tuanlm
Senior Member
Mô hình mạng nhà mình
ISP (bridge mod) ---MIKROTIk ---- SWITCH
Các thiết bị khác đều cắm vào switch. Nhà mình có mấy con deco m4
TH1. Deco để mode router thì truy cập bình thường (tuy nhiên DECO nó sẽ cấp IP cho các máy con trong mạng)
TH2. Deco ở mode access point thì hệ thống không ổn định, hay rớt mạng, ko truy cập được ra internet (ping vẫn tới dc mikrotik)
AE ai có kinh nghiệm xử lý giúp trường hợp này ạ. mình có up file cấu hình lên
ISP (bridge mod) ---MIKROTIk ---- SWITCH
Các thiết bị khác đều cắm vào switch. Nhà mình có mấy con deco m4
TH1. Deco để mode router thì truy cập bình thường (tuy nhiên DECO nó sẽ cấp IP cho các máy con trong mạng)
TH2. Deco ở mode access point thì hệ thống không ổn định, hay rớt mạng, ko truy cập được ra internet (ping vẫn tới dc mikrotik)
AE ai có kinh nghiệm xử lý giúp trường hợp này ạ. mình có up file cấu hình lên
/interface bridge
add add-dhcp-option82=yes dhcp-snooping=yes igmp-snooping=yes name=bridgeLAN
/interface pppoe-client
add add-default-route=yes disabled=no interface=ether1 name=pppoe-out1 \
password=Hn66a1 user=t008_gftth_vandth61
/interface list
add name=WAN
add name=LAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=dhcp ranges=192.168.0.50-192.168.0.254
/ip dhcp-server
add address-pool=dhcp disabled=no interface=bridgeLAN name=dhcp1
/queue simple
add max-limit=55M/55M name="Bang thong Internet" queue=default/default \
target=192.168.0.0/24
add name="1.Danh cho Game" packet-marks=Game-Upload,Game-Download parent=\
"Bang thong Internet" priority=1/1 queue=\
pcq-upload-default/pcq-download-default target=192.168.0.0/24
add name="2.Danh cho ICMP-DNS" packet-marks=ICMP-DNS-Upload,ICMP-DNS-Download \
parent="Bang thong Internet" queue=\
pcq-upload-default/pcq-download-default target=192.168.0.0/24
add max-limit=40M/40M name="3.Danh cho Khac" packet-marks=\
Khac-Upload,Khac-Download,Youtube-Upload,Youtube-Download parent=\
"Bang thong Internet" queue=default/default target=192.168.0.0/24
add max-limit=40M/40M name="1.LAN-Danh cho mang LAN" parent="3.Danh cho Khac" \
queue=pcq-upload-default/pcq-download-default target=192.168.0.0/24
/queue tree
add name="Ket noi Internet" parent=global queue=default
add max-limit=55M name=Tai-Xuong parent="Ket noi Internet" queue=\
pcq-download-default
add max-limit=55M name=Tai-Len parent="Ket noi Internet" queue=\
pcq-upload-default
add name="1.GAME Tai-Xuong" packet-mark=Game-Download parent=Tai-Xuong \
priority=1 queue=pcq-download-default
add name="1.Game Tai-Len" packet-mark=Game-Upload parent=Tai-Len priority=1 \
queue=pcq-upload-default
add name="2.ICMP-DNS Tai-Xuong" packet-mark=ICMP-DNS-Download parent=\
Tai-Xuong queue=pcq-download-default
add name="2.ICMP-DNS Tai-Len" packet-mark=ICMP-DNS-Upload parent=Tai-Len \
queue=pcq-upload-default
add max-limit=40M name="3.Khac Tai-Xuong" parent=Tai-Xuong queue=\
pcq-download-default
add max-limit=40M name="3.Khac Tai-Len" parent=Tai-Len queue=\
pcq-upload-default
add limit-at=30M max-limit=35M name="1. Khac Tai-Xuong" packet-mark=\
Khac-Download parent="3.Khac Tai-Xuong" queue=pcq-download-default
add limit-at=30M max-limit=35M name="1.Khac Tai-Len" packet-mark=Khac-Upload \
parent="3.Khac Tai-Len" queue=pcq-upload-default
add limit-at=30M max-limit=35M name="2.Youtube Tai-Xuong" packet-mark=\
Youtube-Download parent="3.Khac Tai-Xuong" priority=3 queue=\
pcq-download-default
add limit-at=30M max-limit=35M name="2.Youtube Tai-Len" packet-mark=\
Youtube-Upload parent="3.Khac Tai-Len" priority=3 queue=\
pcq-upload-default
/interface bridge port
add bridge=bridgeLAN interface=ether2
add bridge=bridgeLAN interface=ether3
add bridge=bridgeLAN interface=ether4
add bridge=bridgeLAN interface=ether5
/interface detect-internet
set detect-interface-list=all internet-interface-list=all lan-interface-list=\
all wan-interface-list=all
/interface list member
add interface=pppoe-out1 list=WAN
add interface=bridgeLAN list=LAN
/interface pptp-server server
set enabled=yes
/ip address
add address=192.168.0.1/24 interface=bridgeLAN network=192.168.0.0
/ip cloud
set ddns-enabled=yes
/ip dhcp-server network
add address=192.168.0.0/24 dns-server=8.8.8.8,8.8.4.4 gateway=192.168.0.1
/ip dns
set servers=8.8.8.8,8.8.4.4
/ip firewall address-list
add address=192.168.0.0/24 list=IP-LAN
/ip firewall mangle
add action=mark-connection chain=prerouting comment="Dich Vu DNS/ICMP" \
dst-address-list=!IP-LAN new-connection-mark=ICMP-DNS passthrough=yes \
protocol=icmp src-address-list=IP-LAN
add action=mark-connection chain=prerouting dst-address-list=!IP-LAN \
dst-port=53 new-connection-mark=ICMP-DNS passthrough=yes protocol=udp \
src-address-list=IP-LAN
add action=mark-packet chain=forward connection-mark=ICMP-DNS in-interface=\
pppoe-out1 new-packet-mark=ICMP-DNS-Download passthrough=no
add action=mark-packet chain=forward connection-mark=ICMP-DNS \
new-packet-mark=ICMP-DNS-Upload out-interface=pppoe-out1 passthrough=no
add action=mark-connection chain=postrouting comment="Game Online" \
dst-address-list=IP-Game new-connection-mark=Ket-noi-Game passthrough=yes \
src-address-list=IP-LAN
add action=mark-packet chain=forward connection-mark=Ket-noi-Game \
in-interface=pppoe-out1 new-packet-mark=Game-Download passthrough=no
add action=mark-packet chain=forward connection-mark=Ket-noi-Game \
new-packet-mark=Game-Upload out-interface=pppoe-out1 passthrough=no
add action=mark-connection chain=postrouting comment=\
"Chuyen ket noi Game > Ket noi thong thuong" connection-rate=200k-100M \
dst-address-list=IP-Game new-connection-mark=Ket-noi-Khac passthrough=yes \
src-address-list=IP-LAN
add action=mark-connection chain=postrouting comment="Dich vu khac" \
dst-address-list=IP-Khac new-connection-mark=Ket-noi-Khac passthrough=yes \
src-address-list=IP-LAN
add action=mark-packet chain=forward connection-mark=Ket-noi-Khac \
in-interface=pppoe-out1 new-packet-mark=Khac-Download passthrough=no
add action=mark-packet chain=forward connection-mark=Ket-noi-Khac \
new-packet-mark=Khac-Upload out-interface=pppoe-out1 passthrough=no
add action=mark-connection chain=postrouting comment="Dich vu Youtube" \
dst-address-list=IP-Youtube new-connection-mark=Ket-noi-Youtube \
passthrough=yes src-address-list=IP-LAN
add action=mark-packet chain=forward connection-mark=Ket-noi-Youtube \
in-interface=pppoe-out1 new-packet-mark=Youtube-Download passthrough=no
add action=mark-packet chain=forward connection-mark=Ket-noi-Youtube \
new-packet-mark=Youtube-Upload out-interface=pppoe-out1 passthrough=no
/ip firewall nat
add action=masquerade chain=srcnat out-interface=pppoe-out1
/ip firewall raw
add action=add-dst-to-address-list address-list=IP-Game address-list-timeout=\
12h chain=prerouting comment=PUBG dst-address-list=!IP-LAN dst-port=\
7889,10012,17500,18081 protocol=tcp src-address-list=IP-LAN
add action=add-dst-to-address-list address-list=IP-Game address-list-timeout=\
12h chain=prerouting dst-address-list=!IP-LAN dst-port=\
8011,9030,10010-10650,11000-14000,17000,20000,20001,20002 protocol=udp \
src-address-list=IP-LAN
add action=add-dst-to-address-list address-list=IP-Game address-list-timeout=\
12h chain=prerouting comment="FREE FIRE" dst-address-list=!IP-LAN \
dst-port=7006,14000,20561,39698,39779,39003 protocol=tcp \
src-address-list=IP-LAN
add action=add-dst-to-address-list address-list=IP-Game address-list-timeout=\
12h chain=prerouting dst-address-list=!IP-LAN dst-port=\
7008,10000-10009,17000 protocol=udp src-address-list=IP-LAN
add action=add-dst-to-address-list address-list=IP-Game address-list-timeout=\
12h chain=prerouting comment="MOBILE LEGENDS" dst-address-list=!IP-LAN \
dst-port=5000-5508,5551-5558,5601-5608,5651-5658,30097-30147,9000-9010 \
protocol=tcp src-address-list=IP-LAN
add action=add-dst-to-address-list address-list=IP-Game address-list-timeout=\
12h chain=prerouting dst-address-list=!IP-LAN dst-port=\
5000-5200,5500-5700,8001,30000-30300,9000-9010 protocol=udp \
src-address-list=IP-LAN
add action=add-dst-to-address-list address-list=IP-Game address-list-timeout=\
12h chain=prerouting dst-address-list=!IP-LAN dst-port=40000-40010 \
protocol=udp src-address-list=IP-LAN
add action=add-dst-to-address-list address-list=IP-Game address-list-timeout=\
12h chain=prerouting comment="AOV (Lien Quan Mobile)" dst-address-list=\
!IP-LAN dst-port=10001-10094 protocol=tcp src-address-list=IP-LAN
add action=add-dst-to-address-list address-list=IP-Game address-list-timeout=\
12h chain=prerouting dst-address-list=!IP-LAN dst-port=\
10101-10201,10080-10110,17000-18000 protocol=udp src-address-list=IP-LAN
add action=add-dst-to-address-list address-list=IP-Game address-list-timeout=\
12h chain=prerouting comment="CALL OF DUTY" dst-address-list=!IP-LAN \
dst-port=3013,18082,65010,65050 protocol=tcp src-address-list=IP-LAN
add action=add-dst-to-address-list address-list=IP-Game address-list-timeout=\
12h chain=prerouting dst-address-list=!IP-LAN dst-port=\
7500-7700,17000-20100 protocol=tcp src-address-list=IP-LAN
add action=add-dst-to-address-list address-list=IP-Khac address-list-timeout=\
12h chain=prerouting comment=Khac dst-address-list=!IP-LAN dst-port=\
80,81,443,8000-8081,21,22,23,81,88,5050,843,182,53 protocol=tcp \
src-address-list=IP-LAN
add action=add-dst-to-address-list address-list=IP-Khac address-list-timeout=\
12h chain=prerouting dst-address-list=!IP-LAN dst-port=\
80,81,443,8000-8081,21,22,23,81,88,5050,843,182,53 protocol=udp \
src-address-list=IP-LAN
add action=add-dst-to-address-list address-list=IP-Youtube \
address-list-timeout=30m chain=prerouting comment=YOUTUBE content=\
googlevideo.com dst-address-list=!IP-LAN src-address-list=IP-LAN
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set ssh disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/ppp secret
add local-address=192.168.0.1 name=tuanlm password=minhtuan remote-address=\
192.168.0.100
/system clock
set time-zone-name=Asia/Bangkok
/system logging
set 2 disabled=yes
add disabled=yes topics=pppoe,ppp,debug
add topics=route,debug,dns
/system ntp client
set enabled=yes primary-ntp=216.239.35.4
/system package update
set channel=long-term
Last edited: