Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # aug/31/2021 09:43:59 by RouterOS 6.48.3
- # software id = D34D-B33F
- #
- # model = RB760iGS
- # serial number = 8675309JiNY
- /interface bridge
- add admin-mac= auto-mac=no name=bridge vlan-filtering=yes
- /interface ethernet
- set [ find default-name=ether3 ] disabled=yes
- set [ find default-name=ether4 ] disabled=yes
- set [ find default-name=ether5 ] loop-protect=on poe-out=off
- set [ find default-name=sfp1 ] disabled=yes
- /interface vlan
- add interface=ether5 name=guest vlan-id=10
- /interface list
- add comment=defconf name=WAN
- add comment=defconf name=LAN
- add name=VLAN
- /ip dhcp-server option
- add code=6 name=dns1 value="'192.168.1.13''192.168.1.14''192.168.1.1'"
- add code=6 name=dns3 value="'192.168.1.14''192.168.1.13''192.168.1.1'"
- add code=6 name=dns2 value="'192.168.1.1'"
- add code=42 name="NTP Server" value="'192.168.1.16'"
- /ip kid-control
- add fri=6h-23h59m mon=6h-21h name=Kids sat=6h-23h thu=6h-21h tue=6h-21h \
- wed=6h-21h
- /ip pool
- add name=dhcp ranges=192.168.1.100-192.168.1.125
- add name=pool_guest ranges=192.168.10.2-192.168.10.14
- /ip dhcp-server
- add address-pool=dhcp disabled=no interface=bridge name=dhcp_lan
- add address-pool=pool_guest disabled=no interface=guest name=dhcp_guest
- /interface bridge port
- add bridge=bridge comment=defconf interface=ether2
- add bridge=bridge comment=defconf interface=ether3
- add bridge=bridge comment=defconf interface=ether4
- add bridge=bridge comment=defconf frame-types=admit-only-vlan-tagged \
- interface=ether5
- add bridge=bridge comment=defconf interface=sfp1
- /ip neighbor discovery-settings
- set discover-interface-list=LAN
- /interface bridge vlan
- add bridge=bridge comment=guest tagged=ether5 untagged=ether2,bridge \
- vlan-ids=10
- add bridge=bridge tagged=ether5 untagged=bridge,ether2 vlan-ids=1
- /interface list member
- add comment=defconf interface=bridge list=LAN
- add comment=defconf interface=ether1 list=WAN
- add interface=guest list=VLAN
- /ip address
- add address=192.168.1.1/25 interface=bridge network=192.168.1.0
- add address=192.186.10.1/28 interface=guest network=192.186.10.0
- /ip dhcp-client
- add comment=defconf disabled=no interface=ether1
- /ip dhcp-server lease
- /ip dhcp-server network
- add address=192.168.1.0/25 dhcp-option=dns dns-server=\
- 192.168.1.13,192.168.1.14,192.168.1.15 gateway=192.168.1.1 netmask=25
- add address=192.168.10.0/28 dns-server=192.168.1.13,192.168.1.14 gateway=\
- 192.168.10.1 netmask=28
- /ip dns
- set allow-remote-requests=yes
- /ip dns static
- add address=192.168.1.1 name=router.lan
- /ip firewall filter
- add action=accept chain=input comment=\
- "defconf: accept established,related,untracked" connection-state=\
- established,related,untracked
- add action=drop chain=input comment="defconf: drop invalid" connection-state=\
- invalid
- add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
- add action=drop chain=input comment="defconf: drop all not coming from LAN" \
- in-interface-list=!LAN
- add action=accept chain=forward comment="defconf: accept in ipsec policy" \
- disabled=yes ipsec-policy=in,ipsec
- add action=accept chain=forward comment="defconf: accept out ipsec policy" \
- disabled=yes ipsec-policy=out,ipsec
- add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
- connection-state=established,related
- add action=accept chain=forward comment=\
- "defconf: accept established,related, untracked" connection-state=\
- established,related,untracked
- add action=drop chain=forward comment="defconf: drop invalid" \
- connection-state=invalid
- add action=drop chain=forward comment=\
- "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
- connection-state=new in-interface-list=WAN
- /ip firewall nat
- add action=masquerade chain=srcnat comment=defcon ipsec-policy=out,none \
- out-interface-list=WAN
- /ip kid-control device
- add mac-address=C0:8C:71:A7:70:D1 name=Jubilee user=Kids
- add mac-address=24:4B:FE:8E:6A:2C name="Desktop" user=Kids
- add mac-address=58:B1:0F:BE:CD:24 name="Tablet" user=Kids
- add mac-address=B8:A1:75:DF:34:A9 name="Roku" user=Kids
- add mac-address=DC:FB:48:ED:7C:81 name="Chromebook" user=Kids
- /system clock
- set time-zone-name=
- /system identity
- set name=
- /system ntp client
- set enabled=yes primary-ntp=192.168.1.16
- /tool mac-server
- set allowed-interface-list=LAN
- /tool mac-server mac-winbox
- set allowed-interface-list=LAN
Add Comment
Please, Sign In to add comment