Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /system identity
- set name=ALSiTEK
- /interface bridge
- add name=bridge1 protocol-mode=none
- /interface bridge port
- add bridge=bridge1 interface=ether2
- add bridge=bridge1 interface=ether3
- add bridge=bridge1 interface=ether4
- add bridge=bridge1 interface=ether5
- add bridge=bridge1 interface=wlan1
- /ppp profile
- add name=profile-pppoe change-tcp-mss=yes only-one=no use-compression=no use-encryption=no
- /interface pppoe-client
- add name=pppoe-out1 user=PPPOE_USER password=PPPOE_PASS interface=ether1 allow=chap profile=profile-pppoe add-default-route=yes use-peer-dns=yes disabled=no
- /interface bridge settings
- set use-ip-firewall=yes use-ip-firewall-for-pppoe=yes use-ip-firewall-for-vlan=yes
- /ip firewall connection tracking
- set enabled=yes
- /ip settings
- set rp-filter=strict
- /interface list
- add name=lan
- add name=wan
- /interface list member
- add list=lan interface=bridge1
- add list=wan interface=ether1
- add list=wan interface=pppoe-out1
- /ip address
- add interface=bridge1 address=192.168.0.1/24
- /ip pool
- add name=pool1 ranges=192.168.0.20-192.168.0.254
- /ip dhcp-server
- add name=server1 interface=bridge1 lease-time=1d add-arp=yes address-pool=pool1 always-broadcast=yes bootp-support=dynamic disabled=no
- /ip dhcp-server network
- add address=192.168.0.0/24 dns-server=192.168.0.1 gateway=192.168.0.1 ntp-server=192.168.0.1
- /ip dns
- set allow-remote-requests=yes
- /ip firewall address-list
- add address=8.8.8.8 list=DNS
- add address=8.8.4.4 list=DNS
- /ip firewall filter
- add chain=- action=log disabled=yes
- add chain=accept-FT action=fasttrack-connection
- add chain=accept-FT action=accept
- add chain=- action=log disabled=yes
- add chain=input action=jump jump-target=accept-FT in-interface-list=lan
- add chain=input action=jump jump-target=accept-FT protocol=tcp src-port=53 src-address-list=DNS
- add chain=input action=jump jump-target=accept-FT protocol=udp src-port=53 src-address-list=DNS
- add chain=input action=jump jump-target=accept-FT protocol=tcp dst-port=123 src-port=123
- add chain=input action=jump jump-target=accept-FT protocol=udp dst-port=123 src-port=123
- add chain=input action=jump jump-target=accept-FT protocol=tcp dst-port=8291
- add chain=input action=jump jump-target=accept-FT connection-state=established,related
- add chain=input action=drop
- add chain=- action=log disabled=yes
- add chain=forward action=jump jump-target=accept-FT in-interface-list=lan out-interface-list=wan
- add chain=forward action=jump jump-target=accept-FT in-interface-list=lan out-interface-list=lan
- add chain=forward action=jump jump-target=accept-FT in-interface-list=wan connection-nat-state=dstnat
- add chain=forward action=jump jump-target=accept-FT connection-state=established,related
- add chain=forward action=drop
- add chain=- action=log disabled=yes
- add chain=output action=jump jump-target=accept-FT
- /ip firewall mangle
- add chain=forward action=change-mss new-mss=clamp-to-pmtu out-interface-list=wan passthrough=yes protocol=tcp tcp-flags=syn
- add chain=postrouting action=change-mss new-mss=clamp-to-pmtu out-interface-list=wan passthrough=yes protocol=tcp tcp-flags=syn
- /ip firewall nat
- add chain=srcnat action=masquerade out-interface-list=wan
- /ip firewall raw
- add chain=- action=log disabled=yes
- add chain=accept-NOCT action=notrack
- add chain=accept-NOCT action=accept
- add chain=- action=log disabled=yes
- add chain=prerouting action=jump jump-target=accept-NOCT dst-address-type=local in-interface-list=lan protocol=tcp dst-port=53
- add chain=prerouting action=jump jump-target=accept-NOCT dst-address-type=local in-interface-list=lan protocol=udp dst-port=53
- add chain=prerouting action=jump jump-target=accept-NOCT dst-address-type=local src-address-list=DNS protocol=tcp src-port=53
- add chain=prerouting action=jump jump-target=accept-NOCT dst-address-type=local src-address-list=DNS protocol=udp src-port=53
- add chain=prerouting action=drop dst-address-type=local in-interface-list=wan protocol=tcp dst-port=53
- add chain=prerouting action=drop dst-address-type=local in-interface-list=wan protocol=udp dst-port=53
- add chain=- action=log disabled=yes
- add chain=output action=jump jump-target=accept-NOCT dst-address-list=DNS protocol=tcp dst-port=53
- add chain=output action=jump jump-target=accept-NOCT dst-address-list=DNS protocol=udp dst-port=53
- /ip ipsec policy
- set 0 disabled=yes
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set www disabled=yes
- set ssh disabled=yes
- set api disabled=yes
- set api-ssl disabled=yes
- /system clock
- set time-zone-autodetect=no
- /system clock manual
- set time-zone=+03:00
- /system ntp client
- set enabled=yes primary-ntp=0.pool.ntp.org secondary-ntp=1.pool.ntp.org
- /system ntp server
- set broadcast=yes broadcast-addresses=192.168.0.255 enabled=yes
- /ip upnp interfaces
- add interface=bridge1 type=internal
- add interface=pppoe-out1 type=external
- /ip ipsec proposal
- set [ find default=yes ] disabled=yes
- /ip neighbor discovery
- set ether1 discover=no
- set wlan1 discover=no
- set pppoe-out1 discover=no
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement