Download as txt, pdf, or txt
Download as txt, pdf, or txt
You are on page 1of 1

# apr/22/2014 12:46:43 by RouterOS 6.

10
# software id = 53XE-9ER0
#
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-b/g/n disabled=no ht-rxchains=0 \
ht-txchains=0 l2mtu=2290 ra
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk group-ciphers=\
tkip,aes-ccm mode=dynamic-keys supplicant-identity=MikroTik \
unicast-ciphers=tkip,aes-cc
set [ find default=yes ] idle-timeout=none keepalive-timeout=2m \
mac-cookie-timeout=3d
/ip ipsec proposal
set [ find default=yes ] enc-algorithms=3des
/ip address
add address=192.168.13.254/24 interface=ether1 network=192.168.13.0
add address=10.1.1.13/24 interface=wlan1 network=10.1.1.0
add address=10.1.1.113/24 interface=wlan1 network=10.1.1.0
/ip dns
set allow-remote-requests=yes servers=192.168.1.254
/ip firewall address-list
add address=192.168.13.1 list=allowed
add address=10.1.1.14 list=allowed
add address=192.168.13.1 list=admin_list
add address=10.1.1.13 list=admin_list
/ip firewall filter
add action=drop chain=input connection-state=invalid
add chain=input connection-state=established
add chain=input connection-state=related
add action=log chain=input log-prefix="[accesing-winbox]" protocol=tcp \
src-port=8291
add action=jump chain=input jump-target=admin src-address-list=admin_list
add chain=input disabled=yes src-address=192.168.13.1
add chain=forward disabled=yes protocol=udp src-port=53
add chain=input disabled=yes src-address-list=allowed
add action=drop chain=input disabled=yes
add chain=admin protocol=tcp src-port=8291,21-23
add chain=admin protocol=icmp
/ip firewall nat
add action=src-nat chain=srcnat dst-port=80 out-interface=wlan1 protocol=tcp \
to-addresses=10.1.1.113
add action=masquerade chain=srcnat out-interface=wlan1 to-addresses=0.0.0.0
add action=redirect chain=dstnat dst-port=53 protocol=udp src-address=\
192.168.13.1
add action=dst-nat chain=dstnat dst-address=10.1.1.13 dst-port=5900 protocol=\
tcp to-addresses=192.168.13.1
/ip route
add distance=1 gateway=10.1.1.254
/ip upnp
set allow-disable-external-interface=no
/system clock
set time-zone-name=Asia/Jakarta
/system id
/system leds
set 0 interface=wlan1
/system ntp client
set enabled=yes mode=unicast primary-ntp=67.215.65.132 secondary-ntp=\
65.55.56.206

You might also like