I'm very new to Mikrotik and have a small problem of accessing Virgin ISP modem through Mikrotik hAP ac.
DHCP is enabled. Any pointer would and explanation would be greatly appreciated
My configuration file :
Code: Select all
# jun/26/2020 18:14:41 by RouterOS 6.47
# software id = FIZY-JWRI
#
# model = RouterBOARD 962UiGS-5HacT2HnT
# serial number = 673706DFBAA7
/interface bridge
add admin-mac=6C:3B:6B:11:E6:A1 auto-mac=no comment=defconf fast-forward=no \
name=bridge
/interface ethernet
set [ find default-name=ether1 ] full-duplex=no rx-flow-control=on \
tx-flow-control=on
set [ find default-name=ether2 ] name=ether2-master rx-flow-control=auto \
tx-flow-control=auto
set [ find default-name=ether3 ] rx-flow-control=auto tx-flow-control=auto
set [ find default-name=ether4 ] rx-flow-control=auto tx-flow-control=auto
set [ find default-name=ether5 ] auto-negotiation=no
set [ find default-name=sfp1 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
/interface vlan
add interface=bridge name=vlan1 vlan-id=1
/interface list
add exclude=dynamic name=discover
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
add authentication-types=wpa2-psk group-ciphers=tkip,aes-ccm \
group-key-update=23h59m mode=dynamic-keys name=WEP static-algo-0=\
40bit-wep static-key-0=42c96e4136 supplicant-identity=MikroTik \
unicast-ciphers=tkip,aes-ccm wpa2-pre-shared-key=42c96e4136
/interface wireless
set [ find default-name=wlan1 ] antenna-gain=0 band=2ghz-b/g/n channel-width=\
20/40mhz-Ce country=no_country_set disabled=no distance=indoors \
frequency=auto frequency-mode=manual-txpower mode=ap-bridge \
security-profile=WEP ssid=MikroTik wireless-protocol=802.11
set [ find default-name=wlan2 ] antenna-gain=0 band=5ghz-a/n/ac \
channel-width=20/40mhz-Ce country=no_country_set disabled=no distance=\
indoors frequency=auto frequency-mode=manual-txpower mode=ap-bridge \
security-profile=WEP ssid="MT Szarlej" wireless-protocol=802.11
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/ip pool
add name=dhcp ranges=192.168.88.10-192.168.88.254
add name=dhcp_pool1 ranges=192.168.87.2-192.168.87.254
/ip dhcp-server
add add-arp=yes address-pool=dhcp authoritative=after-2sec-delay disabled=no \
interface=bridge lease-time=23h name=defconf
/snmp community
set [ find default=yes ] addresses=0.0.0.0/0
/interface bridge port
add bridge=bridge comment=defconf interface=ether2-master
add bridge=bridge comment=defconf hw=no interface=sfp1
add bridge=bridge comment=defconf interface=wlan1
add bridge=bridge comment=defconf interface=wlan2
add bridge=bridge interface=ether3
add bridge=bridge interface=ether4
add bridge=bridge interface=ether5
/ip neighbor discovery-settings
set discover-interface-list=discover
/interface list member
add interface=wlan1 list=discover
add interface=ether2-master list=discover
add interface=ether3 list=discover
add interface=ether4 list=discover
add interface=ether5 list=discover
add interface=sfp1 list=discover
add interface=wlan2 list=discover
add interface=bridge list=discover
add interface=vlan1 list=discover
/interface wireless access-list
add interface=wlan1 mac-address=68:17:29:9E:D3:BA
add interface=wlan1 mac-address=00:D7:3B:9D:B0:11
/interface wireless connect-list
add interface=wlan1 mac-address=68:17:29:9E:D3:BA security-profile=WEP
add interface=wlan1 mac-address=00:D7:3B:9D:B0:11 security-profile=WEP
/ip address
add address=192.168.88.1/24 comment=defconf interface=ether2-master network=\
192.168.88.0
/ip dhcp-client
add comment=defconf disabled=no interface=ether1
/ip dhcp-server config
set store-leases-disk=immediately
/ip dhcp-server lease
add address=192.168.88.249 client-id=1:2c:56:dc:3b:30:94 mac-address=\
2C:56:DC:3B:30:94 server=defconf
add address=192.168.88.165 client-id=1:68:17:29:9e:d3:ba mac-address=\
68:17:29:9E:D3:BA server=defconf
add address=192.168.88.166 client-id=1:0:d7:3b:9d:b0:11 mac-address=\
00:D7:3B:9D:B0:11 server=defconf
add address=192.168.88.149 client-id=1:b0:5a:da:87:49:8c mac-address=\
B0:5A:DA:87:49:8C server=defconf
add address=192.168.88.133 client-id=1:b0:5a:da:87:49:8e mac-address=\
B0:5A:DA:87:49:8E server=defconf
add address=192.168.88.131 client-id=1:b0:5a:da:87:49:8d mac-address=\
B0:5A:DA:87:49:8D server=defconf
add address=192.168.88.100 mac-address=00:0C:29:D8:E7:80 server=defconf
/ip dhcp-server network
add address=192.168.87.0/24 dns-server=192.168.87.1 gateway=192.168.87.1
add address=192.168.88.0/24 comment=defconf gateway=192.168.88.1
/ip dns
set allow-remote-requests=yes servers=192.168.88.1
/ip dns static
add address=192.168.88.1 name=router type=A
add address=192.168.88.1 name=Router.os ttl=5m type=A
add address=192.168.88.133 name=vmware ttl=5m type=A
add address=192.168.88.147 name=Home-dc01 type=A
add address=192.168.88.145 name=Home-util01 type=A
add address=192.168.88.133 name=ilocz1545012c ttl=2s type=A
add address=192.168.88.100 name=ftpserver type=A
/ip firewall address-list
add list=Fantasy_Grounds
/ip firewall filter
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment="defconf: accept established,related" \
connection-state=established,related
add action=drop chain=input comment="defconf: drop all from WAN" \
in-interface=ether1
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
connection-state=established,related
add action=accept chain=forward comment="defconf: accept established,related" \
connection-state=established,related
add action=drop chain=forward comment="defconf: drop invalid" \
connection-state=invalid
add action=drop chain=forward comment=\
"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
connection-state=new in-interface=ether1
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
out-interface=ether1
/ip service
set www-ssl disabled=no
/ip smb shares
set [ find default=yes ] directory=/pub
/system clock
set time-zone-name=Europe/London
/system leds
set 1 interface=wlan2