Это текущая конфигурация IP Web Proxy: включен=да, src-address=0.0.0.0, port=8081, hostname=“proxy”, transparent-proxy=да, parent-proxy=0.0.0.0:0, cache-administrator=“webmaster”, max-object-size=“4096 kB”, cache-drive=system, max-cache-size=none.
/ ip web-proxy access add dst-port=!443,563, method=connect, action=deny, comment=“allow CONNECT only to SSL ports 443 [https] and 563 [snews]”, disabled=no.
/ ip web-proxy cache add url=“cgi-bin \?”, action=deny, comment=“don’t cache dynamic http pages”, disabled=no.
IP Firewall:
set input name=“input”, policy=accept, comment=“”.
set forward name=“forward”, policy=accept, comment=“”.
set output name=“output”, policy=accept, comment=“”.
add name=“hotspot-temp”, policy=none, comment=“limit unauthorized hotspot clients”.
add name=“hotspot”, policy=none, comment=“account authorized hotspot clients”.
/ ip firewall rule forward add in-interface=wlan1, action=jump, jump-target=hotspot-temp, comment=“limit access for unauthorized hotspot clients”, disabled=no.
add action=jump, jump-target=hotspot, comment=“account traffic for authorized hotspot clients”, disabled=no.
/ ip firewall rule hotspot-temp add flow=hs-auth, action=return, comment=“return, if connection is authorized”, disabled=no.
add protocol=icmp, action=return, comment=“allow ping requests”, disabled=no.
add dst-address=:53, protocol=udp, action=return, comment=“allow dns requests”, disabled=no.
add action=reject, comment=“reject access for unauthorized hotspot clients”, disabled=no.
/ ip firewall rule input add in-interface=wlan1, dst-address=:80, protocol=tcp, action=jump, jump-target=hotspot, comment=“account traffic from hotspot clients to hotspot servlet”, disabled=no.
add in-interface=wlan1, dst-address=:80, protocol=tcp, action=accept, comment=“accept requests for hotspot servlet”, disabled=no.
add in-interface=wlan1, dst-address=:67, protocol=udp, action=accept, comment=“accept requests for local DHCP server”, disabled=no.
add in-interface=wlan1, action=jump, jump-target=hotspot-temp, comment=“limit access for unauthorized hotspot clients”, disabled=no.
/ ip firewall rule output add src-address=:80, out-interface=wlan1, protocol=tcp, action=jump, jump-target=hotspot, comment=“account traffic from hotspot servlet to hotspot clients”, disabled=no.
/ ip firewall dst-nat add dst-address=:53, protocol=udp, action=nat to-dst-address=63.98.108.1, comment=“intercept all DNS requests”, disabled=no.
add in-interface=wlan1, protocol=tcp, flow=!hs-auth, action=redirect to-dst-port=80, comment=“redirect unauthorized hotspot clients to hotspot service”, disabled=no.
add dst-address=:25, protocol=tcp, action=nat to-dst-address=63.98.108.4, comment=“send e-mails through our SMTP server”, disabled=no.
add in-interface=wlan1, dst-address=:80, protocol=tcp, action=redirect to-dst-port=80, comment=“transparent HTTP proxy for hotspot clients”, disabled=no.
add in-interface=wlan1, dst-address=!10.5.50.1/32:80, protocol=tcp, action=redirect to-dst-port=8081, comment=“”.
/ ip firewall service-port set ftp ports=21, disabled=no.
set pptp, disabled=no.
set gre, disabled=no.
set h323, disabled=yes.
set mms, disabled=no.
set irc ports=6667, disabled=no.
set quake3, disabled=no.
set tftp ports=69, disabled=no.
/ ip firewall src-nat add src-address=10.5.50.0/24, action=masquerade, comment=“masquerade hotspot network”, disabled=no.
/ ip firewall connection tracking set enabled=yes, tcp-syn-sent-timeout=2m, tcp-syn-received-timeout=1m, tcp-established-timeout=5d, tcp-fin-wait-timeout=2m, tcp-close-wait-timeout=1m, tcp-last-ack-timeout=30s, tcp-time-wait-timeout=2m, tcp-close-timeout=10s, udp-timeout=30s, udp-stream-timeout=3m, icmp-timeout=30s, generic-timeout=10m.
По какой-то причине это все равно не работает.