Итак имеем следующую проблему
Сам микротик и компы за ним
микротик 192.168.4.1/22
Комп 192.168.7.7
При трейсе с компа - микротик отзывается звёздочками
Так-же часть маршрутов не работает (не читает таблицу маршрутизации чтобы уходить в туннель на BGP маршруты, вернее уходит частично)
Конфиг маршрутов
Код: Выделить всё
/ip route
add distance=1 routing-mark=ddoser-route-mark type=blackhole
add check-gateway=ping comment=BACKUP distance=1 gateway=06.ISP_06_BACKUP \
routing-mark=route_backup
add check-gateway=ping distance=1 gateway=192.168.2.1 pref-src=192.168.2.2 \
routing-mark=vpn_lv
add distance=1 dst-address=192.168.88.0/24 gateway=03.ISP_03 pref-src=\
192.168.88.1 routing-mark=to_60ghz scope=10
add check-gateway=arp distance=1 gateway=00.pppoe-ISP01 routing-mark=IT39_1
add check-gateway=arp distance=2 gateway=00.pppoe-ISP02 routing-mark=IT39_1
add check-gateway=arp distance=3 gateway=00.pppoe-ISP03 routing-mark=IT39_1
add check-gateway=arp distance=4 gateway=00.pppoe-ISP04 routing-mark=IT39_1
add check-gateway=arp distance=5 gateway=00.pppoe-ISP05 routing-mark=IT39_1
add check-gateway=arp comment=BACKUP distance=6 gateway=06.ISP_06_BACKUP \
routing-mark=IT39_1
add check-gateway=arp distance=1 gateway=00.pppoe-ISP02 routing-mark=IT39_2
add check-gateway=arp distance=2 gateway=00.pppoe-ISP03 routing-mark=IT39_2
add check-gateway=arp distance=3 gateway=00.pppoe-ISP04 routing-mark=IT39_2
add check-gateway=arp distance=4 gateway=00.pppoe-ISP05 routing-mark=IT39_2
add check-gateway=arp distance=5 gateway=00.pppoe-ISP01 routing-mark=IT39_2
add check-gateway=arp comment=BACKUP distance=6 gateway=06.ISP_06_BACKUP \
routing-mark=IT39_2
add check-gateway=arp distance=1 gateway=00.pppoe-ISP03 routing-mark=IT39_3
add check-gateway=arp distance=2 gateway=00.pppoe-ISP04 routing-mark=IT39_3
add check-gateway=arp distance=3 gateway=00.pppoe-ISP05 routing-mark=IT39_3
add check-gateway=arp distance=4 gateway=00.pppoe-ISP01 routing-mark=IT39_3
add check-gateway=arp distance=5 gateway=00.pppoe-ISP02 routing-mark=IT39_3
add check-gateway=arp comment=BACKUP distance=6 gateway=06.ISP_06_BACKUP \
routing-mark=IT39_3
add check-gateway=arp distance=1 gateway=00.pppoe-ISP04 routing-mark=IT39_4
add check-gateway=arp distance=2 gateway=00.pppoe-ISP05 routing-mark=IT39_4
add check-gateway=arp distance=3 gateway=00.pppoe-ISP01 routing-mark=IT39_4
add check-gateway=arp distance=4 gateway=00.pppoe-ISP02 routing-mark=IT39_4
add check-gateway=arp distance=5 gateway=00.pppoe-ISP03 routing-mark=IT39_4
add check-gateway=arp comment=BACKUP distance=6 gateway=06.ISP_06_BACKUP \
routing-mark=IT39_4
add check-gateway=arp distance=1 gateway=00.pppoe-ISP05 routing-mark=IT39_5
add check-gateway=arp distance=2 gateway=00.pppoe-ISP01 routing-mark=IT39_5
add check-gateway=arp distance=3 gateway=00.pppoe-ISP02 routing-mark=IT39_5
add check-gateway=arp distance=4 gateway=00.pppoe-ISP03 routing-mark=IT39_5
add check-gateway=arp distance=5 gateway=00.pppoe-ISP04 routing-mark=IT39_5
add check-gateway=arp comment=BACKUP distance=6 gateway=06.ISP_06_BACKUP \
routing-mark=IT39_5
add distance=1 dst-address=172.30.0.0/22 gateway=WiFi+LAN routing-mark=\
to_client scope=10
add check-gateway=arp distance=1 gateway=00.pppoe-ISP01
add check-gateway=ping distance=1 gateway=00.pppoe-ISP03
add check-gateway=ping distance=1 gateway=00.pppoe-ISP05
add check-gateway=ping distance=1 gateway=00.pppoe-ISP01
add check-gateway=ping distance=1 gateway=00.pppoe-ISP02
add check-gateway=ping distance=1 gateway=06.ISP_06_BACKUP
add check-gateway=arp distance=2 gateway=00.pppoe-ISP02
add check-gateway=arp distance=3 gateway=00.pppoe-ISP05
add check-gateway=arp distance=3 gateway=06.ISP_06_BACKUP
add check-gateway=arp distance=4 gateway=00.pppoe-ISP03
add distance=1 dst-address=149.154.167.220/32 gateway=00.BYPASS_LV
/ip route rule
add action=lookup-only-in-table comment=\
"\D2\E5\EB\E5\E3\E0 \F7\E5\F0\E5\E7 \CB\E0\F2\E2\E8\FE" dst-address=\
149.154.167.220/32 interface=00.BYPASS_LV table=main
add action=lookup-only-in-table routing-mark=route_isp_01 table=IT39_1
add action=lookup-only-in-table routing-mark=route_isp_02 table=IT39_2
add action=lookup-only-in-table routing-mark=route_isp_03 table=IT39_3
add action=lookup-only-in-table routing-mark=route_isp_04 table=IT39_4
add action=lookup-only-in-table routing-mark=route_isp_05 table=IT39_5
add action=drop comment=\
"\C7\E0\EF\F0\E5\F2 \E2 \EE\F1\ED\EE\E2\ED\F3\FE \F1\E5\F2\FC" \
dst-address=172.16.252.0/22 src-address=10.90.90.0/24
add action=drop comment=\
"\C7\E0\EF\F0\E5\F2 \E2 \EE\F1\ED\EE\E2\ED\F3\FE \F1\E5\F2\FC" \
dst-address=172.16.252.0/22 src-address=192.168.0.0/24
add action=drop comment=\
"\C7\E0\EF\F0\E5\F2 \E2 \EE\F1\ED\EE\E2\ED\F3\FE \F1\E5\F2\FC" \
dst-address=172.16.252.0/22 src-address=192.168.4.0/22
add action=drop comment=\
"\C7\E0\EF\F0\E5\F2 \E2 \EE\F1\ED\EE\E2\ED\F3\FE \F1\E5\F2\FC" \
dst-address=172.16.252.0/22 src-address=172.16.1.0/24
add action=drop comment=\
"\C7\E0\EF\F0\E5\F2 \E2 \EE\F1\ED\EE\E2\ED\F3\FE \F1\E5\F2\FC" \
dst-address=172.16.252.0/22 src-address=192.168.88.0/24
add action=drop comment=\
"\C7\E0\EF\F0\E5\F2 \E2 \EE\F1\ED\EE\E2\ED\F3\FE \F1\E5\F2\FC" \
dst-address=172.16.252.0/22 src-address=172.16.30.0/24
add action=drop comment=\
"\C7\E0\EF\F0\E5\F2 \E2 \EE\F1\ED\EE\E2\ED\F3\FE \F1\E5\F2\FC" \
dst-address=172.16.252.0/22 src-address=172.16.251.0/24
Код: Выделить всё
/routing bgp instance
set default as=64577 ignore-as-path-len=yes out-filter=64577-out router-id=\
78.36.201.240
/routing bgp peer
add address-families=ip,ipv6,l2vpn,l2vpn-cisco,vpnv4 hold-time=4m in-filter=\
bgp_in multihop=yes name=Blacklist out-filter=64577-out remote-address=\
192.3.134.152 remote-as=65432 ttl=default
/routing filter
add action=discard chain=64577-out
add action=accept chain=bgp_in comment="\D4\E8\EB\FC\F2\F0 \E4\EB\FF \EE\E1\F5\
\EE\E4\E0 \E1\EB\EE\EA\E8\F0\EE\E2\EE\EA \F7\E5\F0\E5\E7 BGP" \
set-in-nexthop-direct=00.BYPASS_LV
Код: Выделить всё
traceroute 2ip.ru
traceroute to 2ip.ru (195.201.201.32), 64 hops max, 52 byte packets
1 * * *
2 * * *
3 89.201.0.1 (89.201.0.1) 56.687 ms 54.323 ms 54.655 ms
4 * * *
5 78.154.154.165 (78.154.154.165) 54.522 ms 54.344 ms 54.305 ms
6 riga-b1-link.telia.net (213.248.84.32) 54.131 ms 54.232 ms 53.867 ms
7 s-bb4-link.telia.net (62.115.136.78) 63.280 ms 63.141 ms 63.379 ms
8 ffm-bb4-link.telia.net (62.115.138.105) 81.668 ms
ffm-bb3-link.telia.net (62.115.138.237) 90.513 ms 92.133 ms
9 ffm-b4-link.telia.net (62.115.120.6) 104.854 ms
ffm-b4-link.telia.net (62.115.120.0) 86.876 ms
ffm-b4-link.telia.net (62.115.120.6) 81.841 ms
10 hetzner-ic-326013-ffm-b4.c.telia.net (213.248.70.3) 87.360 ms 91.065 ms 81.908 ms
11 core22.fsn1.hetzner.com (213.239.224.245) 97.276 ms
core21.fsn1.hetzner.com (213.239.224.241) 97.506 ms 97.604 ms
12 ex9k1.dc13.fsn1.hetzner.com (213.239.245.242) 94.626 ms 94.843 ms
ex9k1.dc13.fsn1.hetzner.com (213.239.245.238) 98.526 ms
13 node-2ip.barznet.de (188.40.9.67) 94.205 ms 94.085 ms 89.069 ms
14 2ip.ru (195.201.201.32) 99.596 ms 94.458 ms 99.588 ms
Причём, при отправке туда-же speedtest.net - он не реагирует
Где-то намудрил, ибо первый хоп отвечал 192.168.4.1