Advertisement
Guest User

Untitled

a guest
Nov 20th, 2019
147
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 21.33 KB | None | 0 0
  1. # software id = 5B2I-ECMM
  2. #
  3. /interface bridge
  4. add name=bridge1-Klient
  5. /interface ethernet
  6. set [ find default-name=ether1 ] name=ether1_klient
  7. set [ find default-name=ether3 ] name=ether3_NanoKricen
  8. set [ find default-name=ether4 ] name=ether4_NanoKasalice
  9. /interface wireless security-profiles
  10. set [ find default=yes ] supplicant-identity=RB-750UP-RetrKasaliceKricen
  11. /ip ipsec proposal
  12. set [ find default=yes ] enc-algorithms=aes-128-cbc
  13. /ip pool
  14. add name=dhcp_pool1 ranges=10.3.5.250-10.3.5.254
  15. /ip dhcp-server
  16. add address-pool=dhcp_pool1 disabled=no interface=bridge1-Klient lease-time=\
  17. 3d name=dhcp1
  18. /routing bgp instance
  19. set default as=3020172 redistribute-connected=yes redistribute-static=yes
  20. /routing ospf area
  21. add area-id=12.0.0.0 name=pardubice
  22. /routing ospf instance
  23. set [ find default=yes ] redistribute-connected=as-type-1
  24. /snmp community
  25. set [ find default=yes ] read-access=no
  26. add addresses=0.0.0.0/0 name=zabbix
  27. /system logging action
  28. add name=logfuk remote=10.254.254.254 remote-port=5141 src-address=\
  29. 10.3.20.172 target=remote
  30. /user group
  31. set read policy="local,telnet,ssh,reboot,read,test,winbox,web,sniff,api,!ftp,!\
  32. write,!policy,!password,!sensitive"
  33. add name=telnet policy="local,telnet,ssh,reboot,read,write,policy,test,api,!ft\
  34. p,!winbox,!password,!web,!sniff,!sensitive"
  35. add name=winbox policy="local,ssh,reboot,read,write,policy,test,winbox,api,!te\
  36. lnet,!ftp,!password,!web,!sniff,!sensitive"
  37. add name=ssh policy="ssh,!local,!telnet,!ftp,!reboot,!read,!write,!policy,!tes\
  38. t,!winbox,!password,!web,!sniff,!sensitive,!api"
  39. /interface bridge port
  40. add bridge=bridge1-Klient interface=ether1_klient
  41. add bridge=bridge1-Klient interface=ether5
  42. /interface ethernet poe settings
  43. set ether1-poe-in-long-cable=yes
  44. /ip address
  45. add address=10.3.5.249/29 comment=Klient interface=bridge1-Klient network=\
  46. 10.3.5.248
  47. add address=10.3.20.172/29 comment="UBNT KRicen" interface=ether3_NanoKricen \
  48. network=10.3.20.168
  49. add address=10.3.20.156/29 disabled=yes interface=ether4_NanoKasalice \
  50. network=10.3.20.152
  51. add address=10.12.32.45/30 comment="Zaloha Kasalice" interface=\
  52. ether4_NanoKasalice network=10.12.32.44
  53. add address=10.3.20.153/29 comment="UBNT kasalice" interface=\
  54. ether4_NanoKasalice network=10.3.20.152
  55. /ip dhcp-server lease
  56. add address=10.3.5.253 mac-address=C4:E9:84:6D:3E:9D server=dhcp1
  57. /ip dhcp-server network
  58. add address=10.3.5.248/29 dns-server=77.48.254.254,77.48.100.254 gateway=\
  59. 10.3.5.249
  60. /ip dns
  61. set servers=77.48.254.254,77.48.100.254
  62. /ip ipsec policy
  63. set 0 dst-address=0.0.0.0/0 src-address=0.0.0.0/0
  64. /ip proxy
  65. set cache-path=web-proxy1
  66. /ip route
  67. add distance=1 dst-address=10.3.0.0/16 gateway=10.12.32.46
  68. add distance=1 dst-address=10.12.0.0/16 gateway=10.3.20.169
  69. /ip service
  70. set telnet disabled=yes
  71. set ftp disabled=yes
  72. set www disabled=yes
  73. set ssh port=2222
  74. set api disabled=yes
  75. set api-ssl disabled=yes
  76. /ppp aaa
  77. set use-radius=yes
  78. /radius
  79. add address=10.254.254.254 secret=Sup3R_T4jn3H3sl0 service=\
  80. ppp,login,wireless,dhcp timeout=1s500ms
  81. add address=37.221.240.48 secret=Sup3R_T4jn3H3sl0 service=\
  82. ppp,login,wireless,dhcp timeout=1s500ms
  83. /radius incoming
  84. set accept=yes port=1700
  85. /routing bgp peer
  86. add hold-time=20s in-filter=backup_in_kri keepalive-time=5s name=Kricen \
  87. out-filter=backup_out_kri remote-address=10.3.20.169 remote-as=12042100 \
  88. tcp-md5-key=tlaptlap
  89. add disabled=yes hold-time=20s in-filter=backup keepalive-time=5s name=\
  90. "peer 10.3.100.94" out-filter=backup remote-address=10.3.20.153 \
  91. remote-as=3100094 tcp-md5-key=tlaptlap
  92. add hold-time=20s in-filter=backup_in_kas keepalive-time=5s name=Kasalice \
  93. out-filter=backup_out_kas remote-address=10.12.32.46 remote-as=3231244 \
  94. tcp-md5-key=tlaptlap
  95. /routing filter
  96. add chain=backup_in_kas set-bgp-prepend=10
  97. add chain=backup_out_kas set-bgp-prepend=10
  98. add chain=backup_in_kri set-bgp-prepend=10
  99. add chain=backup_out_kri set-bgp-prepend=10
  100. add action=discard chain=backup_out_kas prefix=10.3.0.0/16
  101. add action=discard chain=backup_out_kri prefix=10.12.0.0/16
  102. add action=accept chain=backup_in_kas prefix=10.3.0.0/16 prefix-length=17-32 \
  103. set-bgp-communities=no-export
  104. add action=accept chain=backup_in_kri prefix=10.12.0.0/16 prefix-length=17-32 \
  105. set-bgp-communities=no-export
  106. /routing ospf interface
  107. add authentication=md5 authentication-key=tlaptlap dead-interval=5s \
  108. hello-interval=1s network-type=broadcast retransmit-interval=4s
  109. /routing ospf network
  110. add area=pardubice disabled=yes
  111. /snmp
  112. set enabled=yes
  113. /system clock
  114. set time-zone-autodetect=no time-zone-name=Europe/Prague
  115. /system identity
  116. set name=RohovladovaBela_Retranclace_MAIN
  117. /system logging
  118. add action=echo disabled=yes topics=radius
  119. add action=logfuk topics=!debug,!packet,!raw,!snmp
  120. /system ntp client
  121. set enabled=yes primary-ntp=37.221.240.61 secondary-ntp=37.221.240.62
  122. /system scheduler
  123. add interval=2m name=AD155-MONITOR on-event=AD155-MONITOR policy=\
  124. ftp,reboot,read,write,policy,test,password,sniff,sensitive start-time=\
  125. startup
  126. /system script
  127. add name=AD155-MONITOR owner=Jirka policy=\
  128. ftp,reboot,read,write,policy,test,password,sniff,sensitive source="# Prome\
  129. nna pro aktualni stav baterie a priznaku\r\
  130. \n:global voltage;\r\
  131. \n:global priznak;\r\
  132. \n# kdyz jede na elektriku ma 27V - kdyztak doladit dle MK potenciometrem \
  133. na zdroji, Kdyz Spadne klesne pri plnem nabiti dle zateze k cca 26,2V\r\
  134. \n:global frombatt 265;\r\
  135. \n# vypina pri 19,7V\r\
  136. \n:global minbatt 200;\r\
  137. \n# promene pro desetinny zapis napeti\r\
  138. \n:global V;\r\
  139. \n\r\
  140. \n:if ((\"-\" . \$priznak)=\"-\") do={:set priznak 0}\r\
  141. \n\r\
  142. \n# Ziskame info o napeti na baterii\r\
  143. \n:set voltage [system health get voltage];\r\
  144. \n#Rozdelime si napeti abychom ho mohli vyjadrit ve Voltech\r\
  145. \n :set V {\"V1\"=[:pick \$voltage 0 2]; \"V2\"=[:pick \$voltage 2 3]; \"V\
  146. P\"=[(((\$voltage-197)*100)/65)]};\r\
  147. \n\r\
  148. \n# zjistime stavy a podle toho reagujeme\r\
  149. \n:if (\$voltage>\$frombatt) do={\r\
  150. \n:if (\$priznak=0 && \$voltage>\$frombatt) do={\r\
  151. \n:log info \"Napajeni ze site obnoveno\";\r\
  152. \n:set priznak 1;\r\
  153. \n/tool e-mail send to=\"jiri.tlapak1@vodafonemail.cz\" subject=(\"Napajen\
  154. i bylo obnoveno!\") body=(\"Napajeni bylo obnoveno a baterie je na \" . (\
  155. \$V->\"V1\") . \",\" . (\$V->\"V2\") . \"V. Zbyvalo jeste: \" . (\$V->\"VP\
  156. \") . \"%\");\r\
  157. \n} else={\r\
  158. \n:log warning \"Napajeni je v poradku\";\r\
  159. \n:log warning (\"Aktualni napeti:\" . (\$V->\"V1\") . \",\" . (\$V->\"V2\
  160. \") . \"V. Do uplneho vybiti zbyva: \" . (\$V->\"VP\") . \"%\");\r\
  161. \n}\r\
  162. \n} else={\r\
  163. \n:log error \"Napajeni preruseno\";\r\
  164. \n:if (\$voltage<=\$minbatt) do={\r\
  165. \n:log error (\"Stav baterie na kriticke mezi:\" . (\$V->\"V1\") . \",\" .\
  166. \_(\$V->\"V2\") . \"V. Za chvili dojde k automatickemu vypnuti. Do uplneho\
  167. \_vybiti zbyva: \" . (\$V->\"VP\") . \"%\");\r\
  168. \n/tool e-mail send to=\"jiri.tlapak1@vodafonemail.cz\" subject=(\"Napajen\
  169. i preruseno! Kriticky stav baterie:\" . (\$V->\"V1\") . \",\" . (\$V->\"V2\
  170. \") . \"V\") body=(\"Baterie je na \" . (\$V->\"V1\") . \",\" . (\$V->\"V2\
  171. \") . \"V! Do uplneho vybiti zbyva: \" . (\$V->\"VP\") . \"%\");\r\
  172. \n} else={\r\
  173. \n:log warning (\"Aktualni napeti:\" . (\$V->\"V1\") . \",\" . (\$V->\"V2\
  174. \") . \"V. Do uplneho vybiti zbyva: \" . (\$V->\"VP\") . \"%\");\r\
  175. \n/tool e-mail send to=\"jiri.tlapak1@vodafonemail.cz\" subject=(\"Napajen\
  176. i preruseno! Zbyva:\" . (\$V->\"V1\") . \",\" . (\$V->\"V2\") . \"V\") bod\
  177. y=(\"Baterie je na \" . (\$V->\"V1\") . \",\" . (\$V->\"V2\") . \"V! Do up\
  178. lneho vybiti zbyva: \" . (\$V->\"VP\") . \"%\");\r\
  179. \n:set priznak 0;\r\
  180. \n}};\r\
  181. \n"
  182. /tool e-mail
  183. set address=77.48.101.171 from=\
  184. RB-750UP-RetrKasaliceKricen_10.3.254.90@tlapnet.cz port=55522
  185. /user aaa
  186. set accounting=no use-radius=yes
  187. "
  188. string(3325) "# nov/20/2019 09:10:58 by RouterOS 6.45.7
  189. # software id = 34BR-JK01
  190. #
  191. # model = 912UAG-5HPnD
  192. # serial number = 603D01665F37
  193. /interface ethernet
  194. set [ find default-name=ether1 ] speed=100Mbps
  195. /interface wireless
  196. set [ find default-name=wlan1 ] band=5ghz-onlyn country="united states" \
  197. disabled=no frequency=5660 frequency-mode=superchannel mode=ap-bridge \
  198. name=wlan1_PECRAY1 rx-chains=0,1 ssid=PECRAY1 tx-chains=0,1 \
  199. wireless-protocol=nv2
  200. /interface wireless security-profiles
  201. set [ find default=yes ] supplicant-identity=MikroTik
  202. /ip ipsec proposal
  203. set [ find default=yes ] enc-algorithms=aes-128-cbc
  204. /routing bgp instance
  205. set default as=13011171 redistribute-connected=yes
  206. /routing ospf area
  207. add area-id=13.0.0.0 name=Kolin
  208. /routing ospf instance
  209. set [ find default=yes ] redistribute-connected=as-type-1
  210. /snmp community
  211. set [ find default=yes ] addresses=0.0.0.0/0 read-access=no
  212. add addresses=0.0.0.0/0 name=zabbix
  213. /system logging action
  214. add name=logfuk remote=10.254.254.254 remote-port=5141 src-address=\
  215. 10.13.11.171 target=remote
  216. /user group
  217. set read policy="local,telnet,ssh,reboot,read,test,winbox,web,sniff,api,romon,\
  218. tikapp,!ftp,!write,!policy,!password,!sensitive,!dude"
  219. add name=telnet policy="local,telnet,ssh,reboot,read,write,policy,test,api,dud\
  220. e,!ftp,!winbox,!password,!web,!sniff,!sensitive,!romon,!tikapp"
  221. add name=winbox policy="local,ssh,reboot,read,write,policy,test,winbox,api,rom\
  222. on,dude,tikapp,!telnet,!ftp,!password,!web,!sniff,!sensitive"
  223. add name=ssh policy="ssh,!local,!telnet,!ftp,!reboot,!read,!write,!policy,!tes\
  224. t,!winbox,!password,!web,!sniff,!sensitive,!api,!romon,!dude,!tikapp"
  225. /ip firewall connection tracking
  226. set enabled=no
  227. /ipv6 settings
  228. set max-neighbor-entries=1024
  229. /interface wireless connect-list
  230. add interface=wlan1_PECRAY1 mac-address=4C:5E:0C:D9:2A:3B security-profile=\
  231. default
  232. /ip address
  233. add address=10.13.11.171/29 comment=WAN interface=ether1 network=10.13.11.168
  234. add address=10.13.12.33/28 comment=PECRAY1 interface=wlan1_PECRAY1 network=\
  235. 10.13.12.32
  236. /ip dns
  237. set servers=77.48.254.254,77.48.100.254
  238. /ip service
  239. set telnet disabled=yes
  240. set ftp disabled=yes
  241. set www disabled=yes
  242. set ssh port=2222
  243. set api disabled=yes
  244. set api-ssl disabled=yes
  245. /ppp aaa
  246. set use-radius=yes
  247. /radius
  248. add address=10.254.254.254 secret=Sup3R_T4jn3H3sl0 service=\
  249. ppp,login,wireless,dhcp timeout=1s500ms
  250. add address=37.221.240.48 secret=Sup3R_T4jn3H3sl0 service=\
  251. ppp,login,wireless,dhcp timeout=1s500ms
  252. /radius incoming
  253. set accept=yes port=1700
  254. /routing bgp peer
  255. add hold-time=20s keepalive-time=5s name="peer 10.13.11.162" remote-address=\
  256. 10.13.11.169 remote-as=13024250 tcp-md5-key=tlaptlap
  257. /routing ospf interface
  258. add authentication=md5 authentication-key=tlaptlap dead-interval=5s \
  259. hello-interval=1s network-type=broadcast retransmit-interval=4s
  260. /routing ospf network
  261. add area=Kolin disabled=yes
  262. /snmp
  263. set enabled=yes
  264. /system clock
  265. set time-zone-autodetect=no time-zone-name=Europe/Prague
  266. /system identity
  267. set name=Cervene_Pecky_150_PECRAY1
  268. /system leds
  269. set 0 interface=wlan1_PECRAY1
  270. /system logging
  271. add action=echo disabled=yes topics=radius
  272. add action=logfuk topics=!debug,!packet,!raw,!snmp
  273. /system ntp client
  274. set enabled=yes primary-ntp=37.221.240.61 secondary-ntp=37.221.240.62
  275. /user aaa
  276. set accounting=no use-radius=yes
  277. "
  278. string(2937) "# nov/20/2019 09:11:21 by RouterOS 6.42.3
  279. # software id = 2SPT-1IRB
  280. #
  281. # model = 912UAG-5HPnD
  282. # serial number = 68120500E63B
  283. /interface wireless
  284. set [ find default-name=wlan1 ] band=5ghz-onlyn country="czech republic" \
  285. disabled=no frequency=5620 frequency-mode=superchannel mode=ap-bridge \
  286. name=wlan1_RAY2 rx-chains=0,1 ssid=169_RAY2 tx-chains=0,1 \
  287. wireless-protocol=nv2
  288. /interface wireless security-profiles
  289. set [ find default=yes ] supplicant-identity=MikroTik
  290. /routing bgp instance
  291. set default as=9011214 redistribute-connected=yes
  292. /routing ospf instance
  293. set [ find default=yes ] redistribute-connected=as-type-1
  294. /snmp community
  295. set [ find default=yes ] addresses=0.0.0.0/0 read-access=no
  296. add addresses=0.0.0.0/0 name=zabbix
  297. /system logging action
  298. add name=logfuk remote=10.254.254.254 remote-port=5141 src-address=\
  299. 10.9.11.214 target=remote
  300. /user group
  301. set read policy="local,telnet,ssh,reboot,read,test,winbox,web,sniff,api,romon,\
  302. tikapp,!ftp,!write,!policy,!password,!sensitive,!dude"
  303. add name=telnet policy="local,telnet,ssh,reboot,read,write,policy,test,api,!ft\
  304. p,!winbox,!password,!web,!sniff,!sensitive,!romon,!dude,!tikapp"
  305. add name=winbox policy="local,ssh,reboot,read,write,policy,test,winbox,api,!te\
  306. lnet,!ftp,!password,!web,!sniff,!sensitive,!romon,!dude,!tikapp"
  307. add name=ssh policy="ssh,!local,!telnet,!ftp,!reboot,!read,!write,!policy,!tes\
  308. t,!winbox,!password,!web,!sniff,!sensitive,!api,!romon,!dude,!tikapp"
  309. /ip firewall connection tracking
  310. set enabled=no
  311. /ip address
  312. add address=10.9.11.214/28 interface=ether1 network=10.9.11.208
  313. add address=10.9.14.33/28 interface=wlan1_RAY2 network=10.9.14.32
  314. /ip dns
  315. set servers=77.48.254.254,77.48.100.254
  316. /ip service
  317. set telnet disabled=yes
  318. set ftp disabled=yes
  319. set www disabled=yes
  320. set ssh port=2222
  321. set api disabled=yes
  322. set api-ssl disabled=yes
  323. /ppp aaa
  324. set use-radius=yes
  325. /radius
  326. add address=10.254.254.254 secret=Sup3R_T4jn3H3sl0 service=\
  327. ppp,login,wireless,dhcp timeout=1s500ms
  328. add address=37.221.240.48 secret=Sup3R_T4jn3H3sl0 service=\
  329. ppp,login,wireless,dhcp timeout=1s500ms
  330. /radius incoming
  331. set accept=yes port=1700
  332. /routing bgp peer
  333. add comment=WAN hold-time=20s keepalive-time=5s name="peer 10.9.11.209" \
  334. remote-address=10.9.11.209 remote-as=12052044 tcp-md5-key=tlaptlap
  335. /routing ospf interface
  336. add authentication=md5 authentication-key=tlaptlap network-type=broadcast
  337. /routing ospf network
  338. add area=backbone disabled=yes
  339. /snmp
  340. set enabled=yes
  341. /system clock
  342. set time-zone-name=Europe/Prague
  343. /system identity
  344. set name=Mikulovice_cp169_Ray2_smerVLouckach
  345. /system leds
  346. set 0 interface=wlan1_RAY2
  347. /system logging
  348. add action=echo topics=info
  349. add action=echo disabled=yes topics=radius
  350. add action=logfuk topics=!debug,!packet,!raw,!snmp
  351. /system ntp client
  352. set enabled=yes primary-ntp=37.221.240.61 secondary-ntp=37.221.240.62
  353. /system routerboard settings
  354. set silent-boot=no
  355. /user aaa
  356. set accounting=no use-radius=yes
  357. "
  358. string(4502) "# nov/20/2019 09:10:48 by RouterOS 6.43.7
  359. # software id = RXLE-131N
  360. #
  361. # model = 2011UAS
  362. # serial number = 402F02A4C4AD
  363. /interface bridge
  364. add fast-forward=no mtu=1500 name=IPTV-SWITCH protocol-mode=none
  365. add fast-forward=no mtu=1500 name=NET-SWITCH protocol-mode=none
  366. add fast-forward=no mtu=1500 name=WAN-TRUNK-SWITCH protocol-mode=none
  367. /interface ethernet
  368. set [ find default-name=ether1 ] comment=tripleplay_READY speed=100Mbps
  369. set [ find default-name=ether2 ] comment=tripleplay_READY speed=100Mbps
  370. set [ find default-name=ether3 ] comment=IPTV_READY speed=100Mbps
  371. set [ find default-name=ether4 ] comment=IPTV_READY speed=100Mbps
  372. set [ find default-name=ether5 ] comment=IPTV_READY speed=100Mbps
  373. set [ find default-name=ether6 ] comment=NET_READY
  374. set [ find default-name=ether7 ] comment=NET_READY
  375. set [ find default-name=ether8 ] comment=NET_READY
  376. set [ find default-name=ether9 ] comment=NET_READY
  377. set [ find default-name=ether10 ] comment=NET_READY
  378. set [ find default-name=sfp1 ] comment=WAN speed=100Mbps
  379. /interface vlan
  380. add interface=WAN-TRUNK-SWITCH name=IPTV vlan-id=104
  381. add interface=WAN-TRUNK-SWITCH name=NET vlan-id=318
  382. /interface list
  383. add exclude=dynamic name=discover
  384. /interface wireless security-profiles
  385. set [ find default=yes ] supplicant-identity=MikroTik
  386. /ip ipsec proposal
  387. set [ find default=yes ] enc-algorithms=3des
  388. /snmp community
  389. set [ find default=yes ] read-access=no
  390. add addresses=0.0.0.0/0 name=zabbix
  391. /system logging action
  392. set 0 memory-lines=100
  393. set 1 disk-lines-per-file=100
  394. add name=logfuk remote=37.221.240.47 remote-port=5141 src-address=10.3.191.2 \
  395. target=remote
  396. /user group
  397. set read policy="local,telnet,ssh,reboot,read,test,winbox,web,sniff,api,romon,\
  398. tikapp,!ftp,!write,!policy,!password,!sensitive,!dude"
  399. add name=telnet policy="local,telnet,ssh,reboot,read,write,policy,test,api,dud\
  400. e,!ftp,!winbox,!password,!web,!sniff,!sensitive,!romon,!tikapp"
  401. add name=winbox policy="local,ssh,reboot,read,write,policy,test,winbox,api,rom\
  402. on,dude,tikapp,!telnet,!ftp,!password,!web,!sniff,!sensitive"
  403. add name=ssh policy="ssh,!local,!telnet,!ftp,!reboot,!read,!write,!policy,!tes\
  404. t,!winbox,!password,!web,!sniff,!sensitive,!api,!romon,!dude,!tikapp"
  405. /interface bridge port
  406. add bridge=WAN-TRUNK-SWITCH hw=no interface=sfp1
  407. add bridge=WAN-TRUNK-SWITCH hw=no interface=ether1
  408. add bridge=WAN-TRUNK-SWITCH hw=no interface=ether2
  409. add bridge=IPTV-SWITCH hw=no interface=ether3
  410. add bridge=IPTV-SWITCH hw=no interface=ether4
  411. add bridge=IPTV-SWITCH hw=no interface=ether5
  412. add bridge=IPTV-SWITCH interface=IPTV
  413. add bridge=NET-SWITCH interface=NET
  414. add bridge=NET-SWITCH hw=no interface=ether6
  415. add bridge=NET-SWITCH hw=no interface=ether7
  416. add bridge=NET-SWITCH hw=no interface=ether8
  417. add bridge=NET-SWITCH hw=no interface=ether9
  418. add bridge=NET-SWITCH hw=no interface=ether10
  419. /ip neighbor discovery-settings
  420. set discover-interface-list=discover
  421. /interface list member
  422. add interface=sfp1 list=discover
  423. add interface=ether1 list=discover
  424. add interface=ether2 list=discover
  425. add interface=ether3 list=discover
  426. add interface=ether4 list=discover
  427. add interface=ether5 list=discover
  428. add interface=ether6 list=discover
  429. add interface=ether7 list=discover
  430. add interface=ether8 list=discover
  431. add interface=ether9 list=discover
  432. add interface=ether10 list=discover
  433. add interface=WAN-TRUNK-SWITCH list=discover
  434. add interface=IPTV-SWITCH list=discover
  435. add interface=NET-SWITCH list=discover
  436. add interface=IPTV list=discover
  437. add interface=NET list=discover
  438. /ip address
  439. add address=10.3.191.2/24 interface=NET-SWITCH network=10.3.191.0
  440. /ip dns
  441. set servers=77.48.254.254,77.48.100.254
  442. /ip route
  443. add distance=1 gateway=10.3.191.1
  444. /ip service
  445. set telnet disabled=yes
  446. set ftp disabled=yes
  447. set www disabled=yes
  448. set ssh port=2222
  449. set api disabled=yes
  450. set api-ssl disabled=yes
  451. /ppp aaa
  452. set use-radius=yes
  453. /radius
  454. add address=10.254.254.254 secret=Sup3R_T4jn3H3sl0 service=\
  455. ppp,login,wireless,dhcp timeout=1s500ms
  456. add address=37.221.240.48 secret=Sup3R_T4jn3H3sl0 service=\
  457. ppp,login,wireless,dhcp timeout=1s500ms
  458. /radius incoming
  459. set accept=yes port=1700
  460. /snmp
  461. set enabled=yes location=Pardubicka_1334
  462. /system clock
  463. set time-zone-autodetect=no time-zone-name=Europe/Prague
  464. /system identity
  465. set name=Prelouc_Pardubicka-1334-switch_RB2011
  466. /system logging
  467. add action=echo disabled=yes topics=radius
  468. add action=logfuk topics=!debug,!packet,!raw,!snmp
  469. /system ntp client
  470. set enabled=yes primary-ntp=37.221.240.61 secondary-ntp=37.221.240.62
  471. /user aaa
  472. set accounting=no use-radius=yes
  473. "
  474. string(2526) "# nov/20/2019 09:10:46 by RouterOS 6.38.5
  475. # software id = M0ZF-CLGL
  476. #
  477. /interface wireless
  478. set [ find default-name=wlan1 ] band=5ghz-a/n country="czech republic" \
  479. disabled=no frequency=5775 mode=ap-bridge name=wlan1_Ray4-smerKunka \
  480. rx-chains=0,1 ssid=MikSEKH1 tx-chains=0,1 wireless-protocol=nv2
  481. /interface wireless security-profiles
  482. set [ find default=yes ] supplicant-identity=MikroTik
  483. /routing bgp instance
  484. set default as=9011210 redistribute-connected=yes
  485. /snmp community
  486. set [ find default=yes ] read-access=no
  487. add addresses=0.0.0.0/0 name=zabbix
  488. /system logging action
  489. add name=logfuk remote=10.254.254.254 remote-port=5141 src-address=\
  490. 10.9.11.210 target=remote
  491. /user group
  492. set read policy="local,telnet,ssh,reboot,read,test,winbox,web,sniff,api,romon,\
  493. tikapp,!ftp,!write,!policy,!password,!sensitive,!dude"
  494. add name=telnet policy="local,telnet,ssh,reboot,read,write,policy,test,api,!ft\
  495. p,!winbox,!password,!web,!sniff,!sensitive,!romon,!dude,!tikapp"
  496. add name=winbox policy="local,ssh,reboot,read,write,policy,test,winbox,api,!te\
  497. lnet,!ftp,!password,!web,!sniff,!sensitive,!romon,!dude,!tikapp"
  498. add name=ssh policy="ssh,!local,!telnet,!ftp,!reboot,!read,!write,!policy,!tes\
  499. t,!winbox,!password,!web,!sniff,!sensitive,!api,!romon,!dude,!tikapp"
  500. /ip address
  501. add address=10.9.11.210/28 comment=WAN interface=ether1 network=10.9.11.208
  502. add address=10.9.12.225/28 comment=Sek interface=wlan1_Ray4-smerKunka \
  503. network=10.9.12.224
  504. /ip dns
  505. set servers=77.48.254.254,77.48.100.254
  506. /ip service
  507. set telnet disabled=yes
  508. set ftp disabled=yes
  509. set www disabled=yes
  510. set ssh port=2222
  511. set api disabled=yes
  512. set api-ssl disabled=yes
  513. /ppp aaa
  514. set use-radius=yes
  515. /radius
  516. add address=10.254.254.254 secret=Sup3R_T4jn3H3sl0 service=\
  517. ppp,login,wireless,dhcp timeout=1s500ms
  518. add address=37.221.240.48 secret=Sup3R_T4jn3H3sl0 service=\
  519. ppp,login,wireless,dhcp timeout=1s500ms
  520. /radius incoming
  521. set accept=yes port=1700
  522. /routing bgp peer
  523. add comment=WAN hold-time=20s keepalive-time=5s name="peer 10.9.11.209" \
  524. remote-address=10.9.11.209 remote-as=12052044 tcp-md5-key=tlaptlap
  525. /snmp
  526. set enabled=yes
  527. /system clock
  528. set time-zone-name=Europe/Prague
  529. /system identity
  530. set name=Mikulovice_cp169_Ray4_smerKunka
  531. /system logging
  532. add action=echo disabled=yes topics=radius
  533. add action=logfuk topics=!debug,!packet,!raw,!snmp
  534. /system ntp client
  535. set enabled=yes primary-ntp=37.221.240.61 secondary-ntp=37.221.240.62
  536. /system routerboard settings
  537. set init-delay=0s
  538. /user aaa
  539. set accounting=no use-radius=yes
  540. "
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement