ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืจื•ื˜ื™ื ื’ ืื™ื– ื“ืขืจ ืคึผืจืึธืฆืขืก ืคื•ืŸ ื“ืขืจื’ื™ื™ื•ื ื’ ื“ืขืจ ื‘ืขืกื˜ืขืจ ื•ื•ืขื’ ืคึฟืึทืจ ื˜ืจืึทื ืกืžื™ื˜ื™ื ื’ ืคึผืึทืงื™ืฅ ืื™ื‘ืขืจ TCP / IP ื ืขื˜ื•ื•ืึธืจืงืก. ื™ืขื“ืขืจ ืžื™ื˜ืœ ืคืืจื‘ื•ื ื“ืŸ ืฆื• ืึทืŸ IPv4 ื ืขืฅ ื›ึผื•ืœืœ ืึท ืคึผืจืึธืฆืขืก ืื•ืŸ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ.

ื“ืขืจ ืึทืจื˜ื™ืงืœ ืื™ื– ื ื™ืฉื˜ ืึท HOWTO, ืขืก ื‘ืืฉืจื™ื™ื‘ื˜ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ RouterOS ืžื™ื˜ ื‘ื™ื™ืฉืคื™ืœืŸ, ืื™ืš ื“ื™ืœื™ื‘ืจืึทื˜ืœื™ ืื™ื‘ืขืจื’ืขื”ื™ืคึผืขืจื˜ ื“ื™ ืจืขืฉื˜ ืคื•ืŸ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก (ืœืžืฉืœ, srcnat ืคึฟืึทืจ ืึทืงืกืขืก ื“ื™ ืื™ื ื˜ืขืจื ืขื˜), ืึทื–ื•ื™ ืฆื• ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื“ืขื ืžืึทื˜ืขืจื™ืึทืœ ืจื™ืงื•ื•ื™ื™ืขืจื– ืึท ื–ื™ื›ืขืจ ืžื“ืจื’ื” ืคื•ืŸ ื•ื•ื™ืกืŸ ืคื•ืŸ ื ืขื˜ื•ื•ืึธืจืงืก ืื•ืŸ RouterOS.

ืกื•ื•ื™ื˜ืฉื™ื ื’ ืื•ืŸ ืจื•ื˜ื™ื ื’

ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืกื•ื•ื™ื˜ืฉื™ื ื’ ืื™ื– ื“ืขืจ ืคึผืจืึธืฆืขืก ืคื•ืŸ ื™ืงืกื˜ืฉื™ื™ื ื“ื–ืฉื™ื ื’ ืคึผืึทืงื™ืฅ ืื™ืŸ ืื™ื™ืŸ Layer2 ืึธืคึผืฉื ื™ื˜ (ืขื˜ื”ืขืจื ืขื˜, ืคึผืคึผืคึผ, ...). ืื•ื™ื‘ ื“ืขืจ ืžื™ื˜ืœ ื–ืขื˜ ืึทื– ื“ืขืจ ื‘ืึทืงื•ืžืขืจ ืคื•ืŸ ื“ื™ ืคึผืึทืงืึทื˜ ืื™ื– ืื•ื™ืฃ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืขื˜ื”ืขืจื ืขื˜ ืกื•ื‘ื ืขื˜ ืžื™ื˜ ืื™ื, ืขืก ืœืขืจื ื˜ ื“ื™ ืžืขืง ืึทื“ืจืขืก ื ื™ืฆืŸ ื“ื™ ืึทืจืคึผ ืคึผืจืึธื˜ืึธืงืึธืœ ืื•ืŸ ื˜ืจืึทื ืกืžื™ื˜ื˜ ื“ื™ ืคึผืึทืงืึทื˜ ื’ืœื™ื™ึทืš, ื‘ื™ื™ืคึผืึทืกื™ื ื’ ื“ื™ ืจืึทื•ื˜ืขืจ. ื ืคึผืคึผืคึผ (ืคื•ื ื˜-ืฆื•-ืคื•ื ื˜) ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ ืงืขื ืขืŸ ื”ืึธื‘ืŸ ื‘ืœื•ื™ื– ืฆื•ื•ื™ื™ ืคึผืึทืจื˜ื™ืกืึทืคึผืึทื ืฅ ืื•ืŸ ื“ื™ ืคึผืึทืงืึทื˜ ืื™ื– ืฉื˜ืขื ื“ื™ืง ื’ืขืฉื™ืงื˜ ืฆื• ืื™ื™ืŸ ืึทื“ืจืขืก 0xff.

ืจื•ื˜ื™ื ื’ ืื™ื– ื“ืขืจ ืคึผืจืึธืฆืขืก ืคื•ืŸ ื˜ืจืึทื ืกืคืขืจื™ื ื’ ืคึผืึทืงื™ืฅ ืฆื•ื•ื™ืฉืŸ Layer2 ืกืขื’ืžืึทื ืฅ. ืื•ื™ื‘ ืึท ืžื™ื˜ืœ ื•ื•ื™ืœ ืฆื• ืฉื™ืงืŸ ืึท ืคึผืึทืงืึทื˜ ื•ื•ืขืžืขื ืก ื‘ืึทืงื•ืžืขืจ ืื™ื– ืึทืจื•ื™ืก ื“ื™ ืขื˜ื”ืขืจื ืขื˜ ืกืขื’ืžืขื ื˜, ืขืก ืงื•ืงื˜ ืื™ืŸ ื–ื™ื™ืŸ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ ืื•ืŸ ืคึผืึทืกื™ื– ื“ื™ ืคึผืึทืงืึทื˜ ืฆื• ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™, ื•ื•ืึธืก ื•ื•ื™ื™ืกื˜ ื•ื•ื• ืฆื• ืฉื™ืงืŸ ื“ื™ ืคึผืึทืงืึทื˜ ื•ื•ื™ื™ึทื˜ืขืจ (ืึธื“ืขืจ ืงืขืŸ ื ื™ืฉื˜ ื•ื•ื™ืกืŸ ื“ืขืจ ืึธืจื™ื’ื™ื ืขืœ ืกืขื ื“ืขืจ ืคื•ืŸ ื“ื™ ืคึผืึทืงืึทื˜ ืื™ื– ื ื™ืฉื˜ ืึทื•ื•ืขืจ ืคื•ืŸ ื“ืขื).

ื“ื™ ื™ื–ื™ืึทืกื˜ ื•ื•ืขื’ ืฆื• ื˜ืจืึทื›ื˜ืŸ ื•ื•ืขื’ืŸ ืึท ืจืึทื•ื˜ืขืจ ืื™ื– ื•ื•ื™ ืึท ืžื™ื˜ืœ ืคืืจื‘ื•ื ื“ืŸ ืฆื• ืฆื•ื•ื™ื™ ืึธื“ืขืจ ืžืขืจ Layer2 ืกืขื’ืžืึทื ืฅ ืื•ืŸ ืงืขื ืขืŸ ืคืึธืจืŸ ืคึผืึทืงื™ืฅ ืฆื•ื•ื™ืฉืŸ ื–ื™ื™ ื“ื•ืจืš ื“ื™ื˜ืขืจืžืึทื ื™ื ื’ ื“ืขืจ ื‘ืขืกื˜ืขืจ ืžืึทืจืฉืจื•ื˜ ืคึฟื•ืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ.

ืื•ื™ื‘ ืื™ืจ ืคึฟืึทืจืฉื˜ื™ื™ืŸ ืึทืœืฅ, ืึธื“ืขืจ ืื™ืจ ืฉื•ื™ืŸ ื’ืขื•ื•ืื•ืกื˜ ืขืก, ืœื™ื™ืขื ืขืŸ ืื•ื™ืฃ. ืคึฟืึทืจ ื“ื™ ืžื ื•ื—ื”, ืื™ืš ืฉื˜ืืจืง ืจืขืงืึธืžืขื ื“ื™ืจืŸ ืึทื– ืื™ืจ ื‘ืึทืงืขื ืขืŸ ื–ื™ืš ืžื™ื˜ ืึท ืงืœื™ื™ืŸ, ืึธื‘ืขืจ ื–ื™ื™ืขืจ ื’ืขืจืึทื ืืจื˜ื™ืงืœืขืŸ.

ืจื•ื˜ื™ื ื’ ืื™ืŸ RouterOS ืื•ืŸ PacketFlow

ื›ึผืžืขื˜ ืึทืœืข ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™ ืฉื™ื™ึทื›ื•ืช ืฆื• ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ื– ืื™ืŸ ื“ืขื ืคึผืขืงืœ ืกื™ืกื˜ืขืžืข. ืคึผืœืึทืกื˜ื™ืง ื–ืขืงืœ ืจื•ื˜ื™ื ื’ ืžื•ืกื™ืฃ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื“ื™ื ืึทืžื™ืฉ ืจื•ื˜ื™ื ื’ ืึทืœื’ืขืจื™ื“ืึทืžื– (ืจื™ืคึผ, OSPF, BGP, MME), ืจื•ื˜ื™ื ื’ ืคื™ืœื˜ืขืจืก ืื•ืŸ BFD.

ื”ื•ื™ืคึผื˜ ืžืขื ื™ื• ืคึฟืึทืจ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืจื•ื˜ื™ื ื’: [IP]->[Route]. ืงืึธืžืคึผืœืขืงืก ืกืงื™ืžื– ืงืขืŸ ื“ืึทืจืคืŸ ืคึผืึทืงื™ืฅ ืฆื• ื–ื™ื™ืŸ ืคืึทืจ-ืœื™ื™ื‘ืึทืœื“ ืžื™ื˜ ืึท ืจื•ื˜ื™ื ื’ ืฆื™ื™ื›ืŸ ืื™ืŸ: [IP]->[Firewall]->[Mangle] (ืงื™ื™ื˜ืŸ PREROUTING ะธ OUTPUT).

ืขืก ื–ืขื ืขืŸ ื“ืจื™ื™ ืขืจื˜ืขืจ ืื•ื™ืฃ PacketFlow ื•ื•ื• IP ืคึผืึทืงืึทื˜ ืจื•ื˜ื™ื ื’ ื“ื™ืกื™ื–ืฉืึทื ื– ื–ืขื ืขืŸ ื’ืขืžืื›ื˜:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

  1. ืจื•ื˜ื™ื ื’ ืคึผืึทืงื™ืฅ ื‘ืืงื•ืžืขืŸ ื“ื•ืจืš ื“ื™ ืจืึทื•ื˜ืขืจ. ืื™ืŸ ื“ืขื ื‘ื™ื ืข, ืขืก ืื™ื– ื‘ืึทืฉืœืึธืกืŸ ืฆื™ ื“ื™ ืคึผืึทืงืึทื˜ ื•ื•ืขื˜ ื’ื™ื™ืŸ ืฆื• ื“ื™ ื”ื™ื’ืข ืคึผืจืึธืฆืขืก ืึธื“ืขืจ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขืฉื™ืงื˜ ื•ื•ื™ื™ึทื˜ืขืจ ืฆื• ื“ื™ ื ืขืฅ. ื“ื•ืจื›ืคืึธืจ ืคึผืึทืงืึทื“ื–ืฉืึทื– ื‘ืึทืงื•ืžืขืŸ ืจืขื–ื•ืœื˜ืึทื˜ ืฆื•ื‘ื™ื ื“
  2. ืจื•ื˜ื™ื ื’ ื”ื™ื’ืข ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืคึผืึทืงื™ืฅ. ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืคึผืึทืงื™ืฅ ื‘ืึทืงื•ืžืขืŸ ืจืขื–ื•ืœื˜ืึทื˜ ืฆื•ื‘ื™ื ื“
  3. ื ืึธืš ืจื•ื˜ื™ื ื’ ืฉืจื™ื˜ ืคึฟืึทืจ ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืคึผืึทืงื™ืฅ, ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื˜ื•ื™ืฉืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื‘ืึทืฉืœื•ืก ืื™ืŸ [Output|Mangle]

  • ื“ื™ ืคึผืึทืงืึทื˜ ื“ืจืš ืื™ืŸ ื‘ืœืึทืงืก 1, 2 ื“ืขืคึผืขื ื“ืก ืื•ื™ืฃ ื“ื™ ื›ึผืœืœื™ื ืื™ืŸ [IP]->[Route]
  • ื“ื™ ืคึผืึทืงืึทื˜ ื“ืจืš ืื™ืŸ ืคื•ื ืงื˜ืŸ 1, 2 ืื•ืŸ 3 ื“ืขืคึผืขื ื“ืก ืื•ื™ืฃ ื“ื™ ื›ึผืœืœื™ื ืื™ืŸ [IP]->[Route]->[Rules]
  • ื“ืขืจ ืคึผืขืงืœ ื“ืจืš ืื™ืŸ ื‘ืœืึทืงืก 1, 3 ืงืขื ืขืŸ ื–ื™ื™ืŸ ื™ื ืคืœื•ืึทื ืกื˜ ืžื™ื˜ [IP]->[Firewall]->[Mangle]

RIB, FIB, ืจื•ื˜ื™ื ื’ ืงืึทืฉ

ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืจื•ื˜ื™ื ื’ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื‘ืึทื–ืข
ื“ื™ ื‘ืึทื–ืข ืื™ืŸ ื•ื•ืึธืก ืจื•ืฅ ื–ืขื ืขืŸ ื’ืขื–ืืžืœื˜ ืคึฟื•ืŸ ื“ื™ื ืึทืžื™ืฉ ืจื•ื˜ื™ื ื’ ืคึผืจืึธื˜ืึธืงืึธืœืก, ืจื•ืฅ ืคึฟื•ืŸ ืคึผืคึผืคึผ ืื•ืŸ ื“ื”ืงืคึผ, ืกื˜ืึทื˜ื™ืง ืื•ืŸ ืงืึธื ื ืขืงื˜ืขื“ ืจื•ืฅ. ื“ื™ ื“ืึทื˜ืึทื‘ื™ื™ืก ื›ึผื•ืœืœ ืึทืœืข ืจื•ืฅ, ืึทื—ื•ืฅ ื“ื™ ืคื™ืœื˜ืขืจื“ ื“ื•ืจืš ื“ื™ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ.

ืงืึทื ื“ื™ืฉืึทื ืึทืœื™, ืžื™ืจ ืงืขื ืขืŸ ื™ื‘ืขืจื ืขืžืขืŸ ืึทื– [IP]->[Route] ื“ื™ืกืคึผืœื™ื™ื– RIB.

ืคืึธืจื•ื•ืขืจื“ื™ื ื’ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื‘ืึทื–ืข
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ื“ื™ ื‘ืึทื–ืข ืื™ืŸ ื•ื•ืึธืก ื“ื™ ื‘ืขืกื˜ืขืจ ืจื•ืฅ ืคื•ืŸ RIB ื–ืขื ืขืŸ ื’ืขื–ืืžืœื˜. ืึทืœืข ืจื•ืฅ ืื™ืŸ ื“ื™ FIB ื–ืขื ืขืŸ ืึทืงื˜ื™ื•ื• ืื•ืŸ ื–ืขื ืขืŸ ื’ืขื ื™ืฆื˜ ืฆื• ืคืึธืจื•ื™ืก ืคึผืึทืงื™ืฅ. ืื•ื™ื‘ ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ื•ื•ืขืจื˜ ื™ื ืึทืงื˜ื™ื•ื• (ืคืึทืจืงืจื™ืคึผืœื˜ ื“ื•ืจืš ื“ื™ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ (ืกื™ืกื˜ืขื), ืึธื“ืขืจ ื“ื™ ืฆื•ื‘ื™ื ื“ ื“ื•ืจืš ื•ื•ืึธืก ื“ื™ ืคึผืึทืงืึทื˜ ื–ืึธืœ ื–ื™ื™ืŸ ื’ืขืฉื™ืงื˜ ืื™ื– ื ื™ืฉื˜ ืึทืงื˜ื™ื•ื•), ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืื™ื– ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ ืคื•ืŸ ื“ื™ FIB.

ืฆื• ืžืึทื›ืŸ ืึท ืจื•ื˜ื™ื ื’ ื‘ืึทืฉืœื•ืก, ื“ื™ FIB ื˜ื™ืฉ ื ื™ืฆื˜ ื“ื™ ืคืืœื’ืขื ื“ืข ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืึทืŸ IP ืคึผืึทืงืึทื˜:

  • ืžืงื•ืจ ืึทื“ืจืขืก
  • ื“ืขืกื˜ื™ื ืึทื˜ื™ืึธืŸ ืึทื“ืจืขืก
  • ืžืงื•ืจ ืฆื•ื‘ื™ื ื“
  • ืจื•ื˜ื™ื ื’ ืฆื™ื™ื›ืŸ
  • ToS (DSCP)

ื‘ืึทืงื•ืžืขืŸ ืื™ืŸ ื“ื™ FIB ืคึผืขืงืœ ื’ื™ื™ื˜ ื“ื•ืจืš ื“ื™ ืคืืœื’ืขื ื“ืข ืกื˜ืึทื’ืขืก:

  • ืื™ื– ื“ืขืจ ืคึผืขืงืœ ื‘ื“ืขื” ืคึฟืึทืจ ืึท ื”ื™ื’ืข ืจืึทื•ื˜ืขืจ ืคึผืจืึธืฆืขืก?
  • ืื™ื– ื“ื™ ืคึผืึทืงืึทื˜ ืื•ื ื˜ืขืจื˜ืขื ื™ืง ืฆื• ืกื™ืกื˜ืขื ืึธื“ืขืจ ื‘ืึทื ื™ืฆืขืจ PBR ื›ึผืœืœื™ื?
    • ืื•ื™ื‘ ื™ืึธ, ื“ื™ ืคึผืึทืงืึทื˜ ืื™ื– ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ
  • ื“ื™ ืคึผืึทืงืึทื˜ ืื™ื– ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ ื”ื•ื™ืคึผื˜ ื˜ื™ืฉ

ืงืึทื ื“ื™ืฉืึทื ืึทืœื™, ืžื™ืจ ืงืขื ืขืŸ ื™ื‘ืขืจื ืขืžืขืŸ ืึทื– [IP]->[Route Active=yes] ื“ื™ืกืคึผืœื™ื™ื– FIB.

ืจื•ื˜ื™ื ื’ ืงืึทืฉ
ืจื•ื˜ ืงืึทื˜ืฉื™ื ื’ ืžืขืงืึทื ื™ื–ืึทื. ื“ืขืจ ืจืึทื•ื˜ืขืจ ื’ืขื“ืขื ืงื˜ ื•ื•ื• ื“ื™ ืคึผืึทืงื™ืฅ ื–ืขื ืขืŸ ื’ืขืฉื™ืงื˜ ืื•ืŸ ืื•ื™ื‘ ืขืก ื–ืขื ืขืŸ ืขื ืœืขืš ืึธื ืขืก (ืžืึทืฉืžืึธืขืก ืคื•ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืงืฉืจ) ืขืก ืœืขืฅ ื–ื™ื™ ื’ื™ื™ืŸ ืฆื•ื–ืืžืขืŸ ื“ื™ ื–ืขืœื‘ืข ืžืึทืจืฉืจื•ื˜, ืึธืŸ ื˜ืฉืขืง ืื™ืŸ ื“ื™ ืคื™ื‘. ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืงืึทืฉ ืื™ื– ืคึผื™ืจื™ืึทื“ื™ืงืœื™ ืงืœื™ืจื“.

ืคึฟืึทืจ ืจืึธื•ื˜ืขืจืึธืก ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจืก, ื–ื™ื™ ื”ืึธื‘ืŸ ื ื™ืฉื˜ ื’ืขืžืื›ื˜ ืžื›ืฉื™ืจื™ื ืคึฟืึทืจ ื•ื•ื™ื•ื™ื ื’ ืื•ืŸ ืึธื ืคื™ืจื•ื ื’ ื“ื™ ืจื•ื˜ื™ื ื’ ืงืึทืฉ, ืึธื‘ืขืจ ื•ื•ืขืŸ ืขืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ืคืึทืจืงืจื™ืคึผืœื˜ ืื™ืŸ [IP]->[Settings].

ื“ืขืจ ืžืขืงืึทื ื™ื–ืึทื ืื™ื– ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ ืคื•ืŸ ื“ื™ ืœื™ื ื•ืงืก 3.6 ืงืขืจืŸ, ืึธื‘ืขืจ RouterOS ื ืึธืš ื ื™ืฆื˜ ืงืขืจืŸ 3.3.5, ื˜ืึธืžืขืจ ืจื•ื˜ื™ื ื’ ืงืึทื”ืกืข ืื™ื– ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืกื™ื‘ื•ืช.

ืœื™ื™ื’ ืžืึทืจืฉืจื•ื˜ ื“ื™ืึทืœืึธื’

[IP]->[Route]->[+]
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

  1. ืกื•ื‘ื ืขื˜ ืคึฟืึทืจ ื•ื•ืึธืก ืื™ืจ ื•ื•ื™ืœืŸ ืฆื• ืฉืึทืคึฟืŸ ืึท ืžืึทืจืฉืจื•ื˜ (ืคืขืœื™ืงื™ื™ึทื˜: 0.0.0.0/0)
  2. ื’ื™ื™ื˜ื•ื•ื™ื™ IP ืึธื“ืขืจ ืฆื•ื‘ื™ื ื“ ืฆื• ื•ื•ืึธืก ื“ื™ ืคึผืึทืงืึทื˜ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขืฉื™ืงื˜ (ืขืก ืงืขืŸ ื–ื™ื™ืŸ ืขื˜ืœืขื›ืข, ื–ืขืŸ ECMP ืื•ื ื˜ืŸ)
  3. ื’ื™ื™ื˜ื•ื•ื™ื™ ืึทื•ื•ืึทื™ืœืึทื‘ื™ืœื™ื˜ื™ ื˜ืฉืขืง
  4. ืจืขืงืึธืจื“ ื˜ื™ืคึผ
  5. ื“ื™ืกื˜ืึทื ืกืข (ืžืขื˜ืจื™ืง) ืคึฟืึทืจ ืึท ืžืึทืจืฉืจื•ื˜
  6. ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ
  7. IP ืคึฟืึทืจ ื”ื™ื’ืข ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืคึผืึทืงื™ืฅ ื“ื•ืจืš ื“ืขื ืžืึทืจืฉืจื•ื˜
  8. ื“ืขืจ ืฆื™ืœ ืคื•ืŸ ืคืึทืจื ืขื ืื•ืŸ ืฆื™ืœ ืคืึทืจื ืขื ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ ื“ื™ ืกื•ืฃ ืคื•ืŸ ื“ืขื ืึทืจื˜ื™ืงืœ.

ืจื•ื˜ ืคืœืึทื’ืก
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

  • X - ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืื™ื– ืคืึทืจืงืจื™ืคึผืœื˜ ื“ื•ืจืš ื“ื™ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ (disabled=yes)
  • ื - ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ืฉื™ืงืŸ ืคึผืึทืงื™ืฅ
  • ื“ - ืžืึทืจืฉืจื•ื˜ ืฆื•ื’ืขื’ืขื‘ืŸ ื“ื™ื ืึทืžื™ืงืึทืœืœื™ (BGP, OSPF, RIP, MME, PPP, DHCP, ืงืึธื ื ืขืงื˜ืขื“)
  • C - ื“ื™ ืกื•ื‘ื ืขื˜ ืื™ื– ืงืึธื ื ืขืงื˜ืขื“ ื’ืœื™ื™ึทืš ืฆื• ื“ื™ ืจืึทื•ื˜ืขืจ
  • ื“ - ืกื˜ืึทื˜ื™ืง ืžืึทืจืฉืจื•ื˜
  • r,b,o,m - ืจื•ื˜ ืฆื•ื’ืขื’ืขื‘ืŸ ื“ื•ืจืš ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ื“ื™ื ืึทืžื™ืฉ ืจื•ื˜ื™ื ื’ ืคึผืจืึธื˜ืึธืงืึธืœืก
  • B,U,P - ืคื™ืœื˜ืขืจื™ื ื’ ืžืึทืจืฉืจื•ื˜ (ื“ืจืึธืคึผืก ืคึผืึทืงื™ืฅ ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ื˜ืจืึทื ืกืžื™ื˜ื™ื ื’)

ื•ื•ืึธืก ืฆื• ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืื™ืŸ ื’ื™ื™ื˜ื•ื•ื™ื™: ื™ืคึผ ืึทื“ืจืขืก ืึธื“ืขืจ ืฆื•ื‘ื™ื ื“?

ื“ื™ ืกื™ืกื˜ืขื ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื‘ื™ื™ื“ืข, ื‘ืฉืขืช ืขืก ื˜ื•ื˜ ื ื™ืฉื˜ ืฉื•ื•ืขืจืŸ ืื•ืŸ ื ื™ืฉื˜ ื’ืขื‘ืŸ ื”ื™ื ืฅ ืื•ื™ื‘ ืื™ืจ ื˜ืึธืŸ ืขืคึผืขืก ืคืึทืœืฉ.

IP ืึทื“ืจืขืก
ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ ืึทื“ืจืขืก ืžื•ื–ืŸ ื–ื™ื™ืŸ ืฆื•ื˜ืจื™ื˜ืœืขืš ืื™ื‘ืขืจ Layer2. ืคึฟืึทืจ ืขื˜ื”ืขืจื ืขื˜, ื“ืึธืก ืžื™ื˜ืœ ืึทื– ื“ืขืจ ืจืึทื•ื˜ืขืจ ืžื•ื–ืŸ ื”ืึธื‘ืŸ ืึทืŸ ืึทื“ืจืขืก ืคื•ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืกื•ื‘ื ืขื˜ ืื•ื™ืฃ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืึทืงื˜ื™ื•ื• ื™ืคึผ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–, ืคึฟืึทืจ ืคึผืคึผืคึผ, ืึทื– ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ ืึทื“ืจืขืก ืื™ื– ืกืคึผืขืกื™ืคื™ืขื“ ืื•ื™ืฃ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืึทืงื˜ื™ื•ื• ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ื•ื•ื™ ื“ื™ ืกื•ื‘ื ืขื˜ ืึทื“ืจืขืก.
ืื•ื™ื‘ ื“ื™ ืึทืงืกืขืกืึทื‘ื™ืœื™ื˜ื™ ืฆื•ืฉื˜ืึทื ื“ ืคึฟืึทืจ Layer2 ืื™ื– ื ื™ืฉื˜ ื‘ืื’ืขื’ื ื˜, ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืื™ื– ื’ืขืจืขื›ื ื˜ ื•ื•ื™ ื™ื ืึทืงื˜ื™ื•ื• ืื•ืŸ ืงืขืŸ ื ื™ืฉื˜ ืคืึทืœืŸ ืื™ืŸ ื“ื™ FIB.

ืฆื•ื‘ื™ื ื“
ืึทืœืฅ ืื™ื– ืžืขืจ ืงืึธืžืคึผืœื™ืฆื™ืจื˜ ืื•ืŸ ื“ื™ ื ืึทื˜ื•ืจ ืคื•ืŸ ื“ื™ ืจืึทื•ื˜ืขืจ ื“ืขืคึผืขื ื“ืก ืื•ื™ืฃ ื“ื™ ื˜ื™ืคึผ ืคื•ืŸ ืฆื•ื‘ื™ื ื“:

  • PPP (Async, PPTP, L2TP, SSTP, PPPoE, OpenVPN *) ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ ืึทืกื•ืžื– ื‘ืœื•ื™ื– ืฆื•ื•ื™ื™ ืคึผืึทืจื˜ื™ืกืึทืคึผืึทื ืฅ ืื•ืŸ ื“ื™ ืคึผืึทืงืึทื˜ ื•ื•ืขื˜ ืฉื˜ืขื ื“ื™ืง ื–ื™ื™ืŸ ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ ืคึฟืึทืจ ื˜ืจืึทื ืกืžื™ืกื™ืข, ืื•ื™ื‘ ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ ื“ื™ื˜ืขืงืฅ ืึทื– ื“ืขืจ ื‘ืึทืงื•ืžืขืจ ืื™ื– ื–ื™ืš, ืขืก ื•ื•ืขื˜ ืึทืจื™ื‘ืขืจืคื™ืจืŸ ื“ื™ ืคึผืึทืงืึทื˜ ืฆื• ื–ื™ื™ึทืŸ ื”ื™ื’ืข ืคึผืจืึธืฆืขืก.
    ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS
  • ืขื˜ื”ืขืจื ืขื˜ ืึทืกื•ืžื– ื“ื™ ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ืคื™ืœืข ืคึผืึทืจื˜ื™ืกืึทืคึผืึทื ืฅ ืื•ืŸ ื•ื•ืขื˜ ืฉื™ืงืŸ ืจื™ืงื•ื•ืขืก ืฆื• ื“ื™ ืึทืจืคึผ ืฆื•ื‘ื™ื ื“ ืžื™ื˜ ื“ื™ ืึทื“ืจืขืก ืคื•ืŸ ื“ื™ ื‘ืึทืงื•ืžืขืจ ืคื•ืŸ ื“ื™ ืคึผืึทืงืึทื˜, ื“ืึธืก ืื™ื– ื“ืขืจื•ื•ืึทืจื˜ ืื•ืŸ ื’ืึทื ืฅ ื ืึธืจืžืึทืœ ื ืึทื˜ื•ืจ ืคึฟืึทืจ ืคืืจื‘ื•ื ื“ืŸ ืจื•ืฅ.
    ืึธื‘ืขืจ ื•ื•ืขืŸ ืื™ืจ ืคึผืจื•ื‘ื™ืจืŸ ืฆื• ื ื•ืฆืŸ ื“ื™ ืฆื•ื‘ื™ื ื“ ื•ื•ื™ ืึท ืžืึทืจืฉืจื•ื˜ ืคึฟืึทืจ ืึท ื•ื•ื™ื™ึทื˜ ืกื•ื‘ื ืขื˜, ืื™ืจ ื•ื•ืขื˜ ื‘ืึทืงื•ืžืขืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ืกื™ื˜ื•ืึทืฆื™ืข: ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืื™ื– ืึทืงื˜ื™ื•ื•, ืคึผื™ื ื’ ืฆื• ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ ืคึผืึทืกื™ื–, โ€‹โ€‹ืึธื‘ืขืจ ืงืขืŸ ื ื™ืฉื˜ ื“ืขืจื’ืจื™ื™ื›ืŸ ื“ื™ ื‘ืึทืงื•ืžืขืจ ืคึฟื•ืŸ ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ืกื•ื‘ื ืขื˜. ืื•ื™ื‘ ืื™ืจ ืงื•ืง ืื™ืŸ ื“ื™ ืฆื•ื‘ื™ื ื“ ื“ื•ืจืš ืึท ืกื ื™ืคืขืจ, ืื™ืจ ื•ื•ืขื˜ ื–ืขืŸ ืึทืจืคึผ ืจื™ืงื•ื•ืขืก ืžื™ื˜ ืึทื“ืจืขืกืขืก ืคึฟื•ืŸ ืึท ื•ื•ื™ื™ึทื˜ ืกื•ื‘ื ืขื˜.
    ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืคึผืจื•ึผื•ื•ื˜ ืฆื• ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ IP ืึทื“ืจืขืก ื•ื•ื™ ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ ื•ื•ืขืŸ ืžืขื’ืœืขืš. ื“ื™ ื•ื™ืกื ืขื ืื™ื– ืคืืจื‘ื•ื ื“ืŸ ืจื•ืฅ (ื‘ืืฉืืคืŸ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ) ืื•ืŸ ืคึผืคึผืคึผ (ืึทืกื™ื ืง, PPTP, L2TP, SSTP, PPPoE, OpenVPN *) ื™ื ื˜ืขืจืคื™ื™ืกื™ื–.

OpenVPN ื˜ื•ื˜ ื ื™ืฉื˜ ืึทื ื˜ื”ืึทืœื˜ืŸ ืึท PPP ื›ืขื“ืขืจ, ืึธื‘ืขืจ ืื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ื“ื™ OpenVPN ืฆื•ื‘ื™ื ื“ ื ืึธืžืขืŸ ืฆื• ืฉืึทืคึฟืŸ ืึท ืžืึทืจืฉืจื•ื˜.

ืžืขืจ ืกืคึผืขืฆื™ืคื™ืฉ ืจื•ื˜

ื™ืงืขืจื“ื™ืง ืจื•ื˜ื™ื ื’ ื”ืขืจืฉืŸ. ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ื•ื•ืึธืก ื‘ืืฉืจื™ื™ื‘ื˜ ื“ื™ ืงืœืขื ืขืจืขืจ ืกื•ื‘ื ืขื˜ (ืžื™ื˜ ื“ื™ ื’ืจืขืกื˜ืŸ ืกื•ื‘ื ืขื˜ ืžืึทืกืงืข) ื ืขืžื˜ ืคึผืจื™ื™ื“ืึทื ืก ืื™ืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื‘ืึทืฉืœื•ืก ืคื•ืŸ ื“ื™ ืคึผืึทืงืึทื˜. ื“ื™ ืฉื˜ืขืœืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืื™ื™ื ืกืŸ ืื™ืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ ืื™ื– ื ื™ืฉื˜ ื‘ืึทื˜ื™ื™ึทื˜ื™ืง ืฆื• ื“ื™ ื‘ืจื™ืจื” - ื“ื™ ื”ื•ื™ืคึผื˜ ื”ืขืจืฉืŸ ืื™ื– ืžืขืจ ืกืคึผืขืฆื™ืคื™ืฉ.

ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืึทืœืข ืจื•ืฅ ืคื•ืŸ ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ืกื›ืขืžืข ื–ืขื ืขืŸ ืึทืงื˜ื™ื•ื• (ืœื™ื’ืŸ ืื™ืŸ FIB). ืคื•ื ื˜ ืฆื• ืคืึทืจืฉื™ื“ืขื ืข ืกื•ื‘ื ืขืฅ ืื•ืŸ ื˜ืึธืŸ ื ื™ื˜ ืงืึธื ืคืœื™ืงื˜ ืžื™ื˜ ื™ืขื“ืขืจ ืื ื“ืขืจืขืจ.

ืื•ื™ื‘ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ื– ื•ื•ืขื˜ ื–ื™ื™ืŸ ืึทื ืึทื•ื•ื™ื™ืœืึทื‘ืึทืœ, ื“ื™ ืคึฟืึทืจื‘ื•ื ื“ืŸ ืžืึทืจืฉืจื•ื˜ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขืจืขื›ื ื˜ ื•ื•ื™ ื™ื ืึทืงื˜ื™ื•ื• (ืึทืจื•ื™ืกื’ืขื ื•ืžืขืŸ ืคื•ืŸ ื“ื™ FIB) ืื•ืŸ ืคึผืึทืงื™ืฅ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขื–ื•ื›ื˜ ืคึฟื•ืŸ ื“ื™ ืจื•ืขืŸ ืจื•ืฅ.

ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืžื™ื˜ ืกื•ื‘ื ืขื˜ 0.0.0.0/0 ืื™ื– ืžืืœ ื’ืขื’ืขื‘ืŸ ืึท ืกืคึผืขืฆื™ืขืœ ื˜ื™ื™ึทื˜ืฉ ืื•ืŸ ืื™ื– ื’ืขืจื•ืคืŸ ื“ื™ "ื“ื™ืคืึธืœื˜ ืจื•ื˜" ืึธื“ืขืจ "ื’ืึทื˜ืขื•ื•ื™ื™ึท ืคื•ืŸ ืœืขืฆื˜ืข ืจื™ื–ืึธืจื˜". ืื™ืŸ ืคืึทืงื˜, ืขืก ืื™ื– ื’ืึธืจื ื™ืฉื˜ ืžืึทื“ื–ืฉื™ืงืึทืœ ืื™ืŸ ืขืก ืื•ืŸ ืขืก ืคืฉื•ื˜ ื™ื ืงืœื•ื“ื– ืึทืœืข ืžืขื’ืœืขืš IPv4 ืึทื“ืจืขืกืขืก, ืึธื‘ืขืจ ื“ื™ ื ืขืžืขืŸ ื‘ืึทืฉืจื™ื™ึทื‘ืŸ ื–ื™ื™ืŸ ืึทืจื‘ืขื˜ ื’ื•ื˜ - ืขืก ื™ื ื“ื™ืงื™ื™ืฅ ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ ืฆื• ืคืึธืจื•ื™ืก ืคึผืึทืงื™ืฅ ืคึฟืึทืจ ื•ื•ืึธืก ืขืก ื–ืขื ืขืŸ ืงื™ื™ืŸ ืื ื“ืขืจืข, ืžืขืจ ืคึผื™ื ื˜ืœืขืš ืจื•ืฅ.

ื“ื™ ืžืึทืงืกื™ืžื•ื ืžืขื’ืœืขืš ืกื•ื‘ื ืขื˜ ืžืึทืกืงืข ืคึฟืึทืจ IPv4 ืื™ื– / 32, ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ื•ื•ื™ื™ื–ื˜ ืฆื• ืึท ืกืคึผืขืฆื™ืคื™ืฉ ื‘ืึทืœืขื‘ืึธืก ืื•ืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืื™ืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ.

ืคืืจืฉื˜ืื ื“ ืคื•ืŸ ืžืขืจ ืกืคึผืขืฆื™ืคื™ืฉ ืจื•ื˜ ืื™ื– ืคื•ื ื“ืึทืžืขื ื˜ืึทืœ ืคึฟืึทืจ ืงื™ื™ืŸ TCP / IP ืžื™ื˜ืœ.

ืžืขื”ืึทืœืขืš

ื“ื™ืกื˜ืึทื ืกืึทื– (ืึธื“ืขืจ ืžืขื˜ืจื™ืงืก) ื–ืขื ืขืŸ ืคืืจืœืื ื’ื˜ ืคึฟืึทืจ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ื™ื•ื•ืข ืคึฟื™ืœื˜ืจื™ืจื•ื ื’ ืคื•ืŸ ืจื•ืฅ ืฆื• ืึท ืื™ื™ืŸ ืกื•ื‘ื ืขื˜ ืฆื•ื˜ืจื™ื˜ืœืขืš ื“ื•ืจืš ืงื™ื™ืคืœ ื’ื™ื™ื˜ื•ื•ื™ื™ื–. ื ืžืึทืจืฉืจื•ื˜ ืžื™ื˜ ืึท ื ื™ื“ืขืจื™ืงืขืจ ืžืขื˜ืจื™ืง ืื™ื– ื’ืขื”ืืœื˜ืŸ ืึท ื‘ื™ืœื›ืขืจืงื™ื™ึทื˜ ืื•ืŸ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ืŸ ื“ื™ FIB. ืื•ื™ื‘ ืึท ืžืึทืจืฉืจื•ื˜ ืžื™ื˜ ืึท ื ื™ื“ืขืจื™ืงืขืจ ืžืขื˜ืจื™ืง ื”ืืœื˜ ืฆื• ื–ื™ื™ืŸ ืึทืงื˜ื™ื•ื•, ืขืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืจื™ืคึผืœื™ื™ืกื˜ ื“ื•ืจืš ืึท ืžืึทืจืฉืจื•ื˜ ืžื™ื˜ ืึท ื”ืขื›ืขืจ ืžืขื˜ืจื™ืง ืื™ืŸ ื“ื™ FIB.
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืื•ื™ื‘ ืขืก ื–ืขื ืขืŸ ืขื˜ืœืขื›ืข ืจื•ืฅ ืฆื• ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืกื•ื‘ื ืขื˜ ืžื™ื˜ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืžืขื˜ืจื™ืง, ื“ืขืจ ืจืึทื•ื˜ืขืจ ื•ื•ืขื˜ ืœื™ื™ื’ืŸ ื‘ืœื•ื™ื– ืื™ื™ื ืขืจ ืคื•ืŸ ื–ื™ื™ ืฆื• ื“ื™ FIB ื˜ื™ืฉ, ื’ื™ื™ื“ื™ื“ ื“ื•ืจืš ื–ื™ื™ืŸ ื™ื ืขืจืœืขืš ืœืึธื’ื™ืง.

ื“ื™ ืžืขื˜ืจื™ืง ืงืขืŸ ื ืขืžืขืŸ ืึท ื•ื•ืขืจื˜ ืคื•ืŸ 0 ืฆื• 255:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

  • 0 - ืžืขื˜ืจื™ืง ืคึฟืึทืจ ืคืืจื‘ื•ื ื“ืŸ ืจื•ืฅ. ื“ื™ืกื˜ืึทื ืกืข 0 ืงืขื ืขืŸ ื ื™ื˜ ื–ื™ื™ืŸ ื‘ืึทืฉื˜ื™ืžื˜ ื“ื•ืจืš ื“ื™ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ
  • 1-254 - ืžืขื˜ืจื™ืงืก ื‘ื ื™ืžืฆื ืฆื• ื“ืขืจ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืคึฟืึทืจ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืจื•ืฅ. ืžืขื˜ืจื™ืงืก ืžื™ื˜ ืึท ื ื™ื“ืขืจื™ืงืขืจ ื•ื•ืขืจื˜ ื”ืึธื‘ืŸ ืึท ื”ืขื›ืขืจ ื‘ื™ืœื›ืขืจืงื™ื™ึทื˜
  • 255 - ืžืขื˜ืจื™ืง ื‘ื ื™ืžืฆื ืฆื• ื“ืขืจ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืคึฟืึทืจ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืจื•ืฅ. ื ื™ื˜ ืขื ืœืขืš 1-254, ืึท ืžืึทืจืฉืจื•ื˜ ืžื™ื˜ ืึท ืžืขื˜ืจื™ืง ืคื•ืŸ 255 ืื™ื– ืฉื˜ืขื ื“ื™ืง ื™ื ืึทืงื˜ื™ื•ื• ืื•ืŸ ื˜ื•ื˜ ื ื™ืฉื˜ ืคืึทืœืŸ ืื™ืŸ ื“ื™ FIB
  • ืกืคึผืขืฆื™ืคื™ืฉ ืžืขื˜ืจื™ืงืก. ืจื•ืฅ ื“ืขืจื™ื™ื•ื•ื“ ืคื•ืŸ ื“ื™ื ืึทืžื™ืฉ ืจื•ื˜ื™ื ื’ ืคึผืจืึธื˜ืึธืงืึธืœืก ื”ืึธื‘ืŸ ื ืึธืจืžืึทืœ ืžืขื˜ืจื™ืง ื•ื•ืึทืœื•ืขืก

ื˜ืฉืขืง ื’ื™ื™ื˜ื•ื•ื™ื™

ื˜ืฉืขืง ื’ื™ื™ื˜ื•ื•ื™ื™ ืื™ื– ืึท MikroTik RoutesOS ืคืึทืจืœืขื ื’ืขืจื•ื ื’ ืคึฟืึทืจ ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ื“ื™ ืึทื•ื•ื™ื™ืœืึทื‘ื™ืœืึทื˜ื™ ืคื•ืŸ ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ ื“ื•ืจืš icmp ืึธื“ืขืจ arp. ืึทืžืึธืœ ื™ืขื“ืขืจ 10 ืกืขืงื•ื ื“ืขืก (ืงืขื ืขืŸ ื ื™ื˜ ื–ื™ื™ืŸ ื’ืขื‘ื™ื˜ืŸ), ืึท ื‘ืงืฉื” ืื™ื– ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™, ืื•ื™ื‘ ื“ืขืจ ืขื ื˜ืคืขืจ ืื™ื– ื ื™ืฉื˜ ื‘ืืงื•ืžืขืŸ ืฆื•ื•ื™ื™ ืžืึธืœ, ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืื™ื– ื’ืขื”ืืœื˜ืŸ ืึทื ืึทื•ื•ื™ื™ืœืึทื‘ืึทืœ ืื•ืŸ ืื™ื– ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ ืคื•ืŸ ื“ื™ FIB. ืื•ื™ื‘ ื˜ืฉืขืง ื’ื™ื™ื˜ื•ื•ื™ื™ ืื™ื– ืคืึทืจืงืจื™ืคึผืœื˜ ื“ื™ ื˜ืฉืขืง ืžืึทืจืฉืจื•ื˜ ื”ืืœื˜ ืื•ืŸ ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ื•ื•ืขื˜ ื•ื•ืขืจืŸ ืึทืงื˜ื™ื•ื• ื•ื•ื™ื“ืขืจ ื ืึธืš ืื™ื™ืŸ ื’ืขืจืึธื˜ืŸ ื˜ืฉืขืง.
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืงื•ืง ื’ื™ื™ื˜ื•ื•ื™ื™ ื“ื™ืกื™ื™ื‘ืึทืœื– ื“ื™ ืคึผืึธื–ื™ืฆื™ืข ืื™ืŸ ื•ื•ืึธืก ืขืก ืื™ื– ืงืึทื ืคื™ื’ื™ืขืจื“ ืื•ืŸ ืึทืœืข ืื ื“ืขืจืข ืื™ื™ื ืกืŸ (ืื™ืŸ ืึทืœืข ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ ืื•ืŸ ecmp ืจื•ืฅ) ืžื™ื˜ ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ื’ื™ื™ื˜ื•ื•ื™ื™.

ืื™ืŸ ืึทืœื’ืขืžื™ื™ืŸ, ื˜ืฉืขืง ื’ื™ื™ื˜ื•ื•ื™ื™ ืึทืจื‘ืขื˜ ื’ื•ื˜ ื•ื•ื™ ืœืึทื ื’ ื•ื•ื™ ืขืก ื–ืขื ืขืŸ ืงื™ื™ืŸ ืคืจืื‘ืœืขืžืขืŸ ืžื™ื˜ ืคึผืึทืงืึทื˜ ืึธื ื•ื•ืขืจ ืฆื• ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™. ื˜ืฉืขืง ื’ื™ื™ื˜ื•ื•ื™ื™ ื˜ื•ื˜ ื ื™ืฉื˜ ื•ื•ื™ืกืŸ ื•ื•ืึธืก ืื™ื– ื’ืขืฉืขืขื ื™ืฉ ืžื™ื˜ ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ืึทืจื•ื™ืก ื“ื™ ืึธืคึผื’ืขืฉื˜ืขืœื˜ ื’ื™ื™ื˜ื•ื•ื™ื™, ื“ืึธืก ืจื™ืงื•ื•ื™ื™ืขืจื– ื ืึธืš ืžื›ืฉื™ืจื™ื: ืกืงืจื™ืคึผืก, ืจืขืงื•ืจืกื™ื•ื•ืข ืจื•ื˜ื™ื ื’, ื“ื™ื ืึทืžื™ืฉ ืจื•ื˜ื™ื ื’ ืคึผืจืึธื˜ืึธืงืึธืœืก.

ืจื•ื‘ึฟ ื•ื•ืคึผืŸ ืื•ืŸ ื˜ื•ื ืขืœ ืคึผืจืึธื˜ืึธืงืึธืœืก ืึทื ื˜ื”ืึทืœื˜ืŸ ื’ืขื‘ื•ื™ื˜-ืื™ืŸ ืžื›ืฉื™ืจื™ื ืคึฟืึทืจ ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ืงืฉืจ ื˜ืขื˜ื™ืงื™ื™ื˜, ื•ื•ืึธืก ืึทืœืึทื•ื– ื“ื™ ื˜ืฉืขืง ื’ื™ื™ื˜ื•ื•ื™ื™ ืคึฟืึทืจ ื–ื™ื™ ืื™ื– ืึทืŸ ื ืึธืš (ืึธื‘ืขืจ ื–ื™ื™ืขืจ ืงืœื™ื™ืŸ) ืžืึทืกืข ืื•ื™ืฃ ื“ื™ ื ืขืฅ ืื•ืŸ ืžื™ื˜ืœ ืคืึธืจืฉื˜ืขืœื•ื ื’.

ECMP ืจื•ืฅ

Equal-Cost Multi-Path - ืฉื™ืงื˜ ืคึผืึทืงื™ืฅ ืฆื• ื“ื™ ื‘ืึทืงื•ืžืขืจ ืžื™ื˜ ืขื˜ืœืขื›ืข ื’ื™ื™ื˜ื•ื•ื™ื™ื– ืกื™ื™ืžืึทืœื˜ื™ื™ื ื™ืึทืกืœื™ ื ื™ืฆืŸ ื“ื™ ืจืึธื•ื ื“ ืจืึธื‘ื™ืŸ ืึทืœื’ืขืจื™ื“ืึทื.

ืึทืŸ ECMP ืžืึทืจืฉืจื•ื˜ ืื™ื– ื‘ืืฉืืคืŸ ื“ื•ืจืš ื“ืขืจ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ื“ื•ืจืš ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืงื™ื™ืคืœ ื’ื™ื™ื˜ื•ื•ื™ื™ื– ืคึฟืึทืจ ืื™ื™ืŸ ืกื•ื‘ื ืขื˜ (ืึธื“ืขืจ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืื•ื™ื‘ ืขืก ื–ืขื ืขืŸ ืฆื•ื•ื™ื™ ืขืงื•ื•ื™ื•ื•ืึทืœืขื ื˜ OSPF ืจื•ืฅ).
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ECMP ืื™ื– ื’ืขื ื™ืฆื˜ ืคึฟืึทืจ ืžืึทืกืข ื‘ืึทืœืึทื ืกื™ื ื’ ืฆื•ื•ื™ืฉืŸ ืฆื•ื•ื™ื™ ื˜ืฉืึทื ืึทืœื–, ืื™ืŸ ื˜ืขืึธืจื™ืข, ืื•ื™ื‘ ืขืก ื–ืขื ืขืŸ ืฆื•ื•ื™ื™ ื˜ืฉืึทื ืึทืœื– ืื™ืŸ ื“ื™ ecmp ืžืึทืจืฉืจื•ื˜, ืคึฟืึทืจ ื™ืขื“ืขืจ ืคึผืึทืงืึทื˜ ื“ื™ ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืงืึทื ืึทืœ ื–ืึธืœ ื–ื™ื™ืŸ ืึทื ื“ืขืจืฉ. ืึธื‘ืขืจ ื“ื™ ืจื•ื˜ื™ื ื’ ืงืึทืฉ ืžืขืงืึทื ื™ื–ืึทื ืกืขื ื“ื– ืคึผืึทืงื™ืฅ ืคื•ืŸ ื“ื™ ืงืฉืจ ืฆื•ื–ืืžืขืŸ ื“ื™ ืžืึทืจืฉืจื•ื˜ ืึทื– ื“ืขืจ ืขืจืฉื˜ืขืจ ืคึผืึทืงืึทื˜ ื’ืขื ื•ืžืขืŸ, ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜, ืžื™ืจ ื‘ืึทืงื•ืžืขืŸ ืึท ืžื™ืŸ ืคื•ืŸ ื‘ืึทืœืึทื ืกื™ื ื’ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ืงืึทื ืขืงืฉืึทื ื– (ืคึผืขืจ-ืงืฉืจ ืœืึธื•ื“ื™ื ื’ ื‘ืึทืœืึทื ืกื™ื ื’).

ืื•ื™ื‘ ืื™ืจ ื“ื™ืกื™ื™ื‘ืึทืœ ืจื•ื˜ื™ื ื’ ืงืึทืฉ, ื“ื™ ืคึผืึทืงื™ืฅ ืื™ืŸ ื“ื™ ECMP ืžืึทืจืฉืจื•ื˜ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืฉืขืจื“ ืจื™ื›ื˜ื™ืง, ืึธื‘ืขืจ ืขืก ืื™ื– ืึท ืคึผืจืึธื‘ืœืขื ืžื™ื˜ NAT. ื“ื™ NAT โ€‹โ€‹ื”ืขืจืฉืŸ ืคึผืจืึทืกืขืกืึทื– ื‘ืœื•ื™ื– ื“ืขืจ ืขืจืฉื˜ืขืจ ืคึผืึทืงืึทื˜ ืคื•ืŸ ื“ื™ ืงืฉืจ (ื“ื™ ืžื ื•ื—ื” ื–ืขื ืขืŸ ืคึผืจืึทืกืขืกื˜ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ), ืื•ืŸ ืขืก ื˜ื•ืจื ืก ืื•ื™ืก ืึทื– ืคึผืึทืงื™ืฅ ืžื™ื˜ ื“ื™ ื–ืขืœื‘ืข ืžืงื•ืจ ืึทื“ืจืขืก ืœืึธื–ืŸ ืคืึทืจืฉื™ื“ืขื ืข ื™ื ื˜ืขืจืคื™ื™ืกื™ื–.
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืงื•ืง ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ ื˜ื•ื˜ ื ื™ืฉื˜ ืึทืจื‘ืขื˜ืŸ ืื™ืŸ ECMP ืจื•ืฅ (ืจืึธื•ื˜ืขืจืึธืก ื–ืฉื•ืง). ืึธื‘ืขืจ ืื™ืจ ืงืขื ืขืŸ ื‘ืึทืงื•ืžืขืŸ ืึทืจื•ื ื“ืขื ื‘ืึทื’ืจืขื ืขืฆื•ื ื’ ื“ื•ืจืš ืงืจื™ื™ื™ื˜ื™ื ื’ ื ืึธืš ื•ื•ืึทืœืึทื“ื™ื™ืฉืึทืŸ ืจื•ืฅ ื•ื•ืึธืก ื•ื•ืขื˜ ื“ื™ืกื™ื™ื‘ืึทืœ ืื™ื™ื ืกืŸ ืื™ืŸ ECMP.

ืคื™ืœื˜ืขืจื™ื ื’ ื“ื•ืจืš ืจื•ื˜ื™ื ื’

ื“ื™ ื˜ื™ืคึผ ืึธืคึผืฆื™ืข ื“ื™ื˜ืขืจืžืึทื ื– ื•ื•ืึธืก ืฆื• ื˜ืึธืŸ ืžื™ื˜ ื“ืขื ืคึผืขืงืœ:

  • unicast - ืฉื™ืงืŸ ืฆื• ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ื’ื™ื™ื˜ื•ื•ื™ื™ ( ืฆื•ื‘ื™ื ื“)
  • ื‘ืœืึทืงื›ืึธืœ - ืึทื•ื•ืขืงื•ื•ืึทืจืคืŸ ืึท ืคึผืึทืงืึทื˜
  • ืคืึทืจื•ื•ืขืจืŸ, ืึทื ืจื™ืึทื˜ืฉืึทื‘ืึทืœ - ืึทื•ื•ืขืงื•ื•ืึทืจืคืŸ ื“ื™ ืคึผืึทืงืึทื˜ ืื•ืŸ ืฉื™ืงืŸ ืึท ื™ืงืžืคึผ ืึธื ื–ืึธื’ ืฆื• ื“ื™ ืกืขื ื“ืขืจ

ืคื™ืœื˜ืขืจื™ื ื’ ืื™ื– ื™ื•ื–ืฉืึทื•ื•ืึทืœื™ ื’ืขื ื™ืฆื˜ ื•ื•ืขืŸ ืขืก ืื™ื– ื ื™ื™ื˜ื™ืง ืฆื• ื‘ืึทื•ื•ืึธืจืขื ืขืŸ ื“ื™ ืฉื™ืงื˜ ืคื•ืŸ ืคึผืึทืงื™ืฅ ืื•ื™ืฃ ื“ืขื ืื•ืžืจืขื›ื˜ ื•ื•ืขื’, ืคื•ืŸ ืงื•ืจืก, ืื™ืจ ืงืขื ืขืŸ ืคื™ืœื˜ืขืจ ื“ืขื ื“ื•ืจืš ื“ื™ ืคื™ื™ืจื•ื•ืึทืœ.

ื ืคึผืึธืจ ืคื•ืŸ ื‘ื™ื™ืฉืคื™ืœืŸ

ืฆื• ืงืึธื ืกืึธืœื™ื“ื™ืจืŸ ื“ื™ ื™ืงืขืจื“ื™ืง ื˜ื™ื ื’ื– ื•ื•ืขื’ืŸ ืจื•ื˜ื™ื ื’.

ื˜ื™ืคึผื™ืฉ ื”ื™ื™ื ืจืึทื•ื˜ืขืจ
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

/ip route
add dst-address=0.0.0.0/0 gateway=10.10.10.1

  1. ืกื˜ืึทื˜ื™ืง ืžืึทืจืฉืจื•ื˜ ืฆื• 0.0.0.0/0 (ืคืขืœื™ืงื™ื™ึทื˜ ืžืึทืจืฉืจื•ื˜)
  2. ืงืึธื ื ืขืงื˜ืขื“ ืžืึทืจืฉืจื•ื˜ ืื•ื™ืฃ ื“ื™ ืฆื•ื‘ื™ื ื“ ืžื™ื˜ ื“ืขืจ ืฉืคึผื™ื™ึทื–ืขืจ
  3. ืงืึธื ื ืขืงื˜ืขื“ ืžืึทืจืฉืจื•ื˜ ืื•ื™ืฃ ืœืึทืŸ ืฆื•ื‘ื™ื ื“

ื˜ื™ืคึผื™ืฉ ื”ื™ื™ื ืจืึทื•ื˜ืขืจ ืžื™ื˜ PPPoE
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

  1. ืกื˜ืึทื˜ื™ืง ืžืึทืจืฉืจื•ื˜ ืฆื• ืคืขืœื™ืงื™ื™ึทื˜ ืžืึทืจืฉืจื•ื˜, ืžื•ืกื™ืฃ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ. ืขืก ืื™ื– ืกืคึผืขืกื™ืคื™ืขื“ ืื™ืŸ ืงืฉืจ ืคึผืจืึธืคึผืขืจื˜ื™ืขืก
  2. ืงืึธื ื ืขืงื˜ืขื“ ืžืึทืจืฉืจื•ื˜ ืคึฟืึทืจ ืคึผืคึผืคึผ ืงืฉืจ
  3. ืงืึธื ื ืขืงื˜ืขื“ ืžืึทืจืฉืจื•ื˜ ืื•ื™ืฃ ืœืึทืŸ ืฆื•ื‘ื™ื ื“

ื˜ื™ืคึผื™ืฉ ื”ื™ื™ื ืจืึทื•ื˜ืขืจ ืžื™ื˜ ืฆื•ื•ื™ื™ ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื– ืื•ืŸ ื™ื‘ืขืจื™ืงื™ื™ึทื˜
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

/ip route
add dst-address=0.0.0.0/0 gateway=10.10.10.1 distance=1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=10.20.20.1 distance=2

  1. ืกื˜ืึทื˜ื™ืง ืžืึทืจืฉืจื•ื˜ ืฆื• ืคืขืœื™ืงื™ื™ึทื˜ ืžืึทืจืฉืจื•ื˜ ื“ื•ืจืš ื“ืขืจ ืขืจืฉื˜ืขืจ ืฉืคึผื™ื™ึทื–ืขืจ ืžื™ื˜ ืžืขื˜ืจื™ืง 1 ืื•ืŸ ื’ื™ื™ื˜ื•ื•ื™ื™ ืึทื•ื•ื™ื™ืœืึทื‘ื™ืœืึทื˜ื™ ื˜ืฉืขืง
  2. ืกื˜ืึทื˜ื™ืง ืžืึทืจืฉืจื•ื˜ ืฆื• ืคืขืœื™ืงื™ื™ึทื˜ ืžืึทืจืฉืจื•ื˜ ื“ื•ืจืš ืจื’ืข ืฉืคึผื™ื™ึทื–ืขืจ ืžื™ื˜ ืžืขื˜ืจื™ืง 2
  3. ืงืึธื ื ืขืงื˜ืขื“ ืจื•ืฅ

ืคืึทืจืงืขืจ ืฆื• 0.0.0.0/0 ื’ื™ื™ื˜ ื“ื•ืจืš 10.10.10.1 ื‘ืฉืขืช ื“ืขื ื’ื™ื™ื˜ื•ื•ื™ื™ ืื™ื– ื‘ื ื™ืžืฆื, ืึทื ื“ืขืจืฉ ืขืก ืกื•ื•ื™ื˜ืฉื™ื– ืฆื• 10.20.20.1

ืึทื–ืึท ืึท ืกื›ืขืžืข ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื”ืืœื˜ืŸ ืึท ืงืึทื ืึทืœ ืจืขื–ืขืจื•ื•ืึทืฆื™ืข, ืึธื‘ืขืจ ืขืก ืื™ื– ื ื™ืฉื˜ ืึธืŸ ื“ื™ืกืึทื“ื•ื•ืึทื ื˜ื™ื“ื–ืฉื™ื–. ืื•ื™ื‘ ืึท ื‘ืจืขื›ืŸ ืึทืงืขืจื– ืึทืจื•ื™ืก ื“ื™ ื’ืึทื˜ืขื•ื•ื™ื™ึท ืคื•ืŸ ื“ื™ ืฉืคึผื™ื™ึทื–ืขืจ (ืœืžืฉืœ, ื™ืŸ ื“ืขืจ ืึธืคึผืขืจืึทื˜ืึธืจ ืก ื ืขืฅ), ื“ื™ื™ืŸ ืจืึทื•ื˜ืขืจ ื•ื•ืขื˜ ื ื™ืฉื˜ ื•ื•ื™ืกืŸ ื•ื•ืขื’ืŸ ืื™ื ืื•ืŸ ื•ื•ืขื˜ ืคืึธืจื–ืขืฆืŸ ืฆื• ื‘ืึทื˜ืจืึทื›ื˜ืŸ ื“ืขื ืžืึทืจืฉืจื•ื˜ ื•ื•ื™ ืึทืงื˜ื™ื•ื•.

ื˜ื™ืคึผื™ืฉ ื”ื™ื™ื ืจืึทื•ื˜ืขืจ ืžื™ื˜ ืฆื•ื•ื™ื™ ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื–, ื™ื‘ืขืจื™ืงื™ื™ึทื˜ ืื•ืŸ ECMP
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

/ip route
add dst-address=0.0.0.0/0 gateway=10.10.10.1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=10.20.20.1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=10.10.10.1,10.20.20.1 distance=1

  1. ืกื˜ืึทื˜ื™ืง ืจื•ืฅ ืคึฟืึทืจ ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ื˜ืฉืึทืง ื’ื™ื™ื˜ื•ื•ื™ื™
  2. ECMP ืžืึทืจืฉืจื•ื˜
  3. ืงืึธื ื ืขืงื˜ืขื“ ืจื•ืฅ

ืจื•ืฅ ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื–ืขื ืขืŸ ื‘ืœื•ื™ (ื“ื™ ืงืึธืœื™ืจ ืคื•ืŸ ื™ื ืึทืงื˜ื™ื•ื• ืจื•ืฅ), ืึธื‘ืขืจ ื“ืึธืก ื˜ื•ื˜ ื ื™ืฉื˜ ืึทืจื™ื™ึทื ืžื™ืฉื  ื–ื™ืš ืžื™ื˜ ื“ื™ ื˜ืฉืขืง ื’ื™ื™ื˜ื•ื•ื™ื™. ื“ื™ ืงืจืึทื ื˜ ื•ื•ืขืจืกื™ืข (6.44) ืคื•ืŸ RoS ื’ื™ื˜ ืึธื˜ืึทืžืึทื˜ื™ืง ื‘ื™ืœื›ืขืจืงื™ื™ึทื˜ ืฆื• ื“ื™ ECMP ืžืึทืจืฉืจื•ื˜, ืึธื‘ืขืจ ืขืก ืื™ื– ื‘ืขืกืขืจ ืฆื• ืœื™ื™ื’ืŸ ืคึผืจื•ื‘ื™ืจืŸ ืจื•ืฅ ืฆื• ืื ื“ืขืจืข ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ (ืึธืคึผืฆื™ืข). routing-mark)

ืื•ื™ืฃ ืกืคึผืขืขื“ื˜ืขืกื˜ ืื•ืŸ ืื ื“ืขืจืข ืขื ืœืขืš ื–ื™ื™ื˜ืœืขืš, ืขืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืงื™ื™ืŸ ืคืึทืจื’ืจืขืกืขืจืŸ ืื™ืŸ ื’ื™ื›ืงื™ื™ึทื˜ (ECMP ื“ื™ื•ื•ื™ื™ื“ื– ืคืึทืจืงืขืจ ื“ื•ืจืš ืงืึทื ืขืงืฉืึทื ื–, ื ื™ืฉื˜ ื“ื•ืจืš ืคึผืึทืงื™ืฅ), ืึธื‘ืขืจ ืคึผ2ืคึผ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื–ืึธืœ ืžืึทืกืข ืคืึทืกื˜ืขืจ.

ืคื™ืœื˜ืขืจื™ื ื’ ื“ื•ืจืš ืจื•ื˜ื™ื ื’
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

/ip route
add dst-address=0.0.0.0/0 gateway=10.10.10.1
add dst-address=192.168.200.0/24 gateway=10.30.30.1 distance=1
add dst-address=192.168.200.0/24 gateway=10.10.10.1 distance=2 type=blackhole

  1. ืกื˜ืึทื˜ื™ืง ืžืึทืจืฉืจื•ื˜ ืฆื• ืคืขืœื™ืงื™ื™ึทื˜ ืžืึทืจืฉืจื•ื˜
  2. ืกื˜ืึทื˜ื™ืง ืžืึทืจืฉืจื•ื˜ ืฆื• 192.168.200.0/24 ืื™ื‘ืขืจ ื™ืคึผื™ืคึผ ื˜ื•ื ืขืœ
  3. ืคืึธืจื‘ื™ื“ื™ื ื’ ืกื˜ืึทื˜ื™ืง ืžืึทืจืฉืจื•ื˜ ืฆื• 192.168.200.0/24 ื“ื•ืจืš ื™ืกืคึผ ืจืึทื•ื˜ืขืจ

ื ืคึฟื™ืœื˜ืจื™ืจื•ื ื’ ืึธืคึผืฆื™ืข ืื™ืŸ ื•ื•ืึธืก ื˜ื•ื ืขืœ ืคืึทืจืงืขืจ ื•ื•ืขื˜ ื ื™ืฉื˜ ื’ื™ื™ืŸ ืฆื• ื“ื™ ืจืึทื•ื˜ืขืจ ืคื•ืŸ ื“ื™ ืฉืคึผื™ื™ึทื–ืขืจ ื•ื•ืขืŸ ื“ื™ ipip ืฆื•ื‘ื™ื ื“ ืื™ื– ืคืึทืจืงืจื™ืคึผืœื˜. ืึทื–ืึท ืกืงื™ืžื– ื–ืขื ืขืŸ ืจืึทืจืขืœื™ ืคืืจืœืื ื’ื˜, ื•ื•ื™ื™ึทืœ ืื™ืจ ืงืขื ืขืŸ ื™ื ืกื˜ืจื•ืžืขื ื˜ ื‘ืœืึทืงื™ื ื’ ื“ื•ืจืš ื“ื™ ืคื™ื™ืจื•ื•ืึทืœ.

ืจื•ื˜ื™ื ื’ ืฉืœื™ื™ืฃ
ืจื•ื˜ื™ื ื’ ืฉืœื™ื™ืฃ - ืึท ืกื™ื˜ื•ืึทืฆื™ืข ื•ื•ืขืŸ ืึท ืคึผืึทืงืึทื˜ ืœื•ื™ืคื˜ ืฆื•ื•ื™ืฉืŸ ืจืึธื•ื˜ืขืจืก ืื™ื™ื“ืขืจ ื“ื™ ืขืงืกืคึผืขืจื™ื™ืฉืึทืŸ ืคื•ืŸ ื˜ื˜ืœ. ื™ื•ื–ืฉืึทื•ื•ืึทืœื™ ืขืก ืื™ื– ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ืึท ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขื•ืช, ืื™ืŸ ื’ืจื•ื™ืก ื ืขื˜ื•ื•ืึธืจืงืก ืขืก ืื™ื– ื‘ืื”ืื ื“ืœื˜ ื“ื•ืจืš ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ื ืึทืžื™ืฉ ืจื•ื˜ื™ื ื’ ืคึผืจืึธื˜ืึธืงืึธืœืก, ืื™ืŸ ืงืœื™ื™ืŸ - ืžื™ื˜ ื–ืึธืจื’.

ืขืก ืงื•ืงื˜ ืขืคึผืขืก ื•ื•ื™ ื“ืึธืก:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ื ื‘ื™ื™ืฉืคึผื™ืœ (ืกื™ืžืคึผืึทืกื˜) ืคื•ืŸ ื•ื•ื™ ืฆื• ื‘ืึทืงื•ืžืขืŸ ืึท ืขื ืœืขืš ืจืขื–ื•ืœื˜ืึทื˜:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ื“ื™ ืจื•ื˜ื™ื ื’ ืฉืœื™ื™ืฃ ื‘ื™ื™ึทืฉืคึผื™ืœ ืื™ื– ืคื•ืŸ ืงื™ื™ืŸ ืคึผืจืึทืงื˜ื™ืฉ ื ื•ืฆืŸ, ืึธื‘ืขืจ ืขืก ื•ื•ื™ื™ื–ื˜ ืึทื– ืจืึธื•ื˜ืขืจืก ื”ืึธื‘ืŸ ืงื™ื™ืŸ ื’ืขื“ืึทื ืง ื•ื•ืขื’ืŸ ื–ื™ื™ืขืจ ื—ื‘ืจ ืก ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ.

ืคึผืึธืœื™ื˜ื™ืง ื‘ืึทื–ืข ืจื•ื˜ื™ื ื’ ืื•ืŸ ื ืึธืš ืจื•ื˜ื™ื ื’ ื˜ืึทื‘ืœืขืก

ื•ื•ืขืŸ ื˜ืฉื•ื–ื™ื ื’ ืึท ืžืึทืจืฉืจื•ื˜, ื“ื™ ืจืึทื•ื˜ืขืจ ื ื™ืฆื˜ ื‘ืœื•ื™ื– ืื™ื™ืŸ ืคืขืœื“ ืคื•ืŸ ื“ื™ ืคึผืึทืงืึทื˜ ื›ืขื“ืขืจ (ื“ืกื˜. ืึทื“ืจืขืก) - ื“ืึธืก ืื™ื– ื™ืงืขืจื“ื™ืง ืจื•ื˜ื™ื ื’. ืจื•ื˜ื™ื ื’ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ืื ื“ืขืจืข ื‘ืื“ื™ื ื’ื•ื ื’ืขืŸ, ืึทื–ืึท ื•ื•ื™ ืžืงื•ืจ ืึทื“ืจืขืก, ื˜ื™ืคึผ ืคื•ืŸ ืคืึทืจืงืขืจ (ToS), ื‘ืึทืœืึทื ืกื™ื ื’ ืึธืŸ ECMP, ื’ืขื”ืขืจื˜ ืฆื• ืคึผืึธืœื™ื˜ื™ืง ื‘ืึทืกืข ืจื•ื˜ื™ื ื’ (PBR) ืื•ืŸ ื ื™ืฆื˜ ื ืึธืš ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ.

ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืžืขืจ ืกืคึผืขืฆื™ืคื™ืฉ ืจื•ื˜ ืื™ื– ื“ื™ ื”ื•ื™ืคึผื˜ ืžืึทืจืฉืจื•ื˜ ืกืขืœืขืงืฆื™ืข ื”ืขืจืฉืŸ ืื™ืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ.

ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ืึทืœืข ืจื•ื˜ื™ื ื’ ื›ึผืœืœื™ื ื–ืขื ืขืŸ ืžื•ืกื™ืฃ ืฆื• ื“ื™ ื”ื•ื™ืคึผื˜ ื˜ื™ืฉ. ื“ืขืจ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืงืขื ืขืŸ ืžืึทื›ืŸ ืึท ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ื ื•ืžืขืจ ืคื•ืŸ ื ืึธืš ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ ืื•ืŸ ืžืึทืจืฉืจื•ื˜ ืคึผืึทืงื™ืฅ ืฆื• ื–ื™ื™. ื›ึผืœืœื™ื ืื™ืŸ ืคืึทืจืฉื™ื“ืขื ืข ื˜ื™ืฉืŸ ื˜ืึธืŸ ื ื™ื˜ ืงืึธื ืคืœื™ืงื˜ ืžื™ื˜ ื™ืขื“ืขืจ ืื ื“ืขืจืขืจ. ืื•ื™ื‘ ื“ืขืจ ืคึผืขืงืœ ืงืขืŸ ื ื™ืฉื˜ ื’ืขืคึฟื™ื ืขืŸ ืึท ืคึผืึทืกื™ืง ื”ืขืจืฉืŸ ืื™ืŸ ื“ื™ ืกืคึผืขืกืึทืคื™ื™ื“ ื˜ื™ืฉ, ืขืก ื•ื•ืขื˜ ื’ื™ื™ืŸ ืฆื• ื“ื™ ื”ื•ื™ืคึผื˜ ื˜ื™ืฉ.

ื‘ื™ื™ึทืฉืคึผื™ืœ ืžื™ื˜ ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’ ื“ื•ืจืš ืคื™ืจืขื•ื•ืึทืœืœ:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

  • 192.168.100.10 -> 8.8.8.8
    1. ืคืึทืจืงืขืจ ืคื•ืŸ 192.168.100.10 ื•ื•ืขืจื˜ ืœื™ื™ื‘ืึทืœื“ via-isp1 ะฒ [Prerouting|Mangle]
    2. ืื™ืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื‘ื™ื ืข ืื™ืŸ ื“ื™ ื˜ื™ืฉ via-isp1 ื–ื•ื›ืŸ ืคึฟืึทืจ ืึท ืžืึทืจืฉืจื•ื˜ ืฆื• 8.8.8.8
    3. ืจื•ื˜ ื’ืขืคื•ื ืขืŸ, ืคืึทืจืงืขืจ ืื™ื– ื’ืขืฉื™ืงื˜ ืฆื• ื’ื™ื™ื˜ื•ื•ื™ื™ 10.10.10.1
  • 192.168.200.20 -> 8.8.8.8
    1. ืคืึทืจืงืขืจ ืคื•ืŸ 192.168.200.20 ื•ื•ืขืจื˜ ืœื™ื™ื‘ืึทืœื“ via-isp2 ะฒ [Prerouting|Mangle]
    2. ืื™ืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื‘ื™ื ืข ืื™ืŸ ื“ื™ ื˜ื™ืฉ via-isp2 ื–ื•ื›ืŸ ืคึฟืึทืจ ืึท ืžืึทืจืฉืจื•ื˜ ืฆื• 8.8.8.8
    3. ืจื•ื˜ ื’ืขืคื•ื ืขืŸ, ืคืึทืจืงืขืจ ืื™ื– ื’ืขืฉื™ืงื˜ ืฆื• ื’ื™ื™ื˜ื•ื•ื™ื™ 10.20.20.1
  • ืื•ื™ื‘ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ื– (10.10.10.1 ืึธื“ืขืจ 10.20.20.1) ื•ื•ืขืจื˜ ืึทื ืึทื•ื•ื™ื™ืœืึทื‘ืึทืœ, ื“ื™ ืคึผืึทืงืึทื˜ ื•ื•ืขื˜ ื’ื™ื™ืŸ ืฆื• ื“ื™ ื˜ื™ืฉ ื”ื•ื™ืคึผื˜ ืื•ืŸ ื•ื•ืขื˜ ื–ื•ื›ืŸ ืึท ืคึผืึทืกื™ืง ืžืึทืจืฉืจื•ื˜ ื“ืึธืจื˜

ื˜ืขืจืžื™ื ืึธืœืึธื’ื™ืข ื™ืฉื•ื–

RouterOS ื”ืื˜ ื–ื™ื›ืขืจ ื˜ืขืจืžื™ื ืึธืœืึธื’ื™ืข ื™ืฉื•ื–.
ื•ื•ืขืŸ ืืจื‘ืขื˜ืŸ ืžื™ื˜ ื›ึผืœืœื™ื ืื™ืŸ [IP]->[Routes] ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ ืื™ื– ืื ื’ืขื•ื•ื™ื–ืŸ, ื›ืึธื˜ืฉ ืขืก ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ืึทื– ื“ื™ ืคื™ืจืžืข:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ะ’ [IP]->[Routes]->[Rule] ืึทืœืฅ ืื™ื– ืจื™ื›ื˜ื™ืง, ืื™ืŸ ื“ื™ ืคื™ืจืžืข ืฆื•ืฉื˜ืึทื ื“ ืื™ืŸ ื“ื™ ื˜ื™ืฉ ืงืึทืžืฃ:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ื•ื•ื™ ืฆื• ืฉื™ืงืŸ ืึท ืคึผืึทืงืึทื˜ ืฆื• ืึท ืกืคึผืขืฆื™ืคื™ืฉ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ

RouterOS ื’ื™ื˜ ืขื˜ืœืขื›ืข ืžื›ืฉื™ืจื™ื:

  • ื›ึผืœืœื™ื ืื™ืŸ [IP]->[Routes]->[Rules]
  • ืจื•ื˜ ืžืึทืจืงืขืจืก (action=mark-routing) ืื™ืŸ [IP]->[Firewall]->[Mangle]
  • VRF

ืจืขื’ื™ืึทืœื™ื™ืฉืึทื ื– [IP]->[Route]->[Rules]
ื›ึผืœืœื™ื ื–ืขื ืขืŸ ืคึผืจืึทืกืขืกื˜ ืกืึทืงื•ื•ืขื ื˜ืฉืึทืœื™, ืื•ื™ื‘ ื“ื™ ืคึผืึทืงืึทื˜ ืฉื•ื•ืขื‘ืขืœืขืš ื“ื™ ื‘ืื“ื™ื ื’ื•ื ื’ืขืŸ ืคื•ืŸ ื“ื™ ื”ืขืจืฉืŸ, ืขืก ื˜ื•ื˜ ื ื™ืฉื˜ ืคืึธืจืŸ ื•ื•ื™ื™ึทื˜ืขืจ.

ืจื•ื˜ื™ื ื’ ื›ึผืœืœื™ื ืœืึธื–ืŸ ืื™ืจ ืฆื• ื™ืงืกืคึผืึทื ื“ ื“ื™ ืคึผืึทืกืึทื‘ื™ืœืึทื˜ื™ื– ืคื•ืŸ ืจื•ื˜ื™ื ื’, ืจื™ืœื™ื™ื™ื ื’ ื ื™ื˜ ื‘ืœื•ื™ื– ืื•ื™ืฃ ื“ื™ ื‘ืึทืงื•ืžืขืจ ืึทื“ืจืขืก, ืึธื‘ืขืจ ืื•ื™ืš ืื•ื™ืฃ ื“ื™ ืžืงื•ืจ ืึทื“ืจืขืก ืื•ืŸ ืฆื•ื‘ื™ื ื“ ืื•ื™ืฃ ื•ื•ืึธืก ื“ื™ ืคึผืึทืงืึทื˜ ืื™ื– ื‘ืืงื•ืžืขืŸ.

ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ื›ืœืœื™ื ื‘ืืฉื˜ื™ื™ื˜ ืคื•ืŸ ื‘ืื“ื™ื ื’ื•ื ื’ืขืŸ ืื•ืŸ ืึท ืงืึทืžืฃ:

  • ื‘ืื“ื™ื ื’ื•ื ื’ืขืŸ. ืคึผืจืึทืงื˜ืึทืงืœื™ ืื™ื‘ืขืจื—ื–ืจืŸ ื“ื™ ืจืฉื™ืžื” ืคื•ืŸ ื•ื•ืื•ื ื“ืขืจ ื“ื•ืจืš ื•ื•ืึธืก ื“ื™ ืคึผืขืงืœ ืื™ื– ืึธืคึผื’ืขืฉื˜ืขืœื˜ ืื™ืŸ ื“ื™ FIB, ื‘ืœื•ื™ื– ื˜ืึธืก ืื™ื– ืคืขืœื ื“ื™ืง.
  • ื˜ืขื˜ื™ืงื™ื™ื˜
    • ืœื•ืงืึทืคึผ - ืฉื™ืงืŸ ืึท ืคึผืึทืงืึทื˜ ืฆื• ืึท ื˜ื™ืฉ
    • ื–ื•ื›ืŸ ื‘ืœื•ื™ื– ืื™ืŸ ื˜ื™ืฉ - ืฉืœืึธืก ื“ื™ ืคึผืขืงืœ ืื™ืŸ ื“ื™ ื˜ื™ืฉ, ืื•ื™ื‘ ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืื™ื– ื ื™ืฉื˜ ื’ืขืคึฟื•ื ืขืŸ, ื“ืขืจ ืคึผืขืงืœ ื•ื•ืขื˜ ื ื™ืฉื˜ ื’ื™ื™ืŸ ืฆื• ื“ื™ ื”ื•ื™ืคึผื˜ ื˜ื™ืฉ
    • ืคืึทืœืŸ - ืคืึทืœืŸ ืึท ืคึผืึทืงืึทื˜
    • ืึทื ืจื™ื˜ืฉืึทื‘ืึทืœ - ืึทื•ื•ืขืงื•ื•ืึทืจืคืŸ ื“ื™ ืคึผืึทืงืึทื˜ ืžื™ื˜ ืกืขื ื“ืขืจ ืึธื ื–ืึธื’

ืื™ืŸ FIB, ืคืึทืจืงืขืจ ืฆื• ื”ื™ื’ืข ืคึผืจืึทืกืขืกืึทื– ืื™ื– ืคึผืจืึทืกืขืกื˜ ื‘ื™ื™ืคึผืึทืกื™ื ื’ ื“ื™ ื›ึผืœืœื™ื [IP]->[Route]->[Rules]:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืžืึทืจืงื™ื ื’ [IP]->[Firewall]->[Mangle]
ืจื•ื˜ื™ื ื’ ืžืึทืจืงืก ืœืึธื–ืŸ ืื™ืจ ืฆื• ืฉื˜ืขืœืŸ ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ ืคึฟืึทืจ ืึท ืคึผืึทืงืึทื˜ ื ื™ืฆืŸ ื›ึผืžืขื˜ ืงื™ื™ืŸ ืคื™ืจืขื•ื•ืึทืœืœ ื˜ื ืึธื™ื:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืคึผืจืึทืงื˜ืึทืงืœื™, ื•ื•ื™ื™ึทืœ ื ื™ื˜ ืึทืœืข ืคื•ืŸ โ€‹โ€‹ื–ื™ื™ ืžืึทื›ืŸ ื–ื™ื ืขืŸ, ืื•ืŸ ืขื˜ืœืขื›ืข ืงืขืŸ ืึทืจื‘ืขื˜ ืึทื ืกื˜ื™ื™ื‘ืึทืœ.

ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืขืก ื–ืขื ืขืŸ ืฆื•ื•ื™ื™ ื•ื•ืขื’ืŸ ืฆื• ืฉื˜ืขืœืŸ ืึท ืคึผืขืงืœ:

  • ื’ืœื™ื™ืš ืฉื˜ืขืœืŸ ืจื•ื˜ื™ื ื’ ืฆื™ื™ื›ืŸ
  • ืฉื˜ืขืœืŸ ืขืจืฉื˜ืขืจ ืงืฉืจ-ืฆื™ื™ื›ืŸ, ื“ืขืžืึธืœื˜ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ืงืฉืจ-ืฆื™ื™ื›ืŸ ืฆื• ืœื™ื™ื’ืŸ ืจื•ื˜ื™ื ื’ ืฆื™ื™ื›ืŸ

ืื™ืŸ ืึทืŸ ืึทืจื˜ื™ืงืœ ื•ื•ืขื’ืŸ ืคื™ืจืขื•ื•ืึทืœืœืก, ืื™ืš ื’ืขืฉืจื™ื‘ืŸ ืึทื– ื“ื™ ืจื’ืข ืึธืคึผืฆื™ืข ืื™ื– ื‘ื™ืœื›ืขืจ. ืจืึทื“ื•ืกืึทื– ื“ื™ ืžืึทืกืข ืื•ื™ืฃ ื“ื™ ืงืคึผื•, ืื™ืŸ ื“ื™ ืคืึทืœ ืคื•ืŸ ืžืึทืจืงื™ื ื’ ืจื•ืฅ - ื“ืึธืก ืื™ื– ื ื™ืฉื˜ ืœืขื’ืึทืžืจืข ืืžืช. ื“ื™ ืžืึทืจืงื™ื ื’ ืžืขื˜ื”ืึธื“ืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ืฉื˜ืขื ื“ื™ืง ืขืงื•ื•ื™ื•ื•ืึทืœืขื ื˜ ืื•ืŸ ื–ืขื ืขืŸ ื™ื•ื–ืฉืึทื•ื•ืึทืœื™ ื’ืขื ื™ืฆื˜ ืฆื• ืกืึธืœื•ื•ืข ืคืึทืจืฉื™ื“ืŸ ืคึผืจืึธื‘ืœืขืžืก.

ื‘ืึทื ื™ืฅ ื‘ื™ื™ืฉืคื™ืœืŸ

ื–ืืœ ืก ืžืึทืš ืื•ื™ืฃ ืฆื• ื“ื™ ื‘ื™ื™ืฉืคื™ืœืŸ ืคื•ืŸ ื ื™ืฆืŸ ืคึผืึธืœื™ื˜ื™ืง ื‘ืึทืกืข ืจื•ื˜ื™ื ื’, ื–ื™ื™ ื–ืขื ืขืŸ ืคื™ืœ ื’ืจื™ื ื’ืขืจ ืฆื• ื•ื•ื™ื™ึทื–ืŸ ื•ื•ืึธืก ืึทืœืข ื“ืขื ืื™ื– ื“ืืจืฃ.

MultiWAN ืื•ืŸ ืฆื•ืจื™ืงืงื•ืžืขืŸ ืึทื•ื˜ื’ืึธื•ื™ื ื’ (ืจืขื–ื•ืœื˜ืึทื˜) ืคืึทืจืงืขืจ
ื ืคึผืจืึธืกื˜ ืคึผืจืึธื‘ืœืขื ืžื™ื˜ ืึท ืžื•ืœื˜ื™ื•ื•ืึทืŸ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ: ืžื™ืงืจืึธื˜ื™ืง ืื™ื– ื‘ื ื™ืžืฆื ืคึฟื•ืŸ ื“ืขืจ ืื™ื ื˜ืขืจื ืขืฅ ื‘ืœื•ื™ื– ื“ื•ืจืš ืึทืŸ "ืึทืงื˜ื™ื•ื•" ืฉืคึผื™ื™ึทื–ืขืจ.
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ื“ืขืจ ืจืึทื•ื˜ืขืจ ื˜ื•ื˜ ื ื™ืฉื˜ ื–ืึธืจื’ืŸ ื•ื•ืึธืก ื™ืคึผ ื“ื™ ื‘ืงืฉื” ื’ืขืงื•ืžืขืŸ ืฆื•, ื•ื•ืขืŸ ื“ื–ืฉืขื ืขืจื™ื™ื˜ื™ื ื’ ืึท ืขื ื˜ืคืขืจ, ืขืก ื•ื•ืขื˜ ืงื•ืงืŸ ืคึฟืึทืจ ืึท ืžืึทืจืฉืจื•ื˜ ืื™ืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ ื•ื•ื• ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ื“ื•ืจืš ื™ืกืคึผ 1 ืื™ื– ืึทืงื˜ื™ื•ื•. ื•ื•ื™ื™ึทื˜ืขืจ, ืึทื–ืึท ืึท ืคึผืึทืงืึทื˜ ื•ื•ืขื˜ ืจื•ื‘ึฟ ืžืกืชึผืžื ื–ื™ื™ืŸ ืคื™ืœื˜ืขืจื“ ืฆื•ื–ืืžืขืŸ ื“ืขื ื•ื•ืขื’ ืฆื• ื“ื™ ื‘ืึทืงื•ืžืขืจ.

ืืŸ ืื ื“ืขืจ ื˜ืฉื™ืงืึทื•ื•ืข ืคื•ื ื˜. ืื•ื™ื‘ ืึท "ืคึผืฉื•ื˜" ืžืงื•ืจ ื ืึทื˜ ืื™ื– ืงืึทื ืคื™ื’ื™ืขืจื“ ืื•ื™ืฃ ื“ื™ ether1 ืฆื•ื‘ื™ื ื“: /ip fi nat add out-interface=ether1 action=masquerade ื“ืขืจ ืคึผืขืงืœ ื•ื•ืขื˜ ื’ื™ื™ืŸ ืึธื ืœื™ื™ืŸ ืžื™ื˜ src. ืึทื“ืจืขืก=10.10.10.100, ื•ื•ืึธืก ืžืื›ื˜ ื“ื™ ื˜ื™ื ื’ื– ืืคื™ืœื• ืขืจื’ืขืจ.

ืขืก ื–ืขื ืขืŸ ืขื˜ืœืขื›ืข ื•ื•ืขื’ืŸ ืฆื• ืคืึทืจืจื™ื›ื˜ืŸ ื“ืขื ืคึผืจืึธื‘ืœืขื, ืึธื‘ืขืจ ืงื™ื™ืŸ ืคื•ืŸ ื–ื™ื™ ื•ื•ืขื˜ ื“ืึทืจืคืŸ ื ืึธืš ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

/ip route
add dst-address=0.0.0.0/0 gateway=10.10.10.1 check-gateway=ping distance=1
add dst-address=0.0.0.0/0 gateway=10.20.20.1 check-gateway=ping distance=2
add dst-address=0.0.0.0/0 gateway=10.10.10.1 routing-mark=over-isp1
add dst-address=0.0.0.0/0 gateway=10.20.20.1 routing-mark=over-isp2

ื ื•ืฆืŸ [IP]->[Route]->[Rules]
ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ ื•ื•ืึธืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืคึฟืึทืจ ืคึผืึทืงื™ืฅ ืžื™ื˜ ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ืžืงื•ืจ IP.
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

/ip route rule
add src-address=10.10.10.100/32 action=lookup-only-in-table table=over-isp1
add src-address=10.20.20.200/32 action=lookup-only-in-table table=over-isp2

ืงืขื ืขืŸ ื ื•ืฆืŸ action=lookup, ืึธื‘ืขืจ ืคึฟืึทืจ ื”ื™ื’ืข ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืคืึทืจืงืขืจ, ื“ืขื ืึธืคึผืฆื™ืข ื’ืึธืจ ื™ืงืกืงืœื•ื“ื– ืงืึทื ืขืงืฉืึทื ื– ืคื•ืŸ ื“ื™ ืื•ืžืจืขื›ื˜ ืฆื•ื‘ื™ื ื“.

  • ื“ืขืจ ืกื™ืกื˜ืขื ื“ื–ืฉืขื ืขืจื™ื™ืฅ ืึท ืขื ื˜ืคืขืจ ืคึผืึทืงืึทื˜ ืžื™ื˜ Src. ืึทื“ืจืขืก: 10.20.20.200
  • ื“ื™ ืจื•ื˜ื™ื ื’ ื‘ืึทืฉืœื•ืก (2) ืฉืจื™ื˜ ื˜ืฉืขืงืก [IP]->[Routes]->[Rules] ืื•ืŸ ื“ื™ ืคึผืึทืงืึทื˜ ืื™ื– ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ over-isp2
  • ืœื•ื™ื˜ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ, ื“ื™ ืคึผืึทืงืึทื˜ ืžื•ื–ืŸ ื–ื™ื™ืŸ ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ 10.20.20.1 ื“ื•ืจืš ื“ื™ ether2 ืฆื•ื‘ื™ื ื“

ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ื“ืขืจ ืื•ืคึฟืŸ ื˜ื•ื˜ ื ื™ืฉื˜ ื“ืึทืจืคืŸ ืึท ืืจื‘ืขื˜ืŸ ืงืึทื ืขืงืฉืึทืŸ ื˜ืจืึทืงืขืจ, ื ื™ื˜ ืขื ืœืขืš ื“ื™ ืžืึทื ื’ืœ ื˜ื™ืฉ.

ื ื•ืฆืŸ [IP]->[Firewall]->[Mangle]
ื“ืขืจ ืงืฉืจ ืกื˜ืึทืจืฅ ืžื™ื˜ ืึท ื™ื ืงืึทืžื™ื ื’ ืคึผืึทืงืึทื˜, ืึทื–ื•ื™ ืžื™ืจ ืฆื™ื™ื›ืŸ ืขืก (action=mark-connection), ืคึฟืึทืจ ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืคึผืึทืงื™ืฅ ืคื•ืŸ ืึท ืื ื’ืขืฆื™ื™ื›ื ื˜ ืงืฉืจ, ืฉื˜ืขืœืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ืคื™ืจืžืข (action=mark-routing).
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

/ip firewall mangle
#ะœะฐั€ะบะธั€ะพะฒะบะฐ ะฒั…ะพะดัั‰ะธั… ัะพะตะดะธะฝะตะฝะธะน
add chain=input in-interface=ether1 connection-state=new action=mark-connection new-connection-mark=from-isp1
add chain=input in-interface=ether2 connection-state=new action=mark-connection new-connection-mark=from-isp2
#ะœะฐั€ะบะธั€ะพะฒะบะฐ ะธัั…ะพะดัั‰ะธั… ะฟะฐะบะตั‚ะพะฒ ะฝะฐ ะพัะฝะพะฒะต ัะพะตะดะธะฝะตะฝะธะน
add chain=output connection-mark=from-isp1 action=mark-routing new-routing-mark=over-isp1 passthrough=no
add chain=output connection-mark=from-isp2 action=mark-routing new-routing-mark=over-isp2 passthrough=no

ืื•ื™ื‘ ืขื˜ืœืขื›ืข ื™ืคึผืก ื–ืขื ืขืŸ ืงืึทื ืคื™ื’ื™ืขืจื“ ืื•ื™ืฃ ืื™ื™ืŸ ืฆื•ื‘ื™ื ื“, ืื™ืจ ืงืขื ืขืŸ ืœื™ื™ื’ืŸ ืฆื• ื“ื™ ืฆื•ืฉื˜ืึทื ื“ dst-address ืฆื• ื–ื™ื™ืŸ ื–ื™ื›ืขืจ.

  • ื ืคึผืึทืงืึทื˜ ืึธืคึผืขื ืก ื“ื™ ืงืฉืจ ืื•ื™ืฃ ื“ื™ ether2 ืฆื•ื‘ื™ื ื“. ื“ืขืจ ืคึผืขืงืœ ื’ื™ื™ื˜ ืืจื™ื™ืŸ [INPUT|Mangle] ื•ื•ืึธืก ื–ืื’ื˜ ืฆื• ืฆื™ื™ื›ืŸ ืึทืœืข ืคึผืึทืงื™ืฅ ืคื•ืŸ ื“ื™ ืงืฉืจ ื•ื•ื™ ืคึฟื•ืŸ-ื™ืกืคึผ2
  • ื“ืขืจ ืกื™ืกื˜ืขื ื“ื–ืฉืขื ืขืจื™ื™ืฅ ืึท ืขื ื˜ืคืขืจ ืคึผืึทืงืึทื˜ ืžื™ื˜ Src. ืึทื“ืจืขืก: 10.20.20.200
  • ืื™ืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื‘ืึทืฉืœื•ืก (2) ื‘ื™ื ืข, ื“ื™ ืคึผืึทืงืึทื˜, ืื™ืŸ ืœื•ื™ื˜ ืžื™ื˜ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ, ืื™ื– ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ 10.20.20.1 ื“ื•ืจืš ื“ื™ ether1 ืฆื•ื‘ื™ื ื“. ืื™ืจ ืงืขื ืขืŸ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ืขื ื“ื•ืจืš ืœืึธื’ื™ื ื’ ื“ื™ ืคึผืึทืงืึทื“ื–ืฉืึทื– ืื™ืŸ [OUTPUT|Filter]
  • ืื™ืŸ ื“ืขืจ ื‘ื™ื ืข [OUTPUT|Mangle] ืงืฉืจ ืคื™ืจืžืข ืื™ื– ืึธืคึผื’ืขืฉื˜ืขืœื˜ ืคึฟื•ืŸ-ื™ืกืคึผ2 ืื•ืŸ ื“ื™ ืคึผืึทืงืึทื˜ ื ืขืžื˜ ืึท ืžืึทืจืฉืจื•ื˜ ืคื™ืจืžืข over-isp2
  • ื“ื™ ืจื•ื˜ื™ื ื’ ืึทื“ื“ื–ืฉื•ืกืžืึทื ื˜ (3) ืฉืจื™ื˜ ื˜ืฉืขืงืก ืคึฟืึทืจ ื“ื™ ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ืึท ืจื•ื˜ื™ื ื’ ืคื™ืจืžืข ืื•ืŸ ืกืขื ื“ื– ืขืก ืฆื• ื“ื™ ืฆื•ื ืขืžืขืŸ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ
  • ืœื•ื™ื˜ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ, ื“ื™ ืคึผืึทืงืึทื˜ ืžื•ื–ืŸ ื–ื™ื™ืŸ ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ 10.20.20.1 ื“ื•ืจืš ื“ื™ ether2 ืฆื•ื‘ื™ื ื“

ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

MultiWAN ืื•ืŸ ืฆื•ืจื™ืงืงื•ืžืขืŸ dst-nat ืคืึทืจืงืขืจ

ื ื‘ื™ื™ืฉืคึผื™ืœ ืื™ื– ืžืขืจ ืงืึธืžืคึผืœื™ืฆื™ืจื˜, ื•ื•ืึธืก ืฆื• ื˜ืึธืŸ ืื•ื™ื‘ ืขืก ืื™ื– ืึท ืกืขืจื•ื•ืขืจ (ืœืžืฉืœ, ื•ื•ืขื‘) ื”ื™ื ื˜ืขืจ ื“ื™ ืจืึทื•ื˜ืขืจ ืื•ื™ืฃ ืึท ืคึผืจื™ื•ื•ืึทื˜ ืกื•ื‘ื ืขื˜ ืื•ืŸ ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืฆื•ืฉื˜ืขืœืŸ ืึทืงืกืขืก ืฆื• ืขืก ื“ื•ืจืš ืงื™ื™ืŸ ืคื•ืŸ ื“ื™ ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื–.

/ip firewall nat
add chain=dstnat proto=tcp dst-port=80,443 in-interface=ether1 action=dst-nat to-address=192.168.100.100
add chain=dstnat proto=tcp dst-port=80,443 in-interface=ether2 action=dst-nat to-address=192.168.100.100

ื“ื™ ืขืกืึทื ืก ืคื•ืŸ ื“ื™ ืคึผืจืึธื‘ืœืขื ื•ื•ืขื˜ ื–ื™ื™ืŸ ื“ื™ ื–ืขืœื‘ืข, ื“ื™ ืœื™ื™ื–ื•ื ื’ ืื™ื– ืขื ืœืขืš ืฆื• ื“ื™ Firewall Mangle ืึธืคึผืฆื™ืข, ื‘ืœื•ื™ื– ืื ื“ืขืจืข ืงื™ื™ื˜ืŸ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

/ip firewall mangle
add chain=prerouting connection-state=new in-interface=ether1 protocol=tcp dst-port=80,443 action=mark-connection new-connection-mark=web-input-isp1
add chain=prerouting connection-state=new in-interface=ether2 protocol=tcp dst-port=80,443 action=mark-connection new-connection-mark=web-input-isp2
add chain=prerouting connection-mark=web-input-isp1 in-interface=ether3 action=mark-routing new-routing-mark=over-isp1 passthrough=no
add chain=prerouting connection-mark=web-input-isp2 in-interface=ether3 action=mark-routing new-routing-mark=over-isp2 passthrough=no

ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS
ื“ื™ ื“ื™ืึทื’ืจืึทืžืข ื˜ื•ื˜ ื ื™ืฉื˜ ื•ื•ื™ื™ึทื–ืŸ NAT, ืึธื‘ืขืจ ืื™ืš ื˜ืจืึทื›ื˜ืŸ ืึทืœืฅ ืื™ื– ืงืœืึธืจ.

ืžื•ืœื˜ื™ื•ื•ืึทืŸ ืื•ืŸ ืึทื•ื˜ื‘ืึทื•ื ื“ ืงืึทื ืขืงืฉืึทื ื–

ืื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ื“ื™ PBR ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื– ืฆื• ืฉืึทืคึฟืŸ ืงื™ื™ืคืœ ื•ื•ืคึผืŸ (SSTP ืื™ืŸ ื“ืขื ื‘ื™ื™ึทืฉืคึผื™ืœ) ืงืึทื ืขืงืฉืึทื ื– ืคื•ืŸ ืคืึทืจืฉื™ื“ืขื ืข ืจืึทื•ื˜ืขืจ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–.

ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ื ืึธืš ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ:

/ip route
add dst-address=0.0.0.0/0 gateway=192.168.100.1 routing-mark=over-isp1
add dst-address=0.0.0.0/0 gateway=192.168.200.1 routing-mark=over-isp2
add dst-address=0.0.0.0/0 gateway=192.168.0.1 routing-mark=over-isp3

add dst-address=0.0.0.0/0 gateway=192.168.100.1 distance=1
add dst-address=0.0.0.0/0 gateway=192.168.200.1 distance=2
add dst-address=0.0.0.0/0 gateway=192.168.0.1 distance=3

ืคึผืขืงืœ ืžืึทืจืงืก:

/ip firewall mangle
add chain=output dst-address=10.10.10.100 proto=tcp dst-port=443 action=mark-routing new-routing-mark=over-isp1 passtrough=no
add chain=output dst-address=10.10.10.101 proto=tcp dst-port=443 action=mark-routing new-routing-mark=over-isp2 passtrough=no
add chain=output dst-address=10.10.10.102 proto=tcp dst-port=443 action=mark-routing new-routing-mark=over-isp3 passtrough=no

ืคึผืฉื•ื˜ NAT ื›ึผืœืœื™ื, ืึทื ื“ืขืจืฉ ื“ื™ ืคึผืึทืงืึทื˜ ื•ื•ืขื˜ ืœืึธื–ืŸ ื“ื™ ืฆื•ื‘ื™ื ื“ ืžื™ื˜ ื“ืขื ืื•ืžืจืขื›ื˜ Src. ืึทื“ืจืขืก:

/ip firewall nat
add chain=srcnat out-interface=ether1 action=masquerade
add chain=srcnat out-interface=ether2 action=masquerade
add chain=srcnat out-interface=ether3 action=masquerade

ืคึผืึทืจืกื™ื ื’:

  • ืจืึทื•ื˜ืขืจ ืงืจื™ื™ื™ืฅ ื“ืจื™ื™ SSTP ืคึผืจืึทืกืขืกืึทื–
  • ืื™ืŸ ื“ืขืจ ื‘ื™ื ืข ืคื•ืŸ โ€‹โ€‹ืจื•ื˜ื™ื ื’ ื‘ืึทืฉืœื•ืก (2), ืึท ืžืึทืจืฉืจื•ื˜ ืื™ื– ืื•ื™ืกื’ืขืงืœื™ื‘ืŸ ืคึฟืึทืจ ื“ื™ ืคึผืจืึทืกืขืกืึทื– ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ ื”ื•ื™ืคึผื˜ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ. ืคึฟื•ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืžืึทืจืฉืจื•ื˜, ื“ื™ ืคึผืึทืงืึทื˜ ื ืขืžื˜ Src. ืึทื“ืจืขืก ื’ืขื‘ื•ื ื“ืŸ ืฆื• ether1 ืฆื•ื‘ื™ื ื“
  • ะ’ [Output|Mangle] ืคึผืึทืงื™ืฅ ืคื•ืŸ ืคืึทืจืฉื™ื“ืขื ืข ืงืึทื ืขืงืฉืึทื ื– ื‘ืึทืงื•ืžืขืŸ ืคืึทืจืฉื™ื“ืขื ืข ืœืึทื‘ืขืœืก
  • ืคึผืึทืงื™ืฅ ืึทืจื™ื™ึทืŸ ื“ื™ ื˜ื™ืฉืŸ ืงืึธืจืึทืกืคึผืึทื ื“ื™ื ื’ ืฆื• ื“ื™ ืœืึทื‘ืขืœืก ืื™ืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ืึทื“ื–ืฉืึทืกื˜ืžืึทื ื˜ ื‘ื™ื ืข ืื•ืŸ ื‘ืึทืงื•ืžืขืŸ ืึท ื ื™ื™ึทืข ืžืึทืจืฉืจื•ื˜ ืคึฟืึทืจ ืฉื™ืงืŸ ืคึผืึทืงื™ืฅ
  • ืึธื‘ืขืจ ืคึผืึทืงืึทื“ื–ืฉืึทื– ื ืึธืš ื”ืึธื‘ืŸ Src. ืึทื“ืจืขืก ืคื•ืŸ ether1, ืื•ื™ืฃ ื‘ื™ื ืข [Nat|Srcnat] ื“ื™ ืึทื“ืจืขืก ืื™ื– ืกืึทื‘ืกื˜ืึทื˜ื•ื˜ืึทื“ ืœื•ื™ื˜ ื“ื™ ืฆื•ื‘ื™ื ื“

ื™ื ื˜ืขืจืขืกื˜ื™ื ื’ืœื™, ืื•ื™ืฃ ื“ื™ ืจืึทื•ื˜ืขืจ ืื™ืจ ื•ื•ืขื˜ ื–ืขืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ืงืฉืจ ื˜ื™ืฉ:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืงืึทื ืขืงืฉืึทืŸ ื˜ืจืึทืงืขืจ ืึทืจื‘ืขื˜ ืคืจื™ืขืจ [Mangle] ะธ [Srcnat], ืึทื–ื•ื™ ืึทืœืข ืงืึทื ืขืงืฉืึทื ื– ืงื•ืžืขืŸ ืคื•ืŸ ื“ื™ ื–ืขืœื‘ืข ืึทื“ืจืขืก, ืื•ื™ื‘ ืื™ืจ ืงื•ืง ืื™ืŸ ืžืขืจ ื“ืขื˜ืึทืœ, ื“ืขืžืึธืœื˜ ืื™ืŸ Replay Dst. Address ืขืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืึทื“ืจืขืกืขืก ื ืึธืš NAT:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืื•ื™ืฃ ื“ื™ VPN ืกืขืจื•ื•ืขืจ (ืื™ืš ื”ืึธื‘ืŸ ืื™ื™ืŸ ืื•ื™ืฃ ื“ื™ ืคึผืจืึธื‘ืข ื‘ืึทื ืง), ืื™ืจ ืงืขื ืขืŸ ื–ืขืŸ ืึทื– ืึทืœืข ืงืึทื ืขืงืฉืึทื ื– ืงื•ืžืขืŸ ืคึฟื•ืŸ ื“ื™ ืจื™ื›ื˜ื™ืง ืึทื“ืจืขืกืขืก:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ื•ื•ืึทืจื˜ืŸ ืึท ื•ื•ืขื’
ืขืก ืื™ื– ืึท ื’ืจื™ื ื’ืขืจ ื•ื•ืขื’, ืื™ืจ ืงืขื ืขืŸ ืคืฉื•ื˜ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืึท ืกืคึผืขืฆื™ืคื™ืฉ ื’ื™ื™ื˜ื•ื•ื™ื™ ืคึฟืึทืจ ื™ืขื“ืขืจ ืคื•ืŸ ื“ื™ ืึทื“ืจืขืกืขืก:

/ip route
add dst-address=10.10.10.100 gateway=192.168.100.1
add dst-address=10.10.10.101 gateway=192.168.200.1
add dst-address=10.10.10.102 gateway=192.168.0.1

ืื‘ืขืจ ืึทื–ืึท ืจื•ืฅ ื•ื•ืขื˜ ื•ื•ื™ืจืงืŸ ื ื™ื˜ ื‘ืœื•ื™ื– ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืึธื‘ืขืจ ืื•ื™ืš ื“ื•ืจื›ืคืึธืจ ืคืึทืจืงืขืจ. ืคึผืœื•ืก, ืื•ื™ื‘ ืื™ืจ ื˜ืึธืŸ ื ื™ื˜ ื“ืึทืจืคึฟืŸ ืคืึทืจืงืขืจ ืฆื• ื“ื™ ื•ื•ืคึผืŸ ืกืขืจื•ื•ืขืจ ืฆื• ื’ื™ื™ืŸ ื“ื•ืจืš ื™ื ืึทืคึผืจืึธื•ืคึผืจื™ื™ื˜ ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ื˜ืฉืึทื ืึทืœื–, ืื™ืจ ื•ื•ืขื˜ ื”ืึธื‘ืŸ ืฆื• ืœื™ื™ื’ืŸ 6 ืžืขืจ ื›ึผืœืœื™ื. [IP]->[Routes]ั type=blackhole. ืื™ืŸ ื“ื™ ืคืจื™ืขืจื“ื™ืงืข ื•ื•ืขืจืกื™ืข - 3 ื›ึผืœืœื™ื ืื™ืŸ [IP]->[Route]->[Rules].

ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’ ืคื•ืŸ ื‘ืึทื ื™ืฆืขืจ ืงืึทื ืขืงืฉืึทื ื– ื“ื•ืจืš ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ื˜ืฉืึทื ืึทืœื–

ืคึผืฉื•ื˜, ื•ื•ืึธื›ืขื“ื™ืง ื˜ืึทืกืงืก. ื•ื•ื™ื“ืขืจ, ื ืึธืš ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื“ืืจืฃ:

/ip route
add dst-address=0.0.0.0/0 gateway=10.10.10.1 dist=1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=10.20.20.1 dist=2 check-gateway=ping

add dst-address=0.0.0.0/0 gateway=10.10.10.1 dist=1 routing-mark=over-isp1
add dst-address=0.0.0.0/0 gateway=10.20.20.1 dist=1 routing-mark=over-isp2

ื ื™ืฆืŸ [IP]->[Route]->[Rules]
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

/ip route rules
add src-address=192.168.100.0/25 action=lookup-only-in-table table=over-isp1
add src-address=192.168.100.128/25 action=lookup-only-in-table table=over-isp2

ืื•ื™ื‘ ื ื•ืฆืŸ action=lookup, ื“ืขืžืึธืœื˜ ื•ื•ืขืŸ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ื˜ืฉืึทื ืึทืœื– ืื™ื– ืคืึทืจืงืจื™ืคึผืœื˜, ื“ืขืจ ืคืึทืจืงืขืจ ื•ื•ืขื˜ ื’ื™ื™ืŸ ืฆื• ื“ื™ ื”ื•ื™ืคึผื˜ ื˜ื™ืฉ ืื•ืŸ ื’ื™ื™ืŸ ื“ื•ืจืš ื“ื™ ืึทืจื‘ืขื˜ ืงืึทื ืึทืœ. ืฆื™ ื“ืึธืก ืื™ื– ื ื™ื™ื˜ื™ืง ืึธื“ืขืจ ื ื™ื˜ ื“ืขืคึผืขื ื“ืก ืื•ื™ืฃ ื“ื™ ืึทืจื‘ืขื˜.

ื ื™ืฆืŸ ื“ื™ ืžืึทืจืงื™ื ื’ื– ืื™ืŸ [IP]->[Firewall]->[Mangle]
ื ืคึผืฉื•ื˜ ื‘ื™ื™ึทืฉืคึผื™ืœ ืžื™ื˜ ืจืฉื™ืžื•ืช ืคื•ืŸ IP ืึทื“ืจืขืกืขืก. ืื™ืŸ ืคึผืจื™ื ืฆื™ืคึผ, ื›ึผืžืขื˜ ืงื™ื™ืŸ ื‘ืื“ื™ื ื’ื•ื ื’ืขืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜. ื“ืขืจ ื‘ืœื•ื™ื– ืงื™ื™ื•ื•ื™ืึทื˜ ืคื•ืŸ Layer7, ืืคื™ืœื• ื•ื•ืขืŸ ืคึผืขืจื“ ืžื™ื˜ ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ ืœืึทื‘ืขืœืก, ืขืก ืงืขืŸ ื•ื™ืกืงื•ืžืขืŸ ืึทื– ืึทืœืฅ ืึทืจื‘ืขื˜ ืจื™ื›ื˜ื™ืง, ืึธื‘ืขืจ ืขื˜ืœืขื›ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืคืึทืจืงืขืจ ื•ื•ืขื˜ ื ืึธืš ื’ื™ื™ืŸ ื“ื™ ืื•ืžืจืขื›ื˜ ื•ื•ืขื’.
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

/ip firewall mangle
add chain=prerouting src-address-list=users-over-isp1 dst-address-type=!local action=mark-routing new-routing-mark=over-isp1
add chain=prerouting src-address-list=users-over-isp2 dst-address-type=!local action=mark-routing new-routing-mark=over-isp2

ืื™ืจ ืงืขื ืขืŸ "ืฉืœืึธืก" ื ื™ืฆืขืจืก ืื™ืŸ ืื™ื™ืŸ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ ื“ื•ืจืš [IP]->[Route]->[Rules]:

/ip route rules
add routing-mark=over-isp1 action=lookup-only-in-table table=over-isp1
add routing-mark=over-isp2 action=lookup-only-in-table table=over-isp2

ืึธื“ืขืจ ื“ื•ืจืš [IP]->[Firewall]->[Filter]:

/ip firewall filter
add chain=forward routing-mark=over-isp1 out-interface=!ether1 action=reject
add chain=forward routing-mark=over-isp2 out-interface=!ether2 action=reject

ืจืขื˜ืจืขืึทื˜ ืคึผืจืึธ dst-address-type=!local
ื ืึธืš ืฆื•ืฉื˜ืึทื ื“ dst-address-type=!local ืขืก ืื™ื– ื ื™ื™ื˜ื™ืง ืึทื– ืคืึทืจืงืขืจ ืคื•ืŸ ื ื™ืฆืขืจืก ื“ืขืจื’ืจื™ื™ื›ืŸ ื“ื™ ื”ื™ื’ืข ืคึผืจืึทืกืขืกืึทื– ืคื•ืŸ ื“ื™ ืจืึทื•ื˜ืขืจ (dns, winbox, ssh, ...). ืื•ื™ื‘ ืขื˜ืœืขื›ืข ื”ื™ื’ืข ืกื•ื‘ื ืขืฅ ื–ืขื ืขืŸ ืงืึธื ื ืขืงื˜ืขื“ ืฆื• ื“ื™ ืจืึทื•ื˜ืขืจ, ืขืก ืื™ื– ื ื™ื™ื˜ื™ืง ืฆื• ืขื ืฉื•ืจ ืึทื– ื“ืขืจ ืคืึทืจืงืขืจ ืฆื•ื•ื™ืฉืŸ ื–ื™ื™ ื˜ื•ื˜ ื ื™ืฉื˜ ื’ื™ื™ืŸ ืฆื• ื“ื™ ืื™ื ื˜ืขืจื ืขื˜, ืœืžืฉืœ, ื ื™ืฆืŸ dst-address-table.

ืื™ืŸ ื“ืขื ื‘ื™ื™ึทืฉืคึผื™ืœ ื ื™ืฆืŸ [IP]->[Route]->[Rules] ืขืก ื–ืขื ืขืŸ ื ื™ื˜ ืึทื–ืึท ืื•ื™ืกื ืขืžืขืŸ, ืึธื‘ืขืจ ืคืึทืจืงืขืจ ืจื™ื˜ืฉืึทื– ื”ื™ื’ืข ืคึผืจืึทืกืขืกืึทื–. ื“ืขืจ ืคืึทืงื˜ ืื™ื– ืึทื– ืื™ืจ ื‘ืึทืงื•ืžืขืŸ ืื™ืŸ ื“ื™ FIB ืคึผืขืงืœ ืื ื’ืขืฆื™ื™ื›ื ื˜ ืื™ืŸ [PREROUTING|Mangle] ื”ืื˜ ืึท ืžืึทืจืฉืจื•ื˜ ืคื™ืจืžืข ืื•ืŸ ื’ื™ื™ื˜ ืื™ืŸ ืึท ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ ืื ื“ืขืจืข ื•ื•ื™ ื”ื•ื™ืคึผื˜, ื•ื•ื• ืขืก ืื™ื– ืงื™ื™ืŸ ื”ื™ื’ืข ืฆื•ื‘ื™ื ื“. ืื™ืŸ ื“ืขื ืคืึทืœ ืคื•ืŸ ืจื•ื˜ื™ื ื’ ืจื•ืœืขืก, ืขืจืฉื˜ืขืจ ืขืก ืื™ื– ืึธืคึผื’ืขืฉื˜ืขืœื˜ ืฆื™ ื“ื™ ืคึผืึทืงืึทื˜ ืื™ื– ื‘ื“ืขื” ืคึฟืึทืจ ืึท ื”ื™ื’ืข ืคึผืจืึธืฆืขืก ืื•ืŸ ื‘ืœื•ื™ื– ืื™ืŸ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ PBR ื‘ื™ื ืข ื’ื™ื™ื˜ ืขืก ืฆื• ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ.

ื ื™ืฆืŸ [IP]->[Firewall]->[Mangle action=route]
ื“ืขืจ ืงืึทืžืฃ ืึทืจื‘ืขื˜ ื‘ืœื•ื™ื– ืื™ืŸ [Prerouting|Mangle] ืื•ืŸ ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืคื™ืจืŸ ืคืึทืจืงืขืจ ืฆื• ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ื’ื™ื™ื˜ื•ื•ื™ื™ ืึธืŸ ื ื™ืฆืŸ ื ืึธืš ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ, ื“ื•ืจืš ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ ืึทื“ืจืขืก ื’ืœื™ื™ึทืš:

/ip firewall mangle
add chain=prerouting src-address=192.168.100.0/25 action=route gateway=10.10.10.1
add chain=prerouting src-address=192.168.128.0/25 action=route gateway=10.20.20.1

ืงืึทืžืฃ route ื”ืื˜ ืึท ื ื™ื“ืขืจื™ืงืขืจ ื‘ื™ืœื›ืขืจืงื™ื™ึทื˜ ื•ื•ื™ ืจื•ื˜ื™ื ื’ ื›ึผืœืœื™ื ([IP]->[Route]->[Rules]). ืื™ืŸ ื“ืขื ืคืึทืœ ืคื•ืŸ ืžืึทืจืฉืจื•ื˜ ืžืึทืจืงืก, ืึทืœืฅ ื“ืขืคึผืขื ื“ืก ืื•ื™ืฃ ื“ื™ ืฉื˜ืขืœืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ื›ึผืœืœื™ื, ืื•ื™ื‘ ื“ื™ ื”ืขืจืฉืŸ ืžื™ื˜ action=route ื•ื•ืขืจื˜ ืžืขืจ ื•ื•ื™ action=mark-route, ื“ืขืžืึธืœื˜ ืขืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ (ืจืึทื’ืึทืจื“ืœืึทืก ืคื•ืŸ ื“ื™ ืคืึธืŸ passtrough), ืึทื ื“ืขืจืฉ ืžืึทืจืงื™ื ื’ ื“ื™ ืžืึทืจืฉืจื•ื˜.
ืขืก ืื™ื– ื–ื™ื™ืขืจ ืงืœื™ื™ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืื•ื™ืฃ ื“ื™ ื•ื•ื™ืงื™ ื•ื•ืขื’ืŸ ื“ืขื ืงืึทืžืฃ ืื•ืŸ ืึทืœืข ืงืึทื ืงืœื•ื–ืฉืึทื ื– ื–ืขื ืขืŸ ื‘ืืงื•ืžืขืŸ ื™ืงืกืคึผืขืจืžืขื ืึทืœื™, ืื™ืŸ ืงื™ื™ืŸ ืคืึทืœ, ืื™ืš ื”ืื˜ ื ื™ืฉื˜ ื’ืขืคึฟื™ื ืขืŸ ืึธืคึผืฆื™ืขืก ื•ื•ืขืŸ ื ื™ืฆืŸ ื“ืขื ืึธืคึผืฆื™ืข ื’ื™ื˜ ืึทื“ื•ื•ืึทื ื˜ื™ื“ื–ืฉื™ื– ืื™ื‘ืขืจ ืื ื“ืขืจืข.

ื“ื™ื ืึทืžื™ืฉ ื‘ืึทืœืึทื ืกื™ื ื’ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ืคึผืคึผืง

ืคึผืขืจ ืงืึทื ืขืงืฉืึทืŸ ืงืœืึทืกืกื™ืคื™ืขืจ - ืื™ื– ืึท ืžืขืจ ืคืœืขืงืกืึทื‘ืึทืœ ืึทื ืึทืœืึธื’ ืคื•ืŸ ECMP. ื ื™ื˜ ืขื ืœืขืš ECMP, ืขืก ื“ื™ื•ื•ื™ื™ื“ื– ืคืึทืจืงืขืจ ื“ื•ืจืš ืงืึทื ืขืงืฉืึทื ื– ืžืขืจ ืฉื˜ืจืขื ื’ (ECMP ื•ื•ื™ื™ืกื˜ ื’ืึธืจื ื™ืฉื˜ ื•ื•ืขื’ืŸ ืงืึทื ืขืงืฉืึทื ื–, ืึธื‘ืขืจ ื•ื•ืขืŸ ืคึผืขืจื“ ืžื™ื˜ ืจื•ื˜ื™ื ื’ ืงืึทืฉ, ืขืคึผืขืก ืขื ืœืขืš ืื™ื– ื‘ืืงื•ืžืขืŸ).

PCC ื ืขืžื˜ ืกืคึผืขืกืึทืคื™ื™ื“ ืคืขืœื“ืขืจ ืคื•ืŸ ื“ื™ IP ื›ืขื“ืขืจ, ืงืึทื ื•ื•ืขืจืฅ ื–ื™ื™ ืฆื• ืึท 32-ื‘ื™ืกืœ ื•ื•ืขืจื˜, ืื•ืŸ ื“ื™ื•ื•ื™ื™ื“ื– ื“ื•ืจืš ื“ืขื ืึธืžื™ื ืึทื˜ืึธืจ. ื“ื™ ืจืขืฉื˜ ืคื•ืŸ ื“ื™ ืึธืคึผื˜ื™ื™ืœ ืื™ื– ืงืึทืžืคึผืขืจื“ ืžื™ื˜ ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ืจืขืฉื˜ ืื•ืŸ ืื•ื™ื‘ ื–ื™ื™ ื’ืœื™ื™ึทื›ืŸ, ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ืงืึทืžืฃ ืื™ื– ื’ืขื•ื•ืขื ื“ื˜. ืžืขืจ. ืกืึธื•ื ื“ืก ืžืขืฉื•ื’ืข, ืึธื‘ืขืจ ืขืก ืึทืจื‘ืขื˜.
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ื‘ื™ื™ืฉืคึผื™ืœ ืžื™ื˜ ื“ืจื™ื™ ืึทื“ืจืขืกืขืก:

192.168.100.10: 192+168+100+10 = 470 % 3 = 2
192.168.100.11: 192+168+100+11 = 471 % 3 = 0
192.168.100.12: 192+168+100+12 = 472 % 3 = 1

ืึท ื‘ื™ื™ืฉืคึผื™ืœ ืคื•ืŸ ื“ื™ื ืึทืžื™ืฉ ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’ ืคื•ืŸ ืคืึทืจืงืขืจ ื“ื•ืจืš src.address ืฆื•ื•ื™ืฉืŸ ื“ืจื™ื™ ื˜ืฉืึทื ืึทืœื–:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

#ะขะฐะฑะปะธั†ะฐ ะผะฐั€ัˆั€ัƒั‚ะธะทะฐั†ะธะธ
/ip route
add dst-address=0.0.0.0/0 gateway=10.10.10.1 dist=1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=10.20.20.1 dist=2 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=10.30.30.1 dist=3 check-gateway=ping

add dst-address=0.0.0.0/0 gateway=10.10.10.1 dist=1 routing-mark=over-isp1
add dst-address=0.0.0.0/0 gateway=10.20.20.1 dist=1 routing-mark=over-isp2
add dst-address=0.0.0.0/0 gateway=10.30.30.1 dist=1 routing-mark=over-isp3

#ะœะฐั€ะบะธั€ะพะฒะบะฐ ัะพะตะดะธะฝะตะฝะธะน ะธ ะผะฐั€ัˆั€ัƒั‚ะพะฒ
/ip firewall mangle
add chain=prerouting in-interface=br-lan dst-address-type=!local connection-state=new per-connection-classifier=src-address:3/0 action=mark-connection new-connection-mark=conn-over-isp1
add chain=prerouting in-interface=br-lan dst-address-type=!local connection-state=new per-connection-classifier=src-address:3/1 action=mark-connection new-connection-mark=conn-over-isp2
add chain=prerouting in-interface=br-lan dst-address-type=!local connection-state=new per-connection-classifier=src-address:3/2 action=mark-connection new-connection-mark=conn-over-isp3

add chain=prerouting in-interface=br-lan connection-mark=conn-over-isp1 action=mark-routing new-routing-mark=over-isp1
add chain=prerouting in-interface=br-lan connection-mark=conn-over-isp2 action=mark-routing new-routing-mark=over-isp2
add chain=prerouting in-interface=br-lan connection-mark=conn-over-isp3 action=mark-routing new-routing-mark=over-isp3

ื•ื•ืขืŸ ืžืึทืจืงื™ื ื’ ืจื•ืฅ, ืขืก ืื™ื– ืึทืŸ ื ืึธืš ืฆื•ืฉื˜ืึทื ื“: in-interface=br-lan, ืืŸ ืขืก ืื•ื ื˜ืขืจ action=mark-routing ืขื ื˜ืคืขืจ ืคืึทืจืงืขืจ ืคื•ืŸ ื“ื™ ืื™ื ื˜ืขืจื ืขื˜ ื•ื•ืขื˜ ื‘ืึทืงื•ืžืขืŸ ืื•ืŸ, ืื™ืŸ ืœื•ื™ื˜ ืžื™ื˜ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ, ื•ื•ืขื˜ ื’ื™ื™ืŸ ืฆื•ืจื™ืง ืฆื• ื“ืขืจ ืฉืคึผื™ื™ึทื–ืขืจ.

ื‘ืึทืฉื˜ื™ืžืขืŸ ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ื˜ืฉืึทื ืึทืœื–

ื˜ืฉืขืง ืคึผื™ื ื’ ืื™ื– ืึท ื’ื•ื˜ ื’ืขืฆื™ื™ึทื’, ืึธื‘ืขืจ ืขืก ื ืึธืจ ื˜ืฉืขืง ื“ื™ ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ ืžื™ื˜ ื“ื™ ื ื™ืจืึทืกื˜ IP ื™ื™ึทื ืงื•ืงื , ืคึผืจืึทื•ื•ื™ื™ื“ืขืจ ื ืขื˜ื•ื•ืึธืจืงืก ื™ื•ื–ืฉืึทื•ื•ืึทืœื™ ืฆื•ื ื•ื™ืคืฉื˜ืขืœื  ื–ื™ืš ืคื•ืŸ ืึท ื’ืจื•ื™ืก ื ื•ืžืขืจ ืคื•ืŸ ืจืึธื•ื˜ืขืจืก ืื•ืŸ ืึท ืงืฉืจ ื‘ืจืขื›ืŸ ืงืขืŸ ืคึผืึทืกื™ืจืŸ ืึทืจื•ื™ืก ื“ื™ ื ื™ืจืึทืกื˜ ื™ื™ึทื ืงื•ืงื , ืื•ืŸ ืขืก ื–ืขื ืขืŸ ื‘ืึทืงื‘ืึธื•ืŸ ื˜ืขืœืขืงืึธื ืึธืคึผืขืจื™ื™ื˜ืขืจื– ื•ื•ืึธืก ืงืขืŸ ืื•ื™ืš ื”ืึธื‘ืŸ ืคึผืจืึธื‘ืœืขืžืก, ืื™ืŸ ืึทืœื’ืขืžื™ื™ืŸ, ื˜ืฉืขืง ืคึผื™ื ื’ ื˜ื•ื˜ ื ื™ืฉื˜ ืฉื˜ืขื ื“ื™ืง ื•ื•ื™ื™ึทื–ืŸ ืึทืจื•ื™ืฃ-ืฆื•-ื˜ืึธื’ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืึทืงืกืขืก ืฆื• ื“ื™ ื’ืœืื‘ืืœืข ื ืขืฅ.
ืื•ื™ื‘ ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื– ืื•ืŸ ื’ืจื•ื™ืก ืงืึธืจืคึผืขืจื™ื™ืฉืึทื ื– ื”ืึธื‘ืŸ ื“ื™ BGP ื“ื™ื ืึทืžื™ืฉ ืจื•ื˜ื™ื ื’ ืคึผืจืึธื˜ืึธืงืึธืœ, ื”ื™ื™ื ืื•ืŸ ืึธืคื™ืก ื ื™ืฆืขืจืก ืžื•ื–ืŸ ื™ื ื“ื™ืคึผืขื ื“ืึทื ื˜ืœื™ ืจืขื›ืขื ืขืŸ ืื•ื™ืก ื•ื•ื™ ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืื™ื ื˜ืขืจื ืขื˜ ืึทืงืกืขืก ื“ื•ืจืš ืึท ืกืคึผืขืฆื™ืคื™ืฉ ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ืงืึทื ืึทืœ.

ื˜ื™ืคึผื™ืงืึทืœืœื™, ืกืงืจื™ืคึผืก ื–ืขื ืขืŸ ื’ืขื ื™ืฆื˜ ื•ื•ืึธืก, ื“ื•ืจืš ืึท ื–ื™ื›ืขืจ ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ืงืึทื ืึทืœ, ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืึทื•ื•ื™ื™ืœืึทื‘ื™ืœืึทื˜ื™ ืคื•ืŸ ืึทืŸ ื™ืคึผ ืึทื“ืจืขืก ืื•ื™ืฃ ื“ืขืจ ืื™ื ื˜ืขืจื ืขืฅ, ื‘ืฉืขืช ื˜ืฉื•ื–ื™ื ื’ ืขืคึผืขืก ืคืึทืจืœืึธื–ืœืขืš, ืœืžืฉืœ, Google dns: 8.8.8.8. 8.8.4.4. ืื‘ืขืจ ืื™ืŸ ื“ื™ ืžื™ืงืจืึธื˜ื™ืง ืงื”ืœ, ืึท ืžืขืจ ื˜ืฉื™ืงืึทื•ื•ืข ื’ืขืฆื™ื™ึทื’ ืื™ื– ืฆื•ื’ืขืคืืกื˜ ืคึฟืึทืจ ื“ืขื.

ืขื˜ืœืขื›ืข ื•ื•ืขืจื˜ืขืจ ื•ื•ืขื’ืŸ ืจืขืงื•ืจืกื™ื•ื•ืข ืจื•ื˜ื™ื ื’
ืจืขืงื•ืจืกื™ื•ื•ืข ืจื•ื˜ื™ื ื’ ืื™ื– ื ื™ื™ื˜ื™ืง ื•ื•ืขืŸ ืื™ืจ ื‘ื•ื™ืขืŸ Multihop BGP ืคึผื™ืจื™ื ื’ ืื•ืŸ ื‘ืึทืงื•ืžืขืŸ ืื™ืŸ ื“ืขื ืึทืจื˜ื™ืงืœ ื•ื•ืขื’ืŸ ื“ื™ ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ื‘ืœื•ื™ื– ืจืขื›ื˜ ืฆื• ื›ื™ื˜ืจืข ืžื™ืงืจืึธื˜ื™ืง ื™ื•ื–ืขืจื– ื•ื•ืึธืก ื”ืึธื‘ืŸ ื’ืขืคึฟื•ื ืขืŸ ื•ื•ื™ ืฆื• ื ื•ืฆืŸ ืจืขืงื•ืจืกื™ื•ื•ืข ืจื•ืฅ ืคึผืขืจื“ ืžื™ื˜ ื˜ืฉืขืง ื’ื™ื™ื˜ื•ื•ื™ื™ ืฆื• ื‘ืึทืฉื˜ื™ืžืขืŸ ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ื˜ืฉืึทื ืึทืœื– ืึธืŸ ื ืึธืš ืกืงืจื™ืคึผืก.

ืขืก ืื™ื– ืฆื™ื™ื˜ ืฆื• ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื“ื™ ืึธืคึผืฆื™ืขืก ืคึฟืึทืจ ืคืึทืจื ืขื / ืฆื™ืœ ืคืึทืจื ืขื ืื™ืŸ ืึทืœื’ืขืžื™ื™ืŸ ื˜ืขืจืžื™ื ืขืŸ ืื•ืŸ ื•ื•ื™ ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืื™ื– ื’ืขื‘ื•ื ื“ืŸ ืฆื• ื“ื™ ืฆื•ื‘ื™ื ื“:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

  1. ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืงื•ืงื˜ ืึท ืฆื•ื‘ื™ื ื“ ืฆื• ืฉื™ืงืŸ ื“ื™ ืคึผืึทืงืึทื˜ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื–ื™ื™ืŸ ืคืึทืจื ืขื ื•ื•ืขืจื˜ ืื•ืŸ ืึทืœืข ืื™ื™ื ืกืŸ ืื™ืŸ ื“ื™ ื”ื•ื™ืคึผื˜ ื˜ื™ืฉ ืžื™ื˜ ื•ื•ื™ื™ื ื™ืงืขืจ ื•ื•ื™ ืึธื“ืขืจ ื’ืœื™ื™ึทืš ืฆื™ืœ ืคืึทืจื ืขื ื•ื•ืึทืœื•ืขืก
  2. ืคึฟื•ืŸ ื“ื™ ื’ืขืคึฟื•ื ืขืŸ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–, ื“ืขืจ ืื™ื™ื ืขืจ ื“ื•ืจืš ื•ื•ืึธืก ืื™ืจ ืงืขื ืขืŸ ืฉื™ืงืŸ ืึท ืคึผืึทืงืึทื˜ ืฆื• ื“ื™ ืกืคึผืขืกืึทืคื™ื™ื“ ื’ื™ื™ื˜ื•ื•ื™ื™ ืื™ื– ืื•ื™ืกื’ืขืงืœื™ื‘ืŸ
  3. ื“ื™ ืฆื•ื‘ื™ื ื“ ืคื•ืŸ ื“ื™ ื’ืขืคึฟื•ื ืขืŸ ืงืึธื ื ืขืงื˜ืขื“ ืคึผืึธื–ื™ืฆื™ืข ืื™ื– ืื•ื™ืกื’ืขืงืœื™ื‘ืŸ ืฆื• ืฉื™ืงืŸ ื“ื™ ืคึผืึทืงืึทื˜ ืฆื• ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™

ืื™ืŸ ื“ืขื ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ืึท ืจืขืงื•ืจืกื™ื•ื•ืข ืžืึทืจืฉืจื•ื˜, ืึทืœืฅ ื›ืึทืคึผืึทื ื– ื“ื™ ื–ืขืœื‘ืข, ืึธื‘ืขืจ ืื™ืŸ ืฆื•ื•ื™ื™ ืกื˜ืึทื’ืขืก:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

  • 1-3 ืื™ื™ื ืขืจ ืžืขืจ ืžืึทืจืฉืจื•ื˜ ืื™ื– ืžื•ืกื™ืฃ ืฆื• ื“ื™ ืคืืจื‘ื•ื ื“ืŸ ืจื•ืฅ, ื“ื•ืจืš ื•ื•ืึธืก ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ื’ื™ื™ื˜ื•ื•ื™ื™ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืจื™ื˜ืฉื˜
  • 4-6 ื’ืขืคึฟื™ื ืขืŸ ื“ื™ ืžืึทืจืฉืจื•ื˜ ืคืืจื‘ื•ื ื“ืŸ ืžืึทืจืฉืจื•ื˜ ืคึฟืึทืจ ื“ื™ "ื™ื ื˜ืขืจืžื™ื“ื™ื™ื˜" ื’ื™ื™ื˜ื•ื•ื™ื™

ืึทืœืข ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทื ื– ืžื™ื˜ ื“ื™ ืจืขืงื•ืจืกื™ื•ื•ืข ื–ื•ื›ืŸ ืคืึทืœืŸ ืื™ืŸ ื“ื™ RIB, ืื•ืŸ ื‘ืœื•ื™ื– ื“ื™ ืœืขืฆื˜ ืจืขื–ื•ืœื˜ืึทื˜ ืื™ื– ื˜ืจืึทื ืกืคืขืจื“ ืฆื• ื“ื™ FIB: 0.0.0.0/0 via 10.10.10.1 on ether1.

ื ื‘ื™ื™ืฉืคึผื™ืœ ืคื•ืŸ ื ื™ืฆืŸ ืจืขืงื•ืจืกื™ื•ื•ืข ืจื•ื˜ื™ื ื’ ืฆื• ื‘ืึทืฉื˜ื™ืžืขืŸ ืจื•ืฅ
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

/ip route
add dst-address=0.0.0.0/0 gateway=8.8.8.8 check-gateway=ping distance=1 target-scope=10
add dst-address=8.8.8.8 gateway=10.10.10.1 scope=10
add dst-address=0.0.0.0/0 gateway=10.20.20.1 distance=2

ืื™ืจ ืงืขื ืขืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืึทื– ืคึผืึทืงื™ืฅ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขืฉื™ืงื˜ ืฆื• 10.10.10.1:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ื˜ืฉืขืง ื’ื™ื™ื˜ื•ื•ื™ื™ ื•ื•ื™ื™ืกื˜ ื’ืึธืจื ื™ืฉื˜ ื•ื•ืขื’ืŸ ืจืขืงื•ืจืกื™ื•ื•ืข ืจื•ื˜ื™ื ื’ ืื•ืŸ ืคืฉื•ื˜ ืกืขื ื“ื– ืคึผื™ื ื’ืก ืฆื• 8.8.8.8, ื•ื•ืึธืก (ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ ื”ื•ื™ืคึผื˜ ื˜ื™ืฉ) ืื™ื– ืฆื•ื˜ืจื™ื˜ืœืขืš ื“ื•ืจืš ื’ื™ื™ื˜ื•ื•ื™ื™ 10.10.10.1.

ืื•ื™ื‘ ืขืก ืื™ื– ืึท ืึธื ื•ื•ืขืจ ืคื•ืŸ ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ืฆื•ื•ื™ืฉืŸ 10.10.10.1 ืื•ืŸ 8.8.8.8, ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืื™ื– ื“ื™ืกืงืึทื ืขืงื˜ื™ื“, ืึธื‘ืขืจ ืคึผืึทืงื™ืฅ (ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืคึผืจื•ื‘ื™ืจืŸ ืคึผื™ื ื’ืก) ืฆื• 8.8.8.8 ืคืึธืจื–ืขืฆืŸ ืฆื• ื’ื™ื™ืŸ ื“ื•ืจืš 10.10.10.1:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืื•ื™ื‘ ื“ื™ ืœื™ื ืง ืฆื• ether1 ืื™ื– ืคืึทืจืคืึทืœืŸ, ืึท ืคึผืจื™ืงืจืข ืกื™ื˜ื•ืึทืฆื™ืข ืึทืงืขืจื– ื•ื•ืขืŸ ืคึผืึทืงื™ืฅ ืื™ื™ื“ืขืจ 8.8.8.8 ื’ื™ื™ืŸ ื“ื•ืจืš ื“ื™ ืจื’ืข ืฉืคึผื™ื™ึทื–ืขืจ:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ื“ืึธืก ืื™ื– ืึท ืคึผืจืึธื‘ืœืขื ืื•ื™ื‘ ืื™ืจ ื ื•ืฆืŸ NetWatch ืฆื• ืœื•ื™ืคืŸ ืกืงืจื™ืคึผืก ื•ื•ืขืŸ 8.8.8.8 ืื™ื– ื ื™ื˜ ื‘ื ื™ืžืฆื. ืื•ื™ื‘ ื“ื™ ืœื™ื ืง ืื™ื– ืฆืขื‘ืจืื›ืŸ, NetWatch ื•ื•ืขื˜ ืคืฉื•ื˜ ืึทืจื‘ืขื˜ืŸ ื“ื•ืจืš ื“ื™ ื‘ืึทืงืึทืคึผ ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ืงืึทื ืึทืœ ืื•ืŸ ื™ื‘ืขืจื ืขืžืขืŸ ืึทื– ืึทืœืฅ ืื™ื– ื’ื•ื˜. ืกืึทืœื•ื•ื“ ื“ื•ืจืš ืึทื“ื™ื ื’ ืึทืŸ ื ืึธืš ืคื™ืœื˜ืขืจ ืžืึทืจืฉืจื•ื˜:

/ip route
add dst-address=8.8.8.8 gateway=10.20.20.1 distance=100 type=blackhole

ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืขืก ืื™ื– ืื•ื™ืฃ ื›ืึทื‘ืจืข ืึทืจื˜ื™ืงืœ, ื•ื•ื• ื“ื™ ืกื™ื˜ื•ืึทืฆื™ืข ืžื™ื˜ NetWatch ืื™ื– ื‘ืึทื˜ืจืึทื›ื˜ ืื™ืŸ ืžืขืจ ื“ืขื˜ืึทืœ.

ืื•ืŸ ื™ืึธ, ื•ื•ืขืŸ ื ื™ืฆืŸ ืึทื–ืึท ืึท ืจืขื–ืขืจื•ื•ืึทืฆื™ืข, ื“ื™ ืึทื“ืจืขืก 8.8.8.8 ื•ื•ืขื˜ ื–ื™ื™ืŸ ื›ืึทืจื“ื•ื•ื™ื™ืขืจื“ ืฆื• ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื–, ืึทื–ื•ื™ ื˜ืฉื•ื–ื™ื ื’ ืขืก ื•ื•ื™ ืึท ื“ื ืก ืžืงื•ืจ ืื™ื– ื ื™ืฉื˜ ืึท ื’ื•ื˜ ื’ืขื“ืึทื ืง.

ืขื˜ืœืขื›ืข ื•ื•ืขืจื˜ืขืจ ื•ื•ืขื’ืŸ ื•ื•ื™ืจื˜ื•ืึทืœ ืจื•ื˜ื™ื ื’ ืื•ืŸ ืคืึธืจื•ื•ืขืจื“ื™ื ื’ (VRF)

VRF ื˜ืขื›ื ืึธืœืึธื’ื™ืข ืื™ื– ื“ื™ื–ื™ื™ื ื“ ืฆื• ืฉืึทืคึฟืŸ ืขื˜ืœืขื›ืข ื•ื•ื™ืจื˜ื•ืึทืœ ืจืึธื•ื˜ืขืจืก ืื™ืŸ ืื™ื™ืŸ ืคื™ื–ื™ืฉ, ื“ื™ ื˜ืขื›ื ืึธืœืึธื’ื™ืข ืื™ื– ื•ื•ื™ื™ื“ืœื™ ื’ืขื ื™ืฆื˜ ื“ื•ืจืš ื˜ืขืœืขืงืึธื ืึธืคึผืขืจื™ื™ื˜ืขืจื– (ื™ื•ื–ืฉืึทื•ื•ืึทืœื™ ืื™ืŸ ืงืึทื ื“ื–ืฉืึทื ื’ืงืฉืึทืŸ ืžื™ื˜ MPLS) ืฆื• ืฆื•ืฉื˜ืขืœืŸ L3VPN ื‘ืึทื“ื™ื ื•ื ื’ืก ืฆื• ืงืœื™ื™ืึทื ืฅ ืžื™ื˜ ืึธื•ื•ื•ืขืจืœืึทืคึผื™ื ื’ ืกื•ื‘ื ืขื˜ ืึทื“ืจืขืกืขืก:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืึธื‘ืขืจ VRF ืื™ืŸ ืžื™ืงืจืึธื˜ื™ืง ืื™ื– ืึธืจื’ืึทื ื™ื–ื™ืจื˜ ืื•ื™ืฃ ื“ืขืจ ื‘ืื–ืข ืคื•ืŸ โ€‹โ€‹ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ ืื•ืŸ ื”ืื˜ ืึท ื ื•ืžืขืจ ืคื•ืŸ ื“ื™ืกืึทื“ื•ื•ืึทื ื˜ื™ื“ื–ืฉื™ื–, ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ื”ื™ื’ืข IP ืึทื“ืจืขืกืขืก ืคื•ืŸ ื“ื™ ืจืึทื•ื˜ืขืจ ื–ืขื ืขืŸ ื‘ื ื™ืžืฆื ืคื•ืŸ ืึทืœืข VRFs, ืื™ืจ ืงืขื ืขืŸ ืœื™ื™ืขื ืขืŸ ืžืขืจ ะฟะพ ััั‹ะปะบะต.

vrf ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื‘ื™ื™ึทืฉืคึผื™ืœ:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

/ip route vrf
add interfaces=ether1 routing-mark=vrf1
add interfaces=ether2 routing-mark=vrf2

/ip address
add address=192.168.100.1/24 interface=ether1 network=192.168.100.0
add address=192.168.200.1/24 interface=ether2 network=192.168.200.0

ืคึฟื•ืŸ ื“ื™ ืžื™ื˜ืœ ืงืึธื ื ืขืงื˜ืขื“ ืฆื• ether2, ืžื™ืจ ื–ืขืŸ ืึทื– ืคึผื™ื ื’ ื’ื™ื™ื˜ ืฆื• ื“ื™ ืจืึทื•ื˜ืขืจ ืึทื“ืจืขืก ืคึฟื•ืŸ ืืŸ ืื ื“ืขืจ ื•ื•ืจืฃ (ืื•ืŸ ื“ืึธืก ืื™ื– ืึท ืคึผืจืึธื‘ืœืขื), ื‘ืฉืขืช ืคึผื™ื ื’ ื’ื™ื™ื˜ ื ื™ืฉื˜ ืฆื• ื“ื™ ืื™ื ื˜ืขืจื ืขื˜:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืฆื• ืึทืงืกืขืก ื“ื™ ืื™ื ื˜ืขืจื ืขื˜, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืจืขื’ื™ืกื˜ืจื™ืจืŸ ืึทืŸ ื ืึธืš ืžืึทืจืฉืจื•ื˜ ื•ื•ืึธืก ืึทืงืกืขืก ื“ื™ ื”ื•ื™ืคึผื˜ ื˜ื™ืฉ (ืื™ืŸ vrf ื˜ืขืจืžื™ื ืึธืœืึธื’ื™ืข, ื“ืึธืก ืื™ื– ื’ืขืจื•ืคืŸ ืžืึทืจืฉืจื•ื˜ ืœื™ืงื™ื ื’):
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

/ip route
add distance=1 gateway=172.17.0.1@main routing-mark=vrf1
add distance=1 gateway=172.17.0.1%wlan1 routing-mark=vrf2

ื“ืึธ ื–ืขื ืขืŸ ืฆื•ื•ื™ื™ ื•ื•ืขื’ืŸ ืคื•ืŸ ืžืึทืจืฉืจื•ื˜ ืœื™ืงื™ื ื’: ื ื™ืฆืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ: 172.17.0.1@main ืื•ืŸ ื ื™ืฆืŸ ืฆื•ื‘ื™ื ื“ ื ืึธืžืขืŸ: 172.17.0.1%wlan1.

ืื•ืŸ ืฉื˜ืขืœืŸ ืึทืจื•ื™ืฃ ืžืึทืจืงื™ื ื’ ืคึฟืึทืจ ืฆื•ืจื™ืงืงื•ืžืขืŸ ืคืึทืจืงืขืจ ืื™ืŸ [PREROUTING|Mangle]:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

/ip firewall mangle
add chain=prerouting in-interface=ether1 action=mark-connection new-connection-mark=from-vrf1 passthrough=no
add chain=prerouting connection-mark=from-vrf1 routing-mark=!vrf1 action=mark-routing new-routing-mark=vrf1 passthrough=no 
add chain=prerouting in-interface=ether2 action=mark-connection new-connection-mark=from-vrf2 passthrough=no
add chain=prerouting connection-mark=from-vrf2 routing-mark=!vrf1 action=mark-routing new-routing-mark=vrf2 passthrough=no 

ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืกื•ื‘ื ืขืฅ ืžื™ื˜ ื“ื™ ื–ืขืœื‘ืข ืึทื“ืจืขืก
ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ืึทืงืกืขืก ืฆื• ืกื•ื‘ื ืขืฅ ืžื™ื˜ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืึทื“ืจืขืกื™ื ื’ ืื•ื™ืฃ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืจืึทื•ื˜ืขืจ ื ื™ืฆืŸ VRF ืื•ืŸ ื ืขื˜ืžืึทืคึผ:
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ื™ืงืขืจื“ื™ืง ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ:

/ip route vrf
add interfaces=ether1 routing-mark=vrf1
add interfaces=ether2 routing-mark=vrf2

/ip address
add address=192.168.100.1/24 interface=ether1 network=192.168.100.0
add address=192.168.100.1/24 interface=ether2 network=192.168.100.0
add address=192.168.0.1/24 interface=ether3 network=192.168.0.0

ืคื™ืจืขื•ื•ืึทืœืœ ื›ึผืœืœื™ื:

#ะœะฐั€ะบะธั€ัƒะตะผ ะฟะฐะบะตั‚ั‹ ะดะปั ะพั‚ะฟั€ะฐะฒะบะธ ะฒ ะฟั€ะฐะฒะธะปัŒะฝัƒัŽ ั‚ะฐะฑะปะธั†ัƒ ะผะฐั€ัˆั€ัƒั‚ะธะทะฐั†ะธะธ
/ip firewall mangle
add chain=prerouting dst-address=192.168.101.0/24 in-interface=ether3 action=mark-routing new-routing-mark=vrf1 passthrough=no
add chain=prerouting dst-address=192.168.102.0/24 in-interface=ether3 action=mark-routing new-routing-mark=vrf2 passthrough=no

#ะกั€ะตะดัั‚ะฒะฐะผะธ netmap ะทะฐะผะตะฝัะตะผ ะฐะดั€ะตัะฐ "ัั„ะธะผะตั€ะฝั‹ั…" ะฟะพะดัะตั‚ะตะน ะฝะฐ ั€ะตะฐะปัŒะฝั‹ะต ะฟะพะดัะตั‚ะธ
/ip firewall nat
add chain=dstnat dst-address=192.168.101.0/24 in-interface=ether3 action=netmap to-addresses=192.168.100.0/24
add chain=dstnat dst-address=192.168.102.0/24 in-interface=ether3 action=netmap to-addresses=192.168.100.0/24

ืจื•ื˜ื™ื ื’ ื›ึผืœืœื™ื ืคึฟืึทืจ ืฆื•ืจื™ืงืงื•ืžืขืŸ ืคืึทืจืงืขืจ:

#ะฃะบะฐะทะฐะฝะธะต ะธะผะตะฝะธ ะธะฝั‚ะตั€ั„ะตะนัะฐ ั‚ะพะถะต ะผะพะถะตั‚ ัั‡ะธั‚ะฐั‚ัŒัั route leaking, ะฝะพ ะฟะพ ััƒั‚ะธ ั‚ัƒั‚ ัะพะทะดะฐะตั‚ัั ะฐะฝะฐะปะพะณ connected ะผะฐั€ัˆั€ัƒั‚ะฐ
/ip route
add distance=1 dst-address=192.168.0.0/24 gateway=ether3 routing-mark=vrf1
add distance=1 dst-address=192.168.0.0/24 gateway=ether3 routing-mark=vrf2

ืึทื“ื™ื ื’ ืจื•ืฅ ื‘ืืงื•ืžืขืŸ ื“ื•ืจืš dhcp ืฆื• ืึท ื’ืขื’ืขื‘ืŸ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ
VRF ืงืขืŸ ื–ื™ื™ืŸ ื˜ืฉื™ืงืึทื•ื•ืข ืื•ื™ื‘ ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืœื™ื™ื’ืŸ ืึท ื“ื™ื ืึทืžื™ืฉ ืžืึทืจืฉืจื•ื˜ (ืœืžืฉืœ ืคึฟื•ืŸ ืึท dhcp ืงืœื™ืขื ื˜) ืฆื• ืึท ืกืคึผืขืฆื™ืคื™ืฉ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ.

ืึทื“ื™ื ื’ ืฆื•ื‘ื™ื ื“ ืฆื• vrf:

/ip route vrf
add interface=ether1 routing-mark=over-isp1

ื›ึผืœืœื™ื ืคึฟืึทืจ ืฉื™ืงื˜ ืคืึทืจืงืขืจ (ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืื•ืŸ ื“ื•ืจื›ืคืึธืจ) ื“ื•ืจืš ื“ื™ ื˜ื™ืฉ over-isp1:

/ip firewall mangle
add chain=output out-interface=!br-lan action=mark-routing new-routing-mark=over-isp1 passthrough=no
add chain=prerouting in-interface=br-lan dst-address-type=!local action=mark-routing new-routing-mark=over-isp1 passthrough=no

ื ืึธืš ืฉื•ื•ื™ื ื“ืœ ืžืึทืจืฉืจื•ื˜ ืคึฟืึทืจ ืึทื•ื˜ื‘ืึทื•ื ื“ ืจื•ื˜ื™ื ื’ ืฆื• ืึทืจื‘ืขื˜ืŸ:

/interface bridge
add name=bare

/ip route
add dst-address=0.0.0.0/0 gateway=bare

ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืื™ื– ื ืึธืจ ื“ืืจืฃ ืึทื–ื•ื™ ืึทื– ื”ื™ื’ืข ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืคึผืึทืงื™ืฅ ืงืขื ืขืŸ ืคืึธืจืŸ ื“ื•ืจืš ื“ื™ ืจื•ื˜ื™ื ื’ ื‘ืึทืฉืœื•ืก (2) ืคืจื™ืขืจ [OUTPUT|Mangle] ืื•ืŸ ื‘ืึทืงื•ืžืขืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ืคื™ืจืžืข, ืื•ื™ื‘ ืขืก ื–ืขื ืขืŸ ืื ื“ืขืจืข ืึทืงื˜ื™ื•ื• ืจื•ืฅ ืื•ื™ืฃ ื“ื™ ืจืึทื•ื˜ืขืจ ืื™ื™ื“ืขืจ 0.0.0.0/0 ืื™ืŸ ื“ื™ ื”ื•ื™ืคึผื˜ ื˜ื™ืฉ, ืขืก ืื™ื– ื ื™ืฉื˜ ืคืืจืœืื ื’ื˜.
ื‘ืึทืกื™ืงืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ื˜ื™ื ื’ ืื™ืŸ Mikrotik RouterOS

ืงื™ื™ื˜ืŸ connected-in ะธ dynamic-in ะฒ [Routing] -> [Filters]

ืจื•ื˜ ืคึฟื™ืœื˜ืจื™ืจื•ื ื’ (ื™ื ื‘ืึทื•ื ื“ ืื•ืŸ ืึทื•ื˜ื‘ืึทื•ื ื“) ืื™ื– ืึท ื’ืขืฆื™ื™ึทื’ ื•ื•ืึธืก ืื™ื– ื™ื•ื–ืฉืึทื•ื•ืึทืœื™ ื’ืขื ื™ืฆื˜ ืื™ืŸ ืงืึทื ื“ื–ืฉืึทื ื’ืงืฉืึทืŸ ืžื™ื˜ ื“ื™ื ืึทืžื™ืฉ ืจื•ื˜ื™ื ื’ ืคึผืจืึธื˜ืึธืงืึธืœืก (ืื•ืŸ ื“ืขืจื™ื‘ืขืจ ื‘ืœื•ื™ื– ื‘ื ื™ืžืฆื ื ืึธืš ื™ื ืกื˜ืึธืœื™ื ื’ ื“ื™ ืคึผืขืงืœ) ืจื•ื˜ื™ื ื’), ืึธื‘ืขืจ ืขืก ื–ืขื ืขืŸ ืฆื•ื•ื™ื™ ื˜ืฉื™ืงืึทื•ื•ืข ืงื™ื™ื˜ืŸ ืื™ืŸ ื“ื™ ื™ื ืงืึทืžื™ื ื’ ืคื™ืœื˜ืขืจืก:

  • ืงืึธื ื ืขืงื˜ืขื“-ืื™ืŸ - ืคื™ืœื˜ืขืจื™ื ื’ ืคืืจื‘ื•ื ื“ืŸ ืจื•ืฅ
  • ื“ื™ื ืึทืžื™ืฉ-ืื™ืŸ - ืคื™ืœื˜ืขืจื™ื ื’ ื“ื™ื ืึทืžื™ืฉ ืจื•ืฅ ื‘ืืงื•ืžืขืŸ ื“ื•ืจืš PPP ืื•ืŸ DCHP

ืคึฟื™ืœื˜ืจื™ืจื•ื ื’ ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื ื™ืฉื˜ ื‘ืœื•ื™ื– ืึทื•ื•ืขืงื•ื•ืึทืจืคืŸ ืจื•ืฅ, ืึธื‘ืขืจ ืื•ื™ืš ื˜ื•ื™ืฉืŸ ืึท ื ื•ืžืขืจ ืคื•ืŸ ืึธืคึผืฆื™ืขืก: ื“ื™ืกื˜ืึทื ืกืข, ืจื•ื˜ื™ื ื’-ืžืึทืจืง, ื‘ืึทืžืขืจืงื•ื ื’, ืคืึทืจื ืขื, ืฆื™ืœ ืคืึทืจื ืขื, ...

ื“ืึธืก ืื™ื– ืึท ื–ื™ื™ืขืจ ื’ืขื ื•ื™ ื’ืขืฆื™ื™ึทื’ ืื•ืŸ ืื•ื™ื‘ ืื™ืจ ืงืขื ืขืŸ ื˜ืึธืŸ ืขืคึผืขืก ืึธืŸ ืจื•ื˜ื™ื ื’ ืคื™ืœื˜ืขืจืก (ืึธื‘ืขืจ ื ื™ืฉื˜ ืกืงืจื™ืคึผืก), ื˜ืึธืŸ ื ื™ื˜ ื ื•ืฆืŸ ืจื•ื˜ื™ื ื’ ืคื™ืœื˜ืขืจืก, ื˜ืึธืŸ ื ื™ื˜ ืฆืขืžื™ืฉืŸ ื–ื™ืš ืื•ืŸ ื“ื™ ื•ื•ืืก ื•ื•ืขืœืŸ ืงืึทื ืคื™ื’ื™ืขืจ ื“ื™ ืจืึทื•ื˜ืขืจ ื ืึธืš ืื™ืจ. ืื™ืŸ ื“ืขื ืงืึธื ื˜ืขืงืกื˜ ืคื•ืŸ ื“ื™ื ืึทืžื™ืฉ ืจื•ื˜ื™ื ื’, ืจื•ื˜ื™ื ื’ ืคื™ืœื˜ืขืจืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืคื™ืœ ืžืขืจ ืึธืคื˜ ืื•ืŸ ืžืขืจ ืคึผืจืึธื“ื•ืงื˜ื™ื•ื•.

ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ืžืืจืง ืคึฟืึทืจ ื“ื™ื ืึทืžื™ืฉ ืจืึธื•ื˜ืขืก
ื ื‘ื™ื™ืฉืคึผื™ืœ ืคื•ืŸ ืึท ื”ื™ื™ื ืจืึทื•ื˜ืขืจ. ืื™ืš ื”ืึธื‘ืŸ ืฆื•ื•ื™ื™ VPN ืงืึทื ืขืงืฉืึทื ื– ืงืึทื ืคื™ื’ื™ืขืจื“ ืื•ืŸ ื“ื™ ืคืึทืจืงืขืจ ืื™ืŸ ื–ื™ื™ ื–ืึธืœ ื–ื™ื™ืŸ ืืœื ื’ืขื•ื•ื™ืงืœื˜ ืื™ืŸ ืœื•ื™ื˜ ืžื™ื˜ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ. ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜, ืื™ืš ื•ื•ื™ืœืŸ ื“ื™ ืจื•ืฅ ืฆื• ื–ื™ื™ืŸ ื‘ืืฉืืคืŸ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื•ื•ืขืŸ ื“ื™ ืฆื•ื‘ื™ื ื“ ืื™ื– ืึทืงื˜ื™ื•ื•ื™ื™ื˜ื™ื“:

#ะŸั€ะธ ัะพะทะดะฐะฝะธะธ vpn ะฟะพะดะบะปัŽั‡ะตะฝะธะน ัƒะบะฐะทั‹ะฒะฐะตะผ ัะพะทะดะฐะฝะธะต default route ะธ ะทะฐะดะฐะตะผ ะดะธัั‚ะฐะฝั†ะธัŽ
/interface pptp-client
add connect-to=X.X.X.X add-default-route=yes default-route-distance=101 ...
add connect-to=Y.Y.Y.Y  add-default-route=yes default-route-distance=100 ...

#ะคะธะปัŒั‚ั€ะฐะผะธ ะพั‚ะฟั€ะฐะฒะปัะตะผ ะผะฐั€ัˆั€ัƒั‚ั‹ ะฒ ะพะฟั€ะตะดะตะปะตะฝะฝั‹ะต ั‚ะฐะฑะปะธั†ั‹ ะผะฐั€ัˆั€ัƒั‚ะธะทะฐั†ะธะธ ะฝะฐ ะพัะฝะพะฒะต ะฟะพะดัะตั‚ะธ ะฝะฐะทะฝะฐั‡ะตะฝะธั ะธ ะดะธัั‚ะฐะฝั†ะธะธ
/routing filter
add chain=dynamic-in distance=100 prefix=0.0.0.0/0 action=passthrough set-routing-mark=over-vpn1
add chain=dynamic-in distance=101 prefix=0.0.0.0/0 action=passthrough set-routing-mark=over-vpn2

ืื™ืš ื˜ืึธืŸ ื ื™ื˜ ื•ื•ื™ืกืŸ ื•ื•ืึธืก, ืžื™ืกื˜ืึธืžืข ืึท ื–ืฉื•ืง, ืึธื‘ืขืจ ืื•ื™ื‘ ืื™ืจ ืžืึทื›ืŸ ืึท VRF ืคึฟืึทืจ ื“ื™ ืคึผืคึผืคึผ ืฆื•ื‘ื™ื ื“, ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืฆื• 0.0.0.0/0 ื•ื•ืขื˜ ื ืึธืš ื‘ืึทืงื•ืžืขืŸ ืื™ืŸ ื“ื™ ื”ื•ื™ืคึผื˜ ื˜ื™ืฉ. ืึทื ื“ืขืจืฉ, ืึทืœืฅ ื•ื•ืึธืœื˜ ื–ื™ื™ืŸ ืืคื™ืœื• ื’ืจื™ื ื’ืขืจ.

ื“ื™ืกื™ื™ื‘ืœื™ื ื’ ืงืึธื ื ืขืงื˜ืขื“ ืจืึธื•ื˜ืขืก
ืžืืœ ื“ืึธืก ืื™ื– ืคืืจืœืื ื’ื˜:

/route filter
add chain=connected-in prefix=192.168.100.0/24 action=reject

ื“ื™ื‘ืึทื’ื™ื ื’ ืžื›ืฉื™ืจื™ื

RouterOS ื’ื™ื˜ ืึท ื ื•ืžืขืจ ืคื•ืŸ ืžื›ืฉื™ืจื™ื ืคึฟืึทืจ ื“ื™ื‘ืึทื’ื™ื ื’ ืจื•ื˜ื™ื ื’:

  • [Tool]->[Tourch] - ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื–ืขืŸ ืคึผืึทืงื™ืฅ ืื•ื™ืฃ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–
  • /ip route check - ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื–ืขืŸ ื•ื•ืึธืก ื’ื™ื™ื˜ื•ื•ื™ื™ ื“ื™ ืคึผืึทืงืึทื˜ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขืฉื™ืงื˜ ืฆื•, ื˜ื•ื˜ ื ื™ืฉื˜ ืึทืจื‘ืขื˜ืŸ ืžื™ื˜ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉืŸ
  • /ping routing-table=<name> ะธ /tool traceroute routing-table=<name> - ืคึผื™ื ื’ ืื•ืŸ ืฉืคึผื•ืจ ื ื™ืฆืŸ ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ
  • action=log ะฒ [IP]->[Firewall] - ืึท ื•ื™ืกื’ืขืฆื™ื™ื›ื ื˜ ื’ืขืฆื™ื™ึทื’ ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืฉืคึผื•ืจ ื“ื™ ื“ืจืš ืคื•ืŸ ืึท ืคึผืึทืงืึทื˜ ืฆื•ื–ืืžืขืŸ ื“ื™ ืคึผืึทืงืึทื˜ ืœื•ื™ืคืŸ, ื“ืขื ืงืึทืžืฃ ืื™ื– ื‘ื ื™ืžืฆื ืื™ืŸ ืึทืœืข ืงื™ื™ื˜ืŸ ืื•ืŸ ื˜ื™ืฉืŸ

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’