Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # jun/17/2024 15:12:37 by RouterOS 6.49.15
- # software id = ********
- #
- # model = RouterBOARD 3011UiAS
- # serial number = 783D0731FC21
- /caps-man channel
- add band=2ghz-b/g/n control-channel-width=20mhz frequency=\
- 2412,2417,2422,2427,2432,2437,2442,2447,2452,2457,2462,2467,2472 name=\
- channelUniversal tx-power=20
- /interface bridge
- add comment=" Guest DOMRU Network" name=bridge_DOM.RU
- add admin-mac=DE:A5:97:57:0F:B4 auto-mac=no comment="Local Network" name=\
- bridge_Local vlan-filtering=yes
- /interface ethernet
- set [ find default-name=ether1 ] comment=Local loop-protect=on \
- loop-protect-send-interval=1s
- set [ find default-name=ether2 ] comment=Reserve loop-protect-send-interval=\
- 1s speed=100Mbps
- set [ find default-name=ether3 ] comment="UPLINK_Servers to Dialine" speed=\
- 100Mbps
- set [ find default-name=ether4 ] comment=\
- "SIP \F2\E5\EB\E5\F4\EE\ED \D0\E5\F1\E5\EF\F8\E5\ED MP 202 \F8\EB\FE\E7" \
- speed=100Mbps
- set [ find default-name=ether5 ] comment="Dom_RU_Corporate Network" speed=\
- 100Mbps
- set [ find default-name=ether6 ] comment="ISP 2 Rostelekom" speed=100Mbps
- set [ find default-name=ether7 ] comment="Guest network DOM.RU" loop-protect=\
- on speed=100Mbps
- set [ find default-name=ether8 ] comment=Reserve loop-protect=on speed=\
- 100Mbps
- set [ find default-name=ether9 ] comment="Up-Link MikroTik_Reseption" speed=\
- 100Mbps
- set [ find default-name=ether10 ] comment="Up-Link 1C-Server" speed=100Mbps
- set [ find default-name=sfp1 ] advertise=\
- 10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full disabled=yes \
- loop-protect=on
- /interface pppoe-client
- add comment="ISP 1 DOM.RU" disabled=no interface=ether5 name=pppoe-out1 \
- password=**** use-peer-dns=yes user=****
- /interface vlan
- add comment="Network device management MGMT" interface=bridge_Local \
- loop-protect=on loop-protect-disable-time=4s loop-protect-send-interval=\
- 1s name=ManagementVlan2 vlan-id=2
- add comment="Network of Servers" interface=bridge_Local loop-protect=on \
- loop-protect-disable-time=4s loop-protect-send-interval=1s name=\
- "Network of ServersVlan3" vlan-id=3
- add comment=Personal interface=bridge_Local loop-protect=on \
- loop-protect-disable-time=4s loop-protect-send-interval=1s name=\
- Teh.PersonalVlan9 vlan-id=9
- add comment=UnlimitedSpeed interface=bridge_Local loop-protect=on \
- loop-protect-disable-time=4s loop-protect-send-interval=1s name=\
- UnlimitedSpeedVlan7 vlan-id=7
- add comment=VoIP disabled=yes interface=bridge_Local \
- loop-protect-disable-time=4s loop-protect-send-interval=1s name=\
- VoiceVlan8 vlan-id=8
- add comment=Vlan3603_Guest_DOMRU interface=bridge_Local loop-protect=on \
- loop-protect-disable-time=4s name=vlan_Dom.Ru vlan-id=3603
- /caps-man datapath
- add bridge=bridge_DOM.RU comment="Config Stage4" name=datapath2Stage4 \
- vlan-id=3603
- add bridge=bridge_DOM.RU comment="Config Stage3" name=datapath3Stage3 \
- vlan-id=3603
- add bridge=bridge_DOM.RU comment="Config Stage2" name=datapath4Stage2 \
- vlan-id=3603
- add bridge=bridge_Local name=datapath1Stage1-4_TehnicalWifi vlan-id=9 \
- vlan-mode=use-tag
- add bridge=bridge_Local comment=VIP name=datapath5 vlan-id=7 vlan-mode=\
- use-tag
- /caps-man configuration
- add channel=channelUniversal country=russia2 datapath=datapath4Stage2 mode=ap \
- name=cfg1_Stage2 rx-chains=0,1,2,3 ssid=***** tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=datapath2Stage4 mode=ap \
- name=cfg6_Stage2 rx-chains=0,1,2,3 ssid=***** tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=datapath4Stage2 mode=ap \
- name=cfg11_Stage2 rx-chains=0,1,2,3 ssid=***** tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=datapath3Stage3 mode=ap \
- name=cfg1Stage3 rx-chains=0,1,2,3 ssid=***** tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=datapath3Stage3 mode=ap \
- name=cfg6Stage3 rx-chains=0,1,2,3 ssid=***** tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=datapath3Stage3 mode=ap \
- name=cfg11Stage3 rx-chains=0,1,2,3 ssid=***** tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=datapath3Stage3 mode=ap \
- name=cfg2Stage3 rx-chains=0,1,2,3 ssid=***** tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=datapath2Stage4 mode=ap \
- name=cfg12Stage4 rx-chains=0,1,2,3 ssid=***** tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=datapath2Stage4 mode=ap \
- name=cfg1Stage4 rx-chains=0,1,2,3 ssid=***** tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=datapath2Stage4 mode=ap \
- name=cfg6_Stage4 rx-chains=0,1,2,3 ssid=***** tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=datapath4Stage2 mode=ap \
- name=cfg1Stage0 rx-chains=0,1,2,3 ssid=***** tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=datapath4Stage2 mode=ap \
- name=cfg1Stage2DublinBar rx-chains=0,1,2,3 ssid=***** tx-chains=\
- 0,1,2,3
- add channel=channelUniversal country=russia2 datapath=datapath4Stage2 mode=ap \
- name=cfg11Stage0 rx-chains=0,1,2,3 ssid=***** tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=datapath4Stage2 mode=ap \
- name=cfg6Stage1 rx-chains=0,1,2,3 ssid=***** tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=datapath4Stage2 mode=ap \
- name=cfg3BarLondon rx-chains=0,1,2,3 ssid=***** tx-chains=0,1,2,3
- add channel=channelUniversal country=russia3 datapath=datapath4Stage2 mode=ap \
- name="cfg4_fijifitnes " rx-chains=0,1,2,3 ssid=***** tx-chains=\
- 0,1,2,3
- /caps-man interface
- add channel=channelUniversal configuration=cfg1Stage4 disabled=no l2mtu=1600 \
- mac-address=CC:2D:E0:01:15:25 master-interface=none name=\
- MikroTik_Administraciya radio-mac=CC:2D:E0:01:15:25 radio-name=\
- CC2DE0011525
- add channel=channelUniversal channel.frequency=\
- 2412,2417,2422,2427,2432,2437,2442,2447,2452,2457,2462,2467,2472 comment=\
- Dublin configuration=cfg1Stage2DublinBar disabled=no l2mtu=1600 \
- mac-address=2C:C8:1B:14:56:CB master-interface=none name=MikroTik_Dublin \
- radio-mac=2C:C8:1B:14:56:CB radio-name=2CC81B1456CB
- add channel=channelUniversal channel.frequency=\
- 2412,2417,2422,2427,2432,2437,2442,2447,2452,2457,2462,2467,2472 comment=\
- MikroTik_Fitness configuration=cfg1Stage0 disabled=yes l2mtu=1600 \
- mac-address=2C:C8:1B:B4:F0:AD master-interface=none name=MikroTik_Fitness \
- radio-mac=2C:C8:1B:B4:F0:AD radio-name=2CC81BB4F0AD
- add channel.frequency=\
- 2412,2417,2422,2427,2432,2437,2442,2447,2452,2457,2462,2467,2472 \
- configuration="cfg4_fijifitnes " disabled=yes l2mtu=1600 mac-address=\
- 08:55:31:11:9A:0F master-interface=none name=MikroTik_FitnessFIJI \
- radio-mac=08:55:31:11:9A:0F radio-name=085531119A0F
- add channel.frequency=\
- 2412,2417,2422,2427,2432,2437,2442,2447,2452,2457,2462,2467,2472 \
- disabled=yes l2mtu=1600 mac-address=08:55:31:11:9A:0F master-interface=\
- MikroTik_FitnessFIJI name=MikroTik_FitnessFIJI_VIP radio-mac=\
- 08:55:31:11:9A:0F radio-name=085531119A0F
- add channel=channelUniversal channel.frequency=\
- 2412,2417,2422,2427,2432,2437,2442,2447,2452,2457,2462,2467,2472 \
- disabled=yes l2mtu=1600 mac-address=2C:C8:1B:B4:F0:AD master-interface=\
- MikroTik_Fitness name=MikroTik_Fitness_VIP radio-mac=2C:C8:1B:B4:F0:AD \
- radio-name=2CC81BB4F0AD
- add comment=Hostel configuration=cfg1Stage2DublinBar disabled=no l2mtu=1600 \
- mac-address=B8:69:F4:2E:6E:F1 master-interface=none name=MikroTik_Hostel \
- radio-mac=B8:69:F4:2E:6E:F1
- add configuration=cfg1_Stage2 disabled=no l2mtu=1600 mac-address=\
- CC:2D:E0:19:D2:93 master-interface=none name=MikroTik_Hostel_2 radio-mac=\
- CC:2D:E0:19:D2:93 radio-name=CC2DE019D293
- add comment="Stage 0_Prachka" configuration=cfg11Stage0 disabled=no l2mtu=\
- 1600 mac-address=64:D1:54:F3:E6:FE master-interface=none name=\
- MikroTik_Stage0_Prachka radio-mac=64:D1:54:F3:E6:FE
- add channel.frequency=2412 comment="Stage 1" configuration=cfg1_Stage2 \
- disabled=no l2mtu=1600 mac-address=CC:2D:E0:EF:A1:F1 master-interface=\
- none name="MikroTik_Stage1\B9107" radio-mac=CC:2D:E0:EF:A1:F1 radio-name=\
- CC2DE0EFA1F1
- add channel.frequency=\
- 2412,2417,2422,2427,2432,2437,2442,2447,2452,2457,2462,2467,2472 comment=\
- "Stage 2" configuration=cfg6_Stage2 disabled=no l2mtu=1600 mac-address=\
- 74:4D:28:98:C7:EF master-interface=none name="MikroTik_Stage2\B9201" \
- radio-mac=74:4D:28:98:C7:EF radio-name=744D2898C7EF
- add channel.frequency=\
- 2412,2417,2422,2427,2432,2437,2442,2447,2452,2457,2462,2467,2472 \
- configuration=cfg11_Stage2 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:26:FA:47 master-interface=none name="MikroTik_Stage2\B9205" \
- radio-mac=64:D1:54:26:FA:47 radio-name=""
- add configuration=cfg6_Stage2 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:14:4B:83 master-interface=none name="MikroTik_Stage2\B9209" \
- radio-mac=64:D1:54:14:4B:83
- add configuration=cfg11_Stage2 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:25:29:DD master-interface=none name="MikroTik_Stage2\B9215" \
- radio-mac=64:D1:54:25:29:DD
- add comment="Stage 3" configuration=cfg1Stage3 disabled=no l2mtu=1600 \
- mac-address=CC:2D:E0:BE:0A:0F master-interface=none name=\
- "MikroTik_Stage3\B9301" radio-mac=CC:2D:E0:BE:0A:0F radio-name=\
- CC2DE0BE0A0F
- add configuration=cfg6Stage3 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:25:29:8F master-interface=none name="MikroTik_Stage3\B9305" \
- radio-mac=64:D1:54:25:29:8F
- add configuration=cfg11Stage3 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:44:C0:CF master-interface=none name="MikroTik_Stage3\B9309" \
- radio-mac=64:D1:54:44:C0:CF
- add configuration=cfg1Stage3 disabled=no l2mtu=1600 mac-address=\
- CC:2D:E0:A7:3E:83 master-interface=none name="MikroTik_Stage3\B9312" \
- radio-mac=CC:2D:E0:A7:3E:83 radio-name=CC2DE0A73E83
- add configuration=cfg1Stage3 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:44:C0:AB master-interface=none name="MikroTik_Stage3\B9315" \
- radio-mac=64:D1:54:44:C0:AB
- add comment="Stage 4" configuration=cfg6_Stage4 disabled=no l2mtu=1600 \
- mac-address=CC:2D:E0:BE:73:6F master-interface=none name=\
- "MikroTik_Stage4\B9401" radio-mac=CC:2D:E0:BE:73:6F radio-name=\
- CC2DE0BE736F
- add configuration=cfg1Stage4 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:46:D1:0B master-interface=none name="MikroTik_Stage4\B9405" \
- radio-mac=64:D1:54:46:D1:0B
- add configuration=cfg12Stage4 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:49:BF:83 master-interface=none name="MikroTik_Stage4\B9409" \
- radio-mac=64:D1:54:49:BF:83
- add configuration=cfg6_Stage4 disabled=no l2mtu=1600 mac-address=\
- 64:D1:54:EC:19:FF master-interface=none name="MikroTik_Stage4\B9415" \
- radio-mac=64:D1:54:EC:19:FF
- add channel.frequency=2422 comment=BarLondon configuration=cfg3BarLondon \
- disabled=no l2mtu=1600 mac-address=CC:2D:E0:12:2C:33 master-interface=\
- none name=Mikrotik_BarLondon radio-mac=CC:2D:E0:12:2C:33 radio-name=\
- CC2DE0122C33
- add configuration=cfg1_Stage2 disabled=no l2mtu=1600 mac-address=\
- CC:2D:E0:A7:3E:F2 master-interface=none name=cap2 radio-mac=\
- CC:2D:E0:A7:3E:F2 radio-name=CC2DE0A73EF2
- /caps-man security
- add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm \
- name=security1 passphrase=ring2016
- add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm \
- name=securityVIP passphrase=315920258456
- add authentication-types=wpa-psk,wpa2-psk encryption=aes-ccm \
- group-encryption=aes-ccm name=securityTehnicalWifi passphrase=258456123
- /caps-man configuration
- add channel=channelUniversal country=russia2 datapath=\
- datapath1Stage1-4_TehnicalWifi mode=ap name=cfg11Stage3_TehnicalWifi \
- rx-chains=0,1,2,3 security=securityTehnicalWifi ssid=TehnicalWifi \
- tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=\
- datapath1Stage1-4_TehnicalWifi mode=ap name=cfg6_Stage2_TehnicalWifi \
- rx-chains=0,1,2,3 security=securityTehnicalWifi ssid=TehnicalWifi \
- tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=\
- datapath1Stage1-4_TehnicalWifi mode=ap name=cfg7Stage4_409_TehnicalWifi \
- rx-chains=0,1,2,3 security=securityTehnicalWifi ssid=TehnicalWifi \
- tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=\
- datapath1Stage1-4_TehnicalWifi mode=ap name=cfg8_Stage2_209_TehnicalWifi \
- rx-chains=0,1,2,3 security=securityTehnicalWifi ssid=TehnicalWifi \
- tx-chains=0,1,2,3
- add channel=channelUniversal country=russia2 datapath=datapath2Stage4 mode=ap \
- name=cfg12_TehnicalWifi rx-chains=0,1,2,3 security=securityTehnicalWifi \
- ssid=TehnicalWifi tx-chains=0,1,2,3
- /caps-man interface
- add channel=channelUniversal channel.frequency=\
- 2412,2417,2422,2427,2432,2437,2442,2447,2452,2457,2462,2467,2472 \
- configuration=cfg6_Stage2_TehnicalWifi disabled=no l2mtu=1600 \
- mac-address=CC:2D:E0:01:15:25 master-interface=MikroTik_Administraciya \
- name="MikroTik_Adm_Technical Wifi" radio-mac=CC:2D:E0:01:15:25 \
- radio-name=CC2DE0011525
- add channel.frequency=2422 configuration=cfg6_Stage2_TehnicalWifi disabled=no \
- l2mtu=1600 mac-address=CC:2D:E0:12:2C:33 master-interface=\
- Mikrotik_BarLondon name=MikroTik_BarLondon_TechnicalWiFI radio-mac=\
- CC:2D:E0:12:2C:33 radio-name=CC2DE0122C33
- add channel=channelUniversal channel.frequency=\
- 2412,2417,2422,2427,2432,2437,2442,2447,2452,2457,2462,2467,2472 \
- configuration=cfg6_Stage2_TehnicalWifi disabled=no l2mtu=1600 \
- mac-address=2C:C8:1B:14:56:CB master-interface=MikroTik_Dublin name=\
- MikroTik_Dublin_TechnicalWi-FI radio-mac=2C:C8:1B:14:56:CB radio-name=\
- 2CC81B1456CB
- add channel.frequency=\
- 2412,2417,2422,2427,2432,2437,2442,2447,2452,2457,2462,2467,2472 \
- configuration=cfg6_Stage2_TehnicalWifi disabled=yes l2mtu=1600 \
- mac-address=08:55:31:11:9A:0F master-interface=MikroTik_FitnessFIJI name=\
- MikroTik_FitnessFIJI_Technical radio-mac=08:55:31:11:9A:0F radio-name=\
- 085531119A0F
- add channel=channelUniversal channel.frequency=\
- 2412,2417,2422,2427,2432,2437,2442,2447,2452,2457,2462,2467,2472 \
- configuration=cfg6_Stage2_TehnicalWifi disabled=yes l2mtu=1600 \
- mac-address=2C:C8:1B:B4:F0:AD master-interface=MikroTik_Fitness name=\
- MikroTik_Fitness_Technical radio-mac=2C:C8:1B:B4:F0:AD radio-name=\
- 2CC81BB4F0AD
- add configuration=cfg6_Stage2_TehnicalWifi disabled=no l2mtu=1600 \
- mac-address=66:D1:54:F3:E6:FE master-interface=MikroTik_Stage0_Prachka \
- name=MikroTik_Stage0_Prachka_TehnicalWifi radio-mac=00:00:00:00:00:00 \
- radio-name=""
- add configuration=cfg8_Stage2_209_TehnicalWifi disabled=no l2mtu=1600 \
- mac-address=64:D1:54:14:4B:83 master-interface="MikroTik_Stage2\B9209" \
- name=MikroTik_Stage2_TehnicalWifi radio-mac=64:D1:54:14:4B:83 radio-name=\
- ""
- add configuration=cfg11Stage3_TehnicalWifi disabled=no l2mtu=1600 \
- mac-address=64:D1:54:44:C0:AB master-interface="MikroTik_Stage3\B9315" \
- name=MikroTik_Stage3N315_TechnicalWIFI radio-mac=64:D1:54:44:C0:AB \
- radio-name=""
- add configuration=cfg11Stage3_TehnicalWifi disabled=no l2mtu=1600 \
- mac-address=64:D1:54:44:C0:CF master-interface="MikroTik_Stage3\B9309" \
- name=MikroTik_Stage3_309_TehnicalWifi radio-mac=64:D1:54:44:C0:CF \
- radio-name=""
- add configuration=cfg7Stage4_409_TehnicalWifi disabled=no l2mtu=1600 \
- mac-address=64:D1:54:49:BF:83 master-interface="MikroTik_Stage4\B9409" \
- name=MikroTik_Stage4_409_TehnicalWifi radio-mac=64:D1:54:49:BF:83 \
- radio-name=""
- add channel=channelUniversal channel.frequency=\
- 2412,2417,2422,2427,2432,2437,2442,2447,2452,2457,2462,2467,2472 comment=\
- Reseption_Holl configuration=cfg6_Stage2_TehnicalWifi disabled=no l2mtu=\
- 1600 mac-address=74:4D:28:1E:DA:67 master-interface=none name=\
- Reseption_Holl_Technical radio-mac=74:4D:28:1E:DA:67 radio-name=\
- 744D281EDA67
- /interface list
- add exclude=dynamic name=discover
- add name=Wan
- /interface wireless security-profiles
- set [ find default=yes ] supplicant-identity=MikroTik
- /ip hotspot user profile
- set [ find default=yes ] keepalive-timeout=2h shared-users=unlimited \
- status-autorefresh=1d
- /ip ipsec profile
- add dh-group=modp1024 enc-algorithm=3des hash-algorithm=md5 name=profile_1
- add dh-group=modp1536 name=profile_2
- /ip ipsec peer
- add address=*****/32 comment="Tayshetskiy 10" disabled=yes name=\
- Tayshetskiy10 passive=yes profile=profile_1
- /ip ipsec proposal
- set [ find default=yes ] auth-algorithms=sha1,md5 enc-algorithms=\
- aes-128-cbc,3des
- /ip pool
- add comment=Management name=PoolVlan2 ranges=172.16.1.40-172.16.1.254
- add comment=Servers name=PoolVlan3 ranges=172.16.3.30-172.16.3.254
- add comment="Personal network" name=PoolVlan9 ranges=172.16.9.10-172.16.9.254
- add comment="VIP network" name=PoolVlan7 ranges=172.16.7.30-172.16.7.254
- add comment=Other name=PoolVlan8 ranges=172.16.8.30-172.16.8.254
- add comment="VPN network" name=Pool_VPN5 ranges=172.16.5.30-172.16.5.254
- /ip dhcp-server
- add address-pool=PoolVlan2 disabled=no interface=ManagementVlan2 lease-time=\
- 1d name=ServerdhcpVlan2
- add address-pool=PoolVlan3 disabled=no interface="Network of ServersVlan3" \
- lease-time=1d name=ServerdhcpVlan3
- add address-pool=PoolVlan9 disabled=no interface=Teh.PersonalVlan9 \
- lease-time=1d name=ServerdhcpVlan9
- add address-pool=PoolVlan7 disabled=no interface=UnlimitedSpeedVlan7 \
- lease-time=1d name=ServerdhcpVlan7
- add address-pool=PoolVlan8 interface=VoiceVlan8 lease-time=1d10m name=\
- ServerdhcpVlan8
- /ppp profile
- add dns-server=172.16.5.1,8.8.8.8 local-address=172.16.5.1 name=MyVPN2 \
- only-one=no remote-address=Pool_VPN5 use-encryption=yes
- /queue type
- add kind=pcq name=sip pcq-classifier=\
- src-address,dst-address,src-port,dst-port pcq-dst-address6-mask=64 \
- pcq-rate=100k pcq-src-address6-mask=64
- add kind=pcq name=rdp pcq-classifier=\
- src-address,dst-address,src-port,dst-port pcq-dst-address6-mask=64 \
- pcq-rate=1M pcq-src-address6-mask=64
- add kind=pcq name=pcq-download-2M pcq-classifier=dst-address pcq-rate=2M
- add kind=pcq name=pcq-upload-2M pcq-classifier=src-address pcq-rate=2M
- /snmp community
- set [ find default=yes ] addresses=0.0.0.0/0
- /user group
- set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
- sword,web,sniff,sensitive,api,romon,dude,tikapp"
- /caps-man manager
- set enabled=yes
- /caps-man provisioning
- add action=create-dynamic-enabled comment=MikroTIK_209 hw-supported-modes=gn \
- master-configuration=cfg6_Stage2 radio-mac=64:D1:54:14:4B:7E
- add action=create-dynamic-enabled comment=MikroTIK_215 hw-supported-modes=gn \
- master-configuration=cfg11_Stage2 radio-mac=64:D1:54:25:29:D8
- add action=create-dynamic-enabled comment=MikroTIK_305 hw-supported-modes=gn \
- master-configuration=cfg11Stage3 radio-mac=64:D1:54:25:29:8A
- add action=create-dynamic-enabled comment=MikroTIK_315 hw-supported-modes=gn \
- master-configuration=cfg6Stage3 radio-mac=64:D1:54:44:C0:A6
- add action=create-dynamic-enabled comment=MikroTIK_309 hw-supported-modes=gn \
- master-configuration=cfg2Stage3 radio-mac=64:D1:54:44:C0:CA
- add action=create-dynamic-enabled comment=MikroTIK_409 hw-supported-modes=gn \
- master-configuration=cfg12Stage4 radio-mac=64:D1:54:49:BF:7E
- add action=create-dynamic-enabled comment=MikroTIK_405 hw-supported-modes=gn \
- master-configuration=cfg1Stage4 radio-mac=64:D1:54:46:D1:06
- add action=create-dynamic-enabled comment=MikroTIK_415 hw-supported-modes=gn \
- master-configuration=cfg6_Stage4 radio-mac=64:D1:54:EC:19:FA
- add action=create-dynamic-enabled comment=MikroTIK_205 hw-supported-modes=gn \
- master-configuration=cfg11_Stage2 radio-mac=64:D1:54:26:FA:42
- add action=create-dynamic-enabled comment=MikroTIK_Prachka \
- hw-supported-modes=gn master-configuration=cfg1Stage0 radio-mac=\
- 64:D1:54:F3:E6:F9
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1Stage2DublinBar radio-mac=CC:2D:E0:12:2C:2E
- add action=create-dynamic-enabled comment=MikroTIK_Sauna1 hw-supported-modes=\
- gn master-configuration=cfg1Stage0 radio-mac=CC:2D:E0:01:15:20
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg11Stage0 radio-mac=CC:2D:E0:02:51:6F
- add action=create-dynamic-enabled comment=MikroTIK_401 hw-supported-modes=gn \
- master-configuration=cfg6_Stage4 radio-mac=CC:2D:E0:BE:73:6A
- add action=create-dynamic-enabled comment=MikroTIK_312 hw-supported-modes=gn \
- master-configuration=cfg1Stage3 radio-mac=CC:2D:E0:A7:3E:7E
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1Stage2DublinBar radio-mac=B8:69:F4:2E:6E:F1
- add action=create-dynamic-enabled comment=MikroTik_301 hw-supported-modes=gn \
- master-configuration=cfg1Stage3 radio-mac=CC:2D:E0:BE:0A:0A
- add action=create-dynamic-enabled comment="Hostel Koridor" \
- hw-supported-modes=gn master-configuration=cfg1_Stage2 radio-mac=\
- CC:2D:E0:19:D2:8E
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1_Stage2 radio-mac=CC:2D:E0:EF:A1:EC
- add action=create-dynamic-enabled comment=MikroTik_201 hw-supported-modes=gn \
- master-configuration=cfg6_Stage2 radio-mac=74:4D:28:98:C7:EA
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg6_Stage2 radio-mac=4C:5E:0C:69:10:64
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg3BarLondon radio-mac=CC:2D:E0:12:2C:33
- add action=create-dynamic-enabled comment=MikroTik_DublinBar \
- hw-supported-modes=gn master-configuration=cfg1Stage2DublinBar radio-mac=\
- 2C:C8:1B:14:56:CB
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1Stage4 radio-mac=CC:2D:E0:01:15:20
- add action=create-dynamic-enabled comment=Resepshen_Holl disabled=yes \
- master-configuration=cfg1_Stage2 name-format=prefix-identity radio-mac=\
- 74:4D:28:1E:DA:67 slave-configurations=*11,cfg6_Stage2_TehnicalWifi
- add action=create-dynamic-enabled comment=Fitness disabled=yes \
- master-configuration=cfg1Stage0 name-format=prefix-identity radio-mac=\
- 2C:C8:1B:B4:F0:AC slave-configurations=*11
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1_Stage2 radio-mac=08:55:31:11:9A:0A
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1_Stage2 radio-mac=74:4D:28:98:C7:EA slave-configurations=\
- cfg6_Stage2_TehnicalWifi
- add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
- cfg1_Stage2 radio-mac=CC:2D:E0:A7:3E:ED slave-configurations=\
- cfg11Stage3_TehnicalWifi
- /interface bridge port
- add bridge=bridge_DOM.RU comment="Guest DOMRU Network" interface=vlan_Dom.Ru
- add bridge=bridge_Local comment="UPLINK to Switch Ring 52 Port" interface=\
- ether1 multicast-router=disabled
- add bridge=bridge_Local comment="UPLINK to Switch Hostel 25 Port" interface=\
- ether3 multicast-router=disabled
- add bridge=bridge_Local comment=Reserve interface=ether2 multicast-router=\
- disabled pvid=3
- add bridge=bridge_Local comment=1C-Servers interface=ether10 pvid=3
- add bridge=bridge_Local comment=\
- "SIP \F2\E5\EB\E5\F4\EE\ED \D0\E5\F1\E5\EF\F8\E5\ED MP 202 \F8\EB\FE\E7" \
- interface=ether4 pvid=9
- add bridge=bridge_Local comment=Reserve interface=ether8 pvid=3
- add bridge=bridge_Local comment="Up-Link Mikrotik_Reseption" interface=ether9
- /interface bridge settings
- set use-ip-firewall-for-vlan=yes
- /ip neighbor discovery-settings
- set discover-interface-list=discover
- /interface bridge vlan
- add bridge=bridge_Local comment=MGMT tagged=ether1,ether3,ether9,bridge_Local \
- vlan-ids=2
- add bridge=bridge_Local comment="Servers Network" tagged=\
- bridge_Local,ether1,ether3 untagged=ether8,ether2 vlan-ids=3
- add bridge=bridge_Local comment=Voip disabled=yes tagged=\
- bridge_Local,ether3,ether1 vlan-ids=8
- add bridge=bridge_Local comment=DOMRU tagged=\
- ether3,ether1,bridge_Local,ether9 vlan-ids=3603
- add bridge=bridge_Local comment=Vip tagged=ether1,bridge_Local,ether9 \
- vlan-ids=7
- add bridge=bridge_Local tagged=ether1,bridge_Local,ether9,ether3 untagged=\
- ether4 vlan-ids=9
- /interface l2tp-server server
- set authentication=mschap2 enabled=yes ipsec-secret=***** use-ipsec=yes
- /interface list member
- add interface=ManagementVlan2 list=discover
- add interface=ether6 list=Wan
- add interface=pppoe-out1 list=Wan
- add interface=ether4 list=discover
- add interface=ether2 list=discover
- /interface pptp-server server
- set default-profile=default
- /ip address
- add address=172.16.1.1/24 comment="Network device management MGMT" interface=\
- ManagementVlan2 network=172.16.1.0
- add address=172.16.3.1/24 comment="Servers network" interface=\
- "Network of ServersVlan3" network=172.16.3.0
- add address=172.16.7.1/24 comment="Unlimited speed" interface=\
- UnlimitedSpeedVlan7 network=172.16.7.0
- add address=172.16.9.1/24 comment=Personal interface=Teh.PersonalVlan9 \
- network=172.16.9.0
- add address=*****/24 comment="ISP 1 Rostelekom 434011354633 " \
- interface=ether6 network=85.172.120.0
- /ip cloud
- set ddns-enabled=yes
- /ip dhcp-server alert
- add disabled=no interface=ManagementVlan2
- /ip dhcp-server lease
- add address=172.16.9.50 client-id=1:90:2b:34:cf:94:af mac-address=\
- 90:2B:34:CF:94:AF server=ServerdhcpVlan9
- add address=172.16.9.90 client-id=1:bc:5f:f4:6:a0:a7 mac-address=\
- BC:5F:F4:06:A0:A7 server=ServerdhcpVlan9
- add address=172.16.9.134 client-id=1:68:6d:bc:22:48:d0 comment=\
- "\CA\F3\F5\ED\FF" mac-address=68:6D:BC:22:48:D0 server=ServerdhcpVlan9
- add address=172.16.9.93 client-id=1:94:e1:ac:d2:8:9e mac-address=\
- 94:E1:AC:D2:08:9E server=ServerdhcpVlan9
- add address=172.16.3.34 client-id=1:d4:3d:7e:35:af:a8 mac-address=\
- D4:3D:7E:35:AF:A8 server=ServerdhcpVlan3
- add address=172.16.9.110 client-id=1:48:ea:63:a2:c8:3 mac-address=\
- 48:EA:63:A2:C8:03 server=ServerdhcpVlan9
- add address=172.16.9.57 client-id=1:0:95:69:d6:60:6a mac-address=\
- 00:95:69:D6:60:6A server=ServerdhcpVlan9
- add address=172.16.9.51 client-id=1:48:ea:63:a2:c7:f4 mac-address=\
- 48:EA:63:A2:C7:F4 server=ServerdhcpVlan9
- add address=172.16.9.52 client-id=1:ec:3d:fd:80:63:ff mac-address=\
- EC:3D:FD:80:63:FF server=ServerdhcpVlan9
- add address=172.16.9.161 client-id=1:44:19:b6:92:9:1b mac-address=\
- 44:19:B6:92:09:1B server=ServerdhcpVlan9
- add address=172.16.9.49 client-id=1:54:c4:15:96:d:1a mac-address=\
- 54:C4:15:96:0D:1A server=ServerdhcpVlan9
- add address=172.16.9.60 client-id=1:48:ea:63:cb:c3:34 mac-address=\
- 48:EA:63:CB:C3:34 server=ServerdhcpVlan9
- add address=172.16.9.74 client-id=1:54:c4:15:ad:f1:60 mac-address=\
- 54:C4:15:AD:F1:60 server=ServerdhcpVlan9
- add address=172.16.9.75 client-id=1:b4:a3:82:8b:fd:b1 mac-address=\
- B4:A3:82:8B:FD:B1 server=ServerdhcpVlan9
- add address=172.16.9.63 client-id=1:48:98:ca:46:e8:5c mac-address=\
- 48:98:CA:46:E8:5C server=ServerdhcpVlan9
- add address=172.16.9.30 client-id=1:bc:1c:81:87:d3:73 mac-address=\
- BC:1C:81:87:D3:73 server=ServerdhcpVlan9
- add address=172.16.9.61 client-id=1:e0:b9:4d:e4:45:cc mac-address=\
- E0:B9:4D:E4:45:CC server=ServerdhcpVlan9
- /ip dhcp-server network
- add address=172.16.1.0/24 comment=MGMT dns-server=172.16.1.1,8.8.8.8 gateway=\
- 172.16.1.1
- add address=172.16.3.0/24 comment="Servers Network" dns-server=\
- 172.16.3.1,8.8.8.8 gateway=172.16.3.1
- add address=172.16.5.0/24 comment="VPN User" dns-server=172.16.5.1,8.8.8.8 \
- gateway=172.16.5.1
- add address=172.16.7.0/24 comment=VIP dns-server=172.16.7.1,8.8.8.8 gateway=\
- 172.16.7.1
- add address=172.16.8.0/24 comment=VoIP dns-server=172.16.8.1,8.8.8.8 gateway=\
- 172.16.8.1
- add address=172.16.9.0/24 comment=Personal dns-server=172.16.9.1,8.8.8.8 \
- gateway=172.16.9.1
- /ip dns
- set allow-remote-requests=yes servers=8.8.8.8
- /ip dns static
- add address=172.16.3.30 name=Voip.local
- add address=172.16.3.12 name=1C-Server.local
- add address=172.16.3.6 name=Serveron.local
- add address=172.16.3.16 name=TS.local
- add address=172.16.9.34 name=Fiji.local
- add address=172.16.9.48 name=London.local
- add address=172.16.3.32 name=Backup.local
- /ip firewall address-list
- add address=93.94.221.181 list=Winbox_White
- add address=***** list=Winbox_White
- add address=178.35.151.148 list=Winbox_White
- add address=172.16.1.0/24 list=Winbox_White
- add address=172.16.9.87 list=Winbox_White
- add address=172.16.9.60 list=Winbox_White
- add address=172.16.5.116 list=Winbox_White
- add address=172.16.9.126 list=Winbox_White
- add address=172.16.5.20 list=Winbox_White
- add address=172.16.3.6 list=Winbox_White
- add address=172.16.5.147 list=Winbox_White
- add address=77.244.212.49-77244.212.62 list=TraveLine
- add address=89.248.195.81-89.248.195.94 list=TraveLine
- add address=172.16.5.120 list=Winbox_White
- add address=77.233.14.2 list=Winbox_White
- add address=Sbis.ru list=Sbis
- /ip firewall filter
- add action=accept chain=forward dst-port=443 protocol=tcp
- add action=drop chain=input comment=\
- "Bruteforce login prevention(Winbox,PPTP)" dst-address-list=\
- winbox_blacklist dst-port=1723,8291 protocol=tcp src-address-list=\
- !Winbox_White
- add action=accept chain=forward dst-address=172.16.1.0/24 src-address=\
- 172.16.3.0/24
- add action=add-src-to-address-list address-list=winbox_blacklist \
- address-list-timeout=none-dynamic chain=input comment=\
- "Bruteforce login prevention(Winbox: stage1)" connection-state=new \
- dst-port=1723,8291 protocol=tcp
- add action=accept chain=input comment=L2TP dst-port=1701 protocol=udp
- add action=accept chain=forward comment=IpSec dst-port=500 protocol=udp
- add action=accept chain=forward dst-port=4500 protocol=udp
- add action=accept chain=input comment="Allow IPSec-esp" protocol=ipsec-esp
- add action=accept chain=input comment="Allow IPSec-ah" protocol=ipsec-ah
- add action=accept chain=forward dst-address=10.8.0.0/24 src-address=\
- 172.16.9.0/24
- add action=drop chain=forward comment="Drop Traffic VIP->Servers" \
- dst-address=172.16.3.0/24 src-address=172.16.7.0/24
- add action=drop chain=forward dst-address=172.16.7.0/24 src-address=\
- 172.16.3.0/24
- add action=drop chain=forward comment="Drop Traffic VIP->VoIP" dst-address=\
- 172.16.8.0/24 src-address=172.16.7.0/24
- add action=drop chain=forward dst-address=172.16.7.0/24 src-address=\
- 172.16.8.0/24
- add action=drop chain=forward comment="Drop Traffic MGMT->VoIP" dst-address=\
- 172.16.8.0/24 src-address=172.16.9.0/24
- add action=drop chain=forward dst-address=172.16.9.0/24 src-address=\
- 172.16.8.0/24
- add action=drop chain=forward comment="Drop Traffic VIP->MGMT" dst-address=\
- 172.16.1.0/24 src-address=172.16.7.0/24
- add action=drop chain=forward dst-address=172.16.7.0/24 src-address=\
- 172.16.1.0/24
- add action=drop chain=forward comment="Drop Traffic MGMT->VoIP" dst-address=\
- 172.16.8.0/24 src-address=172.16.1.0/24
- add action=drop chain=forward dst-address=172.16.1.0/24 src-address=\
- 172.16.8.0/24
- add action=drop chain=forward comment="Drop Traffic Servers->VoIP" \
- dst-address=172.16.8.0/24 src-address=172.16.3.0/24
- add action=drop chain=forward dst-address=172.16.3.0/24 src-address=\
- 172.16.8.0/24
- add action=drop chain=forward comment="Drop Traffic VIP->Personal" \
- dst-address=172.16.7.0/24 src-address=172.16.9.0/24
- add action=drop chain=forward dst-address=172.16.9.0/24 src-address=\
- 172.16.7.0/24
- add action=accept chain=forward dst-address=192.168.1.0/24 src-address=\
- 172.16.5.0/24
- add action=accept chain=forward dst-address=192.168.0.0/24 src-address=\
- 172.16.5.0/24
- add action=accept chain=input comment=OSPF in-interface=all-ppp protocol=ospf
- add action=accept chain=input comment=PPP dst-port=1723 protocol=udp
- add action=accept chain=forward dst-port=4000 protocol=tcp
- add action=drop chain=output comment="GOOGLE PING DENY 8.8.4.4" dst-address=\
- 8.8.4.4 out-interface=ether6
- add action=add-src-to-address-list address-list=Winbox_stage1 \
- address-list-timeout=1m chain=input connection-state=new dst-port=8291 \
- protocol=tcp src-address-list=!Winbox_White
- add action=add-src-to-address-list address-list=Winbox_blacklist \
- address-list-timeout=none-dynamic chain=input connection-state=new \
- dst-port=8291 protocol=tcp src-address-list=Winbox_stage1
- add action=reject chain=input comment="drop Winbox brute forcers" dst-port=\
- 8291 protocol=tcp reject-with=icmp-network-unreachable src-address-list=\
- Winbox_blacklist
- add action=drop chain=forward comment="Printers Reseption hp laserJet 428" \
- src-address=172.16.9.225
- add action=drop chain=forward comment="Printers hp 400 mfp" src-address=\
- 172.16.9.89
- add action=accept chain=input protocol=gre
- add action=drop chain=input comment="DNS ROSTELEKOM" dst-port=53 \
- in-interface=ether6 protocol=udp
- add action=drop chain=input comment="DNS DOM.RU" dst-port=53 in-interface=\
- pppoe-out1 protocol=udp
- add action=accept chain=input comment=Estabilished/Related connection-state=\
- established,related
- add action=accept chain=forward connection-state=established,related
- add action=drop chain=forward comment=Invalid connection-state=invalid \
- connection-type="" in-interface-list=Wan
- add action=drop chain=input connection-state=invalid in-interface-list=Wan
- add action=accept chain=input comment=WinBox dst-port=8291 protocol=tcp \
- src-address-list=Winbox_White
- add action=accept chain=input comment="Allow ping" protocol=icmp
- add action=accept chain=forward comment="IIS Server" dst-port=80 protocol=tcp
- add action=accept chain=input comment=\
- "Bruteforce login prevention(Winbox: droop Winbox brute forcers)" \
- dst-port=1723,8291 protocol=tcp src-address-list=winbox_blacklist
- /ip firewall mangle
- add action=change-mss chain=forward comment=MTU disabled=yes new-mss=1300 \
- out-interface=all-ppp passthrough=yes protocol=tcp tcp-flags=syn
- add action=mark-connection chain=prerouting comment=ISP1 connection-state=new \
- in-interface=ether6 new-connection-mark=from-ISP1 passthrough=yes
- add action=mark-routing chain=prerouting connection-mark=from-ISP1 \
- new-routing-mark=to-ISP1 passthrough=yes
- add action=mark-routing chain=output new-routing-mark=to-ISP1 passthrough=yes \
- src-address=*****
- add action=mark-routing chain=output connection-mark=from-ISP1 \
- new-routing-mark=to-ISP1 passthrough=yes
- add action=mark-connection chain=prerouting comment=ISP2 in-interface=\
- pppoe-out1 new-connection-mark=from-ISP2 passthrough=yes
- add action=mark-routing chain=prerouting connection-mark=from-ISP2 \
- new-routing-mark=to-ISP2 passthrough=yes
- add action=mark-routing chain=output connection-mark=from-ISP2 \
- new-routing-mark=to-ISP2 passthrough=yes
- add action=mark-routing chain=output new-routing-mark=to-ISP2 passthrough=yes \
- src-address=*****
- add action=mark-packet chain=forward comment=Web connection-mark=from-ISP2 \
- disabled=yes new-packet-mark=web_out out-interface=pppoe-out1 \
- passthrough=no routing-mark=to-ISP2
- add action=mark-packet chain=forward connection-mark=from-ISP2 disabled=yes \
- in-interface=pppoe-out1 new-packet-mark=web_in passthrough=no \
- routing-mark=to-ISP2
- add action=mark-packet chain=forward connection-mark=from-ISP2 disabled=yes \
- new-packet-mark=web_vpn_in out-interface=all-ppp passthrough=no
- add action=mark-packet chain=forward connection-mark=from-ISP2 disabled=yes \
- in-interface=all-ppp new-packet-mark=web_vpn_out passthrough=no
- add action=mark-connection chain=input comment=L2TP disabled=yes dst-port=\
- 1701,500,4500 new-connection-mark=L2TP_IN passthrough=no protocol=udp
- add action=mark-packet chain=prerouting connection-mark=L2TP_IN disabled=yes \
- new-packet-mark=L2TP_OUT passthrough=no
- add action=mark-connection chain=output disabled=yes new-connection-mark=\
- L2TP_OUT passthrough=no protocol=udp src-port=1701,4500,500
- add action=mark-packet chain=postrouting connection-mark=L2TP_OUT disabled=\
- yes new-packet-mark=L2TP_IN passthrough=no
- add action=mark-connection chain=prerouting comment=Sip disabled=yes \
- dst-port=5060,20000-50000 new-connection-mark=sip passthrough=no \
- protocol=udp
- add action=mark-packet chain=forward connection-mark=sip disabled=yes \
- in-interface=pppoe-out1 new-packet-mark=Sip_in passthrough=no
- add action=mark-packet chain=forward connection-mark=sip disabled=yes \
- new-packet-mark=Sip_out out-interface=pppoe-out1 passthrough=no
- add action=mark-packet chain=forward connection-mark=sip disabled=yes \
- new-packet-mark=vpn_sip_in out-interface=all-ppp passthrough=no
- add action=mark-packet chain=forward connection-mark=sip disabled=yes \
- in-interface=all-ppp new-packet-mark=vpn_sip_out passthrough=no
- add action=mark-connection chain=prerouting comment=Rdp disabled=yes \
- dst-port=3389 new-connection-mark=rdp passthrough=no protocol=tcp
- add action=mark-packet chain=forward connection-mark=rdp disabled=yes \
- in-interface=all-ppp new-packet-mark=rdp_in passthrough=no
- add action=mark-packet chain=forward connection-mark=rdp disabled=yes \
- new-packet-mark=rdp_out out-interface=all-ppp passthrough=no
- add action=mark-packet chain=forward comment=all disabled=yes \
- new-packet-mark=vpn_all_in out-interface=all-ppp passthrough=no
- add action=mark-packet chain=forward disabled=yes in-interface=all-ppp \
- new-packet-mark=vpn_all_out passthrough=no
- add action=mark-packet chain=forward disabled=yes new-packet-mark=all_out \
- out-interface=pppoe-out1 passthrough=no
- add action=mark-packet chain=forward disabled=yes in-interface=pppoe-out1 \
- new-packet-mark=all_in passthrough=no
- /ip firewall nat
- add action=dst-nat chain=dstnat comment="RDP Gateway" dst-port=443 \
- in-interface=pppoe-out1 protocol=tcp to-addresses=172.16.3.69 to-ports=\
- 443
- add action=dst-nat chain=dstnat comment="PPTP Borisov" dst-port=1723 \
- in-interface=pppoe-out1 protocol=tcp to-addresses=172.16.3.66 to-ports=\
- 1723
- add action=dst-nat chain=dstnat comment=Borisov1 dst-port=38889 in-interface=\
- pppoe-out1 protocol=tcp to-addresses=172.16.3.65 to-ports=3389
- add action=dst-nat chain=dstnat comment=Borisov2 dst-port=8889 in-interface=\
- pppoe-out1 protocol=tcp to-addresses=172.16.3.66 to-ports=3389
- add action=dst-nat chain=dstnat comment="Video Registrator HikVision" \
- dst-port=8000 in-interface=pppoe-out1 protocol=tcp to-addresses=\
- 172.16.9.215 to-ports=8000
- add action=dst-nat chain=dstnat comment="Lift Dialain" dst-port=46000 \
- in-interface=pppoe-out1 log=yes protocol=udp to-addresses=172.16.1.29 \
- to-ports=46000
- add action=dst-nat chain=dstnat dst-port=46001 in-interface=pppoe-out1 log=\
- yes protocol=udp to-addresses=172.16.1.29 to-ports=46001
- add action=dst-nat chain=dstnat comment="Apache Server TravelLine" dst-port=\
- 82 protocol=tcp to-addresses=172.16.3.16 to-ports=81
- add action=dst-nat chain=dstnat comment="EDS-Kolibri Server" dst-port=80 \
- in-interface=pppoe-out1 protocol=tcp to-addresses=172.16.3.33 to-ports=80
- add action=dst-nat chain=dstnat dst-port=80 in-interface=ether6 protocol=tcp \
- to-addresses=172.16.3.33 to-ports=80
- add action=dst-nat chain=dstnat comment="EDS Server impuls" dst-port=89 \
- in-interface=pppoe-out1 protocol=tcp to-addresses=172.16.3.30 to-ports=80
- add action=dst-nat chain=dstnat dst-port=89 in-interface=ether6 protocol=tcp \
- to-addresses=172.16.3.30 to-ports=80
- add action=dst-nat chain=dstnat comment="EDS Server TEST" dst-port=88 \
- in-interface=pppoe-out1 protocol=tcp to-addresses=172.16.3.33 to-ports=80
- add action=dst-nat chain=dstnat dst-port=88 in-interface=ether6 protocol=tcp \
- to-addresses=172.16.3.33 to-ports=80
- add action=masquerade chain=srcnat comment="Nat Domru & Rostelekom" \
- out-interface=ether6
- add action=masquerade chain=srcnat out-interface=pppoe-out1
- /ip firewall service-port
- set sip sip-timeout=5m
- /ip hotspot user
- add name=admin
- /ip ipsec identity
- add generate-policy=port-override peer=Tayshetskiy10 remote-id=ignore secret=\
- *******
- # Peer does not exist
- add secret=*******
- /ip route
- add distance=1 gateway=pppoe-out1 routing-mark=ISP2
- add distance=1 gateway=85.172.120.101 routing-mark=ISP1
- add comment=WLAN2 distance=1 gateway=pppoe-out1
- add comment=WLAN1 disabled=yes distance=2 gateway=85.172.120.101
- add comment=Google distance=1 dst-address=8.8.4.4/32 gateway=pppoe-out1
- /ip route rule
- add src-address=*****/32 table=ISP1
- add src-address=*****/32 table=ISP2
- add dst-address=10.0.0.0/8 table=main
- add dst-address=192.168.0.0/16 table=main
- add dst-address=172.16.0.0/12 table=main
- add routing-mark=to-ISP1 table=ISP1
- add routing-mark=to-ISP2 table=ISP2
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set www disabled=yes port=99
- set ssh disabled=yes
- set api address=172.16.1.0/24,172.16.3.0/24 disabled=yes
- set winbox address="172.16.9.0/24,77.233.14.2/32,172.16.3.0/24,172.16.5.0/24,1\
- 72.16.1.0/24,*****/32,*****/32,93.94.221.181/32"
- set api-ssl disabled=yes
- /routing ospf interface
- add authentication=md5 authentication-key=*******
- add authentication=md5 authentication-key=******* disabled=yes \
- network-type=broadcast passive=yes
- add authentication=md5 authentication-key=******* interface=\
- "Network of ServersVlan3" network-type=broadcast passive=yes
- add authentication=md5 authentication-key=******* interface=\
- Teh.PersonalVlan9 network-type=broadcast passive=yes
- /routing ospf network
- add area=backbone comment="\CC\EE\F1\EA\E2\E0 \EE\F4\E8\F1 \C4\E0\E2\E8\E4" \
- network=172.19.19.40/30
- add area=backbone comment="\CA\EE\EC\EF\FC\FE\F2\E5\F0\ED\FB\E9 \EA\EB\F3\E1" \
- network=172.19.19.36/30
- add area=backbone comment="\C5\F0\E5\E2\E0\ED" network=172.19.19.0/30
- add area=backbone comment="\D2\E0\E9\F8\E5\F2\F1\EA\E8\E9 10 \C1\E0\E7\E0" \
- network=172.19.19.32/30
- add area=backbone comment="VPN " network=172.16.5.0/24
- add area=backbone comment="\D1\E5\F0\E2\E5\F0\E0" network=172.16.3.0/24
- add area=backbone network=172.16.9.0/24
- /snmp
- set enabled=yes
- /system clock
- set time-zone-autodetect=no time-zone-name=Europe/Moscow
- /system clock manual
- set time-zone=+03:00
- /system identity
- set name="MikroTik *****"
- /system note
- set note=***** show-at-login=no
- /system ntp client
- set enabled=yes primary-ntp=88.147.254.232 secondary-ntp=91.226.136.155 \
- server-dns-names=ntp1.stratum2.ru
- /system scheduler
- add disabled=yes interval=1d name=Reboot on-event=" /system reboot" policy=\
- ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
- start-date=oct/17/2017 start-time=03:00:00
- add interval=4w2d name=BackupRouter***** on-event=\
- "/system script run ScriptBackup" policy=\
- ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
- start-date=nov/02/2017 start-time=23:00:24
- /tool sniffer
- set filter-interface=bridge_Local filter-stream=yes streaming-enabled=yes \
- streaming-server=172.16.3.6
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement