Mikrotik
0
Вклад в тег
/ip firewall mangle
add action=mark-connection chain=input in-interface=ether1 new-connection-mark="isp1 in" passthrough=no
add action=mark-routing chain=output connection-mark="isp1 in" new-routing-mark=isp1 passthrough=no
add action=mark-connection chain=input in-interface=ether2 new-connection-mark="isp2 in" passthrough=no
add action=mark-routing chain=output connection-mark="isp2 in" new-routing-mark=isp2 passthrough=no
/ip route
add distance=1 gateway='шлюз ISP1' routing-mark=isp1
add distance=1 gateway='шлюз ISP2' routing-mark=isp2
/ip firewall layer7-protocol
add name=via_isp1 regexp="^.+(mail.***.ru).*\$"
ip firewall mangle
add action=add-dst-to-address-list address-list=isp1_addlist address-list-timeout=1d chain=prerouting disabled=no layer7-protocol=via_isp1 src-address=192.168.0.0/24
add action=mark-routing chain=prerouting disabled=no dst-address-list=isp1_addlist new-routing-mark=mail.*** passthrough=no
add action=mark-routing chain=prerouting disabled=no dst-address=!192.168.0.0/24 new-routing-mark=office passthrough=no
/ip route
add distance=10 gateway='шлюз ISP1' routing-mark=mail.***
add distance=10 gateway='шлюз ISP2' routing-mark=office
/ip firewall mangle
add action=mark-routing chain=prerouting disabled=no dst-address-list new-routing-mark=via_crs125 passthrough=no src-address='адреса клиентов которых выпускаем через crs125'
/ip route
add disabled=no distance=1 gateway='шлюз ISP1' routing-mark=via_crs125
/ip firewall mangle
add action=mark-routing chain=prerouting disabled=yes dst-address-list new-routing-mark=via_crs125 passthrough=no src-address='все подсеть'
add action=mark-routing chain=prerouting disabled=yes dst-address-list new-routing-mark=via_rb951 passthrough=no src-address='все подсеть'