+ Responder ao Tópico



  1. #81

    Padrão

    Citação Postado originalmente por marsilba Ver Post
    Segue aí pessoal

    /ip firewall mangle
    add action=accept chain=prerouting comment="SEM BALANCE" disabled=no \
    dst-address-list=sem_balance in-interface=EthClientes
    add action=mark-connection chain=input comment="" connection-state=new \
    disabled=no in-interface=EthLinkA new-connection-mark=conn_na \
    passthrough=yes
    add action=mark-connection chain=input comment="" connection-state=new \
    disabled=no in-interface=EthLinkB new-connection-mark=conn_nb \
    passthrough=yes
    add action=mark-routing chain=output comment="" connection-mark=conn_na \
    disabled=no new-routing-mark=to_ra passthrough=no
    add action=mark-routing chain=output comment="" connection-mark=conn_nb \
    disabled=no new-routing-mark=to_rb passthrough=no
    add action=mark-connection chain=prerouting comment="" disabled=no \
    dst-address-type=!local in-interface=EthClientes new-connection-mark=\
    conn_ma0 passthrough=yes per-connection-classifier=both-addresses:2/0
    add action=mark-connection chain=prerouting comment="" disabled=no \
    dst-address-type=!local in-interface=EthClientes new-connection-mark=\
    conn_mb1 passthrough=yes per-connection-classifier=both-addresses:2/1
    add action=mark-routing chain=prerouting comment="" connection-mark=conn_ma0 \
    disabled=no in-interface=EthClientes new-routing-mark=to_nra passthrough=\
    no
    add action=mark-routing chain=prerouting comment="" connection-mark=conn_mb1 \
    disabled=no in-interface=EthClientes new-routing-mark=to_nrb passthrough=\
    no

    /ip firewall nat
    add action=accept chain=srcnat comment="MASCARAMENTO PCC" disabled=no \
    out-interface=EthLinkA
    add action=masquerade chain=srcnat comment="" disabled=no out-interface=\
    EthLinkB
    add action=masquerade chain=srcnat comment="MASCARAMENTO PCC" disabled=no \
    src-address=10.1.1.0/24

    /ip route
    add comment="" disabled=no distance=2 dst-address=0.0.0.0/0 gateway=EthLinkA
    add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=EthLinkA \
    routing-mark=to_nra
    add comment="" disabled=no distance=3 dst-address=0.0.0.0/0 gateway=EthLinkB
    add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=EthLinkB \
    routing-mark=to_nrb

    /ip address
    add address=10.1.1.1/24 broadcast=10.1.1.255 comment="" disabled=no \
    interface=EthClientes network=10.1.1.0


    A propósito estou utilizando uma rb450g somente para balanceamento. Minha máquina que faz o controle de mac, banda, proxy etc está com ip 10.1.1.5 Ajuda aí pessoal. Não canso de falar isso.
    Amigo marsilba fica complicado ele funcionar corretamente se não se configura corretamente...
    vamos aos fatos, quando se configura o mikrotik para discar os modens ADSL/VELOX etc com pppoe-outX as interfaces dos links n é mais a interface q esta conectado ao modem e sim o pppoe-outX que vc definiu para discar o modem. Pensando nesta lógica toda sua configuração aonde tem as interfaces EthLinkX mude para as respectivas interfaces pppoe-outX.

    Por isso seu balanceamento estava furado, ele n estava fazendo marcação corretamente.

    Em fim só para frisar, mude em toda sua configuração aonde tiver EthLinkX para os pppoe-outX, digo em:

    /ip firewall nat
    /ip firewall mangle
    /ip route

    Acredito que agora vc resolve seu problema,

    Volto a dizer o PCC é o melhor loadbalaced que a mikrotik tem excelente ferramente, mas lógico que bem configurado, n basta seguir um howto e não se adptar a sua realidade

    abraços

  2. #82

    Padrão

    Citação Postado originalmente por DSSS Ver Post
    Aqui amigo do mesmo jeito que o seu, só topa um link, fiz um teste de profile de 12Mbits, (meus links juntos dão 30 Mbits, mas ele não passa dos 9Mbits, porque ele estoura apenas o link da rota com prioridade maior, os outros links deveriam tb repassar abanda e não passa. Algo muito estranho. Lembrando que não tenho um regra se quer nessa rb que não seja as do PCC, ela funcioan exclusivamente como balance, pelo jeito vou ter que comprar uma Balanc da TP-Link.
    poste suas regras amigo...

  3. #83

    Padrão pcc

    acredito que deva ser isso mesmo faça isso tb no nat em out-interface...

  4. #84

    Padrão Problemas de Acesso Remoto

    Então. fiz o balanceamento com 6links ADSL de 2.5mb.
    ficou uma beleza.
    confesso que não esperava tando.
    o grande problema que estou tendo aki é que: não consigo me conectar ao mikrotik que faz o pcc (no caso é uma rb493ah), tão pouco me conectar ao servidor onde os clientes autenticam.

    minha estrutura tá assim:

    Link1 Link2 Link3 Link4 Link5 Link6------> RB_493ah_PCC------->PC_MK--->Clientes....
    preciso me conectar pelas portas 2200 e 8291 remotamente. |_>proxy em paralelo.

    mais não consegui.

  5. #85

    Padrão pcc

    vc tem link dedicado, se sim post suas regras desde firewall filter, nat, e mangle e ip services...

  6. #86

    Padrão

    add action=accept chain=dstnat comment=aceita_webmikrotik disabled=no dst-address=200.212.248.0/28 protocol=tcp

    add action=dst-nat chain=pre-hotspot comment=mensagem_pendencia disabled=no dst-address=!200.212.248.0/28 protocol=tcp src-address-list=pendencia to-addresses=200.212.248.10 to-ports=11103

    add action=dst-nat chain=pre-hotspot comment=mensagem_bloqueio disabled=no \
    dst-address=!200.212.248.0/28 protocol=tcp src-address-list=bloqueio \
    to-addresses=200.212.248.10 to-ports=12103

    add action=dst-nat chain=dstnat comment=mensagem_pendencia disabled=no \
    dst-address=!200.212.248.0/28 protocol=tcp src-address-list=pendencia \
    to-addresses=200.212.248.10 to-ports=11103

    add action=dst-nat chain=dstnat comment=mensagem_bloqueio disabled=no \
    dst-address=!200.212.248.0/28 protocol=tcp src-address-list=bloqueio \
    to-addresses=200.212.248.10 to-ports=12103

    add action=masquerade chain=srcnat comment=faixa_padrao disabled=no \
    src-address=10.0.0.1-10.0.255.253
    no meu mk não tem nada dmais. até pq antes do pcc ele aceitava estas conexões naboa...

    "Acredito" q o problema seja somente no PCC.

    "add action=accept chain=dstnat comment=aceita_webmikrotik disabled=no dst-address=200.212.248.0/28 protocol=tcp"

    "add action=accept chain=dstnat comment="winbox" disabled=no dst-nat (para o ip e porta do mk)"

  7. #87

    Padrão

    Citação Postado originalmente por tiagomatias Ver Post
    poste suas regras amigo...
    Tiago é a segunda vez que posto minhas regras, obrigador por se dispor:
     
    /ip firewall mangle
    Código :
    add action=accept chain=prerouting comment="Sem Balance" disabled=no dst-address-list=sem_balance in-interface=\
        EthClientes
    add action=mark-connection chain=input comment=PCC connection-state=new disabled=no in-interface=EthLinkA \
        new-connection-mark=conn_na passthrough=yes
    add action=mark-connection chain=input comment="" connection-state=new disabled=no in-interface=pppoe-out1 \
        new-connection-mark=conn_nb passthrough=yes
    add action=mark-connection chain=input comment="" connection-state=new disabled=no in-interface=pppoe-out2 \
        new-connection-mark=conn_nc passthrough=yes
    add action=mark-routing chain=output comment="" connection-mark=conn_na disabled=no new-routing-mark=to_ra passthrough=\
        no
    add action=mark-routing chain=output comment="" connection-mark=conn_nb disabled=no new-routing-mark=to_rb passthrough=\
        no
    add action=mark-routing chain=output comment="" connection-mark=conn_nc disabled=no new-routing-mark=to_rc passthrough=\
        no
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_ma0 passthrough=yes per-connection-classifier=both-addresses:8/0
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_mb1 passthrough=yes per-connection-classifier=both-addresses:8/1
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_mb1 passthrough=yes per-connection-classifier=src-address:8/2
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_mb1 passthrough=yes per-connection-classifier=src-address:8/3
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_mb1 passthrough=yes per-connection-classifier=src-address:8/4
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_mc2 passthrough=yes per-connection-classifier=src-address:8/5
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_mc2 passthrough=yes per-connection-classifier=src-address:8/6
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_mc2 passthrough=yes per-connection-classifier=src-address:8/7
    add action=mark-routing chain=prerouting comment="" connection-mark=conn_ma0 disabled=no in-interface=EthClientes \
        new-routing-mark=to_nra passthrough=no
    add action=mark-routing chain=prerouting comment="" connection-mark=conn_mb1 disabled=no in-interface=EthClientes \
        new-routing-mark=to_nrb passthrough=no
    add action=mark-routing chain=prerouting comment="" connection-mark=conn_mc2 disabled=no in-interface=EthClientes \
        new-routing-mark=to_nrc passthrough=no
     
     
    /ip firewall nat
    Código :
    add action=masquerade chain=srcnat comment="MASCARAMENTO PCC" disabled=no out-interface=EthLinkA
    add action=masquerade chain=srcnat comment="" disabled=no out-interface=pppoe-out1
    add action=masquerade chain=srcnat comment="" disabled=no out-interface=pppoe-out2
     
     
    /ip route
    Código :
    add check-gateway=ping comment="" disabled=no distance=3 dst-address=0.0.0.0/0 gateway=200.249.152.129 scope=30 \
        target-scope=10
    add comment="" disabled=no distance=2 dst-address=0.0.0.0/0 gateway=pppoe-out1
    add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=200.249.152.129 routing-mark=to_nra scope=30 \
        target-scope=10
    add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=pppoe-out2 routing-mark=to_nrc
    add comment="" disabled=no distance=4 dst-address=0.0.0.0/0 gateway=pppoe-out2
    add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=pppoe-out1 routing-mark=to_nrb
    add comment="" disabled=no distance=2 dst-address=200.249.152.129/32 gateway=EthLinkA
     

  8. #88

    Padrão

    Citação Postado originalmente por DSSS Ver Post
    Tiago é a segunda vez que posto minhas regras, obrigador por se dispor:
     
    /ip firewall mangle
    Código :
    add action=accept chain=prerouting comment="Sem Balance" disabled=no dst-address-list=sem_balance in-interface=\
        EthClientes
    add action=mark-connection chain=input comment=PCC connection-state=new disabled=no in-interface=EthLinkA \
        new-connection-mark=conn_na passthrough=yes
    add action=mark-connection chain=input comment="" connection-state=new disabled=no in-interface=pppoe-out1 \
        new-connection-mark=conn_nb passthrough=yes
    add action=mark-connection chain=input comment="" connection-state=new disabled=no in-interface=pppoe-out2 \
        new-connection-mark=conn_nc passthrough=yes
    add action=mark-routing chain=output comment="" connection-mark=conn_na disabled=no new-routing-mark=to_ra passthrough=\
        no
    add action=mark-routing chain=output comment="" connection-mark=conn_nb disabled=no new-routing-mark=to_rb passthrough=\
        no
    add action=mark-routing chain=output comment="" connection-mark=conn_nc disabled=no new-routing-mark=to_rc passthrough=\
        no
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_ma0 passthrough=yes per-connection-classifier=both-addresses:8/0
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_mb1 passthrough=yes per-connection-classifier=both-addresses:8/1
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_mb1 passthrough=yes per-connection-classifier=src-address:8/2
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_mb1 passthrough=yes per-connection-classifier=src-address:8/3
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_mb1 passthrough=yes per-connection-classifier=src-address:8/4
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_mc2 passthrough=yes per-connection-classifier=src-address:8/5
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_mc2 passthrough=yes per-connection-classifier=src-address:8/6
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=EthClientes \
        new-connection-mark=conn_mc2 passthrough=yes per-connection-classifier=src-address:8/7
    add action=mark-routing chain=prerouting comment="" connection-mark=conn_ma0 disabled=no in-interface=EthClientes \
        new-routing-mark=to_nra passthrough=no
    add action=mark-routing chain=prerouting comment="" connection-mark=conn_mb1 disabled=no in-interface=EthClientes \
        new-routing-mark=to_nrb passthrough=no
    add action=mark-routing chain=prerouting comment="" connection-mark=conn_mc2 disabled=no in-interface=EthClientes \
        new-routing-mark=to_nrc passthrough=no
     
     
    /ip firewall nat
    Código :
    add action=masquerade chain=srcnat comment="MASCARAMENTO PCC" disabled=no out-interface=EthLinkA
    add action=masquerade chain=srcnat comment="" disabled=no out-interface=pppoe-out1
    add action=masquerade chain=srcnat comment="" disabled=no out-interface=pppoe-out2
     
     
    /ip route
    Código :
    add check-gateway=ping comment="" disabled=no distance=3 dst-address=0.0.0.0/0 gateway=200.249.152.129 scope=30 \
        target-scope=10
    add comment="" disabled=no distance=2 dst-address=0.0.0.0/0 gateway=pppoe-out1
    add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=200.249.152.129 routing-mark=to_nra scope=30 \
        target-scope=10
    add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=pppoe-out2 routing-mark=to_nrc
    add comment="" disabled=no distance=4 dst-address=0.0.0.0/0 gateway=pppoe-out2
    add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=pppoe-out1 routing-mark=to_nrb
    add comment="" disabled=no distance=2 dst-address=200.249.152.129/32 gateway=EthLinkA
     
    DSS, aparentemente esta tudo certo seu loadbalaced com PCC, só para confirmar os pesos dos links q vc esta dividindo é:

    conn_ma0 - 1
    conn_mb1 - 4
    conn_mc2 - 3

    vc poderia nós dizer qual é a velocidade de cada link desse e nós dizer tmb o q exatamente acontece q vc acha q n esta correto.

    abraços

  9. #89

    Padrão

    Citação Postado originalmente por tiagomatias Ver Post
    DSS, aparentemente esta tudo certo seu loadbalaced com PCC, só para confirmar os pesos dos links q vc esta dividindo é:

    conn_ma0 - 1
    conn_mb1 - 4
    conn_mc2 - 3

    vc poderia nós dizer qual é a velocidade de cada link desse e nós dizer tmb o q exatamente acontece q vc acha q n esta correto.

    abraços

    ma0 - 2 mbits
    ma1 - 8 mbits
    mc2 - 6 mbits

    O que acontece é que o link só usado quando esta em rota default ( distancia), por exemplo se o pego o ma0 e ponho ele com distancia 1 somente ele é que consumido, mesmo tendo a banda sobrando nos outros dois! crio o profiles no meu hot spot para 15 megas, o link ma0 estoura e eu fico só com 2 mbits de download, e os outros links não são "ativados", do mesmo modo acontece se eu fizer o mesmo com os outros links! O que será que pode ser? lembrando que nessa rb não tem nenhuma outra regra que não seja ao do PCC. Ja estou encucado com isso.

    Abraços e obrigado por responder

  10. #90

    Padrão

    Tiagomatias... se puder me ajudar eu agradeço muito.

    Lembrando que tenho 2Links de 2MB FULL (2mb/2mb)

    /ip firewall nat
    add action=masquerade chain=srcnat comment="MASCARAMENTO PCC" disabled=no out-interface=LINK1
    add action=masquerade chain=srcnat comment="" disabled=no out-interface=LINK2
    add action=masquerade chain=srcnat comment="" disabled=no src-address=10.0.0.0/8
    /ip route
    add comment="BALANCEAMENTO DE CARGA - LINK1" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=201.90.162.161 routing-mark=to_nra scope=30 target-scope=\
    10
    add comment="BALANCEAMENTO DE CARGA - LINK2" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=189.22.8.1 routing-mark=to_nrb scope=30 target-scope=10
    add comment="LINK2 - TELEFONICA" disabled=no distance=3 dst-address=0.0.0.0/0 gateway=189.22.8.1 scope=30 target-scope=10
    add comment="LINK1 - EMBRATEL" disabled=no distance=2 dst-address=0.0.0.0/0 gateway=201.90.162.161 scope=30 target-scope=10
    /ip fireall mangle
    add action=mark-connection chain=output comment="CACHE FULL" content="X-Cache: HIT" disabled=no new-connection-mark=conn_squid-up passthrough=yes protocol=\
    tcp src-port=3128
    add action=mark-packet chain=output comment="" connection-mark=conn_squid-up disabled=no new-packet-mark=pacotes_squid-up passthrough=yes
    add action=mark-connection chain=prerouting comment="" disabled=no dst-port=3128 new-connection-mark=conn_squid-down passthrough=yes protocol=tcp
    add action=mark-packet chain=prerouting comment="" connection-mark=conn_squid-down disabled=no new-packet-mark=pacotes_squid-down passthrough=yes
    add action=accept chain=prerouting comment="SEM BALANCE DE DESTINO" disabled=no dst-address-list=sem_balance in-interface=LOCAL
    add action=mark-connection chain=input comment="MARCACAO DE NOVAS CONEXOES" connection-state=new disabled=no in-interface=LINK1 new-connection-mark=conn_na \
    passthrough=yes
    add action=mark-connection chain=input comment="" connection-state=new disabled=no in-interface=LINK2 new-connection-mark=conn_nb passthrough=yes
    add action=mark-routing chain=output comment="MARCACAO DE ROTAS" connection-mark=conn_na disabled=no new-routing-mark=to_ra passthrough=no
    add action=mark-routing chain=output comment="" connection-mark=conn_nb disabled=no new-routing-mark=to_rb passthrough=no
    add action=mark-connection chain=prerouting comment="MARCACAO DE NOVAS CONEXOES" disabled=no dst-address-type=!local in-interface=LOCAL new-connection-mark=\
    conn_ma0 passthrough=yes per-connection-classifier=both-addresses:2/0
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=LOCAL new-connection-mark=conn_mb1 passthrough=yes \
    per-connection-classifier=both-addresses:2/1
    add action=mark-routing chain=prerouting comment="MARCACAO DE INTERFACES" connection-mark=conn_ma0 disabled=no in-interface=LOCAL new-routing-mark=to_nra \
    passthrough=no
    add action=mark-routing chain=prerouting comment="" connection-mark=conn_mb1 disabled=no in-interface=LOCAL new-routing-mark=to_nrb passthrough=no
    Última edição por thiagotgc; 28-09-2009 às 09:06.

  11. #91

    Padrão

    Citação Postado originalmente por tiagomatias Ver Post
    Amigo marsilba fica complicado ele funcionar corretamente se não se configura corretamente...
    vamos aos fatos, quando se configura o mikrotik para discar os modens ADSL/VELOX etc com pppoe-outX as interfaces dos links n é mais a interface q esta conectado ao modem e sim o pppoe-outX que vc definiu para discar o modem. Pensando nesta lógica toda sua configuração aonde tem as interfaces EthLinkX mude para as respectivas interfaces pppoe-outX.

    Por isso seu balanceamento estava furado, ele n estava fazendo marcação corretamente.

    Em fim só para frisar, mude em toda sua configuração aonde tiver EthLinkX para os pppoe-outX, digo em:

    /ip firewall nat
    /ip firewall mangle
    /ip route

    Acredito que agora vc resolve seu problema,

    Volto a dizer o PCC é o melhor loadbalaced que a mikrotik tem excelente ferramente, mas lógico que bem configurado, n basta seguir um howto e não se adptar a sua realidade

    abraços
    Prezado Tiago, mudei as interfaces mas aí mesmo é que ninguém conseguiu mais navegar. Essa sua orientação não funcionou, justamente piorou. Será que tem outra idéia para poder testar aqui?

  12. #92

    Padrão

    Citação Postado originalmente por tiagomatias Ver Post
    Amigo exclusivenet, faça as modificções do seu PCC para igual a este que vou postar a vc abaixo.

    Código :
    /ip firewall mangle
    add action=mark-connection chain=input comment="Mark new inbound connection wan1" connection-state=new disabled=no in-interface=wan1-pppoe new-connection-mark=wan1 \
        passthrough=yes
    add action=mark-connection chain=input comment="Mark new inbound connection wan2" connection-state=new disabled=no in-interface=wan2-pppoe new-connection-mark=wan2 \
        passthrough=yes
    add action=mark-connection chain=input comment="Mark new inbound connection wan3" connection-state=new disabled=no in-interface=wan3-pppoe new-connection-mark=wan3 \
        passthrough=yes
    add action=mark-connection chain=prerouting comment="Mark established inbound connection wan1" connection-state=established disabled=no in-interface=wan1-pppoe \
        new-connection-mark=wan1 passthrough=yes
    add action=mark-connection chain=prerouting comment="Mark established inbound connection wan2" connection-state=established disabled=no in-interface=wan2-pppoe \
        new-connection-mark=wan2 passthrough=yes
    add action=mark-connection chain=prerouting comment="Mark established inbound connection wan3" connection-state=established disabled=no in-interface=wan3-pppoe \
        new-connection-mark=wan3 passthrough=yes
    add action=mark-connection chain=prerouting comment="Mark related inbound connection wan1" connection-state=related disabled=no in-interface=wan1-pppoe \
        new-connection-mark=wan2 passthrough=yes
    add action=mark-connection chain=prerouting comment="Mark related inbound connection wan2" connection-state=related disabled=no in-interface=wan2-pppoe \
        new-connection-mark=wan2 passthrough=yes
    add action=mark-connection chain=prerouting comment="Mark related inbound connection wan3" connection-state=related disabled=no in-interface=wan3-pppoe \
        new-connection-mark=wan3 passthrough=yes
    add action=mark-routing chain=output comment="Mark new inbound route wan1" connection-mark=wan1 disabled=no new-routing-mark=wan1 passthrough=no
    add action=mark-routing chain=output comment="Mark new inbound route wan2" connection-mark=wan2 disabled=no new-routing-mark=wan2 passthrough=no
    add action=mark-routing chain=output comment="Mark new inbound route wan3" connection-mark=wan3 disabled=no new-routing-mark=wan3 passthrough=no
    add action=mark-connection chain=prerouting comment="Mark traffic that isn't local with PCC mark rand (3 possibilities) - option 1" connection-state=new disabled=no \
        dst-address-type=!local in-interface=hotspot-bridge new-connection-mark=wan1_pcc_conn passthrough=yes per-connection-classifier=both-addresses:3/0
    add action=mark-connection chain=prerouting comment="Mark traffic that isn't local with PCC mark rand (3 possibilities) - option 2" connection-state=new disabled=no \
        dst-address-type=!local in-interface=hotspot-bridge new-connection-mark=wan2_pcc_conn passthrough=yes per-connection-classifier=both-addresses:3/1
    add action=mark-connection chain=prerouting comment="Mark traffic that isn't local with PCC mark rand (3 possibilities) - option 3" connection-state=new disabled=no \
        dst-address-type=!local in-interface=hotspot-bridge new-connection-mark=wan3_pcc_conn passthrough=yes per-connection-classifier=both-addresses:3/2
    add action=mark-connection chain=prerouting comment="Mark established traffic that isn't local with PCC mark rand (3 possibilities) - option 1" connection-state=\
        established disabled=no dst-address-type=!local in-interface=hotspot-bridge new-connection-mark=wan1_pcc_conn passthrough=yes per-connection-classifier=\
        both-addresses:3/0
    add action=mark-connection chain=prerouting comment="Mark established traffic that isn't local with PCC mark rand (3 possibilities) - option 2" connection-state=\
        established disabled=no dst-address-type=!local in-interface=hotspot-bridge new-connection-mark=wan2_pcc_conn passthrough=yes per-connection-classifier=\
        both-addresses:3/1
    add action=mark-connection chain=prerouting comment="Mark established traffic that isn't local with PCC mark rand (3 possibilities) - option 3" connection-state=\
        established disabled=no dst-address-type=!local in-interface=hotspot-bridge new-connection-mark=wan3_pcc_conn passthrough=yes per-connection-classifier=\
        both-addresses:3/2
    add action=mark-connection chain=prerouting comment="Mark related traffic that isn't local with PCC mark rand (3 possibilities) - option 1" connection-state=related \
        disabled=no dst-address-type=!local in-interface=hotspot-bridge new-connection-mark=wan1_pcc_conn passthrough=yes per-connection-classifier=both-addresses:3/0
    add action=mark-connection chain=prerouting comment="Mark related traffic that isn't local with PCC mark rand (3 possibilities) - option 2" connection-state=related \
        disabled=no dst-address-type=!local in-interface=hotspot-bridge new-connection-mark=wan2_pcc_conn passthrough=yes per-connection-classifier=both-addresses:3/1
    add action=mark-connection chain=prerouting comment="Mark related traffic that isn't local with PCC mark rand (3 possibilities) - option 3" connection-state=related \
        disabled=no dst-address-type=!local in-interface=hotspot-bridge new-connection-mark=wan3_pcc_conn passthrough=yes per-connection-classifier=both-addresses:3/2
    add action=mark-routing chain=prerouting comment="Mark routing for  PCC mark - option 1" connection-mark=wan1_pcc_conn disabled=no new-routing-mark=wan1 passthrough=\
        yes
    add action=mark-routing chain=prerouting comment="Mark routing for  PCC mark - option 2" connection-mark=wan2_pcc_conn disabled=no new-routing-mark=wan2 passthrough=\
        yes
    add action=mark-routing chain=prerouting comment="Mark routing for  PCC mark - option 3" connection-mark=wan3_pcc_conn disabled=no new-routing-mark=wan3 passthrough=\
        yes
    TiagoMatias, preciso falar com você, como faço? É pessoal, um trabalho, grana rs,rs!!!

    Abraços!!!

  13. #93

    Padrão

    Citação Postado originalmente por DSSS Ver Post
    ma0 - 2 mbits
    ma1 - 8 mbits
    mc2 - 6 mbits

    O que acontece é que o link só usado quando esta em rota default ( distancia), por exemplo se o pego o ma0 e ponho ele com distancia 1 somente ele é que consumido, mesmo tendo a banda sobrando nos outros dois! crio o profiles no meu hot spot para 15 megas, o link ma0 estoura e eu fico só com 2 mbits de download, e os outros links não são "ativados", do mesmo modo acontece se eu fizer o mesmo com os outros links! O que será que pode ser? lembrando que nessa rb não tem nenhuma outra regra que não seja ao do PCC. Ja estou encucado com isso.

    Abraços e obrigado por responder
    Muito estranho....
    se puder poste uma foto da tela de INTERFACE sua para vermos o trafego dele. Para poder tentar de ajudar

  14. #94

    Padrão

    Citação Postado originalmente por marsilba Ver Post
    Prezado Tiago, mudei as interfaces mas aí mesmo é que ninguém conseguiu mais navegar. Essa sua orientação não funcionou, justamente piorou. Será que tem outra idéia para poder testar aqui?
    sinceramente, vc n esta fazendo certo.

  15. #95

    Padrão

    Citação Postado originalmente por jociano Ver Post
    TiagoMatias, preciso falar com você, como faço? É pessoal, um trabalho, grana rs,rs!!!

    Abraços!!!
    Me manda uma mensagem em PVT ou Email

  16. #96

    Padrão

    Bom dia pessoal, alguem teve problema com video da globo.com? to com pcc com 2 links, e globo.com nao abre os videos.
    abraços.

  17. #97

    Padrão

    Citação Postado originalmente por raus Ver Post
    Bom dia pessoal, alguem teve problema com video da globo.com? to com pcc com 2 links, e globo.com nao abre os videos.
    abraços.
    veja esse link
    >>> https://under-linux.org/f131999-load...ites-de-bancos

  18. #98

    Padrão

    Citação Postado originalmente por tiagomatias Ver Post
    sinceramente, vc n esta fazendo certo.
    Tive que voltar à configuração antiga pq não estava funcionando nada. Vou alterar de novo o que você disse e postar as regras para você dar uma olhada. Acho que não mudei nada de errado, mantive o que estava feito e apenas alterei as interfaces como vc disse, não tem mistério algum, mas não funcionou e parou tudo.Dá uma luz aí.

  19. #99

    Padrão

    Tiagomatias... se puder me ajudar eu agradeço muito.

    Lembrando que tenho 2Links de 2MB FULL (2mb/2mb)

    /ip firewall nat
    add action=masquerade chain=srcnat comment="MASCARAMENTO PCC" disabled=no out-interface=LINK1
    add action=masquerade chain=srcnat comment="" disabled=no out-interface=LINK2
    add action=masquerade chain=srcnat comment="" disabled=no src-address=10.0.0.0/8
    /ip route
    add comment="BALANCEAMENTO DE CARGA - LINK1" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=201.90.162.161 routing-mark=to_nra scope=30 target-scope=\
    10
    add comment="BALANCEAMENTO DE CARGA - LINK2" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=189.22.8.1 routing-mark=to_nrb scope=30 target-scope=10
    add comment="LINK2 - TELEFONICA" disabled=no distance=3 dst-address=0.0.0.0/0 gateway=189.22.8.1 scope=30 target-scope=10
    add comment="LINK1 - EMBRATEL" disabled=no distance=2 dst-address=0.0.0.0/0 gateway=201.90.162.161 scope=30 target-scope=10
    /ip fireall mangle
    add action=mark-connection chain=output comment="CACHE FULL" content="X-Cache: HIT" disabled=no new-connection-mark=conn_squid-up passthrough=yes protocol=\
    tcp src-port=3128
    add action=mark-packet chain=output comment="" connection-mark=conn_squid-up disabled=no new-packet-mark=pacotes_squid-up passthrough=yes
    add action=mark-connection chain=prerouting comment="" disabled=no dst-port=3128 new-connection-mark=conn_squid-down passthrough=yes protocol=tcp
    add action=mark-packet chain=prerouting comment="" connection-mark=conn_squid-down disabled=no new-packet-mark=pacotes_squid-down passthrough=yes
    add action=accept chain=prerouting comment="SEM BALANCE DE DESTINO" disabled=no dst-address-list=sem_balance in-interface=LOCAL
    add action=mark-connection chain=input comment="MARCACAO DE NOVAS CONEXOES" connection-state=new disabled=no in-interface=LINK1 new-connection-mark=conn_na \
    passthrough=yes
    add action=mark-connection chain=input comment="" connection-state=new disabled=no in-interface=LINK2 new-connection-mark=conn_nb passthrough=yes
    add action=mark-routing chain=output comment="MARCACAO DE ROTAS" connection-mark=conn_na disabled=no new-routing-mark=to_ra passthrough=no
    add action=mark-routing chain=output comment="" connection-mark=conn_nb disabled=no new-routing-mark=to_rb passthrough=no
    add action=mark-connection chain=prerouting comment="MARCACAO DE NOVAS CONEXOES" disabled=no dst-address-type=!local in-interface=LOCAL new-connection-mark=\
    conn_ma0 passthrough=yes per-connection-classifier=both-addresses:2/0
    add action=mark-connection chain=prerouting comment="" disabled=no dst-address-type=!local in-interface=LOCAL new-connection-mark=conn_mb1 passthrough=yes \
    per-connection-classifier=both-addresses:2/1
    add action=mark-routing chain=prerouting comment="MARCACAO DE INTERFACES" connection-mark=conn_ma0 disabled=no in-interface=LOCAL new-routing-mark=to_nra \
    passthrough=no
    add action=mark-routing chain=prerouting comment="" connection-mark=conn_mb1 disabled=no in-interface=LOCAL new-routing-mark=to_nrb passthrough=no

  20. #100

    Padrão

    Citação Postado originalmente por tiagomatias Ver Post

    Obrigadoai Thiago, Realmente agora 100% link embratel 14 e gvt 20 dedicado, load perfeito.
    Abraço.