Professional Documents
Culture Documents
Original Mikrotik Mtcna-0905 PDF
Original Mikrotik Mtcna-0905 PDF
Basic
Jadwal Training
Day 1
Day 2
Day 3
Day 4
00-2
Sessi 1
Sessi 2
Introduction
TCP/IP
Installation
Basic
Configuration
Wireless
Firewall
Lab
Sessi 3
Static
Route
Sessi 4
Bridge
EOIP
Hotspot
QoS
PPTP
Test
29-May-09
Jadwal Harian
00-3
Sessi 1
Coffee Break
Sessi 2
Lunch
Sessi 3
Coffee Break
Sessi 4
08.30 10.00
10.00 10.30
10.30 - 12.00
12.00 13.00
13.00 14.30
14.30 15.00
15.00 - 17.00
29-May-09
Basic/Essential Training
Advance Training
Wireless
Routing
Traffic Management
00-4
29-May-09
Certification Test
00-5
29-May-09
Introduction to
Mikrotik
One engineer:
Mikrotik Certified Consultant (2005)
http://www.mikrotik.com/consultants.html
01-2
Head Office
Rep. Office
01-3
01-4
29-May-09
01-5
29-May-09
Pemilihan Routerboard
Kinerja Processor
Memori (RAM)
Jumlah interface
Level Lisensi
01-6
Ethernet
MiniPCI
Level 3 wireless client / PTP
Level 4 wireless access point
Custom Frequency ?
29-May-09
01-7
Jenis
Processor
RB600
PPC266/400
RAM
Ethernet
128MB 3 (gigabit)
MiniPCI
Lisensi
RB433AH
Atheros AR7161
128MB
680 MHz/800MHz
RB433
Atheros AR7130
300 MHz
64MB
RB411AH
Atheros AR7161
680 MHz/800MHz
64MB
RB411A
Atheros AR7130
300 MHz
64MB
RB411
Atheros AR7130
300 MHz
32MB
29-May-09
01-8
Jenis
Processor
RB1000
PPC 1333MHz
RB493AH
RAM
Ethernet
MiniPCI
Lisensi
512MB 4 (gigabit)
Atheros AR7161
680 MHz/800MHz
64MB
RB493
Atheros AR7130
300 MHz
64MB
RB450G
Atheros AR7161
680 MHz/800MHz
256MB 5 (gigabit)
RB450
Atheros AR7130
300 MHz
32MB
29-May-09
Discontinued Hardware
01-9
RB230
RB112
RB133
RB333
RB532
RB150
RB192
RB153
29-May-09
RB1000
4 gigabit ethernet
0 minipci
1333 MHz processor
RAM: 512MB
up to:
01-10
3 Gbps
340.000 pps
29-May-09
RB600
3 gigabit ethernet
4 minipci slot
MPC8343E 266/400MHz
network CPU
RouterOS Level 4
01-11
29-May-09
RB433UAH
01-12
3 ethernet, 3 minipci
Atheros AR7161 680MHz
RAM: 128MB
With micro-SD slot
RouterOS Level 5
2 port USB
29-May-09
RB433
01-13
3 ethernet, 3 minipci
Atheros AR7130 300 MHz
RAM: 64MB
RouterOS Level 4
29-May-09
CPU: Atheros
Memory:
32 MB (411)
1 minipci, 1 ethernet
01-14
Lisensi RouterOS:
Level 3 (411)
Level 4 (411A & 411AH)
29-May-09
MikroPoynt
01-15
NEW
PRODUCT
Embedded
Antenna 2,4GHz
11db1
With Routerboard
411 series
29-May-09
RB493(AH)
9 ethernet, 3 minipci
Processor :
RAM: 64MB
RouterOS:
01-16
Level 4 (RB493)
Level 5 (RB493AH)
29-May-09
RB450G
01-17
5 gigabit port
Tanpa minipci port
Processor : Atheros
AR7161 680 MHz
RAM: 256 MB
RouterOS Level 4
29-May-09
Hardware (Interface)
R52
Atheros chipset
MiniPCI type
interface
65 mWatt
3 band wireless
Custom Frequency
Support
01-18
29-May-09
Hardware (Interface)
R52H
Atheros chipset
MiniPCI type
interface
350 mWatt
3 band wireless
01-19
2.4 GHz,
5.2 GHz,
5.8 GHz
2.1 2.5 GHz
4.9 6.0 GHz
29-May-09
R52N
01-20
NEW
PRODUCT
29-May-09
R2N
01-21
NEW
PRODUCT
29-May-09
RB600 + R52N
01-22
29-May-09
Hardware (Interface)
RB44
01-23
29-May-09
Hardware (Interface)
RB44GV
01-24
10/100/1000 Mbps
Chipset VIA VT6122
29-May-09
Mikrotik RouterOS
01-25
29-May-09
Keunggulan
01-26
29-May-09
Penggunaan Kernel
01-27
29-May-09
Hardware Compability
(versi 3.x)
01-28
29-May-09
RB44 Test
01-29
6 pcs RB44
Total of 24 ethernet ports
29-May-09
IP Routing
Interface
Bandwidth Management
01-30
Firewall
29-May-09
Services
AAA
01-31
Monitoring
VRRP
Mikrotik Indonesia http://www.mikrotik.co.id
29-May-09
Licence Level
Level
Upgrade time
Wireless CPE/PTP
yes
Wireless AP
no
yes
Sync Interface
no
yes
EoIP
unlimited
PPPoE
200
200
500
unlimited
unlimited
unlimited
yes
Dynamic Routing
01-32
RB = yes
yes
200
500
unlimited
10
20
50
unlimited
29-May-09
Pembelian Lisensi
01-33
29-May-09
Checking Licence
01-34
29-May-09
01-35
Fungsi perangkat
Jumlah trafik
Fitur yang dibutuhkan
Interface yang dibutuhkan
29-May-09
Berdasarkan Processor
PC
Routerboard System
01-36
29-May-09
Kebutuhan Router
01-37
untuk WAN
untuk LAN
untuk kebutuhan khusus (proxy, server)
29-May-09
Fungsi Web-Proxy
01-38
29-May-09
GSM Router
01-39
29-May-09
Wireless Device
01-40
29-May-09
Wireless Repeater
01-41
29-May-09
01-42
29-May-09
Kebutuhan Gigabit
01-43
PC + DOM + RB44GV
RB1000
RB600
RB450G
29-May-09
01-44
PC + License Level 6
RB1000
RB433AH (maksimal 50 active users)
RB433UAH (maksimal 50 active users)
29-May-09
Mikrotik
Installation
Installasi Mikrotik
Harddisk
CF Disk
DOM (Disk On Module)
02-2
Routerboard
29-May-09
Installation
CD
Netinstall
02-3
29-May-09
Download Area
mikrotik.co.id
02-4
29-May-09
CD Installation (1)
02-5
29-May-09
CD Installation (2)
02-6
29-May-09
CD Installation (2)
Choose Yes
Yes/No
Creating partition...
Formatting disk...
Software installed.
02-7
29-May-09
Installation
02-8
Welcome menu
Level 0
Softwere id =
F724-MMT
29-May-09
Installation
02-9
License level 0
Demo time
15:39:27 jam
Copy license key
tekan tombol
Paste Key
29-May-09
Netinstall
Switch
Network:
192.168.1.0/24
IP Address:
192.168.1.10/24
RS-232
Serial null modem
console cable
02-10
29-May-09
Netinstall
02-11
29-May-09
02-12
29-May-09
02-13
29-May-09
02-14
29-May-09
Netinstall Software
02-15
29-May-09
Netinstall Software
02-16
29-May-09
Netinstall Software
02-17
29-May-09
System Package
02-18
29-May-09
Paket di RouterOS
02-19
Nama Paket
Fungsi
advanced-tools
dhcp
hotspot
hotspot gateway
ntp
NTP server
ppp
PPP,PPTP,L2TP,PPPoE
routerboard
routing
security
wireless
Wireless 802.11a/b/g
user-manager
ipv6
IPv6
Mikrotik Indonesia http://www.mikrotik.co.id
29-May-09
Version Upgrade
Download modul
02-20
routeros-mipsbe-3.xx.npk (RB400)
routeros-mipsle-3.xx.npk (RB100 & RB500)
routeros-powerpc-3.xx.npk (RB300 & RB600)
routeros-x86-3.xx.npk (PC & RB200)
Harus menggunakan userid yang full access
Reboot
29-May-09
Version Downgrade
Download modul
FTP modul tersebut ke router
Cek modul : /file print
/system package downgrade
admin@MikroTik] system package> downgrade
Router will be rebooted. Continue? [y/N]: y
system will reboot shortly
02-21
29-May-09
02-22
29-May-09
29-May-09
29-May-09
Quick Typing
02-25
= /system shutdown
29-May-09
RouterOS Basic
Configuration
WLAN1
10.10.10.1/24
WLAN1
10.10.10.X/24
ETHER1
192.168.1.1/24
ETHER1
192.168.2.1/24
ETHER1
192.168.X.1/24
ETHERNET PORT
192.168.1.2/24
ETHERNET PORT
192.168.2.2/24
ETHERNET PORT
192.168.X.2/24
MEJA 1
03-2
WLAN1
10.10.10.1/24
MEJA 2
Mikrotik Indonesia http://www.mikrotik.co.id
MEJA X
29-May-09
IP Configuration
Lab-1 adalah sebuah
simulasi konfigurasi dasar
sebuah Router Mikrotik
yang akan digunakan di
jaringan local seperti
warnet, office, kampus
atau bahkan di RT/RWNET
X = nomor peserta
03-3
Routerboard Setting
WAN IP
: 10.10.10.x/24
Gateway
: 10.10.10.100
LAN IP
: 192.168.x.1/24
DNS
: 10.100.100.1
Src-NAT and DNS Server
Laptop Setting
IP Address : 192.168.x.2/24
Gateway
: 192.168.x.1
DNS
: 192.168.x.1
29-May-09
03-4
29-May-09
03-5
29-May-09
Konfigurasi Wireless
03-6
Aktifkan Interface
Wireless pada
Ether1
Mikrotik Indonesia http://www.mikrotik.co.id
29-May-09
03-7
29-May-09
03-8
29-May-09
Firewall-Src-NAT
03-9
29-May-09
Konfigurasi IP Address
Konfigurasi NAT
03-10
Konfigurasi DNS
29-May-09
03-11
29-May-09
03-12
29-May-09
03-13
29-May-09
03-14
29-May-09
System Reset
03-15
29-May-09
03-16
29-May-09
4
192.168.1.1
6
7
03-17
29-May-09
03-18
29-May-09
03-19
29-May-09
03-20
29-May-09
03-21
29-May-09
Keamanan DHCP
03-22
ARP=reply-only
Client yang bisa terkoneksi hanyalah yang
mendapatkan IP Address melalui proses DHCP,
bukan pengisian manual
29-May-09
03-23
29-May-09
03-24
29-May-09
Interface
03-25
29-May-09
03-26
29-May-09
03-27
29-May-09
03-28
29-May-09
03-29
29-May-09
03-30
29-May-09
03-31
29-May-09
03-32
29-May-09
03-33
Setting clock
/system clock
Set enable
/system ntp server set enabled=yes
Mikrotik Indonesia http://www.mikrotik.co.id
29-May-09
NTP Client
Konfigurasi
03-34
Set enable
Set mode unicast
Set IP NTP server
Set time zone
pada menu
/system clock
29-May-09
4 fase sinkronisasi
03-35
Started
: start service NTP
Reached
: terkoneksi dengan NTP server
Timeset
: mengganti waktu/tanggal lokal
sesuai waktu NTP server
Synchronized :mengganti jam lokal sama
dengan jam NTP server
29-May-09
Monitoring
Tool monitoring
Ping
03-36
29-May-09
Monitoring
03-37
Mac Ping
29-May-09
Monitoring
03-38
Flood Ping
29-May-09
Monitoring
Torch
Realtime Traffic Monitor
called also torch is used
for monitoring traffic
that is going through
an interface.
03-39
29-May-09
Monitoring
Traceroute
03-40
Traceroute determines
how packets are being
routed to a particular
host
We can choose the
protocol : ICMP or UDP
29-May-09
Proxy
03-41
29-May-09
Konsep Proxy
PROXY
03-42
29-May-09
Konsep Proxy
03-43
29-May-09
Kebutuhan Proxy
PC Router :
03-44
29-May-09
Access list
03-45
Logging facility
Mikrotik Indonesia http://www.mikrotik.co.id
29-May-09
Setup Proxy
03-46
29-May-09
Mengaktifkan Proxy
03-47
29-May-09
Redirect TCP-80
03-48
29-May-09
Akses
03-49
Mengatur hak
akses client
29-May-09
Cache
03-50
29-May-09
03-51
29-May-09
Storage
Penyimpanan Cache
03-52
System
Harddisk
29-May-09
Basic TCP/IP
Computer Network
04-2
29-May-09
04-3
29-May-09
OSI Layer
04-4
Presentation
Session
Transport
Network
Data
Physical
Transport Set
Application
Application Set
29-May-09
Application
Presentation
Session
Transport
Network
Data
Physical
04-5
29-May-09
Application
Presentation
Session
Transport
Network
Data
Physical
04-6
29-May-09
Application
Presentation
Session
Transport
Network
Data
Physical
04-7
29-May-09
Application
Presentation
Session
Transport
Network
Data
Physical
04-8
29-May-09
Application
Presentation
Session
Transport
Network
Data
Physical
04-9
29-May-09
Application
Presentation
Session
Transport
Network
Data
Physical
04-10
29-May-09
Application
Presentation
Session
Transport
Network
Data
Physical
04-11
29-May-09
04-12
29-May-09
Hal ini dikarenakan NIC beroperasi dalam lapisan fisik dan lapisan datalink dan menggunakan alamat fisik daripada menggunakan alamat logis
(seperti halnya alamat IP atau nama NetBIOS) untuk melakukan
komunikasi data dalam jaringan.
04-13
29-May-09
Alamat IP versi 4 (sering disebut dengan Alamat IPv4) adalah sebuah jenis
pengalamatan jaringan yang digunakan di dalam protokol jaringan TCP/IP
yang menggunakan protokol IP versi 4. Panjang totalnya adalah 32-bit, dan
secara teoritis dapat mengalamati hingga 4 miliar host komputer di seluruh
dunia. Contoh alamat IP versi 4 adalah 192.168.0.3.
29-May-09
Netmask: 255.255.255.0
11111111.11111111.11111111. 00000000
Network:
192.168.0.0
11000000.10101000.00000000. 00000000
HostMin:
192.168.0.1
11000000.10101000.00000000. 00000001
HostMax: 192.168.0.254
11000000.10101000.00000000. 11111110
Broadcast: 192.168.0.255
11000000.10101000.00000000. 11111111
04-15
29-May-09
Netmask
04-16
29-May-09
IP Version
04-17
IP version 4
x.x.x.x (x 0-255) - 32 bit - 4,294,967,296 possible IP addreses.
IP version 6
hhhh:hhhh:hhhh:hhhh:hhhh:hhhh:hhhh:hhhh
128 bit
Not used
0.0.0.0 0.255.255.255
Localhost
127.0.0.1
Other 127.x.x.x not used
Private IP Address (intranet IP) RFC 1918
10.0.0.0 10.255.255.255 (10./8)
172.16.0.0 172.31.255.255 (172.16./12)
192.168.0.0 192.168.255.255 (192.168./16)
Mikrotik Indonesia - http://www.mikrotik.co.id
29-May-09
Packet Header
IP version (4)
IP Header Length
Type of service
ver
IHL
ToS
16 bit total length
fragment offset flag/length
16 bit identification
TTL
protocol 16 bit header checksum
32 bit source IP Address
Time to Live
32 bit destination IP Address
options (if any)
data
04-18
29-May-09
Packet Header
04-19
29-May-09
Packet Header
04-20
29-May-09
IP Subneting
192.168.0.0/25
Netmask
: 255.255.255.128
Prefix
: /25
IP Network : 192.168.0.0
First HostIP: 192.168.0.1
Last HostIP : 192.168.0.126
Broadcast : 192.168.0.127
HostIP
: total IP di dalam Subnet () minus 2
04-21
29-May-09
Tabel Subnet
04-22
Subnet Mask
Prefix
No of IP
Usable IP
255.255.255.0
/24
256
254
255.255.255.128
/25
128
126
255.255.255.192
/26
64
62
255.255.255.224
/27
32
30
255.255.255.240
/28
16
14
255.255.255.248
/29
255.255.255.252
/30
255.255.255.254
/31
255.255.255.255
/32
29-May-09
Protocol
04-23
29-May-09
04-24
29-May-09
04-25
29-May-09
ICMP berbeda tujuan dengan TCP dan UDP dalam hal ICMP tidak digunakan
secara langsung oleh aplikasi jaringan milik pengguna. salah satu
pengecualian adalah aplikasi ping yang mengirim pesan ICMP Echo Request
(dan menerima Echo Reply) untuk menentukan apakah komputer tujuan dapat
dijangkau dan berapa lama paket yang dikirimkan dibalas oleh komputer
tujuan.
Typ e N a m e
04-26
0
1
2
3
4
5
6
7
8
9
10
11
Echo Re p ly
Una ssig ne d
Una ssig ne d
D e st ina t ion Unre a cha b le
Source Que nch
Re d ire ct
Alt e rna t e H ost Ad d re ss
Una ssig ne d
Echo
Rout e r Ad ve rt ise m e nt
Rout e r Solicit a t ion
Tim e Exce e d e d
29-May-09
04-27
29-May-09
Static Route
Routed Network
05-2
29-May-09
Routing!
05-3
29-May-09
Routing
192.168.1.0/24
192.168.3.0/24
192.168.2.0/24
ROUTER
GATEWAY
WIRELESS
05-4
192.168.0.0/24
29-May-09
dynamic routes
yang akan dibuat secara otomatis:
05-5
static routes
adalah informasi routing yang dibuat secara
manual oleh user untuk mengatur ke arah
mana trafik tertentu akan disalurkan. Default
route adalah salah satu contoh static routes.
Mikrotik Indonesia http://www.mikrotik.co.id
29-May-09
Menambahkan Routing
05-6
29-May-09
Tipe Routing
A: Active
S: Static
A: Active
D: Dynamic
C: Connected
05-7
29-May-09
05-8
Destination
Destination address & network mask
0.0.0.0/0 -> ke semua network
Gateway
IP Address gateway, harus merupakan IP Address yang satu
subnet dengan IP yang terpasang pada salah satu interface
Gateway Interface
Digunakan apabila IP gateway tidak diketahui dan bersifat
dinamik.
Pref Source
source IP address dari paket yang akan meninggalkan router
Distance
Beban untuk kalkulasi pemilihan routing
29-May-09
10.10.0.2/24
A
10.10.1.1/24
10.10.2.1/24
10.10.2.2/24
10.10.3.2/24
B
10.10.4.1/24
10.10.4.2/24
05-9
Dst-address=0.0.0.0/0 gateway=10.10.2.1
29-May-09
10.10.0.1/24
10.10.0.2/24
10.10.2.2/24
10.10.1.1/24
10.10.1.2/24
10.10.2.1/24
05-10
29-May-09
10.10.0.2/24
10.10.2.2/24
10.10.1.1/24
10.10.1.2/24
10.10.2.1/24
10.10.3.1/24
10.10.3.2/24
(DAC) Dst-addr= 10.10.3.0/24
pref-source=10.10.3.2
05-11
29-May-09
Distance
05-12
29-May-09
Contoh Pemilihan
Destination
05-13
Gateway
Distance
Prioritas
192.168.0.0/27 192.168.1.1
192.168.0.0/29 192.168.2.1
192.168.0.0/24 192.168.3.1
192.168.0.0/24 192.168.4.1
29-May-09
05-14
10.10.10.100
Router 1
10.10.10.1
Router 2
10.10.10.2
192.168.1.1
192.168.2.1
192.168.1.2
192.168.2.2
29-May-09
Langkah-langkah
05-15
29-May-09
192.168.X.2/24
WLAN1:10.10.10.X/24
10.10.10.100/24
WLAN2:
10.Y.1.1/24
192.168.X.2/24
AP
WLAN2:
10.Y.2.1/24
WLAN1:
10.Y.2.2/24
AP
WLAN1:
10.Y.1.2/24
AP
192.168.X.2/24
192.168.X.2/24
05-16
29-May-09
AP
WLAN2:
10.Y.1.1/24
10.10.10.100/24
WLAN2:
10.10.10.X/24
WLAN2:
10.Y.3.1/24
WLAN1:
10.Y.3.2/24
192.168.X.2/24
192.168.X.2/24
AP
WLAN2:
10.Y.2.1/24
WLAN1:
10.Y.2.2/24
AP
WLAN1:
10.Y.1.2/24
AP
192.168.X.2/24
192.168.X.2/24
05-17
29-May-09
Bridge
06-2
29-May-09
Sistem Bridge
192.168.0.1
192.168.0.100-254
ROUTER
GATEWAY
WIRELESS
192.168.0.2
06-3
29-May-09
Sistem Bridge
CLIENT
ROUTER
GATEWAY
WIRELESS
192.168.0.2
192.168.0.100-254
06-4
29-May-09
Sistem Bridge
06-5
29-May-09
Bridge Interface
Ethernet
VLAN
PPTP
06-6
29-May-09
Perhatikan!
06-7
29-May-09
Membuat Bridge
06-8
29-May-09
Konfigurasi Bridge
Secara default, jika kita menggunakan bridge, maka rule yang ada di firewall
tidak akan berpengaruh. Aktifkanlah setting ini jika dibutuhkan.
06-9
29-May-09
06-10
29-May-09
06-11
29-May-09
Bridge Ports
Setelah ketiga interface dimasukkan ke dalam bridge
06-12
29-May-09
10.10.10.51-150/24
06-13
10.10.10.151-250/24
29-May-09
Perhatikanlah IP Route
Sebelum bridge dibuat IP Address terletak
pada interface masing-masing
06-14
29-May-09
IP Route
06-15
29-May-09
Bridge Monitoring
06-16
29-May-09
192.168.10.1/24
06-17
Ether3
192.168.10.2/24
Ether3
Ether1
192.168.10.4/24
192.168.10.3/24
29-May-09
Bridge Loop
06-18
29-May-09
Ether3
Ether2
06-19
Ether3
Ether1
Ether2
29-May-09
06-20
Root - A forwarding port that has been elected for the spanning-tree
topology
Designated - A forwarding port for every LAN segment
Alternate - An alternate path to the root bridge. This path is different
than using the root port.
Backup - A backup/redundant path to a segment where another
switch port already connects.
Disabled - Not strictly part of STP, a network administrator can
manually disable a port
29-May-09
RSTP
06-21
29-May-09
06-22
29-May-09
Prioritas Bridge
06-23
29-May-09
Status Bridge
06-24
29-May-09
Monitoring Link
06-25
29-May-09
06-26
29-May-09
06-27
29-May-09
Bridge Filtering
06-28
29-May-09
06-29
29-May-09
Konfigurasi Console-Terminal
Mengaktifkan Protocol RSTP
/interface bridge set bridge1 protocol=rstp
06-30
29-May-09
06-31
29-May-09
06-32
29-May-09
EoIP Example
10.0.0.1
10.10.10.2
City A
City B
192.168.0.11
192.168.0.1
EoIP
192.168.0.12
192.168.0.13
192.168.0.3
192.168.0.2
Secara Virtual setiap Laptop terletak di dalam satu segmen network yang sama.
06-33
29-May-09
EoIP Configuration
06-34
29-May-09
Router A
10.10.10.1
Router B
10.10.10.2
192.168.1.1
192.168.1.11
EoIP
192.168.1.2
06-35
192.168.1.12
29-May-09
06-36
29-May-09
06-37
ROUTER B
29-May-09
Wireless Concept
Kemudahan WirelessLAN
07-2
29-May-09
Channels 80211b
World Wide Band
915 MHz
2.4 GHz
26 MHz
84.5 MHz
2401
2423
5.8 GHz
125 MHz
2426
2412
2448
2437
2406
2428
2453
2433
2458
2438
2421
2463
2443
2446
2432
2430
2483
Top of channel
14
2473
2452
Channel number
13
2472
2441
2427
2420
2461
2447
2416
2478
2467
2436
2422
2410
12
2456
2442
2411
2473
2462
2431
2417
2400
11
2451
2495
2484
10
Center frequency
2468
2457
2440
2450
2460
2470
2480
MHz
Bottom of
channel
ISM Band
07-3
29-May-09
Channels 80211a
36
40
42
44
48
5210
5150
5200
5220
5240
149
152 153
157
160 161
5760
07-4
5765
52
56
5250
5180
5735 5745
50
58
60
64
5300
5320
5290
5260
5280
5350
5800
5785
5805 5815
29-May-09
Custom Frequencies
4920-5170
MHz
-5735
MHz
07-5
2484
2312-2372
MHz
2512-2732
MHz
5180-5320
MHz
5745-5805
MHz
5330-
MHz
5815-6100
MHz
29-May-09
Spectrum Analyzer
07-6
29-May-09
07-7
29-May-09
Wavelength
Panjang Gelombang atau Wavelength adalah jarak
diantara kedua titik yang sama pada satu getaran.
Dalam sistem wireless, biasanya diukur dalam satuan
meter, sentimeter atau milli meter
07-8
29-May-09
29-May-09
8 m/s
3
x
10
______________
2,4 x 10 9 Hz
= 0,125 meter
Jadi panjang gelombang-nya hanya 12,5 cm
07-10
29-May-09
Tx Power
07-11
29-May-09
Perhitungan db - mWatt
dBm adalah nilai 10 log dari sinyal untuk 1 milli
Watt
dBW adalah nilai 10 log dari sinyal untuk 1
Watt
Sinyal 100 milli Watt jika dijadikan dBm akan
menjadi :
10 log
100 mW
1 mW
07-12
= 20 dBm
29-May-09
Watts vs dbm
Setiap kenaikan atau
kehilangan 3 dB, kita
akan mendapatkan
dua kali lipat daya
atau kehilangan
setengahnya .
100 W
50 dBm
10 W
40 dBm
2W
33 dBm
1W
30 dBm
100 mW
20 dBm
1 mW
07-13
0 dBm
100 uW
-10 dBm
0.001 nW
-80 dBm
29-May-09
Rx Sensivity
07-14
29-May-09
07-15
29-May-09
Losses Kabel
07-16
RG8
LMR400
LMR600
Heliax 3/8
Heliax
Heliax 5/8
: 10
: 6,8
: 5,4
: 5,36
: 3,74
: 2,15
29-May-09
07-17
29-May-09
07-18
Jarak
2.4 GHz
5.2 GHz
5.8 GHz
1 km
100.026
106.742
107.69
3 km
109.568
116.284
117.233
5 km
114.005
120.721
121.670
10 km
120.026
126.742
127.690
15 km
123.548
130.264
131.212
20 km
126.047
132.762
133.711
30 km
129.568
136.284
137.233
40 km
132.067
138.783
139.732
29-May-09
Perhitungan RX-Rate
RX-Rate /
Signal Strength
EIRP
Path Loss
(FSL)
TX-Rate Pemancar
+ Kekuatan antenna pemancar
- Loss Kabel & konektor
07-19
Penguatan
Penerimaan
29-May-09
Perhitungan RX-Rate
Asumsi :
Access Point 100 mWatt
tanpa booster
kabel LMR400 100 feet
antenna grid 24 db
frekuensi 2,4 GHz
jarak 10 km
07-20
29-May-09
Perhitungan
Perangkat
db
Pemancar (EIRP)
Access Point 100 mWatt
20 dbm
Kabel 30 meter
-6.8 db
37.2 db
Antenna 24 db
24 dbi
(EIRP)
-120.026 db
-6.8 db
Antenna 24 db
24 dbi
17.2 db
-65.626 db
29-May-09
Online
Calculator
07-22
www.mikrotik.co.id/
test_link.php
Mikrotik Indonesia http://www.mikrotik.co.id
29-May-09
07-23
29-May-09
07-24
29-May-09
Fresnel Zone
07-25
29-May-09
07-26
29-May-09
Fresnel Zone
07-27
29-May-09
Freznel Zone
Selain Line of Sight juga memenuhi ketentuan Freznel Zone
TX antenna
gain
Freznel Zone
RX antenna
gain
Line of sight
TX antenna
loss
TX power
RX antenna
loss
r (radius
fresnel zone)
d1
d2
RX signal
level
07-28
RECEIVER
29-May-09
07-29
29-May-09
4 f (GHz)
10 (km)
= 17.32 *
= 17.32 *
07-30
4 * 2.4 (GHz)
1.042 = 17.68 meter
29-May-09
Lengkung Bumi
07-31
29-May-09
07-32
http://www.mikrotik.co.id/test_tower.php
Mikrotik Indonesia http://www.mikrotik.co.id
29-May-09
Tinggi Antena
120
100
tinggi antena
80
meter
60
Fresnel Zone
40
20
10
20
30
40
50
60
29-May-09
GPS
07-34
Untuk mengukur
ketinggian dan posisi
pemasangan di dua
titik, digunakan alat
GPS (Global Positioning System)
29-May-09
Antenna Concept
Directionality
Omnidirectional
Polarization
07-35
In db
Higher db, longer distance coverage
Ussualy using vertical polarization
29-May-09
Antenna Type
29-May-09
Omni Directional
07-37
29-May-09
Yagi Antenna
07-38
29-May-09
07-39
29-May-09
Grid Antenna
07-40
29-May-09
07-41
29-May-09
Sectoral Antenna
07-42
29-May-09
07-43
29-May-09
07-44
29-May-09
PROTEKSI CUACA
07-45
29-May-09
07-46
29-May-09
Network Topology
Point to Point
07-47
Dual Nstream
29-May-09
Point to Point
Menghubungkan 2 buah alat, biasanya menggunakan antenna
directional dan jarak yang cukup jauh
Kedua alat cukup menggunakan lisensi level 4 : Bridge dan
Station
Bisa menggunakan proprietary setting (nstream, Custom
Frequency)
07-48
29-May-09
07-49
29-May-09
Point to Multipoint
1 buah AP Mikrotik sebagai base
station untuk melayani CPE
07-50
29-May-09
Point to Multipoint
Antena bisa menggunakan
Omnidirectional atau sectoral. Jika
client berada di satu area, bisa
menggunakan flat panel atau bahkan
directional antenna. Perhatikan
besaran bukaan antena.
Gunakan standart 80211.b, supaya
semua tipe CPE bisa terkoneksi.
07-51
29-May-09
07-52
29-May-09
07-53
29-May-09
Keamanan Wireless
Hidden SSID
Disable Default Authenticate
07-54
WEP
29-May-09
Wireless
Configuration
Wireless Menu
08-2
Wireless Sub-Menu:
Nstreme-Dual - list of Dual-Nstreme Interface
Access-List - list of associations of clients
Registration - list of connected clients
Connect-List - list of rules, that determine to which AP
the station should connect to
Security-Profile list of security functions to wireless
interfaces WEP and WPA/WPA2
29-May-09
Advance &
Simple Menu
08-3
29-May-09
Wireless Mode :
08-4
alignment-only
ap-bridge
bridge
nstreme-dual-slave
station
station-wds
wds-slave
station-pseudobridge
station-pseudobridge-clone
29-May-09
Wireless Mode - 1
08-5
29-May-09
Wireless Mode 2
08-6
29-May-09
Wireless Configuration
Basic Configuration :
Advance Configuration :
08-7
Point to Point
Point to Multi Point
Wireless Bridge
Virtual AP
Nstreme
Dual Nstreme
WDS
Mikrotik Indonesia http://www.mikrotik.co.id
29-May-09
Point to Point
AP Side
Client Side
08-8
29-May-09
08-9
29-May-09
08-10
29-May-09
08-11
29-May-09
Configuration AP Side
08-12
29-May-09
08-13
29-May-09
08-14
29-May-09
08-15
29-May-09
Client Management
08-16
Kita dapat
melakukan
pengaturan
untuk setiap
klien dan hal ini
akan
mengabaikan
konfigurasi
global
29-May-09
08-17
29-May-09
08-18
Membutuhkan lisensi
level 4
Set mode=ap-bridge
Konfigurasi lainnya
sama dengan
konfigurasi point-topoint
29-May-09
08-19
Dapat menggunakan
lisensi level 3
Set mode, ssid, band,
scan-list
Set mode=station
Pastikan frekuensi yang
digunakan berada
dalam rentang scan-list
29-May-09
Configuration AP Side
08-20
29-May-09
08-21
29-May-09
08-22
29-May-09
Configuration Console-Terminal
Bridge-AP
Configuration bridged - AP
08-23
29-May-09
Virtual AP
08-24
29-May-09
Virtual AP Configuration
08-25
29-May-09
Configuration Console-Terminal
VAP
Configuration - VAP
08-26
29-May-09
Wireless Bridge
08-27
29-May-09
AP
A
ethernet
192.168.0.x/24
08-28
Station
Wireless
connection
192.168.0.100+x/24
ethernet
192.168.0.100+x/24
192.168.0.x/24
29-May-09
08-29
29-May-09
08-30
29-May-09
08-31
29-May-09
08-32
29-May-09
Other Setting
08-33
29-May-09
Scan Tool
08-34
29-May-09
Snoop Tool
08-35
29-May-09
Connect List
08-36
29-May-09
Rate Jumping
5% of time
54Mbps
80% of time
15% of time
36Mbps
Recalibration
08-37
48Mbps
Recalibration
29-May-09
08-38
Supported rates
client data rates
Basic rates link
management data
rates
If router can't send or
receive data at basic
rate link goes down
29-May-09
Hotspot
HotSpot
09-2
29-May-09
Wired Network
Hotspot Gateway
09-3
29-May-09
09-4
29-May-09
09-5
29-May-09
HotSpot features
09-6
Autentikasi User
Perhitungan
Waktu akses
Data dikirim atau diterima
Limitasi Data
Berdasarkan data rate (kecepatan akses)
Berdasarkan jumlah data
Limitasi Akses User berdasarkan waktu
Support RADIUS
Bypass!
Mikrotik Indonesia http://www.mikrotik.co.id
29-May-09
09-7
29-May-09
09-8
29-May-09
09-9
29-May-09
09-10
29-May-09
09-11
29-May-09
09-12
29-May-09
09-13
29-May-09
09-14
29-May-09
Authentication Method
29-May-09
09-16
29-May-09
09-17
29-May-09
09-18
29-May-09
HotSpot User
09-19
29-May-09
HotSpot users
09-20
29-May-09
User Limitation
Limit Uptime batas
waktu user dapat
menggunakan akses
ke Hotspot Network.
Limit-bytes-in dan
Limit-bytes-out
batas Jumlah trasfer
data yang bisa
dilakukan oleh user.
09-21
29-May-09
Bypass! - IP bindings
09-22
29-May-09
HotSpot IP bindings
09-23
29-May-09
Bypass - WalledGarden
09-24
29-May-09
HTTP-level WalledGarden
09-25
29-May-09
IP-WalledGarden
09-26
29-May-09
Advertisement
09-27
29-May-09
Advertisement
09-28
29-May-09
VPN Basic
10-2
29-May-09
VPN Networks
Aplication Server
Office 1
PC
Aplication Server
Router
PC
File Server
Office 2
Router
WAN
PC
PC
VPN Networks
File Server
Office 3
Router
PC
10-3
PC
PC
PC
29-May-09
10-4
29-May-09
10-5
29-May-09
PPTP tunnel
10.10.10.100/24
10.10.20.1/32
10.10.10.1/24
10.10.10.2/24
10.10.20.2/32
192.168.1.1/24
192.168.1.2/24
Table 1
10-6
192.168.2.1/24
192.168.2.2/24
Table 2
29-May-09
10-7
29-May-09
Membuat PPTP-Client :
Username dan Password disesuaikan dari
konfigurasi server.
Connect-to adalah parameter Alamat IP dari
PPTP-Server.
Add-Default-Route adalah parameter jika akan
menggunakan koneksi PPTP sebagai gateway
utama.
10-8
29-May-09
10-9
29-May-09
10.200.200.1
Pool-pptp
10-10
29-May-09
10-11
29-May-09
10-12
29-May-09
Firewall
Firewall
Workstation
Switch
Server
Firewall
Internet
Laptop
11-2
29-May-09
Firewall
Rules
NAT (source-nat and destination-nat)
Mangle
Address List
Layer 7 Protocol (baru di versi 3)
Service Ports
Connections
11-3
29-May-09
Paket Data
11-4
29-May-09
PRE
ROUTING
ROUTING
DECISION
MANGLE
FORWARD
OUTPUT
FILTER
FORWARD
POST
ROUTING
QUEUE
GLOBAL-IN
FILTER
OUTPUT
MANGLE
POSTROUTING
DST-NAT
ROUTING
ADJUSTMENT
QUEUE
GLOBAL-OUT
INPUT
MANGLE
PREROUTING
MANGLE
INPUT
MANGLE
OUTPUT
SRC-NAT
CONNECTION
TRACKING
FILTER
INPUT
CONNECTION
TRACKING
HTB
INTERFACE
INPUT
INTERFACE
LOCAL
PROCESS
ROUTING
DECISION
OUTPUT
INTERFACE
11-5
29-May-09
To
Mangle
Firewall
Queue
Outside
Router/
Local
Process
Prerouting
Input
Input
Global-Total
Router/
Local
Process
Outside
Output
Output
Global-Out
Outside
Outside
Global-In
Postrouting
Global-Total
Interface
Prerouting
Forward
Global-In
Forward
Postrouting
Global-Out
Global-Total
Interface
11-6
29-May-09
Use IP Firewall
11-7
29-May-09
Connection State
11-8
29-May-09
Connection State
Firewall
New
11-9
Established
Related
Invalid
29-May-09
11-10
29-May-09
Mangle
11-11
29-May-09
Mangle on Winbox
11-12
29-May-09
11-13
Prerouting
yes
yes
no
Input
yes
no
no
Forward
no
yes
no
Output
no
no
yes
Postrouting
no
yes
yes
29-May-09
Type of Mark
Packet Mark
Connection Mark
Route Mark
11-14
29-May-09
Connection Mark
11-15
29-May-09
Passthrough
Passthrough=no
Passthrough=yes
Biasanya pada :
11-16
29-May-09
Uplink traffic
Downlink traffic
11-17
add src-address=192.168.0.2/32
action=mark-packet chain=prerouting
new-packet-mark=mark-uplink
add dst-address=192.168.0.2/32
action=mark-packet chain=prerouting
new-packet-mark=mark-downlink
29-May-09
11-18
29-May-09
11-19
29-May-09
Firewall Filters
11-20
29-May-09
11-21
Prerouting
not
implemented
not
implemented
not
implemented
Input
yes
no
no
Forward
no
yes
no
Output
no
no
yes
Postrouting
not
implemented
not
implemented
not
implemented
29-May-09
11-22
29-May-09
11-23
DROP virus
DROP spam server
DROP virus
DROP
DROP
DROP
DROP
DROP
DROP
DROP
ACCEPT ALL
29-May-09
11-24
ACCEPT HTTP
ACCEPT POP3
ACCEPT SMTP
ACCEPT IM
ACCEPT IRC
ACCEPT FTP
ACCEPT SSH
ACCEPT TELNET
ACCEPT ..
ACCEPT ..
DROP THE OTHER
29-May-09
Filter Rules
11-25
29-May-09
RouterOS v3 Services
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
11-26
PORT
20
21
22
23
53
80
179
443
646
1080
1723
1968
2000
2210
2211
2828
3128
8291
8728
-------
PROTOCOL
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
/1
/2
/4
DESCRIPTION
FTP
FTP
SSH, SFTP
Telnet
DNS
HTTP
BGP
SHTTP (Hotspot)
LDP (MPLS)
SoCKS (Hotspot)
PPTP
MME
Bandwidth Server
Dude Server
Dude Server
uPnP
Web Proxy
Winbox
API
ICMP
IGMP (Multicast)
IPIP
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
PORT
53
123
161
500
520
521
646
1698
1699
1701
1812
1813
1900
1966
5678
---------------
PROTOCOL
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
/46
/47
/50
/51
/89
/103
/112
DESCRIPTION
DNS
NTP
SNMP
IPSec
RIP
RIP
LDP (MPLS)
RSVP (MPLS)
RSVP (MPLS)
L2TP
User-Manager
User-Manager
uPnP
MME
Neighbor Discovery
RSVP (MPLS)
PPRP, EoIP
IPSec
IPSec
OSPF
PIM (Multicast)
VRRP
29-May-09
11-27
Playboy - 216.163.137.3
Penthouse - 64.124.57.235
29-May-09
11-28
29-May-09
11-29
29-May-09
11-30
29-May-09
IP Address List
11-31
29-May-09
11-32
29-May-09
Memasukkan ke Address-List
11-33
29-May-09
11-34
29-May-09
Blok IP di Address-List
11-35
29-May-09
11-36
29-May-09
11-37
29-May-09
11-38
29-May-09
11-39
29-May-09
Firewall NAT
OUTGOING
OUTGOING
NAT ROUTER
INCOMING
INCOMING
INCOMING
INCOMING
PUBLIC NETWORK
PRIVATE NETWORK
OUTGOING
OUTGOING
11-40
29-May-09
Firewall NAT
11-41
29-May-09
masquerade
11-42
29-May-09
redirect
11-43
29-May-09
11-44
29-May-09
Mengaktifkan Web-Proxy
11-45
29-May-09
Redirect TCP-80
11-46
29-May-09
Last Issue
11-47
29-May-09
11-48
29-May-09
11-50
29-May-09
11-51
29-May-09
11-52
29-May-09
11-53
29-May-09
11-54
29-May-09
11-55
29-May-09
11-56
29-May-09
Quality of Service
Quality of Service
12-2
29-May-09
Quality of Service
12-3
29-May-09
Simple Queue
12-4
29-May-09
12-5
29-May-09
12-6
29-May-09
12-7
29-May-09
12-8
29-May-09
Staged Limitation
12-9
29-May-09
Burst
12-10
29-May-09
Rate(kbps)
512
Burst-limit
Average Rate
384
256
Max-limit
192
Burst-Threshold
128
Limit-at
12-11
10
15
20
time(s)
29-May-09
12-12
29-May-09
12-13
29-May-09
12-14
29-May-09
12-15
allow-address
IP address yang dapat
melihat grafik tersebut
allow-target
memperbolehkan IP
Address yang tercantum
pada target untuk melihat
grafik.
29-May-09
12-16
29-May-09
12-17
29-May-09
Queue Disciplines
Scheduler queues
Mengatur packet flow, sesuai dengan jumlah
Shaper queues
Mengontrol kecepatan date rate.
12-18
29-May-09
Shaper
Mbps
2
10
15
20
detik
kelebihan data-rate
akan didrop
12-19
10
15
20
detik
29-May-09
Scheduler
Mbps
2
10
15
20
detik
kelebihan data-rate
akan di antri
12-20
10
15
20
detik
29-May-09
Queue Kinds
Scheduler queues:
Shaper queues:
12-21
29-May-09
Queue Kinds
12-22
29-May-09
12-23
29-May-09
Skema FIFO
Flow 1
Flow 2
Paket disalurkan
sesuai yang datang
duluan
ke
interface
Flow 3
Flow 4
Jika penuh
akan di drop
12-24
29-May-09
12-25
29-May-09
Skema RED
Flow 1
ke
interface
Flow 2
Flow 3
Flow 4
Secara random
akan di drop
12-26
29-May-09
12-27
29-May-09
Skema SFQ
Flow 1
ke
interface
Flow 2
Flow 3
Flow 4
Algoritma
Hashing
12-28
sub-queue
Algoritma
Round
Robin
29-May-09
12-29
29-May-09
Setting PCQ
12-30
29-May-09
Skema PCQ
pcq-clasifier
src-address
sub-queue
Algoritma
Round
Robin
SRC-ADDRESS=10.0.0.1
SRC-ADDRESS=10.0.0.2
Flow 1
Flow 2
Flow 3
SRC-ADDRESS=10.0.0.3
SRC-ADDRESS=10.0.0.4
ke
interface
SRC-ADDRESS=10.0.0.5
Flow 4
SRC-ADDRESS=10.0.0.6
SRC-ADDRESS=10.0.0.7
12-31
29-May-09
Pcq-rate=128000
2 users
4 users
128k
128k
queue=pcq-down
max-limit=512k
73k
73k
73k
73k
128k
128k
12-32
7 users
128k
128k
73k
73k
73k
29-May-09
Pcq-rate=0
1 user
2 users
7 users
73k
256k
73k
73k
queue=pcq-down
max-limit=512k
512k
73k
73k
256k
73k
73k
12-33
29-May-09
12-34
29-May-09
Level1
Level2
POP3
Flow 1
ke
interface
HTTP
Flow 2
HTTP
&FTP
Flow 3
Flow 4
LOCAL
FTP
FILTER
12-35
29-May-09
Skema HTB
Level 1
Inner
Feed
Slots
Class A
Inner
Feed
Self
Slots
Self
Feed
Level 2
Leaf1
priority 7
Leaf2
priority 8
Filter
12-36
29-May-09
HTB States
hijau
kuning
Posisi di mana data-rate lebih besar dari limit-at, namun lebih kecil dari
max-limit.
Diijinkan atau tidaknya penambahan trafik bergantung pada :
merah
12-37
posisi parent, jika prioritas class sama dengan parentnya dan parentnya
dalam posisi kuning
posisi class itu sendiri, jika parent sudah berstatus kuning.
29-May-09
Queue with
SRC-NAT & Internal Proxy
ROUTER
SRC-NAT
INTERNET
WEB-PROXY
LOCAL
PROCESS
12-38
29-May-09
SRC-NAT
Direct Downstream
3
INTERNET
Upstream to proxy
WEB-PROXY
LOCAL
PROCESS
Downstream from proxy
4
12-39
29-May-09
Web-Proxy Setup
> ip web-proxy pr enabled: yes
src-address: 0.0.0.0
port: 3128
hostname: "proxy"
transparent-proxy: yes
parent-proxy: 0.0.0.0:0
cache-administrator: "webmaster"
max-object-size: 4096KiB
cache-drive: system
max-cache-size: none
max-ram-cache-size: unlimited
status: running
reserved-for-cache: 0KiB
reserved-for-ram-cache: 154624KiB
12-40
29-May-09
Firewall Setup
[admin@instaler] ip firewall nat> pr
Flags: X - disabled, I - invalid, D - dynamic
0 chain=srcnat out-interface=public
src-address=192.168.x.0/24
action=masquerade
1 chain=dstnat in-interface=lan srcaddress=192.168.1.0/24 protocol=tcp
dst-port=80 action=redirect to-ports=3128
12-41
29-May-09
Queue Setup
Simple-Queue Setup :
name="queue-notebook"
target-addresses=192.168.x.2/32
interface=all
parent=none
direction=both
queue=default-small/default-small
12-42
29-May-09
[LAB]Simple-Queue Traffic
Internasional dan IIX
12-43
29-May-09
12-44
29-May-09
Nice.rsc
# Script untuk mengenerate IP Address di Router NICE
# Script by www.mikrotik.co.id
# Generated at 1 February 2007 13:47:12 WIB ... 1390 lines
/ip firewall address-list
rem [find list=nice]
add list=nice address="61.94.0.0/16"
add list=nice address="125.160.0.0/16"
add list=nice address="125.161.0.0/16"
add list=nice address="125.162.0.0/16"
add list=nice address="125.163.0.0/16"
add list=nice address="125.164.0.0/16"
add list=nice address="222.124.0.0/16"
add list=nice address="61.5.0.0/17"
add list=nice address="202.158.0.0/17"
add list=nice address="61.14.0.0/18"
..
12-45
29-May-09
Address-List on
Winbox
12-46
29-May-09
Pengaturan Mangle
[admin@MikroTik] > /ip firewall mangle pr
Flags: X - disabled, I - invalid, D - dynamic
0 chain=prerouting in-interface=[interface menuju network local]
dst-address-list=nice
action=mark-connection new-connection-mark=conn-iix
passthrough=yes
1 chain=prerouting connection-mark=conn-iix
action=mark-packet new-packet-mark=packet-iix
passthrough=no
2 chain=prerouting action=mark-packet
new-packet-mark=packet-intl passthrough=no
12-47
29-May-09
Pengaturan Simple-Queue
[admin@MikroTik]> /queue simple pr
Flags: X - disabled, I - invalid, D - dynamic
0 name="client-iix" target-addresses=192.168.x.2/32
dst-address=0.0.0.0/0 interface=all parent=none
packet-marks=packet-iix direction=both priority=8
queue=default-small/default-small limit-at=0/0
max-limit=64000/256000 total-queue=default-small
1 name="client-intl" target-addresses=192.168.x.2/32
dst-address=0.0.0.0/0 interface=all parent=none
packet-marks=packet-intl direction=both priority=8
queue=default-small/default-small limit-at=0/0
max-limit=32000/128000 total-queue=default-small
12-48
29-May-09