ืจืืืื ื ืืื ืืขืจ ืคึผืจืึธืฆืขืก ืคืื ืืขืจืืืืื ื ืืขืจ ืืขืกืืขืจ ืืืขื ืคึฟืึทืจ ืืจืึทื ืกืืืืื ื ืคึผืึทืงืืฅ ืืืืขืจ TCP / IP ื ืขืืืืึธืจืงืก. ืืขืืขืจ ืืืื ืคืืจืืื ืื ืฆื ืึทื IPv4 ื ืขืฅ ืึผืืื ืึท ืคึผืจืึธืฆืขืก ืืื ืจืืืื ื ืืืฉื.
ืืขืจ ืึทืจืืืงื ืืื ื ืืฉื ืึท HOWTO, ืขืก ืืืฉืจืืืื ืกืืึทืืืง ืจืืืื ื ืืื RouterOS ืืื ืืืืฉืคืืื, ืืื ืืืืืืจืึทืืื ืืืืขืจืืขืืืคึผืขืจื ืื ืจืขืฉื ืคืื ืื ืกืขืืืื ืืก (ืืืฉื, srcnat ืคึฟืึทืจ ืึทืงืกืขืก ืื ืืื ืืขืจื ืขื), ืึทืืื ืฆื ืคึฟืึทืจืฉืืืื ืืขื ืืึทืืขืจืืึทื ืจืืงืืืืืขืจื ืึท ืืืืขืจ ืืืจืื ืคืื ืืืืกื ืคืื ื ืขืืืืึธืจืงืก ืืื RouterOS.
ืกืืืืืฉืื ื ืืื ืจืืืื ื
ืกืืืืืฉืื ื ืืื ืืขืจ ืคึผืจืึธืฆืขืก ืคืื ืืงืกืืฉืืื ืืืฉืื ื ืคึผืึทืงืืฅ ืืื ืืืื Layer2 ืึธืคึผืฉื ืื (ืขืืืขืจื ืขื, ืคึผืคึผืคึผ, ...). ืืืื ืืขืจ ืืืื ืืขื ืึทื ืืขืจ ืืึทืงืืืขืจ ืคืื ืื ืคึผืึทืงืึทื ืืื ืืืืฃ ืืขืจ ืืขืืืืงืขืจ ืขืืืขืจื ืขื ืกืืื ืขื ืืื ืืื, ืขืก ืืขืจื ื ืื ืืขืง ืึทืืจืขืก ื ืืฆื ืื ืึทืจืคึผ ืคึผืจืึธืืึธืงืึธื ืืื ืืจืึทื ืกืืืื ืื ืคึผืึทืงืึทื ืืืืึทื, ืืืืคึผืึทืกืื ื ืื ืจืึทืืืขืจ. ื ืคึผืคึผืคึผ (ืคืื ื-ืฆื-ืคืื ื) ืคึฟืึทืจืืื ืืื ื ืงืขื ืขื ืืึธืื ืืืืื ืฆืืืื ืคึผืึทืจืืืกืึทืคึผืึทื ืฅ ืืื ืื ืคึผืึทืงืึทื ืืื ืฉืืขื ืืืง ืืขืฉืืงื ืฆื ืืืื ืึทืืจืขืก 0xff.
ืจืืืื ื ืืื ืืขืจ ืคึผืจืึธืฆืขืก ืคืื ืืจืึทื ืกืคืขืจืื ื ืคึผืึทืงืืฅ ืฆืืืืฉื Layer2 ืกืขืืืึทื ืฅ. ืืืื ืึท ืืืื ืืืื ืฆื ืฉืืงื ืึท ืคึผืึทืงืึทื ืืืขืืขื ืก ืืึทืงืืืขืจ ืืื ืึทืจืืืก ืื ืขืืืขืจื ืขื ืกืขืืืขื ื, ืขืก ืงืืงื ืืื ืืืื ืจืืืื ื ืืืฉ ืืื ืคึผืึทืกืื ืื ืคึผืึทืงืึทื ืฆื ืื ืืืืืืืื, ืืืึธืก ืืืืืกื ืืื ืฆื ืฉืืงื ืื ืคึผืึทืงืึทื ืืืืึทืืขืจ (ืึธืืขืจ ืงืขื ื ืืฉื ืืืืกื ืืขืจ ืึธืจืืืื ืขื ืกืขื ืืขืจ ืคืื ืื ืคึผืึทืงืึทื ืืื ื ืืฉื ืึทืืืขืจ ืคืื ืืขื).
ืื ืืืืึทืกื ืืืขื ืฆื ืืจืึทืืื ืืืขืื ืึท ืจืึทืืืขืจ ืืื ืืื ืึท ืืืื ืคืืจืืื ืื ืฆื ืฆืืืื ืึธืืขืจ ืืขืจ Layer2 ืกืขืืืึทื ืฅ ืืื ืงืขื ืขื ืคืึธืจื ืคึผืึทืงืืฅ ืฆืืืืฉื ืืื ืืืจื ืืืืขืจืืึทื ืื ื ืืขืจ ืืขืกืืขืจ ืืึทืจืฉืจืื ืคึฟืื ืื ืจืืืื ื ืืืฉ.
ืืืื ืืืจ ืคึฟืึทืจืฉืืืื ืึทืืฅ, ืึธืืขืจ ืืืจ ืฉืืื ืืขืืืืืกื ืขืก, ืืืืขื ืขื ืืืืฃ. ืคึฟืึทืจ ืื ืื ืืื, ืืื ืฉืืืจืง ืจืขืงืึธืืขื ืืืจื ืึทื ืืืจ ืืึทืงืขื ืขื ืืื ืืื ืึท ืงืืืื, ืึธืืขืจ ืืืืขืจ ืืขืจืึทื
ืจืืืื ื ืืื RouterOS ืืื PacketFlow
ืึผืืขื ืึทืืข ืคืึทื ืืงืฉืึทื ืึทืืืื ืฉืืึทืืืช ืฆื ืกืืึทืืืง ืจืืืื ื ืืื ืืื ืืขื ืคึผืขืงื ืกืืกืืขืืข. ืคึผืืึทืกืืืง ืืขืงื ืจืืืื ื ืืืกืืฃ ืฉืืืฆื ืคึฟืึทืจ ืืื ืึทืืืฉ ืจืืืื ื ืึทืืืขืจืืืึทืื (ืจืืคึผ, OSPF, BGP, MME), ืจืืืื ื ืคืืืืขืจืก ืืื BFD.
ืืืืคึผื ืืขื ืื ืคึฟืึทืจ ืืึทืฉืืขืืืงื ืจืืืื ื: [IP]->[Route]
. ืงืึธืืคึผืืขืงืก ืกืงืืื ืงืขื ืืึทืจืคื ืคึผืึทืงืืฅ ืฆื ืืืื ืคืึทืจ-ืืืืืึทืื ืืื ืึท ืจืืืื ื ืฆืืืื ืืื: [IP]->[Firewall]->[Mangle]
(ืงืืืื PREROUTING
ะธ OUTPUT
).
ืขืก ืืขื ืขื ืืจืื ืขืจืืขืจ ืืืืฃ PacketFlow ืืื IP ืคึผืึทืงืึทื ืจืืืื ื ืืืกืืืฉืึทื ื ืืขื ืขื ืืขืืืื:
- ืจืืืื ื ืคึผืึทืงืืฅ ืืืงืืืขื ืืืจื ืื ืจืึทืืืขืจ. ืืื ืืขื ืืื ืข, ืขืก ืืื ืืึทืฉืืึธืกื ืฆื ืื ืคึผืึทืงืึทื ืืืขื ืืืื ืฆื ืื ืืืืข ืคึผืจืึธืฆืขืก ืึธืืขืจ ืืืขื ืืืื ืืขืฉืืงื ืืืืึทืืขืจ ืฆื ืื ื ืขืฅ. ืืืจืืคืึธืจ ืคึผืึทืงืึทืืืฉืึทื ืืึทืงืืืขื ืจืขืืืืืึทื ืฆืืืื ื
- ืจืืืื ื ืืืืข ืึทืืืืึธืืื ื ืคึผืึทืงืืฅ. ืึทืืืืึธืืื ื ืคึผืึทืงืืฅ ืืึทืงืืืขื ืจืขืืืืืึทื ืฆืืืื ื
- ื ืึธื ืจืืืื ื ืฉืจืื ืคึฟืึทืจ ืึทืืืืึธืืื ื ืคึผืึทืงืืฅ, ืึทืืึทืื ืืืจ ืฆื ืืืืฉื ืื ืจืืืื ื ืืึทืฉืืืก ืืื
[Output|Mangle]
- ืื ืคึผืึทืงืึทื ืืจื ืืื ืืืึทืงืก 1, 2 ืืขืคึผืขื ืืก ืืืืฃ ืื ืึผืืืื ืืื
[IP]->[Route]
- ืื ืคึผืึทืงืึทื ืืจื ืืื ืคืื ืงืื 1, 2 ืืื 3 ืืขืคึผืขื ืืก ืืืืฃ ืื ืึผืืืื ืืื
[IP]->[Route]->[Rules]
- ืืขืจ ืคึผืขืงื ืืจื ืืื ืืืึทืงืก 1, 3 ืงืขื ืขื ืืืื ืื ืคืืืึทื ืกื ืืื
[IP]->[Firewall]->[Mangle]
RIB, FIB, ืจืืืื ื ืงืึทืฉ
ืจืืืื ื ืืื ืคึฟืึธืจืืึทืฆืืข ืืึทืืข
ืื ืืึทืืข ืืื ืืืึธืก ืจืืฅ ืืขื ืขื ืืขืืืืื ืคึฟืื ืืื ืึทืืืฉ ืจืืืื ื ืคึผืจืึธืืึธืงืึธืืก, ืจืืฅ ืคึฟืื ืคึผืคึผืคึผ ืืื ืืืงืคึผ, ืกืืึทืืืง ืืื ืงืึธื ื ืขืงืืขื ืจืืฅ. ืื ืืึทืืึทืืืืก ืึผืืื ืึทืืข ืจืืฅ, ืึทืืืฅ ืื ืคืืืืขืจื ืืืจื ืื ืึทืืืื ืืกืืจืึทืืึธืจ.
ืงืึทื ืืืฉืึทื ืึทืื, ืืืจ ืงืขื ืขื ืืืขืจื ืขืืขื ืึทื [IP]->[Route]
ืืืกืคึผืืืื RIB.
ืคืึธืจืืืขืจืืื ื ืืื ืคึฟืึธืจืืึทืฆืืข ืืึทืืข
ืื ืืึทืืข ืืื ืืืึธืก ืื ืืขืกืืขืจ ืจืืฅ ืคืื RIB ืืขื ืขื ืืขืืืืื. ืึทืืข ืจืืฅ ืืื ืื FIB ืืขื ืขื ืึทืงืืืื ืืื ืืขื ืขื ืืขื ืืฆื ืฆื ืคืึธืจืืืก ืคึผืึทืงืืฅ. ืืืื ืืขืจ ืืึทืจืฉืจืื ืืืขืจื ืื ืึทืงืืืื (ืคืึทืจืงืจืืคึผืื ืืืจื ืื ืึทืืืื ืืกืืจืึทืืึธืจ (ืกืืกืืขื), ืึธืืขืจ ืื ืฆืืืื ื ืืืจื ืืืึธืก ืื ืคึผืึทืงืึทื ืืึธื ืืืื ืืขืฉืืงื ืืื ื ืืฉื ืึทืงืืืื), ืืขืจ ืืึทืจืฉืจืื ืืื ืึทืืืขืงืืขื ืืืขื ืคืื ืื FIB.
ืฆื ืืึทืื ืึท ืจืืืื ื ืืึทืฉืืืก, ืื FIB ืืืฉ ื ืืฆื ืื ืคืืืืขื ืืข ืืื ืคึฟืึธืจืืึทืฆืืข ืืืขืื ืึทื IP ืคึผืึทืงืึทื:
- ืืงืืจ ืึทืืจืขืก
- ืืขืกืืื ืึทืืืึธื ืึทืืจืขืก
- ืืงืืจ ืฆืืืื ื
- ืจืืืื ื ืฆืืืื
- ToS (DSCP)
ืืึทืงืืืขื ืืื ืื FIB ืคึผืขืงื ืืืื ืืืจื ืื ืคืืืืขื ืืข ืกืืึทืืขืก:
- ืืื ืืขืจ ืคึผืขืงื ืืืขื ืคึฟืึทืจ ืึท ืืืืข ืจืึทืืืขืจ ืคึผืจืึธืฆืขืก?
- ืืื ืื ืคึผืึทืงืึทื ืืื ืืขืจืืขื ืืง ืฆื ืกืืกืืขื ืึธืืขืจ ืืึทื ืืฆืขืจ PBR ืึผืืืื?
- ืืืื ืืึธ, ืื ืคึผืึทืงืึทื ืืื ืืขืฉืืงื ืฆื ืื ืกืคึผืขืกืืคืืขื ืจืืืื ื ืืืฉ
- ืื ืคึผืึทืงืึทื ืืื ืืขืฉืืงื ืฆื ืื ืืืืคึผื ืืืฉ
ืงืึทื ืืืฉืึทื ืึทืื, ืืืจ ืงืขื ืขื ืืืขืจื ืขืืขื ืึทื [IP]->[Route Active=yes]
ืืืกืคึผืืืื FIB.
ืจืืืื ื ืงืึทืฉ
ืจืื ืงืึทืืฉืื ื ืืขืงืึทื ืืืึทื. ืืขืจ ืจืึทืืืขืจ ืืขืืขื ืงื ืืื ืื ืคึผืึทืงืืฅ ืืขื ืขื ืืขืฉืืงื ืืื ืืืื ืขืก ืืขื ืขื ืขื ืืขื ืึธื ืขืก (ืืึทืฉืืึธืขืก ืคืื ืืขืจ ืืขืืืืงืขืจ ืงืฉืจ) ืขืก ืืขืฅ ืืื ืืืื ืฆืืืืืขื ืื ืืขืืืข ืืึทืจืฉืจืื, ืึธื ืืฉืขืง ืืื ืื ืคืื. ืืขืจ ืืึทืจืฉืจืื ืงืึทืฉ ืืื ืคึผืืจืืึทืืืงืื ืงืืืจื.
ืคึฟืึทืจ ืจืึธืืืขืจืึธืก ืึทืืืื ืืกืืจืึทืืึธืจืก, ืืื ืืึธืื ื ืืฉื ืืขืืืื ืืืฉืืจืื ืคึฟืึทืจ ืืืืืื ื ืืื ืึธื ืคืืจืื ื ืื ืจืืืื ื ืงืึทืฉ, ืึธืืขืจ ืืืขื ืขืก ืงืขื ืขื ืืืื ืคืึทืจืงืจืืคึผืื ืืื [IP]->[Settings]
.
ืืขืจ ืืขืงืึทื ืืืึทื ืืื ืึทืืืขืงืืขื ืืืขื ืคืื ืื ืืื ืืงืก 3.6 ืงืขืจื, ืึธืืขืจ RouterOS ื ืึธื ื ืืฆื ืงืขืจื 3.3.5, ืืึธืืขืจ ืจืืืื ื ืงืึทืืกืข ืืื ืืืื ืขืจ ืคืื ืื ืกืืืืช.
ืืืื ืืึทืจืฉืจืื ืืืึทืืึธื
[IP]->[Route]->[+]
- ืกืืื ืขื ืคึฟืึทืจ ืืืึธืก ืืืจ ืืืืื ืฆื ืฉืึทืคึฟื ืึท ืืึทืจืฉืจืื (ืคืขืืืงืืึทื: 0.0.0.0/0)
- ืืืืืืืื IP ืึธืืขืจ ืฆืืืื ื ืฆื ืืืึธืก ืื ืคึผืึทืงืึทื ืืืขื ืืืื ืืขืฉืืงื (ืขืก ืงืขื ืืืื ืขืืืขืืข, ืืขื ECMP ืืื ืื)
- ืืืืืืืื ืึทืืืึทืืืึทืืืืืื ืืฉืขืง
- ืจืขืงืึธืจื ืืืคึผ
- ืืืกืืึทื ืกืข (ืืขืืจืืง) ืคึฟืึทืจ ืึท ืืึทืจืฉืจืื
- ืจืืืื ื ืืืฉ
- IP ืคึฟืึทืจ ืืืืข ืึทืืืืึธืืื ื ืคึผืึทืงืืฅ ืืืจื ืืขื ืืึทืจืฉืจืื
- ืืขืจ ืฆืื ืคืื ืคืึทืจื ืขื ืืื ืฆืื ืคืึทืจื ืขื ืืื ืืขืฉืจืืื ืืื ืื ืกืืฃ ืคืื ืืขื ืึทืจืืืงื.
ืจืื ืคืืึทืืก
- X - ืืขืจ ืืึทืจืฉืจืื ืืื ืคืึทืจืงืจืืคึผืื ืืืจื ืื ืึทืืืื ืืกืืจืึทืืึธืจ (
disabled=yes
) - ื - ืืขืจ ืืึทืจืฉืจืื ืืื ืืขื ืืฆื ืฆื ืฉืืงื ืคึผืึทืงืืฅ
- ื - ืืึทืจืฉืจืื ืฆืืืขืืขืื ืืื ืึทืืืงืึทืืื (BGP, OSPF, RIP, MME, PPP, DHCP, ืงืึธื ื ืขืงืืขื)
- C - ืื ืกืืื ืขื ืืื ืงืึธื ื ืขืงืืขื ืืืืึทื ืฆื ืื ืจืึทืืืขืจ
- ื - ืกืืึทืืืง ืืึทืจืฉืจืื
- r,b,o,m - ืจืื ืฆืืืขืืขืื ืืืจื ืืืื ืขืจ ืคืื ืื ืืื ืึทืืืฉ ืจืืืื ื ืคึผืจืึธืืึธืงืึธืืก
- B,U,P - ืคืืืืขืจืื ื ืืึทืจืฉืจืื (ืืจืึธืคึผืก ืคึผืึทืงืืฅ ืึทื ืฉืืึธื ืคืื ืืจืึทื ืกืืืืื ื)
ืืืึธืก ืฆื ืกืคึผืขืฆืืคืืฆืืจื ืืื ืืืืืืืื: ืืคึผ ืึทืืจืขืก ืึธืืขืจ ืฆืืืื ื?
ืื ืกืืกืืขื ืึทืืึทืื ืืืจ ืฆื ืกืคึผืขืฆืืคืืฆืืจื ืืืืืข, ืืฉืขืช ืขืก ืืื ื ืืฉื ืฉืืืขืจื ืืื ื ืืฉื ืืขืื ืืื ืฅ ืืืื ืืืจ ืืึธื ืขืคึผืขืก ืคืึทืืฉ.
IP ืึทืืจืขืก
ืื ืืืืืืืื ืึทืืจืขืก ืืืื ืืืื ืฆืืืจืืืืขื ืืืืขืจ Layer2. ืคึฟืึทืจ ืขืืืขืจื ืขื, ืืึธืก ืืืื ืึทื ืืขืจ ืจืึทืืืขืจ ืืืื ืืึธืื ืึทื ืึทืืจืขืก ืคืื ืืขืจ ืืขืืืืงืขืจ ืกืืื ืขื ืืืืฃ ืืืื ืขืจ ืคืื ืื ืึทืงืืืื ืืคึผ ืื ืืขืจืคืืืกืื, ืคึฟืึทืจ ืคึผืคึผืคึผ, ืึทื ืื ืืืืืืืื ืึทืืจืขืก ืืื ืกืคึผืขืกืืคืืขื ืืืืฃ ืืืื ืขืจ ืคืื ืื ืึทืงืืืื ืื ืืขืจืคืืืกืื ืืื ืื ืกืืื ืขื ืึทืืจืขืก.
ืืืื ืื ืึทืงืกืขืกืึทืืืืืื ืฆืืฉืืึทื ื ืคึฟืึทืจ Layer2 ืืื ื ืืฉื ืืืืขืื ื, ืืขืจ ืืึทืจืฉืจืื ืืื ืืขืจืขืื ื ืืื ืื ืึทืงืืืื ืืื ืงืขื ื ืืฉื ืคืึทืื ืืื ืื FIB.
ืฆืืืื ื
ืึทืืฅ ืืื ืืขืจ ืงืึธืืคึผืืืฆืืจื ืืื ืื ื ืึทืืืจ ืคืื ืื ืจืึทืืืขืจ ืืขืคึผืขื ืืก ืืืืฃ ืื ืืืคึผ ืคืื ืฆืืืื ื:
- PPP (Async, PPTP, L2TP, SSTP, PPPoE, OpenVPN *) ืคึฟืึทืจืืื ืืื ื ืึทืกืืื ืืืืื ืฆืืืื ืคึผืึทืจืืืกืึทืคึผืึทื ืฅ ืืื ืื ืคึผืึทืงืึทื ืืืขื ืฉืืขื ืืืง ืืืื ืืขืฉืืงื ืฆื ืื ืืืืืืืื ืคึฟืึทืจ ืืจืึทื ืกืืืกืืข, ืืืื ืื ืืืืืืืื ืืืืขืงืฅ ืึทื ืืขืจ ืืึทืงืืืขืจ ืืื ืืื, ืขืก ืืืขื ืึทืจืืืขืจืคืืจื ืื ืคึผืึทืงืึทื ืฆื ืืืึทื ืืืืข ืคึผืจืึธืฆืขืก.
- ืขืืืขืจื ืขื ืึทืกืืื ืื ืืืึทืืืึทื ืคืื ืคืืืข ืคึผืึทืจืืืกืึทืคึผืึทื ืฅ ืืื ืืืขื ืฉืืงื ืจืืงืืืขืก ืฆื ืื ืึทืจืคึผ ืฆืืืื ื ืืื ืื ืึทืืจืขืก ืคืื ืื ืืึทืงืืืขืจ ืคืื ืื ืคึผืึทืงืึทื, ืืึธืก ืืื ืืขืจืืืึทืจื ืืื ืืึทื ืฅ ื ืึธืจืืึทื ื ืึทืืืจ ืคึฟืึทืจ ืคืืจืืื ืื ืจืืฅ.
ืึธืืขืจ ืืืขื ืืืจ ืคึผืจืืืืจื ืฆื ื ืืฆื ืื ืฆืืืื ื ืืื ืึท ืืึทืจืฉืจืื ืคึฟืึทืจ ืึท ืืืืึทื ืกืืื ืขื, ืืืจ ืืืขื ืืึทืงืืืขื ืื ืคืืืืขื ืืข ืกืืืืึทืฆืืข: ืืขืจ ืืึทืจืฉืจืื ืืื ืึทืงืืืื, ืคึผืื ื ืฆื ืื ืืืืืืืื ืคึผืึทืกืื, โโืึธืืขืจ ืงืขื ื ืืฉื ืืขืจืืจืืืื ืื ืืึทืงืืืขืจ ืคึฟืื ืื ืกืคึผืขืกืืคืืขื ืกืืื ืขื. ืืืื ืืืจ ืงืืง ืืื ืื ืฆืืืื ื ืืืจื ืึท ืกื ืืคืขืจ, ืืืจ ืืืขื ืืขื ืึทืจืคึผ ืจืืงืืืขืก ืืื ืึทืืจืขืกืขืก ืคึฟืื ืึท ืืืืึทื ืกืืื ืขื.
ืคึผืจืึผืืื ืฆื ืกืคึผืขืฆืืคืืฆืืจื ืื IP ืึทืืจืขืก ืืื ืื ืืืืืืืื ืืืขื ืืขืืืขื. ืื ืืืกื ืขื ืืื ืคืืจืืื ืื ืจืืฅ (ืืืฉืืคื ืืืืืึธืืึทืืืฉ) ืืื ืคึผืคึผืคึผ (ืึทืกืื ืง, PPTP, L2TP, SSTP, PPPoE, OpenVPN *) ืื ืืขืจืคืืืกืื.
OpenVPN ืืื ื ืืฉื ืึทื ืืืึทืืื ืึท PPP ืืขืืขืจ, ืึธืืขืจ ืืืจ ืงืขื ืขื ื ืืฆื ืื OpenVPN ืฆืืืื ื ื ืึธืืขื ืฆื ืฉืึทืคึฟื ืึท ืืึทืจืฉืจืื.
ืืขืจ ืกืคึผืขืฆืืคืืฉ ืจืื
ืืงืขืจืืืง ืจืืืื ื ืืขืจืฉื. ืืขืจ ืืึทืจืฉืจืื ืืืึธืก ืืืฉืจืืืื ืื ืงืืขื ืขืจืขืจ ืกืืื ืขื (ืืื ืื ืืจืขืกืื ืกืืื ืขื ืืึทืกืงืข) ื ืขืื ืคึผืจืืืืึทื ืก ืืื ืื ืจืืืื ื ืืึทืฉืืืก ืคืื ืื ืคึผืึทืงืึทื. ืื ืฉืืขืืข ืคืื โโืื ืืืื ืกื ืืื ืื ืจืืืื ื ืืืฉ ืืื ื ืืฉื ืืึทืืืึทืืืง ืฆื ืื ืืจืืจื - ืื ืืืืคึผื ืืขืจืฉื ืืื ืืขืจ ืกืคึผืขืฆืืคืืฉ.
ืึทืืข ืจืืฅ ืคืื ืื ืกืคึผืขืกืืคืืขื ืกืืขืืข ืืขื ืขื ืึทืงืืืื (ืืืื ืืื FIB). ืคืื ื ืฆื ืคืึทืจืฉืืืขื ืข ืกืืื ืขืฅ ืืื ืืึธื ื ืื ืงืึธื ืคืืืงื ืืื ืืขืืขืจ ืื ืืขืจืขืจ.
ืืืื ืืืื ืขืจ ืคืื ืื ืืืืืืืืื ืืืขื ืืืื ืึทื ืึทืืืืืืึทืืึทื, ืื ืคึฟืึทืจืืื ืื ืืึทืจืฉืจืื ืืืขื ืืืื ืืขืจืขืื ื ืืื ืื ืึทืงืืืื (ืึทืจืืืกืืขื ืืืขื ืคืื ืื FIB) ืืื ืคึผืึทืงืืฅ ืืืขื ืืืื ืืขืืืื ืคึฟืื ืื ืจืืขื ืจืืฅ.
ืืขืจ ืืึทืจืฉืจืื ืืื ืกืืื ืขื 0.0.0.0/0 ืืื ืืื ืืขืืขืื ืึท ืกืคึผืขืฆืืขื ืืืึทืืฉ ืืื ืืื ืืขืจืืคื ืื "ืืืคืึธืื ืจืื" ืึธืืขืจ "ืืึทืืขืืืืึท ืคืื ืืขืฆืืข ืจืืืึธืจื". ืืื ืคืึทืงื, ืขืก ืืื ืืึธืจื ืืฉื ืืึทืืืฉืืงืึทื ืืื ืขืก ืืื ืขืก ืคืฉืื ืื ืงืืืื ืึทืืข ืืขืืืขื IPv4 ืึทืืจืขืกืขืก, ืึธืืขืจ ืื ื ืขืืขื ืืึทืฉืจืืึทืื ืืืื ืึทืจืืขื ืืื - ืขืก ืื ืืืงืืืฅ ืื ืืืืืืืื ืฆื ืคืึธืจืืืก ืคึผืึทืงืืฅ ืคึฟืึทืจ ืืืึธืก ืขืก ืืขื ืขื ืงืืื ืื ืืขืจืข, ืืขืจ ืคึผืื ืืืขื ืจืืฅ.
ืื ืืึทืงืกืืืื ืืขืืืขื ืกืืื ืขื ืืึทืกืงืข ืคึฟืึทืจ IPv4 ืืื / 32, ืืขืจ ืืึทืจืฉืจืื ืืืืืื ืฆื ืึท ืกืคึผืขืฆืืคืืฉ ืืึทืืขืืึธืก ืืื ืงืขื ืขื ืืืื ืืขืืืืื ื ืืื ืื ืจืืืื ื ืืืฉ.
ืคืืจืฉืืื ื ืคืื ืืขืจ ืกืคึผืขืฆืืคืืฉ ืจืื ืืื ืคืื ืืึทืืขื ืืึทื ืคึฟืึทืจ ืงืืื TCP / IP ืืืื.
ืืขืืึทืืขื
ืืืกืืึทื ืกืึทื (ืึธืืขืจ ืืขืืจืืงืก) ืืขื ืขื ืคืืจืืื ืื ืคึฟืึทืจ ืึทืืืื ืืกืืจืึทืืืืืข ืคึฟืืืืจืืจืื ื ืคืื ืจืืฅ ืฆื ืึท ืืืื ืกืืื ืขื ืฆืืืจืืืืขื ืืืจื ืงืืืคื ืืืืืืืืื. ื ืืึทืจืฉืจืื ืืื ืึท ื ืืืขืจืืงืขืจ ืืขืืจืืง ืืื ืืขืืืืื ืึท ืืืืืขืจืงืืึทื ืืื ืืืขื ืืืื ืึทืจืืึทื ืืขืจืขืื ื ืืื ืื FIB. ืืืื ืึท ืืึทืจืฉืจืื ืืื ืึท ื ืืืขืจืืงืขืจ ืืขืืจืืง ืืืื ืฆื ืืืื ืึทืงืืืื, ืขืก ืืืขื ืืืื ืจืืคึผืืืืกื ืืืจื ืึท ืืึทืจืฉืจืื ืืื ืึท ืืขืืขืจ ืืขืืจืืง ืืื ืื FIB.
ืืืื ืขืก ืืขื ืขื ืขืืืขืืข ืจืืฅ ืฆื ืืขืจ ืืขืืืืงืขืจ ืกืืื ืขื ืืื ืืขืจ ืืขืืืืงืขืจ ืืขืืจืืง, ืืขืจ ืจืึทืืืขืจ ืืืขื ืืืืื ืืืืื ืืืื ืขืจ ืคืื ืืื ืฆื ืื FIB ืืืฉ, ืืืืืื ืืืจื ืืืื ืื ืขืจืืขื ืืึธืืืง.
ืื ืืขืืจืืง ืงืขื ื ืขืืขื ืึท ืืืขืจื ืคืื 0 ืฆื 255:
- 0 - ืืขืืจืืง ืคึฟืึทืจ ืคืืจืืื ืื ืจืืฅ. ืืืกืืึทื ืกืข 0 ืงืขื ืขื ื ืื ืืืื ืืึทืฉืืืื ืืืจื ืื ืึทืืืื ืืกืืจืึทืืึธืจ
- 1-254 - ืืขืืจืืงืก ืื ืืืฆื ืฆื ืืขืจ ืึทืืืื ืืกืืจืึทืืึธืจ ืคึฟืึทืจ ืืึทืฉืืขืืืงื ืจืืฅ. ืืขืืจืืงืก ืืื ืึท ื ืืืขืจืืงืขืจ ืืืขืจื ืืึธืื ืึท ืืขืืขืจ ืืืืืขืจืงืืึทื
- 255 - ืืขืืจืืง ืื ืืืฆื ืฆื ืืขืจ ืึทืืืื ืืกืืจืึทืืึธืจ ืคึฟืึทืจ ืืึทืฉืืขืืืงื ืจืืฅ. ื ืื ืขื ืืขื 1-254, ืึท ืืึทืจืฉืจืื ืืื ืึท ืืขืืจืืง ืคืื 255 ืืื ืฉืืขื ืืืง ืื ืึทืงืืืื ืืื ืืื ื ืืฉื ืคืึทืื ืืื ืื FIB
- ืกืคึผืขืฆืืคืืฉ ืืขืืจืืงืก. ืจืืฅ ืืขืจืืืืื ืคืื ืืื ืึทืืืฉ ืจืืืื ื ืคึผืจืึธืืึธืงืึธืืก ืืึธืื ื ืึธืจืืึทื ืืขืืจืืง ืืืึทืืืขืก
ืืฉืขืง ืืืืืืืื
ืืฉืขืง ืืืืืืืื ืืื ืึท MikroTik RoutesOS ืคืึทืจืืขื ืืขืจืื ื ืคึฟืึทืจ ืงืึธื ืืจืึธืืืจืื ื ืื ืึทืืืืืืึทืืืืึทืื ืคืื ืื ืืืืืืืื ืืืจื icmp ืึธืืขืจ arp. ืึทืืึธื ืืขืืขืจ 10 ืกืขืงืื ืืขืก (ืงืขื ืขื ื ืื ืืืื ืืขืืืื), ืึท ืืงืฉื ืืื ืืขืฉืืงื ืฆื ืื ืืืืืืืื, ืืืื ืืขืจ ืขื ืืคืขืจ ืืื ื ืืฉื ืืืงืืืขื ืฆืืืื ืืึธื, ืืขืจ ืืึทืจืฉืจืื ืืื ืืขืืืืื ืึทื ืึทืืืืืืึทืืึทื ืืื ืืื ืึทืืืขืงืืขื ืืืขื ืคืื ืื FIB. ืืืื ืืฉืขืง ืืืืืืืื ืืื ืคืึทืจืงืจืืคึผืื ืื ืืฉืขืง ืืึทืจืฉืจืื ืืืื ืืื ืืขืจ ืืึทืจืฉืจืื ืืืขื ืืืขืจื ืึทืงืืืื ืืืืืขืจ ื ืึธื ืืืื ืืขืจืึธืื ืืฉืขืง.
ืงืืง ืืืืืืืื ืืืกืืืืึทืื ืื ืคึผืึธืืืฆืืข ืืื ืืืึธืก ืขืก ืืื ืงืึทื ืคืืืืขืจื ืืื ืึทืืข ืื ืืขืจืข ืืืื ืกื (ืืื ืึทืืข ืจืืืื ื ืืืฉื ืืื ecmp ืจืืฅ) ืืื ืื ืกืคึผืขืกืืคืืขื ืืืืืืืื.
ืืื ืึทืืืขืืืื, ืืฉืขืง ืืืืืืืื ืึทืจืืขื ืืื ืืื ืืึทื ื ืืื ืขืก ืืขื ืขื ืงืืื ืคืจืืืืขืืขื ืืื ืคึผืึทืงืึทื ืึธื ืืืขืจ ืฆื ืื ืืืืืืืื. ืืฉืขืง ืืืืืืืื ืืื ื ืืฉื ืืืืกื ืืืึธืก ืืื ืืขืฉืขืขื ืืฉ ืืื ืงืึธืืื ืืงืึทืฆืืข ืึทืจืืืก ืื ืึธืคึผืืขืฉืืขืื ืืืืืืืื, ืืึธืก ืจืืงืืืืืขืจื ื ืึธื ืืืฉืืจืื: ืกืงืจืืคึผืก, ืจืขืงืืจืกืืืืข ืจืืืื ื, ืืื ืึทืืืฉ ืจืืืื ื ืคึผืจืึธืืึธืงืึธืืก.
ืจืืึฟ ืืืคึผื ืืื ืืื ืขื ืคึผืจืึธืืึธืงืึธืืก ืึทื ืืืึทืืื ืืขืืืื-ืืื ืืืฉืืจืื ืคึฟืึทืจ ืงืึธื ืืจืึธืืืจืื ื ืงืฉืจ ืืขืืืงืืื, ืืืึธืก ืึทืืึทืื ืื ืืฉืขืง ืืืืืืืื ืคึฟืึทืจ ืืื ืืื ืึทื ื ืึธื (ืึธืืขืจ ืืืืขืจ ืงืืืื) ืืึทืกืข ืืืืฃ ืื ื ืขืฅ ืืื ืืืื ืคืึธืจืฉืืขืืื ื.
ECMP ืจืืฅ
Equal-Cost Multi-Path - ืฉืืงื ืคึผืึทืงืืฅ ืฆื ืื ืืึทืงืืืขืจ ืืื ืขืืืขืืข ืืืืืืืืื ืกืืืืึทืืืืื ืืึทืกืื ื ืืฆื ืื ืจืึธืื ื ืจืึธืืื ืึทืืืขืจืืืึทื.
ืึทื ECMP ืืึทืจืฉืจืื ืืื ืืืฉืืคื ืืืจื ืืขืจ ืึทืืืื ืืกืืจืึทืืึธืจ ืืืจื ืกืคึผืขืฆืืคืืฆืืจื ืงืืืคื ืืืืืืืืื ืคึฟืึทืจ ืืืื ืกืืื ืขื (ืึธืืขืจ ืืืืืึธืืึทืืืฉ ืืืื ืขืก ืืขื ืขื ืฆืืืื ืขืงืืืืืืึทืืขื ื OSPF ืจืืฅ).
ECMP ืืื ืืขื ืืฆื ืคึฟืึทืจ ืืึทืกืข ืืึทืืึทื ืกืื ื ืฆืืืืฉื ืฆืืืื ืืฉืึทื ืึทืื, ืืื ืืขืึธืจืืข, ืืืื ืขืก ืืขื ืขื ืฆืืืื ืืฉืึทื ืึทืื ืืื ืื ecmp ืืึทืจืฉืจืื, ืคึฟืึทืจ ืืขืืขืจ ืคึผืึทืงืึทื ืื ืึทืืืืึธืืื ื ืงืึทื ืึทื ืืึธื ืืืื ืึทื ืืขืจืฉ. ืึธืืขืจ ืื ืจืืืื ื ืงืึทืฉ ืืขืงืึทื ืืืึทื ืกืขื ืื ืคึผืึทืงืืฅ ืคืื ืื ืงืฉืจ ืฆืืืืืขื ืื ืืึทืจืฉืจืื ืึทื ืืขืจ ืขืจืฉืืขืจ ืคึผืึทืงืึทื ืืขื ืืืขื, ืืื ืึท ืจืขืืืืืึทื, ืืืจ ืืึทืงืืืขื ืึท ืืื ืคืื ืืึทืืึทื ืกืื ื ืืืืืจื ืืืืฃ ืงืึทื ืขืงืฉืึทื ื (ืคึผืขืจ-ืงืฉืจ ืืึธืืืื ื ืืึทืืึทื ืกืื ื).
ืืืื ืืืจ ืืืกืืืืึทื ืจืืืื ื ืงืึทืฉ, ืื ืคึผืึทืงืืฅ ืืื ืื ECMP ืืึทืจืฉืจืื ืืืขื ืืืื ืฉืขืจื ืจืืืืืง, ืึธืืขืจ ืขืก ืืื ืึท ืคึผืจืึธืืืขื ืืื NAT. ืื NAT โโืืขืจืฉื ืคึผืจืึทืกืขืกืึทื ืืืืื ืืขืจ ืขืจืฉืืขืจ ืคึผืึทืงืึทื ืคืื ืื ืงืฉืจ (ืื ืื ืืื ืืขื ืขื ืคึผืจืึทืกืขืกื ืืืืืึธืืึทืืืฉ), ืืื ืขืก ืืืจื ืก ืืืืก ืึทื ืคึผืึทืงืืฅ ืืื ืื ืืขืืืข ืืงืืจ ืึทืืจืขืก ืืึธืื ืคืึทืจืฉืืืขื ืข ืื ืืขืจืคืืืกืื.
ืงืืง ืื ืืืืืืืื ืืื ื ืืฉื ืึทืจืืขืื ืืื ECMP ืจืืฅ (ืจืึธืืืขืจืึธืก ืืฉืืง). ืึธืืขืจ ืืืจ ืงืขื ืขื ืืึทืงืืืขื ืึทืจืื ืืขื ืืึทืืจืขื ืขืฆืื ื ืืืจื ืงืจืืืืืื ื ื ืึธื ืืืึทืืึทืืืืฉืึทื ืจืืฅ ืืืึธืก ืืืขื ืืืกืืืืึทื ืืืื ืกื ืืื ECMP.
ืคืืืืขืจืื ื ืืืจื ืจืืืื ื
ืื ืืืคึผ ืึธืคึผืฆืืข ืืืืขืจืืึทื ื ืืืึธืก ืฆื ืืึธื ืืื ืืขื ืคึผืขืงื:
- unicast - ืฉืืงื ืฆื ืื ืกืคึผืขืกืืคืืขื ืืืืืืืื ( ืฆืืืื ื)
- ืืืึทืงืืึธื - ืึทืืืขืงืืืึทืจืคื ืึท ืคึผืึทืงืึทื
- ืคืึทืจืืืขืจื, ืึทื ืจืืึทืืฉืึทืืึทื - ืึทืืืขืงืืืึทืจืคื ืื ืคึผืึทืงืึทื ืืื ืฉืืงื ืึท ืืงืืคึผ ืึธื ืืึธื ืฆื ืื ืกืขื ืืขืจ
ืคืืืืขืจืื ื ืืื ืืืืฉืึทืืืึทืื ืืขื ืืฆื ืืืขื ืขืก ืืื ื ืืืืืง ืฆื ืืึทืืืึธืจืขื ืขื ืื ืฉืืงื ืคืื ืคึผืึทืงืืฅ ืืืืฃ ืืขื ืืืืจืขืื ืืืขื, ืคืื ืงืืจืก, ืืืจ ืงืขื ืขื ืคืืืืขืจ ืืขื ืืืจื ืื ืคืืืจืืืึทื.
ื ืคึผืึธืจ ืคืื ืืืืฉืคืืื
ืฆื ืงืึธื ืกืึธืืืืืจื ืื ืืงืขืจืืืง ืืื ืื ืืืขืื ืจืืืื ื.
ืืืคึผืืฉ ืืืื ืจืึทืืืขืจ
/ip route
add dst-address=0.0.0.0/0 gateway=10.10.10.1
- ืกืืึทืืืง ืืึทืจืฉืจืื ืฆื 0.0.0.0/0 (ืคืขืืืงืืึทื ืืึทืจืฉืจืื)
- ืงืึธื ื ืขืงืืขื ืืึทืจืฉืจืื ืืืืฃ ืื ืฆืืืื ื ืืื ืืขืจ ืฉืคึผืืึทืืขืจ
- ืงืึธื ื ืขืงืืขื ืืึทืจืฉืจืื ืืืืฃ ืืึทื ืฆืืืื ื
ืืืคึผืืฉ ืืืื ืจืึทืืืขืจ ืืื PPPoE
- ืกืืึทืืืง ืืึทืจืฉืจืื ืฆื ืคืขืืืงืืึทื ืืึทืจืฉืจืื, ืืืกืืฃ ืืืืืึธืืึทืืืฉ. ืขืก ืืื ืกืคึผืขืกืืคืืขื ืืื ืงืฉืจ ืคึผืจืึธืคึผืขืจืืืขืก
- ืงืึธื ื ืขืงืืขื ืืึทืจืฉืจืื ืคึฟืึทืจ ืคึผืคึผืคึผ ืงืฉืจ
- ืงืึธื ื ืขืงืืขื ืืึทืจืฉืจืื ืืืืฃ ืืึทื ืฆืืืื ื
ืืืคึผืืฉ ืืืื ืจืึทืืืขืจ ืืื ืฆืืืื ืคึผืจืึทืืืืืืขืจื ืืื ืืืขืจืืงืืึทื
/ip route
add dst-address=0.0.0.0/0 gateway=10.10.10.1 distance=1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=10.20.20.1 distance=2
- ืกืืึทืืืง ืืึทืจืฉืจืื ืฆื ืคืขืืืงืืึทื ืืึทืจืฉืจืื ืืืจื ืืขืจ ืขืจืฉืืขืจ ืฉืคึผืืึทืืขืจ ืืื ืืขืืจืืง 1 ืืื ืืืืืืืื ืึทืืืืืืึทืืืืึทืื ืืฉืขืง
- ืกืืึทืืืง ืืึทืจืฉืจืื ืฆื ืคืขืืืงืืึทื ืืึทืจืฉืจืื ืืืจื ืจืืข ืฉืคึผืืึทืืขืจ ืืื ืืขืืจืืง 2
- ืงืึธื ื ืขืงืืขื ืจืืฅ
ืคืึทืจืงืขืจ ืฆื 0.0.0.0/0 ืืืื ืืืจื 10.10.10.1 ืืฉืขืช ืืขื ืืืืืืืื ืืื ืื ืืืฆื, ืึทื ืืขืจืฉ ืขืก ืกืืืืืฉืื ืฆื 10.20.20.1
ืึทืืึท ืึท ืกืืขืืข ืงืขื ืขื ืืืื ืืขืืืืื ืึท ืงืึทื ืึทื ืจืขืืขืจืืืึทืฆืืข, ืึธืืขืจ ืขืก ืืื ื ืืฉื ืึธื ืืืกืึทืืืืึทื ืืืืืฉืื. ืืืื ืึท ืืจืขืื ืึทืงืขืจื ืึทืจืืืก ืื ืืึทืืขืืืืึท ืคืื ืื ืฉืคึผืืึทืืขืจ (ืืืฉื, ืื ืืขืจ ืึธืคึผืขืจืึทืืึธืจ ืก ื ืขืฅ), ืืืื ืจืึทืืืขืจ ืืืขื ื ืืฉื ืืืืกื ืืืขืื ืืื ืืื ืืืขื ืคืึธืจืืขืฆื ืฆื ืืึทืืจืึทืืื ืืขื ืืึทืจืฉืจืื ืืื ืึทืงืืืื.
ืืืคึผืืฉ ืืืื ืจืึทืืืขืจ ืืื ืฆืืืื ืคึผืจืึทืืืืืืขืจื, ืืืขืจืืงืืึทื ืืื ECMP
/ip route
add dst-address=0.0.0.0/0 gateway=10.10.10.1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=10.20.20.1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=10.10.10.1,10.20.20.1 distance=1
- ืกืืึทืืืง ืจืืฅ ืคึฟืึทืจ ืงืึธื ืืจืึธืืืจืื ื ืืฉืึทืง ืืืืืืืื
- ECMP ืืึทืจืฉืจืื
- ืงืึธื ื ืขืงืืขื ืจืืฅ
ืจืืฅ ืฆื ืงืึธื ืืจืึธืืืจื ืืขื ืขื ืืืื (ืื ืงืึธืืืจ ืคืื ืื ืึทืงืืืื ืจืืฅ), ืึธืืขืจ ืืึธืก ืืื ื ืืฉื ืึทืจืืึทื ืืืฉื ืืื ืืื ืื ืืฉืขืง ืืืืืืืื. ืื ืงืจืึทื ื ืืืขืจืกืืข (6.44) ืคืื RoS ืืื ืึธืืึทืืึทืืืง ืืืืืขืจืงืืึทื ืฆื ืื ECMP ืืึทืจืฉืจืื, ืึธืืขืจ ืขืก ืืื ืืขืกืขืจ ืฆื ืืืืื ืคึผืจืืืืจื ืจืืฅ ืฆื ืื ืืขืจืข ืจืืืื ื ืืืฉื (ืึธืคึผืฆืืข). routing-mark
)
ืืืืฃ ืกืคึผืขืขืืืขืกื ืืื ืื ืืขืจืข ืขื ืืขื ืืืืืืขื, ืขืก ืืืขื ืืืื ืงืืื ืคืึทืจืืจืขืกืขืจื ืืื ืืืืงืืึทื (ECMP ืืืืืืืื ืคืึทืจืงืขืจ ืืืจื ืงืึทื ืขืงืฉืึทื ื, ื ืืฉื ืืืจื ืคึผืึทืงืืฅ), ืึธืืขืจ ืคึผ2ืคึผ ืึทืคึผืืึทืงืืืฉืึทื ื ืืึธื ืืึทืกืข ืคืึทืกืืขืจ.
ืคืืืืขืจืื ื ืืืจื ืจืืืื ื
/ip route
add dst-address=0.0.0.0/0 gateway=10.10.10.1
add dst-address=192.168.200.0/24 gateway=10.30.30.1 distance=1
add dst-address=192.168.200.0/24 gateway=10.10.10.1 distance=2 type=blackhole
- ืกืืึทืืืง ืืึทืจืฉืจืื ืฆื ืคืขืืืงืืึทื ืืึทืจืฉืจืื
- ืกืืึทืืืง ืืึทืจืฉืจืื ืฆื 192.168.200.0/24 ืืืืขืจ ืืคึผืืคึผ ืืื ืขื
- ืคืึธืจืืืืื ื ืกืืึทืืืง ืืึทืจืฉืจืื ืฆื 192.168.200.0/24 ืืืจื ืืกืคึผ ืจืึทืืืขืจ
ื ืคึฟืืืืจืืจืื ื ืึธืคึผืฆืืข ืืื ืืืึธืก ืืื ืขื ืคืึทืจืงืขืจ ืืืขื ื ืืฉื ืืืื ืฆื ืื ืจืึทืืืขืจ ืคืื ืื ืฉืคึผืืึทืืขืจ ืืืขื ืื ipip ืฆืืืื ื ืืื ืคืึทืจืงืจืืคึผืื. ืึทืืึท ืกืงืืื ืืขื ืขื ืจืึทืจืขืื ืคืืจืืื ืื, ืืืืึทื ืืืจ ืงืขื ืขื ืื ืกืืจืืืขื ื ืืืึทืงืื ื ืืืจื ืื ืคืืืจืืืึทื.
ืจืืืื ื ืฉืืืืฃ
ืจืืืื ื ืฉืืืืฃ - ืึท ืกืืืืึทืฆืืข ืืืขื ืึท ืคึผืึทืงืึทื ืืืืคื ืฆืืืืฉื ืจืึธืืืขืจืก ืืืืืขืจ ืื ืขืงืกืคึผืขืจืืืฉืึทื ืคืื ืืื. ืืืืฉืึทืืืึทืื ืขืก ืืื ืืขืจ ืจืขืืืืืึทื ืคืื ืึท ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืืช, ืืื ืืจืืืก ื ืขืืืืึธืจืงืก ืขืก ืืื ืืืืื ืืื ืืืจื ืื ืืืคึผืืึทืืขื ืืืืฉืึทื ืคืื ืืื ืึทืืืฉ ืจืืืื ื ืคึผืจืึธืืึธืงืึธืืก, ืืื ืงืืืื - ืืื ืืึธืจื.
ืขืก ืงืืงื ืขืคึผืขืก ืืื ืืึธืก:
ื ืืืืฉืคึผืื (ืกืืืคึผืึทืกื) ืคืื ืืื ืฆื ืืึทืงืืืขื ืึท ืขื ืืขื ืจืขืืืืืึทื:
ืื ืจืืืื ื ืฉืืืืฃ ืืืึทืฉืคึผืื ืืื ืคืื ืงืืื ืคึผืจืึทืงืืืฉ ื ืืฆื, ืึธืืขืจ ืขืก ืืืืืื ืึทื ืจืึธืืืขืจืก ืืึธืื ืงืืื ืืขืืึทื ืง ืืืขืื ืืืืขืจ ืืืจ ืก ืจืืืื ื ืืืฉ.
ืคึผืึธืืืืืง ืืึทืืข ืจืืืื ื ืืื ื ืึธื ืจืืืื ื ืืึทืืืขืก
ืืืขื ืืฉืืืื ื ืึท ืืึทืจืฉืจืื, ืื ืจืึทืืืขืจ ื ืืฆื ืืืืื ืืืื ืคืขืื ืคืื ืื ืคึผืึทืงืึทื ืืขืืขืจ (ืืกื. ืึทืืจืขืก) - ืืึธืก ืืื ืืงืขืจืืืง ืจืืืื ื. ืจืืืื ื ืืืืืจื ืืืืฃ ืื ืืขืจืข ืืืืื ืืื ืืขื, ืึทืืึท ืืื ืืงืืจ ืึทืืจืขืก, ืืืคึผ ืคืื ืคืึทืจืงืขืจ (ToS), ืืึทืืึทื ืกืื ื ืึธื ECMP, ืืขืืขืจื ืฆื ืคึผืึธืืืืืง ืืึทืกืข ืจืืืื ื (PBR) ืืื ื ืืฆื ื ืึธื ืจืืืื ื ืืืฉื.
ืืขืจ ืกืคึผืขืฆืืคืืฉ ืจืื ืืื ืื ืืืืคึผื ืืึทืจืฉืจืื ืกืขืืขืงืฆืืข ืืขืจืฉื ืืื ืื ืจืืืื ื ืืืฉ.
ืืืจื ืคืขืืืงืืึทื, ืึทืืข ืจืืืื ื ืึผืืืื ืืขื ืขื ืืืกืืฃ ืฆื ืื ืืืืคึผื ืืืฉ. ืืขืจ ืึทืืืื ืืกืืจืึทืืึธืจ ืงืขื ืขื ืืึทืื ืึท ืึทืจืืืืจืึทืจืืฉ ื ืืืขืจ ืคืื ื ืึธื ืจืืืื ื ืืืฉื ืืื ืืึทืจืฉืจืื ืคึผืึทืงืืฅ ืฆื ืืื. ืึผืืืื ืืื ืคืึทืจืฉืืืขื ืข ืืืฉื ืืึธื ื ืื ืงืึธื ืคืืืงื ืืื ืืขืืขืจ ืื ืืขืจืขืจ. ืืืื ืืขืจ ืคึผืขืงื ืงืขื ื ืืฉื ืืขืคึฟืื ืขื ืึท ืคึผืึทืกืืง ืืขืจืฉื ืืื ืื ืกืคึผืขืกืึทืคืืื ืืืฉ, ืขืก ืืืขื ืืืื ืฆื ืื ืืืืคึผื ืืืฉ.
ืืืึทืฉืคึผืื ืืื ืคืึทืจืฉืคึผืจืืืืื ื ืืืจื ืคืืจืขืืืึทืื:
- 192.168.100.10 -> 8.8.8.8
- ืคืึทืจืงืขืจ ืคืื 192.168.100.10 ืืืขืจื ืืืืืึทืื via-isp1 ะฒ
[Prerouting|Mangle]
- ืืื ืื ืจืืืื ื ืืื ืข ืืื ืื ืืืฉ via-isp1 ืืืื ืคึฟืึทืจ ืึท ืืึทืจืฉืจืื ืฆื 8.8.8.8
- ืจืื ืืขืคืื ืขื, ืคืึทืจืงืขืจ ืืื ืืขืฉืืงื ืฆื ืืืืืืืื 10.10.10.1
- ืคืึทืจืงืขืจ ืคืื 192.168.100.10 ืืืขืจื ืืืืืึทืื via-isp1 ะฒ
- 192.168.200.20 -> 8.8.8.8
- ืคืึทืจืงืขืจ ืคืื 192.168.200.20 ืืืขืจื ืืืืืึทืื via-isp2 ะฒ
[Prerouting|Mangle]
- ืืื ืื ืจืืืื ื ืืื ืข ืืื ืื ืืืฉ via-isp2 ืืืื ืคึฟืึทืจ ืึท ืืึทืจืฉืจืื ืฆื 8.8.8.8
- ืจืื ืืขืคืื ืขื, ืคืึทืจืงืขืจ ืืื ืืขืฉืืงื ืฆื ืืืืืืืื 10.20.20.1
- ืคืึทืจืงืขืจ ืคืื 192.168.200.20 ืืืขืจื ืืืืืึทืื via-isp2 ะฒ
- ืืืื ืืืื ืขืจ ืคืื ืื ืืืืืืืืื (10.10.10.1 ืึธืืขืจ 10.20.20.1) ืืืขืจื ืึทื ืึทืืืืืืึทืืึทื, ืื ืคึผืึทืงืึทื ืืืขื ืืืื ืฆื ืื ืืืฉ ืืืืคึผื ืืื ืืืขื ืืืื ืึท ืคึผืึทืกืืง ืืึทืจืฉืจืื ืืึธืจื
ืืขืจืืื ืึธืืึธืืืข ืืฉืื
RouterOS ืืื ืืืืขืจ ืืขืจืืื ืึธืืึธืืืข ืืฉืื.
ืืืขื ืืจืืขืื ืืื ืึผืืืื ืืื [IP]->[Routes]
ืื ืจืืืื ื ืืืฉ ืืื ืื ืืขืืืืื, ืืึธืืฉ ืขืก ืืื ืืขืฉืจืืื ืึทื ืื ืคืืจืืข:
ะ [IP]->[Routes]->[Rule]
ืึทืืฅ ืืื ืจืืืืืง, ืืื ืื ืคืืจืืข ืฆืืฉืืึทื ื ืืื ืื ืืืฉ ืงืึทืืฃ:
ืืื ืฆื ืฉืืงื ืึท ืคึผืึทืงืึทื ืฆื ืึท ืกืคึผืขืฆืืคืืฉ ืจืืืื ื ืืืฉ
RouterOS ืืื ืขืืืขืืข ืืืฉืืจืื:
- ืึผืืืื ืืื
[IP]->[Routes]->[Rules]
- ืจืื ืืึทืจืงืขืจืก (
action=mark-routing
) ืืื[IP]->[Firewall]->[Mangle]
- VRF
ืจืขืืืึทืืืืฉืึทื ื [IP]->[Route]->[Rules]
ืึผืืืื ืืขื ืขื ืคึผืจืึทืกืขืกื ืกืึทืงืืืขื ืืฉืึทืื, ืืืื ืื ืคึผืึทืงืึทื ืฉืืืขืืขืืขื ืื ืืืืื ืืื ืืขื ืคืื ืื ืืขืจืฉื, ืขืก ืืื ื ืืฉื ืคืึธืจื ืืืืึทืืขืจ.
ืจืืืื ื ืึผืืืื ืืึธืื ืืืจ ืฆื ืืงืกืคึผืึทื ื ืื ืคึผืึทืกืึทืืืืึทืืื ืคืื ืจืืืื ื, ืจืืืืืื ื ื ืื ืืืืื ืืืืฃ ืื ืืึทืงืืืขืจ ืึทืืจืขืก, ืึธืืขืจ ืืืื ืืืืฃ ืื ืืงืืจ ืึทืืจืขืก ืืื ืฆืืืื ื ืืืืฃ ืืืึธืก ืื ืคึผืึทืงืึทื ืืื ืืืงืืืขื.
ืืืืื ืืืฉืืืื ืคืื ืืืืื ืืื ืืขื ืืื ืึท ืงืึทืืฃ:
- ืืืืื ืืื ืืขื. ืคึผืจืึทืงืืึทืงืื ืืืืขืจืืืจื ืื ืจืฉืืื ืคืื ืืืืื ืืขืจ ืืืจื ืืืึธืก ืื ืคึผืขืงื ืืื ืึธืคึผืืขืฉืืขืื ืืื ืื FIB, ืืืืื ืืึธืก ืืื ืคืขืื ืืืง.
- ืืขืืืงืืื
- ืืืงืึทืคึผ - ืฉืืงื ืึท ืคึผืึทืงืึทื ืฆื ืึท ืืืฉ
- ืืืื ืืืืื ืืื ืืืฉ - ืฉืืึธืก ืื ืคึผืขืงื ืืื ืื ืืืฉ, ืืืื ืืขืจ ืืึทืจืฉืจืื ืืื ื ืืฉื ืืขืคึฟืื ืขื, ืืขืจ ืคึผืขืงื ืืืขื ื ืืฉื ืืืื ืฆื ืื ืืืืคึผื ืืืฉ
- ืคืึทืื - ืคืึทืื ืึท ืคึผืึทืงืึทื
- ืึทื ืจืืืฉืึทืืึทื - ืึทืืืขืงืืืึทืจืคื ืื ืคึผืึทืงืึทื ืืื ืกืขื ืืขืจ ืึธื ืืึธื
ืืื FIB, ืคืึทืจืงืขืจ ืฆื ืืืืข ืคึผืจืึทืกืขืกืึทื ืืื ืคึผืจืึทืกืขืกื ืืืืคึผืึทืกืื ื ืื ืึผืืืื [IP]->[Route]->[Rules]
:
ืืึทืจืงืื ื [IP]->[Firewall]->[Mangle]
ืจืืืื ื ืืึทืจืงืก ืืึธืื ืืืจ ืฆื ืฉืืขืื ืื ืืืืืืืื ืคึฟืึทืจ ืึท ืคึผืึทืงืึทื ื ืืฆื ืึผืืขื ืงืืื ืคืืจืขืืืึทืื ืื ืึธืื:
ืคึผืจืึทืงืืึทืงืื, ืืืืึทื ื ืื ืึทืืข ืคืื โโืืื ืืึทืื ืืื ืขื, ืืื ืขืืืขืืข ืงืขื ืึทืจืืขื ืึทื ืกืืืืืึทื.
ืขืก ืืขื ืขื ืฆืืืื ืืืขืื ืฆื ืฉืืขืื ืึท ืคึผืขืงื:
- ืืืืื ืฉืืขืื ืจืืืื ื ืฆืืืื
- ืฉืืขืื ืขืจืฉืืขืจ ืงืฉืจ-ืฆืืืื, ืืขืืึธืื ืืืืืจื ืืืืฃ ืงืฉืจ-ืฆืืืื ืฆื ืืืืื ืจืืืื ื ืฆืืืื
ืืื ืึทื ืึทืจืืืงื ืืืขืื ืคืืจืขืืืึทืืืก, ืืื ืืขืฉืจืืื ืึทื ืื ืจืืข ืึธืคึผืฆืืข ืืื ืืืืืขืจ. ืจืึทืืืกืึทื ืื ืืึทืกืข ืืืืฃ ืื ืงืคึผื, ืืื ืื ืคืึทื ืคืื ืืึทืจืงืื ื ืจืืฅ - ืืึธืก ืืื ื ืืฉื ืืขืืึทืืจืข ืืืช. ืื ืืึทืจืงืื ื ืืขืืืึธืืก ืืขื ืขื ื ืืฉื ืฉืืขื ืืืง ืขืงืืืืืืึทืืขื ื ืืื ืืขื ืขื ืืืืฉืึทืืืึทืื ืืขื ืืฆื ืฆื ืกืึธืืืืข ืคืึทืจืฉืืื ืคึผืจืึธืืืขืืก.
ืืึทื ืืฅ ืืืืฉืคืืื
ืืื ืก ืืึทื ืืืืฃ ืฆื ืื ืืืืฉืคืืื ืคืื ื ืืฆื ืคึผืึธืืืืืง ืืึทืกืข ืจืืืื ื, ืืื ืืขื ืขื ืคืื ืืจืื ืืขืจ ืฆื ืืืืึทืื ืืืึธืก ืึทืืข ืืขื ืืื ืืืจืฃ.
MultiWAN ืืื ืฆืืจืืงืงืืืขื ืึทืืืืึธืืื ื (ืจืขืืืืืึทื) ืคืึทืจืงืขืจ
ื ืคึผืจืึธืกื ืคึผืจืึธืืืขื ืืื ืึท ืืืืืืืืึทื ืงืึทื ืคืืืืขืจืืืฉืึทื: ืืืงืจืึธืืืง ืืื ืื ืืืฆื ืคึฟืื ืืขืจ ืืื ืืขืจื ืขืฅ ืืืืื ืืืจื ืึทื "ืึทืงืืืื" ืฉืคึผืืึทืืขืจ.
ืืขืจ ืจืึทืืืขืจ ืืื ื ืืฉื ืืึธืจืื ืืืึธืก ืืคึผ ืื ืืงืฉื ืืขืงืืืขื ืฆื, ืืืขื ืืืฉืขื ืขืจืืืืื ื ืึท ืขื ืืคืขืจ, ืขืก ืืืขื ืงืืงื ืคึฟืึทืจ ืึท ืืึทืจืฉืจืื ืืื ืื ืจืืืื ื ืืืฉ ืืื ืืขืจ ืืึทืจืฉืจืื ืืืจื ืืกืคึผ 1 ืืื ืึทืงืืืื. ืืืืึทืืขืจ, ืึทืืึท ืึท ืคึผืึทืงืึทื ืืืขื ืจืืึฟ ืืกืชึผืื ืืืื ืคืืืืขืจื ืฆืืืืืขื ืืขื ืืืขื ืฆื ืื ืืึทืงืืืขืจ.
ืื ืื ืืขืจ ืืฉืืงืึทืืืข ืคืื ื. ืืืื ืึท "ืคึผืฉืื" ืืงืืจ ื ืึทื ืืื ืงืึทื ืคืืืืขืจื ืืืืฃ ืื ether1 ืฆืืืื ื: /ip fi nat add out-interface=ether1 action=masquerade
ืืขืจ ืคึผืขืงื ืืืขื ืืืื ืึธื ืืืื ืืื src. ืึทืืจืขืก=10.10.10.100, ืืืึธืก ืืืื ืื ืืื ืื ืืคืืื ืขืจืืขืจ.
ืขืก ืืขื ืขื ืขืืืขืืข ืืืขืื ืฆื ืคืึทืจืจืืืื ืืขื ืคึผืจืึธืืืขื, ืึธืืขืจ ืงืืื ืคืื ืืื ืืืขื ืืึทืจืคื ื ืึธื ืจืืืื ื ืืืฉื:
/ip route
add dst-address=0.0.0.0/0 gateway=10.10.10.1 check-gateway=ping distance=1
add dst-address=0.0.0.0/0 gateway=10.20.20.1 check-gateway=ping distance=2
add dst-address=0.0.0.0/0 gateway=10.10.10.1 routing-mark=over-isp1
add dst-address=0.0.0.0/0 gateway=10.20.20.1 routing-mark=over-isp2
ื ืืฆื [IP]->[Route]->[Rules]
ืกืคึผืขืฆืืคืืฆืืจื ืื ืจืืืื ื ืืืฉ ืืืึธืก ืืืขื ืืืื ืืขืืืืื ื ืคึฟืึทืจ ืคึผืึทืงืืฅ ืืื ืื ืกืคึผืขืกืืคืืขื ืืงืืจ IP.
/ip route rule
add src-address=10.10.10.100/32 action=lookup-only-in-table table=over-isp1
add src-address=10.20.20.200/32 action=lookup-only-in-table table=over-isp2
ืงืขื ืขื ื ืืฆื action=lookup
, ืึธืืขืจ ืคึฟืึทืจ ืืืืข ืึทืืืืึธืืื ื ืคืึทืจืงืขืจ, ืืขื ืึธืคึผืฆืืข ืืึธืจ ืืงืกืงืืืื ืงืึทื ืขืงืฉืึทื ื ืคืื ืื ืืืืจืขืื ืฆืืืื ื.
- ืืขืจ ืกืืกืืขื ืืืฉืขื ืขืจืืืฅ ืึท ืขื ืืคืขืจ ืคึผืึทืงืึทื ืืื Src. ืึทืืจืขืก: 10.20.20.200
- ืื ืจืืืื ื ืืึทืฉืืืก (2) ืฉืจืื ืืฉืขืงืก
[IP]->[Routes]->[Rules]
ืืื ืื ืคึผืึทืงืึทื ืืื ืืขืฉืืงื ืฆื ืื ืจืืืื ื ืืืฉ over-isp2 - ืืืื ืื ืจืืืื ื ืืืฉ, ืื ืคึผืึทืงืึทื ืืืื ืืืื ืืขืฉืืงื ืฆื ืื ืืืืืืืื 10.20.20.1 ืืืจื ืื ether2 ืฆืืืื ื
ืืขืจ ืืืคึฟื ืืื ื ืืฉื ืืึทืจืคื ืึท ืืจืืขืื ืงืึทื ืขืงืฉืึทื ืืจืึทืงืขืจ, ื ืื ืขื ืืขื ืื ืืึทื ืื ืืืฉ.
ื ืืฆื [IP]->[Firewall]->[Mangle]
ืืขืจ ืงืฉืจ ืกืืึทืจืฅ ืืื ืึท ืื ืงืึทืืื ื ืคึผืึทืงืึทื, ืึทืืื ืืืจ ืฆืืืื ืขืก (action=mark-connection
), ืคึฟืึทืจ ืึทืืืืึธืืื ื ืคึผืึทืงืืฅ ืคืื ืึท ืื ืืขืฆืืืื ื ืงืฉืจ, ืฉืืขืื ืื ืจืืืื ื ืคืืจืืข (action=mark-routing
).
/ip firewall mangle
#ะะฐัะบะธัะพะฒะบะฐ ะฒั
ะพะดััะธั
ัะพะตะดะธะฝะตะฝะธะน
add chain=input in-interface=ether1 connection-state=new action=mark-connection new-connection-mark=from-isp1
add chain=input in-interface=ether2 connection-state=new action=mark-connection new-connection-mark=from-isp2
#ะะฐัะบะธัะพะฒะบะฐ ะธัั
ะพะดััะธั
ะฟะฐะบะตัะพะฒ ะฝะฐ ะพัะฝะพะฒะต ัะพะตะดะธะฝะตะฝะธะน
add chain=output connection-mark=from-isp1 action=mark-routing new-routing-mark=over-isp1 passthrough=no
add chain=output connection-mark=from-isp2 action=mark-routing new-routing-mark=over-isp2 passthrough=no
ืืืื ืขืืืขืืข ืืคึผืก ืืขื ืขื ืงืึทื ืคืืืืขืจื ืืืืฃ ืืืื ืฆืืืื ื, ืืืจ ืงืขื ืขื ืืืืื ืฆื ืื ืฆืืฉืืึทื ื dst-address
ืฆื ืืืื ืืืืขืจ.
- ื ืคึผืึทืงืึทื ืึธืคึผืขื ืก ืื ืงืฉืจ ืืืืฃ ืื ether2 ืฆืืืื ื. ืืขืจ ืคึผืขืงื ืืืื ืืจืืื
[INPUT|Mangle]
ืืืึธืก ืืืื ืฆื ืฆืืืื ืึทืืข ืคึผืึทืงืืฅ ืคืื ืื ืงืฉืจ ืืื ืคึฟืื-ืืกืคึผ2 - ืืขืจ ืกืืกืืขื ืืืฉืขื ืขืจืืืฅ ืึท ืขื ืืคืขืจ ืคึผืึทืงืึทื ืืื Src. ืึทืืจืขืก: 10.20.20.200
- ืืื ืื ืจืืืื ื ืืึทืฉืืืก (2) ืืื ืข, ืื ืคึผืึทืงืึทื, ืืื ืืืื ืืื ืื ืจืืืื ื ืืืฉ, ืืื ืืขืฉืืงื ืฆื ืื ืืืืืืืื 10.20.20.1 ืืืจื ืื ether1 ืฆืืืื ื. ืืืจ ืงืขื ืขื ืืึทืฉืืขืืืงื ืืขื ืืืจื ืืึธืืื ื ืื ืคึผืึทืงืึทืืืฉืึทื ืืื
[OUTPUT|Filter]
- ืืื ืืขืจ ืืื ืข
[OUTPUT|Mangle]
ืงืฉืจ ืคืืจืืข ืืื ืึธืคึผืืขืฉืืขืื ืคึฟืื-ืืกืคึผ2 ืืื ืื ืคึผืึทืงืึทื ื ืขืื ืึท ืืึทืจืฉืจืื ืคืืจืืข over-isp2 - ืื ืจืืืื ื ืึทืืืืฉืืกืืึทื ื (3) ืฉืจืื ืืฉืขืงืก ืคึฟืึทืจ ืื ืืืึทืืืึทื ืคืื ืึท ืจืืืื ื ืคืืจืืข ืืื ืกืขื ืื ืขืก ืฆื ืื ืฆืื ืขืืขื ืจืืืื ื ืืืฉ
- ืืืื ืื ืจืืืื ื ืืืฉ, ืื ืคึผืึทืงืึทื ืืืื ืืืื ืืขืฉืืงื ืฆื ืื ืืืืืืืื 10.20.20.1 ืืืจื ืื ether2 ืฆืืืื ื
MultiWAN ืืื ืฆืืจืืงืงืืืขื dst-nat ืคืึทืจืงืขืจ
ื ืืืืฉืคึผืื ืืื ืืขืจ ืงืึธืืคึผืืืฆืืจื, ืืืึธืก ืฆื ืืึธื ืืืื ืขืก ืืื ืึท ืกืขืจืืืขืจ (ืืืฉื, ืืืขื) ืืื ืืขืจ ืื ืจืึทืืืขืจ ืืืืฃ ืึท ืคึผืจืืืืึทื ืกืืื ืขื ืืื ืืืจ ืืึทืจืคึฟื ืฆื ืฆืืฉืืขืื ืึทืงืกืขืก ืฆื ืขืก ืืืจื ืงืืื ืคืื ืื ืคึผืจืึทืืืืืืขืจื.
/ip firewall nat
add chain=dstnat proto=tcp dst-port=80,443 in-interface=ether1 action=dst-nat to-address=192.168.100.100
add chain=dstnat proto=tcp dst-port=80,443 in-interface=ether2 action=dst-nat to-address=192.168.100.100
ืื ืขืกืึทื ืก ืคืื ืื ืคึผืจืึธืืืขื ืืืขื ืืืื ืื ืืขืืืข, ืื ืืืืืื ื ืืื ืขื ืืขื ืฆื ืื Firewall Mangle ืึธืคึผืฆืืข, ืืืืื ืื ืืขืจืข ืงืืืื ืืืขื ืืืื ืืขืืืืื ื:
/ip firewall mangle
add chain=prerouting connection-state=new in-interface=ether1 protocol=tcp dst-port=80,443 action=mark-connection new-connection-mark=web-input-isp1
add chain=prerouting connection-state=new in-interface=ether2 protocol=tcp dst-port=80,443 action=mark-connection new-connection-mark=web-input-isp2
add chain=prerouting connection-mark=web-input-isp1 in-interface=ether3 action=mark-routing new-routing-mark=over-isp1 passthrough=no
add chain=prerouting connection-mark=web-input-isp2 in-interface=ether3 action=mark-routing new-routing-mark=over-isp2 passthrough=no
ืื ืืืึทืืจืึทืืข ืืื ื ืืฉื ืืืืึทืื NAT, ืึธืืขืจ ืืื ืืจืึทืืื ืึทืืฅ ืืื ืงืืึธืจ.
ืืืืืืืืึทื ืืื ืึทืืืืึทืื ื ืงืึทื ืขืงืฉืึทื ื
ืืืจ ืงืขื ืขื ื ืืฆื ืื PBR ืงืืืคึผืึทืืืืึทืืื ืฆื ืฉืึทืคึฟื ืงืืืคื ืืืคึผื (SSTP ืืื ืืขื ืืืึทืฉืคึผืื) ืงืึทื ืขืงืฉืึทื ื ืคืื ืคืึทืจืฉืืืขื ืข ืจืึทืืืขืจ ืื ืืขืจืคืืืกืื.
ื ืึธื ืจืืืื ื ืืืฉื:
/ip route
add dst-address=0.0.0.0/0 gateway=192.168.100.1 routing-mark=over-isp1
add dst-address=0.0.0.0/0 gateway=192.168.200.1 routing-mark=over-isp2
add dst-address=0.0.0.0/0 gateway=192.168.0.1 routing-mark=over-isp3
add dst-address=0.0.0.0/0 gateway=192.168.100.1 distance=1
add dst-address=0.0.0.0/0 gateway=192.168.200.1 distance=2
add dst-address=0.0.0.0/0 gateway=192.168.0.1 distance=3
ืคึผืขืงื ืืึทืจืงืก:
/ip firewall mangle
add chain=output dst-address=10.10.10.100 proto=tcp dst-port=443 action=mark-routing new-routing-mark=over-isp1 passtrough=no
add chain=output dst-address=10.10.10.101 proto=tcp dst-port=443 action=mark-routing new-routing-mark=over-isp2 passtrough=no
add chain=output dst-address=10.10.10.102 proto=tcp dst-port=443 action=mark-routing new-routing-mark=over-isp3 passtrough=no
ืคึผืฉืื NAT ืึผืืืื, ืึทื ืืขืจืฉ ืื ืคึผืึทืงืึทื ืืืขื ืืึธืื ืื ืฆืืืื ื ืืื ืืขื ืืืืจืขืื Src. ืึทืืจืขืก:
/ip firewall nat
add chain=srcnat out-interface=ether1 action=masquerade
add chain=srcnat out-interface=ether2 action=masquerade
add chain=srcnat out-interface=ether3 action=masquerade
ืคึผืึทืจืกืื ื:
- ืจืึทืืืขืจ ืงืจืืืืฅ ืืจืื SSTP ืคึผืจืึทืกืขืกืึทื
- ืืื ืืขืจ ืืื ืข ืคืื โโืจืืืื ื ืืึทืฉืืืก (2), ืึท ืืึทืจืฉืจืื ืืื ืืืืกืืขืงืืืื ืคึฟืึทืจ ืื ืคึผืจืึทืกืขืกืึทื ืืืืืจื ืืืืฃ ืื ืืืืคึผื ืจืืืื ื ืืืฉ. ืคึฟืื ืืขืจ ืืขืืืืงืขืจ ืืึทืจืฉืจืื, ืื ืคึผืึทืงืึทื ื ืขืื Src. ืึทืืจืขืก ืืขืืื ืื ืฆื ether1 ืฆืืืื ื
- ะ
[Output|Mangle]
ืคึผืึทืงืืฅ ืคืื ืคืึทืจืฉืืืขื ืข ืงืึทื ืขืงืฉืึทื ื ืืึทืงืืืขื ืคืึทืจืฉืืืขื ืข ืืึทืืขืืก - ืคึผืึทืงืืฅ ืึทืจืืึทื ืื ืืืฉื ืงืึธืจืึทืกืคึผืึทื ืืื ื ืฆื ืื ืืึทืืขืืก ืืื ืื ืจืืืื ื ืึทืืืฉืึทืกืืืึทื ื ืืื ืข ืืื ืืึทืงืืืขื ืึท ื ืืึทืข ืืึทืจืฉืจืื ืคึฟืึทืจ ืฉืืงื ืคึผืึทืงืืฅ
- ืึธืืขืจ ืคึผืึทืงืึทืืืฉืึทื ื ืึธื ืืึธืื Src. ืึทืืจืขืก ืคืื ether1, ืืืืฃ ืืื ืข
[Nat|Srcnat]
ืื ืึทืืจืขืก ืืื ืกืึทืืกืืึทืืืืึทื ืืืื ืื ืฆืืืื ื
ืื ืืขืจืขืกืืื ืืื, ืืืืฃ ืื ืจืึทืืืขืจ ืืืจ ืืืขื ืืขื ืื ืคืืืืขื ืืข ืงืฉืจ ืืืฉ:
ืงืึทื ืขืงืฉืึทื ืืจืึทืงืขืจ ืึทืจืืขื ืคืจืืขืจ [Mangle]
ะธ [Srcnat]
, ืึทืืื ืึทืืข ืงืึทื ืขืงืฉืึทื ื ืงืืืขื ืคืื ืื ืืขืืืข ืึทืืจืขืก, ืืืื ืืืจ ืงืืง ืืื ืืขืจ ืืขืืึทื, ืืขืืึธืื ืืื Replay Dst. Address
ืขืก ืืืขื ืืืื ืึทืืจืขืกืขืก ื ืึธื NAT:
ืืืืฃ ืื VPN ืกืขืจืืืขืจ (ืืื ืืึธืื ืืืื ืืืืฃ ืื ืคึผืจืึธืืข ืืึทื ืง), ืืืจ ืงืขื ืขื ืืขื ืึทื ืึทืืข ืงืึทื ืขืงืฉืึทื ื ืงืืืขื ืคึฟืื ืื ืจืืืืืง ืึทืืจืขืกืขืก:
ืืืึทืจืื ืึท ืืืขื
ืขืก ืืื ืึท ืืจืื ืืขืจ ืืืขื, ืืืจ ืงืขื ืขื ืคืฉืื ืกืคึผืขืฆืืคืืฆืืจื ืึท ืกืคึผืขืฆืืคืืฉ ืืืืืืืื ืคึฟืึทืจ ืืขืืขืจ ืคืื ืื ืึทืืจืขืกืขืก:
/ip route
add dst-address=10.10.10.100 gateway=192.168.100.1
add dst-address=10.10.10.101 gateway=192.168.200.1
add dst-address=10.10.10.102 gateway=192.168.0.1
ืืืขืจ ืึทืืึท ืจืืฅ ืืืขื ืืืืจืงื ื ืื ืืืืื ืึทืืืืึธืืื ื ืึธืืขืจ ืืืื ืืืจืืคืึธืจ ืคืึทืจืงืขืจ. ืคึผืืืก, ืืืื ืืืจ ืืึธื ื ืื ืืึทืจืคึฟื ืคืึทืจืงืขืจ ืฆื ืื ืืืคึผื ืกืขืจืืืขืจ ืฆื ืืืื ืืืจื ืื ืึทืคึผืจืึธืืคึผืจืืื ืงืึธืืื ืืงืึทืฆืืข ืืฉืึทื ืึทืื, ืืืจ ืืืขื ืืึธืื ืฆื ืืืืื 6 ืืขืจ ืึผืืืื. [IP]->[Routes]
ั type=blackhole
. ืืื ืื ืคืจืืขืจืืืงืข ืืืขืจืกืืข - 3 ืึผืืืื ืืื [IP]->[Route]->[Rules]
.
ืคืึทืจืฉืคึผืจืืืืื ื ืคืื ืืึทื ืืฆืขืจ ืงืึทื ืขืงืฉืึทื ื ืืืจื ืงืึธืืื ืืงืึทืฆืืข ืืฉืึทื ืึทืื
ืคึผืฉืื, ืืืึธืืขืืืง ืืึทืกืงืก. ืืืืืขืจ, ื ืึธื ืจืืืื ื ืืืฉื ืืืขื ืืืื ืืืจืฃ:
/ip route
add dst-address=0.0.0.0/0 gateway=10.10.10.1 dist=1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=10.20.20.1 dist=2 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=10.10.10.1 dist=1 routing-mark=over-isp1
add dst-address=0.0.0.0/0 gateway=10.20.20.1 dist=1 routing-mark=over-isp2
ื ืืฆื [IP]->[Route]->[Rules]
/ip route rules
add src-address=192.168.100.0/25 action=lookup-only-in-table table=over-isp1
add src-address=192.168.100.128/25 action=lookup-only-in-table table=over-isp2
ืืืื ื ืืฆื action=lookup
, ืืขืืึธืื ืืืขื ืืืื ืขืจ ืคืื ืื ืืฉืึทื ืึทืื ืืื ืคืึทืจืงืจืืคึผืื, ืืขืจ ืคืึทืจืงืขืจ ืืืขื ืืืื ืฆื ืื ืืืืคึผื ืืืฉ ืืื ืืืื ืืืจื ืื ืึทืจืืขื ืงืึทื ืึทื. ืฆื ืืึธืก ืืื ื ืืืืืง ืึธืืขืจ ื ืื ืืขืคึผืขื ืืก ืืืืฃ ืื ืึทืจืืขื.
ื ืืฆื ืื ืืึทืจืงืื ืื ืืื [IP]->[Firewall]->[Mangle]
ื ืคึผืฉืื ืืืึทืฉืคึผืื ืืื ืจืฉืืืืช ืคืื IP ืึทืืจืขืกืขืก. ืืื ืคึผืจืื ืฆืืคึผ, ืึผืืขื ืงืืื ืืืืื ืืื ืืขื ืงืขื ืขื ืืืื ืืขืืืืื ื. ืืขืจ ืืืืื ืงืืืืืืึทื ืคืื Layer7, ืืคืืื ืืืขื ืคึผืขืจื ืืื ืคึฟืึทืจืืื ืืื ื ืืึทืืขืืก, ืขืก ืงืขื ืืืกืงืืืขื ืึทื ืึทืืฅ ืึทืจืืขื ืจืืืืืง, ืึธืืขืจ ืขืืืขืืข ืคืื โโืื ืคืึทืจืงืขืจ ืืืขื ื ืึธื ืืืื ืื ืืืืจืขืื ืืืขื.
/ip firewall mangle
add chain=prerouting src-address-list=users-over-isp1 dst-address-type=!local action=mark-routing new-routing-mark=over-isp1
add chain=prerouting src-address-list=users-over-isp2 dst-address-type=!local action=mark-routing new-routing-mark=over-isp2
ืืืจ ืงืขื ืขื "ืฉืืึธืก" ื ืืฆืขืจืก ืืื ืืืื ืจืืืื ื ืืืฉ ืืืจื [IP]->[Route]->[Rules]
:
/ip route rules
add routing-mark=over-isp1 action=lookup-only-in-table table=over-isp1
add routing-mark=over-isp2 action=lookup-only-in-table table=over-isp2
ืึธืืขืจ ืืืจื [IP]->[Firewall]->[Filter]
:
/ip firewall filter
add chain=forward routing-mark=over-isp1 out-interface=!ether1 action=reject
add chain=forward routing-mark=over-isp2 out-interface=!ether2 action=reject
ืจืขืืจืขืึทื ืคึผืจืึธ dst-address-type=!local
ื ืึธื ืฆืืฉืืึทื ื dst-address-type=!local
ืขืก ืืื ื ืืืืืง ืึทื ืคืึทืจืงืขืจ ืคืื ื ืืฆืขืจืก ืืขืจืืจืืืื ืื ืืืืข ืคึผืจืึทืกืขืกืึทื ืคืื ืื ืจืึทืืืขืจ (dns, winbox, ssh, ...). ืืืื ืขืืืขืืข ืืืืข ืกืืื ืขืฅ ืืขื ืขื ืงืึธื ื ืขืงืืขื ืฆื ืื ืจืึทืืืขืจ, ืขืก ืืื ื ืืืืืง ืฆื ืขื ืฉืืจ ืึทื ืืขืจ ืคืึทืจืงืขืจ ืฆืืืืฉื ืืื ืืื ื ืืฉื ืืืื ืฆื ืื ืืื ืืขืจื ืขื, ืืืฉื, ื ืืฆื dst-address-table
.
ืืื ืืขื ืืืึทืฉืคึผืื ื ืืฆื [IP]->[Route]->[Rules]
ืขืก ืืขื ืขื ื ืื ืึทืืึท ืืืืกื ืขืืขื, ืึธืืขืจ ืคืึทืจืงืขืจ ืจืืืฉืึทื ืืืืข ืคึผืจืึทืกืขืกืึทื. ืืขืจ ืคืึทืงื ืืื ืึทื ืืืจ ืืึทืงืืืขื ืืื ืื FIB ืคึผืขืงื ืื ืืขืฆืืืื ื ืืื [PREROUTING|Mangle]
ืืื ืึท ืืึทืจืฉืจืื ืคืืจืืข ืืื ืืืื ืืื ืึท ืจืืืื ื ืืืฉ ืื ืืขืจืข ืืื ืืืืคึผื, ืืื ืขืก ืืื ืงืืื ืืืืข ืฆืืืื ื. ืืื ืืขื ืคืึทื ืคืื ืจืืืื ื ืจืืืขืก, ืขืจืฉืืขืจ ืขืก ืืื ืึธืคึผืืขืฉืืขืื ืฆื ืื ืคึผืึทืงืึทื ืืื ืืืขื ืคึฟืึทืจ ืึท ืืืืข ืคึผืจืึธืฆืขืก ืืื ืืืืื ืืื ืืขืจ ืืึทื ืืฆืขืจ PBR ืืื ืข ืืืื ืขืก ืฆื ืื ืกืคึผืขืกืืคืืขื ืจืืืื ื ืืืฉ.
ื ืืฆื [IP]->[Firewall]->[Mangle action=route]
ืืขืจ ืงืึทืืฃ ืึทืจืืขื ืืืืื ืืื [Prerouting|Mangle]
ืืื ืึทืืึทืื ืืืจ ืฆื ืคืืจื ืคืึทืจืงืขืจ ืฆื ืื ืกืคึผืขืกืืคืืขื ืืืืืืืื ืึธื ื ืืฆื ื ืึธื ืจืืืื ื ืืืฉื, ืืืจื ืกืคึผืขืฆืืคืืฆืืจื ืื ืืืืืืืื ืึทืืจืขืก ืืืืึทื:
/ip firewall mangle
add chain=prerouting src-address=192.168.100.0/25 action=route gateway=10.10.10.1
add chain=prerouting src-address=192.168.128.0/25 action=route gateway=10.20.20.1
ืงืึทืืฃ route
ืืื ืึท ื ืืืขืจืืงืขืจ ืืืืืขืจืงืืึทื ืืื ืจืืืื ื ืึผืืืื ([IP]->[Route]->[Rules]
). ืืื ืืขื ืคืึทื ืคืื ืืึทืจืฉืจืื ืืึทืจืงืก, ืึทืืฅ ืืขืคึผืขื ืืก ืืืืฃ ืื ืฉืืขืืข ืคืื โโืื ืึผืืืื, ืืืื ืื ืืขืจืฉื ืืื action=route
ืืืขืจื ืืขืจ ืืื action=mark-route
, ืืขืืึธืื ืขืก ืืืขื ืืืื ืืขืืืืื ื (ืจืึทืืึทืจืืืึทืก ืคืื ืื ืคืึธื passtrough
), ืึทื ืืขืจืฉ ืืึทืจืงืื ื ืื ืืึทืจืฉืจืื.
ืขืก ืืื ืืืืขืจ ืงืืืื ืืื ืคึฟืึธืจืืึทืฆืืข ืืืืฃ ืื ืืืืงื ืืืขืื ืืขื ืงืึทืืฃ ืืื ืึทืืข ืงืึทื ืงืืืืฉืึทื ื ืืขื ืขื ืืืงืืืขื ืืงืกืคึผืขืจืืขื ืึทืื, ืืื ืงืืื ืคืึทื, ืืื ืืื ื ืืฉื ืืขืคึฟืื ืขื ืึธืคึผืฆืืขืก ืืืขื ื ืืฆื ืืขื ืึธืคึผืฆืืข ืืื ืึทืืืืึทื ืืืืืฉืื ืืืืขืจ ืื ืืขืจืข.
ืืื ืึทืืืฉ ืืึทืืึทื ืกืื ื ืืืืืจื ืืืืฃ ืคึผืคึผืง
ืคึผืขืจ ืงืึทื ืขืงืฉืึทื ืงืืึทืกืกืืคืืขืจ - ืืื ืึท ืืขืจ ืคืืขืงืกืึทืืึทื ืึทื ืึทืืึธื ืคืื ECMP. ื ืื ืขื ืืขื ECMP, ืขืก ืืืืืืืื ืคืึทืจืงืขืจ ืืืจื ืงืึทื ืขืงืฉืึทื ื ืืขืจ ืฉืืจืขื ื (ECMP ืืืืืกื ืืึธืจื ืืฉื ืืืขืื ืงืึทื ืขืงืฉืึทื ื, ืึธืืขืจ ืืืขื ืคึผืขืจื ืืื ืจืืืื ื ืงืึทืฉ, ืขืคึผืขืก ืขื ืืขื ืืื ืืืงืืืขื).
PCC ื ืขืื ืกืคึผืขืกืึทืคืืื ืคืขืืืขืจ ืคืื ืื IP ืืขืืขืจ, ืงืึทื ืืืขืจืฅ ืืื ืฆื ืึท 32-ืืืกื ืืืขืจื, ืืื ืืืืืืืื ืืืจื ืืขื ืึธืืื ืึทืืึธืจ. ืื ืจืขืฉื ืคืื ืื ืึธืคึผืืืื ืืื ืงืึทืืคึผืขืจื ืืื ืื ืกืคึผืขืกืืคืืขื ืจืขืฉื ืืื ืืืื ืืื ืืืืึทืื, ืื ืกืคึผืขืกืืคืืขื ืงืึทืืฃ ืืื ืืขืืืขื ืื.
ืืืืฉืคึผืื ืืื ืืจืื ืึทืืจืขืกืขืก:
192.168.100.10: 192+168+100+10 = 470 % 3 = 2
192.168.100.11: 192+168+100+11 = 471 % 3 = 0
192.168.100.12: 192+168+100+12 = 472 % 3 = 1
ืึท ืืืืฉืคึผืื ืคืื ืืื ืึทืืืฉ ืคืึทืจืฉืคึผืจืืืืื ื ืคืื ืคืึทืจืงืขืจ ืืืจื src.address ืฆืืืืฉื ืืจืื ืืฉืึทื ืึทืื:
#ะขะฐะฑะปะธัะฐ ะผะฐัััััะธะทะฐัะธะธ
/ip route
add dst-address=0.0.0.0/0 gateway=10.10.10.1 dist=1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=10.20.20.1 dist=2 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=10.30.30.1 dist=3 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=10.10.10.1 dist=1 routing-mark=over-isp1
add dst-address=0.0.0.0/0 gateway=10.20.20.1 dist=1 routing-mark=over-isp2
add dst-address=0.0.0.0/0 gateway=10.30.30.1 dist=1 routing-mark=over-isp3
#ะะฐัะบะธัะพะฒะบะฐ ัะพะตะดะธะฝะตะฝะธะน ะธ ะผะฐัััััะพะฒ
/ip firewall mangle
add chain=prerouting in-interface=br-lan dst-address-type=!local connection-state=new per-connection-classifier=src-address:3/0 action=mark-connection new-connection-mark=conn-over-isp1
add chain=prerouting in-interface=br-lan dst-address-type=!local connection-state=new per-connection-classifier=src-address:3/1 action=mark-connection new-connection-mark=conn-over-isp2
add chain=prerouting in-interface=br-lan dst-address-type=!local connection-state=new per-connection-classifier=src-address:3/2 action=mark-connection new-connection-mark=conn-over-isp3
add chain=prerouting in-interface=br-lan connection-mark=conn-over-isp1 action=mark-routing new-routing-mark=over-isp1
add chain=prerouting in-interface=br-lan connection-mark=conn-over-isp2 action=mark-routing new-routing-mark=over-isp2
add chain=prerouting in-interface=br-lan connection-mark=conn-over-isp3 action=mark-routing new-routing-mark=over-isp3
ืืืขื ืืึทืจืงืื ื ืจืืฅ, ืขืก ืืื ืึทื ื ืึธื ืฆืืฉืืึทื ื: in-interface=br-lan
, ืื ืขืก ืืื ืืขืจ action=mark-routing
ืขื ืืคืขืจ ืคืึทืจืงืขืจ ืคืื ืื ืืื ืืขืจื ืขื ืืืขื ืืึทืงืืืขื ืืื, ืืื ืืืื ืืื ืื ืจืืืื ื ืืืฉื, ืืืขื ืืืื ืฆืืจืืง ืฆื ืืขืจ ืฉืคึผืืึทืืขืจ.
ืืึทืฉืืืืขื ืงืึธืืื ืืงืึทืฆืืข ืืฉืึทื ืึทืื
ืืฉืขืง ืคึผืื ื ืืื ืึท ืืื ืืขืฆืืึทื, ืึธืืขืจ ืขืก ื ืึธืจ ืืฉืขืง ืื ืคึฟืึทืจืืื ืืื ื ืืื ืื ื ืืจืึทืกื IP ืืึทื ืงืืงื , ืคึผืจืึทืืืืืืขืจ ื ืขืืืืึธืจืงืก ืืืืฉืึทืืืึทืื ืฆืื ืืืคืฉืืขืื ืืื ืคืื ืึท ืืจืืืก ื ืืืขืจ ืคืื ืจืึธืืืขืจืก ืืื ืึท ืงืฉืจ ืืจืขืื ืงืขื ืคึผืึทืกืืจื ืึทืจืืืก ืื ื ืืจืึทืกื ืืึทื ืงืืงื , ืืื ืขืก ืืขื ืขื ืืึทืงืืึธืื ืืขืืขืงืึธื ืึธืคึผืขืจืืืืขืจื ืืืึธืก ืงืขื ืืืื ืืึธืื ืคึผืจืึธืืืขืืก, ืืื ืึทืืืขืืืื, ืืฉืขืง ืคึผืื ื ืืื ื ืืฉื ืฉืืขื ืืืง ืืืืึทืื ืึทืจืืืฃ-ืฆื-ืืึธื ืืื ืคึฟืึธืจืืึทืฆืืข ืืืขืื ืึทืงืกืขืก ืฆื ืื ืืืืืืืข ื ืขืฅ.
ืืืื ืคึผืจืึทืืืืืืขืจื ืืื ืืจืืืก ืงืึธืจืคึผืขืจืืืฉืึทื ื ืืึธืื ืื BGP ืืื ืึทืืืฉ ืจืืืื ื ืคึผืจืึธืืึธืงืึธื, ืืืื ืืื ืึธืคืืก ื ืืฆืขืจืก ืืืื ืื ืืืคึผืขื ืืึทื ืืื ืจืขืืขื ืขื ืืืืก ืืื ืฆื ืงืึธื ืืจืึธืืืจื ืืื ืืขืจื ืขื ืึทืงืกืขืก ืืืจื ืึท ืกืคึผืขืฆืืคืืฉ ืงืึธืืื ืืงืึทืฆืืข ืงืึทื ืึทื.
ืืืคึผืืงืึทืืื, ืกืงืจืืคึผืก ืืขื ืขื ืืขื ืืฆื ืืืึธืก, ืืืจื ืึท ืืืืขืจ ืงืึธืืื ืืงืึทืฆืืข ืงืึทื ืึทื, ืงืึธื ืืจืึธืืืจื ืื ืึทืืืืืืึทืืืืึทืื ืคืื ืึทื ืืคึผ ืึทืืจืขืก ืืืืฃ ืืขืจ ืืื ืืขืจื ืขืฅ, ืืฉืขืช ืืฉืืืื ื ืขืคึผืขืก ืคืึทืจืืึธืืืขื, ืืืฉื, Google dns: 8.8.8.8. 8.8.4.4. ืืืขืจ ืืื ืื ืืืงืจืึธืืืง ืงืื, ืึท ืืขืจ ืืฉืืงืึทืืืข ืืขืฆืืึทื ืืื ืฆืืืขืคืืกื ืคึฟืึทืจ ืืขื.
ืขืืืขืืข ืืืขืจืืขืจ ืืืขืื ืจืขืงืืจืกืืืืข ืจืืืื ื
ืจืขืงืืจืกืืืืข ืจืืืื ื ืืื ื ืืืืืง ืืืขื ืืืจ ืืืืขื Multihop BGP ืคึผืืจืื ื ืืื ืืึทืงืืืขื ืืื ืืขื ืึทืจืืืงื ืืืขืื ืื ืืึทืกืืงืก ืคืื ืกืืึทืืืง ืจืืืื ื ืืืืื ืจืขืื ืฆื ืืืืจืข ืืืงืจืึธืืืง ืืืืขืจื ืืืึธืก ืืึธืื ืืขืคึฟืื ืขื ืืื ืฆื ื ืืฆื ืจืขืงืืจืกืืืืข ืจืืฅ ืคึผืขืจื ืืื ืืฉืขืง ืืืืืืืื ืฆื ืืึทืฉืืืืขื ืงืึธืืื ืืงืึทืฆืืข ืืฉืึทื ืึทืื ืึธื ื ืึธื ืกืงืจืืคึผืก.
ืขืก ืืื ืฆืืื ืฆื ืคึฟืึทืจืฉืืืื ืื ืึธืคึผืฆืืขืก ืคึฟืึทืจ ืคืึทืจื ืขื / ืฆืื ืคืึทืจื ืขื ืืื ืึทืืืขืืืื ืืขืจืืื ืขื ืืื ืืื ืืขืจ ืืึทืจืฉืจืื ืืื ืืขืืื ืื ืฆื ืื ืฆืืืื ื:
- ืืขืจ ืืึทืจืฉืจืื ืงืืงื ืึท ืฆืืืื ื ืฆื ืฉืืงื ืื ืคึผืึทืงืึทื ืืืืืจื ืืืืฃ ืืืื ืคืึทืจื ืขื ืืืขืจื ืืื ืึทืืข ืืืื ืกื ืืื ืื ืืืืคึผื ืืืฉ ืืื ืืืืื ืืงืขืจ ืืื ืึธืืขืจ ืืืืึทื ืฆืื ืคืึทืจื ืขื ืืืึทืืืขืก
- ืคึฟืื ืื ืืขืคึฟืื ืขื ืื ืืขืจืคืืืกืื, ืืขืจ ืืืื ืขืจ ืืืจื ืืืึธืก ืืืจ ืงืขื ืขื ืฉืืงื ืึท ืคึผืึทืงืึทื ืฆื ืื ืกืคึผืขืกืึทืคืืื ืืืืืืืื ืืื ืืืืกืืขืงืืืื
- ืื ืฆืืืื ื ืคืื ืื ืืขืคึฟืื ืขื ืงืึธื ื ืขืงืืขื ืคึผืึธืืืฆืืข ืืื ืืืืกืืขืงืืืื ืฆื ืฉืืงื ืื ืคึผืึทืงืึทื ืฆื ืื ืืืืืืืื
ืืื ืืขื ืืืึทืืืึทื ืคืื ืึท ืจืขืงืืจืกืืืืข ืืึทืจืฉืจืื, ืึทืืฅ ืืึทืคึผืึทื ื ืื ืืขืืืข, ืึธืืขืจ ืืื ืฆืืืื ืกืืึทืืขืก:
- 1-3 ืืืื ืขืจ ืืขืจ ืืึทืจืฉืจืื ืืื ืืืกืืฃ ืฆื ืื ืคืืจืืื ืื ืจืืฅ, ืืืจื ืืืึธืก ืื ืกืคึผืขืกืืคืืขื ืืืืืืืื ืงืขื ืขื ืืืื ืจืืืฉื
- 4-6 ืืขืคึฟืื ืขื ืื ืืึทืจืฉืจืื ืคืืจืืื ืื ืืึทืจืฉืจืื ืคึฟืึทืจ ืื "ืื ืืขืจืืืืืื" ืืืืืืืื
ืึทืืข ืืึทื ืืคึผืืึทืืืืฉืึทื ื ืืื ืื ืจืขืงืืจืกืืืืข ืืืื ืคืึทืื ืืื ืื RIB, ืืื ืืืืื ืื ืืขืฆื ืจืขืืืืืึทื ืืื ืืจืึทื ืกืคืขืจื ืฆื ืื FIB: 0.0.0.0/0 via 10.10.10.1 on ether1
.
ื ืืืืฉืคึผืื ืคืื ื ืืฆื ืจืขืงืืจืกืืืืข ืจืืืื ื ืฆื ืืึทืฉืืืืขื ืจืืฅ
ืงืึทื ืคืืืืขืจืืืฉืึทื:
/ip route
add dst-address=0.0.0.0/0 gateway=8.8.8.8 check-gateway=ping distance=1 target-scope=10
add dst-address=8.8.8.8 gateway=10.10.10.1 scope=10
add dst-address=0.0.0.0/0 gateway=10.20.20.1 distance=2
ืืืจ ืงืขื ืขื ืงืึธื ืืจืึธืืืจื ืึทื ืคึผืึทืงืืฅ ืืืขื ืืืื ืืขืฉืืงื ืฆื 10.10.10.1:
ืืฉืขืง ืืืืืืืื ืืืืืกื ืืึธืจื ืืฉื ืืืขืื ืจืขืงืืจืกืืืืข ืจืืืื ื ืืื ืคืฉืื ืกืขื ืื ืคึผืื ืืก ืฆื 8.8.8.8, ืืืึธืก (ืืืืืจื ืืืืฃ ืื ืืืืคึผื ืืืฉ) ืืื ืฆืืืจืืืืขื ืืืจื ืืืืืืืื 10.10.10.1.
ืืืื ืขืก ืืื ืึท ืึธื ืืืขืจ ืคืื ืงืึธืืื ืืงืึทืฆืืข ืฆืืืืฉื 10.10.10.1 ืืื 8.8.8.8, ืืขืจ ืืึทืจืฉืจืื ืืื ืืืกืงืึทื ืขืงืืื, ืึธืืขืจ ืคึผืึทืงืืฅ (ืึทืจืืึทื ืืขืจืขืื ื ืคึผืจืืืืจื ืคึผืื ืืก) ืฆื 8.8.8.8 ืคืึธืจืืขืฆื ืฆื ืืืื ืืืจื 10.10.10.1:
ืืืื ืื ืืื ืง ืฆื ether1 ืืื ืคืึทืจืคืึทืื, ืึท ืคึผืจืืงืจืข ืกืืืืึทืฆืืข ืึทืงืขืจื ืืืขื ืคึผืึทืงืืฅ ืืืืืขืจ 8.8.8.8 ืืืื ืืืจื ืื ืจืืข ืฉืคึผืืึทืืขืจ:
ืืึธืก ืืื ืึท ืคึผืจืึธืืืขื ืืืื ืืืจ ื ืืฆื NetWatch ืฆื ืืืืคื ืกืงืจืืคึผืก ืืืขื 8.8.8.8 ืืื ื ืื ืื ืืืฆื. ืืืื ืื ืืื ืง ืืื ืฆืขืืจืืื, NetWatch ืืืขื ืคืฉืื ืึทืจืืขืื ืืืจื ืื ืืึทืงืึทืคึผ ืงืึธืืื ืืงืึทืฆืืข ืงืึทื ืึทื ืืื ืืืขืจื ืขืืขื ืึทื ืึทืืฅ ืืื ืืื. ืกืึทืืืื ืืืจื ืึทืืื ื ืึทื ื ืึธื ืคืืืืขืจ ืืึทืจืฉืจืื:
/ip route
add dst-address=8.8.8.8 gateway=10.20.20.1 distance=100 type=blackhole
ืขืก ืืื ืืืืฃ ืืึทืืจืข
ืืื ืืึธ, ืืืขื ื ืืฆื ืึทืืึท ืึท ืจืขืืขืจืืืึทืฆืืข, ืื ืึทืืจืขืก 8.8.8.8 ืืืขื ืืืื ืืึทืจืืืืืืขืจื ืฆื ืืืื ืขืจ ืคืื ืื ืคึผืจืึทืืืืืืขืจื, ืึทืืื ืืฉืืืื ื ืขืก ืืื ืึท ืื ืก ืืงืืจ ืืื ื ืืฉื ืึท ืืื ืืขืืึทื ืง.
ืขืืืขืืข ืืืขืจืืขืจ ืืืขืื ืืืืจืืืึทื ืจืืืื ื ืืื ืคืึธืจืืืขืจืืื ื (VRF)
VRF ืืขืื ืึธืืึธืืืข ืืื ืืืืืื ื ืฆื ืฉืึทืคึฟื ืขืืืขืืข ืืืืจืืืึทื ืจืึธืืืขืจืก ืืื ืืืื ืคืืืืฉ, ืื ืืขืื ืึธืืึธืืืข ืืื ืืืืืืื ืืขื ืืฆื ืืืจื ืืขืืขืงืึธื ืึธืคึผืขืจืืืืขืจื (ืืืืฉืึทืืืึทืื ืืื ืงืึทื ืืืฉืึทื ืืงืฉืึทื ืืื MPLS) ืฆื ืฆืืฉืืขืื L3VPN ืืึทืืื ืื ืืก ืฆื ืงืืืืึทื ืฅ ืืื ืึธืืืืขืจืืึทืคึผืื ื ืกืืื ืขื ืึทืืจืขืกืขืก:
ืึธืืขืจ VRF ืืื ืืืงืจืึธืืืง ืืื ืึธืจืืึทื ืืืืจื ืืืืฃ ืืขืจ ืืืืข ืคืื โโืจืืืื ื ืืืฉื ืืื ืืื ืึท ื ืืืขืจ ืคืื ืืืกืึทืืืืึทื ืืืืืฉืื, ืคึฟืึทืจ ืืืึทืฉืคึผืื, ืืืืข IP ืึทืืจืขืกืขืก ืคืื ืื ืจืึทืืืขืจ ืืขื ืขื ืื ืืืฆื ืคืื ืึทืืข VRFs, ืืืจ ืงืขื ืขื ืืืืขื ืขื ืืขืจ
vrf ืงืึทื ืคืืืืขืจืืืฉืึทื ืืืึทืฉืคึผืื:
/ip route vrf
add interfaces=ether1 routing-mark=vrf1
add interfaces=ether2 routing-mark=vrf2
/ip address
add address=192.168.100.1/24 interface=ether1 network=192.168.100.0
add address=192.168.200.1/24 interface=ether2 network=192.168.200.0
ืคึฟืื ืื ืืืื ืงืึธื ื ืขืงืืขื ืฆื ether2, ืืืจ ืืขื ืึทื ืคึผืื ื ืืืื ืฆื ืื ืจืึทืืืขืจ ืึทืืจืขืก ืคึฟืื ืื ืื ืืขืจ ืืืจืฃ (ืืื ืืึธืก ืืื ืึท ืคึผืจืึธืืืขื), ืืฉืขืช ืคึผืื ื ืืืื ื ืืฉื ืฆื ืื ืืื ืืขืจื ืขื:
ืฆื ืึทืงืกืขืก ืื ืืื ืืขืจื ืขื, ืืืจ ืืึทืจืคึฟื ืฆื ืจืขืืืกืืจืืจื ืึทื ื ืึธื ืืึทืจืฉืจืื ืืืึธืก ืึทืงืกืขืก ืื ืืืืคึผื ืืืฉ (ืืื vrf ืืขืจืืื ืึธืืึธืืืข, ืืึธืก ืืื ืืขืจืืคื ืืึทืจืฉืจืื ืืืงืื ื):
/ip route
add distance=1 gateway=172.17.0.1@main routing-mark=vrf1
add distance=1 gateway=172.17.0.1%wlan1 routing-mark=vrf2
ืืึธ ืืขื ืขื ืฆืืืื ืืืขืื ืคืื ืืึทืจืฉืจืื ืืืงืื ื: ื ืืฆื ืื ืจืืืื ื ืืืฉ: 172.17.0.1@main
ืืื ื ืืฆื ืฆืืืื ื ื ืึธืืขื: 172.17.0.1%wlan1
.
ืืื ืฉืืขืื ืึทืจืืืฃ ืืึทืจืงืื ื ืคึฟืึทืจ ืฆืืจืืงืงืืืขื ืคืึทืจืงืขืจ ืืื [PREROUTING|Mangle]
:
/ip firewall mangle
add chain=prerouting in-interface=ether1 action=mark-connection new-connection-mark=from-vrf1 passthrough=no
add chain=prerouting connection-mark=from-vrf1 routing-mark=!vrf1 action=mark-routing new-routing-mark=vrf1 passthrough=no
add chain=prerouting in-interface=ether2 action=mark-connection new-connection-mark=from-vrf2 passthrough=no
add chain=prerouting connection-mark=from-vrf2 routing-mark=!vrf1 action=mark-routing new-routing-mark=vrf2 passthrough=no
ืกืืื ืขืฅ ืืื ืื ืืขืืืข ืึทืืจืขืก
ืึธืจืืึทื ืืืึทืฆืืข ืคืื โโืึทืงืกืขืก ืฆื ืกืืื ืขืฅ ืืื ืืขืจ ืืขืืืืงืขืจ ืึทืืจืขืกืื ื ืืืืฃ ืืขืจ ืืขืืืืงืขืจ ืจืึทืืืขืจ ื ืืฆื VRF ืืื ื ืขืืืึทืคึผ:
ืืงืขืจืืืง ืงืึทื ืคืืืืขืจืืืฉืึทื:
/ip route vrf
add interfaces=ether1 routing-mark=vrf1
add interfaces=ether2 routing-mark=vrf2
/ip address
add address=192.168.100.1/24 interface=ether1 network=192.168.100.0
add address=192.168.100.1/24 interface=ether2 network=192.168.100.0
add address=192.168.0.1/24 interface=ether3 network=192.168.0.0
ืคืืจืขืืืึทืื ืึผืืืื:
#ะะฐัะบะธััะตะผ ะฟะฐะบะตัั ะดะปั ะพัะฟัะฐะฒะบะธ ะฒ ะฟัะฐะฒะธะปัะฝัั ัะฐะฑะปะธัั ะผะฐัััััะธะทะฐัะธะธ
/ip firewall mangle
add chain=prerouting dst-address=192.168.101.0/24 in-interface=ether3 action=mark-routing new-routing-mark=vrf1 passthrough=no
add chain=prerouting dst-address=192.168.102.0/24 in-interface=ether3 action=mark-routing new-routing-mark=vrf2 passthrough=no
#ะกัะตะดััะฒะฐะผะธ netmap ะทะฐะผะตะฝัะตะผ ะฐะดัะตัะฐ "ััะธะผะตัะฝัั
" ะฟะพะดัะตัะตะน ะฝะฐ ัะตะฐะปัะฝัะต ะฟะพะดัะตัะธ
/ip firewall nat
add chain=dstnat dst-address=192.168.101.0/24 in-interface=ether3 action=netmap to-addresses=192.168.100.0/24
add chain=dstnat dst-address=192.168.102.0/24 in-interface=ether3 action=netmap to-addresses=192.168.100.0/24
ืจืืืื ื ืึผืืืื ืคึฟืึทืจ ืฆืืจืืงืงืืืขื ืคืึทืจืงืขืจ:
#ะฃะบะฐะทะฐะฝะธะต ะธะผะตะฝะธ ะธะฝัะตััะตะนัะฐ ัะพะถะต ะผะพะถะตั ััะธัะฐัััั route leaking, ะฝะพ ะฟะพ ัััะธ ััั ัะพะทะดะฐะตััั ะฐะฝะฐะปะพะณ connected ะผะฐัััััะฐ
/ip route
add distance=1 dst-address=192.168.0.0/24 gateway=ether3 routing-mark=vrf1
add distance=1 dst-address=192.168.0.0/24 gateway=ether3 routing-mark=vrf2
ืึทืืื ื ืจืืฅ ืืืงืืืขื ืืืจื dhcp ืฆื ืึท ืืขืืขืื ืจืืืื ื ืืืฉ
VRF ืงืขื ืืืื ืืฉืืงืึทืืืข ืืืื ืืืจ ืืึทืจืคึฟื ืฆื ืืืืืึธืืึทืืืฉ ืืืืื ืึท ืืื ืึทืืืฉ ืืึทืจืฉืจืื (ืืืฉื ืคึฟืื ืึท dhcp ืงืืืขื ื) ืฆื ืึท ืกืคึผืขืฆืืคืืฉ ืจืืืื ื ืืืฉ.
ืึทืืื ื ืฆืืืื ื ืฆื vrf:
/ip route vrf
add interface=ether1 routing-mark=over-isp1
ืึผืืืื ืคึฟืึทืจ ืฉืืงื ืคืึทืจืงืขืจ (ืึทืืืืึธืืื ื ืืื ืืืจืืคืึธืจ) ืืืจื ืื ืืืฉ over-isp1:
/ip firewall mangle
add chain=output out-interface=!br-lan action=mark-routing new-routing-mark=over-isp1 passthrough=no
add chain=prerouting in-interface=br-lan dst-address-type=!local action=mark-routing new-routing-mark=over-isp1 passthrough=no
ื ืึธื ืฉืืืื ืื ืืึทืจืฉืจืื ืคึฟืึทืจ ืึทืืืืึทืื ื ืจืืืื ื ืฆื ืึทืจืืขืื:
/interface bridge
add name=bare
/ip route
add dst-address=0.0.0.0/0 gateway=bare
ืืขืจ ืืึทืจืฉืจืื ืืื ื ืึธืจ ืืืจืฃ ืึทืืื ืึทื ืืืืข ืึทืืืืึธืืื ื ืคึผืึทืงืืฅ ืงืขื ืขื ืคืึธืจื ืืืจื ืื ืจืืืื ื ืืึทืฉืืืก (2) ืคืจืืขืจ [OUTPUT|Mangle]
ืืื ืืึทืงืืืขื ืื ืจืืืื ื ืคืืจืืข, ืืืื ืขืก ืืขื ืขื ืื ืืขืจืข ืึทืงืืืื ืจืืฅ ืืืืฃ ืื ืจืึทืืืขืจ ืืืืืขืจ 0.0.0.0/0 ืืื ืื ืืืืคึผื ืืืฉ, ืขืก ืืื ื ืืฉื ืคืืจืืื ืื.
ืงืืืื connected-in
ะธ dynamic-in
ะฒ [Routing] -> [Filters]
ืจืื ืคึฟืืืืจืืจืื ื (ืื ืืึทืื ื ืืื ืึทืืืืึทืื ื) ืืื ืึท ืืขืฆืืึทื ืืืึธืก ืืื ืืืืฉืึทืืืึทืื ืืขื ืืฆื ืืื ืงืึทื ืืืฉืึทื ืืงืฉืึทื ืืื ืืื ืึทืืืฉ ืจืืืื ื ืคึผืจืึธืืึธืงืึธืืก (ืืื ืืขืจืืืขืจ ืืืืื ืื ืืืฆื ื ืึธื ืื ืกืืึธืืื ื ืื ืคึผืขืงื) ืจืืืื ื), ืึธืืขืจ ืขืก ืืขื ืขื ืฆืืืื ืืฉืืงืึทืืืข ืงืืืื ืืื ืื ืื ืงืึทืืื ื ืคืืืืขืจืก:
- ืงืึธื ื ืขืงืืขื-ืืื - ืคืืืืขืจืื ื ืคืืจืืื ืื ืจืืฅ
- ืืื ืึทืืืฉ-ืืื - ืคืืืืขืจืื ื ืืื ืึทืืืฉ ืจืืฅ ืืืงืืืขื ืืืจื PPP ืืื DCHP
ืคึฟืืืืจืืจืื ื ืึทืืึทืื ืืืจ ืฆื ื ืืฉื ืืืืื ืึทืืืขืงืืืึทืจืคื ืจืืฅ, ืึธืืขืจ ืืืื ืืืืฉื ืึท ื ืืืขืจ ืคืื ืึธืคึผืฆืืขืก: ืืืกืืึทื ืกืข, ืจืืืื ื-ืืึทืจืง, ืืึทืืขืจืงืื ื, ืคืึทืจื ืขื, ืฆืื ืคืึทืจื ืขื, ...
ืืึธืก ืืื ืึท ืืืืขืจ ืืขื ืื ืืขืฆืืึทื ืืื ืืืื ืืืจ ืงืขื ืขื ืืึธื ืขืคึผืขืก ืึธื ืจืืืื ื ืคืืืืขืจืก (ืึธืืขืจ ื ืืฉื ืกืงืจืืคึผืก), ืืึธื ื ืื ื ืืฆื ืจืืืื ื ืคืืืืขืจืก, ืืึธื ื ืื ืฆืขืืืฉื ืืื ืืื ืื ืืืืก ืืืขืื ืงืึทื ืคืืืืขืจ ืื ืจืึทืืืขืจ ื ืึธื ืืืจ. ืืื ืืขื ืงืึธื ืืขืงืกื ืคืื ืืื ืึทืืืฉ ืจืืืื ื, ืจืืืื ื ืคืืืืขืจืก ืืืขื ืืืื ืืขืืืืื ื ืคืื ืืขืจ ืึธืคื ืืื ืืขืจ ืคึผืจืึธืืืงืืืื.
ืืึทืฉืืขืืืงื ืื ืจืืืื ื ืืืจืง ืคึฟืึทืจ ืืื ืึทืืืฉ ืจืึธืืืขืก
ื ืืืืฉืคึผืื ืคืื ืึท ืืืื ืจืึทืืืขืจ. ืืื ืืึธืื ืฆืืืื VPN ืงืึทื ืขืงืฉืึทื ื ืงืึทื ืคืืืืขืจื ืืื ืื ืคืึทืจืงืขืจ ืืื ืืื ืืึธื ืืืื ืืื ืืขืืืืงืื ืืื ืืืื ืืื ืื ืจืืืื ื ืืืฉื. ืืื ืืขืจ ืืขืืืืงืขืจ ืฆืืื, ืืื ืืืืื ืื ืจืืฅ ืฆื ืืืื ืืืฉืืคื ืืืืืึธืืึทืืืฉ ืืืขื ืื ืฆืืืื ื ืืื ืึทืงืืืืืืืืื:
#ะัะธ ัะพะทะดะฐะฝะธะธ vpn ะฟะพะดะบะปััะตะฝะธะน ัะบะฐะทัะฒะฐะตะผ ัะพะทะดะฐะฝะธะต default route ะธ ะทะฐะดะฐะตะผ ะดะธััะฐะฝัะธั
/interface pptp-client
add connect-to=X.X.X.X add-default-route=yes default-route-distance=101 ...
add connect-to=Y.Y.Y.Y add-default-route=yes default-route-distance=100 ...
#ะคะธะปัััะฐะผะธ ะพัะฟัะฐะฒะปัะตะผ ะผะฐัััััั ะฒ ะพะฟัะตะดะตะปะตะฝะฝัะต ัะฐะฑะปะธัั ะผะฐัััััะธะทะฐัะธะธ ะฝะฐ ะพัะฝะพะฒะต ะฟะพะดัะตัะธ ะฝะฐะทะฝะฐัะตะฝะธั ะธ ะดะธััะฐะฝัะธะธ
/routing filter
add chain=dynamic-in distance=100 prefix=0.0.0.0/0 action=passthrough set-routing-mark=over-vpn1
add chain=dynamic-in distance=101 prefix=0.0.0.0/0 action=passthrough set-routing-mark=over-vpn2
ืืื ืืึธื ื ืื ืืืืกื ืืืึธืก, ืืืกืืึธืืข ืึท ืืฉืืง, ืึธืืขืจ ืืืื ืืืจ ืืึทืื ืึท VRF ืคึฟืึทืจ ืื ืคึผืคึผืคึผ ืฆืืืื ื, ืืขืจ ืืึทืจืฉืจืื ืฆื 0.0.0.0/0 ืืืขื ื ืึธื ืืึทืงืืืขื ืืื ืื ืืืืคึผื ืืืฉ. ืึทื ืืขืจืฉ, ืึทืืฅ ืืืึธืื ืืืื ืืคืืื ืืจืื ืืขืจ.
ืืืกืืืืืื ื ืงืึธื ื ืขืงืืขื ืจืึธืืืขืก
ืืื ืืึธืก ืืื ืคืืจืืื ืื:
/route filter
add chain=connected-in prefix=192.168.100.0/24 action=reject
ืืืืึทืืื ื ืืืฉืืจืื
RouterOS ืืื ืึท ื ืืืขืจ ืคืื ืืืฉืืจืื ืคึฟืึทืจ ืืืืึทืืื ื ืจืืืื ื:
[Tool]->[Tourch]
- ืึทืืึทืื ืืืจ ืฆื ืืขื ืคึผืึทืงืืฅ ืืืืฃ ืื ืืขืจืคืืืกืื/ip route check
- ืึทืืึทืื ืืืจ ืฆื ืืขื ืืืึธืก ืืืืืืืื ืื ืคึผืึทืงืึทื ืืืขื ืืืื ืืขืฉืืงื ืฆื, ืืื ื ืืฉื ืึทืจืืขืื ืืื ืจืืืื ื ืืืฉื/ping routing-table=<name>
ะธ/tool traceroute routing-table=<name>
- ืคึผืื ื ืืื ืฉืคึผืืจ ื ืืฆื ืื ืกืคึผืขืกืืคืืขื ืจืืืื ื ืืืฉaction=log
ะฒ[IP]->[Firewall]
- ืึท ืืืกืืขืฆืืืื ื ืืขืฆืืึทื ืืืึธืก ืึทืืึทืื ืืืจ ืฆื ืฉืคึผืืจ ืื ืืจื ืคืื ืึท ืคึผืึทืงืึทื ืฆืืืืืขื ืื ืคึผืึทืงืึทื ืืืืคื, ืืขื ืงืึทืืฃ ืืื ืื ืืืฆื ืืื ืึทืืข ืงืืืื ืืื ืืืฉื
ืืงืืจ: www.habr.com