- 192.168.1.1
2. IP Mikrotik:
- 192.168.100.1 = local
- 192.168.1.10 = speedy
3. IP Client: 192.168.100.0/24
/ip firewall nat
add chain=srcnat out-interface=speedy action=masquerade
add chain=dstnat in-interface=local src-address=192.168.100.0/24 protocol=tcp dst-port=80 action=redirect to-ports=3128
/ip firewall mangle
add chain=output out-interface=local dscp=4 action=mark-packet new-packet-mark=proxy-hit passthrough=no comment="HIT TRAFFIC FROM PROXY"
add chain=prerouting in-interface=local src-address=192.168.100.0/24 action=mark-packet new-packet-mark=test-up passthrough=no comment="UP TRAFFIC"
add chain=forward src-address=192.168.100.0/24 action=mark-connection new-connection-mark=test-conn passthrough=yes comment="CONN-MARK"
add chain=forward in-interface=speedy connection-mark=test-conn action=mark-packet new-packet-mark=test-down passthrough=no comment="DOWN-DIRECT CONNECTION"
add chain=output out-interface=local dst-address=192.168.100.0/24 action=mark-packet new-packet-mark=test-down passthrough=no comment="DOWN-VIA PROXY"
/que tree
add name="downstream" parent=local packet-mark=test-down limit-at=32000 queue=default priority=8 max-limit=32000 burst-limit=0 burst-threshold=0 burst-time=0s
add name="upstream" parent=global-in packet-mark=test-up limit-at=32000 queue=default priority=8 max-limit=32000 burst-limit=0 burst-threshold=0 burst-time=0s