Вы находитесь на странице: 1из 2

1# AGREGAR IPS WAN

/ ip address
add address=192.168.11.2/24 interface=wan1 network=192.168.11.0
add address=192.168.12.2/24 interface=wan2 network=192.168.12.0
add address=192.168.13.2/24 interface=ether3 network=192.168.13.0
add address=192.168.14.2/24 interface=ether4 network=192.168.14.0

2# AGREGAR LAN

/ ip address
add address=172.16.0.1/24 network=172.16.0.0 interface=Lan

3# ENMASCARADO NAT

/ip firewall nat


add action=masquerade chain=srcnat out-interface=wan1
add action=masquerade chain=srcnat out-interface=wan2
add action=masquerade chain=srcnat out-interface=ether3
add action=masquerade chain=srcnat out-interface=ether4

4# AGREGAR DNS

/ip dns
set servers=8.8.8.8,8.8.4.4

5# LO QUE ENTRA POR 1 WAN SALE POR EL MISMO

/ip firewall mangle


add action=mark-connection chain=prerouting connection-mark=no-mark in-
interface=wan1 new-connection-mark=ISP1_conn
add action=mark-connection chain=prerouting connection-mark=no-mark in-
interface=wan2 new-connection-mark=ISP2_conn
add action=mark-routing chain=output connection-mark=ISP1_conn new-routing-
mark=to_ISP1 passthrough=no
add action=mark-routing chain=output connection-mark=ISP2_conn new-routing-
mark=to_ISP2 passthrough=no

6# AGREGAR RED BALANCEADA

/ip firewall address-list


add address=172.16.0.0/24 list=RED

7# BALANCEO DE PETICIONES NTH

/ip firewall mangle


add action=mark-connection chain=prerouting connection-mark=no-mark dst-address-
type=!local new-connection-mark=ISP1_conn nth=2,1 src-address-list=RED
add action=mark-routing chain=prerouting connection-mark=ISP1_conn new-routing-
mark=to_ISP1 passthrough=no src-address-list=RED
add action=mark-connection chain=prerouting connection-mark=no-mark dst-address-
type=!local new-connection-mark=ISP2_conn nth=2,0 src-address-list=RED
add action=mark-routing chain=prerouting connection-mark=ISP2_conn new-routing-
mark=to_ISP2 passthrough=no src-address-list=RED

8# Agregar Gateway Y FAILOVER

/ip route
add check-gateway=ping distance=1 gateway=192.168.50.1
add check-gateway=ping distance=2 gateway=192.168.10.1
add check-gateway=ping distance=1 gateway=192.168.50.1 routing-mark=to_ISP1
add check-gateway=ping distance=1 gateway=192.168.10.1 routing-mark=to_ISP2

FAILOVER ALTERNATIVO CON PING A SERVIDORES DNS (EN PRUEBAS)

/ip route

add check-gateway=ping distance=1 gateway=1.1.1.1 routing-mark=to_ISP1


add check-gateway=ping distance=2 gateway=8.8.8.8 routing-mark=to_ISP2

add distance=1 gateway=192.168.50.1 routing-mark=to_ISP1


add distance=2 gateway=192.168.10.1 routing-mark=to_ISP2

add distance=1 gateway=192.168.50.1


add distance=2 gateway=192.168.10.1

add distance=1 dst-address=1.1.1.1 gateway=192.168.50.1 scope=10


add distance=1 dst-address=8.8.8.8 gateway=192.168.10.1 scope=10

add check-gateway=ping distance=1 dst-address=192.168.50.0/24 gateway=1.1.1.1


scope=10
add check-gateway=ping distance=2 dst-address=192.168.10.0/24 gateway=8.8.8.8
scope=10

Вам также может понравиться