<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6028699343644528576</id><updated>2011-11-27T15:37:41.383-08:00</updated><category term='Wireless'/><category term='VPN'/><category term='Routing'/><category term='Script'/><category term='Firewall'/><category term='QOS'/><category term='Video'/><title type='text'>Mikrotik routers, Links and Resources</title><subtitle type='html'>Network, Router and wireless</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>29</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-5878289109198687616</id><published>2008-04-24T09:48:00.000-07:00</published><updated>2008-04-24T09:50:05.436-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Routing'/><title type='text'>Load Balancing Persistent</title><content type='html'>Quick Start for Impatient&lt;br /&gt;&lt;br /&gt;Configuration export from the gateway router:&lt;br /&gt;&lt;br /&gt;'''/ ip address''' &lt;br /&gt;add address=192.168.0.1/24 network=192.168.0.0 broadcast=192.168.0.255 interface=Local &lt;br /&gt;add address=10.111.0.2/24 network=10.111.0.0 broadcast=10.111.0.255 interface=wlan2&lt;br /&gt;add address=10.112.0.2/24 network=10.112.0.0 broadcast=10.112.0.255 interface=wlan1&lt;br /&gt;&lt;br /&gt;'''/ ip firewall mangle''' &lt;br /&gt;add chain=prerouting src-address-list=odd in-interface=Local action=mark-connection \&lt;br /&gt;  new-connection-mark=odd passthrough=yes &lt;br /&gt;add chain=prerouting src-address-list=odd in-interface=Local action=mark-routing \&lt;br /&gt;  new-routing-mark=odd passthrough=no&lt;br /&gt;add chain=prerouting src-address-list=even in-interface=Local action=mark-connection \&lt;br /&gt;  new-connection-mark=even passthrough=yes &lt;br /&gt;add chain=prerouting src-address-list=even in-interface=Local action=mark-routing \&lt;br /&gt;  new-routing-mark=even passthrough=no&lt;br /&gt;add chain=prerouting in-interface=Local connection-state=new nth=1,1,0 \ &lt;br /&gt;    action=mark-connection new-connection-mark=odd passthrough=yes&lt;br /&gt;add chain=prerouting in-interface=Local action=add-src-to-address-list \&lt;br /&gt;  address-list=odd address-list-timeout=1d connection-mark=odd passthrough=yes &lt;br /&gt;add chain=prerouting in-interface=Local connection-mark=odd action=mark-routing \ &lt;br /&gt;    new-routing-mark=odd passthrough=no&lt;br /&gt;add chain=prerouting in-interface=Local connection-state=new nth=1,1,1 \ &lt;br /&gt;    action=mark-connection new-connection-mark=even passthrough=yes&lt;br /&gt;add chain=prerouting in-interface=Local action=add-src-to-address-list \&lt;br /&gt;  address-list=even address-list-timeout=1d connection-mark=even passthrough=yes &lt;br /&gt;add chain=prerouting in-interface=Local connection-mark=even action=mark-routing \ &lt;br /&gt;    new-routing-mark=even passthrough=no&lt;br /&gt;&lt;br /&gt;'''/ ip firewall nat''' &lt;br /&gt;add chain=srcnat connection-mark=odd action=src-nat to-addresses=10.111.0.2 \&lt;br /&gt;    to-ports=0-65535 &lt;br /&gt;add chain=srcnat connection-mark=even action=src-nat to-addresses=10.112.0.2 \&lt;br /&gt;    to-ports=0-65535 &lt;br /&gt;&lt;br /&gt;'''/ ip route''' &lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.111.0.1 scope=255 target-scope=10 routing-mark=odd&lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.112.0.1 scope=255 target-scope=10 routing-mark=even &lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.112.0.1 scope=255 target-scope=10 &lt;br /&gt;&lt;br /&gt;[edit] Explanation&lt;br /&gt;&lt;br /&gt;First we give a code snippet and then explain what it actually does.&lt;br /&gt;[edit] IP Addresses&lt;br /&gt;&lt;br /&gt;/ ip address &lt;br /&gt;add address=192.168.0.1/24 network=192.168.0.0 broadcast=192.168.0.255 interface=Local&lt;br /&gt;add address=10.111.0.2/24 network=10.111.0.0 broadcast=10.111.0.255 interface=wlan2 &lt;br /&gt;add address=10.112.0.2/24 network=10.112.0.0 broadcast=10.112.0.255 interface=wlan1 &lt;br /&gt;&lt;br /&gt;The router has two upstream (WAN) interfaces with the addresses of 10.111.0.2/24 and 10.112.0.2/24. The LAN interface has the name "Local" and IP address of 192.168.0.1/24.&lt;br /&gt;[edit] Mangle&lt;br /&gt;&lt;br /&gt;/ ip firewall mangle &lt;br /&gt;add chain=prerouting src-address-list=odd in-interface=Local action=mark-connection \&lt;br /&gt;  new-connection-mark=odd passthrough=yes &lt;br /&gt;add chain=prerouting src-address-list=odd in-interface=Local action=mark-routing \&lt;br /&gt;  new-routing-mark=odd &lt;br /&gt;&lt;br /&gt;All traffic from customers having their IP address previously placed in the address list "odd" is instantly marked with connection and routing marks "odd". Afterwards the traffic is excluded from processing against successive mangle rules in prerouting chain.&lt;br /&gt;&lt;br /&gt;/ ip firewall mangle &lt;br /&gt;add chain=prerouting src-address-list=even in-interface=Local action=mark-connection \&lt;br /&gt;  new-connection-mark=even passthrough=yes &lt;br /&gt;add chain=prerouting src-address-list=even in-interface=Local action=mark-routing \&lt;br /&gt;  new-routing-mark=even &lt;br /&gt;&lt;br /&gt;Same stuff as above, only for customers having their IP address previously placed in the address list "even".&lt;br /&gt;&lt;br /&gt;/ ip firewall mangle &lt;br /&gt;add chain=prerouting in-interface=Local connection-state=new nth=1,1,0 \ &lt;br /&gt;    action=mark-connection new-connection-mark=odd passthrough=yes&lt;br /&gt;add chain=prerouting in-interface=Local action=add-src-to-address-list \&lt;br /&gt;  address-list=odd address-list-timeout=1d connection-mark=odd passthrough=yes &lt;br /&gt;add chain=prerouting in-interface=Local connection-mark=odd action=mark-routing \ &lt;br /&gt;    new-routing-mark=odd passthrough=no&lt;br /&gt;&lt;br /&gt;First we take every second packet that establishes new session (note connection-state=new), and mark it with connection mark "odd". Consequently all successive packets belonging to the same session will carry the connection mark "odd". Note that we are passing these packets to the second and third rules (passthrough=yes). Second rule adds IP address of the client to the address list to enable all successive sessions to go through the same gateway. Third rule places the routing mark "odd" on all packets that belong to the "odd" connection and stops processing all other mangle rules for these packets in prerouting chain.&lt;br /&gt;&lt;br /&gt;/ ip firewall mangle &lt;br /&gt;add chain=prerouting in-interface=Local connection-state=new nth=1,1,1 \ &lt;br /&gt;    action=mark-connection new-connection-mark=even passthrough=yes&lt;br /&gt;add chain=prerouting in-interface=Local action=add-src-to-address-list \&lt;br /&gt;  address-list=even address-list-timeout=1d connection-mark=even passthrough=yes &lt;br /&gt;add chain=prerouting in-interface=Local connection-mark=even action=mark-routing \ &lt;br /&gt;    new-routing-mark=even passthrough=no&lt;br /&gt;&lt;br /&gt;These rules do the same for the remaining half of the traffic as the first three rules for the first half of the traffic.&lt;br /&gt;&lt;br /&gt;The code above effectively means that each new connection initiated through the router from the local network will be marked as either "odd" or "even" with both routing and connection marks.&lt;br /&gt;&lt;br /&gt;The above works fine. There are however some situations where you might find that the same IP address is listed under both the ODD and EVEN scr-address-lists. This behavior causes issues with apps that require persistent connections. A simple remedy for this situation is to add the following statement to your mangle rules:&lt;br /&gt;&lt;br /&gt;add chain=prerouting in-interface=Local connection-state=new nth=1,1,1 \ &lt;br /&gt;    src-address-list=!odd action=mark-connection new-connection-mark=even \&lt;br /&gt;    passthrough=yes&lt;br /&gt;&lt;br /&gt;This will ensure that the new connection will not already be part of the ODD src-address-list. You will have to do the same for the ODD mangle rule thus excluding IP's already part of the EVEN scr-address-list.&lt;br /&gt;[edit] NAT&lt;br /&gt;&lt;br /&gt;/ ip firewall nat &lt;br /&gt;add chain=srcnat connection-mark=odd action=src-nat to-addresses=10.111.0.2 \&lt;br /&gt;    to-ports=0-65535 &lt;br /&gt;add chain=srcnat connection-mark=even action=src-nat to-addresses=10.112.0.2 \&lt;br /&gt;    to-ports=0-65535&lt;br /&gt;&lt;br /&gt;All traffic marked "odd" is being NATted to source IP address of 10.111.0.2, while traffic marked "even" gets "10.112.0.2" source IP address.&lt;br /&gt;[edit] Routing&lt;br /&gt;&lt;br /&gt;/ ip route &lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.111.0.1 scope=255 target-scope=10 routing-mark=odd &lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.112.0.1 scope=255 target-scope=10 routing-mark=even&lt;br /&gt;&lt;br /&gt;For all traffic marked "odd" (consequently having 10.111.0.2 translated source address) we use 10.111.0.1 gateway. In the same manner all traffic marked "even" is routed through the 10.112.0.1 gateway.&lt;br /&gt;&lt;br /&gt;/ ip route&lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.112.0.1 scope=255 target-scope=10&lt;br /&gt;&lt;br /&gt;Finally, we have one additional entry specifying that traffic from the router itself (the traffic without any routing marks) should go to 10.112.0.1 gateway. &lt;br /&gt;&lt;br /&gt;source:http://wiki.mikrotik.com/wiki/Load_Balancing_Persistent&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-5878289109198687616?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/5878289109198687616/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=5878289109198687616' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/5878289109198687616'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/5878289109198687616'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/04/load-balancing-persistent.html' title='Load Balancing Persistent'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-3509151626759373828</id><published>2008-04-24T09:44:00.000-07:00</published><updated>2008-04-24T09:47:15.445-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Routing'/><title type='text'>Two gateways failover with load balancing</title><content type='html'>Route&lt;br /&gt;&lt;br /&gt;According to the examples above, you have:&lt;br /&gt;&lt;br /&gt;/ ip route &lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.111.0.1 scope=255 target-scope=10 routing-mark=odd  &lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.112.0.1 scope=255 target-scope=10 routing-mark=even  &lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.112.0.1 scope=255 target-scope=10&lt;br /&gt;&lt;br /&gt;Now you have to change these lines to:&lt;br /&gt;&lt;br /&gt;/ ip route &lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.111.0.1 scope=255 target-scope=10 routing-mark=odd check-gateway=ping &lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.112.0.1 scope=255 target-scope=10 routing-mark=even check-gateway=ping &lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.112.0.1 scope=255 target-scope=10&lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.111.0.1 scope=255 target-scope=10 distance=2&lt;br /&gt;&lt;br /&gt;If ping fails to 10.111.0.1, then all traffic marked odd go's to the gateway 10.112.0.1, the oposite is also true.&lt;br /&gt;&lt;br /&gt;All local traffic go's to the 10.112.0.1 as it's distance is smaller, if 10.112.0.1 fails, then 10.111.0.1 takes over.&lt;br /&gt;&lt;br /&gt;The router pings gateway every 10 seconds and if to consecutive pings to the gateway fail, the route is considered dead. So, then testing keep in mind, that gateway failure is detected in 20 to 30 seconds.&lt;br /&gt;[edit] NAT&lt;br /&gt;&lt;br /&gt;/ ip firewall nat &lt;br /&gt;add chain=srcnat connection-mark=odd action=src-nat to-addresses=10.111.0.2 \&lt;br /&gt;    to-ports=0-65535 comment="" disabled=no &lt;br /&gt;add chain=srcnat connection-mark=even action=src-nat to-addresses=10.112.0.2 \&lt;br /&gt;    to-ports=0-65535 comment="" disabled=no &lt;br /&gt;&lt;br /&gt;change to:&lt;br /&gt;&lt;br /&gt;/ip firewall nat &lt;br /&gt;add chain=srcnat src-address=192.168.0.0/24 action=masquerade&lt;br /&gt;&lt;br /&gt;source:http://wiki.mikrotik.com/wiki/Two_gateways_failover_with_load_balancing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-3509151626759373828?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/3509151626759373828/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=3509151626759373828' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/3509151626759373828'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/3509151626759373828'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/04/two-gateways-failover-with-load.html' title='Two gateways failover with load balancing'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-8410402201933113968</id><published>2008-04-11T05:21:00.000-07:00</published><updated>2008-04-11T05:37:55.001-07:00</updated><title type='text'>Memisahkan gateway traffic Local dan International</title><content type='html'>/ ip address&lt;br /&gt;add address=203.89.24.66/27 network=203.89.24.64 broadcast=203.89.24.95 \&lt;br /&gt;interface=ether1 comment=”ip point to point utk traffic lnternational” \&lt;br /&gt;disabled=no&lt;br /&gt;add address=203.89.24.178/30 network=203.89.24.176 broadcast=203.89.24.179 \&lt;br /&gt;interface=ether1 comment=”ip point to point utk traffic local” disabled=no&lt;br /&gt;/ ip firewall address-list&lt;br /&gt;add list=nice address=58.65.240.0/23 comment=”” disabled=no&lt;br /&gt;add list=nice address=58.65.242.0/23 comment=”” disabled=no&lt;br /&gt;add list=nice address=58.65.244.0/23 comment=”” disabled=no&lt;br /&gt;add list=nice address=58.65.246.0/23 comment=”” disabled=no&lt;br /&gt;add list=nice address=58.145.174.0/24 comment=”” disabled=no&lt;br /&gt;add list=nice address=58.147.184.0/24 comment=”” disabled=no&lt;br /&gt;add list=nice address=58.147.185.0/24 comment=”” disabled=no&lt;br /&gt;dst…&lt;br /&gt;&lt;br /&gt;/ ip firewall mangle&lt;br /&gt;add chain=postrouting dst-address-list=nice action=mark-routing \&lt;br /&gt;new-routing-mark=nice passthrough=yes comment=”” disabled=no &lt;br /&gt;&lt;br /&gt;/ ip route&lt;br /&gt;add dst-address=0.0.0.0/0 gateway=203.89.24.65 scope=255 target-scope=10 \&lt;br /&gt;comment=”traffic selain local Indonesia” disabled=no&lt;br /&gt;add dst-address=0.0.0.0/0 gateway=203.89.24.177 scope=255 target-scope=10 \&lt;br /&gt;routing-mark=nice comment=”traffic local Indonesia” disabled=no&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-8410402201933113968?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/8410402201933113968/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=8410402201933113968' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/8410402201933113968'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/8410402201933113968'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/04/memisahkan-gateway-traffic-local-dan.html' title='Memisahkan gateway traffic Local dan International'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-8502044089520449889</id><published>2008-03-08T11:59:00.000-08:00</published><updated>2008-03-08T12:04:11.690-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VPN'/><title type='text'>EoIP</title><content type='html'>Quick Setup Guide&lt;br /&gt;&lt;br /&gt;To make an EoIP tunnel between 2 routers which have IP addresses 10.5.8.1 and 10.1.0.1:&lt;br /&gt;&lt;br /&gt;   1.&lt;br /&gt;&lt;br /&gt;      On router with IP address 10.5.8.1, add an EoIP interface and set its MAC address:&lt;br /&gt;&lt;br /&gt;      /interface eoip add remote-address=10.1.0.1 tunnel-id=1 mac-address=00-00-5E-80-00-01 \&lt;br /&gt;      \... disabled=no&lt;br /&gt;&lt;br /&gt;   2.&lt;br /&gt;&lt;br /&gt;      On router with IP address 10.1.0.1, add an EoIP interface and set its MAC address::&lt;br /&gt;&lt;br /&gt;      /interface eoip add remote-address=10.5.8.1 tunnel-id=1 mac-address=00-00-5E-80-00-02 \&lt;br /&gt;      \... disabled=no&lt;br /&gt;&lt;br /&gt;Now you can add IP addresses to the created EoIP interfaces from the same subnet.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;EoIP Application Example&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.mikrotik.com/testdocs/ros/3.0/img/eoip.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px;" src="http://www.mikrotik.com/testdocs/ros/3.0/img/eoip.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;To make a secure Ethernet bridge between two routers you should:&lt;br /&gt;&lt;br /&gt;   1.&lt;br /&gt;&lt;br /&gt;      Create a PPTP tunnel between them. Our_GW will be the pptp server:&lt;br /&gt;&lt;br /&gt;      [admin@Our_GW] interface pptp-server&gt; /ppp secret add name=joe service=pptp \&lt;br /&gt;      \... password=top_s3 local-address=10.0.0.1 remote-address=10.0.0.2&lt;br /&gt;      [admin@Our_GW] interface pptp-server&gt; add name=from_remote user=joe&lt;br /&gt;      [admin@Our_GW] interface pptp-server&gt; server set enable=yes&lt;br /&gt;      [admin@Our_GW] interface pptp-server&gt; print&lt;br /&gt;      Flags: X - disabled, D - dynamic, R - running&lt;br /&gt;       #     NAME         USER         MTU        CLIENT-AD... UPTIME   ENCODING&lt;br /&gt;       0     from_remote  joe&lt;br /&gt;      [admin@Our_GW] interface pptp-server&gt;&lt;br /&gt;&lt;br /&gt;      The Remote router will be the pptp client: &lt;br /&gt;&lt;br /&gt;      [admin@Remote] interface pptp-client&gt; add name=pptp user=joe \&lt;br /&gt;      \... connect-to=192.168.1.1 password=top_s3 mtu=1500 mru=1500&lt;br /&gt;      [admin@Remote] interface pptp-client&gt; enable pptp&lt;br /&gt;      [admin@Remote] interface pptp-client&gt; print&lt;br /&gt;      Flags: X - disabled, R - running&lt;br /&gt;        0  R name="pptp" mtu=1500 mru=1500 connect-to=192.168.1.1 user="joe"&lt;br /&gt;             password="top_s2" profile=default add-default-route=no&lt;br /&gt;&lt;br /&gt;      [admin@Remote] interface pptp-client&gt; monitor pptp&lt;br /&gt;            status: "connected"&lt;br /&gt;            uptime: 39m46s&lt;br /&gt;          encoding: "none"&lt;br /&gt;&lt;br /&gt;      [admin@Remote] interface pptp-client&gt;&lt;br /&gt;&lt;br /&gt;      See the PPTP Interface Manual for more details on setting up encrypted channels.&lt;br /&gt;   2.&lt;br /&gt;&lt;br /&gt;      Configure the EoIP tunnel by adding the eoip tunnel interfaces at both routers. Use the ip addresses of the pptp tunnel interfaces when specifying the argument values for the EoIP tunnel:&lt;br /&gt;&lt;br /&gt;      [admin@Our_GW] interface eoip&gt; add name="eoip-remote" tunnel-id=0 \&lt;br /&gt;      \... remote-address=10.0.0.2&lt;br /&gt;      [admin@Our_GW] interface eoip&gt; enable eoip-remote&lt;br /&gt;      [admin@Our_GW] interface eoip&gt; print&lt;br /&gt;      Flags: X - disabled, R - running&lt;br /&gt;        0    name=eoip-remote mtu=1500 arp=enabled remote-address=10.0.0.2 tunnel-id=0&lt;br /&gt;      [admin@Our_GW] interface eoip&gt;&lt;br /&gt;&lt;br /&gt;      [admin@Remote] interface eoip&gt; add name="eoip" tunnel-id=0 \&lt;br /&gt;      \... remote-address=10.0.0.1&lt;br /&gt;      [admin@Remote] interface eoip&gt; enable eoip-main&lt;br /&gt;      [admin@Remote] interface eoip&gt; print&lt;br /&gt;      Flags: X - disabled, R - running&lt;br /&gt;        0   name=eoip mtu=1500 arp=enabled remote-address=10.0.0.1 tunnel-id=0&lt;br /&gt;&lt;br /&gt;      [Remote] interface eoip&gt;&lt;br /&gt;&lt;br /&gt;   3.&lt;br /&gt;&lt;br /&gt;      Enable bridging between the EoIP and Ethernet interfaces on both routers.&lt;br /&gt;&lt;br /&gt;      On the Our_GW:&lt;br /&gt;&lt;br /&gt;      [admin@Our_GW] interface bridge&gt; add &lt;br /&gt;      [admin@Our_GW] interface bridge&gt; print&lt;br /&gt;      Flags: X - disabled, R - running&lt;br /&gt;       0  R name="bridge1" mtu=1500 arp=enabled mac-address=00:00:00:00:00:00 &lt;br /&gt;            protocol-mode=none priority=0x8000 auto-mac=yes &lt;br /&gt;            admin-mac=00:00:00:00:00:00 max-message-age=20s forward-delay=15s &lt;br /&gt;            transmit-hold-count=6 ageing-time=5m &lt;br /&gt;      [admin@Our_GW] interface bridge&gt; port add bridge=bridge1 interface=eoip-remote&lt;br /&gt;      [admin@Our_GW] interface bridge&gt; port add bridge=bridge1 interface=office-eth&lt;br /&gt;      [admin@Our_GW] interface bridge&gt; port print&lt;br /&gt;      Flags: X - disabled, I - inactive, D - dynamic&lt;br /&gt;       #    INTERFACE      BRIDGE  PRIORITY PATH-COST&lt;br /&gt;       0    eoip-remote    bridge1 128      10&lt;br /&gt;       1    office-eth     bridge1 128      10&lt;br /&gt;      [admin@Our_GW] interface bridge&gt;&lt;br /&gt;&lt;br /&gt;      And the same for the Remote:&lt;br /&gt;&lt;br /&gt;      [admin@Remote] interface bridge&gt; add &lt;br /&gt;      [admin@Remote] interface bridge&gt; print&lt;br /&gt;      Flags: X - disabled, R - running&lt;br /&gt;       0  R name="bridge1" mtu=1500 arp=enabled mac-address=00:00:00:00:00:00 &lt;br /&gt;            protocol-mode=none priority=0x8000 auto-mac=yes &lt;br /&gt;            admin-mac=00:00:00:00:00:00 max-message-age=20s forward-delay=15s &lt;br /&gt;            transmit-hold-count=6 ageing-time=5m &lt;br /&gt;      [admin@Remote] interface bridge&gt; port add bridge=bridge1 interface=ether&lt;br /&gt;      [admin@Remote] interface bridge&gt; port add bridge=bridge1 interface=eoip-main&lt;br /&gt;      [admin@Remote] interface bridge&gt; port print&lt;br /&gt;      Flags: X - disabled, I - inactive, D - dynamic&lt;br /&gt;       #    INTERFACE      BRIDGE  PRIORITY PATH-COST&lt;br /&gt;       0    ether          bridge1 128      10&lt;br /&gt;       1    eoip-main      bridge1 128      10     &lt;br /&gt;      [admin@Remote] interface bridge&gt;&lt;br /&gt;&lt;br /&gt;   4. Addresses from the same network can be used both in the Office LAN and in the Remote LAN. &lt;br /&gt;&lt;br /&gt;source: http://www.mikrotik.com/testdocs/ros/3.0/vpn/eoip.php&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-8502044089520449889?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/8502044089520449889/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=8502044089520449889' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/8502044089520449889'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/8502044089520449889'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/03/eoip.html' title='EoIP'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-6086909749357879460</id><published>2008-03-02T02:56:00.000-08:00</published><updated>2008-03-02T02:57:44.284-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Routing'/><title type='text'>Routing Questions</title><content type='html'>Question: How does /ip route check-gateway work?&lt;br /&gt;&lt;br /&gt;check-gateway sends pings every 10 seconds. if two successive pings fail, the gateway is considered dead.&lt;br /&gt;Question: I have one /24 network advertised to two BGP peers using "/routing bgp networks" facility. How do I advertise a higher path cost to one of the peers?&lt;br /&gt;&lt;br /&gt;You have to change the way you are redistributing your network, as filters are not applied to routes advertised from "/routing bgp networks". In most cases the network is connected directly to your router, so it's enough to set BGP instance to redistribute directly connected routes:&lt;br /&gt;&lt;br /&gt;/routing bgp instance set default redistribute-connected=yes&lt;br /&gt;&lt;br /&gt;    To filter out all other connected networks except the needed one, create a routing filter for the BGP instance, &lt;br /&gt;&lt;br /&gt;/routing filter add invert-match=yes prefix=10.0.0.0/24 action=discard name=InstanceOutFilter&lt;br /&gt;&lt;br /&gt;    then set filter "InstanceOutFilter" as the out-filter for "default" BGP instance. &lt;br /&gt;&lt;br /&gt;/routing bgp instance set default out-filter=InstanceOutFilter&lt;br /&gt;&lt;br /&gt;    To communicate a lower preference value (higher path cost) to one of the peers, you have to prepend your AS number multiple times to the BGP AS_PATH attribute &lt;br /&gt;&lt;br /&gt;/routing filter add prefix=10.0.0.0/24 set-bgp-prepend=4 name=Peer1OutFilter&lt;br /&gt;/routing bgp peer set Peer1 out-filter=Peer1OutFilter&lt;br /&gt;&lt;br /&gt;Question: I have a /22 (say 10.0.0.0/22) assigned IP space, split internally down into /30's, /28's, etc. Is it possible just to announce the /22 space via BGP with routing-test package?&lt;br /&gt;&lt;br /&gt;Yes, it is possible. Do the following:&lt;br /&gt;&lt;br /&gt;    1. add an empty bridge interface: &lt;br /&gt;&lt;br /&gt;/interface bridge add name=loopback&lt;br /&gt;&lt;br /&gt;    2. assign a /22 address to the bridge interface: &lt;br /&gt;&lt;br /&gt;/ip address add address=10.0.0.1/22 interface=loopback&lt;br /&gt;&lt;br /&gt;    3. create a routing filter that filters out all prefixes except the /22 one &lt;br /&gt;&lt;br /&gt;/routing filter add invert-match=yes prefix=10.0.0.0/22 prefix-length=22 action=discard name=myfilter&lt;br /&gt;&lt;br /&gt;    4. set filter "myfilter" as the out-filter for "default" BGP instance &lt;br /&gt;&lt;br /&gt;/routing bgp instance set default out-filter=myfilter&lt;br /&gt;&lt;br /&gt;Question: How to blackhole a network?&lt;br /&gt;&lt;br /&gt;There are two ways to blackhole a network. First, you can do this manually by adding a blackhole route to the routing table, for example, to blackhole a 10.0.0.0/8 network, issue the following command:&lt;br /&gt;&lt;br /&gt;/ip route add dst-address=10.0.0.0/8 kernel-type=blackhole&lt;br /&gt;&lt;br /&gt;Routing filters are the other mean to blackhole a network. To create a routing filter that automatically blackholes all prefixes in 10.0.0.0/8 in the BGP feed, issue the following command:&lt;br /&gt;&lt;br /&gt;/routing filter add prefix=10.0.0.0/8 prefix-length=8-32 set-kernel-type=blackhole chain=myfilter&lt;br /&gt;&lt;br /&gt;Question: How to filter out the default route from outgoing BGP advertisements?&lt;br /&gt;&lt;br /&gt;Assuming you have a static default route that is redistributed because redistribute-static parameter is set to yes, do the following:&lt;br /&gt;&lt;br /&gt;/routing filter add chain=myfilter prefix=0.0.0.0/0 action=discard&lt;br /&gt;&lt;br /&gt;Then set myfilter as the out-filter for BGP instance&lt;br /&gt;&lt;br /&gt;/routing bgp instance set default out-filter=myfilter&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-6086909749357879460?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/6086909749357879460/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=6086909749357879460' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/6086909749357879460'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/6086909749357879460'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/03/routing-questions.html' title='Routing Questions'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-5861223011227732987</id><published>2008-02-28T04:22:00.000-08:00</published><updated>2008-02-28T04:24:10.351-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Video'/><title type='text'>Mikrotik simple/basic manual for biginers</title><content type='html'>&lt;span&gt;Mikrotik simple/basic manual for biginers&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;object width="425" height="355"&gt;&lt;param name="movie" value="http://www.youtube.com/v/f3-7QtaYeGk"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/f3-7QtaYeGk" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-5861223011227732987?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/5861223011227732987/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=5861223011227732987' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/5861223011227732987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/5861223011227732987'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/mikrotik-simplebasic-manual-for.html' title='Mikrotik simple/basic manual for biginers'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-177280743846859352</id><published>2008-02-27T09:35:00.000-08:00</published><updated>2008-02-27T09:38:13.327-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='QOS'/><title type='text'>Transparent Traffic Shaper</title><content type='html'>&lt;p&gt;This example shows how to configure a transparent traffic shaper. The transparent traffic shaper is essentially a bridge that is able to differentiate and prioritize traffic that passes through it. &lt;/p&gt;&lt;p&gt;Consider the following network layout: &lt;/p&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_HYC3qIW2Tpc/R8WfupIufsI/AAAAAAAAAMQ/tgu5H-yHaQQ/s1600-h/Transparent-shaper.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_HYC3qIW2Tpc/R8WfupIufsI/AAAAAAAAAMQ/tgu5H-yHaQQ/s400/Transparent-shaper.png" alt="" id="BLOGGER_PHOTO_ID_5171715370770136770" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;We will configure one queue limiting the total throughput to the client and three sub-queues that limit HTTP, P2P and all other traffic separately. &lt;/p&gt; &lt;a name="Quick_Start_for_Impatient"&gt;&lt;/a&gt;&lt;h2&gt; &lt;span class="mw-headline"&gt;Quick Start for Impatient&lt;/span&gt;&lt;/h2&gt; &lt;p&gt;Configuration snippet from the MikroTik router: &lt;/p&gt; &lt;pre&gt;/ interface bridge&lt;br /&gt;add name="bridge1"&lt;br /&gt;/ interface bridge port&lt;br /&gt;add interface=ether2 bridge=bridge1&lt;br /&gt;add interface=ether3 bridge=bridge1&lt;br /&gt;&lt;br /&gt;/ ip firewall mangle&lt;br /&gt;add chain=prerouting protocol=tcp dst-port=80 action=mark-connection \&lt;br /&gt;   new-connection-mark=http_conn passthrough=yes&lt;br /&gt;add chain=prerouting connection-mark=http_conn action=mark-packet \&lt;br /&gt;   new-packet-mark=http passthrough=no&lt;br /&gt;add chain=prerouting p2p=all-p2p action=mark-connection \&lt;br /&gt;   new-connection-mark=p2p_conn passthrough=yes&lt;br /&gt;add chain=prerouting connection-mark=p2p_conn action=mark-packet \&lt;br /&gt;   new-packet-mark=p2p passthrough=no&lt;br /&gt;add chain=prerouting action=mark-connection new-connection-mark=other_conn \&lt;br /&gt;   passthrough=yes&lt;br /&gt;add chain=prerouting connection-mark=other_conn action=mark-packet \&lt;br /&gt;   new-packet-mark=other passthrough=no&lt;br /&gt;&lt;br /&gt;/ queue simple&lt;br /&gt;add name="main" target-addresses=10.0.0.12/32 max-limit=256000/512000&lt;br /&gt;add name="http" parent=main packet-marks=http max-limit=240000/500000&lt;br /&gt;add name="p2p" parent=main packet-marks=p2p max-limit=64000/64000&lt;br /&gt;add name="other" parent=main packet-marks=other max-limit=128000/128000&lt;br /&gt;&lt;/pre&gt; &lt;a name="Explanation"&gt;&lt;/a&gt;&lt;h2&gt; &lt;span class="mw-headline"&gt;Explanation&lt;/span&gt;&lt;/h2&gt; &lt;p&gt;Each piece of code is followed by the explanation of what it actually does. &lt;/p&gt; &lt;a name="Bridge"&gt;&lt;/a&gt;&lt;h3&gt; &lt;span class="mw-headline"&gt;Bridge&lt;/span&gt;&lt;/h3&gt; &lt;pre&gt;/ interface bridge&lt;br /&gt;add name="bridge1"&lt;br /&gt;/ interface bridge port&lt;br /&gt;add interface=ether2 bridge=bridge1&lt;br /&gt;add interface=ether3 bridge=bridge1&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;We create a new bridge interface and assign two ethernet interfaces to it. Thus the prospective traffic shaper will be completely transparent to the client. &lt;/p&gt; &lt;a name="Mangle"&gt;&lt;/a&gt;&lt;h3&gt; &lt;span class="mw-headline"&gt;Mangle&lt;/span&gt;&lt;/h3&gt; &lt;pre&gt;/ ip firewall mangle&lt;br /&gt;add chain=prerouting protocol=tcp dst-port=80 action=mark-connection \&lt;br /&gt;   new-connection-mark=http_conn passthrough=yes&lt;br /&gt;add chain=prerouting connection-mark=http_conn action=mark-packet \&lt;br /&gt;   new-packet-mark=http passthrough=no&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;All traffic destined to TCP port 80 is likely to be HTTP traffic and therefore is being marked with the packet mark &lt;b&gt;http&lt;/b&gt;. Note, that the first rule has &lt;b&gt;passthrough=yes&lt;/b&gt; while the second one has &lt;b&gt;passthrough=no&lt;/b&gt;. (You can obtain additional information about mangle at &lt;a href="http://www.mikrotik.com/docs/ros/2.9/ip/mangle" class="external free" title="http://www.mikrotik.com/docs/ros/2.9/ip/mangle" rel="nofollow"&gt;http://www.mikrotik.com/docs/ros/2.9/ip/mangle&lt;/a&gt;) &lt;/p&gt; &lt;pre&gt;/ ip firewall mangle&lt;br /&gt;add chain=prerouting p2p=all-p2p action=mark-connection \&lt;br /&gt;   new-connection-mark=p2p_conn passthrough=yes&lt;br /&gt;add chain=prerouting connection-mark=p2p_conn action=mark-packet \&lt;br /&gt;   new-packet-mark=p2p passthrough=no&lt;br /&gt;add chain=prerouting action=mark-connection new-connection-mark=other_conn \&lt;br /&gt;   passthrough=yes&lt;br /&gt;add chain=prerouting connection-mark=other_conn action=mark-packet \&lt;br /&gt;   new-packet-mark=other passthrough=no&lt;/pre&gt; &lt;p&gt;Same as above, P2P traffic is marked with the packet mark &lt;b&gt;p2p&lt;/b&gt; and all other traffic is marked with the packet mark &lt;b&gt;other&lt;/b&gt;. &lt;/p&gt; &lt;a name="Queues"&gt;&lt;/a&gt;&lt;h3&gt; &lt;span class="mw-headline"&gt;Queues&lt;/span&gt;&lt;/h3&gt; &lt;pre&gt;/ queue simple&lt;br /&gt;add name="main" target-addresses=10.0.0.12/32 max-limit=256000/512000&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;We create a queue that limits all the traffic going to/from the client (specified by the &lt;b&gt;target-address&lt;/b&gt;) to 256k/512k. &lt;/p&gt; &lt;pre&gt;/ queue simple&lt;br /&gt;add name="http" parent=main packet-marks=http max-limit=240000/500000&lt;br /&gt;add name="p2p" parent=main packet-marks=p2p max-limit=64000/64000&lt;br /&gt;add name="other" parent=main packet-marks=other max-limit=128000/128000&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;All sub-queues have the &lt;b&gt;main&lt;/b&gt; queue as the parent, thus the aggregate data rate could not exceed limits specified in the &lt;b&gt;main&lt;/b&gt; queue. Note, that &lt;b&gt;http&lt;/b&gt; queue has higher priority than other queues, meaning that HTTP downloads are prioritized. &lt;/p&gt;source http://wiki.mikrotik.com/wiki/TransparentTrafficShaper&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-177280743846859352?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/177280743846859352/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=177280743846859352' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/177280743846859352'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/177280743846859352'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/transparent-traffic-shaper.html' title='Transparent Traffic Shaper'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_HYC3qIW2Tpc/R8WfupIufsI/AAAAAAAAAMQ/tgu5H-yHaQQ/s72-c/Transparent-shaper.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-4871140302720803902</id><published>2008-02-26T05:25:00.000-08:00</published><updated>2008-02-26T05:30:00.962-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='QOS'/><title type='text'>PCQ Examples</title><content type='html'>&lt;p&gt;Per Connection Queue (PCQ) is a queuing discipline that can be used to dynamically equalize or shape traffic for multiple users, using little administration. It is possible to divide PCQ scenarios into three major groups: equal bandwidth for a number of users, certain bandwidth equal distribution between users, unknown bandwidth equal distribution between users. &lt;/p&gt; &lt;a name="Equal_Bandwidth_for_a_Number_of_Users"&gt;&lt;/a&gt;&lt;h3&gt; &lt;span class="mw-headline"&gt; Equal Bandwidth for a Number of Users &lt;/span&gt;&lt;/h3&gt; &lt;p&gt;Use PCQ type queue when you need to equalize the bandwidth [and set max limit] for a number of users. We will set the 64kbps download and 32kbps upload limits.&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_HYC3qIW2Tpc/R8QTu5IufrI/AAAAAAAAAMI/_yfG8w07ZBU/s1600-h/PCQ.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_HYC3qIW2Tpc/R8QTu5IufrI/AAAAAAAAAMI/_yfG8w07ZBU/s400/PCQ.png" alt="" id="BLOGGER_PHOTO_ID_5171279968460504754" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;There are two ways how to make this: using mangle and queue trees, or, using simple queues. &lt;/p&gt;&lt;p&gt;1. Mark all packets with packet-mark all: &lt;/p&gt; &lt;pre&gt;/ip firewall mangle add chain=prerouting action=mark-packet new-packet-mark=all passthrough=no&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;br /&gt;2. Setup two PCQ queue types - one for download and one for upload. &lt;i&gt;dst-address&lt;/i&gt; is classifier for user's download traffic, &lt;i&gt;src-address&lt;/i&gt; for upload traffic: &lt;/p&gt; &lt;pre&gt;/queue type add name="PCQ_download" kind=pcq pcq-rate=64000 pcq-classifier=dst-address&lt;br /&gt;/queue type add name="PCQ_upload" kind=pcq pcq-rate=32000 pcq-classifier=src-address&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;br /&gt;3. Finally, two queue rules are required, one for download and one for upload: &lt;/p&gt; &lt;pre&gt;/queue tree add parent=global-in queue=PCQ_download packet-mark=all&lt;br /&gt;/queue tree add parent=global-out queue=PCQ_upload packet-mark=all&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;If you don't like using mangle and queue trees, you can skip step 1, do step 2, and step 3 would be to create one simple queue as shown here: &lt;/p&gt; &lt;pre&gt;/queue simple add queue=PCQ_upload/PCQ_download target-addresses=192.168.0.0/24&lt;br /&gt;&lt;/pre&gt; &lt;a name="Certain_Bandwidth_Equal_Distribution_between_Users"&gt;&lt;/a&gt;&lt;h3&gt; &lt;span class="mw-headline"&gt; Certain Bandwidth Equal Distribution between Users&lt;/span&gt;&lt;/h3&gt; &lt;a name="Unknown_Bandwidth_Equal_Distribution_between_Users"&gt;&lt;/a&gt;&lt;h3&gt; &lt;span class="mw-headline"&gt; Unknown Bandwidth Equal Distribution between Users&lt;/span&gt;&lt;/h3&gt;source :http://wiki.mikrotik.com/wiki/PCQ_Examples&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-4871140302720803902?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/4871140302720803902/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=4871140302720803902' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/4871140302720803902'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/4871140302720803902'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/pcq-examples.html' title='PCQ Examples'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_HYC3qIW2Tpc/R8QTu5IufrI/AAAAAAAAAMI/_yfG8w07ZBU/s72-c/PCQ.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-4912490170874554467</id><published>2008-02-24T07:14:00.000-08:00</published><updated>2008-02-24T09:47:30.607-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Firewall'/><title type='text'>Ddos attack Protection</title><content type='html'>This firewall is powerfull to protect router and network from ddos attack&lt;br /&gt;&lt;script type="text/javascript"&gt;&lt;!-- google_ad_client = "pub-4257686693012217"; /* 336x280, created 2/20/08 */ google_ad_slot = "3900193424"; google_ad_width = 336; google_ad_height = 280; google_cpa_choice = ""; // on file //--&gt;&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;Use &lt;a href="http://mikrotik-link.blogspot.com/2008/02/dmitry-on-firewalling.html"&gt;Dimitry Firewall&lt;/a&gt;&lt;br /&gt;and add this rule to firewall&lt;br /&gt;/ip firewall connection tracking set tcp-syncookie=yes&lt;br /&gt;/ip firewall filter add chain=forward action=jump jump-target=block-ddos protocol=udp comment=Jump_to_block-ddos&lt;br /&gt;/ip firewall filter add chain=input action=jump jump-target=block-ddos protocol=udp comment=Jump_to_block-ddos&lt;br /&gt;/ip firewall filter add chain=block-ddos action=return limit=16,32&lt;br /&gt;/ip firewall filter add chain=block-ddos action=log log-prefix=DDOS_ATTACK:&lt;br /&gt;/ip firewall filter add chain=block-ddos action=drop limit=16,32&lt;br /&gt;/ip firewall filter add chain=input action=jump jump-target=block-ddos protocol=udp comment=Jump_to_block-ddos&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-4912490170874554467?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/4912490170874554467/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=4912490170874554467' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/4912490170874554467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/4912490170874554467'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/ddos-protection.html' title='Ddos attack Protection'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-667386411035611521</id><published>2008-02-18T06:09:00.000-08:00</published><updated>2008-02-18T06:11:04.230-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Script'/><title type='text'>stop flooding of smtp / block spammers</title><content type='html'>/ ip firewall filter&lt;br /&gt;add chain=forward action=add-src-to-address-list dst-port=25 protocol=tcp \&lt;br /&gt;    src-address-list=spammer address-list=WasASpammerOnce \&lt;br /&gt;    address-list-timeout=0s comment="Log Spammer to address list for future \&lt;br /&gt;    investigation" disabled=no&lt;br /&gt;add chain=forward action=tarpit dst-port=25 protocol=tcp \&lt;br /&gt;    src-address-list=spammer comment="BLOCK SPAMMERS OR INFECTED USERS" \&lt;br /&gt;    disabled=no&lt;br /&gt;add chain=forward action=add-src-to-address-list dst-port=25 protocol=tcp \&lt;br /&gt;    connection-limit=30,32 limit=50,5 src-address-list=!WhiteListed \&lt;br /&gt;    address-list=spammer address-list-timeout=30m comment="Detect and add-list \&lt;br /&gt;    SMTP virus or spammers" disabled=no&lt;br /&gt;&lt;br /&gt;soure:http://forum.mikrotik.com/viewtopic.php?f=7&amp;t=21836&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-667386411035611521?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/667386411035611521/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=667386411035611521' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/667386411035611521'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/667386411035611521'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/stop-flooding-of-smtp-block-spammers.html' title='stop flooding of smtp / block spammers'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-335170514161066296</id><published>2008-02-15T19:44:00.000-08:00</published><updated>2008-02-15T19:47:53.012-08:00</updated><title type='text'>Mirror Download</title><content type='html'>Mikrotik download from mirror site&lt;br /&gt;&lt;a href="http://mikrotik.bnet-work.com/?cat=9"&gt;Mikrotik Download&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-335170514161066296?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/335170514161066296/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=335170514161066296' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/335170514161066296'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/335170514161066296'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/mirror-download.html' title='Mirror Download'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-4251886165519037816</id><published>2008-02-15T05:29:00.000-08:00</published><updated>2008-02-15T06:58:35.200-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Script'/><title type='text'>Siren II</title><content type='html'>/ tool netwatch&lt;br /&gt;add host=213.xxx.xxx.x timeout=1s interval=1m up-script="" down-script=":log info \"GATEWAY \&lt;br /&gt;\n     :set i 15 \=50 step=1  \\&lt;br /&gt;\n             :beep length=400ms frequency=\$x; \&lt;br /&gt;\n     \       :set x (\$x +35) &lt;br /&gt;\n            :beep length=0 \) &amp;amp;&amp;amp; (\$i &gt;0))&lt;br /&gt;\n}" comment="" disabled=no&lt;br /&gt;[admin@RouTer] tool netwatch&gt;&lt;br /&gt;&lt;br /&gt;and script is&lt;br /&gt;&lt;br /&gt;:log info "GATEWAY Problem No INTERNET"&lt;br /&gt;:for c from=1 to=50 step=1  \&lt;br /&gt;&lt;br /&gt;do={ \&lt;br /&gt;   :set i 15&lt;br /&gt;    :set x 1900&lt;br /&gt;&lt;br /&gt;   :do {\&lt;br /&gt;           :beep length=400ms frequency=$x; :delay 25ms&lt;br /&gt;           :set i ($i - 1);&lt;br /&gt;           :set x ($x +35)&lt;br /&gt;&lt;br /&gt;         } \&lt;br /&gt;           while (($i &lt;16)&gt;0))&lt;br /&gt;          :beep length=0 frequency=0&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;create a script named "&lt;span class="posthilit"&gt;siren&lt;/span&gt;" using danz9370 source code, then&lt;br /&gt;create another script named "end-&lt;span class="posthilit"&gt;siren&lt;/span&gt;" with this source code:&lt;br /&gt;&lt;br /&gt;/sys script job remove [find \&lt;br /&gt;script="&lt;span class="posthilit"&gt;siren&lt;/span&gt;"]&lt;br /&gt;&lt;br /&gt;now do netwatch and specify "end-&lt;span class="posthilit"&gt;siren&lt;/span&gt;" under "on up"  and "&lt;span class="posthilit"&gt;siren&lt;/span&gt;" under "on down"&lt;br /&gt;insert this script with for stop until internet up&lt;br /&gt;&lt;div class="postbody"&gt;:for i from=1000 to=3000 step=80  do={:beep length=10ms frequency=$i; :delay 10ms;}&lt;br /&gt;:for i from=1000 to=2800 step=80  do={:beep length=10ms frequency=$i; :delay 10ms;}&lt;br /&gt;:for i from=2800 to=1000 step=-80  do={:beep length=10ms frequency=$i; :delay 10ms;}&lt;/div&gt;      &lt;br /&gt;source :http://forum.mikrotik.com/viewtopic.php?f=9&amp;amp;t=12072&amp;amp;hilit=siren&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-4251886165519037816?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/4251886165519037816/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=4251886165519037816' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/4251886165519037816'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/4251886165519037816'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/siren-ii.html' title='Siren II'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-252828213178646514</id><published>2008-02-12T04:26:00.000-08:00</published><updated>2008-02-12T04:40:14.571-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Routing'/><title type='text'>Load Balancing over Multiple Gateways</title><content type='html'>&lt;p style="font-family: arial;"&gt;The typical situation where you got one router and want to connect to two ISPs: &lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;a href="http://wiki.mikrotik.com/wiki/Image:Dual_gw_01.jpg" class="image" title="Image:dual_gw_01.jpg"&gt;&lt;img alt="Image:dual_gw_01.jpg" longdesc="/wiki/Image:Dual_gw_01.jpg" src="http://wiki.mikrotik.com/images/2/23/Dual_gw_01.jpg" height="432" width="417" /&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="font-family: arial;"&gt;Of course, you want to do load balancing! There are several ways how to do it. Depending on the particular situation, you may find one best suited for you. &lt;/p&gt; &lt;a style="font-family: arial;" name="Policy_Routing_based_on_Client_IP_Address"&gt;&lt;/a&gt;&lt;h2 style="font-family: arial;"&gt;&lt;span class="editsection"&gt;&lt;/span&gt;&lt;span class="mw-headline"&gt; Policy Routing based on Client IP Address &lt;/span&gt;&lt;/h2&gt; &lt;p style="font-family: arial;"&gt;If you have a number of hosts, you may group them by IP addresses. Then, depending on the source IP address, send the traffic out through Gateway #1 or #2. This is not really the best approach, giving you perfect load balancing, but it's easy to implement, and gives you some control too. &lt;/p&gt;&lt;p style="font-family: arial;"&gt;Let us assume we use for our workstations IP addresses from network 192.168.100.0/24. The IP addresses are assigned as follows: &lt;/p&gt; &lt;ul style="font-family: arial;"&gt;&lt;li&gt; 192.168.100.1-127 are used for Group A workstations &lt;/li&gt;&lt;li&gt; 192.168.100.128-253 are used for Group B workstations &lt;/li&gt;&lt;li&gt; 192.168.100.254 is used for the router. &lt;/li&gt;&lt;/ul&gt; &lt;p style="font-family: arial;"&gt;All workstations have IP configuration with the IP address from the relevant group, they all have network mask 255.255.255.0, and 192.168.100.254 is the default gateway for them. We will talk about DNS servers later. &lt;/p&gt;&lt;p style="font-family: arial;"&gt;Now, when we have workstations divided into groups, we can refer to them using subnet addressing: &lt;/p&gt; &lt;ul style="font-family: arial;"&gt;&lt;li&gt; Group A is 192.168.100.0/25, i.e., addresses 192.168.100.0-127 &lt;/li&gt;&lt;li&gt; Group B is 192.168.100.128/25, i.e., addresses 192.168.100.128-255 &lt;/li&gt;&lt;/ul&gt; &lt;pre style="font-family: arial;"&gt;If you do not understand this, take the TCP/IP Basics course,&lt;br /&gt;or, look for some resources about subnetting on the Internet!&lt;br /&gt;&lt;/pre&gt; &lt;p style="font-family: arial;"&gt;We need to add two IP Firewall Mangle rules to mark the packets originated from Group A or Group B workstations. &lt;/p&gt;&lt;p style="font-family: arial;"&gt;For &lt;b&gt;Group A&lt;/b&gt;, specify &lt;/p&gt; &lt;ul style="font-family: arial;"&gt;&lt;li&gt; Chain &lt;b&gt;prerouting&lt;/b&gt; and Src. Address &lt;b&gt;192.168.100.0/25&lt;/b&gt; &lt;/li&gt;&lt;li&gt; Action &lt;b&gt;mark routing&lt;/b&gt; and New Routing Mark &lt;b&gt;GroupA&lt;/b&gt;. &lt;/li&gt;&lt;/ul&gt; &lt;p style="font-family: arial;"&gt;&lt;a href="http://wiki.mikrotik.com/wiki/Image:Dual_gw_22.jpg" class="image" title="Image:dual_gw_22.jpg"&gt;&lt;img alt="Image:dual_gw_22.jpg" longdesc="/wiki/Image:Dual_gw_22.jpg" src="http://wiki.mikrotik.com/images/3/3a/Dual_gw_22.jpg" height="411" width="675" /&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="font-family: arial;"&gt;It is a good practice to add a comment as well. Your mangle rules might be interesting for someone else and for yourself as well after some time. &lt;/p&gt;&lt;p style="font-family: arial;"&gt;For &lt;b&gt;Group B&lt;/b&gt;, specify &lt;/p&gt; &lt;ul style="font-family: arial;"&gt;&lt;li&gt; Chain &lt;b&gt;prerouting&lt;/b&gt; and Src. Address &lt;b&gt;192.168.100.128/25&lt;/b&gt; &lt;/li&gt;&lt;li&gt; Action &lt;b&gt;mark routing&lt;/b&gt; and New Routing Mark &lt;b&gt;GroupB&lt;/b&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="font-family: arial;"&gt;&lt;a href="http://wiki.mikrotik.com/wiki/Image:Dual_gw_25.jpg" class="image" title="Image:dual_gw_25.jpg"&gt;&lt;img alt="Image:dual_gw_25.jpg" longdesc="/wiki/Image:Dual_gw_25.jpg" src="http://wiki.mikrotik.com/images/a/ae/Dual_gw_25.jpg" height="363" width="665" /&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="font-family: arial;"&gt;All IP traffic coming from workstations is marked with the routing marks &lt;b&gt;GroupA&lt;/b&gt; or &lt;b&gt;GroupB&lt;/b&gt;. We can use these marks in the routing table. &lt;/p&gt;&lt;p style="font-family: arial;"&gt;Next, we should specify two default routes (destination 0.0.0.0/0) with appropriate routing marks and gateways: &lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;a href="http://wiki.mikrotik.com/wiki/Image:Dual_gw_26.jpg" class="image" title="Image:dual_gw_26.jpg"&gt;&lt;img alt="Image:dual_gw_26.jpg" longdesc="/wiki/Image:Dual_gw_26.jpg" src="http://wiki.mikrotik.com/images/d/dd/Dual_gw_26.jpg" height="359" width="718" /&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="font-family: arial;"&gt;This thing is not going to work, unless you do masquerading for your LAN! The simplest way to do it is by adding one NAT rule for Src. Address &lt;b&gt;192.168.100.0/24&lt;/b&gt; and Action &lt;b&gt;masquerade&lt;/b&gt;: &lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;a href="http://wiki.mikrotik.com/wiki/Image:Dual_gw_28.jpg" class="image" title="Image:dual_gw_28.jpg"&gt;&lt;img alt="Image:dual_gw_28.jpg" longdesc="/wiki/Image:Dual_gw_28.jpg" src="http://wiki.mikrotik.com/images/a/a0/Dual_gw_28.jpg" height="391" width="778" /&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="font-family: arial;"&gt;Test the setup by tracing the route to some IP address on the Internet! &lt;/p&gt;&lt;p style="font-family: arial;"&gt;From a workstation of &lt;b&gt;Group A&lt;/b&gt;, it should go like this: &lt;/p&gt; &lt;pre style="font-family: arial;"&gt;C:\&gt;tracert -d 8.8.8.8&lt;br /&gt;&lt;br /&gt;Tracing route to 8.8.8.8 over a maximum of 30 hops&lt;br /&gt;&lt;br /&gt;1     2 ms     2 ms     2 ms  192.168.100.254&lt;br /&gt;2    10 ms     4 ms     3 ms  10.1.0.1&lt;br /&gt;...&lt;br /&gt;&lt;/pre&gt; &lt;p style="font-family: arial;"&gt;From a workstation of &lt;b&gt;Group B&lt;/b&gt;, it should go like this: &lt;/p&gt; &lt;pre style="font-family: arial;"&gt;C:\&gt;tracert -d 8.8.8.8&lt;br /&gt;&lt;br /&gt;Tracing route to 8.8.8.8 over a maximum of 30 hops&lt;br /&gt;&lt;br /&gt;1     2 ms     2 ms     2 ms  192.168.100.254&lt;br /&gt;2    10 ms     4 ms     3 ms  10.5.8.1&lt;br /&gt;...&lt;br /&gt;&lt;/pre&gt; &lt;p style="font-family: arial;"&gt;You can specify the DNS server for workstations quite freely, just make it can be reached (test it by tracing the route to DNS server's IP address)!&lt;/p&gt;&lt;br /&gt;&lt;p style="font-family: arial;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p style="font-family: arial;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;Source : http://wiki.mikrotik.com/wiki/Load_Balancing_over_Multiple_Gateways&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-252828213178646514?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/252828213178646514/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=252828213178646514' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/252828213178646514'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/252828213178646514'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/load-balancing-over-multiple-gateways.html' title='Load Balancing over Multiple Gateways'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-4516056553954992578</id><published>2008-02-11T20:58:00.000-08:00</published><updated>2008-02-11T20:59:24.485-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Script'/><title type='text'>Improved Netwatch II</title><content type='html'>&lt;p&gt;This setup now changes the distance number on the interfaces that is being used for gateways instead of disabling an interface. That way you could continue to monitor the unused interface to know whether it is actually up or down to the internet. &lt;/p&gt;&lt;p&gt;With these scripts you must use the scheduler to run them. I set mine to every 5 seconds. This will send 5 pings in a row out ether 1 and if all 5 fail it will increase the distance on that port to 3 instead of 1. To start this process you must set your distance on port 1 to 1. The other port that is being used as a failover gateway should be set to a distance of 2. By switching distance on the port instead of disabling it allows you to continue to ping out ether 1 until it pings all 5 times and at that point it will switch back to the main gateway. &lt;/p&gt;&lt;p&gt;&lt;br /&gt;script 1: &lt;/p&gt; &lt;pre&gt;       :local i 0; {:do {:set i ($i + 1)} while i &lt; 5) &amp;amp;&amp;amp; ([/ping 64.233.169.99 interval=3 count=1]=0)};&lt;br /&gt;      :if ($i=5 &amp;amp;&amp;amp; [/ip route get [find comment="Default Route"] distance]=1) do={:log info "Main Gateway down";&lt;br /&gt;       /ip route set [find comment="Default Route"] distance=3}&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;script 2: &lt;/p&gt; &lt;pre&gt;      :local i 0; {:do {:set i ($i + 1)} while i &lt; 5) &amp;amp;&amp;amp; ([/ping 64.233.169.99 interval=3 count=1]=1)};&lt;br /&gt;     :if ($i=5 &amp;amp;&amp;amp; [/ip route get [find comment="Default Route"] distance]=3) do={:log info "Main Gateway up";&lt;br /&gt;     /ip route set [find comment="Default Route"] distance=1}&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;Suggestion: A trick could be use ping with different sizes and have a different route for each. That would require creating a mangle rule based on packet size and place a routing mark on each.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Source : http://wiki.mikrotik.com/wiki/Improved_Netwatch_II&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-4516056553954992578?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/4516056553954992578/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=4516056553954992578' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/4516056553954992578'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/4516056553954992578'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/improved-netwatch-ii.html' title='Improved Netwatch II'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-4968179372796185027</id><published>2008-02-11T20:56:00.000-08:00</published><updated>2008-02-11T20:57:59.560-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Script'/><title type='text'>Improved Netwatch</title><content type='html'>&lt;p&gt;This is an improved version of Netwatch that removes false positives. It works by pinging the target IP 5 times. If all 5 time out then the specified action is taken. &lt;/p&gt; &lt;pre&gt;        :local i 0; {:do {:set i ($i + 1)} while i &lt; 5) &amp;amp;&amp;amp; ([/ping 72.14.207.104 interval=3 count=1]=0)};&lt;br /&gt;       :if ($i=5 &amp;amp;&amp;amp; [/ip route get [find comment="Default Route"] disabled]=false) do={:log info "Main Gateway down";&lt;br /&gt;        /ip route set [find comment="Default Route"] disabled=yes}&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;In this case it searches for a route labelled "Default Route" and disables it if 5 pings in a row to www.google.com time out. To re-enable on 5 succesfull pings you could have some thing like: &lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt; &lt;pre&gt;       :local i 0; {:do {:set i ($i + 1)} while i &lt; 5) &amp;amp;&amp;amp; ([/ping 72.14.207.104 interval=3 count=1]=1)};&lt;br /&gt;      :if ($i=5 &amp;amp;&amp;amp; [/ip route get [find comment="Default Route"] disabled]=true) do={:log info "Main Gateway up";&lt;br /&gt;      /ip route set [find comment="Default Route"] disabled=no}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Source: http://wiki.mikrotik.com/wiki/Improved_Netwatch&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-4968179372796185027?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/4968179372796185027/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=4968179372796185027' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/4968179372796185027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/4968179372796185027'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/improved-netwatch.html' title='Improved Netwatch'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-148295236256228871</id><published>2008-02-11T07:15:00.000-08:00</published><updated>2008-02-11T07:20:24.643-08:00</updated><title type='text'>SETTING OSPF MAIN ROUTER</title><content type='html'>&lt;p style="color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;b&gt;Setting Interface &lt;/b&gt;&lt;/p&gt;  &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; [admin@MainRouter] &gt; in pr&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;Flags: X - disabled, D - dynamic, R - running&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;#&lt;span&gt;    &lt;/span&gt;NAME&lt;span&gt;                         &lt;/span&gt;TYPE&lt;span&gt;             &lt;/span&gt;RX-RATE&lt;span&gt;    &lt;/span&gt;TX-RATE&lt;span&gt;    &lt;/span&gt;MTU&lt;span&gt;  &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;0&lt;span&gt;  &lt;/span&gt;R ether1=ToClient&lt;span&gt;              &lt;/span&gt;ether&lt;span&gt;            &lt;/span&gt;0&lt;span&gt;    &lt;/span&gt;&lt;span&gt;      &lt;/span&gt;0&lt;span&gt;          &lt;/span&gt;1500&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;1&lt;span&gt;  &lt;/span&gt;R ether2=ToInternet&lt;span&gt;            &lt;/span&gt;ether&lt;span&gt;            &lt;/span&gt;0&lt;span&gt;          &lt;/span&gt;0&lt;span&gt;          &lt;/span&gt;1500&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;b&gt;Setting IP&lt;/b&gt;&lt;/p&gt;  &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; [admin@MainRouter] &gt; ip add pr&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;Flags: X - disabled, I - invalid, D - dynamic&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;#&lt;span&gt;   &lt;/span&gt;ADDRESS&lt;span&gt;            &lt;/span&gt;NETWORK&lt;span&gt;         &lt;/span&gt;BROADCAST&lt;span&gt;       &lt;/span&gt;INTERFACE&lt;span&gt;        &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;0&lt;span&gt;   &lt;/span&gt;192.168.10.18/27&lt;span&gt;   &lt;/span&gt;192.168.10.0&lt;span&gt;    &lt;/span&gt;192.168.10.31&lt;span&gt;   &lt;/span&gt;ether2=ToInternet&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;1&lt;span&gt;   &lt;/span&gt;10.10.10.1/24&lt;span&gt;      &lt;/span&gt;10.10.10.0&lt;span&gt;      &lt;/span&gt;10.10.10.255&lt;span&gt;    &lt;/span&gt;ether1=ToClient&lt;span&gt;  &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;2&lt;span&gt;   &lt;/span&gt;10.10.20.1/24&lt;span&gt;      &lt;/span&gt;10.10.20.0&lt;span&gt;      &lt;/span&gt;10.10.20.255&lt;span&gt;    &lt;/span&gt;ether1=ToClient&lt;span&gt;  &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;b&gt;Setting Gateway (ROUTE)&lt;/b&gt;&lt;/p&gt;  &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; [admin@MainRouter] &gt; ip rou pr&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;Flags: X - disabled, A - active, D - dynamic,&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;C - connect, S - static, r - rip, b - bgp, o - ospf&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;#&lt;span&gt;     &lt;/span&gt;DST-ADDRESS&lt;span&gt;        &lt;/span&gt;PREF-SRC&lt;span&gt;        &lt;/span&gt;G GATEWAY&lt;span&gt;         &lt;/span&gt;DIS&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;0 ADC 192.168.10.0/27&lt;span&gt;    &lt;/span&gt;192.168.10.18&lt;span&gt;  &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;1 A S 0.0.0.0/0&lt;span&gt;                          &lt;/span&gt;r 192.168.10.1&lt;span&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;br /&gt;&lt;b&gt;Setting NAT&lt;/b&gt;&lt;/p&gt;  &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; [admin@MainRouter] &gt; ip fire nat pr&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;Flags: X - disabled, I - invalid, D - dynamic&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;0&lt;span&gt;   &lt;/span&gt;chain=srcnat out-interface=ether2=ToInternet action=masquerade&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;b&gt;Setting DNS&lt;/b&gt;&lt;/p&gt;  &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; [admin@MainRouter] &gt; ip dns pr&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;            &lt;/span&gt;primary-dns: 222.124.180.40&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;          &lt;/span&gt;secondary-dns: 0.0.0.0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;  &lt;/span&gt;allow-remote-requests: yes&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;             &lt;/span&gt;cache-size: 2048KiB&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;          &lt;/span&gt;cache-max-ttl: 1w&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;             &lt;/span&gt;cache-used: 20KiB&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;/p&gt; &lt;p  style="color: rgb(255, 255, 255);font-family:arial;"&gt;&lt;b&gt;&lt;span style="font-size:12;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;b&gt;SETTING OSPF&lt;/b&gt;&lt;/p&gt;  &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; [admin@MainRouter] &gt; routing ospf pr&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;         &lt;/span&gt;&lt;span&gt;      &lt;/span&gt;router-id: 0.0.0.0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;      &lt;/span&gt;distribute-default: if-installed-as-type-2&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;  &lt;/span&gt;redistribute-connected: as-type-1&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;     &lt;/span&gt;redistribute-static: as-type-2&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;        &lt;/span&gt;redistribute-rip: no&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;        &lt;/span&gt;redistribute-bgp: no&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;          &lt;/span&gt;metric-default: 1&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;        &lt;/span&gt;metric-connected: 0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;           &lt;/span&gt;metric-static: 0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;              &lt;/span&gt;metric-rip: 0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;              &lt;/span&gt;metric-bgp: 0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;b&gt;Setting OSPF AREA&lt;/b&gt;&lt;/p&gt;  &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; [admin@MainRouter] &gt; routing ospf area print &lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;Flags: X - disabled&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;#&lt;span&gt;   &lt;/span&gt;NAME&lt;span&gt;                   &lt;/span&gt;AREA-ID&lt;span&gt;         &lt;/span&gt;TYPE&lt;span&gt;    &lt;/span&gt;DEFAULT-COST AUTHENTICATION&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;0&lt;span&gt;   &lt;/span&gt;backbone&lt;span&gt;               &lt;/span&gt;0.0.0.0&lt;span&gt;         &lt;/span&gt;default&lt;span&gt;              &lt;/span&gt;none&lt;span&gt;          &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;1&lt;span&gt;   &lt;/span&gt;Local&lt;span&gt;                  &lt;/span&gt;0.0.0.1&lt;span&gt;         &lt;/span&gt;default 1&lt;span&gt;            &lt;/span&gt;none&lt;span&gt;          &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;b&gt;Setting OSPF NETWORK&lt;/b&gt;&lt;/p&gt;  &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; [admin@MainRouter] &gt; routing ospf network print&lt;span&gt;   &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;Flags: X - disabled, I - invalid&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;#&lt;span&gt;   &lt;/span&gt;NETWORK&lt;span&gt;            &lt;/span&gt;AREA&lt;span&gt;    &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;0&lt;span&gt;   &lt;/span&gt;10.10.10.0/24&lt;span&gt;      &lt;/span&gt;Local&lt;span&gt;   &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;1&lt;span&gt;   &lt;/span&gt;10.10.20.0/24&lt;span&gt;      &lt;/span&gt;Local&lt;span&gt;   &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;b&gt;Hasil Settingan di OSPF Neighbors&lt;/b&gt;&lt;/p&gt;  &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; [admin@MainRouter] &gt; routing ospf neighbor print &lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;router-id=192.168.101.1 address=10.10.20.2 priority=1 state=”Full”&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;   &lt;/span&gt;state-changes=4 ls-retransmits=0 ls-requests=0 db-summaries=0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;   &lt;/span&gt;dr-id=10.10.20.1 backup-dr-id=10.10.20.2&lt;/p&gt;  &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;span&gt;&lt;/span&gt;router-id=192.168.200.1 address=10.10.10.2 priority=1 state=”Full”&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;   &lt;/span&gt;state-changes=8 ls-retransmits=0 ls-requests=0 db-summaries=0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;   &lt;/span&gt;dr-id=10.10.10.1 backup-dr-id=10.10.10.2&lt;/p&gt;  &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;span&gt;&lt;/span&gt;router-id=192.168.10.18 address=10.10.20.1 priority=1 state=”2-Way”&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;   &lt;/span&gt;state-changes=0 ls-retransmits=0 ls-requests=0 db-summaries=0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;   &lt;/span&gt;dr-id=10.10.20.1 backup-dr-id=10.10.20.2&lt;/p&gt; &lt;p style="color: rgb(255, 255, 255);" face="arial" class="MsoNormal"&gt; &lt;b&gt;&lt;!--[endif]--&gt;&lt;/b&gt;&lt;/p&gt; &lt;p style="color: rgb(255, 255, 255);" face="arial" class="MsoNormal"&gt;[admin@MainRouter] &gt; ip rou pr&lt;/p&gt; &lt;p style="color: rgb(255, 255, 255);" face="arial" class="MsoNormal"&gt;Flags: X - disabled, A - active, D - dynamic,&lt;/p&gt; &lt;p style="color: rgb(255, 255, 255);" face="arial" class="MsoNormal"&gt;C - connect, S - static, r - rip, b - bgp, o - ospf&lt;/p&gt; &lt;p style="color: rgb(255, 255, 255);" face="arial" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;#&lt;span&gt;     &lt;/span&gt;DST-ADDRESS&lt;span&gt;        &lt;/span&gt;PREF-SRC&lt;span&gt;        &lt;/span&gt;G GATEWAY&lt;span&gt;         &lt;/span&gt;DIS&lt;/p&gt; &lt;p style="color: rgb(255, 255, 255);" face="arial" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;0 ADC 10.10.10.0/24&lt;span&gt;      &lt;/span&gt;10.10.10.1&lt;span&gt;     &lt;/span&gt;&lt;/p&gt; &lt;p style="color: rgb(255, 255, 255);" face="arial" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;1&lt;span&gt;  &lt;/span&gt;Do 10.10.10.0/24&lt;span&gt;     &lt;/span&gt;&lt;/p&gt; &lt;p style="color: rgb(255, 255, 255);" face="arial" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;2 ADC 10.10.20.0/24&lt;span&gt;      &lt;/span&gt;10.10.20.1&lt;span&gt;     &lt;/span&gt;&lt;/p&gt; &lt;p style="color: rgb(255, 255, 255);" face="arial" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;3&lt;span&gt;  &lt;/span&gt;Do 10.10.20.0/24&lt;span&gt;     &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;4 ADC 192.168.10.0/27&lt;span&gt;    &lt;/span&gt;192.168.10.18&lt;span&gt;  &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;5 ADo 192.168.100.0/30&lt;span&gt;                   &lt;/span&gt;r 10.10.10.2&lt;span&gt;     &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;6 ADo 192.168.101.0/24&lt;span&gt;                   &lt;/span&gt;r 10.10.20.2&lt;span&gt;     &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;7 ADo 192.168.200.0/30&lt;span&gt;                   &lt;/span&gt;r 10.10.10.2&lt;span&gt;     &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;8 A S 0.0.0.0/0&lt;span&gt;                          &lt;/span&gt;r 192.168.10.1&lt;span&gt;   &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;b&gt;SETTING OSPF CLIENT1&lt;/b&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;[admin@Client1=RouterBoard] &gt; in pr&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;Flags: X - disabled, D - dynamic, R - running&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;#&lt;span&gt;    &lt;/span&gt;NAME&lt;span&gt;                         &lt;/span&gt;TYPE&lt;span&gt;             &lt;/span&gt;RX-RATE&lt;span&gt;    &lt;/span&gt;TX-RATE&lt;span&gt;    &lt;/span&gt;MTU&lt;span&gt;  &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;0&lt;span&gt;  &lt;/span&gt;R ether1=ToMainRouter&lt;span&gt;          &lt;/span&gt;ether&lt;span&gt;            &lt;/span&gt;0&lt;span&gt;          &lt;/span&gt;0&lt;span&gt;          &lt;/span&gt;1500&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;1&lt;span&gt;  &lt;/span&gt;R ether2=ToLocal&lt;span&gt;               &lt;/span&gt;ether&lt;span&gt;            &lt;/span&gt;0&lt;span&gt;          &lt;/span&gt;0&lt;span&gt;          &lt;/span&gt;1500&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;2&lt;span&gt;  &lt;/span&gt;R ether3&lt;span&gt;                       &lt;/span&gt;ether&lt;span&gt;            &lt;/span&gt;0&lt;span&gt;  &lt;/span&gt;&lt;span&gt;        &lt;/span&gt;0&lt;span&gt;          &lt;/span&gt;1500&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;3&lt;span&gt;    &lt;/span&gt;wlan1&lt;span&gt;                        &lt;/span&gt;wlan&lt;span&gt;             &lt;/span&gt;0&lt;span&gt;          &lt;/span&gt;0&lt;span&gt;          &lt;/span&gt;1500&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;4 X&lt;span&gt;  &lt;/span&gt;wlan2&lt;span&gt;                        &lt;/span&gt;wlan&lt;span&gt;             &lt;/span&gt;0&lt;span&gt;          &lt;/span&gt;0&lt;span&gt;          &lt;/span&gt;1500&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;[admin@Client1=RouterBoard] &gt; ip add pr&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;Flags: X - disabled, I - invalid, D - dynamic&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;#&lt;span&gt;   &lt;/span&gt;ADDRESS&lt;span&gt;            &lt;/span&gt;NETWORK&lt;span&gt;         &lt;/span&gt;BROADCAST&lt;span&gt;       &lt;/span&gt;INTERFACE&lt;span&gt;          &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;0&lt;span&gt;   &lt;/span&gt;10.10.10.2/24&lt;span&gt;      &lt;/span&gt;10.10.10.0&lt;span&gt;      &lt;/span&gt;10.10.10.255&lt;span&gt;    &lt;/span&gt;ether1=ToMainRouter&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;1&lt;span&gt;   &lt;/span&gt;192.168.100.1/30&lt;span&gt;   &lt;/span&gt;192.168.100.0&lt;span&gt;   &lt;/span&gt;192.168.100.3&lt;span&gt;   &lt;/span&gt;ether2=ToLocal&lt;span&gt;     &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;2&lt;span&gt;   &lt;/span&gt;192.168.200.1/30&lt;span&gt;   &lt;/span&gt;192.168.200.0&lt;span&gt;   &lt;/span&gt;192.168.200.3&lt;span&gt;   &lt;/span&gt;wlan1&lt;span&gt;  &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;            &lt;/span&gt;&lt;/p&gt; &lt;p style="color: rgb(255, 255, 255);font-family:arial;" &gt; &lt;span style=";font-size:12;" &gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;[admin@Client1=RouterBoard] &gt; ip dns pr&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;            &lt;/span&gt;primary-dns: 0.0.0.0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;          &lt;/span&gt;secondary-dns: 0.0.0.0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;  &lt;/span&gt;allow-remote-requests: no&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;             &lt;/span&gt;cache-size: 2048KiB&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;          &lt;/span&gt;cache-max-ttl: 1w&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;             &lt;/span&gt;cache-used: 17KiB&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;[admin@Client1=RouterBoard] &gt; rou ospf pr&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;               &lt;/span&gt;router-id: 0.0.0.0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;      &lt;/span&gt;distribute-default: never&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;  &lt;/span&gt;redistribute-connected: as-type-1&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;     &lt;/span&gt;redistribute-static: no&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;        &lt;/span&gt;redistribute-rip: no&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;        &lt;/span&gt;redistribute-bgp: no&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;          &lt;/span&gt;metric-default: 1&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;        &lt;/span&gt;metric-connected: 0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;           &lt;/span&gt;metric-static: 0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;              &lt;/span&gt;metric-rip: 0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt;              &lt;/span&gt;metric-bgp: 0&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;/p&gt; &lt;p style="color: rgb(255, 255, 255);font-family:arial;" &gt;   &lt;span style="font-size:12;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;[admin@Client1=RouterBoard] &gt; rou ospf area pr&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;Flags: X - disabled&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;#&lt;span&gt;   &lt;/span&gt;NAME&lt;span&gt;                  &lt;/span&gt;&lt;span&gt; &lt;/span&gt;AREA-ID&lt;span&gt;         &lt;/span&gt;TYPE&lt;span&gt;    &lt;/span&gt;DEFAULT-COST AUTHENTICATION&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;0&lt;span&gt;   &lt;/span&gt;backbone&lt;span&gt;               &lt;/span&gt;0.0.0.0&lt;span&gt;         &lt;/span&gt;default&lt;span&gt;              &lt;/span&gt;none&lt;span&gt;          &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;1&lt;span&gt;   &lt;/span&gt;Local&lt;span&gt;                  &lt;/span&gt;0.0.0.1&lt;span&gt;         &lt;/span&gt;default 1&lt;span&gt;            &lt;/span&gt;none&lt;span&gt;          &lt;/span&gt;&lt;/p&gt;    &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;br /&gt;[admin@Client1=RouterBoard] &gt; rou ospf network pr&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;Flags: X - disabled, I - invalid&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;#&lt;span&gt;   &lt;/span&gt;NETWORK&lt;span&gt;            &lt;/span&gt;AREA&lt;span&gt;    &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;0&lt;span&gt;   &lt;/span&gt;10.10.10.0/24&lt;span&gt;      &lt;/span&gt;Local&lt;span&gt;   &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;1&lt;span&gt;   &lt;/span&gt;10.10.20.0/24&lt;span&gt;      &lt;/span&gt;Local&lt;span&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt; &lt;!--[if gte vml 1]&gt;   &lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;br /&gt;[admin@Client1=RouterBoard] &gt; ip route pr&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;Flags: X - disabled, A - active, D - dynamic,&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;C - connect, S - static, r - rip, b - bgp, o - ospf&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;#&lt;span&gt;     &lt;/span&gt;DST-ADDRESS&lt;span&gt;        &lt;/span&gt;PREF-SRC&lt;span&gt;        &lt;/span&gt;G GATEWAY&lt;span&gt;         &lt;/span&gt;DIS&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;0 ADC 10.10.10.0/24&lt;span&gt;      &lt;/span&gt;10.10.10.2&lt;span&gt;     &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;1&lt;span&gt;  &lt;/span&gt;Do 10.10.10.0/24&lt;span&gt;     &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;2 ADC 192.168.100.0/30&lt;span&gt;   &lt;/span&gt;192.168.100.1&lt;span&gt;  &lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: arial; color: rgb(255, 255, 255);" class="MsoNormal"&gt;&lt;span&gt; &lt;/span&gt;3 ADC 192.168.200.0/30&lt;span&gt;   &lt;/span&gt;192.168.200.1&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-148295236256228871?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/148295236256228871/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=148295236256228871' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/148295236256228871'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/148295236256228871'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/setting-ospf-main-router.html' title='SETTING OSPF MAIN ROUTER'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-2445433898452016793</id><published>2008-02-11T07:08:00.000-08:00</published><updated>2008-02-11T07:12:17.544-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Script'/><title type='text'>Generate routes for stress testing BGP functionality</title><content type='html'>Here is a script that we used to quickly generate 65000 routes for stress testing bgp peer sessions on 2.9.x.&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;# Removing old route table.&lt;br /&gt;/ip route remove [/ip route find routing-mark=bgptest]&lt;br /&gt;&lt;br /&gt;# Start new routing entries.&lt;br /&gt;:local startip 10.100.1.0&lt;br /&gt;:for i from=1 to=65535 do={&lt;br /&gt;&lt;br /&gt;:log info ("adding route " . ($startip   $i�&lt;br /&gt;/ip route add dst-address=�startip   $i) . "/32") gateway=10.20.0.1 routing-mark=bgptest&lt;br /&gt;&lt;br /&gt;}&lt;/pre&gt;&lt;br /&gt;source: http://wiki.mikrotik.com/wiki/Generate_routes_for_stress_testing_BGP_functionality&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-2445433898452016793?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/2445433898452016793/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=2445433898452016793' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/2445433898452016793'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/2445433898452016793'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/generate-routes-for-stress-testing-bgp.html' title='Generate routes for stress testing BGP functionality'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-5835653657453585820</id><published>2008-02-11T01:53:00.000-08:00</published><updated>2008-02-11T01:54:12.804-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Script'/><title type='text'>Limit traffic from Rapidshare</title><content type='html'>You can use this little script to get an IP from Rapidshare...This script will look into the DNS cache, and everytime the word rapidshare comes out, it will place the IP it get to a address list, then after that you can config a queue rule to limit the traffic...&lt;br /&gt;&lt;br /&gt;:foreach i in=[/ip dns cache find] do={&lt;br /&gt; :if ([:find [/ip dns cache get $i name] "rapidshare"] &gt; 0) do={&lt;br /&gt;   :log info ("rapidshare: " . [/ip dns cache get $i name] . " (ip address " . [/ip dns cache get $i address] . ")")&lt;br /&gt;   /ip firewall address-list add address=[/ip dns cache get $i address] list=rapidshare disabled=no&lt;br /&gt; }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;Source : http://forum.mikrotik.com/viewtopic.php?p=84349#p84349&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-5835653657453585820?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/5835653657453585820/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=5835653657453585820' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/5835653657453585820'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/5835653657453585820'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/limit-traffic-from-rapidshare.html' title='Limit traffic from Rapidshare'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-1603311815758192041</id><published>2008-02-10T09:34:00.000-08:00</published><updated>2008-02-10T09:36:44.840-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VPN'/><title type='text'>Layer2 VPN Server</title><content type='html'>&lt;p&gt;Ethernet over IP (EoIP) Tunneling is a MikroTik RouterOS protocol that creates an Ethernet tunnel between two routers on top of an IP connection. A VLAN is a logical grouping that allows end users to communicate as if they were physically connected to a single isolated LAN, independent of the physical configuration of the network. &lt;/p&gt;&lt;p&gt;It's required that you have switch that support 802.1Q VLAN and shows how to setup Layer 2 VPN Server.  Configuration of switches not added coz it depends on how network you have. &lt;/p&gt;&lt;p&gt;With this example we group devices on one or more LANs that are configured ,so that they can communicate as if they were attached to the same wire when in fact they are located on a number of different LAN segments. Using EoIP you can reach routers that are connected by wireless and with vlans we then segment network. Because VLANs are based on logical instead of physical connections, they are extremely flexible. So, in my network i added a few location that goes througt fiber optic and about 40 wireless locations. &lt;/p&gt;&lt;p&gt;&lt;b&gt;Server Side:&lt;/b&gt; &lt;/p&gt; &lt;pre&gt;   First, install latest  Mikrotik OS on computer with 2 ethernet intefaces.&lt;br /&gt;&lt;/pre&gt; &lt;pre&gt;   Now lets configure them.&lt;br /&gt; &lt;br /&gt;  /interface  set 0 name=ether1-internet &lt;br /&gt;    set 1 name=ether2-trunk    &lt;br /&gt;&lt;br /&gt;  /ip address  add address=195.101.10.5/29 interface=ether1-internet comment="" disabled=no&lt;br /&gt;   &lt;br /&gt;&lt;br /&gt; Create Eoip interface for remote router1:&lt;br /&gt;&lt;br /&gt; /interface eoip&lt;br /&gt;  add name=eoip-router1 tunnel-id=310 remote-address=196.200.50.5 comment="" disabled=no&lt;br /&gt; &lt;br /&gt; Create vlan for remote router1:&lt;br /&gt;&lt;br /&gt;  /interface vlan&lt;br /&gt;  add name=vlan-router1 interface=ether2-trunk vlan-id=310 comment="" disabled=no&lt;br /&gt;&lt;/pre&gt; &lt;pre&gt;  Now bridge eoip and vlan:&lt;br /&gt;&lt;br /&gt;  /interface bridge&lt;br /&gt;  add name=bridge-to-router1&lt;br /&gt; &lt;br /&gt; /interface bridge port&lt;br /&gt;  add interface=eoip-router1 bridge=bridge-to-router1&lt;br /&gt;  add interface=vlan-router1 bridge=bridge-to-router1&lt;br /&gt; &lt;br /&gt;&lt;/pre&gt; &lt;p&gt;Now we add configuration for remote router2 &lt;/p&gt; &lt;pre&gt;  Create Eoip interface for remote router2:&lt;br /&gt;&lt;br /&gt; /interface eoip&lt;br /&gt;  add name="eoip-router2" tunnel-id=312 remote-address=196.200.50.6 comment="" disabled=no&lt;br /&gt; &lt;br /&gt; Create vlan for remote router2:&lt;br /&gt;&lt;br /&gt;  /interface vlan&lt;br /&gt;  add name=vlan-router2 interface=ether2-trunk vlan-id=312 comment="" disabled=no&lt;br /&gt;&lt;/pre&gt; &lt;pre&gt;  Now bridge eoip and vlan:&lt;br /&gt;&lt;br /&gt;  /interface bridge&lt;br /&gt;  add name=bridge-to-router2&lt;br /&gt; &lt;br /&gt; /interface bridge port&lt;br /&gt;  add interface=eoip-router2 bridge=bridge-to-router2 comment="" disabled=no&lt;br /&gt;  add interface=vlan-router2 bridge=bridge-to-router2 comment="" disabled=no&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;br /&gt;&lt;b&gt;Remote Router1 side:&lt;/b&gt; &lt;/p&gt; &lt;pre&gt;  /interface eoip&lt;br /&gt;  add name=eoip-client remote-address=195.101.10.5 tunnel-id=310 comment="" disabled=no&lt;br /&gt;&lt;br /&gt; /interface bridge&lt;br /&gt;  add name=bridge-to-router1&lt;br /&gt;   &lt;br /&gt; /interface bridge port&lt;br /&gt;  add interface=eoip-client bridge=bridge-to-router1 comment="" disabled=no&lt;br /&gt;  add interface=ether1 bridge=bridge-to-router1 comment="" disabled=no&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;b&gt;Remote Router2 side:&lt;/b&gt; &lt;/p&gt; &lt;pre&gt;   /interface eoip&lt;br /&gt;  add name=eoip-client remote-address=195.101.10.5 tunnel-id=312 comment="" disabled=no&lt;br /&gt;&lt;br /&gt; /interface bridge&lt;br /&gt;  add name=bridge-to-router2&lt;br /&gt;   &lt;br /&gt; /interface bridge port&lt;br /&gt;  add interface=eoip-client bridge=bridge-to-router2 comment="" disabled=no&lt;br /&gt;  add interface=ether1 bridge=bridge-to-router2 comment="" disabled=no&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Depends on the network you have , some modifications are required , and dont forget to add and configure conresponding VLANS on  Allied Telesyn, Cisco , etc. switches. &lt;/p&gt;&lt;p&gt;TIP: You can always add some address to bridge, just to check if there is connectivity to remote router with ping command. &lt;/p&gt;&lt;p&gt;Server side: /ip address   &lt;/p&gt; &lt;pre&gt; add adress=192.168.100.1/30 interface=bridge-to-router1 comment="" disabled=no&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;Remote router side: /ip address &lt;/p&gt; &lt;pre&gt; add address=192.168.100.2/30 interface=bridge-to-router1 comment="" disabled=no&lt;br /&gt;&lt;br /&gt;from: http://wiki.mikrotik.com/wiki/Layer2_VPN_Server&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-1603311815758192041?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/1603311815758192041/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=1603311815758192041' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/1603311815758192041'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/1603311815758192041'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/layer2-vpn-server.html' title='Layer2 VPN Server'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-8887814678759557771</id><published>2008-02-08T19:11:00.000-08:00</published><updated>2008-02-08T19:18:13.421-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VPN'/><title type='text'>IPSec VPN with Dynamic Routing / Mikrotik and Cisco</title><content type='html'>&lt;h2&gt;&lt;span class="mw-headline"&gt; Mikrotik RouterOS &lt;/span&gt;&lt;/h2&gt; &lt;p&gt;&lt;b&gt;If you are using ROS v3.0 or above, be sure to check the end of this list to see a list of necessary mod.&lt;/b&gt; &lt;/p&gt;&lt;p&gt;&lt;span style="color: rgb(255, 255, 153);"&gt;First should configure a Tunnel Interface:&lt;/span&gt; &lt;/p&gt; &lt;pre&gt;   / interface ipip&lt;br /&gt;  add name="Tunnel1" mtu=1480 local-address=10.10.1.100 remote-address=10.10.1.200 comment="" disabled=no&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;span style="color: rgb(255, 255, 153);"&gt;After that all interfaces are configured, than should asign IP addresses for interfaces:&lt;/span&gt; &lt;/p&gt; &lt;pre&gt;   / ip address&lt;br /&gt;  add address=10.10.1.100/24 network=10.10.1.0 broadcast=10.10.1.255 interface=WAN comment="" disabled=no&lt;br /&gt;  add address=192.168.1.1/24 network=192.168.1.0 broadcast=192.168.1.255 interface=LAN comment="" disabled=no&lt;br /&gt;  add address=172.16.0.1/30 network=172.16.0.0 broadcast=192.168.0.3 interface=Tunnel1 comment="" disabled=no&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;span style="color: rgb(255, 255, 204);"&gt;Enable Routing in Mikrotik Router, in this case RIP:&lt;/span&gt; &lt;/p&gt; &lt;pre&gt;  / routing rip&lt;br /&gt; set redistribute-static=no redistribute-connected=no redistribute-ospf=no redistribute-bgp=no metric-static=1 \&lt;br /&gt; metric-connected=1  metric-ospf=1 metric-bgp=1 update-timer=30s timeout-timer=3m garbage-timer=2m&lt;br /&gt; &lt;b&gt;/ routing rip interface&lt;/b&gt;&lt;br /&gt; &lt;b&gt;add interface=Tunnel1 receive=v2 send=v2 authentication=none authentication-key="" prefix-list-in="" prefix-list-out=""&lt;/b&gt;&lt;br /&gt; / routing rip neighbor&lt;br /&gt; add address=172.16.0.2&lt;br /&gt; / routing rip network&lt;br /&gt; add address=192.168.1.0/24&lt;br /&gt; add address=172.16.0.0/30&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;span style="color: rgb(255, 255, 153);"&gt;IPSec setup, here should be defined the ipsec policy, peer and proposal. Make sure that policy should not have enabled option tunnel, in this case tunel should be set to NO, because it will be used the transport mode of IPSec not the tunnel mode:&lt;/span&gt; &lt;/p&gt; &lt;pre&gt;  &lt;b&gt;/ ip ipsec proposal&lt;/b&gt;&lt;br /&gt; &lt;b&gt;add name="IPSec" auth-algorithms=md5 enc-algorithms=3des lifetime=30m lifebytes=0 pfs-group=modp1024 disabled=no&lt;/b&gt;&lt;br /&gt; &lt;b&gt;/ ip ipsec peer&lt;/b&gt;&lt;br /&gt; &lt;b&gt;add address=10.10.1.200 secret="ipsec" generate-policy=no exchange-mode=main send-initial-contact=yes \&lt;/b&gt;&lt;br /&gt; &lt;b&gt;proposal-check=obey   hash-algorithm=md5 enc-algorithm=3des dh-group=modp1024 lifetime=1d lifebytes=0 disabled=no&lt;/b&gt;&lt;br /&gt; / ip ipsec policy&lt;br /&gt; add src-address=10.10.1.100/32:any dst-address=10.10.1.200/32:any protocol=all action=encrypt level=require \&lt;br /&gt; ipsec-protocols=esp  tunnel=no sa-src-address=10.10.1.100 sa-dst-address=10.10.1.200 \&lt;br /&gt; proposal=IPSec manual-sa=none dont-fragment=clear disabled=no&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;b&gt;In V3.0 the bolded line will change on:&lt;/b&gt; &lt;/p&gt; &lt;pre&gt;  / routing rip interface&lt;br /&gt; add interface=Tunnel1 receive=v2 send=v2 authentication=none authentication-key="" in-prefix-list="" out-prefix-list=""&lt;br /&gt; / ip ipsec proposal&lt;br /&gt; add name="IPSec" auth-algorithms=md5 enc-algorithms=3des lifetime=30m pfs-group=modp1024 disabled=no&lt;br /&gt; / ip ipsec peer&lt;br /&gt; add address=10.10.1.200/32:500 secret="ipsec" generate-policy=no exchange-mode=main send-initial-contact=yes \&lt;br /&gt; proposal-check=obey   hash-algorithm=md5 enc-algorithm=3des dh-group=modp1024 lifetime=1d lifebytes=0 disabled=no&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;br /&gt;&lt;/p&gt; &lt;a name="Cisco_IOS"&gt;&lt;/a&gt;&lt;h2&gt;&lt;span class="editsection"&gt;&lt;/span&gt;&lt;span class="mw-headline"&gt; Cisco IOS &lt;/span&gt;&lt;/h2&gt; &lt;p&gt;&lt;span style="color: rgb(255, 255, 153);"&gt;Cisco Interfaces and addresses:&lt;/span&gt; &lt;/p&gt; &lt;pre&gt;  FastEthernet 0/0&lt;br /&gt;  description *** WAN ***&lt;br /&gt;  ip address 10.10.1.200 255.255.255.0&lt;br /&gt;  crypto map vpn&lt;br /&gt;&lt;/pre&gt; &lt;pre&gt;  FastEthernet 0/1&lt;br /&gt;  description *** LAN ***&lt;br /&gt;  ip address 192.168.2.1 255.255.255.0&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;span style="color: rgb(255, 255, 153);"&gt;Cisco Tunnel Interface:&lt;/span&gt; &lt;/p&gt; &lt;pre&gt;  interface Tunnel1&lt;br /&gt; description **Cisco Peer**&lt;br /&gt; ip address 172.16.0.2 255.255.255.252&lt;br /&gt; no ip redirects&lt;br /&gt; no ip unreachables&lt;br /&gt; no ip proxy-arp&lt;br /&gt; ip mtu 1480&lt;br /&gt; ip rip v2-broadcast&lt;br /&gt; ip tcp adjust-mss 1400&lt;br /&gt; load-interval 30&lt;br /&gt; tunnel source 10.10.1.200&lt;br /&gt; tunnel destination 10.10.1.100&lt;br /&gt; tunnel mode ipip&lt;br /&gt; hold-queue 1024 in&lt;br /&gt; hold-queue 1024 out&lt;br /&gt;&lt;/pre&gt; &lt;p style="color: rgb(255, 255, 153);"&gt;Routing in Cisco: &lt;/p&gt; &lt;pre&gt;  router rip&lt;br /&gt;  version 2&lt;br /&gt;  timers basic 30 60 90 90&lt;br /&gt;  redistribute connected metric 1 route-map connected-to-rip&lt;br /&gt;  redistribute static metric 5 route-map static-to-rip&lt;br /&gt;  network 172.16.0.2&lt;br /&gt;  network 192.168.2.0&lt;br /&gt;  distribute-list prefix LAN out&lt;br /&gt;  no auto-summary&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;span style="color: rgb(255, 255, 153);"&gt;Setup the prefix-list to match the Local subnet:&lt;/span&gt; &lt;/p&gt; &lt;pre&gt;  ip prefix-list LAN seq 10 permit 192.168.2.0/24&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;span style="color: rgb(255, 255, 153);"&gt;Setup route-maps to match interfaces to be advertised by RIP:&lt;/span&gt; &lt;/p&gt; &lt;pre&gt;  route-map connected-to-rip permit 10&lt;br /&gt; match interface FastEthernet0/0&lt;br /&gt; !&lt;br /&gt; route-map static-to-rip permit 10&lt;br /&gt; match ip address prefix-list LAN&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;span style="color: rgb(255, 255, 153);"&gt;IPSec and Crypto setup in Cisco, also here trasnport mode of IPSec should be setup:&lt;/span&gt; &lt;/p&gt; &lt;pre&gt; !&lt;br /&gt; crypto isakmp policy 1&lt;br /&gt;  encr 3des&lt;br /&gt;  hash md5&lt;br /&gt;  authentication pre-share&lt;br /&gt;  group 2&lt;br /&gt; !&lt;br /&gt; crypto isakmp key ipsec address 0.0.0.0 0.0.0.0&lt;br /&gt; !&lt;br /&gt; crypto ipsec security-association idle-time 600&lt;br /&gt; !&lt;br /&gt; crypto ipsec transform-set vpn esp-3des esp-md5-hmac&lt;br /&gt;  mode transport&lt;br /&gt; !&lt;br /&gt; crypto map vpn 1 ipsec-isakmp&lt;br /&gt;  description **To Mikrotik Peer**&lt;br /&gt;  set peer 10.10.1.100&lt;br /&gt;  set transform-set vpn&lt;br /&gt;  set pfs group2&lt;br /&gt;  match address mikrotik_peer&lt;br /&gt; !&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;span style="color: rgb(255, 255, 153);"&gt;Setup access-list to match the IPSec peer:&lt;/span&gt; &lt;/p&gt; &lt;pre&gt;  ip access-list extended mikrotik_peer&lt;br /&gt;  permit ipinip host 10.10.1.200 host 10.10.1.100&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;span style="color: rgb(255, 255, 153);"&gt;Type this in "enable" mode to view your routing table (after succesfull RIP update):&lt;/span&gt; &lt;/p&gt; &lt;pre&gt;  sh ip route&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;or &lt;/p&gt; &lt;pre&gt;  sh ip rip database&lt;br /&gt;&lt;/pre&gt; &lt;p style="color: rgb(255, 255, 153);"&gt;This example can be implemented also with another routing protocol like OSPF, and also very simply we can setup here a failover connection. Regarding the failover, the setup is very easy, all that we need is to create another set of tunnels via another ISP or gateway, but again the remote peer is the same router. Instead of the routing protocol for the second set of tunnels, it needs static routes to be configured, only that the static routes should have higher distance than the dynamic protocol. The idea is that, when the primary link will go down (dynamic routing distance=120) than the backup link becomes active (static routes distance=200), as soon as the primary link will come up, it will put the failover link in inactive mode.&lt;a href="http://wiki.mikrotik.com/index.php?title=Titolo_del_collegamento&amp;amp;action=edit" class="new" title="Titolo del collegamento"&gt;Titolo del collegamento&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;p style="color: rgb(255, 255, 153);"&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p style="color: rgb(255, 255, 153);"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="color: rgb(255, 255, 153);"&gt;from http://wiki.mikrotik.com/wiki/IPSec_VPN_with_Dynamic_Routing_/_Mikrotik_and_Cisco&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-8887814678759557771?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/8887814678759557771/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=8887814678759557771' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/8887814678759557771'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/8887814678759557771'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/ipsec-vpn-with-dynamic-routing-mikrotik.html' title='IPSec VPN with Dynamic Routing / Mikrotik and Cisco'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-2858678773034758626</id><published>2008-02-08T09:50:00.000-08:00</published><updated>2008-02-08T10:19:58.133-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Wireless'/><title type='text'>Mesh wds</title><content type='html'>&lt;h2&gt;&lt;span class="mw-headline"&gt;Configuration of the AP Mesh router&lt;/span&gt;&lt;/h2&gt; &lt;ul&gt;&lt;li&gt;&lt;span style="color: rgb(255, 255, 204);"&gt;Add the Bridge interface&lt;/span&gt; &lt;/li&gt;&lt;/ul&gt; &lt;pre&gt;/interface bridge add name=bridge1 protocol-mode=rstp&lt;br /&gt;&lt;/pre&gt; &lt;ul&gt;&lt;li&gt;&lt;span style="color: rgb(255, 255, 204);"&gt;Add Ethernet and Wireless interfaces to the bridge group&lt;/span&gt; &lt;/li&gt;&lt;/ul&gt; &lt;pre&gt;/interface bridge port add interface=ether1 bridge=bridge1&lt;br /&gt;/interface bridge port add interface=wlan1 bridge=bridge1&lt;br /&gt;&lt;/pre&gt; &lt;ul&gt;&lt;li&gt;&lt;span style="color: rgb(255, 255, 204);"&gt;Configure the Wireless card as AP and to support WDS&lt;/span&gt; &lt;/li&gt;&lt;/ul&gt; &lt;pre&gt;/interface wireless set wlan1 mode=ap-bridge band=2.4ghz-b/g frequency=2437&lt;br /&gt;ssid=mesh wds-mode=dynamic wds-default-bridge=bridge1  disabled=no&lt;br /&gt;&lt;/pre&gt; &lt;ul&gt;&lt;li&gt;&lt;span style="color: rgb(255, 255, 204);"&gt;Create WPA2-EAP security profile&lt;/span&gt; &lt;/li&gt;&lt;/ul&gt; &lt;pre&gt;/interface wireless security-profiles add name=WPA2 mode=dynamic-keys&lt;br /&gt;authentication-types=wpa2-eap unicast-ciphers=aes-ccm  group-ciphers=aes-ccm eap-methods=eap-tls tls-mode=no-certificates&lt;br /&gt;&lt;/pre&gt; &lt;ul style="color: rgb(255, 255, 204);"&gt;&lt;li&gt;Specify the connect list to apply WPA2 security profile for the WDS links &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;span style="color: rgb(255, 255, 204);"&gt;The communication between the APs using WDS will be encrypted using WPA2 security profile, but the clients will be able to connect to the APs without the encryption.&lt;/span&gt; &lt;/p&gt; &lt;pre&gt;/interface wireless connect-list add interface=wlan1 security-profile=WPA2&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-2858678773034758626?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/2858678773034758626/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=2858678773034758626' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/2858678773034758626'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/2858678773034758626'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/mesh-wds.html' title='Mesh wds'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-1677494952523579370</id><published>2008-02-07T23:33:00.000-08:00</published><updated>2008-02-07T23:36:32.974-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Script'/><title type='text'>Limit Different Bandwidth In Day and Night</title><content type='html'>&lt;p&gt;&lt;b&gt;Limit Different Bandwidth In Day and Night.&lt;/b&gt; &lt;/p&gt;&lt;p&gt;T&lt;span style="font-style: italic;"&gt;here are lot many ways to limit bandwidth for day and Night, but personally I found this is the easiest way, Here it is. &lt;/span&gt;&lt;/p&gt;&lt;p style="font-style: italic;"&gt;I have used Simple Queue, Script and Scheduler. &lt;/p&gt;&lt;p&gt;&lt;span style="font-style: italic;"&gt;Suppose we have one network &lt;/span&gt;&lt;b style="font-style: italic;"&gt;192.168.1.0/24&lt;/b&gt;&lt;span style="font-style: italic;"&gt; and want to limit Bandwidth for day and Night Time.&lt;/span&gt; &lt;/p&gt; &lt;pre&gt;Network 192.168.1.0/24&lt;br /&gt;Bandwidth = 06:00am – 18:00pm – 1Mbps. &lt;max-limit&gt;&lt;br /&gt;Bandwidth = 18:00pm – 06:00am – 2Mbps. &lt;max-limit&gt;&lt;/pre&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Create two simple queues for the same network with different Bandwidth Limit.&lt;/span&gt; &lt;/p&gt; &lt;pre&gt;/queue simple&lt;br /&gt;#name=”Day” target-addresses=192.168.1.0/24 dst-address=0.0.0.0/0&lt;br /&gt;interface=&lt;ether-x&gt; parent=none direction=both priority=8&lt;br /&gt;queue=default-small/default-small limit-at=512k/512k&lt;br /&gt;max-limit=1M/1M total-queue=default-small&lt;br /&gt;&lt;br /&gt;#name=”Night” target-addresses=192.168.1.0/24 dst-address=0.0.0.0/0&lt;br /&gt;interface=&lt;ether-x&gt; parent=none direction=both priority=8&lt;br /&gt;queue=default-small/default-small limit-at=1M/1M&lt;br /&gt;max-limit=2M/2M total-queue=default-small&lt;/pre&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Now, write scripts&lt;/span&gt; &lt;/p&gt; &lt;pre&gt;/system script&lt;br /&gt;#name=”Day” source=/queue simple enable Day; /queue simple disable Night&lt;br /&gt;&lt;br /&gt;#name=”Night” source=/queue simple enable Night; /queue simple disable Day&lt;/pre&gt; &lt;p style="font-weight: bold;"&gt;Finally, Schedule it &lt;/p&gt; &lt;pre&gt;/system scheduler&lt;br /&gt;#name=”Day” on-event=Day start-date=oct/13/2007 start-time=06:00:00 interval=1d&lt;br /&gt;&lt;br /&gt;#name=”Night” on-event=Night start-date=oct/13/2007 start-time=18:00:00 interval=1d&lt;br /&gt;&lt;br /&gt;from: http://wiki.mikrotik.com/wiki/Limit_Different_Bandwidth_In_Day_and_Night&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-1677494952523579370?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/1677494952523579370/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=1677494952523579370' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/1677494952523579370'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/1677494952523579370'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/limit-different-bandwidth-in-day-and.html' title='Limit Different Bandwidth In Day and Night'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-8088362619504936980</id><published>2008-02-07T07:35:00.000-08:00</published><updated>2008-02-07T07:39:57.135-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Script'/><title type='text'>Generate bogons firewall chain based on routing-marks</title><content type='html'>&lt;pre&gt;Code:&lt;br /&gt;## Builds an address list with bogons based on the&lt;br /&gt;## learned bgp routes which have the specific routing-mark.&lt;br /&gt;&lt;br /&gt;:log info "Removing all BOGONS, starting sync."&lt;br /&gt;:foreach subnet in [/ip firewall address-list find list=bogons] do {&lt;br /&gt; /ip firewall address-list remove $subnet&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;:foreach subnet in [/ip route find routing-mark=bogons] do {&lt;br /&gt; :set bogon [/ip route get $subnet dst-address]&lt;br /&gt; :log info ("Found " . $bogon . " as bogon entry.")&lt;br /&gt; /ip firewall address-list add list=bogons address=$bogon&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;p&gt;&lt;span style="color: rgb(255, 255, 204);"&gt;Now you can use this type of chain to catch traffic coming from bogon ip addresses. Reference / jump to this chain from wherever you have traffic coming from untrusted networks. You'll notice that the first few entries are bypasses for specific bogons that are allowed.&lt;/span&gt; &lt;/p&gt; add chain=BOGONS src-address=10.8.24.1 protocol=icmp action=return \     comment="Bypass for cable modem internal IP \(Traceroutes requires \     this\)" disabled=no  add chain=BOGONS src-address=192.168.100.0/24 action=return \     comment="CABLE INTERNAL IP - Bypass also" disabled=no  add chain=BOGONS limit=2,5 src-address-list=bogons action=log \     log-prefix="BOGONS" comment="Reference the BOGONS address-list and \     LOG any that are on that list." disabled=no  add chain=BOGONS src-address-list=bogons action=drop \     comment="Reference the BOGONS address-list and DROP any that are \     on that list." disabled=no  add chain=BOGONS action=return comment="If not, return them to the \     previous chain." disabled=no   &lt;p&gt;Here is the current (12/05) chain if you just want to copy and paste it into your ruleset. &lt;/p&gt; / ip firewall address-list  add list=bogons address=1.0.0.0/8 comment="" disabled=no  add list=bogons address=2.0.0.0/8 comment="" disabled=no  add list=bogons address=5.0.0.0/8 comment="" disabled=no  add list=bogons address=7.0.0.0/8 comment="" disabled=no  add list=bogons address=10.0.0.0/8 comment="" disabled=no  add list=bogons address=23.0.0.0/8 comment="" disabled=no  add list=bogons address=27.0.0.0/8 comment="" disabled=no  add list=bogons address=31.0.0.0/8 comment="" disabled=no  add list=bogons address=36.0.0.0/8 comment="" disabled=no  add list=bogons address=37.0.0.0/8 comment="" disabled=no  add list=bogons address=39.0.0.0/8 comment="" disabled=no  add list=bogons address=42.0.0.0/8 comment="" disabled=no  add list=bogons address=49.0.0.0/8 comment="" disabled=no  add list=bogons address=50.0.0.0/8 comment="" disabled=no  add list=bogons address=77.0.0.0/8 comment="" disabled=no  add list=bogons address=78.0.0.0/8 comment="" disabled=no  add list=bogons address=79.0.0.0/8 comment="" disabled=no  add list=bogons address=92.0.0.0/8 comment="" disabled=no  add list=bogons address=93.0.0.0/8 comment="" disabled=no  add list=bogons address=94.0.0.0/8 comment="" disabled=no  add list=bogons address=95.0.0.0/8 comment="" disabled=no  add list=bogons address=96.0.0.0/8 comment="" disabled=no  add list=bogons address=97.0.0.0/8 comment="" disabled=no  add list=bogons address=98.0.0.0/8 comment="" disabled=no  add list=bogons address=99.0.0.0/8 comment="" disabled=no  add list=bogons address=100.0.0.0/8 comment="" disabled=no  add list=bogons address=101.0.0.0/8 comment="" disabled=no  add list=bogons address=102.0.0.0/8 comment="" disabled=no  add list=bogons address=103.0.0.0/8 comment="" disabled=no  add list=bogons address=104.0.0.0/8 comment="" disabled=no  add list=bogons address=105.0.0.0/8 comment="" disabled=no  add list=bogons address=106.0.0.0/8 comment="" disabled=no  add list=bogons address=107.0.0.0/8 comment="" disabled=no  add list=bogons address=108.0.0.0/8 comment="" disabled=no  add list=bogons address=109.0.0.0/8 comment="" disabled=no  add list=bogons address=110.0.0.0/8 comment="" disabled=no  add list=bogons address=111.0.0.0/8 comment="" disabled=no  add list=bogons address=112.0.0.0/8 comment="" disabled=no  add list=bogons address=113.0.0.0/8 comment="" disabled=no  add list=bogons address=114.0.0.0/8 comment="" disabled=no  add list=bogons address=115.0.0.0/8 comment="" disabled=no  add list=bogons address=116.0.0.0/8 comment="" disabled=no  add list=bogons address=117.0.0.0/8 comment="" disabled=no  add list=bogons address=118.0.0.0/8 comment="" disabled=no  add list=bogons address=119.0.0.0/8 comment="" disabled=no  add list=bogons address=120.0.0.0/8 comment="" disabled=no  add list=bogons address=121.0.0.0/8 comment="" disabled=no  add list=bogons address=122.0.0.0/8 comment="" disabled=no  add list=bogons address=123.0.0.0/8 comment="" disabled=no  add list=bogons address=169.254.0.0/16 comment="" disabled=no  add list=bogons address=172.16.0.0/12 comment="" disabled=no  add list=bogons address=173.0.0.0/8 comment="" disabled=no  add list=bogons address=174.0.0.0/8 comment="" disabled=no  add list=bogons address=175.0.0.0/8 comment="" disabled=no  add list=bogons address=176.0.0.0/8 comment="" disabled=no  add list=bogons address=177.0.0.0/8 comment="" disabled=no  add list=bogons address=178.0.0.0/8 comment="" disabled=no  add list=bogons address=179.0.0.0/8 comment="" disabled=no  add list=bogons address=180.0.0.0/8 comment="" disabled=no  add list=bogons address=181.0.0.0/8 comment="" disabled=no  add list=bogons address=182.0.0.0/8 comment="" disabled=no  add list=bogons address=183.0.0.0/8 comment="" disabled=no  add list=bogons address=184.0.0.0/8 comment="" disabled=no  add list=bogons address=185.0.0.0/8 comment="" disabled=no  add list=bogons address=186.0.0.0/8 comment="" disabled=no  add list=bogons address=187.0.0.0/8 comment="" disabled=no  add list=bogons address=192.0.2.0/24 comment="" disabled=no  add list=bogons address=192.168.0.0/16 comment="" disabled=no  add list=bogons address=197.0.0.0/8 comment="" disabled=no  add list=bogons address=198.18.0.0/15 comment="" disabled=no  add list=bogons address=223.0.0.0/8 comment="" disabled=no &lt;pre&gt;&lt;br /&gt;original script http://wiki.mikrotik.com/wiki/Generate_bogons_firewall_chain_based_on_routing-marks&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-8088362619504936980?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/8088362619504936980/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=8088362619504936980' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/8088362619504936980'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/8088362619504936980'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/generate-bogons-firewall-chain-based-on.html' title='Generate bogons firewall chain based on routing-marks'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-1861754776335423585</id><published>2008-02-07T04:41:00.000-08:00</published><updated>2008-02-07T07:01:56.004-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Script'/><title type='text'>Script Send Backup email</title><content type='html'>&lt;pre&gt;/ tool e-mail&lt;br /&gt;set server=1.2.3.4 from="SomeSystemName@somewhere.tld"&lt;br /&gt;&lt;/pre&gt;&lt;h2&gt;&lt;span class="mw-headline"&gt; "Generate a Backup" Script &lt;/span&gt;&lt;/h2&gt; &lt;a name="Example_1"&gt;&lt;/a&gt;&lt;h3&gt;&lt;span class="editsection"&gt;&lt;/span&gt; &lt;span class="mw-headline"&gt;Example 1 &lt;/span&gt;&lt;/h3&gt; / system script add name="backup_mail" source="/system backup save name=email_backup \n/tool \    e-mail send file=email_backup.backup to=\"someone@somewhere.tld\" body=\"See \    attached file for System Backup\" subject=\(\[/system identity get name\] \    . \" \" .  \[/system clock get time\] . \" \" . \[/system clock get date\] \    . \"  Backup\"\)\n"&lt;br /&gt;&lt;h3&gt;&lt;span class="mw-headline"&gt; Example 2 &lt;/span&gt;&lt;/h3&gt; &lt;pre&gt;:log info "backup beginning now"&lt;br /&gt;:global backupfile ([/system identity get name] . "-" . [/system clock get time])&lt;br /&gt;/system backup save name=$backupfile&lt;br /&gt;:log info "backup pausing for 10s"&lt;br /&gt;:delay 10s&lt;br /&gt;:log info "backup being emailed"&lt;br /&gt;/tool e-mail send to="USERNAME@gmail.com" subject=([/system identity get name] . \&lt;br /&gt;" Backup") from=ROUTER@MAIDOMAIN.com file=$backupfile server=1.3.3.7&lt;br /&gt;:log info "backup finished"&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;h2&gt;&lt;span class="mw-headline"&gt; "Weekly Scheduler" Script &lt;/span&gt;&lt;/h2&gt; &lt;a name="Example_1_2"&gt;&lt;/a&gt;&lt;h3&gt;&lt;span class="editsection"&gt;&lt;/span&gt; &lt;span class="mw-headline"&gt;Example 1 &lt;/span&gt;&lt;/h3&gt; / system scheduler add name="sched_backup_mail" on-event="backup_mail" start-date=jan/01/1970 start-time=07:30:00 interval=7d \ comment="" disabled=no  &lt;a name="Example_2_2"&gt;&lt;/a&gt;&lt;h3&gt;&lt;span class="editsection"&gt;&lt;/span&gt;&lt;span class="mw-headline"&gt;Example 2 &lt;/span&gt;&lt;/h3&gt; /system script add name=ebackup source={/system backup save name=([/system identity get name] . "-" . \ [:pick [/system clock get date] 7 11] . [:pick [/system clock get date] 0 3] . [:pick [/system clock get date] 4 6]); \ /tool e-mail send to="youremail@yourdomain.com" subject=([/system identity get name] . " Backup " . \ [/system clock get date]) file=([/system identity get name] . "-" . [:pick [/system clock get date] 7 11] . \ [:pick [/system clock get date] 0 3] . [:pick [/system clock get date] 4 6] . ".backup"); :delay 10; \ /file rem [/file find name=([/system identity get name] . "-" . [:pick [/system clock get date] 7 11] . \ [:pick [/system clock get date] 0 3] . [:pick [/system clock get date] 4 6] . ".backup")]; \ :log info ("System Backup emailed at " . [/sys cl get time] . " " . [/sys cl get date])} &lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-1861754776335423585?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/1861754776335423585/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=1861754776335423585' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/1861754776335423585'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/1861754776335423585'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/script-send-backup-email.html' title='Script Send Backup email'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-5661328318475582088</id><published>2008-02-06T09:40:00.000-08:00</published><updated>2008-02-07T06:57:00.085-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Script'/><title type='text'>Siren alarm script</title><content type='html'>:for c from=1 to=50 step=1  \&lt;br /&gt;&lt;br /&gt;do={ \&lt;br /&gt;     :set i 15&lt;br /&gt;      :set x 1900&lt;br /&gt;&lt;br /&gt;     :do {\&lt;br /&gt;             :beep length=400ms frequency=$x; :delay 25ms&lt;br /&gt;             :set i ($i - 1);&lt;br /&gt;             :set x ($x +35)&lt;br /&gt;&lt;br /&gt;           } \&lt;br /&gt;             while (($i &lt;16)&gt;0))&lt;br /&gt;            :beep length=0 frequency=0&lt;br /&gt;}&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-5661328318475582088?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/5661328318475582088/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=5661328318475582088' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/5661328318475582088'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/5661328318475582088'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/siren-alarm-script.html' title='Siren alarm script'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-1819275775599863629</id><published>2008-02-05T21:10:00.000-08:00</published><updated>2008-02-07T06:58:34.445-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Firewall'/><title type='text'>Standart Firewall (Standart firewall setting)</title><content type='html'>/ip firewall filter add chain=forward connection-state=invalid action=drop comment="Drop invalid connections" disabled=no&lt;br /&gt;/ip firewall filter add chain=forward connection-state=established action=accept comment="Established Connections" disabled=no&lt;br /&gt;/ip firewall filter add chain=forward connection-state=related action=accept comment="Related connections" disabled=no&lt;br /&gt;/ip firewall filter add chain=forward action=jump jump-target=virus comment="!!! Check for well-known viruses !!!" disabled=no&lt;br /&gt;/ip firewall filter add chain=forward protocol=udp action=accept comment="UDP" disabled=no&lt;br /&gt;/ip firewall filter add chain=forward protocol=icmp limit=50/5,2 action=accept comment="Allow limited Pings" disabled=no&lt;br /&gt;/ip firewall filter add chain=forward protocol=icmp action=drop comment="Drop excess pings" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/ip firewall filter add chain=input connection-state=invalid action=drop comment="Drop invalid connections" disabled=no&lt;br /&gt;/ip firewall filter add chain=input tcp-flags=!syn connection-state=established action=accept comment="Accept established connections" disabled=no&lt;br /&gt;/ip firewall filter add chain=input connection-state=related action=accept comment="Accept related connections" disabled=no&lt;br /&gt;/ip firewall filter add chain=input action=jump jump-target=virus comment="!!! Check for well-known viruses !!!" disabled=no&lt;br /&gt;/ip firewall filter add chain=input protocol=udp action=accept comment="UDP" disabled=no&lt;br /&gt;/ip firewall filter add chain=input protocol=icmp limit=50/5,2 action=accept comment="Allow limited pings" disabled=no&lt;br /&gt;/ip firewall filter add chain=input protocol=icmp action=drop comment="Drop excess pings" disabled=no&lt;br /&gt;/ip firewall filter add chain=input dst-port=22 protocol=tcp action=accept comment="SSH for demo purposes" disabled=no&lt;br /&gt;/ip firewall filter add chain=input dst-port=23 protocol=tcp action=accept comment="Telnet for demo purposes" disabled=no&lt;br /&gt;/ip firewall filter add chain=input dst-port=80 protocol=tcp action=accept comment="http for demo purposes" disabled=no&lt;br /&gt;/ip firewall filter add chain=input dst-port=3987 protocol=tcp action=accept comment="winbox for demo purposes" disabled=no&lt;br /&gt;/ip firewall filter add chain=input action=accept log=yes comment="Log and drop everything else" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/ip firewall filter add chain=virus dst-port=135-139 protocol=tcp action=drop comment="Drop Blaster Worm" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=135-139 protocol=udp action=drop comment="Drop Messenger Worm" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=445 protocol=tcp action=drop comment="Drop Blaster Worm" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=445 protocol=udp action=drop comment="Drop Blaster Worm" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=593 protocol=tcp action=drop comment="________" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=1024-1030 protocol=tcp action=drop comment="________" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=1080 protocol=tcp action=drop comment="Drop MyDoom" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=1214 protocol=tcp action=drop comment="________" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=1363 protocol=tcp action=drop comment="ndm requester" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=1364 protocol=tcp action=drop comment="ndm server" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=1368 protocol=tcp action=drop comment="screen cast" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=1373 protocol=tcp action=drop comment="hromgrafx" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=1377 protocol=tcp action=drop comment="cichlid" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=1433-1434 protocol=tcp action=drop comment="Worm" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=2745 protocol=tcp action=drop comment="Bagle Virus" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=2283 protocol=tcp action=drop comment="Drop Dumaru.Y" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=2535 protocol=tcp action=drop comment="Drop Beagle" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=2745 protocol=tcp action=drop comment="Drop Beagle.C-K" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=3127-3128 protocol=tcp action=drop comment="Drop MyDoom" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=3410 protocol=tcp action=drop comment="Drop Backdoor OptixPro" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=4444 protocol=tcp action=drop comment="Worm" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=4444 protocol=udp action=drop comment="Worm" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=5554 protocol=tcp action=drop comment="Drop Sasser" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=8866 protocol=tcp action=drop comment="Drop Beagle.B" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=9898 protocol=tcp action=drop comment="Drop Dabber.A-B" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=10000 protocol=tcp action=drop comment="Drop Dumaru.Y" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=10080 protocol=tcp action=drop comment="Drop MyDoom.B" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=12345 protocol=tcp action=drop comment="Drop NetBus" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=17300 protocol=tcp action=drop comment="Drop Kuang2" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=27374 protocol=tcp action=drop comment="Drop SubSeven" disabled=no&lt;br /&gt;/ip firewall filter add chain=virus dst-port=65506 protocol=tcp action=drop comment="Drop PhatBot, Agobot, Gaobot" disabled=no&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-1819275775599863629?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/1819275775599863629/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=1819275775599863629' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/1819275775599863629'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/1819275775599863629'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/standart-firewall-standart-firewall.html' title='Standart Firewall (Standart firewall setting)'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-571594854006371142</id><published>2008-02-05T08:10:00.000-08:00</published><updated>2008-02-07T06:58:34.447-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Firewall'/><title type='text'>Dmitry on firewalling</title><content type='html'>&lt;h2&gt;&lt;span class="editsection"&gt;&lt;/span&gt;&lt;span class="mw-headline"&gt;Protocol classifier&lt;/span&gt;&lt;/h2&gt;&lt;br /&gt;&lt;pre&gt;/ ip firewall mangle&lt;br /&gt;add chain=prerouting protocol=tcp connection-state=new action=jump jump-target=tcp-services&lt;br /&gt;add chain=prerouting protocol=udp connection-state=new action=jump jump-target=udp-services&lt;br /&gt;add chain=prerouting connection-state=new action=jump jump-target=other-services&lt;br /&gt;&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=20-21 action=mark-connection new-connection-mark=ftp passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=513-65535 dst-port=22 action=mark-connection new-connection-mark=ssh passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=23 action=mark-connection new-connection-mark=telnet passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=25 action=mark-connection new-connection-mark=smtp passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=53 dst-port=53 action=mark-connection new-connection-mark=dns passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=53 action=mark-connection new-connection-mark=dns passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=80 action=mark-connection new-connection-mark=http passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=110 action=mark-connection new-connection-mark=pop3 passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=113 action=mark-connection new-connection-mark=auth passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=119 action=mark-connection new-connection-mark=nntp passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=143 action=mark-connection new-connection-mark=imap passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=161-162 action=mark-connection new-connection-mark=snmp passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=443 action=mark-connection new-connection-mark=https passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=465 action=mark-connection new-connection-mark=smtps passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=993 action=mark-connection new-connection-mark=imaps passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=995 action=mark-connection new-connection-mark=pop3s passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=1723 action=mark-connection new-connection-mark=pptp passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=2379 action=mark-connection new-connection-mark=kgs passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=3128 action=mark-connection new-connection-mark=proxy passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=3389 action=mark-connection new-connection-mark=win-ts passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=4242-4243 action=mark-connection new-connection-mark=emule passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=4661-4662 dst-port=1024-65535 action=mark-connection new-connection-mark=overnet passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=4711 dst-port=1024-65535 action=mark-connection new-connection-mark=emule passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=5900-5901 action=mark-connection new-connection-mark=vnc passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=6667-6669 action=mark-connection new-connection-mark=irc passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=6881-6889 action=mark-connection new-connection-mark=bittorrent passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=8080 action=mark-connection new-connection-mark=http passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp src-port=1024-65535 dst-port=8291 action=mark-connection new-connection-mark=winbox passthrough=no&lt;br /&gt;add chain=tcp-services protocol=tcp action=mark-connection new-connection-mark=other-tcp passthrough=no&lt;br /&gt;&lt;br /&gt;add chain=udp-services protocol=udp src-port=1024-65535 dst-port=53 action=mark-connection new-connection-mark=dns passthrough=no&lt;br /&gt;add chain=udp-services protocol=udp src-port=1024-65535 dst-port=123 action=mark-connection new-connection-mark=ntp passthrough=no&lt;br /&gt;add chain=udp-services protocol=udp src-port=1024-65535 dst-port=1701 action=mark-connection new-connection-mark=l2tp passthrough=no&lt;br /&gt;add chain=udp-services protocol=udp src-port=1024-65535 dst-port=4665 action=mark-connection new-connection-mark=emule passthrough=no&lt;br /&gt;add chain=udp-services protocol=udp src-port=1024-65535 dst-port=4672 action=mark-connection new-connection-mark=emule passthrough=no&lt;br /&gt;add chain=udp-services protocol=udp src-port=4672 dst-port=1024-65535 action=mark-connection new-connection-mark=emule passthrough=no&lt;br /&gt;add chain=udp-services protocol=udp src-port=1024-65535 dst-port=12053 action=mark-connection new-connection-mark=overnet passthrough=no&lt;br /&gt;add chain=udp-services protocol=udp src-port=12053 dst-port=1024-65535 action=mark-connection new-connection-mark=overnet passthrough=no&lt;br /&gt;add chain=udp-services protocol=udp src-port=36725 dst-port=1024-65535 action=mark-connection new-connection-mark=skype passthrough=no&lt;br /&gt;add chain=udp-services protocol=udp connection-state=new action=mark-connection new-connection-mark=other-udp passthrough=no&lt;br /&gt;&lt;br /&gt;add chain=other-services protocol=icmp icmp-options=8:0-255 action=mark-connection new-connection-mark=ping passthrough=no&lt;br /&gt;add chain=other-services protocol=gre action=mark-connection new-connection-mark=gre passthrough=no&lt;br /&gt;add chain=other-services action=mark-connection new-connection-mark=other passthrough=no&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;span style="font-weight: bold;" class="mw-headline"&gt;Sanity-check&lt;br /&gt;&lt;/span&gt;&lt;pre&gt;/ip firewall mangle&lt;br /&gt;add chain=prerouting in-interface=Public dst-address-list=nat-addr action=mark-packet new-packet-mark=nat-traversal passthrough=no&lt;/pre&gt;/ ip firewall address-list&lt;br /&gt;&lt;pre&gt;add list=illegal-addr address=0.0.0.0/8 comment="illegal addresses"&lt;br /&gt;add list=illegal-addr address=127.0.0.0/8&lt;br /&gt;add list=illegal-addr address=224.0.0.0/3&lt;br /&gt;add list=illegal-addr address=10.0.0.0/8&lt;br /&gt;add list=illegal-addr address=172.16.0.0/12&lt;br /&gt;add list=illegal-addr address=192.168.0.0/16&lt;br /&gt;add list=local-addr address=172.31.255.0/29 comment="my local network "&lt;br /&gt;add list=nat-addr address=172.31.255.0/29 comment="my local network"&lt;br /&gt;&lt;br /&gt;/ ip firewall filter&lt;br /&gt;add chain=forward in-interface=Local out-interface=Local action=accept comment="Allow traffic between wired and wireless networks"&lt;br /&gt;&lt;br /&gt;/ ip firewall filter&lt;br /&gt;add chain=forward action=jump jump-target=sanity-check comment="Sanity Check"&lt;br /&gt;add chain=sanity-check packet-mark=nat-traversal action=jump jump-target=drop comment="Deny illegal NAT traversal"&lt;br /&gt;add chain=sanity-check protocol=tcp psd=20,3s,3,1 action=add-src-to-address-list address-list=blocked-addr address-list-timeout=1d comment="Block port scans"&lt;br /&gt;add chain=sanity-check protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack action=add-src-to-address-list address-list=blocked-addr address-list-timeout=1d comment="Block TCP Null scan"&lt;br /&gt;add chain=sanity-check protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-address-list address-list=blocked-addr address-list-timeout=1d comment="Block TCP Xmas scan"&lt;br /&gt;add chain=sanity-check protocol=tcp src-address-list=blocked-addr action=jump jump-target=drop&lt;br /&gt;add chain=sanity-check protocol=tcp tcp-flags=rst action=jump jump-target=drop comment="Drop TCP RST"&lt;br /&gt;add chain=sanity-check protocol=tcp tcp-flags=fin,syn action=jump jump-target=drop comment="Drop TCP SYN+FIN"&lt;br /&gt;add chain=sanity-check connection-state=invalid action=jump jump-target=drop comment="Dropping invalid connections at once"&lt;br /&gt;add chain=sanity-check connection-state=established action=accept comment="Accepting already established connections"&lt;br /&gt;add chain=sanity-check connection-state=related action=accept comment="Also accepting related connections"&lt;br /&gt;add chain=sanity-check dst-address-type=broadcast,multicast action=jump jump-target=drop comment="Drop all traffic that goes to multicast or broadcast addresses"&lt;br /&gt;add chain=sanity-check in-interface=Local dst-address-list=illegal-addr dst-address-type=!local action=jump jump-target=drop comment="Drop illegal destination addresses"&lt;br /&gt;add chain=sanity-check in-interface=Local src-address-list=!local-addr action=jump jump-target=drop comment="Drop everything that goes from local interface but not from local address"&lt;br /&gt;add chain=sanity-check in-interface=Public src-address-list=illegal-addr action=jump jump-target=drop comment="Drop illegal source addresses"&lt;br /&gt;add chain=sanity-check in-interface=Public dst-address-list=!local-addr action=jump jump-target=drop comment="Drop everything that goes from public interface but not to local address"&lt;br /&gt;add chain=sanity-check src-address-type=broadcast,multicast action=jump jump-target=drop comment="Drop all traffic that goes from multicast or broadcast addresses"&lt;br /&gt;&lt;br /&gt;/ ip firewall filter&lt;br /&gt;add chain=forward protocol=tcp action=jump jump-target=restrict-tcp&lt;br /&gt;add chain=forward protocol=udp action=jump jump-target=restrict-udp&lt;br /&gt;add chain=forward action=jump jump-target=restrict-ip&lt;br /&gt;add chain=restrict-tcp connection-mark=auth action=reject&lt;br /&gt;add chain=restrict-tcp connection-mark=smtp action=jump jump-target=smtp-first-drop comment="anti-spam policy"&lt;br /&gt;add chain=smtp-first-drop src-address-list=first-smtp action=add-src-to-address-list address-list=approved-smtp&lt;br /&gt;add chain=smtp-first-drop src-address-list=approved-smtp action=return&lt;br /&gt;add chain=smtp-first-drop action=add-src-to-address-list address-list=first-smtp&lt;br /&gt;add chain=smtp-first-drop action=reject reject-with=icmp-network-unreachable&lt;br /&gt;&lt;br /&gt;/ ip firewall filter&lt;br /&gt;add chain=restrict-tcp connection-mark=other-tcp action=jump jump-target=drop&lt;br /&gt;add chain=restrict-udp connection-mark=other-udp action=jump jump-target=drop&lt;br /&gt;add chain=restrict-ip connection-mark=other action=jump jump-target=drop&lt;br /&gt;&lt;br /&gt;/ ip firewall filter&lt;br /&gt;add chain=input src-address-type=local dst-address-type=local action=accept comment="Allow local traffic \(between router applications\)"&lt;br /&gt;add chain=input in-interface=Local protocol=udp src-port=68 dst-port=67 action=jump jump-target=dhcp comment="DHCP protocol would not pass sanity checking, so enabling it explicitly before other checks"&lt;br /&gt;add chain=input action=jump jump-target=sanity-check comment="Sanity Check"&lt;br /&gt;add chain=input dst-address-type=!local action=jump jump-target=drop comment="Dropping packets not destined to the router itself, including all broadcast traffic"&lt;br /&gt;add chain=input connection-mark=ping limit=5,5 action=accept comment="Allow pings, but at a very limited rate \(5 per sec\)"&lt;br /&gt;add chain=input in-interface=Local action=jump jump-target=local-services comment="Allowing some services to be accessible from the local network"&lt;br /&gt;add chain=input in-interface=Public action=jump jump-target=public-services comment="Allowing some services to be accessible from the Internet"&lt;br /&gt;add chain=input action=jump jump-target=drop&lt;br /&gt;add chain=dhcp src-address=0.0.0.0 dst-address=255.255.255.255 action=accept&lt;br /&gt;add chain=dhcp src-address=0.0.0.0 dst-address-type=local action=accept&lt;br /&gt;add chain=dhcp src-address-list=local-addr dst-address-type=local action=accept&lt;br /&gt;add chain=local-services connection-mark=ssh action=accept comment="SSH \(22/TCP\)"&lt;br /&gt;add chain=local-services connection-mark=dns action=accept comment="DNS"&lt;br /&gt;add chain=local-services connection-mark=proxy action=accept comment="HTTP Proxy \(3128/TCP\)"&lt;br /&gt;add chain=local-services connection-mark=winbox comment="Winbox \(8291/TCP\)" disabled=no&lt;br /&gt;add chain=local-services action=drop comment="Drop Other Local Services"&lt;br /&gt;add chain=public-services connection-mark=ssh action=accept comment="SSH \(22/TCP\)"&lt;br /&gt;add chain=public-services connection-mark=pptp action=accept comment="PPTP \(1723/TCP\)"&lt;br /&gt;add chain=public-services connection-mark=gre action=accept comment="GRE for PPTP"&lt;br /&gt;add chain=public-services action=drop comment="Drop Other Public Services"&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;h2&gt;&lt;span class="mw-headline"&gt;Proxying everything&lt;/span&gt;&lt;/h2&gt;/ ip firewall nat&lt;br /&gt;&lt;pre&gt;add chain=dstnat in-interface=Local connection-mark=dns action=redirect comment="proxy for DNS requests"&lt;br /&gt;add chain=dstnat in-interface=Local connection-mark=http protocol=tcp action=redirect to-ports=3128 comment="proxy for HTTP requests"&lt;br /&gt;add chain=dstnat in-interface=Local connection-mark=ntp action=redirect comment="proxy for NTP requests"&lt;/pre&gt;&lt;h2&gt;&lt;span class="mw-headline"&gt;Enable Proxy servers&lt;/span&gt;&lt;/h2&gt;&lt;pre&gt;/ system ntp server&lt;br /&gt;set enabled=yes broadcast=no multicast=no manycast=no&lt;br /&gt;/ system ntp client&lt;br /&gt;set enabled=yes mode=unicast primary-ntp=xxx.xxx.xxx.xxx secondary-ntp=0.0.0.0&lt;br /&gt;/ ip proxy&lt;br /&gt;set enabled=yes port=3128 parent-proxy=0.0.0.0:1 maximal-client-connections=1000 maximal-server-connections=1000&lt;br /&gt;/ ip dns&lt;br /&gt;set primary-dns=yyy.yyy.yyy.yyy secondary-dns=0.0.0.0 allow-remote-requests=yes cache-size=2048KiB cache-max-ttl=1w&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-571594854006371142?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/571594854006371142/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=571594854006371142' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/571594854006371142'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/571594854006371142'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/dmitry-on-firewalling.html' title='Dmitry on firewalling'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-2490281831120854375</id><published>2008-02-05T07:55:00.000-08:00</published><updated>2008-02-07T06:58:34.447-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Firewall'/><title type='text'>Firewall 1</title><content type='html'>/ ip firewall filter&lt;br /&gt;add chain=RouterServices action=accept protocol=icmp comment="Allow ICMP" disabled=no&lt;br /&gt;add chain=RouterServices action=accept dst-port=67-68 protocol=udp comment="Allow DHCP" disabled=no&lt;br /&gt;add chain=RouterServices action=accept dst-port=53 protocol=udp comment="Allow DNS" disabled=no&lt;br /&gt;add chain=RouterServices action=accept dst-port=20561 protocol=udp comment="Allow MAC-Winbox" disabled=no&lt;br /&gt;add chain=RouterServices action=accept dst-port=8291 protocol=tcp comment="Allow Winbox" disabled=no&lt;br /&gt;add chain=RouterServices action=accept src-port=123 protocol=udp comment="Allow NTP" disabled=no&lt;br /&gt;add chain=RouterServices action=accept dst-port=123 protocol=udp comment="Allow NTP server "If we are running NTP server" disabled=no&lt;br /&gt;&lt;br /&gt;add chain=RouterServices action=accept protocol=ospf comment="Allow OSPF" disabled=yes&lt;br /&gt;add chain=RouterServices action=accept src-port=520-521 protocol=udp comment="Allow RIP" disabled=yes&lt;br /&gt;&lt;br /&gt;add chain=RouterServices action=accept src-port=520-521 protocol=tcp fragment=no time=0s-23h59m,sat,fri,thu,wed,tue,mon,sun psd=21,3s,3,1 src-address-type="" dst-address-type="" comment="Allow RIP" disabled=yes&lt;br /&gt;&lt;br /&gt;add chain=RouterServices action=accept dst-port=179 protocol=tcp comment="Allow BGP" disabled=yes&lt;br /&gt;add chain=RouterServices action=accept dst-port=3128 protocol=tcp comment="Allow web-proxy "If we are running web-proxy - DEFAULT PORT" disabled=yes&lt;br /&gt;&lt;br /&gt;add chain=RouterServices action=accept src-address=127.0.0.1 dst-address=127.0.0.1 comment="Allow localhost comms to work" disabled=no&lt;br /&gt;add chain=RouterServices action=accept dst-port=2000 protocol=tcp comment="Allow TCP bandwidth test" disabled=no&lt;br /&gt;add chain=RouterServices action=accept dst-port=2000 protocol=udp comment="Allow UDP bandwidth test" disabled=no&lt;br /&gt;add chain=RouterServices action=accept dst-port=5678 protocol=udp comment="Allow Mikrotik router discovery" disabled=no&lt;br /&gt;&lt;br /&gt;add chain=RouterServices action=accept dst-port=1701 protocol=udp comment="Allow L2TP" disabled=yes&lt;br /&gt;add chain=RouterServices action=accept dst-port=1701 protocol=tcp comment="Allow L2TP" disabled=yes&lt;br /&gt;&lt;br /&gt;add chain=RouterServices action=accept dst-port=1723 protocol=tcp comment="Allow PPTP" disabled=no&lt;br /&gt;add chain=RouterServices action=accept protocol=gre comment="Allow GRE - for PPtP and EoIP" disabled=no&lt;br /&gt;&lt;br /&gt;add chain=RouterServices action=accept dst-port=500 protocol=tcp comment="Allow ISAKMP - for IPSEC" disabled=yes&lt;br /&gt;add chain=RouterServices action=accept dst-port=500 protocol=udp comment="Allow ISAKMP - for IPSEC" disabled=yes&lt;br /&gt;add chain=RouterServices action=accept protocol=ipsec-esp comment="Allow protocol 50 - IPSEC" disabled=yes&lt;br /&gt;add chain=RouterServices action=accept protocol=ipsec-ah comment="Allow protocol 51 - IPSEC" disabled=yes&lt;br /&gt;add chain=RouterServices action=accept protocol=vrrp comment="Allow VRRP" disabled=yes&lt;br /&gt;&lt;br /&gt;add chain=input action=accept dst-port=80 protocol=tcp src-address-list=webadmin comment="Allow webadmins access to webbox - DISABLED BY DEFAULT - example for how to limit access for certain admin types" disabled=yes&lt;br /&gt;add chain=input action=accept src-address=10.10.100.101 dst-port=161 protocol=udp src-address-list=MONITORS comment="Allow the NMS to monitor SNMP on this machine - DISABLED BY DEFAULT - use only if you have an SNMP monitoring machine" disabled=yes&lt;br /&gt;&lt;br /&gt;add chain=hackertraps action=add-src-to-address-list dst-port=22 protocol=tcp address-list=hacker address-list-timeout=10s comment="Add SSH attempts to hacker list" disabled=no&lt;br /&gt;add chain=hackertraps action=add-src-to-address-list dst-port=21 protocol=tcp address-list=hacker address-list-timeout=10s comment="Add FTP attempts to hacker list" disabled=no&lt;br /&gt;add chain=hackertraps action=add-src-to-address-list dst-port=23 protocol=tcp address-list=hacker address-list-timeout=1m comment="Add telnet attempts to hacker list" disabled=no&lt;br /&gt;add chain=hackertraps action=add-src-to-address-list protocol=tcp psd=15,3s,3,1 address-list=hacker address-list-timeout=0s comment="Add port scanners to hacker list - DISABLED BY DEFAULT" disabled=no&lt;br /&gt;&lt;br /&gt;add chain=traphackers action=return src-address-list=LOCALIP comment="Insure we do not drop our local IPs if they get added to the hacker list accidentally" disabled=no&lt;br /&gt;&lt;br /&gt;add chain=input action=accept connection-state=established comment="Accept Established" disabled=no&lt;br /&gt;add chain=input action=accept connection-state=related comment="Accept Related" disabled=no&lt;br /&gt;add chain=input action=accept src-address-list=fulladmin comment="Accept ALL from fulladmin address list" disabled=no&lt;br /&gt;&lt;br /&gt;add chain=input action=jump jump-target=RouterServices comment="Jump to Router Services chain" disabled=no&lt;br /&gt;add chain=forward action=jump jump-target=traphackers comment="Jump to traphackers chain "Check to see if we have detected a hacker" disabled=no&lt;br /&gt;add chain=forward action=jump jump-target=known_viruses comment="Jump to known_viruses chain "Check for Virus Traffic" disabled=no&lt;br /&gt;&lt;br /&gt;add chain=input action=jump jump-target=hackertraps comment="Jump to hackertraps chain "trap Hacker Behavior" disabled=no&lt;br /&gt;add chain=input action=log log-prefix="INPUTFW:" comment="" disabled=no&lt;br /&gt;&lt;br /&gt;add chain=traphackers action=drop src-address-list=hacker comment="Protect customers from known hackers" disabled=no&lt;br /&gt;&lt;br /&gt;add chain=forward action=drop tcp-flags=syn protocol=tcp connection-limit=21,32 comment="allow only 20 simultaneous connections from each of the clients" disabled=no&lt;br /&gt;&lt;br /&gt;add chain=input action=drop connection-state=invalid comment="Drop invalid" disabled=no&lt;br /&gt;&lt;br /&gt;add chain=forward action=drop dst-port=25 protocol=tcp src-address-list=spammer comment="BLOCK SPAMMERS OR INFECTED USERS" disabled=no&lt;br /&gt;add chain=forward action=add-src-to-address-list dst-port=25 protocol=tcp connection-limit=30,32 limit=50,5 address-list=spammer address-list-timeout=1d comment="Detect and add-list SMTP virus or spammers" disabled=no&lt;br /&gt;add chain=forward action=drop p2p=all-p2p comment="DROP Most popular p2p protocols recognized by the MirkoTik RouterOS" disabled=no&lt;br /&gt;&lt;br /&gt;add chain=known_viruses action=drop dst-port=135-139 protocol=tcp comment="Windows Netbios" disabled=no&lt;br /&gt;add chain=known_viruses action=drop dst-port=135-139 protocol=udp comment="Windows Netbios" disabled=no&lt;br /&gt;add chain=known_viruses action=drop dst-port=445 protocol=tcp comment="Windows Netbios" disabled=no&lt;br /&gt;add chain=known_viruses action=drop dst-port=445 protocol=udp comment="Windows Netbios" disabled=no&lt;br /&gt;&lt;br /&gt;add chain=input action=drop comment="Drop all remaining traffic" disabled=no&lt;br /&gt;&lt;br /&gt;/ ip firewall address-list&lt;br /&gt;add list=fulladmin address=xx.xx.xxx.xx comment="Access for Butch home" disabled=no&lt;br /&gt;add list=fulladmin address=xx.xxxx.xxx.xxx/28 comment="Access for Jim" disabled=no&lt;br /&gt;add list=fulladmin address=10.1.3.0/24 comment="Access from private network" disabled=no&lt;br /&gt;add list=fulladmin address=xx.xx.xx.xx/27 comment="Access from public range" disabled=no&lt;br /&gt;add list=LOCALIP address=10.0.0.0/8 comment="Private Range" disabled=no&lt;br /&gt;add list=LOCALIP address=192.168.0.0/16 comment="Private Range" disabled=no&lt;br /&gt;add list=LOCALIP address=172.16.0.0/20 comment="Private Range" disabled=no&lt;br /&gt;add list=LOCALIP address=xx.xx.xx.xx/27 comment="Public Range" disabled=no&lt;br /&gt;add list=MONITORS address=10.11.1.3 comment="This is for monitoring servers" disabled=no&lt;br /&gt;add list=MONITORS address=10.13.1.3 comment="This is for monitoring servers" disabled=no&lt;br /&gt;add list=fulladmin address=192.168.200.1 comment="Allow from Border MT" disabled=no&lt;br /&gt;&lt;br /&gt;/ ip firewall service-port&lt;br /&gt;set ftp ports=21 disabled=no&lt;br /&gt;set tftp ports=69 disabled=no&lt;br /&gt;set irc ports=6667 disabled=no&lt;br /&gt;set h323 disabled=yes&lt;br /&gt;set quake3 disabled=no&lt;br /&gt;set gre disabled=yes&lt;br /&gt;set pptp disabled=yes&lt;br /&gt;&lt;br /&gt;/ ip firewall connection tracking&lt;br /&gt;set enabled=yes tcp-syn-sent-timeout=5s tcp-syn-received-timeout=5s tcp-established-timeout=1d tcp-fin-wait-timeout=10s tcp-close-wait-timeout=10s tcp-last-ack-timeout=10s tcp-time-wait-timeout=10s tcp-close-timeout=10s udp-timeout=10s udp-stream-timeout=3m icmp-timeout=10s generic-timeout=10m tcp-syncookie=no&lt;br /&gt;&lt;br /&gt;by &lt;span class="postbody"&gt;Christapher James Hasher &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-2490281831120854375?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/2490281831120854375/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=2490281831120854375' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/2490281831120854375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/2490281831120854375'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/firewall-1.html' title='Firewall 1'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6028699343644528576.post-4843713239534499932</id><published>2008-02-05T04:48:00.000-08:00</published><updated>2008-02-05T04:56:58.724-08:00</updated><title type='text'>Mikrotik Links</title><content type='html'>www.mikrotik.com Mikrotik Official&lt;br /&gt;&lt;span style="font-size:-1;"&gt;&lt;span class="a"&gt;training.&lt;b&gt;mikrotik&lt;/b&gt;.com Mikrotik Training&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:-1;"&gt;&lt;span class="a"&gt;forum.&lt;b&gt;mikrotik&lt;/b&gt;.com Mikrotik Forum&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:-1;"&gt;&lt;span class="a"&gt;mum.&lt;b&gt;mikrotik&lt;/b&gt;.com &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:-1;"&gt;&lt;b&gt;MikroTik&lt;/b&gt; User Meeting (MUM) is a conference on &lt;b&gt;MikroTik&lt;/b&gt; RouterOS software and RouterBoard hardware&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:-1;"&gt;&lt;span class="a"&gt;wiki.&lt;b&gt;mikrotik&lt;/b&gt;.com &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:-1;"&gt;This is a place where users of &lt;b&gt;MikroTik&lt;/b&gt; solutions share information&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6028699343644528576-4843713239534499932?l=mikrotik-link.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mikrotik-link.blogspot.com/feeds/4843713239534499932/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6028699343644528576&amp;postID=4843713239534499932' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/4843713239534499932'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6028699343644528576/posts/default/4843713239534499932'/><link rel='alternate' type='text/html' href='http://mikrotik-link.blogspot.com/2008/02/mikrotik-links.html' title='Mikrotik Links'/><author><name>Crash Devil</name><uri>http://www.blogger.com/profile/11856107176010725795</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
