Advertisement
korpo53

rb4011 config

Apr 24th, 2024
72
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.68 KB | None | 0 0
  1. # 2024-04-24 15:43:27 by RouterOS 7.12.1
  2. # software id = B10P-R5ZW
  3. #
  4. # model = RB4011iGS+
  5. # serial number = XXXXXX
  6. /interface bridge add name=bridge1 vlan-filtering=yes
  7. /interface vlan add interface=bridge1 name=vlan99 vlan-id=99
  8. /interface list add name=wan
  9. /interface list add name=lan
  10. /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik
  11. /port set 0 name=serial0
  12. /port set 1 name=serial1
  13. /zerotier set zt1 comment="ZeroTier Central controller - https://my.zerotier.com/" disabled=yes disabled=yes name=zt1 port=9993
  14. /interface bridge port add bridge=bridge1 interface=sfp-sfpplus1
  15. /interface bridge port add bridge=bridge1 interface=ether1
  16. /interface bridge port add bridge=bridge1 interface=ether2
  17. /interface bridge port add bridge=bridge1 interface=ether3
  18. /interface bridge port add bridge=bridge1 interface=ether4
  19. /interface bridge port add bridge=bridge1 interface=ether5
  20. /interface bridge port add bridge=bridge1 interface=ether6
  21. /interface bridge port add bridge=bridge1 interface=ether7
  22. /interface bridge port add bridge=bridge1 interface=ether8
  23. /interface bridge port add bridge=bridge1 interface=ether9
  24. /ip neighbor discovery-settings set discover-interface-list=!dynamic
  25. /ip settings set max-neighbor-entries=6144
  26. /ipv6 settings set disable-ipv6=yes forward=no max-neighbor-entries=3072
  27. /interface bridge vlan add bridge=bridge1 tagged=sfp-sfpplus1 vlan-ids=99
  28. /interface list member add interface=vlan99 list=wan
  29. /interface list member add interface=bridge1 list=lan
  30. /ip address add address=192.168.0.81/16 interface=bridge1 network=192.168.0.0
  31. /ip cloud set ddns-enabled=yes ddns-update-interval=5m
  32. /ip dns set servers=192.168.0.51
  33. /ip firewall filter add action=fasttrack-connection chain=input comment="accept established or related" connection-state=established,related hw-offload=yes
  34. /ip firewall filter add action=accept chain=input comment="accept established or related" connection-state=established,related
  35. /ip firewall filter add action=drop chain=input comment="drop invalid" connection-state=invalid
  36. /ip firewall filter add action=drop chain=input comment="drop input from outside the lan" in-interface-list=!lan
  37. /ip firewall filter add action=fasttrack-connection chain=forward comment="accept established or related" connection-state=established,related hw-offload=yes
  38. /ip firewall filter add action=accept chain=forward comment="accept established or related" connection-state=established,related
  39. /ip firewall filter add action=drop chain=forward comment="drop invalid" connection-state=invalid
  40. /ip firewall filter add action=drop chain=forward comment="drop forwards from outside the wan no dstnat" connection-nat-state=!dstnat connection-state=new in-interface-list=!lan
  41. /ip firewall nat add action=masquerade chain=srcnat out-interface-list=wan
  42. /ip service set telnet disabled=yes
  43. /ip service set ftp disabled=yes
  44. /ip service set www disabled=yes
  45. /ip service set ssh address=192.168.0.0/16
  46. /ip service set api address=192.168.0.0/16
  47. /ip service set winbox address=192.168.0.0/16
  48. /ip service set api-ssl disabled=yes
  49. /ip smb set allow-guests=no
  50. /ip smb shares set [ find default=yes ] disabled=yes
  51. /system identity set name=rb4011
  52. /system note set show-at-login=no
  53. /system ntp client set enabled=yes
  54. /system ntp server set enabled=yes
  55. /system ntp client servers add address=216.239.35.0
  56. /system ntp client servers add address=216.239.35.4
  57. /system ntp client servers add address=216.239.35.8
  58. /system ntp client servers add address=216.239.35.12
  59. /system routerboard settings set auto-upgrade=yes
  60. /tool mac-server set allowed-interface-list=none
  61. /tool mac-server mac-winbox set allowed-interface-list=lan
  62. /tool mac-server ping set enabled=no
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement