Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # feb/05/2018 08:45:50 by RouterOS 6.41
- #
- # model = RouterBOARD 3011UiAS
- # serial number =
- /interface bridge
- add admin-mac=xxxxxxxxxxxx auto-mac=no comment=defconf fast-forward=no \
- name=bridge
- /interface ethernet
- set [ find default-name=ether1 ] comment=VIdeo
- set [ find default-name=ether2 ] comment=R-Line
- set [ find default-name=ether3 ] comment=ELCO
- set [ find default-name=ether5 ] arp=proxy-arp comment=LAN
- set [ find default-name=ether6 ] comment=Other name=ether6-master
- set [ find default-name=sfp1 ] disabled=yes
- /interface eoip
- add !keepalive mac-address=02:C4:B7:5D:F9:DF name=eoip-over-ellco \
- remote-address=172.16.16.15 tunnel-id=14
- add !keepalive mac-address=02:DC:54:37:AE:6B name=eoip-over-local \
- remote-address=172.16.16.11 tunnel-id=10
- add !keepalive mac-address=02:C4:B7:5D:F9:DF mtu=1480 name=eoip-over-rline \
- remote-address=172.16.16.13 tunnel-id=12
- /interface list
- add name=wan
- add exclude=dynamic name=discover
- add name=mactel
- add name=mac-winbox
- /interface wireless security-profiles
- set [ find default=yes ] supplicant-identity=MikroTik
- /ip dhcp-server
- add authoritative=after-2sec-delay interface=bridge name=defconf
- /ip pool
- add name=default-dhcp ranges=192.168.0.10-192.168.0.30
- add name=vpn_clients ranges=192.168.192.20-192.168.192.253
- /ppp profile
- add local-address=192.168.192.1 name=vpn_client_profile remote-address=\
- vpn_clients
- add change-tcp-mss=yes name=rline use-compression=yes use-encryption=yes \
- use-mpls=yes use-upnp=yes
- /interface bridge port
- add bridge=bridge hw=no interface=ether5
- add bridge=bridge interface=eoip-over-ellco
- add bridge=bridge interface=eoip-over-local
- add bridge=bridge interface=eoip-over-rline
- /ip neighbor discovery-settings
- set discover-interface-list=discover
- /interface list member
- add interface=Internet-Ellco list=wan
- add interface=Internet-Rline list=wan
- add interface=ether2 list=discover
- add interface=ether3 list=discover
- add interface=ether4 list=discover
- add interface=ether5 list=discover
- add interface=sfp1 list=discover
- add list=discover
- add interface=ether7 list=discover
- add interface=ether8 list=discover
- add interface=ether9 list=discover
- add interface=ether10 list=discover
- add interface=bridge list=discover
- add interface=Internet-Rline list=discover
- add interface=Internet-Ellco list=discover
- add interface=pptp-in-axbax list=discover
- add list=discover
- add list=discover
- add list=discover
- add list=discover
- add list=discover
- add list=discover
- add interface=pptp-in-7k list=discover
- add list=discover
- add interface=pptp-in-roche list=discover
- add list=discover
- add interface=bridge list=mactel
- add interface=bridge list=mac-winbox
- /interface pptp-server server
- set enabled=yes
- /ip address
- add address=192.168.0.121/24 comment=LAN interface=ether5 network=192.168.0.0
- /ip dhcp-client
- add comment=defconf dhcp-options=hostname,clientid interface=ether1
- add add-default-route=no comment="rline dhcp ip" dhcp-options=\
- hostname,clientid disabled=no interface=ether2 use-peer-dns=no
- /ip dns
- set allow-remote-requests=yes servers=77.88.8.8
- /ip dns static
- add address=10.1.238.117 name=router
- /ip firewall address-list
- add address=192.168.0.47 comment="free wifi" list=toEllco
- add address=192.168.0.61 list=toEllco
- add address=192.168.0.60 list=toEllco
- add address=192.168.0.205 comment=manager26 disabled=yes list=toEllco
- /ip firewall filter
- add action=accept chain=input comment=" Allow Ping" protocol=icmp
- add action=accept chain=forward protocol=icmp
- add action=accept chain=input comment="Accept established connections" \
- connection-state=established
- add action=accept chain=forward connection-state=established
- add action=accept chain=input comment="Accept related connections" \
- connection-state=related
- add action=accept chain=forward connection-state=related
- add action=drop chain=input comment="drop dns flood" dst-port=53 \
- in-interface=Internet-Rline log-prefix=dns-dlood-rline protocol=udp
- add action=drop chain=input dst-port=53 in-interface=Internet-Ellco \
- log-prefix=dns-dlood-ellco protocol=udp
- add action=drop chain=input comment="Drop invalid connections" \
- connection-state=invalid
- add action=drop chain=forward connection-state=invalid
- add action=accept chain=input comment="Allow UDP" protocol=udp
- add action=accept chain=forward protocol=udp
- /ip firewall mangle
- add action=change-mss chain=forward comment="emran mangle version" disabled=\
- yes new-mss=clamp-to-pmtu out-interface=Internet-Rline passthrough=no \
- protocol=tcp tcp-flags=syn tcp-mss=1430-65535
- add action=change-mss chain=forward new-mss=clamp-to-pmtu out-interface=\
- Internet-Rline passthrough=no protocol=tcp tcp-flags=syn tcp-mss=\
- 1408-65535
- add action=change-mss chain=forward comment="emran mangle version" new-mss=\
- clamp-to-pmtu out-interface=Internet-Ellco passthrough=no protocol=tcp \
- tcp-flags=syn tcp-mss=1451-65535
- add action=mark-routing chain=prerouting comment="VH toEllco" \
- new-routing-mark=VH passthrough=no src-address-list=toEllco
- /ip firewall nat
- add action=masquerade chain=srcnat comment="defconf: masquerade" \
- out-interface-list=wan src-address=192.168.0.0/24
- add action=masquerade chain=srcnat out-interface=ether1
- add action=masquerade chain=srcnat comment="vpn_clients NAT rule" \
- src-address=192.168.192.0/24
- add action=masquerade chain=srcnat out-interface=all-ppp
- /ip firewall service-port
- set ftp disabled=yes
- set tftp disabled=yes
- set irc disabled=yes
- set h323 disabled=yes
- set sip disabled=yes sip-direct-media=no
- set udplite disabled=yes
- set sctp disabled=yes
- /ip route
- add distance=1 gateway=Internet-Ellco routing-mark=VH
- add distance=2 gateway=Internet-Rline routing-mark=VH
- add disabled=yes distance=20 gateway=Internet-Ellco routing-mark=wan2_route
- add disabled=yes distance=20 gateway=Internet-Rline routing-mark=wan1_route
- add distance=1 gateway=Internet-Rline
- add distance=2 gateway=Internet-Ellco
- /ip route rule
- add action=lookup-only-in-table routing-mark=wan2_route table=wan2_route
- add action=lookup-only-in-table routing-mark=wan1_route table=wan1_route
- /lcd
- set time-interval=hour
- /lcd interface
- add
- /lcd interface pages
- set 0 interfaces=\
- ether1,ether2,ether3,ether4,ether5,sfp1,*7,ether7,ether8,ether9,ether10
- /system clock
- set time-zone-name=Europe/Moscow
- /system logging
- add topics=pptp,pppoe
- /system ntp client
- set enabled=yes primary-ntp=85.21.78.91 secondary-ntp=77.73.232.17
- /tool mac-server
- set allowed-interface-list=mactel
- /tool mac-server mac-winbox
- set allowed-interface-list=mac-winbox
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement