Wednesday, March 18, 2020

Netflix High Priority + PCQ 10Mb Per User

0 comments

  • Netflix IP Addresses
/ip firewall address-list
add address=23.246.0.0/18 list=NetflixListByITLearnweb
add address=23.246.2.0/24 list=NetflixListByITLearnweb
add address=23.246.3.0/24 list=NetflixListByITLearnweb
add address=23.246.6.0/24 list=NetflixListByITLearnweb
add address=23.246.7.0/24 list=NetflixListByITLearnweb
add address=23.246.10.0/24 list=NetflixListByITLearnweb
add address=23.246.11.0/24 list=NetflixListByITLearnweb
add address=23.246.14.0/24 list=NetflixListByITLearnweb
add address=23.246.15.0/24 list=NetflixListByITLearnweb
add address=23.246.16.0/24 list=NetflixListByITLearnweb
add address=23.246.17.0/24 list=NetflixListByITLearnweb
add address=23.246.20.0/24 list=NetflixListByITLearnweb
add address=23.246.21.0/24 list=NetflixListByITLearnweb
add address=23.246.26.0/24 list=NetflixListByITLearnweb
add address=23.246.27.0/24 list=NetflixListByITLearnweb
add address=23.246.30.0/24 list=NetflixListByITLearnweb
add address=23.246.31.0/24 list=NetflixListByITLearnweb
add address=23.246.36.0/24 list=NetflixListByITLearnweb
add address=23.246.38.0/24 list=NetflixListByITLearnweb
add address=23.246.39.0/24 list=NetflixListByITLearnweb
add address=23.246.41.0/24 list=NetflixListByITLearnweb
add address=23.246.42.0/24 list=NetflixListByITLearnweb
add address=23.246.44.0/24 list=NetflixListByITLearnweb
add address=23.246.45.0/24 list=NetflixListByITLearnweb
add address=23.246.46.0/24 list=NetflixListByITLearnweb
add address=23.246.47.0/24 list=NetflixListByITLearnweb
add address=23.246.48.0/24 list=NetflixListByITLearnweb
add address=23.246.49.0/24 list=NetflixListByITLearnweb
add address=23.246.50.0/24 list=NetflixListByITLearnweb
add address=23.246.51.0/24 list=NetflixListByITLearnweb
add address=23.246.52.0/24 list=NetflixListByITLearnweb
add address=23.246.54.0/24 list=NetflixListByITLearnweb
add address=23.246.55.0/24 list=NetflixListByITLearnweb
add address=23.246.56.0/24 list=NetflixListByITLearnweb
add address=23.246.57.0/24 list=NetflixListByITLearnweb
add address=23.246.58.0/24 list=NetflixListByITLearnweb
add address=23.246.59.0/24 list=NetflixListByITLearnweb
add address=37.77.184.0/21 list=NetflixListByITLearnweb
add address=37.77.186.0/24 list=NetflixListByITLearnweb
add address=37.77.187.0/24 list=NetflixListByITLearnweb
add address=37.77.188.0/24 list=NetflixListByITLearnweb
add address=37.77.189.0/24 list=NetflixListByITLearnweb
add address=45.57.0.0/17 list=NetflixListByITLearnweb
add address=45.57.0.0/24 list=NetflixListByITLearnweb
add address=45.57.1.0/24 list=NetflixListByITLearnweb
add address=45.57.2.0/24 list=NetflixListByITLearnweb
add address=45.57.3.0/24 list=NetflixListByITLearnweb
add address=45.57.4.0/24 list=NetflixListByITLearnweb
add address=45.57.5.0/24 list=NetflixListByITLearnweb
add address=45.57.6.0/24 list=NetflixListByITLearnweb
add address=45.57.7.0/24 list=NetflixListByITLearnweb
add address=45.57.10.0/24 list=NetflixListByITLearnweb
add address=45.57.11.0/24 list=NetflixListByITLearnweb
add address=45.57.12.0/24 list=NetflixListByITLearnweb
add address=45.57.13.0/24 list=NetflixListByITLearnweb
add address=45.57.14.0/24 list=NetflixListByITLearnweb
add address=45.57.15.0/24 list=NetflixListByITLearnweb
add address=45.57.16.0/24 list=NetflixListByITLearnweb
add address=45.57.17.0/24 list=NetflixListByITLearnweb
add address=45.57.18.0/24 list=NetflixListByITLearnweb
add address=45.57.19.0/24 list=NetflixListByITLearnweb
add address=45.57.20.0/24 list=NetflixListByITLearnweb
add address=45.57.21.0/24 list=NetflixListByITLearnweb
add address=45.57.22.0/24 list=NetflixListByITLearnweb
add address=45.57.23.0/24 list=NetflixListByITLearnweb
add address=45.57.28.0/24 list=NetflixListByITLearnweb
add address=45.57.29.0/24 list=NetflixListByITLearnweb
add address=45.57.32.0/24 list=NetflixListByITLearnweb
add address=45.57.33.0/24 list=NetflixListByITLearnweb
add address=45.57.34.0/24 list=NetflixListByITLearnweb
add address=45.57.35.0/24 list=NetflixListByITLearnweb
add address=45.57.36.0/24 list=NetflixListByITLearnweb
add address=45.57.37.0/24 list=NetflixListByITLearnweb
add address=45.57.44.0/24 list=NetflixListByITLearnweb
add address=45.57.45.0/24 list=NetflixListByITLearnweb
add address=45.57.46.0/24 list=NetflixListByITLearnweb
add address=45.57.47.0/24 list=NetflixListByITLearnweb
add address=45.57.48.0/24 list=NetflixListByITLearnweb
add address=45.57.49.0/24 list=NetflixListByITLearnweb
add address=45.57.56.0/24 list=NetflixListByITLearnweb
add address=45.57.58.0/24 list=NetflixListByITLearnweb
add address=45.57.59.0/24 list=NetflixListByITLearnweb
add address=45.57.60.0/24 list=NetflixListByITLearnweb
add address=45.57.62.0/24 list=NetflixListByITLearnweb
add address=45.57.63.0/24 list=NetflixListByITLearnweb
add address=45.57.64.0/24 list=NetflixListByITLearnweb
add address=45.57.65.0/24 list=NetflixListByITLearnweb
add address=45.57.68.0/24 list=NetflixListByITLearnweb
add address=45.57.69.0/24 list=NetflixListByITLearnweb
add address=45.57.70.0/24 list=NetflixListByITLearnweb
add address=45.57.71.0/24 list=NetflixListByITLearnweb
add address=45.57.72.0/24 list=NetflixListByITLearnweb
add address=45.57.73.0/24 list=NetflixListByITLearnweb
add address=45.57.74.0/24 list=NetflixListByITLearnweb
add address=45.57.75.0/24 list=NetflixListByITLearnweb
add address=45.57.78.0/24 list=NetflixListByITLearnweb
add address=45.57.79.0/24 list=NetflixListByITLearnweb
add address=45.57.80.0/24 list=NetflixListByITLearnweb
add address=45.57.81.0/24 list=NetflixListByITLearnweb
add address=45.57.82.0/24 list=NetflixListByITLearnweb
add address=45.57.83.0/24 list=NetflixListByITLearnweb
add address=45.57.88.0/24 list=NetflixListByITLearnweb
add address=45.57.89.0/24 list=NetflixListByITLearnweb
add address=45.57.92.0/24 list=NetflixListByITLearnweb
add address=45.57.93.0/24 list=NetflixListByITLearnweb
add address=45.57.95.0/24 list=NetflixListByITLearnweb
add address=45.57.98.0/24 list=NetflixListByITLearnweb
add address=45.57.99.0/24 list=NetflixListByITLearnweb
add address=45.57.100.0/24 list=NetflixListByITLearnweb
add address=45.57.101.0/24 list=NetflixListByITLearnweb
add address=45.57.102.0/24 list=NetflixListByITLearnweb
add address=45.57.103.0/24 list=NetflixListByITLearnweb
add address=64.120.128.0/17 list=NetflixListByITLearnweb
add address=66.197.128.0/17 list=NetflixListByITLearnweb
add address=69.53.224.0/19 list=NetflixListByITLearnweb
add address=69.53.225.0/24 list=NetflixListByITLearnweb
add address=69.53.226.0/24 list=NetflixListByITLearnweb
add address=69.53.228.0/24 list=NetflixListByITLearnweb
add address=69.53.242.0/24 list=NetflixListByITLearnweb
add address=108.175.32.0/20 list=NetflixListByITLearnweb
add address=185.2.220.0/22 list=NetflixListByITLearnweb
add address=185.9.188.0/22 list=NetflixListByITLearnweb
add address=192.173.64.0/18 list=NetflixListByITLearnweb
add address=192.173.68.0/24 list=NetflixListByITLearnweb
add address=192.173.70.0/24 list=NetflixListByITLearnweb
add address=192.173.72.0/24 list=NetflixListByITLearnweb
add address=192.173.73.0/24 list=NetflixListByITLearnweb
add address=192.173.74.0/24 list=NetflixListByITLearnweb
add address=192.173.76.0/24 list=NetflixListByITLearnweb
add address=192.173.77.0/24 list=NetflixListByITLearnweb
add address=192.173.78.0/24 list=NetflixListByITLearnweb
add address=192.173.79.0/24 list=NetflixListByITLearnweb
add address=192.173.83.0/24 list=NetflixListByITLearnweb
add address=192.173.127.0/24 list=NetflixListByITLearnweb
add address=198.38.96.0/19 list=NetflixListByITLearnweb
add address=198.38.98.0/24 list=NetflixListByITLearnweb
add address=198.38.99.0/24 list=NetflixListByITLearnweb
add address=198.38.100.0/24 list=NetflixListByITLearnweb
add address=198.38.108.0/24 list=NetflixListByITLearnweb
add address=198.38.109.0/24 list=NetflixListByITLearnweb
add address=198.38.110.0/24 list=NetflixListByITLearnweb
add address=198.38.111.0/24 list=NetflixListByITLearnweb
add address=198.38.112.0/24 list=NetflixListByITLearnweb
add address=198.38.113.0/24 list=NetflixListByITLearnweb
add address=198.38.114.0/24 list=NetflixListByITLearnweb
add address=198.38.115.0/24 list=NetflixListByITLearnweb
add address=198.38.120.0/24 list=NetflixListByITLearnweb
add address=198.38.121.0/24 list=NetflixListByITLearnweb
add address=198.38.122.0/24 list=NetflixListByITLearnweb
add address=198.45.48.0/20 list=NetflixListByITLearnweb
add address=198.45.48.0/24 list=NetflixListByITLearnweb
add address=198.45.49.0/24 list=NetflixListByITLearnweb
add address=198.45.50.0/24 list=NetflixListByITLearnweb
add address=198.45.56.0/24 list=NetflixListByITLearnweb
add address=208.75.76.0/22 list=NetflixListByITLearnweb



  • Firewall Mangle

/ip firewall mangle
add action=mark-packet chain=prerouting new-packet-mark=Netflix_Packets passthrough=yes protocol=tcp src-address-list=NetflixListByITLearnweb


  • Queue Type for (per user bandwidth limit)

/queue type
add kind=pcq name=10MB_Download pcq-classifier=dst-address pcq-dst-address6-mask=64 pcq-rate=10240k pcq-src-address6-mask=64
add kind=pcq name=10MB_Upload pcq-classifier=src-address pcq-dst-address6-mask=64 pcq-rate=10240k pcq-src-address6-mask=64

  • Simple Queue 
/queue simple
add comment="NetFlix 10MB Per User" max-limit=1024M/1024M name=NetFlix packet-marks=Netflix_Packets priority=6/6 queue=10MB_Upload/10MB_Download target=(Your Network Addresses)


Tested Version 6.44.6

Sunday, January 5, 2020

Block HTTPS Sites (Facbook & Youtube) TLS Hosts

1 comments
http://www.itlearnweb.com/2020/01/block-https-sites-facbook-youtube.html
●  Since Most of the Internet now uses HTTPS, it has become much harder to filter specific WWW content. 

● For this reason, RouterOS 6.41 introduces a new firewall option that allows you to block HTTPS websites (TLS traffic). 

● Based on the TLS SNI extension, called “TLSHost”. The new parameter supports GLOB-style patterns.

/ip firewall filter
add chain=forward dst-port=443 protocol=tcp tls-host=*.facebook.com action=reject
add chain=forward dst-port=443 protocol=tcp tls-host=*.youtube.com action=reject

Tuesday, May 28, 2019

Block TikTok App

7 comments
Related image
/ip firewall filter add action=drop chain=forward comment="Tiktok Block " protocol=tcp tls-host=\
    *.musical.ly




copied

Sunday, June 17, 2018

PPTP Server For Wan Network

0 comments


/ip pool
add name=PPTP ranges=174.16.1.2-174.16.1.254
/ip dns
set servers=8.8.8.8,8.8.4.4
/ip firewall service-port
set gre disabled=no
set pptp disabled=no
/ppp profile
add change-tcp-mss=yes local-address=174.16.1.1 name=PPTP remote-address=PPTP \
    use-encryption=yes
/interface pptp-server server
set default-profile=PPTP enabled=yes max-mru=1460 max-mtu=1460
/ppp secret
add name=MyUser password=MyPwd profile=PPTP service=pptp
/ip firewall filter
add action=accept chain=input protocol=gre
add action=accept chain=input dst-port=1723 protocol=tcp
/ip firewall nat
add action=masquerade chain=srcnat comment="PPTP " src-address=\
    174.16.1.2-174.16.1.254

Sunday, October 1, 2017

Mikrotik Users Base Routing (PPPoE Users)

8 comments
/ip address
add address=192.168.1.10/24 interface=ether1 network=192.168.1.0
add address=192.168.2.10/24 interface=ether2 network=192.168.2.0
add address=10.10.0.1/24 interface=ether5 network=10.10.0.0
/ip dns
set servers=8.8.8.8,8.8.8.4.4

/ip pool
add name=ISP-1 ranges=172.16.1.1-172.16.1.254
add name=ISP-2 ranges=172.16.2.1-172.16.2.254

/ip firewall address-list
add address=172.16.1.0/24 list=ISP-1
add address=172.16.2.0/24 list=ISP-2
/ip firewall mangle
add action=mark-routing chain=prerouting new-routing-mark=isp1routing \
    passthrough=no src-address-list=ISP-1
add action=mark-routing chain=prerouting new-routing-mark=isp2routing \
    passthrough=no src-address-list=ISP-2

/ip route
add comment="ISP-1 Routing" distance=1 gateway=192.168.1.1 routing-mark=\
    isp1routing
add comment="ISP-2 Routing" distance=1 gateway=192.168.2.1 routing-mark=\
    isp2routing

/interface pppoe-server server
add authentication=pap,chap disabled=no interface=ether5 one-session-per-host=\
    yes service-name=service1

/ppp profile
add local-address=10.10.0.1 name=2/2MbISP-2 only-one=yes rate-limit=2M/2M \
    remote-address=ISP-2
add local-address=10.10.0.1 name=2/2MbISP-1 only-one=yes rate-limit=2M/2M \
    remote-address=ISP-1

Sunday, August 27, 2017

Sunday, August 20, 2017

Payment Reminder For PPPoE

19 comments

/ip pool
add name=block ranges=172.16.202.1-172.16.202.254
/ppp profile
add change-tcp-mss=no local-address=10.10.0.1 name=Block rate-limit=100K/100K remote-address=block
/ip firewall nat
add action=redirect chain=dstnat comment="Payment redirect" dst-port=80 protocol=tcp src-address=\
    172.16.202.0/24 to-ports=8080
/ip firewall filter
add action=accept chain=forward comment=Reminder dst-port=53 protocol=tcp src-address=172.16.202.0/24
add action=accept chain=forward dst-port=53 protocol=udp src-address=172.16.202.0/24
add action=drop chain=forward src-address=172.16.202.0/24
/ip proxy
set cache-administrator=AfriCloud enabled=yes max-cache-size=none src-address=0.0.0.0
/ip proxy access
add dst-host=www.paymentreminder.weebly.com
add action=deny redirect-to=www.paymentreminder.weebly.com

Sunday, July 16, 2017

Secondary Link For Backup

10 comments



/interface bonding
add mode=active-backup name=Wan-bonding1 slaves=ether1,ether2
/ip address
add address=98.140.10.54/30 comment="Wan Network" interface=Wan-bonding1 network=\

    98.140.10.52

Sunday, July 9, 2017

Block Daily Motion

1 comments

/ip firewall address-listadd address=198.54.201.0/24 list=DailyMotionadd address=198.54.200.0/24 list=DailyMotionadd address=195.8.214.0/24 list=DailyMotionadd address=195.8.214.0/23 list=DailyMotionadd address=188.65.126.0/24 list=DailyMotionadd address=188.65.125.0/24 list=DailyMotionadd address=188.65.124.0/24 list=DailyMotionadd address=188.65.121.0/24 list=DailyMotionadd address=188.65.120.0/24 list=DailyMotion/ip firewall filteradd action=drop chain=forward comment="Block DailyMotion" dst-address-list=\DailyMotion/

Sunday, July 2, 2017

Friday, June 30, 2017

Site-to-Site GRE Tunnel (MikroTik to MikroTik)

2 comments

Router-1
/interface gre
add !keepalive local-address=41.165.17.158 name=gre-tunnel1 remote-address=95.142.143.17
/ip address
add address=172.16.1.1/30 interface=gre-tunnel1 network=172.16.1.0
/ip route 
  add dst-address=192.168.5.0/24 gateway=172.16.1.2
/
Router-2
/interface gre
add !keepalive local-address=95.142.143.17 name=gre-tunnel1 remote-address=\
    41.165.17.158
/ip address
add address=172.16.1.2/30 interface=gre-tunnel1 network=172.16.1.0
/ip route 
  add dst-address=192.168.2.0/24 gateway=172.16.1.1
/

Friday, June 23, 2017

High Priority For Speed Test 8Mb Per User (speedtest.net)

35 comments


/ip firewall layer7-protocol
add name=SpeedTest regexp="^.+(speedtest).*\\\$"
/ip firewall mangle
add action=mark-connection chain=forward comment="Speed Test Server" \
    layer7-protocol=SpeedTest new-connection-mark=SpeedTest_Con passthrough=yes
add action=mark-connection chain=prerouting new-connection-mark=SpeedTest_Con \
    passthrough=yes protocol=tcp src-port=8080
add action=mark-packet chain=prerouting connection-mark=SpeedTest_Con \
    new-packet-mark=SpeedTest_Packets passthrough=no
add action=mark-connection chain=postrouting dst-port=8080 new-connection-mark=\
    SpeedTest_Con passthrough=yes protocol=tcp
add action=mark-packet chain=postrouting connection-mark=SpeedTest_Con \
    new-packet-mark=SpeedTest_Packets passthrough=no
/queue type
add kind=pcq name=Dow8MB pcq-classifier=dst-address pcq-dst-address6-mask=64 \
    pcq-rate=8192k pcq-src-address6-mask=64
add kind=pcq name=Up8MB pcq-classifier=src-address pcq-dst-address6-mask=64 \
    pcq-rate=8192k pcq-src-address6-mask=64
/queue simple
add comment="Speed Test 8Mb Per User" name="Speed Test" packet-marks=\
    SpeedTest_Packets queue=Up8MB/Dow8MB target=192.168.2.0/24
/

Thursday, June 1, 2017

Secure MikroTik and Limited Access (Winbox, SSH, FTP, Telnet)

2 comments

/tool mac-server
add disabled=yes interface=all
/tool mac-server ping
set enabled=no

/ip firewall filter
add action=drop chain=input comment="Block Mikrotik Discovery" disabled=no dst-port=5678 protocol=udp
add action=drop chain=input comment="Drop All WINBOX Request By MAC Address" disabled=no dst-port=20561 protocol=udp
add action=drop chain=input comment="WINBOX Just Allow On My PC" disabled=no dst-port=8291 protocol=tcp src-address=!##Your IP Address
add action=drop chain=input comment="FTP Just Allow On My PC" disabled=no dst-port=21 protocol=tcp src-address=!##Your IP Address##
add action=drop chain=input comment="SSH Just Allow On My PC" disabled=no dst-port=22 protocol=tcp src-address=!##Your IP Address##
add action=drop chain=input comment="FTP Just Allow On My PC" disabled=no dst-port=23 protocol=tcp src-address=!##Your IP Address##

Tuesday, May 9, 2017

IPIP Tunnel

0 comments

The IPIP tunneling implementation on the MikroTik RouterOS is RFC 2003 compliant. IPIP tunnel is a simple protocol that encapsulates IP packets in IP to make a tunnel between two routers. The IPIP tunnel interface appears as an interface under the interface list. Many routers, including Cisco and Linux, support this protocol. This protocol makes multiple network schemes possible. for more details

IP tunnelling protocol adds the following possibilities to a network setups:
  • to tunnel Intranets over the Internet
  • to use it instead of source routing

##Router-1
##Ether1- WAN IP 42.166.17.158/28
##Ether5- LAN IP 192.168.1.1/24

/interface ethernet
set [ find default-name=ether1 ] name=ether1
set [ find default-name=ether5 ] name=ether5
/interface ipip
add !keepalive name=42.166.17.160 remote-address=42.166.17.160
/ip address
add address=42.166.17.158/28 interface=ether1 network=42.166.17.144
add address=192.168.1.1/24 interface=ether5 network=192.168.1.0
add address=172.16.10.1/30 interface=42.166.17.60 network=172.16.10.0
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1
/ip route
add distance=2 dst-address=192.168.2.0/24 gateway=172.16.10.2


##Router-2
##Ether1- WAN IP 42.166.17.160/28
##Ether5- LAN IP 192.168.2.1/24
/interface ethernet
set [ find default-name=ether1 ] name=ether1
set [ find default-name=ether5 ] name=ether5
/interface ipip
add !keepalive name=42.166.17.158 remote-address=42.166.17.158
/ip address
add address=42.166.17.160/28 interface=ether1 network=42.166.17.144
add address=192.168.2.1/24 interface=ether5 network=192.168.2.0
add address=172.16.10.2/30 interface=42.166.17.158 network=172.16.10.0
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1
/ip route
add distance=2 dst-address=192.168.1.0/24 gateway=172.16.10.1


Sunday, February 19, 2017

IP Cloud (for DSL users)

0 comments

What is IP Cloud ?  

IP Cloud is starting with RouterOS v6.14 MikroTik offers a Dynamic DNS name service for RouterBOARD devices.This means that your device can automatically get a working domain name, this is useful if your IP address changes often, and you want to always know how to connect to your router.






Sunday, February 5, 2017

Send Mikrotik User Manger Backup File Every Day Via E-mail

0 comments


/system script
add name=UserManger policy=\
   ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=":gl\
   obal SenderId #SENDER@gmail.com\r\
   \n:global SenderUser  #USER\r\
   \n:global GmailPwd #SENDER-PWD\r\
   \n:global RecMail #Receive@gmail.com\r\
   \n:local gmailip \"smtp.gmail.com\"\r\
   \n:global sub1 ([/system identity get name])\r\
   \n:global sub2 ([/system clock get time])\r\
   \n:global sub3 ([/system clock get date])\r\
   \n:global UserMangerFile usermanger\r\
   \n:log warning \"Mikrotik Sending UserManger Backup File.....BY >>>>WWW.ITLE\
   ARNWEB.COM<<<<\"\r\
   \n:log warning \"Creating new backup files\"\r\
   \n/tool user-manager database save name=\$UserMangerFile\r\
   \n:delay 10s\r\
   \n/tool e-mail set address=\$gmailip from=\$SenderId password=\$GmailPwd por\
   t=587 start-tls=yes user=\$SenderUser\r\
   \n:log info \"Sending Backup File.....BY >>>>WWW.ITLEARNWEB.COM<<<<\"\r\
   \n/tool e-mail send to=\$RecMail password=\$GmailPwd subject=\"UserManger Ba\
   ckup File (\$sub1 \$sub2 \$sub3) \" from=\$SenderId file=\$UserMangerFile se\
   rver=\$gmailip start-tls=yes\r\
   \n:log warning \"Please Wait....System is Busy\"\r\
   \n:delay 30s\r\
   \n/file remove \$UserMangerFile\r\
   \n:delay 05s\r\
   \n:log warning \"Finished\"\r\
   \n"
/system scheduler
add interval=1d name=UserManger on-event=UserManger policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon start-date=feb/05/2017 start-time=12:00:00

/

Dowload Scripts

Saturday, January 21, 2017

How to change MikroTik login Banner

5 comments






Download SYS-NOTE-FILE

SCRIPT

/system note
set show-at-login=yes
/set note="\t*************************************************************\r\
    \n\t    WARNING - PRIVATE NETWORK DOMAIN - ACCESS PROHIBITED\r\
    \n\r\
    \n       This device is a private network device. Access to this device is\r\
    \n\r\
    \n      not authorized. Any attempt for unauthorized access is being logged\r\
    \n\r\
    \n\t\t and appropriate legal action will be taken.\r\
    \n\t*************************************************************\r\
    \n\r\
    \n\t\t  ############################################# \r\
    \n\t\t  ###########Server Configuration By########### \r\
    \n\t\t  ###############<HAMZA KHALIL>################\r\
    \n\t\t  ############(www.itlearnweb.com)#############\r\
    \n\t\t  #############################################"

Tuesday, December 13, 2016

Connect Multiple Offices With Eoip Tunnel

2 comments
Office Side I Have RB3011UiAS-RM 


Configuration
/interface ethernet
set [find default-name=ether1 ] name=ether1 comment=WAN-Network
set [find default-name=ether2 ] name=ether2
set [find default-name=ether3 ] name=ether3
set [find default-name=ether4 ] name=ether4
set [find default-name=ether5 ] name=ether5
set [find default-name=ether6 ] name=ether6
set [find default-name=ether7 ] name=ether7
set [find default-name=ether8 ] name=ether8
set [find default-name=ether9 ] name=ether9
set [find default-name=ether10 ] name=ether10
/interface eoip add name="2nd Branch" remote-address=###2nd Branch WAN-IP
/interface eoip add name="3nd Branch" remote-address=###3rd Branch WAN-IP
/interface eoip add name="4nd Branch" remote-address=###4th Branch WAN-IP
/interface bridge
add name=DHCP
/interface bridge port
add bridge=DHCP interface=ether2
add bridge=DHCP interface=ether3
add bridge=DHCP interface=ether4
add bridge=DHCP interface=ether5
add bridge=DHCP interface=ether6
add bridge=DHCP interface=ether7
add bridge=DHCP interface=ether8
add bridge=DHCP interface=ether9
add bridge=DHCP interface=ether10
add bridge=DHCP interface="2nd Branch"
add bridge=DHCP interface="3rd Branch"
add bridge=DHCP interface="4th Branch"
/ip address
add address=###your WAN-IP interface=ether1
add address=192.168.10.1/23 interface=DHCP network=192.168.10.0
/ip dns
set servers=8.8.8.8,8.8.4.4
/ip pool
add name=dhcp_pool1 ranges=192.168.10.2-192.168.11.254
/ip dhcp-server
add address-pool=dhcp_pool1 disabled=no interface=DHCP name=dhcp2 lease-time=1h relay=\
    192.168.10.1
/ip dhcp-server network
add address=192.168.10.0/23 dns-server=8.8.8.8,8.8.4.4 gateway=192.168.10.1
/ip firewall nat
add action=masquerade chain=srcnat comment="Masquerade DHCP Network" \
    src-address=192.168.10.0/23
/ip route
add distance=1 gateway=###your gateway
/system identity
set name=Main-Branch

Other Branches Configuration......
we use hexlite

2nd Branch
/interface ethernet
set [find default-name=ether1 ] name=ether1 comment=WAN-Network
set [find default-name=ether2 ] name=ether2
set [find default-name=ether3 ] name=ether3
set [find default-name=ether4 ] name=ether4
set [find default-name=ether5 ] name=ether5
/interface eoip add name="eoip-tunnel1" remote-address=(###Main Branch WAN-IP) tunnel-id=20
/interface bridge
add name=Local-Network
/interface bridge port
add bridge=Local-Network interface=ether2
add bridge=Local-Network interface=ether3
add bridge=Local-Network interface=ether4
add bridge=Local-Network interface=ether5
add bridge=Local-Network interface=eoip-tunnel1
/ip address
add address=(###your WAN-IP) interface=ether1
/ip route
add distance=1 gateway=(###your gateway)
/system identity
set name=2nd-Branch 

3rd Branch
/interface ethernet
set [find default-name=ether1 ] name=ether1 comment=WAN-Network
set [find default-name=ether2 ] name=ether2
set [find default-name=ether3 ] name=ether3
set [find default-name=ether4 ] name=ether4
set [find default-name=ether5 ] name=ether5
/interface eoip add name="eoip-tunnel1" remote-address=(###Main Branch WAN-IP) tunnel-id=30
/interface bridge
add name=Local-Network
/interface bridge port
add bridge=Local-Network interface=ether2
add bridge=Local-Network interface=ether3
add bridge=Local-Network interface=ether4
add bridge=Local-Network interface=ether5
add bridge=Local-Network interface=eoip-tunnel1
/ip address
add address=(###your WAN-IP) interface=ether1
/ip route
add distance=1 gateway=(###your gateway)
/system identity
set name=3rd-Branch

4th Branch
/interface ethernet
set [find default-name=ether1 ] name=ether1 comment=WAN-Network
set [find default-name=ether2 ] name=ether2
set [find default-name=ether3 ] name=ether3
set [find default-name=ether4 ] name=ether4
set [find default-name=ether5 ] name=ether5
/interface eoip add name="eoip-tunnel1" remote-address=(###Main Branch WAN-IP) tunnel-id=40
/interface bridge
add name=Local-Network
/interface bridge port
add bridge=Local-Network interface=ether2
add bridge=Local-Network interface=ether3
add bridge=Local-Network interface=ether4
add bridge=Local-Network interface=ether5
add bridge=Local-Network interface=eoip-tunnel1
/ip address
add address=(###your WAN-IP) interface=ether1
/ip route
add distance=1 gateway=(###your gateway)
/system identity
set name=4th-Branch

Sunday, December 11, 2016

L2TP Tunnel (Remotely Connect To Work Computer From Home)

1 comments

L2TP is a secure tunnel protocol for transporting IP traffic using PPP. L2TP encapsulates PPP in virtual lines that run over IP, Frame Relay and other protocols (that are not currently supported by MikroTik RouterOS). L2TP incorporates PPP and MPPE (Microsoft Point to Point Encryption) to make encrypted links. The purpose of this protocol is to allow the Layer 2 and PPP endpoints to reside on different devices interconnected by a packet-switched network. With L2TP, a user has a Layer 2 connection to an access concentrator - LAC (e.g., modem bank, ADSL DSLAM, etc.), and the concentrator then tunnels individual PPP frames to the Network Access Server - NAS. This allows the actual processing of PPP packets to be separated from the termination of the Layer 2 circuit. From the user's perspective, there is no functional difference between having the L2 circuit terminate in a NAS directly or using L2TP. for more details

/ip pool
add name=L2TP ranges=172.16.100.1-172.16.100.254
/ppp profile
add dns-server=10.10.0.1,8.8.8.8 local-address=10.10.0.1 name=L2TP-VPN \
    remote-address=L2TP
/interface l2tp-server server
set default-profile=L2TP-VPN enabled=yes ipsec-secret=itlearnweb use-ipsec=yes
/ppp secret
add name=test password=test profile=L2TP-VPN service=l2tp
/ip firewall nat
add action=masquerade chain=srcnat comment="L2TP-VPN Masquerade" src-address=\
    172.16.100.1-172.16.100.254