Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Enterprise Networking Mikrotik Routers (RouterBoard & RouterOS), User and owner discussion group

views
     
ssplayboy
post Jul 7 2018, 02:25 PM

New Member
*
Junior Member
21 posts

Joined: Aug 2006
Any SiFu,

For my side, i got Local, unifi and WAN2 mean got 2 income Internet.
Local: 192.168.18.0/24
unifi:xxxx
WAN2: 192.168.2.1/24

So i want my CCTV ip 192.168.18.254 just only access by unifi connection(dont want WAN2 cnnection because it cannot port forwarding)
got any suggestion on this.
ssplayboy
post Jul 7 2018, 04:46 PM

New Member
*
Junior Member
21 posts

Joined: Aug 2006
QUOTE(soonwai @ Jul 7 2018, 02:34 PM)
Looking at it simply, just port forward from your UniFi to your CCTV. When connecting to the CCTV, ensure that you use the IP address of UniFi.
*
ok, like my WAN2 isp cannot go facebook website, just only Unifi can access it, so how can manage my this PC 192.168.18.101 can use unifi connection?this is my second question. the problem is my pc keep using WAN2 connection blush.gif blush.gif
ssplayboy
post Jul 7 2018, 08:54 PM

New Member
*
Junior Member
21 posts

Joined: Aug 2006
QUOTE(izhamsatria @ Jul 7 2018, 05:24 PM)
You can use Firewall Masquerade to mark the connection to desired line, eg "Only WAN1". You need to use Address Lists for this.
Take a look at this script*, change [WAN2 INTERFACE] according to your setup:

/ip firewall mangle
add action=accept chain=prerouting disabled=no in-interface=pppoe-out1
add action=accept chain=prerouting disabled=no in-interface=[WAN2 INTERFACE]

add action=mark-connection chain=prerouting disabled=no dst-address-type=!local new-connection-mark=wan1_conn passthrough=yes per-connection-classifier=both-addresses:1/0 src-address-list="Only WAN1"
add action=mark-connection chain=prerouting disabled=no dst-address-type=!local new-connection-mark=wan2_conn passthrough=yes per-connection-classifier=both-addresses:1/0 src-address-list="Only WAN2"

add action=mark-routing chain=prerouting connection-mark=wan1_conn disabled=no new-routing-mark=to_wan1 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=wan2_conn disabled=no new-routing-mark=to_wan2 passthrough=yes
/ip firewall nat
add action=masquerade chain=srcnat disabled=no out-interface=pppoe-out1
add action=masquerade chain=srcnat disabled=no out-interface=[WAN2 INTERFACE]

/ip route
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=pppoe-out1 routing-mark=to_wan1 scope=30 target-scope=10
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=[WAN2 INTERFACE] routing-mark=to_wan2 scope=30 target-scope=10
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=pppoe-out1 scope=30 target-scope=10
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=[WAN2 INTERFACE] scope=30 target-scope=10

/ip firewall address-list
add address=192.168.18.1-192.168.18.10 list="Only WAN1"
add address=192.168.18.11-192.168.18.100 list="Only WAN2"
*For your reference only, not tested by me as my setup uses 3 pppoe connection, not 1 pppoe and 1 wan like yours.
*
OKOK, i try now thank Guys thumbup.gif thumbup.gif thumbup.gif

ssplayboy
post Jul 8 2018, 04:06 PM

New Member
*
Junior Member
21 posts

Joined: Aug 2006
QUOTE(izhamsatria @ Jul 7 2018, 05:24 PM)
*
rclxms.gif rclxms.gif rclxms.gif Thank is Work

Another one question is "Only WAN2" modem down, so got script to switch Only WAN2 auto connect to "PPPOE unifi"? like (failover)???

This post has been edited by ssplayboy: Jul 8 2018, 04:12 PM
ssplayboy
post Jul 8 2018, 06:25 PM

New Member
*
Junior Member
21 posts

Joined: Aug 2006
QUOTE(izhamsatria @ Jul 8 2018, 04:57 PM)
I don't think so, since u specify which ip address uses which WAN.
*
oh ok icon_rolleyes.gif
ssplayboy
post Jul 9 2018, 11:20 AM

New Member
*
Junior Member
21 posts

Joined: Aug 2006
[quote=izhamsatria,Jul 9 2018, 12:32 AM]
Wait, I've been thinking. Give this a shot.

Oh, okok
ssplayboy
post Aug 8 2019, 12:44 AM

New Member
*
Junior Member
21 posts

Joined: Aug 2006
will be out a new reply, forget about it.

This post has been edited by ssplayboy: Aug 9 2019, 08:38 AM

 

Change to:
| Lo-Fi Version
0.0228sec    0.77    7 queries    GZIP Disabled
Time is now: 17th December 2025 - 02:14 AM