Community discussions

MikroTik App
 
User avatar
Xymox
Member
Member
Topic Author
Posts: 434
Joined: Thu Jan 21, 2010 5:04 pm
Location: Phoenix, Arizona US
Contact:

Device-mode not in backup

Sat Apr 26, 2025 1:49 pm

I would REALLY like to have any Device-mode/update changes I make stored in the backup please :)
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 13101
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: Device-mode not in backup

Sat Apr 26, 2025 2:25 pm

Starting from the fact that requests must be made to support@mikrotik.com and not on the user forum,
and that the device-mode is made with the feet because it doesn't take into account the equipment already in production,
by those who WORK with it and don't PLAY with it...

It makes no sense at all, a request made without thinking at all.

If it were enough to reload a backup to set the device mode,
with a backup made ad hoc it would be possible to deactivate or activate the security settings without pressing any button.

At most a comment should be added in the export, for example:
# 2025-03-10 12:04:35 by RouterOS 7.18.2
# software id = 7AZ9-ZR6Z
#
# model = C52iG-5HaxD2HaxD
# serial number = HDMI8KMKAX9
# mode = advanced
# install-any-version = no
# flagging-enabled = yes
# flagged = no
# allowed = scheduler,fetch,bandwidth-test,sniffer,ipsec,romon,hotspot,smb,email,zerotier
# forbidden = socks,pptp,l2tp,traffic-gen,proxy,container,partitions,routerboard
 
User avatar
Xymox
Member
Member
Topic Author
Posts: 434
Joined: Thu Jan 21, 2010 5:04 pm
Location: Phoenix, Arizona US
Contact:

Re: Device-mode not in backup

Sun Apr 27, 2025 3:49 pm

Wow..

WORK with it ? Interesting. I do 45 multi Mikrotik device systems a month on avg and go back 4 more years in experience then you doing it. Respect and professionalism is important in a good forum.

So what is wrong with doing a backup / restore which includes a power cycle after restore ? This is not secure ?

I would thought it was obvious I posted here first to see if maybe i missed something in the restore/backup and Device-Mode..

You have apperently confirmed I should ask for a new feature as i do not see the security issue as a restore could be, and maybe should be, completed with a physical power cycle. Hmm, OK, I do see a security risk, a restore should require a physical power cycle. Good feature suggestion.

I have not played with adding this to my normal scripts and branding stuff yet. So I cant script device-mode changes either ? So if I have a stack of 50 devices I need to config i have to manually do device-mode commands on each one separate from any config scripts ? That will sure add time to initial config run.
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 13101
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: Device-mode not in backup

Mon Apr 28, 2025 2:49 pm

Well, if you simply base it, without reasoning, that someone work with MikroTik products only if and since is registered on the forum...
[and aside from the fact that (read carefully again) the WORK/PLAY part wasn't in the least referred to you]

I'll avoid answering the "who has the biggest" that you started with the "45 multi Mikrotik device systems" etc....

I think that if MikroTik were to really introduce a physical presence requirement to reload the backup,
it would be "the straw that broke the camel's back", or "the drop that makes the cup overflow", your choice.
And I think that if this thing came from you, everyone would <censored> you to <censored>,
as they already do with those who invented the retroactive device-mode for peripherals already installed.

So I cant script device-mode changes either?
So if I have a stack of 50 devices I need to config i have to manually do device-mode commands on each one separate from any config scripts?
That will sure add time to initial config run.
Just give yourself 60 seconds to "press the button", on last script line and suddenly turn off the power to the device when it's finished configuring itself.
You pretty much already know how long it takes a device to program itself, so you just need to get the timing right.

If you configure the device-mode on a peripheral and then do a netinstall, you will find the device-mode reset to defaults.