Download as txt, pdf, or txt
Download as txt, pdf, or txt
You are on page 1of 1

/ip address

add address=192.168.0.2/24 interface=wan1


add address=192.168.1.2/24 interface=wan2

add address=192.168.10.1/24 interface=lan

/ip firewall nat


add chain=srcnat out-interface=wan1 action=masquerade
add chain=srcnat out-interface=wan2 action=masquerade

/ip firewall mangle


add chain=prerouting in-interface=wan1 connection-state=new new-connection-
mark=wan1_conn action=mark-connection passthrough=yes
add chain=prerouting in-interface=wan2 connection-state=new new-connection-
mark=wan2_conn action=mark-connection passthrough=yes

add chain=output connection-mark=wan1_conn new-routing-mark=wan1_conn action=mark-


routing passthrough=yes
add chain=output connection-mark=wan2_conn new-routing-mark=wan2_conn action=mark-
routing passthrough=yes

/ip firewall mangle


add chain=prerouting in-interface=lan connection-state=new dst-address-type=!local
per-connection-classifier=both-addresses-and-ports:3/0 action=mark-connection new-
connection-mark=wan1_conn passthrough=yes
add chain=prerouting in-interface=lan connection-state=new dst-address-type=!local
per-connection-classifier=both-addresses-and-ports:3/1 action=mark-connection new-
connection-mark=wan1_conn passthrough=yes
add chain=prerouting in-interface=lan connection-state=new dst-address-type=!local
per-connection-classifier=both-addresses-and-ports:3/2 action=mark-connection new-
connection-mark=wan1_conn passthrough=yes

add chain=prerouting in-interface=lan connection-mark=wan1_conn action=mark-routing


new-routing-mark=to_wan1 passthrough=yes
add chain=prerouting in-interface=lan connection-mark=wan2_conn action=mark-routing
new-routing-mark=to_wan2 passthrough=yes

/ip firewall mangle


add chain=prerouting dst-address=192.168.0.0/24 action=accept in-interface=lan
add chain=prerouting dst-address=192.168.1.0/24 action=accept in-interface=lan

/ip route
add gateway=192.168.0.1 routing-mark=to_wan1 check-gateway=ping
add gateway=192.168.1.1 routing-mark=to_wan2 check-gateway=ping

add gateway=192.168.0.1,192.168.1.1 check-gateway=ping distance=2

You might also like