ot Kalin Sabevski(12-06-2009)
reiting (10)
[ dobre ]
[ zle ]
Variant za otpechatvane Kak da konfigurirame Mikrotik ruter za domashno polzvane
Instaliraite Mikrotik OS na mashina s pone dva fizicheski
interfeisa. Predi da konfigurirate interfeisite proverete
tiahnoto sustoianie i nalichnost, ot menyuto /interface
Primer:
[admin@MikroTik] interface> print
Flags: X - disabled, D - dynamic, R - running
# NAME
TYPE
0 X ether1
ether
1 X ether2
ether
[admin@MikroTik] interface>
Za da mozhe da gi konfigurirate te triabva da sa razresheni,
toest pred tiah da niama znaka „X“. Izpolzvaite komandata
/interface enable „ime“ za da razreshite ili zabranite daden
interfeis, kato „ime“ go zamenete s imeto na vashiia
interfeis. Sushto taka e vuzmozhno razreshavaneto i
zabraniavaneto na interfeisite da stava po tehniia nomer.
Primer:
[admin@MikroTik] interface> print
Flags: X - disabled, D - dynamic, R - running
# NAME
TYPE
0 X ether1
ether
1 X ether2
ether
[admin@MikroTik] interface> enable ether2
[admin@MikroTik] interface> enable 0
[admin@MikroTik] interface> print
Flags: X - disabled, D - dynamic, R - running
# NAME
TYPE
0 R ether1
ether
1 R ether2
ether
[admin@MikroTik] interface>
Imenata na interfeisite mogat da budat smeneni s komandata
/interface set posledvana ot nomera na interfeisa.
Primer:
[admin@MikroTik] interface> set 0 name=Public; set 1
name=Local
[admin@MikroTik] interface> print
Flags: X - disabled, D - dynamic, R - running
# NAME
TYPE
RX-RATE TX-RATE MTU
0 R Public
ether
0 0
1500
1 R Local
ether
0 0
1500
[admin@MikroTik] interface>
V nastoiashtata postanovka shte priemem che
mashinata ima 2 fizicheski interfeisa, kato za purviia
interfeis shte priemem che e svurzan s dostavchika ni na
Internet, a za vtoriia interfeis che e svurzan s lokalnata ni
domashna mrezha. Adresite na interfeisite mogat da budat
dobaveni posredstvom slednite komandi:
Primer:
[admin@MikroTik] ip address> add address 10.0.0.217/24
interface Public
[admin@MikroTik] ip address> add address
192.168.0.254/24 interface Local
[admin@MikroTik] ip address> print
Flags: X - disabled, I - invalid, D - dynamic
# ADDRESS
NETWORK BROADCAST
INTERFACE
0 10.0.0.217/24
10.0.0.217 10.0.0.255
Public
1 192.168.0.254/24 192.168.0.0
192.168.0.255 Local
[admin@MikroTik] ip address>
Sled priklyuchvaneto s dobavianeto na adresi na
suotvetnite interfeisi e neobhodimo da zadadem defult rut za
nashata mrezha posredstvom komandata / ip route add
gateway=x.x.x.x kudeto x.x.x.x e nashiia geituei.
[admin@MikroTik] ip route> add gateway=10.0.0.1
[admin@MikroTik] ip route> print
Flags: X - disabled, I - invalid, D - dynamic, J -
rejected,
C - connect, S - static, R - rip, O - ospf, B - bgp
# DST-ADDRESS
G GATEWAY
DISTANCE INTERFACE
0 ADC 192.168.0.0/24
Local
1 ADC 10.0.0.0/24
Public
2 A S 0.0.0.0/0
r 10.0.0.1 0
Public
[admin@MikroTik] ip route>
I nakraia za da izkarate vashata mrezha prez tozi geituei i
za da imate Internet na lokalniia si interfeis napravete NAT
s komandata /ip firewall nat.
Primer:
[admin@MikroTik] ip firewall nat> add chain=srcnat
action=masquerade
out-interface=Public
[admin@MikroTik] ip firewall nat> print
Flags: X - disabled, I - invalid, D - dynamic
0 chain=srcnat out-interface=Public
action=masquerade
<< Zapoznavane s Tor | Kak da suzdadem Vlan pod FreeBSD >>
|