Follow us on...
Follow us on G+ Follow us on Twitter Follow us on Facebook Watch us on YouTube
Register
Page 3 of 8 FirstFirst 12345 ... LastLast
Results 31 to 45 of 107
  1. #31
    Status
    Offline
    faiz_mahbob's Avatar
    Member
    Join Date
    Sep 2009
    Posts
    248
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by Raden_otonk Click here to enlarge
    setuju nich, ane malah suka simple, enak praktis gak repot bikin mange.... nubie nich.....Click here to enlarge
    eh, tapi setingan joko di ataz bener gak sich maz, bisa buat contekan nich.......Click here to enlarge, pengen jajal kue tree enak pa gak nich.....Click here to enlarge
    yahh...kemaren aku juga make simple kwewe....akhirnya ganti ke kwewe tree, lebih enak pake connection byte. IDM mati kutu, brosing masih aman.kalo mau di coba punya ku monggo. . . tapi ngga jaminan loh ya..wong aku ini nubie sejati.itu juga hasil oplosan comot sana sini.

  2. #32
    Status
    Offline
    Raden_otonk's Avatar
    Member
    Join Date
    Feb 2010
    Posts
    121
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by faiz_mahbob Click here to enlarge
    yahh...kemaren aku juga make simple kwewe....akhirnya ganti ke kwewe tree, lebih enak pake connection byte. IDM mati kutu, brosing masih aman.kalo mau di coba punya ku monggo. . . tapi ngga jaminan loh ya..wong aku ini nubie sejati.itu juga hasil oplosan comot sana sini.
    kalo punya saya kayak gini kaka..... pake simple, coz enak gak ribet....

    [azalia@MikroTik] /ip firewall mangle> print
    Flags: X - disabled, I - invalid, D - dynamic
    0 ;;; Proxy Hit
    chain=prerouting action=mark-packet new-packet-mark=Hit passthrough=no
    dscp=12

    19 ;;; Server
    chain=prerouting action=mark-connection new-connection-mark=server
    passthrough=yes src-address=192.168.10.2

    20 chain=prerouting action=mark-packet new-packet-mark=server passthrough=no
    packet-mark=!Hit connection-mark=server

    21 chain=forward action=mark-packet new-packet-mark=server donlot
    passthrough=no protocol=tcp dst-address=192.168.10.2 packet-mark=!Hit
    connection-mark=server connection-bytes=307200-0
    simple quenya

    11 name="PC-SERVER-LOSS" target-addresses=192.168.10.2/32
    dst-address=0.0.0.0/0 interface=all parent=Proxy Hit direction=both
    priority=1 queue=default/default limit-at=0/0 max-limit=0/256k
    burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s
    total-queue=default
    que trenya

    0 name="00.server" parent=global-out packet-mark=server donlot limit-at=0
    queue=default priority=8 max-limit=200k burst-limit=0 burst-threshold=0
    burst-time=0s
    dengan harapan ketika server lagi browsing dan belum melawati nilai con byte maka dia dpat banwit full 256k, apabila telah melewati nilai con byte, maka akan dilempar ke que tre sehingga masih ada sisa 56k buat browsing"......
    bener gak kaka Click here to enlarge
    cuman warnet kecil kaka......Click here to enlargeClick here to enlarge

  3. #33
    Status
    Offline
    adiputrolds's Avatar
    Forum Guru
    Join Date
    Oct 2008
    Posts
    1,485
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by Raden_otonk Click here to enlarge

    [azalia@MikroTik] /ip firewall mangle> print
    Flags: X - disabled, I - invalid, D - dynamic
    0 ;;; Proxy Hit
    chain=prerouting action=mark-packet new-packet-mark=Hit passthrough=no
    dscp=12

    19 ;;; Server
    chain=prerouting action=mark-connection new-connection-mark=server
    passthrough=yes src-address=192.168.10.2

    20 chain=prerouting action=mark-packet new-packet-mark=server passthrough=no
    packet-mark=!Hit connection-mark=server

    21 chain=forward action=mark-packet new-packet-mark=server donlot
    passthrough=no protocol=tcp dst-address=192.168.10.2 packet-mark=!Hit
    connection-mark=server connection-bytes=307200-0

    lebih baik jangan cuman melimit per-ip client dengan simple queue
    sebaiknya dibedakan buat browsing dan download
    jadi browsing tetap enak.....

    ya sebaiknya pakek queue-tree....

  4. #34
    Status
    Offline
    faiz_mahbob's Avatar
    Member
    Join Date
    Sep 2009
    Posts
    248
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by electrix_85 Click here to enlarge
    lebih baik jangan cuman melimit per-ip client dengan simple queue
    sebaiknya dibedakan buat browsing dan download
    jadi browsing tetap enak.....

    ya sebaiknya pakek queue-tree....
    yepp...kalo kata master2 yg udah pengalaman, lebih baik gunakan satu jenis queue.pilih salah satu aja, Tree atau simple, biar ngga rancu.aku sih nurut aja apa kata master2, ngga berani nglawan.Click here to enlarge

  5. #35
    Status
    Offline
    Raden_otonk's Avatar
    Member
    Join Date
    Feb 2010
    Posts
    121
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    thanks kaka atas masukanya, pernah sich pake que tre, tapi responnya lambat, buka poker jadi lama ato ane yang salah seting yach, maklum nubie...Click here to enlarge
    eh ya, yang bener peletakan con byte itu di mark connection apa di mark paket sich kaka, coz punya saya con bytenya di mark paket.......Click here to enlarge

  6. #36
    Status
    Offline
    putra_maiwa's Avatar
    Forum Guru
    Join Date
    Sep 2009
    Posts
    1,298
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by faiz_mahbob Click here to enlarge
    yepp...kalo kata master2 yg udah pengalaman, lebih baik gunakan satu jenis queue.pilih salah satu aja, Tree atau simple, biar ngga rancu.aku sih nurut aja apa kata master2, ngga berani nglawan.Click here to enlarge
    bisa juga kok pake dua2nya, asal rule yg di queue jgn di dua2nya (contoh : limi down di queue simple dan tree)

    kelompokan paketnya,
    Code:
    bila paket limiter pisah IIX dan INTER + up and down di queue simple
    untuk paket gaple, game, youtube, critical dll.. di queue tree 
    :th_angry2:
    gitu juga bisa


    Click here to enlarge Originally Posted by Raden_otonk Click here to enlarge
    thanks kaka atas masukanya, pernah sich pake que tre, tapi responnya lambat, buka poker jadi lama ato ane yang salah seting yach, maklum nubie...Click here to enlarge
    eh ya, yang bener peletakan con byte itu di mark connection apa di mark paket sich kaka, coz punya saya con bytenya di mark paket.......Click here to enlarge
    cocoknya di con byte di letakan pada mark-conn Click here to enlarge

  7. #37
    Status
    Offline
    faiz_mahbob's Avatar
    Member
    Join Date
    Sep 2009
    Posts
    248
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    tuh,,,udah dikasih masukan sama porum guru. maknyus itu.

  8. #38
    Status
    Offline
    joko_kuno's Avatar
    Member Super Senior
    Join Date
    Apr 2010
    Posts
    601
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    maaf masih nubie nich.
    perkataan mas putra kayak gini:
    cocoknya di con byte di letakan pada mark-conn Click here to enlarge
    sedangkan punya maz faiz conn bytenya ada di mark paket.....Click here to enlarge
    ip firewall mangle
    add action=mark-connection chain=forward comment="mark shape donload LAN" \
    disabled=no new-connection-mark=all-con out-interface=2lan passthrough=yes \
    protocol=tcp
    bikin packet mark buat donlod
    add action=mark-packet chain=forward comment="browse-grupA" connection-bytes=\
    1-256000 connection-mark=all-con disabled=no dst-address-list=A \
    new-packet-mark=BR-A out-interface=2lan passthrough=no protocol=tcp
    add action=mark-packet chain=forward comment="browse-grupB" connection-bytes=\
    1-256000 connection-mark=all-con disabled=no dst-address-list=B \
    new-packet-mark=BR-B out-interface=2lan passthrough=no
    bikin juga donlod packet mark
    add action=mark-packet chain=forward comment="donlod-grupA" connection-bytes=\
    256000-4294967295 connection-mark=all-con disabled=no dst-address-list=A \
    new-packet-mark=DL-A out-interface=2lan passthrough=no
    add action=mark-packet chain=forward comment="donlod-grupB" connection-bytes=\
    256000-4294967295 connection-mark=all-con disabled=no dst-address-list=B \
    new-packet-mark=DL-B out-interface=2lan passthrough=no
    sebenarnya apa efeknya jika conn byte di letakan di mark conn / di mark packet sedangkan conn byte sendiri adalah bertugas untuk menandai besaran aliran suatu koneksi, jika <256k akan diarahkan ke que browsing dan jika >256k akan masuk ke que donlot, seperti itukah maz"......Click here to enlarge
    mohon pencerahan masalah pemahaman dari conn byte.....Click here to enlargeClick here to enlarge
    duh, susah bener sich bikin mange yang bener......Click here to enlargeClick here to enlarge
    (otodidak+trial error selalu.... semangaaaaattttttClick here to enlargeClick here to enlarge)

  9. #39
    Status
    Offline
    adiputrolds's Avatar
    Forum Guru
    Join Date
    Oct 2008
    Posts
    1,485
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by joko_kuno Click here to enlarge
    maaf masih nubie nich.
    perkataan mas putra kayak gini:


    sedangkan punya maz faiz conn bytenya ada di mark paket.....Click here to enlarge


    sebenarnya apa efeknya jika conn byte di letakan di mark conn / di mark packet sedangkan conn byte sendiri adalah bertugas untuk menandai besaran aliran suatu koneksi, jika <256k akan diarahkan ke que browsing dan jika >256k akan masuk ke que donlot, seperti itukah maz"......Click here to enlarge
    mohon pencerahan masalah pemahaman dari conn byte.....Click here to enlargeClick here to enlarge
    duh, susah bener sich bikin mange yang bener......Click here to enlargeClick here to enlarge
    (otodidak+trial error selalu.... semangaaaaattttttClick here to enlargeClick here to enlarge)
    memang agak membingungkan dikit
    hahhahaha........

    tp kalo menurut logika ku sepertinya harus terjadi di mark-packet

    alasannya karena akan membaca byte dari connection yg telah terjadi
    jadi harus ada dulu connection-nya yg sudah ada baru di labeli dengan mark-packet

    apa masuk akal jika di mark-connection ???


    contoh :
    /ip firewall mangle

    add chain=postrouting action=mark-connection new-connection-mark=Direct-Down out-interface=Local passthrough=yes

    add chain=postrouting action=mark-packet new-packet-mark=light connection-mark=Direct-Down connection-byte=0-256000 passthrough=no

    add chain=postrouting action=mark-packet new-packet-mark=heavy connection-mark=Direct-Down connection-byte=256001-0 passthrough=no

    jadi semua traffic direct-down yg menuju Local di mark connection-nya
    lalu dengan membaca connection-connection pada connection Direct-Down bisa di baca mana yg connection-byte nya <=256 KB dan mana yg >256 KB dan di beri packet-mark masing-masing


    Yang menjadi pertanyaan ??
    pada mark-packet light passthrough apa yg cocok digunakan , saya agak ragu jika menggunakan passthrough=no
    karena tidak berhenti situ saja
    jika telah melampaui 256 KB kan masih harus di teruskan pada mangle di bawahnya ....

    CMIIW jika salah ya ; butuh response juga neh Click here to enlarge
    Last edited by adiputrolds; 12-07-2010 at 19:38.

  10. #40
    Status
    Offline
    joko_kuno's Avatar
    Member Super Senior
    Join Date
    Apr 2010
    Posts
    601
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    iya nich maz sama, susah bikin mangle yang bener, belum lagi masalah chain, coz di sini kebanyakan pake forward/prerouting....trus kegunaanya postrouting buat apa?.....Click here to enlarge
    kalo pastroug=no berarti paket itu tidak diteruskan ke mangle bawahnya.... gitu mungkin... namanya aja NO.......CMIIW....Click here to enlarge
    nunggu master lewat aja, coz menurut ane nich pemahaman dasar nich.....Click here to enlarge
    cari tempat duduk dulu ach.......Click here to enlargeClick here to enlarge

  11. #41
    Status
    Offline
    adiputrolds's Avatar
    Forum Guru
    Join Date
    Oct 2008
    Posts
    1,485
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by joko_kuno Click here to enlarge
    iya nich maz sama, susah bikin mangle yang bener, belum lagi masalah chain, coz di sini kebanyakan pake forward/prerouting....trus kegunaanya postrouting buat apa?.....Click here to enlarge
    kalo pastroug=no berarti paket itu tidak diteruskan ke mangle bawahnya.... gitu mungkin... namanya aja NO.......CMIIW....Click here to enlarge
    nunggu master lewat aja, coz menurut ane nich pemahaman dasar nich.....Click here to enlarge
    cari tempat duduk dulu ach.......Click here to enlargeClick here to enlarge
    sebenernya gk cocok kalo di tanya kegunaan postrouting itu apa !!!

    itu salah satu chain flow data

    kamu harus tau dulu flow data , coba liat urutan nya

    emang kebanyakan yg di gunakan prerouting dan forward karena kebanyakan packet itu hanya di lewatkan dari satu interface ke interface lainnya.
    jarang yg menggunakan chain input dan output.


    Code:
                                                ---------   input  --- [Local Process] --- output --- postrouting --- out-interface
                                               |
    in-interface --- prerouting --- [Routing Decision] --- forward --- postrouting --- out-interface
    jadi kira2 ada 3 alur data
    1. in-interface --- prerouting --- input --- Local Process
    2. Local Process --- output --- postrouting --- out-interface
    3. in-interface --- prerouting --- forward --- postrouting --- out-interface

    perlu di pahami semua incomiing di mulai dari prerouting.
    chain prerouting terletak sebelom routing decision dengan kata lain bisa menangkap packet yg di tujukan ke local process ataupun yg akan di forward langsung ke interface lainnya...

    jangan heran kalo prerouting dan forward paling sering di gunakan..

    chain prerouting bisa menghandle packet both direction jadi kebanyakan di pakek untuk menangkap paket yg akan di gunakan di simple queue

    sedangkan forward dan postrouting saya kira hampir2 mirip
    di gunakan pada queue tree untuk menangkap packet searah....

    upstream saja
    atau downstream saja
    Last edited by adiputrolds; 12-07-2010 at 22:15.

  12. The Following User Says Thank You to adiputrolds For This Useful Post:


  13. #42
    Status
    Offline
    joko_kuno's Avatar
    Member Super Senior
    Join Date
    Apr 2010
    Posts
    601
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    bener" dah maz elektrik nyetrum banget nich ulasanya.......Click here to enlarge
    ane copy+print+pahami maz yach Click here to enlargeClick here to enlarge
    thanks alot maz...Click here to enlarge

  14. #43
    Status
    Offline
    adiputrolds's Avatar
    Forum Guru
    Join Date
    Oct 2008
    Posts
    1,485
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by joko_kuno Click here to enlarge
    bener" dah maz elektrik nyetrum banget nich ulasanya.......Click here to enlarge
    ane copy+print+pahami maz yach Click here to enlargeClick here to enlarge
    thanks alot maz...Click here to enlarge
    Click here to enlarge

  15. #44
    Status
    Offline
    adiputrolds's Avatar
    Forum Guru
    Join Date
    Oct 2008
    Posts
    1,485
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    oh mau nambahin neh chain linux
    sama aja di mikrotik karena mikrotik di build dari kernel linux

    Click here to enlarge

    di prerouting terjadi dst-nat
    di postrouting terjadi src-nat

    mark-routing hanya bisa terjadi di prerouting dan output ^^

    Click here to enlarge

  16. #45
    Status
    Offline
    joko_kuno's Avatar
    Member Super Senior
    Join Date
    Apr 2010
    Posts
    601
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    hmmm apakah implementasinya seperti inikah..... bener" nubie masalah perroutingan.....Click here to enlarge
    mangle untuk proxy
    /ip firewall mangle
    add action=mark-packet chain=prerouting comment="" disabled=no dscp=12 \
    in-interface=proxy new-packet-mark=Hit passthrough=no
    mangle untuk seluruh coneksi klient
    add action=mark-connection chain=forward comment=all disabled=no \
    new-connection-mark=Local-Con packet-mark=!Hit passthrough=yes protocol=\
    tcp src-address-list=otonk-net
    nah baru koneksi dari seluruh klient di pecah per IP...
    untuk upload
    add action=mark-packet chain=prerouting comment=Server disabled=no \
    in-interface=lokal new-packet-mark=server-up packet-mark=!icmp_pkt \
    passthrough=no protocol=tcp src-address=192.168.10.2
    untuk browsing
    add action=mark-packet chain=postrouting comment="" connection-bytes=0-307200 \
    connection-mark=Local-Con disabled=no dst-address=192.168.10.2 \
    new-packet-mark=server-browsing out-interface=lokal packet-mark=!Hit \
    passthrough=no protocol=!icmp
    untuk donlot
    add action=mark-packet chain=postrouting comment="" connection-bytes=307201-0 \
    connection-mark=Local-Con disabled=no dst-address=192.168.10.2 \
    new-packet-mark=server-donlot out-interface=lokal packet-mark=!Hit \
    passthrough=no protocol=!icmp
    addres list
    add address=192.168.10.2 comment="" disabled=no list=otonk-net
    add address=192.168.10.3 comment="" disabled=no list=otonk-net
    add address=192.168.10.4 comment="" disabled=no list=otonk-net
    add address=192.168.10.5 comment="" disabled=no list=otonk-net
    add address=192.168.10.6 comment="" disabled=no list=otonk-net
    sperti inikah maz, maaf coz teori ane gak begitu paham banget, (cuman dikit) coz basic ane teknik mesin....(gak nyambung ma router"an)Click here to enlarge
    tapi tetep usaha keras untuk memahami dunia per routinganClick here to enlargeClick here to enlarge
    thanks maz atas semuanya....Click here to enlarge

 

 
Page 3 of 8 FirstFirst 12345 ... LastLast

Thread Information

Users Browsing this Thread

There are currently 2 users browsing this thread. (0 members and 2 guests)

Similar Threads

  1. Mohon Bantuan Nya
    By unyil_asjhrc in forum Wireless Networking
    Replies: 6
    Last Post: 31-12-2009, 11:10
  2. Mohon Bantuan ???
    By ghostonk in forum General Networking
    Replies: 2
    Last Post: 24-04-2009, 05:13
  3. [ask] mohon bantuan
    By sone in forum General Networking
    Replies: 1
    Last Post: 30-04-2008, 09:02
  4. Mohon Bantuan
    By rezaferd in forum General Networking
    Replies: 4
    Last Post: 21-11-2007, 17:01

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •