SENHORES BOM DIA, PRECISO DE UM HELP DE VCS. ESTOU COM O SEGUINTE PROBLEMA.. TENHO UMA RB 750GL + THUNDERCACHE. 2 LINKS DE 50MB DEDICADO, E ESTOU REDIRECIONANDO TODO O TRAFEGO DA REDE PARA O THUNDER VIA MANGLE.


###Cria ROTA Thunder


/ip route add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=10.0.0.2 routing-mark=Thunder_router scope=30 target-scope=10


###Habilita Mascaramento Thunder


/ip firewall nat add action=masquerade chain=srcnat comment="MASCARAMENTO DO THUNDER CACHE 7" disabled=no src-address=10.0.0.0/30




###Redireciona Thunder Via Mangle e Regra Cache Full


/ip firewall mangle


add action=mark-routing chain=prerouting comment="REDIRECT THUNDERCACHE" disabled=no dst-address-list=!NO_CACHE dst-port=80 in-interface=!ether2-ThunderCache new-routing-mark=Thunder_router passthrough=no protocol=tcp src-address=192.168.0.0/24


add action=mark-packet chain=postrouting comment="CACHE FULL THUNDER 7" disabled=no dscp=30 new-packet-mark="cache full" passthrough=yes


### Habilita Limite CACHE FULL


/queue type add kind=pcq name=Thunder pcq-classifier=dst-address pcq-limit=50 pcq-rate=0 pcq-total-limit=5000000 set default-small kind=pfifo name=default-small pfifo-limit=10




/queue tree add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=0 max-limit=20M name="CACHE FULL" packet-mark="cache full" parent=global-out priority=8 queue=Thunder


ESSAS AI ACIMA SÃO MINHAS REGRA, POREM O Q ESTA ACONTENCENDO, O HOTSPOT PARA DE BLOQUEAR O PESSOAL QUANDO COLOCO A OPÇÃO "regular", em IPBINDINGS.


OUTRA QUESTÃO É O MEU LOADBALANCE, COMO EU FAÇO O REDIRECT VIA MANGLE E JA TENHO O NAT CONFIGURADO NAS REDES PRECISO COLOCAR AS DUAS ULTIMAS REGRAS ABAIXO.


O QUE EU POSSO MUDAR PARA PODER UTILIZAR A MINHA REDE, REDIRECIONANDO VIA MANGLE AS REQUISIÇÕES PARA O PROXY E O LOAD BALANCE E CONTINUAR BLOQUEANDO MEUS USUÁRIOS SEMPRE Q EU QUISER. ( O PROXY ESTA EM MODO PARALELO )


LOAD BALANCE


/ ip firewall mangle
add chain=prerouting dst-address=189.45.243.40/29 action=accept in-interface=ether3-Residencial
add chain=prerouting dst-address=189.126.143.0/28 action=accept in-interface=ether3-Residencial
add chain=prerouting in-interface=ether1-LinkIB connection-mark=no-mark action=mark-connection new-connection-mark=ether1-LinkIB_conn
add chain=prerouting in-interface=ether4-BACKUP connection-mark=no-mark action=mark-connection new-connection-mark=ether4-BACKUP_conn
add chain=prerouting in-interface=ether3-Residencial connection-mark=no-mark dst-address-type=!local per-connection-classifier=both-addresses:2/0 action=mark-connection new-connection-mark=ether1-LinkIB_conn
add chain=prerouting in-interface=ether3-Residencial connection-mark=no-mark dst-address-type=!local per-connection-classifier=both-addresses:2/1 action=mark-connection new-connection-mark=ether4-BACKUP_conn
add chain=prerouting connection-mark=ether1-LinkIB_conn in-interface=ether3-Residencial action=mark-routing new-routing-mark=to_ether1-LinkIB
add chain=prerouting connection-mark=ether4-BACKUP_conn in-interface=ether3-Residencial action=mark-routing new-routing-mark=to_ether4-BACKUP
add chain=output connection-mark=ether1-LinkIB_conn action=mark-routing new-routing-mark=to_ether1-LinkIB
add chain=output connection-mark=ether4-BACKUP_conn action=mark-routing new-routing-mark=to_ether4-BACKUP


/ ip route
add dst-address=0.0.0.0/0 gateway=189.45.243.41 routing-mark=to_ether1-LinkIB check-gateway=ping
add dst-address=0.0.0.0/0 gateway=189.126.143.1 routing-mark=to_ether4-BACKUP check-gateway=ping
add dst-address=0.0.0.0/0 gateway=189.45.243.41 distance=1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=189.126.143.1 distance=2 check-gateway=ping




/ ip firewall nat
add chain=srcnat out-interface=ether1-LinkIB action=masquerade
add chain=srcnat out-interface=ether4-BACKUP action=masquerade








DESDE JÁ AGRADEÇO PELA ATENÇÃO E AJUDA