I'm trying to add to mikrotik second WAN, because ISP gave me on this WAN link another subnet block of 16 Public IP addresses, these IP should forward for my internal services on LAN, but now I'm stuck with problem even accessing my mikrotik through this second WAN, if I figure this out then will step to port forwarding on this WAN. This is my setup:
LAN - sfp-sfpplus1
DMZ - ETH5
WAN1 - sfp - x.x.x.58/29
WAN2 - ETH8 x.x.x.246/30, routable IP block on this link is x.x.x.145/28
ROS ver 6.37.5
so I've configure already masquerade:
add action=masquerade chain=srcnat out-interface=sfp1
add action=masquerade chain=srcnat out-interface=ether8
add action=mark-connection chain=prerouting comment="WAN1 IN -- > WAN1 OUT" in-interface=sfp1 new-connection-mark=WAN1 passthrough=no
add action=mark-routing chain=output connection-mark=WAN1 new-routing-mark=to_WAN1 passthrough=no
add action=mark-connection chain=prerouting comment="WAN2 IN -- > WAN2 OUT" in-interface=ether8 new-connection-mark=WAN2 passthrough=no
add action=mark-routing chain=output connection-mark=WAN2 new-routing-mark=to_WAN2 passthrough=no
add action=mark-routing chain=prerouting comment="Port Forward WAN2 IN -- > WAN2 OUT" connection-mark=WAN2_pfw in-interface-list=Lan+ETH5 new-routing-mark=\
to_WAN2 passthrough=no
add action=mark-connection chain=forward connection-state=new in-interface=ether8 new-connection-mark=WAN2_pfw passthrough=no
add action=mark-routing chain=prerouting comment="Port Forward WAN1 IN -- > WAN1 OUT" connection-mark=WAN1_pfw in-interface-list=Lan+ETH5 new-routing-mark=\
to_WAN1 passthrough=no
add action=mark-connection chain=forward connection-state=new in-interface=sfp1 new-connection-mark=WAN1_pfw passthrough=no
add check-gateway=ping distance=1 gateway=x.x.x.57 routing-mark=to_WAN1
add check-gateway=ping distance=1 gateway=x.x.x.245 routing-mark=to_WAN2
add comment=WAN1 distance=1 gateway=x.x.x.57
add comment=WAN2 distance=2 gateway=x.x.x.245
My second question how should I configure this IP addresses block, should I simply add this IP block x.x.x.145/28 as secondary address to WAN2?