Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- / ip address
- add address=10.10.0.1/24 network=10.10.0.0 broadcast=10.10.0.255 interface=LAN
- add address=192.168.1.2/24 network=192.168.1.0 broadcast=192.168.1.255 interface=ISP1
- add address=192.168.2.2/24 network=192.168.2.0 broadcast=192.168.2.255 interface=ISP2
- /ip dns set allow-remote-requests=yes cache-max-ttl=1w cache-size=5000KiB max-udp-packet-size=512 servers=8.8.8.8
- / ip firewall mangle
- add chain=prerouting dst-address=192.168.1.0/24 action=accept in-interface=LAN
- add chain=prerouting dst-address=192.168.2.0/24 action=accept in-interface=LAN
- add chain=prerouting in-interface=ISP1 connection-mark=no-mark action=mark-connection \ new-connection-mark=ISP1_conn
- add chain=prerouting in-interface=ISP1 connection-mark=no-mark action=mark-connection \ new-connection-mark=ISP2_conn
- add chain=prerouting in-interface=LAN connection-mark=no-mark dst-address-type=!local \ per-connection-classifier=both-addresses:2/0 action=mark-connection new-connection-mark=ISP1_conn
- add chain=prerouting in-interface=LAN connection-mark=no-mark dst-address-type=!local \ per-connection-classifier=both-addresses:2/1 action=mark-connection new-connection-mark=ISP2_conn
- add chain=prerouting connection-mark=ISP1_conn in-interface=LAN action=mark-routing \ new-routing-mark=to_ISP1
- add chain=prerouting connection-mark=ISP2_conn in-interface=LAN action=mark-routing \ new-routing-mark=to_ISP2
- add chain=output connection-mark=ISP1_conn action=mark-routing new-routing-mark=to_ISP1
- add chain=output connection-mark=ISP2_conn action=mark-routing new-routing-mark=to_ISP2
- / ip route
- add dst-address=0.0.0.0/0 gateway=192.168.1.1 routing-mark=to_ISP1 check-gateway=ping
- add dst-address=0.0.0.0/0 gateway=192.168.2.1 routing-mark=to_ISP2 check-gateway=ping
- add dst-address=0.0.0.0/0 gateway=192.168.1.1 distance=1 check-gateway=ping
- add dst-address=0.0.0.0/0 gateway=192.168.2.1 distance=2 check-gateway=ping
- / ip firewall nat
- add chain=srcnat out-interface=ISP1 action=masquerade
- add chain=srcnat out-interface=ISP2 action=masquerade
- The router has two upstream (ISP) interfaces with the addresses of 192.168.1.2/24 and 192.168.2.2/24. The LAN interface has IP address of 10.10.0.1/24.
- As routing decision is already made we just need rules that will fix src-addresses for all outgoing packets. If this packet will leave via wlan1 it will be NATed to 10.112.0.2, if via wlan2 then NATed to 192.168.1.2
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement