This is featured post 1 title
Replace these every slider sentences with your featured post descriptions.Go to Blogger edit html and find these sentences.Now replace these with your own descriptions.This theme is Bloggerized by Lasantha - Premiumbloggertemplates.com.
This is featured post 2 title
Replace these every slider sentences with your featured post descriptions.Go to Blogger edit html and find these sentences.Now replace these with your own descriptions.This theme is Bloggerized by Lasantha - Premiumbloggertemplates.com.
This is featured post 3 title
Replace these every slider sentences with your featured post descriptions.Go to Blogger edit html and find these sentences.Now replace these with your own descriptions.This theme is Bloggerized by Lasantha - Premiumbloggertemplates.com.
Selasa, 19 Februari 2013
Teknik Wireless Security
Teknik Wireless Security
A.
Menyembunyikan
SSID
1. Buka
winbox, pilih menu interface lalu doble klik wlan yang dimaksut
2. Pilih
tab wireless lalu centang opsi “hide SSID”
B.
Mac
Filtering
1. Buka
winbox pilih menu wireless
2. Pilih
tab access list
3. Klik
tanda + (add)
4. Tulis
mac address yang mau didaftarkan
5. Setelah
itu pilih menu interface
6. Doble
klik wlan yang dijadikan AP
7. Pilih
tab wireless lalu hilangkan centang pada opsi “default authenticate”
C.
IP
Filtering
1. Buka
winbox pilih menu IP kemudian firewall pilih tab address list
2. Klik
tanda add lalu beri nama group dan tulis IP address yang mau didaftarkan
3. Setelah
itu pilih tab NAT lalu doble klik NAT Rule yang dimaksut
4. Pada
tab general kosongkan Src. Address list dengan nama group yang dibuat tadi
D.
ARP
Filtering
1. Buka
winbox pilih menu IP kemudian ARP
2. Klik
tanda add (+)
3. Tulis
IP dan Mac Address yang mau didaftarkan lalu set interface yang digunakan
4. Klik
make static
5. Pilih
menu interface
6. Double
klik wlan yang dijadikan AP
7. Pilih
tab general lalu pada menu ARP Set Reply Only
E.
Enkripsi
WEP
1. Buka
winbox pilih tab wireless
2. Pilih
tab security profile lalu klik tanda +(add)
3. Beri
nama profile lalu set mode static Key Required
4. Pilih
tab static key
5. Set
key 40bit wep (10 digit hexadecimal key) atau 104 bit wep (26 digit hexadecimal
key)
6. Masukkan
hexadecimal key (berupa 0Aca,-aeoe 9 dan Aca-ae oe F) sesuai dengan jumlah
digitnya (tidak boleh kurang atau lebih)
7. Setelah
itu pilih interface double klik wlan yang dimaksut
8. Pilih
tab wireless set security profiles dengan nama profiles tadi
9. Disisi
client harus diset sama supaya bisa connect
setting WDS Mesh
1.rubah identitas
2.rubah interface (eth1=lan)
3.settiing wlan1 (enable wlan1)
-mode=Ap bridge
-band=2 Ghz B/G/N
-ssid=scan dulu (sesuaikandengan yang dinginkan)
4.setting mesh (add name=interface-mesh)
5.setting port mesh (interface=Wlan1 Mesh=interface-mesh)
6.setting wireless (wds mode=dynamic mesh Wds default mode=interface-mesh)
7.setting ip address (interface-mesh=192.168.55.2/24) (lan=192.168.55.100/24)
8.setting gateway (gateway=192.168.55.1)
9.setting dns
10.settng firewall nat
-chain=srcnat
-out interface=interface-mesh
-action=masquarade
11.setting NTP Client
-centang enable
-mode=inicast
-primary=203.168.128.178
-secondary=202.134.6.170
12.setting clock
13.satu kelaskan ip laptop dengan ip router
14.tes koneksi
2.rubah interface (eth1=lan)
3.settiing wlan1 (enable wlan1)
-mode=Ap bridge
-band=2 Ghz B/G/N
-ssid=scan dulu (sesuaikandengan yang dinginkan)
4.setting mesh (add name=interface-mesh)
5.setting port mesh (interface=Wlan1 Mesh=interface-mesh)
6.setting wireless (wds mode=dynamic mesh Wds default mode=interface-mesh)
7.setting ip address (interface-mesh=192.168.55.2/24) (lan=192.168.55.100/24)
8.setting gateway (gateway=192.168.55.1)
9.setting dns
10.settng firewall nat
-chain=srcnat
-out interface=interface-mesh
-action=masquarade
11.setting NTP Client
-centang enable
-mode=inicast
-primary=203.168.128.178
-secondary=202.134.6.170
12.setting clock
13.satu kelaskan ip laptop dengan ip router
14.tes koneksi
setting topologi P2MP
1.Rubah identitas /system identity
2.Rubah interface ( ether 1=lan)
3.setting wlan
4.setting wireless
mode=station
pilih SSID
5.setting ip adrees (buat ip lan dan wlan 1)
6.setting gateway
7.setting DNS
8.setting DNS static (nslan=ip lan)
9.setting firewall NAtT
10.setting NTP Client
primary=203.168.128.178
secondary=202.134.6.170
11.setting clock
12.tes koneksi
2.Rubah interface ( ether 1=lan)
3.setting wlan
4.setting wireless
mode=station
pilih SSID
5.setting ip adrees (buat ip lan dan wlan 1)
6.setting gateway
7.setting DNS
8.setting DNS static (nslan=ip lan)
9.setting firewall NAtT
10.setting NTP Client
primary=203.168.128.178
secondary=202.134.6.170
11.setting clock
12.tes koneksi
Manajemen Bandwidth Queue Tree
contoh :
ether1 = internet gateway (WAN)
ether2 = 192.168.10.1/24 (Hotspot) ==> dibuat dhcp
Langkah pertama kita buat mangle:
/ip firewall mangle
add chain=prerouting action=jump jump-target=hotspot comment=”Hotspot Jump Mangle”
add chain=postrouting action=jump jump-target=hotspot
add chain=prerouting action=mark-connection new-connection-mark=conn-up passthrough=yes dst-address=192.168.10.0/24 comment=”Hotspot Connections”
add chain=postrouting action=mark-connection new-connection-mark=conn-down passthrough=yes src-address=192.168.10.0/24
add chain=prerouting action=mark-packet new-packet-mark=packet-up passthrough=yes connection-mark=conn-up comment=”Hotspot Packets”
add chain=postrouting action=mark-packet new-packet-mark=packet-down passthrough=yes connection-mark=conn-down
add chain=prerouting action=mark-packet new-packet-mark=hotspot-up passthrough=no connection-mark=conn-up
add chain=postrouting action=mark-packet new-packet-mark=hotspot-down passthrough=no connection-mark=conn-down
Setelah mangle utama kita buat, sekarang
kita akan menambahkan lagi mangle untuk memisahkan jalur browsing,
download, facebook dan youtube (yg lain2 bisa ditambahkan sendiri ya)
cara blokir situs lewat 7 layer
/ip firewall mangle
add action=add-dst-to-address-list adress-list=facebook \ adress-list-timeout=1m chain=prerouting comment="" content=facebook.com \disabled=no
kedua baru eksekusi facebooknya
/ip firewall filter
add action=drop chain=forward comment="Drop Facebook" disabled=no \
dst-adress-list=facebook
add action=add-dst-to-address-list adress-list=facebook \ adress-list-timeout=1m chain=prerouting comment="" content=facebook.com \disabled=no
kedua baru eksekusi facebooknya
/ip firewall filter
add action=drop chain=forward comment="Drop Facebook" disabled=no \
dst-adress-list=facebook
Senin, 18 Februari 2013
Limit Browsing, Upload, Download & Game
Limit Browsing, Upload, Download & Game:
Settingan ini Berjalan Pada Mikrotik RB750 OS ver.4.5 Dan percobaan Ini dilakukan pada mikrotik PC dengan Mikrotik Versi V2.9.27
Siapkan Perangkat PC dan Instal Mikrotik V2.9.27
* Lan Card 1 menuju ISP dalam settingan ini menggunakan Speedy "Jaringan Speedy"
* Lan Card 2 Menuju Jaringan Local dengan nama "Jaringan Local"
* Setting IP untuk Lan 1 (Baca Tutorial Instal Mikrotik)
* setting IP untuk Lan 2 (disini IP : 192.168.0.0/24
setting bandwith malam
/queue simple
#name=”Day” target-addresses=192.168.1.0/24 dst-address=0.0.0.0/0
interface= parent=none direction=both priority=8
queue=default-small/default-small limit-at=512k/512k
max-limit=1M/1M total-queue=default-small
#name=”Night” target-addresses=192.168.1.0/24 dst-address=0.0.0.0/0
interface= parent=none direction=both priority=8
queue=default-small/default-small limit-at=1M/1M
max-limit=2M/2M total-queue=default-small
setting bandwith siang dan malam
cara memisahkan bandwidth siang dan malam hari dengan mikrotik
Contoh kasus sederhana ,Anda memiliki 3 jenis pengguna:
- 256k/256k pada siang hari, 1M/1M di malam hari
- 512k/512k pada siang hari, 2M/2M di sore hari
- 1M/1M pada siang hari, 4M/4M di malam hari
pertama yang kita lakukan adalah Pengaturan NTP Client dengan menggunakan perintah berikut :
/system ntp client
set enabled=yes mode=unicast primary-ntp=213.239.154.12 secondary-ntp=213.249.66.35
setelah itu instal queues nya , dengan perintah :
/queue simple
add comment="CAT1" direction=both disabled=no dst-address=192.168.4.15/32 \
max-limit=256000/256000 name="George_CAT1" parent=none priority=8 \
queue=default-small/default-small
add comment="CAT1" direction=both disabled=no dst-address=192.168.4.16/32 \
max-limit=256000/256000 name="Robinson_CAT1" parent=none priority=8 \
queue=default-small/default-small
add comment="CAT2" direction=both disabled=no dst-address=192.168.4.17/32 \
max-limit=512000/512000 name="Crusoe_CAT2" parent=none priority=8 \
queue=default-small/default-small
add comment="CAT3" direction=both disabled=no dst-address=192.168.4.18/32 \
max-limit=1024000/1024000 name="Momma_CAT3" parent=none priority=8 \
queue=default-small/default-small
setelah itu barulah kita pisahkan limit bandwidth siang dan malam nya :
untuk “siang” limits:
/system scheduler
add comment="" disabled=no interval=1d name="Day" on-event="/queue simple\r\nset [find \
comment=CAT1] max-limit=256000/256000\r\nset [find comment=CAT2] \
max-limit=512000/512000\r\nset [find comment=CAT3] max-limit=1024000/1024000\r\n" \
start-date=jan/01/1970 start-time=06:00:00
untuk “malam” limits:
/system scheduler
add comment="" disabled=no interval=1d name="Night" on-event="/queue simple\r\nset [find \
comment=CAT1] max-limit=1024000/1024000\r\nset [find comment=CAT2] \
max-limit=2048000/2048000\r\nset [find comment=CAT3] max-limit=4096000/4096000\r\n" \
start-date=jan/01/1970 start-time=18:00:00
prakktek proxy eksternal
/system identity set name=routerA
/interface set ether1 name=wan
/interface set ether3 name=proxy
/interface set ether5 name=lan
/ip address add address=10.10.10.2/29 interface=wan comment="ip to modem"
/ip address add address=192.168.80.1/29 interface=proxy comment="ip to proxy"
/ip address add address=192.168.100.1/28 interface=lan comment="ip to lan"
/ip route add gateway=10.10.10.1
/ip dns set server=180.131.144.144,180.131.145.145 allow-remote-request=yes cache-size=6144
/ip dns static add name=nslan address=192.168.100.1
/ip dns static add name=nsproxy address=192.168.80.1
prakktek proxy eksternal
/system identity set name=routerA
/interface set ether1 name=wan
/interface set ether3 name=proxy
/interface set ether5 name=lan
/ip address add address=10.10.10.2/29 interface=wan comment="ip to modem"
/ip address add address=192.168.80.1/29 interface=proxy comment="ip to proxy"
/ip address add address=192.168.100.1/28 interface=lan comment="ip to lan"
/ip route add gateway=10.10.10.1
/ip dns set server=180.131.144.144,180.131.145.145 allow-remote-request=yes cache-size=6144
/ip dns static add name=nslan address=192.168.100.1
/ip dns static add name=nsproxy address=192.168.80.1
ip untuk setting pemisah bandwith lokal dan internasional
# Script untuk menambahkan IP Address BGP yang terdaftar di Router NICE(OIXP) # ke RouterOS dalam ADDRESS-LIST dengan nama "nice" # Script created by: Valens Riyadi @ www.mikrotik.co.id # Generated at 19 February 2013 09:14:07 WIB ... 1229 lines # Generated in 6.11 seconds # How-to: http://www.mikrotik.co.id/artikel_lihat.php?id=23 /sys note set show-at-login=yes note="Using nice.rsc from www.mikrotik.co.id, 19 February 2013 09:14:07 WIB, 1229 lines." /ip firewall address-list add list=nice address="1.2.3.4" rem [find list="nice"] add list=nice address="120.160.0.0/11" add list=nice address="182.0.0.0/12" add list=nice address="114.120.0.0/13" add list=nice address="114.56.0.0/14"
perintah router
/system identity set name=peserta2
/interface set ether1 name=wan
/interface set ether3 name=lan
/ip address add address=10.10.10.3/24 interface: wan
/ip address add address=192.168.20.1/24 interface=lan
/ip route add gateway=10.10.10.1
/ip dns set servers=180.131.144.144,180.131.145.145 allow-remote-requests=yes cache-size=4096
/ip firewall nat add chain=srcnat out-interface=wan action=masquerade
script pemisahan koneksi u, d, g, b
chain=game action=mark-connection new-connection-mark=Game passthrough=yes protocol=tcp dst-address=203.89.146.0/23 dst-port=39190 comment=”Point Blank”
-------------------------------------------------------------------------------------------------
chain=game action=mark-connection new-connection-mark=Game passthrough=yes protocol=udp dst-address=203.89.146.0/23 dst-port=40000-40010
-------------------------------------------------------------------------------------------------
chain=game action=mark-packet new-packet-mark=Game_pkt passthrough=no connection-mark=Game
-------------------------------------------------------------------------------------------------
chain=prerouting action=jump jump-target=game
-------------------------------------------------------------------------------------------------
22.47
Unknown

