Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # 2025-04-06 03:45:06 by RouterOS 7.17
- # system id = s+UXm/vUeeG
- #
- /interface bridge
- add name=bridge1
- /interface ethernet
- set [ find default-name=ether1 ] disable-running-check=no name=ether3
- set [ find default-name=ether2 ] disable-running-check=no name=ether4
- /interface wireguard
- add listen-port=[port] mtu=1420 name="ID CHR(S) --> US SF CHR"
- add listen-port=[port] mtu=1400 name="SG CHR(S) --> US SF CHR"
- add listen-port=[port] mtu=1420 name="US SF CHR(S) --> DE CHR"
- add listen-port=[port] mtu=1420 name="US SF CHR(S) --> L009"
- add listen-port=[port] mtu=1420 name="US SF CHR(S) --> RB3011"
- add listen-port=[port] mtu=1420 name="US SF CHR(S) --> RB5009"
- add listen-port=[port] mtu=1420 name="US SF CHR(S) --> PC"
- add listen-port=[port] mtu=1420 name="US SF CHR(S) --> US NY CHR"
- /ip smb users
- set [ find default=yes ] disabled=yes
- /port
- set 0 name=serial0
- /ip firewall connection tracking
- set udp-timeout=10s
- /interface ovpn-server server
- add mac-address=FE:75:55:58:D0:F6 name=ovpn-server1
- /interface wireguard peers
- add allowed-address=172.25.110.2/32,0.0.0.0/0,::/0 interface="US SF CHR(S) --> ID RB3011" name="RB3011" \
- persistent-keepalive=15s public-key="[key]"
- add allowed-address=172.22.110.4/32,0.0.0.0/0,::/0 interface="US SF CHR(S) --> ID RB5009" name="RB5009" \
- public-key="[key]"
- add allowed-address=172.25.100.3/32,0.0.0.0/0,::/0 endpoint-address=[ip addr] endpoint-port=32002 \
- interface="SG CHR(S) --> US SF CHR" name="SG CHR" persistent-keepalive=15s public-key=\
- "[key]"
- add allowed-address=172.25.110.8/32,0.0.0.0/0,::/0 endpoint-address=[ip addr] endpoint-port=32101 \
- interface="US SF CHR(S) --> DE CHR" name="DE CHR" persistent-keepalive=15s public-key=\
- "[key]"
- add allowed-address=172.25.110.10/32,0.0.0.0/0,::/0 endpoint-address=[ip addr] endpoint-port=32103 \
- interface="US SF CHR(S) --> US NY CHR" name="NY CHR" persistent-keepalive=15s public-key=\
- "[key]"
- add allowed-address=172.25.150.5/32,0.0.0.0/0,::/0 endpoint-address=[ip addr] endpoint-port=32505 \
- interface="ID CHR(S) --> US SF CHR" name="ID CHR" persistent-keepalive=15s public-key=\
- "[key]"
- add allowed-address=::/0,0.0.0.0/0,172.22.110.20/32 interface="US SF CHR(S) --> PC" name=PC \
- public-key="[key]"
- add allowed-address=::/0,0.0.0.0/0,172.25.110.6/32 interface="US SF CHR(S) --> L009" name="L009 GS" \
- persistent-keepalive=15s public-key="[key]"
- /ip address
- add address=172.25.100.4 interface="SG CHR(S) --> US SF CHR" network=172.25.100.3
- add address=172.25.110.5 interface="US SF CHR(S) --> L009" network=172.25.110.6
- add address=172.22.110.3 interface="US SF CHR(S) --> RB5009" network=172.22.110.4
- add address=172.25.110.7 interface="US SF CHR(S) --> DE CHR" network=172.25.110.8
- add address=172.25.110.9 interface="US SF CHR(S) --> US NY CHR" network=172.25.110.10
- add address=172.25.150.6 interface="ID CHR(S) --> US SF CHR" network=172.25.150.5
- add address=172.22.110.19 interface="US SF CHR(S) --> PC" network=172.22.110.20
- /ip dhcp-client
- add interface=ether3
- /ip dns
- set servers=1.1.1.1,8.8.8.8
- /ip firewall filter
- add action=accept chain=input comment="WinBox Wan Administration" disabled=yes dst-port=8291 protocol=tcp
- /ip firewall mangle
- add action=change-mss chain=forward in-interface="US SF CHR(S) --> RB5009" new-mss=1380 protocol=tcp \
- tcp-flags=syn tcp-mss=1381-65535
- /ip firewall nat
- add action=dst-nat chain=dstnat dst-address=[ip addr] dst-port=7050 protocol=tcp to-addresses=\
- 10.3.0.10 to-ports=7050
- add action=dst-nat chain=dstnat dst-address=[ip addr] dst-port=7050 protocol=udp to-addresses=\
- 10.3.0.10 to-ports=7050
- add action=masquerade chain=srcnat out-interface="US SF CHR(S) --> DE CHR"
- add action=masquerade chain=srcnat out-interface="ID CHR(S) --> US SF CHR"
- add action=masquerade chain=srcnat out-interface="US SF CHR(S) --> L009"
- add action=masquerade chain=srcnat out-interface="US SF CHR(S) --> US NY CHR"
- add action=masquerade chain=srcnat out-interface="US SF CHR(S) --> RB3011"
- add action=masquerade chain=srcnat out-interface="US SF CHR(S) --> RB5009"
- add action=masquerade chain=srcnat out-interface="US SF CHR(S) --> PC"
- add action=masquerade chain=srcnat out-interface="SG CHR(S) --> US SF CHR"
- add action=dst-nat chain=dstnat dst-address=[ip addr] dst-port=25590 protocol=tcp to-addresses=\
- 10.0.0.16 to-ports=25590
- add action=dst-nat chain=dstnat disabled=yes dst-address=[ip addr] dst-port=25598 protocol=tcp \
- to-addresses=10.100.63.251 to-ports=25590
- add action=dst-nat chain=dstnat disabled=yes dst-address=[ip addr] dst-port=25595 protocol=tcp \
- to-addresses=10.0.15.192 to-ports=25590
- add action=dst-nat chain=dstnat dst-address=[ip addr] dst-port=25596 protocol=tcp to-addresses=\
- 10.0.0.102 to-ports=25590
- add action=dst-nat chain=dstnat disabled=yes dst-address=[ip addr] dst-port=25596 protocol=udp \
- to-addresses=10.0.0.102 to-ports=25565
- add action=dst-nat chain=dstnat comment="UNIFI INFORM (UDP)" dst-address=[ip addr] dst-port=8080 \
- protocol=udp to-addresses=10.0.0.9 to-ports=8080
- add action=dst-nat chain=dstnat comment="UNIFI STUN (UDP)" dst-address=[ip addr] dst-port=3478 \
- protocol=udp to-addresses=10.0.0.9 to-ports=3478
- add action=dst-nat chain=dstnat comment="UNIFI STUN (TCP)" dst-address=[ip addr] dst-port=3478 \
- protocol=tcp to-addresses=10.0.0.9 to-ports=3478
- add action=dst-nat chain=dstnat comment="UNIFI WEB (TCP)" disabled=yes dst-address=[ip addr] dst-port=\
- 8443 protocol=tcp to-addresses=10.0.0.9 to-ports=8443
- add action=dst-nat chain=dstnat disabled=yes dst-address=[ip addr] dst-port=54500 protocol=tcp \
- to-addresses=10.0.0.16 to-ports=3000
- add action=dst-nat chain=dstnat comment="UNIFI INFORM (TCP)" dst-address=[ip addr] dst-port=8080 \
- protocol=tcp to-addresses=10.0.0.9 to-ports=8080
- add action=dst-nat chain=dstnat dst-address=[ip addr] dst-port=25590 protocol=udp to-addresses=\
- 10.0.0.16 to-ports=25590
- add action=dst-nat chain=dstnat dst-address=[ip addr] dst-port=25595 protocol=udp to-addresses=\
- 10.0.0.102 to-ports=25590
- /ip ipsec profile
- set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5
- /ip route
- add disabled=no distance=1 dst-address=10.0.0.0/16 gateway=172.25.100.3 pref-src="" routing-table=main \
- scope=30 suppress-hw-offload=no target-scope=10
- add disabled=no distance=2 dst-address=10.100.0.0/16 gateway=172.22.110.4 pref-src="" routing-table=main \
- scope=30 suppress-hw-offload=no target-scope=10
- add disabled=no distance=2 dst-address=10.0.0.0/16 gateway=172.25.110.2 pref-src="" routing-table=main \
- scope=30 suppress-hw-offload=no target-scope=10
- add disabled=no dst-address=[ip addr] gateway=172.25.110.8 routing-table=main suppress-hw-offload=no
- add disabled=yes distance=1 dst-address=10.100.0.0/16 gateway=172.25.100.3 pref-src="" routing-table=main \
- scope=30 suppress-hw-offload=no target-scope=10
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set www disabled=yes
- set ssh address=[ip addr]
- set api disabled=yes
- set winbox address=[ip addr] port=8450
- set api-ssl disabled=yes
- /ip smb shares
- set [ find default=yes ] directory=/pub
- /system clock
- set time-zone-autodetect=no time-zone-name=Asia/Bangkok
- /system identity
- set name="US SF CHR"
- /system note
- set show-at-login=no
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement