Follow us on...
Follow us on G+ Follow us on Twitter Follow us on Facebook Watch us on YouTube
Register
Page 1 of 2 12 LastLast
Results 1 to 15 of 26
  1. #1
    Status
    Offline
    ikonk's Avatar
    Newbie
    Join Date
    Mar 2014
    Posts
    20
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0

    Sharing file beda ip dan 2 line speedy

    Permisi semuanya..
    newbie mau tanya
    skema jaringan di kantor ane kira2 begini :

    Ether 1
    Speedy 1 ---- | |----- Ether 3 Switch 1 (gateway : speedy 1)
    | | 192.168.10.0/26
    |===== Mikrotik==== | gateway 192.168.10.1
    | |
    Ether 2 | |
    Speedy 2 ---- | |------ Ether 4 Switch 2 (gateway : Speedy 2)
    192.168.20.0/26
    gateway 192.168.20.1

    tujuan ane mau sharing file dari address 192.168.10.0/26 ke 192.168.20.0/26, begitu juga sebaliknya... gimana settingnya ??
    dari masing2 address sudah bisa browsing..

    mohon pencerahannya...Thx

  2. #2
    Status
    Offline
    brutuz_1's Avatar
    VIP Member
    Join Date
    Feb 2010
    Posts
    792
    Reviews
    Read 0 Reviews
    Downloads
    3
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by ikonk Click here to enlarge
    Permisi semuanya..
    newbie mau tanya
    skema jaringan di kantor ane kira2 begini :

    Ether 1
    Speedy 1 ---- | |----- Ether 3 Switch 1 (gateway : speedy 1)
    | | 192.168.10.0/26
    |===== Mikrotik==== | gateway 192.168.10.1
    | |
    Ether 2 | |
    Speedy 2 ---- | |------ Ether 4 Switch 2 (gateway : Speedy 2)
    192.168.20.0/26
    gateway 192.168.20.1

    tujuan ane mau sharing file dari address 192.168.10.0/26 ke 192.168.20.0/26, begitu juga sebaliknya... gimana settingnya ??
    dari masing2 address sudah bisa browsing..

    mohon pencerahannya...Thx
    langsung tembak ip client nya, biasanya di network places gk bakalan muncul dengan sendiri nya kalo beda segmen ip...Click here to enlarge

  3. #3
    Status
    Offline
    ikonk's Avatar
    Newbie
    Join Date
    Mar 2014
    Posts
    20
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by brutuz_1 Click here to enlarge
    langsung tembak ip client nya, biasanya di network places gk bakalan muncul dengan sendiri nya kalo beda segmen ip...Click here to enlarge
    gabisa di ping juga gan, misalnya ane dari 192.168.10.5 langsung ke client \\192.168.20.5 juga gabisa

  4. #4
    Status
    Offline
    tkgit's Avatar
    Member
    Join Date
    Mar 2014
    Location
    nomaden
    Posts
    175
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    ping klien 10.xx ke ip gw 20.1 bisa ga?
    kalau bisa harusnya antar klien udah bisa konek, asal setting firewall & AV udah allow
    kalau ga bisa berarti setting di RB ada yg belum bener

  5. #5
    Status
    Offline
    ikonk's Avatar
    Newbie
    Join Date
    Mar 2014
    Posts
    20
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by tkgit Click here to enlarge
    ping klien 10.xx ke ip gw 20.1 bisa ga?
    kalau bisa harusnya antar klien udah bisa konek, asal setting firewall & AV udah allow
    kalau ga bisa berarti setting di RB ada yg belum bener
    ping client 10.xx ke GW 20.1 bisa gan.... kira2 apa penyebabnya ya???

  6. #6
    Status
    Offline
    junstm's Avatar
    Baru Gabung
    Join Date
    Aug 2012
    Posts
    7
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by ikonk Click here to enlarge
    Permisi semuanya..
    newbie mau tanya
    skema jaringan di kantor ane kira2 begini :

    Ether 1
    Speedy 1 ---- | |----- Ether 3 Switch 1 (gateway : speedy 1)
    | | 192.168.10.0/26
    |===== Mikrotik==== | gateway 192.168.10.1
    | |
    Ether 2 | |
    Speedy 2 ---- | |------ Ether 4 Switch 2 (gateway : Speedy 2)
    192.168.20.0/26
    gateway 192.168.20.1

    tujuan ane mau sharing file dari address 192.168.10.0/26 ke 192.168.20.0/26, begitu juga sebaliknya... gimana settingnya ??
    dari masing2 address sudah bisa browsing..

    mohon pencerahannya...Thx
    address listnya kudu d tambah kali bro, untuk ether 3 & ether 4

  7. #7
    Status
    Offline
    chabyiolue's Avatar
    Member
    Join Date
    Feb 2010
    Posts
    228
    Reviews
    Read 0 Reviews
    Downloads
    9
    Uploads
    0
    Feedback Score
    0
    ping antara client speedy 1 sama speedy 2 replay gak gan ....
    contoh client spdy1 IP 10.2 ke client spdy2 20.2 .... sudah bisa blom ....

  8. #8
    Status
    Offline
    ikonk's Avatar
    Newbie
    Join Date
    Mar 2014
    Posts
    20
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by junstm Click here to enlarge
    address listnya kudu d tambah kali bro, untuk ether 3 & ether 4
    di address list udah ane isi utk ether 3 & 4 gan dari awal

    Click here to enlarge Originally Posted by chabyiolue Click here to enlarge
    ping antara client speedy 1 sama speedy 2 replay gak gan ....
    contoh client spdy1 IP 10.2 ke client spdy2 20.2 .... sudah bisa blom ....
    justri ini masalahnya gan, ga bisa ping antara client 10.xxx <> 20.xxx

  9. #9
    Status
    Offline
    chabyiolue's Avatar
    Member
    Join Date
    Feb 2010
    Posts
    228
    Reviews
    Read 0 Reviews
    Downloads
    9
    Uploads
    0
    Feedback Score
    0
    berarti harus buat statick route gan ....
    misalkan agan mau ping dari client spdy1 10.x ke 20.x berarti agan harus melewati ip speedy2 dulo dong untuk sampai ke client spdy2, begitu juga sebaliknya .....
    sudah agan buat blom routenya ....

    misalkan dari speedy1 mau menuju ke sppdy 2 agan harus buat dst.address : 20.0/24 gateway : speedy2 begitu juga sebaliknya .....
    maaf kalo salah .... Click here to enlarge

  10. #10
    Status
    Offline
    brutuz_1's Avatar
    VIP Member
    Join Date
    Feb 2010
    Posts
    792
    Reviews
    Read 0 Reviews
    Downloads
    3
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by ikonk Click here to enlarge
    di address list udah ane isi utk ether 3 & 4 gan dari awal


    justri ini masalahnya gan, ga bisa ping antara client 10.xxx <> 20.xxx
    pingin tanya dulu... ip client emang di kasih berapa?? 192.168.10.??? 192.168.20.???
    Click here to enlarge Originally Posted by chabyiolue Click here to enlarge
    berarti harus buat statick route gan ....
    misalkan agan mau ping dari client spdy1 10.x ke 20.x berarti agan harus melewati ip speedy2 dulo dong untuk sampai ke client spdy2, begitu juga sebaliknya .....
    sudah agan buat blom routenya ....

    misalkan dari speedy1 mau menuju ke sppdy 2 agan harus buat dst.address : 20.0/24 gateway : speedy2 begitu juga sebaliknya .....
    maaf kalo salah .... Click here to enlarge
    harus nya gk usah bikin statik routing, karna udah tercreate otomatis routing untuk kedua segment ip lokal tersebut (/26), kecuali emang kalo TS menggunakan IP di atas 64, itulah mengapa saya pengen tau ip yg di gunakan client nya berapa,Click here to enlarge

  11. #11
    Status
    Offline
    ikonk's Avatar
    Newbie
    Join Date
    Mar 2014
    Posts
    20
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by brutuz_1 Click here to enlarge
    pingin tanya dulu... ip client emang di kasih berapa?? 192.168.10.??? 192.168.20.???


    harus nya gk usah bikin statik routing, karna udah tercreate otomatis routing untuk kedua segment ip lokal tersebut (/26), kecuali emang kalo TS menggunakan IP di atas 64, itulah mengapa saya pengen tau ip yg di gunakan client nya berapa,Click here to enlarge
    Ip client ane kasih 192.168.10.2-63/26 & 192.168.20.2-63/26 ..... mohon contoh routenya gan.... ane newbie soalnya
    gateway masing2 ISP : Speedy 1 > 192.168.10.1 & speedy 2 > 192.168.20.1

    mohon pencerahan gan

  12. #12
    Status
    Offline
    brutuz_1's Avatar
    VIP Member
    Join Date
    Feb 2010
    Posts
    792
    Reviews
    Read 0 Reviews
    Downloads
    3
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by ikonk Click here to enlarge
    Ip client ane kasih 192.168.10.2-63/26 & 192.168.20.2-63/26 ..... mohon contoh routenya gan.... ane newbie soalnya
    gateway masing2 ISP : Speedy 1 > 192.168.10.1 & speedy 2 > 192.168.20.1

    mohon pencerahan gan
    waaduhh.. belom kelar juga ternyata....Click here to enlarge
    mungkin gini deh...
    1. coba si Om paste semua konfigurasi mikrotik nya di sini, silahkan paste hasil dari
    /ip addr pr
    /ip fi nat pr
    /ip fi fi pr
    /ip fi ma
    /ip route
    dengan maksud setelah di lihat semua konfigurasi mikrotik nya di sini, kalo emang ada yg kurang tepat dalam settingan mikrotiknya, mungkin suhu-suhu yg lain yg udah berpengalaman bisa ikut kasih pencerahan karna kadang dengan ketrangan yg kurang, sulit juga untuk melihat/menganalisa kesalahannya di mana...Click here to enlarge

    2.untuk rule routing antar dua segment ip lokal, kita harus nya tidak usah bikin manual lagi karna untuk routingan itu akan tercipta/tercreate secara otomatis di /ip route seketika, ketika kita membuat/setting ip address di /ip address, untuk meyakinkan, silahkan si Om lihat di /Ip route, harus nya ada rule yg kira2 seperti ini
    DAC 192.168.10.0/26 Etherxx reachable
    DAC 192.168.20.0/26 Etheryy reachable
    nah umum nya kedua routingan tersebut yg di gunakan untuk berkomunikasi antar client lokal...

    3. cek dulu client yg akan di gunakan sharing file nya, karna kadang OS sekarang seperti win 7 atau win 8 , untuk sharing agak sedikit ribet kayak nya terkait dengan firewall nya, si Om mungkin bisa setting untuk network conectionnya, terutama untuk settingan network discovery nya, atau juga kalo ada yg menggunakan antivirus dengan tambahan internet security (IS) biasanya di sertai dengan firewall sehingga kadang ke blok sama firewall tersebut
    kalo ada yg memakai win xp, sebaiknya ujicoba dulu antar client yg menggunakan kedua OS tersebut, karna kayak nya win xp lebih mudah dalam setting sharing file nya, paling kalo mentok, di win xp ada setting wizard nya di control panel nya "Network setting Wizard"

    4. sharing file client beda segment ip umumnya tidak akan muncul di "my network places"/ "network neigberhood" jadi mesti tembak ip taget langsung di address bar
    5. btw... fitur hotspot di aktifkan gk nih....:

    goodluck.....Click here to enlarge

  13. #13
    Status
    Offline
    ikonk's Avatar
    Newbie
    Join Date
    Mar 2014
    Posts
    20
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by brutuz_1 Click here to enlarge
    waaduhh.. belom kelar juga ternyata....Click here to enlarge
    mungkin gini deh...
    1. coba si Om paste semua konfigurasi mikrotik nya di sini, silahkan paste hasil dari
    /ip addr pr
    /ip fi nat pr
    /ip fi fi pr
    /ip fi ma
    /ip route
    dengan maksud setelah di lihat semua konfigurasi mikrotik nya di sini, kalo emang ada yg kurang tepat dalam settingan mikrotiknya, mungkin suhu-suhu yg lain yg udah berpengalaman bisa ikut kasih pencerahan karna kadang dengan ketrangan yg kurang, sulit juga untuk melihat/menganalisa kesalahannya di mana...Click here to enlarge

    2.untuk rule routing antar dua segment ip lokal, kita harus nya tidak usah bikin manual lagi karna untuk routingan itu akan tercipta/tercreate secara otomatis di /ip route seketika, ketika kita membuat/setting ip address di /ip address, untuk meyakinkan, silahkan si Om lihat di /Ip route, harus nya ada rule yg kira2 seperti ini
    DAC 192.168.10.0/26 Etherxx reachable
    DAC 192.168.20.0/26 Etheryy reachable
    nah umum nya kedua routingan tersebut yg di gunakan untuk berkomunikasi antar client lokal...

    3. cek dulu client yg akan di gunakan sharing file nya, karna kadang OS sekarang seperti win 7 atau win 8 , untuk sharing agak sedikit ribet kayak nya terkait dengan firewall nya, si Om mungkin bisa setting untuk network conectionnya, terutama untuk settingan network discovery nya, atau juga kalo ada yg menggunakan antivirus dengan tambahan internet security (IS) biasanya di sertai dengan firewall sehingga kadang ke blok sama firewall tersebut
    kalo ada yg memakai win xp, sebaiknya ujicoba dulu antar client yg menggunakan kedua OS tersebut, karna kayak nya win xp lebih mudah dalam setting sharing file nya, paling kalo mentok, di win xp ada setting wizard nya di control panel nya "Network setting Wizard"

    4. sharing file client beda segment ip umumnya tidak akan muncul di "my network places"/ "network neigberhood" jadi mesti tembak ip taget langsung di address bar
    5. btw... fitur hotspot di aktifkan gk nih....:

    goodluck.....Click here to enlarge
    Ini gan konfigurasi ane...
    /ip addr pr
    [admin@MikroTik] > ip addr pr
    Flags: X - disabled, I - invalid, D - dynamic
    # ADDRESS NETWORK INTERFACE
    0 192.168.10.1/26 192.168.10.0 ether3-Switch Lt.1
    1 192.168.20.1/26 192.168.20.0 ether4-Switch Lt.2
    2 192.168.1.10/30 192.168.1.8 ether1-Billion
    3 192.168.30.1/27 192.168.30.0 ether5-Lan
    4 192.168.2.10/30 192.168.2.8 ether2-ZTE
    5 D 36.70.69.191/32 36.70.64.1 pppoe-out1
    6 D 125.161.208.243/32 125.161.208.1 pppoe-out2


    ip fi nat pr
    Flags: X - disabled, I - invalid, D - dynamic
    0 ;;; NAT Speedy ( Masquerade)
    chain=srcnat action=masquerade src-address=192.168.10.0/26
    out-interface=pppoe-out1

    1 X ;;; Rule Redirect / Block keyword
    chain=dstnat action=redirect to-ports=8080 protocol=tcp dst-port=80

    2 ;;; NAT Speedy ZTE Modem
    chain=srcnat action=masquerade src-address=192.168.20.0/26
    out-interface=pppoe-out2

    3 X ;;; masquerade Switch1
    chain=srcnat action=masquerade to-addresses=192.168.20.0/26
    src-address-type="" out-interface=ether3-Switch Lt.1

    4 X ;;; Masquerade Switch2
    chain=srcnat action=masquerade out-interface=ether4-Switch Lt.2

    ip fi fi pr
    Flags: X - disabled, I - invalid, D - dynamic
    0 X ;;; Block keyword web
    chain=forward action=reject reject-with=icmp-admin-prohibited
    out-interface=ether1-Billion content=www.kaskus.co.id.*

    1 X ;;; drop ftp brute forcers
    chain=input action=drop protocol=tcp src-address-list=ftp_blacklist
    dst-port=21

    2 X chain=output action=accept protocol=tcp content=530 Login incorrect
    limit=1/1m,5 dst-limit=1/1m,5,dst-address/1m40s

    3 X chain=output action=add-dst-to-address-list protocol=tcp
    address-list=ftp_blacklist address-list-timeout=3h
    content=530 Login incorrect

    4 X ;;; drop ssh brute forcers
    chain=input action=drop protocol=tcp src-address-list=ssh_blacklist
    dst-port=22

    5 X chain=input action=add-src-to-address-list connection-state=new protocol=tc>
    src-address-list=ssh_stage3 address-list=ssh_blacklist
    address-list-timeout=1w3d dst-port=22

    6 X chain=input action=add-src-to-address-list connection-state=new protocol=tc>
    src-address-list=ssh_stage2 address-list=ssh_stage3
    address-list-timeout=1m dst-port=22

    7 X chain=input action=add-src-to-address-list connection-state=new protocol=tc>
    src-address-list=ssh_stage1 address-list=ssh_stage2
    address-list-timeout=1m dst-port=22

    8 X chain=input action=add-src-to-address-list connection-state=new protocol=tc>
    address-list=ssh_stage1 address-list-timeout=1m dst-port=22

    9 X ;;; drop ssh brute downstream
    chain=forward action=drop protocol=tcp src-address-list=ssh_blacklist
    dst-port=22

    10 X ;;; Block IP ssh yg masuk
    chain=input action=drop src-address=221.120.224.179

    11 X chain=input action=drop src-address=221.238.40.138

    12 X ;;; torrentsites
    chain=forward action=drop src-address=192.168.10.0/26
    layer7-protocol=torrentsites in-interface=ether3-Switch Lt.1

    13 X ;;; dropDNS
    chain=forward action=drop protocol=udp src-address=192.168.10.0/26
    layer7-protocol=torrentsites in-interface=ether3-Switch Lt.1 dst-port=53

    /ip fi ma
    /ip firewall mangle> pr
    Flags: X - disabled, I - invalid, D - dynamic
    0 chain=prerouting action=mark-routing new-routing-mark=GroupA passthrough=no
    src-address=192.168.10.0/26

    1 chain=prerouting action=mark-routing new-routing-mark=GroupB passthrough=no
    src-address=192.168.20.0/26

    2 X ;;; Switch Lt.1
    chain=forward action=accept src-address=192.168.10.0/26
    dst-address=192.168.20.0/26

    3 X ;;; Switch Lt.2
    chain=forward action=accept src-address=192.168.20.0/26
    dst-address=192.168.10.0/26

    4 X chain=forward action=accept in-interface=ether3-Switch Lt.1

    5 X chain=forward action=accept out-interface=ether4-Switch Lt.2

    6 X chain=forward action=accept in-interface=ether4-Switch Lt.2

    7 X chain=forward action=accept out-interface=ether3-Switch Lt.1


    /ip route
    /ip route> pr
    Flags: X - disabled, A - active, D - dynamic,
    C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme,
    B - blackhole, U - unreachable, P - prohibit
    # DST-ADDRESS PREF-SRC GATEWAY DISTANCE
    0 A S 0.0.0.0/0 pppoe-out1 1
    1 A S 0.0.0.0/0 pppoe-out2 1
    2 ADS 0.0.0.0/0 36.70.64.1 1
    3 DS 0.0.0.0/0 125.161.208.1 1
    4 X S 0.0.0.0/0 ether2-ZTE 1
    5 X S 0.0.0.0/0 ether1-Billion 1
    6 ADC 36.70.64.1/32 36.70.69.191 pppoe-out1 0
    7 ADC 125.161.208.1/32 125.161.208.243 pppoe-out2 0
    8 ADC 192.168.1.8/30 192.168.1.10 ether1-Billion 0
    9 ADC 192.168.2.8/30 192.168.2.10 ether2-ZTE 0
    10 ADC 192.168.10.0/26 192.168.10.1 ether3-Switch Lt.1 0
    11 ADC 192.168.20.0/26 192.168.20.1 ether4-Switch Lt.2 0
    12 ADC 192.168.30.0/27 192.168.30.1 ether5-Lan 0

    Fitur Hotspot ga aktif gan..

  14. #14
    Status
    Offline
    brutuz_1's Avatar
    VIP Member
    Join Date
    Feb 2010
    Posts
    792
    Reviews
    Read 0 Reviews
    Downloads
    3
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by ikonk Click here to enlarge
    Ini gan konfigurasi ane...
    /ip addr pr
    [admin@MikroTik] > ip addr pr
    Flags: X - disabled, I - invalid, D - dynamic
    # ADDRESS NETWORK INTERFACE
    0 192.168.10.1/26 192.168.10.0 ether3-Switch Lt.1
    1 192.168.20.1/26 192.168.20.0 ether4-Switch Lt.2
    2 192.168.1.10/30 192.168.1.8 ether1-Billion
    3 192.168.30.1/27 192.168.30.0 ether5-Lan
    4 192.168.2.10/30 192.168.2.8 ether2-ZTE
    5 D 36.70.69.191/32 36.70.64.1 pppoe-out1
    6 D 125.161.208.243/32 125.161.208.1 pppoe-out2


    ip fi nat pr
    Flags: X - disabled, I - invalid, D - dynamic
    0 ;;; NAT Speedy ( Masquerade)
    chain=srcnat action=masquerade src-address=192.168.10.0/26
    out-interface=pppoe-out1

    1 X ;;; Rule Redirect / Block keyword
    chain=dstnat action=redirect to-ports=8080 protocol=tcp dst-port=80

    2 ;;; NAT Speedy ZTE Modem
    chain=srcnat action=masquerade src-address=192.168.20.0/26
    out-interface=pppoe-out2

    3 X ;;; masquerade Switch1
    chain=srcnat action=masquerade to-addresses=192.168.20.0/26
    src-address-type="" out-interface=ether3-Switch Lt.1

    4 X ;;; Masquerade Switch2
    chain=srcnat action=masquerade out-interface=ether4-Switch Lt.2

    ip fi fi pr
    Flags: X - disabled, I - invalid, D - dynamic
    0 X ;;; Block keyword web
    chain=forward action=reject reject-with=icmp-admin-prohibited
    out-interface=ether1-Billion content=www.kaskus.co.id.*

    1 X ;;; drop ftp brute forcers
    chain=input action=drop protocol=tcp src-address-list=ftp_blacklist
    dst-port=21

    2 X chain=output action=accept protocol=tcp content=530 Login incorrect
    limit=1/1m,5 dst-limit=1/1m,5,dst-address/1m40s

    3 X chain=output action=add-dst-to-address-list protocol=tcp
    address-list=ftp_blacklist address-list-timeout=3h
    content=530 Login incorrect

    4 X ;;; drop ssh brute forcers
    chain=input action=drop protocol=tcp src-address-list=ssh_blacklist
    dst-port=22

    5 X chain=input action=add-src-to-address-list connection-state=new protocol=tc>
    src-address-list=ssh_stage3 address-list=ssh_blacklist
    address-list-timeout=1w3d dst-port=22

    6 X chain=input action=add-src-to-address-list connection-state=new protocol=tc>
    src-address-list=ssh_stage2 address-list=ssh_stage3
    address-list-timeout=1m dst-port=22

    7 X chain=input action=add-src-to-address-list connection-state=new protocol=tc>
    src-address-list=ssh_stage1 address-list=ssh_stage2
    address-list-timeout=1m dst-port=22

    8 X chain=input action=add-src-to-address-list connection-state=new protocol=tc>
    address-list=ssh_stage1 address-list-timeout=1m dst-port=22

    9 X ;;; drop ssh brute downstream
    chain=forward action=drop protocol=tcp src-address-list=ssh_blacklist
    dst-port=22

    10 X ;;; Block IP ssh yg masuk
    chain=input action=drop src-address=221.120.224.179

    11 X chain=input action=drop src-address=221.238.40.138

    12 X ;;; torrentsites
    chain=forward action=drop src-address=192.168.10.0/26
    layer7-protocol=torrentsites in-interface=ether3-Switch Lt.1

    13 X ;;; dropDNS
    chain=forward action=drop protocol=udp src-address=192.168.10.0/26
    layer7-protocol=torrentsites in-interface=ether3-Switch Lt.1 dst-port=53

    /ip fi ma
    /ip firewall mangle> pr
    Flags: X - disabled, I - invalid, D - dynamic
    0 chain=prerouting action=mark-routing new-routing-mark=GroupA passthrough=no
    src-address=192.168.10.0/26

    1 chain=prerouting action=mark-routing new-routing-mark=GroupB passthrough=no
    src-address=192.168.20.0/26

    2 X ;;; Switch Lt.1
    chain=forward action=accept src-address=192.168.10.0/26
    dst-address=192.168.20.0/26

    3 X ;;; Switch Lt.2
    chain=forward action=accept src-address=192.168.20.0/26
    dst-address=192.168.10.0/26

    4 X chain=forward action=accept in-interface=ether3-Switch Lt.1

    5 X chain=forward action=accept out-interface=ether4-Switch Lt.2

    6 X chain=forward action=accept in-interface=ether4-Switch Lt.2

    7 X chain=forward action=accept out-interface=ether3-Switch Lt.1


    /ip route
    /ip route> pr
    Flags: X - disabled, A - active, D - dynamic,
    C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme,
    B - blackhole, U - unreachable, P - prohibit
    # DST-ADDRESS PREF-SRC GATEWAY DISTANCE
    0 A S 0.0.0.0/0 pppoe-out1 1
    1 A S 0.0.0.0/0 pppoe-out2 1
    2 ADS 0.0.0.0/0 36.70.64.1 1
    3 DS 0.0.0.0/0 125.161.208.1 1
    4 X S 0.0.0.0/0 ether2-ZTE 1
    5 X S 0.0.0.0/0 ether1-Billion 1
    6 ADC 36.70.64.1/32 36.70.69.191 pppoe-out1 0
    7 ADC 125.161.208.1/32 125.161.208.243 pppoe-out2 0
    8 ADC 192.168.1.8/30 192.168.1.10 ether1-Billion 0
    9 ADC 192.168.2.8/30 192.168.2.10 ether2-ZTE 0
    10 ADC 192.168.10.0/26 192.168.10.1 ether3-Switch Lt.1 0
    11 ADC 192.168.20.0/26 192.168.20.1 ether4-Switch Lt.2 0
    12 ADC 192.168.30.0/27 192.168.30.1 ether5-Lan 0

    Fitur Hotspot ga aktif gan..
    nah keliatan ....
    coba saya kasih masukan dari /ip fi nat dlu
    coba tambahkan rule berikut ini
    Code:
    chain=srcnat out-interface=ether3-Switch Lt.1 action=masquerade
    chain=srcnat out-interface=ether4-Switch Lt.4 action=masquerade
    untk /ip fi ma, disitu ada rule routing mark, tapi saya gk lihat rule tersebut di gnakan di /ip route,
    coba untuk rle tersebut yaitu rle nmr 0 dan 1 di disable dlu, lalu coba lakukan file sharing antar client nya atau coba di ping antar client beda segmen ip nya..
    atau kalo memang rule routing mark tersebut diperlukan, coba tambahkan "selain" dst-address lokal nya
    Code:
     0   chain=prerouting action=mark-routing new-routing-mark=GroupA passthrough=no 
         src-address=192.168.10.0/26 dst-address=!192.168.20.0/26
     1   chain=prerouting action=mark-routing new-routing-mark=GroupB passthrough=no 
         src-address=192.168.20.0/26 dst-address=!192.168.10.0/26
    dengan begitu trafic tujuan lokal to lokal tidak masuk ke rule tersebut, krna walau bagaimanapun trafik lokal beda segmen ip akan melalui router dulu, dan akan otomatos terkena rule yg berada di router tersebut cmiww..
    goodluck...

  15. #15
    Status
    Offline
    ikonk's Avatar
    Newbie
    Join Date
    Mar 2014
    Posts
    20
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by brutuz_1 Click here to enlarge
    nah keliatan ....
    coba saya kasih masukan dari /ip fi nat dlu
    coba tambahkan rule berikut ini
    Code:
    chain=srcnat out-interface=ether3-Switch Lt.1 action=masquerade
    chain=srcnat out-interface=ether4-Switch Lt.4 action=masquerade
    untk /ip fi ma, disitu ada rule routing mark, tapi saya gk lihat rule tersebut di gnakan di /ip route,
    coba untuk rle tersebut yaitu rle nmr 0 dan 1 di disable dlu, lalu coba lakukan file sharing antar client nya atau coba di ping antar client beda segmen ip nya..
    atau kalo memang rule routing mark tersebut diperlukan, coba tambahkan "selain" dst-address lokal nya
    Code:
     0   chain=prerouting action=mark-routing new-routing-mark=GroupA passthrough=no 
         src-address=192.168.10.0/26 dst-address=!192.168.20.0/26
     1   chain=prerouting action=mark-routing new-routing-mark=GroupB passthrough=no 
         src-address=192.168.20.0/26 dst-address=!192.168.10.0/26
    dengan begitu trafic tujuan lokal to lokal tidak masuk ke rule tersebut, krna walau bagaimanapun trafik lokal beda segmen ip akan melalui router dulu, dan akan otomatos terkena rule yg berada di router tersebut cmiww..
    goodluck...
    terimakasih atas pencerahannya gan brutuz_1... sy sudah mencoba dan berhasil ping ke client beda segment, hanya saja ada 1 masalah lagi.. karena sy menggunakan 2 speedy jadi masing2 network 192.168.10.xxx dan 192.168.20.xxx itu menggunakan masing2 speedy juga. dan apabila rule mangle dibawah ini di disable,maka network yang 192.168.20.xx (yang menggunakan gateway 192.168.20.1 ) tidak bisa connect ke inet, apabila rule mangle di enable dan ditambahkan " selain ",tetap tdk bisa ping atau sharing beda segment gan...

    Code:
     0   chain=prerouting action=mark-routing new-routing-mark=GroupA passthrough=no 
         src-address=192.168.10.0/26 dst-address=!192.168.20.0/26
     1   chain=prerouting action=mark-routing new-routing-mark=GroupB passthrough=no 
         src-address=192.168.20.0/26 dst-address=!192.168.10.0/26
    kira2 rule apa lagi yang harus diterapkan?soalnya saya mengikuti membuat load balance 2 ISP dan 2 segment nework ( masing2 network menggunakan masing2 speedy), rule itu yg sy terapkan pada saat ini termasuk rule mangle tersebut hehehe( maklum masih nubi gan )Click here to enlarge Click here to enlarge
    - dan saya bingung kenapa kedua rule mangle tersebut di disable,hanya ppoe1 saja yang connect ke inet dan yang pppoe2 nya tidak bisa connect inet

    terimakasih atas pencerahannya
    Last edited by ikonk; 22-04-2014 at 11:20.

 

 
Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Replies: 9
    Last Post: 25-12-2013, 21:34
  2. 3 Line Speedy @1MB + 1 Line SmartFren LB jadi ngaco...
    By Yudh1stira in forum General Networking
    Replies: 0
    Last Post: 12-01-2012, 17:31
  3. file sharing 2 komputer beda gateway ke internet
    By viheri32 in forum Beginner Basics
    Replies: 0
    Last Post: 13-10-2010, 00:06
  4. Replies: 2
    Last Post: 30-05-2010, 07:18
  5. Cara sharing file tapi beda subnetmask
    By Anoordy in forum General Networking
    Replies: 12
    Last Post: 31-01-2008, 22:54

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •