Simpel aja gan semoga bermanfaat, pengen nulis setting mikrotik tentang LB, sapa tau ada yang butuh, hehehee... disini saya kasih contohnya 2 line yang di LB gan, karna saya juga masih newbie, jadi harap maklum kalau ada yang salah, tapi ane dah coba kaya gini lancar gan, silahkan sesuaikan dengan kondisi IP Address yang agan-agan pake, ether1 saya pake untuk menuju ke local network dan inet yang masuk saya kasih di ether2 dan ether3!! langsung aja gan.
#INTERFACE
interface
set ether1 name=local
interface
set ether2 name=wan1
interface
set ether3 name=wan2
#IP
ADDRESS
ip
address add address=192.168.1.1/24 netmask=255.255.255.0
interface=local
ip
address add address=192.168.2.2/24 netmask=255.255.255.0
interface=wan1
ip
address add address=192.168.3.2/24 netmask=255.255.255.0
interface=wan2
ip
dns set servers=8.8.8.8,8.8.4.4
#MANGLE
ip
firewall mangle add chain=input in-interface=wan1
action=mark-connection new-connection-mark=jalur01
ip
firewall mangle add chain=input in-interface=wan2
action=mark-connection new-connection-mark=jalur02
ip
firewall mangle add chain=output out-interface=wan1
connection-mark=jalur01 action=mark-routing
new-routing-mark=ke_jalur01
ip
firewall mangle add chain=output out-interface=wan2
connection-mark=jalur02 action=mark-routing
new-routing-mark=ke_jalur02
ip
firewall mangle add chain=prerouting dst-address=192.168.2.0/24
action=accept in-interface=local
ip
firewall mangle add chain=prerouting dst-address=192.168.3.0/24
action=accept in-interface=local
ip
firewall mangle add chain=prerouting dst-address-type=!local
in-interface=local per-connection-classifier=both-addresses:2/0
action=mark-connection new-connection-mark=jalur01 passthrough=yes
ip
firewall mangle add chain=prerouting dst-address-type=!local
in-interface=local per-connection-classifier=both-addresses:2/1
action=mark-connection new-connection-mark=jalur02 passthrough=yes
ip
firewall mangle add chain=prerouting connection-mark=jalur01
in-interface=local action=mark-routing new-routing-mark=ke_jalur01
ip
firewall mangle add chain=prerouting connection-mark=jalur02
in-interface=local action=mark-routing new-routing-mark=ke_jalur02
#IP
ROUTE
ip
route add dst-address=0.0.0.0/0 gateway=192.168.2.1 distance=1
check-gateway=ping
ip
route add dst-address=0.0.0.0/0 gateway=192.168.3.1 distance=2
check-gateway=ping
ip
route add dst-address=0.0.0.0/0 gateway=192.168.2.1
routing-mark=ke_jalur01 check-gateway=ping
ip
route add dst-address=0.0.0.0/0 gateway=192.168.3.1
routing-mark=ke_jalur02 check-gateway=ping
ip
route add dst-address=0.0.0.0/0 gateway=192.168.2.1 distance=1
check-ateway=ping
ip
route add dst-address=0.0.0.0/0 gateway=192.168.3.1 distance=2
check-gateway=ping
#NAT
ip
firewall nat add chain=srcnat out-interface=wan1 action=masquerade
ip
firewall nat add chain=srcnat out-interface=wan2 action=masquerade
#DHCP
ip
pool add name=dhcp-ether1 ranges=192.168.1.10-192.168.1.254
ip
dhcp-server network add address=192.168.1.0/24 gateway=192.168.1.1
ip
dhcp-server add interface=local address-pool=dhcp-ether1
ip
dhcp-server enable 0

0 komentar:
Posting Komentar