Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /ip address
- add address=10.100.0.1/24 interface=bridge network=10.100.0.0
- /ip pool
- add name=dhcppool ranges=10.100.0.2-10.100.0.254
- /ip dhcp-server network
- add address=10.100.0.0/24 dns-server=10.100.0.1 gateway=10.100.0.1 ntp-server=216.239.35.0,216.239.35.4,216.239.35.8,216.239.35.12
- /ip dhcp-server
- add address-pool=dhcppool disabled=no interface=bridge lease-time=23h59m59s name=dhcpserver
- /interface ethernet switch port
- set 0 default-vlan-id=100 vlan-mode=secure
- set 1 default-vlan-id=100 vlan-mode=secure
- set 2 default-vlan-id=100 vlan-mode=secure
- set 3 default-vlan-id=100 vlan-mode=secure
- set 4 default-vlan-id=100 vlan-mode=secure
- set 5 vlan-mode=secure
- /interface ethernet switch vlan
- add independent-learning=no ports=ether1,ether2,ether3,ether4,ether5,switch1-cpu switch=switch1 vlan-id=100
- add independent-learning=no ports=ether1,ether2,ether3,ether4,ether5,switch1-cpu switch=switch1 vlan-id=101
- add independent-learning=no ports=ether1,ether2,ether3,ether4,ether5,switch1-cpu switch=switch1 vlan-id=102
- /interface bridge port
- add bridge=bridge interface=VLAN100-TRUSTED
- add bridge=bridge interface=VLAN101-IOTINT
- add bridge=bridge interface=VLAN102-IOTEXT
- /interface bridge settings
- set use-ip-firewall=yes
- /interface vlan
- add interface=ether1 name=VLAN100-ether1 vlan-id=100
- add interface=ether2 name=VLAN100-ether2 vlan-id=100
- add interface=ether3 name=VLAN100-ether3 vlan-id=100
- add interface=ether4 name=VLAN100-ether4 vlan-id=100
- add interface=ether5 name=VLAN100-ether5 vlan-id=100
- add interface=ether1 name=VLAN101-ether1 vlan-id=101
- add interface=ether2 name=VLAN101-ether2 vlan-id=101
- add interface=ether3 name=VLAN101-ether3 vlan-id=101
- add interface=ether4 name=VLAN101-ether4 vlan-id=101
- add interface=ether5 name=VLAN101-ether5 vlan-id=101
- add interface=ether1 name=VLAN102-ether1 vlan-id=102
- add interface=ether2 name=VLAN102-ether2 vlan-id=102
- add interface=ether3 name=VLAN102-ether3 vlan-id=102
- add interface=ether4 name=VLAN102-ether4 vlan-id=102
- add interface=ether5 name=VLAN102-ether5 vlan-id=102
- /interface list
- add name=VLAN100-TRUSTED
- add name=VLAN101-IOTINT
- add name=VLAN102-IOTEXT
- /ip firewall filter
- add action=accept chain=input dst-address=10.100.0.1 dst-port=53 in-bridge-port-list=VLAN101-IOTINT protocol=udp
- add action=accept chain=input dst-address=10.100.0.1 in-bridge-port-list=VLAN101-IOTINT protocol=icmp
- add action=drop chain=input in-bridge-port-list=VLAN101-IOTINT
- add action=accept chain=forward dst-port=123 in-bridge-port-list=VLAN101-IOTINT out-interface=sfp1 protocol=udp
- add action=accept chain=forward connection-state=established,related in-bridge-port-list=VLAN101-IOTINT out-bridge-port-list=VLAN100-TRUSTED
- add action=drop chain=forward in-bridge-port-list=VLAN101-IOTINT
- add action=accept chain=input dst-address=10.100.0.1 dst-port=53 in-bridge-port-list=VLAN102-IOTEXT protocol=udp
- add action=accept chain=input dst-address=10.100.0.1 dst-port=53 in-bridge-port-list=VLAN102-IOTEXT protocol=tcp
- add action=accept chain=input dst-address=10.100.0.1 in-bridge-port-list=VLAN102-IOTEXT protocol=icmp
- add action=drop chain=input in-bridge-port-list=VLAN102-IOTEXT
- add action=accept chain=forward in-bridge-port-list=VLAN102-IOTEXT out-interface=sfp1
- add action=accept chain=forward connection-state=established,related in-bridge-port-list=VLAN102-IOTEXT out-bridge-port-list=VLAN100-TRUSTED
- add action=accept chain=forward dst-port=5353 in-bridge-port-list=VLAN102-IOTEXT out-bridge-port-list=VLAN100-TRUSTED protocol=udp
- add action=accept chain=forward in-bridge-port-list=VLAN102-IOTEXT out-bridge-port-list=VLAN100-TRUSTED protocol=tcp src-port=8008-8009
- add action=accept chain=forward dst-port=32400 in-bridge-port-list=VLAN102-IOTEXT out-bridge-port-list=VLAN100-TRUSTED protocol=tcp src-address-list=PlexApprovedDevices src-port=""
- add action=drop chain=forward in-bridge-port-list=VLAN102-IOTEXT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement