# apr/09/2018 17:27:06 by RouterOS 6.41.3
# software id = 1HEQ-9C45
#
# model = 2011UiAS
# serial number = 608905E95FFB
/interface bridge
add admin-mac=E4:8D:8C:2C:7D:CA auto-mac=no name=bridge
/interface ethernet
set [ find default-name=ether1 ] name=ether1-Net
set [ find default-name=ether2 ] name=ether2-local-wifi
set [ find default-name=ether3 ] name=ether3-Main
set [ find default-name=ether4 ] name=ether4-WISP
set [ find default-name=ether5 ] name=ether5-longrun
set [ find default-name=ether6 ] name=ether6-master
set [ find default-name=ether7 ] disabled=yes
set [ find default-name=ether8 ] disabled=yes
set [ find default-name=ether9 ] loop-protect=off
set [ find default-name=ether10 ] name=ether10-mAP
set [ find default-name=sfp1 ] disabled=yes
/caps-man interface
add arp=enabled channel.band=2ghz-g/n channel.control-channel-width=20mhz channel.skip-dfs-channels=yes comment=bedroom configuration.country=canada configuration.hw-retries=5 configuration.mode=ap \
configuration.ssid=MT1 datapath.bridge=bridge disabled=no l2mtu=1600 mac-address=4C:5E:0C:14:8A:94 master-interface=none name=cap7 radio-mac=4C:5E:0C:14:8A:94 security.authentication-types=wpa2-psk \
security.encryption=aes-ccm
/interface ethernet switch port
set 6 vlan-mode=fallback
set 7 vlan-mode=fallback
set 9 vlan-mode=fallback
set 10 vlan-mode=fallback
set 12 vlan-mode=fallback
/interface list
add exclude=dynamic name=discover
add name=mactel
add name=mac-winbox
add name=WAN
add name=LAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=dhcp ranges=10.10.98.2-10.10.98.254
/ip dhcp-server
add add-arp=yes address-pool=dhcp always-broadcast=yes disabled=no interface=bridge lease-time=1d17h46m39s name=dhcp2
/tool user-manager customer
set admin access=own-routers,own-users,own-profiles,own-limits,config-payment-gw
/caps-man manager
set enabled=yes upgrade-policy=require-same-version
/caps-man manager interface
add disabled=no forbid=yes interface=ether1-Net
add disabled=no interface=ether4-WISP
add disabled=no interface=ether5-longrun
add interface=ether10-mAP
add disabled=no interface=ether9
/interface bridge port
add bridge=bridge hw=no interface=ether10-mAP
add bridge=bridge hw=no interface=ether4-WISP
add bridge=bridge hw=no interface=ether3-Main
add bridge=bridge hw=no interface=ether5-longrun
add bridge=bridge hw=no interface=ether6-master
add interface=sfp1
add bridge=bridge hw=no interface=ether2-local-wifi
add interface=ether1-Net
add interface=ether8
add bridge=bridge interface=ether9
add bridge=bridge interface=ether7
/ip neighbor discovery-settings
set discover-interface-list=all
/interface detect-internet
set internet-interface-list=WAN lan-interface-list=dynamic wan-interface-list=WAN
/interface list member
add interface=ether2-local-wifi list=discover
add interface=ether3-Main list=discover
add interface=ether4-WISP list=discover
add interface=ether5-longrun list=discover
add interface=ether6-master list=discover
add interface=ether10-mAP list=discover
add interface=bridge list=discover
add interface=bridge list=mactel
add interface=ether3-Main list=mactel
add interface=bridge list=mac-winbox
add interface=ether4-WISP list=mactel
add interface=ether2-local-wifi list=mac-winbox
add interface=ether5-longrun list=mactel
add interface=ether3-Main list=mac-winbox
add interface=ether2-local-wifi list=mactel
add interface=ether10-mAP list=mactel
add interface=ether4-WISP list=mac-winbox
add interface=ether5-longrun list=mac-winbox
add interface=ether10-mAP list=mac-winbox
add interface=ether1-Net list=WAN
/ip accounting web-access
set accessible-via-web=yes address=10.10.98.254/32
/ip address
add address=10.10.98.1/24 comment=defconf interface=ether2-local-wifi network=10.10.98.0
/ip dhcp-client
add dhcp-options=hostname,clientid disabled=no interface=ether1-Net use-peer-dns=no
/ip dhcp-server config
set store-leases-disk=2h
/ip dhcp-server lease
add address=10.10.98.24 comment="Michelle's tablet" mac-address=8C:84:01:91:64:14
add address=10.10.98.28 client-id=1:2c:59:8a:55:1d:4 comment="Lance's Phone" mac-address=2C:59:8A:55:1D:04
add address=10.10.98.29 client-id=1:14:49:e0:1:bf:97 comment="GMA Tv LR" mac-address=14:49:E0:01:BF:97
add address=10.10.98.39 always-broadcast=yes comment="Comfast repeater #204" mac-address=40:A5:EF:9D:4E:21 server=dhcp2
add address=10.10.98.33 always-broadcast=yes client-id=1:b8:97:5a:fb:44:8f mac-address=B8:97:5A:FB:44:8F server=dhcp2
add address=10.10.98.20 client-id=1:ec:8:6b:4:f6:47 mac-address=EC:08:6B:04:F6:47 server=dhcp2
add address=10.10.98.2 always-broadcast=yes client-id=1:4c:5e:c:f9:4b:84 mac-address=4C:5E:0C:F9:4B:84 server=dhcp2
add address=10.10.98.3 client-id=1:6c:3b:6b:c0:b5:4d mac-address=6C:3B:6B:C0:B5:4D server=dhcp2
add address=10.10.98.4 client-id=1:4c:5e:c:40:32:3a mac-address=4C:5E:0C:40:32:3A server=dhcp2
add address=10.10.98.5 client-id=1:4c:5e:c:14:8a:93 mac-address=4C:5E:0C:14:8A:93 server=dhcp2
add address=10.10.98.22 always-broadcast=yes client-id=1:2c:59:8a:55:1d:4 comment=mp mac-address=2C:59:8A:55:1D:04 server=dhcp2
/ip dhcp-server network
add address=10.10.98.0/24 comment=defconf dns-server=8.8.8.8,8.8.4.4 gateway=10.10.98.1 netmask=24
/ip dns
set allow-remote-requests=yes servers=8.8.8.8,8.8.4.4
/ip firewall address-list
add address=0.0.0.0/8 comment="Self-Identification [RFC 3330]" list=bogons
add address=10.0.0.0/8 comment="Private[RFC 1918] - CLASS A # Check if you need this subnet before enable it" disabled=yes list=bogons
add address=127.0.0.0/8 comment="Loopback [RFC 3330]" list=bogons
add address=169.254.0.0/16 comment="Link Local [RFC 3330]" list=bogons
add address=172.16.0.0/12 comment="Private[RFC 1918] - CLASS B # Check if you need this subnet before enable it" disabled=yes list=bogons
add address=192.168.0.0/16 comment="Private[RFC 1918] - CLASS C # Check if you need this subnet before enable it" disabled=yes list=bogons
add address=192.0.2.0/24 comment="Reserved - IANA - TestNet1" list=bogons
add address=192.88.99.0/24 comment="6to4 Relay Anycast [RFC 3068]" list=bogons
add address=198.18.0.0/15 comment="NIDB Testing" list=bogons
add address=198.51.100.0/24 comment="Reserved - IANA - TestNet2" list=bogons
add address=203.0.113.0/24 comment="Reserved - IANA - TestNet3" list=bogons
add address=224.0.0.0/4 comment="MC, Class D, IANA # Check if you need this subnet before enable it" disabled=yes list=bogons
add address=10.10.98.0/24 list=support
/ip firewall filter
add action=drop chain=input comment="defconf: accept ICMP" disabled=yes protocol=icmp
add action=accept chain=input comment="defconf: accept established,related" connection-state=established,related
add action=drop chain=input comment="defconf: drop all from WAN" in-interface=ether1-Net
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
add action=drop chain=input comment="Block all access to the winbox - except to support list # DO NOT ENABLE THIS RULE BEFORE ADD YOUR SUBNET IN THE SUPPORT ADDRESS LIST" dst-port=8291 protocol=tcp \
src-address-list=!support
add action=accept chain=forward comment="defconf: accept established,related" connection-state=established,related
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface=ether1-Net
add action=add-src-to-address-list address-list=Syn_Flooder address-list-timeout=30m chain=input comment="Add Syn Flood IP to the list" connection-limit=30,32 protocol=tcp tcp-flags=syn
add action=drop chain=input comment="Drop to syn flood list" src-address-list=Syn_Flooder
add action=add-src-to-address-list address-list=Port_Scanner address-list-timeout=1w chain=input comment="Port Scanner Detect" protocol=tcp psd=21,3s,3,1
add action=drop chain=input comment="Drop to port scan list" src-address-list=Port_Scanner
add action=jump chain=input comment="Jump for icmp input flow" jump-target=ICMP protocol=icmp
add action=jump chain=forward comment="Jump for icmp forward flow" jump-target=ICMP protocol=icmp
add action=drop chain=forward comment="Drop to bogon list" dst-address-list=bogons
add action=add-src-to-address-list address-list=spammers address-list-timeout=3h chain=forward comment="Add Spammers to the list for 3 hours" connection-limit=30,32 dst-port=25,587 limit=30/1m,0 protocol=tcp
add action=drop chain=forward comment="Avoid spammers action" dst-port=25,587 protocol=tcp src-address-list=spammers
add action=accept chain=input comment="Accept DNS - UDP" port=53 protocol=udp
add action=accept chain=input comment="Accept DNS - TCP" port=53 protocol=tcp
add action=accept chain=input comment="Accept to established connections" connection-state=established
add action=accept chain=input comment="Accept to related connections" connection-state=related
add action=accept chain=input comment="Full access to SUPPORT address list" src-address-list=support
add action=drop chain=input comment="Drop anything else! # DO NOT ENABLE THIS RULE BEFORE YOU MAKE SURE ABOUT ALL ACCEPT RULES YOU NEED" disabled=yes
add action=accept chain=ICMP comment="Destination unreachable" icmp-options=3:0-1 protocol=icmp
add action=accept chain=ICMP comment=PMTUD icmp-options=3:4 protocol=icmp
add action=drop chain=ICMP comment="Drop to the other ICMPs" disabled=yes protocol=icmp
add action=jump chain=output comment="Jump for icmp output" jump-target=ICMP protocol=icmp
add action=reject chain=input dst-address=58.61.184.32 reject-with=icmp-network-unreachable
add action=reject chain=input dst-address=203.93.215.81 reject-with=icmp-network-unreachable
add action=reject chain=input reject-with=icmp-network-unreachable src-address=203.93.215.81
add action=reject chain=input dst-address=187.10.244.247 reject-with=icmp-network-unreachable
add action=reject chain=input reject-with=icmp-network-unreachable src-address=187.10.244.247
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" out-interface=ether1-Net out-interface-list=WAN
add action=dst-nat chain=dstnat comment=SCP disabled=yes dst-address=PUBLIC IP[/b] dst-port=7777,7778,7779,7780,7781,7782,7783,7784 protocol=udp to-addresses=10.10.98.20 to-ports=7777-7784
add action=dst-nat chain=dstnat comment=SCP disabled=yes dst-address=PUBLIC IP dst-port=7777,7778,7779,7780,7781,7782,7783,7784 protocol=tcp to-addresses=10.10.98.20
add action=dst-nat chain=dstnat comment=steam disabled=yes dst-address=PUBLIC IP dst-port=27000-27037 protocol=udp to-addresses=10.10.98.20 to-ports=7777
add action=dst-nat chain=dstnat comment=steam disabled=yes dst-address=PUBLIC IP dst-port=27000-27037 protocol=tcp to-addresses=10.10.98.20 to-ports=27000-27037
add action=dst-nat chain=dstnat comment=fortnite disabled=yes dst-address=PUBLIC IP dst-port=5222 protocol=tcp to-addresses=10.10.98.20 to-ports=27000-27037
/ip firewall service-port
set ftp disabled=yes
set tftp disabled=yes
set irc disabled=yes
set h323 disabled=yes
set sip disabled=yes
set pptp disabled=yes
set udplite disabled=yes
set dccp disabled=yes
set sctp disabled=yes
/ip smb
set domain=WORKGROUP interfaces=bridge
/ip traffic-flow
set enabled=yes interfaces=bridge
/ip upnp
set enabled=yes
/ip upnp interfaces
add interface=ether1-Net type=external
add interface=ether2-local-wifi type=internal
add interface=bridge type=internal
add interface=ether3-Main type=internal
add interface=ether4-WISP type=internal
add interface=ether5-longrun type=internal
add interface=ether6-master type=internal
add interface=ether7 type=internal
add interface=ether8 type=internal
add interface=ether9 type=internal
add interface=ether10-mAP type=internal
/lcd
set backlight-timeout=never
/ppp aaa
set accounting=no use-radius=yes
/ppp profile
set *FFFFFFFE bridge=*F local-address=dhcp only-one=no remote-address=dhcp use-upnp=yes
/ppp secret
add caller-id=tester-username name=tester-username profile=default-encryption
/system clock
set time-zone-name=America/Toronto
/system identity
set name=MikroTik-Main
/system lcd
set contrast=0 enabled=no port=parallel type=24x4
/system lcd page
set time disabled=yes display-time=5s
set resources disabled=yes display-time=5s
set uptime disabled=yes display-time=5s
set packets disabled=yes display-time=5s
set bits disabled=yes display-time=5s
set version disabled=yes display-time=5s
set identity disabled=yes display-time=5s
set bridge disabled=yes display-time=5s
set cap7 disabled=yes display-time=5s
set sfp1 disabled=yes display-time=5s
set ether1-Net disabled=yes display-time=5s
set ether2-local-wifi disabled=yes display-time=5s
set ether3-Main disabled=yes display-time=5s
set ether4-WISP disabled=yes display-time=5s
set ether5-longrun disabled=yes display-time=5s
set ether6-master disabled=yes display-time=5s
set ether7 disabled=yes display-time=5s
set ether8 disabled=yes display-time=5s
set ether9 disabled=yes display-time=5s
set ether10-mAP disabled=yes display-time=5s
/system routerboard settings
set silent-boot=yes
/system scheduler
add disabled=yes interval=1m name=schedule1 on-event="system script run Killport7\r\
\n:delay 30\r\
\nsystem script run Startport7" policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon start-time=startup
/system script
add name=Killport7 owner=admin policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="interface disable ether7"
add name=Startport7 owner=admin policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="interface enable ether7"
/tool bandwidth-server
set max-sessions=1000
/tool graphing interface
add allow-address=10.10.98.0/24 interface=ether1-Net
add allow-address=10.10.98.0/24 interface=ether3-Main
/tool mac-server
set allowed-interface-list=discover
/tool mac-server mac-winbox
set allowed-interface-list=discover
/tool romon port
set [ find default=yes ] forbid=yes
add disabled=no interface=ether3-Main
add disabled=no interface=ether4-WISP
add disabled=no interface=ether5-longrun
add disabled=no interface=ether2-local-wifi
/tool sniffer
set file-limit=100000KiB file-name=obs4 filter-interface=ether3-Main filter-port=52348 memory-limit=100000KiB only-headers=yes
/tool user-manager database
set db-path=user-manager