|
本帖最后由 Baishui 于 2024-7-21 23:23 编辑
- /interface bridge
- add comment=defconf ingress-filtering=no name=bridge port-cost-mode=short vlan-filtering=yes
- /interface ethernet
- set [ find default-name=ether1 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=ether2 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=ether3 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=ether4 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=ether5 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=ether6 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=ether7 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=ether8 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=ether9 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=ether10 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=ether11 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=ether12 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=ether13 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=sfp-sfpplus1 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=sfp-sfpplus2 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=sfp-sfpplus3 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- set [ find default-name=sfp-sfpplus4 ] l2mtu=9570 mtu=9014 rx-flow-control=on tx-flow-control=on
- /interface vlan
- add interface=bridge name=vlan15 vlan-id=15
- add interface=bridge name=vlan20 vlan-id=20
- add interface=bridge name=vlan25 vlan-id=25
- add interface=bridge name=vlan35 vlan-id=35
- add interface=bridge name=vlan809 vlan-id=809
- /interface bonding
- add mode=802.3ad mtu=9014 name=crs510 slaves=sfp-sfpplus1,sfp-sfpplus2 transmit-hash-policy=layer-3-and-4
- /interface pppoe-client
- add add-default-route=yes disabled=no interface=vlan809 keepalive-timeout=60 name=pppoe-out1 use-peer-dns=yes user=xxx
- /disk
- set nvme1 media-interface=none media-sharing=no
- /interface ethernet switch
- set 0 l3-hw-offloading=yes qos-hw-offloading=yes
- /interface list
- add name=WAN
- add name=LAN
- /interface wireless security-profiles
- set [ find default=yes ] supplicant-identity=MikroTik
- /ip dhcp-server
- add address-pool=dhcp_pool0 interface=bridge lease-time=10m name=dhcp1
- add address-pool=dhcp_pool1 interface=vlan15 lease-time=10m name=dhcp2
- add address-pool=dhcp_pool2 interface=vlan25 lease-time=10m name=dhcp3
- /ip smb users
- set [ find default=yes ] disabled=yes
- /ipv6 pool
- add name=common prefix=::/0 prefix-length=63
- /port
- set 0 name=serial0
- /interface bridge port
- add bridge=bridge comment=defconf disabled=yes ingress-filtering=no interface=sfp-sfpplus1 internal-path-cost=10 path-cost=10
- add bridge=bridge comment=defconf disabled=yes ingress-filtering=no interface=sfp-sfpplus2 internal-path-cost=10 path-cost=10
- add bridge=bridge comment=defconf ingress-filtering=no interface=sfp-sfpplus3 internal-path-cost=10 path-cost=10
- add bridge=bridge comment=defconf ingress-filtering=no interface=sfp-sfpplus4 internal-path-cost=10 path-cost=10 pvid=809
- add bridge=bridge comment=defconf ingress-filtering=no interface=ether1 internal-path-cost=10 path-cost=10
- add bridge=bridge comment=defconf ingress-filtering=no interface=ether2 internal-path-cost=10 path-cost=10
- add bridge=bridge comment=defconf ingress-filtering=no interface=ether3 internal-path-cost=10 path-cost=10
- add bridge=bridge comment=defconf ingress-filtering=no interface=ether4 internal-path-cost=10 path-cost=10
- add bridge=bridge comment=defconf ingress-filtering=no interface=ether5 internal-path-cost=10 path-cost=10
- add bridge=bridge comment=defconf ingress-filtering=no interface=ether6 internal-path-cost=10 path-cost=10
- add bridge=bridge comment=defconf ingress-filtering=no interface=ether7 internal-path-cost=10 path-cost=10
- add bridge=bridge comment=defconf ingress-filtering=no interface=ether8 internal-path-cost=10 path-cost=10
- add bridge=bridge comment=defconf ingress-filtering=no interface=ether9 internal-path-cost=10 path-cost=10
- add bridge=bridge comment=defconf ingress-filtering=no interface=ether10 internal-path-cost=10 path-cost=10
- add bridge=bridge comment=defconf ingress-filtering=no interface=ether11 internal-path-cost=10 path-cost=10 pvid=15
- add bridge=bridge comment=defconf ingress-filtering=no interface=ether12 internal-path-cost=10 path-cost=10 pvid=15
- add bridge=bridge interface=crs510 internal-path-cost=10 path-cost=10
- add bridge=bridge comment=defconf disabled=yes ingress-filtering=no interface=sfp-sfpplus1 internal-path-cost=10 path-cost=10
- add bridge=bridge comment=defconf disabled=yes ingress-filtering=no interface=sfp-sfpplus2 internal-path-cost=10 path-cost=10
- /interface ethernet switch l3hw-settings
- set ipv6-hw=yes
- /ip firewall connection tracking
- set udp-timeout=10s
- /ip neighbor discovery-settings
- set discover-interface-list=all lldp-mac-phy-config=yes
- /ip settings
- set max-neighbor-entries=8192
- /ipv6 settings
- set disable-ipv6=yes max-neighbor-entries=8192
- /interface bridge vlan
- add bridge=bridge tagged=bridge vlan-ids=809
- add bridge=bridge tagged=bridge vlan-ids=35
- add bridge=bridge tagged=bridge,crs510,sfp-sfpplus3 vlan-ids=15
- add bridge=bridge tagged=bridge,crs510,sfp-sfpplus3 vlan-ids=25
- add bridge=bridge tagged=bridge,crs510,sfp-sfpplus3 vlan-ids=20
- /interface ethernet switch rule
- add comment="allow 15 dns" dst-address=192.168.15.0/28 dst-port=53 mac-protocol=ip ports=\
- sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12 \
- protocol=udp src-address=192.168.15.0/24 switch=switch1
- add comment="drop 15 to gw" dst-address=192.168.15.0/28 mac-protocol=ip new-dst-ports=ether12 ports=\
- sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12 \
- src-address=192.168.15.0/24 switch=switch1
- add comment="allow 15 to 15" dst-address=192.168.15.0/24 mac-protocol=ip ports=\
- sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12 \
- src-address=192.168.15.0/24 switch=switch1
- add comment="drop 15 to 192" dst-address=192.168.0.0/16 mac-protocol=ip new-dst-ports=ether12 ports=\
- sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12 \
- src-address=192.168.15.0/24 switch=switch1
- add comment="allow 25 dns" dst-address=192.168.25.0/28 dst-port=53 mac-protocol=ip ports=\
- sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12 \
- protocol=udp src-address=192.168.25.0/24 switch=switch1
- add comment="allow 15 dns" dst-address=192.168.15.0/28 dst-port=53 mac-protocol=ip ports=\
- sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12 \
- protocol=udp src-address=192.168.15.0/24 switch=switch1
- add comment="drop 15 to gw" dst-address=192.168.15.0/28 mac-protocol=ip new-dst-ports=ether12 ports=\
- sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12 \
- src-address=192.168.15.0/24 switch=switch1
- add comment="allow 15 to 15" dst-address=192.168.15.0/24 mac-protocol=ip ports=\
- sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12 \
- src-address=192.168.15.0/24 switch=switch1
- add comment="drop 15 to 192" dst-address=192.168.0.0/16 mac-protocol=ip new-dst-ports=ether12 ports=\
- sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12 \
- src-address=192.168.15.0/24 switch=switch1
- add comment="allow 25 dns" dst-address=192.168.25.0/28 dst-port=53 mac-protocol=ip ports=\
- sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12 \
- protocol=udp src-address=192.168.25.0/24 switch=switch1
- add comment="drop 25 to gw" dst-address=192.168.25.0/28 mac-protocol=ip new-dst-ports=ether12 ports=\
- sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12 \
- src-address=192.168.25.0/24 switch=switch1
- add comment="allow 25 to 25" dst-address=192.168.25.0/24 mac-protocol=ip ports=\
- sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12 \
- src-address=192.168.25.0/24 switch=switch1
- add comment="drop 25 to 192" dst-address=192.168.0.0/16 mac-protocol=ip new-dst-ports=ether12 ports=\
- sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12 \
- src-address=192.168.25.0/24 switch=switch1
- /interface list member
- add interface=sfp-sfpplus1 list=LAN
- add interface=sfp-sfpplus2 list=LAN
- add interface=sfp-sfpplus3 list=LAN
- add interface=sfp-sfpplus4 list=LAN
- add interface=ether1 list=LAN
- add interface=ether2 list=LAN
- add interface=ether3 list=LAN
- add interface=ether4 list=LAN
- add interface=ether5 list=LAN
- add interface=ether6 list=LAN
- add interface=ether7 list=LAN
- add interface=ether8 list=LAN
- add interface=ether9 list=LAN
- add interface=ether10 list=LAN
- add interface=ether11 list=LAN
- add interface=ether12 list=LAN
- add interface=vlan809 list=WAN
- add interface=crs510 list=WAN
- add interface=pppoe-out1 list=WAN
- /interface o**-server server
- set auth=sha1,md5
- /ip dns
- set allow-remote-requests=yes
- /ip firewall filter
- add action=accept chain=input comment="accept established,related" connection-state=established,related in-interface-list=WAN
- add action=drop chain=input connection-state=invalid in-interface-list=WAN
- add action=drop chain=input comment="block everything else" in-interface-list=WAN
- add action=fasttrack-connection chain=forward comment="fast-track for established,related" connection-state=established,related hw-offload=yes \
- in-interface-list=WAN
- add action=accept chain=forward comment="accept established,related" connection-state=established,related in-interface-list=WAN
- add action=drop chain=forward connection-state=invalid in-interface-list=WAN
- add action=drop chain=forward comment="drop access to clients behind NAT form WAN" connection-nat-state=!dstnat connection-state=new \
- in-interface-list=WAN
- /ip firewall mangle
- add action=change-mss chain=forward new-mss=clamp-to-pmtu passthrough=yes protocol=tcp tcp-flags=syn
- /ip firewall nat
- add action=masquerade chain=srcnat out-interface-list=WAN
- add action=dst-nat chain=dstnat dst-port=46881 in-interface-list=WAN protocol=tcp to-addresses=192.168.5.4 to-ports=81
- add action=dst-nat chain=dstnat dst-port=32163 in-interface-list=WAN protocol=tcp to-addresses=192.168.5.4 to-ports=63
- add action=dst-nat chain=dstnat dst-port=33956 in-interface-list=WAN protocol=tcp to-addresses=192.168.5.4 to-ports=56
- add action=dst-nat chain=dstnat dst-port=33956 in-interface-list=WAN protocol=udp to-addresses=192.168.5.4 to-ports=56
- add action=dst-nat chain=dstnat dst-port=56816 in-interface-list=WAN protocol=tcp to-addresses=192.168.5.4 to-ports=16
- /ip nat-pmp
- set enabled=yes
- /ip nat-pmp interfaces
- add interface=pppoe-out1 type=external
- add interface=bridge type=internal
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set api disabled=yes
- set api-ssl disabled=yes
- /ip smb shares
- set [ find default=yes ] directory=/flash/pub
- /ip upnp
- set allow-disable-external-interface=yes enabled=yes
- /ip upnp interfaces
- add interface=pppoe-out1 type=external
- add interface=bridge type=internal
- /routing bfd configuration
- add disabled=no
- /system clock
- set time-zone-name=Asia/Shanghai
- /system gps
- set port=usb2
- /system logging
- add action=remote
- /system note
- set show-at-login=no
- /system ntp client
- set enabled=yes
- /system ntp client servers
- add address=cn.ntp.org.cn
复制代码 |
|