# version: 7.19.6 (stable) # factory-software: 6.35.3 # total-memory: 1024.0MiB # cpu: ARM # cpu-count: 2 # total-hdd-space: 128.0MiB # architecture-name: arm # board-name: RB3011UiAS # platform: MikroTik # installed-version: 7.19.6 # # software id = 8Y34-RAUA # # model = RB3011UiAS # serial number = 8EEE085FB25F /interface bridge add name=LAN-Somnet port-cost-mode=short /interface ethernet set [ find default-name=ether3 ] name="ether3 " set [ find default-name=ether5 ] name="ether5-WAN ASN SOMNET" set [ find default-name=ether6 ] name=ether6-AP-UNIFI set [ find default-name=ether9 ] auto-negotiation=no speed=100M-baseT-full set [ find default-name=ether10 ] name=ether10-InterConexion-SW-WISP-OFICINA set [ find default-name=sfp1 ] auto-negotiation=no /interface wireguard add listen-port=13231 mtu=1420 name=WireGuard-VPN private-key="+M+sY3vExr81Fi9nlgJMZikQbiaFlHmG0g95v57tung=" /interface vlan add interface=LAN-Somnet name="VLAN Invitados #5" vlan-id=5 /interface list add name=WAN /interface lte apn set [ find default=yes ] ip-type=ipv4 use-network-apn=no /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik /ip ipsec profile set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5 add dh-group=modp2048 dpd-interval=2m dpd-maximum-failures=5 enc-algorithm=aes-256 hash-algorithm=sha256 name=Somnet-CHR /ip ipsec peer add address=54.80.194.153/32 disabled=yes name=Somnet-CHR profile=Somnet-CHR /ip ipsec proposal set [ find default=yes ] auth-algorithms=sha256,sha1 pfs-group=modp2048 add auth-algorithms=sha256,md5 disabled=yes enc-algorithms=aes-256-cbc name=Somnet-CHR pfs-group=none /ip pool add name=Pool_Invitados ranges=10.1.7.2-10.1.7.150 add name=dhcp_LAN ranges=10.1.5.100-10.1.5.254 add name=Invitados ranges=10.1.6.2-10.1.6.200 add name=dhcp_pool17 ranges=10.1.5.200-10.1.5.254 add name=dhcp_pool18 ranges=10.1.5.200-10.1.5.254 add name=dhcp_pool19 ranges=10.1.7.200-10.1.7.254 /ip dhcp-server add address-pool=dhcp_pool18 disabled=yes interface=LAN-Somnet lease-time=10m name=dhcp1 add address-pool=dhcp_pool19 interface="VLAN Invitados #5" lease-time=10m name=dhcp2 /ip smb users set [ find default=yes ] disabled=yes /port set 0 name=serial0 /ppp profile set *0 only-one=no set *FFFFFFFE local-address=10.1.5.1 remote-address=dhcp_LAN /queue simple add max-limit=2M/5M name="IP Fake" target=10.1.9.21/32 /routing bgp template set default disabled=no output.network=bgp-networks /routing ospf instance add disabled=no name=default-v2 /routing ospf area add disabled=yes instance=default-v2 name=backbone-v2 /routing table add fib name=PRUEBA-POS add disabled=no fib name=AP-UNIFI /snmp community set [ find default=yes ] name=SNMP-SOMNET /system logging action set 1 disk-file-count=10 add name=GrafanaLoki remote=172.20.0.254 remote-log-format=syslog remote-port=1514 src-address=172.20.3.95 target=remote /interface vlan add interface=*19 name=vlan1200 vlan-id=1200 /interface bridge port add bridge=LAN-Somnet ingress-filtering=no interface=ether6-AP-UNIFI internal-path-cost=10 path-cost=10 add bridge=LAN-Somnet ingress-filtering=no interface=ether8 internal-path-cost=10 path-cost=10 add bridge=LAN-Somnet ingress-filtering=no interface=ether4 internal-path-cost=10 path-cost=10 add bridge=LAN-Somnet ingress-filtering=no interface="ether3 " internal-path-cost=10 path-cost=10 add bridge=LAN-Somnet ingress-filtering=no interface=ether9 internal-path-cost=10 path-cost=10 add bridge=LAN-Somnet ingress-filtering=no interface=ether2 internal-path-cost=10 path-cost=10 add bridge=LAN-Somnet ingress-filtering=no interface=ether7 internal-path-cost=10 path-cost=10 /ip firewall connection tracking set udp-timeout=10s /ip neighbor discovery-settings set discover-interface-list=all /ip settings set max-neighbor-entries=8192 /ipv6 settings set disable-ipv6=yes max-neighbor-entries=8192 soft-max-neighbor-entries=8191 /interface l2tp-server server set authentication=chap,mschap1,mschap2 enabled=yes ipsec-secret=V1c70R!4 use-ipsec=yes /interface list member add interface=ether1 list=WAN /interface ovpn-server server add auth=sha1,md5 mac-address=FE:60:5C:2D:2F:7E name=ovpn-server1 /interface pppoe-server server add default-profile=default-encryption interface="ether3 " service-name=service1 /interface wireguard peers add allowed-address=192.168.50.6/32 client-address=::/0 client-dns=8.8.8.8 comment="VPN-PC MARY" interface=WireGuard-VPN name=PC-MARY public-key="89nSVHxni0ybxXPRDcwvlPOvfPPE38x2VAWlP+LpvwQ=" add allowed-address=192.168.50.7/32 client-address=::/0 client-dns=8.8.8.8 comment="VPN-PC NATALIA" interface=WireGuard-VPN name=PC-NATALIA public-key="OurdltHoVJPsto4BIrWvbJuVbKQqhtaFFnvjG1WNEHU=" add allowed-address=192.168.50.4/32 comment="VPN DE CESAR PLATA" interface=WireGuard-VPN name=CP public-key="cF9m0goDgFUskMyjj4KKuflxX5WsXoxZ8qK/nmPBmzI=" /ip address add address=10.1.7.1/24 comment="Red para Inalambricos" interface="VLAN Invitados #5" network=10.1.7.0 add address=38.123.220.8/24 comment="IP PUBLICA PARA OFICINA SOMNET" interface=ether10-InterConexion-SW-WISP-OFICINA network=38.123.220.0 add address=172.20.3.95/16 comment="IP Administraci\F3n" interface=ether10-InterConexion-SW-WISP-OFICINA network=172.20.0.0 add address=192.168.50.1/24 comment="RED VPN" interface=WireGuard-VPN network=192.168.50.0 add address=10.1.5.1/24 comment="Red para inalambricos " interface=LAN-Somnet network=10.1.5.0 /ip cloud set ddns-enabled=yes /ip cloud advanced set use-local-address=yes /ip dhcp-server network add address=10.1.5.0/24 dns-server=8.8.8.8 gateway=10.1.5.1 add address=10.1.7.0/24 dns-server=8.8.8.8 gateway=10.1.7.1 add address=192.168.9.0/24 dns-server=1.1.1.1 gateway=192.168.9.1 /ip dns set cache-size=4096KiB servers=1.1.1.2,1.0.0.2 /ip dns static add address=10.1.9.103 name=monitoreowisp.somnet type=A add address=10.1.9.101 name=unifi.somnet type=A add address=10.1.9.101 name=unifi type=A add address=10.1.9.101 name=hotspot.somnet type=A add address=10.1.5.1 disabled=yes name=somnet.local type=A add address=10.1.9.21 name=somnetmexico.3cx.us type=A add address=127.0.0.1 regexp="^((\?!\\.).)*\$" type=A add address=172.19.2.1 disabled=yes name=camioneta type=A add address=172.19.2.1 disabled=yes name=camioneta.somnet type=A add address=10.1.9.21 disabled=yes name=capacitacion.somnet.com.mx type=A add address=10.1.9.21 disabled=yes name=somnet.com.mx type=A add address=10.1.9.21 disabled=yes name=portal.somnet.com.mx/monitoreo type=A add address=10.8.3.81 name=miaap2.com type=A /ip firewall address-list add address=10.1.9.105 list="Servidores UTSEM" add address=10.1.9.100 list="Servidores UTSEM" add address=10.1.9.20 list="Servidores UTSEM" add address=10.1.9.22 list="Servidores UTSEM" add address=192.168.102.20 list=ImpresoraGrande add address=10.1.5.25 list=AP-MeshSOMNET add address=10.8.0.0/16 list=REDWISP add address=10.1.7.1 list=A add address=www.banorte.com list=BANORTE /ip firewall filter add action=accept chain=input comment="VPN TUNNEL L2TP" dst-port=1701,500,4500 protocol=udp add action=accept chain=input protocol=ipsec-esp add action=accept chain=input comment="Permitir tr\E1fico WireGuard" disabled=yes src-address=192.168.50.0/24 add action=accept chain=input comment="Puerto WireGuard" dst-port=13231 protocol=udp /ip firewall mangle add action=mark-routing chain=prerouting dst-address-list=BANORTE add action=mark-routing chain=prerouting disabled=yes new-routing-mark=AP-UNIFI src-address=10.1.5.2 /ip firewall nat add action=masquerade chain=srcnat out-interface="ether5-WAN ASN SOMNET" add action=masquerade chain=srcnat out-interface=ether10-InterConexion-SW-WISP-OFICINA /ip firewall service-port set sip disabled=yes /ip ipsec identity add disabled=yes peer=Somnet-CHR secret="8j-Wy}gp\"/Gv" /ip ipsec policy add disabled=yes dst-address=172.31.32.0/20 peer=Somnet-CHR proposal=Somnet-CHR src-address=10.1.5.0/24 tunnel=yes /ip route add check-gateway=ping comment="RUTA CORE" disabled=no distance=20 dst-address=0.0.0.0/0 gateway=172.20.1.1 pref-src="" routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add comment="USUARIOS RESIDENCIALES SAN SIMON" disabled=no distance=1 dst-address=192.168.31.0/24 gateway=172.20.1.9 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add comment="USUARIOS RESIDENCIALES TEJUPILCO" disabled=no distance=1 dst-address=192.168.30.0/24 gateway=172.20.1.9 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add check-gateway=ping comment="CLIENTES RESIDENCIALES ZONA IXTLAHUACA" disabled=no dst-address=192.168.33.0/24 gateway=172.20.1.9 routing-table=main suppress-hw-offload=no add comment="CLIENTES RESIDENCIALES SAN PEDRO LIM\D3N" disabled=no distance=1 dst-address=192.168.34.0/24 gateway=172.20.1.1 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add comment="RUTA COGENT" disabled=no distance=10 dst-address=0.0.0.0/0 gateway=38.123.220.1 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add comment="RUTA CLIENTES RESIDENCIALES AMATEPEC" disabled=no distance=1 dst-address=192.168.32.0/24 gateway=172.20.1.9 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add comment="CLIENTES RESIDENCIALES SAN BARTOLO" disabled=no distance=1 dst-address=192.168.12.0/24 gateway=172.20.1.9 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add check-gateway=ping comment="CLIENTES RESIDENCIALES SAN MIGUEL" disabled=no distance=1 dst-address=192.168.15.0/24 gateway=38.123.220.32 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add disabled=no dst-address=172.148.148.0/24 gateway=172.20.4.102 routing-table=main suppress-hw-offload=no add check-gateway=ping comment="CLIENTES RESIDENCIALES SAN MARTIN" disabled=no distance=1 dst-address=192.168.11.0/24 gateway=172.20.1.90 routing-table=main scope=30 suppress-hw-offload=no target-scope=10 /ip service set ftp disabled=yes set telnet disabled=yes set www port=8080 set api disabled=yes set api-ssl disabled=yes set ssh port=46825 /ip smb shares set [ find default=yes ] directory=/pub /ppp l2tp-secret add secret=Deividgr98 /ppp profile add dns-server=8.8.8.8 local-address=*10 name=L2TP remote-address=*10 /ppp secret add local-address=192.168.254.5 name=cplata password=#593c7RuM% remote-address=192.168.254.6 service=l2tp add local-address=192.168.254.1 name=dplata password=dpv33#gh%* remote-address=192.168.254.2 service=l2tp add local-address=192.168.254.40 name=malegria password=Rojo71046 remote-address=192.168.254.41 service=l2tp /radius add address=172.30.1.254 disabled=yes require-message-auth=no secret=123 service=ppp,login,hotspot,wireless,dhcp,ipsec,dot1x timeout=3s add address=172.20.6.1 secret=Fr3eR4d!u5 service=login src-address=172.20.3.95 /routing bfd configuration add disabled=no /snmp set enabled=yes location="OFICINA " trap-generators=interfaces trap-interfaces=all trap-version=2 /system clock set time-zone-name=America/Mexico_City /system identity set name=RT-OFICINA-Somnet /system logging add action=GrafanaLoki prefix=172.20.3.95 topics=critical add action=GrafanaLoki prefix=172.20.3.95 topics=error add action=GrafanaLoki prefix=172.20.3.95 topics=info add action=GrafanaLoki prefix=172.20.3.95 topics=warning /system ntp client set enabled=yes /system ntp client servers add address=0.mx.pool.ntp.org add address=1.mx.pool.ntp.org /system scheduler add interval=1w name=BK_Edi_Semanal on-event=BK_Edi_Semanal policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon start-date=2021-02-10 start-time=12:05:00 add interval=1w name=BK_Semanal on-event=Backup_Semanal policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon start-date=2021-02-10 start-time=12:00:00 /system script add dont-require-permissions=no name=Backup_Semanal owner=somnet policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=":local backuptime ([/system identity get name] . \"-\" . [:pick [/system clock get date] 4 6]. [:pick [/system clock get date] 0 3]. [:pick [/system clock get date] 7 11]);\r\n/system backup save name=\$backuptime;\r\nset \$backuptime (\$backuptime.\".backup\");\r\n:local dstpath (\"/backups/Binarios/\".\$backuptime);\r\n/tool fetch address=10.1.9.103 src-path=\$backuptime user=mkftp mode=ftp\_password=mkftp dst-path=\$dstpath upload=yes;\r\ndelay delay-time=2;\r\nfile remove \$backuptime;" add dont-require-permissions=no name=BK_Edi_Semanal owner=somnet policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=":local backupedi ([/system identity get name] . \"-\" . [:pick [/system clock get date] 4 6]. [:pick [/system clock get date] 0 3]. [:pick [/system clock get date] 7 11]);\r\n/export compact file=\$backupedi;\r\nset \$backupedi (\$backupedi.\".rsc\");\r\n:local dstpath2 (\"/backups/Editables/\".\$backupedi);\r\n/tool fetch address=10.1.9.103 src-path=\$backupedi user=mkftp mode=ftp password=mkftp dst-path=\$dstpath2 upload=yes\r\ndelay delay-time=2;\r\nfile remove \$backupedi;" /tool graphing interface add /tool graphing resource add /tool netwatch add disabled=no down-script=":local id -473048195;\r\n:local token 1405310170:AAE83Z70zwGsSnI7zijNMVd-KEv-0ppZgEY;\r\n\r\n/tool fetch url=\"https://api.telegram.org/bot\$token/sendmessage\\\?chat_id=\$id&text=VPN TEPETLIXPA *[ABAJO]*\"" host=192.168.254.33 interval=1m timeout=1s type=simple up-script=":local id -473048195;\r\n:local token 1405310170:AAE83Z70zwGsSnI7zijNMVd-KEv-0ppZgEY;\r\n\r\n/tool fetch url=\"https://api.telegram.org/bot\$token/sendmessage\\\?chat_id=\$id&text=VPN TEPETLIXPA *[ARRIBA]*\"" /tool sniffer set file-name=rt-of.cap filter-direction=rx filter-interface=ether7 /user aaa set default-group=full use-radius=yes