Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ubnt@Edgerouter-X:~$ show configuration
- firewall {
- all-ping enable
- broadcast-ping disable
- group {
- address-group LAN1_lte_only {
- address 192.168.2.11-192.168.2.19
- }
- address-group ping_DSL_L_weby {
- address 173.249.11.214
- address 216.58.201.99
- description "dsl.cz a google.sk"
- }
- address-group ping_DSL_M_weby {
- address 217.67.19.197
- description dsl.sk
- }
- address-group ping_LTE_weby {
- address 91.235.52.167
- description zive.sk
- }
- network-group PRIVATE_NETS {
- network 192.168.0.0/16
- network 172.16.0.0/12
- network 10.0.0.0/8
- }
- network-group VLAN_isolate {
- description "Drop traffic between vlans"
- network 192.168.50.0/24
- network 192.168.102.0/24
- network 192.168.103.0/24
- network 192.168.104.0/24
- network 192.168.105.0/24
- network 192.168.106.0/24
- network 192.168.107.0/24
- network 192.168.108.0/24
- network 192.168.2.0/24
- }
- port-group broadcast_steam {
- description broadcast_steam
- port 27000-28999
- }
- port-group game_porty {
- description Steam_LoL_PUBG_TS
- port 2099
- port 5000-5500
- port 8393-8400
- port 7000-7999
- port 16000-17999
- port 35000-35999
- port 9000-9999
- port 4379-4380
- port 5795-5847
- port 10000-10300
- port 27000-28999
- port 24024
- }
- port-group imap_mail {
- description "Porty pre emaily"
- port 143
- port 993
- port 465
- port 995
- port 25
- }
- }
- ipv6-receive-redirects disable
- ipv6-src-route disable
- ip-src-route disable
- log-martians disable
- modify DSL_M_only {
- rule 5 {
- action modify
- modify {
- lb-group DSL_M
- }
- }
- }
- modify LTE_Pecalka {
- description "Pecalka LTE + Game porty cez DSL"
- rule 3 {
- action modify
- description test_ping_dsl_sk
- destination {
- group {
- address-group ping_DSL_M_weby
- }
- }
- modify {
- lb-group DSL_M
- }
- }
- rule 4 {
- action modify
- description Game_porty_cez_DSL_M
- destination {
- group {
- port-group game_porty
- }
- }
- modify {
- lb-group LTE
- }
- }
- rule 5 {
- action modify
- modify {
- lb-group DSL_L
- }
- }
- }
- modify Lukas_DSL_vlan {
- rule 5 {
- action modify
- modify {
- lb-group DSL_L
- }
- }
- }
- modify Lukas_LTE_vlan {
- rule 5 {
- action modify
- modify {
- lb-group LTE
- }
- }
- }
- modify balance {
- rule 2 {
- action modify
- description "Ping DSL_L weby"
- destination {
- group {
- address-group ping_DSL_L_weby
- }
- }
- modify {
- lb-group DSL_L
- }
- }
- rule 3 {
- action modify
- description "Ping LTE weby"
- destination {
- group {
- address-group ping_LTE_weby
- }
- }
- modify {
- lb-group LTE
- }
- }
- rule 4 {
- action modify
- description "Ping DSL_M weby"
- destination {
- group {
- address-group ping_DSL_M_weby
- }
- }
- modify {
- lb-group DSL_M
- }
- }
- rule 5 {
- action modify
- description maily_LTE
- destination {
- group {
- port-group imap_mail
- }
- }
- modify {
- lb-group LTE
- }
- }
- rule 6 {
- action modify
- description Game_porty
- destination {
- group {
- port-group game_porty
- }
- }
- modify {
- lb-group DSL_M
- }
- }
- rule 7 {
- action modify
- description LTE_pre_LAN_subnet
- modify {
- lb-group LTE
- }
- source {
- group {
- address-group LAN1_lte_only
- }
- }
- }
- rule 8 {
- action modify
- description Stahovanie_IP_100_Loadbalacing
- modify {
- lb-group G
- }
- source {
- address 192.168.2.100
- }
- }
- rule 9 {
- action modify
- description "LTE30 only pre IP 101"
- modify {
- lb-group LTE30
- }
- source {
- address 192.168.2.101
- }
- }
- rule 10 {
- action modify
- description "do NOT load balance lan to lan"
- destination {
- group {
- network-group PRIVATE_NETS
- }
- }
- modify {
- table main
- }
- }
- rule 20 {
- action modify
- description "do NOT load balance destination public address"
- destination {
- group {
- address-group ADDRv4_eth0
- }
- }
- modify {
- table main
- }
- }
- rule 30 {
- action modify
- description "do NOT load balance destination public address"
- destination {
- group {
- address-group ADDRv4_eth1
- }
- }
- modify {
- table main
- }
- }
- rule 40 {
- action modify
- description "do NOT load balance destination public address"
- destination {
- group {
- address-group ADDRv4_eth2
- }
- }
- modify {
- table main
- }
- }
- rule 70 {
- action modify
- modify {
- lb-group LTE
- }
- }
- }
- name PROTECT_IN {
- default-action accept
- rule 10 {
- action accept
- description "Accept Established/Related"
- protocol all
- state {
- established enable
- related enable
- }
- }
- rule 20 {
- action drop
- description "Drop LAN_NETWORKS"
- destination {
- group {
- network-group VLAN_isolate
- }
- }
- protocol all
- }
- }
- name PROTECT_LOCAL {
- default-action drop
- rule 10 {
- action accept
- description "Accept DNS"
- destination {
- port 53
- }
- protocol tcp_udp
- }
- rule 20 {
- action accept
- description "accept DHCP"
- destination {
- port 67
- }
- protocol udp
- }
- }
- name WAN_IN {
- default-action drop
- description "WAN to internal"
- rule 10 {
- action accept
- description "Allow established/related"
- state {
- established enable
- related enable
- }
- }
- rule 20 {
- action drop
- description "Drop invalid state"
- state {
- invalid enable
- }
- }
- }
- name WAN_LOCAL {
- default-action drop
- description "WAN to router"
- rule 10 {
- action accept
- description "Allow established/related"
- state {
- established enable
- related enable
- }
- }
- rule 20 {
- action drop
- description "Drop invalid state"
- state {
- invalid enable
- }
- }
- }
- receive-redirects disable
- send-redirects enable
- source-validation disable
- syn-cookies enable
- }
- interfaces {
- ethernet eth0 {
- description x_ETH0_2x_LTE
- duplex auto
- firewall {
- in {
- name WAN_IN
- }
- local {
- name WAN_LOCAL
- }
- }
- speed auto
- vif 9 {
- address dhcp
- description 0_LTE_15Mbit
- firewall {
- in {
- name WAN_IN
- }
- local {
- name WAN_LOCAL
- }
- }
- }
- vif 10 {
- address dhcp
- description 0_LTE_30Mbit
- firewall {
- in {
- name WAN_IN
- }
- local {
- name WAN_LOCAL
- }
- }
- }
- }
- ethernet eth1 {
- address 192.168.11.10/24
- description 1_DSL_M
- duplex auto
- firewall {
- in {
- name WAN_IN
- }
- local {
- name WAN_LOCAL
- }
- }
- speed auto
- }
- ethernet eth2 {
- address 192.168.12.11/24
- description 2_DSL_L
- disable
- :
- name WAN_LOCAL
- }
- }
- }
- }
- ethernet eth1 {
- address 192.168.11.10/24
- description 1_DSL_M
- duplex auto
- firewall {
- in {
- name WAN_IN
- }
- local {
- name WAN_LOCAL
- }
- }
- speed auto
- }
- ethernet eth2 {
- address 192.168.12.11/24
- description 2_DSL_L
- disable
- duplex auto
- firewall {
- in {
- name WAN_IN
- }
- local {
- name WAN_LOCAL
- }
- }
- speed auto
- }
- ethernet eth3 {
- address 192.168.2.1/24
- description LAN
- duplex auto
- firewall {
- in {
- modify balance
- }
- }
- speed auto
- vif 5 {
- address 192.168.50.1/24
- description VLAN_Guest
- firewall {
- in {
- modify DSL_M_only
- name PROTECT_IN
- }
- local {
- name PROTECT_LOCAL
- }
- }
- mtu 1500
- }
- }
- ethernet eth4 {
- address 192.168.3.1/24
- description KLIENTI
- duplex auto
- firewall {
- in {
- modify balance
- }
- }
- poe {
- output off
- }
- speed auto
- vif 102 {
- address 192.168.102.1/24
- description Byt_Tomas
- firewall {
- in {
- modify Lukas_DSL_vlan
- name PROTECT_IN
- }
- local {
- name PROTECT_LOCAL
- }
- }
- }
- vif 103 {
- address 192.168.103.1/24
- description Byt_Jozko
- firewall {
- in {
- modify Lukas_DSL_vlan
- name PROTECT_IN
- }
- local {
- name PROTECT_LOCAL
- }
- }
- }
- vif 104 {
- address 192.168.104.1/24
- description Byt_Pecalka
- firewall {
- in {
- modify LTE_Pecalka
- name PROTECT_IN
- }
- local {
- name PROTECT_LOCAL
- }
- }
- }
- vif 105 {
- address 192.168.105.1/24
- description x_Byt_105
- firewall {
- in {
- modify Lukas_LTE_vlan
- name PROTECT_IN
- }
- local {
- name PROTECT_LOCAL
- }
- }
- }
- vif 106 {
- address 192.168.106.1/24
- description x_Byt_106
- firewall {
- in {
- modify Lukas_LTE_vlan
- name PROTECT_IN
- }
- local {
- name PROTECT_LOCAL
- }
- }
- }
- vif 107 {
- address 192.168.107.1/24
- description Byt__Lukas
- firewall {
- in {
- modify Lukas_LTE_vlan
- name PROTECT_IN
- }
- local {
- name PROTECT_LOCAL
- }
- }
- }
- vif 108 {
- address 192.168.108.1/24
- description Byt_Janka
- firewall {
- in {
- modify Lukas_DSL_vlan
- name PROTECT_IN
- }
- local {
- name PROTECT_LOCAL
- }
- }
- }
- vif 109 {
- address 192.168.109.1/24
- description Nano_109
- firewall {
- in {
- modify Lukas_DSL_vlan
- name PROTECT_IN
- }
- local {
- name PROTECT_LOCAL
- }
- }
- mtu 1500
- }
- }
- loopback lo {
- }
- switch switch0 {
- address 192.168.1.1/24
- description Local
- firewall {
- in {
- modify balance
- }
- }
- mtu 1500
- switch-port {
- vlan-aware disable
- }
- }
- }
- load-balance {
- group DSL_L {
- interface eth0.9 {
- failover-only
- }
- interface eth2 {
- route-test {
- count {
- failure 5
- success 5
- }
- initial-delay 60
- interval 10
- type {
- ping {
- target 1.1.1.1
- }
- }
- }
- }
- lb-local enable
- lb-local-metric-change disable
- }
- group DSL_M {
- interface eth1 {
- route-test {
- count {
- failure 5
- success 5
- }
- initial-delay 60
- interval 10
- type {
- ping {
- target 1.1.1.1
- }
- }
- }
- }
- lb-local enable
- lb-local-metric-change disable
- }
- group G {
- interface eth0.9 {
- }
- interface eth0.10 {
- }
- interface eth2 {
- route-test {
- count {
- failure 5
- success 5
- }
- initial-delay 60
- interval 10
- type {
- ping {
- target 1.1.1.1
- }
- }
- }
- weight 20
- }
- lb-local enable
- lb-local-metric-change disable
- }
- group LTE {
- interface eth0.9 {
- weight 70
- }
- interface eth0.10 {
- weight 30
- }
- lb-local enable
- lb-local-metric-change disable
- }
- group LTE30 {
- interface eth0.9 {
- failover-only
- }
- interface eth0.10 {
- }
- lb-local enable
- lb-local-metric-change disable
- }
- }
- protocols {
- static {
- route 0.0.0.0/0 {
- next-hop 192.168.10.1 {
- }
- next-hop 192.168.11.1 {
- }
- next-hop 192.168.12.1 {
- }
- }
- }
- }
- service {
- dhcp-server {
- disabled false
- hostfile-update disable
- shared-network-name ETH4 {
- authoritative disable
- subnet 192.168.3.0/24 {
- default-router 192.168.3.1
- lease 86400
- start 192.168.3.10 {
- stop 192.168.3.10
- }
- }
- }
- shared-network-name LAN_PRIVATE {
- authoritative enable
- subnet 192.168.2.0/24 {
- default-router 192.168.2.1
- dns-server 192.168.2.1
- lease 43200
- start 192.168.2.50 {
- stop 192.168.2.55
- }
- static-mapping Brother_Tlaciaren {
- ip-address 192.168.2.18
- mac-address c4:8e:8f:bd:e9:5f
- }
- static-mapping IP_Cam {
- ip-address 192.168.2.15
- mac-address 00:e0:f8:a2:37:4a
- }
- static-mapping Lenovo_android {
- ip-address 192.168.2.16
- mac-address 14:36:c6:4a:29:13
- }
- static-mapping Michal_PC {
- ip-address 192.168.2.10
- mac-address 4c:cc:6a:cd:91:36
- }
- static-mapping NB_Katarina {
- ip-address 192.168.2.12
- mac-address 94:e9:79:73:8e:fd
- }
- static-mapping OPO_Find7a {
- ip-address 192.168.2.17
- mac-address 8c:0e:e3:5d:21:b5
- }
- static-mapping RedmiNote5 {
- ip-address 192.168.2.11
- mac-address 20:47:da:25:88:0f
- }
- static-mapping TV_Box {
- ip-address 192.168.2.14
- mac-address c4:2f:ad:15:84:14
- }
- static-mapping XIAOMI {
- ip-address 192.168.2.2
- mac-address F0:B4:29:17:DB:95
- }
- }
- }
- shared-network-name VLAN5 {
- authoritative disable
- subnet 192.168.50.0/24 {
- default-router 192.168.50.1
- dns-server 192.168.2.1
- lease 86400
- start 192.168.50.10 {
- stop 192.168.50.19
- }
- }
- }
- shared-network-name VLAN_102 {
- authoritative enable
- subnet 192.168.102.0/24 {
- default-router 192.168.102.1
- dns-server 1.1.1.1
- dns-server 1.0.0.1
- lease 86400
- start 192.168.102.2 {
- stop 192.168.102.2
- }
- static-mapping Tomas_TPLink {
- ip-address 192.168.102.2
- mac-address 74:d4:35:1a:17:34
- }
- }
- }
- shared-network-name VLAN_103 {
- authoritative enable
- subnet 192.168.103.0/24 {
- default-router 192.168.103.1
- dns-server 1.1.1.1
- dns-server 1.0.0.1
- lease 86400
- start 192.168.103.2 {
- stop 192.168.103.2
- }
- static-mapping Jozko {
- ip-address 192.168.103.2
- mac-address 18:31:bf:65:6b:e4
- }
- }
- }
- shared-network-name VLAN_104 {
- authoritative enable
- subnet 192.168.104.0/24 {
- default-router 192.168.104.1
- dns-server 1.1.1.1
- dns-server 1.0.0.1
- lease 86400
- start 192.168.104.2 {
- stop 192.168.104.2
- }
- static-mapping Pecalka {
- ip-address 192.168.104.2
- mac-address c8:3a:35:5e:63:80
- }
- }
- }
- shared-network-name VLAN_105 {
- authoritative enable
- subnet 192.168.105.0/24 {
- default-router 192.168.105.1
- dns-server 1.1.1.1
- dns-server 1.0.0.1
- lease 86400
- start 192.168.105.2 {
- stop 192.168.105.3
- }
- }
- }
- shared-network-name VLAN_106 {
- authoritative enable
- subnet 192.168.106.0/24 {
- default-router 192.168.106.1
- dns-server 1.1.1.1
- dns-server 1.0.0.1
- lease 86400
- start 192.168.106.2 {
- stop 192.168.106.3
- }
- }
- }
- shared-network-name VLAN_107 {
- authoritative enable
- subnet 192.168.107.0/24 {
- default-router 192.168.107.1
- dns-server 1.1.1.1
- dns-server 1.0.0.1
- lease 86400
- start 192.168.107.2 {
- stop 192.168.107.2
- }
- static-mapping Lukas_ASUS {
- ip-address 192.168.107.2
- mac-address b0:6e:bf:db:e8:b4
- }
- }
- }
- shared-network-name VLAN_108_Nano {
- authoritative enable
- subnet 192.168.108.0/24 {
- default-router 192.168.108.1
- dns-server 1.1.1.1
- dns-server 1.0.0.1
- lease 86400
- start 192.168.108.2 {
- stop 192.168.108.2
- }
- static-mapping Janka_LocoM2 {
- ip-address 192.168.108.2
- mac-address 78:8a:20:a6:85:fd
- }
- }
- }
- shared-network-name VLAN_109_Nano {
- authoritative enable
- disable
- subnet 192.168.109.0/24 {
- default-router 192.168.109.1
- dns-server 1.1.1.1
- dns-server 1.0.0.1
- lease 86400
- start 192.168.109.2 {
- stop 192.168.109.2
- }
- }
- }
- static-arp disable
- use-dnsmasq disable
- }
- dns {
- forwarding {
- cache-size 150
- listen-on eth3
- listen-on eth4
- listen-on eth3.5
- listen-on eth4.102
- listen-on eth4.103
- listen-on eth4.104
- listen-on eth4.105
- listen-on eth4.106
- listen-on eth4.107
- listen-on eth4.108
- listen-on eth4.109
- }
- }
- gui {
- http-port 80
- https-port 443
- older-ciphers enable
- }
- nat {
- rule 5000 {
- description "masquerade for WAN"
- outbound-interface eth0
- type masquerade
- }
- rule 5002 {
- description "masquerade for WAN 2"
- outbound-interface eth1
- type masquerade
- }
- rule 5004 {
- description "masquerade for WAN 3"
- outbound-interface eth2
- type masquerade
- }
- rule 5005 {
- description "masquerade for WAN_LTE_VLAN9"
- log disable
- outbound-interface eth0.9
- protocol all
- type masquerade
- }
- rule 5006 {
- description "masquerade for WAN_LTE_VLAN10"
- log disable
- outbound-interface eth0.10
- protocol all
- type masquerade
- }
- }
- snmp {
- community public {
- authorization ro
- client 192.168.2.10
- }
- }
- ssh {
- port 22
- protocol-version v2
- }
- unms {
- connection wss://unms888.ddns.net:443+7RLlzLaILNwXhgN-YohBBNipa3EJdybK3pjbK9qSNMsAAAAA+allowUntrustedCertificate
- }
- }
- system {
- conntrack {
- expect-table-size 4096
- hash-size 4096
- table-size 32768
- tcp {
- half-open-connections 512
- loose enable
- max-retrans 3
- }
- }
- domain-name Edgerouter-X
- flow-accounting {
- disable-memory-table
- ingress-capture post-dnat
- interface eth0
- interface eth2
- interface eth1
- netflow {
- enable-egress {
- engine-id 1
- }
- engine-id 0
- server 35.198.77.34 {
- port 2055
- }
- timeout {
- expiry-interval 60
- flow-generic 60
- icmp 60
- max-active-life 60
- tcp-fin 10
- tcp-generic 60
- tcp-rst 10
- udp 60
- }
- version 9
- }
- syslog-facility daemon
- }
- host-name Edgerouter-X
- login {
- user ubnt {
- authentication {
- encrypted-password ****************
- plaintext-password ****************
- }
- full-name "EdgeRouter X"
- level admin
- }
- }
- name-server 1.1.1.1
- name-server 1.0.0.1
- ntp {
- server 0.ubnt.pool.ntp.org {
- }
- server 1.ubnt.pool.ntp.org {
- }
- server 2.ubnt.pool.ntp.org {
- }
- server 3.ubnt.pool.ntp.org {
- }
- }
- package {
- repository wheezy {
- components "main contrib non-free"
- distribution wheezy
- password ****************
- url http://http.us.debian.org/debian
- username ""
- }
- }
- syslog {
- global {
- facility all {
- level notice
- }
- facility protocols {
- level debug
- }
- }
- }
- time-zone Europe/Bratislava
- traffic-analysis {
- dpi enable
- export enable
- }
- }
- traffic-control {
- advanced-queue {
- filters {
- match 1 {
- attach-to 1023
- ip {
- source {
- address 192.168.102.0/24
- }
- }
- target 1
- }
- match 2 {
- attach-to 1023
- ip {
- destination {
- address 192.168.102.0/24
- }
- }
- target 2
- }
- match 3 {
- attach-to 1023
- ip {
- source {
- address 192.168.103.0/24
- }
- }
- target 3
- }
- match 4 {
- attach-to 1023
- ip {
- destination {
- address 192.168.103.0/24
- }
- }
- target 4
- }
- match 5 {
- attach-to 1023
- ip {
- source {
- address 192.168.104.0/24
- }
- }
- target 5
- }
- match 6 {
- attach-to 1023
- ip {
- destination {
- address 192.168.104.0/24
- }
- }
- target 6
- }
- match 7 {
- attach-to 1023
- ip {
- source {
- address 192.168.108.0/24
- }
- }
- target 7
- }
- match 8 {
- attach-to 1023
- ip {
- destination {
- address 192.168.108.0/24
- }
- }
- target 8
- }
- match 9 {
- attach-to 1023
- ip {
- source {
- address 192.168.107.0/24
- }
- }
- target 9
- }
- match 10 {
- attach-to 1023
- ip {
- destination {
- address 192.168.107.0/24
- }
- }
- target 10
- }
- }
- leaf {
- queue 1 {
- bandwidth 100mbit
- parent 1023
- queue-type UBNT_BQ_SFQ
- }
- queue 2 {
- bandwidth 2.5mbit
- burst {
- burst-rate 7mbit
- burst-size 1mb
- }
- parent 1023
- queue-type UBNT_BQ_SFQ
- }
- queue 3 {
- bandwidth 100mbit
- parent 1023
- queue-type UBNT_BQ_SFQ
- }
- queue 4 {
- bandwidth 2.5mbit
- burst {
- burst-rate 7mbit
- burst-size 1mb
- }
- parent 1023
- queue-type UBNT_BQ_SFQ
- }
- queue 5 {
- bandwidth 100mbit
- parent 1023
- queue-type UBNT_BQ_SFQ
- }
- queue 6 {
- bandwidth 3.5mbit
- burst {
- burst-rate 7mbit
- burst-size 1mb
- }
- parent 1023
- queue-type UBNT_BQ_SFQ
- }
- queue 7 {
- bandwidth 100mbit
- parent 1023
- queue-type UBNT_BQ_SFQ
- }
- queue 8 {
- bandwidth 2.5mbit
- burst {
- burst-rate 7mbit
- burst-size 1mb
- }
- parent 1023
- queue-type UBNT_BQ_SFQ
- }
- queue 9 {
- bandwidth 2mbit
- parent 1023
- queue-type UBNT_BQ_SFQ
- }
- queue 10 {
- bandwidth 10mbit
- parent 1023
- queue-type UBNT_BQ_SFQ
- }
- }
- queue-type {
- sfq UBNT_BQ_SFQ {
- }
- }
- root {
- queue 1023 {
- attach-to global
- bandwidth 1000mbit
- description UBNT-BQ
- }
- }
- }
- smart-queue LTE_30 {
- download {
- ecn enable
- flows 1024
- fq-quantum 1514
- limit 10240
- rate 18mbit
- }
- upload {
- ecn enable
- flows 1024
- fq-quantum 1514
- limit 10240
- rate 5mbit
- }
- wan-interface eth0.10
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement