Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ! $$$ Model: ZyXEL Keenetic Ultra II
- ! $$$ Version: 2.06.1
- ! $$$ Agent: http/rci
- ! $$$ Last change: Tue, 28 Jan 2020 17:32:31 GMT
- ! $$$ Md5 checksum: 11c7ab5858ae8b9001a0e68d500e7fa7
- system
- set net.ipv4.ip_forward 1
- set net.ipv4.tcp_fin_timeout 30
- set net.ipv4.tcp_keepalive_time 120
- set vm.swappiness 100
- set dev.usb.force_usb2 1
- set net.ipv6.conf.all.forwarding 1
- clock timezone Europe/Moscow
- domainname WORKGROUP
- hostname fox
- !
- ntp server 0.pool.ntp.org
- ntp server 1.pool.ntp.org
- ntp server 2.pool.ntp.org
- ntp server 3.pool.ntp.org
- known host DESKTOP
- known host Air
- known host MacAir
- known host bridge
- known host NAS
- known host tvbox
- known host Galaxy
- known host iPad
- known host Galaxy
- known host HTC
- known host alice
- access-list _WEBADMIN_L2TP0
- !
- access-list _WEBADMIN_PPPoE0
- deny udp 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 port eq 53
- !
- isolate-private
- user admin
- password md5
- password nt
- tag cli
- tag http
- tag opt
- tag ftp
- tag cifs
- tag printers
- !
- dyndns profile _WEBADMIN
- type noip
- domain *.myftp.org
- username *
- password *
- !
- interface GigabitEthernet0
- up
- !
- interface GigabitEthernet0/0
- rename 1
- switchport mode access
- switchport access vlan 1
- up
- !
- interface GigabitEthernet0/1
- rename 2
- switchport mode access
- switchport access vlan 1
- up
- !
- interface GigabitEthernet0/2
- rename 3
- switchport mode access
- switchport access vlan 1
- up
- !
- interface GigabitEthernet0/3
- rename 4
- switchport mode access
- switchport access vlan 1
- up
- !
- interface GigabitEthernet0/4
- rename 5
- switchport mode access
- switchport access vlan 1
- up
- !
- interface GigabitEthernet0/5
- rename 6
- switchport mode access
- switchport access vlan 1
- up
- !
- interface GigabitEthernet0/6
- rename 7
- switchport mode access
- switchport access vlan 1
- up
- !
- interface GigabitEthernet0/Vlan1
- description "Home VLAN"
- security-level private
- ip dhcp client dns-routes
- ip dhcp client name-servers
- up
- !
- interface GigabitEthernet1
- rename ISP
- description RT
- mac address factory wan
- security-level public
- ip address dhcp
- ip dhcp client hostname fox
- ip dhcp client dns-routes
- ip dhcp client name-servers
- ip mtu 1500
- ip adjust-ttl inc 1
- up
- !
- interface GigabitEthernet1/0
- rename 0
- up
- !
- interface WifiMaster0
- country-code US
- compatibility BGN
- channel 8
- channel width 40-below
- tx-burst
- rekey-interval 3600
- up
- !
- interface WifiMaster0/AccessPoint0
- rename AccessPoint
- description "Wi-Fi access point"
- mac access-list type none
- security-level private
- authentication wpa-psk *
- encryption key 1 * default
- encryption enable
- encryption wpa2
- ip dhcp client dns-routes
- ip dhcp client name-servers
- ssid *
- wmm
- up
- !
- interface WifiMaster0/AccessPoint1
- rename GuestWiFi
- description "Guest access point"
- traffic-shape rate 5000
- mac access-list type none
- security-level protected
- ip address 10.1.30.1 255.255.255.0
- ip dhcp client dns-routes
- ip dhcp client name-servers
- ssid Guest
- wmm
- down
- !
- interface WifiMaster0/AccessPoint2
- mac access-list type none
- security-level private
- ip dhcp client dns-routes
- ip dhcp client name-servers
- down
- !
- interface WifiMaster0/AccessPoint3
- mac access-list type none
- security-level private
- ip dhcp client dns-routes
- ip dhcp client name-servers
- down
- !
- interface WifiMaster0/WifiStation0
- security-level public
- encryption disable
- ip address dhcp
- ip dhcp client dns-routes
- ip dhcp client name-servers
- down
- !
- interface WifiMaster1
- country-code US
- compatibility AN+AC
- channel width 40-above/80
- channel auto-rescan 00:00 interval 6
- tx-burst
- rekey-interval 3600
- no band-steering
- up
- !
- interface WifiMaster1/AccessPoint0
- rename AccessPoint_5G
- description "5Ghz Wi-Fi access point"
- mac access-list type none
- security-level private
- authentication wpa-psk *
- encryption enable
- encryption wpa2
- ip dhcp client dns-routes
- ip dhcp client name-servers
- ssid *
- wmm
- up
- !
- interface WifiMaster1/AccessPoint1
- mac access-list type none
- security-level private
- ip dhcp client dns-routes
- ip dhcp client name-servers
- down
- !
- interface WifiMaster1/AccessPoint2
- mac access-list type none
- security-level private
- ip dhcp client dns-routes
- ip dhcp client name-servers
- down
- !
- interface WifiMaster1/AccessPoint3
- mac access-list type none
- security-level private
- ip dhcp client dns-routes
- ip dhcp client name-servers
- down
- !
- interface WifiMaster1/WifiStation0
- security-level public
- encryption disable
- ip address dhcp
- ip dhcp client dns-routes
- ip dhcp client name-servers
- down
- !
- interface Bridge0
- rename Home
- description "Home VLAN"
- inherit GigabitEthernet0/Vlan1
- include AccessPoint
- include AccessPoint_5G
- mac access-list type none
- security-level private
- ip address 192.168.1.1 255.255.255.0
- ip dhcp client dns-routes
- ip dhcp client name-servers
- up
- !
- interface PPPoE0
- description RT
- role inet
- dyndns profile _WEBADMIN
- ipv6cp
- lcp echo 30 3
- ipcp default-route
- ipcp no name-servers
- ipcp dns-routes
- no ccp
- security-level public
- authentication identity *
- authentication password *
- ip mtu 1492
- ip access-group _WEBADMIN_PPPoE0 in
- ip global 65526
- ip tcp adjust-mss pmtu
- igmp upstream
- ipv6 address auto
- ipv6 prefix auto
- ipv6 name-servers auto
- connect via ISP
- up
- bandwidth-limit 97280
- !
- interface PPPoE1
- description S*
- no ipv6cp
- lcp echo 30 3
- ipcp default-route
- ipcp name-servers
- ipcp dns-routes
- no ccp
- security-level public
- authentication identity *
- authentication password *
- ip mtu 1492
- ip global 65520
- ip tcp adjust-mss pmtu
- no connect via ISP
- down
- bandwidth-limit 97280
- !
- interface OpenVPN0
- description A*
- role misc
- security-level public
- ip dhcp client dns-routes
- ip dhcp client name-servers
- ip global 65522
- ip tcp adjust-mss pmtu
- openvpn accept-routes
- openvpn connect via PPPoE0
- down
- !
- interface Wireguard0
- description WireGuard
- security-level public
- ip address 10.8.1.2 255.255.255.0
- ip mtu 1420
- ip global 65518
- ip tcp adjust-mss pmtu
- wireguard peer *
- endpoint *
- keepalive-interval 10
- allow-ips 0.0.0.0 0.0.0.0
- !
- up
- !
- ip dhcp pool _WEBADMIN
- range 192.168.1.2 192.168.1.26
- default-router 192.168.1.1
- dns-server 192.168.1.1
- lease 25200
- bind Home
- enable
- !
- ip dhcp pool _WEBADMIN_GUEST_AP
- enable
- !
- ip dhcp host * 192.168.1.10
- ip dhcp host * 192.168.1.3
- ip dhcp host * 192.168.1.2
- ip dhcp host * 192.168.1.60
- ip dhcp host * 192.168.1.20
- ip dhcp host * 192.168.1.4
- ip name-server 77.88.8.8:1253 ""
- ip name-server 8.8.8.8 "" on Wireguard0
- ip policy Policy0
- description VPN
- no permit global OpenVPN0
- no permit global PPPoE0
- no permit global PPPoE1
- no permit global Wireguard0
- !
- ip http security-level private
- ip http lockout-policy 5 15 3
- ip http ssl enable
- ip http ssl redirect
- ip nat Home
- ip nat GuestWiFi
- ip nat vpn
- ip nat sstp
- ip static tcp PPPoE0 * 192.168.1.20 5000 !NAS
- ip static tcp PPPoE0 * 192.168.1.20 5001 !NAS2
- ip static tcp PPPoE0 * 192.168.1.20 21 !ftp
- ip static tcp PPPoE0 * through 55537 192.168.1.20 !ftp2
- ip static tcp PPPoE0 * 192.168.1.20 8080 !http
- ip static tcp PPPoE0 * * !utorrent
- ip telnet
- security-level private
- lockout-policy 5 15 3
- !
- ip ftp
- security-level private
- lockout-policy 4 15 3
- !
- ip hotspot
- policy Home permit
- host * permit
- host * permit
- host * permit
- host * permit
- host * permit
- host * permit
- host * permit
- host * permit
- host * permit
- host * permit
- host * permit
- auto-scan no interface Home
- !
- ipv6 subnet Default
- bind Home
- number 0
- mode slaac
- !
- ipv6 firewall
- ppe software
- ppe hardware
- upnp lan Home
- udpxy
- timeout 5
- port 4022
- interface PPPoE0
- renew-interval 0
- !
- crypto engine hardware
- crypto ipsec mtu auto
- sstp-server
- interface Home
- pool-range 172.16.3.33 30
- multi-login
- lcp echo 30 3
- !
- vpn-server
- interface Home
- pool-range 172.16.1.33 30
- multi-login
- lcp echo 30 3
- lockout-policy 3 30 5
- !
- service dhcp
- service dns-proxy
- service http
- service telnet
- service ntp-client
- service upnp
- service ntce
- service no cloud-control2
- cifs
- share OPKG 1531ed6f-3aeb-485c-8558-e023b46f4555:
- automount
- permissive
- !
- dns-proxy
- tls upstream 8.8.8.8 853 sni dns.google.com
- tls upstream 8.8.4.4 853 sni dns.google.com
- tls upstream 1.1.1.1 853 sni cloudflare-dns.com
- tls upstream 1.0.0.1 853 sni cloudflare-dns.com
- tls upstream 9.9.9.9 853 sni dns.quad9.net
- !
- monitor
- capture
- interface AccessPoint
- direction in-out
- filter "host 192.168.1.14"
- timeout 1000
- buffer-size 512
- max-frame-size 1518
- capture-size 16384
- !
- !
- !
- opkg disk OPKG:/
- opkg initrc /opt/etc/init.d/rc.unslung
- ntce shaping
- components
- auto-update disable
- auto-update channel stable
- !
- !
RAW Paste Data