Professional Documents
Culture Documents
MTCNA (Basic) PDF
MTCNA (Basic) PDF
Jadwal Training
00-2
Session 1
Session 2
Hari 1
Introduction
Pre-Test
TCP/IP
Instalation
Hari 2
Bridge
Hari 3
Firewall
Hari 4
Hotspot
Session 3
Session 4
Basic Configuration
Wireless
Routing
QOS
VPN
Test
01/17/13
Jadwal Harian
00-3
Sessi 1
Coffee Break
Sessi 2
Lunch
Sessi 3
Coffee Break
Sessi 4
08.30 10.00
10.00 10.30
10.30 - 12.00
12.00 13.00
13.00 14.30
14.30 15.00
15.00 - 17.00
01/17/13
00-4
Basic/Essential Training
MikroTik Certified Network Associate (MTCNA)
Advanced Training
Certified Wireless Engineer (MTCWE)
Certified Routing Engineer (MTCRE)
Certified Traffic Control Engineer (MTCTCE)
Certified User Managing Engineer (MTCUME)
Certified Inter Networking Engineer (MTCINE)
01/17/13
Certification Test
00-5
01/17/13
Introduction to Mikrotik
One engineer:
Mikrotik Certified Consultant (2005)
http://www.mikrotik.com/consultants.html
01-7
01/17/13
Head Office
Rep. Office
01-8
01/17/13
What Is Mikrotik?
01-9
Wireless board
contoh: RB400, RB600, RB750, RB1000
Wireless interface (R52, R52H, R5H, R52N, R2N)
menggunakan RouterOS sebagai software
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
What Is Mikrotik?
01-10
01/17/13
Processor
RAM
Ether
RB800
MPC8544 800MHz
256MB
3 (gig)
RB435G
AR71xx 680MHz
256MB
3 (gig)
RB433UAH
AR71xx 680MHz
128MB
RB433/ AH
AR71xx
300/680MHz
64MB/128MB
4/5
RB411UAHR
64MB
RB411AH
64MB
RB411U/ AR
32MB/64MB
1/-
-/1
GrooveA5Hn
AR72xx 400MHz
64MB
RB711A-5nH
AR72xx 400MHz
64MB
Groove-5Hn
AR72xx 400MHz
32MB
RB711-5nH
AR72xx 400MHz
32M
01/17/13
Processor
RAM
Ethernet
MiniPCI
Lisensi
RB1100AH
X2
2GB
13 (gigabit)
RB1100AH
PPC 1Ghz
2GB
13 (gigabit)
RB1200
PPC 1Ghz
512MB
10 (gigabit)
RB493G
256MB
9 (gigabit)
64MB / 128MB
4/5
RB493 / AH
RB450G
256MB
5 (gigabit)
RB450
32MB
RB750
AR72xx 400MHz
32MB
RB750GL
AR72xx 400MHz
64MB
5 (gigabit)
01-12
01/17/13
Discontinued Hardware
RB100 series
01-13
RB230
RB333
RB411A,RB411R
RB532,RB511
RB600 series
RB600
RB700 series
RB400 series
RB500 series
RB300series
RB112,RB133,RB133C
RB153,RB150,RB192
RB200 series
RB750G
RB1000 series
RB1000, RB1100
01/17/13
RB1100AH / X2
RAM: 2GB
up to:
2 Gbps
1U rackmount
Bypass Function
RackMount
Case
01-14
01/17/13
RB800
3 Gigabit Ethernet
4 Minipci Slot
DoughterBoard Expandable
CF slot
MPC8544 800MHz CPU
256 DDR SDRAM
RouterOS Level 5
Doughter Board
01-15
01/17/13
RB433UAH
3 Ethernet, 3 Minipci
Atheros AR7161 680MHz
RAM: 128MB
With micro-SD slot
RouterOS Level 5
2 port USB
OutDoor Case
01-16
01/17/13
RB411 / U / AR / AH / UAHR
CPU: Atheros
Memory:
32 MB (411/U)
64MB (411AR/UAHR/AH)
1 ethernet
1 MiniPCI (411/U/AR/AH/UAHR)
Lisensi RouterOS:
01-17
Level 3 (411)
Level 4 (411U/AR/AH/UAHR)
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
RB493/AH/G
RAM: 64MB
RouterOS:
01-18
Level 4 (RB493)
Level 5 (RB493AH & G)
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
Embeded Solution
NEW
PRODUCT
01/17/13
RB450 / G
01-20
01/17/13
RB750 / GL
01-21
Produk routerboard
terhemat dan
terkecil
Processor :
AR7240 400Mhz
5 ethernet port (750)
5 gigabit port (750GL)
Lisensi Level 4
01/17/13
RB751U-2HND
High power 1W
802.11b/g/n wireless AP
5 Port Ethernet
1 Port USB
01-22
Intregated Antenna
For Modem
For Flashdisk
01/17/13
Wireless Interface
R52/H (a/b/g)
Atheros chipset
MiniPCI type interface
65 mWatt / 350 mWatt
3 band wireless
01-23
01/17/13
R52N (a/b/g/n)
01-24
NEW
PRODUCT
01/17/13
Wireless N - Performance
01-25
01/17/13
01-26
Industrial grade
Performance :
NEW
PRODUCT
01/17/13
Performance :
01-27
Industrial grade
PRODUCT
01/17/13
01-28
01/17/13
Mikrotik RouterOS
01-29
01/17/13
IP Routing
Interface
Bandwidth Management
01-30
Firewall
01/17/13
Services (Server)
AAA
01-31
Monitoring
VRRP
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
Licence Level
Level
Upgrade time
Wireless CPE/PTP
yes
Wireless AP
no
yes
Sync Interface
no
yes
EoIP
unlimited
PPPoE
200
200
500
unlimited
unlimited
unlimited
yes
Dynamic Routing
RB = yes
yes
200
500
unlimited
10
20
50
unlimited
01-32
01/17/13
01-33
01/17/13
Buyers Guide
01-34
RB1100AHx2
RB1200, RB1100AH
Mikrobits : Dinara
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
Quiz !
01-35
01/17/13
Mikrotik Installation
Installasi Mikrotik
Harddisk
CF Disk
DOM (Disk On Module)
02-37
Routerboard
01/17/13
Installation Method
CD
Netinstall
02-38
CD-Rom Required
PXE,EtherBoot Required
01/17/13
Download Area
02-39
01/17/13
CD Installation (1)
02-40
01/17/13
CD Installation (2)
02-41
01/17/13
CD Installation (3)
Choose Yes
Yes/No
02-42
Creating partition...
Formatting disk...
Software installed.
Press ENTER to reboot
01/17/13
Installation Check
02-43
Welcome menu
01/17/13
License Trial
02-44
01/17/13
02-45
01/17/13
02-46
01/17/13
02-47
01/17/13
02-48
01/17/13
Netinstall
Switch
Network:
192.168.1.0/24
IP Address:
192.168.1.10/24
RS-232
02-49
01/17/13
Netinstall
02-50
01/17/13
Netinstall
02-51
01/17/13
Netinstall - Config
02-52
01/17/13
02-53
01/17/13
02-54
01/17/13
02-55
01/17/13
Netinstall - Install
02-56
01/17/13
02-57
01/17/13
Netinstall - Install
02-58
01/17/13
Netinstall Reboot
02-59
01/17/13
Netinstall - Cleanup
02-60
Video Tutorial :
http://www.mikrotik.co.id/artikel_lihat.php?id=25
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
Reset Password
Hard Reset :
02-61
01/17/13
Quiz !
02-62
01/17/13
02-63
01/17/13
RouterOS Package
02-64
Nama Paket
advanced-tools
Fungsi
email client, ping, netwatch
dhcp
hotspot
hotspot gateway
ntp
NTP server
ppp
PPP,PPTP,L2TP,PPPoE
routerboard
routing
security
wireless
Wireless 802.11a/b/g
user-manager
ipv6
IPv6
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
Version Upgrade
02-65
01/17/13
FTP ke Router
IP Router
02-66
01/17/13
Version Downgrade
02-67
01/17/13
02-68
01/17/13
01/17/13
[TAB]
02-70
..
01/17/13
Quick Typing
/sys shut
= /system shutdown
02-71
http://wiki.mikrotik.com/wiki/Scripting
01/17/13
Quiz !
02-72
System
Routing
Advance-tools
DHCP
01/17/13
Basic TCP/IP
Training Outline
03-74
OSI Layer
Packet Header
Mac Address
IP Address and subnetting
IP Protocol
Basic networking, DNS, gateway
01/17/13
Internet Topologi
01/17/13
Application Set
Application
Transport
Link
Transport Set
Network
Open Systems
Interconnection (OSI)
adalah sebuah model
referensi arsitektur
antarmuka jaringan yang
dikembangkan oleh ISO
yang kemudian menjadi
konsep standard
komunikasi jaringan di
hampir semua perangkat
jaringan.
Physical
03-76
01/17/13
SMTP
HTTP
FTP
Telnet
DNS
DHCP
SNMP
TFTP
Session
Domain Resolve
TCP Data Session Maintenance
Transport
UDP
TCP
Transmission Control Protocol
Network
IP
ICMP
03-77
ARP
Link
Physical
01/17/13
Packet Header
IP version (4)
IP Header Length
Type of service
ver
IHL
ToS
16 bit total length
fragment offset flag/length
16 bit identification
TTL
protocol 16 bit header checksum
32 bit source IP Address
Time to Live
32 bit destination IP Address
options (if any)
data
03-78
01/17/13
MAC Address
03-79
01/17/13
IP Address
03-80
01/17/13
Pengelompokan IP Address
03-81
01/17/13
IP Subneting (contoh 1)
Contoh: 192.168.0.0/24
Netmask
: 255.255.255.0
Prefix
: /24
IP Network : 192.168.0.0
First HostIP: 192.168.0.1
Last HostIP : 192.168.0.254
Broadcast : 192.168.0.255
HostIP
: total IP di dalam Subnet () minus 2
03-82
01/17/13
IP Subneting (contoh 2)
Contoh: 192.168.0.0/25
Netmask
: 255.255.255.128
Prefix
: /25
IP Network : 192.168.0.0
First HostIP: 192.168.0.1
Last HostIP : 192.168.0.126
Broadcast : 192.168.0.127
HostIP
: total IP di dalam Subnet () minus 2
03-83
01/17/13
Tabel Subnet
03-84
Subnet Mask
Prefix
No of IP
Usable IP
255.255.255.0
/24
256
254
255.255.255.128
/25
128
126
255.255.255.192
/26
64
62
255.255.255.224
/27
32
30
255.255.255.240
/28
16
14
255.255.255.248
/29
255.255.255.252
/30
255.255.255.254
/31
255.255.255.255
/32
01/17/13
Quiz !
03-85
01/17/13
Public IP Address
Private IP Address
03-86
01/17/13
IP / subnet
Self Identification
0.0.0.0/8
Localhost
127.0.0.1
Not Used
Other 127.0.0.0/8
Multicast
224.0.0.0/4
169.245.0.0/16
TEST-NET-1
192.0.2.0/24
TEST-NET-2
198.51.100.0/24
TEST-NET-3
203.0.113.0/24
192.88.99.0/24
Benchmark Test
198.18.0.0/15
Future Used
240.0.0.0/4
Limited Broadcast
255.255.255.255/32
01/17/13
IP Protocol
03-88
01/17/13
03-89
Name
Echo Reply
Unassigned
Unassigned
Destination
Unreachable
Source Quench
Redirect
Alternate Host
Address
Unassigned
Echo
Router
Advertisement
10
Router Solicitation
11
Time Exceeded
01/17/13
03-90
01/17/13
03-91
01/17/13
Connection Oriented
Koneksi diawali dengan proses handshake
03-92
Client SYN
Server
Server SYN-ACK Client
Client ACK
Server
Reliable Transmission
Mampu melakukan pengurutan paket data, setiap
byte data ditandai dengan nomor yang unik
Error Detection
Jika terjadi error, bisa dilakukan pengiriman ulang
data
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
03-93
Flow Control
Mendeteksi supaya satu host tidak mengirimkan
data ke host lainnya terlalu cepat
Segment Size Control
Mendeteksi besaran MSS (maximum segment
size) yang bisa dikirimkan supaya tidak terjadi IP
fragmentation
Congestion Control
TCP menggunakan beberapa mekanisme untuk
mencegah terjadinya congestion pada network
01/17/13
Internet
192.168.0.4/24
192.168.0.246/24
192.168.0.191/24
192.168.0.26/24
192.168.0.41/24
03-94
192.168.0.142/24
01/17/13
Internet
192.168.0.74/24
10.10.10.34/24
192.168.0.254/24
192.168.1.254/24
192.168.1.48/24
192.168.0.4/24
192.168.0.141/24
192.168.1.4/24
03-95
192.168.1.24/24
01/17/13
Ether1
192.168.0.28/24
Ether3
192.168.4.151/24
03-96
Ether2
192.168.2.74/24
Ether4
192.168.5.211/24
01/17/13
192.168.0.254/24
Internet
192.168.0.4/24
192.168.0.246/24
192.168.0.191/24
192.168.0.26/24
192.168.0.41/24
03-97
192.168.0.142/24
01/17/13
03-98
01/17/13
Quiz !
03-99
01/17/13
RouterOS Basic
Configuration
Certified Mikrotik Training Basic Class
Organized by: Citraweb Nusa Infomedia
(Mikrotik Certified Training Partner)
Winbox - Download
04-101
01/17/13
WLAN1
10.10.10.1/24
WLAN1
10.10.10.X/24
ETHER1
192.168.1.1/24
ETHER1
192.168.2.1/24
ETHER1
192.168.X.1/24
ETHERNET PORT
192.168.1.2/24
ETHERNET PORT
192.168.2.2/24
ETHERNET PORT
192.168.X.2/24
MEJA 1
04-102
WLAN1
10.10.10.2/24
MEJA 2
Mikrotik Indonesia http://www.mikrotik.co.id
MEJA X
01/17/13
IP Configuration
Lab-1 adalah sebuah simulasi
konfigurasi dasar sebuah Router
Mikrotik yang akan digunakan di
jaringan local seperti Warnet,
Office, Kampus atau bahkan di
RT/RW-NET
X = nomor peserta
04-103
Routerboard Setting
WAN IP
: 10.10.10.x/24
Gateway
: 10.10.10.100
LAN IP
: 192.168.x.1/24
DNS
: 10.100.100.1
Src-NAT and DNS Server
Laptop Setting
IP Address : 192.168.x.2/24
Gateway
: 192.168.x.1
DNS
: 192.168.x.1
01/17/13
Laptop Config
04-104
01/17/13
First Setup
04-105
01/17/13
04-106
01/17/13
04-107
Aktifkan Interface
Wireless Wlan1
01/17/13
04-108
01/17/13
04-109
01/17/13
04-110
01/17/13
04-111
01/17/13
Konfigurasi DNS
Konfigurasi IP Address
Konfigurasi NAT
04-112
01/17/13
Installation Debug
04-113
01/17/13
04-114
01/17/13
[LAB-7] NTP
04-115
01/17/13
System - Clock
04-116
01/17/13
04-117
01/17/13
04-118
01/17/13
System Reset
04-119
01/17/13
04-120
01/17/13
04-121
01/17/13
04-122
01/17/13
04-123
01/17/13
DHCP Server
04-124
01/17/13
04-125
01/17/13
04-126
01/17/13
04-127
01/17/13
04-128
01/17/13
DHCP Test
04-129
01/17/13
DHCP Management
04-130
01/17/13
DHCP Static
04-131
01/17/13
DHCP Client
04-132
01/17/13
04-133
01/17/13
Interface
04-134
01/17/13
04-135
01/17/13
04-136
01/17/13
04-137
01/17/13
04-138
01/17/13
About User
04-139
01/17/13
04-140
01/17/13
04-141
IP-Winbox
Telnet
SSH
WebFig
01/17/13
04-142
01/17/13
04-143
01/17/13
ARP Table
Merupakan protokol
penghubung antara layer 2
data-link dan 3 network.
ARP Table di router
merupakan daftar host yang
terhubung langsung berisi
informasi pasangan mac
address dan
ip address.
Di IPv6 arp digantikan
dengan NDP (Network
Discovery Protocol).
04-144
01/17/13
04-145
01/17/13
ARP Protocol
04-146
01/17/13
ARP Security !
04-147
01/17/13
Monitoring - Ping
Tool monitoring
Ping
04-148
01/17/13
04-149
Flood Ping
01/17/13
Monitoring - Traceroute
Traceroute
04-150
Traceroute determines
how packets are being
routed to a particular
host
We can choose the
protocol : ICMP or UDP
01/17/13
Monitoring - Torch
04-151
01/17/13
Monitoring - Resource
Resource
04-152
To monitor the
System.
Detail Resource
monitor located on
right side buttons
01/17/13
04-153
01/17/13
Bridge - Concept
05-155
01/17/13
Ether6 Ether10
Configured as Bridge Mode
05-156
01/17/13
CLIENT
ROUTER
GATEWAY
WIRELESS
05-157
192.168.0.0/24
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
System Bridge
05-158
01/17/13
Ethernet
VLAN
PPTP
05-159
01/17/13
Bridge!
05-160
01/17/13
222.152.211.0/28
222.152.211.2
Public IP - WEB Server
Public IP - Client
222.152.211.3
222.152.211.4-222.152.211.10
05-161
01/17/13
192.168.10.1/24
05-162
Ether3
Ether1
Ether3
192.168.10.4/24
01/17/13
01/17/13
01/17/13
Bridge Monitoring
05-165
01/17/13
Switch Chipset
05-166
01/17/13
05-167
01/17/13
05-168
01/17/13
Quiz !
05-169
01/17/13
05-170
01/17/13
Network Skenario
Jogja Office
05-171
01/17/13
EoIP Example
Internet
City A
City B
10.0.0.1
10.10.10.2
EoIP
192.168.0.13
192.168.0.3
192.168.0.12
192.168.0.2
Secara Virtual setiap Laptop terletak di dalam satu segmen network yang sama.
05-172
01/17/13
05-173
01/17/13
Meja 30
Meja 31
Router A
10.10.10.30
Router B
10.10.10.31
EoIP
192.168.200.10
05-174
192.168.200.11
01/17/13
05-175
01/17/13
05-176
ROUTER B
01/17/13
01/17/13
Quiz !
05-178
01/17/13
Wireless Concept
802.11 2.4Ghz
802.11 5Ghz
06-180
01/17/13
Channels 80211-b
World Wide Band
915 MHz
2.4 GHz
26 MHz
84.5 MHz
2401
2423
5.8 GHz
125 MHz
2426
2448
2406
2428
2453
2433
2458
2438
2421
13
2463
2443
2446
2432
2430
Top of channel
14
2473
2452
Channel number
2483
2472
2441
2427
2420
2461
2447
2416
2478
2467
2436
2422
2410
12
2456
2442
2411
2473
2462
2431
2417
2400
11
2451
2437
2412
2495
2484
10
Center frequency
2468
2457
2440
2450
2460
2470
2480
MHz
Bottom of
channel
ISM Band
06-181
01/17/13
Channels 80211-a
36
40
42
44
48
5210
5150
5200
5220
5240
149
152 153
157
160 161
5760
06-182
5765
52
56
5250
5180
5735 5745
50
58
60
64
5300
5320
5290
5260
5280
5350
5800
5785
5805 5815
01/17/13
Kaidah Wireless :
06-183
01/17/13
EIRP
Path Loss
(FSL)
TX-Rate Pemancar
+ Kekuatan antenna pemancar
- Loss Kabel & konektor
06-184
Penguatan
Penerimaan
01/17/13
RX-Rate Calculation
Contoh Kasus :
Access Point 100 mWatt
tanpa booster
kabel LMR400 100 feet
antenna grid 24 db
frekuensi 2,4 GHz
jarak 10 km
06-185
01/17/13
Calculation Example
Perangkat
db
Pemancar (EIRP)
Access Point 100 mWatt
20 dbm
Kabel 30 meter
-6.8 db
Antenna 24 db
24 dbi
37.2 db
(EIRP)
-120.026 db
-6.8 db
Antenna 24 db
24 dbi
17.2 db
-65.626 db
01/17/13
Online
Calculator
06-187
www.mikrotik.co.id/
test_link.php
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
06-188
01/17/13
06-189
01/17/13
Earth Curve
06-190
01/17/13
06-191
http://www.mikrotik.co.id/test_tower.php
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
Antenna Concept
Directionality
Omnidirectional
Polarization
06-192
In db
Higher db, longer distance coverage
Ussualy using vertical polarization
01/17/13
Omni Directional
06-193
01/17/13
06-194
01/17/13
Grid Antenna
06-195
01/17/13
01/17/13
Sectoral Antenna
06-197
01/17/13
06-198
01/17/13
Point to Point
06-199
01/17/13
06-200
01/17/13
Point to Multipoint
1 buah AP Mikrotik sebagai base
station untuk melayani CPE
06-201
01/17/13
06-202
01/17/13
Wireless Configuration
Wireless Configuration
Basic Configuration :
Wireless Protocol
07-204
01/17/13
Scan Tool
07-205
01/17/13
Snoop Tool
07-206
01/17/13
Wireless Menu
Wireless Menu:
Interface Daftar Interface wireless yang terpasang
Access-List Security Mac-address Client (AP Mode)
Registration Daftar Wireless yang terkoneksi
Connect-List Security Mac-address AP (Station Mode)
Security-Profile Konfigurasi Wireless Security (WPA/WEP)
07-207
01/17/13
Wireless Mode :
07-208
alignment-only
ap-bridge
bridge
nstreme-dual-slave
station
station-wds
wds-slave
station-pseudobridge
station-pseudobridge-clone
station-bridge
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
Wireless Mode - 1
07-209
01/17/13
Wireless Mode 2
07-210
01/17/13
AP Side
Client Side
07-211
01/17/13
Konfigurasi :
Set mode, ssid, band dan frequency
mode=bridge
07-212
01/17/13
Konfigurasi :
Set mode, ssid, band
dan scan-list
mode=station
Pastikan frequency
yang dipilih oleh AP
masuk dalam range
scan-list
07-213
01/17/13
07-214
01/17/13
07-215
01/17/13
07-216
01/17/13
Wireless Bridge
07-217
01/17/13
07-218
01/17/13
AP
A
ethernet
Station
Wireless
connection
192.168.0.x/24
07-219
B
ethernet
192.168.0.x/24
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
07-220
01/17/13
Client Side:
07-221
01/17/13
01/17/13
01/17/13
07-224
01/17/13
07-225
01/17/13
07-226
01/17/13
07-227
01/17/13
Client Management
07-228
MAC Address
Signal Strength
Time
01/17/13
Klasifikasi mac-address
dari client
07-229
01/17/13
07-230
01/17/13
Wireless Security
07-231
01/17/13
Tentukan passwordnya
07-232
01/17/13
07-233
01/17/13
07-234
01/17/13
07-235
SSID
Mac-Address
IP Address
WDS
Security Profile
01/17/13
07-236
01/17/13
07-237
01/17/13
Mikrotik Nstreme
07-238
01/17/13
[LAB-9] Nstreme
07-239
01/17/13
07-240
01/17/13
Nstreme - Results
B
[
07-241
r
o
ef
]
e
]
r
e
t
f
[A
01/17/13
07-242
01/17/13
Wireless WDS
07-243
01/17/13
WDS - Config
Buat Bridge baru untuk WDS
Network
07-244
01/17/13
07-245
01/17/13
Routing
Routed Network
08-247
01/17/13
Routing Example
Ether2 Ether13
Configured as Routing Mode
(default)
Internet / WAN
192.168.0.0/24
LAN 1
08-248
LAN 2
192.168.1.0/24
Mikrotik Indonesia http://www.mikrotik.co.id
192.168.2.0/24
LAN 3
01/17/13
Routing Benefit
08-249
01/17/13
192.168.3.0/24
192.168.2.0/24
ROUTER
GATEWAY
WIRELESS
08-250
192.168.0.0/24
01/17/13
dynamic routes
yang akan dibuat secara otomatis:
08-251
static routes
adalah informasi routing yang dibuat secara
manual oleh user untuk mengatur ke arah
mana trafik tertentu akan disalurkan. Default
route adalah salah satu contoh static routes.
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
Menambahkan Routing
08-252
01/17/13
Tipe Routing
A: Active
S: Static
A: Active
D: Dynamic
C: Connected
08-253
01/17/13
08-254
Destination
Destination address 222.152.211.7
Network mask 202.53.246.0/24
0.0.0.0/0 -> ke semua network
Gateway
IP Address gateway, harus merupakan IP Address yang satu
subnet dengan IP yang terpasang pada salah satu interface
Gateway Interface
Digunakan apabila IP gateway tidak diketahui dan bersifat dinamik
(biasanya digunakan di ppp interface).
Pref Source
source IP address dari paket yang akan meninggalkan router
Distance
Beban untuk kalkulasi pemilihan routing
01/17/13
Internet
10.10.0.2/24
A
10.10.1.1/24
10.10.2.1/24
10.10.2.2/24
10.10.3.2/24
B
10.10.4.1/24
10.10.4.2/24
08-255
Dst-address=0.0.0.0/0 gateway=10.10.2.1
01/17/13
10.10.0.2/24
10.10.2.2/24
10.10.1.1/24
10.10.1.2/24
10.10.2.1/24
10.10.3.1/24
08-256
10.10.3.2/24
(DAC) Dst-addr= 10.10.3.0/24
pref-source=10.10.3.2
(AS) Dst-addr= 0.0.0.0/0 gw=10.10.3.1
01/17/13
08-257
Internet
10.10.10.100
10.10.10.1
10.10.10.2
Router 1
Router 2
192.168.1.1
192.168.2.1
192.168.1.2
192.168.2.2
01/17/13
Langkah-langkah
08-258
01/17/13
Distance
08-259
01/17/13
Contoh Pemilihan
Destination
Distance
Prioritas
192.168.0.0/27 192.168.1.1
192.168.0.0/29 192.168.2.1
192.168.0.0/24 192.168.3.1
192.168.0.0/24 192.168.4.1
08-260
Gateway
01/17/13
WLAN1:10.10.10.X/24
ETHER3:
10.Y.3.1/24
ETHER2:
10.Y.3.2/24
192.168.X.2/24
10.10.10.100/24
192.168.X.2/24
ETHER3:
10.Y.1.1/24
ETHER3:
10.Y.2.1/24
ETHER2:
10.Y.2.2/24
ETHER2:
10.Y.1.2/24
2
192.168.X.2/24
192.168.X.2/24
08-261
01/17/13
Dynamic Routing
08-262
01/17/13
Huge Network
08-263
01/17/13
08-264
01/17/13
Internet
Backbone Area
IR
Router 1
IR
Router 2
IR
Router X
LAN 2
LAN Y
LAN 1
08-265
01/17/13
OSPF - Configuration
08-266
01/17/13
08-267
01/17/13
Firewall
Firewall ?
Workstation
Switch
Server
Firewall
Internet
Laptop
09-269
01/17/13
Rules
NAT (source-nat and destination-nat)
Mangle
Address List
Layer 7 Protocol (baru di versi 3)
Service Ports
Connections
09-270
01/17/13
09-271
01/17/13
PRE
ROUTING
ROUTING
DECISION
MANGLE
FORWARD
OUTPUT
FILTER
FORWARD
POST
ROUTING
QUEUE
GLOBAL-IN
ROUTING
ADJUSTMENT
MANGLE
POSTROUTING
DST-NAT
FILTER
OUTPUT
QUEUE
GLOBAL-OUT
INPUT
MANGLE
PREROUTING
MANGLE
INPUT
MANGLE
OUTPUT
SRC-NAT
CONNECTION
TRACKING
FILTER
INPUT
CONNECTION
TRACKING
HTB
INTERFACE
INPUT
INTERFACE
LOCAL
PROCESS
ROUTING
DECISION
OUTPUT
INTERFACE
09-272
01/17/13
To
Router/
Local
Process
Mangle
Prerouting
Firewall
Queue
Global-In
Input
Input
Global-Total
Router/
Local
Process
Outside
Output
Output
Global-Out
Outside
Outside
Postrouting
Global-Total
Interface
Prerouting
Forward
Global-In
Forward
Postrouting
Global-Out
Global-Total
Interface
09-273
01/17/13
09-274
01/17/13
09-275
Prerouting
not
implemented
not
implemented
not
implemented
Input
yes
no
no
Forward
no
yes
no
Output
no
no
yes
Postrouting
not
implemented
not
implemented
not
implemented
01/17/13
RouterOS v5 Services
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
09-276
PORT
PROTOCOL
DESCRIPTION
20
21
22
23
53
80
179
443
646
1080
1723
1968
2000
2210
2211
2828
3128
8291
8728
-------
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
/1
/2
/4
FTP
FTP
SSH, SFTP
Telnet
DNS
HTTP
BGP
SHTTP (Hotspot)
LDP (MPLS)
SoCKS (Hotspot)
PPTP
MME
Bandwidth Server
Dude Server
Dude Server
uPnP
Web Proxy
Winbox
API
ICMP
IGMP (Multicast)
IPIP
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
PORT
PROTOCOL
DESCRIPTION
53
123
161
500
520
521
646
1698
1699
1701
1812
1813
1900
1966
5678
---------------
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
/46
/47
/50
/51
/89
/103
/112
DNS
NTP
SNMP
IPSec
RIP
RIP
LDP (MPLS)
RSVP (MPLS)
RSVP (MPLS)
L2TP
User-Manager
User-Manager
uPnP
MME
Neighbor Discovery
RSVP (MPLS)
PPRP, EoIP
IPSec
IPSec
OSPF
PIM (Multicast)
VRRP
01/17/13
Connection State
09-277
01/17/13
Connection State
Firewall
New
09-278
Established
Related
Invalid
01/17/13
Action Filter
09-279
01/17/13
Filter Rules
09-280
01/17/13
09-281
01/17/13
09-282
01/17/13
09-283
01/17/13
09-284
01/17/13
IP Address List
Kita dapat melakukan pengelompokan IP Address dengan
Address List
09-285
01/17/13
09-286
01/17/13
Firewall NAT
INCOMING
INCOMING
OUTGOING
OUTGOING
NAT ROUTER
INCOMING
INCOMING
PUBLIC NETWORK
PRIVATE NETWORK
OUTGOING
OUTGOING
09-287
01/17/13
masquerade
09-288
01/17/13
redirect
09-289
01/17/13
Firewall NAT
09-290
01/17/13
Konsep Proxy
Internet
PROXY
09-291
Internet
01/17/13
Access list
09-292
Logging facility
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
09-293
01/17/13
Mengaktifkan Proxy
09-294
01/17/13
Redirect TCP-80
09-295
01/17/13
Akses
09-296
01/17/13
Penyimpanan Cache
System Disk
Hardisk
Flash memory
Format terlebih
dahulu
09-297
01/17/13
09-298
01/17/13
Proxy - Cache
09-299
Aktifkan Cache On
Disk untuk
mengaktifkan Mikrotik
Proxy Cache.
Perhatikan pada pada
parameter Cache
Drive sudah
menggunakan USB
disk.
01/17/13
09-301
01/17/13
09-302
01/17/13
09-303
01/17/13
09-304
01/17/13
09-305
01/17/13
09-306
01/17/13
09-307
01/17/13
Quality of Service
Quality of Service
10-309
01/17/13
Quality of Service
10-310
01/17/13
Simple Queue
10-311
01/17/13
10-312
Target Address :
IP Address client yang
akan dilimit
01/17/13
10-313
01/17/13
10-314
01/17/13
Burst
10-315
01/17/13
Max-limit=256kbps, burst-time=8,
burst-threshold=192kbps, burst-limit=512kbps.
Actual Rate
Rate(kbps)
512
Burst-limit
Average Rate
384
256
Max-limit
192
Burst-Threshold
128
Limit-at
10-316
10
15
20
time(s)
01/17/13
10-317
01/17/13
10-318
01/17/13
10-319
Downstream max-limit=256k
Upstream max-limit=128k
Burst-limit=1M
Burst-threshold=512K
Burst-time=30s
01/17/13
10-320
01/17/13
Address :
Direction :
Upload
Download
Upload &
Download
Protocol :
Ip address test
server
TCP / UDP
10-321
Autentikasi
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
Staged Limitation
10-322
01/17/13
Bandwith share
1Mbps 1:4
Client 4 Bandwith:
Min : 256Kbps
Up-to 1Mbps
Client 2 Bandwith:
Min : 256Kbps
Up-to 1Mbps
Client 1 Bandwith:
Min : 256Kbps
Up-to 1Mbps
10-323
Client 3 Bandwith:
Min : 256Kbps
Up-to 1Mbps
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
10-324
01/17/13
10-325
01/17/13
10-326
01/17/13
Contoh soal : 1
Name: A
Parent: interface
Limit-at: 1mbps
Max-limit: 5mbps
Name: B
Parent: A
Limit-at: 2mbps
Max-limit: 5mbps
10-327
Name: C
Parent: A
Limit-at: 1mbps
Max-limit: 5mbps
Name: D
Parent: A
Limit-at: 2mbps
Max-limit: 5mbps
01/17/13
Contoh soal : 2
Name: A
Parent: interface
Max-limit: 5mbps
Name: B
Parent: A
Limit-at: 2mbps
Max-limit: 4mbps
Name: C
Parent: A
Limit-at: 2mbps
Max-limit: 4mbps
Name: C1
Parent: C
Limit-at: 1mbps
Max-limit: 4mbps
10-328
Name: C2
Parent: C
Limit-at: 2mbps
Max-limit: 4mbps
01/17/13
10-329
01/17/13
Graph
10-330
01/17/13
192.168.0.0/24
Bandwith share
254 Client
01/17/13
Skema PCQ
pcq-clasifier
src-address
sub-queue
Algoritma
Round
Robin
SRC-ADDRESS=10.0.0.1
SRC-ADDRESS=10.0.0.2
Flow 1
Flow 2
Flow 3
SRC-ADDRESS=10.0.0.3
SRC-ADDRESS=10.0.0.4
ke
interface
SRC-ADDRESS=10.0.0.5
Flow 4
SRC-ADDRESS=10.0.0.6
SRC-ADDRESS=10.0.0.7
10-332
01/17/13
Pcq-rate=128000
2 users
4 users
128k
queue=pcq-down
max-limit=512k
128k
73k
73k
73k
73k
128k
128k
10-333
7 users
128k
128k
73k
73k
73k
01/17/13
Pcq-rate=0
1 user
2 users
7 users
73k
256k
73k
73k
queue=pcq-down
max-limit=512k
512k
73k
73k
256k
73k
73k
10-334
01/17/13
10-335
01/17/13
10-336
01/17/13
10-337
01/17/13
Mangle
10-338
01/17/13
10-339
01/17/13
10-340
Prerouting
yes
yes
no
Input
yes
no
no
Forward
no
yes
no
Output
no
no
yes
Postrouting
no
yes
yes
01/17/13
Type of Mark
Packet Mark
Connection Mark
Route Mark
10-341
01/17/13
Connection Mark
10-342
01/17/13
Passthrough
Passthrough=no
Passthrough=yes
Biasanya pada :
10-343
01/17/13
192.168.0.0/24
TCP
ICMP
UDP
Sisa
10-344
01/17/13
10-345
01/17/13
10-346
01/17/13
10-347
01/17/13
10-348
01/17/13
10-349
01/17/13
10-350
01/17/13
10-351
01/17/13
10-352
01/17/13
10-353
01/17/13
10-354
01/17/13
10-355
01/17/13
10-356
01/17/13
QueueTree Parent
10-357
01/17/13
10-358
01/17/13
10-359
01/17/13
10-360
01/17/13
10-361
01/17/13
QueueTree - Action
10-362
01/17/13
Hotspot
HotSpot
11-364
01/17/13
Wired Network
Hotspot Gateway
11-365
01/17/13
11-366
01/17/13
11-367
01/17/13
HotSpot features
11-368
Autentikasi User
Perhitungan
Waktu akses
Data dikirim atau diterima
Limitasi Data
Berdasarkan data rate (kecepatan akses)
Berdasarkan jumlah data
Limitasi Akses User berdasarkan waktu
Support RADIUS
Bypass!
Mikrotik Indonesia http://www.mikrotik.co.id
01/17/13
11-369
01/17/13
11-370
01/17/13
11-371
01/17/13
11-372
01/17/13
11-373
01/17/13
11-374
01/17/13
11-375
01/17/13
11-376
01/17/13
Authentication Method
01/17/13
11-378
01/17/13
11-379
01/17/13
User Profiles
Untuk melakukan log-off otomatis
bagi user yang tidak ada traffic atau
lupa menekan tombol log-off.
Untuk menentukan jumlah user maksimal jika
menggunakan username yang sama.
Untuk menentukan bandwith peruser yang menggunakan profile
yang sama.
Format : Upload / Download
11-380
01/17/13
HotSpot User
11-381
01/17/13
HotSpot users
11-382
01/17/13
User Limitation
Limit Uptime batas
waktu user dapat
menggunakan akses
ke Hotspot Network.
Limit-bytes-in,
Limit-bytes-out dan
Limit-bytes-total
batas quota trasfer
data yang bisa
dilakukan oleh user.
11-383
01/17/13
Bypass! - IP bindings
11-384
01/17/13
HotSpot IP bindings
11-385
01/17/13
Bypass - WalledGarden
11-386
01/17/13
HTTP-level WalledGarden
11-387
01/17/13
IP-WalledGarden
11-388
01/17/13
Advertisement
11-389
01/17/13
Advertisement
11-390
01/17/13
VPN Basic
12-392
01/17/13
VPN Networks
Aplication Server
Office 1
PC
Aplication Server
Router
PC
File Server
Office 2
Router
WAN
PC
PC
VPN Networks
File Server
Office 3
Router
PC
12-393
PC
PC
PC
01/17/13
VPN Type
Bridge Network :
12-394
01/17/13
12-395
01/17/13
12-396
01/17/13
12-397
01/17/13
12-398
01/17/13
12-399
01/17/13
12-400
01/17/13
12-401
01/17/13
12-402
01/17/13
12-403
01/17/13
12-404
01/17/13
PPP - Secret
12-405
01/17/13
12-406
01/17/13
PPPoE Server
12-407
01/17/13