add accounting-backup=yes address=104.238.144.172 disabled=yes \
require-message-auth=no service=ppp,hotspot,dhcp src-address=\
204.110.188.254 timeout=3s
add address=204.110.191.2 disabled=yes require-message-auth=no service=\
ppp,hotspot,dhcp src-address=204.110.188.254 timeout=3s
/radius incoming
set accept=yes
/routing bfd configuration
add disabled=no interfaces=all min-rx=200ms min-tx=200ms multiplier=5
/routing filter rule
add chain=ospf-in disabled=no rule="accept;"
add chain=ospf-out disabled=no rule="accept;"
/routing ospf interface-template
add area=backbone-v2 auth=sha512 auth-id=1 cost=10 disabled=no interfaces=\
ether3-climax-11ghz priority=1 type=ptp use-bfd=no
add area=backbone-v3 cost=10 disabled=no passive use-bfd=no
add area=backbone-v2 disabled=no passive
/routing ospf static-neighbor
add address=10.250.1.30%ether3-climax-11ghz area=backbone-v2 disabled=no \
poll-interval=10s
/routing rip interface-template
add disabled=no instance=rip-instance-1 interfaces=ether3-climax-11ghz
/snmp
set contact="Graham McIntire" enabled=yes location=Verona
/system clock
set time-zone-name=America/Chicago
/system identity
set name=Verona
/system logging
add action=remote topics=info
add disabled=yes topics=ospf
add action=disk prefix=gtemp topics=firewall
/system note
set show-at-login=no
/system ntp client
set enabled=yes
/system ntp client servers
add address=ntp.vntx.net
add address=0.us.pool.ntp.org
/system package update
set channel=long-term
/system routerboard settings
set auto-upgrade=yes enter-setup-on=delete-key
/system scheduler
add name=reboot on-event="/system reboot" policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
start-date=2025-02-16 start-time=03:00:00
add interval=1d name=upgrade policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
start-date=2024-02-22 start-time=03:30:00
/system script
add dont-require-permissions=no name=upgrade owner=graham policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="#\
\_Script name: BackupAndUpdate\r\
\n#\r\
\n#----------SCRIPT INFORMATION-------------------------------------------\
--------\r\
\n#\r\
\n# Script: Mikrotik RouterOS automatic backup & update\r\
\n# Version: 23.11.25\r\
\n# Created: 07/08/2018\r\
\n# Updated: 25/11/2023\r\
\n# Author: Alexander Tebiev\r\
\n# Website: https://github.com/beeyev\r\
\n# You can contact me by e-mail at tebiev@mail.com\r\
\n#\r\
\n# IMPORTANT!\r\
\n# Minimum supported RouterOS version is v6.43.7\r\
\n#\r\
\n#----------MODIFY THIS SECTION AS NEEDED--------------------------------\
--------\r\
\n## Notification e-mail\r\
\n## (Make sure you have configurated Email settings in Tools -> Email)\r\
\n:local emailAddress \"graham@vntx.net\";\r\
\n\r\
\n## Script mode, possible values: backup, osupdate, osnotify.\r\
\n# backup - Only backup will be performed. (default value, if none p\
rovided)\r\
\n#\r\
\n# osupdate - The script will install a new RouterOS version if it is \
available.\r\
\n# It will also create backups before and after update proc\
ess (it does not matter what value `forceBackup` is set to)\r\
\n# Email will be sent only if a new RouterOS version is ava\
ilable.\r\
\n# Change parameter `forceBackup` if you need the script to\
\_create backups every time when it runs (even when no updates were found)\
.\r\
\n#\r\
\n# osnotify - The script will send email notifications only (without b\
ackups) if a new RouterOS update is available.\r\
\n# Change parameter `forceBackup` if you need the script to\
\_create backups every time when it runs.\r\
\n:local scriptMode \"osupdate\";\r\
\n\r\
\n## Additional parameter if you set `scriptMode` to `osupdate` or `osnoti\
fy`\r\
\n# Set `true` if you want the script to perform backup every time it's fi\
red, whatever script mode is set.\r\
\n:local forceBackup false;\r\
\n\r\
\n## Backup encryption password, no encryption if no password.\r\
\n:local backupPassword \"\"\r\
\n\r\
\n## If true, passwords will be included in exported config.\r\
\n:local sensitiveDataInConfig true;\r\
\n\r\
\n## Update channel. Possible values: stable, long-term, testing, developm\
ent\r\
\n:local updateChannel \"stable\";\r\
\n\r\
\n## Install only patch versions of RouterOS updates.\r\
\n## Works only if you set scriptMode to \"osupdate\"\r\
\n## Means that new update will be installed only if MAJOR and MINOR versi\
on numbers remained the same as currently installed RouterOS.\r\
\n## Example: v6.43.6 => major.minor.PATCH\r\
\n## Script will send information if new version is greater than just patc\
h.\r\
\n:local installOnlyPatchUpdates false;\r\
\n\r\
\n## If true, device public IP address information will be included into t\
he email message\r\
\n:local detectPublicIpAddress true;\r\
\n\r\
\n## Allow anonymous statistics collection. (script mode, device model, OS\
\_version)\r\
\n:local allowAnonymousStatisticsCollection true;\r\
\n\r\
\n##----------------------------------------------------------------------\
--------------------##\r\
\n# !!!! DO NOT CHANGE ANYTHING BELOW THIS LINE, IF YOU ARE NOT SURE WHAT\
\_YOU ARE DOING !!!! #\r\
\n##----------------------------------------------------------------------\
--------------------##\r\
\n\r\
\n#Script messages prefix\r\
\n:local SMP \"Bkp&Upd:\"\r\
\n\r\
\n:log info \"\\r\\n\$SMP script \\\"Mikrotik RouterOS automatic backup & \
update\\\" started.\";\r\
\n:log info \"\$SMP Script Mode: \$scriptMode, forceBackup: \$forceBackup\
\";\r\
\n\r\
\n# Check email settings\r\
\n:if ([:len \$emailAddress] = 0) do={\r\
\n :log error (\"\$SMP \\\$emailAddress variable is empty. Script stopp\
ed.\");\r\
\n :error \"\$SMP bye!\";\r\
\n}\r\
\n:local emailServer \"\"\r\
\n:do {\r\
\n :set emailServer [/tool e-mail get server];\r\
\n} on-error={\r\
\n # Old of getting email server before the RouterOS v7.12\r\
\n :log info \"\$SMP Checking email server using old command `/tool e-m\
ail get address`\";\r\
\n :set emailServer [/tool e-mail get address];\r\
\n}\r\
\n:if (\$emailServer = \"0.0.0.0\") do={\r\
\n :log error (\"\$SMP Email server address is not correct, please chec\
k Tools -> Email. Script stopped.\");\r\
\n :error \"\$SMP bye!\";\r\
\n}\r\
\n:if ([:len [/tool e-mail get from]] = 0 or [/tool e-mail get from] = \"<\
>\") do={\r\
\n :log error (\"\$SMP Email configuration FROM address is not correct,\
\_please check Tools -> Email. Script stopped.\");\r\
\n :error \"\$SMP bye!\";\r\
\n}\r\
\n\r\
\n\r\
\n#Check if proper identity name is set\r\
\nif ([:len [/system identity get name]] = 0 or [/system identity get name\
] = \"MikroTik\") do={\r\
\n :log warning (\"\$SMP Please set identity name of your device (Syste\
m -> Identity), keep it short and informative.\");\r\
\n};\r\
\n\r\
\n############### vvvvvvvvv GLOBALS vvvvvvvvv ###############\r\
\n# Function converts standard mikrotik build versions to the number.\r\
\n# Possible arguments: paramOsVer\r\
\n# Example:\r\
\n# :put [\$buGlobalFuncGetOsVerNum paramOsVer=[/system routerboard get cu\
rrent-RouterOS]];\r\
\n# Result will be: 64301, because current RouterOS version is: 6.43.1\r\
\n:global buGlobalFuncGetOsVerNum do={\r\
\n :local osVer \$paramOsVer;\r\
\n :local osVerNum;\r\
\n :local osVerMicroPart;\r\
\n :local zro 0;\r\
\n :local tmp;\r\
\n\r\
\n # Replace word `beta` with dot\r\
\n :local isBetaPos [:tonum [:find \$osVer \"beta\" 0]];\r\
\n :if (\$isBetaPos > 1) do={\r\
\n :set osVer ([:pick \$osVer 0 \$isBetaPos] . \".\" . [:pick \$osV\
er (\$isBetaPos + 4) [:len \$osVer]]);\r\
\n }\r\
\n # Replace word `rc` with dot\r\
\n :local isRcPos [:tonum [:find \$osVer \"rc\" 0]];\r\
\n :if (\$isRcPos > 1) do={\r\
\n :set osVer ([:pick \$osVer 0 \$isRcPos] . \".\" . [:pick \$osVer\
\_(\$isRcPos + 2) [:len \$osVer]]);\r\
\n }\r\
\n\r\
\n :local dotPos1 [:find \$osVer \".\" 0];\r\
\n\r\
\n :if (\$dotPos1 > 0) do={\r\
\n\r\
\n # AA\r\
\n :set osVerNum [:pick \$osVer 0 \$dotPos1];\r\
\n\r\
\n :local dotPos2 [:find \$osVer \".\" \$dotPos1];\r\
\n #Taking minor version, everything after first dot\r\
\n :if ([:len \$dotPos2] = 0) do={:set tmp [:pick \$osVer (\$dotPos\
1+1) [:len \$osVer]];}\r\
\n #Taking minor version, everything between first and second dots\
\r\
\n :if (\$dotPos2 > 0) do={:set tmp [:pick \$osVer (\$dotPos1+1) \$\
dotPos2];}\r\
\n\r\
\n # AA 0B\r\
\n :if ([:len \$tmp] = 1) do={:set osVerNum \"\$osVerNum\$zro\$tmp\
\";}\r\
\n # AA BB\r\
\n :if ([:len \$tmp] = 2) do={:set osVerNum \"\$osVerNum\$tmp\";}\r\
\n\r\
\n :if (\$dotPos2 > 0) do={\r\
\n :set tmp [:pick \$osVer (\$dotPos2+1) [:len \$osVer]];\r\
\n # AA BB 0C\r\
\n :if ([:len \$tmp] = 1) do={:set osVerNum \"\$osVerNum\$zro\$\
tmp\";}\r\
\n # AA BB CC\r\
\n :if ([:len \$tmp] = 2) do={:set osVerNum \"\$osVerNum\$tmp\"\
;}\r\
\n } else={\r\
\n # AA BB 00\r\
\n :set osVerNum \"\$osVerNum\$zro\$zro\";\r\
\n }\r\
\n } else={\r\
\n # AA 00 00\r\
\n :set osVerNum \"\$osVer\$zro\$zro\$zro\$zro\";\r\
\n }\r\
\n\r\
\n :return \$osVerNum;\r\
\n}\r\
\n\r\
\n\r\
\n# Function creates backups (system and config) and returns array with na\
mes\r\
\n# Possible arguments:\r\
\n# `backupName` | string | backup file name, without \
extension!\r\
\n# `backupPassword` | string |\r\
\n# `sensitiveDataInConfig` | boolean |\r\
\n# Example:\r\
\n# :put [\$buGlobalFuncCreateBackups name=\"daily-backup\"];\r\
\n:global buGlobalFuncCreateBackups do={\r\
\n :log info (\"\$SMP Global function \\\"buGlobalFuncCreateBackups\\\"\
\_was fired.\");\r\
\n\r\
\n :local backupFileSys \"\$backupName.backup\";\r\
\n :local backupFileConfig \"\$backupName.rsc\";\r\
\n :local backupNames {\$backupFileSys;\$backupFileConfig};\r\
\n\r\
\n ## Make system backup\r\
\n :if ([:len \$backupPassword] = 0) do={\r\
\n /system backup save dont-encrypt=yes name=\$backupName;\r\
\n } else={\r\
\n /system backup save password=\$backupPassword name=\$backupName;\
\r\
\n }\r\
\n :log info (\"\$SMP System backup created. \$backupFileSys\");\r\
\n\r\
\n ## Export config file\r\
\n :if (\$sensitiveDataInConfig = true) do={\r\
\n # Since RouterOS v7 it needs to be explicitly set that we want t\
o export sensitive data\r\
\n :if ([:pick [/system package update get installed-version] 0 1] \
< 7) do={\r\
\n :execute \"/export compact terse file=\$backupName\";\r\
\n } else={\r\
\n :execute \"/export compact show-sensitive terse file=\$backu\
pName\";\r\
\n }\r\
\n } else={\r\
\n /export compact hide-sensitive terse file=\$backupName;\r\
\n }\r\
\n :log info (\"\$SMP Config file was exported. \$backupFileConfig, the\
\_script execution will be paused for a moment.\");\r\
\n\r\
\n #Delay after creating backups\r\
\n :delay 20s;\r\
\n :return \$backupNames;\r\
\n}\r\
\n\r\
\n:global buGlobalVarUpdateStep;\r\
\n############### ^^^^^^^^^ GLOBALS ^^^^^^^^^ ###############\r\
\n\r\
\n:local scriptVersion \"23.11.25\";\r\
\n\r\
\n# Current time `hh-mm-ss`\r\
\n:local currentTime ([:pick [/system clock get time] 0 2] . \"-\" . [:pic\
k [/system clock get time] 3 5] . \"-\" . [:pick [/system clock get time] \
6 8]);\r\
\n\r\
\n:local currentDateTime (\"-\" . \$currentTime);\r\
\n\r\
\n# Detect old date format, Example: `nov/11/2023`\r\
\n:if ([:len [:tonum [:pick [/system clock get date] 0 1]]] = 0) do={\r\
\n :set currentDateTime ([:pick [/system clock get date] 7 11] . [:pick\
\_[/system clock get date] 0 3] . [:pick [/system clock get date] 4 6] . \
\"-\" . \$currentTime);\r\
\n} else={\r\
\n # New date format, Example: `2023-11-11`\r\
\n :set currentDateTime ([/system clock get date] . \"-\" . \$currentTi\
me);\r\
\n};\r\
\n\r\
\n:local isSoftBased false;\r\
\n:if ([/system resource get board-name] = \"CHR\" or [/system resource ge\
t board-name] = \"x86\") do={\r\
\n :set isSoftBased true;\r\
\n};\r\
\n\r\
\n:local deviceOsVerInst [/system package update get installed-ve\
rsion];\r\
\n:local deviceOsVerInstNum [\$buGlobalFuncGetOsVerNum paramOsVer=\$\
deviceOsVerInst];\r\
\n:local deviceOsVerAvail \"\";\r\
\n:local deviceOsVerAvailNum 0;\r\
\n:local deviceIdentityName [/system identity get name];\r\
\n:local deviceIdentityNameShort [:pick \$deviceIdentityName 0 18]\r\
\n:local deviceUpdateChannel [/system package update get channel];\r\
\n\r\
\n\r\
\n:local deviceRbModel \"CloudHostedRouter\";\r\
\n:local deviceRbSerialNumber \"--\";\r\
\n:local deviceRbCurrentFw \"--\";\r\
\n:local deviceRbUpgradeFw \"--\";\r\
\n\r\
\n:if (\$isSoftBased = false) do={\r\
\n :set deviceRbModel [/system routerboard get model];\r\
\n :set deviceRbSerialNumber [/system routerboard get serial-number];\
\r\
\n :set deviceRbCurrentFw [/system routerboard get current-firmwar\
e];\r\
\n :set deviceRbUpgradeFw [/system routerboard get upgrade-firmwar\
e];\r\
\n};\r\
\n\r\
\n:local isOsUpdateAvailable false;\r\
\n:local isOsNeedsToBeUpdated false;\r\
\n\r\
\n:local isSendEmailRequired true;\r\
\n\r\
\n:local mailSubject \"\$SMP Device - \$deviceIdentityNameShort.\";\r\
\n:local mailBody \"\";\r\
\n\r\
\n:local mailBodyDeviceInfo \"\\r\\n\\r\\nDevice information: \\r\\nIden\
tity: \$deviceIdentityName \\r\\nModel: \$deviceRbModel \\r\\nSerial numbe\
r: \$deviceRbSerialNumber \\r\\nCurrent RouterOS: \$deviceOsVerInst (\$[/s\
ystem package update get channel]) \$[/system resource get build-time] \\r\
\\nCurrent routerboard FW: \$deviceRbCurrentFw \\r\\nDevice uptime: \$[/sy\
stem resource get uptime]\";\r\
\n:local mailBodyCopyright \"\\r\\n\\r\\nMikrotik RouterOS automatic ba\
ckup & update (ver. \$scriptVersion) \\r\\nhttps://github.com/beeyev/Mikro\
tik-RouterOS-automatic-backup-and-update\";\r\
\n:local changelogUrl (\"Check RouterOS changelog: https://mikroti\
k.com/download/changelogs/\" . \$updateChannel . \"-release-tree\");\r\
\n\r\
\n:local backupName \"v\$deviceOsVerInst_\$deviceUpdateChannel_\
\$currentDateTime\";\r\
\n:local backupNameBeforeUpd \"backup_before_update_\$backupName\";\r\
\n:local backupNameAfterUpd \"backup_after_update_\$backupName\";\r\
\n\r\
\n:local backupNameFinal \$backupName;\r\
\n:local mailAttachments [:toarray \"\"];\r\
\n\r\
\n\r\
\n:local ipAddressDetectServiceDefault \"https://ipv4.mikrotik.ovh/\"\r\
\n:local ipAddressDetectServiceFallback \"https://api.ipify.org/\"\r\
\n:local publicIpAddress \"not detected\";\r\
\n:local telemetryDataQuery \"\";\r\
\n\r\
\n:local updateStep \$buGlobalVarUpdateStep;\r\
\n:do {/system script environment remove buGlobalVarUpdateStep;} on-error=\
{}\r\
\n:if ([:len \$updateStep] = 0) do={\r\
\n :set updateStep 1;\r\
\n}\r\
\n\r\
\n## IP address detection & anonymous statistics collection\r\
\n:if (\$updateStep = 1 or \$updateStep = 3) do={\r\
\n :if (\$updateStep = 3) do={\r\
\n :log info (\"\$SMP Waiting for one minute before continuing to t\
he final step.\");\r\
\n :delay 1m;\r\
\n }\r\
\n\r\
\n :if (\$detectPublicIpAddress = true or \$allowAnonymousStatisticsCol\
lection = true) do={\r\
\n :if (\$allowAnonymousStatisticsCollection = true) do={\r\
\n :set telemetryDataQuery (\"\\\?mode=\" . \$scriptMode . \"&o\
sver=\" . \$deviceOsVerInst . \"&model=\" . \$deviceRbModel);\r\
\n }\r\
\n\r\
\n :do {:set publicIpAddress ([/tool fetch http-method=\"get\" url=\
(\$ipAddressDetectServiceDefault . \$telemetryDataQuery) output=user as-va\
lue]->\"data\");} on-error={\r\
\n\r\
\n :if (\$detectPublicIpAddress = true) do={\r\
\n :log warning \"\$SMP Could not detect public IP address \
using default detection service.\"\r\
\n :log warning \"\$SMP Trying to detect public ip using fa\
llback detection service.\"\r\
\n\r\
\n :do {:set publicIpAddress ([/tool fetch http-method=\"ge\
t\" url=\$ipAddressDetectServiceFallback output=user as-value]->\"data\");\
} on-error={\r\
\n :log warning \"\$SMP Could not detect public IP addr\
ess using fallback detection service.\"\r\
\n }\r\
\n }\r\
\n }\r\
\n\r\
\n :if (\$detectPublicIpAddress = true) do={\r\
\n # Always truncate the string for safety measures\r\
\n :set publicIpAddress ([:pick \$publicIpAddress 0 15])\r\
\n :set mailBodyDeviceInfo (\$mailBodyDeviceInfo . \"\\r\\nPubl\
ic IP address: \" . \$publicIpAddress);\r\
\n }\r\
\n }\r\
\n}\r\
\n\r\
\n\r\
\n## STEP ONE: Creating backups, checking for new RouterOs version and sen\
ding email with backups,\r\
\n## Steps 2 and 3 are fired only if script is set to automatically update\
\_device and if a new RouterOs version is available.\r\
\n:if (\$updateStep = 1) do={\r\
\n :log info (\"\$SMP Performing the first step.\");\r\
\n\r\
\n # Checking for new RouterOS version\r\
\n if (\$scriptMode = \"osupdate\" or \$scriptMode = \"osnotify\") do={\
\r\
\n log info (\"\$SMP Checking for new RouterOS version. Current ver\
sion is: \$deviceOsVerInst\");\r\
\n /system package update set channel=\$updateChannel;\r\
\n /system package update check-for-updates;\r\
\n :delay 5s;\r\
\n :set deviceOsVerAvail [/system package update get latest-version\
];\r\
\n\r\
\n # If there is a problem getting information about available Rout\
erOS versions from server\r\
\n :if ([:len \$deviceOsVerAvail] = 0) do={\r\
\n :log warning (\"\$SMP There is a problem getting information\
\_about new RouterOS from server.\");\r\
\n :set mailSubject (\$mailSubject . \" Error: No data about\
\_new RouterOS!\")\r\
\n :set mailBody (\$mailBody . \"Error occured! \\r\\nM\
ikrotik couldn't get any information about new RouterOS from server! \\r\\\
nWatch additional information in device logs.\")\r\
\n } else={\r\
\n #Get numeric version of OS\r\
\n :set deviceOsVerAvailNum [\$buGlobalFuncGetOsVerNum paramOsV\
er=\$deviceOsVerAvail];\r\
\n\r\
\n # Checking if OS on server is greater than installed one.\r\
\n :if (\$deviceOsVerAvailNum > \$deviceOsVerInstNum) do={\r\
\n :set isOsUpdateAvailable true;\r\
\n :log info (\"\$SMP New RouterOS is available! \$deviceOs\
VerAvail\");\r\
\n } else={\r\
\n :set isSendEmailRequired false;\r\
\n :log info (\"\$SMP System is already up to date.\");\r\
\n :set mailSubject (\$mailSubject . \" No new OS updates.\
\");\r\
\n :set mailBody (\$mailBody . \"Your system is up to \
date.\");\r\
\n }\r\
\n };\r\
\n } else={\r\
\n :set scriptMode \"backup\";\r\
\n };\r\
\n\r\
\n if (\$forceBackup = true) do={\r\
\n # In this case the script will always send email, because it has\
\_to create backups\r\
\n :set isSendEmailRequired true;\r\
\n }\r\
\n\r\
\n # If a new OS version is available to install\r\
\n if (\$isOsUpdateAvailable = true and \$isSendEmailRequired = true) d\
o={\r\
\n # If we only need to notify about a new available version\r\
\n if (\$scriptMode = \"osnotify\") do={\r\
\n :set mailSubject (\$mailSubject . \" New RouterOS is avai\
lable! v.\$deviceOsVerAvail.\")\r\
\n :set mailBody (\$mailBody . \"New RouterOS version is \
available to install: v.\$deviceOsVerAvail (\$updateChannel) \\r\\n\$chang\
elogUrl\")\r\
\n }\r\
\n\r\
\n # If we need to initiate RouterOS update process\r\
\n if (\$scriptMode = \"osupdate\") do={\r\
\n :set isOsNeedsToBeUpdated true;\r\
\n # If we need to install only patch updates\r\
\n :if (\$installOnlyPatchUpdates = true) do={\r\
\n #Check if Major and Minor builds are the same.\r\
\n :if ([:pick \$deviceOsVerInstNum 0 ([:len \$deviceOsVerI\
nstNum]-2)] = [:pick \$deviceOsVerAvailNum 0 ([:len \$deviceOsVerAvailNum]\
-2)]) do={\r\
\n :log info (\"\$SMP New patch version of RouterOS fir\
mware is available.\");\r\
\n } else={\r\
\n :log info (\"\$SMP New major or minor vers\
ion of RouterOS firmware is available. You need to update it manually.\");\
\r\
\n :set mailSubject (\$mailSubject . \" New RouterOS\
: v.\$deviceOsVerAvail needs to be installed manually.\");\r\
\n :set mailBody (\$mailBody . \"New major or min\
or RouterOS version is available to install: v.\$deviceOsVerAvail (\$updat\
eChannel). \\r\\nYou chose to automatically install only patch updates, so\
\_this major update you need to install manually. \\r\\n\$changelogUrl\");\
\r\
\n :set isOsNeedsToBeUpdated false;\r\
\n }\r\
\n }\r\
\n\r\
\n #Check again, because this variable could be changed during \
checking for installing only patch updats\r\
\n if (\$isOsNeedsToBeUpdated = true) do={\r\
\n :log info (\"\$SMP New RouterOS is going to be\
\_installed! v.\$deviceOsVerInst -> v.\$deviceOsVerAvail\");\r\
\n :set mailSubject (\$mailSubject . \" New RouterOS is \
going to be installed! v.\$deviceOsVerInst -> v.\$deviceOsVerAvail.\");\r\
\n :set mailBody (\$mailBody . \"Your Mikrotik will b\
e updated to the new RouterOS version from v.\$deviceOsVerInst to v.\$devi\
ceOsVerAvail (Update channel: \$updateChannel) \\r\\nA final report with d\
etailed information will be sent once the update process is completed. \\r\
\\nIf you do not receive a second email within the next 10 minutes, there \
may be an issue. Please check your device logs for further information.\")\
;\r\
\n #!! There is more code connected to this part and first \
step at the end of the script.\r\
\n }\r\
\n\r\
\n }\r\
\n }\r\
\n\r\
\n ## Checking If the script needs to create a backup\r\
\n :log info (\"\$SMP Checking If the script needs to create a backup.\
\");\r\
\n if (\$forceBackup = true or \$scriptMode = \"backup\" or \$isOsNeeds\
ToBeUpdated = true) do={\r\
\n :log info (\"\$SMP Creating system backups.\");\r\
\n if (\$isOsNeedsToBeUpdated = true) do={\r\
\n :set backupNameFinal \$backupNameBeforeUpd;\r\
\n };\r\
\n if (\$scriptMode != \"backup\") do={\r\
\n :set mailBody (\$mailBody . \"\\r\\n\\r\\n\");\r\
\n };\r\
\n\r\
\n :set mailSubject (\$mailSubject . \" Backup was created.\");\
\r\
\n :set mailBody (\$mailBody . \"System backups were created \
and attached to this email.\");\r\
\n\r\
\n :set mailAttachments [\$buGlobalFuncCreateBackups backupName=\$b\
ackupNameFinal backupPassword=\$backupPassword sensitiveDataInConfig=\$sen\
sitiveDataInConfig];\r\
\n } else={\r\
\n :log info (\"\$SMP There is no need to create a backup.\");\r\
\n }\r\
\n\r\
\n # Combine first step email\r\
\n :set mailBody (\$mailBody . \$mailBodyDeviceInfo . \$mailBodyCopyrig\
ht);\r\
\n}\r\
\n\r\
\n## STEP TWO: (after first reboot) routerboard firmware upgrade\r\
\n## Steps 2 and 3 are fired only if script is set to automatically update\
\_device and if new RouterOs is available.\r\
\n:if (\$updateStep = 2) do={\r\
\n :log info (\"\$SMP Performing the second step.\");\r\
\n ## RouterOS is the latest, let's check for upgraded routerboard firm\
ware\r\
\n if (\$deviceRbCurrentFw != \$deviceRbUpgradeFw) do={\r\
\n :set isSendEmailRequired false;\r\
\n :delay 10s;\r\
\n :log info \"\$SMP Upgrading routerboard firmware from v.\$device\
RbCurrentFw to v.\$deviceRbUpgradeFw\";\r\
\n ## Start the upgrading process\r\
\n /system routerboard upgrade;\r\
\n ## Wait until the upgrade is completed\r\
\n :delay 5s;\r\
\n :log info \"\$SMP routerboard upgrade process was completed, goi\
ng to reboot in a moment!\";\r\
\n ## Set scheduled task to send final report on the next boot, tas\
k will be deleted when is is done. (That is why you should keep original s\
cript name)\r\
\n /system scheduler add name=BKPUPD-FINAL-REPORT-ON-NEXT-BOOT on-e\
vent=\":delay 5s; /system scheduler remove BKPUPD-FINAL-REPORT-ON-NEXT-BOO\
T; :global buGlobalVarUpdateStep 3; :delay 10s; /system script run BackupA\
ndUpdate;\" start-time=startup interval=0;\r\
\n ## Reboot system to boot with new firmware\r\
\n /system reboot;\r\
\n } else={\r\
\n :log info \"\$SMP It appers that your routerboard is already up \
to date, skipping this step.\";\r\
\n :set updateStep 3;\r\
\n };\r\
\n}\r\
\n\r\
\n## STEP THREE: Last step (after second reboot) sending final report\r\
\n## Steps 2 and 3 are fired only if script is set to automatically update\
\_device and if new RouterOs is available.\r\
\n## This step is executed after some delay\r\
\n:if (\$updateStep = 3) do={\r\
\n :log info (\"\$SMP Performing the third step.\");\r\
\n :log info \"Bkp&Upd: RouterOS and routerboard upgrade process was co\
mpleted. New RouterOS version: v.\$deviceOsVerInst, routerboard firmware: \
v.\$deviceRbCurrentFw.\";\r\
\n ## Small delay in case mikrotik needs some time to initialize connec\
tions\r\
\n :log info \"\$SMP Sending the final email with report and backups.\"\
;\r\
\n :set mailSubject (\$mailSubject . \" RouterOS Upgrade is complete\
d, new version: v.\$deviceOsVerInst!\");\r\
\n :set mailBody \"RouterOS and routerboard upgrade process was c\
ompleted. \\r\\nNew RouterOS version: v.\$deviceOsVerInst, routerboard fir\
mware: v.\$deviceRbCurrentFw. \\r\\n\$changelogUrl \\r\\n\\r\\nBackups of \
the upgraded system are in the attachment of this email. \$mailBodyDevice\
Info \$mailBodyCopyright\";\r\
\n :set mailAttachments [\$buGlobalFuncCreateBackups backupName=\$backu\
pNameAfterUpd backupPassword=\$backupPassword sensitiveDataInConfig=\$sens\
itiveDataInConfig];\r\
\n}\r\
\n\r\
\n# Remove functions from global environment to keep it fresh and clean.\r\
\n:do {/system script environment remove buGlobalFuncGetOsVerNum;} on-erro\
r={}\r\
\n:do {/system script environment remove buGlobalFuncCreateBackups;} on-er\
ror={}\r\
\n\r\
\n##\r\
\n## SENDING EMAIL\r\
\n##\r\
\n# Trying to send email with backups as attachments.\r\
\n\r\
\n:if (\$isSendEmailRequired = true) do={\r\
\n :log info \"\$SMP Sending email message, it will take around half a \
minute...\";\r\
\n :do {/tool e-mail send to=\$emailAddress subject=\$mailSubject body=\
\$mailBody file=\$mailAttachments;} on-error={\r\
\n :delay 5s;\r\
\n :log error \"\$SMP could not send email message (\$[/tool e-mail\
\_get last-status]). Going to try it again in a while.\"\r\
\n\r\
\n :delay 5m;\r\
\n\r\
\n :do {/tool e-mail send to=\$emailAddress subject=\$mailSubject b\
ody=\$mailBody file=\$mailAttachments;} on-error={\r\
\n :delay 5s;\r\
\n :log error \"\$SMP could not send email message (\$[/tool e-\
mail get last-status]) for the second time.\"\r\
\n\r\
\n if (\$isOsNeedsToBeUpdated = true) do={\r\
\n :set isOsNeedsToBeUpdated false;\r\
\n :log warning \"\$SMP script is not going to initialise u\
pdate process due to inability to send backups to email.\"\r\
\n }\r\
\n }\r\
\n }\r\
\n\r\
\n :delay 30s;\r\
\n\r\
\n :if ([:len \$mailAttachments] > 0 and [/tool e-mail get last-status]\
\_= \"succeeded\") do={\r\
\n :log info \"\$SMP File system cleanup.\"\r\
\n /file remove \$mailAttachments;\r\
\n :delay 2s;\r\
\n }\r\
\n\r\
\n}\r\
\n\r\
\n\r\
\n# Fire RouterOS update process\r\
\nif (\$isOsNeedsToBeUpdated = true) do={\r\
\n\r\
\n :if (\$isSoftBased = false) do={\r\
\n ## Set scheduled task to upgrade routerboard firmware on the nex\
t boot, task will be deleted when upgrade is done. (That is why you should\
\_keep original script name)\r\
\n /system scheduler add name=BKPUPD-UPGRADE-ON-NEXT-BOOT on-event=\
\":delay 5s; /system scheduler remove BKPUPD-UPGRADE-ON-NEXT-BOOT; :global\
\_buGlobalVarUpdateStep 2; :delay 10s; /system script run BackupAndUpdate;\
\" start-time=startup interval=0;\r\
\n } else= {\r\
\n ## If the script is executed on CHR, step 2 will be skipped\r\
\n /system scheduler add name=BKPUPD-UPGRADE-ON-NEXT-BOOT on-event=\
\":delay 5s; /system scheduler remove BKPUPD-UPGRADE-ON-NEXT-BOOT; :global\
\_buGlobalVarUpdateStep 3; :delay 10s; /system script run BackupAndUpdate;\
\" start-time=startup interval=0;\r\
\n };\r\
\n\r\
\n\r\
\n :log info \"\$SMP everything is ready to install new RouterOS, going\
\_to reboot in a moment!\"\r\
\n ## Command is reincarnation of the \"upgrade\" command - doing exact\
ly the same but under a different name\r\
\n /system package update install;\r\
\n}\r\
\n\r\
\n:log info \"\$SMP script \\\"Mikrotik RouterOS automatic backup & update\
\\\" completed it's job.\\r\\n\";\r\
\n"
add dont-require-permissions=no name=debug_netbox_api owner=graham policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="#\
\_Minimal Interface Test for NetBox API\
\n# Absolute bare minimum to isolate 400 error cause\
\n\
\n:local netboxUrl \"https://netbox.vntx.net\"\
\n:local netboxToken \"d7d1086aa69b3dff46207e4f1b44d99de4188c04\"\
\n:local routerName [/system identity get name]\
\n\
\n:log info \"Starting minimal interface test for \$routerName\"\
\n\
\n# Step 1: Get device ID - this must work first\
\n:local deviceId \"\"\
\n:do {\
\n /tool fetch url=\"\$netboxUrl/api/dcim/devices/\?name=\$routerName\"\
\_http-method=get http-header-field=\"Authorization: Token \$netboxToken\"\
\_dst-path=device.json\
\n :local content [/file get device.json contents]\
\n :log info \"Device lookup response: \$content\"\
\n\
\n # Simple ID extraction\
\n :local start [:find \$content \"\\\"id\\\":\"]\
\n :if (\$start >= 0) do={\
\n :set start (\$start + 5)\
\n :local end [:find \$content \",\" \$start]\
\n :if (\$end < 0) do={ :set end [:find \$content \"}\" \$start] }\
\n :set deviceId [:pick \$content \$start \$end]\
\n }\
\n /file remove device.json\
\n} on-error={\
\n :log error \"Device lookup failed\"\
\n}\
\n\
\n:if ([:len \$deviceId] = 0) do={\
\n :log error \"No device ID - cannot test interfaces\"\
\n} else={\
\n :log info \"Using device ID: \$deviceId\"\
\n\
\n # Step 2: Test absolute minimal interface\
\n :log info \"Testing minimal interface creation\"\
\n :local minimalJson \"{\\\"device\\\":\$deviceId,\\\"name\\\":\\\"tes\
t1\\\",\\\"type\\\":\\\"other\\\"}\"\
\n :log info \"JSON: \$minimalJson\"\
\n :local jsonLen [:len \$minimalJson]\
\n :log info \"JSON length: \$jsonLen\"\
\n\
\n :do {\
\n /tool fetch url=\"\$netboxUrl/api/dcim/interfaces/\" http-method\
=post http-header-field=\"Authorization: Token \$netboxToken,Content-Type:\
\_application/json\" http-data=\$minimalJson dst-path=result.json\
\n :local result [/file get result.json contents]\
\n :log info \"SUCCESS: \$result\"\
\n /file remove result.json\
\n } on-error={\
\n :log error \"FAILED - checking error response\"\
\n :do {\
\n :local errorResp [/file get result.json contents]\
\n :log error \"Error response: \$errorResp\"\
\n /file remove result.json\
\n } on-error={\
\n :log error \"Could not read error response file\"\
\n }\
\n }\
\n}\
\n\
\n:log info \"Minimal interface test completed\"\
\n"
/tool e-mail
set from=mikrotik@vntx.net server=10.0.0.250
/tool romon
set enabled=yes id=08:55:31:E5:F8:C1
/tool sniffer
set file-name=vilo filter-ip-address=100.64.0.52/32
/user aaa
set default-group=full use-radius=yes