# version: 6.45.9 (long-term) # factory-software: 6.40 # total-memory: 256.0MiB # cpu: MIPS 1004Kc V2.15 # cpu-count: 4 # total-hdd-space: 16.3MiB # architecture-name: mmips # board-name: hEX # platform: MikroTik # installed-version: 6.45.9 # Flags: U - undoable, R - redoable, F - floating-undo # ACTION BY POLICY # U log action changed iper write # U log action changed iper write # U ip service changed iper write # U ip service changed iper write # # software id = JF0C-7RL0 # # model = RouterBOARD 750G r3 # serial number = 8AFF084BECA3 /interface bridge add name=bridge1 /interface ethernet set [ find default-name=ether1 ] comment="WAN infopasa" mac-address=CC:2D:E0:81:F4:BC name=ether1-wan speed=100Mbps set [ find default-name=ether2 ] comment=switch-atm mac-address=CC:2D:E0:81:F4:BD speed=100Mbps set [ find default-name=ether3 ] mac-address=CC:2D:E0:81:F4:BE speed=100Mbps set [ find default-name=ether4 ] comment=Servidor mac-address=CC:2D:E0:81:F4:BF speed=100Mbps set [ find default-name=ether5 ] mac-address=CC:2D:E0:81:F4:C0 speed=100Mbps /interface vlan add interface=ether2 name=vlan256-servidor-lages vlan-id=256 /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik /ip hotspot profile set [ find default=yes ] html-directory=flash/hotspot /ip pool add name=dhcp_pool0 ranges=200.200.200.30-200.200.200.254 add name=dhcp_pool1 ranges=200.200.200.25-200.200.200.35 /ip dhcp-server add address-pool=dhcp_pool1 disabled=no interface=bridge1 name=dhcp1 /ppp profile add dns-server=177.75.161.22 local-address=200.200.200.1 name="atm aurin" /queue simple add max-limit=100M/100M name=lages target=vlan256-servidor-lages /snmp community set [ find default=yes ] addresses=192.168.50.97/32 add addresses=45.163.12.9/32 name=brdrive add addresses=::/0 name=ipermonitor /system logging action add name=iper remote=45.163.13.106 remote-port=8514 src-address=177.75.160.206 target=remote /user group set read policy="local,telnet,ssh,ftp,read,test,winbox,web,sensitive,romon,dude,tikapp,!reboot,!write,!policy,!password,!sniff,!api" add name=suporte-nivel-2 policy="local,telnet,ftp,reboot,read,write,test,winbox,web,sniff,sensitive,!ssh,!policy,!password,!api,!romon,!dude,!tikapp" /interface bridge port add bridge=bridge1 interface=ether4 add bridge=bridge1 interface=vlan256-servidor-lages /ip neighbor discovery-settings set discover-interface-list=all /interface l2tp-server server set enabled=yes ipsec-secret=Atm2020 use-ipsec=yes /interface ovpn-server server set certificate=SERVER-ATM cipher=blowfish128,aes128,aes192,aes256 enabled=yes /interface pptp-server server set authentication=pap,chap,mschap1,mschap2 enabled=yes /ip address add address=177.75.160.206/30 interface=ether1-wan network=177.75.160.204 add address=200.200.200.1/24 interface=bridge1 network=200.200.200.0 /ip dhcp-server network add address=200.200.200.0/24 gateway=200.200.200.1 /ip dns set servers=177.75.161.22,177.75.161.23,8.8.8.8 /ip firewall address-list add address=45.163.12.252/30 list=src-wts-ok add address=192.168.0.0/16 list=src-wts-ok add list=src-block-acesso add address=45.163.14.252/30 list=src-wts-ok /ip firewall filter add action=drop chain=input comment=Bloqueando-DNS-Externo dst-port=53 in-interface=ether1-wan protocol=udp add action=drop chain=input comment=Bloqueando-DNS-Externo dst-port=53 in-interface=ether1-wan protocol=tcp add action=accept chain=forward dst-address=200.200.200.0/24 src-address=200.200.200.0/24 /ip firewall nat add action=masquerade chain=srcnat out-interface=ether1-wan add action=masquerade chain=srcnat add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=903 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.2 to-ports=903 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=902 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.2 to-ports=902 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=4433 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.2 to-ports=443 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=4431 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.5 to-ports=4431 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=9100 in-interface=ether1-wan protocol=tcp src-address=52.25.193.58 to-addresses=200.200.200.5 to-ports=9100 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=4432 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.5 to-ports=443 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=4434 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.5 to-ports=4434 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=8086 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.6 to-ports=8086 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=8087 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.6 to-ports=8087 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=33006 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.6 to-ports=33006 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=33007 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.6 to-ports=33007 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=4435 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.5 to-ports=4435 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=22 in-interface=ether1-wan protocol=tcp src-address=52.67.199.51 src-address-list="" to-addresses=200.200.200.5 to-ports=28022 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=28023 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.6 to-ports=22 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=28024 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.35 to-ports=22 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=36006 in-interface=ether1-wan protocol=tcp src-address=177.75.172.230 to-addresses=200.200.200.6 to-ports=3406 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=9104 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.6 to-ports=9104 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=9103 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.6 to-ports=9100 add action=dst-nat chain=dstnat disabled=yes dst-address=177.75.160.206 dst-port=19001 in-interface=ether1-wan protocol=tcp src-port="" to-addresses=200.200.200.5 to-ports=9001 add action=dst-nat chain=dstnat disabled=yes dst-address=177.75.160.206 dst-port=19000 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.5 to-ports=9000 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=443 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.5 to-ports=443 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=80 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.5 to-ports=80 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=4436 in-interface=ether1-wan protocol=tcp to-addresses=200.200.200.5 to-ports=4436 add action=dst-nat chain=dstnat dst-address=177.75.160.206 dst-port=4437 in-interface=ether1-wan protocol=tcp to-ports=4437 /ip route add distance=1 gateway=177.75.160.205 /ip service set telnet disabled=yes set ftp disabled=yes set www disabled=yes port=8080 set ssh port=2200 set api disabled=yes set winbox address="192.168.0.0/16,45.163.12.252/30,200.200.200.0/24,177.73.253.3/32,177.75.162.43/32,45.163.13.106/32" set api-ssl disabled=yes /ppp secret add local-address=200.200.200.1 name=paulo password=P@08042020 profile="atm aurin" remote-address=200.200.200.200 service=ovpn add local-address=200.200.200.1 name=atm password=atm@2020 profile="atm aurin" remote-address=200.200.200.201 service=l2tp add local-address=200.200.200.1 name=paulo-casa password="z\$&+)}K31Q74:T*" profile="atm aurin" remote-address=200.200.200.202 service=ovpn /radius add address=45.163.12.255 comment=myisp_chipset secret=rloginchipset service=login /snmp set contact=noc@iper.net.br enabled=yes location=br-sc-vii-vinhedo /system clock set time-zone-name=America/Sao_Paulo /system identity set name=atm-router-aurin /system logging add action=iper topics=info,!firewall /system ntp client set enabled=yes primary-ntp=177.75.161.10 secondary-ntp=200.144.121.33 /system resource irq rps set ether1-wan disabled=no set ether2 disabled=no set ether3 disabled=no set ether4 disabled=no set ether5 disabled=no /system scheduler add interval=1d name=script_backup_email on-event=script_backup_email policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon start-date=jan/01/1970 start-time=03:30:00 add interval=1d name=script_backup_ftp on-event=script_backup_ftp policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon start-date=jan/01/1970 start-time=03:00:00 /system script add dont-require-permissions=no name=script_backup_ftp owner=iper policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=":log info \"Iniciado Backup FTP\"\r\nexport file=backup-ftp\r\n/tool fetch address=ftp.iper.net.br port=8021 src-path=backup-ftp.rsc user=bkp.atm mode=ftp password=atm.bkp dst-path=([/system identity get name].\".rsc\") upload=yes\r\n:log info \"Terminado Backup FTP\"\r\n" add dont-require-permissions=no name=script_backup_email owner=iper policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=":log info \"Inciando Backup Email\"\r\nexport file=backup-email\r\n/tool e-mail send to=\"bkp.rb@iper.net.br\" subject=\"\$[/system identity get name]\" body=\"\$[/system clock get date]\" file=\"backup-email.rsc\"\r\n:log info \"Terminado Backup Email\"\r\n" /tool e-mail set address=45.163.12.11 from=envia.bkp@iper.net.br password=Iper@2022 port=587 start-tls=yes user=envia.bkp@iper.net.br /tool graphing interface add /tool graphing queue add /tool graphing resource add /user aaa set use-radius=yes