Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /caps-man channel
- add band=2ghz-onlyn control-channel-width=20mhz frequency=2412,2422,2437,2452,2462 name=channel24
- add band=5ghz-onlyac control-channel-width=20mhz frequency=5180,5200,5240 name=channel5
- /interface wireless
- # managed by CAPsMAN
- # channel: 2412/20-Ce/gn(17dBm), SSID: home_wifi, CAPsMAN forwarding
- set [ find default-name=wlan1 ] ssid=MikroTik station-roaming=enabled
- # managed by CAPsMAN
- # channel: 5180/20-Ceee/ac/P(17dBm), SSID: home_wifi, CAPsMAN forwarding
- set [ find default-name=wlan2 ] ssid=MikroTik station-roaming=enabled
- /interface bridge
- add igmp-snooping=yes name=bridge1 protocol-mode=none
- /interface ethernet
- set [ find default-name=ether1 ] comment=WAN
- set [ find default-name=ether2 ] comment=Ajax
- set [ find default-name=ether3 ] comment=TV
- /caps-man datapath
- add bridge=bridge1 name=datapath1
- /caps-man security
- add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm group-key-update=1h name=security1
- /caps-man configuration
- add channel=channel24 country=ukraine datapath=datapath1 distance=indoors hw-protection-mode=rts-cts hw-retries=7 installation=indoor \
- keepalive-frames=enabled mode=ap multicast-helper=full name=cfg24 rx-chains=0,1,2,3 security=security1 ssid=home_wifi tx-chains=0,1,2,3
- add channel=channel5 country=ukraine datapath=datapath1 distance=indoors hw-protection-mode=rts-cts hw-retries=7 installation=indoor \
- keepalive-frames=enabled mode=ap multicast-helper=full name=cfg5 rx-chains=0,1,2,3 security=security1 ssid=home_wifi tx-chains=0,1,2,3
- /caps-man interface
- add configuration=cfg5 disabled=no l2mtu=1600 mac-address=48:8F:5A:E7:BA:49 master-interface=none name=cap3 radio-mac=48:8F:5A:E7:BA:49 \
- radio-name=488F5AE7BA49
- add configuration=cfg24 disabled=no l2mtu=1600 mac-address=48:8F:5A:E7:BA:48 master-interface=none name=cap4 radio-mac=48:8F:5A:E7:BA:48 \
- radio-name=488F5AE7BA48
- add configuration=cfg5 disabled=no l2mtu=1600 mac-address=48:8F:5A:6F:D7:1D master-interface=none name=cap5 radio-mac=48:8F:5A:6F:D7:1D \
- radio-name=488F5A6FD71D
- add configuration=cfg24 disabled=no l2mtu=1600 mac-address=48:8F:5A:6F:D7:1C master-interface=none name=cap6 radio-mac=48:8F:5A:6F:D7:1C \
- radio-name=488F5A6FD71C
- add configuration=cfg24 disabled=no l2mtu=1600 mac-address=48:8F:5A:78:37:E2 master-interface=none name=cap7 radio-mac=48:8F:5A:78:37:E2 \
- radio-name=488F5A7837E2
- add configuration=cfg5 disabled=no l2mtu=1600 mac-address=48:8F:5A:78:37:E3 master-interface=none name=cap8 radio-mac=48:8F:5A:78:37:E3 \
- radio-name=488F5A7837E3
- /interface list
- add name=WAN_Interface
- /interface wireless security-profiles
- set [ find default=yes ] supplicant-identity=MikroTik
- /ip hotspot profile
- set [ find default=yes ] html-directory=flash/hotspot
- /ip pool
- add name=dhcp_pool0 ranges=192.168.9.21-192.168.9.254
- /ip dhcp-server
- add address-pool=dhcp_pool0 disabled=no interface=bridge1 lease-time=1d name=dhcp1
- /ppp profile
- set *FFFFFFFE bridge=bridge1 local-address=dhcp_pool0 remote-address=dhcp_pool0
- /tool user-manager customer
- set admin access=own-routers,own-users,own-profiles,own-limits,config-payment-gw
- /user group
- set full policy=local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,password,web,sniff,sensitive,api,romon,dude,tikapp
- /caps-man manager
- set enabled=yes
- /caps-man provisioning
- add action=create-enabled hw-supported-modes=gn master-configuration=cfg24
- add action=create-enabled hw-supported-modes=ac master-configuration=cfg5
- /interface bridge port
- add bridge=bridge1 interface=ether2
- add bridge=bridge1 interface=ether3
- add bridge=bridge1 interface=ether4
- add bridge=bridge1 interface=ether5
- add bridge=bridge1 disabled=yes interface=wlan1
- add bridge=bridge1 disabled=yes interface=wlan2
- add bridge=bridge1 interface=eoip-tunnel1_office
- /ip neighbor discovery-settings
- set discover-interface-list=!dynamic
- /interface l2tp-server server
- set allow-fast-path=yes authentication=mschap2 enabled=yes one-session-per-host=yes use-ipsec=yes
- /interface list member
- add interface=ether1 list=WAN_Interface
- /interface wireless cap
- #
- set bridge=bridge1 caps-man-addresses=192.168.9.1 enabled=yes interfaces=wlan1,wlan2
- /ip address
- add address=192.168.9.1/24 interface=bridge1 network=192.168.9.0
- /ip cloud
- set ddns-enabled=yes
- /ip dhcp-client
- add disabled=no interface=ether1
- /ip dhcp-server lease
- add address=192.168.9.2 client-id=1:48:8f:5a:6f:d7:1a mac-address=48:8F:5A:6F:D7:1A server=dhcp1
- /ip dhcp-server network
- add address=192.168.9.0/24 dns-server=1.0.0.1,8.8.8.8 gateway=192.168.9.1
- /ip dns
- set allow-remote-requests=yes
- /ip firewall address-list
- add address=xxxxxxxxxx list=My_DNS
- add address= xxxxxxxxxx list=My_DNS
- add address= xxxxxxxxxx list=Input_Access
- add address= xxxxxxxxxx list=Input_Access
- add address= xxxxxxxxxx list=Input_Access
- add address= xxxxxxxxxx list=Input_Access
- /ip firewall filter
- add action=accept chain=forward comment="Accept Established+Related WAN-LAN" connection-state=established,related disabled=yes \
- in-interface-list=WAN_Interface
- add action=drop chain=input comment=Drop_DNS_WAN disabled=yes dst-port=53 in-interface-list=WAN_Interface protocol=tcp src-address-list=\
- !My_DNS
- add action=drop chain=input comment=Drop_DNS_WAN disabled=yes dst-port=53 in-interface-list=WAN_Interface protocol=udp src-address-list=\
- !My_DNS
- add action=drop chain=forward comment="DROP Invalid" connection-state=invalid disabled=yes
- add action=add-src-to-address-list address-list=portscan address-list-timeout=1d chain=input comment=\
- "\C4\EE\E1\E0\E2\EB\FF\E5\EC \F1\EA\E0\ED\E5\F0 \EF\EE\F0\F2\EE\E2 \E2 \F1\EF\E8\F1\EE\EA" disabled=yes in-interface-list=WAN_Interface \
- protocol=tcp psd=21,3s,3,1
- add action=add-src-to-address-list address-list=spammer address-list-timeout=1d chain=forward comment=\
- "\C4\EE\E1\E0\E2\EB\E5\ED\E8\E5\E2 \F1\EF\E8\F1\EE\EA \B3\F0-\E0\E4\F0\E5\F1\EE\E2 email-\F1\EF\E0\EC\EC\E5\F0\EE\E2" connection-limit=\
- 50,32 disabled=yes dst-port=25,587,465 limit=10,30:packet protocol=tcp
- add action=drop chain=input comment="\C1\EB\EE\EA\E8\F0\EE\E2\E0\ED\E8\E5 \F1\EA\E0\ED\E5\F0\EE\E2 \EF\EE\F0\F2\EE\E2" disabled=yes \
- in-interface-list=WAN_Interface src-address-list=portscan
- add action=drop chain=forward comment="\C1\EB\EE\EA\E8\F0\EE\E2\E0\ED\E8\E5 email-\F1\EF\E0\EC\E5\F0\EE\E2" disabled=yes dst-port=\
- 25,587,465 protocol=tcp src-address-list=spammer
- add action=accept chain=input comment="NTP port" disabled=yes dst-port=123 protocol=udp
- add action=accept chain=input comment="Accept Ping_WAN" connection-limit=5,32 disabled=yes in-interface-list=WAN_Interface limit=1,5:packet \
- protocol=icmp
- add action=accept chain=input comment=Access_Router disabled=yes dst-port=8291,81 protocol=tcp src-address-list=Input_Access
- add action=drop chain=input comment=DROP_ALL disabled=yes log-prefix=no_access/drop protocol=tcp src-address-list=!Input_Access
- /ip firewall nat
- add action=masquerade chain=srcnat out-interface=ether1
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set www address=192.168.9.0/24 port=81
- set ssh disabled=yes
- set api disabled=yes
- set api-ssl disabled=yes
- /ppp secret
- add name=uzhnet profile=default-encryption service=l2tp
- /system clock
- set time-zone-name=Europe/Kiev
- /system identity
- set name=ac2_Uzhnet_user
- /system ntp client
- set enabled=yes primary-ntp=10.0.0.1
- /system ntp server
- set broadcast=yes enabled=yes multicast=yes
- /tool graphing interface
- add
- /tool graphing queue
- add
- /tool graphing resource
- add
- /tool user-manager database
- set db-path=flash/user-manager
Advertisement
Add Comment
Please, Sign In to add comment