ืžื™ืงืจืึธื˜ื™ืง ืฉืคึผืึทืœื˜ืŸ-ื“ื ืก: ื–ื™ื™ ื”ืื‘ืŸ ืขืก

ื•ื•ื™ื™ื ื™ืงืขืจ ื•ื•ื™ 10 ื™ืึธืจ ืฉืคึผืขื˜ืขืจ, ื“ื™ ื“ืขื•ื•ืขืœืึธืคึผืขืจืก ืคื•ืŸ RoS (ืื™ืŸ ืกื˜ืึทื‘ื™ืœ 6.47) ืฆื•ื’ืขื’ืขื‘ืŸ ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™ ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืจื™ื“ืขืจืขืงื˜ ื“ื ืก ืคึฟืจืื’ืŸ ืœื•ื™ื˜ ืกืคึผืขืฆื™ืขืœ ื›ึผืœืœื™ื. ืื•ื™ื‘ ืคืจื™ืขืจ ืขืก ืื™ื– ื ื™ื™ื˜ื™ืง ืฆื• ื“ืึทื“ื–ืฉ ืžื™ื˜ ืœื™ื™ึทืขืจ-7 ื›ึผืœืœื™ื ืื™ืŸ ื“ื™ ืคื™ื™ืจื•ื•ืึทืœ, ืื™ืฆื˜ ื“ืึธืก ืื™ื– ืคืฉื•ื˜ ืื•ืŸ ืขืœืขื’ืึทื ื˜:

/ip dns static
add forward-to=192.168.88.3 regexp=".*\.test1\.localdomain" type=FWD
add forward-to=192.168.88.56 regexp=".*\.test2\.localdomain" type=FWD

ืžื™ื™ืŸ ื’ืœื™ืง ืงืขืŸ ื ื™ืฉื˜ ืงื™ื™ืŸ ื’ืจืขื ืขืฆืŸ!

ืžื™ื˜ ื•ื•ืืก ืกื˜ืจืืฉืขื˜ ืื•ื ื– ื“ืืก?

ืื™ืŸ ืึท ืžื™ื ื™ืžื•ื, ืžื™ืจ ื‘ืึทืงื•ืžืขืŸ ื‘ืึทืคืจื™ื™ึทืขืŸ ืคื•ืŸ ืžืึธื“ื ืข NAT ืงืึทื ืกื˜ืจืึทืงืฉืึทื ื– ื•ื•ื™ ื“ืึธืก:


/ip firewall layer7-protocol
add comment="DNS Nat contoso.com" name=contoso.com regexp="\x07contoso\x03com"
/ip firewall mangle
add action=mark-packet chain=prerouting comment="mark dns contoso.com" dst-address-type=local dst-port=53 in-interface-list=DNSMASQ layer7-protocol=contoso.com new-packet-mark=dns-contoso.com passthrough=yes protocol=udp
add action=mark-packet chain=prerouting comment="mark dns contoso.com" dst-address-type=local dst-port=53 in-interface-list=DNSMASQ layer7-protocol=contoso.com new-packet-mark=dns-contoso.com passthrough=yes protocol=tcp
/ip firewall nat
add action=dst-nat chain=dstnat comment="DST-NAT dns contoso.com" dst-port=53 in-interface-list=DNSMASQ packet-mark=dns-contoso.com protocol=udp to-addresses=192.0.2.15
add action=dst-nat chain=dstnat comment="DST-NAT dns contoso.com" dst-port=53 in-interface-list=DNSMASQ packet-mark=dns-contoso.com protocol=tcp to-addresses=192.0.2.15
add action=masquerade chain=srcnat comment="mask dns contoso.com" dst-port=53 packet-mark=dns-contoso.com protocol=udp
add action=masquerade chain=srcnat comment="mask dns contoso.com" dst-port=53 packet-mark=dns-contoso.com protocol=tcp

ืื•ืŸ ืึทื– ืก ื ื™ื˜ ืึทืœืข, ืื™ืฆื˜ ืื™ืจ ืงืขื ืขืŸ ืคืึทืจืฉืจื™ื™ึทื‘ืŸ ืขื˜ืœืขื›ืข ืคืึธืจื•ื•ืขืจื“ืขืจื–, ื•ื•ืึธืก ื•ื•ืขื˜ ื”ืขืœืคึฟืŸ ืžืึทื›ืŸ ื“ื ืก ืคื™ื™ืœืึธื•ื•ืขืจ.
ื™ื ื˜ืขืœื™ื’ืขื ื˜ ื“ื ืก ืคึผืจืึทืกืขืกื™ื ื’ ื•ื•ืขื˜ ืžืึทื›ืŸ ืขืก ืžืขื’ืœืขืš ืฆื• ืึธื ื”ื™ื™ื‘ืŸ ื™ื ื˜ืจืึธื•ื“ื•ืกื™ื ื’ ื™ืคึผื•ื•6 ืื™ืŸ ื“ื™ ืคื™ืจืžืข 'ืก ื ืขืฅ. ืคืืจ ื“ืขื ื”ืื‘ ืื™ืš ื“ืืก ื ื™ืฉื˜ ื’ืขื˜ื•ืŸ, ื“ื™ ืกื™ื‘ื” ืื™ื– ืื– ืื™ืš ื”ืื‘ ื’ืขื“ืืจืคื˜ ืœื™ื™ื–ืŸ ื ืฆืืœ ื“ื ืก ื ืขืžืขืŸ ืฆื• ืœืืงืืœืข ืื“ืจืขืกืŸ, ืื•ืŸ ืื™ืŸ IPv6 ื”ืื˜ ืžืขืŸ ื“ืืก ื ื™ืฉื˜ ื’ืขืงืขื ื˜ ื˜ื•ื”ืŸ ืืŸ ื’ืืจ ื’ืจื•ื™ืกืข ืงืจืื˜ืฉืขืก.

ืžืงื•ืจ: www.habr.com