update mikrotik/mt-dg.ke.einsle.de

This commit is contained in:
oxidized 2019-08-08 19:55:05 +02:00
parent 873181fcdc
commit 064722be6d

View File

@ -1,107 +1,131 @@
# routerboard: yes # /system routerboard print [oxidized@mt-dg] > /system routerboard print
# board-name: hAP ac # routerboard: yes
# model: RouterBOARD 962UiGS-5HacT2HnT # board-name: hAP ac
# serial-number: 67370685D272 # model: RouterBOARD 962UiGS-5HacT2HnT
# firmware-type: qca9550L # serial-number: 67370685D272
# factory-firmware: 3.31 # firmware-type: qca9550L
# current-firmware: 6.45.3 # factory-firmware: 3.31
# current-firmware: 6.45.3
# upgrade-firmware: 6.45.3 # upgrade-firmware: 6.45.3
# # [oxidized@mt-dg] > [oxidized@mt-dg] > # /system package update print [oxidized@mt-dg] > /system package update print
# channel: stable # channel: stable
# installed-version: 6.45.3 # installed-version: 6.45.3
# # [oxidized@mt-dg] > [oxidized@mt-dg] > # /system history print [oxidized@mt-dg] > /system history print
# Flags: U - undoable, R - redoable, F - floating-undo # Flags: U - undoable, R - redoable, F - floating-undo
# ACTION BY POLICY #  ACTION BY POLICY
# # [oxidized@mt-dg] > [oxidized@mt-dg] > /export [oxidized@mt-dg] > /export
# software id = 4J0Q-ELYL # aug/08/2019 19:55:03 by RouterOS 6.45.3
# # software id = 4J0Q-ELYL
# model = RouterBOARD 962UiGS-5HacT2HnT #
# serial number = 67370685D272 # model = RouterBOARD 962UiGS-5HacT2HnT
/interface bridge # serial number = 67370685D272
add fast-forward=no name=br_vlan1 protocol-mode=none /interface bridge
add fast-forward=no name=br_vlan10 protocol-mode=none add fast-forward=no name=br_vlan1 protocol-mode=none
add fast-forward=no name=br_vlan42 protocol-mode=none add fast-forward=no name=br_vlan10 protocol-mode=none
add fast-forward=no name=br_vlan50 protocol-mode=none add fast-forward=no name=br_vlan42 protocol-mode=none
add fast-forward=no name=br_vlan51 protocol-mode=none add fast-forward=no name=br_vlan50 protocol-mode=none
add fast-forward=no name=br_vlan52 protocol-mode=none add fast-forward=no name=br_vlan51 protocol-mode=none
add fast-forward=no name=br_vlan99 protocol-mode=none add fast-forward=no name=br_vlan52 protocol-mode=none
add fast-forward=no name=br_wlan protocol-mode=none add fast-forward=no name=br_vlan99 protocol-mode=none
/interface ethernet add fast-forward=no name=br_wlan protocol-mode=none
set [ find default-name=ether1 ] speed=100Mbps /interface ethernet
set [ find default-name=ether2 ] speed=100Mbps set [ find default-name=ether1 ] speed=100Mbps
set [ find default-name=ether3 ] speed=100Mbps set [ find default-name=ether2 ] speed=100Mbps
set [ find default-name=ether4 ] speed=100Mbps set [ find default-name=ether3 ] speed=100Mbps
set [ find default-name=ether5 ] speed=100Mbps set [ find default-name=ether4 ] speed=100Mbps
set [ find default-name=sfp1 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full set [ find default-name=ether5 ] speed=100Mbps
/interface wireless set [ find default-name=sfp1 ] advertise=\
# managed by CAPsMAN 10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
# channel: 2412/20/gn(10dBm), SSID: wifis.org/ke/bertling, CAPsMAN forwarding /interface wireless
set [ find default-name=wlan1 ] ssid=MikroTik # managed by CAPsMAN
# managed by CAPsMAN # channel: 2412/20/gn(10dBm), SSID: wifis.org/ke/bertling, CAPsMAN forwarding
# channel: 5180/20/ac(20dBm), SSID: wifis.org/ke/bertling, CAPsMAN forwarding set [ find default-name=wlan1 ] ssid=MikroTik
set [ find default-name=wlan2 ] ssid=MikroTik # managed by CAPsMAN
/interface vlan # channel: 5180/20/ac(20dBm), SSID: wifis.org/ke/bertling, CAPsMAN forwarding
add interface=br_wlan loop-protect-disable-time=0s loop-protect-send-interval=0s name=br_wlan_vlan42 vlan-id=42 set [ find default-name=wlan2 ] ssid=MikroTik
add interface=br_wlan loop-protect-disable-time=0s loop-protect-send-interval=0s name=br_wlan_vlan50 vlan-id=50 /interface vlan
add interface=br_wlan loop-protect-disable-time=0s loop-protect-send-interval=0s name=br_wlan_vlan51 vlan-id=51 add interface=br_wlan loop-protect-disable-time=0s \
add interface=br_wlan loop-protect-disable-time=0s loop-protect-send-interval=0s name=br_wlan_vlan52 vlan-id=52 loop-protect-send-interval=0s name=br_wlan_vlan42 vlan-id=42
add interface=br_wlan loop-protect-disable-time=0s loop-protect-send-interval=0s name=br_wlan_vlan99 vlan-id=99 add interface=br_wlan loop-protect-disable-time=0s \
add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=0s name=vlan1 vlan-id=1 loop-protect-send-interval=0s name=br_wlan_vlan50 vlan-id=50
add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=0s name=vlan10 vlan-id=10 add interface=br_wlan loop-protect-disable-time=0s \
add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=0s name=vlan42 vlan-id=42 loop-protect-send-interval=0s name=br_wlan_vlan51 vlan-id=51
add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=0s name=vlan50 vlan-id=50 add interface=br_wlan loop-protect-disable-time=0s \
add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=0s name=vlan51 vlan-id=51 loop-protect-send-interval=0s name=br_wlan_vlan52 vlan-id=52
add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=0s name=vlan52 vlan-id=52 add interface=br_wlan loop-protect-disable-time=0s \
add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=0s name=vlan60 vlan-id=60 loop-protect-send-interval=0s name=br_wlan_vlan99 vlan-id=99
add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=0s name=vlan99 vlan-id=99 add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=\
/interface wireless security-profiles 0s name=vlan1 vlan-id=1
set [ find default=yes ] supplicant-identity=MikroTik add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=\
/ip hotspot profile 0s name=vlan10 vlan-id=10
set [ find default=yes ] html-directory=flash/hotspot add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=\
/routing bgp instance 0s name=vlan42 vlan-id=42
set default disabled=yes add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=\
/routing ospf instance 0s name=vlan50 vlan-id=50
set [ find default=yes ] disabled=yes add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=\
/snmp community 0s name=vlan51 vlan-id=51
set [ find default=yes ] addresses=172.24.0.0/16 authentication-password=nUTIRozDeJMiQ2Goj8BR authentication-protocol=SHA1 encryption-password=nUTIRozDeJMiQ2Goj8BR encryption-protocol=AES name=jie6Wao5weeSahs add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=\
add addresses=172.24.1.0/24,172.24.10.0/24 authentication-password=nUTIRozDeJMiQ2Goj8BR authentication-protocol=SHA1 encryption-password=nUTIRozDeJMiQ2Goj8BR encryption-protocol=AES name=monitor security=private 0s name=vlan52 vlan-id=52
/interface bridge port add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=\
add bridge=br_vlan1 interface=vlan1 0s name=vlan60 vlan-id=60
add bridge=br_vlan10 interface=vlan10 add interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=\
add bridge=br_vlan42 interface=vlan42 0s name=vlan99 vlan-id=99
add bridge=br_vlan50 interface=vlan50 /interface wireless security-profiles
add bridge=br_vlan51 interface=vlan51 set [ find default=yes ] supplicant-identity=MikroTik
add bridge=br_vlan52 interface=vlan52 /ip hotspot profile
add bridge=br_vlan10 hw=no interface=ether2 set [ find default=yes ] html-directory=flash/hotspot
add bridge=br_vlan51 hw=no interface=ether3 /routing bgp instance
add bridge=br_vlan51 hw=no interface=ether4 set default disabled=yes
add bridge=br_vlan52 hw=no interface=ether5 /routing ospf instance
add bridge=br_vlan42 interface=br_wlan_vlan42 set [ find default=yes ] disabled=yes
add bridge=br_vlan50 interface=br_wlan_vlan50 /snmp community
add bridge=br_vlan51 interface=br_wlan_vlan51 set [ find default=yes ] addresses=172.24.0.0/16 authentication-password=\
add bridge=br_vlan52 interface=br_wlan_vlan52 nUTIRozDeJMiQ2Goj8BR authentication-protocol=SHA1 encryption-password=\
add bridge=br_vlan99 interface=br_wlan_vlan99 nUTIRozDeJMiQ2Goj8BR encryption-protocol=AES name=jie6Wao5weeSahs
add bridge=br_vlan99 interface=vlan99 add addresses=172.24.1.0/24,172.24.10.0/24 authentication-password=\
/interface wireless cap nUTIRozDeJMiQ2Goj8BR authentication-protocol=SHA1 encryption-password=\
# nUTIRozDeJMiQ2Goj8BR encryption-protocol=AES name=monitor security=\
set bridge=br_wlan caps-man-addresses=172.24.1.97 enabled=yes interfaces=wlan1,wlan2 private
/ip address /interface bridge port
add address=172.24.1.95/24 interface=vlan1 network=172.24.1.0 add bridge=br_vlan1 interface=vlan1
add address=172.24.10.95/24 interface=vlan10 network=172.24.10.0 add bridge=br_vlan10 interface=vlan10
add address=172.24.42.95/24 interface=vlan42 network=172.24.42.0 add bridge=br_vlan42 interface=vlan42
/ip dns add bridge=br_vlan50 interface=vlan50
set servers=172.24.10.11,172.24.10.12 add bridge=br_vlan51 interface=vlan51
/ip route add bridge=br_vlan52 interface=vlan52
add distance=1 gateway=172.24.1.1 add bridge=br_vlan10 hw=no interface=ether2
/ip ssh add bridge=br_vlan51 hw=no interface=ether3
set allow-none-crypto=yes forwarding-enabled=remote add bridge=br_vlan51 hw=no interface=ether4
/snmp add bridge=br_vlan52 hw=no interface=ether5
set contact="Robert Einsle <robert@einsle.de>" enabled=yes location="Kempten, Dachgeschoss" trap-version=3 add bridge=br_vlan42 interface=br_wlan_vlan42
/system clock add bridge=br_vlan50 interface=br_wlan_vlan50
set time-zone-name=Europe/Berlin add bridge=br_vlan51 interface=br_wlan_vlan51
/system identity add bridge=br_vlan52 interface=br_wlan_vlan52
set name=mt-dg add bridge=br_vlan99 interface=br_wlan_vlan99
/system ntp client add bridge=br_vlan99 interface=vlan99
set enabled=yes primary-ntp=172.24.10.13 secondary-ntp=172.24.10.12 /interface wireless cap
/tool romon #
set enabled=yes id=6C:3B:6B:19:5C:58 secrets=78f244b59c set bridge=br_wlan caps-man-addresses=172.24.1.97 enabled=yes interfaces=\
wlan1,wlan2
/ip address
add address=172.24.1.95/24 interface=vlan1 network=172.24.1.0
add address=172.24.10.95/24 interface=vlan10 network=172.24.10.0
add address=172.24.42.95/24 interface=vlan42 network=172.24.42.0
/ip dns
set servers=172.24.10.11,172.24.10.12
/ip route
add distance=1 gateway=172.24.1.1
/ip ssh
set allow-none-crypto=yes forwarding-enabled=remote
/snmp
set contact="Robert Einsle <robert@einsle.de>" enabled=yes location=\
"Kempten, Dachgeschoss" trap-version=3
/system clock
set time-zone-name=Europe/Berlin
/system identity
set name=mt-dg
/system ntp client
set enabled=yes primary-ntp=172.24.10.13 secondary-ntp=172.24.10.12
/tool romon
set enabled=yes id=6C:3B:6B:19:5C:58 secrets=78f244b59c
[oxidized@mt-dg] > [oxidized@mt-dg] >