I setup this configuration for my Dual ISP, and into console can ping 8.8.8.8 sucessfully, but when connect some device to LAN or WiFi, then show that have internet (notification icon in Win 10), but i basically cant open nothing. Whats wrong with my configuration? Some help?
Code: Select all
# 1923-06-24 02:09:31 by RouterOS 7.11beta2
# software id = MGL0-4L4W
#
# model = C53UiG+5HPaxD2HPaxD
# serial number = XXXXXX
/interface bridge
add admin-mac=XXXXXXXXXXX auto-mac=no name=bridge
/interface wifiwave2
# SSID not set
set [ find default-name=wifi1 ] configuration.mode=ap disabled=no
set [ find default-name=wifi2 ] configuration.mode=ap .ssid=MikroTIk-2G \
disabled=no security.authentication-types=wpa-psk,wpa2-psk .encryption=\
ccmp
/interface list
add name=WAN
add name=LAN
/ip pool
add name=dhcp_pool1 ranges=192.168.88.2-192.168.88.254
/ip dhcp-server
add address-pool=dhcp_pool1 interface=bridge name=dhcp1
/routing table
add disabled=no fib name=to_ISP1
add disabled=no fib name=to_ISP2
/interface bridge port
add bridge=bridge ingress-filtering=no interface=ether3
add bridge=bridge ingress-filtering=no interface=ether4
add bridge=bridge ingress-filtering=no interface=ether5
add bridge=bridge ingress-filtering=no interface=wifi1
add bridge=bridge ingress-filtering=no interface=wifi2
/ip settings
set allow-fast-path=no
/interface list member
add interface=bridge list=LAN
add interface=ether1 list=WAN
add interface=ether2 list=WAN
/ip address
add address=192.168.88.1/24 interface=bridge network=192.168.88.0
/ip cloud
set ddns-enabled=yes
/ip dhcp-client
add add-default-route=no interface=ether1 use-peer-dns=no use-peer-ntp=no
add add-default-route=no interface=ether2 use-peer-dns=no use-peer-ntp=no
/ip dhcp-server network
add address=192.168.88.0/24 dns-server=192.168.88.1 gateway=192.168.88.1
/ip dns static
add address=192.168.88.1 name=router.lan
/ip firewall address-list
add address=192.168.88.0/24 list=local
/ip firewall mangle
add action=accept chain=prerouting dst-address-list=local in-interface-list=\
LAN
add action=mark-connection chain=prerouting connection-mark=no-mark \
connection-state=established,related in-interface=ether1 \
new-connection-mark=ISP1_conn passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark \
connection-state=established,related in-interface=ether2 \
new-connection-mark=ISP2_conn passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark \
dst-address-type=!local in-interface-list=LAN new-connection-mark=\
ISP1_conn passthrough=yes per-connection-classifier=\
both-addresses-and-ports:2/0
add action=mark-connection chain=prerouting connection-mark=no-mark \
dst-address-type=!local in-interface-list=LAN new-connection-mark=\
ISP2_conn passthrough=yes per-connection-classifier=\
both-addresses-and-ports:2/1
add action=mark-routing chain=prerouting connection-mark=ISP1_conn \
in-interface-list=LAN new-routing-mark=to_ISP1 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=ISP2_conn \
in-interface-list=LAN new-routing-mark=to_ISP2 passthrough=yes
add action=mark-routing chain=output connection-mark=ISP1_conn \
dst-address-type=!local new-routing-mark=to_ISP1 passthrough=yes
add action=mark-routing chain=output connection-mark=ISP2_conn \
dst-address-type=!local new-routing-mark=to_ISP2 passthrough=yes
/ip firewall nat
add action=masquerade chain=srcnat ipsec-policy=out,none out-interface-list=\
WAN
/ip route
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=\
192.168.1.1 pref-src="" routing-table=to_ISP1 scope=30 \
suppress-hw-offload=no target-scope=10
add check-gateway=ping disabled=no distance=2 dst-address=0.0.0.0/0 gateway=\
192.168.99.1 pref-src="" routing-table=to_ISP2 scope=30 \
suppress-hw-offload=no target-scope=10
add check-gateway=ping disabled=no distance=1 dst-address=8.8.8.8/32 gateway=\
192.168.1.1 routing-table=main scope=10 suppress-hw-offload=no \
target-scope=11
add check-gateway=ping disabled=no distance=2 dst-address=8.8.4.4/32 gateway=\
192.168.99.1 routing-table=main scope=10 suppress-hw-offload=no \
target-scope=11