Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #RANCID-CONTENT-TYPE: mikrotik
- #
- # name="advanced-tools" version="6.33.3" build-time=dec/03/2015 16:08:10 scheduled="" bundle=routeros-mipsbe
- # name="dhcp" version="6.33.3" build-time=dec/03/2015 16:08:10 scheduled="" bundle=routeros-mipsbe
- # name="hotspot" version="6.33.3" build-time=dec/03/2015 16:08:10 scheduled="" bundle=routeros-mipsbe
- # name="ipv6" version="6.33.3" build-time=dec/03/2015 16:08:10 scheduled="" bundle=routeros-mipsbe
- # name="mpls" version="6.33.3" build-time=dec/03/2015 16:08:10 scheduled="" bundle=routeros-mipsbe
- # name="ppp" version="6.33.3" build-time=dec/03/2015 16:08:10 scheduled="" bundle=routeros-mipsbe
- # name="routeros-mipsbe" version="6.33.3" build-time=dec/03/2015 16:08:10 scheduled=""
- # name="routing" version="6.33.3" build-time=dec/03/2015 16:08:10 scheduled="" bundle=routeros-mipsbe
- # name="security" version="6.33.3" build-time=dec/03/2015 16:08:10 scheduled="" bundle=routeros-mipsbe
- # name="system" version="6.33.3" build-time=dec/03/2015 16:08:10 scheduled="" bundle=routeros-mipsbe
- # X name="wireless-cm2" version="6.33.3" build-time=dec/03/2015 16:08:10 scheduled="" bundle=routeros-mipsbe
- # name="wireless-fp" version="6.33.3" build-time=dec/03/2015 16:08:10 scheduled="" bundle=routeros-mipsbe
- #
- # routerboard: yes
- # model: CRS226-24G-2S+
- # serial-number: 50D305FB4CE6
- # firmware-type: qca8513
- # current-firmware: 3.22
- # upgrade-firmware: 3.22
- #
- # software-id: AC4L-GZK8
- # nlevel: 5
- # features:
- #
- #
- /interface bridge
- add comment="CTC WAN VLAN" name=bridge_204
- add comment="Internal Wired LAN VLAN" name=bridge_909
- add comment="Internal Wireless VLAN" disabled=yes name=bridge_910
- /interface ethernet
- set [ find default-name=ether1 ] comment="CTC WAN" name=ether1-master-204
- set [ find default-name=ether2 ] master-port=ether1-master-204 name=ether2-slave-204
- set [ find default-name=ether3 ] master-port=ether1-master-204 name=ether3-slave-204
- set [ find default-name=ether4 ] master-port=ether1-master-204 name=ether4-slave-204
- set [ find default-name=ether5 ] name=ether5-master-909
- set [ find default-name=ether6 ] master-port=ether5-master-909 name=ether6-slave-909
- set [ find default-name=ether7 ] master-port=ether5-master-909 name=ether7-slave-909
- set [ find default-name=ether8 ] master-port=ether5-master-909 name=ether8-slave-909
- set [ find default-name=ether9 ] master-port=ether5-master-909 name=ether9-slave-909
- set [ find default-name=ether10 ] master-port=ether5-master-909 name=ether10-slave-909
- set [ find default-name=ether11 ] master-port=ether5-master-909 name=ether11-slave-909
- set [ find default-name=ether12 ] master-port=ether5-master-909 name=ether12-slave-909
- set [ find default-name=ether13 ] master-port=ether5-master-909 name=ether13-slave-909
- set [ find default-name=ether14 ] master-port=ether5-master-909 name=ether14-slave-909
- set [ find default-name=ether15 ] master-port=ether5-master-909 name=ether15-slave-909
- set [ find default-name=ether16 ] master-port=ether5-master-909 name=ether16-slave-909
- set [ find default-name=ether17 ] master-port=ether5-master-909 name=ether17-slave-909
- set [ find default-name=ether18 ] master-port=ether5-master-909 name=ether18-slave-909
- set [ find default-name=ether19 ] master-port=ether5-master-909 name=ether19-slave-909
- set [ find default-name=ether20 ] master-port=ether5-master-909 name=ether20-slave-909
- set [ find default-name=ether21 ] master-port=ether5-master-909 name=ether21-slave-909
- set [ find default-name=ether22 ] master-port=ether5-master-909 name=ether22-slave-909
- set [ find default-name=ether23 ] comment="Wireless AP Interface" name=ether23-master-909
- set [ find default-name=ether24 ] comment="SPAN Port" name=ether24-master-span
- set [ find default-name=sfp-sfpplus1 ] master-port=ether1-master-204 name=sfp-sfpplus1-slave-local
- set [ find default-name=sfpplus2 ] master-port=ether1-master-204 name=sfpplus2-slave-local
- /interface 6to4
- add comment="Hurricane Electric IPv6 Tunnel Broker" !keepalive local-address=172.11.76.115 mtu=1280 name=sit1 remote-address=209.51.181.2
- /ip neighbor discovery
- set ether1-master-204 comment="CTC WAN"
- set ether23-master-909 comment="Wireless AP Interface"
- set ether24-master-span comment="SPAN Port"
- set bridge_204 comment="CTC WAN VLAN"
- set bridge_909 comment="Internal Wired LAN VLAN"
- set bridge_910 comment="Internal Wireless VLAN"
- set sit1 comment="Hurricane Electric IPv6 Tunnel Broker"
- /interface vlan
- add interface=ether1-master-204 l2mtu=1584 name=vlan_204 vlan-id=1
- add interface=ether5-master-909 l2mtu=1584 name=vlan_909 vlan-id=1
- add interface=ether23-master-909 l2mtu=1584 name=vlan_910 vlan-id=1
- /interface wireless security-profiles
- set [ find default=yes ] supplicant-identity=MikroTik
- /ip pool
- add name=vlan_909_pool ranges=10.10.9.10-10.10.9.55
- add name=vlan_910_pool ranges=10.11.0.5-10.11.0.30
- /ip dhcp-server
- add address-pool=vlan_909_pool authoritative=yes disabled=no interface=bridge_909 lease-time=24m name=vlan_909_dhcp
- add address-pool=vlan_910_pool authoritative=yes disabled=no interface=bridge_910 lease-time=24m name=vlan_910_dhcp
- /snmp community
- set [ find default=yes ] addresses=10.5.123.16/29,10.10.9.0/26 name=community-string-redacted
- /system logging action
- set 3 remote=10.10.9.3 src-address=10.10.9.1
- /interface bridge port
- add bridge=bridge_204 interface=ether1-master-204
- add bridge=bridge_909 interface=vlan_909
- add bridge=bridge_910 disabled=yes interface=vlan_910
- add bridge=bridge_909 interface=ether5-master-909
- add bridge=bridge_909 interface=ether23-master-909
- add bridge=bridge_909 interface=ether24-master-span
- add bridge=bridge_204 interface=vlan_204
- /interface ethernet switch
- set ingress-mirror0=ether24-master-span
- /interface ethernet switch vlan
- add disabled=yes ports=ether23-master-909 vlan-id=910
- add ingress-mirror=yes ports="ether5-master-909,ether6-slave-909,ether7-slave-909,ether8-slave-909,ether9-slave-909,ether10-slave-909,ether11-slave-909, ether12-slave-909,ether13-slave-909,ether14-slave-909,ether15-slave-909,et her16-slave-909,ether17-slave-909,ether18-slave-909,ether19-slave-909,ethe r20-slave-909,ether21-slave-909,ether22-slave-909,ether23-master-909" vlan-id=909
- add ports=ether1-master-204,ether2-slave-204,ether3-slave-204,ether4-slave-204 vlan-id=204
- /ip accounting
- set account-local-traffic=yes enabled=yes
- /ip accounting web-access
- set accessible-via-web=yes address=10.10.9.0/26
- /ip address
- add address=172.11.76.115/29 comment="VLAN 204 Gateway" interface=bridge_204 network=172.11.76.112
- add address=10.10.9.1/26 comment="VLAN 909 Gateway" interface=bridge_909 network=10.10.9.0
- add address=10.11.0.1/27 comment="VLAN 910 Gateway" interface=bridge_910 network=10.11.0.0
- /ip dhcp-client
- add dhcp-options=hostname,clientid interface=bridge_204
- /ip dhcp-server lease
- add address=10.10.9.5 always-broadcast=yes client-id=1:c0:ff:b3:d1:19:54 comment="Probe" mac-address=c0:ff:B3:D1:19:54 server=vlan_909_dhcp
- add address=10.10.9.7 always-broadcast=yes client-id=1:c0:ff:38:83:31:75 comment="Laster Printer" mac-address=c0:ff:38:83:31:75 server=vlan_909_dhcp
- add address=10.10.9.9 always-broadcast=yes client-id=1:c0:ff:b1:de:c2:24 comment="tb1" mac-address=c0:ff:B1:DE:C2:24 server=vlan_909_dhcp
- add address=10.10.9.3 always-broadcast=yes client-id=1:c0:ff:32:43:1b:19 comment="NAS" mac-address=c0:ff:32:43:1B:19 server=vlan_909_dhcp
- add address=10.10.9.10 always-broadcast=yes client-id=1:0:21:29:79:e7:78 comment="Network Camera" mac-address=00:21:29:79:E7:78 server=vlan_909_dhcp
- /ip dhcp-server network
- add address=10.10.9.0/26 comment="LAN DHCP Network" dns-server=172.11.72.12 gateway=10.10.9.1 netmask=26
- add address=10.11.0.0/27 comment="Wireless LAN Network" dns-server=172.11.72.12 gateway=10.11.0.1 netmask=27
- /ip dns
- set servers=172.11.72.12
- /ip firewall address-list
- add address=10.15.123.216/29 comment="mgt prefix" list="mgt net"
- /ip firewall filter
- add chain=forward comment="default allow out"
- add action=drop chain=forward comment="drop invalid" connection-state=invalid
- add chain=forward comment="Allow all established and related outbound back in" connection-state=established,related
- add chain=input comment="Permit SSH in" dst-port=22 log-prefix=SSH protocol=tcp
- add chain=input comment="permit wireless to wired" dst-address=10.10.9.0/26 src-address=10.11.0.0/27
- add chain=input comment="permit wired to wireless" dst-address=10.11.0.0/27 src-address=10.10.9.0/26
- add chain=input comment="allow HE tunnel broker" src-address=209.51.181.2
- add chain=input comment="allow all from mgt Net" src-address-list="mgt Net"
- add action=drop chain=input comment="Default Drop" dst-address=172.11.76.115 log=yes
- /ip firewall nat
- add action=masquerade chain=srcnat out-interface=bridge_204
- /ip route
- add distance=1 gateway=172.11.76.113
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set www disabled=yes
- set api disabled=yes
- set winbox disabled=yes
- set api-ssl disabled=yes
- /ip ssh
- set strong-crypto=yes
- /ip upnp
- set enabled=no
- /ipv6 address
- add address=2001:db8:1f10:fd4::2 advertise=no interface=sit1
- add address=2001:db8:c0d7:909::1 comment="VLAN 909 IPv6" interface=bridge_909
- add address=2001:db8:c0d7:910:e68d:8cff:fe80:e00 comment="VLAN 910 IPv6" interface=bridge_910
- /ipv6 firewall filter
- add chain=input comment="Allow all IPv6"
- add chain=forward comment="Allow all IPv6"
- /ipv6 route
- add distance=1 dst-address=2000::/3 gateway=2001:db8:1f10:fd4::1
- /lcd interface pages
- set 1 interfaces="ether13-slave-909,ether14-slave-909,ether15-slave-909,ether16-slave-909,ether17-slave-909,ether18-slave-909,ether19-slave-909,ether20- slave-909,ether21-slave-909"
- /snmp
- set [email protected] enabled=yes location=“Office 909“
- /system clock
- set time-zone-name=America/Chicago
- /system identity
- set name=gw909
- /system logging
- set 0 action=disk
- set 1 action=disk
- set 2 action=disk
- set 3 action=disk
- add action=remote topics=critical,info,error,warning
- /system ntp client
- set enabled=yes primary-ntp=130.126.24.44 secondary-ntp=130.126.24.53
- /system routerboard settings
- set protected-routerboot=disabled
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement