ืžื•ืœื˜ื™ื•ื•ืึทืŸ ืื•ืŸ ืจื•ื˜ื™ื ื’ ืื•ื™ืฃ Mikrotik RouterOS

ื”ืงื“ืžื”

ืื™ื‘ืขืจื ืขืžืขืŸ ื“ืขื ืึทืจื˜ื™ืงืœ, ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• ื’ืึทื“ืœืขืก, ืื™ื– ื’ืขื•ื•ืขืŸ ืคึผืจืึทืžืคึผื˜ื™ื“ ื“ื•ืจืš ื“ื™ ื“ื™ืคึผืจืขืกื™ื ื’ ืึธืคื˜ืงื™ื™ึทื˜ ืคื•ืŸ ืคืจืื’ืขืก ืื•ื™ืฃ ื“ืขื ื˜ืขืžืข ืื™ืŸ ื“ื™ ืคึผืจืึธืคื™ืœ ื’ืจื•ืคึผืขืก ืคื•ืŸ ื“ื™ ืจื•ืกื™ืฉ-ื’ืขืจืขื“ื˜ ื˜ืขืœืขื’ืจืึทื ืงื”ืœ. ื“ืขืจ ืึทืจื˜ื™ืงืœ ืื™ื– ืึทื™ืžืขื“ ืฆื• ืึธื ื”ื™ื™ื‘ืขืจ ืžื™ืงืจืึธื˜ื™ืง ืจืึธื•ื˜ืขืจืึธืก (ื“ืขืจื ืึธืš ืจื™ืคืขืจื“ ืฆื• ื•ื•ื™ ROS) ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจืก. ืขืก ื“ื™ืœื– ื‘ืœื•ื™ื– ืžื™ื˜ ื“ื™ ืžื•ืœื˜ื™ื•ื•ืึทืŸ, ืžื™ื˜ ืึท ื˜ืจืึธืคึผ ืื•ื™ืฃ ืจื•ื˜ื™ื ื’. ื•ื•ื™ ืึท ื‘ืึธื ื•ืก, ืขืก ื–ืขื ืขืŸ ืžื™ื ื™ืžืึทืœ ื’ืขื ื•ื’ ืกืขื˜ื˜ื™ื ื’ืก ืฆื• ืขื ืฉื•ืจ ื–ื™ื›ืขืจ ืื•ืŸ ื‘ืึทืงื•ื•ืขื ืึธืคึผืขืจืึทืฆื™ืข. ื“ื™ ื•ื•ืืก ื–ืขื ืขืŸ ืงื•ืงืŸ ืคึฟืึทืจ ืึทื ื˜ืคึผืœืขืงื•ื ื’ ืคื•ืŸ ื“ื™ ื˜ืขืžืขืก ืคื•ืŸ ืงื™ื•ื–, ืžืึทืกืข ื‘ืึทืœืึทื ืกื™ื ื’, ื•ื•ืœืึทื ื–, ื‘ืจื™ืงืŸ, ืžืึทืœื˜ื™-ื‘ื™ื ืข ื˜ื™ืฃ ืึทื ืึทืœื™ืกื™ืก ืคื•ืŸ ื“ื™ ืฉื˜ืึทื˜ ืคื•ืŸ ื“ื™ ืงืึทื ืึทืœ ืื•ืŸ ื“ื™ ื•ื•ื™ - ืงืขืŸ ื ื™ืฉื˜ ื•ื•ื™ืกื˜ ืฆื™ื™ื˜ ืื•ืŸ ืžื™ ืœื™ื™ืขื ืขืŸ.

ืขืจืฉื˜ ื“ืึทื˜ืข

ื•ื•ื™ ืึท ืคึผืจืึธื‘ืข ื•ื ื˜ืขืจื˜ืขื ื™ืง, ืึท ืคื™ื ืฃ-ืคึผืึธืจื˜ ืžื™ืงืจืึธื˜ื™ืง ืจืึทื•ื˜ืขืจ ืžื™ื˜ ืจืึธืก ื•ื•ืขืจืกื™ืข 6.45.3 ืื™ื– ืื•ื™ืกื’ืขืงืœื™ื‘ืŸ. ืขืก ื•ื•ืขื˜ ืžืึทืจืฉืจื•ื˜ ืคืึทืจืงืขืจ ืฆื•ื•ื™ืฉืŸ ืฆื•ื•ื™ื™ ื”ื™ื’ืข ื ืขื˜ื•ื•ืึธืจืงืก (LAN1 ืื•ืŸ LAN2) ืื•ืŸ ื“ืจื™ื™ ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื– (ISP1, ISP2, ISP3). ื“ืขืจ ืงืึทื ืึทืœ ืฆื• ISP1 ื”ืื˜ ืึท ืกื˜ืึทื˜ื™ืง "ื’ืจื•ื™" ืึทื“ืจืขืก, ISP2 - "ื•ื•ื™ื™ึทืก", ื‘ืืงื•ืžืขืŸ ื“ื•ืจืš DHCP, ISP3 - "ื•ื•ื™ื™ึทืก" ืžื™ื˜ PPPoE ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ. ื“ื™ ืงืฉืจ ื“ื™ืึทื’ืจืึทืžืข ืื™ื– ื’ืขื•ื•ื™ื–ืŸ ืื™ืŸ ื“ื™ ืคื™ื’ื•ืจ:

ืžื•ืœื˜ื™ื•ื•ืึทืŸ ืื•ืŸ ืจื•ื˜ื™ื ื’ ืื•ื™ืฃ Mikrotik RouterOS

ื“ื™ ืึทืจื‘ืขื˜ ืื™ื– ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ ื“ื™ MTK ืจืึทื•ื˜ืขืจ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ ืกื›ืขืžืข ืึทื–ื•ื™ ืึทื–:

  1. ืฆื•ืฉื˜ืขืœืŸ ืึธื˜ืึทืžืึทื˜ื™ืง ืกื•ื•ื™ื˜ืฉื™ื ื’ ืฆื• ืึท ื‘ืึทืงืึทืคึผ ืฉืคึผื™ื™ึทื–ืขืจ. ื“ืขืจ ื”ื•ื™ืคึผื˜ ืฉืคึผื™ื™ึทื–ืขืจ ืื™ื– ISP2, ื“ืขืจ ืขืจืฉื˜ืขืจ ืจืขื–ืขืจื•ื• ืื™ื– ISP1, ื“ื™ ืจื’ืข ืจืขื–ืขืจื•ื• ืื™ื– ISP3.
  2. ืึธืจื’ืึทื ื™ื–ื™ืจืŸ LAN1 ื ืขืฅ ืึทืงืกืขืก ืฆื• ื“ื™ ืื™ื ื˜ืขืจื ืขื˜ ื‘ืœื•ื™ื– ื“ื•ืจืš ISP1.
  3. ืฆื•ืฉื˜ืขืœืŸ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืžืึทืจืฉืจื•ื˜ ืคืึทืจืงืขืจ ืคื•ืŸ ื”ื™ื’ืข ื ืขื˜ื•ื•ืึธืจืงืก ืฆื• ื“ื™ ืื™ื ื˜ืขืจื ืขื˜ ื“ื•ืจืš ื“ื™ ืื•ื™ืกื’ืขืงืœื™ื‘ืŸ ืฉืคึผื™ื™ึทื–ืขืจ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ ืึทื“ืจืขืก ืจืฉื™ืžื”.
  4. ืฆื•ืฉื˜ืขืœืŸ ื“ื™ ืžืขื’ืœืขื›ืงื™ื™ื˜ ืคื•ืŸ ืืจื•ื™ืกื’ืขื‘ืŸ ื‘ืึทื“ื™ื ื•ื ื’ืก ืคึฟื•ืŸ ื“ื™ ื”ื™ื’ืข ื ืขืฅ ืฆื• ื“ืขืจ ืื™ื ื˜ืขืจื ืขืฅ (DSTNAT)
  5. ืฉื˜ืขืœืŸ ืึท ืคื™ื™ืจื•ื•ืึทืœ ืคื™ืœื˜ืขืจ ืฆื• ืฆื•ืฉื˜ืขืœืŸ ื“ื™ ืžื™ื ื™ืžื•ื ื’ืขื ื•ื’ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคื•ืŸ ื“ื™ ืื™ื ื˜ืขืจื ืขื˜.
  6. ื“ืขืจ ืจืึทื•ื˜ืขืจ ืงืขืŸ ืึทืจื•ื™ืกื’ืขื‘ืŸ ื–ื™ื™ืŸ ืื™ื™ื’ืขื ืข ืคืึทืจืงืขืจ ื“ื•ืจืš ืงื™ื™ืŸ ืคื•ืŸ ื“ื™ ื“ืจื™ื™ ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื–, ื“ื™ืคึผืขื ื“ื™ื ื’ ืื•ื™ืฃ ื“ื™ ืื•ื™ืกื“ืขืจื•ื•ื™ื™ืœื˜ืข ืžืงื•ืจ ืึทื“ืจืขืก.
  7. ืคืึทืจื–ื™ื›ืขืจืŸ ืึทื– ืขื ื˜ืคืขืจ ืคึผืึทืงื™ืฅ ื–ืขื ืขืŸ ืจืึทื•ื˜ื™ื“ ืฆื• ื“ืขื ืงืึทื ืึทืœ ืคื•ืŸ ื•ื•ืึธืก ื–ื™ื™ ื’ืขืงื•ืžืขืŸ (ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืœืึทืŸ).

ื‘ืึทืžืขืจืงื•ื ื’. ืžื™ืจ ื•ื•ืขืœืŸ ืงืึทื ืคื™ื’ื™ืขืจ ื“ื™ ืจืึทื•ื˜ืขืจ "ืคื•ืŸ ืงืจืึทืฆืŸ" ืื™ืŸ ืกื“ืจ ืฆื• ื’ืึทืจืึทื ื˜ื™ืจืŸ ื“ื™ ืึทื•ื•ืขืง ืคื•ืŸ ืกืึทืคึผืจื™ื™ื–ื™ื– ืื™ืŸ ื“ื™ ืกื˜ืึทืจื˜ื™ื ื’ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทื ื– "ืื•ื™ืก ื“ื™ ืงืขืกื˜ืœ" ื•ื•ืึธืก ื˜ื•ื™ืฉืŸ ืคื•ืŸ ื•ื•ืขืจืกื™ืข ืฆื• ื•ื•ืขืจืกื™ืข. ื•ื•ื™ื ื‘ืึธืงืก ืื™ื– ืื•ื™ืกื“ืขืจื•ื•ื™ื™ืœื˜ ื•ื•ื™ ืึท ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื’ืขืฆื™ื™ึทื’, ื•ื•ื• ืขื ื“ืขืจื•ื ื’ืขืŸ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื•ื•ื™ื–ืฉื•ื•ืึทืœื™ ื’ืขื•ื•ื™ื–ืŸ. ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก ื–ื™ืš ื•ื•ืขื˜ ื–ื™ื™ืŸ ื‘ืึทืฉื˜ื™ืžื˜ ื“ื•ืจืš ืงืึทืžืึทื ื“ื– ืื™ืŸ ื“ื™ ื•ื•ื™ื ื‘ืึธืงืก ื•ื•ืึธืงื–ืึทืœ. ื“ื™ ื’ืฉืžื™ื•ืช ืงืฉืจ ืคึฟืึทืจ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืื™ื– ื’ืขืžืื›ื˜ ื“ื•ืจืš ืึท ื“ื™ืจืขืงื˜ ืงืฉืจ ืฆื• ื“ื™ Ether5 ืฆื•ื‘ื™ื ื“.

ื ื‘ื™ืกืœ ืจื™ื–ืึทื ื™ื ื’ ื•ื•ืขื’ืŸ ื•ื•ืึธืก ืึท ืžื•ืœื˜ื™ื•ื•ืึทืŸ ืื™ื–, ืื™ื– ืขืก ืึท ืคึผืจืึธื‘ืœืขื ืึธื“ืขืจ ื–ืขื ืขืŸ ื›ื™ื˜ืจืข ืงืœื•ื’ ืžืขื ื˜ืฉืŸ ืึทืจื•ื ื•ื•ื™ื•ื•ื™ื ื’ ืงืึทื ืกืคึผื™ืจืึทืกื™ ื ืขื˜ื•ื•ืึธืจืงืก

ืึท ื ื™ื™ึทื’ืขืจื™ืง ืื•ืŸ ืึทื˜ืขื ื˜ื™ื•ื• ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ, ืฉื˜ืขืœืŸ ื–ื™ืš ืื•ื™ืฃ ื–ื™ืš ืึทื–ืึท ืึธื“ืขืจ ืขื ืœืขืš ืกื›ืขืžืข, ืคึผืœื•ืฆืœื™ื ื’ ืคืึทืจืฉื˜ื™ื™ืŸ ืึทื– ืขืก ืึทืจื‘ืขื˜ ืฉื•ื™ืŸ ื ืึธืจืžืึทืœื™. ื™ืึธ, ื™ืึธ, ืึธืŸ ื“ื™ื™ืŸ ืžื ื”ื’ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ ืื•ืŸ ืื ื“ืขืจืข ืžืึทืจืฉืจื•ื˜ ื›ึผืœืœื™ื, ื•ื•ืึธืก ืจื•ื‘ึฟ ืึทืจื˜ื™ืงืœืขืŸ ืื•ื™ืฃ ื“ืขื ื˜ืขืžืข ื–ืขื ืขืŸ ืคื•ืœ ืคื•ืŸ. ื–ืืœ ืก ื˜ืฉืขืง?

ืงืขื ืขืŸ ืžื™ืจ ืงืึทื ืคื™ื’ื™ืขืจ ืึทื“ืจืขืกื™ื ื’ ืื•ื™ืฃ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืื•ืŸ ืคืขืœื™ืงื™ื™ึทื˜ ื’ื™ื™ื˜ื•ื•ื™ื™ื–? ื™ื:

ืื•ื™ืฃ ISP1, ื“ื™ ืึทื“ืจืขืก ืื•ืŸ ื’ื™ื™ื˜ื•ื•ื™ื™ ื–ืขื ืขืŸ ืจืขื’ื™ืกื˜ืจื™ืจื˜ ืžื™ื˜ ื“ื™ืกื˜ืึทื ืกืข=2 ะธ ื˜ืฉืขืง-ื’ื™ื™ื˜ื•ื•ื™ื™ = ืคึผื™ื ื’.
ืื•ื™ืฃ ISP2, ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ DHCP ืงืœื™ืขื ื˜ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ - ืึทืงืึธืจื“ื™ื ื’ืœื™, ื“ื™ ื•ื•ื™ื™ึทื˜ืงื™ื™ื˜ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืœื™ื™ึทืš ืฆื• ืื™ื™ืŸ.
ืื•ื™ืฃ ISP3 ืื™ืŸ ื“ื™ pppoe ืงืœื™ืขื ื˜ ืกืขื˜ื˜ื™ื ื’ืก ื•ื•ืขืŸ add-default-route = ื™ืึธ ืฉื˜ืขืœืŸ default-route-distance=3.

ื“ื• ื–ืืœืกื˜ ื ื™ืฉื˜ ืคืึทืจื’ืขืกืŸ ืฆื• ืจืขื’ื™ืกื˜ืจื™ืจืŸ NAT ืื•ื™ืฃ ื“ื™ ืึทืจื•ื™ืกื’ืึทื ื’:

/ ื™ืคึผ ืคื™ื™ืจื•ื•ืึทืœ ื ืึทื˜ ืœื™ื™ื’ืŸ ืงืึทืžืฃ = ืžืึทืกืงืขืจื™ื™ื“ ืงื™ื™ื˜ = ืกืจืงื ืึทื˜ ืึธื•ื˜-interface-list = ื•ื•ืึทืŸ

ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜, ื ื™ืฆืขืจืก ืคื•ืŸ ื”ื™ื’ืข ื–ื™ื™ื˜ืœืขืš ื”ืึธื‘ืŸ ืฉืคึผืึทืก ื“ืึทื•ื ืœืึธื•ื“ื™ื ื’ ืงืึทืฅ ื“ื•ืจืš ื“ื™ ื”ื•ื™ืคึผื˜ ISP2 ืฉืคึผื™ื™ึทื–ืขืจ ืื•ืŸ ืขืก ืื™ื– ืึท ืงืึทื ืึทืœ ืจืขื–ืขืจื•ื•ืึทืฆื™ืข ืžื™ื˜ ื“ื™ ืžืขืงืึทื ื™ื–ืึทื. ื˜ืฉืขืง ื’ื™ื™ื˜ื•ื•ื™ื™ ื–ืขืŸ ื‘ืึทืžืขืจืงื•ื ื’ 1

ืคื•ื ื˜ 1 ืคื•ืŸ ื“ื™ ืึทืจื‘ืขื˜ ืื™ื– ื™ืžืคึผืœืึทืžืขื ืึทื“. ื•ื•ื• ืื™ื– ื“ืขืจ ืžื•ืœื˜ื™ื•ื•ืึทืŸ ืžื™ื˜ ื–ื™ื™ึทืŸ ืžืึทืจืงืก? ื ื™ื™ืŸโ€ฆ

ื•ื•ื™ื™ื˜ืขืจ. ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ื‘ืึทืคืจื™ื™ึทืขืŸ ืกืคึผืขืฆื™ืคื™ืฉ ืงืœื™ื™ืึทื ืฅ ืคึฟื•ืŸ ื“ื™ ืœืึทืŸ ื“ื•ืจืš ISP1:

/ ื™ืคึผ ืคื™ื™ืจื•ื•ืึทืœ ืžืึทื ื’ืœ ืœื™ื™ื’ืŸ ืงืึทืžืฃ = ืžืึทืจืฉืจื•ื˜ ืงื™ื™ื˜ = ืคึผืจืขืจืึธื•ื˜ื™ื ื’ ื“ืกื˜-ืึทื“ืจืขืก-ืœื™ืกื˜ =! BOGONS
passthrough=ื™ืึธ route-dst=100.66.66.1 src-address-list=Via_ISP1
/ ื™ืคึผ ืคื™ื™ืจื•ื•ืึทืœ ืžืึทื ื’ืœ ืœื™ื™ื’ืŸ ืงืึทืžืฃ = ืžืึทืจืฉืจื•ื˜ ืงื™ื™ื˜ = ืคึผืจืขืจืึธื•ื˜ื™ื ื’ ื“ืกื˜-ืึทื“ืจืขืก-ืœื™ืกื˜ =! BOGONS
passthrough=no route-dst=100.66.66.1 src-address=192.168.88.0/24

ื™ื™ื˜ืึทืžื– 2 ืื•ืŸ 3 ืคื•ืŸ ื“ื™ ืึทืจื‘ืขื˜ ื–ืขื ืขืŸ ื™ืžืคึผืœืึทืžืขื ืึทื“. ืœืึทื‘ืขืœืก, ืกื˜ืึทืžืคึผืก, ืžืึทืจืฉืจื•ื˜ ื›ึผืœืœื™ื, ื•ื•ื• ื‘ื™ืกื˜ ืื™ืจ?!

ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ื’ืขื‘ืŸ ืึทืงืกืขืก ืฆื• ื“ื™ื™ืŸ ื‘ืึทืœื™ื‘ืกื˜ืข OpenVPN ืกืขืจื•ื•ืขืจ ืžื™ื˜ ื“ื™ ืึทื“ืจืขืก 172.17.17.17 ืคึฟืึทืจ ืงืœื™ื™ืึทื ืฅ ืคึฟื•ืŸ ื“ืขืจ ืื™ื ื˜ืขืจื ืขืฅ? ื‘ื™ื˜ืข:

/ ื™ืคึผ ื•ื•ืึธืœืงืŸ ืฉื˜ืขืœืŸ ddns-enabled = ื™ืึธ

ื•ื•ื™ ืึท ื™ื™ึทื ืงื•ืงื , ืžื™ืจ ื’ืขื‘ืŸ ื“ืขื ืงืœื™ืขื ื˜ ื“ื™ ืจืขื–ื•ืœื˜ืึทื˜ ืจืขื–ื•ืœื˜ืึทื˜: ": ืฉื˜ืขืœืŸ [ื™ืคึผ ื•ื•ืึธืœืงืŸ ื‘ืึทืงื•ืžืขืŸ ื“ื ืก-ื ืึธืžืขืŸ]"

ืžื™ืจ ืจืขื’ื™ืกื˜ืจื™ืจืŸ ืคึผืึธืจื˜ ืคืึธืจื•ื•ืขืจื“ื™ื ื’ ืคื•ืŸ ื“ื™ ืื™ื ื˜ืขืจื ืขื˜:

/ ื™ืคึผ ืคื™ื™ืจื•ื•ืึทืœ ื ืึทื˜ ืœื™ื™ื’ืŸ ืงืึทืžืฃ = ื“ืกื˜-ื ืึทื˜ ืงื™ื™ื˜ = ื“ืกื˜ื ืึทื˜ ื“ืกื˜-ืคึผืึธืจื˜ = 1194
in-interface-list=WAN protocol=udp to-addresses=172.17.17.17

ื ื•ืžืขืจ 4 ืื™ื– ื’ืจื™ื™ื˜.

ืžื™ืจ ืฉื˜ืขืœืŸ ื–ื™ืš ืึท ืคื™ื™ืจื•ื•ืึทืœ ืื•ืŸ ืื ื“ืขืจืข ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึฟืึทืจ ืคื•ื ื˜ 5, ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜ ืžื™ืจ ื–ืขื ืขืŸ ืฆื•ืคืจื™ื“ืŸ ืึทื– ืึทืœืฅ ืื™ื– ืฉื•ื™ืŸ ืืจื‘ืขื˜ืŸ ืคึฟืึทืจ ื™ื•ื–ืขืจื– ืื•ืŸ ื“ืขืจื’ืจื™ื™ื›ืŸ ืึท ืงืึทื ื˜ื™ื™ื ืขืจ ืžื™ื˜ ืึท ื‘ืึทืœื™ื‘ืกื˜ืข ื˜ืจื™ื ืงืขืŸ ...
ื! ื˜ืึทื ืึทืœื– ื–ืขื ืขืŸ ืคืืจื’ืขืกืŸ.

l2tp-ืงืœื™ืขื ื˜, ืงืึทื ืคื™ื’ื™ืขืจื“ ื“ื•ืจืš Google ืึทืจื˜ื™ืงืœ, ืื™ื– ืื•ื™ืคื’ืขืฉื˜ืื ืขืŸ ืฆื• ื“ื™ื™ืŸ ื‘ืึทืœื™ื‘ืกื˜ืข ื”ืึธืœืขื ื“ื™ืฉ VDS? ื™ื.
l2tp-server ืžื™ื˜ IPsec ืื™ื– ืื•ื™ืคื’ืขืฉื˜ืื ืขืŸ ืื•ืŸ ืงืœื™ื™ืึทื ืฅ ื“ื•ืจืš ื“ื ืก-ื ืึธืžืขืŸ ืคึฟื•ืŸ IP ืงืœืึธื•ื“ (ื–ืขืŸ ืื•ื™ื‘ืŸ.) ืงืœื™ื ื’? ื™ื.
ืœื•ื™ื ื“ื ื“ื™ื’ ืฆื•ืจื™ืง ืื™ืŸ ืื•ื ื“ื–ืขืจ ืฉื˜ื•ืœ, ืกื™ืคึผื™ื ื’ ืึท ื˜ืจื™ื ืงืขืŸ, ืžื™ืจ ืคื•ื™ืœ ื‘ืึทื˜ืจืึทื›ื˜ืŸ ื“ื™ ืคื•ื ืงื˜ืŸ 6 ืื•ืŸ 7 ืคื•ืŸ ื“ื™ ืึทืจื‘ืขื˜. ืžื™ืจ ื˜ืจืึทื›ื˜ืŸ - ื˜ืึธืŸ ืžื™ืจ ื“ืึทืจืคึฟืŸ ืขืก? ืึทืœืข ื“ื™ ื–ืขืœื‘ืข, ืขืก ืึทืจื‘ืขื˜ ื•ื•ื™ ืึทื– (ื’) ... ืึทื–ื•ื™, ืื•ื™ื‘ ืขืก ืื™ื– ื ืึธืš ื ื™ื˜ ื“ืืจืฃ, ื“ืขืžืึธืœื˜ ืึทื– ืก ืขืก. ืžื•ืœื˜ื™ื•ื•ืึทืŸ ื™ืžืคึผืœืึทืžืขื ืึทื“.

ื•ื•ืึธืก ืื™ื– ืึท ืžื•ืœื˜ื™ื•ื•ืึทืŸ? ื“ืึธืก ืื™ื– ื“ื™ ืงืฉืจ ืคื•ืŸ ืขื˜ืœืขื›ืข ืื™ื ื˜ืขืจื ืขื˜ ื˜ืฉืึทื ืึทืœื– ืฆื• ืื™ื™ืŸ ืจืึทื•ื˜ืขืจ.

ืื™ืจ ื˜ืึธืŸ ื ื™ื˜ ื”ืึธื‘ืŸ ืฆื• ืœื™ื™ืขื ืขืŸ ื“ืขื ืึทืจื˜ื™ืงืœ ื•ื•ื™ื™ึทื˜ืขืจ, ื•ื•ื™ื™ึทืœ ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ืึธืจื˜ ืึทื—ื•ืฅ ืึท ื•ื•ื™ื™ึทื–ืŸ ืึทื•ื•ืขืง ืคื•ืŸ ืกืึธืคืขืงื“ื™ืง ืึธื ื•ื•ืขื ื“ืœืขืš?

ืคืืจ ื“ื™ ื•ื•ืืก ืคืืจื‘ืœื™ื™ื‘ืŸ, ื•ื•ืืก ื–ืขื ืขืŸ ืคืืจืื™ื ื˜ืขืจืขืกื™ืจื˜ ืื™ืŸ ื“ื™ ื ืงื•ื“ื•ืช 6 ืื•ืŸ 7 ืคื•ืŸ ื“ืขืจ ืื•ื™ืคื’ืื‘ืข, ืื•ืŸ ืื•ื™ืš ืคื™ืœืŸ ื“ืขื ื’ืขืจืขื˜ืขื ื™ืฉ ืคื•ืŸ ืคืขืจืคืขืงืฆื™ืื ืืœื™ื–ื, ื˜ื•ื ืงืขืŸ ืžื™ืจ ื˜ื™ืคืขืจ.

ื“ื™ ืžืขืจืกื˜ ื•ื•ื™ื›ื˜ื™ืง ืึทืจื‘ืขื˜ ืคื•ืŸ ื™ืžืคึผืœืึทืžืขื ื™ื ื’ ืึท ืžื•ืœื˜ื™ื•ื•ืึทืŸ ืื™ื– ื“ื™ ืจื™ื›ื˜ื™ืง ืคืึทืจืงืขืจ ืจื•ื˜ื™ื ื’. ื ื™ื™ืžืœื™: ืจืึทื’ืึทืจื“ืœืึทืก ืคื•ืŸ ื•ื•ืึธืก (ืึธื“ืขืจ ื•ื•ืึธืก) ื–ืขืŸ. ื‘ืึทืžืขืจืงื•ื ื’ 3 ื“ื™ ืงืึทื ืึทืœ (s) ืคื•ืŸ ื“ื™ ISP ืงื•ืง ืื™ืŸ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืžืึทืจืฉืจื•ื˜ ืื•ื™ืฃ ืื•ื ื“ื–ืขืจ ืจืึทื•ื˜ืขืจ, ืขืก ื–ืึธืœ ืฆื•ืจื™ืงืงื•ืžืขืŸ ืึท ืขื ื˜ืคืขืจ ืฆื• ื“ื™ ืคึผื™ื ื˜ืœืขืš ืงืึทื ืึทืœ ืคื•ืŸ ื“ื™ ืคึผืึทืงืึทื˜ ื’ืขืงื•ืžืขืŸ. ื“ื™ ืึทืจื‘ืขื˜ ืื™ื– ืงืœืึธืจ. ื•ื•ืื• ืื™ื– ื“ืขืจ ืคืจืื‘ืœืขื? ื˜ืึทืงืข, ืื™ืŸ ืึท ืคึผืฉื•ื˜ ื”ื™ื’ืข ื ืขืฅ, ื“ื™ ืึทืจื‘ืขื˜ ืื™ื– ื“ื™ ื–ืขืœื‘ืข, ืึธื‘ืขืจ ืงื™ื™ืŸ ืื™ื™ื ืขืจ ื‘ืึทื“ืขืจื– ืžื™ื˜ ื ืึธืš ืกืขื˜ื˜ื™ื ื’ืก ืื•ืŸ ื˜ื•ื˜ ื ื™ืฉื˜ ืคื™ืœืŸ ืงืึธื ืคืœื™ืงื˜. ื“ืขืจ ื—ื™ืœื•ืง ืื™ื– ืึทื– ืงื™ื™ืŸ ืจื•ื˜ืึทื‘ืึทืœ ื ืึธื“ืข ืื•ื™ืฃ ื“ืขืจ ืื™ื ื˜ืขืจื ืขืฅ ืื™ื– ืฆื•ื˜ืจื™ื˜ืœืขืš ื“ื•ืจืš ื™ืขื“ืขืจ ืคื•ืŸ ืื•ื ื“ื–ืขืจ ื˜ืฉืึทื ืึทืœื–, ืื•ืŸ ื ื™ืฉื˜ ื“ื•ืจืš ืึท ืฉื˜ืจืขื ื’ ืกืคึผืขืฆื™ืคื™ืฉ, ื•ื•ื™ ืื™ืŸ ืึท ืคึผืฉื•ื˜ ืœืึทืŸ. ืื•ืŸ ื“ื™ "ืฆืจื”" ืื™ื– ืึทื– ืื•ื™ื‘ ืขืก ืื™ื– ื’ืขืงื•ืžืขืŸ ืฆื• ืื•ื ื“ื– ืึท ื‘ืงืฉื” ืคึฟืึทืจ ื“ื™ IP ืึทื“ืจืขืก ืคื•ืŸ ISP3, ืื™ืŸ ืื•ื ื“ื–ืขืจ ืคืึทืœ, ื“ื™ ืขื ื˜ืคืขืจ ื•ื•ืขื˜ ื’ื™ื™ืŸ ื“ื•ืจืš ื“ื™ ISP2 ืงืึทื ืึทืœ, ื•ื•ื™ื™ึทืœ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ื’ื™ื™ื˜ื•ื•ื™ื™ ืื™ื– ื“ื™ืจืขืงื˜ืขื“ ื“ืึธืจื˜. ื‘ืœืขื˜ืขืจ ืื•ืŸ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื“ื™ืกืงืึทืจื“ื™ื“ ื“ื•ืจืš ื“ื™ ืฉืคึผื™ื™ึทื–ืขืจ ื•ื•ื™ ืคืึทืœืฉ. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื™ื™ื“ืขื ืึทืคื™ื™ื“. ื•ื•ื™ ืฆื• ืกืึธืœื•ื•ืข ืขืก?

ื“ื™ ืœื™ื™ื–ื•ื ื’ ืื™ื– ืฆืขื˜ื™ื™ืœื˜ ืื™ืŸ ื“ืจื™ื™ึท ืกื˜ืึทื’ืขืก:

  1. ืคึผืจื™ืกืขื˜ื˜ื™ื ื’. ืื™ืŸ ื“ืขื ื‘ื™ื ืข, ื“ื™ ื’ืจื•ื ื˜ ืกืขื˜ื˜ื™ื ื’ืก ืคื•ืŸ ื“ื™ ืจืึทื•ื˜ืขืจ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื‘ืึทืฉื˜ื™ืžื˜: ื”ื™ื’ืข ื ืขืฅ, ืคื™ื™ืจื•ื•ืึทืœ, ืึทื“ืจืขืก ืจืฉื™ืžื•ืช, ื”ืึทื™ืจืคึผื™ืŸ NAT, ืขื˜ืง.
  2. ืžื•ืœื˜ื™ื•ื•ืึทืŸ. ืื™ืŸ ื“ืขื ื‘ื™ื ืข, ื“ื™ ื ื™ื™ื˜ื™ืง ืงืึทื ืขืงืฉืึทื ื– ื•ื•ืขื˜ ื–ื™ื™ืŸ ืื ื’ืขืฆื™ื™ื›ื ื˜ ืื•ืŸ ืื•ื™ืกื’ืขืฉื˜ืขืœื˜ ืื™ืŸ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ.
  3. ืงืึทื ืขืงื˜ื™ื ื’ ืฆื• ืึทืŸ ISP. ืื™ืŸ ื“ืขื ื‘ื™ื ืข, ื“ื™ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ื•ื•ืึธืก ืฆื•ืฉื˜ืขืœืŸ ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ ืฆื• ื“ื™ ืื™ื ื˜ืขืจื ืขื˜ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืงืึทื ืคื™ื’ื™ืขืจื“, ืจื•ื˜ื™ื ื’ ืื•ืŸ ื“ื™ ืจืขื–ืขืจื•ื•ืึทืฆื™ืข ืžืขืงืึทื ื™ื–ืึทื ืคื•ืŸ ืื™ื ื˜ืขืจื ืขื˜ ืงืึทื ืึทืœ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืึทืงื˜ื™ื•ื•ื™ื™ื˜ื™ื“.

1. ืคึผืจื™ืกืขื˜ื˜ื™ื ื’

1.1. ืžื™ืจ ื•ื™ืกืžืขืงืŸ ื“ื™ ืจืึทื•ื˜ืขืจ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืžื™ื˜ ื“ืขื ื‘ืึทืคึฟืขืœ:

/system reset-configuration skip-backup=yes no-defaults=yes

ืžืกื›ื™ื ืžื™ื˜ "ื’ืขืคืขืจืœืขืš! ื‘ืึทืฉื˜ืขื˜ื™ืง ืกื™ื™ึท ื•ื•ื™ ืกื™ื™ึท? [ื™/ืขืŸ]:"ืื•ืŸ, ื ืึธืš ืจืขื‘ืึธืึธื˜ื™ื ื’, ืžื™ืจ ืคืึทืจื‘ื™ื ื“ืŸ ืžื™ื˜ Winbox ื“ื•ืจืš MAC. ืื™ืŸ ื“ืขื ื‘ื™ื ืข, ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืื•ืŸ ื‘ืึทื ื™ืฆืขืจ ื‘ืึทื–ืข ื–ืขื ืขืŸ ืงืœื™ืจื“.

1.2. ืฉืึทืคึฟืŸ ืึท ื ื™ื™ึทืข ื‘ืึทื ื™ืฆืขืจ:

/user add group=full name=knight password=ultrasecret comment=โ€Not horseโ€

ืงืœืึธืฅ ืื™ืŸ ืื•ื ื˜ืขืจ ืขืก ืื•ืŸ ื•ื™ืกืžืขืงืŸ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืื™ื™ื ืขืจ:

/user remove admin

ื‘ืึทืžืขืจืงื•ื ื’. ืขืก ืื™ื– ื“ื™ ื‘ืึทื–ื™ื™ึทื˜ื™ืงื•ื ื’ ืื•ืŸ ื ื™ื˜ ื“ื™ืกื™ื™ื‘ืึทืœื™ื ื’ ืคื•ืŸ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ื‘ืึทื ื™ืฆืขืจ ืึทื– ื“ืขืจ ืžื—ื‘ืจ ื”ืืœื˜ ืกืึทืคืขืจ ืื•ืŸ ืจืขืงืึทืžืขื ื“ื– ืคึฟืึทืจ ื ื•ืฆืŸ.

1.3. ืžื™ืจ ืžืึทื›ืŸ ื™ืงืขืจื“ื™ืง ืฆื•ื‘ื™ื ื“ ืจืฉื™ืžื•ืช ืคึฟืึทืจ ื“ื™ ืงืึทื ื•ื•ื™ื ื™ืึทื ืก ืคื•ืŸ ืึทืคึผืขืจื™ื™ื˜ื™ื ื’ ืื™ืŸ ืึท ืคื™ื™ืจื•ื•ืึทืœ, ื•ืคื“ืขืงื•ื ื’ ืกืขื˜ื˜ื™ื ื’ืก ืื•ืŸ ืื ื“ืขืจืข MAC ืกืขืจื•ื•ืขืจืก:

/interface list add name=WAN comment="For Internet"
/interface list add name=LAN comment="For Local Area"

ืกื™ื™ื ื™ื ื’ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืžื™ื˜ ื‘ืึทืžืขืจืงื•ื ื’ืขืŸ

/interface ethernet set ether1 comment="to ISP1"
/interface ethernet set ether2 comment="to ISP2"
/interface ethernet set ether3 comment="to ISP3"
/interface ethernet set ether4 comment="to LAN1"
/interface ethernet set ether5 comment="to LAN2"

ืื•ืŸ ืคึผืœืึธืžื‘ื™ืจืŸ ื“ื™ ืฆื•ื‘ื™ื ื“ ืจืฉื™ืžื•ืช:

/interface list member add interface=ether1 list=WAN comment=ISP1
/interface list member add interface=ether2 list=WAN comment=ISP2 
/interface list member add interface=ether3 list=WAN comment="to ISP3"
/interface list member add interface=ether4 list=LAN  comment="LAN1"
/interface list member add interface=ether5 list=LAN  comment="LAN2"

ื‘ืึทืžืขืจืงื•ื ื’. ืฉืจื™ื™ื‘ืŸ ืคืึทืจืฉื˜ื™ื™ื™ืง ื‘ืึทืžืขืจืงื•ื ื’ืขืŸ ืื™ื– ื•ื•ืขืจื˜ ื“ื™ ืฆื™ื™ื˜ ืคืืจื‘ืจืื›ื˜ ืื•ื™ืฃ ื“ืขื, ืคึผืœื•ืก ืขืก ืคืึทืกื™ืœืึทื˜ื™ื™ืฅ ื–ื™ื™ืขืจ ื˜ืจืึธื•ื‘ืœืขืฉืึธืึธื˜ื™ื ื’ ืื•ืŸ ืคืืจืฉื˜ืื ื“ ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ.

ื“ืขืจ ืžื—ื‘ืจ ื”ืืœื˜ ืขืก ื ื•ื™ื˜ื™ืง, ืคึฟืึทืจ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืกื™ื‘ื•ืช, ืฆื• ืœื™ื™ื’ืŸ ื“ื™ ether3 ืฆื•ื‘ื™ื ื“ ืฆื• ื“ื™ "WAN" ืฆื•ื‘ื™ื ื“ ืจืฉื™ืžื”, ื˜ืจืึธืฅ ื“ืขื ืคืึทืงื˜ ืึทื– ื“ื™ IP ืคึผืจืึธื˜ืึธืงืึธืœ ื•ื•ืขื˜ ื ื™ืฉื˜ ื“ื•ืจื›ื’ื™ื™ืŸ ืขืก.

ื“ื• ื–ืืœืกื˜ ื ื™ืฉื˜ ืคืึทืจื’ืขืกืŸ ืึทื– ื ืึธืš ื“ื™ PPP ืฆื•ื‘ื™ื ื“ ืื™ื– ืื•ื™ืคืฉื˜ื™ื™ืŸ ืื•ื™ืฃ ether3, ืขืก ื•ื•ืขื˜ ืื•ื™ืš ื–ื™ื™ืŸ ืžื•ืกื™ืฃ ืฆื• ื“ื™ ืฆื•ื‘ื™ื ื“ ืจืฉื™ืžื” "WAN"

1.4. ืžื™ืจ ื‘ืึทื”ืึทืœื˜ืŸ ื“ื™ ืจืึทื•ื˜ืขืจ ืคื•ืŸ ืงื•ื•ืึทืจื˜ืึทืœ ื“ื™ื˜ืขืงืฉืึทืŸ ืื•ืŸ ืงืึธื ื˜ืจืึธืœ ืคื•ืŸ ืฉืคึผื™ื™ึทื–ืขืจ ื ืขื˜ื•ื•ืึธืจืงืก ื“ื•ืจืš MAC:

/ip neighbor discovery-settings set discover-interface-list=!WAN
/tool mac-server set allowed-interface-list=LAN
/tool mac-server mac-winbox set allowed-interface-list=LAN

1.5. ืžื™ืจ ืžืึทื›ืŸ ื“ื™ ืžื™ื ื™ืžื•ื ื’ืขื ื•ื’ ื’ืึทื ื’ ืคื•ืŸ ืคื™ื™ืจื•ื•ืึทืœ ืคื™ืœื˜ืขืจ ื›ึผืœืœื™ื ืฆื• ื‘ืึทืฉื™ืฆืŸ ื“ื™ ืจืึทื•ื˜ืขืจ:

/ip firewall filter add action=accept chain=input comment="Related Established Untracked Allow" 
connection-state=established,related,untracked

(ื“ื™ ื”ืขืจืฉืŸ ื’ื™ื˜ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืคึฟืึทืจ ื’ืขื’ืจื™ื ื“ืขื˜ ืื•ืŸ ืคึฟืึทืจื‘ื•ื ื“ืขื ืข ืงืึทื ืขืงืฉืึทื ื– ื•ื•ืึธืก ื–ืขื ืขืŸ ื™ื ื™ืฉื™ื™ื™ื˜ื™ื“ ืคึฟื•ืŸ ื‘ื™ื™ื“ืข ืงืึธื ื ืขืงื˜ืขื“ ื ืขื˜ื•ื•ืึธืจืงืก ืื•ืŸ ื“ื™ ืจืึทื•ื˜ืขืจ ื–ื™ืš)

/ip firewall filter add action=accept chain=input comment="ICMP from ALL" protocol=icmp

(ืคึผื™ื ื’ ืื•ืŸ ื ื™ื˜ ื‘ืœื•ื™ื– ืคึผื™ื ื’. ื›ืœ icmp ืื™ื– ืขืจืœื•ื™ื‘ื˜ ืื™ืŸ. ื–ื™ื™ืขืจ ื ื•ืฆื™ืง ืคึฟืึทืจ ื“ืขืจื’ื™ื™ื•ื ื’ MTU ืคึผืจืึธื‘ืœืขืžืก)

/ip firewall filter add action=drop chain=input comment="All other WAN Drop" in-interface-list=WAN

(ื“ื™ ื”ืขืจืฉืŸ ื•ื•ืึธืก ืงืœืึธื•ื–ื™ื– ื“ื™ ืึทืจื™ื™ึทื ืฉืจื™ื™ึทื‘ ืงื™ื™ื˜ ืคืึทืจื•ื•ืขืจืŸ ืึทืœืฅ ืึทื ื“ืขืจืฉ ื•ื•ืึธืก ืงื•ืžื˜ ืคื•ืŸ ื“ื™ ืื™ื ื˜ืขืจื ืขื˜)

/ip firewall filter add action=accept chain=forward 
comment="Established, Related, Untracked allow" 
connection-state=established,related,untracked

(ื“ื™ ื”ืขืจืฉืŸ ืึทืœืึทื•ื– ื’ืขื’ืจื™ื ื“ืขื˜ ืื•ืŸ ืคึฟืึทืจื‘ื•ื ื“ืขื ืข ืงืึทื ืขืงืฉืึทื ื– ื•ื•ืึธืก ืคืึธืจืŸ ื“ื•ืจืš ื“ื™ ืจืึทื•ื˜ืขืจ)

/ip firewall filter add action=drop chain=forward comment="Invalid drop" connection-state=invalid

(ื“ื™ ื”ืขืจืฉืŸ ื‘ืึทืฉื˜ืขื˜ื™ืงื˜ ืงืึทื ืขืงืฉืึทื ื– ืžื™ื˜ ืงืึธื ื ืขืงืฆื™ืข-ืฉื˜ืึทื˜ = ืคืึทืจืงืจื™ืคึผืœื˜ ื“ื•ืจื›ืคืึธืจ ื“ื•ืจืš ื“ื™ ืจืึทื•ื˜ืขืจ. ืขืก ืื™ื– ืฉื˜ืืจืง ืจืขืงืึทืžืขื ื“ื™ื“ ื“ื•ืจืš ืžื™ืงืจืึธื˜ื™ืง, ืึธื‘ืขืจ ืื™ืŸ ืขื˜ืœืขื›ืข ื–ืขืœื˜ืŸ ืกื™ื˜ื•ืึทื˜ื™ืึธื ืก ืขืก ืงืขื ืขืŸ ืคืึทืจืฉืคึผืึทืจืŸ ื ื•ืฆื™ืง ืคืึทืจืงืขืจ)

/ip firewall filter add action=drop chain=forward comment="Drop all from WAN not DSTNATed"  
connection-nat-state=!dstnat connection-state=new in-interface-list=WAN

(ื“ื™ ื›ืœืœ ืคืืจื‘ืื˜ ืคืขืงืœืขืš ื•ื•ืืก ืงื•ืžืขืŸ ืคื•ืŸ ืื™ื ื˜ืขืจื ืขืฅ ืื•ืŸ ื”ืื‘ืŸ ื ื™ืฉื˜ ื“ื•ืจื›ื’ืขื’ืื ื’ืขืŸ ื“ืขื ื“ืกื˜ื ืื˜ ืคืจืืฆืขื“ื•ืจ ืฆื• ื“ื•ืจื›ื’ื™ื™ืŸ ื“ืขื ืจืื•ื˜ืขืจ. ื“ืืก ื•ื•ืขื˜ ื‘ืืฉื™ืฆืŸ ืœืืงืืœืข ื ืขื˜ื•ื•ืึธืจืงืก ืคื•ืŸ ืื™ื ื˜ืจื•ื“ืขืจืก ื•ื•ืขืœื›ืข, ื–ื™ื™ืขื ื“ื™ื’ ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ืขืจ ื‘ืจืึธื“ืงืึทืกื˜ ืคืขืœื“ ืžื™ื˜ ืื•ื ื–ืขืจืข ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืงืข ื ืขื˜ื•ื•ืึธืจืงืก, ื•ื•ืขืœืŸ ืจืขื“ื–ืฉื™ืกื˜ืจื™ืจืŸ ืื•ื ื–ืขืจืข ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืงืข IPืก ืืœืก ื ื. ื’ื™ื™ื˜ื•ื•ื™ื™ ืื•ืŸ, ืึทื–ื•ื™, ืคึผืจื•ื‘ื™ืจืŸ ืฆื• "ื•ื™ืกืคืึธืจืฉืŸ" ืื•ื ื“ื–ืขืจ ื”ื™ื’ืข ื ืขื˜ื•ื•ืึธืจืงืก.)

ื‘ืึทืžืขืจืงื•ื ื’. ืœืึธืžื™ืจ ื™ื‘ืขืจื ืขืžืขืŸ ืึทื– ื“ื™ ื ืขื˜ื•ื•ืึธืจืงืก LAN1 ืื•ืŸ LAN2 ื–ืขื ืขืŸ ื˜ืจืึทืกื˜ื™ื“ ืื•ืŸ ื“ื™ ืคืึทืจืงืขืจ ืฆื•ื•ื™ืฉืŸ ื–ื™ื™ ืื•ืŸ ืคึฟื•ืŸ ื–ื™ื™ ืื™ื– ื ื™ืฉื˜ ืคื™ืœื˜ืขืจื“.

1.6. ืฉืึทืคึฟืŸ ืึท ืจืฉื™ืžื” ืžื™ื˜ ืึท ืจืฉื™ืžื” ืคื•ืŸ ื ื™ื˜-ืจืึธื•ื˜ืึทื‘ืึทืœ ื ืขื˜ื•ื•ืึธืจืงืก:

/ip firewall address-list
add address=0.0.0.0/8 comment=""This" Network" list=BOGONS
add address=10.0.0.0/8 comment="Private-Use Networks" list=BOGONS
add address=100.64.0.0/10 comment="Shared Address Space. RFC 6598" list=BOGONS
add address=127.0.0.0/8 comment=Loopback list=BOGONS
add address=169.254.0.0/16 comment="Link Local" list=BOGONS
add address=172.16.0.0/12 comment="Private-Use Networks" list=BOGONS
add address=192.0.0.0/24 comment="IETF Protocol Assignments" list=BOGONS
add address=192.0.2.0/24 comment=TEST-NET-1 list=BOGONS
add address=192.168.0.0/16 comment="Private-Use Networks" list=BOGONS
add address=198.18.0.0/15 comment="Network Interconnect Device Benchmark Testing"
 list=BOGONS
add address=198.51.100.0/24 comment=TEST-NET-2 list=BOGONS
add address=203.0.113.0/24 comment=TEST-NET-3 list=BOGONS
add address=224.0.0.0/4 comment=Multicast list=BOGONS
add address=192.88.99.0/24 comment="6to4 Relay Anycast" list=BOGONS
add address=240.0.0.0/4 comment="Reserved for Future Use" list=BOGONS
add address=255.255.255.255 comment="Limited Broadcast" list=BOGONS

(ื“ืึธืก ืื™ื– ืึท ืจืฉื™ืžื” ืคื•ืŸ ืึทื“ืจืขืกืขืก ืื•ืŸ ื ืขื˜ื•ื•ืึธืจืงืก ื•ื•ืึธืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ืจืึธื•ื˜ืึทื‘ืึทืœ ืฆื• ื“ื™ ืื™ื ื˜ืขืจื ืขื˜ ืื•ืŸ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื ืื›ื’ืขื’ืื ื’ืขืŸ ืึทืงืึธืจื“ื™ื ื’ืœื™.)

ื‘ืึทืžืขืจืงื•ื ื’. ื“ื™ ืจืฉื™ืžื” ืื™ื– ืื•ื ื˜ืขืจื˜ืขื ื™ืง ืฆื• ื˜ื•ื™ืฉืŸ, ืึทื–ื•ื™ ืื™ืš ืจืขืงืึธืžืขื ื“ื™ืจืŸ ืื™ืจ ืฆื• ืคึผื™ืจื™ืึทื“ื™ืงืœื™ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืฉื™ื™ื›ื•ืช.

1.7. ื‘ืึทืฉื˜ืขื˜ื™ืง DNS ืคึฟืึทืจ ื“ื™ ืจืึทื•ื˜ืขืจ ื–ื™ืš:

/ip dns set servers=1.1.1.1,8.8.8.8

ื‘ืึทืžืขืจืงื•ื ื’. ืื™ืŸ ื“ื™ ืงืจืึทื ื˜ ื•ื•ืขืจืกื™ืข ืคื•ืŸ โ€‹โ€‹ROS, ื“ื™ื ืึทืžื™ืฉ ืกืขืจื•ื•ืขืจืก ื ืขืžืขืŸ ืคึผืจื™ื™ื“ืึทื ืก ืื™ื‘ืขืจ ืกื˜ืึทื˜ื™ืง ืึธื ืขืก. ื“ื™ ื ืึธืžืขืŸ ื”ืึทื›ืœืึธื˜ืข ื‘ืขื˜ืŸ ืื™ื– ื’ืขืฉื™ืงื˜ ืฆื• ื“ืขืจ ืขืจืฉื˜ืขืจ ืกืขืจื•ื•ืขืจ ืื™ืŸ ืกื“ืจ ืื™ืŸ ื“ืขืจ ืจืฉื™ืžื”. ื“ื™ ื™ื‘ืขืจื’ืึทื ื’ ืฆื• ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ืกืขืจื•ื•ืขืจ ืื™ื– ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ื•ื•ืขืŸ ื“ื™ ืงืจืึทื ื˜ ืื™ื– ืึทื ืึทื•ื•ื™ื™ืœืึทื‘ืึทืœ. ื“ื™ ืฆื™ื™ื˜ ืื™ื– ื’ืจื•ื™ืก - ืžืขืจ ื•ื•ื™ 5 ืกืขืงื•ื ื“ืขืก. ืฆื•ืจื™ืงืงื•ืžืขืŸ ืฆื•ืจื™ืง, ื•ื•ืขืŸ ื“ื™ "ื’ืขืคืืœืŸ ืกืขืจื•ื•ืขืจ" ืื™ื– ืจื™ื–ื•ืžื“, ื˜ื•ื˜ ื ื™ืฉื˜ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืคืึทืœืŸ. ื’ืขื’ืขื‘ืŸ ื“ืขื ืึทืœื’ืขืจื™ื“ืึทื ืื•ืŸ ื“ื™ ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ืึท ืžื•ืœื˜ื™ื•ื•ืึทืŸ, ื“ืขืจ ืžื—ื‘ืจ ืจืขืงืึทืžืขื ื“ื– ื ื™ืฉื˜ ืฆื• ื ื•ืฆืŸ ืกืขืจื•ื•ืขืจืก ืฆื•ื’ืขืฉื˜ืขืœื˜ ื“ื•ืจืš ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื–.

1.8. ืฉื˜ืขืœืŸ ืึทืจื•ื™ืฃ ืึท ื”ื™ื’ืข ื ืขืฅ.
1.8.1. ืžื™ืจ ืงืึทื ืคื™ื’ื™ืขืจ ืกื˜ืึทื˜ื™ืง IP ืึทื“ืจืขืกืขืก ืื•ื™ืฃ ืœืึทืŸ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–:

/ip address add interface=ether4 address=192.168.88.254/24 comment="LAN1 IP"
/ip address add interface=ether5 address=172.16.1.0/23 comment="LAN2 IP"

1.8.2. ืžื™ืจ ืฉื˜ืขืœืŸ ื“ื™ ื›ึผืœืœื™ื ืคึฟืึทืจ ืจื•ืฅ ืฆื• ืื•ื ื“ื–ืขืจ ื”ื™ื’ืข ื ืขื˜ื•ื•ืึธืจืงืก ื“ื•ืจืš ื“ื™ ื”ื•ื™ืคึผื˜ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ:

/ip route rule add dst-address=192.168.88.0/24 table=main comment=โ€to LAN1โ€
/ip route rule add dst-address=172.16.0.0/23 table=main comment="to LAN2"

ื‘ืึทืžืขืจืงื•ื ื’. ื“ืึธืก ืื™ื– ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืฉื ืขืœ ืื•ืŸ ื’ืจื™ื ื’ ื•ื•ืขื’ืŸ ืฆื• ืึทืงืกืขืก ืœืึทืŸ ืึทื“ืจืขืกืขืก ืžื™ื˜ ืงื•ื•ืืœืŸ ืคื•ืŸ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง IP ืึทื“ืจืขืกืขืก ืคื•ืŸ ืจืึทื•ื˜ืขืจ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ื•ื•ืึธืก ื˜ืึธืŸ ื ื™ื˜ ื’ื™ื™ืŸ ื“ื•ืจืš ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืžืึทืจืฉืจื•ื˜.

1.8.3. ื’ืขื‘ืŸ ื”ืึทื™ืจืคึผื™ืŸ NAT ืคึฟืึทืจ LAN1 ืื•ืŸ LAN2:

/ip firewall nat add action=src-nat chain=srcnat comment="Hairpin to LAN1" 
out-interface=ether4 src-address=192.168.88.0/24 to-addresses=192.168.88.254
/ip firewall nat add action=src-nat chain=srcnat comment="Hairpin to LAN2" 
out-interface=ether5 src-address=172.16.0.0/23 to-addresses=172.16.1.0

ื‘ืึทืžืขืจืงื•ื ื’. ื“ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืึทืงืกืขืก ื“ื™ื™ืŸ ืจืขืกื•ืจืกืŸ (ื“ืกื˜ื ืึทื˜) ื“ื•ืจืš ืึท ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง IP ื‘ืฉืขืช ืื™ืจ ื–ืขื ื˜ ืื™ืŸ ื“ื™ ื ืขืฅ.

2. ืึทืงื˜ื•ืึทืœืœื™, ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ื–ื™ื™ืขืจ ืจื™ื›ื˜ื™ืง ืžื•ืœื˜ื™ื•ื•ืึทืŸ

ืฆื• ืกืึธืœื•ื•ืข ื“ื™ ืคึผืจืึธื‘ืœืขื ืคื•ืŸ "ืขื ื˜ืคืขืจืŸ ืคื•ืŸ ื•ื•ื• ื–ื™ื™ ื’ืขืคืจืขื’ื˜", ืžื™ืจ ื•ื•ืขืœืŸ ื ื•ืฆืŸ ืฆื•ื•ื™ื™ ROS ืžื›ืฉื™ืจื™ื: ืงืฉืจ ืฆื™ื™ื›ืŸ ะธ ืจื•ื˜ื™ื ื’ ืฆื™ื™ื›ืŸ. ืงืฉืจ ืฆื™ื™ื›ืŸ ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืฆื™ื™ื›ืŸ ื“ื™ ื’ืขื‘ืขื˜ืŸ ืงืฉืจ ืื•ืŸ ืึทืจื‘ืขื˜ ืžื™ื˜ ื“ืขื ืคื™ืจืžืข ื•ื•ื™ ืึท ืฆื•ืฉื˜ืึทื ื“ ืคึฟืึทืจ ืึทืคึผืœื™ื™ื™ื ื’ ืจื•ื˜ื™ื ื’ ืฆื™ื™ื›ืŸ. ืื•ืŸ ืฉื•ื™ืŸ ืžื™ื˜ ืจื•ื˜ื™ื ื’ ืฆื™ื™ื›ืŸ ืžืขื’ืœืขืš ืฆื• ืึทืจื‘ืขื˜ืŸ ืื™ืŸ IP ืžืึทืจืฉืจื•ื˜ ะธ ืžืึทืจืฉืจื•ื˜ ื›ึผืœืœื™ื. ืžื™ืจ ืคื™ื’ื™ืขืจื“ ืื•ื™ืก ื“ื™ ืžื›ืฉื™ืจื™ื, ืื™ืฆื˜ ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ื‘ืึทืฉืœื™ืกืŸ ื•ื•ืึธืก ืงืึทื ืขืงืฉืึทื ื– ืฆื• ืฆื™ื™ื›ืŸ - ืึทืžืึธืœ, ืคึผื•ื ืงื˜ ื•ื•ื• ืฆื• ืฆื™ื™ื›ืŸ - ืฆื•ื•ื™ื™.

ืžื™ื˜ ื“ืขืจ ืขืจืฉื˜ืขืจ, ืึทืœืฅ ืื™ื– ืคึผืฉื•ื˜ - ืžื™ืจ ืžื•ื–ืŸ ืฆื™ื™ื›ืŸ ืึทืœืข ื“ื™ ืงืึทื ืขืงืฉืึทื ื– ื•ื•ืึธืก ืงื•ืžืขืŸ ืฆื• ื“ื™ ืจืึทื•ื˜ืขืจ ืคึฟื•ืŸ ื“ื™ ืื™ื ื˜ืขืจื ืขื˜ ื“ื•ืจืš ื“ื™ ืฆื•ื ืขืžืขืŸ ืงืึทื ืึทืœ. ืื™ืŸ ืื•ื ื“ื–ืขืจ ืคืึทืœ, ื“ืึธืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ื“ืจื™ื™ ืœืึทื‘ืขืœืก (ื“ื•ืจืš ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ื˜ืฉืึทื ืึทืœื–): "conn_isp1", "conn_isp2" ืื•ืŸ "conn_isp3".

ื“ื™ ื ื•ืึทื ืก ืžื™ื˜ ื“ื™ ืจื’ืข ืื™ื– ืึทื– ื™ื ืงืึทืžื™ื ื’ ืงืึทื ืขืงืฉืึทื ื– ื•ื•ืขื˜ ื–ื™ื™ืŸ ืคื•ืŸ ืฆื•ื•ื™ื™ ื˜ื™ื™ืคึผืก: ื“ื•ืจื›ืคืึธืจ ืื•ืŸ ื™ืขื ืข ื•ื•ืึธืก ื–ืขื ืขืŸ ื‘ื“ืขื” ืคึฟืึทืจ ื“ื™ ืจืึทื•ื˜ืขืจ ื–ื™ืš. ื“ื™ ืžืขืงืึทื ื™ื–ืึทื ืคื•ืŸ ืงืฉืจ ืฆื™ื™ื›ืŸ ืึทืจื‘ืขื˜ ืื™ืŸ ื“ื™ ื˜ื™ืฉ ืคืึทืจืงืœืขื ืขืจืŸ. ื‘ืึทื˜ืจืึทื›ื˜ืŸ ื“ื™ ื‘ืึทื•ื•ืขื’ื•ื ื’ ืคื•ืŸ ื“ืขื ืคึผืขืงืœ ืื•ื™ืฃ ืึท ืกื™ืžืคึผืœืึทืคื™ื™ื“ ื“ื™ืึทื’ืจืึทืžืข, ืœื™ื‘ ืงืึทืžืคึผื™ื™ืœื“ ื“ื•ืจืš ื“ื™ ืกืคึผืขืฉืึทืœืึทืกืฅ ืคื•ืŸ ื“ื™ ืžื™ืงืจืึธtik-trainings.com ืžื™ื˜ืœ (ื ื™ื˜ ื’ืึทื ืฆืข):

ืžื•ืœื˜ื™ื•ื•ืึทืŸ ืื•ืŸ ืจื•ื˜ื™ื ื’ ืื•ื™ืฃ Mikrotik RouterOS

ื ืึธืš ื“ื™ ืึทืจืึธื•ื–, ืžื™ืจ ื–ืขืŸ ืึทื– ื“ื™ ืคึผืึทืงืึทื˜ ืงื•ืžื˜ ืฆื• "ืึทืจื™ื™ึทื ืฉืจื™ื™ึทื‘ ืฆื•ื‘ื™ื ื“", ื’ื™ื™ื˜ ื“ื•ืจืš ื“ื™ ืงื™ื™ื˜ "ืคึผืจืขืจืึธื•ื˜ื™ื ื’" ืื•ืŸ ื‘ืœื•ื™ื– ื“ืขืžืึธืœื˜ ืื™ื– ืฆืขื˜ื™ื™ืœื˜ ืื™ืŸ ื“ื•ืจื›ืคืึธืจ ืื•ืŸ ื”ื™ื’ืข ืื™ืŸ ื“ื™ ื‘ืœืึธืง "ืจื•ื˜ื™ื ื’ ื‘ืึทืฉืœื•ืก". ื“ืขืจื™ื‘ืขืจ, ืฆื• ื˜ื™ื™ื˜ืŸ ืฆื•ื•ื™ื™ ืคื™ื™ื’ืœ ืžื™ื˜ ืื™ื™ืŸ ืฉื˜ื™ื™ืŸ, ืžื™ืจ ื ื•ืฆืŸ ืงืฉืจ ืžืืจืง ืื™ืŸ ื“ื™ ื˜ื™ืฉ ืžืึทื ื’ืœ ืคึผืจื™ืจืึธื•ื˜ื™ื ื’ ืงื™ื™ื˜ืŸ ืคึผืจืขืจืึธื•ื˜ื™ื ื’.

ื‘ืึทืžืขืจืงื•ื ื’:. ืื™ืŸ ืจืึธืก, "ืจืึธื•ื˜ื™ื ื’ ืžืืจืง" ืœืึทื‘ืขืœืก ื–ืขื ืขืŸ ืœื™ืกื˜ืขื“ ื•ื•ื™ "ื˜ื™ืฉ" ืื™ืŸ ื“ื™ ื™ืคึผ / ืจืึธื•ื˜ืขืก / ืจื•ืœืขืก ืึธืคึผื˜ื™ื™ืœื•ื ื’, ืื•ืŸ ื•ื•ื™ "ืจืึธื•ื˜ื™ื ื’ ืžืืจืง" ืื™ืŸ ืื ื“ืขืจืข ืกืขืงืฉืึทื ื–. ื“ืึธืก ืงืขืŸ ืคืึธืจืฉื˜ืขืœืŸ ืขื˜ืœืขื›ืข ืฆืขืžื™ืฉื•ื ื’ ืื™ืŸ ืคืืจืฉื˜ืื ื“, ืึธื‘ืขืจ, ืื™ืŸ ืคืึทืงื˜, ื“ืึธืก ืื™ื– ื“ื™ ื–ืขืœื‘ืข ื–ืึทืš ืื•ืŸ ืื™ื– ืึทืŸ ืึทื ืึทืœืึธื’ ืคื•ืŸ rt_tables ืื™ืŸ iproute2 ืื•ื™ืฃ ืœื™ื ื•ืงืก.

2.1. ืžื™ืจ ืฆื™ื™ื›ืŸ ื™ื ืงืึทืžื™ื ื’ ืงืึทื ืขืงืฉืึทื ื– ืคื•ืŸ ื™ืขื“ืขืจ ืคื•ืŸ ื“ื™ ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื–:

/ip firewall mangle add action=mark-connection chain=prerouting 
comment="Connmark in from ISP1" connection-mark=no-mark in-interface=ether1  new-connection-mark=conn_isp1 passthrough=no

/ip firewall mangle add action=mark-connection chain=prerouting 
comment="Connmark in from ISP2" connection-mark=no-mark in-interface=ether2  new-connection-mark=conn_isp2 passthrough=no

/ip firewall mangle add action=mark-connection chain=prerouting 
comment="Connmark in from ISP3" connection-mark=no-mark in-interface=pppoe-isp3  new-connection-mark=conn_isp3 passthrough=no

ื‘ืึทืžืขืจืงื•ื ื’. ื›ื“ื™ ื ื™ืฉื˜ ืฆื• ืžืืจืงื™ืจืŸ ืฉื•ื™ืŸ ืื ื’ืขืฆื™ื™ื›ื ื˜ืข ืคืืจื‘ื™ื ื“ื•ื ื’ืขืŸ, ื ื•ืฆื˜ ืื™ืš ื“ืขื ืงืฉืจ-ืžืืจืง=ืงื™ื™ืŸ-ืžืืจืง ืฆื•ืฉื˜ืึทื ื“ ืื ืฉื˜ืื˜ ืงืฉืจ-ืฉื˜ืื˜=ื ื™ื™ึท ื•ื•ื™ื™ืœ ืื™ืš ืžื™ื™ืŸ ืื– ื“ืืก ืื™ื– ืžืขืจ ืจื™ื›ื˜ื™ื’, ื•ื•ื™ ืื•ื™ืš ื“ื™ ืืคื•ื•ืืจื’ ืคื•ืŸ ืคืืœืŸ ืื•ืžื’ื™ืœื˜ื™ื’ืข ืคืืจื‘ื™ื ื“ื•ื ื’ืขืŸ ืื™ืŸ ื“ืขื ืื™ื™ื ืคืœื•ืก ืคื™ืœื˜ืขืจ.


passthrough=no - ื•ื•ื™ื™ึทืœ ืื™ืŸ ื“ืขื ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืื•ืคึฟืŸ, ืฉื™ื™ึทืขืš-ืžืึทืจืงื™ื ื’ ืื™ื– ื™ืงืกืงืœื•ื“ื™ื“ ืื•ืŸ, ืฆื• ืคืึทืจื’ื™ื›ืขืจืŸ, ืื™ืจ ืงืขื ืขืŸ ื™ื‘ืขืจืจื™ื™ึทืกืŸ ื“ื™ ื™ื ื•ืžืขืจื™ื™ืฉืึทืŸ ืคื•ืŸ ื›ึผืœืœื™ื ื ืึธืš ื“ืขืจ ืขืจืฉื˜ืขืจ ื’ืœื™ื™ึทื›ืŸ.

ืขืก ื–ืึธืœ ื–ื™ื™ืŸ ื’ืขื˜ืจืื’ืŸ ืื™ืŸ ื–ื™ื ืขืŸ ืึทื– ืžื™ืจ ื˜ืึธืŸ ื ื™ื˜ ืึทืจื™ื™ึทื ืžื™ืฉื  ื–ื™ืš ืื™ืŸ ืงื™ื™ืŸ ื•ื•ืขื’ ืžื™ื˜ ืจื•ื˜ื™ื ื’ ื ืึธืš. ืื™ืฆื˜ ืขืก ื–ืขื ืขืŸ ื‘ืœื•ื™ื– ืกื˜ืึทื’ืขืก ืคื•ืŸ ืฆื•ื’ืจื™ื™ื˜ื•ื ื’. ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ื‘ื™ื ืข ืคื•ืŸ โ€‹โ€‹ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื“ื™ ืคึผืจืึทืกืขืกื™ื ื’ ืคื•ืŸ ื“ื•ืจื›ืคืึธืจ ืคืึทืจืงืขืจ ื•ื•ืึธืก ืงืขืจื˜ ืื™ื‘ืขืจ ื“ื™ ื’ืขื’ืจื™ื ื“ืขื˜ ืงืฉืจ ืคื•ืŸ ื“ื™ ื“ืขืกื˜ื™ื ื™ื™ืฉืึทืŸ ืื™ืŸ ื“ื™ ื”ื™ื’ืข ื ืขืฅ. ื™ืขื ืข. ื“ื™ ืคึผืึทืงื™ืฅ ื•ื•ืึธืก (ื–ืขืŸ ื“ื™ ื“ื™ืึทื’ืจืึทืžืข) ื“ื•ืจื›ื’ืขื’ืื ื’ืขืŸ ื“ื•ืจืš ื“ื™ ืจืึทื•ื˜ืขืจ ืฆื•ื–ืืžืขืŸ ื“ืขื ื•ื•ืขื’:

"ื™ื ืคึผื•ื˜ ืฆื•ื‘ื™ื ื“"=>"ืคึผืจืขืจืึธื•ื˜ื™ื ื’"=>"ืจื•ื˜ื™ื ื’ ื‘ืึทืฉืœื•ืก"=>"ืคืึธืจื•ื•ืขืจื˜ืก"=>"ืคึผืึธืกื˜ ืจื•ื˜ื™ื ื’"=>"ืจืขื–ื•ืœื˜ืึทื˜ ืฆื•ื‘ื™ื ื“" ืื•ืŸ ื’ืึทื˜ ืฆื• ื–ื™ื™ืขืจ ืึทื“ืจืขืกื™ ืื™ืŸ ื“ื™ ื”ื™ื’ืข ื ืขืฅ.

ื•ื•ื™ื›ื˜ื™ืง! ืื™ืŸ ROS, ืขืก ืื™ื– ืงื™ื™ืŸ ืœืึทื“ื–ืฉื™ืงืึทืœ ืึธืคึผื˜ื™ื™ืœ ืื™ืŸ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืื•ืŸ ื™ื ืขืจืœืขืš ื™ื ื˜ืขืจืคื™ื™ืกื™ื–. ืื•ื™ื‘ ืžื™ืจ ืฉืคึผื•ืจ ื“ื™ ื•ื•ืขื’ ืคื•ืŸ ื“ื™ ืขื ื˜ืคืขืจ ืคึผืึทืงืึทื˜ ืœื•ื™ื˜ ื“ื™ ืื•ื™ื‘ืŸ ื“ื™ืึทื’ืจืึทืžืข, ืขืก ื•ื•ืขื˜ ื ืึธื›ืคืึธืœื’ืŸ ื“ื™ ื–ืขืœื‘ืข ืœืึทื“ื–ืฉื™ืงืึทืœ ื•ื•ืขื’ ื•ื•ื™ ื“ื™ ื‘ืขื˜ืŸ:

"ื™ื ืคึผื•ื˜ ืฆื•ื‘ื™ื ื“"=>"ืคึผืจืขืจืึธื•ื˜ื™ื ื’"=>"ืจื•ื˜ื™ื ื’ ื‘ืึทืฉืœื•ืก"=>"ืคืึธืจื•ื•ืขืจื˜ืก"=>"ืคึผืึธืกื˜ ืจื•ื˜ื™ื ื’"=>"ืจืขื–ื•ืœื˜ืึทื˜ ืฆื•ื‘ื™ื ื“" ื ืึธืจ ืคึฟืึทืจ ืึท ื‘ืงืฉื”"ื™ื ืคึผื•ื˜ ืฆื•ื‘ื™ื ื“"ืื™ื– ื’ืขื•ื•ืขืŸ ื“ื™ ื™ืกืคึผ ืฆื•ื‘ื™ื ื“, ืื•ืŸ ืคึฟืึทืจ ื“ื™ ืขื ื˜ืคืขืจ - ืœืึทืŸ

2.2. ืžื™ืจ ืึธื ื•ื•ื™ื™ึทื–ืŸ ื“ื™ ื“ื•ืจื›ืคืึธืจ ืคืึทืจืงืขืจ ืฆื• ื“ื™ ืงืึธืจืึทืกืคึผืึทื ื“ื™ื ื’ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ:

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Routemark transit out via ISP1" connection-mark=conn_isp1 
dst-address-type=!local in-interface-list=!WAN new-routing-mark=to_isp1 passthrough=no

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Routemark transit out via ISP2" connection-mark=conn_isp2 
dst-address-type=!local in-interface-list=!WAN new-routing-mark=to_isp2 passthrough=no

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Routemark transit out via ISP3" connection-mark=conn_isp3 
dst-address-type=!local in-interface-list=!WAN new-routing-mark=to_isp3 passthrough=no

ื‘ืึทืžืขืจืงื•ื ื’. in-interface-list=!WAN - ืžื™ืจ ืึทืจื‘ืขื˜ืŸ ื‘ืœื•ื™ื– ืžื™ื˜ ืคืึทืจืงืขืจ ืคื•ืŸ ื“ื™ ื”ื™ื’ืข ื ืขืฅ ืื•ืŸ dst-address-type=!local ื•ื•ืึธืก ื˜ื•ื˜ ื ื™ืฉื˜ ื”ืึธื‘ืŸ ื“ื™ ื“ืขืกื˜ื™ื ื™ื™ืฉืึทืŸ ืึทื“ืจืขืก ืคื•ืŸ ื“ื™ ืึทื“ืจืขืก ืคื•ืŸ ื“ื™ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืคื•ืŸ ื“ื™ ืจืึทื•ื˜ืขืจ ื–ื™ืš.

ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืคึฟืึทืจ ื”ื™ื’ืข ืคึผืึทืงื™ืฅ ื•ื•ืึธืก ื–ืขื ืขืŸ ื’ืขืงื•ืžืขืŸ ืฆื• ื“ื™ ืจืึทื•ื˜ืขืจ ืฆื•ื–ืืžืขืŸ ื“ืขื ื•ื•ืขื’:

"ื™ื ืคึผื•ื˜ ืฆื•ื‘ื™ื ื“"=>"ืคึผืจืขืจืึธื•ื˜ื™ื ื’"=>"ืจื•ื˜ื™ื ื’ ื‘ืึทืฉืœื•ืก"=>"ืื™ื ืคึผื•ื˜"=>"ืœืืงืืœืข ืคึผืจืึธืฆืขืก"

ื•ื•ื™ื›ื˜ื™ืง! ื“ืขืจ ืขื ื˜ืคืขืจ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืื™ืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ื•ื•ืขื’:

โ€ืœืืงืืœืข ืคืจืืกืขืกโ€=>โ€ืจื•ื˜ื™ื ื’ ื‘ืืฉืœื•ืกโ€=>โ€ืื•ื™ืกืฆื•ื’โ€=>โ€ืคึผืึธืกื˜ ืจื•ื˜ื™ื ื’โ€=>โ€ืจืขื–ื•ืœื˜ืึทื˜ ืฆื•ื‘ื™ื ื“โ€

2.3. ืžื™ืจ ืึธื ื•ื•ื™ื™ึทื–ืŸ ื“ื™ ื”ื™ื’ืข ืคืึทืจืงืขืจ ืฆื• ื“ื™ ืงืึธืจืึทืกืคึผืึทื ื“ื™ื ื’ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ:

/ip firewall mangle add action=mark-routing chain=output 
comment="Routemark local out via ISP1" connection-mark=conn_isp1 dst-address-type=!local 
new-routing-mark=to_isp1 passthrough=no

/ip firewall mangle add action=mark-routing chain=output 
comment="Routemark local out via ISP2" connection-mark=conn_isp2 dst-address-type=!local 
new-routing-mark=to_isp2 passthrough=no

/ip firewall mangle add action=mark-routing chain=output 
comment="Routemark local out via ISP3" connection-mark=conn_isp3 dst-address-type=!local 
new-routing-mark=to_isp3 passthrough=no

ืื™ืŸ ื“ืขื ื‘ื™ื ืข, ื“ื™ ืึทืจื‘ืขื˜ ืคื•ืŸ ืคึผืจื™ืคึผืขืจื™ื ื’ ืฆื• ืฉื™ืงืŸ ืึทืŸ ืขื ื˜ืคืขืจ ืฆื• ื“ื™ ืื™ื ื˜ืขืจื ืขื˜ ืงืึทื ืึทืœ ืคื•ืŸ ื•ื•ืึธืก ื“ื™ ื‘ืงืฉื” ืื™ื– ื’ืขืงื•ืžืขืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื”ืืœื˜ืŸ ืกืึทืœื•ื•ื“. ืึทืœืฅ ืื™ื– ืื ื’ืขืฆื™ื™ื›ื ื˜, ืœื™ื™ื‘ืึทืœื“ ืื•ืŸ ื’ืจื™ื™ื˜ ืฆื• ื–ื™ื™ืŸ ืจืึทื•ื˜ื™ื“.
ืึท ื•ื™ืกื’ืขืฆื™ื™ื›ื ื˜ "ื–ื™ื™ึทื˜" ื•ื•ื™ืจืงื•ื ื’ ืคื•ืŸ ื“ืขื ืกืขื˜ืึทืคึผ ืื™ื– ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืึทืจื‘ืขื˜ืŸ ืžื™ื˜ DSNAT ืคึผืึธืจื˜ ืคืึธืจื•ื•ืขืจื“ื™ื ื’ ืคื•ืŸ ื‘ื™ื™ื“ืข (ISP2, ISP3) ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื– ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜. ื‘ื›ืœืœ ื ื™ืฉื˜, ื•ื•ื™ื™ึทืœ ืื•ื™ืฃ ISP1 ืžื™ืจ ื”ืึธื‘ืŸ ืึท ื ื™ื˜-ืจืึธื•ื˜ืึทื‘ืึทืœ ืึทื“ืจืขืก. ื“ืขืจ ื•ื•ื™ืจืงื•ื ื’ ืื™ื– ื•ื•ื™ื›ื˜ื™ืง, ืœืžืฉืœ, ืคึฟืึทืจ ืึท ืคึผืึธืกื˜ ืกืขืจื•ื•ืขืจ ืžื™ื˜ ืฆื•ื•ื™ื™ ืžืงืก ื•ื•ืึธืก ืงื•ืง ืื™ืŸ ืคืึทืจืฉื™ื“ืขื ืข ืื™ื ื˜ืขืจื ืขื˜ ื˜ืฉืึทื ืึทืœื–.

ืฆื• ืขืœื™ืžื™ื ื™ืจืŸ ื“ื™ ื ื•ืึทื ืกื™ื– ืคื•ืŸ ื“ื™ ืึธืคึผืขืจืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื”ื™ื’ืข ื ืขื˜ื•ื•ืึธืจืงืก ืžื™ื˜ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง IP ืจืึธื•ื˜ืขืจืก, ืžื™ืจ ื ื•ืฆืŸ ื“ื™ ืกืึทืœื•ืฉืึทื ื– ืคื•ืŸ ืคึผืึทืจืึทื’ืจืึทืคืก. 1.8.2 ืื•ืŸ 3.1.2.6.

ืื™ืŸ ืึทื“ื™ืฉืึทืŸ, ืื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ืึท ื’ืขืฆื™ื™ึทื’ ืžื™ื˜ ืžืึทืจืงื™ื ื’ื– ืฆื• ืกืึธืœื•ื•ืข ืคึผืึทืจืึทื’ืจืึทืฃ 3 ืคื•ืŸ ื“ื™ ืคึผืจืึธื‘ืœืขื. ืžื™ืจ ื™ื ืกื˜ืจื•ืžืขื ื˜ ืขืก ื•ื•ื™ ื“ืึธืก:

2.4. ืžื™ืจ ืคื™ืจืŸ ืคืึทืจืงืขืจ ืคื•ืŸ ื”ื™ื’ืข ืงืœื™ื™ืึทื ืฅ ืคึฟื•ืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ืจืฉื™ืžื•ืช ืฆื• ื“ื™ ืฆื•ื ืขืžืขืŸ ื˜ื™ืฉืŸ:

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Address List via ISP1" dst-address-list=!BOGONS new-routing-mark=to_isp1 
passthrough=no src-address-list=Via_ISP1

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Address List via ISP2" dst-address-list=!BOGONS new-routing-mark=to_isp2 
passthrough=no src-address-list=Via_ISP2

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Address List via ISP3" dst-address-list=!BOGONS new-routing-mark=to_isp3 
passthrough=no src-address-list=Via_ISP3

ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜, ืขืก ืงื•ืงื˜ ืขืคึผืขืก ื•ื•ื™ ื“ืึธืก:

ืžื•ืœื˜ื™ื•ื•ืึทืŸ ืื•ืŸ ืจื•ื˜ื™ื ื’ ืื•ื™ืฃ Mikrotik RouterOS

3. ืฉื˜ืขืœืŸ ืึทืจื•ื™ืฃ ืึท ืงืฉืจ ืฆื• ื“ื™ ื™ืกืคึผ ืื•ืŸ ื’ืขื‘ืŸ ื‘ืจืึทื ื“ื™ื“ ืจื•ื˜ื™ื ื’

3.1. ืฉื˜ืขืœืŸ ืึท ืงืฉืจ ืฆื• ISP1:
3.1.1. ืงืึทื ืคื™ื’ื™ืขืจ ืึท ืกื˜ืึทื˜ื™ืง IP ืึทื“ืจืขืก:

/ip address add interface=ether1 address=100.66.66.2/30 comment="ISP1 IP"

3.1.2. ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’:
3.1.2.1. ืœื™ื™ื’ ืึท ืคืขืœื™ืงื™ื™ึทื˜ "ื ื•ื™ื˜ืคืึทืœ" ืžืึทืจืฉืจื•ื˜:

/ip route add comment="Emergency route" distance=254 type=blackhole

ื‘ืึทืžืขืจืงื•ื ื’. ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืึทืœืึทื•ื– ืคืึทืจืงืขืจ ืคื•ืŸ ื”ื™ื’ืข ืคึผืจืึทืกืขืกืึทื– ืฆื• ืคืึธืจืŸ ื“ื™ ืจื•ื˜ ื“ื™ืกื™ื–ืฉืึทืŸ ื‘ื™ื ืข, ืจืึทื’ืึทืจื“ืœืึทืก ืคื•ืŸ ื“ื™ ืฉื˜ืึทื˜ ืคื•ืŸ ื“ื™ ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ืขืŸ ืคื•ืŸ ืงื™ื™ืŸ ืคื•ืŸ ื“ื™ ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื–. ื“ื™ ื ื•ืึทื ืก ืคื•ืŸ ืึทื•ื˜ื’ืึธื•ื™ื ื’ ื”ื™ื’ืข ืคืึทืจืงืขืจ ืื™ื– ืึทื– ืื™ืŸ ืกื“ืจ ืคึฟืึทืจ ื“ื™ ืคึผืึทืงืึทื˜ ืฆื• ืžืึทืš ื‘ื™ื™ึท ืžื™ื ื“ืกื˜ืขืจ ืขืจื’ืขืฅ, ื“ื™ ื”ื•ื™ืคึผื˜ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ ืžื•ื–ืŸ ื”ืึธื‘ืŸ ืึทืŸ ืึทืงื˜ื™ื•ื• ืžืึทืจืฉืจื•ื˜ ืฆื• ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ื’ื™ื™ื˜ื•ื•ื™ื™. ืื•ื™ื‘ ื ื™ืฉื˜, ื“ืขืจ ืคึผืขืงืœ ื•ื•ืขื˜ ืคืฉื•ื˜ ื–ื™ื™ืŸ ื—ืจื•ื‘ึฟ.

ื•ื•ื™ ืึท ื’ืขืฆื™ื™ึทื’ ืคืึทืจืœืขื ื’ืขืจื•ื ื’ ื˜ืฉืขืง ื’ื™ื™ื˜ื•ื•ื™ื™ ืคึฟืึทืจ ืึท ื“ื™ืคึผืขืจ ืึทื ืึทืœื™ืกื™ืก ืคื•ืŸ ื“ื™ ืงืึทื ืึทืœ ืฉื˜ืึทื˜, ืื™ืš ืคึฟืึธืจืฉืœืึธื’ืŸ ื ื™ืฆืŸ ื“ื™ ืจืขืงื•ืจืกื™ื•ื•ืข ืžืึทืจืฉืจื•ื˜ ืื•ืคึฟืŸ. ื“ื™ ืขืกืึทื ืก ืคื•ืŸ ื“ืขื ืื•ืคึฟืŸ ืื™ื– ืึทื– ืžื™ืจ ื–ืึธื’ืŸ ื“ื™ ืจืึทื•ื˜ืขืจ ืฆื• ืงื•ืงืŸ ืคึฟืึทืจ ืึท ื“ืจืš ืฆื• ื–ื™ื™ืŸ ื’ื™ื™ื˜ื•ื•ื™ื™ ื ื™ื˜ ื’ืœื™ื™ึทืš, ืึธื‘ืขืจ ื“ื•ืจืš ืึท ื™ื ื˜ืขืจืžื™ื“ื™ื™ื˜ ื’ื™ื™ื˜ื•ื•ื™ื™. 4.2.2.1, 4.2.2.2 ืื•ืŸ 4.2.2.3 ื•ื•ืขืœืŸ ื–ื™ื™ืŸ ืื•ื™ืกื“ืขืจื•ื•ื™ื™ืœื˜ ื•ื•ื™ ืึทื–ืึท "ืคึผืจื•ื‘ื™ืจืŸ" ื’ื™ื™ื˜ื•ื•ื™ื™ื– ืคึฟืึทืจ ISP1, ISP2 ืื•ืŸ ISP3 ืจื™ืกืคึผืขืงื˜ื™ื•ื•ืœื™.

3.1.2.2. ืจื•ื˜ ืฆื• ื“ื™ "ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ" ืึทื“ืจืขืก:

/ip route add check-gateway=ping comment="For recursion via ISP1"  
distance=1 dst-address=4.2.2.1 gateway=100.66.66.1 scope=10

ื‘ืึทืžืขืจืงื•ื ื’. ืžื™ืจ ื ื™ื“ืขืจื™ืงืขืจ ื“ืขืจ ืคืึทืจื ืขื ื•ื•ืขืจื˜ ืฆื• ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืื™ืŸ ROS ืฆื™ืœ ืคืึทืจื ืขื ืฆื• ื ื•ืฆืŸ 4.2.2.1 ื•ื•ื™ ืึท ืจืขืงื•ืจืกื™ื•ื•ืข ื’ื™ื™ื˜ื•ื•ื™ื™ ืื™ืŸ ื“ืขืจ ืฆื•ืงื•ื ืคึฟื˜. ืื™ืš ื•ื ื˜ืขืจืฉื˜ืจื™ื™ึทื›ืŸ: ื“ืขืจ ืคืึทืจื ืขื ืคื•ืŸ ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืฆื• ื“ื™ "ืคึผืจื•ื‘ื™ืจืŸ" ืึทื“ืจืขืก ืžื•ื–ืŸ ื–ื™ื™ืŸ ื•ื•ื™ื™ื ื™ืงืขืจ ื•ื•ื™ ืึธื“ืขืจ ื’ืœื™ื™ึทืš ืฆื• ื“ื™ ืฆื™ืœ ืคืึทืจื ืขื ืคื•ืŸ ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ื•ื•ืึธืก ื•ื•ืขื˜ ืึธืคึผืฉื™ืงืŸ ืฆื• ื“ื™ ืคึผืจืึธื‘ืข ืื™ื™ื ืขืจ.

3.1.2.3. ืจืขืงื•ืจืกื™ื•ื•ืข ืคืขืœื™ืงื™ื™ึทื˜ ืžืึทืจืฉืจื•ื˜ ืคึฟืึทืจ ืคืึทืจืงืขืจ ืึธืŸ ืจื•ื˜ื™ื ื’ ืฆื™ื™ื›ืŸ:

/ip route add comment="Unmarked via ISP1" distance=2 gateway=4.2.2.1

ื‘ืึทืžืขืจืงื•ื ื’. ื“ื™ ื“ื™ืกื˜ืึทื ืกืข = 2 ื•ื•ืขืจื˜ ืื™ื– ื’ืขื ื™ืฆื˜ ื•ื•ื™ื™ึทืœ ISP1 ืื™ื– ื“ืขืจืงืœืขืจื˜ ื•ื•ื™ ื“ืขืจ ืขืจืฉื˜ืขืจ ื‘ืึทืงืึทืคึผ ืœื•ื™ื˜ ื“ื™ ืึทืจื‘ืขื˜ ื˜ื ืึธื™ื.

3.1.2.4. ืจืขืงื•ืจืกื™ื•ื•ืข ืคืขืœื™ืงื™ื™ึทื˜ ืžืึทืจืฉืจื•ื˜ ืคึฟืึทืจ ืคืึทืจืงืขืจ ืžื™ื˜ ืจื•ื˜ื™ื ื’ ืฆื™ื™ื›ืŸ "to_isp1":

/ip route add comment="Marked via ISP1 Main" distance=1 gateway=4.2.2.1 
routing-mark=to_isp1

ื‘ืึทืžืขืจืงื•ื ื’. ืึทืงื˜ื•ืึทืœืœื™, ื“ืึธ ืžื™ืจ ืœืขืกืึธืฃ ืึธื ื”ื™ื™ื‘ืŸ ืฆื• ื’ืขื ื™ืกืŸ ื“ื™ ืคื™ืจื•ืช ืคื•ืŸ ื“ื™ ืคึผืจื™ืคึผืขืจืึทื˜ืึธืจื™ ืึทืจื‘ืขื˜ ื•ื•ืึธืก ืื™ื– ื’ืขื•ื•ืขืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืื™ืŸ ืคึผืึทืจืึทื’ืจืึทืฃ 2.


ืื•ื™ืฃ ื“ืขื ืžืึทืจืฉืจื•ื˜, ืึทืœืข ืคืึทืจืงืขืจ ื•ื•ืึธืก ื”ืึธื‘ืŸ ื“ื™ ืžืึทืจืง ืžืึทืจืฉืจื•ื˜ "to_isp1" ื•ื•ืขื˜ ื–ื™ื™ืŸ ื“ื™ืจืขืงื˜ืขื“ ืฆื• ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ ืคื•ืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ืฉืคึผื™ื™ึทื–ืขืจ, ืจืึทื’ืึทืจื“ืœืึทืก ืคื•ืŸ ื•ื•ืึธืก ืคืขืœื™ืงื™ื™ึทื˜ ื’ื™ื™ื˜ื•ื•ื™ื™ ืื™ื– ื“ืขืจื•ื•ื™ื™ึทืœ ืึทืงื˜ื™ื•ื• ืคึฟืึทืจ ื“ื™ ื”ื•ื™ืคึผื˜ ื˜ื™ืฉ.

3.1.2.5. ืขืจืฉื˜ืขืจ ืคืึทืœื‘ืึทืงืง ืจืขืงื•ืจืกื™ื•ื•ืข ืคืขืœื™ืงื™ื™ึทื˜ ืžืึทืจืฉืจื•ื˜ ืคึฟืึทืจ ISP2 ืื•ืŸ ISP3 ื˜ืึทื’ื“ ืคืึทืจืงืขืจ:

/ip route add comment="Marked via ISP2 Backup1" distance=2 gateway=4.2.2.1 
routing-mark=to_isp2
/ip route add comment="Marked via ISP3 Backup1" distance=2 gateway=4.2.2.1 
routing-mark=to_isp3

ื‘ืึทืžืขืจืงื•ื ื’. ื“ื™ ืจื•ืฅ ื–ืขื ืขืŸ ื“ืืจืฃ, ืฆื•ื•ื™ืฉืŸ ืื ื“ืขืจืข ื–ืื›ืŸ, ืฆื• ืจืขื–ืขืจื•ื•ื™ืจืŸ ืคืึทืจืงืขืจ ืคื•ืŸ ื”ื™ื’ืข ื ืขื˜ื•ื•ืึธืจืงืก ื•ื•ืึธืก ื–ืขื ืขืŸ ืžื™ื˜ื’ืœื™ื“ืขืจ ืคื•ืŸ ื“ืขืจ ืึทื“ืจืขืก ืจืฉื™ืžื” "to_isp*"'

3.1.2.6. ืžื™ืจ ืคืึทืจืฉืจื™ื™ึทื‘ืŸ ื“ื™ ืžืึทืจืฉืจื•ื˜ ืคึฟืึทืจ ื“ื™ ื”ื™ื’ืข ืคืึทืจืงืขืจ ืคื•ืŸ ื“ื™ ืจืึทื•ื˜ืขืจ ืฆื• ื“ื™ ืื™ื ื˜ืขืจื ืขื˜ ื“ื•ืจืš ISP1:

/ip route rule add comment="From ISP1 IP to Inet" src-address=100.66.66.2 table=to_isp1

ื‘ืึทืžืขืจืงื•ื ื’. ืื™ืŸ ืงืึธืžื‘ื™ื ืึทืฆื™ืข ืžื™ื˜ ื“ื™ ื›ึผืœืœื™ื ืคื•ืŸ ืคึผืึทืจืึทื’ืจืึทืฃ 1.8.2, ืขืก ื’ื™ื˜ ืึทืงืกืขืก ืฆื• ื“ื™ ื’ืขื‘ืขื˜ืŸ ืงืึทื ืึทืœ ืžื™ื˜ ืึท ื’ืขื’ืขื‘ืŸ ืžืงื•ืจ. ื“ืึธืก ืื™ื– ืงืจื™ื˜ื™ืฉ ืคึฟืึทืจ ื‘ื ื™ืŸ ื˜ืึทื ืึทืœื– ื•ื•ืึธืก ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ื”ื™ื’ืข ื–ื™ื™ึทื˜ IP ืึทื“ืจืขืก (EoIP, IP-IP, GRE). ื–ื™ื ื˜ ื“ื™ ื›ึผืœืœื™ื ืื™ืŸ ื™ืคึผ ืžืึทืจืฉืจื•ื˜ ื›ึผืœืœื™ื ื–ืขื ืขืŸ ืขืงืกืึทืงื™ื•ื˜ืึทื“ ืคื•ืŸ ืฉืคึผื™ืฅ ืฆื• ื“ื ืึธ, ื‘ื™ื– ื“ืขืจ ืขืจืฉื˜ืขืจ ื’ืœื™ื™ึทื›ืŸ ืคื•ืŸ ื“ื™ ื‘ืื“ื™ื ื’ื•ื ื’ืขืŸ, ื“ืขืจ ื”ืขืจืฉืŸ ื–ืึธืœ ื–ื™ื™ืŸ ื ืึธืš ื“ื™ ื›ึผืœืœื™ื ืคื•ืŸ ืคึผื•ื ืงื˜ 1.8.2.

3.1.3. ืžื™ืจ ืจืขื’ื™ืกื˜ืจื™ืจืŸ ื“ื™ NAT โ€‹โ€‹ื”ืขืจืฉืŸ ืคึฟืึทืจ ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืคืึทืจืงืขืจ:

/ip firewall nat add action=src-nat chain=srcnat comment="NAT via ISP1"  
ipsec-policy=out,none out-interface=ether1 to-addresses=100.66.66.2

ื‘ืึทืžืขืจืงื•ื ื’. NATim ืึทืœืฅ ื•ื•ืึธืก ื’ื™ื™ื˜ ืื•ื™ืก, ืึทื—ื•ืฅ ืคึฟืึทืจ ื•ื•ืึธืก ืงื•ืžื˜ ืื™ืŸ ื“ื™ IPsec ืคึผืึทืœืึทืกื™ื–. ืื™ืš ืคึผืจื•ื‘ื™ืจืŸ ื ื™ืฉื˜ ืฆื• ื ื•ืฆืŸ ืงืึทืžืฃ = ืžืึทืกืงืขืจื™ื™ื“ ืกื™ื™ึทื“ืŸ ืœืขื’ืึทืžืจืข ื ื™ื™ื˜ื™ืง. ืขืก ืื™ื– ืกืœืึธื•ืขืจ ืื•ืŸ ืžืขืจ ืจื™ืกืึธืจืก ืื™ื ื˜ืขื ืกื™ื•ื•ืข ื•ื•ื™ src-nat ื•ื•ื™ื™ึทืœ ืขืก ืงืึทืœืงื™ืึทืœื™ื™ืฅ ื“ื™ NAT โ€‹โ€‹ืึทื“ืจืขืก ืคึฟืึทืจ ื™ืขื“ืขืจ ื ื™ื™ึทืข ืงืฉืจ.

3.1.4. ืžื™ืจ ืฉื™ืงืŸ ืงืœื™ื™ืึทื ืฅ ืคื•ืŸ ื“ืขืจ ืจืฉื™ืžื” ื•ื•ืึธืก ื–ืขื ืขืŸ ืคึผืจืึธื•ื›ื™ื‘ืึทื˜ืึทื“ ืคื•ืŸ ืึทืงืกืขืก ื“ื•ืจืš ืื ื“ืขืจืข ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื– ื’ืœื™ื™ึทืš ืฆื• ื“ื™ ISP1 ืฉืคึผื™ื™ึทื–ืขืจ ืก ื’ื™ื™ื˜ื•ื•ื™ื™.

/ip firewall mangle add action=route chain=prerouting comment="Address List via ISP1 only" 
dst-address-list=!BOGONS passthrough=no route-dst=100.66.66.1 
src-address-list=Via_only_ISP1 place-before=0

ื‘ืึทืžืขืจืงื•ื ื’. action=route ื”ืื˜ ืึท ื”ืขื›ืขืจ ื‘ื™ืœื›ืขืจืงื™ื™ึทื˜ ืื•ืŸ ืื™ื– ื’ืขื•ื•ืขื ื“ื˜ ืื™ื™ื“ืขืจ ืื ื“ืขืจืข ืจื•ื˜ื™ื ื’ ื›ึผืœืœื™ื.


place-before=0 - ืฉื˜ืขืœืŸ ืื•ื ื“ื–ืขืจ ื”ืขืจืฉืŸ ืขืจืฉื˜ืขืจ ืื™ืŸ ื“ืขืจ ืจืฉื™ืžื”.

3.2. ืฉื˜ืขืœืŸ ืึท ืงืฉืจ ืฆื• ISP2.

ื–ื™ื ื˜ ื“ื™ ISP2 ืฉืคึผื™ื™ึทื–ืขืจ ื’ื™ื˜ ืื•ื ื“ื– ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก ื“ื•ืจืš DHCP, ืขืก ืื™ื– ื’ืœื™ื™ึทืš ืฆื• ืžืึทื›ืŸ ื“ื™ ื ื™ื™ื˜ื™ืง ืขื ื“ืขืจื•ื ื’ืขืŸ ืžื™ื˜ ืึท ืฉืจื™ืคื˜ ื•ื•ืึธืก ืกื˜ืึทืจืฅ ื•ื•ืขืŸ ื“ื™ DHCP ืงืœื™ืขื ื˜ ืื™ื– ื˜ืจื™ื’ืขืจื“:

/ip dhcp-client
add add-default-route=no disabled=no interface=ether2 script=":if ($bound=1) do={r
    n    /ip route add check-gateway=ping comment="For recursion via ISP2" distance=1 
           dst-address=4.2.2.2/32 gateway=$"gateway-address" scope=10r
    n    /ip route add comment="Unmarked via ISP2" distance=1 gateway=4.2.2.2;r
    n    /ip route add comment="Marked via ISP2 Main" distance=1 gateway=4.2.2.2 
           routing-mark=to_isp2;r
    n    /ip route add comment="Marked via ISP1 Backup1" distance=2 gateway=4.2.2.2 
           routing-mark=to_isp1;r
    n    /ip route add comment="Marked via ISP3 Backup2" distance=3 gateway=4.2.2.2 
           routing-mark=to_isp3;r
    n    /ip firewall nat add action=src-nat chain=srcnat ipsec-policy=out,none 
           out-interface=$"interface" to-addresses=$"lease-address" comment="NAT via ISP2" 
           place-before=1;r
    n    if ([/ip route rule find comment="From ISP2 IP to Inet"] ="") do={r
    n        /ip route rule add comment="From ISP2 IP to Inet" 
               src-address=$"lease-address" table=to_isp2 r
    n    } else={r
    n       /ip route rule set [find comment="From ISP2 IP to Inet"] disabled=no 
              src-address=$"lease-address"r
    n    }      r
    n} else={r
    n   /ip firewall nat remove  [find comment="NAT via ISP2"];r
    n   /ip route remove [find comment="For recursion via ISP2"];r
    n   /ip route remove [find comment="Unmarked via ISP2"];r
    n   /ip route remove [find comment="Marked via ISP2 Main"];r
    n   /ip route remove [find comment="Marked via ISP1 Backup1"];r
    n   /ip route remove [find comment="Marked via ISP3 Backup2"];r
    n   /ip route rule set [find comment="From ISP2 IP to Inet"] disabled=yesr
    n}r
    n" use-peer-dns=no use-peer-ntp=no

ื“ืขืจ ืฉืจื™ืคื˜ ื–ื™ืš ืื™ืŸ ื“ื™ ื•ื•ื™ื ื‘ืึธืงืก ืคึฟืขื ืฆื˜ืขืจ:

ืžื•ืœื˜ื™ื•ื•ืึทืŸ ืื•ืŸ ืจื•ื˜ื™ื ื’ ืื•ื™ืฃ Mikrotik RouterOS
ื‘ืึทืžืขืจืงื•ื ื’. ื“ืขืจ ืขืจืฉื˜ืขืจ ื˜ื™ื™ืœ ืคื•ืŸ ื“ื™ ืฉืจื™ืคื˜ ืื™ื– ื˜ืจื™ื’ืขืจื“ ื•ื•ืขืŸ ื“ื™ ื“ื™ื ื’ืขืŸ ืื™ื– ื”ืฆืœื—ื” ื‘ืืงื•ืžืขืŸ, ื“ื™ ืจื’ืข - ื ืึธืš ื“ื™ ื“ื™ื ื’ืขืŸ ืื™ื– ื‘ืืคืจื™ื™ื˜.ื–ืขืŸ ื‘ืึทืžืขืจืงื•ื ื’ 2

3.3. ืžื™ืจ ืฉื˜ืขืœืŸ ืึท ืงืฉืจ ืฆื• ื“ื™ ISP3 ืฉืคึผื™ื™ึทื–ืขืจ.

ื–ื™ื ื˜ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก ืฉืคึผื™ื™ึทื–ืขืจ ื’ื™ื˜ ืื•ื ื“ื– ื“ื™ื ืึทืžื™ืฉ, ืขืก ืื™ื– ื’ืœื™ื™ึทืš ืฆื• ืžืึทื›ืŸ ื“ื™ ื ื™ื™ื˜ื™ืง ืขื ื“ืขืจื•ื ื’ืขืŸ ืžื™ื˜ ืกืงืจื™ืคึผืก ื•ื•ืึธืก ืึธื ื”ื™ื™ื‘ืŸ ื ืึธืš ื“ื™ ืคืคึผืคึผ ืฆื•ื‘ื™ื ื“ ืื™ื– ืื•ื™ืคื’ืขืฉื˜ืื ืขืŸ ืื•ืŸ ื ืึธืš ื“ืขื ืคืึทืœ.

3.3.1. ืขืจืฉื˜ืขืจ ืžื™ืจ ืงืึทื ืคื™ื’ื™ืขืจ ื“ื™ ืคึผืจืึธืคื™ืœ:

/ppp profile
add comment="for PPPoE to ISP3" interface-list=WAN name=isp3_client 
on-down="/ip firewall nat remove  [find comment="NAT via ISP3"];r
    n/ip route remove [find comment="For recursion via ISP3"];r
    n/ip route remove [find comment="Unmarked via ISP3"];r
    n/ip route remove [find comment="Marked via ISP3 Main"];r
    n/ip route remove [find comment="Marked via ISP1 Backup2"];r
    n/ip route remove [find comment="Marked via ISP2 Backup2"];r
    n/ip route rule set [find comment="From ISP3 IP to Inet"] disabled=yes;" 
on-up="/ip route add check-gateway=ping comment="For recursion via ISP3" distance=1 
    dst-address=4.2.2.3/32 gateway=$"remote-address" scope=10r
    n/ip route add comment="Unmarked via ISP3" distance=3 gateway=4.2.2.3;r
    n/ip route add comment="Marked via ISP3 Main" distance=1 gateway=4.2.2.3 
    routing-mark=to_isp3;r
    n/ip route add comment="Marked via ISP1 Backup2" distance=3 gateway=4.2.2.3 
    routing-mark=to_isp1;r
    n/ip route add comment="Marked via ISP2 Backup2" distance=3 gateway=4.2.2.3 
    routing-mark=to_isp2;r
    n/ip firewall mangle set [find comment="Connmark in from ISP3"] 
    in-interface=$"interface";r
    n/ip firewall nat add action=src-nat chain=srcnat ipsec-policy=out,none 
    out-interface=$"interface" to-addresses=$"local-address" comment="NAT via ISP3" 
    place-before=1;r
    nif ([/ip route rule find comment="From ISP3 IP to Inet"] ="") do={r
    n   /ip route rule add comment="From ISP3 IP to Inet" src-address=$"local-address" 
    table=to_isp3 r
    n} else={r
    n   /ip route rule set [find comment="From ISP3 IP to Inet"] disabled=no 
    src-address=$"local-address"r
    n};r
    n"

ื“ืขืจ ืฉืจื™ืคื˜ ื–ื™ืš ืื™ืŸ ื“ื™ ื•ื•ื™ื ื‘ืึธืงืก ืคึฟืขื ืฆื˜ืขืจ:

ืžื•ืœื˜ื™ื•ื•ืึทืŸ ืื•ืŸ ืจื•ื˜ื™ื ื’ ืื•ื™ืฃ Mikrotik RouterOS
ื‘ืึทืžืขืจืงื•ื ื’. ืคึผืึทืก
/ ื™ืคึผ ืคื™ื™ืจื•ื•ืึทืœ ืžืึทื ื’ืœ ืฉื˜ืขืœืŸ [ื’ืขืคึฟื™ื ืขืŸ ืงืึธืžืขื ื˜ืึทืจ = "ืงืึธื ื ืžืึทืจืง ืื™ืŸ ืคึฟื•ืŸ ื™ืกืคึผ3"] ืื™ืŸ-ืฆื•ื‘ื™ื ื“ = $ "ืฆื•ื‘ื™ื ื“";
ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืจื™ื›ื˜ื™ืง ื“ื™ ืจื™ื ื™ื™ืžื™ื ื’ ืคื•ืŸ ื“ื™ ืฆื•ื‘ื™ื ื“, ื•ื•ื™ื™ึทืœ ืขืก ืึทืจื‘ืขื˜ ืžื™ื˜ ื–ื™ื™ืŸ ืงืึธื“ ืื•ืŸ ื ื™ืฉื˜ ื“ื™ ืึทืจื•ื™ืกื•ื•ื™ื™ึทื–ืŸ ื ืึธืžืขืŸ.

3.3.2. ืื™ืฆื˜, ื ื™ืฆืŸ ื“ืขื ืคึผืจืึธืคื™ืœ, ืฉืึทืคึฟืŸ ืึท ืคึผืคึผืคึผ ืงืฉืจ:

/interface pppoe-client add allow=mschap2 comment="to ISP3" disabled=no 
interface=ether3 name=pppoe-isp3 password=isp3_pass profile=isp3_client user=isp3_client

ื•ื•ื™ ืึท ืœืขืฆื˜ ืคืึทืจื‘ื™ื ื“ืŸ, ืœืึธืžื™ืจ ืฉื˜ืขืœืŸ ื“ื™ ื–ื™ื™ื’ืขืจ:

/system ntp client set enabled=yes server-dns-names=0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org

ืคืืจ ื“ื™ ื•ื•ืืก ืœื™ื™ืขื ืขืŸ ื‘ื™ื–ืŸ ืกื•ืฃ

ื“ื™ ืคืืจื’ืขืœื™ื™ื’ื˜ ื•ื•ืขื’ ืฆื• ื™ื ืกื˜ืจื•ืžืขื ื˜ ืึท ืžื•ืœื˜ื™ื•ื•ืึทืŸ ืื™ื– ื“ื™ ืคืขืจื–ืขื ืœืขื›ืข ื™ื™ื‘ืขืจื”ืึทื ื˜ ืคื•ืŸ ื“ืขืจ ืžื—ื‘ืจ ืื•ืŸ ืื™ื– ื ื™ืฉื˜ ื“ืขืจ ื‘ืœื•ื™ื– ืžืขื’ืœืขืš. ื“ื™ ROS Toolkit ืื™ื– ื‘ืจื™ื™ื˜ ืื•ืŸ ืคืœืขืงืกืึทื‘ืึทืœ, ื•ื•ืึธืก, ืื•ื™ืฃ ื“ื™ ืื™ื™ืŸ ื”ืึทื ื˜, ื–ื™ื™ึทื ืขืŸ ืฉื•ื•ืขืจื™ืงื™ื™ื˜ืŸ ืคึฟืึทืจ ื‘ื™ื’ื™ื ืขืจื–, ืื•ืŸ, ืื•ื™ืฃ ื“ื™ ืื ื“ืขืจืข ื”ืึทื ื˜, ื“ื™ ืกื™ื‘ื” ืคึฟืึทืจ ื–ื™ื™ืŸ ืคึผืึธืคึผื•ืœืึทืจื™ื˜ืขื˜. ืœืขืจื ืขืŸ, ืคึผืจื•ื‘ื™ืจืŸ, ืึทื ื˜ื“ืขืงืŸ ื ื™ื™ึทืข ืžื›ืฉื™ืจื™ื ืื•ืŸ ืกืึทืœื•ืฉืึทื ื–. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ื•ื•ื™ ืึท ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ืงื•ื ื” ื•ื•ื™ืกืŸ, ืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ืคืึทืจื‘ื™ื™ึทื˜ืŸ ื“ื™ ื’ืขืฆื™ื™ึทื’ ืื™ืŸ ื“ืขื ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ืžื•ืœื˜ื™ื•ื•ืึทืŸ ื˜ืฉืขืง-ื’ื™ื™ื˜ื•ื•ื™ื™ ืžื™ื˜ ืจืขืงื•ืจืกื™ื•ื•ืข ืจื•ืฅ ืฆื• ื ืขื˜ื•ื•ืึทื˜ืฉ.

ื”ืขืจื•ืช

  1. ื˜ืฉืขืง-ื’ื™ื™ื˜ื•ื•ื™ื™ - ืึท ืžืขืงืึทื ื™ื–ืึทื ืึทื– ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื“ื™ืึทืงื˜ื™ื•ื•ื™ื™ื˜ ื“ื™ ืžืึทืจืฉืจื•ื˜ ื ืึธืš ืฆื•ื•ื™ื™ ืงืึธื ืกืขืงื•ื˜ื™ื•ื•ืข ื ื™ื˜ ื’ืขืจืึธื˜ืŸ ื˜ืฉืขืงืก ืคื•ืŸ ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ ืคึฟืึทืจ ืึทื•ื•ื™ื™ืœืึทื‘ื™ืœืึทื˜ื™. ื“ื™ ื˜ืฉืขืง ืื™ื– ื’ืขื˜ืืŸ ืึทืžืึธืœ ื™ืขื“ืขืจ 10 ืกืขืงื•ื ื“ืขืก, ืคึผืœื•ืก ื“ื™ ืขื ื˜ืคืขืจ ื˜ื™ื™ืžืึทื•ื˜. ืื™ืŸ ื’ืึทื ืฅ, ื“ื™ ืคืึทืงื˜ื™ืฉ ืกื•ื•ื™ื˜ืฉื™ื ื’ ื˜ื™ื™ืžื™ื ื’ ืœื™ื’ื˜ ืื™ืŸ ื“ื™ ืงื™ื™ื˜ ืคื•ืŸ 20-30 ืกืขืงื•ื ื“ืขืก. ืื•ื™ื‘ ืึทื–ืึท ืกื•ื•ื™ื˜ืฉื™ื ื’ ื˜ื™ื™ืžื™ื ื’ ืื™ื– ื ื™ืฉื˜ ื’ืขื ื•ื’, ืขืก ืื™ื– ืึทืŸ ืึธืคึผืฆื™ืข ืฆื• ื ื•ืฆืŸ ื“ื™ ื’ืขืฆื™ื™ึทื’ ื ืขื˜ื•ื•ืึทื˜ืฉ, ื•ื•ื• ื“ื™ ื˜ืฉืขืง ื˜ื™ื™ึทืžืขืจ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืฉื˜ืขืœืŸ ืžืึทื ื™ื•ืึทืœื™. ื˜ืฉืขืง-ื’ื™ื™ื˜ื•ื•ื™ื™ ื˜ื•ื˜ ื ื™ืฉื˜ ืคื™ื™ึทืขืจ ืื•ื™ืฃ ื™ื ื˜ืขืจืžื™ื˜ืึทื ื˜ ืคึผืึทืงืึทื˜ ืึธื ื•ื•ืขืจ ืื•ื™ืฃ ื“ื™ ืœื™ื ืง.

    ื•ื•ื™ื›ื˜ื™ืง! ื“ื™ืึทืงื˜ื™ื•ื•ื™ื™ื˜ื™ื ื’ ืึท ืขืจืฉื˜ื™ืง ืžืึทืจืฉืจื•ื˜ ื•ื•ืขื˜ ื“ื™ืึทืงื˜ื™ื•ื•ื™ื™ื˜ ืึทืœืข ืื ื“ืขืจืข ืจื•ืฅ ื•ื•ืึธืก ืึธืคึผืฉื™ืงืŸ ืฆื• ืื™ื. ื“ืขืจื™ื‘ืขืจ, ืคึฟืึทืจ ื–ื™ื™ ืฆื• ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื˜ืฉืขืง-ื’ื™ื™ื˜ื•ื•ื™ื™ = ืคึผื™ื ื’ ื ื™ืฉื˜ ื•ื•ื™ื›ื˜ื™ื’.

  2. ืขืก ื›ืึทืคึผืึทื ื– ืึทื– ืึท ื“ื•ืจื›ืคืึทืœ ืึทืงืขืจื– ืื™ืŸ ื“ื™ DHCP ืžืขืงืึทื ื™ื–ืึทื, ื•ื•ืึธืก ืงื•ืงื˜ ื•ื•ื™ ืึท ืงืœื™ืขื ื˜ ืกื˜ืึทืง ืื™ืŸ ื“ื™ ื‘ืึทื ื™ื™ึทืขืŸ ืฉื˜ืึทื˜. ืื™ืŸ ื“ืขื ืคืึทืœ, ื“ื™ ืจื’ืข ื˜ื™ื™ืœ ืคื•ืŸ ื“ื™ ืฉืจื™ืคื˜ ื•ื•ืขื˜ ื ื™ืฉื˜ ืึทืจื‘ืขื˜ืŸ, ืึธื‘ืขืจ ืขืก ื•ื•ืขื˜ ื ื™ืฉื˜ ืคืึทืจืžื™ื™ึทื“ืŸ ืคืึทืจืงืขืจ ืฆื• ื’ื™ื™ืŸ ืจื™ื›ื˜ื™ืง, ื•ื•ื™ื™ึทืœ ื“ื™ ืฉื˜ืึทื˜ ื˜ืจืึทืงืก ื“ื™ ืงืึธืจืึทืกืคึผืึทื ื“ื™ื ื’ ืจืขืงื•ืจืกื™ื•ื•ืข ืžืึทืจืฉืจื•ื˜.
  3. ECMP (Equal Cost Multi-Path) - ืื™ืŸ ROS ืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ืฉื˜ืขืœืŸ ืึท ืžืึทืจืฉืจื•ื˜ ืžื™ื˜ ืขื˜ืœืขื›ืข ื’ื™ื™ื˜ื•ื•ื™ื™ื– ืื•ืŸ ื“ื™ ื–ืขืœื‘ืข ื•ื•ื™ื™ึทื˜ืงื™ื™ื˜. ืื™ืŸ ื“ืขื ืคืึทืœ, ืงืึทื ืขืงืฉืึทื ื– ื•ื•ืขื˜ ื–ื™ื™ืŸ ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืื™ื‘ืขืจ ื˜ืฉืึทื ืึทืœื– ื ื™ืฆืŸ ื“ื™ ืจืึธื•ื ื“ ืจืึธื‘ื™ืŸ ืึทืœื’ืขืจื™ื“ืึทื, ืื™ืŸ ืคึผืจืึธืคึผืึธืจืฆื™ืข ืฆื• ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ืกืคึผืขืกื™ืคื™ืขื“ ื’ื™ื™ื˜ื•ื•ื™ื™ื–.

ืคึฟืึทืจ ื“ื™ ื™ืžืคึผืึทื˜ืึทืก ืฆื• ืฉืจื™ื™ึทื‘ืŸ ื“ืขื ืึทืจื˜ื™ืงืœ, ื”ื™ืœืฃ ืื™ืŸ ื“ื™ ืคืึธืจืขื ืคื•ืŸ ื–ื™ื™ึทืŸ ืกื˜ืจื•ืงื˜ื•ืจ ืื•ืŸ ืคึผืœื™ื™ืกืžืึทื ื˜ ืคื•ืŸ ืึทืงืกืขื ืฅ - ืคึผืขืจื–ืขื ืœืขืš ื“ืื ืงื‘ืืจืงื™ื™ื˜ ืฆื• ืขื•ื•ื’ืขื ื™ @ื“ื–ืฉืกืงืึทืจ

ืžืงื•ืจ: www.habr.com