找回密码
 注册

QQ登录

只需一步,快速开始

搜索
查看: 2247|回复: 5

[其它] 新人第一贴,有关部分常识及动态切换线路icmp掉线的问题

[复制链接]
发表于 2007-1-21 17:16:26 | 显示全部楼层 |阅读模式

马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。

您需要 登录 才可以下载或查看,没有账号?注册

×
各位好,这是我在本论坛发的第一篇贴子,由于是初学,有着众多问题可能让大家扔鸡蛋,不过为避免在同一问题上做第二次小白,请您将解决方法或致错因素也扔给我,在此谢了

好了,转入正题,观摩学习了论坛大量贴子后我参考以下内容:

host2318的 [双线不同网关分流教程]
专卖精品等高手在 [光纤用户使用NAT方式多还是使用masquerade方式的多] 中的讨论
wwjun的 [双网关按源地址动态稳固分流]
bow在 [关于ros限速] 中的回答

做了一个自已的路由routeros2.9.27,忘了说,路由也是打置顶贴子里下载的,感谢loverouter感谢routerclub.con感谢CCTV
路由也按照我的设想实现了:

1.识别接入IP并分配相应网关   192.168.1.146-147 to 192.168.111.1  ; 192.168.1.148-149 to 192.168.222.1
2.模拟静态SRC NAT转发
3.识别网关通路并动态切换网关并修改SRC NAT地址源
4.针对IP地址集合进行不同要求限速

但我在使用当中发现线路切换&3后http访问正常但部分软件就会掉线,例如ping(icmp),看以前的贴子QQ也会掉,所以想请教具体原因及解决方法
同时线路切换后我将当前的icmp连接清除后ping会恢复正常,QQ没条件测试
若我想在线路切换的同时删除icmp或某个特征连接,脚本应如何写?
再,假设以上脚本可行,如何识别只删除切换了网关的接入IP icmp连接(路由标识或连接标记+当前协议?)

按以下配置:
网关192.168.222.1掉线后
192.168.1.146 ping(icmp) www.163.com gateway 192.168.111.1 保留
192.168.1.168 ping(icmp) www.163.com gateway 192.168.222.1 删除

再问wwjun的 [双网关按源地址动态稳固分流]中通过nth来分辨新连接的奇偶,具体算法是什么?passthrough的作用又是什么?

最后请教ROS使用了大量脚本对性能有多大影响?较高配置(2.0+/1G/ATA)能否抵消这些影响?


以下是我路由的配置
RouterOS 2.9.27


  1. / interface ethernet
  2. set ether1 name="ether1_LAN"
  3. set ether2 name="ether2_WAN1"
  4. set ether3 name="ether3_WAN2"

  5. / ip address
  6. add address=192.168.1.254/24 network=192.168.1.0 broadcast=192.168.1.255 \
  7.     interface=ether1_LAN comment="LAN" disabled=no
  8. add address=192.168.111.110/24 network=192.168.111.0 broadcast=192.168.111.255 \
  9.     interface=ether2_WAN1 comment="WAN1" disabled=no
  10. add address=192.168.222.110/24 network=192.168.222.0 broadcast=192.168.222.255 \
  11.     interface=ether3_WAN2 comment="WAN2" disabled=no

  12. / ip firewall mangle
  13. add chain=prerouting src-address=192.168.1.146/31 action=mark-routing \
  14.     new-routing-mark=10 passthrough=yes comment="" disabled=no
  15. add chain=prerouting src-address=192.168.1.148/31 action=mark-routing \
  16.     new-routing-mark=20 passthrough=yes comment="" disabled=no

  17. / ip firewall nat
  18. add chain=srcnat routing-mark=10 action=src-nat to-addresses=192.168.111.110 \
  19.     to-ports=0-65535 comment="wan1" disabled=no
  20. add chain=srcnat routing-mark=20 action=src-nat to-addresses=192.168.111.110 \
  21.     to-ports=0-65535 comment="wan2" disabled=no

  22. / ip route
  23. add dst-address=0.0.0.0/0 gateway=192.168.111.1 scope=255 target-scope=10 \
  24.     routing-mark=10 comment="wan1" disabled=no
  25. add dst-address=0.0.0.0/0 gateway=192.168.111.1 scope=255 target-scope=10 \
  26.     routing-mark=20 comment="wan2" disabled=no

  27. / system script
  28. add name="wan1up" source="/ip route set wan1 gateway=192.168.111.1 \n/ip fir nat set wan1  to-
  29. addresses=192.168.111.110" \
  30.     policy=ftp,reboot,read,write,policy,test,winbox,password
  31. add name="wan1down" source="/ip route set wan1 gateway=192.168.222.1 \n/ip fir nat set wan1  to-
  32. addresses=192.168.222.110" \
  33.     policy=ftp,reboot,read,write,policy,test,winbox,password
  34. add name="wan2up" source="/ip route set wan2 gateway=192.168.222.1 \n/ip fir nat set wan2  to-
  35. addresses=192.168.222.110" \
  36.     policy=ftp,reboot,read,write,policy,test,winbox,password
  37. add name="wan2down" source="/ip route set wan2 gateway=192.168.111.1 \n/ip fir nat set wan2  to-
  38. addresses=192.168.111.110" \
  39.     policy=ftp,reboot,read,write,policy,test,winbox,password

  40. / tool netwatch
  41. add host=192.168.111.1 timeout=30ms interval=1s up-script=wan1up \
  42.     down-script=wan1down comment="" disabled=no
  43. add host=192.168.222.1 timeout=30ms interval=1s up-script=wan2up \
  44.     down-script=wan2down comment="" disabled=no

  45. / queue simple
  46. add name="queueA" target-addresses=192.168.1.146/32,192.168.1.147/32 \
  47.     dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8 \
  48.     queue=default-small/default-small limit-at=0/0 max-limit=64000/200000 \
  49.     burst-limit=128000/400000 burst-threshold=64000/180000 burst-time=3s/10s \
  50.     total-queue=default-small time=0s-1d,sun,mon,tue,wed,thu,fri,sat \
  51.     disabled=no
  52. add name="queueB" target-addresses=192.168.1.148/32,192.168.1.149/32 \
  53.     dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8 \
  54.     queue=default-small/default-small limit-at=0/0 max-limit=128000/256000 \
  55.     burst-limit=256000/512000 burst-threshold=100000/200000 burst-time=3s/10s \
  56.     total-queue=default-small time=0s-1d,sun,mon,tue,wed,thu,fri,sat \
  57.     disabled=yes

复制代码
routeros
 楼主| 发表于 2007-1-21 19:41:07 | 显示全部楼层
如果我修改/route与/system script两个地方的代码不知是否可行

/ ip route
add dst-address=0.0.0.0/0 gateway=192.168.111.1;192.168.222.1 scope=255 target-scope=10 \
    comment="wan" disabled=no

/ system script
add name="wan1up" source="/ip fir nat set wan1  to-
addresses=192.168.111.110" \
    policy=ftp,reboot,read,write,policy,test,winbox,password
add name="wan1down" source="/ip fir nat set wan1  to-
addresses=192.168.222.110" \
    policy=ftp,reboot,read,write,policy,test,winbox,password
add name="wan2up" source="/ip fir nat set wan2  to-
addresses=192.168.222.110" \
    policy=ftp,reboot,read,write,policy,test,winbox,password
add name="wan2down" source="/ip fir nat set wan2  to-
addresses=192.168.111.110" \
    policy=ftp,reboot,read,write,policy,test,winbox,password

[ 本帖最后由 everest79 于 2007-1-21 19:43 编辑 ]
routeros
回复

使用道具 举报

 楼主| 发表于 2007-1-21 21:45:18 | 显示全部楼层
各位老大,回贴呀,我这等着类
routeros
回复

使用道具 举报

 楼主| 发表于 2007-1-24 02:23:39 | 显示全部楼层
两动态ip+1静态ip 3网关分流+自动切换

  1. / interface ethernet
  2. set ether1 name="ether1_LAN"
  3. set ether2 name="ether2_WAN1"
  4. set ether3 name="ether3_WAN2"
  5. set ether4 name="ether4_WAN3"

  6. / interface pppoe-client
  7. add name="pppoe-out1" max-mtu=1480 max-mru=1480 interface=ether2_WAN1 \
  8.     user="adsl01" password="123456" profile=default service-name="" ac-name="" \
  9.     add-default-route=no dial-on-demand=no use-peer-dns=yes \
  10.     allow=pap,chap,mschap1,mschap2 disabled=no
  11. add name="pppoe-out2" max-mtu=1480 max-mru=1480 interface=ether3_WAN2 \
  12.     user="adsl02" password="654321" profile=default service-name="" ac-name="" \
  13.     add-default-route=no dial-on-demand=no use-peer-dns=yes \
  14.     allow=pap,chap,mschap1,mschap2 disabled=yes


  15. / ip address
  16. add address=192.168.1.254/24 network=192.168.1.0 broadcast=192.168.1.255 \
  17.     interface=ether1_LAN comment="added by setup" disabled=no
  18. add address=15.12.11.1/32 network=15.12.11.1 broadcast=15.12.11.1 \
  19.     interface=ether3_WAN2 comment="" disabled=yes
  20. add address=15.12.11.2/24 network=15.12.11.0 broadcast=15.12.11.255 \
  21.     interface=ether1_LAN comment="wan" disabled=no

  22. / ip route
  23. add dst-address=0.0.0.0/0 gateway=192.168.100.186 scope=255 target-scope=10 \
  24.     routing-mark=10 comment="wan1" disabled=no
  25. add dst-address=0.0.0.0/0 gateway=192.168.100.186 scope=255 target-scope=10 \
  26.     routing-mark=20 comment="wan2" disabled=no
  27. add dst-address=0.0.0.0/0 gateway=192.168.100.186 scope=255 target-scope=10 \
  28.     routing-mark=30 comment="wan3" disabled=no
  29. / ip firewall mangle
  30. add chain=prerouting src-address=192.168.1.146/31 action=mark-routing \
  31.     new-routing-mark=10 passthrough=yes comment="wan1" disabled=no
  32. add chain=prerouting src-address=192.168.1.148/31 action=mark-routing \
  33.     new-routing-mark=20 passthrough=yes comment="wan2" disabled=no
  34. add chain=prerouting src-address=192.168.1.150/31 action=mark-routing \
  35.     new-routing-mark=30 passthrough=yes comment="wan3" disabled=no
  36. / ip firewall nat
  37. add chain=srcnat routing-mark=10 action=src-nat to-addresses=192.168.100.184 \
  38.     to-ports=0-65535 comment="wan1" disabled=no
  39. add chain=srcnat routing-mark=20 action=src-nat to-addresses=192.168.100.184 \
  40.     to-ports=0-65535 comment="wan2" disabled=no
  41. add chain=srcnat routing-mark=30 action=src-nat to-addresses=192.168.100.184 \
  42.     to-ports=0-65535 comment="wan3" disabled=no


  43. / system script
  44. \n/ip firewall nat set \="/ip route set wan1 gateway=\$wan1
  45. \n/system scheduler dis wan1stat" \
  46.     policy=ftp,reboot,read,write,policy,test,winbox,password
  47. \n:if \(\[/tool \2" source=":set chw1 \$wan2
  48. \n:if \(\[/tool netwatch get wan3 \) do={
  49. \n:set chw1 \$src3} else={
  50. \n/ip route set \disable wan1}
  51. \n/ip \ip route find dst-address=0.0.0.0/0 gateway=\$wan1\] gateway=\$chw1
  52.     firewall nat set \[/ip firewall nat find action=src-nat to-addresses=\$src1\] \
  53. \n/system scheduler enable wan1stat" \
  54.     policy=ftp,reboot,read,write,policy,test,winbox,password
  55. \n/ip firewall nat set \="/ip route set wan2 gateway=\$wan2
  56. \n/system scheduler dis wan2stat" \
  57.     policy=ftp,reboot,read,write,policy,test,winbox,password
  58. \n:if \(\[/tool \3" source=":set chw2 \$wan3
  59. \n:if \(\[/tool netwatch get wan1 \) do={
  60. \n:set chw2 \$src1} else={
  61. \n/ip route set \disable wan2}
  62. \n/ip \ip route find dst-address=0.0.0.0/0 gateway=\$wan2\] gateway=\$chw2
  63.     firewall nat set \[/ip firewall nat find action=src-nat to-addresses=\$src2\] \
  64. \n/system scheduler enable wan2stat" \
  65.     policy=ftp,reboot,read,write,policy,test,winbox,password
  66. \n/ip firewall nat set \="/ip route set wan3 gateway=\$wan3
  67. \n/system scheduler disable wan3stat" \
  68.     policy=ftp,reboot,read,write,policy,test,winbox,password
  69. \n:if \(\[/tool \1" source=":set chw3 \$wan1
  70. \n:if \(\[/tool netwatch get wan2 \) do={
  71. \n:set chw3 \$src2} else={
  72. \n/ip route set \[/ip route find \
  73. \n/ip firewall nat set \0 gateway=\$wan3\] gateway=\$chw3
  74.     \[/ip firewall nat find action=src-nat to-addresses=\$src3\] \
  75. \n/system scheduler enable wan3stat" \
  76.     policy=ftp,reboot,read,write,policy,test,winbox,password
  77. \n:global src3 \n" source=":global wan3 15.12.11.1
  78. \n:global wan2 \one0.0.1
  79. \n:global src1 \one
  80. \n:global chs2 \55.0.0.1
  81. \n:global \pp2 none
  82. \n/tool netwatch disable \
  83. \n/tool netwatch set wan3 host=\$wan3 \
  84. \n/system scheduler enable \an1stat
  85. \n" \stem scheduler enable wan3stat
  86.     policy=ftp,reboot,read,write,policy,test,winbox,password
  87. add name="wan1stat" source="/interface pppoe-client monitor pppoe-out1 once \
  88. \n:set wan1 \[/ip \nnected"\) do={
  89. \n:set src1 \et \[/ip address find interface=pppoe-out1\] network\]
  90. \n/tool \ route get \[/ip route find dst-address=\$wan1\] pref-src\]
  91. \n/tool \10h set wan1 host=\$wan1 disabled=no
  92.     netwatch enable wan1}" \
  93.     policy=ftp,reboot,read,write,policy,test,winbox,password
  94. add name="wan2stat" source="/interface pppoe-client monitor pppoe-out2 once \
  95. \n:set wan2 \[/ip \nnected"\) do={
  96. \n:set src2 \et \[/ip address find interface=pppoe-out2\] network\]
  97. \n/tool \ route get \[/ip route find dst-address=\$wan2\] pref-src\]
  98. \n/tool \10h set wan2 host=\$wan2 disabled=no
  99.     netwatch enable wan2}" \
  100.     policy=ftp,reboot,read,write,policy,test,winbox,password
  101. \n:if \(\[/tool netwatch get wan1 \pc 0
  102. \n:if \(\[/tool netwatch get wan2 \$tmpc+1\)}
  103. \n/tool \$tmpc>0\) do={set tmpc \(\$tmpc+1\)}
  104. \n}" \ay 20h enable wan3
  105.     policy=ftp,reboot,read,write,policy,test,winbox,password
  106. add name="local886" source=":set ppp2 \$status" \
  107.     policy=ftp,reboot,read,write,policy,test,winbox,password


  108. / system scheduler
  109. add name="startup" on-event=autorun start-time=startup interval=0s \
  110.     comment="autorun" disabled=no
  111. add name="startup1" on-event=wan1stat start-time=startup interval=0s comment="" \
  112.     disabled=no
  113. add name="startup2" on-event=wan2stat start-time=startup interval=0s comment="" \
  114.     disabled=no
  115. add name="wan1stat" on-event=wan1stat start-date=jan/01/1970 start-time=00:00:00 \
  116.     interval=10s comment="wan1stat" disabled=yes
  117. add name="wan2stat" on-event=wan2stat start-date=jan/01/1970 start-time=00:00:00 \
  118.     interval=10s comment="wan2stat" disabled=no
  119. add name="wan3stat" on-event=wan3stat start-date=jan/01/1970 start-time=00:00:00 \
  120.     interval=20s comment="wan3stat" disabled=no


  121. / queue simple
  122. add name="queueA" target-addresses=192.168.1.146/32,192.168.1.147/32 \
  123.     dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8 \
  124.     queue=default-small/default-small limit-at=0/0 max-limit=64000/200000 \
  125.     burst-limit=128000/400000 burst-threshold=64000/180000 burst-time=3s/10s \
  126.     total-queue=default-small time=0s-1d,sun,mon,tue,wed,thu,fri,sat disabled=yes
  127. add name="queueB" target-addresses=192.168.1.148/32,192.168.1.149/32 \
  128.     dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8 \
  129.     queue=default-small/default-small limit-at=0/0 max-limit=128000/256000 \
  130.     burst-limit=256000/512000 burst-threshold=100000/200000 burst-time=3s/10s \
  131.     total-queue=default-small time=0s-1d,sun,mon,tue,wed,thu,fri,sat disabled=no
  132. add name="queueC" target-addresses=192.168.1.150/32,192.168.1.151/32 \
  133.     dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8 \
  134.     queue=default-small/default-small limit-at=0/0 max-limit=128000/256000 \
  135.     burst-limit=256000/512000 burst-threshold=100000/200000 burst-time=3s/10s \
  136.     total-queue=default-small time=0s-1d,sun,mon,tue,wed,thu,fri,sat disabled=yes


  137. / tool netwatch
  138. add host=192.168.100.186 timeout=30ms interval=1s up-script=wan1up \
  139.     down-script=wan1down comment="wan1" disabled=no
  140. add host=192.168.100.188 timeout=30ms interval=1s up-script=wan2up \
  141.     down-script=wan2down comment="wan2" disabled=no
  142. add host=15.12.11.1 timeout=30ms interval=1s up-script=wan3up down-script=wan3down \
  143.     comment="wan3" disabled=no
复制代码
routeros
回复

使用道具 举报

发表于 2007-1-24 09:57:29 | 显示全部楼层
因为ICMP不使用重传机制,这样一旦丢包就发现了.而别的协议也丢包,但有重传机制,所以就看不出来,你可以抓包看看.
routeros
回复

使用道具 举报

 楼主| 发表于 2007-1-24 15:12:06 | 显示全部楼层
谢谢ssffzz1的回答
routeros
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

本版积分规则

QQ|Archiver|手机版|小黑屋|软路由 ( 渝ICP备15001194号-1|渝公网安备 50011602500124号 )

GMT+8, 2024-9-30 09:21 , Processed in 0.098489 second(s), 4 queries , Gzip On, Redis On.

Powered by Discuz! X3.5 Licensed

© 2001-2024 Discuz! Team.

快速回复 返回顶部 返回列表