# jan/05/1970 00:55:31 by RouterOS 6.46.1 # software id = TDS4-ECSP # # model = CRS354-48G-4S+2Q+ # serial number = D1F00B7E4B42 /interface bridge add disabled=yes name=bridge_001 add admin-mac=C4:AD:34:DB:19:DB auto-mac=no name=bridge_200 add name=bridge_202 add name=bridge_203 /interface ethernet set [ find default-name=ether48 ] l2mtu=10000 mtu=9000 /interface list add name=net200 add name=net201 add name=net203 add name=net001 /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik /ip hotspot profile set [ find default=yes ] html-directory=flash/hotspot /ip pool add name=dhcp_pool200 ranges=192.168.200.100-192.168.200.254 add name=dhcp_pool202 ranges=192.168.202.100-192.168.202.254 add name=dhcp_pool203 ranges=192.168.203.100-192.168.203.254 /ip dhcp-server add address-pool=dhcp_pool200 disabled=no interface=bridge_200 lease-time=1d \ name=dhcp200 add address-pool=dhcp_pool202 disabled=no interface=bridge_202 lease-time=1d \ name=dhcp202 add address-pool=dhcp_pool203 disabled=no interface=bridge_203 lease-time=1d \ name=dhcp203 /interface bridge port add bridge=bridge_200 comment=defconf interface=ether49 add bridge=bridge_200 comment=defconf interface=qsfpplus1-1 add bridge=bridge_200 comment=defconf interface=qsfpplus1-2 add bridge=bridge_200 comment=defconf interface=qsfpplus1-3 add bridge=bridge_200 comment=defconf interface=qsfpplus1-4 add bridge=bridge_200 comment=defconf interface=qsfpplus2-1 add bridge=bridge_200 comment=defconf interface=qsfpplus2-2 add bridge=bridge_200 comment=defconf interface=qsfpplus2-3 add bridge=bridge_200 comment=defconf interface=qsfpplus2-4 add bridge=bridge_200 comment=defconf interface=sfp-sfpplus1 add bridge=bridge_200 comment=defconf interface=sfp-sfpplus2 add bridge=bridge_200 comment=defconf interface=sfp-sfpplus3 add bridge=bridge_200 comment=defconf interface=sfp-sfpplus4 add bridge=bridge_202 interface=ether13 trusted=yes add bridge=bridge_202 interface=ether14 trusted=yes add bridge=bridge_202 interface=ether15 trusted=yes add bridge=bridge_202 interface=ether16 trusted=yes add bridge=bridge_202 interface=ether17 trusted=yes add bridge=bridge_202 interface=ether18 trusted=yes add bridge=bridge_202 interface=ether19 trusted=yes add bridge=bridge_202 interface=ether20 trusted=yes add bridge=bridge_202 interface=ether21 trusted=yes add bridge=bridge_202 interface=ether22 trusted=yes add bridge=bridge_202 interface=ether23 trusted=yes add bridge=bridge_202 interface=ether24 trusted=yes add bridge=bridge_203 interface=ether25 trusted=yes add bridge=bridge_203 interface=ether26 trusted=yes add bridge=bridge_203 interface=ether27 trusted=yes add bridge=bridge_203 interface=ether28 trusted=yes add bridge=bridge_203 interface=ether29 trusted=yes add bridge=bridge_203 interface=ether30 trusted=yes add bridge=bridge_203 interface=ether31 trusted=yes add bridge=bridge_203 interface=ether32 trusted=yes add bridge=bridge_203 interface=ether33 trusted=yes add bridge=bridge_203 interface=ether34 trusted=yes add bridge=bridge_203 interface=ether35 trusted=yes add bridge=bridge_203 interface=ether36 trusted=yes add bridge=bridge_203 interface=ether37 trusted=yes add bridge=bridge_203 interface=ether38 trusted=yes add bridge=bridge_203 interface=ether39 trusted=yes add bridge=bridge_203 interface=ether40 trusted=yes add bridge=bridge_203 interface=ether41 trusted=yes add bridge=bridge_203 interface=ether42 trusted=yes add bridge=bridge_203 interface=ether43 trusted=yes add bridge=bridge_203 interface=ether44 trusted=yes add bridge=bridge_203 interface=ether45 trusted=yes add bridge=bridge_203 interface=ether46 trusted=yes add bridge=bridge_203 interface=ether47 trusted=yes add bridge=bridge_203 disabled=yes interface=ether48 trusted=yes add bridge=bridge_200 interface=ether1 trusted=yes add bridge=bridge_200 interface=ether2 trusted=yes add bridge=bridge_200 interface=ether3 trusted=yes add bridge=bridge_200 interface=ether4 trusted=yes add bridge=bridge_200 interface=ether5 trusted=yes add bridge=bridge_200 interface=ether6 trusted=yes add bridge=bridge_200 interface=ether7 trusted=yes add bridge=bridge_200 interface=ether8 trusted=yes add bridge=bridge_200 interface=ether9 trusted=yes add bridge=bridge_200 interface=ether10 trusted=yes add bridge=bridge_200 interface=ether11 trusted=yes add bridge=bridge_200 interface=ether12 trusted=yes /interface list member add interface=ether1 list=net200 add interface=ether2 list=net200 add interface=ether3 list=net200 add interface=ether4 list=net200 add interface=ether5 list=net200 add interface=ether6 list=net200 add interface=ether7 list=net200 add interface=ether8 list=net200 add interface=ether9 list=net200 add interface=ether10 list=net200 add interface=ether11 list=net200 add interface=ether12 list=net200 add interface=ether13 list=net201 add interface=ether14 list=net201 add interface=ether15 list=net201 add interface=ether16 list=net201 add interface=ether17 list=net201 add interface=ether18 list=net201 add interface=ether19 list=net201 add interface=ether20 list=net201 add interface=ether21 list=net201 add interface=ether22 list=net201 add interface=ether23 list=net201 add interface=ether24 list=net201 add interface=ether25 list=net203 add interface=ether26 list=net203 add interface=ether27 list=net203 add interface=ether28 list=net203 add interface=ether29 list=net203 add interface=ether30 list=net203 add interface=ether31 list=net203 add interface=ether32 list=net203 add interface=ether33 list=net203 add interface=ether34 list=net203 add interface=ether35 list=net203 add interface=ether36 list=net203 add interface=ether37 list=net203 add interface=ether38 list=net203 add interface=ether39 list=net203 add interface=ether40 list=net203 add interface=ether41 list=net203 add interface=ether42 list=net203 add interface=ether43 list=net203 add interface=ether44 list=net203 add interface=ether45 list=net203 add interface=ether46 list=net203 add interface=ether47 list=net203 add interface=ether48 list=net203 /ip address add address=192.168.200.99/24 interface=bridge_200 network=192.168.200.0 add address=192.168.202.99/24 interface=bridge_202 network=192.168.202.0 add address=192.168.203.99/24 interface=bridge_203 network=192.168.203.0 add address=192.168.1.1/24 interface=ether48 network=192.168.1.0 /ip dhcp-server lease add address=192.168.203.50 mac-address=00:19:32:00:F5:AD server=dhcp203 add address=192.168.202.1 mac-address=00:E0:4C:68:9B:18 server=dhcp202 add address=192.168.203.1 mac-address=00:E0:4C:68:9B:17 server=dhcp203 add address=192.168.203.2 mac-address=00:E0:4C:68:9A:E1 server=dhcp203 add address=192.168.202.3 mac-address=00:0A:35:00:01:24 server=dhcp202 add address=192.168.202.4 mac-address=D4:BE:D9:AD:19:77 server=dhcp202 add address=192.168.203.20 client-id=1:48:2a:e3:20:5:6b mac-address=\ 48:2A:E3:20:05:6B server=dhcp203 add address=192.168.203.247 client-id=1:28:87:ba:24:54:50 mac-address=\ 28:87:BA:24:54:50 server=dhcp203 add address=192.168.203.21 mac-address=7C:C2:C6:41:E8:1C server=dhcp203 add address=192.168.202.5 mac-address=D0:37:45:92:F1:28 server=dhcp202 add address=192.168.203.6 client-id=1:b8:ae:ed:79:3d:e mac-address=\ B8:AE:ED:79:3D:0E server=dhcp203 add address=192.168.203.25 client-id=1:0:e0:4c:68:1:75 mac-address=\ 00:E0:4C:68:01:75 server=dhcp203 /ip dhcp-server network add address=192.168.200.0/24 gateway=192.168.200.99 netmask=24 add address=192.168.201.0/24 gateway=192.168.201.99 netmask=24 add address=192.168.203.0/24 gateway=192.168.203.99 netmask=24 /ip firewall filter add action=accept chain=input comment=\ "defconf: accept established,related,untracked" connection-state=\ established,related,untracked add action=drop chain=input comment="defconf: drop invalid" connection-state=\ invalid add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp add action=accept chain=input comment=\ "defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1 add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \ connection-state=established,related add action=accept chain=forward comment=\ "defconf: accept established,related, untracked" connection-state=\ established,related,untracked add action=drop chain=forward comment="defconf: drop invalid" \ connection-state=invalid add action=accept chain=forward dst-address=192.168.1.0/24 src-address=\ 192.168.203.0/24 add action=accept chain=forward dst-address=192.168.203.0/24 src-address=\ 192.168.1.0/24 add action=reject chain=forward dst-address=192.168.200.0/24 reject-with=\ icmp-network-unreachable src-address=192.168.202.0/24 add action=reject chain=forward dst-address=192.168.202.0/24 reject-with=\ icmp-network-unreachable src-address=192.168.200.0/24 add action=reject chain=forward dst-address=192.168.200.0/24 log=yes \ reject-with=icmp-network-unreachable src-address=192.168.203.0/24 add action=reject chain=forward dst-address=192.168.203.0/24 log=yes \ reject-with=icmp-network-unreachable src-address=192.168.200.0/24 add action=reject chain=forward dst-address=192.168.202.0/24 reject-with=\ icmp-network-unreachable src-address=192.168.203.0/24 add action=reject chain=forward dst-address=192.168.203.0/24 reject-with=\ icmp-network-unreachable src-address=192.168.202.0/24 /ip firewall nat add action=dst-nat chain=dstnat dst-address=192.168.1.1 in-interface=ether48 \ to-addresses=192.168.203.25 add action=src-nat chain=srcnat out-interface=ether48 src-address=\ 192.168.203.25 to-addresses=192.168.1.1 add action=masquerade chain=srcnat disabled=yes out-interface=ether48 /system routerboard settings set boot-os=router-os #error exporting /system swos