You are on page 1of 2

Perlengkapan:

* Kerio Winroute Firewall (KWF) versi 6.x.x


* PC-router: Win2k/WinXP/Win2k3, 384-512 mb, P3 500+ Mhz
* Modem ADSL dan hub/switch

Alur: Modem -- PC-router -- hub/switch -- PC-client

1. Konfugurasi network:
* Modem:
o Internet: (sesuai setting dari ISP)
o LAN:
+ IP: 192.168.1.1
+ Gateway (bila ada): (dikosongkan)
+ DNS (bila ada): 192.168.1.1
* PC-router (terinstall KWF)
o LAN1 (terhubung crossover ke modem):
+ IP: 192.168.1.2
+ Gateway: 192.168.1.1 (IP dari LAN modem)
+ DNS (kalau ada): 192.168.1.1 (IP dari LAN modem)
o LAN2 (terhubung ke hub/switch secara standard/non-crossover)
+ IP: 192.168.0.1
+ Gateway: (dikosongkan)
+ DNS (kalau ada): 192.168.0.1 (IP dari LAN2)
* PC-client (static atau dynamic dipilih salahsatunya)
o LAN Static (terhubung ke hub/switch secara standard/non-
crossover):
o
+ IP: 192.168.0.x (x = 2 sampai 254 asal belum dipakai)
+ Gateway: 192.168.0.1 (IP dari LAN2 PC-router)
+ DNS (kalau ada): 192.168.0.1 (IP dari LAN2 PC-router)
o LAN Dynamic (terhubung ke hub/switch secara standard/non-
crossover):
+ automatic
2. Setting Kerio Winroute Firewall (versi 6.0 ke atas):
* DHCP Server:
o Scope:
+ Description: Local
+ First Address: 192.168.0.1
+ Last Address: 192.168.0.254
+ Network mask: 255.255.255.0
+ Lease Time: 15 days
+ Exclusions:
# 192.168.0.1-192.168.0.50 (untuk IP Static pc tipe
"Server")
# 192.168.0.201-192.168.0.254 (untuk IP Static pc tipe
"Client")
+ Default Gateway: 192.168.0.1
+ Domain Name Server (DNS): 192.168.0.1
+ Time Server: 192.168.0.1
* DNS Forwarding: (diisi; berguna apabila mengaktifkan website intranet)
* Traffic Policy:
o NAT:
+ source: (LAN2)
+ Destination: (LAN1)
+ Service: ANY
+ Action: permit
o Local Traffic:
+ source: (LAN2) + Firewall
+ Destination: (LAN2) + Firewall
+ Service: ANY
+ Action: permit
o Firewall Traffic:
+ source: Firewall
+ Destination: (LAN1)
+ Service: ANY
+ Action: permit
o Ident:
+ source: (LAN1)
+ Destination: Firewall
+ Service: H232, Ident, SIP
+ Action: permit
o Default rule:
+ source: ANY
+ Destination: ANY
+ Service: ANY
+ Action: drop

Catatan: LAN1=LAN-EXTRA, LAN2=LAN-INTRA

You might also like