Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #
- /ip firewall mangle
- add action=mark-connection chain=prerouting comment="===>PING-LANCAR" \
- new-connection-mark=icmp-conn passthrough=yes protocol=icmp src-address=\
- 192.10.10.0/24
- add action=mark-packet chain=prerouting connection-mark=icmp-conn \
- new-packet-mark=icmp-p passthrough=no
- add action=change-dscp chain=prerouting new-dscp=0 packet-mark=icmp-p \
- passthrough=yes
- add action=mark-connection chain=prerouting comment="====>DNS" dst-port=53 \
- new-connection-mark=dns-conn passthrough=yes protocol=tcp src-address=\
- 192.10.10.0/24
- add action=mark-connection chain=prerouting dst-port=53 new-connection-mark=\
- dns-conn passthrough=yes protocol=udp src-address=192.10.10.0/24
- add action=mark-packet chain=prerouting connection-mark=dns-conn \
- new-packet-mark=dns-p passthrough=yes
- add action=change-dscp chain=prerouting new-dscp=0 packet-mark=dns-p \
- passthrough=yes
- add action=mark-connection chain=forward comment=Mobile-Legend dst-port=\
- 30100-30200 new-connection-mark=moba-conn passthrough=yes protocol=tcp \
- src-address=192.10.10.0/24
- add action=mark-connection chain=forward dst-port=30091-30099 \
- new-connection-mark=moba-conn passthrough=yes protocol=udp src-address=\
- 192.10.10.0/24
- add action=mark-connection chain=forward dst-port=5001-5009 \
- new-connection-mark=moba-conn passthrough=yes protocol=udp src-address=\
- 192.10.10.0/24
- add action=mark-packet chain=forward connection-mark=moba-conn \
- new-packet-mark=moba-packet passthrough=no
- add action=accept chain=input comment="mangel GGC" dst-address-list=\
- private-lokal src-address-list=private-lokal
- add action=accept chain=prerouting dst-address-list=private-lokal \
- src-address-list=private-lokal
- add action=accept chain=forward dst-address-list=private-lokal \
- src-address-list=private-lokal
- add action=accept chain=postrouting dst-address-list=private-lokal \
- src-address-list=private-lokal
- add action=accept chain=output dst-address-list=private-lokal \
- src-address-list=private-lokal
- add action=mark-connection chain=prerouting comment=icmp-dns \
- dst-address-list=!private-lokal new-connection-mark=icmp-dns passthrough=\
- yes protocol=icmp src-address-list=private-lokal
- add action=mark-connection chain=prerouting dst-address-list=!private-lokal \
- dst-port=5353,123 new-connection-mark=icmp-dns passthrough=yes protocol=\
- tcp src-address-list=private-lokal
- add action=mark-connection chain=prerouting dst-address-list=!private-lokal \
- dst-port=5353,123 new-connection-mark=icmp-dns passthrough=yes protocol=\
- udp src-address-list=private-lokal
- add action=accept chain=prerouting connection-mark=icmp-dns
- add action=mark-packet chain=forward connection-mark=icmp-dns \
- new-packet-mark=icmp-dns passthrough=no
- add action=mark-connection chain=prerouting comment=ggc-telkom \
- connection-mark=no-mark dst-address-list=ggc-telkom new-connection-mark=\
- ggc-telkom passthrough=yes src-address-list=private-lokal
- add action=mark-packet chain=forward connection-mark=ggc-telkom \
- new-packet-mark=ggc-telkom passthrough=no
- add action=mark-connection chain=prerouting comment=sosmed connection-mark=\
- no-mark dst-address-list=sosmed new-connection-mark=sosmed passthrough=\
- yes src-address-list=private-lokal
- add action=mark-packet chain=forward connection-mark=sosmed new-packet-mark=\
- sosmed passthrough=no
- add action=mark-connection chain=prerouting comment=trafik connection-mark=\
- no-mark dst-address-list=!private-lokal dst-port=\
- 5000,5500-7100,9000,9091,3000-3200 new-connection-mark=trafik \
- passthrough=yes protocol=tcp src-address-list=private-lokal
- add action=mark-connection chain=prerouting connection-mark=no-mark \
- dst-address-list=!private-lokal dst-port=\
- 5000,5500-7100,9000,9091,3000-3200 new-connection-mark=trafik \
- passthrough=yes protocol=udp src-address-list=private-lokal
- add action=mark-connection chain=prerouting connection-mark=no-mark \
- dst-address-list=!private-lokal dst-port=\
- 0-2000,5050,8777,8000-8099,5353,5938,8291,12671-12675,16800 \
- new-connection-mark=trafik passthrough=yes protocol=tcp src-address-list=\
- private-lokal
- add action=mark-connection chain=prerouting connection-mark=no-mark \
- dst-address-list=!private-lokal dst-port=\
- 0-2000,5050,8777,8000-8099,5353,5938,8291,12671-12675,16800 \
- new-connection-mark=trafik passthrough=yes protocol=udp src-address-list=\
- private-lokal
- add action=mark-connection chain=prerouting connection-mark=no-mark \
- dst-address-list=!private-lokal layer7-protocol=torrent1 \
- new-connection-mark=trafik passthrough=yes src-address-list=private-lokal
- add action=mark-connection chain=prerouting connection-mark=no-mark \
- dst-address-list=!private-lokal layer7-protocol=torrent2 \
- new-connection-mark=trafik passthrough=yes src-address-list=private-lokal
- add action=mark-connection chain=prerouting connection-mark=no-mark \
- dst-address-list=!private-lokal layer7-protocol=torrent3 \
- new-connection-mark=trafik passthrough=yes src-address-list=private-lokal
- add action=mark-connection chain=prerouting connection-mark=no-mark \
- dst-address-list=!private-lokal layer7-protocol=torrent4 \
- new-connection-mark=trafik passthrough=yes src-address-list=private-lokal
- add action=mark-connection chain=prerouting comment=high-priority \
- connection-mark=no-mark dst-address-list=!private-lokal \
- new-connection-mark=high-priority passthrough=yes src-address-list=\
- private-lokal
- add action=accept chain=prerouting connection-mark=high-priority
- add action=mark-packet chain=forward connection-mark=high-priority \
- new-packet-mark=high-priority passthrough=no
- add action=mark-packet chain=forward comment=browsing connection-mark=trafik \
- connection-rate=0-1M new-packet-mark=browsing passthrough=no
- add action=mark-packet chain=forward comment=midle-trafik connection-mark=\
- trafik connection-rate=1000001-3M new-packet-mark=midle-trafik \
- passthrough=no
- add action=mark-packet chain=forward comment=high-trafik connection-mark=\
- trafik connection-rate=3000001-1G new-packet-mark=high-trafik \
- passthrough=no
- /ip firewall raw
- add action=add-dst-to-address-list address-list=mobile-legend \
- address-list-timeout=0s chain=prerouting disabled=yes dst-port=\
- 30100-30110 protocol=tcp
- add action=add-src-to-address-list address-list=client-on-ml \
- address-list-timeout=5m chain=prerouting comment=Mobile-Legend \
- dst-address=161.202.0.0/16 dst-address-list=!private-lokal
- add action=add-src-to-address-list address-list=client-on-ml \
- address-list-timeout=5m chain=prerouting dst-address=119.81.0.0/16 \
- dst-address-list=!private-lokal
- #
- /queue tree
- add max-limit=25M name=INCOMING parent=global queue=default
- add limit-at=64k max-limit=25M name=I.01.ICMP-DNS packet-mark=icmp-dns \
- parent=INCOMING priority=1 queue=default
- add limit-at=5M max-limit=25M name=I.02.HIGH-PRIORITY packet-mark=\
- high-priority parent=INCOMING priority=3 queue=default
- add limit-at=25M max-limit=25M name=I.03.NORMAL parent=INCOMING queue=default
- add limit-at=15M max-limit=25M name=I.03.1.SOSMED packet-mark=sosmed parent=\
- I.03.NORMAL priority=5 queue=pcq-download-default
- add limit-at=15M max-limit=25M name=I.03.2.BROWSING packet-mark=browsing \
- parent=I.03.NORMAL priority=5 queue=pcq-download-default
- add limit-at=10M max-limit=25M name=I.03.3.MIDLE-TRAFIK packet-mark=\
- midle-trafik parent=I.03.NORMAL priority=7 queue=pcq-download-default
- add limit-at=15M max-limit=25M name=I.03.4.HIGH-TRAFIK packet-mark=\
- high-trafik parent=I.03.NORMAL queue=pcq-download-default
- add limit-at=10M max-limit=25M name=I.04.YOUTUBE-GOOGLE packet-mark=\
- ggc-telkom parent=INCOMING queue=pcq-download-default
- add max-limit=10M name=OUTGOING parent=global queue=default
- add limit-at=64k max-limit=10M name=O.01.ICMP-DNS packet-mark=icmp-dns \
- parent=OUTGOING priority=1 queue=default
- add limit-at=3M max-limit=10M name=O.02.HIGH-PRIORITY packet-mark=\
- high-priority parent=OUTGOING priority=3 queue=default
- add limit-at=10M max-limit=10M name=O.03.NORMAL parent=OUTGOING queue=default
- add limit-at=3M max-limit=10M name=O.03.1.SOSMED packet-mark=sosmed parent=\
- O.03.NORMAL priority=5 queue=pcq-upload-default
- add limit-at=3M max-limit=10M name=O.03.2.BROWSING packet-mark=browsing \
- parent=O.03.NORMAL priority=5 queue=pcq-upload-default
- add limit-at=1M max-limit=10M name=O.03.3.MIDLE-TRAFIK packet-mark=\
- midle-trafik parent=O.03.NORMAL priority=7 queue=pcq-upload-default
- add limit-at=3M max-limit=10M name=O.03.4.HIGH-TRAFIK packet-mark=high-trafik \
- parent=O.03.NORMAL queue=pcq-upload-default
- add limit-at=3M max-limit=10M name=O.04.YOUTUBE-GOOGLE packet-mark=ggc-telkom \
- parent=OUTGOING queue=pcq-upload-default
- add max-limit=25M name=#JAMU-DOWN parent=global priority=1 queue=PING-LANCAR
- add limit-at=56k max-limit=128k name=dns packet-mark=icmp-p parent=#JAMU-DOWN \
- priority=1 queue=PING-LANCAR
- add limit-at=56k max-limit=128k name=ping packet-mark=icmp-p parent=\
- #JAMU-DOWN priority=1 queue=PING-LANCAR
- /queue type
- add kind=pcq name=PCQ-Download pcq-classifier=dst-address \
- pcq-dst-address6-mask=64 pcq-rate=4096k pcq-src-address6-mask=64
- add kind=pcq name=PCQ-Upload pcq-classifier=src-address \
- pcq-dst-address6-mask=64 pcq-rate=4096k pcq-src-address6-mask=64
- add kind=pfifo name=PING-LANCAR pfifo-limit=64
- set 9 pcq-rate=1024
- config firewall.txt
- Masuk
- Menampilkan config firewall.txt.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement