# version: 7.23.2 (stable) # factory-software: 6.7 # total-memory: 128.0MiB # cpu: MIPS 74Kc V4.12 # cpu-count: 1 # total-hdd-space: 128.0MiB # architecture-name: mipsbe # board-name: RB2011UiAS # platform: MikroTik # installed-version: 7.23.2 # Flags: U - UNDOABLE # Columns: ACTION, BY, POLICY, TIME # ACTION BY POLICY TIME # U route 0.0.0.0/0 changed brayan write 2026-08-12 17:45:38 # U route 0.0.0.0/0 added brayan write 2026-08-12 17:00:27 # U address changed brayan write 2026-08-12 16:59:57 # U address added brayan write 2026-08-12 16:59:47 # # software id = NK1S-BIBJ # # model = RB2011UiAS # serial number = 8C1808B3D022 /interface bridge add name=LAN port-cost-mode=short add name="bridge WAN" port-cost-mode=short /interface ethernet set [ find default-name=ether1 ] l2mtu=1598 name="ether1 - WAN" set [ find default-name=ether2 ] l2mtu=1598 set [ find default-name=ether3 ] l2mtu=1598 set [ find default-name=ether4 ] l2mtu=1598 set [ find default-name=ether5 ] l2mtu=1598 set [ find default-name=ether8 ] disabled=yes set [ find default-name=sfp1 ] advertise="10M-baseT-half,10M-baseT-full,100M-baseT-half,100M-baseT-full,1G-baseT-half,1G-baseT-full" l2mtu=1598 /interface lte apn set [ find default=yes ] ip-type=ipv4 use-network-apn=no /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik add authentication-types=wpa-psk,wpa2-psk eap-methods="" management-protection=allowed mode=dynamic-keys name=profile1 supplicant-identity="" wpa-pre-shared-key=987654321 wpa2-pre-shared-key=987654321 /ip pool add name=dhcp_pool0 ranges=192.168.101.2-192.168.101.254 /ip dhcp-server add address-pool=dhcp_pool0 interface=LAN lease-time=10m name=dhcp1 /ip smb users set [ find default=yes ] disabled=yes /snmp community add addresses=::/0 name=SNMP-SOMNET /system logging action add name=GrafanaLoki remote=172.20.0.254 remote-log-format=syslog remote-port=1514 src-address=172.20.1.224 target=remote /interface bridge port add bridge=LAN ingress-filtering=no interface=ether3 internal-path-cost=10 path-cost=10 add bridge=LAN ingress-filtering=no interface=ether4 internal-path-cost=10 path-cost=10 add bridge=LAN ingress-filtering=no interface=ether6 internal-path-cost=10 path-cost=10 add bridge=LAN ingress-filtering=no interface=ether7 internal-path-cost=10 path-cost=10 add bridge=LAN ingress-filtering=no interface=ether8 internal-path-cost=10 path-cost=10 add bridge=LAN ingress-filtering=no interface=ether9 internal-path-cost=10 path-cost=10 add bridge=LAN ingress-filtering=no interface=ether10 internal-path-cost=10 path-cost=10 add bridge=LAN ingress-filtering=no interface=sfp1 internal-path-cost=10 path-cost=10 add bridge=LAN ingress-filtering=no interface=ether5 internal-path-cost=10 path-cost=10 add bridge=LAN ingress-filtering=no interface=ether2 internal-path-cost=10 path-cost=10 /ip firewall connection tracking set udp-timeout=10s /ip neighbor discovery-settings set discover-interface-list=!dynamic /ip settings set max-neighbor-entries=8192 /ipv6 settings set disable-ipv6=yes max-neighbor-entries=8192 /interface ovpn-server server add auth=sha1,md5 mac-address=FE:90:31:C8:FD:2A name=ovpn-server1 /ip address add address=192.168.101.1/24 comment=LAN interface=LAN network=192.168.101.0 add address=38.123.220.99/24 comment="IP PUBLICA SOMNET" interface="ether1 - WAN" network=38.123.220.0 add address=172.20.1.224/16 comment="IP REDUNDANCIA SOMNET" interface="ether1 - WAN" network=172.20.0.0 add address=38.58.38.11/24 comment="IP Somnet" interface="ether1 - WAN" network=38.58.38.0 /ip dhcp-server network add address=192.168.101.0/24 dns-server=4.2.2.1,8.8.8.8 gateway=192.168.101.1 /ip dns set servers=1.1.1.2,1.0.0.2 /ip firewall nat add action=masquerade chain=srcnat comment="NAT DEFECTO SOMNET" out-interface="ether1 - WAN" /ip ipsec profile set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5 /ip route add check-gateway=ping comment=DEFECTO disabled=no distance=10 dst-address=0.0.0.0/0 gateway=38.123.220.1 routing-table=main scope=30 target-scope=10 add check-gateway=ping disabled=no distance=2 dst-address=0.0.0.0/0 gateway=38.58.38.1 routing-table=main /ip service set ftp disabled=yes set telnet disabled=yes set www port=8080 set api disabled=yes set api-ssl disabled=yes set ssh port=46825 /ipv6 nd set [ find default=yes ] advertise-dns=yes /lcd set time-interval=daily /radius add address=172.20.6.1 require-message-auth=no secret=Fr3eR4d!u5 service=login timeout=300ms /routing bfd configuration add disabled=no /snmp set contact=SOMNET enabled=yes location="ICATI CENTRAL" trap-community=SNMP-SOMNET trap-interfaces=all trap-version=2 /system clock set time-zone-name=America/Mexico_City /system identity set name=MK_ICATICentral /system logging add action=GrafanaLoki prefix=172.20.1.224 topics=critical add action=GrafanaLoki prefix=172.20.1.224 topics=error add action=GrafanaLoki prefix=172.20.1.224 topics=info add action=GrafanaLoki prefix=172.20.1.224 topics=warning /system ntp client set enabled=yes /system ntp client servers add address=193.182.111.13 add address=192.36.143.130 /tool graphing interface add /tool graphing queue add /tool graphing resource add /user aaa set default-group=full use-radius=yes