Devices in VLAN in Management Bridge unreachable

I have 4 devices, each of them has management vlan enabled as VLAN 10.
2 devices are connected to ether2 and the other 2 devices are connected to ether3

So, I create a VLAN with ID 10 on ether2 and another VLAN 10 on ether3.
Then I create a Bridge called Management Bridge and give it an IP of 172.16.0.1/24
Then I add the two VLANs into the Management Bridge

DHCP server is running on the Management Bridge and gives out IPs on the 172.16.0.1/24 range.

If I add both the ether2 and ether3 and both VLANS to the management bridge, then I can reach the devices. But if the ether interfaces are not in the bridge the devices are unreachable.

Could you tell me what is the correct way of doing this?

post your config
/export hide-sensitive file=yourconfig

Well, the original post is a very simplified version of my config. My actual config is more complex. Could I PM you my output?

Check https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Management_access_configuration and also examples before that, they will help you to understand basics.

i dont play whackamole with attempting to solve config issues.
Just remove any sensitive bits (dont need to see any vpn stuff, dhcp leases, any firewall address lists, etc…
as a minimum

interface ethernet
ip addresses
vlan config
bridge config
bridge port config
birdge vlan config
dhcp-server
ip pool
dhcp-server network
firewall rules (all)
ip dns
interface list and list member

So exactly whats happening is, if i move Management-VLAN10-Ether5 into the Management-Bridge then I cannot access the devices, even though the DHCP server hands them IPs. But If I add it to the new bridge called Cambium-Bridge then i can access the devices.

Why not just cut and paste and use the code block in the FONT line a the top of the EDIT block.
My firewall/AV setup blocks pastebin LOL.

Removed

Because it was rather large, but I’ve did as you said.

The code Font icon is perfect for this (black square with white square brackets). :slight_smile:
Go to your post the one above this and try it (edit it).

#apr/24/2019 14:49:29 by RouterOS 6.44
# software id = 1937-YN8A
#
# model = CCR1016-12G
# serial number = 52A204A4AB7E
/interface bridge
add name=Cambium-Bridge
add fast-forward=no name=site2
add fast-forward=no name=LoopBack
add admin-mac=4C:5E:0C:4E:40:C7 auto-mac=no fast-forward=no name=\
    Management-Bridge
add fast-forward=no name=PTP-Bridge
add fast-forward=no name=RoomInHouse
add fast-forward=no name=bridge1
add disabled=yes name=bridge2
add disabled=yes name=bridge3
add disabled=yes name=bridge4
add fast-forward=no name=bridge5
/interface ethernet
set [ find default-name=ether1 ] name=INTERNET speed=100Mbps
set [ find default-name=ether2 ] comment=site2 name=ether2-ap1 speed=100Mbps
set [ find default-name=ether3 ] comment="PPPOE Server for Room Internet" \
    speed=100Mbps
set [ find default-name=ether4 ] comment="New Link site3 PtP" speed=100Mbps
set [ find default-name=ether5 ] comment=Cambium speed=100Mbps
set [ find default-name=ether6 ] speed=100Mbps
set [ find default-name=ether7 ] comment="UNMS Server" speed=100Mbps
set [ find default-name=ether8 ] comment=site4 rx-flow-control=auto \
    tx-flow-control=auto
set [ find default-name=ether9 ] advertise=\
    10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full comment=\
    Room-House-Internet-PPPOE speed=100Mbps
set [ find default-name=ether10 ] comment=Revid speed=100Mbps
set [ find default-name=ether11 ] comment=\
    "iDRAC   192.168.251.0/24 - server is 251.2" disabled=yes speed=100Mbps
set [ find default-name=ether12 ] speed=100Mbps
/interface pptp-client
add connect-to=splynxIP disabled=no name=Splynx-Tunnel user=Room
/interface vpls
add advertised-l2mtu=1530 mac-address=02:63:28:E5:F6:2B mtu=1530 name=\
    ManagNewSchool remote-peer=10.255.255.20 vpls-id=11:10
add disabled=no l2mtu=1500 mac-address=02:E1:39:1A:73:D6 name=\
    Management-Link-Baywest-PB remote-peer=10.255.255.31 vpls-id=31:1
add mac-address=02:B6:F6:54:A1:C3 name=Management-Link-site2 remote-peer=\
    10.255.255.20 vpls-id=20:1
add disabled=no l2mtu=1500 mac-address=02:A3:6E:51:FB:28 name=\
    Management-Link-Malabar-PB remote-peer=10.255.255.30 vpls-id=30:1
add mac-address=02:3D:7E:EA:3A:96 name=Management-Link-site4 remote-peer=\
    10.255.255.8 vpls-id=11:1
add advertised-l2mtu=1530 mac-address=02:F8:4C:BA:65:65 name=\
    Management-Link-site32 remote-peer=10.255.255.6 vpls-id=6:5
add advertised-l2mtu=1530 mac-address=02:BE:82:5C:B3:81 mtu=1530 name=\
    Management-School-2 remote-peer=10.255.255.22 vpls-id=22:1
add disabled=no l2mtu=1500 mac-address=02:CC:23:FC:9F:69 name=\
    Management-VPLS-Link-Barcelona remote-peer=10.255.255.4 vpls-id=4:10
add disabled=no l2mtu=1500 mac-address=02:85:B9:CB:8D:CB name=\
    Management-VPLS-Link-Hospital2 remote-peer=10.255.255.21 vpls-id=21:1
add disabled=no l2mtu=1500 mac-address=02:F8:4C:BA:65:65 name=\
    Management-VPLS-Link-Room5 remote-peer=10.255.255.5 vpls-id=5:5
add disabled=no l2mtu=1500 mac-address=02:CC:23:FC:9F:69 name=\
    Management-VPLS-Link-School remote-peer=10.255.255.3 vpls-id=3:10
add disabled=no l2mtu=1500 mac-address=02:9D:B5:06:38:E9 name=\
    Management-VPLS-Link-Room2 remote-peer=10.255.255.7 vpls-id=7:10
add disabled=no l2mtu=1500 mac-address=02:9D:B5:06:38:E9 name=\
    Management-VPLS-Link-Room9 remote-peer=10.255.255.2 vpls-id=2:10
add disabled=no l2mtu=1500 mac-address=02:C7:00:62:49:49 name=\
    Management-VPLS-site32-Core remote-peer=10.255.255.16 vpls-id=16:1
add disabled=no l2mtu=1500 mac-address=02:F8:4C:BA:65:65 name=\
    PPPoE-Barcelona-Sector-1 remote-peer=10.255.255.4 vpls-id=4:1
add disabled=no l2mtu=1500 mac-address=02:F8:4C:BA:65:65 name=\
    PPPoE-Barcelona-Sector-2 remote-peer=10.255.255.4 vpls-id=4:2
add disabled=no l2mtu=1500 mac-address=02:F8:4C:BA:65:65 name=\
    PPPoE-Barcelona-Sector-3 remote-peer=10.255.255.4 vpls-id=4:3
add disabled=no l2mtu=1500 mac-address=02:99:11:AC:B0:1A name=\
    PPPoE-Barcelona-Sector-4 remote-peer=10.255.255.4 vpls-id=4:4
add mac-address=02:15:23:79:11:A1 name=PPPoE-Barcelona-Sector-5 remote-peer=\
    10.255.255.4 vpls-id=4:5
add mac-address=02:4C:7E:A3:2A:B8 name=PPPoE-site2-Personal-Line \
    remote-peer=10.255.255.20 vpls-id=20:3
add mac-address=02:4C:7E:A3:2A:B8 name=PPPoE-site2-Sector-1 remote-peer=\
    10.255.255.20 vpls-id=20:2
add mac-address=02:F8:4C:BA:65:65 name=PPPoE-Hospital-1 remote-peer=\
    10.255.255.6 vpls-id=6:1
add mac-address=02:F8:4C:BA:65:65 name=PPPoE-Hospital-2 remote-peer=\
    10.255.255.6 vpls-id=6:2
add mac-address=02:F8:4C:BA:65:65 name=PPPoE-Hospital-3 remote-peer=\
    10.255.255.6 vpls-id=6:3
add mac-address=02:F8:4C:BA:65:65 name=PPPoE-Hospital-4 remote-peer=\
    10.255.255.6 vpls-id=6:4
add mac-address=02:B9:AB:64:96:46 name=PPPoE-Hospital-5 remote-peer=\
    10.255.255.6 vpls-id=6:6
add mac-address=02:D7:6E:B4:83:6D name=PPPoE-Hospital-6 remote-peer=\
    10.255.255.6 vpls-id=6:7
add mac-address=02:D4:27:CB:82:91 name=PPPoE-Hospital2-Sector-1 remote-peer=\
    10.255.255.21 vpls-id=21:2
add mac-address=02:FF:BB:64:86:2C name=PPPoE-Hospital2-Sector-2 remote-peer=\
    10.255.255.21 vpls-id=21:3
add mac-address=02:0B:D3:53:52:4F name=PPPoE-Hospital2-Sector-3 remote-peer=\
    10.255.255.21 vpls-id=21:4
add mac-address=02:DD:6C:75:E9:3B name=PPPoE-Hospital2-Sector-4 remote-peer=\
    10.255.255.21 vpls-id=21:5
add mac-address=02:20:9E:48:9C:E1 name=PPPoE-Hospital2-Sector-5 remote-peer=\
    10.255.255.21 vpls-id=21:6
add mac-address=02:44:AB:07:2F:BD name=PPPoE-Hospital2-Sector-6 remote-peer=\
    10.255.255.21 vpls-id=21:7
add mac-address=02:2E:4C:FB:6F:51 name=PPPoE-Hospital2-Sector-7 remote-peer=\
    10.255.255.21 vpls-id=21:8
add mac-address=02:72:7A:5B:92:94 name=PPPoE-Hospital2-Sector-8 remote-peer=\
    10.255.255.21 vpls-id=21:9
add mac-address=02:F8:4C:BA:65:65 name=PPPoE-Room5-Sector-1 remote-peer=\
    10.255.255.5 vpls-id=5:1
add mac-address=02:F8:4C:BA:65:65 name=PPPoE-Room5-Sector-2 remote-peer=\
    10.255.255.5 vpls-id=5:2
add mac-address=02:F8:4C:BA:65:65 name=PPPoE-Room5-Sector-3 remote-peer=\
    10.255.255.5 vpls-id=5:3
add mac-address=02:51:D5:07:7E:8C name=PPPoE-School-Sector-1 remote-peer=\
    10.255.255.3 vpls-id=3:1
add mac-address=02:AF:F0:06:2E:17 name=PPPoE-School-Sector-2 remote-peer=\
    10.255.255.3 vpls-id=3:2
add mac-address=02:F8:4C:BA:65:65 name=PPPoE-School-Sector-3 remote-peer=\
    10.255.255.3 vpls-id=3:3
add mac-address=02:F4:7B:04:54:67 name=PPPoE-School-Sector-4 remote-peer=\
    10.255.255.3 vpls-id=3:4
add disabled=no l2mtu=1500 mac-address=02:9D:B5:06:38:E9 name=\
    PPPoE-VPLS-Room9-Sector-1 remote-peer=10.255.255.2 vpls-id=2:1
add disabled=no l2mtu=1500 mac-address=02:9D:B5:06:38:E9 name=\
    PPPoE-VPLS-Room9-Sector-2 remote-peer=10.255.255.2 vpls-id=2:2
add mac-address=02:3B:66:FE:BE:DE name=PPPoE-site4-Sector-1 remote-peer=\
    10.255.255.8 vpls-id=8:1
add mac-address=02:3B:66:FE:BE:DE name=PPPoE-site4-Sector-2 remote-peer=\
    10.255.255.8 vpls-id=8:2
add mac-address=02:B5:9E:16:B8:4B name=School-Temp-Network remote-peer=\
    10.255.255.3 vpls-id=3:50
/interface vlan
add interface=ether2-ap1 name=site2-Management-VLAN10 vlan-id=10
add interface=ether8 name=Management-VLAN-Room-PTP-site4 vlan-id=10
add interface=ether12 loop-protect-disable-time=0s \
    loop-protect-send-interval=10s name=Management-VLAN-Switch vlan-id=10
add interface=ether5 name=Management-VLAN10-Ether5 vlan-id=10
add interface=ether4 name=Management-site3-2 vlan-id=10
add interface=ether12 name=Room-PTP-Room5 vlan-id=15
add interface=ether12 loop-protect-disable-time=0s \
    loop-protect-send-interval=10s name=Room-PTP-Room2 vlan-id=16
add comment="site3 and School" interface=ether12 loop-protect-disable-time=0s \
    loop-protect-send-interval=10s name=Room-PTP-Room9 vlan-id=14
add interface=ether12 name=Room-Sector-1 vlan-id=11
add interface=ether12 name=Room-Sector-2 vlan-id=12
add disabled=yes interface=ether10 name=Room-Sector-3 vlan-id=70
add disabled=yes interface=Management-VPLS-Link-Barcelona \
    loop-protect-disable-time=0s loop-protect-send-interval=0s name=vlan2 \
    vlan-id=10
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip firewall layer7-protocol
add comment=download name=high regexp="^.*get.+\\.(exe|rar|iso|zip|7zip|0[0-9]\
    [1-9]|flv|mkv|avi|mp4|3gp|rmvb|mp3|img|dat|mov).*\$"
add comment=download name=document regexp=\
    "^.*get.+\\.(pdf|doc|docx|xlsx|xls|rtf|ppt|ppt).*\$"
add comment=video name=youtube regexp="^.*get.+\\.(c.youtube.com|cdn.dailymoti\
    on.com|metacafe.com|mccont.com).*\$"
add comment=video name=streaming regexp=videoplayback|video
add comment=video name=youtube_matcher regexp=\
    "(GET \\/videoplayback\\\?|GET \\/crossdomain\\.xml)"
add name=.Bittorrent regexp="^(\\x13bittorrent protocol|azver\\x01\$|get /scra\
    pe\\\?info_hash=get /announce\\\?info_hash=|get /client/bitcomet/|GET /dat\
    a\\\?fid=)|d1:ad2:id20:|\\x08'7P\\)[RP]"
add comment="Block Bit Torrent" name=layer7-bittorrent-exp regexp="^(\\x13bitt\
    orrent protocol|azver\\x01\$|get /scrape\\\?info_hash=get /announce\\\?inf\
    o_hash=|get /client/bitcomet/|GET /data\\\?fid=)|d1:ad2:id20:|\\x08'7P\\)[\
    RP]"
add name=torrentsites regexp="^.*(get|GET).+(torrent|thepiratebay|isohunt|ente\
    rtane|demonoid|btjunkie|mininova|flixflux|torrentz|vertor|h33t|btscene|bit\
    unity|bittoxic|thunderbytes|entertane|zoozle|vcdq|bitnova|bitsoup|meganova\
    |fulldls|btbot|flixflux|seedpeer|fenopy|gpirate|commonbits).*\$"
add name=L7-Torrent regexp="^(\\x13bittorrent protocol|azver\\x01\$|get /scrap\
    e\\\?info_hash=get /announce\\\?info_hash=|get /client/bitcomet/|GET /data\
    \\\?fid=)|d1:ad2:id20:|\\x08'7P\\)[RP]"
add name=bittorrent regexp="^(\13bittorrent protocol|azver1\$|get /scrape\\\\\
    \?info_hash=)|d1:ad2:id20:|87P\\)[RP]"
add name=nntp regexp=\
    "^(20[01][\t-\r -~]*AUTHINFO USER|20[01][\t-\r -~]*news)"
add name=http-video regexp="http/(0.9|1.0|1.1)[x09-x0d ][1-5][0-9][0-9][x09-x0\
    d -~]*(content-type: video)"
add name=speedtest regexp="^.+(speedtest).*\\\$"
/ip pool
add name=pool1 ranges=192.168.10.1-192.168.10.254
add name=dhcp ranges=192.168.10.1-192.168.10.255
add name=pppoe-Client-Pool-1 ranges=10.254.0.1-10.254.3.253
add name=pool2 ranges=192.168.0.0/22
add name=dhcp_pool1 ranges=192.168.77.1-192.168.77.253
add name=dhcp_pool2 ranges=192.168.7.231-192.168.7.254
add name=PTP-IP-Pool ranges=10.200.0.2-10.200.0.254
add name=Management_Pool ranges=172.16.0.200-172.16.3.254
add name=PPPoE-Pool ranges=10.0.0.2-10.0.1.254
add name=RoomDHCPTest ranges=10.40.40.2-10.40.40.5
add name=VPNPool ranges=10.31.31.5-10.31.31.50
add name=dhcp_pool20 ranges=172.16.10.2-172.16.10.254
add name=temprad ranges=10.0.9.0/24
add name=dhcp_pool24 ranges=172.16.22.2-172.16.22.254
add name=dhcp_pool25 ranges=172.16.22.2-172.16.22.254
add name=dhcp_pool26 ranges=192.168.12.2-192.168.12.254
add name=dhcp_pool27 ranges=172.16.225.2-172.16.225.254
add name=dhcp_pool28 ranges=172.16.225.2-172.16.225.254
add name=dhcp_pool30 ranges=172.20.1.2-172.20.1.254
add name=dhcp_pool31 ranges=172.23.16.2-172.23.16.254
add name=dhcp_pool32 ranges=10.10.10.2-10.10.10.6
add name=dhcp_pool33 ranges=10.31.31.2-10.31.31.6
add name=wan ranges=197.100.8.4
add name=dhcp_pool35 ranges=172.16.50.2-172.16.50.254
add name=pool3 ranges=10.50.1.2-10.50.1.254
/ip dhcp-server
add address-pool=dhcp_pool1 authoritative=after-2sec-delay interface=ether12 \
    name=dhcp2
add address-pool=dhcp_pool2 authoritative=after-2sec-delay disabled=no \
    interface=bridge1 name=dhcp1
add address-pool=PTP-IP-Pool authoritative=after-2sec-delay interface=\
    PTP-Bridge name=dhcp3
add address-pool=Management_Pool authoritative=after-10sec-delay disabled=no \
    interface=Management-Bridge name=dhcp4
add address-pool=RoomDHCPTest interface=ether3 name=server1
add address-pool=Management_Pool authoritative=after-10sec-delay interface=\
    ether4 name=server2
add address-pool=dhcp_pool20 authoritative=after-10sec-delay interface=\
    Management-VPLS-Link-Hospital2 name=dhcp5
add address-pool=dhcp_pool25 disabled=no interface=bridge5 name=dhcp6
add address-pool=dhcp_pool26 disabled=no interface=site2 name=dhcp7
add address-pool=dhcp_pool28 name=dhcp8 relay=172.16.225.1
add address-pool=dhcp_pool30 interface=ether7 name=dhcp9
add address-pool=dhcp_pool31 interface=Management-VPLS-site32-Core name=\
    dhcp10
add address-pool=dhcp_pool33 disabled=no interface=ether10 name=dhcp11
add address-pool=dhcp_pool35 disabled=no interface=Cambium-Bridge name=dhcp12
/ppp profile
set *0 use-compression=no use-encryption=no use-mpls=yes use-upnp=yes
add change-tcp-mss=yes local-address=10.50.1.1 name=pppoe-Profile-2 \
    remote-address=pool3 use-mpls=yes use-upnp=yes
add change-tcp-mss=yes local-address=dhcp_pool1 name=pppoe-profile-4 \
    remote-address=dhcp_pool1 use-compression=yes use-mpls=yes use-upnp=yes
add change-tcp-mss=yes dns-server=8.8.8.8 local-address=pppoe-Client-Pool-1 \
    name=L2TP-Profile remote-address=pppoe-Client-Pool-1 use-compression=no \
    use-encryption=no use-mpls=yes use-upnp=yes
add change-tcp-mss=yes dns-server=8.8.8.8,8.8.4.4 local-address=10.0.0.1 \
    name=PPPoE-Profile
add local-address=10.0.93.1 name=profile1 remote-address=10.0.93.2
add local-address=10.31.31.1 name=VPN only-one=yes remote-address=VPNPool \
    use-encryption=required
add local-address=VPNPool name=vpn2 remote-address=VPNPool use-compression=no \
    use-encryption=yes
/queue simple
add name=server target=10.31.31.2/32
add dst=10.31.31.2/32 name=queue1 target=""
/queue type
set 0 kind=pcq pcq-burst-rate=20M pcq-classifier=dst-address pcq-limit=100KiB \
    pcq-rate=10M pcq-total-limit=1000000KiB
add kind=pcq name=PPPOE-Hard-Shape pcq-burst-time=30s pcq-classifier=\
    src-address pcq-dst-address6-mask=64 pcq-rate=100M pcq-src-address6-mask=\
    64 pcq-total-limit=50000KiB
add kind=pcq name=Pings-download pcq-classifier=dst-address \
    pcq-dst-address6-mask=64 pcq-rate=1M pcq-src-address6-mask=64
add kind=pcq name=Pings-Upload pcq-classifier=src-address \
    pcq-dst-address6-mask=64 pcq-rate=1M pcq-src-address6-mask=64
add kind=pcq name=Download_INTERNET pcq-classifier=dst-address pcq-rate=50M \
    pcq-total-limit=25000KiB
add kind=pcq name=Upload_INTERNET pcq-classifier=src-address pcq-rate=10M \
    pcq-total-limit=25000KiB
add kind=pcq name=Total pcq-classifier=src-address,dst-address \
    pcq-dst-address6-mask=64 pcq-limit=0KiB pcq-src-address6-mask=64 \
    pcq-total-limit=292969KiB
add kind=pcq name=test pcq-classifier=src-address pcq-dst-address6-mask=64 \
    pcq-limit=500KiB pcq-src-address6-mask=64 pcq-total-limit=80000KiB
set 12 pcq-burst-time=30s pcq-limit=200KiB pcq-total-limit=500000KiB
set 13 pcq-burst-time=30s pcq-limit=200KiB pcq-total-limit=1000000KiB
set 16 pfifo-limit=100
/ppp profile
add change-tcp-mss=yes dns-server=8.8.8.8,8.8.4.4 insert-queue-before=bottom \
    local-address=pppoe-Client-Pool-1 name=pppoe-Profile-1 queue-type=\
    PPPOE-Hard-Shape rate-limit="" remote-address=pppoe-Client-Pool-1 \
    use-compression=no use-encryption=no use-mpls=yes use-upnp=yes
/queue simple
add burst-limit=44M/88M burst-threshold=17600k/35200k burst-time=1m/1m \
    comment="Tariff Main-2MB-Uncapped" limit-at=11M/22M max-limit=22M/44M \
    name=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target="10.2.0.4/32,10.2.1.95/32,1\
    0.2.0.23/32,10.2.0.39/32,10.2.1.190/32,10.2.1.194/32,10.2.1.197/32,10.2.1.\
    243/32,10.2.2.25/32,10.2.0.118/32,10.2.0.119/32,10.2.2.42/32,10.2.1.129/32\
    ,10.2.0.152/32,10.2.0.157/32,10.2.1.145/32,10.2.0.182/32,10.2.1.222/32,10.\
    2.0.200/32,10.2.0.206/32,10.2.0.211/32,10.2.0.216/32,10.2.0.219/32,10.2.0.\
    222/32,10.2.0.230/32,10.2.0.231/32,10.2.1.110/32,10.2.0.238/32,10.2.0.245/\
    32,10.2.0.248/32,10.2.0.251/32,10.2.1.2/32,10.2.1.48/32,10.2.1.163/32,10.2\
    .1.12/32,10.2.1.13/32,10.2.1.227/32,10.2.1.157/32,10.2.1.91/32,10.2.1.167/\
    32,10.2.1.173/32,10.2.1.143/32,10.3.0.225/32,10.4.1.86/32"
add burst-limit=13M/39M burst-threshold=5200k/15600k burst-time=1m/1m \
    comment="Tariff Main-3MB-Uncapped" limit-at=3250k/9750k max-limit=\
    6500k/19500k name=SpLSTG_0-2 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target="10.3.0.2/32,10.3.0.182/32,\
    10.3.0.202/32,10.3.0.205/32,10.3.0.41/32,10.3.0.46/32,10.3.0.61/32,10.3.0.\
    65/32,10.3.0.84/32,10.3.0.188/32,10.2.1.14/32,10.2.1.189/32,10.16.0.4/32"
add burst-limit=45M/120M burst-threshold=18M/48M burst-time=1m/1m comment=\
    "Tariff Main-4MB-Uncapped" limit-at=11250k/30M max-limit=22500k/60M name=\
    SpLSTG_0-3 priority=5/5 queue=pcq-upload-default/pcq-download-default \
    target="10.4.1.87/32,10.4.1.73/32,10.4.1.72/32,10.4.1.164/32,10.4.1.197/32\
    ,10.4.2.0/32,10.4.1.123/32,10.4.0.100/32,10.4.2.1/32,10.4.1.130/32,10.4.1.\
    132/32,10.4.0.154/32,10.4.0.157/32,10.4.1.209/32,10.4.0.165/32,10.4.0.166/\
    32,10.4.1.211/32,10.4.0.243/32,10.4.1.10/32,10.4.1.29/32,10.4.1.106/32,10.\
    4.1.156/32,10.4.1.157/32,10.4.1.115/32,10.4.1.124/32,10.4.1.158/32,10.2.1.\
    193/32,10.5.0.67/32,10.2.0.204/32,10.4.0.6/32"
add burst-limit=7500k/25M burst-threshold=3M/10M burst-time=1m/1m comment=\
    "Tariff Main-5MB-Uncapped" limit-at=2812500/9375k max-limit=3750k/12500k \
    name=SpLSTG_0-4 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=\
    10.5.0.24/32,10.5.0.78/32,10.5.0.83/32,10.2.0.215/32,10.16.0.12/32
add burst-limit=7500k/30M burst-threshold=3M/12M burst-time=1m/1m comment=\
    "Tariff Main-6MB-Uncapped" limit-at=2812500/11250k max-limit=3750k/15M \
    name=SpLSTG_0-5 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=\
    10.6.0.60/32,10.6.0.42/32,10.6.0.7/32,10.6.0.69/32,10.6.0.16/32
add burst-limit=4M/16M burst-threshold=1600k/6400k burst-time=1m/1m comment=\
    "Tariff Main-8MB-Uncapped" limit-at=1500k/6M max-limit=2M/8M name=\
    SpLSTG_0-7 priority=5/5 queue=pcq-upload-default/pcq-download-default \
    target=10.8.0.12/32
add burst-limit=12500k/50M burst-threshold=5M/20M burst-time=1m/1m comment=\
    "Tariff Main-10MB-Uncapped" limit-at=4687500/18750k max-limit=6250k/25M \
    name=SpLSTG_0-9 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=\
    10.10.0.21/32,10.10.0.15/32,10.10.0.54/32,10.16.0.3/32,10.4.1.181/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1001afzal@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_4-6 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.87/32
add burst-limit=3M/12M burst-threshold=1200k/4800k burst-time=1m/1m comment=\
    1003candice@ITECH limit-at=562500/2250k max-limit=1500k/6M name=SpLSTQ_5-7 \
    parent=SpLSTG_0-5 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.6.0.60/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1009zaiyaan@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_8-10 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.73/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1014mubin@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_10-12 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.4/32
add burst-limit=2M/6M burst-threshold=800k/2400k burst-time=1m/1m comment=\
    1052yakub@ITECH limit-at=250k/750k max-limit=1M/3M name=SpLSTQ_14-16 \
    parent=SpLSTG_0-2 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.3.0.2/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1054roopesh@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_16-18 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.72/32
add burst-limit=2M/6M burst-threshold=800k/2400k burst-time=1m/1m comment=\
    1060shanaaz@ITECH limit-at=250k/750k max-limit=1M/3M name=SpLSTQ_22-24 \
    parent=SpLSTG_0-2 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.3.0.182/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1071melissa@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_31-33 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.95/32
add burst-limit=5M/20M burst-threshold=2M/8M burst-time=1m/1m comment=\
    1074dhiroshan@ITECH limit-at=937500/3750k max-limit=2500k/10M name=\
    SpLSTQ_33-35 parent=SpLSTG_0-9 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.10.0.21/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1098branton@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_55-57 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.23/32
add burst-limit=3M/12M burst-threshold=1200k/4800k burst-time=1m/1m comment=\
    1106sunjay@ITECH limit-at=562500/2250k max-limit=1500k/6M name=\
    SpLSTQ_60-62 parent=SpLSTG_0-5 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.6.0.42/32
add burst-limit=5M/20M burst-threshold=2M/8M burst-time=1m/1m comment=\
    1128vinash@ITECH limit-at=937500/3750k max-limit=2500k/10M name=\
    SpLSTQ_78-80 parent=SpLSTG_0-9 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.10.0.15/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1137fazel@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_85-87 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.39/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1164ahmed@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_106-108 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.190/32
add burst-limit=2M/6M burst-threshold=800k/2400k burst-time=1m/1m comment=\
    1167javed@ITECH limit-at=250k/750k max-limit=1M/3M name=SpLSTQ_109-111 \
    parent=SpLSTG_0-2 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.3.0.202/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1171k.coopod@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_112-114 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.194/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1174haseena@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_114-116 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.164/32
add burst-limit=2M/6M burst-threshold=800k/2400k burst-time=1m/1m comment=\
    1178ramesh@ITECH limit-at=250k/750k max-limit=1M/3M name=SpLSTQ_117-119 \
    parent=SpLSTG_0-2 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.3.0.205/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1180zubir@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_119-121 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.197/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1208deshan@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_140-142 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.197/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1224shabbir@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_152-154 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.243/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1303fatima@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_218-220 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.2.25/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1338s.desai@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_246-248 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.118/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1343ameera@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_251-253 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.119/32
add burst-limit=2M/6M burst-threshold=800k/2400k burst-time=1m/1m comment=\
    1363luke@ITECH limit-at=250k/750k max-limit=1M/3M name=SpLSTQ_269-271 \
    parent=SpLSTG_0-2 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.3.0.41/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1381mike@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_284-286 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.2.42/32
add burst-limit=2M/6M burst-threshold=800k/2400k burst-time=1m/1m comment=\
    1396muhammad@ITECH limit-at=250k/750k max-limit=1M/3M name=SpLSTQ_297-299 \
    parent=SpLSTG_0-2 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.3.0.46/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1398rahmman@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_299-301 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.2.0/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1402pieter@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_303-305 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.123/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1406zahier@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_307-309 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.129/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1420qamaal@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_321-323 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.157/32
add burst-limit=3M/10M burst-threshold=1200k/4M burst-time=1m/1m comment=\
    1427dinon@ITECH limit-at=562500/1875k max-limit=1500k/5M name=\
    SpLSTQ_325-327 parent=SpLSTG_0-4 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.5.0.24/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1432deshan@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_330-332 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.0.100/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1437aisha@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_334-336 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.145/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1467yonas@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_361-363 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.182/32
add burst-limit=3M/12M burst-threshold=1200k/4800k burst-time=1m/1m comment=\
    1477ashley@ITECH limit-at=562500/2250k max-limit=1500k/6M name=\
    SpLSTQ_370-372 parent=SpLSTG_0-5 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.6.0.7/32
add burst-limit=3M/12M burst-threshold=1200k/4800k burst-time=1m/1m comment=\
    1502zaynap@ITECH limit-at=562500/2250k max-limit=1500k/6M name=\
    SpLSTQ_392-394 parent=SpLSTG_0-5 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.6.0.69/32
add burst-limit=3M/10M burst-threshold=1200k/4M burst-time=1m/1m comment=\
    1509rhusdi@ITECH limit-at=562500/1875k max-limit=1500k/5M name=\
    SpLSTQ_398-400 parent=SpLSTG_0-4 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.5.0.78/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1522ismail@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_410-412 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.2.1/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1524adnnan@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_412-414 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.222/32
add burst-limit=2M/6M burst-threshold=800k/2400k burst-time=1m/1m comment=\
    29nithia@ITECH limit-at=250k/750k max-limit=1M/3M name=SpLSTQ_427-429 \
    parent=SpLSTG_0-2 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.3.0.61/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    34hajira@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_430-432 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.200/32
add burst-limit=2M/6M burst-threshold=800k/2400k burst-time=1m/1m comment=\
    42lenny@ITECH limit-at=250k/750k max-limit=1M/3M name=SpLSTQ_439-441 \
    parent=SpLSTG_0-2 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.3.0.65/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    43araf@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_440-442 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.206/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    adnaan2@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_448-450 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.211/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    ameer@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_454-456 parent=\
    SpLSTG_0-1 priority=5/5 queue=pcq-upload-default/pcq-download-default \
    target=10.2.0.216/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    faraz@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_471-473 parent=\
    SpLSTG_0-1 priority=5/5 queue=pcq-upload-default/pcq-download-default \
    target=10.2.0.222/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    howie@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_484-486 parent=\
    SpLSTG_0-1 priority=5/5 queue=pcq-upload-default/pcq-download-default \
    target=10.2.0.230/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    ilyaas@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_485-487 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.231/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    ina.ethe.trading@ITECH limit-at=375k/1M max-limit=1500k/4M name=\
    SpLSTQ_488-490 parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.130/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    izat@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_491-493 parent=\
    SpLSTG_0-3 priority=5/5 queue=pcq-upload-default/pcq-download-default \
    target=10.4.1.132/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    kamaa@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_494-496 parent=\
    SpLSTG_0-1 priority=5/5 queue=pcq-upload-default/pcq-download-default \
    target=10.2.1.110/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1720kumar@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_496-498 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.238/32
add burst-limit=3M/12M burst-threshold=1200k/4800k burst-time=1m/1m comment=\
    mamo@ITECH limit-at=562500/2250k max-limit=1500k/6M name=SpLSTQ_501-503 \
    parent=SpLSTG_0-5 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.6.0.16/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    mlshafiek@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_506-508 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.245/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    moosalaher@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_508-510 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.0.154/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    nazir@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_513-515 parent=\
    SpLSTG_0-1 priority=5/5 queue=pcq-upload-default/pcq-download-default \
    target=10.2.0.248/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    rafiq-site4@ITECH limit-at=375k/1M max-limit=1500k/4M name=\
    SpLSTQ_515-517 parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.0.157/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    raza@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_518-520 parent=\
    SpLSTG_0-1 priority=5/5 queue=pcq-upload-default/pcq-download-default \
    target=10.2.0.251/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    shamil@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_527-529 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.2/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    snacktime@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_531-533 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.48/32
add burst-limit=2M/6M burst-threshold=800k/2400k burst-time=1m/1m comment=\
    soraya@ITECH limit-at=250k/750k max-limit=1M/3M name=SpLSTQ_532-534 \
    parent=SpLSTG_0-2 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.3.0.84/32
add burst-limit=5M/20M burst-threshold=2M/8M burst-time=1m/1m comment=test \
    limit-at=937500/3750k max-limit=2500k/10M name=SpLSTQ_536-538 parent=\
    SpLSTG_0-9 priority=5/5 queue=pcq-upload-default/pcq-download-default \
    target=10.10.0.54/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    thareef@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_538-540 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.163/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    waseem2@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_543-545 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.209/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    yazeed@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_545-547 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.12/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    site3@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_547-549 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.0.165/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    site3j@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_548-550 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.13/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    zakaria@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_549-551 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.0.166/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1545camille@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_554-556 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.211/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1540dennis@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_557-559 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.227/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    44nasir@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_574-576 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.157/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1566vikash@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_581-583 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.0.243/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1573deva@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_590-592 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.10/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1583gerard@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_591-593 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.29/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    0000rafiq@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_610-612 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.91/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1609nasir@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_617-619 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.167/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1951sauketallie@ITECH limit-at=375k/1M max-limit=1500k/4M name=\
    SpLSTQ_635-637 parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.106/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1630tarek@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_643-645 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.173/32
add burst-limit=2M/6M burst-threshold=800k/2400k burst-time=1m/1m comment=\
    1631nafeesa@ITECH limit-at=250k/750k max-limit=1M/3M name=SpLSTQ_644-646 \
    parent=SpLSTG_0-2 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.3.0.188/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1953hamaada@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_648-650 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.143/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1643skapery@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_658-660 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.156/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1644anrico@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_659-661 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.157/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1701nazir@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_664-666 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.115/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1705ivanah@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_671-673 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.124/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1652clarence@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_672-674 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.158/32
add burst-limit=3M/10M burst-threshold=1200k/4M burst-time=1m/1m comment=\
    1657shafiek@ITECH limit-at=562500/1875k max-limit=1500k/5M name=\
    SpLSTQ_680-682 parent=SpLSTG_0-4 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.5.0.83/32
add burst-limit=5M/20M burst-threshold=2M/8M burst-time=1m/1m comment=\
    1711fareed@ITECH limit-at=937500/3750k max-limit=2500k/10M name=\
    SpLSTQ_698-708 parent=SpLSTG_0-9 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.16.0.3/32
add burst-limit=3M/10M burst-threshold=1200k/4M burst-time=1m/1m comment=\
    alister@ITECH limit-at=562500/1875k max-limit=1500k/5M name=SpLSTQ_452-710 \
    parent=SpLSTG_0-4 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.215/32
add burst-limit=3M/10M burst-threshold=1200k/4M burst-time=1m/1m comment=\
    farouktower@ITECH limit-at=562500/1875k max-limit=1500k/5M name=\
    SpLSTQ_709-743 parent=SpLSTG_0-4 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.16.0.12/32
add burst-limit=4M/16M burst-threshold=1600k/6400k burst-time=1m/1m comment=\
    1088heshaam@ITECH limit-at=1500k/6M max-limit=2M/8M name=SpLSTQ_46-48 \
    parent=SpLSTG_0-7 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.8.0.12/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    1414shakeel@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_315-317 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.152/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    daruloom@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_464-466 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.219/32
add burst-limit=1M/2M burst-threshold=400k/800k burst-time=1m/1m comment=\
    "Tariff Main-1MB-Uncapped" limit-at=250k/500k max-limit=500k/1M name=\
    SpLSTG_0-10 priority=5/5 queue=pcq-upload-default/pcq-download-default \
    target=10.16.0.14/32
add burst-limit=1M/2M burst-threshold=400k/800k burst-time=1m/1m comment=\
    001haroon@ITECH limit-at=250k/500k max-limit=500k/1M name=SpLSTQ_3-733 \
    parent=SpLSTG_0-10 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.16.0.14/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1169luqmaan@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_111-760 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.193/32
add burst-limit=2M/6M burst-threshold=800k/2400k burst-time=1m/1m comment=\
    zubir@ITECH limit-at=250k/750k max-limit=1M/3M name=SpLSTQ_551-754 parent=\
    SpLSTG_0-2 priority=5/5 queue=pcq-upload-default/pcq-download-default \
    target=10.2.1.14/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    1422nadia@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_681-788 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.5.0.67/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    hassanshop@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_481-791 \
    parent=SpLSTG_0-1 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.3.0.225/32
add burst-limit=2M/4M burst-threshold=800k/1600k burst-time=1m/1m comment=\
    3star@ITECH limit-at=250k/500k max-limit=1M/2M name=SpLSTQ_436-801 parent=\
    SpLSTG_0-1 priority=5/5 queue=pcq-upload-default/pcq-download-default \
    target=10.4.1.86/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    40tarek@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_437-816 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.0.204/32
add burst-limit=2M/6M burst-threshold=800k/2400k burst-time=1m/1m comment=\
    1162ismail@ITECH limit-at=250k/750k max-limit=1M/3M name=SpLSTQ_104-828 \
    parent=SpLSTG_0-2 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.2.1.189/32
add burst-limit=2M/6M burst-threshold=800k/2400k burst-time=1m/1m comment=\
    1712ismail@ITECH limit-at=250k/750k max-limit=1M/3M name=SpLSTQ_699-832 \
    parent=SpLSTG_0-2 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.16.0.4/32
add burst-limit=3M/8M burst-threshold=1200k/3200k burst-time=1m/1m comment=\
    victory@ITECH limit-at=375k/1M max-limit=1500k/4M name=SpLSTQ_660-833 \
    parent=SpLSTG_0-3 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.0.6/32
add burst-limit=5M/20M burst-threshold=2M/8M burst-time=1m/1m comment=\
    1520asim@ITECH limit-at=937500/3750k max-limit=2500k/10M name=\
    SpLSTQ_408-838 parent=SpLSTG_0-9 priority=5/5 queue=\
    pcq-upload-default/pcq-download-default target=10.4.1.181/32
/queue tree
add disabled=yes limit-at=470M max-limit=490M name=1-Main-Download \
    packet-mark=Global-Download parent=global queue=pcq-download-default
add disabled=yes name=1-Main-Upload packet-mark=Global-Upload parent=global \
    queue=default
add disabled=yes name=1-WEB-Browsing-Download packet-mark=\
    WEB-Browsing-Download parent=1-Main-Download priority=3 queue=\
    pcq-download-default
add disabled=yes name=1-WEB-Browsing-Upload packet-mark=WEB-Browsing-Upload \
    parent=1-Main-Upload priority=2 queue=pcq-upload-default
add disabled=yes name=7-Undefined-Download packet-mark=Undefined-Download \
    parent=1-Main-Download priority=7 queue=pcq-download-default
add disabled=yes name=7-Undefined-Upload packet-mark=Undefined-Upload parent=\
    1-Main-Upload priority=7 queue=pcq-upload-default
add disabled=yes name=1-Speedtest-Download packet-mark=Speedtest-Download \
    parent=global priority=1 queue=pcq-download-default
add disabled=yes name=1-Speedtest-Upload packet-mark=Speedtest-Upload parent=\
    global priority=1 queue=pcq-upload-default
add disabled=yes name=2-Admin-Download packet-mark=Admin-Download parent=\
    1-Main-Download priority=2 queue=pcq-download-default
add disabled=yes name=2-Admin-Upload packet-mark=Admin-Upload parent=\
    1-Main-Upload priority=2 queue=pcq-upload-default
add disabled=yes name=5-Youtube-Download packet-mark=Youtube-Download parent=\
    global priority=1 queue=pcq-download-default
add disabled=yes name=5-Youtube-Upload packet-mark=Youtube-Upload parent=\
    1-Main-Upload priority=5 queue=pcq-upload-default
add disabled=yes name=1-MikroTik-Download packet-mark=MikroTik-Download \
    parent=1-Main-Download priority=1 queue=PPPOE-Hard-Shape
add disabled=yes name=1-MikroTik-Upload packet-mark=MikroTik-Upload parent=\
    1-Main-Upload priority=1 queue=pcq-upload-default
add disabled=yes name=8-Torrent-Download packet-mark=Torrent-Download parent=\
    1-Main-Download queue=pcq-download-default
add disabled=yes name=8-Torrent-Upload packet-mark=Torrent-Upload parent=\
    1-Main-Upload queue=pcq-upload-default
add disabled=yes name=1-SNMP-Download packet-mark=SNMP-Download parent=\
    1-Main-Download priority=1 queue=pcq-download-default
add disabled=yes name="1-SNMP Upload" packet-mark=SNMP-Upload parent=\
    1-Main-Upload priority=1 queue=pcq-upload-default
add disabled=yes name="3-Mail Server Download" packet-mark=Mail-Download \
    parent=global priority=1 queue=pcq-download-default
add disabled=yes name="3-Mail Server Upload" packet-mark=Mail-Upload parent=\
    global priority=1 queue=pcq-upload-default
add disabled=yes name=3-Game-Download packet-mark=Games-Download-Download \
    parent=global priority=1 queue=pcq-download-default
add disabled=yes name=3-Game-Upload packet-mark=Games-Upload parent=global \
    priority=1 queue=pcq-upload-default
add disabled=yes name="6-Documents Download" packet-mark=Document-Download \
    parent=1-Main-Download priority=1 queue=pcq-download-default
add disabled=yes name="5-Files Download" packet-mark=File-Download parent=\
    1-Main-Download priority=5 queue=pcq-download-default
add disabled=yes name="6-Files Upload" packet-mark=File-Upload parent=\
    1-Main-Upload priority=6 queue=pcq-upload-default
add disabled=yes name="6-Document Upload" packet-mark=Document-Upload parent=\
    1-Main-Upload priority=6 queue=pcq-upload-default
add disabled=yes name="7-Apple Update Downloads" packet-mark=\
    "Apple Update Downloads" parent=1-Main-Download priority=7 queue=default
add disabled=yes name="7-Apple Updates Uploads" packet-mark=\
    "Apple Update Upload" parent=1-Main-Upload priority=7 queue=\
    pcq-upload-default
add disabled=yes name="3-NTP Time Download" packet-mark="NTP Time Download" \
    parent=1-Main-Download priority=3 queue=pcq-download-default
add disabled=yes name="3-NTP Time Upload" packet-mark="NTP Time Upload" \
    parent=1-Main-Upload priority=3 queue=pcq-upload-default
add disabled=yes name="1-VOIP SIP Download" packet-mark="VOIP SIP Download" \
    parent=global priority=1 queue=pcq-download-default
add disabled=yes name="1-VOIP Sip Upload" packet-mark="VOIP SIP Upload" \
    parent=1-Main-Upload priority=1 queue=pcq-upload-default
add disabled=yes name="1-ICMP Download" packet-mark="ICMP Download" parent=\
    1-Main-Download priority=1 queue=pcq-download-default
add disabled=yes name="1-ICMP Upload" packet-mark="ICMP Upload" parent=\
    1-Main-Upload priority=1 queue=pcq-upload-default
add disabled=yes name="1-DNS Download" packet-mark="DNS Download" parent=\
    1-Main-Download queue=pcq-download-default
add disabled=yes name="8-NNTP Download" packet-mark="NNTP Download" parent=\
    1-Main-Download queue=pcq-download-default
add disabled=yes name="8-NNTP Upload" packet-mark="NNTP Upload" parent=\
    1-Main-Upload queue=pcq-upload-default
add disabled=yes name="7-Windows Updates Download" packet-mark=\
    "Windows Update Downloads" parent=1-Main-Download priority=7 queue=\
    default
add disabled=yes name="7-Windows Updates Upload" packet-mark=\
    "Windows Update Upload" parent=1-Main-Upload priority=7 queue=\
    pcq-upload-default
add disabled=yes name=1-Radius-Download packet-mark=Radius-Download parent=\
    1-Main-Download priority=1 queue=pcq-upload-default
add disabled=yes name=1-Radius-Upload packet-mark=Radius-Upload parent=\
    1-Main-Upload priority=1 queue=pcq-upload-default
add disabled=yes name=2-WhatsApp packet-mark=Whatsapp-Download parent=\
    1-Main-Download priority=2 queue=pcq-download-default
add disabled=yes name=1-Stream-Download packet-mark=Stream-Download parent=\
    global priority=1 queue=pcq-download-default
add disabled=yes name=1-Facebook-Download packet-mark=Facebook-Download \
    parent=1-Main-Download priority=1 queue=pcq-download-default
add disabled=yes name=1-Facebook-Upload packet-mark=Facebook-Upload parent=\
    1-Main-Upload priority=1 queue=pcq-upload-default
add disabled=yes name=1-Stream-Upload packet-mark=Stream-Upload parent=global \
    priority=1 queue=pcq-upload-default
add disabled=yes name=2-WhatsApp-Upload packet-mark=Whatsapp-Upload parent=\
    global priority=1 queue=pcq-upload-default
add disabled=yes name="1-DNS Upload" packet-mark="DNS Download" parent=\
    1-Main-Upload priority=1 queue=pcq-download-default
add disabled=yes limit-at=470M max-limit=490M name=1-Main-Pipe parent=global \
    queue=Total
add disabled=yes name=facebookunshaped packet-mark=Facebook-Download parent=\
    global priority=1 queue=pcq-download-default
add disabled=yes name=whatsppunshaped packet-mark=Whatsapp-Download parent=\
    global priority=1 queue=pcq-download-default
add disabled=yes name=faceupunshaped packet-mark=Facebook-Upload parent=\
    global priority=1 queue=pcq-upload-default
add disabled=yes name=whatsunsha packet-mark=Whatsapp-Upload parent=global \
    priority=1 queue=pcq-upload-default
add disabled=yes name=NetflixOutofQueue packet-mark=Netflix parent=global \
    priority=1 queue=pcq-download-default
add disabled=yes max-limit=500M name=INTERNET parent=INTERNET queue=default
add disabled=yes name=routine_0_INTERNET packet-mark=dscp_0_eth parent=\
    INTERNET queue=ethernet-default
add disabled=yes name=routine_1_INTERNET packet-mark=dscp_1_eth parent=\
    INTERNET queue=ethernet-default
add disabled=yes name=routine_2_INTERNET packet-mark=dscp_2_eth parent=\
    INTERNET queue=ethernet-default
add disabled=yes name=routine_3_INTERNET packet-mark=dscp_3_eth parent=\
    INTERNET queue=ethernet-default
add disabled=yes name=routine_4_INTERNET packet-mark=dscp_4_eth parent=\
    INTERNET queue=ethernet-default
add disabled=yes name=routine_5_INTERNET packet-mark=dscp_5_eth parent=\
    INTERNET queue=ethernet-default
add disabled=yes name=routine_6_INTERNET packet-mark=dscp_6_eth parent=\
    INTERNET queue=ethernet-default
add disabled=yes name=routine_7_INTERNET packet-mark=dscp_7_eth parent=\
    INTERNET queue=ethernet-default
add disabled=yes name=priority_8_INTERNET packet-mark=dscp_8_eth parent=\
    INTERNET priority=7 queue=ethernet-default
add disabled=yes name=priority_9_INTERNET packet-mark=dscp_9_eth parent=\
    INTERNET priority=7 queue=ethernet-default
add disabled=yes name=priority_10_INTERNET packet-mark=dscp_10_eth parent=\
    INTERNET priority=7 queue=ethernet-default
add disabled=yes name=priority_11_INTERNET packet-mark=dscp_11_eth parent=\
    INTERNET priority=7 queue=ethernet-default
add disabled=yes name=priority_12_INTERNET packet-mark=dscp_12_eth parent=\
    INTERNET priority=7 queue=ethernet-default
add disabled=yes name=priority_13_INTERNET packet-mark=dscp_13_eth parent=\
    INTERNET priority=7 queue=ethernet-default
add disabled=yes name=priority_14_INTERNET packet-mark=dscp_14_eth parent=\
    INTERNET priority=7 queue=ethernet-default
add disabled=yes name=priority_15_INTERNET packet-mark=dscp_15_eth parent=\
    INTERNET priority=7 queue=ethernet-default
add disabled=yes name=immediate_16_INTERNET packet-mark=dscp_16_eth parent=\
    INTERNET priority=6 queue=ethernet-default
add disabled=yes name=immediate_17_INTERNET packet-mark=dscp_17_eth parent=\
    INTERNET priority=6 queue=ethernet-default
add disabled=yes name=immediate_18_INTERNET packet-mark=dscp_18_eth parent=\
    INTERNET priority=6 queue=ethernet-default
add disabled=yes name=immediate_19_INTERNET packet-mark=dscp_19_eth parent=\
    INTERNET priority=6 queue=ethernet-default
add disabled=yes name=immediate_20_INTERNET packet-mark=dscp_20_eth parent=\
    INTERNET priority=6 queue=ethernet-default
add disabled=yes name=immediate_21_INTERNET packet-mark=dscp_21_eth parent=\
    INTERNET priority=6 queue=ethernet-default
add disabled=yes name=immediate_22_INTERNET packet-mark=dscp_22_eth parent=\
    INTERNET priority=6 queue=ethernet-default
add disabled=yes name=immediate_23_INTERNET packet-mark=dscp_23_eth parent=\
    INTERNET priority=6 queue=ethernet-default
add disabled=yes name=flash_24_INTERNET packet-mark=dscp_24_eth parent=\
    INTERNET priority=5 queue=ethernet-default
add disabled=yes name=flash_25_INTERNET packet-mark=dscp_25_eth parent=\
    INTERNET priority=5 queue=ethernet-default
add disabled=yes name=flash_26_INTERNET packet-mark=dscp_26_eth parent=\
    INTERNET priority=5 queue=ethernet-default
add disabled=yes name=flash_27_INTERNET packet-mark=dscp_27_eth parent=\
    INTERNET priority=5 queue=ethernet-default
add disabled=yes name=flash_28_INTERNET packet-mark=dscp_28_eth parent=\
    INTERNET priority=5 queue=ethernet-default
add disabled=yes name=flash_29_INTERNET packet-mark=dscp_29_eth parent=\
    INTERNET priority=5 queue=ethernet-default
add disabled=yes name=flash_30_INTERNET packet-mark=dscp_30_eth parent=\
    INTERNET priority=5 queue=ethernet-default
add disabled=yes name=flash_31_INTERNET packet-mark=dscp_31_eth parent=\
    INTERNET priority=5 queue=ethernet-default
add disabled=yes name=flash_override_32_INTERNET packet-mark=dscp_32_eth \
    parent=INTERNET priority=4 queue=ethernet-default
add disabled=yes name=flash_override_33_INTERNET packet-mark=dscp_33_eth \
    parent=INTERNET priority=4 queue=ethernet-default
add disabled=yes name=flash_override_34_INTERNET packet-mark=dscp_34_eth \
    parent=INTERNET priority=4 queue=ethernet-default
add disabled=yes name=flash_override_35_INTERNET packet-mark=dscp_35_eth \
    parent=INTERNET priority=4 queue=ethernet-default
add disabled=yes name=flash_override_36_INTERNET packet-mark=dscp_36_eth \
    parent=INTERNET priority=4 queue=ethernet-default
add disabled=yes name=flash_override_37_INTERNET packet-mark=dscp_37_eth \
    parent=INTERNET priority=4 queue=ethernet-default
add disabled=yes name=flash_override_38_INTERNET packet-mark=dscp_38_eth \
    parent=INTERNET priority=4 queue=ethernet-default
add disabled=yes name=flash_override_39_INTERNET packet-mark=dscp_39_eth \
    parent=INTERNET priority=4 queue=ethernet-default
add disabled=yes name=critical_40_INTERNET packet-mark=dscp_40_eth parent=\
    INTERNET priority=3 queue=ethernet-default
add disabled=yes name=critical_41_INTERNET packet-mark=dscp_41_eth parent=\
    INTERNET priority=3 queue=ethernet-default
add disabled=yes name=critical_42_INTERNET packet-mark=dscp_42_eth parent=\
    INTERNET priority=3 queue=ethernet-default
add disabled=yes name=critical_43_INTERNET packet-mark=dscp_43_eth parent=\
    INTERNET priority=3 queue=ethernet-default
add disabled=yes name=critical_44_INTERNET packet-mark=dscp_44_eth parent=\
    INTERNET priority=3 queue=ethernet-default
add disabled=yes name=critical_45_INTERNET packet-mark=dscp_45_eth parent=\
    INTERNET priority=3 queue=ethernet-default
add disabled=yes name=critical_46_INTERNET packet-mark=dscp_46_eth parent=\
    INTERNET priority=3 queue=ethernet-default
add disabled=yes name=critical_47_INTERNET packet-mark=dscp_47_eth parent=\
    INTERNET priority=3 queue=ethernet-default
add disabled=yes name=intercon_48_INTERNET packet-mark=dscp_48_eth parent=\
    INTERNET priority=2 queue=ethernet-default
add disabled=yes name=intercon_49_INTERNET packet-mark=dscp_49_eth parent=\
    INTERNET priority=2 queue=ethernet-default
add disabled=yes name=intercon_50_INTERNET packet-mark=dscp_50_eth parent=\
    INTERNET priority=2 queue=ethernet-default
add disabled=yes name=intercon_51_INTERNET packet-mark=dscp_51_eth parent=\
    INTERNET priority=2 queue=ethernet-default
add disabled=yes name=intercon_52_INTERNET packet-mark=dscp_52_eth parent=\
    INTERNET priority=2 queue=ethernet-default
add disabled=yes name=intercon_53_INTERNET packet-mark=dscp_53_eth parent=\
    INTERNET priority=2 queue=ethernet-default
add disabled=yes name=intercon_54_INTERNET packet-mark=dscp_54_eth parent=\
    INTERNET priority=2 queue=ethernet-default
add disabled=yes name=intercon_55_INTERNET packet-mark=dscp_55_eth parent=\
    INTERNET priority=2 queue=ethernet-default
add disabled=yes name=netcon_56_INTERNET packet-mark=dscp_56_eth parent=\
    INTERNET priority=1 queue=ethernet-default
add disabled=yes name=netcon_57_INTERNET packet-mark=dscp_57_eth parent=\
    INTERNET priority=1 queue=ethernet-default
add disabled=yes name=netcon_58_INTERNET packet-mark=dscp_58_eth parent=\
    INTERNET priority=1 queue=ethernet-default
add disabled=yes name=netcon_59_INTERNET packet-mark=dscp_59_eth parent=\
    INTERNET priority=1 queue=ethernet-default
add disabled=yes name=netcon_60_INTERNET packet-mark=dscp_60_eth parent=\
    INTERNET priority=1 queue=ethernet-default
add disabled=yes name=netcon_61_INTERNET packet-mark=dscp_61_eth parent=\
    INTERNET priority=1 queue=ethernet-default
add disabled=yes name=netcon_62_INTERNET packet-mark=dscp_62_eth parent=\
    INTERNET priority=1 queue=ethernet-default
add disabled=yes name=netcon_63_INTERNET packet-mark=dscp_63_eth parent=\
    INTERNET priority=1 queue=ethernet-default
/routing ospf area
add area-id=10.0.0.0 name=external
/routing ospf instance
set [ find default=yes ] distribute-default=always-as-type-1 mpls-te-area=\
    backbone mpls-te-router-id=LoopBack router-id=10.255.255.1
/snmp community
set [ find default=yes ] addresses=129.232.202.243/32,129.232.202.250/32 \
    name=Fire-IT
add addresses=::/0 name=ITECH
/system logging action
set 0 memory-lines=200
set 1 disk-file-count=20 disk-stop-on-full=yes
add disk-file-count=10 disk-file-name=logins disk-lines-per-file=5000 name=\
    loginlog target=disk
/user group
set read policy="local,telnet,ssh,reboot,read,test,winbox,web,sniff,api,romon,\
    tikapp,!ftp,!write,!policy,!password,!sensitive,!dude"
add name=test policy="local,test,winbox,web,!telnet,!ssh,!ftp,!reboot,!read,!w\
    rite,!policy,!password,!sniff,!sensitive,!api,!romon,!dude,!tikapp"
add name=Radius policy="reboot,read,write,policy,sensitive,api,!local,!telnet,\
    !ssh,!ftp,!test,!winbox,!password,!web,!sniff,!romon,!dude,!tikapp"
/interface bridge port
add bridge=Management-Bridge interface=Management-VPLS-Link-Barcelona
add bridge=Management-Bridge interface=Management-VPLS-Link-School
add bridge=Management-Bridge interface=Management-VPLS-Link-Room9
add bridge=Management-Bridge interface=Management-VLAN-Switch
add bridge=bridge1 disabled=yes interface=School-Temp-Network
add bridge=Management-Bridge interface=Management-VPLS-Link-Room5
add bridge=bridge1 disabled=yes interface=PPPoE-Barcelona-Sector-2
add bridge=Management-Bridge hw=no interface=ether12
add bridge=Management-Bridge interface=Management-VPLS-Link-Room2
add bridge=Management-Bridge disabled=yes interface=ether11
add bridge=Management-Bridge interface=Management-Link-site4
add bridge=Management-Bridge interface=Management-VLAN-Room-PTP-site4
add bridge=bridge1 hw=no interface=ether8
add bridge=Management-Bridge disabled=yes interface=ether10
add bridge=Management-Bridge comment="UNMS Server" hw=no interface=ether7
add bridge=Management-Bridge interface=Management-Link-site2
add bridge=Management-Bridge interface=Management-VPLS-Link-Hospital2
add bridge=Management-Bridge interface=site2-Management-VLAN10
add bridge=site2 hw=no interface=ether2-ap1
add bridge=RoomInHouse interface=ether9
add bridge=Management-Bridge interface=vlan2
add bridge=Management-Bridge interface=Management-VPLS-site32-Core
add bridge=bridge5 interface=Management-Link-site32
add bridge=bridge5 interface=ether4
add bridge=Management-Bridge interface=Management-Link-Baywest-PB
add bridge=Management-Bridge interface=Management-Link-Malabar-PB
add bridge=Cambium-Bridge interface=Management-VLAN10-Ether5
/interface detect-internet
set detect-interface-list=all
/interface l2tp-server server
set default-profile=VPN use-ipsec=required
/interface pppoe-server server
add default-profile=PPPoE-Profile disabled=no interface=bridge1 service-name=\
    site4-PPPOE
add default-profile=PPPoE-Profile interface=PPPoE-Barcelona-Sector-1 \
    one-session-per-host=yes service-name=Barcelona-Sector-1
add default-profile=PPPoE-Profile interface=PPPoE-Barcelona-Sector-2 \
    one-session-per-host=yes service-name=Barcelona-Sector-2
add default-profile=PPPoE-Profile disabled=no interface=\
    PPPoE-VPLS-Room9-Sector-1 one-session-per-host=yes service-name=\
    Room9-Sector-1
add default-profile=PPPoE-Profile disabled=no interface=Room-Sector-1 \
    one-session-per-host=yes service-name=Room-Sector-1
add default-profile=PPPoE-Profile disabled=no interface=Room-Sector-2 \
    one-session-per-host=yes service-name=Room-Sector-2
add default-profile=PPPoE-Profile interface=School-Temp-Network \
    one-session-per-host=yes service-name=Hospital-Sector
add default-profile=PPPoE-Profile disabled=no interface=PPPoE-Room5-Sector-2 \
    one-session-per-host=yes service-name=Room5-Sector-2
add default-profile=PPPoE-Profile disabled=no interface=PPPoE-Room5-Sector-3 \
    one-session-per-host=yes service-name=Room5-Sector-3
add default-profile=PPPoE-Profile disabled=no interface=PPPoE-Room5-Sector-1 \
    one-session-per-host=yes service-name=Room5-Sector-1
add default-profile=PPPoE-Profile disabled=no interface=PPPoE-Hospital-1 \
    one-session-per-host=yes service-name=Hospital-Sector-1
add default-profile=PPPoE-Profile disabled=no interface=PPPoE-Hospital-2 \
    keepalive-timeout=disabled one-session-per-host=yes service-name=\
    Hospital-Sector-2
add default-profile=PPPoE-Profile disabled=no interface=PPPoE-Hospital-3 \
    keepalive-timeout=disabled one-session-per-host=yes service-name=\
    Hospital-Sector-3
add default-profile=PPPoE-Profile disabled=no interface=PPPoE-Hospital-4 \
    one-session-per-host=yes service-name=Hospital-Sector-4
add default-profile=PPPoE-Profile interface=PPPoE-Barcelona-Sector-3 \
    one-session-per-host=yes service-name=Barcelona-Sector-3
add default-profile=PPPoE-Profile disabled=no interface=\
    PPPoE-site4-Sector-1 service-name=site4-Sector-1
add default-profile=PPPoE-Profile disabled=no interface=\
    PPPoE-site4-Sector-2 one-session-per-host=yes service-name=\
    site4-Sector-2
add disabled=no interface=Management-Bridge service-name=service1
add default-profile=PPPoE-Profile interface=ether3 service-name=PPPOERoom
add default-profile=PPPoE-Profile interface=ether5 service-name=PPPOETesting
add authentication=mschap2 default-profile=VPN interface=INTERNET \
    service-name=vpn-in
add default-profile=PPPoE-Profile disabled=no interface=Room-Sector-3 \
    one-session-per-host=yes service-name=Room-Sector-3
add default-profile=PPPoE-Profile disabled=no interface=PPPoE-site2-Sector-1 \
    one-session-per-host=yes service-name=PPPoE-Server-site2-Sector-1
add default-profile=PPPoE-Profile disabled=no interface=\
    PPPoE-site2-Personal-Line one-session-per-host=yes service-name=\
    PPPoE-Server-site2-Personal-Line
add default-profile=PPPoE-Profile disabled=no interface=PPPoE-Hospital-5 \
    one-session-per-host=yes service-name=Hospital-Sector-5
add default-profile=PPPoE-Profile disabled=no interface=PPPoE-Hospital-6 \
    one-session-per-host=yes service-name=Hospital-Sector-6
add default-profile=PPPoE-Profile disabled=no interface=\
    PPPoE-Hospital2-Sector-1 one-session-per-host=yes service-name=\
    Hospital2-Sector-1
add default-profile=PPPoE-Profile disabled=no interface=\
    PPPoE-Hospital2-Sector-3 one-session-per-host=yes service-name=\
    Hospital2-Sector-3
add default-profile=PPPoE-Profile disabled=no interface=\
    PPPoE-Hospital2-Sector-2 one-session-per-host=yes service-name=\
    Hospital2-Sector-2-PPPOE-Service
add default-profile=PPPoE-Profile interface=PPPoE-Barcelona-Sector-4 \
    one-session-per-host=yes service-name=Barcelona-Sector-4
add default-profile=PPPoE-Profile interface=PPPoE-Barcelona-Sector-5 \
    one-session-per-host=yes service-name=Barcelona-Sector-5
add default-profile=PPPoE-Profile disabled=no interface=PPPoE-School-Sector-3 \
    one-session-per-host=yes service-name=School-Sector-3
add default-profile=PPPoE-Profile disabled=no interface=\
    PPPoE-VPLS-Room9-Sector-2 one-session-per-host=yes service-name=site32
add default-profile=PPPoE-Profile disabled=no interface=PPPoE-School-Sector-1 \
    one-session-per-host=yes service-name=School-Sector-1
add default-profile=PPPoE-Profile disabled=no interface=PPPoE-School-Sector-2 \
    one-session-per-host=yes service-name=School-Sector-2
add default-profile=PPPoE-Profile disabled=no interface=PPPoE-School-Sector-4 \
    one-session-per-host=yes service-name=School-Sector-4
add default-profile=PPPoE-Profile disabled=no interface=\
    PPPoE-Hospital2-Sector-4 one-session-per-host=yes service-name=\
    Hospital2-Sector-4-PPPOE-Service
add default-profile=PPPoE-Profile disabled=no interface=\
    PPPoE-Hospital2-Sector-5 one-session-per-host=yes service-name=\
    Hospital2-Sector-5-PPPOE-Service
add default-profile=PPPoE-Profile disabled=no interface=\
    PPPoE-Hospital2-Sector-6 one-session-per-host=yes service-name=\
    Hospital2-Sector-6-PPPOE-Service
add default-profile=PPPoE-Profile disabled=no interface=\
    PPPoE-Hospital2-Sector-7 one-session-per-host=yes service-name=\
    Hospital2-Sector-7-PPPOE-Service
add default-profile=PPPoE-Profile disabled=no interface=\
    PPPoE-Hospital2-Sector-8 one-session-per-host=yes service-name=\
    Hospital2-Sector-8-PPPOE-Service
add default-profile=PPPoE-Profile disabled=no one-session-per-host=yes \
    service-name=site2
add default-profile=PPPoE-Profile disabled=no interface=site2 service-name=\
    site2-PPPOE
add default-profile=PPPoE-Profile disabled=no interface=RoomInHouse \
    one-session-per-host=yes service-name=service4
/interface pptp-server server
set default-profile=L2TP-Profile
/interface sstp-server server
set enabled=yes port=4433
/ip accounting
set account-local-traffic=yes enabled=yes threshold=6500
/ip accounting web-access
set accessible-via-web=yes
/ip address
add address=197.100.8.4/29 interface=INTERNET network=197.100.8.0
add address=192.168.7.230/24 comment="This IP address allows you to connect to\
    \_the Sectors AND it is the IP address for the Usermanager to connect to" \
    interface=bridge1 network=192.168.7.0
add address=7.8.6.5/24 disabled=yes interface=ether2-ap1 network=7.8.6.0
add address=192.168.77.254/24 disabled=yes interface=ether11 network=\
    192.168.77.0
add address=10.254.3.254/22 disabled=yes interface=bridge1 network=10.254.0.0
add address=10.255.255.1 interface=LoopBack network=10.255.255.1
add address=10.200.0.1/29 interface=Room-PTP-Room9 network=10.200.0.0
add address=172.16.0.1/22 interface=Management-Bridge network=172.16.0.0
add address=10.200.0.25/29 interface=Room-PTP-Room5 network=10.200.0.24
add address=192.168.1.1/24 disabled=yes interface=Room-PTP-Room2 network=\
    192.168.1.0
add address=10.200.0.73/29 interface=Room-PTP-Room2 network=10.200.0.72
add address=10.200.0.105/29 interface=ether8 network=10.200.0.104
add address=197.100.8.3/29 interface=INTERNET network=197.100.8.0
add address=10.45.45.1/24 disabled=yes interface=ether3 network=10.45.45.0
add address=10.40.40.90/24 disabled=yes interface=ether3 network=10.40.40.0
add address=10.230.1.1 disabled=yes interface=bridge2 network=10.230.1.1
add address=10.200.0.220/29 disabled=yes network=10.200.0.216
add address=10.200.0.225/29 interface=bridge5 network=10.200.0.224
add address=172.16.10.1/24 disabled=yes interface=bridge4 network=172.16.10.0
add address=10.0.101.11/29 disabled=yes interface=ether4 network=10.0.101.8
add address=192.168.88.82/24 disabled=yes interface=ether9 network=\
    192.168.88.0
add address=10.231.0.2/24 disabled=yes interface=ether4 network=10.231.0.0
add address=172.16.10.1/24 disabled=yes interface=\
    Management-VPLS-Link-Hospital2 network=172.16.10.0
add address=10.50.0.1/24 disabled=yes interface=ether5 network=10.50.0.0
add address=172.16.22.1/24 interface=bridge5 network=172.16.22.0
add address=197.100.8.2/29 disabled=yes interface=INTERNET network=\
    197.100.8.0
add address=192.168.1.28/24 comment=\
    "Temp route for sector radios not on DHCP" disabled=yes interface=\
    Management-Bridge network=192.168.1.0
add address=192.168.12.1/24 interface=site2 network=192.168.12.0
add address=10.201.0.1/29 interface=bridge1 network=10.201.0.0
add address=10.209.1.2/29 interface=RoomInHouse network=10.209.1.0
add address=10.213.0.10/29 interface=site2 network=10.213.0.8
add address=197.100.8.5/29 interface=INTERNET network=197.100.8.0
add address=172.20.1.1/24 interface=ether7 network=172.20.1.0
add address=172.23.16.1 disabled=yes interface=Management-VPLS-site32-Core \
    network=172.23.16.1
add address=197.100.8.6/29 interface=INTERNET network=197.100.8.0
add address=10.31.31.1/29 interface=ether10 network=10.31.31.0
add address=192.168.251.1/29 comment=iDRAC interface=ether11 network=\
    192.168.251.0
add address=172.16.50.1/24 interface=Cambium-Bridge network=172.16.50.0
/ip cloud
set ddns-enabled=yes
/ip dhcp-server lease
add address=172.16.0.10 always-broadcast=yes client-id=1:0:27:22:42:7b:61 \
    mac-address=00:27:22:42:7B:61 server=dhcp4
add address=172.16.0.2 always-broadcast=yes client-id=1:0:27:22:12:e1:4a \
    mac-address=00:27:22:12:E1:4A server=dhcp4
add address=172.16.0.3 always-broadcast=yes client-id=1:0:27:22:42:7c:1 \
    mac-address=00:27:22:42:7C:01 server=dhcp4
add address=172.16.0.22 always-broadcast=yes client-id=1:80:2a:a8:a4:dd:85 \
    mac-address=80:2A:A8:A4:DD:85 server=dhcp4
add address=172.16.0.21 always-broadcast=yes client-id=1:80:2a:a8:a4:de:45 \
    mac-address=80:2A:A8:A4:DE:45 server=dhcp4
add address=172.16.0.215 always-broadcast=yes client-id=1:78:8a:20:1c:e4:f0 \
    mac-address=78:8A:20:1C:E4:F0 server=dhcp4
add address=172.16.0.219 always-broadcast=yes client-id=1:f0:9f:c2:ec:4e:47 \
    mac-address=F0:9F:C2:EC:4E:47 server=dhcp4
add address=172.16.0.205 mac-address=2C:56:DC:92:A0:39 server=dhcp4
add address=172.16.0.210 always-broadcast=yes client-id=1:f0:9f:c2:4a:9f:a6 \
    mac-address=F0:9F:C2:4A:9F:A6 server=dhcp4
add address=172.16.0.234 client-id=1:78:8a:20:ce:b5:dd mac-address=\
    78:8A:20:CE:B5:DD server=dhcp4
add address=192.168.7.254 client-id=1:cc:2d:e0:31:0:38 mac-address=\
    CC:2D:E0:31:00:38 server=dhcp1
add address=172.16.0.204 always-broadcast=yes client-id=1:f0:9f:c2:4a:a6:7b \
    mac-address=F0:9F:C2:4A:A6:7B server=dhcp4
add address=172.16.0.216 always-broadcast=yes client-id=1:80:2a:a8:e8:79:83 \
    mac-address=80:2A:A8:E8:79:83 server=dhcp4
add address=172.16.0.214 client-id=1:80:2a:a8:e8:77:4c mac-address=\
    80:2A:A8:E8:77:4C server=dhcp4
add address=172.16.0.217 always-broadcast=yes client-id=1:f0:9f:c2:50:d:f5 \
    mac-address=F0:9F:C2:50:0D:F5 server=dhcp4
add address=172.16.0.228 client-id=1:f0:9f:c2:50:33:a6 mac-address=\
    F0:9F:C2:50:33:A6 server=dhcp4
add address=172.16.0.229 client-id=1:80:2a:a8:24:e2:4d mac-address=\
    80:2A:A8:24:E2:4D server=dhcp4
add address=172.16.0.209 client-id=1:78:8a:20:6c:f8:e8 comment=\
    "Room2 Sector 2" mac-address=78:8A:20:6C:F8:E8 server=dhcp4
add address=172.16.0.225 client-id=1:80:2a:a8:e8:77:55 comment=\
    "Room2 Sector 1" mac-address=80:2A:A8:E8:77:55 server=dhcp4
add address=172.16.0.221 client-id=1:f0:9f:c2:e2:3c:0 comment=\
    "site4 Sector 1" mac-address=F0:9F:C2:E2:3C:00 server=dhcp4
add address=172.16.0.222 client-id=1:f0:9f:c2:e2:41:6 comment=\
    "site4 Sector 2" mac-address=F0:9F:C2:E2:41:06 server=dhcp4
add address=172.16.0.236 client-id=1:0:27:22:8:42:23 mac-address=\
    00:27:22:08:42:23 server=dhcp4
add address=172.16.0.235 client-id=1:4:18:d6:ea:44:d2 mac-address=\
    04:18:D6:EA:44:D2 server=dhcp4
add address=172.16.0.200 client-id=1:78:8a:20:6c:fa:b1 mac-address=\
    78:8A:20:6C:FA:B1 server=dhcp4
add address=172.16.0.220 client-id=1:78:8a:20:6c:f9:a0 mac-address=\
    78:8A:20:6C:F9:A0 server=dhcp4
add address=172.16.0.211 client-id=1:44:d9:e7:d2:43:d mac-address=\
    44:D9:E7:D2:43:0D server=dhcp4
add address=172.16.0.202 comment="ePMP Cambium School Station" mac-address=\
    00:04:56:29:43:CC server=dhcp4
add address=172.16.0.206 comment="ePMP Cambium site3 AP " mac-address=\
    00:04:56:29:2D:01 server=dhcp4
add address=172.16.0.223 client-id=1:78:8a:20:ec:e4:64 comment=\
    "Room2 Sector 3 (PrismStation)" mac-address=78:8A:20:EC:E4:64 server=\
    dhcp4
add address=172.16.0.224 client-id=1:fc:ec:da:96:b:8c comment=\
    "site2 PtP Room" mac-address=FC:EC:DA:96:0B:8C server=dhcp4
add address=172.16.0.227 client-id=1:0:27:22:8:42:28 comment="site2 Sector" \
    mac-address=00:27:22:08:42:28 server=dhcp4
add address=172.16.0.230 client-id=1:44:d9:e7:de:80:f9 comment=\
    "Room PtP site2" mac-address=44:D9:E7:DE:80:F9 server=dhcp4
add address=172.16.0.201 client-id=1:80:2a:a8:64:ec:a0 mac-address=\
    80:2A:A8:64:EC:A0 server=dhcp4
add address=172.16.0.207 client-id=1:80:2a:a8:64:ec:e8 mac-address=\
    80:2A:A8:64:EC:E8 server=dhcp4
add address=172.16.0.218 client-id=1:44:d9:e7:c2:d5:8a mac-address=\
    44:D9:E7:C2:D5:8A server=dhcp4
add address=172.16.0.231 client-id=1:f0:9f:c2:ec:9e:6a mac-address=\
    F0:9F:C2:EC:9E:6A server=dhcp4
add address=172.16.0.213 client-id=1:f0:9f:c2:ec:50:17 mac-address=\
    F0:9F:C2:EC:50:17 server=dhcp4
add address=172.16.0.208 client-id=1:44:d9:e7:c2:d6:6 mac-address=\
    44:D9:E7:C2:D6:06 server=dhcp4
add address=172.16.0.212 client-id=1:80:2a:a8:ae:ca:e5 mac-address=\
    80:2A:A8:AE:CA:E5 server=dhcp4
add address=172.16.0.226 client-id=1:24:a4:3c:42:5f:81 mac-address=\
    24:A4:3C:42:5F:81 server=dhcp4
add address=172.16.0.238 client-id=1:fc:ec:da:96:a:82 mac-address=\
    FC:EC:DA:96:0A:82 server=dhcp4
add address=172.16.0.243 client-id=1:78:8a:20:ac:f0:66 mac-address=\
    78:8A:20:AC:F0:66 server=dhcp4
add address=172.16.0.242 client-id=1:fc:ec:da:dc:f7:b0 comment=Malabar \
    mac-address=FC:EC:DA:DC:F7:B0 server=dhcp4
add address=172.16.0.239 client-id=1:fc:ec:da:dc:f8:3e comment=Baywest \
    mac-address=FC:EC:DA:DC:F8:3E server=dhcp4
add address=172.16.0.240 client-id=1:fc:ec:da:dc:f5:e9 mac-address=\
    FC:EC:DA:DC:F5:E9 server=dhcp4
add address=172.16.0.241 client-id=1:fc:ec:da:dc:f7:e6 mac-address=\
    FC:EC:DA:DC:F7:E6 server=dhcp4
add address=172.16.0.232 client-id=1:78:8a:20:6c:f8:35 mac-address=\
    78:8A:20:6C:F8:35 server=dhcp4
add address=172.16.0.233 client-id=1:78:8a:20:6c:f9:ad mac-address=\
    78:8A:20:6C:F9:AD server=dhcp4
add address=172.16.0.237 client-id=1:78:8a:20:62:82:28 mac-address=\
    78:8A:20:62:82:28 server=dhcp4
add address=172.16.0.244 client-id=1:80:2a:a8:ec:10:cd mac-address=\
    80:2A:A8:EC:10:CD server=dhcp4
add address=172.16.0.246 client-id=1:f0:9f:c2:ec:da:77 mac-address=\
    F0:9F:C2:EC:DA:77 server=dhcp4
add address=172.16.0.245 client-id=1:80:2a:a8:6:61:ab mac-address=\
    80:2A:A8:06:61:AB server=dhcp4
add address=172.16.0.249 client-id=1:4:18:d6:32:15:5a mac-address=\
    04:18:D6:32:15:5A server=dhcp4
add address=172.16.0.250 client-id=1:fc:ec:da:dc:f8:50 mac-address=\
    FC:EC:DA:DC:F8:50 server=dhcp4
add address=172.16.0.247 client-id=1:80:2a:a8:a4:19:dc comment="New Link" \
    mac-address=80:2A:A8:A4:19:DC server=dhcp4
add address=172.16.0.248 client-id=1:80:2a:a8:a4:19:e8 comment="New Link" \
    mac-address=80:2A:A8:A4:19:E8 server=dhcp4
add address=172.16.22.254 client-id=1:78:8a:20:e4:49:6b comment="New Link" \
    mac-address=78:8A:20:E4:49:6B server=dhcp6
add address=172.16.22.253 client-id=1:78:8a:20:e4:4a:c4 mac-address=\
    78:8A:20:E4:4A:C4 server=dhcp6
add address=10.31.31.2 client-id=\
    ff:b6:22:f:eb:0:2:0:0:ab:11:29:d4:e8:31:91:36:f1:46 mac-address=\
    00:25:64:F9:2F:C8 server=dhcp11
/ip dhcp-server network
add address=10.31.31.0/29 dns-server=8.8.8.8,8.8.4.4 gateway=10.31.31.1
add address=10.200.0.0/24 gateway=10.200.0.1
add address=172.16.0.0/23 dns-server=8.8.8.8,8.8.4.4 gateway=172.16.0.1
add address=172.16.2.0/24 gateway=172.16.2.1
add address=172.16.3.0/24 gateway=172.16.3.1
add address=172.16.10.0/24 gateway=172.16.10.1
add address=172.16.22.0/24 gateway=172.16.22.1
add address=172.16.50.0/24 gateway=172.16.50.1
add address=172.16.225.0/24 gateway=172.16.225.1
add address=172.20.1.0/24 gateway=172.20.1.1
add address=172.23.16.0/24 gateway=172.23.16.1
add address=192.168.7.0/24 gateway=192.168.7.230
add address=192.168.12.0/24 gateway=192.168.12.1
add address=192.168.77.0/24 gateway=192.168.77.254
/ip dns
set allow-remote-requests=yes cache-max-ttl=1d cache-size=20240KiB \
    max-concurrent-queries=500 max-concurrent-tcp-sessions=220 \
    max-udp-packet-size=10240 servers=8.8.8.8,8.8.4.4
/ip dns static
add address=172.16.0.205 name=unms.ITECH.co.za
add address=10.31.31.2 name=revid.co.za
add address=10.31.31.2 name=www.revid.co.za
add address=10.31.31.2 name=encode.revid.co.za
add address=10.31.31.2 name=www.encode.revid.co.za
add address=192.168.1.186 name=encode.revid.co.za
add address=127.0.0.1 disabled=yes regexp="\\.(ru|de|be|cz)\$"
add address=10.31.31.2 name=speedtest.ITECH.co.za
add address=10.31.31.2 name=www.speedtest.ITECH.co.za
/ip firewall address-list

/ip firewall filter
add action=jump chain=forward disabled=yes dst-address-list=!white-resource \
    jump-target=Blocked src-address-list=SpLBL_blocked
add action=jump chain=forward disabled=yes dst-address-list=!white-resource \
    jump-target=Blocked src-address-list=SpLBL_new
add action=jump chain=forward disabled=yes dst-address-list=!white-resource \
    jump-target=Blocked src-address-list=SpLBL_active
add action=accept chain=Blocked disabled=yes dst-limit=2,0,src-address/1m40s \
    dst-port=53 protocol=udp
add action=accept chain=Blocked disabled=yes dst-address=splynxIP \
    dst-port=80,8101,8102,8103,8104 protocol=tcp
add action=reject chain=Blocked disabled=yes dst-limit=10,0,src-address/1m40s \
    reject-with=icmp-admin-prohibited
add action=drop chain=Blocked disabled=yes
add action=add-dst-to-address-list address-list=white-resource \
    address-list-timeout=none-dynamic chain=forward comment=\
    "Add Absa to Allowed List" protocol=tcp tls-host=*absa.co.za
add action=add-dst-to-address-list address-list=white-resource \
    address-list-timeout=none-dynamic chain=forward comment=\
    "Add Nedank to Allowed List" protocol=tcp tls-host=*nedbank.co.za
add action=add-dst-to-address-list address-list=white-resource \
    address-list-timeout=none-dynamic chain=forward comment=\
    "Add Standard Bank to Allowed List" protocol=tcp tls-host=\
    *standardbank.co.za
add action=add-dst-to-address-list address-list=white-resource \
    address-list-timeout=none-dynamic chain=forward comment=\
    "Add FNB to Allowed List" protocol=tcp tls-host=*fnb.co.za
add action=add-dst-to-address-list address-list=white-resource \
    address-list-timeout=none-dynamic chain=forward comment=\
    "Add Capitec to Allowed List" protocol=tcp tls-host=*capitecbank.co.za
add action=accept chain=forward comment=Mikroserv disabled=yes dst-port=53 \
    protocol=tcp src-address-list=BLOCKED_USERS
add action=accept chain=forward comment=Mikroserv disabled=yes dst-port=53 \
    protocol=udp src-address-list=BLOCKED_USERS
add action=drop chain=forward comment=Mikroserv disabled=yes \
    dst-address-list=!AllowedList src-address-list=BLOCKED_USERS
add action=accept chain=forward connection-nat-state=dstnat disabled=yes \
    in-interface=INTERNET
add action=drop chain=input comment=Mikroserv disabled=yes dst-address-list=\
    !AllowedList src-address-list=BLOCKED_USERS
add action=accept chain=input comment=bestpratice disabled=yes dst-port=23023 \
    protocol=tcp
add action=accept chain=input comment=bestpratice disabled=yes dst-port=23023 \
    protocol=tcp
add action=add-dst-to-address-list address-list=Torrent-List \
    address-list-timeout=30m chain=forward disabled=yes p2p=all-p2p \
    src-address=10.0.0.0/8
add action=drop chain=forward disabled=yes dst-address=172.16.0.0/22 \
    src-address=10.0.0.0/23
add action=accept chain=input comment="default configuration" disabled=yes \
    protocol=icmp
add action=accept chain=input comment="default configuration" disabled=yes \
    dst-port=8291 protocol=tcp
add action=accept chain=input comment="default configuration" disabled=yes \
    dst-port=5016 protocol=tcp
add action=accept chain=input comment="default configuration" disabled=yes \
    dst-port=8728 protocol=tcp
add action=accept chain=input comment="default configuration" disabled=yes \
    dst-port=8099 protocol=tcp
add action=accept chain=input comment="default configuration" disabled=yes \
    dst-port=1723 protocol=tcp
add action=accept chain=input comment="default configuration" disabled=yes \
    dst-port=161 protocol=tcp
add action=accept chain=input comment="default configuration" disabled=yes \
    dst-port=161 protocol=udp
add action=accept chain=input comment="default configuration" disabled=yes \
    src-address=197.242.146.87
add action=drop chain=input comment="default configuration" disabled=yes \
    src-address=41.185.26.95
add action=accept chain=forward comment="default configuration" disabled=yes \
    src-address=10.44.10.0/24
add action=accept chain=input comment="default configuration" disabled=yes \
    src-address=154.0.169.24
add action=accept chain=input comment="default configuration" disabled=yes \
    dst-port=1701 protocol=udp
add action=accept chain=input comment="default configuration" disabled=yes \
    protocol=gre
add action=accept chain=input comment="default configuration" disabled=yes \
    dst-port=1723 protocol=udp
add action=accept chain=input comment="Wired-IT-Public Network" disabled=yes \
    src-address=196.213.202.88/29
add action=accept chain=input comment="default configuration" \
    connection-state=established,related disabled=yes
add action=drop chain=input comment="default configuration" disabled=yes \
    in-interface=INTERNET
add action=accept chain=forward comment="default configuration" \
    connection-state=established,related disabled=yes
add action=drop chain=forward comment="default configuration" \
    connection-state=invalid disabled=yes
add action=drop chain=forward comment="default configuration" \
    connection-nat-state=!dstnat connection-state=new disabled=yes \
    in-interface=INTERNET
add action=jump chain=forward comment=ucrm_forward_first disabled=yes \
    jump-target=ucrm_forward_first
add action=jump chain=forward comment=ucrm_forward_general disabled=yes \
    jump-target=ucrm_forward_general
add action=jump chain=forward comment=ucrm_forward_drop disabled=yes \
    jump-target=ucrm_forward_drop
add action=accept chain=ucrm_forward_general comment=\
    ucrm_blocked_users_allow_dns disabled=yes dst-port=53 protocol=udp \
    src-address-list=BLOCKED_USERS
add action=accept chain=input comment=ucrm_accept_input disabled=yes \
    src-address=172.16.0.205
add action=accept chain=forward comment=ucrm_accept_forward disabled=yes \
    src-address=172.16.0.205
add action=drop chain=ucrm_forward_drop comment=ucrm_blocked_users_drop \
    disabled=yes dst-address=!172.16.0.205 src-address-list=BLOCKED_USERS
add action=drop chain=input disabled=yes dst-port=53 in-interface=INTERNET \
    protocol=udp
add action=drop chain=input disabled=yes dst-port=53 in-interface=INTERNET \
    protocol=tcp
add action=drop chain=forward disabled=yes dst-port=\
    !0-1024,8291,5900,5800,3389,14147,5222,59905 protocol=tcp \
    src-address-list=Torrent-Conn
add action=drop chain=forward disabled=yes dst-port=\
    !0-1024,8291,5900,5800,3389,14147,5222,59905 protocol=udp \
    src-address-list=Torrent-Conn
add action=accept chain=forward dst-port=25,587 protocol=tcp
add action=drop chain=forward dst-port=25,587 protocol=tcp
/ip firewall mangle
add action=mark-routing chain=prerouting disabled=yes new-routing-mark=\
    Some-Clients passthrough=yes src-address=10.0.0.2-10.0.0.40
add action=mark-routing chain=prerouting disabled=yes new-routing-mark=\
    Some-Clients passthrough=yes src-address=10.0.0.210
add action=accept chain=prerouting comment=\
    "Accept traffic From QOSCustomerIPs to QOSCustomerIPs" disabled=yes \
    dst-address-list=QOSCustomerIPs src-address-list=QOSCustomerIPs
add action=accept chain=prerouting comment=\
    "Accept traffic From QOSCustomerIPs to QOSCustomerIPs" disabled=yes \
    dst-address-list=QOSCustomerIPs src-address-list=QOSCustomerIPs
add action=accept chain=prerouting comment=\
    "Accept traffic From QOSCustomerIPs to QOSCustomerIPs" disabled=yes \
    dst-address-list=QOSCustomerIPs src-address-list=QOSCustomerIPs
add action=mark-packet chain=postrouting comment="Mark All Download Traffic" \
    disabled=yes new-packet-mark=Global-Upload out-interface=INTERNET \
    passthrough=yes
add action=mark-packet chain=prerouting comment="Mark All Upload Traffic" \
    disabled=yes in-interface=INTERNET new-packet-mark=Global-Download \
    passthrough=yes
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    "DNS Upload" out-interface=INTERNET passthrough=yes protocol=tcp \
    tcp-flags=ack
add action=mark-packet chain=prerouting comment="ShowMax Streaming Download " \
    disabled=yes in-interface=INTERNET new-packet-mark="DNS Download" \
    passthrough=yes protocol=tcp tcp-flags=ack
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Undefined-Upload out-interface=INTERNET passthrough=yes
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Undefined-Download passthrough=yes
add action=mark-packet chain=postrouting disabled=yes dst-address-list=\
    NetFlix new-packet-mark=Stream-Upload out-interface=INTERNET passthrough=\
    no
add action=mark-packet chain=prerouting comment="ShowMax Streaming Download " \
    disabled=yes in-interface=INTERNET new-packet-mark=Stream-Download \
    passthrough=no src-address-list=ShowMax
add action=mark-packet chain=postrouting disabled=yes dst-address-list=\
    FaceBook new-packet-mark=Facebook-Upload out-interface=INTERNET \
    passthrough=no
add action=mark-packet chain=prerouting comment=\
    "FaceBook Streaming Download " disabled=yes in-interface=INTERNET \
    new-packet-mark=Facebook-Download passthrough=yes src-address-list=\
    FaceBook
add action=mark-packet chain=postrouting disabled=yes dst-address-list=\
    ShowMax new-packet-mark=Stream-Upload out-interface=INTERNET passthrough=\
    no
add action=mark-packet chain=prerouting comment="NetFlix Streaming Download " \
    disabled=yes in-interface=INTERNET new-packet-mark=Netflix passthrough=no \
    src-address-list=NetFlix
add action=mark-packet chain=postrouting disabled=yes dst-address-list=\
    YouTube new-packet-mark=Youtube-Upload out-interface=INTERNET \
    passthrough=no
add action=mark-packet chain=prerouting comment="YouTube Streaming Download " \
    disabled=yes in-interface=INTERNET new-packet-mark=Youtube-Download \
    passthrough=no src-address-list=YouTube
add action=mark-packet chain=postrouting disabled=yes dst-address-list=\
    Teamviewer new-packet-mark=Speedtest-Upload out-interface=INTERNET \
    passthrough=no
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Speedtest-Download passthrough=no src-address-list=\
    SpeedTest
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Admin-Upload out-interface=INTERNET passthrough=no port=1723 protocol=tcp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Admin-Download passthrough=no port=1723 protocol=tcp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Admin-Upload out-interface=INTERNET passthrough=no port=1701 protocol=tcp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Admin-Download passthrough=no port=1701 protocol=tcp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Admin-Upload out-interface=INTERNET passthrough=no port=3389 protocol=tcp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Admin-Download passthrough=no port=3389 protocol=tcp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Admin-Upload out-interface=INTERNET passthrough=no port=1723 protocol=udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Admin-Download passthrough=no port=1723 protocol=udp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Admin-Upload out-interface=INTERNET passthrough=no port=1701 protocol=udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Admin-Download passthrough=no port=1701 protocol=udp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Admin-Upload out-interface=INTERNET passthrough=no port=3389 protocol=udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Admin-Download passthrough=no port=3389 protocol=udp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Admin-Upload out-interface=INTERNET passthrough=no protocol=gre
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Admin-Download passthrough=no protocol=gre
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Admin-Upload out-interface=INTERNET passthrough=no port=161 protocol=udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Admin-Download passthrough=no port=161 protocol=udp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=9987 protocol=udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=9987 protocol=udp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=2302-2305 \
    protocol=udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=2302-2305 protocol=udp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=25565 protocol=\
    tcp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=25565 protocol=tcp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=27000-27030 \
    protocol=udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=27000-27030 protocol=\
    udp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=8087 protocol=tcp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=8087 protocol=tcp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=3000-3003 \
    protocol=udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=3000-3003 protocol=udp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=13000 protocol=\
    tcp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=13000 protocol=tcp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=14000 protocol=\
    tcp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=14000 protocol=tcp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=14008 protocol=\
    tcp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=14008 protocol=tcp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=9091 protocol=udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=9091 protocol=udp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=9987 protocol=tcp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=9987 protocol=tcp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=51413 protocol=\
    tcp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=51413 protocol=tcp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=48119 protocol=\
    udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=48119 protocol=udp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=48130 protocol=\
    udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=48130 protocol=udp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=48118 protocol=\
    udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=48118 protocol=udp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=48120 protocol=\
    udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=48120 protocol=udp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Games-Upload out-interface=INTERNET passthrough=no port=51413 protocol=\
    udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Games-Download passthrough=no port=51413 protocol=udp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Speedtest-Upload out-interface=INTERNET passthrough=no port=8080 \
    protocol=tcp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Speedtest-Download passthrough=no port=8080 protocol=tcp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Speedtest-Upload out-interface=INTERNET passthrough=no port=8080 \
    protocol=udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Speedtest-Download passthrough=no port=8080 protocol=udp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Speedtest-Upload out-interface=INTERNET passthrough=no port=5938 \
    protocol=tcp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Speedtest-Download passthrough=no port=5938 protocol=tcp
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    Speedtest-Upload out-interface=INTERNET passthrough=no port=5938 \
    protocol=udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Speedtest-Download passthrough=no port=5938 protocol=udp
add action=mark-packet chain=postrouting disabled=yes dst-address-list=\
    SpeedTest new-packet-mark=Speedtest-Upload out-interface=INTERNET \
    passthrough=no
add action=mark-packet chain=prerouting comment=ST disabled=yes in-interface=\
    INTERNET new-packet-mark=Speedtest-Download passthrough=no \
    src-address-list=Teamviewer
add action=mark-packet chain=postrouting disabled=yes dst-port=1935 \
    new-packet-mark=Stream-Upload out-interface=INTERNET passthrough=no \
    protocol=tcp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Stream-Download passthrough=no protocol=tcp src-port=1935
add action=mark-packet chain=postrouting disabled=yes layer7-protocol=\
    streaming new-packet-mark=Stream-Upload out-interface=INTERNET \
    passthrough=no
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    layer7-protocol=streaming new-packet-mark=Stream-Download passthrough=no
add action=mark-packet chain=postrouting disabled=yes dst-port=554 \
    new-packet-mark=Stream-Upload out-interface=INTERNET passthrough=no \
    protocol=tcp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Stream-Download passthrough=no protocol=tcp src-port=554
add action=mark-packet chain=postrouting disabled=yes dst-port=554 \
    new-packet-mark=Stream-Upload out-interface=INTERNET passthrough=no \
    protocol=udp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=Stream-Download passthrough=no protocol=udp src-port=554
add action=mark-packet chain=postrouting disabled=yes dst-address-list=\
    Whatsapp new-packet-mark=Whatsapp-Upload out-interface=INTERNET \
    passthrough=no
add action=mark-packet chain=prerouting comment=\
    "WhatsApp Streaming Download " disabled=yes in-interface=INTERNET \
    new-packet-mark=Whatsapp-Download passthrough=no src-address-list=\
    Whatsapp
add action=mark-packet chain=postrouting disabled=yes dst-address=\
    41.185.28.216 new-packet-mark=Radius-Upload out-interface=INTERNET \
    passthrough=no
add action=mark-packet chain=prerouting comment="Radius Download" disabled=\
    yes in-interface=INTERNET new-packet-mark=Radius-Download passthrough=no \
    src-address=41.185.28.216
add action=mark-packet chain=postrouting disabled=yes dst-address=\
    41.185.26.95 new-packet-mark=SNMP-Upload out-interface=INTERNET \
    passthrough=no
add action=mark-packet chain=prerouting comment=SNMP disabled=yes \
    in-interface=INTERNET new-packet-mark=SNMP-Download passthrough=no \
    src-address=41.185.26.95
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    MikroTik-Upload out-interface=INTERNET passthrough=no port=\
    8291,22,5016,8728 protocol=tcp
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark=MikroTik-Download passthrough=no port=8291,22,5016,8728 \
    protocol=tcp
add action=mark-packet chain=postrouting comment="Windows Updates Uploads" \
    disabled=yes dst-address-list=MicroSoft new-packet-mark=\
    "Windows Update Upload" out-interface=INTERNET passthrough=no
add action=mark-packet chain=prerouting comment="Windows Update Downloads" \
    disabled=yes in-interface=INTERNET new-packet-mark=\
    "Windows Update Downloads" passthrough=no src-address-list=MicroSoft
add action=mark-packet chain=prerouting comment="Apple Downloads" disabled=\
    yes in-interface=INTERNET new-packet-mark="Apple Update Downloads" \
    passthrough=no src-address=17.0.0.0/8
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark="Apple Update Downloads" passthrough=no src-address=\
    17.128.0.0/9
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark="Apple Update Downloads" passthrough=no src-address=\
    17.253.0.0/16
add action=mark-packet chain=prerouting disabled=yes in-interface=INTERNET \
    new-packet-mark="Apple Update Downloads" passthrough=no src-address=\
    17.253.52.0/22
add action=mark-packet chain=postrouting comment="Apple Uploads" disabled=yes \
    new-packet-mark="Apple Update Upload" out-interface=INTERNET passthrough=\
    no src-address=17.0.0.0/8
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    "Apple Update Upload" out-interface=INTERNET passthrough=no src-address=\
    17.128.0.0/9
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    "Apple Update Upload" out-interface=INTERNET passthrough=no src-address=\
    17.253.0.0/16
add action=mark-packet chain=postrouting disabled=yes new-packet-mark=\
    "Apple Update Upload" out-interface=INTERNET passthrough=no src-address=\
    17.253.52.0/22
add action=mark-packet chain=postrouting comment="Mail Server POP3 Upload" \
    disabled=yes new-packet-mark=Mail-Upload out-interface=INTERNET \
    passthrough=no port=110 protocol=tcp
add action=mark-packet chain=prerouting comment="Mail Server POP3 Download" \
    disabled=yes in-interface=INTERNET new-packet-mark=Mail-Download \
    passthrough=no port=110 protocol=tcp
add action=mark-packet chain=postrouting comment="Mail Server IMAP Upload" \
    disabled=yes new-packet-mark=Mail-Upload out-interface=INTERNET \
    passthrough=no port=143 protocol=tcp
add action=mark-packet chain=prerouting comment="Mail Server IMAP Download" \
    disabled=yes in-interface=INTERNET new-packet-mark=Mail-Download \
    passthrough=no port=143 protocol=tcp
add action=mark-packet chain=postrouting comment=\
    "Mail Server Secure POP3 Upload" disabled=yes new-packet-mark=Mail-Upload \
    out-interface=INTERNET passthrough=no port=995 protocol=tcp
add action=mark-packet chain=prerouting comment=\
    "Mail Server Secure POP3 Download" disabled=yes in-interface=INTERNET \
    new-packet-mark=Mail-Download passthrough=no port=995 protocol=tcp
add action=mark-packet chain=postrouting comment=\
    "Mail Server Secure IMAP Upload" disabled=yes new-packet-mark=Mail-Upload \
    out-interface=INTERNET passthrough=no port=993 protocol=tcp
add action=mark-packet chain=prerouting comment=\
    "Mail server Secure IMAP Download" disabled=yes in-interface=INTERNET \
    new-packet-mark=Mail-Download passthrough=no port=993 protocol=tcp
add action=mark-packet chain=postrouting comment="Mail Server SMTP Upload" \
    disabled=yes new-packet-mark=Mail-Upload out-interface=INTERNET \
    passthrough=no port=25 protocol=tcp
add action=mark-packet chain=prerouting comment="Mail Server SMTP Download" \
    disabled=yes in-interface=INTERNET new-packet-mark=Mail-Download \
    passthrough=no port=25 protocol=tcp
add action=mark-packet chain=postrouting comment=\
    "Mail Server Old Secure SMTP Upload" disabled=yes new-packet-mark=\
    Mail-Upload out-interface=INTERNET passthrough=no port=465 protocol=tcp
add action=mark-packet chain=prerouting comment=\
    "Mail Server Old Secure SMTP Download" disabled=yes in-interface=INTERNET \
    new-packet-mark=Mail-Download passthrough=no port=465 protocol=tcp
add action=mark-packet chain=postrouting comment=\
    "Mail Server New Secure SMTP Upload" disabled=yes new-packet-mark=\
    Mail-Upload out-interface=INTERNET passthrough=no port=587 protocol=tcp
add action=mark-packet chain=prerouting comment=\
    "Mail Server New Secure SMTP Download" disabled=yes in-interface=INTERNET \
    new-packet-mark=Mail-Download passthrough=no port=587 protocol=tcp \
    src-port=""
add action=mark-packet chain=postrouting comment="File ext Upload (Layer 7)" \
    disabled=yes layer7-protocol=high new-packet-mark=File-Upload \
    out-interface=INTERNET passthrough=no
add action=mark-packet chain=prerouting comment="File ext Download (Layer 7)" \
    disabled=yes in-interface=INTERNET layer7-protocol=high new-packet-mark=\
    File-Download passthrough=no
add action=mark-packet chain=postrouting comment=\
    "Document ext Upload  (Layer 7)" disabled=yes layer7-protocol=document \
    new-packet-mark=Document-Upload out-interface=INTERNET passthrough=no
add action=mark-packet chain=prerouting comment=\
    "Document ext Download (Layer 7)" disabled=yes in-interface=INTERNET \
    layer7-protocol=document new-packet-mark=Document-Download passthrough=no
add action=mark-packet chain=postrouting comment="Mark DNS Upload TCP" \
    connection-rate=0-256 disabled=yes new-packet-mark="DNS Upload" \
    out-interface=INTERNET passthrough=no port=53 protocol=tcp
add action=mark-packet chain=prerouting comment="Mark DNS Download TCP" \
    connection-rate=0-256 disabled=yes in-interface=INTERNET new-packet-mark=\
    "DNS Download" passthrough=no port=53 protocol=tcp
add action=mark-packet chain=postrouting comment="Mark DNS Upload TCP" \
    connection-rate=0-256 disabled=yes new-packet-mark="DNS Upload" \
    out-interface=INTERNET passthrough=no port=53 protocol=udp
add action=mark-packet chain=prerouting comment="Mark DNS Download TCP" \
    connection-rate=0-256 disabled=yes in-interface=INTERNET new-packet-mark=\
    "DNS Download" passthrough=no port=53 protocol=udp
add action=mark-packet chain=postrouting comment="NTP Time Upload TCP" \
    disabled=yes new-packet-mark="NTP Time Upload" out-interface=INTERNET \
    passthrough=no port=123 protocol=tcp
add action=mark-packet chain=prerouting comment="NTP Time Download TCP" \
    disabled=yes in-interface=INTERNET new-packet-mark="NTP Time Download" \
    passthrough=no port=123 protocol=tcp src-port=""
add action=mark-packet chain=postrouting comment="VOIP SIP Upload TCP" \
    disabled=yes new-packet-mark="VOIP SIP Upload" out-interface=INTERNET \
    passthrough=no port=5060-5061 protocol=tcp
add action=mark-packet chain=prerouting comment="VOIP SIP Download TCP" \
    disabled=yes in-interface=INTERNET new-packet-mark="VOIP SIP Download" \
    passthrough=no port=5060-5061 protocol=tcp
add action=mark-packet chain=postrouting comment="ICMP Upload" disabled=yes \
    new-packet-mark="ICMP Upload" out-interface=INTERNET passthrough=no \
    protocol=icmp
add action=mark-packet chain=prerouting comment="ICMP Download" disabled=yes \
    in-interface=INTERNET new-packet-mark="ICMP Download" passthrough=no \
    protocol=icmp
add action=mark-packet chain=postrouting comment="NNTP Upload" disabled=yes \
    new-packet-mark="NNTP Upload" out-interface=INTERNET passthrough=no port=\
    119 protocol=tcp
add action=mark-packet chain=prerouting comment="NNTP Download" disabled=yes \
    in-interface=INTERNET new-packet-mark="NNTP Download" passthrough=no \
    port=119 protocol=udp src-port=""
add action=mark-packet chain=postrouting comment="NNTP Upload" disabled=yes \
    new-packet-mark="NNTP Upload" out-interface=INTERNET passthrough=no port=\
    119 protocol=udp
add action=mark-packet chain=postrouting connection-bytes=0-15728640 \
    disabled=yes new-packet-mark=WEB-Browsing-Upload out-interface=INTERNET \
    passthrough=no port=80,443 protocol=tcp
add action=mark-packet chain=prerouting connection-bytes=0-15728640 disabled=\
    yes in-interface=INTERNET new-packet-mark=WEB-Browsing-Download \
    passthrough=no port=80,443 protocol=tcp
add action=mark-packet chain=postrouting connection-bytes=0-15728640 \
    disabled=yes new-packet-mark=WEB-Browsing-Upload out-interface=INTERNET \
    passthrough=no port=80,443 protocol=udp
add action=mark-packet chain=prerouting connection-bytes=0-15728640 disabled=\
    yes in-interface=INTERNET new-packet-mark=WEB-Browsing-Download \
    passthrough=no port=80,443 protocol=udp
add action=mark-packet chain=postrouting disabled=yes dst-address-list=\
    Torrent-List new-packet-mark=Torrent-Upload out-interface=INTERNET \
    passthrough=no
add action=mark-packet chain=prerouting comment=Torrent-Download \
    in-interface=INTERNET new-packet-mark=Torrent-Download passthrough=no \
    src-address-list=Torrent-List
add action=mark-routing chain=prerouting disabled=yes new-routing-mark=VPN \
    passthrough=yes src-address-list=vpnclients
add action=mark-packet chain=postrouting comment=dscp_0_eth disabled=yes \
    dscp=0 new-packet-mark=dscp_0_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_1_eth disabled=yes \
    dscp=1 new-packet-mark=dscp_1_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_2_eth disabled=yes \
    dscp=2 new-packet-mark=dscp_2_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_3_eth disabled=yes \
    dscp=3 new-packet-mark=dscp_3_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_4_eth disabled=yes \
    dscp=4 new-packet-mark=dscp_4_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_5_eth disabled=yes \
    dscp=5 new-packet-mark=dscp_5_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_6_eth disabled=yes \
    dscp=6 new-packet-mark=dscp_6_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_7_eth disabled=yes \
    dscp=7 new-packet-mark=dscp_7_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_8_eth disabled=yes \
    dscp=8 new-packet-mark=dscp_8_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_9_eth disabled=yes \
    dscp=9 new-packet-mark=dscp_9_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_10_eth disabled=yes \
    dscp=10 new-packet-mark=dscp_10_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_11_eth disabled=yes \
    dscp=11 new-packet-mark=dscp_11_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_12_eth disabled=yes \
    dscp=12 new-packet-mark=dscp_12_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_13_eth disabled=yes \
    dscp=13 new-packet-mark=dscp_13_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_14_eth disabled=yes \
    dscp=14 new-packet-mark=dscp_14_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_15_eth disabled=yes \
    dscp=15 new-packet-mark=dscp_15_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_16_eth disabled=yes \
    dscp=16 new-packet-mark=dscp_16_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_17_eth disabled=yes \
    dscp=17 new-packet-mark=dscp_17_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_18_eth disabled=yes \
    dscp=18 new-packet-mark=dscp_18_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_19_eth disabled=yes \
    dscp=19 new-packet-mark=dscp_19_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_20_eth disabled=yes \
    dscp=20 new-packet-mark=dscp_20_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_21_eth disabled=yes \
    dscp=21 new-packet-mark=dscp_21_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_22_eth disabled=yes \
    dscp=22 new-packet-mark=dscp_22_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_23_eth disabled=yes \
    dscp=23 new-packet-mark=dscp_23_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_24_eth disabled=yes \
    dscp=24 new-packet-mark=dscp_24_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_25_eth disabled=yes \
    dscp=25 new-packet-mark=dscp_25_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_26_eth disabled=yes \
    dscp=26 new-packet-mark=dscp_26_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_27_eth disabled=yes \
    dscp=27 new-packet-mark=dscp_27_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_28_eth disabled=yes \
    dscp=28 new-packet-mark=dscp_28_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_29_eth disabled=yes \
    dscp=29 new-packet-mark=dscp_29_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_30_eth disabled=yes \
    dscp=30 new-packet-mark=dscp_30_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_31_eth disabled=yes \
    dscp=31 new-packet-mark=dscp_31_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_32_eth disabled=yes \
    dscp=32 new-packet-mark=dscp_32_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_33_eth disabled=yes \
    dscp=33 new-packet-mark=dscp_33_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_34_eth disabled=yes \
    dscp=34 new-packet-mark=dscp_34_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_35_eth disabled=yes \
    dscp=35 new-packet-mark=dscp_35_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_36_eth disabled=yes \
    dscp=36 new-packet-mark=dscp_36_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_37_eth disabled=yes \
    dscp=37 new-packet-mark=dscp_37_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_38_eth disabled=yes \
    dscp=38 new-packet-mark=dscp_38_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_39_eth disabled=yes \
    dscp=39 new-packet-mark=dscp_39_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_40_eth disabled=yes \
    dscp=40 new-packet-mark=dscp_40_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_41_eth disabled=yes \
    dscp=41 new-packet-mark=dscp_41_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_42_eth disabled=yes \
    dscp=42 new-packet-mark=dscp_42_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_43_eth disabled=yes \
    dscp=43 new-packet-mark=dscp_43_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_44_eth disabled=yes \
    dscp=44 new-packet-mark=dscp_44_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_45_eth disabled=yes \
    dscp=45 new-packet-mark=dscp_45_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_46_eth disabled=yes \
    dscp=46 new-packet-mark=dscp_46_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_47_eth disabled=yes \
    dscp=47 new-packet-mark=dscp_47_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_48_eth disabled=yes \
    dscp=48 new-packet-mark=dscp_48_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_49_eth disabled=yes \
    dscp=49 new-packet-mark=dscp_49_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_50_eth disabled=yes \
    dscp=50 new-packet-mark=dscp_50_eth passthrough=no
add action=mark-packet chain=prerouting comment=dscp_50_eth disabled=yes \
    dscp=50 new-packet-mark=dscp_50_eth passthrough=yes
add action=mark-packet chain=postrouting comment=dscp_51_eth disabled=yes \
    dscp=51 new-packet-mark=dscp_51_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_52_eth disabled=yes \
    dscp=52 new-packet-mark=dscp_52_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_53_eth disabled=yes \
    dscp=53 new-packet-mark=dscp_53_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_54_eth disabled=yes \
    dscp=54 new-packet-mark=dscp_54_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_55_eth disabled=yes \
    dscp=55 new-packet-mark=dscp_55_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_56_eth disabled=yes \
    dscp=56 new-packet-mark=dscp_56_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_57_eth disabled=yes \
    dscp=57 new-packet-mark=dscp_57_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_58_eth disabled=yes \
    dscp=58 new-packet-mark=dscp_58_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_59_eth disabled=yes \
    dscp=59 new-packet-mark=dscp_59_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_60_eth disabled=yes \
    dscp=60 new-packet-mark=dscp_60_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_61_eth disabled=yes \
    dscp=61 new-packet-mark=dscp_61_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_62_eth disabled=yes \
    dscp=62 new-packet-mark=dscp_62_eth passthrough=no
add action=mark-packet chain=postrouting comment=dscp_63_eth disabled=yes \
    dscp=63 new-packet-mark=dscp_63_eth passthrough=no
add action=mark-connection chain=forward comment=SPEEDTEST disabled=yes \
    layer7-protocol=speedtest new-connection-mark=speedtest_conn passthrough=\
    yes
add action=mark-connection chain=prerouting disabled=yes new-connection-mark=\
    speedtest_conn passthrough=yes protocol=tcp src-port=8080
add action=mark-packet chain=prerouting connection-mark=speedtest_conn \
    disabled=yes new-packet-mark=speedtest_pkt passthrough=no
add action=mark-connection chain=postrouting disabled=yes dst-port=8080 \
    new-connection-mark=speedtest_conn passthrough=yes protocol=tcp
add action=mark-packet chain=postrouting connection-mark=speedtest_conn \
    disabled=yes new-packet-mark=speedtest_pkt passthrough=no
/ip firewall nat
add action=redirect chain=dstnat comment="Blocked -> 8102" disabled=yes \
    dst-port=80 protocol=tcp src-address-list=SpLBL_blocked to-ports=8102
add action=redirect chain=dstnat comment="new -> 8101" disabled=yes dst-port=\
    80 protocol=tcp src-address-list=SpLBL_new to-ports=8101
add action=redirect chain=dstnat comment="FUP or CAP -> 8102" disabled=yes \
    dst-port=80 protocol=tcp src-address-list=SpLBL_active to-ports=8102
add action=redirect chain=dstnat comment="user not found" disabled=yes \
    dst-port=80 protocol=tcp src-address-list=Reject_0 to-ports=8101
add action=redirect chain=dstnat comment=\
    "blocked, not active or not in system" disabled=yes dst-port=80 protocol=\
    tcp src-address-list=Reject_1 to-ports=8101
add action=redirect chain=dstnat comment="negative balance or FUP/CAP" \
    disabled=yes dst-port=80 protocol=tcp src-address-list=Reject_2 to-ports=\
    8102
add action=redirect chain=dstnat comment="wrong MAC" disabled=yes dst-port=80 \
    protocol=tcp src-address-list=Reject_3 to-ports=8104
add action=redirect chain=dstnat comment="wrong password" disabled=yes \
    dst-port=80 protocol=tcp src-address-list=Reject_4 to-ports=8103
add action=netmap chain=dstnat disabled=yes dst-address=197.100.8.6 \
    to-addresses=10.200.0.74
add action=netmap chain=srcnat disabled=yes src-address=10.200.0.74 \
    to-addresses=197.100.8.6
add action=src-nat chain=srcnat comment="Room5 1:1 NAT" out-interface=\
    INTERNET src-address=10.200.0.26 to-addresses=197.100.8.5
add action=dst-nat chain=dstnat comment="Room5 1:1 NAT" dst-address=\
    197.100.8.5 in-interface=INTERNET to-addresses=10.200.0.26
add action=src-nat chain=srcnat comment="Room2 1:1 NAT" disabled=yes \
    out-interface=INTERNET src-address=10.200.0.74 to-addresses=197.100.8.6
add action=dst-nat chain=dstnat comment="Room2 1:1 NAT" disabled=yes \
    dst-address=197.100.8.6 in-interface=INTERNET to-addresses=10.200.0.74
add action=src-nat chain=srcnat comment="Hospital 1:1 NAT" disabled=yes \
    out-interface=INTERNET src-address=10.200.0.234 to-addresses=197.100.8.4
add action=src-nat chain=srcnat comment=Server out-interface=INTERNET \
    src-address=10.31.31.2 to-addresses=197.100.8.4
add action=dst-nat chain=dstnat comment=Server dst-address=197.100.8.4 \
    in-interface=INTERNET to-addresses=10.31.31.2
add action=src-nat chain=srcnat comment="School 1:1 NAT" out-interface=\
    INTERNET src-address=10.200.0.10 to-addresses=197.100.8.3
add action=dst-nat chain=dstnat comment="School 1:1 NAT" dst-address=\
    197.100.8.3 in-interface=INTERNET to-addresses=10.200.0.10
add action=src-nat chain=srcnat comment=Room out-interface=INTERNET \
    src-address=10.0.0.0/12 to-addresses=197.100.8.6
add action=dst-nat chain=dstnat comment=Room dst-address=197.100.8.6 \
    in-interface=INTERNET to-addresses=10.0.0.0/12
add action=src-nat chain=srcnat comment=1609nasir disabled=yes out-interface=\
    INTERNET src-address=10.2.1.167 to-addresses=197.100.8.6
add action=dst-nat chain=dstnat comment="Gerhad Port Opening" disabled=yes \
    dst-address=197.100.8.4 dst-port=3074 in-interface=INTERNET protocol=tcp \
    to-addresses=10.7.0.7 to-ports=3074
add action=dst-nat chain=dstnat comment="Working Test" disabled=yes \
    dst-address=197.100.8.2 dst-port=30741 in-interface=INTERNET protocol=tcp \
    to-addresses=10.9.0.23 to-ports=80
add action=dst-nat chain=dstnat comment=TEST disabled=yes dst-address=\
    197.100.8.2 dst-port=30741 in-interface=INTERNET protocol=tcp \
    to-addresses=10.31.31.7 to-ports=80
add action=dst-nat chain=dstnat comment="Gerhad Port Opening" disabled=yes \
    dst-address=197.100.8.4 dst-port=88 in-interface=INTERNET protocol=udp \
    to-addresses=10.7.0.7 to-ports=88
add action=dst-nat chain=dstnat comment="Gerhad Port Opening" disabled=yes \
    dst-address=197.100.8.4 dst-port=3047 in-interface=INTERNET protocol=udp \
    to-addresses=10.7.0.7 to-ports=3047
add action=dst-nat chain=dstnat comment="Gerhad Port Opening" disabled=yes \
    dst-address=197.100.8.4 dst-port=3544 in-interface=INTERNET protocol=udp \
    to-addresses=10.7.0.7 to-ports=3544
add action=dst-nat chain=dstnat comment="Gerhad Port Opening" disabled=yes \
    dst-address=197.100.8.4 dst-port=6672 in-interface=INTERNET protocol=udp \
    to-addresses=10.7.0.7 to-ports=6672
add action=dst-nat chain=dstnat comment="Gerhad Port Opening" disabled=yes \
    dst-address=197.100.8.4 dst-port=61455-61458 in-interface=INTERNET \
    protocol=udp to-addresses=10.7.0.7 to-ports=61455-61458
add action=dst-nat chain=dstnat comment="Gerhad Port Opening" disabled=yes \
    dst-address=197.100.8.4 dst-port=4500 in-interface=INTERNET protocol=udp \
    to-addresses=10.7.0.7 to-ports=4500
add action=dst-nat chain=dstnat comment="Gerhad Port Opening" disabled=yes \
    dst-address=197.100.8.4 dst-port=3074 in-interface=INTERNET protocol=udp \
    to-addresses=10.7.0.7 to-ports=3074
add action=dst-nat chain=dstnat comment="Gerhad Port Opening" disabled=yes \
    dst-address=197.100.8.4 dst-port=500 in-interface=INTERNET protocol=udp \
    to-addresses=10.7.0.7 to-ports=500
add action=dst-nat chain=dstnat comment="Gerhad Port Opening" disabled=yes \
    dst-address=197.100.8.4 dst-port=30211-30217 in-interface=INTERNET \
    protocol=tcp to-addresses=10.7.0.7 to-ports=30211-30217
add action=src-nat chain=srcnat comment="Change IP for 44nasir" disabled=yes \
    out-interface=INTERNET src-address=10.3.0.115 to-addresses=197.100.8.4
add action=src-nat chain=srcnat comment="Change IP for 44nasir" disabled=yes \
    out-interface=INTERNET src-address=10.2.1.98 to-addresses=197.100.8.4
add action=src-nat chain=srcnat comment="Change IP for 44nasir" disabled=yes \
    out-interface=INTERNET src-address=10.2.1.167 to-addresses=197.100.8.4
add action=src-nat chain=srcnat comment="Change IP for 44nasir" disabled=yes \
    out-interface=INTERNET src-address=10.10.0.49 to-addresses=197.100.8.5
add action=src-nat chain=srcnat comment="Change IP for 1347" disabled=yes \
    out-interface=INTERNET src-address=10.7.0.7 to-addresses=197.100.8.4
add action=src-nat chain=srcnat comment="IP for Barcelona" disabled=yes \
    out-interface=INTERNET src-address=10.200.0.19 to-addresses=197.100.8.4
add action=dst-nat chain=dstnat comment="Port to Winbox School router" \
    disabled=yes dst-port=1024 protocol=tcp to-addresses=172.16.0.231 \
    to-ports=443
add action=dst-nat chain=dstnat comment=Mikroserv disabled=yes \
    dst-address-list=!AllowedList protocol=tcp src-address-list=BLOCKED_USERS \
    to-addresses=80.240.21.118 to-ports=81
add action=dst-nat chain=dstnat comment="To iDRAC" disabled=yes dst-port=2334 \
    protocol=tcp to-addresses=10.0.3.4 to-ports=2334
add action=dst-nat chain=dstnat comment="To iDRAC" disabled=yes dst-port=5900 \
    protocol=tcp to-addresses=10.0.3.4 to-ports=5900
add action=dst-nat chain=dstnat comment="To iDRAC" disabled=yes dst-port=3480 \
    protocol=tcp to-addresses=10.0.3.4 to-ports=2480
add action=dst-nat chain=dstnat comment="Babiana Cameras" disabled=yes \
    dst-port=55100 in-interface=INTERNET protocol=tcp to-addresses=10.0.7.11 \
    to-ports=55100
add action=dst-nat chain=dstnat comment="To iDRAC" disabled=yes dst-port=2251 \
    protocol=tcp to-addresses=10.0.3.4 to-ports=2251
add action=dst-nat chain=dstnat comment="1395 Cameras" disabled=yes dst-port=\
    1395 protocol=tcp to-addresses=10.0.3.77 to-ports=1396
add action=dst-nat chain=dstnat comment="1395 Cameras" disabled=yes dst-port=\
    1001 protocol=tcp to-addresses=10.0.3.4 to-ports=1396
add action=dst-nat chain=dstnat comment="Port to Winbox School router" \
    disabled=yes dst-port=8218 protocol=tcp to-addresses=10.255.255.3 \
    to-ports=8291
add action=dst-nat chain=dstnat comment="Mikroserv >> School router" \
    disabled=yes dst-port=8740 in-interface=INTERNET protocol=tcp \
    src-address=41.185.8.128 to-addresses=10.255.255.3 to-ports=8740
add action=dst-nat chain=dstnat comment="Mikroserv >> School router" \
    dst-port=8740 in-interface=INTERNET protocol=tcp src-address=\
    80.240.21.118 to-addresses=10.255.255.3 to-ports=8741
add action=dst-nat chain=dstnat comment="Mikroserv >> School router" \
    dst-port=7691 protocol=tcp to-addresses=192.168.1.20 to-ports=443
add action=dst-nat chain=dstnat comment="Mikroserv >> Room2 router" \
    dst-port=8750 in-interface=INTERNET protocol=tcp to-addresses=10.200.0.74 \
    to-ports=8751
add action=dst-nat chain=dstnat comment="Mikroserv >> Room2 router" \
    dst-port=7819 in-interface=INTERNET protocol=tcp to-addresses=10.231.0.1 \
    to-ports=8291
add action=dst-nat chain=dstnat comment="Port to Winbox site4 Router" \
    dst-port=7898 protocol=tcp to-addresses=192.168.7.254 to-ports=8291
add action=dst-nat chain=dstnat comment="Port to Winbox site4 Router" \
    dst-port=7899 protocol=tcp to-addresses=10.201.0.2 to-ports=8291
add action=dst-nat chain=dstnat comment="Port to Winbox site4 Router" \
    dst-port=7897 protocol=tcp to-addresses=10.213.0.9 to-ports=8291
add action=dst-nat chain=dstnat comment="Allow access to UCRM server" \
    disabled=yes dst-port=7443 protocol=tcp to-addresses=172.16.0.205 \
    to-ports=7443
add action=dst-nat chain=dstnat comment="Allow access to UCRM server" \
    disabled=yes dst-port=9443 protocol=tcp to-addresses=172.16.0.205 \
    to-ports=443
add action=dst-nat chain=dstnat comment="Allow access to UCRM server" \
    disabled=yes dst-port=85 protocol=tcp to-addresses=172.16.0.205 to-ports=\
    80
add action=dst-nat chain=dstnat comment="Allow access to UNMS server" \
    disabled=yes dst-port=8443 protocol=tcp to-addresses=172.16.0.205 \
    to-ports=8443
add action=dst-nat chain=dstnat comment=\
    "Allow SSH access to Ubuntu UCRM/UNMS server " disabled=yes dst-port=2255 \
    protocol=tcp to-addresses=172.16.0.205 to-ports=22
add action=masquerade chain=srcnat disabled=yes out-interface=ether7
add action=dst-nat chain=dstnat disabled=yes dst-port=80 protocol=tcp \
    to-addresses=172.16.0.231 to-ports=809
add action=dst-nat chain=dstnat disabled=yes dst-port=2255 protocol=tcp \
    to-addresses=172.16.0.231 to-ports=22
add action=dst-nat chain=dstnat disabled=yes dst-port=8080 in-interface=\
    INTERNET protocol=tcp to-addresses=172.16.0.231 to-ports=8080
add action=dst-nat chain=dstnat disabled=yes dst-port=8292 in-interface=\
    all-ethernet log=yes protocol=tcp to-addresses=172.16.0.205 to-ports=8291
add action=dst-nat chain=dstnat disabled=yes dst-port=8730 in-interface=\
    INTERNET protocol=tcp to-addresses=10.255.255.7 to-ports=8728
add action=dst-nat chain=dstnat disabled=yes dst-port=9008 in-interface=\
    INTERNET protocol=tcp to-addresses=10.40.40.2 to-ports=8291
add action=dst-nat chain=dstnat disabled=yes dst-port=2277 in-interface=\
    all-ethernet log=yes protocol=tcp to-addresses=192.168.7.254 to-ports=22
add action=dst-nat chain=dstnat disabled=yes dst-port=9090 in-interface=\
    INTERNET protocol=tcp to-addresses=172.16.0.205 to-ports=80
add action=dst-nat chain=dstnat disabled=yes dst-port=9091 in-interface=\
    INTERNET protocol=tcp to-addresses=172.16.0.205 to-ports=443
add action=dst-nat chain=dstnat disabled=yes dst-port=8091 in-interface=\
    all-ethernet protocol=tcp to-addresses=172.16.0.205 to-ports=8080
add action=dst-nat chain=dstnat disabled=yes dst-port=8296 in-interface=\
    all-ethernet log=yes protocol=tcp to-addresses=172.16.0.2 to-ports=80
add action=dst-nat chain=dstnat disabled=yes dst-port=7001 in-interface=\
    all-ethernet log=yes protocol=tcp to-addresses=172.16.0.230 to-ports=80
add action=dst-nat chain=dstnat disabled=yes dst-port=7002 in-interface=\
    all-ethernet log=yes protocol=tcp to-addresses=172.16.0.215 to-ports=80
add action=dst-nat chain=dstnat disabled=yes dst-port=7003 in-interface=\
    all-ethernet log=yes protocol=tcp to-addresses=172.16.0.21 to-ports=80
add action=dst-nat chain=dstnat disabled=yes dst-port=7004 in-interface=\
    all-ethernet log=yes protocol=tcp to-addresses=172.16.0.22 to-ports=80
add action=masquerade chain=srcnat disabled=yes out-interface=INTERNET \
    src-address=10.0.0.0/22
add action=masquerade chain=srcnat disabled=yes out-interface=INTERNET \
    src-address=10.254.0.0/24
add action=masquerade chain=srcnat disabled=yes out-interface=INTERNET \
    src-address=10.200.0.0/24
add action=masquerade chain=srcnat disabled=yes out-interface=INTERNET \
    src-address=172.16.0.0/22
add action=masquerade chain=srcnat out-interface=INTERNET
add action=masquerade chain=srcnat disabled=yes out-interface=*2AE
add action=masquerade chain=srcnat disabled=yes out-interface=ether4
add action=masquerade chain=srcnat out-interface=Management-Bridge
add action=masquerade chain=srcnat comment=\
    "Allow clients to access the internet " out-interface=INTERNET
add action=masquerade chain=srcnat comment="Allow access to the sectors" \
    out-interface=bridge1
add action=masquerade chain=srcnat comment="Allow access to the sectors" \
    out-interface-list=all
add action=masquerade chain=srcnat out-interface=ether5
add action=masquerade chain=srcnat out-interface=ether3
add action=jump chain=dstnat comment=ucrm_first_dstnat disabled=yes \
    jump-target=ucrm_first_dstnat
add action=jump chain=dstnat comment=ucrm_general_dstnat disabled=yes \
    jump-target=ucrm_general_dstnat
add action=jump chain=dstnat comment=ucrm_last_dstnat disabled=yes \
    jump-target=ucrm_last_dstnat
add action=jump chain=srcnat comment=ucrm_first_srcnat disabled=yes \
    jump-target=ucrm_first_srcnat
add action=jump chain=srcnat comment=ucrm_general_srcnat disabled=yes \
    jump-target=ucrm_general_srcnat
add action=jump chain=srcnat comment=ucrm_range_srcnat disabled=yes \
    jump-target=ucrm_range_srcnat
add action=jump chain=srcnat comment=ucrm_last_srcnat disabled=yes \
    jump-target=ucrm_last_srcnat
add action=redirect chain=dstnat dst-port=53 protocol=udp to-ports=53
add action=redirect chain=dstnat dst-port=53 protocol=tcp to-ports=53
add action=dst-nat chain=dstnat comment=UNMS dst-address=172.16.0.205 \
    dst-port=8443 protocol=tcp to-addresses=172.16.0.205 to-ports=443
add action=masquerade chain=srcnat disabled=yes out-interface=ether10
/ip proxy
set enabled=yes port=8080,8101,8102,8103,8104
/ip proxy access
add dst-address=splynxIP dst-port=80
add action=deny dst-port=80 local-port=8080 redirect-to=splynxIP/portal \
    src-address=!splynxIP
add action=deny dst-port=80 local-port=8101 redirect-to=splynxIP:8101 \
    src-address=!splynxIP
add action=deny dst-port=80 local-port=8102 redirect-to=splynxIP:8102 \
    src-address=!splynxIP
add action=deny dst-port=80 local-port=8103 redirect-to=splynxIP:8103 \
    src-address=!splynxIP
add action=deny dst-port=80 local-port=8104 redirect-to=splynxIP:8104 \
    src-address=!splynxIP
add action=deny
/ip route
add check-gateway=ping disabled=yes distance=1 gateway=10.200.0.26 \
    routing-mark=Some-Clients
add distance=1 gateway=197.100.8.1
add disabled=yes distance=10 gateway=10.200.0.26
add disabled=yes distance=1 gateway=10.200.0.4
/ip service
set telnet disabled=yes port=23023
set ftp address=splynxIP/32
set www disabled=yes port=8087
set ssh address=splynxIP/32
set api port=8731
set winbox port=7811
set api-ssl disabled=yes
/ip ssh
set allow-none-crypto=yes
/ip traffic-flow target
add disabled=yes dst-address=172.16.0.205
/ip upnp
set enabled=yes
/ip upnp interfaces
add type=internal
add interface=INTERNET type=external
/lcd
set time-interval=hour
/mpls ldp
set enabled=yes lsr-id=10.255.255.1 transport-address=10.255.255.1
/mpls ldp interface
add interface=LoopBack
add interface=Room-PTP-Room9
add interface=Room-PTP-Room5
add disabled=yes interface=Room-PTP-Room2
add interface=ether4
/ppp aaa
set interim-update=1m use-radius=yes
/ppp profile
add local-address=*6 name=pppoe-Profile-3 remote-address=*6 use-compression=\
    no use-encryption=no use-mpls=yes
/ppp secret
add name=Markvpn profile=VPN

/radius
add address=127.0.0.1 called-id=7.8.6.5 disabled=yes service=ppp
add address=127.0.0.1 disabled=yes service=ppp timeout=2s
add address=207.246.119.3 disabled=yes service=ppp,login
add address=10.200.0.74 disabled=yes service=ppp,login
add address=80.240.21.118 disabled=yes service=ppp
add address=splynxIP service=ppp src-address=197.100.8.2
/radius incoming
set accept=yes
/routing ospf interface
add interface=Room-PTP-Room5 network-type=point-to-point
add interface=Room-PTP-Room2 network-type=point-to-point
add comment=site4 interface=ether8 network-type=point-to-point
add disabled=yes interface=Management-Bridge network-type=broadcast passive=\
    yes
add disabled=yes network-type=point-to-point
add interface=Room-PTP-Room9 network-type=point-to-point
add disabled=yes interface=bridge4 network-type=point-to-point
add interface=ether5 network-type=point-to-point
add interface=ether4 network-type=point-to-point
add interface=site2 network-type=point-to-point
add interface=bridge5 network-type=point-to-point
add interface=bridge1 network-type=point-to-point
/routing ospf nbma-neighbor
add address=10.200.0.4 poll-interval=20s
/routing ospf network
add area=backbone network=10.255.255.1/32
add area=backbone network=10.200.0.0/29
add area=backbone network=172.16.0.0/22
add area=backbone network=10.200.0.24/29
add area=backbone network=10.200.0.72/29
add area=backbone network=10.200.0.104/29
add area=backbone network=10.200.0.216/29
add area=backbone network=10.200.0.224/29
add area=backbone disabled=yes network=10.0.101.8/29
add area=backbone disabled=yes network=10.231.0.0/24
add area=backbone network=10.216.0.0/29
add area=backbone network=10.201.0.0/29
add area=backbone network=10.213.0.8/29
/snmp
set contact=Mark enabled=yes location=ITECH trap-community=ITECH \
    trap-generators=interfaces,temp-exception trap-interfaces=all \
    trap-version=2
/system clock
set time-zone-autodetect=no time-zone-name=Africa/Johannesburg
/system identity
set name=ITECHCore
/system logging
add disabled=yes prefix=radius topics=radius
add disabled=yes topics=pppoe
add disabled=yes topics=debug
add disabled=yes topics=pptp
add disabled=yes topics=debug
add disabled=yes topics=pppoe
add prefix=Acc topics=account
/system ntp client
set enabled=yes primary-ntp=41.79.80.34 secondary-ntp=196.4.160.4

Well that config is way beyond my level of comprehension.

All I can say is that this reference is the bible…
http://forum.mikrotik.com/t/using-routeros-to-vlan-your-network/126489/1

My general comments are
A. do not use a bridge to give out DHCP. (the only thing that should reference bridge as an interface should be the vlans themselves.)
B. do not use default vlan1

With such a complicate setup, I would try to keep things as clean and as simple as possible (may mean reducing the number of bridges).

Sounds like ether2 and ether2 are trunk ports.
So clearly identify which are trunk ports and which are access ports and config them accordingly in both interface bridge port and interface bridge vlan configs

Last comment: I am truly impressed. I find it difficult not to have errors on a very small config, let alone the monster you have created!!