이런구성 직관적이고 저렴하고 쓸만합니다.
DHCP를 하나만 두는게 중요합니다.
장비별로, 사람별로 IP랑 게이트웨이 골라서 세팅하면 됩니다.
DHCP돌아가는 공유기가 공용공유기가 되겠죠.
모두가 10G로 연결되고 공유기 골라쓰면 되고 자유로워요.
뭐하나 고장나도 대응하기 수월합니다.
다만 직원이 늘어나면 권장하지않아요.
공부하는거 좋아하시면 공유기 3개를 미크로틱 라우터 하나로 교체하셔도 좋습니다.
1G 3개 NAT로 돌리려면 공유기도 많이 비싸져요.
모냥은 좀 빠지지만 1G 지원하는 공유 3개가 훨 쌉니다. 그리고 쉬워요.
¶ÇÇÑ °øÀ¯±â 3°³¸¦ ¹ÌÅ©·Îƽ Çϳª·Î ´ëü´Â ¾î¶»°Ô Çϴ°ɱî¿ä?? ¤¾¤¾¤¾
ÀÌ·±°Ç ¾îµð¼ ¾î¶»°Ô ¹è¿ï ¼ö ÀÖ´ÂÁö, ¹°¾îº¼µ¥µµ ¸¶¶¥Âú´øµ¥ °¡¸£Ä§À» ¹Þ°í ½Í½À´Ï´Ù! ¤Ð¤Ð
-> º¹ÀâÇÏÀݾƿä. ¾²´Â»ç¶÷ÀÌ ¾Ë¾Æ¼ °ÔÀÌÆ®¿þÀ̸¦ °ñ¶ó¾²´Â°Ç 10¸í¾ÈÂʱîÁö¶ó°íºÁ¿ä. ÀÌ·¡Àú·¡ ºÒÆíÇÏÁÒ.¼ºê³ÝÀº ¹¹. cŬ·¡½º ºÎÁ·ÇÒÁ¤µµ¸é Àü»ê°ü¸®ÀÚ ÇÑ¸í »Ì¾Æ¾ßÁÒ.
¶ÇÇÑ °øÀ¯±â 3°³¸¦ ¹ÌÅ©·Îƽ Çϳª·Î ´ëü´Â ¾î¶»°Ô Çϴ°ɱî¿ä?? ¤¾¤¾¤¾
-> chatgpt ¸¸¼¼ÀÔ´Ï´Ù.
CCR2004-16G-2S+ ¿¡ 1G ÀÎÅͳÝȸ¼± 3°³¸¦ 1,2,3¹ø Æ÷Æ®¿¡ ¿¬°áÇß¾î.
ù¹ø° SPF+ ¸¦ ³»ºÎ¸Á¿ë ½ºÀ§Ä¡¿¡ ¿¬°áÇß¾î.
NAT¿Í ·Îµå¹ë·±¼ ¼³Á¤ÇØÁà.
ChatGPTÀÇ ¸»:
¸Þ¸ð¸® ¾÷µ¥ÀÌÆ®µÊ
ÁÁ½À´Ï´Ù! MikroTik CCR2004-16G-2S+ Àåºñ¿¡¼:
ether1, ether2, ether3: °¢°¢ 1Gbps ÀÎÅÍ³Ý È¸¼±
sfp-sfpplus1: ³»ºÎ¸Á ½ºÀ§Ä¡ ¿¬°á
À̶ó´Â ±¸¼ºÀ» ±âÁØÀ¸·Î, **NAT + 3¶óÀÎ ·Îµå¹ë·±½Ì(ECMP ¹æ½Ä)**À» CLI·Î ¼³Á¤Çص帱°Ô¿ä.
✅ 1. ÀÎÅÍÆäÀ̽º À̸§ È®ÀÎ (Áß¿ä!)
¸ÕÀú ½ÇÁ¦ ÀÎÅÍÆäÀ̽º À̸§À» È®ÀÎÇϼ¼¿ä:
bash
º¹»ç
ÆíÁý
/interface print
º¸ÅëÀº ´ÙÀ½°ú °°ÀÌ µÇ¾î ÀÖÀ» °Ì´Ï´Ù:
ether1: ISP1
ether2: ISP2
ether3: ISP3
sfp-sfpplus1: ³»ºÎ¸Á
✅ 2. ±âº» ¼³Á¤ Áغñ
³»ºÎ¸Á: 192.168.88.0/24, °ÔÀÌÆ®¿þÀÌ: 192.168.88.1
bash
º¹»ç
ÆíÁý
/ip address
add address=192.168.88.1/24 interface=sfp-sfpplus1 comment="LAN"
✅ 3. ÀÎÅÍ³Ý È¸¼±º° IP ¼³Á¤ (¿¹½Ã)
bash
º¹»ç
ÆíÁý
/ip address
add address=1.1.1.2/24 interface=ether1 comment="ISP1"
add address=2.2.2.2/24 interface=ether2 comment="ISP2"
add address=3.3.3.2/24 interface=ether3 comment="ISP3"
✅ 4. ECMP ±â¹Ý ·Îµå¹ë·±½Ì ±âº» °æ·Î ¼³Á¤
bash
º¹»ç
ÆíÁý
/ip route
add dst-address=0.0.0.0/0 gateway=1.1.1.1,2.2.2.1,3.3.3.1
°¢ ISPÀÇ °ÔÀÌÆ®¿þÀÌ ÁÖ¼Ò¿¡ ¸ÂÃç¼ ¼öÁ¤ ÇÊ¿ä
✅ 5. NAT (masquerade) ¼³Á¤ - °¢°¢ÀÇ ÀÎÅÍ³Ý È¸¼±¿¡ ´ëÇØ
bash
º¹»ç
ÆíÁý
/ip firewall nat
add chain=srcnat out-interface=ether1 action=masquerade
add chain=srcnat out-interface=ether2 action=masquerade
add chain=srcnat out-interface=ether3 action=masquerade
✅ 6. Ä¿³Ø¼Ç ÃßÀû Æ©´× (ECMP¿¡¼ Áß¿äÇÑ ¼³Á¤)
bash
º¹»ç
ÆíÁý
/ip firewall mangle
add chain=prerouting connection-mark=no-mark in-interface=sfp-sfpplus1 \
action=mark-connection new-connection-mark=ISP1_conn passthrough=yes \
per-connection-classifier=both-addresses:3/0
add chain=prerouting connection-mark=no-mark in-interface=sfp-sfpplus1 \
action=mark-connection new-connection-mark=ISP2_conn passthrough=yes \
per-connection-classifier=both-addresses:3/1
add chain=prerouting connection-mark=no-mark in-interface=sfp-sfpplus1 \
action=mark-connection new-connection-mark=ISP3_conn passthrough=yes \
per-connection-classifier=both-addresses:3/2
/ip firewall mangle
add chain=prerouting connection-mark=ISP1_conn in-interface=sfp-sfpplus1 \
action=mark-routing new-routing-mark=to_ISP1 passthrough=yes
add chain=prerouting connection-mark=ISP2_conn in-interface=sfp-sfpplus1 \
action=mark-routing new-routing-mark=to_ISP2 passthrough=yes
add chain=prerouting connection-mark=ISP3_conn in-interface=sfp-sfpplus1 \
action=mark-routing new-routing-mark=to_ISP3 passthrough=yes
✅ 7. ¸¶Å©µÈ ¶ó¿ìÆà Å×ÀÌºí º°µµ °æ·Î ¼³Á¤
bash
º¹»ç
ÆíÁý
/ip route
add dst-address=0.0.0.0/0 gateway=1.1.1.1 routing-mark=to_ISP1
add dst-address=0.0.0.0/0 gateway=2.2.2.1 routing-mark=to_ISP2
add dst-address=0.0.0.0/0 gateway=3.3.3.1 routing-mark=to_ISP3
✅ 8. DNS ¹× NAT È®ÀÎ
bash
º¹»ç
ÆíÁý
/ip dns set servers=8.8.8.8,1.1.1.1 allow-remote-requests=yes
Á¦°¡ ¾Æ´Â Áö½Ä »óÀ¸·Ð µ¿ÀÏ ±¸¼ºÀº ºÒ°¡ÇÒ °Í °°¾Æ¼¿ä,,, ³»ºÎ¸Á ´ë¿ª¿¡¼ °ÔÀÌÆ®¿þÀÌ·Î ¾µ ¾ÆÀÌÇÇ°¡ ³ª´µÁö ¾ÊÀ¸´Ï...
Á¤µµ ÃëµæÇÏ½Ã¸é ¾î´À Á¤µµ ¾Ë°Ô µÇ°í ±× ´ÙÀ½Àº °ÅÀÇ ´Ù ½ÇÀüÀÔ´Ï´Ù..