95 lines
3.4 KiB
Python
95 lines
3.4 KiB
Python
import os
|
|
import requests
|
|
import json
|
|
import ipaddress
|
|
from dotenv import load_dotenv
|
|
|
|
# Load configuration dari file .env
|
|
load_dotenv()
|
|
|
|
BGP_ROUTER_IP = os.getenv("BGP_ROUTER_IP")
|
|
BGP_ROUTER_USER = os.getenv("BGP_ROUTER_USER")
|
|
BGP_ROUTER_PASSWORD = os.getenv("BGP_ROUTER_PASSWORD")
|
|
|
|
# URL API RouterOS v7 untuk membaca tabel routing
|
|
API_URL = f"http://{BGP_ROUTER_IP}/rest/routing/route"
|
|
|
|
# Kredensial basic auth
|
|
auth = (BGP_ROUTER_USER, BGP_ROUTER_PASSWORD)
|
|
|
|
def get_local_bgp_routes():
|
|
"""Mengambil daftar IP lokal dari address-list 'bgp-export' di router BGP.
|
|
|
|
Address-list ini diisi secara berkala oleh scheduler MikroTik (bgp_lokal_scheduler)
|
|
yang menjalankan script bgp_lokal_export setiap hari jam 04:00.
|
|
Script mengumpulkan dst-address dari rute CDN (distance=15) dan NIX (distance=200)
|
|
lalu menulisnya ke address-list 'bgp-export'.
|
|
"""
|
|
import urllib3
|
|
urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)
|
|
|
|
print(f"Menghubungi router {BGP_ROUTER_IP} via REST API...")
|
|
|
|
session = requests.Session()
|
|
session.auth = auth
|
|
session.verify = False
|
|
|
|
api_url = f"http://{BGP_ROUTER_IP}/rest"
|
|
|
|
print("Mengambil address-list 'bgp-export' dari router...")
|
|
try:
|
|
res = session.get(f"{api_url}/ip/firewall/address-list",
|
|
params={"list": "bgp-export", ".proplist": "address"},
|
|
timeout=30)
|
|
|
|
if res.status_code == 200:
|
|
data = res.json()
|
|
routes = [r.get("address") for r in data if r.get("address")]
|
|
# Hapus default routes
|
|
routes = [r for r in routes if r not in ("0.0.0.0/0", "::/0")]
|
|
print(f" -> Berhasil: {len(routes)} rute lokal")
|
|
return list(set(routes))
|
|
else:
|
|
print(f" -> Error: {res.status_code} - {res.text[:100]}")
|
|
return []
|
|
except Exception as e:
|
|
print(f" -> Gagal: {e}")
|
|
return []
|
|
|
|
def generate_address_list_script(route_list, list_name, filename):
|
|
"""Membentuk file .rsc yang berisi perintah create address-list MikroTik"""
|
|
if not route_list:
|
|
print(f"List kosong, tidak ada rute LOKAL yang ditemukan.")
|
|
return
|
|
|
|
print(f"Membuat file {filename} dengan {len(route_list)} subnet IP...")
|
|
|
|
with open(filename, "w") as f:
|
|
f.write(f"# Dibuat otomatis via Script API Python\n")
|
|
f.write(f"/ip firewall address-list\n")
|
|
# Bersihkan list lama sebelum memasukkan yang baru
|
|
f.write(f"remove [find list=\"{list_name}\"]\n")
|
|
|
|
for ip in route_list:
|
|
f.write(f"add list={list_name} address=\"{ip}\"\n")
|
|
|
|
print(f"File {filename} berhasil dibuat.")
|
|
|
|
if __name__ == "__main__":
|
|
if not all([BGP_ROUTER_IP, BGP_ROUTER_USER, BGP_ROUTER_PASSWORD]):
|
|
print("Error: Variabel kredensial/BGP_ROUTER_IP belum diset dengan benar di file .env")
|
|
exit(1)
|
|
|
|
print("--- Memulai Proses Ekstraksi Ringan Routing LOKAL ---")
|
|
local_ips = get_local_bgp_routes()
|
|
|
|
if local_ips:
|
|
print(f"\nRingkasan:")
|
|
print(f"Total Subnet IP Lokal & CDN: {len(local_ips)}")
|
|
|
|
# Generate script address-list khusus untuk trafik Lokal
|
|
generate_address_list_script(local_ips, "ip-lokal", "routing-lokal.rsc")
|
|
|
|
print("\nSelesai! File routing-lokal.rsc siap di-upload ke router distribusi.")
|
|
print("Di Router Distribusi jalankan perintah: /import file-name=routing-lokal.rsc")
|