<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Areksitiung's Blog &#187; Mikrotik</title>
	<atom:link href="http://www.areksitiung.com/category/mikrotik/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.areksitiung.com</link>
	<description>Catat Apa yg Anda Kerjakan, Kerjakan Apa yg Anda Catat;)</description>
	<lastBuildDate>Tue, 03 Nov 2009 12:14:17 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Load Balancing 5 Line Speedy</title>
		<link>http://www.areksitiung.com/2009/06/18/load-balancing-5-line-speedy/</link>
		<comments>http://www.areksitiung.com/2009/06/18/load-balancing-5-line-speedy/#comments</comments>
		<pubDate>Fri, 19 Jun 2009 02:28:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Mikrotik]]></category>

		<guid isPermaLink="false">http://www.areksitiung.com/?p=484</guid>
		<description><![CDATA[  MMM      MMM       KKK                          TTTTTTTTTTT      KKK
  MMMM    MMMM       KKK                          TTTTTTTTTTT      KKK
  MMM MMMM MMM  III  KKK  KKK  RRRRRR     OOOOOO      TTT     III  KKK  KKK
  MMM  MM  MMM  III  KKKKK     RRR  RRR  OOO  OOO     TTT     III  KKKKK
  MMM      MMM  III  KKK KKK   RRRRRR    OOO  OOO     TTT     III  KKK KKK
  MMM      MMM  III  KKK  KKK  RRR  RRR   OOOOOO      [...]]]></description>
			<content:encoded><![CDATA[<p>  MMM      MMM       KKK                          TTTTTTTTTTT      KKK<br />
  MMMM    MMMM       KKK                          TTTTTTTTTTT      KKK<br />
  MMM MMMM MMM  III  KKK  KKK  RRRRRR     OOOOOO      TTT     III  KKK  KKK<br />
  MMM  MM  MMM  III  KKKKK     RRR  RRR  OOO  OOO     TTT     III  KKKKK<br />
  MMM      MMM  III  KKK KKK   RRRRRR    OOO  OOO     TTT     III  KKK KKK<br />
  MMM      MMM  III  KKK  KKK  RRR  RRR   OOOOOO      TTT     III  KKK  KKK</p>
<p>  MikroTik RouterOS 2.9.27 (c) 1999-2006       <a href="http://www.mikrotik.com/">http://www.mikrotik.com/</a></p>
<p>/ interface ethernet</p>
<p>set Local name=&#8221;Local&#8221; mtu=1500 mac-address=00:10:5A:6C:5E:86 arp=enabled disable-running-check=yes auto-negotiation=no \<br />
    full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no<br />
set Speedy1 name=&#8221;Speedy1&#8243; mtu=1500 mac-address=00:10:5A:6C:5F:1C arp=enabled disable-running-check=yes \<br />
    auto-negotiation=no full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no<br />
set Speedy2 name=&#8221;Speedy2&#8243; mtu=1500 mac-address=00:10:4B:11:73:69 arp=enabled disable-running-check=yes \<br />
    auto-negotiation=no full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no<br />
set Speedy3 name=&#8221;Speedy3&#8243; mtu=1500 mac-address=00:10:4B:11:72:44 arp=enabled disable-running-check=yes \<br />
    auto-negotiation=no full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no<br />
set Hotspot name=&#8221;Hotspot&#8221; mtu=1500 mac-address=00:60:97:3D:3C:5F arp=enabled disable-running-check=yes \<br />
    auto-negotiation=no full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no<br />
set Speedy4 name=&#8221;Speedy4&#8243; mtu=1500 mac-address=00:0C:42:1A:2F:84 arp=enabled disable-running-check=yes \<br />
    auto-negotiation=yes full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no<br />
set Speedy5 name=&#8221;Speedy5&#8243; mtu=1500 mac-address=00:0C:42:1A:2F:85 arp=enabled disable-running-check=yes \<br />
    auto-negotiation=yes full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no<br />
set Speedy6 name=&#8221;Speedy6&#8243; mtu=1500 mac-address=00:0C:42:1A:2F:86 arp=enabled disable-running-check=yes \<br />
    auto-negotiation=yes full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no<br />
set Speedy7 name=&#8221;Speedy7&#8243; mtu=1500 mac-address=00:0C:42:1A:2F:87 arp=enabled disable-running-check=yes \<br />
    auto-negotiation=yes full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no</p>
<p>/ interface pppoe-client<br />
add name=&#8221;pppoe-out1&#8243; max-mtu=1480 max-mru=1480 interface=Speedy1 user=&#8221;<a href="mailto:1114021xxxx@telkom.net">1114021xxxx@telkom.net</a>&#8221; password=&#8221;tairinighani&#8221; \<br />
    profile=default service-name=&#8221;" ac-name=&#8221;" add-default-route=yes dial-on-demand=no use-peer-dns=no \<br />
    allow=pap,chap,mschap1,mschap2 disabled=no<br />
add name=&#8221;pppoe-out2&#8243; max-mtu=1480 max-mru=1480 interface=Speedy2 user=&#8221;<a href="mailto:1114021xxxx@telkom.net">1114021xxxx@telkom.net</a>&#8221; password=&#8221;pocarisweat&#8221; \<br />
    profile=default service-name=&#8221;" ac-name=&#8221;" add-default-route=yes dial-on-demand=no use-peer-dns=no \<br />
    allow=pap,chap,mschap1,mschap2 disabled=no<br />
add name=&#8221;pppoe-out3&#8243; max-mtu=1480 max-mru=1480 interface=Speedy3 user=&#8221;<a href="mailto:1114021xxxx@telkom.net">1114021xxxx@telkom.net</a>&#8221; password=&#8221;fnjozz56xq&#8221; \<br />
    profile=default service-name=&#8221;" ac-name=&#8221;" add-default-route=yes dial-on-demand=no use-peer-dns=no \<br />
    allow=pap,chap,mschap1,mschap2 disabled=no<br />
add name=&#8221;pppoe-out4&#8243; max-mtu=1480 max-mru=1480 interface=Speedy5 user=&#8221;<a href="mailto:1114021xxxx@telkom.net">1114021xxxx@telkom.net</a>&#8221; password=&#8221;pocarisweat&#8221; \<br />
    profile=default service-name=&#8221;" ac-name=&#8221;" add-default-route=yes dial-on-demand=no use-peer-dns=no \<br />
    allow=pap,chap,mschap1,mschap2 disabled=no</p>
<p>/ ip dns<br />
set primary-dns=203.130.193.74 secondary-dns=202.134.0.155 allow-remote-requests=yes cache-size=2048KiB cache-max-ttl=1w</p>
<p>/ ip dns static<br />
add name=&#8221;<a href="http://www.palimo.net">www.palimo.net</a>&#8221; address=192.168.6.1 ttl=1d</p>
<p>/ ip address<br />
add address=192.168.0.254/24 network=192.168.0.0 broadcast=192.168.0.255 interface=Local comment=&#8221;" disabled=no<br />
add address=192.168.2.2/24 network=192.168.2.0 broadcast=192.168.2.255 interface=Speedy1 comment=&#8221;" disabled=no<br />
add address=192.168.3.2/24 network=192.168.3.0 broadcast=192.168.3.255 interface=Speedy2 comment=&#8221;" disabled=no<br />
add address=192.168.4.2/24 network=192.168.4.0 broadcast=192.168.4.255 interface=Speedy3 comment=&#8221;" disabled=no<br />
add address=192.168.5.2/24 network=192.168.5.0 broadcast=192.168.5.255 interface=Speedy4 comment=&#8221;" disabled=no<br />
add address=192.168.6.1/24 network=192.168.6.0 broadcast=192.168.6.255 interface=Hotspot comment=&#8221;" disabled=no<br />
add address=192.168.7.2/24 network=192.168.7.0 broadcast=192.168.7.255 interface=Speedy5 comment=&#8221;" disabled=no<br />
add address=192.168.8.2/24 network=192.168.8.0 broadcast=192.168.8.255 interface=Speedy6 comment=&#8221;" disabled=no<br />
add address=192.168.9.2/24 network=192.168.9.0 broadcast=192.168.9.255 interface=Speedy7 comment=&#8221;" disabled=no</p>
<p>/ ip route<br />
add dst-address=0.0.0.0/0 gateway=125.162.84.1 scope=255 target-scope=10 routing-mark=speedy1 comment=&#8221;" disabled=no<br />
add dst-address=0.0.0.0/0 gateway=125.162.88.1 scope=255 target-scope=10 routing-mark=speedy2 comment=&#8221;" disabled=no<br />
add dst-address=0.0.0.0/0 gateway=125.165.156.1 scope=255 target-scope=10 routing-mark=speedy3 comment=&#8221;" disabled=no<br />
add dst-address=0.0.0.0/0 gateway=192.168.5.1 scope=255 target-scope=10 routing-mark=speedy4 comment=&#8221;" disabled=no<br />
add dst-address=0.0.0.0/0 gateway=125.165.104.1 scope=255 target-scope=10 routing-mark=speedy5 comment=&#8221;" disabled=no<br />
add dst-address=0.0.0.0/0 gateway=125.162.80.1 scope=255 target-scope=10 routing-mark=speedy6 comment=&#8221;" disabled=no<br />
add dst-address=0.0.0.0/0 gateway=125.162.82.1 scope=255 target-scope=10 routing-mark=speedy7 comment=&#8221;" disabled=no</p>
<p>/ ip firewall mangle<br />
add chain=prerouting in-interface=Local connection-state=new nth=4,1,0 action=mark-connection new-connection-mark=speedy1 \<br />
    passthrough=yes comment=&#8221;LoadBalancing 4 Line Speedy&#8221; disabled=no<br />
add chain=prerouting in-interface=Local connection-mark=speedy1 action=mark-routing new-routing-mark=speedy1 \<br />
    passthrough=no comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-state=new nth=4,1,1 action=mark-connection new-connection-mark=speedy2 \<br />
    passthrough=yes comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-mark=speedy2 action=mark-routing new-routing-mark=speedy2 \<br />
    passthrough=no comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-state=new nth=4,1,2 action=mark-connection new-connection-mark=speedy3 \<br />
    passthrough=yes comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-mark=speedy3 action=mark-routing new-routing-mark=speedy3 \<br />
    passthrough=no comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-state=new nth=4,1,3 action=mark-connection new-connection-mark=speedy4 \<br />
    passthrough=yes comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-mark=speedy4 action=mark-routing new-routing-mark=speedy4 \<br />
    passthrough=no comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-state=new nth=4,1,4 action=mark-connection new-connection-mark=speedy5 \<br />
    passthrough=yes comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-mark=speedy5 action=mark-routing new-routing-mark=speedy5 \<br />
    passthrough=no comment=&#8221;" disabled=no</p>
<p>/ ip firewall nat<br />
add chain=srcnat connection-mark=speedy1 action=src-nat to-addresses=125.162.84.xx to-ports=0-65535 comment=&#8221;NAT 2 CLIENT \<br />
    5 LINE SPEEDY&#8221; disabled=no<br />
add chain=srcnat connection-mark=speedy2 action=src-nat to-addresses=125.162.88.xx to-ports=0-65535 comment=&#8221;" disabled=no<br />
add chain=srcnat connection-mark=speedy3 action=src-nat to-addresses=125.165.158.xx to-ports=0-65535 comment=&#8221;" \<br />
    disabled=no<br />
add chain=srcnat src-address=192.168.6.0/24 action=masquerade comment=&#8221;Masquerade Network Hotspot &#8221; disabled=no<br />
add chain=srcnat connection-mark=speedy4 action=src-nat to-addresses=192.168.5.2 to-ports=0-65535 comment=&#8221;" disabled=no<br />
add chain=srcnat connection-mark=speedy5 action=src-nat to-addresses=125.165.110.xxx to-ports=0-65535 comment=&#8221;" \<br />
    disabled=no</p>
<p>/ ip firewall filter<br />
add chain=input connection-state=established action=accept comment=&#8221;Connection State&#8221; disabled=yes<br />
add chain=input connection-state=related action=accept comment=&#8221;" disabled=yes<br />
add chain=input protocol=icmp limit=50/5s,2 action=accept comment=&#8221;" disabled=yes<br />
add chain=input connection-state=invalid action=drop comment=&#8221;" disabled=yes<br />
add chain=forward src-address=0.0.0.0/8 action=drop comment=&#8221;Block Bogus IP Address&#8221; disabled=no<br />
add chain=forward dst-address=0.0.0.0/8 action=drop comment=&#8221;" disabled=no<br />
add chain=forward src-address=127.0.0.0/8 action=drop comment=&#8221;" disabled=no<br />
add chain=forward dst-address=127.0.0.0/8 action=drop comment=&#8221;" disabled=no<br />
add chain=forward src-address=224.0.0.0/3 action=drop comment=&#8221;" disabled=no<br />
add chain=forward dst-address=224.0.0.0/3 action=drop comment=&#8221;" disabled=no<br />
add chain=forward protocol=icmp icmp-options=11:0 action=drop comment=&#8221;Drop Traceroute&#8221; disabled=no<br />
add chain=forward protocol=icmp icmp-options=3:3 action=drop comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp dst-port=22 src-address-list=ssh_blacklist action=drop comment=&#8221;Drop SSH brute forcers&#8221; \<br />
    disabled=no<br />
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=ssh_stage3 action=add-src-to-address-list \<br />
    address-list=ssh_blacklist address-list-timeout=1w3d comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=ssh_stage2 action=add-src-to-address-list \<br />
    address-list=ssh_stage3 address-list-timeout=1m comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=ssh_stage1 action=add-src-to-address-list \<br />
    address-list=ssh_stage2 address-list-timeout=1m comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp dst-port=22 connection-state=new action=add-src-to-address-list address-list=ssh_stage1 \<br />
    address-list-timeout=1m comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp psd=21,3s,3,1 action=add-src-to-address-list address-list=&#8221;port scanners&#8221; \<br />
    address-list-timeout=2w comment=&#8221;Port Scanners to list &#8221; disabled=no<br />
add chain=input protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-address-list address-list=&#8221;port \<br />
    scanners&#8221; address-list-timeout=2w comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp tcp-flags=fin,syn action=add-src-to-address-list address-list=&#8221;port scanners&#8221; \<br />
    address-list-timeout=2w comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp tcp-flags=syn,rst action=add-src-to-address-list address-list=&#8221;port scanners&#8221; \<br />
    address-list-timeout=2w comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack action=add-src-to-address-list address-list=&#8221;port \<br />
    scanners&#8221; address-list-timeout=2w comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg action=add-src-to-address-list address-list=&#8221;port scanners&#8221; \<br />
    address-list-timeout=2w comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-address-list address-list=&#8221;port \<br />
    scanners&#8221; address-list-timeout=2w comment=&#8221;" disabled=no<br />
add chain=input src-address-list=&#8221;port scanners&#8221; action=drop comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp dst-port=21 src-address-list=ftp_blacklist action=drop comment=&#8221;Filter FTP to Box&#8221; \<br />
    disabled=no<br />
add chain=output protocol=tcp content=&#8221;530 Login incorrect&#8221; dst-limit=1/1m,9,dst-address/1m action=accept comment=&#8221;" \<br />
    disabled=no<br />
add chain=output protocol=tcp content=&#8221;530 Login incorrect&#8221; action=add-dst-to-address-list address-list=ftp_blacklist \<br />
    address-list-timeout=3h comment=&#8221;" disabled=no<br />
add chain=forward protocol=tcp action=jump jump-target=tcp comment=&#8221;Separate Protocol into Chains&#8221; disabled=no<br />
add chain=forward protocol=udp action=jump jump-target=udp comment=&#8221;" disabled=no<br />
add chain=forward protocol=icmp action=jump jump-target=icmp comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp action=jump jump-target=tcp comment=&#8221;" disabled=no<br />
add chain=input protocol=udp action=jump jump-target=udp comment=&#8221;" disabled=no<br />
add chain=udp protocol=udp dst-port=69 action=drop comment=&#8221;Blocking UDP Packet&#8221; disabled=no<br />
add chain=udp protocol=udp dst-port=111 action=drop comment=&#8221;" disabled=no<br />
add chain=udp protocol=udp dst-port=135 action=drop comment=&#8221;" disabled=no<br />
add chain=udp protocol=udp dst-port=445 action=drop comment=&#8221;" disabled=no<br />
add chain=udp protocol=udp dst-port=137-139 action=drop comment=&#8221;" disabled=no<br />
add chain=udp protocol=udp dst-port=2049 action=drop comment=&#8221;" disabled=no<br />
add chain=udp protocol=udp dst-port=3133 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=25 action=drop comment=&#8221;Bloking TCP Packet&#8221; disabled=no<br />
add chain=tcp protocol=tcp dst-port=69 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=111 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=137-139 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=135 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=119 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=445 action=add-src-to-address-list address-list=conficker address-list-timeout=5m \<br />
    comment=&#8221;&#8212;&#8212;&#8212;&#8212; Virus &#8212; Conficker&#8221; disabled=no<br />
add chain=tcp protocol=tcp dst-port=445 action=drop comment=&#8221;&#8212;&#8212;&#8212;&#8212; Virus &#8212; Conficker&#8221; disabled=no<br />
add chain=tcp protocol=tcp dst-port=2049 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=12345-12346 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=20034 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=3133 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=67-68 action=drop comment=&#8221;" disabled=no<br />
add chain=icmp protocol=icmp icmp-options=0:0-255 limit=5,5 action=accept comment=&#8221;Limited Ping Flood&#8221; disabled=no<br />
add chain=icmp protocol=icmp icmp-options=8:0-255 limit=5,5 action=accept comment=&#8221;" disabled=no<br />
add chain=icmp protocol=icmp icmp-options=3:3 limit=5,5 action=accept comment=&#8221;" disabled=no<br />
add chain=icmp protocol=icmp icmp-options=11:0-255 limit=5,5 action=accept comment=&#8221;" disabled=no<br />
add chain=icmp protocol=icmp icmp-options=3:4 limit=5,5 action=accept comment=&#8221;" disabled=no<br />
add chain=input dst-address-type=broadcast action=accept comment=&#8221;Allow Broadcast Traffic&#8221; disabled=no</p>
]]></content:encoded>
			<wfw:commentRss>http://www.areksitiung.com/2009/06/18/load-balancing-5-line-speedy/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Load Balancing 4 Line Speedy</title>
		<link>http://www.areksitiung.com/2009/05/11/load-balancing-4-line-speedy/</link>
		<comments>http://www.areksitiung.com/2009/05/11/load-balancing-4-line-speedy/#comments</comments>
		<pubDate>Mon, 11 May 2009 04:07:52 +0000</pubDate>
		<dc:creator>harinto</dc:creator>
				<category><![CDATA[Mikrotik]]></category>

		<guid isPermaLink="false">http://harinto.wordpress.com/?p=471</guid>
		<description><![CDATA[MMM      MMM       KKK                          TTTTTTTTTTT      KKK
MMMM    MMMM       KKK                          TTTTTTTTTTT      KKK
MMM MMMM MMM  III  KKK  KKK  RRRRRR     OOOOOO      TTT     III  KKK  KKK
MMM  MM  MMM  III  KKKKK     RRR  RRR  OOO  OOO     TTT     III  KKKKK
MMM      MMM  III  KKK KKK   RRRRRR    OOO  OOO     TTT     III  KKK KKK
MMM      MMM  III  KKK  KKK  RRR  RRR   OOOOOO      TTT     III  KKK  KKK
# may/11/2009 10:24:04 [...]]]></description>
			<content:encoded><![CDATA[<p>MMM      MMM       KKK                          TTTTTTTTTTT      KKK<br />
MMMM    MMMM       KKK                          TTTTTTTTTTT      KKK<br />
MMM MMMM MMM  III  KKK  KKK  RRRRRR     OOOOOO      TTT     III  KKK  KKK<br />
MMM  MM  MMM  III  KKKKK     RRR  RRR  OOO  OOO     TTT     III  KKKKK<br />
MMM      MMM  III  KKK KKK   RRRRRR    OOO  OOO     TTT     III  KKK KKK<br />
MMM      MMM  III  KKK  KKK  RRR  RRR   OOOOOO      TTT     III  KKK  KKK</p>
<p># may/11/2009 10:24:04 by RouterOS 2.9.27<br />
# software id = 2RS9-M0T<br />
#</p>
<p>/ interface ethernet<br />
set Local name=&#8221;Local&#8221; mtu=1500 mac-address=00:10:5A:6C:5E:86 arp=enabled disable-running-check=yes auto-negotiation=no \<br />
full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no<br />
set Speedy1 name=&#8221;Speedy1&#8243; mtu=1500 mac-address=00:10:5A:6C:5F:1C arp=enabled disable-running-check=yes \<br />
auto-negotiation=no full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no<br />
set Speedy2 name=&#8221;Speedy2&#8243; mtu=1500 mac-address=00:10:4B:11:73:69 arp=enabled disable-running-check=yes \<br />
auto-negotiation=no full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no<br />
set Speedy3 name=&#8221;Speedy3&#8243; mtu=1500 mac-address=00:10:4B:11:72:44 arp=enabled disable-running-check=yes \<br />
auto-negotiation=no full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no<br />
set Speedy4 name=&#8221;Speedy4&#8243; mtu=1500 mac-address=00:10:4B:11:72:3B arp=enabled disable-running-check=yes \<br />
auto-negotiation=no full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no<br />
set Hotspot name=&#8221;Hotspot&#8221; mtu=1500 mac-address=00:60:97:3D:3C:5F arp=enabled disable-running-check=yes \<br />
auto-negotiation=no full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no</p>
<p>/ interface pppoe-client<br />
add name=&#8221;pppoe-out1&#8243; max-mtu=1480 max-mru=1480 interface=Speedy1 user=&#8221;11140xxxxx@telkom.net&#8221; password=&#8221;xxxxx&#8221; \<br />
profile=default service-name=&#8221;" ac-name=&#8221;" add-default-route=yes dial-on-demand=no use-peer-dns=no \<br />
allow=pap,chap,mschap1,mschap2 disabled=no<br />
add name=&#8221;pppoe-out2&#8243; max-mtu=1480 max-mru=1480 interface=Speedy2 user=&#8221;11140xxxxx@telkom.net&#8221; password=&#8221;xxxxx&#8221; \<br />
profile=default service-name=&#8221;" ac-name=&#8221;" add-default-route=yes dial-on-demand=no use-peer-dns=no \<br />
allow=pap,chap,mschap1,mschap2 disabled=no<br />
add name=&#8221;pppoe-out3&#8243; max-mtu=1480 max-mru=1480 interface=Speedy3 user=&#8221;11140xxxxx@telkom.net&#8221; password=&#8221;xxxxx&#8221; \<br />
profile=default service-name=&#8221;" ac-name=&#8221;" add-default-route=yes dial-on-demand=no use-peer-dns=no \<br />
allow=pap,chap,mschap1,mschap2 disabled=no</p>
<p>/ ip dns<br />
set primary-dns=203.130.193.74 secondary-dns=202.134.0.155 allow-remote-requests=yes cache-size=2048KiB cache-max-ttl=1w</p>
<p>/ ip dns static<br />
add name=&#8221;router.palimo.net&#8221; address=192.168.0.254 ttl=1d</p>
<p>/ ip traffic-flow<br />
set enabled=no interfaces=all cache-entries=4k active-flow-timeout=30m inactive-flow-timeout=15s</p>
<p>/ ip address<br />
add address=192.168.0.254/24 network=192.168.0.0 broadcast=192.168.0.255 interface=Local comment=&#8221;" disabled=no<br />
add address=192.168.2.2/24 network=192.168.2.0 broadcast=192.168.2.255 interface=Speedy1 comment=&#8221;" disabled=no<br />
add address=192.168.3.2/24 network=192.168.3.0 broadcast=192.168.3.255 interface=Speedy2 comment=&#8221;" disabled=no<br />
add address=192.168.4.2/24 network=192.168.4.0 broadcast=192.168.4.255 interface=Speedy3 comment=&#8221;" disabled=no<br />
add address=192.168.5.2/24 network=192.168.5.0 broadcast=192.168.5.255 interface=Speedy4 comment=&#8221;" disabled=no<br />
add address=192.168.6.1/24 network=192.168.6.0 broadcast=192.168.6.255 interface=Hotspot comment=&#8221;" disabled=no</p>
<p>/ ip route<br />
add dst-address=0.0.0.0/0 gateway=125.162.84.1 scope=255 target-scope=10 routing-mark=speedy1 comment=&#8221;" disabled=no<br />
add dst-address=0.0.0.0/0 gateway=125.162.88.1 scope=255 target-scope=10 routing-mark=speedy2 comment=&#8221;" disabled=no<br />
add dst-address=0.0.0.0/0 gateway=125.165.156.1 scope=255 target-scope=10 routing-mark=speedy3 comment=&#8221;" disabled=no<br />
add dst-address=0.0.0.0/0 gateway=192.168.5.1 scope=255 target-scope=10 routing-mark=speedy4 comment=&#8221;" disabled=no</p>
<p>/ ip firewall mangle<br />
add chain=prerouting in-interface=Local connection-state=new nth=3,4,0 action=mark-connection new-connection-mark=speedy1 \<br />
passthrough=yes comment=&#8221;LB 4 Line Speedy&#8221; disabled=no<br />
add chain=prerouting in-interface=Local connection-mark=speedy1 action=mark-routing new-routing-mark=speedy1 \<br />
passthrough=no comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-state=new nth=3,4,1 action=mark-connection new-connection-mark=speedy2 \<br />
passthrough=yes comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-mark=speedy2 action=mark-routing new-routing-mark=speedy2 \<br />
passthrough=no comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-state=new nth=3,4,2 action=mark-connection new-connection-mark=speedy3 \<br />
passthrough=yes comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-mark=speedy3 action=mark-routing new-routing-mark=speedy3 \<br />
passthrough=no comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-state=new nth=3,4,3 action=mark-connection new-connection-mark=speedy4 \<br />
passthrough=yes comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-mark=speedy4 action=mark-routing new-routing-mark=speedy4 \<br />
passthrough=no comment=&#8221;" disabled=no</p>
<p>/ ip firewall nat<br />
add chain=srcnat connection-mark=speedy1 action=src-nat to-addresses=125.162.84.155 to-ports=0-65535 comment=&#8221;NAT 2 CLIENT \<br />
4 LINE SPEEDY&#8221; disabled=no<br />
add chain=srcnat connection-mark=speedy2 action=src-nat to-addresses=125.162.88.93 to-ports=0-65535 comment=&#8221;" disabled=no<br />
add chain=srcnat connection-mark=speedy3 action=src-nat to-addresses=125.165.158.18 to-ports=0-65535 comment=&#8221;" \<br />
disabled=no<br />
add chain=srcnat connection-mark=speedy4 action=src-nat to-addresses=192.168.5.2 to-ports=0-65535 comment=&#8221;" disabled=no<br />
add chain=srcnat src-address=192.168.6.0/24 action=masquerade comment=&#8221;masquerade hotspot network&#8221; disabled=no</p>
]]></content:encoded>
			<wfw:commentRss>http://www.areksitiung.com/2009/05/11/load-balancing-4-line-speedy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Load Balancing 3 Line Speedy</title>
		<link>http://www.areksitiung.com/2009/05/10/load-balancing-3-line-speedy-2/</link>
		<comments>http://www.areksitiung.com/2009/05/10/load-balancing-3-line-speedy-2/#comments</comments>
		<pubDate>Sun, 10 May 2009 09:45:02 +0000</pubDate>
		<dc:creator>harinto</dc:creator>
				<category><![CDATA[Mikrotik]]></category>

		<guid isPermaLink="false">http://harinto.wordpress.com/?p=467</guid>
		<description><![CDATA[Mencoba berbagi pengalaman karena baru saja disuruh load balancing 3 line speedy dengan mikrotik. Walaupun mungkin bisa dikatakan belum sempurna, tapi tidak ada salahnya tho bagi-ilmu?? 
Load balancing yang coba aku bahas saat ini dilakukan pada mikrotik 2.9 (Jadul euy) yang diinstall pada PC pentium 3 dengan ethernet card sebanyak 4 buah yang diinstal di [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-178" title="ilustrasi_mikrotik_speedy" src="http://infonesia.info/wp-content/uploads/2009/01/ilustrasi_mikrotik_speedy.jpg" alt="ilustrasi_mikrotik_speedy" width="165" height="148" align="left" />Mencoba berbagi pengalaman karena baru saja disuruh load balancing 3 line speedy dengan mikrotik. Walaupun mungkin bisa dikatakan belum sempurna, tapi tidak ada salahnya <em>tho</em> bagi-ilmu?? <img class="wp-smiley" src="http://infonesia.info/wp-includes/images/smilies/icon_biggrin.gif" alt=":D" /></p>
<p>Load balancing yang coba aku bahas saat ini dilakukan pada mikrotik 2.9 (Jadul euy) yang diinstall pada PC pentium 3 dengan ethernet card sebanyak 4 buah yang diinstal di slot PCI.</p>
<p>Gambaran topologi yang aku tulis seperti ini :</p>
<p><img class="alignnone size-full wp-image-190" title="topology-balancing" src="http://infonesia.info/wp-content/uploads/2009/05/topology-balancing.jpg" alt="topology-balancing" width="356" height="414" /></p>
<p>Langkah-langkah load balancing :</p>
<ol>
<li>Ubah IP dan Nama interface ethernet tiap port ehternet seperti contoh gambar di atas.<br />
Ex : Ether1 -&gt; Nama interface diganti menjadi “local” dan IP di set 192.168.10.1/24</li>
<li>Mulai dengan menambah  gateway di mikrotik
<div class="wp_syntax">
<div class="code">
<pre class="dos" style="font-family:monospace;">ip route add dst-address=0.0.0.0/<span style="color:#cc66cc;">0</span> gateway 192.168.1.1 scope=<span style="color:#cc66cc;">255</span> target-scope=<span style="color:#cc66cc;">10</span> routing-mark=satu comment="" disabled=no

ip route add dst-address=0.0.0.0/<span style="color:#cc66cc;">0</span> gateway 192.168.2.1 scope=<span style="color:#cc66cc;">255</span> target-scope=<span style="color:#cc66cc;">10</span> routing-mark=dua comment="" disabled=no

ip route add dst-address=0.0.0.0/<span style="color:#cc66cc;">0</span> gateway 192.168.3.1 scope=<span style="color:#cc66cc;">255</span> target-scope=<span style="color:#cc66cc;">10</span> routing-mark=tiga comment="" disabled=no</pre>
</div>
</div>
</li>
<li>Dilanjutkan dengan menggunakan ip firewall mangle
<div class="wp_syntax">
<div class="code">
<pre class="dos" style="font-family:monospace;">ip firewall mangle

add chain=prerouting in-interface=local connection-state=new nth=<span style="color:#cc66cc;">2</span>,<span style="color:#cc66cc;">3</span>,<span style="color:#cc66cc;">0</span> action=mark-connection new-connection-mark=satu passtrough=yes comment="load balancing" disabled=no

add chain=prerouting in-interface=local connection-mark=satu action=mark-routing new-routing-mark=satu passthrough=no comment="" disabled=no

add chain=prerouting in-interface=local connection-state=new nth=<span style="color:#cc66cc;">2</span>,<span style="color:#cc66cc;">3</span>,<span style="color:#cc66cc;">1</span> action=mark-connection new-connection-mark=dua passtrough=yes comment="" disabled=no

add chain=prerouting in-interface=local connection-mark=dua action=mark-routing new-routing-mark=dua passthrough=no comment="" disabled=no

add chain=prerouting in-interface=local connection-state=new nth=<span style="color:#cc66cc;">2</span>,<span style="color:#cc66cc;">3</span>,<span style="color:#cc66cc;">2</span> action=mark-connection new-connection-mark=tiga passtrough=yes comment="" disabled=no

add chain=prerouting in-interface=local connection-mark=tiga action=mark-routing new-routing-mark=tiga passthrough=no comment="" disabled=no</pre>
</div>
</div>
</li>
<li>dan yan terakhir dengan proses NAT
<div class="wp_syntax">
<div class="code">
<pre class="dos" style="font-family:monospace;">ip firewall nat add chain=srcnat out-interface=speedy1 action=masquerade

ip firewall nat add chain=srcnat out-interface=speedy2 action=masquerade

ip firewall nat add chain=srcnat out-interface=speedy3 action=masquerade</pre>
</div>
</div>
</li>
</ol>
<p>Selamat mencoba… <img class="wp-smiley" src="http://infonesia.info/wp-includes/images/smilies/icon_smile.gif" alt=":)" /></p>
<p>Sumber : http://infonesia.info</p>
]]></content:encoded>
			<wfw:commentRss>http://www.areksitiung.com/2009/05/10/load-balancing-3-line-speedy-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Load Balancing 3 Line Speedy</title>
		<link>http://www.areksitiung.com/2009/04/22/load-balancing-3-line-speedy/</link>
		<comments>http://www.areksitiung.com/2009/04/22/load-balancing-3-line-speedy/#comments</comments>
		<pubDate>Wed, 22 Apr 2009 03:27:15 +0000</pubDate>
		<dc:creator>harinto</dc:creator>
				<category><![CDATA[Mikrotik]]></category>

		<guid isPermaLink="false">http://harinto.wordpress.com/?p=455</guid>
		<description><![CDATA[MMM      MMM       KKK                          TTTTTTTTTTT      KKK
MMMM    MMMM      [...]]]></description>
			<content:encoded><![CDATA[<p>MMM      MMM       KKK                          TTTTTTTTTTT      KKK<br />
MMMM    MMMM       KKK                          TTTTTTTTTTT      KKK<br />
MMM MMMM MMM  III  KKK  KKK  RRRRRR     OOOOOO      TTT     III  KKK  KKK<br />
MMM  MM  MMM  III  KKKKK     RRR  RRR  OOO  OOO     TTT     III  KKKKK<br />
MMM      MMM  III  KKK KKK   RRRRRR    OOO  OOO     TTT     III  KKK KKK<br />
MMM      MMM  III  KKK  KKK  RRR  RRR   OOOOOO      TTT     III  KKK  KKK</p>
<p>MikroTik RouterOS 2.9.27 (c) 1999-2006       http://www.mikrotik.com/</p>
<p>/ interface ethernet<br />
set Local name=&#8221;Local&#8221; mtu=1500 mac-address=0A:C0:18:1A:3C:8A arp=enabled disable-running-check=yes auto-negotiation=no \<br />
full-duplex=yes cable-settings=default speed=100Mbps comment=&#8221;" disabled=no<br />
set Speedy1 name=&#8221;Speedy1&#8243; mtu=1500 mac-address=0A:C0:18:1A:3C:75 arp=enabled disable-running-check=yes \<br />
auto-negotiation=no full-duplex=yes cable-settings=default speed=1Gbps comment=&#8221;" disabled=no<br />
set Speedy2 name=&#8221;Speedy2&#8243; mtu=1500 mac-address=C0:10:18:C0:30:94 arp=enabled disable-running-check=yes \<br />
auto-negotiation=no full-duplex=yes cable-settings=default speed=1Gbps comment=&#8221;" disabled=no<br />
set Speedy3 name=&#8221;Speedy3&#8243; mtu=1500 mac-address=00:0C:6E:D3:0D:FC arp=enabled disable-running-check=yes \<br />
auto-negotiation=no full-duplex=yes cable-settings=default speed=1Gbps comment=&#8221;" disabled=no<br />
/ interface l2tp-server server<br />
set enabled=no max-mtu=1460 max-mru=1460 authentication=pap,chap,mschap1,mschap2 default-profile=default-encryption<br />
/ interface pptp-server<br />
add name=&#8221;vpn&#8221; user=&#8221;" disabled=no<br />
/ interface pptp-server server<br />
set enabled=yes max-mtu=1460 max-mru=1460 authentication=mschap1,mschap2 keepalive-timeout=30 default-profile=vpn<br />
/ interface pppoe-client<br />
add name=&#8221;pppoe-out1&#8243; max-mtu=1480 max-mru=1480 interface=Speedy2 user=&#8221;111401104174@telkom.net&#8221; password=&#8221;sttlqg13mc&#8221; \<br />
profile=default service-name=&#8221;" ac-name=&#8221;" add-default-route=yes dial-on-demand=no use-peer-dns=no \<br />
allow=pap,chap,mschap1,mschap2 disabled=no<br />
/ ip pool<br />
add name=&#8221;dhcp_pool1&#8243; ranges=10.2.1.1-10.2.1.252,10.2.1.254<br />
add name=&#8221;vpn&#8221; ranges=172.16.1.1-172.16.1.6<br />
/ ip accounting<br />
set enabled=no account-local-traffic=no threshold=256<br />
/ ip accounting web-access<br />
set accessible-via-web=no address=0.0.0.0/0<br />
/ ip service<br />
set telnet port=23 address=0.0.0.0/0 disabled=yes<br />
set ftp port=21 address=0.0.0.0/0 disabled=yes<br />
set www port=7479 address=0.0.0.0/0 disabled=no<br />
set ssh port=1981 address=0.0.0.0/0 disabled=no<br />
set www-ssl port=443 address=0.0.0.0/0 certificate=none disabled=yes<br />
/ ip upnp<br />
set enabled=no allow-disable-external-interface=yes show-dummy-rule=yes<br />
/ ip arp<br />
/ ip socks<br />
set enabled=no port=1080 connection-idle-timeout=2m max-connections=200<br />
/ ip dns<br />
set primary-dns=203.130.193.74 secondary-dns=202.134.0.155 allow-remote-requests=yes cache-size=2048KiB cache-max-ttl=1w<br />
/ ip dns static<br />
add name=&#8221;www.ktr-pjk-pdg.org&#8221; address=10.2.1.253 ttl=1d<br />
/ ip traffic-flow<br />
set enabled=no interfaces=all cache-entries=4k active-flow-timeout=30m inactive-flow-timeout=15s<br />
/ ip address<br />
add address=10.2.1.253/24 network=10.2.1.0 broadcast=10.2.1.255 interface=Local comment=&#8221;" disabled=no<br />
add address=192.168.1.2/24 network=192.168.1.0 broadcast=192.168.1.255 interface=Speedy1 comment=&#8221;" disabled=no<br />
add address=192.168.2.2/24 network=192.168.2.0 broadcast=192.168.2.255 interface=Speedy2 comment=&#8221;" disabled=no<br />
add address=192.168.3.2/24 network=192.168.3.0 broadcast=192.168.3.255 interface=Speedy3 comment=&#8221;" disabled=no<br />
add address=172.16.1.1/29 network=172.16.1.0 broadcast=172.16.1.7 interface=Local comment=&#8221;" disabled=no<br />
/ ip proxy<br />
set enabled=no port=8080 parent-proxy=0.0.0.0:0 maximal-client-connecions=1000 maximal-server-connectons=1000<br />
/ ip proxy access<br />
add dst-port=23-25 action=deny comment=&#8221;block telnet &amp; spam e-mail relaying&#8221; disabled=no<br />
/ ip neighbor discovery<br />
set Local discover=yes<br />
set Speedy1 discover=yes<br />
set Speedy2 discover=yes<br />
set Speedy3 discover=yes<br />
set pppoe-out1 discover=no<br />
set vpn discover=no<br />
/ ip route<br />
add dst-address=0.0.0.0/0 gateway=192.168.1.1 scope=255 target-scope=10 routing-mark=speedy1 comment=&#8221;" disabled=no<br />
add dst-address=0.0.0.0/0 gateway=125.165.112.1 scope=255 target-scope=10 routing-mark=speedy2 comment=&#8221;" disabled=no<br />
add dst-address=0.0.0.0/0 gateway=192.168.3.1 scope=255 target-scope=10 routing-mark=speedy3 comment=&#8221;" disabled=no<br />
add dst-address=0.0.0.0/0 gateway=125.165.112.1 scope=255 target-scope=10 comment=&#8221;" disabled=no<br />
/ ip firewall mangle<br />
add chain=prerouting p2p=all-p2p action=mark-connection new-connection-mark=prio_conn_p2p passthrough=yes comment=&#8221;Prio \<br />
P2P&#8221; disabled=yes<br />
add chain=prerouting connection-mark=prio_conn_p2p action=mark-packet new-packet-mark=prio_p2p_packet passthrough=no \<br />
comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=995 action=mark-connection new-connection-mark=prio_conn_download_services \<br />
passthrough=yes comment=&#8221;Prio Download_Services&#8221; disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=143 action=mark-connection new-connection-mark=prio_conn_download_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=993 action=mark-connection new-connection-mark=prio_conn_download_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=995 action=mark-connection new-connection-mark=prio_conn_download_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=25 action=mark-connection new-connection-mark=prio_conn_download_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=80 action=mark-connection new-connection-mark=prio_conn_download_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=20-21 action=mark-connection new-connection-mark=prio_conn_download_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=22 packet-size=1400-1500 action=mark-connection \<br />
new-connection-mark=prio_conn_download_services passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting connection-mark=prio_conn_download_services action=mark-packet new-packet-mark=prio_download_packet \<br />
passthrough=no comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=53 action=mark-connection new-connection-mark=prio_conn_ensign_services \<br />
passthrough=yes comment=&#8221;Prio Ensign_Services&#8221; disabled=yes<br />
add chain=prerouting protocol=udp dst-port=53 action=mark-connection new-connection-mark=prio_conn_ensign_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=icmp action=mark-connection new-connection-mark=prio_conn_ensign_services passthrough=yes \<br />
comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=443 action=mark-connection new-connection-mark=prio_conn_ensign_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=23 action=mark-connection new-connection-mark=prio_conn_ensign_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=80 connection-bytes=0-500000 action=mark-connection \<br />
new-connection-mark=prio_conn_ensign_services passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=8080 action=mark-connection new-connection-mark=prio_conn_ensign_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting connection-mark=prio_conn_ensign_services action=mark-packet new-packet-mark=prio_ensign_packet \<br />
passthrough=no comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=22 packet-size=1400-1500 action=mark-connection \<br />
new-connection-mark=prio_conn_user_services passthrough=yes comment=&#8221;Prio User_Request&#8221; disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=8291 packet-size=1400-1500 action=mark-connection \<br />
new-connection-mark=prio_conn_user_services passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting connection-mark=prio_conn_user_services action=mark-packet new-packet-mark=prio_request_packet \<br />
passthrough=no comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=5100 action=mark-connection new-connection-mark=prio_conn_comm_services \<br />
passthrough=yes comment=&#8221;Prio_Communication&#8221; disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=5050 action=mark-connection new-connection-mark=prio_conn_comm_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=udp dst-port=5060 action=mark-connection new-connection-mark=prio_conn_comm_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=1869 action=mark-connection new-connection-mark=prio_conn_comm_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=1723 action=mark-connection new-connection-mark=prio_conn_comm_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=5190 action=mark-connection new-connection-mark=prio_conn_comm_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=tcp dst-port=6660-7000 action=mark-connection new-connection-mark=prio_conn_comm_services \<br />
passthrough=yes comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=ipencap action=mark-connection new-connection-mark=prio_conn_comm_services passthrough=yes \<br />
comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=gre action=mark-connection new-connection-mark=prio_conn_comm_services passthrough=yes \<br />
comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=ipsec-esp action=mark-connection new-connection-mark=prio_conn_comm_services passthrough=yes \<br />
comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=ipsec-ah action=mark-connection new-connection-mark=prio_conn_comm_services passthrough=yes \<br />
comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=ipip action=mark-connection new-connection-mark=prio_conn_comm_services passthrough=yes \<br />
comment=&#8221;" disabled=yes<br />
add chain=prerouting protocol=encap action=mark-connection new-connection-mark=prio_conn_comm_services passthrough=yes \<br />
comment=&#8221;" disabled=yes<br />
add chain=prerouting connection-mark=prio_conn_comm_services action=mark-packet new-packet-mark=prio_comm_packet \<br />
passthrough=no comment=&#8221;" disabled=yes<br />
add chain=prerouting in-interface=Local connection-state=new nth=2,1,0 action=mark-connection new-connection-mark=speedy1 \<br />
passthrough=yes comment=&#8221;LB 3 Line Speedy&#8221; disabled=no<br />
add chain=prerouting in-interface=Local connection-mark=speedy1 action=mark-routing new-routing-mark=speedy1 \<br />
passthrough=no comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-state=new nth=2,1,1 action=mark-connection new-connection-mark=speedy2 \<br />
passthrough=yes comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-mark=speedy2 action=mark-routing new-routing-mark=speedy2 \<br />
passthrough=no comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-state=new nth=2,1,2 action=mark-connection new-connection-mark=speedy3 \<br />
passthrough=yes comment=&#8221;" disabled=no<br />
add chain=prerouting in-interface=Local connection-mark=speedy3 action=mark-routing new-routing-mark=speedy3 \<br />
passthrough=no comment=&#8221;" disabled=no<br />
/ ip firewall nat<br />
add chain=srcnat connection-mark=speedy1 action=src-nat to-addresses=192.168.1.2 to-ports=0-65535 comment=&#8221;NAT 2 CLIENT&#8221; \<br />
disabled=no<br />
add chain=srcnat connection-mark=speedy2 action=src-nat to-addresses=125.165.115.184 to-ports=0-65535 comment=&#8221;" \<br />
disabled=no<br />
add chain=srcnat connection-mark=speedy3 action=src-nat to-addresses=192.168.3.2 to-ports=0-65535 comment=&#8221;" disabled=no<br />
add chain=srcnat src-address=172.16.1.0/29 action=masquerade comment=&#8221;NAT VPN&#8221; disabled=no<br />
/ ip firewall connection tracking<br />
set enabled=yes tcp-syn-sent-timeout=5s tcp-syn-received-timeout=5s tcp-established-timeout=1d tcp-fin-wait-timeout=10s \<br />
tcp-close-wait-timeout=10s tcp-last-ack-timeout=10s tcp-time-wait-timeout=10s tcp-close-timeout=10s udp-timeout=10s \<br />
udp-stream-timeout=3m icmp-timeout=10s generic-timeout=10m tcp-syncookie=no<br />
/ ip firewall filter<br />
add chain=forward src-address=0.0.0.0/8 action=drop comment=&#8221;Block Bogus IP Address&#8221; disabled=no<br />
add chain=forward dst-address=0.0.0.0/8 action=drop comment=&#8221;" disabled=no<br />
add chain=forward src-address=127.0.0.0/8 action=drop comment=&#8221;" disabled=no<br />
add chain=forward dst-address=127.0.0.0/8 action=drop comment=&#8221;" disabled=no<br />
add chain=forward src-address=224.0.0.0/3 action=drop comment=&#8221;" disabled=no<br />
add chain=forward dst-address=224.0.0.0/3 action=drop comment=&#8221;" disabled=no<br />
add chain=forward src-address=192.168.1.99 protocol=tcp content=www action=drop comment=&#8221;block browsing 1&#8243; disabled=yes<br />
add chain=forward src-address=192.168.1.7 content=!www action=drop comment=&#8221;" disabled=yes<br />
add chain=forward src-address=192.168.1.8 protocol=tcp content=www action=drop comment=&#8221;" disabled=yes<br />
add chain=forward src-address=192.168.1.9 action=drop comment=&#8221;" disabled=yes<br />
add chain=forward src-address=192.168.1.10 content=!www action=drop comment=&#8221;" disabled=yes<br />
add chain=forward src-address=192.168.1.11 protocol=tcp content=www action=drop comment=&#8221;" disabled=yes<br />
add chain=forward src-address=192.168.1.12 protocol=tcp content=www action=drop comment=&#8221;" disabled=yes<br />
add chain=forward src-address=192.168.1.99 protocol=tcp content=http: action=drop comment=&#8221;block browsing 2&#8243; disabled=yes<br />
add chain=forward src-address=192.168.1.4 protocol=tcp content=http: action=drop comment=&#8221;" disabled=yes<br />
add chain=forward src-address=192.168.1.5 protocol=tcp content=http: action=drop comment=&#8221;" disabled=yes<br />
add chain=forward src-address=192.168.1.6 protocol=tcp content=http: action=drop comment=&#8221;" disabled=yes<br />
add chain=forward src-address=192.168.1.7 content=!http: action=drop comment=&#8221;" disabled=yes<br />
add chain=forward src-address=192.168.1.8 protocol=tcp content=http: action=drop comment=&#8221;" disabled=yes<br />
add chain=input src-address=192.168.1.9 action=drop comment=&#8221;" disabled=yes<br />
add chain=input src-address=192.168.1.10 content=!http: action=drop comment=&#8221;" disabled=yes<br />
add chain=forward src-address=192.168.1.11 protocol=tcp content=http: action=drop comment=&#8221;" disabled=yes<br />
add chain=forward src-address=192.168.1.12 protocol=tcp content=http: action=drop comment=&#8221;" disabled=yes<br />
add chain=forward protocol=icmp icmp-options=11:0 action=drop comment=&#8221;Drop Traceroute&#8221; disabled=no<br />
add chain=forward protocol=icmp icmp-options=3:3 action=drop comment=&#8221;Drop Traceroute&#8221; disabled=no<br />
add chain=input protocol=tcp dst-port=22 src-address-list=ssh_blacklist action=drop comment=&#8221;Drop SSH brute forcers&#8221; \<br />
disabled=no<br />
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=ssh_stage3 action=add-src-to-address-list \<br />
address-list=ssh_blacklist address-list-timeout=1w3d comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=ssh_stage2 action=add-src-to-address-list \<br />
address-list=ssh_stage3 address-list-timeout=1m comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=ssh_stage1 action=add-src-to-address-list \<br />
address-list=ssh_stage2 address-list-timeout=1m comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp dst-port=22 connection-state=new action=add-src-to-address-list address-list=ssh_stage1 \<br />
address-list-timeout=1m comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp psd=21,3s,3,1 action=add-src-to-address-list address-list=&#8221;port scanners&#8221; \<br />
address-list-timeout=2w comment=&#8221;Port Scanners to list &#8221; disabled=no<br />
add chain=input protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-address-list address-list=&#8221;port \<br />
scanners&#8221; address-list-timeout=2w comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp tcp-flags=fin,syn action=add-src-to-address-list address-list=&#8221;port scanners&#8221; \<br />
address-list-timeout=2w comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp tcp-flags=syn,rst action=add-src-to-address-list address-list=&#8221;port scanners&#8221; \<br />
address-list-timeout=2w comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack action=add-src-to-address-list address-list=&#8221;port \<br />
scanners&#8221; address-list-timeout=2w comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg action=add-src-to-address-list address-list=&#8221;port scanners&#8221; \<br />
address-list-timeout=2w comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-address-list address-list=&#8221;port \<br />
scanners&#8221; address-list-timeout=2w comment=&#8221;" disabled=no<br />
add chain=input src-address-list=&#8221;port scanners&#8221; action=drop comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp dst-port=21 src-address-list=ftp_blacklist action=drop comment=&#8221;Filter FTP to Box&#8221; \<br />
disabled=no<br />
add chain=output protocol=tcp content=&#8221;530 Login incorrect&#8221; dst-limit=1/1m,9,dst-address/1m action=accept comment=&#8221;" \<br />
disabled=no<br />
add chain=output protocol=tcp content=&#8221;530 Login incorrect&#8221; action=add-dst-to-address-list address-list=ftp_blacklist \<br />
address-list-timeout=3h comment=&#8221;" disabled=no<br />
add chain=forward protocol=tcp action=jump jump-target=tcp comment=&#8221;Separate Protocol into Chains&#8221; disabled=no<br />
add chain=forward protocol=udp action=jump jump-target=udp comment=&#8221;" disabled=no<br />
add chain=forward protocol=icmp action=jump jump-target=icmp comment=&#8221;" disabled=no<br />
add chain=input protocol=tcp action=jump jump-target=tcp comment=&#8221;" disabled=no<br />
add chain=input protocol=udp action=jump jump-target=udp comment=&#8221;" disabled=no<br />
add chain=udp protocol=udp dst-port=69 action=drop comment=&#8221;Blocking UDP Packet&#8221; disabled=no<br />
add chain=udp protocol=udp dst-port=111 action=drop comment=&#8221;" disabled=no<br />
add chain=udp protocol=udp dst-port=135 action=drop comment=&#8221;" disabled=no<br />
add chain=udp protocol=udp dst-port=445 action=drop comment=&#8221;" disabled=no<br />
add chain=udp protocol=udp dst-port=137-139 action=drop comment=&#8221;" disabled=no<br />
add chain=udp protocol=udp dst-port=2049 action=drop comment=&#8221;" disabled=no<br />
add chain=udp protocol=udp dst-port=3133 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=25 action=drop comment=&#8221;Bloking TCP Packet&#8221; disabled=no<br />
add chain=tcp protocol=tcp dst-port=69 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=111 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=137-139 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=135 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=119 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=445 action=drop comment=&#8221;&#8212;&#8212;&#8212;&#8212; Virus &#8212; Conficker&#8221; disabled=no<br />
add chain=tcp protocol=tcp dst-port=2049 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=12345-12346 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=20034 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=3133 action=drop comment=&#8221;" disabled=no<br />
add chain=tcp protocol=tcp dst-port=67-68 action=drop comment=&#8221;" disabled=no<br />
add chain=icmp protocol=icmp icmp-options=0:0-255 limit=5,5 action=accept comment=&#8221;Limited Ping Flood&#8221; disabled=no<br />
add chain=icmp protocol=icmp icmp-options=8:0-255 limit=5,5 action=accept comment=&#8221;" disabled=no<br />
add chain=icmp protocol=icmp icmp-options=3:3 limit=5,5 action=accept comment=&#8221;" disabled=no<br />
add chain=icmp protocol=icmp icmp-options=11:0-255 limit=5,5 action=accept comment=&#8221;" disabled=no<br />
add chain=icmp protocol=icmp icmp-options=3:4 limit=5,5 action=accept comment=&#8221;" disabled=no<br />
add chain=icmp protocol=icmp action=drop comment=&#8221;" disabled=no<br />
add chain=input dst-address-type=broadcast action=accept comment=&#8221;Allow Broadcast Traffic&#8221; disabled=no<br />
add chain=input connection-state=established action=accept comment=&#8221;Connection State&#8221; disabled=no<br />
add chain=input connection-state=related action=accept comment=&#8221;" disabled=no<br />
add chain=input protocol=icmp limit=50/5s,2 action=accept comment=&#8221;" disabled=no<br />
add chain=input connection-state=invalid action=drop comment=&#8221;" disabled=no<br />
/ ip firewall service-port<br />
set ftp ports=21 disabled=yes<br />
set tftp ports=69 disabled=yes<br />
set irc ports=6667 disabled=yes<br />
set h323 disabled=yes<br />
set quake3 disabled=yes<br />
set gre disabled=yes<br />
set pptp disabled=yes<br />
/ ip hotspot service-port<br />
set ftp ports=21 disabled=no<br />
/ ip hotspot profile<br />
set default name=&#8221;default&#8221; hotspot-address=0.0.0.0 dns-name=&#8221;" html-directory=hotspot rate-limit=&#8221;" http-proxy=0.0.0.0:0 \<br />
smtp-server=0.0.0.0 login-by=cookie,http-chap http-cookie-lifetime=3d split-user-domain=no use-radius=no<br />
/ ip hotspot user profile<br />
set default name=&#8221;default&#8221; idle-timeout=none keepalive-timeout=2m status-autorefresh=1m shared-users=1 \<br />
transparent-proxy=yes open-status-page=always advertise=no<br />
/ ip dhcp-server<br />
add name=&#8221;dhcp1&#8243; interface=Local lease-time=3d address-pool=dhcp_pool1 bootp-support=static authoritative=after-2sec-delay \<br />
disabled=no<br />
/ ip dhcp-server config<br />
set store-leases-disk=5m<br />
/ ip dhcp-server lease<br />
/ ip dhcp-server network<br />
add address=10.2.1.0/24 gateway=10.2.1.253 comment=&#8221;"<br />
/ ip ipsec proposal<br />
add name=&#8221;default&#8221; auth-algorithms=sha1 enc-algorithms=3des lifetime=30m lifebytes=0 pfs-group=modp1024 disabled=no<br />
/ ip web-proxy<br />
set enabled=yes src-address=0.0.0.0 port=3128 hostname=&#8221;proxy&#8221; transparent-proxy=yes parent-proxy=0.0.0.0:0 \<br />
cache-administrator=&#8221;webmaster&#8221; max-object-size=4096KiB cache-drive=system max-cache-size=unlimited \<br />
max-ram-cache-size=unlimited<br />
/ ip web-proxy access<br />
add dst-port=23-25 action=deny comment=&#8221;block telnet &amp; spam e-mail relaying&#8221; disabled=no<br />
/ ip web-proxy cache<br />
add url=&#8221;:cgi-bin \\?&#8221; action=deny comment=&#8221;don&#8217;t cache dynamic http pages&#8221; disabled=no<br />
/ system logging<br />
add topics=info prefix=&#8221;" action=memory disabled=no<br />
add topics=error prefix=&#8221;" action=memory disabled=no<br />
add topics=warning prefix=&#8221;" action=memory disabled=no<br />
add topics=critical prefix=&#8221;" action=echo disabled=no<br />
/ system logging action<br />
set memory name=&#8221;memory&#8221; target=memory memory-lines=100 memory-stop-on-full=no<br />
set disk name=&#8221;disk&#8221; target=disk disk-lines=100 disk-stop-on-full=no<br />
set echo name=&#8221;echo&#8221; target=echo remember=yes<br />
set remote name=&#8221;remote&#8221; target=remote remote=0.0.0.0:514<br />
/ system upgrade mirror<br />
set enabled=no primary-server=0.0.0.0 secondary-server=0.0.0.0 check-interval=1d user=&#8221;"<br />
/ system clock dst<br />
set dst-delta=+00:00 dst-start=&#8221;jan/01/1970 00:00:00&#8243; dst-end=&#8221;jan/01/1970 00:00:00&#8243;<br />
/ system watchdog<br />
set reboot-on-failure=yes watch-address=none watchdog-timer=yes no-ping-delay=5m automatic-supout=yes auto-send-supout=no<br />
/ system console<br />
add port=serial0 term=&#8221;" disabled=no<br />
set FIXME term=&#8221;linux&#8221; disabled=no<br />
set FIXME term=&#8221;linux&#8221; disabled=no<br />
set FIXME term=&#8221;linux&#8221; disabled=no<br />
set FIXME term=&#8221;linux&#8221; disabled=no<br />
set FIXME term=&#8221;linux&#8221; disabled=no<br />
set FIXME term=&#8221;linux&#8221; disabled=no<br />
set FIXME term=&#8221;linux&#8221; disabled=no<br />
set FIXME term=&#8221;linux&#8221; disabled=no<br />
/ system console screen<br />
set line-count=25<br />
/ system identity<br />
set name=&#8221;ROUTER-NET&#8221;<br />
/ system note<br />
set show-at-login=yes note=&#8221;"<br />
/ port<br />
set serial0 name=&#8221;serial0&#8243; baud-rate=9600 data-bits=8 parity=none stop-bits=1 flow-control=hardware<br />
/ ppp profile<br />
set default name=&#8221;default&#8221; use-compression=default use-vj-compression=default use-encryption=default only-one=default \<br />
change-tcp-mss=yes comment=&#8221;"<br />
add name=&#8221;vpn&#8221; local-address=vpn remote-address=vpn use-compression=default use-vj-compression=default \<br />
use-encryption=required only-one=default change-tcp-mss=default dns-server=203.130.193.74 comment=&#8221;"<br />
set default-encryption name=&#8221;default-encryption&#8221; use-compression=default use-vj-compression=default use-encryption=yes \<br />
only-one=default change-tcp-mss=yes comment=&#8221;"<br />
/ ppp secret<br />
add name=&#8221;areksitiung&#8221; service=pptp caller-id=&#8221;" password=&#8221;sentot&#8221; profile=vpn routes=&#8221;" limit-bytes-in=0 \<br />
limit-bytes-out=0 comment=&#8221;" disabled=no<br />
/ ppp aaa<br />
set use-radius=yes accounting=yes interim-update=0s<br />
/ queue type<br />
set default name=&#8221;default&#8221; kind=pfifo pfifo-limit=50<br />
set ethernet-default name=&#8221;ethernet-default&#8221; kind=pfifo pfifo-limit=50<br />
set wireless-default name=&#8221;wireless-default&#8221; kind=sfq sfq-perturb=5 sfq-allot=1514<br />
set synchronous-default name=&#8221;synchronous-default&#8221; kind=red red-limit=60 red-min-threshold=10 red-max-threshold=50 \<br />
red-burst=20 red-avg-packet=1000<br />
set hotspot-default name=&#8221;hotspot-default&#8221; kind=sfq sfq-perturb=5 sfq-allot=1514<br />
add name=&#8221;default-small&#8221; kind=pfifo pfifo-limit=10<br />
/ queue simple<br />
add name=&#8221;DreamNet&#8221; target-addresses=192.168.1.0/24 dst-address=0.0.0.0/0 interface=Local parent=none direction=both \<br />
priority=1 queue=default-small/default-small limit-at=0/0 max-limit=0/0 total-queue=default-small disabled=no<br />
add name=&#8221;Down_Services&#8221; dst-address=0.0.0.0/0 interface=all parent=none packet-marks=prio_download_packet direction=both \<br />
priority=5 queue=default-small/default-small limit-at=0/0 max-limit=0/0 total-queue=default-small disabled=no<br />
add name=&#8221;Ensign_Services&#8221; dst-address=0.0.0.0/0 interface=all parent=none packet-marks=prio_ensign_packet direction=both \<br />
priority=1 queue=default-small/default-small limit-at=0/0 max-limit=0/0 total-queue=default-small disabled=no<br />
add name=&#8221;User_Request&#8221; dst-address=0.0.0.0/0 interface=all parent=none packet-marks=prio_request_packet direction=both \<br />
priority=8 queue=default-small/default-small limit-at=0/0 max-limit=0/0 total-queue=default-small disabled=no<br />
add name=&#8221;Communication&#8221; target-addresses=0.0.0.0/0 dst-address=0.0.0.0/0 interface=all parent=none \<br />
packet-marks=prio_comm_packet direction=both priority=3 queue=default-small/default-small limit-at=0/0 max-limit=0/0 \<br />
total-queue=default-small disabled=no<br />
add name=&#8221;Kasir&#8221; target-addresses=192.168.1.99/32 dst-address=0.0.0.0/0 interface=Local parent=DreamNet direction=both \<br />
priority=8 queue=default-small/default-small limit-at=16000/32000 max-limit=32000/128000 total-queue=default-small \<br />
disabled=no<br />
add name=&#8221;Client1&#8243; target-addresses=192.168.1.15/32 dst-address=0.0.0.0/0 interface=Local parent=DreamNet direction=both \<br />
priority=8 queue=default-small/default-small limit-at=16000/32000 max-limit=32000/128000 total-queue=default \<br />
disabled=no<br />
add name=&#8221;Client2&#8243; target-addresses=192.168.1.4/32 dst-address=0.0.0.0/0 interface=Local parent=DreamNet direction=both \<br />
priority=8 queue=default-small/default-small limit-at=16000/32000 max-limit=32000/128000 total-queue=default \<br />
disabled=no<br />
add name=&#8221;Client3&#8243; target-addresses=192.168.1.5/32 dst-address=0.0.0.0/0 interface=Local parent=DreamNet direction=both \<br />
priority=8 queue=default-small/default-small limit-at=16000/32000 max-limit=32000/128000 total-queue=default \<br />
disabled=no<br />
add name=&#8221;Client4&#8243; target-addresses=192.168.1.6/32 dst-address=0.0.0.0/0 interface=Local parent=DreamNet direction=both \<br />
priority=8 queue=default-small/default-small limit-at=16000/32000 max-limit=32000/128000 total-queue=default \<br />
disabled=no<br />
add name=&#8221;Client5&#8243; target-addresses=192.168.1.7/32 dst-address=0.0.0.0/0 interface=Local parent=DreamNet direction=both \<br />
priority=8 queue=default-small/default-small limit-at=16000/32000 max-limit=32000/128000 total-queue=default \<br />
disabled=no<br />
add name=&#8221;Client6&#8243; target-addresses=192.168.1.8/32 dst-address=0.0.0.0/0 interface=Local parent=DreamNet direction=both \<br />
priority=8 queue=default-small/default-small limit-at=16000/32000 max-limit=32000/128000 total-queue=default \<br />
disabled=no<br />
add name=&#8221;Client7&#8243; target-addresses=192.168.1.9/32 dst-address=0.0.0.0/0 interface=Local parent=DreamNet direction=both \<br />
priority=8 queue=default-small/default-small limit-at=16000/32000 max-limit=32000/128000 total-queue=default \<br />
disabled=no<br />
add name=&#8221;Client8&#8243; target-addresses=192.168.1.10/32 dst-address=0.0.0.0/0 interface=Local parent=DreamNet direction=both \<br />
priority=8 queue=default-small/default-small limit-at=16000/32000 max-limit=32000/128000 total-queue=default \<br />
disabled=no<br />
add name=&#8221;Client9&#8243; target-addresses=192.168.1.11/32 dst-address=0.0.0.0/0 interface=Local parent=DreamNet direction=both \<br />
priority=8 queue=default-small/default-small limit-at=16000/32000 max-limit=32000/128000 total-queue=default \<br />
disabled=no<br />
add name=&#8221;Client10&#8243; target-addresses=192.168.1.12/32 dst-address=0.0.0.0/0 interface=Local parent=DreamNet direction=both \<br />
priority=8 queue=default-small/default-small limit-at=16000/32000 max-limit=32000/128000 total-queue=default \<br />
disabled=no<br />
/ user<br />
add name=&#8221;admin&#8221; group=full address=0.0.0.0/0 comment=&#8221;system default user&#8221; disabled=yes<br />
add name=&#8221;areksitiung&#8221; group=full address=0.0.0.0/0 comment=&#8221;" disabled=no<br />
add name=&#8221;nanda&#8221; group=full address=0.0.0.0/0 comment=&#8221;" disabled=no<br />
add name=&#8221;riko&#8221; group=full address=0.0.0.0/0 comment=&#8221;" disabled=no<br />
add name=&#8221;padang&#8221; group=full address=0.0.0.0/0 comment=&#8221;" disabled=no<br />
/ user group<br />
add name=&#8221;read&#8221; policy=local,telnet,ssh,reboot,read,test,winbox,password,web,!ftp,!write,!policy<br />
add name=&#8221;write&#8221; policy=local,telnet,ssh,reboot,read,write,test,winbox,password,web,!ftp,!policy<br />
add name=&#8221;full&#8221; policy=local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,password,web<br />
/ user aaa<br />
set use-radius=no accounting=yes interim-update=0s default-group=read<br />
/ radius incoming<br />
set accept=no port=1700<br />
/ driver<br />
/ snmp<br />
set enabled=no contact=&#8221;" location=&#8221;"<br />
/ snmp community<br />
set public name=&#8221;public&#8221; address=0.0.0.0/0 read-access=yes<br />
/ tool bandwidth-server<br />
set enabled=yes authenticate=yes allocate-udp-ports-from=2000 max-sessions=10<br />
/ tool mac-server ping<br />
set enabled=yes<br />
/ tool e-mail<br />
set server=0.0.0.0 from=&#8221;&lt;&gt;&#8221;<br />
/ tool sniffer<br />
set interface=all only-headers=no memory-limit=10 file-name=&#8221;" file-limit=10 streaming-enabled=no streaming-server=0.0.0.0 \<br />
filter-stream=yes filter-protocol=ip-only filter-address1=0.0.0.0/0:0-65535 filter-address2=0.0.0.0/0:0-65535<br />
/ tool graphing<br />
set store-every=5min<br />
/ tool graphing queue<br />
add simple-queue=all allow-address=0.0.0.0/0 store-on-disk=yes allow-target=yes disabled=no<br />
/ tool graphing resource<br />
add allow-address=0.0.0.0/0 store-on-disk=yes disabled=no<br />
/ tool graphing interface<br />
add interface=all allow-address=0.0.0.0/0 store-on-disk=yes disabled=no<br />
/ routing ospf<br />
set router-id=0.0.0.0 distribute-default=never redistribute-connected=no redistribute-static=no redistribute-rip=no \<br />
redistribute-bgp=no metric-default=1 metric-connected=20 metric-static=20 metric-rip=20 metric-bgp=20<br />
/ routing ospf area<br />
set backbone area-id=0.0.0.0 type=default translator-role=translate-candidate authentication=none prefix-list-import=&#8221;" \<br />
prefix-list-export=&#8221;" disabled=no<br />
/ routing bgp<br />
set enabled=no as=1 router-id=0.0.0.0 redistribute-static=no redistribute-connected=no redistribute-rip=no \<br />
redistribute-ospf=no<br />
/ routing rip<br />
set redistribute-static=no redistribute-connected=no redistribute-ospf=no redistribute-bgp=no metric-static=1 \<br />
metric-connected=1 metric-ospf=1 metric-bgp=1 update-timer=30s timeout-timer=3m garbage-timer=2m</p>
]]></content:encoded>
			<wfw:commentRss>http://www.areksitiung.com/2009/04/22/load-balancing-3-line-speedy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Load Balancing 3 Line Speedy + Setingan Dasar</title>
		<link>http://www.areksitiung.com/2009/04/09/load-balancing-3-line-speedy-setingan-dasar/</link>
		<comments>http://www.areksitiung.com/2009/04/09/load-balancing-3-line-speedy-setingan-dasar/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 11:44:54 +0000</pubDate>
		<dc:creator>harinto</dc:creator>
				<category><![CDATA[Mikrotik]]></category>

		<guid isPermaLink="false">http://harinto.wordpress.com/?p=452</guid>
		<description><![CDATA[IP address
Load balancer = 192.168.8.10
Mikrotik dengan 3 lan card:
—&#62; Eth1 = 192.168.8.1 (ke load balancer)
—&#62; Eth2 = 192.168.15.1 (ke IPCOP)
—&#62; Eth3 = 192.168.1.1 (ke Switch/hub)
IPCOP = 192.168.15.10
Modem di set mode bridge, jadi yang dial PPPoE dari loadbalancer nya
2. Setting Mikrotik
—&#62; Ethernet Card
name=”Speedy” mtu=1500 mac-address=4C:00:10:1B:4E:6F arp=enabled disable-running-check=yes auto-negotiation=yes full-duplex=yes cable-settings=default speed=100Mbps
name=”Lokal” mtu=1500 mac-address=00:02:2A:BF:E2:08 arp=enabled disable-running-check=yes auto-negotiation=yes [...]]]></description>
			<content:encoded><![CDATA[<p>IP address<br />
Load balancer = 192.168.8.10<br />
Mikrotik dengan 3 lan card:<br />
—&gt; Eth1 = 192.168.8.1 (ke load balancer)<br />
—&gt; Eth2 = 192.168.15.1 (ke IPCOP)<br />
—&gt; Eth3 = 192.168.1.1 (ke Switch/hub)<br />
IPCOP = 192.168.15.10</p>
<p>Modem di set mode bridge, jadi yang dial PPPoE dari loadbalancer nya</p>
<p>2. Setting Mikrotik</p>
<p>—&gt; Ethernet Card</p>
<p>name=”Speedy” mtu=1500 mac-address=4C:00:10:1B:4E:6F arp=enabled disable-running-check=yes auto-negotiation=yes full-duplex=yes cable-settings=default speed=100Mbps</p>
<p>name=”Lokal” mtu=1500 mac-address=00:02:2A:BF:E2:08 arp=enabled disable-running-check=yes auto-negotiation=yes full-duplex=yes cable-settings=default speed=100Mbps</p>
<p>name=”Squid” mtu=1500 mac-address=00:0E:2E:01:62:24 arp=enabled disable-running-check=yes auto-negotiation=yes full-duplex=yes cable-settings=default speed=100Mbps</p>
<p>—&gt; IP address</p>
<p>[admin@satelit-internet]/ip address<br />
add address=192.168.8.1/24 interface=Speedy<br />
add address=192.168.1.1/24 interface=Lokal<br />
add address=192.168.15.1/24 interface=Squid</p>
<p>—&gt; DNS</p>
<p>[admin@satelit-internet]/ip dns<br />
set primary-dns=192.168.8.10 allow-remote-request=yes</p>
<p>—&gt; Route</p>
<p>[admin@satelit-internet]/ip route<br />
add gateway=192.168.8.10</p>
<p>—&gt; NAT</p>
<p>[admin@satelit-internet]/ip firewall nat<br />
add chain=dstnat src-address=!192.168.8.0/24 protocol=tcp dst-port=80 action=dst-nat to-addresses=192.168.8.10 to-ports=818</p>
<p>add chain=srcnat out-interface=Speedy action=masquerade</p>
<p>tujuannya membelokkan semua port 80 dari client ke port 818 (squid IPCOP) yang berfungsi sebagai web proxy</p>
<p>—&gt; Mangle</p>
<p>tujuannya<br />
memisahkan bandwidth internasional dan lokal (OpenIXP dan IIX)<br />
Daftar IP Address yang diadvertise di OpenIXP dan IIX dapat di download di <a href="http://www.mikrotik.co.id/getfile.php?nf=nice.rsc" target="_blank">http://www.mikrotik.co.id/getfile.php?nf=nice.rsc</a><br />
File nice.rsc ini dibuat secara otomatis di server Mikrotik Indonesia setiap pagi sekitar pk 05.30, dan merupakan data yang telah di optimasi untuk menghilangkan duplikat entry dan tumpang tindih subnet.<br />
Untuk tutorial auto import script ke mikrotik bisa diintip disini</p>
<p>[admin@satelit-internet] &gt;/ip firewall mangle</p>
<p>add chain=forward dst-address=192.168.1.0/24 action=change-ttl new-ttl=set:1 comment=”change TTL”</p>
<p>add chain=forward out-interface=internet protocol=tcp tcp-flags=syn action=change-mss new-mss=1300 comment=”change mss”</p>
<p>add chain=forward content=X-Cache: HIT action=mark-connection new-connection-mark=squid_conn passthrough=yes comment=”squid proxy”</p>
<p>chain=forward connection-mark=squid_conn action=mark-packet new-packet-mark=squid_packet passthrough=no</p>
<p>/* Prioritaskan ping dan DNS */</p>
<p>add chain=prerouting protocol=icmp action=mark-connection new-connection-mark=icmp passthrough=yes comment=”icmp”</p>
<p>add chain=prerouting connection-mark=icmp action=change-tos new-tos=min-delay</p>
<p>add chain=prerouting connection-mark=icmp action=mark-packet new-packet-mark=icmp passthrough=no</p>
<p>add chain=prerouting protocol=udp dst-port=53 action=mark-connection new-connection-mark=DNS passthrough=yes comment=”DNS”</p>
<p>add chain=prerouting connection-mark=DNS action=change-tos new-tos=max-throughput</p>
<p>add chain=prerouting protocol=udp dst-port=53 connection-mark=DNS action=mark-packet new-packet-mark=DNS passthrough=no</p>
<p>add chain=forward protocol=tcp dst-port=6000-7000 action=mark-connection new-connection-mark=IRC passthrough=yes comment=”irc”</p>
<p>add chain=prerouting src-address=192.168.1.0/24 protocol=tcp dst-port=6000-7000 action=mark-packet new-packet-mark=irc passthrough=no</p>
<p>add chain=forward connection-mark=IRC action=mark-packet new-packet-mark=irc passthrough=no</p>
<p>/* Upload Connections */</p>
<p>add chain=prerouting src-address=192.168.1.0/24 dst-address-list=!nice action=mark-packet new-packet-mark=upload comment=”upload” passthrough=no</p>
<p>/* Download Connections hanya untuk bandwidth internasional (OpenIXP) */</p>
<p>add chain=forward dst-address=!192.168.1.0/24 connection-mark=!squid_conn dst-address-list=!nice action=mark-connection new-connection-mark=download passthrough=yes comment=”download”</p>
<p>add chain=forward connection-mark=download action=mark-packet new-packet-mark=download passthrough=no</p>
<p>—&gt; Queue type</p>
<p>[admin@satelit-internet]/queue tree</p>
<p>add name=”pfifo-64″ kind=pfifo pfifo-limit=64</p>
<p>add name=”pcq-down” kind=pcq pcq-rate=0 pcq-limit=50 pcq-classifier=dst-address pcq-total-limit=2000</p>
<p>add name=”pcq-up” kind=pcq pcq-rate=0 pcq-limit=50 pcq-classifier=src-address pcq-total-limit=2000</p>
<p>—&gt; Queue Tree</p>
<p>[admin@satelit-internet]/queue tree</p>
<p>add name=”download” parent=lan packet-mark=download limit-at=0 queue=pcq-down priority=8 max-limit=0 burst-limit=0 burst-threshold=0 burst-time=0s</p>
<p>—&gt; Queue simple</p>
<p>[admin@satelit-internet]/queue simple</p>
<p>add name=”squid” dst-address=0.0.0.0/0 interface=all parent=none packet-marks=squid_packet direction=both priority=8 queue=default-small/ethernet-default limit-at=0/0 max-limit=0/0 total-queue=default-small</p>
<p>add name=”irc” dst-address=0.0.0.0/0 interface=all parent=none packet-marks=irc direction=both priority=8 queue=default-small/default-small limit-at=16000/16000 max-limit=16000/16000 total-queue=default-small</p>
<p>add name=”DNS” dst-address=0.0.0.0/0 interface=all parent=none packet-marks=DNS direction=both priority=8 queue=pfifo-64/pfifo-64 limit-at=8000/8000 max-limit=8000/8000 total-queue=default-small</p>
<p>add name=”icmp” dst-address=0.0.0.0/0 interface=all parent=none packet-marks=icmp direction=both priority=8 queue=pfifo-64/pfifo-64 limit-at=8000/8000 max-limit=8000/8000 total-queue=default-small</p>
<p>add name=”parent” dst-address=0.0.0.0/0 interface=all parent=none packet-marks=download,upload direction=both priority=8 queue=default-small/pcq-down limit-at=0/0 max-limit=0/0 total-queue=default-small</p>
<p>add name=”Satelit-01″ target-addresses=192.168.1.100/32 dst-address=0.0.0.0/0 interface=all parent=parent packet-marks=download,upload direction=both priority=8 queue=default-small/default-small limit-at=0/0 max-limit=0/0 total-queue=default-small<br />
.<br />
.<br />
.<br />
dst sampe 15 client</p>
<p>source: http://echo.or.id</p>
]]></content:encoded>
			<wfw:commentRss>http://www.areksitiung.com/2009/04/09/load-balancing-3-line-speedy-setingan-dasar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Melakukan Shaper Secara Quota</title>
		<link>http://www.areksitiung.com/2009/04/09/melakukan-shaper-secara-quota/</link>
		<comments>http://www.areksitiung.com/2009/04/09/melakukan-shaper-secara-quota/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 11:12:09 +0000</pubDate>
		<dc:creator>harinto</dc:creator>
				<category><![CDATA[Mikrotik]]></category>

		<guid isPermaLink="false">http://harinto.wordpress.com/?p=440</guid>
		<description><![CDATA[Bagi banyak orang yang berkecimpung di RT/RW-net atau ISP atau WARNET, sering kali yang menjadi masalah adalah kehadiran pelanggan yang &#8216;MANIAK DOWNLOAD&#8216; dimana bandwidth kita akan tersedot habis oleh 1 orang user yang nota bene membayar sama dengan yang lain namun berdampak sangat buruk bagi yang lain.
Gara-gara satu orang user, maka kita terpaksa dikomplain seluruh [...]]]></description>
			<content:encoded><![CDATA[<p>Bagi banyak orang yang berkecimpung di RT/RW-net atau ISP atau WARNET, sering kali yang menjadi masalah adalah kehadiran pelanggan yang &#8216;<em>MANIAK DOWNLOAD</em>&#8216; dimana bandwidth kita akan tersedot habis oleh 1 orang user yang nota bene membayar sama dengan yang lain namun berdampak sangat buruk bagi yang lain.</p>
<p>Gara-gara satu orang user, maka kita terpaksa dikomplain seluruh pelanggan yang lain. Namun untuk memberikan peringatan pada satu orang itu, rasanya juga sulit karena dia merasa <strong>membayar</strong> sehingga merasa berhak untuk menggunakan akses internet sesuka hati.</p>
<p>Ada cara yang cukup efektif untuk menahan hal semacam ini dengan cara membuat shaper berbasis quota. Misalnya begini : <em>jika pemakaian download masih dibawah 75 MB maka user akan mendapat kecepatan maksimal 128 kbps. Tapi jika dia sudah menggunakan lebih dari 75 MB tapi masih kurang dari 150 MB, maka kecepatannya menurun menjadi hanya 92 kbps. Tapi kalau dia sudah mendownload lebih dari 150 MB, maka kecepatannya kita batasi hanya tersisa 64 kbps</em>.</p>
<p>Cara untuk melakukan hal semacam itu adalah dengan memasang script berikut ini :</p>
<p>/queue simple<br />
:local traf;<br />
:local maxi;<br />
:set traf [get [find name="&lt;eddy&gt;"] total-bytes]<br />
:set maxi [get [find name="&lt;eddy&gt;"] max-limit]<br />
:set ips [get [find name="&lt;eddy&gt;"] target-address]<br />
:if ($traf  &gt; 150000000) do = { :log info &#8220;Si Eddy sudah melampaui 150MB&#8221;;<br />
set [find name="&lt;eddy&gt;"] max-limit= &#8220;64000/64000&#8243;}<br />
:if ($traf  &lt; 150000000) do = { :log info &#8220;Si Eddy masih dibawah 150MB&#8221;;<br />
set [find name="&lt;eddy&gt;"] max-limit= &#8220;92000/92000&#8243;}<br />
:if ($traf  &lt; 75000000) do = { :log info &#8220;Si Eddy masih dibawah 75MB&#8221;;<br />
set [find name="&lt;eddy&gt;"] max-limit= &#8220;128000/128000&#8243;}</p>
<p>Keterangan :</p>
<ul>
<li>150000000 : artinya 150 MB</li>
<li>&lt;eddy&gt; : adalah nama queue yang sudah kita setting di queue simple list</li>
<li>:log info  : untuk membuat keterangan dibagian LOG agar kita bisa lihat proses yang dijalankan</li>
<li>max-limit adalah perintah untuk melakukan perubahan limiter</li>
</ul>
<p>Script ini kita letakkan di bagian /system scheduler dengan menambahkan schedule (misalnya):</p>
<p>start-date=feb/20/2009 start-time=02:25:00 interval=30m</p>
<p>Kemudian pada bagian on-event kita tuliskan script kita tersebut di atas. Artinya, setiap 30 menit sekali, mikrotik akan menjalankan script cek tadi dan user eddy akan diaudit setiap 30 menit sekali. Dengan demikian setiap 30 menit akan dicek pemakaian si eddy apakah sudah melampaui batas atau belum.</p>
<p>Kita bisa mengatur interval menjadi lebih cepat ataupun lebih lambat sesuai dengan kehendak kita. Selamat mencoba dan semoga berguna.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.areksitiung.com/2009/04/09/melakukan-shaper-secara-quota/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cara Mudah menginstall Mikrotik</title>
		<link>http://www.areksitiung.com/2009/04/09/cara-mudah-menginstall-mikrotik/</link>
		<comments>http://www.areksitiung.com/2009/04/09/cara-mudah-menginstall-mikrotik/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 11:09:21 +0000</pubDate>
		<dc:creator>harinto</dc:creator>
				<category><![CDATA[Mikrotik]]></category>

		<guid isPermaLink="false">http://harinto.wordpress.com/?p=437</guid>
		<description><![CDATA[Untuk menginstall Mikrotik kita perlu mendownload ISO filenya dari mikrotik kemudian di-burn ke CD.
Setelah di burn ke CD, booting komputer menggunakan CD mikrotik dan tunggu sampai menu pilihan muncul seperti ini :

Kita tinggal memilih paket-paket yang kita butuhkan dengan menekan tombol spasi. Paket-paket yang kita perlukan misalnya ppp, dhcp, advanced tools, hotspot, ntp, routing, security, [...]]]></description>
			<content:encoded><![CDATA[<p>Untuk menginstall Mikrotik kita perlu mendownload <a title="Download ISO file mikrotik disini" href="http://www.mikrotik.co.id/download.php" target="_blank">ISO filenya</a> dari <a title="Mikrotik Indonesia" href="http://www.mikrotik.co.id/" target="_blank">mikrotik</a> kemudian di-burn ke CD.</p>
<p>Setelah di burn ke CD, booting komputer menggunakan CD mikrotik dan tunggu sampai menu pilihan muncul seperti ini :</p>
<p><img title="Install Mikrotik" src="http://www.vavai.com/images/mikrotik/mikro1.jpg" border="0" alt="Install Mikrotik" width="553" height="322" /></p>
<p>Kita tinggal memilih paket-paket yang kita butuhkan dengan menekan tombol spasi. Paket-paket yang kita perlukan misalnya ppp, dhcp, advanced tools, hotspot, ntp, routing, security, telephony, ups, user manager, web-proxy. Untuk system harus dicentang karena kalau tidak salah-salah tidak nginstall mikrotik tapi nginstall windows&#8230; hahaha&#8230;</p>
<p>Setelah itu tekan huruf &#8216;i&#8217; untuk mulai menginstall dan tunggu selama proses installasi. Setelah proses installasi selesai, maka komputer akan reboot sendiri. Lepas CD mikrotik dan biarkan komputer booting dari harddisk. Tunggu selama proses booting pertama ini sampai muncul halaman login seperti ini :</p>
<p><img title="mikrotik login" src="http://www.vavai.com/images/mikrotik/mikro3.jpg" border="0" alt="mikrotik login" width="547" height="316" /></p>
<p>Untuk bisa login, username yang kita pakai adalah &#8216;admin&#8217; dan passwordnya kosong (langsung enter saja). Pada kondisi default, mikrotik yang baru terinstall tidak memiliki IP sehingga kita tidak bisa meremote ke Mikrotik. Untuk melakukan setting awal, gunakan perintah ini :</p>
<p>* interface print</p>
<p>gunanya untuk mengetahui interface yang aktif di mikrotik. Hasilnya kurang lebih akan seperti ini :</p>
<p>[ayom@Heliconia-RT/RW-net] &gt; interface print<br />
Flags: D &#8211; dynamic, X &#8211; disabled, R &#8211; running, S &#8211; slave<br />
#     NAME                                              TYPE             MTU<br />
0     ether1                                             ether            1500<br />
1     ether2                                            ether            1500<br />
[ayom@Heliconia-RT/RW-net] &gt;</p>
<p>Setelah itu kita bisa memberikan IP ke interface yang kita mau dengan cara :</p>
<p>* ip address add interface=ether1 address=192.168.1.254/24</p>
<p>maka interface ether1 sudah akan berisi IP 192.168.1.254/24. Dan mikrotik kita sudah bisa kita remote dari PC dengan menuliskan http://192.168.1.254 di web-browser (IE atau Firefox). Jika benar, akan muncul halaman layar seperti berikut :</p>
<p><img title="Web Mikrotik" src="http://i153.photobucket.com/albums/s205/miji_qitink/gambar-1.jpg" border="0" alt="Web Mikrotik" width="548" height="411" /></p>
<p>Silakan download WINBOX yang ada di sebelah kiri atas web ini untuk memudahkan kita melakukan remote mikrotik. Kalau sudah di-download, maka akan muncul program seperti berikut :</p>
<p><img title="Winbox Login" src="http://www.mikrotik.com/testdocs/ros/2.9/img/winboxlogin.jpg" border="0" alt="Winbox Login" width="270" height="221" /></p>
<p>Tekan tanda titik-titik yang ada disebelah kiri Connect untuk menemukan mac address atau IP address dari mikrotik yang baru saja kita install. Username yang dipakai masih sama yaitu admin dengan password masih kosong. Setelah itu, kita sudah akan melihat menu lengkap Mikrotik melalui Winbox seperti berikut ini :</p>
<p><img title="Winbox" src="http://www.mikrotik.org.pl/items/screeny/1.jpg" border="0" alt="Winbox" width="508" height="481" /></p>
<p>Setelah itu maka kita bisa dengan mudah mengisi dan mempelajari Mikrotik.</p>
<p>sumber: http://www.istanaku.biz</p>
]]></content:encoded>
			<wfw:commentRss>http://www.areksitiung.com/2009/04/09/cara-mudah-menginstall-mikrotik/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Melakukan Shaper di Mikrotik</title>
		<link>http://www.areksitiung.com/2009/04/09/melakukan-shaper-di-mikrotik/</link>
		<comments>http://www.areksitiung.com/2009/04/09/melakukan-shaper-di-mikrotik/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 11:04:52 +0000</pubDate>
		<dc:creator>harinto</dc:creator>
				<category><![CDATA[Mikrotik]]></category>

		<guid isPermaLink="false">http://harinto.wordpress.com/?p=433</guid>
		<description><![CDATA[Satu hal yang menyenangkan dari Mikrotik adalah tersedianya sistem shaper atau bandwitdh management (BM) yang sudah built-in dan mudah dalam penggunaannya. Bahkan bagi pemula sekalipun!
Dalam tutorial ini saya ingin memberikan sedikit tata cara untuk membuat shaper atau BM di Mikrotik secara mudah dan simple dengan SIMPLE QUEUE. Untuk dapat mengikuti tutorial ini, silakan menggunakan WINBOX [...]]]></description>
			<content:encoded><![CDATA[<p>Satu hal yang menyenangkan dari Mikrotik adalah tersedianya sistem shaper atau bandwitdh management (BM) yang sudah built-in dan mudah dalam penggunaannya. Bahkan bagi pemula sekalipun!</p>
<p>Dalam tutorial ini saya ingin memberikan sedikit tata cara untuk membuat shaper atau BM di Mikrotik secara mudah dan simple dengan SIMPLE QUEUE. Untuk dapat mengikuti tutorial ini, silakan menggunakan WINBOX untuk login ke Mikrotik anda dan mengisi IP, username, dan password sesuai dengan yang tersedia di Mikrotik anda. Jika sudah, kita akan mulai dari tampilan menu seperti dibawah ini :</p>
<p><img title="Mikrotik Menu Utama" src="http://www.mikrotik.org.pl/items/screeny/1.jpg" border="0" alt="Mikrotik Menu Utama" width="491" height="464" /></p>
<p>Setelah tampil menu seperti diatas, maka kita memulai semua proses shaper atau BM dari menu Queues yang ada di sebelah kiri nomor 7 dari atas. Kalau kita client Queues maka akan muncul tampilan baru sebagai berikut :</p>
<p><img title="Queues" src="http://www.istanaku.biz/images/tutorial/queues.jpg" border="0" alt="Queues" width="481" height="275" /></p>
<p>Untuk membuat shaper, ada 2 cara yaitu menggunakan langkah yang mudah melalui Simple Queue, dan langkah yang lebih rumit namun bisa untuk berbagai macam kebutuhan melalui Queue Tree. Untuk pelajaran awal, saya menerangkan cara untuk membuat shaper menggunakan Simple Queue untuk mudah dimengerti dan dapat segera diimplementasikan.</p>
<p>Untuk membuat entry pada Simple Queue, kita bisa menekan tanda + (tambah) di sebelah kiri atas pada tab Simple Queue. Jika sudah, maka akan muncul tab baru sebagai berikut :</p>
<p><img title="Simple Queue" src="http://www.istanaku.biz/images/tutorial/simple-queue.jpg" border="0" alt="Simple Queue" width="483" height="330" /></p>
<p>Untuk mengisi, cukup mudah.</p>
<ul>
<li>Name adalah nama yang ingin kita pakai untuk menerangkan shaper yang kita buat ini. Misalnya PC1</li>
<li>target address adalah IP address yang ingin kita shaper misalnya : 192.168.0.2. Kita tidak boleh menuliskan subnet /24 atau /29 jika kita hanya ingin menshaper 1 IP saja. Jika beberapa IP yang tidak berada dalam satu subnet kita bisa menekan tanda panah ke bawah disisi kanan Target Address untuk mendapatkan baris kedua IP Address.</li>
<li>Target upload : adalah kecepatan maksimal yang kita inginkan untuk berikan untuk client tersebut untuk bisa mengirim data ke luar network (UPLOAD).</li>
<li>Target download : adalah kecepatan maksimal yang kita inginkan untuk berikan ke client tersebut untuk bisa menerima atau mendownload data ke komputernya.</li>
<li>Burst adalah kondisi khusus yang ingin kita berikan kepada client tersebut dimana pada kondisi tertentu dia bisa melampaui batas yang sudah kita berikan pada Target Upload ataupun target Download. Burst adalah bandwidth extra yang kita berikan kepada client.</li>
<li>Burst limit adalah batas atas burst yang kita berikan sebagai batas tertinggi client bisa mendapat bandwidth</li>
<li>Burst threshold adalah batas control pada sistem burst. Biasanya threshold adalah angka bandwidth yang akan menjadi rata-rata pemakaian jika pengguna akses terus menerus menghabiskan bandwidth yang tersedia. Bagian ini agak rumit untuk diterangkan di tulisan, tapi akan lebih mudah dimengerti dalam implementasi di lapangan.</li>
<li>Burst Time : adalah waktu burst yang diizinkan. Konsep burst adalah client boleh menggunakan angka bandwidth yang tersedia di burst limit selama sekian detik yang ditentukan oleh burst time. Setelah sekian detik itu, maka limit akan dikembalikan kepada bandwidth yang sebenarnya. Kurang lebih aturannya begitu walaupun mungkin tidak 100% seperti itu.</li>
<li>Time adalah saat dimana kita ingin shaper ini difungsikan. Diluar jam/hari yang ditentukan, shaper ini tidak akan berfungsi. Hal ini berguna untuk mengatur misalnya : selama jam kerja, shaper dibuat ketat, namun diluar jam kerja, shaper menjadi tidak ada.</li>
</ul>
<p>Contoh mengisi shaper adalah seperti berikut :</p>
<p><img title="Queue pc1" src="http://www.istanaku.biz/images/tutorial/isi-queue.jpg" border="0" alt="Queue pc1" width="458" height="311" /></p>
<p>Pada contoh tersebut, saya mengisi shaper dengan nama <strong>pc1</strong> yang diperuntukkan untuk IP 192.168.0.3 dengan kecepatan upload maksimal 32 kbps dan download maksimal 64 kbps. Untuk kecepatan 1024 kbps kita bisa juga menuliskan 1M. Jika kita tidak menuliskan tanda &#8216;k&#8217; maka artinya adalah bits.</p>
<p>Setelah itu klik Apply dan OK. Maka selesailah sudah shaper kita. Kita bisa juga membuat shaper-shaper yang lain dengan cara yang sama. Paling tidak kita bisa mendapatkan shaper seperti berikut :</p>
<p><img title="Shaper Jadi" src="http://www.plikimage.com/images/HPJ26067.png" border="0" alt="Shaper Jadi" width="505" height="298" /></p>
<p>Tampak pada gambar diatas, pc1 mendapat bandwidth yang lebih banyak untuk download dibanding pc2 hingga pc6, namun semuanya mendapat bandwidth yang sama besar untuk upload yaitu hanya 32k.</p>
<p>Jika Simple Queue yang kita berikan benar, maka begitu di apply, maka shaper ini akan segera berfungsi. Dan jika berfungsi, kita akan melihat angka Upload Rate dan Download Rate akan bergerak dan berubah-ubah sesuai dengan pemakaian masing-masing komputer.</p>
<p>Warna merah menandakan komputer tersebut sudah menggunakan bandwidth secara penuh atau hampir penuh. Sedangkan warna kuning menandakan separo kapasitas sudah terpakai. Sedangkan warna hijau artinya tidak terpakai atau hanya terpakai kurang dari separo batas.</p>
<p>Dengan demikian selesai sudah shaper yang kita kerjakan untuk network kita. Dengan shaper, kita bisa menjaga operasional network kita agar berfungsi secara maksimal dan sesuai dengan semustinya. Dan membuat everybody happy.</p>
<p>source:  http://www.istanaku.biz</p>
]]></content:encoded>
			<wfw:commentRss>http://www.areksitiung.com/2009/04/09/melakukan-shaper-di-mikrotik/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Simple Firewall by Primadonal</title>
		<link>http://www.areksitiung.com/2009/01/29/simple-firewall-by-primadonal/</link>
		<comments>http://www.areksitiung.com/2009/01/29/simple-firewall-by-primadonal/#comments</comments>
		<pubDate>Thu, 29 Jan 2009 02:06:00 +0000</pubDate>
		<dc:creator>harinto</dc:creator>
				<category><![CDATA[Mikrotik]]></category>

		<guid isPermaLink="false">http://harinto.wordpress.com/?p=327</guid>
		<description><![CDATA[Make simple but powerfull.
triky of firewall management
1. To make filter brute forces
/ ip firewall filter
add chain=input protocol=tcp dst-port=22 src-address-list=ssh_blacklist action=drop comment=”Drop SSH brute forcers” disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=ssh_stage3 action=add-src-to-address-list address-list=ssh_blacklist \
address-list-timeout=1w3d comment=”&#8221; disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=ssh_stage2 action=add-src-to-address-list address-list=ssh_stage3 \
address-list-timeout=1m comment=”&#8221; disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=ssh_stage1 action=add-src-to-address-list address-list=ssh_stage2 \
address-list-timeout=1m comment=”&#8221; disabled=no
add [...]]]></description>
			<content:encoded><![CDATA[<p>Make simple but powerfull.<br />
triky of firewall management</p>
<p>1. To make filter brute forces</p>
<p>/ ip firewall filter<br />
add chain=input protocol=tcp dst-port=22 src-address-list=ssh_blacklist action=drop comment=”Drop SSH brute forcers” disabled=no<br />
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=ssh_stage3 action=add-src-to-address-list address-list=ssh_blacklist \<br />
address-list-timeout=1w3d comment=”&#8221; disabled=no<br />
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=ssh_stage2 action=add-src-to-address-list address-list=ssh_stage3 \<br />
address-list-timeout=1m comment=”&#8221; disabled=no<br />
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=ssh_stage1 action=add-src-to-address-list address-list=ssh_stage2 \<br />
address-list-timeout=1m comment=”&#8221; disabled=no<br />
add chain=input protocol=tcp dst-port=22 connection-state=new action=add-src-to-address-list address-list=ssh_stage1 address-list-timeout=1m comment=”&#8221; \<br />
disabled=no</p>
<p>2. To make filter port scaning<br />
/ ip firewall filter</p>
<p>add chain=input protocol=tcp psd=21,3s,3,1 action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w comment=”Port Scanners to list \<br />
” disabled=no<br />
add chain=input protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w \<br />
comment=”&#8221; disabled=no<br />
add chain=input protocol=tcp tcp-flags=fin,syn action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w comment=”&#8221; disabled=no<br />
add chain=input protocol=tcp tcp-flags=syn,rst action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w comment=”&#8221; disabled=no<br />
add chain=input protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w \<br />
comment=”&#8221; disabled=no<br />
add chain=input protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w comment=”&#8221; \<br />
disabled=no<br />
add chain=input protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w \<br />
comment=”&#8221; disabled=no<br />
add chain=input src-address-list=”port scanners” action=drop comment=”&#8221; disabled=no</p>
<p>3.To make filter ftp port</p>
<p>/ ip firewall filter</p>
<p>add chain=input protocol=tcp dst-port=21 src-address-list=ftp_blacklist action=drop comment=”Filter FTP to Box” disabled=no<br />
add chain=output protocol=tcp content=”530 Login incorrect” dst-limit=1/1m,9,dst-address/1m action=accept comment=”&#8221; disabled=no<br />
add chain=output protocol=tcp content=”530 Login incorrect” action=add-dst-to-address-list address-list=ftp_blacklist address-list-timeout=3h comment=”&#8221; \<br />
disabled=no</p>
<p>4. To make separate packet flag</p>
<p>/ ip firewall filter</p>
<p>add chain=forward protocol=tcp action=jump jump-target=tcp comment=”Separate Protocol into Chains” disabled=no<br />
add chain=forward protocol=udp action=jump jump-target=udp comment=”&#8221; disabled=no<br />
add chain=forward protocol=icmp action=jump jump-target=icmp comment=”&#8221; disabled=no</p>
<p>5. To make blocking udp satan traffic</p>
<p>/ ip firewall filter<br />
add chain=udp protocol=udp dst-port=69 action=drop comment=”Blocking UDP Packet” disabled=no<br />
add chain=udp protocol=udp dst-port=111 action=drop comment=”&#8221; disabled=no<br />
add chain=udp protocol=udp dst-port=135 action=drop comment=”&#8221; disabled=no<br />
add chain=udp protocol=udp dst-port=137-139 action=drop comment=”&#8221; disabled=no<br />
add chain=udp protocol=udp dst-port=2049 action=drop comment=”&#8221; disabled=no<br />
add chain=udp protocol=udp dst-port=3133 action=drop comment=”&#8221; disabled=no</p>
<p>6. To make blocking tcp satan traffic</p>
<p>/ ip firewall filter</p>
<p>add chain=tcp protocol=tcp dst-port=69 action=drop comment=”Bloking TCP Packet” disabled=no<br />
add chain=tcp protocol=tcp dst-port=111 action=drop comment=”&#8221; disabled=no<br />
add chain=tcp protocol=tcp dst-port=119 action=drop comment=”&#8221; disabled=no<br />
add chain=tcp protocol=tcp dst-port=135 action=drop comment=”&#8221; disabled=no<br />
add chain=tcp protocol=tcp dst-port=137-139 action=drop comment=”&#8221; disabled=no<br />
add chain=tcp protocol=tcp dst-port=445 action=drop comment=”&#8221; disabled=no<br />
add chain=tcp protocol=tcp dst-port=2049 action=drop comment=”&#8221; disabled=no<br />
add chain=tcp protocol=tcp dst-port=12345-12346 action=drop comment=”&#8221; disabled=no<br />
add chain=tcp protocol=tcp dst-port=20034 action=drop comment=”&#8221; disabled=no<br />
add chain=tcp protocol=tcp dst-port=3133 action=drop comment=”&#8221; disabled=no<br />
add chain=tcp protocol=tcp dst-port=67-68 action=drop comment=”&#8221; disabled=no</p>
<p>7. To make blocking bukis mail  traffic</p>
<p>/ ip firewall filter</p>
<p>add chain=forward protocol=tcp dst-port=25 action=drop comment=”Allow SMTP” disabled=no</p>
<p>8. To make filter dos  traffic</p>
<p>/ ip firewall filter</p>
<p>add chain=icmp protocol=icmp icmp-options=0:0-255 limit=5,5 action=accept comment=”Limited Ping Flood” disabled=no<br />
add chain=icmp protocol=icmp icmp-options=3:3 limit=5,5 action=accept comment=”&#8221; disabled=no<br />
add chain=icmp protocol=icmp icmp-options=3:4 limit=5,5 action=accept comment=”&#8221; disabled=no<br />
add chain=icmp protocol=icmp icmp-options=8:0-255 limit=5,5 action=accept comment=”&#8221; disabled=no<br />
add chain=icmp protocol=icmp icmp-options=11:0-255 limit=5,5 action=accept comment=”&#8221; disabled=no<br />
add chain=icmp protocol=icmp action=drop comment=”&#8221; disabled=no</p>
<p>9. To make filter p2p  traffic</p>
<p>/ ip firewall filter</p>
<p>add chain=forward p2p=all-p2p action=accept comment=”trafik P2P ” disabled=no</p>
<p>10. To make filter access network mapping  traffic</p>
<p>/ ip firewall filter<br />
add chain=input dst-address-type=broadcast,multicast action=accept comment=”Allow Broadcast Traffic” disabled=no<br />
add chain=input src-address=192.168.0.0/28 action=accept comment=”Allow access to router from known network” disabled=no<br />
add chain=input src-address=192.168.1.0/24 action=accept comment=”&#8221; disabled=no<br />
add chain=input src-address=192.168.2.0/30 action=accept comment=”&#8221; disabled=no<br />
add chain=input src-address=125.162.0.0/16 action=accept comment=”&#8221; disabled=no</p>
<p>11. To make filter junk  traffic and real traffic connection</p>
<p>/ ip firewall filter</p>
<p>add chain=input connection-state=established action=accept comment=”Connection State” disabled=no<br />
add chain=input connection-state=related action=accept comment=”&#8221; disabled=no<br />
add chain=input connection-state=invalid action=drop comment=”&#8221; disabled=no</p>
<p>sumber : http://harrychanputra.wordpress.com/</p>
]]></content:encoded>
			<wfw:commentRss>http://www.areksitiung.com/2009/01/29/simple-firewall-by-primadonal/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mengatasi Ping Reply Besar</title>
		<link>http://www.areksitiung.com/2009/01/05/mengatasi-ping-reply-besar/</link>
		<comments>http://www.areksitiung.com/2009/01/05/mengatasi-ping-reply-besar/#comments</comments>
		<pubDate>Mon, 05 Jan 2009 01:15:18 +0000</pubDate>
		<dc:creator>harinto</dc:creator>
				<category><![CDATA[Mikrotik]]></category>

		<guid isPermaLink="false">http://harinto.wordpress.com/?p=285</guid>
		<description><![CDATA[Setelah beberapa hari limiter jalan, saya masih sering dapat complain tentang salah satu lab disaat full maka “ping” replynya sampai ribuan ms bahkan kadang-kadang putus / tidak reply. asumsi orang (sugesti) bahwa kalau ping besar koneksi lambat…. apalagi kalau ada putus dipikir kita “ngak fair” bagi bandwidthnya….wah ini salah kaprah. coba dijelaskan juga, dasar user [...]]]></description>
			<content:encoded><![CDATA[<p>Setelah beberapa hari limiter jalan, saya masih sering dapat complain tentang salah satu lab disaat full maka “ping” replynya sampai ribuan ms bahkan kadang-kadang putus / tidak reply. asumsi orang (sugesti) bahwa kalau ping besar koneksi lambat…. apalagi kalau ada putus dipikir kita “ngak fair” bagi bandwidthnya….wah ini salah kaprah. coba dijelaskan juga, dasar user adalah raja … dan dari pada nantinya saya dibilang kerja ngga “bejussss” …. ya akhirnya surfing dan tanya &#8211; tanya sama om google.</p>
<p>kenapa ping bisa besar ?? karena limit bandwidth di koneksi dia sudah habis/mepet. nah icmp yang akan lewat “diapsen” dan akan di “antri” ….</p>
<p>64 bytes from 66.94.234.13: icmp_seq=1 ttl=48 time=1045.0 ms<br />
64 bytes from 66.94.234.13: icmp_seq=2 ttl=48 time=1922.0 ms<br />
64 bytes from 66.94.234.13: icmp_seq=5 ttl=49 time=2013.0 ms<br />
64 bytes from 66.94.234.13: icmp_seq=6 ttl=48 time=1903.0 ms<br />
64 bytes from 66.94.234.13: icmp_seq=7 ttl=48 time=1979.2 ms<br />
64 bytes from 66.94.234.13: icmp_seq=8 ttl=48 time=1932.0 ms<br />
64 bytes from 66.94.234.13: icmp_seq=9 ttl=48 time=2300.2 ms</p>
<p>Triknya adalah menyediakan sedikit bandwidth dari limitnya lab bersangkutan untuk didedikasikan packet ICMP.</p>
<p>pertama tama bikin manglenya :<br />
/ip firewall mangle add chain=forward src-address=192.168.0.64/<br />
28 protocol=icmp action=mark-connection new-connection-mark=lab1icmp-cm passthrough=yes<br />
/ip firewall mangle add chain=forward connection-mark=lab1icmp-<br />
cm action=mark-packet new-packet-mark=lab1icmp-pm passthrough=yes<br />
/ip firewall mangle add chain=forward packet-mark=lab1icmp-pm a<br />
ction=change-tos new-tos=min-delay</p>
<p>Ok sekarang bikin Queuenya<br />
Skema saya adalah sebagai berikut :<br />
Bandwidth 128 Kbps : 4 Kbps untuk ICMP sisanya untuk service internet lainnya…<br />
pertama kita dedikasikan dulu bandwith yang nanti dijadikan parent oleh rule queue yang kita buat.<br />
/queue tree add name=lab1-down parent=Downstream max-limit=128k<br />
kemudian kita pecah menjadi:<br />
/queue tree add name=downlab1 parent=lab1-down packet-mark=lab1<br />
-pm queue=default max-limit=124k<br />
/queue tree add name=icmplab1 parent=lab1-down packet-mark=lab1<br />
icmp-pm queue=default max-limit=4k<br />
Hasilnya :<br />
64 bytes from 66.94.234.13: icmp_seq=22 ttl=48 time=655.3 ms<br />
64 bytes from 66.94.234.13: icmp_seq=23 ttl=48 time=645.0 ms<br />
64 bytes from 66.94.234.13: icmp_seq=24 ttl=49 time=645.0 ms<br />
64 bytes from 66.94.234.13: icmp_seq=25 ttl=48 time=635.0 ms<br />
64 bytes from 66.94.234.13: icmp_seq=26 ttl=48 time=634.7 ms<br />
64 bytes from 66.94.234.13: icmp_seq=27 ttl=48 time=634.8 ms<br />
64 bytes from 66.94.234.13: icmp_seq=28 ttl=48 time=655.3 ms<br />
sumber:om google</p>
]]></content:encoded>
			<wfw:commentRss>http://www.areksitiung.com/2009/01/05/mengatasi-ping-reply-besar/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
