Hypestteam

Untitled

May 25th, 2024
72
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.42 KB | None | 0 0
  1. [admin@MikroTik] > export compact hide-sensitive
  2. # 1970-01-02 00:13:38 by RouterOS 7.12.2
  3. # software id = LDNX-UHAN
  4. #
  5. # model = L009UiGS-2HaxD
  6. # serial number = HG509N6TMYE
  7. /interface bridge
  8. add admin-mac=D4:01:C3:3A:08:E6 auto-mac=no comment=defconf name=bridge
  9. /interface wifiwave2
  10. set [ find default-name=wifi1 ] channel.band=2ghz-ax .skip-dfs-channels=\
  11. 10min-cac .width=20/40mhz configuration.mode=ap .ssid=MikroTik-3A08EE \
  12. disabled=no security.authentication-types=wpa2-psk,wpa3-psk
  13. /interface pppoe-client
  14. add add-default-route=yes disabled=no interface=ether1 name=pppoe-out1 user=\
  15. ps675742
  16. /interface list
  17. add comment=defconf name=WAN
  18. add comment=defconf name=LAN
  19. /ip pool
  20. add name=default-dhcp ranges=192.168.88.10-192.168.88.254
  21. /ip dhcp-server
  22. add address-pool=default-dhcp interface=bridge lease-time=10m name=defconf
  23. /port
  24. set 0 name=serial0
  25. /interface bridge port
  26. add bridge=bridge comment=defconf interface=ether2
  27. add bridge=bridge comment=defconf interface=ether3
  28. add bridge=bridge comment=defconf interface=ether4
  29. add bridge=bridge comment=defconf interface=ether5
  30. add bridge=bridge comment=defconf interface=ether6
  31. add bridge=bridge comment=defconf interface=ether7
  32. add bridge=bridge comment=defconf interface=ether8
  33. add bridge=bridge comment=defconf interface=sfp1
  34. add bridge=bridge comment=defconf interface=wifi1
  35. /ip neighbor discovery-settings
  36. set discover-interface-list=LAN
  37. /interface list member
  38. add comment=defconf interface=bridge list=LAN
  39. add comment=defconf interface=ether1 list=WAN
  40. /ip address
  41. add address=192.168.88.1/24 comment=defconf interface=bridge network=\
  42. 192.168.88.0
  43. /ip dhcp-client
  44. add comment=defconf interface=ether1
  45. /ip dhcp-server network
  46. add address=192.168.88.0/24 comment=defconf dns-server=192.168.88.1 gateway=\
  47. 192.168.88.1
  48. /ip dns
  49. set allow-remote-requests=yes
  50. /ip dns static
  51. add address=192.168.88.1 comment=defconf name=router.lan
  52. /ip firewall filter
  53. add action=accept chain=input comment=\
  54. "defconf: accept established,related,untracked" connection-state=\
  55. established,related,untracked
  56. add action=drop chain=input comment="defconf: drop invalid" connection-state=\
  57. invalid
  58. add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
  59. add action=accept chain=input comment=\
  60. "defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
  61. add action=drop chain=input comment="defconf: drop all not coming from LAN" \
  62. in-interface-list=!LAN
  63. add action=accept chain=forward comment="defconf: accept in ipsec policy" \
  64. ipsec-policy=in,ipsec
  65. add action=accept chain=forward comment="defconf: accept out ipsec policy" \
  66. ipsec-policy=out,ipsec
  67. add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
  68. connection-state=established,related hw-offload=yes
  69. add action=accept chain=forward comment=\
  70. "defconf: accept established,related, untracked" connection-state=\
  71. established,related,untracked
  72. add action=drop chain=forward comment="defconf: drop invalid" connection-state=\
  73. invalid
  74. add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" \
  75. connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
  76. /ip firewall nat
  77. add action=masquerade chain=srcnat
  78. /ipv6 firewall address-list
  79. add address=::/128 comment="defconf: unspecified address" list=bad_ipv6
  80. add address=::1/128 comment="defconf: lo" list=bad_ipv6
  81. add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6
  82. add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6
  83. add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6
  84. add address=100::/64 comment="defconf: discard only " list=bad_ipv6
  85. add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6
  86. add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6
  87. add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6
  88. /ipv6 firewall filter
  89. add action=accept chain=input comment=\
  90. "defconf: accept established,related,untracked" connection-state=\
  91. established,related,untracked
  92. add action=drop chain=input comment="defconf: drop invalid" connection-state=\
  93. invalid
  94. add action=accept chain=input comment="defconf: accept ICMPv6" protocol=icmpv6
  95. add action=accept chain=input comment="defconf: accept UDP traceroute" port=\
  96. 33434-33534 protocol=udp
  97. add action=accept chain=input comment=\
  98. "defconf: accept DHCPv6-Client prefix delegation." dst-port=546 protocol=\
  99. udp src-address=fe80::/10
  100. add action=accept chain=input comment="defconf: accept IKE" dst-port=500,4500 \
  101. protocol=udp
  102. add action=accept chain=input comment="defconf: accept ipsec AH" protocol=\
  103. ipsec-ah
  104. add action=accept chain=input comment="defconf: accept ipsec ESP" protocol=\
  105. ipsec-esp
  106. add action=accept chain=input comment=\
  107. "defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
  108. add action=drop chain=input comment=\
  109. "defconf: drop everything else not coming from LAN" in-interface-list=!LAN
  110. add action=accept chain=forward comment=\
  111. "defconf: accept established,related,untracked" connection-state=\
  112. established,related,untracked
  113. add action=drop chain=forward comment="defconf: drop invalid" connection-state=\
  114. invalid
  115. add action=drop chain=forward comment="defconf: drop packets with bad src ipv6" \
  116. src-address-list=bad_ipv6
  117. add action=drop chain=forward comment="defconf: drop packets with bad dst ipv6" \
  118. dst-address-list=bad_ipv6
  119. add action=drop chain=forward comment="defconf: rfc4890 drop hop-limit=1" \
  120. hop-limit=equal:1 protocol=icmpv6
  121. add action=accept chain=forward comment="defconf: accept ICMPv6" protocol=\
  122. icmpv6
  123. add action=accept chain=forward comment="defconf: accept HIP" protocol=139
  124. add action=accept chain=forward comment="defconf: accept IKE" dst-port=500,4500 \
  125. protocol=udp
  126. add action=accept chain=forward comment="defconf: accept ipsec AH" protocol=\
  127. ipsec-ah
  128. add action=accept chain=forward comment="defconf: accept ipsec ESP" protocol=\
  129. ipsec-esp
  130. add action=accept chain=forward comment=\
  131. "defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
  132. add action=drop chain=forward comment=\
  133. "defconf: drop everything else not coming from LAN" in-interface-list=!LAN
  134. /system note
  135. set show-at-login=no
  136. /system routerboard settings
  137. set enter-setup-on=delete-key
  138. /tool mac-server
  139. set allowed-interface-list=LAN
  140. /tool mac-server mac-winbox
  141. set allowed-interface-list=LAN
  142.  
Advertisement
Add Comment
Please, Sign In to add comment