I tried to upgrade one router in our network to 7.1, but unfortunately, it ended up badly.
After reboot, there was high packet loss (90+%) to the router and to a few people behind it. Winbox hung up on "logging in". I was able to login via SSH a few times for a short amount of time, so I could get to these last messages:
Code: Select all
Press F1 for help
(12904 messages not shown)
jan/02/1970 00:00:47 system,error,critical kernel failure in previous boot
jan/02/1970 00:00:47 system,error,critical out of memory condition was detected
jan/02/1970 00:02:21 system,error,critical,,,,,,,,,radius error while running customized default configuration script: std failure: timeout (13)
jan/02/1970 00:06:14 system,error,critical login failure for user admin from 78.156.32.131 via winbox
jan/02/1970 00:00:45 system,error,critical router was rebooted without proper shutdown
jan/02/1970 00:00:46 system,error,critical kernel failure in previous boot
jan/02/1970 00:00:46 system,error,critical out of memory condition was detected
jan/02/1970 00:02:19 system,error,critical,,,,,,,,,radius error while running customized default configuration script: std failure: timeout (13)
Code: Select all
/system/routerboard/print
routerboard: yes
model: 750
serial-number: 3B0202CE9968
firmware-type: ar7240
factory-firmware: 2.38
current-firmware: 6.47.1
upgrade-firmware: 7.1
Code: Select all
# dec/05/2021 03:42:12 by RouterOS 6.47.1
# software id = XEF5-JKG3
#
# model = 750
# serial number = 3B0202CE9968
/interface ethernet
set [ find default-name=ether1 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
set [ find default-name=ether2 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
set [ find default-name=ether3 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
set [ find default-name=ether4 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
set [ find default-name=ether5 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
/interface list
add exclude=dynamic name=discover
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=ETH
/ip ipsec proposal
set [ find default=yes ] enc-algorithms=3des
/queue type
add kind=pfifo name=ethr pfifo-limit=100
/queue simple
add burst-limit=39321600/39321600 burst-threshold=10/10 burst-time=20s/20s \
max-limit=32768k/32768k name="id=43" queue=ethr/ethr target=\
84.244.105.166/32
add burst-limit=272793600/272793600 burst-threshold=10/10 burst-time=20s/20s \
max-limit=227328k/227328k name="id=50" queue=ethr/ethr target=\
78.156.44.238/32
add burst-limit=272793600/272793600 burst-threshold=10/10 burst-time=20s/20s \
max-limit=227328k/227328k name="id=158" queue=ethr/ethr target=\
78.156.44.230/32
add burst-limit=61440k/61440k burst-threshold=10/10 burst-time=20s/20s \
max-limit=51200k/51200k name="id=463" queue=ethr/ethr target=\
78.156.44.235/32
add burst-limit=61440k/61440k burst-threshold=10/10 burst-time=20s/20s \
max-limit=51200k/51200k name="id=580" queue=ethr/ethr target=\
78.156.44.232/32
add burst-limit=272793600/272793600 burst-threshold=10/10 burst-time=20s/20s \
max-limit=227328k/227328k name="id=1168" queue=ethr/ethr target=\
172.16.14.101/32,84.244.105.162/32
add burst-limit=61440k/61440k burst-threshold=10/10 burst-time=20s/20s \
max-limit=51200k/51200k name="id=3087" queue=ethr/ethr target=\
84.244.105.168/32
add burst-limit=272793600/272793600 burst-threshold=10/10 burst-time=20s/20s \
max-limit=227328k/227328k name="id=4184" queue=ethr/ethr target=\
78.156.44.234/32
add burst-limit=272793600/272793600 burst-threshold=10/10 burst-time=20s/20s \
max-limit=227328k/227328k name="id=4324" queue=ethr/ethr target=\
78.156.44.236/32
add burst-limit=86016k/86016k burst-threshold=10/10 burst-time=20s/20s \
max-limit=71680k/71680k name="id=4683" queue=ethr/ethr target=\
78.156.44.229/32
add burst-limit=61440k/61440k burst-threshold=10/10 burst-time=20s/20s \
max-limit=51200k/51200k name="id=6980" queue=ethr/ethr target=\
172.16.14.102/32
add burst-limit=61440k/61440k burst-threshold=10/10 burst-time=20s/20s \
max-limit=51200k/51200k name="id=7182" queue=ethr/ethr target=\
172.16.14.103/32
add burst-limit=61440k/61440k burst-threshold=10/10 burst-time=20s/20s \
max-limit=51200k/51200k name="id=7774" queue=ethr/ethr target=\
172.16.14.104/32
add burst-limit=86016k/86016k burst-threshold=10/10 burst-time=20s/20s \
max-limit=71680k/71680k name="id=3096" queue=ethr/ethr target=\
78.156.44.226/32
add burst-limit=24576k/24576k burst-threshold=10/10 burst-time=20s/20s \
max-limit=20480k/20480k name="id=6331" queue=ethr/ethr target=\
172.16.14.120/32
add burst-limit=61440k/61440k burst-threshold=10/10 burst-time=20s/20s \
max-limit=51200k/51200k name="id=6220" queue=ethr/ethr target=\
172.16.14.106/32
add burst-limit=61440k/61440k burst-threshold=10/10 burst-time=20s/20s \
max-limit=51200k/51200k name="id=1472" queue=ethr/ethr target=\
172.16.14.126/32
/snmp community
set [ find default=yes ] addresses=192.168.0.0/21
add addresses=192.168.0.0/22 name=dohled
/system logging action
set 0 memory-lines=100
set 1 disk-lines-per-file=100
/ip neighbor discovery-settings
set discover-interface-list=discover
/ip address
add address=192.168.0.50/24 interface=ether1 network=192.168.0.0
add address=172.16.14.97/27 interface=ether2 network=172.16.14.96
add address=78.156.44.225/28 interface=ether2 network=78.156.44.224
add address=84.244.105.161/28 interface=ether2 network=84.244.105.160
/ip firewall filter
add chain=forward comment=Established connection-state=established
add action=accept chain=forward comment="idip=8320" dst-address=\
84.244.105.166
add action=accept chain=forward comment="idip=8320" limit=32768,32768:packet \
src-address=84.244.105.166 src-mac-address=20:AA:4B:57:C3:15
add action=accept chain=forward comment="idip=10444" dst-address=\
78.156.44.238
add action=accept chain=forward comment="idip=10444" limit=\
227328,227328:packet src-address=78.156.44.238 src-mac-address=\
4C:5E:0C:78:97:B8
add action=accept chain=forward comment="idip=5957" dst-address=78.156.44.230
add action=accept chain=forward comment="idip=5957" limit=\
227328,227328:packet src-address=78.156.44.230 src-mac-address=\
D4:CA:6D:F1:D0:6F
add action=accept chain=forward comment="idip=16358" dst-address=\
78.156.44.235
add action=accept chain=forward comment="idip=16358" limit=51200,51200:packet \
src-address=78.156.44.235 src-mac-address=54:83:3A:D5:F2:8D
add action=accept chain=forward comment="idip=11031" dst-address=\
78.156.44.232
add action=accept chain=forward comment="idip=11031" limit=51200,51200:packet \
src-address=78.156.44.232 src-mac-address=4C:5E:0C:04:91:33
add action=accept chain=forward comment="idip=12137" dst-address=\
172.16.14.101
add action=accept chain=forward comment="idip=12137" limit=\
227328,227328:packet src-address=172.16.14.101 src-mac-address=\
54:E6:FC:B9:53:A5
add action=accept chain=forward comment="idip=6976" dst-address=\
84.244.105.162
add action=accept chain=forward comment="idip=6976" limit=\
227328,227328:packet src-address=84.244.105.162 src-mac-address=\
54:E6:FC:B9:53:A5
add action=accept chain=forward comment="idip=9765" dst-address=\
84.244.105.168
add action=accept chain=forward comment="idip=9765" limit=51200,51200:packet \
src-address=84.244.105.168 src-mac-address=E8:DE:27:25:CB:37
add action=accept chain=forward comment="idip=6828" dst-address=78.156.44.234
add action=accept chain=forward comment="idip=6828" limit=\
227328,227328:packet src-address=78.156.44.234 src-mac-address=\
D4:CA:6D:F4:43:B0
add action=accept chain=forward comment="idip=7147" dst-address=78.156.44.236
add action=accept chain=forward comment="idip=7147" limit=\
227328,227328:packet src-address=78.156.44.236 src-mac-address=\
54:E6:FC:AF:D0:2B
add action=accept chain=forward comment="idip=10445" dst-address=\
78.156.44.229
add action=accept chain=forward comment="idip=10445" limit=71680,71680:packet \
src-address=78.156.44.229 src-mac-address=4C:5E:0C:69:C5:29
add action=accept chain=forward comment="idip=12309" dst-address=\
172.16.14.102
add action=accept chain=forward comment="idip=12309" limit=51200,51200:packet \
src-address=172.16.14.102 src-mac-address=E4:8D:8C:65:96:7B
add action=accept chain=forward comment="idip=12789" dst-address=\
172.16.14.103
add action=accept chain=forward comment="idip=12789" limit=51200,51200:packet \
src-address=172.16.14.103 src-mac-address=98:DE:D0:AB:C7:2F
add action=accept chain=forward comment="idip=14007" dst-address=\
172.16.14.104
add action=accept chain=forward comment="idip=14007" limit=51200,51200:packet \
src-address=172.16.14.104 src-mac-address=A4:2B:B0:CB:12:A1
add action=accept chain=forward comment="idip=5184" dst-address=78.156.44.226
add action=accept chain=forward comment="idip=5184" limit=71680,71680:packet \
src-address=78.156.44.226 src-mac-address=E4:8D:8C:6A:0C:7C
add action=accept chain=forward comment="idip=10918" dst-address=\
172.16.14.120
add action=accept chain=forward comment="idip=10918" limit=20480,20480:packet \
src-address=172.16.14.120 src-mac-address=4C:5E:0C:C2:2F:BB
add action=accept chain=forward comment="idip=10683" dst-address=\
172.16.14.106
add action=accept chain=forward comment="idip=10683" limit=51200,51200:packet \
src-address=172.16.14.106 src-mac-address=C4:6E:1F:DE:DE:29
add action=accept chain=forward comment="idip=16522" dst-address=\
172.16.14.126
add action=accept chain=forward comment="idip=16522" limit=51200,51200:packet \
src-address=172.16.14.126 src-mac-address=00:31:92:3A:F2:1F
add action=drop chain=forward comment=OSTATNI
/ip ipsec policy
set 0 dst-address=0.0.0.0/0 src-address=0.0.0.0/0
/ip proxy
set cache-path=web-proxy1
/ip route
add distance=1 gateway=192.168.0.1
/ip service
set telnet address=192.168.0.0/21 disabled=yes
set ftp address=192.168.0.0/21 disabled=yes
set www address=192.168.0.0/21 disabled=yes
set ssh address=192.168.0.0/21
set www-ssl address=192.168.0.0/21
set api address=192.168.0.0/21
set winbox address=192.168.0.0/21
set api-ssl address=192.168.0.0/21 disabled=yes port=8728
/snmp
set enabled=yes
/system clock
set time-zone-autodetect=no
/system identity
set name=ETH
/system ntp client
set enabled=yes primary-ntp=192.168.0.6