Ну не знаю откуда у меня руки растут. Но вот конфигурация которая сейчас в роутере:
Код: Выделить всё
[admin@MikroTik] > ip firewall nat print
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; default configuration
chain=srcnat action=masquerade to-addresses=0.0.0.0 out-interface=ether1-gatew
1 chain=srcnat action=masquerade out-interface=ether5-gaterway
2 chain=dstnat action=dst-nat to-addresses=10.0.0.1 protocol=tcp
in-interface=ether1-gateway dst-port=10123
3 chain=dstnat action=dst-nat to-addresses=10.0.0.1 protocol=udp
in-interface=ether1-gateway dst-port=10122
4 chain=dstnat action=dst-nat to-addresses=10.0.0.1 protocol=tcp
in-interface=ether5-gaterway dst-port=10123 out-bridge-port=ether5-gaterway
5 chain=dstnat action=dst-nat to-addresses=10.0.0.1 protocol=udp
in-interface=ether5-gaterway dst-port=10122
6 chain=dstnat action=dst-nat to-addresses=10.0.0.2 protocol=tcp
in-interface=ether1-gateway dst-port=6130
7 chain=dstnat action=dst-nat to-addresses=10.0.0.2 protocol=tcp
in-interface=ether5-gaterway dst-port=6130
8 chain=dstnat action=dst-nat to-addresses=10.0.0.1 to-ports=6130 protocol=tcp
in-interface=ether5-gaterway dst-port=6131
9 chain=dstnat action=dst-nat to-addresses=10.0.0.1 to-ports=6130 protocol=tcp
in-interface=ether1-gateway dst-port=6131
Код: Выделить всё
[admin@MikroTik] > /ip firewall mangle print
Flags: X - disabled, I - invalid, D - dynamic
0 chain=input action=mark-connection new-connection-mark=IS-input passthrough=no
in-interface=ether1-gateway
1 chain=input action=mark-connection new-connection-mark=RT-input passthrough=no
in-interface=ether5-gaterway
2 chain=prerouting action=mark-routing new-routing-mark=RT passthrough=no
src-address=10.0.0.1 connection-mark=RT-input
3 chain=prerouting action=mark-routing new-routing-mark=IS passthrough=no
src-address=10.0.0.1 connection-mark=IS-input
4 chain=forward action=mark-connection new-connection-mark=IS-input passthrough=no
in-interface=ether1-gateway
5 chain=forward action=mark-connection new-connection-mark=RT-input passthrough=no
in-interface=ether5-gaterway
6 chain=output action=mark-routing new-routing-mark=IS passthrough=no
connection-mark=IS-input
7 chain=output action=mark-routing new-routing-mark=RT passthrough=no
connection-mark=RT-input
Код: Выделить всё
[admin@MikroTik] > ip route print detail
Flags: X - disabled, A - active, D - dynamic,
C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme,
B - blackhole, U - unreachable, P - prohibit
0 A S dst-address=0.0.0.0/0 gateway=192.168.1.1
gateway-status=192.168.1.1 reachable via ether1-gateway check-gateway=ping
distance=1 scope=30 target-scope=10 routing-mark=IS
1 A S dst-address=0.0.0.0/0 gateway=192.168.2.1
gateway-status=192.168.2.1 reachable via ether5-gaterway check-gateway=ping
distance=1 scope=30 target-scope=10 routing-mark=RT
2 A S dst-address=0.0.0.0/0 gateway=192.168.1.1
gateway-status=192.168.1.1 reachable via ether1-gateway check-gateway=ping
distance=1 scope=30 target-scope=10
3 ADC dst-address=10.0.0.0/24 pref-src=10.0.0.100 gateway=ether2-master-local
gateway-status=ether2-master-local reachable distance=0 scope=10
4 ADC dst-address=192.168.1.0/24 pref-src=192.168.1.2 gateway=ether1-gateway
gateway-status=ether1-gateway reachable distance=0 scope=10
5 ADC dst-address=192.168.2.0/24 pref-src=192.168.2.2 gateway=ether5-gaterway
gateway-status=ether5-gaterway reachable distance=0 scope=10
6 ADC dst-address=192.168.88.0/24 pref-src=192.168.88.1 gateway=ether2-master-loc
gateway-status=ether2-master-local reachable distance=0 scope=10
7 X S dst-address=233.3.2.0/24 gateway=192.168.2.1 gateway-status=192.168.2.1 ina
check-gateway=ping distance=1 scope=30 target-scope=10
Всё идет в согласовании с Вашими инструкциями