# version: 7.19.1 (stable) # factory-software: 6.38.4 # total-memory: 1024.0MiB # cpu: ARM # cpu-count: 4 # total-hdd-space: 128.0MiB # architecture-name: arm # board-name: RB1100AHx4 Dude Edition # platform: MikroTik # installed-version: 7.19.1 # # software id = NZMR-N2D0 # # model = RB1100Dx4 # serial number = 735B072A24B3 /disk add parent=sata1 partition-number=1 partition-offset=512 partition-size=64023256576 slot=disk1 type=partition /interface bridge add name=LAN port-cost-mode=short priority=0x1 add name="WAN BR" port-cost-mode=short /interface ethernet set [ find default-name=ether1 ] advertise="10M-baseT-half,10M-baseT-full,100M-baseT-half,100M-baseT-full,1G-baseT-half,1G-baseT-full,2.5G-baseT,5G-baseT,10G-baseT" set [ find default-name=ether2 ] advertise="10M-baseT-half,10M-baseT-full,100M-baseT-half,100M-baseT-full,1G-baseT-half,1G-baseT-full,10G-baseT" name="ether2-WAN 1-FO" set [ find default-name=ether3 ] name="ether3 - " set [ find default-name=ether4 ] name="ether4 -MODEM" set [ find default-name=ether5 ] name=ether5- set [ find default-name=ether6 ] loop-protect=on rx-flow-control=auto tx-flow-control=auto set [ find default-name=ether7 ] name="ether7 " set [ find default-name=ether8 ] name="ether8 -WAN 2-PBE" set [ find default-name=ether9 ] name=ether9-OLT set [ find default-name=ether10 ] name=ether10-DVR /interface wireguard add listen-port=13231 mtu=1420 name=VPN_PORVENIR private-key="eFMQS9zJgAXHarZR40hPXMaGNnFiyQWqLxT95Sr/YkQ=" /interface lte apn set [ find default=yes ] ip-type=ipv4 use-network-apn=no /ip pool add name=dhcp_pool0 ranges=192.168.150.250-192.168.150.254 add name=dhcp_pool1 ranges=192.168.151.50-192.168.151.254 /ip dhcp-server add address-pool=dhcp_pool0 interface=LAN lease-time=10m name=dhcp1 add address-pool=dhcp_pool1 interface=ether9-OLT lease-time=10m name=dhcp2 /port set 0 name=serial0 set 1 name=serial1 /snmp community set [ find default=yes ] name=SNMP-SOMNET /system logging action add name=GrafanaLoki remote=172.20.0.254 remote-log-format=syslog remote-port=1514 src-address=172.20.3.141 target=remote /interface bridge port add bridge=LAN ingress-filtering=no interface="ether4 -MODEM" internal-path-cost=10 path-cost=10 add bridge=LAN ingress-filtering=no interface=ether10-DVR internal-path-cost=10 path-cost=10 add bridge="WAN BR" ingress-filtering=no interface="ether2-WAN 1-FO" internal-path-cost=10 path-cost=10 /ip firewall connection tracking set udp-timeout=10s /ip neighbor discovery-settings set discover-interface-list=all /ip settings set max-neighbor-entries=8192 /ipv6 settings set disable-ipv6=yes max-neighbor-entries=8192 soft-max-neighbor-entries=8191 /interface ovpn-server server add auth=sha1,md5 mac-address=FE:32:B7:F7:D7:CA name=ovpn-server1 /interface pptp-server server # PPTP connections are considered unsafe, it is suggested to use a more modern VPN protocol instead set authentication=pap,chap,mschap1,mschap2 enabled=yes /interface wireguard peers add allowed-address=172.23.1.2/32 client-dns=8.8.8.8 interface=VPN_PORVENIR name=LB public-key="EFbpZX4BMth1RPnumoh8h1hwbNd5jNUxQZuX3YNXIwM=" add allowed-address=172.23.1.3/32 client-dns=8.8.8.8 interface=VPN_PORVENIR name=CC public-key="WddsrxHYJ/sTHRk0oNzBe2sn14KH257vhnGLjH7kHy0=" /ip address add address=172.20.3.141/16 comment=";;;;;IP PUBLICA FO" interface="WAN BR" network=172.20.0.0 add address=38.58.38.42/24 comment=";;;;IP POR SAN MARTIN" interface="WAN BR" network=38.58.38.0 add address=192.168.150.1/24 interface=LAN network=192.168.150.0 add address=192.168.151.1/24 comment=";;;;RED FO PORVENIR" interface=ether9-OLT network=192.168.151.0 add address=172.23.1.1/24 comment=VPN-PORVENIR interface=VPN_PORVENIR network=172.23.1.0 /ip cloud set ddns-enabled=yes /ip dhcp-server lease add address=192.168.151.254 client-id=1:6c:68:a4:4d:3:bd comment="CASETA PORVENIR" mac-address=6C:68:A4:4D:03:BD server=dhcp2 /ip dhcp-server network add address=192.168.150.0/24 gateway=192.168.150.1 add address=192.168.151.0/24 gateway=192.168.151.1 /ip dns set servers=1.1.1.2,1.0.0.2 /ip firewall nat add action=masquerade chain=srcnat out-interface="WAN BR" add action=masquerade chain=srcnat out-interface="ether8 -WAN 2-PBE" add action=accept chain=srcnat comment="PERMITIR VPN" dst-port=13231 protocol=udp /ip ipsec profile set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5 /ip route add comment="RUTA OLT OFICINA" disabled=no distance=1 dst-address=172.4.0.0/24 gateway=38.123.220.28 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add disabled=no dst-address=0.0.0.0/0 gateway=38.58.38.1 routing-table=main suppress-hw-offload=no /ip service set ftp disabled=yes set telnet disabled=yes set www port=8080 set api disabled=yes set api-ssl disabled=yes set ssh port=46825 /ppp secret add local-address=10.1.1.1 name=P.PORVE1 password=admin@123 profile=default-encryption remote-address=10.1.1.2 service=pptp /radius add address=172.20.6.1 secret=Fr3eR4d!u5 service=login src-address=172.20.3.141 /routing bfd configuration add disabled=no interfaces=all min-rx=200ms min-tx=200ms multiplier=5 /snmp set contact="SOMNET MEXICO" enabled=yes location=PORVENIR trap-interfaces=all trap-version=2 /system clock set time-zone-name=America/Mexico_City /system identity set name=MK_PORVENIR /system logging add action=GrafanaLoki prefix=172.20.3.141 topics=critical add action=GrafanaLoki prefix=172.20.3.141 topics=error add action=GrafanaLoki prefix=172.20.3.141 topics=info add action=GrafanaLoki prefix=172.20.3.141 topics=warning /system ntp client set enabled=yes /system ntp client servers add address=0.mx.pool.ntp.org add address=1.mx.pool.ntp.org /tool graphing interface add /tool graphing resource add /tool sniffer set file-name=porvenir.cap filter-direction=rx filter-interface="ether8 -WAN 2-PBE" /user aaa set default-group=full use-radius=yes