Hey guys,
I have created a load balancing configuration with a couple of different WANS. The load balancing is working but I am unable to get over 100Mbps on bridges.
Could anyone check what I configured wrong?
# may/05/2020 07:00:21 by RouterOS 6.45.6
# software id = PH86-G17J
#
# model = CCR1036-12G-4S
/interface bridge
add name=Bridge_T2
add name=bridge_backhaul1
add name=bridge_backhaul2
add name=bridge_default
/interface ethernet
set [ find default-name=ether1 ] name="eth1 - WAN1"
set [ find default-name=ether2 ] name="eth2 - WAN2"
set [ find default-name=ether3 ] comment="100 MBs DL + 100 MBs UL" name=\
"eth3 - WAN3"
set [ find default-name=ether4 ] disabled=yes name="eth4 - WAN4"
set [ find default-name=ether5 ] comment="60 MBs DL + 10 MBs UL" name=\
"eth5 - WAN5"
set [ find default-name=ether6 ] comment="60 MBs DL + 10 MBs UL" disabled=yes \
name="eth6 - WAN6"
set [ find default-name=ether7 ] comment="60 MBs DL + 10 MBs UL" name=\
"eth7 - WAN7"
set [ find default-name=ether8 ] disabled=yes name="eth8 - WAN8"
set [ find default-name=ether9 ] name="eth9 - Network Server"
set [ find default-name=ether10 ] comment="Backhaul -> Allsides (T3)" name=\
"eth10 - Backhaul (T3)"
set [ find default-name=ether11 ] comment="Backhaul -> Buntump (T2)" name=\
"eth11 - Backhaul (T2)"
set [ find default-name=ether12 ] comment="EdgeSwitch 24 + POE" name=\
"ether12 - EdgeSwitch"
/interface vlan
add interface="eth3 - WAN3" name=VLAN447_Management vlan-id=447
add interface="eth10 - Backhaul (T3)" name=VLAN447_Management_p10 vlan-id=447
add interface="eth11 - Backhaul (T2)" name=VLAN447_Management_p11 vlan-id=447
add interface="eth5 - WAN5" name=VLAN447_Management_p5 vlan-id=447
add interface="eth6 - WAN6" name=VLAN447_Management_p6 vlan-id=447
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=dhcp_pool0 ranges=10.22.16.2-10.22.16.200
add name=dhcp_pool1 ranges=10.22.17.2-10.22.17.6
add name=dhcp_pool2 ranges=10.0.0.2-10.0.0.254
/ip dhcp-server
add address-pool=dhcp_pool0 disabled=no interface=bridge_backhaul1 lease-time=\
1d name=dhcp1
add address-pool=dhcp_pool1 disabled=no interface=bridge_backhaul2 lease-time=\
1d name=dhcp2
add address-pool=dhcp_pool2 disabled=no interface=bridge_default lease-time=1d \
name=dhcp3
set admin access=\
own-routers,own-users,own-profiles,own-limits,config-payment-gw
/interface bridge port
add bridge=bridge_backhaul1 disabled=yes interface="eth2 - WAN2"
add bridge=bridge_backhaul1 disabled=yes interface="eth3 - WAN3"
add bridge=bridge_backhaul2 disabled=yes interface="eth4 - WAN4"
add bridge=bridge_backhaul2 disabled=yes interface="eth5 - WAN5"
add bridge=bridge_default interface="ether12 - EdgeSwitch"
add bridge=Bridge_T2 interface="eth11 - Backhaul (T2)"
add bridge=bridge_backhaul1 interface=VLAN447_Management
add bridge=bridge_backhaul1 interface=VLAN447_Management_p11
add bridge=bridge_backhaul1 interface=VLAN447_Management_p5
add bridge=bridge_backhaul1 interface=VLAN447_Management_p6
add bridge=bridge_default interface="eth10 - Backhaul (T3)"
add bridge=bridge_backhaul1 interface=VLAN447_Management_p10
add bridge=Bridge_T2 interface="eth9 - Network Server"
/ip address
add address=10.22.16.1/27 interface=bridge_backhaul1 network=10.22.16.0
add address=10.22.17.1/29 interface=bridge_backhaul2 network=10.22.17.0
add address=10.0.0.1/24 interface=bridge_default network=10.0.0.0
add address=10.2.0.1/22 interface=Bridge_T2 network=10.2.0.0
add address=10.22.16.1/27 disabled=yes interface=Bridge_T2 network=10.22.16.0
/ip dhcp-client
add add-default-route=no dhcp-options=hostname,clientid disabled=no interface=\
"eth5 - WAN5"
add add-default-route=no dhcp-options=hostname,clientid disabled=no interface=\
"eth6 - WAN6"
add add-default-route=no dhcp-options=hostname,clientid disabled=no interface=\
"eth7 - WAN7"
add add-default-route=no dhcp-options=hostname,clientid disabled=no interface=\
"eth8 - WAN8"
add add-default-route=no dhcp-options=hostname,clientid disabled=no interface=\
"eth4 - WAN4"
add add-default-route=no dhcp-options=hostname,clientid disabled=no interface=\
"eth3 - WAN3"
/ip dhcp-server network
add address=10.0.0.0/24 dns-server=8.8.8.8 gateway=10.0.0.1
add address=10.22.16.0/27 dns-server=8.8.8.8 gateway=10.22.16.1
add address=10.22.17.0/29 dns-server=8.8.8.8 gateway=10.22.17.1
/ip dns
set servers=8.8.8.8
/ip firewall address-list
add address=google.com list=google
add address=64.233.160.0/19 list=google
add address=66.102.0.0/20 list=google
add address=66.249.64.0/19 list=google
add address=72.14.192.0/18 list=google
add address=74.125.0.0/16 list=google
add address=209.85.128.0/17 list=google
add address=216.239.32.0/19 list=google
add address=10.24.10.0/24 list=SitesIPS
add address=10.24.11.0/24 list=SitesIPS
add address=10.24.12.0/24 list=SitesIPS
add address=10.24.13.0/24 list=SitesIPS
/ip firewall filter
add action=accept chain=input dst-address=10.2.0.0/22 src-address=10.0.0.0/24
add action=accept chain=input dst-address=10.0.0.0/24 src-address=10.2.0.0/22
/ip firewall mangle
add action=mark-connection chain=forward comment="Client | DL | Connection" \
disabled=yes in-interface="eth3 - WAN3" new-connection-mark=\
"Client | DL | Connection" passthrough=no
add action=mark-packet chain=forward comment="Client | DL | Packets" \
connection-mark="Client | DL | Connection" disabled=yes new-packet-mark=\
"Client | DL | Packets" passthrough=yes
add action=mark-connection chain=prerouting comment="Client | UP | Connection" \
disabled=yes in-interface=bridge_default new-connection-mark=\
"Client | UP | Connection" passthrough=yes
add action=mark-packet chain=prerouting comment="Client | UP | Packets" \
connection-mark="Client | UP | Connection" disabled=yes new-packet-mark=\
"Client | UP | Packets" passthrough=yes
add action=mark-packet chain=forward comment="HTTP/S | DL | Packets" disabled=\
yes new-packet-mark="HTTP/S | DL | Packets" packet-mark=\
"Client | DL | Packets" passthrough=no port=80,443 protocol=tcp
add action=mark-packet chain=forward comment="HTTP/S | UP | Packets" disabled=\
yes new-packet-mark="HTTP/S | UP | Packets" packet-mark=\
"Client | UP | Packets" passthrough=no port=80,443 protocol=tcp
add action=mark-packet chain=forward comment="Client | DL | Other | Packets" \
disabled=yes new-packet-mark="Client | DL | Other | Packets" packet-mark=\
"Client | DL | Packets" passthrough=no
add action=mark-packet chain=forward comment="Client | UP | Other | Packets" \
disabled=yes new-packet-mark="Client | UP | Other | Packets" packet-mark=\
"Client | UP | Packets" passthrough=yes
add action=accept chain=prerouting dst-address=192.168.1.0/24 in-interface=\
bridge_default
add action=accept chain=prerouting dst-address=10.2.0.0/22 in-interface=\
Bridge_T2
add action=accept chain=prerouting dst-address=10.0.0.0/24 in-interface=\
bridge_default
add action=accept chain=prerouting dst-address=10.42.28.0/22 in-interface=\
bridge_default
add action=accept chain=prerouting dst-address=192.168.5.0/24 in-interface=\
bridge_default
add action=accept chain=prerouting dst-address=10.22.16.0/24 in-interface=\
bridge_default
add action=accept chain=prerouting dst-address=192.168.20.0/24 in-interface=\
bridge_default
add action=accept chain=prerouting dst-address=192.168.77.0/24 in-interface=\
bridge_default
add action=mark-connection chain=prerouting connection-mark=no-mark \
in-interface="eth3 - WAN3" new-connection-mark=WAN3_Conn passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark \
in-interface="eth4 - WAN4" new-connection-mark=WAN4_Conn passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark \
in-interface="eth5 - WAN5" new-connection-mark=WAN5_Conn passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark \
in-interface="eth6 - WAN6" new-connection-mark=WAN6_Conn passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark \
in-interface="eth7 - WAN7" new-connection-mark=WAN7_Conn passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark \
in-interface="eth8 - WAN8" new-connection-mark=WAN8_Conn passthrough=yes
add action=mark-connection chain=prerouting comment=Wan3 connection-mark=\
no-mark dst-address-type=!local in-interface=bridge_default \
new-connection-mark=WAN3_Conn passthrough=yes per-connection-classifier=\
both-addresses:7/0
add action=mark-connection chain=prerouting connection-mark=no-mark \
dst-address-type=!local in-interface=Bridge_T2 new-connection-mark=\
WAN3_Conn passthrough=yes per-connection-classifier=both-addresses:7/0
add action=mark-connection chain=prerouting comment=Wan4 connection-mark=\
no-mark dst-address-type=!local in-interface=bridge_default \
new-connection-mark=WAN4_Conn passthrough=yes per-connection-classifier=\
both-addresses:7/1
add action=mark-connection chain=prerouting connection-mark=no-mark \
dst-address-type=!local in-interface=Bridge_T2 new-connection-mark=\
WAN4_Conn passthrough=yes per-connection-classifier=both-addresses:7/1
add action=mark-connection chain=prerouting comment=Wan5 connection-mark=\
no-mark dst-address-type=!local in-interface=bridge_default \
new-connection-mark=WAN5_Conn passthrough=yes per-connection-classifier=\
both-addresses:7/2
add action=mark-connection chain=prerouting connection-mark=no-mark \
dst-address-type=!local in-interface=Bridge_T2 new-connection-mark=\
WAN5_Conn passthrough=yes per-connection-classifier=both-addresses:7/2
add action=mark-connection chain=prerouting comment=Wan6 connection-mark=\
no-mark dst-address-type=!local in-interface=bridge_default \
new-connection-mark=WAN6_Conn passthrough=yes per-connection-classifier=\
both-addresses:7/3
add action=mark-connection chain=prerouting connection-mark=no-mark \
dst-address-type=!local in-interface=Bridge_T2 new-connection-mark=\
WAN6_Conn passthrough=yes per-connection-classifier=both-addresses:7/3
add action=mark-connection chain=prerouting comment=Wan7 connection-mark=\
no-mark dst-address-type=!local in-interface=bridge_default \
new-connection-mark=WAN7_Conn passthrough=yes per-connection-classifier=\
both-addresses:7/4
add action=mark-connection chain=prerouting connection-mark=no-mark \
dst-address-type=!local in-interface=Bridge_T2 new-connection-mark=\
WAN7_Conn passthrough=yes per-connection-classifier=both-addresses:7/4
add action=mark-connection chain=prerouting comment=Wan8 connection-mark=\
no-mark dst-address-type=!local in-interface=bridge_default \
new-connection-mark=WAN8_Conn passthrough=yes per-connection-classifier=\
both-addresses:7/5
add action=mark-connection chain=prerouting connection-mark=no-mark \
dst-address-type=!local in-interface=Bridge_T2 new-connection-mark=\
WAN8_Conn passthrough=yes per-connection-classifier=both-addresses:7/5
add action=mark-routing chain=prerouting comment=Wan3 connection-mark=WAN3_Conn \
in-interface=bridge_default new-routing-mark=to_wan3 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=WAN3_Conn \
in-interface=Bridge_T2 new-routing-mark=to_wan3 passthrough=yes
add action=mark-routing chain=prerouting comment=Wan4 connection-mark=WAN4_Conn \
in-interface=bridge_default new-routing-mark=to_wan4 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=WAN4_Conn \
in-interface=Bridge_T2 new-routing-mark=to_wan4 passthrough=yes
add action=mark-routing chain=prerouting comment=Wan5 connection-mark=WAN5_Conn \
in-interface=bridge_default new-routing-mark=to_wan5 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=WAN5_Conn \
in-interface=Bridge_T2 new-routing-mark=to_wan5 passthrough=yes
add action=mark-routing chain=prerouting comment=Wan6 connection-mark=WAN6_Conn \
in-interface=bridge_default new-routing-mark=to_wan6 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=WAN6_Conn \
in-interface=Bridge_T2 new-routing-mark=to_wan6 passthrough=yes
add action=mark-routing chain=prerouting comment=Wan7 connection-mark=WAN7_Conn \
in-interface=bridge_default new-routing-mark=to_wan7 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=WAN7_Conn \
in-interface=Bridge_T2 new-routing-mark=to_wan7 passthrough=yes
add action=mark-routing chain=prerouting comment=Wan8 connection-mark=WAN8_Conn \
in-interface=bridge_default new-routing-mark=to_wan8 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=WAN8_Conn \
in-interface=Bridge_T2 new-routing-mark=to_wan8 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN3_Conn \
new-routing-mark=to_wan3 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN4_Conn \
new-routing-mark=to_wan4 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN5_Conn \
new-routing-mark=to_wan5 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN6_Conn \
new-routing-mark=to_wan6 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN7_Conn \
new-routing-mark=to_wan7 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN8_Conn \
new-routing-mark=to_wan8 passthrough=yes
/ip firewall nat
add action=masquerade chain=srcnat disabled=yes out-interface="eth2 - WAN2"
add action=masquerade chain=srcnat out-interface="eth3 - WAN3"
add action=masquerade chain=srcnat out-interface="eth4 - WAN4"
add action=masquerade chain=srcnat out-interface="eth5 - WAN5"
add action=masquerade chain=srcnat out-interface="eth6 - WAN6"
add action=masquerade chain=srcnat out-interface="eth7 - WAN7"
add action=masquerade chain=srcnat out-interface="eth8 - WAN8"
add action=masquerade chain=srcnat disabled=yes
/ip route
add check-gateway=ping distance=1 gateway=10.42.28.1 routing-mark=to_wan3 \
scope=10
add check-gateway=ping distance=2 gateway=192.168.77.1 routing-mark=to_wan4
add check-gateway=ping distance=1 gateway=192.168.74.1 routing-mark=to_wan5
add check-gateway=ping distance=1 gateway=192.168.5.1 routing-mark=to_wan6
add check-gateway=ping distance=1 gateway=192.168.76.1 routing-mark=to_wan7
add check-gateway=ping distance=2 gateway=192.168.78.1 routing-mark=to_wan8
add check-gateway=ping distance=1 gateway=10.42.28.1
add check-gateway=ping distance=2 gateway=192.168.5.1
add check-gateway=ping distance=3 gateway=192.168.74.1
add check-gateway=ping distance=4 gateway=192.168.76.1
add check-gateway=ping distance=5 gateway=192.168.78.1
add check-gateway=ping distance=6 gateway=192.168.77.1
add disabled=yes distance=1 dst-address=10.2.0.0/22 gateway=bridge_default
/lcd
set backlight-timeout=never color-scheme=dark default-screen=stats
/system identity
set name="Core Router"
/system logging
add topics=dhcp
add topics=interface
/system scheduler
add name=Reboot on-event="system reboot" policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
start-date=jan/31/2020 start-time=03:00:00
/tool graphing interface
add allow-address=10.0.0.0/24 interface="eth3 - WAN3"
add allow-address=10.0.0.0/24 interface="eth5 - WAN5"
add allow-address=10.0.0.0/24 interface="eth6 - WAN6"
add interface="eth2 - WAN2"
add interface="eth4 - WAN4"
add interface="eth7 - WAN7"
I’d love to hear from you guys with ideas!
Kind regards,
Ian