routeros
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| routeros [2024/09/01 10:45] – protocol | routeros [2026/09/23 14:16] (current) – protocol | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | === OSPF watchdog when default route vanishes, set your variables! === | + | ===== Known your IP ===== |
| + | < | ||
| + | /tool fetch https:// | ||
| + | </ | ||
| + | |||
| + | |||
| + | ===== Balance ===== | ||
| + | |||
| + | [[balance]] | ||
| + | |||
| + | |||
| + | ===== OSPF watchdog when default route vanishes, set your variables! | ||
| < | < | ||
| Line 11: | Line 22: | ||
| }</ | }</ | ||
| + | ===== something about wifi reg tables ===== | ||
| + | < | ||
| - | === Dirty block x.com with address-list (more granularity, | ||
| - | < | + | :foreach ITEM in=[/interface wireless registration-table print] do={ |
| - | ip firewall address-list add list=x.com address=69.195.185.0/24 comment=x.com | + | : |
| - | ip firewall address-list add list=x.com address=192.133.76.0/ | + | :put " |
| - | ip firewall address-list add list=x.com address=69.195.187.0/24 comment=x.com | + | } |
| - | ip firewall address-list add list=x.com address=199.16.156.0/ | + | |
| - | ip firewall address-list add list=x.com address=104.244.45.0/ | + | :foreach a in=[/interface wireless registration-table] do={ |
| - | ip firewall address-list add list=x.com address=209.237.196.0/ | + | :put [interface wireless registration-table get $a comment] |
| - | ip firewall address-list add list=x.com address=69.195.184.0/ | + | } |
| - | ip firewall address-list add list=x.com address=69.195.178.0/24 comment=x.com | + | |
| - | ip firewall address-list add list=x.com address=69.195.169.0/ | + | |
| - | ip firewall address-list add list=x.com address=103.252.114.0/ | + | :foreach i in [/interface wireless registration-table find] do={ |
| - | ip firewall address-list add list=x.com address=104.244.41.0/ | + | :find [/interface wireless registration-table get $i comment] |
| - | ip firewall address-list add list=x.com address=202.160.131.0/ | + | :put " |
| - | ip firewall address-list add list=x.com address=69.195.162.0/ | + | } |
| - | ip firewall address-list add list=x.com address=209.237.194.0/24 comment=x.com | + | } |
| - | ip firewall address-list add list=x.com address=104.244.47.0/ | + | |
| - | ip firewall address-list add list=x.com address=103.252.112.0/23 comment=x.com | + | { |
| - | ip firewall address-list add list=x.com address=202.160.130.0/ | + | :local registration [/interface wireless registration-table print where interface=wlan2 count-only]; |
| - | ip firewall address-list add list=x.com address=69.195.180.0/ | + | :if ($registration > 0) do={ |
| - | ip firewall address-list add list=x.com address=104.244.40.0/ | + | /tool fetch url=" |
| - | ip firewall address-list add list=x.com address=69.195.181.0/ | + | } |
| - | ip firewall address-list add list=x.com address=202.160.128.0/ | + | } |
| - | ip firewall address-list add list=x.com address=209.237.199.0/ | + | |
| - | ip firewall address-list add list=x.com address=69.195.179.0/24 comment=x.com | + | |
| - | ip firewall address-list add list=x.com address=199.16.156.0/ | + | |
| - | ip firewall address-list add list=x.com address=104.244.46.0/ | + | |
| - | ip firewall address-list add list=x.com address=69.195.168.0/24 comment=x.com | + | |
| - | ip firewall address-list add list=x.com address=69.195.182.0/24 comment=x.com | + | |
| - | ip firewall address-list add list=x.com address=199.59.148.0/22 comment=x.com | + | |
| - | ip firewall address-list add list=x.com address=64.63.0.0/18 comment=x.com | + | |
| - | ip firewall address-list add list=x.com address=199.96.56.0/23 comment=x.com | + | |
| - | ip firewall address-list add list=x.com address=69.195.175.0/24 comment=x.com | + | |
| - | ip firewall address-list add list=x.com address=69.195.174.0/ | + | |
| - | ip firewall address-list add list=x.com address=209.237.192.0/ | + | |
| - | ip firewall address-list add list=x.com address=69.195.160.0/ | + | |
| - | ip firewall address-list add list=x.com address=69.195.166.0/ | + | |
| - | ip firewall address-list add list=x.com address=209.237.198.0/ | + | |
| - | ip firewall address-list add list=x.com address=69.195.183.0/ | + | |
| - | ip firewall address-list add list=x.com address=209.237.195.0/ | + | |
| - | ip firewall address-list add list=x.com address=69.195.171.0/ | + | |
| - | ip firewall address-list add list=x.com address=104.244.42.0/ | + | |
| - | ip firewall address-list add list=x.com address=202.160.129.0/ | + | |
| - | ip firewall address-list add list=x.com address=69.195.160.0/ | + | |
| - | ip firewall address-list add list=x.com address=209.237.192.0/ | + | |
| - | ip firewall address-list add list=x.com address=104.244.44.0/ | + | |
| - | ip firewall address-list add list=x.com address=69.195.186.0/ | + | |
| - | ip firewall address-list add list=x.com address=209.237.193.0/ | + | |
| - | ip firewall address-list add list=x.com address=188.64.224.0/ | + | |
| - | ipv6 firewall address-list add list=x.com address=2400: | + | |
| - | ipv6 firewall address-list add list=x.com address=2a04: | + | |
| - | ipv6 firewall address-list add list=x.com address=2606: | + | |
| </ | </ | ||
| + | ===== MPLS basic ===== | ||
| + | < | ||
| - | === Dirty block x.com with blackhole routes (least resources used, no firewall needed, no options) | + | /mpls ldp set enabled=yes lsr-id=172.26.0.101 transport-address=172.26.0.101 |
| + | /mpls ldp interface add interface=ether2 | ||
| + | /mpls ldp interface add interface=ether5 | ||
| + | /interface vpls add remote-peer=172.26.0.103 vpls-id=3012: | ||
| + | /interface bridge port | ||
| + | add bridge=vlan3012-bridge interface=vpls1 | ||
| + | add bridge=vlan3012-bridge interface=vpls2 | ||
| + | add bridge=vlan3012-bridge interface=ether1 | ||
| + | </ | ||
| + | |||
| + | ===== Automatic PPPoE creation local secrets ===== | ||
| < | < | ||
| - | ip route add type=blackhole dst-address=69.195.185.0/ | + | |
| - | ip route add type=blackhole dst-address=192.133.76.0/ | + | { |
| - | ip route add type=blackhole dst-address=69.195.187.0/ | + | :put " |
| - | ip route add type=blackhole dst-address=199.16.156.0/23 comment=x.com | + | |
| - | ip route add type=blackhole dst-address=104.244.45.0/ | + | # Initialize the log pointer to the very last current entry |
| - | ip route add type=blackhole dst-address=209.237.196.0/ | + | : |
| - | ip route add type=blackhole dst-address=69.195.184.0/24 comment=x.com | + | : |
| - | ip route add type=blackhole dst-address=69.195.178.0/ | + | :if ([:len $terminalLogID] > 0) do={ |
| - | ip route add type=blackhole dst-address=69.195.169.0/24 comment=x.com | + | :set lastID ($terminalLogID->([:len $terminalLogID] |
| - | ip route add type=blackhole dst-address=103.252.114.0/ | + | } |
| - | ip route add type=blackhole dst-address=104.244.41.0/ | + | |
| - | ip route add type=blackhole dst-address=202.160.131.0/ | + | # Continuous loop |
| - | ip route add type=blackhole dst-address=69.195.162.0/ | + | : |
| - | ip route add type=blackhole dst-address=209.237.194.0/ | + | # Filter logs containing authentication failure and include "user " |
| - | ip route add type=blackhole dst-address=104.244.47.0/ | + | : |
| - | ip route add type=blackhole dst-address=103.252.112.0/ | + | |
| - | ip route add type=blackhole dst-address=202.160.130.0/24 comment=x.com | + | : |
| - | ip route add type=blackhole dst-address=69.195.180.0/ | + | # Process only newer entries than our saved marker |
| - | ip route add type=blackhole dst-address=104.244.40.0/ | + | :if ($entry > $lastID) do={ |
| - | ip route add type=blackhole dst-address=69.195.181.0/ | + | : |
| - | ip route add type=blackhole dst-address=202.160.128.0/ | + | |
| - | ip route add type=blackhole dst-address=209.237.199.0/24 comment=x.com | + | # STRICT TOPIC CHECK: Ensure the log contains the ' |
| - | ip route add type=blackhole dst-address=69.195.179.0/ | + | :if ($logTopics ~ " |
| - | ip route add type=blackhole dst-address=199.16.156.0/ | + | : |
| - | ip route add type=blackhole dst-address=104.244.46.0/ | + | : |
| - | ip route add type=blackhole dst-address=69.195.168.0/24 comment=x.com | + | |
| - | ip route add type=blackhole dst-address=69.195.182.0/24 comment=x.com | + | : |
| - | ip route add type=blackhole dst-address=199.59.148.0/ | + | : |
| - | ip route add type=blackhole dst-address=64.63.0.0/ | + | |
| - | ip route add type=blackhole dst-address=199.96.56.0/ | + | :if ($endPos > $startPos) do={ |
| - | ip route add type=blackhole dst-address=69.195.175.0/ | + | : |
| - | ip route add type=blackhole dst-address=69.195.174.0/ | + | |
| - | ip route add type=blackhole dst-address=209.237.192.0/ | + | # Verify if it already exists |
| - | ip route add type=blackhole dst-address=69.195.160.0/ | + | :if ([:len [/ppp secret find where name=$pppoeUser]] |
| - | ip route add type=blackhole dst-address=69.195.166.0/ | + | /ppp secret |
| - | ip route add type=blackhole dst-address=209.237.198.0/24 comment=x.com | + | :put " |
| - | ip route add type=blackhole dst-address=69.195.183.0/24 comment=x.com | + | } else={ |
| - | ip route add type=blackhole dst-address=209.237.195.0/24 comment=x.com | + | :put " |
| - | ip route add type=blackhole dst-address=69.195.171.0/ | + | } |
| - | ip route add type=blackhole dst-address=104.244.42.0/ | + | } |
| - | ip route add type=blackhole dst-address=202.160.129.0/ | + | } |
| - | ip route add type=blackhole dst-address=69.195.160.0/ | + | :set lastID $entry |
| - | ip route add type=blackhole dst-address=209.237.192.0/ | + | } |
| - | ip route add type=blackhole dst-address=104.244.44.0/24 comment=x.com | + | } |
| - | ip route add type=blackhole dst-address=69.195.186.0/ | + | # 2-second delay before checking the log buffer again |
| - | ip route add type=blackhole dst-address=209.237.193.0/ | + | |
| - | ip route add type=blackhole dst-address=188.64.224.0/ | + | } |
| - | ipv6 route add type=unreachable dst-address=2400:6680: | + | } |
| - | ipv6 route add type=unreachable dst-address=2a04:9d40: | + | |
| - | ipv6 route add type=unreachable dst-address=2606: | + | |
| </ | </ | ||
| + | |||
routeros.1725198345.txt.gz · Last modified: by protocol
