Hello,
I just configure policy routing for 2 of my uplink from different ISP. Both are running well, but I cannot ping one network from other one. Below is my route list
ip route> rule print
Flags: X - disabled, I - inactive
0 src-address=1XX.10X.38.32/28 routing-mark=FiberNet action=lookup
table=FiberNet
ip route> print
DST-ADDRESS PREF-SRC G GATEWAY DISTANCE INTERFACE
0 ADC 1XX.10X.38.20/30 1XX.10X.38.22 Wan
1 ADC 1XX.10X.38.32/28 1XX.10X.38.33 Lan
3 ADC 2YY.14Y.58.80/30 2YY.14Y.58.82 Wan
4 ADC 2YY.14Y.58.96/27 2YY.14Y.58.97 Lan
5 A S ;;; added by setup
0.0.0.0/0 r 2YY.14Y.58.81 Wan
6 A S ;;; added by setup
0.0.0.0/0 r 1XX.10X.38.21 Wan
No firewall to drop ICMP of any usefull port, where from each network (2YY.14Y.58.96/27 & 1XX.10X.38.32/28) everything is running well and fine. Both network can out and available from outside. But not accessible with each other. Where they(network) live together and sharing same room(interface & machine) but seems they are divorced(no route).
Can anyone plz help me to make their(network) relations good.
I think, that you have to exclude traffic betweern these subnets from policy-routing rules, then communication should work,
it should be like ‘ip firewall mangle add src-address=local_subnet_1 dst-address=local_subnet_2 action=accept passtrough=no’.
Place this rule before mark-routing rules.
Dear sergejs,
I just put the following mangle rule, but things remain same. I also used pre routing chain.
ip firewall mangle> print
Flags: X - disabled, I - invalid, D - dynamic
0 chain=forward src-address=2YY.14Y.58.96/27 dst-address=1XX.10X.38.32/28
action=accept
I know these are your defualt gateways man, disable them do the trace and sumbit the results. after that you can reenable them! plus sumbit your routing table with detials and submit your NAT rule if you have so.