|
马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。
您需要 登录 才可以下载或查看,没有账号?注册
×
原本正常的端口隐射,在做了持续的负载均衡后,端口隐射失效,隐射的端口无法访问,请各位高手告诉我问题何在!
我现在将持续的负载均衡的脚本内容发出来,请大家看看我的问题所在,我需要隐射的端口为80
- / ip address
- add address=192.168.0.1/24 network=192.168.0.0 broadcast=192.168.0.255 interface=lan
- add address=61.178.176.218/24 network=61.178.176.0 broadcast=61.178.176.255 interface=218
- add address=61.178.176.165/24 network=61.178.176.0 broadcast=61.178.176.255 interface=165
复制代码
注释:路由器的两个WAN口地址分别是61.178.176.218/24和61.178.176.165/24,LAN口的地址是192.168.0.1/24,内网网卡命名为lan
- / ip firewall mangle
- add chain=prerouting src-address-list=odd in-interface=lan action=mark-connection \
- new-connection-mark=odd passthrough=yes
- add chain=prerouting src-address-list=odd in-interface=lan action=mark-routing \
- new-routing-mark=odd
- / ip firewall mangle
- add chain=prerouting src-address-list=even in-interface=lan action=mark-connection \
- new-connection-mark=even passthrough=yes
- add chain=prerouting src-address-list=even in-interface=lan action=mark-routing \
- new-routing-mark=even
- / ip firewall mangle
- add chain=prerouting in-interface=lan connection-state=new nth=1,1,0 \
- action=mark-connection new-connection-mark=odd passthrough=yes
- add chain=prerouting in-interface=lan action=add-src-to-address-list \
- address-list=odd address-list-timeout=1d connection-mark=odd passthrough=yes
- add chain=prerouting in-interface=lan connection-mark=odd action=mark-routing \
- new-routing-mark=odd passthrough=no
- / ip firewall mangle
- add chain=prerouting in-interface=lan connection-state=new nth=1,1,1 \
- action=mark-connection new-connection-mark=even passthrough=yes
- add chain=prerouting in-interface=lan action=add-src-to-address-list \
- address-list=even address-list-timeout=1d connection-mark=even passthrough=yes
- add chain=prerouting in-interface=lan connection-mark=even action=mark-routing \
- new-routing-mark=even passthrough=no
- add chain=prerouting in-interface=lan connection-state=new nth=1,1,1 \
- src-address-list=!odd action=mark-connection new-connection-mark=even \
- passthrough=yes
复制代码
- / ip firewall nat
- add chain=srcnat connection-mark=odd action=src-nat to-addresses=61.178.176.218 \
- to-ports=0-65535
- add chain=srcnat connection-mark=even action=src-nat to-addresses=61.178.176.165 \
- to-ports=0-65535
复制代码
注释:被标记为ODD的数据NAT为61.178.176.218 ,以EVEN为标记的数据NAT为61.178.176.165
- / ip route
- add dst-address=0.0.0.0/0 gateway=61.178.176.1 scope=255 target-scope=10 routing-mark=odd
- add dst-address=0.0.0.0/0 gateway=61.178.176.178 scope=255 target-scope=10 routing-mark=even
复制代码
注释:被标记为ODD的数据用61.178.176.1为网关,同样,被标记为EVEN的数据从61.178.176.178这个网关出去。
- / ip route
- add dst-address=0.0.0.0/0 gateway=61.178.176.178 scope=255 target-scope=10
复制代码
注释:最后,没有做任何标记的数据从61.178.176.178这个网关出去,也是给路由器的一个默然网关。
[ 本帖最后由 笑看风云 于 2007-6-5 11:03 编辑 ] |
|