Sunteți pe pagina 1din 3

Mikrotik Router Policy Routing 2 WAN Fail-over Configuration

IP address Configuration:

/ip address
add address=10.10.1.206/29 network=10.10.1.200 broadcast=10.10.1.207 interface=WAN1
add address=10.10.2.206/29 network=10.10.2.200 broadcast=10.10.2.207 interface=WAN2
add address=10.10.3.206/29 network=10.10.3.200 broadcast=10.10.3.207 interface=WAN3

VLAN Configuration on Mikrotik Router:

/interface vlan
add name=VLAN-100 interface=LOCAL vlan-id=100
add name=VLAN-200 interface=LOCAL vlan-id=200
add name=VLAN-300 interface=LOCAL vlan-id=300
/ip address
add address=192.168.21.1/24 interface=VLAN-100
add address=192.168.22.1/24 interface=VLAN-200
add address=192.168.23.1/24 interface=VLAN-300

DNS Configuration:
/ip dns set allow-remote-requests=yes cache-max-ttl=7d cache-size=5000KiB max-udp-
packet-size=512 servers=4.4.4.4,8,8.8.8.8

NAT Configuration:

/ip firewall nat


add chain=srcnat action=masquerade src-address=192.168.21.0/24 out-interface=WAN1
add chain=srcnat action=masquerade src-address=192.168.22.0/24 out-interface=WAN2
add chain=srcnat action=masquerade src-address=192.168.23.0/24 out-interface=WAN3

Mangle Configuration for 192.168.10.0/24 forward interface WAN1 and


172.16.10.0/24 forward WAN2

/ip firewall mangle


chain=prerouting action=mark-routing new-routing-mark=WAN1 passthrough=yes src-
address=192.168.21.0/24

chain=prerouting action=mark-routing new-routing-mark=WAN2 passthrough=yes src-


address=192.168.22.0/24

chain=prerouting action=mark-routing new-routing-mark=WAN2 passthrough=yes src-


address=192.168.23.0/24

Route Configuration
/ip route
add dst-address=0.0.0.0/0 routing-mark=WAN1 check-gateway=ping distance=1
gateway=10.10.1.201
add dst-address=0.0.0.0/0 routing-mark=WAN2 check-gateway=ping distance=1
gateway=10.10.2.201
add dst-address=0.0.0.0/0 routing-mark=WAN3 check-gateway=ping distance=1
gateway=10.10.3.1.201

Fail-Over Configuration
/ip route add dst-address=0.0.0.0/0 routing-mark=WAN1 check-gateway=ping distance=2
gateway=10.10.1.201
add dst-address=0.0.0.0/0 routing-mark=WAN2 check-gateway=ping distance=2
gateway=10.10.2.201
add dst-address=0.0.0.0/0 routing-mark=WAN3 check-gateway=ping distance=2
gateway=10.10.3.201
Simple Queue Configuration For Client 192.168.10.2:

/queue simple
Add name="Test1" target-addresses=192.168.10.2/32 interface=VLAN-100 parent=none
packet-marks="" direction=both priority=8
queue=default-small/default-small limit-at=0/0 max-limit=1M/1M
burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s
total-queue=default-small

Simple Queue Configuration For Client 172.16.10.2:

/queue simple
Add name="Test2" target-addresses=172.16.10.2/32 interface=VLAN-200 parent=none
packet-marks="" direction=both priority=8
queue=default-small/default-small limit-at=0/0 max-limit=1M/1M
burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s
total-queue=default-small

AccessSwitch Configuration:

AccessSwitch>enable
AccessSwitch#configuration terminal
AccessSwitch(config)#interface fastethernet 0/0
AccessSwitch(config-if)#switchport mode trunk
AccessSwitch(config-if)#switchport trunk allowed vlan all
AccessSwitch(config-if)#switchport nonegotiate
AccessSwitch(config)#vlan 100
AccessSwitch(config)#vlan 200
AccessSwitch(config)#interface fastethernet 0/1
AccessSwitch(config-if)#switchport mode access
AccessSwitch(config-if)#switchport access vlan 100

AccessSwitch(config)#interface fastethernet 0/2


AccessSwitch(config-if)#switchport mode access
AccessSwitch(config-if)#switchport access vlan 200
AccessSwitch#wr

S-ar putea să vă placă și