# routerboard: yes # model: CCR1036-12G-4S # serial-number: 468A04C4ECFB # firmware-type: tilegx # factory-firmware: 3.10 # current-firmware: 6.49.18 # upgrade-firmware: 6.49.18 # # channel: long-term # installed-version: 6.49.18 # # Flags: U - undoable, R - redoable, F - floating-undo # ACTION BY POLICY # # software id = WESU-WYDC # # model = CCR1036-12G-4S # serial number = 468A04C4ECFB /interface bridge add name=bridge1 add name=bridge2 add fast-forward=no name=loopbridge /interface ethernet set [ find default-name=ether1 ] comment="LINK " name=ether1-link speed=100Mbps set [ find default-name=ether2 ] comment=PTK-RKT-SR-02 speed=10Mbps set [ find default-name=ether3 ] comment=CONVERSOR-ESCOLA loop-protect=off speed=100Mbps set [ find default-name=ether4 ] comment=PTK-RKT-SR-04 speed=100Mbps set [ find default-name=ether5 ] comment="PTK-GRD-SR-02(Omini)" mtu=1480 speed=100Mbps set [ find default-name=ether6 ] comment="PTK-GRD-SR-01(Grade)" set [ find default-name=ether7 ] comment=PTK-RKT-SR-05 speed=10Mbps set [ find default-name=ether8 ] comment=PTK-PWB-SR-01 set [ find default-name=ether9 ] comment=PTK-ARG-RANDON set [ find default-name=ether10 ] comment="VLAN BRESOLIN (antes BRESOLIN)" set [ find default-name=ether11 ] comment=QUEIMADA disabled=yes /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik /ip pool add name=pool1 ranges=100.65.8.2-100.65.8.254 add comment="Bloqueio IXCSoft" name=pool_bloqueio ranges=172.21.11.0/24 /ppp profile set *0 dns-server=45.236.84.18,45.236.84.19 add change-tcp-mss=yes dns-server=45.236.84.18,45.236.84.19 local-address=192.168.17.1 name=PPPOE_12M only-one=yes rate-limit=15m/15m remote-address=pool1 session-timeout=1d23h use-mpls=no add change-tcp-mss=yes dns-server=45.236.84.18,45.236.84.19 local-address=192.168.17.1 name=PPOE_15M only-one=yes rate-limit=15m/15m remote-address=pool1 session-timeout=1d23h use-mpls=no add comment="{{IXCSoft Aviso de Bloqueio}}" name=pool_bloqueio rate-limit="" remote-address=pool_bloqueio add comment="{{IXCSoft}}" name=Servicos_de_Comunicacao rate-limit="" add comment="{{IXCSoft}}" name=Energia_Eletrica rate-limit="" add comment="{{IXCSoft}}" name=Compra_de_Servicos rate-limit="" add comment="{{IXCSoft}}" name=CTe_Conhecimento_de_Frete rate-limit="" add comment="{{IXCSoft}}" name=SVA_Servico_Valor_Agregado rate-limit="" add comment="{{IXCSoft}}" name=Plano_15_MB_Fibra_ rate-limit="17M/17M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_25_MB_Fibra rate-limit="25M/25M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_35_MB_Fibra rate-limit="35M/35M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_8_MB_Radio_ rate-limit="9M/9M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_60_MB_Fibra rate-limit="61M/61M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_70_MB_Fibra rate-limit="70M/70M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_1_5_MB_Radio rate-limit="1M/1M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_1_5_MB_Radio_Comodato_ rate-limit="2M/2M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_1MB_Radio rate-limit="1M/1M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_2_MB_Radio rate-limit="2M/4M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_4_MB_Radio_ rate-limit="2M/4M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_5_MB_Radio___ rate-limit="2M/5M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Servico_de_Comodato rate-limit="" add comment="{{IXCSoft}}" name=Servico_de_ativacao rate-limit="" add comment="{{IXCSoft}}" name=Servico_de_Ativacao___Gratuito__ rate-limit="" add comment="{{IXCSoft}}" name=Plano_8_MB_Radio rate-limit="4M/9M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_6_MB_Radio rate-limit="2M/6M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Internet_230mbps_Dedicado_Prefeitura rate-limit="100M/100M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Servico_de_Manutencao_de_rede_de_internet_ rate-limit="" add comment="{{IXCSoft}}" name=Servico_de_Abastecimento_de_Agua_ rate-limit="" add comment="{{IXCSoft}}" name=Plano_15_MB_Fibra rate-limit="17M/17M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_5_MB_Radio rate-limit="6M/6M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_10_MB_ rate-limit="11M/11M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=15_MB_Fibra___Prefeitura__ rate-limit="16M/16M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_30_MB_Fibra rate-limit="32M/32M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_10_MB_Radio rate-limit="5M/10M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_5_MB_Radio_ rate-limit="3M/5M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_40_MB_Fibra_ rate-limit="40M/40M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_300_MB_Fibra rate-limit="300M/300M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_130_MB_Fibra rate-limit="65M/130M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Troca_de_Senha rate-limit="" add comment="{{IXCSoft}}" name=Troca_de_Endereco rate-limit="" add comment="{{IXCSoft}}" name=Plano_Ultra_200_MB_Fibra rate-limit="201M/201M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_Ultra_300_MB_Fibra rate-limit="301M/301M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_Ultra_250_MB rate-limit="251M/251M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_50_MB_Fibra_ rate-limit="50M/50M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_Ultra_600_MB rate-limit="600M/600M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name="Plano 80MB" rate-limit="80M/80M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=PLANO_ULTRA_ILIMITADO rate-limit="2500M/2500M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_20_MB_Fibra rate-limit="21M/21M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_100_MB_Fibra rate-limit="100M/100M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_Ultra_800_MB rate-limit="800M/800M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_Ultra_400_MB rate-limit="400M/400M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_200_MB_Fibra rate-limit="202M/200M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_400_MB_Fibra rate-limit="400M/400M 0/0 0/0 0/0 1 0/0" add comment="{{IXCSoft}}" name=Plano_Ultra_500_MB rate-limit="500M/500M 0/0 0/0 0/0 1 0/0" set *FFFFFFFE dns-server=45.236.84.18,45.236.84.19 /routing ospf area add area-id=0.0.0.1 default-cost=1 inject-summary-lsas=yes name=area1 type=stub /routing ospf instance set [ find default=yes ] redistribute-connected=as-type-1 redistribute-static=as-type-1 router-id=192.168.200.4 /snmp community set [ find default=yes ] addresses=0.0.0.0/0 name=public-noway write-access=yes /user group set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,password,web,sniff,sensitive,api,romon,dude,tikapp" add name=backup policy="local,telnet,ssh,ftp,read,write,policy,test,password,sensitive,!reboot,!winbox,!web,!sniff,!api,!romon,!dude,!tikapp" /interface bridge filter add action=accept chain=input mac-protocol=pppoe add action=accept chain=input mac-protocol=pppoe-discovery add action=accept chain=input disabled=yes in-bridge=loopbridge src-mac-address=DC:9F:DB:5A:BF:C3/FF:FF:FF:FF:FF:FF add action=accept chain=input disabled=yes in-bridge=bridge1 src-mac-address=DC:9F:DB:3C:21:4F/FF:FF:FF:FF:FF:FF add action=accept chain=input disabled=yes in-bridge=bridge1 src-mac-address=24:A4:3C:F6:F9:20/FF:FF:FF:FF:FF:FF add action=accept chain=input disabled=yes in-bridge=loopbridge src-mac-address=00:27:22:3C:7A:64/FF:FF:FF:FF:FF:FF add action=accept chain=input disabled=yes mac-protocol=pppoe add action=accept chain=input disabled=yes mac-protocol=pppoe-discovery add action=accept chain=input disabled=yes in-bridge=loopbridge src-mac-address=DC:9F:DB:5A:BF:C3/FF:FF:FF:FF:FF:FF add action=accept chain=input disabled=yes in-bridge=bridge1 src-mac-address=DC:9F:DB:3C:21:4F/FF:FF:FF:FF:FF:FF add action=accept chain=input disabled=yes in-bridge=bridge1 src-mac-address=24:A4:3C:F6:F9:20/FF:FF:FF:FF:FF:FF add action=accept chain=input disabled=yes in-bridge=loopbridge src-mac-address=00:27:22:3C:7A:64/FF:FF:FF:FF:FF:FF /interface bridge port add bridge=bridge2 interface=ether4 add bridge=bridge2 interface=ether9 add bridge=bridge2 disabled=yes interface=ether10 add bridge=bridge2 interface=ether6 add bridge=bridge2 interface=ether3 add bridge=bridge2 interface=ether2 add bridge=bridge2 interface=ether8 add bridge=bridge2 interface=ether7 add bridge=bridge2 interface=ether5 add bridge=bridge2 disabled=yes interface=ether11 /ip firewall connection tracking set enabled=yes /ip neighbor discovery-settings set discover-interface-list=!dynamic /ip settings set max-neighbor-entries=1024 rp-filter=loose tcp-syncookies=yes /interface pppoe-server server # Service is on a slave interface add default-profile=PPPOE_12M disabled=no interface=ether2 max-mru=1480 max-mtu=1480 service-name=PTK-GRD-SR-02 # Service is on a slave interface add default-profile=PPPOE_12M disabled=no interface=ether5 max-mru=1480 max-mtu=1480 service-name=PTK-RKT-SR-04 add default-profile=PPPOE_12M disabled=no interface=bridge2 max-mru=1480 max-mtu=1480 service-name=PTK-RKT-SR-05 add default-profile=PPPOE_12M disabled=no interface=ether10 max-mru=1480 max-mtu=1480 service-name=PTP-PTK-SRxBRESOLIN # Service is on a slave interface add default-profile=PPPOE_12M disabled=no interface=ether7 max-mru=1480 max-mtu=1480 service-name=PTK-ARG-SR-03 add default-profile=PPPOE_12M interface=ether4 max-mru=1480 max-mtu=1480 service-name=PTK-ARG-RND # Service is on a slave interface add default-profile=PPPOE_12M disabled=no interface=ether8 max-mru=1480 max-mtu=1480 service-name=PTK-GRD-SR-01 /ip address add address=192.168.99.172/29 interface=ether1-link network=192.168.99.168 add address=192.168.100.217/29 interface=ether10 network=192.168.100.216 add address=192.168.200.4 interface=loopbridge network=192.168.200.4 add address=192.168.101.65/28 interface=bridge2 network=192.168.101.64 add address=192.168.100.65/29 interface=bridge2 network=192.168.100.64 add address=192.168.100.233/29 interface=ether8 network=192.168.100.232 add address=192.168.101.97/29 interface=ether2 network=192.168.101.96 add address=192.168.100.241/29 interface=ether7 network=192.168.100.240 add address=192.168.101.145/29 interface=ether6 network=192.168.101.144 add address=192.168.100.73/29 interface=ether3 network=192.168.100.72 add address=192.168.5.9/30 disabled=yes interface=ether6 network=192.168.5.8 add address=192.168.1.1/24 disabled=yes interface=ether9 network=192.168.1.0 add address=189.127.169.73 disabled=yes interface=loopbridge network=189.127.169.73 /ip arp add address=192.168.0.34 interface=bridge2 mac-address=68:27:19:96:64:81 /ip dns set servers=45.236.84.18,45.236.84.19,2804:4de8:800:8000::18,2804:4de8:800:8000::19 /ip firewall address-list add address=192.168.199.1 comment="IXCProvedor endereco IP do sistema" list=rede_local /ip firewall filter add action=fasttrack-connection chain=forward add action=drop chain=forward comment="IXCProvedor regra de aviso bloqueio" dst-address=!192.168.199.1 protocol=tcp src-address=172.21.11.0/24 add action=drop chain=forward comment="IXCProvedor regra de aviso bloqueio" dst-address=!192.168.199.1 protocol=tcp src-address-list=aviso_bloqueio add action=drop chain=forward comment="IXCProvedor regra de aviso bloqueio" dst-port=!53 protocol=udp src-address=172.21.11.0/24 add action=drop chain=forward comment="IXCProvedor regra de aviso bloqueio" dst-port=!53 protocol=udp src-address-list=aviso_bloqueio /ip firewall nat add action=src-nat chain=srcnat disabled=yes src-address=192.168.17.0/24 to-addresses=45.236.84.4 add action=accept chain=srcnat disabled=yes dst-address=192.168.0.0/16 src-address=192.168.0.0/16 add action=dst-nat chain=dstnat comment="IXCProvedor regra de aviso bloqueio" dst-address=!181.214.230.16 dst-port=80 protocol=tcp src-address=172.21.11.0/24 to-addresses=181.214.230.16 to-ports=8082 add action=dst-nat chain=dstnat comment="IXCProvedor regra de aviso bloqueio" dst-address=!181.214.230.16 dst-port=80 protocol=tcp src-address-list=aviso_bloqueio to-addresses=181.214.230.16 to-ports=8082 /ip service set telnet disabled=yes set ftp address=192.168.0.0/16,45.236.84.0/22,100.64.0.0/10 disabled=yes port=10021 set www address=192.168.0.0/16,45.236.84.0/22,100.64.0.0/10,0.0.0.0/0 disabled=yes port=8888 set ssh address=45.236.84.0/22,45.236.84.34/32,45.236.86.37/32,192.168.199.1/32 port=10022 set api address=45.236.84.24/32,45.236.84.25/32,45.236.87.255/32,192.168.199.1/32 set winbox address=45.236.84.0/22,45.236.84.34/32,45.236.86.37/32,45.187.80.250/32 port=25000 set api-ssl address=45.236.84.24/32,45.236.84.25/32,45.236.87.255/32,192.168.199.1/32 /ip smb set allow-guests=no interfaces=loopbridge /ip ssh set allow-none-crypto=yes /ppp aaa set interim-update=20m use-radius=yes /ppp secret add name=teste password=Ac4c10 profile=PPPOE_12M service=pppoe /radius add address=45.236.84.27 require-message-auth=no secret=proinfo25. service=ppp src-address=192.168.200.4 add address=192.168.199.1 comment="IXCProvedor configuracao radius" require-message-auth=no secret=radiusixcsoft service=ppp,hotspot,wireless src-address=192.168.200.4 timeout=3s /radius incoming set accept=yes /routing filter add chain=ospf-in prefix=0.0.0.0/0 set-pref-src=192.168.200.4 /routing ospf area range add area=area1 range=100.65.8.0/24 /routing ospf interface add network-type=broadcast passive=yes add interface=ether1-link network-type=point-to-point /routing ospf nbma-neighbor add address=192.168.99.81 add address=192.168.99.150 /routing ospf network add area=backbone disabled=yes network=192.168.0.0/16 add area=backbone disabled=yes network=45.236.84.0/22 add area=area1 network=100.65.8.0/24 add area=area1 network=192.168.200.4/32 add area=backbone network=192.168.99.168/29 add area=backbone network=192.168.99.112/29 /snmp set contact="Acacio Correa " enabled=yes location="[-26.42434465, -51.31973698]" trap-version=2 /system clock set time-zone-autodetect=no time-zone-name=America/Sao_Paulo /system identity set name=Santa_Rosa /system ntp client set enabled=yes primary-ntp=45.236.84.23 secondary-ntp=200.160.0.8 /system package update set channel=long-term /system scheduler add interval=1d name=IXCProvedor_agendamento-backup on-event=IXCProvedor-fazer-e-enviar-backup policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive start-date=dec/08/2025 start-time=04:00:00 /system script add dont-require-permissions=no name=IXCProvedor-fazer-e-enviar-backup owner=ixc.sistema policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive source="export file=backup-mikrotik_Santa_Rosa.rsc; :log info message=\"IXCSoft enviando backup por email\"; /tool e-mail send to=\"acacio@proteknet.com.br\" subject=\"backup-Santa_Rosa\" file=backup-mikrotik_Santa_Rosa.rsc start-tls=yes" /system watchdog set watchdog-timer=no /tool e-mail set address=smtps.uhserver.com from=financeiro@proteknet.com.br password="a56KDanItAjFYbhK57WSGcAJA303==" port=465 user=financeiro@proteknet.com.br /tool netwatch add comment="{IXCSoft Netwatch}" down-script="/ppp secret ; :foreach i in [ find comment~\"IXCSoft PPPOE\" ] do={ enable \$i };" host=192.168.199.1 interval=5m up-script="/ppp secret ; :foreach i in [ find comment~\"IXCSoft PPPOE\" ] do={ disable \$i }; /ppp active; :foreach p in [find comment~\"IXCSoft\"] do={ remove \$p; :delay 1};" /tool romon set enabled=yes secrets=protek-info-12