<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-703198821028820861</id><updated>2011-11-28T07:22:44.039+07:00</updated><title type='text'>Mikrotik - How To</title><subtitle type='html'>A little blog about Mikrotik</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://mikrotik-howto.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/703198821028820861/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://mikrotik-howto.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Akbar</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>7</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-703198821028820861.post-1852735218071691126</id><published>2007-08-23T21:46:00.000+07:00</published><updated>2007-08-23T21:49:00.617+07:00</updated><title type='text'>[Bahasa Indonesia] How To : Melindungi FTP Server Mikrotik Anda</title><content type='html'>&lt;b&gt;&lt;span style="font-size:130%;"&gt;&lt;div align="center"&gt;How To : Melindungi FTP Server Mikrotik Anda&lt;/div&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Artikel singkat ini akan menjelaskan cara untuk melindungi FTP Server Mikrotik anda dari serangan Brute Force.&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Service FTP Server pada Router Mikrotik kita kadang2 tentunya kita perlu jalankan untuk keperluan-keperluan administrasi.&lt;br /&gt;&lt;br /&gt;Tapi, bagaimana bila jika FTP sedang running, ada pihak-pihak yang ingin memanfaatkan FTP pada Router Mikrotik untuk mencoba hal-hal yang membahayakan Jaringan kita. Cara yang paling umum dilakukan untuk hal ini biasanya adalah dengan menggunakan metode Brute Force Attack.&lt;br /&gt;&lt;br /&gt;Brute force attack adalah sebuah teknik serangan terhadap sebuah sistem keamanan komputer yang menggunakan percobaan terhadap semua kunci yang mungkin. Pendekatan ini pada awalnya merujuk pada sebuah program komputer yang mengandalkan kekuatan pemrosesan komputer dibandingkan kecerdasan manusia. (Source : &lt;a href="http://id.wikipedia.org/wiki/Brute_force_attack" target="_blank"&gt;Wikipedia&lt;/a&gt; )&lt;br /&gt;&lt;br /&gt;Hal yang harus dilakukan untuk mencegah hal diatas sebenarnya cukup sederhana. Hanya butuh 3 rule di firewall.&lt;br /&gt;&lt;br /&gt;&lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 162px; text-align: left;"&gt;/ ip firewall filter&lt;br /&gt;add chain=input in-interface=ether1 protocol=tcp dst-port=21 src-address-list=ftp_blacklist action=drop&lt;br /&gt;&lt;br /&gt;# accept 10 incorrect logins per minute&lt;br /&gt;/ ip firewall filter&lt;br /&gt;add chain=output action=accept protocol=tcp content=530 Login incorrect dst-limit=1/1m,9,dst-address/1m&lt;br /&gt;&lt;br /&gt;#add to blacklist&lt;br /&gt;add chain=output action=add-dst-to-address-list protocol=tcp content=530 Login incorrect address-list=ftp_blacklist address-list-timeout=3h&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Ingat, urutan diatas harus tepat...tidak boleh tertukar-tukar...&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Mari kita bahas satu persatu dari rule-rule diatas...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;div style="margin: 5px 20px 20px;"&gt;  &lt;div class="smallfont" style="margin-bottom: 2px;"&gt;Code:&lt;/div&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 50px; text-align: left;"&gt;/ ip firewall filter&lt;br /&gt;add chain=input in-interface=ether1 protocol=tcp dst-port=21 src-address-list=ftp_blacklist action=drop&lt;/pre&gt; &lt;/div&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Rule pertama ini akan melakukan filtering untuk traffik yang berasal dari ether1 (silahkan dirubah sesuai kebutuhan), protocol TCP dengan port 21...dan IP asal traffik dicocokkan dengan addr-list ftp_blacklist (yang akan dicreate di rule berikutnya)....bila cocok / positif maka action drop akan dilakukan...&lt;br /&gt;&lt;br /&gt;Bila ada yang melakukan brute force attack untuk pertama kalinya, rule pertama ini tidak melakukan apa2...Namun apabila IP-nya telah tercatat, maka akan langsung di Drop.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;div style="margin: 5px 20px 20px;"&gt;  &lt;div class="smallfont" style="margin-bottom: 2px;"&gt;Code:&lt;/div&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 66px; text-align: left;"&gt;# accept 10 incorrect logins per minute&lt;br /&gt;/ ip firewall filter&lt;br /&gt;add chain=output action=accept protocol=tcp content=530 Login incorrect dst-limit=1/1m,9,dst-address/1m&lt;/pre&gt; &lt;/div&gt;&lt;/b&gt;&lt;br /&gt;Rule ini bertindak sebagai pengawas, apakah dari IP tertentu telah melakukan Login secara Incorrect sebanyak 9 kali dalam jangka waktu 1 menit....Jadi bila masih dalam batasan 9 kali dalam 1 menit maka masih akan diaccept...Nah apabila telah melampaui 9 kali, maka rule ini tidak akan apply dan akan lanjut ke rule setelahnya yakni...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;div style="margin: 5px 20px 20px;"&gt;  &lt;div class="smallfont" style="margin-bottom: 2px;"&gt;Code:&lt;/div&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 50px; text-align: left;"&gt;#add to blacklist&lt;br /&gt;add chain=output action=add-dst-to-address-list protocol=tcp content=530 Login incorrect address-list=blacklist address-list-timeout=3h&lt;/pre&gt; &lt;/div&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Rule ini akan menambahkan IP sang penyerang ke dalam addr-list bernama &lt;b&gt;ftp_blacklist&lt;/b&gt;...hanya itu yang dilakukan rule ini...&lt;br /&gt;&lt;br /&gt;Nah, pada saat percobaan yang ke-11 serangan ini akan di Drop oleh Rule yang Pertama....&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Sekian artikel singkat ini...Selamat mencoba &lt;img src="http://www.forummikrotik.com/images/smilies/Nouve%20Smiley/Smiley-msn.com-3D-2010.gif" alt="" title=":[thumbsup]" class="inlineimg" border="0" /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/703198821028820861-1852735218071691126?l=mikrotik-howto.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-howto.blogspot.com/feeds/1852735218071691126/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=703198821028820861&amp;postID=1852735218071691126' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/703198821028820861/posts/default/1852735218071691126'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/703198821028820861/posts/default/1852735218071691126'/><link rel='alternate' type='text/html' href='http://mikrotik-howto.blogspot.com/2007/08/bahasa-indonesia-how-to-melindungi-ftp.html' title='[Bahasa Indonesia] How To : Melindungi FTP Server Mikrotik Anda'/><author><name>Akbar</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-703198821028820861.post-5765700557765810509</id><published>2007-08-18T19:33:00.000+07:00</published><updated>2007-08-18T19:39:51.610+07:00</updated><title type='text'>[bahasa indonesia]Cara Buat ISP Yang Gampang dan Cepat Pake Mikrotik + Squid box</title><content type='html'>Source : http://www.forummikrotik.com/showthread.php?t=251&lt;br /&gt;Written By : &lt;a href="http://www.forummikrotik.com/member.php?u=52"&gt;d3v4&lt;/a&gt;&lt;br /&gt;topologi jaringan adalah sebagai berikut :&lt;br /&gt;&lt;br /&gt;inet -- cisco --hub -- Squid (slackware) -- mikrotik (bw managr) -- client&lt;br /&gt;......................|&lt;br /&gt;......................|&lt;br /&gt;......................|-- server lain nya&lt;br /&gt;&lt;br /&gt;&lt;b&gt; IP ADDRESS SESUAIKAN DENGAN YANG DI MILIKI &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;blok ip yang di dapat adalah : 202.152.100.0/24&lt;br /&gt;&lt;br /&gt;syarat dasar pemahaman :&lt;br /&gt;1. ip subnetting&lt;br /&gt;2. perintah dasar linux&lt;br /&gt;3. perintah dasar mikrotik&lt;br /&gt;&lt;br /&gt;Langkah2...&lt;br /&gt;&lt;br /&gt;&lt;b&gt;1. Liat ip address cisco nya&lt;/b&gt; (asumsi menggunakan FO)&lt;br /&gt;ip address cisco s0/0 202.152.30.1&lt;br /&gt;netmask 255.255.255.252&lt;br /&gt;gateway 202.152.30.2&lt;br /&gt;&lt;br /&gt;(biasanya di dapat dari ISP yang di atas isp kita)&lt;br /&gt;&lt;br /&gt;&lt;b&gt;2. Memecah blok ip address yang kita dapat :&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;sebelum blok ip address yang kita miliki kita gunakan ada baik nya di pecah dulu. pada contoh berikut akan saya berikan untuk di bagi menjadi 2. BLOK IP SERVER dan blok ip CLIENT.&lt;br /&gt;&lt;br /&gt;BLOK IP SERVER2 :&lt;br /&gt;network : 202.152.100.0/28&lt;br /&gt;ip yang dapat di gunakan  :202.152.100.1 - 202.152.100.14&lt;br /&gt;broadcast : 202.152.100.15&lt;br /&gt;&lt;br /&gt;BLOK IP CLIENT :&lt;br /&gt;selain yang di atas adalah ip yang dapat di gunakan untuk client.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;3. SET IP ETHERNET CISCO&lt;/b&gt;&lt;br /&gt;set ip cisco ethernet0/0&lt;br /&gt;ip address : 202.152.100.1&lt;br /&gt;netmask 255.255.255.240&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;4. &lt;b&gt;setting Proxy server + TUNE UP &lt;/b&gt;:&lt;br /&gt;Linux yang di gunakan adalah SLACKWARE 9 dapat di download di :&lt;br /&gt;&lt;a href="http://mirror.vip.net.id/pub/slackware/" target="_blank"&gt;http://mirror.vip.net.id/pub/slackware/&lt;/a&gt;&lt;br /&gt;yang di gunakan adalah :&lt;br /&gt;komputer P4&lt;br /&gt;HARD DISK 40 G seagate baracuda 7200 rpm 3 keping dengan RAM 2 G&lt;br /&gt;keping hardisk pertama di mount ke /&lt;br /&gt;keping hardisk ke 2 di mount ke /cache1&lt;br /&gt;keping hard disk ke 3 di mount ke /cache2&lt;br /&gt;&lt;br /&gt;setelah di install isikan ip address berikut :&lt;br /&gt;&lt;br /&gt;&lt;b&gt;interface eth0&lt;/b&gt;&lt;br /&gt;ip address : 202.152.100.2&lt;br /&gt;netmask 255.255.255.240&lt;br /&gt;gateway 202.152.100.1&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Interface eth1&lt;/b&gt;&lt;br /&gt;ip address : 202.152.100.17&lt;br /&gt;netmask 255.255.255.252&lt;br /&gt;&lt;br /&gt;setelah itu ...&lt;br /&gt;&lt;br /&gt;buka file : type.h&lt;br /&gt;root@proxy:~# vi  /usr/include/bits/types.h&lt;br /&gt;edit bagian ini :&lt;br /&gt;&lt;br /&gt;#define __FD_SETSIZE    1024&lt;br /&gt;&lt;br /&gt;jadi seperti ini&lt;br /&gt;&lt;br /&gt;#define __FD_SETSIZE    8192&lt;br /&gt;&lt;br /&gt;==&gt; kemudian keluar dari VI EDITOR&lt;br /&gt;&lt;br /&gt;kemudian ketik perintah ini :&lt;br /&gt;&lt;br /&gt;root@proxy:~# ulimit -HSn 8192&lt;br /&gt;&lt;br /&gt;kemudian download squid 2.5.STABLE9 dari sini :&lt;br /&gt;&lt;br /&gt;wget &lt;a href="http://202.154.183.7/squid-2.5.STABLE9.tar.gz" target="_blank"&gt;http://202.154.183.7/squid-2.5.STABLE9.tar.gz&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;simpan di direktori /usr/local/src&lt;br /&gt;&lt;br /&gt;ekstrak dengan perintah :&lt;br /&gt;&lt;br /&gt;tar -zxvf squid-2.5.STABLE9.tar.gz&lt;br /&gt;&lt;br /&gt;masuk kedirektori squid&lt;br /&gt;ketik perintah berikut ini :&lt;br /&gt;&lt;br /&gt;./configure \&lt;br /&gt;--prefix=/opt/squid \&lt;br /&gt;--exec-prefix=/opt/squid \&lt;br /&gt;--enable-gnuregex \&lt;br /&gt;--enable-async-io=30 \&lt;br /&gt;--with-aufs-threads=30 \&lt;br /&gt;--with-pthreads \&lt;br /&gt;--with-aio \&lt;br /&gt;--with-dl \&lt;br /&gt;--enable-storeio=aufs \&lt;br /&gt;--enable-removal-policies=heap \&lt;br /&gt;--enable-icmp \&lt;br /&gt;--disable-wccp \&lt;br /&gt;--enable-snmp \&lt;br /&gt;--enable-cache-digests \&lt;br /&gt;--enable-default-err-languages=English \&lt;br /&gt;--enable-err-languages=English \&lt;br /&gt;--enable-linux-netfilter \&lt;br /&gt;--disable-ident-lookups \&lt;br /&gt;--disable-hostname-checks \&lt;br /&gt;--enable-underscores&lt;br /&gt;&lt;br /&gt;karena udah ada mikrotik untuk bw management tidak di perlukan lagi delay pool. Konfigurasi ini adalah untuk komputer dengan spek seperti berikut :&lt;br /&gt;&lt;br /&gt;HARDISK 3 keping 40 G seagate baracuda 7200 rpm, RAM 2 G&lt;br /&gt;&lt;br /&gt;2 keping hard disk untuk cache, 1 keping untuk system. apabila menggunakan hard disk scsi --enable-async-io=30 --with-aufs-threads=30 bisa di naekkan jadi 32.&lt;br /&gt;&lt;br /&gt;==&gt; selesai install squid. semua file squid akan terletak di direktori /opt/squid&lt;br /&gt;&lt;br /&gt;setelah itu gunakan squid.conf di bawah ini :&lt;br /&gt;&lt;br /&gt;&lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 498px; text-align: left;"&gt;http_port 8080&lt;br /&gt;acl youtube dstdomain .youtube.com&lt;br /&gt;no_cache allow youtube&lt;br /&gt;hierarchy_stoplist cgi-bin ? localhost .js .jsp .friendster.com&lt;br /&gt;acl QUERY urlpath_regex cgi-bin \? localhost   .friendster.com&lt;br /&gt;no_cache deny QUERY&lt;br /&gt;cache_replacement_policy heap LFUDA&lt;br /&gt;memory_replacement_policy heap GDSF&lt;br /&gt;cache_mem 6 MB&lt;br /&gt;cache_dir aufs /cache1 8000 13 256&lt;br /&gt;cache_dir aufs /cache2 8000 13 256&lt;br /&gt;cache_swap_low 98&lt;br /&gt;cache_swap_high 99&lt;br /&gt;cache_access_log /cache1/access.log&lt;br /&gt;cache_log /dev/null&lt;br /&gt;cache_store_log none&lt;br /&gt;mime_table /opt/squid/etc/mime.conf&lt;br /&gt;pid_filename /var/run/squid.pid&lt;br /&gt;client_netmask 255.255.255.0&lt;br /&gt;refresh_pattern ^ftp: 10080 95% 241920 reload-into-ims override-lastmod&lt;br /&gt;refresh_pattern . 180 95% 120960 reload-into-ims override-lastmod&lt;br /&gt;redirect_rewrites_host_header off&lt;br /&gt;acl all src 0.0.0.0/0.0.0.0&lt;br /&gt;acl manager proto cache_object&lt;br /&gt;acl localnet src 202.152.100.0/255.255.255.0&lt;br /&gt;acl localhost src 127.0.0.1/255.255.255.255&lt;br /&gt;acl SSL_ports port 443 8443 563 777&lt;br /&gt;acl Safe_ports port 25 80 81 110 443 563 6667 7000 777 210 119 70 21 1025-65535&lt;br /&gt;acl Safe_ports port 280 6668 6669&lt;br /&gt;acl Safe_ports port 488&lt;br /&gt;acl Safe_ports port 591&lt;br /&gt;acl Safe_ports port 777&lt;br /&gt;acl lewat dst_as 4622 4761 4787 4795 4796 4855 4800 7587 7597 7713 9326 9340 9448 9657 9791 9794 9875 9905 9228 9251 10114 10137 10208 10217 17440 17450 17451 17538 17658 17671 17670  17725  17727  17769  4832 4833 17817 17884 17907  17910  17922  17800  10220  17974  17826  17885  18052  18056  18059  7632 4821  18103  17996  18004  18153  18156  18189  18237  18251  18347  3583    3382    4382 4434 18364 18365  18379  9341    9785    18393  17995  23651  23666  23671  23679  23691  23756  23945  24052  24057  24194&lt;br /&gt;always_direct allow lewat&lt;br /&gt;always_direct deny all&lt;br /&gt;#header_access Accept-Encoding deny all&lt;br /&gt;acl CONNECT method CONNECT&lt;br /&gt;http_access allow manager localhost&lt;br /&gt;http_access deny manager&lt;br /&gt;http_access allow localnet&lt;br /&gt;http_access allow localhost&lt;br /&gt;http_access deny !Safe_ports&lt;br /&gt;http_access deny CONNECT !SSL_ports&lt;br /&gt;http_access deny CONNECT&lt;br /&gt;httpd_accel_host virtual&lt;br /&gt;httpd_accel_port 80&lt;br /&gt;httpd_accel_with_proxy on&lt;br /&gt;httpd_accel_uses_host_header on&lt;br /&gt;http_access deny all&lt;br /&gt;maximum_object_size  128 MB&lt;br /&gt;maximum_object_size_in_memory 8 KB&lt;br /&gt;ipcache_size 4096&lt;br /&gt;ipcache_low 98&lt;br /&gt;ipcache_high 99&lt;br /&gt;quick_abort_min 0&lt;br /&gt;quick_abort_max 0&lt;br /&gt;quick_abort_pct 75&lt;br /&gt;fqdncache_size 4096&lt;br /&gt;shutdown_lifetime 10 seconds&lt;br /&gt;cache_mgr hendraarif@yahoo.com&lt;br /&gt;cache_effective_user squid&lt;br /&gt;cache_effective_group squid&lt;br /&gt;memory_pools off&lt;br /&gt;buffered_logs off&lt;br /&gt;log_icp_queries off&lt;br /&gt;logfile_rotate 1&lt;br /&gt;log_fqdn off&lt;br /&gt;forwarded_for off&lt;br /&gt;icp_hit_stale on&lt;br /&gt;query_icmp on&lt;br /&gt;reload_into_ims on&lt;br /&gt;emulate_httpd_log off&lt;br /&gt;negative_ttl 2 minutes&lt;br /&gt;pipeline_prefetch on&lt;br /&gt;vary_ignore_expire on&lt;br /&gt;half_closed_clients off&lt;br /&gt;high_page_fault_warning 2&lt;br /&gt;visible_hostname proxy@dodol.org&lt;br /&gt;nonhierarchical_direct on&lt;br /&gt;prefer_direct off&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;perhatikan ip address yang di izinkan. sesuaikan dengan ip yang di gunakan.&lt;br /&gt;perhatikan juga penggunaan cache direktori. maksimal untuk 1 keping adalah 18 Giga.&lt;br /&gt;&lt;br /&gt;setelah itu tambahkan user squid di linux :&lt;br /&gt;&lt;br /&gt;root@proxy:~# useradd squid&lt;br /&gt;&lt;br /&gt;tambahkan juga group squid&lt;br /&gt;&lt;br /&gt;root@proxy:~# groupadd squid&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;bentuk direktori cache di squid :&lt;br /&gt;&lt;br /&gt;root@proxy:~# /opt/squid/sbin/squid -z&lt;br /&gt;&lt;br /&gt;ketik perintah ini sekali lagi :&lt;br /&gt;&lt;br /&gt;root@proxy:~# ulimit -HSn 8192&lt;br /&gt;&lt;br /&gt;kemudian jalankan squid dengan perintah :&lt;br /&gt;&lt;br /&gt;root@proxy:~# /opt/squid/sbin/squid -DY &amp;&lt;br /&gt;&lt;br /&gt;==================================================  ==============&lt;br /&gt;&lt;br /&gt;okeee.. kita lanjut :&lt;br /&gt;&lt;br /&gt;5. Setting mikrotik :&lt;br /&gt;&lt;br /&gt;masukin ip address ether 1 :&lt;br /&gt;/ip address add address=202.152.100.18/30 interface=ether1&lt;br /&gt;&lt;br /&gt;karena seluruh ip yang di gunakan adalah ip public maka perlu subnetting di pisah-pisah :&lt;br /&gt;masukin ip address untuk pasangan ip client :&lt;br /&gt;misalkan ip client adalah 202.152.100.22 maka yang di masukkan di mikrotik ethr2 adalah 202.152.100.21/30&lt;br /&gt;&lt;br /&gt;demikian pula untuk pasangan ip client2 yang lain.&lt;br /&gt;&lt;br /&gt;/ip address add address=202.152.100.21/30 interface=ether2&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;untuk lebih jelasnya dapat di liat pada tablel berikut :&lt;br /&gt;&lt;div style="margin: 5px 20px 20px;"&gt;  &lt;div class="smallfont" style="margin-bottom: 2px;"&gt;Code:&lt;/div&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 498px; text-align: left;"&gt;   network      first avail           last avail         broadcast&lt;br /&gt;202.152.100.20 202.152.100.21 202.152.100.22 202.152.100.23&lt;br /&gt;202.152.100.24 202.152.100.25 202.152.100.26 202.152.100.27&lt;br /&gt;202.152.100.28 202.152.100.29 202.152.100.30 202.152.100.31&lt;br /&gt;202.152.100.32 202.152.100.33 202.152.100.34 202.152.100.35&lt;br /&gt;202.152.100.36 202.152.100.37 202.152.100.38 202.152.100.39&lt;br /&gt;202.152.100.40 202.152.100.41 202.152.100.42 202.152.100.43&lt;br /&gt;202.152.100.44 202.152.100.45 202.152.100.46 202.152.100.47&lt;br /&gt;202.152.100.48 202.152.100.49 202.152.100.50 202.152.100.51&lt;br /&gt;202.152.100.52 202.152.100.53 202.152.100.54 202.152.100.55&lt;br /&gt;202.152.100.56 202.152.100.57 202.152.100.58 202.152.100.59&lt;br /&gt;202.152.100.60 202.152.100.61 202.152.100.62 202.152.100.63&lt;br /&gt;202.152.100.64 202.152.100.65 202.152.100.66 202.152.100.67&lt;br /&gt;202.152.100.68 202.152.100.69 202.152.100.70 202.152.100.71&lt;br /&gt;202.152.100.72 202.152.100.73 202.152.100.74 202.152.100.75&lt;br /&gt;202.152.100.76 202.152.100.77 202.152.100.78 202.152.100.79&lt;br /&gt;202.152.100.80 202.152.100.81 202.152.100.82 202.152.100.83&lt;br /&gt;202.152.100.84 202.152.100.85 202.152.100.86 202.152.100.87&lt;br /&gt;202.152.100.88 202.152.100.89 202.152.100.90 202.152.100.91&lt;br /&gt;202.152.100.92 202.152.100.93 202.152.100.94 202.152.100.95&lt;br /&gt;202.152.100.96 202.152.100.97 202.152.100.98 202.152.100.99&lt;br /&gt;202.152.100.100 202.152.100.101 202.152.100.102 202.152.100.103&lt;br /&gt;202.152.100.104 202.152.100.105 202.152.100.106 202.152.100.107&lt;br /&gt;202.152.100.108 202.152.100.109 202.152.100.110 202.152.100.111&lt;br /&gt;202.152.100.112 202.152.100.113 202.152.100.114 202.152.100.115&lt;br /&gt;202.152.100.116 202.152.100.117 202.152.100.118 202.152.100.119&lt;br /&gt;202.152.100.120 202.152.100.121 202.152.100.122 202.152.100.123&lt;br /&gt;202.152.100.124 202.152.100.125 202.152.100.126 202.152.100.127&lt;br /&gt;202.152.100.128 202.152.100.129 202.152.100.130 202.152.100.131&lt;br /&gt;202.152.100.132 202.152.100.133 202.152.100.134 202.152.100.135&lt;br /&gt;202.152.100.136 202.152.100.137 202.152.100.138 202.152.100.139&lt;br /&gt;202.152.100.140 202.152.100.141 202.152.100.142 202.152.100.143&lt;br /&gt;202.152.100.144 202.152.100.145 202.152.100.146 202.152.100.147&lt;br /&gt;202.152.100.148 202.152.100.149 202.152.100.150 202.152.100.151&lt;br /&gt;202.152.100.152 202.152.100.153 202.152.100.154 202.152.100.155&lt;br /&gt;202.152.100.156 202.152.100.157 202.152.100.158 202.152.100.159&lt;br /&gt;202.152.100.160 202.152.100.161 202.152.100.162 202.152.100.163&lt;br /&gt;202.152.100.164 202.152.100.165 202.152.100.166 202.152.100.167&lt;br /&gt;202.152.100.168 202.152.100.169 202.152.100.170 202.152.100.171&lt;br /&gt;202.152.100.172 202.152.100.173 202.152.100.174 202.152.100.175&lt;br /&gt;202.152.100.176 202.152.100.177 202.152.100.178 202.152.100.179&lt;br /&gt;202.152.100.180 202.152.100.181 202.152.100.182 202.152.100.183&lt;br /&gt;202.152.100.184 202.152.100.185 202.152.100.186 202.152.100.187&lt;br /&gt;202.152.100.188 202.152.100.189 202.152.100.190 202.152.100.191&lt;br /&gt;202.152.100.192 202.152.100.193 202.152.100.194 202.152.100.195&lt;br /&gt;202.152.100.196 202.152.100.197 202.152.100.198 202.152.100.199&lt;br /&gt;202.152.100.200 202.152.100.201 202.152.100.202 202.152.100.203&lt;br /&gt;202.152.100.204 202.152.100.205 202.152.100.206 202.152.100.207&lt;br /&gt;202.152.100.208 202.152.100.209 202.152.100.210 202.152.100.211&lt;br /&gt;202.152.100.212 202.152.100.213 202.152.100.214 202.152.100.215&lt;br /&gt;202.152.100.216 202.152.100.217 202.152.100.218 202.152.100.219&lt;br /&gt;202.152.100.220 202.152.100.221 202.152.100.222 202.152.100.223&lt;br /&gt;202.152.100.224 202.152.100.225 202.152.100.226 202.152.100.227&lt;br /&gt;202.152.100.228 202.152.100.229 202.152.100.230 202.152.100.231&lt;br /&gt;202.152.100.232 202.152.100.233 202.152.100.234 202.152.100.235&lt;br /&gt;202.152.100.236 202.152.100.237 202.152.100.238 202.152.100.239&lt;br /&gt;202.152.100.240 202.152.100.241 202.152.100.242 202.152.100.243&lt;br /&gt;202.152.100.244 202.152.100.245 202.152.100.246 202.152.100.247&lt;br /&gt;202.152.100.248 202.152.100.249 202.152.100.250 202.152.100.251&lt;br /&gt;202.152.100.252 202.152.100.253 202.152.100.254 202.152.100.255&lt;/pre&gt; &lt;/div&gt;kemudian masukan gateway nya ke arah proxy :&lt;br /&gt;&lt;br /&gt;/route add gateway=202.152.100.17&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;atur route di proxy &lt;/b&gt;agar mengizinkan network end mikrotik dapat lewat :&lt;br /&gt;&lt;br /&gt;route add -net 202.152.100.16/30 gateway 202.154.183.18&lt;br /&gt;&lt;br /&gt;selesai urusan ip address...&lt;br /&gt;&lt;br /&gt;6. &lt;b&gt;dapat di uji coba client &lt;/b&gt;&lt;br /&gt;menggunakan ip address :&lt;br /&gt;202.152.100.22&lt;br /&gt;netmask 255.255.255.252&lt;br /&gt;gateway 202.152.100.21&lt;br /&gt;&lt;br /&gt;karena menggunakan subnetting selain ip address 22 tidak akan dapat melewati router mikrotik yang di buat&lt;br /&gt;&lt;br /&gt;7. &lt;b&gt; iptables di proxy &lt;/b&gt;&lt;br /&gt;semua traffic harus di paksa lewat proxy server yang kita buat dengan perintah :&lt;br /&gt;&lt;br /&gt;&lt;div style="margin: 5px 20px 20px;"&gt;  &lt;div class="smallfont" style="margin-bottom: 2px;"&gt;Code:&lt;/div&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 34px; text-align: left;"&gt;iptables -A PREROUTING -t nat -p tcp -s 202.152.100.0/24 -i eth2 -d \! 202.152.100.0/24 --dport 80 -j REDIRECT --to 8080&lt;/pre&gt; &lt;/div&gt;9. &lt;b&gt; DNS SERVER &lt;/b&gt;&lt;br /&gt;jalankan dns server yang telah ada secara defaul di slackware dengan perintah :&lt;br /&gt;&lt;br /&gt;root@proxy:~# named -d1&lt;br /&gt;&lt;br /&gt;tinggal masukin di /etc/resolv.conf&lt;br /&gt;&lt;br /&gt;nameserver 127.0.0.1&lt;br /&gt;&lt;br /&gt;dan seluruh client pake dns ip 202.152.100.18&lt;br /&gt;&lt;br /&gt;TANPA NAT/MASQUERADE .................. ip public terdistribusi ke client&lt;br /&gt;&lt;br /&gt;jadi deeeehhhhhh gampang dan cepat kan ?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/703198821028820861-5765700557765810509?l=mikrotik-howto.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-howto.blogspot.com/feeds/5765700557765810509/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=703198821028820861&amp;postID=5765700557765810509' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/703198821028820861/posts/default/5765700557765810509'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/703198821028820861/posts/default/5765700557765810509'/><link rel='alternate' type='text/html' href='http://mikrotik-howto.blogspot.com/2007/08/bahasa-indonesiacara-buat-isp-yang.html' title='[bahasa indonesia]Cara Buat ISP Yang Gampang dan Cepat Pake Mikrotik + Squid box'/><author><name>Akbar</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-703198821028820861.post-5393276896222097475</id><published>2007-08-18T19:00:00.000+07:00</published><updated>2007-08-18T19:01:16.326+07:00</updated><title type='text'>How To : Creating a Transparent Web Proxy</title><content type='html'>&lt;p&gt;Web proxy allows clients to make indirect network connections to other network services. A client connects to the proxy server, then requests file, or other resource available on a different server. Web proxy performs Internet object cache function by storing requested Internet objects, i.e., data available via HTTP and FTP protocols on a system positioned closer to the recipient than the site the data is originated from. Transparent proxy performs request caching invisibly to the end-user. This way the user does not notice that his connection is being processed by the proxy and therefore does not need to perform any additional configuration of the software he is using. To setup transparent proxy follow the steps listed bellow &lt;/p&gt;&lt;p&gt;1. Configure the router to redirect all connections coming from clients (we assume that clients are connected to routers ether1 interface) to port 80 to the web proxy listening on port 8080, by adding the following destination NAT rule: &lt;/p&gt; &lt;pre&gt;[admin@MikroTik] &gt;ip firewall nat add in-interface=ether1 dst-port=80 \&lt;br /&gt;\... protocol=tcp action=redirect to-ports=8080 chain=dstnat&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;2. Specify DNS server: &lt;/p&gt; &lt;pre&gt;[admin@MikroTik] ip dns set primary-dns=195.2.96.2&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;3. Enable the proxy on port 8080: &lt;/p&gt; &lt;pre&gt;[admin@MikroTik] ip web-proxy set enabled=yes port=8080 transparent-proxy=yes&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;Notice that only HTTP traffic is supported in transparent mode of the web proxy. HTTPS and FTP protocols are not going to work this way. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/703198821028820861-5393276896222097475?l=mikrotik-howto.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-howto.blogspot.com/feeds/5393276896222097475/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=703198821028820861&amp;postID=5393276896222097475' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/703198821028820861/posts/default/5393276896222097475'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/703198821028820861/posts/default/5393276896222097475'/><link rel='alternate' type='text/html' href='http://mikrotik-howto.blogspot.com/2007/08/how-to-creating-transparent-web-proxy.html' title='How To : Creating a Transparent Web Proxy'/><author><name>Akbar</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-703198821028820861.post-1772505521062279922</id><published>2007-08-17T21:12:00.001+07:00</published><updated>2007-08-17T21:14:53.455+07:00</updated><title type='text'>How to limit traffic from Rapidshare</title><content type='html'>You can use this little script to get an IP from Rapidshare...This script will look into the DNS cache, and everytime the word rapidshare comes out, it will place the IP it get to a address list, then after that you can config a queue rule to limit the traffic...&lt;br /&gt;&lt;br /&gt;:foreach i in=[/ip dns cache find] do={&lt;br /&gt;  :if ([:find [/ip dns cache get $i name] "rapidshare"] &gt; 0) do={&lt;br /&gt;    :log info ("rapidshare: " . [/ip dns cache get $i name] . " (ip address " . [/ip dns cache get $i address] . ")")&lt;br /&gt;    /ip firewall address-list add address=[/ip dns cache get $i address] list=rapidshare disabled=no&lt;br /&gt;  }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;Source : http://forum.mikrotik.com/viewtopic.php?p=84349#p84349&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/703198821028820861-1772505521062279922?l=mikrotik-howto.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-howto.blogspot.com/feeds/1772505521062279922/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=703198821028820861&amp;postID=1772505521062279922' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/703198821028820861/posts/default/1772505521062279922'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/703198821028820861/posts/default/1772505521062279922'/><link rel='alternate' type='text/html' href='http://mikrotik-howto.blogspot.com/2007/08/how-to-limit-traffic-from-rapidshare.html' title='How to limit traffic from Rapidshare'/><author><name>Akbar</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-703198821028820861.post-5085408378717708590</id><published>2007-08-17T21:03:00.002+07:00</published><updated>2007-08-17T21:04:21.314+07:00</updated><title type='text'>Free Level 6 Mikrotik License</title><content type='html'>&lt;b&gt;normis :&lt;/b&gt;&lt;br /&gt;...who uploads MikroTik related videos to the &lt;a href="http://www.tiktube.com/" target="_blank"&gt;http://www.TikTube.com&lt;/a&gt; video system. Any video directly related with MikroTik stuff will do. We will evaluate your video, and you will receive a free license!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://forum.mikrotik.com/viewtopic.php?f=2&amp;amp;t=17521" target="_blank"&gt;&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/703198821028820861-5085408378717708590?l=mikrotik-howto.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-howto.blogspot.com/feeds/5085408378717708590/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=703198821028820861&amp;postID=5085408378717708590' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/703198821028820861/posts/default/5085408378717708590'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/703198821028820861/posts/default/5085408378717708590'/><link rel='alternate' type='text/html' href='http://mikrotik-howto.blogspot.com/2007/08/free-level-6-mikrotik-license.html' title='Free Level 6 Mikrotik License'/><author><name>Akbar</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-703198821028820861.post-2494186925828660639</id><published>2007-08-17T21:03:00.001+07:00</published><updated>2007-08-17T21:03:20.740+07:00</updated><title type='text'>How to Block a Customer and Tell him to Pay the Bill</title><content type='html'>&lt;p&gt;Sometimes you may need to cut off a customer and tell him to pay his bill. It's best done by redirecting his http requests to a page with information telling to pay in order to get reconnected. You can do it with a simple destination NAT rule that captures all http requests from a specific address and sends them to a server with webpage telling to pay the bill. However, it's quite easy to make this using the HotSpot feature of RouterOS. Please note that this don't work with PPPoE connections. &lt;/p&gt;&lt;p&gt;To make this setup, you should have Hotspot package enabled on the RouterOS. This example will cover how to block customer's computer. When he tries to open a webpage he would be redirected to the hotspot page which will contain info that he hasn't paid the bill for the Internet access. Your router should have already been configured and working (customer should have access to the Internet), you should have the DNS server specified in the router. &lt;/p&gt;&lt;p&gt;First you should edit the Hotspot login.html page with the text that contains information that will be shown to the customers who haven't paid their bills. It could be something like this: "Service not available, please pay the bill and contact us by phone to get reconnected". This page can be found within the hotspot folder of RouterOS. &lt;/p&gt;&lt;p&gt;Next, add an ip-binding rule that will allow all customers to bypass the hotspot page. It is done using such a command: &lt;/p&gt; &lt;pre&gt;/ip hotspot ip-binding add type=bypassed address=0.0.0.0/0 \&lt;br /&gt;comment="bypass the hotspot for all the paying customers"&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;After that add the Hotspot server on the interface where your clients are connected. It can be done using such command: &lt;/p&gt; &lt;pre&gt;/ip hotspot add interface=local disabled=no&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;Now you can add ip-binding rules for the customers that haven't paid their bill. You can match them by IP address or MAC address. Here is an example using MAC address: &lt;/p&gt; &lt;pre&gt;/ip hotspot ip-binding add mac-address=00:0C:42:00:00:90 type=regular comment "Non paying client 1"&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;Now we have such configuration: &lt;/p&gt; &lt;pre&gt;[admin@MikroTik] ip hotspot ip-binding&gt; print&lt;br /&gt;Flags: X - disabled, P - bypassed, B - blocked&lt;br /&gt;#   MAC-ADDRESS       ADDRESS                         TO-ADDRESS      SERVER&lt;br /&gt;0 P ;;; bypass the hotspot for all the paying customers&lt;br /&gt;                     0.0.0.0/0&lt;br /&gt;1   ;;; Non paying client 1&lt;br /&gt;   00:0C:42:00:00:90&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;There is one more step to make it work, you should change the order of these rules, the first rule should be above the bypass rule so it could be processed. You can move it using move command: &lt;/p&gt; &lt;pre&gt;[admin@MikroTik] ip hotspot ip-binding&gt; move 1 0&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;Now the ip-binding configuration should look like this: &lt;/p&gt; &lt;pre&gt;[admin@MikroTik] ip hotspot ip-binding&gt; print&lt;br /&gt;Flags: X - disabled, P - bypassed, B - blocked&lt;br /&gt;#   MAC-ADDRESS       ADDRESS                         TO-ADDRESS      SERVER&lt;br /&gt;0   ;;; Non paying client 1&lt;br /&gt;   00:0C:42:00:00:90&lt;br /&gt;1 P ;;; bypass the hotspot for all the paying customers&lt;br /&gt;                     0.0.0.0/0&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;If the customers can pay their bill using internet you can modify the login.html by adding some links to clients bank web-page where they can pay their bill. After you add these links in the login page you should also add them in the hotspot configuration so the blocked customer could access that page. This can be done in the 'ip hotspot walled-garden ip' menu. Here is an example: &lt;/p&gt; &lt;pre&gt;/ip hotspot walled-garden ip add dst-host=www.paypal.com&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/703198821028820861-2494186925828660639?l=mikrotik-howto.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-howto.blogspot.com/feeds/2494186925828660639/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=703198821028820861&amp;postID=2494186925828660639' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/703198821028820861/posts/default/2494186925828660639'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/703198821028820861/posts/default/2494186925828660639'/><link rel='alternate' type='text/html' href='http://mikrotik-howto.blogspot.com/2007/08/how-to-block-customer-and-tell-him-to.html' title='How to Block a Customer and Tell him to Pay the Bill'/><author><name>Akbar</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-703198821028820861.post-8731472610829028410</id><published>2007-08-17T20:56:00.000+07:00</published><updated>2007-08-17T21:02:24.406+07:00</updated><title type='text'>Drop port scanners</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://wiki.mikrotik.com/wiki/Image:Arp_add_hosts.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px;" src="http://wiki.mikrotik.com/wiki/Image:Arp_add_hosts.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;To protect the Router from port scanners, we can record the IPs of hackers who try to scan your box. Using this address list we can drop connection from those IP &lt;/p&gt;&lt;p&gt;in &lt;b&gt;/ip firewall filter&lt;/b&gt; &lt;/p&gt;&lt;br /&gt;&lt;pre&gt;add chain=input protocol=tcp psd=21,3s,3,1 action=add-src-to-address-list address-list="port scanners"&lt;br /&gt;address-list-timeout=2w comment="Port scanners to list " disabled=no&lt;/pre&gt;&lt;br /&gt;Various combinations of TCP flags can also indicate port scanner activity.&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;add chain=input protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg&lt;br /&gt;action=add-src-to-address-list address-list="port scanners"&lt;br /&gt;address-list-timeout=2w comment="NMAP FIN Stealth scan"&lt;br /&gt;&lt;/pre&gt; &lt;pre&gt;add chain=input protocol=tcp tcp-flags=fin,syn&lt;br /&gt;action=add-src-to-address-list address-list="port scanners"&lt;br /&gt;address-list-timeout=2w comment="SYN/FIN scan"&lt;br /&gt;&lt;/pre&gt; &lt;pre&gt;add chain=input protocol=tcp tcp-flags=syn,rst&lt;br /&gt;action=add-src-to-address-list address-list="port scanners"&lt;br /&gt;address-list-timeout=2w comment="SYN/RST scan"&lt;br /&gt;&lt;/pre&gt; &lt;pre&gt;add chain=input protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack&lt;br /&gt;action=add-src-to-address-list address-list="port scanners"&lt;br /&gt;address-list-timeout=2w comment="FIN/PSH/URG scan"&lt;br /&gt;&lt;/pre&gt; &lt;pre&gt;add chain=input protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg&lt;br /&gt;action=add-src-to-address-list address-list="port scanners"&lt;br /&gt;address-list-timeout=2w comment="ALL/ALL scan"&lt;br /&gt;&lt;/pre&gt; &lt;pre&gt;add chain=input protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg&lt;br /&gt;action=add-src-to-address-list address-list="port scanners"&lt;br /&gt;address-list-timeout=2w comment="NMAP NULL scan"&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;Then you can drop those IPs:&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;add chain=input src-address-list="port scanners" action=drop comment="dropping port scanners" disabled=no&lt;/pre&gt;Similarly, you can drop these port scanners in the forward chain, but using the above rules with "chain=forward".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/703198821028820861-8731472610829028410?l=mikrotik-howto.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-howto.blogspot.com/feeds/8731472610829028410/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=703198821028820861&amp;postID=8731472610829028410' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/703198821028820861/posts/default/8731472610829028410'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/703198821028820861/posts/default/8731472610829028410'/><link rel='alternate' type='text/html' href='http://mikrotik-howto.blogspot.com/2007/08/drop-port-scanners.html' title='Drop port scanners'/><author><name>Akbar</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
