hadrianradityo

ISP -RGNet

Aug 11th, 2018
96
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. # aug/04/2016 10:41:01 by RouterOS 6.42
  2. # software id = 3AAJ-2WFL
  3. #
  4. # model = RouterBOARD 750G r3
  5. # serial number = 6F3806801D16
  6. /interface ethernet
  7. set [ find default-name=ether1 ] name=e1-Indihome
  8. set [ find default-name=ether2 ] name="e2-My Republic"
  9. set [ find default-name=ether3 ] comment=Local name=e3-Distribusi
  10. set [ find default-name=ether4 ] name=e4
  11. set [ find default-name=ether5 ] name=e5
  12. /interface pppoe-client
  13. add add-default-route=yes comment=ISP default-route-distance=2 \
  14.     dial-on-demand=yes disabled=no interface=e1-Indihome keepalive-timeout=5 \
  15.     name=PPPoE password=KXTJAU04WE user=122861213234@telkom.net
  16. /interface wireless security-profiles
  17. set [ find default=yes ] supplicant-identity=MikroTik
  18. /ip hotspot profile
  19. set [ find default=yes ] html-directory=flash/hotspot
  20. /ip pool
  21. add name=PPTPool ranges=192.168.3.3-192.168.3.25
  22. /ppp profile
  23. add local-address=PPTPool name=PPTP-Profile remote-address=PPTPool
  24. /queue tree
  25. add limit-at=100M max-limit=500M name=Icmp packet-mark=PKT-ICMP parent=global \
  26.     priority=1 queue=default
  27. /routing ospf instance
  28. set [ find default=yes ] redistribute-connected=as-type-2 \
  29.     redistribute-other-ospf=as-type-2 redistribute-static=as-type-2 \
  30.     router-id=192.168.3.1
  31. /snmp community
  32. set [ find default=yes ] addresses=0.0.0.0/0
  33. /tool user-manager customer
  34. set admin access=\
  35.     own-routers,own-users,own-profiles,own-limits,config-payment-gw
  36. /user group
  37. set read policy="local,telnet,ssh,read,winbox,web,sniff,sensitive,api,romon,ti\
  38.    kapp,!ftp,!reboot,!write,!policy,!test,!password,!dude"
  39. /interface l2tp-server server
  40. set enabled=yes ipsec-secret=ratmonogroup use-ipsec=yes
  41. /interface pptp-server server
  42. set enabled=yes
  43. /ip address
  44. add address=192.168.1.2/24 interface=e1-Indihome network=192.168.1.0
  45. add address=192.168.2.2/24 interface="e2-My Republic" network=192.168.2.0
  46. add address=192.168.3.1/24 interface=e3-Distribusi network=192.168.3.0
  47. /ip cloud
  48. set ddns-enabled=yes
  49. /ip dns
  50. set allow-remote-requests=yes servers=192.168.1.1,192.168.2.1,8.8.8.8,8.8.4.4
  51. /ip dns static
  52. add address=8.8.8.8 disabled=yes name=google.com
  53. add address=8.8.8.8 disabled=yes name=google.co.id
  54. /ip firewall address-list
  55. add address=6f3806801d16.sn.mynetname.net list="Remote ALL"
  56. /ip firewall mangle
  57. add action=mark-connection chain=input comment="Load Balance" in-interface=\
  58.     PPPoE new-connection-mark=ISP1-Indihome passthrough=no
  59. add action=mark-connection chain=input in-interface="e2-My Republic" \
  60.     new-connection-mark="ISP2-My Republic" passthrough=no
  61. add action=mark-routing chain=output connection-mark=ISP1-Indihome \
  62.     new-routing-mark=ISP1 passthrough=no
  63. add action=mark-routing chain=output connection-mark="ISP2-My Republic" \
  64.     new-routing-mark=ISP2 passthrough=no
  65. add action=accept chain=prerouting comment=PCC dst-address=192.168.1.0/24 \
  66.     in-interface=e3-Distribusi
  67. add action=accept chain=prerouting dst-address=192.168.2.0/24 in-interface=\
  68.     e3-Distribusi
  69. add action=mark-connection chain=prerouting dst-address-type=!local \
  70.     in-interface=e3-Distribusi new-connection-mark=ISP1-Indihome passthrough=\
  71.     yes per-connection-classifier=both-addresses-and-ports:2/0
  72. add action=mark-connection chain=prerouting dst-address-type=!local \
  73.     in-interface=e3-Distribusi new-connection-mark="ISP2-My Republic" \
  74.     passthrough=yes per-connection-classifier=both-addresses-and-ports:2/1
  75. add action=mark-routing chain=prerouting connection-mark=ISP1-Indihome \
  76.     in-interface=e3-Distribusi new-routing-mark=ISP1 passthrough=no
  77. add action=mark-routing chain=prerouting connection-mark="ISP2-My Republic" \
  78.     in-interface=e3-Distribusi new-routing-mark=ISP2 passthrough=no
  79. add action=mark-connection chain=prerouting comment=ICMP new-connection-mark=\
  80.     ICMP_LOKAL passthrough=yes protocol=icmp
  81. add action=mark-packet chain=prerouting connection-mark=ICMP_LOKAL \
  82.     new-packet-mark=PKT-ICMP passthrough=no
  83. /ip firewall nat
  84. add action=masquerade chain=srcnat comment="Nat ISP" out-interface=PPPoE
  85. add action=masquerade chain=srcnat out-interface=e1-Indihome
  86. add action=masquerade chain=srcnat out-interface="e2-My Republic"
  87. add action=masquerade chain=srcnat comment="Nat Local" out-interface=\
  88.     e3-Distribusi
  89. add action=dst-nat chain=dstnat comment="Remote Mikrotik" dst-address-list=\
  90.     "!Remote ALL" dst-port=81 protocol=tcp to-addresses=192.168.3.2 to-ports=\
  91.     8081
  92. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=82 \
  93.     protocol=tcp to-addresses=192.168.3.2 to-ports=8291
  94. add action=dst-nat chain=dstnat comment="Remote Radio PTP" dst-address-list=\
  95.     "Remote ALL" dst-port=213 protocol=tcp to-addresses=192.168.2.3 to-ports=\
  96.     443
  97. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=214 \
  98.     protocol=tcp to-addresses=192.168.2.4 to-ports=443
  99. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=211 \
  100.     protocol=tcp to-addresses=192.168.2.1 to-ports=80
  101. add action=dst-nat chain=dstnat comment="Remote Radio AP" dst-address-list=\
  102.     "Remote ALL" dst-port=223 protocol=tcp to-addresses=192.168.22.3 \
  103.     to-ports=80
  104. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=233 \
  105.     protocol=tcp to-addresses=192.168.23.3 to-ports=443
  106. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=234 \
  107.     protocol=tcp to-addresses=192.168.23.4 to-ports=443
  108. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=235 \
  109.     protocol=tcp to-addresses=192.168.23.5 to-ports=443
  110. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=236 \
  111.     protocol=tcp to-addresses=192.168.23.6 to-ports=443
  112. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=237 \
  113.     protocol=tcp to-addresses=192.168.23.7 to-ports=80
  114. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=238 \
  115.     protocol=tcp to-addresses=192.168.23.8 to-ports=443
  116. add action=dst-nat chain=dstnat comment="Remote Radio Client" \
  117.     dst-address-list="Remote ALL" dst-port=2310 protocol=tcp to-addresses=\
  118.     192.168.23.10 to-ports=443
  119. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2311 \
  120.     protocol=tcp to-addresses=192.168.23.11 to-ports=443
  121. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2312 \
  122.     protocol=tcp to-addresses=192.168.23.12 to-ports=443
  123. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2313 \
  124.     protocol=tcp to-addresses=192.168.23.13 to-ports=443
  125. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2314 \
  126.     protocol=tcp to-addresses=192.168.23.14 to-ports=80
  127. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2315 \
  128.     protocol=tcp to-addresses=192.168.23.15 to-ports=80
  129. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2316 \
  130.     protocol=tcp to-addresses=192.168.23.16 to-ports=443
  131. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2317 \
  132.     protocol=tcp to-addresses=192.168.23.17 to-ports=443
  133. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2318 \
  134.     protocol=tcp to-addresses=192.168.23.18 to-ports=443
  135. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2319 \
  136.     protocol=tcp to-addresses=192.168.23.19 to-ports=443
  137. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2320 \
  138.     protocol=tcp to-addresses=192.168.23.20 to-ports=443
  139. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2326 \
  140.     protocol=tcp to-addresses=192.168.23.26 to-ports=443
  141. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2327 \
  142.     protocol=tcp to-addresses=192.168.23.27 to-ports=443
  143. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2333 \
  144.     protocol=tcp to-addresses=192.168.23.33 to-ports=443
  145. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2390 \
  146.     protocol=tcp to-addresses=192.168.23.90 to-ports=80
  147. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2391 \
  148.     protocol=tcp to-addresses=192.168.23.91 to-ports=443
  149. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2392 \
  150.     protocol=tcp to-addresses=192.168.23.92 to-ports=443
  151. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2393 \
  152.     protocol=tcp to-addresses=192.168.23.93 to-ports=443
  153. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2394 \
  154.     protocol=tcp to-addresses=192.168.23.94 to-ports=443
  155. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2395 \
  156.     protocol=tcp to-addresses=192.168.23.95 to-ports=443
  157. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2396 \
  158.     protocol=tcp to-addresses=192.168.23.96 to-ports=80
  159. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2397 \
  160.     protocol=tcp to-addresses=192.168.23.97 to-ports=443
  161. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2398 \
  162.     protocol=tcp to-addresses=192.168.23.98 to-ports=443
  163. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2399 \
  164.     protocol=tcp to-addresses=192.168.23.99 to-ports=443
  165. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=23100 \
  166.     protocol=tcp to-addresses=192.168.23.100 to-ports=443
  167. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=23101 \
  168.     protocol=tcp to-addresses=192.168.23.101 to-ports=443
  169. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=23102 \
  170.     protocol=tcp to-addresses=192.168.23.102 to-ports=443
  171. add action=dst-nat chain=dstnat comment="Remote Router Client" \
  172.     dst-address-list="Remote ALL" dst-port=2248 protocol=tcp to-addresses=\
  173.     192.168.22.48 to-ports=8080
  174. add action=dst-nat chain=dstnat dst-address-list="Remote ALL" dst-port=2364 \
  175.     protocol=tcp to-addresses=192.168.23.64 to-ports=8080
  176. add action=masquerade chain=srcnat disabled=yes out-interface=*A
  177. /ip route
  178. add check-gateway=ping distance=1 gateway=PPPoE routing-mark=ISP1
  179. add check-gateway=ping comment=PCC distance=1 gateway=192.168.2.1 \
  180.     routing-mark=ISP2
  181. add check-gateway=ping distance=1 gateway=8.8.8.8 target-scope=30
  182. add check-gateway=ping comment=Failover distance=2 gateway=PPPoE
  183. add check-gateway=ping distance=1 dst-address=8.8.8.8/32 gateway=192.168.2.1
  184. add comment="Static Routing VPN" distance=1 dst-address=66.96.232.56/32 \
  185.     gateway=192.168.2.1
  186. /ip service
  187. set telnet disabled=yes
  188. set ftp disabled=yes
  189. set www port=808
  190. set ssh disabled=yes
  191. /ppp secret
  192. add name=vpn-rgnet password=ratmonogroup profile=PPTP-Profile
  193. add name=rgnet password=rgnet profile=PPTP-Profile
  194. /routing ospf network
  195. add area=backbone network=192.168.1.0/24
  196. add area=backbone network=192.168.2.0/24
  197. add area=backbone network=192.168.3.0/24
  198. /system clock
  199. set time-zone-autodetect=no time-zone-name=Asia/Jakarta
  200. /system identity
  201. set name="RGNet - ISP"
  202. /system routerboard settings
  203. set silent-boot=no
  204. /system scheduler
  205. add interval=1d name=update-cloud on-event="/ip cloud-force update" policy=\
  206.     ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
  207.     start-date=mar/26/2018 start-time=22:02:17
  208. add interval=5h15m name=flush-dns on-event=flush-dns policy=\
  209.     ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
  210.     start-date=may/02/2018 start-time=09:42:00
  211. /system script
  212. add name=flush-dns owner=hadrian policy=\
  213.     ftp,reboot,read,write,policy,test,password,sniff,sensitive source=\
  214.     "/ip dns cache flush"
  215. /tool netwatch
  216. add down-script="/tool fetch url=\"https://api.telegram.org/bot580086614:AAHxe\
  217.    58Y2rdoa2C127ZUZEyYQiN9tzkgr8w/sendmessage\?chat_id=-287628716&text=Jaring\
  218.    an Indihome Down\" keep-result=no" host=192.168.1.1 interval=5s \
  219.     up-script="/tool fetch url=\"https://api.telegram.org/bot580086614:AAHxe58\
  220.    Y2rdoa2C127ZUZEyYQiN9tzkgr8w/sendmessage\?chat_id=-287628716&text=Jaringan\
  221.    \_Indihome Bagus\" keep-result=no"
  222. add down-script="/tool fetch url=\"https://api.telegram.org/bot580086614:AAHxe\
  223.    58Y2rdoa2C127ZUZEyYQiN9tzkgr8w/sendmessage\?chat_id=-287628716&text=Jaring\
  224.    an My Repulic Down\" keep-result=no" host=192.168.2.1 interval=5s \
  225.     up-script="/tool fetch url=\"https://api.telegram.org/bot580086614:AAHxe58\
  226.    Y2rdoa2C127ZUZEyYQiN9tzkgr8w/sendmessage\?chat_id=-287628716&text=Jaringan\
  227.    \_My Republic Bagus\" keep-result=no"
  228. /tool user-manager database
  229. set db-path=flash/user-manager
Add Comment
Please, Sign In to add comment