Está en la página 1de 4

/interface bridge

add admin-mac=64:D1:54:CB:AB:DA auto-mac=no comment="created from master port"


name=bridge1 protocol-mode=none
/interface ethernet
set [ find default-name=ether1 ] comment="Red You Win" mac-
address=C4:34:6B:1D:00:E0 name=ether1-Lan speed=100Mbps
set [ find default-name=ether2 ] comment=Monitoreo mac-address=C4:34:6B:2D:09:E1
speed=100Mbps
set [ find default-name=ether3 ] comment=Games disabled=yes mac-
address=C4:34:6B:3D:08:E2 speed=100Mbps
set [ find default-name=ether4 ] mac-address=C4:34:6B:4D:07:E3 speed=100Mbps
set [ find default-name=ether5 ] mac-address=C4:34:6B:5D:06:E4 speed=100Mbps
set [ find default-name=ether6 ] mac-address=C4:34:6B:6D:05:E5 speed=100Mbps
set [ find default-name=ether7 ] mac-address=C4:34:6B:7D:04:E6 speed=100Mbps
set [ find default-name=ether8 ] comment="200m nat 2" mac-address=C4:34:6B:8D:03:E7
speed=100Mbps
set [ find default-name=ether9 ] comment="80 Mb Doris\r\
\n" mac-address=C4:34:6B:9D:02:E8 speed=100Mbps
set [ find default-name=ether10 ] comment=80Mb mac-address=C4:34:6B:0D:01:E9
speed=100Mbps
set [ find default-name=sfp1 ] advertise=10M-half,10M-full,100M-half,100M-
full,1000M-half,1000M-full disabled=yes
/interface pppoe-client
add disabled=no interface=ether4 name=pppoe-out4 password=speedy user=speedy
add disabled=no interface=ether5 name=pppoe-out5 password=speedy user=speedy
/interface ovpn-client
add connect-to=hanantech.com disabled=yes mac-address=02:98:07:49:E3:4D
mode=ethernet name=ovpn-out1 password=soportemikrotik user=ovpn_supp
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip firewall layer7-protocol
add name=Youtube-Googlevideo regexp="r[0-9]+---[a-z]+-+[a-z0-9-]+-
+aphs\\.googlevideo\\.com"
add name=joyou regexp="^.+(youtube.com).*\$"
add name=videoplayback regexp=videoplayback|video
add name=L7-Netflix regexp="^.+(nflxvideo).*\$"
add name=netflix1 regexp="\"^.*(host|HOST).+(netflix).*\\\$\""
add name=netflix2 regexp="\"^.*(get|GET) /s.+(wma|wmv|token|random|p=).*\\\$\""
add name=L7-YOUTUBE regexp=googlevideo.com|youtube.com|ytimg.com
add name=L7-VIDEOFB regexp="^.*video.*\\.fbcdn\\.net.*\$"
add name=L7-STEAM regexp="^.*(\\.cs\\.steampowered\\.com)|(\\.steamcontent\\.com)|
(.*\\.wpc\\.xicdn\\.net).*\$"
add name="L7-Test de Velocidad" regexp="^.+(speedtest.net/es).*\$"
add comment="Actualizacion Windows 10" name=block-update-ms regexp=".(stats|
ntservicepack|update|download|windowsupdate|v4.windowsupdate).(microsoft|
windowsupdate)"
add comment="Actualizacion 2 Windows 10" name=block-update-msw regexp=".(wustat|ws|
v4.windowsupdate.microsoft|windowsupdate.microsoft).(nsatc|windows|microsoft)"
/queue simple
add max-limit=6M/30M name=PC1 target=192.168.11.101/32
add max-limit=3M/30M name=PC2 target=192.168.11.102/32
add max-limit=3M/30M name=PC3 target=192.168.11.103/32
add max-limit=1200k/15M name=PC37 target=192.168.11.137/32
add max-limit=3M/30M name=PC4 target=192.168.11.104/32
add max-limit=3M/30M name=PC5 target=192.168.11.105/32
add max-limit=3M/30M name=PC6 target=192.168.11.106/32
add max-limit=3M/30M name=PC7 target=192.168.11.107/32
add max-limit=3M/30M name=PC8 target=192.168.11.108/32
add max-limit=3M/30M name=PC9 target=192.168.11.109/32
add max-limit=3M/30M name=PC10 target=192.168.11.110/32
add max-limit=3M/30M name=PC11 target=192.168.11.111/32
add max-limit=3M/30M name=PC12 target=192.168.11.112/32
add max-limit=3M/40M name=PC13 target=192.168.11.113/32
add max-limit=3M/40M name=PC14 target=192.168.11.114/32
add max-limit=3M/30M name=PC15 target=192.168.11.115/32
add max-limit=3M/30M name=PC16 target=192.168.11.116/32
add max-limit=3M/30M name=PC17 target=192.168.11.117/32
add max-limit=3M/30M name=PC18 target=192.168.11.118/32
add max-limit=1200k/15M name=PC38 target=192.168.11.138/32
add max-limit=1200k/15M name=PC39 target=192.168.11.139/32
add max-limit=1200k/15M name=PC41 target=192.168.11.141/32
add max-limit=1200k/15M name=PC46 target=192.168.11.146/32
add max-limit=1200k/15M name=PC52 target=192.168.11.152/32
add max-limit=1200k/15M name=PC51 target=192.168.11.151/32
add max-limit=1200k/15M name=PC50 target=192.168.11.150/32
add max-limit=1200k/15M name=PC49 target=192.168.11.149/32
add max-limit=1200k/15M name=PC48 target=192.168.11.148/32
add max-limit=1200k/15M name=PC47 target=192.168.11.147/32
add max-limit=1200k/15M name=PC45 target=192.168.11.145/32
add max-limit=1200k/15M name=PC44 target=192.168.11.144/32
add max-limit=1200k/15M name=PC43 target=192.168.11.143/32
add max-limit=1200k/15M name=PC42 target=192.168.11.142/32
add max-limit=1200k/15M name=PC40 target=192.168.11.140/32
add max-limit=1500k/15M name=PC19 target=192.168.11.119/32
add max-limit=1200k/15M name=PC20 target=192.168.11.120/32
add max-limit=1200k/15M name=PC21 target=192.168.11.121/32
add max-limit=1200k/15M name=PC23 target=192.168.11.123/32
add max-limit=1200k/15M name=PC24 target=192.168.11.124/32
add max-limit=1200k/15M name=PC25 target=192.168.11.125/32
add max-limit=1200k/15M name=PC26 target=192.168.11.126/32
add max-limit=1200k/15M name=PC27 target=192.168.11.127/32
add max-limit=1200k/15M name=PC28 target=192.168.11.128/32
add max-limit=1200k/15M name=PC29 target=192.168.11.129/32
add max-limit=1200k/15M name=PC30 target=192.168.11.130/32
add max-limit=1200k/15M name=PC31 target=192.168.11.131/32
add max-limit=1200k/15M name=PC35 target=192.168.11.135/32
add max-limit=1200k/15M name=PC34 target=192.168.11.134/32
add max-limit=1200k/15M name=PC32 target=192.168.11.132/32
add max-limit=1200k/15M name=PC33 target=192.168.11.133/32
add max-limit=1200k/15M name=PC36 target=192.168.11.136/32
add disabled=yes max-limit=5M/50M name=Administrador target=192.168.11.100/32
/queue tree
add name=queue1 parent=global
/snmp community
set [ find default=yes ] addresses=0.0.0.0/0
/interface bridge port
add bridge=bridge1 interface=ether2
add bridge=bridge1 interface=ether1-Lan
/ip address
add address=192.168.11.1/24 interface=bridge1 network=192.168.11.0
add address=192.168.100.4 comment="HFC Multimedia" disabled=yes interface=ether10
network=192.168.100.4
add address=192.168.10.4/24 interface=ether10 network=192.168.10.0
/ip cloud
set ddns-enabled=yes
/ip dhcp-client
add add-default-route=no dhcp-options=hostname,clientid disabled=no
interface=ether9 use-peer-dns=no use-peer-ntp=no
add add-default-route=no dhcp-options=hostname,clientid interface=ether3 use-peer-
dns=no use-peer-ntp=no
add add-default-route=no dhcp-options=hostname,clientid interface=ether10 use-peer-
dns=no use-peer-ntp=no
add add-default-route=no dhcp-options=hostname,clientid disabled=no
interface=ether8 use-peer-dns=no use-peer-ntp=no
/ip dns
set allow-remote-requests=yes servers=8.8.8.8,8.8.4.4
/ip firewall filter
add action=add-dst-to-address-list address-list=YOUTUBE_LIST_FILTRO address-list-
timeout=10m chain=forward comment="Ruteo Youtube" connection-
state=established,related dst-port=443 layer7-protocol=L7-YOUTUBE protocol=tcp
add action=add-dst-to-address-list address-list=STEAM_IP_LIST address-list-
timeout=10m chain=forward comment="Ruteo Steam" in-interface=bridge1 layer7-
protocol=L7-STEAM
add action=add-dst-to-address-list address-list=VIDEOFB_LIST_FILTRO address-list-
timeout=10m chain=forward comment="Ruteo Facebook" connection-
state=established,related dst-port=443 layer7-protocol=L7-VIDEOFB protocol=tcp
add action=add-dst-to-address-list address-list=Netflix_list_Filtro address-list-
timeout=10m chain=forward comment="Ruteo Netflix" connection-
state=established,related disabled=yes dst-port=443 layer7-protocol=L7-Netflix
protocol=tcp
add action=drop chain=forward comment=Block-Update-Windows layer7-protocol=block-
update-ms
add action=drop chain=forward layer7-protocol=block-update-msw
/ip firewall mangle
add action=mark-routing chain=prerouting comment="Ruteo Youtube" disabled=yes dst-
address-list=YOUTUBE_LIST_FILTRO in-interface=bridge1 new-routing-
mark=mark_route_youtube passthrough=no
add action=mark-routing chain=prerouting comment="Ruteo Netflix" disabled=yes dst-
address-list=Netflix_list_Filtro in-interface=bridge1 new-routing-
mark=mark_route_Netflix passthrough=no
add action=mark-routing chain=prerouting comment="Ruteo Facebook" disabled=yes dst-
address-list=VIDEOFB_LIST_FILTRO in-interface=bridge1 new-routing-
mark=mark_route_facebook passthrough=no
add action=mark-connection chain=prerouting comment="Ruteo Steam" connection-
state=new disabled=yes dst-address-list=STEAM_IP_LIST in-interface=bridge1 new-
connection-mark=steam_downloads passthrough=yes
add action=mark-routing chain=prerouting connection-mark=steam_downloads
disabled=yes in-interface=bridge1 new-routing-mark=to_hfc1 passthrough=no
add action=mark-connection chain=prerouting comment=gm connection-mark=no-mark
connection-state=new disabled=yes dst-port=27000-28000 in-interface=bridge1 new-
connection-mark=conn_wan3 passthrough=yes protocol=udp
add action=mark-connection chain=prerouting connection-mark=no-mark connection-
state=new disabled=yes dst-port=4380,7000-7999 in-interface=bridge1 new-connection-
mark=conn_wan3 passthrough=yes protocol=udp
add action=mark-connection chain=prerouting connection-mark=no-mark connection-
state=new disabled=yes dst-port=5222,9000-9090,6666,6250 in-interface=bridge1 new-
connection-mark=conn_wan3 passthrough=yes protocol=udp
add action=mark-connection chain=prerouting connection-mark=no-mark connection-
state=new disabled=yes dst-port=1119,1120,3478-
3479,3724,5060,5062,6113,6120,6250,12000-64000 in-interface=bridge1 new-connection-
mark=conn_wan3 passthrough=yes protocol=\
udp
add action=mark-connection chain=prerouting connection-mark=no-mark connection-
state=new disabled=yes dst-port=27000-28000 in-interface=bridge1 new-connection-
mark=conn_wan3 passthrough=yes protocol=tcp
add action=mark-connection chain=prerouting connection-mark=no-mark connection-
state=new disabled=yes dst-port=1119,3724,6112-6119 in-interface=bridge1 new-
connection-mark=conn_wan3 passthrough=yes protocol=tcp
add action=mark-routing chain=prerouting connection-mark=conn_wan3 disabled=yes in-
interface=bridge1 new-routing-mark=to_wan3 passthrough=no
add action=mark-connection chain=prerouting comment=BL connection-mark=no-mark
connection-state=new dst-address-type=!local in-interface=bridge1 new-connection-
mark=conn_wan8 passthrough=yes per-connection-classifier=both-addresses-and-
ports:4/0
add action=mark-connection chain=prerouting connection-mark=no-mark connection-
state=new dst-address-type=!local in-interface=bridge1 new-connection-
mark=conn_wan8 passthrough=yes per-connection-classifier=both-addresses-and-
ports:4/2
add action=mark-connection chain=prerouting connection-mark=no-mark connection-
state=new dst-address-type=!local in-interface=bridge1 new-connection-
mark=conn_wan9 passthrough=yes per-connection-classifier=both-addresses-and-
ports:4/1
add action=mark-connection chain=prerouting connection-mark=no-mark connection-
state=new dst-address-type=!local in-interface=bridge1 new-connection-
mark=conn_wan10 passthrough=yes per-connection-classifier=both-addresses-and-
ports:4/3
add action=mark-routing chain=prerouting connection-mark=conn_wan8 in-
interface=bridge1 new-routing-mark=to_wan8 passthrough=no
add action=mark-routing chain=prerouting connection-mark=conn_wan9 in-
interface=bridge1 new-routing-mark=to_wan9 passthrough=no
add action=mark-routing chain=prerouting connection-mark=conn_wan10 in-
interface=bridge1 new-routing-mark=to_wan10 passthrough=no
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether10
add action=masquerade chain=srcnat out-interface=ether9
add action=masquerade chain=srcnat out-interface=ether8
add action=masquerade chain=srcnat out-interface=ether3
add action=masquerade chain=srcnat out-interface=pppoe-out4
add action=masquerade chain=srcnat out-interface=pppoe-out5
/ip route
add disabled=yes distance=1 gateway=192.168.10.1 routing-mark=mark_route_youtube
add disabled=yes distance=1 gateway=192.168.10.1 routing-mark=mark_route_Netflix
add disabled=yes distance=1 gateway=192.168.10.1 routing-mark=mark_route_facebook
add disabled=yes distance=1 gateway=192.168.10.1 routing-mark=to_hfc1
add disabled=yes distance=1 gateway=pppoe-out4,pppoe-out5 routing-mark=to_wan3
add distance=1 gateway=192.168.8.1 routing-mark=to_wan8
add distance=1 gateway=192.168.5.1 routing-mark=to_wan9
add distance=1 gateway=192.168.10.1 routing-mark=to_wan10
add distance=1 gateway=192.168.8.1
add distance=2 gateway=192.168.5.1
add distance=3 gateway=192.168.10.1
/lcd
set backlight-timeout=never color-scheme=light
/lcd interface
add interface=bridge1
/lcd interface pages
set 0
interfaces=bridge1,ether2,ether3,ether4,ether5,sfp1,ether6,ether7,ether8,ether9,eth
er10
/system clock
set time-zone-name=America/Lima
/system identity
set name="You Win SAC"
/tool romon
set enabled=yes

También podría gustarte