# 2026-07-05 20:56:54 by RouterOS 7.19.6 # software id = GC2N-9GEZ # # model = RB4011iGS+ # serial number = HGN09NXASMJ /interface bridge add name=loopback vlan-filtering=yes /interface ethernet set [ find default-name=ether1 ] comment="WAN Secondary" set [ find default-name=ether2 ] comment="LAN - Management" set [ find default-name=sfp-sfpplus1 ] comment=WAN /interface vlan add interface=ether2 name=ether2-jsm vlan-id=10 add interface=ether2 name=ether2-pos vlan-id=30 add interface=ether2 name=ether2-public vlan-id=20 add interface=ether2 name=ether2-staff vlan-id=40 /interface list add name=wans add name=neighbours add name=lans /ip dhcp-server option add code=43 name=unifi value=0x01040a01540a add code=67 name=pxe-bios value="'undionly.kpxe'" add code=67 name=pxe-uefi value="'ipxe.efi'" /ip dhcp-server option sets add name=pxe-bios options=pxe-bios add name=pxe-uefi options=pxe-uefi /ip hotspot profile add login-by=http-pap name=heyliverpool radius-interim-update=2m use-radius=yes /ip hotspot add disabled=no interface=ether2-public name=heyliverpool profile=heyliverpool /ip hotspot user profile add name=heyliverpool rate-limit=5M/5M session-timeout=1h status-autorefresh=2m /ip pool add name=lan ranges=10.23.248.10-10.23.248.254 add name=lan_jsm ranges=10.23.0.10-10.23.0.254 add name=lan_staff ranges=10.23.8.10-10.23.11.254 add name=lan_pos ranges=10.23.1.10-10.23.1.254 add name=lan_public ranges=10.23.100.10-10.23.102.254 /ip dhcp-server add address-pool=lan interface=ether2 lease-time=1w name=ether2 add address-pool=lan_jsm interface=ether2-jsm lease-time=1w name=ether2-jsm add address-pool=lan_staff interface=ether2-staff lease-time=10m name=ether2-staff add address-pool=lan_pos interface=ether2-pos lease-time=1w name=ether2-pos add address-pool=lan_public interface=ether2-public lease-time=10m name=ether2-public /port set 0 name=serial0 set 1 name=serial1 /snmp community add addresses=10.1.84.18/32,10.1.84.16/32 name=pubinvest /interface list member add interface=ether1 list=wans add interface=ether2-jsm list=lans add interface=ether2-staff list=lans add interface=ether2-pos list=lans add interface=ether2 list=lans add interface=ether2-public list=lans add interface=sfp-sfpplus1 list=neighbours add interface=sfp-sfpplus1 list=wans /interface ovpn-server server add mac-address=FE:B4:C4:35:EB:D7 name=ovpn-server1 /ip address add address=10.254.30.6/30 interface=sfp-sfpplus1 network=10.254.30.4 add address=10.254.5.46/30 interface=ether1 network=10.254.5.44 add address=10.23.255.255 interface=loopback network=10.23.255.255 add address=10.23.248.1/24 interface=ether2 network=10.23.248.0 add address=10.23.1.1/24 interface=ether2-pos network=10.23.1.0 add address=10.23.0.1/24 interface=ether2-jsm network=10.23.0.0 add address=10.23.100.1/22 interface=ether2-public network=10.23.100.0 add address=10.23.8.1/22 interface=ether2-staff network=10.23.8.0 /ip dhcp-server matcher add address-pool=lan_pos code=93 matching-type=substring name=pxe-uefi32 option-set=pxe-uefi server=ether2-pos value=0x0006 add address-pool=lan_pos code=93 matching-type=substring name=pxe-uefi64 option-set=pxe-uefi server=ether2-pos value=0x0007 add address-pool=lan_pos code=93 matching-type=substring name=pxe-bios option-set=pxe-bios server=ether2-pos value=0x0000 /ip dhcp-server network add address=10.23.0.0/24 dns-server=10.1.84.3,10.1.6.1,10.1.6.2 domain=pubinvest.co.uk gateway=10.23.0.1 add address=10.23.1.0/24 dns-server=10.1.84.3,10.1.6.1,10.1.6.2 domain=pubinvest.co.uk gateway=10.23.1.1 next-server=10.1.84.40 add address=10.23.8.0/22 dns-server=8.8.8.8,8.8.4.4 domain=wifi.pubinvest.co.uk gateway=10.23.8.1 add address=10.23.100.0/22 dns-server=8.8.8.8,8.8.4.4 domain=wifi.pubinvest.co.uk gateway=10.23.100.1 add address=10.23.248.0/24 dhcp-option=unifi dns-server=10.1.84.3,10.1.6.1,10.1.6.2 domain=pubinvest.co.uk gateway=10.23.248.1 /ip dns set servers=8.8.8.8,8.8.4.4 /ip firewall address-list add address=34.117.150.224 list=pos-outbound-permitted add address=34.102.172.235 list=pos-outbound-permitted add address=10.1.84.40 list=pos-outbound-permitted add address=134.122.104.33 list=pos-outbound-permitted add address=10.1.84.39 list=pos-outbound-permitted add address=10.201.201.0/24 list=trusted-inbound add address=10.249.1.0/28 list=trusted-inbound add address=10.1.80.0/21 list=trusted-inbound add address=10.1.6.0/24 list=trusted-inbound add address=10.1.6.5 list=management add address=10.201.201.0/24 list=management add address=10.249.1.2 list=management add address=10.1.80.0/21 list=management add address=10.1.84.18 list=snmp-servers add address=10.1.84.16 list=snmp-servers add address=10.1.84.3 list=ad-servers add address=10.1.6.1 list=ad-servers add address=10.1.6.2 list=ad-servers add address=10.1.84.10 list=unifi add address=10.1.88.10 list=ad-servers /ip firewall filter add action=passthrough chain=unused-hs-chain comment="place hotspot rules here" disabled=yes add action=jump chain=trusted comment="Permit WAN" jump-target=wan add action=accept chain=trusted comment="Allow UNIFI for trusted devices" dst-address-list=unifi add action=accept chain=trusted comment="Allow Active Directory for trusted devices" dst-address-list=ad-servers add action=return chain=trusted add action=accept chain=input comment="Allow established connections to the firewall" connection-state=established add action=accept chain=input comment="Allow related connections to the firewall" connection-state=related add action=drop chain=input comment="Drop invalid connections to the firewall" connection-state=invalid add action=accept chain=input comment="Allow ICMP to the firewall" protocol=icmp add action=accept chain=input comment="Allow SSH/Winbox/HTTPS to Firewall from management addresses" dst-port=8291,22,443 protocol=tcp src-address-list=management add action=accept chain=input comment="Allow SNMP from Monitoring IPs" dst-port=161 protocol=udp src-address-list=snmp-servers add action=accept chain=input comment="Allow SSH/Winbox/HTTPS from LAN interface" dst-port=8291,22,443 in-interface=ether2 protocol=tcp add action=drop chain=input comment="Default drop all traffic to the firewall" add action=jump chain=pos comment="Permit WAN" jump-target=wan add action=accept chain=pos comment="Permit AD Servers" dst-address-list=ad-servers add action=accept chain=pos comment="Permit POS Outbound IPs" dst-address-list=pos-outbound-permitted add action=return chain=pos add action=jump chain=forward comment="Jump staff interface to WAN chain to allow WAN only access" in-interface=ether2-staff jump-target=wan add action=accept chain=forward comment="Allow established connections through the firewall" connection-state=established add action=accept chain=forward comment="Allow related connections through the firewall" connection-state=related add action=drop chain=forward comment="Drop invalid connections through the firewall" connection-state=invalid add action=accept chain=forward comment="Allow traffic to pass through if this is a router to connect two venues to WAN" in-interface-list=neighbours out-interface-list=neighbours add action=accept chain=forward comment="Allow traffic the LAN interfaces from the trusted IP ranges" out-interface-list=lans src-address-list=trusted-inbound add action=jump chain=forward comment="Jump public interface to WAN chain to allow WAN only access" in-interface=ether2-public jump-target=wan add action=jump chain=forward comment="Jump pos interface to POS chain to allow WAN and POS access" in-interface=ether2-pos jump-target=pos add action=jump chain=forward comment="Jump jsm interface to TRUSTED chain to allow WAN and TRUSTED access" in-interface=ether2-jsm jump-target=trusted add action=jump chain=forward comment="Jump lan interface to TRUSTED chain to allow WAN and TRUSTED access" in-interface=ether2 jump-target=trusted add action=drop chain=forward comment="Default drop any other traffic through firewall" add action=accept chain=wan comment="Allow access to the internet but deny 10.0.0.0/8 via wan interface" dst-address=!10.0.0.0/8 out-interface-list=wans add action=return chain=wan /ip firewall nat add action=passthrough chain=unused-hs-chain comment="place hotspot rules here" disabled=yes /ip hotspot walled-garden add comment="place hotspot rules here" disabled=yes /ip hotspot walled-garden ip add action=accept disabled=no dst-address=185.109.40.9 add action=accept disabled=no dst-address=185.109.40.8 /ip ipsec profile set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5 /ip route add check-gateway=ping distance=10 dst-address=0.0.0.0/0 gateway=10.254.5.45 routing-table=main scope=30 target-scope=10 add check-gateway=ping distance=1 dst-address=0.0.0.0/0 gateway=10.254.30.5 routing-table=main scope=30 target-scope=10 /ip service set ftp disabled=yes set telnet disabled=yes set www disabled=yes set www-ssl certificate=router disabled=no set api disabled=yes /radius add address=10.1.88.11 service=hotspot timeout=30s /snmp set contact="Pub Invest Group" enabled=yes location="Seel Street, L1 4BH, Liverpool" /system clock set time-zone-name=Europe/London /system identity set name=RTR-DOS-001 /system ntp client set enabled=yes /system ntp client servers add address=time.cloudflare.com /system routerboard settings set enter-setup-on=delete-key [admin@RTR-DOS-001] >