|
楼主 |
发表于 2005-9-26 17:30:35
|
显示全部楼层
# jan/20/1999 06:53:57 by RouterOS 2.8.11
# software id = HNL6-TJT
#
/ interface ethernet
set wan name="wan" mtu=1500 arp=enabled disable-running-check=yes \
auto-negotiation=yes full-duplex=yes long-cable=no speed=100Mbps \
disabled=no
set lan name="lan" mtu=1500 arp=enabled disable-running-check=yes \
auto-negotiation=yes full-duplex=yes long-cable=no speed=100Mbps \
disabled=no
/ interface bridge port
set wan bridge=none priority=128 path-cost=10
set lan bridge=none priority=128 path-cost=10
/ interface l2tp-server server
set enabled=no mtu=1460 mru=1460 authentication=mschap2,mschap1,chap,pap \
default-profile=default
/ interface pppoe-client
add name="pppoe-out1" mtu=1492 mru=1492 interface=wan user="bnnxxxxxxx" \
password="xxxxxxx" profile=default service-name="" ac-name="" \
add-default-route=yes dial-on-demand=no use-peer-dns=no \
allow=mschap1,chap,pap disabled=no
/ interface pptp-server server
set enabled=no mtu=1460 mru=1460 authentication=mschap2,mschap1 \
keepalive-timeout=30 default-profile=default
/ ip accounting
set enabled=no threshold=256
/ ip accounting web-access
set accessible-via-web=no address=0.0.0.0/0
/ ip address
add address=192.168.0.4/24 network=192.168.0.0 broadcast=192.168.0.255 \
interface=lan comment="added by setup" disabled=no
/ ip arp
/ ip dns
set primary-dns=0.0.0.0 secondary-dns=0.0.0.0 allow-remote-requests=no \
cache-size="2048 kB" cache-max-ttl=7d
/ ip firewall
set input name="input" policy=accept comment=""
set forward name="forward" policy=accept comment=""
set output name="output" policy=accept comment=""
/ ip firewall dst-nat
add dst-address=:4662 protocol=tcp action=nat to-dst-address=192.168.0.10 \
to-dst-port=4662 comment="" disabled=yes
add dst-address=:16889 protocol=tcp action=nat to-dst-address=192.168.0.10 \
to-dst-port=16889 comment="" disabled=yes
add in-interface=pppoe-out1 dst-address=:22747 protocol=tcp action=nat \
to-dst-address=192.168.0.10 to-dst-port=22747 comment="" disabled=yes
add in-interface=pppoe-out1 dst-address=:16888 protocol=tcp action=nat \
to-dst-address=192.168.0.10 to-dst-port=16888 comment="" disabled=yes
add in-interface=pppoe-out1 dst-address=:16887 protocol=tcp action=nat \
to-dst-address=192.168.0.10 to-dst-port=16887 comment="" disabled=yes
add in-interface=pppoe-out1 dst-address=:16886 protocol=tcp action=nat \
to-dst-address=192.168.0.10 to-dst-port=16886 comment="" disabled=yes
add in-interface=pppoe-out1 dst-address=:16885 protocol=tcp action=nat \
to-dst-address=192.168.0.10 to-dst-port=16885 comment="" disabled=yes
add in-interface=pppoe-out1 dst-address=:16884 protocol=tcp action=nat \
to-dst-address=192.168.0.10 to-dst-port=16884 comment="" disabled=yes
add in-interface=pppoe-out1 dst-address=:16883 protocol=tcp action=nat \
to-dst-address=192.168.0.10 to-dst-port=16883 comment="" disabled=yes
add in-interface=pppoe-out1 dst-address=:16882 protocol=tcp action=nat \
to-dst-address=192.168.0.10 to-dst-port=16882 comment="" disabled=yes
add in-interface=pppoe-out1 dst-address=:16881 protocol=tcp action=nat \
to-dst-address=192.168.0.10 to-dst-port=16881 comment="" disabled=yes
add in-interface=pppoe-out1 dst-address=:22747 protocol=tcp action=nat \
to-dst-address=192.168.0.10 to-dst-port=22747 comment="" disabled=no
/ ip firewall mangle
add protocol=tcp tcp-options=syn-only action=accept tcp-mss=1400 comment="" \
disabled=no
/ ip firewall service-port
set ftp ports=21 disabled=no
set pptp disabled=no
set gre disabled=no
set h323 disabled=yes
set mms disabled=no
set irc ports=6667 disabled=no
set quake3 disabled=no
set tftp ports=69 disabled=no
/ ip firewall src-nat
add action=masquerade comment="" disabled=no
add action=nat comment="" disabled=yes
/ ip firewall connection tracking
set enabled=yes tcp-syn-sent-timeout=2m tcp-syn-received-timeout=1m \
tcp-established-timeout=5d tcp-fin-wait-timeout=2m \
tcp-close-wait-timeout=1m tcp-last-ack-timeout=30s \
tcp-time-wait-timeout=2m tcp-close-timeout=10s udp-timeout=30s \
udp-stream-timeout=3m icmp-timeout=30s generic-timeout=10m
/ ip neighbor discovery
set wan discover=yes
set lan discover=yes
set pppoe-out1 discover=no
/ ip route
add dst-address=0.0.0.0/0 preferred-source=0.0.0.0 gateway=192.168.0.254 \
distance=1 comment="added by setup" disabled=no
/ ip service
set telnet port=23 address=192.168.0.0/24 disabled=yes
set ftp port=27 address=192.168.0.0/24 disabled=no
set www port=1227 address=192.168.0.0/24 disabled=no
set hotspot port=8088 address=0.0.0.0/0 disabled=no
set ssh port=22 address=192.168.0.0/24 disabled=yes
set hotspot-ssl port=443 address=0.0.0.0/0 certificate=none disabled=yes
/ ip socks
set enabled=no port=1080 connection-idle-timeout=2m max-connections=200
/ ip policy-routing
/ ip policy-routing rule
add src-address=0.0.0.0/0 dst-address=0.0.0.0/0 flow="" interface=all \
action=lookup table=main comment="" disabled=no
/ ip policy-routing table main
add dst-address=0.0.0.0/0 gateway=192.168.0.254 preferred-source=0.0.0.0 \
comment="added by setup" disabled=no
/ ip upnp
set enabled=no
/ ip dhcp-client
set enabled=no host-name="" client-id="" add-default-route=yes \
use-peer-dns=yes
/ ip hotspot
set use-ssl=no hotspot-address=0.0.0.0 dns-name="" status-autorefresh=1m \
universal-proxy=yes parent-proxy=0.0.0.0:0 auth-requires-mac=yes \
auth-mac=no auth-mac-password=no auth-http-cookie=no \
http-cookie-lifetime=1d allow-unencrypted-passwords=no \
login-mac-universal=no split-user-domain=no
/ ip hotspot profile
set default name="default" shared-users=1 mark-flow="" login-method=smart \
keepalive-timeout=2m
/ ip hotspot aaa
set use-radius=no accounting=yes interim-update=0s
/ ip hotspot universal service-port
set ftp ports=21 disabled=no
/ ip ipsec proposal
add name="default" auth-algorithms=sha1 enc-algorithms=3des lifetime=30m \
lifebytes=0 pfs-group=modp1024 disabled=no
/ ip web-proxy
set enabled=no src-address=0.0.0.0 port=3128 hostname="proxy" \
transparent-proxy=no parent-proxy=0.0.0.0:0 \
cache-administrator="webmaster" max-object-size="4096 kB" \
cache-drive=system max-cache-size=none
/ ip web-proxy access
add dst-port=!443,563 method=connect action=deny comment="allow CONNECT only \
to SSL ports 443 \[https\] and 563 \[snews\]" disabled=no
/ ip web-proxy cache
add url="cgi-bin \\?" action=deny comment="don't cache dynamic http pages" \
disabled=no
/ system identity
set name="MikroTik"
/ system logging
set default-remote-address=0.0.0.0 default-remote-port=514 \
disk-buffer-lines=100 memory-buffer-lines=100
/ system logging facility
set Firewall-Log local=memory remote=none remote-address=0.0.0.0 \
remote-port=0 prefix="" echo=no
set PPP-Account local=memory remote=none remote-address=0.0.0.0 remote-port=0 \
prefix="" echo=no
set PPP-Info local=memory remote=none remote-address=0.0.0.0 remote-port=0 \
prefix="" echo=no
set PPP-Error local=memory remote=none remote-address=0.0.0.0 remote-port=0 \
prefix="" echo=no
set System-Info local=memory remote=none remote-address=0.0.0.0 remote-port=0 \
prefix="" echo=no
set System-Error local=memory remote=none remote-address=0.0.0.0 \
remote-port=0 prefix="" echo=no
set System-Warning local=memory remote=none remote-address=0.0.0.0 \
remote-port=0 prefix="" echo=no
set Web-Proxy-Access local=memory remote=none remote-address=0.0.0.0 \
remote-port=0 prefix="" echo=no
set Hotspot-Account local=memory remote=none remote-address=0.0.0.0 \
remote-port=0 prefix="" echo=no
set Hotspot-Info local=memory remote=none remote-address=0.0.0.0 \
remote-port=0 prefix="" echo=no
set Hotspot-Error local=memory remote=none remote-address=0.0.0.0 \
remote-port=0 prefix="" echo=no
set IPsec-Event local=memory remote=none remote-address=0.0.0.0 remote-port=0 \
prefix="" echo=no
set IKE-Event local=memory remote=none remote-address=0.0.0.0 remote-port=0 \
prefix="" echo=no
set IPsec-Warning local=memory remote=none remote-address=0.0.0.0 \
remote-port=0 prefix="" echo=no
set System-Echo local=memory remote=none remote-address=0.0.0.0 remote-port=0 \
prefix="" echo=yes
set OSPF-Info local=memory remote=none remote-address=0.0.0.0 remote-port=0 \
prefix="" echo=no
/ system serial-console
set enabled=yes port=serial0
/ system upgrade mirror
set enabled=no primary-server=0.0.0.0 secondary-server=0.0.0.0 \
check-interval=1d user=""
/ system watchdog
set reboot-on-failure=no watch-address=none watchdog-timer=no \
ping-start-after-boot=5m
/ system routerboard health
set state-after-reboot=enabled
/ system routerboard bios
set
/ port
set serial0 name="serial0" baud-rate=9600 data-bits=8 parity=none stop-bits=1 \
flow-control=hardware
set serial1 name="serial1" baud-rate=9600 data-bits=8 parity=none stop-bits=1 \
flow-control=hardware
/ ppp profile
set default name="default" local-address=0.0.0.0 remote-address=0.0.0.0 \
session-timeout=0s idle-timeout=0s use-compression=no \
use-vj-compression=no use-encryption=no require-encryption=no only-one=no \
change-tcp-mss=yes tx-bit-rate=0 rx-bit-rate=0 incoming-filter="" \
outgoing-filter="" dns-server="" wins-server="" comment=""
/ ppp aaa
set use-radius=no accounting=yes interim-update=0s
/ queue type
set default name="default" kind=pfifo bfifo-limit=15000 pfifo-limit=50 \
red-limit=60 red-min-threshold=10 red-max-threshold=50 red-burst=20 \
sfq-perturb=5 sfq-allot=1514 pcq-rate=0 pcq-limit=50 pcq-classifier=""
set ethernet-default name="ethernet-default" kind=pfifo bfifo-limit=15000 \
pfifo-limit=50 red-limit=60 red-min-threshold=10 red-max-threshold=50 \
red-burst=20 sfq-perturb=5 sfq-allot=1514 pcq-rate=0 pcq-limit=50 \
pcq-classifier=""
set wireless-default name="wireless-default" kind=sfq bfifo-limit=15000 \
pfifo-limit=50 red-limit=60 red-min-threshold=10 red-max-threshold=50 \
red-burst=20 sfq-perturb=5 sfq-allot=1514 pcq-rate=0 pcq-limit=50 \
pcq-classifier=""
set synchronous-default name="synchronous-default" kind=red bfifo-limit=15000 \
pfifo-limit=50 red-limit=60 red-min-threshold=10 red-max-threshold=50 \
red-burst=20 sfq-perturb=5 sfq-allot=1514 pcq-rate=0 pcq-limit=50 \
pcq-classifier=""
/ user
add name="admin" group=full address=0.0.0.0/0 comment="system default user" \
disabled=no
/ user group
add name="read" policy=local,telnet,ssh,!ftp,reboot,read,!write,!policy,test,w\
eb
add name="write" policy=local,telnet,ssh,!ftp,reboot,read,write,!policy,test,w\
eb
add name="full" policy=local,telnet,ssh,ftp,reboot,read,write,policy,test,web
/ user aaa
set use-radius=no accounting=yes interim-update=0s default-group=read
/ driver
/ snmp
set enabled=no contact="" location=""
/ snmp community
set public name="public" address=0.0.0.0/0 read-access=yes
/ tool bandwidth-server
set enabled=yes authenticate=yes allocate-udp-ports-from=2000 max-sessions=10
/ tool mac-server ping
set enabled=yes
/ tool sniffer
set interface=all only-headers=no memory-limit=10 file-name="" file-limit=10 \
streaming-enabled=no streaming-server=0.0.0.0 filter-stream=yes \
filter-protocol=ip-only filter-address1=0.0.0.0/0:0-65535 \
filter-address2=0.0.0.0/0:0-65535
/ tool e-mail
set server=0.0.0.0 from=""
/ routing bgp
set enabled=no as=1 router-id=0.0.0.0 redistribute-static=no \
redistribute-connected=no redistribute-rip=no redistribute-ospf=no
/ routing ospf
set router-id=0.0.0.0 distribute-default=never redistribute-connected=no \
redistribute-static=no redistribute-rip=no redistribute-bgp=no \
metric-default=1 metric-connected=20 metric-static=20 metric-rip=20 \
metric-bgp=20
/ routing ospf area
set backbone area-id=0.0.0.0 authentication=none disabled=no
/ routing rip
set redistribute-static=no redistribute-connected=no redistribute-ospf=no \
redistribute-bgp=no metric-static=1 metric-connected=1 metric-ospf=1 \
metric-bgp=1 update-timer=30s timeout-timer=3m garbage-timer=2m
麻烦各位了!靠我一个人自己解决的话真的要花的时间太多了! |
|