Mon May 11, 2020 12:02 pm
for my server sir:
# may/11/2020 16:54:21 by RouterOS 6.46.6
# software id = WCTL-6CZ3
#
# model = CCR1009-7G-1C-1S+
# serial number = 91500A71B096
/interface bridge
add fast-forward=no name=bridge-local
add fast-forward=no name=zbridge-bro
/interface ethernet
set [ find default-name=combo1 ] comment=WAN1 mac-address=CC:2D:E0:1F:46:24 \
name=ether0-WAN1
set [ find default-name=ether1 ] comment=WAN2 disabled=yes mac-address=\
CC:2D:E0:1F:46:25 name=ether1-WAN2 speed=100Mbps
set [ find default-name=ether2 ] comment=WAN3 disabled=yes mac-address=\
CC:2D:E0:1F:46:26 name=ether2-WAN3 speed=100Mbps
set [ find default-name=ether3 ] comment=LAN mac-address=CC:2D:E0:1F:46:27 \
speed=100Mbps
set [ find default-name=ether4 ] comment=LAN mac-address=CC:2D:E0:1F:46:28 \
speed=100Mbps
set [ find default-name=ether5 ] advertise=\
10M-full,100M-full,1000M-full,2500M-full arp=proxy-arp comment=BROADBAND \
mac-address=CC:2D:E0:1F:46:29 speed=100Mbps
set [ find default-name=ether6 ] comment=LAN mac-address=CC:2D:E0:1F:46:2A \
mtu=1580 speed=100Mbps
set [ find default-name=ether7 ] comment=LAN mac-address=CC:2D:E0:1F:46:2B \
speed=100Mbps
set [ find default-name=sfp-sfpplus1 ] advertise=\
10M-full,100M-full,1000M-full disabled=yes mac-address=CC:2D:E0:1F:46:23
/interface pppoe-client
add add-default-route=yes dial-on-demand=yes disabled=no interface=\
ether0-WAN1 keepalive-timeout=disabled name=pppoe-out1 password=286364 \
use-peer-dns=yes user=YCSC08-032020
/interface ethernet switch
set 0 name=switch1
set 1 name=switch2
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk eap-methods="" \
group-ciphers=tkip,aes-ccm mode=dynamic-keys supplicant-identity=MikroTik \
unicast-ciphers=tkip,aes-ccm wpa-pre-shared-key=1212121212 \
wpa2-pre-shared-key=1212121212
add authentication-types=wpa-psk eap-methods="" group-ciphers=tkip \
management-protection=allowed mode=dynamic-keys name=se1233 \
supplicant-identity="" unicast-ciphers=tkip wpa-pre-shared-key=se1233 \
wpa2-pre-shared-key=se1233
add authentication-types=wpa-psk eap-methods="" management-protection=allowed \
mode=dynamic-keys name=ianwifi supplicant-identity="" \
wpa-pre-shared-key=wifi123 wpa2-pre-shared-key=sec1234
/ip hotspot profile
set [ find default=yes ] login-by=""
/ip ipsec profile
add dh-group=modp2048 enc-algorithm=aes-256,aes-128,3des name=profile_1
/ip ipsec peer
add name=peer1 passive=yes profile=profile_1
/ip ipsec proposal
set [ find default=yes ] enc-algorithms=aes-256-cbc,aes-128-cbc pfs-group=\
none
/ip kid-control
add name=5t
/ip pool
add name=local-pool ranges=192.168.175.150-192.168.175.200
add name=guest-pool ranges=180.180.180.10-180.180.180.254
add name=vilcore-secure ranges=150.150.150.10-150.150.150.254
add name=hs-homebro1 ranges=10.20.0.0/24
add name=hs-homebro3 ranges=10.22.0.0/24
add name=hs-homebro2 ranges=10.21.0.0/24
/ip dhcp-server
add address-pool=local-pool disabled=no interface=bridge-local lease-time=1h \
name=local-dhcp
add address-pool=guest-pool bootp-support=none disabled=no lease-time=3h \
name=guest-dhcp
add address-pool=vilcore-secure authoritative=after-2sec-delay disabled=no \
lease-time=3h name=vilcore-dhcp
add add-arp=yes address-pool=hs-homebro1 bootp-support=none interface=\
zbridge-bro lease-time=3h name=bro-dhcp
/port
set 0 baud-rate=auto name=serial0
set 1 name=usb2
/ppp profile
set *FFFFFFFE use-encryption=default
/snmp community
set [ find default=yes ] addresses=0.0.0.0/0
/user group
set read policy="local,read,test,winbox,api,romon,tikapp,!telnet,!ssh,!ftp,!re\
boot,!write,!policy,!password,!web,!sniff,!sensitive,!dude"
set write policy="reboot,read,write,policy,test,web,sniff,sensitive,api,!local\
,!telnet,!ssh,!ftp,!winbox,!password,!romon,!dude,!tikapp"
add name=admin policy="reboot,read,write,test,password,web,api,!local,!telnet,\
!ssh,!ftp,!policy,!winbox,!sniff,!sensitive,!romon,!dude,!tikapp"
add name=techedit policy="telnet,reboot,read,write,test,winbox,api,!local,!ssh\
,!ftp,!policy,!password,!web,!sniff,!sensitive,!romon,!dude,!tikapp"
add name=adminftp policy="ftp,reboot,read,write,password,api,!local,!telnet,!s\
sh,!policy,!test,!winbox,!web,!sniff,!sensitive,!romon,!dude,!tikapp"
add name=adminowner policy="reboot,read,write,test,password,web,api,!local,!te\
lnet,!ssh,!ftp,!policy,!winbox,!sniff,!sensitive,!romon,!dude,!tikapp"
add name=adminsave policy="reboot,read,write,policy,test,web,api,!local,!telne\
t,!ssh,!ftp,!winbox,!password,!sniff,!sensitive,!romon,!dude,!tikapp"
add name=terminal policy="local,telnet,write,password,web,!ssh,!ftp,!reboot,!r\
ead,!policy,!test,!winbox,!sniff,!sensitive,!api,!romon,!dude,!tikapp"
add name=PPP policy="read,write,test,password,web,api,!local,!telnet,!ssh,!ftp\
,!reboot,!policy,!winbox,!sniff,!sensitive,!romon,!dude,!tikapp"
/caps-man manager
set ca-certificate=auto certificate=auto
/interface bridge port
add bridge=bridge-local comment=LAN hw=no interface=ether3
add bridge=bridge-local comment=HOTSPOT hw=no interface=ether4
add bridge=zbridge-bro comment=BROADBAND interface=ether5
add bridge=bridge-local comment=LAN interface=ether7
add bridge=bridge-local comment=LAN interface=ether6
/ip neighbor discovery-settings
set discover-interface-list=all
/ip settings
set allow-fast-path=no
/interface detect-internet
set internet-interface-list=all lan-interface-list=all wan-interface-list=all
/interface l2tp-server server
set enabled=yes ipsec-secret=12345 max-mru=1400 max-mtu=1400 \
one-session-per-host=yes
/interface ovpn-server server
set auth=sha1 certificate=server-certificate cipher=aes256 \
require-client-certificate=yes
/interface pppoe-server server
add disabled=no interface=zbridge-bro keepalive-timeout=disabled max-mru=1464 \
max-mtu=1464 service-name="BROADBAND"
/interface pptp-server server
set authentication=pap,chap,mschap1,mschap2 enabled=yes max-mru=1460 max-mtu=\
1460
/interface sstp-server server
set authentication=pap
/ip address
add address=192.168.175.1/24 interface=bridge-local network=192.168.175.0
add address=172.16.50.1/24 network=172.16.50.0
add address=172.16.60.1/24 network=172.16.60.0
add address=180.180.180.1/24 network=180.180.180.0
add address=150.150.150.1/24 network=150.150.150.0
add address=172.16.51.1/24 network=172.16.51.0
add address=172.16.61.1/24 network=172.16.61.0
add address=172.16.52.1/24 network=172.16.52.0
add address=172.16.53.1/24 network=172.16.53.0
add address=172.16.54.1/24 network=172.16.54.0
add address=172.16.55.1/24 network=172.16.55.0
add address=192.168.9.2 disabled=yes interface=ether2-WAN3 network=\
192.168.9.1
add address=192.168.176.1/24 interface=zbridge-bro network=192.168.176.0
/ip arp
add address=172.16.55.250 mac-address=90:A2:DA:45:DE:FC
/ip cloud
set update-time=no
/ip dhcp-client
add comment=WAN2 default-route-distance=2 dhcp-options=clientid,hostname \
interface=ether1-WAN2 use-peer-dns=no
add comment=WAN3 default-route-distance=3 interface=ether2-WAN3
add comment=WAN1 dhcp-options=clientid,clientid,hostname,clientid interface=\
ether0-WAN1
/ip dhcp-server
add add-arp=yes address-pool=hs-unauthenticated bootp-support=none disabled=\
no lease-time=6h name=hotspot-dhcp
/ip dhcp-server lease
add address=172.16.55.7 always-broadcast=yes client-id=1:cc:6e:a4:d8:c4:2d \
comment="SAMSUNG SMARTV" mac-address=C0:48:E6:CC:B2:4C server=\
hotspot-dhcp
add address=192.168.175.252 client-id=1:c0:48:e6:cc:b2:4c comment=\
"SAMSUNG SMARTV" mac-address=C0:48:E6:CC:B2:4C server=local-dhcp
/ip dhcp-server network
add address=150.150.150.0/24 dns-server=150.150.150.1 gateway=150.150.150.1 \
netmask=24 ntp-server=150.150.150.1
add address=172.16.50.0/24 dns-server=172.16.50.1 gateway=172.16.50.1 \
netmask=32 ntp-server=172.16.50.1
add address=172.16.51.0/24 dns-server=172.16.50.1 gateway=172.16.51.1 \
netmask=32 ntp-server=172.16.50.1
add address=172.16.52.0/24 dns-server=172.16.50.1 gateway=172.16.52.1 \
netmask=32 ntp-server=172.16.50.1
add address=172.16.53.0/24 dns-server=172.16.50.1 gateway=172.16.53.1 \
netmask=32 ntp-server=172.16.50.1
add address=172.16.54.0/24 dns-server=172.16.50.1 gateway=172.16.54.1 \
netmask=32 ntp-server=172.16.50.1
add address=172.16.55.0/24 dns-server=172.16.50.1 gateway=172.16.55.1 \
netmask=32 ntp-server=172.16.50.1
add address=180.180.180.0/24 dns-server=180.180.180.1 gateway=180.180.180.1 \
netmask=32 ntp-server=180.180.180.1
add address=192.168.175.0/24 dns-server=192.168.175.1 gateway=192.168.175.1 \
netmask=24 ntp-server=192.168.175.1
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.175.1 name=admin.portal
add address=8.8.8.8 name=dns.google
add address=8.8.4.4 name=dns.google
/ip firewall nat
add action=masquerade chain=srcnat comment=WAN1 out-interface=pppoe-out1 \
time=0s-1d,sun,mon,tue,wed,thu,fri,sat
add action=dst-nat chain=dstnat dst-address=101.58.69.101 dst-port=3389 log=\
yes protocol=tcp to-addresses=10.20.0.255 to-ports=8292
/ip firewall raw
add action=drop chain=prerouting comment="BLOCK YOUTUBE" content=youtube \
disabled=yes
add action=drop chain=prerouting content=googlevideo disabled=yes
add action=drop chain=prerouting comment="BLOCK Y8" content=y8 disabled=yes
/ip hotspot user
set [ find default=yes ] limit-bytes-total=209715200
/ip hotspot user profile
set [ find default=yes ] add-mac-cookie=no address-pool=hs-wifi \
keepalive-timeout=15m name=EXPIRED rate-limit=1k/1k shared-users=100 \
status-autorefresh=5m
/ip ipsec identity
add generate-policy=port-override peer=peer1 remote-id=ignore secret=12345
/ip pool
add name=hs-wifi next-pool=hs-wifi ranges=\
172.16.60.10-172.16.60.254,172.16.61.10-172.16.61.254
add name=hs-unauthenticated next-pool=hs-unauthenticated ranges="172.16.55.20-\
172.16.55.254,172.16.54.10-172.16.54.254,172.16.53.10-172.16.53.254,172.16\
.52.10-172.16.52.254,172.16.51.10-172.16.51.254,172.16.50.10-172.16.50.254\
"
/ip route
add comment=WAN2 disabled=yes distance=1 gateway=2.2.2.2 routing-mark=PL2
add check-gateway=ping comment=WAN3 disabled=yes distance=1 gateway=\
192.168.8.1 routing-mark=PL3
add check-gateway=ping comment=WAN1 distance=1 gateway=pppoe-out1
add check-gateway=ping comment="NETWATCH WAN3" distance=1 dst-address=\
8.8.4.4/32 gateway=192.168.8.1
add check-gateway=ping comment="NETWATCH WAN1" distance=1 dst-address=\
8.8.8.8/32 gateway=192.168.1.1
/ip route rule
add dst-address=0.0.0.0/0 routing-mark=RT-PL1 src-address=0.0.0.0/0 table=PL1
add dst-address=0.0.0.0/0 routing-mark=RT-PL2 src-address=0.0.0.0/0 table=PL2
add dst-address=0.0.0.0/0 routing-mark=RT-PL3 src-address=0.0.0.0/0 table=PL3
add dst-address=0.0.0.0/0 routing-mark=RT-PL4 src-address=0.0.0.0/0 table=PL4
add dst-address=0.0.0.0/0 routing-mark=RT-PL5 src-address=0.0.0.0/0 table=PL5
/ip service
set telnet address="172.16.50.0/24,172.16.51.0/24,172.16.52.0/24,172.16.53.0/2\
4,172.16.54.0/24,172.16.55.0/24,192.168.175.0/24"
set ftp address=192.168.175.251/32 disabled=yes
set www port=82
set ssh disabled=yes
set www-ssl certificate=ca-certificate
set winbox port=8291
set api-ssl disabled=yes
/ip smb
set allow-guests=no
/ip ssh
set allow-none-crypto=yes forwarding-enabled=remote
/ip upnp
set show-dummy-rule=no
/lcd
set backlight-timeout=never color-scheme=dark default-screen=interfaces \
read-only-mode=yes
/lcd interface
set *1 disabled=yes
set *2 disabled=yes
set *3 disabled=yes
set *4 disabled=yes
set *5 disabled=yes
set *6 disabled=yes
set *7 disabled=yes
set *8 disabled=yes
set *9 disabled=yes
set *A disabled=yes
set *B disabled=yes
set *C disabled=yes
set *16 disabled=yes
set sfp-sfpplus1 disabled=yes
set ether3 disabled=yes
set ether4 disabled=yes
set ether5 disabled=yes
set ether6 disabled=yes
set ether7 disabled=yes
/lcd screen
set 2 disabled=yes
set 3 disabled=yes
set 4 disabled=yes
set 5 disabled=yes
/ppp aaa
set accounting=no
/ppp profile
set *0 dns-server=192.168.175.1 local-address=hs-unauthenticated \
remote-address=local-pool
/ppp secret
add name=p password=1 profile=default-encryption service=l2tp
/radius incoming
set accept=yes
/system clock
set time-zone-autodetect=no time-zone-name=Asia/Manila
/system clock manual
set time-zone=+08:00
/system identity
set name=ION
/system leds
set 0 interface=ether0-WAN1 leds=user-led type=interface-status
/system logging
add disabled=yes topics=e-mail
/system ntp client
set enabled=yes primary-ntp=162.159.200.1 secondary-ntp=162.159.200.123
/system watchdog
set automatic-supout=no watchdog-timer=no
/tool e-mail
set address=74.125.68.109 from="" start-tls=yes
/tool graphing
set store-every=hour
/tool romon
set secrets=bki
/tool romon port