Follow us on...
Follow us on G+ Follow us on Twitter Follow us on Facebook Watch us on YouTube
Register
Page 1 of 2 12 LastLast
Results 1 to 15 of 22
  1. #1
    Status
    Offline
    hr10f's Avatar
    Member
    Join Date
    Mar 2010
    Posts
    119
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0

    mac filter ga jalan??

    Mohon bantuan, kk n sodara semua.Click here to enlarge

    mac filter saya kok gak jalan ya. apa yang salah y..?
    add action=drop chain=input comment="Reject MAC" disabled=no \
    src-mac-address=!00:00:00:00:00:00

    trus kalau di buat drop saya gak bisa login ke mikrotik lewat ip address, mesti lewat mac address dan lemotnya minta ampun...

    mohon bantuaanya y

  2. #2
    Status
    Offline
    zdienos's Avatar
    Forum Guru
    Join Date
    Feb 2010
    Location
    ~/makasar
    Posts
    1,252
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by hr10f Click here to enlarge
    Mohon bantuan, kk n sodara semua.Click here to enlarge

    mac filter saya kok gak jalan ya. apa yang salah y..?
    add action=drop chain=input comment="Reject MAC" disabled=no \
    src-mac-address=!00:00:00:00:00:00

    trus kalau di buat drop saya gak bisa login ke mikrotik lewat ip address, mesti lewat mac address dan lemotnya minta ampun...

    mohon bantuaanya y
    ini yang maw difilter MAC nya berapa???, kalau ada tanda "!" itu berarti kecuali..
    nah kalo' diartikan di atas, drop semua mac address selain 00:00:00:00:00:00..

    maaf, bukannya kasih solusi, malah balik bertanya.... he he he...Click here to enlarge

  3. The Following 2 Users Say Thank You to zdienos For This Useful Post:


  4. #3
    Status
    Offline
    xeon's Avatar
    Verified Account - Partner
    Join Date
    Mar 2008
    Location
    DKI Jakarta
    Posts
    1,539
    Reviews
    Read 0 Reviews
    Downloads
    3
    Uploads
    0
    Feedback Score
    2 (100%)
    Click here to enlarge Originally Posted by hr10f Click here to enlarge
    add action=drop chain=input comment="Reject MAC" disabled=no \
    src-mac-address=!00:00:00:00:00:00
    Arti bahasa indonesianya:

    Selain asal komputer dengan mac address 00:00:00:00:00:00, dengan tujuan masuk ke mikrotik, akan direject.

  5. The Following 2 Users Say Thank You to xeon For This Useful Post:


  6. #4
    Status
    Offline
    hr10f's Avatar
    Member
    Join Date
    Mar 2010
    Posts
    119
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by zdienos Click here to enlarge
    ini yang maw difilter MAC nya berapa???, kalau ada tanda "!" itu berarti kecuali..
    nah kalo' diartikan di atas, drop semua mac address selain 00:00:00:00:00:00..

    maaf, bukannya kasih solusi, malah balik bertanya.... he he he...Click here to enlarge
    oo, begitu maksud tanda pentung. setting ini saya dapat dari tempat sy membeli mikrotik dan perangkat wifi. benar sekali, setiap saya pake rule ini semua klient gak bisa apa-apa jadinya. Mohon bantu solusinya gan, kita ini nubi banget. thank

  7. #5
    Status
    Offline
    oktama's Avatar
    Forum Guru
    Join Date
    Jul 2008
    Location
    Jayapura
    Posts
    1,929
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by hr10f Click here to enlarge
    oo, begitu maksud tanda pentung. setting ini saya dapat dari tempat sy membeli mikrotik dan perangkat wifi. benar sekali, setiap saya pake rule ini semua klient gak bisa apa-apa jadinya. Mohon bantu solusinya gan, kita ini nubi banget. thank
    tinggal buat ajah rules-nya kan

    Code:
    add action=drop chain=input comment="Reject MAC" disabled=no \
    src-mac-address=!00:00:00:00:00:00
    00:00:00:00:00:00 ganti pake mac-address yang boleh konek

  8. The Following 2 Users Say Thank You to oktama For This Useful Post:


  9. #6
    Status
    Offline
    hr10f's Avatar
    Member
    Join Date
    Mar 2010
    Posts
    119
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by oktama Click here to enlarge
    tinggal buat ajah rules-nya kan

    Code:
    add action=drop chain=input comment="Reject MAC" disabled=no \
    src-mac-address=!00:00:00:00:00:00
    00:00:00:00:00:00 ganti pake mac-address yang boleh konek
    maaf, tanya lagi kang. saya punya 12client yg mesti di kasih lewat. Jadi saya mesti buat 12 rule seperti di atas dengan Mac masing2. apa benarClick here to enlarge

  10. #7
    Status
    Offline
    rto
    rto's Avatar
    Newbie
    Join Date
    Jun 2010
    Posts
    49
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    dengan terpaksa, iya gan..
    semakin ingin secure, admin kudu ngalah semakin ribet Click here to enlarge

  11. The Following 2 Users Say Thank You to rto For This Useful Post:


  12. #8
    Status
    Offline
    oktama's Avatar
    Forum Guru
    Join Date
    Jul 2008
    Location
    Jayapura
    Posts
    1,929
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by hr10f Click here to enlarge
    maaf, tanya lagi kang. saya punya 12client yg mesti di kasih lewat. Jadi saya mesti buat 12 rule seperti di atas dengan Mac masing2. apa benarClick here to enlarge
    tuh dah dijawab diatas Click here to enlarge
    keamanan berbanding kenyamanan selalu berbanding terbalik, disaat keamanan ditingkatkan kenyamanan berkurang, ada kompie rusak ganti kompie kl lan pake onboard terpaksa rubah filter mac lagi Click here to enlargeClick here to enlarge

  13. The Following 2 Users Say Thank You to oktama For This Useful Post:


  14. #9
    abhiebol
    abhiebol's Avatar
    Click here to enlarge Originally Posted by oktama Click here to enlarge
    tinggal buat ajah rules-nya kan

    Code:
    add action=drop chain=input comment="Reject MAC" disabled=no \
    src-mac-address=!00:00:00:00:00:00
    00:00:00:00:00:00 ganti pake mac-address yang boleh konek
    tapi tetep kan client bisa internetan tapi gak bisa masuk mikrotik yah....

  15. The Following 2 Users Say Thank You to abhiebol For This Useful Post:


  16. #10
    Status
    Offline
    clovanzo's Avatar
    Member Senior
    Join Date
    Sep 2007
    Posts
    408
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    emang sulit kalo maksain di 1 rule, paling bisa kayak gini

    Code:
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:01
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:02
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:03
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:04
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:05
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:06
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:07
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:08
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:09
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:10
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:11
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:12
    add action=drop chain=forward comment="Reject ALL" disabled=no \
    ke 12 mac diganti dengan mac-address yang di allow

  17. The Following 2 Users Say Thank You to clovanzo For This Useful Post:


  18. #11
    abhiebol
    abhiebol's Avatar
    Click here to enlarge Originally Posted by clovanzo Click here to enlarge
    emang sulit kalo maksain di 1 rule, paling bisa kayak gini

    Code:
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:01
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:02
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:03
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:04
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:05
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:06
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:07
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:08
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:09
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:10
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:11
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:12
    add action=drop chain=forward comment="Reject ALL" disabled=no \
    ke 12 mac diganti dengan mac-address yang di allow
    pertanyaan saya yang sama jika menggunakan settingan ini kan berarti ke 12 MAC Address ini tidak dapat masuk ke Winbox tapi apakah bisa internet juga gak???
    Click here to enlarge

  19. The Following User Says Thank You to abhiebol For This Useful Post:


  20. #12
    Status
    Offline
    xeon's Avatar
    Verified Account - Partner
    Join Date
    Mar 2008
    Location
    DKI Jakarta
    Posts
    1,539
    Reviews
    Read 0 Reviews
    Downloads
    3
    Uploads
    0
    Feedback Score
    2 (100%)
    Settingan tersebut, ke 12 mac address itu tetap bisa masuk ke mikrotik, tetapi tidak bisa ke internet, karena chainnya "forward". Kalau yang diinginkan adalah tidak bisa masuk ke mikrotik, maka chain harus diganti menjadi "input".

  21. The Following 2 Users Say Thank You to xeon For This Useful Post:


  22. #13
    Status
    Offline
    clovanzo's Avatar
    Member Senior
    Join Date
    Sep 2007
    Posts
    408
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    setelah saya baca baca lagi.. ini tujuannya menghindari user untuk akses winbox bukan membatasi akses internet? Click here to enlarge

    saya rasa menggunakan strong password + allowed address nya diisi sudah lebih dari cukup.

  23. The Following User Says Thank You to clovanzo For This Useful Post:


  24. #14
    Status
    Offline
    hr10f's Avatar
    Member
    Join Date
    Mar 2010
    Posts
    119
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by clovanzo Click here to enlarge
    emang sulit kalo maksain di 1 rule, paling bisa kayak gini

    Code:
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:01
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:02
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:03
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:04
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:05
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:06
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:07
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:08
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:09
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:10
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:11
    add action=accept chain=forward disabled=no \
    src-mac-address=00:00:00:00:00:12
    add action=drop chain=forward comment="Reject ALL" disabled=no \
    ke 12 mac diganti dengan mac-address yang di allow
    mas, jika saya tambahkan rule
    add action=drop chain=forward comment="Reject ALL" disabled=no \
    di paling bawah kok semua jadi tidak bisa internetan
    jika di disable baru bisa inet lagi
    semua mac client sudah saya daftar seperti contoh di atas. Click here to enlarge

    apa yg salah ya...?

  25. #15
    abhiebol
    abhiebol's Avatar
    Click here to enlarge Originally Posted by xeon Click here to enlarge
    Settingan tersebut, ke 12 mac address itu tetap bisa masuk ke mikrotik, tetapi tidak bisa ke internet, karena chainnya "forward". Kalau yang diinginkan adalah tidak bisa masuk ke mikrotik, maka chain harus diganti menjadi "input".
    ok deh...terima kasih...caba tak praktekkan dulu...Click here to enlarge

 

 
Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. [ask] filter mac address
    By kabuto in forum Scripting @ Mikrotik
    Replies: 12
    Last Post: 28-11-2011, 22:07
  2. Filter rules
    By anarcy99 in forum General Networking
    Replies: 1
    Last Post: 09-08-2010, 12:02
  3. browsing pake mikrotik ga bisa jalan, nge-ping jalan
    By bludab in forum Beginner Basics
    Replies: 14
    Last Post: 13-02-2010, 20:19
  4. tolong di filter
    By alie in forum General Networking
    Replies: 10
    Last Post: 12-09-2008, 11:53
  5. (ask) filter dan blok ip
    By agung in forum Beginner Basics
    Replies: 3
    Last Post: 28-11-2007, 09:42

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •