File: /home/posscale/backup/MT_Backups/workrehab/BACKUP-Work-Rehab_Paddington-2024apr04-232553.rsc
# apr/04/2024 23:25:53 by RouterOS 6.47.1
# software id = 3RR6-Z60S
#
# model = RB2011UiAS
# serial number = D51F0C470C0F
/interface bridge
add admin-mac=48:8F:5A:BA:81:C7 auto-mac=no comment=defconf name=bridge
/interface ethernet
set [ find default-name=ether2 ] comment="POE Switch"
/interface l2tp-client
add connect-to=3.106.179.83 disabled=no ipsec-secret=!Pss.974082** name=\
Management password=WzKY!F^iml8l3b0v use-ipsec=yes user=\
Work_Rehab_Paddington
/interface vlan
add comment="NBN Vlan 100" interface=ether1 name=vlan100 vlan-id=100
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=default-dhcp ranges=192.168.1.51-192.168.1.254
/ip dhcp-server
add address-pool=default-dhcp disabled=no interface=bridge name=defconf
/snmp community
add addresses=20.11.211.118/32 authentication-password=Welc0me123!! \
authentication-protocol=SHA1 encryption-password=Welc0me123!! \
encryption-protocol=AES name=observium security=private write-access=yes
/system logging action
add disk-file-name=Scrips_Log disk-lines-per-file=2000 name=ScripsLog target=\
disk
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=ether6
add bridge=bridge comment=defconf interface=ether7
add bridge=bridge comment=defconf interface=ether8
add bridge=bridge comment=defconf interface=ether9
add bridge=bridge comment=defconf interface=ether10
add bridge=bridge comment=defconf interface=sfp1
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
add interface=vlan100 list=WAN
/ip address
add address=192.168.1.1/24 comment=defconf interface=bridge network=\
192.168.1.0
add address=61.69.66.246/30 interface=vlan100 network=61.69.66.244
/ip dhcp-client
add comment=defconf disabled=no interface=ether1
/ip dhcp-server network
add address=192.168.1.0/24 comment=defconf gateway=192.168.1.1
/ip dns
set allow-remote-requests=yes servers=8.8.8.8
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan type=A
/ip firewall address-list
add address=61.69.57.74 comment="Jason VoIP It UP" list=Management
add address=103.133.98.103 comment="IT Department" list=Management
add address=20.11.211.118 comment=\
"This allows the IT department to monitor the router via SNMP" list=\
Observium
/ip firewall filter
add action=accept chain=input comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=accept chain=input dst-port=8291 in-interface-list=WAN protocol=\
tcp src-address-list=Management
add action=accept chain=input dst-port=8291 in-interface=Management protocol=\
tcp
add action=accept chain=input dst-port=22 in-interface-list=WAN protocol=tcp \
src-address-list=Management
add action=accept chain=input dst-port=161 in-interface-list=WAN protocol=udp \
src-address-list=Observium
add action=drop chain=input dst-port=53 in-interface=vlan100 protocol=tcp
add action=drop chain=input dst-port=53 in-interface=vlan100 protocol=udp
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment=\
"defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
connection-state=established,related
add action=accept chain=forward comment=\
"defconf: accept established,related, untracked" connection-state=\
established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
connection-state=invalid
add action=drop chain=forward comment=\
"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
connection-state=new in-interface-list=WAN
/ip firewall nat
add action=masquerade chain=srcnat out-interface=Management
add action=masquerade chain=srcnat comment="defconf: masquerade" \
ipsec-policy=out,none out-interface-list=WAN
add action=dst-nat chain=dstnat dst-port=8080 in-interface-list=WAN protocol=\
tcp to-addresses=192.168.1.10 to-ports=8080
/ip route
add distance=1 gateway=61.69.66.245
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/snmp
set contact=monitoring@itdepartment.com.au enabled=yes location=\
"WRB - Paddington,QLD" trap-community=observium trap-generators=\
interfaces trap-interfaces=all trap-target=20.11.211.118 trap-version=3
/system clock
set time-zone-name=Australia/Brisbane
/system identity
set name=Work-Rehab_Paddington
/system logging
set 2 topics=warning,!script
add action=disk topics=ssh,debug
add action=ScripsLog topics=script
/system routerboard settings
set boot-device=nand-only
/system scheduler
add interval=1w name=AUTO_FTP_Backup on-event=":local saveUserDB false\r\r\
\n:local saveSysBackup true\r\r\
\n:local encryptSysBackup false\r\r\
\n:local saveRawExport true\r\r\
\n\r\r\
\n:local FTPServer \"backup.posscales.com.au\"\r\r\
\n:local FTPPort 21\r\r\
\n:local FTPUser \"MT_Backups@backup.posscales.com.au\"\r\r\
\n:local FTPPass \"!Dgt.974082\"\r\r\
\n:local FTPdest \"/workrehab\"\r\r\
\n\r\r\
\n:local ts [/system clock get time]\r\r\
\n:set ts ([:pick \$ts 0 2].[:pick \$ts 3 5].[:pick \$ts 6 8])\r\r\
\n:local ds [/system clock get date]\r\r\
\n:set ds ([:pick \$ds 7 11].[:pick \$ds 0 3].[:pick \$ds 4 6])\r\r\
\n\r\r\
\n:local fname (\"BACKUP-\".[/system identity get name].\"-\".\$ds.\"-\".\
\$ts)\r\r\
\n:local sfname (\"/\".\$fname)\r\r\
\n:if (\$saveUserDB) do={\r\r\
\n /tool user-manager database save name=(\$sfname.\".umb\")\r\r\
\n :log info message=\"User Manager DB Backup Finished\"\r\r\
\n}\r\r\
\n:if (\$saveSysBackup) do={\r\r\
\n :if (\$encryptSysBackup = true) do={ /system backup save name=(\$sfnam\
e.\".backup\") }\r\r\
\n :if (\$encryptSysBackup = false) do={ /system backup save dont-encrypt\
=yes name=(\$sfname.\".backup\") }\r\r\
\n :log info message=\"System Backup Finished\"\r\r\
\n}\r\r\
\nif (\$saveRawExport) do={\r\r\
\n /export file=(\$sfname.\".rsc\")\r\r\
\n :log info message=\"Raw configuration script export Finished\"\r\r\
\n}\r\r\
\n:delay 10s\r\r\
\n:local backupFileName \"\"\r\r\
\n:local backupDestPath \"\"\r\r\
\n:foreach backupFile in=[/file find] do={\r\r\
\n :set backupFileName (\"/\".[/file get \$backupFile name])\r\r\
\n :set backupDestPath (\$FTPdest.\$backupFileName)\r\r\
\n :if ([:typeof [:find \$backupFileName \$sfname]] != \"nil\") do={\r\r\
\n # :log warning message=\"/tool fetch address=\$FTPServer port=\$FTPPor\
t src-path=\$backupFileName user=\$FTPUser mode=ftp password=\$FTPPass dst\
-path=\$backupDestPath upload=yes\"\r\r\
\n\r\r\
\n /tool fetch address=\$FTPServer port=\$FTPPort src-path=\$backupFile\
Name user=\$FTPUser mode=ftp password=\$FTPPass dst-path=\$backupDestPath \
upload=yes\r\r\
\n }\r\r\
\n}\r\r\
\n:delay 10s\r\r\
\n:foreach backupFile in=[/file find] do={\r\r\
\n :if ([:typeof [:find [/file get \$backupFile name] \"BACKUP-\"]]!=\"ni\
l\") do={\r\r\
\n /file remove \$backupFile\r\r\
\n }\r\r\
\n}\r\r\
\n\r\r\
\n:log info message=\"Successfully removed Temporary Backup Files\"\r\r\
\n:log info message=\"Automatic Backup Completed Successfully\"" policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
start-date=oct/06/2022 start-time=23:25:53
/system script
add dont-require-permissions=no name="manual Backup" owner=admin policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=":\
local saveUserDB false\r\r\
\n:local saveSysBackup true\r\r\
\n:local encryptSysBackup false\r\r\
\n:local saveRawExport true\r\r\
\n\r\r\
\n:local FTPServer \"backup.posscales.com.au\"\r\r\
\n:local FTPPort 21\r\r\
\n:local FTPUser \"MT_Backups@backup.posscales.com.au\"\r\r\
\n:local FTPPass \"!Dgt.974082\"\r\r\
\n:local FTPdest \"/workrehab\"\r\r\
\n\r\r\
\n:local ts [/system clock get time]\r\r\
\n:set ts ([:pick \$ts 0 2].[:pick \$ts 3 5].[:pick \$ts 6 8])\r\r\
\n:local ds [/system clock get date]\r\r\
\n:set ds ([:pick \$ds 7 11].[:pick \$ds 0 3].[:pick \$ds 4 6])\r\r\
\n\r\r\
\n:local fname (\"BACKUP-\".[/system identity get name].\"-\".\$ds.\"-\".\
\$ts)\r\r\
\n:local sfname (\"/\".\$fname)\r\r\
\n:if (\$saveUserDB) do={\r\r\
\n /tool user-manager database save name=(\$sfname.\".umb\")\r\r\
\n :log info message=\"User Manager DB Backup Finished\"\r\r\
\n}\r\r\
\n:if (\$saveSysBackup) do={\r\r\
\n :if (\$encryptSysBackup = true) do={ /system backup save name=(\$sfnam\
e.\".backup\") }\r\r\
\n :if (\$encryptSysBackup = false) do={ /system backup save dont-encrypt\
=yes name=(\$sfname.\".backup\") }\r\r\
\n :log info message=\"System Backup Finished\"\r\r\
\n}\r\r\
\nif (\$saveRawExport) do={\r\r\
\n /export file=(\$sfname.\".rsc\")\r\r\
\n :log info message=\"Raw configuration script export Finished\"\r\r\
\n}\r\r\
\n:delay 10s\r\r\
\n:local backupFileName \"\"\r\r\
\n:local backupDestPath \"\"\r\r\
\n:foreach backupFile in=[/file find] do={\r\r\
\n :set backupFileName (\"/\".[/file get \$backupFile name])\r\r\
\n :set backupDestPath (\$FTPdest.\$backupFileName)\r\r\
\n :if ([:typeof [:find \$backupFileName \$sfname]] != \"nil\") do={\r\r\
\n # :log warning message=\"/tool fetch address=\$FTPServer port=\$FTPPor\
t src-path=\$backupFileName user=\$FTPUser mode=ftp password=\$FTPPass dst\
-path=\$backupDestPath upload=yes\"\r\r\
\n\r\r\
\n /tool fetch address=\$FTPServer port=\$FTPPort src-path=\$backupFile\
Name user=\$FTPUser mode=ftp password=\$FTPPass dst-path=\$backupDestPath \
upload=yes\r\r\
\n }\r\r\
\n}\r\r\
\n:delay 10s\r\r\
\n:foreach backupFile in=[/file find] do={\r\r\
\n :if ([:typeof [:find [/file get \$backupFile name] \"BACKUP-\"]]!=\"ni\
l\") do={\r\r\
\n /file remove \$backupFile\r\r\
\n }\r\r\
\n}\r\r\
\n\r\r\
\n:log info message=\"Successfully removed Temporary Backup Files\"\r\r\
\n:log info message=\"Automatic Backup Completed Successfully\""
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
/tool netwatch
add down-script=":local CurDate [/system clock get date];\r\
\n:local CurTime [/system clock get time];\r\
\n:log err (\"Internet Connection is DOWN - \".[:tostr \$CurDate].\"\
\_- \".[:tostr \$CurTime]);\r\
\n#Set the monitored IP address\r\
\n:local addre 8.8.8.8;\r\
\n\r\
\n:local int;\r\
\n:local RouterName; #identity\r\
\n:local RouterVer; #version\r\
\n:local RouterUP; #uptime\r\
\n\r\
\n:local Themes \"Work Rehab Paddington Monitor \$RouterName - Connection \
UP - IP: \$addre\";\r\
\n\r\
\n#Set the delay\r\
\n:local ms 2;\r\
\n:local avgRtt;\r\
\n:local pin\r\
\n:local pout\r\
\n/tool flood-ping \$addre count=10 do={\r\
\n :if (\$sent = 10) do={\r\
\n :set avgRtt \$\"avg-rtt\"\r\
\n :set pout \$sent\r\
\n :set pin \$received\r\
\n }\r\
\n}\r\
\n\r\
\n:local ploss (100 - ((\$pin * 100) / \$pout))\r\
\n:local logmsg (\"Ping Average for \".[:tostr \$addre].\" - \".[:tostr \$\
avgRtt].\"ms - packet loss: \".[:tostr \$ploss].\"%\")\r\
\n:log warning \$logmsg\r\
\n\r\
\n:delay 10s\r\
\n:set addre 61.69.66.246;\r\
\n/tool flood-ping \$addre count=10 do={\r\
\n :if (\$sent = 10) do={\r\
\n :set avgRtt \$\"avg-rtt\"\r\
\n :set pout \$sent\r\
\n :set pin \$received\r\
\n }\r\
\n}\r\
\n\r\
\n:local ploss (100 - ((\$pin * 100) / \$pout))\r\
\n:local logmsg (\"Ping Average for \".[:tostr \$addre].\" - \".[:tostr \$\
avgRtt].\"ms - packet loss: \".[:tostr \$ploss].\"%\")\r\
\n:log warning \$logmsg\r\
\n\r\
\n:delay 10s\r\
\n:set addre 61.69.66.245;\r\
\n/tool flood-ping \$addre count=10 do={\r\
\n :if (\$sent = 10) do={\r\
\n :set avgRtt \$\"avg-rtt\"\r\
\n :set pout \$sent\r\
\n :set pin \$received\r\
\n }\r\
\n}\r\
\n\r\
\n:local ploss (100 - ((\$pin * 100) / \$pout))\r\
\n:local logmsg (\"Ping Average for \".[:tostr \$addre].\" - \".[:tostr \$\
avgRtt].\"ms - packet loss: \".[:tostr \$ploss].\"%\")\r\
\n:log warning \$logmsg\r\
\n\r\
\n:local NeighborList [/ip neighbor print detail];\r\
\n\r\
\n:log err \"Connection to Internet is DOWN <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<\
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<\"; \r\
\n" host=8.8.8.8 up-script=":local CurDate [/system clock get date];\r\
\n:local CurTime [/system clock get time];\r\
\n:log err (\"Internet Connection is UP - \".[:tostr \$CurDate].\" -\
\_\".[:tostr \$CurTime]);\r\
\n#Set the monitored IP address Below\r\
\n:local addre 8.8.8.8;\r\
\n\r\
\n:local int;\r\
\n:local RouterName; #identity\r\
\n:local RouterVer; #version\r\
\n:local RouterUP; #uptime\r\
\n\r\
\n\r\
\n#:log err \"RouterName= /system/identity get value-name=name\";\r\
\n#:log err \"RouterVer= \$RouterVer\";\r\
\n#:log err \"RouterUP= \$RouterUP\";\r\
\n\r\
\n:local Themes \"Work Rehab Paddington Monitor \$RouterName - Connection \
UP - IP: \$addre\";\r\
\n#:log err \"START Monitor UP\";\r\
\n\r\
\n#Set the delay\r\
\n:local ms 2;\r\
\n:local avgRtt;\r\
\n:local pin\r\
\n:local pout\r\
\n/tool flood-ping \$addre count=10 do={\r\
\n :if (\$sent = 10) do={\r\
\n :set avgRtt \$\"avg-rtt\"\r\
\n :set pout \$sent\r\
\n :set pin \$received\r\
\n }\r\
\n}\r\
\n#:log err \"START Monitor UP\";\r\
\n\r\
\n:local ploss (100 - ((\$pin * 100) / \$pout))\r\
\n:local logmsg (\"Ping Average for \".[:tostr \$addre].\" - \".[:tostr \$\
avgRtt].\"ms - packet loss: \".[:tostr \$ploss].\"%\")\r\
\n:log warning \$logmsg\r\
\n\r\
\n:delay 10s\r\
\n:set addre 61.69.66.246;\r\
\n/tool flood-ping \$addre count=10 do={\r\
\n :if (\$sent = 10) do={\r\
\n :set avgRtt \$\"avg-rtt\"\r\
\n :set pout \$sent\r\
\n :set pin \$received\r\
\n }\r\
\n}\r\
\n\r\
\n:local ploss (100 - ((\$pin * 100) / \$pout))\r\
\n:local logmsg (\"Ping Average for \".[:tostr \$addre].\" - \".[:tostr \$\
avgRtt].\"ms - packet loss: \".[:tostr \$ploss].\"%\")\r\
\n:log warning \$logmsg\r\
\n\r\
\n:delay 10s\r\
\n:set addre 61.69.66.245;\r\
\n/tool flood-ping \$addre count=10 do={\r\
\n :if (\$sent = 10) do={\r\
\n :set avgRtt \$\"avg-rtt\"\r\
\n :set pout \$sent\r\
\n :set pin \$received\r\
\n }\r\
\n}\r\
\n\r\
\n:local ploss (100 - ((\$pin * 100) / \$pout))\r\
\n:local logmsg (\"Ping Average for \".[:tostr \$addre].\" - \".[:tostr \$\
avgRtt].\"ms - packet loss: \".[:tostr \$ploss].\"%\")\r\
\n:log warning \$logmsg\r\
\n\r\
\n:local NeighborList [/ip neighbor print];\r\
\n\r\
\n:log err \"Connection to Internet is Back UP\"; \r\
\n\r\
\n:log info \"\$NeighborList\";\r\
\n\r\
\n"