# version: 7.23.2 (stable) # factory-software: 7.18 # total-memory: 32.0GiB # cpu: ARM64 # cpu-count: 16 # total-hdd-space: 128.0MiB # architecture-name: arm64 # board-name: ROSE Data Server # platform: MikroTik # installed-version: 7.23.2 # Flags: U - UNDOABLE # Columns: ACTION, BY, POLICY, TIME # ACTION BY POLICY TIME # U device changed brayan write 2026-08-17 14:01:01 # U device changed brayan write 2026-08-17 14:00:55 # U device changed brayan write 2026-08-17 14:00:50 # U device changed brayan write 2026-08-17 13:58:02 # U device changed brayan write 2026-08-17 13:56:45 # U address changed brayan write 2026-08-17 13:55:28 # U device added brayan write 2026-08-17 13:54:48 # U bridge port removed brayan write 2026-08-17 13:42:11 # U bridge port changed brayan write 2026-08-17 13:42:11 # U bridge port changed brayan write 2026-08-17 13:42:10 # U device changed brayan write 2026-08-17 13:40:57 # U device changed brayan write 2026-08-17 13:40:54 # U bridge port added brayan write 2026-08-17 13:40:11 # U bridge port removed brayan write 2026-08-15 16:43:27 # U device changed brayan write 2026-08-15 16:43:23 # U nat rule changed brayan write 2026-08-15 16:42:35 # U device changed brayan write 2026-08-15 16:35:54 # U bridge port removed brayan write 2026-08-14 10:45:02 # U device changed brayan write 2026-08-14 10:44:58 # U bridge port removed brayan write 2026-08-14 10:21:06 # U device changed brayan write 2026-08-14 10:14:44 # U bridge port removed brayan write 2026-08-12 15:00:46 # U device changed MEXICARRIER write 2026-08-12 14:39:18 # U route 148.215.0.0/16 changed brayan write 2026-08-10 13:30:09 # U address list entry changed brayan write 2026-08-10 13:29:51 # U to-administrativo changed brayan write 2026-08-10 13:28:38 # U to-administrativo changed brayan write 2026-08-10 10:54:43 # U address list entry changed brayan write 2026-08-10 10:54:19 # U to-cirion changed brayan write 2026-08-10 10:46:31 # U to-administrativo changed brayan write 2026-08-10 10:44:56 # U to-administrativo changed brayan write 2026-08-10 10:44:40 # U to-administrativo changed brayan write 2026-08-10 10:43:56 # U route 148.215.0.0/16 added brayan write 2026-08-10 10:40:20 # U address list entry changed brayan write 2026-08-08 14:38:48 # U to-administrativo changed brayan write 2026-08-08 14:17:10 # U to-administrativo changed brayan write 2026-08-08 14:07:09 # U address list entry changed brayan write 2026-08-08 14:05:56 # U to-administrativo changed brayan write 2026-08-08 14:01:56 # U filter-rule-4 added brayan write 2026-08-08 14:01:21 # U to-administrativo changed brayan write 2026-08-08 13:59:22 # U to-administrativo changed brayan write 2026-08-08 13:57:51 # U address list entry added brayan write 2026-08-08 13:57:10 # U address removed brayan write 2026-08-07 17:46:37 # U address changed brayan write 2026-08-07 17:46:36 # U device removed brayan write 2026-08-07 17:46:26 # U address added brayan write 2026-08-07 17:42:51 # U device added brayan write 2026-08-07 17:42:34 # U ntp settings changed MEXICARRIER write 2026-07-21 10:51:00 # U log rule added MEXICARRIER write 2026-07-21 10:49:43 # U log rule added MEXICARRIER write 2026-07-21 10:49:18 # U log rule added MEXICARRIER write 2026-07-21 10:49:04 # U log rule added MEXICARRIER write 2026-07-21 10:48:50 # U log action added MEXICARRIER write 2026-07-21 10:48:32 # U RADIUS client changed MEXICARRIER write 2026-07-21 10:47:33 # U device changed MEXICARRIER write 2026-07-20 14:35:21 # U route 172.23.1.0/24 removed MEXICARRIER write 2026-07-17 17:42:03 # U route 172.23.1.0/24 changed MEXICARRIER write 2026-07-17 17:41:32 # U route 172.23.1.0/24 added MEXICARRIER write 2026-07-17 17:39:29 # U device changed MEXICARRIER write 2026-07-17 12:28:30 # U ip service changed MEXICARRIER write 2026-07-17 10:28:49 # # software id = 572X-23F7 # # model = RDS2216-2XG-4S+4XS-2XQ # serial number = HJB0A9RJ881 /disk set nvme2 slot=nvme2 set nvme4 slot=nvme4 set nvme5 slot=nvme5 set nvme6 slot=nvme6 set nvme7 slot=nvme7 set nvme8 slot=nvme8 set nvme9 slot=nvme9 set nvme10 slot=nvme10 set nvme11 slot=nvme11 set nvme12 slot=nvme12 set nvme13 slot=nvme13 set nvme14 slot=nvme14 set nvme15 slot=nvme15 set nvme16 slot=nvme16 set nvme17 slot=nvme17 set nvme18 slot=nvme18 set nvme19 slot=nvme19 set nvme20 slot=nvme20 /interface bridge add mtu=1500 name="BRIDGE-AS273304 LAN" priority=0 add name=BRIDGE-CONTAINERS /interface ethernet set [ find default-name=ether1 ] name=ether1-PC-PRUEBAS set [ find default-name=mgmt1 ] name=ether3-AP-UNIFI set [ find default-name=qsfp28-1-1 ] advertise="10M-baseT-half,10M-baseT-full,100M-baseT-half,100M-baseT-full,1G-baseT-half,1G-baseT-full,1G-baseX,2.5G-baseT,2.5G-baseX,5G-baseT,10G-baseT,10G-baseSR-LR,10G-baseCR,40G-baseSR4-LR4,40G-baseCR4,25G-baseSR-LR,25G-baseCR,50G-baseSR2-LR2,50G-baseCR2,100G-baseSR4-LR4,100G-baseCR4" fec-mode=fec91 name="qsfp28-1-1-ARISTA OFICINA" set [ find default-name=qsfp28-1-3 ] advertise="10M-baseT-half,10M-baseT-full,100M-baseT-half,100M-baseT-full,1G-baseT-half,1G-baseT-full,1G-baseX,2.5G-baseT,2.5G-baseX,5G-baseT,10G-baseT,10G-baseSR-LR,10G-baseCR,40G-baseSR4-LR4,40G-baseCR4,25G-baseSR-LR,25G-baseCR,50G-baseSR2-LR2,50G-baseCR2" set [ find default-name=qsfp28-2-1 ] auto-negotiation=no speed=40G-baseCR4 set [ find default-name=qsfp28-2-3 ] advertise="10M-baseT-half,10M-baseT-full,100M-baseT-half,100M-baseT-full,1G-baseT-half,1G-baseT-full,1G-baseX,2.5G-baseT,2.5G-baseX,5G-baseT,10G-baseT,10G-baseSR-LR,10G-baseCR,40G-baseSR4-LR4,40G-baseCR4,25G-baseSR-LR,25G-baseCR,50G-baseSR2-LR2,50G-baseCR2" set [ find default-name=sfp-sfpplus1 ] name="sfp-sfpplus1-WAN1 CRS504" set [ find default-name=sfp-sfpplus2 ] name="sfp-sfpplus2-WAN2 CRS504" set [ find default-name=sfp-sfpplus3 ] name="sfp-sfpplus3-WAN3 CRS504" set [ find default-name=sfp-sfpplus4 ] auto-negotiation=no name="sfp-sfpplus4-SERVIDOR DELL" set [ find default-name=sfp28-1 ] auto-negotiation=no speed=10G-baseCR set [ find default-name=sfp28-2 ] auto-negotiation=no name="sfp28-2-PE\C3\91UELA" speed=10G-baseCR set [ find default-name=sfp28-4 ] name="sfp28-4-SAN MARTIN ASN" /interface eoip add local-address=201.234.96.54 mac-address=02:F7:12:E5:B5:CC name=eoip-tunnel-atlaco remote-address=148.224.57.21 tunnel-id=1 add local-address=38.104.249.75 mac-address=02:15:83:74:FE:AF name=eoip-tunnel-core remote-address=38.58.38.200 tunnel-id=2 /interface veth add address=172.17.0.2/24 container-mac-address=66:A7:2B:0E:96:B4 dhcp=no gateway=172.17.0.1 gateway6="" mac-address=64:D8:BC:B3:9A:D4 name=veth1-unifi /interface vlan add interface="BRIDGE-AS273304 LAN" name="vlan13-Residenciales Toluca" vlan-id=13 add interface="BRIDGE-AS273304 LAN" name=vlan111-Capacitacion vlan-id=111 /interface bonding add lacp-rate=1sec mode=802.3ad name=LACP-100GCirion slaves="sfp-sfpplus2-WAN2\_CRS504,sfp-sfpplus3-WAN3 CRS504,sfp-sfpplus1-WAN1 CRS504" transmit-hash-policy=layer-2-and-3 /container add comment="Controlador Unifi" dns=1.1.1.1 envlists=1 healthcheck-status="good, output: HTTP/1.1 302 \r\nLocation: /manage\r\nDate: Wed, 19 Aug 2026 18:51:33 GMT\r\n\r\nHTTP/1.1 302 \r\nLocation: /manage/account/login\?redirect=%2Fmanage\r\nDate: Wed, 19 Aug 2026 18:51:33 GMT\r\n\r\nHTTP/1.1 200 \r\nX-Frame-Options: SAMEORIGIN\r\nAccept-Ranges: bytes\r\nLast-Modified: Tue, 02 Dec 2025 10:08:55 GMT\r\nCache-Control: max-age=0\r\nExpires: Wed, 19 Aug 2026 18:51:33 GMT\r\nContent-Type: text/html;charset=ISO-8859-1\r\nContent-Length: 1088\r\nDate: Wed, 19 Aug 2026 18:51:33 GMT\r\n\r\n" interface=veth1-unifi layer-dir="" logging=yes mount=/nvme1/unify_data:/1:rw,/nvme1/unify_log:/1:rw name=unifi:latest remote-image=jacobalberty/unifi:latest root-dir=/nvme1/unify_root shm-size=512.0MiB start-on-boot=yes workdir=/unifi /interface vlan add interface=LACP-100GCirion name="vlan1200-WAN CIRION" vlan-id=1200 /ip pool add name=dhcp_pool0 ranges=172.18.0.20-172.18.0.254 add name=dhcp_pool1 ranges=172.17.13.20-172.17.13.254 add name=dhcp_pool2 ranges=172.17.111.20-172.17.111.254 /ip dhcp-server add address-pool=dhcp_pool0 interface=BRIDGE-CONTAINERS name=Ap-Unifi add address-pool=dhcp_pool1 interface="vlan13-Residenciales Toluca" lease-time=10m name="Residenciales Toluca" add address-pool=dhcp_pool2 interface=vlan111-Capacitacion lease-time=10m name="Capacitaci\F3n" /routing bgp instance add as=273304 disabled=no name=AS27334 router-id=172.20.100.1 /snmp community set [ find default=yes ] name=SNMP-SOMNET /system logging action add name=GrafanaLoki remote=172.20.0.254 remote-log-format=syslog remote-port=1514 src-address=172.20.100.1 target=remote /app set cinny firewall-redirects=8094:80:tcp:web set goaway container-command-lines=goaway:none:docker.io/pommee/goaway:latest set home-assistant container-command-lines=home-assistant:none:lscr.io/linuxserver/homeassistant set lorawan-stack secrets="lorawan-stack__admin_password:=" set n8n firewall-redirects=5678:5678:tcp:web set nextcloud container-command-lines="db:none:docker.io/postgres:17,redis:none:docker.io/valkey/valkey:/bin/sh -c 'valkey-server --port 6379 --appendonly yes --requirepass \$VALKEY_PASSWORD',server:none:docker.io/nextcloud:apache" set pihole environment="pihole:FTLCONF_dns_listeningMode=all,pihole:FTLCONF_webserver_api_password=password" set redlib firewall-redirects=8087:8080:tcp:web set solr container-command-lines=solr:none:docker.io/solr:latest set uptime-kuma container-command-lines=uptime-kuma:none:docker.io/louislam/uptime-kuma:1 set zulip secrets="zulip__postgres_password:=,zulip__memcached_password:=,zulip__rabbitmq_password:=,zulip__redis_password:=,zulip__secret_key:=,zulip__email_password:=" /container config set registry-url=https://registry-1.docker.io tmpdir=/nvme1/tmp /container envs add key=TZ list=openbpmn_env value=America/Mexico_City add key=TZ list=unify_env value=America/Mexico_City /container mounts add dst="/dst=/usr/src/app/open-bpmn.glsp-client/workspace" list=openbpmn_workspace src=/nvme1/openbpmn_workspace add dst=/etc/raddb list=radius_config src=/nvme1/radius_config add dst=/var/log/radius list=radius_log src=/nvme1/radius_log add dst=/unifi/data list=unify_data src=/nvme1/unify_data add dst=/unifi/log list=unify_log src=/nvme1/unify_log /interface bridge port add bridge=BRIDGE-CONTAINERS interface=veth1-unifi add bridge="BRIDGE-AS273304 LAN" interface=ether1-PC-PRUEBAS add bridge="BRIDGE-AS273304 LAN" interface=eoip-tunnel-atlaco add bridge="BRIDGE-AS273304 LAN" interface="sfp-sfpplus4-SERVIDOR DELL" add bridge="BRIDGE-AS273304 LAN" edge=yes interface=eoip-tunnel-core path-cost=20000 add bridge=BRIDGE-CONTAINERS interface=ether3-AP-UNIFI add bridge="BRIDGE-AS273304 LAN" interface="sfp28-4-SAN MARTIN ASN" add auto-isolate=yes bridge="BRIDGE-AS273304 LAN" interface="qsfp28-1-1-ARISTA OFICINA" add bridge="BRIDGE-AS273304 LAN" interface="sfp28-2-PE\C3\91UELA" /interface bridge settings set use-ip-firewall=yes /ip neighbor discovery-settings set discover-interface-list=all /ipv6 settings set disable-ipv6=yes /ip address add address=172.17.0.1/24 comment="Segmento Containers" interface=BRIDGE-CONTAINERS network=172.17.0.0 add address=172.18.0.1/24 comment="DHCP AP unifi" interface=BRIDGE-CONTAINERS network=172.18.0.0 add address=38.58.38.1/24 comment="LAN MEXICARRIER" interface="BRIDGE-AS273304 LAN" network=38.58.38.0 add address=38.104.249.75/29 comment="IP Peer Cogent" interface=LACP-100GCirion network=38.104.249.72 add address=201.234.96.54/27 comment="IP Peer Cirion" interface="vlan1200-WAN CIRION" network=201.234.96.32 add address=172.30.1.1/16 comment="LAN Privada " interface="BRIDGE-AS273304 LAN" network=172.30.0.0 add address=172.20.100.1/16 comment="IP ADMINISTRACI\D3N" interface="sfp-sfpplus1-WAN1 CRS504" network=172.20.0.0 add address=172.18.18.1/24 comment="Management Arista" interface="BRIDGE-AS273304 LAN" network=172.18.18.0 add address=172.17.13.1/24 comment="Residenciales Toluca" interface="vlan13-Residenciales Toluca" network=172.17.13.0 add address=172.17.111.1/24 comment="Capacitaci\F3n" interface=vlan111-Capacitacion network=172.17.111.0 /ip cloud set ddns-enabled=yes /ip dhcp-server network add address=172.17.13.0/24 gateway=172.17.13.1 add address=172.17.111.0/24 gateway=172.17.111.1 add address=172.18.0.0/24 gateway=172.18.0.1 /ip dns set servers=1.0.0.2,1.1.1.2 /ip firewall address-list add address=189.138.129.159 comment="Mi IP Actual" list=Lista_Blanca add address=38.58.38.0/24 list=AS273304 add address=148.215.0.0/16 disabled=yes list=AS273304 /ip firewall filter add action=accept chain=output comment="PERMITIR EOIP" protocol=gre /ip firewall mangle add action=change-mss chain=forward comment="fragmentar paquetes mss" disabled=yes new-mss=1380 passthrough=no protocol=tcp tcp-flags=syn /ip firewall nat add action=masquerade chain=srcnat comment="Container Unifi y VLAN's Salida a Internet" src-address=172.17.0.0/16 add action=masquerade chain=srcnat comment="AP Unifi Salida a Internet" src-address=172.18.0.0/24 /ip route add check-gateway=ping comment="RED TONY " disabled=no distance=1 dst-address=172.18.62.0/24 gateway=172.20.3.248 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add check-gateway=ping comment="CLIENTES TEJUPILCO" disabled=no distance=1 dst-address=192.168.30.0/24 gateway=172.20.1.9 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add check-gateway=ping comment="CLIENTES SSG" disabled=no distance=1 dst-address=192.168.31.0/24 gateway=172.20.1.9 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add check-gateway=ping comment="CLIENTES AMATEPEC" disabled=no distance=1 dst-address=192.168.32.0/24 gateway=172.20.1.9 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add check-gateway=ping comment="CLIENTES SAN PEDRO" disabled=no distance=1 dst-address=192.168.34.0/24 gateway=172.20.1.9 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add check-gateway=ping comment=CLIENTES-SAN-BARTOLO dst-address=192.168.12.0/24 gateway=172.20.1.9 add comment="Segmento MGMT" dst-address=192.168.69.0/24 gateway=172.20.1.1 add comment="Red Anonas Tony" dst-address=172.18.61.0/24 gateway=38.58.38.16 add check-gateway=ping comment="Clientes Paseos San Martin" dst-address=192.168.10.0/24 gateway=38.58.38.29 add check-gateway=ping comment="Clientes San Martin" dst-address=192.168.11.0/24 gateway=38.58.38.28 add blackhole comment="LAN UAEM\C3\A9x" disabled=yes dst-address=148.215.0.0/16 gateway="" routing-table=main suppress-hw-offload=no /ip service set ftp disabled=yes set telnet disabled=yes set www port=8080 set api disabled=yes set api-ssl disabled=yes set ssh max-sessions=5 port=46825 /radius add address=172.20.6.1 secret=Fr3eR4d!u5 service=login src-address=172.20.100.1 /routing bgp connection add afi=ip as=273304 connect=yes disabled=no input.filter=bgp-in-cirion instance=AS27334 listen=yes local.address=201.234.96.54 .role=ebgp name=to-cirion output.filter-chain=bgp-out .network=AS273304 .network-blackhole=yes remote.address=201.234.96.33/32 .as=3356 routing-table=main add afi=ip as=273304 connect=yes disabled=no input.filter=bgp-in instance=AS27334 listen=yes local.address=38.104.249.75 .role=ebgp name=to-cogent output.filter-chain=bgp-out .network=AS273304 remote.address=38.104.249.73/32 .as=174 add afi=ip as=273304 connect=yes disabled=no input.filter=bgp-in-admin instance=AS27334 listen=yes local.address=38.58.38.1 .role=ebgp name=to-administrativo output.default-originate=always .redistribute=bgp remote.address=38.58.38.65/32 .as=28526 routing-table=main tcp-md5-key=UAEMEX2026 /routing filter rule add chain=bgp-out disabled=no rule="if (dst in 38.58.38.0/24) { accept } else { reject }" add chain=bgp-in-admin disabled=no rule="if (dst in 148.215.0.0/16) { accept } else { reject }" add chain=bgp-in disabled=no rule="if (dst-len == 0 ) { accept } else { reject }" add chain=bgp-in-cirion disabled=no rule="set bgp-local-pref 200; accept" /snmp set enabled=yes /system clock set time-zone-name=America/Mexico_City /system identity set name=AS273304-RDS /system logging add action=GrafanaLoki prefix=172.20.100.1 topics=critical add action=GrafanaLoki prefix=172.20.100.1 topics=error add action=GrafanaLoki prefix=172.20.100.1 topics=info add action=GrafanaLoki prefix=172.20.100.1 topics=warning /system ntp client set enabled=yes /system ntp client servers add address=0.mx.pool.ntp.org add address=1.mx.pool.ntp.org /system routerboard settings set enter-setup-on=delete-key /tool graphing interface add /tool graphing resource add /user aaa set default-group=full use-radius=yes