Attached
# may/27/2022 18:31:08 by RouterOS 7.2.3
# software id = TRGR-BPA8
#
# model = RB760iGS
# serial number = A36A0B8BDDB0
/caps-man channel
add band=2ghz-b/g control-channel-width=20mhz name=24g
add band=5ghz-a/n/ac name=5g
/interface bridge
add admin-mac=C4:AD:34:E6:00:07 auto-mac=no comment=defconf \
ingress-filtering=no name=bridge vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] arp=proxy-arp l2mtu=1598 name=ether1-WAN
set [ find default-name=ether2 ] name=ether2-SG1024DE
set [ find default-name=ether4 ] name=ether4-SG108PE
set [ find default-name=ether5 ] name=ether5-RB951
/interface wireguard
add listen-port=13231 mtu=1420 name=wireguard1
add listen-port=13232 mtu=1420 name=wireguard2
/interface vlan
add interface=bridge name=vlan10-Public vlan-id=10
add interface=bridge name=vlan11-Adam vlan-id=11
add interface=bridge name=vlan20-AP vlan-id=20
add interface=bridge name=vlan30-IOT vlan-id=30
/caps-man security
add authentication-types=wpa2-psk name=ap
add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm \
name=iot
/caps-man configuration
add channel=24g country=poland datapath.bridge=bridge .local-forwarding=yes \
.vlan-id=20 .vlan-mode=use-tag installation=indoor name=public \
security=ap ssid=public
add channel=24g country=poland datapath.bridge=bridge .local-forwarding=yes \
.vlan-id=30 .vlan-mode=use-tag installation=indoor name=iot security=iot \
ssid=oz14iot
add channel=5g country=poland datapath.bridge=bridge .local-forwarding=yes \
.vlan-id=20 .vlan-mode=use-tag installation=indoor name=public-5g \
security=ap ssid="public 5G"
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface lte apn
set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=pool-LAN ranges=10.1.1.190-10.1.1.199
add name=pool-AP ranges=10.1.20.100-10.1.20.253
add name=pool-Public ranges=10.1.10.200-10.1.10.253
add name=pool-IOT ranges=10.1.30.100-10.1.30.253
add name=dhcp_pool5 ranges=10.1.11.10-10.1.11.19
/ip dhcp-server
add address-pool=pool-LAN interface=bridge name=dhcp-LAN
add address-pool=pool-Public interface=vlan10-Public name=dhcp-Public
add address-pool=pool-AP interface=vlan20-AP name=dhcp-AP
add address-pool=pool-IOT interface=vlan30-IOT name=dhcp-IOT
add address-pool=dhcp_pool5 interface=vlan11-Adam name=dhcp-Adam
/port
set 0 name=serial0
/routing bgp template
set default disabled=no output.network=bgp-networks
/routing ospf instance
add disabled=no name=default-v2
/routing ospf area
add disabled=yes instance=default-v2 name=backbone-v2
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
sword,web,sniff,sensitive,api,romon,dude,rest-api"
/caps-man manager
set enabled=yes
/caps-man provisioning
add action=create-dynamic-enabled hw-supported-modes=a master-configuration=\
public-5g
add action=create-dynamic-enabled hw-supported-modes=g master-configuration=\
public slave-configurations=iot
/interface bridge port
add bridge=bridge ingress-filtering=no interface=ether3
add bridge=bridge ingress-filtering=no interface=ether4-SG108PE
add bridge=bridge ingress-filtering=no interface=ether5-RB951
add bridge=bridge interface=ether2-SG1024DE
/ip firewall connection tracking
set enabled=yes
/ip neighbor discovery-settings
set discover-interface-list=LAN
/ip settings
set accept-source-route=yes
/ipv6 settings
set disable-ipv6=yes max-neighbor-entries=8192
/interface bridge vlan
add bridge=bridge tagged=bridge,ether4-SG108PE,ether5-RB951,ether2-SG1024DE \
vlan-ids=10,20,30,11
/interface list member
add comment=defconf interface=bridge list=LAN
add interface=vlan20-AP list=LAN
add interface=vlan30-IOT list=LAN
add interface=vlan10-Public list=LAN
add interface=ether1-WAN list=WAN
add interface=wireguard1 list=LAN
add interface=vlan11-Adam list=LAN
add interface=wireguard2 list=LAN
/ip address
add address=10.1.1.254/24 interface=bridge network=10.1.1.0
add address=10.1.20.254/24 interface=vlan20-AP network=10.1.20.0
add address=10.1.10.254/24 interface=vlan10-Public network=10.1.10.0
add address=10.1.30.254/24 interface=vlan30-IOT network=10.1.30.0
add address=172.16.0.1/29 interface=wireguard1 network=172.16.0.0
add address=addrE/29 comment="ELIM (piwnica)" interface=ether1-WAN \
network=ISP_NETWORK
add address=addrA/29 comment=ANCHORAGE interface=ether1-WAN network=\
ISP_NETWORK
add address=addrB/29 comment=BUCKLAND interface=ether1-WAN network=\
ISP_NETWORK
add address=addrC/29 comment=COLDBAY interface=ether1-WAN network=\
ISP_NETWORK
add address=addrD/29 comment=DEERING interface=ether1-WAN network=\
ISP_NETWORK
add address=10.1.11.254/24 interface=vlan11-Adam network=10.1.11.0
add address=172.16.11.1/29 interface=wireguard2 network=172.16.11.0
/ip cloud
set ddns-enabled=yes
/ip dhcp-client
add comment=defconf disabled=yes interface=ether1-WAN
/ip dhcp-server network
add address=10.1.1.0/24 comment=LAN dns-server=10.1.1.254 domain=oz gateway=\
10.1.1.254 ntp-server=10.1.1.254
add address=10.1.10.0/24 comment="Public servers" dns-server=10.1.10.254 \
domain=public gateway=10.1.10.254
add address=10.1.11.0/24 gateway=10.1.11.254
add address=10.1.20.0/24 comment=AP dns-server=10.1.20.254 domain=wifi \
gateway=10.1.20.254
add address=10.1.30.0/24 comment=IOT dns-server=10.1.30.254 domain=iot \
gateway=10.1.30.254
/ip dns
set allow-remote-requests=yes servers=8.8.8.8,8.8.4.4
/ip firewall address-list
add address=addrA list=INEA
add address=addrB list=INEA
add address=addrC list=INEA
add address=addrD list=INEA
add address=addrE list=INEA
add address=10.1.1.0/24 disabled=yes list=LANs
add address=10.1.10.0/24 disabled=yes list=LANs
add address=10.1.20.0/24 disabled=yes list=LANs
add address=10.1.30.0/24 disabled=yes list=LANs
/ip firewall filter
add action=accept chain=input comment="defconf: accept ICMP" \
dst-address-list=INEA protocol=icmp
add action=accept chain=forward comment="Accept DST NAT" \
connection-nat-state=dstnat connection-state="" disabled=yes \
in-interface=ether1-WAN
add action=accept chain=forward comment="Accept SRC NAT" \
connection-nat-state=srcnat connection-state="" disabled=yes
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
connection-state=established,related hw-offload=yes
add action=accept chain=forward comment=\
"defconf: accept established,related, untracked" connection-state=\
established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
connection-state=invalid log=yes log-prefix=INVALID
add action=drop chain=forward comment=\
"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
connection-state=new in-interface=ether1-WAN log=yes log-prefix=INVALID
add action=accept chain=input comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
invalid log=yes log-prefix=INVALID
add action=accept chain=input comment="SSH HEXs" dst-address=addrE \
dst-port=22222 protocol=tcp
add action=accept chain=input comment=WireGuard dst-address=addrE \
dst-port=13231,13232 protocol=udp
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
in-interface-list=!LAN log=yes log-prefix="NOT LAN"
/ip firewall nat
add action=src-nat chain=srcnat comment="Anchorage SRC (email)" log-prefix=\
"ANCHORAGE SRC" out-interface=ether1-WAN src-address=10.1.10.234 \
to-addresses=addrA
add action=src-nat chain=srcnat comment="Buckland SRC (eto)" log-prefix=\
"BUCKLAND SRC" out-interface=ether1-WAN src-address=10.1.10.235 \
to-addresses=addrB
add action=src-nat chain=srcnat comment="Coldbay SRC (Adam)" disabled=yes \
out-interface=ether1-WAN src-address=10.1.11.0/24 to-addresses=\
addrC
add action=src-nat chain=srcnat comment="Deering SRC (git)" log-prefix=\
"DEERING SRC" out-interface=ether1-WAN src-address=10.1.10.237 \
to-addresses=addrD
add action=src-nat chain=srcnat comment="LAN SRC" out-interface=ether1-WAN \
src-address=10.1.1.0/24 to-addresses=addrA
add action=src-nat chain=srcnat comment="LAN SRC" out-interface=\
ether1-WAN src-address=10.1.10.0/24 to-addresses=addrB
add action=src-nat chain=srcnat comment="LAN SRC" out-interface=ether1-WAN \
src-address=10.1.20.0/24 to-addresses=addrE
add action=masquerade chain=srcnat comment="defconf: masquerade" disabled=yes \
out-interface=ether1-WAN
add action=dst-nat chain=dstnat comment="Anchorage E-mail" dst-address=\
addrA dst-port=80,443,25,587,110,143,993,995 protocol=tcp \
to-addresses=10.1.10.234
add action=dst-nat chain=dstnat comment="Anchorage SSH" dst-address=\
addrA dst-port=22222 protocol=tcp to-addresses=10.1.10.234 \
to-ports=22
add action=dst-nat chain=dstnat comment="Buckland HTTPS" dst-address=\
addrB dst-port=80,443 log-prefix="BUCKLAND DST" protocol=tcp \
to-addresses=10.1.10.235
add action=dst-nat chain=dstnat comment="Buckland SSH" dst-address=\
addrB dst-port=22222 protocol=tcp to-addresses=10.1.10.235 \
to-ports=22
add action=dst-nat chain=dstnat comment="Coldbay Adam" dst-address=\
addrC dst-port=8444 protocol=tcp to-addresses=10.1.11.10
add action=dst-nat chain=dstnat comment="Coldbay Adam" dst-address=\
addrC dst-port=22,80,443,1922,25565 protocol=tcp to-addresses=\
10.1.11.11
add action=dst-nat chain=dstnat comment="Deering GIT, HTTPS" dst-address=\
addrD dst-port=22,80 log-prefix="DEERING DST" protocol=tcp \
to-addresses=10.1.10.237
add action=dst-nat chain=dstnat comment="Deering GIT, HTTPS" dst-address=\
addrD dst-port=443 log-prefix="DEERING DST" protocol=tcp \
to-addresses=10.1.10.237 to-ports=443
add action=dst-nat chain=dstnat comment=CCTV disabled=yes dst-port=8000 \
in-interface=*9 protocol=tcp to-addresses=10.1.10.200 to-ports=8000
add action=dst-nat chain=dstnat comment="R720 PVE webui" disabled=yes \
dst-port=38006 in-interface=*9 protocol=tcp to-addresses=10.1.1.11 \
to-ports=8006
add action=dst-nat chain=dstnat comment="Transmission TCP" disabled=yes \
dst-address=addrE dst-port=51413,59091 protocol=tcp \
to-addresses=10.1.10.2
add action=dst-nat chain=dstnat comment="Transmission UDP" disabled=yes \
dst-address=addrE dst-port=51413 protocol=udp to-addresses=\
10.1.10.2
add action=dst-nat chain=dstnat comment="Elim TRAEFIK" dst-address=\
addrE dst-port=80 in-interface=ether1-WAN protocol=tcp \
to-addresses=10.1.10.3 to-ports=8088
add action=dst-nat chain=dstnat comment="Elim TRAEFIK" dst-address=\
addrE dst-port=443 in-interface=ether1-WAN protocol=tcp \
to-addresses=10.1.10.3 to-ports=8443
/ip firewall service-port
set ftp disabled=yes
/ip route
add disabled=yes distance=1 dst-address=10.3.10.0/24 gateway=172.16.0.3 \
pref-src="" routing-table=main scope=30 suppress-hw-offload=no \
target-scope=10
add disabled=yes dst-address=10.2.10.0/24 gateway=172.16.0.2
add disabled=yes distance=1 dst-address=10.2.30.0/24 gateway=172.16.0.2 \
pref-src="" routing-table=main scope=30 suppress-hw-offload=no \
target-scope=10
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=ISP_GW \
pref-src=0.0.0.0 routing-table=main scope=30 suppress-hw-offload=no \
target-scope=10
/ip service
set telnet disabled=yes
set ssh port=22222
/system clock
set time-zone-name=Europe/Warsaw
/system logging
add topics=caps,debug
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
/tool romon
set enabled=yes
export.rsc (11.8 KB)