<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8518056064991556503</id><updated>2012-02-16T14:54:33.862+08:00</updated><title type='text'>MIKROTIK</title><subtitle type='html'>Saatnya Melakukan Perubahan</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://anaknagi.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://anaknagi.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Materi Jaringan</name><uri>http://www.blogger.com/profile/18432157139474714821</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_mq7TojsGMx0/THm0VD0tWoI/AAAAAAAAACw/c_xErIz7CTA/S220/IMG0270A.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>12</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8518056064991556503.post-3247732249262476030</id><published>2010-09-02T12:24:00.004+08:00</published><updated>2010-09-02T13:02:08.357+08:00</updated><title type='text'>SETTING HOTSPOT MIKROTIK TERCEPAT AND MUDAH</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Beberapa langkah untuk membangun sebuah &lt;/span&gt;&lt;b style="font-weight: bold;"&gt;system hotspot dan user manager :&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;ul style="font-weight: bold;"&gt;&lt;li&gt;INSTAL MIKROTIK&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: center;"&gt;&lt;img src="file:///C:/DOCUME%7E1/SERVER/LOCALS%7E1/Temp/moz-screenshot-1.png" alt="" /&gt;&lt;img src="file:///C:/DOCUME%7E1/SERVER/LOCALS%7E1/Temp/moz-screenshot-2.png" alt="" /&gt;&lt;img src="file:///C:/DOCUME%7E1/SERVER/LOCALS%7E1/Temp/moz-screenshot-3.png" alt="" /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mq7TojsGMx0/TH8vBFeGQbI/AAAAAAAAADY/llUXi65QxHc/s1600/mikro1.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 187px;" src="http://4.bp.blogspot.com/_mq7TojsGMx0/TH8vBFeGQbI/AAAAAAAAADY/llUXi65QxHc/s320/mikro1.jpg" alt="" id="BLOGGER_PHOTO_ID_5512176164619567538" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;img src="file:///C:/DOCUME%7E1/SERVER/LOCALS%7E1/Temp/moz-screenshot.png" alt="" /&gt;&lt;ul&gt;&lt;li style="font-weight: bold;"&gt;NAMAKAN INTERACE&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;PEMBERIAN IP&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;SETTING IP GATEWAY&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;SETTING DNS&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;SETTING NAT&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;BUAT IP POOL&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;SETTING RADIUS SERVER&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;SETTING HOTSPOT&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;SETTING USERMANAGER&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518056064991556503-3247732249262476030?l=anaknagi.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anaknagi.blogspot.com/feeds/3247732249262476030/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518056064991556503&amp;postID=3247732249262476030&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/3247732249262476030'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/3247732249262476030'/><link rel='alternate' type='text/html' href='http://anaknagi.blogspot.com/2010/09/setting-hotspot-mikrotik-tercepat-and.html' title='SETTING HOTSPOT MIKROTIK TERCEPAT AND MUDAH'/><author><name>Materi Jaringan</name><uri>http://www.blogger.com/profile/18432157139474714821</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_mq7TojsGMx0/THm0VD0tWoI/AAAAAAAAACw/c_xErIz7CTA/S220/IMG0270A.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_mq7TojsGMx0/TH8vBFeGQbI/AAAAAAAAADY/llUXi65QxHc/s72-c/mikro1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518056064991556503.post-2707109521016580854</id><published>2010-08-30T16:42:00.003+08:00</published><updated>2010-08-30T18:28:46.288+08:00</updated><title type='text'>Cara Memisahkan Browse, Download, Upload, Dan Game</title><content type='html'>&lt;span style="font-family: arial; font-weight: bold; color: rgb(255, 0, 0);"&gt;Settingan ini Berjalan Pada Mikrotik &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;RB750 OS ver.4.5 Dan percobaan Ini dilakukan pada mikrotik PC dengan Mikrotik Versi V2.9.27 &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Siapkan Perangkat PC dan Instal Mikrotik V2.9.27&lt;/span&gt;&lt;br /&gt;&lt;ul style="font-weight: bold;"&gt;&lt;li style="color: rgb(0, 153, 0);"&gt;Lan Card 1 menuju ISP dalam settingan ini menggunakan Speedy "Jaringan Speedy"&lt;/li&gt;&lt;li&gt;Lan Card 2 Menuju Jaringan Local dengan nama "Jaringan Local"&lt;/li&gt;&lt;li style="color: rgb(153, 102, 51);"&gt;Setting IP untuk Lan 1 (Baca Tutorial Instal Mikrotik)&lt;/li&gt;&lt;li&gt;setting IP untuk Lan 2 (disini IP : &lt;span style="color: rgb(255, 0, 0);"&gt;192.168.0.0/24&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Settingan Yang akan Dilakukan :&lt;/span&gt;&lt;br /&gt;&lt;ul style="font-weight: bold; color: rgb(0, 153, 0);"&gt;&lt;li&gt;GAME Poin Blank&lt;br /&gt;&lt;/li&gt;&lt;li style="color: rgb(255, 102, 0);"&gt;Game Poker&lt;/li&gt;&lt;li&gt;BROWSING&lt;/li&gt;&lt;li style="color: rgb(204, 51, 204);"&gt;UPLOAD&lt;/li&gt;&lt;li&gt;LIMIT DOWNLOAD&lt;/li&gt;&lt;li style="color: rgb(255, 153, 255);"&gt;QUEUE&lt;/li&gt;&lt;/ul&gt;Tahapan atau teknik setting seperti berikut :&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Settingan Untuk GAME Poin Blank&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;span style="color: rgb(51, 153, 153);"&gt;contoh buat Point Blank&lt;/span&gt;, &lt;span style="color: rgb(255, 0, 0);"&gt;game lain sesuaikan aja port/ip nya&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Untuk Perintah Dibawah buatkan Pada bagian IP-Firewall-Mangle&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;chain=game action=mark-connection new-connection-mark=Game  passthrough=yes protocol=tcp dst-address=203.89.146.0/23 dst-port=39190  comment=”Point Blank”&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(153, 153, 0);"&gt;chain=game action=mark-connection new-connection-mark=Game  passthrough=yes protocol=udp dst-address=203.89.146.0/23  dst-port=40000-40010&lt;/span&gt;&lt;br /&gt; -------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 51, 0);"&gt;chain=game action=mark-packet new-packet-mark=Game_pkt passthrough=no connection-mark=Game&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(153, 51, 0);"&gt;chain=prerouting action=jump jump-target=game&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Settingan Untuk GAME Poker&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Untuk Perintah Dibawah buatkan Pada bagian IP-Firewall-Mangle&lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="color: rgb(255, 102, 0);"&gt;chain=forward action=mark-connection new-connection-mark=Poker_con  passthrough=yes protocol=tcp dst-address-list=LOAD POKER comment=”POKER”&lt;/span&gt;&lt;/span&gt;&lt;br /&gt; &lt;span style="font-weight: bold;"&gt;-------------------------------------------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; &lt;span style="color: rgb(0, 153, 0);"&gt;chain=forward action=mark-connection new-connection-mark=Poker_con  passthrough=yes protocol=tcp content=statics.poker.static.zynga.com&lt;/span&gt;&lt;/span&gt;&lt;br /&gt; &lt;span style="font-weight: bold;"&gt;-------------------------------------------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(204, 153, 51);"&gt; chain=forward action=mark-packet new-packet-mark=Poker passthrough=no connection-mark=Poker_con&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;ul style="font-weight: bold;"&gt;&lt;li&gt;BROWSING&lt;/li&gt;&lt;/ul&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;chain=forward action=mark-connection new-connection-mark=http  passthrough=yes protocol=tcp in-interface=WAN out-interface=Lan  packet-mark=!Game_pkt connection-mark=!Game connection-bytes=0-262146  comment=”BROWSE”&lt;/span&gt;&lt;br /&gt; &lt;span style="font-weight: bold;"&gt;-------------------------------------------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; &lt;span style="color: rgb(0, 153, 0);"&gt;chain=forward action=mark-packet new-packet-mark=http_pkt passthrough=no protocol=tcp connection-mark=http&lt;/span&gt;&lt;/span&gt;&lt;br /&gt; &lt;span style="font-weight: bold;"&gt;-------------------------------------------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; &lt;span style="color: rgb(51, 102, 255);"&gt;chain=forward action=mark-packet new-packet-mark=http_pkt passthrough=no protocol=tcp connection-mark=http&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;ul style="font-weight: bold;"&gt;&lt;li&gt;UPLOAD&lt;/li&gt;&lt;/ul&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;chain=prerouting action=mark-packet new-packet-mark=Upload  passthrough=no protocol=tcp src-address=192.168.0.0/24 in-interface=Lan  packet-mark=!icmp_pkt comment=”UPLOAD”&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;ul style="font-weight: bold;"&gt;&lt;li&gt;LIMIT DOWNLOAD&lt;/li&gt;&lt;/ul&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt;chain=forward action=mark-connection new-connection-mark=Download  passthrough=yes protocol=tcp in-interface=WAN out-interface=Lan  packet-mark=!Game_pkt connection-mark=!Poker_con connection  bytes=262146-4294967295 comment=”LIMIT DOWNLOAD”&lt;/span&gt;&lt;br /&gt; -------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; &lt;span style="color: rgb(204, 0, 0);"&gt;chain=forward action=mark-packet new-packet-mark=Download_pkt passthrough=no packet-mark=!Game_pk&gt; connection-mark=Download&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;ul style="font-weight: bold;"&gt;&lt;li&gt;QUEUE&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Queue Type&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;name=”Download” kind=pcq pcq-rate=256000 pcq-limit=50 pcq-classifier=dst-address pcq-total-limit=2000&lt;/span&gt;&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 255);"&gt; name=”Http” kind=pcq pcq-rate=1M pcq-limit=50 pcq-classifier=dst-address pcq-total-limit=2000&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 255);"&gt; name=”Game” kind=pcq pcq-rate=0 pcq-limit=50 pcq-classifier=src-address,dst-address,src-port,dst-port pcq-total-limit=2000&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 255);"&gt; name=”Upload” kind=pcq pcq-rate=0 pcq-limit=50 pcq-classifier=src-address pcq-total-limit=2000&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Queue Tree&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(204, 51, 204);"&gt;name=”Main Browse” parent=Lan limit-at=0 priority=8 max-limit=1M burst-limit=0 burst-threshold=0 burst-time=0s&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(204, 51, 204);"&gt; name=”Browse” parent=Main Browse packet-mark=http_pkt limit-at=0  queue=Http priority=8 max-limit=1M burst-limit=0 burst-threshold=0  burst-time=0s&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(204, 51, 204);"&gt; name=”Game” parent=global-total packet-mark=Game_pkt limit-at=0  queue=Game priority=1 max-limit=0 burst-limit=0 burst-threshold=0  burst-time=0s&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(204, 51, 204);"&gt; name=”Poker” parent=global-out packet-mark=Poker limit-at=0 queue=Game  priority=3 max-limit=0 burst-limit=0 burst-threshold=0 burst-time=0s&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(204, 51, 204);"&gt; name=”Download” parent=global-out packet-mark=Download_pkt limit-at=0  queue=Download priority=8 max-limit=256k burst-limit=0 burst-threshold=0  burst-time=0s&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(204, 51, 204);"&gt; name=”Main Upload” parent=global-in limit-at=0 priority=8 max-limit=256k burst-limit=0 burst-threshold=0 burst-time=0s&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(204, 51, 204);"&gt; name=”Upload” parent=Main Upload packet-mark=Upload limit-at=0  queue=Upload priority=8 max-limit=0 burst-limit=0 burst-threshold=0  burst-time=0s&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518056064991556503-2707109521016580854?l=anaknagi.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anaknagi.blogspot.com/feeds/2707109521016580854/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518056064991556503&amp;postID=2707109521016580854&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/2707109521016580854'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/2707109521016580854'/><link rel='alternate' type='text/html' href='http://anaknagi.blogspot.com/2010/08/cara-memisahkan-browse-download-upload.html' title='Cara Memisahkan Browse, Download, Upload, Dan Game'/><author><name>Materi Jaringan</name><uri>http://www.blogger.com/profile/18432157139474714821</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_mq7TojsGMx0/THm0VD0tWoI/AAAAAAAAACw/c_xErIz7CTA/S220/IMG0270A.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518056064991556503.post-6614439954313208951</id><published>2010-08-29T09:40:00.003+08:00</published><updated>2010-08-29T09:53:08.600+08:00</updated><title type='text'>Setting Mikrotik Dengan Line Speedy (Versi Mr. A)</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;Skema Jaringan dan IP Address yang akan dibuat:&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; Oleh Mr. A :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold; color: rgb(0, 153, 0);"&gt;SPEEDY (Internet)  –&gt; Modem ADSL (IP modem=192.168.1.1) –&gt; (IP ether1=192.168.1.2)  Mikrotik Routeros (IP ether2=10.0.0.30) –&gt; LAN (IP LAN=10.0.0.1 s/d  10.0.0.29)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;IP Address LAN&lt;/span&gt;, kita gunakan network &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;10.0.0.0/27&lt;/span&gt; &lt;span style="font-style: italic; color: rgb(51, 51, 255);"&gt;(transfer data =27 bit untuk maks 30 IP Address/komputer).&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Untuk  &lt;span style="font-weight: bold;"&gt;Mikrotik RouterOS&lt;/span&gt;, kita perlu &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;dua (2) ethernet card&lt;/span&gt;. Satu &lt;span style="font-weight: bold; color: rgb(51, 51, 255);"&gt;(ether1 –  192.168.1.2/24)&lt;/span&gt; untuk &lt;span style="font-weight: bold; color: rgb(51, 51, 255);"&gt;sambungan ke Modem ADSL&lt;/span&gt; dan satu lagi (&lt;span style="font-weight: bold; color: rgb(153, 153, 0);"&gt;ether2 –  10.0.0.30/27) untuk sambungan ke LAN/switch.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold; color: rgb(153, 51, 153);"&gt;Untuk Modem ADSL, IP kita set 192.168.1.1/24.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;&lt;span style="font-weight: bold;"&gt;Pastikan Anda sebelum mengetikkan apapun, telah berada pada root menu dengan mengetikkan &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;“/”&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;1. Set IP untuk masing² ethernet card:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;ip address add address=192.168.1.2/24 interface=ether1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;ip address add address=10.0.0.30/27 interface=ether2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Untuk menampilkan hasil perintah di atas ketikkan perintah berikut:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;ip address print&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Kemudian  lakukan testing dengan &lt;span style="font-weight: bold; font-style: italic;"&gt;mencoba nge-ping ke gateway &lt;/span&gt;atau ke komputer yg  ada pada LAN. Jika hasilnya sukses, maka konfigurasi IP Anda sudah benar&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-style: italic;"&gt;ping 192.168.1.1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-style: italic;"&gt;ping 10.0.0.30&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;2. Menambahkan Routing&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold; color: rgb(255, 0, 0);"&gt;ip route add gateway=192.168.1.1 (IP Gateway adalag IP modem)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;3. Setting DNS&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold; color: rgb(153, 153, 0);"&gt;ip dns set primary-dns=203.130.193.74 allow-remote-requests=yes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold; color: rgb(153, 153, 0);"&gt;ip dns set secondary-dns=202.134.0.155 allow-remote-requests=yes&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-style: italic; color: rgb(255, 0, 0);"&gt;Karena  koneksi menggunakan Speedy dari Telkom, maka DNS yg kita gunakan DNS  Telkom. Silahkan sesuaikan dengan DNS Telkom masing tempat  Anda berada.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Setelah itu coba Anda lakukan &lt;span style="font-weight: bold; color: rgb(255, 153, 0);"&gt;ping ke yahoo.com&lt;/span&gt; misalnya:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;ping yahoo.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Jika hasilnya sukses, maka settingan DNS sudah benar&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;4. Source NAT (Network Address Translation) / Masquerading.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Agar semua komputer yg ada di LAN bisa terhubung ke internet juga, maka Anda perlu menambahkan &lt;span style="font-weight: bold; color: rgb(0, 153, 0);"&gt;NAT (Masquerade)&lt;/span&gt; pada Mikrotik.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold; color: rgb(255, 0, 0);"&gt;ip firewall nat add chain=srcnat action=masquerade out-interface=ether1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Sekarang coba lakukan ping ke yahoo.com dari komputer yang ada di LAN&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;ping yahoo.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Jika hasilnya sukses, maka setting masquerade sudah benar&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;5. DHCP (DynamicHost Configuration Protocol)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Supaya  praktis, kita gunakan saja DHCP Server. Agar setiap ada klien yang  ingin konek, dia ga perlu setting IP secara manual. Tinggal obtain aja  dari DHCP Server, beres dah. Untungnya Mikrotik ini juga ada fitur DHCP  Servernya. Jadi ya ga ada masalah… OK! Langkah2nya sbb:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;Buat IP Address Pool&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold; color: rgb(255, 0, 0);"&gt;ip pool add name=dhcp-pool ranges=10.0.0.1-10.0.0.29&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;Menambahkan DHCP Network&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left; font-weight: bold; color: rgb(255, 0, 0);"&gt;&lt;span style="font-family: arial;"&gt;ip dhcp-server network add address=10.0.0.0/27 gateway=10.0.0.30 dns-server=203.130.193.74,202.134.0.155&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Menambahkan Server DHCP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;ip dhcp-server add name=DHCP_LAN disabled=no interface=ether2 address-pool=dhcp-pool&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Sekarang  coba lakukan testing dari komputer klien, untuk me-request IP Address  dari Server DHCP. Jika sukses, maka sekali lagi, settingannya sudah OK.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;6. Bandwidth Control&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold; font-style: italic; color: rgb(255, 102, 102);"&gt;Agar  semua komputer klien pada LAN tidak saling berebut bandwidth, maka  perlu dilakukan yg namanya bandwidth management atau bandwidth control&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Model yg saya gunakan adalah &lt;span style="font-weight: bold;"&gt;queue trees.&lt;/span&gt; Untuk lebih jelas apa itu, silahkan merujuk ke situsnya Mikrotik. (&lt;/span&gt;&lt;a style="font-family: arial;" href="http://mikrotik.co.id/" target="_blank"&gt;http://mikrotik.co.id&lt;/a&gt;&lt;span style="font-family: arial;"&gt;)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Kondisinya seperti ini:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Koneksi  Speedy sekarang ini katanya speednya sampai 1Mbps/128kbps  (Download/Upload). Untuk itu setingan bandwidth management nya bisa kita  set sbb berikut:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Tandai semua paket yg asalnya dari LAN&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold; color: rgb(255, 0, 0);"&gt;ip firewall mangle add src-address=10.0.0.0/27 action=mark-connection&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold; color: rgb(255, 0, 0);"&gt;ip  firewall mangle add connection-mark=Clients-con action=mark-packet  new-packet-mark=Clients chain=prerouting new-connection-mark=Clients-con  chain=prerouting&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;Menambahkan rule yg akan membatasi kecepatan download dan upload&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold; color: rgb(255, 0, 0);"&gt;queue tree add name=Clients-Download parent=ether2 packet-mark=Clients limit-at=0 max-limit=0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold; color: rgb(255, 0, 0);"&gt;queue tree add name=Clients-Upload parent=ether1 packet-mark=Clients limit-at=0 max-limit=0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Nilai  download dan upload  kita set “0″ (nol) dengan tujuan agar bandwidth  yang kita dapatkan tidak terbatasi. Karena pada saat-saat tertentu speed  speedy bisa mencapai 1,5Mbps. Jadi kalo kita set maks=1mbps maka speed  yang kita dapatkan hanya mentok 1mbps saja. rugikan :-D&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Sekarang  coba lakukan test download dari beberapa klien, mestinya sekarang tiap2  klien akan berbagi bandwidthnya. Jika jumlah klien yg online tidak  sampai 10, maka sisa bandwidth yang nganggur itu akan dibagikan kepada  klien yg online.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;7. Graphing&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Mikrotik ini juga dilengkapi  dengan fungsi monitoring traffic layaknya MRTG biasa. Jadi kita bisa  melihat berapa banyak paket yg dilewatkan pada PC Mikrotik kita.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;tool graphing set store-every=5min&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Berikutnya  yang akan kita monitor adalah paket² yg lewat semua interface yg ada di  PC Mikrotik kita.&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;tool graphing interface add-interface=all  store-on-disk=yes&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Sekarang coba arahkan browser anda ke IP Router Mikrotik (IP ether2 yang ke LAN)&lt;/span&gt;&lt;br /&gt;&lt;a style="font-family: arial;" href="http://10.0.0.30/graphs/" target="_blank"&gt;http://10.0.0.30/graphs/&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Nanti  akan ada pilihan interface apa aja yg ada di router Anda. Coba klik  salah satu, maka Anda akan bisa melihat grafik dari paket2 yg lewat pada  interface tersebut.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Sampai disini kita telah selesai melakukan setting mikrotik dasar untuk koneksi speedy&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518056064991556503-6614439954313208951?l=anaknagi.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anaknagi.blogspot.com/feeds/6614439954313208951/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518056064991556503&amp;postID=6614439954313208951&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/6614439954313208951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/6614439954313208951'/><link rel='alternate' type='text/html' href='http://anaknagi.blogspot.com/2010/08/setting-mikrotik-dengan-line-speedy.html' title='Setting Mikrotik Dengan Line Speedy (Versi Mr. A)'/><author><name>Materi Jaringan</name><uri>http://www.blogger.com/profile/18432157139474714821</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_mq7TojsGMx0/THm0VD0tWoI/AAAAAAAAACw/c_xErIz7CTA/S220/IMG0270A.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518056064991556503.post-1895603594157043710</id><published>2010-08-29T09:17:00.005+08:00</published><updated>2010-08-29T09:38:12.799+08:00</updated><title type='text'>Setting Firewall Filter Mikrotik</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link style="font-family: arial;" rel="File-List" href="file:///C:%5CDOCUME%7E1%5CSERVER%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link style="font-family: arial;" rel="themeData" href="file:///C:%5CDOCUME%7E1%5CSERVER%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link style="font-family: arial;" rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CSERVER%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0cm; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:"Times New Roman";} span.fullpost 	{mso-style-name:fullpost; 	mso-style-unhide:no;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt;} @page Section1 	{size:612.0pt 792.0pt; 	margin:72.0pt 72.0pt 72.0pt 72.0pt; 	mso-header-margin:36.0pt; 	mso-footer-margin:36.0pt; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0cm 5.4pt 0cm 5.4pt; 	mso-para-margin:0cm; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link style="font-family: arial;" rel="File-List" href="file:///C:%5CDOCUME%7E1%5CSERVER%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link style="font-family: arial;" rel="themeData" href="file:///C:%5CDOCUME%7E1%5CSERVER%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link style="font-family: arial;" rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CSERVER%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0cm; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:"Times New Roman";} span.fullpost 	{mso-style-name:fullpost; 	mso-style-unhide:no;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt;} @page Section1 	{size:612.0pt 792.0pt; 	margin:72.0pt 72.0pt 72.0pt 72.0pt; 	mso-header-margin:36.0pt; 	mso-footer-margin:36.0pt; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0cm 5.4pt 0cm 5.4pt; 	mso-para-margin:0cm; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);font-family:arial;font-size:100%;" class="fullpost"  &gt;&lt;span style=""&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Langkah pertama yaitu ketikan atau copykan perintah dibawah ini dan letakan paa bagian&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;terminal mikrotik.&lt;/span&gt;&lt;br /&gt;----------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;/ ip firewall filter&lt;br /&gt;----------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Setelah melakukan langkah diatas,lakukan langkahberikutnya yaitu copykan perintah dibawah ini dan langsung masukan dalam terminal mikrotik.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link style="font-family: arial;" rel="File-List" href="file:///C:%5CDOCUME%7E1%5CSERVER%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link style="font-family: arial;" rel="themeData" href="file:///C:%5CDOCUME%7E1%5CSERVER%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link style="font-family: arial;" rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CSERVER%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0cm; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:"Times New Roman";} span.fullpost 	{mso-style-name:fullpost; 	mso-style-unhide:no;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt;} @page Section1 	{size:612.0pt 792.0pt; 	margin:72.0pt 72.0pt 72.0pt 72.0pt; 	mso-header-margin:36.0pt; 	mso-footer-margin:36.0pt; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0cm 5.4pt 0cm 5.4pt; 	mso-para-margin:0cm; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;&lt;span style="font-weight: bold; color: rgb(102, 51, 255);font-family:arial;font-size:100%;" class="fullpost"  &gt;&lt;span style=""&gt;add chain=input connection-state=invalid action=drop comment="Drop Invalid &lt;/span&gt;&lt;/span&gt;&lt;span style=";font-family:&amp;quot;;font-size:100%;"  &gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 51, 255);" class="fullpost"&gt;connections" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(255, 0, 0);" class="fullpost"&gt;add chain=input src-address=!192.168.0.0/27 protocol=tcp src-port=1024-65535 &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);" class="fullpost"&gt;dst-port=8080 action=drop comment="Block to Proxy" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 51, 255);" class="fullpost"&gt;add chain=input protocol=udp dst-port=12667 action=drop comment="Trinoo" &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 255);" class="fullpost"&gt;disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(0, 153, 0);" class="fullpost"&gt;add chain=input protocol=udp dst-port=27665 action=drop comment="Trinoo" &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);" class="fullpost"&gt;disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 51, 255);" class="fullpost"&gt;add chain=input protocol=udp dst-port=31335 action=drop comment="Trinoo" &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 255);" class="fullpost"&gt;disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(102, 102, 0);" class="fullpost"&gt;add chain=input protocol=udp dst-port=27444 action=drop comment="Trinoo" &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 102, 0);" class="fullpost"&gt;disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(204, 102, 204);" class="fullpost"&gt;add chain=input protocol=udp dst-port=34555 action=drop comment="Trinoo" &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 102, 204);" class="fullpost"&gt;disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(153, 153, 0);" class="fullpost"&gt;add chain=input protocol=udp dst-port=35555 action=drop comment="Trinoo" &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(153, 153, 0);" class="fullpost"&gt;disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(255, 102, 102);" class="fullpost"&gt;add chain=input protocol=tcp dst-port=27444 action=drop comment="Trinoo" &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 102, 102);" class="fullpost"&gt;disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(102, 255, 255);" class="fullpost"&gt;add chain=input protocol=tcp dst-port=27665 action=drop comment="Trinoo" &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 255, 255);" class="fullpost"&gt;disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(51, 204, 0);" class="fullpost"&gt;add chain=input protocol=tcp dst-port=31335 action=drop comment="Trinoo" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 153, 102);" class="fullpost"&gt;add chain=input protocol=tcp dst-port=31846 action=drop comment="Trinoo" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(51, 0, 51);" class="fullpost"&gt;add chain=input protocol=tcp dst-port=34555 action=drop comment="Trinoo" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="color: rgb(51, 0, 51);"&gt;disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(153, 153, 255);" class="fullpost"&gt;add chain=input protocol=tcp dst-port=35555 action=drop comment="Trinoo" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(153, 153, 255);"&gt;disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(255, 0, 0);" class="fullpost"&gt;add chain=input connection-state=established action=accept comment="Allow &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Established connections" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(255, 204, 0);"&gt;add chain=input protocol=udp action=accept comment="Allow UDP" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=input protocol=icmp action=accept comment="Allow ICMP" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 102, 0);" class="fullpost"&gt;add chain=input src-address=192.168.0.0/27 action=accept comment="Allow access &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt;to router from known network" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=input action=drop comment="Drop anything else" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(0, 102, 0);" class="fullpost"&gt;add chain=forward protocol=tcp connection-state=invalid action=drop&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;comment="drop invalid connections" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=forward connection-state=established action=accept comment="allow &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;already established connections" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 51, 255);" class="fullpost"&gt;add chain=forward connection-state=related action=accept comment="allow &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 255);"&gt;related connections" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=forward src-address=0.0.0.0/8 action=drop comment="" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt;add chain=forward dst-address=0.0.0.0/8 action=drop comment="" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=forward src-address=127.0.0.0/8 action=drop comment="" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;&lt;span style="color: rgb(51, 102, 255); font-weight: bold;"&gt;add chain=forward dst-address=127.0.0.0/8 action=drop comment="" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;&lt;span style="color: rgb(153, 153, 0);"&gt;add chain=forward src-address=224.0.0.0/3 action=drop comment="" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;&lt;span style="color: rgb(255, 102, 0); font-weight: bold;"&gt;add chain=forward dst-address=224.0.0.0/3 action=drop comment="" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=forward protocol=tcp action=jump jump-target=tcp comment="" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0); font-weight: bold;" class="fullpost"&gt;add chain=forward protocol=udp action=jump jump-target=udp comment="" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=forward protocol=icmp action=jump jump-target=icmp comment="" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 153, 255);" class="fullpost"&gt;add chain=tcp protocol=tcp dst-port=69 action=drop comment="deny TFTP" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 255);"&gt;disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=tcp protocol=tcp dst-port=111 action=drop comment="deny RPC &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;portmapper" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 102, 255);" class="fullpost"&gt;add chain=tcp protocol=tcp dst-port=135 action=drop comment="deny RPC &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(51, 102, 255);"&gt;portmapper" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(0, 153, 0);" class="fullpost"&gt;add chain=tcp protocol=tcp dst-port=137-139 action=drop comment="deny NBT" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=tcp protocol=tcp dst-port=445 action=drop comment="deny cifs" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 0, 0);" class="fullpost"&gt;add chain=tcp protocol=tcp dst-port=2049 action=drop comment="deny NFS" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=tcp protocol=tcp dst-port=12345-12346 action=drop comment="deny &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;NetBus" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(51, 0, 153); font-weight: bold;" class="fullpost"&gt;add chain=tcp protocol=tcp dst-port=20034 action=drop comment="deny NetBus" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="color: rgb(51, 0, 153); font-weight: bold;"&gt;disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=tcp protocol=tcp dst-port=3133 action=drop comment="deny &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;BackOriffice" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(102, 0, 204); font-weight: bold;" class="fullpost"&gt;add chain=tcp protocol=tcp dst-port=67-68 action=drop comment="deny DHCP" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="color: rgb(102, 0, 204); font-weight: bold;"&gt;disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=udp protocol=udp dst-port=69 action=drop comment="deny TFTP" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 204, 0);" class="fullpost"&gt;add chain=udp protocol=udp dst-port=111 action=drop comment="deny PRC &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(51, 204, 0);"&gt;portmapper" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=udp protocol=udp dst-port=135 action=drop comment="deny PRC &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;portmapper" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 51, 255);" class="fullpost"&gt;add chain=udp protocol=udp dst-port=137-139 action=drop comment="deny NBT" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 255);"&gt;disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=udp protocol=udp dst-port=2049 action=drop comment="deny NFS" &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(204, 102, 0);" class="fullpost"&gt;add chain=udp protocol=udp dst-port=3133 action=drop comment="deny &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(204, 102, 0);"&gt;BackOriffice" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=input protocol=tcp psd=21,3s,3,1 action=add-src-to-address-list &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;address-list="port scanners" address-list-timeout=2w comment="Port &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;scanners to list " disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 102, 255);" class="fullpost"&gt;add chain=input protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(51, 102, 255);"&gt;action=add-src-to-address-list address-list="port scanners" &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;address-list-timeout=2w comment="NMAP FIN Stealth scan" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(51, 204, 0);"&gt;add chain=input protocol=tcp tcp-flags=fin,syn action=add-src-to-address-list &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;address-list="port scanners" address-list-timeout=2w comment="SYN/FIN &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;scan" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 204, 0);" class="fullpost"&gt;add chain=input protocol=tcp tcp-flags=syn,rst action=add-src-to-address-list &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(51, 204, 0);" class="fullpost"&gt;address-list="port scanners" address-list-timeout=2w comment="SYN/RST &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(51, 204, 0);"&gt;scan" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;&lt;span style="color: rgb(204, 153, 51);"&gt;add chain=input protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(255, 204, 102);"&gt;action=add-src-to-address-list address-list="port scanners" &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;address-list-timeout=2w comment="FIN/PSH/URG scan" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(204, 102, 204);" class="fullpost"&gt;add chain=input protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(204, 102, 204);" class="fullpost"&gt;action=add-src-to-address-list address-list="port scanners"&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(204, 102, 204);"&gt;address-list-timeout=2w comment="ALL/ALL scan" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(0, 102, 0);" class="fullpost"&gt;add chain=input protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 102, 0);" class="fullpost"&gt;action=add-src-to-address-list address-list="port scanners"&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;&lt;span style="color: rgb(0, 102, 0);"&gt;address-list-timeout=2w comment="NMAP NULL scan" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 102, 255);" class="fullpost"&gt;add chain=input src-address-list="port scanners" action=drop comment="dropping &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(51, 102, 255);"&gt;port scanners" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(255, 0, 0);" class="fullpost"&gt;add chain=icmp protocol=icmp icmp-options=0:0 action=accept comment="drop &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;invalid connections" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 51, 153);" class="fullpost"&gt;add chain=icmp protocol=icmp icmp-options=3:0 action=accept comment="allow &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 153);"&gt;established connections" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=icmp protocol=icmp icmp-options=3:1 action=accept comment="allow &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;already established connections" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(51, 51, 255); font-weight: bold;" class="fullpost"&gt;add chain=icmp protocol=icmp icmp-options=4:0 action=accept comment="allow &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="color: rgb(51, 51, 255); font-weight: bold;"&gt;source quench" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(153, 102, 51);" class="fullpost"&gt;add chain=icmp protocol=icmp icmp-options=8:0 action=accept comment="allow &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="color: rgb(153, 102, 51);"&gt;echo request" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(0, 153, 0);" class="fullpost"&gt;add chain=icmp protocol=icmp icmp-options=11:0 action=accept comment="allow &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(0, 153, 0);"&gt;time exceed" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(255, 204, 51);" class="fullpost"&gt;add chain=icmp protocol=icmp icmp-options=12:0 action=accept comment="allow &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="color: rgb(255, 204, 51);"&gt;parameter bad" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(153, 153, 0);"&gt;add chain=icmp action=drop comment="deny all other types" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(102, 51, 102);" class="fullpost"&gt;add chain=tcp protocol=tcp dst-port=25 action=reject &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="color: rgb(102, 51, 102);"&gt;reject-with=icmp-network-unreachable comment="Smtp" disabled=no&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(255, 153, 0); font-weight: bold;" class="fullpost"&gt;add chain=tcp protocol=udp dst-port=25 action=reject &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;reject-with=icmp-network-unreachable comment="Smtp" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;add chain=tcp protocol=tcp dst-port=110 action=reject &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;reject-with=icmp-network-unreachable comment="Smtp" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 0, 0);" class="fullpost"&gt;add chain=tcp protocol=udp dst-port=110 action=reject&lt;br /&gt;&lt;/span&gt; &lt;span class="fullpost"&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;reject-with=icmp-network-unreachable comment="Smtp" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="color: rgb(51, 204, 0);" class="fullpost"&gt;add chain=tcp protocol=udp dst-port=110 action=reject &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);" class="fullpost"&gt;reject-with=icmp-network-unreachable comment="Smtp" disabled=no&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;/span&gt; &lt;!--[if !supportLineBreakNewLine]--&gt;&lt;br /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518056064991556503-1895603594157043710?l=anaknagi.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anaknagi.blogspot.com/feeds/1895603594157043710/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518056064991556503&amp;postID=1895603594157043710&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/1895603594157043710'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/1895603594157043710'/><link rel='alternate' type='text/html' href='http://anaknagi.blogspot.com/2010/08/setting-firewall-filter-mikrotik.html' title='Setting Firewall Filter Mikrotik'/><author><name>Materi Jaringan</name><uri>http://www.blogger.com/profile/18432157139474714821</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_mq7TojsGMx0/THm0VD0tWoI/AAAAAAAAACw/c_xErIz7CTA/S220/IMG0270A.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518056064991556503.post-3225973840718012430</id><published>2010-08-29T02:06:00.003+08:00</published><updated>2010-08-29T02:14:59.983+08:00</updated><title type='text'>Fitur Mikrotik RouterOS</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;strong&gt;Penanganan Protokol TCP/IP:&lt;/strong&gt;  &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li style="color: rgb(204, 0, 0); font-weight: bold;"&gt;Firewall and NAT - stateful packet filtering; Peer-to-Peer protocol filtering;  source and destination NAT; classification by source MAC, IP addresses, ports,  protocols, protocol options, interfaces, internal marks, content, matching frequency&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="color: rgb(0, 153, 0); font-weight: bold;"&gt;Routing - Static routing; Equal cost multi-path routing; Policy based routing  (classification by source and destination addresses and/or by firewall mark);  RIP v1 / v2, OSPF v2, BGP v4&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="color: rgb(204, 153, 51); font-weight: bold;"&gt;Data Rate Management - per IP / protocol / subnet / port / firewall mark; HTB,  PCQ, RED, SFQ, byte limited queue, packet limited queue; hierarchical limitation,  CIR, MIR, contention ratios, dynamic client rate equalizing (PCQ)&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="color: rgb(102, 0, 204); font-weight: bold;"&gt;HotSpot - HotSpot Gateway with RADIUS authentication/accounting; data rate limitation;  traffic quota; real-time status information; walled-garden; customized HTML login  pages; iPass support; SSL secure authentication&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="color: rgb(204, 51, 204); font-weight: bold;"&gt;Point-to-Point tunneling protocols - PPTP, PPPoE and L2TP Access Concentrators  and clients; PAP, CHAP, MSCHAPv1 and MSCHAPv2 authentication protocols; RADIUS  authentication and accounting; MPPE encryption; compression for PPPoE; data rate  limitation; PPPoE dial on demand&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;Simple tunnels - IPIP tunnels, EoIP (Ethernet over IP)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;span style="color: rgb(204, 102, 204);"&gt;IPsec - IP security AH and ESP protocols; Diffie-Hellman groups 1,2,5; MD5 and  SHA1 hashing algorithms; DES, 3DES, AES-128, AES-192, AES-256 encryption algorithms;  Perfect Forwarding Secresy (PFS) groups 1,2,5 &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;span style="color: rgb(0, 0, 102);"&gt;Web proxy - FTP, HTTP and HTTPS caching proxy server; transparent HTTP caching  proxy; SOCKS protocol support; support for caching on a separate drive; access  control lists; caching lists; parent proxy support &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;span style="color: rgb(102, 51, 0);"&gt;Caching DNS client - name resolving for local use; Dynamic DNS Client; local  DNS cache with static entries &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;DHCP - DHCP server per interface; DHCP relay; DHCP client; multiple DHCP networks;  static and dynamic DHCP leases &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;span style="color: rgb(204, 153, 51);"&gt;Universal Client - Transparent address translation not depending on the client's  setup &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;VRRP - VRRP protocol for high availability&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;span style="color: rgb(102, 0, 204);"&gt;UPnP - Universal Plug-and-Play support &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 153, 255);"&gt;NTP - Network Time Protocol server and client; synchronization with GPS system &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;Monitoring/Accounting - IP traffic accounting, firewall actions logging&lt;br /&gt;&lt;br /&gt; &lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;span style="color: rgb(102, 51, 255);"&gt;SNMP - read-only access&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;span style="color: rgb(102, 102, 204);"&gt;M3P - MikroTik Packet Packer Protocol for Wireless links and Ethernet &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 102, 102);"&gt;MNDP - MikroTik Neighbor Discovery Protocol; also supports Cisco Discovery Protocol  (CDP) &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="color: rgb(102, 51, 255);"&gt;&lt;span style="font-weight: bold;"&gt;Tools - ping; traceroute; bandwidth test; ping flood; telnet; SSH; packet sniffer&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt; &lt;strong&gt;Layer 2 connectivity&lt;/strong&gt;  &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;Wireless - IEEE802.11a/b/g wireless client and Access Point; Wireless Distribution  System (WDS) support; virtual AP; 40 and 104 bit WEP; access control list; authentication  on RADIUS server; roaming (for wireless client); Access Point bridging&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Bridge - spanning tree protocol; multiple bridge interfaces; bridge firewalling&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;VLAN - IEEE802.1q Virtual LAN support on Ethernet and WLAN links; multiple VLANs;  VLAN bridging&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Synchronous - V.35, V.24, E1/T1, X.21, DS3 (T3) media types; sync-PPP, Cisco  HDLC, Frame Relay line protocols; ANSI-617d (ANDI or annex D) and Q933a (CCITT  or annex A) Frame Relay LMI types&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Asynchronous - serial PPP dial-in / dial-out; PAP, CHAP, MSCHAPv1 and MSCHAPv2  authentication protocols; RADIUS authentication and accounting; onboard serial  ports; modem pool with up to 128 ports; dial on demand&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; color: rgb(204, 102, 0);"&gt;ISDN - ISDN dial-in / dial-out; PAP, CHAP, MSCHAPv1 and MSCHAPv2 authentication  protocols; RADIUS authentication and accounting; 128K bundle support; Cisco HDLC,  x75i, x75ui, x75bui line protocols; dial on demand &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="color: rgb(0, 153, 0);"&gt;SDSL - Single-line DSL support; line termination and network termination modes &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt; &lt;strong&gt;Hardware requirements&lt;/strong&gt;  &lt;/div&gt;&lt;ul style="text-align: justify; font-weight: bold; color: rgb(0, 102, 0);"&gt;&lt;li&gt;CPU and motherboard - advanced 4th generation (core frequency 100MHz or more),  5th generation (Intel Pentium, Cyrix 6X86, AMD K5 or comparable) or newer uniprocessor  Intel IA-32 (i386) compatible (multiple processors are not supported)&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;RAM - minimum 48 MB, maximum 1 GB; 64 MB or more recommended &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Hard Drive/Flash - standard ATA interface controller and drive (SCSI and USB  controllers and drives are not supported; RAID controllers that require additional  drivers are not supported) with minimum of 64 MB space &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt; &lt;strong&gt;Hardware needed for installation time only&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Depending on installation method chosen the router must have the following hardware:  &lt;/div&gt;&lt;ul style="text-align: justify; font-weight: bold;"&gt;&lt;li&gt;&lt;span style="color: rgb(255, 102, 102);"&gt;Floppy-based installation - standard AT floppy controller and 3.5'' disk drive  connected as the first floppy disk drive (A); AT, PS/2 or USB keyboard; VGA-compatible  video controller card and monitor &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(102, 0, 204);"&gt;CD-based installation - standard ATA/ATAPI interface controller and CD drive  supporting "El Torito" bootable CDs (you might need also to check if the router's  BIOS supports booting from this type of media); AT, PS/2 or USB keyboard; VGA-compatible  video controller card and monitor &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(153, 102, 51);"&gt;Floppy-based network installation - standard AT floppy controller and 3.5'' disk  drive connected as the first floppy disk drive (A); PCI Ethernet network interface  card supported by MikroTik RouterOS (see the Device Driver List for the list) &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;Full network-based installation - PCI Ethernet network interface card supported  by MikroTik RouterOS (see the Device Driver List for the list) with PXE or EtherBoot  extension booting ROM (you might need also to check if the router's BIOS supports  booting from network)&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt; &lt;strong&gt;Configuration possibilities&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153); font-weight: bold;"&gt;RouterOS provides powerful command-line configuration interface. You can also  manage the router through WinBox - the easy-to-use remote configuration GUI for  Windows -, which provides all the benefits of the command-line interface, without  the actual "command-line", which may scare novice users. Major features:  &lt;/span&gt;&lt;/div&gt;&lt;ul style="text-align: justify; color: rgb(204, 0, 0);"&gt;&lt;li&gt;Clean and consistent user interface &lt;/li&gt;&lt;li&gt;Runtime configuration and monitoring &lt;/li&gt;&lt;li&gt;Multiple connections &lt;/li&gt;&lt;li&gt;User policies &lt;/li&gt;&lt;li&gt;Action history, undo/redo actions &lt;/li&gt;&lt;li&gt;safe mode operation &lt;/li&gt;&lt;li&gt;Scripts can be scheduled for executing at certain times, periodically, or on  events. All command-line commands are supported in scripts &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt; &lt;span style="font-weight: bold;"&gt;When router is not configured, there are only two ways to configure it:  &lt;/span&gt;&lt;/div&gt;&lt;ul style="text-align: justify; font-weight: bold; color: rgb(102, 51, 102);"&gt;&lt;li&gt;Local terminal console - AT, PS/2 or USB keyboard and VGA-compatible video controller  card with monitor &lt;/li&gt;&lt;li&gt;Serial console - First RS232 asynchronous serial port (usually, onboard port  marked as COM1), which is by default set to 9600bit/s, 8 data bits, 1 stop bit,  no parity &lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt; &lt;span style="font-weight: bold;"&gt;After the router is configured, it may be managed through the following interfaces:  &lt;/span&gt;&lt;/div&gt;&lt;ul style="text-align: justify; font-weight: bold;"&gt;&lt;li&gt;&lt;span style="color: rgb(102, 102, 0);"&gt;Local teminal console - AT, PS/2 or USB keyboard and VGA-compatible video controller  card with monitor &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Serial console - any (you may choose any one; the first, also known as COM1,  is used by default) RS232 asynchronous serial port, which is by default set to  9600bit/s, 8 data bits, 1 stop bit, no parity &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Telnet - telnet server is running on 23 TCP port by default&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(255, 102, 0);"&gt;SSH - SSH (secure shell) server is running on 22 TCP port by default (available  only if security package is installed) &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(153, 51, 0);"&gt;MAC Telnet - MikroTik MAC Telnet potocol server is by default enabled on all  Ethernet-like interfaces &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="color: rgb(51, 0, 0);"&gt;Winbox - Winbox is a RouterOS remote administration GUI for Windows, that use  3986 TCP port (or 3987 if security package is installed) &lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518056064991556503-3225973840718012430?l=anaknagi.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anaknagi.blogspot.com/feeds/3225973840718012430/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518056064991556503&amp;postID=3225973840718012430&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/3225973840718012430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/3225973840718012430'/><link rel='alternate' type='text/html' href='http://anaknagi.blogspot.com/2010/08/fitur-mikrotik-routeros.html' title='Fitur Mikrotik RouterOS'/><author><name>Materi Jaringan</name><uri>http://www.blogger.com/profile/18432157139474714821</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_mq7TojsGMx0/THm0VD0tWoI/AAAAAAAAACw/c_xErIz7CTA/S220/IMG0270A.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518056064991556503.post-9026804554700602267</id><published>2010-08-29T01:37:00.005+08:00</published><updated>2010-08-29T02:04:12.682+08:00</updated><title type='text'>BGP-Peer, Memisahkan Routing dan Bandwidth Management</title><content type='html'>&lt;p style="font-weight: bold; color: rgb(0, 102, 0); text-align: justify;"&gt;Dalam artikel ini, akan dibahas cara untuk melakukan BGP-Peer ke BGP Router Mikrotik  Indonesia untuk melakukan pemisahan gateway untuk koneksi internet internasional  dan OpenIXP (NICE). Setelah pemisahan koneksi ini dilakukan, selanjutnya akan dibuat  queue untuk tiap klien, yang bisa membatasi penggunaan untuk bandwidth internasional  dan OpenIXP (NICE).  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Beberapa asumsi yang akan dipakai untuk kasus kali ini adalah &lt;/span&gt;: &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ol style="color: rgb(153, 51, 153); font-weight: bold; text-align: justify;"&gt;&lt;li&gt;Router memiliki 3 buah interface, yang masing-masing terhubung ke gateway internasional,  gateway OpenIXP (NICE), dan ke network klien.&lt;/li&gt;&lt;li&gt;Untuk koneksi ke OpenIXP (NICE), router milik Anda harus memiliki IP publik.&lt;/li&gt;&lt;li&gt;Untuk klien, akan menggunakan IP private, sehingga akan dilakukan NAT (network  address translation)&lt;/li&gt;&lt;li&gt;Mikrotik RouterOS Anda menggunakan versi 2.9.39 atau yang lebih baru, dan mengaktifkan  paket routing-test&lt;/li&gt;&lt;/ol&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;img src="http://www.mikrotik.co.id/images/artikel/bgp-09.png" width="438" border="0" height="373" /&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;Jika Anda menghadapi kondisi yang tidak sesuai dengan parameter di atas, harus  dilakukan penyesuaian.  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;img src="http://www.mikrotik.co.id/images/line.gif" width="438" border="0" height="18" /&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;strong&gt;PENGATURAN DASAR&lt;/strong&gt; &lt;/p&gt;&lt;p style="text-align: justify;"&gt;Diagram network dan konfigurasi IP Address yang digunakan pada contoh ini adalah  seperti gambar berikut ini.  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;img src="http://www.mikrotik.co.id/images/artikel/bgp-01.png" width="438" border="0" height="336" /&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;Untuk mempermudah pemberian contoh, kami mengupdate nama masing-masing interface  sesuai dengan tugasnya masing-masing. &lt;br /&gt;  &lt;table style="width: 680px; height: 168px; text-align: left; margin-left: 0px; margin-right: 0px;" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;[admin@MikroTik] &gt; /in pr&lt;br /&gt;Flags: X - disabled, D - dynamic, R - running&lt;br /&gt;#    NAME            TYPE   RX-RATE  TX-RATE  MTU&lt;br /&gt;0  R ether1-intl     ether  0        0        1500&lt;br /&gt;1  R ether2-iix      ether  0        0        1500&lt;br /&gt;2  R ether3-client   ether  0        0        1500&lt;br /&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;  &lt;/p&gt;&lt;p style="font-weight: bold; color: rgb(153, 51, 0); text-align: justify;"&gt;Konfigurasi IP Address sesuai dengan contoh berikut ini. Sesuaikanlah dengan  IP Address yang Anda gunakan. Dalam contoh ini, IP Address yang terhubung ke OpenIXP (NICE)  menggunakan IP 202.65.113.130/29, terpasang pada interface ether2-iix dan gatewaynya  adalah 202.65.113.129. Sedangkan untuk koneksi ke internasional menggunakan IP  Address 69.1.1.2/30 pada interface ether1-intl, dengan gateway 69.1.1.1. &lt;/p&gt;&lt;p style="font-weight: bold; color: rgb(102, 102, 0); text-align: justify;"&gt;Untuk klien, akan menggunakan blok IP 192.168.1.0/24, dan IP Address 192.168.1.1  difungsikan sebagai gateway dan dipasang pada ether3-client. Klien dapat menggunakan  IP Address 192.168.1-2 hingga 192.168.1.254 dengan subnet mask 255.255.255.0.  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;img style="width: 520px; height: 107px;" src="http://www.mikrotik.co.id/images/artikel/bgp-02.png" border="0" /&gt;  &lt;/p&gt;&lt;p style="font-weight: bold; color: rgb(204, 0, 0); text-align: justify;"&gt;Jangan lupa melakukan konfigurasi DNS server pada router, dan mengaktifkan fitur  &lt;span style="color: rgb(0, 0, 0);"&gt;"allow remote request"&lt;/span&gt;. &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Karena klien menggunakan IP private, maka kita harus melakukan fungsi src-nat  untuk kedua jalur gateway.  &lt;/span&gt;&lt;br /&gt;  &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px; width: 680px; height: 126px;" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;[admin@MikroTik] &gt; /ip fi nat pr&lt;br /&gt;Flags: X - disabled, I - invalid, D - dynamic&lt;br /&gt;0   chain=srcnat out-interface=ether1-intl action=masquerade&lt;br /&gt;1   chain=srcnat out-interface=ether2-iix action=masquerade&lt;br /&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;   &lt;/p&gt;&lt;p style="color: rgb(153, 51, 0); font-weight: bold; text-align: justify;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;CEK:&lt;/span&gt; Pastikan semua konfigurasi telah berfungsi baik. Buatlah default route pada  router secara bergantian ke IP gateway OpenIXP (NICE) dan internasional. Lakukanlah ping  (baik dari router maupun dari klien) ke luar network Anda secara bergantian.  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;img src="http://www.mikrotik.co.id/images/line.gif" width="438" border="0" height="18" /&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;strong&gt;PENGATURAN BGP-PEER&lt;/strong&gt;  &lt;/p&gt;&lt;p style="color: rgb(255, 0, 0); font-weight: bold; text-align: justify;"&gt;Pertama-tama, pastikan bahwa Anda menggunakan gateway internasional Anda sebagai  default route, dalam contoh ini adalah 69.1.1.1. Kemudian Anda perlu membuat sebuah  static route ke mesin BGP Mikrotik Indonesia, yaitu IP 202.65.120.250. &lt;/p&gt;&lt;p style="font-weight: bold; color: rgb(51, 204, 0); text-align: justify;"&gt;Lalu periksalah apakah Anda bisa melakukan ping ke 202.65.120.250. Periksalah  juga dengan traceroute dari router, apakah jalur pencapaian ke IP 202.65.120.250  telah melalui jalur koneksi yang diperuntukkan bagi trafik OpenIXP (NICE), dan bukan melalui  jalur internasional.  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;img style="width: 541px; height: 160px;" src="http://www.mikrotik.co.id/images/artikel/bgp-03.png" border="0" /&gt;  &lt;/p&gt;&lt;p style="font-weight: bold; color: rgb(102, 0, 204); text-align: justify;"&gt;Kemudian, Anda harus mendaftarkan IP Address Anda di website Mikrotik Indonesia  untuk mengaktifkan layanan BGP-Peer ini.&lt;br /&gt;&lt;/p&gt;&lt;p style="font-weight: bold; color: rgb(102, 0, 204); text-align: justify;"&gt;Aktivasi bisa dilakukan di &lt;a href="http://www.mikrotik.co.id/user_bgp_aktivasi.php"&gt;halaman ini&lt;/a&gt;.  IP Address yang bisa Anda daftarkan hanyalah IP Address yang bisa di-ping dari  mesin kami, dan juga harus sudah diadvertise di OIXP. Aturan selengkapnya mengenai  penggunaan layanan ini bisa dibaca di &lt;a href="http://www.mikrotik.co.id/index_lihat.php?id=22"&gt;halaman ini&lt;/a&gt;.  Setelah Anda mendaftarkan IP  Address Anda, jika semua syarat sudah terpenuhi, Anda akan diinformasikan bahwa  aktivasi layanan BGP-Peer Anda sudah sukses. Selanjutnya Anda bisa melihat status  layanan BGP Anda di &lt;a href="http://www.mikrotik.co.id/user_bgp_manage.php"&gt;halaman ini&lt;/a&gt;. &lt;/p&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(204, 51, 204);"&gt;BGP Router Mikrotik Indonesia akan menggunakan IP Address 202.65.120.250 dan  AS Number 64888, dan Router Anda akan menjadi BGP Peer dengan menggunakan AS Number  64666. &lt;/p&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(51, 0, 153);"&gt;Berikutnya adalah langkah-langkah yang harus Anda lakukan pada router Anda. Pertama-tama  Anda harus membuat beberapa prefix-list untuk BGP ini. Untuk prefix yang akan  Anda terima, untuk alasan keamanan dan hematnya agregasi routing, maka Anda perlu  melakukan setting untuk menerima hanya prefix 8 hingga 24. Prefix 0 sampai 7,  dan 25 sampai 32 akan Anda blok. Prefix ini kita berinama prefix-in. Untuk prefix-in  yang accept, harap diperhatikan bahwa Anda perlu menentukan gateway untuk informasi  routing ini, yaitu IP gateway OpenIXP (NICE) Anda. Dalam contoh ini adalah 202.65.113.129.  Gantilah IP ini sesuai dengan gateway OpenIXP (NICE) Anda.  &lt;/p&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(204, 51, 204);"&gt;Sedangkan karena sifat BGP-Peer ini hanya Anda menerima informasi routing saja,  di mana Anda tidak dapat melakukan advertisement, maka harus dilakukan blok untuk  semua prefix yang dikirimkan, dan kita beri nama prefix-out. &lt;/p&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(204, 51, 204);"&gt;Berikut ini adalah konfigurasi prefix list yang telah dibuat.  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;img src="http://www.mikrotik.co.id/images/artikel/bgp-04.png" width="438" border="0" height="86" /&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;Tahap selanjutnya adalah konfigurasi BGP instance. Yang perlu di-set di sini hanyalah  AS Number Anda, pada kasus ini kita menggunakan AS Number private, yaitu 64666.  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;img src="http://www.mikrotik.co.id/images/artikel/bgp-05.png" width="438" border="0" height="78" /&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;Dan langkah terakhir pada konfigurasi BGP ini adalah konfigurasi peer.  AS Number BGP Router Mikrotik Indonesia adalah 64888 dan IP Addressnya adalah 202.65.120.250.  Karena kita sulit menentukan berapa hop jarak BGP Router Mikrotik Indonesia dengan Router  Anda, maka kita melakukan konfigurasi TTL menjadi 255. Jangan lupa mengatur rule prefix-in  dan prefix-out sesuai dengan prefix yang telah kita buat sebelumnya.  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;img style="width: 438px; height: 134px;" src="http://www.mikrotik.co.id/images/artikel/bgp-06.png" border="0" /&gt;  &lt;/p&gt;&lt;p style="text-align: justify; color: rgb(153, 51, 0); font-weight: bold;"&gt;Setelah langkah ini, seharusnya BGP Router Mikrotik sudah dapat terkoneksi dengan  Router Anda. Koneksi ini ditandai dengan status peer yang menjadi "established"  dan akan dicantumkan pula jumlah informasi routing yang diterima. Anda juga bisa  mengecek status peer ini dari sisi BGP Router Mikrotik Indonesia dengan melihat  pada &lt;a href="http://www.mikrotik.co.id/user_bgp_manage.php"&gt;halaman ini&lt;/a&gt;.  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;img style="width: 438px; height: 193px;" src="http://www.mikrotik.co.id/images/artikel/bgp-07.png" border="0" /&gt;  &lt;/p&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(255, 0, 0);"&gt;Cek pula pada bagian IP Route, seharusnya sudah diterima ribuan informasi routing,  dan pastikan bahwa gatewaynya sesuai dengan gateway OpenIXP (NICE) Anda, dan berada pada  interface yang benar, dalam contoh ini adalah "ether2-iix".  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;img src="http://www.mikrotik.co.id/images/artikel/bgp-08.png" width="374" border="0" height="401" /&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="color: rgb(153, 51, 0); font-weight: bold;"&gt;Jika semua sudah berjalan, pastikan bahwa penggunaan 2 buah gateway ini sudah  sukses dengan cara melakukan tracerute dari router ataupun dari laptop ke beberapa  IP Address baik yang berada di internasional maupun yang berada di jaringan OpenIXP (NICE).  &lt;/span&gt;&lt;br /&gt;  &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" width="100%" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;C:&gt;tracert www.yahoo.com&lt;br /&gt;&lt;br /&gt;Tracing route to www.yahoo-ht2.akadns.net&lt;br /&gt;[209.131.36.158]&lt;br /&gt;over a maximum of 30 hops:&lt;br /&gt;&lt;br /&gt;1    &lt;1 ms    &lt;1 ms    &lt;1 ms  192.168.1.1&lt;br /&gt;2     1 ms    &lt;1 ms    &lt;1 ms  69.1.1.1&lt;br /&gt;3   222 ms   223 ms   223 ms  157.130.195.13&lt;br /&gt;4   222 ms   289 ms   222 ms  152.63.54.118&lt;br /&gt;5   226 ms   242 ms  ^C&lt;br /&gt;&lt;br /&gt;C:&gt;tracert www.cbn.net.id&lt;br /&gt;&lt;br /&gt;Tracing route to web.cbn.net.id [210.210.145.202]&lt;br /&gt;over a maximum of 30 hops:&lt;br /&gt;&lt;br /&gt; 1    &lt;1 ms    &lt;1 ms    &lt;1 ms  192.168.1.1&lt;br /&gt; 2     1 ms    &lt;1 ms     1 ms  202.65.113.129&lt;br /&gt; 3    11 ms    12 ms   127 ms  218.100.27.218&lt;br /&gt; 4    21 ms    41 ms    21 ms  218.100.27.165&lt;br /&gt; 5    22 ms    24 ms  ^C&lt;br /&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;    &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;img src="http://www.mikrotik.co.id/images/line.gif" width="438" border="0" height="18" /&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;strong&gt;PENGATURAN BANDWIDTH MANAGEMENT&lt;/strong&gt;  &lt;/p&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(102, 0, 204);"&gt;Setelah semua routing dan BGP Peer berjalan dengan baik,  yang perlu kita lakukan sekarang adalah mengkonfigurasi bandwidth management. Untuk contoh ini kita akan menggunakan mangle dan queue tree.  &lt;/p&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(102, 0, 204);"&gt;Karena network klien menggunakan IP private, maka kita perlu melakukan connection tracking pada mangle. Pastikan bahwa Anda telah mengaktifkan  connection tracking pada router Anda.  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;img src="http://www.mikrotik.co.id/images/artikel/bgp-10.png" width="330" border="0" height="135" /&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;Untuk masing-masing trafik, lokal dan internasional, kita membuat sebuah rule mangle connection. Dari connection mark tersebut kemudian kita membuat packet-mark untuk masing-masing trafik.  &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;  &lt;/span&gt;&lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" width="100%" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;[admin@MikroTik] &gt; /ip firewall mangle print&lt;br /&gt;Flags: X - disabled, I - invalid, D - dynamic&lt;br /&gt;0   chain=forward out-interface=ether1-intl&lt;br /&gt;    src-address=192.168.1.2 action=mark-connection&lt;br /&gt;    new-connection-mark=conn-intl&lt;br /&gt;    passthrough=yes&lt;br /&gt;&lt;br /&gt;1   chain=forward out-interface=ether2-iix&lt;br /&gt;    src-address=192.168.1.2 action=mark-connection&lt;br /&gt;    new-connection-mark=conn-nice&lt;br /&gt;    passthrough=yes&lt;br /&gt;&lt;br /&gt;2   chain=forward connection-mark=conn-intl&lt;br /&gt;    action=mark-packet&lt;br /&gt;    new-packet-mark=packet-intl passthrough=yes&lt;br /&gt;&lt;br /&gt;3   chain=forward connection-mark=conn-nice&lt;br /&gt;    action=mark-packet new-packet-mark=packet-nice&lt;br /&gt;    passthrough=yes&lt;br /&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;  &lt;/p&gt;&lt;p style="text-align: justify; color: rgb(51, 51, 255); font-weight: bold;"&gt;Untuk setiap klien, Anda harus membuat rule seperti di atas, sesuai dengan IP Address yang digunakan oleh klien.  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="color: rgb(51, 51, 255); font-weight: bold;"&gt;Langkah berikutnya adalah membuat queue tree rule. Kita akan membutuhkan 4 buah rule, untuk membedakan upstream / downstream  untuk koneksi internasional dan lokal.  &lt;/span&gt;&lt;br /&gt;  &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" width="100%" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;[admin@MikroTik] &gt; queue tree print&lt;br /&gt;Flags: X - disabled, I - invalid&lt;br /&gt;0   name="intl-down" parent=ether3-client&lt;br /&gt;    packet-mark=packet-intl limit-at=0&lt;br /&gt;    queue=default priority=8 max-limit=128000&lt;br /&gt;    burst-limit=0 burst-threshold=0 burst-time=0s&lt;br /&gt;&lt;br /&gt;1   name="intl-up" parent=ether1-intl&lt;br /&gt;    packet-mark=packet-intl limit-at=0&lt;br /&gt;    queue=default priority=8 max-limit=32000&lt;br /&gt;    burst-limit=0 burst-threshold=0 burst-time=0s&lt;br /&gt;&lt;br /&gt;2   name="nice-up" parent=ether2-iix&lt;br /&gt;    packet-mark=packet-nice limit-at=0&lt;br /&gt;    queue=default priority=8 max-limit=256000&lt;br /&gt;    burst-limit=0 burst-threshold=0 burst-time=0s&lt;br /&gt;&lt;br /&gt;3   name="nice-down" parent=ether3-client&lt;br /&gt;    packet-mark=packet-nice limit-at=0&lt;br /&gt;    queue=default priority=8 max-limit=1024000&lt;br /&gt;    burst-limit=0 burst-threshold=0 burst-time=0s&lt;br /&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;  &lt;/p&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(255, 0, 0);"&gt;Besarnya limit-at / max-limit dan burst bisa Anda sesuaikan dengan  layanan yang dibeli oleh klien.  &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518056064991556503-9026804554700602267?l=anaknagi.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anaknagi.blogspot.com/feeds/9026804554700602267/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518056064991556503&amp;postID=9026804554700602267&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/9026804554700602267'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/9026804554700602267'/><link rel='alternate' type='text/html' href='http://anaknagi.blogspot.com/2010/08/bgp-peer-memisahkan-routing-dan.html' title='BGP-Peer, Memisahkan Routing dan Bandwidth Management'/><author><name>Materi Jaringan</name><uri>http://www.blogger.com/profile/18432157139474714821</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_mq7TojsGMx0/THm0VD0tWoI/AAAAAAAAACw/c_xErIz7CTA/S220/IMG0270A.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518056064991556503.post-8230497680159274967</id><published>2010-08-29T01:33:00.004+08:00</published><updated>2010-08-29T01:35:38.387+08:00</updated><title type='text'>Teknik Pengggunaan Wireless</title><content type='html'>&lt;strong&gt;Di manakah sebaiknya saya menempatkan Base Station?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Base station biasanya diletakkan di tempat yang tinggi, yang memungkinkan dapat terjangkau dari pelanggan. Bisa berupa rooftop dari gedung tinggi, ataupun tower.  &lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;br /&gt;Perangkat apa saja yang dibutuhkan di Base Station?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;Pada dasarnya, perangkat wireless di base station di bagi dua, yaitu perangkat point to point sebagai backhaul, dan perangkat lainnya untuk melayani pelanggan. Perangkat backhaul tidak dibutuhkan jika Anda memiliki akses internet ke BTS via kabel ataupun media lain. Untuk access pointnya sendiri, biasanya menggunakan antenna yang dapat melayani area yang cukup lebar. Bisa berupa omnidirectional antenna, ataupun antenna sectoral. Omnidirectional antenna dapat menjangkau 360 derajat, sedangkan antenna sectoral hanya dapat menjangkau 90 hingga 120 derajat, sehingga dibutuhkan 3 hingga 4 antenna, termasuk juga access pointnya.  &lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;br /&gt;Berapa client yang dapat terkoneksi ke base station? &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 51, 204); font-weight: bold;"&gt;Secara teori, perangkat wireless Mikrotik dapat melayani 2007 client. Namun, bagaimanapun juga, performance nya tergantung pada kehandalan sistem dan kondisi sekitar. Jumlah ini sangat regantung pada penggunaan setiap client, dan berapa jumlah komputer yang terkoneksi di belakang sebuah AP Client. Jumlah yang pernah dicapai pada penggunaan normal adalah 100 client.  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Berapakah jarak terjauh antara BTS dan lokasi client? &lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153); font-weight: bold;"&gt;Jarak terjauh akan tergantung pada daya antena, loss pada kabel antenna, kekuatan  pancar radio, sensifitas radio, dan tingkat inteferensi dari radio lain yang menggunakan  frekuensi yang sama.   &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153); font-weight: bold;"&gt;Dengan frekuensi 2,4 GHz, biasanya jarak terjauh yang bisa dicapai adalah 12  kilometer, sedangkan dengan frekuensi 5 GHz, dengan menggunakan antenna solid  disc 30db, bisa dicapai jarak 28 km. Lebar bandwidth yang bisa dicapai adalah  sekitar 10 mbps dengan uji coba bandwidth test.  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Dapatkah saya menggunakan amplifier untuk memperjauh jangkauan ?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 0); font-weight: bold;"&gt;Secara teknis, bisa. Namun, perhatikan regulasi yang berlaku. Penggunaan amplifier  dapat digunakan untuk mengkompensasikan loss yang terjadi akibat penggunaan kabel  antenna yang panjang.  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Apakah antara BTS dan client harus benar-benar bebas halangan (Line of sight)  ?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Ya. Kondisi line of sight mutlak dibutuhkan. Juga perhatikan freznel zone yang  dibutuhkan.  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Apakah yang dimaksud dengan fresnel zone?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;Freznel Zone adalah area di sekitar garis lurus antar alat yang digunakan untuk  rambatan gelombang. Area ini juga harus bebas dari gangguan, atau kekuatan signal  akan menurun. Sebagai contoh, pada link berjarak 16 km, dengan frekuensi 5,8 GHz,  besarnya lingkaran freznel zone di tengah-tengah kedua alat adalah lingkaran dengan  radius 8,7 meter, dan 13,6 meter untuk frekuensi 2,4 GHz.  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Dapatkah saya melakukan bridge saat menggunakan produk wireless Mikrotik? &lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(153, 51, 0);"&gt;Ya. Jika Anda menggunakan Access Point Mikrotik dan client merk lainnya, yang  perlu Anda lakukan adalah memasukkan interface wlan pada mikrotik ke interface  bridge, demikian juga dengan ethernetnya. Sedangkan bila menggunakan wireless  client Mikrotik, Anda bisa melakukan bridge dengan menggunakan teknik &lt;/span&gt;&lt;a style="font-weight: bold; color: rgb(153, 51, 0);" href="http://www.mikrotik.com/docs/ros/2.9/interface/eoip" target="_blank"&gt;EoIP&lt;/a&gt;&lt;span style="font-weight: bold; color: rgb(153, 51, 0);"&gt; atau  menggunakan &lt;/span&gt;&lt;a style="font-weight: bold; color: rgb(153, 51, 0);" href="http://www.mikrotik.com/docs/ros/2.9/interface/wireless.content#4.13.10" target="_blank"&gt;WDS Wireless&lt;/a&gt;&lt;span style="font-weight: bold; color: rgb(153, 51, 0);"&gt;. Simak manual penggunaan untuk lebih jelasnya.  &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518056064991556503-8230497680159274967?l=anaknagi.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anaknagi.blogspot.com/feeds/8230497680159274967/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518056064991556503&amp;postID=8230497680159274967&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/8230497680159274967'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/8230497680159274967'/><link rel='alternate' type='text/html' href='http://anaknagi.blogspot.com/2010/08/teknik-pengggunaan-wireless.html' title='Teknik Pengggunaan Wireless'/><author><name>Materi Jaringan</name><uri>http://www.blogger.com/profile/18432157139474714821</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_mq7TojsGMx0/THm0VD0tWoI/AAAAAAAAACw/c_xErIz7CTA/S220/IMG0270A.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518056064991556503.post-3589977614167225935</id><published>2010-08-29T00:50:00.007+08:00</published><updated>2010-08-29T01:13:58.410+08:00</updated><title type='text'>Cara Setting Abacus Pada PC dan Mikrotik</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Setting Abacus Pada PC&lt;br /&gt;&lt;br /&gt;MEMBUAT KONEKSI VPN&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Klik START &lt;span style="color: rgb(0, 0, 0);"&gt;→&lt;/span&gt; CONTROL PANEL &lt;span style="color: rgb(0, 0, 0);"&gt;→&lt;/span&gt; NETWORK AND DIAL UP CONNECTION / NETWORK CONNECTION &lt;span style="color: rgb(0, 0, 0);"&gt;→&lt;/span&gt; pilih CREATE NEW CONNECTION Klik NEXT &lt;span style="color: rgb(0, 0, 0);"&gt;→&lt;/span&gt; pilih CONNECT TO THE NETWORK AT MY NETWORK&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I.DETAIL MEMBUAT KONEKSI VPN&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;ol&gt;&lt;li style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Klik START → CONTROL PANEL → NETWORK AND DIAL UP CONNECTION / NETWORK CONNECTION → pilih CREATE NEW CONNECTION&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;Klik NEXT → pilih CONNECT TO THE NETWORK AT MY NETWORK PLACE&lt;/li&gt;&lt;li style="font-weight: bold; color: rgb(153, 51, 0);"&gt;Klik NEXT → pilih VIRTUAL PRIVATE NETWORKING&lt;/li&gt;&lt;li style="font-weight: bold; color: rgb(51, 0, 153);"&gt;Tulis COMPANY NAME dengan AbacusVPN&lt;/li&gt;&lt;li style="font-weight: bold; color: rgb(0, 102, 0);"&gt;Klik NEXT → tulis HOSTNAME dengan IP ADDRESS = 202.152.13.207&lt;/li&gt;&lt;li style="font-weight: bold;"&gt; &lt;span style="color: rgb(102, 51, 102);"&gt;Klik NEXT → pilih Anyone’s Use&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Klik NEXT → checklist (v) pada kotak ADD A SHORTCUT kemudian klik FINISH&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;br /&gt;II. SETTING KONEKSI&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Gunakan username dan password sementara di bawah ini. Jika sudah berhasil melakukan koneksi abacus vpn, hubungi Teknikal Abacus untuk mendapatkan username dan password sendiri&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;br /&gt;&lt;span style="color: rgb(153, 0, 0);"&gt;            USERNAME         : admin&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(153, 51, 0);"&gt;            PASSWORD        : admin&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;      checklist &lt;span style="color: rgb(255, 0, 0);"&gt;(v)&lt;/span&gt; pada kotak save user name and password&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(153, 0, 0);"&gt;Kemudian klik Properties&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="color: rgb(0, 102, 0);"&gt;Pada tab SECURITY → klik ADVANCED (CUSTOM SETTINGS) → klik SETTINGS&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;Pada DATA ENCRYPTION pilih OPTIONAL ENCRYPTION. Pada bagian ALLOW THESE PROTOCOLS checklist (v) PAP, CHAP, MS-CHAP v 2 (kolom 1, 3, dan 5), selain kolom tersebut hilangkan tanda checklist (v), kemudian OK &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;Klik tab NETWORKING, kemudian double click pada INTERNET PROTOCOL (TCP/IP), lalu klik ADVANCED, setelah itu hilangkan tanda checklist (v) yang ada pada USE DEFAULT GATEWAY ON REMOTE NETWORK.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;span style="color: rgb(204, 51, 204);"&gt;Klik OK sampai tampilan Login (Username &amp;amp; Password) muncul pada layar&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Kemudian klik CONNECT sampai gambar komputer muncul di sudut kanan monitor atau muncul balloon :&lt;span style="color: rgb(255, 0, 0);"&gt; "AbacusVPN is now connected"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;Sekarang anda sudah dapat melakukan reservasi pada sistem Domestik Arga.&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;/span&gt;&lt;/span&gt;&lt;ul style="color: rgb(255, 102, 0);"&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt; Perlu diketahui apabila menggunakan firewall, protokol TCP 1723 dan protocol 47 (GRE) harus dibuka. Hubungi Administrator firewall anda untuk membuka protocol tersebut.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;Jika masih mengalami kesulitan dalam membuat konfigurasi Abacus VPN, silahkan hubungi Unit Technical Support Abacus Indonesia 021-27535399 ext 3171-3178 atau melalui e-mail technical@abacus-ind.co.idThis e-mail address is being protected from spambots, you need JavaScript enabled to view it .&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;------------------------------------------------------------------------------------------------------&lt;br /&gt;------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Setting Abacus Pada Mikrotik :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;/ ip ipsec policy   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;add src-address=[your ip address]/32:any dst-address=10.10.1.0/24:any   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;    protocol=all action=encrypt level=require ipsec-protocols=esp tunnel=yes   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;    sa-src-address=[ip router] sa-dst-address=203.130.231.5   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;    proposal=abacus manual-sa=none dont-fragment=clear disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 153, 0);"&gt;/ ip ipsec peer   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 153, 0);"&gt;add address=203.130.231.5/32:0 secret="[secret key nya di sini]"   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 153, 0);"&gt;    generate-policy=yes   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 153, 0);"&gt;    exchange-mode=main send-initial-contact=yes proposal-check=obey   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 153, 0);"&gt;    hash-algorithm=md5 enc-algorithm=des dh-group=modp768 lifetime=1d   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 153, 0);"&gt;    lifebytes=0 disabled=no   &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;/ ip ipsec proposal   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;add name="abacus" auth-algorithms=md5 enc-algorithms=des lifetime=1d   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;    lifebytes=0 pfs-group=none disabled=no   &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518056064991556503-3589977614167225935?l=anaknagi.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anaknagi.blogspot.com/feeds/3589977614167225935/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518056064991556503&amp;postID=3589977614167225935&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/3589977614167225935'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/3589977614167225935'/><link rel='alternate' type='text/html' href='http://anaknagi.blogspot.com/2010/08/penggunaan-ipsec-untuk-abacus.html' title='Cara Setting Abacus Pada PC dan Mikrotik'/><author><name>Materi Jaringan</name><uri>http://www.blogger.com/profile/18432157139474714821</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_mq7TojsGMx0/THm0VD0tWoI/AAAAAAAAACw/c_xErIz7CTA/S220/IMG0270A.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518056064991556503.post-1051090576263546829</id><published>2010-08-29T00:31:00.003+08:00</published><updated>2010-08-29T00:50:30.953+08:00</updated><title type='text'>Setting Mikrotik Wireless Bridge</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Sering kali, kita ingin menggunakan Mikrotik Wireless&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;untuk solusi point to point  dengan mode jaringan bridge (bukan routing)&lt;/span&gt;. &lt;span style="font-weight: bold; color: rgb(102, 51, 102);"&gt;Namun&lt;/span&gt;, &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Mikrotik RouterOS sendiri  didesain bekerja dengan sangat baik pada mode routing&lt;/span&gt;. Kita perlu melakukan beberapa  hal &lt;span style="font-weight: bold;"&gt;supaya link wireless kita bisa bekerja untuk mode bridge&lt;/span&gt;.  &lt;/div&gt;&lt;p style="text-align: justify; font-weight: bold;"&gt;Mode bridge memungkinkan network yang satu tergabung dengan network di sisi satunya  secara transparan, tanpa perlu melalui routing, sehingga mesin yang ada di network  yang satu bisa memiliki IP Address yang berada dalam 1 subnet yang sama dengan  sisi lainnya.&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Namun&lt;/span&gt;,&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt; jika jaringan wireless kita sudah cukup besar, mode bridge ini akan membuat  traffic wireless meningkat, mengingat akan ada banyak traffic broadcast dari network  yang satu ke network lainnya. Untuk jaringan yang sudah cukup besar, saya menyarankan  penggunaan mode routing. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;span style="font-weight: bold;"&gt;Berikut ini adalah diagram network yang akan kita set.  &lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;img style="width: 584px; height: 111px;" src="http://www.mikrotik.co.id/images/artikel/wireless-bridge-01-new.jpg" alt="" title="" /&gt; &lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;img src="http://www.mikrotik.co.id/images/line.gif" alt="" title="" width="438" height="18" /&gt; &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Konfigurasi Pada Access Point&lt;/strong&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(102, 0, 204);"&gt;1. Buatlah sebuah interface bridge yang baru, berilah nama bridge1&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;img style="width: 554px; height: 248px;" title="" alt="" src="http://www.mikrotik.co.id/images/artikel/wireless-bridge-02.jpg" /&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(102, 0, 204);"&gt;2. Masukkan ethernet ke dalam interface bridge&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;img style="width: 564px; height: 278px;" src="http://www.mikrotik.co.id/images/artikel/wireless-bridge-03.jpg" alt="" title="" /&gt; &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(102, 0, 204);"&gt;3.  Masukkan IP Address pada interface bridge1&lt;/p&gt;&lt;div style="text-align: justify;"&gt;&lt;img src="http://www.mikrotik.co.id/images/artikel/wireless-bridge-04.jpg" alt="" title="" width="435" height="209" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;4. Selanjutnya adalah setting wireless interface.&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Kliklah pada menu Wireless   (1),&lt;/li&gt;&lt;li style="font-weight: bold; color: rgb(0, 102, 0);"&gt;Pilihlah tab interface   (2)&lt;/li&gt;&lt;li style="font-weight: bold; color: rgb(51, 0, 153);"&gt;Lalu double click pada nama interface wireless  yang akan digunakan (3).&lt;/li&gt;&lt;li style="font-weight: bold; color: rgb(0, 0, 0);"&gt;&lt;span style="color: rgb(204, 51, 204);"&gt;Pilihlah mode AP-bridge  (4),&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold; color: rgb(51, 0, 153);"&gt;Tentukanlah ssid       (5),&lt;/li&gt;&lt;li style="font-weight: bold; color: rgb(0, 0, 0);"&gt; &lt;span style="color: rgb(51, 51, 153);"&gt;Band  2.4GHz-B/G     (6),&lt;/span&gt;&lt;/li&gt;&lt;li style="font-weight: bold; color: rgb(0, 0, 0);"&gt;&lt;span style="color: rgb(0, 51, 0);"&gt; Frekuensi yang akan digunakan  (7). &lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Jangan lupa mengaktifkan  default authenticated  (8)&lt;/li&gt;&lt;li style="font-weight: bold; color: rgb(0, 0, 0);"&gt;Dan default forward   (9).&lt;/li&gt;&lt;li style="font-weight: bold; color: rgb(0, 0, 0);"&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;Lalu aktifkankanlah interface  wireless  (10) &lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Dan klik OK   (11).  &lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;&lt;img style="width: 565px; height: 528px;" title="" alt="" src="http://www.mikrotik.co.id/images/artikel/wireless-bridge-05.jpg" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;5. Berikutnya adalah konfigurasi WDS pada wireless interface yang digunakan.  Bukalah kembali konfigurasi wireless seperti langkah di atas,&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;pilihlah tab WDS  (1). &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="color: rgb(102, 102, 0);"&gt;&lt;span style="font-weight: bold;"&gt;Tentukanlah WDS Mode dynamic (2)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(0, 153, 0);"&gt; dan pilihlah bridge interface untuk WDS  ini (3). &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;Lalu tekan tombol OK.  &lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;&lt;img style="width: 569px; height: 414px;" src="http://www.mikrotik.co.id/images/artikel/wireless-bridge-06.jpg" alt="" title="" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(255, 0, 0);"&gt;6. Langkah selanjutnya adalah menambahkan virtual interface WDS. Tambahkan interface  WDS baru seperti pada gambar, lalu pilihlah interface wireless yang kita gunakan  untuk WDS ini. Lalu tekan OK.&lt;/p&gt;&lt;div style="text-align: justify;"&gt;&lt;img style="width: 557px; height: 328px;" src="http://www.mikrotik.co.id/images/artikel/wireless-bridge-07.jpg" alt="" title="" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(0, 0, 153);"&gt;7. Jika WDS telah ditambahkan, maka akan tampak interface WDS baru seperti pada  gambar di bawah.&lt;/p&gt;&lt;div style="text-align: justify;"&gt;&lt;img style="width: 562px; height: 171px;" src="http://www.mikrotik.co.id/images/artikel/wireless-bridge-08.jpg" alt="" title="" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;img src="http://www.mikrotik.co.id/images/line.gif" alt="" title="" width="438" height="18" /&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Konfigurasi pada Wireless Station&lt;/strong&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt;Konfigurasi pada wireless station hampir sama dengan langkah-langkah di atas,  &lt;span style="font-weight: bold; color: rgb(153, 51, 0);"&gt;kecuali pada langkah memasukkan IP Address dan konfigurasi wirelessnya.&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Pada konfigurasi  station, mode yang digunakan adalah &lt;/span&gt;&lt;em style="font-weight: bold; color: rgb(255, 0, 0);"&gt;station-wds&lt;/em&gt;,&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt; frekuensi tidak perlu ditentukan,&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;namun harus menentukan scan-list di mana  frekuensi pada access point masuk dalam scan list ini&lt;/span&gt;. &lt;span style="font-weight: bold; color: rgb(102, 51, 51);"&gt;Misalnya pada access point  kita menentukan frekuensi 2412, maka tuliskanlah scan-list 2400-2500&lt;/span&gt;. &lt;br /&gt;&lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;img style="width: 556px; height: 525px;" src="http://www.mikrotik.co.id/images/artikel/wireless-bridge-09.jpg" alt="" title="" /&gt; &lt;/p&gt;&lt;div style="text-align: justify;"&gt;&lt;img title="" alt="" src="http://www.mikrotik.co.id/images/line.gif" width="438" height="18" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Pengecekan link&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Jika link wireless yang kita buat sudah bekerja dengan baik, maka pada menu wireless,  akan muncul status R (lihat gambar di bawah).  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;img style="width: 563px; height: 179px;" title="" alt="" src="http://www.mikrotik.co.id/images/artikel/wireless-bridge-10.jpg" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;p style="text-align: justify; color: rgb(0, 0, 153); font-weight: bold;"&gt;Selain itu, mac-address dari wireless yang terkoneksi juga bisa dilihat pada  jendela registration (lihat gambar di bawah).&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;img style="width: 538px; height: 179px;" title="" alt="" src="http://www.mikrotik.co.id/images/artikel/wireless-bridge-11.jpg" /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;strong&gt;&lt;img title="" alt="" src="http://www.mikrotik.co.id/images/line.gif" width="438" height="18" /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Konfigurasi keamanan jaringan wireless&lt;/strong&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;Pada Mikrotik, cara paling mudah &lt;span style="font-weight: bold; color: rgb(102, 0, 0);"&gt;untuk menjaga keamanan jaringan adalah dengan  mendaftarkan mac-address wireless pasangan pada access list&lt;/span&gt;. &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Hal ini harus dilakukan  pada sisi access point maupun pada sisi client.&lt;/span&gt;&lt;span style="color: rgb(51, 0, 0); font-weight: bold;"&gt; &lt;span style="color: rgb(204, 51, 204);"&gt;Jika penginputan access-list telah  dilakukan, maka matikanlah fitur &lt;/span&gt;&lt;/span&gt;&lt;em style="color: rgb(204, 51, 204); font-weight: bold;"&gt;default authenticated &lt;/em&gt;&lt;span style="color: rgb(204, 51, 204); font-weight: bold;"&gt;pada wireless&lt;/span&gt;,&lt;span style="color: rgb(102, 51, 102); font-weight: bold;"&gt; maka wireless lain yang mac addressnya tidak terdaftar tidak akan  bisa terkoneksi ke jaringan kita.&lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(255, 0, 0);"&gt;Jika kita menginginkan fitur keamanan yang lebih baik, kita juga bisa menggunakan  enkripsi baik WEP maupun WPA.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518056064991556503-1051090576263546829?l=anaknagi.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anaknagi.blogspot.com/feeds/1051090576263546829/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518056064991556503&amp;postID=1051090576263546829&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/1051090576263546829'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/1051090576263546829'/><link rel='alternate' type='text/html' href='http://anaknagi.blogspot.com/2010/08/setting-mikrotik-wireless-bridge.html' title='Setting Mikrotik Wireless Bridge'/><author><name>Materi Jaringan</name><uri>http://www.blogger.com/profile/18432157139474714821</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_mq7TojsGMx0/THm0VD0tWoI/AAAAAAAAACw/c_xErIz7CTA/S220/IMG0270A.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518056064991556503.post-5267671863548084012</id><published>2010-08-29T00:14:00.003+08:00</published><updated>2010-08-29T00:24:25.386+08:00</updated><title type='text'>Queue dengan SRC-NAT dan WEB-PROXY</title><content type='html'>&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Pada penggunaan queue (bandwidth limiter),&lt;/span&gt; penentuan &lt;span style="color: rgb(102, 0, 0); font-weight: bold;"&gt;CHAIN&lt;/span&gt; pada &lt;span style="color: rgb(102, 0, 0); font-weight: bold;"&gt;MENGLE &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;sangat  menentukan jalannya sebuah rule&lt;/span&gt;. &lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;Jika kita memasang SRC-NAT&lt;/span&gt; dan &lt;span style="font-weight: bold; color: rgb(153, 102, 51);"&gt;WEB-PROXY&lt;/span&gt;&lt;span style="color: rgb(153, 0, 0); font-weight: bold;"&gt; pada  mesin yang sama&lt;/span&gt;, &lt;span style="font-weight: bold; color: rgb(51, 0, 153);"&gt;sering kali agak sulit untuk membuat rule QUEUE yang sempurna&lt;/span&gt;.&lt;br /&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-weight: bold; color: rgb(51, 0, 0);"&gt;Penjelasan detail mengenai pemilihan CHAIN, dapat dilihat pada manual Mikrotik  &lt;/span&gt;&lt;a style="font-weight: bold; color: rgb(51, 0, 0);" href="http://www.mikrotik.com/docs/ros/2.9/ip/flow"&gt;di sini&lt;/a&gt;&lt;span style="font-weight: bold; color: rgb(51, 0, 0);"&gt;.  &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Percobaan&lt;/span&gt; yang dilakukan menggunakan &lt;span style="font-weight: bold; color: rgb(0, 51, 51);"&gt;&lt;span style="color: rgb(255, 102, 0);"&gt;sebuah PC dengan Mikrotik RouterOS versi 2.9.28.&lt;/span&gt; &lt;/span&gt;Pada mesin tersebut, digunakan &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;2 buah interface&lt;/span&gt;, &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;satu untuk gateway&lt;/span&gt; yang dinamai &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;PUBLIC&lt;/span&gt;  dan satu lagi untuk &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;jaringan lokal yang dinamai LAN.   &lt;/span&gt;&lt;br /&gt; &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px; width: 680px; height: 159px;" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;&lt;span style="font-weight: bold;"&gt;[admin@instaler] &gt; in pr&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Flags: X - disabled, D - dynamic, R - running &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; #    NAME       TYPE    RX-RATE    TX-RATE    MTU  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; 0  R public     ether   0          0          1500 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; 1  R lan        wlan    0          0          1500&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;Dan berikut ini adalah IP Address yang digunakan. &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Subnet 192.168.0.0/24&lt;/span&gt; adalah subnet gateway untuk mesin ini. &lt;br /&gt; &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px; width: 680px; height: 119px;" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;&lt;span style="font-weight: bold;"&gt;[admin@instaler] &gt; ip ad pr&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Flags: X - disabled, I - invalid, D - dynamic &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; #  ADDRESS           NETWORK      BROADCAST      INTERFACE&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; 0  192.168.0.217/24  192.168.0.0  192.168.0.255  public   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; 1  172.21.1.1/24     172.21.1.0   172.21.1.255   lan&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;Fitur web-proxy dengan transparan juga diaktifkan.   &lt;/span&gt;&lt;br /&gt; &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px; font-weight: bold; width: 680px; height: 292px;" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt; [admin@instaler] &gt; ip web-proxy pr&lt;br /&gt;                enabled: yes&lt;br /&gt;            src-address: 0.0.0.0&lt;br /&gt;                   port: 3128&lt;br /&gt;               hostname: "proxy"&lt;br /&gt;      transparent-proxy: yes&lt;br /&gt;           parent-proxy: 0.0.0.0:0&lt;br /&gt;    cache-administrator: "webmaster"&lt;br /&gt;        max-object-size: 4096KiB&lt;br /&gt;            cache-drive: system&lt;br /&gt;         max-cache-size: none&lt;br /&gt;     max-ram-cache-size: unlimited&lt;br /&gt;                 status: running&lt;br /&gt;     reserved-for-cache: 0KiB&lt;br /&gt; reserved-for-ram-cache: 154624KiB&lt;br /&gt;&lt;/pre&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold; color: rgb(153, 51, 0);"&gt;Fungsi MASQUERADE diaktifkan, juga satu buah rule REDIRECTING untuk membelokkan traffic HTTP menuju ke WEB-PROXY  &lt;/span&gt;&lt;br /&gt; &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px; width: 680px; height: 153px;" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;&lt;span style="font-weight: bold;"&gt;[admin@instaler] ip firewall nat&gt; pr&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Flags: X - disabled, I - invalid, D - dynamic &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; 0   chain=srcnat out-interface=public &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     src-address=172.21.1.0/24 action=masquerade &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; 1   chain=dstnat in-interface=lan src-address=172.21.1.0/24 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     protocol=tcp dst-port=80 action=redirect to-ports=3128&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;Berikut ini adalah langkah terpenting dalam proses ini, yaitu pembuatan MANGLE.&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Kita akan membutuhkan 2 buah PACKET-MARK&lt;/span&gt;. &lt;span style="font-weight: bold; color: rgb(51, 51, 255);"&gt;Satu untuk paket data upstream&lt;/span&gt;,  yang pada contoh ini kita sebut &lt;b&gt;test-up&lt;/b&gt;. &lt;span style="color: rgb(51, 51, 255); font-weight: bold;"&gt;Dan satu lagi untuk paket data  downstream&lt;/span&gt;, yang pada contoh ini kita sebut &lt;b&gt;test-down&lt;/b&gt;.  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;Untuk paket data upstream, proses pembuatan manglenya cukup sederhana. Kita bisa langsung melakukannya dengan &lt;span style="font-weight: bold;"&gt;1 buah rule&lt;/span&gt;, cukup dengan menggunakan &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;parameter  SRC-ADDRESS&lt;/span&gt; dan &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;IN-INTERFACE&lt;/span&gt;. Di sini kita menggunakan chain &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;prerouting&lt;/span&gt;. Paket data untuk upstream ini kita namai &lt;b&gt;test-up&lt;/b&gt;.  &lt;/p&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(0, 0, 153);"&gt;Namun, untuk paket data downstream, kita membutuhkan beberapa buah rule. Karena kita menggunakan translasi IP/masquerade, kita membutuhkan Connection  Mark. Pada contoh ini, kita namai test-conn.  &lt;/p&gt;&lt;p style="text-align: justify; color: rgb(153, 0, 0); font-weight: bold;"&gt;Kemudian, kita harus membuat juga 2 buah rule.  Rule yang pertama, untuk paket data downstream non HTTP yang langsung dari  internet (tidak melewati proxy). Kita menggunakan chain forward, karena  data mengalir melalui router.  &lt;/p&gt;&lt;p style="text-align: justify; font-weight: bold; color: rgb(204, 0, 0);"&gt;Rule yang kedua, untuk paket data yang berasal dari WEB-PROXY. Kita menggunakan chain output, karena arus data berasal dari aplikasi internal di dalam  router ke mesin di luar router.  &lt;/p&gt;&lt;p style="text-align: justify; color: rgb(153, 0, 0); font-weight: bold;"&gt;Paket data untuk downstream pada kedua rule ini kita namai test-down.  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold; color: rgb(51, 0, 153);"&gt;Jangan lupa, parameter passthrough hanya diaktifkan untuk connection mark saja.  &lt;/span&gt;&lt;br /&gt; &lt;table style="width: 680px; height: 402px; text-align: left; margin-left: 0px; margin-right: 0px;" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;&lt;span style="font-weight: bold;"&gt;[admin@instaler] &gt; ip firewall mangle print&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Flags: X - disabled, I - invalid, D - dynamic &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; 0   ;;; UP TRAFFIC&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     chain=prerouting in-interface=lan &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     src-address=172.21.1.0/24 action=mark-packet &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     new-packet-mark=test-up passthrough=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; 1   ;;; CONN-MARK&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     chain=forward src-address=172.21.1.0/24 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     action=mark-connection &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     new-connection-mark=test-conn passthrough=yes &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; 2   ;;; DOWN-DIRECT CONNECTION&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     chain=forward in-interface=public &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     connection-mark=test-conn action=mark-packet &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     new-packet-mark=test-down passthrough=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; 3   ;;; DOWN-VIA PROXY&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     chain=output out-interface=lan &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     dst-address=172.21.1.0/24 action=mark-packet &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     new-packet-mark=test-down passthrough=no &lt;/span&gt;&lt;br /&gt;&lt;/pre&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold; color: rgb(0, 153, 0);"&gt;Untuk tahap terakhir, tinggal mengkonfigurasi queue. Di sini kita menggunakan queue tree. Satu buah rule untuk data dowstream, dan satu lagi untuk upstream. Yang penting di sini, adalah pemilihan parent. Untuk downstream, kita menggunakan parent &lt;/span&gt;&lt;b style="font-weight: bold; color: rgb(0, 153, 0);"&gt;lan&lt;/b&gt;&lt;span style="font-weight: bold; color: rgb(0, 153, 0);"&gt;, sesuai dengan interface yang mengarah ke jaringan lokal, dan untuk upstream, kita menggunakan parent &lt;/span&gt;&lt;b style="font-weight: bold; color: rgb(0, 153, 0);"&gt;global-in&lt;/b&gt;&lt;span style="font-weight: bold; color: rgb(0, 153, 0);"&gt;.  &lt;/span&gt;&lt;br /&gt; &lt;table style="width: 680px; height: 304px; text-align: left; margin-left: 0px; margin-right: 0px;" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;&lt;span style="font-weight: bold;"&gt;[admin@instaler] &gt; queue tree pr&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Flags: X - disabled, I - invalid &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; 0   name="downstream" parent=lan packet-mark=test-down &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     limit-at=32000 queue=default priority=8 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     max-limit=32000 burst-limit=0 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     burst-threshold=0 burst-time=0s &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; 1   name="upstream" parent=global-in &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     packet-mark=test-up limit-at=32000 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     queue=default priority=8 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     max-limit=32000 burst-limit=0 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     burst-threshold=0 burst-time=0s&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;  &lt;/p&gt;&lt;div style="text-align: justify; font-weight: bold; color: rgb(255, 0, 0);"&gt;&lt;br /&gt;Variasi lainnya, untuk bandwidth management, dimungkinkan juga kita menggunakan tipe queue PCQ, yang bisa secara otomatis membagi trafik  per client.   &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518056064991556503-5267671863548084012?l=anaknagi.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anaknagi.blogspot.com/feeds/5267671863548084012/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518056064991556503&amp;postID=5267671863548084012&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/5267671863548084012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/5267671863548084012'/><link rel='alternate' type='text/html' href='http://anaknagi.blogspot.com/2010/08/queue-dengan-src-nat-dan-web-proxy.html' title='Queue dengan SRC-NAT dan WEB-PROXY'/><author><name>Materi Jaringan</name><uri>http://www.blogger.com/profile/18432157139474714821</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_mq7TojsGMx0/THm0VD0tWoI/AAAAAAAAACw/c_xErIz7CTA/S220/IMG0270A.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518056064991556503.post-2225454116593328609</id><published>2010-08-28T23:30:00.004+08:00</published><updated>2010-08-28T23:47:54.726+08:00</updated><title type='text'>Simple Queue, Memisah Bandwidth Lokal dan Internasional</title><content type='html'>&lt;div style="text-align: justify;"&gt;Selama mengelola Mikrotik Indonesia, &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;banyak sekali muncul pertanyaan bagaimana  cara melakukan pemisahan queue untuk trafik internet internasional dan trafik  ke internet Indonesia (OpenIXP dan IIX).&lt;/span&gt; Di internet sebetulnya sudah ada beberapa  website yang menampilkan cara pemisahan ini, tapi kami akan coba menampilkan kembali  sesederhana mungkin supaya mudah diikuti. &lt;/div&gt;&lt;p style="font-weight: bold; color: rgb(255, 0, 0); text-align: justify;"&gt;Pada artikel ini, kami mengasumsikan bahwa: &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ol style="text-align: justify;"&gt;&lt;li style="font-weight: bold; color: rgb(0, 153, 0);"&gt;Router Mikrotik melakukan Masquerading / src-nat untuk client. Client menggunakan  IP privat.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold; color: rgb(204, 51, 204);"&gt;Gateway yang digunakan hanya satu, baik untuk trafik internasional maupun IIX.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold; color: rgb(0, 102, 0);"&gt;Anda bisa menggunakan web-proxy internal ataupun tanpa web-proxy. Jika Anda menggunakan web-proxy, maka ada beberapa tambahan rule yang perlu dilakukan. Perhatikan bagian  NAT  dan MANGLE pada contoh di bawah ini. &lt;/li&gt;&lt;/ol&gt;&lt;div style="text-align: justify;"&gt; Jika ada parameter di atas yang berbeda dengan kondisi Anda di lapangan, maka  konfigurasi yang ada di artikel ini harus Anda modifikasi sesuai dengan konfigurasi  network Anda.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Pengaturan Dasar &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Berikut ini adalah diagram network dan asumsi IP Address yang akan digunakan  dalam contoh ini.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mq7TojsGMx0/THksxax3R2I/AAAAAAAAACI/RMnx-C2AfHQ/s1600/iix-01.jpg"&gt;&lt;img style="cursor: pointer; width: 557px; height: 214px;" src="http://4.bp.blogspot.com/_mq7TojsGMx0/THksxax3R2I/AAAAAAAAACI/RMnx-C2AfHQ/s320/iix-01.jpg" alt="" id="BLOGGER_PHOTO_ID_5510484846578190178" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Untuk mempermudah pemberian contoh, kami mengupdate nama masing-masing interface  sesuai dengan tugasnya masing-masing. &lt;br /&gt;  &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" width="100%" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;[admin@MikroTik] &gt; /interface pr&lt;br /&gt;Flags: X - disabled, D - dynamic, R - running&lt;br /&gt;#    NAME            TYPE   RX-RATE  TX-RATE  MTU&lt;br /&gt;0  R ether-public     ether  0        0       1500&lt;br /&gt;1  R ether-local      ether  0        0       1500&lt;br /&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/p&gt; &lt;p&gt;Untuk klien, akan menggunakan &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;blok IP 192.168.0.0/24&lt;/span&gt;, dan&lt;span style="color: rgb(255, 0, 0);"&gt; &lt;span style="font-weight: bold;"&gt;IP Address 192.168.0.1 &lt;/span&gt;&lt;/span&gt; &lt;span style="color: rgb(0, 102, 0); font-weight: bold;"&gt;difungsikan sebagai gateway&lt;/span&gt; dan &lt;span style="font-weight: bold; color: rgb(153, 51, 0);"&gt;dipasang pada router, interface ether-local&lt;/span&gt;. &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Klien&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;  dapat menggunakan IP Address 192.168.0-2 hingga 192.168.0.254&lt;/span&gt; dengan subnet mask  &lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;255.255.255.0.  &lt;/span&gt;&lt;br /&gt;  &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" width="100%" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;[admin@MikroTik] &gt; /ip ad pr&lt;br /&gt;Flags: X - disabled, I - invalid, D - dynamic&lt;br /&gt;# ADDRESS         NETWORK     BROADCAST     INTERFACE&lt;br /&gt;0 202.0.0.1/24    202.0.0.0   202.0.0.255   ether-public  &lt;br /&gt;1 192.168.0.1/24  192.168.0.0 192.168.0.255 ether-local &lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Jangan lupa melakukan konfigurasi DNS server pada router, dan mengaktifkan fitur&lt;/span&gt;  "&lt;span style="font-weight: bold;"&gt;allow remote request&lt;/span&gt;". &lt;/p&gt; &lt;span style="font-weight: bold; color: rgb(51, 0, 153);"&gt;Karena klien menggunakan IP private, maka kita harus melakukan fungsi src-nat  seperti contoh berikut.  &lt;/span&gt;&lt;br /&gt;&lt;pre style="font-weight: bold; color: rgb(204, 0, 0);"&gt;[admin@MikroTik] &gt; /ip fi nat pr&lt;br /&gt;Flags: X - disabled, I - invalid, D - dynamic&lt;br /&gt;0   chain=srcnat out-interface=ether-public&lt;br /&gt;    action=masquerade&lt;/pre&gt; &lt;p&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;Jika Anda menggunakan web-proxy transparan&lt;/span&gt;, &lt;span style="font-weight: bold; color: rgb(51, 0, 51);"&gt;Anda perlu menambahkan rule nat redirect&lt;/span&gt;,  seperti terlihat pada contoh di bawah ini (rule tambahan yang tercetak tebal). &lt;br /&gt;  &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" width="100%" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;[admin@MikroTik] &gt; /ip fi nat pr&lt;br /&gt;Flags: X - disabled, I - invalid, D - dynamic&lt;br /&gt;0  chain=srcnat out-interface=ether-public&lt;br /&gt;  action=masquerade&lt;br /&gt;&lt;strong&gt;1  chain=dstnat in-interface=ether-local protocol=tcp&lt;br /&gt;  dst-port=80 action=redirect to-ports=8080&lt;/strong&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/p&gt; &lt;p style="font-weight: bold; color: rgb(153, 0, 0);"&gt;Jangan lupa mengaktifkan fitur web-proxy, dan men-set port layanan web-proxynya,  dan disesuaikan dengan port redirect pada contoh di atas. &lt;/p&gt; &lt;p style="font-weight: bold; color: rgb(0, 0, 102);"&gt;CEK: Pastikan semua konfigurasi telah berfungsi baik. Lakukanlah ping  (baik dari router maupun dari klien) ke luar network Anda secara bergantian.  &lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;Pengaturan IP Address List&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Mulai Mikrotik RouterOS versi 2.9, dikenal dengan fitur yang disebut &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;IP Address  List&lt;/span&gt;. Fitur ini adalah pengelompokan IP Address tertentu dan setiap IP Address tersebut  bisa kita namai. &lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;Kelompok ini bisa digunakan sebagai parameter dalam mangle, firewall filter, nat,  ataupun queue. &lt;/span&gt;&lt;/p&gt; &lt;p style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Mikrotik Indonesia telah menyediakan daftar IP Address yang diadvertise di OpenIXP  dan IIX,  yang bisa didownload dengan bebas di URL: &lt;a href="http://www.mikrotik.co.id/getfile.php?nf=nice.rsc" target="_blank"&gt;http://www.mikrotik.co.id/getfile.php?nf=nice.rsc&lt;/a&gt;&lt;/p&gt; &lt;p&gt;File nice.rsc ini dibuat secara otomatis di server Mikrotik Indonesia setiap  jam, dan merupakan data yang telah dioptimalkan untuk menghilangkan  duplikasi entri dan tumpang tindih subnet. Saat ini jumlah baris pada script tersebut  berkisar 7000 baris. &lt;/p&gt; &lt;p&gt;&lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;Contoh isi file nice.rsc :  &lt;/span&gt;&lt;br /&gt;  &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" width="100%" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;# Script created by: Valens Riyadi @ www.mikrotik.co.id&lt;br /&gt;# Generated at 26 April 2007 05:30:02 WIB ... 431 lines&lt;br /&gt;/ip firewall address-list&lt;br /&gt;add list=nice address="1.2.3.4"&lt;br /&gt;rem [find list=nice]&lt;br /&gt;add list=nice address="125.162.0.0/16"&lt;br /&gt;add list=nice address="125.163.0.0/16"&lt;br /&gt;add list=nice address="152.118.0.0/16"&lt;br /&gt;add list=nice address="125.160.0.0/16"&lt;br /&gt;add list=nice address="125.161.0.0/16"&lt;br /&gt;add list=nice address="125.164.0.0/16"&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;dst...&lt;br /&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/p&gt;  &lt;p&gt;Proses pengambilan file nice.rsc bisa dilakukan langsung dari terminal di RouterOS dengan perintah: &lt;br /&gt;  &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" width="100%" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;/tool fetch address=ixp.mikrotik.co.id src-path=/download/nice.rsc;&lt;br /&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/p&gt;   &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Kemudian, import-lah file tersebut.  &lt;/span&gt;&lt;br /&gt;  &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" width="100%" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;[admin@MikroTik] &gt; &lt;strong&gt;import nice.rsc&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Opening script file nice.rsc&lt;br /&gt;Script file loaded and executed successfully&lt;br /&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Pastikan bahwa proses import telah berlangsung dengan sukses, dengan mengecek  Address-List pada Menu IP - Firewall &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;img src="http://www.mikrotik.co.id/images/artikel/iix-02.jpg" alt="address list nice" title="address list nice" width="438" height="534" /&gt;&lt;/p&gt; &lt;p&gt;Proses upload ini dapat juga dilakukan secara otomatis jika Anda memiliki pengetahuan  scripting. &lt;span style="font-weight: bold; color: rgb(0, 51, 0);"&gt;Misalnya Anda membuat shell script pada Linux untuk melakukan download  secara otomatis dan mengupload file secara otomatis setiap pk 06.00 pagi. Kemudian  Anda tinggal membuat scheduler pada router untuk melakukan import file. &lt;/span&gt;&lt;/p&gt; &lt;p&gt;Jika Anda menggunakan &lt;span style="font-weight: bold; color: rgb(153, 0, 0);"&gt;RouterOS versi 3.x&lt;/span&gt;, proses update juga dapat dilakukan  secara otomatis.  &lt;/p&gt; &lt;p&gt;&lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Perintah yang perlu dibuat adalah :  &lt;/span&gt;&lt;br /&gt;  &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" width="100%" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; /system sched add comment=”update-nice” disabled=no interval=1d name=”update-nice-rsc” on-event=”:if ([:len [/file find name=nice.rsc]] &gt; 0) do={/file remove nice.rsc }; /tool fetch address=ixp.mikrotik.co.id src-path=/download/nice.rsc;/import nice.rsc” start-date=jan/01/1970 start-time=00:06:00&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Hati-hati!&lt;/span&gt; : &lt;span style="font-weight: bold; color: rgb(102, 0, 0);"&gt;Setelah copy paste, pastikan hasil copy paste sama persis. Proses  copy paste kadang-kadang menghilangkan beberapa karakter tertentu. &lt;/span&gt;&lt;br /&gt;&lt;/p&gt; &lt;p&gt;&lt;img src="http://www.mikrotik.co.id/images/line.gif" alt="" title="" width="438" height="18" /&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Pengaturan Mangle&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Langkah selanjutnya adalah &lt;span style="font-weight: bold; color: rgb(255, 102, 102);"&gt;membuat mangle&lt;/span&gt;. Kita perlu membuat &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;1 buah connection  mark&lt;/span&gt; dan &lt;span style="font-weight: bold; color: rgb(102, 0, 0);"&gt;2 buah packet mark&lt;/span&gt;, masing-masing untuk trafik &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;internasional&lt;/span&gt; dan&lt;span style="font-weight: bold; color: rgb(153, 0, 0);"&gt; lokal&lt;/span&gt;. &lt;br /&gt;  &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" width="100%" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;[admin@MikroTik] &gt; /ip firewall mangle pr&lt;br /&gt;Flags: X - disabled, I - invalid, D - dynamic&lt;br /&gt;&lt;br /&gt;0 chain=prerouting in-interface=ether-local&lt;br /&gt; dst-address-list=nice&lt;br /&gt; action=mark-connection new-connection-mark=conn-iix&lt;br /&gt; passthrough=yes&lt;br /&gt;&lt;br /&gt;1 chain=prerouting connection-mark=conn-iix&lt;br /&gt; action=mark-packet new-packet-mark=packet-iix&lt;br /&gt; passthrough=no&lt;br /&gt;&lt;br /&gt;2 chain=prerouting action=mark-packet&lt;br /&gt; new-packet-mark=packet-intl passthrough=no&lt;br /&gt; &lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/p&gt; &lt;p style="color: rgb(153, 51, 0); font-weight: bold;"&gt;Untuk rule #0, pastikanlah bahwa Anda memilih interface yang mengarah ke client. Untuk chain, kita menggunakan prerouting, dan untuk kedua packet-mark, kita menggunakan passthrough=no. &lt;/p&gt; &lt;p&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;Jika Anda menggunakan web-proxy internal dan melakukan redirecting trafic, maka Anda membuat 2 buah rule tambahan seperti contoh di bawah ini  (rule tambahan yang tercetak tebal).  &lt;/span&gt;&lt;br /&gt;  &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" width="100%" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;[admin@MikroTik] &gt; /ip firewall mangle pr&lt;br /&gt;Flags: X - disabled, I - invalid, D - dynamic&lt;br /&gt;&lt;br /&gt;0 chain=prerouting in-interface=ether-local&lt;br /&gt; dst-address-list=nice&lt;br /&gt; action=mark-connection new-connection-mark=conn-iix&lt;br /&gt; passthrough=yes&lt;br /&gt;&lt;br /&gt;1 chain=prerouting connection-mark=conn-iix&lt;br /&gt; action=mark-packet new-packet-mark=packet-iix&lt;br /&gt; passthrough=no&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;2 chain=output connection-mark=conn-iix&lt;br /&gt; action=mark-packet new-packet-mark=packet-iix&lt;br /&gt; passthrough=no&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;3 chain=prerouting action=mark-packet&lt;br /&gt; new-packet-mark=packet-intl passthrough=no&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;4 chain=output action=mark-packet&lt;br /&gt; new-packet-mark=packet-intl passthrough=no&lt;br /&gt;&lt;/strong&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/p&gt; &lt;p&gt;&lt;img src="http://www.mikrotik.co.id/images/line.gif" alt="" title="" width="438" height="18" /&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Pengaturan Simple Queue&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-weight: bold; color: rgb(153, 0, 0);"&gt;Untuk setiap client,&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 102);"&gt; kita harus membuat 2 buah rule simple queue.&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Pada contoh berikut ini, kita akan melakukan limitasi untuk IP client 192.168.0.2/32, dan kita akan memberikan limitasi iix (up/down) sebesar 64k/256k, dan untuk internasional  sebesar (up/down) 32k/128k. &lt;br /&gt;  &lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" width="100%" border="0" cellpadding="3" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ffffcc"&gt; &lt;pre&gt;[admin@MikroTik]&gt; /queue simple pr&lt;br /&gt;Flags: X - disabled, I - invalid, D - dynamic&lt;br /&gt;0 name="client02-iix" target-addresses=192.168.0.2/32&lt;br /&gt; dst-address=0.0.0.0/0 interface=all parent=none&lt;br /&gt; packet-marks=packet-iix direction=both priority=8&lt;br /&gt; queue=default-small/default-small limit-at=0/0&lt;br /&gt; max-limit=64000/256000 total-queue=default-small&lt;br /&gt;&lt;br /&gt;1 name="client02-intl" target-addresses=192.168.0.2/32&lt;br /&gt; dst-address=0.0.0.0/0 interface=all parent=none&lt;br /&gt; packet-marks=packet-intl direction=both priority=8&lt;br /&gt; queue=default-small/default-small limit-at=0/0&lt;br /&gt; max-limit=32000/128000 total-queue=default-small&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/p&gt; &lt;p&gt;&lt;img src="http://www.mikrotik.co.id/images/artikel/iix-03.jpg" alt="simple queue" title="simple queue" width="438" height="345" /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p style="font-weight: bold; color: rgb(153, 0, 0);"&gt;&lt;strong&gt;Pengecekan Akhir&lt;/strong&gt;&lt;/p&gt; &lt;p style="font-weight: bold; color: rgb(153, 0, 0);"&gt;Setelah selesai, lakukanlah pengecekan dengan melakukan akses ke situs lokal  maupun ke situs internasional,  dan perhatikanlah counter baik pada firewall mangle maupun pada simple queue. &lt;/p&gt; &lt;p style="font-weight: bold; color: rgb(153, 0, 0);"&gt;Anda juga dapat mengembangkan queue type menggunakan pcq sehingga trafik pada  setiap client dapat tersebar secara merata. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518056064991556503-2225454116593328609?l=anaknagi.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anaknagi.blogspot.com/feeds/2225454116593328609/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518056064991556503&amp;postID=2225454116593328609&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/2225454116593328609'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/2225454116593328609'/><link rel='alternate' type='text/html' href='http://anaknagi.blogspot.com/2010/08/simple-queue-memisah-bandwidth-lokal.html' title='Simple Queue, Memisah Bandwidth Lokal dan Internasional'/><author><name>Materi Jaringan</name><uri>http://www.blogger.com/profile/18432157139474714821</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_mq7TojsGMx0/THm0VD0tWoI/AAAAAAAAACw/c_xErIz7CTA/S220/IMG0270A.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_mq7TojsGMx0/THksxax3R2I/AAAAAAAAACI/RMnx-C2AfHQ/s72-c/iix-01.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518056064991556503.post-4615606868860625606</id><published>2010-08-28T22:39:00.008+08:00</published><updated>2010-08-29T00:26:24.112+08:00</updated><title type='text'>Load Balance menggunakan Metode PCC</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-family:arial;"&gt;&lt;span style="font-weight: bold;"&gt;Load balance pada mikrotik adalah&lt;/span&gt; teknik untuk mendistribusikan beban trafik pada dua atau lebih jalur koneksi secara seimbang, agar trafik dapat berjalan optimal, memaksimalkan throughput, memperkecil waktu tanggap dan menghindari overload pada salah satu jalur koneksi.&lt;/span&gt;  &lt;span style="font-family:arial;"&gt;Selama ini banyak dari kita yang beranggapan salah, bahwa dengan menggunakan loadbalance dua jalur koneksi , maka besar bandwidth yang akan kita dapatkan menjadi dua kali lipat dari bandwidth sebelum menggunakan loadbalance (&lt;span style="font-weight: bold; font-style: italic;"&gt;akumulasi dari kedua bandwidth tersebu&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;t&lt;/span&gt;).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Hal ini perlu kita perjelas dahulu, bahwa loadbalance tidak akan menambah besar bandwidth yang kita peroleh, tetapi hanya bertugas untuk membagi trafik dari kedua bandwidth tersebut agar dapat terpakai secara seimbang.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 51, 0);"&gt; &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(102, 51, 0);font-family:arial;" &gt;Dengan artikel ini, kita akan membuktikan bahwa dalam penggunaan loadbalancing tidak seperti rumus matematika 512 + 256 = 768, akan tetapi 512 + 256 = 512 + 256, atau 512 + 256 = 256 + 256 + 256.&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(102, 51, 0);"&gt;  &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(102, 51, 0);font-family:arial;" &gt;Pada artikel ini kami menggunakan RB433UAH dengan kondisi sebagai berikut :&lt;/span&gt;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;ol style="text-align: justify; color: rgb(255, 102, 0); font-weight: bold;"&gt;&lt;li style="color: rgb(255, 0, 0);"&gt;&lt;span style="font-family:arial;"&gt;Ether1 dan Ether2 terhubung pada ISP yang berbeda dengan besar bandwdith yang berbeda. ISP1 sebesar 512kbps dan ISP2 sebesar 256kbps.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:arial;"&gt; &lt;span style="color: rgb(0, 153, 0);"&gt;Kita akan menggunakan w&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 153, 0);font-family:arial;" &gt;eb-proxy internal dan menggunakan openDNS.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:arial;"&gt; &lt;span style="color: rgb(204, 51, 204);"&gt;Mikrotik RouterOS anda menggunakan versi 4.5  karena fitur PCC mulai dikenal pada versi 3.24.&lt;/span&gt;&lt;/span&gt; &lt;/li&gt;&lt;/ol&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family:arial;"&gt;Jika pada kondisi diatas berbeda dengan kondisi jaringan ditempat anda, maka konfigurasi yang akan kita jabarkan disini harus anda sesuaikan dengan konfigurasi untuk jaringan ditempat anda. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Konfigurasi Dasar &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Berikut ini adalah Topologi Jaringan dan IP address yang akan kita gunakan&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_mq7TojsGMx0/THkhVfMgd9I/AAAAAAAAABw/TAj8Ti2lduo/s1600/LoadBalance.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 182px;" src="http://1.bp.blogspot.com/_mq7TojsGMx0/THkhVfMgd9I/AAAAAAAAABw/TAj8Ti2lduo/s320/LoadBalance.png" alt="" id="BLOGGER_PHOTO_ID_5510472272099440594" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;span style="color: rgb(204, 51, 204); font-weight: bold;"&gt;/ip address&lt;/span&gt; &lt;span style="color: rgb(204, 51, 204); font-weight: bold;"&gt;add address=192.168.101.2/30 interface=ether1&lt;/span&gt; &lt;span style="color: rgb(204, 51, 204); font-weight: bold;"&gt;add address=192.168.102.2/30 interface=ether2&lt;/span&gt; &lt;span style="color: rgb(204, 51, 204); font-weight: bold;"&gt;add address=10.10.10.1/24 interface=wlan2&lt;/span&gt; &lt;span style="color: rgb(204, 51, 204); font-weight: bold;"&gt;/ip dns&lt;/span&gt; &lt;span style="color: rgb(204, 51, 204); font-weight: bold;"&gt;set allow-remote-requests=yes primary-dns=208.67.222.222 secondary-dns=208.67.220.220 &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Untuk &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;koneksi client, kita menggunakan koneksi wireless pada wlan2  dengan range IP client 10.10.10.2 s/d 10.10.10.254 netmask  255.255.255.0&lt;/span&gt;, dimana IP 10.10.10.1 yang dipasangkan pada&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;&lt;span style="color: rgb(51, 51, 255); font-style: italic; font-weight: bold;"&gt;wlan2  berfungsi sebagai gateway dan dns server dari client&lt;/span&gt;&lt;span style="font-style: italic;"&gt;.&lt;/span&gt; Jika anda  menggunakan DNS dari salah satu isp anda, maka akan ada tambahan mangle  yang akan kami berikan tanda tebal   &lt;/span&gt;       &lt;span style="font-family:arial;"&gt; &lt;span style="color: rgb(153, 102, 51); font-weight: bold; font-style: italic;"&gt;Setelah pengkonfigurasian IP dan DNS sudah benar, kita harus memasangkan  default route ke masing-masing IP gateway ISP kita agar router  meneruskan semua trafik yang tidak terhubung padanya ke gateway  tersebut.&lt;/span&gt; Disini kita menggunakan fitur check-gateway berguna jika salah  satu gateway kita putus, maka koneksi akan dibelokkan ke gateway  lainnya.  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 102, 102);"&gt;/ip route&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 102, 102);"&gt;add dst-address=0.0.0.0/0 gateway=192.168.101.1 distance=1 check-gateway=ping&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 102, 102);"&gt;add dst-address=0.0.0.0/0 gateway=192.168.102.1 distance=2 check-gateway=ping &lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Untuk pengaturan Access Point sehingga PC client dapat terhubung dengan wireless kita, kita menggunakan perintah&lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;/interface wireless&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;set wlan2 mode=ap-bridge band=2.4ghz-b/g ssid=Mikrotik disabled=no&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;Agar pc client dapat melakukan koneksi ke internet, kita juga harus merubah IP privat client ke IP publik yang ada di interface publik kita yaitu ether1 dan ether2.&lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;/ip firewall nat&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;add action=masquerade chain=srcnat out-interface=ether1&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;add action=masquerade chain=srcnat out-interface=ether2&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Sampai langkah ini, router dan pc client sudah dapat melakukan koneksi internet. Lakukan ping baik dari router ataupun pc client ke internet. Jika belum berhasil, cek sekali lagi konfigurasi anda.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Webproxy Internal&lt;/span&gt;&lt;br /&gt;Pada routerboard tertentu, seperti &lt;span style="color: rgb(255, 102, 102);"&gt;RB450G&lt;/span&gt;, &lt;span style="color: rgb(153, 0, 0);"&gt;RB433AH&lt;/span&gt;, &lt;span style="color: rgb(153, 153, 0);"&gt;RB433UAH&lt;/span&gt;, &lt;span style="color: rgb(255, 0, 0);"&gt;RB800&lt;/span&gt; dan &lt;span style="color: rgb(204, 51, 204);"&gt;RB1100 &lt;span style="font-weight: bold;"&gt;mempunyai&lt;/span&gt;&lt;/span&gt; &lt;span style="font-style: italic; color: rgb(255, 0, 0);"&gt;expansion slot (USB, MicroSD, CompactFlash)&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 102, 102);"&gt;untuk storage tambahan&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Pada contoh berikut, kita akan menggunakan usb flashdisk yang dipasangkan pada slot USB. Untuk pertama kali pemasangan, storage tambahan ini akan terbaca statusnya invalid di &lt;span style="font-weight: bold;"&gt;/system store&lt;/span&gt;. Agar dapat digunakan sebagai media penyimpan cache, maka storage harus diformat dahulu dan diaktifkan Nantinya kita tinggal m&lt;span style="color: rgb(255, 0, 0);"&gt;engaktifkan webproxy&lt;/span&gt; dan &lt;span style="color: rgb(204, 0, 0);"&gt;set cache-on-disk=yes&lt;/span&gt; untuk menggunakan media storage kita. &lt;span style="color: rgb(204, 0, 0);"&gt;Jangan lupa untuk membelokkan trafik HTTP (tcp port 80) kedalam webproxy kita.&lt;br /&gt;&lt;/span&gt;------------------------------------------------------------------------------------------------- &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;/store disk format-drive usb1&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 102, 0); font-weight: bold;"&gt;/store&lt;/span&gt; &lt;span style="color: rgb(0, 102, 0); font-weight: bold;"&gt;add disk=usb1 name=cache-usb type=web-proxy&lt;/span&gt; &lt;span style="color: rgb(0, 102, 0); font-weight: bold;"&gt;activate cache-usb&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51); font-weight: bold;"&gt;/ip proxy&lt;/span&gt; &lt;span style="color: rgb(51, 255, 51); font-weight: bold;"&gt;set cache-on-disk=yes enabled=yes max-cache-size=200000KiB port=8080&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 153, 51); font-weight: bold;"&gt;/ip firewall nat&lt;/span&gt; &lt;span style="color: rgb(204, 153, 51); font-weight: bold;"&gt;add chain=dstnat protocol=tcp dst-port=80 in-interface=wlan2 action=redirect to-ports=8080 &lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Pengaturan Mangle&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Pada loadbalancing kali ini kita akan menggunakan fitur yang disebut PCC (Per Connection Classifier)&lt;/span&gt;.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="color: rgb(102, 51, 255);"&gt;Dengan PCC kita bisa mengelompokan trafik koneksi yang melalui atau keluar masuk router menjadi beberapa kelompok&lt;/span&gt;. &lt;span style="color: rgb(204, 102, 0);"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(204, 102, 0);"&gt;Pengelompokan ini bisa dibedakan berdasarkan src-address, dst-address, src-port dan atau dst-port&lt;/span&gt;.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Router akan mengingat-ingat jalur gateway yang dilewati diawal trafik koneksi, sehingga pada paket-paket selanjutnya yang masih berkaitan dengan koneksi awalnya akan dilewatkan  pada jalur gateway yang sama juga.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Kelebihan dari PCC ini yang menjawab banyaknya keluhan sering putusnya koneksi pada teknik loadbalancing lainnya sebelum adanya PCC karena perpindahan gateway..&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 102, 0); font-weight: bold;"&gt;Sebelum membuat mangle loadbalance, untuk mencegah terjadinya loop routing pada trafik, maka semua trafik client yang menuju network yang terhubung langsung dengan router, &lt;span style="color: rgb(255, 0, 0);"&gt;harus kita bypass dari loadbalancing&lt;/span&gt;. Kita bisa membuat daftar IP yang masih dalam satu network router dan  memasang mangle pertama kali sebagai berikut&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;/ip firewall address-list&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;add address=192.168.101.0/30 list=lokal&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;add address=192.168.102.0/30 list=lokal&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;add address=10.10.10.0/24 list=lokal&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(153, 153, 0);"&gt;/ip firewall mangle&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(153, 153, 0);"&gt;add action=accept chain=prerouting dst-address-list=lokal in-interface=wlan2 comment=”trafik lokal”&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(153, 153, 0);"&gt;add action=accept chain=output dst-address-list=lokal&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Pada kasus tertentu, trafik pertama bisa berasal dari Internet, seperti &lt;span style="color: rgb(255, 153, 0);"&gt;penggunaan remote winbox atau telnet dari internet dan sebagainya&lt;/span&gt;, oleh &lt;span style="color: rgb(255, 0, 0);"&gt;karena itu kita juga memerlukan mark-connection untuk menandai trafik&lt;/span&gt; tersebut agar trafik baliknya juga bisa melewati interface dimana trafik itu masuk&lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;/ip firewall mangle&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;add action=mark-connection chain=prerouting connection-mark=no-mark in-interface=ether1 new-connection-mark=con-from-isp1 passthrough=yes comment=”trafik dari isp1”&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;add action=mark-connection chain=prerouting connection-mark=no-mark in-interface=ether2 new-connection-mark=con-from-isp2 passthrough=yes comment=”trafik dari isp2”&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="color: rgb(102, 0, 204);"&gt;Umumnya, sebuah ISP akan membatasi akses DNS servernya dari IP yang hanya dikenalnya, jadi jika anda menggunakan DNS dari salah satu ISP anda, anda harus menambahkan mangle agar trafik DNS tersebut melalui gateway ISP yang bersangkutan bukan melalui gateway ISP lainnya. Disini kami berikan mangle DNS ISP1 yang melalui gateway ISP1. Jika anda menggunakan publik DNS independent, seperti opendns, anda tidak memerlukan mangle dibawah ini.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;/ip firewall mangle&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;add action=mark-connection chain=output comment=dns dst-address=202.65.112.21 dst-port=53 new-connection-mark=dns passthrough=yes protocol=tcp comment=”trafik DNS citra.net.id”&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;add action=mark-connection chain=output dst-address=202.65.112.21 dst-port=53 new-connection-mark=dns passthrough=yes protocol=udp&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;add action=mark-routing chain=output connection-mark=dns new-routing-mark=route-to-isp1 passthrough=no&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;Karena kita menggunakan webproxy pada router, maka trafik yang perlu kita loadbalance ada 2 jenis:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;Yang pertama adalah trafik dari client menuju internet (non HTTP), dan trafik dari webproxy menuju internet. Agar lebih terstruktur dan mudah dalam pembacaannya, kita akan menggunakan custom-chain sebagai berikut :&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;/ip firewall mangle&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;add action=jump chain=prerouting comment=”lompat ke client-lb” connection-mark=no-mark in-interface=wlan2 jump-target=client-lb&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;add action=jump chain=output comment=”lompat ke lb-proxy” connection-mark=no-mark out-interface=!wlan2 jump-target=lb-proxy&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0); font-style: italic;"&gt;Pada mangle diatas&lt;/span&gt;, untuk trafik loadbalance client pastikan &lt;span style="color: rgb(255, 102, 0);"&gt;p&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 0);"&gt;&lt;span style="color: rgb(255, 102, 0);"&gt;arameter in-interface adalah interface yang terhubung dengan clien&lt;/span&gt;t&lt;/span&gt;, dan &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;untuk trafik loadbalance webproxy, kita menggunakan chain output dengan parameter out-interface yang bukan terhubung ke interface client.&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(153, 51, 153);"&gt;Setelah custom chain untuk loadbalancing dibuat, kita bisa membuat mangle di custom chain tersebut sebagai berikut&lt;/span&gt;:&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;/ip firewall mangle&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;add action=mark-connection chain=client-lb dst-address-type=!local new-connection-mark=to-isp1 passthrough=yes per-connection-classifier=both-addresses:3/0 comment=”awal loadbalancing klien”&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;add action=mark-connection chain=client-lb dst-address-type=!local new-connection-mark=to-isp1 passthrough=yes per-connection-classifier=both-addresses:3/1&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;add action=mark-connection chain=client-lb dst-address-type=!local new-connection-mark=to-isp2 passthrough=yes per-connection-classifier=both-addresses:3/2&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;add action=return chain=client-lb comment=”akhir dari loadbalancing”&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;/ip firewall mangle&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;add action=mark-connection chain=lb-proxy dst-address-type=!local new-connection-mark=con-from-isp1 passthrough=yes per-connection-classifier=both-addresses:3/0 comment=”awal load balancing proxy”&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;add action=mark-connection chain=lb-proxy dst-address-type=!local new-connection-mark=con-from-isp1 passthrough=yes per-connection-classifier=both-addresses:3/1&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;add action=mark-connection chain=lb-proxy dst-address-type=!local new-connection-mark=con-from-isp2 passthrough=yes per-connection-classifier=both-addresses:3/2&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;add action=return chain=lb-proxy comment=”akhir dari loadbalancing”&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Untuk contoh diatas, pada loadbalancing client dan webproxy &lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;menggunakan parameter pemisahan trafik pcc yang sama&lt;/span&gt;, &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;yaitu both-address,&lt;/span&gt; sehingga router akan mengingat-ingat berdasarkan src-address dan dst-address dari sebuah koneksi. &lt;span style="font-weight: bold; color: rgb(153, 0, 0);"&gt;Karena trafik ISP kita yang berbeda (512kbps dan 256kbps), kita membagi beban trafiknya menjadi 3 bagian. &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 255);"&gt;2 bagian pertama akan melewati gateway ISP1&lt;/span&gt;, &lt;span style="color: rgb(255, 102, 0); font-weight: bold;"&gt;dan 1 bagian terakhir akan melewati gateway ISP2&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Jika masing-masing trafik dari client dan proxy sudah ditandai, langkah berikutnya kita tinggal membuat mangle mark-route yang akan digunakan dalam proses routing nantinya:&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 0);"&gt;/ip firewall mangle&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 51, 0);"&gt;add action=jump chain=prerouting comment=”marking route client” connection-mark=!no-mark in-interface=wlan2 jump-target=route-client&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 51, 0);"&gt;add action=mark-routing chain=route-client connection-mark=to-isp1 new-routing-mark=route-to-isp1 passthrough=no&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 51, 0);"&gt;add action=mark-routing chain=route-client connection-mark=to-isp2 new-routing-mark=route-to-isp2 passthrough=no&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 51, 0);"&gt;add action=mark-routing chain=route-client connection-mark=con-from-isp1 new-routing-mark=route-to-isp1 passthrough=no&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 51, 0);"&gt;add action=mark-routing chain=route-client connection-mark=con-from-isp2 new-routing-mark=route-to-isp2 passthrough=no&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(51, 51, 0);"&gt;add action=return chain=route-client disabled=no&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(153, 153, 0);"&gt;/ip firewall mangle&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(153, 153, 0);"&gt;add action=mark-routing chain=output comment=”marking route proxy” connection-mark=con-from-isp1 new-routing-mark=route-to-isp1 out-interface=!wlan2 passthrough=no&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(153, 153, 0);"&gt;add action=mark-routing chain=output connection-mark=con-from-isp2 new-routing-mark=route-to-isp2 out-interface=!wlan2 passthrough=no&lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Pengaturan Routing&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Pengaturan mangle diatas tidak akan berguna jika anda belum membuat routing berdasar mark-route yang sudah kita buat. Disini kita juga akan membuat routing backup, sehingga apabila sebuah gateway terputus, maka semua koneksi akan melewati gateway yang masing terhubung&lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;/ip route&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;add check-gateway=ping dst-address=0.0.0.0/0 gateway=192.168.101.1 routing-mark=route-to-isp1 distance=1&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;add check-gateway=ping dst-address=0.0.0.0/0 gateway=192.168.102.1 routing-mark=route-to-isp1 distance=2&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;add check-gateway=ping dst-address=0.0.0.0/0 gateway=192.168.102.1 routing-mark=route-to-isp2 distance=1&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;add check-gateway=ping dst-address=0.0.0.0/0 gateway=192.168.101.1 routing-mark=route-to-isp2 distance=2 &lt;/span&gt;&lt;br /&gt;-------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Pengujian&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Dari hasil pengujian kami, didapatkan sebagai berikut :&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mq7TojsGMx0/THkprTZDxzI/AAAAAAAAACA/GemiG0xUXtc/s1600/LoadBalance-test.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 455px; height: 293px;" src="http://4.bp.blogspot.com/_mq7TojsGMx0/THkprTZDxzI/AAAAAAAAACA/GemiG0xUXtc/s320/LoadBalance-test.jpg" alt="" id="BLOGGER_PHOTO_ID_5510481442981005106" border="0" /&gt;&lt;/a&gt;Dari gambar terlihat, bahwa &lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt;hanya dengan melakukan 1 file download (1  koneksi), kita hanya mendapatkan speed 56kBps (448kbps)&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;karena pada  saat itu melewati gateway ISP1&lt;/span&gt;, sedangkan &lt;span style="font-weight: bold; color: rgb(102, 0, 204);"&gt;jika kita mendownload file  (membuka koneksi baru) lagi pada web lain, akan mendapatkan 30kBps  (240kbps)&lt;/span&gt;. Dari pengujian ini terlihat dapat disimpulkan bahwa:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;512kbps + 256kbps ≠ 768kbps&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;Catatan :&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt; Loadbalancing menggunakan teknik pcc ini akan berjalan efektif dan mendekati seimbang jika semakin banyak koneksi (dari client) yang terjadi.&lt;/li&gt;&lt;li&gt;Gunakan ISP yang memiliki bandwith FIX bukan Share untuk mendapatkan hasil yang lebih optimal.&lt;/li&gt;&lt;li&gt;Load Balance menggunakan PCC ini bukan selamanya dan sepenuhnya sebuah solusi yang pasti berhasil baik di semua jenis network, karena proses penyeimbangan dari traffic adalah berdasarkan logika probabilitas.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518056064991556503-4615606868860625606?l=anaknagi.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anaknagi.blogspot.com/feeds/4615606868860625606/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518056064991556503&amp;postID=4615606868860625606&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/4615606868860625606'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518056064991556503/posts/default/4615606868860625606'/><link rel='alternate' type='text/html' href='http://anaknagi.blogspot.com/2010/08/load-balance-menggunakan-metode-pcc.html' title='Load Balance menggunakan Metode PCC'/><author><name>Materi Jaringan</name><uri>http://www.blogger.com/profile/18432157139474714821</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_mq7TojsGMx0/THm0VD0tWoI/AAAAAAAAACw/c_xErIz7CTA/S220/IMG0270A.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mq7TojsGMx0/THkhVfMgd9I/AAAAAAAAABw/TAj8Ti2lduo/s72-c/LoadBalance.png' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
