首页
学习
活动
专区
圈层
工具
发布
社区首页 >问答首页 >如何从他们在RouterOS中输入的同一网关中获得连接答案?

问如何从他们在RouterOS中输入的同一网关中获得连接答案?
EN

Server Fault用户
提问于 2015-01-09 11:36:49
回答 1查看 10.5K关注 0票数 5

我有一个MikroTik RouterOS 6.23设备,我的网络如下所示:

代码语言:javascript
复制
Router
  |
  |-- bridge1_LAN (wlan1 + ether1) (192.168.0.210) -- LAN (192.168.0.0/24)
  |   Here is where computers are. Those include some servers and some users.
  |   Users should be able to navigate always, and servers should
  |   be reachable online always.
  |
  |-- ether2_ADSL (192.168.2.2) -- ADSL router (192.168.2.1) -- WAN
  |   Users should navigate through here because there is no traffic limit.
  |   Incoming traffic should work exactly as with ether3_3G, as a temporary
  |   backup solution in case it fails.
  |
  |-- ether3_3G (192.168.3.2) -- 3G router (192.168.3.1) -- WAN
      This connection has a traffic limit, but faster upload rate, so it's
      mainly for incoming traffic. In case ether2_ADSL fails, this should be
      used as a temporary backup connection for outgoing traffic.

现在,相关配置:

代码语言:javascript
复制
/ip firewall mangle

# This rule is disabled because, when enabled, users cannot browse Internet
add action=mark-routing chain=prerouting connection-mark=no-mark disabled=yes \
    in-interface=ether2_ADSL new-routing-mark=to_ether2_ADSL passthrough=no

# This marks all traffic coming from ether3_3G to get out through there too
add action=mark-routing chain=prerouting in-interface=ether3_3G \
    new-routing-mark=to_ether3_3G passthrough=no

/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether2_ADSL
add action=masquerade chain=srcnat out-interface=ether3_3G

# This is just an example web server listening in port 8069, for testing purposes
add action=dst-nat chain=dstnat comment="Test server" dst-port=8069 \
    in-interface=ether2_ADSL protocol=tcp to-addresses=192.168.0.156 \
    to-ports=8069
add action=dst-nat chain=dstnat comment="Test server" dst-port=8069 \
    in-interface=ether3_3G protocol=tcp to-addresses=192.168.0.156 \
    to-ports=8069

/ip route

# Outgoing traffic by routing-mark
add check-gateway=ping distance=10 gateway=192.168.3.1 routing-mark=\
    to_ether3_3G
add check-gateway=ping distance=10 gateway=192.168.2.1 routing-mark=\
    to_ether2_ADSL

# Outgoing traffic by default
add check-gateway=ping distance=20 gateway=192.168.2.1
add check-gateway=ping distance=30 gateway=192.168.3.1

使用此配置,只有当ether3_3G失败时,所有通信量才会由ether2_ADSL发出,而ether2_ADSL则会输出(大多数情况下)。

现在的问题是,传入的连接只能通过ether2_ADSL工作。从ether3_3G传入的连接总是处于syn received状态。

在我看来,来自ether3_3G的传入连接似乎到达目标服务器,但是响应通过ether2_ADSL发出,这就是为什么TCP握手从未完成的原因。实际上,如果我物理上拔掉了ether2_ADSL电缆,那么与ether3_3G的所有连接都可以正常工作。

我怎么才能解决呢?

EN

回答 1

Server Fault用户

回答已采纳

发布于 2015-01-09 14:24:41

您需要标记来自ether3_3G的连接,这样您就可以标记将通过ether3_3G路由回路由的回复。

下面是一个示例配置(未测试)

代码语言:javascript
复制
/ip firewall mangle
add action=mark-connection chain=prerouting comment="Mark connection so packets from 3G get returned to 3G properly" disabled=no in-interface=ether3_3G new-connection-mark=3g-packets passthrough=no
add action=mark-routing chain=prerouting connection-mark=3g-packets disabled=no new-routing-mark=3g-packets passthrough=no
add action=mark-routing chain=output connection-mark=3g-packets disabled=no new-routing-mark=3g-packets passthrough=no


/ip route
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=192.168.3.1 routing-mark=3g-packets

第一条规则将在从connection-mark接口到达的任何数据包上放置一个ether3_3G。

第二条和第三条规则将根据该连接标记“捕获”回复,然后在这些连接上放置一个routing-mark。

第二条规则用于实质上被转发的数据包,第三条规则用于路由器本身将发送的答复(例如pings)。

最后,终端的静态路由将通过ether3_3G接口使用适当的路由标记对数据包进行路由。

票数 5
EN
页面原文内容由Server Fault提供。腾讯云小微IT领域专用引擎提供翻译支持
原文链接:

https://serverfault.com/questions/658361

复制
相关文章

相似问题

领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档