# model: CRS309-1G-8S+ # serial-number: HD6085RX6M0 # firmware-type: dx3230L # current-firmware: 7.16.2 # installed-version: 7.18.2 # Flags: U - UNDOABLE # Columns: ACTION, BY, POLICY, TIME # ACTION BY POLICY TIME # U changed snmp settings daniel write 2025-09-30 13:28:20 # U item changed daniel write 2025-09-30 13:28:19 # U item removed daniel write 2025-09-30 13:28:17 # U device changed daniel write 2025-08-28 22:16:26 # U device changed daniel write 2025-08-28 22:16:26 # U device changed daniel write 2025-08-28 22:16:24 # U device changed daniel write 2025-08-28 22:16:19 # U device changed daniel write 2025-08-28 22:16:10 # U device changed daniel write 2025-08-28 22:16:06 # U device changed daniel write 2025-08-28 22:16:02 # U device changed daniel write 2025-08-28 22:16:00 # U device changed daniel write 2025-08-28 22:15:56 # U device changed daniel write 2025-08-28 22:15:50 # U device changed daniel write 2025-08-28 14:27:04 # U device changed daniel write 2025-08-28 14:26:33 # U device changed daniel write 2025-08-28 13:05:56 # U device changed daniel write 2025-08-28 13:05:50 # U device changed daniel write 2025-08-28 13:05:43 # U device changed daniel write 2025-08-28 09:21:10 # U device changed daniel write 2025-08-28 09:21:10 # U device changed daniel write 2025-08-28 09:21:10 # U device changed daniel write 2025-08-28 09:21:10 # U device changed daniel write 2025-08-28 09:21:10 # U device changed daniel write 2025-08-28 09:21:10 # U device changed daniel write 2025-08-28 09:21:09 # U device changed daniel write 2025-08-28 09:21:09 # U device changed daniel write 2025-08-27 20:06:53 # U device changed daniel write 2025-08-27 20:06:53 # U device changed daniel write 2025-08-27 20:06:53 # U device changed daniel write 2025-08-27 20:06:53 # U device changed daniel write 2025-08-27 20:06:53 # U device changed daniel write 2025-08-27 20:06:53 # U device changed daniel write 2025-08-27 20:06:53 # U device changed daniel write 2025-08-27 20:06:53 # U device changed daniel write 2025-08-27 20:06:24 # U device changed daniel write 2025-08-27 20:06:24 # U device changed daniel write 2025-08-27 20:06:24 # U device changed daniel write 2025-08-27 20:06:24 # U device changed daniel write 2025-08-27 20:06:24 # U device changed daniel write 2025-08-27 20:06:24 # U device changed daniel write 2025-08-27 20:06:24 # U device changed daniel write 2025-08-27 20:06:24 # U device changed daniel write 2025-08-27 20:06:23 # U ovpn server added read 2025-05-04 01:51:12 # # software id = QDVJ-E4WS # # model = CRS309-1G-8S+ # serial number = HD6085RX6M0 /interface bridge add admin-mac=18:FD:74:B2:CD:57 auto-mac=no ingress-filtering=no name=bridge port-cost-mode=short vlan-filtering=yes /interface ethernet set [ find default-name=ether1 ] l2mtu=9200 mtu=9000 set [ find default-name=sfp-sfpplus1 ] l2mtu=9200 mtu=9000 set [ find default-name=sfp-sfpplus2 ] auto-negotiation=no disabled=yes l2mtu=1596 speed=1G-baseX set [ find default-name=sfp-sfpplus3 ] disabled=yes l2mtu=1596 set [ find default-name=sfp-sfpplus4 ] disabled=yes l2mtu=1596 set [ find default-name=sfp-sfpplus5 ] auto-negotiation=no comment=L13-T1 l2mtu=1596 speed=1G-baseX set [ find default-name=sfp-sfpplus6 ] auto-negotiation=no comment=L21-T4 l2mtu=1596 speed=1G-baseX set [ find default-name=sfp-sfpplus7 ] auto-negotiation=no disabled=yes l2mtu=1596 speed=1G-baseX set [ find default-name=sfp-sfpplus8 ] disabled=yes l2mtu=1596 /interface vlan add interface=bridge name=BR.VL5 vlan-id=5 add interface=bridge name=BR.VL10 vlan-id=10 add interface=bridge name=BR.VL99 vlan-id=99 add interface=bridge name=BR.VL100 vlan-id=100 add interface=bridge name=BR.VL214 vlan-id=214 add interface=bridge name=BR.VL3000 vlan-id=3000 add interface=BR.VL3000 name=BR.VL3000.VL8 vlan-id=8 add interface=bridge name=BR.VL3001 vlan-id=3001 /interface ethernet switch port set 3 egress-rate=100.0Mbps ingress-rate=40.0Mbps set 4 egress-rate=400.0Mbps ingress-rate=400.0Mbps set 5 egress-rate=250.0Mbps ingress-rate=100.0Mbps /interface lte apn set [ find default=yes ] ip-type=ipv4 use-network-apn=no /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik /ip smb users set [ find default=yes ] disabled=yes /port set 0 name=serial0 /snmp community set [ find default=yes ] name=CFNCOM /system logging action add name=Syslog remote=172.16.0.250 src-address=172.16.2.3 target=remote /interface bridge port add bridge=bridge ingress-filtering=no interface=sfp-sfpplus2 internal-path-cost=10 path-cost=10 pvid=20 add bridge=bridge ingress-filtering=no interface=sfp-sfpplus5 internal-path-cost=10 path-cost=10 pvid=3001 add bridge=bridge ingress-filtering=no interface=sfp-sfpplus6 internal-path-cost=10 path-cost=10 pvid=3000 add bridge=bridge ingress-filtering=no interface=ether1 internal-path-cost=10 path-cost=10 add bridge=bridge ingress-filtering=no interface=sfp-sfpplus1 internal-path-cost=10 path-cost=10 /ip firewall connection tracking set udp-timeout=10s /ip neighbor discovery-settings set discover-interface-list=!dynamic /ip settings set max-neighbor-entries=8192 /ipv6 settings set disable-ipv6=yes /interface bridge vlan add bridge=bridge tagged=bridge,ether1,sfp-sfpplus1 vlan-ids=100 # sfp-sfpplus4 not a bridge port add bridge=bridge tagged=bridge,ether1,sfp-sfpplus1 untagged=sfp-sfpplus2,sfp-sfpplus4 vlan-ids=20 add bridge=bridge tagged=bridge,ether1,sfp-sfpplus1 untagged=sfp-sfpplus5 vlan-ids=3001 add bridge=bridge tagged=bridge,ether1,sfp-sfpplus1 vlan-ids=214 add bridge=bridge tagged=bridge,ether1,sfp-sfpplus1 untagged=sfp-sfpplus6 vlan-ids=3000 add bridge=bridge tagged=bridge,ether1,sfp-sfpplus1 vlan-ids=21 add bridge=bridge tagged=bridge,ether1,sfp-sfpplus1 vlan-ids=99 add bridge=bridge tagged=bridge,ether1,sfp-sfpplus1 vlan-ids=5 add bridge=bridge tagged=bridge,ether1,sfp-sfpplus1 vlan-ids=10 /interface ovpn-server server add auth=sha1,md5 mac-address=FE:E5:DB:D3:F3:B9 name=ovpn-server1 /ip address add address=192.168.99.252/24 interface=BR.VL99 network=192.168.99.0 add address=172.16.2.3/16 interface=BR.VL5 network=172.16.0.0 /ip dns set servers=1.1.1.1 /ip ipsec profile set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5 /ip route add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=172.16.0.1 pref-src=0.0.0.0 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add disabled=no distance=1 dst-address=192.168.255.0/24 gateway=172.16.0.1 pref-src=0.0.0.0 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add disabled=no distance=1 dst-address=192.168.1.0/24 gateway=172.16.0.1 pref-src=0.0.0.0 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 /ip service set telnet disabled=yes set ftp disabled=yes set www disabled=yes set api disabled=yes set api-ssl disabled=yes /ip smb shares set [ find default=yes ] directory=/flash/pub /radius add address=172.16.0.1 require-message-auth=no secret=CFNCOM service=login /routing bfd configuration add disabled=no interfaces=all min-rx=200ms min-tx=200ms multiplier=5 /snmp set contact=noc@corefibre.com.au enabled=yes location=Melbourne,Australia trap-version=2 /system clock set time-zone-name=Australia/Sydney /system identity set name=SW1.8Ex.CFN.net.au /system logging add action=Syslog topics=critical add action=Syslog topics=error add action=Syslog topics=info add action=Syslog topics=warning /system note set show-at-login=no /system ntp client set enabled=yes /system ntp client servers add address=172.16.0.1 /system scheduler add name=reboot-at-10pm on-event=reboot-schedule policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon start-date=2024-12-27 start-time=22:00:00 /system script add dont-require-permissions=no name=reboot-schedule owner=daniel policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="/system reboot" /tool romon set enabled=yes id=18:FD:74:B2:CD:57 secrets=CFN /user aaa set use-radius=yes