# dec/28/2021 16:53:28 by RouterOS 6.48.5
#
# model = RouterBOARD 3011UiAS
/interface bridge
add name=bri-lan-cdama
add name=bri-lan-dv
add admin-mac=00:05:5D:D3:C8:9C auto-mac=no fast-forward=no mtu=1500 name=\
bri-wan-sbb protocol-mode=none
/interface ethernet
set [ find default-name=ether1 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-full name=eth1-sbb-wlnk
set [ find default-name=ether2 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-full name=eth2
set [ find default-name=ether3 ] name=eth3-cdama-lan
set [ find default-name=ether4 ] name=eth4-cdama-11-llnk
set [ find default-name=ether5 ] name=eth5
set [ find default-name=ether6 ] name=eth6-dn-soba-wifi
set [ find default-name=ether7 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-full name=eth7-sp-soba-wifi
set [ find default-name=ether8 ] name=eth8-sp-soba-tv
set [ find default-name=ether9 ] name=eth9-rsoba-switch
set [ find default-name=ether10 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-full name=eth10
/interface list
add exclude=dynamic name=discover
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=dhcp_server ranges=10.16.0.200-10.16.0.254
add name=cdama.dv-pool ranges=10.16.1.101-10.16.1.151
add name=cdama.lan1-pool ranges=10.16.6.81-10.16.6.94
/ip dhcp-server
add add-arp=yes address-pool=cdama.dv-pool always-broadcast=yes disabled=no \
interface=bri-lan-dv lease-time=5m name=cdama-dv-dhcp
add address-pool=cdama.lan1-pool always-broadcast=yes disabled=no interface=\
bri-lan-cdama name=cdama.lan1-pool
/queue simple
add disabled=yes max-limit=1G/1G name=#SBB target=bri-wan-sbb
add disabled=yes max-limit=100M/100M name=queue1 target=eth2
add disabled=yes max-limit=128k/32k name=adsl-p2p parent=#SBB
/queue interface
set eth1-sbb-wlnk queue=ethernet-default
set eth2 queue=ethernet-default
/queue simple
add dst=bri-wan-sbb max-limit=1G/1G name=#WAN queue=default/default target=""
add max-limit=1G/1G name="DV [LS]" parent=#WAN priority=2/2 queue=\
default/default target=10.16.1.0/24 total-priority=2 total-queue=\
ethernet-default
add dst=eth7-sp-soba-wifi max-limit=1G/1G name=#LNK-CDAMA-11 queue=\
default/default target="" total-queue=ethernet-default
add dst=eth2 max-limit=1G/1G name=#LNK-CDAMA-21 queue=default/default target=\
"" total-queue=ethernet-default
add dst=bri-wan-sbb max-limit=1M/1M name=everything-else queue=\
default/default target="" total-queue=default
/system logging action
set 0 memory-lines=100
set 1 disk-lines-per-file=100
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
sword,web,sniff,sensitive,api,romon,dude,tikapp"
/dude
set enabled=yes
/interface bridge port
add bridge=bri-wan-sbb interface=eth1-sbb-wlnk
add bridge=bri-lan-dv interface=eth6-dn-soba-wifi
add bridge=bri-lan-dv interface=eth8-sp-soba-tv
add bridge=bri-lan-dv interface=eth9-rsoba-switch
add bridge=bri-lan-dv interface=eth10
add bridge=bri-lan-dv interface=eth7-sp-soba-wifi
add bridge=bri-lan-cdama interface=eth3-cdama-lan
/ip firewall connection tracking
set generic-timeout=1m icmp-timeout=1m tcp-close-timeout=1m \
tcp-close-wait-timeout=1m tcp-established-timeout=1m \
tcp-fin-wait-timeout=1m tcp-last-ack-timeout=30s \
tcp-syn-received-timeout=1m tcp-syn-sent-timeout=1m \
tcp-time-wait-timeout=1m udp-stream-timeout=1m udp-timeout=1m
/ip neighbor discovery-settings
set discover-interface-list=all
/ip settings
set rp-filter=loose
/interface detect-internet
set detect-interface-list=all
/interface list member
add interface=eth2 list=discover
/interface pptp-server server
set default-profile=default enabled=yes max-mru=1460 max-mtu=1460
/ip address
add address=10.16.6.34/29 comment="stari lan ruter" disabled=yes interface=\
eth2 network=10.16.6.32
add address=10.16.2.6/30 comment=wiif-krov interface=eth4-cdama-11-llnk \
network=10.16.2.4
add address=89.216.114.92/26 disabled=yes interface=bri-wan-sbb network=\
89.216.114.64
add address=10.16.0.1/24 comment=server-lan interface=bri-lan-dv network=\
10.16.0.0
add address=10.16.1.1/24 comment=dv-lan interface=bri-lan-dv network=\
10.16.1.0
add address=10.16.6.65/27 interface=bri-lan-cdama network=10.16.6.64
add address=192.168.100.9/24 interface=bri-wan-sbb network=192.168.100.0
/ip dhcp-client
add default-route-distance=2 disabled=no interface=bri-wan-sbb use-peer-dns=\
no use-peer-ntp=no
add default-route-distance=2 interface=eth1-sbb-wlnk use-peer-dns=no \
use-peer-ntp=no
/ip dhcp-server config
set store-leases-disk=immediately
add address=10.16.6.78 comment="Precistac vazduha Xiaomi" mac-address=\
04:CF:8C:AB:09:0C server=cdama.lan1-pool
/ip dhcp-server network
add address=10.16.0.0/24 dns-server=10.16.0.1 gateway=10.16.0.1
add address=10.16.1.0/24 dns-server=10.16.1.1 gateway=10.16.1.1
add address=10.16.6.64/27 dns-server=10.16.6.65 gateway=10.16.6.65
/ip dns
set allow-remote-requests=yes cache-size=4096KiB servers=1.1.1.1,1.0.0.1
/ip dns static
add address=10.16.0.1 name=lan-dns
/ip firewall filter
add action=drop chain=input comment="Drop invalid connections" \
connection-state=invalid disabled=yes log-prefix=\
"Dropped invalid connection"
add action=drop chain=forward comment="Drop invalid connections" \
connection-state=invalid disabled=yes log-prefix=\
"Dropped invalid connection"
add action=accept chain=input dst-port=22 in-interface=bri-wan-sbb protocol=\
tcp src-address-list=allow_ssh
add action=add-src-to-address-list address-list=ssh_conn_level_0 \
address-list-timeout=1m chain=input connection-state=new dst-port=22 \
protocol=tcp
add action=add-src-to-address-list address-list=ssh_conn_level_1 \
address-list-timeout=1m chain=input connection-state=new dst-port=22 \
protocol=tcp src-address-list=ssh_conn_level_0
add action=add-src-to-address-list address-list=ssh_conn_level_2 \
address-list-timeout=1h10m chain=input connection-state=new dst-port=22 \
protocol=tcp src-address-list=ssh_conn_level_1
add action=drop chain=input connection-state=new dst-port=22 log=yes \
log-prefix="Dropped brute force to SSL" protocol=tcp src-address-list=\
ssh_conn_level_2
add action=drop chain=input comment="block public DNS" dst-port=53 \
in-interface=bri-wan-sbb log=yes protocol=tcp
add action=drop chain=input comment="block public DNS" dst-port=53 \
in-interface=bri-wan-sbb log=yes protocol=udp
add action=reject chain=input comment="Drop banned addresses by list" \
log-prefix="banned by list" reject-with=icmp-host-prohibited \
src-address-list=banned-addresses
add action=reject chain=forward comment="Drop banned addresses by list" \
log-prefix="banned by list" reject-with=icmp-host-prohibited \
src-address-list=banned-addresses
add action=add-src-to-address-list address-list=new_connections \
address-list-timeout=none-dynamic chain=input comment=\
"Detect new connections" connection-state=new disabled=yes in-interface=\
bri-wan-sbb nth=2,1
add action=log chain=input disabled=yes log=yes log-prefix=\
"in new connections list" src-address-list=new_connections
add action=accept chain=input comment="Allow established connections" \
connection-state=established
add action=accept chain=input comment="Allow related connections" \
connection-state=related
add action=accept chain=input comment="Allow UDP" protocol=udp
add action=accept chain=input comment="Allow ICMP Ping" protocol=icmp
add action=accept chain=input comment="Allow access from address list" \
src-address-list=allow_access_from
add action=accept chain=input comment="Allow access to MT" src-address-list=\
access_to_mt
add action=accept chain=forward dst-port=25 in-interface=bri-wan-sbb \
protocol=tcp
add action=accept chain=forward dst-port=25 log=yes log-prefix=\
"Allowed outgoing SMTP" out-interface=bri-wan-sbb protocol=tcp \
src-address-list=all-smtp-allowed
add action=drop chain=forward comment=\
"Drop outgoing SMTP not allowed by list" dst-port=25 log=yes log-prefix=\
"Drop outgoing SMTP not allowed by list" out-interface=bri-wan-sbb \
protocol=tcp src-address-list=!all-smtp-allowed
add action=drop chain=forward comment="Drop all other outgoing SMTP" \
disabled=yes dst-port=25 log=yes log-prefix=\
"Drop all other outgoing SMTP" protocol=tcp
add action=drop chain=forward comment="Microsoft Networking is disallowed" \
dst-port=135-139,445 protocol=tcp
add action=drop chain=forward dst-port=135-139,445 protocol=udp
add action=accept chain=forward in-interface=bri-wan-sbb
add action=accept chain=forward out-interface=bri-wan-sbb
add action=accept chain=forward dst-address-list=dst_allowed_to_all
add action=accept chain=forward src-address-list=dst_allowed_to_all
add action=accept chain=forward dst-address-list=licenced
add action=accept chain=forward comment="Allow connections to allowed sites" \
dst-address-list=dst_allowed_to_all
add action=log chain=forward comment="Drop everything else" log-prefix=\
"drop other forward"
add action=drop chain=forward
/ip firewall mangle
/ip firewall nat
add action=masquerade chain=srcnat comment="privremena maskarada svega" \
log-prefix=masquarade out-interface=bri-wan-sbb
add action=dst-nat chain=dstnat dst-address-list=dst_nat dst-port=25,110,143 \
in-interface=bri-wan-sbb protocol=tcp to-addresses=10.16.1.10
add action=dst-nat chain=dstnat comment=SSL dst-address-list=dst_nat \
dst-port=443,465,993,995,587 in-interface=bri-wan-sbb protocol=tcp \
to-addresses=10.16.1.10
add action=dst-nat chain=dstnat comment=DC++ dst-address-list=dst_nat \
dst-port=411 in-interface=bri-wan-sbb protocol=tcp to-addresses=\
10.16.1.10
add action=dst-nat chain=dstnat comment="HTTP to 10.16.0.11" \
dst-address-list=dst_nat dst-port=80 in-interface=bri-wan-sbb log-prefix=\
www protocol=tcp to-addresses=10.16.1.10
add action=dst-nat chain=dstnat comment="Chia to 10.16.0.11" \
dst-address-list=dst_nat dst-port=8444 in-interface=bri-wan-sbb \
log-prefix=www protocol=tcp to-addresses=10.16.1.10
add action=dst-nat chain=dstnat comment="FTP/SFTP to 10.16.0.11" \
dst-address-list=dst_nat dst-port=21,990 in-interface=bri-wan-sbb \
protocol=tcp to-addresses=10.16.1.10
add action=dst-nat chain=dstnat comment="FTP passive ports to 10.16.0.11" \
dst-address-list=dst_nat dst-port=2221-2231 in-interface=bri-wan-sbb \
protocol=tcp to-addresses=10.16.1.10
add action=dst-nat chain=dstnat comment=HTTP dst-address-list=dst_nat \
dst-port=88 in-interface=bri-wan-sbb protocol=tcp to-addresses=10.16.1.10 \
to-ports=80
add action=dst-nat chain=dstnat comment=cluster.uzice.net dst-address-list=\
dst_nat dst-port=7373 in-interface=bri-wan-sbb protocol=tcp to-addresses=\
10.16.1.10
add action=dst-nat chain=dstnat comment=cluster.uzice.net dst-address-list=\
dst_nat dst-port=3608 in-interface=bri-wan-sbb protocol=tcp to-addresses=\
10.16.1.10
add action=dst-nat chain=dstnat comment=HTTP dst-address-list=dst_nat \
dst-port=90 in-interface=bri-wan-sbb protocol=tcp to-addresses=10.16.1.10 \
to-ports=90
add action=dst-nat chain=dstnat comment=SVN dst-address-list=dst_nat \
dst-port=8443 in-interface=bri-wan-sbb protocol=tcp to-addresses=\
10.16.1.10
add action=dst-nat chain=dstnat comment=CVS dst-port=2401 in-interface=\
bri-wan-sbb protocol=tcp to-addresses=10.16.1.10
add action=dst-nat chain=dstnat comment=eQSO dst-address-list=dst_nat \
dst-port=10024 in-interface=bri-wan-sbb protocol=tcp to-addresses=\
10.16.1.11
add action=dst-nat chain=dstnat comment="VOIP HAM RADIO" dst-address-list=\
dst_nat dst-port=5060 in-interface=bri-wan-sbb protocol=tcp to-addresses=\
10.16.1.11
add action=dst-nat chain=dstnat comment="VOIP HAM RADIO" dst-address-list=\
dst_nat dst-port=5060 in-interface=bri-wan-sbb protocol=udp to-addresses=\
10.16.1.11
add action=dst-nat chain=dstnat comment="VOIP HAM RADIO" dst-address-list=\
dst_nat dst-port=4000-4019 in-interface=bri-wan-sbb protocol=udp \
to-addresses=10.16.1.11
add action=dst-nat chain=dstnat comment="VOIP HAM RADIO" dst-address-list=\
dst_nat dst-port=4000-4019 in-interface=bri-wan-sbb protocol=tcp \
to-addresses=10.16.1.11
add action=dst-nat chain=dstnat comment="AnyDesk to 10.16.1.11" \
dst-address-list=dst_nat dst-port=7070 in-interface=bri-wan-sbb log=yes \
protocol=tcp to-addresses=10.16.1.11
add action=dst-nat chain=dstnat comment="AnyDesk to 10.16.0.11" \
dst-address-list=dst_nat dst-port=7071 in-interface=bri-wan-sbb log=yes \
protocol=tcp to-addresses=10.16.0.11
add action=dst-nat chain=dstnat comment="EchoLink Pedja" dst-address-list=\
dst_nat dst-port=5198,5199 in-interface=bri-wan-sbb protocol=udp \
to-addresses=10.16.1.11
add action=dst-nat chain=dstnat comment="Skype to 10.16.1.11" dst-port=1025 \
in-interface=bri-wan-sbb protocol=tcp to-addresses=10.16.1.11 to-ports=\
1024
add action=dst-nat chain=dstnat comment=\
"Port 31000 dst-nat to 10.16.1.11 (BasCelik)" dst-port=31000 \
in-interface=bri-wan-sbb protocol=tcp to-addresses=10.16.1.11 to-ports=\
31000
add action=dst-nat chain=dstnat comment="Winbox to 10.16.0.1" dst-port=8293 \
in-interface=bri-wan-sbb protocol=tcp to-addresses=10.16.0.1 to-ports=\
8292
add action=dst-nat chain=dstnat comment="Winbox to 10.16.2.5" dst-port=8294 \
in-interface=bri-wan-sbb protocol=tcp to-addresses=10.16.2.5 to-ports=\
8291
add action=dst-nat chain=dstnat comment=IPIP dst-address-list=dst_nat \
in-interface=bri-wan-sbb protocol=ipip to-addresses=10.16.6.17
/ip route
add distance=5 gateway=89.216.114.65 routing-mark=to-sbb
add distance=2 gateway=89.216.114.65
add distance=1 dst-address=10.16.0.0/16 gateway=10.16.6.33
add distance=1 dst-address=10.31.0.0/16 gateway=10.16.6.33 scope=255
add distance=1 dst-address=10.50.10.0/24 gateway=eth2 scope=255
add distance=1 dst-address=192.168.100.0/24 gateway=bri-wan-sbb pref-src=\
192.168.100.10 scope=10
/ip ssh
set allow-none-crypto=yes forwarding-enabled=remote
/ipv6 nd
set [ find default=yes ] advertise-dns=no
/routing ospf network
add area=backbone network=10.16.0.0/16
/system identity
set name=IDR
/system logging
add topics=watchdog
add topics=e-mail
add topics=script
add prefix=pptp topics=pptp
add topics=account
/system ntp client
set enabled=yes primary-ntp=109.245.222.66 secondary-ntp=217.24.20.5
/system ntp server
set broadcast=yes enabled=yes multicast=yes
/system package update
set channel=long-term