/ip/firewall/address-list timeout for entries

Hi,

In the menu /ip/firewall/address-list i can add a timeout for an ip address when it needs to expire.
Is there a way to set a timeout when i use add src to address list from a firewall filter rule?
This is not clear where this can be done.

Thanks, Peter

What you use to configure the device?
Just specify a timeout (on seconds) on winbox on timeout field just under Address List field…

Hi,

I tried with winbox and cli.
When i gave the entries a timeout they timed out and the new entries do not have a timout value.
The addresses added to the list do not timeout and stay on the list, without a timeout they are committed to disk instead of memory.

It would be a very handy feature if the add src to address list filter rule had a timeout parameter to be set.

Running ROS 7.8 on a hEX S


Screenshot 2023-04-26 at 14.42.26.png

He has it and it works… I don’t know why for you don’t work, or why you don’t see it…

I quit agree, it should work.
There where articles on the forum as long back as 2010 on this feature.

For me it is the first time i use this feature, i read the documentation on this topic but found no clue.

If someone can confirm this as well on 7.8, then it must be a bug.

Do you mean like the image below or a timeout on the filter rule itself (ie “Src/Dst Address List”)?
Screenshot 09.17.33.png

Well i tried to do it both ways and found only one, on the address list dialog (your screenshot depicts).

When setting a new address list i tried:

  • set it with a time out, i turns dynamic instantly and the countdown starts, it counts down and they get removed from the list when the timer is exhausted.
  • set it with no time out, it does not become dynamic and stay on the list (and will be written to disk probably).

I tried to find a timeout value in the filter rule, to set the timeout for the address list , but found only “time”, what seems to be a scheduler.

It might just be a presentation problem with WinBox showing an entry despite the timeout. try refreshing the list by using the filter box or close and reopen it.

Regarding filter rules, you can only specify fixed times.

What are you trying to resolv?

i found this in the documentation:https://help.mikrotik.com/docs/display/ROS/Filter

address-list-timeout (none-dynamic | none-static | time; Default: none-dynamic)
Time interval after which the address will be removed from the address list specified by address-list parameter.
Used in conjunction with add-dst-to-address-list or add-src-to-address-list actions

Value of none-dynamic (00:00:00) will leave the address in the address list till reboot
Value of none-static will leave the address in the address list forever and will be included in configuration export/backup


Tryed this and that worked.
Got thrown off by the dialogue box choices…


BTW, why not use the same name as the option is named in the documentation, it is called “timeout” not address-list-timeout !
Why not call the section address-list and the option timeout, also in the docs.
… because it is cli centric you idiot :open_mouth: ( no offense to others )

Any way, it is my stupidy and misunderstanding … Tally ho, go block, my beautiful rule :smiley:
Thanks!

:+1: :grin:

Welcome to the wonderful world of Mikrotik where the help docs are full of inconsistent explanations! :smiley:

Thanks Larsa,

I actually rediscovered MikroTik after it got lost somewhere, and found it again around two years ago.
We, my colleagues and i, had “cheap” pc’s and loads of NICs back in the days, before the Y2K fear.
I do not remember to much, but do know MikroTik was fun to work with.

It could be that a license change made it impossible to tinker with it no longer, and abandoned it, but that was than.

For now, i love MikroTik products (except my own wonky mAP lite*).

  • whishlist 2G/5G 2 port better processor one :wink:

Cheers