Académique Documents
Professionnel Documents
Culture Documents
/ip
add
add
add
add
protocol=udp in-interface=ether3-loc
protocol=tcp in-interface=ether3-loc
protocol=udp in-interface=ether5-pro
protocol=tcp in-interface=ether5-pro
firewall address-list
list=LAN-NeT address=192.168.0.0/24
list=Proxy-NeT address=192.168.50.0/24
list=Local+Proxy address=192.168.0.0/24
list=Local+Proxy address=192.168.50.0/24
HTTP CONN
MARK-HTTP ROUTE :
add chain=prerouting action=mark-routing new-routing-mark=pppoe-out1 passthrough
=yes in-interface=ether5-proxy \
connection-mark=http-pppoe1 comment="MARK-HTTP ROUTE"
add chain=prerouting action=mark-routing new-routing-mark=pppoe-out2 passthrough
=yes in-interface=ether5-proxy \
connection-mark=http-pppoe2
NON-HTTP CONN :
add chain=prerouting action=mark-connection new-connection-mark=non-http-pppoe1
passthrough=yes protocol=tcp
dst-address-type=!local dst-address-list=!Local+Proxy in-interface=ether5-proxy
dst-port=80,3128 \
per-connection-classifier=both-addresses-and-ports:2/0 comment="NON-HTTP CONN"
add chain=prerouting action=mark-connection new-connection-mark=non-http-pppoe2
passthrough=yes protocol=tcp \
dst-address-type=!local dst-address-list=!Local+Proxy in-interface=ether5-pr
oxy dst-port=80,3128 \
per-connection-classifier=both-addresses-and-ports:2/1
add chain=prerouting action=mark-connection new-connection-mark=non-http-pppoe1
passthrough=yes protocol=tcp \
dst-address-type=!local dst-address-list=!Local+Proxy in-interface=ether3-lo
cal dst-port=!80,3128 \
per-connection-classifier=both-addresses-and-ports:2/0
add chain=prerouting action=mark-connection new-connection-mark=non-http-pppoe2
passthrough=yes protocol=tcp \
dst-address-type=!local dst-address-list=!Local+Proxy in-interface=ether3-lo
cal dst-port=!80,3128 \
per-connection-classifier=both-addresses-and-ports:2/1
add chain=prerouting action=mark-connection new-connection-mark=non-http-pppoe1
passthrough=yes protocol=udp \
dst-address-type=!local dst-address-list=!Local+Proxy in-interface=ether5-pr
oxy \
per-connection-classifier=both-addresses-and-ports:2/0
add chain=prerouting action=mark-connection new-connection-mark=non-http-pppoe2
passthrough=yes protocol=udp \
dst-address-type=!local dst-address-list=!Local+Proxy in-interface=ether5-pr
oxy \
per-connection-classifier=both-addresses-and-ports:2/1
add chain=prerouting action=mark-connection new-connection-mark=non-http-pppoe1
passthrough=yes protocol=udp \
dst-address-type=!local in-interface=ether3-local per-connection-classifier=
both-addresses-and-ports:2/0 \
add chain=prerouting action=mark-connection new-connection-mark=non-http-pppoe2
passthrough=yes protocol=udp \
dst-address-type=!local in-interface=ether3-local per-connection-classifier=
both-addresses-and-ports:2/1
MARK NON HTTP ROUTE :
add chain=prerouting action=mark-routing new-routing-mark=pppoe-out1 passthr
ough=yes in-interface=ether3-local \
connection-mark=non-http-pppoe1 comment="MARK NON HTTP ROUTE"
add chain=prerouting action=mark-routing new-routing-mark=pppoe-out2 passthr
ough=yes in-interface=ether3-local \
connection-mark=non-http-pppoe2
CRITICAL CONN :
add chain=postrouting action=change-dscp new-dscp=1 protocol=tcp dst-port=53
comment="CRITICAL CONN"
add chain=postrouting action=change-dscp new-dscp=1 protocol=icmp
add chain=postrouting action=change-dscp new-dscp=1 protocol=udp dst-port=53
add chain=postrouting action=mark-connection new-connection-mark=critical-co
nn passthrough=yes dscp=1
add chain=postrouting action=mark-packet new-packet-mark=critical-pkt passth
rough=no connection-mark=critical-conn
PROXY-HIT :
add chain=prerouting action=mark-packet new-packet-mark=PKT-HIT passthrough=
no protocol=tcp \
in-interface=Proxy dscp=12 comment="PROXY-HIT"
add chain=postrouting action=mark-packet new-packet-mark=PKT-HIT passthrough
=no out-interface=LAN dscp=12
IP ROUTE :
/ip route
add dst-address=0.0.0.0/0 gateway=pppoe-out1 gateway-status=pppoe-out1 reachable
check-gateway=ping distance=1 \
scope=30 target-scope=10 comment="Default_Speedy1"
add dst-address=0.0.0.0/0 gateway=pppoe-out2 gateway-status=pppoe-out2 reachable
check-gateway=ping distance=2 \
scope=30 target-scope=10 routing-mark=PointBlank comment="Default_Speedy2"
add dst-address=0.0.0.0/0 gateway=pppoe-out1 gateway-status=pppoe-out1 reachable
check-gateway=ping distance=1 \
scope=30 target-scope=10 routing-mark=pppoe-out1
add dst-address=0.0.0.0/0 gateway=pppoe-out2 gateway-status=pppoe-out2 reachable
check-gateway=ping distance=1 \
scope=30 target-scope=10 routing-mark=pppoe-out2
atau
/ip route
add dst-address=0.0.0.0/0 gateway=pppoe-out1 check-gateway=ping distance=1
scope=30 target-scope=10 comment="Default_Speedy1"
add dst-address=0.0.0.0/0 gateway=pppoe-out2 check-gateway=ping distance=2
scope=30 target-scope=10 routing-mark=PointBlank comment="Default_Speedy2"
add dst-address=0.0.0.0/0 gateway=pppoe-out1 check-gateway=ping distance=1
scope=30 target-scope=10 routing-mark=pppoe-out1
add dst-address=0.0.0.0/0 gateway=pppoe-out2 check-gateway=ping distance=1
scope=30 target-scope=10 routing-mark=pppoe-out2
\
\
\
\