Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # jun/11/2020 15:03:44 by RouterOS 6.47
- # software id = 8VAQ-SIN4
- #
- # model = RouterBOARD 962UiGS-5HacT2HnT
- # serial number = 908C0990A7B2
- /interface bridge
- add name=bridgeLAN
- add name=bridgeWAN
- /interface ethernet
- set [ find default-name=ether3 ] loop-protect=on
- set [ find default-name=ether5 ] loop-protect=on
- /interface wireless
- set [ find default-name=wlan1 ] ssid=MikroTik
- set [ find default-name=wlan2 ] ssid=MikroTik
- /interface list
- add name=WAN
- add name=LAN
- /interface wireless security-profiles
- set [ find default=yes ] supplicant-identity=MikroTik
- /ip pool
- add name=dhcp ranges=192.168.0.10-192.168.0.20
- /ip dhcp-server
- add address-pool=dhcp disabled=no interface=bridgeLAN name=LAN
- /interface bridge port
- add bridge=bridgeWAN interface=ether4
- add bridge=bridgeLAN interface=ether5
- add bridge=bridgeLAN interface=ether3
- add bridge=bridgeLAN interface=ether2
- /interface list member
- add interface=ether4 list=WAN
- add interface=ether3 list=LAN
- add interface=ether5 list=LAN
- add interface=ether2 list=LAN
- /ip address
- add address=195.68.152.xx/27 interface=bridgeWAN network=195.68.xx.xx
- add address=192.168.0.1/24 interface=bridgeLAN network=192.168.0.0
- /ip dhcp-server network
- add address=192.168.0.0/24 dns-server=8.8.8.8 gateway=192.168.0.1
- /ip dns
- set allow-remote-requests=yes servers=8.8.8.8
- /ip firewall address-list
- add address=195.208.xxx.xxx list=ITB
- add address=172.16.16.1 list=ITB
- /ip firewall filter
- add action=accept chain=input disabled=yes
- add action=accept chain=forward disabled=yes
- add action=accept chain=input comment="ITB: Allow managment" \
- src-address-list=ITB
- add action=drop chain=input comment="ITB: Disable incoming DNS" dst-port=53 \
- in-interface=bridgeWAN protocol=udp
- add action=accept chain=input comment="ITB: Allow VPN support" dst-port=\
- 1701,1723,4500,500 protocol=udp
- add action=accept chain=input comment="ITB: Allow GRE support" protocol=gre
- add action=drop chain=input comment="ITB: Drop PSD" src-address-list=PSD
- add action=accept chain=forward comment="ITB: Allow access to sistematika" \
- src-address-list=Sistematika
- add action=accept chain=input comment=\
- "defconf: accept established,related,untracked" connection-state=\
- established,related,untracked
- add action=drop chain=input comment="defconf: drop invalid" connection-state=\
- invalid
- add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
- add action=drop chain=input comment="defconf: drop all not coming from LAN" \
- in-interface-list=!LAN
- add action=accept chain=forward comment="defconf: accept in ipsec policy" \
- ipsec-policy=in,ipsec
- add action=accept chain=forward comment="defconf: accept out ipsec policy" \
- ipsec-policy=out,ipsec
- add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
- connection-state=established,related
- add action=accept chain=forward comment=\
- "defconf: accept established,related, untracked" connection-state=\
- established,related,untracked
- add action=drop chain=forward comment="defconf: drop invalid" \
- connection-state=invalid
- add action=drop chain=forward comment=\
- "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
- connection-state=new in-interface-list=WAN
- /ip firewall mangle
- add action=change-mss chain=forward new-mss=1408 passthrough=yes protocol=tcp \
- tcp-flags=syn tcp-mss=1401-65535
- add action=add-src-to-address-list address-list=PSD address-list-timeout=\
- none-dynamic chain=prerouting comment="ITB: PSD" in-interface-list=WAN \
- protocol=tcp psd=21,3s,3,1
- /ip firewall nat
- add action=dst-nat chain=dstnat dst-port=6589 protocol=tcp to-addresses=\
- 192.168.0.100 to-ports=3389
- add action=masquerade chain=srcnat out-interface=bridgeWAN
- add action=src-nat chain=srcnat disabled=yes dst-address=192.168.0.100 \
- to-addresses=192.168.0.1
- /ip firewall service-port
- set ftp disabled=yes
- set tftp disabled=yes
- set irc disabled=yes
- set h323 disabled=yes
- set sip disabled=yes
- set pptp disabled=yes
- set udplite disabled=yes
- set dccp disabled=yes
- set sctp disabled=yes
- /ip route
- add distance=1 gateway=195.68.xxx.xx
- /system clock
- set time-zone-name=Asia/Yekaterinburg
- /system routerboard settings
- set auto-upgrade=yes
Add Comment
Please, Sign In to add comment