You are on page 1of 8

/ip firewall address-list

add address=192.168.0.0/16
list=IP_LOKAL

add address=10.10.0.0/16
list=IP_LOKAL

/ip firewall nat

add chain=srcnat out-


interface="ether1_Internet_fiber"
action=masquerade

add chain=srcnat out-


interface="ether6_mikrotik_astinet"
action=masquerade

/ip firewall mangle


add action=accept chain=prerouting dst-
address-list=IP_LOKAL src-address-
list=IP_LOKAL
add action=accept chain=postrouting
dst-address-list=IP_LOKAL src-address-
list=IP_LOKAL

add action=accept chain=forward dst-


address-list=IP_LOKAL src-address-
list=IP_LOKAL

add action=accept chain=input dst-


address-list=IP_LOKAL src-address-
list=IP_LOKAL

add action=accept chain=output dst-


address-list=IP_LOKAL src-address-
list=IP_LOKAL

add action=mark-connection chain=input


in-interface="ether1_Internet_fiber" new-
connection-mark="cm-
ether1_Internet_fiber" passthrough=yes
add action=mark-connection chain=input
in-interface="ether6_mikrotik_astinet"
new-connection-mark="cm-
ether6_mikrotik_astinet"
passthrough=yes

add action=mark-routing chain=output


connection-mark="cm-
ether1_Internet_fiber" new-routing-
mark="to-ether1_Internet_fiber"
passthrough=yes

add action=mark-routing chain=output


connection-mark="cm-
ether6_mikrotik_astinet" new-routing-
mark="to-ether6_mikrotik_astinet"
passthrough=yes

add action=mark-connection
chain=prerouting dst-address-type=!local
new-connection-mark="cm-
ether1_Internet_fiber" passthrough=yes
per-connection-classifier=both-
addresses-
and-ports:2/0 dst-address-list=!
IP_LOKAL src-address-list=IP_LOKAL

add action=mark-connection
chain=prerouting dst-address-type=!local
new-connection-mark="cm-
ether6_mikrotik_astinet"
passthrough=yes per-connection-
classifier=both-addresses-and-ports:2/1
dst-address-list=!IP_LOKAL src-address-
list=IP_LOKAL

add action=mark-routing
chain=prerouting connection-mark="cm-
ether1_Internet_fiber" new-routing-
mark="to-ether1_Internet_fiber"
passthrough=yes dst-address-list=!
IP_LOKAL src-address-list=IP_LOKAL

add action=mark-routing
chain=prerouting connection-mark="cm-
ether6_mikrotik_astinet" new-routing-
mark="to-ether6_mikrotik_astinet"
passthrough=yes dst-address-list=!
IP_LOKAL src-address-list=IP_LOKAL

/ip route
add check-gateway=ping distance=1
gateway=173.168.169.177 routing-
mark="to-ether1_Internet_fiber"

add check-gateway=ping distance=1


gateway=10.10.1.1 routing-mark="to-
ether6_mikrotik_astinet"

add check-gateway=ping distance=1


gateway=173.168.169.177

add check-gateway=ping distance=2


gateway=10.10.1.1

You might also like