Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [busadmin@mayak01_freewifi] > export
- # aug/16/2019 10:22:39 by RouterOS 6.43.4
- # software id = REMU-NLIH
- #
- # model = RouterBOARD 941-2nD
- # serial number = 8B0E08C682B7
- /interface bridge
- add arp=reply-only comment=MGMT fast-forward=no name=bridge-vlan250-mgmt
- add comment=freewifi fast-forward=no name=bridge-vlan519-freewifi
- add arp=disabled name=cap
- add name=lan
- /interface wireless
- set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-Ce disabled=no distance=indoors frequency=auto \
- mode=ap-bridge ssid=_FreeWiFi wireless-protocol=802.11
- /interface ethernet
- set [ find default-name=ether1 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full mac-address=\
- CC:2D:E0:5F:04:9F
- set [ find default-name=ether2 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full mac-address=\
- CC:2D:E0:5F:04:A0
- set [ find default-name=ether3 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full mac-address=\
- CC:2D:E0:5F:04:A1
- set [ find default-name=ether4 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full mac-address=\
- CC:2D:E0:5F:04:A2
- /interface l2tp-client
- add allow=mschap2 connect-to=185.46.198.156 disabled=no mrru=1600 name=vpn01 password=2tn2i2WnVA user=fw095
- /interface eoip
- add arp=disabled local-address=10.100.25.95 mac-address=FE:2D:8E:FD:6F:2C name=eoip-cap remote-address=10.100.24.1 \
- tunnel-id=95
- /interface vlan
- add interface=ether1 name=vlan1 vlan-id=250
- add interface=cap name=vlan2 vlan-id=519
- /interface list
- add comment=defconf name=WAN
- add comment=defconf name=LAN
- add exclude=dynamic name=discover
- add name=mactel
- add name=mac-winbox
- /interface wireless security-profiles
- set [ find default=yes ] supplicant-identity=MikroTik
- /snmp community
- set [ find default=yes ] addresses=10.100.24.1/32
- /interface bridge port
- add bridge=cap interface=wlan1
- add bridge=cap interface=eoip-cap
- add bridge=lan hw=no interface=ether1
- add bridge=lan hw=no interface=ether3
- /ip neighbor discovery-settings
- set discover-interface-list=discover
- /interface list member
- add comment=defconf list=LAN
- add comment=defconf interface=ether1 list=WAN
- add interface=wlan1 list=discover
- add interface=ether2 list=discover
- add interface=ether3 list=discover
- add interface=ether4 list=discover
- add interface=cap list=discover
- add interface=vpn01 list=discover
- add interface=eoip-cap list=discover
- add interface=lan list=discover
- add list=mactel
- add list=mac-winbox
- /ip address
- add address=10.0.25.95/21 interface=ether2 network=10.0.24.0
- /ip dhcp-client
- add dhcp-options=hostname,clientid disabled=no interface=lan use-peer-dns=no use-peer-ntp=no
- /ip dns
- set servers=8.8.8.8,8.8.4.4
- /ip firewall filter
- add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=\
- established,related,untracked
- add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
- add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
- connection-state=new in-interface-list=WAN
- add chain=input in-interface=all-ppp
- add chain=input connection-state=established,related
- add action=drop chain=input connection-state=invalid
- add chain=input protocol=icmp
- add chain=input dst-port=22 protocol=tcp src-address=91.240.25.0/24
- add chain=input dst-port=22 protocol=tcp src-address=185.46.196.0/22
- add chain=input dst-port=22 protocol=tcp src-address=10.0.7.0/24
- add chain=input dst-port=22 protocol=tcp src-address=10.7.0.0/16
- add chain=input dst-port=22 protocol=tcp src-address=10.0.24.0/21
- add action=drop chain=input
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set www disabled=yes
- set winbox disabled=yes
- set api-ssl disabled=yes
- /snmp
- set contact=admin enabled=yes location=l
- /system clock
- set time-zone-name=Asia/Yekaterinburg
- /system identity
- set name=mayak01_freewifi
- /system ntp client
- set enabled=yes server-dns-names=0.pool.ntp.org
- /system routerboard settings
- set silent-boot=no
- /tool mac-server
- set allowed-interface-list=mactel
- /tool mac-server mac-winbox
- set allowed-interface-list=mac-winbox
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement