Mikroberto
Usuari@ ADSLzone
- Mensajes
- 64
Hola,
En primer lugar muchas gracias a todos por vuestra ayuda, soy novato y he conseguido configurar más o menos todo como quería, pero tengo un problema de baja velocidad, está en torno a 100 mbps por cable y 150 mbps por wifi.
Tengo las VLAN directamente en un puerto trunk (5-SWITCH) sin bridge, por lo que lo que he leído de VLAN filtering no sé cómo aplica en mi caso.
Cualquier ayuda será bienvenida y cualquier comentario sobre el resto de la configuración también...
Muchas gracias!!!
Datos:
- Movistar 1 gb con router HGU en modo bridge
- MIKROTIK Hex S Ethernet RB760IGS debidamente actualizado
- Switch gestionado D-LINK DGS-1100-08V2 (reparten bien las VLAN)
- AP para domótica TP-Link TL-WA901ND
- AP para WIFI general TP-Link Archer C80 (con wifi de invitados)
Configuración:
/interface ethernet
set [ find default-name=ether1 ] name=1-WAN
set [ find default-name=ether2 ] name=2-pruebas
set [ find default-name=ether3 ] name=3-DOMOTICA
set [ find default-name=ether4 ] name=4-WIFI
set [ find default-name=ether5 ] name=5-SWITCH
set [ find default-name=sfp1 ] disabled=yes
/interface pppoe-client
add add-default-route=yes disabled=no interface=1-WAN name=pppoe-out1 use-peer-dns=yes user=adslppp@telefonicanetpa
/interface vlan
add interface=5-SWITCH name=VLAN_44-Alarma vlan-id=44
add interface=5-SWITCH name="VLAN_55-D1 Isabel" vlan-id=55
add interface=5-SWITCH name="VLAN_66-D2 Paco" vlan-id=66
add interface=5-SWITCH name="VLAN_77-D3 Maite" vlan-id=77
add interface=5-SWITCH name="VLAN_88-D4 Alberto" vlan-id=88
/interface list
add name=WANs
add name=LANs
add name=VLANs
/ip pool
add name=dhcp_pool4-WIFI ranges=192.168.4.2-192.168.4.254
add name=dhcp_pool3-DOMOTICA ranges=192.168.3.2-192.168.3.254
add name=dhcp_pool44-ALARMA ranges=192.168.44.2-192.168.44.254
add name=dhcp_pool1-WAN ranges=192.168.100.1-192.168.100.4,192.168.100.6-192.168.100.254
add name=dhcp_pool55-D1 ranges=192.168.55.2-192.168.55.254
add name=dhcp_pool66-D2 ranges=192.168.66.2-192.168.66.254
add name=dhcp_pool77-MAITE ranges=192.168.77.2-192.168.77.254
add name=dhcp_pool88-D4 ranges=192.168.88.2-192.168.88.254
add name=dhcp_pool2-pruebas ranges=192.168.2.2-192.168.2.254
/ip dhcp-server
add address-pool=dhcp_pool4-WIFI disabled=no interface=4-WIFI name=dhcp4-WIFI
add address-pool=dhcp_pool3-DOMOTICA disabled=no interface=3-DOMOTICA name=dhcp3-DOMOTICA
add address-pool=dhcp_pool44-ALARMA disabled=no interface=VLAN_44-Alarma name=dhcp44-Alarma
add address-pool=dhcp_pool1-WAN disabled=no interface=1-WAN name=dhcp1-WAN
add address-pool=dhcp_pool55-D1 disabled=no interface="VLAN_55-D1 Isabel" name="dhcp55-D1 Isabel"
add address-pool=dhcp_pool66-D2 disabled=no interface="VLAN_66-D2 Paco" name="dhcp66-D2 Paco"
add address-pool=dhcp_pool77-MAITE disabled=no interface="VLAN_77-D3 Maite" name="dhcp77-D3 Maite"
add address-pool=dhcp_pool88-D4 disabled=no interface="VLAN_88-D4 Alberto" name="dhcp88-D4 Alberto"
add address-pool=dhcp_pool2-pruebas disabled=no interface=2-pruebas name=dhcp2-pruebas
/ip neighbor discovery-settings
set discover-interface-list=LANs
/interface bridge vlan
add tagged=*11 vlan-ids=44
add tagged=*11 vlan-ids=55
add tagged=*11 vlan-ids=66
add tagged=*11 vlan-ids=77
add tagged=*11 vlan-ids=88
/interface list member
add interface=5-SWITCH list=LANs
add interface=1-WAN list=WANs
add interface=pppoe-out1 list=WANs
add interface=VLAN_44-Alarma list=VLANs
add interface="VLAN_55-D1 Isabel" list=VLANs
add interface="VLAN_66-D2 Paco" list=VLANs
add interface="VLAN_77-D3 Maite" list=VLANs
add interface="VLAN_88-D4 Alberto" list=VLANs
add interface=2-pruebas list=LANs
add interface=3-DOMOTICA list=LANs
add interface=4-WIFI list=LANs
/ip address
add address=192.168.4.1/24 interface=4-WIFI network=192.168.4.0
add address=192.168.3.1/24 interface=3-DOMOTICA network=192.168.3.0
add address=192.168.100.5/24 interface=1-WAN network=192.168.100.0
add address=192.168.44.1/24 interface=VLAN_44-Alarma network=192.168.44.0
add address=192.168.55.1/24 interface="VLAN_55-D1 Isabel" network=192.168.55.0
add address=192.168.66.1/24 interface="VLAN_66-D2 Paco" network=192.168.66.0
add address=192.168.77.1/24 interface="VLAN_77-D3 Maite" network=192.168.77.0
add address=192.168.88.1/24 interface="VLAN_88-D4 Alberto" network=192.168.88.0
add address=192.168.2.1/24 interface=2-pruebas network=192.168.2.0
/ip cloud
set ddns-enabled=yes
/ip dhcp-client
add comment=defconf interface=1-WAN
/ip dhcp-server lease
add address=192.168.3.206 comment="MANDO INALAMBRICO POR VOZ" mac-address=A0:43:B0:46:85:3A server=dhcp3-DOMOTICA
add address=192.168.3.204 comment="INTERRUPTOR COMEDOR" mac-address=60:01:94:9B:A7
B server=dhcp3-DOMOTICA
add address=192.168.4.231 client-id=1:9e:67:6c:63:b0:d5 comment="IPHONE ALBERTO TRABAJO" mac-address=9E:67:6C:63:B0
5 server=dhcp4-WIFI
add address=192.168.4.230 client-id=1:0:31:92:38:b6:fe comment="ANTENA WIFI GRAL" mac-address=00:31:92:38:B6:FE server=dhcp4-WIFI
add address=192.168.3.202 client-id=1:c:80:63:66:49:1c comment="ANTENA DOMOTICA" mac-address=0C:80:63:66:49:1C server=dhcp3-DOMOTICA
add address=192.168.3.201 comment="GOOGLE NEST MINI" mac-address=14:C1:4E:9F:1D:9E server=dhcp3-DOMOTICA
add address=192.168.3.200 comment="ENCHUFE SECADOR" mac-address=84:0D:8E:5F:3D:5A server=dhcp3-DOMOTICA
add address=192.168.3.199 comment="ENCHUFE ALBERTO" mac-address=60:01:94:B5:01:E6 server=dhcp3-DOMOTICA
add address=192.168.3.198 comment="ENCHUFE MOSQUITOS ISABEL" mac-address=84:E3:42:54:9E:28 server=dhcp3-DOMOTICA
add address=192.168.3.197 comment="ENCHUFE MOSQUITOS PAQUITO" mac-address=84:E3:42:62:38:22 server=dhcp3-DOMOTICA
add address=192.168.3.196 comment="GOOGLE HOME" mac-address=20
F:B9:5B:FA:65 server=dhcp3-DOMOTICA
add address=192.168.3.195 comment="ENCHUFE ORDENADORES" mac-address=84:0D:8E:5F:43:9A server=dhcp3-DOMOTICA
add address=192.168.3.203 comment="ENCHUFE ISABEL" mac-address=DC:4F:22:29:7A:50 server=dhcp3-DOMOTICA
add address=192.168.3.194 comment="ENCHUFE PAQUITO" mac-address=DC:4F:22:29:E2:88 server=dhcp3-DOMOTICA
add address=192.168.3.193 comment="ENCHUFE PLANCHA" mac-address=DC:4F:22:EF:FF:ED server=dhcp3-DOMOTICA
add address=192.168.3.192 comment="ENCHUFE MAITE" mac-address=84:0D:8E:50:49:56 server=dhcp3-DOMOTICA
add address=192.168.3.191 comment="ENCHUFE LAMPARITA" mac-address=60:01:94:BA:98:BF server=dhcp3-DOMOTICA
add address=192.168.3.190 comment="BOMBILLA DESPACHO" mac-address=EC:FA:BC:9E:02:0A server=dhcp3-DOMOTICA
add address=192.168.4.237 client-id=1:0:31:92:9:c1:7b comment="REPETIDOR TV DORMITORIO" mac-address=00:31:92:09:C1:7B server=dhcp4-WIFI
add address=192.168.4.233 client-id=1:ac:d1:b8:79:96:f3 comment="IMPRESORA BROTHER" mac-address=AC
1:B8:79:96:F3 server=dhcp4-WIFI
add address=192.168.44.254 comment=ALARMA mac-address=00:23:B6:08:A2:7F server=dhcp44-Alarma
add address=192.168.2.2 client-id=1:a0:1d:48:e8:ea:a0 comment="PORTATIL FAMILIA" mac-address=A0:1D:48:E8:EA:A0 server=dhcp2-pruebas
add address=192.168.4.229 client-id=1:7a:67:fb:e8:53:ec comment="IPHONE ALBERTO" mac-address=7A:67:FB:E8:53:EC server=dhcp4-WIFI
add address=192.168.4.228 client-id=1:b2:d9:45:33:78:1 comment="IPAD DE ALBERTO" mac-address=B2
9:45:33:78:01 server=dhcp4-WIFI
/ip dhcp-server network
add address=10.9.0.0/16 gateway=10.9.2.1
add address=10.90.0.0/16 gateway=10.90.88.1
add address=10.90.44.0/30 gateway=10.90.44.1
add address=10.90.55.0/24 gateway=10.90.55.1
add address=10.90.66.0/24 gateway=10.90.66.1
add address=10.90.77.0/24 gateway=10.90.77.1
add address=10.90.90.0/24 gateway=10.90.90.1
add address=172.16.33.0/24 gateway=172.16.33.1
add address=172.16.44.0/24 gateway=172.16.44.1
add address=172.16.55.0/24 gateway=172.16.55.1
add address=172.16.66.0/24 gateway=172.16.66.1
add address=172.16.77.0/24 gateway=172.16.77.1
add address=172.16.88.0/24 gateway=172.16.88.1
add address=192.168.2.0/24 gateway=192.168.2.1
add address=192.168.3.0/24 gateway=192.168.3.1
add address=192.168.4.0/24 gateway=192.168.4.1
add address=192.168.44.0/24 gateway=192.168.44.1
add address=192.168.55.0/24 gateway=192.168.55.1
add address=192.168.66.0/24 gateway=192.168.66.1
add address=192.168.77.0/24 gateway=192.168.77.1
add address=192.168.88.0/24 comment=defconf gateway=192.168.88.1
add address=192.168.100.0/24 gateway=192.168.100.5
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan
/ip firewall filter
add action=accept chain=input comment="Aceptas toda conexi\F3n previamente establecida, con destino el router." connection-state=established,related,untracked
add action=drop chain=input comment="Rechazas toda conexi\F3n con estado \"inv\E1lido\"" connection-state=invalid
add action=accept chain=input comment="Aceptas que puedas hacerle un ping a tu IP p\FAblica. Si esta regla la quitas, ver\E1s que dejas de poder hacer ping a tu IP p\FAblica desde internet." protocol=icmp
add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" disabled=yes dst-address=127.0.0.1
add action=drop chain=input comment="Impide que nada que no sea un elemento de tu lista LAN acceda al propio equipo" in-interface-list=!LANs
add action=accept chain=forward comment="Acepta que los elementos LAN y el exterior se puedan comunicar con una policy de IPSec." ipsec-policy=in,ipsec
add action=accept chain=forward comment="Acepta que los elementos LAN y el exterior se puedan comunicar con una policy de IPSec." ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
add action=accept chain=forward comment="Esa regla lo que hace es saltarse el flujo de paquetes que seguir\EDa cualquier paquete en el chain de forward, para toda conexi\F3n ya activa." connection-state=established,related,untracked
add action=drop chain=forward comment="Al igual que en input, paquetes marcados como inv\E1lidos, los rechazamos.\r\
\n" connection-state=invalid
add action=drop chain=forward comment="Esta es la excepci\F3n que confirma la regla. S\F3lo vamos a aceptar nuevas conexiones que vienen del exterior a nuestra LAN, si dicho tr\E1fico est\E1 expl\EDcitamente declarado en el NAT." \
connection-nat-state=!dstnat connection-state=new in-interface-list=WANs
add action=drop chain=forward in-interface=4-WIFI out-interface-list=VLANs
add action=drop chain=forward in-interface-list=VLANs out-interface=4-WIFI
add action=drop chain=forward in-interface=3-DOMOTICA out-interface=4-WIFI
add action=drop chain=forward in-interface=4-WIFI out-interface=3-DOMOTICA
add action=drop chain=forward in-interface=3-DOMOTICA out-interface-list=VLANs
add action=drop chain=forward in-interface=3-DOMOTICA out-interface=5-SWITCH
add action=drop chain=forward in-interface=5-SWITCH out-interface=3-DOMOTICA
add action=drop chain=forward in-interface-list=VLANs out-interface=3-DOMOTICA
add action=drop chain=forward dst-address=192.168.55.0/24 src-address=192.168.44.0/24
add action=drop chain=forward dst-address=192.168.66.0/24 src-address=192.168.44.0/24
add action=drop chain=forward dst-address=192.168.77.0/24 src-address=192.168.44.0/24
add action=drop chain=forward dst-address=192.168.44.0/24 src-address=192.168.55.0/24
add action=drop chain=forward dst-address=192.168.66.0/24 src-address=192.168.55.0/24
add action=drop chain=forward dst-address=192.168.77.0/24 src-address=192.168.55.0/24
add action=drop chain=forward dst-address=192.168.88.0/24 src-address=192.168.55.0/24
add action=drop chain=forward dst-address=192.168.44.0/24 src-address=192.168.66.0/24
add action=drop chain=forward dst-address=192.168.55.0/24 src-address=192.168.66.0/24
add action=drop chain=forward dst-address=192.168.77.0/24 src-address=192.168.66.0/24
add action=drop chain=forward dst-address=192.168.88.0/24 src-address=192.168.66.0/24
add action=drop chain=forward dst-address=192.168.44.0/24 src-address=192.168.77.0/24
add action=drop chain=forward dst-address=192.168.55.0/24 src-address=192.168.77.0/24
add action=drop chain=forward dst-address=192.168.66.0/24 src-address=192.168.77.0/24
add action=drop chain=forward dst-address=192.168.88.0/24 src-address=192.168.77.0/24
add action=drop chain=forward dst-address=192.168.44.0/24 src-address=192.168.88.0/24
add action=drop chain=forward dst-address=192.168.55.0/24 src-address=192.168.88.0/24
add action=drop chain=forward dst-address=192.168.66.0/24 src-address=192.168.88.0/24
add action=drop chain=forward dst-address=192.168.77.0/24 src-address=192.168.88.0/24
/ip firewall nat
add action=masquerade chain=srcnat comment="Como tienes una IP p\FAblica din\E1mica, no puedes usar una regla de src-nat directamente para cambiar unas por otras (si la tuvieras y fuera est\E1tica, esa regla ser\EDa incuso m\E1s simple), as\ED que ti\
enes que tirar de un \"truco\" para salir a internet: usar un sub-grupo dentro del src-nat: el masquerade. Esta regla enmascara todo tr\E1fico saliente no encriptado que acabe saliendo por cualquier interfaz dentro de tu lista WAN. De esa manera \
tan elegante, resuelves el problema de no tener una IP p\FAblica est\E1tica. " ipsec-policy=out,none out-interface-list=WANs
/system clock
set time-zone-name=Europe/Madrid
/system identity
set name=AlberTIK
/tool mac-server
set allowed-interface-list=LANs
/tool mac-server mac-winbox
set allowed-interface-list=LANs
En primer lugar muchas gracias a todos por vuestra ayuda, soy novato y he conseguido configurar más o menos todo como quería, pero tengo un problema de baja velocidad, está en torno a 100 mbps por cable y 150 mbps por wifi.
Tengo las VLAN directamente en un puerto trunk (5-SWITCH) sin bridge, por lo que lo que he leído de VLAN filtering no sé cómo aplica en mi caso.
Cualquier ayuda será bienvenida y cualquier comentario sobre el resto de la configuración también...
Muchas gracias!!!
Datos:
- Movistar 1 gb con router HGU en modo bridge
- MIKROTIK Hex S Ethernet RB760IGS debidamente actualizado
- Switch gestionado D-LINK DGS-1100-08V2 (reparten bien las VLAN)
- AP para domótica TP-Link TL-WA901ND
- AP para WIFI general TP-Link Archer C80 (con wifi de invitados)
Configuración:
/interface ethernet
set [ find default-name=ether1 ] name=1-WAN
set [ find default-name=ether2 ] name=2-pruebas
set [ find default-name=ether3 ] name=3-DOMOTICA
set [ find default-name=ether4 ] name=4-WIFI
set [ find default-name=ether5 ] name=5-SWITCH
set [ find default-name=sfp1 ] disabled=yes
/interface pppoe-client
add add-default-route=yes disabled=no interface=1-WAN name=pppoe-out1 use-peer-dns=yes user=adslppp@telefonicanetpa
/interface vlan
add interface=5-SWITCH name=VLAN_44-Alarma vlan-id=44
add interface=5-SWITCH name="VLAN_55-D1 Isabel" vlan-id=55
add interface=5-SWITCH name="VLAN_66-D2 Paco" vlan-id=66
add interface=5-SWITCH name="VLAN_77-D3 Maite" vlan-id=77
add interface=5-SWITCH name="VLAN_88-D4 Alberto" vlan-id=88
/interface list
add name=WANs
add name=LANs
add name=VLANs
/ip pool
add name=dhcp_pool4-WIFI ranges=192.168.4.2-192.168.4.254
add name=dhcp_pool3-DOMOTICA ranges=192.168.3.2-192.168.3.254
add name=dhcp_pool44-ALARMA ranges=192.168.44.2-192.168.44.254
add name=dhcp_pool1-WAN ranges=192.168.100.1-192.168.100.4,192.168.100.6-192.168.100.254
add name=dhcp_pool55-D1 ranges=192.168.55.2-192.168.55.254
add name=dhcp_pool66-D2 ranges=192.168.66.2-192.168.66.254
add name=dhcp_pool77-MAITE ranges=192.168.77.2-192.168.77.254
add name=dhcp_pool88-D4 ranges=192.168.88.2-192.168.88.254
add name=dhcp_pool2-pruebas ranges=192.168.2.2-192.168.2.254
/ip dhcp-server
add address-pool=dhcp_pool4-WIFI disabled=no interface=4-WIFI name=dhcp4-WIFI
add address-pool=dhcp_pool3-DOMOTICA disabled=no interface=3-DOMOTICA name=dhcp3-DOMOTICA
add address-pool=dhcp_pool44-ALARMA disabled=no interface=VLAN_44-Alarma name=dhcp44-Alarma
add address-pool=dhcp_pool1-WAN disabled=no interface=1-WAN name=dhcp1-WAN
add address-pool=dhcp_pool55-D1 disabled=no interface="VLAN_55-D1 Isabel" name="dhcp55-D1 Isabel"
add address-pool=dhcp_pool66-D2 disabled=no interface="VLAN_66-D2 Paco" name="dhcp66-D2 Paco"
add address-pool=dhcp_pool77-MAITE disabled=no interface="VLAN_77-D3 Maite" name="dhcp77-D3 Maite"
add address-pool=dhcp_pool88-D4 disabled=no interface="VLAN_88-D4 Alberto" name="dhcp88-D4 Alberto"
add address-pool=dhcp_pool2-pruebas disabled=no interface=2-pruebas name=dhcp2-pruebas
/ip neighbor discovery-settings
set discover-interface-list=LANs
/interface bridge vlan
add tagged=*11 vlan-ids=44
add tagged=*11 vlan-ids=55
add tagged=*11 vlan-ids=66
add tagged=*11 vlan-ids=77
add tagged=*11 vlan-ids=88
/interface list member
add interface=5-SWITCH list=LANs
add interface=1-WAN list=WANs
add interface=pppoe-out1 list=WANs
add interface=VLAN_44-Alarma list=VLANs
add interface="VLAN_55-D1 Isabel" list=VLANs
add interface="VLAN_66-D2 Paco" list=VLANs
add interface="VLAN_77-D3 Maite" list=VLANs
add interface="VLAN_88-D4 Alberto" list=VLANs
add interface=2-pruebas list=LANs
add interface=3-DOMOTICA list=LANs
add interface=4-WIFI list=LANs
/ip address
add address=192.168.4.1/24 interface=4-WIFI network=192.168.4.0
add address=192.168.3.1/24 interface=3-DOMOTICA network=192.168.3.0
add address=192.168.100.5/24 interface=1-WAN network=192.168.100.0
add address=192.168.44.1/24 interface=VLAN_44-Alarma network=192.168.44.0
add address=192.168.55.1/24 interface="VLAN_55-D1 Isabel" network=192.168.55.0
add address=192.168.66.1/24 interface="VLAN_66-D2 Paco" network=192.168.66.0
add address=192.168.77.1/24 interface="VLAN_77-D3 Maite" network=192.168.77.0
add address=192.168.88.1/24 interface="VLAN_88-D4 Alberto" network=192.168.88.0
add address=192.168.2.1/24 interface=2-pruebas network=192.168.2.0
/ip cloud
set ddns-enabled=yes
/ip dhcp-client
add comment=defconf interface=1-WAN
/ip dhcp-server lease
add address=192.168.3.206 comment="MANDO INALAMBRICO POR VOZ" mac-address=A0:43:B0:46:85:3A server=dhcp3-DOMOTICA
add address=192.168.3.204 comment="INTERRUPTOR COMEDOR" mac-address=60:01:94:9B:A7
add address=192.168.4.231 client-id=1:9e:67:6c:63:b0:d5 comment="IPHONE ALBERTO TRABAJO" mac-address=9E:67:6C:63:B0
add address=192.168.4.230 client-id=1:0:31:92:38:b6:fe comment="ANTENA WIFI GRAL" mac-address=00:31:92:38:B6:FE server=dhcp4-WIFI
add address=192.168.3.202 client-id=1:c:80:63:66:49:1c comment="ANTENA DOMOTICA" mac-address=0C:80:63:66:49:1C server=dhcp3-DOMOTICA
add address=192.168.3.201 comment="GOOGLE NEST MINI" mac-address=14:C1:4E:9F:1D:9E server=dhcp3-DOMOTICA
add address=192.168.3.200 comment="ENCHUFE SECADOR" mac-address=84:0D:8E:5F:3D:5A server=dhcp3-DOMOTICA
add address=192.168.3.199 comment="ENCHUFE ALBERTO" mac-address=60:01:94:B5:01:E6 server=dhcp3-DOMOTICA
add address=192.168.3.198 comment="ENCHUFE MOSQUITOS ISABEL" mac-address=84:E3:42:54:9E:28 server=dhcp3-DOMOTICA
add address=192.168.3.197 comment="ENCHUFE MOSQUITOS PAQUITO" mac-address=84:E3:42:62:38:22 server=dhcp3-DOMOTICA
add address=192.168.3.196 comment="GOOGLE HOME" mac-address=20
add address=192.168.3.195 comment="ENCHUFE ORDENADORES" mac-address=84:0D:8E:5F:43:9A server=dhcp3-DOMOTICA
add address=192.168.3.203 comment="ENCHUFE ISABEL" mac-address=DC:4F:22:29:7A:50 server=dhcp3-DOMOTICA
add address=192.168.3.194 comment="ENCHUFE PAQUITO" mac-address=DC:4F:22:29:E2:88 server=dhcp3-DOMOTICA
add address=192.168.3.193 comment="ENCHUFE PLANCHA" mac-address=DC:4F:22:EF:FF:ED server=dhcp3-DOMOTICA
add address=192.168.3.192 comment="ENCHUFE MAITE" mac-address=84:0D:8E:50:49:56 server=dhcp3-DOMOTICA
add address=192.168.3.191 comment="ENCHUFE LAMPARITA" mac-address=60:01:94:BA:98:BF server=dhcp3-DOMOTICA
add address=192.168.3.190 comment="BOMBILLA DESPACHO" mac-address=EC:FA:BC:9E:02:0A server=dhcp3-DOMOTICA
add address=192.168.4.237 client-id=1:0:31:92:9:c1:7b comment="REPETIDOR TV DORMITORIO" mac-address=00:31:92:09:C1:7B server=dhcp4-WIFI
add address=192.168.4.233 client-id=1:ac:d1:b8:79:96:f3 comment="IMPRESORA BROTHER" mac-address=AC
add address=192.168.44.254 comment=ALARMA mac-address=00:23:B6:08:A2:7F server=dhcp44-Alarma
add address=192.168.2.2 client-id=1:a0:1d:48:e8:ea:a0 comment="PORTATIL FAMILIA" mac-address=A0:1D:48:E8:EA:A0 server=dhcp2-pruebas
add address=192.168.4.229 client-id=1:7a:67:fb:e8:53:ec comment="IPHONE ALBERTO" mac-address=7A:67:FB:E8:53:EC server=dhcp4-WIFI
add address=192.168.4.228 client-id=1:b2:d9:45:33:78:1 comment="IPAD DE ALBERTO" mac-address=B2
/ip dhcp-server network
add address=10.9.0.0/16 gateway=10.9.2.1
add address=10.90.0.0/16 gateway=10.90.88.1
add address=10.90.44.0/30 gateway=10.90.44.1
add address=10.90.55.0/24 gateway=10.90.55.1
add address=10.90.66.0/24 gateway=10.90.66.1
add address=10.90.77.0/24 gateway=10.90.77.1
add address=10.90.90.0/24 gateway=10.90.90.1
add address=172.16.33.0/24 gateway=172.16.33.1
add address=172.16.44.0/24 gateway=172.16.44.1
add address=172.16.55.0/24 gateway=172.16.55.1
add address=172.16.66.0/24 gateway=172.16.66.1
add address=172.16.77.0/24 gateway=172.16.77.1
add address=172.16.88.0/24 gateway=172.16.88.1
add address=192.168.2.0/24 gateway=192.168.2.1
add address=192.168.3.0/24 gateway=192.168.3.1
add address=192.168.4.0/24 gateway=192.168.4.1
add address=192.168.44.0/24 gateway=192.168.44.1
add address=192.168.55.0/24 gateway=192.168.55.1
add address=192.168.66.0/24 gateway=192.168.66.1
add address=192.168.77.0/24 gateway=192.168.77.1
add address=192.168.88.0/24 comment=defconf gateway=192.168.88.1
add address=192.168.100.0/24 gateway=192.168.100.5
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan
/ip firewall filter
add action=accept chain=input comment="Aceptas toda conexi\F3n previamente establecida, con destino el router." connection-state=established,related,untracked
add action=drop chain=input comment="Rechazas toda conexi\F3n con estado \"inv\E1lido\"" connection-state=invalid
add action=accept chain=input comment="Aceptas que puedas hacerle un ping a tu IP p\FAblica. Si esta regla la quitas, ver\E1s que dejas de poder hacer ping a tu IP p\FAblica desde internet." protocol=icmp
add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" disabled=yes dst-address=127.0.0.1
add action=drop chain=input comment="Impide que nada que no sea un elemento de tu lista LAN acceda al propio equipo" in-interface-list=!LANs
add action=accept chain=forward comment="Acepta que los elementos LAN y el exterior se puedan comunicar con una policy de IPSec." ipsec-policy=in,ipsec
add action=accept chain=forward comment="Acepta que los elementos LAN y el exterior se puedan comunicar con una policy de IPSec." ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
add action=accept chain=forward comment="Esa regla lo que hace es saltarse el flujo de paquetes que seguir\EDa cualquier paquete en el chain de forward, para toda conexi\F3n ya activa." connection-state=established,related,untracked
add action=drop chain=forward comment="Al igual que en input, paquetes marcados como inv\E1lidos, los rechazamos.\r\
\n" connection-state=invalid
add action=drop chain=forward comment="Esta es la excepci\F3n que confirma la regla. S\F3lo vamos a aceptar nuevas conexiones que vienen del exterior a nuestra LAN, si dicho tr\E1fico est\E1 expl\EDcitamente declarado en el NAT." \
connection-nat-state=!dstnat connection-state=new in-interface-list=WANs
add action=drop chain=forward in-interface=4-WIFI out-interface-list=VLANs
add action=drop chain=forward in-interface-list=VLANs out-interface=4-WIFI
add action=drop chain=forward in-interface=3-DOMOTICA out-interface=4-WIFI
add action=drop chain=forward in-interface=4-WIFI out-interface=3-DOMOTICA
add action=drop chain=forward in-interface=3-DOMOTICA out-interface-list=VLANs
add action=drop chain=forward in-interface=3-DOMOTICA out-interface=5-SWITCH
add action=drop chain=forward in-interface=5-SWITCH out-interface=3-DOMOTICA
add action=drop chain=forward in-interface-list=VLANs out-interface=3-DOMOTICA
add action=drop chain=forward dst-address=192.168.55.0/24 src-address=192.168.44.0/24
add action=drop chain=forward dst-address=192.168.66.0/24 src-address=192.168.44.0/24
add action=drop chain=forward dst-address=192.168.77.0/24 src-address=192.168.44.0/24
add action=drop chain=forward dst-address=192.168.44.0/24 src-address=192.168.55.0/24
add action=drop chain=forward dst-address=192.168.66.0/24 src-address=192.168.55.0/24
add action=drop chain=forward dst-address=192.168.77.0/24 src-address=192.168.55.0/24
add action=drop chain=forward dst-address=192.168.88.0/24 src-address=192.168.55.0/24
add action=drop chain=forward dst-address=192.168.44.0/24 src-address=192.168.66.0/24
add action=drop chain=forward dst-address=192.168.55.0/24 src-address=192.168.66.0/24
add action=drop chain=forward dst-address=192.168.77.0/24 src-address=192.168.66.0/24
add action=drop chain=forward dst-address=192.168.88.0/24 src-address=192.168.66.0/24
add action=drop chain=forward dst-address=192.168.44.0/24 src-address=192.168.77.0/24
add action=drop chain=forward dst-address=192.168.55.0/24 src-address=192.168.77.0/24
add action=drop chain=forward dst-address=192.168.66.0/24 src-address=192.168.77.0/24
add action=drop chain=forward dst-address=192.168.88.0/24 src-address=192.168.77.0/24
add action=drop chain=forward dst-address=192.168.44.0/24 src-address=192.168.88.0/24
add action=drop chain=forward dst-address=192.168.55.0/24 src-address=192.168.88.0/24
add action=drop chain=forward dst-address=192.168.66.0/24 src-address=192.168.88.0/24
add action=drop chain=forward dst-address=192.168.77.0/24 src-address=192.168.88.0/24
/ip firewall nat
add action=masquerade chain=srcnat comment="Como tienes una IP p\FAblica din\E1mica, no puedes usar una regla de src-nat directamente para cambiar unas por otras (si la tuvieras y fuera est\E1tica, esa regla ser\EDa incuso m\E1s simple), as\ED que ti\
enes que tirar de un \"truco\" para salir a internet: usar un sub-grupo dentro del src-nat: el masquerade. Esta regla enmascara todo tr\E1fico saliente no encriptado que acabe saliendo por cualquier interfaz dentro de tu lista WAN. De esa manera \
tan elegante, resuelves el problema de no tener una IP p\FAblica est\E1tica. " ipsec-policy=out,none out-interface-list=WANs
/system clock
set time-zone-name=Europe/Madrid
/system identity
set name=AlberTIK
/tool mac-server
set allowed-interface-list=LANs
/tool mac-server mac-winbox
set allowed-interface-list=LANs