Вы находитесь на странице: 1из 3

Bienvenido a este entrenamiento

Por: Rodrigo Anrrango


www.institutodewisp.com

***Configurar PPPoE Cliente


***Activar DNS

** Interfaces Mikrotik
IPS1, ISP2, ISP3, ISP4. LAN

** Interface de PPPoE
pppoe-out1, pppoe-out2, pppoe-out3, pppoe-out4

****Nat All Interfaces

/ip firewall nat


add action=masquerade chain=srcnat disabled=no out-interface=pppoe-out1
add action=masquerade chain=srcnat disabled=no out-interface=pppoe-out2
add action=masquerade chain=srcnat disabled=no out-interface=pppoe-out3
add action=masquerade chain=srcnat disabled=no out-interface=pppoe-out4

*** Anidir pool de IPS del LAN puede ser /24 0r /30

/ip firewall address-list


add address=192.168.19.0/30 disabled=no list=GW01_LAN

****MANGLE and First Https and second ACCEP prerouting with address-
list=GW01_LAN*****

/ip firewall mangle


add action=accept chain=prerouting disabled=no dst-address-list=GW01_LAN src-
address-list=GW01_LAN
add action=mark-connection chain=forward connection-mark=no-mark disabled=no in-
interface=pppoe-out1 new-connection-mark=ISP1_conn passthrough=no
add action=mark-connection chain=forward connection-mark=no-mark disabled=no in-
interface=pppoe-out2 new-connection-mark=ISP2_conn passthrough=no
add action=mark-connection chain=forward connection-mark=no-mark disabled=no in-
interface=pppoe-out3 new-connection-mark=ISP3_conn passthrough=no
add action=mark-connection chain=forward connection-mark=no-mark disabled=no in-
interface=pppoe-out4 new-connection-mark=ISP4_conn passthrough=no
add action=mark-connection chain=prerouting connection-mark=no-mark disabled=no in-
interface=pppoe-out1 new-connection-mark=ISP1_conn passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark disabled=no in-
interface=pppoe-out2 new-connection-mark=ISP2_conn passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark disabled=no in-
interface=pppoe-out3 new-connection-mark=ISP3_conn passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark disabled=no in-
interface=pppoe-out4 new-connection-mark=ISP4_conn passthrough=yes
add action=jump chain=prerouting connection-mark=no-mark disabled=no in-
interface=LAN jump-target=policy_routing
add action=mark-routing chain=prerouting connection-mark=ISP1_conn disabled=no new-
routing-mark=ISP1_traffic passthrough=yes src-address-list=GW01_LAN
add action=mark-routing chain=prerouting connection-mark=ISP2_conn disabled=no new-
routing-mark=ISP2_traffic passthrough=yes src-address-list=GW01_LAN
add action=mark-routing chain=prerouting connection-mark=ISP3_conn disabled=no new-
routing-mark=ISP3_traffic passthrough=yes src-address-list=GW01_LAN
add action=mark-routing chain=prerouting connection-mark=ISP4_conn disabled=no new-
routing-mark=ISP4_traffic passthrough=yes src-address-list=GW01_LAN
add action=mark-routing chain=output connection-mark=ISP1_conn disabled=no new-
routing-mark=ISP1_traffic passthrough=yes
add action=mark-routing chain=output connection-mark=ISP2_conn disabled=no new-
routing-mark=ISP2_traffic passthrough=yes
add action=mark-routing chain=output connection-mark=ISP3_conn disabled=no new-
routing-mark=ISP3_traffic passthrough=yes
add action=mark-routing chain=output connection-mark=ISP4_conn disabled=no new-
routing-mark=ISP4_traffic passthrough=yes
add action=mark-connection chain=policy_routing dst-address-type=!local new-
connection-mark=ISP1_conn per-connection-classifier=both-addresses-and-ports:4/0
add action=mark-connection chain=policy_routing dst-address-type=!local new-
connection-mark=ISP2_conn per-connection-classifier=both-addresses-and-ports:4/1
add action=mark-connection chain=policy_routing dst-address-type=!local new-
connection-mark=ISP3_conn per-connection-classifier=both-addresses-and-ports:4/2
add action=mark-connection chain=policy_routing dst-address-type=!local new-
connection-mark=ISP4_conn per-connection-classifier=both-addresses-and-ports:4/3

***NOTA Importante***
Opci�n: both-addresses
add action=mark-connection chain=policy_routing dst-address-type=!local new-
connection-mark=ISP1_conn per-connection-classifier=both-addresses:4/0
add action=mark-connection chain=policy_routing dst-address-type=!local new-
connection-mark=ISP2_conn per-connection-classifier=both-addresses:4/1
add action=mark-connection chain=policy_routing dst-address-type=!local new-
connection-mark=ISP3_conn per-connection-classifier=both-addresses:4/2
add action=mark-connection chain=policy_routing dst-address-type=!local new-
connection-mark=ISP4_conn per-connection-classifier=both-addresses:4/3

************************
##Difinici�n##
both-addresses = ambas-direcciones IP
both-addresses: La petici�n de origen y destino IP entre el mismo cliente y el
servidor siempre ser� la misma, por lo que todo el tr�fico
entre un cliente espec�fico y un servidor espec�fico (por ejemplo, su computadora
port�til y servidor 67.89.2.5) siempre que coincida con el
mismo matcher PCC , y siempre ser� puesto en el mismo enlace.

both-addresses = ambas-direcciones IP ,se refiere a src-address y dst-address


Como el clasificador. Aunque esto va a cambiar aleatoriamente cosas la teor�a m�s y
le dar� la asignaci�n m�s justa de ancho de banda,
pero tambi�n hay una buena probabilidad de que se rompa ciertas cosas como los
sitios web bancarios y algunos foros.
Esto se debe a las peticiones muchas veces un HTTP generar�n varias conexiones, por
lo que existe la posibilidad de
que algunas solicitudes podr�n salir una ruta diferente a la inicial, y que se
romper�n los sitios web seguros.

Mas informaci�n: http://wiki.mikrotik.com/wiki/How_PCC_works_%28beginner%29


************************

***Failover

/ip route
add check-gateway=arp distance=1 gateway=pppoe-out1 routing-mark=ISP1_traffic
add check-gateway=arp distance=1 gateway=pppoe-out2 routing-mark=ISP2_traffic
add check-gateway=arp distance=1 gateway=pppoe-out3 routing-mark=ISP3_traffic
add check-gateway=arp distance=1 gateway=pppoe-out4 routing-mark=ISP4_traffic
add check-gateway=arp distance=2 gateway=pppoe-out1
add check-gateway=arp distance=3 gateway=pppoe-out2
add check-gateway=arp distance=4 gateway=pppoe-out3
add check-gateway=arp distance=5 gateway=pppoe-out4

By: Rodrigo Anrrango

Вам также может понравиться