thiagoeiky
(usa Outra)
Enviado em 09/11/2016 - 07:51h
Muito obrigado pela resposta. Exemplificando o cenário:
Address: Link1 entra na eth1, lan 192.168.0.0/24 (ip da interface 192.168.0.251) eth2, link 2 eth3, rede 10.0.0.0/24 (ip da interface 10.0.0.254) eth4, rede 172.16.0.0/29 (ip da interface 172.16.0.1) eth5.
Firewall: Nat
1° Regra: Action: Accept Chain: dstnat Dst. Address: 172.16.0.0/29
2° Regra: Action: Masquared Chain:srcnat Src. Address: 192.168.0.0/24
2° Regra: Action: Masquared Chain:srcnat Src. Address: 10.0.0.0/24
Mangle
1° Regra: Action: Accept Chain: prerouting src. Address:192.168.0.0/24 Dst. Address: 172.16.0.0/29
2° Regra: Action: Accept Chain: prerouting src. Address:10.0.0.0/24 Dst. Address: 172.16.0.0/29
3°Regra: Action: mark routing Chain: prerouting src. Address: 192.168.0.0/24
4°Regra: Action: mark routing Chain: prerouting src. Address: 10.0.0.0/24
Routes
AS Dst.Address: 0.0.0.0/0 Gateway: Link1 routing-mark: Rede 192.168.0.0/24
AS Dst.Address: 0.0.0.0/0 Gateway: Link1 routing-mark: Rede 10.0.0.0/24
O resto das rotas são as criadas automaticamente pelo Mikrotik.
Como dito, consigo pingar da rede 192.168.0.0/24 na rede 172.16.0.0/29, porém só funciona na interface de rede, ou seja, só pinga no ip 172.16.0.1/29