Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # jul/11/2016 10:13:27 by RouterOS 6.34.6
- # software id = UPA0-2NBC
- #
- /interface ethernet
- set [ find default-name=ether1 ] comment="Wan ISP1"
- set [ find default-name=ether2 ] comment=Local
- /ip neighbor discovery
- set ether1 comment="Wan ISP1" discover=no
- set ether2 comment=Local
- /interface vlan
- add comment="\D3\EF\F0\E0\E2\EB\E5\ED\E8\E5 \F3\F1\F2\F0\EE\E9\F1\F2\E2\E0\EC\
- \E8 \E2 \F1\E5\F2\E8 (\EA\EE\EC\EC\F3\F2\E0\F2\EE\F0\FB)" interface=\
- ether2 name=ManagementVlan2 vlan-id=2
- add comment="\D0\E5\F1\F2\EE\F0\E0\ED Dublin" interface=ether2 name=\
- RestoranDublinVlan5 vlan-id=5
- add comment="\D0\E5\F1\F2\EE\F0\E0\ED London" interface=ether2 name=\
- RestoranLondonVlan6 vlan-id=6
- add comment="\D1\E5\F2\FC \E4\EB\FF \F1\E5\F0\E2\E5\F0\EE\E2" interface=\
- ether2 name=ServersVlan3 vlan-id=3
- add comment="\DD\F2\E0\E6 1" interface=ether2 name=Stage1Vlan10 vlan-id=10
- add comment="\DD\F2\E0\E6 2" interface=ether2 name=Stage2Vlan20 vlan-id=20
- add comment="\DD\F2\E0\E6 3" interface=ether2 name=Stage3Vlan30 vlan-id=30
- add comment="\DD\F2\E0\E6 4 " interface=ether2 name=Stage4Vlan40 vlan-id=40
- add comment="\CF\E5\F0\F1\EE\ED\E0\EB \E3\EE\F1\F2\E8\ED\E8\F6\FB" interface=\
- ether2 name=Teh.PersonalVlan9 vlan-id=9
- add comment="\CD\E5 \EE\E3\F0\E0\ED\E8\F7\E5\ED\ED\E0\FF \F1\E5\F2\FC \E4\EB\
- \FF \F0\F3\EA-\E2\E0" interface=ether2 name=UnlimitedSpeedVlan7 vlan-id=7
- add comment=\
- "\D1\E5\F2\FC \E4\EB\FF \E2\E8\E4\E5\EE\ED\E0\E1\EB\FE\E4\E5\ED\E8\FF" \
- interface=ether2 name=VideoVlan4 vlan-id=4
- /ip neighbor discovery
- set ManagementVlan2 comment="\D3\EF\F0\E0\E2\EB\E5\ED\E8\E5 \F3\F1\F2\F0\EE\E9\
- \F1\F2\E2\E0\EC\E8 \E2 \F1\E5\F2\E8 (\EA\EE\EC\EC\F3\F2\E0\F2\EE\F0\FB)"
- set RestoranDublinVlan5 comment="\D0\E5\F1\F2\EE\F0\E0\ED Dublin" discover=no
- set RestoranLondonVlan6 comment="\D0\E5\F1\F2\EE\F0\E0\ED London" discover=no
- set ServersVlan3 comment="\D1\E5\F2\FC \E4\EB\FF \F1\E5\F0\E2\E5\F0\EE\E2"
- set Stage1Vlan10 comment="\DD\F2\E0\E6 1" discover=no
- set Stage2Vlan20 comment="\DD\F2\E0\E6 2" discover=no
- set Stage3Vlan30 comment="\DD\F2\E0\E6 3" discover=no
- set Stage4Vlan40 comment="\DD\F2\E0\E6 4 " discover=no
- set Teh.PersonalVlan9 comment=\
- "\CF\E5\F0\F1\EE\ED\E0\EB \E3\EE\F1\F2\E8\ED\E8\F6\FB"
- set UnlimitedSpeedVlan7 comment="\CD\E5 \EE\E3\F0\E0\ED\E8\F7\E5\ED\ED\E0\FF \
- \F1\E5\F2\FC \E4\EB\FF \F0\F3\EA-\E2\E0" discover=no
- set VideoVlan4 comment=\
- "\D1\E5\F2\FC \E4\EB\FF \E2\E8\E4\E5\EE\ED\E0\E1\EB\FE\E4\E5\ED\E8\FF" \
- discover=no
- /ip pool
- add name=poolVlan3 ranges=172.16.3.30-172.16.3.254
- add name=poolVlan9 ranges=172.16.9.30-172.16.9.254
- add name=poolVlan10 ranges=172.16.10.30-172.16.10.254
- add name=poolVan20 ranges=172.16.20.30-172.16.20.254
- add name=poolVlan30 ranges=172.16.30.30-172.16.30.254
- add name=poolVlan40 ranges=172.16.40.30-172.16.40.254
- add name=poolVlan2 ranges=172.16.1.30-172.16.1.254
- add name=poolVlan4 ranges=172.16.4.30-172.16.4.254
- add name=poolVlan5 ranges=172.16.5.30-172.16.5.254
- add name=poolVlan6 ranges=172.16.6.30-172.16.6.254
- add name=poolVlan7 ranges=172.16.7.30-172.16.7.254
- /ip dhcp-server
- add add-arp=yes address-pool=poolVlan2 authoritative=yes disabled=no \
- interface=ManagementVlan2 name=ServerdhcpVlan2
- add add-arp=yes address-pool=poolVlan3 authoritative=yes disabled=no \
- interface=ServersVlan3 name=ServerdhcpVlan3
- add add-arp=yes address-pool=poolVlan9 authoritative=yes disabled=no \
- interface=Teh.PersonalVlan9 name=ServerdhcpVlan9
- add add-arp=yes address-pool=poolVlan10 authoritative=yes disabled=no \
- interface=Stage1Vlan10 name=ServerdhcpVlan10
- add add-arp=yes address-pool=poolVlan40 authoritative=yes disabled=no \
- interface=Stage4Vlan40 name=ServerdhcpVlan40
- add add-arp=yes address-pool=poolVlan30 authoritative=yes disabled=no \
- interface=Stage3Vlan30 name=ServerdhcpVlan30
- add add-arp=yes address-pool=poolVan20 authoritative=yes disabled=no \
- interface=Stage2Vlan20 name=ServerdhcpVlan20
- add add-arp=yes address-pool=poolVlan4 authoritative=yes disabled=no \
- interface=VideoVlan4 name=ServerdhcpVlan4
- add add-arp=yes address-pool=poolVlan5 authoritative=yes disabled=no \
- interface=RestoranDublinVlan5 name=ServerdhcpVlan5
- add add-arp=yes address-pool=poolVlan6 authoritative=yes disabled=no \
- interface=RestoranLondonVlan6 name=ServerdhcpVlan6
- add add-arp=yes address-pool=poolVlan7 authoritative=yes disabled=no \
- interface=UnlimitedSpeedVlan7 name=ServerdhcpVlan7
- /queue simple
- add burst-threshold=512k/512k burst-time=30s/30s comment="\CE\E3\F0\E0\ED\E8\
- \F7\E5\ED\E8\E5 \F1\EA\EE\F0\EE\F1\F2\E8 \ED\E0 512 Kbit/s \FD\F2\E0\E6 1" \
- max-limit=512k/512k name="UpLoad\\downloadVlan10" target=Stage1Vlan10
- add burst-threshold=512k/512k burst-time=30s/30s comment="\CE\E3\F0\E0\ED\E8\
- \F7\E5\ED\E8\E5 \F1\EA\EE\F0\EE\F1\F2\E8 \ED\E0 512 Kbit/s \FD\F2\E0\E6 2" \
- max-limit=512k/512k name="UpLoad\\downloadVlan20" target=Stage2Vlan20
- add burst-threshold=512k/512k burst-time=30s/30s comment="\CE\E3\F0\E0\ED\E8\
- \F7\E5\ED\E8\E5 \F1\EA\EE\F0\EE\F1\F2\E8 \ED\E0 512 Kbit/s \FD\F2\E0\E6 3" \
- max-limit=512k/512k name="UpLoad\\downloadVlan30" target=Stage3Vlan30
- add burst-threshold=512k/512k burst-time=30s/30s comment="\CE\E3\F0\E0\ED\E8\
- \F7\E5\ED\E8\E5 \F1\EA\EE\F0\EE\F1\F2\E8 \ED\E0 512 Kbit/s \FD\F2\E0\E6 4" \
- max-limit=512k/512k name="UpLoad\\downloadVlan40" target=Stage4Vlan40
- add burst-threshold=512k/512k burst-time=30s/30s comment="\CE\E3\F0\E0\ED\E8\
- \F7\E5\ED\E8\E5 \F1\EA\EE\F0\EE\F1\F2\E8 \ED\E0 512 Kbit/s \F1\E5\F2\FC \
- \EF\E5\F0\F1\EE\ED\E0\EB\E0" max-limit=512k/512k name=\
- "UpLoad\\downloadVlan9" target=Teh.PersonalVlan9
- add burst-threshold=512k/512k burst-time=30s/30s comment="\CE\E3\F0\E0\ED\E8\
- \F7\E5\ED\E8\E5 \F1\EA\EE\F0\EE\F1\F2\E8 \ED\E0 512 Kbit/s \F0\E5\F1\F2\EE\
- \F0\E0\ED Dublin" max-limit=512k/512k name="Upload\\downloadVlan5" \
- target=RestoranDublinVlan5
- add burst-threshold=512k/512k burst-time=30s/30s comment="\CE\E3\F0\E0\ED\E8\
- \F7\E5\ED\E8\E5 \F1\EA\EE\F0\EE\F1\F2\E8 \ED\E0 512 Kbit/s \F0\E5\F1\F2\EE\
- \F0\E0\ED London" max-limit=512k/512k name="UpLoad\\downloadVlan6" \
- target=RestoranLondonVlan6
- /tool user-manager customer
- set admin access=\
- own-routers,own-users,own-profiles,own-limits,config-payment-gw
- /interface pptp-server server
- set enabled=yes
- /ip address
- add address=172.16.1.1/24 comment="\D1\E5\F2\FC \F3\EF\F0\E0\E2\EB\E5\ED\E8\FF\
- \_\F3\F1\F2\F0\EE\E9\F1\F2\E2\E0\EC\E8" interface=ManagementVlan2 \
- network=172.16.1.0
- add address=172.16.9.1/24 comment="\D1\E5\F2\FC \E4\EB\FF \EF\E5\F0\F1\EE\ED\
- \E0\EB\E0 \E3\EE\F1\F2\E8\ED\E8\F6\FB" interface=Teh.PersonalVlan9 \
- network=172.16.9.0
- add address=172.16.10.1/24 comment="\DD\F2\E0\E6 1" interface=Stage1Vlan10 \
- network=172.16.10.0
- add address=172.16.20.1/24 comment="\DD\F2\E0\E6 2" interface=Stage2Vlan20 \
- network=172.16.20.0
- add address=172.16.30.1/24 comment="\DD\F2\E0\E6 3" interface=Stage3Vlan30 \
- network=172.16.30.0
- add address=172.16.40.1/24 comment="\DD\F2\E0\E6 4" interface=Stage4Vlan40 \
- network=172.16.40.0
- add address=172.16.3.1/24 comment=\
- "\D1\E5\F2\FC \E4\EB\FF \F1\E5\F0\E2\E5\F0\EE\E2" interface=ServersVlan3 \
- network=172.16.3.0
- add address=172.16.4.1/24 comment=\
- "\D1\E5\F2\FC \E2\E8\E4\E5\EE\ED\E0\E1\EB\FE\E4\E5\ED\E8\FF" interface=\
- VideoVlan4 network=172.16.4.0
- add address=172.16.5.1/24 comment="\D0\E5\F1\F2\EE\F0\E0\ED Dublin" \
- interface=RestoranDublinVlan5 network=172.16.5.0
- add address=172.16.6.1/24 comment="\D0\E5\F1\F2\EE\F0\E0\ED London" \
- interface=RestoranLondonVlan6 network=172.16.6.0
- add address=172.16.7.1/24 comment="\D1\E5\F2\FC \F1 \ED\E5\EE\E3\F0\E0\ED\E8\
- \F7\E5\ED\ED\EE\E9 \F1\EA\EE\F0\EE\F1\F2\FC\FE \E4\EB\FF \F0\F3\EA-\E2\E0" \
- interface=UnlimitedSpeedVlan7 network=172.16.7.0
- /ip dhcp-client
- add default-route-distance=0 dhcp-options=hostname,clientid disabled=no \
- interface=ether1
- /ip dhcp-server network
- add address=172.16.1.0/24 dns-server=172.16.1.1 gateway=172.16.1.1
- add address=172.16.3.0/24 dns-server=172.16.3.1 gateway=172.16.3.1
- add address=172.16.4.0/24 dns-server=172.16.4.1 gateway=172.16.4.1
- add address=172.16.5.0/24 dns-server=172.16.5.1 gateway=172.16.5.1
- add address=172.16.6.0/24 dns-server=172.16.6.1 gateway=172.16.6.1
- add address=172.16.7.0/24 dns-server=172.16.7.1 gateway=172.16.7.1
- add address=172.16.9.0/24 dns-server=172.16.9.1 gateway=172.16.9.1
- add address=172.16.10.0/24 dns-server=172.16.10.1 gateway=172.16.10.1
- add address=172.16.20.0/24 dns-server=172.16.20.1 gateway=172.16.20.1
- add address=172.16.30.0/24 dns-server=172.16.30.1 gateway=172.16.30.1
- add address=172.16.40.0/24 dns-server=172.16.40.1 gateway=172.16.40.1
- /ip dns
- set allow-remote-requests=yes servers=100.100.100.100
- /ip firewall filter
- add chain=input comment="\D3\E4\E0\EB\E5\ED\ED\FB\E9 \E4\EE\F1\F2\F3\EF \E2 \
- \F0\EE\F3\F2\E5\F0 Mikrotik WinBox" dst-port=8291 protocol=tcp
- add chain=input comment="PPTP VPN \E4\EE\F1\F2\F3\EF \EA \F1\E5\F2\E8" \
- dst-port=1723 protocol=tcp
- add chain=input comment=GRE protocol=gre
- add action=drop chain=forward dst-address=172.16.10.0/24 src-address=\
- 172.16.3.0/24
- add action=drop chain=forward dst-address=172.16.3.0/24 src-address=\
- 172.16.10.0/24
- /ip firewall nat
- add action=masquerade chain=srcnat comment=\
- "Nat \E2\FB\F5\EE\E4 \E2 \E8\ED\F2\E5\F0\ED\E5\F2" out-interface=ether1
- add action=netmap chain=dstnat comment=\
- "Nat \D1\E5\F0\E2\E5\F0 \D2\E5\F0\EC\E8\ED\E0\EB\EE\E2" dst-port=3389 \
- in-interface=ether1 protocol=tcp to-addresses=172.16.3.2 to-ports=3389
- add action=redirect chain=dstnat comment=\
- "\D3\E4\E0\EB\E5\ED\ED\FB\E9 \E4\EE\F1\F2\F3\EF \EA Mikrotik \EF\EE web" \
- dst-port=25 in-interface=ether1 protocol=tcp to-ports=80
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set www address=178.236.242.166/32,172.16.9.0/24,213.234.25.92/32
- set ssh port=24
- set api disabled=yes
- set winbox address=178.236.242.166/32,172.16.9.0/24,213.234.25.92/32
- set api-ssl disabled=yes
- /ppp secret
- add comment="\C0\E4\EC\E8\ED\E8\F1\F2\F0\E0\F2\EE\F0 \F1\E5\F2\E8" \
- local-address=172.16.9.1 name=Wizart password=HXXB4-XR9QR remote-address=\
- 172.16.9.3 service=pptp
- /system clock
- set time-zone-autodetect=no time-zone-name=Europe/Moscow
- /system lcd
- set contrast=0 enabled=no port=parallel type=24x4
- /system lcd page
- set time disabled=yes display-time=5s
- set resources disabled=yes display-time=5s
- set uptime disabled=yes display-time=5s
- set packets disabled=yes display-time=5s
- set bits disabled=yes display-time=5s
- set version disabled=yes display-time=5s
- set identity disabled=yes display-time=5s
- set VideoVlan4 disabled=yes display-time=5s
- set UnlimitedSpeedVlan7 disabled=yes display-time=5s
- set Teh.PersonalVlan9 disabled=yes display-time=5s
- set Stage4Vlan40 disabled=yes display-time=5s
- set ether1 disabled=yes display-time=5s
- set ether2 disabled=yes display-time=5s
- set Stage3Vlan30 disabled=yes display-time=5s
- set Stage2Vlan20 disabled=yes display-time=5s
- set Stage1Vlan10 disabled=yes display-time=5s
- set ServersVlan3 disabled=yes display-time=5s
- set RestoranLondonVlan6 disabled=yes display-time=5s
- set RestoranDublinVlan5 disabled=yes display-time=5s
- set ManagementVlan2 disabled=yes display-time=5s
- /system ntp client
- set enabled=yes primary-ntp=88.147.254.232 secondary-ntp=88.147.254.235
- /system scheduler
- add interval=10m name=Send_beckup_to_email on-event=\
- "/system script run backup_to_mail" policy=\
- ftp,reboot,read,write,policy,test,password,sniff,sensitive start-date=\
- jul/10/2016 start-time=21:42:45
- /system script
- add comment="\C1\FD\EA\E0\EF \ED\E0\F1\F2\F0\EE\E5\EA \F0\EE\F3\F2\E5\F0\E0" \
- name=Backup_to_mail owner=admin policy=\
- ftp,reboot,read,write,policy,test,password,sniff,sensitive source="{\r\
- \n:log info \"Starting Backup Script...\";\r\
- \n:local sysname [/system identity get name];\r\
- \n:local sysver [/system package get system version];\r\
- \n:log info \"Flushing DNS cache...\";\r\
- \n/ip dns cache flush;\r\
- \n:delay 2;\r\
- \n:log info \"Deleting last Backups...\";\r\
- \n:foreach i in=[/file find] do={:if ([:typeof [:find [/file get \$i name]\
- \_\\\r\
- \n\"\$sysname-backup-\"]]!=\"nil\") do={/file remove \$i}};\r\
- \n:delay 2;\r\
- \n:local smtpserv [:resolve \"smtp.gmail.com\"];\r\
- \n:local Eaccount \"igor.krivintsov@gmail.com\";\r\
- \n:local pass \"Gfhjkm1978\";\r\
- \n:local backupfile (\"\$sysname-backup-\" . \\\r\
- \n[:pick [/system clock get date] 7 11] . [:pick [/system \\\r\
- \nclock get date] 0 3] . [:pick [/system clock get date] 4 6] . \".backup\
- \");\r\
- \n:log info \"Creating new Full Backup file...\";\r\
- \n/system backup save name=\$backupfile;\r\
- \n:delay 2;\r\
- \n:log info \"Sending Full Backup file via E-mail...\";\r\
- \n/tool e-mail send from=\"<\$Eaccount>\" to=\$Eaccount server=\$smtpserv \
- \\\r\
- \nport=587 user=\$Eaccount password=\$pass start-tls=yes file=\$backupfile\
- \_\\\r\
- \nsubject=(\"\$sysname Full Backup (\" . [/system clock get date] . \")\")\
- \_\\\r\
- \nbody=(\"\$sysname full Backup file see in attachment.\\nRouterOS version\
- : \\\r\
- \n\$sysver\\nTime and Date stamp: \" . [/system clock get time] . \" \" . \
- \\\r\
- \n[/system clock get date]);\r\
- \n:delay 5;\r\
- \n:local exportfile (\"\$sysname-backup-\" . \\\r\
- \n[:pick [/system clock get date] 7 11] . [:pick [/system \\\r\
- \nclock get date] 0 3] . [:pick [/system clock get date] 4 6] . \".rsc\");\
- \r\
- \n:log info \"Creating new Setup Script file...\";\r\
- \n/export verbose file=\$exportfile;\r\
- \n:delay 2;\r\
- \n:log info \"Sending Setup Script file via E-mail...\";\r\
- \n/tool e-mail send from=\"<\$Eaccount>\" to=\$Eaccount server=\$smtpserv \
- \\\r\
- \nport=587 user=\$Eaccount password=\$pass start-tls=yes file=\$exportfile\
- \_\\\r\
- \nsubject=(\"\$sysname Setup Script Backup (\" . [/system clock get date] \
- . \\\r\
- \n\")\") body=(\"\$sysname Setup Script file see in attachment.\\nRouterOS\
- \_\\\r\
- \nversion: \$sysver\\nTime and Date stamp: \" . [/system clock get time] .\
- \_\" \\\r\
- \n\" . [/system clock get date]);\r\
- \n:delay 5;\r\
- \n:log info \"All System Backups emailed successfully.\\nBackuping complet\
- ed.\";\r\
- \n}"
- /tool mac-server
- set [ find default=yes ] disabled=yes
- add interface=ServersVlan3
- add interface=Teh.PersonalVlan9
- /tool mac-server mac-winbox
- add interface=Teh.PersonalVlan9
- add interface=ServersVlan3
- /tool user-manager database
- set db-path=user-manager
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement