Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [admin@MikroTik] > /export
- # jul/30/2017 01:25:15 by RouterOS 6.41rc3
- # software id = B4SW-VDRD
- #
- # model = 951Ui-2HnD
- # serial number = 5581040CB71C
- /interface lte
- set [ find ] apn="" disabled=yes mac-address=58:2C:80:13:92:63 name=lte1
- /interface bridge
- add admin-mac=4C:5E:0C:E0:54:EE arp=proxy-arp auto-mac=no comment="created from master port" igmp-snooping=no mtu=1500 name=br1-lan \
- protocol-mode=none
- /interface ethernet
- set [ find default-name=ether1 ] name=eth1-wan
- set [ find default-name=ether2 ] name=eth2-lan
- set [ find default-name=ether3 ] name=eth3-lan
- set [ find default-name=ether4 ] name=eth4-lan
- set [ find default-name=ether5 ] name=eth5-lan
- /interface pppoe-client
- add add-default-route=yes disabled=no interface=eth1-wan name=tap1-wan password=xxx user=xxx
- /interface pptp-server
- add name=pptp-in1 user=vpn
- /interface wireless security-profiles
- add authentication-types=wpa-psk,wpa2-psk eap-methods="" management-protection=allowed mode=dynamic-keys name=wpa2-protect \
- supplicant-identity="" wpa-pre-shared-key=xxx wpa2-pre-shared-key=xxx
- /interface wireless
- set [ find default-name=wlan1 ] band=2ghz-b/g/n disabled=no frequency=auto mode=ap-bridge security-profile=wpa2-protect ssid=omgwtfbbq \
- wireless-protocol=802.11
- /interface wireless nstreme
- set wlan1 enable-polling=no
- /ip pool
- add name=dhcp-pc ranges=10.0.0.2-10.0.0.50
- /ip dhcp-server
- add address-pool=dhcp-pc disabled=no interface=br1-lan lease-time=8h name=dhcp-pc
- /interface bridge port
- add bridge=br1-lan interface=wlan1
- add bridge=br1-lan interface=eth2-lan
- add bridge=br1-lan interface=eth3-lan
- add bridge=br1-lan interface=eth4-lan
- add bridge=br1-lan interface=eth5-lan
- /interface pptp-server server
- set enabled=yes
- /ip address
- add address=10.0.0.1/24 interface=br1-lan network=10.0.0.0
- /ip dhcp-server lease
- add address=10.0.0.100 client-id=1:14:da:e9:df:e2:7a mac-address=14:DA:E9:DF:E2:7A server=dhcp-pc
- add address=10.0.0.99 client-id=1:0:26:2d:84:82:13 mac-address=00:26:2D:84:82:13 server=dhcp-pc
- /ip dhcp-server network
- add address=10.0.0.0/24 dns-server=10.0.0.1 gateway=10.0.0.1 netmask=24 ntp-server=10.0.0.1
- /ip dns
- set allow-remote-requests=yes servers=77.88.8.8
- /ip dns static
- add address=192.168.88.1 name=router.lan
- /ip firewall filter
- add action=accept chain=input dst-port=1723 protocol=tcp
- add action=accept chain=input protocol=gre
- add action=accept chain=input protocol=icmp
- add action=accept chain=input connection-state=new dst-port=80,8291,22 in-interface=br1-lan protocol=tcp src-address=10.0.0.0/24
- add action=accept chain=input connection-mark=allow_in connection-state=new dst-port=80 in-interface=tap1-wan protocol=tcp
- add action=accept chain=input connection-state=established,related
- add action=accept chain=input connection-state=new dst-port=53,123 in-interface=br1-lan protocol=udp src-address=10.0.0.0/24
- add action=accept chain=forward connection-state=established,new in-interface=br1-lan out-interface=tap1-wan src-address=10.0.0.0/24
- add action=accept chain=forward connection-state=established,related dst-address=10.0.0.0/24 in-interface=tap1-wan out-interface=\
- br1-lan
- add action=accept chain=output connection-state=!invalid
- add action=drop chain=input
- add action=drop chain=output
- add action=drop chain=forward
- /ip firewall mangle
- add action=mark-connection chain=prerouting connection-state=new dst-port=9999 in-interface=tap1-wan new-connection-mark=allow_in \
- passthrough=yes protocol=tcp
- /ip firewall nat
- add action=masquerade chain=srcnat out-interface=tap1-wan src-address=10.0.0.0/24
- add action=redirect chain=dstnat dst-port=9999 protocol=tcp to-ports=80
- /ip firewall service-port
- set sip disabled=yes
- /ip route
- add distance=1 dst-address=10.0.1.0/24 gateway=10.0.0.250
- /ip upnp
- set enabled=yes
- /ppp secret
- add local-address=10.0.0.1 name=vpn password=xxx remote-address=10.0.0.250 service=pptp
- /system clock
- set time-zone-autodetect=no time-zone-name=Europe/Astrakhan
- #error exporting /system routerboard mode-button
- [admin@MikroTik] >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement