Mikrotik RouterOS™" adalah sistem operasi dan perangkat lunak yang dapat digunakan untuk menjadikan komputer biasa menjadi router network yang handal,mencakup berbagai fitur yang dibuat untuk ip network dan jaringan wireless.
Mikrotik RouterOS™, merupakan sistem operasi Linux base yang diperuntukkan sebagai network router. Didesain untuk memberikan kemudahan bagi penggunanya. Administrasinya bisa dilakukan melalui Windows Application (WinBox). Selain itu instalasi dapat dilakukan pada Standard komputer PC (Personal Computer). PC yang akan dijadikan router Mikrotik pun tidak memerlukan resource yang cukup besar untuk penggunaan standard, misalnya hanya sebagai gateway. Untuk keperluan beban yang besar (network yang kompleks, routing yang rumit) disarankan untuk mempertimbangkan pemilihan resource/spesifikasi PC yang memadai.
Dalam dunia router, mesin yang berfungsi mengarahkan alamat di Internet, Cisco merupakan nama yang sudah tidak diragukan lagi. Tetapi di dunia lain, nama Mikrotik, yang berbentuk software, lumayan dikenal sebagai penyedia solusi murah untuk fungsi router, bahkan kita dapat membuat router sendiri dari computer rumahan.
Jenis-Jenis Mikrotik
* Mikrotik RouterOS™ yang berbentuk software yang dapat di-download di www.Mikrotik.com. Dapat diinstal pada komputer rumahan (PC).
* BUILT-IN Hardware Mikrotik dalam bentuk perangkat keras yang khusus dikemas dalam board router yang didalamnya sudah terinstal Mikrotik RouterOS™.
Fitur-Fitur Mikrotik
1. Address List, Pengelompokan IP address berdasarkan nama.
2. Asynchronous, Mendukung serial PPP dial-in/dialout, dengan otentikasi CHAP,
PAP, MSCHAPv1 dan MSCHAPv2, Radius, dial on demand, modem pool hingga 128 ports.
3. Bonding, Mendukung dalam pengkombinasian beberapa antarmuka ethernet ke dalam 1
pipa pada koneksi yang cepat.
4. Bridge, Mendukung fungsi bridge spanning tree, multiple bridge interface, bridge
firewalling.
5. Data Rate Management, QoS berbasis HTB dengan penggunaan busrt, PCQ, RED, SFQ,
FIFO queue, CIR, MIR, limit antar peer to peer.
6. DHCP, Mendukung DHCP tiap antar muka; DHCP relay; DHCP client, multiple network
DHCP; static and dynamic DHCP leases.
7. Firewall and NAT, Mendukung pemfilteran koneksi peer to peer, source NAT dan
destination NAT. Mampu memfilter berdasarkan MAC, IP address, range port,
protokol IP, pemilihan opsi protokol seperti ICMP, TCP flags dan MSS.
8. Hotspot, Hotspot gateway dengan otentifikasi RADIUS. Mendukung limit data rate,
SSL, HTTPS.
9. IPSec, Protokol AH dan ESP untuk IPSec; MODP Diffie-Hellman groups 1, 2, 5; MD5
dan algoritma SHA1 hashing; algoritma enkripsi menggunakan DES, 3DES, AES-128,
AES-129, AES-256; Perfect Forwarding Secresy (PFS) MODP groups 1, 2, 5.
10.ISDN, Mendukung ISDN dial-in/dial out. Dengan otentikasi PAP, CHAP, MSCHAPv1
dan MSCHAPv2, Radius. Mendukung 128K bundle, Cisco HDLC, x751, x75ui, x75bui
line protokol.
11.M3P, Mikrotik Protokol Paket Packer untuk wireless links dan ethernet.
12.MNDP, Mikrotik Discovery Neighbor Protocol, juga mendukung Cisco Discovery
Protocol (CDP).
13.Monitoring/Accounting, Laporan traffic IP, log, statistik graphs yang dapat
diakses melalui HTTP.
14.NTP, Network Time Protokol untuk server dan client; sinkronisasi menggunkan
system GPS.
15.Point to Point Tunneling Protocol, PPTP, PPPoE dan L2TP Access Concentrators;
protokol otentikasi menggunakan PAP, CHAP, MSCHAPv1, MSCHAPv2; otentikasi dan
laporan RADIUs; enkripsi MPPE; kompresi untuk PpoE; Limit data rate.
16.Proxy, Cache untuk FTP dan HTTP proxy server; HTTPS proxy; transparent proxy
untuk DNS dan HTTP; mendukung protokol SOKCS; mendukung parent proxy; statik DNS
17.Routing, Routing statik dan dinamik; RIP v1/v2, OSPF v2, BGP v4.
18.SDSL, Mendukung Single Line DSL; mode pemutusan jalur koneksi dan jaringan.
19.Simple Tunnels, Tunnel IPIP dan EoIP (Ethernet over IP).
20.SNMP, Mode akses read only.
21.Synchronous, V.35, V.24, E1/T1, X21, DS3 (T3) media types; sync-PPP, Cisco HDLC;
Frame Relay line protocol; ANSI-617d (ANDI atau annex D) dan Q933a (CCIT atau
annex A); Frame Relay jenis LMI.
22.Tool, Ping; Traceroute; bandwidth test; ping flood; telnet; SSH; packet sniffer;
Dinamic DNS update.
23.UpnP, Mendukung antar muka universal Plug and Play.
24.VLAN, Mendukung Virtual LAN IEEE802.1q untuk jaringan ethernet dan wireless;
multiple VLAN; VLAN bridging.
25.VOIP, Mendukung aplikasi voice over IP.
26.VRPP, Mendukung Virtual Router Redudant Protocol.
27.Winbox, Aplikasi mode GUI untuk meremote dan mengkonfigurasi Mikrotik RouterOS.
sumber: mikrotik.com
Selengkapnya...
Sabtu, 18 Desember 2010
TENTANG Mikrotik RouterOS™"
Senin, 29 November 2010
Setting Mikrotik 2 line speedy untuk warnet
Setting Mikrotik 2 line speedy untuk warnet
Iseng cuma buat sinpan data aja.. setting mikrotik 2 line speedy dengan mikrotik dengan memisahkan ip game dan browsing, agar menuju Jalur nya masing masing...
rencana routerdibuat 3 in 1, yaitu warnet di mana Game+Browsing dan Download + Bermain game online bisa kita laksanakan dalam 1 PC.
ok lanjut : topologi yang saya gunakan dengan menggunakan 2 line speedy yaitu speedy Excekutif dan speedy Game
topologi :
Speedy1------->|MikroTik|--------Client
-----------------|
Speedy2------->|
-----------------|
Proxy ubuntu---|
Speck :
= Speedy Game
= Speedy Excekutif
= mikrotik RB 450G
= Squid Proxy Settingnya di sini
di sini hanya akan mengulas Mikrotik nya aja di mana saya Menggunakan RB 450G
interpace 1 : lan
interface 2 : speedy game (jalur game )
interface 3 : speedy Excekutif ( jalur browsing )
interface 4 : Proxy ( ubuntu server 10.10 )
interface yang terpakai sebanyak 4 interface dari 5 interface rb 450G
[admin@Mitr@Net] > interface pr
Flags: D - dynamic, X - disabled, R - running, S - slave
# NAME TYPE MTU L2MTU
0 R lan ether 1500
1 R speedy5.1 ether 1500
2 R speedy3.1 ether 1500
3 R proxy ether 1500
memberikan ip dan nama pada masing masing interface
[admin@Mitr@Net] > ip address pr
Flags: X - disabled, I - invalid, D - dynamic
# ADDRESS NETWORK BROADCAST INTERFACE
0 192.168.10.1/24 192.168.10.0 192.168.10.255 lan
1 192.168.1.1/24 192.168.1.0 192.168.1.255 proxy
2 192.168.5.2/24 192.168.5.0 192.168.5.255 speedy5.1
3 192.168.3.2/24 192.168.3.0 192.168.3.255 speedy3.1
Proses pppoe only via modem sehingga gatway mikrotik adalah ip modem
[admin@MikroTik] > ip route pr
Flags: X - disabled, A - active, D - dynamic, C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme,
B - blackhole, U - unreachable, P - prohibit
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 A S 0.0.0.0/0 192.168.3.1 1
1 A S 0.0.0.0/0 192.168.5.1 1
2 ADC 192.168.1.0/24 192.168.1.1 proxy 0
3 ADC 192.168.3.0/24 192.168.3.2 speedy3.1 0
4 ADC 192.168.5.0/24 192.168.5.2 speedy5.1 0
5 ADC 192.168.10.0/24 192.168.10.1 lan 0
NB : ip modem : 192.168.3.1 & 192.168.5.1
---- ip Proxy : 192.168.1.10
nat untuk menyambungkan masing masing interface pada mikrotik
[admin@Mitr@Net] > ip firewall nat pr
Flags: X - disabled, I - invalid, D - dynamic
0 chain=srcnat action=masquerade src-address=192.168.10.0/24 routing-mark=iix dst-address-list=nice
out-interface=speedy3.1
1 chain=srcnat action=masquerade src-address=192.168.1.0/24
2 chain=srcnat action=masquerade src-address=192.168.10.0/24 out-interface=speedy5.1
3 chain=dstnat action=dst-nat to-addresses=192.168.1.10 to-ports=3128 protocol=tcp src-address=!192.168.1.10
routing-mark=!iix dst-port=80
4 chain=dstnat action=dst-nat to-addresses=192.168.1.10 to-ports=3128 protocol=tcp dst-port=8080
Memasang jebakan untuk trafik yang berasal dari lan, agar bisa diproses dan menuju post nya masing masing
[admin@Mitr@Net > ip firewall mangle pr
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; squid
chain=postrouting action=mark-packet new-packet-mark=proxy-hit
passthrough=no dscp=12
1 ;;; game
chain=prerouting action=mark-routing new-routing-mark=iix passthrough=no
protocol=tcp src-address=192.168.10.0/24 dst-address-list=nice
dst-port=!80
2 ;;; game udp
chain=prerouting action=mark-routing new-routing-mark=iix passthrough=no
protocol=udp src-address=192.168.10.0/24 dst-address-list=nice
dst-port=!80
3 ;;; browsing
chain=forward action=mark-connection new-connection-mark=semua
passthrough=yes src-address=192.168.10.0/26 dst-address=!202.58.181.0/24
dst-address-list=!nice
4 chain=postrouting action=mark-packet new-packet-mark=paket_kecil
passthrough=no protocol=tcp connection-mark=semua
connection-bytes=0-600000
5 chain=postrouting action=mark-packet new-packet-mark=paket_besar
passthrough=no connection-mark=semua
mengatur bandwith hasil jebakan dari firewall
[admin@Mitr@Net > queue tree pr
Flags: X - disabled, I - invalid
0 name="File_Besar" parent=B-Global-Download packet-mark=paket_besar
limit-at=64k queue=PCQ_download priority=8 max-limit=456k burst-limit=0
burst-threshold=0 burst-time=0s
1 name="File_Kecil" parent=B-Global-Download packet-mark=paket_kecil
limit-at=256k queue=PCQ_download priority=1 max-limit=1400k
burst-limit=0 burst-threshold=0 burst-time=0s
2 name="Upload_Kecil" parent=C-Global_Upload packet-mark=paket_kecil
limit-at=64k queue=PCQ_upload priority=8 max-limit=350k burst-limit=0
burst-threshold=0 burst-time=0s
3 name="Upload_Besar" parent=C-Global_Upload packet-mark=paket_besar
limit-at=24k queue=PCQ_upload priority=8 max-limit=85k burst-limit=0
burst-threshold=0 burst-time=0s
4 name="A_HIT-Proxy" parent=lan packet-mark=proxy-hit limit-at=0
queue=default priority=1 max-limit=0 burst-limit=0 burst-threshold=0
burst-time=0s
5 name="C-Global_Upload" parent=proxy packet-mark="" limit-at=0 priority=1
max-limit=500k burst-limit=0 burst-threshold=0 burst-time=0s
6 name="B-Global-Download" parent=lan packet-mark="" limit-at=0 priority=1
max-limit=0 burst-limit=0 burst-threshold=0 burst-time=0s
isi file Nice :
[admin@Mitr@Net] > ip firewall address pr
Flags: X - disabled, D - dynamic
# LIST ADDRESS
0 nice 202.10.32.0/24
1 nice 202.75.54.0/24
2 nice 202.93.20.0/24
3 nice 202.93.21.0/24
4 ;;; POINT BLANK
nice 203.89.146.0/24
5 nice 202.93.17.0/24
6 ;;; POIN BLANK!!
nice 216.239.61.0/24
7 nice 119.110.107.0/24
........................ sampai disini udah bisa berjalan normal
Selengkapnya...
Sabtu, 27 November 2010
Jumat, 26 November 2010
Load Balancing Mikrotik + Proxy
Load balancing Mikrotik kali ini saya coba dengan 2 line speedy digabungkan dengan mesin squid web proxy, berbeda dengan load balancing versi sebelum ini. Pada load balancing kali ini saya tambahkan redirect ke squid dengan mengunakan mikrotik sebagai mesin load balancer-nya.
Langkah pertama install dulu mikrotik seperti di tutorial ini, lalu sebelum mencoba, saya sarankan mereset mikrotik dulu, supaya kembali pada settingan default. untuk reset bisa menggunkan perintah : “/sy reset“.
Setelah Mikrotik diinstall, pastikan dulu bahwa interface pada mikrotik ada 4biji, interface 1 menuju ke klient, interface 2 menuju ke Speedy 1, interface 3 menuju ke speedy 2 dan interface 4 menuju ke squid web proxy.
baiklah kita mulai copy paste setting dibawah ini pada terminal Mikrotik :
/in eth
set ether1 name="intranet" disabled=no
set ether2 name="speedy-1" disabled=no
set ether3 name="speedy-2" disabled=no
set ether4 name="proxy" disabled=no
/ip add
add address=192.168.1.2/24 interface=speedy-1 comment="ke speedy-1"
add address=192.168.2.2/24 interface=speedy-2 comment="ke speedy-2"
add address=192.168.11.1/27 interface=intranet comment="ke Hub"
add address=192.168.10.2/30 interface=proxy comment="ke-proxy"
/ ip dns
set primary-dns=203.130.193.74 secondary-dns=202.134.0.155 allow-remote-requests=yes cache-size=2048KiB cache-max-ttl=1w
/ ip firewall mangle
add chain=prerouting in-interface=intranet connection-state=new nth=1,2,0 action=mark-connection new-connection-mark=satu passthrough=yes comment=""
add chain=prerouting in-interface=intranet connection-mark=satu action=mark-routing new-routing-mark=satu passthrough=no comment=""
add chain=prerouting in-interface=intranet connection-state=new nth=1,2,1 action=mark-connection new-connection-mark=dua passthrough=yes comment=""
add chain=prerouting in-interface=intranet connection-mark=dua action=mark-routing new-routing-mark=dua passthrough=no comment="" disabled=no
add chain=prerouting in-interface=proxy connection-state=new nth=1,2,0 action=mark-connection new-connection-mark=tiga passthrough=yes comment=""
add chain=prerouting in-interface=proxy connection-mark=tiga action=mark-routing new-routing-mark=tiga passthrough=no comment=""
add chain=prerouting in-interface=proxy connection-state=new nth=1,2,1 action=mark-connection new-connection-mark=empat passthrough=yes comment=""
add chain=prerouting in-interface=proxy connection-mark=empat action=mark-routing new-routing-mark=empat passthrough=no comment="" disabled=no
/ ip firewall nat
add chain=srcnat out-interface=speedy-1 connection-mark=satu action=src-nat to-addresses=192.168.1.1 to-ports=0-65535 comment="" disabled=no
add chain=srcnat out-interface=speedy-2 connection-mark=dua action=src-nat to-addresses=192.168.2.1 to-ports=0-65535 comment="" disabled=no
nat add chain=dstnat protocol=tcp dst-port=80 action=redirect to-ports=3128
add chain=dstnat protocol=tcp dst-port=3128 action=redirect to-ports=3128
add chain=dstnat protocol=tcp dst-port=8080 action=redirect to-ports=3128
/ ip firewall connection tracking
set enabled=yes tcp-syn-sent-timeout=2s tcp-syn-received-timeout=2s tcp-established-timeout=1d tcp-fin-wait-timeout=5s tcp-close-wait-timeout=5s tcp-last-ack-timeout=5s tcp-time-wait-timeout=5s tcp-close-timeout=5s udp-timeout=5s udp-stream-timeout=1m icmp-timeout=5s generic-timeout=5m tcp-syncookie=no
/ ip route
add dst-address=0.0.0.0/0 gateway=192.168.1.1 scope=255 target-scope=10 routing-mark=satu comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=192.168.2.1 scope=255 target-scope=10 routing-mark=dua comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=192.168.1.1 scope=255 target-scope=10
/ ip proxy
set enabled=yes port=3128 parent-proxy=192.168.10.1:3128 maximal-client-connecions=1000 maximal-server-connectons=1000
Ohya mikrotik yang saya gunakan untuk testing kali ini adalah versi bajakan 2.9.27, untuk versi 3 keatas silahkan lihat setting mangle-nya pada tulisan ini dan tulisan ini. ohya kalo pake bajakan saya sarankan setelah settingannya berjalan, silahkan beli Mikrotik ASLI ya!!
NB : tidak disarankan untuk GameOnline Just Browsing
Selengkapnya...
Minggu, 14 November 2010
Rule For Gaming, Download And Browsing
Pembagian Port Prioritas untuk Game, Download Dan Browsing kira-kira sebagai berikut.
Dengan paket Speedy EXECUTIVE ( DownStream UpTo 2mbps UpStream UpTo 512kbps )
Asumsi Jaringan sudah terhubung dengan internet
KE CLIENT ; LOKAL
1. Add Queue Type
/queue type
set default-small kind=pfifo name=default-small pfifo-limit=10
2. Add Firewall > Filter
/ip firewall filter
add action=drop chain=forward comment=”Limit Simulation Connection” connection-limit=32,32 disabled=no protocol=tcp \
src-address=192.168.1.0/24 tcp-flags=syn
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.exe \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.7z \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.iso \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.zip \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.mpeg \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.mpg \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.flv \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.3gp \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.rm \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.avi \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.rar \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.mp4 \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.mkv \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.mov \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.msi \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.wav \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.wmv \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.wma \
disabled=no protocol=tcp src-address=192.168.1.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=.mp3 \
disabled=no protocol=tcp src-address=192.168.0.0/24
add action=add-dst-to-address-list address-list=DOWNLOAD address-list-timeout=1h chain=forward comment=”" content=\
videoplayback disabled=no protocol=tcp src-address=192.168.1.0/24
3. Add Firewall > Mangle
/ip firewall mangle
add action=mark-connection chain=prerouting comment=”ICMP & DNS———————————————–” disabled=\
no dst-port=53,123 in-interface=LOKAL new-connection-mark=QoS_0_con passthrough=yes protocol=udp
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_0_con disabled=no new-packet-mark=QoS_0 \
passthrough=no
add action=mark-connection chain=prerouting comment=”" disabled=no in-interface=LOKAL new-connection-mark=QoS_0_con \
passthrough=yes protocol=icmp
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_0_con disabled=no new-packet-mark=QoS_0 \
passthrough=no
add action=mark-connection chain=prerouting comment=SSH———————————————————— \
disabled=no dst-port=22 in-interface=LOKAL new-connection-mark=QoS_1_con passthrough=yes protocol=tcp
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_1_con disabled=no new-packet-mark=QoS_1 \
passthrough=no
add action=mark-connection chain=prerouting comment=”World of Warcraft—————————————” disabled=\
no dst-port=1119,3724,6881,6112,24783,4000 in-interface=LOKAL new-connection-mark=QoS_1_con passthrough=yes protocol=\
tcp
add action=mark-connection chain=prerouting comment=”" disabled=no dst-port=1028 in-interface=LOKAL new-connection-mark=\
QoS_1_con passthrough=yes protocol=udp
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_1_con disabled=no new-packet-mark=QoS_1 \
passthrough=no
add action=mark-connection chain=prerouting comment=”POINT BLANK——————————————–” disabled=no \
dst-port=39100-49100 in-interface=LOKAL new-connection-mark=QoS_1_con passthrough=yes protocol=tcp
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_1_con disabled=no new-packet-mark=QoS_1 \
passthrough=no
add action=mark-connection chain=prerouting comment=”" disabled=no dst-port=40000-40009 in-interface=LOKAL \
new-connection-mark=QoS_1_con passthrough=yes protocol=udp
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_1_con disabled=no new-packet-mark=QoS_1 \
passthrough=no
add action=mark-connection chain=prerouting comment=”RF ONLINE————————————————-” \
disabled=no dst-port=27780,10007 in-interface=LOKAL new-connection-mark=QoS_2_con passthrough=yes protocol=tcp
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_2_con disabled=no new-packet-mark=QoS_2 \
passthrough=no
add action=mark-connection chain=prerouting comment=”DOTA ONLINE——————————————-” disabled=no \
dst-port=6100-6250 in-interface=LOKAL new-connection-mark=QoS_2_con passthrough=yes protocol=tcp
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_2_con disabled=no new-packet-mark=QoS_2 \
passthrough=no
add action=mark-connection chain=prerouting comment=”AYO DANCE———————————————–” disabled=\
no dst-port=18900-18910 in-interface=LOKAL new-connection-mark=QoS_2_con passthrough=yes protocol=tcp
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_2_con disabled=no new-packet-mark=QoS_2 \
passthrough=no
add action=mark-connection chain=prerouting comment=CABAL——————————————————– \
disabled=no dst-port=63123,38122 in-interface=LOKAL new-connection-mark=QoS_2_con passthrough=yes protocol=tcp
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_2_con disabled=no new-packet-mark=QoS_2 \
passthrough=no
add action=mark-connection chain=prerouting comment=”Hold’em Poker” disabled=no dst-port=9339,843,1935 in-interface=LOKAL \
new-connection-mark=QoS_2_con passthrough=yes protocol=tcp
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_2_con disabled=no new-packet-mark=QoS_2 \
passthrough=no
add action=mark-connection chain=prerouting comment=”PW ONLINE———————————————–” disabled=\
no dst-port=29000 in-interface=LOKAL new-connection-mark=QoS_3_con passthrough=yes protocol=tcp
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_3_con disabled=no new-packet-mark=QoS_3 \
passthrough=no
add action=mark-connection chain=prerouting comment=DOWNLOAD———————————————- disabled=no \
dst-address-list=DOWNLOAD dst-port=80,8080,3128 in-interface=LOKAL new-connection-mark=QoS_5_con passthrough=yes \
protocol=tcp
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_5_con disabled=no new-packet-mark=QoS_5 \
passthrough=no
add action=mark-connection chain=prerouting comment=”" disabled=no dst-address-list=DOWNLOAD dst-port=\
110,995,143,993,25,20,21 in-interface=LOKAL new-connection-mark=QoS_5_con passthrough=yes protocol=tcp
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_5_con disabled=no new-packet-mark=QoS_5 \
passthrough=no
add action=mark-connection chain=prerouting comment=BROWSING———————————————— disabled=no \
dst-port=80,8080,3128,443,7778 in-interface=LOKAL new-connection-mark=QoS_4_con packet-size=0-666 passthrough=yes \
protocol=tcp tcp-flags=syn
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_4_con disabled=no new-packet-mark=QoS_4 \
passthrough=no
add action=mark-connection chain=prerouting comment=”" disabled=no dst-port=80,8080,3128,443,7778 in-interface=LOKAL \
new-connection-mark=QoS_4_con packet-size=0-666 passthrough=yes protocol=tcp tcp-flags=ack
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_4_con disabled=no new-packet-mark=QoS_4 \
passthrough=no
add action=mark-connection chain=prerouting comment=”" connection-bytes=0-1000000 disabled=no dst-port=\
80,8080,3128,443,7778 in-interface=LOKAL new-connection-mark=QoS_4_con passthrough=yes protocol=tcp
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_4_con disabled=no new-packet-mark=QoS_4 \
passthrough=no
add action=mark-connection chain=prerouting comment=”" disabled=no dst-port=110,995,143,993,25,20,21 in-interface=LOKAL \
new-connection-mark=QoS_4_con packet-size=0-666 passthrough=yes protocol=tcp tcp-flags=syn
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_4_con disabled=no new-packet-mark=QoS_4 \
passthrough=no
add action=mark-connection chain=prerouting comment=”" disabled=no dst-port=110,995,143,993,25,20,21 in-interface=LOKAL \
new-connection-mark=QoS_4_con packet-size=0-666 passthrough=yes protocol=tcp tcp-flags=ack
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_4_con disabled=no new-packet-mark=QoS_4 \
passthrough=no
add action=mark-connection chain=prerouting comment=”P2P Kelaut Aja——————————————–” \
disabled=no in-interface=LOKAL new-connection-mark=QoS_8_con p2p=all-p2p passthrough=yes
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_8_con disabled=no new-packet-mark=QoS_8 \
passthrough=no
add action=mark-connection chain=prerouting comment=Other———————————————————– \
disabled=no in-interface=LOKAL new-connection-mark=QoS_7_con passthrough=yes
add action=mark-packet chain=prerouting comment=”" connection-mark=QoS_7_con disabled=no new-packet-mark=QoS_7 \
passthrough=no
4. Add Queue > Simple
/queue simple
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s comment=”" \
direction=both disabled=no dst-address=0.0.0.0/0 interface=all limit-at=\
0/0 max-limit=512k/2M name=TOTAL parent=none priority=8 queue=\
default-small/default-small target-addresses=192.168.1.0/24 total-queue=\
default-small
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s comment=”" \
direction=both disabled=no dst-address=0.0.0.0/0 interface=all limit-at=\
8k/16k max-limit=16k/64k name=”QoS_0 – ICMP & DNS” packet-marks=QoS_0 \
parent=TOTAL priority=1 queue=pfifo-64/pfifo-64 target-addresses=\
192.168.1.0/24 total-queue=default-small
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s comment=”" \
direction=both disabled=no dst-address=0.0.0.0/0 interface=all limit-at=\
16k/32k max-limit=512k/2M name=”QoS_1 – WoW, PB” packet-marks=QoS_1 \
parent=TOTAL priority=1 queue=default-small/default-small \
target-addresses=192.168.1.0/24 total-queue=default-small
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s comment=”" \
direction=both disabled=no dst-address=0.0.0.0/0 interface=all limit-at=\
16k/64k max-limit=512k/2M name=\
“QoS_2 – RF | Dota | Poker | Ayo Dance | Cabal” packet-marks=QoS_2 \
parent=TOTAL priority=2 queue=default-small/default-small \
target-addresses=192.168.1.0/24 total-queue=default-small
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s comment=”" \
direction=both disabled=no dst-address=0.0.0.0/0 interface=all limit-at=\
16k/32k max-limit=512k/2M name=”QoS_3 – Perfect World” packet-marks=QoS_3 \
parent=TOTAL priority=3 queue=default-small/default-small \
target-addresses=192.168.1.0/24 total-queue=default-small
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s comment=”" \
direction=both disabled=no dst-address=0.0.0.0/0 interface=all limit-at=\
32k/128k max-limit=512k/2M name=”QoS_4 – Browsing” packet-marks=QoS_4 \
parent=TOTAL priority=4 queue=UpStream/DownStream target-addresses=\
192.168.1.0/24 total-queue=default-small
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s comment=”" \
direction=both disabled=no dst-address=0.0.0.0/0 interface=all limit-at=\
16k/32k max-limit=32k/1M name=”QoS_5 – Download” packet-marks=QoS_5 \
parent=TOTAL priority=5 queue=default-small/default-small \
target-addresses=192.168.1.0/24 total-queue=default-small
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s comment=”" \
direction=both disabled=no dst-address=0.0.0.0/0 interface=all limit-at=\
0/0 max-limit=0/0 name=QoS_6 packet-marks=QoS_6 parent=TOTAL priority=6 \
queue=default-small/default-small target-addresses=192.168.1.0/24 \
total-queue=default-small
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s comment=”" \
direction=both disabled=no dst-address=0.0.0.0/0 interface=all limit-at=\
0/0 max-limit=32k/128k name=”QoS_7 – Lain – Lain” packet-marks=QoS_7 \
parent=TOTAL priority=7 queue=default-small/default-small \
target-addresses=192.168.1.0/24 total-queue=default-small
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s comment=”" \
direction=both disabled=no dst-address=0.0.0.0/0 interface=all limit-at=\
0/0 max-limit=8k/32k name=”QoS_8 – Peer To Peer” packet-marks=QoS_8 \
parent=TOTAL priority=8 queue=default-small/default-small \
target-addresses=192.168.1.0/24 total-queue=default-small
Selengkapnya...
SCRIPT SHUTDOWN MIKROTIK DARI WINDOWS
Untuk melakukan soft halt mikrotik dari windows dengan satu script langkah - langkahnya adalah sebagai berikut:
- buat user khusus untuk shutdown dengan kewenangan terbatas
misal username operator password operator
- Install putty
- jalankan perintah berikut di command prompt :
set PATH=C:\Program Files\Putty;%PATH%
usahakan path tersebut diset setiap komputer startup dengan meletakkan
perintah diatas pada autoexec.bat
- buat dengan notepad file script.ssh yang berisi perintah
/system shutdown;
/yes;
- buat dengan notepad file shutdown.bat yang berisi :
plink.exe -pw operator -m script.ssh operator@192.168.1.1
jalankan file shutdown.bat dari direktori yg sama dengan file script.ssh
Untuk file plink.exe bisa di download disini.
Selengkapnya...
MEMFILTER BRUTE FORCES DI MIKROTIK
simple firewall untuk memfilter brute forces di mikrotik.
/ ip firewall filter
add chain=input protocol=tcp dst-port=22 src-address-list=ssh_blacklist action=drop comment=”KILL SSH brute forcers” disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=ssh_stage3 action=add-src-to-address-list address-list=ssh_blacklist address-list-timeout=1w1d comment=”” disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=ssh_stage2 action=add-src-to-address-list address-list=ssh_stage3 address-list-timeout=1m comment=”” disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=ssh_stage1 action=add-src-to-address-list address-list=ssh_stage2 address-list-timeout=1m comment=”” disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new action=add-src-to-address-list address-list=ssh_stage1 address-list-timeout=1m comment=”” disabled=no
Selengkapnya...
SCRIPT AUTO CHANGE DNS + FLUSH DNS DI MIKROTIK
script auto change dns + flush dns di mikrotik. Tujuan dibuat script adalah untuk melimit akses konten dewasa pada jam - jam sibuk dan membukanya kembali pada saat jam santai, dengan asumsi jam 08.00 - 21.00 WIB memakai OpenDNS, dan jam 21.00 - 08.00 WIB memakai DNS Telkom lagi. Langkah - langkahnya adalah sebagai berikut:
- Bikin script dulu dengan nama "proteksi" dengan source code seperti dibawah ini:
/ip dns cache flush
/ip dns set primary-dns=208.67.222.222
/ip dns set secondary-dns=208.67.220.220
- Bikin satu script lagi dengan nama "bebas", source code seperti dibawah ini:
/ip dns cache flush
/ip dns set primary-dns=203.130.208.18
/ip dns set secondary-dns=202.134.1.10
- Kemudian bikin schedule nya, seperti dibawah ini:
/system scheduler add name="pengamanan" interval=1d start-time=08:00:00 on-event=proteksi
/system scheduler add name="pembebasan" interval=1d start-time=21:00:00 on-event=bebas
jangan lupa untuk DNS client diarahkan ke Mikrotiknya, dan /ip dns di set allow-remote-requests=yes.
best Open DNS
Selengkapnya...
SIMPLE FIREWALL DI MIKROTIK
Simple Firewall Ampuh di mikrotik. Fungsi dari firewall ini adalah: Memblok akses yang tidak di ijinkan yang datang dari arah publik. selain yang di allow. semua akses masuk dari publik akan di drop. attacker flooder maupun port scanner yang akan menembus mikrotik anda dari luar akan di drop.
Asumsi:
Wan : Interface ke arah internet.
Lokal : Interface ke arah client.
Ip Local : 192.168.1.0/24
Rule:
ip firewall filter
add chain=forward in-interface=Wan out-interface=Lokal dst-address=192.168.1.0/24 action=accept comment="Allow semua akses internet to client" disabled=no
add chain=input in-interface=Wan protocol=tcp dst-port=8291 action=accept comment="Allow Remote winbox dari Publik" disabled=no
add chain=input in-interface=Wan protocol=udp src-port=123 action=accept comment="Allow NTP Traffic" disabled=no
add chain=input in-interface=Wan protocol=udp src-port=53 action=accept comment="Allow DNS Traffic" disabled=no
add chain=input in-interface=Wan protocol=icmp action=accept comment="Allow Ping Traceroute Traffic" disabled=no
add chain=input in-interface=Wan connection-state=new action=add-src-to-address-list address-list=spam address-list-timeout=30m comment="Log Ip Yang Di drop" disabled=no
add chain=input in-interface=Wan action=drop comment="Drop Semua Akses yang tidak di ijinkan" disabled=no
semoga bermanfaat
Selengkapnya...
BLOK GAME ONLINE DI MIKROTIK
Untuk memblok user di kantor yang suka main game melulu and gak pernah ngerjain pekerjaan kantor,...:D
\ip firewall filter
add chain=forward src-address=202.93.20.0/24 protocol=tcp action=drop comment="RF indo" disabled=yes
add chain=forward src-address=202.93.20.218 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.20.0/24 protocol=tcp action=drop comment="Idol street" disabled=yes
add chain=forward src-address=202.93.20.172 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=209.190.9.202 protocol=tcp action=drop comment="RF Poa n Blitz" disabled=yes
add chain=forward src-address=75.125.122.98 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.20.215 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=209.51.218.170 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.49.0/24 protocol=tcp action=drop comment="ayodance" disabled=yes
add chain=forward src-address=122.102.49.70 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.49.71 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.49.72 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.49.73 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.49.74 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.49.75 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.49.76 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.49.77 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.49.78 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.49.79 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.49.80 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.48.0/24 protocol=tcp action=drop comment="Megaxus" disabled=yes
add chain=forward src-address=119.110.77.1 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=119.110.77.2 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=119.110.77.3 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=119.110.77.4 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=119.110.77.5 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=119.110.77.6 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=119.110.77.7 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.50.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.51.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.52.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.53.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.54.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=122.102.55.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.16.0/24 protocol=tcp action=drop comment="IP LYTO BRO" disabled=yes
add chain=forward src-address=202.93.17.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.18.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.19.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.20.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.21.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.22.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.23.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.24.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.25.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.26.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.27.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.28.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.29.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.30.0/24 protocol=tcp action=drop comment="" disabled=yes
add chain=forward src-address=202.93.31.0/24 protocol=tcp action=drop comment="" disabled=yes
semoga bermanfaat
Selengkapnya...
KONFIGURASI MIKROTIK SEJAJAR DENGAN SQUID PROXY
Berikut ini adalah konfigurasi mikrotik sejajar dengan squid proxy. Distro yang saya pake adalah slackware 13.0, squid yang saya pakai adalah squid-2.6.STABLE17, mikrotik v3.31.
Berikut adalah topologinya:
Internet - MIKROTIK - Squid Box - klien
Saya asumsikan squid proxy sudah berjalan dengan baik. bagi yang belum menginstal squidnya, silahkan anda baca artikel saya tentang instalasi squid proxy di link bawah.
Untuk konfigurasi di mesin slackware:
- http_port 3128 transparent
- isi dari /etc/rc.d/rc.local adalah
/usr/local/squid/sbin/squid -D
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 3128
Untuk konfigurasi mikrotik:
- chain=dstnat action=redirect to-ports=3228 protocol=tcp src-address=!10.10.10.2 dst-address=0.0.0.0/0 dst-port=80
- ip proxy pr
enabled: yes
src-address: 0.0.0.0
port: 3228
parent-proxy: 10.10.10.2
parent-proxy-port: 3128
cache-administrator: "mitran3t@usa.com"
max-cache-size: none
cache-on-disk: no
max-client-connections: 600
max-server-connections: 600
max-fresh-time: 3d
serialize-connections: no
always-from-cache: no
cache-hit-dscp: 4
cache-drive: system
Semoga bermanfaat
Selengkapnya...
STEP BY STEP INSTALASI SQUID PROXY DI SLACKWARE 13.0
Berikut ini adalah Step by step instalasi squid proxy di slackware 13.0 menurut pengalaman saya. Saya asumsikan mesin slackware anda sudah terkoneksi dengan internet. Baiklah kita mulai langkah - langkahnya.
Spesifikasi CPU
P4. 2.4Ghz or more
HDD 40Gb or more
Ram 512Mb or more
- login ke server dengan mengisikan username dan password
- download dulu paket squidnya, disini saya menggunakan squid-2.6.STABLE17
root@mitr@net:~# wget http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE17.tar.gz
- copykan file squid-2.6.STABLE17.tar.gz ke direktori /usr/local/
root@mitr@net:~# cp squid-2.6.STABLE17.tar.gz /usr/local/
- masuk ke direktori /usr/local/
root@mitr@net:~# cd /usr/local/
- ekstrak file squid-2.6.STABLE17.tar.gz ke direktori /usr/local
root@mitr@net:/usr/local# tar -zxvf squid-2.6.STABLE17.tar.gz
- masuk ke direktori squid-2.6.STABLE17
root@mitr@net:/usr/local# cd squid-2.6.STABLE17
- konfigurasi squid
root@mitr@net:/usr/local/squid-2.6.STABLE17# ./configure
- kompile dan instal squid
root@mitr@net:/usr/local/squid-2.6.STABLE17# make && make install
- buat user dan group squid
root@mitr@net:/usr/local/squid-2.6.STABLE17# groupadd squid
root@mitr@net:/usr/local/squid-2.6.STABLE17# useradd -c "SQUID PROXY CACHE" -d /dev/null -s /bin/false -g squid squid
- buat cache direktori dan rubah kepemilikan
root@mitr@net:/usr/local/squid-2.6.STABLE17# mkdir /var/spool/squid
root@mitr@net:/usr/local/squid-2.6.STABLE17# chown -R squid.squid /var/spool/squid
- buat file squid.pid dan rubah kepemilikan
root@mitr@net:/usr/local/squid-2.6.STABLE17# touch /var/run/squid.pid
root@mitr@net:/usr/local/squid-2.6.STABLE17# chown -R squid.squid /var/run/squid.pid
- buat direktori untuk file access.log dan rubah kepemilikan
root@mitr@net:/usr/local/squid-2.6.STABLE17# mkdir /var/log/squid
root@mitr@net:/usr/local/squid-2.6.STABLE17# touch /var/log/squid/access.log
root@mitr@net:/usr/local/squid-2.6.STABLE17# chown -R squid.squid /var/log/squid/access.log
- edit squid.conf nya
root@mitr@net:~# pico /usr/local/squid/etc/squid.conf
untuk isi dari squid.conf bisa anda sesuaikan sendiri, jika anda ingin copy contoh squid.conf saya, silahkan download disini.
- buat direktori swapnya (jalankan hanya satu kali saja)
root@mitr@net:~# /usr/local/squid/sbin/squid -z
- cek konfigurasi squid sudah benar atau belum (jika tidak ada pesan error berarti udah bener)
root@mitr@net:~# /usr/local/squid/sbin/squid -k parse
- menjalankan squid
root@mitr@net:~# /usr/local/squid/sbin/squid -D
- cek squid udah jalan atau belum
root@mitr@net:~# ps -x | grep squid
- karena pada konfigurasi squid menggunakan mode transparent pada port 8181 maka disini hanya perlu untuk membuat redirect dari port 80 (http) ke port 8181 (transparent proxy)
iptables -t nat -A PREROUTING -i eth1 -p tcp –dport 80 -j REDIRECT –to-port 8181
Demikian step by step instalasi squid proxy di slackware 13.0 saya, bagi anda mungkin ada yang kurang jelas ataupun mengalami error sana - sini, silahkan kita berbagi pengalamannya dan menemukan pemecahannya. Thanks telah berkunjung di blog saya.
semoga bermanfaat
Selengkapnya...
CONTOH FIREWALL STANDARD DI MIKROTIK
berikut ini contoh firewall standard di mikrotik yang sering saya terapkan di warnet maupun di Kantor.
/ip firewall filter
add chain=forward connection-state=established comment=”allow established connections”
add chain=forward connection-state=related comment=”allow related connections”
add chain=forward connection-state=invalid action=drop comment=”drop invalid connections”
add chain=virus protocol=tcp dst-port=135-139 action=drop comment=”Drop Blaster Worm”
add chain=virus protocol=udp dst-port=135-139 action=drop comment=”Drop Messenger Worm”
add chain=virus protocol=tcp dst-port=445 action=drop comment=”Drop Blaster Worm”
add chain=virus protocol=udp dst-port=445 action=drop comment=”Drop Blaster Worm”
add chain=virus protocol=tcp dst-port=593 action=drop comment=”________”
add chain=virus protocol=tcp dst-port=1024-1030 action=drop comment=”________”
add chain=virus protocol=tcp dst-port=1080 action=drop comment=”Drop MyDoom”
add chain=virus protocol=tcp dst-port=1214 action=drop comment=”________”
add chain=virus protocol=tcp dst-port=1363 action=drop comment=”ndm requester”
add chain=virus protocol=tcp dst-port=1364 action=drop comment=”ndm server”
add chain=virus protocol=tcp dst-port=1368 action=drop comment=”screen cast”
add chain=virus protocol=tcp dst-port=1373 action=drop comment=”hromgrafx”
add chain=virus protocol=tcp dst-port=1377 action=drop comment=”cichlid”
add chain=virus protocol=tcp dst-port=1433-1434 action=drop comment=”Worm”
add chain=virus protocol=tcp dst-port=2745 action=drop comment=”Bagle Virus”
add chain=virus protocol=tcp dst-port=2283 action=drop comment=”Drop Dumaru.Y”
add chain=virus protocol=tcp dst-port=2535 action=drop comment=”Drop Beagle”
add chain=virus protocol=tcp dst-port=2745 action=drop comment=”Drop Beagle.C-K”
add chain=virus protocol=tcp dst-port=3127-3128 action=drop comment=”Drop MyDoom”
add chain=virus protocol=tcp dst-port=3410 action=drop comment=”Drop Backdoor OptixPro”
add chain=virus protocol=tcp dst-port=4444 action=drop comment=”Worm”
add chain=virus protocol=udp dst-port=4444 action=drop comment=”Worm”
add chain=virus protocol=tcp dst-port=5554 action=drop comment=”Drop Sasser”
add chain=virus protocol=tcp dst-port=8866 action=drop comment=”Drop Beagle.B”
add chain=virus protocol=tcp dst-port=9898 action=drop comment=”Drop Dabber.A-B”
add chain=virus protocol=tcp dst-port=10000 action=drop comment=”Drop Dumaru.Y”
add chain=virus protocol=tcp dst-port=10080 action=drop comment=”Drop MyDoom.B”
add chain=virus protocol=tcp dst-port=12345 action=drop comment=”Drop NetBus”
add chain=virus protocol=tcp dst-port=17300 action=drop comment=”Drop Kuang2″
add chain=virus protocol=tcp dst-port=27374 action=drop comment=”Drop SubSeven”
add chain=virus protocol=tcp dst-port=65506 action=drop comment=”Drop PhatBot, Agobot, Gaobot”
add chain=forward action=jump jump-target=virus comment=”jump to the virus chain”
add chain=forward action=accept protocol=tcp dst-port=80 comment=”Allow HTTP”
add chain=forward action=accept protocol=tcp dst-port=25 comment=”Allow SMTP”
add chain=forward protocol=tcp comment=”allow TCP”
add chain=forward protocol=icmp comment=”allow ping”
add chain=forward protocol=udp comment=”allow udp”
add chain=forward action=drop comment=”drop everything else”
add chain=input src-address-list=”port scanners” action=drop comment=”dropping port scanners” disabled=no
Selengkapnya...
BEBERAPA FIREWALL MIKROTIK UNTUK BLOK VIRUS
Ringkasan ini tidak tersedia. Harap klik di sini untuk melihat postingan. Selengkapnya...
Kamis, 11 November 2010
ROUTING DAN LOOS PAKCET UNTUK FACEBOOK DAN GAME POINT BLANK PADA MIKROTIK
Saya kembali lagi…
Dengan hasil ngutak-ngatik Mikrotik RB450G, akhirnya dapat juga metode untuk memisahkan jalur untuk akses Poker (FB) dan games Point Blank (PB) supaya gak Cacad dan nge Lag…
Dengan Asumsi ISP ada 2 (Dalam riset ini pake FASNET dan SPEEDY)
Topologi
Internet ==> Router ==> Proxy (CentOS) ==> Hub==> Client
Secara logikal…. ip address dari dari FB dan PB di kumpulkan kedalam suatu list…
kemudian dari acuan List IP yang sudah di buat tadi digunakan untuk pengaturan Routing Jalur ISP mana yang akan digunakan untuk mengakses situs tersebut
Berikut Settingannya
/ip address
add address=192.168.5.2/24 broadcast=192.168.5.255 comment=IP-STAR disabled=\
no interface=ether2-IPSTAR network=192.168.5.0
add address=192.168.42.1/24 broadcast=192.168.42.255 comment=”Dari ^TELKOM^” \
disabled=no interface=ether3-LOCAL network=192.168.42.0
add address=192.168.41.1/24 broadcast=192.168.41.255 comment=Proxy disabled=\
no interface=ether4-AP-WIRELESS network=192.168.41.0
add address=10.8.1.38/30 broadcast=10.8.1.39 comment=”FASTNET” disabled=no \
interface=ether1-CSM network=10.8.1.36
/ip dns
set allow-remote-requests=yes cache-max-ttl=1w cache-size=3000KiB \
max-udp-packet-size=512 primary-dns=180.131.144.144 secondary-dns=\
180.131.145.145
/ip firewall filter
add action=add-dst-to-address-list address-list=Facebook \
address-list-timeout=0s chain=forward comment=\
“ADD to address-list Facebook” content=fbcdn.net disabled=no
add action=add-dst-to-address-list address-list=Facebook \
address-list-timeout=0s chain=forward comment=\
“ADD to address-list Facebook” content=facebook.com disabled=no
add action=add-dst-to-address-list address-list=Facebook \
address-list-timeout=0s chain=forward comment=\
“ADD to address-list Facebook” content=zynga.com disabled=no
add action=add-dst-to-address-list address-list=Facebook \
address-list-timeout=0s chain=forward comment=\
“ADD to address-list Facebook” content=playfish.com disabled=no
add action=add-dst-to-address-list address-list=Facebook \
address-list-timeout=0s chain=forward comment=\
“ADD to address-list Facebook” content=cloudfront.net disabled=no
add action=add-dst-to-address-list address-list=Facebook \
address-list-timeout=0s chain=forward comment=\
“ADD to address-list Facebook” content=gemscool.com disabled=no
/ip firewall mangle
add action=mark-connection chain=prerouting comment=”Pengaturan PB dan FB” \
disabled=no dst-address-list=Facebook new-connection-mark=\
mark-con-indonesia passthrough=yes
add action=mark-connection chain=prerouting comment=\
“Pengaturan Selain PB dan FB” disabled=no dst-address-list=!Facebook \
new-connection-mark=mark-con-internasional passthrough=yes
add action=mark-packet chain=prerouting comment=”Paket PB dan FB” \
connection-mark=mark-con-indonesia disabled=no new-packet-mark=indonesia \
passthrough=yes
add action=mark-routing chain=prerouting comment=\
“Routing PB dan FB ke 3G-CSM” connection-mark=mark-con-indonesia \
disabled=no dst-address-list=Facebook new-routing-mark=jalur1 \
passthrough=yes
add action=mark-packet chain=prerouting comment=”Pakcet Selain PB dan FB” \
connection-mark=mark-con-internasional disabled=no new-packet-mark=\
international passthrough=yes
add action=mark-packet chain=prerouting comment=”Mark Packet HTTP Video” \
disabled=no in-interface=ether1-CSM layer7-protocol=http-video \
new-packet-mark=http-video-up passthrough=yes
add action=mark-connection chain=forward comment=”" disabled=no \
layer7-protocol=http-video new-connection-mark=video-stream passthrough=\
yes
add action=mark-packet chain=forward comment=”" connection-mark=video-stream \
disabled=no in-interface=ether5-LAN layer7-protocol=http-video \
new-packet-mark=http-video-down passthrough=yes
add action=mark-connection chain=prerouting comment=”Pengaturan Port PB” \
disabled=no dst-address-list=Facebook dst-port=40000-40010 \
new-connection-mark=gameport passthrough=yes protocol=udp
add action=mark-connection chain=prerouting comment=”" disabled=no \
dst-address-list=Facebook dst-port=39100,39110,39220,39190,49100 \
new-connection-mark=gameport passthrough=yes protocol=tcp
add action=mark-packet chain=prerouting comment=”Pakcet Game” \
connection-mark=gameport disabled=no new-packet-mark=game passthrough=yes
add action=mark-routing chain=prerouting comment=”Routing PB Port ke 3G-CSM” \
connection-mark=gameport disabled=no dst-address-list=Facebook \
new-routing-mark=jalur1 passthrough=yes
add action=mark-connection chain=prerouting comment=\
“Pengaturan dropped Virus Conficker” disabled=no dst-port=445 \
new-connection-mark=conn-conficker passthrough=yes protocol=udp
add action=mark-connection chain=prerouting comment=445-TCP disabled=no \
dst-port=445 new-connection-mark=conn-conficker passthrough=yes protocol=\
tcp
add action=mark-connection chain=prerouting comment=135,137,138,139-TCP \
disabled=no dst-port=135,137,138,139 new-connection-mark=conn-conficker \
passthrough=yes protocol=tcp
add action=mark-connection chain=prerouting comment=135,137,138,139-UDP \
disabled=no dst-port=135,137,138,139 new-connection-mark=conn-conficker \
passthrough=yes protocol=udp
add action=mark-routing chain=prerouting comment=\
“Routing selain PB dan FB ke IPSTAR” connection-mark=\
mark-con-internasional disabled=no dst-address-list=!Facebook \
new-routing-mark=main passthrough=yes
/ip firewall nat
add action=masquerade chain=srcnat comment=”" disabled=no out-interface=\
ether1-CSM
add action=masquerade chain=srcnat comment=”" disabled=no out-interface=\
ether2-IPSTAR
/ip route
add comment=”" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=\
192.168.5.100 routing-mark=main scope=30 target-scope=10
add comment=”" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=10.8.1.37 \
routing-mark=jalur1 scope=30 target-scope=10
/queue interface
set ether1-CSM queue=ethernet-default
set ether2-IPSTAR queue=ethernet-default
set ether3-LOCAL queue=ethernet-default
set ether4-AP-WIRELESS queue=ethernet-default
set ether5-LAN queue=ethernet-default
Tidak ada keluhan dari Para Pelanggan Warnet untuk masalah Cacad dan “ngelag” lagi…. (Wakakakak)
Karena 1 jalur ISP dengan BW 1 mbps digunakan Khusus untuk mengases FB dan PB
Selengkapnya...
Selasa, 31 Agustus 2010
SETING JALUR GAMES ONLINE, DOWNLOAD, BROWSING PADA MIKROTIK
Port buat Point Blank, untuk game lain disesuaikan aja port/ip nya Pusing Kalau Game lelet karena terganggu ulah Browsing dan download
(Running PC Pentium 4 - 2,8Ghz, HDD 40GB, Memory 512MB )
(Provider TELKOM Speedy, 2MB)
1st = IP=>Firewall=>Mangle=>+
Untuk GAME Online
buat Point Blank, game lain sesuaikan aja port/ip nya
chain=GAMES
protocol=tcp 6
dst-port=39190
action=mark-connection
new-connection-mark=Game
passthrough=yes
comment=Point Blank
===================================
chain=GAMES
protocol=udp 17
dst-port=40000-40010
action=mark-connection
new-connection-mark=Game
passthrough=yes
===================================
chain=GAMES
action=mark-packet
new-packet-mark=Game_Akses
passthrough=no
connection-mark=Game
===================================
chain=prerouting
action=jump
jump-target=GAMES
===================================
Untuk Zynga POKER
chain=forward
protocol=tcp
dst-address-list=LOAD POKER
action=mark-connection
new-connection-mark=Poker_Akses
passthrough=yes
comment=POKER
===================================
chain=forward
protocol=tcp
content=statics.poker.static.zynga.com
action=mark-connection
new-connection-mark=Poker_Akses
passthrough=yes
===================================
chain=forward
connection-mark=Poker_Akses
action=mark-packet
new-packet-mark=Poker
passthrough=no
===================================
BROWSING
chain=forward
action=mark-connection
new-connection-mark=HTTP
passthrough=yes
protocol=tcp
in-interface=WAN ( Provider )
out-interface=LOKAL ( ke Client )
packet-mark=!Game_Akses
connection-mark=!GAMES
connection-bytes=0-261024
comment=BROWSING
===================================
chain=forward
action=mark-packet
new-packet-mark=http_akses
passthrough=no
protocol=tcp
connection-mark=HTTP
===================================
UPLOAD
chain=prerouting
action=mark-packet
new-packet-mark=Upload
passthrough=no
protocol=tcp
src-address=192.168.0.0/24
in-interface=LOKAL
packet-mark=!icmp_pkt
comment=UPLOAD
===================================
LIMIT DOWNLOAD
chain=forward
action=mark-connection
new-connection-mark=Download
passthrough=yes
protocol=tcp
in-interface=WAN
out-interface=LOKAL
packet-mark=!Game_Akses
connection-mark=!Poker_Akses
connection bytes=262146-4294967295
comment=LIMIT DOWNLOAD
===================================
chain=forward
action=mark-packet
new-packet-mark=Download_paket
passthrough=no
packet-mark=!Game_Akses
connection-mark=Download
===================================
QUEUE
queue type
name=Download
kind=pcq pcq-rate=256000
pcq-limit=50
pcq-classifier=dst-address
pcq-total-limit=2000
===================================
name=”Http”
kind=pcq
pcq-rate=1M
pcq-limit=50
pcq-classifier=dst-address
pcq-total-limit=2000
===================================
name=Games
kind=pcq
pcq-rate=0
pcq-limit=50
pcq-classifier=src-address,dst-address,src-port,dst-port
pcq-total-limit=2000
===================================
name=Upload
kind=pcq
pcq-rate=0
pcq-limit=50
pcq-classifier=src-address
pcq-total-limit=2000
===================================
Queue Tree
name=Browsing
parent=LOKAL
limit-at=0
priority=8
max-limit=1M
burst-limit=0
burst-threshold=0
burst-time=0s
===================================
name=Browse
parent=Browsing
packet-mark=http_Akses
limit-at=0
queue=Http
priority=8
max-limit=1M
burst-limit=0
burst-threshold=0
burst-time=0s
===================================
name=Game
parent=global-total
packet-mark=Game_Akses
limit-at=0
queue=Game
priority=1
max-limit=0
burst-limit=0
burst-threshold=0
burst-time=0s
===================================
name=Poker
parent=global-out
packet-mark=Poker
limit-at=0
queue=Game
priority=3
max-limit=0
burst-limit=0
burst-threshold=0
burst-time=0s
===================================
name=Download
parent=global-out
packet-mark=Download_Akses
limit-at=0
queue=Download
priority=8
max-limit=256k
burst-limit=0
burst-threshold=0
burst-time=0s
===================================
name=Main Upload
parent=global-in
limit-at=0
priority=8
max-limit=256k
burst-limit=0
burst-threshold=0
burst-time=0s
===================================
name=Upload
parent=Main Upload
packet-mark=Upload
limit-at=0
queue=Upload
priority=8
max-limit=0
burst-limit=0
burst-threshold=0
burst-time=0s
===================================
ip firewall address-list
add address=202.93.20.0/24 list=game
add address=202.93.20.218 list=game
add address=202.93.20.0/24 list=game
add address=202.93.20.172 list=game
add address=209.190.9.202 list=game
add address=75.125.122.98 list=game
add address=202.93.20.215 list=game
add address=209.51.218.170 list=game
add address=122.102.49.0/24 list=game
add address=122.102.49.70 list=game
add address=122.102.49.71 list=game
add address=122.102.49.72 list=game
add address=122.102.49.73 list=game
add address=122.102.49.74 list=game
add address=122.102.49.75 list=game
add address=122.102.49.76 list=game
add address=122.102.49.77 list=game
add address=122.102.49.78 list=game
add address=122.102.49.79 list=game
add address=122.102.49.80 list=game
add address=122.102.48.0/24 list=game
add address=119.110.77.1 list=game
add address=119.110.77.2 list=game
add address=119.110.77.3 list=game
add address=119.110.77.4 list=game
add address=119.110.77.5 list=game
add address=119.110.77.6 list=game
add address=119.110.77.7 list=game
add address=122.102.50.0/24 list=game
add address=122.102.51.0/24 list=game
add address=122.102.52.0/24 list=game
add address=122.102.53.0/24 list=game
add address=122.102.54.0/24 list=game
add address=122.102.55.0/24 list=game
add address=202.93.16.0/24 list=game
add address=202.93.17.0/24 list=game
add address=202.93.18.0/24 list=game
add address=202.93.19.0/24 list=game
add address=202.93.20.0/24 list=game
add address=202.93.21.0/24 list=game
add address=202.93.22.0/24 list=game
add address=202.93.23.0/24 list=game
add address=202.93.24.0/24 list=game
add address=202.93.25.0/24 list=game
add address=202.93.26.0/24 list=game
add address=202.93.27.0/24 list=game
add address=202.93.28.0/24 list=game
add address=202.93.29.0/24 list=game
add address=202.93.30.0/24 list=game
add address=202.93.31.0/24 list=game
sedikit Info
BROWSING 1Mbs bagi dengan Adil dalam satu jaringan
DOWNLOAD 256Kbps terbagi rata di Jaringan LOKAL
GAME dengan bandwith disesuaikan kebutuhan Client
POKER dengan bandwith disesuaikan kebutuhan Client
UPLOAD seadanya bandwith bagi rata sesuai kebutuhan Client
========================================================
Membagi Rata Bandwith Di Mikrotik
Misalkan kita mempunyai client sebanyak 20 unit. Link yang kita sewa sebesar 2mb/512kbps ke ISP. Kendala yang sering ditemui pada sebuah jaringan adalah tidak ada pembagian bandwidth yang adil diantara client jaringan tersebut. Jika salah satu dari client kita menggunakan program semisal download accelerator atau flashget, niscaya bandwidth yang kita miliki tersebut akan habis oleh satu client saja, sementara client lain jika ingin menggunakan bandwidth menjadi terhambat, karena link yang kita sewa telah di serobot atau do embay ama yang tadi. sebel banget deh ( gondok gitu loh )
Untuk mengatasi itu semua maka diperlukan bandwith management, pada mikrotik ada sebuah fitur PCQ (Per Connection Queue) yaitu mekanisme antrian untuk menyamakan bandwidth yang dipakai oleh multiple client.
Cara kerja PCQ jika hanya satu client yang sedang aktif menggunakan bandwidth sementar yang lain idle, maka client tersebut dapat menggunakan maximal bandwidth yang tersedia, tetapi pada saat client ke dua aktif, maka maximal bandwith yang digunakan oleh kedua client tadi menjadi masing-masing 2000kbps /2 , jika ada client lain pada saat bersamaan aktif, maka masing-masing akan mendapat jatah maximal 2000kbps /3. Sehingga akan terjadi pembagian bandwidth yang adil untuk seluruh client.
Kode:
/ip firewall mangle add chain=prerouting action=mark-packet new-packet-mark=Full \ passthrough=no
/queue type add name="PCQ_download" kind=pcq pcq-rate=2412000 pcq-classifier=dst-address
/queue type add name="PCQ_upload" kind=pcq pcq-rate=658920 pcq-classifier=src-address
/queue tree add parent=global-in queue=PCQ_download packet-mark=Full
/queue tree add parent=global-out queue=PCQ_upload packet-mark=Full
===========================================================
asumsi ke pengguna = LOKAL
dari isp = Speedy
/ip firewall mangle add chain=forward src-address=192.168.1.0/24 \
action=mark-connection new-connection-mark=users-con
/ip firewall mangle add connection-mark=users-con action=mark-packet \
new-packet-mark=users chain=forward
/queue type add name=pcq-download kind=pcq pcq-classifier=dst-address
/queue type add name=pcq-upload kind=pcq pcq-classifier=src-address
/queue tree add name=Download parent=LOKAL max-limit=2048000
/queue tree add parent=Download queue=pcq-download packet-mark=users
/queue tree add name=Upload parent=Speedy max-limit=1024000
/queue tree add parent=Upload queue=pcq-upload packet-mark=users
/queue tree add parent=LOKAL queue=pcq-download packet-mark=users
/queue tree add parent=Speedy queue=pcq-upload packet-mark=users
===========================================================
Berikut ini data port game online yang menggunakan IIX/koneksi lokal:
1. Ayo Dance : tcp 18901-18909
2. SealOnline : tcp 1818
3. PointBlank : tcp 39190, udp 40000-40010
4. Lineage2 : tcp 7777
5. GhostOnline : tcp 19101
6. RF-Elven : tcp 27780
7. Perfect world : tcp 29000
8. Rohan : tcp 22100
9. Zeus RO : tcp 5121
10. Dotta : tcp 6000-6152
11. IdolStreet : tcp 2001
12. CrazyKart : 9601-9602
13. WOW AMPM : tcp 8085
14. DriftCity : tcp 11011-11041
15. GetAmped : tcp 13413
16. Yullgang : tcp 19000
17. RAN Online : tcp 5105
18. CrossFire : tcp 10009, udp 12060-12070
19. WarRock : tcp 5340-5352
20. FastBlack : tcp 6000-6001
21. Rose Online : tcp 29200
22. Return Of Warrior : tcp 10402
23. CrazyKart 2 : tcp 9600
25. Luna Online : tcp 15002
26. Runes Of Magic : tcp 16402-16502
27. FreshRO : tcp 5126
28. Tantra Online : tcp 3010
29. Heroes Of Newearth Incatamers : tcp 11031 udp 11100-11125,11440-11460
30. Atlantica : tcp 4300 , ip 203.89.147.0/24
31. ECO Online : tcp Port 12011 , 12110
32. Cabal Indo : tcp Port 15001, 15002
33. X-SHOT : tcp 7341,7451 , udp 7808,30000
34. Return Of Warrior : tcp 10402
35. CrazyKart 2 : tcp 9600
36. Luna Online : tcp 15000-15002
37. Runes Of Magic : tcp 16402-16502
38. Fresh Ragnarok PS, www.freshro.org dst address 119.110.87.179 : 5171
39. Tantra Online : tcp 3010
40. Heroes Of Newearth Incatamers chat server -> TCP 11031 game server -> UDP 11100-11125 VOIP -> UDP 11440-11460 (by LOVIAN)
41. Atlantica : tcp 4300 , ip 203.89.147.0/24 link: http://atlantica.gemscool.com/
42. ECO Online --> Port 12011 , 12110 by RB750
43. Cabal Indo --> Port 15001, 15002 by RB750
44. X-SHOT : tcp 7341-7350,7451 , udp 7777-7977,30000
45. 3 Kingdoms : UDP 42051-42052
buat tambahan aja untuk di mangle nya
0 ;;; Download
chain=prerouting action=mark-connection
new-connection-mark=conn download passthrough=yes protocol=tcp
dst-port=80 connection-bytes=175000-4294967295
1 chain=prerouting action=mark-packet new-packet-mark=cekek bw
passthrough=no protocol=tcp connection-mark=conn download
2 ;;; Browsing
chain=prerouting action=mark-connection
new-connection-mark=conn browsing passthrough=yes protocol=tcp
dst-port=80 content=!statics.poker.static.zynga.com
connection-bytes=0-175000
3 chain=prerouting action=mark-connection new-connection-mark=conn browsing
passthrough=yes protocol=tcp dst-port=80 connection-bytes=0-175000
4 chain=prerouting action=mark-packet new-packet-mark=browsing packet
passthrough=no connection-mark=conn browsing connection-bytes=0-175000
5 ;;; Limit IDM
chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.exe
6 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.mpg
7 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.avi
8 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.mov
9 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.rar
10 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.zip
11 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.wav
12 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.mov
13 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.wma
14 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.wmv
15 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.tiff
16 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.tif
17 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.pdf
18 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.7z
19 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.3gp
20 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.mp3
21 chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.rm
22 chain=forward action=mark-packet new-packet-mark=jerat bw passthrough=no
protocol=tcp src-address-list=cekek connection-bytes=175000-4294967295
23 ;;; Point Blank
chain=prerouting action=mark-connection new-connection-mark=PB_1
passthrough=yes protocol=udp dst-address=203.89.146.0/23
dst-port=40000-40010
24 chain=prerouting action=mark-connection new-connection-mark=PB_1
passthrough=yes protocol=tcp dst-address=203.89.146.0/23 dst-port=39190
25 chain=prerouting action=mark-packet new-packet-mark=PB Oke passthrough=no
connection-mark=PB_1
26 ;;; Poker
chain=forward action=mark-connection new-connection-mark=Poker conn
passthrough=yes protocol=tcp dst-address-list=Load Game
27 chain=forward action=mark-connection new-connection-mark=Poker conn
passthrough=yes protocol=tcp content=profile.ak.fbcdn.net
28 chain=forward action=mark-connection new-connection-mark=Poker conn
passthrough=yes protocol=tcp content=statics.poker.static.zynga.com
29 chain=forward action=mark-connection new-connection-mark=Poker conn
passthrough=yes protocol=tcp content=apps.facebook.com
30 chain=forward action=mark-packet new-packet-mark=Poker passthrough=no
connection-mark=Poker conn
31 ;;; Ayo Dance
chain=prerouting action=mark-connection new-connection-mark=Ayo Dance
passthrough=yes protocol=tcp dst-address=122.102.48.0/24
dst-port=18901-18909
32 chain=prerouting action=mark-packet new-packet-mark=Ayo Dance Oke
passthrough=no connection-mark=Ayo Dance
buat tambahan aja untuk di mangle nya
Selengkapnya...