# version: 7.21.3 (stable) # factory-software: 7.15 # total-memory: 4096.0MiB # cpu: ARM64 # cpu-count: 4 # total-hdd-space: 128.0MiB # architecture-name: arm64 # board-name: CCR2004-16G-2S+ # platform: MikroTik # installed-version: 7.21.3 # Flags: U - UNDOABLE # Columns: ACTION, BY, POLICY, TIME # ACTION BY POLICY TIME # U ip service changed MEXICARRIER write 2026-07-31 16:07:58 # U ip service changed MEXICARRIER write 2026-07-31 16:07:52 # U address list entry removed apy_python write 2026-07-29 17:42:07 # U filter rule removed apy_python write 2026-07-29 17:42:00 # U address list entry added apy_python write 2026-07-29 17:38:07 # U filter rule added apy_python write 2026-07-29 17:37:58 # U address list entry removed apy_python write 2026-07-29 15:45:53 # U filter rule removed apy_python write 2026-07-29 15:45:49 # U address list entry added apy_python write 2026-07-29 15:41:00 # U filter rule added apy_python write 2026-07-29 15:40:56 # U address list entry removed apy_python write 2026-07-28 00:44:47 # U filter rule removed apy_python write 2026-07-28 00:44:41 # U address list entry added apy_python write 2026-07-28 00:42:10 # U filter rule added apy_python write 2026-07-28 00:42:04 # U address changed MEXICARRIER write 2026-07-27 11:48:40 # U device removed MEXICARRIER write 2026-07-27 11:47:29 # U bridge port removed MEXICARRIER write 2026-07-27 11:47:25 # U filter rule removed apy_python write 2026-07-27 00:16:56 # U filter rule added apy_python write 2026-07-27 00:11:18 # U dhcp lease changed Cris_net write 2026-07-27 00:08:52 # U dhcp lease changed Cris_net write 2026-07-27 00:08:31 # U address list entry removed apy_python write 2026-07-26 19:12:06 # U filter rule removed apy_python write 2026-07-26 19:12:01 # U address list entry added apy_python write 2026-07-26 19:10:11 # U filter rule added apy_python write 2026-07-26 19:10:04 # U address list entry removed apy_python write 2026-07-26 18:02:41 # U filter rule removed apy_python write 2026-07-26 18:02:35 # U address list entry added apy_python write 2026-07-26 17:58:20 # U filter rule added apy_python write 2026-07-26 17:58:15 # U address list entry removed apy_python write 2026-07-26 17:17:49 # U filter rule removed apy_python write 2026-07-26 17:17:42 # U address list entry added apy_python write 2026-07-26 17:06:38 # U filter rule added apy_python write 2026-07-26 17:06:29 # U device changed MEXICARRIER write 2026-07-26 10:16:48 # U address list entry removed apy_python write 2026-07-26 00:57:45 # U filter rule removed apy_python write 2026-07-26 00:57:38 # U address list entry added apy_python write 2026-07-26 00:54:21 # U filter rule added apy_python write 2026-07-26 00:54:13 # U filter rule added Cris_net write 2026-07-26 00:39:56 # U ip service changed Cris_net write 2026-07-26 00:39:44 # U address list entry removed apy_python write 2026-07-26 00:27:43 # U filter rule removed apy_python write 2026-07-26 00:27:38 # U address list entry added apy_python write 2026-07-26 00:20:56 # U filter rule added apy_python write 2026-07-26 00:20:49 # U address list entry removed Cris_net write 2026-07-25 21:44:35 # U dhcp lease changed Cris_net write 2026-07-25 20:14:40 # U dhcp lease changed Cris_net write 2026-07-25 12:25:15 # U dhcp lease changed Cris_net write 2026-07-25 12:22:41 # U dhcp lease changed apy_python write 2026-07-25 12:10:11 # U dhcp lease changed apy_python write 2026-07-25 12:02:25 # U device changed MEXICARRIER write 2026-07-25 11:56:20 # U bridge port changed MEXICARRIER write 2026-07-25 11:52:43 # U device changed MEXICARRIER write 2026-07-25 11:52:13 # U bridge port changed MEXICARRIER write 2026-07-25 11:52:07 # U bridge port added MEXICARRIER write 2026-07-25 11:51:56 # U device added MEXICARRIER write 2026-07-25 11:51:50 # U address changed MEXICARRIER write 2026-07-25 11:51:43 # U item changed MEXICARRIER write 2026-07-25 11:47:29 # U dhcp lease changed apy_python write 2026-07-25 11:29:11 # U dhcp lease changed apy_python write 2026-07-25 11:29:05 # U dhcp lease changed apy_python write 2026-07-25 11:26:01 # U dhcp lease changed apy_python write 2026-07-25 11:25:56 # U dhcp lease changed apy_python write 2026-07-25 11:25:44 # U dhcp lease changed apy_python write 2026-07-25 11:25:39 # U dhcp lease changed apy_python write 2026-07-25 11:25:29 # U dhcp lease changed apy_python write 2026-07-25 11:25:23 # U dhcp lease changed apy_python write 2026-07-25 11:25:13 # U dhcp lease changed apy_python write 2026-07-25 11:25:08 # U dhcp lease changed apy_python write 2026-07-25 11:24:56 # U dhcp lease changed apy_python write 2026-07-25 11:24:50 # U dhcp lease changed apy_python write 2026-07-25 11:24:40 # U dhcp lease changed apy_python write 2026-07-25 11:24:34 # U dhcp lease changed apy_python write 2026-07-25 11:24:25 # U dhcp lease changed apy_python write 2026-07-25 11:24:19 # U dhcp lease changed apy_python write 2026-07-25 11:24:09 # U dhcp lease changed apy_python write 2026-07-25 11:24:04 # U dhcp lease changed apy_python write 2026-07-25 11:21:43 # U dhcp lease changed apy_python write 2026-07-25 11:21:37 # U dhcp lease changed apy_python write 2026-07-25 11:21:27 # U dhcp lease changed apy_python write 2026-07-25 11:21:22 # U dhcp lease changed apy_python write 2026-07-25 11:21:12 # U dhcp lease changed apy_python write 2026-07-25 11:21:06 # U dhcp lease changed apy_python write 2026-07-25 11:20:56 # U dhcp lease changed apy_python write 2026-07-25 11:20:50 # U dhcp lease changed apy_python write 2026-07-25 11:20:37 # U dhcp lease changed apy_python write 2026-07-25 11:20:31 # U dhcp lease changed apy_python write 2026-07-25 11:20:13 # U dhcp lease changed apy_python write 2026-07-25 11:20:08 # U dhcp lease changed apy_python write 2026-07-25 11:12:24 # U dhcp lease changed apy_python write 2026-07-25 11:12:20 # U dhcp lease changed Cris_net write 2026-07-25 11:11:53 # U dhcp lease changed Cris_net write 2026-07-25 11:11:27 # U dhcp lease changed apy_python write 2026-07-25 11:00:53 # U dhcp lease changed apy_python write 2026-07-25 11:00:51 # U dhcp lease changed apy_python write 2026-07-25 11:00:40 # U dhcp lease changed apy_python write 2026-07-25 11:00:38 # U dhcp lease changed apy_python write 2026-07-25 10:31:36 # U dhcp lease changed apy_python write 2026-07-25 10:31:35 # U dhcp lease changed apy_python write 2026-07-25 10:28:42 # U dhcp lease changed apy_python write 2026-07-25 10:28:41 # # software id = QF70-RRAH # # model = CCR2004-16G-2S+ # serial number = HGV0AD93S4A /interface bridge add admin-mac=F4:1E:57:15:6A:AC auto-mac=no name=BRIDGE-LAN /interface ethernet set [ find default-name=ether1 ] comment="IP: 172.20.4.39" name="ether1-WAN BONIXI" set [ find default-name=ether2 ] comment="IP: 172.20.4.158" name="ether2-WAN SAN MARTIN" set [ find default-name=ether3 ] comment="IP: 192.168.8.16" name="ether3-PALOS AMARILLOS" set [ find default-name=ether4 ] comment="IP: 192.168.8.14" name="ether4-PRISMA 5AC CENTRO" set [ find default-name=ether5 ] comment="IP: 192.168.8.102" name=ether5-OLT1 set [ find default-name=ether6 ] comment=IP:192.168.1.22 name="ether6 SEC_M2" set [ find default-name=ether8 ] comment="DVR CASA" name="ether8 DVR" set [ find default-name=sfp-sfpplus1 ] comment="IP: 192.168.8.101" name=sfp-sfpplus1-OLT2 set [ find default-name=sfp-sfpplus2 ] comment="IP: 192.168.8.100" name=sfp-sfpplus2-OLT3 /interface wireguard add listen-port=21960 mtu=1420 name=TUNEL_SERVIDOR private-key="EAt9pJC9keNPS1MATFoMGDQZ5n9JAkq42+szJv8A0V8=" add listen-port=13231 mtu=1420 name=VPN_YEBUCIVI private-key="uG5uD/TRsYM9pfn2ZV09fYGpx3J3/6T99RtMhZ8DhH4=" /ip pool add name=dhcp_pool0 ranges=172.21.0.20-172.21.10.254 /ip dhcp-server add address-pool=dhcp_pool0 interface=BRIDGE-LAN lease-time=10m name=dhcp1 /snmp community add addresses=0.0.0.0/0 name=SNMP-SOMNET /system logging action add name=GrafanaLoki remote=172.20.0.254 remote-log-format=syslog remote-port=1514 src-address=172.20.1.24 target=remote /interface bridge port add bridge=BRIDGE-LAN interface=sfp-sfpplus2-OLT3 add bridge=BRIDGE-LAN interface="ether3-PALOS AMARILLOS" add bridge=BRIDGE-LAN interface="ether4-PRISMA 5AC CENTRO" add bridge=BRIDGE-LAN interface=ether5-OLT1 add bridge=BRIDGE-LAN interface="ether6 SEC_M2" add bridge=BRIDGE-LAN interface="ether8 DVR" add bridge=BRIDGE-LAN interface=sfp-sfpplus1-OLT2 add bridge=BRIDGE-LAN interface=ether16 add bridge=*17 interface="ether2-WAN SAN MARTIN" /interface wireguard peers add allowed-address=172.23.1.2/32 client-allowed-address=::/0 client-dns=8.8.8.8 interface=VPN_YEBUCIVI name=LB public-key="F+EqFLRbExnFBEh0xt0ec6IWOhIJj/+5HpOwKVYHsDA=" add allowed-address=172.23.1.3/32 client-dns=8.8.8.8 interface=VPN_YEBUCIVI name=LC public-key="gCv9NMEmSMNpX1ew3siFqbkiv8cHMRQJ+nonjkA59Ek=" add allowed-address=172.23.1.4/32 client-dns=8.8.8.8 interface=VPN_YEBUCIVI name=CC public-key="ug2eNpbbmpdgHf3tqQBOIAZ82UIG6qxrZl253JkfXBg=" add allowed-address=172.23.1.6/32 client-dns=8.8.8.8 interface=VPN_YEBUCIVI name="iPhone Cristian" public-key="A8yhm/Wd/XpblKQISAvgI117Y7jiNhf7/V+h1GAzNBA=" add allowed-address=172.23.1.5/32 client-dns=1.1.1.3 interface=VPN_YEBUCIVI name=LB2 public-key="+Us94DyXl7q+JWgG01FzRvOtGTCB2nyAQKkxPmUSZAk=" add allowed-address=172.23.1.40/32 client-allowed-address=::/0 client-dns=1.1.1.1 interface=VPN_YEBUCIVI name="To\F1o" public-key="KsMkLxhlTBfeSztxY2qVDqOhA4HOJ0FDUsVamSJ1nk0=" add allowed-address=0.0.0.0/0 client-allowed-address=::/0 endpoint-address=69.164.199.205 endpoint-port=51820 interface=TUNEL_SERVIDOR name=CONEXION_SERVIDOR persistent-keepalive=25s public-key="ir2CFhs+8ELkS8FggPpyoqcDU52pcG+BqFNr7CWp0hE=" /ip address add address=192.168.8.1/24 comment="LAN YEBUCIVI" interface=BRIDGE-LAN network=192.168.8.0 add address=172.21.0.1/16 comment="Server DHCP" interface=BRIDGE-LAN network=172.21.0.0 add address=192.168.40.1/24 comment="GW Palos Amarillos" interface=BRIDGE-LAN network=192.168.40.0 add address=38.58.38.37/24 comment="WAN2 SAN MARTIN" interface="ether2-WAN SAN MARTIN" network=38.58.38.0 add address=38.123.220.40/24 comment="WAN BONIXI" interface="ether1-WAN BONIXI" network=38.123.220.0 add address=172.20.1.24/16 comment=REDUNDANCIA interface="ether1-WAN BONIXI" network=172.20.0.0 add address=172.23.1.1/24 comment=VPN interface=VPN_YEBUCIVI network=172.23.1.0 add address=10.8.0.2/24 comment=IP_SERVIDOR interface=TUNEL_SERVIDOR network=10.8.0.0 /ip dhcp-server lease add client-id="CRISTIAN ENRIQUEZ GARDUNO" mac-address=88:C2:27:BE:48:A1 add client-id=KARINAENRIQUEZ mac-address=78:DD:33:20:3F:FF /ip dhcp-server network add address=172.21.0.0/16 dns-server=1.1.1.0,1.0.0.1 gateway=172.21.0.1 /ip dns set servers=1.1.1.2,1.0.0.2 /ip firewall filter add action=drop chain=forward src-address-list=MOROSOS add action=accept chain=input dst-port=22 protocol=tcp src-address=10.8.0.0/24 add action=drop chain=input comment=BLOQUEAR_SSH_FUERA_VPN dst-port=22 protocol=tcp /ip firewall nat add action=masquerade chain=srcnat out-interface="ether1-WAN BONIXI" add action=masquerade chain=srcnat out-interface="ether2-WAN SAN MARTIN" add action=redirect chain=dstnat comment="Segundo puerto SSH" dst-port=22 protocol=tcp to-ports=46825 /ip route add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=38.123.220.1 routing-table=main scope=30 target-scope=10 add disabled=no distance=10 dst-address=0.0.0.0/0 gateway=172.20.1.1 routing-table=main scope=30 target-scope=10 add check-gateway=ping disabled=no dst-address=0.0.0.0/0 gateway=38.58.38.1 routing-table=main /ip service set ftp disabled=yes set telnet disabled=yes set www port=8080 set api disabled=yes set api-ssl disabled=yes set ssh address=10.8.0.0/24,172.20.0.254/32 port=46825 /radius add address=172.20.6.1 secret=Fr3eR4d!u5 service=login /snmp set enabled=yes trap-community=SNMP-SOMNET /system clock set time-zone-name=America/Mexico_City /system identity set name=RT-YRBUCIVI /system logging add action=GrafanaLoki prefix=172.20.1.24 topics=error add action=GrafanaLoki prefix=172.20.1.24 topics=critical add action=GrafanaLoki prefix=172.20.1.24 topics=info add action=GrafanaLoki prefix=172.20.1.24 topics=warning /system ntp client servers add address=0.mx.pool.ntp.org add address=1.mx.pool.ntp.org /system routerboard settings set enter-setup-on=delete-key /tool graphing interface add /tool graphing resource add /tool sniffer set file-name=yebucivi.cap filter-direction=rx filter-interface=ether7 /user aaa set default-group=full use-radius=yes