|
楼主 |
发表于 2009-4-7 20:03:53
|
显示全部楼层
本帖最后由 yanggame81 于 2009-4-7 20:14 编辑
麻烦高手帮我看下脚本对不对,红色部分为我依照单内网加的
/ ip firewall mangle
add chain=prerouting src-address-list=odd in-interface=lan1 action=mark-connection new-connection-mark=odd passthrough=yes
add chain=prerouting src-address-list=odd in-interface=lan1 action=mark-routing new-routing-mark=odd
/ ip firewall mangle
add chain=prerouting src-address-list=even in-interface=lan1 action=mark-connection new-connection-mark=even passthrough=yes
add chain=prerouting src-address-list=even in-interface=lan1 action=mark-routing new-routing-mark=even
/ ip firewall mangle
add chain=prerouting src-address-list=odd in-interface=lan2 action=mark-connection new-connection-mark=odd passthrough=yes
add chain=prerouting src-address-list=odd in-interface=lan2 action=mark-routing new-routing-mark=odd
/ ip firewall mangle
add chain=prerouting src-address-list=even in-interface=lan2 action=mark-connection new-connection-mark=even passthrough=yes
add chain=prerouting src-address-list=even in-interface=lan2 action=mark-routing new-routing-mark=even
/ ip firewall mangle
add chain=prerouting in-interface=lan1 connection-state=new nth=1,1,0 action=mark-connection new-connection-mark=odd passthrough=yes
add chain=prerouting in-interface=lan1 action=add-src-to-address-list address-list=odd address-list-timeout=1d connection-mark=odd passthrough=yes
add chain=prerouting in-interface=lan1 connection-mark=odd action=mark-routing new-routing-mark=odd passthrough=no
/ ip firewall mangle
add chain=prerouting in-interface=lan2 connection-state=new nth=1,1,0 action=mark-connection new-connection-mark=odd passthrough=yes
add chain=prerouting in-interface=lan2 action=add-src-to-address-list address-list=odd address-list-timeout=1d connection-mark=odd passthrough=yes
add chain=prerouting in-interface=lan2 connection-mark=odd action=mark-routing new-routing-mark=odd passthrough=no
/ ip firewall mangle
add chain=prerouting in-interface=lan1 connection-state=new nth=1,1,1 action=mark-connection new-connection-mark=even passthrough=yes
add chain=prerouting in-interface=lan1 action=add-src-to-address-list address-list=even address-list-timeout=1d connection-mark=even passthrough=yes
add chain=prerouting in-interface=lan1 connection-mark=even action=mark-routing new-routing-mark=even passthrough=no
/ ip firewall mangle
add chain=prerouting in-interface=lan2 connection-state=new nth=1,1,1 action=mark-connection new-connection-mark=even passthrough=yes
add chain=prerouting in-interface=lan2 action=add-src-to-address-list address-list=even address-list-timeout=1d connection-mark=even passthrough=yes
add chain=prerouting in-interface=lan2 connection-mark=even action=mark-routing new-routing-mark=even passthrough=no
add chain=prerouting in-interface=lan1 connection-state=new nth=1,1,1 src-address-list=!odd action=mark-connection new-connection-mark=even passthrough=yes
add chain=prerouting in-interface=lan2 connection-state=new nth=1,1,1 src-address-list=!odd action=mark-connection new-connection-mark=even passthrough=yes
/ ip firewall nat
add chain=srcnat connection-mark=odd action=src-nat to-addresses=10.111.0.2 to-ports=0-65535
add chain=srcnat connection-mark=even action=src-nat to-addresses=10.112.0.2 to-ports=0-65535
/ ip route
add dst-address=0.0.0.0/0 gateway=10.111.0.2 scope=255 target-scope=10 routing-mark=odd
add dst-address=0.0.0.0/0 gateway=10.112.0.2 scope=255 target-scope=10 routing-mark=even
/ ip route
add dst-address=0.0.0.0/0 gateway=10.111.0.2 scope=255 target-scope=10 |
|