Mikrotik | Forum Mikrotik Indonesia   Mikrotik Manual Mikrotik iSPY Mikrotik RSS Feed
This Logo is a Courtesy from RumahDowty

Go Back   Mikrotik | Forum Mikrotik Indonesia > Diskusi Mikrotik RouterOS > General Networking
iSpy My iTrade Register FAQ Members List Calendar Mark Forums Read

Diskusi [ask]Gimana caranya memblok trafiic local pada General Networking | Mikrotik | Forum Mikrotik Indonesia : kk.., numpang tanya yah gimana seh caranya ngeblok/ ngebatasin semua trafic lokal. Pengennya seh biar ...


Official Board Announcements
NEW
Kunjungi Forum Diskusi PROXY Linux di FMI
donasi



 
Reply
 
LinkBack Thread Tools
  #1 (permalink)  
Old 13-07-2007, 12:08
gateway's Avatar
gateway gateway is offline
Newbie
 
Join Date: Jul 2007
Posts: 63
iTrader: (0)
Thanks: 10
Thanked 1 Time in 1 Post
gateway is on a distinguished road
[ask]Gimana caranya memblok trafiic local




kk..,

numpang tanya yah gimana seh caranya ngeblok/ ngebatasin semua trafic lokal.

Pengennya seh biar semua client yang ada dalam satu LAN nga bisa nge ping satu sama lain atau ngaliat satu sama lain.

makasi sebelumnya

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to gateway For This Useful Post:
  #2 (permalink)  
Old 13-07-2007, 13:42
c0nf's Avatar
c0nf c0nf is offline
Forum Guru
 
Join Date: Jul 2007
Location: Bdg, Id.
Posts: 1,079
iTrader: (0)
Thanks: 88
Thanked 107 Times in 87 Posts
c0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the rough
Send a message via Yahoo to c0nf Send a message via Skype™ to c0nf
dibedain aja ip per client nya
misalkan
client a = 192.168.1.2/30 gateway 192.168.1.1
client b = 192.168.1.6/30 gateway 192.168.1.5
client c = 192.168.1.10/30 gateway 192.168.1.9
dst

kayaknya kalo pengen langsung, susah. soalnya topologinya kan mikrotik -- switch -- client.

atau ada ide lain ?

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to c0nf For This Useful Post:
  #3 (permalink)  
Old 13-07-2007, 15:21
[a]'s Avatar
[a] [a] is offline
Forum Advisor
 
Join Date: Jun 2007
Location: Jakarta
Posts: 1,690
iTrader: (1)
Thanks: 311
Thanked 964 Times in 243 Posts
[a] has disabled reputation
Send a message via Yahoo to [a]
halloo bos gateway

RB 532nya gimana bossss.......heuhehehhe

kalo emang masih satu network...kita ga akan bisa nge-blok traffic antar sesama node didalam network tersebut....

klo emang kebutuhannya kaya gitu, coba ikutin saran dari bro cOnf...bikin subnet untuk tiap2 kategori user....nanti baru bisa pembatasan antar subnet tersebut dilakukan di mikrotik...

atau cara gua, yang emang ga mau ribet...gua pake IP yang berbeda-beda untuk tiap kategori user....

office : 10.10.x.x
guest : 192.168.1.x
outlet : 172.16.x.x

dan networknya secara fisik juga gua pisah...dan di mikrotiknya gua pakein interface ethernet sebanyak network tersebut + wan (menuju isp)....

klo dah kaya gini gua bisa control traffic antar network tersebut secara mudah.....


mudah-mudahan bisa sedikit membantu...

__________________
Follow me on twitter @alternatifer
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 13-07-2007, 21:32
okto_2005's Avatar
okto_2005 okto_2005 is offline
Member Super Senior
 
Join Date: Jul 2007
Posts: 642
iTrader: (0)
Thanks: 10
Thanked 470 Times in 129 Posts
okto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond reputeokto_2005 has a reputation beyond repute
Send a message via Yahoo to okto_2005 Send a message via Skype™ to okto_2005
??? MAKSUTNYA NGEPING SATU SAMA LAIN DALAM JARINGAN GIMANA YAHHHH

1 network gitu ato ada beberapa network terus di jadiin satu lewat mikrotik???

BTW ini udah salah jalur, harusnya di bagian general networking. pindahin om admin

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 13-07-2007, 21:54
[a]'s Avatar
[a] [a] is offline
Forum Advisor
 
Join Date: Jun 2007
Location: Jakarta
Posts: 1,690
iTrader: (1)
Thanks: 311
Thanked 964 Times in 243 Posts
[a] has disabled reputation
Send a message via Yahoo to [a]
siap bro....


thanks..

__________________
Follow me on twitter @alternatifer
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 14-07-2007, 10:25
symbal_pecah symbal_pecah is offline
Newbie
 
Join Date: Jul 2007
Posts: 64
iTrader: (0)
Thanks: 8
Thanked 4 Times in 4 Posts
symbal_pecah is on a distinguished road
Smile

Quote:
Originally Posted by c0nf View Post
dibedain aja ip per client nya
misalkan
client a = 192.168.1.2/30 gateway 192.168.1.1
client b = 192.168.1.6/30 gateway 192.168.1.5
client c = 192.168.1.10/30 gateway 192.168.1.9
dst

kayaknya kalo pengen langsung, susah. soalnya topologinya kan mikrotik -- switch -- client.

atau ada ide lain ?
kl misalnya cm satu network ( 192.168.1.0/24 ) trs yang mw diblok akses pingnya dan cm satu gateway saja yang boleh diping misalnya 192.168.1.1
coba aja rule ini :
/ip fi filter add chain=forward out-interface=ether1 dst-address=!192.168.1.1 protocol=icmp action=drop

mungkin sdh ada yg tau

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 14-07-2007, 12:33
[a]'s Avatar
[a] [a] is offline
Forum Advisor
 
Join Date: Jun 2007
Location: Jakarta
Posts: 1,690
iTrader: (1)
Thanks: 311
Thanked 964 Times in 243 Posts
[a] has disabled reputation
Send a message via Yahoo to [a]
gini bro..

klo ping yang mau diblok adalah :

host(yang nge-ping) -> switch -> mikrotik -> switch -> host(yang diping)

ini bisa dilakukan dengan rule diatas / rule yang nge-blok paket forward ICMP

tapi klo topologi kaya dibawah :

host(yang nge-ping) -> Switch -> Mikrotik
........................................^
........................................|
host(yang di-ping) -------

ini ga akan bisa dilakukan dengan firewall rule di Mikrotik,

hal ini mungkin bisa dicapai dengan mengganti switch yang ada dengan Manageable Switch...Cuma musti diliat cost-nya yang gede tuhh....

__________________
Follow me on twitter @alternatifer
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 14-07-2007, 13:31
c0nf's Avatar
c0nf c0nf is offline
Forum Guru
 
Join Date: Jul 2007
Location: Bdg, Id.
Posts: 1,079
iTrader: (0)
Thanks: 88
Thanked 107 Times in 87 Posts
c0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the rough
Send a message via Yahoo to c0nf Send a message via Skype™ to c0nf
yups
semuanya betul
hehehhehe
jadi sebenernya itu masalah di topologi jaringan mas gateway
tinggal dipilih mana yg paling cocok dalam kasus anda

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 14-07-2007, 18:21
ponywaterhouse ponywaterhouse is offline
Forum Guru
 
Join Date: Jul 2007
Posts: 1,489
iTrader: (0)
Thanks: 62
Thanked 165 Times in 132 Posts
ponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura about
klo kasusnya di rt/rw net gmn yah?
user yg satu ga boleh tau ada user lain...

klo dia pake IP scanner kan bisa tau IP mana aja yg reply..

nah klo gt gmn??

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 14-07-2007, 19:18
c0nf's Avatar
c0nf c0nf is offline
Forum Guru
 
Join Date: Jul 2007
Location: Bdg, Id.
Posts: 1,079
iTrader: (0)
Thanks: 88
Thanked 107 Times in 87 Posts
c0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the rough
Send a message via Yahoo to c0nf Send a message via Skype™ to c0nf
kalo di gw dibagi2 kayak gini :

client a = 192.168.1.2/30 gateway 192.168.1.1
client b = 192.168.1.6/30 gateway 192.168.1.5
client c = 192.168.1.10/30 gateway 192.168.1.9

netmasknya diitung sendiri ya (buat latihan heheheh)

cuman emang kerjaan lagi masuk2in ip gateway nya di mikrotik
untuk sementara sih masih aman2 aja dengan cara di atas.
kalo mau bener2 safe, ya harus beli switch mahal (manageble switch)
atau kalo ngga salah, dulu pernah liat lan card mikrotik yg banyak port rj45 nya.cuman ngga tau bener itu dari mikrotik atau bukan. soalnya blm pernah pegang yg "gituan" sih heheheh

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #11 (permalink)  
Old 14-07-2007, 19:23
ponywaterhouse ponywaterhouse is offline
Forum Guru
 
Join Date: Jul 2007
Posts: 1,489
iTrader: (0)
Thanks: 62
Thanked 165 Times in 132 Posts
ponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura about
waduh, klo klien nya sampe puluhan gmn tuh? hehe...

berarti satu2 nya cara emang di pisahin segmen nya yah?

gw ada tuh, lan card nya mikrotik 10/100 yg port.. terpaksa beli, soalnya kebutuhan NIC nya banyak.. hehe..

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #12 (permalink)  
Old 14-07-2007, 19:25
c0nf's Avatar
c0nf c0nf is offline
Forum Guru
 
Join Date: Jul 2007
Location: Bdg, Id.
Posts: 1,079
iTrader: (0)
Thanks: 88
Thanked 107 Times in 87 Posts
c0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the roughc0nf is a jewel in the rough
Send a message via Yahoo to c0nf Send a message via Skype™ to c0nf
kalo kliennya udah puluhan dan pake cara saya, berarti bentar lagi bro ponywaterhouse bakal menghilang dari forum ini. soalnya jarinya udah jadi segede jempol semuanya
heheheh
jangan marah ya bro
just kidding

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #13 (permalink)  
Old 14-07-2007, 19:32
ponywaterhouse ponywaterhouse is offline
Forum Guru
 
Join Date: Jul 2007
Posts: 1,489
iTrader: (0)
Thanks: 62
Thanked 165 Times in 132 Posts
ponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura aboutponywaterhouse has a spectacular aura about
hahaha...
jari gw kenapa bisa segede jempol yah??

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #14 (permalink)  
Old 15-07-2007, 00:32
[a]'s Avatar
[a] [a] is offline
Forum Advisor
 
Join Date: Jun 2007
Location: Jakarta
Posts: 1,690
iTrader: (1)
Thanks: 311
Thanked 964 Times in 243 Posts
[a] has disabled reputation
Send a message via Yahoo to [a]
emang subnet sih satu-satunya cara....atau ada yang pernah pake managable switch ??

__________________
Follow me on twitter @alternatifer
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #15 (permalink)  
Old 15-07-2007, 13:02
symbal_pecah symbal_pecah is offline
Newbie
 
Join Date: Jul 2007
Posts: 64
iTrader: (0)
Thanks: 8
Thanked 4 Times in 4 Posts
symbal_pecah is on a distinguished road
kl rule itu saya coba topologinya spt ini "

WAN ----- switch ----- mikroTik
|
|
PC client

switchnya unmanageable, jd item yang ada tanda seru negasi dr ip gateway.



Quote:
Originally Posted by [a] View Post
gini bro..

klo ping yang mau diblok adalah :

host(yang nge-ping) -> switch -> mikrotik -> switch -> host(yang diping)

ini bisa dilakukan dengan rule diatas / rule yang nge-blok paket forward ICMP

tapi klo topologi kaya dibawah :

host(yang nge-ping) -> Switch -> Mikrotik
........................................^
........................................|
host(yang di-ping) -------

ini ga akan bisa dilakukan dengan firewall rule di Mikrotik,

hal ini mungkin bisa dicapai dengan mengganti switch yang ada dengan Manageable Switch...Cuma musti diliat cost-nya yang gede tuhh....

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to symbal_pecah For This Useful Post:
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


This Forum is Powered by Orion Net.

All times are GMT +8. The time now is 09:04.