treba takto ?
add chain=forward in-interface=!WAN out-interface=!WAN \
src-address=192.168.6.0/24 dst-address=192.168.6.0/28 action=mark-packet \
new-packet-mark=local1 passthrough=no comment="" disabled=no
add chain=forward in-interface=!WAN out-interface=!WAN \
src-address=192.168.6.0/24 dst-address=192.168.6.16/28 action=mark-packet \
new-packet-mark=local2 passthrough=no comment="" disabled=no samozrejme, by to pokracovalo v dalsich podmaskach, aby sa zavrsil cely subnet 24bit (192.168.6.32/16, 192.168.6.48/16 apod...). Zaroven usery ozaj musia byt "podsietovany", inak si vela nepomozete... Najidealnejsie je tieto subnety mat aj pridane na rozhrani, aby niektory user nevymyslal(dvaja si daju spolocny subnet...), v pripade, ze na APckach nejde zakazat lokalny traffic na HW casti.add chain=forward in-interface=LAN src-address=192.168.6.162 p2p=!all-p2p \
action=mark-packet new-packet-mark=162-net passthrough=no comment="Mustafo \
manual" disabled=no
add chain=forward in-interface=LAN src-address=192.168.6.162 \
action=mark-packet new-packet-mark=162-net-p2p passthrough=no comment="" \
disabled=no
add chain=forward in-interface=WAN dst-address=192.168.6.162 p2p=!all-p2p \
action=mark-packet new-packet-mark=net-162 passthrough=no comment="" disabled=no
add chain=forward in-interface=WAN dst-address=192.168.6.162 action=mark-packet \
new-packet-mark=net-162-p2p passthrough=no comment="" disabled=no
btw, nevyhodou takehoto manglovania internet prevadzky, ako uz Jali spomenul, je mierne komplikovane scitanie dat... I ked nie je to nerealne spravit i taketo scitanie (predpokladam, ze by sa to riesilo asi takto :"passthrough=yes" na celu prevadzku konkretnej IP smerom do a z netu, nastavit patricne marky a potom uz pokracovat tymto uvedenym vyssie...)
Tu som to uz rozoberal, ale nikto ma neuistil, ze to nie je iba moj bug http://forum.promedia.cz/routeros.cz/viewtopic.php?t=95