From bee027f93838044e11739eadbf976ab6ad5ba67c Mon Sep 17 00:00:00 2001 From: Maghiel Dijksman Date: Tue, 26 Nov 2024 09:03:31 +0100 Subject: [PATCH] Update mikrotik.markdown - group policy fix (#35982) --- source/_integrations/mikrotik.markdown | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/source/_integrations/mikrotik.markdown b/source/_integrations/mikrotik.markdown index 8717382e1de..680a1856b2b 100644 --- a/source/_integrations/mikrotik.markdown +++ b/source/_integrations/mikrotik.markdown @@ -62,10 +62,10 @@ If everything is working fine you can disable the pure `api` service in RouterOS ## The user privileges in RouterOS -To use this device tracker, you only need limited privileges. To enhance the security of your MikroTik device, create a "read only" user who can connect to API and perform ping test only: +To use this device tracker, you only need limited privileges. To enhance the security of your MikroTik device, create a "read only" group with solely API and ping test permissions and add a user to that group: ```bash -/user group add name=homeassistant policy=read,api,test,!local,!telnet,!ssh,!ftp,!reboot,!write,!policy,!winbox,!password,!web,!sniff,!sensitive,!romon,!dude,!tikapp -/user add group=homeassistant name=homeassistant -/user set password="YOUR_PASSWORD" homeassistant +/user +group add name=homeassistant policy=read,api,test +add group=homeassistant name=homeassistant ```