Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /interface bridge
- add admin-mac=XX:XX:XX:XX:XX:XX auto-mac=no name=bridge
- /interface wireless
- set [ find default-name=wlan1 ] adaptive-noise-immunity=ap-and-client-mode \
- band=2ghz-onlyn basic-rates-a/g="" basic-rates-b="" channel-width=\
- 20/40mhz-eC country=ukraine disabled=no distance=indoors frequency=2472 \
- hw-protection-mode=rts-cts mode=ap-bridge multicast-helper=full name=wlan \
- ssid=XXXXXX supported-rates-a/g="" supported-rates-b="" \
- wireless-protocol=802.11 wmm-support=enabled
- /interface ethernet
- set [ find default-name=ether2 ] name=lan1
- set [ find default-name=ether3 ] master-port=lan1 name=lan2
- set [ find default-name=ether4 ] master-port=lan1 name=lan3
- set [ find default-name=ether1 ] name=wan
- /interface pppoe-client
- add add-default-route=yes disabled=no interface=wan name=pppoe-internet \
- password=XXXXXX use-peer-dns=yes user=XXXXXX
- /interface wireless nstreme
- set wlan enable-polling=no
- /ip neighbor discovery
- set wan discover=no
- set wlan discover=no
- set pppoe-internet discover=no
- /interface wireless security-profiles
- set [ find default=yes ] authentication-types=wpa2-psk mode=dynamic-keys \
- wpa2-pre-shared-key=XXXXXXX
- /ip pool
- add name=dhcp-pool ranges=192.168.88.10-192.168.88.254
- /ip dhcp-server
- add address-pool=dhcp-pool disabled=no interface=bridge lease-time=3d name=\
- dhcp-server
- /interface bridge port
- add bridge=bridge interface=lan1
- add bridge=bridge interface=wlan
- /ip address
- add address=192.168.88.1/24 interface=bridge network=192.168.88.0
- /ip cloud
- set ddns-enabled=yes
- /ip dhcp-client
- add dhcp-options=hostname,clientid disabled=no interface=wan
- /ip dhcp-server network
- add address=192.168.88.0/24 dns-server=192.168.88.1 gateway=192.168.88.1 \
- netmask=24
- /ip dns
- set allow-remote-requests=yes servers=194.143.136.1,194.143.136.2
- /ip dns static
- add address=192.168.88.1 name=router
- /ip firewall address-list
- add address=46.250.0.0/19 list=briz-list
- add address=109.200.224.0/19 list=briz-list
- add address=185.6.184.0/22 list=briz-list
- add address=194.143.136.0/23 list=briz-list
- add address=195.66.216.0/21 list=briz-list
- add address=213.231.0.0/18 list=briz-list
- add address=94.74.100.0/22 list=briz-list
- add address=94.74.104.0/22 list=briz-list
- add address=94.74.120.0/21 list=briz-list
- add address=195.66.212.0/22 list=briz-list
- add address=172.17.0.0/16 list=briz-local-list
- add address=172.18.0.0/16 list=briz-local-list
- add address=172.19.0.0/16 list=briz-local-list
- /ip firewall filter
- add chain=input comment="Enable access port Winbox of PPPoE" dst-port=18291 \
- in-interface=pppoe-internet protocol=tcp src-address-list=briz-list
- add chain=input comment="Enable access port Winbox of WAN" dst-port=18291 \
- in-interface=wan protocol=tcp src-address-list=briz-local-list
- add chain=input comment="Enable PING" icmp-options=8 protocol=icmp
- add chain=input comment="Enable IPTV" in-interface=wan protocol=igmp
- add chain=forward dst-port=1234 in-interface=wan protocol=udp
- add chain=forward in-interface=wan protocol=igmp
- add chain=input comment="Enable establieshed,related connections" \
- connection-state=established,related
- add action=drop chain=input comment="Drop all from WAN" in-interface=wan
- add action=drop chain=input comment="Drop all from PPPoE" in-interface=\
- pppoe-internet
- add chain=forward comment="Enable establieshed,related connections" \
- connection-state=established,related
- add action=fasttrack-connection chain=forward comment=Fasttrack \
- connection-state=established,related
- add action=drop chain=forward comment="Drop invalid connection packets" \
- connection-state=invalid
- add action=drop chain=forward comment="Drop all from WAN not DSTNATed" \
- connection-nat-state=!dstnat connection-state=new in-interface=wan
- add action=drop chain=forward comment="Drop all from PPPoE not DSTNATed" \
- connection-nat-state=!dstnat connection-state=new in-interface=\
- pppoe-internet
- /ip firewall nat
- add action=masquerade chain=srcnat comment="NAT LOCAL ISP" out-interface=wan
- add action=masquerade chain=srcnat comment="NAT INTERNET" out-interface=\
- pppoe-internet
- /ip firewall service-port
- set ftp disabled=yes
- set tftp disabled=yes
- set irc disabled=yes
- set h323 disabled=yes
- set sip disabled=yes
- set pptp disabled=yes
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set www disabled=yes
- set ssh disabled=yes
- set api disabled=yes
- set winbox port=18291
- set api-ssl disabled=yes
- /routing igmp-proxy
- set query-interval=1m quick-leave=yes
- /routing igmp-proxy interface
- add comment="Downstream IPTV" interface=bridge
- add alternative-subnets=172.17.24.0/24,10.255.5.0/24 comment="Upstream IPTV" \
- interface=wan upstream=yes
- /system clock
- set time-zone-name=Europe/Kiev
- /system ntp client
- set enabled=yes primary-ntp=91.218.89.74 secondary-ntp=62.149.0.30
- /system routerboard settings
- set cpu-frequency=650MHz protected-routerboot=disabled
- /tool bandwidth-server
- set authenticate=no enabled=no
- /tool mac-server
- set [ find default=yes ] disabled=yes
- add interface=bridge
- /tool mac-server mac-winbox
- set [ find default=yes ] disabled=yes
- add interface=bridge
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement