HEX1.BKM: Difference between revisions
Jump to navigation
Jump to search
(Created page with "{{Template:HamWAN Site Bar| backlink=BKM HamWAN Sector}} == Ports == {| class="wikitable" border="1" |- ! ! style="background: rgb(62,74,6...") |
No edit summary |
||
| Line 27: | Line 27: | ||
! colspan="4" | | ! colspan="4" | | ||
|} | |} | ||
==Configuration== | |||
<pre> | |||
# mar/02/1970 09:34:36 by RouterOS 6.36.3 | |||
# software id = N044-E777 | |||
# | |||
/interface bridge | |||
add name=BRIDGE-HAMWAN-PRIVATE | |||
add name=BRIDGE-HAMWAN-PUBLIC | |||
/ip neighbor discovery | |||
set ether1 discover=no | |||
/interface vlan | |||
add interface=ether2 name=ETH2-HAMWAN-PRIVATE vlan-id=601 | |||
add interface=ether2 name=ETH2-HAMWAN-PUBLIC vlan-id=600 | |||
add interface=ether3 name=ETH3-HAMWAN-PRIVATE vlan-id=601 | |||
add interface=ether3 name=ETH3-HAMWAN-PUBLIC vlan-id=600 | |||
add interface=ether4 name=ETH4-HAMWAN-PRIVATE vlan-id=601 | |||
add interface=ether4 name=ETH4-HAMWAN-PUBLIC vlan-id=600 | |||
add interface=ether5 name=ETH5-HAMWAN-PRIVATE vlan-id=601 | |||
add interface=ether5 name=ETH5-HAMWAN-PUBLIC vlan-id=600 | |||
add interface=sfp1 name=SFP1-HAMWAN-PRIVATE vlan-id=601 | |||
add interface=sfp1 name=SFP1-HAMWAN-PUBLIC vlan-id=600 | |||
/ip hotspot profile | |||
set [ find default=yes ] html-directory=flash/hotspot | |||
/snmp community | |||
set [ find default=yes ] name=hamwan | |||
/interface bridge port | |||
add bridge=BRIDGE-HAMWAN-PUBLIC interface=SFP1-HAMWAN-PUBLIC | |||
add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH2-HAMWAN-PUBLIC | |||
add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH3-HAMWAN-PUBLIC | |||
add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH4-HAMWAN-PUBLIC | |||
add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH5-HAMWAN-PUBLIC | |||
add bridge=BRIDGE-HAMWAN-PRIVATE interface=SFP1-HAMWAN-PRIVATE | |||
add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH2-HAMWAN-PRIVATE | |||
add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH3-HAMWAN-PRIVATE | |||
add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH4-HAMWAN-PRIVATE | |||
add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH5-HAMWAN-PRIVATE | |||
add bridge=BRIDGE-HAMWAN-PUBLIC interface=ether1 | |||
/ip address | |||
add address=10.246.3.1/16 comment=defconf interface=BRIDGE-HAMWAN-PRIVATE network=10.246.0.0 | |||
/ip dns static | |||
add address=192.168.88.1 name=router | |||
/ip firewall filter | |||
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp | |||
add action=accept chain=input comment="defconf: accept established,related" connection-state=\ | |||
established,related | |||
# in/out-interface matcher not possible when interface (ether1) is slave - use master instead (BRIDGE-H MWAN-PUBLIC) | |||
add action=drop chain=input comment="defconf: drop all from WAN" in-interface=ether1 | |||
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=\ | |||
established,related | |||
add action=accept chain=forward comment="defconf: accept established,related" connection-state=\ | |||
established,related | |||
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid | |||
# in/out-interface matcher not possible when interface (ether1) is slave - use master instead (BRIDGE-H MWAN-PUBLIC) | |||
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" \ | |||
connection-nat-state=!dstnat connection-state=new in-interface=ether1 | |||
/ip firewall nat | |||
# in/out-interface matcher not possible when interface (ether1) is slave - use master instead (BRIDGE-H MWAN-PUBLIC) | |||
add action=masquerade chain=srcnat comment="defconf: masquerade" out-interface=ether1 | |||
/snmp | |||
set contact="#HamWAN on irc.freenode.org" enabled=yes | |||
/system identity | |||
set name=HEX1.KUI | |||
/system routerboard settings | |||
set cpu-frequency=800MHz protected-routerboot=disabled | |||
/tool mac-server | |||
set [ find default=yes ] disabled=yes | |||
Revision as of 04:00, 1 October 2017
Ports
| DC IN | SFP |
eth1 PoE IN |
eth2 PoE OUT |
eth3 PoE OUT |
eth4 PoE OUT |
eth5 PoE OUT | |
|---|---|---|---|---|---|---|---|
| not used | not used | not used | not used | not used | not used | ||
| Power | no | 12v battery |
|||||
Configuration
# mar/02/1970 09:34:36 by RouterOS 6.36.3
# software id = N044-E777
#
/interface bridge
add name=BRIDGE-HAMWAN-PRIVATE
add name=BRIDGE-HAMWAN-PUBLIC
/ip neighbor discovery
set ether1 discover=no
/interface vlan
add interface=ether2 name=ETH2-HAMWAN-PRIVATE vlan-id=601
add interface=ether2 name=ETH2-HAMWAN-PUBLIC vlan-id=600
add interface=ether3 name=ETH3-HAMWAN-PRIVATE vlan-id=601
add interface=ether3 name=ETH3-HAMWAN-PUBLIC vlan-id=600
add interface=ether4 name=ETH4-HAMWAN-PRIVATE vlan-id=601
add interface=ether4 name=ETH4-HAMWAN-PUBLIC vlan-id=600
add interface=ether5 name=ETH5-HAMWAN-PRIVATE vlan-id=601
add interface=ether5 name=ETH5-HAMWAN-PUBLIC vlan-id=600
add interface=sfp1 name=SFP1-HAMWAN-PRIVATE vlan-id=601
add interface=sfp1 name=SFP1-HAMWAN-PUBLIC vlan-id=600
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/snmp community
set [ find default=yes ] name=hamwan
/interface bridge port
add bridge=BRIDGE-HAMWAN-PUBLIC interface=SFP1-HAMWAN-PUBLIC
add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH2-HAMWAN-PUBLIC
add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH3-HAMWAN-PUBLIC
add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH4-HAMWAN-PUBLIC
add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH5-HAMWAN-PUBLIC
add bridge=BRIDGE-HAMWAN-PRIVATE interface=SFP1-HAMWAN-PRIVATE
add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH2-HAMWAN-PRIVATE
add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH3-HAMWAN-PRIVATE
add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH4-HAMWAN-PRIVATE
add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH5-HAMWAN-PRIVATE
add bridge=BRIDGE-HAMWAN-PUBLIC interface=ether1
/ip address
add address=10.246.3.1/16 comment=defconf interface=BRIDGE-HAMWAN-PRIVATE network=10.246.0.0
/ip dns static
add address=192.168.88.1 name=router
/ip firewall filter
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment="defconf: accept established,related" connection-state=\
established,related
# in/out-interface matcher not possible when interface (ether1) is slave - use master instead (BRIDGE-H MWAN-PUBLIC)
add action=drop chain=input comment="defconf: drop all from WAN" in-interface=ether1
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=\
established,related
add action=accept chain=forward comment="defconf: accept established,related" connection-state=\
established,related
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
# in/out-interface matcher not possible when interface (ether1) is slave - use master instead (BRIDGE-H MWAN-PUBLIC)
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" \
connection-nat-state=!dstnat connection-state=new in-interface=ether1
/ip firewall nat
# in/out-interface matcher not possible when interface (ether1) is slave - use master instead (BRIDGE-H MWAN-PUBLIC)
add action=masquerade chain=srcnat comment="defconf: masquerade" out-interface=ether1
/snmp
set contact="#HamWAN on irc.freenode.org" enabled=yes
/system identity
set name=HEX1.KUI
/system routerboard settings
set cpu-frequency=800MHz protected-routerboot=disabled
/tool mac-server
set [ find default=yes ] disabled=yes