Mikrotik | Forum Mikrotik Indonesia   Mikrotik Manual Mikrotik iSPY Mikrotik RSS Feed
This Logo is a Courtesy from RumahDowty

Go Back   Mikrotik | Forum Mikrotik Indonesia > Diskusi Mikrotik RouterOS > General Networking
iSpy My iTrade Register FAQ Members List Calendar Mark Forums Read

Diskusi membuat hanya beberapa user aj yang bisa konek ke internet pada General Networking | Mikrotik | Forum Mikrotik Indonesia : kali ini gw ingin berbagi ilmu lagi. cara ini menggunakan subnetting ip begini ceritanya. misalkan ...


Official Board Announcements
NEW
Kunjungi Forum Diskusi PROXY Linux di FMI
donasi



 
Reply
 
LinkBack Thread Tools
  #1 (permalink)  
Old 29-01-2008, 21:17
ahmad.rifani's Avatar
ahmad.rifani ahmad.rifani is offline
Newbie
 
Join Date: Aug 2007
Posts: 27
iTrader: (0)
Thanks: 7
Thanked 24 Times in 7 Posts
ahmad.rifani is on a distinguished roadahmad.rifani is on a distinguished road
membuat hanya beberapa user aj yang bisa konek ke internet




kali ini gw ingin berbagi ilmu lagi.

cara ini menggunakan subnetting ip

begini ceritanya.

misalkan kita hanya ingin memberikan user 10.1.1.2-10.1.1.6 hanya bisa mengakses internet sedangkan ip selain itu tidak diberi akses internet.

gunakan winbox agar lebih gampang.
pada menu IP-->Firewall-->NAT

buat baris peintah ini.
add chain=src-nat src-address=10.1.1.0/29 out-interface=WAN action= masquerade

untuk out-interface namanya disesuaikan pada interface external pada masing -masing mikrotik router anda.

nah sekarang hanya ip yang diijinkan saja yang bisa mengakses internet, selain ip di atas tidak akan bisa akses internet. ok

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following 2 Users Say Thank You to ahmad.rifani For This Useful Post:
  #2 (permalink)  
Old 29-01-2008, 21:40
sy4ms_4's Avatar
sy4ms_4 sy4ms_4 is offline
Member Senior
 
Join Date: Jan 2008
Location: Bantul, Ngayogyokarto Hadiningrat
Posts: 468
iTrader: (0)
Thanks: 23
Thanked 63 Times in 48 Posts
sy4ms_4 is on a distinguished roadsy4ms_4 is on a distinguished roadsy4ms_4 is on a distinguished roadsy4ms_4 is on a distinguished road
Send a message via Yahoo to sy4ms_4
Quote:
kali ini gw ingin berbagi ilmu lagi.

cara ini menggunakan subnetting ip

begini ceritanya.

misalkan kita hanya ingin memberikan user 10.1.1.2-10.1.1.6 hanya bisa mengakses internet sedangkan ip selain itu tidak diberi akses internet.

gunakan winbox agar lebih gampang.
pada menu IP-->Firewall-->NAT

buat baris peintah ini.
add chain=src-nat src-address=10.1.1.0/29 out-interface=WAN action= masquerade

untuk out-interface namanya disesuaikan pada interface external pada masing -masing mikrotik router anda.

nah sekarang hanya ip yang diijinkan saja yang bisa mengakses internet, selain ip di atas tidak akan bisa akses internet. ok
Kalo 10.1.1.10??? Kalo bisa piye hayo?

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 30-01-2008, 01:20
rendyka rendyka is offline
Member
 
Join Date: Jul 2007
Posts: 130
iTrader: (0)
Thanks: 0
Thanked 2 Times in 2 Posts
rendyka is on a distinguished road
kalo misal cuman .2 , .4 , 10 , 12 , 20 gitu...gimana hayo ngeset IP nyaaa....

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 30-01-2008, 01:56
ponywaterhouse ponywaterhouse is offline
Forum Guru
 
Join Date: Jul 2007
Posts: 1,489
iTrader: (0)
Thanks: 62
Thanked 164 Times in 132 Posts
ponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura about
seperti yg pernah dibahas oleh bro okto_2005,

Code:
add chain=src-nat src-address=10.1.1.0/29 out-interface=WAN action= masquerade
diganti

Code:
chain=srcnat action=masquerade src-address-list=ournetwork
dimana ournetwork adalah address list yg udah kita daftarin di IP>firewall>adress yang bisa akses ke router...

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following 2 Users Say Thank You to ponywaterhouse For This Useful Post:
  #5 (permalink)  
Old 30-01-2008, 18:07
ahmad.rifani's Avatar
ahmad.rifani ahmad.rifani is offline
Newbie
 
Join Date: Aug 2007
Posts: 27
iTrader: (0)
Thanks: 7
Thanked 24 Times in 7 Posts
ahmad.rifani is on a distinguished roadahmad.rifani is on a distinguished road
Quote:
Originally Posted by sy4ms_4 View Post
Kalo 10.1.1.10??? Kalo bisa piye hayo?
udah ku coba bisa kok

ente udah coba lom, klo lom coba dulu to mas.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 31-01-2008, 17:02
safir safir is offline
Newbie
 
Join Date: Oct 2007
Posts: 52
iTrader: (0)
Thanks: 25
Thanked 2 Times in 2 Posts
safir is on a distinguished road


kalo jaringannya kaya gitu

ethernet 1 (yang ke internet)
sama
ethernet 2 (yang ke web server)

di bridge

tapi mau sebagian client cuma bisa akses ke web server sendiri ke yang lain (internet) engga bisa

gmana

client yang lainnya bebas koneksi ke internet

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 01-02-2008, 10:48
rendyka rendyka is offline
Member
 
Join Date: Jul 2007
Posts: 130
iTrader: (0)
Thanks: 0
Thanked 2 Times in 2 Posts
rendyka is on a distinguished road
Quote:
Originally Posted by ponywaterhouse View Post
seperti yg pernah dibahas oleh bro okto_2005,

Code:
add chain=src-nat src-address=10.1.1.0/29 out-interface=WAN action= masquerade
diganti

Code:
chain=srcnat action=masquerade src-address-list=ournetwork
dimana ournetwork adalah address list yg udah kita daftarin di IP>firewall>adress yang bisa akses ke router...
pintarrrrrr....

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 01-02-2008, 15:10
okto_2005's Avatar
okto_2005 okto_2005 is offline
Member Super Senior
 
Join Date: Jul 2007
Posts: 642
iTrader: (0)
Thanks: 10
Thanked 468 Times in 129 Posts
okto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond repute
Send a message via Yahoo to okto_2005 Send a message via Skype™ to okto_2005
@safir

pertama buat masquearade dulu ip yang boleh akses internet sesuai bro pony diatas, buat juga daftar kedua yang hanya boleh akses ke webserver:

add chain=src-nat src-address-list=allowinternet out-interface=WAN action= masquerade
add chain=src-nat src-address-list=allowlocal out-interface=web_server action= masquerade

bisa ga yah?? hahaha blum pernah coba.... praktekin aja deh soalnya gue pake router board mikrotik gue diatas belum bisa coba2 ginian.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to okto_2005 For This Useful Post:
  #9 (permalink)  
Old 01-02-2008, 20:57
sum14rdi's Avatar
sum14rdi sum14rdi is offline
VIP Member
 
Join Date: Sep 2007
Location: Tambun-Bekasi
Posts: 731
iTrader: (1)
Thanks: 115
Thanked 140 Times in 108 Posts
sum14rdi is on a distinguished roadsum14rdi is on a distinguished roadsum14rdi is on a distinguished roadsum14rdi is on a distinguished roadsum14rdi is on a distinguished roadsum14rdi is on a distinguished roadsum14rdi is on a distinguished road
Send a message via Yahoo to sum14rdi
Quote:
Originally Posted by okto_2005 View Post
@safir

pertama buat masquearade dulu ip yang boleh akses internet sesuai bro pony diatas, buat juga daftar kedua yang hanya boleh akses ke webserver:

add chain=src-nat src-address-list=allowinternet out-interface=WAN action= masquerade
add chain=src-nat src-address-list=allowlocal out-interface=web_server action= masquerade

bisa ga yah?? hahaha blum pernah coba.... praktekin aja deh soalnya gue pake router board mikrotik gue diatas belum bisa coba2 ginian.
bro....interface internet ama interface webserver khan di bridge...
emang bisa masquerade-nya dipisah gitu? (...bisa sich bisa tapi apa ada efeknya ke pembagian traficknya?.....)

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 02-02-2008, 11:00
okto_2005's Avatar
okto_2005 okto_2005 is offline
Member Super Senior
 
Join Date: Jul 2007
Posts: 642
iTrader: (0)
Thanks: 10
Thanked 468 Times in 129 Posts
okto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond repute
Send a message via Yahoo to okto_2005 Send a message via Skype™ to okto_2005
@sumiardi
wan sama web server harusnya jangan pake bridge tapi pake DMZ
http://www.mikrotik.com/testdocs/ros...mz_content.php

untuk trafficnya buat aja PCQ untuk ke WAN kena limit untuk yang ke DMZ (web server) di loss.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #11 (permalink)  
Old 06-02-2008, 10:00
safir safir is offline
Newbie
 
Join Date: Oct 2007
Posts: 52
iTrader: (0)
Thanks: 25
Thanked 2 Times in 2 Posts
safir is on a distinguished road
Quote:
Originally Posted by okto_2005 View Post
@sumiardi
wan sama web server harusnya jangan pake bridge tapi pake DMZ
http://www.mikrotik.com/testdocs/ros...mz_content.php

untuk trafficnya buat aja PCQ untuk ke WAN kena limit untuk yang ke DMZ (web server) di loss.
masalahnya ip webserver sama ip mikrotik satu segment

selain di bridge di DMZ
seting DMZ nya gmana?

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #12 (permalink)  
Old 14-06-2008, 00:53
vinandasanyoto vinandasanyoto is offline
Baru Gabung
 
Join Date: May 2008
Posts: 1
iTrader: (0)
Thanks: 0
Thanked 0 Times in 0 Posts
vinandasanyoto is on a distinguished road
Smile Mikrotik sbg Bandwidth Management Murni

Mas,

Bisa bantu sy untuk solusi sperti " Konfigurasi posisi router board Mikrotik sebagai Bandwidth Management murni bukan sebagai posisi gateway
mohon dibantu solusinya. Thx

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Gmn Cara Ngebatesin IP spy tidak konek internet ??? arovah General Networking 6 04-04-2008 19:05
Klient mikrotik ga bisa konek ke internet bangbross Beginner Basics 17 04-02-2008 04:36
Block Akses Internet user vxd_1986 General Networking 3 02-01-2008 18:08
[Help] Mikrotik gak bisa konek speedy... Dr.Geyonk General Networking 4 24-12-2007 19:06
(tanya) mikrotik ga mau konek internet paktujul General Networking 12 21-11-2007 18:53


This Forum is Powered by Orion Net.

All times are GMT +8. The time now is 05:46.