Postado originalmente por
scinfovirtual
segue a forma que eu ja usei aqui, que é assim....um cliente conecta vai para o link 1 outro conecta vai para o link 2, outro link1, outro link2, e assim sucessivamente....
/ ip firewall mangle
add chain=prerouting in-interface=Saida src-address-list=link1 \
action=mark-connection new-connection-mark=link1 passthrough=yes \
comment="" disabled=no
add chain=prerouting in-interface=Saida src-address-list=link1 \
action=mark-routing new-routing-mark=link1 passthrough=no comment="" \
disabled=no
add chain=prerouting in-interface=Saida src-address-list=link2 \
action=mark-connection new-connection-mark=link2 passthrough=yes \
comment="" disabled=no
add chain=prerouting in-interface=Saida src-address-list=link2 \
action=mark-routing new-routing-mark=link2 passthrough=no comment="" \
disabled=no
add chain=prerouting in-interface=Saida connection-state=new nth=1,1,0 \
action=mark-connection new-connection-mark=link1 passthrough=yes \
comment="" disabled=no
add chain=prerouting in-interface=Saida src-address=192.168.0.0/16 \
connection-mark=link1 action=add-src-to-address-list address-list=link1 \
address-list-timeout=1d comment="" disabled=no
add chain=prerouting in-interface=Saida connection-mark=link1 \
action=mark-routing new-routing-mark=link1 passthrough=no comment="" \
disabled=no
add chain=prerouting in-interface=Saida connection-state=new nth=1,1,1 \
action=mark-connection new-connection-mark=link2 passthrough=yes \
comment="" disabled=no
add chain=prerouting in-interface=Saida src-address=192.168.0.0/16 \
connection-mark=link2 action=add-src-to-address-list address-list=link2 \
address-list-timeout=1d comment="" disabled=no
add chain=prerouting in-interface=Saida connection-mark=link2 \
action=mark-routing new-routing-mark=link2 passthrough=no comment="" \
disabled=no
/ ip firewall nat
add chain=srcnat connection-mark=link1 action=src-nat \
to-addresses=192.168.5.103 to-ports=0-65535 comment="" disabled=no
add chain=srcnat connection-mark=link2 action=src-nat \
to-addresses=192.168.4.103 to-ports=0-65535 comment="" disabled=no
/ ip route
add dst-address=0.0.0.0/0 gateway=192.168.5.254 scope=255 target-scope=10 \
comment="ROTA PADRAO" disabled=no
add dst-address=0.0.0.0/0 gateway=192.168.5.254 scope=255 target-scope=10 \
routing-mark=link1 comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=192.168.4.254 scope=255 target-scope=10 \
routing-mark=link2 comment="" disabled=no
abração....
Kildare....receita de bolo vai ser dificel vc encontrar aqui amigo...mas use a ferramenta pesquisar que vc vai encontrar oque precisa....pode se basear tbm nestas regras que enviei ai....