PC Ekspert Forum

PC Ekspert Forum (https://forum.pcekspert.com/index.php)
-   Mreže (https://forum.pcekspert.com/forumdisplay.php?f=16)
-   -   Mikrotik - za početnika (https://forum.pcekspert.com/showthread.php?t=289115)

Nikky 09.12.2021. 15:17

Na ovo sam mislio > https://klseet.com/networking/mikrot...p-revisit-2021
to je čoeku 2021 verzija konfiga,
imaš sve fino objašnjeno kako, zašto,

certifikati nisu nužni ali ih je on stavio jer mu trebaju za DNS over HTTPS,
to je dobar štos jer Tik - ove vole napadati preko DNS - a,
ako ti je taj dio "kompliciran" onda DNS riješiš na klasični način,

isto tako možeš preskočiti dio oko javnog TCP/IP v6,

u onoj njegovoj uputi samo promijeniš umjesto 500 kod HT oprike ide Vlan = 100.

That's it :)

OuttaControl 21.12.2021. 14:55

Citiraj:

Autor OuttaControl (Post 3562599)
Ne radi mi slanje mejlova preko skripte:
Code:

/tool e-mail send to="xxxxx@gmail.com" subject="PPPoE Down" \
body=" PPPoE Is Down "


Ovo je proradilo, ali, nije bas da radi najbolje :D ili bolje reci radi malo predobro?
https://prnt.sc/23v3c1e

c-shadow 21.12.2021. 15:29

Ma nije to ništa, još si daleko od limita da te provider isključi radi spama :)

OuttaControl 21.12.2021. 15:58

Samo cu rec da sam bio vrlo svjestan da je internet crka oko 5.45 :D

c-shadow 03.01.2022. 14:27

1 privitaka
Vezano na problem iz posta #249 i problema da se neki mobilni uređaji ne mogu povezati na mikrotik 5GHz AP, priča dobila epilog u ovom postu:
https://forum.mikrotik.com/viewtopic...177459#p899238
Code:

The problem is that by default, when configuring the WLAN Interface in  menu "Advanced", "Distance" is set to "dynamic."
After I changed it to  "indoors", the phone connects quickly and without problems.
 In the  "dynamics" settings, the phone does not have time to "negotiate" with  the MKT.

Ja sam nekako slučajno između ostalih postavki (post #260)nabo i taj Distance setting, evo stavljam tu za referencu ako se još netko bude patio sa sličnim problemom.
Zanimljivo kako kod mene su samo neki uređaji imali problema s time, pretežno androidi s MTK (Mediadrek) chipsetom tako da moguće da tu nije samo mtik kriv :)
Evo već 3 mjeseca kod mene niti jedan od tih uređaja nema problema s konektiranjem na 5GHz mikrotik.


http://forum.pcekspert.com/attachmen...1&d=1641212975

Perestrojka 03.01.2022. 21:49

nije direktno vezano uz tvoj problem, no na nekim Apple/Windows uredjajima se zna javit cesti reconnect na wifi, naocigled sve izgleda ok, no po defaultnim ROS postavkama za group-key-update ne radi, pa se isti mora postaviti na group-key-update=1h u security profilu.

kiki86 07.01.2022. 16:16

Posudio sam hap ac lite za igranje doma, i očekivao sam da će bit komplicirano, ali ovo je još gore nego sam mislio :D


želim za početak koristit ga samo kao mini switch i wifi ap dok ne prokužim kako sve posložit, a kasnije bi kupio hap ac3 najvjerovatnije da ga koristim kao glavni router i zamjenim ubee koji imam od a1


ima neki beginner friendly how to koji bi mogao iskoristit za ove moje želje?

dadoremix 07.01.2022. 16:29

Odes na quick setup
Wisp odaberi iz izbornika i vozi
I to je vulgaris switch + ap
Nema dhcp server nit ista drugo
Znaci nebude “gazda”

kiki86 07.01.2022. 16:34

E takvo nešto za početak, a drugo ću postepeno mjenjat kad bar ovo proradi. :fala:

The AC 13.01.2022. 15:25

Ekipa, da li se tko detaljnije poigrao sa ROS 7? Da li u praksi ima kakvog napretka u pogledu wireless performansi?

conan 13.01.2022. 21:41

Kaj nije ROS 7 još u beti?

From Tapatalk With Love

The AC 14.01.2022. 00:32

Nije više koliko vidim ( čak i ak stable branch smatraš beta verzijama :D)

Matta 14.01.2022. 10:36

Citiraj:

Autor The AC (Post 3576300)
Ekipa, da li se tko detaljnije poigrao sa ROS 7? Da li u praksi ima kakvog napretka u pogledu wireless performansi?

Na žalost, nema.
Mikrotik je predstavio wifiwave2 paket, ali trenutno samo 4 uređaja mogu imati benificije od njega:
hAP ac³ (non-LTE)
Audience
Audience LTE6 kit
RB4011iGS+5HacQ2HnD

Ostali ne mogu jer ili imaju manje od 32MB storage prostora ili imaju manje od 256MB RAM-a.

Naravno, ima još kvaka:
Citiraj:

-The wifiwave2 package is not compatible with CAPsMAN. And does not yet offer wireless meshing (4-address mode).
-The 2.4GHz wireless interface on the RB4011iGS+5HacQ2HnD is not compatible with the wifiwave2 package. It will not be usable with the package installed.
Dakle, čeka se dok ne izbace novu verziju, koj će riješiti probleme gore, i koja će se moći instalirati na uređaje koji imaju manje od 256MB RAM-a i manje od 32MB storage-a.

Detaljnije na https://help.mikrotik.com/docs/display/ROS/WifiWave2

Guls 17.01.2022. 09:44

Trebam pomoć pametnijih.
Mreža mi se više manje bazira na kombinaciji mikrotika i win domenskih kontrolera.
Mikrotik je gateway i firewall. Unutar mreže imamo iPBX za telefoniju.
telefonija je počela nešto pucati, pozivi rade ali dosta ima "artefakata" u razgovorima do te mjere da postanu nerazumljivi. Također primjećujem da na switchevima imam čudan promet (hrpa portova vozi istu količinu prometa u jedinici vremena). Sumnjam na neki loop ili što već.
Kako izolirati problem? Osim čupati konektor po konektor pa pratiti promet?

Cuky 17.01.2022. 12:19

Ako su managed switchevi upali loop protection pa vidi dal je koji u loopu, bez da odspajas ista.

Jesi radio kakav update mikrotika u zadnje vrijeme? ...da nije update nesto potrgao.

Jel ti pristup mirkotiku izvana (s interneta) blokiran? Da nemas minera kakvog na njemu 😁

Guls 17.01.2022. 12:21

jesu, svi su managed crs serija.
imao sam rstp i ubijao je mrežu, nakon isključenja sve je prodisalo.
ovaj loop protection bi mogao upaliti za svaki port i onda pričekati da vidim koji će biti offline. dobra metoda.

OuttaControl 22.01.2022. 11:17

Kako dobit neke detaljnije greske za spajanje na PPPoE,

U logu je
Initializing
Connecting
terminated-Disconnected
Disconnected

Na windozama dobijam error kodove iz kojih mogu dokučiti problem.

c-shadow 22.01.2022. 19:59

1 privitaka
System --> Logging
Pod Rules dodaš pppoe, debug.


http://forum.pcekspert.com/attachmen...1&d=1642874362

OuttaControl 22.01.2022. 20:11

Thanks, za ne falit imao sam ga, disabled :)

BlackDwarf 28.01.2022. 11:48

kad se upali ip cloud, da li treba biti iskljucen nat na isp routeru?

Cuky 28.01.2022. 11:52

Ne moras nista dirati na isp ruteru.

BlackDwarf 28.01.2022. 11:57

ni dmz prema mirku?
ne prolazi mi ssh.

Cuky 28.01.2022. 11:58

Onongore vrijedi ako ti je router u bridge modu.

Ako nije onda bubni mtika u dmz na isp routeru 😁

BlackDwarf 28.01.2022. 12:01

je stavio sam, ali isto nece.

Cuky 28.01.2022. 12:02

Onda te zeza cgnat (carrier grade nat).

Zovi isp da te maknu s dijeljene ip adrese i nek te puste samog direktno na net.

BlackDwarf 28.01.2022. 12:03

thx

dadoremix 15.02.2022. 23:47

ima li kojeg mikrotik skriptera ovdje ?
kako slozit skriptu, tj da mi logira vanji ip adresu
da vidim kad dođe do promjene
ip>>cloud>>public adress
e sad, kako slozit da on promjenu objavi u log history ?

OuttaControl 24.02.2022. 00:18

Mi mikrotik amateri :D

Sad imam(cu imat) PPPoE distance 20, A1 WAN distance 10
Jeli moguće nasteliti da jedan uredjaj (tv s netflixom) ide na net preko PPPoE, a ostali uredjaji da idu preko WANa vanka? Ako da u kojem smijeru trebam gledat?

johnsmith 24.02.2022. 01:39

@dado:
https://mhelp.pro/mikrotik-scripts-n...outer-changes/

Za output u log slozis u if bloku umjesto mail i telegram npr:
/log info ""New IP: $NewIP, Previous IP: $CurrentIP";

dadoremix 24.02.2022. 10:37

Cu probat. Tnx


A ovo za 2 wana koristit, moguce je

madox 24.02.2022. 10:37

Citiraj:

Autor OuttaControl (Post 3585859)
Mi mikrotik amateri :D

Sad imam(cu imat) PPPoE distance 20, A1 WAN distance 10
Jeli moguće nasteliti da jedan uredjaj (tv s netflixom) ide na net preko PPPoE, a ostali uredjaji da idu preko WANa vanka? Ako da u kojem smijeru trebam gledat?

Treba ti ruta koja usmjerava promet s odredjenim routing markom prema gateway-u.
Takodjer firewall/mangle - chain prerouting - src adress (ip adresa uredjaja) / in interface (interface na kojem je lokalna mreza) - action - mark routing - new routing mark (naziv routinga koji ce biti gore naveden u ruti.

OuttaControl 24.02.2022. 20:10

E to te ja pitam, tenks sad cu prckat tako.

Eh problem u startu, koju nisam mislio da cu imat.
Spojim 5G antenu od A1 direkt u laptop automatski imam full internet u roku od 10 sekundi.
U mikrotika ustekam u Ether 3, gdje je prije bio WAN 4G od HTa, nema interneta, iako aplikacija kaze da ima o.O

Problem je sto antena mijenja IP.

https://prnt.sc/3sXC1xWBFNrO

Edit riješio izgleda da je modemu trebalo malo duze da se digne

OuttaControl 25.02.2022. 19:18

Dragi dnevnice, j*** te mikrotik da te j*** i sta si ga kupio:

Ovaj mikrotik je stvanro most user UNfriendly device ikad.
Isa disejblat ether3 wan da provjerim nesto na ether1. Kaze mikrotik internet detected, ali nista ne radi ofc zasto bi jer je jucer radilo.
Dobro jebe me se Iden resetirat config i ucitat ponovo staru kad resetira. Kliknem ja reset, after reset load preA1 config. I restiram kad ono nema ničega.
Pajdo se vratio kompletno na tvornicke, disejblao ip login,izbrisao usere, sve potaraca nista nije restorea. Valjda bi odabrao factory reset da sam htjeo reset a ne reset configuration.
Nije restorea zato jer je izbrisa file iz kojeg je triba restorat. Ali neces mene tako lako zajebat, svaki backup je downloadan. Uploadam ja backup selektiram odakle restorat. On kaze No file found, file koji sam upravo odabrao iz tog menija.

Nista nasa skriptu backupiranu isa u terminal i pokrenio. je iz suta, vidim ima nekih errora al ko ce to sad ispravljat. Zasto je pppoe crka nikad necemo sazanat, idalje ne radi iako kaze da radi. Tako da mi propada i plan o tvu koji ide na pppoe a ostali uredjaji preko ether 3.

Previse je osjetljiv, jedan krivi pogled i sve crkne, a skuzit zašto crkne, pa lakse ga skoro resetirat pa ponovo konfigurirat, tj bilo bi da nije osjetljiv koliko je.

Ether1 crkne zato jer namjestis ether3, a erher 3 jenprije radio sa pppoe ali novi ether3 ne radi sa pppoe :facepalm:

pppoe sad ne radi jer je factory izbrisa podatke o pppoe, ali nije ni bitno jer je sad isp modem u normalnom modu, ali to je sve radilo

Alister 25.02.2022. 19:37

A što si uzeo Mikrotik ako nemaš živaca za podešavati sve to, svi znaju da on nije plug&play igračka, i da za većinu stvari treba više stvari poklikati.
Meni se nikada nije desilo ovo što si ti napisao, a tebe očito zeza tvoja kriva konfiguracija više nego Mikrotik :)

OuttaControl 25.02.2022. 20:26

Uzeo sam ga dok beba nije bila ni u planu :D
Ono sam gore napisao u trenutku ljutnje, dosao sa posla, uspavali bebu i idem predahnuti 15 minuta tako da na hrti pogledam TV Kalendar prije ponovne akcije. Uplaim hrti koji ne radi jer A1. I racunam ok samo se spojim na mikrotika disjeblam ether3 interface di je drugi wan i ovaj ether1 koji je uvijek radio ce jednostavno raditi kao i sto je radio uvjek do sad. (Do sad sam doduse disejblao ether1 da se spoji na ether3) Sad to vise ne radi. Jeli zbog moje konfiguracije, je sigurno, ali do cega, pojma nemam, jer roureru na 192.168.5.1 mogu pristupiti preko mikrotika, ruta postoji, sam mikrotik kaze internet detected. Distanci su konfigurirani di mi dopusta. Samo ne radi.

Ovaj dio sa backupom me šokirao, bio sam uvjeren da tu nema sta ne raditi. Mozda ja nesto krivo radim?

Edit pošaljem konfiguraciju cim dodjem doma

Alister 25.02.2022. 20:29

pusti nam tvoju konfiguraciju tu pa da vidimo što te muči

jp_rv 25.02.2022. 22:22

meni je naprosto fantaplastično da mikrotik u 2022. godini nema neke stvari koje drugi vendori imaju već 10 godina, a obzirom da drkanjem po postavkama često nešto prvo sjebeš prije nego popraviš bilo bi sasvim realno očekivati da umjesto APPLY prvo klineš na TEST, vidiš dal nešto radi, i onda tek lupiš apply ako je sve ok, ili undo ako ne radi.

ubiquiti ima taj test feature koji je prva liga, znam ako sjebem konfig da će se stari restorat za 3 minute.

slično i na openwrt, ako sjebem i ubijem konfig, vratit će se na staro nakon par minuta.

na mikrotiku lupim OK pa kud puklo da puklo.



za neke stvari su sasvim ok, ali neke bolesti vuku zadnjih 15 godina.

dadoremix 25.02.2022. 22:29

ima ima, zove se safe mode
a hebiga, nije mikrotik za svakog, kao i linux

c-shadow 25.02.2022. 22:59

+1
Safe mode je super.
Ja sam prčkao sve i svašta u početku po mtiku i stvarno nisam nikad zatrebao factory reset. Paziš da ne zezneš, a za sve ostalo tu je safe mode. Naravno i backup + export jer i sam mtik (barem na forumu) preporuča da se i export napravi budući da restore backupa nije toliko pouzdan :)

OuttaControl 25.02.2022. 23:05

Evo ovde je sve sprckano, trenutno stanje

Code:

# feb/25/2022 22:00:52 by RouterOS 6.49
# software id = H8IP-FT07
#
# model = RBD52G-5HacD2HnD
# serial number = D7160D9D7422
/interface bridge
add admin-mac=XX:XX:XX:XX:XX:XX auto-mac=no comment=defconf name=bridge
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-Ce \
    country="united states" disabled=no distance=indoors frequency=auto mode=\
    ap-bridge ssid= station-roaming=enabled wireless-protocol=802.11
set [ find default-name=wlan2 ] band=5ghz-a/n/ac channel-width=\
    20/40/80mhz-XXXX country="united states" disabled=no distance=indoors \
    frequency=auto installation=indoor mode=ap-bridge ssid=" 5GHz" \
    station-roaming=enabled wireless-protocol=802.11
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa2-psk mode=dynamic-keys \
    supplicant-identity=MikroTik
/ip firewall layer7-protocol
add name="Amazon Update" regexp="^.+d1s31zyz7dcc2d.cloudfront.net.*\$|^.+amzdi\
    gital-a.akamaihd.net.*\$|^.+amzdigitaldownloads.edgesuite.net.*\$|^.+updat\
    es.amazon.com.*\$|^.+softwareupdates.amazon.com.*\$"
/ip kid-control
add fri=0s-1d mon=0s-1d name=system-dummy sat=0s-1d sun=0s-1d thu=0s-1d tue=\
    0s-1d tur-fri=0s-1d tur-mon=0s-1d tur-sat=0s-1d tur-sun=0s-1d tur-thu=\
    0s-1d tur-tue=0s-1d tur-wed=0s-1d wed=0s-1d
/ip pool
add name=dhcp ranges=192.168.1.150-192.168.1.254
/ip dhcp-server
add address-pool=dhcp disabled=no interface=bridge lease-time=8h name=defconf
/ppp profile
set *FFFFFFFE on-up="/tool e-mail send to=\"@gmail.com\" subject=\"PPPo\
    E Up\" \\\
    \nbody=\" PPPoE Is Up \""
/interface pppoe-client
add add-default-route=yes default-route-distance=10 interface=ether1 max-mru=\
    1480 max-mtu=1480 name=pppoe-out1 profile=default-encryption user=\
    %bit@iskon-dsl
/queue simple
add burst-time=5s/0s dst=pppoe-out1 limit-at=512k/0 max-limit=768k/0 name=\
    "Main Queue" target=192.168.1.0/24
add name="1PM bojler Filip " parent="Main Queue" target=192.168.1.30/32
add name="1PM bojler mater " parent="Main Queue" target=192.168.1.31/32
add name=1EM parent="Main Queue" target=192.168.1.40/32
add name="Plug S" parent="Main Queue" target=192.168.1.50/32
add max-limit=384k/2M name=Imilab parent="Main Queue" target=192.168.1.167/32
add burst-limit=128k/2M burst-time=1s/1s max-limit=128k/2M name="Galaxy J7" \
    parent="Main Queue" target=192.168.1.248/32
/system logging action
add email-to=v@gmail.com name=EmailVul target=email
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
    sword,web,sniff,sensitive,api,romon,dude,tikapp"
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf disabled=yes interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=wlan1
add bridge=bridge comment=defconf disabled=yes interface=ether3
add bridge=bridge comment=defconf interface=wlan2
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface detect-internet
set detect-interface-list=all
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
add interface=pppoe-out1 list=WAN
add interface=ether3 list=WAN
/interface wireless access-list
add interface=wlan1 mac-address=XX:XX:XX:XX:XX:XX
add interface=wlan1 mac-address=XX:XX:XX:XX:XX:XX
add interface=wlan1 mac-address=XX:XX:XX:XX:XX:XX
add interface=wlan1 mac-address=XX:XX:XX:XX:XX:XX
add interface=wlan1 mac-address=XX:XX:XX:XX:XX:XX
add comment=OnStep interface=wlan1 mac-address=XX:XX:XX:XX:XX:XX
add comment=Imilab interface=wlan1 mac-address=XX:XX:XX:XX:XX:XX
/ip address
add address=192.168.5.2/24 interface=ether1 network=192.168.5.0
add address=192.168.1.1/24 interface=bridge network=192.168.1.0
add address=172.20.168.2/24 interface=ether3 network=172.20.168.0
/ip dhcp-client
add disabled=no interface=ether3
/ip dhcp-server lease
add address=192.168.1.151 comment="Klima Daikin" mac-address=\
    XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.248 client-id=1:XX:XX:XX:XX:XX:XX mac-address=\
    XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.120 client-id=1:XX:XX:XX:XX:XX:XX:1 comment=\
    "Roborock S5max" mac-address=XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.158 client-id=1:XX:XX:XX:XX:XX:XX mac-address=\
    XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.152 client-id=1:XX:XX:XX:XX:XX:XX mac-address=\
    XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.20 client-id=1:XX:XX:XX:XX:XX:XX mac-address=\
    XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.150 client-id=Withings mac-address=XX:XX:XX:XX:XX:XX \
    server=defconf
add address=192.168.1.160 client-id=1:XX:XX:XX:XX:XX:XX mac-address=\
    XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.167 client-id=1:XX:XX:XX:XX:XX:XX comment=imilab \
    mac-address=XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.170 client-id=1:XX:XX:XX:XX:XX:XX mac-address=\
    XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.159 client-id=1:XX:XX:XX:XX:XX:XX comment="lg tv" \
    mac-address=XX:XX:XX:XX:XX:XX server=defconf
/ip dhcp-server network
add address=192.168.1.0/24 comment=defconf gateway=192.168.1.1 netmask=24
/ip dns
set allow-remote-requests=yes servers=1.1.1.1,8.8.8.8,192.168.1.1
/ip dns static
add address=192.168.1.1 comment=defconf name=router.lan
/ip firewall filter
add action=accept chain=input comment=\
    "defconf: accept established,related,untracked" connection-state=\
    established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
    invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment=\
    "defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
    in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
    ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
    ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
    connection-state=established,related disabled=yes
add action=accept chain=forward comment=\
    "defconf: accept established,related, untracked" connection-state=\
    established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
    connection-state=invalid
add action=drop chain=forward comment=\
    "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
    connection-state=new in-interface-list=WAN
add action=drop chain=forward layer7-protocol="Amazon Update" protocol=tcp \
    src-port=80,443
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
    ipsec-policy=out,none out-interface-list=WAN
/ip route
add distance=9 gateway=192.168.5.1
add check-gateway=ping disabled=yes distance=20 gateway=192.168.0.1
add disabled=yes distance=1 gateway=172.20.168.1
/ip service
set telnet disabled=yes
set ssh disabled=yes
/system clock
set time-zone-name=Europe/Zagreb
/system logging
add topics=wireless,debug
add action=EmailVul disabled=yes topics=pppoe
add action=EmailVul topics=critical
add disabled=yes topics=pppoe,debug
/tool e-mail
set address=in-v3.mailjet.com from= port=587 start-tls=yes \
   
/tool graphing interface
add interface=pppoe-out1
add interface=ether3
/tool graphing queue
add simple-queue=1EM
add simple-queue="1PM bojler "
add simple-queue="1PM bojler mater "
add simple-queue="Galaxy J7"
add simple-queue="Main Queue"
add simple-queue="Plug S"
/tool graphing resource
add
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
/tool netwatch
add disabled=yes down-script="/interface ethernet disable ether1 \
    \n\r\
    \n /interface ethernet enable ether1" host=213.191.128.9 interval=8s \
    timeout=2s
/tool traffic-monitor
add interface=bridge name=tmon1

A ovo. je prije unintended reseta

Code:

# feb/25/2022 17:33:29 by RouterOS 6.49
# software id = H8IP-FT07
#
# model = RBD52G-5HacD2HnD
# serial number = D7160D9D7422
/interface bridge
add admin-mac=XX:XX:XX:XX:XX:XX auto-mac=no comment=defconf name=bridge
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-Ce \
    country="united states" disabled=no distance=indoors frequency=auto mode=\
    ap-bridge ssid= station-roaming=enabled wireless-protocol=802.11
set [ find default-name=wlan2 ] band=5ghz-a/n/ac channel-width=\
    20/40/80mhz-XXXX country="united states" disabled=no distance=indoors \
    frequency=auto installation=indoor mode=ap-bridge ssid=" 5GHz" \
    station-roaming=enabled wireless-protocol=802.11
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa2-psk mode=dynamic-keys \
    supplicant-identity=MikroTik wpa2-pre-shared-key
/ip firewall layer7-protocol
add name="Amazon Update" regexp="^.+d1s31zyz7dcc2d.cloudfront.net.*\$|^.+amzdi\
    gital-a.akamaihd.net.*\$|^.+amzdigitaldownloads.edgesuite.net.*\$|^.+updat\
    es.amazon.com.*\$|^.+softwareupdates.amazon.com.*\$"
/ip kid-control
add fri=0s-1d mon=0s-1d name=system-dummy sat=0s-1d sun=0s-1d thu=0s-1d tue=\
    0s-1d tur-fri=0s-1d tur-mon=0s-1d tur-sat=0s-1d tur-sun=0s-1d tur-thu=\
    0s-1d tur-tue=0s-1d tur-wed=0s-1d wed=0s-1d
/ip pool
add name=dhcp ranges=192.168.1.150-192.168.1.254
/ip dhcp-server
add address-pool=dhcp disabled=no interface=bridge lease-time=8h name=defconf
/port
set 0 baud-rate=9600 data-bits=8 flow-control=none name=usb1 parity=none \
    stop-bits=1
/interface ppp-client
add apn=internet name=ppp-out1 port=usb1
/ppp profile
set *FFFFFFFE on-up="/tool e-mail send to=\"@gmail.com\" subject=\"PPPo\
    E Up\" \\\
    \nbody=\" PPPoE Is Up \""
/interface pppoe-client
add add-default-route=yes default-route-distance=10 interface=ether1 max-mru=\
    1480 max-mtu=1480 name=pppoe-out1 password= profile=\
    default-encryption user=***l%bit@iskon-dsl
/queue simple
add burst-time=5s/0s dst=pppoe-out1 limit-at=512k/0 max-limit=768k/0 name=\
    "Main Queue" target=192.168.1.0/24
add name="1PM bojler " parent="Main Queue" target=192.168.1.30/32
add name="1PM bojler mater " parent="Main Queue" target=192.168.1.31/32
add name=1EM parent="Main Queue" target=192.168.1.40/32
add name="Plug S" parent="Main Queue" target=192.168.1.50/32
add max-limit=384k/2M name=Imilab parent="Main Queue" target=192.168.1.167/32
add burst-limit=128k/2M burst-time=1s/1s max-limit=128k/2M name="Galaxy J7" \
    parent="Main Queue" target=192.168.1.248/32
/system logging action
add email-t@gmail.com name=EmailVul target=email
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
    sword,web,sniff,sensitive,api,romon,dude,tikapp"
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf disabled=yes interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=wlan1
add bridge=bridge comment=defconf interface=wlan2
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface detect-internet
set detect-interface-list=all
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
add interface=pppoe-out1 list=WAN
add interface=ether3 list=WAN
/interface wireless access-list
add interface=wlan1 mac-address=XX:XX:XX:XX:XX:XX
add interface=wlan1 mac-address=XX:XX:XX:XX:XX:XX
add interface=wlan1 mac-address=XX:XX:XX:XX:XX:XX
add interface=wlan1 mac-address=XX:XX:XX:XX:XX:XX
add interface=wlan1 mac-address=XX:XX:XX:XX:XX:XX
add comment=OnStep interface=wlan1 mac-address=XX:XX:XX:XX:XX:XX
add comment=Imilab interface=wlan1 mac-address=XX:XX:XX:XX:XX:XX
/ip address
add address=192.168.5.2/24 interface=ether1 network=192.168.5.0
add address=192.168.1.1/24 interface=bridge network=192.168.1.0
add address=172.20.168.2/24 interface=ether3 network=172.20.168.0
/ip dhcp-client
add disabled=no interface=ether3
/ip dhcp-server lease
add address=192.168.1.151 comment="Klima Daikin" mac-address=\
    XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.248 client-id=1:XX:XX:XX:XX:XX:XX mac-address=\
    XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.120 client-id=1:XX:XX:XX:XX:XX:XX:1 comment=\
    "Roborock S5max" mac-address=XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.158 client-id=1:XX:XX:XX:XX:XX:XX mac-address=\
    XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.152 client-id=1:XX:XX:XX:XX:XX:XX mac-address=\
    XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.20 client-id=1:XX:XX:XX:XX:XX:XX:1:fe mac-address=\
    XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.150 client-id=Withings mac-address=XX:XX:XX:XX:XX:XX \
    server=defconf
add address=192.168.1.160 client-id=1:XX:XX:XX:XX:XX:XX mac-address=\
    XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.167 client-id=1:XX:XX:XX:XX:XX:XX comment=imilab \
    mac-address=XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.170 client-id=1:XX:XX:XX:XX:XX:XX:1:e0 mac-address=\
    XX:XX:XX:XX:XX:XX server=defconf
add address=192.168.1.159 client-id=1:XX:XX:XX:XX:XX:XX comment="lg tv" \
    mac-address=XX:XX:XX:XX:XX:XX server=defconf
/ip dhcp-server network
add address=192.168.1.0/24 comment=defconf gateway=192.168.1.1 netmask=24
/ip dns
set allow-remote-requests=yes servers=1.1.1.1,8.8.8.8,192.168.1.1
/ip dns static
add address=192.168.1.1 comment=defconf name=router.lan
/ip firewall filter
add action=accept chain=input comment=\
    "defconf: accept established,related,untracked" connection-state=\
    established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
    invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment=\
    "defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
    in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
    ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
    ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
    connection-state=established,related disabled=yes
add action=accept chain=forward comment=\
    "defconf: accept established,related, untracked" connection-state=\
    established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
    connection-state=invalid
add action=drop chain=forward comment=\
    "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
    connection-state=new in-interface-list=WAN
add action=drop chain=forward layer7-protocol="Amazon Update" protocol=tcp \
    src-port=80,443
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
    ipsec-policy=out,none out-interface-list=WAN
/ip route
add distance=9 gateway=192.168.5.1
add check-gateway=ping disabled=yes distance=20 gateway=192.168.0.1
add disabled=yes distance=1 gateway=172.20.168.1
/ip service
set telnet disabled=yes
set ssh disabled=yes
/system clock
set time-zone-name=Europe/Zagreb
/system logging
add topics=wireless,debug
add action=EmailVul disabled=yes topics=pppoe
add action=EmailVul topics=critical
add disabled=yes topics=pppoe,debug
/tool e-mail
set address=in-v3.mailjet.com from= password=\
    port=587 start-tls=yes user=\
   
/tool graphing interface
add interface=pppoe-out1
add interface=ether3
/tool graphing queue
add simple-queue=1EM
add simple-queue="1PM bojler Filip "
add simple-queue="1PM bojler mater "
add simple-queue="Galaxy J7"
add simple-queue="Main Queue"
add simple-queue="Plug S"
/tool graphing resource
add
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
/tool netwatch
add disabled=yes down-script="/interface ethernet disable ether1 \
    \n\r\
    \n /interface ethernet enable ether1" host=213.191.128.9 interval=8s \
    timeout=2s
/tool traffic-monitor
add interface=bridge name=tmon1



Sva vremena su GMT +2. Sada je 01:12.

Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
© 1999-2024 PC Ekspert - Sva prava pridržana ISSN 1334-2940
Ad Management by RedTyger