Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /interface bridge
- add admin-mac={mac address} auto-mac=no comment=defconf disabled=yes name=bridge
- /interface ethernet
- set [ find default-name=ether8 ] name=WAN1
- set [ find default-name=ether9 ] name=WAN2
- set [ find default-name=ether2 ] name=ether2-master
- set [ find default-name=ether3 ] master-port=ether2-master
- set [ find default-name=ether4 ] master-port=ether2-master
- set [ find default-name=ether5 ] master-port=ether2-master
- set [ find default-name=ether6 ] name=ether6-master
- /ip neighbor discovery
- set bridge comment=defconf
- /interface ethernet
- set [ find default-name=ether1 ] master-port=ether2-master
- /ip neighbor discovery
- set ether1 discover=no
- /interface list
- add name=WAN-List
- /ip pool
- add name=default-dhcp ranges=10.1.5.10-10.1.5.254
- /ip dhcp-server
- add address-pool=default-dhcp disabled=no interface=ether2-master name=defconf
- /interface bridge port
- add bridge=bridge comment=defconf interface=ether2-master
- add bridge=bridge comment=defconf interface=ether6-master
- add bridge=bridge comment=defconf interface=sfp1
- /interface list member
- add interface=WAN1 list=WAN-List
- add interface=WAN2 list=WAN-List
- /ip address
- add address=10.1.4.1/24 comment=Servers interface=ether2-master network=10.1.4.0
- add address=10.1.5.1/24 comment=Computers interface=ether2-master network=10.1.5.0
- add address=192.168.1.174/28 comment="WAN Connected" interface=WAN1 network=192.168.1.160
- add address=192.168.2.78/28 comment="WAN Netia" interface=WAN2 network=192.168.2.64
- add address=10.1.3.1/24 comment=Routers interface=ether2-master network=10.1.3.0
- /ip dhcp-client
- add comment=defconf dhcp-options=hostname,clientid disabled=yes interface=WAN1
- /ip dhcp-server network
- add address=10.1.5.0/24 comment=defconf dns-server=8.8.8.8,8.8.4.4 gateway=10.1.5.1
- /ip dns
- set allow-remote-requests=no servers=8.8.8.8,8.8.4.4
- /ip dns static
- add address=192.168.88.1 name=router
- /ip firewall filter
- add action=drop chain=input comment="Limit access to WINBOX from the internet" in-interface-list=WAN-List port=8291 protocol=tcp
- add action=drop chain=input in-interface-list=WAN-List port=8291 protocol=udp
- add action=drop chain=input comment="Limit access to DNS from the internet" disabled=yes in-interface-list=WAN-List port=53 protocol=tcp
- add action=drop chain=input disabled=yes in-interface-list=WAN-List port=53 protocol=udp
- add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
- add action=accept chain=input comment="defconf: accept established,related" connection-state=established,related,new
- add action=drop chain=input comment="defconf: drop all from WAN" in-interface=WAN1
- add action=drop chain=input comment="defconf: drop all from WAN" in-interface=WAN2
- add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
- add action=accept chain=forward comment="defconf: accept established,related" connection-state=established,related,new
- add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
- add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface=WAN1
- add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" in-interface=WAN2
- /ip firewall mangle
- add action=passthrough chain=forward disabled=yes in-interface=WAN1 out-interface=ether1
- add action=passthrough chain=forward disabled=yes in-interface=WAN2 out-interface=ether1
- add action=accept chain=prerouting dst-address=192.168.1.0/24 in-interface=ether2-master
- add action=accept chain=prerouting dst-address=192.168.2.0/24 in-interface=ether2-master
- add action=mark-connection chain=prerouting connection-mark=no-mark in-interface=WAN1 new-connection-mark=WAN1_conn
- add action=mark-connection chain=prerouting connection-mark=no-mark in-interface=WAN2 new-connection-mark=WAN2_conn
- add action=mark-connection chain=prerouting connection-mark=no-mark dst-address-type=!local in-interface=ether2-master new-connection-mark=WAN1_conn passthrough=yes per-connection-classifier=both-addresses:2/0
- add action=mark-connection chain=prerouting connection-mark=no-mark dst-address-type=!local in-interface=ether2-master new-connection-mark=WAN2_conn passthrough=yes per-connection-classifier=both-addresses:2/1
- add action=mark-routing chain=prerouting connection-mark=WAN1_conn new-routing-mark=to_WAN1 passthrough=yes
- add action=mark-routing chain=prerouting connection-mark=WAN2_conn new-routing-mark=to_WAN2 passthrough=yes
- add action=mark-routing chain=output connection-mark=WAN1_conn new-routing-mark=to_WAN1
- add action=mark-routing chain=output connection-mark=WAN2_conn new-routing-mark=to_WAN2
- /ip firewall nat
- add action=masquerade chain=srcnat comment="defconf: masquerade" out-interface=ether2-master
- add action=masquerade chain=srcnat out-interface=WAN1
- add action=masquerade chain=srcnat out-interface=WAN2
- /ip route
- add check-gateway=ping distance=1 gateway=192.168.1.161 routing-mark=to_WAN1
- add check-gateway=ping distance=1 gateway=192.168.2.65 routing-mark=to_WAN2
- add check-gateway=ping distance=1 gateway=192.168.1.161
- add check-gateway=ping distance=2 gateway=192.168.2.65
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set www disabled=yes
- set ssh disabled=yes
- set api disabled=yes
- set api-ssl disabled=yes
- /system clock
- set time-zone-name=Europe/Warsaw
- /system ntp client
- set enabled=yes primary-ntp=95.158.95.123 secondary-ntp=91.232.160.1
- /system routerboard settings
- set protected-routerboot=disabled
- /tool mac-server
- set [ find default=yes ] disabled=yes
- add interface=bridge
- /tool mac-server mac-winbox
- set [ find default=yes ] disabled=yes
- add interface=bridge
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement