You are on page 1of 1

/ip firewall mangle

add action=accept chain=prerouting dst-address=192.168.252.0/24


add action=accept chain=prerouting dst-address=192.168.254.0/24

add action=mark-connection chain=input in-interface=ether1_WAN new-connection-


mark=\
WAN_conn passthrough=yes
add action=mark-connection chain=input in-interface=ether3_ISP new-connection-
mark=\
ISP_conn passthrough=yes

add action=mark-routing chain=output connection-mark=WAN_conn \


new-routing-mark=to_WAN passthrough=yes
add action=mark-routing chain=output connection-mark=ISP_conn \
new-routing-mark=to_ISP passthrough=yes

add action=mark-connection chain=prerouting dst-address-type=!local \


new-connection-mark=WAN_conn passthrough=yes per-connection-classifier=\
both-addresses-and-ports:2/0 src-address=10.1.1.0/24

add action=mark-connection chain=prerouting dst-address-type=!local \


new-connection-mark=ISP_conn passthrough=yes per-connection-classifier=\
both-addresses-and-ports:2/1 src-address=10.1.1.0/24

add action=mark-routing chain=prerouting connection-mark=WAN1_conn \


new-routing-mark=to_WAN passthrough=yes
add action=mark-routing chain=prerouting connection-mark=ISP_conn \
new-routing-mark=to_ISP passthrough=yes

/ip firewall nat


add action=masquerade chain=srcnat out-interface=ether1_WAN
add action=masquerade chain=srcnat out-interface=ether3_ISP

/ip route
add check-gateway=ping distance=1 gateway=192.168.252.251 routing-mark=to_WAN
add check-gateway=ping distance=1 gateway=192.168.254.251 routing-mark=to_ISP

add check-gateway=ping distance=1 gateway=192.168.252.251,192.168.254.251

You might also like