Im currently using this setup for Load Balancing and seems to be working pretty well. but noticed I cant ping or do anything from the routerboard itself. what do I need to add to it to get local access to the box?
/interface ethernet
set 0 arp=enabled auto-negotiation=yes comment=“” disabled=no full-duplex=yes
l2mtu=1526 mtu=1500 name=“ETH1 - LAN”
speed=100Mbps
set 1 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited comment=
“” disabled=no full-duplex=yes l2mtu=1522
master-port=none mtu=1500 name=“ETH2 - WAN1” speed=100Mbps
set 2 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited comment=
“” disabled=no full-duplex=yes l2mtu=1522
master-port=none mtu=1500 name=“ETH3 - WAN2” speed=100Mbps
set 3 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited comment=
“” disabled=no full-duplex=yes l2mtu=1522
master-port=none mtu=1500 name=“ETH4 - WAN3” speed=100Mbps
set 4 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited comment=
“” disabled=no full-duplex=yes l2mtu=1522
master-port=none mtu=1500 name=“ETH5 - WAN4” speed=100Mbps
set 5 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited comment=
“” disabled=no full-duplex=yes l2mtu=1522
master-port=none mtu=1500 name=“ETH6 - WAN5” speed=100Mbps
set 6 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited comment=
“” disabled=no full-duplex=yes l2mtu=1522
master-port=none mtu=1500 name=“ETH7 - WAN6” speed=100Mbps
/ip address
add address=192.168.254.50/24 broadcast=192.168.254.255 comment=“” disabled=no interface=“ETH1 - LAN” network=192.168.254.0
add address=10.2.1.3/24 broadcast=10.2.1.255 comment=“” disabled=no interface=“ETH2 - WAN1” network=10.2.1.0
add address=10.2.2.3/24 broadcast=10.2.2.255 comment=“” disabled=no interface=“ETH3 - WAN2” network=10.2.2.0
add address=10.2.3.3/24 broadcast=10.2.3.255 comment=“” disabled=no interface=“ETH4 - WAN3” network=10.2.3.0
add address=10.2.4.3/24 broadcast=10.2.4.255 comment=“” disabled=no interface=“ETH5 - WAN4” network=10.2.4.0
add address=10.2.5.3/24 broadcast=10.2.5.255 comment=“” disabled=no interface=“ETH6 - WAN5” network=10.2.5.0
add address=10.2.6.3/24 broadcast=10.2.6.255 comment=“” disabled=no interface=“ETH7 - WAN6” network=10.2.6.0
/ip firewall connection tracking
set enabled=yes generic-timeout=10m icmp-timeout=10s tcp-close-timeout=10s tcp-close-wait-timeout=10s tcp-established-timeout=1d tcp-fin-wait-timeout=10s
tcp-last-ack-timeout=10s tcp-syn-received-timeout=5s tcp-syn-sent-timeout=5s tcp-syncookie=no tcp-time-wait-timeout=10s udp-stream-timeout=3m
udp-timeout=10s
/ip firewall filter
add action=drop chain=forward comment=“” disabled=no p2p=all-p2p
/ip firewall mangle
add action=mark-routing chain=prerouting comment=“RUTA CLIENTES PLUS” disabled=no dscp=3 new-routing-mark=“Ruta Privada” passthrough=no
add action=mark-connection chain=input comment=“” disabled=no in-interface=“ETH2 - WAN1” new-connection-mark=“Conexion WAN1” passthrough=yes
add action=mark-connection chain=input comment=“” disabled=no in-interface=“ETH3 - WAN2” new-connection-mark=“Conexion WAN2” passthrough=yes
add action=mark-connection chain=input comment=“” disabled=no in-interface=“ETH4 - WAN3” new-connection-mark=“Conexion WAN3” passthrough=yes
add action=mark-connection chain=input comment=“” disabled=no in-interface=“ETH5 - WAN4” new-connection-mark=“Conexion WAN4” passthrough=yes
add action=mark-connection chain=input comment=“” disabled=no in-interface=“ETH6 - WAN5” new-connection-mark=“Conexion WAN5” passthrough=yes
add action=mark-connection chain=input comment=“” disabled=no in-interface=“ETH7 - WAN6” new-connection-mark=“Conexion WAN6” passthrough=yes
add action=mark-routing chain=output comment=“” connection-mark=“Conexion WAN1” disabled=no new-routing-mark=“Ruta WAN1” passthrough=yes
add action=mark-routing chain=output comment=“” connection-mark=“Conexion WAN2” disabled=no new-routing-mark=“Ruta WAN2” passthrough=yes
add action=mark-routing chain=output comment=“” connection-mark=“Conexion WAN3” disabled=no new-routing-mark=“Ruta WAN3” passthrough=yes
add action=mark-routing chain=output comment=“” connection-mark=“Conexion WAN4” disabled=no new-routing-mark=“Ruta WAN4” passthrough=yes
add action=mark-routing chain=output comment=“” connection-mark=“Conexion WAN5” disabled=no new-routing-mark=“Ruta WAN5” passthrough=yes
add action=mark-routing chain=output comment=“” connection-mark=“Conexion WAN6” disabled=no new-routing-mark=“Ruta WAN6” passthrough=yes
add action=accept chain=prerouting comment=“” disabled=no dst-address=10.2.1.0/24 in-interface=“ETH1 - LAN”
add action=accept chain=prerouting comment=“” disabled=no dst-address=10.2.2.0/24 in-interface=“ETH1 - LAN”
add action=accept chain=prerouting comment=“” disabled=no dst-address=10.2.3.0/24 in-interface=“ETH1 - LAN”
add action=accept chain=prerouting comment=“” disabled=no dst-address=10.2.4.0/24 in-interface=“ETH1 - LAN”
add action=accept chain=prerouting comment=“” disabled=no dst-address=10.2.5.0/24 in-interface=“ETH1 - LAN”
add action=accept chain=prerouting comment=“” disabled=no dst-address=10.2.6.0/24 in-interface=“ETH1 - LAN”
add action=mark-connection chain=prerouting comment=“” disabled=no dst-address-type=!local in-interface=“ETH1 - LAN” new-connection-mark=“Conexion WAN1”
passthrough=yes per-connection-classifier=both-addresses:6/0
add action=mark-connection chain=prerouting comment=“” disabled=no dst-address-type=!local in-interface=“ETH1 - LAN” new-connection-mark=“Conexion WAN2”
passthrough=yes per-connection-classifier=both-addresses:6/1
add action=mark-connection chain=prerouting comment=“” disabled=no dst-address-type=!local in-interface=“ETH1 - LAN” new-connection-mark=“Conexion WAN3”
passthrough=yes per-connection-classifier=both-addresses:6/2
add action=mark-connection chain=prerouting comment=“” disabled=no dst-address-type=!local in-interface=“ETH1 - LAN” new-connection-mark=“Conexion WAN4”
passthrough=yes per-connection-classifier=both-addresses:6/3
add action=mark-connection chain=prerouting comment=“” disabled=no dst-address-type=!local in-interface=“ETH1 - LAN” new-connection-mark=“Conexion WAN5”
passthrough=yes per-connection-classifier=both-addresses:6/4
add action=mark-connection chain=prerouting comment=“” disabled=no dst-address-type=!local in-interface=“ETH1 - LAN” new-connection-mark=“Conexion WAN6”
passthrough=yes per-connection-classifier=both-addresses:6/5
add action=mark-routing chain=prerouting comment=“” connection-mark=“Conexion WAN1” disabled=no in-interface=“ETH1 - LAN” new-routing-mark=“Ruta WAN1”
passthrough=yes
add action=mark-routing chain=prerouting comment=“” connection-mark=“Conexion WAN2” disabled=no in-interface=“ETH1 - LAN” new-routing-mark=“Ruta WAN2”
passthrough=yes
add action=mark-routing chain=prerouting comment=“” connection-mark=“Conexion WAN3” disabled=no in-interface=“ETH1 - LAN” new-routing-mark=“Ruta WAN3”
passthrough=yes
add action=mark-routing chain=prerouting comment=“” connection-mark=“Conexion WAN4” disabled=no in-interface=“ETH1 - LAN” new-routing-mark=“Ruta WAN4”
passthrough=yes
add action=mark-routing chain=prerouting comment=“” connection-mark=“Conexion WAN5” disabled=no in-interface=“ETH1 - LAN” new-routing-mark=“Ruta WAN5”
passthrough=yes
add action=mark-routing chain=prerouting comment=“” connection-mark=“Conexion WAN6” disabled=no in-interface=“ETH1 - LAN” new-routing-mark=“Ruta WAN6”
passthrough=yes
/ip firewall nat
add action=masquerade chain=srcnat comment=“” disabled=no out-interface=“ETH2 - WAN1”
add action=masquerade chain=srcnat comment=“” disabled=no out-interface=“ETH3 - WAN2”
add action=masquerade chain=srcnat comment=“” disabled=no out-interface=“ETH4 - WAN3”
add action=masquerade chain=srcnat comment=“” disabled=no out-interface=“ETH5 - WAN4”
add action=masquerade chain=srcnat comment=“” disabled=no out-interface=“ETH6 - WAN5”
add action=masquerade chain=srcnat comment=“” disabled=no out-interface=“ETH7 - WAN6”
/ip route
add comment=“” disabled=no distance=1 dst-address=0.0.0.0/0 gateway=10.2.1.1 routing-mark=“Ruta Privada” scope=30 target-scope=10
add comment=“” disabled=no distance=1 dst-address=0.0.0.0/0 gateway=10.2.1.1 routing-mark=“Ruta WAN1” scope=30 target-scope=10
add comment=“” disabled=no distance=1 dst-address=0.0.0.0/0 gateway=10.2.2.1 routing-mark=“Ruta WAN2” scope=30 target-scope=10
add comment=“” disabled=no distance=1 dst-address=0.0.0.0/0 gateway=10.2.3.1 routing-mark=“Ruta WAN3” scope=30 target-scope=10
add comment=“” disabled=no distance=1 dst-address=0.0.0.0/0 gateway=10.2.4.1 routing-mark=“Ruta WAN4” scope=30 target-scope=10
add comment=“” disabled=no distance=1 dst-address=0.0.0.0/0 gateway=10.2.5.1 routing-mark=“Ruta WAN5” scope=30 target-scope=10
add comment=“” disabled=no distance=1 dst-address=0.0.0.0/0 gateway=10.2.6.1 routing-mark=“Ruta WAN6” scope=30 target-scope=10