You are on page 1of 1

/ip firewall nat

add action=masquerade chain=srcnat out-interface=ether1-ISP-1


add action=masquerade chain=srcnat out-interface=ether2-ISP-2

/ip firewall mangle


add action=mark-connection chain=prerouting connection-mark=no-mark \
in-interface=ether1-ISP-1 new-connection-mark=isp-1 passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark \
in-interface=ether2-ISP-2 new-connection-mark=isp-2 passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark \
in-interface=ether3-swicth new-connection-mark=isp-1 passthrough=yes \
per-connection-classifier=both-addresses-and-ports:2/0
add action=mark-connection chain=prerouting connection-mark=no-mark \
in-interface=ether3-swicth new-connection-mark=isp-2 passthrough=yes \
per-connection-classifier=both-addresses-and-ports:2/1
add action=mark-routing chain=prerouting connection-mark=isp-1 in-interface=\
ether3-swicth new-routing-mark=KE_ISP1 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=isp-2 in-interface=\
ether3-swicth new-routing-mark=KE_ISP2 passthrough=yes
add action=mark-routing chain=output connection-mark=isp-1 new-routing-mark=\
KE_ISP1 passthrough=yes
add action=mark-routing chain=output connection-mark=isp-2 new-routing-mark=\
KE_ISP2 passthrough=yes

/ip route
add check-gateway=ping distance=1 gateway=192.168.100.1 routing-mark=KE_ISP1
add check-gateway=ping distance=1 gateway=192.168.0.254 routing-mark=KE_ISP2
add check-gateway=ping distance=1 gateway=192.168.100.1
add check-gateway=ping distance=1 gateway=192.168.0.254

You might also like