RouterOS的MikroTik脚本从DNS更新IPSEC端的IP地址

#Script for changing IPSEC address when DNS changes.
#Script will iterate through all peers looking for addr_<dnsname> in the comments. It will then
#check for changes in the IP for that DNS name if the ip address differs it will modify the peer
#as well as any policy with the old IP address as well.

#TODO Add log entries for changes.
#TODO Setup netwatch entries for each tunnel


:local ipsecpeer;
:local "vpn-interface-name";
:local "vpn-dns-name";
:local "current-vpn-ip";
:local "new-vpn-ip";
:local ipsecpolicy;
:local iskillneeded;
/ip ipsec peer;
:foreach ipsecpeer in={[find where comment~"$addr_.*"]} do={
    :set "vpn-dns-name" ([get $ipsecpeer comment]);
    :set "vpn-dns-name" ([:pick $"vpn-dns-name" 5 [:len $"vpn-dns-name"]]);
    :set "new-vpn-ip" [:resolve $"vpn-dns-name"]
    :set "current-vpn-ip" [/ip ipsec peer get $ipsecpeer address]
    :set "current-vpn-ip" [:pick $"current-vpn-ip" 0 [:find $"current-vpn-ip" "/"]]
    :if ($"current-vpn-ip" != $"new-vpn-ip") do={
        :set iskillneeded true;
        /ip ipsec peer set $ipsecpeer address=$"new-vpn-ip";
        /ip ipsec policy;
        :foreach ipsecpolicy in={[find where sa-dst-address=$"current-vpn-ip"]} do={
            set $ipsecpolicy sa-dst-address=$"new-vpn-ip";
        }
    }
}

:if ($iskillneeded = true) do={
    /ip ipsec remote-peers kill-connections;
}
posted on 2015-04-14 00:06  电子灵魂 阅读( ...) 评论( ...) 编辑 收藏

转载于:https://www.cnblogs.com/wordgao/p/4423716.html

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值