Код: Выделить всё
/interface bridge
add name=bridge_inet protocol-mode=none
add name=bridge_local protocol-mode=none
/interface ethernet
set [ find default-name=ether1 ] name=ether1_Vlan
set [ find default-name=ether2 ] disabled=yes name=ether2_inet
set [ find default-name=ether3 ] name=ether3_inet
set [ find default-name=ether4 ] name=ether4_local
set [ find default-name=ether5 ] disabled=yes name=ether5_local
/interface vlan
add interface=ether1_Vlan name=vlan10_inet vlan-id=10
add interface=ether1_Vlan name=vlan20_local vlan-id=20
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip ipsec proposal
set [ find default=yes ] enc-algorithms=aes-128-cbc
/interface bridge port
add bridge=bridge_inet interface=vlan10_inet
add bridge=bridge_local interface=vlan20_local
add bridge=bridge_inet disabled=yes interface=ether2_inet
add bridge=bridge_inet interface=ether3_inet
add bridge=bridge_local interface=ether4_local
add bridge=bridge_local disabled=yes interface=ether5_local
/interface bridge settings
set use-ip-firewall-for-vlan=yes
/ip address
add address=192.168.7.8/24 interface=vlan10_inet network=192.168.7.0
add address=192.168.1.238/24 interface=vlan20_local network=192.168.1.0
/ip dns
set servers=192.168.7.7
/ip firewall filter
add chain=input connection-state=established
/ip route
add distance=1 gateway=192.168.7.7