#配置DNS /ip dns set servers=8.8.8.8 / #激活ROS /system license renew account=u818134@gmail.com password=KypwFypvVC level=p-unlimited / #######分割线######################################################################## / /interface bridge add name=bridge1 protocol-mode=none /interface bridge add name=bridge2 protocol-mode=none /interface bridge add name=bridge3 protocol-mode=none /ip address add address=10.252.0.254/16 interface=bridge1 /ip address add address=172.21.1.254/24 interface=bridge2 /ip address add address=172.21.2.254/24 interface=bridge3 /interface veth add address=10.252.0.253/16 comment=10.252.0.253/16 gateway=10.252.0.254 gateway6="" name=veth1 add address=172.21.1.253/24 comment=172.21.1.253/24 gateway=172.21.1.254 gateway6="" name=veth2 add address=172.21.2.253/24 comment=172.21.2.253/24 gateway=172.21.2.254 gateway6="" name=veth3 / /container add comment=10.252.0.253/16 dns=8.8.8.8 hostname=S5-1 interface=veth1 root-dir=docker/1 start-on-boot=yes file=alpine.tar /container add comment=172.21.1.253/24 dns=8.8.8.8 hostname=whats-1 interface=veth2 root-dir=docker/2 start-on-boot=yes file=whats.tar /container add comment=172.21.2.253/24 dns=8.8.8.8 hostname=ss-1 interface=veth3 root-dir=docker/3 start-on-boot=yes file=ss.tar / /interface bridge port add bridge=bridge1 interface=veth1 /interface bridge port add bridge=bridge2 interface=veth2 /interface bridge port add bridge=bridge3 interface=veth3 /interface l2tp-server server set enabled=yes /ppp profile add change-tcp-mss=yes dns-server=8.8.8.8 local-address=192.168.0.254 name=VPN remote-address=192.168.0.253 /ppp secret add name=VPN1 password=qwe@123456 profile=VPN /ip firewall mangle add action=change-mss chain=forward new-mss=1200 passthrough=yes protocol=tcp tcp-flags=syn tcp-mss=1201-65535 add action=accept chain=prerouting dst-address=172.21.1.254 add action=accept chain=prerouting dst-address=172.21.2.254 add action=accept chain=prerouting dst-address=10.252.0.254 / /system ntp client set enabled=yes /system ntp client servers add address=time1.aliyun.com add address=cn.pool.ntp.org /system clock manual set time-zone=+08:00 / ####################分割线############################### /ip firewall nat add action=masquerade chain=srcnat /ip firewall nat add action=dst-nat chain=dstnat dst-port=10501 in-interface=ether1 protocol=tcp to-addresses=172.21.1.253 to-ports=34567 /ip firewall nat add action=dst-nat chain=dstnat dst-port=20501 in-interface=ether1 protocol=tcp to-addresses=172.21.1.253 to-ports=45678 /ip firewall nat add action=dst-nat chain=dstnat dst-port=31080 in-interface=ether1 protocol=tcp to-addresses=10.252.0.253 to-ports=1080 /ip firewall nat add action=dst-nat chain=dstnat dst-port=40808 in-interface=ether1 protocol=tcp to-addresses=10.252.0.253 to-ports=808 /ip firewall nat add action=dst-nat chain=dstnat dst-port=54321 in-interface=ether1 protocol=tcp to-addresses=172.21.2.253 to-ports=54321 /ip firewall nat add action=dst-nat chain=dstnat dst-port=54321 in-interface=ether1 protocol=udp to-addresses=172.21.2.253 to-ports=54321 /ip firewall nat add action=dst-nat chain=dstnat dst-port=!1701,500,4500,53,161,2000 in-interface=ether1 protocol=udp to-addresses=10.252.0.253 #安全策略 /ip firewall filter add action=accept chain=input dst-port=6500 in-interface=ether1 protocol=tcp add action=accept chain=input dst-port=161 in-interface=ether1 protocol=udp add action=drop chain=input in-interface=ether1 src-address-list=DDOS add action=add-src-to-address-list address-list=DDOS address-list-timeout=12h chain=input in-interface=ether1 protocol=tcp psd=21,3s,3,1 add action=add-src-to-address-list address-list=DDOS address-list-timeout=12h chain=input dst-port=3389,8291,21,22 in-interface=ether1 protocol=tcp / ##启动容器 /container start [find comment=10.252.0.253/16] /container start [find comment=172.21.1.253/24] /container start [find comment=172.21.2.253/24]