/ip firewall mangle
add action=mark-connection chain=input comment="Load Balance" disabled=no in-interface=ether3/FM2 new-connection-mark=fm1-cm passthrough=yes
add action=mark-connection chain=input disabled=no in-interface=ether4/FM1 new-connection-mark=fm2-cm passthrough=yes
add action=mark-routing chain=output connection-mark=fm1-cm disabled=no new-routing-mark=via-fm1 passthrough=no
add action=mark-routing chain=output connection-mark=fm2-cm disabled=no new-routing-mark=via-fm2 passthrough=no
add action=mark-connection chain=prerouting disabled=no dst-address-type=!local in-interface=ether2 new-connection-mark=fm1-cm passthrough=yes per-connection-classifier=\
both-addresses-and-ports:2/0
add action=mark-connection chain=prerouting disabled=no dst-address-type=!local in-interface=ether2 new-connection-mark=fm2-cm passthrough=yes per-connection-classifier=\
both-addresses-and-ports:2/1
add action=mark-routing chain=prerouting connection-mark=fm1-cm disabled=no in-interface=ether2 new-routing-mark=via-fm1 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=fm2-cm disabled=no in-interface=ether2 new-routing-mark=via-fm2 passthrough=yes
/ip route
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=111.94.139.1 routing-mark=via-fm1 scope=30 target-scope=10
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=61.247.33.129 routing-mark=via-fm2 scope=30 target-scope=10
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=61.247.33.129 scope=30 target-scope=10
add check-gateway=ping disabled=no distance=2 dst-address=0.0.0.0/0 gateway=111.94.139.1 scope=30 target-scope=10
add disabled=no distance=1 dst-address=110.50.87.0/24 gateway=172.10.10.2 scope=30 target-scope=10
add disabled=no distance=1 dst-address=202.87.254.0/24 gateway=172.10.10.2 scope=30 target-scope=10
add disabled=no distance=1 dst-address=202.87.255.0/24 gateway=172.10.10.2 scope=30 target-scope=10
add disabled=no distance=1 dst-address=202.147.203.0/24 gateway=172.10.10.2 scope=30 target-scope=10
/ip firewall nat
add action=masquerade chain=srcnat disabled=no out-interface=ether4/FM1
add action=masquerade chain=srcnat disabled=no out-interface=ether3/FM2
[rafa@RB750-FM-Distribusi] > ip add pr
Flags: X - disabled, I - invalid, D - dynamic
# ADDRESS NETWORK INTERFACE
0 172.10.10.1/30 172.10.10.0 ether2
1 D 111.94.139.51/24 111.94.139.0 ether3/FM2
2 D 61.247.33.204/25 61.247.33.128 ether4/FM1