Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # aug/23/2018 09:42:50 by RouterOS 6.39.2
- # software id = ***********-DQS3
- #
- /caps-man channel
- add band=2ghz-b/g/n control-channel-width=20mhz frequency=2412 name=channel1 \
- tx-power=20
- add band=2ghz-b/g/n control-channel-width=20mhz frequency=2437 name=channel6 \
- tx-power=20
- add band=2ghz-b/g/n control-channel-width=20mhz frequency=2462 name=channel11 \
- tx-power=20
- add band=2ghz-b/g/n control-channel-width=20mhz frequency=2417 name=channel2 \
- tx-power=20
- add band=2ghz-b/g/n control-channel-width=20mhz frequency=2432 name=channel5 \
- tx-power=20
- /interface bridge
- add name=BridgeStage2
- add name=BridgeStage3
- add name=BridgeStage4
- /interface ethernet
- set [ find default-name=ether1 ] comment=Local loop-protect=on speed=1Gbps
- set [ find default-name=ether2 ] disabled=yes
- set [ find default-name=ether3 ] disabled=yes
- set [ find default-name=ether4 ] disabled=yes
- set [ find default-name=ether5 ] disabled=yes
- set [ find default-name=ether6 ] comment=\
- "ISP 1 Primary Rostelekom *********** "
- set [ find default-name=ether7 ] disabled=yes
- set [ find default-name=ether8 ] comment="ISP2 Reserve Dom.ru " loop-protect=\
- on
- set [ find default-name=ether9 ] disabled=yes
- set [ find default-name=ether10 ] disabled=yes
- set [ find default-name=sfp1 ] disabled=yes loop-protect=on
- /interface pppoe-client
- add comment="ISP 2 DOM.RU" disabled=no interface=ether8 name=pppoe-out1 \
- password=*********** use-peer-dns=yes ***********
- /ip neighbor discovery
- set ether1 discover=no
- set ether3 discover=no
- set ether4 discover=no
- set ether5 discover=no
- set ether6 discover=no
- set ether7 discover=no
- set ether8 discover=no
- set ether9 discover=no
- set ether10 discover=no
- set sfp1 discover=no
- set BridgeStage2 discover=no
- set BridgeStage3 discover=no
- set BridgeStage4 discover=no
- set pppoe-out1 discover=no
- /interface vlan
- add comment="Network device management " interface=ether1 loop-protect=on \
- name=ManagementVlan2 vlan-id=2
- add comment="Network of Servers" interface=ether1 loop-protect=on name=\
- "Network of ServersVlan3" vlan-id=3
- add comment=Stage1 interface=ether1 loop-protect=on name=Stage1Vlan10 \
- vlan-id=10
- add comment=Stage2 interface=ether1 loop-protect=on name=Stage2Vlan20 \
- vlan-id=20
- add comment=Stage3 interface=ether1 loop-protect=on name=Stage3Vlan30 \
- vlan-id=30
- add comment=Stage4 interface=ether1 loop-protect=on name=Stage4Vlan40 \
- vlan-id=40
- add comment=Personal interface=ether1 loop-protect=on name=Teh.PersonalVlan9 \
- vlan-id=9
- add comment=UnlimitedSpeed interface=ether1 loop-protect=on name=\
- UnlimitedSpeedVlan7 vlan-id=7
- add comment="Video network" interface=ether1 loop-protect=on name=VideoVlan4 \
- vlan-id=4
- /caps-man datapath
- add bridge=BridgeStage4 comment="Config Stage4" local-forwarding=no name=\
- datapath2Stage4 vlan-id=40
- add bridge=BridgeStage3 comment="Config Stage3" local-forwarding=no name=\
- datapath3Stage3 vlan-id=30
- add bridge=BridgeStage2 comment="Config Stage2" local-forwarding=no name=\
- datapath4Stage2 vlan-id=20
- /ip neighbor discovery
- set Stage1Vlan10 discover=no
- set Stage2Vlan20 discover=no
- set Stage3Vlan30 discover=no
- set Stage4Vlan40 discover=no
- set UnlimitedSpeedVlan7 discover=no
- set VideoVlan4 discover=no
- /caps-man security
- add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm \
- name=security1 passphrase=***********2016
- /caps-man configuration
- add channel=channel1 datapath=datapath4Stage2 mode=ap name=cfg1_Stage2 \
- rx-chains=0,1,2 security=security1 ssid=*********** tx-chains=0,1,2
- add channel=channel6 datapath=datapath4Stage2 mode=ap name=cfg6_Stage2 \
- rx-chains=0,1,2 security=security1 ssid=*********** tx-chains=0,1,2
- add channel=channel11 datapath=datapath4Stage2 mode=ap name=cfg11_Stage2 \
- rx-chains=0,1,2 security=security1 ssid=*********** tx-chains=0,1,2
- add channel=channel1 datapath=datapath3Stage3 mode=ap name=cfg1Stage3 \
- rx-chains=0,1,2 security=security1 ssid=*********** tx-chains=0,1,2
- add channel=channel6 datapath=datapath3Stage3 mode=ap name=cfg6Stage3 \
- rx-chains=0,1,2 security=security1 ssid=*********** tx-chains=0,1,2
- add channel=channel11 datapath=datapath3Stage3 mode=ap name=cfg11Stage3 \
- rx-chains=0,1,2 security=security1 ssid=*********** tx-chains=0,1,2
- add channel=channel2 datapath=datapath3Stage3 mode=ap name=cfg2Stage3 \
- rx-chains=0,1,2 security=security1 ssid=*********** tx-chains=0,1,2
- add channel=channel5 datapath=datapath2Stage4 mode=ap name=cfg5Stage4 \
- rx-chains=0,1,2 security=security1 ssid=*********** tx-chains=0,1,2
- add channel=channel1 datapath=datapath2Stage4 mode=ap name=cfg1Stage4 \
- rx-chains=0,1,2 security=security1 ssid=*********** tx-chains=0,1,2
- add channel=channel11 datapath=datapath2Stage4 mode=ap name=cfg11_Stage4 \
- rx-chains=0,1,2 security=security1 ssid=*********** tx-chains=0,1,2
- add channel=channel1 datapath=datapath4Stage2 mode=ap name=cfg1Stage0 \
- rx-chains=0,1,2 security=security1 ssid=*********** tx-chains=0,1,2
- add channel=channel1 datapath=datapath4Stage2 mode=ap name=\
- cfg1Stage2DublinBar rx-chains=0,1,2 security=security1 ssid=*********** \
- tx-chains=0,1,2
- add channel=channel11 datapath=datapath4Stage2 mode=ap name=\
- "cfg11Stage0Sauna\B93" rx-chains=0,1,2 security=security1 ssid=*********** \
- tx-chains=0,1,2
- add channel=channel6 datapath=datapath4Stage2 mode=ap name=cfg6Stage1 \
- rx-chains=0,1,2 security=security1 ssid=*********** tx-chains=0,1,2
- /caps-man interface
- add comment="Stage 0_Prachka" configuration=cfg1Stage0 disabled=no l2mtu=1600 \
- mac-address=64:D1:54:F3:E6:FE master-interface=none name=\
- MikroTik_Stage0_Prachka radio-mac=64:D1:54:F3:E6:FE
- add comment="Stage 0_Sauna \B91" configuration=cfg1Stage0 disabled=no l2mtu=\
- 1600 mac-address=CC:2D:E0:01:15:25 master-interface=none name=\
- "MikroTik_Stage0_Sauna\B91" radio-mac=CC:2D:E0:01:15:25
- add comment="Stage 0_Sauna \B93" configuration="cfg11Stage0Sauna\B93" \
- disabled=no l2mtu=1600 mac-address=CC:2D:E0:02:51:74 master-interface=\
- none name="MikroTik_Stage0_Sauna\B93" radio-mac=CC:2D:E0:02:51:74
- add comment="Restoraunt London" configuration=cfg6Stage1 disabled=no l2mtu=\
- 1600 mac-address=CC:2D:E0:BE:73:6F master-interface=none name=\
- MikroTik_Stage1_London radio-mac=CC:2D:E0:BE:73:6F
- add comment="Restoraunt DublinBar" configuration=cfg1_Stage2 disabled=no \
- l2mtu=1600 mac-address=CC:2D:E0:12:2C:33 master-interface=none name=\
- MikroTik_Stage2_Dublin_Bar radio-mac=CC:2D:E0:12:2C:33
- add comment="Stage 2" configuration=cfg11_Stage2 disabled=no l2mtu=1600 \
- mac-address=64:D1:54:26:FA:47 master-interface=none name=\
- "MikroTik_Stage2\B9205" radio-mac=64:D1:54:26:FA:47
- add configuration=cfg1_Stage2 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:14:4B:83 master-interface=none name="MikroTik_Stage2\B9209" \
- radio-mac=64:D1:54:14:4B:83
- add configuration=cfg6_Stage2 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:25:29:DD master-interface=none name="MikroTik_Stage2\B9215" \
- radio-mac=64:D1:54:25:29:DD
- add comment="Stage 3" configuration=cfg6Stage3 disabled=no l2mtu=1600 \
- mac-address=64:D1:54:25:29:8F master-interface=none name=\
- "MikroTik_Stage3\B9305" radio-mac=64:D1:54:25:29:8F
- add configuration=cfg11Stage3 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:44:C0:CF master-interface=none name="MikroTik_Stage3\B9309" \
- radio-mac=64:D1:54:44:C0:CF
- add configuration=cfg1Stage3 disabled=no l2mtu=1600 mac-address=\
- CC:2D:E0:0A:6A:EC master-interface=none name="MikroTik_Stage3\B9312" \
- radio-mac=CC:2D:E0:0A:6A:EC
- add configuration=cfg2Stage3 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:44:C0:AB master-interface=none name="MikroTik_Stage3\B9315" \
- radio-mac=64:D1:54:44:C0:AB
- add comment="Stage 4" configuration=cfg5Stage4 disabled=no l2mtu=1600 \
- mac-address=64:D1:54:46:D1:0B master-interface=none name=\
- "MikroTik_Stage4\B9405" radio-mac=64:D1:54:46:D1:0B
- add configuration=cfg1Stage4 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:49:BF:83 master-interface=none name="MikroTik_Stage4\B9409" \
- radio-mac=64:D1:54:49:BF:83
- add configuration=cfg11_Stage4 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:EC:19:FF master-interface=none name="MikroTik_Stage4\B9415" \
- radio-mac=64:D1:54:EC:19:FF
- /ip neighbor discovery
- set MikroTik_Stage0_Prachka discover=no
- set "MikroTik_Stage0_Sauna\B91" discover=no
- set "MikroTik_Stage0_Sauna\B93" discover=no
- set MikroTik_Stage1_London discover=no
- set MikroTik_Stage2_Dublin_Bar discover=no
- set "MikroTik_Stage2\B9205" discover=no
- set "MikroTik_Stage2\B9209" discover=no
- set "MikroTik_Stage2\B9215" discover=no
- set "MikroTik_Stage3\B9305" discover=no
- set "MikroTik_Stage3\B9309" discover=no
- set "MikroTik_Stage3\B9312" discover=no
- set "MikroTik_Stage3\B9315" discover=no
- set "MikroTik_Stage4\B9405" discover=no
- set "MikroTik_Stage4\B9409" discover=no
- set "MikroTik_Stage4\B9415" discover=no
- /interface wireless security-profiles
- set [ find default=yes ] supplicant-identity=MikroTik
- /ip firewall layer7-protocol
- add name="Social Network" regexp="\"^.+(vk.com|vkontakte|odnoklassniki|odnokla\
- sniki|fall-in-\\\r\
- \nlove|loveplanet|my.mail.ru).*\\\$\""
- /ip hotspot profile
- add hotspot-address=172.16.5.1 login-by=http-chap,trial name=*********** \
- trial-uptime-limit=0s trial-uptime-reset=1m
- /ip hotspot
- add disabled=no interface=ether2 name=hotspot1 profile=***********
- /ip hotspot user profile
- set [ find default=yes ] keepalive-timeout=2h shared-users=unlimited \
- status-autorefresh=1d
- /ip ipsec proposal
- set [ find default=yes ] enc-algorithms=aes-128-cbc,3des pfs-group=none
- /ip pool
- add name=PoolVlan2 ranges=172.16.1.30-172.16.1.254
- add name=PoolVlan3 ranges=172.16.3.30-172.16.3.254
- add name=PoolVlan10 ranges=172.16.10.30-172.16.10.254
- add name=PoolVlan20 ranges=172.16.20.30-172.16.20.254
- add name=PoolVlan30 ranges=172.16.30.30-172.16.30.254
- add name=PoolVlan40 ranges=172.16.40.30-172.16.40.254
- add name=PoolVlan9 ranges=172.16.9.30-172.16.9.254
- add name=PoolVlan7 ranges=172.16.7.30-172.16.7.254
- add name=PoolVlan4 ranges=172.16.4.30-172.16.4.254
- add name=dhcp_pool10 ranges=172.16.5.30-172.16.5.254
- /ip dhcp-server
- add address-pool=PoolVlan2 disabled=no interface=ManagementVlan2 lease-time=\
- 1d name=ServerdhcpVlan2
- add address-pool=PoolVlan3 disabled=no interface="Network of ServersVlan3" \
- lease-time=1d name=ServerdhcpVlan3
- add address-pool=PoolVlan10 disabled=no interface=Stage1Vlan10 lease-time=1d \
- name=ServerdhcpVlan10
- add address-pool=PoolVlan20 disabled=no interface=BridgeStage2 lease-time=1d \
- name=ServerdhcpVlan20
- add address-pool=PoolVlan30 disabled=no interface=BridgeStage3 lease-time=1d \
- name=ServerdhcpVlan30
- add address-pool=PoolVlan40 disabled=no interface=BridgeStage4 lease-time=1d \
- name=ServerdhcpVlan40
- add address-pool=PoolVlan9 disabled=no interface=Teh.PersonalVlan9 \
- lease-time=1d name=ServerdhcpVlan9
- add address-pool=PoolVlan7 disabled=no interface=UnlimitedSpeedVlan7 \
- lease-time=1d name=ServerdhcpVlan7
- add address-pool=PoolVlan4 disabled=no interface=VideoVlan4 lease-time=1d \
- name=ServerdhcpVlan4
- /queue simple
- add max-limit=3M/3M name=CompEkaterina target=172.16.9.38/32
- add max-limit=3M/3M name=CompDizainer target=172.16.9.34/32
- add max-limit=5M/5M name=FItnessReseption target=172.16.9.33/32
- /queue tree
- add disabled=yes max-limit=25M name=in parent=global
- add disabled=yes max-limit=25M name=out parent=global
- add disabled=yes max-limit=1M name=Web_in packet-mark=WEB_in parent=in \
- priority=5
- add disabled=yes max-limit=1M name=WEB_out packet-mark=WEB_out parent=out \
- priority=5
- /queue type
- add kind=pcq name=" pcq-download-7M" pcq-classifier=dst-address \
- pcq-dst-address6-mask=64 pcq-rate=7M pcq-src-address6-mask=64
- add kind=pcq name=pcq-upload-7M pcq-classifier=src-address \
- pcq-dst-address6-mask=64 pcq-rate=7M pcq-src-address6-mask=64
- add kind=pcq name=SIP pcq-classifier=\
- src-address,dst-address,src-port,dst-port pcq-dst-address6-mask=64 \
- pcq-rate=100k pcq-src-address6-mask=64
- /queue simple
- add comment="Limit speed 7M/bit Stage 1" max-limit=50M/50M name=\
- Stage1_queue-limit-7M_Vlan10 queue="pcq-upload-7M/ pcq-download-7M" \
- target=Stage1Vlan10
- add comment="Limit speed 7 M/bit Stage 2" max-limit=50M/50M name=\
- Stage2_queue-limit-7M_Vlan20 queue="pcq-upload-7M/ pcq-download-7M" \
- target=BridgeStage2
- add comment="Limit speed 7 M/bit Stage 3" max-limit=50M/50M name=\
- Stage3_queue-limit-7M_Vlan30 queue="pcq-upload-7M/ pcq-download-7M" \
- target=BridgeStage3
- add comment="Limit speed 7 M/bit Stage 4" max-limit=50M/50M name=\
- Stage4_queue-limit-7M_Vlan40 queue="pcq-upload-7M/ pcq-download-7M" \
- target=BridgeStage4
- /queue tree
- add disabled=yes max-limit=10M name=VPN_in packet-mark=PPTP_in,GRE_in parent=\
- in priority=3 queue=pcq-download-default
- add disabled=yes max-limit=10M name=VPN_out packet-mark=PPTP_out,GRE_out \
- parent=out priority=3 queue=pcq-upload-default
- add disabled=yes max-limit=2M name=SIP_in packet-mark=SIP_in parent=in \
- priority=1 queue=SIP
- add disabled=yes max-limit=2M name=SIP_out packet-mark=SIP_OUT parent=out \
- priority=1 queue=SIP
- add disabled=yes max-limit=2M name=VPN_SIP_in packet-mark=SIP_VPN_in parent=\
- VPN_in priority=1 queue=SIP
- add disabled=yes max-limit=2M name=VPN_SIP_out packet-mark=SIP_VPN_OUT \
- parent=VPN_out priority=1 queue=SIP
- add disabled=yes max-limit=10M name=VPN_WEB_in packet-mark=VPN_WEB_in parent=\
- VPN_in priority=5 queue=pcq-download-default
- add disabled=yes max-limit=10M name=VPN_WEB_out packet-mark=VPN_WEB_out \
- parent=VPN_out priority=5 queue=pcq-download-default
- /caps-man manager
- set enabled=yes
- /caps-man provisioning
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg6_Stage2 radio-mac=64:D1:54:14:4B:7E
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg11_Stage2 radio-mac=64:D1:54:25:29:D8
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg11Stage3 radio-mac=64:D1:54:25:29:8A
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg6Stage3 radio-mac=64:D1:54:44:C0:A6
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg2Stage3 radio-mac=64:D1:54:44:C0:CA
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg5Stage4 radio-mac=64:D1:54:49:BF:7E
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1Stage4 radio-mac=64:D1:54:46:D1:06
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg11_Stage4 radio-mac=64:D1:54:EC:19:FA
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg11_Stage2 radio-mac=64:D1:54:26:FA:42
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1Stage0 radio-mac=64:D1:54:F3:E6:F9
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1Stage2DublinBar radio-mac=CC:2D:E0:12:2C:2E
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1Stage0 radio-mac=CC:2D:E0:01:15:20
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- "cfg11Stage0Sauna\B93" radio-mac=CC:2D:E0:02:51:6F
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1_Stage2 radio-mac=CC:2D:E0:BE:73:6A
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1Stage3 radio-mac=CC:2D:E0:0A:6A:EC
- /interface bridge port
- add bridge=BridgeStage4 interface=Stage4Vlan40
- add bridge=BridgeStage3 interface=Stage3Vlan30
- add bridge=BridgeStage2 interface=Stage2Vlan20
- /interface pptp-server server
- set enabled=yes
- /ip address
- add address=172.16.1.1/24 comment="Network device management " interface=\
- ManagementVlan2 network=172.16.1.0
- add address=172.16.3.1/24 comment="Servers network" interface=\
- "Network of ServersVlan3" network=172.16.3.0
- add address=172.16.4.1/24 comment="Network video" interface=VideoVlan4 \
- network=172.16.4.0
- add address=172.16.7.1/24 comment="Unlimited speed" interface=\
- UnlimitedSpeedVlan7 network=172.16.7.0
- add address=172.16.9.1/24 comment=Personal interface=Teh.PersonalVlan9 \
- network=172.16.9.0
- add address=172.16.10.1/24 comment="Stage 1" interface=Stage1Vlan10 network=\
- 172.16.10.0
- add address=172.16.20.1/24 comment="Stage 2" interface=BridgeStage2 network=\
- 172.16.20.0
- add address=172.16.30.1/24 comment="Stage 3" interface=BridgeStage3 network=\
- 172.16.30.0
- add address=172.16.40.1/24 comment="Stage 4" interface=BridgeStage4 network=\
- 172.16.40.0
- add address=***********/24 comment="ISP 1 Rostelekom *********** " \
- interface=ether6 network=85.172.120.0
- /ip dhcp-client
- add dhcp-options=hostname,clientid disabled=no interface=ether6
- /ip dhcp-server alert
- add disabled=no interface=ManagementVlan2
- /ip dhcp-server lease
- add address=172.16.9.33 always-broadcast=yes client-id=1:0:25:ab:1a:6:6c \
- mac-address=00:25:AB:1A:06:6C server=ServerdhcpVlan9
- add address=172.16.10.161 always-broadcast=yes client-id=1:0:6d:52:15:13:a3 \
- mac-address=00:6D:52:15:13:A3 server=ServerdhcpVlan10
- add address=172.16.9.51 always-broadcast=yes client-id=1:0:1b:67:15:8f:bd \
- mac-address=00:1B:67:15:8F:BD server=ServerdhcpVlan9
- add address=172.16.20.135 client-id=1:0:6d:52:15:13:a3 mac-address=\
- 00:6D:52:15:13:A3 server=ServerdhcpVlan20
- add address=172.16.9.50 client-id=1:90:2b:34:cf:94:af mac-address=\
- 90:2B:34:CF:94:AF server=ServerdhcpVlan9
- /ip dhcp-server network
- add address=172.16.1.0/24 dns-server=172.16.1.1,8.8.8.8 gateway=172.16.1.1
- add address=172.16.3.0/24 dns-server=172.16.3.1,8.8.8.8 gateway=172.16.3.1
- add address=172.16.4.0/24 dns-server=172.16.4.1,8.8.8.8 gateway=172.16.4.1
- add address=172.16.5.0/24 dns-server=172.16.5.1 gateway=172.16.5.1
- add address=172.16.6.0/24 dns-server=172.16.6.1,8.8.8.8 gateway=172.16.6.1
- add address=172.16.7.0/24 dns-server=172.16.7.1,8.8.8.8 gateway=172.16.7.1
- add address=172.16.9.0/24 dns-server=172.16.9.1,8.8.8.8 gateway=172.16.9.1
- add address=172.16.10.0/24 dns-server=172.16.10.1,8.8.8.8 gateway=172.16.10.1
- add address=172.16.20.0/24 dns-server=172.16.20.1,8.8.8.8 gateway=172.16.20.1
- add address=172.16.30.0/24 dns-server=172.16.30.1,8.8.8.8 gateway=172.16.30.1
- add address=172.16.40.0/24 dns-server=172.16.40.1,8.8.8.8 gateway=172.16.40.1
- /ip dns
- set allow-remote-requests=yes servers=172.16.5.1,8.8.8.8
- /ip firewall filter
- add action=passthrough chain=unused-hs-chain comment=\
- "place hotspot rules here" disabled=yes
- add action=drop chain=input comment="DNS ROSTELEKOM" dst-port=53 \
- in-interface=ether6 protocol=udp
- add action=drop chain=input comment="DNS DOM.RU" dst-port=53 in-interface=\
- pppoe-out1 protocol=udp
- add action=drop chain=output comment="GOOGLE PING DENY 8.8.4.4" dst-address=\
- 8.8.4.4 out-interface=pppoe-out1
- add action=accept chain=input comment=Estabilished/Related connection-state=\
- established,related
- add action=accept chain=forward connection-state=established,related
- add action=drop chain=forward comment=Invalid connection-state=invalid
- add action=drop chain=input connection-state=invalid in-interface=ether6
- add action=accept chain=forward comment=IpSec dst-port=500 protocol=udp
- add action=accept chain=forward dst-port=4500 protocol=udp
- add action=accept chain=input comment="Allow IPSec-esp" protocol=ipsec-esp
- add action=accept chain=input comment="Allow IPSec-ah" protocol=ipsec-ah
- add action=accept chain=input comment=WinBox dst-port=8291 in-interface=\
- ether6 protocol=tcp
- add action=accept chain=input comment="Allow ping" protocol=icmp
- add action=accept chain=forward comment=Video dst-port=34567 protocol=tcp
- add action=accept chain=forward dst-port=90 protocol=tcp
- add action=accept chain=forward comment="IIS Server" dst-port=80 protocol=tcp
- add action=accept chain=input comment=Iwinbox dst-port=8728 in-interface=\
- ether6 protocol=tcp
- add action=accept chain=input comment="Allow UDP" protocol=udp
- /ip firewall mangle
- add action=mark-connection chain=input comment=PPTP disabled=yes dst-port=\
- 1723 new-connection-mark=PPTP_in passthrough=no protocol=tcp
- add action=mark-packet chain=prerouting connection-mark=PPTP_in disabled=yes \
- new-packet-mark=PPTP_out passthrough=no
- add action=mark-connection chain=output disabled=yes new-connection-mark=\
- PPTP_out passthrough=no protocol=tcp src-port=1723
- add action=mark-packet chain=postrouting connection-mark=PPTP_out disabled=\
- yes new-packet-mark=PPTP_in passthrough=no
- add action=mark-connection chain=input comment=GRE disabled=yes \
- new-connection-mark=GRE_in passthrough=no protocol=gre
- add action=mark-packet chain=prerouting connection-mark=GRE_in disabled=yes \
- new-packet-mark=GRE_out passthrough=no
- add action=mark-connection chain=output disabled=yes new-connection-mark=\
- GRE_out passthrough=no protocol=gre
- add action=mark-packet chain=postrouting connection-mark=GRE_out disabled=yes \
- new-packet-mark=GRE_in passthrough=no
- add action=mark-connection chain=prerouting comment=WEB disabled=yes \
- dst-port=80,443,8080 new-connection-mark=Web passthrough=no protocol=tcp
- add action=mark-packet chain=forward connection-mark=Web disabled=yes \
- new-packet-mark=VPN_WEB_in out-interface=all-ppp passthrough=no
- add action=mark-packet chain=forward connection-mark=Web disabled=yes \
- in-interface=all-ppp new-packet-mark=VPN_WEB_out passthrough=no
- add action=mark-packet chain=forward connection-mark=Web disabled=yes \
- in-interface=ether6 new-packet-mark=WEB_in passthrough=no
- add action=mark-packet chain=forward connection-mark=Web disabled=yes \
- new-packet-mark=WEB_out out-interface=ether6 passthrough=no
- add action=mark-packet chain=forward comment=ALL disabled=yes \
- new-packet-mark=VPN_ALL_in out-interface=all-ppp passthrough=no
- add action=mark-packet chain=forward disabled=yes in-interface=all-ppp \
- new-packet-mark=VPN_ALL_out passthrough=no
- add action=mark-packet chain=forward disabled=yes in-interface=ether6 \
- new-packet-mark=ALL_in passthrough=yes
- add action=mark-packet chain=forward disabled=yes new-packet-mark=ALL_out \
- out-interface=ether6 passthrough=yes
- add action=mark-connection chain=prerouting comment=SIP disabled=yes \
- dst-port=5060,36600-39999 new-connection-mark=sip passthrough=no \
- protocol=udp
- add action=mark-packet chain=forward connection-mark=sip disabled=yes \
- new-packet-mark=SIP_VPN_in out-interface=all-ppp passthrough=no
- add action=mark-packet chain=forward connection-mark=sip disabled=yes \
- in-interface=all-ppp new-packet-mark=SIP_VPN_OUT passthrough=no
- add action=mark-packet chain=forward connection-mark=sip disabled=yes \
- in-interface=ether6 new-packet-mark=SIP_in passthrough=no
- add action=mark-packet chain=forward connection-mark=sip disabled=yes \
- new-packet-mark=SIP_OUT out-interface=ether6 passthrough=no
- /ip firewall nat
- add action=passthrough chain=unused-hs-chain comment=\
- "place hotspot rules here" disabled=yes
- add action=dst-nat chain=dstnat comment=ZABBIX dst-port=2255 in-interface=\
- ether6 protocol=tcp to-addresses=172.16.3.9 to-ports=80
- add action=dst-nat chain=dstnat comment="ZABBIX SSH" dst-port=2222 \
- in-interface=ether6 protocol=tcp to-addresses=172.16.3.9 to-ports=22
- add action=dst-nat chain=dstnat comment="Debian backup SSH" dst-port=2233 \
- in-interface=ether6 protocol=tcp to-addresses=172.16.3.8 to-ports=22
- add action=accept chain=srcnat comment=Adler disabled=yes dst-address=\
- 172.18.1.0/24 src-address=172.16.1.0/24
- add action=accept chain=srcnat comment=Moscow dst-address=100.65.224.0/24 \
- src-address=172.16.3.0/24
- add action=accept chain=srcnat comment=EREVAN dst-address=192.168.1.0/24 \
- src-address=172.16.1.0/24
- add action=accept chain=srcnat dst-address=192.168.1.0/24 src-address=\
- 172.16.3.0/24
- add action=accept chain=srcnat comment="BASE VOLGOGRAD" dst-address=\
- 10.8.0.0/24 src-address=172.16.3.0/24
- add action=dst-nat chain=dstnat comment="Terminal Server" dst-address-list="" \
- dst-port=6988 protocol=tcp to-addresses=172.16.3.16 to-ports=3389
- add action=dst-nat chain=dstnat comment="Apache Server" dst-port=80 \
- in-interface=ether6 protocol=tcp to-addresses=172.16.3.6 to-ports=80
- add action=dst-nat chain=dstnat comment="Video nat" dst-port=88 in-interface=\
- ether6 protocol=tcp to-addresses=172.16.4.2 to-ports=34567
- add action=dst-nat chain=dstnat dst-port=95 in-interface=ether6 protocol=tcp \
- to-addresses=172.16.4.6 to-ports=34567
- add action=dst-nat chain=dstnat dst-port=96 in-interface=ether6 protocol=tcp \
- to-addresses=172.16.4.8 to-ports=34567
- add action=dst-nat chain=dstnat dst-port=90 in-interface=ether6 protocol=tcp \
- to-addresses=172.16.4.3 to-ports=90
- add action=masquerade chain=srcnat comment="Nat rostelekom" out-interface=\
- ether6
- add action=masquerade chain=srcnat comment="Nat Dom.ru" out-interface=\
- pppoe-out1
- add action=masquerade chain=srcnat comment="masquerade hotspot network" \
- src-address=172.16.5.0/24
- /ip hotspot user
- add name=admin
- /ip ipsec peer
- add address=213.234.25.92/32 dh-group=modp1536 exchange-mode=main-l2tp \
- generate-policy=port-override passive=yes secret=***********
- add address=93.94.221.180/32 dh-group=modp1536 exchange-mode=main-l2tp \
- generate-policy=port-override passive=yes secret=***********
- add address=194.114.128.135/32 dh-group=modp1536 disabled=yes secret=\
- ***********
- add address=178.236.241.126/32 dh-group=modp1536 disabled=yes secret=\
- ***********
- /ip ipsec policy
- add disabled=yes dst-address=100.65.224.0/24 sa-dst-address=178.236.241.126 \
- sa-src-address=*********** src-address=172.16.3.0/24 tunnel=yes
- add dst-address=10.8.0.0/24 sa-dst-address=213.234.25.92 sa-src-address=\
- *********** src-address=172.16.3.0/24 tunnel=yes
- /ip route
- add comment=ISP1 distance=3 gateway=85.172.120.101
- add comment=ISP2 disabled=yes distance=2 gateway=pppoe-out1
- add comment=GOOGLE distance=1 dst-address=8.8.4.4/32 gateway=85.172.120.101
- /ip route rule
- add action=unreachable dst-address=172.16.30.0/24 src-address=172.16.40.0/24
- add action=unreachable dst-address=172.16.20.0/24 src-address=172.16.40.0/24
- add action=unreachable dst-address=172.16.10.0/24 src-address=172.16.40.0/24
- add action=unreachable dst-address=172.16.9.0/24 src-address=172.16.40.0/24
- add action=unreachable dst-address=172.16.7.0/24 src-address=172.16.40.0/24
- add action=unreachable dst-address=172.16.5.0/24 src-address=172.16.40.0/24
- add action=unreachable dst-address=172.16.4.0/24 src-address=172.16.40.0/24
- add action=unreachable dst-address=172.16.3.0/24 src-address=172.16.40.0/24
- add action=unreachable dst-address=172.16.2.0/24 src-address=172.16.40.0/24
- add action=unreachable dst-address=172.16.1.0/24 src-address=172.16.40.0/24
- add action=unreachable dst-address=172.16.40.0/24 src-address=172.16.30.0/24
- add action=unreachable dst-address=172.16.20.0/24 src-address=172.16.30.0/24
- add action=unreachable dst-address=172.16.10.0/24 src-address=172.16.30.0/24
- add action=unreachable dst-address=172.16.9.0/24 src-address=172.16.30.0/24
- add action=unreachable dst-address=172.16.7.0/24 src-address=172.16.30.0/24
- add action=unreachable dst-address=172.16.5.0/24 src-address=172.16.30.0/24
- add action=unreachable dst-address=172.16.4.0/24 src-address=172.16.30.0/24
- add action=unreachable dst-address=172.16.3.0/24 src-address=172.16.30.0/24
- add action=unreachable dst-address=172.16.2.0/24 src-address=172.16.30.0/24
- add action=unreachable dst-address=172.16.1.0/24 src-address=172.16.30.0/24
- add action=unreachable dst-address=172.16.40.0/24 src-address=172.16.20.0/24
- add action=unreachable dst-address=172.16.30.0/24 src-address=172.16.20.0/24
- add action=unreachable dst-address=172.16.10.0/24 src-address=172.16.20.0/24
- add action=unreachable dst-address=172.16.9.0/24 src-address=172.16.20.0/24
- add action=unreachable dst-address=172.16.7.0/24 src-address=172.16.20.0/24
- add action=unreachable dst-address=172.16.5.0/24 src-address=172.16.20.0/24
- add action=unreachable dst-address=172.16.4.0/24 src-address=172.16.20.0/24
- add action=unreachable dst-address=172.16.3.0/24 src-address=172.16.20.0/24
- add action=unreachable dst-address=172.16.2.0/24 src-address=172.16.20.0/24
- add action=unreachable dst-address=172.16.1.0/24 src-address=172.16.20.0/24
- add action=unreachable dst-address=172.16.40.0/24 src-address=172.16.10.0/24
- add action=unreachable dst-address=172.16.30.0/24 src-address=172.16.10.0/24
- add action=unreachable dst-address=172.16.20.0/24 src-address=172.16.10.0/24
- add action=unreachable dst-address=172.16.9.0/24 src-address=172.16.10.0/24
- add action=unreachable dst-address=172.16.7.0/24 src-address=172.16.10.0/24
- add action=unreachable dst-address=172.16.5.0/24 src-address=172.16.10.0/24
- add action=unreachable dst-address=172.16.4.0/24 src-address=172.16.10.0/24
- add action=unreachable dst-address=172.16.3.0/24 src-address=172.16.10.0/24
- add action=unreachable dst-address=172.16.2.0/24 src-address=172.16.10.0/24
- add action=unreachable dst-address=172.16.1.0/24 src-address=172.16.10.0/24
- add action=unreachable dst-address=172.16.40.0/24 src-address=172.16.9.0/24
- add action=unreachable dst-address=172.16.30.0/24 src-address=172.16.9.0/24
- add action=unreachable dst-address=172.16.20.0/24 src-address=172.16.9.0/24
- add action=unreachable dst-address=172.16.10.0/24 src-address=172.16.9.0/24
- add action=unreachable dst-address=172.16.7.0/24 src-address=172.16.9.0/24
- add action=unreachable dst-address=172.16.5.0/24 src-address=172.16.9.0/24
- add action=unreachable dst-address=172.16.40.0/24 src-address=172.16.7.0/24
- add action=unreachable dst-address=172.16.30.0/24 src-address=172.16.7.0/24
- add action=unreachable dst-address=172.16.20.0/24 src-address=172.16.7.0/24
- add action=unreachable dst-address=172.16.10.0/24 src-address=172.16.7.0/24
- add action=unreachable dst-address=172.16.9.0/24 src-address=172.16.7.0/24
- add action=unreachable dst-address=172.16.5.0/24 src-address=172.16.7.0/24
- add action=unreachable dst-address=172.16.4.0/24 src-address=172.16.7.0/24
- add action=unreachable dst-address=172.16.3.0/24 src-address=172.16.7.0/24
- add action=unreachable dst-address=172.16.2.0/24 src-address=172.16.7.0/24
- add action=unreachable dst-address=172.16.1.0/24 src-address=172.16.7.0/24
- add action=unreachable dst-address=172.16.40.0/24 src-address=172.16.5.0/24
- add action=unreachable dst-address=172.16.30.0/24 src-address=172.16.5.0/24
- add action=unreachable dst-address=172.16.20.0/24 src-address=172.16.5.0/24
- add action=unreachable dst-address=172.16.10.0/24 src-address=172.16.5.0/24
- add action=unreachable dst-address=172.16.9.0/24 src-address=172.16.5.0/24
- add action=unreachable dst-address=172.16.7.0/24 src-address=172.16.5.0/24
- add action=unreachable dst-address=172.16.4.0/24 src-address=172.16.5.0/24
- add action=unreachable dst-address=172.16.3.0/24 src-address=172.16.5.0/24
- add action=unreachable dst-address=172.16.2.0/24 src-address=172.16.5.0/24
- add action=unreachable dst-address=172.16.1.0/24 src-address=172.16.5.0/24
- add action=unreachable dst-address=172.16.40.0/24 src-address=172.16.4.0/24
- add action=unreachable dst-address=172.16.30.0/24 src-address=172.16.4.0/24
- add action=unreachable dst-address=172.16.20.0/24 src-address=172.16.4.0/24
- add action=unreachable dst-address=172.16.10.0/24 src-address=172.16.4.0/24
- add action=unreachable dst-address=172.16.7.0/24 src-address=172.16.4.0/24
- add action=unreachable dst-address=172.16.5.0/24 src-address=172.16.4.0/24
- add action=unreachable disabled=yes dst-address=172.16.3.0/24 src-address=\
- 172.16.4.0/24
- add action=unreachable disabled=yes dst-address=172.16.1.0/24 src-address=\
- 172.16.4.0/24
- add action=unreachable dst-address=172.16.40.0/24 src-address=172.16.3.0/24
- add action=unreachable dst-address=172.16.30.0/24 src-address=172.16.3.0/24
- add action=unreachable dst-address=172.16.20.0/24 src-address=172.16.3.0/24
- add action=unreachable dst-address=172.16.10.0/24 src-address=172.16.3.0/24
- add action=unreachable dst-address=172.16.40.0/24 src-address=172.16.1.0/24
- add action=unreachable dst-address=172.16.30.0/24 src-address=172.16.1.0/24
- add action=unreachable dst-address=172.16.20.0/24 src-address=172.16.1.0/24
- add action=unreachable dst-address=172.16.10.0/24 src-address=172.16.1.0/24
- add action=unreachable dst-address=172.16.7.0/24 src-address=172.16.1.0/24
- add action=unreachable disabled=yes dst-address=172.16.4.0/24 src-address=\
- 172.16.1.0/24
- add action=unreachable dst-address=172.16.5.0/24 src-address=172.16.1.0/24
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set www disabled=yes port=99
- set ssh disabled=yes
- set api disabled=yes
- set winbox address=\
- 172.16.9.0/24,172.16.3.0/24,213.234.25.92/32,178.236.242.126/32
- set api-ssl disabled=yes
- /ppp secret
- add local-address=172.16.9.1 name=*********** password=*********** remote-address=\
- 172.16.9.29 service=pptp
- add disabled=yes local-address=172.16.9.1 name=*********** password=*********** \
- remote-address=172.16.9.28 service=pptp
- add disabled=yes local-address=172.16.9.1 name=*********** password=*********** \
- remote-address=172.16.9.26 service=pptp
- /snmp
- set enabled=yes
- /system clock
- set time-zone-name=Europe/Volgograd
- /system clock manual
- set time-zone=+03:00
- /system identity
- set name="MikroTik ***********"
- /system ntp client
- set enabled=yes primary-ntp=88.147.254.232 secondary-ntp=91.226.136.155 \
- server-dns-names=ntp1.stratum2.ru
- /system scheduler
- add interval=1w3d name=Reboot on-event=" /system reboot" policy=\
- ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
- start-date=oct/17/2017 start-time=03:00:00
- add interval=5d name=BackupRouter*********** on-event=\
- "/system script run ScriptBackup" policy=\
- ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
- start-date=nov/02/2017 start-time=23:00:24
- /system script
- add name=ScriptBackup owner=*********** policy=\
- ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="{\
- \r\
- \n:log info \"Starting Backup Script...\";\r\
- \n:local sysname [/system identity get name];\r\
- \n:local sysver [/system package get system version];\r\
- \n:log info \"Flushing DNS cache...\";\r\
- \n/ip dns cache flush;\r\
- \n:delay 2;\r\
- \n:log info \"Deleting last Backups...\";\r\
- \n:foreach i in=[/file find] do={:if ([:typeof [:find [/file get \$i name]\
- \_\\\r\
- \n\"\$sysname-backup-\"]]!=\"nil\") do={/file remove \$i}};\r\
- \n:delay 2;\r\
- \n:local smtpserv [:resolve \"smtp.yandex.ru\"];\r\
- \n:local Eaccount \"[email protected]\";\r\
- \n:local pass \"***********\";\r\
- \n:local backupfile (\"\$sysname-backup-\" . \\\r\
- \n[:pick [/system clock get date] 7 11] . [:pick [/system \\\r\
- \nclock get date] 0 3] . [:pick [/system clock get date] 4 6] . \".backup\
- \");\r\
- \n:log info \"Creating new Full Backup file...\";\r\
- \n/system backup save name=\$backupfile;\r\
- \n:delay 2;\r\
- \n:log info \"Sending Full Backup file via E-mail...\";\r\
- \n/tool e-mail send from=\"<\$Eaccount>\" to=\$Eaccount server=\$smtpserv \
- \\\r\
- \nport=587 user=\$Eaccount password=\$pass start-tls=yes file=\$backupfile\
- \_\\\r\
- \nsubject=(\"\$sysname Full Backup (\" . [/system clock get date] . \")\")\
- \_\\\r\
- \nbody=(\"\$sysname full Backup file see in attachment.\\nRouterOS version\
- : \\\r\
- \n\$sysver\\nTime and Date stamp: \" . [/system clock get time] . \" \" . \
- \\\r\
- \n[/system clock get date]);\r\
- \n:delay 5;\r\
- \n:local exportfile (\"\$sysname-backup-\" . \\\r\
- \n[:pick [/system clock get date] 7 11] . [:pick [/system \\\r\
- \nclock get date] 0 3] . [:pick [/system clock get date] 4 6] . \".rsc\");\
- \r\
- \n:log info \"Creating new Setup Script file...\";\r\
- \n/export verbose file=\$exportfile;\r\
- \n:delay 2;\r\
- \n:log info \"Sending Setup Script file via E-mail...\";\r\
- \n/tool e-mail send from=\"<\$Eaccount>\" to=\$Eaccount server=\$smtpserv \
- \\\r\
- \nport=587 user=\$Eaccount password=\$pass start-tls=yes file=\$exportfile\
- \_\\\r\
- \nsubject=(\"\$sysname Setup Script Backup (\" . [/system clock get date] \
- . \\\r\
- \n\")\") body=(\"\$sysname Setup Script file see in attachment.\\nRouterOS\
- \_\\\r\
- \nversion: \$sysver\\nTime and Date stamp: \" . [/system clock get time] .\
- \_\" \\\r\
- \n\" . [/system clock get date]);\r\
- \n:delay 5;\r\
- \n:log info \"All System Backups emailed successfully.\\nBackuping complet\
- ed.\";\r\
- \n}\r\
- \n"
- add name=Enable_sms owner=*********** policy=\
- ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=\
- "/tool sms set receive-enabled=yes\r\
- \n"
- add name=Reboot owner=*********** policy=\
- ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="/\
- tool sms send usb3 channel=3 \"+7***********\" message=\"Rebooting Mikrotik\
- ...\"; \r\
- \n:delay 5s; \r\
- \n/system reboot"
- add name=Reboot_interfaces3 owner=*********** policy=\
- ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=":\
- log warning (\"Rebooting interfaces\");\r\
- \n /tool sms send usb3 channel=3 \"+7***********\" message=\"Rebooting inte\
- rfaces3...\"; \r\
- \n/interface ethernet set ether3 disabled=yes; :delay 15s; \r\
- \n/interface ethernet set ether3 disabled=no;"
- add name=Reboot_interfaces4 owner=*********** policy=\
- ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=":\
- log warning (\"Rebooting interfaces4\"); /tool sms send usb3 channel=3 \"+\
- 7***********\" message=\"Rebooting interfaces4...\"; /interface ethernet se\
- t ether4 disabled=yes; :delay 15s; \r\
- \n/interface ethernet set ether4 disabled=no"
- add name=Down_interfaces3 owner=*********** policy=\
- ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=":\
- log warning (\"Down interfaces3\");\r\
- \n /tool sms send usb3 channel=3 \"+7***********\" message=\"Down interface\
- s3...\"; \r\
- \n/interface ethernet set ether3 disabled=yes"
- add name=UP_interfaces3 owner=*********** policy=\
- ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=":\
- log warning (\"UP interfaces3\");\r\
- \n/tool sms send usb3 channel=3 \"+7***********\" message=\"UP interfaces3.\
- ..\"; \r\
- \n/interface ethernet set ether3 disabled=no"
- /tool bandwidth-server
- set authenticate=no
- /tool e-mail
- set [email protected] password=*********** start-tls=yes user=\
- /tool netwatch
- add down-script="/ip route enable [find comment=\"ISP2\"]\r\
- \n/tool e-mail send server=smtp.yandex.ru port=25 user=ZabbixServer***********@ya\
- ndex.ru password=*********** [email protected] from=\"MikroTIK3011RI\
- NG<ZabbixServer***********@yandex.ru>\" \\\r\
- \nsubject=\"MikroTIK3011***********: \$[/system clock get date], \$[/system clock\
- \_get time]\" \\\r\
- \nbody=\"\CF\E5\F0\E5\EA\EB\FE\F7\E5\ED\E8\E5 \ED\E0 \EE\F1\ED\EE\E2\ED\EE\
- \E9 \EA\E0\ED\E0\EB\\n\C4\E0\F2\E0: \$[/system clock get date]\\nA\C2\F0\
- \E5\EC\FF: \$[/system clock get time]\";" host=8.8.4.4 up-script="/ip rout\
- e disable [find comment=\"ISP2\"]\r\
- \n/tool e-mail send server=smtp.yandex.ru port=25 user=ZabbixServer***********@ya\
- ndex.ru password=*********** [email protected] from=\"MikroTIK3011RI\
- NG<ZabbixServer***********@yandex.ru>\" \\\r\
- \nsubject=\"MikroTIK3011***********: \$[/system clock get date], \$[/system clock\
- \_get time]\" \\\r\
- \nbody=\"\CF\E5\F0\E5\EA\EB\FE\F7\E5\ED\E8\E5 \ED\E0 \F0\E5\E7\E5\F0\E2\ED\
- \FB\E9 \EA\E0\ED\E0\EB\\n\C4\E0\F2\E0: \$[/system clock get date]\\nA\C2\
- \F0\E5\EC\FF: \$[/system clock get time]\";"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement