{"id":706,"date":"2026-09-16T17:19:15","date_gmt":"2026-09-16T14:19:15","guid":{"rendered":"https:\/\/imaxis.ru\/?p=706"},"modified":"2026-09-16T17:36:44","modified_gmt":"2026-09-16T14:36:44","slug":"dscp-mangle-vpn-mikrotik","status":"publish","type":"post","link":"https:\/\/imaxis.ru\/?p=706","title":{"rendered":"\u041a\u0430\u043a \u043f\u043e\u043c\u0435\u0442\u0438\u0442\u044c DSCP \u0442\u0440\u0430\u0444\u0438\u043a \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u043e\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0432 Windows \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u0435\u0433\u043e \u0432 VPN \u0447\u0435\u0440\u0435\u0437 mangle \u043d\u0430 Mikrotik"},"content":{"rendered":"<h1>\u041a\u0430\u043a \u043f\u043e\u043c\u0435\u0442\u0438\u0442\u044c DSCP \u0442\u0440\u0430\u0444\u0438\u043a \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u043e\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0432 Windows \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u0435\u0433\u043e \u0432 VPN \u0447\u0435\u0440\u0435\u0437 mangle \u043d\u0430 Mikrotik<\/h1>\n<p>\u0418\u043d\u043e\u0433\u0434\u0430 \u043d\u0443\u0436\u043d\u043e, \u0447\u0442\u043e\u0431\u044b \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u043e\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, 1\u0421, \u0432\u0438\u0434\u0435\u043e\u0437\u0432\u043e\u043d\u043a\u0438 \u0438\u043b\u0438 \u043e\u0431\u043b\u0430\u0447\u043d\u044b\u0439 \u043a\u043b\u0438\u0435\u043d\u0442) \u0445\u043e\u0434\u0438\u043b\u043e \u043d\u0435 \u0447\u0435\u0440\u0435\u0437 \u043e\u0431\u044b\u0447\u043d\u044b\u0439 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442, \u0430 \u0447\u0435\u0440\u0435\u0437 VPN-\u0442\u0443\u043d\u043d\u0435\u043b\u044c. \u041f\u0440\u043e\u0441\u0442\u043e \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u00ab\u0432 \u0442\u0443\u043d\u043d\u0435\u043b\u0435\u00bb \u0441\u043b\u043e\u0436\u043d\u043e \u2014 \u0432 Windows \u043d\u0435\u0442 \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u043e\u0433\u043e \u0441\u043f\u043e\u0441\u043e\u0431\u0430 \u043f\u0440\u0438\u0432\u044f\u0437\u0430\u0442\u044c \u0437\u0430\u043f\u0443\u0441\u043a exe \u043a \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0443. \u0420\u0435\u0448\u0435\u043d\u0438\u0435 \u2014 \u0441\u0432\u044f\u0437\u043a\u0430 \u0438\u0437 \u0434\u0432\u0443\u0445 \u0448\u0430\u0433\u043e\u0432:<\/p>\n<ol>\n<li><strong>Windows<\/strong>: \u043f\u043e\u043c\u0435\u0442\u0438\u0442\u044c \u043f\u0430\u043a\u0435\u0442\u044b \u043d\u0443\u0436\u043d\u043e\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u043c\u0435\u0442\u043a\u043e\u0439 DSCP (QoS-\u043c\u0435\u0442\u043a\u043e\u0439).<\/li>\n<li><strong>Mikrotik<\/strong>: \u043f\u043e DSCP-\u043c\u0435\u0442\u043a\u0435 \u0447\u0435\u0440\u0435\u0437 mangle \u043f\u043e\u043c\u0435\u0442\u0438\u0442\u044c \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u0438\u0445 \u0432 VPN-\u0442\u0443\u043d\u043d\u0435\u043b\u044c.<\/li>\n<\/ol>\n<p>DSCP \u2014 \u043f\u043e\u043b\u0435 \u0432 IP-\u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0435 (6 \u0431\u0438\u0442). Windows \u0443\u043c\u0435\u0435\u0442 \u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0435\u0433\u043e \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 QoS Policy. Mikrotik \u0443\u043c\u0435\u0435\u0442 \u0435\u0433\u043e \u0447\u0438\u0442\u0430\u0442\u044c \u0438 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043f\u043e \u043d\u0435\u043c\u0443. \u041d\u0438\u0436\u0435 \u2014 \u043f\u043e\u043b\u043d\u0430\u044f \u0440\u0430\u0431\u043e\u0447\u0430\u044f \u0441\u0445\u0435\u043c\u0430.<\/p>\n<hr \/>\n<h2>\u0427\u0430\u0441\u0442\u044c 1. Windows: \u0441\u0442\u0430\u0432\u0438\u043c DSCP-\u043c\u0435\u0442\u043a\u0443 \u043d\u0430 \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u043e\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435<\/h2>\n<h3>\u0421\u043f\u043e\u0441\u043e\u0431 A. \u041f\u043e\u043b\u0438\u0442\u0438\u043a\u0430 QoS \u0447\u0435\u0440\u0435\u0437 gpedit (\u043d\u0430\u0433\u043b\u044f\u0434\u043d\u044b\u0439)<\/h3>\n<p>\u041e\u0442\u043a\u0440\u043e\u0439\u0442\u0435 <code>gpedit.msc<\/code> \u0438 \u043f\u0435\u0440\u0435\u0439\u0434\u0438\u0442\u0435:<\/p>\n<pre><code>\u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u0430 \u2192 \u0410\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u0438\u0432\u043d\u044b\u0435 \u0448\u0430\u0431\u043b\u043e\u043d\u044b \u2192 \u0421\u0435\u0442\u044c \u2192 QoS Packet Scheduler \u2192 \u041f\u043e\u043b\u0438\u0442\u0438\u043a\u0430 \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 QoS\n<\/code><\/pre>\n<p>\u041d\u0430\u0436\u043c\u0438\u0442\u0435 <strong>\u0421\u043e\u0437\u0434\u0430\u0442\u044c \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0443<\/strong> \u0438 \u0437\u0430\u043f\u043e\u043b\u043d\u0438\u0442\u0435:<\/p>\n<ul>\n<li>\u0418\u043c\u044f: \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440 <code>VPN-1C<\/code><\/li>\n<li>DSCP-\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435: <strong>46<\/strong> (\u0438\u043b\u0438 56\/40 \u2014 \u0441\u043c. \u0442\u0430\u0431\u043b\u0438\u0446\u0443 \u043d\u0438\u0436\u0435)<\/li>\n<li>\u041f\u0440\u0438\u043c\u0435\u043d\u044f\u0442\u044c \u043a: <strong>\u0422\u043e\u043b\u044c\u043a\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u043c \u0441 \u0438\u043c\u0435\u043d\u0435\u043c<\/strong> \u2192 <code>1cv8.exe<\/code><\/li>\n<li>\u041f\u0440\u043e\u0442\u043e\u043a\u043e\u043b: <strong>TCP \u0438 UDP<\/strong><\/li>\n<li>\u0423\u043a\u0430\u0436\u0438\u0442\u0435 \u043f\u043e\u0440\u0442 \u0438\u043b\u0438 \u043e\u0441\u0442\u0430\u0432\u044c\u0442\u0435 \u00ab\u041b\u044e\u0431\u043e\u0439\u00bb.<\/li>\n<\/ul>\n<p>\u041f\u0440\u0438\u043c\u0435\u043d\u0438\u0442\u0435 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0443 \u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u0435 \u0432 \u043a\u043e\u043d\u0441\u043e\u043b\u0438 <code>gpupdate \/force<\/code>.<\/p>\n<blockquote><p><strong>\u0412\u0430\u0436\u043d\u043e:<\/strong> gpedit \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 Windows Pro\/Enterprise. \u0412 Home \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0439\u0442\u0435 \u0441\u043f\u043e\u0441\u043e\u0431 B.<\/p><\/blockquote>\n<h3>\u0421\u043f\u043e\u0441\u043e\u0431 B. \u0427\u0435\u0440\u0435\u0437 \u0440\u0435\u0435\u0441\u0442\u0440 \u0438\u043b\u0438 PowerShell (Windows Home)<\/h3>\n<p>DSCP \u0442\u0430\u043a\u0436\u0435 \u043c\u043e\u0436\u043d\u043e \u0437\u0430\u0434\u0430\u0442\u044c \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u043e\u0439 QoS \u0447\u0435\u0440\u0435\u0437 \u0440\u0435\u0435\u0441\u0442\u0440. \u0421\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u043a\u043b\u044e\u0447 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0438:<\/p>\n<pre><code class=\"language-powershell\">$policyName = \"VPN-App-DSCP-46\"\n$policyPath = \"HKLM:SOFTWAREPoliciesMicrosoftWindowsPsched\"\n$qosPath = \"$policyPath$policyName\"\nNew-Item -Path $qosPath -Force | Out-Null\nNew-ItemProperty -Path $policyPath -Name \"Version\" -Value 1 -PropertyType DWord\nNew-ItemProperty -Path $qosPath -Name \"AppName\" -Value \"myapp.exe\" \nNew-ItemProperty -Path $qosPath -Name \"DSCPValue\" -Value 46 -PropertyType DWord\nNew-ItemProperty -Path $qosPath -Name \"Protocol\" -Value 6 -PropertyType DWord\nNew-ItemProperty -Path $qosPath -Name \"Port\" -Value 0 -PropertyType DWord\nNew-ItemProperty -Path $qosPath -Name \"ThrottleRate\" -Value -1 -PropertyType DWord\nNew-ItemProperty -Path $qosPath -Name \"Version\" -Value 1 -PropertyType DWord\ngpupdate \/force\n<\/code><\/pre>\n<ul>\n<li><code>AppName<\/code> \u2014 \u0438\u043c\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 (\u043c\u043e\u0436\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u043e\u0434\u043d\u043e\u0439 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u043e\u0439 \u043d\u0435 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c; \u043d\u0430 \u043a\u0430\u0436\u0434\u043e\u0435 \u2014 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u0430\u044f \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0430, \u043b\u0438\u0431\u043e \u043f\u0435\u0440\u0435\u0447\u0438\u0441\u043b\u0438\u0442\u0435 \u0447\u0435\u0440\u0435\u0437 <code>|<\/code>, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440 <code>one.exe|two.exe<\/code>).<\/li>\n<li><code>Protocol<\/code>: 6 = TCP, 17 = UDP, 0 = \u043b\u044e\u0431\u043e\u0439.<\/li>\n<li><code>DSCPValue<\/code>: \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 \u0432 \u0434\u0435\u0441\u044f\u0442\u0438\u0447\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 (46 = EF \u0434\u043b\u044f \u0432\u0438\u0434\u0435\u043e).<\/li>\n<\/ul>\n<h3>\u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u043c\u0435\u0442\u043a\u0438 \u043d\u0430 Windows<\/h3>\n<p>\u0421 PowerShell \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u0430 \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u0435 <code>netsh trace start<\/code>, \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435, \u0437\u0430\u0442\u0435\u043c <code>netsh trace stop<\/code> \u0438 \u043e\u0442\u043a\u0440\u043e\u0439\u0442\u0435 <code>.etl<\/code> \u0432 Microsoft Message Analyzer \/ Wireshark. \u0412 \u0444\u0438\u043b\u044c\u0442\u0440\u0435 Wireshark:<\/p>\n<pre><code>ip.dsfield.dscp == 46\n<\/code><\/pre>\n<p>\u0415\u0441\u043b\u0438 \u043c\u0435\u0442\u043a\u0430 \u0441\u0442\u0430\u0432\u0438\u0442\u0441\u044f, \u0432\u044b \u0443\u0432\u0438\u0434\u0438\u0442\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0441 DSCP 46 \u043e\u0442 \u043d\u0443\u0436\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430.<\/p>\n<blockquote><p><strong>\u041d\u044e\u0430\u043d\u0441:<\/strong> DSCP \u0441\u0442\u0430\u0432\u0438\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u0434\u043b\u044f \u0438\u0441\u0445\u043e\u0434\u044f\u0449\u0438\u0445 \u0441 \u044d\u0442\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u044b \u043f\u0430\u043a\u0435\u0442\u043e\u0432. \u0414\u043b\u044f \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u044b\u0445 \u0442\u0443\u043d\u043d\u0435\u043b\u0435\u0439 (IPsec) \u043c\u0435\u0442\u043a\u0430 \u0443\u0445\u043e\u0434\u0438\u0442 \u0432 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u043d\u0443\u044e \u0447\u0430\u0441\u0442\u044c \u2014 \u044d\u0442\u043e \u043e\u043a, \u0435\u0441\u043b\u0438 \u0442\u0443\u043d\u043d\u0435\u043b\u044c \u0442\u0435\u0440\u043c\u0438\u043d\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u043d\u0430 Mikrotik, \u0430 \u043d\u0435 \u043d\u0430 Windows.<\/p><\/blockquote>\n<hr \/>\n<h2>\u0427\u0430\u0441\u0442\u044c 2. Mikrotik: mangle \u2014 \u0432 VPN \u0442\u0443\u043d\u043d\u0435\u043b\u044c \u043f\u043e DSCP<\/h2>\n<p>\u0422\u0435\u043f\u0435\u0440\u044c \u043d\u0430 \u0440\u043e\u0443\u0442\u0435\u0440\u0435 Mikrotik (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u043d\u0430 \u0433\u0440\u0430\u043d\u0438\u0446\u0435 \u0441\u0435\u0442\u0438) \u0447\u0438\u0442\u0430\u0435\u043c DSCP \u0432\u0445\u043e\u0434\u044f\u0449\u0438\u0445 \u0438\u0437 LAN \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u043f\u043e\u043c\u0435\u0447\u0430\u0435\u043c \u0438\u0445 \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c \u0432 \u0442\u0443\u043d\u043d\u0435\u043b\u044c.<\/p>\n<h3>\u0428\u0430\u0433 1. \u041f\u043e\u043c\u0435\u0447\u0430\u0435\u043c \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u0438 \u043f\u0430\u043a\u0435\u0442 \u043f\u043e DSCP<\/h3>\n<pre><code class=\"language-routeros\">\/ip firewall mangle\nadd chain=prerouting dst-address-list=!no_vpn in-interface=bridge-local \n    dscp=46 action=mark-connection new-connection-mark=vpn-conn \n    pass-through=yes comment=\"DSCP46 -&gt; connection\"\nadd chain=prerouting connection-mark=vpn-conn in-interface=bridge-local \n    action=mark-packet new-packet-mark=vpn-traffic \n    pass-through=no comment=\"marked conn -&gt; packet\"\n<\/code><\/pre>\n<p>\u0413\u0434\u0435:<br \/>\n&#8212; <code>in-interface=bridge-local<\/code> \u2014 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441, \u0441 \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u043f\u0440\u0438\u0445\u043e\u0434\u0438\u0442 \u0442\u0440\u0430\u0444\u0438\u043a \u043e\u0442 \u041f\u041a (\u0443 \u0432\u0430\u0441 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c <code>ether1-local<\/code> \u0438 \u0442.\u043f.);<br \/>\n&#8212; <code>dscp=46<\/code> \u2014 \u043d\u043e\u043c\u0435\u0440 \u043c\u0435\u0442\u043a\u0438 \u0438\u0437 Windows;<br \/>\n&#8212; <code>dst-address-list=!no_vpn<\/code> \u2014 \u043d\u0435 \u0442\u0440\u043e\u0433\u0430\u0442\u044c \u0438\u0441\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f (\u0441\u043f\u0438\u0441\u043e\u043a <code>no_vpn<\/code> \u0441\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u0441\u0430\u043c\u0438 \u0438 \u0434\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u043d\u0443\u0436\u043d\u044b\u0435 \u043f\u043e\u0434\u0441\u0435\u0442\u0438).<br \/>\n&#8212; <code>pass-through<\/code> \u043f\u0435\u0440\u0432\u043e\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u043e = yes (\u0446\u0435\u043f\u043e\u0447\u043a\u0430: \u0441\u043d\u0430\u0447\u0430\u043b\u0430 connect-mark, \u043f\u043e\u0442\u043e\u043c packet-mark).<\/p>\n<h3>\u0428\u0430\u0433 2. \u0421\u043e\u0437\u0434\u0430\u0451\u043c \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0446\u0438\u0438 (routing rule)<\/h3>\n<p>\u041a\u043b\u044e\u0447\u0435\u0432\u043e\u0439 \u043c\u043e\u043c\u0435\u043d\u0442: \u043c\u0435\u0442\u043a\u0430 \u043f\u0430\u043a\u0435\u0442\u0430 \u2260 \u043c\u0430\u0440\u0448\u0440\u0443\u0442. \u0427\u0442\u043e\u0431\u044b \u00ab\u0437\u0430\u0441\u0442\u0430\u0432\u0438\u0442\u044c\u00bb marked-\u043f\u0430\u043a\u0435\u0442 \u0443\u0439\u0442\u0438 \u0432 \u0442\u0443\u043d\u043d\u0435\u043b\u044c, \u043d\u0443\u0436\u0435\u043d <strong>router-mark + \u043e\u0442\u0440\u0438\u043d\u0441\u043a\u0430\u044f \u0442\u0430\u0431\u043b\u0438\u0446\u0430 + routing rule<\/strong>:<\/p>\n<pre><code class=\"language-routeros\"># \u0432\u0440\u0435\u043c\u0435\u043d\u043d\u043e (\u043d\u0430 \u0432\u0440\u0435\u043c\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438) \u043c\u043e\u0436\u043d\u043e \u0447\u0435\u0440\u0435\u0437 route table:\n\/ip route\nadd dst-address=0.0.0.0\/0 gateway=&lt;vpn_interface&gt; routing-table=vpn-table \n    distance=1 comment=\"VPN default\"\n\n\/routing\/rule\nadd src-address=0.0.0.0\/0 routing-table=main table=vpn-table \n    packet-mark=vpn-traffic comment=\"VPN traffic -&gt; vpn-table\"\n<\/code><\/pre>\n<p>\u0427\u0442\u043e \u0432\u0430\u0436\u043d\u043e:<\/p>\n<ul>\n<li>Lane \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430: <code>routing\/rule<\/code> \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442: \u043f\u0430\u043a\u0435\u0442\u044b \u0441 <code>packet-mark=vpn-traffic<\/code>, \u043f\u0440\u0438\u0448\u0435\u0434\u0448\u0438\u0435 \u0441 main routing table, \u0438\u0449\u0443\u0442 \u043c\u0430\u0440\u0448\u0440\u0443\u0442 \u0432 \u0442\u0430\u0431\u043b\u0438\u0446\u0435 <code>vpn-table<\/code>.<\/li>\n<li>\u0412 <code>vpn-table<\/code> \u0442\u043e\u043b\u044c\u043a\u043e \u043e\u0434\u0438\u043d \u043c\u0430\u0440\u0448\u0440\u0443\u0442 \u2014 default \u0447\u0435\u0440\u0435\u0437 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 \u0442\u0443\u043d\u043d\u0435\u043b\u044f (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440 <code>wireguard1<\/code>, <code>pppoe-out<\/code> \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 VPN, <code>l2tp-out1<\/code>, <code>ovpn-out1<\/code>).<\/li>\n<li>\u041d\u0435 \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0439\u0442\u0435 \u044d\u0442\u043e\u0442 default \u0432 main \u2014 \u0442\u043e\u043b\u044c\u043a\u043e \u0432 <code>vpn-table<\/code>, \u0438\u043d\u0430\u0447\u0435 \u0432\u0435\u0441\u044c \u0442\u0440\u0430\u0444\u0438\u043a \u0443\u043f\u0430\u0434\u0451\u0442 \u0432 \u0442\u0443\u043d\u043d\u0435\u043b\u044c.<\/li>\n<\/ul>\n<h3>\u0428\u0430\u0433 3. NAT \u2014 \u0435\u0441\u043b\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u0445\u043e\u0434\u0438\u0442 \u0432 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u0447\u0435\u0440\u0435\u0437 \u0442\u0443\u043d\u043d\u0435\u043b\u044c<\/h3>\n<p>\u0415\u0441\u043b\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u043e\u0431\u0440\u0430\u0449\u0430\u0435\u0442\u0441\u044f \u043a \u0432\u043d\u0435\u0448\u043d\u0438\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c (\u043d\u0435 \u0432 \u0432\u0430\u0448\u0435\u0439 LAN), \u043d\u0443\u0436\u043d\u043e \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c masquerade \u0434\u043b\u044f marked-\u0442\u0440\u0430\u0444\u0438\u043a\u0430:<\/p>\n<pre><code class=\"language-routeros\">\/ip firewall nat\nadd chain=srcnat packet-mark=vpn-traffic out-interface=&lt;vpn_interface&gt; \n    action=masquerade comment=\"NAT VPN traffic\"\n<\/code><\/pre>\n<p>\u0415\u0441\u043b\u0438 \u0436\u0435 \u0442\u0443\u043d\u043d\u0435\u043b\u044c \u0432\u0435\u0434\u0451\u0442 \u0432 \u0432\u0430\u0448\u0443 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u0443\u044e \u0441\u0435\u0442\u044c (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, 10.0.0.0\/8) \u2014 masquerade \u043d\u0435 \u043d\u0443\u0436\u0435\u043d, \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e route.<\/p>\n<hr \/>\n<h2>\u0413\u043e\u0442\u043e\u0432\u0430\u044f \u0441\u0445\u0435\u043c\u0430 \u00ab\u043f\u043e\u0434 \u043a\u043b\u044e\u0447\u00bb<\/h2>\n<p>\u0426\u0435\u043f\u043e\u0447\u043a\u0430 \u043f\u043e\u043b\u043d\u043e\u0441\u0442\u044c\u044e:<\/p>\n<table>\n<thead>\n<tr>\n<th>\u041f\u0430\u043a\u0435\u0442<\/th>\n<th>\u0413\u0434\u0435 \u0440\u0435\u0448\u0430\u0435\u0442\u0441\u044f<\/th>\n<th>\u0420\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u0418\u0437 <code>myapp.exe<\/code><\/td>\n<td>Windows QoS<\/td>\n<td>DSCP=46<\/td>\n<\/tr>\n<tr>\n<td>\u041f\u0440\u0438\u0445\u043e\u0434\u0438\u0442 \u0432 LAN \u043d\u0430 Mikrotik<\/td>\n<td>mangle prerouting<\/td>\n<td>connection-mark=vpn-conn<\/td>\n<\/tr>\n<tr>\n<td>\u0422\u043e\u0442 \u0436\u0435 \u043f\u0430\u043a\u0435\u0442<\/td>\n<td>mangle prerouting (\u043f\u043e conn)<\/td>\n<td>packet-mark=vpn-traffic<\/td>\n<\/tr>\n<tr>\n<td>\u041c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0446\u0438\u044f<\/td>\n<td>routing\/rule<\/td>\n<td>main \u2192 vpn-table<\/td>\n<\/tr>\n<tr>\n<td>\u0418\u0441\u0445\u043e\u0434<\/td>\n<td>route vpn-table<\/td>\n<td>gateway=&lt;\u0442\u0443\u043d\u043d\u0435\u043b\u044c&gt;<\/td>\n<\/tr>\n<tr>\n<td>\u0412 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442<\/td>\n<td>NAT srcnat<\/td>\n<td>masquerade<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>\u041f\u043e\u043b\u043d\u044b\u0439 \u0441\u043f\u0438\u0441\u043e\u043a \u043f\u0440\u0430\u0432\u0438\u043b (\u0432\u0441\u0435 \u0432\u043c\u0435\u0441\u0442\u0435)<\/h3>\n<pre><code class=\"language-routeros\"># Mangle\n\/ip firewall mangle\nadd chain=prerouting in-interface=bridge-local dscp=46 \n    action=mark-connection new-connection-mark=vpn-conn pass-through=yes \n    comment=\"DSCP 46 -&gt; connection mark\"\nadd chain=prerouting in-interface=bridge-local connection-mark=vpn-conn \n    action=mark-packet new-packet-mark=vpn-traffic pass-through=no \n    comment=\"conn mark -&gt; packet mark\"\n\n# Routing table \u0438 \u043f\u0440\u0430\u0432\u0438\u043b\u043e\n\/ip route\nadd dst-address=0.0.0.0\/0 gateway=wireguard1 routing-table=vpn-table \n    comment=\"Default via VPN\"\n\n\/routing\/rule\nadd packet-mark=vpn-traffic routing-table=main table=vpn-table \n    comment=\"Marked traffic uses vpn-table\"\n\n# NAT\n\/ip firewall nat\nadd chain=srcnat packet-mark=vpn-traffic out-interface=wireguard1 \n    action=masquerade comment=\"Masq for VPN traffic\"\n<\/code><\/pre>\n<p>\u0417\u0430\u043c\u0435\u043d\u0438\u0442\u0435 <code>wireguard1<\/code> \u043d\u0430 \u0432\u0430\u0448 \u0442\u0443\u043d\u043d\u0435\u043b\u044c (WireGuard, OpenVPN, L2TP, PPPoE-\u0442\u0443\u043d\u043d\u0435\u043b\u044c \u0438 \u0442.\u0434.).<\/p>\n<hr \/>\n<h2>\u0412\u044b\u0431\u043e\u0440 DSCP-\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f<\/h2>\n<table>\n<thead>\n<tr>\n<th>\u0417\u043d\u0430\u0447\u0435\u043d\u0438\u0435<\/th>\n<th>Class<\/th>\n<th>\u0414\u043b\u044f \u0447\u0435\u0433\u043e<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>46<\/td>\n<td>EF (Expedited Forwarding)<\/td>\n<td>\u0412\u0438\u0434\u0435\u043e, \u0433\u043e\u043b\u043e\u0441<\/td>\n<\/tr>\n<tr>\n<td>34<\/td>\n<td>AF41<\/td>\n<td>\u0422\u0440\u0435\u0431\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u043d\u043e \u043a \u0437\u0430\u0434\u0435\u0440\u0436\u043a\u0430\u043c<\/td>\n<\/tr>\n<tr>\n<td>26<\/td>\n<td>AF31<\/td>\n<td>\u041e\u0431\u044b\u0447\u043d\u044b\u0439 \u043f\u0440\u0438\u043e\u0440\u0438\u0442\u0435\u0442<\/td>\n<\/tr>\n<tr>\n<td>0<\/td>\n<td>Best Effort<\/td>\n<td>\u0412\u0435\u0441\u044c \u043e\u0441\u0442\u0430\u043b\u044c\u043d\u043e\u0439 \u0442\u0440\u0430\u0444\u0438\u043a<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u0414\u043b\u044f 1\u0421\/\u0431\u0438\u0437\u043d\u0435\u0441-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u043e\u0431\u044b\u0447\u043d\u043e \u0445\u0432\u0430\u0442\u0430\u0435\u0442 <strong>46<\/strong>, \u0435\u0441\u043b\u0438 \u0432 \u0441\u0435\u0442\u0438 \u043d\u0435 \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043d QoS-\u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b \u0441 \u043a\u043e\u043d\u0444\u043b\u0438\u043a\u0442\u0443\u044e\u0449\u0438\u043c\u0438 \u043a\u043b\u0430\u0441\u0441\u0430\u043c\u0438, \u0438\u043b\u0438 <strong>26\/34<\/strong>, \u0447\u0442\u043e\u0431\u044b \u043d\u0435 \u0437\u0430\u0434\u0438\u0440\u0430\u0442\u044c \u043f\u0440\u0438\u043e\u0440\u0438\u0442\u0435\u0442 \u0432\u044b\u0448\u0435 \u0433\u043e\u043b\u043e\u0441\u0430\/VoIP.<\/p>\n<blockquote><p><code>dscp=46<\/code> \u0432 RouterOS \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u0435\u0442 <code>DSCPValue=46<\/code> \u0432 Windows \u043f\u0440\u0438 <code>Protocol=6|17<\/code>. \u0423\u0431\u0435\u0434\u0438\u0442\u0435\u0441\u044c, \u0447\u0442\u043e \u0442\u0443\u043d\u043d\u0435\u043b\u044c-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 \u0438\u043c\u0435\u0435\u0442 MTU \u043d\u0435 \u0431\u043e\u043b\u044c\u0448\u0435, \u0447\u0435\u043c \u043d\u0430 \u0444\u0438\u0437\u0438\u0447\u0435\u0441\u043a\u043e\u043c \u043a\u0430\u043d\u0430\u043b\u0435, \u0438\u043d\u0430\u0447\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u043c\u043e\u0433\u0443\u0442 \u0444\u0440\u0430\u0433\u043c\u0435\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0438 \u0442\u0435\u0440\u044f\u0442\u044c \u043c\u0435\u0442\u043a\u0443.<\/p><\/blockquote>\n<hr \/>\n<h2>\u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0430<\/h2>\n<ol>\n<li>\u0418\u0437 Windows: <code>ping -S &lt;IP&gt; -c 5 &lt;\u0430\u0434\u0440\u0435\u0441_VPN_\u0440\u0435\u0441\u0443\u0440\u0441\u0430&gt;<\/code> \u043d\u0435 \u043f\u043e\u043c\u043e\u0436\u0435\u0442 \u2014 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0439\u0442\u0435 \u0441\u0430\u043c\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u0438\u043b\u0438 <code>tracert<\/code>:<br \/>\n<code>cmd<br \/>\ntracert &lt;IP_VPN_\u0440\u0435\u0441\u0443\u0440\u0441\u0430&gt;<\/code><br \/>\n\u0415\u0441\u043b\u0438 \u043f\u0435\u0440\u0432\u044b\u0439 \u0445\u043e\u043f \u2014 IP \u0442\u0443\u043d\u043d\u0435\u043b\u044c\u043d\u043e\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430 Mikrotik (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440 10.0.0.2), \u0437\u043d\u0430\u0447\u0438\u0442 \u0442\u0440\u0430\u0444\u0438\u043a \u0438\u0434\u0451\u0442 \u0432 \u0442\u0443\u043d\u043d\u0435\u043b\u044c.<\/li>\n<li>\u041d\u0430 Mikrotik: <code>\/tool sniffer quick ip-protocol=tcp port=&lt;\u043f\u043e\u0440\u0442&gt; interface=bridge-local<\/code>, \u043e\u0442\u0444\u0438\u043b\u044c\u0442\u0440\u0443\u0439\u0442\u0435 \u043f\u043e DSCP 46 \u2014 \u043f\u0430\u043a\u0435\u0442\u044b \u0441 \u043c\u0435\u0442\u043a\u043e\u0439 \u0432\u0438\u0434\u043d\u044b.<\/li>\n<li><code>:put [\/ip firewall mangle print count-only]<\/code> \u0441\u0447\u0451\u0442\u0447\u0438\u043a\u0438 \u2014 \u0434\u043e\u043b\u0436\u043d\u044b \u0440\u0430\u0441\u0442\u0438 \u0443 \u043f\u0440\u0430\u0432\u0438\u043b mangle \u043f\u0440\u0438 \u0440\u0430\u0431\u043e\u0442\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f.<\/li>\n<li>\u041d\u0430 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c VPN-\u0441\u0435\u0440\u0432\u0435\u0440\u0435: <code>tcpdump -i tun0 ip[1] == 0xb8<\/code> (46 DSCP = 0xB8 \u0432 TOS-\u0431\u0430\u0439\u0442\u0435 \u0441 ECN-\u0431\u0438\u0442\u0430\u043c\u0438) \u2014 \u0443\u0432\u0438\u0434\u0438\u0442\u0435 \u043f\u043e\u043c\u0435\u0447\u0435\u043d\u043d\u044b\u0435 \u043f\u0430\u043a\u0435\u0442\u044b.<\/li>\n<\/ol>\n<hr \/>\n<h2>\u0422\u043e\u043d\u043a\u043e\u0441\u0442\u0438 \u0438 \u043f\u043e\u0434\u0432\u043e\u0434\u043d\u044b\u0435 \u043a\u0430\u043c\u043d\u0438<\/h2>\n<ul>\n<li><strong>Windows QoS Policy \u043d\u0435 \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0434\u043b\u044f \u0441\u0442\u0430\u0440\u043e\u0433\u043e \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442\u0430.<\/strong> \u0415\u0441\u043b\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u0441\u0442\u0430\u0440\u0442\u0443\u0435\u0442 \u0434\u043e \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0438, \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u0435 \u0435\u0433\u043e. \u041f\u0440\u043e\u0432\u0435\u0440\u0438\u0442\u044c \u043c\u043e\u0436\u043d\u043e \u0447\u0435\u0440\u0435\u0437 <code>Get-NetQosPolicy<\/code>.<\/li>\n<li><strong>\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439:<\/strong> \u0432 \u043e\u0434\u043d\u043e\u0439 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0435 <code>AppName=one.exe|two.exe<\/code> \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u043d\u0435 \u0432\u0441\u0435\u0433\u0434\u0430 \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u043e. \u041d\u0430\u0434\u0451\u0436\u043d\u0435\u0435 \u2014 \u043e\u0434\u043d\u0430 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0430 \u043d\u0430 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u0441 \u043e\u0434\u0438\u043d\u0430\u043a\u043e\u0432\u044b\u043c DSCP. \u041b\u0438\u0431\u043e \u0435\u0434\u0438\u043d\u0430\u044f \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0430 \u043d\u0430 \u043f\u043e\u0440\u0442\/\u043f\u043e\u0434\u0441\u0435\u0442\u044c, \u0435\u0441\u043b\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, 1\u0421-\u0441\u0435\u0440\u0432\u0435\u0440 (<code>1cv8.exe<\/code> \u043d\u0430 \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u043e\u043c \u043f\u043e\u0440\u0442\u0443).<\/li>\n<li><strong>DSCP \u0442\u0435\u0440\u044f\u0435\u0442\u0441\u044f \u043f\u0440\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0438<\/strong>, \u0435\u0441\u043b\u0438 \u0442\u0443\u043d\u043d\u0435\u043b\u044c \u0434\u0435\u043b\u0430\u0435\u0442 IPsec \u043d\u0430 Windows-\u043c\u0430\u0448\u0438\u043d\u0435. \u041f\u043e\u044d\u0442\u043e\u043c\u0443 \u0442\u0443\u043d\u043d\u0435\u043b\u044c \u0434\u043e\u043b\u0436\u043d\u044b \u0442\u0435\u0440\u043c\u0438\u043d\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0438\u043c\u0435\u043d\u043d\u043e Mikrotik (WireGuard\/OpenVPN \u043d\u0430 \u0440\u043e\u0443\u0442\u0435\u0440\u0435), \u0438\u043d\u0430\u0447\u0435 \u043c\u0435\u0442\u043a\u0430 \u0432\u043d\u0443\u0442\u0440\u0438 ESP \u043d\u0435 \u0432\u0438\u0434\u043d\u0430.<\/li>\n<li><strong>FastTrack \u0440\u0443\u043b\u0438\u0442 \u043c\u0438\u043c\u043e mangle<\/strong>: \u0435\u0441\u043b\u0438 \u0432\u043a\u043b\u044e\u0447\u0451\u043d FastTrack, \u0441\u043d\u0430\u0447\u0430\u043b\u0430 \u0447\u0435\u0440\u0435\u0437 firewall filter \u043e\u0442\u043a\u043b\u044e\u0447\u0438\u0442\u0435 fasttrack \u0434\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0430:<br \/>\n<code>routeros<br \/>\n\/ip firewall raw<br \/>\nadd chain=prerouting in-interface=bridge-local dscp=46 action=notrack<br \/>\ncomment=\"no fasttrack for dscp46\"<\/code><br \/>\n\u0418\u043d\u0430\u0447\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0443\u0439\u0434\u0443\u0442 \u043f\u043e \u0441\u0432\u043e\u0438\u043c \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0430\u043c, \u043c\u0438\u043d\u0443\u044f connection-mark.<\/li>\n<li><strong>RouterOS 6 vs 7<\/strong>: \u0441\u0438\u043d\u0442\u0430\u043a\u0441\u0438\u0441 <code>routing\/rule<\/code> \u0432\u0435\u0440\u0435\u043d \u0434\u043b\u044f RouterOS 7; \u0432 6-\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u0442\u043e\u0436\u0435 \u0435\u0441\u0442\u044c <code>\/routing rule<\/code>, \u043d\u043e \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u0443\u0435\u0442\u0441\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0442\u044c \u043d\u0430 \u0432\u0430\u0448\u0435\u0439 \u0441\u0431\u043e\u0440\u043a\u0435.<\/li>\n<\/ul>\n<hr \/>\n<h2>\u0412\u044b\u0432\u043e\u0434<\/h2>\n<p>\u0427\u0435\u0440\u0435\u0437 \u0441\u0432\u044f\u0437\u043a\u0443 QoS Policy \u0432 Windows (DSCP) + mangle\/routing rule \u043d\u0430 Mikrotik \u043c\u043e\u0436\u043d\u043e \u043f\u0440\u0438\u0446\u0435\u043b\u044c\u043d\u043e \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u043e\u0433\u043e exe-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0432 VPN-\u0442\u0443\u043d\u043d\u0435\u043b\u044c, \u043d\u0435 \u043f\u0435\u0440\u0435\u0432\u043e\u0434\u044f \u0432\u0435\u0441\u044c \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440 \u0432 VPN \u0438 \u043d\u0435 \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u044b\u0435 VPN-\u043a\u043b\u0438\u0435\u043d\u0442\u044b. \u0413\u043b\u0430\u0432\u043d\u043e\u0435 \u2014 \u0440\u043e\u0432\u043d\u043e \u0442\u0440\u0438 \u0442\u043e\u0447\u043a\u0438: <strong>DSCP \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u0435 \u2192 connection\/packet mark \u0432 mangle \u2192 routing rule \u0432 vpn-\u0442\u0430\u0431\u043b\u0438\u0446\u0443<\/strong>.<br \/>\n\u0421\u0442\u043e\u0438\u0442 \u043e\u0442\u043c\u0435\u0442\u0438\u0442\u044c \u0447\u0442\u043e 1C \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u043f\u0440\u0438\u043c\u0435\u0440\u0430, \u0430 \u043f\u043e\u043c\u0435\u0442\u0438\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a \u043c\u043e\u0436\u043d\u043e \u0430\u0431\u0441\u043e\u043b\u044e\u0442\u043d\u043e \u043b\u044e\u0431\u043e\u0433\u043e EXE \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 OpenCode, \u0431\u0440\u0430\u0443\u0437\u0435\u0440, \u043f\u0440\u043e\u0434\u0443\u043a\u0442\u044b Adobe \u0438 \u0442.\u0434.<\/p>\n<p><em>\u041f\u0440\u043e\u0432\u0435\u0440\u0435\u043d\u043e \u043d\u0430: Windows 10\/11 Pro + RouterOS 7.<\/em><br \/>\n<em>\u0414\u0430\u0442\u0430: \u0421\u0435\u043d\u0442\u044f\u0431\u0440\u044c 2026.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u041a\u0430\u043a \u043f\u043e\u043c\u0435\u0442\u0438\u0442\u044c DSCP \u0442\u0440\u0430\u0444\u0438\u043a \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u043e\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0432 Windows \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u0442\u044c<\/p>\n","protected":false},"author":1,"featured_media":710,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[7,1],"tags":[],"class_list":["post-706","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mikrotik","category-windows"],"aioseo_notices":[],"views":15,"_links":{"self":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/706","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=706"}],"version-history":[{"count":3,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/706\/revisions"}],"predecessor-version":[{"id":712,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/706\/revisions\/712"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/media\/710"}],"wp:attachment":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=706"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=706"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=706"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}