دمج خطين على فتحة وخطين على فتحتبن
دمج خطين على فتحة وخطين على فتحتبن
دمج خطين على فتحة وخطين على فتحتبن
دمج خطين على فتحة وخطين على فتحتبن
دمج خطين على فتحة وخطين على فتحتبن
دمج خطين على فتحة وخطين على فتحتبن
دمج خطين على فتحة وخطين على فتحتبن
الكود
- الكود:
-
ip address
add address=192.168.1.2/24 broadcast=192.168.1.255 comment="" disabled=no interface=WAN1 network=192.168.1.0
add address=192.168.2.2/24 broadcast=192.168.2.255 comment="" disabled=no interface=WAN1 network=192.168.2.0
add address=10.10.10.1/24 broadcast=10.10.10.255 comment="" disabled=no interface=Local network=10.10.10.0
/ip firewall mangle
add action=mark-connection chain=input disabled=no in-interface=WAN1 \
new-connection-mark=WAN1_conn passthrough=yes
add action=mark-connection chain=input disabled=no in-interface=pppoe-out1 \
new-connection-mark=WAN2_conn passthrough=yes
add action=mark-connection chain=input disabled=no in-interface=pppoe-out2 \
new-connection-mark=WAN3_conn passthrough=yes
add action=mark-routing chain=output connection-mark=WAN1_conn disabled=no \
hotspot=auth new-routing-mark=WAN1 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN1_conn disabled=no \
hotspot=auth new-routing-mark=WAN1 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN2_conn disabled=no \
hotspot=auth new-routing-mark=WAN2 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN3_conn disabled=no \
hotspot=auth new-routing-mark=WAN3 passthrough=yes
add action=mark-connection chain=prerouting disabled=no dst-address-type=\
!local in-interface=Local new-connection-mark=WAN1_conn passthrough=yes \
per-connection-classifier=both-addresses-and-ports:5/0
add action=mark-connection chain=prerouting disabled=no dst-address-type=\
!local in-interface=Local new-connection-mark=WAN1_conn passthrough=yes \
per-connection-classifier=both-addresses-and-ports:5/1
add action=mark-connection chain=prerouting disabled=no dst-address-type=\
!local in-interface=Local new-connection-mark=WAN2_conn passthrough=yes \
per-connection-classifier=both-addresses-and-ports:5/2
add action=mark-connection chain=prerouting disabled=no dst-address-type=\
!local in-interface=Local new-connection-mark=WAN3_conn passthrough=yes \
per-connection-classifier=both-addresses-and-ports:5/3
add action=mark-routing chain=prerouting connection-mark=WAN1_conn disabled=\
no in-interface=Local new-routing-mark=WAN1 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=WAN1_conn disabled=\
no in-interface=Local new-routing-mark=WAN1 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=WAN2_conn disabled=\
no in-interface=Local new-routing-mark=WAN2 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=WAN3_conn disabled=\
no in-interface=Local new-routing-mark=WAN3 passthrough=yes
/ip firewall nat
add action=passthrough chain=unused-hs-chain comment=\
"place hotspot rules here" disabled=yes to-addresses=0.0.0.0
add action=masquerade chain=srcnat comment="masquerade hotspot network" \
disabled=no src-address=10.0.0.0/22 to-addresses=0.0.0.0
add action=masquerade chain=srcnat disabled=no src-address=192.168.8.0/24
add action=masquerade chain=srcnat comment="masquerade hotspot network" \
disabled=no src-address=192.168.28.0/22 to-addresses=0.0.0.0
add action=masquerade chain=srcnat comment=WAN1 disabled=no out-interface=\
WAN1
add action=masquerade chain=srcnat comment=WAN2 disabled=no out-interface=\
pppoe-out1
add action=masquerade chain=srcnat comment=WAN3 disabled=no out-interface=\
pppoe-out2
/ip route
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=\
192.168.1.1,192.168.2.1 routing-mark=WAN1 scope=30 target-scope=10
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=\
pppoe-out1 routing-mark=WAN2 scope=30 target-scope=10
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=\
pppoe-out2 routing-mark=WAN3 scope=30 target-scope=10
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=\
192.168.1.1.1,192.168.2.1 scope=30 target-scope=10
add check-gateway=ping disabled=no distance=2 dst-address=0.0.0.0/0 gateway=\
pppoe-out1 scope=30 target-scope=10
add check-gateway=ping disabled=no distance=3 dst-address=0.0.0.0/0 gateway=\
pppoe-out2 scope=30 target-scope=10
/ip dns
set allow-remote-requests=no cache-max-ttl=1w cache-size=2048KiB max-udp-packet-size=512 servers=8.8.8.8,8.8.4.4