Раздача интернета от PTP линка
Добавлено: 02 янв 2019, 19:17
toto
Привет и с Новым Годом!
Помогите, пожалуйста, настроить роутер Б для такой конфигурации:

Сейчас, вместо роутера Б - подключен ПК - все работает, айпи по DHCP выдается (от роутера А), интернет есть, WinBox видит Роутер А и оба sxt.
При подключении роутера Б (через wan-порт) и включении галки DHCP client на этом интерфейсе - ай-пи не выдается.
Хочется сделать 2 подсети: 77.0/24 и 78.0/24, чтобы осталась локальная сеть для клиентов роутера Б (если PTP отвалится).
конфиги:
Помогите, пожалуйста, настроить роутер Б для такой конфигурации:

Сейчас, вместо роутера Б - подключен ПК - все работает, айпи по DHCP выдается (от роутера А), интернет есть, WinBox видит Роутер А и оба sxt.
При подключении роутера Б (через wan-порт) и включении галки DHCP client на этом интерфейсе - ай-пи не выдается.
Хочется сделать 2 подсети: 77.0/24 и 78.0/24, чтобы осталась локальная сеть для клиентов роутера Б (если PTP отвалится).
конфиги:
# jan/02/2019 18:27:48 by RouterOS 6.43.7
# software id = V1Z8-WB8U
#
# model = RBD52G-5HacD2HnD
# serial number = XXXXXXXXXXXX
/interface bridge
add arp=proxy-arp mtu=1500 name=lan-bridge
/interface ethernet
set [ find default-name=ether2 ] name=lan1
set [ find default-name=ether3 ] name=lan2
set [ find default-name=ether4 ] name=lan3
set [ find default-name=ether5 ] name=lan4
set [ find default-name=ether1 ] name=wan
/interface wireless
set [ find default-name=wlan1 ] adaptive-noise-immunity=ap-and-client-mode \
band=2ghz-onlyn channel-width=20/40mhz-XX disconnect-timeout=15s distance=\
indoors frequency=auto frequency-mode=superchannel hw-protection-mode=\
rts-cts hw-retries=10 mode=ap-bridge multicast-helper=full \
on-fail-retry-time=1s ssid=mv_wifi2.4 wireless-protocol=802.11 wmm-support=\
enabled wps-mode=disabled
set [ find default-name=wlan2 ] adaptive-noise-immunity=ap-and-client-mode \
band=5ghz-n/ac channel-width=20/40/80mhz-XXXX disconnect-timeout=15s \
distance=indoors frequency=auto frequency-mode=superchannel \
hw-protection-mode=rts-cts hw-retries=10 mode=ap-bridge multicast-helper=\
full on-fail-retry-time=1s ssid=mv_wifi5.0 wireless-protocol=802.11 \
wmm-support=enabled wps-mode=disabled
/interface wireless nstreme
set wlan1 enable-polling=no
set wlan2 enable-polling=no
/interface list
add name=Internet
add name=Local
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa2-psk disable-pmkid=yes \
eap-methods="" mode=dynamic-keys supplicant-identity=MikroTik \
wpa2-pre-shared-key=XXXXXXXXXXXXXXX
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/ip pool
add name=lan-pool ranges=192.168.77.5-192.168.77.30
/ip dhcp-server
add add-arp=yes address-pool=lan-pool bootp-lease-time=lease-time \
bootp-support=dynamic disabled=no interface=lan-bridge lease-time=12h name=\
server1
/interface bridge port
add bridge=lan-bridge interface=lan1
add bridge=lan-bridge interface=lan2
add bridge=lan-bridge interface=lan3
add bridge=lan-bridge interface=lan4
add bridge=lan-bridge interface=wlan1
add bridge=lan-bridge interface=wlan2
/ip neighbor discovery-settings
set discover-interface-list=Local
/interface list member
add interface=wan list=Internet
add interface=lan-bridge list=Local
add interface=lan1 list=Local
add interface=lan2 list=Local
add interface=lan3 list=Local
add interface=lan4 list=Local
add interface=wlan1 list=Local
add interface=wlan2 list=Local
/ip address
add address=192.168.77.1/24 interface=lan-bridge network=192.168.77.0
/ip dhcp-client
add dhcp-options=hostname,clientid disabled=no interface=wan
/ip dhcp-server network
add address=192.168.77.0/24 dns-server=192.168.77.1 gateway=192.168.77.1 \
netmask=24
/ip dns
set allow-remote-requests=yes
/ip firewall filter
add action=accept chain=forward comment=\
"1.1. Forward and Input Established and Related connections" \
connection-state=established,related
add action=drop chain=forward connection-state=invalid
add action=accept chain=input connection-state=established,related
add action=drop chain=input connection-state=invalid
add action=add-src-to-address-list address-list=ddos-blacklist \
address-list-timeout=1d chain=input comment=\
"1.2. DDoS Protect - Connection Limit" connection-limit=100,32 \
in-interface-list=Internet protocol=tcp
add action=tarpit chain=input connection-limit=3,32 protocol=tcp \
src-address-list=ddos-blacklist
add action=jump chain=forward comment="1.3. DDoS Protect - SYN Flood" \
connection-state=new jump-target=SYN-Protect protocol=tcp tcp-flags=syn
add action=jump chain=input connection-state=new in-interface-list=Internet \
jump-target=SYN-Protect protocol=tcp tcp-flags=syn
add action=return chain=SYN-Protect connection-state=new limit=200,5:packet \
protocol=tcp tcp-flags=syn
add action=drop chain=SYN-Protect connection-state=new protocol=tcp tcp-flags=\
syn
add action=drop chain=input comment="1.4. Protected - Ports Scanners" \
src-address-list="Port Scanners"
add action=add-src-to-address-list address-list="Port Scanners" \
address-list-timeout=none-dynamic chain=input in-interface-list=Internet \
protocol=tcp psd=21,3s,3,1
add action=drop chain=input comment="1.5. Protected - WinBox Access" \
src-address-list="Black List Winbox"
add action=add-src-to-address-list address-list="Black List Winbox" \
address-list-timeout=none-dynamic chain=input connection-state=new \
dst-port=8291 in-interface-list=Internet log=yes log-prefix="BLACK WINBOX" \
protocol=tcp src-address-list="Winbox Stage 3"
add action=add-src-to-address-list address-list="Winbox Stage 3" \
address-list-timeout=1m chain=input connection-state=new dst-port=8291 \
in-interface-list=Internet protocol=tcp src-address-list="Winbox Stage 2"
add action=add-src-to-address-list address-list="Winbox Stage 2" \
address-list-timeout=1m chain=input connection-state=new dst-port=8291 \
in-interface-list=Internet protocol=tcp src-address-list="Winbox Stage 1"
add action=add-src-to-address-list address-list="Winbox Stage 1" \
address-list-timeout=1m chain=input connection-state=new dst-port=8291 \
in-interface-list=Internet protocol=tcp
add action=accept chain=input dst-port=8291 in-interface-list=Internet \
protocol=tcp
add action=drop chain=input comment="1.6. Protected - OpenVPN Connections" \
src-address-list="Black List OpenVPN"
add action=add-src-to-address-list address-list="Black List OpenVPN" \
address-list-timeout=none-dynamic chain=input connection-state=new \
dst-port=1194 in-interface-list=Internet log=yes log-prefix="BLACK OVPN" \
protocol=tcp src-address-list="OpenVPN Stage 3"
add action=add-src-to-address-list address-list="OpenVPN Stage 3" \
address-list-timeout=1m chain=input connection-state=new dst-port=1194 \
in-interface-list=Internet protocol=tcp src-address-list="OpenVPN Stage 2"
add action=add-src-to-address-list address-list="OpenVPN Stage 2" \
address-list-timeout=1m chain=input connection-state=new dst-port=1194 \
in-interface-list=Internet protocol=tcp src-address-list="OpenVPN Stage 1"
add action=add-src-to-address-list address-list="OpenVPN Stage 1" \
address-list-timeout=1m chain=input connection-state=new dst-port=1194 \
in-interface-list=Internet protocol=tcp
add action=accept chain=input dst-port=1194 in-interface-list=Internet \
protocol=tcp
add action=accept chain=input comment="1.8. Access Normal Ping" \
in-interface-list=Internet limit=50/5s,2:packet protocol=icmp
add action=drop chain=input comment="1.9. Drop All Other" in-interface-list=\
Internet
/ip firewall nat
add action=masquerade chain=srcnat out-interface-list=Internet src-address=\
192.168.77.0/24
/tool mac-server
set allowed-interface-list=Local
/tool mac-server mac-winbox
set allowed-interface-list=Local
# software id = V1Z8-WB8U
#
# model = RBD52G-5HacD2HnD
# serial number = XXXXXXXXXXXX
/interface bridge
add arp=proxy-arp mtu=1500 name=lan-bridge
/interface ethernet
set [ find default-name=ether2 ] name=lan1
set [ find default-name=ether3 ] name=lan2
set [ find default-name=ether4 ] name=lan3
set [ find default-name=ether5 ] name=lan4
set [ find default-name=ether1 ] name=wan
/interface wireless
set [ find default-name=wlan1 ] adaptive-noise-immunity=ap-and-client-mode \
band=2ghz-onlyn channel-width=20/40mhz-XX disconnect-timeout=15s distance=\
indoors frequency=auto frequency-mode=superchannel hw-protection-mode=\
rts-cts hw-retries=10 mode=ap-bridge multicast-helper=full \
on-fail-retry-time=1s ssid=mv_wifi2.4 wireless-protocol=802.11 wmm-support=\
enabled wps-mode=disabled
set [ find default-name=wlan2 ] adaptive-noise-immunity=ap-and-client-mode \
band=5ghz-n/ac channel-width=20/40/80mhz-XXXX disconnect-timeout=15s \
distance=indoors frequency=auto frequency-mode=superchannel \
hw-protection-mode=rts-cts hw-retries=10 mode=ap-bridge multicast-helper=\
full on-fail-retry-time=1s ssid=mv_wifi5.0 wireless-protocol=802.11 \
wmm-support=enabled wps-mode=disabled
/interface wireless nstreme
set wlan1 enable-polling=no
set wlan2 enable-polling=no
/interface list
add name=Internet
add name=Local
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa2-psk disable-pmkid=yes \
eap-methods="" mode=dynamic-keys supplicant-identity=MikroTik \
wpa2-pre-shared-key=XXXXXXXXXXXXXXX
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/ip pool
add name=lan-pool ranges=192.168.77.5-192.168.77.30
/ip dhcp-server
add add-arp=yes address-pool=lan-pool bootp-lease-time=lease-time \
bootp-support=dynamic disabled=no interface=lan-bridge lease-time=12h name=\
server1
/interface bridge port
add bridge=lan-bridge interface=lan1
add bridge=lan-bridge interface=lan2
add bridge=lan-bridge interface=lan3
add bridge=lan-bridge interface=lan4
add bridge=lan-bridge interface=wlan1
add bridge=lan-bridge interface=wlan2
/ip neighbor discovery-settings
set discover-interface-list=Local
/interface list member
add interface=wan list=Internet
add interface=lan-bridge list=Local
add interface=lan1 list=Local
add interface=lan2 list=Local
add interface=lan3 list=Local
add interface=lan4 list=Local
add interface=wlan1 list=Local
add interface=wlan2 list=Local
/ip address
add address=192.168.77.1/24 interface=lan-bridge network=192.168.77.0
/ip dhcp-client
add dhcp-options=hostname,clientid disabled=no interface=wan
/ip dhcp-server network
add address=192.168.77.0/24 dns-server=192.168.77.1 gateway=192.168.77.1 \
netmask=24
/ip dns
set allow-remote-requests=yes
/ip firewall filter
add action=accept chain=forward comment=\
"1.1. Forward and Input Established and Related connections" \
connection-state=established,related
add action=drop chain=forward connection-state=invalid
add action=accept chain=input connection-state=established,related
add action=drop chain=input connection-state=invalid
add action=add-src-to-address-list address-list=ddos-blacklist \
address-list-timeout=1d chain=input comment=\
"1.2. DDoS Protect - Connection Limit" connection-limit=100,32 \
in-interface-list=Internet protocol=tcp
add action=tarpit chain=input connection-limit=3,32 protocol=tcp \
src-address-list=ddos-blacklist
add action=jump chain=forward comment="1.3. DDoS Protect - SYN Flood" \
connection-state=new jump-target=SYN-Protect protocol=tcp tcp-flags=syn
add action=jump chain=input connection-state=new in-interface-list=Internet \
jump-target=SYN-Protect protocol=tcp tcp-flags=syn
add action=return chain=SYN-Protect connection-state=new limit=200,5:packet \
protocol=tcp tcp-flags=syn
add action=drop chain=SYN-Protect connection-state=new protocol=tcp tcp-flags=\
syn
add action=drop chain=input comment="1.4. Protected - Ports Scanners" \
src-address-list="Port Scanners"
add action=add-src-to-address-list address-list="Port Scanners" \
address-list-timeout=none-dynamic chain=input in-interface-list=Internet \
protocol=tcp psd=21,3s,3,1
add action=drop chain=input comment="1.5. Protected - WinBox Access" \
src-address-list="Black List Winbox"
add action=add-src-to-address-list address-list="Black List Winbox" \
address-list-timeout=none-dynamic chain=input connection-state=new \
dst-port=8291 in-interface-list=Internet log=yes log-prefix="BLACK WINBOX" \
protocol=tcp src-address-list="Winbox Stage 3"
add action=add-src-to-address-list address-list="Winbox Stage 3" \
address-list-timeout=1m chain=input connection-state=new dst-port=8291 \
in-interface-list=Internet protocol=tcp src-address-list="Winbox Stage 2"
add action=add-src-to-address-list address-list="Winbox Stage 2" \
address-list-timeout=1m chain=input connection-state=new dst-port=8291 \
in-interface-list=Internet protocol=tcp src-address-list="Winbox Stage 1"
add action=add-src-to-address-list address-list="Winbox Stage 1" \
address-list-timeout=1m chain=input connection-state=new dst-port=8291 \
in-interface-list=Internet protocol=tcp
add action=accept chain=input dst-port=8291 in-interface-list=Internet \
protocol=tcp
add action=drop chain=input comment="1.6. Protected - OpenVPN Connections" \
src-address-list="Black List OpenVPN"
add action=add-src-to-address-list address-list="Black List OpenVPN" \
address-list-timeout=none-dynamic chain=input connection-state=new \
dst-port=1194 in-interface-list=Internet log=yes log-prefix="BLACK OVPN" \
protocol=tcp src-address-list="OpenVPN Stage 3"
add action=add-src-to-address-list address-list="OpenVPN Stage 3" \
address-list-timeout=1m chain=input connection-state=new dst-port=1194 \
in-interface-list=Internet protocol=tcp src-address-list="OpenVPN Stage 2"
add action=add-src-to-address-list address-list="OpenVPN Stage 2" \
address-list-timeout=1m chain=input connection-state=new dst-port=1194 \
in-interface-list=Internet protocol=tcp src-address-list="OpenVPN Stage 1"
add action=add-src-to-address-list address-list="OpenVPN Stage 1" \
address-list-timeout=1m chain=input connection-state=new dst-port=1194 \
in-interface-list=Internet protocol=tcp
add action=accept chain=input dst-port=1194 in-interface-list=Internet \
protocol=tcp
add action=accept chain=input comment="1.8. Access Normal Ping" \
in-interface-list=Internet limit=50/5s,2:packet protocol=icmp
add action=drop chain=input comment="1.9. Drop All Other" in-interface-list=\
Internet
/ip firewall nat
add action=masquerade chain=srcnat out-interface-list=Internet src-address=\
192.168.77.0/24
/tool mac-server
set allowed-interface-list=Local
/tool mac-server mac-winbox
set allowed-interface-list=Local
# dec/28/2018 22:35:20 by RouterOS 6.43.7
# software id = E5FE-2S0M
#
# model = RouterBOARD SXTsq G-5acD
# serial number = XXXXXXXXXXXXXX
/interface bridge
add name=bridge1
/interface ethernet
set [ find default-name=ether1 ] speed=100Mbps
/interface wireless
set [ find default-name=wlan1 ] band=5ghz-n/ac channel-width=20/40/80mhz-eeCe disabled=no frequency=5330 frequency-mode=superchannel mode=station-wds nv2-preshared-key=XXXXXXXXXXXX nv2-security=enabled scan-list=5150-5350 ssid=XXXXX \
wds-default-bridge=bridge1 wds-mode=dynamic
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk eap-methods="" mode=dynamic-keys supplicant-identity=MikroTik wpa-pre-shared-key=XXXXXXXXX wpa2-pre-shared-key=XXXXXXXXXXXXXX
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/queue type
set 1 pfifo-limit=500
set 2 kind=pfifo pfifo-limit=500
/interface bridge port
add bridge=bridge1 interface=ether1
add bridge=bridge1 interface=wlan1
/ip address
add address=192.168.77.102/24 interface=bridge1 network=192.168.77.0
# software id = E5FE-2S0M
#
# model = RouterBOARD SXTsq G-5acD
# serial number = XXXXXXXXXXXXXX
/interface bridge
add name=bridge1
/interface ethernet
set [ find default-name=ether1 ] speed=100Mbps
/interface wireless
set [ find default-name=wlan1 ] band=5ghz-n/ac channel-width=20/40/80mhz-eeCe disabled=no frequency=5330 frequency-mode=superchannel mode=station-wds nv2-preshared-key=XXXXXXXXXXXX nv2-security=enabled scan-list=5150-5350 ssid=XXXXX \
wds-default-bridge=bridge1 wds-mode=dynamic
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk eap-methods="" mode=dynamic-keys supplicant-identity=MikroTik wpa-pre-shared-key=XXXXXXXXX wpa2-pre-shared-key=XXXXXXXXXXXXXX
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/queue type
set 1 pfifo-limit=500
set 2 kind=pfifo pfifo-limit=500
/interface bridge port
add bridge=bridge1 interface=ether1
add bridge=bridge1 interface=wlan1
/ip address
add address=192.168.77.102/24 interface=bridge1 network=192.168.77.0
# dec/30/2018 01:08:58 by RouterOS 6.43.7
# software id = 8JW8-M77S
#
# model = RouterBOARD SXTsq G-5acD
# serial number = XXXXXXXXXXXX
/interface bridge
add name=bridge1
/interface wireless
set [ find default-name=wlan1 ] band=5ghz-onlyac channel-width=20/40/80mhz-eeCe disabled=no frequency=5330 frequency-mode=superchannel mode=bridge nv2-preshared-key=XXXXXXXXXX nv2-security=enabled scan-list=5150-5350 ssid=XXXXX wds-default-bridge=\
bridge1 wds-mode=dynamic wireless-protocol=802.11 wps-mode=disabled
/interface wireless nstreme
set wlan1 enable-polling=no
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk eap-methods="" mode=dynamic-keys supplicant-identity=MikroTik wpa-pre-shared-key=XXXXXXXXXX wpa2-pre-shared-key=XXXXXXXXXX
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/queue type
set 1 pfifo-limit=500
set 2 kind=pfifo pfifo-limit=500
/interface bridge port
add bridge=bridge1 interface=wlan1
add bridge=bridge1 interface=ether1
/ip address
add address=192.168.77.101/24 interface=bridge1 network=192.168.77.0
# software id = 8JW8-M77S
#
# model = RouterBOARD SXTsq G-5acD
# serial number = XXXXXXXXXXXX
/interface bridge
add name=bridge1
/interface wireless
set [ find default-name=wlan1 ] band=5ghz-onlyac channel-width=20/40/80mhz-eeCe disabled=no frequency=5330 frequency-mode=superchannel mode=bridge nv2-preshared-key=XXXXXXXXXX nv2-security=enabled scan-list=5150-5350 ssid=XXXXX wds-default-bridge=\
bridge1 wds-mode=dynamic wireless-protocol=802.11 wps-mode=disabled
/interface wireless nstreme
set wlan1 enable-polling=no
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk eap-methods="" mode=dynamic-keys supplicant-identity=MikroTik wpa-pre-shared-key=XXXXXXXXXX wpa2-pre-shared-key=XXXXXXXXXX
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/queue type
set 1 pfifo-limit=500
set 2 kind=pfifo pfifo-limit=500
/interface bridge port
add bridge=bridge1 interface=wlan1
add bridge=bridge1 interface=ether1
/ip address
add address=192.168.77.101/24 interface=bridge1 network=192.168.77.0
# jan/02/1970 01:11:23 by RouterOS 6.43.8
# software id = Y167-AVTJ
#
# model = RBD52G-5HacD2HnD
# serial number = xxxxxxxxxxxx
/interface bridge
add arp=proxy-arp mtu=1500 name=bridge1
/interface ethernet
set [ find default-name=ether2 ] name=lan1
set [ find default-name=ether3 ] name=lan2
set [ find default-name=ether4 ] name=lan3
set [ find default-name=ether5 ] name=lan4
set [ find default-name=ether1 ] name=wan
/interface wireless
set [ find default-name=wlan1 ] ssid=MikroTik
set [ find default-name=wlan2 ] ssid=MikroTik
/interface list
add name=Local
add name=Internet
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/ip pool
add name=pool1 ranges=192.168.78.2-192.168.78.30
/ip dhcp-server
add address-pool=pool1 bootp-lease-time=lease-time bootp-support=dynamic disabled=no interface=bridge1 lease-time=12h name=server1
/interface bridge port
add bridge=bridge1 interface=lan1
add bridge=bridge1 interface=lan2
add bridge=bridge1 interface=lan3
add bridge=bridge1 interface=lan4
add bridge=bridge1 interface=wlan1
add bridge=bridge1 interface=wlan2
/ip neighbor discovery-settings
set discover-interface-list=Local
/interface list member
add interface=bridge1 list=Local
add interface=lan1 list=Local
add interface=lan2 list=Local
add interface=lan3 list=Local
add interface=lan4 list=Local
add interface=wlan1 list=Local
add interface=wlan2 list=Local
add interface=wan list=Internet
/ip address
add address=192.168.78.1/24 interface=bridge1 network=192.168.78.0
/ip dhcp-client
add dhcp-options=hostname,clientid disabled=no interface=wan
/ip dhcp-server network
add address=192.168.78.0/24 dns-server=192.168.78.1 gateway=192.168.78.1 netmask=24
/ip dns
set allow-remote-requests=yes
/ip firewall nat
add action=masquerade chain=srcnat out-interface-list=Internet src-address=192.168.78.0/24
/tool mac-server
set allowed-interface-list=Local
/tool mac-server mac-winbox
set allowed-interface-list=Local
# software id = Y167-AVTJ
#
# model = RBD52G-5HacD2HnD
# serial number = xxxxxxxxxxxx
/interface bridge
add arp=proxy-arp mtu=1500 name=bridge1
/interface ethernet
set [ find default-name=ether2 ] name=lan1
set [ find default-name=ether3 ] name=lan2
set [ find default-name=ether4 ] name=lan3
set [ find default-name=ether5 ] name=lan4
set [ find default-name=ether1 ] name=wan
/interface wireless
set [ find default-name=wlan1 ] ssid=MikroTik
set [ find default-name=wlan2 ] ssid=MikroTik
/interface list
add name=Local
add name=Internet
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/ip pool
add name=pool1 ranges=192.168.78.2-192.168.78.30
/ip dhcp-server
add address-pool=pool1 bootp-lease-time=lease-time bootp-support=dynamic disabled=no interface=bridge1 lease-time=12h name=server1
/interface bridge port
add bridge=bridge1 interface=lan1
add bridge=bridge1 interface=lan2
add bridge=bridge1 interface=lan3
add bridge=bridge1 interface=lan4
add bridge=bridge1 interface=wlan1
add bridge=bridge1 interface=wlan2
/ip neighbor discovery-settings
set discover-interface-list=Local
/interface list member
add interface=bridge1 list=Local
add interface=lan1 list=Local
add interface=lan2 list=Local
add interface=lan3 list=Local
add interface=lan4 list=Local
add interface=wlan1 list=Local
add interface=wlan2 list=Local
add interface=wan list=Internet
/ip address
add address=192.168.78.1/24 interface=bridge1 network=192.168.78.0
/ip dhcp-client
add dhcp-options=hostname,clientid disabled=no interface=wan
/ip dhcp-server network
add address=192.168.78.0/24 dns-server=192.168.78.1 gateway=192.168.78.1 netmask=24
/ip dns
set allow-remote-requests=yes
/ip firewall nat
add action=masquerade chain=srcnat out-interface-list=Internet src-address=192.168.78.0/24
/tool mac-server
set allowed-interface-list=Local
/tool mac-server mac-winbox
set allowed-interface-list=Local