Tampilkan postingan dengan label mikrotik. Tampilkan semua postingan
Tampilkan postingan dengan label mikrotik. Tampilkan semua postingan

Rabu, 25 April 2012

queun tree

/ip fi ma
add chain=prerouting action=jump jump-target=hotspot comment="Hotspot Jump Mangle"
add chain=postrouting action=jump jump-target=hotspot

add chain=prerouting action=mark-connection new-connection-mark=conn-up passthrough=yes dst-address=192.168.101.0/24 comment="Hotspot Connections"
add chain=postrouting action=mark-connection new-connection-mark=conn-down passthrough=yes src-address=192.168.101.0/24

/ip fi ma
add chain=prerouting action=mark-connection new-connection-mark=conn-up passthrough=yes dst-address=192.168.100.0/24 comment="Hotspot Connections2"
add chain=postrouting action=mark-connection new-connection-mark=conn-down passthrough=yes src-address=192.168.100.0/24


add chain=prerouting action=mark-packet new-packet-mark=packet-up passthrough=yes connection-mark=conn-up comment="Hotspot Packets"
add chain=postrouting action=mark-packet new-packet-mark=packet-down passthrough=yes connection-mark=conn-down

add chain=prerouting action=mark-packet new-packet-mark=hotspot-up passthrough=no connection-mark=conn-up
add chain=postrouting action=mark-packet new-packet-mark=hotspot-down passthrough=no connection-mark=conn-down



/queue type
add name="pcq-down" kind=pcq pcq-rate=128k pcq-limit=4 pcq-classifier=dst-address pcq-total-limit=2000 pcq-burst-rate=0 pcq-burst-threshold=0 pcq-burst-time=10s pcq-src-address-mask=32 pcq-dst-address-mask=32 pcq-src-address6-mask=64 pcq-dst-address6-mask=64
add name="pcq-up" kind=pcq pcq-rate=96k pcq-limit=4 pcq-classifier=src-address pcq-total-limit=2000 pcq-burst-rate=0 pcq-burst-threshold=0 pcq-burst-time=10s pcq-src-address-mask=32 pcq-dst-address-mask=32 pcq-src-address6-mask=64 pcq-dst-address6-mask=64

/queue tree
add name="Testing Down" parent=global-out limit-at=0 priority=8 max-limit=128k burst-limit=0 burst-threshold=0 burst-time=0s

add name="Testing Up" parent=global-in limit-at=0 priority=8 max-limit=128k burst-limit=0 burst-threshold=0 burst-time=0s

add name="Browsing Hotspot" parent="Testing Down" packet-mark=hotspot-down limit-at=64k queue=pcq-down priority=3 max-limit=128k burst-limit=256k burst-threshold=128k burst-time=16s

add name="Hotspot Up" parent="Testing Up" packet-mark=hotspot-up limit-at=32k queue=pcq-up priority=8 max-limit=64k burst-limit=0 burst-threshold=0 burst-time=0s

web proxy mikrotik

Bagaimana cara mengkonfigurasi proxy di mesin mikrotik? berikut langkah-langkahnya :
Login ke mikrotik denga username dan password mikrotik sobat.
Dalam hal ini saya mengetikkan perintah melalui console mikrotik karena lebih mudah dan cepat

IP Proxy :
/ip proxy set enabled=yes  "mengaktifkan fiture web proxy"

maximal-client-connections=1000
maximal-server-connections=1000

IP Web-Proxy :
/ip web-proxy set enabled=yes "mengaktifkan web proxy (IP proxy dan IP web-proxy tergantung versi mikrotik"

set src-address=0.0.0.0 "alamat yang kita gunakan untuk koneksi ke parent proxy (default-nya 0.0.0.0)"

set port=8080 "port yang digunakan untuk web proxy"

set hostname="proxy.andisyam.web.id" "nama hostname untuk web proxy (optional)"

set transparent-proxy=yes "mengaktifkan transparent proxy"

set parent-proxy=0.0.0.0 "sesuaikan jika sobat ingin menggunakan parent proxy (optional)"

set cache-administrator="syam_u@bismillah.com" "email admin yang akan dikirim jika proxy mengalami error"

set max-object-size=8192KiB "ukuran maksimal file yang akan disimpan sebagai cache (default=4096kilobytes)"

set cache-drive=system "drive tempat menyimpan cache"

set max-cache-size=unlimited "ukuran maksimal harddisk yang akan dipakai menyimpan file cache (4 kali total RAM atau unlimited)"

set max-ram-cache-size=unlimited "maksimal ram yang digunakan untuk cache"


Membuat rule NAT untuk transparent proxy, dimana me-redirect port web ke transparent proxy yaitu mengarahkan semua trafik yang menuju port 80, 3128 dan 8000 kita belokkan menuju port 8080, yaitu port Web-Proxy :

/ip firewall nat add chain=dstnat protocol=tcp dst-port=80 action=redirect to-ports=8080
/ip firewall nat add chain=dstnat protocol=tcp dst-port=3128 action=redirect to-ports=8080

/ip firewall nat add chain=dstnat protocol=tcp dst-port=8000 action=redirect to-ports=8080


Memeriksa hasil konfigurasi NAT :

[gajah.net] > /ip firewall nat print
Flags: X - disabled, I - invalid, D - dynamic
0  chain=srcnat out-interface=public action=masquerade
1 chain=dstnat in-interface=local src-address=192.168.0.0/24 protocol=tcp dst-port=80 action=redirect to-ports=3128

Untuk melihat hasil konfigurasi web-proxy :

/ip web-proxy print

Monitoring kinerja web-proxy :

/ip web-proxy monitor

memisah bandwith lokal dan international

Jika anda ingin membagi bandwidth di Mikrotik beda antara local dan internasional,contoh client1 bandwidth untuk Lokal (seperti yahoo.co.id itu local)1 Mbps dan Internasionalnya (seperti yahoo.com itu internasional)512 Kbps,berikut ini caranya:

--Remote Mikrotik anda dengan Winbox kemudian pilih New Terminal”
--Topologi interface saya:
public:interface yang mengarah ke internet (Modem)
local:interface yang mengarah ke client

--Selanjutnya Masih di “New Terminal”,copy address list di bawah ini kemudian pastekan di “New Terminal” mikrotik:

/ip firewall address-list
add list=nice address="1.2.3.4"
remove [find list="nice"]
add list=nice address="182.0.0.0/12"
add list=nice address="114.120.0.0/13"
add list=nice address="120.168.0.0/13"
add list=nice address="114.56.0.0/14"
add list=nice address="120.166.0.0/15"
add list=nice address="125.162.0.0/16"
add list=nice address="125.163.0.0/16"
add list=nice address="125.160.0.0/16"
add list=nice address="125.161.0.0/16"
add list=nice address="125.166.0.0/16"
add list=nice address="125.167.0.0/16"
add list=nice address="125.164.0.0/16"
add list=nice address="125.165.0.0/16"
add list=nice address="223.164.0.0/16"
add list=nice address="180.251.0.0/16"
add list=nice address="180.250.0.0/16"
add list=nice address="180.249.0.0/16"
add list=nice address="180.248.0.0/16"
add list=nice address="180.254.0.0/16"
add list=nice address="180.253.0.0/16"
add list=nice address="180.252.0.0/16"
add list=nice address="120.163.0.0/16"
add list=nice address="180.243.0.0/16"
add list=nice address="120.162.0.0/16"
add list=nice address="180.242.0.0/16"
add list=nice address="120.161.0.0/16"
add list=nice address="180.241.0.0/16"
add list=nice address="120.160.0.0/16"
add list=nice address="180.247.0.0/16"
add list=nice address="180.246.0.0/16"
add list=nice address="180.245.0.0/16"
add list=nice address="180.244.0.0/16"
add list=nice address="117.54.0.0/16"
add list=nice address="124.81.0.0/16"
add list=nice address="222.124.0.0/16"
add list=nice address="61.94.0.0/16"
add list=nice address="118.96.0.0/16"
add list=nice address="118.97.0.0/16"
add list=nice address="167.205.0.0/16"
add list=nice address="110.139.0.0/16"
add list=nice address="110.138.0.0/16"
add list=nice address="110.137.0.0/16"
add list=nice address="110.136.0.0/16"
add list=nice address="202.158.0.0/17"
add list=nice address="61.5.0.0/17"
add list=nice address="124.195.0.0/17"
add list=nice address="180.240.128.0/17"
add list=nice address="118.98.0.0/17"
add list=nice address="202.155.0.0/17"
add list=nice address="120.165.0.0/17"
add list=nice address="119.11.128.0/17"
add list=nice address="125.252.64.0/18"
add list=nice address="118.99.64.0/18"
add list=nice address="152.118.128.0/18"
add list=nice address="152.118.192.0/18"
add list=nice address="152.118.0.0/18"
add list=nice address="152.118.64.0/18"
add list=nice address="221.132.192.0/18"
add list=nice address="125.208.128.0/18"
add list=nice address="124.153.0.0/18"
add list=nice address="222.165.192.0/18"
add list=nice address="61.14.128.0/18"
add list=nice address="203.130.192.0/18"
add list=nice address="203.192.128.0/18"
add list=nice address="210.210.128.0/18"
add list=nice address="202.147.0.0/18"
add list=nice address="202.152.0.0/18"
add list=nice address="202.173.64.0/19"
add list=nice address="203.100.128.0/19"
add list=nice address="114.199.96.0/19"
add list=nice address="202.171.0.0/19"
add list=nice address="202.47.192.0/19"
add list=nice address="202.169.32.0/19"
add list=nice address="117.102.224.0/19"
add list=nice address="202.149.128.0/19"
add list=nice address="122.152.128.0/19"
add list=nice address="202.149.64.0/19"
add list=nice address="202.146.224.0/19"
add list=nice address="202.155.128.0/19"
add list=nice address="118.82.0.0/19"
add list=nice address="61.247.0.0/19"
add list=nice address="61.247.32.0/19"
add list=nice address="111.94.0.0/19"
add list=nice address="111.94.32.0/19"
add list=nice address="111.94.64.0/19"
add list=nice address="111.94.96.0/19"
add list=nice address="111.94.128.0/19"
add list=nice address="111.94.160.0/19"
add list=nice address="111.94.192.0/19"
add list=nice address="111.95.0.0/19"
add list=nice address="111.95.32.0/19"
add list=nice address="111.95.64.0/19"
add list=nice address="111.95.96.0/19"
add list=nice address="111.95.128.0/19"
add list=nice address="111.95.160.0/19"
add list=nice address="111.95.192.0/19"
add list=nice address="114.79.0.0/19"
add list=nice address="114.79.32.0/19"
add list=nice address="117.102.96.0/19"
add list=nice address="117.104.192.0/19"
add list=nice address="118.98.160.0/19"
add list=nice address="118.98.192.0/19"
add list=nice address="118.136.0.0/19"
add list=nice address="118.136.32.0/19"
add list=nice address="118.136.64.0/19"
add list=nice address="118.136.96.0/19"
add list=nice address="118.136.128.0/19"
add list=nice address="118.136.160.0/19"
add list=nice address="118.136.192.0/19"
add list=nice address="118.136.224.0/19"
add list=nice address="118.137.0.0/19"
add list=nice address="118.137.32.0/19"
add list=nice address="118.137.64.0/19"
add list=nice address="118.137.96.0/19"
add list=nice address="118.137.128.0/19"
add list=nice address="118.137.160.0/19"
add list=nice address="118.137.192.0/19"
add list=nice address="118.137.224.0/19"
add list=nice address="120.164.0.0/19"
add list=nice address="123.231.224.0/19"
add list=nice address="202.43.160.0/19"
add list=nice address="202.46.64.0/19"
add list=nice address="202.53.224.0/19"
add list=nice address="202.77.96.0/19"
add list=nice address="202.137.0.0/19"
add list=nice address="202.148.0.0/19"
add list=nice address="202.150.64.0/19"
add list=nice address="202.153.224.0/19"
add list=nice address="202.154.0.0/19"
add list=nice address="202.154.32.0/19"
add list=nice address="202.159.0.0/19"
add list=nice address="202.159.32.0/19"
add list=nice address="202.159.64.0/19"
add list=nice address="202.159.96.0/19"
add list=nice address="202.162.192.0/19"
add list=nice address="203.123.224.0/19"
add list=nice address="203.128.64.0/19"
add list=nice address="203.153.96.0/19"
add list=nice address="219.83.0.0/19"
add list=nice address="219.83.32.0/19"
add list=nice address="27.50.16.0/20"
add list=nice address="27.124.80.0/20"
add list=nice address="49.128.176.0/20"
add list=nice address="60.253.96.0/20"
add list=nice address="61.8.64.0/20"
add list=nice address="110.5.96.0/20"
add list=nice address="111.68.112.0/20"
add list=nice address="111.94.224.0/20"
add list=nice address="111.95.224.0/20"
add list=nice address="113.212.112.0/20"
add list=nice address="114.134.64.0/20"
add list=nice address="114.199.80.0/20"
add list=nice address="115.124.64.0/20"
add list=nice address="116.213.48.0/20"
add list=nice address="117.20.48.0/20"
add list=nice address="117.74.112.0/20"
add list=nice address="117.102.80.0/20"
add list=nice address="119.2.80.0/20"
add list=nice address="119.235.16.0/20"
add list=nice address="119.235.208.0/20"
add list=nice address="121.52.64.0/20"
add list=nice address="121.100.16.0/20"
add list=nice address="122.129.96.0/20"
add list=nice address="122.129.192.0/20"
add list=nice address="122.152.160.0/20"
add list=nice address="122.200.0.0/20"
add list=nice address="122.248.32.0/20"
add list=nice address="175.158.32.0/20"
add list=nice address="180.178.96.0/20"
add list=nice address="180.214.240.0/20"
add list=nice address="182.16.240.0/20"
add list=nice address="182.23.16.0/20"
add list=nice address="182.23.32.0/20"
add list=nice address="182.23.160.0/20"
add list=nice address="182.48.160.0/20"
add list=nice address="183.91.64.0/20"
add list=nice address="184.86.64.0/20"
add list=nice address="202.3.208.0/20"
add list=nice address="202.6.208.0/20"
add list=nice address="202.6.224.0/20"
add list=nice address="202.46.144.0/20"
add list=nice address="202.47.64.0/20"
add list=nice address="202.51.192.0/20"
add list=nice address="202.51.224.0/20"
add list=nice address="202.58.64.0/20"
add list=nice address="202.58.160.0/20"
add list=nice address="202.58.192.0/20"
add list=nice address="202.59.160.0/20"
add list=nice address="202.62.16.0/20"
add list=nice address="202.65.112.0/20"
add list=nice address="202.67.32.0/20"
add list=nice address="202.69.96.0/20"
add list=nice address="202.70.48.0/20"
add list=nice address="202.72.208.0/20"
add list=nice address="202.73.112.0/20"
add list=nice address="202.73.224.0/20"
add list=nice address="202.75.96.0/20"
add list=nice address="202.78.192.0/20"
add list=nice address="202.80.112.0/20"
add list=nice address="202.80.208.0/20"
add list=nice address="202.87.176.0/20"
add list=nice address="202.89.208.0/20"
add list=nice address="202.92.192.0/20"
add list=nice address="202.93.16.0/20"
add list=nice address="202.93.32.0/20"
add list=nice address="202.93.128.0/20"
add list=nice address="202.93.224.0/20"
add list=nice address="202.95.128.0/20"
add list=nice address="202.122.160.0/20"
add list=nice address="202.123.224.0/20"
add list=nice address="202.127.96.0/20"
add list=nice address="202.138.224.0/20"
add list=nice address="202.143.32.0/20"
add list=nice address="202.145.0.0/20"
add list=nice address="202.147.192.0/20"
add list=nice address="202.150.128.0/20"
add list=nice address="202.152.160.0/20"
add list=nice address="202.152.224.0/20"
add list=nice address="202.153.16.0/20"
add list=nice address="202.165.32.0/20"
add list=nice address="202.169.224.0/20"
add list=nice address="202.182.48.0/20"
add list=nice address="203.77.224.0/20"
add list=nice address="203.78.112.0/20"
add list=nice address="203.83.32.0/20"
add list=nice address="203.89.16.0/20"
add list=nice address="203.161.16.0/20"
add list=nice address="203.166.192.0/20"
add list=nice address="210.57.208.0/20"
add list=nice address="210.79.208.0/20"
add list=nice address="210.247.240.0/20"
add list=nice address="219.83.80.0/20"
add list=nice address="219.83.96.0/20"
add list=nice address="220.157.96.0/20"
add list=nice address="223.25.96.0/20"
add list=nice address="223.27.144.0/20"
add list=nice address="27.112.64.0/21"
add list=nice address="27.121.80.0/21"
add list=nice address="27.123.0.0/21"
add list=nice address="27.131.0.0/21"
add list=nice address="27.131.248.0/21"
add list=nice address="49.156.56.0/21"
add list=nice address="58.65.240.0/21"
add list=nice address="60.253.112.0/21"
add list=nice address="110.35.80.0/21"
add list=nice address="110.44.168.0/21"
add list=nice address="110.50.80.0/21"
add list=nice address="110.76.144.0/21"
add list=nice address="111.68.24.0/21"
add list=nice address="111.94.240.0/21"
add list=nice address="112.78.40.0/21"
add list=nice address="112.78.136.0/21"
add list=nice address="112.78.144.0/21"
add list=nice address="112.78.168.0/21"
add list=nice address="112.78.176.0/21"
add list=nice address="112.109.16.0/21"
add list=nice address="113.20.136.0/21"
add list=nice address="113.212.160.0/21"
add list=nice address="114.31.240.0/21"
add list=nice address="114.110.16.0/21"
add list=nice address="114.110.40.0/21"
add list=nice address="114.141.48.0/21"
add list=nice address="114.141.88.0/21"
add list=nice address="115.69.216.0/21"
add list=nice address="115.85.64.0/21"
add list=nice address="115.124.80.0/21"
add list=nice address="115.178.48.0/21"
add list=nice address="115.178.120.0/21"
add list=nice address="116.0.0.0/21"
add list=nice address="116.50.24.0/21"
add list=nice address="116.66.200.0/21"
add list=nice address="116.68.248.0/21"
add list=nice address="116.90.208.0/21"
add list=nice address="116.197.128.0/21"
add list=nice address="116.212.72.0/21"
add list=nice address="116.254.96.0/21"
add list=nice address="117.102.160.0/21"
add list=nice address="117.103.32.0/21"
add list=nice address="117.103.48.0/21"
add list=nice address="117.103.168.0/21"
add list=nice address="117.121.200.0/21"
add list=nice address="119.2.40.0/21"
add list=nice address="119.2.48.0/21"
add list=nice address="119.2.72.0/21"
add list=nice address="119.10.176.0/21"
add list=nice address="119.47.88.0/21"
add list=nice address="119.82.224.0/21"
add list=nice address="119.110.64.0/21"
add list=nice address="119.110.80.0/21"
add list=nice address="119.235.248.0/21"
add list=nice address="119.252.104.0/21"
add list=nice address="119.252.128.0/21"
add list=nice address="119.252.160.0/21"
add list=nice address="120.29.152.0/21"
add list=nice address="120.136.16.0/21"
add list=nice address="120.164.40.0/21"
add list=nice address="121.50.32.0/21"
add list=nice address="121.52.48.0/21"
add list=nice address="121.52.136.0/21"
add list=nice address="121.58.184.0/21"
add list=nice address="121.101.128.0/21"
add list=nice address="122.49.224.0/21"
add list=nice address="122.129.112.0/21"
add list=nice address="122.144.0.0/21"
add list=nice address="122.152.184.0/21"
add list=nice address="122.200.48.0/21"
add list=nice address="122.200.144.0/21"
add list=nice address="123.108.8.0/21"
add list=nice address="123.255.200.0/21"
add list=nice address="124.6.32.0/21"
add list=nice address="124.66.160.0/21"
add list=nice address="124.158.128.0/21"
add list=nice address="175.45.184.0/21"
add list=nice address="175.103.32.0/21"
add list=nice address="175.106.8.0/21"
add list=nice address="175.106.16.0/21"
add list=nice address="175.111.112.0/21"
add list=nice address="175.176.160.0/21"
add list=nice address="180.211.88.0/21"
add list=nice address="182.23.8.0/21"
add list=nice address="182.23.48.0/21"
add list=nice address="182.255.0.0/21"
add list=nice address="183.91.80.0/21"
add list=nice address="202.43.248.0/21"
add list=nice address="202.46.0.0/21"
add list=nice address="202.46.24.0/21"
add list=nice address="202.51.16.0/21"
add list=nice address="202.51.120.0/21"
add list=nice address="202.51.208.0/21"
add list=nice address="202.57.0.0/21"
add list=nice address="202.57.24.0/21"
add list=nice address="202.58.176.0/21"
add list=nice address="202.59.200.0/21"
add list=nice address="202.67.8.0/21"
add list=nice address="202.73.104.0/21"
add list=nice address="202.74.72.0/21"
add list=nice address="202.87.248.0/21"
add list=nice address="202.91.8.0/21"
add list=nice address="202.91.24.0/21"
add list=nice address="202.122.8.0/21"
add list=nice address="202.129.184.0/21"
add list=nice address="202.133.0.0/21"
add list=nice address="202.134.0.0/21"
add list=nice address="202.138.240.0/21"
add list=nice address="202.146.128.0/21"
add list=nice address="202.146.176.0/21"
add list=nice address="202.147.248.0/21"
add list=nice address="202.150.168.0/21"
add list=nice address="202.152.248.0/21"
add list=nice address="202.153.128.0/21"
add list=nice address="202.153.144.0/21"
add list=nice address="202.158.136.0/21"
add list=nice address="202.162.32.0/21"
add list=nice address="202.164.216.0/21"
add list=nice address="202.169.240.0/21"
add list=nice address="202.173.16.0/21"
add list=nice address="203.80.8.0/21"
add list=nice address="203.81.184.0/21"
add list=nice address="203.83.24.0/21"
add list=nice address="203.84.136.0/21"
add list=nice address="203.84.152.0/21"
add list=nice address="203.135.176.0/21"
add list=nice address="203.142.64.0/21"
add list=nice address="203.142.80.0/21"
add list=nice address="203.153.24.0/21"
add list=nice address="203.160.56.0/21"
add list=nice address="203.174.8.0/21"
add list=nice address="203.190.40.0/21"
add list=nice address="203.190.112.0/21"
add list=nice address="203.190.240.0/21"
add list=nice address="203.191.40.0/21"
add list=nice address="203.201.168.0/21"
add list=nice address="219.83.72.0/21"
add list=nice address="219.83.112.0/21"
add list=nice address="220.247.168.0/21"
add list=nice address="222.229.80.0/21"
add list=nice address="14.102.152.0/22"
add list=nice address="42.62.176.0/22"
add list=nice address="49.0.4.0/22"
add list=nice address="49.0.24.0/22"
add list=nice address="49.50.4.0/22"
add list=nice address="49.50.8.0/22"
add list=nice address="49.156.20.0/22"
add list=nice address="58.145.172.0/22"
add list=nice address="60.253.120.0/22"
add list=nice address="79.140.192.0/22"
add list=nice address="101.50.0.0/22"
add list=nice address="101.203.168.0/22"
add list=nice address="110.92.72.0/22"
add list=nice address="110.93.12.0/22"
add list=nice address="110.232.72.0/22"
add list=nice address="110.232.80.0/22"
add list=nice address="111.67.64.0/22"
add list=nice address="111.67.76.0/22"
add list=nice address="111.92.164.0/22"
add list=nice address="111.92.168.0/22"
add list=nice address="111.221.40.0/22"
add list=nice address="112.78.128.0/22"
add list=nice address="112.78.152.0/22"
add list=nice address="112.78.184.0/22"
add list=nice address="113.11.128.0/22"
add list=nice address="113.11.144.0/22"
add list=nice address="113.20.28.0/22"
add list=nice address="113.52.148.0/22"
add list=nice address="114.30.80.0/22"
add list=nice address="115.124.92.0/22"
add list=nice address="115.166.96.0/22"
add list=nice address="115.166.108.0/22"
add list=nice address="115.166.112.0/22"
add list=nice address="115.166.124.0/22"
add list=nice address="116.12.44.0/22"
add list=nice address="116.90.176.0/22"
add list=nice address="116.199.200.0/22"
add list=nice address="116.212.96.0/22"
add list=nice address="117.102.64.0/22"
add list=nice address="117.102.76.0/22"
add list=nice address="117.103.0.0/22"
add list=nice address="117.103.56.0/22"
add list=nice address="118.98.232.0/22"
add list=nice address="119.2.64.0/22"
add list=nice address="119.82.232.0/22"
add list=nice address="119.82.240.0/22"
add list=nice address="119.252.168.0/22"
add list=nice address="120.89.88.0/22"
add list=nice address="121.52.80.0/22"
add list=nice address="121.52.92.0/22"
add list=nice address="121.52.132.0/22"
add list=nice address="121.101.184.0/22"
add list=nice address="122.102.40.0/22"
add list=nice address="122.102.48.0/22"
add list=nice address="123.176.120.0/22"
add list=nice address="124.6.40.0/22"
add list=nice address="124.40.248.0/22"
add list=nice address="124.158.136.0/22"
add list=nice address="138.32.236.0/22"
add list=nice address="146.23.252.0/22"
add list=nice address="175.103.40.0/22"
add list=nice address="175.103.52.0/22"
add list=nice address="175.103.56.0/22"
add list=nice address="175.111.88.0/22"
add list=nice address="180.131.144.0/22"
add list=nice address="180.178.92.0/22"
add list=nice address="180.222.216.0/22"
add list=nice address="180.233.156.0/22"
add list=nice address="180.235.148.0/22"
add list=nice address="182.23.4.0/22"
add list=nice address="182.23.64.0/22"
add list=nice address="182.255.16.0/22"
add list=nice address="183.182.92.0/22"
add list=nice address="184.86.96.0/22"
add list=nice address="202.10.32.0/22"
add list=nice address="202.10.40.0/22"
add list=nice address="202.43.72.0/22"
add list=nice address="202.43.92.0/22"
add list=nice address="202.43.112.0/22"
add list=nice address="202.46.8.0/22"
add list=nice address="202.51.28.0/22"
add list=nice address="202.51.56.0/22"
add list=nice address="202.51.96.0/22"
add list=nice address="202.51.104.0/22"
add list=nice address="202.51.116.0/22"
add list=nice address="202.51.216.0/22"
add list=nice address="202.51.252.0/22"
add list=nice address="202.55.164.0/22"
add list=nice address="202.55.168.0/22"
add list=nice address="202.57.8.0/22"
add list=nice address="202.57.16.0/22"
add list=nice address="202.62.8.0/22"
add list=nice address="202.70.132.0/22"
add list=nice address="202.72.192.0/22"
add list=nice address="202.73.96.0/22"
add list=nice address="202.75.16.0/22"
add list=nice address="202.75.24.0/22"
add list=nice address="202.81.4.0/22"
add list=nice address="202.87.240.0/22"
add list=nice address="202.93.240.0/22"
add list=nice address="202.95.148.0/22"
add list=nice address="202.95.152.0/22"
add list=nice address="202.129.224.0/22"
add list=nice address="202.130.52.0/22"
add list=nice address="202.138.248.0/22"
add list=nice address="202.146.0.0/22"
add list=nice address="202.146.32.0/22"
add list=nice address="202.146.136.0/22"
add list=nice address="202.147.224.0/22"
add list=nice address="202.147.244.0/22"
add list=nice address="202.150.160.0/22"
add list=nice address="202.151.12.0/22"
add list=nice address="202.152.200.0/22"
add list=nice address="202.153.136.0/22"
add list=nice address="202.158.132.0/22"
add list=nice address="202.162.40.0/22"
add list=nice address="202.179.188.0/22"
add list=nice address="202.180.0.0/22"
add list=nice address="202.180.52.0/22"
add list=nice address="202.182.160.0/22"
add list=nice address="202.182.172.0/22"
add list=nice address="203.77.208.0/22"
add list=nice address="203.114.224.0/22"
add list=nice address="203.123.60.0/22"
add list=nice address="203.128.248.0/22"
add list=nice address="203.142.76.0/22"
add list=nice address="203.153.212.0/22"
add list=nice address="203.153.216.0/22"
add list=nice address="203.189.120.0/22"
add list=nice address="203.190.52.0/22"
add list=nice address="203.190.184.0/22"
add list=nice address="203.201.160.0/22"
add list=nice address="203.217.132.0/22"
add list=nice address="203.217.188.0/22"
add list=nice address="210.23.64.0/22"
add list=nice address="210.23.72.0/22"
add list=nice address="219.83.120.0/22"
add list=nice address="223.165.4.0/22"
add list=nice address="32.114.24.0/23"
add list=nice address="49.0.0.0/23"
add list=nice address="58.145.170.0/23"
add list=nice address="58.147.184.0/23"
add list=nice address="60.253.124.0/23"
add list=nice address="101.50.16.0/23"
add list=nice address="103.3.76.0/23"
add list=nice address="110.232.68.0/23"
add list=nice address="110.232.76.0/23"
add list=nice address="110.232.84.0/23"
add list=nice address="111.67.68.0/23"
add list=nice address="111.67.74.0/23"
add list=nice address="111.67.86.0/23"
add list=nice address="111.67.88.0/23"
add list=nice address="111.92.174.0/23"
add list=nice address="112.78.96.0/23"
add list=nice address="112.78.132.0/23"
add list=nice address="112.215.6.0/23"
add list=nice address="112.215.10.0/23"
add list=nice address="112.215.14.0/23"
add list=nice address="112.215.18.0/23"
add list=nice address="112.215.22.0/23"
add list=nice address="112.215.40.0/23"
add list=nice address="112.215.44.0/23"
add list=nice address="113.11.148.0/23"
add list=nice address="113.11.152.0/23"
add list=nice address="113.208.64.0/23"
add list=nice address="114.4.14.0/23"
add list=nice address="114.4.40.0/23"
add list=nice address="114.6.6.0/23"
add list=nice address="114.6.10.0/23"
add list=nice address="114.6.12.0/23"
add list=nice address="114.30.84.0/23"
add list=nice address="114.141.58.0/23"
add list=nice address="115.124.88.0/23"
add list=nice address="115.166.100.0/23"
add list=nice address="115.166.104.0/23"
add list=nice address="115.178.128.0/23"
add list=nice address="116.68.224.0/23"
add list=nice address="116.90.162.0/23"
add list=nice address="116.90.166.0/23"
add list=nice address="116.90.170.0/23"
add list=nice address="116.90.172.0/23"
add list=nice address="116.193.190.0/23"
add list=nice address="116.199.206.0/23"
add list=nice address="116.212.100.0/23"
add list=nice address="117.18.18.0/23"
add list=nice address="117.102.68.0/23"
add list=nice address="117.103.8.0/23"
add list=nice address="117.103.14.0/23"
add list=nice address="117.103.60.0/23"
add list=nice address="118.98.226.0/23"
add list=nice address="119.2.70.0/23"
add list=nice address="119.18.152.0/23"
add list=nice address="119.82.244.0/23"
add list=nice address="119.110.72.0/23"
add list=nice address="119.110.76.0/23"
add list=nice address="119.252.172.0/23"
add list=nice address="121.52.58.0/23"
add list=nice address="121.52.60.0/23"
add list=nice address="121.52.86.0/23"
add list=nice address="121.52.88.0/23"
add list=nice address="121.52.130.0/23"
add list=nice address="121.101.188.0/23"
add list=nice address="122.102.44.0/23"
add list=nice address="122.128.16.0/23"
add list=nice address="122.128.24.0/23"
add list=nice address="124.40.254.0/23"
add list=nice address="124.158.150.0/23"
add list=nice address="124.158.152.0/23"
add list=nice address="175.103.44.0/23"
add list=nice address="175.184.248.0/23"
add list=nice address="180.214.232.0/23"
add list=nice address="180.233.154.0/23"
add list=nice address="182.48.176.0/23"
add list=nice address="182.253.0.0/23"
add list=nice address="184.26.164.0/23"
add list=nice address="202.0.88.0/23"
add list=nice address="202.0.92.0/23"
add list=nice address="202.4.160.0/23"
add list=nice address="202.4.170.0/23"
add list=nice address="202.8.28.0/23"
add list=nice address="202.9.72.0/23"
add list=nice address="202.10.62.0/23"
add list=nice address="202.14.92.0/23"
add list=nice address="202.20.106.0/23"
add list=nice address="202.20.108.0/23"
add list=nice address="202.43.64.0/23"
add list=nice address="202.43.88.0/23"
add list=nice address="202.43.116.0/23"
add list=nice address="202.46.14.0/23"
add list=nice address="202.46.130.0/23"
add list=nice address="202.46.240.0/23"
add list=nice address="202.46.252.0/23"
add list=nice address="202.47.90.0/23"
add list=nice address="202.51.60.0/23"
add list=nice address="202.51.102.0/23"
add list=nice address="202.51.110.0/23"
add list=nice address="202.51.114.0/23"
add list=nice address="202.51.222.0/23"
add list=nice address="202.52.48.0/23"
add list=nice address="202.52.58.0/23"
add list=nice address="202.55.160.0/23"
add list=nice address="202.57.12.0/23"
add list=nice address="202.58.238.0/23"
add list=nice address="202.58.242.0/23"
add list=nice address="202.59.194.0/23"
add list=nice address="202.59.196.0/23"
add list=nice address="202.61.98.0/23"
add list=nice address="202.61.100.0/23"
add list=nice address="202.61.104.0/23"
add list=nice address="202.61.112.0/23"
add list=nice address="202.61.124.0/23"
add list=nice address="202.73.100.0/23"
add list=nice address="202.75.20.0/23"
add list=nice address="202.75.28.0/23"
add list=nice address="202.81.62.0/23"
add list=nice address="202.87.246.0/23"
add list=nice address="202.89.116.0/23"
add list=nice address="202.90.194.0/23"
add list=nice address="202.90.198.0/23"
add list=nice address="202.93.246.0/23"
add list=nice address="202.94.84.0/23"
add list=nice address="202.124.196.0/23"
add list=nice address="202.125.80.0/23"
add list=nice address="202.125.88.0/23"
add list=nice address="202.125.100.0/23"
add list=nice address="202.129.216.0/23"
add list=nice address="202.135.6.0/23"
add list=nice address="202.138.252.0/23"
add list=nice address="202.146.4.0/23"
add list=nice address="202.146.36.0/23"
add list=nice address="202.147.228.0/23"
add list=nice address="202.147.232.0/23"
add list=nice address="202.147.240.0/23"
add list=nice address="202.150.166.0/23"
add list=nice address="202.152.194.0/23"
add list=nice address="202.152.196.0/23"
add list=nice address="202.152.206.0/23"
add list=nice address="202.152.240.0/23"
add list=nice address="202.154.176.0/23"
add list=nice address="202.158.130.0/23"
add list=nice address="202.162.46.0/23"
add list=nice address="202.179.184.0/23"
add list=nice address="202.180.4.0/23"
add list=nice address="202.180.8.0/23"
add list=nice address="202.182.164.0/23"
add list=nice address="202.182.168.0/23"
add list=nice address="202.182.176.0/23"
add list=nice address="202.182.182.0/23"
add list=nice address="202.182.184.0/23"
add list=nice address="202.191.2.0/23"
add list=nice address="203.6.148.0/23"
add list=nice address="203.12.20.0/23"
add list=nice address="203.21.74.0/23"
add list=nice address="203.24.76.0/23"
add list=nice address="203.27.6.0/23"
add list=nice address="203.29.26.0/23"
add list=nice address="203.30.236.0/23"
add list=nice address="203.30.254.0/23"
add list=nice address="203.31.164.0/23"
add list=nice address="203.34.118.0/23"
add list=nice address="203.57.24.0/23"
add list=nice address="203.77.214.0/23"
add list=nice address="203.77.216.0/23"
add list=nice address="203.77.240.0/23"
add list=nice address="203.77.246.0/23"
add list=nice address="203.79.26.0/23"
add list=nice address="203.89.146.0/23"
add list=nice address="203.99.96.0/23"
add list=nice address="203.99.102.0/23"
add list=nice address="203.99.130.0/23"
add list=nice address="203.134.232.0/23"
add list=nice address="203.146.36.0/23"
add list=nice address="203.148.84.0/23"
add list=nice address="203.153.60.0/23"
add list=nice address="203.189.88.0/23"
add list=nice address="203.190.36.0/23"
add list=nice address="203.190.48.0/23"
add list=nice address="203.190.190.0/23"
add list=nice address="203.194.70.0/23"
add list=nice address="203.201.50.0/23"
add list=nice address="203.201.166.0/23"
add list=nice address="203.209.188.0/23"
add list=nice address="203.210.80.0/23"
add list=nice address="203.217.172.0/23"
add list=nice address="203.223.90.0/23"
add list=nice address="210.23.76.0/23"
add list=nice address="219.83.68.0/23"
add list=nice address="219.83.124.0/23"
add list=nice address="223.255.224.0/23"
add list=nice address="27.111.32.0/24"
add list=nice address="27.111.36.0/24"
add list=nice address="27.111.63.0/24"
add list=nice address="32.234.168.0/24"
add list=nice address="32.234.170.0/24"
add list=nice address="49.0.2.0/24"
add list=nice address="58.147.188.0/24"
add list=nice address="58.147.191.0/24"
add list=nice address="60.253.126.0/24"
add list=nice address="101.0.5.0/24"
add list=nice address="101.0.6.0/24"
add list=nice address="103.3.78.0/24"
add list=nice address="110.232.78.0/24"
add list=nice address="111.67.71.0/24"
add list=nice address="111.67.73.0/24"
add list=nice address="111.67.80.0/24"
add list=nice address="111.67.83.0/24"
add list=nice address="111.67.84.0/24"
add list=nice address="111.67.91.0/24"
add list=nice address="111.67.95.0/24"
add list=nice address="111.92.160.0/24"
add list=nice address="111.92.172.0/24"
add list=nice address="111.223.252.0/24"
add list=nice address="112.78.33.0/24"
add list=nice address="112.78.39.0/24"
add list=nice address="112.78.100.0/24"
add list=nice address="112.78.188.0/24"
add list=nice address="112.78.191.0/24"
add list=nice address="112.215.5.0/24"
add list=nice address="112.215.13.0/24"
add list=nice address="112.215.16.0/24"
add list=nice address="112.215.21.0/24"
add list=nice address="112.215.27.0/24"
add list=nice address="112.215.29.0/24"
add list=nice address="112.215.30.0/24"
add list=nice address="112.215.33.0/24"
add list=nice address="112.215.34.0/24"
add list=nice address="112.215.42.0/24"
add list=nice address="112.215.46.0/24"
add list=nice address="112.215.49.0/24"
add list=nice address="112.215.50.0/24"
add list=nice address="113.11.132.0/24"
add list=nice address="113.11.143.0/24"
add list=nice address="113.11.156.0/24"
add list=nice address="113.11.159.0/24"
add list=nice address="113.208.67.0/24"
add list=nice address="114.1.3.0/24"
add list=nice address="114.4.1.0/24"
add list=nice address="114.4.12.0/24"
add list=nice address="114.4.16.0/24"
add list=nice address="114.4.21.0/24"
add list=nice address="114.4.35.0/24"
add list=nice address="114.4.44.0/24"
add list=nice address="114.4.47.0/24"
add list=nice address="114.5.1.0/24"
add list=nice address="114.5.5.0/24"
add list=nice address="114.6.8.0/24"
add list=nice address="114.6.14.0/24"
add list=nice address="114.30.86.0/24"
add list=nice address="114.129.18.0/24"
add list=nice address="114.141.57.0/24"
add list=nice address="114.141.60.0/24"
add list=nice address="115.124.90.0/24"
add list=nice address="115.166.123.0/24"
add list=nice address="116.12.40.0/24"
add list=nice address="116.12.43.0/24"
add list=nice address="116.68.165.0/24"
add list=nice address="116.68.168.0/24"
add list=nice address="116.90.161.0/24"
add list=nice address="116.90.165.0/24"
add list=nice address="116.90.168.0/24"
add list=nice address="116.193.188.0/24"
add list=nice address="116.199.205.0/24"
add list=nice address="117.18.17.0/24"
add list=nice address="117.18.20.0/24"
add list=nice address="117.102.72.0/24"
add list=nice address="117.103.11.0/24"
add list=nice address="118.91.128.0/24"
add list=nice address="119.82.237.0/24"
add list=nice address="119.82.239.0/24"
add list=nice address="119.82.247.0/24"
add list=nice address="119.110.74.0/24"
add list=nice address="119.110.79.0/24"
add list=nice address="120.89.92.0/24"
add list=nice address="121.52.1.0/24"
add list=nice address="121.52.25.0/24"
add list=nice address="121.52.29.0/24"
add list=nice address="121.52.35.0/24"
add list=nice address="121.52.40.0/24"
add list=nice address="121.52.42.0/24"
add list=nice address="121.52.45.0/24"
add list=nice address="121.52.62.0/24"
add list=nice address="121.52.84.0/24"
add list=nice address="121.52.91.0/24"
add list=nice address="121.52.129.0/24"
add list=nice address="121.101.190.0/24"
add list=nice address="122.102.47.0/24"
add list=nice address="122.102.52.0/24"
add list=nice address="123.108.97.0/24"
add list=nice address="123.176.124.0/24"
add list=nice address="123.176.127.0/24"
add list=nice address="124.158.141.0/24"
add list=nice address="152.158.247.0/24"
add list=nice address="175.103.49.0/24"
add list=nice address="175.103.50.0/24"
add list=nice address="175.103.60.0/24"
add list=nice address="180.92.212.0/24"
add list=nice address="180.150.232.0/24"
add list=nice address="180.150.244.0/24"
add list=nice address="180.214.234.0/24"
add list=nice address="180.233.119.0/24"
add list=nice address="180.233.153.0/24"
add list=nice address="182.16.160.0/24"
add list=nice address="182.253.2.0/24"
add list=nice address="192.5.5.0/24"
add list=nice address="192.8.8.0/24"
add list=nice address="192.23.186.0/24"
add list=nice address="193.194.194.0/24"
add list=nice address="202.1.236.0/24"
add list=nice address="202.3.14.0/24"
add list=nice address="202.4.179.0/24"
add list=nice address="202.4.185.0/24"
add list=nice address="202.9.69.0/24"
add list=nice address="202.9.85.0/24"
add list=nice address="202.10.36.0/24"
add list=nice address="202.10.39.0/24"
add list=nice address="202.10.44.0/24"
add list=nice address="202.10.61.0/24"
add list=nice address="202.12.75.0/24"
add list=nice address="202.14.255.0/24"
add list=nice address="202.37.120.0/24"
add list=nice address="202.45.149.0/24"
add list=nice address="202.46.12.0/24"
add list=nice address="202.46.129.0/24"
add list=nice address="202.47.80.0/24"
add list=nice address="202.47.88.0/24"
add list=nice address="202.51.100.0/24"
add list=nice address="202.51.108.0/24"
add list=nice address="202.51.113.0/24"
add list=nice address="202.51.220.0/24"
add list=nice address="202.52.50.0/24"
add list=nice address="202.52.52.0/24"
add list=nice address="202.52.131.0/24"
add list=nice address="202.52.132.0/24"
add list=nice address="202.55.162.0/24"
add list=nice address="202.55.172.0/24"
add list=nice address="202.57.14.0/24"
add list=nice address="202.58.124.0/24"
add list=nice address="202.59.192.0/24"
add list=nice address="202.59.198.0/24"
add list=nice address="202.59.255.0/24"
add list=nice address="202.61.96.0/24"
add list=nice address="202.61.126.0/24"
add list=nice address="202.65.227.0/24"
add list=nice address="202.70.136.0/24"
add list=nice address="202.70.138.0/24"
add list=nice address="202.72.196.0/24"
add list=nice address="202.72.202.0/24"
add list=nice address="202.72.206.0/24"
add list=nice address="202.74.43.0/24"
add list=nice address="202.75.22.0/24"
add list=nice address="202.75.31.0/24"
add list=nice address="202.81.32.0/24"
add list=nice address="202.81.49.0/24"
add list=nice address="202.87.245.0/24"
add list=nice address="202.93.245.0/24"
add list=nice address="202.94.80.0/24"
add list=nice address="202.95.144.0/24"
add list=nice address="202.95.147.0/24"
add list=nice address="202.124.203.0/24"
add list=nice address="202.124.205.0/24"
add list=nice address="202.135.5.0/24"
add list=nice address="202.135.16.0/24"
add list=nice address="202.135.23.0/24"
add list=nice address="202.137.225.0/24"
add list=nice address="202.137.230.0/24"
add list=nice address="202.146.142.0/24"
add list=nice address="202.147.230.0/24"
add list=nice address="202.147.234.0/24"
add list=nice address="202.150.164.0/24"
add list=nice address="202.151.8.0/24"
add list=nice address="202.152.192.0/24"
add list=nice address="202.152.199.0/24"
add list=nice address="202.152.243.0/24"
add list=nice address="202.152.244.0/24"
add list=nice address="202.152.246.0/24"
add list=nice address="202.153.159.0/24"
add list=nice address="202.154.179.0/24"
add list=nice address="202.154.183.0/24"
add list=nice address="202.154.185.0/24"
add list=nice address="202.154.187.0/24"
add list=nice address="202.158.129.0/24"
add list=nice address="202.158.252.0/24"
add list=nice address="202.160.254.0/24"
add list=nice address="202.162.44.0/24"
add list=nice address="202.167.97.0/24"
add list=nice address="202.169.248.0/24"
add list=nice address="202.171.233.0/24"
add list=nice address="202.179.186.0/24"
add list=nice address="202.180.7.0/24"
add list=nice address="202.180.10.0/24"
add list=nice address="202.180.13.0/24"
add list=nice address="202.180.14.0/24"
add list=nice address="202.180.48.0/24"
add list=nice address="202.180.51.0/24"
add list=nice address="202.182.166.0/24"
add list=nice address="202.182.170.0/24"
add list=nice address="202.182.189.0/24"
add list=nice address="203.1.25.0/24"
add list=nice address="203.14.176.0/24"
add list=nice address="203.14.183.0/24"
add list=nice address="203.17.21.0/24"
add list=nice address="203.19.4.0/24"
add list=nice address="203.77.212.0/24"
add list=nice address="203.77.220.0/24"
add list=nice address="203.77.223.0/24"
add list=nice address="203.77.255.0/24"
add list=nice address="203.79.29.0/24"
add list=nice address="203.89.148.0/24"
add list=nice address="203.99.98.0/24"
add list=nice address="203.99.119.0/24"
add list=nice address="203.99.120.0/24"
add list=nice address="203.99.123.0/24"
add list=nice address="203.99.127.0/24"
add list=nice address="203.119.13.0/24"
add list=nice address="203.119.17.0/24"
add list=nice address="203.119.112.0/24"
add list=nice address="203.134.234.0/24"
add list=nice address="203.134.238.0/24"
add list=nice address="203.142.72.0/24"
add list=nice address="203.146.33.0/24"
add list=nice address="203.153.49.0/24"
add list=nice address="203.160.128.0/24"
add list=nice address="203.163.76.0/24"
add list=nice address="203.163.81.0/24"
add list=nice address="203.171.221.0/24"
add list=nice address="203.173.89.0/24"
add list=nice address="203.173.90.0/24"
add list=nice address="203.190.51.0/24"
add list=nice address="203.190.188.0/24"
add list=nice address="203.194.90.0/24"
add list=nice address="203.196.90.0/24"
add list=nice address="203.207.52.0/24"
add list=nice address="203.207.55.0/24"
add list=nice address="203.207.59.0/24"
add list=nice address="203.209.190.0/24"
add list=nice address="203.210.83.0/24"
add list=nice address="203.210.87.0/24"
add list=nice address="203.215.48.0/24"
add list=nice address="203.215.50.0/24"
add list=nice address="203.217.140.0/24"
add list=nice address="210.23.68.0/24"
add list=nice address="216.244.94.0/24"
add list=nice address="218.100.70.0/24"
add list=nice address="219.83.70.0/24"
add list=nice address="223.255.229.0/24"
add list=nice address="223.255.230.0/24"






--Kemudian kembali di “New Terminal” winbox ketik printah berikut di “New Terminal” winbox,perintahnya:

--Keterangan:
Perhatikan interface local di bawah saya beri warna merah,jika nama interface anda yang mengarah ke client beda namanya tinggal anda tukar local dengan nama interface yang mengarah ke client anda:

/ip firewall mangle add chain=prerouting in-interface=local dst-address-list=nice action=mark-connection new-connection-mark=conn-lokal passthrough=yes

Selanjutnya:

/ip firewall mangle add chain=prerouting connection-mark=conn-lokal action=mark-packet new-packet-mark=packet-lokal passthrough=no

Selanjutnya:

/ip firewall mangle add chain=prerouting action=mark-packet new-packet-mark=packet-internasional passthrough=no

Selanjutnya:

/ip firewall mangle add chain=output action=mark-packet new-packet-mark=packet-internasional passthrough=no



Selanjutnya buat simple queue limit untuk ip address client1,di bawah ini ip address 192.168.0.5 hanya contoh nya saja,silahkan tukar ip address sesuai dengan keinginan anda,ketik perintah di bawah ini di “New Terminal”,perintahnya:

/queue simple add name="client1_lokal" target-addresses=192.168.0.5/32 dst-address=0.0.0.0/0 interface=all parent=none packet-marks=packet-lokal direction=both priority=8 queue=default-small/default-small limit-at=0/0 max-limit=512000/512000 total-queue=default-small

Selanjutnya untuk internasional:

/queue simple add name="client1_internasional" target-addresses=192.168.0.5/32 dst-address=0.0.0.0/0 interface=all parent=none packet-marks=packet-internasional direction=both priority=8 queue=default-small/default-small limit-at=0/0 max-limit=1000000/1000000 total-queue=default-small

mangel game

Bagi yang mempunyai warnet khusunya
warnet yang bertemakan GAME ONLINE
Berikut ini adalah mangle port game online yang nanti nya anda masukkan ke queue tree atau queue simple yang akan di jadikan prioritas yang tertinggi di mikrotik router,berikut ini mangle mangle port game online :

Di paket kan dulu Semua Game nya:

/ip firewall mangle
add action=mark-packet chain=forward comment="SEMUA GAME DIPAKETKAN" \
connection-mark="GAME KONEKSI" disabled=no new-packet-mark="GAME PAKET" \
passthrough=no


/ip firewall mangle
add action=mark-connection chain=prerouting comment="POKER KONEKSI" \
disabled=no dst-port=9339,843 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp

/ip firewall mangle
add action=mark-connection chain=prerouting comment="AYODANCE KONEKSI" \
disabled=no dst-port=18901,18902,18903,18904,18905,18906,18907,18908,18909 \
new-connection-mark="GAME KONEKSI" passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="SEAL ONLINE KONEKSI" \
disabled=no dst-port=1818 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp

/ip firewall mangle
add action=mark-connection chain=prerouting comment="LINE AGE2 KONEKSI" \
disabled=no dst-port=7777 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp

/ip firewall mangle
add action=mark-connection chain=prerouting comment="POINT BLANK KONEKSI UDP" \
disabled=no dst-port=40000-40010 new-connection-mark="GAME KONEKSI" \
passthrough=no protocol=udp


/ip firewall mangle
add chain=prerouting action=mark-connection \
new-connection-mark="GAME KONEKSI" passthrough=yes protocol=tcp \
dst-address=203.89.146.0/23 dst-port=39190 comment="POINT BLANK KONEKSI TCP"

/ip firewall mangle
add action=mark-connection chain=prerouting comment="RF KONEKSI UDP" \
disabled=no dst-port=10001,10002,10003,10004,10005,10006,10007 \
new-connection-mark="GAME KONEKSI" passthrough=no protocol=udp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="RF-ELVENT KONEKSI" \
disabled=no dst-port=27780 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp

/ip firewall mangle
add action=mark-connection chain=prerouting comment="PERFECT WORLD KONEKSI" \
disabled=no dst-port=29000 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="ROHAN KONEKSI" \
disabled=no dst-port=22100 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp

/ip firewall mangle
add action=mark-connection chain=prerouting comment="ZEUS RO KONEKSI" \
disabled=no dst-port=5121 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="DOTTA KONEKSI" \
disabled=no dst-port=6000-6152 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp

/ip firewall mangle
add action=mark-connection chain=prerouting comment="GHOST ONLINE KONEKSI" \
disabled=no dst-port=19101 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="WOW AMPM KONEKSI" \
disabled=no dst-port=8085 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="DRIFT CITY KONEKSI" \
disabled=no dst-port=11011-11041 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="GET AMPED KONEKSI" \
disabled=no dst-port=13413 new-connection-mark="GAME KONEKSI" \
passthrough=no protocol=tcp

/ip firewall mangle
add action=mark-connection chain=prerouting comment="YULLGANG KONEKSI" \
disabled=no dst-port=19000 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="IDOL STREET KONEKSI" \
disabled=no dst-port=2001 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="CRAZY KART KONEKSI" \
disabled=no dst-port=9601-9602 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="RAN ONLINE KONEKSI" \
disabled=no dst-port=5105 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="CROSS FIRE KONEKSI TCP" \
disabled=no dst-port=10009 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="CROSS FIRE KONEKSI UDP" \
disabled=no dst-port=40000-40010 new-connection-mark="GAME KONEKSI" \
passthrough=no protocol=udp

/ip firewall mangle
add action=mark-connection chain=prerouting comment="RETURN OF WARRIOR" \
disabled=no dst-port=10402 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp

/ip firewall mangle
add action=mark-connection chain=prerouting comment="CRAZY KART 2" \
disabled=no dst-port=9600 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="LUNA ONLINE" \
disabled=no dst-port=15002 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="RUNES OF MAGIC" \
disabled=no dst-port=16402-16502 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="FRESH RO" \
disabled=no dst-port=5126 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="CABAL INDONESIA" \
disabled=no dst-port=15001,15002 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp

Mangle WAR ROCK tcp port
/ip firewall mangle
add action=mark-connection chain=prerouting comment="WAR ROCK" \
disabled=no dst-port=5340-5352 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="FASTBLACK" \
disabled=no dst-port=6000-6001 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="ROSE ONLINE" \
disabled=no dst-port=29200 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="X-SHOT TCP" \
disabled=no dst-port=7341,7451 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp


/ip firewall mangle
add action=mark-connection chain=prerouting comment="X-SHOT UDP" \
disabled=no dst-port=7808,30000 new-connection-mark="GAME KONEKSI" \
passthrough=no protocol=udp

/ip firewall mangle
add action=mark-connection chain=prerouting comment="TANTRA ONLINE" \
disabled=no dst-port=3010 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp

/ip firewall mangle
add action=mark-connection chain=prerouting comment="HEROES OF NEWEARTH INCATAMERS TCP" \
disabled=no dst-port=11031 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp

/ip firewall mangle
add action=mark-connection chain=prerouting comment="HEROES OF NEWEARTH INCATAMERS UDP" \
disabled=no dst-port=11100-11125,11440-11460 new-connection-mark="GAME KONEKSI" \
passthrough=no protocol=udp

/ip firewall mangle
add action=mark-connection chain=prerouting comment="ATLANTICA" \
disabled=no dst-port=4300 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp dst-address=203.89.147.0/24


/ip firewall mangle
add action=mark-connection chain=prerouting comment="ECO ONLINE" \
disabled=no dst-port=12011,12110 new-connection-mark="GAME KONEKSI" \
passthrough=yes protocol=tcp



/queue tree
add name="Testing Down" parent=global-out limit-at=0 priority=8 max-limit=384k burst-limit=0 burst-threshold=0 burst-time=0s

add name="Testing Up" parent=global-in limit-at=0 priority=8 max-limit=96k burst-limit=0 burst-threshold=0 burst-time=0s

add name="Browsing Hotspot" parent="Testing Down" packet-mark=hotspot-down limit-at=64k queue=pcq-down priority=3 max-limit=384k burst-limit=384k burst-threshold=288k burst-time=16s

add name="Hotspot Up" parent="Testing Up" packet-mark=hotspot-up limit-at=64k queue=pcq-up priority=8 max-limit=96k burst-limit=0 burst-threshold=0 burst-time=0s


nah…sekarang tinggal anda buat queue tree atau simple nya..dengan prioritas tertinggi…

queun tree pcq

/ ip firewall mangle
add chain=forward protocol=!icmp src-address=192.168.0.1 action=mark-connection new-connection-mark=PC1-con passthrough=yes disabled=no
add chain=forward protocol=!icmp connection-mark=PC1-con action=mark-packet new-packet-mark=PC1 passthrough=no disabled=no
add chain=forward protocol=!icmp src-address=192.168.0.2 action=mark-connection new-connection-mark=PC2-con passthrough=yes disabled=no
add chain=forward protocol=!icmp connection-mark=PC2-con action=mark-packet new-packet-mark=PC2 passthrough=no disabled=no
add chain=forward protocol=!icmp src-address=192.168.0.3 action=mark-connection new-connection-mark=PC3-con passthrough=yes disabled=no
add chain=forward protocol=!icmp connection-mark=PC3-con action=mark-packet new-packet-mark=PC3 passthrough=no disabled=no
add chain=forward protocol=!icmp src-address=192.168.0.4 action=mark-connection new-connection-mark=PC4-con passthrough=yes disabled=no
add chain=forward protocol=!icmp connection-mark=PC4-con action=mark-packet new-packet-mark=PC4 passthrough=no disabled=no
add chain=forward protocol=!icmp src-address=192.168.0.5 action=mark-connection new-connection-mark=PC5-con passthrough=yes disabled=no
add chain=forward protocol=!icmp connection-mark=PC5-con action=mark-packet new-packet-mark=PC5 passthrough=no disabled=no
add chain=forward protocol=!icmp src-address=192.168.0.6 action=mark-connection new-connection-mark=PC6-con passthrough=yes disabled=no
add chain=forward protocol=!icmp connection-mark=PC6-con action=mark-packet new-packet-mark=PC6 passthrough=no disabled=no
add chain=forward protocol=!icmp src-address=192.168.0.7 action=mark-connection new-connection-mark=PC7-con passthrough=yes disabled=no
add chain=forward protocol=!icmp connection-mark=PC7-con action=mark-packet new-packet-mark=PC7 passthrough=no disabled=no
add chain=forward protocol=!icmp src-address=192.168.0.8 action=mark-connection new-connection-mark=PC8-con passthrough=yes disabled=no
add chain=forward protocol=!icmp connection-mark=PC8-con action=mark-packet new-packet-mark=PC8 passthrough=no disabled=no
add chain=forward protocol=!icmp src-address=192.168.0.9 action=mark-connection new-connection-mark=PC9-con passthrough=yes disabled=no
add chain=forward protocol=!icmp connection-mark=PC9-con action=mark-packet new-packet-mark=PC9 passthrough=no disabled=no
add chain=forward protocol=!icmp src-address=192.168.0.10 action=mark-connection new-connection-mark=PC10-con passthrough=yes disabled=no
add chain=forward protocol=!icmp connection-mark=PC10-con action=mark-packet new-packet-mark=PC10 passthrough=no disabled=no
/



queue type add name=Client-DL kind=pcq pcq-classifier=dst-address
queue type add name=Client-UL kind=pcq pcq-classifier=src-address



queue tree add name=Client-DL parent=ether2 max-limit=2048k
queue tree add name=Client-UL parent=ether1 max-limit=512k



queue tree add name=PC1-DL packet-mark=PC1 parent=Client-DL queue=Client-DL limit-at=512k max-limit=1024k burst-limit=2048k burst-time=10
queue tree add name=PC2-DL packet-mark=PC2 parent=Client-DL queue=Client-DL limit-at=512k max-limit=1024k burst-limit=2048k burst-time=10
queue tree add name=PC3-DL packet-mark=PC3 parent=Client-DL queue=Client-DL limit-at=512k max-limit=1024k burst-limit=2048k burst-time=10
queue tree add name=PC4-DL packet-mark=PC4 parent=Client-DL queue=Client-DL limit-at=512k max-limit=1024k burst-limit=2048k burst-time=10
queue tree add name=PC5-DL packet-mark=PC5 parent=Client-DL queue=Client-DL limit-at=512k max-limit=1024k burst-limit=2048k burst-time=10
queue tree add name=PC6-DL packet-mark=PC6 parent=Client-DL queue=Client-DL limit-at=512k max-limit=1024k burst-limit=2048k burst-time=10
queue tree add name=PC7-DL packet-mark=PC7 parent=Client-DL queue=Client-DL limit-at=512k max-limit=1024k burst-limit=2048k burst-time=10
queue tree add name=PC8-DL packet-mark=PC8 parent=Client-DL queue=Client-DL limit-at=512k max-limit=1024k burst-limit=2048k burst-time=10
queue tree add name=PC9-DL packet-mark=PC9 parent=Client-DL queue=Client-DL limit-at=512k max-limit=1024k burst-limit=2048k burst-time=10
queue tree add name=PC10-DL packet-mark=PC10 parent=Client-DL queue=Client-DL limit-at=512k max-limit=1024k burst-limit=2048k burst-time=10


queue tree add name=PC1-UL packet-mark=PC1 parent=Client-UL queue=Client-DL limit-at=128k max-limit=256k burst-limit=512k burst-time=10
queue tree add name=PC2-UL packet-mark=PC2 parent=Client-UL queue=Client-DL limit-at=128k max-limit=256k burst-limit=512k burst-time=10
queue tree add name=PC3-UL packet-mark=PC3 parent=Client-UL queue=Client-DL limit-at=128k max-limit=256k burst-limit=512k burst-time=10
queue tree add name=PC4-UL packet-mark=PC4 parent=Client-UL queue=Client-DL limit-at=128k max-limit=256k burst-limit=512k burst-time=10
queue tree add name=PC5-UL packet-mark=PC5 parent=Client-UL queue=Client-DL limit-at=128k max-limit=256k burst-limit=512k burst-time=10
queue tree add name=PC6-UL packet-mark=PC6 parent=Client-UL queue=Client-DL limit-at=128k max-limit=256k burst-limit=512k burst-time=10
queue tree add name=PC7-UL packet-mark=PC7 parent=Client-UL queue=Client-DL limit-at=128k max-limit=256k burst-limit=512k burst-time=10
queue tree add name=PC8-UL packet-mark=PC8 parent=Client-UL queue=Client-DL limit-at=128k max-limit=256k burst-limit=512k burst-time=10
queue tree add name=PC9-UL packet-mark=PC9 parent=Client-UL queue=Client-DL limit-at=128k max-limit=256k burst-limit=512k burst-time=10
queue tree add name=PC10-UL packet-mark=PC10 parent=Client-UL queue=Client-DL limit-at=128k max-limit=256k burst-limit=512k burst-time=10

seting mikrotik



Cara Memisahkan Browse, Download, Upload, Dan Game

Settingan ini Berjalan Pada Mikrotik RB750 OS ver.4.5 Dan percobaan Ini dilakukan pada mikrotik PC dengan Mikrotik Versi V2.9.27

Siapkan Perangkat PC dan Instal Mikrotik V2.9.27

Lan Card 1 menuju ISP dalam settingan ini menggunakan Speedy “Jaringan Speedy”
Lan Card 2 Menuju Jaringan Local dengan nama “Jaringan Local”
Setting IP untuk Lan 1 (Baca Tutorial Instal Mikrotik)
setting IP untuk Lan 2 (disini IP : 192.168.0.0/24
Settingan Yang akan Dilakukan :

GAME Poin Blank
Game Poker
BROWSING
UPLOAD
LIMIT DOWNLOAD
QUEUE
Tahapan atau teknik setting seperti berikut :

Settingan Untuk GAME Poin Blank
contoh buat Point Blank, game lain sesuaikan aja port/ip nya

Untuk Perintah Dibawah buatkan Pada bagian IP-Firewall-Mangle

————————————————————————————————-
chain=game action=mark-connection new-connection-mark=Game passthrough=yes protocol=tcp dst-address=203.89.146.0/23 dst-port=39190 comment=”Point Blank”
————————————————————————————————-
chain=game action=mark-connection new-connection-mark=Game passthrough=yes protocol=udp dst-address=203.89.146.0/23 dst-port=40000-40010
————————————————————————————————-
chain=game action=mark-packet new-packet-mark=Game_pkt passthrough=no connection-mark=Game
————————————————————————————————-
chain=prerouting action=jump jump-target=game
————————————————————————————————-

Settingan Untuk GAME Poker
Untuk Perintah Dibawah buatkan Pada bagian IP-Firewall-Mangle

————————————————————————————————-
chain=forward action=mark-connection new-connection-mark=Poker_con passthrough=yes protocol=tcp dst-address-list=LOAD POKER comment=”POKER”
————————————————————————————————-
chain=forward action=mark-connection new-connection-mark=Poker_con passthrough=yes protocol=tcp content=statics.poker.static.zynga.com
————————————————————————————————-
chain=forward action=mark-packet new-packet-mark=Poker passthrough=no connection-mark=Poker_con
————————————————————————————————-

BROWSING
————————————————————————————————-
chain=forward action=mark-connection new-connection-mark=http passthrough=yes protocol=tcp in-interface=WAN out-interface=Lan packet-mark=!Game_pkt connection-mark=!Game connection-bytes=0-262146 comment=”BROWSE”
————————————————————————————————-
chain=forward action=mark-packet new-packet-mark=http_pkt passthrough=no protocol=tcp connection-mark=http
————————————————————————————————-
chain=forward action=mark-packet new-packet-mark=http_pkt passthrough=no protocol=tcp connection-mark=http
————————————————————————————————-

UPLOAD
————————————————————————————————-
chain=prerouting action=mark-packet new-packet-mark=Upload passthrough=no protocol=tcp src-address=192.168.0.0/24 in-interface=Lan packet-mark=!icmp_pkt comment=”UPLOAD”
————————————————————————————————-

LIMIT DOWNLOAD
————————————————————————————————-
chain=forward action=mark-connection new-connection-mark=Download passthrough=yes protocol=tcp in-interface=WAN out-interface=Lan packet-mark=!Game_pkt connection-mark=!Poker_con connection bytes=262146-4294967295 comment=”LIMIT DOWNLOAD”
————————————————————————————————-
chain=forward action=mark-packet new-packet-mark=Download_pkt passthrough=no packet-mark=!Game_pk> connection-mark=Download
————————————————————————————————-

QUEUE
Queue Type
————————————————————————————————-
name=”Download” kind=pcq pcq-rate=256000 pcq-limit=50 pcq-classifier=dst-address pcq-total-limit=2000

name=”Http” kind=pcq pcq-rate=1M pcq-limit=50 pcq-classifier=dst-address pcq-total-limit=2000

name=”Game” kind=pcq pcq-rate=0 pcq-limit=50 pcq-classifier=src-address,dst-address,src-port,dst-port pcq-total-limit=2000

name=”Upload” kind=pcq pcq-rate=0 pcq-limit=50 pcq-classifier=src-address pcq-total-limit=2000
————————————————————————————————-

Queue Tree
————————————————————————————————-
name=”Main Browse” parent=Lan limit-at=0 priority=8 max-limit=1M burst-limit=0 burst-threshold=0 burst-time=0s

name=”Browse” parent=Main Browse packet-mark=http_pkt limit-at=0 queue=Http priority=8 max-limit=1M burst-limit=0 burst-threshold=0 burst-time=0s

name=”Game” parent=global-total packet-mark=Game_pkt limit-at=0 queue=Game priority=1 max-limit=0 burst-limit=0 burst-threshold=0 burst-time=0s

name=”Poker” parent=global-out packet-mark=Poker limit-at=0 queue=Game priority=3 max-limit=0 burst-limit=0 burst-threshold=0 burst-time=0s

name=”Download” parent=global-out packet-mark=Download_pkt limit-at=0 queue=Download priority=8 max-limit=256k burst-limit=0 burst-threshold=0 burst-time=0s

name=”Main Upload” parent=global-in limit-at=0 priority=8 max-limit=256k burst-limit=0 burst-threshold=0 burst-time=0s

name=”Upload” parent=Main Upload packet-mark=Upload limit-at=0 queue=Upload priority=8 max-limit=0 burst-limit=0 burst-threshold=0 burst-time=0s
————————————————————————————————-

Membatasi BW jika suatu traffic client melewati batas tertentu

add name="Isp" target-addresses=192.111.111.99/32 dst-address=0.0.0.0/0 \

    interface=all parent=none direction=both priority=8 \

    queue=default-small/share-ni-down limit-at=0/0 max-limit=32000/64000 \

    burst-limit=/128000 burst-threshold=/30000 burst-time=/10s \

    total-queue=default-small disabled=no
dan kita menginginkan membatasi bandwidth-nya jika trafficnya sudah melewati misalkan 500MB dalam satu hari, maka kita bisa membuat script dibawah ini:

add name="trafwatcher01" source="

/queue simple

:local traf;

:set traf [get [find name="Isp"] total-bytes]

:if ($traf  > 500000000) do = {

set [find name="Isp"] max-limit= 32000/32000

:log info "isp traffic exceeding 500MB"}

policy=ftp,reboot,read,write,policy,test,winbox,password
variabel traf fungsinya untuk menampung sementara nilai total traffic

buat scheduler untuk mengecek traffic script-nya, misalnya dibuat setiap 1/2 jam untuk mengeceknya.

Code:

add name="trafisp" on-event=trafwatcher01 start-date=jan/01/1970 \

    start-time=11:00:00 interval=30m comment="" disabled=no
nah itu untuk script untuk membatasinya, tinggal membuat script satu lagi jika sudah melewati satu hari (misal jam 12 malam), counternya mereset total traffic queue client tsb dan mereset bandwidthnya normal ke 64 kbps lagi.

GOODLUCK

mudahan ini bisa jadi gambaran :

/queue simple

:local traf;

:local maxi;

:set traf [get [find name="Isp"] total-bytes]

:set maxi [get [find name="Isp"] max-limit]

:if ($traf  < 10000000 && $maxi != "64000/96000") do = {

set [find name="Isp"] max-limit= "64000/96000"}

:if ($traf  > 10000000 && $maxi != "64000/64000") do = {

set [find name="Isp"] max-limit= "64000/64000"}

:if ($traf  > 100000000 && $maxi != "64000/32000") do = {

set [find name="Isp"] max-limit= "32000/32000"

/sys sched disa [find name="isp-trafwatcher"]}
Penjelasan:

Gue buat 2 tingkat bandwidth limiternya jadi dibawah 10MB masih sesuai limit awal, 10 – 100 MB turun jadi 64k, atas 100MB jadi 32k

biar script ngga ngulang ngulang terus di log-nya dibuat satu variabel lagi yaitu variabel maxi yang menampung setting bandwidthnya, kalo tidak sama dengan logika-nya maka que simple ga di set ulang.

di script terakhir ditambahin buat mendisable schedulernya biar scheduler ga jalan terus ( di disable).

nah biar enable lagi, perlu dibuat satu script lagi untuk men-clear counter trafficnya dan meng-enable lagi schedulernya,misalnya tiap jam 00:00

script buat enable lagi en autoclear counter. kasi nama script bebas, abis itu buat juga schedulenya

Code:

/ip fire filt reset-counters-all
/que tree reset-counters-all

/que sim reset-counters-all

/sys sched ena [find name="isp-trafwatcher"]
Membagi Bandwidth Rata dengan PCQ di Mikrotik

Dengan menggunakan queue type pcq di Mikrotik, kita bisa membagi bandwidth yang ada secara merata untuk para “pelahap-bandwidth” saat jaringan pada posisi peak.

Contohnya, kita berlangganan 256 Kbps. Kalau ada yang sedang berinternet ria, maka beliau dapat semua itu jatah bandwidth. Tetapi begitu teman-temannya datang, katakanlah 9 orang lagi, maka masing-masingnya dapat sekitar 256/10 Kbps.

Yah.. masih cukup layaklah untuk buka-buka situs non-porn atau sekedar cek e-mail & blog.

OK, langsung saja ke caranya :

Asumsi : Network Address 192.168.169.0/28, interface yang mengarah ke pengguna diberi nama LAN, dan interface yang mengarah ke upstream provider diberi nama INTERNET;
Ketikkan di console atau terminal :
> /ip firewall mangle add chain=forward src-address=192.168.169.0/28 action=mark-connection new-connection-mark=NET1-CM
> /ip firewall mangle add connection-mark=NET1-CM action=mark-packet new-packet-mark=NET1-PM chain=forward
> /queue type add name=downsteam-pcq kind=pcq pcq-classifier=dst-address
> /queue type add name=upstream-pcq kind=pcq pcq-classifier=src-address
> /queue tree add parent=LAN queue=DOWNSTREAM packet-mark=NET1-PM
> /queue tree add parent=INTERNET queue=UPSTREAM packet-mark=NET1-PM
Good Luck!!
kalo pake cara diatas targetnya cuman sebisa mungkin membagi bandwidth sama rata antar client..
kalo menghadapi IDM pengalaman saya gak bisa pake cara di atas, harus ditambah masing-masing client dibuat mangle-nya dan queue tree typenya pake pcq.

contoh: nama client = unyil ip-nya=192.168.1.12/32 bw-limitnya=64k/128k
caranya:
> /ip firewall mangle add chain=forward src-address=192.168.1.12/32 action=mark-connection new-connection-mark=UNYIL-CM
> /ip firewall mangle add connection-mark=UNYIL-CM action=mark-packet new-packet-mark=UNYIL-PM chain=forward
> /queue type add name=downsteam-pcq kind=pcq pcq-classifier=dst-address
> /queue type add name=upstream-pcq kind=pcq pcq-classifier=src-address
> /queue tree add parent=LAN queue=UNYIL_DOWNSTREAM packet-mark=UNYIL-PM max-limit=128k
> /queue tree add parent=INTERNET queue=UNYIL_UPSTREAM packet-mark=UNYIL-PM max-limit=64k

mengatur bandwith berdasarkan waktu siang dan malam

Sekarang kita coba untuk mengatur bandwith user Hotspot berdasarkan waktu pagi dan malam, karena pada siang hari banyak user yang kuliah jadi bandwith kosong, dan malam banyak user yang browsing dan download

Untuk Script Limit bandwith malam :
1.Akses Router Miktorik anda
2.System > Clock > kemudian perhatikan date(tgl) & time(waktu)
3.System > Scripts > New Script isikan data berikut :
Name : Limit Malam
Policy : Conteng Read, Policy dan Write
Source :
/ip hotspot user profile set 125 idle-timeout=none keepalive-timeout=2m status-autorefresh=1m shared-users=1 rate-limit=64k/128k transparent-proxy=yes open-status-page=always advertise=no

4.System > Scheduler > New Schedule isikan data berikut :
Name : Malam
Start Date : (tgl mulai disesuaikan dengan tgl di mikrotik) jun/28/2009
Start Time : (waktu mulai disesuaikan kebutuhan) 19:00:00 (untuk jam 7 mlm)
Interval : 1d 00:00:00 (rolling per 1 hari)
On Event :
Limit Malam
Untuk Script Limit bandwith siang :
1.System > Scripts > New Script isikan data berikut :
Name : Limit Siang
Policy : Conteng Read, Policy dan Write
Source :
/ip hotspot user profile set 125 idle-timeout=none keepalive-timeout=2m status-autorefresh=1m shared-users=1 rate-limit=64k/256k transparent-proxy=yes open-status-page=always advertise=no
nb:silahkan sesuaian pada user yg laen
2.System > Scheduler > New Schedule isikan data berikut :
Name : Siang
Start Date : (tgl mulai disesuaikan dengan tgl di mikrotik) jun/28/2009
Start Time : (waktu mulai disesuaikan kebutuhan) 07:00:00 (untuk jam 7 pagi)
Interval : 1d 00:00:00 (rolling per 1 hari)
On Event :
Limit Siang
Langkah diatas secara otomatis akan memberikan setting limit pada siang hari 64k/256k mulai jam 7 pagi s/d jam 7 mlm sedangkan limit bandwith malam hari 64k/128k mulai jam 7 mlm s/d jam 7 pagi.
Semua setting bisa disesuaikan dengan kebutuhan, mudah-mudahan bisa dengan mudah dimengerti dan membantu.

Pengamanan Mikrotik dari Scan Winbox dan Neighbour
On October 8, 2008, in MikroTik, Networking, by Oemar-BGS

0

Kadang kala para ISP atau penyedia jasa layanan tidak terlalu jeli untuk melindungi customernya. Terutama ketika melindungi router pelanggan yang menggunakan Mikrotik RouterOS(tm). Dengan menjalankan IP >> Neighbor kita bisa melihat router mikrotik lainnya yang secara fisik terhubung dengan router kita melalui jaringan di provider kita.
Untuk itu kita bisa melindunginya dengan berbagai cara misalnya memblok scan dari winbox dan neighbor kita. Berikut adalah cara yang paling mudah :

Code:

admin@mikrotik] interface bridge> filter print
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; block discovery mikrotik
chain=forward in-interface=ether1 mac-protocol=ip dst-port=5678
ip-protocol=udp action=drop
1 ;;; block discovery mikrotik
chain=input in-interface=ether1 mac-protocol=ip dst-port=5678
ip-protocol=udp action=drop
2 ;;; block discovery mikrotik
chain=output mac-protocol=ip dst-port=5678 ip-protocol=udp action=drop
3 ;;; block discovery mikrotik
chain=input in-interface=ether1 mac-protocol=ip dst-port=8291
ip-protocol=tcp action=drop
4 ;;; block winbox mikrotik
chain=forward in-interface=ether1 mac-protocol=ip dst-port=8291
ip-protocol=tcp action=drop
5 ;;; block request DHCP
chain=input mac-protocol=ip dst-port=68 ip-protocol=udp action=drop
6 ;;; block request DHCP
chain=forward mac-protocol=ip dst-port=68 ip-protocol=udp action=drop
7 ;;; block request DHCP
chain=output mac-protocol=ip dst-port=68 ip-protocol=udp action=drop
Dengan perintah tersebut kita bisa menutup beberapa scan terutama yang menggunakan winbox dan ip neighbor. Port diatas adalah bagian dari share Mikrotik RouterOS yang memang di perlukan untuk monitoring.

24 Sep 2011
CARA MEMBLOKIR SITUS-SITUS TERTENTU (PORNO)
00:01 Diposkan oleh tantoroni

Salah satu masalah yang sering kita jumpai dalam dunia maya adalah beberapa situs dewasa yang semakin banyak jumlahnya. Mungkin, kita sebagai orang yang paham terhadap komputer dan Internet bisa saja mengenali dan waspada terhadap situs-situs dewasa tersebut. Tetapi bagaimana bila anak-anak yang sedang mencoba berselancar di internet melalui Pc atau Laptop kita terjaring masuk ke dalam situs-situs dewasa tersebut?

Salah satu cara untuk mengatasi hal ini adalah Dengan menggunakan software anti-p0rn dari tu Eagles. Langkah-langkahnya adalah sebagai berikut:

1. Download softwarenya dulu dari sini
2. Download softwarenya dengan meng-klik tombol Local download, perlu diperhatikan juga bahwa software ini masih berjalan dalam platform Windows, belum ada versi iOS nya.

3. Setelah di download kemudian klik dua kali terhadap aplikasinya, kemudian lakukan Next pada halaman Welcome.

4. Klik Install pada halaman Installasi agar proses installasi bisa dilanjutkan.

5. Tunggulah samai proses installasi berjalan.

6. Jika sudah selesai maka akan ada pilihan untuk me-restart komputer anda. Berikan tanda centang untuk me-restart dan sebaliknya, hapus tanda centang untuk tidak me-restart Windows anda.

7. Secara Default, icon mata akan bertambah di ujung kanan bawah pada taskbar windows anda.

8. Klik kanan > Settings and Options > masukkan Password anda.

Dengan trik ini, semua situs yang terblokir oleh aplikasi ini tidak akan lagi bisa diakses melalui komputer/notebook anda. Selamat mencoba.

Penulis Artikel : Nathan Gusti Ryan

DHCP Server ( Dynamic Host Configuration Protocol ) adalah Sebuah Server yang menyediakan Services atau memberikan layanan IP Address Otomatis bagi Client yang IP Address-nya di setting Automatic. DHCP Server menyediakan konfigurasi IP Address Otomatis yang meliputi : IP Address, IP Gateway dan IP DNS Server.

Membuat DHCP Server Mikrotik memanglah sangat mudah, tapi bagi beginner bisa bikin puyeng juga. So… Artikel ini adalah konfigurasi yang lebih manusiawi dengan konfigurasi melalui Winbox. Selain melalui Winbox, kita bisa melakukan konfigurasi DHCP Server melalui Console / CLI, Telnet, WebBox, dll.

Berikut ini Step by Step membuat DHCP Server Mikrotik dengan Winbox :

1. Pastikan semua konfigurasi Mikrotik telah selesai dan siap pakai. Lalu masuk ke menu : IP -> DHCP SERVER.
2. Pada menu DHCP Server, pilih menu DHCP Setup untuk memulai Wizard-nya. Lalu pilih interface yang akan di gunakan untuk memberikan layanan DHCP. Tentunya disini kita akan mengunakan Interface LAN lalu kita klik Next.

3. Selanjutnya kita menentukan DHCP Address Space. Karena IP Address jairngan LAN kita adalah 192.168.0.xxx/24 maka secara otomatis Wizard akan menawarkan DHCP Address Space : 192.168.0.0/24

4. Selanjutnya kita menentukan IP Gateway untuk DHCP ini. IP Gateway adalah IP Address dari interface yang menjembatani antara jaringan LAN dan Mikrotik, tentunya pada contoh Mikrotik ini kita gunakan IP Address : 192.168.0.1, lalu kita klik Next.

5. Selanjutnya kita menentukan DHCP IP Address Range alias alokasi IP Address yang akan di layani untuk Client. Pada Mikrotik ini kita tentukan IP Address Range yang dilayani adalah 192.168.0.100 – 192.168.0.200. Lalu kita Klik Next.

6. Selanjutnya menentukan IP Address DNS Server. Disini kita dapat mengunakan IP DNS yang di gunakan oleh Provider kita atau bisa mengunakan IP DNS punya Nawala, yaitu :  180.131.144.144 dan 180.131.145.145. Lalu kita klik Next…

7. Selanjutnya kita menentukan LEASE TIME alias Waktu Persewaan IP Address atau Waktu yang di sewakan. Intinya adalah Lama waktu yang diberikan kepada Client untuk mengunakan IP Address otomatis dari DHCP Server Mikrotik. Misalnya kita berikan waktu 4 jam ( 4:00:00 ) -> Artinya : Jika Client masih terkoneksi ke jaringan LAN melebihi waktu 4 jam, maka Client tersebut akan tetap mendapatkan IP Address yang sama dan lease time-nya kembali mulai 4 jam lagi. Namun jika dalam waktu 4 jam Client sudah tidak terkoneksi ke jaringan maka IP Address tersebut dapat digunakan oleh Client yang lain. Lalu kita klik Next.

8. Selanjutnya akan muncul tampilan seperti dibawah ini : “Setup has completed successfully”. Berarti Wizard DHCP Server telah selasai dan telah sukses kita lakukan. Lalu kita klik “OK”.

9. Selanjutnya kalau kita buka menu : IP -> POOL maka kita akan ada IP Pool baru dengan nama “dhcp_pool1? yang berisi IP : 192.168.0.100 – 192.168.0.200. ( lihat langkah ke 5 ).

10. Selanjutnya kita dapat mengamati pada menu tab “Leases”. Disitu ditampilkan informasi dari Layanan DHCP Server, termasuk informasi client penguna DHCP. Informasi tersebut berupa : Nama Host, IP Address yang digunakan, Mac Address, Lease Time, dll. Kita juga dapat menjadikan suatu IP Address khusus bagi suatu client tertentu, istilahnya adalah IP Address Reservation ( Reservasi IP Address ). IP Address Reservation dilakukan berdasarkan Mac Addres. Cukup Klik IP Address yang akan di buat statik lalu klik menu “Make Static” atau dengan cara Klik kanan lalu klik “Make Static”.


Mudah sekali bukan???  Selamat mencoba…

BLOK SITUS

facebook

/ip firewall filter add chain=forward src-address=0.0.0.0/0 protocol=tcp \ dst-port=80 content=”facebook” action=drop comment=”Blokir Situs Facebook”;

twitter

/ip firewall filter add chain=forward src-address=0.0.0.0/0 protocol=tcp \ dst-port=80 content=”twitter” action=drop comment=”Blokir Situs twitter”;

youtube

/ip firewall filter add chain=forward src-address=0.0.0.0/0 protocol=tcp \ dst-port=80 content=”youtube” action=drop comment=”Blokir Situs youtube”;

WEB PROXY

ip web proxy web proxy setting v enable apply ok

add dst host=*.facebook.com;*.twitter.com action=deny apply ok

LAYER 7 PROTOCOL

ip firewall layer 7 protocol add name:denied action=drop/reject regexp=^.+(facebook|twitter|youtube).*$ app ok

address list add name=nama user address=ip user

filter rule add advanced dst address list=nama user layer 7 protocol=denied action=drop/reject comment=… apply ok

FIREWALL

add chain=forward action=mark-connection new-connection mark=download passthrough=yes protocol=tcp in-interface=wan out-interface=lan connection–bytes=128000-4294967295

add chain=forward action=mark-packet new-packet-mark=download passthrough=no protocol=tcp in-interface=wan out-interface=lan connection-mark=download

add chain=forward action=mark-connection new-connection-mark=upload passthrough=yes protocol=tcp in-interface=wan out-interface=lan connection-bytes=64000-4294967295

add chain=forward action=mark-packet new-packet-mark=upload passthrough=no protocol=tcp in-interface=lan out-interface=wan connection-mark=upload

add chain=forward action=mark-connection new-connection-mark=browse passthrough=yes protocol=tcp in-interface=wan out-interface=lan connection-bytes=0-128000

add chain=forward action=mark-packet new-packet-mark=browse passthrough=no protocol=tcp in-interface=wan out-interface=lan connection-mark=browse

FIREWALL PROXY

FIREWALL PROXY SEJAJAR DENGAN ROUTER

/ip firewall mangle add chain=prerouting action=mark-packet new-packet-mark=p2p passthrough=no connection-mark=p2p-conn

/ip firewall mangle add chain=prerouting action=mark-connection new-connection-mark=other_conn passthrough=yes

/ip firewall nat add chain=dst-nat to-address=ip pc proxy to-ports=8000 protocol=tcp src-address=!ip pc proxy src-address-list=warnet in-interface=lan dst-port=80

/ip firewall nat add chain=dstnat action=dst-nat to-address=ip pc proxy to-ports=8000

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.pdf address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.exe address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.zip address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.rar address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.tar address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.mov address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.3gp address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.mp3 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.mp4 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.mkv address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.avi address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.mpeg address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.flv address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.001 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.002 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.003 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.004 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.005 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.006 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.007 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.008 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.009 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.010 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.011 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.012 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.013 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.014 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.015 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.016 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.017 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.018 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.019 address-list=download

/ip firewall filter add chain=forward action=add-dst-to-address-list protocol=tcp src-address=ip pusat(192.168.88.0/25) content=*.020 address-list=download

FILE OVER

LOAD BALANCING FAIL OVER

merubah ether eth1=wan1 eth2=wan2 eth3=lan

set ip, misal: wan1=10.10.10.5/29 wan2=10.10.11.5/29 lan=192.168.10.1/28

/ip address add

set gateway

/ip route add gateway=10.10.10.1 apply ok

/ip route add gateway=10.10.11.1 apply ok

/ip route add dst-address=0.0.0.0/0 gateway=10.10.10.1 scope=255 target=10 routing-mark=odd comment=”…”disabled=no

/ip route add dst-address=0.0.0.0/0 gateway=10.10.11.1 scope=255 target=10 routing-mark=even comment=”…”disabled=no

/ip route add dst-address=0.0.0.0/0 gateway=10.10.10.1 scope=255 target=10 comment=”…”disabled=no

/ip firewall mangle add chain=prerouting in-interface=lan connection-state=new nth=10,1 action=mark-connection new-connection-mark=odd passthrough=yes comment=”..” disabled=no

/ip firewall mangle add chain=prerouting in-interface=lan connection-mark=odd action=mark-routing new=routing-mark=odd passthrough=no comment=”..” disabled=no

/ip firewall mangle add chain=prerouting in-interface=lan connection-state=new nth=11,1 action=mark-connection new-connection-mark=even passthrough=yes comment=”..” disabled=no

/ip firewall mangle add chain=prerouting in-interface=lan connection-mark=even action=mark-routing new-routing-mark=even passthrough=no comment=”..” disabled=no

/ip firewall nat add chain=srcnat action=masquerade src-address=192.168.10.1

/ip firewall nat add chain=src-nat to-address=10.10.10.5 to-ports=0-65535 protocol=tcp connection-mark=even

/ip firewall nat add chain=src-nat to-address=10.10.10.5 to-ports=0-65535 protocol=tcp connection-mark=odd

/ip firewall nat add chain=src-nat out-interface=10.10.10.5 action=masquerade

/ip firewall filter add chain=input action=drop protocol=tcp in-interface=lan dst-port=135-139,445

/ip firewall filter add chain=input action=drop protocol=udp in-interface=lan dst-port=135-139,445

/ip firewall filter add chain=forward action=drop protocol=tcp in-interface=lan dst-port=25,135,137-139,445,593,1025,4691,5933

/ip firewall filter add chain=forward action=drop protocol=udp in-interface=lan dst-port=25,135,137-139,445,593,1025,4691,5933

/ip firewall filter add chain=forward action=drop p2p=bit-torrent

/ip firewall filter add chain=forward action=accept connection-state=established

/ip firewall filter add chain=forward action=accept connection-state=related

/ip firewall filter add chain=forward action=drop connection-state=invalid

LOAD BALANCING

LOAD BALANCING TIPE PCC

/ip address add address=192.168.10.5/30 interface=wan1

/ip address add address=192.168.20.5/30 interface=wan2

/ip address add address=192.168.1.1/28 interface=lan

/ip dns set allow-remote-request=yes primary-dns=180.131.144.144 secondary-dns=180.131.145.145

/ip route add dst-address=0.0.0.0/0 gateway=192.168.10.1 distance=1 check-gateway=ping

/ip route add dst-address=0.0.0.0/0 gateway=192.168.20.1 distance=2 check-gateway=ping

/ip firewall nat add action=masquerade chain=src-nat out-interface=wan1

/ip firewall nat add action=masquerade chain=src-nat out-interface=wan2

/ip firewall address-list add address=192.168.10.0/30 list=local

/ip firewall address-list add address=192.168.10.0/30 list=local

/ip firewall address-list add address=192.168.10.0/30 list=local

/ip firewall mangle add action=accept chain=prerouting dst-address-list=local in-interface=lan comment=”trafik lokal”

/ip firewall mangle add action=accept chain=output dst-address-list=local

==========================================================================

TAMBAHAN UNTUK FIREWALL MANGLE

/ip firewall mangle add action=mark-connection chain=prerouting connection-mark=no-mark in-interface=wan1 new-connection-mark=con-from-isp1 passthrough=yes comment=”trafik dari isp1?

/ip firewall mangle add action=mark-connection chain=prerouting connection-mark=no-mark in-interface=wan2 new-connection-mark=con-from-isp2 passthrough=yes comment=”trafik dari isp2?

/ip firewall mangle add action=mark-connection chain=output comment=dns dst-address=125.160.2.34 dst-port=53 new-connection-mark=dns passthrough=yes protocol=tcp comment=”trafik dns telkom speedy”

/ip firewall mangle add action=mark-connection chain=output dst-address=202.134.1.10 dst-port=53 new-connection-mark=dns passthrough=yes protocol=udp

/ip firewall mangle add action=mark-routing chain=output connection-mark=dns

/ip route add check gateway=ping dst-address=0.0.0.0/0 gateway=192.168.10.1 routing-mark=route-to-isp1 distance=1

/ip route add check gateway=ping dst-address=0.0.0.0/0 gateway=192.168.20.1 routing-mark=route-to-isp1 distance=2

/ip route add check gateway=ping dst-address=0.0.0.0/0 gateway=192.168.20.1 routing-mark=route-to-isp2 distance=1

/ip route add check gateway=ping dst-address=0.0.0.0/0 gateway=192.168.10.1 routing-mark=route-to-isp2 distance=2