I installed a Mkrotik RB750GL with the followin configuration:-
Port1 = WAN1 (192.168.100.10)
Port2 = WAN2 (192.168.200.10)
Port3 = LAN (192.168.6.1)
Port4 = Servers (192.0.0.99)
Port5 = 2nd Office (192.168.15.1)
When I configure this router for Load Balancing and fiailover, user on LAN (192.168.6.1) not able to access servers on Port 4 (192.0.0.0 Network). But my Mikrotik can ping those servers.
After disabling following mangle rules, my LAN users can access servers.
add action=mark-routing chain=output connection-mark=WAN1_Conn
new-routing-mark=To_WAN1 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN2_Conn
new-routing-mark=To_WAN2 passthrough=yes
I’ve added the following mangle rules:-
/ip firewall mangle
add action=accept chain=prerouting dst-address=192.168.10.0/24 in-interface=
LAN-Bridge
add action=accept chain=prerouting dst-address=192.168.20.0/24 in-interface=
LAN-Bridge
add action=mark-connection chain=prerouting connection-mark=no-mark
in-interface=WAN-1 new-connection-mark=WAN1_Conn passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark
in-interface=WAN-2 new-connection-mark=WAN2_Conn passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark
dst-address-type=!local in-interface=LAN-Bridge new-connection-mark=
WAN1_Conn passthrough=yes per-connection-classifier=both-addresses:2/0
add action=mark-connection chain=prerouting connection-mark=no-mark
dst-address-type=!local in-interface=LAN-Bridge new-connection-mark=
WAN2_Conn passthrough=yes per-connection-classifier=both-addresses:2/1
add action=mark-routing chain=prerouting connection-mark=WAN1_Conn
in-interface=LAN-Bridge new-routing-mark=To_WAN1 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=WAN2_Conn
in-interface=LAN-Bridge new-routing-mark=To_WAN2 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN1_Conn
new-routing-mark=To_WAN1 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN2_Conn
new-routing-mark=To_WAN2 passthrough=yes
If anyone can help, it’ll be great.