pjhtech Tools
MikroTik

MikroTik “failure: not allowed by device-mode”

Find the device-mode setting for the refused RouterOS tool, then enable the sniffer with physical confirmation. Handle flagged configuration separately.

For failure: not allowed by device-mode, enable the blocked feature and confirm the change physically. For the sniffer, use /system/device-mode/update sniffer=yes. For fetch, use fetch=yes. Successful confirmation reboots the router; the examples apply to RouterOS 7.17+.

Check the sniffer permission

Read the effective device-mode settings
/system/device-mode/print
sniffer: no and flagged: no
The packet sniffer is disabled. Follow the change below. A mode name such as advanced does not by itself mean every feature is enabled.
sniffer: yes and flagged: no
Device-mode permits the sniffer. Read the exact error from the failing command; changing this setting again will not fix a different restriction.
flagged: yes
RouterOS detected suspicious configuration. Go to the flagged-configuration section below before enabling tools.

Enable the sniffer and confirm locally

Arrange the interruption before requesting the change: successful confirmation reboots the router and disconnects its users. Run:

Request one feature change
/system/device-mode/update sniffer=yes

Change only the required permission. Do not add mode=: changing the mode replaces existing per-feature overrides except those included in the same update.

Confirm within the countdown printed by the command. The default is five minutes; activation-timeout can change that interval. Choose one physical method:

  • Disconnect all power feeds, including PoE if used, so the router actually turns off; then reconnect power.
  • On a model that supports button confirmation, press and release its reset or mode button while RouterOS is running and the request is pending. Do not hold reset while powering on: that is a different procedure that can reset the configuration. Some older models require the power-cycle method.

/system/reboot does not provide physical confirmation. If the countdown expires, the change is canceled. Do not start a second update while waiting: it cancels both requests.

Verify after the reboot

Reconnect and read the settings again:

Verify the applied permission
/system/device-mode/print

Expect sniffer: yes and flagged: no. Retry the capture that originally failed. Stop a quick capture with Ctrl+C; stop a background capture with:

Stop a background packet capture
/tool/sniffer/stop

If the permission was temporary, /system/device-mode/update sniffer=no disables it again using the same confirmation procedure and another reboot.

If the error says configuration flagged

failure: configuration flagged is different from an ordinary disabled feature. RouterOS has detected suspicious configuration and can block the sniffer even when its feature permission is enabled. Audit the configuration for unauthorized changes, including disabled entries, before clearing this state. MikroTik also calls for password changes and a RouterOS update after that audit; follow its flagged-status recovery instructions. Do not reset the flagged state simply to make a capture work.

Choose the setting for the refused tool

Packet sniffer
sniffer permits /tool/sniffer. The complete change procedure follows below.
Flood ping or traffic generator
traffic-gen permits /tool/flood-ping, /tool/traffic-generator and /tool/ping-speed. The separate bandwidth-test setting permits /tool/bandwidth-test and the bandwidth server.
Fetch
fetch permits /tool/fetch.
Containers
container permits container functionality; enabling it does not install or start a container.
RouterBOARD settings or dual-boot SwOS
On RouterOS 7.17+, routerboard permits changes in /system/routerboard/settings (except auto-upgrade, which is not restricted by this setting) and SwOS/RouterOS switching on dual-boot devices.

Use /system/device-mode/print to read the matching field. For example, fetch: no is an output field; the corresponding update parameter is fetch=yes. If that is the feature you need, substitute it for sniffer=yes in the request above, then confirm and verify that field after reboot. Change only the required permission.

References