Anda di halaman 1dari 2

TUTORIAL MIKROTIK

1. MerubahIdentitasMikrotik
- system identity set name=madefunday
2. MerubahNama Interfaces
- interfaces set 0 name=internet
- interfaces set 1 name=lan1
- interfaces set 2 name=lan2
- interfaces set 3 name=lan3
- interfaces set 4 name=lan4
3. Memberi IP Address padamasing-masing Interfaces
- ip address add address=192.168.1.25/24 interfaces=internet comment=IP-Address-
untuk-interface-internet
- ip address add address=192.168.10.1/30 interfaces=lan1 comment=IP-Address-
untuk-interface-lan1
- ip address add address=192.168.20.1/29 interfaces=lan2 comment=IP-Address-
untuk-interface-lan2
- ip address add address=192.168.30.1/28 interfaces=lan3 comment=IP-Address-
untuk-interface-lan3
- ip address add address=192.168.40.1/27 interfaces=lan4 comment=IP-Address-
untuk-interface-lan4
4. Menambahkan Gateway Internet
- Ip route add gateway=192.168.1.1
5. Menambahkan DNS
- Ipdns set servers=192.168.1.1,8.8.8.8,8.8.4.4
6. Mengaktifkan NAT padamasing-masing Interfaces
- Ip firewall nat add chain=srcnat action=masquerade out-interfaces=internet src-
address=192.168.10.0/30 comment=NAT-untuk-lan1
- Ip firewall nat add chain=srcnat action=masquerade out-interfaces=internet src-
address=192.168.20.0/29 comment=NAT-untuk-lan2
- Ip firewall nat add chain=srcnat action=masquerade out-interfaces=internet src-
address=192.168.30.0/28 comment=NAT-untuk-lan3
- Ip firewall nat add chain=srcnat action=masquerade out-interfaces=internet src-
address=192.168.40.0/27 comment=NAT-untuk-lan4
7. Mengaktifkan DHCP padamasing-masing Interfaces
- Ipdhcp-server setup
Dhcp server interface:lan1
Dhcp address space: 192.168.10.0/30
Gateway for dhcp network: 192.168.10.1
Addresses to give out: 192.168.10.2
Dns servers: 192.168.1.1,8.8.8.8,8.8.4.4
Lease time: 10m
(DHCP Untuk lan1)
8. Mengaktifkan proxy
- Ip proxy set enable=yes port=3128 cache-
administrator=madefunday@sekolah.sch.id
9. Transparan proxy
- Ip firewall nat add chain=dstnat protocol=tcp dst-port=80 actions=redirect to-
ports=3128 src-address=192.168.10.0/30 in-interface=lan comment=transparent-
untuk-lan1
-
10. Block situs
- Ip proxy access add dst-host=*.linux.or.id action=deny
11. Block kata/extensi file
- Ip proxy access add path=*porno action=deny
- Ip proxy access add path=*.mp3 acction=deny
12. Setting clock
- Pakai GUI aja bro

13. Block internet (koneksi off)pada jam tertentu


- Block (pakeguikalomauenak :p )
 Ip firewall filter add chain=forward src-address=192.168.10.0/30 time=07:00-
14:00,sun,sat,wed action=drop
- Allow (pakeguikalomaugampang :p )
 Ip firewall filter add chain=forward src-address=192.168.10.0/30 time=14:00-
23:00,sun,sat,wed action=accept

14. Block situs https pada jam tertentu


- Ip firewall layer7-protocol add name=blockfb regexp=facebook.com
- Ip firewall filter add chain=forward src-address=192.168.10.0/30 layer7-
protocol=blockfb time=07:00-15:00,sun,sat,wed action=drop
15. Mengaktifkan interface wifi
- Interface wireless set 0 mode=ap-bridge ssid=johanapip@proxy disabled=no

17. Block ip dari 192.168.100.2-192.168.100.50


- ip firewall filter add chain=input src-address=192.168.100.2-192.168.100.50 dst-
address=192.168.100.1 action=drop protocol=icmp

18. buat rule filter mengijinkan permintaan http, https


- ip firewall filter add chain=forward protocol=tcp dst-port=80,443 in-interface=lan
out-interface=internet action=drop

19. STATIC dns


- ip proxy access add dst-host=www.mikrotik.com dst-port=80 action=deny redirect-
to=www.bsnp-indonesia.org

20. NTP

-system clock set time-zone-name=asia/jakarta time=08:00:00 date=feb/08/2019

Anda mungkin juga menyukai