Documente Academic
Documente Profesional
Documente Cultură
Routing (MTCRE)
Certified Mikrotik Training - Advanced Class (MTCRE)
Organized by: Citraweb Nusa Infomedia
(Mikrotik Certified Training Partner)
Jadwal Training
Sessi 1
08.30-10.00
Hari 1
Sessi 2
10.30-12.00
Static Route
Hari 2
Hari 3
Hari 4
00-2
Sessi 3
13.00-15.00
Sessi 4
15.30-17.00
IP Tunnel
OSPF
BGP Basic
MPLS Basic
Lab
Load Balanced
Test
15-Nov-11
00-3
Basic/Essential Training
l MikroTik Certified Network Associate (MTCNA)
Advanced Training
l Certified Wireless Engineer (MTCWE)
l Certified Routing Engineer (MTCRE)
l Certified Traffic Control Engineer (MTCTCE)
l Certified User Managing Engineer (MTCUME)
l Certified Inter Networking Engineer (MTCINE)
15-Nov-11
Certification Test
00-4
15-Nov-11
Trainers
Valens Riyadi
l
l
l
Novan Chris
l
l
l
Pujo Dewobroto
l
l
00-5
15-Nov-11
Perkenalan
Perkenalkanlah :
l
l
l
l
00-6
Nama Anda :
Tempat Bekerja :
Kota / Domisili :
Apa yang Anda kerjakan sehari-hari dan
fitur-fitur apa yang ada di Mikrotik yang
sudah Anda gunakan.
Motivasi mengikuti training.
15-Nov-11
01-8
15-Nov-11
01-9
15-Nov-11
01-10
Aktifkan
Neighbour
Protocol
pada wlan1
15-Nov-11
01-11
Persiapkan User di
system mikrotik
supaya siap di semua
kegiatan training.
15-Nov-11
WLAN1
10.10.10.1/24
WLAN1
10.10.10.X/24
ETHER1
192.168.1.1/24
ETHER1
192.168.2.1/24
ETHER1
192.168.X.1/24
ETHERNET PORT
192.168.1.2/24
ETHERNET PORT
192.168.2.2/24
ETHERNET PORT
192.168.X.2/24
MEJA 1
01-12
WLAN1
10.10.10.2/24
MEJA 2
Mikrotik Indonesia http://www.mikrotik.co.id
MEJA X
15-Nov-11
IP Configuration
01-13
Routerboard Setting
l WAN IP : 10.10.10.x/24
l Gateway : 10.10.10.100
l LAN IP : 192.168.x.1/24
l DNS : 10.100.100.1
l Services: Src-NAT and DNS Server
Laptop Setting
l IP Address : 192.168.x.2/24
l Gateway : 192.168.x.1
l DNS : 192.168.x.1
Mikrotik Indonesia http://www.mikrotik.co.id
15-Nov-11
Configuration
01-14
15-Nov-11
Routed Network
01-15
15-Nov-11
Routing!
01-16
15-Nov-11
Routing
192.168.1.0/24
192.168.3.0/24
192.168.2.0/24
ROUTER
GATEWAY
WIRELESS
01-17
192.168.0.0/24
15-Nov-11
Static Route
01-18
IP Address
Interface
15-Nov-11
dynamic routes
yang akan dibuat secara otomatis:
01-19
static routes
adalah informasi routing yang dibuat secara
manual oleh user untuk mengatur ke arah mana
trafik tertentu akan disalurkan. Default route
adalah salah satu contoh static routes.
15-Nov-11
Menambahkan Routing
01-20
15-Nov-11
Tipe Routing
A: Active
S: Static
A: Active
D: Dynamic
C: Connected
01-21
15-Nov-11
Connected Routes
01-22
15-Nov-11
Connected Routes
Network Prefix
Network Address
Forwarding Interface
Local Address
01-23
15-Nov-11
Static Route
15-Nov-11
01-25
Destination
l Destination address & network mask
l 0.0.0.0/0 -> ke semua network
Gateway
l IP Address gateway, harus merupakan IP Address yang satu subnet
dengan IP yang terpasang pada salah satu interface
l Gateway Interface, digunakan apabila IP gateway tidak diketahui dan
bersifat dinamik.
Pref Source
l source IP address dari paket yang akan meninggalkan router,
Biasanya adalah ip address yang terpasang di interface yang menjadi
gateway.
Distance
l Beban untuk kalkulasi pemilihan rule routing yang akan dijalankan
router.
15-Nov-11
Distance
Connected routes : 0
Static Routes
:1
eBGP
: 20
OSPF
RIP
MME
: 110
: 120
: 130
iBGP
: 200
l
l
01-26
Note:
Distance=255
berarti rejected
15-Nov-11
Internet
10.10.0.2/24
A
10.10.1.1/24
10.10.2.1/24
10.10.2.2/24
10.10.3.2/24
B
10.10.4.1/24
10.10.4.2/24
01-27
Dst-address=0.0.0.0/0 gateway=10.10.2.1
15-Nov-11
10.10.0.2/24
10.10.2.2/24
10.10.1.1/24
10.10.1.2/24
10.10.2.1/24
10.10.3.1/24
01-28
10.10.3.2/24
(DAC) Dst-addr= 10.10.3.0/24
pref-source=10.10.3.2
(AS) Dst-addr= 0.0.0.0/0 gw=10.10.3.1
15-Nov-11
Distance
01-29
15-Nov-11
Contoh Pemilihan
Destination
01-30
Gateway
Distance
Prioritas
192.168.0.0/27 192.168.1.1
192.168.0.0/29 192.168.2.1
192.168.0.0/24 192.168.3.1
192.168.0.0/24 192.168.4.1
15-Nov-11
01-31
Router 2
172.16.0.X1/32
IP Address
172.16.0.X2/32
172.16.0.X2
Network Address
172.16.0.X1
[kosongkan]
Broadcast Address
[kosongkan]
ether2
Interface
ether2
15-Nov-11
Router Meja X
172.16.0.X1/32
Ether2
Router Meja X
172.16.0.X2/32
Ether2
192.168.X.2
01-32
192.168.X.2
15-Nov-11
Router Meja 2
01-33
15-Nov-11
Check Gateway
01-34
15-Nov-11
01-35
15-Nov-11
192.168.X.2
R1
Ether2
172.16.Y.1/32
172.16.Y.3/32
Ether3
Ether3
172.16.Y.2/32
172.16.Y.5/32
Ether2
Internet
Ether3
172.16.Y.6/32
Ether2
172.16.Y.4/32
R3
172.16.Y.7/32
Ether3
172.16.Y.8/32
Ether2
192.168.X.2
01-36
R2
R4
192.168.X.2
15-Nov-11
01-37
15-Nov-11
192.168.1.2
R1
Ether2
172.16.Y.1/32
Ether3
172.16.Y.2/32
192.168.8.2
172.16.Y.3/32
Ether3
Ether2
172.16.Y.4/32
192.168.7.2
01-38
Dst-Address Gateway
0.0.0.0/0
10.10.10.100 No
192.168.2.0/24 172.16.Y.2
ping
192.168.2.0/24 172.16.Y.4
no
192.168.7.0/24 172.16.Y.4
ping
192.168.7.0/24 172.16.Y.2
no
192.168.8.0/24 172.16.Y.2
ping
192.168.8.0/24 172.16.Y.4
no
15-Nov-11
192.168.X.2
R1
Ether2
172.16.Y.1/32
172.16.Y.3/32
Ether3
Ether3
172.16.Y.2/32
172.16.Y.5/32
Ether2
Internet
Ether3
172.16.Y.6/32
Ether2
172.16.Y.4/32
R3
172.16.Y.7/32
Ether3
172.16.Y.8/32
Ether2
192.168.X.2
01-39
R2
R4
192.168.X.2
15-Nov-11
Evaluasi
01-40
15-Nov-11
01-41
15-Nov-11
01-42
15-Nov-11
10.10.10.1/24
01-43
117.20.50.233
Dst-Address
Gateway
Scope
Target Scope
0.0.0.0/0
117.20.50.233
30
30
117.20.50.233
10.10.10.100
30
10
15-Nov-11
01-44
15-Nov-11
Routing Modification
Dst-Address
Gateway
0.0.0.0/0
10.10.10.100 no
30
10
172.16.Y.5
172.16.Y.2
no
30
10
172.16.Y.6
172.16.Y.2
no
30
10
172.16.Y.7
172.16.Y.4
no
30
10
172.16.Y.8
172.16.Y.4
no
30
10
192.168.2.0/24
172.16.Y.2
ping
30
10
192.168.2.0/24
172.16.Y.4
no
30
10
192.168.7.0/24
172.16.Y.4
ping
30
10
192.168.7.0/24
172.16.Y.2
no
30
10
192.168.8.0/24
172.16.Y.6
ping
30
30
192.168.8.0/24
172.16.Y.4
no
30
10
01-45
15-Nov-11
01-46
15-Nov-11
01-47
15-Nov-11
Routing Type
01-48
15-Nov-11
Pref-source
01-49
15-Nov-11
Source Routing
01-50
15-Nov-11
[LAB-9] Pref-Source
Uplink Traffic
Downlink Traffic
10.20.20.100/24
10.10.10.100/24
10.10.10.X/24
WLAN1
01-51
10.20.20.X/24
WLAN2
15-Nov-11
01-52
15-Nov-11
Src-Nat Setting
01-53
15-Nov-11
All
Routes
OSPF
BGP
OSPF
RIP
MME
Output
Filters
Protocols
Routes
Input
Filters
RIP
Actives
Routes
Instance 1
Route
Selection
MME
BGP
Instance 1
Discard
01-54
Instance 2
Instance 2
Instance n
Instance n
15-Nov-11
01-55
15-Nov-11
Digunakan untuk:
l
l
01-56
15-Nov-11
Merupakan informasi
routing yang disimpan
dalam cache, sebagai
hasil olahan Routing
Information Base yang
telah terfilter
Cache
FIB
FIB
Routing Tables
Connected
Routes
Rules
Main
Implicit
Active
Routes
User
Defined
Catch All
01-57
15-Nov-11
Policy Route
01-58
IP - Route Rules
IP - Firewall - Mangle Route-mark
15-Nov-11
Route Rules
01-59
15-Nov-11
Internet
10.10.10.100/24
10.20.20.100/24
10.10.10.X/24
WLAN1
Ether1
192.168.X.0/24
01-60
10.20.20.X/24
WLAN2
Ether2
172.16.X.0/24
15-Nov-11
Route - Rules
01-61
Tambahkan Route
Rules untuk
menentukan
klasifikasi dari
segmen network yang
akan menggunakan
gateway yang
berbeda.
15-Nov-11
01-62
Tambahkan rule
routing untuk
mengarahkan
segmen network2
supaya menggunakan
gateway lain.
15-Nov-11
01-63
15-Nov-11
Internet
10.10.10.100/24
10.20.20.100/24
10.10.10.X/24
WLAN1
01-64
10.20.20.X/24
WLAN2
15-Nov-11
01-65
15-Nov-11
01-66
15-Nov-11
Static Route
Trafik Lainnya
01-67
Trafik TCP 80
15-Nov-11
Tunnel
Certified Mikrotik Training Advanced Class (MTCRE)
Organized by: Citraweb Nusa Infomedia
(Mikrotik Certified Training Partner)
IP Tunnel
IP Tunnel Network
WAN CLOUD
Point 1
tunnel
1.1.1.1
R1
Point 2
1.1.1.2
R2
IP Address: 10.0.0.0/24
IP Address: 20.1.1.0/24
VPN Networks
Aplication Server
File Server
Client 1
Server
Office 1
PC
Aplication Server
Router
Office 2
Router
WAN
PC
PC
PC
VPN Networks
File Server
Client 2
Mobile
Client 2
Mobile
Client 1
Office 3
Router
PC
PC
PC
PC
Tunnel
l
l
l
l
IPIP IP Tunnel
EoIP Ethernet Over IP
VLAN Virtual Lan
Gre Tunnel
VPN
l
l
l
l
l
l
IPIP
IPIP Example
Internet
Uplink ISP
DVB Provider
Sattelite
IPIP Tunnel
Our Router
IPIP Configuration
IPIP Configuration
10.10.10.30/24
IPIP1 Address :
192.168.200.2/30
10.10.10.100/24
10.10.10.31/24
ROUTER B
10.10.10.30/24
IPIP1 Address :
192.168.200.2/30
10.10.10.100/24
10.10.10.31/24
IPIP1 Address :
192.168.200.2/30
Meja 1
192.168.1.1/24
Meja 2
10.10.10.100/24
192.168.2.1/24
IP Sec Example
IPSec on Mikrotik
Internet
City A
City B
IPIP
192.168.1.1
192.168.2.1
192.168.2.2
192.168.1.2
IPSec Peer
IPSec on Mikrotik
IPSec on Mikrotik
Router A
Router B
IPSec Encryption
IPSec Decryption
[LAB-2] IPSec
Internet
10.10.10.1
10.10.10.2
Meja 1
Meja 2
192.168.2.1
IPIP
192.168.1.1
10.20.20.1
10.20.20.2
192.168.1.2
192.168.2.2
IP Sec Encrypted Tunnel
Router 1
Router 2
IPSec Performance
EoIP Example
Internet
10.0.0.1
10.10.10.1
City A
192.168.0.11
192.168.0.12
City B
192.168.0.1
EoIP
192.168.0.13
192.168.0.3
192.168.0.2
EoIP Configuration
Parameter Remote-Address
adalah parameter ip address
dari Router lawan.
Tunnel-ID adalah parameter
identitas dari koneksi tunnel.
Jika ingin membangun
sebuah tunnel melewati
jaringan WAN atau Internet
maka gunakan IP public untuk
parameter Remote-Address.
Pastikan Tunnel ID yang
berbeda di tiap tunnel
interface pada satu router.
EoIP Configuration