#!/usr/bin/env python3 """Hub-only: portal DNS / www scope. Keeps wo-byp:* MAC bypass bindings.""" from __future__ import annotations from mk_hub_exec import import_rsc, run RSC = r""" :put "HUB-PORTAL-ACCESS START" /system backup save name=wo-before-portal-access :do { /ip service set www address=192.168.88.0/24 } on-error={} # Empty dns-name so http://10.8.192.1/status works even with Private DNS. # Brand name still resolves locally via static DNS below. :do { /ip hotspot profile set [find name=hs-otantik] dns-name="" } on-error={} :do { /ip dns static remove [find where name="otantik.net" and comment="wifi-otantik-hs"] } on-error={} :do { /ip dns static add name=otantik.net address=10.8.192.1 comment=wifi-otantik-hs } on-error={} :do { /ip dns static remove [find where name="www.otantik.net" and comment="wifi-otantik-hs"] } on-error={} :do { /ip dns static add name=www.otantik.net address=10.8.192.1 comment=wifi-otantik-hs } on-error={} :do { /ip dns static set [find where name="hotspot.lan"] address=10.8.192.1 } on-error={} :if ([:len [/ip dns static find where name="hotspot.lan"]] = 0) do={ :do { /ip dns static add name=hotspot.lan address=10.8.192.1 comment=wifi-otantik-hs } on-error={} } # Keep wo-byp:* (intentional post-pay MAC bypass). Office LAN 192.168.88.0/24 stays too. :do { /ip firewall filter remove [find where comment="wo-hs-block-quic"] } on-error={} # Do not re-add QUIC drop on whole bridge — it hits logged-in clients too. :put "HUB-PORTAL-ACCESS DONE" /ip service print where name=www /ip dns static print where comment="wifi-otantik-hs" /ip hotspot profile print detail where name=hs-otantik /ip hotspot ip-binding print """ def main() -> None: idn = run("/system identity print") print("identity:", idn) if "Otantik Hub" not in idn or "Nkoabang" in idn: raise SystemExit("refusing: not Hub RB2011") print(import_rsc("wo-portal-access.rsc", RSC, timeout=90)) print("DONE") if __name__ == "__main__": main()