Fri Jan 28, 2011 12:55 am
[admin@MikroTik] > /ip address print detail
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; Public Static
address=199.X.X.X/28 network=199.X.X.X broadcast=199.X.X.X
interface=Public actual-interface=Public
1 ;;; Internal Privates
address=10.X.X.X/24 network=10.X.X.X broadcast=10.X.X.X
interface=ether2-local-master actual-interface=ether2-local-master
[admin@MikroTik] > /ip route print detail
Flags: X - disabled, A - active, D - dynamic,
C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme,
B - blackhole, U - unreachable, P - prohibit
0 A S dst-address=0.0.0.0/0 gateway=199.X.X.X
gateway-status=199.X.X.X reachable Public distance=1 scope=30
target-scope=10
1 ADC dst-address=10.X.X.X/24 pref-src=10.X.X.X
gateway=ether2-local-master
gateway-status=ether2-local-master reachable distance=0 scope=10
2 ADC dst-address=199.X.X.X/28 pref-src=199.X.X.X gateway=Public
gateway-status=Public reachable distance=0 scope=10
[admin@MikroTik] > /interface print
Flags: D - dynamic, X - disabled, R - running, S - slave
# NAME TYPE MTU L2MTU
0 R Public ether 1500 1524
1 R ether2-local-master ether 1500 1524
2 ether3-local-slave ether 1500 1524
3 R ether4-local-slave ether 1500 1524
4 R ether5-local-slave ether 1500 1524
[admin@MikroTik] > /ip firewall export
# jan/07/1970 21:23:56 by RouterOS 4.16
# software id = FK91-TZAZ
#
/ip firewall connection tracking
set enabled=yes generic-timeout=10m icmp-timeout=10s tcp-close-timeout=10s \
tcp-close-wait-timeout=10s tcp-established-timeout=1d \
tcp-fin-wait-timeout=10s tcp-last-ack-timeout=10s \
tcp-syn-received-timeout=5s tcp-syn-sent-timeout=5s tcp-syncookie=no \
tcp-time-wait-timeout=10s udp-stream-timeout=3m udp-timeout=10s
/ip firewall filter
add action=accept chain=input comment="default configuration" disabled=no \
protocol=icmp
add action=accept chain=input comment="default configuration" \
connection-state=established disabled=no in-interface=Public
add action=accept chain=input comment="default configuration" \
connection-state=related disabled=no in-interface=Public
add action=accept chain=input comment="Winbox Access from Wan" disabled=no \
in-interface=Public port=8291 protocol=tcp
add action=drop chain=input comment="default configuration" disabled=no \
in-interface=Public
/ip firewall nat
add action=masquerade chain=srcnat comment="default configuration" disabled=\
no out-interface=Public
add action=dst-nat chain=dstnat comment="Eric VNC Help Desk" disabled=no \
dst-port=5999 protocol=tcp to-addresses=10.X.X.X to-ports=5999
add action=dst-nat chain=dstnat comment="Eric VNC Help Desk" disabled=no \
dst-port=5999 protocol=udp to-addresses=10.X.X.X to-ports=5999
add action=dst-nat chain=dstnat comment="Cam VNC Help Desk" disabled=no \
dst-port=5998 protocol=tcp to-addresses=10.X.X.X to-ports=5998
add action=dst-nat chain=dstnat comment="Cam VNC Help Desk" disabled=no \
dst-port=5998 protocol=udp to-addresses=10.X.X.X to-ports=5998
add action=dst-nat chain=dstnat comment="Marv VNC Help Desk" disabled=no \
dst-port=5997 protocol=tcp to-addresses=10.X.X.X to-ports=5997
add action=dst-nat chain=dstnat comment="Marv VNC Help Desk" disabled=no \
dst-port=5997 protocol=udp to-addresses=10.X.X.X to-ports=5997
add action=dst-nat chain=dstnat comment="Remote Desktop to Eric Workstation" \
disabled=no dst-port=3389 in-interface=Public protocol=tcp to-addresses=\
10.X.X.X
add action=dst-nat chain=dstnat comment="Remote Desktop to Eric workstation" \
disabled=yes dst-port=3389 in-interface=Public protocol=udp to-addresses=\
10.X.X.X
/ip firewall service-port
set ftp disabled=no ports=21
set tftp disabled=no ports=69
set irc disabled=no ports=6667
set h323 disabled=no
set sip disabled=no ports=5060,5061
set pptp disabled=no
[admin@MikroTik] >