Я только что установил один роутер Mikrotik у клиента. Это мой первый опыт работы с этим устройством, поэтому я провёл несколько тестов у нас в офисе с роутером CCR1009-8g-1s-1s+ — всё работало без проблем. Но сегодня, спустя два часа после установки роутера у клиента, мне позвонили и пожаловались, что на некоторых ПК возникли проблемы с подключением. Они получают DHCP-конфигурацию, но, например, не могут выйти в интернет. При попытке пропинговать роутер ситуация очень странная: иногда нет ответа, иногда высокая задержка с потерей пакетов, а иногда после долгого времени отклика пинг становится нормальным без потерь, но с очень большим временем отклика. Создаётся впечатление, что есть проблемы с производительностью, возможно, я что-то пропустил в настройках (копирую их ниже). Пожалуйста, нужна любая подсказка, как исправить ситуацию. Заранее спасибо.
[admin@MikroTik] > export
jul/10/2015 11:26:12 by RouterOS 6.30.2
software id = 2SIC-ZGP8
/interface ethernet
set [ find default-name=ether1 ] name=ether1-gateway
set [ find default-name=ether2 ] name=ether2-master-local
set [ find default-name=ether3 ] master-port=ether2-master-local name=ether3-slave-local
set [ find default-name=ether4 ] master-port=ether2-master-local name=ether4-slave-local
/interface vlan
add interface=ether1-gateway l2mtu=1574 name=vlan3 vlan-id=3
add interface=ether1-gateway l2mtu=1574 name=vlan6 vlan-id=6
/interface pppoe-client
add add-default-route=yes allow=pap,chap default-route-distance=1 disabled=no interface=vlan6 max-mru=1492 max-mtu=1492 name=pppoe-out1 password=adslppp use-peer-dns=yes user=adslppp@telefonicanetpa
/ip pool
add name=dhcp ranges=10.10.2.1-10.10.3.254
add name=vpn ranges=192.168.3.10-192.168.3.20
/ip dhcp-server
add address-pool=dhcp disabled=no interface=ether2-master-local name=dhcp1
/ppp profile
set *FFFFFFFE dns-server=192.168.3.250 local-address=192.168.3.250 remote-address=vpn
/interface pptp-server server
set authentication=mschap2 enabled=yes
/ip address
add address=10.10.1.1/20 interface=ether2-master-local network=10.10.0.0
add address=192.168.100.10/24 interface=ether1-gateway network=192.168.100.0
/ip dhcp-client
add add-default-route=no dhcp-options=hostname,clientid disabled=no interface=vlan3 use-peer-ntp=no
/ip dhcp-server network
add address=10.10.0.0/20 dns-server=10.10.1.1 gateway=10.10.1.1 netmask=20
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=10.10.1.1 name=router
/ip firewall filter
add chain=input comment="default configuration" protocol=icmp
add chain=input comment="default configuration" connection-state=established
add chain=input comment="default configuration" connection-state=related
add chain=input disabled=yes dst-port=23,80 in-interface=pppoe-out1 protocol=tcp
add chain=input dst-port=8291 in-interface=pppoe-out1 protocol=tcp
add chain=input dst-port=1723 in-interface=pppoe-out1 protocol=tcp
add action=drop chain=input comment="default configuration" in-interface=pppoe-out1
add chain=forward comment="default configuration" connection-state=established
add chain=forward comment="default configuration" connection-state=related
add action=drop chain=forward comment="default configuration" connection-state=invalid
/ip firewall mangle
add action=set-priority chain=postrouting new-priority=4 out-interface=vlan3
add action=set-priority chain=postrouting new-priority=1 out-interface=pppoe-out1
/ip firewall nat
add action=masquerade chain=srcnat comment="default configuration" out-interface=pppoe-out1
add action=masquerade chain=srcnat comment="default configuration" out-interface=ether1-gateway
add action=masquerade chain=srcnat comment="default configuration" out-interface=vlan3
add action=dst-nat chain=dstnat disabled=yes dst-port=80 in-interface=pppoe-out1 protocol=tcp to-addresses=192.168.1.125
add action=dst-nat chain=dstnat disabled=yes dst-port=21 in-interface=pppoe-out1 protocol=tcp to-addresses=192.168.1.125
add chain=dstnat dst-address=10.10.1.5 dst-port=554-557 protocol=tcp src-address=192.168.100.10
add chain=dstnat dst-address=10.10.1.2 dst-port=3389 protocol=tcp src-address=192.168.100.10
add chain=dstnat dst-address=10.10.1.2 dst-port=9191 protocol=tcp src-address=192.168.100.10
add chain=dstnat dst-address=10.10.1.9 dst-port=10000-10006 protocol=tcp src-address=192.168.100.10
add chain=dstnat dst-address=10.10.1.2 dst-port=1433 protocol=tcp src-address=192.168.100.10
add chain=dstnat dst-address=10.10.1.4 dst-port=1000 protocol=tcp src-address=192.168.100.10
/ip route
add distance=255 gateway=255.255.255.255
/ip upnp
set enabled=yes
/ip upnp interfaces
add interface=ether2-master-local type=internal
add interface=pppoe-out1 type=external
/routing rip interface
add interface=vlan3 passive=yes receive=v2
/routing rip network
add network=10.0.0.0/8
/system clock
set time-zone-name=Europe/Madrid
/system ntp client
set enabled=yes primary-ntp=163.117.202.33 secondary-ntp=89.248.104.162
/system resource irq rps
set sfp-sfpplus1 disabled=yes
set sfp1 disabled=yes
set ether5 disabled=yes
set ether6 disabled=yes
set ether7 disabled=yes
set ether8 disabled=yes
/system routerboard settings
set cpu-frequency=1000MHz memory-frequency=1066DDR
/tool romon port add
[admin@MikroTik] > export
jul/10/2015 11:26:12 by RouterOS 6.30.2
software id = 2SIC-ZGP8
/interface ethernet
set [ find default-name=ether1 ] name=ether1-gateway
set [ find default-name=ether2 ] name=ether2-master-local
set [ find default-name=ether3 ] master-port=ether2-master-local name=ether3-slave-local
set [ find default-name=ether4 ] master-port=ether2-master-local name=ether4-slave-local
/interface vlan
add interface=ether1-gateway l2mtu=1574 name=vlan3 vlan-id=3
add interface=ether1-gateway l2mtu=1574 name=vlan6 vlan-id=6
/interface pppoe-client
add add-default-route=yes allow=pap,chap default-route-distance=1 disabled=no interface=vlan6 max-mru=1492 max-mtu=1492 name=pppoe-out1 password=adslppp use-peer-dns=yes user=adslppp@telefonicanetpa
/ip pool
add name=dhcp ranges=10.10.2.1-10.10.3.254
add name=vpn ranges=192.168.3.10-192.168.3.20
/ip dhcp-server
add address-pool=dhcp disabled=no interface=ether2-master-local name=dhcp1
/ppp profile
set *FFFFFFFE dns-server=192.168.3.250 local-address=192.168.3.250 remote-address=vpn
/interface pptp-server server
set authentication=mschap2 enabled=yes
/ip address
add address=10.10.1.1/20 interface=ether2-master-local network=10.10.0.0
add address=192.168.100.10/24 interface=ether1-gateway network=192.168.100.0
/ip dhcp-client
add add-default-route=no dhcp-options=hostname,clientid disabled=no interface=vlan3 use-peer-ntp=no
/ip dhcp-server network
add address=10.10.0.0/20 dns-server=10.10.1.1 gateway=10.10.1.1 netmask=20
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=10.10.1.1 name=router
/ip firewall filter
add chain=input comment="default configuration" protocol=icmp
add chain=input comment="default configuration" connection-state=established
add chain=input comment="default configuration" connection-state=related
add chain=input disabled=yes dst-port=23,80 in-interface=pppoe-out1 protocol=tcp
add chain=input dst-port=8291 in-interface=pppoe-out1 protocol=tcp
add chain=input dst-port=1723 in-interface=pppoe-out1 protocol=tcp
add action=drop chain=input comment="default configuration" in-interface=pppoe-out1
add chain=forward comment="default configuration" connection-state=established
add chain=forward comment="default configuration" connection-state=related
add action=drop chain=forward comment="default configuration" connection-state=invalid
/ip firewall mangle
add action=set-priority chain=postrouting new-priority=4 out-interface=vlan3
add action=set-priority chain=postrouting new-priority=1 out-interface=pppoe-out1
/ip firewall nat
add action=masquerade chain=srcnat comment="default configuration" out-interface=pppoe-out1
add action=masquerade chain=srcnat comment="default configuration" out-interface=ether1-gateway
add action=masquerade chain=srcnat comment="default configuration" out-interface=vlan3
add action=dst-nat chain=dstnat disabled=yes dst-port=80 in-interface=pppoe-out1 protocol=tcp to-addresses=192.168.1.125
add action=dst-nat chain=dstnat disabled=yes dst-port=21 in-interface=pppoe-out1 protocol=tcp to-addresses=192.168.1.125
add chain=dstnat dst-address=10.10.1.5 dst-port=554-557 protocol=tcp src-address=192.168.100.10
add chain=dstnat dst-address=10.10.1.2 dst-port=3389 protocol=tcp src-address=192.168.100.10
add chain=dstnat dst-address=10.10.1.2 dst-port=9191 protocol=tcp src-address=192.168.100.10
add chain=dstnat dst-address=10.10.1.9 dst-port=10000-10006 protocol=tcp src-address=192.168.100.10
add chain=dstnat dst-address=10.10.1.2 dst-port=1433 protocol=tcp src-address=192.168.100.10
add chain=dstnat dst-address=10.10.1.4 dst-port=1000 protocol=tcp src-address=192.168.100.10
/ip route
add distance=255 gateway=255.255.255.255
/ip upnp
set enabled=yes
/ip upnp interfaces
add interface=ether2-master-local type=internal
add interface=pppoe-out1 type=external
/routing rip interface
add interface=vlan3 passive=yes receive=v2
/routing rip network
add network=10.0.0.0/8
/system clock
set time-zone-name=Europe/Madrid
/system ntp client
set enabled=yes primary-ntp=163.117.202.33 secondary-ntp=89.248.104.162
/system resource irq rps
set sfp-sfpplus1 disabled=yes
set sfp1 disabled=yes
set ether5 disabled=yes
set ether6 disabled=yes
set ether7 disabled=yes
set ether8 disabled=yes
/system routerboard settings
set cpu-frequency=1000MHz memory-frequency=1066DDR
/tool romon port add