You are on page 1of 1

/ip firewall mangle

add chain=input in-interface=FIBRE action=mark-connection new-connection-


mark=FIBRE_conn

add chain=output connection-mark=FIBRE_conn action=mark-routing new-routing-


mark=to_FIBRE

add chain=prerouting dst-address=192.168.1.0/24 action=accept in-interface=PONT


add chain=prerouting dst-address=192.168.1.0/24 action=accept in-interface=CYBER
add chain=prerouting dst-address=192.168.1.0/24 action=accept in-interface=WIFI
CYBER

add chain=prerouting dst-address-type=!local in-interface=PONT per-connection-


classifier=both-addresses-and-ports:1/0 action=mark-connection new-connection-
mark=WAN1_conn passthrough=yes
add chain=prerouting dst-address-type=!local in-interface=CYBER per-connection-
classifier=both-addresses-and-ports:2/0 action=mark-connection new-connection-
mark=WAN1_conn passthrough=yes
add chain=prerouting dst-address-type=!local in-interface=WIFI CYBER per-
connection-classifier=both-addresses-and-ports:3/0 action=mark-connection new-
connection-mark=WAN1_conn passthrough=yes

add chain=prerouting connection-mark=FIBRE_conn in-interface=PONT action=mark-


routing new-routing-mark=to_FIBRE
add chain=prerouting connection-mark=FIBRE_conn in-interface=CYBER action=mark-
routing new-routing-mark=to_FIBRE
add chain=prerouting connection-mark=FIBRE_conn in-interface=WIFI CYBER
action=mark-routing new-routing-mark=to_FIBRE

/ip route
add dst-address=0.0.0.0/0 gateway=192.168.1.1 routing-mark=to_FIBRE check-
gateway=ping

add dst-address=0.0.0.0/0 gateway=192.168.1.1 distance=1 check-gateway=ping

/ip firewall nat


add chain=srcnat out-interface=FIBRE action=masquerade

You might also like