1 dst-nat pre x packet-mark. ako?
Napsal: 14 Feb 2012 11:10
Ahojte, nedavno som sa pytal ako nastavit queue tree pre neznamych zakaznikov. pouzil som pravidlo:
/ip firewall mangle
add action=mark-packet chain=forward comment=_192.168.116.0/24 disabled=no new-packet-mark=_192.168.116.0/24_UP passthrough=no src-address=192.168.116.0/24
add action=mark-packet chain=forward comment=_192.168.116.0/24 disabled=no dst-address=192.168.116.0/24 new-packet-mark=_192.168.116.0/24_D passthrough=no
/queue tree
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=0 max-limit=64k name=_192.168.116.0/24_UP packet-mark=_192.168.116.0/24_UP parent="xxxx" \
priority=8 queue=default
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=0 max-limit=64k name=_192.168.116.0/24_D packet-mark=_192.168.116.0/24_D parent="xxxx" \
priority=8 queue=default
cize neznamych zakaznikov mam orezanych na 64k, ale rad by som im aj zobrazil hlasku, ze maju neznamu ip, nech kontaktuju hotline. takto mam omanglovanych zatial asi 6 subnetov, bude ich podstatne viac. Da sa urobit jedno dst-nat pravidlo uz s mojimi aktualnymi manglovackami? pripadne do tej manglovacky pridat nieco, co budem moct pouzit?
diky
/ip firewall mangle
add action=mark-packet chain=forward comment=_192.168.116.0/24 disabled=no new-packet-mark=_192.168.116.0/24_UP passthrough=no src-address=192.168.116.0/24
add action=mark-packet chain=forward comment=_192.168.116.0/24 disabled=no dst-address=192.168.116.0/24 new-packet-mark=_192.168.116.0/24_D passthrough=no
/queue tree
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=0 max-limit=64k name=_192.168.116.0/24_UP packet-mark=_192.168.116.0/24_UP parent="xxxx" \
priority=8 queue=default
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=0 max-limit=64k name=_192.168.116.0/24_D packet-mark=_192.168.116.0/24_D parent="xxxx" \
priority=8 queue=default
cize neznamych zakaznikov mam orezanych na 64k, ale rad by som im aj zobrazil hlasku, ze maju neznamu ip, nech kontaktuju hotline. takto mam omanglovanych zatial asi 6 subnetov, bude ich podstatne viac. Da sa urobit jedno dst-nat pravidlo uz s mojimi aktualnymi manglovackami? pripadne do tej manglovacky pridat nieco, co budem moct pouzit?
diky