Postado originalmente por
cleciorodrigo
Galera essas sao as regras de firewall que uso aqui
# sep/10/2007 16:22:16 by RouterOS 2.9.27
# software id = Q4W8-A50
#
/ ip firewall nat
add chain=srcnat out-interface=Internet action=masquerade comment="NAT" \
disabled=no
add chain=pre-hotspot in-interface="Rede Local" dst-address=200.201.160.0/24 \
protocol=tcp dst-port=80 hotspot=auth action=accept comment="Conectividade \
Social" disabled=no
add chain=pre-hotspot in-interface="Rede Local" dst-address=200.201.166.0/24 \
protocol=tcp dst-port=80 hotspot=auth action=accept comment="" disabled=no
add chain=pre-hotspot in-interface="Rede Local" dst-address=200.201.173.0/24 \
protocol=tcp dst-port=80 hotspot=auth action=accept comment="" disabled=no
add chain=pre-hotspot in-interface="Rede Local" dst-address=200.201.174.0/24 \
protocol=tcp dst-port=80 hotspot=auth action=accept comment="" disabled=no
add chain=pre-hotspot dst-address=192.168.160.1 protocol=tcp dst-port=80 \
hotspot=auth action=redirect to-ports=64873 comment="Paginas de status do \
hotspot" disabled=no
add chain=pre-hotspot in-interface="Rede Local" protocol=tcp dst-port=80 \
hotspot=auth action=redirect to-ports=3128 comment="Redirecionamento \
Proxy" disabled=no
Lembrando que não defino o proxy nas configurações do profile do hotspot, e que vc deve alterar o nome da interface de rede nas regras pro nome que vcs usam ai.
Falow