Follow us on...
Follow us on G+ Follow us on Twitter Follow us on Facebook Watch us on YouTube
Register
Page 2 of 3 FirstFirst 123 LastLast
Results 16 to 30 of 40
  1. #16
    Status
    Offline
    nux
    nux's Avatar
    Member
    Join Date
    Jul 2007
    Posts
    268
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by kucingGarong Click here to enlarge
    ....kayanya mikrotik ga mungkin bisa deh selama gateway yg di proxy server itu IP si router mikrotik...
    bisa kok bro, saat ini aku masih pake konfigurasi tersebut, proxy server sebagai client mikrotik, jadi gateway yg ada di proxy server menggunakan ip mikrotik.
    coba cek konfigurasi squidnya (squid.conf):

    acl localnet src 192.168.0.0/255.255.255.224 #-->> network yg diijinkan mengakses squid

    Click here to enlarge Originally Posted by okto_2005 Click here to enlarge
    ...kl buat gitu bandwidthnya bocor ga bro????

    soalnya gue udah buat gitu, bandwidthnya narik ke proxy semua. di client ga kena shaping. udah gue coba pake pcq, simple queue sama aja bocor...
    karena request http dibelokkan ke proxy server semua, otomatis b/w kesedot proxy server, tp client udah kena shaping di mikrotik saat mengakses proxy server.
    aku pake queue tree, gak ada yg bocor tuh, semua client kena shaping...
    saran: utk proxy server jangan di shaping (mangle,limit), biarkan unlimited..

  2. #17
    Status
    Offline
    kucingGarong's Avatar
    Member
    Join Date
    Jul 2007
    Posts
    235
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by nux Click here to enlarge
    bisa kok bro, saat ini aku masih pake konfigurasi tersebut, proxy server sebagai client mikrotik, jadi gateway yg ada di proxy server menggunakan ip mikrotik.
    coba cek konfigurasi squidnya (squid.conf):

    acl localnet src 192.168.0.0/255.255.255.224 #-->> network yg diijinkan mengakses squid
    kalo gitu emg bisa bro, tapi sekarang yg jadi masalah tuh mo deny & allow per IP bukan per network gitu bro. udah di liat blom access log di proxy servernya...? yg kebaca ip dari client ato ip si router mikrotik...?

  3. #18
    Status
    Offline
    nux
    nux's Avatar
    Member
    Join Date
    Jul 2007
    Posts
    268
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    deny & allow per IP???, maksudnya hanya ip client tertentu yg dibelokin ke proxy??, ato bagaimana??, teranginnya yg jelas dong...

  4. #19
    Status
    Offline
    kucingGarong's Avatar
    Member
    Join Date
    Jul 2007
    Posts
    235
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by nux Click here to enlarge
    deny & allow per IP???, maksudnya hanya ip client tertentu yg dibelokin ke proxy??, ato bagaimana??, teranginnya yg jelas dong...
    lah emg kurang jelas yah dari tadi bro Click here to enlarge yg saya maksud per IP client yg di allow ato di deny di proxy servernya

  5. #20
    Status
    Offline
    d3v4's Avatar
    Forum Guru
    Join Date
    Jul 2007
    Location
    di alam baka
    Posts
    1,015
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    segini banyak yg replay..

    gw masih blom mudeng yg di maksud TS Click here to enlarge


    duh bebel amat ya otak gw Click here to enlarge
    kek mana sih yang mau nya ..? gambar nya gmn ? maap boss blom bisa bantu .. otak ga mudeng

    Click here to enlarge

  6. #21
    Status
    Offline
    okto_2005's Avatar
    Member Super Senior
    Join Date
    Jul 2007
    Posts
    655
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    menurut hasil analisa dari quote yg saya attach disini sih.... proxy bacanya kalo jalur dibuat sejajar dengan client sih proxynya bacanya alamat routernya(mikrotik), bukan di client:
    When packet is dst-natted (no matter - action=nat or action=redirect), dst address is changed. Information about translation of addresses (including original dst address) is kept in router's internal tables. Transparent web proxy working on router (when web requests get redirected to proxy port on router) can access this information from internal tables and get address of web server from them
    nah menurut quote lagi:
    Only correct way is to add transparent proxy on the router itself, and configure it so that your "real" proxy is parent-proxy. In this situation your "real" proxy does not have to be transparent any more, as proxy on router will be transparent and will forward proxy-style requests (according to standard; these requests include all necessary information about web server) to "real" proxy.
    hanya bisa dibuat transparant proxy kalo proxynya hanya ada di routernya itu.
    diluar router hanya sebagai parent-proxy.


    @nux
    gue udah pake pcq (queue tree) squid ga gue mangle.... sama aja bocor..... tologin dong rule mangle sama queue taruh sini Click here to enlarge


    @kucing
    kalo mao per ip sih tambahin aja bro kaya gini:

    acl client src 192.168.0.4 192.168.0.78 192.168.0.54
    acl admins src 192.168.0.2 192.168.0.77
    dst.
    Last edited by okto_2005; 01-11-2007 at 09:22.

  7. #22
    Status
    Offline
    nux
    nux's Avatar
    Member
    Join Date
    Jul 2007
    Posts
    268
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by okto_2005 Click here to enlarge
    ...gue udah pake pcq (queue tree) squid ga gue mangle.... sama aja bocor..... tologin dong rule mangle sama queue taruh sini Click here to enlarge...
    mangle yg aku pake:
    :for e from 2 to 29 do={
    /ip firewall mangle add chain=prerouting src-address=(192.168.0. . $e) action=mark-connection new-connection-mark=($e . nuxcon )
    /ip firewall mangle add chain=prerouting connection-mark=($e . nuxcon ) action=mark-packet new-packet-mark=($e . nuxflow ) passthrough=no
    }
    queue nya..:
    queue tree add name="DOWNLOAD" parent=Lokal
    queue tree add name="UPLOAD" parent=Publik
    :for e from 2 to 29 do={/queue tree add name=(Down_nux_ . $e) parent=DOWNLOAD packet-mark=($e . nuxflow)}
    :for e from 2 to 29 do={/queue tree add name=(Up_nux_ . $e) parent=UPLOAD packet-mark=($e . nuxflow)}
    jangan lupa bedakan ip & netmask client dengan proxy server (lihat gambar dibawah), dari pengalamanku jika client & proxy server satu netmask maka limiter tidak berfungsi dengan baik.

    Click here to enlarge

  8. The Following User Says Thank You to nux For This Useful Post:


  9. #23
    Status
    Offline
    zulhanif's Avatar
    Calon Member
    Join Date
    Aug 2007
    Location
    mBantoel, DIY
    Posts
    71
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Proxy tuh untuk apa to sebenarnya? Keknya cuman untuk ngeblok content adult aja deh... Click here to enlarge
    Ada yang bilang proxynya mikrotik jelek, bener apa ga ya?
    Pencerahan ditunggu......

  10. #24
    Status
    Offline
    nux
    nux's Avatar
    Member
    Join Date
    Jul 2007
    Posts
    268
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    nggak cuman buat ngeblok content (filtering) aja kok bro, proxy juga berguna untuk connection sharing dan web caching. connection sharing merupakan fungsi proxy server sebagai gateway ke internet, jadi semua komputer client yang berada di bawahnya akan dapat mengakses internet melalui gateway ini, sedangkan web caching berguna utk menyimpan content2 yg telah diakses oleh client, sebuah client tidak harus melakukan kontak dengan server untuk meminta layanan akan tetapi client dapat mendapatkan (data/content) layanan yang sudah tersimpan pada proxy server, dengan hal ini maka akses akan semakin cepat, disamping itu kita juga akan menghemat b/w karena content yg sama jika dibuka lagi akan mengambil dr cache proxy.

    mengenai proxy-nya mikrotik memang kurang bagus, disarankan menggunakan proxy server tersendiri, misal pake squid di linux.

  11. The Following 2 Users Say Thank You to nux For This Useful Post:


  12. #25
    Status
    Offline
    zulhanif's Avatar
    Calon Member
    Join Date
    Aug 2007
    Location
    mBantoel, DIY
    Posts
    71
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by nux Click here to enlarge
    nggak cuman buat ngeblok content (filtering) aja kok bro, proxy juga berguna untuk connection sharing dan web caching. connection sharing merupakan fungsi proxy server sebagai gateway ke internet, jadi semua komputer client yang berada di bawahnya akan dapat mengakses internet melalui gateway ini, sedangkan web caching berguna utk menyimpan content2 yg telah diakses oleh client, sebuah client tidak harus melakukan kontak dengan server untuk meminta layanan akan tetapi client dapat mendapatkan (data/content) layanan yang sudah tersimpan pada proxy server, dengan hal ini maka akses akan semakin cepat, disamping itu kita juga akan menghemat b/w karena content yg sama jika dibuka lagi akan mengambil dr cache proxy.

    mengenai proxy-nya mikrotik memang kurang bagus, disarankan menggunakan proxy server tersendiri, misal pake squid di linux.

    Uuuppssss.....makasih banyak bro... Click here to enlarge

  13. The Following User Says Thank You to zulhanif For This Useful Post:


  14. #26
    Status
    Offline
    okto_2005's Avatar
    Member Super Senior
    Join Date
    Jul 2007
    Posts
    655
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    sebagai bahan pembantu:





  15. #27
    Status
    Offline
    rudi86's Avatar
    Baru Gabung
    Join Date
    Aug 2007
    Location
    pekanbaru
    Posts
    9
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge weww....................

  16. #28
    Status
    Offline
    rj-45's Avatar
    Moderator
    Join Date
    Jul 2007
    Posts
    885
    Reviews
    Read 0 Reviews
    Downloads
    1
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by nux Click here to enlarge
    proxynya ada di lokal..., udah sering dibahas, tp mo sekedar sharing aja...
    ini contoh konfigurasi yg pernah aku pake:

    Click here to enlarge

    proxy server sejajar dengan client (lumayan buat ngirit switch & lancard Click here to enlarge)
    asumsi proxy & mikrotik udah diinstal & berjln dgn baik.
    ethernet Lokal dibikin dua ip:
    192.168.0.1/27 utk client
    192.168.1.1/29 utk proxy server

    bikin nat masq:
    ip firewall nat add chain=srcnat src-address=192.168.0.0/27 out-interface=Publik action=masquerade

    ip firewall nat add chain=srcnat src-address=192.168.1.0/29 out-interface=Publik action=masquerade

    buat daftar client yg mo dibelokin ke proxy:
    ip firewall address-list add list=belokinproxy address=192.168.0.0/27

    rule utk membelokkan ke port proxy (yg aku pake buat squid port 3128):
    ip firewall nat add chain=dstnat protocol=tcp dst-port=80 src-address-list=belokinproxy action=dst-nat to-addresses=192.168.1.2 to-ports=3128

    semoga membantu...
    ini gateway proxy sama gateway client jadi 192.168.0.1 yak bos?

  17. #29
    Status
    Offline
    nux
    nux's Avatar
    Member
    Join Date
    Jul 2007
    Posts
    268
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    gateway nya pake yg satu network!, contoh di sini ip proxy 192.168.1.2, jd gunakan gateway yg 192.168.1.1 utk gateway proxy.
    utk gateway client 192.168.0.1.

  18. #30
    Status
    Offline
    L0sTBoY's Avatar
    Newbie
    Join Date
    Sep 2007
    Posts
    43
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    kalau kayak gini gimana??

    internet -- mikrotik --- hub ---notebook
    |
    |
    |--- squid
    dalam dalam 1 ip local client ama squid nya
    apa bisa bocor kga bw yang di kasih ke squid??

    router 192.168.10.254
    client 192.168.10.128
    squid 192.168.10.10

    di dalam mikrotik ada 3 koneksi yang di balance

    terima kasih

 

 
Page 2 of 3 FirstFirst 123 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Transparent Traffic Shaper
    By [a] in forum QOS & Traffic Shaping
    Replies: 13
    Last Post: 06-07-2015, 16:35
  2. There is a loop in network for HTTP traffic.
    By seafer in forum General Networking
    Replies: 21
    Last Post: 13-10-2012, 18:04
  3. Replies: 3
    Last Post: 21-05-2010, 08:54
  4. Nge redirect traffic Yahoo Messenger gimana caranya...
    By kdebugx86 in forum General Networking
    Replies: 3
    Last Post: 11-05-2009, 22:34

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •