Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /interface bridge
- add name=VLAN10-VPN protocol-mode=none
- add name=VLAN20-LOCAL protocol-mode=none
- /interface ethernet
- set [ find default-name=ether1 ] name=ether1-gateway
- set [ find default-name=ether2 ] name=ether2-gateway2
- set [ find default-name=ether3 ] name=ether3-TRUNK
- set [ find default-name=ether4 ] name=ether4-VPN
- set [ find default-name=ether5 ] name=ether5-LOCAL
- /interface pppoe-client
- add add-default-route=yes disabled=no interface=ether1-gateway max-mru=1480 max-mtu=1480 mrru=1600 name=pppoe-out1 password=antel user=antel
- add add-default-route=yes default-route-distance=1 disabled=no interface=ether2-gateway2 name=pppoe-out2 password=antel user=antel
- /interface vlan
- add interface=ether3-TRUNK name=LOCAL vlan-id=20
- add interface=ether3-TRUNK name=VPN vlan-id=10
- /ppp profile
- add change-tcp-mss=yes local-address=10.11.19.2 name=OPENVPN remote-address=10.11.19.1
- /interface ovpn-client
- add certificate="saeta (1).crt_0" cipher=aes128 connect-to=190.64.65.123 mac-address=02:E9:30:F3:7A:33 name=ovpn-out1 port=1195 profile=OPENVPN user=saeta
- /interface bridge port
- add bridge=VLAN10-VPN interface=VPN
- add bridge=VLAN20-LOCAL interface=LOCAL
- add bridge=VLAN10-VPN interface=ether4-VPN
- add bridge=VLAN20-LOCAL interface=ether5-LOCAL
- /ip address
- add address=10.2.10.1/24 interface=VLAN10-VPN network=10.2.10.0
- add address=10.2.255.1/24 interface=VLAN10-VPN network=10.2.255.0
- /ip firewall filter
- add action=accept chain=input src-address=190.64.65.123
- add action=accept chain=output
- add action=accept chain=forward comment="default configuration"
- add action=drop chain=input comment="default configuration" connection-state=new in-interface=pppoe-out1
- add action=drop chain=input connection-state=new in-interface=pppoe-out2
- add action=accept chain=input comment="default configuration" connection-state=invalid,established,related,new
- /ip firewall nat
- add action=dst-nat chain=dstnat dst-port=12345-12350 protocol=udp to-addresses=10.2.255.10 to-ports=12345-12350
- add action=masquerade chain=srcnat comment="default configuration" out-interface=pppoe-out1
- add action=masquerade chain=srcnat out-interface=pppoe-out2
- /ip route
- add distance=1 dst-address=10.11.0.0/20 gateway=ovpn-out1
- /routing igmp-proxy interface
- add
- add alternative-subnets=224.0.0.0/4,169.254.0.0/16,10.2.10.0/24 interface=ether2-gateway2 upstream=yes
- /system clock
- set time-zone-name=America/Montevideo
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement