Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # mar/20/2020 17:48:08 by RouterOS 6.46.4
- # software id = D0RZ-Z0QJ
- #
- # model = RB962UiGS-5HacT2HnT
- # serial number = BEC40A57A931
- /interface bridge
- add name=bridge-main
- add name=bridge-wlan
- /interface ethernet
- set [ find default-name=ether1 ] name=ether1-wan
- set [ find default-name=ether2 ] name=ether2-wan
- set [ find default-name=ether3 ] name=ether3-wan
- set [ find default-name=ether4 ] name=ether4-lan
- set [ find default-name=ether5 ] name=ether5-trust
- set [ find default-name=sfp1 ] disabled=yes
- /interface wireless
- set [ find default-name=wlan1 ] band=2ghz-b/g/n country=ukraine disabled=no \
- frequency=auto mode=ap-bridge ssid=IvaHouse-2.4GHz wireless-protocol=\
- 802.11
- set [ find default-name=wlan2 ] band=5ghz-a/n/ac country=ukraine disabled=no \
- frequency=auto mode=ap-bridge ssid=IvaHouse-5GHz wireless-protocol=802.11
- /interface vlan
- add interface=ether5-trust name=vlan-srv157 vlan-id=157
- add interface=ether5-trust name=vlan-srv158 vlan-id=158
- add interface=ether5-trust name=vlan-usr192 vlan-id=192
- add interface=bridge-wlan name=vlan-wlan vlan-id=168
- /interface list
- add name=WAN
- add name=LAN
- /interface wireless security-profiles
- set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk mode=\
- dynamic-keys supplicant-identity=MikroTik
- /ip hotspot profile
- set [ find default=yes ] html-directory=flash/hotspot
- /ip pool
- add name=dhcp ranges=10.0.10.100-10.0.10.199
- add name=dhcp-srv157 ranges=10.0.20.100-10.0.20.199
- add name=dhcp-srv158 ranges=10.0.30.100-10.0.30.199
- add name=dhcp-usr192 ranges=192.168.10.100-192.168.10.199
- add name=dhcp-wlan ranges=192.168.0.100-192.168.0.199
- /ip dhcp-server
- add address-pool=dhcp disabled=no interface=bridge-main name=dhcp-main
- add address-pool=dhcp-srv157 disabled=no interface=vlan-srv157 name=\
- dhcp-srv157
- add address-pool=dhcp-srv158 disabled=no interface=vlan-srv158 name=\
- dhcp-srv158
- add address-pool=dhcp-usr192 disabled=no interface=vlan-usr192 name=\
- dhcp-usr192
- add address-pool=dhcp-wlan disabled=no interface=bridge-wlan name=dhcp-wlan
- /interface bridge port
- add bridge=bridge-main interface=ether4-lan
- add bridge=bridge-main interface=ether5-trust
- add bridge=bridge-wlan interface=wlan2
- add bridge=bridge-wlan interface=wlan1
- add bridge=bridge-wlan interface=vlan-wlan
- /ip neighbor discovery-settings
- set discover-interface-list=LAN
- /interface detect-internet
- set detect-interface-list=all
- /interface ethernet switch vlan
- add independent-learning=no ports=ether5-trust switch=switch1 vlan-id=1
- add independent-learning=no ports=ether5-trust switch=switch1 vlan-id=157
- add independent-learning=no ports=ether5-trust switch=switch1 vlan-id=158
- /interface list member
- add interface=ether1-wan list=WAN
- add interface=bridge-main list=LAN
- /ip address
- add address=10.0.10.251/24 interface=ether4-lan network=10.0.10.0
- add address=10.0.20.251/24 interface=vlan-srv157 network=10.0.20.0
- add address=10.0.30.251/24 interface=vlan-srv158 network=10.0.30.0
- add address=192.168.10.251/24 interface=vlan-usr192 network=192.168.10.0
- add address=192.168.0.251/24 interface=bridge-wlan network=192.168.0.0
- /ip dhcp-client
- add disabled=no interface=ether1-wan
- add disabled=no interface=ether2-wan
- add disabled=no interface=ether3-wan
- /ip dhcp-server network
- add address=10.0.10.0/24 dns-server=193.25.176.1,193.25.176.100 domain=\
- rd.main gateway=10.0.10.251 netmask=24
- add address=10.0.20.0/24 dns-server=193.25.176.1,193.25.176.100 domain=rd.srv \
- gateway=10.0.20.251 netmask=24
- add address=10.0.30.0/24 dns-server=193.25.176.1,193.25.176.100 domain=rd.srv \
- gateway=10.0.30.251 netmask=24
- add address=192.168.0.0/24 dns-server=193.25.176.1,193.25.176.100 domain=\
- rd.user gateway=192.168.0.251 netmask=24
- add address=192.168.10.0/24 dns-server=193.25.176.1,193.25.176.100 domain=\
- rd.user gateway=192.168.10.251 netmask=24
- /ip dns
- set allow-remote-requests=yes
- /ip firewall address-list
- add address=10.0.10.0/24 list=localnet
- add address=10.0.20.0/24 list=localnet
- add address=10.0.30.0/24 list=localnet
- /ip firewall filter
- add action=accept chain=input protocol=icmp
- add action=accept chain=input connection-state=established
- add action=accept chain=input connection-state=related
- add action=drop chain=input in-interface-list=!LAN
- add action=accept chain=input dst-port=80 protocol=tcp
- /ip firewall mangle
- add action=mark-connection chain=input dst-address=193.***.***.156 \
- in-interface=ether1-wan new-connection-mark=156 passthrough=yes
- add action=mark-connection chain=input dst-address=193.***.***.157 \
- in-interface=ether2-wan new-connection-mark=157 passthrough=yes
- add action=mark-connection chain=input dst-address=193.***.***.158 \
- in-interface=ether3-wan new-connection-mark=158 passthrough=yes
- add action=mark-routing chain=output connection-mark=156 new-routing-mark=\
- 156-ip out-interface=ether1-wan passthrough=yes src-address=10.0.10.0/24
- add action=mark-routing chain=output connection-mark=156 new-routing-mark=\
- 156-ip out-interface=ether1-wan passthrough=yes src-address=\
- 192.168.0.0/24
- add action=mark-routing chain=output connection-mark=156 new-routing-mark=\
- 156-ip out-interface=ether1-wan passthrough=yes src-address=\
- 192.168.10.0/24
- add action=mark-routing chain=output connection-mark=157 new-routing-mark=\
- 157-ip out-interface=ether2-wan passthrough=yes src-address=10.0.20.0/24
- add action=mark-routing chain=output connection-mark=158 new-routing-mark=\
- 158-ip out-interface=ether3-wan passthrough=yes src-address=10.0.30.0/24
- /ip firewall nat
- add action=masquerade chain=srcnat out-interface-list=WAN
- add action=masquerade chain=srcnat out-interface=ether1-wan
- add action=masquerade chain=srcnat out-interface=ether2-wan
- add action=masquerade chain=srcnat out-interface=ether3-wan
- add action=src-nat chain=srcnat disabled=yes out-interface=ether1-wan \
- src-address=10.0.10.0/24 to-addresses=193.***.***.156
- add action=src-nat chain=srcnat disabled=yes out-interface=ether2-wan \
- src-address=10.0.20.0/24 to-addresses=193.***.***.157
- add action=src-nat chain=srcnat disabled=yes out-interface=ether3-wan \
- src-address=10.0.30.0/24 to-addresses=193.***.***.158
- add action=src-nat chain=srcnat disabled=yes out-interface=ether1-wan \
- src-address=192.168.0.0/24 to-addresses=193.***.***.156
- add action=src-nat chain=srcnat disabled=yes out-interface=ether1-wan \
- src-address=192.168.10.0/24 to-addresses=193.***.***.156
- add action=netmap chain=dstnat dst-address=193.***.***.157 dst-port=8080 \
- protocol=tcp to-addresses=10.0.20.25 to-ports=8080
- add action=netmap chain=dstnat dst-address=193.***.***.157 dst-port=80 \
- protocol=tcp to-addresses=10.0.20.25 to-ports=80
- add action=netmap chain=dstnat dst-address=193.***.***.157 dst-port=443 \
- protocol=tcp to-addresses=10.0.20.25 to-ports=443
- add action=netmap chain=dstnat dst-address=193.***.***.157 dst-port=25 \
- protocol=tcp to-addresses=10.0.20.25 to-ports=25
- add action=netmap chain=dstnat dst-address=193.***.***.157 dst-port=587 \
- protocol=tcp to-addresses=10.0.20.25 to-ports=587
- add action=netmap chain=dstnat dst-address=193.***.***.157 dst-port=465 \
- protocol=tcp to-addresses=10.0.20.25 to-ports=465
- add action=netmap chain=dstnat dst-address=193.***.***.157 dst-port=110 \
- protocol=tcp to-addresses=10.0.20.25 to-ports=110
- add action=netmap chain=dstnat dst-address=193.***.***.157 dst-port=995 \
- protocol=tcp to-addresses=10.0.20.25 to-ports=995
- add action=netmap chain=dstnat dst-address=193.***.***.157 dst-port=993 \
- protocol=tcp to-addresses=10.0.20.25 to-ports=993
- add action=netmap chain=dstnat dst-address=193.***.***.157 dst-port=53 \
- protocol=tcp to-addresses=10.0.20.25 to-ports=53
- add action=netmap chain=dstnat dst-address=193.***.***.157 dst-port=3306 \
- protocol=tcp to-addresses=10.0.20.25 to-ports=3306
- add action=netmap chain=dstnat dst-address=193.***.***.158 dst-port=8080 \
- protocol=tcp to-addresses=10.0.30.35 to-ports=8080
- add action=netmap chain=dstnat dst-address=193.***.***.158 dst-port=80 \
- protocol=tcp to-addresses=10.0.30.35 to-ports=80
- add action=netmap chain=dstnat dst-address=193.***.***.158 dst-port=443 \
- protocol=tcp to-addresses=10.0.30.35 to-ports=443
- add action=netmap chain=dstnat dst-address=193.***.***.158 dst-port=25 \
- protocol=tcp to-addresses=10.0.30.35 to-ports=25
- add action=netmap chain=dstnat dst-address=193.***.***.158 dst-port=587 \
- protocol=tcp to-addresses=10.0.30.35 to-ports=587
- add action=netmap chain=dstnat dst-address=193.***.***.158 dst-port=465 \
- protocol=tcp to-addresses=10.0.30.35 to-ports=465
- add action=netmap chain=dstnat dst-address=193.***.***.158 dst-port=110 \
- protocol=tcp to-addresses=10.0.30.35 to-ports=110
- add action=netmap chain=dstnat dst-address=193.***.***.158 dst-port=995 \
- protocol=tcp to-addresses=10.0.30.35 to-ports=995
- add action=netmap chain=dstnat dst-address=193.***.***.158 dst-port=993 \
- protocol=tcp to-addresses=10.0.30.35 to-ports=993
- add action=netmap chain=dstnat dst-address=193.***.***.158 dst-port=53 \
- protocol=tcp to-addresses=10.0.30.35 to-ports=53
- add action=netmap chain=dstnat dst-address=193.***.***.158 dst-port=3306 \
- protocol=tcp to-addresses=10.0.30.35 to-ports=3306
- add action=netmap chain=dstnat dst-address=193.***.***.158 dst-port=1500 \
- protocol=tcp to-addresses=10.0.30.35 to-ports=1500
- add action=netmap chain=dstnat dst-address=193.***.***.158 dst-port=8006 \
- protocol=tcp to-addresses=10.0.30.30 to-ports=8006
- add action=netmap chain=dstnat dst-address=193.***.***.158 dst-port=86 \
- protocol=tcp to-addresses=10.0.30.30 to-ports=22
- add action=netmap chain=dstnat dst-address=193.***.***.158 dst-port=22 \
- protocol=tcp to-addresses=10.0.30.35 to-ports=22
- add action=netmap chain=dstnat dst-address=193.***.***.156 dst-port=27016 \
- protocol=tcp to-addresses=10.0.10.10 to-ports=27016
- /ip route
- add distance=1 gateway=193.25.176.1%ether1-wan routing-mark=156-ip
- add distance=1 gateway=193.25.176.1%ether2-wan routing-mark=157-ip
- add distance=1 gateway=193.25.176.1%ether3-wan routing-mark=158-ip
- /ip route rule
- add action=lookup-only-in-table dst-address=10.0.0.0/8 table=main
- add action=lookup-only-in-table dst-address=192.168.0.0/16 table=main
- add src-address=193.***.***.156/32 table=156-ip
- add src-address=193.***.***.157/32 table=157-ip
- add src-address=193.***.***.158/32 table=158-ip
- add src-address=10.0.10.0/24 table=156-ip
- add src-address=10.0.20.0/24 table=157-ip
- add src-address=10.0.30.0/24 table=158-ip
- add src-address=192.168.0.0/24 table=156-ip
- add src-address=192.168.10.0/24 table=156-ip
- /ip upnp
- set enabled=yes
- /ip upnp interfaces
- add interface=bridge-main type=internal
- add interface=ether1-wan type=external
- /system clock
- set time-zone-name=Europe/Kiev
- /system identity
- set name=rd-router
- /tool mac-server
- set allowed-interface-list=LAN
- /tool mac-server mac-winbox
- set allowed-interface-list=LAN
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement