RouterOS的Fasttrack,可以极大的减少ROS的CPU使用率以及增加带宽!
原文:
https://wiki.mikrotik.com/wiki/Manual:IP/Fasttrack
需要兩條命令來執(zhí)行:
/ip firewall filter add chain=forward action=fasttrack-connection connection-state=established,related /ip firewall filter add chain=forward action=accept connection-state=established,related
描述
IPv4 FastTrack處理程序自動(dòng)用于標(biāo)記的連接。使用防火墻操作“ fasttrack-connection”來標(biāo)記FastTrack的連接。當(dāng)前,只有TCP和UDP連接實(shí)際上可以被快速跟蹤(即使可以將任何連接標(biāo)記為快速跟蹤)。IPv4 FastTrack處理程序支持NAT(SNAT和/或DNAT)。
請(qǐng)注意,并非連接中的所有數(shù)據(jù)包都可以被FastTracked,因此即使將連接標(biāo)記為FastTrack,也有可能看到某些數(shù)據(jù)包通過慢速路徑。這就是為什么快速跟蹤連接通常遵循相同的action = accept規(guī)則的原因。FastTracked數(shù)據(jù)包繞過防火墻,連接跟蹤,簡(jiǎn)單隊(duì)列,parent = global的隊(duì)列樹,IP流量(在6.33中取消了限制),IP accounting,IPSec,熱點(diǎn)通用客戶端,VRF分配,因此管理員應(yīng)確保FastTrack不干擾其他配置;
要求
如果滿足以下條件,則IPv4 FastTrack處于活動(dòng)狀態(tài):
沒有網(wǎng)狀,元路由器接口配置;
sniffer,torchandtraffic generatoris not running;
沒有活動(dòng)的mac-ping,mac-telnet或mac-winbox會(huì)話限制已在6.33中刪除;
/ tool mac-scan沒有被積極使用;
/ tool ip-scan沒有被積極使用;
在IP /Settings 下啟用了FastPath和路由緩存
Supported hardware
FastTrack is supported on the listed devices.
| RouterBoard | Interfaces |
|---|---|
| RB6xx series | ether1,2 |
| RB7xx series | all ports |
| RB800 | ether1,2 |
| RB9xx series | all ports |
| RB1000 | all ports |
| RB1100, RB1000AHx2 | ether1-11 |
| RB1000AHx2 | all ports |
| RB2011 series | all ports |
| RB3011 series | all ports |
| RB4011 series | all ports |
| CRS series routers | all ports except management interface (if the device has one) |
| CCR series routers | all ports except management interface (if the device has one) |
| All devices | wireless interfaces, if wireless-fp, wireless-cm2, wireless-rep or wireless (starting from 6.37) package used |
Examples
Initial configuration
For example, in home routers with factory default configuration, you could FastTrack all LAN traffic with this one rule placed at the top of the Firewall Filter. The same configuration accept rule is required:
/ip firewall filter add chain=forward action=fasttrack-connection connection-state=established,related /ip firewall filter add chain=forward action=accept connection-state=established,related
View of simple FastTrack rules in the firewall, it is important to have other filter or mangle rules to get the advantage of the FastTrack:
/ip firewall filter
/ip firewall mangle
Warning:Queues (except Queue Trees parented to interfaces), firewall filter and mangle rules will not be applied for FastTracked traffic.
Connection is FastTracked until connection is closed, timed-out or router is rebooted.
Dummy rules will dissapear only after FastTrack firewall rules will be deleted/disabled and router rebooted.
FastTrack on RB2011
FastTrack is enabled on RB2011 at chain=forward with the rule from previous example. Bandwidth test with single TCP stream is sent,
總結(jié)
以上是生活随笔為你收集整理的RouterOS的Fasttrack,可以极大的减少ROS的CPU使用率以及增加带宽!的全部?jī)?nèi)容,希望文章能夠幫你解決所遇到的問題。
- 上一篇: 机器学习实战(九)树回归
- 下一篇: 360公布财报:安全业务实现营业收入约1