You are on page 1of 8

# oct/22/2015 19:12:16 by RouterOS 6.

28
# software id = STGQ-TI0T
#
/queue type
add kind=sfq name=browsing
/queue tree
add limit-at=1M max-limit=2500k name=Master-Browsing parent=ether2 queue=\
default
add limit-at=100k max-limit=2500k name="10.03 WIFI-NET" packet-mark=pack.10.3 \
parent=Master-Browsing queue=browsing
add limit-at=100k max-limit=2500k name=10.11 packet-mark=pack.10.11.WARNET1 \
parent=Master-Browsing queue=browsing
add limit-at=100k max-limit=2500k name=10.12 packet-mark=pack.10.11.WARNET2 \
parent=Master-Browsing queue=browsing
add limit-at=100k max-limit=2500k name=10.13 packet-mark=pack.10.11.WARNET3 \
parent=Master-Browsing queue=browsing
add limit-at=100k max-limit=2500k name=10.14 packet-mark=pack.10.11.WARNET4 \
parent=Master-Browsing queue=browsing
add limit-at=100k max-limit=2500k name=10.15 packet-mark=pack.10.11.WARNET5 \
parent=Master-Browsing queue=browsing
add limit-at=100k max-limit=2500k name=10.16 packet-mark=pack.10.11.WARNET6 \
parent=Master-Browsing queue=browsing
add limit-at=100k max-limit=2500k name=10.17 packet-mark=pack.10.11.WARNET7 \
parent=Master-Browsing queue=browsing
add limit-at=100k max-limit=2500k name=10.18 packet-mark=pack.10.11.WARNET8 \
parent=Master-Browsing queue=browsing
add max-limit=2M name=Gaming-Browser parent=ether2 queue=default
add limit-at=100k max-limit=2048k name=10.101 packet-mark=pack.10.101 parent=\
Gaming-Browser queue=browsing
add limit-at=100k max-limit=2048k name=10.102 packet-mark=pack.10.102 parent=\
Gaming-Browser queue=browsing
add limit-at=100k max-limit=2048k name=10.103 packet-mark=pack.10.103 parent=\
Gaming-Browser queue=browsing
add limit-at=100k max-limit=2048k name=10.104 packet-mark=pack.10.104 parent=\
Gaming-Browser queue=browsing
add limit-at=100k max-limit=2048k name=10.105 packet-mark=pack.10.105 parent=\
Gaming-Browser queue=browsing
add limit-at=100k max-limit=2048k name=10.106 packet-mark=pack.10.106 parent=\
Gaming-Browser queue=browsing
add limit-at=100k max-limit=2048k name=10.107 packet-mark=pack.10.107 parent=\
Gaming-Browser queue=browsing
add limit-at=100k max-limit=2048k name=10.2.OP packet-mark=pack.10.2.OP \
parent=Gaming-Browser queue=browsing
/ip firewall connection tracking
set tcp-established-timeout=6h
/ip address
add address=192.168.1.2/24 interface=ether1 network=192.168.1.0
add address=192.168.10.1/24 interface=ether2 network=192.168.10.0
add address=10.5.7.6/30 comment=Arthacom interface=ether5 network=10.5.7.4
/ip dns
set allow-remote-requests=yes servers=\
172.20.88.254,180.131.145.145,180.131.144.144
/ip firewall address-list
add address=192.168.10.3-192.168.10.18 list=browsing
add address=192.168.10.101-192.168.10.107 list=game
add address=8.8.4.0/24 list=google
add address=8.8.8.0/24 list=google
add address=8.15.202.0/24 list=google
add address=8.34.208.0/21 list=google
add address=8.34.216.0/21 list=google

add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add

address=8.35.192.0/21 list=google
address=8.35.200.0/21 list=google
address=23.236.48.0/20 list=google
address=23.251.128.0/19 list=google
address=64.233.160.0/19 list=google
address=64.233.160.0/24 list=google
address=64.233.161.0/24 list=google
address=64.233.162.0/24 list=google
address=64.233.164.0/24 list=google
address=64.233.165.0/24 list=google
address=64.233.166.0/24 list=google
address=64.233.167.0/24 list=google
address=64.233.168.0/24 list=google
address=64.233.171.0/24 list=google
address=64.233.176.0/24 list=google
address=64.233.181.0/24 list=google
address=64.233.182.0/24 list=google
address=64.233.183.0/24 list=google
address=64.233.185.0/24 list=google
address=64.233.186.0/24 list=google
address=66.102.0.0/20 list=google
address=66.102.2.0/24 list=google
address=66.102.3.0/24 list=google
address=66.102.4.0/24 list=google
address=66.249.64.0/19 list=google
address=66.249.64.0/24 list=google
address=66.249.65.0/24 list=google
address=66.249.66.0/24 list=google
address=66.249.67.0/24 list=google
address=66.249.69.0/24 list=google
address=66.249.70.0/24 list=google
address=66.249.71.0/24 list=google
address=66.249.72.0/24 list=google
address=66.249.73.0/24 list=google
address=66.249.74.0/24 list=google
address=66.249.76.0/24 list=google
address=66.249.77.0/24 list=google
address=66.249.78.0/24 list=google
address=66.249.79.0/24 list=google
address=66.249.89.0/24 list=google
address=66.249.90.0/24 list=google
address=66.249.91.0/24 list=google
address=66.249.92.0/24 list=google
address=70.32.128.0/19 list=google
address=70.32.144.0/24 list=google
address=70.32.148.0/23 list=google
address=72.14.192.0/18 list=google
address=72.14.199.0/24 list=google
address=72.14.208.0/23 list=google
address=72.14.228.0/24 list=google
address=72.14.244.0/23 list=google
address=74.125.0.0/16 list=google
address=74.125.16.0/24 list=google
address=74.125.17.0/24 list=google
address=74.125.18.0/24 list=google
address=74.125.19.0/24 list=google
address=74.125.20.0/24 list=google
address=74.125.21.0/24 list=google
address=74.125.22.0/24 list=google
address=74.125.23.0/24 list=google

add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add

address=74.125.24.0/24 list=google
address=74.125.25.0/24 list=google
address=74.125.26.0/24 list=google
address=74.125.28.0/24 list=google
address=74.125.29.0/24 list=google
address=74.125.30.0/24 list=google
address=74.125.31.0/24 list=google
address=74.125.36.0/24 list=google
address=74.125.37.0/24 list=google
address=74.125.40.0/24 list=google
address=74.125.41.0/24 list=google
address=74.125.42.0/24 list=google
address=74.125.43.0/24 list=google
address=74.125.45.0/24 list=google
address=74.125.46.0/24 list=google
address=74.125.47.0/24 list=google
address=74.125.54.0/23 list=google
address=74.125.58.0/24 list=google
address=74.125.63.0/24 list=google
address=74.125.68.0/24 list=google
address=74.125.69.0/24 list=google
address=74.125.70.0/24 list=google
address=74.125.71.0/24 list=google
address=74.125.72.0/24 list=google
address=74.125.73.0/24 list=google
address=74.125.74.0/24 list=google
address=74.125.75.0/24 list=google
address=74.125.76.0/24 list=google
address=74.125.88.0/23 list=google
address=74.125.90.0/23 list=google
address=74.125.116.0/24 list=google
address=74.125.117.0/24 list=google
address=74.125.118.0/24 list=google
address=74.125.119.0/24 list=google
address=74.125.121.0/24 list=google
address=74.125.129.0/24 list=google
address=74.125.130.0/24 list=google
address=74.125.131.0/24 list=google
address=74.125.133.0/24 list=google
address=74.125.134.0/24 list=google
address=74.125.136.0/24 list=google
address=74.125.137.0/24 list=google
address=74.125.138.0/24 list=google
address=74.125.139.0/24 list=google
address=74.125.141.0/24 list=google
address=74.125.142.0/24 list=google
address=74.125.143.0/24 list=google
address=74.125.176.0/24 list=google
address=74.125.177.0/24 list=google
address=74.125.178.0/24 list=google
address=74.125.180.0/24 list=google
address=74.125.181.0/24 list=google
address=74.125.182.0/24 list=google
address=74.125.183.0/24 list=google
address=74.125.184.0/24 list=google
address=74.125.185.0/24 list=google
address=74.125.186.0/24 list=google
address=74.125.187.0/24 list=google
address=74.125.188.0/24 list=google
address=74.125.189.0/24 list=google

add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add

address=74.125.190.0/24 list=google
address=74.125.192.0/24 list=google
address=74.125.193.0/24 list=google
address=74.125.194.0/24 list=google
address=74.125.195.0/24 list=google
address=74.125.196.0/24 list=google
address=74.125.198.0/24 list=google
address=74.125.200.0/24 list=google
address=74.125.201.0/24 list=google
address=74.125.202.0/24 list=google
address=74.125.203.0/24 list=google
address=74.125.204.0/24 list=google
address=74.125.205.0/24 list=google
address=74.125.206.0/24 list=google
address=74.125.207.0/24 list=google
address=74.125.224.0/24 list=google
address=74.125.225.0/24 list=google
address=74.125.226.0/24 list=google
address=74.125.227.0/24 list=google
address=74.125.228.0/24 list=google
address=74.125.229.0/24 list=google
address=74.125.230.0/24 list=google
address=74.125.231.0/24 list=google
address=74.125.232.0/24 list=google
address=74.125.233.0/24 list=google
address=74.125.234.0/24 list=google
address=74.125.235.0/24 list=google
address=74.125.236.0/24 list=google
address=74.125.237.0/24 list=google
address=74.125.238.0/24 list=google
address=74.125.239.0/24 list=google
address=104.132.20.0/24 list=google
address=104.154.0.0/15 list=google
address=104.196.0.0/14 list=google
address=107.167.160.0/19 list=google
address=107.178.192.0/18 list=google
address=108.59.80.0/20 list=google
address=108.170.192.0/18 list=google
address=108.177.0.0/17 list=google
address=113.197.106.0/24 list=google
address=130.211.0.0/16 list=google
address=142.250.0.0/15 list=google
address=146.148.0.0/17 list=google
address=162.216.148.0/22 list=google
address=162.222.176.0/21 list=google
address=172.217.0.0/16 list=google
address=172.253.0.0/16 list=google
address=173.194.0.0/16 list=google
address=173.194.32.0/24 list=google
address=173.194.33.0/24 list=google
address=173.194.34.0/24 list=google
address=173.194.35.0/24 list=google
address=173.194.36.0/24 list=google
address=173.194.37.0/24 list=google
address=173.194.38.0/24 list=google
address=173.194.39.0/24 list=google
address=173.194.40.0/24 list=google
address=173.194.41.0/24 list=google
address=173.194.42.0/24 list=google
address=173.194.43.0/24 list=google

add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add
add

address=173.194.44.0/24 list=google
address=173.194.45.0/24 list=google
address=173.194.46.0/24 list=google
address=173.194.47.0/24 list=google
address=173.194.64.0/24 list=google
address=173.194.65.0/24 list=google
address=173.194.66.0/24 list=google
address=173.194.67.0/24 list=google
address=173.194.68.0/24 list=google
address=173.194.69.0/24 list=google
address=173.194.70.0/24 list=google
address=173.194.71.0/24 list=google
address=173.194.72.0/24 list=google
address=173.194.73.0/24 list=google
address=173.194.76.0/24 list=google
address=173.194.77.0/24 list=google
address=173.194.78.0/24 list=google
address=173.194.79.0/24 list=google
address=173.194.90.0/24 list=google
address=173.194.91.0/24 list=google
address=173.194.96.0/24 list=google
address=173.194.98.0/24 list=google
address=173.194.99.0/24 list=google
address=173.194.112.0/24 list=google
address=173.194.113.0/24 list=google
address=173.194.117.0/24 list=google
address=173.194.118.0/24 list=google
address=173.194.119.0/24 list=google
address=173.194.120.0/24 list=google
address=173.194.121.0/24 list=google
address=173.194.124.0/24 list=google
address=173.194.126.0/24 list=google
address=173.194.127.0/24 list=google
address=173.194.136.0/24 list=google
address=173.194.140.0/24 list=google
address=173.194.141.0/24 list=google
address=173.194.142.0/24 list=google
address=173.255.112.0/20 list=google
address=192.158.28.0/22 list=google
address=192.178.0.0/15 list=google
address=193.142.125.0/24 list=google
address=199.192.112.0/22 list=google
address=199.223.232.0/21 list=google
address=207.223.160.0/20 list=google
address=209.85.128.0/17 list=google
address=216.58.192.0/19 list=google
address=216.239.32.0/19 list=google
address=216.239.32.0/24 list=google
address=216.239.33.0/24 list=google
address=216.239.34.0/24 list=google
address=216.239.35.0/24 list=google
address=216.239.36.0/24 list=google
address=216.239.38.0/24 list=google
address=216.239.39.0/24 list=google
address=216.239.44.0/23 list=google
address=122.252.128.0/20 list=google
address=125.252.192.0/18 list=google
address=118.214.0.0/15 list=google
address=192.168.10.2 list=game
address=192.168.10.250 list=game

/ip firewall mangle


add action=mark-connection chain=forward comment=OPERATOR dst-port=\
80,443,8001 new-connection-mark=browse.10.2.OPERATOR protocol=tcp \
src-address=192.168.10.2
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
browse.10.2.OPERATOR protocol=udp src-address=192.168.10.2
add action=mark-packet chain=forward connection-mark=browse.10.2.OPERATOR \
in-interface=ether5 new-packet-mark=pack.10.2.OP passthrough=no
add action=mark-connection chain=forward comment="WIFINET HOTSPOT" dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=con.10.3 protocol=tcp \
src-address=192.168.10.3
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
con.10.3 protocol=udp src-address=192.168.10.3
add action=mark-packet chain=forward connection-mark=con.10.3 in-interface=\
ether1 new-packet-mark=pack.10.3 passthrough=no
add action=mark-connection chain=forward comment=WARNET dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=browse.10.11.WARNET1 \
protocol=tcp src-address=192.168.10.11
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
browse.10.11.WARNET1 protocol=udp src-address=192.168.10.11
add action=mark-packet chain=forward connection-mark=browse.10.11.WARNET1 \
in-interface=ether1 new-packet-mark=pack.10.11.WARNET1 passthrough=no
add action=mark-connection chain=forward dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=browse.10.11.WARNET2 \
protocol=tcp src-address=192.168.10.12
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
browse.10.11.WARNET2 protocol=udp src-address=192.168.10.12
add action=mark-packet chain=forward connection-mark=browse.10.11.WARNET2 \
in-interface=ether1 new-packet-mark=pack.10.11.WARNET2 passthrough=no
add action=mark-connection chain=forward dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=browse.10.11.WARNET3 \
protocol=tcp src-address=192.168.10.13
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
browse.10.11.WARNET3 protocol=udp src-address=192.168.10.13
add action=mark-packet chain=forward connection-mark=browse.10.11.WARNET3 \
in-interface=ether1 new-packet-mark=pack.10.11.WARNET3 passthrough=no
add action=mark-connection chain=forward dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=browse.10.11.WARNET4 \
protocol=tcp src-address=192.168.10.14
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
browse.10.11.WARNET4 protocol=udp src-address=192.168.10.14
add action=mark-packet chain=forward connection-mark=browse.10.11.WARNET4 \
in-interface=ether1 new-packet-mark=pack.10.11.WARNET4 passthrough=no
add action=mark-connection chain=forward dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=browse.10.11.WARNET5 \
protocol=tcp src-address=192.168.10.15
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
browse.10.11.WARNET5 protocol=udp src-address=192.168.10.15
add action=mark-packet chain=forward connection-mark=browse.10.11.WARNET5 \
in-interface=ether1 new-packet-mark=pack.10.11.WARNET5 passthrough=no
add action=mark-connection chain=forward dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=browse.10.11.WARNET6 \
protocol=tcp src-address=192.168.10.16
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
browse.10.11.WARNET6 protocol=udp src-address=192.168.10.16
add action=mark-packet chain=forward connection-mark=browse.10.11.WARNET6 \
in-interface=ether1 new-packet-mark=pack.10.11.WARNET6 passthrough=no
add action=mark-connection chain=forward dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=browse.10.11.WARNET7 \
protocol=tcp src-address=192.168.10.17

add action=mark-connection chain=forward dst-port=443 new-connection-mark=\


browse.10.11.WARNET7 protocol=udp src-address=192.168.10.17
add action=mark-packet chain=forward connection-mark=browse.10.11.WARNET7 \
in-interface=ether1 new-packet-mark=pack.10.11.WARNET7 passthrough=no
add action=mark-connection chain=forward dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=browse.10.11.WARNET8 \
protocol=tcp src-address=192.168.10.18
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
browse.10.11.WARNET8 protocol=udp src-address=192.168.10.18
add action=mark-packet chain=forward connection-mark=browse.10.11.WARNET8 \
in-interface=ether1 new-packet-mark=pack.10.11.WARNET8 passthrough=no
add action=mark-connection chain=forward comment=Gaming dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=browse.10.101 protocol=\
tcp src-address=192.168.10.101
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
browse.10.101 protocol=udp src-address=192.168.10.101
add action=mark-packet chain=forward connection-mark=browse.10.101 \
in-interface=ether5 new-packet-mark=pack.10.101 passthrough=no
add action=mark-connection chain=forward dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=browse.10.102 protocol=\
tcp src-address=192.168.10.102
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
browse.10.102 protocol=udp src-address=192.168.10.102
add action=mark-packet chain=forward connection-mark=browse.10.102 \
in-interface=ether5 new-packet-mark=pack.10.102 passthrough=no
add action=mark-connection chain=forward dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=browse.10.103 protocol=\
tcp src-address=192.168.10.103
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
browse.10.103 protocol=udp src-address=192.168.10.103
add action=mark-packet chain=forward connection-mark=browse.10.103 \
in-interface=ether5 new-packet-mark=pack.10.103 passthrough=no
add action=mark-connection chain=forward dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=browse.10.104 protocol=\
tcp src-address=192.168.10.104
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
browse.10.104 protocol=udp src-address=192.168.10.104
add action=mark-packet chain=forward connection-mark=browse.10.104 \
in-interface=ether5 new-packet-mark=pack.10.104 passthrough=no
add action=mark-connection chain=forward dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=browse.10.105 protocol=\
tcp src-address=192.168.10.105
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
browse.10.105 protocol=udp src-address=192.168.10.105
add action=mark-packet chain=forward connection-mark=browse.10.105 \
in-interface=ether5 new-packet-mark=pack.10.105 passthrough=no
add action=mark-connection chain=forward dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=browse.10.106 protocol=\
tcp src-address=192.168.10.106
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
browse.10.106 protocol=udp src-address=192.168.10.106
add action=mark-packet chain=forward connection-mark=browse.10.106 \
in-interface=ether5 new-packet-mark=pack.10.106 passthrough=no
add action=mark-connection chain=forward dst-port=\
80,81,443,3128,1935,8080,8000 new-connection-mark=browse.10.107 protocol=\
tcp src-address=192.168.10.107
add action=mark-connection chain=forward dst-port=443 new-connection-mark=\
browse.10.107 protocol=udp src-address=192.168.10.107
add action=mark-packet chain=forward connection-mark=browse.10.107 \
in-interface=ether5 new-packet-mark=pack.10.107 passthrough=no

/ip firewall nat


add action=masquerade chain=srcnat out-interface=ether1 src-address-list=\
browsing
add action=masquerade chain=srcnat out-interface=ether5 \
src-address-list=game
/ip route
add distance=1 gateway=192.168.1.1 routing-mark=speedy
add distance=1 gateway=10.5.7.5
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www port=1871
set ssh disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/romon port
add disabled=no
/system clock
set time-zone-name=Asia/Jakarta
/system ntp client
set enabled=yes primary-ntp=119.82.243.189 secondary-ntp=203.160.128.59
/system routerboard settings
set cpu-frequency=720MHz protected-routerboot=disabled

You might also like