балансировка mwan3

Discussion in 'Беспроводные технологии/Wi-Fi/Wardriving' started by aka_google, 1 Jul 2017.

  1. aka_google

    aka_google Well-Known Member

    Joined:
    8 Jan 2010
    Messages:
    292
    Likes Received:
    1,842
    Reputations:
    2
    уважаемые помогите разобраться где ошибка , почему не работают wan2 и wan3 ?
    http://prntscr.com/fqg6an
    как видно по скрину траффик идёт только через wan выкладываю конфиги
    конфиг mwan3
    config rule 'https'
    option sticky '1'
    option dest_port '443'
    option proto 'tcp'
    option use_policy 'balanced'

    config policy 'balanced'
    list use_member 'WAN'
    list use_member 'WAN2'
    list use_member 'WAN3'
    option last_resort 'unreachable'

    config rule 'http'
    option dest_port '80'
    option proto 'tcp'
    option sticky '1'
    option timeout '600'
    option use_policy 'balanced'

    config rule 'flylink'
    option dest_port '40000'
    option proto 'tcp'
    option sticky '1'
    option timeout '600'
    option use_policy 'balanced'

    config rule 'torrent'
    option dest_port '31835'
    option proto 'tcp'
    option sticky '1'
    option timeout '600'
    option use_policy 'balanced'

    config rule 'default_rule'
    option dest_ip '0.0.0.0/0'
    option use_policy 'balanced'

    config interface 'wan'
    option enabled '1'
    list track_ip '8.8.4.4'
    list track_ip '8.8.8.8'
    list track_ip '208.67.222.222'
    list track_ip '208.67.220.220'
    option reliability '2'
    option count '1'
    option timeout '2'
    option interval '5'
    option down '3'
    option up '8'

    config interface 'wan2'
    list track_ip '8.8.8.8'
    list track_ip '208.67.220.220'
    option reliability '1'
    option count '1'
    option timeout '2'
    option interval '5'
    option down '3'
    option up '8'
    option enabled '1'

    config interface 'wan3'
    option enabled '1'
    list track_ip '8.8.8.8'
    option reliability '1'
    option count '1'
    option timeout '2'
    option interval '5'
    option down '3'
    option up '3'

    config member 'WAN'
    option interface 'wan'
    option metric '10'
    option weight '2'

    config member 'WAN2'
    option interface 'wan2'
    option metric '20'
    option weight '2'

    config member 'WAN3'
    option interface 'wan3'
    option metric '30'
    option weight '2'
    конфиг network
    config interface 'loopback'
    option ifname 'lo'
    option proto 'static'
    option ipaddr '127.0.0.1'
    option netmask '255.0.0.0'

    config globals 'globals'
    option ula_prefix 'fd1a:ae72:b5e4::/48'

    config interface 'lan'
    option type 'bridge'
    option ifname 'eth1'
    option proto 'static'
    option netmask '255.255.255.0'
    option ip6assign '60'
    option ipaddr '192.168.10.1'
    option gateway '192.168.10.1'

    config interface 'wan'
    option proto 'dhcp'
    option metric '10'
    option ifname 'eth0'

    config switch
    option name 'switch0'
    option reset '1'
    option enable_vlan '1'

    config switch_vlan
    option device 'switch0'
    option vlan '1'
    option vid '1'
    option ports '0 4'

    config switch_vlan
    option device 'switch0'
    option vlan '2'
    option vid '2'
    option ports '5 6'

    config interface 'wan2'
    option proto 'dhcp'
    option metric '20'

    config switch_vlan
    option device 'switch0'
    option vlan '3'
    option vid '3'
    option ports '0t 1'

    config interface 'wan3'
    option proto 'dhcp'
    option ifname 'eth1.3'
    option metric '30'
    конфиг firewall
    config defaults
    option syn_flood '1'
    option input 'ACCEPT'
    option output 'ACCEPT'
    option forward 'REJECT'

    config zone
    option name 'lan'
    option input 'ACCEPT'
    option output 'ACCEPT'
    option forward 'ACCEPT'
    option network 'lan'

    config zone
    option name 'wan'
    option input 'REJECT'
    option output 'ACCEPT'
    option forward 'REJECT'
    option masq '1'
    option mtu_fix '1'
    option network 'wan wan6'

    config rule
    option name 'Allow-DHCP-Renew'
    option src 'wan'
    option proto 'udp'
    option dest_port '68'
    option target 'ACCEPT'
    option family 'ipv4'

    config rule
    option name 'Allow-Ping'
    option src 'wan'
    option proto 'icmp'
    option icmp_type 'echo-request'
    option family 'ipv4'
    option target 'ACCEPT'

    config rule
    option name 'Allow-IGMP'
    option src 'wan'
    option proto 'igmp'
    option family 'ipv4'
    option target 'ACCEPT'

    config rule
    option name 'Allow-DHCPv6'
    option src 'wan'
    option proto 'udp'
    option src_ip 'fc00::/6'
    option dest_ip 'fc00::/6'
    option dest_port '546'
    option family 'ipv6'
    option target 'ACCEPT'

    config rule
    option name 'Allow-MLD'
    option src 'wan'
    option proto 'icmp'
    option src_ip 'fe80::/10'
    list icmp_type '130/0'
    list icmp_type '131/0'
    list icmp_type '132/0'
    list icmp_type '143/0'
    option family 'ipv6'
    option target 'ACCEPT'

    config rule
    option name 'Allow-ICMPv6-Input'
    option src 'wan'
    option proto 'icmp'
    list icmp_type 'echo-request'
    list icmp_type 'echo-reply'
    list icmp_type 'destination-unreachable'
    list icmp_type 'packet-too-big'
    list icmp_type 'time-exceeded'
    list icmp_type 'bad-header'
    list icmp_type 'unknown-header-type'
    list icmp_type 'router-solicitation'
    list icmp_type 'neighbour-solicitation'
    list icmp_type 'router-advertisement'
    list icmp_type 'neighbour-advertisement'
    option limit '1000/sec'
    option family 'ipv6'
    option target 'ACCEPT'

    config rule
    option name 'Allow-ICMPv6-Forward'
    option src 'wan'
    option dest '*'
    option proto 'icmp'
    list icmp_type 'echo-request'
    list icmp_type 'echo-reply'
    list icmp_type 'destination-unreachable'
    list icmp_type 'packet-too-big'
    list icmp_type 'time-exceeded'
    list icmp_type 'bad-header'
    list icmp_type 'unknown-header-type'
    option limit '1000/sec'
    option family 'ipv6'
    option target 'ACCEPT'

    config rule
    option name 'Allow-IPSec-ESP'
    option src 'wan'
    option dest 'lan'
    option proto 'esp'
    option target 'ACCEPT'

    config rule
    option name 'Allow-ISAKMP'
    option src 'wan'
    option dest 'lan'
    option dest_port '500'
    option proto 'udp'
    option target 'ACCEPT'

    config include
    option path '/etc/firewall.user'

    config zone
    option name 'wan2'
    option forward 'REJECT'
    option output 'ACCEPT'
    option network 'wan2'
    option input 'REJECT'
    option masq '1'
    option mtu_fix '1'

    config zone
    option name 'wan3'
    option forward 'REJECT'
    option output 'ACCEPT'
    option network 'wan3'
    option input 'REJECT'
    option masq '1'
    option mtu_fix '1'

    config forwarding
    option dest 'wan'
    option src 'lan'

    config forwarding
    option dest 'wan2'
    option src 'lan'

    config forwarding
    option dest 'wan3'
    option src 'lan'
     
    #1 aka_google, 1 Jul 2017
    Last edited: 1 Jul 2017
  2. aramaz

    aramaz Member

    Joined:
    25 Jan 2016
    Messages:
    46
    Likes Received:
    14
    Reputations:
    0
    http://forum.ixbt.com/topic.cgi?id=14:62202