ba2001 wrote:我已替您匯出整理,您看漏了那些動作.
好的 , 感謝!網...(恕刪)
/ip pool
add name=dhcp ranges=192.168.17.0/24
/ip address
add address=192.168.17.1/24 interface=bridge-lan network=192.168.17.0
/ip dhcp-server
add address-pool=dhcp disabled=no interface=bridge-lan name=dhcp
/ip dhcp-server network
add address=192.168.17.0/24 dns-server=192.168.17.1 gateway=192.168.17.1
/ip dns
set allow-remote-requests=yes servers=8.8.8.8
/interface pppoe-client
add allow=pap disabled=no interface=Wan-In-2 keepalive-timeout=10 name=HinetLIP \
profile=default-encryption user=87654321@ip.hinet.net password=123456
add allow=pap disabled=no interface=Wan-In-3 keepalive-timeout=10 name=Hinet \
profile=default-encryption user=87654321@hinet.net password=123456
/ip route
add distance=5 gateway=HinetLIP
add distance=4 gateway=Hinet routing-mark=AA
/ip firewall mangle
add action=accept chain=prerouting dst-address=192.168.17.0/24 \ src-address=192.168.17.0/24
add action=accept chain=prerouting dst-address-type=local src-address=192.168.17.0/24
add action=accept chain=output dst-address=192.168.17.0/24
#HinetLIP是預設路由 ,無需做路由標記
add action=mark-connection chain=prerouting in-interface=Hinet \
dst-address-type=local passthrough=yes new-connection-mark=AA_con
add action=mark-routing chain=output connection-mark=AA_conn \
src-address-type=local passthrough=no new-routing-mark=AA
add action=mark-routing chain=prerouting connection-mark=AA_conn \
src-address=192.168.17.0/24 passthrough=no new-routing-mark=AA
/ip firewall nat
add action=masquerade chain=srcnat src-address=192.168.17.0/24 \
dst-address=192.168.17.0/24
add action=masquerade chain=srcnat out-interface=HinetLIP
add action=masquerade chain=srcnat out-interface=Hinet
add action=dst-nat chain=dstnat dst-port=10443 protocol=tcp \
dst-address-type=local to-addresses=192.168.17.2 to-port=443
/ip firewall raw
add action=drop chain=prerouting dst-address=192.168.17.2 dst-port=!443