Advertisement
Guest User

Untitled

a guest
Feb 13th, 2014
6,447
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.64 KB | None | 0 0
  1. # feb/13/2014 13:46:37 by RouterOS 6.9
  2. # software id = LGIN-V8YW
  3. #
  4. /interface bridge
  5. add l2mtu=1598 name="bridge1 - Bureau" protocol-mode=none
  6.  
  7. /interface ethernet
  8. set [ find default-name=ether1 ] name="ether1 - Bureau 1-01"
  9. set [ find default-name=ether2 ] name="ether2 - Bureau 1-04"
  10. set [ find default-name=ether3 ] name="ether3 - Bureau 1-05"
  11. set [ find default-name=ether6 ] name="ether6 - Verixi"
  12. /interface wireless security-profiles
  13. set [ find default=yes ] supplicant-identity=MikroTik
  14. /ip firewall layer7-protocol
  15. add name="Block Facebook" regexp="^.+(facebook.com).*\$"
  16. add name="Block Youtube" regexp="^.+(youtube.com).*\$"
  17. add name="Block Google" regexp="^.+(google.com).*\$"
  18. /ip hotspot user profile
  19. set [ find default=yes ] idle-timeout=none keepalive-timeout=2m \
  20. mac-cookie-timeout=3d
  21. /ip pool
  22. add name="DHCP Lan" ranges=10.0.0.1-10.0.0.200
  23. /ip dhcp-server
  24. add add-arp=yes address-pool="DHCP Lan" disabled=no interface=\
  25. "bridge1 - Bureau" lease-time=1h name="DHCP Lan"
  26. /port
  27. set 0 name=serial0
  28. /queue type
  29. add kind=pcq name="10Mbit Down" pcq-classifier=dst-address \
  30. pcq-dst-address6-mask=64 pcq-rate=10M pcq-src-address6-mask=64
  31. add kind=pcq name="10Mbit Up" pcq-classifier=src-address \
  32. pcq-dst-address6-mask=64 pcq-rate=10M pcq-src-address6-mask=64
  33. /queue simple
  34. add name=Limiter queue="10Mbit Up/10Mbit Down" target="bridge1 - Bureau"
  35. /interface bridge port
  36. add bridge="bridge1 - Bureau" interface="ether1 - Bureau 1-01"
  37. add bridge="bridge1 - Bureau" interface="ether3 - Bureau 1-05"
  38. add bridge="bridge1 - Bureau" interface="ether2 - Bureau 1-04"
  39. /ip address
  40. add address=10.0.0.1/24 interface="bridge1 - Bureau" network=10.0.0.0
  41. /ip dhcp-client
  42. add default-route-distance=0 dhcp-options=hostname,clientid disabled=no \
  43. interface="ether6 - Verixi" use-peer-dns=no use-peer-ntp=no
  44. /ip dhcp-server lease
  45. add address=10.0.0.10 mac-address=00:0D:B9:20:A6:2E server="DHCP Lan"
  46. /ip dhcp-server network
  47. add address=10.0.0.0/24 dns-server=8.8.8.8,8.8.4.4 domain=astel.be gateway=\
  48. 10.0.0.1 netmask=24
  49. /ip dns
  50. set servers=8.8.8.8,8.8.4.4
  51. /ip firewall connection tracking
  52. set enabled=yes
  53. /ip firewall filter
  54. add action=drop chain=input comment="Drop DNS Flood" disabled=yes \
  55. in-interface="ether6 - Verixi" protocol=tcp
  56. add action=drop chain=input comment="Drop DNS Flood" disabled=yes \
  57. in-interface="ether6 - Verixi" protocol=udp
  58. add action=drop chain=forward comment="Drop Facebook" disabled=yes \
  59. layer7-protocol="Block Facebook" src-address=10.0.0.0/24
  60. add action=drop chain=forward comment="Drop Youtube" disabled=yes \
  61. layer7-protocol="Block Youtube" src-address=10.0.0.0/24
  62. add action=drop chain=forward comment="Drop Google" disabled=yes \
  63. layer7-protocol="Block Google" src-address=10.0.0.0/24
  64. /ip firewall nat
  65. add action=masquerade chain=srcnat comment="Masquerade Verixi" out-interface=\
  66. "ether6 - Verixi"
  67. add action=dst-nat chain=dstnat comment="Creative One" dst-port=5060-5070 \
  68. protocol=udp to-addresses=10.0.0.10 to-ports=5060-5070
  69. add action=dst-nat chain=dstnat comment="Creative One" dst-port=49152-53246 \
  70. protocol=udp to-addresses=10.0.0.10 to-ports=49152-53246
  71. add action=dst-nat chain=dstnat comment="Creative One" dst-port=5001 \
  72. protocol=udp to-addresses=10.0.0.10 to-ports=5001
  73. add action=dst-nat chain=dstnat comment="Creative One" dst-port=1194 \
  74. protocol=udp to-addresses=10.0.0.10 to-ports=1194
  75. add action=dst-nat chain=dstnat comment="Creative One" dst-port=2200 \
  76. protocol=tcp to-addresses=10.0.0.10 to-ports=2200
  77. /ip firewall service-port
  78. set sip ports=5060,5070
  79. /ip service
  80. set telnet disabled=yes
  81. set ftp disabled=yes
  82. set www port=8080
  83. set ssh disabled=yes
  84. set api disabled=yes
  85. set api-ssl disabled=yes
  86. /ip upnp
  87. set allow-disable-external-interface=no
  88. /lcd
  89. set backlight-timeout=never default-screen=informative-slideshow \
  90. read-only-mode=yes touch-screen=disabled
  91. /lcd interface
  92. set sfp1 interface=sfp1
  93. set "ether1 - Bureau 1-01" interface="ether1 - Bureau 1-01"
  94. set "ether2 - Bureau 1-04" interface="ether2 - Bureau 1-04"
  95. set "ether3 - Bureau 1-05" interface="ether3 - Bureau 1-05"
  96. set ether4 interface=ether4
  97. set ether5 interface=ether5
  98. set "ether6 - Verixi" interface="ether6 - Verixi"
  99. set ether7 interface=ether7
  100. set ether8 interface=ether8
  101. set ether9 interface=ether9
  102. set ether10 interface=ether10
  103. /lcd screen
  104. set 0 timeout=2s
  105. set 1 timeout=2s
  106. set 2 timeout=2s
  107. set 3 timeout=2s
  108. set 4 timeout=2s
  109. set 5 timeout=2s
  110. /system clock
  111. set time-zone-name=Europe/Brussels
  112. /system identity
  113. set name=Astel
  114. /system lcd
  115. set contrast=0 enabled=yes port=parallel type=24x4
  116. /system lcd page
  117. set time disabled=no display-time=2s
  118. set resources disabled=no display-time=2s
  119. set uptime disabled=no display-time=2s
  120. set packets disabled=no display-time=2s
  121. set bits disabled=no display-time=2s
  122. set version disabled=no display-time=2s
  123. set identity disabled=no display-time=2s
  124. set "bridge1 - Bureau" disabled=yes display-time=5s
  125. set bridge2 disabled=yes display-time=5s
  126. set sfp1 disabled=yes display-time=5s
  127. set "ether1 - Bureau 1-01" disabled=yes display-time=5s
  128. set "ether2 - Bureau 1-04" disabled=yes display-time=5s
  129. set "ether3 - Bureau 1-05" disabled=yes display-time=5s
  130. set ether4 disabled=yes display-time=5s
  131. set ether5 disabled=yes display-time=5s
  132. set "ether6 - Verixi" disabled=yes display-time=5s
  133. set ether7 disabled=yes display-time=5s
  134. set ether8 disabled=yes display-time=5s
  135. set ether9 disabled=yes display-time=5s
  136. set ether10 disabled=yes display-time=5s
  137. /system ntp client
  138. set enabled=yes primary-ntp=195.130.132.18 secondary-ntp=195.13.23.5
  139. /tool graphing interface
  140. add
  141. /tool graphing queue
  142. add
  143. /tool graphing resource
  144. add
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement