Advertisement
Guest User

Untitled

a guest
Feb 18th, 2020
133
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.95 KB | None | 0 0
  1.  
  2. /export file=BACKUP_ANTES_DO_SGP
  3. :global PASSVPNUSER "KzBSaQdCsP3Gb7Z"
  4. :global AUC "1812"
  5. :global ACC "1813"
  6. :global RADIUS "128.201.199.226"
  7. :global TOKENAQUI "91c355fe-94cf-4ec7-b0a9-653dbaf16e81"
  8. :global LINKDOSGP "http://128.201.199.226:8000"
  9. :global IP "128.201.199.226 "
  10. :global AVS "6402"
  11. :global BLQ "6403"
  12.  
  13. /ip firewall address-list
  14. add address=$IP list=SITES-LIBERADOS
  15. add address=208.67.222.222 list=SITES-LIBERADOS
  16. add address=208.67.222.220 list=SITES-LIBERADOS
  17. add address=8.8.8.8 list=SITES-LIBERADOS
  18. add address=8.8.4.4 list=SITES-LIBERADOS
  19. add address=1.1.1.1 list=SITES-LIBERADOS
  20. add address=45.227.76.22 list=SITES-LIBERADOS
  21. add address=45.227.79.1 list=SITES-LIBERADOS
  22. add address=10.24.0.0/22 list=BLOQUEADOS
  23. /ip firewall filter
  24. add action=drop chain=forward dst-address-list=!SITES-LIBERADOS src-address-list=BLOQUEADOS comment="SGP REGRAS"
  25. /ip firewall filter
  26. add chain=forward connection-mark=BLOQUEIO-AVISAR action=add-src-to-address-list \
  27. address-list=BLOQUEIO-AVISADOS address-list-timeout=2h comment="SGP REGRAS" dst-address=$IP dst-port=$AVS protocol=tcp
  28. /ip firewall nat
  29. add action=accept chain=srcnat comment="NAO FAZER NAT PARA O IP DO RADIUS" \
  30. dst-address=$RADIUS dst-port="$AUC-$ACC,3799" protocol=udp
  31. add action=masquerade chain=srcnat comment="SGP REGRAS" src-address-list=\
  32. BLOQUEADOS
  33. add action=dst-nat chain=dstnat comment="SGP REGRAS" dst-address-list=\
  34. !SITES-LIBERADOS dst-port=80,443 log-prefix="" protocol=tcp \
  35. src-address-list=BLOQUEADOS to-addresses=$IP to-ports=$BLQ
  36. add action=dst-nat chain=dstnat comment="SGP REGRAS" connection-mark=\
  37. BLOQUEIO-AVISAR log-prefix="" protocol=tcp to-addresses=$IP to-ports=$AVS
  38. # Aviso bloqueio
  39. /ip firewall mangle
  40. add chain=prerouting connection-state=new src-address-list=BLOQUEIO-AVISAR protocol=tcp dst-port=80,443 \
  41. action=mark-connection new-connection-mark=BLOQUEIO-VERIFICAR passthrough=yes comment="SGP REGRAS"
  42. add chain=prerouting connection-mark=BLOQUEIO-VERIFICAR src-address-list=!BLOQUEIO-AVISADOS \
  43. action=mark-connection new-connection-mark=BLOQUEIO-AVISAR comment="SGP REGRAS"
  44. /system scheduler
  45. add interval=1h name=sgp-aviso on-event=sgp-aviso policy=\
  46. ftp,reboot,read,write,policy,test,password,sniff,sensitive start-date=\
  47. may/29/2017 start-time=01:00:00
  48. /system script
  49. add name=sgp-aviso policy=\
  50. ftp,reboot,read,write,policy,test,password,sniff,sensitive source=":log info\
  51. \_\"sgp aviso\";\r\
  52. \n/file remove [find where name=sgp_aviso.rsc]\r\
  53. \n/tool fetch url=\"$LINKDOSGP/ws/mikrotik/aviso/pendencia/\?token=$TOKENAQUI&app=mikrotik\" dst-path=sgp_aviso.rsc;\r\
  54. \n:delay 30s\r\
  55. \nimport file-name=sgp_aviso.rsc;"
  56. /ip accounting set account-local-traffic=yes enabled=yes
  57. /system ntp client set enabled=yes primary-ntp=200.160.0.8
  58. /system clock set time-zone-name=America/Recife
  59. /radius incoming set accept=yes
  60. /ip service
  61. set api disabled=no port=3540
  62. set www disabled=no port=8008
  63. /user aaa set use-radius=yes
  64. /ppp aaa set interim-update=5m use-radius=yes
  65. /interface pppoe-server server set authentication=pap [ find where .id!=999]
  66. /interface pppoe-server server set one-session-per-host=no [find .id!=999]
  67. /tool graphing set page-refresh=300 store-every=5min
  68. /tool graphing interface add allow-address=$RADIUS disabled=no interface=all store-on-disk=yes
  69. /tool graphing queue add allow-address=$RADIUS allow-target=yes disabled=no simple-queue=all store-on-disk=yes
  70. /tool graphing resource add allow-address=$RADIUS disabled=no store-on-disk=yes
  71. /snmp community add addresses=$RADIUS name=SGP-GRAPHICs
  72. /snmp set enabled=yes trap-community=SGP-GRAPHICs trap-version=2
  73. /system logging set 0 action=memory disabled=no prefix="" topics=info,!account
  74. /radius
  75. add comment="RADIUS SGP" secret=sgp@radius service=ppp,dhcp,login address=$RADIUS accounting-port=$ACC authentication-port=$AUC \
  76. timeout=00:00:03
  77. /user add name=SGP comment="USUARIO QUE O SERVIDOR SGP ACESSA A RB" group=full password=$PASSVPNUSER
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement