fw-addr-lists: masks in array

This commit is contained in:
Christian Hesse 2025-10-15 11:30:26 +02:00
parent 69f78e06ab
commit 2a63a80791

View file

@ -56,6 +56,18 @@
} }
:local ListComment ("managed by " . $ScriptName); :local ListComment ("managed by " . $ScriptName);
:local Maskv4 ({});
:for I from=0 to=32 do={
:local List ("mask-" . $I);
/ip/firewall/address-list/add dynamic=yes timeout=1s list=$List address=("255.255.255.255/" . $I);
:set ($Maskv4->$I) [ /ip/firewall/address-list/get [ find where dynamic=yes list=$List ] address ];
}
:local Maskv6 ({});
:for I from=0 to=128 do={
:local List ("mask-" . $I);
/ipv6/firewall/address-list/add dynamic=yes timeout=1s list=$List address=("ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff/" . $I);
:set ($Maskv4->$I) [ /ipv6/firewall/address-list/get [ find where dynamic=yes list=$List ] address ];
}
:foreach FwListName,FwList in=$FwAddrLists do={ :foreach FwListName,FwList in=$FwAddrLists do={
:local CntAdd 0; :local CntAdd 0;
@ -114,15 +126,13 @@
:do { :do {
:local Branch; :local Branch;
:if ($Address ~ "^[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}(/[0-9]{1,2})?\$") do={ :if ($Address ~ "^[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}(/[0-9]{1,2})?\$") do={
/ip/firewall/address-list/add dynamic=yes list=$Address address=$Address timeout=1s; :set Address
:set Address [ /ip/firewall/address-list/get [ find where dynamic=yes list=$Address ] address ];
:set Branch [ $GetBranch $Address ]; :set Branch [ $GetBranch $Address ];
:set ($IPv4Addresses->$Branch->$Address) $TimeOut; :set ($IPv4Addresses->$Branch->$Address) $TimeOut;
:error true; :error true;
} }
:if ($Address ~ "^[0-9a-zA-Z]*:[0-9a-zA-Z:\\.]+(/[0-9]{1,3})?\$") do={ :if ($Address ~ "^[0-9a-zA-Z]*:[0-9a-zA-Z:\\.]+(/[0-9]{1,3})?\$") do={
/ipv6/firewall/address-list/add dynamic=yes list=$Address address=$Address timeout=1s; :set Address
:set Address [ /ipv6/firewall/address-list/get [ find where dynamic=yes list=$Address ] address ];
:set Branch [ $GetBranch $Address ]; :set Branch [ $GetBranch $Address ];
:set ($IPv6Addresses->$Branch->$Address) $TimeOut; :set ($IPv6Addresses->$Branch->$Address) $TimeOut;
:error true; :error true;