Documentos de Académico
Documentos de Profesional
Documentos de Cultura
Mikrotik
One engineer:
Mikrotik Certified Consultant (2005)
http://www.mikrotik.com/consultants.html
01-2
Head Office
Rep. Office
01-3
01-4
25-Mar-10
01-5
25-Mar-10
Pemilihan Routerboard
Kinerja Processor
Memori (RAM)
Jumlah interface
Level Lisensi
01-6
Ethernet
MiniPCI
Level 3 wireless client / PTP
Level 4 wireless access point
Custom Frequency ?
25-Mar-10
01-7
Jenis
Processor
RAM
Ether
RB800
MiniPCI USB
Radio
Lisensi
MPC8544 800MHz
256MB
3 (gig)
RB600
PPC266/400
128MB
3 (gig)
RB433UAH
AR7161 800MHz
128MB
RB433AH
AR7161 800MHz
128MB
RB433
64MB
RB411AH
AR7161 800MHz
64MB
RB411AR
64MB
RB411U
32MB
RB411R
32MB
RB411
32MB
25-Mar-10
01-8
Jenis
Processor
RB1000
PPC 1333MHz
RB493AH
RAM
Ethernet
MiniPCI
Lisensi
512MB 4 (gigabit)
Atheros AR7161
680 MHz/800MHz
64MB
RB493
Atheros AR7130
300 MHz
64MB
RB450G
Atheros AR7161
680 MHz/800MHz
256MB 5 (gigabit)
RB450
Atheros AR7130
300 MHz
32MB
RB750
Atheros AR7240
400MHz
32MB
RB750G
Atheros AR7161
680 MHz/800MHz
32MB
5 (gigabit)
25-Mar-10
Discontinued Hardware
01-9
RB230
RB112
RB133
RB333
RB532
RB150
RB192
RB153
25-Mar-10
RB1000
4 gigabit ethernet
0 minipci
1333 MHz processor
RAM: 512MB
up to:
01-10
3 Gbps
340.000 pps
25-Mar-10
RB800
01-11
3 gigabit ethernet
4 minipci slot
1 minipci-e slot
CF slot
MPC8544 800MHz
network CPU
256 DDR SDRAM
RouterOS Level 5
25-Mar-10
RB600
3 gigabit ethernet
4 minipci slot
MPC8343E 266/400MHz
network CPU
RouterOS Level 4
01-12
25-Mar-10
RB433UAH
01-13
3 ethernet, 3 minipci
Atheros AR7161 680MHz
RAM: 128MB
With micro-SD slot
RouterOS Level 5
2 port USB
25-Mar-10
RB433
01-14
3 ethernet, 3 minipci
Atheros AR7130 300 MHz
RAM: 64MB
RouterOS Level 4
25-Mar-10
CPU: Atheros
AR7130 300MHz
(411, 411U, 411R, 411AR)
AR7161 680 MHz (411AH)
Memory:
1 ethernet
Lisensi RouterOS:
01-15
25-Mar-10
MikroPoynt
01-16
NEW
PRODUCT
Embedded
Antenna 2,4GHz
11dbi
With Routerboard
411 series
25-Mar-10
RB493(AH)
9 ethernet, 3 minipci
Processor :
RAM: 64MB
RouterOS:
01-17
Level 4 (RB493)
Level 5 (RB493AH)
25-Mar-10
RB450G
01-18
5 gigabit port
Tanpa minipci port
Processor : Atheros
AR7161 680 MHz
RAM: 256 MB
RouterOS Level 5
25-Mar-10
RB750 (G)
01-19
Produk routerboard
terbaru dan
terkecil
Processor :
AR7240 400Mhz (750)
AR7161 680MHz (750G)
5 ethernet port (750)
5 gigabit port (750G)
Lisensi Level 4
Mikrotik Indonesia http://www.mikrotik.co.id
25-Mar-10
Hardware (Interface)
R52
Atheros chipset
MiniPCI type
interface
65 mWatt
3 band wireless
Custom Frequency
Support
01-20
25-Mar-10
Hardware (Interface)
R52H
Atheros chipset
MiniPCI type
interface
350 mWatt
3 band wireless
01-21
2.4 GHz,
5.2 GHz,
5.8 GHz
2.1 2.5 GHz
4.9 6.0 GHz
25-Mar-10
R52N
01-22
NEW
PRODUCT
25-Mar-10
R2N
01-23
NEW
PRODUCT
25-Mar-10
RB600 + R52N
01-24
25-Mar-10
Mikrotik RouterOS
01-25
25-Mar-10
Keunggulan
01-26
25-Mar-10
Penggunaan Kernel
01-27
25-Mar-10
Hardware Compability
(versi 3.x)
01-28
25-Mar-10
RB44 Test
01-29
6 pcs RB44
Total of 24 ethernet ports
25-Mar-10
IP Routing
Interface
Bandwidth Management
01-30
Firewall
25-Mar-10
Services
AAA
01-31
Monitoring
VRRP
Mikrotik Indonesia http://www.mikrotik.co.id
25-Mar-10
Licence Level
Level
Upgrade time
Wireless CPE/PTP
yes
Wireless AP
no
yes
Sync Interface
no
yes
EoIP
unlimited
PPPoE
200
200
500
unlimited
unlimited
unlimited
yes
Dynamic Routing
01-32
RB = yes
yes
200
500
unlimited
10
20
50
unlimited
25-Mar-10
Pembelian Lisensi
01-33
25-Mar-10
Checking Licence
01-34
25-Mar-10
01-35
Fungsi perangkat
Jumlah trafik
Fitur yang dibutuhkan
Interface yang dibutuhkan
25-Mar-10
Berdasarkan Processor
PC
Routerboard System
01-36
25-Mar-10
Kebutuhan Router
01-37
untuk WAN
untuk LAN
untuk kebutuhan khusus (proxy, server)
25-Mar-10
Fungsi Web-Proxy
01-38
25-Mar-10
GSM Router
01-39
25-Mar-10
Wireless Device
01-40
25-Mar-10
Wireless Repeater
01-41
25-Mar-10
01-42
25-Mar-10
Kebutuhan Gigabit
01-43
PC + DOM + RB44GV
RB1000
RB600
RB800
RB450G
RB750G
25-Mar-10
01-44
PC + License Level 6
RB1000
RB800
RB433AH (maksimal 50 active users)
RB433UAH (maksimal 50 active users)
25-Mar-10
Mikrotik
Installation
Installasi Mikrotik
Harddisk
CF Disk
DOM (Disk On Module)
02-46
Routerboard
25-Mar-10
Installation
CD
Netinstall
02-47
25-Mar-10
Download Area
mikrotik.co.id
02-48
25-Mar-10
CD Installation (1)
02-49
25-Mar-10
CD Installation (2)
02-50
25-Mar-10
CD Installation (2)
Choose Yes
Yes/No
Creating partition...
Formatting disk...
Software installed.
02-51
25-Mar-10
Installation
02-52
Welcome menu
Level 0
Softwere id =
F724-MMT
25-Mar-10
Installation
02-53
License level 0
Demo time
15:39:27 jam
Copy license key
tekan tombol
Paste Key
25-Mar-10
Netinstall
Switch
Network:
192.168.1.0/24
IP Address:
192.168.1.10/24
RS-232
Serial null modem
console cable
02-54
25-Mar-10
Netinstall
02-55
25-Mar-10
02-56
25-Mar-10
02-57
25-Mar-10
02-58
25-Mar-10
Netinstall Software
02-59
25-Mar-10
Netinstall Software
02-60
25-Mar-10
Netinstall Software
02-61
25-Mar-10
System Package
02-62
25-Mar-10
Paket di RouterOS
02-63
Nama Paket
Fungsi
advanced-tools
dhcp
hotspot
hotspot gateway
ntp
NTP server
ppp
PPP,PPTP,L2TP,PPPoE
routerboard
routing
security
wireless
Wireless 802.11a/b/g
user-manager
ipv6
IPv6
Mikrotik Indonesia http://www.mikrotik.co.id
25-Mar-10
Version Upgrade
Download modul
02-64
25-Mar-10
Version Downgrade
Download modul
FTP modul tersebut ke router
Cek modul : /file print
/system package downgrade
admin@MikroTik] system package> downgrade
Router will be rebooted. Continue? [y/N]: y
system will reboot shortly
02-65
25-Mar-10
02-66
25-Mar-10
25-Mar-10
25-Mar-10
Quick Typing
02-69
= /system shutdown
25-Mar-10
RouterOS Basic
Configuration
WLAN1
10.10.10.1/24
WLAN1
10.10.10.X/24
ETHER1
192.168.1.1/24
ETHER1
192.168.2.1/24
ETHER1
192.168.X.1/24
ETHERNET PORT
192.168.1.2/24
ETHERNET PORT
192.168.2.2/24
ETHERNET PORT
192.168.X.2/24
MEJA 1
03-71
WLAN1
10.10.10.2/24
MEJA 2
Mikrotik Indonesia http://www.mikrotik.co.id
MEJA X
25-Mar-10
IP Configuration
Lab-1 adalah sebuah
simulasi konfigurasi dasar
sebuah Router Mikrotik
yang akan digunakan di
jaringan local seperti
warnet, office, kampus
atau bahkan di RT/RWNET
X = nomor peserta
03-72
Routerboard Setting
WAN IP
: 10.10.10.x/24
Gateway
: 10.10.10.100
LAN IP
: 192.168.x.1/24
DNS
: 10.100.100.1
Src-NAT and DNS Server
Laptop Setting
IP Address : 192.168.x.2/24
Gateway
: 192.168.x.1
DNS
: 192.168.x.1
25-Mar-10
03-73
25-Mar-10
03-74
25-Mar-10
Konfigurasi Wireless
03-75
Aktifkan Interface
Wireless pada
Ether1
Mikrotik Indonesia http://www.mikrotik.co.id
25-Mar-10
03-76
25-Mar-10
03-77
25-Mar-10
Firewall-Src-NAT
03-78
25-Mar-10
Konfigurasi IP Address
Konfigurasi NAT
03-79
Konfigurasi DNS
25-Mar-10
03-80
25-Mar-10
03-81
Setting clock
/system clock
Set enable
/system ntp server set enabled=yes
Mikrotik Indonesia http://www.mikrotik.co.id
25-Mar-10
NTP Client
Konfigurasi
03-82
Set enable
Set mode unicast
Set IP NTP server
Set time zone
pada menu
/system clock
25-Mar-10
4 fase sinkronisasi
03-83
Started
: start service NTP
Reached
: terkoneksi dengan NTP server
Timeset
: mengganti waktu/tanggal lokal
sesuai waktu NTP server
Synchronized :mengganti jam lokal sama
dengan jam NTP server
25-Mar-10
03-84
25-Mar-10
03-85
25-Mar-10
03-86
25-Mar-10
System Reset
03-87
25-Mar-10
03-88
25-Mar-10
4
192.168.1.1
6
7
03-89
25-Mar-10
03-90
25-Mar-10
03-91
25-Mar-10
03-92
25-Mar-10
03-93
25-Mar-10
Keamanan DHCP
03-94
ARP=reply-only
Client yang bisa terkoneksi hanyalah yang
mendapatkan IP Address melalui proses DHCP,
bukan pengisian manual
25-Mar-10
03-95
25-Mar-10
03-96
25-Mar-10
Interface
03-97
25-Mar-10
03-98
25-Mar-10
03-99
25-Mar-10
03-100
25-Mar-10
03-101
25-Mar-10
03-102
25-Mar-10
03-103
25-Mar-10
03-104
25-Mar-10
Monitoring
Tool monitoring
Ping
03-105
25-Mar-10
Monitoring
03-106
Mac Ping
25-Mar-10
Monitoring
03-107
Flood Ping
25-Mar-10
Monitoring
Torch
Realtime Traffic Monitor
called also torch is used
for monitoring traffic
that is going through
an interface.
03-108
25-Mar-10
Monitoring
Traceroute
03-109
Traceroute determines
how packets are being
routed to a particular
host
We can choose the
protocol : ICMP or UDP
25-Mar-10
Proxy
03-110
25-Mar-10
Konsep Proxy
PROXY
03-111
25-Mar-10
Konsep Proxy
03-112
25-Mar-10
Kebutuhan Proxy
PC Router :
03-113
25-Mar-10
Access list
03-114
Logging facility
Mikrotik Indonesia http://www.mikrotik.co.id
25-Mar-10
Setup Proxy
03-115
25-Mar-10
Mengaktifkan Proxy
03-116
25-Mar-10
Redirect TCP-80
03-117
25-Mar-10
Akses
03-118
Mengatur hak
akses client
25-Mar-10
Cache
03-119
25-Mar-10
03-120
25-Mar-10
Storage
Penyimpanan Cache
03-121
System
Harddisk
25-Mar-10
Basic TCP/IP
Training Outline
04-123
OSI Layer
Packet Header
Mac Address
IP Address and subnetting
IP Protocol
Basic networking, DNS, gateway
25-Mar-10
Internet Topology
25-Mar-10
Application Set
Application
Transport
Link
Transport Set
Network
Open Systems
Interconnection (OSI)
adalah sebuah model
referensi arsitektur
antarmuka jaringan yang
dikembangkan oleh ISO
yang kemudian menjadi
konsep standard
komunikasi jaringan di
hampir semua perangkat
jaringan.
Physical
04-125
25-Mar-10
SMTP
HTTP
FTP
Telnet
DNS
DHCP
SNM
P
TFTP
Session
Transport
TCP
UDP
Network
IP
Routing Protocols
RIP, OSPF, BGP
ICMP
04-126
ARP
Link
Physical
25-Mar-10
Packet Header
IP version (4)
IP Header Length
Type of service
ver
IHL
ToS
16 bit total length
fragment offset flag/length
16 bit identification
TTL
protocol 16 bit header checksum
32 bit source IP Address
Time to Live
32 bit destination IP Address
options (if any)
data
04-127
25-Mar-10
MAC Address
04-128
25-Mar-10
ARP Table
04-129
Address Resolution
Protocol
Merupakan protokol
penghubung antara layer
data-link dan network.
ARP Table di router
merupakan daftar host
yang terhubung langsung
berisi informasi pasangan
mac address dan
ip address
Mikrotik Indonesia - http://www.mikrotik.co.id
25-Mar-10
IP Address
04-130
25-Mar-10
Pengelompokan IP Address
04-131
25-Mar-10
IP Subneting (contoh 1)
Contoh: 192.168.0.0/24
Netmask
: 255.255.255.0
Prefix
: /24
IP Network : 192.168.0.0
First HostIP: 192.168.0.1
Last HostIP : 192.168.0.254
Broadcast : 192.168.0.255
HostIP
: total IP di dalam Subnet () minus 2
04-132
25-Mar-10
IP Subneting (contoh 2)
Contoh: 192.168.0.0/25
Netmask
: 255.255.255.128
Prefix
: /25
IP Network : 192.168.0.0
First HostIP: 192.168.0.1
Last HostIP : 192.168.0.126
Broadcast : 192.168.0.127
HostIP
: total IP di dalam Subnet () minus 2
04-133
25-Mar-10
Tabel Subnet
04-134
Subnet Mask
Prefix
No of IP
Usable IP
255.255.255.0
/24
256
254
255.255.255.128
/25
128
126
255.255.255.192
/26
64
62
255.255.255.224
/27
32
30
255.255.255.240
/28
16
14
255.255.255.248
/29
255.255.255.252
/30
255.255.255.254
/31
255.255.255.255
/32
25-Mar-10
Public IP Address
IP Address yang dapat diakses di jaringan internet.
Kita bisa mendapatkan Public IP Address dari:
Dipinjami dari ISP
Alokasi dari APNIC/IDNIC (www.idnic.net)
Private IP Address
IP Address yang diperuntukkan untuk jaringan lokal (tidak
dapat diakses di jaringan internet)
10.0.0.0
10.255.255.255 (10./8)
172.16.0.0
172.31.255.255 (172.16./12)
192.168.0.0 192.168.255.255 (192.168./16)
04-135
25-Mar-10
IP / subnet
Self Identification
0.0.0.0/8
Localhost
127.0.0.1
Not Used
Other 127.0.0.0/8
Multicast
224.0.0.0/4
169.245.0.0/16
TEST-NET-1
192.0.2.0/24
TEST-NET-2
198.51.100.0/24
TEST-NET-3
203.0.113.0/24
192.88.99.0/24
Benchmark Test
198.18.0.0/15
Future Used
240.0.0.0/4
Limited Broadcast
255.255.255.255/32
25-Mar-10
IP Address v6
04-137
25-Mar-10
IP Protocol
04-138
25-Mar-10
04-139
Name
Echo Reply
Unassigned
Unassigned
Destination
Unreachable
Source Quench
Redirect
Alternate Host
Address
Unassigned
Echo
Router
Advertisement
10
Router Solicitation
11
Time Exceeded
25-Mar-10
04-140
25-Mar-10
04-141
25-Mar-10
Connection Oriented
Koneksi diawali dengan proses handshake
04-142
Client SYN
Server
Server SYN-ACK Client
Client ACK
Server
Reliable Transmission
Mampu melakukan pengurutan paket data, setiap
byte data ditandai dengan nomor yang unik
Error Detection
Jika terjadi error, bisa dilakukan pengiriman ulang
data
Mikrotik Indonesia - http://www.mikrotik.co.id
25-Mar-10
04-143
Flow Control
Mendeteksi supaya satu host tidak mengirimkan
data ke host lainnya terlalu cepat
Segment Size Control
Mendeteksi besaran MSS (maximum segment
size) yang bisa dikirimkan supaya tidak terjadi IP
fragmentation
Congestion Control
TCP menggunakan beberapa mekanisme untuk
mencegah terjadinya congestion pada network
25-Mar-10
192.168.0.4/24
192.168.0.246/24
192.168.0.191/24
192.168.0.26/24
192.168.0.41/24
04-144
192.168.0.142/24
25-Mar-10
Ether1
192.168.0.28/24
Ether3
192.168.4.151/24
04-145
Ether2
192.168.2.74/24
Ether4
192.168.5.211/24
25-Mar-10
192.168.0.74/24
10.10.10.34/24
192.168.0.254/24
192.168.1.254/24
192.168.1.48/24
192.168.0.4/24
192.168.0.141/24
192.168.1.4/24
04-146
192.168.1.24/24
25-Mar-10
192.168.0.254/24
192.168.0.4/24
192.168.0.246/24
192.168.0.191/24
192.168.0.26/24
192.168.0.41/24
04-147
192.168.0.142/24
25-Mar-10
04-148
25-Mar-10
Static Route
Routed Network
05-150
25-Mar-10
Routing!
05-151
25-Mar-10
Routing
192.168.1.0/24
192.168.3.0/24
192.168.2.0/24
ROUTER
GATEWAY
WIRELESS
05-152
192.168.0.0/24
25-Mar-10
dynamic routes
yang akan dibuat secara otomatis:
05-153
static routes
adalah informasi routing yang dibuat secara
manual oleh user untuk mengatur ke arah
mana trafik tertentu akan disalurkan. Default
route adalah salah satu contoh static routes.
Mikrotik Indonesia http://www.mikrotik.co.id
25-Mar-10
Menambahkan Routing
05-154
25-Mar-10
Tipe Routing
A: Active
S: Static
A: Active
D: Dynamic
C: Connected
05-155
25-Mar-10
05-156
Destination
Destination address & network mask
0.0.0.0/0 -> ke semua network
Gateway
IP Address gateway, harus merupakan IP Address yang satu
subnet dengan IP yang terpasang pada salah satu interface
Gateway Interface
Digunakan apabila IP gateway tidak diketahui dan bersifat
dinamik.
Pref Source
source IP address dari paket yang akan meninggalkan router
Distance
Beban untuk kalkulasi pemilihan routing
25-Mar-10
10.10.0.2/24
A
10.10.1.1/24
10.10.2.1/24
10.10.2.2/24
10.10.3.2/24
B
10.10.4.1/24
10.10.4.2/24
05-157
Dst-address=0.0.0.0/0 gateway=10.10.2.1
10.10.0.2/24
10.10.2.2/24
10.10.1.1/24
10.10.1.2/24
10.10.2.1/24
10.10.3.1/24
10.10.3.2/24
(DAC) Dst-addr= 10.10.3.0/24
pref-source=10.10.3.2
05-158
25-Mar-10
Distance
05-159
Contoh Pemilihan
Destination
Distance
Prioritas
192.168.0.0/27 192.168.1.1
192.168.0.0/29 192.168.2.1
192.168.0.0/24 192.168.3.1
192.168.0.0/24 192.168.4.1
05-160
Gateway
25-Mar-10
05-161
10.10.10.100
Router 1
10.10.10.1
Router 2
10.10.10.2
192.168.1.1
192.168.2.1
192.168.1.2
192.168.2.2
25-Mar-10
Langkah-langkah
05-162
25-Mar-10
192.168.X.2/24
WLAN1:10.10.10.X/24
10.10.10.100/24
Buatlah konfigurasi berikut dan lakukan pengaturan
static route sehingga semua laptop dapat
terkoneksi ke internet dan semua laptop dapat
melakukan ping ke laptop lainnya.
Matikanlah src-nat/masquerade.
4
ETHER3:
10.Y.3.1/24
ETHER2:
10.Y.3.2/24
192.168.X.2/24
ETHER3:
10.Y.1.1/24
ETHER3:
10.Y.2.1/24
ETHER2:
10.Y.2.2/24
ETHER2:
10.Y.1.2/24
2
192.168.X.2/24
192.168.X.2/24
05-163
25-Mar-10
AP
ETHER3:
10.Y.1.1/24
10.10.10.100/24
WLAN1:
10.10.10.X/24
ETHER3:
10.Y.3.1/24
ETHER2:
AP
10.Y.3.2/24
192.168.X.2/24
192.168.X.2/24
ETHER3:
10.Y.2.1/24
AP
ETHER2:
10.Y.2.2/24
AP
ETHER2:
10.Y.1.2/24
192.168.X.2/24
192.168.X.2/24
05-164
25-Mar-10
Bridge
Sistem Bridge
192.168.0.1
192.168.0.100-254
ROUTER
GATEWAY
WIRELESS
192.168.0.2
Sistem Bridge
CLIENT
ROUTER
GATEWAY
WIRELESS
192.168.0.2
192.168.0.100-254
Sistem Bridge
Bridge Interface
Ethernet
VLAN
PPTP
Perhatikan!
Membuat Bridge
Konfigurasi Bridge
Secara default, jika kita menggunakan bridge, maka rule yang ada di firewall
tidak akan berpengaruh. Aktifkanlah setting ini jika dibutuhkan.
Bridge Ports
Setelah ketiga interface dimasukkan ke dalam bridge
10.10.10.51-150/24
10.10.10.151-250/24
Perhatikanlah IP Route
Sebelum bridge dibuat IP Address terletak
pada interface masing-masing
IP Route
Bridge Monitoring
192.168.10.1/24
Ether3
192.168.10.2/24
Ether3
Ether1
192.168.10.4/24
192.168.10.3/24
Bridge Loop
Ether3
Ether2
Ether3
Ether1
Ether2
Root - A forwarding port that has been elected for the spanning-tree
topology
Designated - A forwarding port for every LAN segment
Alternate - An alternate path to the root bridge. This path is different
than using the root port.
Backup - A backup/redundant path to a segment where another
switch port already connects.
Disabled - Not strictly part of STP, a network administrator can
manually disable a port
RSTP
Prioritas Bridge
Status Bridge
Monitoring Link
Bridge Filtering
Konfigurasi Console-Terminal
Mengaktifkan Protocol RSTP
/interface bridge set bridge1 protocol=rstp
EoIP Example
10.0.0.1
10.10.10.2
City A
City B
192.168.0.11
192.168.0.1
EoIP
192.168.0.12
192.168.0.13
192.168.0.3
192.168.0.2
Secara Virtual setiap Laptop terletak di dalam satu segmen network yang sama.
EoIP Configuration
Router A
10.10.10.1
Router B
10.10.10.2
192.168.1.1
192.168.1.11
EoIP
192.168.1.2
192.168.1.12
ROUTER B
Wireless Concept
Certified Mikrotik Training Basic Class
Organized by: Citraweb Nusa Infomedia
(Mikrotik Certified Training Partner)
Kemudahan WirelessLAN
Channels 80211b
World Wide Band
915 MHz
2.4 GHz
26 MHz
84.5 MHz
2401
2423
5.8 GHz
125 MHz
2426
2412
2448
2437
2406
2428
2453
2433
2458
2438
2421
2463
2443
2446
2432
2430
2483
Top of channel
14
2473
2452
Channel number
13
2472
2441
2427
2420
2461
2447
2416
2478
2467
2436
2422
2410
12
2456
2442
2411
2473
2462
2431
2417
2400
11
2451
2495
2484
10
Center frequency
2468
2457
2440
2450
ISM Band
2460
2470
2480
MHz
Bottom of
channel
Channels 80211a
36
40
42
44
48
5210
5150
5200
5220
5240
149
152 153
157
160 161
5760
5765
52
56
5250
5180
5735 5745
50
58
60
64
5300
5320
5290
5260
5280
5800
5785
5805 5815
5350
Custom Frequencies
4920-5170
MHz
-5735
MHz
2484
2312-2372
MHz
2512-2732
MHz
5180-5320
MHz
5745-5805
MHz
5330-
MHz
5815-6100
MHz
Spectrum Analyzer
Wavelength
C
= ______
f
dimana :
= wavelength dalam meters
f = frequency dalam Hertz (getaran/detik)
c = kecepatan cahaya (3X108 meter/detik)
8 m/s
3
x
10
______________
2,4 x 10 9 Hz
= 0,125 meter
Tx Power
Perhitungan db - mWatt
10 log
100 mW
1 mW
= 20 dBm
Watts vs dbm
Setiap kenaikan atau
kehilangan 3 dB, kita
akan mendapatkan
dua kali lipat daya
atau kehilangan
setengahnya .
100 W
50 dBm
10 W
40 dBm
2W
33 dBm
1W
30 dBm
100 mW
20 dBm
1 mW
0 dBm
100 uW
-10 dBm
0.001 nW
-80 dBm
Rx Sensivity
Losses Kabel
RG8
LMR400
LMR600
Heliax 3/8
Heliax
Heliax 5/8
: 10
: 6,8
: 5,4
: 5,36
: 3,74
: 2,15
2.4 GHz
5.2 GHz
5.8 GHz
1 km
100.026
106.742
107.69
3 km
109.568
116.284
117.233
5 km
114.005
120.721
121.670
10 km
120.026
126.742
127.690
15 km
123.548
130.264
131.212
20 km
126.047
132.762
133.711
30 km
129.568
136.284
137.233
40 km
132.067
138.783
139.732
Perhitungan RX-Rate
RX-Rate /
Signal Strength
EIRP
Path Loss
(FSL)
Penguatan
Penerimaan
TX-Rate Pemancar
+ Kekuatan antenna pemancar
- Loss Kabel & konektor
Perhitungan RX-Rate
Asumsi :
Access Point 100 mWatt
tanpa booster
kabel LMR400 100 feet
antenna grid 24 db
frekuensi 2,4 GHz
jarak 10 km
Perhitungan
Perangkat
db
Pemancar (EIRP)
Access Point 100 mWatt
20 dbm
Kabel 30 meter
-6.8 db
37.2 db
Antenna 24 db
24 dbi
(EIRP)
-120.026 db
-6.8 db
Antenna 24 db
24 dbi
17.2 db
-65.626 db
Online
Calculator
www.mikrotik.co.id/
test_link.php
Fresnel Zone
Fresnel Zone
Freznel Zone
Selain Line of Sight juga memenuhi ketentuan Freznel Zone
TX antenna
gain
Freznel Zone
RX antenna
gain
Line of sight
TX antenna
loss
TX power
RX antenna
loss
r (radius
fresnel zone)
d1
d2
RX signal
level
RECEIVER
4 f (GHz)
10 (km)
= 17.32 *
= 17.32 *
4 * 2.4 (GHz)
1.042 = 17.68 meter
Lengkung Bumi
http://www.mikrotik.co.id/test_tower.php
Tinggi Antena
120
100
tinggi antena
80
meter
60
Fresnel Zone
40
20
10
20
30
40
50
60
GPS
Untuk mengukur
ketinggian dan posisi
pemasangan di dua
titik, digunakan alat
GPS (Global Positioning System)
Antenna Concept
Directionality
Omnidirectional
In db
Higher db, longer distance coverage
Polarization
Antenna Type
Omni Directional
Yagi Antenna
Grid Antenna
Sectoral Antenna
PROTEKSI CUACA
Network Topology
Point to Point
Dual Nstream
Point to Point
Point to Multipoint
Point to Multipoint
WDS (Wireless
Distribution System) is the
best way how to
interconnect many access
points and allow users to
move around without
getting disconnected from
network.
Keamanan Wireless
Hidden SSID
Disable Default Authenticate
WEP
Wireless Configuration
Certified Mikrotik Training Basic Class
Organized by: Citraweb Nusa Infomedia
(Mikrotik Certified Training Partner)
Wireless Menu
01-257
Wireless Sub-Menu:
Nstreme-Dual - list of Dual-Nstreme Interface
Access-List - list of associations of clients
Registration - list of connected clients
Connect-List - list of rules, that determine to which AP
the station should connect to
Security-Profile list of security functions to wireless
interfaces WEP and WPA/WPA2
Advance &
Simple Menu
01-258
Wireless Mode :
01-259
alignment-only
ap-bridge
bridge
nstreme-dual-slave
station
station-wds
wds-slave
station-pseudobridge
station-pseudobridge-clone
Wireless Mode - 1
01-260
Wireless Mode 2
01-261
Wireless Configuration
Basic Configuration :
Advance Configuration :
01-262
Point to Point
Point to Multi Point
Wireless Bridge
Virtual AP
Nstreme
Dual Nstreme
WDS
Mikrotik Indonesia http://www.mikrotik.co.id
Point to Point
AP Side
Client Side
01-263
01-264
01-265
01-266
Configuration AP Side
01-267
01-268
01-269
01-270
Client Management
Kita dapat
melakukan
pengaturan
untuk setiap
klien dan hal ini
akan
mengabaikan
konfigurasi
global
01-271
01-272
01-273
Membutuhkan lisensi
level 4
Set mode=ap-bridge
Konfigurasi lainnya
sama dengan
konfigurasi point-topoint
01-274
Dapat menggunakan
lisensi level 3
Set mode, ssid, band,
scan-list
Set mode=station
Pastikan frekuensi yang
digunakan berada
dalam rentang scan-list
Configuration AP Side
01-275
01-276
01-277
Configuration Console-Terminal
Bridge-AP
Configuration bridged - AP
01-278
Virtual AP
01-279
Virtual AP Configuration
01-280
Configuration Console-Terminal
VAP
Configuration - VAP
01-281
Wireless Bridge
01-282
AP
A
ethernet
192.168.0.x/24
01-283
Station
Wireless
connection
192.168.0.100+x/24
ethernet
192.168.0.100+x/24
192.168.0.x/24
01-284
01-285
01-286
01-287
Other Setting
01-288
Scan Tool
01-289
Snoop Tool
01-290
Connect List
01-291
Rate Jumping
5% of time
54Mbps
80% of time
15% of time
36Mbps
Recalibration
01-292
48Mbps
Recalibration
01-293
Supported rates
client data rates
Basic rates link
management data
rates
If router can't send or
receive data at basic
rate link goes down
Hotspot
Certified Mikrotik Training Basic Class
Organized by: Citraweb Nusa Infomedia
(Mikrotik Certified Training Partner)
HotSpot
Wired Network
Hotspot Gateway
HotSpot features
Autentikasi User
Perhitungan
Waktu akses
Data dikirim atau diterima
Limitasi Data
Berdasarkan data rate (kecepatan akses)
Berdasarkan jumlah data
Limitasi Akses User berdasarkan waktu
Support RADIUS
Bypass!
Authentication Method
HotSpot User
HotSpot users
User Limitation
Limit Uptime batas
waktu user dapat
menggunakan akses
ke Hotspot Network.
Limit-bytes-in dan
Limit-bytes-out
batas Jumlah trasfer
data yang bisa
dilakukan oleh user.
Bypass! - IP bindings
HotSpot IP bindings
Bypass - WalledGarden
HTTP-level WalledGarden
IP-WalledGarden
Advertisement
Advertisement
VPN Basic
VPN Networks
Aplication Server
Office 1
PC
Aplication Server
Router
PC
File Server
Office 2
Router
WAN
PC
PC
VPN Networks
File Server
Office 3
Router
PC
PC
PC
PC
PPTP tunnel
10.10.10.100/24
10.10.20.1/32
10.10.10.1/24
10.10.10.2/24
10.10.20.2/32
192.168.1.1/24
192.168.1.2/24
Table 1
192.168.2.1/24
192.168.2.2/24
Table 2
Membuat PPTP-Client :
Username dan Password disesuaikan dari
konfigurasi server.
Connect-to adalah parameter Alamat IP dari
PPTP-Server.
Add-Default-Route adalah parameter jika akan
menggunakan koneksi PPTP sebagai gateway
utama.
10.200.200.1
Pool-pptp
PPP - Secret
Firewall
Certified Mikrotik Training Basic Class
Organized by: Citraweb Nusa Infomedia
(Mikrotik Certified Training Partner)
Firewall
Workstation
Switch
Server
Firewall
Laptop
Internet
Firewall
Rules
NAT (source-nat and destination-nat)
Mangle
Address List
Layer 7 Protocol (baru di versi 3)
Service Ports
Connections
Paket Data
PRE
ROUTING
ROUTING
DECISION
MANGLE
FORWARD
OUTPUT
FILTER
FORWARD
POST
ROUTING
QUEUE
GLOBAL-IN
FILTER
OUTPUT
MANGLE
POSTROUTING
DST-NAT
ROUTING
ADJUSTMENT
QUEUE
GLOBAL-OUT
INPUT
MANGLE
PREROUTING
MANGLE
INPUT
MANGLE
OUTPUT
SRC-NAT
CONNECTION
TRACKING
FILTER
INPUT
CONNECTION
TRACKING
HTB
INTERFACE
INPUT
INTERFACE
LOCAL
PROCESS
ROUTING
DECISION
OUTPUT
INTERFACE
To
Mangle
Firewall
Queue
Outside
Router/
Local
Process
Prerouting
Input
Input
Global-Total
Router/
Local
Process
Outside
Output
Output
Global-Out
Outside
Outside
Global-In
Postrouting
Global-Total
Interface
Prerouting
Forward
Postrouting
Global-In
Forward
Global-Out
Global-Total
Interface
Use IP Firewall
Connection State
Connection State
Firewall
New
Established
Related
Invalid
Mangle
Mangle on Winbox
Prerouting
yes
yes
no
Input
yes
no
no
Forward
no
yes
no
Output
no
no
yes
Postrouting
no
yes
yes
Type of Mark
Packet Mark
Connection Mark
Route Mark
Connection Mark
Passthrough
Passthrough=no
Passthrough=yes
Biasanya pada :
Uplink traffic
Downlink traffic
add src-address=192.168.0.2/32
action=mark-packet chain=prerouting
new-packet-mark=mark-uplink
add dst-address=192.168.0.2/32
action=mark-packet chain=prerouting
new-packet-mark=mark-downlink
Firewall Filters
Prerouting
not
implemented
not
implemented
not
implemented
Input
yes
no
no
Forward
no
yes
no
Output
no
no
yes
Postrouting
not
implemented
not
implemented
not
implemented
DROP virus
DROP spam server
DROP virus
DROP
DROP
DROP
DROP
DROP
DROP
DROP
ACCEPT ALL
ACCEPT HTTP
ACCEPT POP3
ACCEPT SMTP
ACCEPT IM
ACCEPT IRC
ACCEPT FTP
ACCEPT SSH
ACCEPT TELNET
ACCEPT ..
ACCEPT ..
DROP THE OTHER
Filter Rules
RouterOS v3 Services
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
PORT
20
21
22
23
53
80
179
443
646
1080
1723
1968
2000
2210
2211
2828
3128
8291
8728
-------
PROTOCOL
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
tcp
/1
/2
/4
DESCRIPTION
FTP
FTP
SSH, SFTP
Telnet
DNS
HTTP
BGP
SHTTP (Hotspot)
LDP (MPLS)
SoCKS (Hotspot)
PPTP
MME
Bandwidth Server
Dude Server
Dude Server
uPnP
Web Proxy
Winbox
API
ICMP
IGMP (Multicast)
IPIP
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
PORT
53
123
161
500
520
521
646
1698
1699
1701
1812
1813
1900
1966
5678
---------------
PROTOCOL
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
udp
/46
/47
/50
/51
/89
/103
/112
DESCRIPTION
DNS
NTP
SNMP
IPSec
RIP
RIP
LDP (MPLS)
RSVP (MPLS)
RSVP (MPLS)
L2TP
User-Manager
User-Manager
uPnP
MME
Neighbor Discovery
RSVP (MPLS)
PPRP, EoIP
IPSec
IPSec
OSPF
PIM (Multicast)
VRRP
Playboy - 216.163.137.3
Penthouse - 64.124.57.235
IP Address List
Memasukkan ke Address-List
Blok IP di Address-List
Firewall NAT
OUTGOING
OUTGOING
NAT ROUTER
INCOMING
INCOMING
INCOMING
INCOMING
PUBLIC NETWORK
PRIVATE NETWORK
OUTGOING
OUTGOING
Firewall NAT
masquerade
redirect
Mengaktifkan Web-Proxy
Redirect TCP-80
Last Issue
01-392
Quality of Service
Certified Mikrotik Training Basic Class
Organized by: Citraweb Nusa Infomedia
(Mikrotik Certified Training Partner)
Quality of Service
Quality of Service
Simple Queue
Staged Limitation
Burst
Rate(kbps)
512
Burst-limit
Average Rate
384
256
Max-limit
192
Burst-Threshold
128
Limit-at
10
15
20
time(s)
Burst-limit=1M
Burst-threshold=512K
Burst-time=30s
allow-address
IP address yang dapat
melihat grafik tersebut
allow-target
memperbolehkan IP
Address yang tercantum
pada target untuk melihat
grafik.
Queue Disciplines
Scheduler queues
Mengatur packet flow, sesuai dengan jumlah
Shaper queues
Mengontrol kecepatan date rate.
Shaper
Mbps
2
10
15
20
detik
kelebihan data-rate
akan didrop
10
15
20
detik
Scheduler
Mbps
2
10
15
20
detik
kelebihan data-rate
akan di antri
10
15
20
detik
Queue Kinds
Scheduler queues:
Shaper queues:
Queue Kinds
Skema FIFO
Flow 1
Flow 2
Paket disalurkan
sesuai yang datang
duluan
Flow 3
Flow 4
Jika penuh
akan di drop
ke
interface
Skema RED
Flow 1
ke
interface
Flow 2
Flow 3
Flow 4
Secara random
akan di drop
Skema SFQ
Flow 1
ke
interface
Flow 2
Flow 3
Flow 4
Algoritma
Hashing
sub-queue
Algoritma
Round
Robin
Setting PCQ
Skema PCQ
pcq-clasifier
src-address
sub-queue
Algoritma
Round
Robin
SRC-ADDRESS=10.0.0.1
SRC-ADDRESS=10.0.0.2
Flow 1
Flow 2
Flow 3
SRC-ADDRESS=10.0.0.3
SRC-ADDRESS=10.0.0.4
SRC-ADDRESS=10.0.0.5
Flow 4
SRC-ADDRESS=10.0.0.6
SRC-ADDRESS=10.0.0.7
ke
interface
Pcq-rate=128000
2 users
4 users
128k
128k
queue=pcq-down
max-limit=512k
7 users
73k
73k
73k
73k
128k
128k
128k
128k
73k
73k
73k
Pcq-rate=0
1 user
2 users
7 users
73k
256k
73k
73k
queue=pcq-down
max-limit=512k
512k
73k
73k
256k
73k
73k
Level1
Level2
POP3
Flow 1
ke
interface
HTTP
Flow 2
HTTP
&FTP
Flow 3
Flow 4
FTP
FILTER
LOCAL
Skema HTB
Level 1
Inner
Feed
Slots
Class A
Inner
Feed
Self
Slots
Self
Feed
Level 2
Leaf1
priority 7
Leaf2
priority 8
Filter
HTB States
hijau
kuning
Posisi di mana data-rate lebih besar dari limit-at, namun lebih kecil dari
max-limit.
Diijinkan atau tidaknya penambahan trafik bergantung pada :
posisi parent, jika prioritas class sama dengan parentnya dan parentnya
dalam posisi kuning
posisi class itu sendiri, jika parent sudah berstatus kuning.
merah
Queue with
SRC-NAT & Internal Proxy
ROUTER
SRC-NAT
INTERNET
SRC-NAT
Direct Downstream
3
INTERNET
Upstream to proxy
WEB-PROXY
LOCAL
PROCESS
Downstream from proxy
4
Web-Proxy Setup
> ip web-proxy pr enabled: yes
src-address: 0.0.0.0
port: 3128
hostname: "proxy"
transparent-proxy: yes
parent-proxy: 0.0.0.0:0
cache-administrator: "webmaster"
max-object-size: 4096KiB
cache-drive: system
max-cache-size: none
max-ram-cache-size: unlimited
status: running
reserved-for-cache: 0KiB
reserved-for-ram-cache: 154624KiB
Firewall Setup
[admin@instaler] ip firewall nat> pr
Flags: X - disabled, I - invalid, D - dynamic
0 chain=srcnat out-interface=public
src-address=192.168.x.0/24
action=masquerade
1 chain=dstnat in-interface=lan srcaddress=192.168.1.0/24 protocol=tcp
dst-port=80 action=redirect to-ports=3128
Queue Setup
Simple-Queue Setup :
name="queue-notebook"
target-addresses=192.168.x.2/32
interface=all
parent=none
direction=both
queue=default-small/default-small
[LAB]Simple-Queue Traffic
Internasional dan IIX
Nice.rsc
# Script untuk mengenerate IP Address di Router NICE
# Script by www.mikrotik.co.id
# Generated at 1 February 2007 13:47:12 WIB ... 1390 lines
/ip firewall address-list
rem [find list=nice]
add list=nice address="61.94.0.0/16"
add list=nice address="125.160.0.0/16"
add list=nice address="125.161.0.0/16"
add list=nice address="125.162.0.0/16"
add list=nice address="125.163.0.0/16"
add list=nice address="125.164.0.0/16"
add list=nice address="222.124.0.0/16"
add list=nice address="61.5.0.0/17"
add list=nice address="202.158.0.0/17"
add list=nice address="61.14.0.0/18"
..
Address-List on
Winbox
Pengaturan Mangle
[admin@MikroTik] > /ip firewall mangle pr
Flags: X - disabled, I - invalid, D - dynamic
0 chain=prerouting in-interface=[interface menuju network local]
dst-address-list=nice
action=mark-connection new-connection-mark=conn-iix
passthrough=yes
1 chain=prerouting connection-mark=conn-iix
action=mark-packet new-packet-mark=packet-iix
passthrough=no
2 chain=prerouting action=mark-packet
new-packet-mark=packet-intl passthrough=no
Pengaturan Simple-Queue
[admin@MikroTik]> /queue simple pr
Flags: X - disabled, I - invalid, D - dynamic
0 name="client-iix" target-addresses=192.168.x.2/32
dst-address=0.0.0.0/0 interface=all parent=none
packet-marks=packet-iix direction=both priority=8
queue=default-small/default-small limit-at=0/0
max-limit=64000/256000 total-queue=default-small
1 name="client-intl" target-addresses=192.168.x.2/32
dst-address=0.0.0.0/0 interface=all parent=none
packet-marks=packet-intl direction=both priority=8
queue=default-small/default-small limit-at=0/0
max-limit=32000/128000 total-queue=default-small