- 1. If the connection has not been marked as HTTP_BIG yet, then mark it as HTTP.
2. If the connection has transferred over 5MB AND the current rate is 200K or more, change the connection mark to HTTP_BIG.
3. Mark the packets.
Note: remove the slash (\) below. It is there for display formatting only.
/ip firewall mangle add action=mark-connection chain=prerouting \ connection-mark=!HTTP_BIG connection-state=new new-connection-mark=HTTP port=80,443 protocol=tcp add action=mark-connection chain=prerouting \ connection-mark=HTTP connection-bytes=500000-0 connection-rate=200k-100M new-connection-mark=HTTP_BIG protocol=tcp add action=mark-packet chain=prerouting \ connection-mark=HTTP_BIG new-packet-mark=HTTP_BIG passthrough=no add action=mark-packet chain=prerouting \ connection-mark=HTTP new-packet-mark=HTTP passthrough=no