tutto risolto, la guida postata da figheras è perfetta e mi è stato molto utile l'aiuto che mi ha dato.
/ip address
add address=10.0.10.2/30 broadcast=10.0.10.3 comment="" disabled=no \
interface=ISP1 network=10.0.10.0
add address=10.0.20.2/30 broadcast=10.0.20.3 comment="" disabled=no \
interface=ISP2 network=10.0.20.0
add address=192.168.88.1/30 broadcast=192.168.88.3 comment="" disabled=no \
interface=Local network=192.168.88.0
/ip firewall mangle
add action=accept chain=prerouting comment=\
"====================================================================" \
disabled=no dst-address=192.168.88.0/30 src-address=192.168.88.0/30
add action=accept chain=prerouting comment="" disabled=no dst-address=\
10.0.10.0/30 src-address=192.168.88.0/30
add action=accept chain=prerouting comment="" disabled=no dst-address=\
10.0.20.0/30 src-address=192.168.88.0/30
add action=mark-connection chain=prerouting comment=\
"====================================================================" \
connection-mark=no-mark disabled=no in-interface=ISP1 \
new-connection-mark=ISP1_conn passthrough=yes
add action=mark-connection chain=prerouting comment="" connection-mark=\
no-mark disabled=no in-interface=ISP2 new-connection-mark=ISP2_conn \
passthrough=yes
add action=jump chain=prerouting comment=\
"====================================================================" \
connection-mark=no-mark disabled=no in-interface=Local jump-target=\
policy_router
add action=mark-routing chain=prerouting comment=\
"====================================================================" \
connection-mark=ISP1_conn disabled=no new-routing-mark=ISP1_trafic \
passthrough=yes src-address=192.168.88.0/30
add action=mark-routing chain=prerouting comment="" connection-mark=ISP2_conn \
disabled=no new-routing-mark=ISP2_trafic passthrough=yes src-address=\
192.168.88.0/30
add action=mark-routing chain=output comment=\
"====================================================================" \
connection-mark=ISP1_conn disabled=no new-routing-mark=ISP1_trafic \
passthrough=yes
add action=mark-routing chain=output comment="" connection-mark=ISP2_conn \
disabled=no new-routing-mark=ISP2_trafic passthrough=yes
add action=mark-connection chain=policy_router comment=\
"====================================================================" \
disabled=no dst-address-type=!local new-connection-mark=ISP1_conn \
passthrough=yes per-connection-classifier=both-addresses:2/0
add action=mark-connection chain=policy_router comment="" disabled=no \
dst-address-type=!local new-connection-mark=ISP2_conn passthrough=yes \
per-connection-classifier=both-addresses:2/1
/ip firewall nat
add action=masquerade chain=srcnat comment="" disabled=no out-interface=ISP1
add action=masquerade chain=srcnat comment="" disabled=no out-interface=ISP2
/ip route
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=10.0.10.1 \
routing-mark=ISP1_trafic scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=10.0.20.1 \
routing-mark=ISP2_trafic scope=30 target-scope=10
add comment="" disabled=no distance=2 dst-address=0.0.0.0/0 gateway=10.0.10.1 \
scope=30 target-scope=10
add comment="" disabled=no distance=3 dst-address=0.0.0.0/0 gateway=10.0.20.1 \
scope=30 target-scope=10
figheras ha scritto:Certo puoi fare il mark delle connessioni sia delle interfacce e sia delle subnet che vuoi...non hai limiti!
add chain=prerouting dst-address-type=!local in-interface=ether3 per-connection-classifier=both-addresses:2/0 \ action=mark-connection new-connection-mark=ether1_conn passthrough=yes
add chain=prerouting src-address=192.168.10.0/24 dst-address-type=!local per-connection-classifier=both-addresses:2/0 \ action=mark-connection new-connection-mark=ether1_conn passthrough=yes
Torna a Wiki routerOSiTalia [GUIDE]
Visitano il forum: Nessuno e 2 ospiti