Startup Config
Startup Config
system
set net.ipv4.ip_forward 1
set net.ipv4.tcp_fin_timeout 30
set net.ipv4.tcp_keepalive_time 120
set net.ipv4.netfilter.ip_conntrack_tcp_timeout_established 1200
set net.ipv4.netfilter.ip_conntrack_max 4096
set vm.swappiness 100
no button WLAN on double-click
no button WLAN on hold
no button FN on click
clock timezone Europe/Moscow
clock date 27 Mar 2017 20:29:49
domainname WORKGROUP
hostname Keenetic_Extra
!
ntp server 0.pool.ntp.org
ntp server 1.pool.ntp.org
ntp server 2.pool.ntp.org
ntp server 3.pool.ntp.org
known host C610A-IP 7c:2f:80:5f:8c:7c
known host PC_Ethernet f4:6d:04:6e:40:86
known host PC_WiFi-usb c0:4a:00:22:e5:7e
known host MediaPad_X1_7 60:e7:01:2b:9c:3e
known host android-169dc36f76cce632 00:66:4b:4e:09:7c
known host iPad-user 04:54:53:f3:47:7b
known host Keenetic_Lite 1c:74:0d:8f:8c:8c
known host ZZ-Book 60:f6:77:91:b5:0e
access-list _WEBADMIN_ISP
permit udp 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 port eq 5060
permit tcp 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 port eq 5060
!
isolate-private
user admin
password md5 597e3b4713b6b3f36b64a00c4b43fccf
password nt c62638b38308e651b21a0f2ccab3ac9b
tag cli
tag http
tag printers
tag cifs
!
interface GigabitEthernet0
up
!
interface GigabitEthernet0/0
rename 0
switchport mode access
switchport access vlan 2
up
!
interface GigabitEthernet0/1
rename 1
switchport mode access
switchport access vlan 1
up
!
interface GigabitEthernet0/2
rename 2
switchport mode access
switchport access vlan 1
up
!
interface GigabitEthernet0/3
rename 3
switchport mode access
switchport access vlan 1
up
!
interface GigabitEthernet0/4
rename 4
switchport mode access
switchport access vlan 1
up
!
interface GigabitEthernet0/Vlan1
description "Home VLAN"
security-level private
ip dhcp client dns-routes
ip dhcp client name-servers
up
!
interface GigabitEthernet0/Vlan2
rename ISP
description "Broadband connection"
mac address factory wan
security-level public
ip address 188.143.132.146 255.255.255.0
ip dhcp client dns-routes
ip dhcp client name-servers
ip mtu 1500
ip access-group _WEBADMIN_ISP in
ip global 700
igmp upstream
up
!
interface WifiMaster0
country-code RU
compatibility BGN
channel width 40-below
channel auto-rescan 03:00 interval 6
power 100
up
!
interface WifiMaster0/AccessPoint0
rename AccessPoint
description "Wi-Fi access point"
mac access-list type none
security-level private
authentication wpa-psk ns3 iaq4bOsu5q3e91/epTze0H6q
encryption enable
encryption wpa2
ip dhcp client dns-routes
ip dhcp client name-servers
ssid zxz_new
wmm
up
!
interface WifiMaster0/AccessPoint1
rename GuestWiFi
description "Guest access point"
mac access-list type none
security-level private
authentication wpa-psk ns3 6gEHGQ0yKnDovxO9m94GrtN3
encryption enable
encryption wpa2
ip address 10.1.30.1 255.255.255.0
ip dhcp client dns-routes
ip dhcp client name-servers
ssid Guest
wmm
down
!
interface WifiMaster0/AccessPoint2
mac access-list type none
security-level private
ip dhcp client dns-routes
ip dhcp client name-servers
down
!
interface WifiMaster0/AccessPoint3
mac access-list type none
security-level private
ip dhcp client dns-routes
ip dhcp client name-servers
down
!
interface WifiMaster0/WifiStation0
security-level public
encryption disable
ip address dhcp
ip dhcp client dns-routes
ip dhcp client name-servers
down
!
interface WifiMaster1
country-code RU
compatibility AN
channel width 40-below
power 100
up
!
interface WifiMaster1/AccessPoint0
rename AccessPoint_5G
description "5Ghz Wi-Fi access point"
mac access-list type none
security-level private
authentication wpa-psk ns3 iaq4bOsu5q3e91/epTze0H6q
encryption enable
encryption wpa2
ip dhcp client dns-routes
ip dhcp client name-servers
ssid zxz_5G
wmm
down
!
interface WifiMaster1/WifiStation0
security-level public
encryption disable
ip address dhcp
ip dhcp client dns-routes
ip dhcp client name-servers
down
!
interface Bridge0
rename Home
description "Home network"
inherit GigabitEthernet0/Vlan1
include AccessPoint
include AccessPoint_5G
security-level private
ip address 192.168.1.1 255.255.255.0
ip dhcp client dns-routes
ip dhcp client name-servers
igmp downstream
up
!
ip route default 188.143.132.1 ISP
ip dhcp pool _WEBADMIN
range 192.168.1.33 192.168.1.52
default-router 192.168.1.1
dns-server 192.168.1.1
lease 86400
bind Home
enable
!
ip dhcp pool _WEBADMIN_GUEST_AP
range 10.1.30.33 10.1.30.52
bind GuestWiFi
enable
!
ip dhcp host 7c:2f:80:5f:8c:7c 192.168.1.38
ip dhcp host f4:6d:04:6e:40:86 192.168.1.37
ip dhcp host c0:4a:00:22:e5:7e 192.168.1.40
ip dhcp host 60:e7:01:2b:9c:3e 192.168.1.42
ip dhcp host 00:66:4b:4e:09:7c 192.168.1.43
ip dhcp host 04:54:53:f3:47:7b 192.168.1.33
ip dhcp host 1c:74:0d:8f:8c:8c 192.168.1.49
ip dhcp host 60:f6:77:91:b5:0e 192.168.1.44
ip name-server 188.143.128.53 "" on ISP
ip name-server 188.143.128.3 "" on ISP
ip http security-level private
ip http lockout-policy 5 15 3
ip nat Home
ip nat GuestWiFi
ip static udp ISP 5060 7c:2f:80:5f:8c:7c 5060
ip static tcp ISP 5060 192.168.1.38 5060 !TCP_5060
ip telnet
security-level private
lockout-policy 5 15 3
!
ip hotspot
policy Home permit
host 7c:2f:80:5f:8c:7c permit
host 1c:74:0d:8f:8c:8c permit
host 60:f6:77:91:b5:0e permit
!
ppe software
ppe hardware
upnp lan Home
service dhcp
service dns-proxy
service http
service telnet
service ntp-client
service upnp
!