Setting Mikrotik GW

10 Juli 2010

Mikrotik

Modem/Internet : 192.168.1.1 (gateway)

Mikrotik : 192.168.1.2 (ether1/internet)

Mikrotik : 192.168.0.1 (ether2/local)

Ada 10 client ip mulai : 192.168.100 – 192.168.110

Ganti nama admin@mikrotik jadi admin@zaeni

[admin@mikrotik]>  system identity set

Ganti nama interface ether1 jadi internet

[admin@zaeni]>  interface set ether1

[admin@zaeni]>  interface set ether2

[admin@zaeni] > interface print

Flags: X – disabled, D – dynamic, R – running

#    NAME                          TYPE             RX-RATE    TX-RATE    MTU

0  R internet                         ether                   0                        0          1500

1  R local                                ether                   0                                 0          1500

Memberi ip address

[admin@zaeni] > ip address add address=192.168.1.2/24 interface=internet

[admin@zaeni] > ip address add address=192.168.0.1/24 interface=local

[admin@zaeni] > ip address print

Flags: X – disabled, I – invalid, D – dynamic

#   ADDRESS            NETWORK         BROADCAST       INTERFACE

0   192.168.0.1/24     192.168.0.0     192.168.0.255   local

1   192.168.1.2/24     192.168.1.0     192.168.1.255   internet

Memberi ip gateway

[admin@zaeni] > ip route add gateway=192.168.1.1

[admin@zaeni] > ip route print

Flags: X – disabled, A – active, D – dynamic,

C – connect, S – static, r – rip, b – bgp, o – ospf

#     DST-ADDRESS        PREF-SRC      G GATEWAY       DISTANCE INTERFACE

0 ADC 192.168.0.0/24     192.168.0.1                                                                 lan

1 ADC 192.168.1.0/24     192.168.1.2                                                                 internet

2 A S 0.0.0.0/0                                            r 192.168.1.1                                    internet

Memberi NAT Masquerade

[admin@zaeni] > ip firewall nat add chain=srcnat out-interface=internet action=masquerade

[admin@zaeni] > ip firewall nat add chain=dstnat src-address=192.168.0.0/24 in-interface=lan action=redirect dst-port=80 protocol=tcp

[admin@zaeni] > ip firewall nat print

Flags: X – disabled, I – invalid, D – dynamic

0   chain=srcnat out-interface=internet action=masquerade

1        chain=dstnat in-interface=lan src-address=192.168.0.0/24 protocol=tcp dst-port=80

action=redirect to-ports=8080

Memberi Ip à Proxy

[admin@zaeni] > ip proxy set enabled=yes port=8080 parent-proxy=0.0.0.0 maximal-client-connecions=1000 maximal-server-connectons=1000

[admin@zaeni] > ip proxy print

enabled: yes

port: 8080

parent-proxy: 0.0.0.0:1

maximal-client-connecions: 1000

maximal-server-connectons: 1000

Memberi Ip Web Proxy

[admin@zaeni] > ip web-proxy set enabled=yes src-address=0.0.0.0 hostname=proxy.zaeni port=8080 transparent-proxy=yes parent-proxy=0.0.0.0 cache-adminis

trator=zaeni@gmail.com max-object-size=4096 cache-drive=system  max-cache-size=unlimited max-ram-cache-size=unlimited

[admin@zaeni] > ip proxy print

enabled: yes

port: 8080

parent-proxy: 0.0.0.0:1

maximal-client-connecions: 1000

maximal-server-connectons: 1000

[admin@zaeni] > ip web-proxy set

cache-administrator  enabled   max-cache-size   max-ram-cache-size  port         transparent-proxy

cache-drive          hostname  max-object-size  parent-proxy        src-address

[admin@zaeni] > ip web-proxy print

enabled: yes

src-address: 0.0.0.0

port: 8080

hostname: “proxy.zaeni”

transparent-proxy: yes

parent-proxy: 0.0.0.0:8080

cache-administrator: “zaeni”

max-object-size: 4096KiB

cache-drive: system

max-cache-size: unlimited

max-ram-cache-size: unlimited

status: running

reserved-for-cache: 3636224KiB

reserved-for-ram-cache: 2048KiB

— [Q quit|D dump]

Membatasi kecepatan dengan queue

[admin@zaeni] > queue simple add target-addresses=192.168.0.101 max-limit=6400/512000

[admin@zaeni] > queue simple print

Flags: X – disabled, I – invalid, D – dynamic

0    name=”komp1″ target-addresses=192.168.0.101/32 dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8

queue=default-small/default-small limit-at=0/0 max-limit=64000/512000 total-queue=default-small

1    name=”komp2″ target-addresses=192.168.0.102/32 dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8

queue=default-small/default-small limit-at=0/0 max-limit=64000/512000 total-queue=default-small

2    name=”komp3″ target-addresses=192.168.0.103/32 dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8

queue=default-small/default-small limit-at=0/0 max-limit=64000/512000 total-queue=default-small

3    name=”komp4″ target-addresses=192.168.0.104/32 dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8

queue=default-small/default-small limit-at=0/0 max-limit=64000/512000 total-queue=default-small

4    name=”komp5″ target-addresses=192.168.0.114/32 dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8

queue=default-small/default-small limit-at=0/0 max-limit=64000/512000 total-queue=default-small

5    name=”komp6″ target-addresses=192.168.0.106/32 dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8

queue=default-small/default-small limit-at=0/0 max-limit=64000/512000 total-queue=default-small

6    name=”komp7″ target-addresses=192.168.0.107/32 dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8

queue=default-small/default-small limit-at=0/0 max-limit=64000/512000 total-queue=default-small

7    name=”komp8″ target-addresses=192.168.0.108/32 dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8

queue=default-small/default-small limit-at=0/0 max-limit=64000/512000 total-queue=default-small

8    name=”komp9″ target-addresses=192.168.0.109/32 dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8

queue=default-small/default-small limit-at=0/0 max-limit=64000/512000 total-queue=default-small

9    name=”komp10″ target-addresses=192.168.0.110/32 dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8

— [Q quit|D dump|down]

Selesai sudah setting mikrotik 10 juli 2010