VPN借线破解电信封路由问题请教?
VPN借线破解电信封路由问题请教?不知道大家是用什么VPN的呢 ,pptp还是l2tp,这两种我都测试过了,不行。不知道是不是VPN提供方要设置什么呢?
bobwalker 发表于 2012-2-19 21:48 static/image/common/back.gif
路由标记只标记了TCP,那使用UDP协议的DNS应用协议不能通过,ICMP也不能通过了。难道你想让DNS等所有UDP协议 ...
/ip firewall nat
add action=src-nat chain=srcnat comment=ADSL1 connection-mark=ad1 disabled=no src-address=10.10.10.0/24 to-addresses=182.33.210.230
add action=src-nat chain=srcnat comment=ADSL2 connection-mark=ad2 disabled=no src-address=10.10.10.0/24 to-addresses=182.33.208.219
add action=src-nat chain=srcnat comment=ADSL3 connection-mark=ad3 disabled=no src-address=10.10.10.0/24 to-addresses=182.33.209.222
add action=masquerade chain=srcnat comment="" disabled=yes
/ip firewall nat> /
> ip firewall mangle export
# dec/30/2011 14:41:20 by RouterOS 3.30
# software id = Z9D1-B07F
#
/ip firewall mangle
add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local new-connection-mark=ad1 passthrough=yes per-connection-classifier=\
both-addresses:3/0 src-address=10.10.10.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=ad1 disabled=no new-routing-mark=sl1 passthrough=yes src-address=10.10.10.0/24
add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local new-connection-mark=ad2 passthrough=yes per-connection-classifier=\
both-addresses:3/1 src-address=10.10.10.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=ad2 disabled=no new-routing-mark=sl2 passthrough=yes src-address=10.10.10.0/24
add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local new-connection-mark=ad3 passthrough=yes per-connection-classifier=\
both-addresses:3/2 src-address=10.10.10.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=ad3 disabled=no new-routing-mark=sl3 passthrough=yes src-address=10.10.10.0/24
add action=mark-routing chain=prerouting comment="" disabled=no new-routing-mark=vpn passthrough=yes protocol=tcp src-address=10.10.10.0/24
这个是别人成功的脚本啊,上图也是成功的。我自己做没成功而已! 你那么说确实有道理! 但似乎别人就是那样做的!所以我才觉的奇怪!
页:
[1]