In the menu /ip/firewall/address-list i can add a timeout for an ip address when it needs to expire.
Is there a way to set a timeout when i use add src to address list from a firewall filter rule?
This is not clear where this can be done.
I tried with winbox and cli.
When i gave the entries a timeout they timed out and the new entries do not have a timout value.
The addresses added to the list do not timeout and stay on the list, without a timeout they are committed to disk instead of memory.
It would be a very handy feature if the add src to address list filter rule had a timeout parameter to be set.
Well i tried to do it both ways and found only one, on the address list dialog (your screenshot depicts).
When setting a new address list i tried:
set it with a time out, i turns dynamic instantly and the countdown starts, it counts down and they get removed from the list when the timer is exhausted.
set it with no time out, it does not become dynamic and stay on the list (and will be written to disk probably).
I tried to find a timeout value in the filter rule, to set the timeout for the address list , but found only “time”, what seems to be a scheduler.
It might just be a presentation problem with WinBox showing an entry despite the timeout. try refreshing the list by using the filter box or close and reopen it.
Regarding filter rules, you can only specify fixed times.
address-list-timeout (none-dynamic | none-static | time; Default: none-dynamic)
Time interval after which the address will be removed from the address list specified by address-list parameter.
Used in conjunction with add-dst-to-address-list or add-src-to-address-list actions
Value of none-dynamic (00:00:00) will leave the address in the address list till reboot
Value of none-static will leave the address in the address list forever and will be included in configuration export/backup
Tryed this and that worked.
Got thrown off by the dialogue box choices…
BTW, why not use the same name as the option is named in the documentation, it is called “timeout” not address-list-timeout !
Why not call the section address-list and the option timeout, also in the docs.
… because it is cli centric you idiot ( no offense to others )
Any way, it is my stupidy and misunderstanding … Tally ho, go block, my beautiful rule
Thanks!
I actually rediscovered MikroTik after it got lost somewhere, and found it again around two years ago.
We, my colleagues and i, had “cheap” pc’s and loads of NICs back in the days, before the Y2K fear.
I do not remember to much, but do know MikroTik was fun to work with.
It could be that a license change made it impossible to tinker with it no longer, and abandoned it, but that was than.
For now, i love MikroTik products (except my own wonky mAP lite*).