Professional Documents
Culture Documents
Mtcna PDF
Mtcna PDF
Jadwal Training
Session 1
Session 2
Hari 1
Pre Test
&
Introduction
Installation
&
Basic
Networking
Basic Configuration
Hari 2
Bridge
Wireless
Routing
Hari 3
Hari 4
00-2
Session 3
Firewall
Hotspot
Session 4
QOS
VPN
TEST
24/07/15
Jadwal Harian
00-3
Sessi 1
Coffee Break
Sessi 2
Lunch
Sessi 3
Coffee Break
Sessi 4
08.30 10.00
10.00 10.30
10.30 - 12.00
12.00 13.00
13.00 14.30
14.30 15.00
15.00 - 17.00
24/07/15
00-4
Basic/Essential Training
l MikroTik Certified Network Associate (MTCNA)
Advanced Training
l Certified Wireless Engineer (MTCWE)
l Certified Routing Engineer (MTCRE)
l Certified Traffic Control Engineer (MTCTCE)
l Certified User Managing Engineer (MTCUME)
l Certified Inter Networking Engineer (MTCINE)
24/07/15
Certification Test
00-5
24/07/15
24/07/15
Introduction to Mikrotik
One engineer:
Mikrotik Certified Consultant (2005)
http://www.mikrotik.com/consultants.html
01-8
24/07/15
Head Office
l
Rep. Office
l
01-9
24/07/15
What Is Mikrotik?
l
l
01-10
Wireless board
contoh: RB400, RB600, RB750, RB1000
Wireless interface (R52, R52H, R5H, R52N, R2N)
menggunakan RouterOS sebagai software
Mikrotik Indonesia http://www.mikrotik.co.id
24/07/15
What Is Mikrotik?
01-11
24/07/15
Processor
RAM
Ether
MiniPCI
Radio
RB800
800MHz
256MB
3 GE
RB43x series
680/300MHz
256/128/ 64MB
3(GE/FE)
3/5
RB41x series
680/300 MHz
64/32MB
1 (GE/FE)
opt
Groove Series
600MHz
128/64MB
1 FE
Metal series
400MHz
64MB
RB91x series
600MHz
64/32MB
1 GE
1/2
01-12
24/07/15
Processor
RAM
Ethernet
Radio
SFP
CCR series
1,2GHz (16/36)
2/4/16GB
12GE
opt
RB1100AH X2
1Ghz Dual
2GB
13GE
RB2011 Series
600MHz
128/64MB
5FE+5GE
opt
opt
RB850Gx2
500MHz Dual
512MB
5GE
RB941 (hAP-Lite)
650MHz
32MB
4FE
RB450 Series
300/680MHz
32/256MB
5(GE/FE)
RB750 Series
400/850MHz
32/64MB
5(GE/FE)
RB951 Series
300/600MHz
32/128MB
5(GE/FE)
24/07/15
Embedded Routerboard
Jenis
Processor
RAM
Ethernet
Radio
Antenna
OmniTIK Series
400MHz
32MB
5 FE
26/30dbm
7,5db
SEXTANT
600MHz
32MB
1 GE
30dbm
18db
SXT Series
400/600MHz
32MB/64MB
1 (FE/GE)
27/31/32dbm
10/16db
QRT Series
400MHz
64MB
1 GE
35dbm
16db
01-14
24/07/15
Product Code
RB
9 1
UAG
2HPND
Routerboard
Jumlah MiniPCI
Fitur Board
900 series
Jumlah Ethernet
Build-in Wireless
01-15
G : Gigabit
L : Light Edition
S : SFP Port
e : PCIe Extension Card
X : Jumlah CPU Core
24/07/15
Protocol
Kosong : standart 802.11a/b/g
n : Support 802.11n
ac : Support 802.11ac
Jumlah Chain
Kosong : single Chain
D : Dual Chain
T : Triple Chain
Power:
Kosong = < 23dBm@6mbps 802.11a ; <24dBm@6mbps 802.11g
H : High = 23-24dBm@6mbps 802.11a ; 24-27dBm@6mbps 802.11g
HP : High Power = 25-26dBm@6mbps 802.11a ; 28-29dBm@6mbps 802.11g
SHP : Super High Power = >27dBm@6mbps 802.11a; >30dBm=@6mbps
802.11g
01-16
24/07/15
Switch Manageable
01-17
24/07/15
Switch Manageable
Type
Proc
RAM
Eth
Wireless
SFP
PoE Out
RB260GS
5GE
RB260GSP
5GE
Yes, eth2-eth5
CRS109-8G-1S-2HnDIN
600MHz
128MB
8GE
Yes
CRS112-8G-4S-IN
400MHz
128MB
8GE
CRS125-24G-1S-2HnD
600MHz
128MB
24GE
Yes
CRS125-24G-1S-IN
600MHz
128MB
24GE
CRS125-24G-1S-RM
600MHz
128MB
24GE
CRS125-24G-2S+IN
400MHz
64MB
24GE
2
(10Gig)
01-18
24/07/15
Discontinued Hardware
RB100 series
l
l
01-19
RB230
RB333
RB600
RB700 series
RB750G
RB1000 series
l
RB411A,RB411R
RB532,RB511
RB600 series
RB400 series
l
RB500 series
RB300series
l
RB112,RB133,RB133C
RB153,RB150,RB192
RB200 series
l
RB1000, RB1100,
RB1100AH, RB1200
24/07/15
Performance :
l
l
01-20
Industrial grade
24/07/15
Performance :
l
01-21
Industrial grade
24/07/15
Mikrotik RouterOS
01-22
24/07/15
IP Routing
l
l
l
Interface
l
l
l
l
Bandwidth Management
l
01-23
Firewall
l
24/07/15
Services (Server)
l
AAA
l
l
01-24
Monitoring
l
VRRP
Mikrotik Indonesia http://www.mikrotik.co.id
24/07/15
Licence Level
Level
Upgrade time
Wireless CPE/PTP
yes
Wireless AP
no
yes
Sync Interface
no
yes
EoIP
unlimited
200
200
OpenVPN
200
200
500
unlimited
unlimited
unlimited
yes
Dynamic Routing
RB = yes
yes
200
500
unlimited
10
20
50
unlimited
01-25
24/07/15
01-26
24/07/15
Buyers Guide
01-27
RB1100AHx2
Mikrobits : Dinara
Mikrotik Indonesia http://www.mikrotik.co.id
24/07/15
Buyers Guide
www.routerboard.co.id
01-28
24/07/15
Quiz !
01-29
24/07/15
Mikrotik Installation
Installasi Mikrotik
Media Installasi (Penyimpan) Mikrotik RouterOS
l
l
l
l
l
02-31
Harddisk
CF Disk
DOM (Disk On Module)
USB Flash Disk
NAND Storage (Routerboard only)
24/07/15
Installation Method
CD
l
l
Netinstall
l
l
02-32
CD-Rom Required
PXE,EtherBoot Required
24/07/15
Download Area
02-33
24/07/15
CD Installation (1)
Download ISO file (mikrotik-***.iso) dan buatlah CD
bootable dengan file tersebut.
02-34
24/07/15
CD Installation (2)
02-35
24/07/15
CD Installation (3)
Choose Yes
Yes/No
Creating partition...
Formatting disk...
Software installed.
02-36
24/07/15
Installation Check
02-37
Welcome menu
24/07/15
License Trial
License level 0 = Trial time 24 jam
02-38
24/07/15
02-39
24/07/15
02-40
24/07/15
02-41
24/07/15
Tutorial : http://mikrotik.co.id/artikel_lihat.php?id=26
02-42
24/07/15
Netinstall
Switch
Network:
172.16.0.0/24
IP Address:
172.16.0.10/24
RS-232
Serial null modem console cable
24/07/15
Netinstall
Download program netinstall dan module yang dibutuhkan
02-44
24/07/15
Paket RouterOS
o routeros-mipsbe-6.xx.npk
o routeros-mipsle-6.xx.npk
CCR series
RB941-2n
o routeros-powerpc-6.xx.npk
o routeros-x86-6.xx.npk
o routeros-tile-6.xx.npk
o routeros-smips-6.xx.npk
Ada 2 macam file yang dapat didownload :
routeros-xxxx-x.xx.npk : Merupakan paket standart.
all_packages-xxx-x.xx.zip : Berisi semua paket routerOS,
termasuk paket tambahan.
02-45
24/07/15
Netinstall
02-46
24/07/15
02-47
24/07/15
02-48
24/07/15
02-49
24/07/15
02-50
24/07/15
Netinstall - Install
02-51
24/07/15
02-52
24/07/15
Netinstall - Install
02-53
24/07/15
Netinstall Reboot
24/07/15
Netinstall - Cleanup
Video Tutorial :
http://www.mikrotik.co.id/artikel_lihat.php?id=25
02-55
24/07/15
Reset Password
02-56
Hard Reset :
24/07/15
Quiz !
02-57
24/07/15
02-58
24/07/15
RouterOS Package
02-59
Nama Paket
Fungsi
advanced-tools
dhcp
hotspot
hotspot gateway
ntp
NTP server
ppp
PPP,PPTP,L2TP,PPPoE
routerboard
routing
security
wireless
Wireless 802.11a/b/g
user-manager
system
ipv6
IPv6
Mikrotik Indonesia http://www.mikrotik.co.id
24/07/15
02-60
24/07/15
02-61
24/07/15
FTP ke Router
IP Router
02-62
24/07/15
*ChangeLog
02-63
24/07/15
02-64
24/07/15
Upgrade-Auto Upgrade
/system upgrade
02-65
24/07/15
Version Downgrade
02-66
24/07/15
02-67
24/07/15
24/07/15
02-69
24/07/15
Quick Typing
l
/sys shut
= /system shutdown
02-70
http://wiki.mikrotik.com/wiki/Scripting
24/07/15
Quiz !
02-71
System
Routing
Advance-tools
DHCP
24/07/15
192.168.0.254/24
Internet
192.168.0.4/24
192.168.0.246/24
192.168.0.191/24
192.168.0.26/24
192.168.0.41/24
03-73
192.168.0.142/24
24/07/15
192.168.1.48/24
192.168.1.254/24
Router
Switch
192.168.0.141/24
192.168.1.4/24
03-74
192.168.1.24/24
24/07/15
Ether1
192.168.0.28/24
Ether3
192.168.4.151/24
03-75
Ether2
192.168.2.74/24
Router
Ether4
192.168.5.211/24
24/07/15
Internet
192.168.0.4/24
192.168.0.246/24
192.168.0.191/24
192.168.0.26/24
192.168.0.41/24
03-76
192.168.0.142/24
24/07/15
03-77
24/07/15
www.google.com
159.148.147.196
203.190.241.43
202.152.130.27
PC Client
www.google.com
03-78
24/07/15
Quiz !
03-79
24/07/15
Topologi Office
192.168.1.10/24
Internet
192.168.1.254/24
AP
Router
192.168.1.12/24
172.16.1.254/24
File Server
10.10.10.1/24
Switch
Switch
Mail
Server
Apps
Server
03-80
172.16.1.1/24
172.16.1.1/24
24/07/15
RouterOS Basic
Configuration
Certified Mikrotik Training Basic Class
Organized by: Citraweb Nusa Infomedia
(Mikrotik Certified Training Partner)
Winbox - Download
Download terlebih dahulu program winbox.exe
untuk mengkonfigurasi RouterOS Mikrotik.
04-82
24/07/15
WLAN1
10.10.10.1/24
WLAN1
10.10.10.X/24
ETHER1
192.168.1.1/24
ETHER1
192.168.2.1/24
ETHER1
192.168.X.1/24
ETHERNET PORT
192.168.1.2/24
ETHERNET PORT
192.168.2.2/24
ETHERNET PORT
192.168.X.2/24
MEJA 1
04-83
WLAN1
10.10.10.2/24
MEJA 2
Mikrotik Indonesia http://www.mikrotik.co.id
MEJA X
24/07/15
IP Configuration
Lab-1 adalah sebuah simulasi
konfigurasi dasar sebuah Router
Mikrotik yang akan digunakan di
jaringan local seperti Warnet,
Office, Kampus atau bahkan di
RT/RW-NET
X = nomor peserta
04-84
Routerboard Setting
l WAN IP
: 10.10.10.x/24
l Gateway
: 10.10.10.100
l LAN IP
: 192.168.x.1/24
l DNS
: 10.100.100.1
l Src-NAT and DNS Server
Laptop Setting
l IP Address : 192.168.x.2/24
l Gateway
: 192.168.x.1
l DNS
: 192.168.x.1
24/07/15
Laptop Config
Konfigurasi ipaddress statik pada
laptop.
04-85
24/07/15
First Setup
04-86
24/07/15
First Setup
04-87
24/07/15
04-88
24/07/15
04-89
24/07/15
04-90
24/07/15
04-91
24/07/15
04-92
24/07/15
24/07/15
04-94
24/07/15
Konfigurasi NAT
l
04-95
Konfigurasi DNS
l
Konfigurasi IP Address
24/07/15
Installation Debug
04-96
24/07/15
Quiz
Asumsikan semua setting lain yang dibutuhkan seperti NAT
dan route, sudah dilakukan. Bisakah PC akses ke
www.yahoo.com ?
l Config Router
PC Config
04-97
24/07/15
04-98
24/07/15
[LAB-7] NTP
04-99
24/07/15
System - Clock
04-100
24/07/15
File hasil backup dapat dilihat di menu file dan didownload via FTP
04-101
24/07/15
04-102
24/07/15
System Reset
04-103
24/07/15
04-104
24/07/15
Export Configuration
Penyimpanan konfigurasi bisa dilakukan juga
menggunakan perintah export.
04-105
24/07/15
Export to File
Hasil export ini berupa script (text base
configuration) yang bisa dilihat dan diedit
menggunakan text editor.
04-106
24/07/15
Import Script
File script bisa langsung di import ke router
04-107
24/07/15
Quiz!
04-108
24/07/15
DHCP Server
Dynamic Host Configuration Protocol digunakan
untuk secara dinamik mendistribusikan konfigurasi
jaringan, seperti:
l
l
l
l
04-109
24/07/15
DHCP Server
Router
DHCP Client
Internet
DHCP Server
Static IP
Tamu
(Dynamic Users)
Karyawan
(Static Users)
DHCP Server cocok diterapkan pada jaringan ber-user banyak dan dinamis
04-110
24/07/15
04-111
24/07/15
04-112
24/07/15
04-113
24/07/15
04-114
24/07/15
DHCP Test
04-115
24/07/15
DHCP Management
04-116
24/07/15
DHCP Static
04-117
24/07/15
DHCP Client
04-118
24/07/15
04-119
24/07/15
Interface
l
04-120
24/07/15
04-121
24/07/15
Quiz!
04-122
24/07/15
04-123
24/07/15
04-124
24/07/15
04-125
24/07/15
04-126
24/07/15
04-127
24/07/15
04-128
IP-Winbox
Telnet
SSH
WebFig
24/07/15
04-129
24/07/15
04-130
24/07/15
ARP Table
Merupakan protokol
penghubung antara layer 2
data-link dan 3 network.
ARP Table di router
merupakan daftar host yang
terhubung langsung berisi
informasi pasangan mac
address dan
ip address.
Di IPv6 arp digantikan
dengan NDP (Network
Discovery Protocol).
04-131
24/07/15
04-132
24/07/15
ARP Protocol
04-133
24/07/15
Router
Interface
MAC
=
9C:8E:99:48:F6:20
IP
Address
=
192.168.128.104
Flag
D (dynamic)
Interface
melakukan
update
tabel
ARP
dengan
kombinasi
MAC
Address
dan
IP
Address
host
secara
otomaGs
04-134
24/07/15
ARP Security !
ARP = Reply-only menandakan ARP
protocol pada interface tidak mengupdate
data di ARP table secara otomatis.
04-135
24/07/15
Router
MAC
=
9C:8E:99:48:F6:20
IP
Address
=
192.168.128.104
Interface
MAC
=
AA:BB:01:CC:FF:EE
IP
Address
=
192.168.128.104
Static ARP
24/07/15
Tool - Scheduler
Digunakan untuk mengeksekusi perintah berdasarkan waktu
04-137
24/07/15
Logging
Digunakan untuk melakukan pencatatan aktivitas sistem dan
informasi status router.
04-138
24/07/15
Logging
Logging Rule
l
Tipe Disk
- Log akan disimpan dalam bentuk teks file pada storage
system Router
Tipe Echo
- Log akan ditampilkan pada New Terminal (winbox) atau
pada saat kita remote menggunakan CLI (direct console)
Tipe Email
- Log akan dikirimkan ke email yang sudah kita tentukan pada
pengaturan SMTP ( /tool email )
Tipe Memory - Log akan disimpan di dalam RAM Router dan bisa kita lihat
pada menu Log
Tipe Remote - Log akan dikirimkan ke perangkat lain yang menjalankan
syslog server
24/07/15
10-140
24/07/15
SNMP Menu
10-141
24/07/15
10-142
24/07/15
Graph
10-143
24/07/15
Newatch
Untuk melakukan monioring kondisi host
144
24 July 2015
Newatch(2)
145
24 July 2015
Email
Untuk melakukan pengiriman email dari Router, lakukan
setting SMTP Server pada menu /tool email
24 July 2015
Send Email
147
24 July 2015
Monitoring - Ping
Ping uses Internet Control Message Protocol (ICMP) Echo
messages to determine if a remote host is active or inactive
and to determine the round-trip delay when communicating
with it.
[user1@MKI] > ping 192.168.0.100
192.168.0.100 64 byte ping: ttl=64 time=1 ms
192.168.0.100 64 byte ping: ttl=64 time=1 ms
192.168.0.100 64 byte ping: ttl=64 time=1 ms
3 packets transmitted, 3 packets received, 0% packet loss
round-trip min/avg/max = 1/1.0/1 ms
04-148
24/07/15
04-149
24 July 2015
Monitoring - Traceroute
l
04-150
Traceroute determines
how packets are being
routed to a particular
host
We can choose the
protocol : ICMP or UDP
24/07/15
Monitoring - Torch
Torch - Realtime traffic monitor
04-151
24/07/15
Monitoring - Resource
l
04-152
To monitor the
System.
Detail Resource
monitor located on
right side buttons
24/07/15
04-153
24/07/15
Switch Chipset
05-155
24/07/15
Ether6 Ether10
Configured as Switch Mode
LAN 1
10.10.10.0/24
LAN 2
172.16.1.0/24
05-156
LAN 3
192.168.1.0/24
Mikrotik Indonesia http://www.mikrotik.co.id
24/07/15
05-157
24/07/15
Switch Chipset
Command Line configuration
05-158
24/07/15
05-159
24/07/15
Bridge - Concept
05-160
24/07/15
Ether6 Ether10
Configured as Bridge Mode
05-161
24/07/15
Ethernet
VLAN
PPTP
05-162
24/07/15
CLIENT
ROUTER
GATEWAY
WIRELESS
05-163
192.168.0.0/24
Mikrotik Indonesia http://www.mikrotik.co.id
24/07/15
222.152.211.0/28
222.152.211.2
Public IP - WEB Server
Public IP - Client
222.152.211.3
222.152.211.4-222.152.211.10
05-164
24/07/15
Ether1
192.168.10.1/24
05-165
Ether3
Ether1
Ether3
192.168.10.4/24
24/07/15
24/07/15
24/07/15
Membuat Bridge
05-168
24/07/15
Bridge Monitoring
Untuk melihat mac-address host yang
terkoneksi dengan bridge tersebut
05-169
24/07/15
System Bridge
Konsekuensi penggunaan Sistem Bridge
l
l
l
l
05-170
24/07/15
Bridge!
05-171
24/07/15
Quiz !
05-172
24/07/15
Wireless
Certified Mikrotik Training Basic Class
Organized by: Citraweb Nusa Infomedia
(Mikrotik Certified Training Partner)
Band 2.4Ghz
l
Band 5Ghz
l
06-174
24/07/15
Channels 80211-b
World Wide Band
915 MHz
2.4 GHz
26 MHz
84.5 MHz
2401
2423
5.8 GHz
125 MHz
2426
2448
2406
2428
2453
2433
2458
2438
2421
13
2443
2446
2432
2430
Top of channel
14
2473
2463
2452
Channel number
2483
2472
2441
2427
2420
2461
2447
2416
2478
2467
2436
2422
2410
12
2456
2442
2411
2473
2462
2431
2417
2400
11
2451
2437
2412
2495
2484
10
Center frequency
2468
2457
2440
2450
2460
2470
2480
MHz
Bottom of
channel
ISM Band
24/07/15
Channels 80211-a
36
40
42
44
48
5210
5150
5200
5220
5240
149
152 153
157
160 161
5760
06-176
5765
52
56
5250
5180
5735 5745
50
58
60
64
5300
5320
5290
5260
5280
5350
5800
5785
5805 5815
24/07/15
Wireless Configuration
Basic Configuration :
l
l
l
l
l
l
l
l
Wireless Protocol
l
l
l
06-177
24/07/15
Scan Tool
06 -178
24/07/15
Snoop Tool
06 -179
24/07/15
Wireless Menu
Wireless Menu:
l Interface Daftar Interface wireless yang terpasang
l Access-List Security Mac-address Client (AP Mode)
l Registration Daftar Wireless yang terkoneksi
l Connect-List Security Mac-address AP (Station Mode)
l Security-Profile Konfigurasi Wireless Security (WPA/WEP)
06 -180
24/07/15
06 -181
alignment-only
ap-bridge
bridge
nstreme-dual-slave
station
station-wds
wds-slave
station-pseudobridge
station-pseudobridge-clone
station-bridge
Mikrotik Indonesia http://www.mikrotik.co.id
24/07/15
Wireless Mode - 1
06 -182
24/07/15
Wireless Mode 2
06 -183
24/07/15
AP
PTP
(only
one
client)
CPE
Repeater
Bridge
WDS
MikroTik
Only
Yes
Yes
Yes
Yes
Bridge
Yes
Yes
Nstreme Dual
Slave
Yes
Station
Yes
Station
Pseudobridge
Yes
Yes
Station
Pseudobridge
clone
Yes
Yes
Station Bridge
Yes
Yes
Yes
Station WDS
Yes
Yes
Yes
WDS Slave
Yes
Yes
Yes
Mode
Alignment Only
AP Bridge
07-184
24/07/15
Client Side
l
06 -185
24/07/15
Konfigurasi :
Set mode, ssid, band dan frequency
mode=bridge
l
06 -186
24/07/15
Konfigurasi :
Set mode, ssid, band dan scan-list
mode=station
Pastikan frequency yang dipilih oleh
AP masuk dalam range scan-list
06 -187
24/07/15
06 -188
24/07/15
06 -189
24/07/15
Tips
Country : Membatasi channel yang bisa
digunakan sesuai dengan regulasi sebuah
Negara.
Jika di set no_country_set maka akan
menggunakan standart channel FCC compliant.
06 -190
24/07/15
Quiz!
06 -191
24/07/15
Data rates
Data rate : Informasi kecepatan transmisi data
yang bisa dilewatkan pada link wireless.
06 -192
24/07/15
TX Power
Tx power : Pengaturan Daya pancar
interface wireless.
default : card wireless akan
menggunakan nilai tx-power dari eeprom
card-rates : Router akan melakukan
perhitungan data rates menggunakan
algoritma eeprom berdasarkan nilai tx
power yang diinput user
all-rates-fixed : Menggunakan satu nilai
tx-power untuk semua data rates.
06 -193
24/07/15
06 -194
24/07/15
Wireless Bridge
l
06 -195
24/07/15
24/07/15
AP
A
ethernet
Station
Wireless
connection
192.168.0.x/24
06 -197
B
ethernet
192.168.0.x/24
Mikrotik Indonesia http://www.mikrotik.co.id
24/07/15
06 -198
24/07/15
06 -199
24/07/15
24/07/15
24/07/15
06 -202
24/07/15
06 -203
24/07/15
06 -204
24/07/15
06 -205
24/07/15
Client Management
06 -206
MAC Address
Signal Strength
Time
24/07/15
Klasifikasi mac-address
dari client
06 -207
24/07/15
AP Management
06 -208
MAC Address
SSID
Area
24/07/15
06 -209
24/07/15
Wireless Security
06 -210
24/07/15
Tentukan passwordnya
06 -211
24/07/15
06 -212
24/07/15
06 -213
24/07/15
06 -214
24/07/15
[LAB-8] Nstreme
06 -215
24/07/15
06 -216
24/07/15
06 -217
24/07/15
Routing
Routed Network
07-219
24/07/15
Routing Example
Routerboard yang berfungsi sebagai router
akan menjembatani komunikasi antar
network yang berbeda
Ether2 Ether13
Configured as Routing Mode
(default)
Internet
192.168.0.0/24
LAN 1
07-220
192.168.1.0/24
192.168.2.0/24
LAN 2
LAN 3
24/07/15
Routing Benefit
08-221
24/07/15
192.168.3.0/24
192.168.2.0/24
ROUTER
GATEWAY
WIRELESS
07-222
192.168.0.0/24
24/07/15
dynamic routes
yang akan dibuat secara otomatis:
07-223
static routes
adalah informasi routing yang dibuat secara
manual oleh user untuk mengatur ke arah
mana trafik tertentu akan disalurkan. Default
route adalah salah satu contoh static routes.
Mikrotik Indonesia http://www.mikrotik.co.id
24/07/15
Menambahkan Routing
07-224
24/07/15
Tipe Routing
A: Active
S: Static
A: Active
D: Dynamic
C: Connected
07-225
24/07/15
Tipe Routing
A: Active
S: Static
A: Active
D: Dynamic
C: Connected
07-226
24/07/15
07-227
Destination
l Destination address 222.152.211.7
l Network mask 202.53.246.0/24
l 0.0.0.0/0 -> ke semua network
Gateway
l IP Address gateway, harus merupakan IP Address yang satu subnet
dengan IP yang terpasang pada salah satu interface
Gateway Interface
l Digunakan apabila IP gateway tidak diketahui dan bersifat dinamik
(biasanya digunakan di ppp interface).
Pref Source
l source IP address dari paket yang akan meninggalkan router
Distance
l Beban untuk kalkulasi pemilihan routing
24/07/15
Internet
10.10.0.2/24
A
10.10.1.1/24
10.10.2.1/24
10.10.2.2/24
10.10.3.2/24
B
10.10.4.1/24
10.10.4.2/24
07-228
Dst-address=0.0.0.0/0 gateway=10.10.2.1
24/07/15
10.10.0.2/24
10.10.2.2/24
10.10.1.1/24
10.10.1.2/24
10.10.2.1/24
10.10.3.1/24
10.10.3.2/24
(DAC) Dst-addr= 10.10.3.0/24
pref-source=10.10.3.2
(AS) Dst-addr= 0.0.0.0/0 gw=10.10.3.1
07-229
24/07/15
Internet
10.10.10.100
10.10.10.2
Router 1
Router 2
192.168.2.1
192.168.1.1
192.168.1.2
07-230
192.168.2.2
24/07/15
Internet
10.10.10.100
10.10.10.2
Router 1
Router 2
192.168.2.1
192.168.1.1
192.168.1.2
07-231
192.168.2.2
24/07/15
Langkah-langkah
07-232
24/07/15
Distance
07-233
24/07/15
Contoh Pemilihan
Untuk koneksi dengan destination 192.168.0.1,
manakah urutan prioritas rule yang digunakan?
Destination
Gateway
Distance
Prioritas
192.168.0.0/27 192.168.1.1
192.168.0.0/29 192.168.2.1
192.168.0.0/24 192.168.3.1
192.168.0.0/24 192.168.4.1
07-234
24/07/15
192.168.X.2/24
WLAN1:10.10.10.X/24
Internet
10.10.10.100/24
ETHER3:
10.Y.3.1/24
ETHER2:
10.Y.3.2/24
192.168.X.2/24
ETHER3:
10.Y.1.1/24
ETHER3:
10.Y.2.1/24
ETHER2:
10.Y.2.2/24
ETHER2:
10.Y.1.2/24
2
192.168.X.2/24
192.168.X.2/24
07-235
24/07/15
Quiz!
o Untuk membuat Static Route, perlu ditambahkan package Routing pada
Router. (Benar/salah)
07-236
24/07/15
24/07/15
Firewall
Firewall ?
Switch
Server
Internet
Firewall
Laptop
08-239
24 July 2015
Rules
NAT (source-nat and destination-nat)
Mangle
Address List
Layer 7 Protocol (baru di versi 3)
Service Ports
Connections
l
08-240
24 July 2015
08-241
Protocol
24 July 2015
08-242
24 July 2015
PRE-ROUTING
INPUT
INPUT
INTERFACE
08-243
POST-ROUTING
OUTPUT
LOCAL
PROCESS
OUTPUT
INTERFACE
24 July 2015
Foward
FORWARD
PRE-ROUTING
INPUT
INTERFACE
OUTPUT
INTERFACE
Laptop
08-244
POST-ROUTING
Server Google
24 July 2015
INPUT
PRE-ROUTING
INPUT
INPUT
INTERFACE
LOCAL
PROCESS
Laptop
08-245
24 July 2015
OUTPUT
POST-ROUTING
OUTPUT
LOCAL
PROCESS
OUTPUT
INTERFACE
Server Google
08-246
24 July 2015
08-247
Prerouting
not
implemented
not
implemented
not
implemented
Input
yes
no
no
Forward
no
yes
no
Output
no
no
yes
Postrouting
not
implemented
not
implemented
not
implemented
24 July 2015
Action Filter
08-248
24 July 2015
Internet
Router
Meja 1
Laptop
meja1
08-249
Router
Meja 2
Laptop
meja2
Mikrotik Indonesia http://www.mikrotik.co.id
24 July 2015
Action
08-250
24 July 2015
PING
Router
FTP Router
Router
MikroTik
HTTP
Router
Laptop
08-251
24 July 2015
Custom Chain
08-252
24 July 2015
HTTP
Router
Drop semua,
kecuali HTTP
Laptop
08-253
24 July 2015
08-254
24 July 2015
RouterOS v5 Services
PORT
PROTOCOL
DESCRIPTION
20-21
22
23
53
80
179
443
646
1080
1723
1968
2000
2210
2211
2828
3128
8291
8728
---
---
---
08-255
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
/1
/2
/4
/41
/46
FTP
SSH,
SFTP
Telnet
DNS
HTTP
BGP
HTTPS
LDP
(MPLS)
SoCKS
PPTP
MME
BTest
Server
Dude
Server
Dude
Server
uPnP
Web
Proxy
Winbox
API
ICMP
IGMP
(MulGcast)
IPIP
IPv6
(encap)
RSVP
(MPLS)
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
/47
/50
/51
/89
/103
/112
DNS
DHCP
Server
DHCP
Client
NTP
SNMP
IPSec
RIP
LDP
(MPLS)
RSVP
(MPLS)
RSVP
(MPLS)
L2TP
User-Manager
User-Manager
uPnP
MME
MNDP
PPRP,
EoIP
IPSec
IPSec
OSPF
PIM
(MulGcast)
VRRP
24 July 2015
Connection State
Setiap paket data yang lewat memiliki status:
l
08-256
24 July 2015
Connection State
Firewall
New
08-257
Established
Related
Invalid
24 July 2015
Connection Tracking
Maximum Connection
yang bisa dihandle
08-258
24 July 2015
08-259
24 July 2015
08-260
24 July 2015
Connection Tracking
Dengan mematikan connection tracking, maka
fungsi berikut tidak bisa digunakan :
NAT
Parameter P2P pada simple queue
Firewall dengan parameter :
08-261
connection-bytes
connection-mark
connection-type
connection-state
connection-limit
connection-rate
layer7-protocol
p2p
new-connection-mark
tarpit
24 July 2015
IP Address List
Kita dapat melakukan pengelompokan IP
Address dengan Address List
08-262
24 July 2015
08-263
24 July 2015
Firewall NAT
Src-add = IP Google
Dst-add = IP Laptop
08-264
Src-add = IP Router
Dst-add = IP Google
Src-add = IP Google
Dst-add = IP Router
24 July 2015
masquerade
l
08-265
24 July 2015
Firewall NAT
08-266
24 July 2015
redirect
l
08-267
24 July 2015
Proxy
Laptop
08-268
24 July 2015
08-269
24 July 2015
08-270
24 July 2015
08-271
24 July 2015
Server
LAN
User Internet
24 July 2015
Quality of Service
Quality of Service
09-274
24 July 2015
Quality of Service
09-275
24 July 2015
09-276
24 July 2015
Internet
Upload 64 Kbps
Router MikroTik
09-277
Laptop
24 July 2015
09-278
24 July 2015
09-279
24 July 2015
09-280
24 July 2015
Tips
Jika kita perhatikan, ada perubahan warna
pada icon Queue rule. Maksud masing
masing warna adalah sebagai berikut :
Hijau : 0 50% bandwidth digunakan.
Kuning : 51 75% bandwidth digunakan
Merah : 76 100% bandwidth digunakan
09-281
24 July 2015
[LAB-2] Destination
Internet
128 Kbps
Router MikroTik
09-282
10 Mbps
Laptop
24 July 2015
09-283
24 July 2015
Destination
09-284
24 July 2015
Simple Queue
09-285
24 July 2015
Burst
09-286
24 July 2015
Rate(kbps)
512
Burst-limit
Average Rate
384
256
Max-limit
128
Burst-Threshold
Limit-at
64
09-287
10
15
20
time(s)
24 July 2015
09-288
24 July 2015
Topologi
Download 256 Kbps
Internet
Laptop
09-289
24 July 2015
09-290
Downstream max-limit=256k
Upstream max-limit=128k
Burst-limit=1M
Burst-threshold=512K
Burst-time=30s
24 July 2015
09-291
24 July 2015
Address :
l
Direction :
l
l
l
Upload
Download
Upload &
Download
Protocol :
l
Ip address test
server
TCP / UDP
09-292
Autentikasi
Mikrotik Indonesia http://www.mikrotik.co.id
24 July 2015
Staged Limitation
Pada RouterOS, dikenal 2 buah limitasi:
l
09-293
24 July 2015
Internet
Total Bandwith : 1 Mbps
Client 1 Bandwith:
Min : 256Kbps
Up-to 1Mbps
09-294
Client 2 Bandwith:
Min : 256Kbps
Up-to 1Mbps
Client 3 Bandwith:
Min : 256Kbps
Up-to 1Mbps
Client 4 Bandwith:
Min : 256Kbps
Up-to 1Mbps
24 July 2015
09-295
24 July 2015
09-296
24 July 2015
24 July 2015
Contoh soal : 1
Name: A
Parent: interface
Limit-at: 1mbps
Max-limit: 5mbps
Name: B
Parent: A
Limit-at: 2mbps
Max-limit: 5mbps
09-298
Name: C
Parent: A
Limit-at: 1mbps
Max-limit: 5mbps
Name: D
Parent: A
Limit-at: 2mbps
Max-limit: 5mbps
24 July 2015
09-299
24 July 2015
09-300
Priority : 1 tertinggi
Priority : 8 terendah
24 July 2015
Internet
192.168.0.0/24
24 July 2015
4 users
128k
queue=pcq-down
max-limit=512k
128k
73k
73k
73k
73k
128k
128k
09-302
7 users
128k
128k
73k
73k
73k
24 July 2015
2 users
7 users
73k
256k
73k
73k
queue=pcq-down
max-limit=512k
512k
73k
73k
256k
73k
73k
09-303
24 July 2015
09-304
24 July 2015
09-305
24 July 2015
VPN Basic
11-307
24 July 2015
VPN Networks
Internet
Branch Office 1
Head Office
Branch Office 2
24 July 2015
VPN Type
Bridge Network :
l
11-309
24 July 2015
11-310
24 July 2015
10.10.20.100/32
10.10.10.100/24
PPTP Tunnel
10.10.20.2/32
10.10.10.1/24
10.10.10.2/24
10.10.20.1/32
192.168.1.1/24
192.168.2.1/24
192.168.1.2/24
192.168.2.2/24
Meja 1
11-311
Meja 2
24 July 2015
11-312
24 July 2015
11-313
24 July 2015
PPTP Server
PPTP Tunnel
192.168.x.1/24
172.16.1.2/32
192.168.x.2/24
PPTP Client
11-314
24 July 2015
11-315
24 July 2015
11-316
24 July 2015
24 July 2015
PPP - Secret
11-318
24 July 2015
PPP - Profiles
PPP Profiles digunakan untuk
menentukan nilai-nilai default untuk catatan
akses pengguna disimpan di ppp secret /
ppp secret submenu
Pengaturan di / ppp secret akan di-override
sesuai pengaturan ppp profil kecuali
alamat IP selalu didahulukan dari IP pools
ketika ditetapkan sebagai local-address
atau remote-address parameter.
11-320
24 July 2015
10.20.20.100/32
10.10.10.100/24
PPPoE Tunnel
10.20.20.2/32
10.20.20.1/32
10.10.10.1/24
192.168.1.1/24
192.168.2.1/24
192.168.1.2/24
192.168.2.2/24
Meja 1
11-321
10.10.10.2/24
Meja 2
24 July 2015
11-322
24 July 2015
11-323
24 July 2015
10.20.20.1/32
PPPoE Server
192.168.x.1/24
10.20.20.2/32
192.168.x.2/24
PPPoE Client
11-324
24 July 2015
11-325
24 July 2015
11-326
24 July 2015
Quiz!
11-327
24 July 2015
[LAB-1] SSTP
Topologi
10.10.10.100/24
SSTP Tunnel
10.10.10.1/24
10.10.10.2/24
172.31.1.1/32
172.31.1.2/32
PPPoE
Meja 1
11-328
PPPoE
Meja 2
Mikrotik Indonesia http://www.mikrotik.co.id
24 July 2015
[LAB-1] SSTP
11-329
24 July 2015
11-330
24 July 2015
11-331
24 July 2015
11-332
24 July 2015
VPN Monitoring
11-333
24 July 2015