Добрый день! Пришел на новое место работы, а тут стоит Mikrotik rb2011uias-2hnd в роли шлюза и 2 wAP ac как точки доступа. С микротиками до сих пор ни разу не работал, только с pfSense. Сотрудники жалуются, что интернет отваливается без особых предпосылок, закономерностей увидеть не удалось. Доступ к микротику есть, пароли от точек доступа затерялись в веках, увы. Причем при поиске сетей видно 3 сети - 2, 5 Ггц и некая с wAP на конце
/interface bridge
add admin-mac=E4:8D:8C:0C:4C:2E auto-mac=no fast-forward=no name=bridge-local
/interface ethernet
set [ find default-name=ether1 ] name=ether1-gateway speed=100Mbps
set [ find default-name=ether2 ] name=ether2-master-local speed=100Mbps
set [ find default-name=ether3 ] name=ether3-slave-local speed=100Mbps
set [ find default-name=ether4 ] name=ether4-slave-local speed=100Mbps
set [ find default-name=ether5 ] name=ether5-slave-local speed=100Mbps
set [ find default-name=ether6 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full name=\
ether6-master-local
set [ find default-name=ether7 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full name=\
ether7-slave-local
set [ find default-name=ether8 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full name=\
ether8-slave-local
set [ find default-name=ether9 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full name=\
ether9-slave-local
set [ find default-name=ether10 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full name=\
ether10-slave-local
/caps-man interface
add disabled=no mac-address=64:D1:54:1C:F3:95 master-interface=none name=\
cap10 radio-mac=64:D1:54:1C:F3:95 radio-name=64D1541CF395
add disabled=no mac-address=E4:8D:8C:6B:80:AF master-interface=none name=\
cap11 radio-mac=E4:8D:8C:6B:80:AF radio-name=E48D8C6B80AF
add disabled=no mac-address=E4:8D:8C:4B:0B:26 master-interface=none name=\
cap12 radio-mac=E4:8D:8C:4B:0B:26 radio-name=E48D8C4B0B26
add disabled=no mac-address=E4:8D:8C:BE:0E:E6 master-interface=none name=\
cap13 radio-mac=E4:8D:8C:BE:0E:E6 radio-name=E48D8CBE0EE6
add disabled=no mac-address=E4:8D:8C:BE:0E:E5 master-interface=none name=\
cap14 radio-mac=E4:8D:8C:BE:0E:E5 radio-name=E48D8CBE0EE5
add disabled=no mac-address=E4:8D:8C:72:A2:03 master-interface=none name=\
cap15 radio-mac=E4:8D:8C:72:A2:03 radio-name=E48D8C72A203
add disabled=no mac-address=E4:8D:8C:72:A2:02 master-interface=none name=\
cap16 radio-mac=E4:8D:8C:72:A2:02 radio-name=E48D8C72A202
add disabled=no mac-address=E4:8D:8C:D5:49:6D master-interface=none name=\
cap17 radio-mac=E4:8D:8C:D5:49:6D radio-name=E48D8CD5496D
add disabled=no mac-address=E4:8D:8C:D5:49:6C master-interface=none name=\
cap18 radio-mac=E4:8D:8C:D5:49:6C radio-name=E48D8CD5496C
add disabled=no mac-address=E4:8D:8C:4B:0B:24 master-interface=none name=\
cap21 radio-mac=E4:8D:8C:4B:0B:24
/caps-man datapath
add bridge=bridge-local name=datapath1
/caps-man security
add authentication-types=wpa2-psk encryption=aes-ccm,tkip group-encryption=\
aes-ccm name=security1 passphrase=
/caps-man configuration
add channel.band=5ghz-a/n/ac channel.control-channel-width=20mhz \
channel.extension-channel=Ce channel.frequency=5180 channel.tx-power=38 \
datapath=datapath1 datapath.bridge=bridge-local guard-interval=any name=\
cfg1 rx-chains=0,1,2 security=security1 security.authentication-types=\
wpa2-psk security.encryption=aes-ccm,tkip security.group-encryption=\
aes-ccm security.passphrase= ssid= tx-chains=\
0,1,2
/caps-man interface
add arp=enabled channel.control-channel-width=20mhz channel.frequency=2412 \
configuration=cfg1 configuration.mode=ap configuration.ssid= \
disabled=no l2mtu=0 mac-address=00:00:00:00:00:00 master-interface=none \
mtu=1500 name=cap1 radio-mac=00:00:00:00:00:00
add arp=enabled configuration=cfg1 datapath=datapath1 datapath.bridge=\
bridge-local disabled=no l2mtu=1600 mac-address=E4:8D:8C:72:A1:FA \
master-interface=none mtu=1500 name=cap2 radio-mac=E4:8D:8C:72:A1:FA \
radio-name=E48D8C72A1FA security.authentication-types=wpa2-psk \
security.encryption=aes-ccm security.passphrase=
add arp=enabled configuration=cfg1 configuration.ssid= disabled=\
no l2mtu=1600 mac-address=E4:8D:8C:72:A1:F9 master-interface=none mtu=\
1500 name=cap3 radio-mac=E4:8D:8C:72:A1:F9 radio-name=E48D8C72A1F9
add arp=enabled configuration=cfg1 disabled=no l2mtu=1600 mac-address=\
D4:CA:6D:C6:12:E1 master-interface=none mtu=1500 name=cap4 radio-mac=\
D4:CA:6D:C6:12:E1 radio-name=D4CA6DC612E1
add arp=enabled configuration=cfg1 disabled=no l2mtu=1600 mac-address=\
E4:8D:8C:72:A1:FD master-interface=none mtu=1500 name=cap5 radio-mac=\
E4:8D:8C:72:A1:FD radio-name=E48D8C72A1FD
add arp=enabled configuration=cfg1 disabled=no l2mtu=0 mac-address=\
D4:CA:6D:C6:12:E2 master-interface=none mtu=1500 name=cap6 radio-mac=\
D4:CA:6D:C6:12:E2 radio-name=D4CA6DC612E2
add arp=enabled configuration=cfg1 disabled=no l2mtu=1600 mac-address=\
E4:8D:8C:72:A1:FC master-interface=none mtu=1500 name=cap7 radio-mac=\
E4:8D:8C:72:A1:FC radio-name=E48D8C72A1FC
add arp=enabled configuration=cfg1 disabled=no l2mtu=1600 mac-address=\
E4:8D:8C:6B:80:AE master-interface=none mtu=1500 name=cap8 radio-mac=\
E4:8D:8C:6B:80:AE radio-name=E48D8C6B80AE
add arp=enabled configuration=cfg1 disabled=no l2mtu=1600 mac-address=\
E4:8D:8C:4B:0B:25 master-interface=none mtu=1500 name=cap9 radio-mac=\
E4:8D:8C:4B:0B:25 radio-name=E48D8C4B0B25
/interface ovpn-client
add certificate= cipher=aes256 connect-to= \
disabled=yes mac-address= name= user=
/interface list
add exclude=dynamic name=discover
add name=
add name=mac-winbox
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
add authentication-types=wpa2-psk management-protection=allowed mode=\
dynamic-keys name= supplicant-identity=MikroTik \
wpa-pre-shared-key= wpa2-pre-shared-key=
/interface wireless
set [ find default-name=wlan1 ] antenna-gain=0 band=2ghz-b/g/n country=\
no_country_set disabled=no distance=indoors frequency=2442 \
frequency-mode=manual-txpower mode=ap-bridge security-profile=\
Profile1 ssid= station-roaming=enabled \
wireless-protocol=802.11
/ip ipsec policy group
add name=l2tp-officegroup
/ip ipsec profile
add dh-group=modp1024 enc-algorithm=aes-256,aes-128,3des name=profile_1
/ip ipsec peer
add local-address=192.168.1.1 name=peer2 passive=yes profile=profile_1
/ip ipsec proposal
set [ find default=yes ] auth-algorithms=sha512,sha256,sha1,md5 \
enc-algorithms=aes-256-ctr,aes-128-cbc,3des
/ip pool
add name=l2tp ranges=192.168.1.15-192.168.1.254
/ppp profile
add local-address=l2tp name="pptp office" remote-address=0.0.0.0 \
use-encryption=yes
/snmp community
set [ find default=yes ] addresses=0.0.0.0/0
add addresses=0.0.0.0/0 authentication-password=\
authentication-protocol=SHA1 encryption-password= name=\
security=private
/caps-man manager
set enabled=yes
/caps-man provisioning
add action=create-enabled ip-address-ranges=192.168.1.5-192.168.1.250 \
master-configuration=cfg1 slave-configurations=cfg1
add action=create-enabled ip-address-ranges=192.168.1.55 \
master-configuration=cfg1 radio-mac=D4:CA:6D:C6:12:E2 \
slave-configurations=cfg1
/interface bridge port
add bridge=bridge-local interface=ether2-master-local
add bridge=bridge-local interface=ether6-master-local
add bridge=bridge-local hw=no interface=sfp1
add bridge=bridge-local interface=wlan1
add bridge=bridge-local disabled=yes interface=ether1-gateway
add bridge=bridge-local interface=ether3-slave-local
add bridge=bridge-local interface=ether4-slave-local
add bridge=bridge-local interface=ether5-slave-local
add bridge=bridge-local interface=ether7-slave-local
add bridge=bridge-local interface=ether8-slave-local
add bridge=bridge-local interface=ether9-slave-local
add bridge=bridge-local interface=ether10-slave-local
/ip neighbor discovery-settings
set discover-interface-list=discover
/interface l2tp-server server
set allow-fast-path=yes default-profile=default enabled=yes ipsec-secret=\
use-ipsec=yes
/interface list member
add interface=sfp1 list=discover
add interface=ether2-master-local list=discover
add interface=ether3-slave-local list=discover
add interface=ether4-slave-local list=discover
add interface=ether5-slave-local list=discover
add interface=ether6-master-local list=discover
add interface=ether7-slave-local list=discover
add interface=ether8-slave-local list=discover
add interface=ether9-slave-local list=discover
add interface=ether10-slave-local list=discover
add interface=wlan1 list=discover
add interface=bridge-local list=discover
add interface=cap1 list=discover
add interface=cap2 list=discover
add interface=cap6 list=discover
add interface=cap3 list=discover
add interface=cap4 list=discover
add interface=cap5 list=discover
add interface=cap7 list=discover
add interface=cap8 list=discover
add interface=cap9 list=discover
add interface=cap21 list=discover
add interface=cap10 list=discover
add interface=cap11 list=discover
add interface=cap12 list=discover
add interface=cap13 list=discover
add interface=cap14 list=discover
add interface=cap15 list=discover
add interface=cap16 list=discover
add interface=cap17 list=discover
add interface=cap18 list=discover
add interface=ovpn-out1 list=discover
add interface=ether2-master-local list=mactel
add interface=ether6-master-local list=mactel
add interface=ether2-master-local list=mac-winbox
add interface=wlan1 list=mactel
add interface=ether6-master-local list=mac-winbox
add interface=sfp1 list=mactel
add interface=wlan1 list=mac-winbox
add interface=sfp1 list=mac-winbox
/interface pptp-server server
set authentication=chap,mschap1,mschap2 default-profile="pptp office" \
enabled=yes