# may/25/2023 16:00:38 by RouterOS 6.49.8 # software id = WN7W-BHXZ # # model = RouterBOARD 3011UiAS # serial number = 8EED09A1007B /caps-man channel add band=2ghz-b/g/n name=channel2 /interface bridge add arp=proxy-arp mtu=1500 name=bridge protocol-mode=none /interface ethernet set [ find default-name=ether1 ] speed=100Mbps set [ find default-name=ether2 ] advertise=\ 100M-half,100M-full,1000M-half,1000M-full,2500M-full comment=Home speed=\ 100Mbps set [ find default-name=ether3 ] comment="\CD\EE\F3\F2 2 \FD\F2\E0\E6" speed=\ 100Mbps set [ find default-name=ether4 ] advertise=\ 100M-half,100M-full,1000M-half,1000M-full comment="ipcam 1mp .243" set [ find default-name=ether5 ] comment="Tyan .5" speed=100Mbps set [ find default-name=ether6 ] advertise=\ 100M-half,100M-full,1000M-half,1000M-full comment=Garage set [ find default-name=ether7 ] advertise=\ 100M-half,100M-full,1000M-half,1000M-full comment="Garden WiFi .14" set [ find default-name=ether8 ] advertise=\ 100M-half,100M-full,1000M-half,1000M-full comment="ipcam 5mp .222" set [ find default-name=ether9 ] advertise=\ 100M-half,100M-full,1000M-half,1000M-full comment="2et desktop" set [ find default-name=ether10 ] advertise=\ 100M-half,100M-full,1000M-half,1000M-full,2500M-full comment="Keno 2" \ poe-out=off set [ find default-name=sfp1 ] advertise=\ 100M-half,100M-full,1000M-half,1000M-full comment=ip-home speed=100Mbps /interface pptp-server add disabled=yes name=pptp-lytkarino user=lytkarino /caps-man datapath add bridge=bridge client-to-client-forwarding=yes local-forwarding=yes name=\ datapath1 /caps-man security add authentication-types=wpa2-psk disable-pmkid=yes encryption=aes-ccm \ group-key-update=1h name=security2 /caps-man configuration add channel=channel2 channel.band=2ghz-b/g/n channel.extension-channel=Ce \ country=no_country_set datapath=datapath1 distance=dynamic \ frame-lifetime=0ms hw-protection-mode=rts-cts hw-retries=10 installation=\ outdoor max-sta-count=2007 mode=ap multicast-helper=full name=cfg2 \ rates.basic=36Mbps,48Mbps,54Mbps rates.ht-basic-mcs="" \ rates.ht-supported-mcs="" rates.supported=36Mbps,48Mbps,54Mbps \ rates.vht-basic-mcs="" rates.vht-supported-mcs="" rx-chains=0,1,2,3 \ security=security2 ssid=WiFi tx-chains=0,1,2,3 /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik /ip ipsec profile add name=NordVPN /ip ipsec proposal set [ find default=yes ] enc-algorithms=3des add enc-algorithms=3des name=NordVPN pfs-group=none /ip pool add name=dhcp_pool ranges=10.0.0.230-10.0.0.253 add name=vpn_pool ranges=10.0.0.55-10.0.0.65 /ip dhcp-server add address-pool=dhcp_pool authoritative=after-2sec-delay bootp-support=none \ disabled=no interface=bridge lease-time=59m59s name=home /ppp profile add change-tcp-mss=yes local-address=10.0.1.1 name=pptp only-one=no \ remote-address=10.0.1.2 use-compression=yes use-encryption=yes use-mpls=\ no use-upnp=no add dns-server=8.8.8.8,8.8.4.4 local-address=10.1.10.1 name=l2tp \ remote-address=vpn_pool set *FFFFFFFE only-one=no use-compression=yes use-mpls=no use-upnp=no /system logging action set 1 disk-file-count=3 /tool traffic-generator port add interface=ether2 name=ether2 /caps-man manager set enabled=yes /caps-man provisioning add action=create-dynamic-enabled master-configuration=cfg2 name-format=\ prefix-identity name-prefix=CAP /interface bridge port add bridge=bridge interface=ether2 add bridge=bridge interface=ether3 add bridge=bridge interface=ether4 add bridge=bridge interface=ether5 add bridge=bridge interface=ether6 add bridge=bridge interface=ether7 add bridge=bridge hw=no interface=ether9 add bridge=bridge interface=ether10 add bridge=bridge interface=ether8 add bridge=bridge interface=ether1 /ip neighbor discovery-settings set discover-interface-list=all /ip settings set allow-fast-path=no /interface l2tp-server server set authentication=mschap2 use-ipsec=yes /interface pptp-server server set enabled=yes max-mru=1460 max-mtu=1460 /ip address add address=10.0.0.1/24 interface=bridge network=10.0.0.0 /ip arp add address=10.0.0.13 interface=bridge mac-address=FC:75:16:64:7B:28 /ip cloud set ddns-update-interval=5m update-time=no /ip dhcp-client add disabled=no interface=sfp1 use-peer-ntp=no /ip dhcp-server lease add address=10.0.0.3 always-broadcast=yes comment="\C8\E3\F0\F3\EB\FF" \ mac-address=FC:75:16:64:7B:28 server=home add address=10.0.0.7 comment="\CA\E0\EC\E5\F0\E0 \D3\F7\E0\F1\F2\EE\EA" \ mac-address=00:27:22:61:95:28 server=home add address=10.0.0.8 always-broadcast=yes comment=\ "\CA\E0\EC\E5\F0\E0 \C4\E2\EE\F0" mac-address=00:12:31:67:89:0D server=\ home add address=10.0.0.5 comment=Tyan mac-address=00:E0:81:31:BF:CA server=home add address=10.0.0.11 always-broadcast=yes client-id=1:2c:59:e5:ee:59:a \ comment="\CF\F0\E8\ED\F2\E5\F0" mac-address=2C:59:E5:EE:59:0A server=home add address=10.0.0.10 comment="\D1\E2\E8\F2\F7\E5\F0" mac-address=\ 42:49:54:00:02:F5 server=home add address=10.0.0.6 always-broadcast=yes comment=\ "\CA\E0\EC\E5\F0\E0 \C3\E0\F0\E0\E6" mac-address=00:27:22:60:3F:B8 \ server=home add address=10.0.0.12 comment="MikroTik Garage" mac-address=00:0C:42:C3:F7:7E \ server=home add address=10.0.0.50 client-id=1:dc:9f:db:29:fb:8a comment=EdgeSwitch5xp \ mac-address=DC:9F:DB:29:FB:8A server=home add address=10.0.0.14 client-id=1:4c:5e:c:a6:d9:ff comment="MikroTik Garden" \ mac-address=4C:5E:0C:A6:D9:FF server=home add address=10.0.0.15 allow-dual-stack-queue=no comment="Eth - rs485" \ mac-address=00:7B:72:E0:4C:17 server=home add address=10.0.0.9 client-id=1:0:27:22:61:16:53 comment=\ "\CA\E0\EC\E5\F0\E0 \D1\E5\F0\E2\E5\F0" mac-address=00:27:22:61:16:53 \ server=home add address=10.0.0.123 client-id=1:0:21:52:8:b5:95 comment="GS B520" \ mac-address=00:21:52:08:B5:95 server=home add address=10.0.0.122 client-id=1:e4:7d:bd:dc:8e:e5 comment=\ "Samsung UE22H5600AK" mac-address=E4:7D:BD:DC:8E:E5 server=home add address=10.0.0.230 comment="\CA\F3\F0\FF\F2\ED\E8\EA Sonoff TH16" \ mac-address=B4:E6:2D:32:DC:19 server=home add address=10.0.0.245 client-id=1:0:d1:ff:6:18:33 comment=NVR mac-address=\ 00:D1:FF:06:18:33 server=home add address=10.0.0.247 client-id=1:0:98:bb:cd:a5:b3 comment="Keno cam1" \ mac-address=00:98:BB:CD:A5:B3 server=home add address=10.0.0.13 comment="MikroTik Home" mac-address=6C:3B:6B:BE:A4:85 \ server=home add address=10.0.0.121 block-access=yes client-id=1:c0:41:f6:75:91:a8 \ comment="LG TV 47LM640T-ZA" mac-address=C0:41:F6:75:91:A8 server=home add address=10.0.0.224 client-id=ff:6e:70:5f:e2:0:3:0:1:b8:87:6e:70:5f:e2 \ comment="\C2\E8\EA\E8\ED\E3 \C0\EB\E8\F1\E0 \CB\E0\E9\F2" mac-address=\ B8:87:6E:70:5F:E2 server=home add address=10.0.0.228 client-id=1:34:51:c9:5e:43:19 comment="iPad 2" \ mac-address=34:51:C9:5E:43:19 server=home add address=10.0.0.226 client-id=1:ec:d0:9f:be:9b:ed comment="Xiaomi Mi 6" \ mac-address=EC:D0:9F:BE:9B:ED server=home add address=10.0.0.227 client-id=1:e2:5c:6f:4d:a3:dd comment="Vivo Y31" \ mac-address=E2:5C:6F:4D:A3:DD server=home add address=10.0.0.212 comment="\D1\E2\E5\F2 \ED\E0 \F3\F7\E0\F1\F2\EA\E5" \ mac-address=4C:EB:D6:C2:58:D1 server=home add address=10.0.0.213 comment="\D1\E2\E5\F2 \F3 \F2\E5\EF\EB\E8\F6\FB" \ mac-address=24:A1:60:1A:FB:6D server=home add address=10.0.0.229 block-access=yes client-id=1:f4:60:e2:ce:a6:ee \ comment=Vik-Pik mac-address=F4:60:E2:CE:A6:EE server=home add address=10.0.0.223 comment="\C2\E8\EA\E8\ED\E3 \CB\E0\EC\EF\E0" \ mac-address=70:03:9F:9A:EE:25 server=home add address=10.0.0.124 client-id=1:e0:b6:55:e9:78:98 comment="Xiaomi MIBOX4" \ mac-address=E0:B6:55:E9:78:98 server=home add address=10.0.0.248 client-id=1:dc:29:19:e2:41:70 comment=\ "Camera 5mp wifi" mac-address=DC:29:19:E2:41:70 server=home add address=10.0.0.225 comment="Xiaomi Gateway 2" mac-address=\ 04:CF:8C:A1:65:21 server=home add address=10.0.0.214 comment="\C3\E0\F0\E0\E6 \E2\FB\F2\FF\E6\EA\E0" \ mac-address=C4:4F:33:EA:E5:83 server=home add address=10.0.0.246 comment="Keno 2" mac-address=00:8D:8F:C8:07:32 server=\ home add address=10.0.0.211 client-id=1:40:22:d8:61:a7:d0 comment=\ "\CA\EE\F2\E5\EB Elite THD16" mac-address=40:22:D8:61:A7:D0 server=home /ip dhcp-server network add address=10.0.0.0/24 dns-server=10.0.0.1,10.10.10.3,10.10.10.2 domain=Home \ gateway=10.0.0.1 netmask=24 ntp-server=10.0.0.1 /ip dns set allow-remote-requests=yes /ip dns static add address=10.0.0.5 name=home.ratser.ru /ip firewall filter add action=log chain=output disabled=yes dst-address=10.0.0.1 log=yes add action=accept chain=output out-interface=bridge add action=accept chain=input in-interface=bridge add action=accept chain=input comment="pptp gre" connection-state=new \ protocol=gre add action=accept chain=input comment="pptp tcp" connection-state=new \ dst-port=1723 protocol=tcp add action=fasttrack-connection chain=forward connection-state=\ established,related disabled=yes add action=accept chain=input disabled=yes protocol=icmp add action=accept chain=input disabled=yes protocol=igmp add action=reject chain=forward disabled=yes dst-address=10.0.0.222 protocol=\ tcp reject-with=tcp-reset add action=drop chain=input dst-port=53 in-interface=sfp1 protocol=udp add action=drop chain=input dst-port=53 in-interface=sfp1 protocol=tcp add action=accept chain=forward in-interface=bridge out-interface=bridge /ip firewall mangle add action=change-mss chain=forward disabled=yes new-mss=1360 passthrough=yes \ protocol=tcp tcp-flags=syn tcp-mss=1453-65535 add action=change-mss chain=forward disabled=yes new-mss=clamp-to-pmtu \ passthrough=yes protocol=tcp tcp-flags=syn /ip firewall nat add action=masquerade chain=srcnat out-interface=sfp1 src-address=10.0.0.0/24 add action=masquerade chain=srcnat disabled=yes out-interface=sfp1 \ src-address=10.0.0.0/24 add action=masquerade chain=srcnat dst-address=10.0.0.5 dst-port=80,443 \ protocol=tcp src-address=10.0.0.0/24 add action=dst-nat chain=dstnat dst-port=80,443 in-interface=sfp1 protocol=\ tcp to-addresses=10.0.0.5 add action=dst-nat chain=dstnat comment=Dvor dst-port=81 in-interface=sfp1 \ protocol=tcp to-addresses=10.0.0.8 to-ports=80 add action=dst-nat chain=dstnat comment=Garden dst-port=82 in-interface=sfp1 \ protocol=tcp to-addresses=10.0.0.7 to-ports=80 add action=dst-nat chain=dstnat comment=Garage dst-port=83 in-interface=sfp1 \ protocol=tcp to-addresses=10.0.0.6 to-ports=80 add action=dst-nat chain=dstnat comment="5mp wifi" dst-port=84 in-interface=\ sfp1 protocol=tcp to-addresses=10.0.0.249 to-ports=80 add action=dst-nat chain=dstnat comment="Keno 1" dst-port=85 in-interface=\ sfp1 protocol=tcp to-addresses=10.0.0.247 to-ports=80 add action=dst-nat chain=dstnat comment="MikroTik Home" disabled=yes \ dst-port=8081 in-interface=ether1 protocol=tcp to-addresses=10.0.0.230 \ to-ports=80 add action=dst-nat chain=dstnat comment=webmin dst-port=10 in-interface=sfp1 \ protocol=tcp to-addresses=10.0.0.5 to-ports=10000 add action=dst-nat chain=dstnat comment="ssh .5" dst-port=222 in-interface=\ sfp1 protocol=tcp to-addresses=10.0.0.5 to-ports=22 add action=dst-nat chain=dstnat comment="home mikrotik" disabled=yes \ dst-port=8888 in-interface=ether1 protocol=tcp to-addresses=10.0.0.13 \ to-ports=8291 add action=dst-nat chain=dstnat comment="switcher http" disabled=yes \ dst-port=666 in-interface=ether1 protocol=tcp to-addresses=10.0.0.10 \ to-ports=80 add action=dst-nat chain=dstnat comment=GardenRB disabled=yes dst-port=1111 \ in-interface=ether1 protocol=tcp to-addresses=10.0.0.14 to-ports=80 add action=dst-nat chain=dstnat comment="ratser FTP 21" dst-port=21 \ in-interface=sfp1 protocol=tcp to-addresses=10.0.0.5 add action=dst-nat chain=dstnat comment="ratser FTP passive" dst-port=\ 49152-65534 in-interface=sfp1 protocol=tcp to-addresses=10.0.0.5 add action=dst-nat chain=dstnat comment="netbook openvpn" disabled=yes \ dst-address=109.206.131.152 dst-port=465 protocol=tcp to-addresses=\ 10.0.0.208 to-ports=465 add action=dst-nat chain=dstnat comment="netbook radmin" disabled=yes \ dst-address=109.206.131.152 dst-port=4899 protocol=tcp to-addresses=\ 10.0.0.208 to-ports=4899 add action=dst-nat chain=dstnat comment="netbook FTP 22" disabled=yes \ dst-address=109.206.131.152 dst-port=2121 protocol=tcp to-addresses=\ 10.0.0.208 to-ports=2121 add action=dst-nat chain=dstnat comment="netbook FTP passive" disabled=yes \ dst-address=109.206.131.152 dst-port=1024-1074 protocol=tcp to-addresses=\ 10.0.0.208 to-ports=1024-1074 /ip firewall service-port set tftp disabled=yes set irc disabled=yes set h323 disabled=yes set sip disabled=yes set udplite disabled=yes set dccp disabled=yes set sctp disabled=yes /ip service set telnet disabled=yes set www disabled=yes set ssh disabled=yes set api disabled=yes set winbox address=\ 10.0.0.0/24,109.206.131.152/32,213.221.40.210/32,46.34.128.207/32 set api-ssl disabled=yes /ppp secret add disabled=yes name=lytkarino /system clock set time-zone-name=Europe/Moscow /system ntp client set enabled=yes primary-ntp=89.109.251.22 secondary-ntp=89.109.251.23 /system routerboard settings set auto-upgrade=yes /system ups add name=ups1 port=usbhid1 /tool bandwidth-server set authenticate=no enabled=no