Claro si se, puede, dejen saco las capturas....
Esta sección te permite ver todos los mensajes escritos por este usuario. Ten en cuenta que sólo puedes ver los mensajes escritos en zonas a las que tienes acceso en este momento.
Menú Mostrar Mensajesset 0 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited disabled=\
no full-duplex=yes l2mtu=1598 mac-address=D4:CA:6D:17:FE:B4 master-port=\
none mtu=1500 name=WAN1 speed=100Mbps
set 1 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited disabled=\
no full-duplex=yes l2mtu=1598 mac-address=D4:CA:6D:17:FE:B5 master-port=\
none mtu=1500 name=WAN2 speed=100Mbps
set 2 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited disabled=\
no full-duplex=yes l2mtu=1598 mac-address=D4:CA:6D:17:FE:B6 master-port=\
none mtu=1500 name=WAN3 speed=100Mbps
set 3 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited disabled=\
no full-duplex=yes l2mtu=1598 mac-address=D4:CA:6D:17:FE:B7 master-port=\
none mtu=1500 name=ether4 speed=100Mbps
set 4 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited disabled=\
no full-duplex=yes l2mtu=1598 mac-address=D4:CA:6D:17:FE:B8 master-port=\
none mtu=1500 name=LAN speed=100Mbps
/interface ethernet switch
set 0 mirror-source=none mirror-target=none name=switch1
/ip hotspot profile
set [ find default=yes ] dns-name="" hotspot-address=0.0.0.0 html-directory=\
hotspot http-cookie-lifetime=3d http-proxy=0.0.0.0:0 login-by=\
cookie,http-chap name=default rate-limit="" smtp-server=0.0.0.0 \
split-user-domain=no use-radius=no
/ip hotspot user profile
set [ find default=yes ] idle-timeout=none keepalive-timeout=2m name=default \
shared-users=1 status-autorefresh=1m transparent-proxy=no
/ip ipsec proposal
set [ find default=yes ] auth-algorithms=sha1 disabled=no enc-algorithms=3des \
lifetime=30m name=default pfs-group=modp1024
/ip pool
add name=dhcp_pool1 ranges=192.168.11.2-192.168.11.254
/ip dhcp-server
add address-pool=dhcp_pool1 authoritative=after-2sec-delay bootp-support=static \
disabled=no interface=LAN lease-time=3d name=dhcp1
/ppp profile
set 0 change-tcp-mss=yes name=default only-one=default use-compression=default \
use-encryption=default use-mpls=default use-vj-compression=default
set 1 change-tcp-mss=yes name=default-encryption only-one=default \
use-compression=default use-encryption=yes use-mpls=default \
use-vj-compression=default
/queue type
set 0 kind=pfifo name=default pfifo-limit=50
set 1 kind=pfifo name=ethernet-default pfifo-limit=50
set 2 kind=sfq name=wireless-default sfq-allot=1514 sfq-perturb=5
set 3 kind=red name=synchronous-default red-avg-packet=1000 red-burst=20 \
red-limit=60 red-max-threshold=50 red-min-threshold=10
set 4 kind=sfq name=hotspot-default sfq-allot=1514 sfq-perturb=5
set 5 kind=none name=only-hardware-queue
set 6 kind=mq-pfifo mq-pfifo-limit=50 name=multi-queue-ethernet-default
set 7 kind=pfifo name=default-small pfifo-limit=10
/routing bgp instance
set default as=65530 client-to-client-reflection=yes disabled=no \
ignore-as-path-len=no name=default out-filter="" redistribute-connected=no \
redistribute-ospf=no redistribute-other-bgp=no redistribute-rip=no \
redistribute-static=no router-id=0.0.0.0 routing-table=""
/routing ospf instance
set [ find default=yes ] disabled=no distribute-default=never in-filter=ospf-in \
metric-bgp=auto metric-connected=20 metric-default=1 metric-other-ospf=auto \
metric-rip=20 metric-static=20 name=default out-filter=ospf-out \
redistribute-bgp=no redistribute-connected=no redistribute-other-ospf=no \
redistribute-rip=no redistribute-static=no router-id=0.0.0.0
/routing ospf area
set [ find default=yes ] area-id=0.0.0.0 disabled=no instance=default name=\
backbone type=default
/snmp community
set [ find default=yes ] addresses=0.0.0.0/0 authentication-password="" \
authentication-protocol=MD5 encryption-password="" encryption-protocol=DES \
name=public read-access=yes security=none write-access=no
/system logging action
set 0 memory-lines=100 memory-stop-on-full=no name=memory target=memory
set 1 disk-file-count=2 disk-file-name=log disk-lines-per-file=100 \
disk-stop-on-full=no name=disk target=disk
set 2 name=echo remember=yes target=echo
set 3 bsd-syslog=no name=remote remote-port=514 src-address=0.0.0.0 \
syslog-facility=daemon syslog-severity=auto target=remote
/user group
set read name=read policy="local,telnet,ssh,reboot,read,test,winbox,password,web\
,sniff,sensitive,api,!ftp,!write,!policy" skin=default
set write name=write policy="local,telnet,ssh,reboot,read,write,test,winbox,pass\
word,web,sniff,sensitive,api,!ftp,!policy" skin=default
set full name=full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,wi\
nbox,password,web,sniff,sensitive,api" skin=default
/interface bridge settings
set use-ip-firewall=no use-ip-firewall-for-pppoe=no use-ip-firewall-for-vlan=no
/interface ethernet switch port
set 0 vlan-header=leave-as-is vlan-mode=disabled
set 1 vlan-header=leave-as-is vlan-mode=disabled
set 2 vlan-header=leave-as-is vlan-mode=disabled
set 3 vlan-header=leave-as-is vlan-mode=disabled
set 4 vlan-header=leave-as-is vlan-mode=disabled
set 5 vlan-header=leave-as-is vlan-mode=disabled
/interface l2tp-server server
set authentication=pap,chap,mschap1,mschap2 default-profile=default-encryption \
enabled=no keepalive-timeout=30 max-mru=1460 max-mtu=1460 mrru=disabled
/interface ovpn-server server
set auth=sha1,md5 certificate=none cipher=blowfish128,aes128 default-profile=\
default enabled=no keepalive-timeout=60 mac-address=FE:71:C0:55:4C:13 \
max-mtu=1500 mode=ip netmask=24 port=1194 require-client-certificate=no
/interface pptp-server server
set authentication=mschap1,mschap2 default-profile=default-encryption enabled=\
no keepalive-timeout=30 max-mru=1460 max-mtu=1460 mrru=disabled
/interface sstp-server server
set authentication=pap,chap,mschap1,mschap2 certificate=none default-profile=\
default enabled=no keepalive-timeout=60 max-mru=1500 max-mtu=1500 mrru=\
disabled port=443 verify-client-certificate=no
/ip accounting
set account-local-traffic=no enabled=no threshold=256
/ip accounting web-access
set accessible-via-web=no address=0.0.0.0/0
/ip address
add address=192.168.11.1/24 comment="Red para Clientes" disabled=no interface=\
LAN network=192.168.11.0
add address=192.168.7.100/24 comment="Internet Pantalla" disabled=no interface=\
WAN1 network=192.168.7.0
add address=192.168.16.100/24 comment="Internet Poza Rica" disabled=no \
interface=WAN2 network=192.168.16.0
add address=172.16.1.150/16 disabled=yes interface=WAN3 network=172.16.0.0
add address=192.168.3.100/24 disabled=no interface=WAN3 network=192.168.3.0
/ip dhcp-server config
set store-leases-disk=5m
/ip dhcp-server network
add address=192.168.11.0/24 dhcp-option="" dns-server="" gateway=192.168.11.1 \
ntp-server="" wins-server=""
/ip dns
set allow-remote-requests=yes cache-max-ttl=1w cache-size=5000KiB \
max-udp-packet-size=512 servers=8.8.8.8,8.8.4.4
/ip firewall connection tracking
set enabled=yes generic-timeout=10m icmp-timeout=10s tcp-close-timeout=10s \
tcp-close-wait-timeout=10s tcp-established-timeout=1d tcp-fin-wait-timeout=\
10s tcp-last-ack-timeout=10s tcp-syn-received-timeout=5s \
tcp-syn-sent-timeout=5s tcp-syncookie=no tcp-time-wait-timeout=10s \
udp-stream-timeout=3m udp-timeout=10s
/ip firewall mangle
add action=accept chain=prerouting disabled=no dst-address=192.168.16.0/24 \
in-interface=LAN
add action=accept chain=prerouting disabled=no dst-address=192.168.7.0/24 \
in-interface=LAN
add action=accept chain=prerouting disabled=no dst-address=192.168.11.0/24 \
in-interface=LAN
add action=accept chain=prerouting disabled=no dst-address=192.168.3.0/24 \
in-interface=LAN
add action=mark-connection chain=input disabled=no in-interface=WAN1 \
new-connection-mark=WAN1_mark passthrough=yes
add action=mark-connection chain=input disabled=no in-interface=WAN2 \
new-connection-mark=WAN2_mark passthrough=yes
add action=mark-routing chain=output connection-mark=WAN1_mark disabled=no \
new-routing-mark=to_ISP1 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN2_mark disabled=no \
new-routing-mark=to_ISP2 passthrough=yes
add action=mark-connection chain=prerouting disabled=no dst-address-type=!local \
in-interface=LAN new-connection-mark=WAN1_mark passthrough=yes \
per-connection-classifier=both-addresses-and-ports:2/0
add action=mark-connection chain=prerouting disabled=no dst-address-type=!local \
in-interface=LAN new-connection-mark=WAN2_mark passthrough=yes \
per-connection-classifier=both-addresses-and-ports:2/1
add action=mark-routing chain=prerouting connection-mark=WAN1_mark disabled=no \
in-interface=LAN new-routing-mark=to_ISP1 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=WAN2_mark disabled=no \
in-interface=LAN new-routing-mark=to_ISP2 passthrough=yes
/ip firewall nat
add action=masquerade chain=srcnat disabled=no out-interface=WAN1
add action=masquerade chain=srcnat disabled=no out-interface=WAN2
add action=masquerade chain=srcnat disabled=no out-interface=WAN3
/ip firewall service-port
set ftp disabled=no ports=21
set tftp disabled=no ports=69
set irc disabled=no ports=6667
set h323 disabled=no
set sip disabled=no ports=5060,5061 sip-direct-media=yes
set pptp disabled=no
/ip hotspot service-port
set ftp disabled=no ports=21
/ip neighbor discovery
set WAN1 disabled=no
set WAN2 disabled=no
set WAN3 disabled=no
set ether4 disabled=no
set LAN disabled=no
/ip proxy
set always-from-cache=no cache-administrator=webmaster cache-hit-dscp=4 \
cache-on-disk=no enabled=no max-cache-size=unlimited \
max-client-connections=600 max-fresh-time=3d max-server-connections=600 \
parent-proxy=0.0.0.0 parent-proxy-port=0 port=8080 serialize-connections=no \
src-address=0.0.0.0
/ip route
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=\
8.8.8.8 routing-mark=to_ISP1 scope=30 target-scope=10
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=192.168.7.254 \
routing-mark=to_ISP1 scope=30 target-scope=10
add check-gateway=ping disabled=no distance=2 dst-address=0.0.0.0/0 gateway=\
221.132.112.8 routing-mark=to_ISP2 scope=30 target-scope=10
add disabled=no distance=2 dst-address=0.0.0.0/0 gateway=192.168.16.1 \
routing-mark=to_ISP2 scope=30 target-scope=10
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=10.0.0.1 scope=30 \
target-scope=10
add disabled=no distance=2 dst-address=0.0.0.0/0 gateway=10.0.0.2 scope=30 \
target-scope=10
add disabled=no distance=1 dst-address=8.8.8.8/32 gateway=192.168.1.1 scope=10 \
target-scope=10
add check-gateway=ping disabled=no distance=1 dst-address=10.0.0.1/32 gateway=\
8.8.8.8 scope=10 target-scope=10
add check-gateway=ping disabled=no distance=1 dst-address=10.0.0.2/32 gateway=\
221.132.112.8 scope=10 target-scope=10
add disabled=no distance=1 dst-address=221.132.112.8/32 gateway=192.168.2.1 \
scope=10 target-scope=10
/ip service
set telnet address="" disabled=no port=23
set ftp address="" disabled=no port=21
set www address="" disabled=no port=80
set ssh address="" disabled=no port=22
set www-ssl address="" certificate=none disabled=yes port=443
set api address="" disabled=yes port=8728
set winbox address="" disabled=no port=8291
/ip smb
set allow-guests=yes comment=MikrotikSMB domain=MSHOME enabled=no interfaces=\
all
/ip smb shares
set [ find default=yes ] comment="default share" directory=/pub disabled=no \
max-sessions=10 name=pub
/ip smb users
set [ find default=yes ] disabled=no name=guest password="" read-only=yes
/ip socks
set connection-idle-timeout=2m enabled=no max-connections=200 port=1080
/ip traffic-flow
set active-flow-timeout=30m cache-entries=4k enabled=no inactive-flow-timeout=\
15s interfaces=all
/ip upnp
set allow-disable-external-interface=yes enabled=no show-dummy-rule=yes
/mpls
set dynamic-label-range=16-1048575 propagate-ttl=yes
/mpls interface
set [ find default=yes ] disabled=no interface=all mpls-mtu=1508
/mpls ldp
set distribute-for-default-route=no enabled=no hop-limit=255 loop-detect=no \
lsr-id=0.0.0.0 path-vector-limit=255 transport-address=0.0.0.0 \
use-explicit-null=no
/port firmware
set directory=firmware ignore-directip-modem=no
/ppp aaa
set accounting=yes interim-update=0s use-radius=no
/queue interface
set WAN1 queue=only-hardware-queue
set WAN2 queue=only-hardware-queue
set WAN3 queue=only-hardware-queue
set ether4 queue=only-hardware-queue
set LAN queue=only-hardware-queue
/radius incoming
set accept=no port=3799
/routing bfd interface
set [ find default=yes ] disabled=no interface=all interval=0.2s min-rx=0.2s \
multiplier=5
/routing mme
set bidirectional-timeout=2 gateway-class=none gateway-keepalive=1m \
gateway-selection=no-gateway origination-interval=5s preferred-gateway=\
0.0.0.0 timeout=1m ttl=50
/routing rip
set distribute-default=never garbage-timer=2m metric-bgp=1 metric-connected=1 \
metric-default=1 metric-ospf=1 metric-static=1 redistribute-bgp=no \
redistribute-connected=no redistribute-ospf=no redistribute-static=no \
routing-table=main timeout-timer=3m update-timer=30s
/snmp
set contact="" enabled=no engine-id="" location="" trap-generators="" \
trap-target="" trap-version=1
/system clock
set time-zone-name=manual
/system clock manual
set dst-delta=+00:00 dst-end="jan/01/1970 00:00:00" dst-start=\
"jan/01/1970 00:00:00" time-zone=+00:00
/system identity
set name=MikroTik
/system logging
set 0 action=memory disabled=no prefix="" topics=info
set 1 action=memory disabled=no prefix="" topics=error
set 2 action=memory disabled=no prefix="" topics=warning
set 3 action=echo disabled=no prefix="" topics=critical
/system note
set note="" show-at-login=yes
/system ntp client
set enabled=no mode=broadcast primary-ntp=0.0.0.0 secondary-ntp=0.0.0.0
/system resource irq
set 0 cpu=auto
/system routerboard settings
set boot-device=nand-if-fail-then-ethernet boot-protocol=bootp cpu-frequency=\
400MHz force-backup-booter=no silent-boot=no
/system upgrade mirror
set check-interval=1d enabled=no primary-server=0.0.0.0 secondary-server=\
0.0.0.0 user=""
/system watchdog
set auto-send-supout=no automatic-supout=yes no-ping-delay=5m watch-address=\
none watchdog-timer=yes
/tool bandwidth-server
set allocate-udp-ports-from=2000 authenticate=yes enabled=yes max-sessions=100
/tool e-mail
set address=0.0.0.0 from=<> password="" port=25 starttls=no user=""
/tool graphing
set page-refresh=300 store-every=5min
/tool mac-server
set [ find default=yes ] disabled=no interface=all
/tool mac-server mac-winbox
set [ find default=yes ] disabled=no interface=all
/tool mac-server ping
set enabled=yes
/tool sms
set allowed-number="" channel=0 keep-max-sms=0 receive-enabled=no secret=""
/tool sniffer
set file-limit=1000KiB file-name="" filter-ip-address="" filter-ip-protocol="" \
filter-mac-address="" filter-mac-protocol="" filter-port="" filter-stream=\
yes interface=all memory-limit=100KiB memory-scroll=yes only-headers=no \
streaming-enabled=no streaming-server=0.0.0.0
/tool traffic-generator
set latency-distribution-scale=10 test-id=0
/user aaa
set accounting=yes default-group=read exclude-groups="" interim-update=0s \
use-radius=no
/ip firewall nat
add action=masquerade chain=srcnat disabled=no out-interface=WAN1
add action=masquerade chain=srcnat disabled=no out-interface=WAN2
add action=masquerade chain=srcnat disabled=no out-interface=WAN3
/ip firewall mangle
add action=accept chain=prerouting disabled=no dst-address=192.168.16.0/24 \
in-interface=LAN
add action=accept chain=prerouting disabled=no dst-address=192.168.7.0/24 \
in-interface=LAN
add action=accept chain=prerouting disabled=no dst-address=192.168.11.0/24 \
in-interface=LAN
add action=accept chain=prerouting disabled=no dst-address=192.168.3.0/24 \
in-interface=LAN
add action=mark-connection chain=input disabled=no in-interface=WAN1 \
new-connection-mark=WAN1_mark passthrough=yes
add action=mark-connection chain=input disabled=no in-interface=WAN2 \
new-connection-mark=WAN2_mark passthrough=yes
add action=mark-routing chain=output connection-mark=WAN1_mark disabled=no \
new-routing-mark=to_ISP1 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN2_mark disabled=no \
new-routing-mark=to_ISP2 passthrough=yes
add action=mark-connection chain=prerouting disabled=no dst-address-type=\
!local in-interface=LAN new-connection-mark=WAN1_mark passthrough=yes \
per-connection-classifier=both-addresses-and-ports:2/0
add action=mark-connection chain=prerouting disabled=no dst-address-type=\
!local in-interface=LAN new-connection-mark=WAN2_mark passthrough=yes \
per-connection-classifier=both-addresses-and-ports:2/1
add action=mark-routing chain=prerouting connection-mark=WAN1_mark disabled=\
no in-interface=LAN new-routing-mark=to_ISP1 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=WAN2_mark disabled=\
no in-interface=LAN new-routing-mark=to_ISP2 passthrough=yes
/ip route
add check-gateway=ping disabled=no distance=1 dst-a
8.8.8.8 routing-mark=to_ISP1 scope=30 target-sc
add disabled=no distance=1 dst-address=0.0.0.0/0 ga
routing-mark=to_ISP1 scope=30 target-scope=10
add check-gateway=ping disabled=no distance=2 dst-a
221.132.112.8 routing-mark=to_ISP2 scope=30 tar
add disabled=no distance=2 dst-address=0.0.0.0/0 ga
routing-mark=to_ISP2 scope=30 target-scope=10
add disabled=no distance=1 dst-address=0.0.0.0/0 ga
target-scope=10
add disabled=no distance=2 dst-address=0.0.0.0/0 ga
target-scope=10
add disabled=no distance=1 dst-address=8.8.8.8/32 g
10 target-scope=10
add check-gateway=ping disabled=no distance=1 dst-a
gateway=8.8.8.8 scope=10 target-scope=10
add check-gateway=ping disabled=no distance=1 dst-a
gateway=221.132.112.8 scope=10 target-scope=10
add disabled=no distance=1 dst-address=221.132.112.
scope=10 target-scope=10
ip firewall filter
add action=passthrough chain=unused-hs-chain comment=\
"place hotspot rules here" disabled=yes
add chain=forward comment="Acepta RaptorCache" src-address=192.168.10.0/30
/ip firewall mangle
add action=mark-connection chain=postrouting comment="== RAPTORCACHE ==" \
content="X-Cache: HIT from Raptor" new-connection-mark=raptor-connection \
protocol=tcp src-address=192.168.10.2
add action=mark-packet chain=postrouting connection-mark=raptor-connection \
new-packet-mark=raptor-packs
add action=mark-connection chain=postrouting comment="== SQUID ==" content=\
"X-Cache: HIT from proxy.os.com" new-connection-mark=squid-connection \
protocol=tcp src-address=192.168.10.2
add action=mark-packet chain=postrouting connection-mark=squid-connection \
new-packet-mark=squid-packs
add action=mark-packet chain=prerouting comment="Marcado de paquetes FTP" \
new-packet-mark=ftp_in passthrough=no protocol=tcp src-port=20
add action=mark-packet chain=postrouting dst-port=20 new-packet-mark=ftp_out \
passthrough=no protocol=tcp
add action=mark-packet chain=prerouting new-packet-mark=ftp_21_in \
passthrough=no protocol=tcp src-port=21
add action=mark-packet chain=postrouting dst-port=21 new-packet-mark=\
ftp_21_out passthrough=no protocol=tcp
add action=mark-packet chain=prerouting comment="Marcado de paquetes SSH" \
new-packet-mark=ssh_in passthrough=no protocol=tcp src-port=22
add action=mark-packet chain=postrouting dst-port=22 new-packet-mark=ssh_out \
passthrough=no protocol=tcp
add action=mark-packet chain=prerouting comment="Marcado de paquetes TELNET" \
new-packet-mark=telnet_in passthrough=no protocol=tcp src-port=23
add action=mark-packet chain=postrouting dst-port=23 new-packet-mark=\
telnet_out passthrough=no protocol=tcp
add action=mark-packet chain=prerouting comment="Marcado de paquetes SMTP" \
new-packet-mark=smtp_in passthrough=no protocol=tcp src-port=25
add action=mark-packet chain=postrouting dst-port=25 new-packet-mark=smtp_out \
passthrough=no protocol=tcp
add action=mark-packet chain=prerouting comment=\
"Marcado de paquetes SMTP sobre SSL" new-packet-mark=smtp_ssl_in \
passthrough=no protocol=tcp src-port=465
add action=mark-packet chain=postrouting dst-port=465 new-packet-mark=\
smtp_ssl_out passthrough=no protocol=tcp
add action=mark-packet chain=prerouting comment="Marcado de paquetes DNS" \
new-packet-mark=dns_in passthrough=no protocol=tcp src-port=53
add action=mark-packet chain=postrouting dst-port=53 new-packet-mark=dns_out \
passthrough=no protocol=tcp
add action=mark-packet chain=prerouting new-packet-mark=dns_udp_in \
passthrough=no protocol=udp src-port=53
add action=mark-packet chain=postrouting dst-port=53 new-packet-mark=\
dns_udp_out passthrough=no protocol=udp
add action=mark-packet chain=prerouting comment="Marcado de paquetes WWW" \
new-packet-mark=www_in passthrough=no protocol=tcp src-port=80
add action=mark-packet chain=postrouting dst-port=80 new-packet-mark=www_out \
passthrough=no protocol=tcp
add action=mark-packet chain=prerouting comment="Marcado de paquetes POP3" \
new-packet-mark=pop3_in passthrough=no protocol=tcp src-port=110
add action=mark-packet chain=postrouting dst-port=110 new-packet-mark=\
pop3_out passthrough=no protocol=tcp
add action=mark-packet chain=prerouting new-packet-mark=pop3_995_in \
passthrough=no protocol=tcp src-port=995
add action=mark-packet chain=postrouting dst-port=995 new-packet-mark=\
pop3_995_up passthrough=no protocol=tcp
add action=mark-packet chain=prerouting comment="Marcado de paquetes SQL" \
new-packet-mark=sql_in passthrough=no protocol=tcp src-port=118
add action=mark-packet chain=postrouting dst-port=118 new-packet-mark=sql_up \
passthrough=no protocol=tcp
add action=mark-packet chain=prerouting new-packet-mark=sql_udp_in \
passthrough=no protocol=udp src-port=118
add action=mark-packet chain=postrouting dst-port=118 new-packet-mark=\
sql_udp_up passthrough=no protocol=udp
add action=mark-packet chain=prerouting comment="Marcado de paquetes IMAP" \
new-packet-mark=imap_in passthrough=no protocol=tcp src-port=143
add action=mark-packet chain=postrouting dst-port=143 new-packet-mark=\
imap_out passthrough=no protocol=tcp
add action=mark-packet chain=prerouting new-packet-mark=imap_993_in \
passthrough=no protocol=tcp src-port=993
add action=mark-packet chain=postrouting dst-port=993 new-packet-mark=\
imap_993_out passthrough=no protocol=tcp
add action=mark-packet chain=prerouting comment="Marcado de paquetes HTTPS" \
new-packet-mark=https_in passthrough=no protocol=tcp src-port=443
add action=mark-packet chain=postrouting dst-port=443 new-packet-mark=\
https_out passthrough=no protocol=tcp
add action=mark-packet chain=prerouting comment="Marcado de paquetes MSN" \
new-packet-mark=msn_in passthrough=no protocol=tcp src-port=1863
add action=mark-packet chain=postrouting dst-port=1863 new-packet-mark=\
msn_out passthrough=no protocol=tcp
add action=mark-packet chain=prerouting comment="Marcado de paquetes VoIP" \
new-packet-mark=voip_in passthrough=no protocol=udp src-port=5060
add action=mark-packet chain=postrouting dst-port=5060 new-packet-mark=\
voip_out passthrough=no protocol=udp
add action=mark-packet chain=prerouting new-packet-mark=voip_5061_in \
passthrough=no protocol=tcp src-port=5061
add action=mark-packet chain=postrouting dst-port=5061 new-packet-mark=\
voip_5061_out passthrough=no protocol=tcp
add action=mark-packet chain=prerouting comment=\
"Marcado de paquetes MSN archivos" new-packet-mark=msn_files_in \
passthrough=no protocol=tcp src-port=6891-6900
add action=mark-packet chain=postrouting dst-port=6891-6900 new-packet-mark=\
msn_files_out passthrough=no protocol=tcp
add action=mark-packet chain=prerouting comment="Marcado de paquetes
new-packet-mark=msn_voz_in passthrough=no protocol=tcp src-port=6
add action=mark-packet chain=postrouting dst-port=6901 new-packet-mar
msn_voz_out passthrough=no protocol=tcp
add action=mark-packet chain=prerouting comment="Marcado de paquetes
dst-port=8291 new-packet-mark=winbox_in passthrough=no protocol=t
add action=mark-packet chain=postrouting new-packet-mark=winbox_out \
passthrough=no protocol=tcp src-port=8291
add action=mark-packet chain=prerouting comment="Marcado de paquetes
new-packet-mark=p2p_in p2p=all-p2p passthrough=no
add action=mark-packet chain=postrouting new-packet-mark=p2p_out p2p=
passthrough=no
add action=mark-packet chain=prerouting new-packet-mark=emule_in pass
no protocol=tcp src-port=4662
add action=mark-packet chain=postrouting dst-port=4672 new-packet-mar
emule_out passthrough=no protocol=udp
add action=mark-packet chain=prerouting new-packet-mark=gnutella_6346
passthrough=no protocol=tcp src-port=6346
add action=mark-packet chain=postrouting dst-port=6346 new-packet-mar
gnutella_6346_out passthrough=no protocol=tcp
add action=mark-packet chain=prerouting new-packet-mark=gnutella_6347
passthrough=no protocol=udp src-port=6347
add action=mark-packet chain=postrouting dst-port=6347 new-packet-mar
gnutella_6347_out passthrough=no protocol=udp
add action=mark-packet chain=prerouting new-packet-mark=gnutella_6348
passthrough=no protocol=udp src-port=6348
add action=mark-packet chain=postrouting dst-port=6348 new-packet-mar
gnutella_6348_out passthrough=no protocol=udp
/ip firewall nat
add action=passthrough chain=unused-hs-chain comment=\
"place hotspot rules here" disabled=yes
add action=masquerade chain=srcnat out-interface=WAN
add action=dst-nat chain=dstnat comment="Redirect Raptorcache" dst-po
protocol=tcp src-address=!192.168.10.2 to-addresses=192.168.10.2
to-ports=3128
add action=masquerade chain=srcnat comment="masquerade hotspot networ
src-address=192.168.2.0/24