/interface ethernet
set [ find default-name=ether1 ] name=1-wan
set [ find default-name=ether2 ] name=2-wan
set [ find default-name=ether3 ] name=3-cfg1
set [ find default-name=ether4 ] name=4-cfg2
set [ find default-name=ether5 ] name=5-sw
set [ find default-name=sfp1 ] disabled=yes
/interface vlan
add interface=5-sw name=vlan-A1 vlan-id=212
add interface=5-sw name=vlan-D1 vlan-id=213
add interface=5-sw name=vlan-D2 vlan-id=214
add interface=5-sw name=vlan-D3 vlan-id=215
add interface=5-sw name=vlan-D4 vlan-id=216
add interface=5-sw name=vlan-RP vlan-id=211
add interface=5-sw name=vlan-wf1 vlan-id=207
add interface=5-sw name=vlan-wf2 vlan-id=208
add interface=1-wan name=vlan20 vlan-id=20
/interface pppoe-client
add add-default-route=yes disabled=no interface=vlan20 max-mru=1492 max-mtu=1492 name=pppoe-out1 user=xxx
/interface list
add name=WAN
add name=LAN
/ip pool
add name=pool-cfg1 ranges=192.168.3.100-192.168.3.200
add name=pool-cfg2 ranges=192.168.4.100-192.168.4.200
add name=pool-wf1 ranges=192.168.207.100-192.168.207.200
add name=pool-wf2 ranges=192.168.208.100-192.168.208.200
add name=pool-A1 ranges=192.168.212.100-192.168.212.200
add name=pool-D1 ranges=192.168.213.100-192.168.213.200
add name=pool-D2 ranges=192.168.214.100-192.168.214.200
add name=pool-D3 ranges=192.168.215.100-192.168.215.200
add name=pool-D4 ranges=192.168.216.100-192.168.216.200
add name=pool-RP ranges=192.168.211.100-192.168.211.200
add name=vpn-pool ranges=192.168.100.2-192.168.100.254
/ip dhcp-server
add address-pool=pool-cfg1 disabled=no interface=3-cfg1 name=dhcp-cfg1
add address-pool=pool-cfg2 disabled=no interface=4-cfg2 name=dhcp-cfg2
add address-pool=pool-wf1 disabled=no interface=vlan-wf1 name=dhcp-wf1
add address-pool=pool-wf2 disabled=no interface=vlan-wf2 name=dhcp-wf2
add address-pool=pool-A1 disabled=no interface=vlan-A1 name=dhcp-A1
add address-pool=pool-D1 disabled=no interface=vlan-D1 name=dhcp-D1
add address-pool=pool-D2 disabled=no interface=vlan-D2 name=dhcp-D2
add address-pool=pool-D3 disabled=no interface=vlan-D3 name=dhcp-D3
add address-pool=pool-D4 disabled=no interface=vlan-D4 name=dhcp-D4
add address-pool=pool-RP disabled=no interface=vlan-RP name=dhcp-RP
/ppp profile
add change-tcp-mss=yes interface-list=LAN local-address=192.168.100.1 name=vpn-profile remote-address=vpn-pool use-encryption=yes
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface detect-internet
set detect-interface-list=all
/interface l2tp-server server
set authentication=mschap2 default-profile=vpn-profile enabled=yes use-ipsec=yes
/interface list member
add interface=3-cfg1 list=LAN
add interface=4-cfg2 list=LAN
add interface=5-sw list=LAN
add interface=1-wan list=WAN
add interface=pppoe-out1 list=WAN
add interface=2-wan list=WAN
/ip address
add address=192.168.3.1/24 interface=3-cfg1 network=192.168.3.0
add address=192.168.4.1/24 interface=4-cfg2 network=192.168.4.0
add address=192.168.212.1/24 interface=vlan-A1 network=192.168.212.0
add address=192.168.213.1/24 interface=vlan-D1 network=192.168.213.0
add address=192.168.214.1/24 interface=vlan-D2 network=192.168.214.0
add address=192.168.215.1/24 interface=vlan-D3 network=192.168.215.0
add address=192.168.216.1/24 interface=vlan-D4 network=192.168.216.0
add address=192.168.1.2/24 interface=1-wan network=192.168.1.0
add address=192.168.211.1/24 interface=vlan-RP network=192.168.211.0
add address=192.168.207.1/24 interface=vlan-wf1 network=192.168.207.0
add address=192.168.208.1/24 interface=vlan-wf2 network=192.168.208.0
/ip cloud
set ddns-enabled=yes
/ip dhcp-client
add default-route-distance=2 disabled=no interface=2-wan
/ip dhcp-server network
add address=192.168.3.0/24 dns-server=1.1.1.3,1.0.0.3 gateway=192.168.3.1
add address=192.168.4.0/24 dns-server=1.1.1.3,1.0.0.3 gateway=192.168.4.1
add address=192.168.207.0/24 dns-server=1.1.1.3,1.0.0.3 gateway=192.168.207.1
add address=192.168.208.0/24 dns-server=1.1.1.3,1.0.0.3 gateway=192.168.208.1
add address=192.168.211.0/24 dns-server=1.1.1.3,1.0.0.3 gateway=192.168.211.1
add address=192.168.212.0/24 dns-server=1.1.1.3,1.0.0.3 gateway=192.168.212.1
add address=192.168.213.0/24 dns-server=1.1.1.3,1.0.0.3 gateway=192.168.213.1
add address=192.168.214.0/24 dns-server=1.1.1.3,1.0.0.3 gateway=192.168.214.1
add address=192.168.215.0/24 dns-server=1.1.1.3,1.0.0.3 gateway=192.168.215.1
add address=192.168.216.0/24 dns-server=1.1.1.3,1.0.0.3 gateway=192.168.216.1
/ip dns
set allow-remote-requests=yes servers=1.1.1.3 use-doh-server=https://cloudflare-dns.com/dns-query verify-doh-cert=yes
/ip dns static
add address=104.16.248.249 name=cloudfare-dns.com
add address=104.16.249.249 name=cloudfare-dns.com
add address=192.168.88.1 comment=defconf name=router.lan
/ip firewall address-list
add address=192.168.211.0/24 list=aislados
add address=192.168.213.0/24 list=aislados
add address=192.168.214.0/24 list=aislados
add address=192.168.215.0/24 list=aislados
add address=192.168.216.0/24 list=aislados
add address=192.168.212.0/24 list=aislados
add address=192.168.207.0/24 list=aislados
add address=192.168.208.0/24 list=aislados
/ip firewall filter
add action=accept chain=input comment="Acepta established,related,untracked" connection-state=established,related,untracked
add action=accept chain=input comment="allow IPsec" dst-port=4500,500 protocol=udp
add action=accept chain=input comment="allow l2tp" dst-port=1701 protocol=udp
add action=drop chain=input comment="Rechaza invalidas en input" connection-state=invalid
add action=accept chain=input comment="Acepta ping ICMP" protocol=icmp
add action=accept chain=input comment="Acepta established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="Rechaza invalidas en input" connection-state=invalid
add action=accept chain=input comment="Acepta ping ICMP" protocol=icmp
add action=drop chain=input comment="Rechaza todo lo que no venga de la lista LAN" in-interface-list=!LAN
add action=accept chain=forward comment="Acepta trafico ipsec entrante" ipsec-policy=in,ipsec
add action=accept chain=forward comment="Acepta trafico ipsec saliente" ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="Fasttrack para conexiones ya establecidas o relacionadas" connection-state=established,related
add action=accept chain=forward comment="Acepta el resto de trafico no capturado por fasttrack" connection-state=established,related,untracked
add action=drop chain=forward comment="Rechaza invalidas en forward" connection-state=invalid
add action=drop chain=forward comment="Rechaza todo trafico desde la WAN salvo el nateado" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
add action=drop chain=forward comment="bloquea toda comunicacion en forward, a cualquier cosa que no sea internet" out-interface-list=!WAN src-address-list=aislados
add action=drop chain=forward comment="permite solamente conexiones de la centralita con servidor Carlus" dst-address=!159.8.126.226 src-address=192.168.212.200
add action=reject chain=forward disabled=yes reject-with=icmp-network-unreachable src-address-list=bloquear
/ip firewall nat
add action=masquerade chain=srcnat comment=masquerade-wan ipsec-policy=out,none out-interface-list=WAN
add action=masquerade chain=srcnat comment="masq. vpn traffic" src-address=192.168.100.0/24
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www address=192.168.88.0/24,192.168.100.0/24,192.168.2.0/24,192.168.3.0/24,192.168.4.0/24,192.168.216.0/24
set ssh disabled=yes port=2200
set api disabled=yes
set winbox address=192.168.88.0/24,192.168.100.0/24,192.168.2.0/24,192.168.3.0/24,192.168.4.0/24,192.168.216.0/24
set api-ssl disabled=yes
/ip traffic-flow
set interfaces=vlan-A1
/ppp secret
add name=ExternoMK service=l2tp
/system clock
set time-zone-name=Europe/Madrid
/system identity
set name=NewTik
/tool e-mail
(...)
/tool mac-server
set allowed-interface-list=none
/tool mac-server mac-winbox
set allowed-interface-list=none
/tool mac-server ping
set enabled=no