Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- set firewall all-ping enable
- set firewall broadcast-ping disable
- set firewall ipv6-receive-redirects disable
- set firewall ipv6-src-route disable
- set firewall ip-src-route disable
- set firewall log-martians enable
- set firewall name WAN_IN default-action drop
- set firewall name WAN_IN description 'WAN to internal'
- set firewall name WAN_IN rule 10 action accept
- set firewall name WAN_IN rule 10 description 'Allow established/related'
- set firewall name WAN_IN rule 10 state established enable
- set firewall name WAN_IN rule 10 state related enable
- set firewall name WAN_IN rule 20 action drop
- set firewall name WAN_IN rule 20 description 'Drop invalid state'
- set firewall name WAN_IN rule 20 state invalid enable
- set firewall name WAN_LOCAL default-action drop
- set firewall name WAN_LOCAL description 'WAN to router'
- set firewall name WAN_LOCAL rule 10 action accept
- set firewall name WAN_LOCAL rule 10 description 'Allow established/related'
- set firewall name WAN_LOCAL rule 10 state established enable
- set firewall name WAN_LOCAL rule 10 state related enable
- set firewall name WAN_LOCAL rule 20 action drop
- set firewall name WAN_LOCAL rule 20 description 'Drop invalid state'
- set firewall name WAN_LOCAL rule 20 state invalid enable
- set firewall receive-redirects disable
- set firewall send-redirects enable
- set firewall source-validation disable
- set firewall syn-cookies enable
- set interfaces ethernet eth0 description Internet
- set interfaces ethernet eth0 duplex auto
- set interfaces ethernet eth0 speed auto
- set interfaces ethernet eth1 address 192.168.3.1/24
- set interfaces ethernet eth1 description 'MGMNT'
- set interfaces ethernet eth1 duplex auto
- set interfaces ethernet eth1 speed auto
- set interfaces ethernet eth2 description Local
- set interfaces ethernet eth2 duplex auto
- set interfaces ethernet eth2 speed auto
- set interfaces ethernet eth3 description Local
- set interfaces ethernet eth3 duplex auto
- set interfaces ethernet eth3 speed auto
- set interfaces ethernet eth4 description Local
- set interfaces ethernet eth4 duplex auto
- set interfaces ethernet eth4 speed auto
- set interfaces loopback lo
- set interfaces switch switch0 description Local
- set interfaces switch switch0 mtu 1500
- set interfaces switch switch0 switch-port interface eth0 vlan pvid 1
- set interfaces switch switch0 switch-port interface eth0 vlan vid 845
- set interfaces switch switch0 switch-port interface eth2 vlan pvid 845
- set interfaces switch switch0 switch-port interface eth3 vlan pvid 100
- set interfaces switch switch0 switch-port interface eth4 vlan pvid 100
- set interfaces switch switch0 switch-port vlan-aware enable
- set interfaces switch switch0 vif 1 address dhcp
- set interfaces switch switch0 vif 1 description Internet
- set interfaces switch switch0 vif 1 firewall in name WAN_IN
- set interfaces switch switch0 vif 1 firewall local name WAN_LOCAL
- set interfaces switch switch0 vif 1 mtu 1500
- set interfaces switch switch0 vif 100 address 192.168.1.1/24
- set interfaces switch switch0 vif 100 description Local
- set interfaces switch switch0 vif 100 mtu 1500
- set interfaces switch switch0 vif 845 description IPTV
- set interfaces switch switch0 vif 845 mtu 1500
- set service dhcp-server disabled false
- set service dhcp-server hostfile-update disable
- set service dhcp-server shared-network-name LAN1 authoritative enable
- set service dhcp-server shared-network-name LAN1 subnet 192.168.3.0/24 default-router 192.168.3.1
- set service dhcp-server shared-network-name LAN1 subnet 192.168.3.0/24 dns-server 192.168.3.1
- set service dhcp-server shared-network-name LAN1 subnet 192.168.3.0/24 dns-server 8.8.8.8
- set service dhcp-server shared-network-name LAN1 subnet 192.168.3.0/24 lease 86400
- set service dhcp-server shared-network-name LAN1 subnet 192.168.3.0/24 start 192.168.3.38 stop 192.168.3.243
- set service dhcp-server shared-network-name LAN3 authoritative enable
- set service dhcp-server shared-network-name LAN3 subnet 192.168.1.0/24 default-router 192.168.1.1
- set service dhcp-server shared-network-name LAN3 subnet 192.168.1.0/24 dns-server 192.168.1.1
- set service dhcp-server shared-network-name LAN3 subnet 192.168.1.0/24 lease 86400
- set service dhcp-server shared-network-name LAN3 subnet 192.168.1.0/24 start 192.168.1.38 stop 192.168.1.243
- set service dhcp-server use-dnsmasq disable
- set service dns forwarding cache-size 150
- set service dns forwarding listen-on eth1
- set service dns forwarding listen-on switch0.100
- set service gui http-port 80
- set service gui https-port 443
- set service gui older-ciphers enable
- set service nat rule 5010 description 'masquerade for WAN'
- set service nat rule 5010 log disable
- set service nat rule 5010 outbound-interface switch0.1
- set service nat rule 5010 protocol all
- set service nat rule 5010 type masquerade
- set service ssh port 22
- set service ssh protocol-version v2
- set system offload hwnat enable
- set system ntp server 0.ubnt.pool.ntp.org
- set system ntp server 1.ubnt.pool.ntp.org
- set system ntp server 2.ubnt.pool.ntp.org
- set system ntp server 3.ubnt.pool.ntp.org
- set system syslog global facility all level notice
- set system syslog global facility protocols level debug
- set system time-zone UTC
Advertisement
Add Comment
Please, Sign In to add comment