Привожу почти Ваш пример, делал (показывал) как делать статическую маршрутизацию
через РРТР.
Роутер 1 (192.168.0.1/24) (является РРТР сервером), создан пользователь рртр,
сделан биндинг юзера к интерфейсу, прописана статическая маршрутизация до
удалённой сети 192.168.88.0/24 через данный (биндинг) интерфейс.
(у РРТР статика). Каждый роутер ещё имеет отдельный WAN порт.
(ОБРАЗЕЦ)
Код: Выделить всё
# feb/12/2019 23:46:25 by RouterOS 6.43.11
# software id = AAAAAAAAAA
#
# model = RouterBOARD 931-2nD
# serial number = хххххххххх
/interface bridge
add name=bridge1-LAN
/interface wireless
set [ find default-name=wlan1 ] adaptive-noise-immunity=ap-and-client-mode band=2ghz-g/n country=russia3 distance=indoors frequency=2437 frequency-mode=regulatory-domain max-station-count=8 mode=ap-bridge multicast-helper=disabled rx-chains=0 ssid=\
RT-WiFi_46A0 tx-chains=0 wireless-protocol=802.11 wmm-support=enabled wps-mode=disabled
/interface ethernet
set [ find default-name=ether1 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full comment=WAN
set [ find default-name=ether2 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full comment=LAN
set [ find default-name=ether3 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full comment=TEST
/interface pptp-server
add name=pptp-in1 user=user1
/interface wireless nstreme
set wlan1 enable-polling=no
/interface list
add name=ls0-LAN
add name=ls1-WAN1
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/user group
add name=read-min policy=local,telnet,read,test,winbox,romon,!ssh,!ftp,!reboot,!write,!policy,!password,!web,!sniff,!sensitive,!api,!dude,!tikapp
/interface bridge port
add bridge=bridge1-LAN interface=ether2
/ip firewall connection tracking
set tcp-established-timeout=12h
/ip neighbor discovery-settings
set discover-interface-list=ls0-LAN
/interface list member
add interface=bridge1-LAN list=ls0-LAN
add interface=ether1 list=ls1-WAN1
/interface pptp-server server
set authentication=pap,chap,mschap1,mschap2 enabled=yes
/ip address
add address=1.1.1.2/30 interface=ether1 network=1.1.1.0
add address=192.168.0.1/24 interface=bridge1-LAN network=192.168.0.0
/ip dns
set allow-remote-requests=yes servers=77.88.8.1
/ip firewall address-list
add address=192.168.0.0/24 list=LocalNet
/ip firewall filter
add action=drop chain=input connection-state=invalid in-interface=ether1
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1 src-address-list=LocalNet
/ip firewall service-port
set ftp disabled=yes
set tftp disabled=yes
set irc disabled=yes
set h323 disabled=yes
set sip disabled=yes
set udplite disabled=yes
set dccp disabled=yes
set sctp disabled=yes
/ip route
add check-gateway=ping distance=1 gateway=1.1.1.1
add distance=1 dst-address=192.168.88.0/24 gateway=pptp-in1
/ppp secret
add local-address=10.10.10.1 name=user1 password=user1 remote-address=10.10.10.2
/system clock
set time-zone-autodetect=no time-zone-name=Asia/Kamchatka
/system identity
set name=R1-0-SRV
/system ntp client
set enabled=yes primary-ntp=88.147.254.234 secondary-ntp=88.147.254.232
/system routerboard settings
set auto-upgrade=yes
/tool romon
set enabled=yes id=00:00:00:00:00:01
Роутер 2 (192.168.88.1/24) (является РРТР клиентом), создан пользователь рртр,
прописана статическая маршрутизация до удалённой сети 192.168.0.0/24 через pptp-out1 интерфейс.
(у РРТР статика). Каждый роутер ещё имеет отдельный WAN порт.
(ОБРАЗЕЦ)
Код: Выделить всё
# feb/12/2019 23:51:17 by RouterOS 6.43.11
# software id = BBBBBBBBB
#
# model = RouterBOARD 941-2nD
# serial number = хххххххххххх
/interface bridge
add fast-forward=no name=bridge1-LAN
/interface wireless
set [ find default-name=wlan1 ] ssid=MikroTik
/interface ethernet
set [ find default-name=ether1 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full comment=WAN
set [ find default-name=ether2 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full comment=LAN
set [ find default-name=ether3 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full comment=TEST
set [ find default-name=ether4 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
/interface pptp-client
add connect-to=1.1.1.2 disabled=no name=pptp-out1 password=user1 user=user1
/interface list
add name=ls0-LAN
add name=ls1-WAN1
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/user group
add name=read-min policy=local,telnet,read,test,winbox,romon,!ssh,!ftp,!reboot,!write,!policy,!password,!web,!sniff,!sensitive,!api,!dude,!tikapp
/interface bridge port
add bridge=bridge1-LAN interface=ether2
/ip firewall connection tracking
set tcp-established-timeout=12h
/ip neighbor discovery-settings
set discover-interface-list=ls0-LAN
/interface list member
add interface=bridge1-LAN list=ls0-LAN
add interface=ether1 list=ls1-WAN1
/ip address
add address=192.168.88.1/24 interface=bridge1-LAN network=192.168.88.0
add address=2.2.2.2/30 interface=ether1 network=2.2.2.0
/ip dns
set allow-remote-requests=yes servers=77.88.8.1
/ip firewall address-list
add address=192.168.88.0/24 list=LocalNet
/ip firewall filter
add action=drop chain=input connection-state=invalid in-interface=ether1
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1 src-address-list=LocalNet
/ip route
add distance=1 gateway=2.2.2.1
add check-gateway=ping distance=1 dst-address=192.168.0.0/24 gateway=pptp-out1
/ppp secret
add name=user1 password=user1
/system clock
set time-zone-autodetect=no time-zone-name=Asia/Kamchatka
/system identity
set name=R2-88-CLIENT
/system ntp client
set enabled=yes primary-ntp=88.147.254.234 secondary-ntp=88.147.254.232
/system routerboard settings
set auto-upgrade=yes
/tool romon
set enabled=yes id=00:00:00:00:00:88
Трассерты:
