{"id":713,"date":"2026-09-16T17:35:26","date_gmt":"2026-09-16T14:35:26","guid":{"rendered":"https:\/\/imaxis.ru\/?p=713"},"modified":"2026-09-16T17:36:44","modified_gmt":"2026-09-16T14:36:44","slug":"dscp-ubuntu-mangle-vpn-mikrotik","status":"publish","type":"post","link":"https:\/\/imaxis.ru\/?p=713","title":{"rendered":"\u041a\u0430\u043a \u043f\u043e\u043c\u0435\u0442\u0438\u0442\u044c DSCP \u0442\u0440\u0430\u0444\u0438\u043a \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u043e\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0432 Ubuntu \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u0435\u0433\u043e \u0432 VPN \u0447\u0435\u0440\u0435\u0437 mangle \u043d\u0430 Mikrotik"},"content":{"rendered":"<h1>\u041a\u0430\u043a \u043f\u043e\u043c\u0435\u0442\u0438\u0442\u044c DSCP \u0442\u0440\u0430\u0444\u0438\u043a \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u043e\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0432 Ubuntu \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u0435\u0433\u043e \u0432 VPN \u0447\u0435\u0440\u0435\u0437 mangle \u043d\u0430 Mikrotik<\/h1>\n<p>\u0412 \u043f\u0440\u043e\u0448\u043b\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0440\u0430\u0437\u0431\u0438\u0440\u0430\u043b\u0438, \u043a\u0430\u043a \u043f\u043e\u043c\u0435\u0442\u0438\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u043e\u0433\u043e exe \u0432 Windows. \u0410\u043d\u0430\u043b\u043e\u0433\u0438\u0447\u043d\u0430\u044f \u0437\u0430\u0434\u0430\u0447\u0430 \u043d\u0430 Ubuntu \u0440\u0435\u0448\u0430\u0435\u0442\u0441\u044f \u043f\u0440\u0438\u043c\u0435\u0440\u043d\u043e \u0442\u0430\u043a \u0436\u0435, \u043d\u043e \u0432\u043c\u0435\u0441\u0442\u043e QoS Policy \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f iptables (\u0438\u043b\u0438 nftables). \u0426\u0435\u043b\u044c \u0442\u0430 \u0436\u0435 \u2014 \u0447\u0442\u043e\u0431\u044b \u0442\u0440\u0430\u0444\u0438\u043a \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u043e\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0443\u0445\u043e\u0434\u0438\u043b \u043d\u0435 \u0432 \u043e\u0431\u044b\u0447\u043d\u044b\u0439 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442, \u0430 \u0432 VPN-\u0442\u0443\u043d\u043d\u0435\u043b\u044c, \u043f\u0440\u0438\u0447\u0451\u043c \u0431\u0435\u0437 \u043f\u0435\u0440\u0435\u0432\u043e\u0434\u0430 \u0432\u0441\u0435\u0433\u043e \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u0430 \u0432 VPN.<\/p>\n<p>\u0421\u0445\u0435\u043c\u0430 \u0438\u0437 \u0434\u0432\u0443\u0445 \u0448\u0430\u0433\u043e\u0432:<\/p>\n<ol>\n<li><strong>Ubuntu<\/strong>: \u043f\u043e\u043c\u0435\u0442\u0438\u0442\u044c \u043f\u0430\u043a\u0435\u0442\u044b \u043d\u0443\u0436\u043d\u043e\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u043c\u0435\u0442\u043a\u043e\u0439 DSCP (\u0432 \u043f\u043e\u043b\u0435 TOS\/IP).<\/li>\n<li><strong>Mikrotik<\/strong>: \u043f\u043e DSCP-\u043c\u0435\u0442\u043a\u0435 \u0447\u0435\u0440\u0435\u0437 mangle \u043f\u043e\u043c\u0435\u0442\u0438\u0442\u044c \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u043f\u0430\u043a\u0435\u0442\u044b \u0432 VPN-\u0442\u0443\u043d\u043d\u0435\u043b\u044c.<\/li>\n<\/ol>\n<p>DSCP \u2014 6-\u0431\u0438\u0442\u043d\u043e\u0435 \u043f\u043e\u043b\u0435 \u0432 IP-\u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0435. Ubuntu \u0443\u043c\u0435\u0435\u0442 \u0435\u0433\u043e \u0432\u044b\u0441\u0442\u0430\u0432\u043b\u044f\u0442\u044c \u0447\u0435\u0440\u0435\u0437 iptables <code>-j DSCP<\/code>, Mikrotik \u0443\u043c\u0435\u0435\u0442 \u043f\u043e \u043d\u0435\u043c\u0443 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u0442\u044c. \u0414\u0430\u043b\u044c\u0448\u0435 \u2014 \u043f\u043e\u043b\u043d\u0430\u044f \u0440\u0430\u0431\u043e\u0447\u0430\u044f \u0441\u0445\u0435\u043c\u0430.<\/p>\n<hr \/>\n<h2>\u0427\u0430\u0441\u0442\u044c 1. Ubuntu: \u0441\u0442\u0430\u0432\u0438\u043c DSCP-\u043c\u0435\u0442\u043a\u0443 \u043d\u0430 \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u043e\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435<\/h2>\n<h3>\u0421\u043f\u043e\u0441\u043e\u0431 A. \u041f\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e (\u0442\u043e\u0447\u043d\u044b\u0439, \u043d\u043e \u0442\u0440\u0435\u0431\u0443\u0435\u0442 \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u044e\u0437\u0435\u0440\u0430)<\/h3>\n<p>\u0421\u0430\u043c\u044b\u0439 \u043d\u0430\u0434\u0451\u0436\u043d\u044b\u0439 \u0441\u043f\u043e\u0441\u043e\u0431 \u2014 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0442\u044c \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u043e\u0442 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u0433\u043e \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u0433\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438 \u043f\u043e\u043c\u0435\u0447\u0430\u0442\u044c \u0432\u0435\u0441\u044c \u0435\u0433\u043e \u0438\u0441\u0445\u043e\u0434\u044f\u0449\u0438\u0439 \u0442\u0440\u0430\u0444\u0438\u043a:<\/p>\n<pre><code class=\"language-bash\"># \u0421\u043e\u0437\u0434\u0430\u0451\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0434\u043b\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f (\u0435\u0441\u043b\u0438 \u0435\u0449\u0451 \u043d\u0435\u0442)\nsudo useradd -r -m vpnapp\n# \u0417\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u043e\u0442 \u044d\u0442\u043e\u0433\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\nsudo -u vpnapp \/opt\/myapp\/myapp --daemon\n\n# \u041f\u0440\u0430\u0432\u0438\u043b\u043e iptables: \u043c\u0435\u0442\u043a\u0430 DSCP 46 \u043d\u0430 \u0432\u0435\u0441\u044c \u0442\u0440\u0430\u0444\u0438\u043a \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f vpnapp\nsudo iptables -t mangle -A OUTPUT -m owner --uid-owner vpnapp -j DSCP --set-dscp 46\n<\/code><\/pre>\n<p>\u0427\u0442\u043e \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442:<br \/>\n&#8212; <code>-t mangle<\/code> \u2014 \u0442\u0430\u0431\u043b\u0438\u0446\u0430 \u0434\u043b\u044f \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u043f\u043e\u043b\u0435\u0439 \u043f\u0430\u043a\u0435\u0442\u0430;<br \/>\n&#8212; <code>OUTPUT<\/code> \u2014 \u0446\u0435\u043f\u043e\u0447\u043a\u0430 \u0434\u043b\u044f \u0438\u0441\u0445\u043e\u0434\u044f\u0449\u0435\u0433\u043e \u0441 \u044d\u0442\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u044b \u0442\u0440\u0430\u0444\u0438\u043a\u0430;<br \/>\n&#8212; <code>-m owner --uid-owner vpnapp<\/code> \u2014 \u043c\u0430\u0442\u0447 \u043f\u043e \u00ab\u0432\u043b\u0430\u0434\u0435\u043b\u044c\u0446\u0443\u00bb \u0441\u043e\u043a\u0435\u0442\u0430 (UID \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0432\u0448\u0435\u0433\u043e \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430);<br \/>\n&#8212; <code>-j DSCP --set-dscp 46<\/code> \u2014 \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u044c \u043f\u043e\u043b\u044f DSCP \u043d\u0430 \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 46 (EF).<\/p>\n<p><strong>\u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430, \u0447\u0442\u043e \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u0432\u0441\u0442\u0430\u043b\u043e:<\/strong><\/p>\n<pre><code class=\"language-bash\">sudo iptables -t mangle -L OUTPUT -nv\n<\/code><\/pre>\n<p>\u0412 \u0432\u044b\u0432\u043e\u0434\u0435 \u0434\u043e\u043b\u0436\u0435\u043d \u043f\u043e\u044f\u0432\u0438\u0442\u044c\u0441\u044f \u043d\u0435\u043d\u0443\u043b\u0435\u0432\u043e\u0439 \u0441\u0447\u0451\u0442\u0447\u0438\u043a \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0443 \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u043f\u043e \u043c\u0435\u0440\u0435 \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f.<\/p>\n<h3>\u0421\u043f\u043e\u0441\u043e\u0431 B. \u041f\u043e \u043f\u043e\u0440\u0442\u0443 (\u0435\u0441\u043b\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u043f\u043e\u0434 \u043e\u0431\u0449\u0438\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c)<\/h3>\n<p>\u0418\u043d\u043e\u0433\u0434\u0430 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044e \u043d\u0435\u043b\u044c\u0437\u044f \u0432\u044b\u0434\u0435\u043b\u0438\u0442\u044c \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u0433\u043e \u044e\u0437\u0435\u0440\u0430. \u0422\u043e\u0433\u0434\u0430 \u043c\u0435\u0442\u0438\u043c \u043f\u043e \u043f\u043e\u0440\u0442\u0443 \u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f:<\/p>\n<pre><code class=\"language-bash\"># \u041d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, 1\u0421-\u0441\u0435\u0440\u0432\u0435\u0440 \u0438\u043b\u0438 \u0441\u0432\u043e\u0439 \u043a\u043b\u0438\u0435\u043d\u0442 \u043d\u0430 TCP 1541\nsudo iptables -t mangle -A OUTPUT -p tcp --dport 1541 -j DSCP --set-dscp 46\n<\/code><\/pre>\n<blockquote>\n<p><strong>\u041d\u044e\u0430\u043d\u0441:<\/strong> \u043c\u0435\u0442\u043a\u0430 \u0441\u0442\u0430\u0432\u0438\u0442\u0441\u044f \u043a\u0430\u0436\u0434\u043e\u043c\u0443 \u043f\u0430\u043a\u0435\u0442\u0443, \u0443\u0445\u043e\u0434\u044f\u0449\u0435\u043c\u0443 \u043d\u0430 \u044d\u0442\u043e\u0442 \u043f\u043e\u0440\u0442, \u043d\u0435\u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e \u043e\u0442 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f. \u0415\u0441\u043b\u0438 \u043f\u043e\u0440\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u043c\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430\u043c\u0438 \u2014 DSCP \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u0441\u044f \u0443 \u0432\u0441\u0435\u0445.<\/p>\n<\/blockquote>\n<h3>\u0421\u043f\u043e\u0441\u043e\u0431 C. \u0427\u0435\u0440\u0435\u0437 nftables (\u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0439 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442 Ubuntu)<\/h3>\n<p>\u041d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 Ubuntu 22.04 \u043f\u0440\u0435\u0434\u043f\u043e\u0447\u0442\u0438\u0442\u0435\u043b\u0435\u043d nftables. \u0422\u043e \u0436\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u043d\u0430 nftables:<\/p>\n<pre><code class=\"language-bash\">sudo nft add table inet mangle\nsudo nft add chain inet mangle output '{ type filter hook output priority 0; }'\nsudo nft add rule inet mangle output meta skuid vpnapp ip dscp set 0x2e\n<\/code><\/pre>\n<ul>\n<li><code>meta skuid vpnapp<\/code> \u2014 \u0442\u043e \u0436\u0435 \u0441\u0430\u043c\u043e\u0435, \u0447\u0442\u043e <code>--uid-owner<\/code>;<\/li>\n<li><code>ip dscp set 0x2e<\/code> \u2014 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c DSCP 46 (0x2e = 46 \u0432 hex);<\/li>\n<li><code>type filter hook output priority 0<\/code> \u2014 \u0446\u0435\u043f\u043e\u0447\u043a\u0430 \u0434\u043b\u044f \u0438\u0441\u0445\u043e\u0434\u044f\u0449\u0438\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432.<\/li>\n<\/ul>\n<p><strong>\u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 nftables:<\/strong><\/p>\n<pre><code class=\"language-bash\">sudo nft list table inet mangle\n<\/code><\/pre>\n<h3>\u0421\u043f\u043e\u0441\u043e\u0431 D. \u0427\u0435\u0440\u0435\u0437 iproute2 \/ cgroup (\u0434\u043b\u044f \u043d\u043e\u0432\u0435\u0439\u0448\u0438\u0445 \u044f\u0434\u0435\u0440)<\/h3>\n<p>\u0415\u0441\u043b\u0438 \u043d\u0443\u0436\u043d\u043e \u043c\u0435\u0442\u0438\u0442\u044c \u043d\u0435 \u043f\u043e UID, \u0430 \u043f\u043e \u0433\u0440\u0443\u043f\u043f\u0435 cgroup (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0434\u043b\u044f \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430 systemd unit), iptables \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u0442 match <code>--cgroup<\/code>:<\/p>\n<pre><code class=\"language-bash\">sudo iptables -t mangle -A OUTPUT -m cgroup --path \/system.slice\/myapp.service -j DSCP --set-dscp 46\n<\/code><\/pre>\n<hr \/>\n<h2>\u0421\u043e\u0445\u0440\u0430\u043d\u0435\u043d\u0438\u0435 \u043f\u0440\u0430\u0432\u0438\u043b \u043f\u043e\u0441\u043b\u0435 \u043f\u0435\u0440\u0435\u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438<\/h2>\n<p>iptables-\u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u043d\u0435 \u0441\u043e\u0445\u0440\u0430\u043d\u044f\u044e\u0442\u0441\u044f \u0441\u0430\u043c\u0438 \u043f\u043e \u0441\u0435\u0431\u0435. \u0421\u0442\u0430\u0432\u0438\u043c \u043f\u0430\u043a\u0435\u0442 <code>iptables-persistent<\/code>:<\/p>\n<pre><code class=\"language-bash\">sudo apt install -y iptables-persistent\n# \u041d\u043e\u0432\u0430\u044f \u0437\u0430\u043f\u0438\u0441\u044c \u043a\u0430\u0436\u0434\u043e\u0433\u043e \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u043f\u043e\u0441\u043b\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f:\nsudo netfilter-persistent save\n<\/code><\/pre>\n<p>\u0414\u043b\u044f nftables:<\/p>\n<pre><code class=\"language-bash\">sudo nft list ruleset &gt; \/tmp\/ruleset.nft\nsudo cp \/tmp\/ruleset.nft \/etc\/nftables.conf\nsudo systemctl enable --now nftables\n<\/code><\/pre>\n<hr \/>\n<h2>\u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u043c\u0435\u0442\u043a\u0438 \u043d\u0430 Ubuntu<\/h2>\n<p>\u0421\u0430\u043c\u043e\u0435 \u043d\u0430\u0433\u043b\u044f\u0434\u043d\u043e\u0435 \u2014 \u043f\u043e\u0434\u0433\u043b\u044f\u0434\u0435\u0442\u044c \u0437\u0430 \u0442\u0440\u0430\u0444\u0438\u043a\u043e\u043c \u0447\u0435\u0440\u0435\u0437 tcpdump \u043f\u0440\u044f\u043c\u043e \u043d\u0430 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 \u0438\u043b\u0438 \u043d\u0430 \u0440\u043e\u0443\u0442\u0435\u0440\u0435:<\/p>\n<pre><code class=\"language-bash\"># \u0421\u043c\u043e\u0442\u0440\u0438\u043c DSCP \u0443 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\nsudo tcpdump -i any 'ip dscp 46' -n\n# \u0417\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u2014 \u043f\u043e\u044f\u0432\u044f\u0442\u0441\u044f \u0441\u0442\u0440\u043e\u043a\u0438 \u0441 \u044d\u0442\u0438\u043c \u0444\u0438\u043b\u044c\u0442\u0440\u043e\u043c\n<\/code><\/pre>\n<p>\u041d\u0430 Mikrotik \u043c\u043e\u0436\u043d\u043e \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0435\u0442\u044c \u0441\u0447\u0451\u0442\u0447\u0438\u043a\u0438 mangle-\u043f\u0440\u0430\u0432\u0438\u043b, \u043d\u043e \u043f\u043e\u043a\u0430 \u043d\u0435 \u0431\u044b\u043b\u043e \u043f\u0440\u0430\u0432\u0438\u043b \u2014 \u043b\u0443\u0447\u0448\u0435 \u0443\u0431\u0435\u0434\u0438\u0442\u044c\u0441\u044f \u043d\u0430 Ubuntu, \u0447\u0442\u043e \u043f\u0430\u043a\u0435\u0442\u044b \u0440\u0435\u0430\u043b\u044c\u043d\u043e \u0443\u0445\u043e\u0434\u044f\u0442 \u0441 \u043c\u0435\u0442\u043a\u043e\u0439.<\/p>\n<hr \/>\n<h2>\u0427\u0430\u0441\u0442\u044c 2. Mikrotik: mangle \u2014 \u0432 VPN \u0442\u0443\u043d\u043d\u0435\u043b\u044c \u043f\u043e DSCP<\/h2>\n<p>\u0420\u043e\u0443\u0442\u0435\u0440 \u0447\u0438\u0442\u0430\u0435\u0442 DSCP \u0443 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0441 LAN-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430, \u043f\u043e\u043c\u0435\u0447\u0430\u0435\u0442 \u0438\u0445 \u0438 \u0437\u0430\u0432\u043e\u0440\u0430\u0447\u0438\u0432\u0430\u0435\u0442 \u0432 \u0442\u0443\u043d\u043d\u0435\u043b\u044c. \u041f\u0440\u0430\u0432\u0438\u043b\u0430 \u0430\u0431\u0441\u043e\u043b\u044e\u0442\u043d\u043e \u0442\u0435 \u0436\u0435, \u0447\u0442\u043e \u0434\u043b\u044f Windows-\u0441\u0442\u0430\u0442\u044c\u0438.<\/p>\n<h3>\u0428\u0430\u0433 1. \u041f\u043e\u043c\u0435\u0447\u0430\u0435\u043c \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u0438 \u043f\u0430\u043a\u0435\u0442 \u043f\u043e DSCP<\/h3>\n<pre><code class=\"language-routeros\">\/ip firewall mangle\nadd chain=prerouting dst-address-list=!no_vpn in-interface=bridge-local \n    dscp=46 action=mark-connection new-connection-mark=vpn-conn \n    pass-through=yes comment=&quot;DSCP46 -&gt; connection&quot;\nadd chain=prerouting connection-mark=vpn-conn in-interface=bridge-local \n    action=mark-packet new-packet-mark=vpn-traffic \n    pass-through=no comment=&quot;marked conn -&gt; packet&quot;\n<\/code><\/pre>\n<p>\u0413\u0434\u0435:<br \/>\n&#8212; <code>in-interface=bridge-local<\/code> \u2014 LAN-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 (\u0443 \u0432\u0430\u0441 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c <code>ether1-local<\/code> \u0438 \u0442.\u043f.);<br \/>\n&#8212; <code>dscp=46<\/code> \u2014 \u0442\u0430 \u0441\u0430\u043c\u0430\u044f \u043c\u0435\u0442\u043a\u0430, \u043a\u043e\u0442\u043e\u0440\u0443\u044e \u0441\u0442\u0430\u0432\u0438\u0442 Ubuntu:<br \/>\n&#8212; <code>dst-address-list=!no_vpn<\/code> \u2014 \u0438\u0441\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f (\u0441\u043f\u0438\u0441\u043e\u043a <code>no_vpn<\/code> \u0441\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u0437\u0430\u0440\u0430\u043d\u0435\u0435).<\/p>\n<h3>\u0428\u0430\u0433 2. \u041c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0446\u0438\u044f marked-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0432 \u0442\u0443\u043d\u043d\u0435\u043b\u044c<\/h3>\n<p>\u0414\u0435\u043b\u0430\u0435\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 \u0447\u0435\u0440\u0435\u0437 routing-rule + \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u0443\u044e \u0442\u0430\u0431\u043b\u0438\u0446\u0443 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u043e\u0432:<\/p>\n<pre><code class=\"language-routeros\">\/ip route\nadd dst-address=0.0.0.0\/0 gateway=&lt;vpn_interface&gt; routing-table=vpn-table \n    distance=1 comment=&quot;VPN default&quot;\n\n\/routing\/rule\nadd src-address=0.0.0.0\/0 routing-table=main table=vpn-table \n    packet-mark=vpn-traffic comment=&quot;VPN traffic -&gt; vpn-table&quot;\n<\/code><\/pre>\n<ul>\n<li>\u0412 <code>vpn-table<\/code> \u043b\u0435\u0436\u0438\u0442 \u043e\u0434\u0438\u043d default \u2014 \u0447\u0435\u0440\u0435\u0437 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 \u0442\u0443\u043d\u043d\u0435\u043b\u044f (<code>wireguard1<\/code>, <code>l2tp-out1<\/code>, <code>ovpn-out1<\/code> \u0438 \u0442.\u0434.);<\/li>\n<li><code>routing\/rule<\/code> \u043f\u0435\u0440\u0435\u043a\u043b\u0430\u0434\u044b\u0432\u0430\u0435\u0442 \u0442\u043e\u043b\u044c\u043a\u043e \u043f\u0430\u043a\u0435\u0442\u044b \u0441 <code>packet-mark=vpn-traffic<\/code> \u0438\u0437 main-\u0442\u0430\u0431\u043b\u0438\u0446\u044b \u0432 <code>vpn-table<\/code>;<\/li>\n<li>\u0412 main-\u0442\u0430\u0431\u043b\u0438\u0446\u0443 default \u0447\u0435\u0440\u0435\u0437 \u0442\u0443\u043d\u043d\u0435\u043b\u044c \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0442\u044c <strong>\u043d\u0435\u043b\u044c\u0437\u044f<\/strong> \u2014 \u0438\u043d\u0430\u0447\u0435 \u0432\u0435\u0441\u044c \u0442\u0440\u0430\u0444\u0438\u043a \u0443\u0439\u0434\u0451\u0442 \u0432 VPN.<\/li>\n<\/ul>\n<h3>\u0428\u0430\u0433 3. NAT<\/h3>\n<p>\u0415\u0441\u043b\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u0445\u043e\u0434\u0438\u0442 \u0432\u043e \u0432\u043d\u0435\u0448\u043d\u0438\u0435 \u0441\u0435\u0442\u0438 \u0447\u0435\u0440\u0435\u0437 \u0442\u0443\u043d\u043d\u0435\u043b\u044c:<\/p>\n<pre><code class=\"language-routeros\">\/ip firewall nat\nadd chain=srcnat packet-mark=vpn-traffic out-interface=&lt;vpn_interface&gt; \n    action=masquerade comment=&quot;NAT VPN traffic&quot;\n<\/code><\/pre>\n<p>\u0415\u0441\u043b\u0438 \u0442\u0443\u043d\u043d\u0435\u043b\u044c \u0432\u0435\u0434\u0451\u0442 \u0432 \u0432\u0430\u0448\u0443 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u0443\u044e \u0441\u0435\u0442\u044c (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440 10.0.0.0\/8) \u2014 masquerade \u043d\u0435 \u043d\u0443\u0436\u0435\u043d.<\/p>\n<hr \/>\n<h2>\u0413\u043e\u0442\u043e\u0432\u0430\u044f \u0441\u0445\u0435\u043c\u0430 \u00ab\u043f\u043e\u0434 \u043a\u043b\u044e\u0447\u00bb<\/h2>\n<table>\n<thead>\n<tr>\n<th>\u041f\u0430\u043a\u0435\u0442<\/th>\n<th>\u0413\u0434\u0435 \u0440\u0435\u0448\u0430\u0435\u0442\u0441\u044f<\/th>\n<th>\u0420\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u041e\u0442 <code>myapp<\/code> (UID vpnapp)<\/td>\n<td>iptables OUTPUT mangle<\/td>\n<td>DSCP=46<\/td>\n<\/tr>\n<tr>\n<td>\u041f\u0440\u0438\u0445\u043e\u0434\u0438\u0442 \u0432 LAN \u043d\u0430 Mikrotik<\/td>\n<td>mangle prerouting<\/td>\n<td>connection-mark=vpn-conn<\/td>\n<\/tr>\n<tr>\n<td>\u0422\u043e\u0442 \u0436\u0435 \u043f\u0430\u043a\u0435\u0442<\/td>\n<td>mangle prerouting (\u043f\u043e conn)<\/td>\n<td>packet-mark=vpn-traffic<\/td>\n<\/tr>\n<tr>\n<td>\u041c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0446\u0438\u044f<\/td>\n<td>routing\/rule<\/td>\n<td>main \u2192 vpn-table<\/td>\n<\/tr>\n<tr>\n<td>\u0418\u0441\u0445\u043e\u0434<\/td>\n<td>route vpn-table<\/td>\n<td>gateway=&lt;\u0442\u0443\u043d\u043d\u0435\u043b\u044c&gt;<\/td>\n<\/tr>\n<tr>\n<td>\u0412 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442<\/td>\n<td>NAT srcnat<\/td>\n<td>masquerade<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>\u041f\u043e\u043b\u043d\u044b\u0439 \u043d\u0430\u0431\u043e\u0440 \u043f\u0440\u0430\u0432\u0438\u043b<\/h3>\n<pre><code class=\"language-routeros\"># Mangle\n\/ip firewall mangle\nadd chain=prerouting in-interface=bridge-local dscp=46 \n    action=mark-connection new-connection-mark=vpn-conn pass-through=yes \n    comment=&quot;DSCP 46 -&gt; connection mark&quot;\nadd chain=prerouting in-interface=bridge-local connection-mark=vpn-conn \n    action=mark-packet new-packet-mark=vpn-traffic pass-through=no \n    comment=&quot;conn mark -&gt; packet mark&quot;\n\n# Routing table \u0438 \u043f\u0440\u0430\u0432\u0438\u043b\u043e\n\/ip route\nadd dst-address=0.0.0.0\/0 gateway=wireguard1 routing-table=vpn-table \n    comment=&quot;Default via VPN&quot;\n\n\/routing\/rule\nadd packet-mark=vpn-traffic routing-table=main table=vpn-table \n    comment=&quot;Marked traffic uses vpn-table&quot;\n\n# NAT\n\/ip firewall nat\nadd chain=srcnat packet-mark=vpn-traffic out-interface=wireguard1 \n    action=masquerade comment=&quot;Masq for VPN traffic&quot;\n<\/code><\/pre>\n<p>\u0417\u0430\u043c\u0435\u043d\u0438\u0442\u0435 <code>wireguard1<\/code> \u043d\u0430 \u0432\u0430\u0448 \u0442\u0443\u043d\u043d\u0435\u043b\u044c (WireGuard, OpenVPN, L2TP, PPPoE) \u2014 \u0441\u0445\u0435\u043c\u0430 \u043d\u0435 \u0437\u0430\u0432\u0438\u0441\u0438\u0442 \u043e\u0442 \u0442\u0438\u043f\u0430 \u0442\u0443\u043d\u043d\u0435\u043b\u044f.<\/p>\n<hr \/>\n<h2>\u0412\u044b\u0431\u043e\u0440 DSCP-\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f<\/h2>\n<table>\n<thead>\n<tr>\n<th>\u0417\u043d\u0430\u0447\u0435\u043d\u0438\u0435<\/th>\n<th>\u041a\u043b\u0430\u0441\u0441<\/th>\n<th>\u0414\u043b\u044f \u0447\u0435\u0433\u043e<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>46<\/td>\n<td>EF (Expedited Forwarding)<\/td>\n<td>\u0412\u0438\u0434\u0435\u043e, \u0433\u043e\u043b\u043e\u0441<\/td>\n<\/tr>\n<tr>\n<td>34<\/td>\n<td>AF41<\/td>\n<td>\u0422\u0440\u0435\u0431\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u043d\u043e \u043a \u0437\u0430\u0434\u0435\u0440\u0436\u043a\u0430\u043c<\/td>\n<\/tr>\n<tr>\n<td>26<\/td>\n<td>AF31<\/td>\n<td>\u041e\u0431\u044b\u0447\u043d\u044b\u0439 \u043f\u0440\u0438\u043e\u0440\u0438\u0442\u0435\u0442<\/td>\n<\/tr>\n<tr>\n<td>0<\/td>\n<td>Best Effort<\/td>\n<td>\u0412\u0435\u0441\u044c \u043e\u0441\u0442\u0430\u043b\u044c\u043d\u043e\u0439 \u0442\u0440\u0430\u0444\u0438\u043a<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u0414\u043b\u044f \u0431\u0438\u0437\u043d\u0435\u0441-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u043e\u0431\u044b\u0447\u043d\u043e \u0445\u0432\u0430\u0442\u0430\u0435\u0442 <strong>46<\/strong> (\u0435\u0441\u043b\u0438 \u0432 \u0441\u0435\u0442\u0438 \u043d\u0435\u0442 VoIP, \u043a\u043e\u0442\u043e\u0440\u043e\u043c\u0443 \u043d\u0443\u0436\u043d\u043e \u0431\u043e\u043b\u044c\u0448\u0435\u0435) \u0438\u043b\u0438 <strong>26\/34<\/strong>. \u0412 iptables \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 \u0437\u0430\u0434\u0430\u0451\u0442\u0441\u044f \u0434\u0435\u0441\u044f\u0442\u0438\u0447\u043d\u044b\u043c (<code>--set-dscp 46<\/code>) \u043b\u0438\u0431\u043e \u043a\u043b\u0430\u0441\u0441\u043e\u043c (<code>--set-dscp EF<\/code>). \u0412 nftables \u2014 hex (<code>0x2e<\/code>).<\/p>\n<hr \/>\n<h2>\u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0430<\/h2>\n<ol>\n<li><strong>\u041d\u0430 Ubuntu<\/strong>: <code>sudo tcpdump -i any 'ip dscp 46' -n<\/code> \u2014 \u043f\u0440\u0438 \u0440\u0430\u0431\u043e\u0442\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0432\u0438\u0434\u043d\u044b \u043f\u043e\u043c\u0435\u0447\u0435\u043d\u043d\u044b\u0435 \u043f\u0430\u043a\u0435\u0442\u044b.<\/li>\n<li><strong>\u041d\u0430 Mikrotik<\/strong>: <code>\/tool sniffer quick interface=bridge-local<\/code> + \u0444\u0438\u043b\u044c\u0442\u0440 \u043f\u043e dscp 46, \u043b\u0438\u0431\u043e \u0441\u0447\u0451\u0442\u0447\u0438\u043a\u0438 mangle-\u043f\u0440\u0430\u0432\u0438\u043b (<code>\/ip firewall mangle print stats<\/code>).<\/li>\n<li><strong>\u041c\u0430\u0440\u0448\u0440\u0443\u0442<\/strong>: \u043d\u0430 Ubuntu <code>ip route get &lt;IP_VPN_\u0440\u0435\u0441\u0443\u0440\u0441\u0430&gt;<\/code> \u2014 \u0442\u0440\u0430\u0444\u0438\u043a \u0443\u0445\u043e\u0434\u0438\u0442 \u0447\u0435\u0440\u0435\u0437 \u0448\u043b\u044e\u0437 (\u043e\u0431\u044b\u0447\u043d\u044b\u0439), \u0430 \u0441\u0430\u043c \u043f\u0430\u043a\u0435\u0442 \u0437\u0430\u0432\u043e\u0440\u0430\u0447\u0438\u0432\u0430\u0435\u0442 Mikrotik. \u041d\u0430 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u043f\u0440\u043e\u0432\u0435\u0440\u044c\u0442\u0435, \u0447\u0442\u043e \u0432 \u0442\u0443\u043d\u043d\u0435\u043b\u044c \u043f\u0440\u0438\u0445\u043e\u0434\u044f\u0442 \u043f\u0430\u043a\u0435\u0442\u044b \u0441 DSCP 46: <code>tcpdump -i tun0 ip dscp 46<\/code>.<\/li>\n<\/ol>\n<hr \/>\n<h2>\u0422\u043e\u043d\u043a\u043e\u0441\u0442\u0438 \u0438 \u043f\u043e\u0434\u0432\u043e\u0434\u043d\u044b\u0435 \u043a\u0430\u043c\u043d\u0438<\/h2>\n<ul>\n<li><strong>\u041f\u0440\u0430\u0432\u0438\u043b\u043e \u0432 mangle OUTPUT \u0432\u0438\u0434\u0438\u0442 \u043f\u0430\u043a\u0435\u0442\u044b<\/strong> \u0442\u043e\u043b\u044c\u043a\u043e \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e \u0438\u0441\u0445\u043e\u0434\u044f\u0449\u0438\u0435. \u0415\u0441\u043b\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u043d\u0430 \u0434\u0440\u0443\u0433\u043e\u043c \u0445\u043e\u0441\u0442\u0435 \u0432 \u0441\u0435\u0442\u0438 \u2014 \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u043d\u0443\u0436\u043d\u043e \u0432\u0435\u0448\u0430\u0442\u044c \u043d\u0430 \u0440\u043e\u0443\u0442\u0435\u0440 \u0438\u043b\u0438 \u043d\u0430 \u0442\u043e\u0442 \u0445\u043e\u0441\u0442.<\/li>\n<li><strong>owner-match \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u043f\u043e \u0440\u0435\u0430\u043b\u044c\u043d\u043e\u043c\u0443 UID.<\/strong> \u0415\u0441\u043b\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u0432\u0435\u0448\u0430\u0435\u0442\u0441\u044f \u0438 \u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u0441\u044f \u0441\u043e\u043a\u0435\u0442\u043e\u043c \u043e\u0442 \u0434\u0440\u0443\u0433\u043e\u0433\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\/root, \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u043f\u0435\u0440\u0435\u0441\u0442\u0430\u043d\u0435\u0442 \u043f\u043e\u043f\u0430\u0434\u0430\u0442\u044c. \u0414\u043b\u044f \u0434\u0435\u043c\u043e\u043d\u043e\u0432 \/ systemd-\u044e\u043d\u0438\u0442\u043e\u0432 \u0432\u044b\u0434\u0435\u043b\u044f\u0439\u0442\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u0433\u043e \u044e\u0437\u0435\u0440\u0430.<\/li>\n<li><strong>DSCP \u0442\u0435\u0440\u044f\u0435\u0442\u0441\u044f \u043f\u0440\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0438.<\/strong> \u0415\u0441\u043b\u0438 \u0442\u0443\u043d\u043d\u0435\u043b\u044c \u0442\u0435\u0440\u043c\u0438\u043d\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u043d\u0430 \u0441\u0430\u043c\u043e\u0439 Ubuntu (IPsec\/WireGuard \u043d\u0430 \u043a\u043b\u0438\u0435\u043d\u0442\u0435), \u043c\u0435\u0442\u043a\u0430 \u0432\u043d\u0443\u0442\u0440\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u043f\u0430\u043a\u0435\u0442\u0430 \u043d\u0435 \u0432\u0438\u0434\u043d\u0430 \u0440\u043e\u0443\u0442\u0435\u0440\u0443 \u2014 \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0442\u0443\u043d\u043d\u0435\u043b\u044c \u0434\u043e\u043b\u0436\u0435\u043d \u0442\u0435\u0440\u043c\u0438\u043d\u0438\u0440\u043e\u0432\u0430\u0442\u044c Mikrotik, \u0430 Ubuntu \u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c \u00ab\u0433\u043e\u043b\u043e\u0439\u00bb.<\/li>\n<li><strong>FastTrack \u043d\u0430 Mikrotik<\/strong> \u00ab\u043f\u0440\u043e\u0435\u0437\u0436\u0430\u0435\u0442\u00bb \u043c\u0438\u043c\u043e mangle. \u041e\u0442\u043a\u043b\u044e\u0447\u0438\u0442\u0435 fasttrack \u0434\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0430:<br \/>\n<code>routeros<br \/>\n  \/ip firewall raw<br \/>\n  add chain=prerouting in-interface=bridge-local dscp=46 action=notrack<br \/>\n      comment=\"no fasttrack for dscp46\"<\/code><\/li>\n<li><strong>\u0422\u0435\u043a\u0443\u0449\u0438\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u043d\u0435 \u043f\u0435\u0440\u0435\u0436\u0438\u0432\u0430\u044e\u0442 \u043f\u0435\u0440\u0435\u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0443<\/strong> Ubuntu \u2014 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0439\u0442\u0435 <code>iptables-persistent<\/code> (\u0438\u043b\u0438 <code>nftables<\/code>) \u0438\u0437 \u0440\u0430\u0437\u0434\u0435\u043b\u0430 \u0432\u044b\u0448\u0435.<\/li>\n<li><strong>\u041d\u0430 Wi-Fi-\u043a\u043b\u0438\u0435\u043d\u0442\u0430\u0445<\/strong> AP \u0438 \u0447\u0430\u0441\u0442\u044c \u0440\u043e\u0443\u0442\u0435\u0440\u043e\u0432 \u043c\u043e\u0433\u0443\u0442 \u043f\u0435\u0440\u0435\u043f\u0438\u0441\u044b\u0432\u0430\u0442\u044c DSCP. \u0415\u0441\u043b\u0438 \u0446\u0435\u043b\u044c \u2014 \u043e\u0444\u0438\u0441\u043d\u0430\u044f \u0441\u0435\u0442\u044c \u043f\u043e \u043f\u0440\u043e\u0432\u043e\u0434\u0443, \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u043e\u0431\u044b\u0447\u043d\u043e \u043d\u0435\u0442.<\/li>\n<\/ul>\n<hr \/>\n<h2>\u0412\u044b\u0432\u043e\u0434<\/h2>\n<p>\u041d\u0430 Ubuntu \u0437\u0430\u0434\u0430\u0447\u0430 \u0440\u0435\u0448\u0430\u0435\u0442\u0441\u044f \u0447\u0435\u0440\u0435\u0437 iptables\/nftables \u0441 match \u043f\u043e <code>--uid-owner<\/code> (\u0438\u043b\u0438 \u043f\u043e \u043f\u043e\u0440\u0442\u0443), \u0434\u0430\u043b\u0435\u0435 \u043d\u0430 Mikrotik \u0440\u043e\u0432\u043d\u043e \u0442\u0430 \u0436\u0435 \u0441\u0432\u044f\u0437\u043a\u0430 mangle + routing-rule \u0432 vpn-\u0442\u0430\u0431\u043b\u0438\u0446\u0443, \u0447\u0442\u043e \u0438 \u0432 Windows-\u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0435. \u0422\u0440\u0438 \u043a\u043b\u044e\u0447\u0435\u0432\u044b\u0435 \u0442\u043e\u0447\u043a\u0438 \u0442\u0435 \u0436\u0435: <strong>DSCP \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u0435 \u2192 connection\/packet mark \u0432 mangle \u2192 routing rule \u0432 vpn-\u0442\u0430\u0431\u043b\u0438\u0446\u0443<\/strong>.<\/p>\n<p><em>\u041f\u0440\u043e\u0432\u0435\u0440\u0435\u043d\u043e \u043d\u0430: Ubuntu 24.04\/26.04 + RouterOS 7.<\/em><br \/>\n<em>\u0414\u0430\u0442\u0430: \u0421\u0435\u043d\u0442\u044f\u0431\u0440\u044c 2026.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u041a\u0430\u043a \u043f\u043e\u043c\u0435\u0442\u0438\u0442\u044c DSCP \u0442\u0440\u0430\u0444\u0438\u043a \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u043e\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0432 Ubuntu \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u0442\u044c<\/p>\n","protected":false},"author":0,"featured_media":714,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[3,7],"tags":[],"class_list":["post-713","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux","category-mikrotik"],"aioseo_notices":[],"views":10,"_links":{"self":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/713","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=713"}],"version-history":[{"count":2,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/713\/revisions"}],"predecessor-version":[{"id":716,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/713\/revisions\/716"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/media\/714"}],"wp:attachment":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=713"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=713"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=713"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}