topologi nyomot dari mikrotik indonesia |
MIKROTIK
/ ip address
add address=192.168.123.1/24 interface=LAN
add address=123.255.203.2/28 interface=DataUtama
add address=192.168.1.2/24 interface=Speedy
/ ip firewall mangle
add chain=prerouting dst-address=123.255.203.0/28 action=accept in-interface=LAN
add chain=prerouting dst-address=192.168.1.0/24 action=accept in-interface=LAN
add chain=prerouting in-interface=DataUtama connection-mark=no-mark action=mark-connection \
new-connection-mark=DataUtama_conn
add chain=prerouting in-interface=Speedy connection-mark=no-mark action=mark-connection \
new-connection-mark=Speedy_conn
add chain=prerouting in-interface=LAN connection-mark=no-mark dst-address-type=!local \
per-connection-classifier=both-addresses:3/0 action=mark-connection new-connection-mark=DataUtama_conn
add chain=prerouting in-interface=LAN connection-mark=no-mark dst-address-type=!local \
per-connection-classifier=both-addresses:3/1 action=mark-connection new-connection-mark=DataUtama_conn
add chain=prerouting in-interface=LAN connection-mark=no-mark dst-address-type=!local \
per-connection-classifier=both-addresses:3/2 action=mark-connection new-connection-mark=Speedy_conn
add chain=prerouting connection-mark=DataUtama_conn in-interface=LAN action=mark-routing \
new-routing-mark=to_DataUtama
add chain=prerouting connection-mark=Speedy_conn in-interface=LAN action=mark-routing \
new-routing-mark=to_Speedy
add chain=output connection-mark=DataUtama_conn action=mark-routing new-routing-mark=to_DataUtama
add chain=output connection-mark=Speedy_conn action=mark-routing new-routing-mark=to_Speedy
/ ip route
add dst-address=0.0.0.0/0 gateway=123.255.203.1 routing-mark=to_DataUtama check-gateway=ping
add dst-address=0.0.0.0/0 gateway=192.168.1.1 routing-mark=to_Speedy check-gateway=ping
add dst-address=0.0.0.0/0 gateway=123.255.203.1 distance=1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=192.168.1.1 distance=2 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=123.255.203.1 distance=2 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=192.168.1.1 distance=1 check-gateway=ping
/ ip firewall nat
add chain=srcnat out-interface=DataUtama action=masquerade
add chain=srcnat out-interface=Speedy action=masquerade
Topologi tested, LB + FailOver berjalan normal.
next to do , LB proxy external.
No comments:
Post a Comment
have a question, just spill it :D