Kryukov Rostislav
Junior Member | Редактировать | Профиль | Сообщение | ICQ | Цитировать | Сообщить модератору Chupaka Цитата: вы любите passthrough=yes | Не совсем. Цитата: вы бы все правила приводили | Согласен. Вот маркировка: /ip firewall mangle add action=mark-connection chain=prerouting connection-mark=no-mark in-interface=ISP1-MTS new-connection-mark=ISP1_conn passthrough=yes add action=mark-connection chain=prerouting connection-mark=no-mark in-interface=ISP2-Rostelecom new-connection-mark=ISP2_conn passthrough=yes add action=mark-connection chain=prerouting connection-mark=no-mark in-interface=ISP3-MTS new-connection-mark=ISP3_conn passthrough=yes add action=mark-connection chain=prerouting connection-mark=no-mark dst-address-type=!local in-interface=eth5-master new-connection-mark=ISP1_conn \ passthrough=yes per-connection-classifier=both-addresses:3/0 add action=mark-connection chain=prerouting connection-mark=no-mark dst-address-type=!local in-interface=eth5-master new-connection-mark=ISP2_conn \ passthrough=yes per-connection-classifier=both-addresses:3/1 add action=mark-connection chain=prerouting connection-mark=no-mark dst-address-type=!local in-interface=eth5-master new-connection-mark=ISP3_conn \ passthrough=yes per-connection-classifier=both-addresses:3/2 add action=mark-packet chain=output dst-address-type=!local dst-port=53 \ new-packet-mark=http passthrough=no protocol=udp add action=mark-packet chain=forward connection-bytes=0-500000 new-packet-mark=http passthrough=no port=80,443,8080 protocol=tcp add action=mark-packet chain=forward new-packet-mark=http-exlcude packet-mark=no-mark dst-address-type=!local passthrough=no - этим правилом маркирую абсолютно все, что не маркировалось выше, но кроме локального траффика. add action=mark-routing chain=prerouting connection-mark=ISP1_conn in-interface=eth5-master new-routing-mark=to_ISP1 passthrough=yes add action=mark-routing chain=prerouting connection-mark=ISP2_conn in-interface=eth5-master new-routing-mark=to_ISP2 passthrough=yes add action=mark-routing chain=prerouting connection-mark=ISP3_conn in-interface=eth5-master new-routing-mark=to_ISP3 passthrough=yes add action=mark-routing chain=output connection-mark=ISP1_conn dst-address=!192.168.100.0/24 new-routing-mark=to_ISP1 passthrough=no add action=mark-routing chain=output connection-mark=ISP2_conn dst-address=!192.168.100.0/24 dst-address-type=!local new-routing-mark=to_ISP2 passthrough=no Очереди: /queue simple add limit-at=5M/5M max-limit=140M/140M name=OVERALL queue=pcq-upload-default/pcq-download-default target=eth5-master time=8h1s-23h59m59s,sun,mon,tue,wed,thu,fri,sat add burst-time=2s/2s limit-at=5M/5M max-limit=10M/10M name=http packet-marks=http parent=OVERALL priority=1/1 queue=pcq-upload-default/pcq-download-default target=eth5-master add max-limit=130M/130M name=other packet-marks=http-exlcude parent=OVERALL queue=pcq-upload-default/pcq-download-default target=eth5-master |