/ip firewall address-list add address=172.16.1.0/24 comment="" disabled=no list=locales add address=192.168.2.

1/24 comment="" disabled=no list=locales Aca hay que fijarse que yo tengo 3 interfaces, la que va a mi linux, en tu caso seria tu thunder, es una IP fija, 172.16.3.250, tu cambia esa IP por la IP de tu thunder (172.16.2.2) 2.- Reglas en la tabla mangle /ip firewall mangle add action=accept chain=prerouting comment="" disabled=no dst-address-list=local es src-address=172.16.1.0/24 add action=mark-connection chain=input comment="Marcar conexiones nuevas es para pppoe1" connection-state=new disabled=no in-interface=wan1-pppoe new-connection-mark=wan1 passthrough=yes add action=mark-connection chain=input comment="Marcar conexiones nuevas es para pppoe2" connection-state=new disabled=no in-interface=wan2-pppoe new-connection-mark=wan2 passthrough=yes add action=mark-connection chain=input comment="Marcar conexiones nuevas es para pppoe3" connection-state=new disabled=no in-interface=wan3-pppoe new-connection-mark=wan3 passthrough=yes entrant \ entrant \ entrant \

add action=mark-connection chain=prerouting comment="Marcar conexiones estableci das entrantes para pppoe1" connection-state=established disabled=no in-interface =\ wan1-pppoe new-connection-mark=wan1 passthrough=yes add action=mark-connection chain=prerouting comment="Marcar conexiones estableci das entrnates para pppoe2" connection-state=established disabled=no in-interface =\ wan2-pppoe new-connection-mark=wan2 passthrough=yes add action=mark-connection chain=prerouting comment="Marcar conexiones estableci das entrnates para pppoe3" connection-state=established disabled=no in-interface =\ wan3-pppoe new-connection-mark=wan3 passthrough=yes add action=mark-connection chain=prerouting comment="Marcar conexiones relaciona das entrantes para pppoe1" connection-state=related disabled=no in-interface=wan 1-pppoe \ new-connection-mark=wan1 passthrough=yes add action=mark-connection chain=prerouting comment="Marcar conexiones relaciona das entrantes para pppoe2" connection-state=related disabled=no in-interface=wan 2-pppoe \ new-connection-mark=wan2 passthrough=yes add action=mark-connection chain=prerouting comment="Marcar conexiones relaciona das entrantes para pppoe2" connection-state=related disabled=no in-interface=wan 2-pppoe \ new-connection-mark=wan3 passthrough=yes add action=mark-routing chain=output comment="Marcar nueva ruta de salida para p ppoe1" connection-mark=wan1 disabled=no new-routing-mark=static-wan1 passthrough =no add action=mark-routing chain=output comment="Marcar nueva ruta de salida para p ppoe2" connection-mark=wan2 disabled=no new-routing-mark=static-wan2 passthrough =no add action=mark-routing chain=output comment="Marcar nueva ruta de salida para p ppoe3" connection-mark=wan3 disabled=no new-routing-mark=static-wan3 passthrough =no

16.0/24 add action=mark-connection chain=prerouting comment="Marcar trafico establecido que no es local usando PCC (2 adsl de 3)" connection-state=established disabled =no \ dst-address-type=!local new-connection-mark=wan2_pcc_conn passthrough=yes pe r-connection-classifier=both-addresses:3/1 src-address=172.1.add action=mark-connection chain=prerouting comment="Marcar trafico nuevo que no es local usando PCC (1 adsl de 3)" connection-state=new disabled=no dst-addres s-type=\ !local new-connection-mark=wan1_pcc_conn passthrough=yes per-connection-clas sifier=both-addresses:3/0 src-address=172.0/24 add action=mark-connection chain=prerouting comment="Marcar trafico nuevo que no es local usando PCC (3 adsl de 3)" connection-state=new disabled=no dst-addres s-type=\ !local new-connection-mark=wan3_pcc_conn passthrough=yes per-connection-clas sifier=both-addresses:3/2 src-address=172.16.0/24 add action=mark-connection chain=prerouting comment="Marcar trafico relacionado que no es local usando PCC (2 adsl de 3)" connection-state=related disabled=no \ dst-address-type=!local new-connection-mark=wan2_pcc_conn passthrough=yes pe r-connection-classifier=both-addresses:3/1 src-address=172.1.0/24 add action=mark-connection chain=prerouting comment="Marcar trafico establecido que no es local usando PCC (1 adsl de 3)" connection-state=established disabled =no \ dst-address-type=!local new-connection-mark=wan1_pcc_conn passthrough=yes pe r-connection-classifier=both-addresses:3/0 src-address=172.1.16.1.16.16.1.1.1.0/24 add action=mark-connection chain=prerouting comment="Marcar trafico nuevo que no es local usando PCC (2 adsl de 3)" connection-state=new disabled=no dst-addres s-type=\ !local new-connection-mark=wan2_pcc_conn passthrough=yes per-connection-clas sifier=both-addresses:3/1 src-address=172.16.0/24 add action=mark-connection chain=prerouting comment="Marcar trafico establecido que no es local usando PCC (3 adsl de 3)" connection-state=established disabled =no \ dst-address-type=!local new-connection-mark=wan3_pcc_conn passthrough=yes pe r-connection-classifier=both-addresses:3/2 src-address=172.16.16.1.0/24 add action=mark-connection chain=prerouting comment="Marcar trafico relacionado que no es local usando PCC (3 adsl de 3)" connection-state=related disabled=no \ dst-address-type=!local new-connection-mark=wan3_pcc_conn passthrough=yes pe r-connection-classifier=both-addresses:3/2 src-address=172.0/24 add action=mark-routing chain=prerouting comment="Enrutamiento para marca PCC (1 adsl de 3)" connection-mark=wan1_pcc_conn disabled=no new-routing-mark=wan1 \ passthrough=yes add action=mark-routing chain=prerouting comment="Enrutamiento para marca PCC (2 adsl de 3)" connection-mark=wan2_pcc_conn disabled=no new-routing-mark=wan2 \ passthrough=yes .0/24 add action=mark-connection chain=prerouting comment="Marcar trafico relacionado que no es local usando PCC (1 adsl de 3)" connection-state=related disabled=no \ dst-address-type=!local new-connection-mark=wan1_pcc_conn passthrough=yes pe r-connection-classifier=both-addresses:3/0 src-address=172.16.1.

0.0/0 g ateway=wan3-pppoe routing-mark=wan3 scope=30 target-scope=10 add check-gateway=ping comment="" disabled=no distance=1 dst-address=0.0..0.0.0.0.2. Reglas en la tabla NAT /ip firewall nat add action=dst-nat chain=dstnat comment="PROXY TRANSPARENTE (WLAN)" disabled=yes dst-port=80 in-interface=LAN protocol=tcp to-addresses=192.0/0 g ateway=wan1-pppoe scope=30 target-scope=10 add check-gateway=ping comment="" disabled=no distance=2 dst-address=0.0.0.Rutas /ip route add check-gateway=ping comment="" disabled=no distance=1 dst-address=0.0.0/0 g ateway=wan1-pppoe routing-mark=static-wan1 scope=30 target-scope=10 add check-gateway=ping comment="" disabled=no distance=2 dst-address=0.0.0.0/0 g ateway=wan1-pppoe routing-mark=wan1 scope=30 target-scope=10 add check-gateway=ping comment="" disabled=no distance=1 dst-address=0.0.168.0.0/0 g ateway=wan3-pppoe scope=30 target-scope=10 .2 to-ports=\ 3128 4.0.add action=mark-routing chain=prerouting comment="Enrutamiento para marca PCC (3 adsl de 3)" connection-mark=wan3_pcc_conn disabled=no new-routing-mark=wan3 \ passthrough=yes 3.0.0/0 g ateway=wan2-pppoe routing-mark=static-wan2 scope=30 target-scope=10 add check-gateway=ping comment="" disabled=no distance=3 dst-address=0.0.0/0 g ateway=wan2-pppoe scope=30 target-scope=10 add check-gateway=ping comment="" disabled=no distance=3 dst-address=0.0/0 g ateway=wan3-pppoe routing-mark=static-wan3 scope=30 target-scope=10 add check-gateway=ping comment="" disabled=no distance=1 dst-address=0.0/0 g ateway=wan2-pppoe routing-mark=wan2 scope=30 target-scope=10 add check-gateway=ping comment="" disabled=no distance=1 dst-address=0.0.0.