Rabu, 04 Januari 2012

Firewall untuk yg suka gaya "adem-ayem" ....


Ketika sebuah pilihan di tentukan .... semuanya pasti ada sisi baik dan buruk-nya .... tanpa kecuali .....
seperti nencuplik slogan begawan Abiyoso .... "sigma X = 0" ..... artinya : ibarat bandul ... ketika berusaha di ayun ke arah kanan sejauh 1mtr maka ideal-nya si bandul tadi akan mengayun sejauh 1 mtr pula ke arah sebaliknya (kiri) .... ketika anda tidak berkenan akan ayunan ke arah kiri tsb ... maka anda  akan membutuhkan gaya sebesar gaya si bandul mengayun ke arah kiri ... artinya "pak-pok" kan ....
itulah hukum alami yg berlangsung di dunia ini .... jadi ... sebenarnya semua itu hanya pilihan pilihan ....
disini kita coba ajukan konsep fi yg sederhana ringan dan gak neko2 ....
anggap saja "multymeter" murahan : biar gak terlalu berharap macem2 .....


ini adalah hasil copas entah sampek lupa dmn kemarin dulu .... maklum paidjo gak mangan sekolahan jadi iso-ne copas dan edit .... heheheheh podo ya ambek sampian kabeh ..... xixiixixi

langsung aja kita copas ya .... siiiiimmm salabimm jadi apa sekarang ..!!!!
catatan : -FO = 192.168.4.250           (publik)
             h-spot = 192.168.10.254     (lokal-1)
             w-net = 192.168.20.254      (lokal-2)
             x-link = 192.168.200.254     (lokal-3) 
            
/ip firewall mangle
add action=mark-packet chain=output comment="HIT TRAFFIC  DARI PROXY" \
    disabled=no dscp=4 new-packet-mark=hotspot-proxy-hit out-interface=h-spot \
    passthrough=no
add action=mark-packet chain=output comment="" disabled=no dscp=4 \
    new-packet-mark=warnet-proxy-hit out-interface=w-net passthrough=no
add action=mark-packet chain=output comment="" disabled=no dscp=4 \
    new-packet-mark=xlink-proxy-hit out-interface=x-link passthrough=no
add action=mark-packet chain=prerouting comment="UP TRAFFIC" disabled=no \
    in-interface=h-spot new-packet-mark=hotspot-test-up passthrough=no \
    src-address=192.168.10.0/24
add action=mark-packet chain=prerouting comment="" disabled=no \
    in-interface=w-net new-packet-mark=warnet-test-up passthrough=no \
    src-address=192.168.20.0/24
add action=mark-packet chain=prerouting comment="" disabled=no \
    in-interface=x-link new-packet-mark=xlink-test-up passthrough=no \
    src-address=192.168.200.0/24
add action=mark-connection chain=forward comment="CONN-MARK" disabled=no \
    new-connection-mark=hotspot-test-conn passthrough=yes \
    src-address=192.168.10.0/24
add action=mark-connection chain=forward comment="" disabled=no \
    new-connection-mark=warnet-test-conn passthrough=yes \
    src-address=192.168.20.0/24
add action=mark-connection chain=forward comment="" disabled=no \
    new-connection-mark=xlink-test-conn passthrough=yes \
    src-address=192.168.200.0/24
add action=mark-packet chain=forward comment="DOWNLOAD LASNGSUNG" \
    connection-mark=hotspot-test-conn disabled=no in-interface=-FO \
    new-packet-mark=hotspot-test-down passthrough=no
add action=mark-packet chain=forward comment="" \
    connection-mark=warnet-test-conn disabled=no in-interface=-FO \
    new-packet-mark=warnet-test-down passthrough=no
add action=mark-packet chain=forward comment="" \
    connection-mark=xlink-test-conn disabled=no in-interface=-FO \
    new-packet-mark=xlink-test-down passthrough=no
add action=mark-packet chain=output comment="DOWNLOAD VIA PROXY" disabled=no \
    dst-address=192.168.10.0/24 new-packet-mark=hotspot-test-down \
    out-interface=h-spot passthrough=no
add action=mark-packet chain=output comment="" disabled=no \
    dst-address=192.168.20.0/24 new-packet-mark=warnet-test-down \
    out-interface=w-net passthrough=no
add action=mark-packet chain=output comment="" disabled=no \
    dst-address=192.168.200.0/24 new-packet-mark=xlink-test-down \
    out-interface=x-link passthrough=no

/ip firewall address-list
add address=192.168.10.0/24 comment="LAN" disabled=no list=LAN
add address=192.168.20.0/24 comment="LAN" disabled=no list=LAN
add address=192.168.200.0/24 comment="LAN" disabled=no list=LAN


/queue tree
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no \
    limit-at=32000000 max-limit=32000000 name="hotspot downstream" \
    packet-mark=hotspot-test-down parent=h-spot priority=8 queue=default
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no \
    limit-at=32000000 max-limit=32000000 name="warnet downstream" \
    packet-mark=warnet-test-down parent=w-net priority=8 queue=default
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no \
    limit-at=32000000 max-limit=32000000 name="x-link downstream" \
    packet-mark=xlink-test-down parent=x-link priority=8 queue=default
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no \
    limit-at=32000000 max-limit=32000000 name="hotspot upstream" \
    packet-mark=hotspot-test-up parent=h-spot priority=8 queue=default
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no \
    limit-at=32000000 max-limit=32000000 name="warnet upstream" \
    packet-mark=warnet-test-up parent=w-net priority=8 queue=default
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no \
    limit-at=32000000 max-limit=32000000 name="x-link upstream" \
    packet-mark=xlink-test-up parent=x-link priority=8 queue=default
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no \
    limit-at=32000000 max-limit=32000000 name="hotspot hit" \
    packet-mark=hotspot-proxy-hit parent=h-spot priority=8 queue=default
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no \
    limit-at=32000000 max-limit=32000000 name="warnet hit" \
    packet-mark=warnet-proxy-hit parent=w-net priority=8 queue=default
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no \
    limit-at=32000000 max-limit=32000000 name="x-link hit" \
    packet-mark=xlink-proxy-hit parent=x-link priority=8 queue=default

ntuuuuhhh .... mudah2-an bermanfaat bagi teman2 semua yg suka adem ayem ...

1 komentar: