Router 1

Código:
# model = RB760iGS# serial number = HD708DEHZY0/interface bridgeadd name=bridge1/interface pppoe-clientadd add-default-route=yes disabled=no interface=ether1 name=pppoe-out1 user=makrosuper@universal.com.br/interface listadd name=WANadd name=LAN/interface wireless security-profilesset [ find default=yes ] supplicant-identity=MikroTik/ip ipsec peeradd address=45.4.55.86/32 name="Makro CD"/ip ipsec profileset [ find default=yes ] dh-group=modp1024 enc-algorithm=3desadd dh-group=modp1024 enc-algorithm=3des name=Makro2add dh-group=modp1024 enc-algorithm=3des name=barra/ip ipsec peeradd address=45.4.55.88/32 name=Barra profile=barraadd name="Makro 2" passive=yes profile=Makro2/ip ipsec proposalset [ find default=yes ] enc-algorithms=aes-128-cbc pfs-group=noneadd enc-algorithms=aes-128-cbc name=Makro2 pfs-group=noneadd enc-algorithms=aes-128-cbc name=Barra pfs-group=none/ip pooladd name=dhcp_pool3 ranges=192.168.10.200-192.168.10.254add name=dhcp_pool7 ranges=192.168.2.200-192.168.2.254/ip dhcp-serveradd address-pool=dhcp_pool3 disabled=no interface=bridge1 lease-time=23h59m59s name=dhcp1add address-pool=dhcp_pool7 disabled=no interface=ether5 lease-time=23h59m59s name=dhcp2/queue simpleadd max-limit=100M/100M name=camaras target=192.168.2.0/24/interface bridge portadd bridge=bridge1 interface=ether2 trusted=yes/ip neighbor discovery-settingsset discover-interface-list=all/interface list memberadd interface=pppoe-out1 list=WANadd interface=bridge1 list=LAN/ip addressadd address=192.168.10.1/24 interface=bridge1 network=192.168.10.0add address=192.168.2.1/24 interface=ether5 network=192.168.2.0/ip dhcp-server networkadd address=192.168.2.0/24 gateway=192.168.2.1add address=192.168.10.0/24 gateway=192.168.10.1/ip dnsset servers=8.8.8.8,8.8.4.4/ip firewall natadd action=accept chain=srcnat dst-address=192.168.20.0/24 src-address=192.168.10.0/24add action=accept chain=srcnat dst-address=192.168.30.0/24 src-address=192.168.10.0/24add action=accept chain=srcnat dst-address=192.168.40.0/24 src-address=192.168.10.0/24add action=accept chain=srcnat dst-address=192.168.3.0/24 src-address=192.168.2.0/24add action=accept chain=srcnat dst-address=192.168.4.0/24 src-address=192.168.2.0/24add action=accept chain=srcnat dst-address=192.168.1.0/24 src-address=192.168.2.0/24add action=masquerade chain=srcnat src-address=192.168.10.0/24add action=masquerade chain=srcnat src-address=192.168.2.0/24add action=dst-nat chain=dstnat dst-address=45.4.55.87 dst-port=21000 protocol=tcp to-addresses=192.168.2.10 to-ports=21000add action=dst-nat chain=dstnat dst-address=45.4.55.87 dst-port=8007 protocol=tcp to-addresses=192.168.2.11 to-ports=8007add action=dst-nat chain=dstnat dst-address=45.4.55.87 dst-port=8003 protocol=tcp to-addresses=192.168.2.12 to-ports=8003add action=dst-nat chain=dstnat dst-address=45.4.55.87 dst-port=8001 protocol=tcp to-addresses=192.168.2.13 to-ports=8001add action=dst-nat chain=dstnat dst-address=45.4.55.87 dst-port=8008 protocol=tcp to-addresses=192.168.2.14 to-ports=8008add action=dst-nat chain=dstnat dst-address=45.4.55.87 dst-port=8000 protocol=tcp to-addresses=192.168.2.230 to-ports=8000/ip firewall rawadd action=accept chain=prerouting dst-address=192.168.20.0/24 src-address=192.168.10.0/24/ip ipsec identityadd peer="Makro CD"add peer="Makro 2"add peer=Barra/ip ipsec policyadd dst-address=192.168.30.0/24 peer="Makro CD" src-address=192.168.10.0/24 tunnel=yesadd dst-address=192.168.20.0/24 peer="Makro 2" proposal=Makro2 src-address=192.168.10.0/24 tunnel=yesadd dst-address=192.168.40.0/24 peer=Barra proposal=Barra src-address=192.168.10.0/24 tunnel=yesadd comment="camaras vigilancia" dst-address=192.168.4.0/24 peer=Barra proposal=Barra src-address=192.168.2.0/24 tunnel=yesadd comment="camaras vigilancia" dst-address=192.168.1.0/24 peer="Makro 2" proposal=Makro2 src-address=192.168.2.0/24 tunnel=yesadd comment="camaras vigilancia" dst-address=192.168.3.0/24 peer="Makro CD" src-address=192.168.2.0/24 tunnel=yes/ip serviceset telnet disabled=yesset ftp disabled=yesset ssh disabled=yesset api disabled=yesset api-ssl disabled=yes/system clockset time-zone-name=America/Sao_Paulo/system identityset name="RB Makro 1"

Router 2

Código:
# model = RB760iGS# serial number = HD70800NP0G/interface bridgeadd name=bridge1/interface pppoe-clientadd add-default-route=yes disabled=no interface=ether1 name=pppoe-out1 user=makrochui@universal.com.br/interface listadd name=WANadd name=LAN/interface wireless security-profilesset [ find default=yes ] supplicant-identity=MikroTik/ip ipsec profileset [ find default=yes ] dh-group=modp1024 enc-algorithm=3desadd dh-group=modp1024 enc-algorithm=3des name=Makro1add dh-group=modp1024 enc-algorithm=3des name=Barra/ip ipsec peeradd address=45.4.55.88/32 name=Barra profile=Barraadd address=45.4.55.87/32 name=makro1 profile=Makro1add address=45.4.55.86/32 name=CD profile=Makro1/ip ipsec proposalset [ find default=yes ] enc-algorithms=aes-128-cbc pfs-group=noneadd enc-algorithms=aes-128-cbc name=Makro1 pfs-group=noneadd enc-algorithms=aes-128-cbc name=barra pfs-group=none/ip pooladd name=dhcp ranges=192.168.20.200-192.168.20.254add name=dhcp_pool4 ranges=192.168.1.200-192.168.1.254/ip dhcp-serveradd address-pool=dhcp disabled=no interface=bridge1 lease-time=23h59m59s name=dhcp1add address-pool=dhcp_pool4 disabled=no interface=ether5 lease-time=23h59m59s name=dhcp2/queue simpleadd max-limit=100M/100M name=Camaras target=192.168.1.0/24/interface bridge portadd bridge=bridge1 interface=ether2 trusted=yes/ip neighbor discovery-settingsset discover-interface-list=all/interface l2tp-server serverset enabled=yes use-ipsec=yes/interface list memberadd interface=pppoe-out1 list=WANadd interface=bridge1 list=LAN/interface pptp-server serverset enabled=yes/interface sstp-server serverset default-profile=default-encryption enabled=yes/ip addressadd address=192.168.20.1/24 interface=bridge1 network=192.168.20.0add address=192.168.1.1/24 comment="camaras vigilancia" interface=ether5 network=192.168.1.0/ip arpadd address=192.168.20.2 interface=bridge1 mac-address=9C:5A:44:72:DA:A7/ip dhcp-server networkadd address=192.168.1.0/24 gateway=192.168.1.1add address=192.168.20.0/24 gateway=192.168.20.1/ip dnsset servers=8.8.8.8,8.8.4.4/ip firewall natadd action=accept chain=srcnat dst-address=192.168.30.0/24 src-address=192.168.20.0/24add action=accept chain=srcnat dst-address=192.168.40.0/24 src-address=192.168.20.0/24add action=accept chain=srcnat dst-address=192.168.10.0/24 src-address=192.168.20.0/24add action=accept chain=srcnat dst-address=192.168.4.0/24 src-address=192.168.1.0/24add action=accept chain=srcnat dst-address=192.168.2.0/24 src-address=192.168.1.0/24add action=accept chain=srcnat dst-address=192.168.3.0/24 src-address=192.168.1.0/24add action=masquerade chain=srcnat src-address=192.168.20.0/24add action=masquerade chain=srcnat src-address=192.168.1.0/24add action=dst-nat chain=dstnat comment="DVR caixas" dst-address=45.4.55.85 dst-port=28000 protocol=tcp to-addresses=192.168.1.116 to-ports=28000add action=dst-nat chain=dstnat comment="DVR deposito" dst-address=45.4.55.85 dst-port=25000 protocol=tcp to-addresses=192.168.1.239 to-ports=25000add action=dst-nat chain=dstnat comment="DVR estacionamiento" dst-address=45.4.55.85 dst-port=15000 protocol=tcp to-addresses=192.168.1.253 to-ports=15000add action=dst-nat chain=dstnat comment="DVR ferragem" dst-address=45.4.55.85 dst-port=35000 protocol=tcp to-addresses=192.168.1.20 to-ports=35000add action=dst-nat chain=dstnat comment="DVR gondola" dst-address=45.4.55.85 dst-port=11000 protocol=tcp to-addresses=192.168.1.29 to-ports=11000add action=dst-nat chain=dstnat comment="DVR padaria" dst-address=45.4.55.85 dst-port=29000 protocol=tcp to-addresses=192.168.1.13 to-ports=29000add action=dst-nat chain=dstnat comment="DVR restoran" dst-address=45.4.55.85 dst-port=34000 protocol=tcp to-addresses=192.168.1.24 to-ports=34000add action=dst-nat chain=dstnat comment="Camaras Gas" dst-address=45.4.55.85 dst-port=36000 protocol=tcp to-addresses=192.168.1.32 to-ports=36000add action=dst-nat chain=dstnat dst-address=45.4.55.85 dst-port=14000 protocol=tcp to-addresses=192.168.1.102 to-ports=14000add action=dst-nat chain=dstnat dst-address=45.4.55.85 dst-port=27000 protocol=tcp to-addresses=192.168.1.46 to-ports=27000/ip firewall rawadd action=accept chain=prerouting dst-address=192.168.10.0/24 src-address=192.168.20.0/24/ip ipsec identityadd peer=CDadd peer=makro1add peer=Barra/ip ipsec policyadd dst-address=192.168.30.0/24 peer=CD src-address=192.168.20.0/24 tunnel=yesadd dst-address=192.168.10.0/24 dst-port=500 peer=makro1 src-address=192.168.20.0/24 tunnel=yesadd dst-address=192.168.40.0/24 peer=Barra proposal=barra src-address=192.168.20.0/24 tunnel=yesset 3 disabled=yesadd comment="camaras vigilancia" dst-address=192.168.4.0/24 peer=Barra proposal=barra src-address=192.168.1.0/24 tunnel=yesadd comment="camaras vigilancia" dst-address=192.168.3.0/24 peer=CD src-address=192.168.1.0/24 tunnel=yesadd comment="camaras vigilancia" dst-address=192.168.2.0/24 peer=makro1 proposal=Makro1 src-address=192.168.1.0/24 tunnel=yes/ip serviceset telnet disabled=yesset ftp disabled=yesset ssh disabled=yes port=51922set api disabled=yesset api-ssl disabled=yes/ppp profileset *FFFFFFFE local-address=192.168.89.1 remote-address=*3/ppp secretadd name=vpn/system clockset time-zone-name=America/Sao_Paulo/system identityset name="RB Makro 2"/system package updateset channel=upgrade/tool traffic-monitoradd name=camaras