Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # jan/15/1970 16:53:12 by RouterOS 6.7
- # software id = IARM-1MHS
- #
- /interface bridge
- add l2mtu=1598 name=LAN-bridge
- add l2mtu=1598 name=LAN2-bridge
- add l2mtu=1598 name=LAN3-bridge
- /interface ethernet
- set [ find default-name=ether1 ] name=ether1-UPLINK
- set [ find default-name=ether2 ] name=ether2-LAN
- set [ find default-name=ether3 ] name=ether3-LAN2
- set [ find default-name=ether4 ] name=ether4-LAN3
- set [ find default-name=ether5 ] disabled=yes name=ether5-slave-local
- /interface wireless
- set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=\
- 20/40mhz-ht-above distance=indoors l2mtu=2290 mode=ap-bridge ssid=\
- MikroTik-5C1F85
- /ip neighbor discovery
- set ether1-UPLINK discover=no
- /ip hotspot user profile
- set [ find default=yes ] idle-timeout=none keepalive-timeout=2m \
- mac-cookie-timeout=3d
- /ip pool
- add name=default-dhcp ranges=192.168.88.10-192.168.88.254
- add name=lan ranges=192.168.10.2-192.168.10.254
- add name=lan2 ranges=192.168.2.10-192.168.2.254
- add name=lan3 ranges=192.168.3.10-192.168.3.254
- /ip dhcp-server
- add address-pool=default-dhcp disabled=no lease-time=10m name=default
- add address-pool=lan disabled=no interface=LAN-bridge lease-time=1w name=LAN
- add address-pool=lan2 disabled=no interface=LAN2-bridge lease-time=1w name=\
- LAN2
- add address-pool=lan3 disabled=no interface=LAN3-bridge lease-time=1w name=\
- LAN3
- /interface bridge port
- add bridge=LAN-bridge interface=ether2-LAN
- add bridge=LAN-bridge interface=wlan1
- add bridge=LAN2-bridge interface=ether3-LAN2
- add bridge=LAN3-bridge interface=ether4-LAN3
- /interface bridge settings
- set use-ip-firewall=yes
- /ip address
- add address=192.168.88.1/24 comment="default configuration" disabled=yes \
- network=192.168.88.0
- add address=192.168.10.1/24 interface=LAN-bridge network=192.168.10.0
- add address=192.168.2.1/24 interface=LAN2-bridge network=192.168.2.0
- add address=192.168.3.1/24 interface=LAN3-bridge network=192.168.3.0
- /ip dhcp-client
- add comment="default configuration" dhcp-options=hostname,clientid disabled=\
- no interface=ether1-UPLINK
- /ip dhcp-server network
- add address=192.168.2.0/24 comment=lan2 dns-server=8.8.8.8 gateway=\
- 192.168.2.1 netmask=24
- add address=192.168.3.0/24 comment=lan3 dns-server=8.8.8.8 gateway=\
- 192.168.3.1 netmask=24
- add address=192.168.10.0/24 comment=lan dns-server=8.8.8.8 gateway=\
- 192.168.10.1 netmask=24
- add address=192.168.88.0/24 comment="default configuration" dns-server=\
- 192.168.88.1 gateway=192.168.88.1
- /ip dns
- set allow-remote-requests=yes
- /ip dns static
- add address=192.168.88.1 name=router
- /ip firewall address-list
- add address=xxxxxx list=SAFE
- add address=xxxxxx list=SAFE
- /ip firewall filter
- add chain=input comment="Mtik access" dst-port=8291 protocol=tcp \
- src-address-type=""
- add chain=input comment="Allow Ping" protocol=icmp
- add chain=input comment="default configuration" connection-state=established \
- disabled=yes
- add chain=input comment="default configuration" connection-state=related \
- disabled=yes
- add chain=forward comment="default configuration" connection-state=related \
- disabled=yes
- add chain=forward comment="default configuration" connection-state=\
- established disabled=yes
- add action=drop chain=forward comment="default configuration" \
- connection-state=invalid
- add action=drop chain=input comment="default configuration" in-interface=\
- ether1-UPLINK
- /ip firewall nat
- add action=dst-nat chain=dstnat disabled=yes dst-address=xxxxxx \
- dst-port=8291 protocol=tcp to-addresses=192.168.10.1 to-ports=8291
- add action=masquerade chain=srcnat out-interface=ether1-UPLINK src-address=\
- 192.168.10.0/24
- add action=masquerade chain=srcnat comment="default configuration" disabled=\
- yes out-interface=ether1-UPLINK
- add action=masquerade chain=srcnat src-address=192.168.2.0/24
- add action=masquerade chain=srcnat src-address=192.168.3.0/24 to-addresses=\
- 0.0.0.0
- /ip service
- set winbox address=0.0.0.0/0
- /system leds
- set 0 interface=wlan1
- /tool mac-server
- set [ find default=yes ] disabled=yes
- add interface=ether2-LAN
- add interface=ether3-LAN2
- add interface=ether4-LAN3
- add interface=ether5-slave-local
- add interface=wlan1
- add
- /tool mac-server mac-winbox
- set [ find default=yes ] disabled=yes
- add interface=ether2-LAN
- add interface=ether3-LAN2
- add interface=ether4-LAN3
- add interface=ether5-slave-local
- add interface=wlan1
- add
- /tool sniffer
- set filter-interface=ether1-UPLINK
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement