Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # dec/12/2020 17:22:25 by RouterOS 6.39.2
- #
- /caps-man channel
- add band=2ghz-onlyn control-channel-width=20mhz frequency=2412 name=channel1 \
- tx-power=20
- add band=2ghz-onlyn control-channel-width=20mhz frequency=2437 name=channel6 \
- tx-power=20
- add band=2ghz-onlyn control-channel-width=20mhz frequency=2462 name=channel11 \
- tx-power=20
- add band=2ghz-onlyn control-channel-width=20mhz frequency=2417 name=channel2 \
- tx-power=20
- add band=2ghz-onlyn control-channel-width=20mhz frequency=2432 name=channel5 \
- tx-power=20
- /interface bridge
- add name=bridgeDublin
- add name=bridgeTehnicalWifi
- add name=bridgeVIP
- add arp=proxy-arp name=bridgeVPN
- add name=bridge_DOM.RU
- /interface ethernet
- set [ find default-name=ether1 ] comment=Local loop-protect=on speed=1Gbps
- set [ find default-name=ether3 ] disabled=yes
- set [ find default-name=ether4 ] disabled=yes
- set [ find default-name=ether5 ] disabled=yes
- set [ find default-name=ether6 ] comment=\
- "ISP 1 Primary Rostelekom
- set [ find default-name=ether7 ] comment=DOM.RU
- set [ find default-name=ether8 ] comment="ISP2 Reserve Dom.ru " loop-protect=\
- on
- set [ find default-name=ether9 ] disabled=yes
- set [ find default-name=ether10 ] disabled=yes
- set [ find default-name=sfp1 ] disabled=yes loop-protect=on
- /interface pppoe-client
- add comment="ISP 2 DOM.RU" disabled=no interface=ether8 name=pppoe-out1 \
- password=******* use-peer-dns=yes user=*****
- /ip neighbor discovery
- set ether1 discover=no
- set ether3 discover=no
- set ether4 discover=no
- set ether5 discover=no
- set ether6 discover=no
- set ether7 discover=no
- set ether8 discover=no
- set ether9 discover=no
- set ether10 discover=no
- set sfp1 discover=no
- set pppoe-out1 discover=no
- /interface vlan
- add comment="Network device management MGMT" interface=ether1 loop-protect=on \
- name=ManagementVlan2 vlan-id=2
- add comment="Network of Servers" interface=ether1 loop-protect=on name=\
- "Network of ServersVlan3" vlan-id=3
- add comment=Personal interface=ether1 loop-protect=on name=Teh.PersonalVlan9 \
- vlan-id=9
- add comment=UnlimitedSpeed interface=ether1 loop-protect=on name=\
- UnlimitedSpeedVlan7 vlan-id=7
- add comment="Video network" interface=ether1 loop-protect=on name=VideoVlan4 \
- vlan-id=4
- add comment="Voice Ip" interface=ether1 name=VoiceVlan8 vlan-id=8
- add comment=Dom.RU interface=ether7 name=vlan_Dom.Ru vlan-id=3603
- /caps-man datapath
- add bridge=bridge_DOM.RU comment="Config Stage4" name=datapath2Stage4 \
- vlan-id=3603
- add bridge=bridge_DOM.RU comment="Config Stage3" name=datapath3Stage3 \
- vlan-id=3603
- add bridge=bridge_DOM.RU comment="Config Stage2" name=datapath4Stage2 \
- vlan-id=3603
- add bridge=bridgeTehnicalWifi client-to-client-forwarding=no name=\
- datapath1Stage1 vlan-id=9
- add bridge=bridgeVIP client-to-client-forwarding=yes comment=VIP name=\
- datapath5 vlan-id=7
- /caps-man configuration
- add channel=channel1 country=russia2 datapath=datapath4Stage2 mode=ap name=\
- cfg1_Stage2 rx-chains=0,1,2 ssid=HotelRING tx-chains=0,1,2
- add channel=channel6 country=russia2 datapath=datapath4Stage2 mode=ap name=\
- cfg6_Stage2 rx-chains=0,1,2 ssid=HotelRING tx-chains=0,1,2
- add channel=channel11 country=russia2 datapath=datapath4Stage2 mode=ap name=\
- cfg11_Stage2 rx-chains=0,1,2 ssid=HotelRING tx-chains=0,1,2
- add channel=channel1 country=russia2 datapath=datapath3Stage3 mode=ap name=\
- cfg1Stage3 rx-chains=0,1,2 ssid=HotelRING tx-chains=0,1,2
- add channel=channel6 country=russia2 datapath=datapath3Stage3 mode=ap name=\
- cfg6Stage3 rx-chains=0,1,2 ssid=HotelRING tx-chains=0,1,2
- add channel=channel11 country=russia2 datapath=datapath3Stage3 mode=ap name=\
- cfg11Stage3 rx-chains=0,1,2 ssid=HotelRING tx-chains=0,1,2
- add channel=channel2 country=russia2 datapath=datapath3Stage3 mode=ap name=\
- cfg2Stage3 rx-chains=0,1,2 ssid=HotelRING tx-chains=0,1,2
- add channel=channel5 country=russia2 datapath=datapath2Stage4 mode=ap name=\
- cfg5Stage4 rx-chains=0,1,2 ssid=HotelRING tx-chains=0,1,2
- add channel=channel1 country=russia2 datapath=datapath2Stage4 mode=ap name=\
- cfg1Stage4 rx-chains=0,1,2 ssid=HotelRING tx-chains=0,1,2
- add channel=channel11 country=russia2 datapath=datapath2Stage4 mode=ap name=\
- cfg11_Stage4 rx-chains=0,1,2 ssid=HotelRING tx-chains=0,1,2
- add channel=channel1 country=russia2 datapath=datapath4Stage2 mode=ap name=\
- cfg1Stage0 rx-chains=0,1,2 ssid=HotelRING tx-chains=0,1,2
- add channel=channel1 country=russia2 datapath=datapath4Stage2 mode=ap name=\
- cfg1Stage2DublinBar rx-chains=0,1,2 ssid=HotelRING tx-chains=0,1,2
- add channel=channel11 country=russia2 datapath=datapath4Stage2 mode=ap name=\
- cfg11Stage0 rx-chains=0,1,2 ssid=HotelRING tx-chains=0,1,2
- add channel=channel6 country=russia2 datapath=datapath4Stage2 mode=ap name=\
- cfg6Stage1 rx-chains=0,1,2 ssid=HotelRING tx-chains=0,1,2
- /caps-man interface
- add comment=Hostel configuration=cfg1Stage2DublinBar disabled=no l2mtu=1600 \
- mac-address=B8:69:F4:2E:6E:F1 master-interface=none name=MikroTik_Hostel \
- radio-mac=B8:69:F4:2E:6E:F1
- add comment=Letka configuration=cfg6_Stage2 disabled=no l2mtu=1600 \
- mac-address=CC:2D:E0:A7:3E:F2 master-interface=none name=MikroTik_Letka \
- radio-mac=CC:2D:E0:A7:3E:F2
- add comment="Stage 0_Prachka" configuration=cfg11Stage0 disabled=no l2mtu=\
- 1600 mac-address=64:D1:54:F3:E6:FE master-interface=none name=\
- MikroTik_Stage0_Prachka radio-mac=64:D1:54:F3:E6:FE
- add comment="Stage 0_Sauna \B91" configuration=cfg1Stage0 disabled=no l2mtu=\
- 1600 mac-address=CC:2D:E0:01:15:25 master-interface=none name=\
- "MikroTik_Stage0_Sauna\B91" radio-mac=CC:2D:E0:01:15:25
- add comment="Stage 0_Sauna \B93" configuration=cfg11Stage0 disabled=yes \
- l2mtu=1600 mac-address=CC:2D:E0:02:51:74 master-interface=none name=\
- "MikroTik_Stage0_Sauna\B93" radio-mac=CC:2D:E0:02:51:74
- add comment="Stage 1" configuration=cfg1_Stage2 disabled=no l2mtu=1600 \
- mac-address=CC:2D:E0:19:D2:93 master-interface=none name=\
- "MikroTik_Stage1\B9101" radio-mac=CC:2D:E0:19:D2:93
- add configuration=cfg1_Stage2 disabled=no l2mtu=1600 mac-address=\
- CC:2D:E0:EF:A1:F1 master-interface=none name="MikroTik_Stage1\B9107" \
- radio-mac=CC:2D:E0:EF:A1:F1
- add comment="Stage 2" configuration=cfg6_Stage2 disabled=no l2mtu=1600 \
- mac-address=74:4D:28:98:C7:EF master-interface=none name=\
- "MikroTik_Stage2\B9201" radio-mac=74:4D:28:98:C7:EF
- add configuration=cfg11_Stage2 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:26:FA:47 master-interface=none name="MikroTik_Stage2\B9205" \
- radio-mac=64:D1:54:26:FA:47
- add configuration=cfg6_Stage2 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:14:4B:83 master-interface=none name="MikroTik_Stage2\B9209" \
- radio-mac=64:D1:54:14:4B:83
- add configuration=cfg11_Stage2 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:25:29:DD master-interface=none name="MikroTik_Stage2\B9215" \
- radio-mac=64:D1:54:25:29:DD
- add comment="Stage 3" configuration=cfg1Stage3 disabled=no l2mtu=1600 \
- mac-address=CC:2D:E0:BE:0A:0F master-interface=none name=\
- "MikroTik_Stage3\B9301" radio-mac=CC:2D:E0:BE:0A:0F
- add configuration=cfg6Stage3 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:25:29:8F master-interface=none name="MikroTik_Stage3\B9305" \
- radio-mac=64:D1:54:25:29:8F
- add configuration=cfg11Stage3 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:44:C0:CF master-interface=none name="MikroTik_Stage3\B9309" \
- radio-mac=64:D1:54:44:C0:CF
- add configuration=cfg1Stage3 disabled=no l2mtu=1600 mac-address=\
- CC:2D:E0:0A:6A:EC master-interface=none name="MikroTik_Stage3\B9312" \
- radio-mac=CC:2D:E0:0A:6A:EC
- add configuration=cfg1Stage3 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:44:C0:AB master-interface=none name="MikroTik_Stage3\B9315" \
- radio-mac=64:D1:54:44:C0:AB
- add comment="Stage 4" configuration=cfg11_Stage4 disabled=no l2mtu=1600 \
- mac-address=CC:2D:E0:BE:73:6F master-interface=none name=\
- "MikroTik_Stage4\B9401" radio-mac=CC:2D:E0:BE:73:6F
- add configuration=cfg1Stage4 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:46:D1:0B master-interface=none name="MikroTik_Stage4\B9405" \
- radio-mac=64:D1:54:46:D1:0B
- add configuration=cfg5Stage4 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:49:BF:83 master-interface=none name="MikroTik_Stage4\B9409" \
- radio-mac=64:D1:54:49:BF:83
- add configuration=cfg11_Stage4 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:EC:19:FF master-interface=none name="MikroTik_Stage4\B9415" \
- radio-mac=64:D1:54:EC:19:FF
- /ip neighbor discovery
- set MikroTik_Hostel discover=no
- set MikroTik_Stage0_Prachka discover=no
- set "MikroTik_Stage0_Sauna\B91" discover=no
- set "MikroTik_Stage0_Sauna\B93" discover=no
- set "MikroTik_Stage1\B9101" discover=no
- set "MikroTik_Stage2\B9205" discover=no
- set "MikroTik_Stage2\B9209" discover=no
- set "MikroTik_Stage2\B9215" discover=no
- set "MikroTik_Stage3\B9301" discover=no
- set "MikroTik_Stage3\B9305" discover=no
- set "MikroTik_Stage3\B9309" discover=no
- set "MikroTik_Stage3\B9312" discover=no
- set "MikroTik_Stage3\B9315" discover=no
- set "MikroTik_Stage4\B9401" discover=no
- set "MikroTik_Stage4\B9405" discover=no
- set "MikroTik_Stage4\B9409" discover=no
- set "MikroTik_Stage4\B9415" discover=no
- set UnlimitedSpeedVlan7 discover=no
- set VideoVlan4 discover=no
- /caps-man security
- add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm \
- name=security1 passphrase=*****
- add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm \
- name=securityVIP passphrase=****
- add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm \
- name=securityTehnicalWifi passphrase=*******
- /caps-man configuration
- add channel=channel6 country=russia2 datapath=datapath5 mode=ap name=\
- cfg6_315VIP rx-chains=0,1,2 security=securityVIP ssid=VIP tx-chains=0,1,2
- add channel=channel6 country=russia2 datapath=datapath5 mode=ap name=\
- cfg1Stage2DublinBar_VIP rx-chains=0,1,2 security=securityVIP ssid=VIP \
- tx-chains=0,1,2
- add channel=channel1 country=russia2 datapath=datapath5 mode=ap name=\
- cfg1LetkaVIP rx-chains=0,1,2 security=securityVIP ssid=VIP tx-chains=\
- 0,1,2
- add channel=channel11 country=russia2 datapath=datapath1Stage1 mode=ap name=\
- cfg11Stage3_TehnicalWI-FI rx-chains=0,1,2 security=securityTehnicalWifi \
- ssid=TehnicalWifi tx-chains=0,1,2
- add channel=channel5 country=russia2 datapath=datapath1Stage1 mode=ap name=\
- cfg4Stage4_Tehnical_Wifi rx-chains=0,1,2 security=securityTehnicalWifi \
- ssid=TehnicalWifi tx-chains=0,1,2
- /caps-man interface
- add configuration=cfg1LetkaVIP disabled=no l2mtu=1600 mac-address=\
- CC:2D:E0:A7:3E:F2 master-interface=MikroTik_Letka name=\
- "MikroTIK LetkaVIP" radio-mac=CC:2D:E0:A7:3E:F2
- add configuration=cfg4Stage4_Tehnical_Wifi disabled=no l2mtu=1600 \
- mac-address=64:D1:54:49:BF:83 master-interface="MikroTik_Stage4\B9409" \
- name="MikroTikStage4\B9409_TehnicalWifi" radio-mac=64:D1:54:49:BF:83
- add configuration=cfg11Stage3_TehnicalWI-FI disabled=no l2mtu=1600 \
- mac-address=64:D1:54:44:C0:CF master-interface="MikroTik_Stage3\B9309" \
- name=MikroTik_Stage3N309Tehnikal_Wifi radio-mac=64:D1:54:44:C0:CF
- add configuration=cfg6_315VIP disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:44:C0:AB master-interface="MikroTik_Stage3\B9315" name=\
- MikroTik_Stage3N315_VIP radio-mac=64:D1:54:44:C0:AB
- /interface wireless security-profiles
- set [ find default=yes ] supplicant-identity=MikroTik
- /ip firewall layer7-protocol
- add name=Block regexp="^.+(youtube.com|ok.ru|vk.com).*\$"
- /ip hotspot user profile
- set [ find default=yes ] keepalive-timeout=2h shared-users=unlimited \
- status-autorefresh=1d
- /ip ipsec proposal
- set [ find default=yes ] auth-algorithms=sha1,md5 enc-algorithms=\
- aes-128-cbc,3des
- /ip pool
- add name=PoolVlan2 ranges=172.16.1.40-172.16.1.254
- add name=PoolVlan3 ranges=172.16.3.30-172.16.3.254
- add name=PoolVlan9 ranges=172.16.9.30-172.16.9.254
- add name=PoolVlan7 ranges=172.16.7.30-172.16.7.254
- add name=PoolVlan4 ranges=172.16.4.30-172.16.4.254
- add name=dhcp_pool12 ranges=172.16.8.30-172.16.8.254
- add name=dhcp_pool14 ranges=172.16.5.30-172.16.5.254
- /ip dhcp-server
- add address-pool=PoolVlan2 disabled=no interface=ManagementVlan2 lease-time=\
- 1d name=ServerdhcpVlan2
- add address-pool=PoolVlan3 disabled=no interface="Network of ServersVlan3" \
- lease-time=1d name=ServerdhcpVlan3
- # DHCP server can not run on slave interface!
- add address-pool=PoolVlan9 disabled=no interface=Teh.PersonalVlan9 \
- lease-time=1d name=ServerdhcpVlan9
- add address-pool=PoolVlan7 disabled=no interface=bridgeVIP lease-time=1d \
- name=ServerdhcpVlan7
- add address-pool=PoolVlan4 disabled=no interface=VideoVlan4 lease-time=1d \
- name=ServerdhcpVlan4
- add address-pool=dhcp_pool12 disabled=no interface=VoiceVlan8 lease-time=\
- 1d10m name=dhcp1
- add address-pool=dhcp_pool14 disabled=no interface=bridgeVPN lease-time=1d10m \
- name=dhcp2
- /ppp profile
- add dns-server=172.16.9.1 local-address=172.16.9.1 name=MyVPN remote-address=\
- PoolVlan9 wins-server=8.8.8.8
- /queue tree
- add comment="\C3\EB\EE\E1\E0\EB\FC\ED\E0\FF \EE\F7\E5\F0\E5\E4\FC In" \
- max-limit=95M name=in parent=global
- add comment="\C3\EB\EE\E1\E0\EB\FC\ED\E0\FF \EE\F7\E5\F0\E5\E4\FC out" \
- max-limit=95M name=out parent=global
- /queue type
- add kind=pcq name=pcq-upload-7M pcq-classifier=src-address \
- pcq-dst-address6-mask=64 pcq-rate=7M pcq-src-address6-mask=64
- add kind=pcq name=sip pcq-classifier=\
- src-address,dst-address,src-port,dst-port pcq-dst-address6-mask=64 \
- pcq-rate=100k pcq-src-address6-mask=64
- add kind=pcq name=rdp pcq-classifier=dst-address pcq-dst-address6-mask=64 \
- pcq-rate=1M pcq-src-address6-mask=64
- /queue tree
- add comment="\C2\F5\EE\E4 \F2\F0\E0\F4\E8\EA WEB \F7\E5\F0\E5\E7 \E8\ED\F2\E5\
- \F0\F4\E5\E9\F1 Wan" max-limit=95M name=Web packet-mark=Web_in parent=in \
- priority=5 queue=pcq-download-default
- add comment="\C8\F1\F5\EE\E4 \F2\F0\E0\F4\E8\EA WEB \F7\E5\F0\E5\E7 \E8\ED\F2\
- \E5\F0\F4\E5\E9\F1 Wan" max-limit=95M name=Web_out packet-mark=Web_out \
- parent=out priority=5 queue=pcq-upload-default
- add comment="\D2\F0\E0\F4\E8\EA \E8\E7 VPN \EA\E0\ED\E0\EB" max-limit=20M \
- name=VPN_in packet-mark=PPTP_in,gre_in parent=in priority=3 queue=\
- pcq-download-default
- add comment="\D2\F0\E0\F4\E8\EA \E2 VPN \EA\E0\ED\E0\EB" max-limit=20M name=\
- VPN_out packet-mark=PPTP_out,gre_out parent=out priority=3 queue=\
- pcq-upload-default
- add comment="IP \D2\E5\EB\E5\F4\EE\ED\E8\FF \E2\F5\EE\E4 \F2\F0\E0\F4\E8\EA" \
- max-limit=5M name=Sip_in packet-mark=SIP_in parent=in priority=1 queue=\
- sip
- add comment=\
- "IP \D2\E5\EB\E5\F4\EE\ED\E8\FF \E8\F1\F5\EE\E4 \F2\F0\E0\F4\E8\EA" \
- max-limit=5M name=SIP_out packet-mark=SIP_out parent=out priority=1 \
- queue=sip
- add comment="\CF\F0\EE\F7\E8\E9 \F2\F0\E0\F4\E8\EA" max-limit=4M name=all_in \
- packet-mark=all_in parent=in queue=pcq-download-default
- add comment="\CF\F0\EE\F7\E8\E9 \F2\F0\E0\F4\E8\EA" max-limit=4M name=all_out \
- packet-mark=all_out parent=out queue=pcq-download-default
- add max-limit=20M name=VPN_web_in packet-mark=VPN_web_in parent=VPN_in \
- priority=5 queue=pcq-download-default
- add max-limit=20M name=VPN_Web_out packet-mark=VPN_Web_out parent=VPN_out \
- priority=5 queue=pcq-upload-default
- add max-limit=2M name=VPN_Sip_in packet-mark=VPN_Sip_in parent=VPN_in \
- priority=1 queue=sip
- add max-limit=2M name=VPN_Sip_out packet-mark=VPN_Sip_out parent=VPN_out \
- priority=1 queue=sip
- add max-limit=20M name=VPN_RDP_in packet-mark=VPN_RDP_in parent=VPN_in \
- priority=5 queue=rdp
- add max-limit=20M name=VPN_RDP_out packet-mark=VPN_RDP_out parent=VPN_out \
- priority=5 queue=rdp
- add max-limit=10M name=VPN_all_in packet-mark=VPN_all_in parent=VPN_in queue=\
- pcq-download-default
- add max-limit=10M name=VPN_all_out packet-mark=VPN_all_out parent=VPN_out \
- queue=pcq-upload-default
- /caps-man manager
- set enabled=yes
- /caps-man provisioning
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg6_Stage2 radio-mac=64:D1:54:14:4B:7E
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg11_Stage2 radio-mac=64:D1:54:25:29:D8 slave-configurations=\
- cfg1Stage2DublinBar_VIP
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg11Stage3 radio-mac=64:D1:54:25:29:8A
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg6Stage3 radio-mac=64:D1:54:44:C0:A6 slave-configurations=cfg6_315VIP
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg2Stage3 radio-mac=64:D1:54:44:C0:CA slave-configurations=\
- cfg11Stage3_TehnicalWI-FI
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg5Stage4 radio-mac=64:D1:54:49:BF:7E slave-configurations=\
- cfg4Stage4_Tehnical_Wifi
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1Stage4 radio-mac=64:D1:54:46:D1:06
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg11_Stage4 radio-mac=64:D1:54:EC:19:FA
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg11_Stage2 radio-mac=64:D1:54:26:FA:42
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1Stage0 radio-mac=64:D1:54:F3:E6:F9
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1Stage2DublinBar radio-mac=CC:2D:E0:12:2C:2E
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1Stage0 radio-mac=CC:2D:E0:01:15:20
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg11Stage0 radio-mac=CC:2D:E0:02:51:6F
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg11_Stage4 radio-mac=CC:2D:E0:BE:73:6A
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1Stage3 radio-mac=CC:2D:E0:0A:6A:EC
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1Stage2DublinBar radio-mac=B8:69:F4:2E:6E:F1
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1Stage3 radio-mac=CC:2D:E0:BE:0A:0A
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1_Stage2 radio-mac=CC:2D:E0:19:D2:8E
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg6_Stage2 radio-mac=CC:2D:E0:A7:3E:ED slave-configurations=cfg1LetkaVIP
- add action=create-dynamic-enabled master-configuration=cfg1_Stage2 radio-mac=\
- CC:2D:E0:EF:A1:EC
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg6_Stage2 radio-mac=74:4D:28:98:C7:EA
- /interface bridge port
- add bridge=bridgeVIP interface=UnlimitedSpeedVlan7
- add bridge=bridgeVPN interface=ether2
- add bridge=bridge_DOM.RU interface=ether1
- add bridge=bridge_DOM.RU interface=vlan_Dom.Ru
- add bridge=bridgeTehnicalWifi interface=Teh.PersonalVlan9
- /interface l2tp-server server
- set authentication=mschap2 enabled=yes ipsec-secret=************ use-ipsec=yes
- /interface pptp-server server
- set default-profile=MyVPN enabled=yes
- /ip address
- add address=172.16.1.1/24 comment="Network device management MGMT" interface=\
- ManagementVlan2 network=172.16.1.0
- add address=172.16.3.1/24 comment="Servers network" interface=\
- "Network of ServersVlan3" network=172.16.3.0
- add address=172.16.4.1/24 comment="Network video" interface=VideoVlan4 \
- network=172.16.4.0
- add address=172.16.7.1/24 comment="Unlimited speed" interface=bridgeVIP \
- network=172.16.7.0
- add address=172.16.9.1/24 comment=Personal interface=bridgeTehnicalWifi \
- network=172.16.9.0
- add address=************/24 comment="ISP 1 Rostelekom " \
- interface=ether6 network=85.172.120.0
- add address=172.16.8.1/24 comment=Voice interface=VoiceVlan8 network=\
- 172.16.8.0
- add address=172.16.5.1/24 comment=VPN interface=bridgeVPN network=172.16.5.0
- /ip dhcp-client
- add dhcp-options=hostname,clientid disabled=no interface=ether6
- /ip dhcp-server alert
- add disabled=no interface=ManagementVlan2
- /ip dhcp-server lease
- add address=172.16.9.33 always-broadcast=yes client-id=1:0:25:ab:1a:6:6c \
- mac-address=00:25:AB:1A:06:6C server=ServerdhcpVlan9
- add address=172.16.10.161 always-broadcast=yes client-id=1:0:6d:52:15:13:a3 \
- mac-address=00:6D:52:15:13:A3
- add address=172.16.9.51 always-broadcast=yes client-id=1:0:1b:67:15:8f:bd \
- mac-address=00:1B:67:15:8F:BD server=ServerdhcpVlan9
- add address=172.16.20.135 client-id=1:0:6d:52:15:13:a3 mac-address=\
- 00:6D:52:15:13:A3
- add address=172.16.9.45 always-broadcast=yes client-id=1:e0:b9:4d:e4:45:cc \
- mac-address=E0:B9:4D:E4:45:CC server=ServerdhcpVlan9
- add address=172.16.9.50 client-id=1:90:2b:34:cf:94:af mac-address=\
- 90:2B:34:CF:94:AF server=ServerdhcpVlan9
- add address=172.16.9.42 client-id=1:0:b0:6c:1b:88:af mac-address=\
- 00:B0:6C:1B:88:AF server=ServerdhcpVlan9
- add address=172.16.9.43 always-broadcast=yes client-id=1:8:ea:40:88:7e:c2 \
- mac-address=08:EA:40:88:7E:C2 server=ServerdhcpVlan9
- add address=172.16.9.32 client-id=1:44:19:b6:92:9:1b mac-address=\
- 44:19:B6:92:09:1B server=ServerdhcpVlan9
- add address=172.16.9.57 always-broadcast=yes client-id=1:0:95:69:d6:60:6a \
- mac-address=00:95:69:D6:60:6A server=ServerdhcpVlan9
- add address=172.16.9.35 always-broadcast=yes client-id=1:0:b0:6c:1b:5e:3e \
- mac-address=00:B0:6C:1B:5E:3E server=ServerdhcpVlan9
- add address=172.16.9.41 always-broadcast=yes client-id=1:8:ea:40:fb:c9:93 \
- mac-address=08:EA:40:FB:C9:93 server=ServerdhcpVlan9
- add address=172.16.9.34 client-id=1:0:e0:b4:6:f:7 mac-address=\
- 00:E0:B4:06:0F:07 server=ServerdhcpVlan9
- add address=172.16.9.49 client-id=1:54:c4:15:96:d:1a mac-address=\
- 54:C4:15:96:0D:1A server=ServerdhcpVlan9
- add address=172.16.9.52 always-broadcast=yes client-id=1:ec:3d:fd:80:63:ff \
- mac-address=EC:3D:FD:80:63:FF server=ServerdhcpVlan9
- add address=172.16.9.44 client-id=1:b4:a3:82:aa:38:f mac-address=\
- B4:A3:82:AA:38:0F server=ServerdhcpVlan9
- add address=172.16.9.67 client-id=1:44:19:b6:92:8:9a mac-address=\
- 44:19:B6:92:08:9A server=ServerdhcpVlan9
- add address=172.16.9.30 client-id=1:bc:1c:81:87:d3:73 mac-address=\
- BC:1C:81:87:D3:73 server=ServerdhcpVlan9
- add address=172.16.40.131 client-id=1:48:98:ca:46:e8:5c mac-address=\
- 48:98:CA:46:E8:5C
- add address=172.16.30.75 client-id=1:bc:1c:81:87:d3:73 mac-address=\
- BC:1C:81:87:D3:73
- add address=172.16.1.31 client-id=1:0:27:7:0:f1:c2 mac-address=\
- 00:27:07:00:F1:C2 server=ServerdhcpVlan2
- add address=172.16.9.106 client-id=1:4:e:3c:68:af:7a mac-address=\
- 04:0E:3C:68:AF:7A server=ServerdhcpVlan9
- /ip dhcp-server network
- add address=172.16.1.0/24 dns-server=172.16.1.1,8.8.8.8 gateway=172.16.1.1
- add address=172.16.3.0/24 dns-server=172.16.3.1,8.8.8.8 gateway=172.16.3.1
- add address=172.16.4.0/24 dns-server=172.16.4.1,8.8.8.8 gateway=172.16.4.1
- add address=172.16.5.0/24 dns-server=172.16.5.1,8.8.8.8 gateway=172.16.5.1
- add address=172.16.6.0/24 dns-server=172.16.6.1,8.8.8.8 gateway=172.16.6.1
- add address=172.16.7.0/24 dns-server=172.16.7.1,8.8.8.8 gateway=172.16.7.1
- add address=172.16.8.0/24 dns-server=172.16.8.1,8.8.8.8 gateway=172.16.8.1
- add address=172.16.9.0/24 dns-server=172.16.9.1,8.8.8.8 gateway=172.16.9.1
- add address=172.16.10.0/24 dns-server=172.16.10.1,8.8.8.8 gateway=172.16.10.1
- add address=172.16.20.0/24 dns-server=172.16.20.1,8.8.8.8 gateway=172.16.20.1
- add address=172.16.30.0/24 dns-server=172.16.30.1,8.8.8.8 gateway=172.16.30.1
- add address=172.16.40.0/24 dns-server=172.16.40.1,8.8.8.8 gateway=172.16.40.1
- /ip dns
- set allow-remote-requests=yes servers=8.8.8.8
- /ip firewall address-list
- add address=************ list=Winbox
- add address=************ list=Winbox
- add address=************ list=Winbox
- add address=************ list=Winbox
- add address=************ list=Winbox_White
- add address=************ list=Winbox_White
- add address=************ list=Winbox_White
- add address=************ list=Winbox_White
- add address=172.16.9.159 list=Social_Net_White
- add address=172.16.9.134 list=Social_Net_White
- add address=************ list=VOIP
- /ip firewall filter
- add action=drop chain=input disabled=yes src-address=************
- add action=accept chain=forward comment="VOIP RTP" disabled=yes dst-port=\
- 10000-20000 protocol=udp
- add action=accept chain=forward disabled=yes dst-port=10000-20000 protocol=\
- tcp
- add action=accept chain=forward disabled=yes dst-port=5060-5065 protocol=udp
- add action=accept chain=input comment=PPP dst-port=1701 protocol=udp
- add action=accept chain=input dst-port=1723 protocol=udp
- add action=accept chain=forward disabled=yes dst-port=4000 protocol=tcp
- add action=drop chain=input comment="drop PPTP brute forcers" disabled=yes \
- dst-port=1723 protocol=tcp src-address-list=PPTP_blacklist
- add action=add-src-to-address-list address-list=PPTP_blacklist \
- address-list-timeout=1w3d chain=input connection-state=new disabled=yes \
- dst-port=1723 protocol=tcp src-address-list=PPTP_stage3
- add action=add-src-to-address-list address-list=PPTP_stage3 \
- address-list-timeout=1m chain=input connection-state=new disabled=yes \
- dst-port=1723 protocol=tcp src-address-list=PPTP_stage2
- add action=add-src-to-address-list address-list=PPTP_stage2 \
- address-list-timeout=1m chain=input connection-state=new disabled=yes \
- dst-port=1723 protocol=tcp src-address-list=PPTP_stage1
- add action=add-src-to-address-list address-list=PPTP_stage1 \
- address-list-timeout=1m chain=input connection-state=new disabled=yes \
- dst-port=1723 protocol=tcp
- add action=reject chain=forward comment="drop PPTP brute downstream" \
- disabled=yes dst-port=1723 protocol=tcp reject-with=\
- icmp-network-unreachable src-address-list=PPTP_blacklist
- add action=reject chain=input comment="drop Winbox brute forcers" dst-port=\
- 8291 protocol=tcp reject-with=icmp-network-unreachable src-address-list=\
- Winbox_blacklist
- add action=add-src-to-address-list address-list=Winbox_blacklist \
- address-list-timeout=0s chain=input connection-state=new dst-port=8291 \
- protocol=tcp src-address-list=Winbox_stage1
- add action=add-src-to-address-list address-list=Winbox_stage1 \
- address-list-timeout=1m chain=input connection-state=new dst-port=8291 \
- protocol=tcp src-address-list=!Winbox_White
- add action=drop chain=forward comment="Printers Reseption hp laserJet 428" \
- src-address=172.16.9.225
- add action=accept chain=input protocol=gre
- add action=reject chain=forward comment="Block List Social network" disabled=\
- yes layer7-protocol=Block log=yes log-prefix=Social_net protocol=tcp \
- reject-with=tcp-reset src-address=172.16.9.0/24 src-address-list=\
- !Social_Net_White
- add action=passthrough chain=unused-hs-chain comment=\
- "place hotspot rules here"
- add action=drop chain=input comment="DNS ROSTELEKOM" dst-port=53 \
- in-interface=ether6 protocol=udp
- add action=drop chain=input comment="DNS DOM.RU" dst-port=53 in-interface=\
- pppoe-out1 protocol=udp
- add action=drop chain=output comment="GOOGLE PING DENY 8.8.4.4" dst-address=\
- 8.8.4.4 out-interface=pppoe-out1
- add action=accept chain=input comment=Estabilished/Related connection-state=\
- established,related
- add action=accept chain=forward connection-state=established,related
- add action=drop chain=forward comment=Invalid connection-state=invalid
- add action=drop chain=input connection-state=invalid in-interface=ether6
- add action=accept chain=forward comment=IpSec dst-port=500 protocol=udp
- add action=accept chain=forward dst-port=4500 protocol=udp
- add action=accept chain=input comment="Allow IPSec-esp" protocol=ipsec-esp
- add action=accept chain=input comment="Allow IPSec-ah" protocol=ipsec-ah
- add action=accept chain=input comment=WinBox dst-port=8291 in-interface=\
- ether6 protocol=tcp src-address-list=Winbox
- add action=accept chain=input comment="Allow ping" protocol=icmp
- add action=accept chain=forward comment=Video dst-port=34567 protocol=tcp
- add action=accept chain=forward dst-port=90 protocol=tcp
- add action=accept chain=forward comment="IIS Server" dst-port=80 protocol=tcp
- add action=accept chain=input comment=Iwinbox dst-port=8728 in-interface=\
- ether6 protocol=tcp
- add action=accept chain=input comment="Allow UDP" protocol=udp
- /ip firewall mangle
- add action=mark-connection chain=input comment=PPTP dst-port=1723 \
- new-connection-mark=PPTP_in passthrough=no protocol=tcp
- add action=mark-packet chain=prerouting connection-mark=PPTP_in \
- new-packet-mark=PPTP_out passthrough=no
- add action=mark-connection chain=output new-connection-mark=PPTP_out \
- passthrough=no protocol=tcp src-port=1723
- add action=mark-packet chain=postrouting connection-mark=PPTP_out \
- new-packet-mark=PPTP_in passthrough=no
- add action=mark-connection chain=input comment=GRE new-connection-mark=gre_in \
- passthrough=no protocol=gre
- add action=mark-connection chain=output new-connection-mark=gre_out \
- passthrough=no protocol=gre
- add action=mark-packet chain=prerouting connection-mark=gre_in \
- new-packet-mark=gre_out passthrough=no
- add action=mark-packet chain=postrouting connection-mark=gre_out \
- new-packet-mark=gre_in passthrough=no
- add action=mark-connection chain=prerouting comment=WEB dst-port=80,443,8080 \
- new-connection-mark=WEB passthrough=no protocol=tcp
- add action=mark-packet chain=forward connection-mark=WEB new-packet-mark=\
- VPN_web_in out-interface=all-ppp passthrough=no
- add action=mark-packet chain=forward connection-mark=WEB in-interface=all-ppp \
- new-packet-mark=VPN_Web_out passthrough=no
- add action=mark-packet chain=forward connection-mark=WEB in-interface=ether6 \
- new-packet-mark=Web_in passthrough=no
- add action=mark-packet chain=forward connection-mark=WEB new-packet-mark=\
- Web_out out-interface=ether6 passthrough=no
- add action=mark-connection chain=prerouting comment=RDP dst-port=3389 \
- new-connection-mark=RDP passthrough=no protocol=tcp
- add action=mark-packet chain=forward connection-mark=RDP new-packet-mark=\
- VPN_RDP_in out-interface=all-ppp passthrough=no
- add action=mark-packet chain=forward connection-mark=RDP in-interface=all-ppp \
- new-packet-mark=VPN_RDP_out passthrough=no
- add action=mark-connection chain=prerouting comment=SIP dst-port=\
- 5060,20000-22000 new-connection-mark=SIP passthrough=no protocol=udp
- add action=mark-packet chain=forward connection-mark=SIP in-interface=all-ppp \
- new-packet-mark=VPN_Sip_out passthrough=no
- add action=mark-packet chain=forward connection-mark=SIP new-packet-mark=\
- VPN_Sip_in out-interface=all-ppp passthrough=no
- add action=mark-packet chain=forward connection-mark=SIP in-interface=ether6 \
- new-packet-mark=SIP_in passthrough=no
- add action=mark-packet chain=forward connection-mark=SIP new-packet-mark=\
- SIP_out out-interface=ether6 passthrough=no
- add action=mark-packet chain=forward comment=all in-interface=all-ppp \
- new-packet-mark=VPN_all_out passthrough=no
- add action=mark-packet chain=forward new-packet-mark=VPN_all_in \
- out-interface=all-ppp passthrough=no
- # in/out-interface matcher not possible when interface (ether1) is slave - use master instead (bridge_DOM.RU)
- add action=mark-packet chain=forward in-interface=ether1 new-packet-mark=\
- all_in passthrough=no
- # in/out-interface matcher not possible when interface (ether1) is slave - use master instead (bridge_DOM.RU)
- add action=mark-packet chain=forward new-packet-mark=all_out out-interface=\
- ether1 passthrough=no
- /ip firewall nat
- add action=dst-nat chain=dstnat comment="NomachineNX \C8\E2\E0\ED" dst-port=\
- 1050 protocol=tcp to-addresses=172.16.9.210 to-ports=1050
- add action=dst-nat chain=dstnat comment=NextCloud dst-port=92 protocol=tcp \
- to-addresses=172.16.9.212 to-ports=92
- add action=dst-nat chain=dstnat comment="NextCloud SSH" dst-port=93 protocol=\
- tcp to-addresses=172.16.9.211 to-ports=443
- add action=dst-nat chain=dstnat comment=Radmin disabled=yes dst-port=4899 \
- protocol=tcp to-addresses=172.16.3.16 to-ports=4899
- add action=dst-nat chain=dstnat comment=Lift dst-port=46000 in-interface=\
- ether6 protocol=tcp src-address-list=Lift to-addresses=172.16.1.31 \
- to-ports=46000
- add action=dst-nat chain=dstnat dst-port=46001 in-interface=ether6 protocol=\
- udp src-address-list=Lift to-addresses=172.16.1.31 to-ports=46001
- add action=passthrough chain=unused-hs-chain comment=\
- "place hotspot rules here" disabled=yes
- add action=dst-nat chain=dstnat comment=ZABBIX dst-port=2255 in-interface=\
- ether6 protocol=tcp to-addresses=172.16.3.9 to-ports=80
- add action=dst-nat chain=dstnat comment="ZABBIX SSH" disabled=yes dst-port=\
- 2222 in-interface=ether6 protocol=tcp to-addresses=172.16.3.9 to-ports=22
- add action=dst-nat chain=dstnat comment="Debian backup SSH" disabled=yes \
- dst-port=2233 in-interface=ether6 protocol=tcp to-addresses=172.16.3.17 \
- to-ports=22
- add action=accept chain=srcnat comment="IPSec VPN Erevan" dst-address=\
- 192.168.1.0/24 src-address=172.16.9.0/24
- add action=accept chain=srcnat comment="IPSec VPN \C0\E4\EB\E5\F0" \
- dst-address=172.18.1.0/24 src-address=172.16.3.0/24
- add action=accept chain=srcnat comment="IPSec VPN BASE VOLGOGRAD" \
- dst-address=10.8.0.0/24 src-address=172.16.3.0/24
- add action=accept chain=srcnat dst-address=10.8.0.0/24 src-address=\
- 172.16.9.0/24
- add action=dst-nat chain=dstnat comment="Apache Server" dst-port=82 \
- in-interface=ether6 protocol=tcp to-addresses=172.16.3.6 to-ports=81
- add action=dst-nat chain=dstnat comment="EDS Server" dst-port=80 \
- in-interface=ether6 protocol=tcp to-addresses=172.16.3.17 to-ports=80
- add action=dst-nat chain=dstnat dst-port=96 in-interface=ether6 protocol=tcp \
- to-addresses=172.16.4.4 to-ports=34567
- add action=dst-nat chain=dstnat dst-port=90 in-interface=ether6 protocol=tcp \
- to-addresses=172.16.4.3 to-ports=90
- add action=masquerade chain=srcnat comment="Nat rostelekom" out-interface=\
- ether6
- add action=masquerade chain=srcnat comment="Nat Dom.ru" out-interface=\
- pppoe-out1
- /ip firewall service-port
- set sip disabled=yes
- /ip hotspot user
- add name=admin
- /ip ipsec peer
- add address=************/32 comment="Tayshetskiy 10" enc-algorithm=3des \
- exchange-mode=main-l2tp generate-policy=port-override hash-algorithm=md5 \
- passive=yes secret=HXXB4-XR9QR
- add address=194.114.128.135/32 comment=ADLER dh-group=modp1536 passive=yes \
- secret=HXXB4-XR9QR
- /ip ipsec policy
- add dst-address=10.8.0.0/24 sa-dst-address=************ sa-src-address=\
- ************ src-address=172.16.3.0/24 tunnel=yes
- add comment=Adler dst-address=172.18.1.0/24 sa-dst-address=************ \
- sa-src-address=************ src-address=172.16.3.0/24 tunnel=yes
- add comment="Tayshetskiy 10" dst-address=10.8.0.0/24 sa-dst-address=\
- ************ sa-src-address=************ src-address=172.16.9.0/24 \
- tunnel=yes
- /ip route
- add comment=ISP1 distance=3 gateway=************
- add comment=ISP2 disabled=yes distance=2 gateway=pppoe-out1
- add comment=GOOGLE distance=1 dst-address=8.8.4.4/32 gateway=************
- add disabled=yes distance=1 dst-address=172.16.10.0/24 gateway=172.16.60.2
- add distance=1 dst-address=192.168.0.0/24 gateway=*F00134
- add comment="Route Erevan" distance=1 dst-address=192.168.1.0/24 gateway=\
- 172.16.32.2 pref-src=172.16.9.1
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set www disabled=yes port=99
- set ssh disabled=yes
- set api address=************/32 disabled=yes
- set winbox address="172.16.9.0/24,172.16.3.0/24,************/32,************\
- 2/32,************/32"
- set api-ssl disabled=yes
- /snmp
- set enabled=yes
- /system clock
- set time-zone-autodetect=no time-zone-name=Europe/Volgograd
- /system clock manual
- set time-zone=+03:00
- /system ntp client
- set enabled=yes primary-ntp=88.147.254.232 secondary-ntp=91.226.136.155 \
- server-dns-names=ntp1.stratum2.ru
- /system scheduler
- add disabled=yes interval=1w3d name=Reboot on-event=" /system reboot" policy=\
- ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
- start-date=oct/17/2017 start-time=03:00:00
- add interval=5d name=BackupRouterHotelRING on-event=\
- "/system script run ScriptBackup" policy=\
- ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
- start-date=nov/02/2017 start-time=23:00:24
- /system watchdog
- set automatic-supout=no no-ping-delay=1h watchdog-timer=no
- /tool bandwidth-server
- set authenticate=no
- /tool netwatch
- add down-script="/ip route enable [find comment=\"ISP2\"]" host=8.8.4.4 \
- interval=30s up-script="/ip route disable [find comment=\"ISP2\"]"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement