|
楼主 |
发表于 2010-6-11 08:49:15
|
显示全部楼层
/interface bridge
add admin-mac=00:00:00:00:00:00 ageing-time=5m arp=enabled auto-mac=yes \
comment="" disabled=no forward-delay=15s max-message-age=20s mtu=1500 \
name=bridge1 priority=0x8000 protocol-mode=none transmit-hold-count=6
/interface vlan
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-2 \
vlan-id=2
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-3 \
vlan-id=3
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-4 \
vlan-id=4
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-5 \
vlan-id=5
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-6 \
vlan-id=6
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-7 \
vlan-id=7
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-8 \
vlan-id=8
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-9 \
vlan-id=9
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-10 \
vlan-id=10
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-14 \
vlan-id=14
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-12 \
vlan-id=12
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-13 \
vlan-id=13
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-15 \
vlan-id=15
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-16 \
vlan-id=16
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-17 \
vlan-id=17
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-18 \
vlan-id=18
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-23 \
vlan-id=23
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-11 \
vlan-id=11
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-20 \
vlan-id=20
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-21 \
vlan-id=21
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-22 \
vlan-id=22
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-19 \
vlan-id=19
add arp=enabled comment="" disabled=no interface=bridge1 mtu=1500 name=v-24 \
vlan-id=24
/ppp profile
set default change-tcp-mss=yes comment="" name=default only-one=default \
use-compression=default use-encryption=default use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-2 only-one=no remote-address=\
1.1.1.2 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-3 only-one=no remote-address=\
1.1.1.3 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-4 only-one=no remote-address=\
1.1.1.4 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-5 only-one=no remote-address=\
1.1.1.5 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-6 only-one=no remote-address=\
1.1.1.6 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-7 only-one=no remote-address=\
1.1.1.7 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-8 only-one=no remote-address=\
1.1.1.8 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-9 only-one=no remote-address=\
1.1.1.9 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-10 only-one=no remote-address=\
1.1.1.10 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-11 only-one=no remote-address=\
1.1.1.11 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-12 only-one=no remote-address=\
1.1.1.12 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-13 only-one=no remote-address=\
1.1.1.13 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-14 only-one=no remote-address=\
1.1.1.14 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-15 only-one=no remote-address=\
1.1.1.15 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-16 only-one=no remote-address=\
1.1.1.16 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-17 only-one=no remote-address=\
1.1.1.17 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-18 only-one=no remote-address=\
1.1.1.18 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-19 only-one=no remote-address=\
1.1.1.19 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-20 only-one=no remote-address=\
1.1.1.20 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-21 only-one=no remote-address=\
1.1.1.21 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-22 only-one=no remote-address=\
1.1.1.22 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-23 only-one=no remote-address=\
1.1.1.23 use-compression=default use-encryption=default \
use-vj-compression=default
add change-tcp-mss=yes comment="" name=adsl-24 only-one=no remote-address=\
1.1.1.24 use-compression=default use-encryption=default \
use-vj-compression=default
set default-encryption change-tcp-mss=yes comment="" name=default-encryption \
only-one=default use-compression=default use-encryption=yes \
use-vj-compression=default
/interface pppoe-client
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-2 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v2 password="" profile=adsl-2 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-3 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v3 password="" profile=adsl-3 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-4 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v4 password="" profile=adsl-4 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-5 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v5 password="" profile=adsl-5 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-6 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v6 password="" profile=adsl-6 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-7 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v7 password="" profile=adsl-7 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-8 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v8 password="" profile=adsl-8 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-9 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v9 password="" profile=adsl-9 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-16 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v16 password="" profile=adsl-16 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-11 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v11 password="" profile=adsl-11 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-12 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v12 password="" profile=adsl-12 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-13 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v13 password="" profile=adsl-13 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-14 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v14 password="" profile=adsl-14 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-15 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v15 password="" profile=adsl-15 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-17 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v17 password="" profile=adsl-17 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-18 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v18 password="" profile=adsl-18 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-19 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v19 password="" profile=adsl-19 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-20 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v20 password="" profile=adsl-20 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-21 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v21 password="" profile=adsl-21 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-22 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v22 password="" profile=adsl-22 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-23 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v23 password="" profile=adsl-23 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-24 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v24 password="" profile=adsl-24 service-name="" \
use-peer-dns=yes user=""
add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment="" \
dial-on-demand=no disabled=no interface=v-10 max-mru=1480 max-mtu=1480 \
mrru=disabled name=adsl-v10 password="" profile=adsl-10 service-name="" \
use-peer-dns=yes user=""
/interface bridge nat
add action=src-nat chain=srcnat comment=adsl-2 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:02 vlan-id=2
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:02/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=2
add action=src-nat chain=srcnat comment=adsl-3 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:03 vlan-id=3
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:03/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=3
add action=src-nat chain=srcnat comment=adsl-4 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:04 vlan-id=4
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:04/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=4
add action=src-nat chain=srcnat comment=adsl-5 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:05 vlan-id=5
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:05/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=5
add action=src-nat chain=srcnat comment=adsl-6 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:06 vlan-id=6
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:06/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=6
add action=src-nat chain=srcnat comment=adsl-7 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:07 vlan-id=7
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:07/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=7
add action=src-nat chain=srcnat comment=adsl-8 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:08 vlan-id=8
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:08/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=8
add action=src-nat chain=srcnat comment=adsl-9 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:09 vlan-id=9
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:09/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=9
add action=src-nat chain=srcnat comment=adsl-10 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:10 vlan-id=10
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:10/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=10
add action=src-nat chain=srcnat comment=adsl-11 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:11 vlan-id=11
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:11/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=11
add action=src-nat chain=srcnat comment=adsl-12 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:12 vlan-id=12
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:12/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=12
add action=src-nat chain=srcnat comment=adsl-13 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:13 vlan-id=13
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:13/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=13
add action=src-nat chain=srcnat comment=adsl-14 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:14 vlan-id=14
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:14/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=14
add action=src-nat chain=srcnat comment=adsl-15 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:15 vlan-id=15
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:15/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=15
add action=src-nat chain=srcnat comment=adsl-16 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:16 vlan-id=16
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:16/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=16
add action=src-nat chain=srcnat comment=adsl-17 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:17 vlan-id=17
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:17/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=17
add action=src-nat chain=srcnat comment=adsl-18 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:18 vlan-id=18
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:18/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=18
add action=src-nat chain=srcnat comment=adsl-19 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:19 vlan-id=19
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:19/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=19
add action=src-nat chain=srcnat comment=adsl-20 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:20 vlan-id=20
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:20/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=20
add action=src-nat chain=srcnat comment=adsl-21 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:21 vlan-id=21
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:21/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=21
add action=src-nat chain=srcnat comment=adsl-22 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:22 vlan-id=22
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:22/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=22
add action=src-nat chain=srcnat comment=adsl-23 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:23 vlan-id=23
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:23/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=23
add action=src-nat chain=srcnat comment=adsl-24 disabled=no mac-protocol=vlan \
to-src-mac-address=00:02:B3:5D:B2:24 vlan-id=24
add action=dst-nat chain=dstnat comment="" disabled=no dst-mac-address=\
00:02:B3:5D:B2:24/FF:FF:FF:FF:FF:FF mac-protocol=vlan to-dst-mac-address=\
00:02:B3:5D:B2:A8 vlan-id=24
/interface bridge port
add bridge=bridge1 comment="" disabled=no edge=yes external-fdb=auto horizon=\
none interface=wan path-cost=10 point-to-point=auto priority=0x80
/interface bridge settings
set use-ip-firewall=no use-ip-firewall-for-pppoe=no use-ip-firewall-for-vlan=\
no
/ip dns
set allow-remote-requests=yes cache-max-ttl=1w cache-size=2048KiB \
max-udp-packet-size=512 primary-dns=202.96.134.133 secondary-dns=\
202.96.128.166
/ip firewall connection tracking
set enabled=yes generic-timeout=10m icmp-timeout=30s tcp-close-timeout=10s \
tcp-close-wait-timeout=1m tcp-established-timeout=5d \
tcp-fin-wait-timeout=2m tcp-last-ack-timeout=30s \
tcp-syn-received-timeout=5s tcp-syn-sent-timeout=10s tcp-syncookie=no \
tcp-time-wait-timeout=2m udp-stream-timeout=3m udp-timeout=30s
/ip firewall mangle
add action=change-mss chain=forward comment="" disabled=no new-mss=\
clamp-to-pmtu protocol=tcp tcp-flags=syn
add action=accept chain=prerouting comment="" disabled=no dst-address-type=\
local src-address=192.168.1.0/24
add action=accept chain=prerouting comment="" disabled=no dst-address=\
192.168.1.0/24 src-address=192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=1 nth=23,1 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=2 nth=23,2 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=3 nth=23,3 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=4 nth=23,4 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=5 nth=23,5 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=6 nth=23,6 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=7 nth=23,7 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=8 nth=23,8 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=9 nth=23,9 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=10 nth=23,10 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=11 nth=23,11 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=12 nth=23,12 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=13 nth=23,13 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=14 nth=23,14 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=15 nth=23,15 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=16 nth=23,16 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=17 nth=23,17 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=18 nth=23,18 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=19 nth=23,19 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=20 nth=23,20 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=21 nth=23,21 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=22 nth=23,22 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-connection chain=prerouting comment="" disabled=no \
new-connection-mark=23 nth=23,23 passthrough=yes src-address=\
192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=1 \
disabled=no new-routing-mark=1 passthrough=no src-address=192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=2 \
disabled=no new-routing-mark=2 passthrough=no src-address=192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=3 \
disabled=no new-routing-mark=3 passthrough=no src-address=192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=4 \
disabled=no new-routing-mark=4 passthrough=no src-address=192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=5 \
disabled=no new-routing-mark=5 passthrough=no src-address=192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=6 \
disabled=no new-routing-mark=6 passthrough=no src-address=192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=7 \
disabled=no new-routing-mark=7 passthrough=no src-address=192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=8 \
disabled=no new-routing-mark=8 passthrough=no src-address=192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=9 \
disabled=no new-routing-mark=9 passthrough=no src-address=192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=10 \
disabled=no new-routing-mark=10 passthrough=no src-address=\
192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=11 \
disabled=no new-routing-mark=11 passthrough=no src-address=\
192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=12 \
disabled=no new-routing-mark=12 passthrough=no src-address=\
192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=13 \
disabled=no new-routing-mark=13 passthrough=no src-address=\
192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=14 \
disabled=no new-routing-mark=14 passthrough=no src-address=\
192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=15 \
disabled=no new-routing-mark=15 passthrough=no src-address=\
192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=16 \
disabled=no new-routing-mark=16 passthrough=no src-address=\
192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=17 \
disabled=no new-routing-mark=17 passthrough=no src-address=\
192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=18 \
disabled=no new-routing-mark=18 passthrough=no src-address=\
192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=19 \
disabled=no new-routing-mark=19 passthrough=no src-address=\
192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=20 \
disabled=no new-routing-mark=20 passthrough=no src-address=\
192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=21 \
disabled=no new-routing-mark=21 passthrough=no src-address=\
192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=22 \
disabled=no new-routing-mark=22 passthrough=no src-address=\
192.168.1.0/24
add action=mark-routing chain=prerouting comment="" connection-mark=23 \
disabled=no new-routing-mark=23 passthrough=no src-address=\
192.168.1.0/24
/ip firewall nat
add action=masquerade chain=srcnat comment="" disabled=no src-address=\
192.168.1.0/24
/ip route
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.17 \
routing-mark=16 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.16 \
routing-mark=15 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.15 \
routing-mark=14 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.9 \
routing-mark=8 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.4 \
routing-mark=3 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.2 \
routing-mark=1 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.5 \
routing-mark=4 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.6 \
routing-mark=5 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.8 \
routing-mark=7 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.7 \
routing-mark=6 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.3 \
routing-mark=2 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.10 \
routing-mark=9 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.11 \
routing-mark=10 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.12 \
routing-mark=11 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.13 \
routing-mark=12 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.14 \
routing-mark=13 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.21 \
routing-mark=20 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.18 \
routing-mark=17 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.19 \
routing-mark=18 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.20 \
routing-mark=19 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.23 \
routing-mark=22 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.22 \
routing-mark=21 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.24 \
routing-mark=23 scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.24 \
scope=30 target-scope=10
这就是配置代码
现在还有一个问题就是重启只能连上15条线
请猛男指教一下是什么问题? |
|