HEX1.LMK: Difference between revisions
Jump to navigation
Jump to search
(Created page with "<pre> #HEX1.LMK /interface vlan add interface=sfp1 name=SFP1-HAMWAN-PUBLIC vlan-id=600 add interface=sfp1 name=SFP1-HAMWAN-PRIVATE vlan-id=601 add interface=ether1 name=ETH1...") |
(→Ports) |
||
(22 intermediate revisions by 2 users not shown) | |||
Line 1: | Line 1: | ||
{{Template:HamWAN Site Bar| backlink=[[Installation/LMK HamWAN Sector|LMK HamWAN Sector]]}} | |||
== Ports == | |||
TODO: Confirm sectors are listed on the right ports, might be backwards | |||
{| class="wikitable" border="1" | |||
|- | |||
! | |||
! style="background: rgb(62,74,60); color: white"|DC IN | |||
! style="background: rgb(101,192,195)"|SFP<br> | |||
! style="background: rgb(101,192,195)"|eth1 <br> PoE IN | |||
! style="background: rgb(250,208,12)"|eth2 <br> PoE OUT | |||
! style="background: rgb(250,208,12)"|eth3 <br> PoE OUT | |||
! style="background: rgb(250,208,12)"|eth4 <br> PoE OUT | |||
! style="background: rgb(250,208,12)"|eth5 <br> PoE OUT | |||
|- | |||
! colspan="2" | Port | |||
| [[RTR1.LMK]] <br>(via Provision) | |||
| [[LINK-BKM.LMK]] | |||
| [[LINK-KUI.LMK]] | |||
| [[RADIO240.LMK]] | |||
| [[RADIO120.LMK]] | |||
| [[RADIO0.LMK]] | |||
|- | |||
! colspan="2" | VLAN | |||
| 601 - Private<br> 600 - Public | |||
| 601 - Private<br> 600 - Public | |||
| 601 - Private<br> 600 - Public | |||
| 601 - Private<br> 600 - Public | |||
| 601 - Private<br> 600 - Public | |||
| 601 - Private<br> 600 - Public | |||
|- | |||
! Power | |||
| 24v<br>Wall Adapter | |||
! | |||
| no | |||
| Power Out <br>[[LINK-KUI.LMK]] | |||
| Power Out <br>[[RADIO240.LMK]] | |||
| Power Out <br>[[RADIO120.LMK]] | |||
| Power Out <br>[[RADIO0.LMK]] | |||
|} | |||
== Configuration == | |||
<pre> | <pre> | ||
HEXPOE | |||
RB960PGS | |||
ASSET 743 | |||
[admin@MikroTik] > export | |||
# jan/02/1970 01:12:32 by RouterOS 6.36.1 | |||
# software id = 6LF8-82K7 | |||
# | |||
/interface bridge | |||
add name=BRIDGE-HAMWAN-PRIVATE | |||
add name=BRIDGE-HAMWAN-PUBLIC | |||
/ip neighbor discovery | |||
set ether1 discover=no | |||
/interface vlan | /interface vlan | ||
add interface= | add interface=ether1 name=ETH1-HAMWAN-PRIVATE vlan-id=601 | ||
add interface=ether1 name=ETH1-HAMWAN-PUBLIC vlan-id=600 | add interface=ether1 name=ETH1-HAMWAN-PUBLIC vlan-id=600 | ||
add interface= | add interface=ether2 name=ETH2-HAMWAN-PRIVATE vlan-id=601 | ||
add interface=ether2 name=ETH2-HAMWAN-PUBLIC vlan-id=600 | add interface=ether2 name=ETH2-HAMWAN-PUBLIC vlan-id=600 | ||
add interface= | add interface=ether3 name=ETH3-HAMWAN-PRIVATE vlan-id=601 | ||
add interface=ether3 name=ETH3-HAMWAN-PUBLIC vlan-id=600 | add interface=ether3 name=ETH3-HAMWAN-PUBLIC vlan-id=600 | ||
add interface= | add interface=ether4 name=ETH4-HAMWAN-PRIVATE vlan-id=601 | ||
add interface=ether4 name=ETH4-HAMWAN-PUBLIC vlan-id=600 | add interface=ether4 name=ETH4-HAMWAN-PUBLIC vlan-id=600 | ||
add interface= | add interface=ether5 name=ETH5-HAMWAN-PRIVATE vlan-id=601 | ||
add interface=ether5 name=ETH5-HAMWAN-PUBLIC vlan-id=600 | add interface=ether5 name=ETH5-HAMWAN-PUBLIC vlan-id=600 | ||
add interface= | add interface=sfp1 name=SFP1-HAMWAN-PRIVATE vlan-id=601 | ||
add interface=sfp1 name=SFP1-HAMWAN-PUBLIC vlan-id=600 | |||
/ip hotspot profile | |||
set [ find default=yes ] html-directory=flash/hotspot | |||
/interface bridge port | /interface bridge port | ||
add comment=defconf interface=ether2 | |||
add comment=defconf interface=sfp1 | |||
add bridge=BRIDGE-HAMWAN-PUBLIC interface=SFP1-HAMWAN-PUBLIC | add bridge=BRIDGE-HAMWAN-PUBLIC interface=SFP1-HAMWAN-PUBLIC | ||
add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH1-HAMWAN-PUBLIC | add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH1-HAMWAN-PUBLIC | ||
Line 34: | Line 80: | ||
add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH4-HAMWAN-PUBLIC | add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH4-HAMWAN-PUBLIC | ||
add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH5-HAMWAN-PUBLIC | add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH5-HAMWAN-PUBLIC | ||
add bridge=BRIDGE-HAMWAN-PRIVATE interface=SFP1-HAMWAN-PRIVATE | add bridge=BRIDGE-HAMWAN-PRIVATE interface=SFP1-HAMWAN-PRIVATE | ||
add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH1-HAMWAN-PRIVATE | add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH1-HAMWAN-PRIVATE | ||
Line 41: | Line 86: | ||
add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH4-HAMWAN-PRIVATE | add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH4-HAMWAN-PRIVATE | ||
add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH5-HAMWAN-PRIVATE | add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH5-HAMWAN-PRIVATE | ||
/ip address | |||
add address=10.246.1.1/16 comment=defconf interface=BRIDGE-HAMWAN-PRIVATE \ | |||
network=10.246.0.0 | |||
/ip dhcp-client | |||
add comment=defconf dhcp-options=hostname,clientid disabled=no interface=\ | |||
ether1 | |||
/ip dns | |||
set allow-remote-requests=yes | |||
/ip dns static | |||
add address=192.168.88.1 name=router | |||
/ip firewall filter | |||
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp | |||
add action=accept chain=input comment="defconf: accept established,related" \ | |||
connection-state=established,related | |||
add action=drop chain=input comment="defconf: drop all from WAN" \ | |||
in-interface=ether1 | |||
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \ | |||
connection-state=established,related | |||
add action=accept chain=forward comment="defconf: accept established,related" \ | |||
connection-state=established,related | |||
add action=drop chain=forward comment="defconf: drop invalid" \ | |||
connection-state=invalid | |||
add action=drop chain=forward comment=\ | |||
"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \ | |||
connection-state=new in-interface=ether1 | |||
/ip firewall nat | |||
add action=masquerade chain=srcnat comment="defconf: masquerade" \ | |||
out-interface=ether1 | |||
/system routerboard settings | |||
set cpu-frequency=800MHz protected-routerboot=disabled | |||
/tool mac-server | |||
set [ find default=yes ] disabled=yes | |||
add | |||
/tool mac-server mac-winbox | |||
set [ find default=yes ] disabled=yes | |||
add | |||
[admin@MikroTik] > | |||
</pre> | </pre> |
Latest revision as of 04:43, 27 June 2017
Ports
TODO: Confirm sectors are listed on the right ports, might be backwards
DC IN | SFP |
eth1 PoE IN |
eth2 PoE OUT |
eth3 PoE OUT |
eth4 PoE OUT |
eth5 PoE OUT | |
---|---|---|---|---|---|---|---|
Port | RTR1.LMK (via Provision) |
LINK-BKM.LMK | LINK-KUI.LMK | RADIO240.LMK | RADIO120.LMK | RADIO0.LMK | |
VLAN | 601 - Private 600 - Public |
601 - Private 600 - Public |
601 - Private 600 - Public |
601 - Private 600 - Public |
601 - Private 600 - Public |
601 - Private 600 - Public | |
Power | 24v Wall Adapter |
no | Power Out LINK-KUI.LMK |
Power Out RADIO240.LMK |
Power Out RADIO120.LMK |
Power Out RADIO0.LMK |
Configuration
HEXPOE RB960PGS ASSET 743 [admin@MikroTik] > export # jan/02/1970 01:12:32 by RouterOS 6.36.1 # software id = 6LF8-82K7 # /interface bridge add name=BRIDGE-HAMWAN-PRIVATE add name=BRIDGE-HAMWAN-PUBLIC /ip neighbor discovery set ether1 discover=no /interface vlan add interface=ether1 name=ETH1-HAMWAN-PRIVATE vlan-id=601 add interface=ether1 name=ETH1-HAMWAN-PUBLIC vlan-id=600 add interface=ether2 name=ETH2-HAMWAN-PRIVATE vlan-id=601 add interface=ether2 name=ETH2-HAMWAN-PUBLIC vlan-id=600 add interface=ether3 name=ETH3-HAMWAN-PRIVATE vlan-id=601 add interface=ether3 name=ETH3-HAMWAN-PUBLIC vlan-id=600 add interface=ether4 name=ETH4-HAMWAN-PRIVATE vlan-id=601 add interface=ether4 name=ETH4-HAMWAN-PUBLIC vlan-id=600 add interface=ether5 name=ETH5-HAMWAN-PRIVATE vlan-id=601 add interface=ether5 name=ETH5-HAMWAN-PUBLIC vlan-id=600 add interface=sfp1 name=SFP1-HAMWAN-PRIVATE vlan-id=601 add interface=sfp1 name=SFP1-HAMWAN-PUBLIC vlan-id=600 /ip hotspot profile set [ find default=yes ] html-directory=flash/hotspot /interface bridge port add comment=defconf interface=ether2 add comment=defconf interface=sfp1 add bridge=BRIDGE-HAMWAN-PUBLIC interface=SFP1-HAMWAN-PUBLIC add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH1-HAMWAN-PUBLIC add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH2-HAMWAN-PUBLIC add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH3-HAMWAN-PUBLIC add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH4-HAMWAN-PUBLIC add bridge=BRIDGE-HAMWAN-PUBLIC interface=ETH5-HAMWAN-PUBLIC add bridge=BRIDGE-HAMWAN-PRIVATE interface=SFP1-HAMWAN-PRIVATE add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH1-HAMWAN-PRIVATE add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH2-HAMWAN-PRIVATE add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH3-HAMWAN-PRIVATE add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH4-HAMWAN-PRIVATE add bridge=BRIDGE-HAMWAN-PRIVATE interface=ETH5-HAMWAN-PRIVATE /ip address add address=10.246.1.1/16 comment=defconf interface=BRIDGE-HAMWAN-PRIVATE \ network=10.246.0.0 /ip dhcp-client add comment=defconf dhcp-options=hostname,clientid disabled=no interface=\ ether1 /ip dns set allow-remote-requests=yes /ip dns static add address=192.168.88.1 name=router /ip firewall filter add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp add action=accept chain=input comment="defconf: accept established,related" \ connection-state=established,related add action=drop chain=input comment="defconf: drop all from WAN" \ in-interface=ether1 add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \ connection-state=established,related add action=accept chain=forward comment="defconf: accept established,related" \ connection-state=established,related add action=drop chain=forward comment="defconf: drop invalid" \ connection-state=invalid add action=drop chain=forward comment=\ "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \ connection-state=new in-interface=ether1 /ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" \ out-interface=ether1 /system routerboard settings set cpu-frequency=800MHz protected-routerboot=disabled /tool mac-server set [ find default=yes ] disabled=yes add /tool mac-server mac-winbox set [ find default=yes ] disabled=yes add [admin@MikroTik] >