Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /interface bridge
- add admin-mac=64:D1:54:B0:94:E8 auto-mac=no comment=defconf name=bridge
- /interface ethernet
- set [ find default-name=ether1 ] comment=ISP
- /interface l2tp-server
- add name=L2TP-DeusEx user=DeusEx
- /interface ovpn-server
- add name=OVPN-DeusEx user=DeusEx
- /interface pptp-server
- add name=PPTP-DeusEx user=DeusEx
- /interface vlan
- add comment=ESXi interface=bridge name=vlan10 vlan-id=10
- add comment=Voice interface=bridge name=vlan11 vlan-id=11
- add comment=Site interface=bridge name=vlan12 vlan-id=12
- add comment=1C interface=bridge name=vlan13 vlan-id=13
- add comment=Video interface=bridge name=vlan14 vlan-id=14
- add comment=Radio interface=bridge name=vlan15 vlan-id=15
- add comment=Wi-Fi interface=bridge name=vlan16 vlan-id=16
- add comment=Management interface=bridge name=vlan20 vlan-id=20
- add comment=VPN interface=bridge name=vlan50 vlan-id=50
- /interface list
- add comment=defconf name=WAN
- add comment=defconf name=LAN
- /interface wireless security-profiles
- set [ find default=yes ] supplicant-identity=MikroTik
- add authentication-types=wpa2-psk eap-methods="" group-ciphers=tkip,aes-ccm management-protection=allowed mode=dynamic-keys name=DeusEx supplicant-identity="" unicast-ciphers=tkip,aes-ccm
- /interface wireless
- set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-XX country=russia disabled=no distance=indoors frequency=auto frequency-mode=manual-txpower installation=indoor mode=ap-bridge \
- security-profile=DeusEx ssid=DeusEx tx-power=30 tx-power-mode=all-rates-fixed wireless-protocol=802.11 wps-mode=disabled
- add disabled=no mac-address=66:D1:54:B0:94:EC master-interface=wlan1 name=wlan2 security-profile=DeusEx ssid=Service vlan-id=20 vlan-mode=use-tag wps-mode=disabled
- /ip pool
- add name=Vlan1 ranges=192.168.1.2-192.168.1.254
- add name=Vlan10 ranges=192.168.10.2-192.168.10.254
- add name=Vlan11 ranges=192.168.11.2-192.168.11.254
- add name=Vlan12 ranges=192.168.12.2-192.168.12.254
- add name=Vlan13 ranges=192.168.13.2-192.168.13.254
- add name=Vlan14 ranges=192.168.14.2-192.168.14.254
- add name=Vlan15 ranges=192.168.15.2-192.168.15.254
- add name=Vlan16 ranges=192.168.16.2-192.168.16.254
- add name=Vlan20 ranges=192.168.20.2-192.168.20.254
- add name=Vlan50 ranges=192.168.50.2-192.168.50.254
- /ip dhcp-server
- add address-pool=Vlan1 disabled=no interface=bridge lease-time=12h name=vlan1
- add address-pool=Vlan10 disabled=no interface=vlan10 lease-time=12h name=vlan10
- add address-pool=Vlan11 disabled=no interface=vlan11 lease-time=12h name=vlan11
- add address-pool=Vlan12 disabled=no interface=vlan12 lease-time=12h name=vlan12
- add address-pool=Vlan13 disabled=no interface=vlan13 lease-time=12h name=vlan13
- add address-pool=Vlan14 disabled=no interface=vlan14 lease-time=12h name=vlan14
- add address-pool=Vlan15 disabled=no interface=vlan15 lease-time=12h name=vlan15
- add address-pool=Vlan16 disabled=no interface=vlan16 lease-time=12h name=vlan16
- add address-pool=Vlan20 disabled=no interface=vlan20 lease-time=12h name=vlan20
- add address-pool=Vlan50 disabled=no interface=vlan50 lease-time=12h name=vlan50
- /ppp profile
- add local-address=Vlan50 name=VPN remote-address=Vlan50
- /interface l2tp-client
- add allow=mschap2 connect-to=95.78.164.203 name=L2TP-MegaService profile=VPN use-ipsec=yes user=DeusEx
- /interface pptp-client
- add allow=mschap2 connect-to=95.78.164.203 name=PPTP-MegaService profile=VPN user=DeusEx
- /interface bridge port
- add auto-isolate=yes bridge=bridge comment=defconf interface=ether2
- add auto-isolate=yes bridge=bridge comment=defconf interface=ether3
- add auto-isolate=yes bridge=bridge comment=defconf interface=ether4 pvid=10
- add auto-isolate=yes bridge=bridge comment=defconf interface=ether5
- add auto-isolate=yes bridge=bridge comment=defconf interface=wlan1
- add auto-isolate=yes bridge=bridge interface=wlan2
- /ip neighbor discovery-settings
- set discover-interface-list=WAN
- /interface bridge vlan
- add bridge=bridge untagged=bridge vlan-ids=""
- add bridge=bridge tagged=bridge,ether2,ether3 vlan-ids=10
- add bridge=bridge tagged=bridge,ether2,ether3 vlan-ids=11
- add bridge=bridge tagged=bridge,ether2,ether3 vlan-ids=12
- Александр Ковалевич, [04.01.20 23:30]
- add bridge=bridge tagged=bridge,ether2,ether3 vlan-ids=13
- add bridge=bridge tagged=bridge,ether2,ether3 vlan-ids=14
- add bridge=bridge tagged=bridge,ether2,ether3 vlan-ids=15
- add bridge=bridge tagged=bridge,ether2,ether3 vlan-ids=16
- add bridge=bridge tagged=bridge,ether2,ether3 untagged=ether4 vlan-ids=20
- add bridge=wlan2 tagged=wlan2,vlan20,ether4 vlan-ids=20
- /interface detect-internet
- set internet-interface-list=WAN lan-interface-list=LAN wan-interface-list=WAN
- /interface l2tp-server server
- set authentication=mschap2 default-profile=VPN enabled=yes use-ipsec=yes
- /interface list member
- add comment=defconf interface=bridge list=LAN
- add comment=defconf interface=ether1 list=WAN
- add interface=vlan10 list=LAN
- add interface=vlan11 list=LAN
- add interface=vlan12 list=LAN
- add interface=vlan13 list=LAN
- add interface=vlan14 list=LAN
- add interface=vlan15 list=LAN
- add interface=vlan16 list=LAN
- add interface=vlan20 list=LAN
- add interface=vlan50 list=LAN
- /interface ovpn-server server
- set auth=sha1 certificate=SRV cipher=blowfish128,aes128,aes192,aes256 default-profile=VPN enabled=yes
- /interface pptp-server server
- set authentication=mschap2 default-profile=VPN enabled=yes
- /ip address
- add address=192.168.1.1/24 comment=defconf interface=bridge network=192.168.1.0
- add address=192.168.10.1/24 interface=vlan10 network=192.168.10.0
- add address=192.168.11.1/24 interface=vlan11 network=192.168.11.0
- add address=192.168.12.1/24 interface=vlan12 network=192.168.12.0
- add address=192.168.13.1/24 interface=vlan13 network=192.168.13.0
- add address=192.168.14.1/24 interface=vlan14 network=192.168.14.0
- add address=192.168.15.1/24 interface=vlan15 network=192.168.15.0
- add address=192.168.16.1/24 interface=vlan16 network=192.168.16.0
- add address=192.168.20.1/24 interface=vlan20 network=192.168.20.0
- add address=192.168.50.1/24 comment=VPN interface=vlan50 network=192.168.50.0
- /ip dhcp-client
- add comment=defconf disabled=no interface=ether1
- /ip dhcp-server lease
- add address=192.168.20.3 client-id=1:bc:ae:c5:3:dc:fe comment=KVM mac-address=BC:AE:C5:03:DC:FE server=vlan20
- add address=192.168.1.4 client-id=1:80:fa:5b:e:c5:e4 comment="NoteBook Lan" mac-address=80:FA:5B:0E:C5:E4 server=vlan1
- add address=192.168.1.3 client-id=1:a8:9c:ed:3b:7f:3 comment="DeusEx Phone" mac-address=A8:9C:ED:3B:7F:03 server=vlan1
- add address=192.168.14.2 client-id=1:2c:7:3c:0:1b:eb comment=Registrator mac-address=2C:07:3C:00:1B:EB server=vlan14
- add address=192.168.14.3 client-id=1:9c:14:63:c9:64:e1 comment=Camera1 mac-address=9C:14:63:C9:64:E1 server=vlan14
- add address=192.168.10.2 client-id=1:0:24:8c:e:e1:c8 comment="ESXi 1" mac-address=00:24:8C:0E:E1:C8 server=vlan10
- add address=192.168.20.2 client-id=cisco-58bf.ea91.60c1-Vl20 comment=Switch mac-address=58:BF:EA:91:60:C1 server=vlan20
- add address=192.168.20.4 client-id=1:0:c:29:b2:5c:10 comment=VCSA mac-address=00:0C:29:B2:5C:10 server=vlan20
- add address=192.168.11.5 comment=A510-IP mac-address=7C:2F:80:5F:E2:18 server=vlan11
- add address=192.168.11.3 client-id=1:38:3f:10:0:bd:cc comment=Goip-4 mac-address=38:3F:10:00:BD:CC server=vlan11
- add address=192.168.11.4 client-id=1:0:15:65:3f:52:e comment=SIP-T26P mac-address=00:15:65:3F:52:0E server=vlan11
- add address=192.168.13.2 client-id=1:0:50:56:8d:d0:8f comment=DC mac-address=00:50:56:8D:D0:8F server=vlan13
- add address=192.168.13.3 client-id=1:0:50:56:8d:e2:8b comment=SQL mac-address=00:50:56:8D:E2:8B server=vlan13
- add address=192.168.13.4 client-id=1:0:50:56:8d:fb:c2 comment=FS mac-address=00:50:56:8D:FB:C2 server=vlan13
- add address=192.168.20.5 client-id=1:0:c0:b7:96:51:f7 comment=APC mac-address=00:C0:B7:96:51:F7 server=vlan20
- add address=192.168.13.5 client-id=1:0:50:56:9c:7:50 comment=1C mac-address=00:50:56:9C:07:50 server=vlan13
- add address=192.168.20.6 comment=PCNS mac-address=00:50:56:9C:7B:9F server=vlan20
- add address=192.168.12.2 comment=Site mac-address=00:50:56:9C:01:A4 server=vlan12
- add address=192.168.1.254 client-id=1:88:5a:92:a7:6c:a5 comment=AccessPoint mac-address=88:5A:92:A7:6C:A5 server=vlan1
- Александр Ковалевич, [04.01.20 23:30]
- /system identity
- set name="DeusEx Home"
- /tool mac-server
- set allowed-interface-list=LAN
- /tool mac-server mac-winbox
- set allowed-interface-list=LAN
- /tool romon
- set enabled=yes
- Александр Ковалевич, [04.01.20 23:30]
- add address=192.168.1.5 client-id=1:ec:5c:68:7b:7a:85 comment=TV mac-address=EC:5C:68:7B:7A:85 server=vlan1
- add address=192.168.11.2 comment=SIP mac-address=00:50:56:2E:A6:BD server=vlan11
- /ip dhcp-server network
- add address=192.168.1.0/24 comment=defconf gateway=192.168.1.1
- add address=192.168.10.0/24 gateway=192.168.10.1
- add address=192.168.11.0/24 dhcp-option=*1 gateway=192.168.11.1 netmask=24
- add address=192.168.12.0/24 gateway=192.168.12.1 netmask=24
- add address=192.168.13.0/24 dns-server=192.168.13.2,192.168.13.1 domain=office.it-sis.ru gateway=192.168.13.1 netmask=24 wins-server=192.168.13.2
- add address=192.168.14.0/24 gateway=192.168.14.1
- add address=192.168.15.0/24 gateway=192.168.15.1
- add address=192.168.16.0/24 gateway=192.168.16.1
- add address=192.168.20.0/24 gateway=192.168.20.1
- add address=192.168.50.0/24 gateway=192.168.50.1
- /ip dns
- set allow-remote-requests=yes cache-size=20480KiB
- /ip dns static
- add address=192.168.1.1 comment=defconf name=router.lan
- add address=192.168.20.4 name=vcsa.office.it-sis.ru
- add address=192.168.10.2 name=esxi.office.it-sis.ru
- add address=192.168.13.2 name=dc.office.it-sis.ru
- add address=192.168.13.3 name=sql.office.it-sis.ru
- add address=192.168.13.4 name=fs.office.it-sis.ru
- add address=192.168.13.5 name=1c.office.it-sis.ru
- /ip firewall filter
- add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
- add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
- add action=drop chain=forward comment="Drop BlackList" in-interface-list=WAN src-address-list=BlackList
- add action=drop chain=forward comment="drop SIP brute forcers" in-interface-list=WAN src-address-list=SIP_blacklist
- add action=add-src-to-address-list address-list=SIP_blacklist address-list-timeout=none-dynamic chain=forward connection-state=new dst-address=192.168.11.2 in-interface-list=WAN protocol=udp \
- src-address-list=SIP_stage3
- add action=add-src-to-address-list address-list=SIP_stage3 address-list-timeout=1h chain=forward connection-state=new dst-address=192.168.11.2 in-interface-list=WAN protocol=udp src-address-list=\
- SIP_stage2
- add action=add-src-to-address-list address-list=SIP_stage2 address-list-timeout=1h chain=forward connection-state=new dst-address=192.168.11.2 in-interface-list=WAN protocol=udp src-address-list=\
- SIP_stage1
- add action=add-src-to-address-list address-list=SIP_stage1 address-list-timeout=1h chain=forward connection-state=new dst-address=192.168.11.2 in-interface-list=WAN protocol=udp src-address=0.0.0.0/0
- add action=drop chain=input comment="drop ssh brute forcers" in-interface-list=WAN protocol=tcp src-address-list=SSH_blacklist
- add action=add-src-to-address-list address-list=SSH_blacklist address-list-timeout=none-dynamic chain=input connection-state=new dst-port=22,9999 in-interface-list=WAN protocol=tcp src-address-list=\
- SSH_stage3
- add action=add-src-to-address-list address-list=SSH_stage3 address-list-timeout=1m chain=input connection-state=new dst-port=22,9999 in-interface-list=WAN protocol=tcp src-address-list=SSH_stage2
- add action=add-src-to-address-list address-list=SSH_stage2 address-list-timeout=1m chain=input connection-state=new dst-port=22,9999 in-interface-list=WAN protocol=tcp src-address-list=SSH_stage1
- add action=add-src-to-address-list address-list=SSH_stage1 address-list-timeout=1m chain=input connection-state=new dst-port=22,9999 in-interface-list=WAN protocol=tcp
- add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
- add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
- add action=accept chain=input comment=PPTP dst-port=1723 protocol=tcp
- add action=accept chain=input protocol=gre
- add action=accept chain=input comment=L2TP port=1701,500,4500 protocol=udp
- add action=accept chain=input protocol=ipsec-esp
- add action=accept chain=input comment=OVPN dst-port=1194 protocol=tcp
- add action=accept chain=forward comment=DevLine dst-port=9786 protocol=tcp
- Александр Ковалевич, [04.01.20 23:30]
- add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
- add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec
- add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec
- add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
- add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
- add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
- add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
- add action=accept chain=input comment="Accept port`s WAN TCP" disabled=yes dst-port=53 in-interface=ether1 protocol=tcp
- add action=accept chain=input disabled=yes dst-port=80 in-interface=ether1 protocol=tcp
- add action=accept chain=input disabled=yes dst-port=443 in-interface=ether1 protocol=tcp
- add action=accept chain=input disabled=yes dst-port=873 in-interface=ether1 protocol=tcp
- add action=accept chain=input disabled=yes dst-port=2221 in-interface=ether1 protocol=tcp
- add action=accept chain=input disabled=yes dst-port=8887 in-interface=ether1 protocol=tcp
- add action=accept chain=input disabled=yes dst-port=8888 in-interface=ether1 protocol=tcp
- add action=accept chain=input disabled=yes dst-port=9090 in-interface=ether1 protocol=tcp
- add action=accept chain=input disabled=yes dst-port=9998 in-interface=ether1 protocol=tcp
- add action=accept chain=input disabled=yes dst-port=9999 in-interface=ether1 protocol=tcp
- add action=accept chain=input disabled=yes dst-port=50000 in-interface=ether1 protocol=tcp
- add action=accept chain=input disabled=yes dst-port=50001 in-interface=ether1 protocol=tcp
- add action=accept chain=input comment="Accept port`s WAN UDP" disabled=yes dst-port=53 in-interface=ether1 protocol=udp
- add action=accept chain=input disabled=yes dst-port=80 in-interface=ether1 protocol=udp
- add action=accept chain=input disabled=yes dst-port=443 in-interface=ether1 protocol=udp
- add action=accept chain=input disabled=yes dst-port=873 in-interface=ether1 protocol=udp
- add action=accept chain=input disabled=yes dst-port=2221 in-interface=ether1 protocol=udp
- add action=accept chain=input disabled=yes dst-port=8887 in-interface=ether1 protocol=udp
- add action=accept chain=input disabled=yes dst-port=8888 in-interface=ether1 protocol=udp
- add action=accept chain=input disabled=yes dst-port=9999 in-interface=ether1 protocol=udp
- add action=accept chain=input disabled=yes dst-port=50000 in-interface=ether1 protocol=udp
- add action=accept chain=input disabled=yes dst-port=50001 in-interface=ether1 protocol=udp
- add action=accept chain=input disabled=yes dst-port=5004-5082,10000-20000 in-interface=ether1 protocol=udp
- add action=accept chain=forward comment="Accept port`s WAN TCP" disabled=yes dst-port=53 in-interface=ether1 protocol=tcp
- add action=accept chain=forward disabled=yes dst-port=80 in-interface=ether1 protocol=tcp
- add action=accept chain=forward disabled=yes dst-port=443 in-interface=ether1 protocol=tcp
- add action=accept chain=forward disabled=yes dst-port=873 in-interface=ether1 protocol=tcp
- add action=accept chain=forward disabled=yes dst-port=2221 in-interface=ether1 protocol=tcp
- add action=accept chain=forward disabled=yes dst-port=8887 in-interface=ether1 protocol=tcp
- add action=accept chain=forward disabled=yes dst-port=8888 in-interface=ether1 protocol=tcp
- add action=accept chain=forward disabled=yes dst-port=9090 in-interface=ether1 protocol=tcp
- add action=accept chain=forward disabled=yes dst-port=9998 in-interface=ether1 protocol=tcp
- add action=accept chain=forward disabled=yes dst-port=9999 in-interface=ether1 protocol=tcp
- add action=accept chain=forward disabled=yes dst-port=50000 in-interface=ether1 protocol=tcp
- add action=accept chain=forward disabled=yes dst-port=50001 in-interface=ether1 protocol=tcp
- Александр Ковалевич, [04.01.20 23:30]
- add action=accept chain=forward comment="Accept port`s WAN UDP" disabled=yes dst-port=53 in-interface=ether1 protocol=udp
- add action=accept chain=forward disabled=yes dst-port=80 in-interface=ether1 protocol=udp
- add action=accept chain=forward disabled=yes dst-port=443 in-interface=ether1 protocol=udp
- add action=accept chain=forward disabled=yes dst-port=873 in-interface=ether1 protocol=udp
- add action=accept chain=forward disabled=yes dst-port=2221 in-interface=ether1 protocol=udp
- add action=accept chain=forward disabled=yes dst-port=8000 in-interface=ether1 protocol=udp
- add action=accept chain=forward disabled=yes dst-port=8887 in-interface=ether1 protocol=udp
- add action=accept chain=forward disabled=yes dst-port=8888 in-interface=ether1 protocol=udp
- add action=accept chain=forward disabled=yes dst-port=9999 in-interface=ether1 protocol=udp
- add action=accept chain=forward disabled=yes dst-port=50000 in-interface=ether1 protocol=udp
- add action=accept chain=forward disabled=yes dst-port=50001 in-interface=ether1 protocol=udp
- add action=accept chain=forward disabled=yes dst-port=5004-5082,10000-20000 protocol=udp
- /ip firewall nat
- add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN
- add action=dst-nat chain=dstnat comment=Site dst-address=55.55.55.55 dst-port=80 protocol=tcp to-addresses=192.168.12.2
- add action=dst-nat chain=dstnat dst-address=55.55.55.55 dst-port=443 protocol=tcp to-addresses=192.168.12.2
- add action=dst-nat chain=dstnat comment=DevLine dst-address=55.55.55.55 dst-port=9786 protocol=tcp to-addresses=192.168.12.2
- add action=masquerade chain=srcnat comment="Client 1C" dst-port=9090 protocol=tcp
- add action=dst-nat chain=dstnat dst-address=55.55.55.55 dst-port=9090 protocol=tcp to-addresses=192.168.13.5
- add action=dst-nat chain=dstnat comment="DNS for DC" dst-address=55.55.55.55 dst-port=53 protocol=tcp to-addresses=192.168.13.2
- add action=masquerade chain=srcnat comment="Eset Rules" dst-address=55.55.55.55 dst-port=2221 protocol=tcp src-address=192.168.13.0/24
- add action=dst-nat chain=dstnat dst-address=55.55.55.55 dst-port=2221 protocol=tcp to-addresses=192.168.13.4
- add action=masquerade chain=srcnat comment="RDP ELENA" dst-address=55.55.55.55 dst-port=50001 protocol=tcp src-address=192.168.13.0/24
- add action=dst-nat chain=dstnat dst-address=55.55.55.55 dst-port=50001 protocol=tcp to-addresses=192.168.13.5 to-ports=3389
- add action=dst-nat chain=dstnat comment="SSH to 192.168.11.2 > 22" dst-address=55.55.55.55 dst-port=9999 protocol=tcp to-addresses=192.168.11.2 to-ports=22
- add action=masquerade chain=srcnat comment=Rsync dst-address=55.55.55.55 dst-port=873 protocol=tcp src-address=192.168.13.0/24
- add action=dst-nat chain=dstnat dst-address=55.55.55.55 dst-port=873 protocol=tcp to-addresses=192.168.13.4 to-ports=873
- add action=masquerade chain=srcnat comment="Loop To Local TCP" disabled=yes dst-address=55.55.55.55 dst-port=53 protocol=tcp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat disabled=yes dst-address=55.55.55.55 dst-port=80 protocol=tcp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat disabled=yes dst-address=55.55.55.55 dst-port=443 protocol=tcp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat disabled=yes dst-address=55.55.55.55 dst-port=8000 protocol=tcp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat disabled=yes dst-address=55.55.55.55 dst-port=9090 protocol=tcp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat comment=DevLine disabled=yes dst-address=55.55.55.55 dst-port=9786 protocol=tcp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat disabled=yes dst-address=55.55.55.55 dst-port=9999 protocol=tcp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat disabled=yes dst-address=55.55.55.55 dst-port=50000 protocol=tcp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat comment="Loop To Local UDP" disabled=yes dst-address=55.55.55.55 dst-port=53 protocol=udp src-address=192.168.1.0/24
- Александр Ковалевич, [04.01.20 23:30]
- add action=masquerade chain=srcnat disabled=yes dst-address=55.55.55.55 dst-port=80 protocol=udp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat disabled=yes dst-address=55.55.55.55 dst-port=443 protocol=udp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat disabled=yes dst-address=55.55.55.55 dst-port=873 protocol=udp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat disabled=yes dst-address=55.55.55.55 dst-port=2221 protocol=udp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat disabled=yes dst-address=55.55.55.55 dst-port=9998 protocol=udp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat disabled=yes dst-address=55.55.55.55 dst-port=9999 protocol=udp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat disabled=yes dst-address=55.55.55.55 dst-port=50000 protocol=udp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat disabled=yes dst-address=55.55.55.55 dst-port=50001 protocol=udp src-address=192.168.1.0/24
- add action=masquerade chain=srcnat disabled=yes dst-address=55.55.55.55 dst-port=5004-5082,10000-20000 protocol=udp src-address=192.168.1.0/24
- add action=dst-nat chain=dstnat disabled=yes dst-address=55.55.55.55 dst-port=5900 protocol=tcp to-addresses=192.168.100.10
- add action=dst-nat chain=dstnat disabled=yes dst-address=55.55.55.55 dst-port=8000 protocol=tcp to-addresses=192.168.1.220
- add action=dst-nat chain=dstnat comment="UAH RDP" disabled=yes dst-address=55.55.55.55 dst-port=5000 protocol=tcp to-addresses=192.168.2.2 to-ports=3389
- add action=dst-nat chain=dstnat disabled=yes dst-address=55.55.55.55 dst-port=9999 in-interface-list=WAN protocol=tcp to-addresses=192.168.1.100 to-ports=22
- add action=dst-nat chain=dstnat disabled=yes dst-address=55.55.55.55 dst-port=9998 in-interface-list=WAN protocol=tcp to-addresses=192.168.1.154 to-ports=22
- add action=dst-nat chain=dstnat disabled=yes dst-address=55.55.55.55 dst-port=50000 protocol=tcp to-addresses=192.168.1.150 to-ports=3389
- add action=dst-nat chain=dstnat comment="DST-NAT UDP" disabled=yes dst-address=55.55.55.55 dst-port=53 protocol=udp to-addresses=192.168.1.150
- add action=dst-nat chain=dstnat disabled=yes dst-address=55.55.55.55 dst-port=80 protocol=udp to-addresses=192.168.1.154
- add action=dst-nat chain=dstnat disabled=yes dst-address=55.55.55.55 dst-port=443 protocol=udp to-addresses=192.168.1.154
- add action=dst-nat chain=dstnat disabled=yes dst-address=55.55.55.55 dst-port=873 protocol=udp to-addresses=192.168.1.152 to-ports=873
- add action=dst-nat chain=dstnat disabled=yes dst-address=55.55.55.55 dst-port=2221 protocol=udp to-addresses=192.168.1.152
- add action=dst-nat chain=dstnat disabled=yes dst-address=55.55.55.55 dst-port=5060 protocol=udp to-addresses=192.168.1.100
- add action=dst-nat chain=dstnat disabled=yes dst-address=55.55.55.55 dst-port=50000 protocol=udp to-addresses=192.168.1.150 to-ports=3389
- add action=dst-nat chain=dstnat disabled=yes dst-address=55.55.55.55 dst-port=50001 protocol=udp to-addresses=192.168.1.153 to-ports=3389
- add action=dst-nat chain=dstnat disabled=yes dst-address=55.55.55.55 dst-port=5004-5082,10000-20000 protocol=udp to-addresses=192.168.1.100
- /ip firewall service-port
- set ftp disabled=yes
- set tftp disabled=yes
- set irc disabled=yes
- set h323 disabled=yes
- set sip sip-timeout=10m
- set udplite disabled=yes
- set dccp disabled=yes
- set sctp disabled=yes
- /ip route
- add distance=100 dst-address=192.168.10.0/24 gateway=PPTP-MegaService
- add distance=100 dst-address=192.168.10.0/24 gateway=L2TP-MegaService
- /ip route rule
- add action=unreachable disabled=yes dst-address=192.168.10.0/24 src-address=192.168.1.0/24
- add action=unreachable disabled=yes dst-address=192.168.1.0/24 src-address=192.168.10.0/24
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set www address=192.168.20.0/24,192.168.1.0/24
- set ssh address=192.168.20.0/24
- set api disabled=yes
- set winbox address=192.168.20.0/24,192.168.1.0/24
- set api-ssl disabled=yes
- /ip smb
- set domain=WORKGROUP
- /ppp secret
- add name=DeusEx profile=VPN
- /system clock
- set time-zone-name=Asia/Yekaterinburg
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement