# 2026-07-05 20:54:40 by RouterOS 7.19.3 # software id = HS87-YF95 # # model = CCR2004-1G-12S+2XS # serial number = HFC096TVWEE /interface bridge add name=loopback port-cost-mode=short /interface ethernet set [ find default-name=sfp-sfpplus1 ] auto-negotiation=no set [ find default-name=sfp-sfpplus3 ] comment="Venue: Rubber Soul" set [ find default-name=sfp-sfpplus4 ] comment="Venue: McCooleys MS" set [ find default-name=sfp-sfpplus5 ] comment="Venue: Revolver" set [ find default-name=sfp-sfpplus6 ] comment="Venue: Legends" /interface list add name=neighbour-routers add name=venues /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik /port set 0 name=serial0 set 1 name=serial1 /routing bgp template add as=65500 disabled=no name=pubinvest_core output.no-client-to-client-reflection=no .redistribute=connected,static router-id=10.255.255.246 routing-table=main /routing ospf instance add disabled=no name=default_v2 redistribute=connected /routing ospf area add disabled=no instance=default_v2 name=backbone_v2 /snmp community set [ find default=yes ] addresses=10.1.84.16/32 /ip firewall connection tracking set udp-timeout=10s /interface list member add interface=sfp-sfpplus1 list=neighbour-routers add interface=sfp-sfpplus3 list=venues add interface=sfp-sfpplus4 list=venues add interface=sfp-sfpplus5 list=venues add interface=sfp-sfpplus6 list=venues add interface=ether1 list=venues /interface ovpn-server server add mac-address=FE:F0:28:7C:2D:65 name=ovpn-server1 /ip address add address=10.255.255.246 comment=Loopback interface=loopback network=10.255.255.246 add address=10.254.254.2/30 comment=CR-LEVEL-001 interface=sfp-sfpplus1 network=10.254.254.0 add address=10.254.20.5/30 comment="Reiss Motor Room" interface=sfp-sfpplus2 network=10.254.20.4 add address=10.254.20.9/30 comment="Rubber Soul" interface=sfp-sfpplus3 network=10.254.20.8 add address=10.254.20.13/30 comment="McCooleys MS" interface=sfp-sfpplus4 network=10.254.20.12 add address=10.254.20.17/30 comment=Revolver interface=sfp-sfpplus5 network=10.254.20.16 add address=10.254.20.21/30 comment=Legends interface=sfp-sfpplus6 network=10.254.20.20 add address=10.254.20.25/30 comment=Peppers interface=ether1 network=10.254.20.24 add address=10.255.255.222 interface=loopback network=10.255.255.222 /ip dns set servers=1.1.1.1 /ip firewall address-list add address=10.201.201.0/24 list=management add address=10.255.255.255 list=routers add address=10.255.255.254 list=routers add address=10.255.255.253 list=routers add address=10.255.255.252 list=routers add address=10.255.255.251 list=routers add address=10.255.255.250 list=routers add address=10.255.255.249 list=routers add address=10.255.255.247 list=routers add address=10.255.255.248 list=routers add address=10.1.84.16 list=management add address=10.1.84.206 list=management add address=10.255.255.234 list=routers /ip firewall filter add action=accept chain=input dst-port=179 protocol=tcp src-address-list=routers add action=accept chain=input in-interface-list=neighbour-routers protocol=ospf add action=accept chain=input protocol=icmp add action=accept chain=input dst-port=8291,22 protocol=tcp src-address-list=management add action=accept chain=input dst-port=161 protocol=udp src-address-list=management add action=drop chain=input /ip ipsec profile set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5 /ip route add check-gateway=ping disabled=no dst-address=10.13.0.0/16 gateway=10.254.20.14 routing-table=main suppress-hw-offload=no add check-gateway=ping disabled=no distance=1 dst-address=10.11.0.0/16 gateway=10.254.20.10 pref-src="" routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add check-gateway=ping disabled=no dst-address=10.12.0.0/16 gateway=10.254.20.22 routing-table=main suppress-hw-offload=no add disabled=no dst-address=10.10.0.0/16 gateway=10.254.20.26 routing-table=main suppress-hw-offload=no add check-gateway=ping disabled=no distance=1 dst-address=10.243.1.0/30 gateway=10.254.20.14 pref-src="" routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add disabled=no dst-address=10.90.0.0/16 gateway=10.254.20.10 routing-table=main suppress-hw-offload=no add disabled=no dst-address=10.255.255.255/32 gateway=10.254.254.1 routing-table=main suppress-hw-offload=no add disabled=no dst-address=10.44.0.0/16 gateway=10.254.20.14 routing-table=main suppress-hw-offload=no add disabled=no dst-address=10.246.1.4/30 gateway=10.254.20.14 routing-table=main suppress-hw-offload=no add disabled=no dst-address=10.25.0.0/16 gateway=10.254.20.14 routing-table=main suppress-hw-offload=no add disabled=no dst-address=10.32.0.0/16 gateway=10.254.20.14 routing-table=main suppress-hw-offload=no /routing bgp connection add as=65500 connect=yes disabled=no listen=yes local.address=10.255.255.246 .role=ibgp name=CR-LEVEL-001 output.no-client-to-client-reflection=no .redistribute=connected,static remote.address=10.255.255.255/32 .as=65500 \ routing-table=main templates=pubinvest_core add as=65500 connect=yes disabled=no listen=yes local.address=10.255.255.246 .role=ibgp name=CR-BOSTON-01 output.no-client-to-client-reflection=no .redistribute=connected,static remote.address=10.255.255.254/32 .as=65500 \ router-id=10.255.255.246 routing-table=main templates=pubinvest_core add as=65500 connect=yes disabled=no listen=yes local.address=10.255.255.246 .role=ibgp name=CR-CELTICROOF-001 output.no-client-to-client-reflection=no .redistribute=connected,static remote.address=10.255.255.247/32 .as=\ 65500 router-id=10.255.255.246 routing-table=main templates=pubinvest_core add as=65500 connect=yes disabled=no listen=yes local.address=10.255.255.246 .role=ibgp name=CR-RUBYROOF-01 output.no-client-to-client-reflection=no .redistribute=connected,static remote.address=10.255.255.248/32 .as=\ 65500 router-id=10.255.255.246 routing-table=main templates=pubinvest_core add as=65500 connect=yes disabled=no listen=yes local.address=10.255.255.246 .role=ibgp name=CR-LEVEL-002 output.no-client-to-client-reflection=no .redistribute=connected,static remote.address=10.255.255.250/32 .as=65500 \ router-id=10.255.255.246 routing-table=main templates=pubinvest_core add as=65500 connect=yes disabled=no listen=yes local.address=10.255.255.246 .role=ibgp name=CR-OLDBANKROOF-001 output.no-client-to-client-reflection=no .redistribute=connected,static remote.address=10.255.255.253/32 .as=\ 65500 router-id=10.255.255.246 routing-table=main templates=pubinvest_core add as=65500 connect=yes disabled=no listen=yes local.address=10.255.255.246 .role=ibgp name=CR-LORDSTREETROOF-001 output.no-client-to-client-reflection=no .redistribute=connected,static remote.address=10.255.255.252/32 \ .as=65500 router-id=10.255.255.246 routing-table=main templates=pubinvest_core add as=65500 connect=yes disabled=no listen=yes local.address=10.255.255.246 .role=ibgp name="CHARLOTTE 2" output.no-client-to-client-reflection=no .redistribute=connected,static remote.address=10.255.255.234/32 .as=65500 \ router-id=10.255.255.246 routing-table=main templates=pubinvest_core /routing ospf interface-template add area=backbone_v2 disabled=no networks=10.254.254.0/30 add area=backbone_v2 disabled=no networks=10.255.255.246/32 /snmp set enabled=yes /system clock set time-zone-name=Europe/London /system identity set name=CR-MATHEWSTREET-01 /system logging add disabled=yes topics=bgp /system routerboard settings set enter-setup-on=delete-key /tool romon set enabled=yes [admin@CR-MATHEWSTREET-01] >