|
# 2023-07-21 08:28:56 by RouterOS 7.10.2 |
|
# software id = CD3F-U3CW |
|
# |
|
# model = RB4011iGS+ |
|
# serial number = D4480E8A8BED |
|
/interface bridge |
|
add admin-mac=2C:C8:1B:27:1A:C8 auto-mac=no comment=defconf name=bridge |
|
/interface list |
|
add comment=defconf name=WAN |
|
add comment=defconf name=LAN |
|
/interface wireless security-profiles |
|
set [ find default=yes ] supplicant-identity=MikroTik |
|
/ip pool |
|
add name=dhcp ranges=192.168.99.10-192.168.99.254 |
|
/ip dhcp-server |
|
add address-pool=dhcp interface=bridge lease-time=10m name=defconf |
|
/port |
|
set 0 name=serial0 |
|
set 1 name=serial1 |
|
/interface bridge port |
|
add bridge=bridge comment=defconf interface=ether2 |
|
add bridge=bridge comment=defconf interface=ether3 |
|
add bridge=bridge comment=defconf interface=ether4 |
|
add bridge=bridge comment=defconf interface=ether5 |
|
add bridge=bridge comment=defconf interface=ether6 |
|
add bridge=bridge comment=defconf interface=ether7 |
|
add bridge=bridge comment=defconf interface=ether8 |
|
add bridge=bridge comment=defconf interface=ether9 |
|
add bridge=bridge comment=defconf interface=ether10 |
|
add bridge=bridge comment=defconf interface=sfp-sfpplus1 |
|
/ip neighbor discovery-settings |
|
set discover-interface-list=LAN |
|
/ipv6 settings |
|
set forward=yes |
|
/interface list member |
|
add comment=defconf interface=bridge list=LAN |
|
add comment=defconf interface=ether1 list=WAN |
|
/ip address |
|
add address=192.168.99.1/24 comment=defconf interface=bridge network=\ |
|
192.168.99.0 |
|
/ip dhcp-client |
|
add comment=defconf interface=ether1 |
|
/ip dhcp-server network |
|
add address=192.168.99.0/24 comment=defconf dns-server=192.168.99.1 gateway=\ |
|
192.168.99.1 netmask=24 |
|
/ip dns |
|
set allow-remote-requests=yes |
|
/ip dns static |
|
add address=192.168.99.1 comment=defconf name=router.lan |
|
/ip firewall filter |
|
add action=accept chain=input comment=\ |
|
"defconf: accept established,related,untracked" connection-state=\ |
|
established,related,untracked |
|
add action=drop chain=input comment="defconf: drop invalid" connection-state=\ |
|
invalid |
|
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp |
|
add action=accept chain=input comment=\ |
|
"defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1 |
|
add action=drop chain=input comment="defconf: drop all not coming from LAN" \ |
|
in-interface-list=!LAN |
|
add action=accept chain=forward comment="defconf: accept in ipsec policy" \ |
|
ipsec-policy=in,ipsec |
|
add action=accept chain=forward comment="defconf: accept out ipsec policy" \ |
|
ipsec-policy=out,ipsec |
|
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \ |
|
connection-state=established,related hw-offload=yes |
|
add action=accept chain=forward comment=\ |
|
"defconf: accept established,related, untracked" connection-state=\ |
|
established,related,untracked |
|
add action=drop chain=forward comment="defconf: drop invalid" \ |
|
connection-state=invalid |
|
add action=drop chain=forward comment=\ |
|
"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \ |
|
connection-state=new in-interface-list=WAN |
|
/ip firewall nat |
|
add action=masquerade chain=srcnat comment="defconf: masquerade" \ |
|
ipsec-policy=out,none out-interface-list=WAN |
|
/ipv6 address |
|
add address=::1 from-pool=sl-pd interface=bridge |
|
/ipv6 dhcp-client |
|
add interface=ether1 pool-name=sl-pd request=prefix |
|
/ipv6 firewall address-list |
|
add address=::/128 comment="defconf: unspecified address" list=bad_ipv6 |
|
add address=::1/128 comment="defconf: lo" list=bad_ipv6 |
|
add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6 |
|
add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6 |
|
add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6 |
|
add address=100::/64 comment="defconf: discard only " list=bad_ipv6 |
|
add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6 |
|
add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6 |
|
add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6 |
|
/ipv6 nd |
|
set [ find default=yes ] hop-limit=64 |
|
/system clock |
|
set time-zone-name=Europe/Paris |
|
/system note |
|
set show-at-login=no |
|
/tool mac-server |
|
set allowed-interface-list=LAN |
|
/tool mac-server mac-winbox |
|
set allowed-interface-list=LAN |