Showing posts with label Mikrotik. Show all posts
Showing posts with label Mikrotik. Show all posts

Mikrotik: Blocking Unleased DHCP IP Address

The case this time is how we block users other than DHCP Client with Mikrotik Winbox, in the other word that users who use a static Ip Address instead of DHCP.

ip can not use our connections. Just who gets an IP address via DHCP Server mikrotik who can use the internet connection,

I asume that Your DHCP server in mikrotik router are already running well.
We only need to change some the existing settings. 

  1. Sign In to Your Mikrotik Via Winbox
  2. IP menu> DHCP Server click 2x on the DHCP server. And Check "Add ARP For Lease"

Go to menu "Interfaces" click 2x on your local interface or an interface where you apply a DHCP Server And Replace option "ARP" to "reply-only '


DONE! Now you try to use a static IP on your computer at yourlocal network, connections to the router will not work unless you use the options "Obtain an IP Address Automaticaly" or DHCP on interfaces / ethernet your computer enabled.


Read More »

Block Any sites (like Facebook - Youtube etc using L7 (Layer7) in Mikrotik

Below i will show you how to block facebook and youtube sites using Mikrotik L7 Protocols (Layer 7). here i use RouterBoardOS RB1100.

STEP 1:
you have to create new Regexp rule at Layer7 Protocols by Press, and name it as “DENIED” (withoue quote), see details below:

You can Copy & Paste the code above at below:
^.+(facebook.com|youtube).*$
STEP 2:
Now create Filter Rules, as follow:

At General Tabs for Chain, Please Choose : Foward


At Advanced tabs, select ‘DENIED’ (rule that you have
create at step 1) for Layer7 Protocols



Choose Action ‘DROP’
And At last, your Filter rule to block facebook and youtube should have effected to your network.
try to access facebook & youtube, and you will see that the two sites will not able to access.
this can be see from the filter rule you have created, it will catch the bytes for denied sites in your network.




Read More »

Auto (Auto Clear DNS|Auto Reboot|Auto Shutdown) on Mikrotik

Auto Clear DNS
/system script
add name=”cacheflush” source=”/ip dns cache flush” policy=ftp,reboot,read,write,policy,test,winbox,password
/system scheduler
add name=”cache flush” on-event=cacheflush start-date=sep/26/2013 start-time=startup interval=1d comment=”” disabled=no
add name=”cache flush-12″ on-event=cacheflush start-date=sep/26/2013 start-time=12:00:00 interval=1d comment=”” disabled=no
add name=”cache flush-15″ on-event=cacheflush start-date=sep/26/2013 start-time=15:00:00 interval=1d comment=”” disabled=no
add name=”cache flush-17″ on-event=cacheflush start-date=sep/26/2013 start-time=17:00:00 interval=1d comment=”” disabled=no
::Auto Reboot
/system script
add name=”reboot” policy=”ftp,reboot,read,write,policy,test,winbox,password,sniff” source=”/system reboot”
/system scheduler
add name=”reboot” start-date=”sep/26/2013″ start-time=”18:00:00″ interval=”1d” on-event=”/system reboot”
::Auto Shutdown
/system script
add name=”shutdown” policy=”ftp,reboot,read,write,policy,test,winbox,password,sniff” source=”/system shutdown”
/system scheduler
add name=”shutdown” start-date=”sep/26/2013″ start-time=”23:00:00″ interval=”1d” on-event=”/system shutdown”
Read More »

HOW TO VIEW LOG MIKROTIK



Some time we need to know what happens with our routers, if someone make achange the router or someone attack our routers, we need to know and analyze the log. How to view log file on mikrotik ? to view log file on mikrotik is very simple. just click on Log menu , see the picture bellow :
Read More »

How to auto check ethernet on Mikrotik

How to auto check ethernet on Mikrotik? Sometimes when you install a network cable to the ethernet to the mikrotik, do not know where ethernet is currently active.

example your router has 3 ethernet cards,
Read More »

How to block Port Frequently Keylogger In Use

Keylogger, so frustrating to be found on the computer you are using, or you manage a computer cafe, several ports that are often used keylogger is the following: 25, 995, 465, 587, 110 or who frequently use email and ftp service.

The ports should be blocked, to minimize fraudulent activity that occurs due to a keylogger. And here's how to block ports used by keyologger:

Read More »

Load Balancing Script

Load balance on the mikrotik is a technique to distribute the traffic load on two or more lines in a balanced connection, so that traffic can run optimally, maximize throughput, minimize response times and avoid overload on one connection path.
During this time many of us who think wrong, that by using loadbalance two connection lines, then the greater the bandwidth that we will get a doubling of bandwidth before using loadbalance (accumulation of both the

Read More »

How to Create VPN in Mikrotik

VPN is a technology that allows a server can be contacted from the Internet, without a special partnership with Internet Service Provider. With this technology the server can be placed anywhere.

Mikrotik novice user for you, how to make vpn mikrotik is very easy in the following explanation:
Read More »

How to protect FTP server Mikrotik

FTP Server service on our Mikrotik Router of course, we need to run for administrative purposes. But, what if  FTP is running, there are those who want to use FTP on the router mikrotik to try things that are harmful to our Network. The most common way for this is usually done is by using the method of Brute Force Attack.
Read More »

Load Balancing With Fail Over

This guide will explain how to create a web load balancer using HAProxy, HAProxy is an open source product and who supports the purposes of fail over load balancing webserver, largely for the purpose reverse proxy in site a high daily traffic (High availability load balance (support fail over and session) using the Debian base HAProxy).
Read More »

Mikrotik Configuration for NAT

Network Address Translation or more commonly referred to as NAT is a method to connect more than one computer to the Internet network using a single IP address. Much use of this method due to the limited availability of IP addresses, the need for safety (security), and the ease and flexibility in network administration.

Read More »

Mikrotik Configuration for Transparent web proxy

One function is to store the proxy cache. If a LAN uses a proxy to connect to the Internet, it is done by the browser when a user accesses a web server url is taking these requests in a proxy server. Whereas if the data has not been contained in the proxy server then get directly from the web proxy server. Then the request is stored in the proxy cache. Furthermore, if there are clients who make requests to the same url, it will be taken from the cache. This will make access to the Internet faster

Read More »

Mikrotik Router OS basic commands

H4BZTXM9N6MC Mikrotik commandactually almost the same as the existing command linux, mikrotik because basically this is a Linux kernel, the result of processing back from the Debian distribution of Linux. Use the same command shell, such as saving the command, simply use the TAB key on the keyboard then a long command, no longer need to be typed, simply type the beginning of the command is called, will automatically display the Shell will own commands respect. For example IP ADDRESS command in mikrotik. Enough just type in the IP ADD spaced press the TAB key, then the automatic shell will recognize and translate the
Read More »

How to Setting Mikrotik Wireless Bridge

ridge mode allows the network to one affiliated with the network on the other transparently, without the need to go through routing, so the engine is in the network that one can have IP addresses that are in a same subnet as the other side.

However, if our wireless network is quite large, this will create a bridge mode wireless traffic increases, since there will be a lot of broadcast traffic from one network to another network. For a network that is large enough, I suggest the use of routing
Read More »

Bandwidth Management in Mikrotik

Another option is the method ofbandwidth management, if if wanted bandwidth is shared equally by Mikrotik, such as bandwidth 256kbps downstream and 256kbps upstream. While the client will access as many as 10 clients, each client automatically gets a small upstream and downstream bandwidth of 256kbps divided by 10. So each one can be 25.6 kbps. If only 2 Client who access it each can be 128kbps.

For that type used PCQ (Per Connection Queue), which can be automatically divide the traffic per client. About the type of queue in mikrotik This can be read on the manual in http://www.mikrotik.com/testdocs/ros/2.9/root/queue.php.

Previously need to be made a rule in the mangle. Such as:

/ip firewall mangle add chain=forward src-address=192.168.0.0/27 \
action=mark-connection new-connection-mark=users-con
/ip firewall mangle add connection-mark=users-con action=mark-packet \
new-packet-mark=users chain=forward
Because type PCQ does not exist, then it needs to be added, there are two types of this PCQ. First named pcq-download, which will regulate all traffic through the destination address / destination address. Traffic is passing Local interface. So that all traffic download / downstream coming from the network 192.168.0.0/27 will be shared automatically.

PCQ second type, called pcq-upload, to regulate all upstream traffic derived from the source address / source address. Traffic is passing public interface. So that all traffic upload / upstream originating from the network 192.168.0.0/27 will be shared automatically. 

Command:
/queue type add name=pcq-download kind=pcq pcq-classifier=dst-address
/queue type add name=pcq-upload kind=pcq pcq-classifier=src-address
Once the rules for the PCQ and Mangle added, now for the rules traffic division. Queue Queue Tree is used, ie:
/queue tree add parent = Local queue = pcq-download packet-mark = users
/queue tree add parent = Public queue = pcq-upload packet-mark = users
The command above assumes that if the bandwidth received from the provider Internet berflukstuasi or changing. If we believe that the bandwidth received, for example can 256kbs downstream, and 256kbps upstream, then No more rules, such as:
For downstream traffic:
/queue tree add name = Download parent = Local max-limit = 256k
/queue tree add parent = Download queue = pcq-download packet-mark = users

And upstream traffic:
/queue tree add name = Upload parent = Public max-limit = 256k
/queue tree add parent = Upload queue = pcq-upload packet-mark = users


My advice Pake Simple Queue.
Read More »

Limit Youtube Video streaming on MikroTik

Previously I've written a Mikrotik Tutorial about Limiting download with IDM in Mikrotik, this time I will share again on how to limit the streaming video, especially youtube.

This step by step limit Youtube Video streaming:
open terminal and copy paste following codes:
Read More »

Limit download with IDM in Mikrotik

For those of you who want to restrict users who use a software download IDM (Internet Download Manager) in Mikrotik. Here's how, For I do not want to bother with what the extension, but can also be configured like this:
* Browse the full bandwidth
* Download any file extension, which is more than 1M, will terlimit so 256kbps
* If the download <1M, will get a full bandwidth
* Watch the video has finished dilimit 128 kbps
I apply this Setiing using RB750G
open new terminal and copy
paste following line
/ip firewall layer7-protocol add comment = "" name = http-video regexp = \
"Http / (0 \ \ .9 | 1 \ \ .0 | 1 \ \ .1) [\ \ x09-\ \ x0d] [1-5] [0-9] [0-9] [\ \ x09 - \ \ x0d -~]*( content-type: video)"
/ip firewall mangle
add chain = forward action = mark-connection comment = "limit download" connection-bytes = 1024000-4294967295 in-interface = lan5 new-connection-mark = Action-Download passthrough = yes disabled = no

add action = mark-packet chain = forward comment = "" connection-mark = Action-Download disabled = no in-interface = lan5 new-packet-mark = download_pkt passthrough = yes

add action = mark-packet chain = prerouting comment = "limit video streaming" disabled = no protocol = http layer7-new-video-packet-mark = http-video-up passthrough = yes protocol = tcp

add action = mark-packet chain = prerouting comment = "limit the audio stream" disabled = no protocol = http layer7-audio-new-packet-mark = http-audio-ups passthrough = yes protocol = tcp
/queue type
add kind = pcq name = pcq-classifier = batasidownload dst-address pcq-limit = 50 pcq-rate = 256000 pcq-total-limit = 2000
/queue simple
add burst-limit = 0 / 0 burst-threshold = 0 / 0 burst-time = 0s/0s comment = "" direction = Both disabled = no dst-address = 0.0.0.0 / 0 interface = all limit-at = 0 / 8k max-limit = 128k/128k name = "HTTP Video Traffict" packet-marks = http-video-up parent = none priority = 8 queue = default-small/default-small total-queue = default-small

add burst-limit = 0 / 0 burst-threshold = 0 / 0 burst-time = 0s/0s comment = "" direction = Both disabled = no dst-address = 0.0.0.0 / 0 interface = all limit-at = 0 / 0 max-limit = 128k/128k name = "HTTP Video Queue" packet-marks = http-video-up parent = "HTTP Video Traffict" priority = 8 queue = default-small/default-small target-addresses = 0.0.0.0 / 0 total-queue = default-small
/queue tree
add burst-limit = 0 burst-threshold = 0 burst-time = 0s disabled = no limit-at = 0 max-limit = 256k name = batasidownloadfreebrowsing packet-mark = download_pkt parent = global-out priority = 8 queue = batasidownload
Read More »