#!/usr/bin/env python3 """Safe RB4011 link: keep existing hotspot/PPPoE users. Do not rewrite pools.""" from __future__ import annotations import paramiko JUMP = ("100.80.255.113", "otantik", "DeararbsFr2@") MK = ("172.30.0.1", "admin", "demopass") RSC = r""" /system backup save name=wo-before-keep-users :put "backup ok" /ip hotspot enable [find name=hotspot1] :put "hotspot1 enabled" :if ([:len [/ip hotspot ip-binding find comment="wifi-otantik-lan-bypass"]] = 0) do={ /ip hotspot ip-binding add address=172.30.0.0/16 type=bypassed comment=wifi-otantik-lan-bypass } :foreach h in={"portal.otantik.cm";"wifi.otantik.cm";"business.otantik.cm";"*.otantik.cm";"mesomb.hachther.com";"*.mesomb.hachther.com"} do={ :if ([:len [/ip hotspot walled-garden find dst-host=$h]] = 0) do={ /ip hotspot walled-garden add action=allow comment=wifi-otantik dst-host=$h } } :if ([:len [/ip hotspot walled-garden ip find dst-address="83.147.38.107"]] = 0) do={ /ip hotspot walled-garden ip add action=accept comment=wifi-otantik dst-address=83.147.38.107 } :do { /interface wireguard peers remove [find where interface~"\\*13"] } on-error={} :do { /ip address remove [find where comment="wifi-otantik" and interface~"\\*13"] } on-error={} :do { /ip route remove [find where comment="wifi-otantik-wg" and inactive] } on-error={} /ip service set api disabled=no :put "SAFE KEEP-USERS DONE" """ def main() -> None: jump = paramiko.SSHClient() jump.set_missing_host_key_policy(paramiko.AutoAddPolicy()) jump.connect(JUMP[0], username=JUMP[1], password=JUMP[2], timeout=25, allow_agent=False, look_for_keys=False) chan = jump.get_transport().open_channel("direct-tcpip", (MK[0], 22), ("127.0.0.1", 0)) mk = paramiko.SSHClient() mk.set_missing_host_key_policy(paramiko.AutoAddPolicy()) mk.connect(MK[0], username=MK[1], password=MK[2], sock=chan, timeout=25, allow_agent=False, look_for_keys=False) sftp = mk.open_sftp() with sftp.file("wo-keep-users.rsc", "w") as f: f.write(RSC) sftp.close() stdin, stdout, stderr = mk.exec_command("/import file-name=wo-keep-users.rsc", timeout=90) print(stdout.read().decode("utf-8", "replace")) print(stderr.read().decode("utf-8", "replace")) stdin, stdout, stderr = mk.exec_command( ":put [/ip hotspot get [find name=hotspot1] disabled]; /ip hotspot print; :put hs-users=; /ip hotspot user print count-only; :put ppp=; /ppp secret print count-only; :put ppp-active=; /ppp active print count-only", timeout=40, ) print(stdout.read().decode("utf-8", "replace")) mk.close() jump.close() if __name__ == "__main__": main()