# aug/13/2014 17:44:17 by RouterOS 5.23
# software id = UZ50-DXUR
#
/interface ethernet
set 0 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited \
    disabled=no full-duplex=yes l2mtu=1598 mac-address=00:0C:42:E6:B1:C1 \
    master-port=none mtu=1500 name=ether1-gateway speed=1Gbps
set 1 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited \
    disabled=no full-duplex=yes l2mtu=1598 mac-address=00:0C:42:E6:B1:C2 \
    master-port=none mtu=1500 name=ether2-master-local speed=1Gbps
...
/interface vlan
add arp=enabled disabled=no interface=\
    ether2-master-local l2mtu=1594 mtu=1500 name=vlan52 use-service-tag=no \
    vlan-id=52
add arp=enabled comment=Management disabled=no interface=ether2-master-local \
    l2mtu=1594 mtu=1500 name=vlan1 use-service-tag=no vlan-id=1
add arp=enabled disabled=no interface=\
    ether2-master-local l2mtu=1594 mtu=1500 name=vlan45 use-service-tag=no \
    vlan-id=45
...
	
/ip pool
add name=default-dhcp ranges=192.168.88.10-192.168.88.254
add name="Restoran str18" ranges=10.79.6.67-10.79.6.94
add name=SIP ranges=10.40.20.100-10.40.20.200
add name=Stokros ranges=10.79.5.194-10.79.5.222
add name="Kondicionery bol6" ranges=10.79.3.18-10.79.3.30
add name="Profit Concept STR18-204" ranges=10.79.5.180-10.79.5.190
add name=Guests ranges=192.168.40.50-192.168.40.250
add name="Kadashevkiy first per 11\\5" ranges=10.79.7.50-10.79.7.100
add name="str18 Artemjev" ranges=10.79.4.162-10.79.4.174
add name="Artemjev STR18-39" ranges=10.79.5.34-10.79.5.63
add name=SpecStroyObjedinenie_Bol18 ranges=10.79.3.194-10.79.3.206
add name=Avangard ranges=10.79.6.50-10.79.6.62
/ip dhcp-server
add add-arp=yes address-pool="Restoran str18" authoritative=after-2sec-delay \
    disabled=no interface=vlan9 lease-time=3h name="Restoran str18"
add add-arp=yes address-pool=SIP authoritative=after-2sec-delay disabled=no \
    interface=vlan110 lease-time=1d name=SIP
add add-arp=yes address-pool=Stokros authoritative=after-2sec-delay disabled=\
    no interface=vlan46 lease-time=6h name=Stokros
add add-arp=yes address-pool="Kondicionery bol6" authoritative=\
    after-2sec-delay bootp-support=static disabled=yes interface=vlan8 \
    lease-time=3d name="Kondicionery bol6"
add add-arp=yes address-pool="Profit Concept STR18-204" authoritative=\
    after-2sec-delay bootp-support=static disabled=no interface=vlan45 \
    lease-time=3d name="Concept Voyage STR18"
add add-arp=yes address-pool=Guests authoritative=after-2sec-delay disabled=\
    no interface=vlan212 lease-time=4h name=Gusets
add add-arp=yes address-pool="Kadashevkiy first per 11\\5" disabled=no \
    interface=vlan55 lease-time=4h name="Kadashevskiy first per 11\\5"
add add-arp=yes address-pool="str18 Artemjev" authoritative=after-2sec-delay \
    bootp-support=static disabled=no interface=vlan33 lease-time=1d name=\
    "str18 Artemjev"
add add-arp=yes address-pool="Artemjev STR18-39" authoritative=\
    after-2sec-delay disabled=no interface=vlan39 lease-time=6h name=Artemjev
add add-arp=yes address-pool=SpecStroyObjedinenie_Bol18 authoritative=\
    after-2sec-delay disabled=no interface=vlan20 lease-time=3d name=\
    SpecStroyObjedinenie_Bol18
add add-arp=yes address-pool=Avangard authoritative=after-2sec-delay \
    bootp-support=static disabled=no interface=vlan52 lease-time=1d name=\
    "Avangard BOL10"
...
/queue type
set 0 kind=pfifo name=default pfifo-limit=50
set 1 kind=pfifo name=ethernet-default pfifo-limit=50
set 2 kind=sfq name=wireless-default sfq-allot=1514 sfq-perturb=5
set 3 kind=red name=synchronous-default red-avg-packet=1000 red-burst=20 \
    red-limit=60 red-max-threshold=50 red-min-threshold=10
set 4 kind=sfq name=hotspot-default sfq-allot=1514 sfq-perturb=5
set 5 kind=none name=only-hardware-queue
set 6 kind=mq-pfifo mq-pfifo-limit=50 name=multi-queue-ethernet-default
set 7 kind=pfifo name=default-small pfifo-limit=10
/queue simple
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s direction=both \
    disabled=no interface=vlan52 limit-at=6M/6M max-limit=6M/6M name=\
    "Avangard bol10" packet-marks="" parent=none priority=8 queue=\
    ethernet-default/ethernet-default target-addresses="" total-queue=\
    default-small
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s direction=both \
    disabled=no interface=vlan9 limit-at=4M/4M max-limit=4M/4M name=\
    "Restoran str18" packet-marks="" parent=none priority=8 queue=\
    ethernet-default/ethernet-default target-addresses="" total-queue=\
    ethernet-default
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s direction=both \
    disabled=no interface=vlan46 limit-at=4M/4M max-limit=4M/4M name=Stokros \
    packet-marks="" parent=none priority=8 queue=\
    ethernet-default/ethernet-default target-addresses="" total-queue=\
    default-small
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s comment=4mb \
    direction=both disabled=no interface=vlan45 limit-at=10M/10M max-limit=\
    10M/10M name="Koncept Vojage Str18" packet-marks="" parent=none priority=\
    8 queue=ethernet-default/ethernet-default target-addresses="" \
    total-queue=default-small
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s direction=both \
    disabled=no interface=vlan55 limit-at=10M/10M max-limit=10M/10M name=\
    "Kadashevskiy first per 11\\5" packet-marks="" parent=none priority=7 \
    queue=ethernet-default/ethernet-default target-addresses="" total-queue=\
    default-small
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s direction=both \
    disabled=no interface=vlan39 limit-at=0/0 max-limit=4M/4M name=queue39 \
    packet-marks="" parent=none priority=8 queue=default-small/default-small \
    target-addresses="" total-queue=default-small
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s direction=both \
    disabled=yes interface=vlan212 limit-at=0/0 max-limit=10M/10M name=Guest \
    packet-marks="" parent=none priority=8 queue=\
    ethernet-default/ethernet-default target-addresses="" total-queue=\
    ethernet-default
/ip address
add address=192.168.88.1/24 comment="default configuration" disabled=no \
    interface=ether2-master-local network=192.168.88.0
add address=94.79.39.74/29 comment="UpLink GateWay" disabled=no interface=\
    ether1-gateway network=94.79.39.72
add address=10.79.6.49/28 disabled=no interface=\
    vlan52 network=10.79.6.48
add address=94.79.39.76/29 comment=OwnClouds disabled=no interface=\
    ether1-gateway network=94.79.39.72
add address=94.79.39.77/29 disabled=no interface=\
    ether1-gateway network=94.79.39.72
add address=94.79.39.78/29 disabled=no interface=\
    ether1-gateway network=94.79.39.72
/ip arp
add address=10.79.6.51 disabled=no interface=vlan52 mac-address=\
    00:12:12:07:1C:9C
/ip dhcp-server lease
add address=10.79.6.94 client-id=1:e0:cb:4e:bf:55:a8 disabled=no mac-address=\
    E0:CB:4E:BF:55:A8 server="Restoran str18"
add address=10.79.6.53 client-id=1:0:12:12:7:1c:9c disabled=no mac-address=\
    00:12:12:07:1C:9C server="Avangard BOL10"
/ip dhcp-server network
add address=10.79.3.192/28 dhcp-option="" dns-server=\
    212.45.0.3,77.88.8.8,77.88.8.1 gateway=10.79.3.193 netmask=28 ntp-server=\
    "" wins-server=""
add address=10.79.6.48/28 comment=Avangard dhcp-option="" dns-server=\
    212.45.0.3,212.45.2.5,77.88.8.8,77.88.8.1 gateway=10.79.6.49 netmask=28 \
    ntp-server="" wins-server=""
/ip firewall address-list
add address=10.40.10.0/24 disabled=no list=support
add address=10.79.1.0/25 disabled=no list=support
add address=10.40.11.0/24 disabled=no list=support
add address=0.0.0.0/8 comment="Self-Identification [RFC 3330]" disabled=no \
    list=bogons
add address=127.0.0.0/16 comment="Loopback [RFC 3330]" disabled=no list=\
    bogons
add address=169.254.0.0/16 comment="Link Local [RFC 3330]" disabled=no list=\
    bogons
add address=192.0.2.0/24 comment="Reserved - IANA - TestNet1" disabled=no \
    list=bogons
add address=192.88.99.0/24 comment="6to4 Relay Anycast [RFC 3068]" disabled=\
    no list=bogons
add address=198.18.0.0/15 comment="NIDB Testing" disabled=no list=bogons
add address=198.51.100.0/24 comment="Reserved - IANA - TestNet2" disabled=no \
    list=bogons
add address=203.0.113.0/24 comment="Reserved - IANA - TestNet3" disabled=no \
    list=bogons
add address=224.0.0.0/4 comment=\
    "MC, Class D, IANA # Check if you need this subnet before enable it" \
    disabled=no list=bogons
add address=10.79.2.0/28 disabled=no list=support
add address=10.79.6.48/28 disabled=no list=support
/ip firewall connection tracking
set enabled=yes generic-timeout=10m icmp-timeout=10s tcp-close-timeout=10s \
    tcp-close-wait-timeout=10s tcp-established-timeout=1d \
    tcp-fin-wait-timeout=10s tcp-last-ack-timeout=10s \
    tcp-syn-received-timeout=5s tcp-syn-sent-timeout=5s tcp-syncookie=no \
    tcp-time-wait-timeout=10s udp-stream-timeout=3m udp-timeout=10s
/ip firewall filter
add action=log chain=input comment="Avangard CCTV" disabled=yes dst-address=\
    94.79.39.74 dst-port=8080,34567,34599 in-interface=ether1-gateway \
    log-prefix="" port="" protocol=tcp
add action=log chain=forward comment="Avangard CCTV" disabled=yes \
    dst-address=94.79.39.74 dst-port=8080,34567,34599 log-prefix="" protocol=\
    tcp
add action=reject chain=input comment="Block DNS outside" connection-state=\
    new disabled=yes dst-port=53 in-interface=ether1-gateway protocol=udp \
    reject-with=icmp-network-unreachable
add action=accept chain=input comment="Full access to SUPPORT address list" \
    disabled=yes src-address-list=support
add action=drop chain=input disabled=yes dst-port=8291 in-interface=\
    ether1-gateway protocol=tcp
add action=accept chain=input comment="Accept to related connections" \
    connection-state=related disabled=yes
add action=accept chain=input comment="Accept to established connections" \
    connection-state=established disabled=yes
add action=accept chain=input disabled=yes protocol=ipsec-esp src-address=\
    80.89.158.150
add action=accept chain=customer comment="ipsec Link wiht Omsk : TEST" \
    disabled=yes dst-address=10.40.20.0/24 in-interface=ether1-gateway \
    out-interface=ether2-master-local src-address=10.55.1.0/24
add action=accept chain=output disabled=yes dst-address=194.67.29.98 \
    dst-port=1403,2499 out-interface=ether1-gateway protocol=tcp src-address=\
    10.79.5.178
add action=accept chain=input disabled=yes dst-address=94.79.39.77 \
    in-interface=ether1-gateway protocol=tcp src-address=194.67.29.98 \
    src-port=1403,2499
add action=accept chain=input comment="default configuration" disabled=yes \
    dst-address=0.0.0.0 protocol=icmp src-address=0.0.0.0
add action=accept chain=ICMP comment="Echo request - Avoiding Ping Flood" \
    disabled=yes icmp-options=8:0 limit=1,5 protocol=icmp
add action=accept chain=ICMP comment="Echo reply" disabled=yes icmp-options=\
    0:0 protocol=icmp
add action=accept chain=ICMP comment="Time Exceeded" disabled=yes \
    icmp-options=11:0 protocol=icmp
add action=accept chain=ICMP comment="Destination unreachable" disabled=yes \
    icmp-options=3:0-1 protocol=icmp
add action=accept chain=ICMP comment=PMTUD disabled=yes icmp-options=3:4 \
    protocol=icmp
add action=jump chain=output comment="Jump for icmp output" disabled=yes \
    jump-target=ICMP protocol=icmp
add action=jump chain=input comment="Jump for icmp input flow" disabled=yes \
    jump-target=ICMP protocol=icmp
add action=drop chain=forward comment="Avoid spammers action" disabled=yes \
    dst-port=25,53,587 protocol=tcp src-address-list=spammers
add action=drop chain=input comment="Drop to port scan list" disabled=yes \
    src-address-list=Port_Scanner
add action=add-src-to-address-list address-list=Syn_Flooder \
    address-list-timeout=30m chain=input comment=\
    "Add Syn Flood IP to the list" connection-limit=30,32 disabled=yes \
    protocol=tcp tcp-flags=syn
add action=add-src-to-address-list address-list=spammers \
    address-list-timeout=3h chain=forward comment=\
    "Add Spammers to the list for 3 hours" connection-limit=30,32 disabled=\
    yes dst-port=25,53,587 limit=30/1m,0 protocol=tcp
add action=add-src-to-address-list address-list=Port_Scanner \
    address-list-timeout=1w chain=input comment="Port Scanner Detect" \
    disabled=yes protocol=tcp psd=21,3s,3,1
add action=drop chain=ICMP comment="Drop to the other ICMPs" disabled=yes \
    protocol=icmp
add action=drop chain=input comment="Drop to syn flood list" disabled=yes \
    src-address-list=Syn_Flooder
add action=drop chain=forward comment="Drop to bogon list" disabled=yes \
    dst-address-list=bogons
add action=drop chain=input comment="Drop anything else! # DO NOT ENABLE THIS \
    RULE BEFORE YOU MAKE SURE ABOUT ALL ACCEPT RULES YOU NEED" disabled=yes
add action=drop chain=forward disabled=yes in-interface=vlan211 \
    out-interface=vlan100
add action=drop chain=forward disabled=yes in-interface=vlan46 out-interface=\
    vlan100
add action=drop chain=forward disabled=yes in-interface=vlan52 out-interface=\
    vlan100
add action=drop chain=forward disabled=yes in-interface=vlan9 out-interface=\
    vlan100
add action=drop chain=forward disabled=yes in-interface=vlan33 out-interface=\
    vlan100
add action=drop chain=forward disabled=yes in-interface=vlan39 out-interface=\
    vlan100
add action=drop chain=forward disabled=yes in-interface=vlan45 out-interface=\
    vlan100
add action=drop chain=input connection-type="" disabled=yes dst-port=22 \
    in-interface=ether1-gateway port=22 protocol=tcp src-address-list=\
    203.66.143.197
add action=reject chain=input disabled=yes dst-port=22 in-interface=\
    ether1-gateway protocol=tcp reject-with=icmp-network-unreachable
/ip firewall mangle
add action=accept chain=prerouting disabled=no dst-address=94.79.39.74 \
    dst-port=8080,34567,34599 in-interface=ether1-gateway protocol=tcp
add action=passthrough chain=input disabled=no dst-address=94.79.39.74 \
    dst-port=8080,34567,34599 protocol=tcp
add action=passthrough chain=forward disabled=no dst-address=94.79.39.74 \
    dst-port=8080,34567,34599 protocol=tcp
/ip firewall nat
add action=dst-nat chain=dstnat comment=Avangard disabled=no dst-address=\
    94.79.39.74 dst-port=34567 in-interface=ether1-gateway packet-mark=\
    bol10cctv protocol=tcp to-addresses=10.79.6.53 to-ports=34567
add action=dst-nat chain=dstnat comment=Avangard disabled=no dst-address=\
    94.79.39.74 dst-port=34567 in-interface=ether1-gateway packet-mark=\
    bol10cctv protocol=udp to-addresses=10.79.6.53 to-ports=34567
add action=dst-nat chain=dstnat comment=Avangard disabled=no dst-address=\
    94.79.39.74 dst-port=34599 in-interface=ether1-gateway packet-mark=\
    bol10cctv protocol=tcp to-addresses=10.79.6.53 to-ports=34599
add action=dst-nat chain=dstnat comment=Avangard disabled=no dst-address=\
    94.79.39.74 dst-port=34599 in-interface=ether1-gateway packet-mark=\
    bol10cctv protocol=udp to-addresses=10.79.6.53 to-ports=34599
add action=dst-nat chain=dstnat comment=Avangard disabled=no dst-address=\
    94.79.39.74 dst-port=8080 in-interface=ether1-gateway packet-mark=\
    bol10cctv protocol=tcp to-addresses=10.79.6.53 to-ports=80
add action=dst-nat chain=dstnat comment=Avangard disabled=yes dst-address=\
    94.79.39.76 dst-port=1723 protocol=tcp to-addresses=10.79.6.51 to-ports=\
    1723
add action=dst-nat chain=dstnat comment=Avangard disabled=yes dst-address=\
    94.79.39.76 dst-port=8291 protocol=tcp to-addresses=10.79.6.51 to-ports=\
    8291
add action=dst-nat chain=dstnat comment="OwnClouds file.krt.ru" disabled=no \
    dst-address=94.79.39.76 to-addresses=10.40.10.224
add action=src-nat chain=srcnat disabled=no src-address=10.40.10.224 \
    to-addresses=94.79.39.76
add action=dst-nat chain=dstnat comment="Concept Voyage STR18#1" disabled=no \
    dst-address=94.79.39.77 to-addresses=10.79.5.178
add action=src-nat chain=srcnat disabled=no src-address=10.79.5.178 \
    to-addresses=94.79.39.77
add action=dst-nat chain=dstnat comment="Concept Voyage STR18#2" disabled=no \
    dst-address=94.79.39.78 to-addresses=10.79.5.179
add action=src-nat chain=srcnat disabled=no src-address=10.79.5.179 \
    to-addresses=94.79.39.78
add action=src-nat chain=srcnat disabled=no out-interface=ether1-gateway \
    src-address=10.79.6.53 to-addresses=94.79.39.74
add action=masquerade chain=srcnat comment="default NAT" disabled=no \
    out-interface=ether1-gateway to-addresses=0.0.0.0
/ip firewall service-port
set ftp disabled=yes ports=21
set tftp disabled=no ports=69
set irc disabled=yes ports=6667
set h323 disabled=no
set sip disabled=yes ports=5060,5061 sip-direct-media=yes
set pptp disabled=no
/ip hotspot service-port
set ftp disabled=no ports=21
/ip neighbor discovery
set ether1-gateway disabled=yes
set ether2-master-local disabled=no
set ether3-slave-local disabled=yes
set ether4-slave-local disabled=yes
set ether5-slave-local disabled=yes
set vlan100 disabled=yes
set vlan46 disabled=yes
set vlan211 disabled=yes
set vlan52 disabled=yes
set vlan9 disabled=yes
set vlan110 disabled=yes
set vlan1 disabled=yes
set vlan8 disabled=yes
set vlan45 disabled=yes
set vlan212 disabled=yes
set vlan220 disabled=yes
set vlan55 disabled=yes
set vlan33 disabled=yes
set vlan39 disabled=yes
set vlan20 disabled=yes
/ip route
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=94.79.39.73 scope=30 \
    target-scope=10
add disabled=no distance=10 dst-address=10.40.20.0/24 gateway=10.40.10.1 \
    scope=30 target-scope=10
/ip service
/ip smb
/ip smb shares
/ip smb users
/ip tftp
/ip traffic-flow
/ip traffic-flow target
/ip upnp
/port firmware
/ppp aaa
/queue interface
set ether1-gateway queue=ethernet-default
set ether2-master-local queue=ethernet-default
set ether3-slave-local queue=ethernet-default
set ether4-slave-local queue=ethernet-default
set ether5-slave-local queue=ethernet-default
/radius
/radius incoming
/routing bfd interface
/routing mme
/routing rip
/snmp
/system clock
/system clock manual
/system console
/system identity
set name=MikroTik_750GL
/system logging
/system note
/system ntp client
/system resource irq
/system routerboard settings
set boot-device=nand-if-fail-then-ethernet boot-protocol=bootp cpu-frequency=\
    400MHz force-backup-booter=no silent-boot=no
/system script
/system upgrade mirror
/system watchdog
/tool bandwidth-server
/tool e-mail
/tool graphing
/tool mac-server
/tool mac-server mac-winbox
/tool mac-server ping
/tool sms
/tool sniffer
/tool traffic-generator
/user aaa