Hello
for tests I created a vlan for my adsl2 connection (lte 4g)
no problem however I lost 50 percent of my speed:
vlan 15mbs
without vlan 30 mbs
is this normal or did i forget to do something
thank you
have a nice week end
Hello
for tests I created a vlan for my adsl2 connection (lte 4g)
no problem however I lost 50 percent of my speed:
vlan 15mbs
without vlan 30 mbs
is this normal or did i forget to do something
thank you
have a nice week end
As you didn’t write much about what you did (where does vlan come in the picture) and what you did write doesn’t make much sense (adsl2 and lte 4g have nothing in common), it’s extremely hard to comment.
Well 50% is significant and as MKX pointed out, with .01% of the information needed to help, there is probably a .001% chance of us being able to solve the issues.
Meanwhile enjoy this theory (as it is as close to solving your problems as .001%) by Anne Elk and thats Anne spelled with an E.
https://www.youtube.com/watch?v=hKc_1gc1pLg
![]()
Hello again
actually not enough, sorry.
I have:
-a routeuros crs125:
ip lan 192.168.2.0/24
ip wan 192.168.1.2 (adsl router in 192.168.1.254)
ip wan2 (lte mikrotik) 192.168.88.251 because my adsl speed is not high (long live France)
router ip 4g 192.168.88.1
with this configuration my speed on the 4g is 30mbs.
for personal tests, I created a vlan 20 on my crs router and on my switch in my office (a crs configure as a switch so no firewall, ect..just a bridge with the ports in it)
config:
bridge:
"0 R name = “br” mtu = auto actual-mtu = 1500 l2mtu = 65535 arp = enabled arp-timeout = auto
mac-address = 82: DF: 30: BF: 81: 57 protocol-mode = rstp fast-forward = yes
igmp-snooping = no auto-mac = yes aging-time = 5m priority = 0x8000
max-message-age = 20s forward-delay = 15s transmit-hold-count = 6
vlan-filtering = no dhcp-snooping = no
1 R name = “br-lan” mtu = auto actual-mtu = 1500 l2mtu = 1588 arp = enabled
arp-timeout = auto mac-address = 64: D1: 54: F9: EF: A6 protocol-mode = rstp
fast-forward = yes igmp-snooping = no auto-mac = yes ageing-time = 5m
priority = 0x8000 max-message-age = 20s forward-delay = 15s
transmit-hold-count = 6 vlan-filtering = no dhcp-snooping = no
2 R name = “br-vlan20” mtu = auto actual-mtu = 1500 l2mtu = 1584 arp = enabled
arp-timeout = auto mac-address = 64: D1: 54: F9: EF: A4 protocol-mode = rstp
fast-forward = yes igmp-snooping = no auto-mac = yes ageing-time = 5m
priority = 0x8000 max-message-age = 20s forward-delay = 15s
transmit-hold-count = 6 vlan-filtering = no dhcp-snooping = no"
Ports:
“0 H ether1 br-lan yes 1 0x 10 10 none
1 H ether2 br-lan yes 1 0x 10 10 none
2 vlan20-eth1 br-vlan20 1 0x 10 10 none
3 I H ether7 br-vlan20 yes 1 0x 10 10 none
4 I H ether5 br-lan yes 1 0x 10 10 none
5 I H ether6 br-lan yes 1 0x 10 10 none
6 bonding1 br-lan yes 1 0x 10 10 none”
on the router crs 125.
vlan 20 eth 20 which is connector to the office switch.
On the mikrotik Lte, there is no vlan.
it has dhcp active and gives ip for vlan 20.
it is on port 7 of my office.
on the router my route its ok.
i hope you can help me .
br
Your description is still not enough for me to understand where VLAN gets into the picture.
Instead of extensive description of CRS125’s configuration you should post ouput of command /export hide-sensitive … additionally describe which ports are used for tests.
BTW, using more than single bridge is sure way to loose HW offload and CRS125’s CPU is no race car. I suggest you to go through this document to learn how things should be done on CRS1xx/CRS2xx switches for maximum performance.
hi,
thank for documents.
MMM MMM KKK TTTTTTTTTTT KKK
MMMM MMMM KKK TTTTTTTTTTT KKK
MMM MMMM MMM III KKK KKK RRRRRR OOOOOO TTT III KKK KKK
MMM MM MMM III KKKKK RRR RRR OOO OOO TTT III KKKKK
MMM MMM III KKK KKK RRRRRR OOO OOO TTT III KKK KKK
MMM MMM III KKK KKK RRR RRR OOOOOO TTT III KKK KKKMikroTik RouterOS 6.46.2 (c) 1999-2020 > http://www.mikrotik.com/
[?] Gives the list of available commands
command [?] Gives help on the command and list of arguments[Tab] Completes the command/word. If the input is ambiguous,
a second [Tab] gives possible options/ Move up to base level
.. Move up one level
/command Use command at the base level
[orabache@Capman-garage] > export /export hide-sensitive
expected end of command (line 1 column >
[orabache@Capman-garage] > /export hide-sensitivemar/01/2020 11:08:17 by RouterOS 6.46.2
software id = V4XF-HAYV
model = CRS125-24G-1S-2HnD
serial number = 786F083D7C15
/interface bridge
add comment=“Interface WAN + vlan 100 freebox” fast-forward=no name=br-Wan
add fast-forward=no name=br-fplayer
add admin-mac=CC:2D:E0:0B:47:95 auto-mac=no comment=defconf name=br-lan
add name=br-vlan-20
add fast-forward=no name=br_domotique
/interface wirelessmanaged by CAPsMAN
channel: 2452/20-Ce/gn(20dBm), SSID: Wifi-Maison, CAPsMAN forwarding
set [ find default-name=wlan1 ] antenna-gain=0 country=no_country_set
frequency-mode=manual-txpower ssid=Capman-garage
/interface ethernet
set [ find default-name=ether2 ] comment=“Ether2 port vlan100” name=
Freeboxplayer speed=100Mbps
set [ find default-name=ether1 ] comment=“Eth1 acces Wan freeboxserveur” name=
Freeboxserveur speed=100Mbps
set [ find default-name=ether3 ] comment=“Interface Lte 4g prise 3” name=
“Ltewan " speed=100Mbps
set [ find default-name=ether4 ] speed=100Mbps
set [ find default-name=ether5 ] speed=100Mbps
set [ find default-name=ether6 ] speed=100Mbps
set [ find default-name=ether7 ] speed=100Mbps
set [ find default-name=ether8 ] speed=100Mbps
set [ find default-name=ether9 ] comment=“Liason grenier” speed=100Mbps
set [ find default-name=ether10 ] comment=“Liason grenier” speed=100Mbps
set [ find default-name=ether11 ] name=“ether11 lte” speed=100Mbps
set [ find default-name=ether12 ] speed=100Mbps
set [ find default-name=ether13 ] speed=100Mbps
set [ find default-name=ether14 ] speed=100Mbps
set [ find default-name=ether15 ] speed=100Mbps
set [ find default-name=ether16 ] speed=100Mbps
set [ find default-name=ether17 ] speed=100Mbps
set [ find default-name=ether18 ] name=ether18-lte speed=100Mbps
set [ find default-name=ether19 ] speed=100Mbps
set [ find default-name=ether20 ] comment=“Bureau olivier prise principale”
speed=100Mbps
set [ find default-name=ether21 ] speed=100Mbps
set [ find default-name=ether22 ] speed=100Mbps
set [ find default-name=ether23 ] speed=100Mbps
set [ find default-name=ether24 ] speed=100Mbps
set [ find default-name=sfp1 ] advertise=10000M-full rx-flow-control=auto
tx-flow-control=auto
/interface vlan
add interface=Freeboxserveur name=ETHER1_VLAN100 vlan-id=100
add interface=Freeboxplayer name=ETHER2_VLAN100 vlan-id=100
add interface=ether20 name=vlan20-eth20 vlan-id=20
/caps-man datapath
add bridge=br_domotique local-forwarding=no name=datapath2
add bridge=br-lan local-forwarding=no name=datapath1
/caps-man security
add authentication-types=wpa2-psk name=SEC-Wifi-maison
add authentication-types=wpa2-psk name=Domotique
/caps-man configuration
add country=france datapath.bridge=br_domotique
datapath.client-to-client-forwarding=no datapath.local-forwarding=no
distance=indoors mode=ap name=Domotique security=Domotique ssid=Domo
add country=france datapath=datapath1 datapath.bridge=br-lan
datapath.client-to-client-forwarding=no datapath.local-forwarding=no
distance=indoors mode=ap name=Maison security=SEC-Wifi-maison ssid=
Wifi-Maison
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
add comment=”;;;;;defconf perso" name=domotique
add name=bureau
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip kid-control
add fri=15h-19h,10h-12h mon=17h-19h,10h-12h name=Angel rate-limit=1M sat=
15h-19h,10h-12h sun=10h-12h,17h-19h thu=15h-19h,10h-12h tue=15h-19h,10h-12h
wed=15h-16h,10h-12h
add disabled=yes fri=9h-22h mon=9h-22h name=eva sat=9h-22h sun=9h-22h thu=
9h-22h tue=9h-22h wed=9h-22h
add disabled=yes fri=9h-22h mon=9h-22h name=kid1 sat=9h-22h sun=9h-22h thu=
9h-22h tue=9h-22h wed=9h-22h
/ip pool
add name=Maison ranges=192.168.2.100-192.168.2.150
add name=Domotique ranges=192.168.3.1-192.168.3.15
/ip dhcp-server
add address-pool=Maison disabled=no interface=br-lan name=Lan-maison
add address-pool=Domotique disabled=no interface=br_domotique name=Domotique
/port
set 1 baud-rate=115200 data-bits=8 flow-control=none name=usb2 parity=none
stop-bits=1
/queue simple
add disabled=yes max-limit=1M/1M name=queue1 target=192.168.2.110/32
/system logging action
set 0 target=disk
set 1 disk-lines-per-file=1
/caps-man access-list
add action=accept allow-signal-out-of-range=10s ap-tx-limit=112000
client-tx-limit=112000 comment=“regalge de la bande passante” disabled=yes
signal-range=-120..120 ssid-regexp=Domo
add action=accept allow-signal-out-of-range=10s disabled=yes signal-range=
-80..120 ssid-regexp=“” time=0s-1d,sun,mon,tue,wed,thu,fri,sat
/caps-man manager
set enabled=yes
/caps-man provisioning
add action=create-dynamic-enabled comment=local master-configuration=Maison
name-format=prefix-identity slave-configurations=Domotique
/interface bridge port
add bridge=br-lan comment=“lan Maison” interface=ether21
add bridge=br-lan comment=“lan Maison” interface=ether22
add bridge=br-lan comment=“lan Maison” interface=ether23
add bridge=br-lan comment=“lan Maison” interface=ether24
add bridge=br-lan comment=“lan Maison” interface=wlan1
add bridge=br-lan comment=“lan Maison” interface=ether15
add bridge=br-lan comment=“lan Maison” interface=ether12
add bridge=br-lan comment=“lan Maison” interface=ether13
add bridge=br-lan comment=“lan Maison” interface=ether14
add bridge=br-lan comment=“lan Maison” interface=ether16
add bridge=br-lan comment=“lan Maison” interface=ether17
add bridge=br-lan comment=“Lan maison” interface=ether19
add bridge=br-fplayer comment=“Vlan freeboxplayer” interface=ETHER1_VLAN100
add bridge=br-Wan interface=Freeboxserveur
add bridge=br-lan comment="Connexion freeboxplayer au lan " interface=
Freeboxplayer
add bridge=br-fplayer comment=“Vlan freeboxplayer” interface=ETHER2_VLAN100
add bridge=br-lan comment=“Lan Maison” interface=ether8
add bridge=br-lan comment=“lan Maison” interface=ether4
add bridge=br-lan comment=“lan Maison” interface=ether5
add bridge=br-lan comment=“lan Maison” interface=ether6
add bridge=br-lan comment=“lan Maison” interface=ether7
add bridge=br-lan comment=“lan Maison” interface=ether10
add bridge=br-lan comment=“lan Maison” interface=ether9
add bridge=br-lan interface=ether20
add bridge=br-vlan-20 interface=vlan20-eth20
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface list member
add comment=defconf interface=br-lan list=LAN
add comment=defconf interface=br-Wan list=WAN
add comment=“pour la domo” interface=br_domotique list=domotique
add interface=ether20 list=bureau
/interface wireless capset bridge=br-lan caps-man-addresses=127.0.0.1 discovery-interfaces=wlan1
enabled=yes interfaces=wlan1
/ip address
add address=192.168.2.1/24 interface=br-lan network=192.168.2.0
add address=192.168.3.1/24 interface=br_domotique network=192.168.3.0
add address=192.168.2.20/24 interface=ether14 network=192.168.2.0
add address=172.16.0.254/16 interface=sfp1 network=172.16.0.0
/ip dhcp-client
add add-default-route=no disabled=no interface=br-Wan use-peer-dns=no
add add-default-route=no disabled=no interface=“Ltewan " use-peer-dns=no
add add-default-route=no disabled=no interface=br-vlan-20 use-peer-dns=no
/ip dhcp-server lease
add address=192.168.2.3 client-id=1:0:1d:73:a3:d:1c mac-address=
00:1D:73:A3:0D:1C server=Lan-maison
add address=192.168.2.5 mac-address=00:24:D4:71:72:BD server=Lan-maison
add address=192.168.2.4 client-id=1:d8:fe:e3:5c:14:68 mac-address=
D8:FE:E3:5C:14:68 server=Lan-maison
add address=192.168.3.7 comment=“Echo bureau olivier” mac-address=
C4:95:00:B2:66:EC server=Domotique
add address=192.168.3.5 client-id=1:50:c7:bf:b6:c4:27 comment=
“Prise tplink salon” mac-address=50:C7:BF:B6:C4:27 server=Domotique
add address=192.168.2.110 client-id=1:88:e9:fe:47:46:a0 mac-address=
88:E9:FE:47:46:A0 server=Lan-maison
add address=192.168.3.12 comment=“Salle de Jeux” mac-address=84:F3:EB:14:C6:32
server=Domotique
add address=192.168.3.4 mac-address=B0:FC:0D:06:FD:69 server=Domotique
add address=192.168.2.100 client-id=1:40:d2:8a:7c:7e:ce mac-address=
40:D2:8A:7C:7E:CE server=Lan-maison
add address=192.168.2.123 mac-address=B0:E1:7E:20:1A:F7 server=Lan-maison
add address=192.168.3.3 comment=amazone mac-address=00:71:47:24:9A:FA server=
Domotique
add address=Maison allow-dual-stack-queue=no block-access=yes mac-address=
00:71:47:24:9A:FA server=Lan-maison
add address=Maison allow-dual-stack-queue=no block-access=yes mac-address=
C4:95:00:B2:66:EC server=Lan-maison
add address=Maison block-access=yes mac-address=B0:FC:0D:06:FD:69 server=
Lan-maison
add address=192.168.2.251 client-id=1:e0:cb:4e:ba:d8:a5 mac-address=
E0:CB:4E:BA:D8:A5 server=Lan-maison
add address=192.168.2.114 client-id=1:14:c9:13:4d:62:c9 mac-address=
14:C9:13:4D:62:C9 server=Lan-maison
add address=192.168.2.104 client-id=1:c8:f6:50:24:28:99 mac-address=
C8:F6:50:24:28:99 server=Lan-maison
add address=192.168.2.108 mac-address=10:BF:48:8D:66:D1 server=Lan-maison
add address=192.168.2.6 client-id=1:b8:27:eb:e0:47:26 mac-address=
B8:27:EB:E0:47:26 server=Lan-maison
add address=192.168.2.115 client-id=1:0:9a:9a:2:5:b7 comment=“camera ip”
mac-address=00:9A:9A:02:05:B7 server=Lan-maison
add address=192.168.3.14 comment=bureau mac-address=B4:E6:2D:5F:8D:C6 server=
Domotique
add address=192.168.3.6 comment=eva mac-address=BC:DD:C2:94:03:4E server=
Domotique
add address=192.168.3.8 mac-address=C4:95:00:2C:89:83 server=Domotique
add address=Maison allow-dual-stack-queue=no block-access=yes mac-address=
C4:95:00:2C:89:83 server=Lan-maison
/ip dhcp-server network
add address=192.168.2.0/24 dns-server=192.168.2.1 gateway=192.168.2.1
add address=192.168.3.0/24 dns-server=192.168.3.1 gateway=192.168.3.1
/ip dns
set allow-remote-requests=yes servers=8.8.8.8
/ip dns static
add address=172.16.0.1 name=workfolders.evanol.fr
add address=172.16.0.1 name=srv-maison.maison.local
add address=192.168.2.99 name=srv2019ess.lab.local
add address=192.168.2.6 name=protecthome.evanol.fr
/ip firewall address-list
add address=192.168.0.0/16 list=Bogon
add address=10.0.0.0/8 list=Bogon
add address=172.16.0.0/12 list=Bogon
add address=127.0.0.0/8 list=Bogon
add address=0.0.0.0/8 list=Bogon
add address=169.254.0.0/16 list=Bogon
add address=192.168.2.0/24 list=Administration
add address=192.168.3.0/24 list=Administration
add address=37.173.114.50 disabled=yes list=Administration
add address=192.168.2.10 list=“withe list rdp”
add address=192.168.2.0/24 list=“withe list rdp”
add address=172.16.0.0/16 list=“withe list rdp”
add address=192.168.88.0/24 list=Administration
add address=172.16.0.0/16 list=Administration
add address=192.168.2.108 list=“mangle freebox pour nat”
add address=172.16.0.1 list=“mangle freebox pour nat”
/ip firewall filter
add action=accept chain=input comment=
“defconf: accept established,related,untracked” connection-state=
established,related,untracked
add action=drop chain=input connection-state=established,related,new disabled=
yes dst-address=8.8.8.8 in-interface-list=all
add action=drop chain=input comment=“defconf: drop invalid” connection-state=
invalid
add action=accept chain=input comment=“CAPSManager filter rules " disabled=yes
dst-port=5246,5247 in-interface=br-lan log=yes log-prefix=“input caps 1”
protocol=udp
add action=accept chain=input comment=“CAPSManager filter rules " disabled=yes
dst-port=5246,5247 in-interface=br-lan log=yes log-prefix=“input caps 1”
protocol=udp
add action=accept chain=input dst-address=127.0.0.1
add action=accept chain=output comment=“cpasman-manager filter rule” dst-port=
5246,5247 log-prefix=“input caps 1” out-interface=br-lan protocol=udp
add action=accept chain=input comment=“cpasman-manager filter rule” dst-port=
5246,5247 in-interface=br-lan log-prefix=“input caps 1” protocol=udp
add action=accept chain=input comment=“defconf: accept ICMP” protocol=icmp
add action=accept chain=input comment=
“defconf: accept to local loopback (for CAPsMAN)” disabled=yes dst-address=
127.0.0.1
add action=accept chain=input in-interface-list=domotique port=53 protocol=tcp
add action=accept chain=input in-interface-list=domotique port=53 protocol=udp
add action=drop chain=input comment=“defconf: drop all not coming from LAN”
disabled=yes in-interface-list=!LAN
add action=accept chain=forward comment=“defconf: accept in ipsec policy”
ipsec-policy=in,ipsec
add action=accept chain=forward comment=“defconf: accept out ipsec policy”
ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment=“defconf: fasttrack”
connection-state=established,related
add action=accept chain=forward comment=
“defconf: accept established,related, untracked” connection-state=
established,related,untracked
add action=drop chain=forward comment=“defconf: drop invalid” connection-state=
invalid
add action=drop chain=forward comment=“defconf: drop all from WAN not DSTNATed”
connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
/ip firewall mangle
add action=mark-routing chain=prerouting comment=“bureau olivier”
connection-state=”” connection-type=”" disabled=yes log-prefix=serveur
new-routing-mark=to-domotique passthrough=yes src-address=192.168.2.116
add action=mark-routing chain=prerouting comment=“routing mark domotique”
new-routing-mark=to-domotique passthrough=yes src-address=192.168.3.0/24
/ip firewall nat
add action=masquerade chain=srcnat comment=“defconf: masquerade”
out-interface-list=WAN
add action=masquerade chain=srcnat out-interface=“Ltewan "
add action=dst-nat chain=dstnat comment=“workfolder vers serveur maison local”
dst-address=172.16.0.1 dst-port=2048 in-interface-list=LAN log=yes
log-prefix=“dossier travail” protocol=tcp to-addresses=172.16.0.1 to-ports=
443
add action=dst-nat chain=dstnat comment=“adblock 2049-443” disabled=yes
dst-address=192.168.2.6 dst-port=443 in-interface-list=WAN log-prefix=
“dossier travail” protocol=tcp to-addresses=192.168.2.6 to-ports=443
add action=dst-nat chain=dstnat comment=” https 192.168.2.6" disabled=yes
dst-port=80 in-interface-list=WAN log=yes log-prefix=guard protocol=tcp
to-addresses=192.168.2.6 to-ports=80
add action=dst-nat chain=dstnat comment=" https 172.16.0.10" disabled=yes
dst-port=53 in-interface-list=WAN log=yes log-prefix=rds protocol=tcp
to-addresses=172.16.0.1 to-ports=53
add action=dst-nat chain=dstnat comment="regle nat " dst-port=2048
in-interface-list=WAN log=yes log-prefix=“direct access exteriru” protocol=
tcp to-addresses=172.16.0.1 to-ports=443
add action=dst-nat chain=dstnat comment="regle nat " dst-port=1194
in-interface-list=WAN log=yes log-prefix=OPENVPN protocol=udp to-addresses=
192.168.2.108 to-ports=1194
/ip kid-control device
add mac-address=A4:67:06:95:02:5E name=ipad user=Angel
add mac-address=C8:F6:50:24:28:99 name=ipadmini user=Angel
add disabled=yes mac-address=B0:E1:7E:20:1A:F7 name=honor user=Angel
/ip route
add disabled=yes distance=1 gateway=192.168.1.254 routing-mark=to-freebox
add disabled=yes distance=1 dst-address=192.168.2.0/24 gateway=br-lan pref-src=
192.168.2.1 routing-mark=to-freebox scope=10
add distance=1 gateway=192.168.1.254 routing-mark=to-domotique
add distance=1 gateway=192.168.1.254
add distance=2 gateway=192.168.88.1add distance=1 dst-address=192.168.10.0/24 gateway=192.168.2.118
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www port=8080
set ssh disabled=yes
set www-ssl address=192.168.88.0/24,192.168.2.0/24 certificate=root-cert port=
444
set winbox address=172.16.0.0/16,192.168.2.0/24
/ip ssh
set allow-none-crypto=yes forwarding-enabled=remote
/lcd
set time-interval=hour
/lcd interface pages
set 0 interfaces=wlan1
/system clock
set time-zone-name=Europe/Paris
/system console
add disabled=no
add disabled=no port=usb2
/system identity
set name=Capman-garage
/system ntp client
set enabled=yes primary-ntp=1.2.3.4 secondary-ntp=5.6.7.8 server-dns-names=
time.google.com,0.pool.ntp.org,1.pool.ntp.org
/system script
add dont-require-permissions=no name=firewall owner=orabache policy=
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=“/ip
_firewall filter\r
\nadd action=accept chain=forward comment="rdp moi" connection-state=""
\\r
\n disabled=yes dst-address=192.168.2.251 log=yes log-prefix="firewall r
dp" \\r
\n src-address=192.168.2.1\r
\nadd action=accept chain=forward comment="test rdp web" connection-nat-st
ate=\\r
\n dstnat log=yes log-prefix="web rdp"\r
\nadd action=drop chain=forward comment="prise tplink" disabled=yes log=ye
s \\r
\n out-interface=br-lan src-address=192.168.2.14\r
\nadd action=drop chain=input comment="drop ssh brute forcers" dst-port=22
_\\r
\n protocol=tcp src-address-list=ssh_blacklist\r
\nadd action=add-src-to-address-list address-list=ssh_blacklist \\r
\n address-list-timeout=1w3d chain=input comment="Black list" \\r
\n connection-state=new dst-port=22 protocol=tcp src-address-list=ssh_sta
ge3\r
\nadd action=add-src-to-address-list address-list=ssh_stage3 \\r
\n address-list-timeout=1m chain=input comment="ssh liste3" \\r
\n connection-state=new dst-port=22 protocol=tcp src-address-list=ssh_sta
ge2\r
\nadd action=add-src-to-address-list address-list=ssh_stage2 \\r
\n address-list-timeout=1m chain=input comment="SSH list2 " \\r
\n connection-state=new dst-port=22 protocol=tcp src-address-list=ssh_sta
ge1\r
\nadd action=add-src-to-address-list address-list=ssh_stage1 \\r
\n address-list-timeout=1m chain=input comment="ssh liste1" \\r
\n connection-state=new dst-port=22 protocol=tcp\r
\nadd action=drop chain=input comment="Block all access to the winbox - exc
ept t\\r
\n o support list # DO NOT ENABLE THIS RULE BEFORE ADD YOUR SUBNET IN THE
_SUP\\r
\n PORT ADDRESS LIST" dst-port=8291 protocol=tcp src-address-list=\\r
\n !Administration\r
\nadd action=drop chain=input comment="Block all access to thehttp - except
_to s\\r
\n upport list # DO NOT ENABLE THIS RULE BEFORE ADD YOUR SUBNET IN THE SU
PPOR\\r
\n T ADDRESS LIST" dst-port=80 log=yes log-prefix="drop mopi" protocol
=tcp \\r
\n src-address-list=!Administration\r
\nadd action=drop chain=input comment="Block all access to the https - exce
pt to\\r
\n \_support list # DO NOT ENABLE THIS RULE BEFORE ADD YOUR SUBNET IN TH
E SUP\\r
\n PORT ADDRESS LIST" dst-port=443 log-prefix="drop mopi" protocol=tcp
_\\r
\n src-address-list=!Administration\r
\nadd action=accept chain=input comment="test ping" disabled=yes dst-addre
ss=\\r
\n 192.168.1.254 in-interface=br-lan src-address=192.168.88.1\r
\nadd action=accept chain=input comment=\\r
\n "defconf: accept established,related,untracked" connection-state=\
\r
\n established,related,untracked\r
\nadd action=drop chain=input comment="defconf: drop invalid" connection-s
tate=\\r
\n invalid\r
\nadd action=accept chain=input comment="allow DNS from domotique" \\r
\n in-interface-list=domotique port=53 protocol=tcp\r
\nadd action=accept chain=input comment="allow DNS from domotique" \\r
\n in-interface-list=domotique log-prefix=cpasinput port=53 protocol=udp
\r
\nadd action=accept chain=input comment="CAPSManager filter rules " dst-po
rt=\\r
\n 5246,5247 in-interface=br-lan log=yes log-prefix="input caps 1" prot
ocol=\\r
\n udp\r
\nadd action=accept chain=output comment="CAPSManager filter rules " dst-p
ort=\\r
\n 5246,5247 log=yes log-prefix="output caps" out-interface=br-lan prot
ocol=\\r
\n udp\r
\nadd action=drop chain=input comment="defconf: drop all not coming from LA
N" \\r
\n disabled=yes in-interface-list=!LAN protocol=tcp\r
\nadd action=accept chain=forward comment="defconf: accept in ipsec policy
" \\r
\n ipsec-policy=in,ipsec\r
\nadd action=accept chain=forward comment="defconf: accept out ipsec policy
" \\r
\n ipsec-policy=out,ipsec\r
\nadd action=accept chain=forward comment=\\r
\n "defconf: accept established,related, untracked" connection-state=\
\r
\n established,related,untracked\r
\nadd action=drop chain=forward comment="defconf: drop invalid" \\r
\n connection-state=invalid\r
\nadd action=drop chain=forward comment=\\r
\n "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dst
nat \\r
\n connection-state=new in-interface-list=WAN”
add dont-require-permissions=no name=“firewall avec bloquage” owner=orabache
policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon
source=“/ip firewall filter\r
\nadd action=drop chain=forward comment="prise tplink" disabled=yes log=ye
s \\r
\n out-interface=br-lan src-address=192.168.2.14\r
\nadd action=accept chain=forward connection-nat-state=dstnat log=yes \\r
\n log-prefix="forward dstnat"\r
\nadd action=drop chain=input comment="drop ssh brute forcers" dst-port=22
_\\r
\n protocol=tcp src-address-list=ssh_blacklist\r
\nadd action=add-src-to-address-list address-list=rdp_blacklist \\r
\n address-list-timeout=1w3d chain=input comment="Black list 3389" \\r
\n connection-state=new dst-port=3389 protocol=tcp src-address-list=\\r
\n ssh_stage3\r
\nadd action=add-src-to-address-list address-list=http_blacklist \\r
\n address-list-timeout=1w3d chain=input comment="Black list http 10d"
\\r
\n connection-state=new dst-port=80 protocol=tcp src-address-list=ssh_sta
ge3\r
\nadd action=add-src-to-address-list address-list=rdp_stage3 \\r
\n address-list-timeout=10m chain=input comment="remote liste3" \\r
\n connection-state=new dst-port=3389 protocol=tcp src-address-list=\\r
\n ssh_stage2\r
\nadd action=add-src-to-address-list address-list=http_stage3 \\r
\n address-list-timeout=10m chain=input comment="http liste3" \\r
\n connection-state=new dst-port=80 protocol=tcp src-address-list=ssh_sta
ge2\r
\nadd action=add-src-to-address-list address-list=rdp_stage2 \\r
\n address-list-timeout=10m chain=input comment="remote liste 2" \\r
\n connection-state=new dst-port=3389 protocol=tcp src-address-list=\\r
\n ssh_stage1\r
\nadd action=add-src-to-address-list address-list=http_stage2 \\r
\n address-list-timeout=10m chain=input comment="http liste 2" \\r
\n connection-state=new dst-port=80 protocol=tcp src-address-list=ssh_sta
ge1\r
\nadd action=add-src-to-address-list address-list=rdp_stage1 \\r
\n address-list-timeout=10m chain=input comment="remote liste 1" \\r
\n connection-state=new dst-port=3389 protocol=tcp\r
\nadd action=add-src-to-address-list address-list=http_stage1 \\r
\n address-list-timeout=10m chain=input comment="http liste 1" \\r
\n connection-state=new dst-port=80 protocol=tcp\r
\nadd action=drop chain=input comment="Block all access to the winbox - exc
ept t\\r
\n o support list # DO NOT ENABLE THIS RULE BEFORE ADD YOUR SUBNET IN THE
_SUP\\r
\n PORT ADDRESS LIST mikrotik regles" dst-port=8291 protocol=tcp \\r
\n src-address-list=!Administration\r
\nadd action=drop chain=input comment="Block all access to thehttp - except
_to s\\r
\n upport list # DO NOT ENABLE THIS RULE BEFORE ADD YOUR SUBNET IN THE SU
PPOR\\r
\n T ADDRESS LIST mikrotik regles" dst-port=8080 log=yes log-prefix=\
\r
\n "drop mopi" protocol=tcp src-address-list=!Administration\r
\nadd action=drop chain=input comment="Block all access to the https - exce
pt to\\r
\n \_support list # DO NOT ENABLE THIS RULE BEFORE ADD YOUR SUBNET IN TH
E SUP\\r
\n PORT ADDRESS LIST mikrotik regles" dst-port=444 log-prefix="drop mop
i" \\r
\n protocol=tcp src-address-list=!Administration\r
\nadd action=accept chain=input comment="test ping" disabled=yes dst-addre
ss=\\r
\n 192.168.1.254 in-interface=br-lan src-address=192.168.88.1\r
\nadd action=accept chain=input comment=\\r
\n "defconf: accept established,related,untracked" connection-state=\
\r
\n established,related,untracked\r
\nadd action=drop chain=input comment="defconf: drop invalid" connection-s
tate=\\r
\n invalid\r
\nadd action=accept chain=input comment="allow DNS from domotique" \\r
\n in-interface-list=domotique port=53 protocol=tcp\r
\nadd action=accept chain=input comment="allow DNS from domotique" \\r
\n in-interface-list=domotique log-prefix=cpasinput port=53 protocol=udp
\r
\nadd action=accept chain=input comment="CAPSManager filter rules " dst-po
rt=\\r
\n 5246,5247 in-interface=br-lan log=yes log-prefix="input caps 1" prot
ocol=\\r
\n udp\r
\nadd action=accept chain=output comment="CAPSManager filter rules " dst-p
ort=\\r
\n 5246,5247 log=yes log-prefix="output caps" out-interface=br-lan prot
ocol=\\r
\n udp\r
\nadd action=drop chain=input comment="defconf: drop all not coming from LA
N" \\r
\n disabled=yes in-interface-list=!LAN protocol=tcp\r
\nadd action=accept chain=forward comment="defconf: accept in ipsec policy
" \\r
\n ipsec-policy=in,ipsec\r
\nadd action=accept chain=forward comment="defconf: accept out ipsec policy
" \\r
\n ipsec-policy=out,ipsec\r
\nadd action=accept chain=forward comment=\\r
\n "defconf: accept established,related, untracked" connection-state=\
\r
\n established,related,untracked\r
\nadd action=drop chain=forward comment="defconf: drop invalid" \\r
\n connection-state=invalid\r
\nadd action=drop chain=forward comment=\\r
\n "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dst
nat \\r
\n connection-state=new in-interface-list=WAN\r
\n”
/tool e-mail/tool graphing interface
add interface=sfp1
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
/tool netwatch
add disabled=yes host=192.168.2.10
add disabled=yes host=192.168.2.253
/tool sniffer
set filter-interface=ETHER2_VLAN100
/tool traffic-monitor
add disabled=yes interface=Freeboxserveur name=wan threshold=3000000 traffic=
received
\
Easy crs is switch an not router!
Too much load!!
hi
thank for your reponse.
pouvez me conseiller sur un routeur.
merci