Follow us on...
Follow us on G+ Follow us on Twitter Follow us on Facebook Watch us on YouTube
Register
Page 2 of 5 FirstFirst 1234 ... LastLast
Results 16 to 30 of 67
  1. #16
    Status
    Offline
    [a]
    [a]'s Avatar
    Administrator
    Join Date
    Jun 2007
    Location
    Jakarta, Indonesia, Indonesia
    Posts
    1,729
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    1 (100%)
    Click here to enlarge Originally Posted by chiepot Click here to enlarge
    kl pake DHCP gimana cara blok nya???
    Thanks...Click here to enlarge
    pake mac-addressnya bro...

  2. #17
    Status
    Offline
    nux
    nux's Avatar
    Member
    Join Date
    Jul 2007
    Posts
    268
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    Click here to enlarge Originally Posted by [a] Click here to enlarge
    pake mac-addressnya bro...
    pake arp bro?, kalo dhcp kan setiap konek ip addressnya selalu berubah, gimana ngeset pc tersebut selalu dapet ip address yg sama?
    ato ip addressnya yg digunakan pake mac address?, berarti harus masukin satu2 semua mac address yg ada?
    mohon pencerahan..

  3. #18
    Status
    Offline
    ace
    ace's Avatar
    Newbie
    Join Date
    Aug 2007
    Posts
    46
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    coba kalo gini bro..

    di daftarkan dulu IP mana aja yg boleh di pake

    contoh:
    / ip firewall address-list
    add list="allow list" address=192.168.10.20 comment="" disabled=no
    add list="allow list" address=192.168.10.30 comment="" disabled=no


    trus di blok dari filter rulenya
    kecuali "allow list" actionnya di drop
    / ip firewall filter
    add chain=forward in-interface=LAN protocol=tcp dst-address-list="!allow list" \
    action=drop comment="blok IP" disabled=no
    add chain=input in-interface=LAN protocol=tcp dst-address-list="!allow list" \
    action=drop comment="" disabled=no

    gw udah coba sih bisa...
    muda2an si bro bisa juga
    kalo engga bisa mohon maaf, soale masi nubi
    Click here to enlarge

  4. #19
    Status
    Offline
    [a]
    [a]'s Avatar
    Administrator
    Join Date
    Jun 2007
    Location
    Jakarta, Indonesia, Indonesia
    Posts
    1,729
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    1 (100%)
    Click here to enlarge Originally Posted by nux Click here to enlarge
    pake arp bro?, kalo dhcp kan setiap konek ip addressnya selalu berubah, gimana ngeset pc tersebut selalu dapet ip address yg sama?
    ato ip addressnya yg digunakan pake mac address?, berarti harus masukin satu2 semua mac address yg ada?
    mohon pencerahan..
    ada beberapa langkah bro menurut gua...

    - ARP di set=reply-only, jadi klo ada client gonta ganti IP secara manual ga akan bisa...

    - Bikin entry ARP static yang berisikan Mac Addr PC A, dengan IP yang diassign untuk PC A, jadi klo PC A ganti IP, ga akan bisa connect (ping aja ga bisa)

    - di DHCP Server, set :

    1. Address Pool, gunakan Static Only
    2. di Leases, bikin rule yang akan memberi IP Static ke PC A, masukkan juga Mac Address PC A disitu. Secara otomatis, rule tersebut akan menjadi Static.

    Coba kaya gitu dulu deh yahh....

    Klo ada yg salah2 mohon dimaafkan, namanya juga masih belajar...

    Mudah2an berhasil.....Click here to enlarge

  5. The Following 2 Users Say Thank You to [a] For This Useful Post:


  6. #20
    Status
    Offline
    unique_leader's Avatar
    Member Super Senior
    Join Date
    Jul 2007
    Posts
    639
    Reviews
    Read 0 Reviews
    Downloads
    5
    Uploads
    0
    Feedback Score
    1 (100%)
    Click here to enlarge Originally Posted by locantop Click here to enlarge
    coba gini
    ip firewall filter>add chain=forward src-address=192.168.x.x action=accept

    (sampai ip yang mau u kasih akses )
    trus di bawah nya

    ip firewall filter add chain=forward action=drop

    nah jadi selain ip yang u masukin ga bakalan bisa konek ke mikrotik/internet
    aku ngikutin cara di atas untuk blok IP tp saat aku masukin

    ip firewall filter add chain=forward action=drop
    malah user/client ga jalan napa ya

  7. #21
    Status
    Offline
    servas's Avatar
    Newbie
    Join Date
    Aug 2007
    Posts
    22
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0

    ask

    Guys di log ku ada tulisan gini :

    sep/01/2007 16:24:01 system,error,critical login failure for user user3 from 83.16.108.102 via ssh
    sep/01/2007 16:24:10 system,error,critical login failure for user ventas from 83.16.108.102 via ssh
    sep/01/2007 16:24:19 system,error,critical login failure for user james from 83.16.108.102 via ssh
    sep/01/2007 16:24:28 system,error,critical login failure for user greg from 83.16.108.102 via ssh
    sep/01/2007 16:24:37 system,error,critical login failure for user areyes from 83.16.108.102 via ssh
    sep/01/2007 16:24:46 system,error,critical login failure for user geoff from 83.16.108.102 via ssh
    sep/01/2007 16:24:55 system,error,critical login failure for user online from 83.16.108.102 via ssh
    sep/01/2007 16:25:04 system,error,critical login failure for user mark from 83.16.108.102 via ssh

    ada someone yang cobain mtku dr luar. untuk ngeblok ipnya gimana ya ? ngeblock biar pingpun ngga bisa.

    mohon pencerahan,

    Rgds,

    Servas

  8. #22
    Status
    Offline
    [a]
    [a]'s Avatar
    Administrator
    Join Date
    Jun 2007
    Location
    Jakarta, Indonesia, Indonesia
    Posts
    1,729
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    1 (100%)
    untuk ngeblok ssh dan akses winbox dari luar bisa diliat dithread2 sebelumnya bro...

    untuk blok ping, bikin rule di firewall, dengan settingan

    chain : input
    protocol : icmp
    in-interface : [wan] (interface yg terhubung ke internet)
    action : drop

    begitu yahh...semoga bisa sedikit membantu Click here to enlarge

  9. #23
    Status
    Offline
    robin's Avatar
    Baru Gabung
    Join Date
    Sep 2007
    Posts
    3
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    ini juga script bikinan temen saya Click here to enlarge

    supaya ip lokal tidak bisa internet

    BLOCKING IP

    Setting dengan WinBox

    New Terminal >

    SCRIPT 1
    # Start of Script1
    /ip firewall filter add chain=forward src-address=192.168.1.0/24 action=jump jump-target=BlockingIP comment="BlockingIP 192.168.1.x"
    # End of Script1

    SCRIPT 2
    # Start of Script2
    :for e from 1 to 254 do={
    /ip firewall filter add chain=BlockingIP src-address=(192.168.1 . . $e) action=reject \ comment=($e)
    }
    /ip firewall filter add chain=BlockingIP action=return comment="Return the packet"
    # End of Script2

    1. a. Menu ip > firewall > filter rules
    b. liat bagian chain Forward
    c. Cari rule dengan comment "BlockingIP 192.168.1.x"
    d. Drag Drop Rule itu ke paling atas
    2. a. Menu ip > firewall > filter rules
    b. liat bagian chain BlockingIP
    c. ada comment 1-254
    d. tinggal disable atau enable aja...
    - disable berarti gak di block
    - enable berarti di block
    e. Rule yang paling bawah.. dengan Comment "Return the packet"
    HARUS SELALU ENABLE
    Last edited by robin; 12-09-2007 at 10:48. Reason: ada yang kelupaan :P

  10. The Following User Says Thank You to robin For This Useful Post:


  11. #24
    Status
    Offline
    [a]
    [a]'s Avatar
    Administrator
    Join Date
    Jun 2007
    Location
    Jakarta, Indonesia, Indonesia
    Posts
    1,729
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    1 (100%)
    Click here to enlarge Originally Posted by robin Click here to enlarge
    ini juga script bikinan temen saya Click here to enlarge

    BLOCKING IP

    Setting dengan WinBox

    New Terminal >
    /ip firewall filter add chain=forward src-address=192.168.1.0/24
    action=jump jump-target=BlockingIP comment="BlockingIP 192.168.1.x"

    1. a. Menu ip > firewall > filter rules
    b. liat bagian chain Forward
    c. Cari rule dengan comment "BlockingIP 192.168.1.x"
    d. Drag Drop Rule itu ke paling atas
    2. a. Menu ip > firewall > filter rules
    b. liat bagian chain BlockingIP
    c. ada comment 1-254
    d. tinggal disable atau enable aja...
    - disable berarti gak di block
    - enable berarti di block
    e. Rule yang paling bawah.. dengan Comment "Return the packet"
    HARUS SELALU ENABLE
    klo rule diatas ini kegunaannya adalah untuk nge-blok ip dari network kita sendiri...

    dan rule2 diatas dah dibikinin duluan sama temennya si bro robin...jadi tinggal pake doang....hayuh bro robin...kita belajar config sendiri sama-sama...Click here to enlarge

  12. #25
    Status
    Offline
    okto_2005's Avatar
    Member Super Senior
    Join Date
    Jul 2007
    Posts
    655
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    blok ssh keknya udah pernah dibahas deh coba cari lagi.....

  13. #26
    Status
    Offline
    c0nf's Avatar
    Contributor
    Join Date
    Jul 2007
    Location
    Bandung, Indonesia
    Posts
    1,816
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    udah ada koq di thread yang mana gitu (saking banyaknya thread jadinya bingung sendiri nyarinya)...

  14. #27
    Status
    Offline
    oxs_juragan's Avatar
    Baru Gabung
    Join Date
    Nov 2007
    Posts
    8
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    to admin, tolong dong fasilitas upload gambarnya di aktifin biar enak nich...tnks

    Untuk block ip sudah agak ngerti siich, tapi kalo mau di gabung dgn mac addres masih agak bingung, tolong pencerahanya.!!!
    untuk gambar.a router board hanya berfungsi sebagai radio, karena takut kl di fungsikan sebagai router penuh bisa hank ( betul gk yach ??? ) makanya di beri pc router lagi.

    ni link gambarnya Click here to enlarge

    di situ ada gambar.a dan gambar.b, tolong koreksinya yg benar gambar.a atau gambar.b atau mungkin ada masukkan dari temen2.

    yg saya inginkan seperti ini.

    ada 3 sektoral, di mana sektoral 1,2,3
    untuk koneksi klient A = 192.168.0.1 -192.168.0.20
    dgn pengecekan ip dan mac addresnya harus sesuai.
    misal : ip 192.168.0.1 dgn mac af:23:hg:89 kalo ip di ganti gk bisa konek.
    yg lain di blok, aksesnya ke wifi/ ip 202.168.100.1

    untuk koneksi klient B = 192.168.10.1-192.168.10.20
    dgn pengecekan ip dan mac addresnya harus sesuai.
    akses tujuan ke ADSL/SPEDY ip 10.40.81.1

    klient A di beri bandwith 64 kbps utk di pake 20klient, kalo misal klient yg
    aktif hanya 2klient maka bandwith 64 kbps otomatis bisa di nikmati dua klient
    sehingga akses menjadi cepat.


    mungkin segitu dulu....mohon bantuan temen2 semua.tnks
    mohon maaf kalo terlalu panjang.
    oxs_juragan@yahoo.com

  15. #28
    Status
    Offline
    d3v4's Avatar
    Forum Guru
    Join Date
    Jul 2007
    Location
    di alam baka
    Posts
    1,015
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    super ribet ngejlimet Click here to enlargeClick here to enlarge

  16. #29
    Status
    Offline
    oxs_juragan's Avatar
    Baru Gabung
    Join Date
    Nov 2007
    Posts
    8
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    kasih solusinya dung...biar simple tapi tetep dapet intinya...

    maklum masih newbie, baru kemaren belajar nicch

    Click here to enlarge

  17. #30
    Status
    Offline
    oxs_juragan's Avatar
    Baru Gabung
    Join Date
    Nov 2007
    Posts
    8
    Reviews
    Read 0 Reviews
    Downloads
    0
    Uploads
    0
    Feedback Score
    0
    @d3v4
    ajarin duung bos, bagi ym nya yach biar bisa mojok berdua....bagi2 ilmu buat indonesia biar makin maju IT nya.

    maklum d kampung gk da teman berkeluh kesah nich.
    p lease help me my brother
    Click here to enlarge

 

 
Page 2 of 5 FirstFirst 1234 ... LastLast

Thread Information

Users Browsing this Thread

There are currently 2 users browsing this thread. (1 members and 1 guests)

  1. boemar_cs

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •