# nov/06/2019 15:03:44 by RouterOS 6.45.7
# software id = ZA4A-W5CN
#
# model = 2011UiAS-2HnD
# serial number = **********
/interface bridge
add admin-mac=00:0C:42:D7:D9:12 auto-mac=no fast-forward=no mtu=1500 name=\
bridge-gigabit protocol-mode=none
/interface ethernet
set [ find default-name=ether1 ] advertise=100M-full,1000M-full name=\
ether1-WAN
set [ find default-name=ether2 ] advertise=10M-full,100M-full,1000M-full \
speed=100Mbps
set [ find default-name=ether3 ] advertise=100M-full,1000M-full
set [ find default-name=ether4 ] advertise=100M-full,1000M-full speed=100Mbps
set [ find default-name=ether5 ] advertise=100M-full,1000M-full speed=100Mbps
set [ find default-name=ether6 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
set [ find default-name=ether7 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
set [ find default-name=ether8 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
set [ find default-name=ether9 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
set [ find default-name=ether10 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-g/n country="united states" \
disabled=no distance=indoors frequency=2447 hw-retries=4 mode=ap-bridge \
ssid=celery359 wps-mode=disabled
/interface ethernet switch port
set 6 vlan-mode=fallback
set 7 vlan-mode=fallback
set 8 vlan-mode=fallback
set 9 vlan-mode=fallback
set 10 vlan-mode=fallback
set 12 vlan-mode=fallback
/interface list
add exclude=dynamic name=discover
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa2-psk eap-methods="" \
group-key-update=1h mode=dynamic-keys supplicant-identity=MikroTik
add authentication-types=wpa2-psk eap-methods="" management-protection=\
allowed mode=dynamic-keys name=guest-wifi1 supplicant-identity=""
/ip ipsec proposal
set [ find default=yes ] enc-algorithms=3des
/ip pool
add name=dhcp ranges=192.168.88.150-192.168.88.175
add name=wifi-dhcp ranges=192.168.89.100-192.168.89.200
/ip dhcp-server
add address-pool=dhcp authoritative=after-2sec-delay disabled=no interface=\
bridge-gigabit lease-time=1d name=default
add address-pool=wifi-dhcp authoritative=after-2sec-delay disabled=no \
interface=wlan1 lease-time=1d name=wifiDHCP
/queue type
set 0 pfifo-limit=500
set 9 pfifo-limit=100
/queue interface
set ether1-WAN queue=default
set ether2 queue=default
set ether3 queue=default
set ether4 queue=default
set ether5 queue=default
set toNMS2-Spectrum queue=default-small
/queue simple
add limit-at=0/100M max-limit=0/100M name=DHCP_Pool queue=\
pcq-upload-default/pcq-download-default target="192.168.88.155/32,192.168.\
88.156/30,192.168.88.160/28,192.168.88.176/30,192.168.89.100/30,192.168.89\
.104/29,192.168.89.112/28,192.168.89.128/26,192.168.89.192/29,192.168.89.2\
00/32,192.168.88.6/32" total-queue=default
add limit-at=0/250M max-limit=0/250M name=Joe queue=default/default target="19\
2.168.88.32/27,192.168.89.241/32,192.168.89.242/31,192.168.89.244/30,192.1\
68.89.248/30,198.168.89.252/31,192.168.88.152/32,10.0.0.61/32" \
total-queue=default
/snmp community
set [ find default=yes ] addresses=0.0.0.0/0
/system logging action
set 0 memory-lines=100
set 1 disk-lines-per-file=100
set 3 remote=1.1.1.1
/interface bridge port
add bridge=bridge-gigabit disabled=yes interface=ether2
add bridge=bridge-gigabit disabled=yes interface=wlan1
add bridge=bridge-gigabit interface=ether3
add bridge=bridge-gigabit interface=ether4
add bridge=bridge-gigabit disabled=yes interface=ether7
add bridge=bridge-gigabit disabled=yes interface=ether8
add bridge=bridge-gigabit disabled=yes interface=ether9
add bridge=bridge-gigabit disabled=yes interface=ether10
add bridge=bridge-gigabit interface=ether5
/interface bridge settings
set allow-fast-path=no
/interface ovpn-server server
set certificate=cert_export_ovpnCA.crt_0
/interface sstp-server server
set authentication=mschap2 certificate=sstpserver-cert default-profile=\
default-encryption enabled=yes force-aes=yes pfs=yes port=25443
/interface wireless access-list
add interface=wlan1 mac-address=F0:27:65:6D:BF:C5 vlan-mode=no-tag
add interface=wlan1 mac-address=34:4D:F7:71:93:21 vlan-mode=no-tag
/ip address
add address=192.168.88.1/24 comment="default configuration" interface=\
bridge-gigabit network=192.168.88.0
add address=192.168.89.1/24 interface=wlan1 network=192.168.89.0
/ip dhcp-client
add comment="default configuration" dhcp-options=hostname,clientid disabled=\
no interface=ether1-WAN use-peer-dns=no use-peer-ntp=no
/ip dhcp-server lease
add address=192.168.88.5 always-broadcast=yes client-id=1:0:b:82:3c:c4:ca \
comment="My VOIP" mac-address=00:0B:82:3C:C4:CA server=default
add address=192.168.88.39 always-broadcast=yes client-id=1:d4:be:d9:bb:b7:22 \
comment="192.168.88.32/27" mac-address=D4:BE:D9:BB:B7:22 server=\
default
add address=192.168.88.41 client-id=1:f4:ce:46:51:9f:51 comment="HP P2055DN" \
mac-address=F4:CE:46:51:9F:51 server=default
add address=192.168.88.6 client-id=1:0:b:82:69:b6:53 comment=\
"VOIP" mac-address=00:0B:82:69:B6:53 server=default
add address=192.168.88.157 always-broadcast=yes client-id=1:b8:ac:6f:90:71:9a \
mac-address=B8:AC:6F:90:71:9A server=default
add address=192.168.89.100 client-id=1:34:4d:f7:71:93:21 mac-address=\
34:4D:F7:71:93:21 server=wifiDHCP
add address=192.168.89.103 mac-address=74:C2:46:5C:F4:F5 server=wifiDHCP
add address=192.168.89.245 client-id=1:d8:eb:97:d0:b4:36 mac-address=\
D8:EB:97:D0:B4:36 server=wifiDHCP
add address=192.168.88.40 client-id=1:2c:27:d7:e2:fb:58 mac-address=\
2C:27:D7:E2:FB:58 server=default
add address=192.168.89.242 client-id=1:0:9d:6b:20:a7:25 mac-address=\
00:9D:6B:20:A7:25 server=wifiDHCP
add address=192.168.89.244 client-id=1:bc:20:a4:7a:e4:6c mac-address=\
BC:20:A4:7A:E4:6C server=wifiDHCP
add address=192.168.88.38 client-id=1:0:c:29:83:e1:ea mac-address=\
00:0C:29:83:E1:EA server=default
add address=192.168.89.241 client-id=1:68:9a:87:5f:11:e2 comment=\
"Wifi IP Range 192.168.89.241-253" mac-address=68:9A:87:5F:11:E2 \
server=wifiDHCP
add address=192.168.89.243 client-id=1:c0:f8:da:3c:c8:d9 mac-address=\
C0:F8:DA:3C:C8:D9 server=wifiDHCP
add address=192.168.89.246 mac-address=AC:AE:19:39:47:A7 server=wifiDHCP
/ip dhcp-server network
add address=192.168.88.0/24 comment="default configuration" dns-server=\
1.1.1.1,1.0.0.1 gateway=192.168.88.1 netmask=24
add address=192.168.89.0/24 dns-server=1.1.1.1,1.0.0.1 gateway=192.168.89.1
/ip dns
set cache-size=8192KiB max-udp-packet-size=8192 servers=8.8.4.4,4.2.2.2
/ip dns static
add address=192.168.88.1 disabled=yes name=router
/ip firewall address-list
add address=192.168.3.0/24 list=routeraccess
add address=192.168.88.0/24 list=routeraccess
add address=192.168.5.0-192.168.6.254 list=routeraccess
/ip firewall filter
add action=drop chain=input comment="Drop ICMP pings" in-interface=ether1-WAN \
protocol=icmp
add action=drop chain=input comment=\
"Block incoming DNS requests from outside" dst-port=53 in-interface=\
ether1-WAN protocol=udp
add action=drop chain=forward comment=\
"Block incoming DNS requests from outside" dst-port=53 in-interface=\
ether1-WAN protocol=tcp
add action=drop chain=input comment="Drop Invalid connections - INPUT" \
connection-mark="" connection-state=invalid
add action=drop chain=forward comment="Drop Invalid Connections - FORWARD" \
connection-state=invalid
add action=accept chain=input comment=\
"Allow Established and Related Connections" connection-state=\
established,related
add action=accept chain=forward comment=\
"Allow Already Established and Related Connections" connection-state=\
established,related
add action=accept chain=forward comment="VOIP FXS port 1" protocol=udp \
src-address=192.168.88.5 src-port=5060
add action=accept chain=forward comment="VOIP FXS Port 1" protocol=udp \
src-address=192.168.88.5 src-port=5004
add action=accept chain=forward comment="VOIP" protocol=udp \
src-address=192.168.88.6 src-port=25060
add action=accept chain=forward comment="VOIP" protocol=udp \
src-address=192.168.88.6 src-port=25004
add action=drop chain=forward comment="Drop Everything Else" in-interface=\
ether1-WAN
add action=drop chain=input comment="Drop Everything Else" in-interface=\
ether1-WAN
/ip firewall nat
add action=dst-nat chain=dstnat dst-port=15900 in-interface=ether1-WAN \
protocol=tcp to-addresses=192.168.88.39 to-ports=5900
add action=dst-nat chain=dstnat dst-port=20080 in-interface=ether1-WAN \
protocol=tcp to-addresses=192.168.89.151 to-ports=80
add action=masquerade chain=srcnat comment="default configuration" \
out-interface=ether1-WAN
/ip firewall service-port
set tftp disabled=yes
set irc disabled=yes
set h323 disabled=yes
set pptp disabled=yes
/ip ipsec policy
set 0 disabled=yes dst-address=0.0.0.0/0 src-address=0.0.0.0/0
/ip proxy
set cache-path=web-proxy1
/ip route
add distance=1 dst-address=192.168.3.0/24 gateway=10.9.9.50
add distance=1 dst-address=192.168.5.0/24 gateway=10.9.9.50
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www address=192.168.89.0/24,192.168.88.0/24,192.168.3.0/24
set api disabled=yes
set api-ssl disabled=yes
/ip ssh
set allow-none-crypto=yes always-allow-password-login=yes forwarding-enabled=\
remote
/ip upnp interfaces
add interface=ether1-WAN type=external
add interface=bridge-gigabit type=internal
/lcd
set enabled=no
/lcd interface
add
/ppp secret
add local-address=10.0.0.60 name=sstp-joe profile=default-encryption \
remote-address=10.0.0.61 service=sstp
/system clock
set time-zone-autodetect=no time-zone-name=America/Los_Angeles
/system identity
set name=rden359
/system logging
add topics=wireless
add action=echo topics=packet,info
add topics=debug,script
/system ntp client
set enabled=yes primary-ntp=204.2.134.163 secondary-ntp=69.50.219.51
/system scheduler
add interval=1d name=freednsCheck on-event=freednsCheck policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive start-date=\
may/26/2016 start-time=23:59:00
add interval=15m name=routeraccess on-event="/system script run routeraccess" \
policy=read,write start-date=jul/30/2016 start-time=21:37:16
add comment="Download dshield list" interval=3d name=DownloadDShieldList \
on-event=Download_dshield policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive start-date=\
jan/01/1970 start-time=01:05:20
add comment="Apply dshield List" interval=3d name=InstallDShieldList \
on-event=Replace_dshield policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive start-date=\
jan/01/1970 start-time=01:10:20
/system script
add dont-require-permissions=no name=freedns owner=admin policy=\
ftp,read,write source="# Installation:\
\n# 1. Modify settings\
\n# 2a. Cut&paste contents of this file to console\
\n# 2b. Or save modified file, upload via tftp, sftp, web, etc.\
\n# 3b. Run /import freedns.rsc\
\n\
\n:global freednsCheckInterval 10m\
\n\
\n/system scheduler\
\nremove [find name=\"freednsCheck\"]\
\nremove [find name=\"freednsUpdate\"]\
\n\
\n/system script\
\n\
\nremove [find name=\"freednsCheck\"]\
\nadd name=\"freednsCheck\" source={\
\n# Required. Can be set to 'auto' if there is only one default gateway.\
\n :global freednsGateIface \"auto\"\
\n\
\n# Required. Set it to FreeDNS key string (query string after \? char).\
\n :global freednsKey \"ODM=\"\
\n\
\n# Optional. Fill it with FQDN or leave it blank to skip verify&retry.\
\n :global freednsVerify \"\"\
\n\
\n# In case freednsVerify is not empty, all freednsRetry* settings are r\
equired!\
\n :global freednsRetryInterval 5m\
\n\
\n# Stop trying after this count of failures. 0 means 'infinity'\
\n :global freednsRetryMax 100\
\n\
\n# Log warning after this count of failures. 0 means 'never'\
\n :global freednsRetryWarn\
\n\
\n\
\n /ip route\
\n :if (\$freednsGateIface=\"auto\") do={\
\n :set freednsGateIface [get [ \\\
\n find dst-address=0.0.0.0/0 ] \\\
\n value-name=\"vrf-interface\"]\
\n :log debug \"freednsCheck: gateway interface IP: \$freednsGateIf\
ace\"\
\n }\
\n\
\n :local gateRemoteIp\
\n :set gateRemoteIp [get [ \\\
\n find dst-address=0.0.0.0/0 and vrf-interface=\$freednsGateIf\
ace] \\\
\n value-name=gateway]\
\n :log debug \"freednsCheck: gateway remote IP: \$gateRemoteIp\"\
\n\
\n :local gateLocalIp\
\n :set gateLocalIp [get [ \\\
\n find gateway=\$freednsGateIface] \\\
\n value-name=pref-src]\
\n :log debug \"freednsCheck: gateway local IP: \$gateLocalIp\"\
\n\
\n /interface ethernet\
\n :local linkStatus\
\n monitor [find name=\$freednsGateIface] once do={\
\n :set linkStatus \$status\
\n }\
\n :log debug \"freednsCheck: link status: \$linkStatus\"\
\n\
\n :global freednsIp\
\n :if (\$linkStatus = \"link-ok\" and \$freednsIp != \$gateLocalIp) do\
={\
\n :log info \"freednsCheck: IP changed on \$freednsGateIface from \
\$freednsIp to \$gateLocalIp\"\
\n :set freednsIp \$gateLocalIp\
\n :if ([:len \$freednsVerify] > 0) do={\
\n :log debug \"freednsCheck: scheduling freednsUpdate at \$fre\
ednsRetryInterval\"\
\n /system scheduler\
\n remove [find name=\"freednsUpdate\"]\
\n add name=\"freednsUpdate\" interval=\$freednsRetryInterval o\
n-event=\"freednsUpdate\"\
\n }\
\n :log debug \"freednsCheck: running freednsUpdate now\"\
\n /system script run freednsUpdate\
\n } else={\
\n :log debug \"freednsCheck: no update required or link is not ok\
\"\
\n }\
\n}\
\n\
\nremove [find name=\"freednsUpdate\"]\
\nadd name=\"freednsUpdate\" source={\
\n :global freednsGateIface\
\n :global freednsIp\
\n :global freednsKey\
\n :global freednsVerify\
\n :global freednsRetryInterval\
\n :global freednsRetryMax\
\n :global freednsRetryWarn\
\n\
\n /interface ethernet\
\n :local linkStatus\
\n monitor [find name=\$freednsGateIface] once do={\
\n :set linkStatus \$status\
\n }\
\n :log debug \"freednsUpdate: link status: \$linkStatus\"\
\n\
\n :if (\$linkStatus = \"link-ok\") do={\
\n :local resolvedIp\
\n :if ([:len \$freednsVerify] > 0) do={\
\n /system scheduler\
\n :local runCount [get [find name=\"freednsUpdate\"] value-nam\
e=\"run-count\"]\
\n :log debug \"freednsUpdate: retry count: \$runCount\"\
\n :if (\$runCount > 0 and \$runCount = \$freednsRetryWarn) do=\
{\
\n :log warning \"freednsUpdate: failed to update \$freedns\
Verify to \$freednsIp\"\
\n }\
\n :if (\$freednsRetryMax > 0 and \$runCount > \$freednsRetryMa\
x) do={\
\n :log debug \"freednsUpdate: freednsRetryMax(\$freednsRet\
ryMax) retry count has reached, stopping\"\
\n /system scheduler remove [find name=\"freednsUpdate\"]\
\n :return 0\
\n } else={\
\n :set resolvedIp [:resolve \$freednsVerify]\
\n :log debug \"freednsUpdate: resolved \$freednsVerify to \
\$resolvedIp\"\
\n }\
\n }\
\n :if (\$resolvedIp = \$freednsIp) do={\
\n :log debug \"freednsUpdate: successfully updated to \$freedn\
sIp, stopping scheduler\"\
\n /system scheduler remove [find name=\"freednsUpdate\"]\
\n } else={\
\n :log debug \"freednsUpdate: sending request to freedns.afrai\
d.org\"\
\n /tool fetch \\\
\n mode=http \\\
\n address=\"freedns.afraid.org\" \\\
\n host=\"freedns.afraid.org\" \\\
\n src-path=\"dynamic/update.php\\\?\$freednsKey\" \\\
\n keep-result=no\
\n }\
\n }\
\n}\
\n\
\n/system scheduler add name=\"freednsCheck\" interval=\$freednsCheckInter\
val on-event=\"freednsCheck\"\
\n\
\nenvironment remove [find name=\"freednsIp\"]\
\nenvironment remove [find name=\"freednsCheckInterval\"]\
\n\
\nrun freednsCheck\
\n/log print\
\n"
add dont-require-permissions=no name=freednsCheck owner=admin policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive source="\r\
\n# Required. Can be set to 'auto' if there is only one default gateway.\
\r\
\n :global freednsGateIface \"auto\"\r\
\n\r\
\n# Required. Set it to FreeDNS key string (query string after \? char).\
\r\
\n :global freednsKey \"wODM=\"\r\
\n\r\
\n# Optional. Fill it with FQDN or leave it blank to skip verify&retry.\
\r\
\n :global freednsVerify \"\"\r\
\n\r\
\n# In case freednsVerify is not empty, all freednsRetry* settings are r\
equired!\r\
\n :global freednsRetryInterval 5m\r\
\n\r\
\n# Stop trying after this count of failures. 0 means 'infinity'\r\
\n :global freednsRetryMax 100\r\
\n\r\
\n# Log warning after this count of failures. 0 means 'never'\r\
\n :global freednsRetryWarn\r\
\n\r\
\n\r\
\n\r\
\n /ip route\r\
\n :if (\$freednsGateIface=\"auto\") do={\r\
\n :set freednsGateIface [get [find dst-address=0.0.0.0/0] value-na\
me=\"vrf-interface\"]\r\
\n :log debug \"freednsCheck: gateway interface IP: \$freednsGateIf\
ace\"\r\
\n }\r\
\n\r\
\n :local gateRemoteIp\r\
\n :set gateRemoteIp [get [ \\\r\
\n find dst-address=0.0.0.0/0 and vrf-interface=\$freednsGateIf\
ace] \\\r\
\n value-name=gateway]\r\
\n :log debug \"freednsCheck: gateway remote IP: \$gateRemoteIp\"\r\
\n\r\
\n\r\
\n :local gateLocalIp\r\
\n :set gateLocalIp [get [ \\\r\
\n find gateway=\$freednsGateIface] \\\r\
\n value-name=pref-src]\r\
\n :log debug \"freednsCheck: gateway local IP: \$gateLocalIp\"\r\
\n\r\
\n /interface ethernet\r\
\n :local linkStatus\r\
\n monitor [find name=\$freednsGateIface] once do={\r\
\n :set linkStatus \$status\r\
\n }\r\
\n :log debug \"freednsCheck: link status: \$linkStatus\"\r\
\n\r\
\n :global freednsIp\r\
\n :if (\$linkStatus = \"link-ok\" and \$freednsIp != \$gateLocalIp) do\
={\r\
\n :log info \"freednsCheck: IP changed on \$freednsGateIface from \
\$freednsIp to \$gateLocalIp\"\r\
\n :set freednsIp \$gateLocalIp\r\
\n :if ([:len \$freednsVerify] > 0) do={\r\
\n :log debug \"freednsCheck: scheduling freednsUpdate at \$fre\
ednsRetryInterval\"\r\
\n /system scheduler\r\
\n remove [find name=\"freednsUpdate\"]\r\
\n add name=\"freednsUpdate\" interval=\$freednsRetryInterval o\
n-event=\"freednsUpdate\"\r\
\n }\r\
\n :log debug \"freednsCheck: running freednsUpdate now\"\r\
\n /system script run freednsUpdate\r\
\n } else={\r\
\n :log debug \"freednsCheck: no update required or link is not ok\
\"\r\
\n }\r\
\n"
add dont-require-permissions=no name=freednsUpdate owner=admin policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive source="\
\n :global freednsGateIface\
\n :global freednsIp\
\n :global freednsKey\
\n :global freednsVerify\
\n :global freednsRetryInterval\
\n :global freednsRetryMax\
\n :global freednsRetryWarn\
\n\
\n /interface ethernet\
\n :local linkStatus\
\n monitor [find name=\$freednsGateIface] once do={\
\n :set linkStatus \$status\
\n }\
\n :log debug \"freednsUpdate: link status: \$linkStatus\"\
\n\
\n :if (\$linkStatus = \"link-ok\") do={\
\n :local resolvedIp\
\n :if ([:len \$freednsVerify] > 0) do={\
\n /system scheduler\
\n :local runCount [get [find name=\"freednsUpdate\"] value-nam\
e=\"run-count\"]\
\n :log debug \"freednsUpdate: retry count: \$runCount\"\
\n :if (\$runCount > 0 and \$runCount = \$freednsRetryWarn) do=\
{\
\n :log warning \"freednsUpdate: failed to update \$freedns\
Verify to \$freednsIp\"\
\n }\
\n :if (\$freednsRetryMax > 0 and \$runCount > \$freednsRetryMa\
x) do={\
\n :log debug \"freednsUpdate: freednsRetryMax(\$freednsRet\
ryMax) retry count has reached, stopping\"\
\n /system scheduler remove [find name=\"freednsUpdate\"]\
\n :return 0\
\n } else={\
\n :set resolvedIp [:resolve \$freednsVerify]\
\n :log debug \"freednsUpdate: resolved \$freednsVerify to \
\$resolvedIp\"\
\n }\
\n }\
\n :if (\$resolvedIp = \$freednsIp) do={\
\n :log debug \"freednsUpdate: successfully updated to \$freedn\
sIp, stopping scheduler\"\
\n /system scheduler remove [find name=\"freednsUpdate\"]\
\n } else={\
\n :log debug \"freednsUpdate: sending request to freedns.afrai\
d.org\"\
\n /tool fetch \\\
\n mode=http \\\
\n address=\"freedns.afraid.org\" \\\
\n host=\"freedns.afraid.org\" \\\
\n src-path=\"dynamic/update.php\\\?\$freednsKey\" \\\
\n keep-result=no\
\n }\
\n }\
\n"
add dont-require-permissions=no name=script1 owner=admin policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive source="/ip fir\
ewall filter\r\
\nadd chain=ICMP protocol=icmp icmp-options=0:0-255 limit=5,5:packet actio\
n=accept comment=\"0:0 and limit for 5pac/s\" disabled=no \r\
\nadd chain=ICMP protocol=icmp icmp-options=3:3 limit=5,5:packet action=ac\
cept comment=\"3:3 and limit for 5pac/s\" disabled=no \r\
\nadd chain=ICMP protocol=icmp icmp-options=3:4 limit=5,5:packet action=ac\
cept comment=\"3:4 and limit for 5pac/s\" disabled=no \r\
\nadd chain=ICMP protocol=icmp icmp-options=8:0-255 limit=5,5:packet actio\
n=accept comment=\"8:0 and limit for 5pac/s\" disabled=no \r\
\nadd chain=ICMP protocol=icmp icmp-options=11:0-255 limit=5,5:packet acti\
on=accept comment=\"11:0 and limit for 5pac/s\" disabled=no \r\
\nadd chain=ICMP protocol=icmp action=drop comment=\"Drop everything else\
\" disabled=no \r\
\n"
/tool bandwidth-server
set enabled=no
/tool mac-server
set allowed-interface-list=none
/tool mac-server ping
set enabled=no