Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /ip ipsec mode-config
- add address=172.16.1.2 address-prefix-length=32 name=GRE split-include=\
- 172.16.1.1/32 system-dns=no
- /ip ipsec policy group
- add name=IKE2
- add name=GRE
- /ip ipsec profile
- set [ find default=yes ] dh-group=modp2048 enc-algorithm=aes-256,aes-128 \
- lifetime=15m
- add enc-algorithm=aes-256,aes-128 name=IKE2
- /ip ipsec peer
- add exchange-mode=ike2 name=IKE2 passive=yes profile=IKE2 \
- send-initial-contact=no
- /ip ipsec proposal
- set [ find default=yes ] auth-algorithms=sha256,sha1 enc-algorithms=\
- aes-256-cbc,aes-128-cbc pfs-group=none
- add auth-algorithms=sha256,sha1 enc-algorithms=aes-256-cbc,aes-128-cbc name=\
- IKE2 pfs-group=none
- /ip pool
- add name=Gabi_DHCP ranges=10.10.11.100-10.10.11.200
- add name=WIFI ranges=10.10.12.100-10.10.12.200
- add name=LAN ranges=10.10.100.150-10.10.100.200
- add name=IKE2 ranges=10.10.13.10-10.10.13.100
- /ip dhcp-server
- add address-pool=Gabi_DHCP disabled=no interface=ether5 lease-time=1h name=\
- Gabi_DHCP
- add address-pool=WIFI disabled=no interface=WIFI name=WIFI
- add address-pool=LAN disabled=no interface=ether2 name=LAN
- /ip ipsec mode-config
- add address-pool=IKE2 address-prefix-length=32 name=IKE2
- /ip address
- add address=10.10.100.1/24 interface=ether2 network=10.10.100.0
- add address=10.10.110.1/24 interface=ether3 network=10.10.110.0
- add address=10.10.120.1/24 interface=ether4 network=10.10.120.0
- add address=10.10.11.1/24 interface=ether5 network=10.10.11.0
- add address=10.10.12.1/24 interface=WIFI network=10.10.12.0
- add address=172.16.1.1 interface=GRE_Site_to_Site network=172.16.1.1
- /ip dhcp-server network
- add address=10.10.11.0/24 dns-server=8.8.8.8,8.8.4.4 gateway=10.10.11.1
- add address=10.10.12.0/24 gateway=10.10.12.1
- add address=10.10.100.0/24 gateway=10.10.100.1
- /ip firewall filter
- add action=accept chain=input dst-port=2250,8291 protocol=tcp
- add action=accept chain=input dst-port=500,1701,4500 protocol=udp
- add action=accept chain=input protocol=ipsec-esp
- add action=accept chain=input protocol=icmp tcp-flags=""
- add action=accept chain=input protocol=gre
- add action=accept chain=input in-interface=ether4 protocol=ospf
- add action=accept chain=input connection-state=established,related
- add action=drop chain=input connection-state=invalid
- add action=drop chain=input
- add action=accept chain=forward ipsec-policy=in,ipsec
- add action=accept chain=forward ipsec-policy=out,ipsec
- add action=fasttrack-connection chain=forward connection-state=\
- established,related
- add action=accept chain=forward connection-state=established,related,new
- add action=drop chain=forward connection-state=invalid
- /ip firewall mangle
- add action=change-mss chain=forward new-mss=1300 out-interface=DIGI_PPPoE \
- passthrough=yes protocol=tcp src-address=10.10.13.0/24 tcp-flags=syn
- /ip firewall nat
- add action=masquerade chain=srcnat out-interface=DIGI_PPPoE
- add action=dst-nat chain=dstnat dst-port=50000 in-interface=DIGI_PPPoE \
- protocol=tcp to-addresses=10.10.14.10 to-ports=50000
- add action=dst-nat chain=dstnat dst-port=50000 in-interface=DIGI_PPPoE \
- protocol=tcp to-addresses=10.10.100.50 to-ports=50000
- add action=dst-nat chain=dstnat dst-port=15000 in-interface=DIGI_PPPoE \
- protocol=tcp to-addresses=10.10.110.2 to-ports=15000
- add action=dst-nat chain=dstnat disabled=yes dst-port=12022 in-interface=\
- DIGI_PPPoE protocol=tcp to-addresses=10.10.11.140 to-ports=12002
- add action=dst-nat chain=dstnat dst-port=12002 in-interface=DIGI_PPPoE \
- protocol=tcp to-addresses=10.10.11.140 to-ports=12002
- add action=dst-nat chain=dstnat dst-port=22220 in-interface=DIGI_PPPoE \
- protocol=tcp to-addresses=10.10.11.118 to-ports=22220
- add action=dst-nat chain=dstnat dst-port=22220 in-interface=DIGI_PPPoE \
- protocol=udp to-addresses=10.10.11.118 to-ports=22220
- add action=dst-nat chain=dstnat disabled=yes dst-port=8001 in-interface=\
- DIGI_PPPoE protocol=tcp to-addresses=10.10.110.3 to-ports=8001
- add action=dst-nat chain=dstnat disabled=yes dst-port=8888 in-interface=\
- DIGI_PPPoE protocol=tcp to-addresses=10.10.11.140 to-ports=8888
- add action=dst-nat chain=dstnat disabled=yes dst-port=80 in-interface=\
- DIGI_PPPoE protocol=tcp to-addresses=10.10.110.3 to-ports=80
- /ip ipsec identity
- add auth-method=digital-signature certificate=server generate-policy=\
- port-strict mode-config=IKE2 peer=IKE2 policy-template-group=IKE2
- add generate-policy=port-strict mode-config=GRE peer=IKE2 \
- policy-template-group=GRE secret=Laci19881124
- /ip ipsec policy
- add dst-address=10.10.13.0/24 group=IKE2 proposal=IKE2 src-address=0.0.0.0/0 \
- template=yes
- add dst-address=172.16.1.2/32 group=GRE proposal=IKE2 src-address=\
- 172.16.1.1/32 template=yes
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set www disabled=yes
- set ssh address=10.10.100.50/32,10.10.14.0 port=2250
- set api disabled=yes
- set api-ssl disabled=yes
- /ip ssh
- set forwarding-enabled=remote strong-crypto=yes
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement