# version: 7.22 (stable) # factory-software: 7.8 # total-memory: 16.0GiB # cpu: ARM64 # cpu-count: 16 # total-hdd-space: 128.0MiB # architecture-name: arm64 # board-name: CCR2116-12G-4S+ # platform: MikroTik # installed-version: 7.22 # Flags: U - UNDOABLE # Columns: ACTION, BY, POLICY, TIME # ACTION BY POLICY TIME # U item changed MEXICARRIER write 2026-08-17 15:47:08 # U bridge port added MEXICARRIER write 2026-08-17 15:46:41 # # software id = FVBX-6C9C # # model = CCR2116-12G-4S+ # serial number = HH10AATF5XC /interface bridge add mtu=1500 name=WAN-SOMNET /interface ethernet set [ find default-name=ether1 ] name="ether1-TP LINK" set [ find default-name=ether12 ] name=ether12-SW-ethernet100G set [ find default-name=sfp-sfpplus1 ] name=sfp-sfpplus1-WAN1 set [ find default-name=sfp-sfpplus2 ] name=sfp-sfpplus2-WAN2 /interface wireguard add listen-port=13231 mtu=1420 name=VPN_COGENT private-key="/GiJiYvffH8crz6xv4bfOEJOL6vuaS1lEI29gLDGFjI=" /interface vlan add interface=WAN-SOMNET name=vlan1200 vlan-id=1200 /interface bonding add lacp-rate=1sec mode=802.3ad name="BONDING WAN" slaves=sfp-sfpplus1-WAN1,sfp-sfpplus2-WAN2 transmit-hash-policy=layer-3-and-4 /routing ospf instance add disabled=yes name=to-toluca router-id=2.2.2.2 /routing ospf area add disabled=no instance=to-toluca name=backbone-ixtlahuaca /snmp community set [ find default=yes ] name=SNMP-SOMNET /system logging action add name=GrafanaLoki remote=172.20.0.254 remote-log-format=syslog remote-port=1514 src-address=172.20.1.50 target=remote /interface bridge port add bridge=WAN-SOMNET interface="ether1-TP LINK" add bridge=WAN-SOMNET interface="BONDING WAN" add bridge=WAN-SOMNET disabled=yes interface=sfp-sfpplus1-WAN1 add bridge=WAN-SOMNET disabled=yes interface=sfp-sfpplus2-WAN2 add bridge=WAN-SOMNET interface=ether11 /ipv6 settings set disable-ipv6=yes /interface wireguard peers add allowed-address=172.24.1.24/32 client-allowed-address=::/0 client-dns=8.8.8.8 comment="LAPTOP DAIRA" interface=VPN_COGENT name=DNPA1 public-key="FBe8jKumO+VIvZGKzkRwSKcIdUzr7+8pLJrxhRNEohQ=" add allowed-address=172.24.1.3/32 client-allowed-address=::/0 client-dns=8.8.8.8 comment="CELULAR DAIRA" interface=VPN_COGENT name=DNPA2 public-key="RPdRReIj4fdEd8xgtwmeeTH+cepAF0kX0S7XPcFUdHY=" add allowed-address=172.24.1.4/32 client-allowed-address=::/0 client-dns=8.8.8.8 comment="LAPTOP CESAR" interface=VPN_COGENT name=CPV public-key="iknPbWfoMd/L0p6dWGqBW3tgeHGO6KOAV9+kWaVVJ0A=" add allowed-address=172.24.1.5/32 client-allowed-address=::/0 client-dns=8.8.8.8 comment="CELULAR CESAR" interface=VPN_COGENT name=CPV2 public-key="ox5S9BUw7fx4Bx+opW1pKd7gW4Vz27vjOYSDs7cv4X8=" add allowed-address=172.24.1.10/32 client-allowed-address=::/0 client-dns=8.8.8.8 comment="CELULAR PRIS" interface=VPN_COGENT name=PVPA public-key="L+V9o0fNYkMVKNqsX7spBzD/9oSvxM/C7ZCZX1jLO3Q=" add allowed-address=172.24.1.7/32 client-allowed-address=::/0 client-dns=8.8.8.8 comment="CELULAR MARY" interface=VPN_COGENT name=MLAF public-key="yeNHT56vK7ByM+qKHacBNF0Icy9lBsMl4Lv0JrsVG0E=" add allowed-address=172.24.1.9/32 client-allowed-address=::/0 client-dns=8.8.8.8 comment="CELULAR BRAYAN" interface=VPN_COGENT name=BJ public-key="wN6Y2HtKr7eE8d3mQWT7g6zihpdDhUElLyZNyHQZzmY=" add allowed-address=172.24.1.8/32 client-allowed-address=::/0 client-dns=8.8.8.8 comment="LAPTOP LENOVO" interface=VPN_COGENT name=LLN public-key="dnQWJRyl42yfjK1/Ae9SGW8D33Wc+wjRfQFBEUxQB1I=" add allowed-address=172.24.1.12/32 client-allowed-address=::/0 client-dns=8.8.8.8 comment="LAPTOP 2 BRAYAN" interface=VPN_COGENT name=L2BJ public-key="BpqAy6Dvyw6Ch4Pop45/T7RdS1kWD0Ocngk8yruC2iI=" add allowed-address=172.24.1.20/32 client-allowed-address=::/0 client-dns=8.8.8.8 comment="CELULAR CLEMENTE " interface=VPN_COGENT name=CC public-key="Z9VZoddyfHulp5Dbgyqnb+XhnqZ/crxHWMsTeZEUxn4=" add allowed-address=172.24.1.13/32 client-allowed-address=::/0 client-dns=8.8.8.8 interface=VPN_COGENT name="DNPA 3" public-key="8mcPGSCVdexatSSfg0uKERjJNMApEd0+qAGCPn96PEw=" add allowed-address=172.24.1.14/32 client-allowed-address=::/0 client-dns=8.8.8.8 interface=VPN_COGENT name=LAPTOP-CESAR public-key="Y0mHLLe7oes+pXZZTiiZI7TgQUmCUJdorK3QGb3T6B4=" add allowed-address=172.24.1.15/32 client-allowed-address=::/0 client-dns=8.8.8.8 comment="LAPTOP BRAYAN" interface=VPN_COGENT name=LB public-key="OB7c1mlen+4VA3H0ZqIwGJ8NQ3mfz4ZARAcsyGa2I30=" add allowed-address=172.24.1.22/32 client-allowed-address=::/0 client-dns=8.8.8.8 interface=VPN_COGENT name=CS public-key="oRkNTk0ZsLn9qMrMa/7w/JaYnGLSnoRgbO9qW5JyAj0=" add allowed-address=172.24.1.24/32 client-dns=8.8.8.8 disabled=yes interface=VPN_COGENT name=LD public-key="0YdVkbiT/2WNo0cAt8L6+hC/NNLIexJ1rVUGxQUzclw=" /ip address add address=172.20.1.50/16 comment="IP ADMINISTRACI\D3N" interface=WAN-SOMNET network=172.20.0.0 add address=38.123.220.2/24 comment="IP COGENT" interface=WAN-SOMNET network=38.123.220.0 add address=172.20.1.1/16 comment="temporal corte FO" disabled=yes interface=WAN-SOMNET network=172.20.0.0 add address=172.24.1.1/24 comment="IP VPN" interface=VPN_COGENT network=172.24.1.0 add address=201.234.96.33/27 comment="temporal corte FO" disabled=yes interface=vlan1200 network=201.234.96.32 /ip dhcp-client add comment=defconf interface=*13 name=client1 /ip dns set servers=1.1.1.2,1.0.0.2 /ip firewall filter add action=accept chain=input comment="Permitir Wireguard" dst-port=13231 protocol=udp add action=accept chain=output comment="permitir EoIP" protocol=gre /ip firewall nat add action=masquerade chain=srcnat out-interface=WAN-SOMNET add action=masquerade chain=srcnat comment="temporal corte FO" disabled=yes in-interface=vlan1200 out-interface=WAN-SOMNET /ip route add check-gateway=ping comment="WAN CIRION" disabled=yes distance=30 dst-address=0.0.0.0/0 gateway=172.20.1.1 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add check-gateway=ping comment="WAN COGENT" disabled=no distance=2 dst-address=0.0.0.0/0 gateway=38.123.220.1 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add check-gateway=ping disabled=yes distance=10 dst-address=0.0.0.0/0 gateway=201.234.96.33 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 /ip service set ftp disabled=yes set telnet disabled=yes set reverse-proxy disabled=yes set www port=8080 set api disabled=yes set api-ssl disabled=yes set ssh port=46825 /radius add address=172.20.6.1 secret=Fr3eR4d!u5 service=login src-address=172.20.1.50 /routing ospf interface-template add area=backbone-ixtlahuaca cost=10 disabled=no interfaces="BONDING WAN" type=ptp add area=backbone-ixtlahuaca cost=100 disabled=no interfaces=VPN_COGENT type=ptp add area=backbone-ixtlahuaca disabled=no interfaces=*1B passive /snmp set enabled=yes /system clock set time-zone-name=America/Mexico_City /system identity set name=RT-IXTLAHUACA /system logging add action=GrafanaLoki prefix=172.20.1.50 topics=critical add action=GrafanaLoki prefix=172.20.1.50 topics=error add action=GrafanaLoki prefix="172.20.1.50 " topics=warning add action=GrafanaLoki prefix=172.20.1.50 topics=info /system ntp client set enabled=yes /system ntp client servers add address=0.mx.pool.ntp.org add address=1.mx.pool.ntp.org /system routerboard settings set enter-setup-on=delete-key /tool graphing interface add /tool graphing resource add /tool sniffer set filter-direction=rx filter-interface=ether11 /user aaa set default-group=full use-radius=yes