Code: Select all
/routing table
add disabled=no fib name=WAN1
add disabled=no fib name=WAN2
/ip firewall connection tracking
set enabled=yes udp-timeout=10s
/ip settings
set accept-redirects=yes accept-source-route=yes allow-fast-path=no \
tcp-syncookies=yes
/interface pppoe-server server
add disabled=no interface=ether5 one-session-per-host=yes service-name=\
service1
/ip dhcp-client
add !dhcp-options interface=ether1 use-peer-dns=no use-peer-ntp=no
add default-route-distance=2 !dhcp-options interface=ether2 use-peer-dns=no \
use-peer-ntp=no
/ip dns
set servers=8.8.8.8,1.1.1.1
/ip firewall mangle
add action=mark-connection chain=prerouting connection-mark=no-mark \
connection-state=new in-interface=ether1 new-connection-mark=ToWAN1 \
passthrough=yes
add action=mark-routing chain=output connection-mark=ToWAN1 new-routing-mark=\
WAN1 passthrough=no
add action=mark-connection chain=prerouting connection-mark=no-mark \
connection-state=new in-interface=ether2 new-connection-mark=ToWAN2 \
passthrough=yes
add action=mark-routing chain=output connection-mark=ToWAN2 new-routing-mark=\
WAN2 passthrough=no
add action=mark-connection chain=prerouting connection-mark=no-mark \
connection-state=new in-interface-list=ppp new-connection-mark=ToWAN1 \
passthrough=yes per-connection-classifier=src-address:2/0
add action=mark-routing chain=prerouting connection-mark=ToWAN1 \
in-interface-list=ppp new-routing-mark=WAN1 passthrough=no
add action=mark-connection chain=prerouting connection-mark=no-mark \
connection-state=new in-interface-list=ppp new-connection-mark=ToWAN2 \
passthrough=yes per-connection-classifier=src-address:2/1
add action=mark-routing chain=prerouting connection-mark=ToWAN2 \
in-interface-list=ppp new-routing-mark=WAN2 passthrough=no
/ip firewall nat
add action=masquerade chain=srcnat out-interface-list=WAN
/ip route
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=ether1 \
routing-table=WAN1 scope=30 suppress-hw-offload=no target-scope=10
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=ether2 \
routing-table=WAN2 scope=30 suppress-hw-offload=no target-scope=10