Showing posts with label TUTORIAL. Show all posts
Showing posts with label TUTORIAL. Show all posts

Storage Servers

Storage Servers


Introduction:

A storage server is a type of server used to store and manage digital data and acts as a backup server to store backup data. A storage server will be used for storing both small and large amount of data over a shared network. Although the need for storage is evident, it is not always clear which solution is right for your organization. There are a variety of options available, the most prevalent are direct-attached storage (DAS), network-attached storage (NAS) and storage area networks (SAN). Choosing the right storage solution can be as personal and individual decision. There is no one right answer for everyone. Instead, it is important to focus on the specific needs and long-term business goals of your organization. Several key criteria to consider include:

1 - Capacity

2 - Performance

3 - Scalability

4 - Availability  reliability

5 - Data protection

6 - IT staff and Resources available

7 - Budgets concern

DAS (Direct Attached Storage):

Direct Attached Storage (DAS) is a digital storage device that is attached directly to a server or PC via cable, meaning that DAS is not a part of the storage network. A DAS device may be an internal or external hard disk drive like internal hard drive in PC. These disk drives can be protected with different RAID levels, depending on data importance and criticality. For the server, a DAS storage is very much similar to its own internal drive or an external drive that has been plugged in.

The main interfaces used for DAS connection include Advanced Technology Attachment (ATA), Serial Advanced Technology Attachment (SATA), eSATA, Small Computer System Interface (SCSI), Serial Attached SCSI (SAS), and Fiber Channel.

It is worth mentioning that high access rate due to network absence, capability of storage capacity extension, data security and fault tolerance are some of advantages of DAS. However, the primary benefits of DAS include low cost and simplicity. Since it does not need components of network storage systems such as routers, switches and appropriate cabling and connections. The drawback of DAS is that it is not accessible by multiple user groups and only one user at a time is allowed.

DAS is the most basic level of storage. The storage devices are part of the host computer or directly connected to a single server, in which the workstation must access the server in order to connect to the storage device. On the opposite side, NAS and SAN are connected to workstation and servers over a network. In the DAS, if the server is down or experiencing problems, users can not store and access data. Surveillance images cannot be retrieved or stored. If the organization grows and needs new servers, storage for each server must be administered separately.

NAS (Network Attached Storage):

NAS is a type of file storage device that connects to a network. NAS devices, which typically do not have a keyboard or display, provide Local Area Network (LAN) nodes with file storage through a standard Ethernet connection. In fact, NAS employs an Ethernet connection for sharing files over the network.

Each NAS on the LAN acts as an independent network node which has its own IP address. Since the NAS device has an IP address, it will be accessible over the network via that IP address. NAS devices can be built with single drive or multiple drives. The latter provides higher capacity and greater data protection.

The existence of multiple computers on the network, is a candidate for using a network attached storage (NAS) device. Some NAS servers are just used for backing up and sharing files across the network, while others can do more tasks, such as sharing a printer among the networked PCs, acting as a media streamer or even a surveillance system by supporting IP cameras.

NAS has benefits such as good reading and writing performance, good data redundancy and protection options, offering security via data encryption, sharing files, backing up data from Windows, Mac, and possibly Linux machines and offering some cloud service for storage and backup.

The application of NAS in homes is storing and serving multimedia files and automated backup. For instance, many smart TVs use NAS to provide centralized storage. If a NAS device has a server mode, it can also act as an email, multimedia, database or print server for a small business. In enterprise level, a NAS array can be used as a backup for archiving and recovery. Also, some NAS products can hold enough disks to support RAID for greater data protection.

For those systems that must store a large amount of videos/images for many days, NAS is a good option. Network-Attached Storage comprised of both hard disks and management software. NAS serves files over a network. As a result, NAS relieves the server of storage and file serving responsibilities and provides more flexibility in data access, because of its independence.

SAN (Storage Area Network):

A Storage Area Network (SAN) is a secure high-speed data transfer network in which storage devices can access to multiple servers. It is a high-performance storage network that transfers data between servers and storage devices separate from local area network. SAN is often used where larger areas of high-speed storage and fast input-output space is required.

In contrast to DAS or NAS, which are optimized for data sharing at the first level, the strength of the SAN lies in its ability to move large blocks of data. This is so important for Band-Width intensive applications such as IP/Megapixel camera system recording. It provides block-level storage, meaning that when a host wants to access a storage device, it sends a block-based access request for that storage device. SAN storage devices include disk-based devices like RAID.

SAN implementation which is in two following types, leads to consistent and secure data transferring. Depending on what type is used, different types of cabling, protocols and routing equipment are used.

 Fiber channel (FC): Storage and servers are connected through a high-speed network of unified fiber channel switches. This is used for mission-critical applications where continuous data access is required. Fiber channel provides data retrieval speed more than 5 Gbps.

 Internet Small Computer System Interface (ISCSI) Protocol: SCSI is a standard used to communicate between servers and storage devices. By this infrastructure, the flexibility of a low-cost IP network is achieved.


In a SAN network, data transferring from one storage to another is conducted without or with minimal server intervention. SAN provides dynamic failover protection which means if a server fails or goes offline for maintenance, network operation continues. Also, additional capacity can be added to SAN as required. These, are the advantages of SAN. The main disadvantages of SANs are cost and complexity. Because SAN hardware is expensive and also building and managing a SAN, require a special skill set.

The distributed architecture of SAN enables it to offer higher level of performance and reliability. SANs provide fast data transfer while reducing latency and server workload.

VSA (Virtual Storage Appliance):

Virtual Storage Appliance (VSA) is a storage controller which runs on a virtual machine to create a shared storage without the need of additional hardware. It presents either file-level or block-level storage to the network.

VSA is not a connected physical device to any specific hardware. It uses the host system's local disk for storage as a virtual disk or it can access to local physical drives directly. In fact, the VSA creates a virtual storage area similar to networked storage by incorporating direct-attached capacity on each physical host. Small businesses that need redundancy and high availability for shared storage and also large enterprises which transfer data between various arrays, are good usage candidates for the virtual storage appliance.

The differences between NAS, SAN and DAS:

NAS differs from a SAN in the way they distribute storage to other devices, meaning that the main difference between these two, is access protocols. NAS supports data storage under CIFS and NFS protocols (file-level), while access protocols in SAN are ISCSI and Fiber channel (block level).

On the other hand, it may seem, DAS is faster than any other storage methods. Since it needs data transferring over the network, while all data transferring will be occurred on a dedicated connection between the server and the storage device. However, due to high speed connection of fiber channel, in some cases SAN presents faster speed compared to speed provided by DAS. Also, Since SAN separates storage from the servers and incorporates them in a place where it can be accessed by any application, it provides better flexibility, availability and storage performance compared to DAS for large organization. So, due to the improved storage performance of SAN, organizations won't need additional storage hardware, which saves money, although SAN hardware can be costly. Moreover, separating storage device from the servers, allows computing resources on the servers to perform other tasks not related to storage.

On the other hand, the difference between DAS and Network Attached Storage (NAS) is that a DAS device connects directly to a server without a network connection. DAS gives good performance, but there are limitations like the number of servers that can access to it. Also DAS storage has to be near to the server in the same rack. The advantage of NAS over DAS is that it simplifies file sharing among multiple users. The main difference is about how the computer or the server treats a particular storage. If the server's processor is responsible for managing the attached storage, it will be some type of DAS and if the computer or the server treats the attached storage as another computer, which shares its data through the network, then it is a NAS.

Using storage servers for NVR and DVR:

Video surveillance requirements for high storage capacity and increasing the retention period, make the NVR or DVR to utilize the external storage servers in order to achieve a desired surveillance system. Regardless of format, both DVRs and NVRs can employ external storages presented in previous sections for improved capacity and reliability.

DAS has been the most implemented storage device in DVRs, so that it has generally became the part of this recording system. For medium and large scale video surveillance where performance, reliability and scalability of the storage system are important issues, newer external storages like SAN and NAS are more helpful than fixed DAS storage.

Summary:

The storage component may be internal, fixed DAS storage, or may employ some type of external storage. Also, the other major component of surveillance system is the DVR or NVR which as engine of the entire system manages one or more cameras and the storage subsystem. Video frames from cameras are transferred from the DVR or NVR to the storage system. So choosing the appropriate storage device to achieve capacity and reliability, leads to a great surveillance system.

Share:

Computer Storage Options - Today Tomorrow

Computer Storage Options - Today  Tomorrow


Abstract:

This is the article brings the brief about the today's and future computer storage options. Most of ours using computers and systems, but we do not know much more details about the storage and storage options existing today. For those people, you can easily get to know about the brief introduction and overview of nowadays storage options - personal and enterprise from this article.

Hard Disk Drive:

If anyone hears about computer storage, suddenly he might have think about this hard disk only. It is a common storage option, most of the PC's have. After 1990, the evolutions of hard disk become more and more. So it easily occupies our PC's without any competitions of other storage options. Compare to other storage options this is the smartest storage, suitable for personal computers. There are two main types of hard disks are used in today's systems. They are,

oMagnetic Hard Disks
oSolid State Disks

Magnetic Hard Disks:

Magnetic Hard Disk Drive is a digital data storage device that reads and writes data via magnetization changes of a magnetic storage disk. This includes one or more randomly accessible rotatable storage media, or disks. Nowadays magnetic hard disks are there in market up to terabytes. Yes, a single hard disk drive has that much memory like a big storage server. The first commercial magnetic HDD introduced by IBM in 1956 having 5MB storage. But last year Hitachi introduced 1TB magnetic HDD. This year 2008, Seagate announced 1.5 TB HDD for personal and enterprise purposes. This HDD are having data transfer rate is nearly 16 to 20 Mb/s.

Solid State Disks:

The design of solid-state disk starts with combining the each block like Flash memory, Memory controller, RAM, RAM Controller, Processor and Host etc., M-Systems introduced first flash-based solid-state drives in 1995. (SanDisk acquired M-Systems in November 2006). Since then, flash based SSDs demands high in military and aerospace industries, as well as other mission-critical applications. Nowadays in SSD, Flash is used as a permanent storage and RAM is used as a temporary storage between Flash and processor to increase the performance.

It's very suitable for small hand held systems and note books, because it does not have moving parts, requires less power, Host data transfer rate of up to 3Gb/s and silent operation. Up to 2007 middle only 64GB (Samsung  SanDisk) solid-state drives are there in the market with in the size that is compatible with notebooks. In this year Samsung announces a super-fast 256 GB, 2.5-inch solid-state drive. 'Super Talent' has announced the world's thinnest 256 GB 2.5-inch SSD drive. Toshiba also launched 3 MLC flash SSD families with SATA interfaces.

Optical Disks:

The main uses of optical storage disks are content exchange, backup and archiving and not for primary storage. It's having capacity from 300 MB to 30 GB. Before the evolutions of Optical Storage Disks, the Magnetic floppy disks are used for data exchange and for small storages. Because of the very little storage (1.44 MB) and small life period of floppy, the optical disks had overtaken that. There are four main commercial types of optical disk's are there for present day usage. They are,

oLaser Disks
oCompact Disks (CD)
oDigital Versatile Disks (DVD)
oBlu-Ray Disks (BD)

Laser Disks:

The laserdisc was the first optical storage medium used for commercial purposes, particularly for the movie industry. Paul Gregg invented the laserdisc technology in 1958, making use of a transparent disc. Laserdiscs are famous in 80's for audio songs and although the VHS (Video Home System) cassettes and the CD/DVD format has overtaken the Laserdisc in usage. It looks 30 centimeters in diameter and it is made up of two single-sided discs. Laserdisc is actually an analog format unlike CDs or DVDs which are digital. Now Laser disks doesn't have any market, but still some people are using this to hear old songs.

Compact Disks:

The most common form of optical storage is the Compact Disk (CD). Even with the arrival of other more powerful optical media, CDs remain a popular way for industries to package software, games, music, and movies. These discs provide low-cost and easy-to-use back-up for and physical transfer of data files. Normally compact disks are coming in two ways. One is CD-R (one time write and more number of reads) and CD-RW (More number of read and writes). A standard CD has a capacity of about 74 minutes of standard CD audio music and holds about 700 MB. But actual capacity depends on the format of writing.

Digital Versatile Disks:

This is the improved form of compact disks, commonly known as DVD. It has another expansion like Digital Video Disks also. It also contains DVD-R and DVD-RW separation like the above. A standard DVD offers 4.7 GB (Single Layer) / 8.5 GB (Dual Layer) storage. But it looks similar like CD. We can read/write the CDs in the DVD Writer, but CD writer won't read the DVD.

Blu-Ray Disks:

It is the next-generation optical disks, able to hold high-definition video and other high-density storage. A single-sided Blu-ray disk can hold 25 GB of storage, while a dual-sided one can store 50 GB. The Blu-ray disk's size is similar to that of the CD and the DVD - 120 mm in diameter. It uses 405 nm wavelength of laser, so only it named as a Blu-ray disk. It has 54 Mbps transfer rate is superior to both the CD (150 Kbps) and the DVD's (11.1 Mbps). Blu-ray discs are more expensive and slower to manufacture, mainly used for Game storage like play stations.

RAID:

It is expanded like Redundant Array of Independent Disks. It is a technology that employs the simultaneous use of two or more Hard disk drive to achieve greater levels of performance, reliability, and/or larger data volume sizes. A RAID distributes data across several physical disks. There are three different types of RAID concepts. They are,

oSoftware RAID

oHardware RAID

oFirmware/driver based RAID

Tape Storage: 
The main usage of tape storage is offline storage and backup for primary storage. Today's magnetic tape is most commonly packaged in cartridges and cassettes. Tape drives can be connected to a computer with SCSI commonly and Fibre Channel, FICON, ESCON, parallel port, IDE, SATA, USB, FireWire or other interfaces also. It has the following important benefits.

oIt offers lowest cost per megabyte of all storage media options.

oExtremely high capacity per cartridge.

oPortable

The same like it has some limitations also.

oVery slow operation (both read and write)

oRelatively short operational life compare to other storage media

oSubject to deterioration and environmental hazards

The difference between tape data storage and disk data storage is that tape is an Sequential access medium while disk is a random access medium. Nowadays Tape Storage is used to store data's, which doesn't need, but should have a Backup like Hospital passed away patients record.

Network Attached Storage:

It is commonly known as NAS, used for enterprise storage as a server. These devices contains embedded processors that run some sort of operating system or microprocessors that understands networking protocols and is optimized for particular tasks, such as file service and network backup etc., NAS is an ideal choice for organizations looking for a simple and cost-effective way to achieve fast data access for multiple clients at the file level. Some important benefits of NAS are listed below.

oFiles are easily shared among users at high demand and performance

oFiles are easily accessible by the same user from different locations

oDemand for local storage at the desktop is reduced

oStorage can be added more economically and partitioned among users-Highly scalable

oData can be backed up form the common repository more efficiently than from desktops

oMultiple file servers can be consolidated into a single managed storage pool

Storage Area Network:

It is commonly known as SAN. It is a high performance storage network that transfers data between servers and storage devices, separate from the local area network. For a normal person these two, SAN and NAS are giving big confusion. These two are used as server storage but the main difference is, NAS uses LAN but SAN won't use it. Some advantages of SAN over NAS are listed below.

oSuperior Performance

oReduces Network bottlenecks

oHighly Scalable

oAllows backup of storage devices with minimal impact on production operations

oFlexibility in configuration.

Online Backup:

The above said methods are convenient and quick, and many offer plenty of inexpensive storage space. For Enterprises, the big problem is coming at the time of disaster, hurricane, earthquake, fire occurs, both the computer and the data backup servers could be destroyed. There's also the problem of theft, of course. But online backup services, which save the most critical computer files on a secure, off-site server over the Internet.

Online Backup means remote Backing up Services. That is taking backup via the Internet to a remote location can protect against some worst-case scenarios mentioned above. A drawback of this an Internet connection is usually substantially slower than the speed of local data storage devices and it also has the risk associated with putting control of company secrets data in the hands of a third party.

Share:

PEMBAHASAN UKK TKJ PAKET 3 TAHUN 2017


PEMBAHASAN UKK TKJ PAKET 3 TAHUN 2017
TOPOLOGI


Mengacu kepada topologi di atas yang saya ambil dari soal dan silahkan sesuaikan dengan kondisi kalian sendiri, saya sendiri akan sesuaikan menjadi
IP Kabel : 192.168.100.1/24
IP Nirkabel : 192.168.200.1/24
IP ISP : 172.16.0.45

Konfigurasi MikroTik Gateway

1. Berikan IP address pada setiap ether
/ip address
add address=172.16.0.45/24 interface=ether1 network=172.16.0.0
add address=192.168.100.1/24 interface=ether2 network=192.168.100.0
add address=192.168.200.1/24 interface=wlan1 network=192.168.200.0

2. Buat routing statis yang berfungsi untuk mengarahkan alamat yang tidak terdefinisikan di routing table ke gateway kita tentukan.

/ip route
add distance=1 dst-address=0.0.0.0/0 gateway=172.16.0.1
3. Agar jaringan lokal kita bisa terhubung dengan jaringan publik maka kita membutuhkan fitur NAT atau Network Address Translation.

/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1

4. Agar router bisa melakukan resolve pada domain maka kita harus menambahkan konfigurasi DNS pada router. Silahkan teman-teman sesuaikan dengan DNS yang digunakan oleh ISP, namun jika tidak tahu kita pakai saja DNS dari Google
/ip dns
set allow-remote-requests=yes servers=8.8.8.8,8.8.4.4

5. Seharusnya kalian sudah bisa terhubung ke internet yang menandakan bahwa kita sudah berhasil membuat MikroTik Gateway, silahkan coba dengan ping via terminal di Router atau bisa juga melalui PC tapi jangan lupa sesuaikan IP Address PC nya ya. Contoh pada kasus ini saya menggunakan IP 192.168.100.2 pada PC saya yang terhubung via kabel. ^_^

Blok YouTube

Ada berbagai macam kombinasi untuk memblokir traffic yang melaju ke YouTube. Namun karena pada kondisi ujian saya tidak yakin teman-teman menggunakan versi RouterOS yang sama maka saya menggunakan cara yang bisa digunakan di sebagian besar RouterOS. Caranya adalah dengan menggunakan keyword pada setiap paket yang melalui router.
/ip firewall filter
add action=drop chain=forward content=youtube.com in-interface=ether2 out-interface=ether1
Kalau sudah silahkan buka www.youtube.com melalui browser dan seharusnya tidak bisa dibuka

Wireless

Karena di awal kita sudah melakukan konfigurasi IP address pada wlan1 jadi kita langsung saja mengganti SSID pada wlan1. Untuk cara ceknya silahkan lihat saja di client apakah muncul wireless dengan SSID kamal@hotspot
/interface wireless
set [ find default-name=wlan1 ] disabled=no l2mtu=1600 mode=ap-bridge ssid=kamal@hotspot



Hotspot

1.Untuk Hotspot agar lebih mudah saya gunakan GUI (winbox). Silahkan ke IP > Hotspot
2. Pada bagian ini karena kita sudah buat NAT di awal tadi maka uncheck bagian Masquerade Network

3. Karena pada bagian Hotspot kita sekalian juga set DHCP Server maka silahkan memasukkan Address Pool sesuai dengan soal

4. Karena tidak memiliki sertifikat SSL maka pada bagian ini langsung Next saja
5. Karena tidak memiliki SMTP server jadi biarkan saja dan langsung Next
6. Karena di awal tadi kita sudah gunakan melakukan konfigurasi untuk DNS maka di sini DNS yang kita masukkan langsung ada. Kita bisa tambahkan atau sunting juga tapi mending tidak usah dan biarkan menggunakan yang dari sistem
7. DNS name of local hotspot server adalah domain yang kita gunakan jika ingin membuka portal hotspot, isi sesuai dengan permintaan soal yaitu sekolah.sch.id
8. Terakhir masukkan user untuk login hotspot dan isi juga passwordnya.
9. Sekarang hotspot sudah siap, teman-teman bisa coba dengan mengkoneksikan ke wireless lalu buka browser dan seharusnya ketika ingin mengakses internet harus login terlebih dahulu.

Bypass bsnp-indonesia.org

Ketika kita mengaktifkan fitur hotspot maka seluruh situs akan ditutup (harus login dulu). Bypass itu dimaksudkan agar user yang belum/tidak login bisa mengakes situs yang telah ditentukan. Untuk caranya silahkan lihat di bawah ini

Jika ingin via CLI bisa lihat cara berikut

/ip hotspot walled-garden
add dst-host=bsnp-indonesia.org

Sekarang silahkan akses bsnp-indonesia.org dengan catatan sudah tidak terkoneksi ke internet. Kalian bisa logout terlebih dahulu, jika tidak mau logout silahkan untuk uncheck cache pada bagian di bawah ini dan coba lagi akses bsnp-indonesia.org


Hotspot User

User pada MikroTik berbasis pada User Profile, maka dari itu kita harus buat 2 User Profile terlebih dahulu yaitu Guru dengan bandwidth unlimited dan siste dengan bandwidth upload/download = 256kbps
/ip hotspot user profile
add name=guru shared-users=unlimited transparent-proxy=yes
add name=siswa rate-limit=256/256 shared-users=unlimited transparent-proxy=yes

Setelah itu kita buat user username guru & siswa yang dikaitkan kepada profile masing-masing.
/ip hotspot user
add name=guru password=guru profile=guru
add name=siswa password=siswa profile=siswa
Sekarang silahkan untuk menguji masing-masing user dengan kecepatannya. Jika tidak sesuai pastikan pada bagian user profile sesuai dengan aturan yang diberikan pada soal.

Ubah Tampilan Portal Login

Untuk mengubah tampilan sebenarnya kita tinggal memasukkan dokumen tampilan hotspot ke Router. Dan cara yang paling mudah adalah dengan melakukan click & drag via winbox. Tapi sebelumnya siapkan terlebih dahulu file dan lakukan drag ke FILES. Sebagai contoh di bawah ini saya drag langsung folder login pada direktori atas.



Jika sudah maka kita akan membuat jika ada yang mengakses hotspot portal maka akan diarakan ke tampilan yang berada di direktori login. Silahkan pergi ke IP > Hotspot dan ikut petunjuk di bawah ini dan jika sudah silahkan buka kembali portal login hotspot di browser.



==========================================================================
Share:

Memisahkan Bandwidth International (IX) dan lokal (IIX) via mikrotik


Memisahkan Bandwidth International (IX) dan lokal (IIX) via mikrotik

pertama :

Mikrotik nat untuk user :
/ip firewall nat add action=masquerade chain=srcnat src-address=192.168.1.0/24

kedua :

download Mikrotik file nice.rsc dari openixp
http://ixp.mikrotik.co.id/download/nice.rsc

ketiga :

selanjutnya kita masukin file nice.rsc nya ke Mikrotik
di Mikrotik winbox klik file trus drag file nice.src nya ke winbox file
jadi masuk ke Mikrotik winbox dan setelah selesai klik terminal
ketik

import nice.rsc
cek apakah ip address nice sudah masuk di mikrotik, silahkan cek di Mikrotik ip firewall – address list

ke empat :

Mikrotik Mangle
karena ini NATed network (contoh : 192.168.1.0/24) maka chain mangle nya prerouting
jika routed end2end (contoh : 192.168.1.1/24) maka pake nya forward
klo mau yang gampang tinggal copy paste saja :
Catatan : iix = koneksi untuk indonesia saja dan ix = koneksi untuk international

Mikrotik

chain=forward src-address-list=nice action=mark-connection new-connection-mark=mark-con-iix passthrough=yes
chain=forward dst-address-list=nice action=mark-connection new-connection-mark=mark-con-iix passthrough=yes
chain=forward src-address-list=!nice action=mark-connection new-connection-mark=mark-con-ix passthrough=yes
chain=forward dst-address-list=!nice action=mark-connection new-connection-mark=mark-con-ix passthrough=yes
chain=prerouting connection-mark=mark-con-indonesia action=mark-packet new-packet-mark=indonesia passthrough=yes
chain=prerouting connection-mark=mark-con-overseas action=mark-packet new-packet-mark=international passthrough=yes

perhatiin PASTROUGH nya jangan sampe salah, sesuaikan dengan topologi masing-masing. gunakan Prerouting atau FORWARD

perhatikan di Mikrotik winbox. Untuk memastikan apakah jalur sudah terpisah dengan baik semua traffic harus ketangkep (coba lakukan beberapa koneksi iix dan ix untuk memastikannya, contohnya : masuk ke speedtest.net, untuk test iix pilih jakarta untuk test internasional pilih yang singapore atau amerika sekalian)

buka ip –> firewall —> mangle

jika semua koneksi sudah terbaca di Mikrotik mangle… maka tinggal di seting Mikrotik queue

misalkan :

client 1
dengan ip :
192.168.1.2
mau kita kasi bandwith iix 512kbps internasional 64 kbps
maka :

Mikrotik
/queue simple

add
name=”client1-iix” target-addresses=192.168.100.2/32 dst-address=0.0.0.0/0 interface=all parent=none packet-marks=indonesia direction=both priority=8
queue=default-small/default-small limit-at=0/0 max-limit=512000/512000 total-queue=default-small

name=”client1-int” target-addresses=192.168.100.2/32 dst-address=0.0.0.0/0 interface=all parent=none packet-marks=international direction=both priority=8
queue=default-small/default-small limit-at=0/0 max-limit=64000/64000 total-queue=default-small

client2
dengan ip : 192.168.1.3
hanya di berikan IIX saja sebesar 64 kbps dan tidak di berikan internasional sama sekali..
maka :

kita buat Mikrotik firewall untuk Mikrotik client 2 blokir jalur internasional

[admin@Mikrotik] > ip firewall filter add
chain=forward src-address=192.168.1.3 connection-mark=mark-con-ix action=drop
kemudian coba test dari client2 buka www.yahoo.com
jika tidak terbuka sukses kita memblokir jalur internasional untuk client 2
jika masih kebuka cek lagi configurasi yg kita buat.

setting ini biasanya di gunakan untuk game center yang hanya di beri akses IIX saja

kemudian kita tinggal membatasi untuk IIX saja atau malah buat saja que simple biasa saja karena kita tau bahwa
client 2 mustahil bisa akses internasional

contoh berikut ini beserta rule iix nya :

Mikrotik
/queue simple

add
name=”client2-iix” target-addresses=192.168.1.3/32 dst-address=0.0.0.0/0 interface=all parent=none packet-marks=indonesia direction=both priority=8
queue=default-small/default-small limit-at=0/0 max-limit=64000/64000 total-queue=default-small
jika kita tetap paranoid apabila si client masih bisa akses internasional alias takut bocor (padahal udah ga bisa lagi)
maka tambahin aja queue untuk internasional dengan besar 8 kbps

Mikrotik
/queue simple

add
name=”client2-int” target-addresses=192.168.1.3/32 dst-address=0.0.0.0/0 interface=all parent=none packet-marks=international direction=both priority=8
queue=default-small/default-small limit-at=0/0 max-limit=8/8 total-queue=default-small
contoh selanjut nya untuk client 3
dengan ip 192.168.1.4
dengan besar bandwith 64 kbps.
maka kita buat queue biasa aja :

Mikrotik
/queue simple

add
name=”client3″ target-addresses=192.168.1.4/32 dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8
queue=default-small/default-small limit-at=0/0 max-limit=64000/64000 total-queue=default-small



selesai
yang penting paham prinsipnya.
selanjut nya kembangkan imajinasi sendiri


Share:

Mangle Pisah Download, Upload, Game dan Browsing


Mangle Pisah Download, Upload, Game dan Browsing


Mangle:


GAME POINT BLANK misalnya
contoh buat Point Blank, game lain sesuaikan aja port/ip nya
chain=prerouting action=mark-connection new-connection-mark=Game passthrough=yes protocol=tcp dst-address=203.89.146.0/23 dst-port=39190 comment=”Point Blank”

chain=prerouting action=mark-connection new-connection-mark=Game passthrough=yes protocol=udp dst-address=203.89.146.0/23 dst-port=40000-40010
chain=prerouting action=mark-packet new-packet-mark=Game_pkt passthrough=no connection-mark=Game
chain=prerouting action=jump jump-target=game


POKER

chain=forward action=mark-connection new-connection-mark=Poker_con passthrough=yes protocol=tcp dst-address-list=LOAD POKER comment=”POKER”
chain=forward action=mark-connection new-connection-mark=Poker_con passthrough=yes protocol=tcp content=statics.poker.static.zynga.com
chain=forward action=mark-packet new-packet-mark=Poker passthrough=no connection-mark=Poker_con


BROWSING

chain=forward action=mark-connection new-connection-mark=http passthrough=yes protocol=tcp in-interface=WAN out-interface=Lan packet-mark=!Game_pkt connection-mark=!Game connection-bytes=0-262146 comment=”BROWSE”
chain=forward action=mark-packet new-packet-mark=http_pkt passthrough=no protocol=tcp connection-mark=http


UPLOAD

chain=prerouting action=mark-packet new-packet-mark=Upload passthrough=no protocol=tcp src-address=192.168.0.0/24 in-interface=Lan packet-mark=!icmp_pkt comment=”UPLOAD”


LIMIT DOWNLOAD

chain=forward action=mark-connection new-connection-mark=Download passthrough=yes protocol=tcp in-interface=WAN out-interface=Lan packet-mark=!Game_pkt connection-mark=!Poker_con connection bytes=262146-4294967295 comment=”LIMIT DOWNLOAD”
chain=forward action=mark-packet new-packet-mark=Download_pkt passthrough=no packet-mark=!Game_pk> connection-mark=Download


QUEUE

queue type
name=”Download” kind=pcq pcq-rate=256000 pcq-limit=50 pcq-classifier=dst-address pcq-total-limit=2000
name=”Http” kind=pcq pcq-rate=1M pcq-limit=50 pcq-classifier=dst-address pcq-total-limit=2000
name=”Game” kind=pcq pcq-rate=0 pcq-limit=50 pcq-classifier=src-address,dst-address,src-port,dst-port pcq-total-limit=2000
name=”Upload” kind=pcq pcq-rate=0 pcq-limit=50 pcq-classifier=src-address pcq-total-limit=2000


Queue Tree
name=”Main Browse” parent=Lan limit-at=0 priority=8 max-limit=1M burst-limit=0 burst-threshold=0 burst-time=0s
name=”Browse” parent=Main Browse packet-mark=http_pkt limit-at=0 queue=Http priority=8 max-limit=1M burst-limit=0 burst-threshold=0 burst-time=0s
name=”Game” parent=global-total packet-mark=Game_pkt limit-at=0 queue=Game priority=1 max-limit=0 burst-limit=0 burst-threshold=0 burst-time=0s
name=”Poker” parent=global-out packet-mark=Poker limit-at=0 queue=Game priority=3 max-limit=0 burst-limit=0 burst-threshold=0 burst-time=0s
name=”Download” parent=global-out packet-mark=Download_pkt limit-at=0 queue=Download priority=8 max-limit=256k burst-limit=0 burst-threshold=0 burst-time=0s
name=”Main Upload” parent=global-in limit-at=0 priority=8 max-limit=256k burst-limit=0 burst-threshold=0 burst-time=0s
name=”Upload” parent=Main Upload packet-mark=Upload limit-at=0 queue=Upload priority=8 max-limit=0 burst-limit=0 burst-threshold=0 burst-time=0s

HASILNYA
BROWSING 1Mbs
DOWNLOAD 256Kbps bagi
GAME seadanya bandwith sesuai kebutuhan
POKER seadanya bandwith sesuai kebutuhan
UPLOAD seadanya bandwith bagi rata sesuai kebutuhan






=========================================================================
Game Point Blank Untuk Game lain sesuaikan Port/IP-nya

chain=GAMES
protocol=tcp 6
dst-port=39190
action=mark-connection
new-connection-mark=Game
passthrough=yes
comment=Point Blank


chain=GAMES
protocol=udp 17
dst-port=40000-40010
action=mark-connection
new-connection-mark=Game
passthrough=yes


chain=GAMES
action=mark-packet
new-packet-mark=Game_Akses
passthrough=no
connection-mark=Game


chain=prerouting
action=jump
jump-target=GAMES

===================================

Game Zynga POKER

chain=forward
protocol=tcp
dst-address-list=LOAD POKER
action=mark-connection
new-connection-mark=Poker_Akses
passthrough=yes
comment=POKER


chain=forward
protocol=tcp
content=statics.poker.static.zynga.com
action=mark-connection
new-connection-mark=Poker_Akses
passthrough=yes


chain=forward
connection-mark=Poker_Akses
action=mark-packet
new-packet-mark=Poker
passthrough=no

===================================

Browsing

chain=forward
action=mark-connection
new-connection-mark=HTTP
passthrough=yes
protocol=tcp
in-interface=WAN ( Provider )
out-interface=LOKAL ( ke Client )
packet-mark=!Game_Akses
connection-mark=!GAMES
connection-bytes=0-261024
comment=BROWSING


chain=forward
action=mark-packet
new-packet-mark=http_akses
passthrough=no
protocol=tcp
connection-mark=HTTP

===================================

Upload

chain=prerouting
action=mark-packet
new-packet-mark=Upload
passthrough=no
protocol=tcp
src-address=192.168.0.0/24
in-interface=LOKAL
packet-mark=!icmp_pkt
comment=UPLOAD

===================================

Download Limiter

chain=forward
action=mark-connection
new-connection-mark=Download
passthrough=yes
protocol=tcp
in-interface=WAN
out-interface=LOKAL
packet-mark=!Game_Akses
connection-mark=!Poker_Akses
connection bytes=262146-4294967295
comment=LIMIT DOWNLOAD


chain=forward
action=mark-packet
new-packet-mark=Download_paket
passthrough=no
packet-mark=!Game_Akses
connection-mark=Download

===================================

Queue

queue type

name=Download
kind=pcq pcq-rate=256000
pcq-limit=50
pcq-classifier=dst-address
pcq-total-limit=2000


name=''Http''
kind=pcq
pcq-rate=1M
pcq-limit=50
pcq-classifier=dst-address
pcq-total-limit=2000


name=Games
kind=pcq
pcq-rate=0
pcq-limit=50
pcq-classifier=src-address,dst-address,src-port,dst-port
pcq-total-limit=2000


name=Upload
kind=pcq
pcq-rate=0
pcq-limit=50
pcq-classifier=src-address
pcq-total-limit=2000

===================================

Queue Tree

name=Browsing
parent=LOKAL
limit-at=0
priority=8
max-limit=1M
burst-limit=0
burst-threshold=0
burst-time=0s


name=Browse
parent=Browsing
packet-mark=http_Akses
limit-at=0
queue=Http
priority=8
max-limit=1M
burst-limit=0
burst-threshold=0
burst-time=0s


name=Game
parent=global-total
packet-mark=Game_Akses
limit-at=0
queue=Game
priority=1
max-limit=0
burst-limit=0
burst-threshold=0
burst-time=0s


name=Poker
parent=global-out
packet-mark=Poker
limit-at=0
queue=Game
priority=3
max-limit=0
burst-limit=0
burst-threshold=0
burst-time=0s


name=Download
parent=global-out
packet-mark=Download_Akses
limit-at=0
queue=Download
priority=8
max-limit=256k
burst-limit=0
burst-threshold=0
burst-time=0s


name=Main Upload
parent=global-in
limit-at=0
priority=8
max-limit=256k
burst-limit=0
burst-threshold=0
burst-time=0s


name=Upload
parent=Main Upload
packet-mark=Upload
limit-at=0
queue=Upload
priority=8
max-limit=0
burst-limit=0
burst-threshold=0
burst-time=0s



===================================

IP Firewall Address-list


add address=202.93.20.0/24 list=game
add address=202.93.20.218 list=game
add address=202.93.20.0/24 list=game
add address=202.93.20.172 list=game
add address=209.190.9.202 list=game
add address=75.125.122.98 list=game
add address=202.93.20.215 list=game
add address=209.51.218.170 list=game
add address=122.102.49.0/24 list=game
add address=122.102.49.70 list=game
add address=122.102.49.71 list=game
add address=122.102.49.72 list=game
add address=122.102.49.73 list=game
add address=122.102.49.74 list=game
add address=122.102.49.75 list=game
add address=122.102.49.76 list=game
add address=122.102.49.77 list=game
add address=122.102.49.78 list=game
add address=122.102.49.79 list=game
add address=122.102.49.80 list=game
add address=122.102.48.0/24 list=game
add address=119.110.77.1 list=game
add address=119.110.77.2 list=game
add address=119.110.77.3 list=game
add address=119.110.77.4 list=game
add address=119.110.77.5 list=game
add address=119.110.77.6 list=game
add address=119.110.77.7 list=game
add address=122.102.50.0/24 list=game
add address=122.102.51.0/24 list=game
add address=122.102.52.0/24 list=game
add address=122.102.53.0/24 list=game
add address=122.102.54.0/24 list=game
add address=122.102.55.0/24 list=game
add address=202.93.16.0/24 list=game
add address=202.93.17.0/24 list=game
add address=202.93.18.0/24 list=game
add address=202.93.19.0/24 list=game
add address=202.93.20.0/24 list=game
add address=202.93.21.0/24 list=game
add address=202.93.22.0/24 list=game
add address=202.93.23.0/24 list=game
add address=202.93.24.0/24 list=game
add address=202.93.25.0/24 list=game
add address=202.93.26.0/24 list=game
add address=202.93.27.0/24 list=game
add address=202.93.28.0/24 list=game
add address=202.93.29.0/24 list=game
add address=202.93.30.0/24 list=game
add address=202.93.31.0/24 list=game

Informasi Tambahan :
BROWSING 1Mbs bagi dengan Adil dalam satu jaringan
DOWNLOAD 256Kbps terbagi rata di Jaringan LOKAL
GAME dengan bandwith disesuaikan kebutuhan Client
POKER dengan bandwith disesuaikan kebutuhan Client
UPLOAD seadanya bandwith bagi rata sesuai kebutuhan Client

================================================

Berikut ini data port game online yang menggunakan IIX/koneksi lokal:


1. Ayo Dance : tcp 18901-18909
2. SealOnline : tcp 1818
3. PointBlank : tcp 39190, udp 40000-40010
4. Lineage2 : tcp 7777
5. GhostOnline : tcp 19101
6. RF-Elven : tcp 27780
7. Perfect world : tcp 29000
8. Rohan : tcp 22100
9. Zeus RO : tcp 5121
10. Dotta : tcp 6000-6152
11. IdolStreet : tcp 2001
12. CrazyKart : 9601-9602
13. WOW AMPM : tcp 8085
14. DriftCity : tcp 11011-11041
15. GetAmped : tcp 13413
16. Yullgang : tcp 19000
17. RAN Online : tcp 5105
18. CrossFire : tcp 10009, udp 12060-12070
19. WarRock : tcp 5340-5352
20. FastBlack : tcp 6000-6001
21. Rose Online : tcp 29200
22. Return Of Warrior : tcp 10402
23. CrazyKart 2 : tcp 9600
25. Luna Online : tcp 15002
26. Runes Of Magic : tcp 16402-16502
27. FreshRO : tcp 5126
28. Tantra Online : tcp 3010
29. Heroes Of Newearth Incatamers : tcp 11031 udp 11100-11125,11440-11460
30. Atlantica : tcp 4300 , ip 203.89.147.0/24
31. ECO Online : tcp Port 12011 , 12110
32. Cabal Indo : tcp Port 15001, 15002
33. X-SHOT : tcp 7341,7451 , udp 7808,30000
34. Return Of Warrior : tcp 10402
35. CrazyKart 2 : tcp 9600
36. Luna Online : tcp 15000-15002
37. Runes Of Magic : tcp 16402-16502
38. Fresh Ragnarok PS, www.freshro.org dst address 119.110.87.179 : 5171
39. Tantra Online : tcp 3010
40. Heroes Of Newearth Incatamers chat server -> TCP 11031 game server -> UDP 11100-11125 VOIP -> UDP 11440-11460 (by LOVIAN)
41. Atlantica : tcp 4300 , ip 203.89.147.0/24 link: http://atlantica.gemscool.com/
42. ECO Online --> Port 12011 , 12110 by RB750
43. Cabal Indo --> Port 15001, 15002 by RB750
44. X-SHOT : tcp 7341-7350,7451 , udp 7777-7977,30000
45. 3 Kingdoms : UDP 42051-42052

Sebagai Tambahan untuk di mangle-nya


Download
chain=prerouting action=mark-connection
new-connection-mark=conn download passthrough=yes protocol=tcp
dst-port=80 connection-bytes=175000-4294967295

chain=prerouting action=mark-packet new-packet-mark=cekek bw
passthrough=no protocol=tcp connection-mark=conn download

Browsing
chain=prerouting action=mark-connection
new-connection-mark=conn browsing passthrough=yes protocol=tcp
dst-port=80 content=!statics.poker.static.zynga.com
connection-bytes=0-175000

chain=prerouting action=mark-connection new-connection-mark=conn browsing
passthrough=yes protocol=tcp dst-port=80 connection-bytes=0-175000

chain=prerouting action=mark-packet new-packet-mark=browsing packet
passthrough=no connection-mark=conn browsing connection-bytes=0-175000

Limit IDM
chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.exe

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.mpg

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.avi

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.mov

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.rar

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.zip

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.wav

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.mov

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.wma

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.wmv

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.tiff

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.tif

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.pdf

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.7z

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.3gp

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.mp3

chain=forward action=add-dst-to-address-list protocol=tcp
address-list=cekek address-list-timeout=1h content=.rm

chain=forward action=mark-packet new-packet-mark=jerat bw passthrough=no
protocol=tcp src-address-list=cekek connection-bytes=175000-4294967295

Point Blank
chain=prerouting action=mark-connection new-connection-mark=PB_1
passthrough=yes protocol=udp dst-address=203.89.146.0/23
dst-port=40000-40010

chain=prerouting action=mark-connection new-connection-mark=PB_1
passthrough=yes protocol=tcp dst-address=203.89.146.0/23 dst-port=39190

chain=prerouting action=mark-packet new-packet-mark=PB Oke passthrough=no
connection-mark=PB_1


Zynga Poker
chain=forward action=mark-connection new-connection-mark=Poker conn
passthrough=yes protocol=tcp dst-address-list=Load Game

chain=forward action=mark-connection new-connection-mark=Poker conn
passthrough=yes protocol=tcp content=profile.ak.fbcdn.net

chain=forward action=mark-connection new-connection-mark=Poker conn
passthrough=yes protocol=tcp content=statics.poker.static.zynga.com

chain=forward action=mark-connection new-connection-mark=Poker conn
passthrough=yes protocol=tcp content=apps.facebook.com

chain=forward action=mark-packet new-packet-mark=Poker passthrough=no
connection-mark=Poker conn

Ayo Dance
chain=prerouting action=mark-connection new-connection-mark=Ayo Dance
passthrough=yes protocol=tcp dst-address=122.102.48.0/24
dst-port=18901-18909

chain=prerouting action=mark-packet new-packet-mark=Ayo Dance Oke
passthrough=no connection-mark=Ayo Dance

================================================


Share:

CARA SETTING HOTSPOT MIKROTIK (Pemula)




Setting Hotspot Mikrotik:

Cara mudah setting hotspot pada mikrotik adalah ada 2 pilihan selain menggunakan teks mode kita juga bisa menggunakan setting wizard dengan menggunakan Winbox Router OS, Langkah-langkat berikut merupakan konfigurasi dasar hotspot mikrotik sebagai Gateway Server. Pertama install Mikrotik Router OS pada PC atau pasang DOM atau kalau menggunakan Rouer Board langsung aja Login = ‘admin’ sedangkan untuk pasword anda kosongin untuk defaultnya.
Masuk ke IP ==> Hotspot ==> Setup

Kemudian tentukan IP lokal hospot yang akan ada gunakan, misal 202.148.80.1 dan Tentukan IP DHCP ke clientnya yang akan anda gunakan, dalam contoh ini adalah 202.148.80.11-202.148.80.255

Untuk SMTP Server sebaiknya anda kosongin saja, Kemudian DNS servernya anda isikan sesuaikan dengan Provider anda, dalam contoh ini adalah DNS1=202.134.1.10 DNS2=202.134.0.155


Hotspot Server Profile digunakan untuk mensetting server yang akan sering digunakan untuk semua user seperti metode autentikasi dan Limitasi data rate. Ada 6 jenis autentikasi Hotspot mikrotik yang berbeda dalam profile setting, jenis autentikas tersebut adalah : HTTP PAP, HTTP CHAP, HTTPS, HTTP cookie, MAC address, Trial


Hotspot user profile digunakan untuk menyimpan data user yang akan dibuatkan rule profilenya. Dimana didalamnya bisa dilakukan setting firewall filter chain untuk traffic yang keluar/masuk, juga bisa untuk mensetting limitasi data rate dan selain itu dapat juga dilakukan paket marking untuk setiap user yang masuk kedalam profile tersebut secara otomatis.



MEMBUAT USERMANAGER
1. masuk winbox - new terminal

2. Buat sebuah server Radius
/ radius add service=hotspot address=127.0.0.1 secret=123456

3. Buat profile dan set profile tersebut untuk menggunakan Radius Server
/ ip hotspot profile set hsprof1 use-radius=yes

4. Membuat scriber
/ tool user-manager customer add login="(username login )" password="(password login)" permissions=owner

5. Tambahkan Router kita dalam hal ini localhost.
/ tool user-manager router add subscriber=MikroTik ip-address=127.0.0.1 shared-secret=123456

6. Lalu silahkan browser ke
http://ip routeranda/userman

scrensnya seperti ini


Share:

Translate

Trending

Labels