#ОБНОВЛЕННЫЙ ОП с финальным экспортом, «дело закрыто»! /20180122/ Всем привет! В итоге правила файрвола пошли лесом. Управление IP будет решаться уже по сервисному принципу. Закрываю тему, спасибо всем, кто пытался помочь! С уважением, IBR
\ software id = 5IAZ-WMI5
model = 2011UiAS
serial number = 724F066F9C98
/interface ethernet
set [ find default-name=ether1 ] comment=WAN mac-address=*********************
set [ find default-name=ether2 ] disabled=yes
set [ find default-name=ether3 ] disabled=yes
set [ find default-name=ether4 ] disabled=yes
set [ find default-name=ether5 ] comment=LAN
set [ find default-name=ether6 ] disabled=yes
set [ find default-name=ether7 ] disabled=yes
set [ find default-name=ether8 ] disabled=yes
set [ find default-name=ether9 ] disabled=yes
set [ find default-name=ether10 ] disabled=yes
set [ find default-name=sfp1 ] disabled=yes
/interface ethernet switch port
set 6 !egress-rate !ingress-rate
set 7 !egress-rate !ingress-rate
set 8 !egress-rate !ingress-rate
set 9 !egress-rate !ingress-rate
set 10 !egress-rate !ingress-rate
set 12 !egress-rate !ingress-rate
/ip pool add name=dhcp_pool_1 ranges=192.168.249.1-192.168.251.254
/ip dhcp-server add address-pool=dhcp_pool_1 disabled=no interface=ether5 lease-time=2d10m name=dhcp1
/ip neighbor discovery-settings set discover-interface-list=!dynamic
/ip address add address=192.168.248.1/22 interface=ether5 network=192.168.248.0
/ip dhcp-client add dhcp-options=hostname,clientid disabled=no interface=ether1
/ip dhcp-server network add address=192.168.248.0/22 dns-server=193.110.57.4,8.8.8.8 gateway=192.168.248.1
/ip firewall nat add action=masquerade chain=srcnat out-interface=ether1 src-address=192.168.248.0/22
/ip service set telnet disabled=yes set www disabled=yes set api disabled=yes set winbox address=192.168.248.0/22 set api-ssl disabled=yes
/system clock set time-zone-name=Europe/Budapest
/system identity set name=MF-M-GW
/system ntp client set enabled=yes server-dns-names=pool.ntp.org,3.hu.pool.ntp.org
\ software id = 5IAZ-WMI5
model = 2011UiAS
serial number = 724F066F9C98
/interface ethernet
set [ find default-name=ether1 ] comment=WAN mac-address=*********************
set [ find default-name=ether2 ] disabled=yes
set [ find default-name=ether3 ] disabled=yes
set [ find default-name=ether4 ] disabled=yes
set [ find default-name=ether5 ] comment=LAN
set [ find default-name=ether6 ] disabled=yes
set [ find default-name=ether7 ] disabled=yes
set [ find default-name=ether8 ] disabled=yes
set [ find default-name=ether9 ] disabled=yes
set [ find default-name=ether10 ] disabled=yes
set [ find default-name=sfp1 ] disabled=yes
/interface ethernet switch port
set 6 !egress-rate !ingress-rate
set 7 !egress-rate !ingress-rate
set 8 !egress-rate !ingress-rate
set 9 !egress-rate !ingress-rate
set 10 !egress-rate !ingress-rate
set 12 !egress-rate !ingress-rate
/ip pool add name=dhcp_pool_1 ranges=192.168.249.1-192.168.251.254
/ip dhcp-server add address-pool=dhcp_pool_1 disabled=no interface=ether5 lease-time=2d10m name=dhcp1
/ip neighbor discovery-settings set discover-interface-list=!dynamic
/ip address add address=192.168.248.1/22 interface=ether5 network=192.168.248.0
/ip dhcp-client add dhcp-options=hostname,clientid disabled=no interface=ether1
/ip dhcp-server network add address=192.168.248.0/22 dns-server=193.110.57.4,8.8.8.8 gateway=192.168.248.1
/ip firewall nat add action=masquerade chain=srcnat out-interface=ether1 src-address=192.168.248.0/22
/ip service set telnet disabled=yes set www disabled=yes set api disabled=yes set winbox address=192.168.248.0/22 set api-ssl disabled=yes
/system clock set time-zone-name=Europe/Budapest
/system identity set name=MF-M-GW
/system ntp client set enabled=yes server-dns-names=pool.ntp.org,3.hu.pool.ntp.org