Code: Select all
# jan/02/1970 00:29:57 by RouterOS 6.45.6
# software id = XP7Q-7UJG
#
# model = RB952Ui-5ac2nD
# serial number = AAAAAAAAAAAA
/interface bridge
add comment=defconf name=bridge
/interface ethernet
set [ find default-name=ether1 ] name=ether1-WAN
set [ find default-name=ether2 ] name=ether2-master
/interface wireless
set [ find default-name=wlan2 ] band=5ghz-a/n/ac channel-width=\
20/40/80mhz-Ceee disabled=no distance=indoors frequency=auto mode=\
ap-bridge name=wlan2-5G-LAN ssid=Ephesus2 wireless-protocol=802.11 \
wps-mode=disabled
/interface list
add exclude=dynamic name=discover
add name=mactel
add name=mac-winbox
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa2-psk eap-methods="" mode=\
dynamic-keys supplicant-identity=MikroTik wpa2-pre-shared-key=\
MyWirelessPasswordGoesHere
add authentication-types=wpa2-psk eap-methods="" group-ciphers=tkip,aes-ccm \
mode=dynamic-keys name=wlan-WAN supplicant-identity="" unicast-ciphers=\
tkip,aes-ccm wpa2-pre-shared-key=596rf3234f
add name=none supplicant-identity=MikroTik
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-b/g/n disabled=no distance=indoors \
frequency=2462 mode=station-pseudobridge name=wlan1-2G-WAN \
security-profile=wlan-WAN ssid=upstreamSSID wireless-protocol=802.11
add disabled=no keepalive-frames=disabled mac-address=AA:AA:AA:AA:AA:AA \
master-interface=wlan1-2G-WAN multicast-buffering=disabled name=\
wlan3-2G-LAN ssid=My24GHzNetwork wds-cost-range=0 wds-default-cost=0 \
wps-mode=disabled
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/ip pool
add name=default-dhcp ranges=172.19.26.10-172.19.26.254
add name=dhcp ranges=172.19.26.3-172.19.26.254
/ip dhcp-server
add address-pool=default-dhcp disabled=no interface=bridge name=defconf
# DHCP server can not run on slave interface!
add address-pool=dhcp disabled=no interface=ether2-master name=dhcp1
/interface bridge port
add bridge=bridge comment=defconf interface=ether2-master
add bridge=bridge comment=defconf interface=wlan2-5G-LAN
add bridge=bridge interface=wlan3-2G-LAN
add bridge=bridge interface=ether4
add bridge=bridge interface=ether5
/interface list member
add interface=ether2-master list=discover
add interface=ether3 list=discover
add interface=ether4 list=discover
add interface=ether5 list=discover
add interface=wlan2-5G-LAN list=discover
add interface=bridge list=discover
add interface=wlan3-2G-LAN list=discover
add interface=bridge list=mactel
add interface=ether2-master list=mactel
add interface=ether3 list=mactel
add interface=bridge list=mac-winbox
add interface=ether4 list=mactel
add interface=ether2-master list=mac-winbox
add interface=ether5 list=mactel
add interface=ether3 list=mac-winbox
add interface=wlan2-5G-LAN list=mactel
add interface=ether4 list=mac-winbox
add interface=wlan3-2G-LAN list=mactel
add interface=ether5 list=mac-winbox
add interface=wlan2-5G-LAN list=mac-winbox
add interface=wlan3-2G-LAN list=mac-winbox
/ip address
add address=172.19.26.1/24 comment=defconf interface=bridge network=\
172.19.26.0
add address=172.19.26.1/24 interface=ether2-master network=172.19.26.0
/ip dhcp-client
add comment=defconf dhcp-options=hostname,clientid disabled=no interface=\
wlan1-2G-WAN
add dhcp-options=hostname,clientid disabled=no interface=ether1-WAN
/ip dhcp-server network
add address=172.19.26.0/24 comment=defconf gateway=172.19.26.1
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=172.19.26.1 name=router
/ip firewall filter
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment="defconf: accept established,related" \
connection-state=established,related
# in/out-interface matcher not possible when interface (wlan3-2G-LAN) is slave - use master instead (bridge)
add action=accept chain=input dst-port=68 in-interface=wlan3-2G-LAN protocol=\
udp
add action=drop chain=input comment="defconf: drop all from WAN" \
in-interface=ether1-WAN
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
connection-state=established,related
add action=accept chain=forward comment="defconf: accept established,related" \
connection-state=established,related
add action=drop chain=forward comment="defconf: drop invalid" \
connection-state=invalid
add action=drop chain=forward comment=\
"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
connection-state=new in-interface=ether1-WAN
add chain=input protocol=icmp
add chain=input connection-state=established
add chain=input connection-state=related
add action=drop chain=input in-interface=ether1-WAN
add action=drop chain=input in-interface=wlan1-2G-WAN
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
out-interface=ether1-WAN
add action=masquerade chain=srcnat out-interface=ether1-WAN
add action=masquerade chain=srcnat out-interface=wlan1-2G-WAN
/ip upnp
set enabled=yes
/ip upnp interfaces
add interface=wlan1-2G-WAN type=external