<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2785178257139955802</id><updated>2011-07-08T11:50:09.940+07:00</updated><title type='text'>what u see, what u learn, 'n what u did</title><subtitle type='html'>Apa yang kamu lihat, Apa yang kamu pelajari, Dan Apa yang kamu lakukan...</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://tapeuwie.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2785178257139955802/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://tapeuwie.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Tape Uwie</name><uri>http://www.blogger.com/profile/12958472702638257190</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2785178257139955802.post-5372152857705991615</id><published>2010-08-18T08:45:00.002+07:00</published><updated>2010-08-18T08:53:28.078+07:00</updated><title type='text'>Setting VPN pptp di mikrotik</title><content type='html'>&lt;span class="Apple-style-span" style=";font-family:Calibri;color:black;"  &gt;&lt;span class="Apple-style-span" style=";font-family:Arial,Helvetica,sans-serif;font-size:small;"  &gt;&lt;div style="margin: 0px; padding: 10px 0px 0px;"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;b&gt;Pertama&lt;/b&gt;  : Setelah kita mendapatkan IP Public,  selanjutnya kita akan melakukan konfigurasi PPP -&gt;  PPTP SERVER.  (Point To Point Tunneling Protocol).&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div id="TixyyLink"  style="background-color: transparent; border: medium none; overflow: hidden; text-align: left; text-decoration: none;color:black;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_-KXHPDKPHqc/S-IOxRbvGNI/AAAAAAAAAGQ/NqLpvMQZzhI/s1600/04.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img src="http://1.bp.blogspot.com/_-KXHPDKPHqc/S-IOxRbvGNI/AAAAAAAAAGQ/NqLpvMQZzhI/s320/04.jpg" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div id="TixyyLink"  style="background-color: transparent; border: medium none; overflow: hidden; text-align: left; text-decoration: none;color:black;"&gt;&lt;span class="Apple-style-span" style=";font-family:Verdana,sans-serif;color:black;"  &gt;&lt;span class="Apple-style-span"  style="font-family:Calibri;"&gt;&lt;span class="Apple-style-span" style=";font-family:Arial,Helvetica,sans-serif;font-size:small;"  &gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id="TixyyLink"  style="background-color: transparent; border: medium none; overflow: hidden; text-align: left; text-decoration: none;color:black;"&gt;&lt;span class="Apple-style-span" style=";font-family:Verdana,sans-serif;color:black;"  &gt;&lt;span class="Apple-style-span"  style="font-family:Calibri;"&gt;&lt;span class="Apple-style-span" style=";font-family:Arial,Helvetica,sans-serif;font-size:small;"  &gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;Kedua &lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;: Kita buat New Interface  &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;PPTP  Server&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;.  Gak perlu setting macam-macam, langsung aja Klik &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;OK&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id="TixyyLink"  style="background-color: transparent; border: medium none; overflow: hidden; text-align: left; text-decoration: none;color:black;"&gt;&lt;span class="Apple-style-span" style=";font-family:Verdana,sans-serif;color:black;"  &gt;&lt;span class="Apple-style-span"  style="font-family:Calibri;"&gt;&lt;span class="Apple-style-span" style=";font-family:Arial,Helvetica,sans-serif;font-size:small;"  &gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;span class="Apple-style-span"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_-KXHPDKPHqc/S-IPQANnJRI/AAAAAAAAAGY/qG4yI73yscI/s1600/05.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img src="http://4.bp.blogspot.com/_-KXHPDKPHqc/S-IPQANnJRI/AAAAAAAAAGY/qG4yI73yscI/s320/05.jpg" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div id="TixyyLink"  style="background-color: transparent; border: medium none; overflow: hidden; text-align: left; text-decoration: none;color:black;"&gt;&lt;span class="Apple-style-span" style=";font-family:Verdana,sans-serif;color:black;"  &gt;&lt;span class="Apple-style-span"  style="font-family:Calibri;"&gt;&lt;span class="Apple-style-span" style=";font-family:Arial,Helvetica,sans-serif;font-size:small;"  &gt;&lt;span class="Apple-style-span"&gt;&lt;div style="margin: 0px; padding: 10px 0px 0px;"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;Ketiga&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt; : Kita membuat IP Pool,  atau sekelompok IP Address yang akan kita buat untuk mengalokasikan  sejumlah IP Address untuk V&lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;PN Client per-user&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;  yang nanti akan  terkoneksi ke Mikrotik VPN Server kita. Selain  mengunakan IP Pool, kita  juga bisa memberikan IP Address per-user satu  per satu. Tapi jika jumlah  VPN Client-nya banyak maka cara inilah yang  tepat untuk kita lakukan.  Caranya : Klik menu &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;IP – POOL.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin: 0px; padding: 10px 0px 0px;"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_-KXHPDKPHqc/S-IPv99HOHI/AAAAAAAAAGg/yK0ANwz_4P8/s1600/06.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img src="http://3.bp.blogspot.com/_-KXHPDKPHqc/S-IPv99HOHI/AAAAAAAAAGg/yK0ANwz_4P8/s320/06.jpg" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div id="TixyyLink"  style="background-color: transparent; border: medium none; overflow: hidden; text-align: left; text-decoration: none;color:black;"&gt;&lt;span class="Apple-style-span" style=";font-family:Verdana,sans-serif;color:black;"  &gt;&lt;span class="Apple-style-span"  style="font-family:Calibri;"&gt;&lt;span class="Apple-style-span" style=";font-family:Arial,Helvetica,sans-serif;font-size:small;"  &gt;&lt;span class="Apple-style-span"&gt;&lt;div style="margin: 0px; padding: 10px 0px 0px;"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;Keempat &lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;: Dari menu &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;IP - Pool&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;, selanjutnya buat &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;New IP Pool&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;. Misalnya kita  alokasikan IP Address :192.168.88.10 – 192.168.88.20 dan kita berikan  nama &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;vpn-client&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin: 0px; padding: 10px 0px 0px;"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;span class="Apple-style-span"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_-KXHPDKPHqc/S-IQGoxppQI/AAAAAAAAAGo/irKaCibaDoI/s1600/07.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img src="http://4.bp.blogspot.com/_-KXHPDKPHqc/S-IQGoxppQI/AAAAAAAAAGo/irKaCibaDoI/s320/07.jpg" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div id="TixyyLink"  style="background-color: transparent; border: medium none; overflow: hidden; text-align: left; text-decoration: none;color:black;"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;span class="Apple-style-span" style=";font-family:Calibri;color:black;"  &gt;&lt;span class="Apple-style-span" style=";font-family:Arial,Helvetica,sans-serif;font-size:small;color:white;"   &gt;&lt;span class="Apple-style-span"  style="color:black;"&gt;&lt;div  style="margin: 0px; padding: 10px 0px 0px;color:black;"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;Kelima &lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;: Selanjutnya kita lihat &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;IP Pool&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt; yang kita buat telah  berhasil dengan baik.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div  style="margin: 0px; padding: 10px 0px 0px;color:black;"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;span class="Apple-style-span"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin: 0px; padding: 10px 0px 0px;"&gt;&lt;img alt="" class="aligncenter" src="http://artikel.xcode.or.id/files/images/mikrotik-ppptp/Mikrotik-PPPTP-05.JPG" style="display: block; margin: 0px auto; max-width: 100%; padding: 0px;" title="VPN" height="244" width="320" /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div id="TixyyLink"  style="background-color: transparent; border: medium none; overflow: hidden; text-align: left; text-decoration: none;color:black;"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;span class="Apple-style-span" style=";font-family:Calibri;color:black;"  &gt;&lt;span class="Apple-style-span" style=";font-family:Arial,Helvetica,sans-serif;font-size:small;color:white;"   &gt;&lt;span class="Apple-style-span"  style="color:black;"&gt;&lt;div  style="margin: 0px; padding: 10px 0px 0px;color:black;"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;Keenam &lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;: Selanjutnya kita buat  sebuah Profile dengan nama &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;VPS-VPN&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt; (atau terserah suka-suka anda). Local Address  adalah IP Address yang digunakan sebagai &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;VPN Gateway&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt; oleh Mikrotik. &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;Remote Address&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt; adalah IP Address yang  akan diberikan kepada masing-masing &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;VPN Client dan IP Address&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt; inilah yang dikenali  dan berkomunikasi dengan PC yang lain.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin: 0px; padding: 10px 0px 0px;"&gt;&lt;img alt="" class="aligncenter" src="http://artikel.xcode.or.id/files/images/mikrotik-ppptp/Mikrotik-PPPTP-06.jpg" style="display: block; margin: 0px auto; max-width: 100%; padding: 0px;" title="VPN" height="320" width="306" /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div id="TixyyLink"  style="background-color: transparent; border: medium none; overflow: hidden; text-align: left; text-decoration: none;color:black;"&gt;&lt;br /&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;span class="Apple-style-span" style=";font-family:Calibri;color:black;"  &gt;&lt;span class="Apple-style-span" style=";font-family:Arial,Helvetica,sans-serif;font-size:small;color:white;"   &gt;&lt;span class="Apple-style-span"  style="color:black;"&gt;&lt;div  style="margin: 0px; padding: 10px 0px 0px;color:black;"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;Ketujuh &lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;: Selanjutnya kita klik &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;PPTP SERVER&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;. Option inilah yang  menentukan Fitur &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;PPTP SERVER&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt; berfungsi apa tidak pada Mikrotik kita. Aktifkan /  centang tanda checkmark “&lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;ENABLE&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;” lalu pilih &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;Default Profile&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt; yang telah kita buat  pada langkah keenam.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin: 0px; padding: 10px 0px 0px;"&gt;&lt;img alt="" class="aligncenter" src="http://artikel.xcode.or.id/files/images/mikrotik-ppptp/Mikrotik-PPPTP-08.jpg" style="display: block; margin: 0px auto; max-width: 100%; padding: 0px;" title="VPN" height="264" width="320" /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div id="TixyyLink" color="black" style="background-color: transparent; border: medium none; overflow: hidden; text-align: left; text-decoration: none;"&gt;&lt;br /&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;span class="Apple-style-span" style=";font-family:Calibri;color:black;"  &gt;&lt;span class="Apple-style-span" style=";font-family:Arial,Helvetica,sans-serif;font-size:small;color:white;"   &gt;&lt;span class="Apple-style-span"  style="color:black;"&gt;&lt;div  style="margin: 0px; padding: 10px 0px 0px;color:black;"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;Kedelapan &lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;: Langkah selanjutnya  adalah membuat User VPN di menu tab &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;“SECRETS”&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;. &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;Setting Username,  Password, Service&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt; : &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;PPTP dan Profile VPS-VPN&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt; seperti gambar dibawah  ini :&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin: 0px; padding: 10px 0px 0px;"&gt;&lt;img alt="" class="aligncenter" src="http://artikel.xcode.or.id/files/images/mikrotik-ppptp/Mikrotik-PPPTP-09.jpg" style="display: block; margin: 0px auto; max-width: 100%; padding: 0px;" title="VPN" height="267" width="320" /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div id="TixyyLink" style="background-color: transparent; border: medium none; color: black; overflow: hidden; text-align: left; text-decoration: none;"&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style=";font-family:Verdana,sans-serif;color:black;"  &gt;&lt;span class="Apple-style-span"  style="font-family:Calibri;"&gt;&lt;span class="Apple-style-span" style=";font-family:Arial,Helvetica,sans-serif;font-size:small;"  &gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;span class="Apple-style-span"  style="font-family:Arial,Helvetica,sans-serif;"&gt;&lt;strong style="margin: 0px; padding: 0px;"&gt;&lt;span class="Apple-style-span"  style="font-family:Verdana,sans-serif;"&gt;&lt;span class="Apple-style-span"&gt;Kesembilan &lt;/span&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;span class="Apple-style-span"&gt;: Sampai disini tugas  membangun &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"&gt;VPN Server&lt;/span&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;span class="Apple-style-span"&gt; telah selesai dibuat dan langkah selanjutnya  adalah membuat setting VPN Client di PC atau Laptop kita.&lt;br /&gt;&lt;br /&gt;sumber : &lt;a href="http://alifaljabar.blogspot.com/2010/05/vpn-virtual-private-network.html"&gt;http://alifaljabar.blogspot.com/2010/05/vpn-virtual-private-network.html&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2785178257139955802-5372152857705991615?l=tapeuwie.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tapeuwie.blogspot.com/feeds/5372152857705991615/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://tapeuwie.blogspot.com/2010/08/setting-vpn-pptp-di-mikrotik.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2785178257139955802/posts/default/5372152857705991615'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2785178257139955802/posts/default/5372152857705991615'/><link rel='alternate' type='text/html' href='http://tapeuwie.blogspot.com/2010/08/setting-vpn-pptp-di-mikrotik.html' title='Setting VPN pptp di mikrotik'/><author><name>Tape Uwie</name><uri>http://www.blogger.com/profile/12958472702638257190</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_-KXHPDKPHqc/S-IOxRbvGNI/AAAAAAAAAGQ/NqLpvMQZzhI/s72-c/04.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2785178257139955802.post-321937998316103395</id><published>2010-08-18T08:22:00.003+07:00</published><updated>2010-08-18T08:48:48.725+07:00</updated><title type='text'>Setting net2net VPN di IPCop</title><content type='html'>Kali ini berkesempatan untuk menghubungkan 2 site yang sama2 mengunakan  IPCOP versi 1.4.21 ( dengan IPsec VPN nya dan yang dipakai adalah paket  openswan).&lt;br /&gt;&lt;br /&gt;Jaringan yang ada sebagai berikut&lt;br /&gt;&lt;br /&gt;gren1 -- site1 ---- internet ----- site2 --- green2&lt;br /&gt;&lt;br /&gt;green1 adalah 192.168.1.0/24&lt;br /&gt;&lt;br /&gt;site1 dengan IP Public 201.130.2.3 dengan hostname site1.localdomain&lt;br /&gt;&lt;br /&gt;green2 adalah 192.168.2.0/24&lt;br /&gt;&lt;br /&gt;site2 dengan IP Public 201.130.132.5 dengan hostname site2.localdomain&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;langkah2nya&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1.  Global Setting&lt;br /&gt;&lt;br /&gt;  Di site1&lt;br /&gt;&lt;div style="margin-left: 40px;"&gt;isi "Public IP or FQDN for RED interface or &lt;%defaultroute&gt;:" dengan  201.130.2.3,  check "enabled" dan tekan Save&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;  Di site2&lt;br /&gt;&lt;div style="margin-left: 40px;"&gt;isi "Public IP or FQDN for RED interface or &lt;%defaultroute&gt;:" dengan  201.130.132.5,  check "enabled" dan&lt;br /&gt;tekan Save&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;2. Generate Root/Host Certificates&lt;br /&gt;&lt;br /&gt;  di site1 :  Tekan tombol "Generate Root/Host Certificates" dan isikan  berikut dibawah&lt;br /&gt;&lt;div style="margin-left: 40px;"&gt;- Organization name : site1&lt;br /&gt;- IPCops Hostname : site1.localdomain&lt;br /&gt;- country : indonesia&lt;br /&gt;- Tekan tombol "Generate Root/Host Certificates" dan tunggu beberapa saat&lt;br /&gt;- dowload root certificate dan ganti namanya ke cacert.site1.pem&lt;br /&gt;- download host certificate dan ganti namanya  ke hostcert.site1.pem&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;  di site2 :   Tekan tombol "Generate Root/Host Certificates" dan isikan  berikut dibawah&lt;br /&gt;&lt;div style="margin-left: 40px;"&gt;- Organization name : site2&lt;br /&gt;- IPCops Hostname : site2.localdomain&lt;br /&gt;- country : indonesia&lt;br /&gt;- Tekan tombol "Generate Root/Host Certificates" dan tunggu beberapa saat&lt;br /&gt;- dowload root certificate dan ganti namanya ke cacert.site2.pem&lt;br /&gt;- download host certificate dan ganti namanya  ke hostcert.site2.pem&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;3. Upload CA certificates&lt;br /&gt;  di site1&lt;br /&gt;&lt;div style="margin-left: 40px;"&gt;- CA Name : site2&lt;br /&gt;- Browse dan pilih file "cacert.site2.pem&lt;br /&gt;-  Tekan tombol "Upload CA Certificate"  dan ini akan menambahkan  CA  certificate dari site2 ke site1 dan akan nampak di baris ke 3 di  certificate authorities.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;  di site2&lt;br /&gt;&lt;div style="margin-left: 40px;"&gt;- CA Name : site1&lt;br /&gt;- Browse dan pilih file "cacert.site1.pem"&lt;br /&gt;- Tekan tombol "Upload CA Certificate"  dan ini akan menambahkan  CA&lt;br /&gt;certificate dari site1 ke site2 dan akan nampak di baris ke 3 di certificate authorities.&lt;/div&gt;&lt;br /&gt;4. Membuat Koneksi&lt;br /&gt;  di site1 : Tekan tombol "ADD" dan pilih "net-to-net" Virtual Private Network" untuk conection type dan isikan dibawah ini&lt;br /&gt;&lt;div style="margin-left: 40px;"&gt;- Name : site2&lt;br /&gt;- Host IP address : Red (201.130.2.3)&lt;br /&gt;-  local subnet :  192.168.1.0/255.255.255.0&lt;br /&gt;- Remote  Host/IP : 201.130.132.5&lt;br /&gt;- Remote subnet : 192.168.2.0/ 255.255.255.0&lt;br /&gt;- di "Authentication" section pilih "Upload a Certificate dan browse&lt;br /&gt;file "hostcert.site2.pem"&lt;br /&gt;- terakhir tekan tombol "Save"&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;di site2 : Tekan tombol "ADD" dan pilih "net-to-net" Virtual Private Network" untuk conection type dan isikan dibawah ini&lt;br /&gt;&lt;div style="margin-left: 40px;"&gt;- Name : site1&lt;br /&gt;- Host IP address : Red (201.130.132.5)&lt;br /&gt;-  local subnet :  192.168.21.0/255.255.255.0&lt;br /&gt;- Remote  Host/IP : 201.130.2.3&lt;br /&gt;- Remote subnet : 192.168.12.0/ 255.255.255.0&lt;br /&gt;- di "Authentication" section pilih "Upload a Certificate dan browse file "hostcert.site1.pem"&lt;br /&gt;- terakhir tekan tombol "Save"&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;5.  selesai dan biarkan beberapa saat maka koneksi nya akan&lt;br /&gt;berubah "Open'&lt;br /&gt;&lt;br /&gt;Sumber : &lt;a href="http://kafemis.blogspot.com/2009/06/net2net-vpn-di-ipcop.html"&gt;http://kafemis.blogspot.com/2009/06/net2net-vpn-di-ipcop.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2785178257139955802-321937998316103395?l=tapeuwie.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tapeuwie.blogspot.com/feeds/321937998316103395/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://tapeuwie.blogspot.com/2010/08/setting-net2net-vpn-di-ipcop.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2785178257139955802/posts/default/321937998316103395'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2785178257139955802/posts/default/321937998316103395'/><link rel='alternate' type='text/html' href='http://tapeuwie.blogspot.com/2010/08/setting-net2net-vpn-di-ipcop.html' title='Setting net2net VPN di IPCop'/><author><name>Tape Uwie</name><uri>http://www.blogger.com/profile/12958472702638257190</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2785178257139955802.post-6027978968689143893</id><published>2009-06-01T16:41:00.001+07:00</published><updated>2009-06-01T16:43:06.571+07:00</updated><title type='text'>Cara Daftar ID Di Nusa Reborn</title><content type='html'>&lt;div class="top_post"&gt;&lt;span style="text-decoration: underline;"&gt;Hasil Copast&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;  &lt;div class="content"&gt; &lt;style&gt;.fullpost{display:inline;}&lt;/style&gt; &lt;p&gt;wah sepertinya kawan2 kita sekarang kalo mau daftar id baru di nusareborn harus dengan sedikit lebih susah di karena hobi leaver menyebabkan pembatasa daftar id dengan sistem kirim email di sertai biodata negh cara daftar di nusa reborn . . .&lt;br /&gt;&lt;br /&gt;Cara Membuat ID NusaReborn PvPGN Server:&lt;br /&gt;&lt;br /&gt;Pembuatan ID NusaReborn mulai 28 February 2009 yang bertepatan dengan 1 tahun NusaReborn PvPGN Server. Telah kami persulit dimana pelanggaran² user semakin meningkat dikarenakan pembuatan ID yang sangat mudah, Sehingga user tidak menghargai ID yang mereka gunakan.&lt;br /&gt;&lt;br /&gt;Berikut Langkah² Pendaftaran ID Battlenet NusaReborn:&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(51, 102, 255);"&gt;1. Kirimkan Email Kepada: g_e_n_t_h_o_n_x@nusa.net.id&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(51, 102, 255);"&gt;2. Subject: Pendaftaran ID Battlenet NusaReborn&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(51, 102, 255);"&gt;3. Lampirkan scan-an kartu identitas anda melalui Attachement&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(51, 102, 255);"&gt;4. Tuliskan Message sebagai berikut:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;# IP Address anda: ? (Lihat IP Address Anda Disini)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;# Username: ? (Max.character 15, character yang diperbolehkan: A-Z 0-9 _ ~ ^ [ ] { } = - +)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;# Password: ? (Max.character 12)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Dengan ini saya secara sadar dan tidak ada tekanan dari pihak manapun. Bersedia menaati &amp;amp; mengikuti semua RULE yang ada di NusaReborn dan siap menerima sanksi bila melakukan Pelanggaran.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;negh gambar contoh cara mengirimnya (klik untuk memperjelasnya)&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Kz4HpKV3B-g/Seis513d78I/AAAAAAAAAGA/xHk88azrmns/s1600-h/battlenetnsr.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 323px; height: 279px;" src="http://3.bp.blogspot.com/_Kz4HpKV3B-g/Seis513d78I/AAAAAAAAAGA/xHk88azrmns/s320/battlenetnsr.jpg" alt="" id="BLOGGER_PHOTO_ID_5325696669077860290" border="0" /&gt;&lt;/a&gt;&lt;span style="color: red;"&gt;&lt;b&gt;"Perhatikan yang di beri tanda Merah"&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;b&gt;Perlu di perhatikan untuk si pendaftar:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;b&gt;1. Proses pembuatan ID Max 10 hari, terhitung dari Tanggal Pengiriman&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;b&gt;2. Tidak perlu mengirimkan berulang² cukup mengirimkan satu kali saja&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;b&gt;3. Kartu identitas yang anda lampirkan harus dalam masa berlaku dan asli&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;4. Bila dianggap tidak memenuhi syarat maka &lt;i&gt;Tidak Akan Di Proses + Tanpa Pemberitahuan&lt;/i&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;INGAT SATU KTP SATU ID . . .! ! !&lt;br /&gt;&lt;br /&gt;UNTUK LEBIH DETAILNY ANDA MASUK KE FORUM NUSAREBORN&lt;br /&gt;&lt;br /&gt;&lt;a href="http://forum.nusa.net.id/"&gt;FORUM.NUSA.NET.ID&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;thankz regard . . .&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;source: NusaReborn Forum&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2785178257139955802-6027978968689143893?l=tapeuwie.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tapeuwie.blogspot.com/feeds/6027978968689143893/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://tapeuwie.blogspot.com/2009/06/cara-daftar-id-di-nusa-reborn.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2785178257139955802/posts/default/6027978968689143893'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2785178257139955802/posts/default/6027978968689143893'/><link rel='alternate' type='text/html' href='http://tapeuwie.blogspot.com/2009/06/cara-daftar-id-di-nusa-reborn.html' title='Cara Daftar ID Di Nusa Reborn'/><author><name>Tape Uwie</name><uri>http://www.blogger.com/profile/12958472702638257190</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Kz4HpKV3B-g/Seis513d78I/AAAAAAAAAGA/xHk88azrmns/s72-c/battlenetnsr.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2785178257139955802.post-5658090189159401363</id><published>2009-03-29T17:11:00.003+07:00</published><updated>2009-03-29T17:22:28.774+07:00</updated><title type='text'>Tutorial Mikrotik Pemula</title><content type='html'>Tutorial ini di kutip dari Forum Mikrotik yang dibuat oleh kucingGarong&lt;br /&gt;&lt;br /&gt;&lt;b&gt;# SETUP MIKROTIK (base 1)&lt;/b&gt;&lt;br /&gt;1. setelah mikrotik terinstall dengan baik dan benar jalankan mikrotik anda&lt;br /&gt;2. masukkan username &amp;amp; password, dalam hal ini karena masih baru maka default usernam : admin   pasword : &lt;i&gt;blank&lt;/i&gt;&lt;br /&gt;3. ganti nama ethernet anda jika anda mau, dalam hal ini anda dapat memberikan nama apa saja = [kucing@mikrotik] &gt;interface&lt;br /&gt;                       [kucing@mikrotik] interface &gt;print (melihat dulu berapa banyak ethernet yg terpasang)&lt;br /&gt;                       [kucing@mikrotik] interface &gt;set 0 name=LAN&lt;br /&gt;                       [kucing@mikrotik] interface &gt;set 1 name=WAN&lt;br /&gt;4. kemudian nambahkan ip addressnya&lt;br /&gt;                       [kucing@mikrotik] &gt;ip address&lt;br /&gt;[kucing@mikrotik] ip address &gt;add address=192.168.0.1/255.255.0.0 interface=LAN ----&gt; ini untuk ip interface lokal&lt;br /&gt;[kucing@mikrotik] ip address &gt;add address=203.90.1.1/255.255.255.240 interface=WAN ---&gt; ini untuk ip global yg di dapet dari ISP&lt;br /&gt;5. kemudian masukin gatewaynya&lt;br /&gt;                       [kucing@mikrotik] &gt; ip route&lt;br /&gt;[kucing@mikrotik] ip route &gt;add gateway=xxx.xxx.xxx.xxx/xxx.xxx.xxx.xxx ----&gt; ini merupakan gateway untuk keluar&lt;br /&gt;6. kemudian setup webproxy&lt;br /&gt;                       [kucing@mikrotik] &gt;ip web-proxy&lt;br /&gt;                       [kucing@mikrotik] ip web-proxy &gt;set enable=yes&lt;br /&gt;                       [kucing@mikrotik] ip web-proxy &gt;set transparent-proxy=yes&lt;br /&gt;[kucing@mikrotik] ip web-proxy &gt;set max-object-size=1200KiB ---&gt; ini supaya nge loadnya ngacir si web proxy&lt;br /&gt;7. kemudian tambahkan rule supaya si client yg menggunakan port 80 akan di oper ke web-proxy&lt;br /&gt;                       [kucing@mikrotik] &gt;ip firewall nat&lt;br /&gt;[kucing@mikrotik] ip firewall nat &gt;add chain=dstnat protocol=tcp dst-port=80 action=redirect to-ports=3128&lt;br /&gt;8. kemudian masukan dns nya&lt;br /&gt;                       [kucing@mikrotik] &gt;ip dns&lt;br /&gt;                       [kucing@mikrotik] ip dns &gt;set primary-dns=xxx.xxx.xxx.xxx&lt;br /&gt;                       [kucing@mikrotik] ip dns &gt;set secondary-dns=xxx.xxx.xxx.xxx&lt;br /&gt;9. Sekarang masqurade interface WANnya&lt;br /&gt;                       [kucing@mikrotik]&gt;ip firewall nat&lt;br /&gt;                       [kucing@mikrotik] ip firewall nat&gt;add chain=srcnat out-interface=WAN action=masquerade&lt;br /&gt;10. sekarang coba ping ke gateway &amp;amp; dns dari mikrotik, kalo REPLY berarti dah konek&lt;br /&gt;11. heuehuueeuhehehueuheuh selesai juga dah tutorial ke 2 gw&lt;br /&gt;&lt;br /&gt;&lt;b&gt;----TUTORIAL SETUP HOTSPOT----&lt;/b&gt;&lt;br /&gt;1.[kucing@mikrotik]&gt;ip hotspot&lt;br /&gt;2.[kucing@mikrotik] ip hotspot&gt;setup&lt;br /&gt;hotspot interface:LAN&lt;br /&gt;local address of network:xxx.xxx.xxx.xxx/xx --&gt;ip dari inteface LAN&lt;br /&gt;masqurade network:yes&lt;br /&gt;address pool of network:xxx.xxx.xxx.xxx-xxx.xxx.xxx.xxx&lt;br /&gt;select certificate:none&lt;br /&gt;ip address of SMTP server:0.0.0.0&lt;br /&gt;DNS server:&lt;br /&gt;DNS name:&lt;br /&gt;name of local hotspot user: admin   ----&gt; user untuk masuk ke halam hotspot&lt;br /&gt;password for the user:&lt;br /&gt;3. sekarang buka web browser, ketikan ip addressnya hotspot&lt;br /&gt;4.masukan username yg telah di buat tadi&lt;br /&gt;5.walah berhasil kan......&lt;br /&gt;&lt;br /&gt;&lt;b&gt;------TUTORIAL USER MANAGER WITH HOTSPOT-------&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;1. enable dulu use-radius di hotspot&lt;br /&gt;                        [kucing@mikrotik]&gt;ip hotspot profile&lt;br /&gt;2.                     [kucing@mikrotik] ip hotspot profile&gt;print&lt;br /&gt;3. akan terlihat profile2 yg telah di buat, kemudian tentukan profile mana yg akan di pake di use-radius&lt;br /&gt;                        [kucing@mikrotik]ip hotspot profile&gt; set 0 use-radius=yes&lt;br /&gt;                        0 = merupakan nomor profile&lt;br /&gt;4.sekarang bikin radiusnya&lt;br /&gt;                        [kucing@mikrotik]&gt;radius&lt;br /&gt;                        [kucing@mikrotik]radius&gt;add address=127.0.0.1&lt;br /&gt;                        [kucing@mikrotik]radius&gt;print&lt;br /&gt;                        [kucing@mikrotik]radius&gt;set 0 service=hotspot, login                               secret=12345678&lt;br /&gt;5.sekarang bikin owner untuk di usermanager&lt;br /&gt;                       [kucing@mikrotik]&gt;/ tool user-manager customer add login="test" password="test" permissions=owner&lt;br /&gt;6.sekarang bikin penghubung/supaya si mikrotik ngeroute ke usermanager&lt;br /&gt;[kucing@mikrotik]&gt;/ tool user-manager router add subscriber=MikroTik ip-address=127.0.0.1 shared-secret=12345678&lt;br /&gt;7.nah setelah ini smua dah di buat, sekarang untuk ngetes apakah usermanager dah konek apa blom&lt;br /&gt;8.buka web browser ketik " 127.0.0.1/userman "&lt;br /&gt;9.akan tampil halaman login userman, masukin dah tuh username=test password=test&lt;br /&gt;10.huehueuhehuuehehuehuheu.....akhirnya kelar juga tutorial usermanagernya&lt;br /&gt;&lt;br /&gt;&lt;b&gt;------TUTORIAL 2 ISP IN 1 ROUTER WITH LOADBALANCING------&lt;/b&gt;&lt;br /&gt;/ ip address&lt;br /&gt;add address=192.168.0.1/24 network=192.168.0.0 broadcast=192.168.0.255 interface=Local comment="" \&lt;br /&gt;    disabled=no&lt;br /&gt;add address=10.111.0.2/24 network=10.111.0.0 broadcast=10.111.0.255 interface=wlan2 \&lt;br /&gt;    comment="" disabled=no&lt;br /&gt;add address=10.112.0.2/24 network=10.112.0.0 broadcast=10.112.0.255 interface=wlan1 \&lt;br /&gt;    comment="" disabled=no&lt;br /&gt;/ ip firewall mangle&lt;br /&gt;add chain=prerouting in-interface=Local connection-state=new nth=1,1,0 \&lt;br /&gt;    action=mark-connection new-connection-mark=odd passthrough=yes comment="" \&lt;br /&gt;    disabled=no&lt;br /&gt;add chain=prerouting in-interface=Local connection-mark=odd action=mark-routing \&lt;br /&gt;    new-routing-mark=odd passthrough=no comment="" disabled=no&lt;br /&gt;add chain=prerouting in-interface=Local connection-state=new nth=1,1,1 \&lt;br /&gt;    action=mark-connection new-connection-mark=even passthrough=yes comment="" \&lt;br /&gt;    disabled=no&lt;br /&gt;add chain=prerouting in-interface=Local connection-mark=even action=mark-routing \&lt;br /&gt;    new-routing-mark=even passthrough=no comment="" disabled=no&lt;br /&gt;/ ip firewall nat&lt;br /&gt;add chain=srcnat connection-mark=odd action=src-nat to-addresses=10.111.0.2 \&lt;br /&gt;    to-ports=0-65535 comment="" disabled=no&lt;br /&gt;add chain=srcnat connection-mark=even action=src-nat to-addresses=10.112.0.2 \&lt;br /&gt;    to-ports=0-65535 comment="" disabled=no&lt;br /&gt;/ ip route&lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.111.0.1 scope=255 target-scope=10 routing-mark=odd \&lt;br /&gt;    comment="" disabled=no&lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.112.0.1 scope=255 target-scope=10 routing-mark=even \&lt;br /&gt;    comment="" disabled=no&lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.112.0.1 scope=255 target-scope=10 comment="" \&lt;br /&gt;    disabled=no&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;Mangle&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;/ ip address&lt;br /&gt;add address=192.168.0.1/24 network=192.168.0.0 broadcast=192.168.0.255 interface=Local comment="" \&lt;br /&gt;    disabled=no&lt;br /&gt;add address=10.111.0.2/24 network=10.111.0.0 broadcast=10.111.0.255 interface=wlan2 \&lt;br /&gt;    comment="" disabled=no&lt;br /&gt;add address=10.112.0.2/24 network=10.112.0.0 broadcast=10.112.0.255 interface=wlan1 \&lt;br /&gt;    comment="" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;i&gt;router punya 2 upstream (WAN) interfaces dengan ip address 10.111.0.2/24 and 10.112.0.2/24. dan interface LAN dengan nama interface "Local" dan ip address 192.168.0.1/24.&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;/ ip firewall mangle&lt;br /&gt;&lt;br /&gt;add chain=prerouting in-interface=Local connection-state=new nth=1,1,0 \&lt;br /&gt;    action=mark-connection new-connection-mark=odd passthrough=yes comment="" \&lt;br /&gt;    disabled=no&lt;br /&gt;&lt;br /&gt;add chain=prerouting in-interface=Local connection-mark=odd action=mark-routing \&lt;br /&gt;    new-routing-mark=odd passthrough=no comment="" disabled=no&lt;br /&gt;&lt;br /&gt;add chain=prerouting in-interface=Local connection-state=new nth=1,1,1 \&lt;br /&gt;    action=mark-connection new-connection-mark=even passthrough=yes comment="" \&lt;br /&gt;    disabled=no&lt;br /&gt;add chain=prerouting in-interface=Local connection-mark=even action=mark-routing \&lt;br /&gt;    new-routing-mark=even passthrough=no comment="" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;&lt;br /&gt;NAT&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;/ ip firewall nat&lt;br /&gt;add chain=srcnat connection-mark=odd action=src-nat to-addresses=10.111.0.2 \&lt;br /&gt;    to-ports=0-65535 comment="" disabled=no&lt;br /&gt;add chain=srcnat connection-mark=even action=src-nat to-addresses=10.112.0.2 \&lt;br /&gt;    to-ports=0-65535 comment="" disabled=no&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;&lt;br /&gt;Routing&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;/ ip route&lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.111.0.1 scope=255 target-scope=10 routing-mark=odd \&lt;br /&gt;    comment="" disabled=no&lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.112.0.1 scope=255 target-scope=10 routing-mark=even \&lt;br /&gt;    comment="" disabled=no&lt;br /&gt;add dst-address=0.0.0.0/0 gateway=10.112.0.1 scope=255 target-scope=10 comment="" \&lt;br /&gt;    disabled=no comment="gateway for the router itself"&lt;br /&gt;&lt;br /&gt;&lt;b&gt;# SETUP QUEUE&lt;/b&gt;&lt;br /&gt;&lt;i&gt;mungkin banyak tersebar dimana2 bagaimana cara untuk membatasi BW, tapi kali ini saya mau mencoba memberikan tutorial yg sudah saya uji terlebih dahulu selama 40 jam 30 menit 100 detik dan berfungsi 100% dengan sempurna&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;oke kita mulai saja=&lt;br /&gt;&lt;br /&gt;1. kita bikin/setup mangle dulu =&lt;br /&gt; [Kucing@mikrotik] &gt; ip firewall mangle print&lt;br /&gt;Flags: X - disabled, I - invalid, D - dynamic&lt;br /&gt; 0   UP LOAD&lt;br /&gt;     chain=prerouting in-interface=LAN&lt;br /&gt;     src-address=xxx.xxx.xxx.xxx/xx action=mark-packet&lt;br /&gt;     new-packet-mark=test-up passthrough=no&lt;br /&gt;&lt;br /&gt; 1   MARK-KONEKSI&lt;br /&gt;     chain=forward src-address=xxx.xxx.xxx.xxx/xx&lt;br /&gt;     action=mark-connection&lt;br /&gt;     new-connection-mark=test-conn passthrough=yes&lt;br /&gt;&lt;br /&gt; 2   ;;; DOWN DIRECT KONEKSI&lt;br /&gt;     chain=forward in-interface=WAN&lt;br /&gt;     connection-mark=test-conn action=mark-packet&lt;br /&gt;     new-packet-mark=test-down passthrough=no&lt;br /&gt;&lt;br /&gt; 3   ;;; DOWN VIA PROXY&lt;br /&gt;     chain=output out-interface=LAN&lt;br /&gt;     dst-address=xxx.xxx.xxx.xxx/xx action=mark-packet&lt;br /&gt;     new-packet-mark=test-down passthrough=no&lt;br /&gt;&lt;br /&gt;2. Tahap terahkir adalah membuat queue tree=&lt;br /&gt;&lt;br /&gt;[Kucing@mikrotik] &gt; queue tree pr&lt;br /&gt;Flags: X - disabled, I - invalid&lt;br /&gt; 0   name="download" parent=LAN packet-mark=test-down&lt;br /&gt;     limit-at=32000 queue=default priority=8&lt;br /&gt;     max-limit=32000 burst-limit=0&lt;br /&gt;     burst-threshold=0 burst-time=0s&lt;br /&gt;&lt;br /&gt; 1   name="UPLOAD" parent=global-in&lt;br /&gt;     packet-mark=test-up limit-at=32000&lt;br /&gt;     queue=default priority=8&lt;br /&gt;     max-limit=32000 burst-limit=0&lt;br /&gt;     burst-threshold=0 burst-time=0s&lt;br /&gt;&lt;br /&gt;di sini saya menggunakan queue typenya adalah &lt;b&gt;PCQ&lt;/b&gt; kenapa, karena &lt;b&gt;PCQ &lt;/b&gt;&lt;i&gt;bisa secara otomatis membagi trafik per client&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;TUTORIAL MISAHIN BW LOKAL DAN INTERNATIONAL&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;1. Bikin src-address list dengan nama nise&lt;br /&gt;&lt;br /&gt;2. atau dengan copy-paste src-address yg di sediain oleh nise&lt;br /&gt;&lt;a onclick="urchinTracker ('/outgoing/http_www_datautama_net_id_harijanto_mikrotik_datautama_nice_php');" rel="nofollow" href="http://www.datautama.net.id/harijanto/mikrotik/datautama-nice.php" target="_blank"&gt;http://www.datautama.net.id/harijant...utama-nice.php&lt;/a&gt;&lt;br /&gt;copy-paste bisa di lakukan dari putty.exe&lt;br /&gt;&lt;br /&gt;3. Bikin mangel / supaya tau itu koneksi &amp;amp; paket nya dateng dari lokal ato international&lt;br /&gt;/ ip firewall mangle&lt;br /&gt;- add chain=forward src-address-list=nice action=mark-connection \&lt;br /&gt;new-connection-mark=con-indonesia passthrough=yes comment=”mark all \&lt;br /&gt;indonesia source connection traffic” disabled=no &lt;b&gt;----&gt; untuk lokal&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;- add chain=forward dst-address-list=nice action=mark-connection \&lt;br /&gt;new-connection-mark=con-indonesia passthrough=yes comment=”mark all \&lt;br /&gt;indonesia destination connection traffic” disabled=no &lt;b&gt;----&gt; untuk lokal&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;- add chain=forward src-address-list=!nice action=mark-connection \&lt;br /&gt;new-connection-mark=con-overseas passthrough=yes comment=”mark all \&lt;br /&gt;overseas source connection traffic” disabled=no &lt;b&gt;---&gt; Untuk International&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;- add chain=forward dst-address-list=!nice action=mark-connection \&lt;br /&gt;new-connection-mark=con-overseas passthrough=yes comment=”mark all \&lt;br /&gt;overseas destination connection traffic” disabled=no&lt;br /&gt;&lt;br /&gt;- add chain=prerouting connection-mark=con-indonesia action=mark-packet \&lt;br /&gt;new-packet-mark=indonesia passthrough=yes comment=”mark all indonesia \&lt;br /&gt;traffic” disabled=no &lt;b&gt;---&gt; paket lokal&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;- add chain=prerouting connection-mark=con-overseas action=mark-packet \&lt;br /&gt;new-packet-mark=overseas passthrough=yes comment=”mark all overseas \&lt;br /&gt;traffic” disabled=no &lt;b&gt;----&gt; paket international&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;4. Bikin simple queue =&lt;br /&gt;/ queue simple&lt;br /&gt;- add name=”test-indonesia” target-addresses=xxx.xxx.xxx.xxx/xx \&lt;br /&gt;dst-address=0.0.0.0/0 interface=all parent=none packet-marks=indonesia \&lt;br /&gt;direction=both priority=8 queue=default/default limit-at=0/0 \&lt;br /&gt;max-limit=256000/256000 total-queue=default disabled=no &lt;b&gt;---&gt; 256 UPLOAD &amp;amp; DOWNLOAD (LOKAL)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;- add name=”test-overseas” target-addresses=xxx.xxx.xxx.xxx/xx \&lt;br /&gt;dst-address=0.0.0.0/0 interface=all parent=none packet-marks=overseas \&lt;br /&gt;direction=both priority=8 queue=default/default limit-at=0/0 \&lt;br /&gt;max-limit=128000/128000 total-queue=default disabled=no &lt;b&gt;----&gt; 256 UPLOAD &amp;amp; DOWNLOAD (INTERNATIONAL)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;5. Untuk mengetahui benar ato tidaknya silahkan mengunjungi&lt;br /&gt;&lt;a onclick="urchinTracker ('/outgoing/http_www_sijiwae_net_speedtest_');" rel="nofollow" href="http://www.sijiwae.net/speedtest/" target="_blank"&gt;http://www.sijiwae.net/speedtest/&lt;/a&gt; ---&gt; liat di kolom kecepatan koneksi&lt;br /&gt;&lt;br /&gt;&lt;b&gt;TUTORIAL SETING IP-PROXY &amp;amp; CONTOH PENGGUNANNYA (BASIC)&lt;/b&gt;&lt;br /&gt;1. Mulai dengan mengkonfigure ip-proxy&lt;br /&gt;&lt;i&gt;/ip proxy&lt;br /&gt;enabled: yes&lt;br /&gt;src-address: 0.0.0.0&lt;br /&gt;port: 8080  &lt;b&gt;---&gt; bisa menggunakan port selain 8080&lt;/b&gt;&lt;br /&gt;parent-proxy: 0.0.0.0:0&lt;br /&gt;parent-proxy-port : 3128 &lt;b&gt;---&gt; kalo ada lebih dari satu proxy&lt;/b&gt;&lt;br /&gt;cache-drive: system&lt;br /&gt;cache-administrator: "TESTING"&lt;br /&gt;max-disk-cache-size: none&lt;br /&gt;max-ram-cache-size: none&lt;br /&gt;cache-only-on-disk: no&lt;br /&gt;maximal-client-connections: 1000&lt;br /&gt;maximal-server-connections: 1000&lt;br /&gt;max-object-size: 512KiB&lt;br /&gt;max-fresh-time: 3d&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;2. Sekarang buat supaya proxynya jadi transparan&lt;br /&gt;&lt;i&gt;/ip firewall nat&lt;br /&gt;chain=dstnat protocol=tcp dst-port=80 action=redirect to-ports=8080&lt;/i&gt; &lt;b&gt;---&gt;letakan setelah masquarade&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;3. Pastiin supaya proxy ente2 ga ada yg pake&lt;br /&gt;&lt;i&gt;/ip firewall filter&lt;br /&gt;chain=input in-interface=&lt;u&gt;&lt;b&gt;PUBLIC-INTERFACE&lt;/b&gt;&lt;/u&gt; src-address=0.0.0.0/0 protocol=tcp dst-port=8080 action=drop&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;4. Contoh untuk memblok suatu site&lt;br /&gt;&lt;i&gt;/ip proxy access&lt;br /&gt;dst-host=www.google.com action=deny&lt;/i&gt;&lt;br /&gt;&lt;b&gt;bisa juga memblok per ip, dengan memasukan src-address&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;5. Contoh untuk memblok/memberhentikan suatu jenis file&lt;br /&gt;&lt;i&gt;/ip proxy access&lt;br /&gt;path=*.exe action=deny&lt;br /&gt;path=*.mp3 action=deny&lt;br /&gt;path=*.zip action=deny&lt;br /&gt;path=*.rar action=deny.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;6. Contoh lain&lt;br /&gt;&lt;i&gt;/ip proxy access&lt;br /&gt;dst-host=:sex action=deny&lt;/i&gt; &lt;b&gt;---&gt; akan memblok semua site yg ada kata &lt;u&gt;SEX&lt;/u&gt;&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2785178257139955802-5658090189159401363?l=tapeuwie.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tapeuwie.blogspot.com/feeds/5658090189159401363/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://tapeuwie.blogspot.com/2009/03/tutorial-mikrotik-pemula.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2785178257139955802/posts/default/5658090189159401363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2785178257139955802/posts/default/5658090189159401363'/><link rel='alternate' type='text/html' href='http://tapeuwie.blogspot.com/2009/03/tutorial-mikrotik-pemula.html' title='Tutorial Mikrotik Pemula'/><author><name>Tape Uwie</name><uri>http://www.blogger.com/profile/12958472702638257190</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2785178257139955802.post-4768635512467254816</id><published>2009-03-27T11:00:00.009+07:00</published><updated>2009-03-28T16:05:36.583+07:00</updated><title type='text'>Secure SMTP Server with Kerio MailSever</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://i85.photobucket.com/albums/k57/becouz/queueoptions.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 410px; height: 317px;" src="http://i85.photobucket.com/albums/k57/becouz/queueoptions.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;strong&gt;&lt;em&gt;Kerio MailServer&lt;/em&gt;&lt;/strong&gt; provides a protection system that enables users to define who will be allowed to send email via this server and where. Anyone can connect to the SMTP server to send messages to local domains. However, only authorized users will be allowed to send email to other domains. &lt;p&gt;Antispam protection of the mailserver enables users to define who will be allowed to use this server and what actions he/she can perform. If the SMTP server is available from the Internet, any client can connect and use the server to send an email message. The server can be misused to send spam messages. Recipients of such email messages will see your SMTP server as the sender in the source text and might block receiving messages sent from this server.&lt;/p&gt; &lt;p&gt;&lt;span id="more-1653"&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;The Parameters can be also set:&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Relay Control Tab&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;Use the Relay control tab to set groups of allowed IP addresses and/or user authentication against SMTP server.&lt;/p&gt; &lt;p style="text-align: center;"&gt;&lt;a onclick="pageTracker._trackPageview('/outgoing/i85.photobucket.com/albums/k57/becouz/smtpdel.png?referer=http://becouz.net/category/computer');javascript:pageTracker._trackPageview('/outgoing/i85.photobucket.com/albums/k57/becouz/smtpdel.png');" rel="nofollow" href="http://i85.photobucket.com/albums/k57/becouz/smtpdel.png" target="_blank"&gt;&lt;img style="width: 410px; height: 337px;" class="aligncenter" rel="nofollow" src="http://i85.photobucket.com/albums/k57/becouz/smtpdel.png" alt="" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Allow relay only for&lt;br /&gt;&lt;/strong&gt; Use this option to activate user authentication by IP addresses or usernames and passwords (see below). Generally, authenticated users can use email messages to any domain via this server, whereas unauthorized users can send messages only to local domains.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Users from IP address group&lt;br /&gt;&lt;/strong&gt; Use this option to define a group of IP addresses from which email can be sent to any domain. Use the IP address group menu to choose an item from the list of groups defined in Configuration Definition IP Address Groups. Use the Edit button to edit a selected group or to create a new one (see chapter IP Address Groups).&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Users authenticated through SMTP server for outgoing mail&lt;br /&gt;&lt;/strong&gt; Users authenticated through SMTP server using a valid username and password will be allowed to send email to any domain. Thus, all users that have their own accounts in Kerio MailServer will have this right.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Users authenticated through POP3 from the same IP address&lt;br /&gt;&lt;/strong&gt; Users authenticated through POP3 (username and password) will be granted relay access from their IP address for a given period of time. The default time period is 30 minutes.&lt;/p&gt; &lt;p&gt;Authentication by IP addresses is independent from authentication by usernames, therefore users must meet at least one of these conditions.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Open relay&lt;/strong&gt;&lt;br /&gt;In this mode, the SMTP server does not check users who use it to send email. Thus any user can send email messages to any domain. Warning:We recommend you not to use this mode if Kerio MailServer is available from the Internet. If you use this option, your server can be used for sending spam and it might be added to a blacklist of spam SMTP server database (see below).&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Blacklists Tab&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;Kerio MailServer can also block incoming messages from servers that are considered as spam servers. For this purpose, it uses public databases of these servers located in the Internet or its own database (either an IP address group, or a list of servers in the Internet blacklists table).&lt;/p&gt; &lt;p&gt;To define these parameters go to the Blacklists tab in Configuration SMTP Server.&lt;/p&gt; &lt;p style="text-align: center;"&gt;&lt;a onclick="pageTracker._trackPageview('/outgoing/i85.photobucket.com/albums/k57/becouz/smtpprop.png?referer=http://becouz.net/category/computer');javascript:pageTracker._trackPageview('/outgoing/i85.photobucket.com/albums/k57/becouz/smtpprop.png');" rel="nofollow" href="http://i85.photobucket.com/albums/k57/becouz/smtpprop.png" target="_blank"&gt;&lt;img style="width: 410px; height: 290px;" class="alignnone" rel="nofollow" src="http://i85.photobucket.com/albums/k57/becouz/smtpprop.png" alt="" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Kerio MailServer administrator can use a couple of different databases. These databases are independent and they can be used simultaneously. Users can also add databases in the Denied servers dialog box. This dialog is opened after you click Add.&lt;/p&gt; &lt;p style="text-align: center;"&gt;&lt;img class="aligncenter" rel="nofollow" src="http://i85.photobucket.com/albums/k57/becouz/intblack.png" alt="" height="208" width="268" /&gt;&lt;/p&gt; &lt;p&gt;ORDB Open Relay Database&lt;/p&gt; &lt;p&gt;This service is free. For details, go to &lt;a onclick="pageTracker._trackPageview('/outgoing/www.ordb.org/?referer=http://becouz.net/category/computer');javascript:pageTracker._trackPageview('/outgoing/www.ordb.org/');" rel="nofollow" href="http://www.ordb.org/" target="_blank"&gt;ordb.org&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Open Relay Database&lt;/strong&gt;&lt;br /&gt;Database of SMTP servers that are not protected from spam misuse.&lt;/p&gt; &lt;p&gt;Logs about received email messages can be created for individual groups (the Log option) or messages can be rejected (the Block option). If the Log option is active, information is recorded into the Security log. The analysis of this log can be used to acquire a list of IP addresses of servers from which spam have been sent.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Custom IP address spammers database&lt;/strong&gt;&lt;br /&gt;This option can be used to select a custom defined IP address group. Use the Edit button to edit the selection or to create a new group.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Security Options Tab&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Apart from completely blocking certain senders Kerio MailServer provides options that limit, for example, sending too many messages or opening too many connections (known as DoS attack). These options can be set in the Security Options section.&lt;/p&gt; &lt;p style="text-align: center;"&gt;&lt;a onclick="pageTracker._trackPageview('/outgoing/i85.photobucket.com/albums/k57/becouz/attackprotection.png?referer=http://becouz.net/category/computer');javascript:pageTracker._trackPageview('/outgoing/i85.photobucket.com/albums/k57/becouz/attackprotection.png');" rel="nofollow" href="http://i85.photobucket.com/albums/k57/becouz/attackprotection.png" target="_blank"&gt;&lt;img style="width: 410px; height: 340px;" class="alignnone" rel="nofollow" src="http://i85.photobucket.com/albums/k57/becouz/attackprotection.png" alt="" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Max. number of messages per hour…&lt;/strong&gt;&lt;br /&gt;Maximum count of messages that can be sent from one IP address per hour. This protects the disc memory from overload by too many messages (often identical and undesirable).&lt;br /&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Max. number of concurrent SMTP connections…&lt;/strong&gt;&lt;br /&gt;Maximum number of concurrent TCP connections to the SMTP server from one IP address. This is a method of protection against DoS attacks (Denial of Service too many concurrent connections overload the system and no other users can connect to the server).&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Max. number of unknown recipients …&lt;/strong&gt;&lt;br /&gt;Also known as a Directory harvest attack, this condition is met when an application that guesses common usernames of recipients’ fails up to the number of allowed unknown recipients.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Do not apply these limits to IP address group&lt;/strong&gt;&lt;br /&gt;Group of IP addresses on which the limitations will not be applied. This rule is often used for groups of local users (see the Relay Control tab). These users send all their outgoing mail through Kerio MailServer the count of messages sent by these users to this server is therefore much higher than the number of messages sent by external users (servers) that use it only to deliver mail to local domains.&lt;/p&gt; &lt;p&gt;&lt;strong&gt; Block if sender’s mail domain…&lt;/strong&gt;&lt;br /&gt;When a message is received Kerio MailServer checks whether the sender’s domain has a record in DNS. If not, the message will be rejected. This feature protects from senders with fictional email addresses. Note: This function may slow down Kerio MailServer (responses of DNS servers may take up to several seconds).&lt;/p&gt; &lt;p&gt;&lt;strong&gt; Max. number of recipients in a message&lt;/strong&gt;&lt;br /&gt;Maximum number of message recipients that will be accepted (in the Rcpt To: entry of the SMTP envelope). This will protect your server from possible loops between two or among more SMTP servers.&lt;br /&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Max. number of failed commands…&lt;br /&gt;&lt;/strong&gt;Spam is often sent by special applications that connect to SMTP servers and ignore its error reports. If this option is enabled, Kerio MailServer will close the SMTP connection automatically after the defened number of failed commands has been expired.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Limit maximum incoming SMTP message size to&lt;/strong&gt;&lt;br /&gt;Maximum size of a message that will be accepted by the SMTP server. This protects the server from being overloaded by large messages. The 0 value means that no limitation is set. For easy definition you can switch between kilobytes (KB) and megabytes (MB).&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Maximum number of accepted Received headers (hops)&lt;/strong&gt;&lt;br /&gt;This parameter helps the server block messages that have been trapped in a loop.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;SMTP Delivery&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;In this section, the delivery parameters can be also set:&lt;/p&gt; &lt;p style="text-align: center;"&gt;&lt;a onclick="pageTracker._trackPageview('/outgoing/i85.photobucket.com/albums/k57/becouz/deliveryqueue.png?referer=http://becouz.net/category/computer');javascript:pageTracker._trackPageview('/outgoing/i85.photobucket.com/albums/k57/becouz/deliveryqueue.png');" rel="nofollow" href="http://i85.photobucket.com/albums/k57/becouz/deliveryqueue.png" target="_blank"&gt;&lt;img style="width: 410px; height: 268px;" class="alignnone" rel="nofollow" src="http://i85.photobucket.com/albums/k57/becouz/deliveryqueue.png" alt="" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Deliver directly using DNS MX records&lt;/strong&gt;&lt;br /&gt;Mail will be delivered directly to destination domains using MX records.&lt;br /&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Use relay SMTP server&lt;/strong&gt;&lt;br /&gt;All outgoing mail will be sent via another relay SMTP server.&lt;br /&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Relay server hostname&lt;/strong&gt;&lt;br /&gt;DNS name or IP address of relay SMTP server.&lt;br /&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Relay server port&lt;/strong&gt;&lt;br /&gt;Port where the relay SMTP is running. Typically the standard port 25 is used (this value is also set as Default).&lt;br /&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Relay server requires authentication&lt;/strong&gt;&lt;br /&gt;Use this option if relay server requires authentication of sender (Kerio MailServer) using username and password. Specify the User and Password entries.&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Authentication&lt;/strong&gt;&lt;br /&gt;Method of authentication at the relay server: SMTP AUTH Command or POP3 before SMTP (users enter local POP3 mailbox first they will be authenticated and allowed to send mail via SMTP server. Username and password used here will be used to login to the mailbox and no messages can be read. Therefore you do not need to define mailbox in Configuration POP3 Download to send an email message.)&lt;br /&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Use SSL if supported by remote SMTP server…&lt;/strong&gt;&lt;br /&gt;When sending a message, SMTP server attempts to use encrypted connection first (SSL). If SSL connection is not supported, unencrypted connection will be used. Thus the maximal possible security of sent mail is ensured.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Queue Options&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;In this tab, mail queue can be set. It can be viewed in Status Mail Queue.&lt;/p&gt; &lt;p style="text-align: center;"&gt;&lt;a onclick="pageTracker._trackPageview('/outgoing/i85.photobucket.com/albums/k57/becouz/queueoptions.png?referer=http://becouz.net/category/computer');javascript:pageTracker._trackPageview('/outgoing/i85.photobucket.com/albums/k57/becouz/queueoptions.png');" rel="nofollow" href="http://i85.photobucket.com/albums/k57/becouz/queueoptions.png" target="_blank"&gt;&lt;img style="width: 410px; height: 273px;" class="alignnone" rel="nofollow" src="http://i85.photobucket.com/albums/k57/becouz/queueoptions.png" alt="" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Maximum number of delivery threads&lt;/strong&gt;&lt;br /&gt;Maximum number of delivery threads that will send messages from the queue (maximum count of messages sent at one moment). The value should be chosen with respect to processor capacity and to speed of the Internet connection.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Delivery retry interval&lt;/strong&gt;&lt;br /&gt;Interval that will be used for repeated retry attempts for sending an email message.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Return the message to sender…&lt;/strong&gt;&lt;br /&gt;If the message cannot be delivered by expiration of this interval, it will be returned to sender. It will be automatically removed from the queue and no more delivery attempts will be taken by the server.&lt;/p&gt; &lt;p&gt;You can also use preset time units (minutes, hours, days) to specify the interval.&lt;/p&gt; &lt;p&gt;However, these time units will not be considered if the messages are delivered via relay SMTP server.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Send warning to sender…&lt;/strong&gt;&lt;br /&gt;If the message could not be delivered by expiration of this period, sender will be sent a warning (server will continue in sending attempts).&lt;br /&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Report language&lt;/strong&gt;&lt;br /&gt;Language that will be used for error, warning and informative reports. Note:Reports are stored in the reports subdirectory of the directory where Kerio MailServer is installed (UTF-8 coding is used). Administrator can modify individual reports or add a new language report version.&lt;/p&gt; &lt;p&gt;Note: Just to remember, for more information read : &lt;a onclick="pageTracker._trackPageview('/outgoing/www.redline-software.com?referer=http://becouz.net/category/computer');javascript:pageTracker._trackPageview('/outgoing/www.redline-software.com');" rel="nofollow" href="http://www.redline-software.com/" target="_blank"&gt;redline-software.com&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2785178257139955802-4768635512467254816?l=tapeuwie.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tapeuwie.blogspot.com/feeds/4768635512467254816/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://tapeuwie.blogspot.com/2009/03/testing.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2785178257139955802/posts/default/4768635512467254816'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2785178257139955802/posts/default/4768635512467254816'/><link rel='alternate' type='text/html' href='http://tapeuwie.blogspot.com/2009/03/testing.html' title='Secure SMTP Server with Kerio MailSever'/><author><name>Tape Uwie</name><uri>http://www.blogger.com/profile/12958472702638257190</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
