# serial number = *********************
/interface bridge
add arp=proxy-arp fast-forward=no name=LAN
/interface ethernet
set [ find default-name=ether2 ] comment=NAS name=LAN-ether2
set [ find default-name=ether3 ] comment=LAN-HOME name=LAN-ether3
set [ find default-name=ether4 ] disabled=yes name=LAN-ether4
set [ find default-name=ether5 ] disabled=yes name=LAN-ether5
set [ find default-name=ether1 ] name=WAN-ether1
/interface pppoe-client
add add-default-route=yes disabled=no interface=WAN-ether1 keepalive-timeout=\
5 max-mru=1480 max-mtu=1480 mrru=1600 name=INTERNET password=**************** \
service-name=pptp.**********.ru user=*********
/interface l2tp-client
add connect-to=***.**.124.168 ipsec-secret=****************** name=hidemy.name \
password=******* use-ipsec=yes user=*************
/interface pptp-client
add connect-to=***.**.124.168 name=PPTP_hidemy.name password=****** user=\
******************
/interface bridge port
add bridge=LAN hw=no interface=LAN-ether3
add bridge=LAN hw=no interface=LAN-ether2
add bridge=LAN interface=Wi-Fi-1
/interface l2tp-server server
set authentication=mschap2 enabled=yes ipsec-secret=**************
/ip address
add address=192.168.88.1/24 interface=LAN network=192.168.88.0
add address=10.1.1.1/24 interface=wi-fi-2 network=10.1.1.0
add address=192.168.0.2/24 network=192.168.0.0
/ip firewall mangle
add action=mark-routing chain=prerouting log-prefix="==MR_VPN==" \
new-routing-mark=hidemy.name passthrough=yes src-address=192.168.88.0/24
add action=mark-routing chain=prerouting log-prefix="==MR_VPN2==" \
new-routing-mark=hidemy.name passthrough=yes src-address=10.1.1.0/24
/ip firewall nat
add action=masquerade chain=srcnat out-interface=INTERNET
# PPTP_hidemy.name not ready
add action=masquerade chain=srcnat log=yes log-prefix="==hidemy.name==" \
out-interface=PPTP_hidemy.name
add action=netmap chain=dstnat dst-port=***** log=yes log-prefix="===RDP===" \
protocol=tcp to-addresses=192.168.88.*** to-ports=3389
# no interface
add action=masquerade chain=srcnat log=yes out-interface=*F00000
/ip ipsec peer
add address=0.0.0.0/0 dh-group=modp1024 enc-algorithm=aes-256,aes-128,3des \
exchange-mode=ike2 generate-policy=port-override passive=yes secret=***************
/ip ipsec policy
set 0 dst-address=0.0.0.0/0 protocol=ipsec-esp src-address=0.0.0.0/0
/ip route
add disabled=yes distance=2 gateway=PPTP_hidemy.name routing-mark=hidemy.name
add comment=Routs_to_M29 distance=1 dst-address=192.168.0.0/24 gateway=\
172.16.30.2 pref-src=192.168.88.1
/ppp secret
add local-address=172.16.30.1 name=M29 password=********** profile=\
default-encryption remote-address=172.16.30.2 service=l2tp
add name=iPhone password=************ profile=default-encryption service=l2tp
add local-address=176.16.40.1 name=Y2 password=********** profile=\
default-encryption remote-address=176.16.40.2 service=l2tp
ip route print
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 X S 0.0.0.0/0 PPTP_hidemy.name 2
1 ADS 0.0.0.0/0 INTERNET 1
2 DS 0.0.0.0/0 ***.**.128.1 1
3 ADC 10.1.1.0/24 10.1.1.1 wi-fi-2 0
4 ADC **.***.***.**/32 **.***.***.*** INTERNET 0
5 ADC ***.**.128.0/17 ***.**.***.*** WAN-ether1 0
6 ADC 172.16.30.2/32 172.16.30.1 0
7 A S ;;; Routs_to_M29
192.168.0.0/24 192.168.88.1 172.16.30.2 1
8ADC 192.168.88.0/24 192.168.88.1 LAN 0
Freepbx 14