HEX
Server: Apache
System: Linux server2.voipitup.com.au 4.18.0-553.104.1.lve.el8.x86_64 #1 SMP Tue Feb 10 20:07:30 UTC 2026 x86_64
User: posscale (1027)
PHP: 8.2.29
Disabled: exec,passthru,shell_exec,system
Upload Files
File: /home/posscale/backup/MT_Backups/Sandstone_World/BACKUP-Sandstone World-2025jun20-104024.rsc
# jun/20/2025 10:40:24 by RouterOS 6.49.6
# software id = IMRC-K311
#
# model = RBD52G-5HacD2HnD
# serial number = CB3A0C164176
/interface bridge
add admin-mac=48:8F:5A:2B:3B:FA auto-mac=no comment=defconf name=bridge
/interface ethernet
set [ find default-name=ether1 ] disabled=yes
/interface l2tp-client
add connect-to=3.106.179.83 disabled=no ipsec-secret=!Pss.974082** name=\
    Management password=pkXn!Yh4N@NLCb%t use-ipsec=yes user=SandStone_World
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-XX \
    disabled=no distance=indoors frequency=auto installation=indoor mode=\
    ap-bridge ssid=SandStone station-roaming=enabled wireless-protocol=802.11
set [ find default-name=wlan2 ] band=5ghz-a/n/ac channel-width=\
    20/40/80mhz-XXXX disabled=no distance=indoors frequency=auto \
    installation=indoor mode=ap-bridge ssid=SandStone-5G station-roaming=\
    enabled wireless-protocol=802.11
/interface vlan
add disabled=yes interface=ether1 name=NBN-100 vlan-id=100
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk comment=\
    Chantelle76# eap-methods="" mode=dynamic-keys supplicant-identity=\
    MikroTik wpa-pre-shared-key=Chantelle76# wpa2-pre-shared-key=Chantelle76#
/ip pool
add name=default-dhcp ranges=192.168.5.50-192.168.5.200
add name=Renters ranges=192.168.15.50-192.168.15.200
/ip dhcp-server
add address-pool=default-dhcp disabled=no interface=bridge lease-time=1h10m \
    name=defconf
add address-pool=Renters insert-queue-before=bottom interface=ether5 name=\
    Renters
/tool traffic-generator port
add interface=ether5 name=port5
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
    sword,web,sniff,sensitive,api,romon,dude,tikapp"
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=wlan1
add bridge=bridge comment=defconf interface=wlan2
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=NBN-100 list=WAN
add interface=ether1 list=WAN
add interface=ether5 list=WAN
/ip address
add address=192.168.5.1/24 comment=defconf interface=bridge network=\
    192.168.5.0
add address=192.168.15.1/24 disabled=yes interface=ether5 network=\
    192.168.15.0
add address=14.202.97.82/30 disabled=yes interface=NBN-100 network=\
    14.202.97.80
/ip dhcp-client
add disabled=no interface=ether5
/ip dhcp-server alert
add disabled=no interface=bridge on-alert="/tool e-mail send from=\"pbx@voipit\
    up.com.au\" server=\"mail.voipitup.com.au\" body=\"Sandstone World Router \
    DHCP ALERT\" subject=\"Sandstone World Router DHCP CONFLICT \" to=\"jloeke\
    n@posscales.com.au\" port=587 user=pbx@voipitup.com.au password=Pss.974082\
    \_start-tls=no"
/ip dhcp-server lease
add address=192.168.5.10 client-id=1:38:1a:52:57:9c:2c mac-address=\
    38:1A:52:57:9C:2C server=defconf
/ip dhcp-server network
add address=192.168.5.0/24 comment=defconf dns-server=192.168.5.1,8.8.8.8 \
    gateway=192.168.5.1
add address=192.168.15.0/24 gateway=192.168.15.1
/ip dns
set allow-remote-requests=yes servers=8.8.8.8
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan
add address=3.105.22.41 name=unifi
/ip firewall address-list
add address=61.69.57.74 list=Managemant
/ip firewall filter
add action=passthrough chain=forward comment="Office Download Counter" \
    disabled=yes in-interface=NBN-100 out-interface=bridge
add action=passthrough chain=forward comment="Rental unit Download Counter" \
    disabled=yes in-interface=NBN-100 out-interface=ether5
add action=accept chain=input dst-port=8291 in-interface-list=WAN protocol=\
    tcp src-address-list=Managemant
add action=accept chain=input dst-port=8291 in-interface=Management protocol=\
    tcp
add action=drop chain=input dst-port=53 in-interface-list=WAN protocol=tcp
add action=drop chain=input dst-port=53 in-interface-list=WAN protocol=udp
add action=accept chain=input comment=\
    "defconf: accept established,related,untracked" connection-state=\
    established,related,untracked
add action=accept chain=input dst-port=8291 in-interface-list=WAN protocol=\
    tcp
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
    invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment=\
    "defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
    in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
    ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
    ipsec-policy=out,ipsec
add action=passthrough chain=forward comment="Office Download Counter" \
    disabled=yes in-interface=NBN-100 out-interface=bridge
add action=passthrough chain=forward comment="Rental unit Download Counter" \
    disabled=yes in-interface=NBN-100 out-interface=ether5
add action=accept chain=forward comment=\
    "defconf: accept established,related, untracked" connection-state=\
    established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
    connection-state=invalid in-interface-list=WAN
add action=drop chain=forward comment=\
    "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
    connection-state=new in-interface-list=WAN
/ip firewall mangle
add action=passthrough chain=forward disabled=yes in-interface=NBN-100 \
    out-interface=bridge
/ip firewall nat
add action=masquerade chain=srcnat out-interface=Management
add action=masquerade chain=srcnat comment="defconf: masquerade" \
    ipsec-policy=out,none out-interface-list=WAN
/ip firewall service-port
set sip disabled=yes
/ip route
add disabled=yes distance=2 gateway=14.202.97.81
add disabled=yes distance=1 dst-address=192.168.20.0/24 gateway=ether1
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set ssh disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/system clock
set time-zone-name=Australia/Melbourne
/system identity
set name="Sandstone World"
/system scheduler
add interval=1w name="Auto FTP Backup" on-event=":local saveUserDB false\r\
    \n:local saveSysBackup true\r\
    \n:local encryptSysBackup false\r\
    \n:local saveRawExport true\r\
    \n\r\
    \n:local FTPServer \"backup.posscales.com.au\"\r\
    \n:local FTPPort 21\r\
    \n:local FTPUser \"MT_Backups@backup.posscales.com.au\"\r\
    \n:local FTPPass \"!Dgt.974082\"\r\
    \n:local FTPdest \"/Sandstone_World\"\r\
    \n\r\
    \n:local ts [/system clock get time]\r\
    \n:set ts ([:pick \$ts 0 2].[:pick \$ts 3 5].[:pick \$ts 6 8])\r\
    \n:local ds [/system clock get date]\r\
    \n:set ds ([:pick \$ds 7 11].[:pick \$ds 0 3].[:pick \$ds 4 6])\r\
    \n\r\
    \n:local fname (\"BACKUP-\".[/system identity get name].\"-\".\$ds.\"-\".\
    \$ts)\r\
    \n:local sfname (\"/\".\$fname)\r\
    \n:if (\$saveUserDB) do={\r\
    \n  /tool user-manager database save name=(\$sfname.\".umb\")\r\
    \n  :log info message=\"User Manager DB Backup Finished\"\r\
    \n}\r\
    \n:if (\$saveSysBackup) do={\r\
    \n  :if (\$encryptSysBackup = true) do={ /system backup save name=(\$sfnam\
    e.\".backup\") }\r\
    \n  :if (\$encryptSysBackup = false) do={ /system backup save dont-encrypt\
    =yes name=(\$sfname.\".backup\") }\r\
    \n  :log info message=\"System Backup Finished\"\r\
    \n}\r\
    \nif (\$saveRawExport) do={\r\
    \n  /export file=(\$sfname.\".rsc\")\r\
    \n  :log info message=\"Raw configuration script export Finished\"\r\
    \n}\r\
    \n:delay 10s\r\
    \n:local backupFileName \"\"\r\
    \n:local backupDestPath \"\"\r\
    \n:foreach backupFile in=[/file find] do={\r\
    \n  :set backupFileName (\"/\".[/file get \$backupFile name])\r\
    \n  :set backupDestPath (\$FTPdest.\$backupFileName)\r\
    \n  :if ([:typeof [:find \$backupFileName \$sfname]] != \"nil\") do={\r\
    \n  # :log warning message=\"/tool fetch address=\$FTPServer port=\$FTPPor\
    t src-path=\$backupFileName user=\$FTPUser mode=ftp password=\$FTPPass dst\
    -path=\$backupDestPath upload=yes\"\r\
    \n\r\
    \n    /tool fetch address=\$FTPServer port=\$FTPPort src-path=\$backupFile\
    Name user=\$FTPUser mode=ftp password=\$FTPPass dst-path=\$backupDestPath \
    upload=yes\r\
    \n  }\r\
    \n}\r\
    \n:delay 10s\r\
    \n:foreach backupFile in=[/file find] do={\r\
    \n  :if ([:typeof [:find [/file get \$backupFile name] \"BACKUP-\"]]!=\"ni\
    l\") do={\r\
    \n    /file remove \$backupFile\r\
    \n  }\r\
    \n}\r\
    \n\r\
    \n:log info message=\"Successfully removed Temporary Backup Files\"\r\
    \n:log info message=\"Automatic Backup Completed Successfully\"" policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
    start-date=feb/11/2022 start-time=10:40:24
/system script
add dont-require-permissions=no name="Manual Backup" owner=posscales policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=":\
    local saveUserDB false\r\
    \n:local saveSysBackup true\r\
    \n:local encryptSysBackup false\r\
    \n:local saveRawExport true\r\
    \n\r\
    \n:local FTPServer \"backup.posscales.com.au\"\r\
    \n:local FTPPort 21\r\
    \n:local FTPUser \"MT_Backups@backup.posscales.com.au\"\r\
    \n:local FTPPass \"!Dgt.974082\"\r\
    \n:local FTPdest \"/Sandstone_World\"\r\
    \n\r\
    \n:local ts [/system clock get time]\r\
    \n:set ts ([:pick \$ts 0 2].[:pick \$ts 3 5].[:pick \$ts 6 8])\r\
    \n:local ds [/system clock get date]\r\
    \n:set ds ([:pick \$ds 7 11].[:pick \$ds 0 3].[:pick \$ds 4 6])\r\
    \n\r\
    \n:local fname (\"BACKUP-\".[/system identity get name].\"-\".\$ds.\"-\".\
    \$ts)\r\
    \n:local sfname (\"/\".\$fname)\r\
    \n:if (\$saveUserDB) do={\r\
    \n  /tool user-manager database save name=(\$sfname.\".umb\")\r\
    \n  :log info message=\"User Manager DB Backup Finished\"\r\
    \n}\r\
    \n:if (\$saveSysBackup) do={\r\
    \n  :if (\$encryptSysBackup = true) do={ /system backup save name=(\$sfnam\
    e.\".backup\") }\r\
    \n  :if (\$encryptSysBackup = false) do={ /system backup save dont-encrypt\
    =yes name=(\$sfname.\".backup\") }\r\
    \n  :log info message=\"System Backup Finished\"\r\
    \n}\r\
    \nif (\$saveRawExport) do={\r\
    \n  /export file=(\$sfname.\".rsc\")\r\
    \n  :log info message=\"Raw configuration script export Finished\"\r\
    \n}\r\
    \n:delay 10s\r\
    \n:local backupFileName \"\"\r\
    \n:local backupDestPath \"\"\r\
    \n:foreach backupFile in=[/file find] do={\r\
    \n  :set backupFileName (\"/\".[/file get \$backupFile name])\r\
    \n  :set backupDestPath (\$FTPdest.\$backupFileName)\r\
    \n  :if ([:typeof [:find \$backupFileName \$sfname]] != \"nil\") do={\r\
    \n  # :log warning message=\"/tool fetch address=\$FTPServer port=\$FTPPor\
    t src-path=\$backupFileName user=\$FTPUser mode=ftp password=\$FTPPass dst\
    -path=\$backupDestPath upload=yes\"\r\
    \n\r\
    \n    /tool fetch address=\$FTPServer port=\$FTPPort src-path=\$backupFile\
    Name user=\$FTPUser mode=ftp password=\$FTPPass dst-path=\$backupDestPath \
    upload=yes\r\
    \n  }\r\
    \n}\r\
    \n:delay 10s\r\
    \n:foreach backupFile in=[/file find] do={\r\
    \n  :if ([:typeof [:find [/file get \$backupFile name] \"BACKUP-\"]]!=\"ni\
    l\") do={\r\
    \n    /file remove \$backupFile\r\
    \n  }\r\
    \n}\r\
    \n\r\
    \n:log info message=\"Successfully removed Temporary Backup Files\"\r\
    \n:log info message=\"Automatic Backup Completed Successfully\""
/tool graphing interface
add
/tool graphing queue
add
/tool graphing resource
add
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
/tool netwatch
add disabled=yes host=8.8.8.8 up-script="/tool e-mail send from=\"pbx@voipitup\
    .com.au\" server=\"mail.voipitup.com.au\" body=\"Sandstone World Router Ba\
    ck UP\" subject=\"Sandstone World Router is back oonline \" to=\"jloeken@p\
    osscales.com.au\" port=587 user=pbx@voipitup.com.au password=Pss.974082 st\
    art-tls=no"
add comment=NEW down-script=":local CurDate [/system clock get date];\r\
    \n:local CurTime [/system clock get time];\r\
    \n:log err (\"Internet Connection is DOWN    -    \".[:tostr \$CurDate].\"\
    \_- \".[:tostr \$CurTime]);\r\
    \n#Set the monitored IP address\r\
    \n:local addre 8.8.8.8;\r\
    \n\r\
    \n:local int;\r\
    \n:local RouterName;  #identity\r\
    \n:local RouterVer;   #version\r\
    \n:local RouterUP;    #uptime\r\
    \n\r\
    \n:local Themes \"Sandstone World  Monitor \$RouterName - Connection DOWN \
    -  IP: \$addre\";\r\
    \n\r\
    \n#Set the delay\r\
    \n:local ms 2;\r\
    \n:local avgRtt;\r\
    \n:local pin\r\
    \n:local pout\r\
    \n/tool flood-ping \$addre count=10 do={\r\
    \n  :if (\$sent = 10) do={\r\
    \n    :set avgRtt \$\"avg-rtt\"\r\
    \n    :set pout \$sent\r\
    \n    :set pin \$received\r\
    \n  }\r\
    \n}\r\
    \n\r\
    \n:local ploss (100 - ((\$pin * 100) / \$pout))\r\
    \n:local logmsg (\"Ping Average for \".[:tostr \$addre].\" - \".[:tostr \$\
    avgRtt].\"ms - packet loss: \".[:tostr \$ploss].\"%\")\r\
    \n:log warning \$logmsg\r\
    \n\r\
    \n:delay 10s\r\
    \n:set addre 14.202.97.82;\r\
    \n/tool flood-ping \$addre count=10 do={\r\
    \n  :if (\$sent = 10) do={\r\
    \n    :set avgRtt \$\"avg-rtt\"\r\
    \n    :set pout \$sent\r\
    \n    :set pin \$received\r\
    \n  }\r\
    \n}\r\
    \n\r\
    \n:local ploss (100 - ((\$pin * 100) / \$pout))\r\
    \n:local logmsg (\"Ping Average for \".[:tostr \$addre].\" - \".[:tostr \$\
    avgRtt].\"ms - packet loss: \".[:tostr \$ploss].\"%\")\r\
    \n:log warning \$logmsg\r\
    \n\r\
    \n:delay 10s\r\
    \n:set addre 614.202.97.81;\r\
    \n/tool flood-ping \$addre count=10 do={\r\
    \n  :if (\$sent = 10) do={\r\
    \n    :set avgRtt \$\"avg-rtt\"\r\
    \n    :set pout \$sent\r\
    \n    :set pin \$received\r\
    \n  }\r\
    \n}\r\
    \n\r\
    \n:local ploss (100 - ((\$pin * 100) / \$pout))\r\
    \n:local logmsg (\"Ping Average for \".[:tostr \$addre].\" - \".[:tostr \$\
    avgRtt].\"ms - packet loss: \".[:tostr \$ploss].\"%\")\r\
    \n:log warning \$logmsg\r\
    \n\r\
    \n:local NeighborList [/ip neighbor print detail];\r\
    \n\r\
    \n:log err \"Connection to Internet is DOWN <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<\
    <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<\"; \r\
    \n" host=8.8.8.8 up-script=":local CurDate [/system clock get date];\r\
    \n:local CurTime [/system clock get time];\r\
    \n:log err (\"Internet Connection is UP    -    \".[:tostr \$CurDate].\" -\
    \_\".[:tostr \$CurTime]);\r\
    \n#Set the monitored IP address Below\r\
    \n:local addre 8.8.8.8;\r\
    \n\r\
    \n:local int;\r\
    \n:local RouterName;  #identity\r\
    \n:local RouterVer;   #version\r\
    \n:local RouterUP;    #uptime\r\
    \n\r\
    \n\r\
    \n#:log err \"RouterName= /system/identity get value-name=name\";\r\
    \n#:log err \"RouterVer= \$RouterVer\";\r\
    \n#:log err \"RouterUP= \$RouterUP\";\r\
    \n\r\
    \n:local Themes \"Sandstone World Monitor \$RouterName - Connection UP -  \
    IP: \$addre\";\r\
    \n#:log err \"START Monitor UP\";\r\
    \n\r\
    \n#Set the delay\r\
    \n:local ms 2;\r\
    \n:local avgRtt;\r\
    \n:local pin\r\
    \n:local pout\r\
    \n/tool flood-ping \$addre count=10 do={\r\
    \n  :if (\$sent = 10) do={\r\
    \n    :set avgRtt \$\"avg-rtt\"\r\
    \n    :set pout \$sent\r\
    \n    :set pin \$received\r\
    \n  }\r\
    \n}\r\
    \n#:log err \"START Monitor UP\";\r\
    \n\r\
    \n:local ploss (100 - ((\$pin * 100) / \$pout))\r\
    \n:local logmsg (\"Ping Average for \".[:tostr \$addre].\" - \".[:tostr \$\
    avgRtt].\"ms - packet loss: \".[:tostr \$ploss].\"%\")\r\
    \n:log warning \$logmsg\r\
    \n\r\
    \n:delay 10s\r\
    \n:set addre 14.202.97.82;\r\
    \n/tool flood-ping \$addre count=10 do={\r\
    \n  :if (\$sent = 10) do={\r\
    \n    :set avgRtt \$\"avg-rtt\"\r\
    \n    :set pout \$sent\r\
    \n    :set pin \$received\r\
    \n  }\r\
    \n}\r\
    \n\r\
    \n:local ploss (100 - ((\$pin * 100) / \$pout))\r\
    \n:local logmsg (\"Ping Average for \".[:tostr \$addre].\" - \".[:tostr \$\
    avgRtt].\"ms - packet loss: \".[:tostr \$ploss].\"%\")\r\
    \n:log warning \$logmsg\r\
    \n\r\
    \n:delay 10s\r\
    \n:set addre 14.202.97.81;\r\
    \n/tool flood-ping \$addre count=10 do={\r\
    \n  :if (\$sent = 10) do={\r\
    \n    :set avgRtt \$\"avg-rtt\"\r\
    \n    :set pout \$sent\r\
    \n    :set pin \$received\r\
    \n  }\r\
    \n}\r\
    \n\r\
    \n:local ploss (100 - ((\$pin * 100) / \$pout))\r\
    \n:local logmsg (\"Ping Average for \".[:tostr \$addre].\" - \".[:tostr \$\
    avgRtt].\"ms - packet loss: \".[:tostr \$ploss].\"%\")\r\
    \n:log warning \$logmsg\r\
    \n\r\
    \n:local NeighborList [/ip neighbor print];\r\
    \n\r\
    \n:log err \"Connection to Internet is Back UP\"; \r\
    \n\r\
    \n:log info \"\$NeighborList\";\r\
    \n\r\
    \n"