# version: 7.17rc3 (testing) # factory-software: 6.49.5 # total-memory: 256.0MiB # cpu: MIPS 1004Kc V2.15 # cpu-count: 4 # total-hdd-space: 16.0MiB # architecture-name: mmips # board-name: hEX S # platform: MikroTik # installed-version: 7.17rc3 # # software id = F2GP-I5ZQ # # model = RB760iGS # serial number = HF409DAK766 /interface bridge add admin-mac=78:9A:18:6D:7B:78 auto-mac=no comment=defconf name=BRLAN port-cost-mode=short /interface ethernet set [ find default-name=ether5 ] poe-out=forced-on /interface list add comment=defconf name=WAN add comment=defconf name=LAN /interface lte apn set [ find default=yes ] ip-type=ipv4 use-network-apn=no /ip pool add name=default-dhcp ranges=192.168.88.10-192.168.88.254 add name=dhcp_pool1 ranges=192.168.1.200-192.168.1.254 add name=dhcp_pool2 ranges=192.168.1.2-192.168.1.25 /ip dhcp-server add address-pool=dhcp_pool2 interface=BRLAN name=dhcp1 /snmp community set [ find default=yes ] name=SNMP-SOMNET /system logging action add bsd-syslog=yes name=GrafanaLoki remote=172.20.0.254 remote-port=1514 src-address=172.20.4.124 target=remote /interface bridge port add bridge=BRLAN comment=defconf ingress-filtering=no interface=ether3 internal-path-cost=10 path-cost=10 add bridge=BRLAN comment=defconf ingress-filtering=no interface=ether4 internal-path-cost=10 path-cost=10 add bridge=BRLAN comment=defconf ingress-filtering=no interface=ether5 internal-path-cost=10 path-cost=10 add bridge=BRLAN comment=defconf ingress-filtering=no interface=sfp1 internal-path-cost=10 path-cost=10 add bridge=BRLAN interface=ether1 add bridge=BRLAN interface=ether2 /ip firewall connection tracking set udp-timeout=10s /ip neighbor discovery-settings set discover-interface-list=all lldp-mac-phy-config=yes lldp-max-frame-size=yes lldp-vlan-info=yes /ipv6 settings set disable-ipv6=yes max-neighbor-entries=8192 /interface list member add comment=defconf interface=BRLAN list=LAN add comment=defconf interface=ether1 list=WAN /interface ovpn-server server add auth=sha1,md5 mac-address=FE:C8:29:8F:EF:D4 name=ovpn-server1 /ip address add address=172.20.4.124/16 interface=BRLAN network=172.20.0.0 /ip dhcp-server network add address=192.168.1.0/24 dns-server=1.1.1.1 gateway=192.168.1.1 /ip dns set allow-remote-requests=yes servers=1.1.1.2,1.0.0.2 /ip dns static add address=192.168.88.1 comment=defconf name=router.lan type=A /ip firewall filter add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1 add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related hw-offload=yes add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN /ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface=BRLAN /ip hotspot profile set [ find default=yes ] html-directory=hotspot /ip ipsec profile set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5 /ip route add disabled=no dst-address=0.0.0.0/0 gateway=172.20.1.1 routing-table=main suppress-hw-offload=no /ip service set telnet disabled=yes set ftp disabled=yes set ssh port=46825 set api disabled=yes set api-ssl disabled=yes /radius add address=172.20.6.1 secret=Fr3eR4d!u5 service=login /routing bfd configuration add disabled=no interfaces=all min-rx=200ms min-tx=200ms multiplier=5 /snmp set enabled=yes trap-version=2 /system clock set time-zone-name=America/Mexico_City /system identity set name="SW Rancho-Alegre" /system logging add action=GrafanaLoki prefix=172.20.4.124 topics=critical add action=GrafanaLoki prefix=172.20.4.124 topics=error add action=GrafanaLoki prefix=172.20.4.124 topics=info add action=GrafanaLoki prefix=172.20.4.124 topics=warning /system note set show-at-login=no /system ntp client set enabled=yes /system ntp client servers add address=0.mx.pool.ntp.org add address=1.mx.pool.ntp.org /tool graphing interface add /tool graphing resource add /tool mac-server set allowed-interface-list=LAN /tool mac-server mac-winbox set allowed-interface-list=LAN /tool sniffer set file-name=CPV1.CAP filter-direction=rx filter-interface=ether5 /user aaa set default-group=full use-radius=yes