<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Siddiqngeblog&#039;s Blog</title>
	<atom:link href="http://siddiqngeblog.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://siddiqngeblog.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Fri, 20 Nov 2009 17:39:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='siddiqngeblog.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Siddiqngeblog&#039;s Blog</title>
		<link>http://siddiqngeblog.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://siddiqngeblog.wordpress.com/osd.xml" title="Siddiqngeblog&#039;s Blog" />
	<atom:link rel='hub' href='http://siddiqngeblog.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Mikrotik + Transparent Proxy Terpisah + Web Filtering</title>
		<link>http://siddiqngeblog.wordpress.com/2009/11/20/mikrotik-transparent-proxy-terpisah-web-filtering/</link>
		<comments>http://siddiqngeblog.wordpress.com/2009/11/20/mikrotik-transparent-proxy-terpisah-web-filtering/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 17:39:29 +0000</pubDate>
		<dc:creator>siddiqngeblog</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://siddiqngeblog.wordpress.com/?p=7</guid>
		<description><![CDATA[Pekerjaan saya yang tertunda selama ini adalah membangun sebuah Proxy Server terpisah dari Mikrotik yang sudah dilengkapi dengan Web Filtering. Untuk Proxy Server yang terpisah saya kali ini menggunakan Red Hat Linux sebagai operating system dan Squid sebagai aplikasi proxy serta Dansguardian sebagai aplikasi Web Filtering Kesulitan saya selama ini adalah membuat agar semua akses [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=siddiqngeblog.wordpress.com&amp;blog=10597145&amp;post=7&amp;subd=siddiqngeblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Pekerjaan saya yang tertunda selama ini adalah membangun sebuah Proxy Server terpisah dari Mikrotik yang sudah dilengkapi dengan Web Filtering.</p>
<p>Untuk Proxy Server yang terpisah saya kali ini menggunakan Red Hat Linux sebagai operating system dan Squid sebagai aplikasi proxy serta Dansguardian sebagai aplikasi Web Filtering</p>
<p>Kesulitan saya selama ini adalah membuat agar semua akses web browsing via port 80 agar terfilter terlebih dahulu pada Proxy Server.</p>
<p>copas from</p>
<p>http://komunitaskami.com/komunitas-linux/mikrotik-transparent-proxy-terpisah-web-filtering/</p>
<p>Beberapa kali saya mencoba menggunakan fitur Web Proxy Mikrotik lalu saya parent kan dengan Proxy Server yang saya bangun terpisah. Kegagalannya adalah selain mikrotik menjadi tambah berat, kesalahan setting Access Control List yang membuat Mikrotik dapat digunakan sebagai proxy dari user diluar jaringan, sudah barang tentu hal ini dapat membuat bandwidth terkuras.</p>
<p>Akhirnya saya berkeinginan agar user dalam jaringan hanya menggunakan proxy diluar fasilitas yang tersedia di Mikrotik. Proxy server ini saya sejajarkan dengan ip user sehingga menggunakan ip local.</p>
<p>Adapun kesulitan saya selama ini adalah melakukan redirect request dari user ke mikrotik melalui port 80 menuju proxy server. Saya beruntung membaca blog <a href="http://cangkirkopi.wordpress.com/2007/07/30/redirect-mikrotik-ke-squidbox/">http://cangkirkopi.wordpress.com</a> yang mengajarkan saya teknik redirect port 80 ke ip tertentu.</p>
<p>Adapun detailnya sbb :</p>
<p>Mikrotik : 192.168.0.1</p>
<p>Internet : eth1</p>
<p>Lan : eth2</p>
<p>Proxy  : 192.168.0.254</p>
<p>port : 3128</p>
<p>———–</p>
<p>di asumsikan bahwa transparent proxy sudah berjalan normal pada Proxy Server</p>
<p>1. Table NAT ( IP &gt; Firewall &gt; NAT )</p>
<p><strong>dst-nat</strong>, <strong>src-address</strong> = <strong>!</strong>192.168.0.254  <strong>protocol</strong>=tcp <strong>dst-port</strong>=80 <strong>in-interface</strong>=ether2 <strong>action</strong>=dstnat <strong>to-addresses</strong>=192.168.0.254 <strong>to-port</strong>=3128</p>
<p><strong>src-nat</strong>,<strong> src-address</strong>=192.168.0.0/24  <strong>out-interface</strong>=ether2 <strong>action</strong>=srcnat <strong>to-addresses</strong>=192.168.0.1 <strong>to-port</strong>=0-65535</p>
<p>2. Table Filter Rules</p>
<p><strong>chain</strong>=forward <strong>src-address</strong>=192.168.0.0/24  <strong>dst-address</strong>=192.168.0.254 <strong>dst-port</strong>=3128  <strong>in-interface</strong>=ether2 <strong>out-interface</strong>=ether1 <strong>action</strong>=accept</p>
<p>dengan script ini akhirnya transparent proxy tanpa menggunakan fitur proxy Mikrotik dapat berjalan dengan sempurna.</p>
<p>Ulasan pengalaman setting Dansguradian sebagai web filtering akan saya lanjutkan pada tulisan berikutnya.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/siddiqngeblog.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/siddiqngeblog.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/siddiqngeblog.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/siddiqngeblog.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/siddiqngeblog.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/siddiqngeblog.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/siddiqngeblog.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/siddiqngeblog.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/siddiqngeblog.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/siddiqngeblog.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/siddiqngeblog.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/siddiqngeblog.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/siddiqngeblog.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/siddiqngeblog.wordpress.com/7/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=siddiqngeblog.wordpress.com&amp;blog=10597145&amp;post=7&amp;subd=siddiqngeblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://siddiqngeblog.wordpress.com/2009/11/20/mikrotik-transparent-proxy-terpisah-web-filtering/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d73c93c68dcff287f26a9640f877e471?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">siddiqngeblog</media:title>
		</media:content>
	</item>
		<item>
		<title>[ mikrotik how-to ] Mikrotik Dengan 2 ISP ( non fail over )</title>
		<link>http://siddiqngeblog.wordpress.com/2009/11/20/mikrotik-how-to-mikrotik-dengan-2-isp-non-fail-over/</link>
		<comments>http://siddiqngeblog.wordpress.com/2009/11/20/mikrotik-how-to-mikrotik-dengan-2-isp-non-fail-over/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 17:37:57 +0000</pubDate>
		<dc:creator>siddiqngeblog</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://siddiqngeblog.wordpress.com/?p=5</guid>
		<description><![CDATA[Kasus ini terjadi di kantor saya dimana didalam LAN terdapat berbagai macam client, antara lain Internal ( staff perusahaan ) dan Management ( kelompok managemen ). Walaupun berada dalam satu jaringan fisik, namun mereka berada pada sub net yang berbeda : Internal = 192.168.0.0/24 Management = 192.168.1.0/24 Sekarang timbul permasalahan saat pihak management meminta akses [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=siddiqngeblog.wordpress.com&amp;blog=10597145&amp;post=5&amp;subd=siddiqngeblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div id="content">
<div id="contentleft">
<h1></h1>
<p>Kasus ini terjadi di kantor saya dimana didalam LAN terdapat berbagai macam client, antara lain Internal ( staff perusahaan ) dan Management ( kelompok managemen ).</p>
<p>Walaupun berada dalam satu jaringan fisik, namun mereka berada pada sub net yang berbeda :</p>
<p>Internal = 192.168.0.0/24</p>
<p>Management = 192.168.1.0/24</p>
<p>Sekarang timbul permasalahan saat pihak management meminta akses Internet dari ISP yang berbeda dengan kapasitas yang berbeda pula. Sebelumnya adalah menggunakan satu ISP saja. Penggabungan Dua ISP ini tidak menggunakan metode FAIL OVER.</p>
<p>Akhirnya saya putuskan untuk memasang tambahan 1 LAN Card pada router menjadi 3 LAN Card dari sebelumnya hanya 2 LAN Card saja :</p>
<p>eth1 = xx.xx.xx.xx/xx ( ISP 1 )</p>
<p>eth2 = 192.168.0.0/24 ( LAN Internel )</p>
<p>eth2 = 192.168.1.0/24 ( LAN Management )</p>
<p>eth3 = yy.yy.yy.yy/yy ( ISP 2 )</p>
<p>keterangan.</p>
<p>eth2 di set duplicate IP untuk menggabung jaringan LAN pada jaringan fisik yang sama.</p>
<p>Setting Dua ISP pada mikrotik saya temukan pada blog Jauh Dimata dengan sedikit modifikasi penyesuaian. Source asli dapat dilihat di <a href="http://jauhdimata.wordpress.com/2007/09/14/6-langkah-memadukan-2-isp-dgn-mikrotik/">sini</a>.</p>
<p>Berikut langkah &#8211; langkah setting :</p>
<p>1. Set IP pada eth1 ( ISP 1 )</p>
<blockquote><p>/ip      address add address=xx.xx.xx.xx/xx interface=eth1</p></blockquote>
<p>2. Set IP pada eth2 ( LAN Internal )</p>
<blockquote><p>/ip      address add address=192.168.0.1/24 interface=eth2</p></blockquote>
<p>3. Set IP pada eth2 ( LAN Management )</p>
<blockquote><p>/ip      address add address=192.168.1.1/24 interface=eth2</p></blockquote>
<p>4. Set IP pada eth3 ( ISP 2 )</p>
<blockquote><p>/ip      address add address=yy.yy.yy.yy/yy interface=eth3</p></blockquote>
<p>5. Setting Gateway Utama ( gateway dari ISP 1 )</p>
<blockquote><p>/ip      route add gateway=xxx.xxx.xxx.xxx/xx routing-mark=LB-RM check-gateway=ping</p></blockquote>
<p>6. Setting Gateway Kedua ( gateway dari ISP 2 )</p>
<blockquote><p>/ip      route add gateway=yyy.yyy.yyy.yyy/yy</p></blockquote>
<p>7. Memberi tanda pada routing dari LAN Internal ( 192.168.0.0/24 ) agar menggunakan Gateway Utama</p>
<blockquote><p>/ip      firewall mangle add chain=prerouting src-address=192.168.0.0/24      action=mark-routing new-routing-mark=LB-RM</p></blockquote>
<p>8. Setting Masquerade pada eth2 untuk jaringan LAN Internal agar jalur Internet via ISP 1 di eth1</p>
<blockquote><p>/ip firewall nat add chain=srcnat out-interface=ether1 src-address=192.168.0.0/24 action=masquerade</p></blockquote>
<p>9. Setting Masquerade pada eth2 untuk jaringan LAN Management agar jalur Internet via ISP 2 di eth3</p>
<blockquote><p>chain=srcnat out-interface=ether3 src-address=192.168.1.0/24 action=masquerade</p></blockquote>
<p>Saat saya coba teknik ini, internet berjalan normal di kedua subnet, begitu juga dengan check ip public yang berjalan pada masing &#8211; masing sub net saat akses internet sudah sesuai.</p>
<p>IP ISP 1 = xx.xx.xx.xx pada subnet LAN Internal</p>
<p>IP ISP 2 = yy.yy.yy.yy pada subnet LAN Management</p>
<p>Untuk mengetahui IP Public yang kita gunakan saat melakukan akses pada Internet seperti uji coba diatas, anda dapat menggunakan Tool <a href="http://komunitaskami.com/web/proxy-check-ip-dan-proxy-anda/">What My IP Is</a></p>
<p>Saya sendiri belum yakin akan benar atau salahnya teknik ini, tapi setidak &#8211; tidaknya akses internet berjalan normal dan sesuai dengan keiginan kami.</p>
<p>Untuk sesepuh senior, mohon pencerahan. CMIIW <img src="http://komunitaskami.com/wp-includes/images/smilies/icon_biggrin.gif" alt=":D" /></p>
<p>original from</p>
<p>http://komunitaskami.com/komunitas-networking/mikrotik-how-to-mikrotik-dengan-2-isp-non-fail-over/</p>
</div>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/siddiqngeblog.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/siddiqngeblog.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/siddiqngeblog.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/siddiqngeblog.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/siddiqngeblog.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/siddiqngeblog.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/siddiqngeblog.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/siddiqngeblog.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/siddiqngeblog.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/siddiqngeblog.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/siddiqngeblog.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/siddiqngeblog.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/siddiqngeblog.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/siddiqngeblog.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=siddiqngeblog.wordpress.com&amp;blog=10597145&amp;post=5&amp;subd=siddiqngeblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://siddiqngeblog.wordpress.com/2009/11/20/mikrotik-how-to-mikrotik-dengan-2-isp-non-fail-over/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d73c93c68dcff287f26a9640f877e471?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">siddiqngeblog</media:title>
		</media:content>

		<media:content url="http://komunitaskami.com/wp-includes/images/smilies/icon_biggrin.gif" medium="image">
			<media:title type="html">:D</media:title>
		</media:content>
	</item>
		<item>
		<title>Menggunakan 2 ISP pakai mikrotik</title>
		<link>http://siddiqngeblog.wordpress.com/2009/11/20/menggunakan-2-isp-pakai-mikrotik/</link>
		<comments>http://siddiqngeblog.wordpress.com/2009/11/20/menggunakan-2-isp-pakai-mikrotik/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 17:36:27 +0000</pubDate>
		<dc:creator>siddiqngeblog</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://siddiqngeblog.wordpress.com/2009/11/20/menggunakan-2-isp-pakai-mikrotik/</guid>
		<description><![CDATA[Sesuaikan skenario dengan yang anda hadapi. Baca dahulu dengan teliti. Diasumsikan server Mikrotik memiliki 3 (tiga) buah interfaces (NIC) dan dalam kondisi fresh install. Skenario: 1. ISP Telkom-Speedy (ADSL) IP Router ADSL(LAN): 192.168.0.254 copas from http://mellasaeblog.blogspot.com/2008/05/mikrotik.html IP DNS1: 202.134.0.155 IP DNS2: 202.134.2.5 2. ISP Diginet (Wireless) IP: 203.81.187.62 IP Gateway: 203.81.187.62 IP DNS1: 203.81.185.12 IP [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=siddiqngeblog.wordpress.com&amp;blog=10597145&amp;post=4&amp;subd=siddiqngeblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Sesuaikan skenario dengan yang anda hadapi. Baca dahulu dengan teliti. Diasumsikan server Mikrotik memiliki 3 (tiga)</p>
<p>buah interfaces (NIC) dan dalam kondisi fresh install.</p>
<p><strong><em>Skenario:</em></strong></p>
<p>1. ISP Telkom-Speedy (ADSL)</p>
<p>IP Router ADSL(LAN): 192.168.0.254</p>
<p>copas from</p>
<p>http://mellasaeblog.blogspot.com/2008/05/mikrotik.html</p>
<p>IP DNS1: 202.134.0.155</p>
<p>IP DNS2: 202.134.2.5</p>
<p>2. ISP Diginet (Wireless)</p>
<p>IP: 203.81.187.62</p>
<p>IP Gateway: 203.81.187.62</p>
<p>IP DNS1: 203.81.185.12</p>
<p>IP DNS2: 203.81.185.13</p>
<p>Jumlah Komputer Internet: 50 pc –&gt;</p>
<p>Network: 192.168.3.0/26 (Ip Address: 192.168.3.1 &#8211; 192.168.3.63 Netmask: 255.255.255.192)</p>
<p>Jumlah Komputer Games: 50 pc –&gt;</p>
<p>Network: 192.168.3.64/26 (Ip Address: 192.168.3.65 &#8211; 192.168.3.128 Netmask: 255.255.255.192)</p>
<p><strong>Skema Network:</strong></p>
<p><strong> </strong></p>
<p>Diginet—, ,—Speedy</p>
<p>| |</p>
<p>| |</p>
<p>203.81.187.62(ether2) 192.168.0.253(ether1)</p>
<p>[M i k r o t i k 2 . 9 . 6]</p>
<p>192.168.3.254/24 (ether3)</p>
<p>|</p>
<p>|</p>
<p>192.168.3.0/24</p>
<p>| |</p>
<p>Games: Internet:</p>
<p>192.168.3.64/26 192.168.3.0/26</p>
<p>&nbsp;</p>
<p><strong>Langkah-langkah:</strong></p>
<p><strong>1. Beri nama Interfaces Ether1-3 di [Interfaces]</strong></p>
<p>Command:</p>
<p>/interface set ether1</p>
<p>/interface set ether2</p>
<p>/interface set ether3</p>
<p>admin@BlueSky.Net] &gt; interface print</p>
<p>Flags: X &#8211; disabled, D &#8211; dynamic, R &#8211; running</p>
<p># NAME TYPE RX-RATE TX-RATE MTU</p>
<p>0 R Telkom ether 0 0 1500</p>
<p>1 R Diginet ether 0 0 1500</p>
<p>2 R Local ether 0 0 1500</p>
<p><strong>2. Beri IP Address untuk masing-masing ethernet. [Ip - Interfaces]</strong></p>
<p>Command:</p>
<p>/ip address add address=192.168.0.253/24 interface=Telkom</p>
<p>/ip address add address=203.81.187.62/24 interface=Diginet &lt;— karena gak tahu netmasknya brp..</p>
<p>/ip address add address=192.168.3.0/24 interface=Local</p>
<p>[admin@BlueSky.Net] &gt; ip address print</p>
<p>Flags: X &#8211; disabled, I &#8211; invalid, D &#8211; dynamic</p>
<p># ADDRESS NETWORK BROADCAST INTERFACE</p>
<p>0 192.168.0.253/24 192.168.0.0 192.168.0.255 Telkom</p>
<p>1 192.168.3.254/24 192.168.3.0 192.168.3.255 Local</p>
<p>2 203.81.187.62/24 203.81.187.0 203.81.187.255 Diginet</p>
<p><strong>3. Buat rule di [IP – Firewall - Mangle]:</strong></p>
<p>- chain=prerouting src-address=192.168.3.0/26 action=mark-routing new-routing-mark=Internet</p>
<p>“untuk menandai paket yang berasal dari 192.168.3.0/26 dengan nama=Internet”</p>
<p>- chain=prerouting src-address=192.168.3.64/26 action=mark-routing new-routing-mark=Games</p>
<p>“untuk menandai paket yang berasal dari 192.168.3.64/26 dengan nama=Games”</p>
<p>Command:</p>
<p>/ip firewall mangle add chain=prerouting src-address=192.168.3.0/26 \</p>
<p>action=mark-routing new-routing-mark=Internet</p>
<p>/ip firewall mangle add chain=prerouting src-address=192.168.3.64/26 \</p>
<p>action=mark-routing new-routing-mark=Games</p>
<p>[admin@BlueSky.Net] ip firewall mangle&gt; print</p>
<p>Flags: X &#8211; disabled, I &#8211; invalid, D &#8211; dynamic</p>
<p>0 chain=prerouting src-address=192.168.3.0/26 action=mark-routing</p>
<p>new-routing-mark=Internet passthrough=yes</p>
<p>1 chain=prerouting src-address=192.168.3.64/26 action=mark-routing</p>
<p>new-routing-mark=Games passthrough=yes</p>
<p><strong>4. Set Gateway untuk masing-masing network. [IP - Route]</strong></p>
<p>Command:</p>
<p>/ip route add gateway=192.168.0.254 dst-address=0.0.0.0/0 routing-mark=Internet</p>
<p>/ip route add gateway=203.81.187.1 dst-address=0.0.0.0/0 routing-mark=Games</p>
<p>[admin@BlueSky.Net] &gt; ip route print</p>
<p>Flags: X &#8211; disabled, A &#8211; active, D &#8211; dynamic,</p>
<p>C &#8211; connect, S &#8211; static, r &#8211; rip, b &#8211; bgp, o &#8211; ospf</p>
<p># DST-ADDRESS PREFSRC G GATEWAY DIS INTE…</p>
<p>0 ADC 192.168.0.0/24 192.168.0.253 Telkom</p>
<p>1 ADC 192.168.3.0/24 192.168.3.254 Local</p>
<p>2 ADC 203.81.187.0/24 203.81.187.62 Diginet</p>
<p>3 A S 0.0.0.0/0 r 192.168.0.254 Telkom</p>
<p>4 A S 0.0.0.0/0 r 203.81.187.1 Diginet</p>
<p><strong>5. Buat rule nat-masquerade untuk network 192.168.3.0/24 [IP - Firewall - Nat]</strong></p>
<p>Command:</p>
<p>/ip firewall nat add chain=srcnat src-address=192.168.3.0/24 action=masquerade</p>
<p>[admin@BlueSky.Net] &gt; ip firewall nat print</p>
<p>Flags: X &#8211; disabled, I &#8211; invalid, D &#8211; dynamic</p>
<p>0 ;;; Masquerade Network 192.168.3.0/24</p>
<p>chain=srcnat src-address=192.168.3.0/24 action=masquerade</p>
<p><strong>6. Buat script untuk melakukan cek gw dengan tools netwatch:</strong></p>
<p>command</p>
<p>/system script add-gw source={</p>
<p>:local R1</p>
<p>:local R2</p>
<p>:if ([/tool netwatch get R1 status]=up) do={:set R1 192.168.0.254}</p>
<p>:if ([/tool netwatch get R2 status]=up) do={:set R2 203.81.187.1}</p>
<p>/ip route set [/ip route find dst-address=0.0.0.0/0] \</p>
<p>gateway=($R1 . , . $R2)</p>
<p>}</p>
<p>/tool netwatch add comment=R1 host=192.168.0.254 interval=5s up-script=check-gw \</p>
<p>down-script=check-gw</p>
<p>/tool netwatch add comment=R2 host=203.81.187.1 interval=5s up-script=check-gw \</p>
<p>down-script=check-gw</p>
<p><strong>Setting di Mikrotik sudah selesai.</strong></p>
<p>Berikutnya, isikan IP address untuk tiap client Internet dengan IP Address mulai dari: 192.168.3.1 sampai 192.168.3.63.</p>
<p>Gunakan Netmask 255.255.255.192 agar workgroup terpisah dengan Games.</p>
<p>Jangan lupa berikan IP DNS Telkom di network-properties client Internet sesuai skenario di atas (202.134.0.155 dan</p>
<p>202.134.2.5).</p>
<p>Gateway diarahkan ke: 192.168.3.254.</p>
<p>Untuk Client Games isikan IP Address mulai dari: 192.168.3.65 sampai dengan 192.168.3.128.</p>
<p>Gunakan juga Netmask 255.255.255.192 jika menginginkan workgroup yang terpisah dengan Client untuk Internet.</p>
<p>Berikan IP DNS Diginet (203.81.185.12 dan 203.81.185.13) di network-propertiesnya.</p>
<p>Gateway diisikan dengan 192.168.3.254.</p>
<p>Selamat mencoba…</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/siddiqngeblog.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/siddiqngeblog.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/siddiqngeblog.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/siddiqngeblog.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/siddiqngeblog.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/siddiqngeblog.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/siddiqngeblog.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/siddiqngeblog.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/siddiqngeblog.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/siddiqngeblog.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/siddiqngeblog.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/siddiqngeblog.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/siddiqngeblog.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/siddiqngeblog.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=siddiqngeblog.wordpress.com&amp;blog=10597145&amp;post=4&amp;subd=siddiqngeblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://siddiqngeblog.wordpress.com/2009/11/20/menggunakan-2-isp-pakai-mikrotik/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d73c93c68dcff287f26a9640f877e471?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">siddiqngeblog</media:title>
		</media:content>
	</item>
		<item>
		<title>Mikrotik Web Proxy Setting for Transparant proxy</title>
		<link>http://siddiqngeblog.wordpress.com/2009/11/20/hello-world/</link>
		<comments>http://siddiqngeblog.wordpress.com/2009/11/20/hello-world/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 17:29:41 +0000</pubDate>
		<dc:creator>siddiqngeblog</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[&#160; 1. first se t web proxy / ip web-proxy set enabled=yes –&#62;&#62; to make ip web proxy enable set src-address=0.0.0.0 –&#62;&#62; to make source address to access web proxy will allow set port=8080 –&#62;&#62; to make port for web proxy set hostname=”proxy.war.net.id” –&#62;&#62; setting for visble hostname web proxy set transparent-proxy=yes –&#62;&#62; make transparant [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=siddiqngeblog.wordpress.com&amp;blog=10597145&amp;post=1&amp;subd=siddiqngeblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h2></h2>
<div>
<div>
<p>&nbsp;</p>
<p>1. first  se t web proxy<br />
/ ip web-proxy<br />
set enabled=yes  –&gt;&gt; to make  ip web proxy enable<br />
set src-address=0.0.0.0  –&gt;&gt; to make source address to access web proxy will allow<br />
set port=8080 –&gt;&gt; to make port for web proxy<br />
set hostname=”proxy.war.net.id” –&gt;&gt; setting for visble hostname web proxy<br />
set transparent-proxy=yes –&gt;&gt; make transparant proxy enable<br />
set parent-proxy=0.0.0.0:0–&gt;&gt; if we  used parent proxy x<br />
set cache-administrator=”support@somethink.org” –&gt;&gt; make set administrator info support<br />
set max-object-size=4096KiB –&gt;&gt; maximal object can cacth with the proxy server<br />
set cache-drive=system –&gt;&gt; where drive position that cache wil be saved<br />
set max-cache-size=unlimited –&gt;&gt; maximal harddrive we used for cache<br />
set max-ram-cache-size=unlimited –&gt;&gt; maximal ram we used for cache</p>
<p>2. add nat for redirect port for squid to make transparant</p>
<p>/ip firewall nat add chain=dstnat protocol=tcp dst-port=80 action=redirect to-ports=8080 –&gt;&gt; setting can redirect port 80 to 8080 for proxy server<br />
/ip firewall nat add chain=dstnat protocol=tcp dst-port=3128 action=redirect to-ports=8080 –&gt;&gt; setting can redirect port 3128 to 8080 for proxy server<br />
/ip firewall nat add chain=dstnat protocol=tcp dst-port=8080 action=redirect to-ports=8080 –&gt;&gt; setting can redirect port 8080 to 8080 for proxy server</p>
</div>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/siddiqngeblog.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/siddiqngeblog.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/siddiqngeblog.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/siddiqngeblog.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/siddiqngeblog.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/siddiqngeblog.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/siddiqngeblog.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/siddiqngeblog.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/siddiqngeblog.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/siddiqngeblog.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/siddiqngeblog.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/siddiqngeblog.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/siddiqngeblog.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/siddiqngeblog.wordpress.com/1/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=siddiqngeblog.wordpress.com&amp;blog=10597145&amp;post=1&amp;subd=siddiqngeblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://siddiqngeblog.wordpress.com/2009/11/20/hello-world/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d73c93c68dcff287f26a9640f877e471?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">siddiqngeblog</media:title>
		</media:content>
	</item>
	</channel>
</rss>
