|
楼主 |
发表于 2011-9-20 16:28:06
|
显示全部楼层
filter:
# sep/20/2011 16:20:35 by RouterOS 5.4
# software id = 4SA9-XXXX
mangle
## sep/19/2011 04:49:08 by RouterOS 5.4
# software id = 4SA9-xxxx
#
/ip firewall mangle
add action=mark-connection chain=forward disabled=yes new-connection-mark=\
web_con passthrough=yes port=80 protocol=tcp
add action=mark-packet chain=forward connection-mark=web_con disabled=yes \
new-packet-mark=web passthrough=no
add action=mark-connection chain=forward disabled=yes new-connection-mark=\
ftp_con passthrough=yes port=21 protocol=tcp
add action=mark-packet chain=forward connection-mark=ftp_con disabled=yes \
new-packet-mark=ftp passthrough=no
NAT:
/ip firewall nat
add action=masquerade chain=srcnat comment="\B3o\A4@\B1\F8\A4\A3\AF\E0\A7R,\A7\
_\ABhNAT\AA\BA\A5\CE\A4\E1\A5X\A4\A3\A5h" disabled=no
add action=dst-nat chain=dstnat comment="\B3o\A4@\B1\F8\ACOPORT\ACM\AEg\BDd\A8\
\D2,(dst-address=123.123.123.123\B3o\B8\CC\ADn\B6\F1\A4JWAN\AA\BAIP),(to-a\
ddresses=192.168.88.5\ADn\B4\AB\A6\A8\B1z\A4\BA\BA\F4\A6\F8\AAA\BE\B9\AA\
\BAIP\A6\EC\A7})" disabled=yes dst-address=123.123.123.123 dst-port=21 \
protocol=tcp to-addresses=192.168.88.5 to-ports=21
Route:
# sep/20/2011 16:21:36 by RouterOS 5.4
# software id = 4SA9-XXXX
#
Tree
# sep/20/2011 16:22:08 by RouterOS 5.4
# software id = 4SA9-XXXX
#
/queue tree
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=yes limit-at=0 \
max-limit=0 name=Download parent=lan priority=8
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=yes limit-at=1M \
max-limit=12M name=Q1 packet-mark=web parent=Download priority=5 queue=\
default
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=yes limit-at=0 \
max-limit=0 name=Q2 parent=Download priority=5
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=yes limit-at=6M \
max-limit=12M name=Q2_1 packet-mark=ftp parent=Q2 priority=6 queue=\
default
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=yes limit-at=1M \
max-limit=12M name=Q2_3 packet-mark=no-mark parent=Q2 priority=7 queue=\
default
我很確定mangle disable就可以正常連上 0.0
|
|