Не весь конфиг влез
/ip address
add address=192.168.1.20/24 comment="default configuration" interface=\
ether2-master-local network=192.168.1.0
add address=192.168.1.1/24 interface=ether2-master-local network=192.168.1.0
add address= interface=ether1-gateway network=
add address=192.168.1.30/24 interface=ether2-master-local network=192.168.1.0
/ip dhcp-client
add comment="default configuration" interface=ether1-gateway
/ip dhcp-server
add address-pool=dhcp authoritative=after-2sec-delay disabled=no interface=\
bridge-local lease-time=10h10m name=default
/ip dhcp-server network
add address=192.168.1.0/24 dns-server=192.168.1.10,192.168.1.11 gateway=\
192.168.1.1 netmask=24
add address=192.168.88.0/24 comment="default configuration" gateway=\
192.168.88.1 netmask=24
/ip dns
set allow-remote-requests=yes servers=
/ip dns static
add address=192.168.1.30 name=router
/ip firewall filter
add action=accept chain=input in-interface=ether1-gateway protocol=gre
add action=accept chain=input dst-port=1723 in-interface=ether1-gateway \
protocol=tcp
add action=accept chain=input in-interface=ether1-gateway protocol=ipsec-esp
add action=accept chain=input dst-port=161 protocol=udp src-address=\
add action=accept chain=input dst-port=1701,500,4500 in-interface=\
ether1-gateway protocol=udp
add action=accept chain=forward src-address=10.8.0.0/24
add action=fasttrack-connection chain=forward comment="default configuration" \
connection-state=established,related
add action=accept chain=forward comment="default configuration" \
connection-state=established,related
add action=drop chain=forward comment="default configuration" \
connection-state=invalid log-prefix=drop6
add action=drop chain=forward comment="default configuration" \
connection-nat-state=!dstnat connection-state=new in-interface=\
ether1-gateway log-prefix=drop7
add action=accept chain=input protocol=icmp
add action=accept chain=input connection-state=established
add action=accept chain=input connection-state=related
add action=drop chain=input in-interface=ether1-gateway log-prefix=drop8
/ip firewall nat
add action=masquerade chain=srcnat comment="default configuration" \
out-interface=ether1-gateway
/ip ipsec identity
add generate-policy=port-override peer=peer2 policy-template-group=\
l2tp-officegroup remote-id=ignore secret=
/ip pool
add name=dhcp next-pool=dhcp ranges=192.168.1.15-192.168.1.254
add name=pool1 next-pool=dhcp ranges=192.168.1.6
/ip route
add distance=1 gateway=
add distance=1 dst-address=10.8.0.0/24 gateway=
/ip service
set telnet disabled=yes
set ftp address=10.8.0.0/24,192.168.1.0/24
set www address=10.8.0.0/24,192.168.1.0/24
set ssh address=10.8.0.0/24
set api address=10.8.0.0/24
set winbox address=10.8.0.0/24,192.168.1.0/24
set api-ssl address=10.8.0.0/24
/lcd interface pages
set 0 interfaces="sfp1,ether1-gateway,ether2-master-local,ether3-slave-local,e\
ther4-slave-local,ether5-slave-local,ether6-master-local,ether7-slave-loca\
l,ether8-slave-local,ether9-slave-local,ether10-slave-local"
/ppp l2tp-secret
add comment="l2tp office" secret=
/ppp secret
add comment="l2tp office connection" name= password= \
service=l2tp
add comment="pptp office test" name= password= \
profile="pptp office" service=pptp
/snmp
set contact= enabled=yes location="mikrotik office" \
trap-community= trap-generators=interfaces,temp-exception \
trap-interfaces=all
/system clock
set time-zone-name=
/system logging
add topics=dhcp
/tool mac-server
set allowed-interface-list=mactel
/tool mac-server mac-winbox
set allowed-interface-list=mac-winbox
/tool romon port
add