# 2024-08-26 21:54:58 by RouterOS 7.12.1
# software id = HLLJ-XHXZ
#
# model = RB951G-2HnD
# serial number = *****
/caps-man channel
add band=2ghz-b/g/n control-channel-width=20mhz extension-channel=Ce name=\
channel1
/interface bridge
add admin-mac=****** auto-mac=no comment=defconf name=bridge
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-onlyn country=no_country_set \
disabled=no distance=indoors frequency=auto installation=indoor mode=\
ap-bridge ssid=Home_Mikrotik wireless-protocol=802.11
/interface wireguard
add listen-port=51820 mtu=1420 name=WG
/caps-man datapath
add bridge=bridge client-to-client-forwarding=yes local-forwarding=yes name=\
datapath1
/caps-man security
add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm \
name=security1
/caps-man configuration
add channel=channel1 channel.extension-channel=Ce country="us 2.4 rb951g" \
datapath=datapath1 datapath.client-to-client-forwarding=yes \
.local-forwarding=yes installation=outdoor mode=ap name=cfg1 rates.basic=\
54Mbps .supported=54Mbps .vht-supported-mcs="" rx-chains=0,1,2,3 \
security=security1 ssid=Home_Mikrotik tx-chains=0,1,2,3
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface lte apn
set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa2-psk mode=dynamic-keys \
supplicant-identity=MikroTik
/ip pool
add name=dhcp ranges=192.168.150.10-192.168.150.254
add name=dhcp_pool1 ranges=192.168.0.2-192.168.0.254
/ip dhcp-server
add address-pool=dhcp interface=bridge lease-time=10m name=defconf
/routing table
add disabled=no fib name=TOVPN
/caps-man access-list
add action=reject allow-signal-out-of-range=10s disabled=no interface=all \
signal-range=-120..-85 ssid-regexp=""
/caps-man manager
set enabled=yes
/caps-man manager interface
set [ find default=yes ] forbid=yes
add disabled=no interface=bridge
/caps-man provisioning
add action=create-dynamic-enabled master-configuration=cfg1 name-format=\
prefix-identity name-prefix=12
/interface bridge port
add bridge=bridge comment=defconf ingress-filtering=no interface=ether2
add bridge=bridge comment=defconf ingress-filtering=no interface=ether3
add bridge=bridge comment=defconf ingress-filtering=no interface=ether4
add bridge=bridge comment=defconf ingress-filtering=no interface=ether5
add bridge=bridge comment=defconf ingress-filtering=no interface=wlan1
/ip neighbor discovery-settings
set discover-interface-list=LAN
/ip settings
set max-neighbor-entries=8192
/ipv6 settings
set disable-ipv6=yes max-neighbor-entries=8192
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
/interface ovpn-server server
set auth=sha1,md5
/interface wireguard peers
add allowed-address=10.8.0.3/24 client-address=10.8.0.3/24 client-dns=1.1.1.1 \
endpoint-address=**.**.**.** endpoint-port=51820 interface=WG \
preshared-key="********" public-key=\
"*********"
/interface wireless cap
set bridge=bridge discovery-interfaces=bridge interfaces=wlan1
/ip address
add address=192.168.150.1/24 comment=defconf interface=bridge network=\
192.168.150.0
add address=10.8.0.3/24 interface=WG network=10.8.0.0
/ip dhcp-client
add comment=defconf interface=ether1
/ip dhcp-server lease
add address=192.168.150.17 client-id=1:62:6f:34:14:ad:64 mac-address=\
62:6F:34:14:AD:64 server=defconf
add address=192.168.150.33 client-id=1:2c:f0:5d:99:17:ff mac-address=\
2C:F0:5D:99:17:FF server=defconf
add address=192.168.150.10 client-id=1:80:7:94:66:74:11 mac-address=\
80:07:94:66:74:11 server=defconf
add address=192.168.150.13 client-id=1:e6:43

bf:e1:61 mac-address=\
E6:43:0A:BF:E1:61 server=defconf
/ip dhcp-server network
add address=192.168.150.0/24 comment=defconf dns-server=192.168.150.1 \
gateway=192.168.150.1 netmask=24
/ip dns
set allow-remote-requests=yes servers=192.168.0.1
/ip dns static
add address=192.168.150.1 comment=defconf name=router.lan
/ip firewall address-list
add address=157.240.247.174 list=Instagram
add address=46.53.178.107 list=Instagram
add address=179.60.195.174 list=Instagram
add address=157.240.205.174 list=Instagram
add address=31.13.24.0/21 list=Instagram
add address=31.13.64.0/18 list=Instagram
add address=45.64.40.0/22 list=Instagram
add address=66.220.144.0/20 list=Instagram
add address=69.63.176.0/20 list=Instagram
add address=69.171.224.0/19 list=Instagram
add address=74.119.76.0/22 list=Instagram
add address=103.4.96.0/22 list=Instagram
add address=129.134.0.0/16 list=Instagram
add address=157.240.0.0/16 list=Instagram
add address=173.252.64.0/18 list=Instagram
add address=179.60.192.0/22 list=Instagram
add address=185.60.216.0/22 list=Instagram
add address=204.15.20.0/22 list=Instagram
add address=157.240.200.63 list=Instagram
add address=185.60.219.63 list=Instagram
add address=129.134.31.12 list=Instagram
add address=66.81.203.132 list=Instagram
add address=185.89.218.12 list=Instagram
add address=31.13.66.63 list=Instagram
add address=84.15.65.162 list=Instagram
add address=68.66.224.28 list=Instagram
add address=157.240.253.63 list=Instagram
add address=83.174.11.224 list=Instagram
add address=157.240.9.52 list=Instagram
add address=157.240.252.174 list=Instagram
add address=157.240.195.63 list=Instagram
add address=31.13.71.52 list=Instagram
add address=57.144.110.192 list=Instagram
add address=157.240.252.17 list=Instagram
add address=84.15.66.97 list=Instagram
add address=217.168.6.33 list=Instagram
add address=31.13.83.52 list=Instagram
add address=157.240.241.63 list=Instagram
add address=129.134.30.12 list=Instagram
add address=185.89.219.12 list=Instagram
add address=157.240.252.10 list=Instagram
add address=157.240.201.63 list=Instagram
add address=66.81.203.197 list=Instagram
add address=179.60.195.52 list=Instagram
add address=66.81.203.7 list=Instagram
add address=216.40.34.41 list=Instagram
add address=157.240.202.63 list=Instagram
add address=157.240.229.63 list=Instagram
add address=157.240.252.63 list=Instagram
add address=31.13.72.53 list=Instagram
add address=124.108.16.224 list=Instagram
add address=157.240.205.63 list=Instagram
add address=92.46.37.96 list=Instagram
add address=157.240.247.63 list=Instagram
add address=157.240.234.63 list=Instagram
add address=157.240.235.63 list=Instagram
add address=87.245.208.97 list=Instagram
add address=216.58.192.0/19 list=Instagram
add address=209.85.128.0/17 list=Instagram
add address=198.105.240.0/20 list=Instagram
add address=173.194.0.0/16 list=Instagram
add address=172.217.0.0/16 list=Instagram
add address=142.250.0.0/15 list=Instagram
add address=108.177.0.0/17 list=Instagram
add address=87.245.197.140 list=Instagram
add address=74.125.0.0/16 list=Instagram
add address=64.233.160.0/19 list=Instagram
add address=157.240.0.1 list=Instagram
add address=157.240.238.63 list=Instagram
add address=157.240.238.174 list=Instagram
add address=157.240.0.63 list=Instagram
add address=157.240.224.63 list=Instagram
add address=157.240.224.174 list=Instagram
add address=157.240.251.36 list=Instagram
add address=157.240.253.12 list=Instagram
add address=157.240.253.35 list=Instagram
add address=157.240.238.13 list=Instagram
add address=157.240.238.56 list=Instagram
add address=157.240.238.175 list=Instagram
add address=57.144.112.141 list=Instagram
add address=157.240.251.60 list=Instagram
add address=157.240.251.128 list=Instagram
add address=157.240.238.5 list=Instagram
add address=157.240.253.13 list=Instagram
add address=157.240.253.5 list=Instagram
add address=157.240.238.2 list=Instagram
add address=157.240.238.37 list=Instagram
add address=157.240.251.5 list=Instagram
add address=157.240.251.34 list=Instagram
add address=57.144.112.1 list=Instagram
add address=157.240.238.54 list=Instagram
add address=129.134.26.123 list=Instagram
add address=157.240.252.3 list=Instagram
add address=31.13.84.4 list=Instagram
add address=157.240.224.12 list=Instagram
add address=157.240.238.4 list=Instagram
add address=157.240.0.13 list=Instagram
add address=3.33.139.32 list=Instagram
add address=157.240.0.35 list=Instagram
add address=157.240.238.14 list=Instagram
add address=157.240.238.60 list=Instagram
add address=57.144.112.145 list=Instagram
add address=157.240.251.35 list=Instagram
add address=157.240.0.21 list=Instagram
add address=8.8.4.0/24 list=YouTube
add address=8.8.8.0/24 list=YouTube
add address=8.34.208.0/20 list=YouTube
add address=8.35.192.0/20 list=YouTube
add address=23.236.48.0/20 list=YouTube
add address=23.251.128.0/19 list=YouTube
add address=34.0.0.0/10 list=YouTube
add address=35.184.0.0/13 list=YouTube
add address=35.192.0.0/14 list=YouTube
add address=35.196.0.0/15 list=YouTube
add address=35.198.0.0/16 list=YouTube
add address=35.199.0.0/17 list=YouTube
add address=35.199.128.0/18 list=YouTube
add address=35.200.0.0/13 list=YouTube
add address=35.208.0.0/12 list=YouTube
add address=64.18.0.0/20 list=YouTube
add address=64.233.160.0/19 list=YouTube
add address=66.102.0.0/20 list=YouTube
add address=66.249.64.0/19 list=YouTube
add address=70.32.128.0/19 list=YouTube
add address=72.14.192.0/18 list=YouTube
add address=74.114.24.0/21 list=YouTube
add address=74.125.0.0/16 list=YouTube
add address=104.132.0.0/23 list=YouTube
add address=104.133.0.0/23 list=YouTube
add address=104.134.0.0/15 list=YouTube
add address=104.156.64.0/18 list=YouTube
add address=104.237.160.0/19 list=YouTube
add address=108.59.80.0/20 list=YouTube
add address=108.170.192.0/18 list=YouTube
add address=108.176.0.0/15 list=YouTube
add address=130.211.0.0/16 list=YouTube
add address=136.112.0.0/12 list=YouTube
add address=142.250.0.0/15 list=YouTube
add address=146.148.0.0/17 list=YouTube
add address=162.216.148.0/22 list=YouTube
add address=162.222.176.0/21 list=YouTube
add address=172.110.32.0/21 list=YouTube
add address=172.217.0.0/16 list=YouTube
add address=172.253.0.0/16 list=YouTube
add address=173.194.0.0/16 list=YouTube
add address=173.255.112.0/20 list=YouTube
add address=192.158.28.0/22 list=YouTube
add address=192.178.0.0/15 list=YouTube
add address=193.186.4.0/24 list=YouTube
add address=199.36.154.0/23 list=YouTube
add address=199.36.156.0/24 list=YouTube
add address=199.192.112.0/22 list=YouTube
add address=199.223.232.0/21 list=YouTube
add address=207.223.160.0/20 list=YouTube
add address=208.65.152.0/22 list=YouTube
add address=208.68.108.0/22 list=YouTube
add address=208.81.188.0/22 list=YouTube
add address=208.117.224.0/19 list=YouTube
add address=209.85.128.0/17 list=YouTube
add address=216.58.192.0/19 list=YouTube
add address=216.239.32.0/19 list=YouTube
add address=216.239.36.0/24 list=YouTube
add address=216.239.38.0/23 list=YouTube
add address=216.239.40.0/22 list=YouTube
add address=34.64.0.0/10 list=YouTube
add address=34.128.0.0/10 list=YouTube
add address=142.251.141.46 list=YouTube
add address=212.188.34.209 list=YouTube
add address=172.217.169.138 list=YouTube
add address=142.250.187.106 list=YouTube
add address=142.250.186.33 list=YouTube
add address=172.217.17.238 list=YouTube
add address=172.217.20.78 list=YouTube
add address=142.250.185.238 list=YouTube
add address=74.125.156.170 list=YouTube
add address=185.38.0.76 list=YouTube
add address=212.188.34.207 list=YouTube
add address=108.177.14.138 list=YouTube
add address=142.251.40.139 list=YouTube
add address=142.251.40.102 list=YouTube
add address=108.177.14.113 list=YouTube
add address=142.251.40.138 list=YouTube
add address=142.250.74.78 list=YouTube
add address=142.251.141.145 list=YouTube
add address=142.250.74.110 list=YouTube
add address=142.251.40.103 list=YouTube
add address=142.250.74.46 list=YouTube
add address=108.177.97.78 list=YouTube
add address=142.250.74.14 list=YouTube
/ip firewall filter
add action=accept chain=input comment=UnblockCapsman dst-address-type=local \
src-address-type=local
add action=accept chain=input comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment=\
"defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
connection-state=established,related hw-offload=yes
add action=accept chain=forward comment=\
"defconf: accept established,related, untracked" connection-state=\
established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
connection-state=invalid
add action=drop chain=forward comment=\
"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
connection-state=new in-interface-list=WAN
/ip firewall mangle
add action=mark-routing chain=prerouting dst-address-list=Instagram \
new-routing-mark=TOVPN passthrough=yes
add action=mark-routing chain=prerouting dst-address-list=YouTube \
new-routing-mark=TOVPN passthrough=yes
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
ipsec-policy=out,none out-interface-list=WAN
add action=masquerade chain=srcnat out-interface=WG src-address=\
192.168.150.0/24
/ip route
add disabled=yes dst-address=0.0.0.0/0 gateway=192.168.0.1
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=WG pref-src="" \
routing-table=TOVPN scope=30 suppress-hw-offload=no target-scope=10
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set ssh disabled=yes
set api disabled=yes
set api-ssl disabled=yes
#error exporting "/ip/ssh" (timeout)
/routing bfd configuration
add disabled=no interfaces=all min-rx=200ms min-tx=200ms multiplier=5
/system clock
set time-zone-name=Asia/Vladivostok
/system identity
set name=KoridoR
/system note
set show-at-login=no
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN