Thu Sep 24, 2009 12:19 pm
I did PCC gateway load balancing configuration with 3 WAN connections.
I intend to do this configuration too for having max speed from proxy cache to clients, but firstly I need to consult with you.
-Is this wright config that I must add to my router?
-New Mangle rules (these ones that I intend to add), must be upper or downer (who must be executed firstly) PCC rules?
config that I intend to add:
[admin@instaler] > ip proxy pr
enabled: yes
src-address: 0.0.0.0
port: 3128
parent-proxy: 0.0.0.0
parent-proxy-port: 0
cache-drive: system
cache-administrator: "webmaster"
max-cache-size: none
cache-on-disk: yes
maximal-client-connections: 600
maximal-server-connections: 600
max-fresh-time: 3d
serialize-connections: yes
cache-hit-dscp: 4
[admin@instaler] ip firewall nat> pr
Flags: X - disabled, I - invalid, D - dynamic
0 chain=srcnat out-interface=WAN1
src-address=192.168.0.0/16 action=masquerade
1 chain=srcnat out-interface=WAN2
src-address=192.168.0.0/16 action=masquerade
2 chain=srcnat out-interface=WAN3
src-address=192.168.0.0/16 action=masquerade
3 chain=dstnat in-interface=lan src-address=192.168.0.0/16
protocol=tcp dst-port=80 action=redirect to-ports=800
/ip firewall mangle
add chain=output out-interface=Local dscp=4 action=mark-packet new-packet-mark=proxy-hit passthrough=no comment="HIT TRAFFIC FROM PROXY"
add chain=prerouting in-interface=Local src-address=192.168.0.0/16 action=mark-packet new-packet-mark=test-up passthrough=no comment="UP TRAFFIC"
add chain=forward src-address=192.168.0.0/16 action=mark-connection new-connection-mark=test-conn passthrough=yes comment="CONN-MARK"
add comment="DOWN-DIRECT CONNECTION" chain=forward in-interface=WAN1 connection-mark=test-conn action=mark-packet new-packet-mark=test-down passthrough=no
add comment="DOWN-DIRECT CONNECTION" chain=forward in-interface=WAN2 connection-mark=test-conn action=mark-packet new-packet-mark=test-down passthrough=no
add comment="DOWN-DIRECT CONNECTION" chain=forward in-interface=WAN3 connection-mark=test-conn action=mark-packet new-packet-mark=test-down passthrough=no
add comment="DOWN-VIA PROXY" chain=output out-interface=Local dst-address=192.168.0.0/16 action=mark-packet new-packet-mark=test-down passthrough=no
[admin@instaler] > queue tree pr
Flags: X - disabled, I - invalid
0 name="downstream" parent=Local packet-mark=test-down
limit-at=32000 queue=default priority=8
max-limit=32000 burst-limit=0
burst-threshold=0 burst-time=0s
1 name="upstream" parent=global-in
packet-mark=test-up limit-at=0
queue=default priority=8
max-limit=0 burst-limit=0
burst-threshold=0 burst-time=0s