我現在有一條中華電信的FTTB線路給的資訊是Gateway=114.67.111.81 mask=255.255.255.240
有台WEB SERVER想用.84這個IP,其他的用.82上網出去,目前我的設定內部的所有電腦可以上網出的去,但是Service的部分進不來,請各位指教一下,謝謝。
以下是我的設定
/ip address
add address=114.67.111.82/28 interface=ether4-FTTB network=114.67.111.80
add address=192.168.12.1/24 interface=ether5-Lan2 network=192.168.12.0
add address=114.67.111.83/28 interface=ether4-FTTB network=114.67.111.80
add address=114.67.111.84/28 interface=ether4-FTTB network=114.67.111.80
add address=114.67.111.85/28 interface=ether4-FTTB network=114.67.111.80
add address=114.67.111.86/28 interface=ether4-FTTB network=114.67.111.80
add address=114.67.111.87/28 interface=ether4-FTTB network=114.67.111.80
add address=114.67.111.88/28 interface=ether4-FTTB network=114.67.111.80
add address=114.67.111.89/28 interface=ether4-FTTB network=114.67.111.80
add address=114.67.111.90/28 interface=ether4-FTTB network=114.67.111.80
add address=114.67.111.91/28 interface=ether4-FTTB network=114.67.111.80
add address=114.67.111.92/28 interface=ether4-FTTB network=114.67.111.80
add address=114.67.111.93/28 interface=ether4-FTTB network=114.67.111.80
add address=114.67.111.94/28 interface=ether4-FTTB network=114.67.111.80
/ip firewall filter
add action=accept chain=input comment=\
"\A4\B9\B3\\21,22,23,80,443,1723,8291 tcp port \B3s\A4J" dst-port=\
21,22,23,80,443,1723,8291 protocol=tcp
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether4-FTTB \
src-address-list=192.168.12.1/24
add action=dst-nat chain=dstnat comment="Webserver Service Ports" \
dst-address=114.67.111.84 dst-port=53 in-interface=ether4-FTTB protocol=\
udp to-addresses=192.168.12.107 to-ports=53
add action=dst-nat chain=dstnat dst-address=114.67.111.84 dst-port=80 \
in-interface=ether4-FTTB protocol=tcp to-addresses=192.168.12.107 \
to-ports=80
add action=dst-nat chain=dstnat dst-address=114.67.111.84 dst-port=443 \
in-interface=ether4-FTTB protocol=tcp to-addresses=192.168.12.107 \
to-ports=443
add action=src-nat chain=srcnat out-interface=ether4-FTTB src-address=\
192.168.12.107 to-addresses=114.67.111.84
add action=src-nat chain=srcnat comment="Lan2 other IP Out by 114.67.111.82" \
out-interface=ether4-FTTB src-address=192.168.12.0/24 to-addresses=\
114.67.111.82
/ip route
add distance=1 gateway=114.67.111.81 pref-src=114.67.111.82
boneyard wrote:您主要的問題在排序,記得"越獨特的項目要越優先執行.
請問各位大大,我現...(恕刪)
/ip firewall nat
add action=masquerade chain=srcnat comment="Nat Loopback" \
dst-address=192.168.12.0/24 src-address=192.168.12.0/24
add action=src-nat chain=srcnat comment="Webserver Service" \
out-interface=ether4-FTTB src-address=192.168.12.107 to-addresses=\
114.67.111.84
add action=src-nat chain=srcnat comment="Other IP Out by 114.67.111.82" \
out-interface=ether4-FTTB to-addresses=114.67.111.82
add action=dst-nat chain=dstnat comment="Webserver Service Ports" \
dst-address=114.67.111.84 dst-port=53 in-interface=ether4-FTTB protocol=\
udp to-addresses=192.168.12.107
add action=dst-nat chain=dstnat dst-address=114.67.111.84 dst-port=80,443 \
in-interface=ether4-FTTB protocol=tcp to-addresses=192.168.12.107
/ip route
add distance=5 gateway=114.67.111.81
為何/ip route的default route ,distance設為"5" ,不設"1"呢?default route的distance設置"1" ,代表中間不能用有比它更優先的route
事事無絕對,保留排序空間給未來未知的route使用比較好.
君不見windows的路由是從"10"開始計算,小弟建議以"5"當起始已經很含蓄了
.

























































































