Условия такие - ограничение скорости доступа до 1 мбит, не возможность *пролезть* в локальную подсеть, применялось на RB751U
конфигурация
Код: Выделить всё
/interface wireless security-profiles
set [ find default=yes ] authentication-types="" eap-methods=passthrough \
group-ciphers=aes-ccm group-key-update=5m interim-update=0s \
management-protection=disabled management-protection-key="" mode=none name=\
default radius-eap-accounting=no radius-mac-accounting=no \
radius-mac-authentication=no radius-mac-caching=disabled radius-mac-format=\
XX:XX:XX:XX:XX:XX radius-mac-mode=as-username static-algo-0=none \
static-algo-1=none static-algo-2=none static-algo-3=none static-key-0="" \
static-key-1="" static-key-2="" static-key-3="" static-sta-private-algo=\
none static-sta-private-key="" static-transmit-key=key-0 \
supplicant-identity=MikroTik tls-certificate=none tls-mode=no-certificates \
unicast-ciphers=aes-ccm wpa-pre-shared-key="" wpa2-pre-shared-key=""
/interface wireless add area="" arp=enabled bridge-mode=enabled default-ap-tx-limit=1000000 \
default-authentication=yes default-client-tx-limit=1000000 \
default-forwarding=yes disable-running-check=no disabled=no hide-ssid=no \
l2mtu=2290 mac-address=02:0C:42:E1:B1:D3 master-interface=wlan1 \
max-station-count=2007 mtu=1500 multicast-helper=disabled name=wlan2 \
proprietary-extensions=post-2.9.25 security-profile=default ssid=inet-free \
update-stats-interval=disabled wds-cost-range=0 wds-default-bridge=none \
wds-default-cost=0 wds-ignore-ssid=no wds-mode=disabled wmm-support=\
disabled
/ip address add address=192.168.10.1/24 interface=wlan2 network=192.168.10.0
/ip pool add name=pool2 ranges=192.168.10.10-192.168.10.110
/ip dhcp-server add add-arp=yes address-pool=pool2 disabled=no interface=wlan2 name=server2
/ip dhcp-server network add address=192.168.10.0/24 dns-server=192.168.10.1 gateway=192.168.10.1
/ip firewall address-list
add address=192.168.1.0/24 list=my_local
add address=192.168.10.0/24 list=inet-free
/ip firewall filter add action=drop chain=forward comment="Drop from inet free to local" dst-address-list=my_local src-address-list=inet-free
/ip firewall nat add action=masquerade chain=srcnat comment=Iner-Free out-interface=pppoe-out1 src-address-list=inet-free