Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /interface bridge
- add fast-forward=no name="BRIDGE LAN ID 10"
- add name="bridge-GUEST ID30"
- add igmp-snooping=yes name="bridge-HDMI ID20" protocol-mode=none
- add name="bridge-TVCC ID50"
- add name=bridge-VLAN200
- add name=bridge-elettrodomestici
- /interface ethernet
- set [ find default-name=ether1 ] comment=WAN1
- set [ find default-name=ether2 ] comment="Camera lato strada" speed=100Mbps
- set [ find default-name=ether3 ] advertise=1000M-half,1000M-full comment=\
- Studio
- set [ find default-name=ether4 ] comment=vlan200-NAS
- set [ find default-name=ether5 ] comment="RB soggiorno"
- set [ find default-name=ether6 ] comment="Camera Matrimoniale"
- set [ find default-name=ether7 ] comment=Cucina
- set [ find default-name=ether8 ] comment="Camera lato strada"
- set [ find default-name=ether9 ] auto-negotiation=no comment=\
- "Stampante disimpegno" speed=10Mbps
- set [ find default-name=ether10 ] comment=TV-CC-LAN poe-out=off
- /interface pppoe-client
- add add-default-route=yes disabled=no interface=ether1 name=pppoe-out1 \
- password=dfrbgg445 user=dfbfgd351bg51
- /interface l2tp-client
- add connect-to=83.xx.xx.xxx disabled=no ipsec-secret=test@CHR_VPN max-mtu=\
- 1400 name="Vpn CHR" password=Trb@Fois use-ipsec=yes user=casa.test
- /interface vlan
- add interface=ether4 name=vlan-200_NAS vlan-id=200
- add interface=ether5 name=vlan10-LAN vlan-id=10
- add interface=ether10 name=vlan10-lan vlan-id=10
- add interface=ether3 name=vlan10>>studio vlan-id=10
- add interface=ether5 name=vlan20-hdmi vlan-id=20
- add interface=ether5 name=vlan30_guest vlan-id=30
- add interface=ether5 name=vlan40-elettrodomestici vlan-id=40
- add interface=ether10 name=vlan50-tvcc vlan-id=50
- add interface=ether3 name=vlan50>>studio vlan-id=50
- add interface=ether1 name=vlan835 vlan-id=835
- /ip pool
- add name=dhcp_pool_LAN ranges=10.246.159.150-10.246.159.155
- add name=dhcp_pool_privateNAS ranges=10.250.159.160-10.250.159.180
- add name=vpn_pool_private ranges=192.168.17.100-192.168.17.150
- add name=dhcp-serv_HDMI ranges=172.17.20.50-172.17.20.100
- add name=dhcp_pool_citofono ranges=10.246.161.100-10.246.161.200
- add name=dhcp-pool-guest ranges=172.16.20.2-172.16.20.50
- add name="dhcp pool elettrodomestici" ranges=10.246.162.100-10.246.162.120
- /ip dhcp-server
- add address-pool=dhcp_pool_LAN authoritative=after-2sec-delay disabled=no \
- interface="BRIDGE LAN ID 10" lease-time=12h name="dhcp server LAN"
- add address-pool=dhcp_pool_privateNAS disabled=no interface=bridge-VLAN200 \
- lease-time=12h name=dhcp-privateNAS
- add address-pool=dhcp-serv_HDMI disabled=no interface="bridge-HDMI ID20" \
- lease-time=12h name=dhcp-serv.hdmi
- add address-pool=dhcp-pool-guest disabled=no interface="bridge-GUEST ID30" \
- lease-time=4h10m name=dhcp-server
- # DHCP server can not run on slave interface!
- add address-pool="dhcp pool elettrodomestici" disabled=no interface=\
- vlan40-elettrodomestici lease-time=1d10m name="dhcp server ELETTRODOM."
- /ppp profile
- add change-tcp-mss=yes local-address=192.168.17.1 name="profile1-vpn private" \
- remote-address=vpn_pool_private use-encryption=yes
- /interface bridge port
- add bridge=bridge-VLAN200 interface=ether4
- add bridge="BRIDGE LAN ID 10" interface=vlan10-LAN
- add bridge="bridge-HDMI ID20" interface=ether6
- add bridge=bridge-VLAN200 interface=vlan-200_NAS
- add bridge="BRIDGE LAN ID 10" interface=ether7
- add bridge="BRIDGE LAN ID 10" interface=ether8
- add bridge="bridge-HDMI ID20" interface=vlan20-hdmi
- add bridge="BRIDGE LAN ID 10" interface=ether9
- add bridge="BRIDGE LAN ID 10" interface=wlan1
- add bridge="bridge-GUEST ID30" interface=wlan2
- add bridge="bridge-GUEST ID30" interface=vlan30-guest
- add bridge="bridge-TVCC ID50" interface=ether10
- add bridge="bridge-GUEST ID30" interface=vlan30_guest
- add bridge="BRIDGE LAN ID 10" interface=ether2
- add bridge="BRIDGE LAN ID 10" interface=vlan10-lan
- add bridge="bridge-TVCC ID50" interface=vlan50-tvcc
- add bridge="BRIDGE LAN ID 10" interface=vlan10>>studio
- add bridge="bridge-TVCC ID50" interface=vlan50>>studio
- add bridge="BRIDGE LAN ID 10" interface=vlan40-elettrodomestici
- /interface l2tp-server server
- set default-profile="profile1-vpn private" enabled=yes ipsec-secret=xxxxxxxx \
- max-mtu=1400 use-ipsec=yes
- /ip address
- add address=10.246.161.1/24 interface="bridge-TVCC ID50" network=10.246.161.0
- add address=10.246.159.50/24 interface="BRIDGE LAN ID 10" network=\
- 10.246.159.0
- add address=10.250.159.1/24 interface=bridge-VLAN200 network=10.250.159.0
- add address=172.17.20.1/24 interface="bridge-HDMI ID20" network=172.17.20.0
- add address=172.16.20.1/24 interface="bridge-GUEST ID30" network=172.16.20.0
- add address=192.168.178.2/24 interface=ether1 network=192.168.178.0
- add address=10.246.162.1/24 interface=vlan40-elettrodomestici network=\
- 10.246.162.0
- /ip dns
- set allow-remote-requests=yes servers=1.1.1.1
- /ip firewall address-list
- add address=10.246.159.3 list="IP FABIO"
- add address=10.246.159.5 list="IP FABIO"
- add address=10.246.159.7 list="IP FABIO"
- add address=10.246.159.2 list="IP FABIO"
- add address=10.246.159.4 list="IP FABIO"
- add address=10.246.159.30 list="IP FABIO"
- add address=10.165.43.0/24 list="IP VPN"
- add address=10.246.159.29 list="IP FABIO"
- add address=10.247.159.5 list="IP FABIO"
- add address=10.246.159.0/24 list="SUBNET FABIO"
- add address=10.247.159.0/24 list="SUBNET FABIO"
- add address=10.250.159.0/24 list="SUBNET FABIO"
- add address=10.247.159.7 list="IP FABIO"
- add address=10.246.161.2 list="OUT VPN"
- add address=10.246.161.3 list="OUT VPN"
- add address=35.160.221.193 list=DAHUA
- add address=54.218.39.76 list=DAHUA
- add address=192.168.17.0/24 list="IP VPN"
- add address=10.246.162.0/24 list=BLACK-LIST
- add address=10.246.161.0/24 list=BLACK-LIST
- add address=172.17.20.0/24 list=BLACK-LIST
- add address=172.16.20.0/24 list=BLACK-LIST
- add address=192.168.17.0/24 list="IP FABIO"
- /ip firewall filter
- add action=fasttrack-connection chain=forward connection-state=\
- established,related
- add action=accept chain=forward comment="related, estabilished" \
- connection-state=established,related
- add action=drop chain=forward comment=invalid connection-state=invalid
- add action=drop chain=input dst-port=53 in-interface=pppoe-out1 protocol=udp
- add action=accept chain=forward comment="Accept IP FABIO vs NAS" dst-address=\
- 10.250.159.0/24 src-address-list="IP FABIO"
- add action=accept chain=forward comment="Accept IP FABIO vs NAS" dst-address=\
- 10.250.159.0/24 src-address-list="IP VPN"
- add action=drop chain=forward comment="drop vs NAS" dst-address=\
- 10.250.159.0/24
- add action=accept chain=forward comment="ACCETTA I PACCHETTI DA TUTTI GLI IP F\
- ABIO INSERITI IN ADDRESS LIST SRC LIST VERSO IL 10.247.159.2" \
- dst-address=10.247.159.2 src-address-list="IP FABIO"
- add action=drop chain=forward comment="RIFIUTA I PACCHETTI DA TUTTA LA SUBNET \
- MA VIENE ESEGUITA PRIMA L'ALTRA REGOLA CHE PERMETTO L'ACCESSO DALL'IP 10.2\
- 46.159.5" dst-address=10.247.159.2
- add action=drop chain=forward comment="drop DAHUA" disabled=yes \
- dst-address-list=DAHUA dst-port=443 protocol=tcp src-address=10.246.161.2
- add action=drop chain=forward comment="firewall vs.lan" disabled=yes \
- dst-address-list="SUBNET FABIO" src-address-list=BLACK-LIST
- /ip firewall nat
- add action=masquerade chain=srcnat comment=WAN out-interface=pppoe-out1
- add action=redirect chain=dstnat comment="DNS VERSO ROUTER" dst-port=53 \
- protocol=udp to-ports=53
- add action=masquerade chain=srcnat dst-address=192.168.178.0/24
- add action=masquerade chain=srcnat comment=VPN src-address=192.168.17.0/24
- add action=masquerade chain=srcnat comment="MASQUERADE DAHUA" out-interface=\
- "Vpn CHR" src-address-list="OUT VPN"
- add action=dst-nat chain=dstnat comment="PORT PORWARDING DAHUA" disabled=yes \
- dst-address=10.165.43.3 dst-port=37777 protocol=tcp to-addresses=\
- 10.246.161.2 to-ports=37777
- /ip route
- add distance=1 gateway=10.165.43.1 routing-mark=OUT
- add distance=1 dst-address=10.245.159.0/24 gateway=10.165.43.1
- add distance=1 dst-address=10.247.159.0/24 gateway=192.168.17.2
- add comment="Route subnet 10.247.159.XX e 10.248.159.xx da pubblico che appart\
- engono al map mikrotik" distance=2 dst-address=10.247.159.0/24 gateway=\
- 10.165.43.1
- add comment="ISP1 route dns" disabled=yes distance=1 dst-address=\
- 104.244.42.1/32 gateway=192.168.1.1
- add distance=1 dst-address=192.168.8.0/24 gateway=10.165.43.1
- /ip route rule
- add src-address=10.246.161.2/32 table=OUT
- /ppp secret
- add name=ford.focus password=ford@focus profile="profile1-vpn private" \
- remote-address=192.168.17.2
- add name=abbio90 password=xxxxxxxxx profile="profile1-vpn private"
- add name=elettrodom.fabio password=xxxxxxxx profile=vpn-bridge
- /snmp
- set enabled=yes
- /system clock
- set time-zone-autodetect=no time-zone-name=Europe/Rome
- /system identity
- set name="Router CASA"
- /system ntp client
- set enabled=yes primary-ntp=193.204.114.105 secondary-ntp=193.204.114.105
- /system routerboard settings
- set silent-boot=yes
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement