Beruflich Dokumente
Kultur Dokumente
IP Flow
Valens Riyadi
info@mikrotik.co.id
Citraweb Nusa Infomedia
on Mikrotik User Meeting, Krakow
January 25 – 26, 2007
Introduction
| Name: Valens Riyadi
| Country: Indonesia
z Graduated as Architect 1998
z 1998 ….. Web developer
z 2001 ….. Make a WISP
z 2002 ….. Mikrotik Reseller
z Photographer
• Administrator of www.fotografer.net
z Head of Security Dept, Indonesian ISP Association
z Volunteer for Airputih Foundation, IT Emergency Task Force
z Steering Committee for ID-SIRTII
Indonesia Security Incident Response Team on Information Infrastructure
z Mikrotik Certified Consultant
INDONESIA-IX
GATEWAY
ROUTER
YOGYA-IX
PROXIES E1 ROUTER
BANDWIDTH
MANAGEMENT
SERVERS TO
CUSTOMER
DISTRIBUTION
ROUTER
INTERNAL NAT
ROUTER
00-5 Mikrotik Indonesia http://www.mikrotik.co.id 1/18/2007
Wireless Instalation
BTS5
BTS1
BTS6
NOC-1 NOC-2
Ethernet Cable
BTS5
BTS1
DOWN
BTS6
DOWN
NOC-1 NOC-2
Ethernet Cable
BTS5
BTS1
BTS6
DOWN
X
NOC-1 NOC-2
Ethernet Cable
LOCAL
INPUT OUTPUT
PROCESS
IP Flow Mangle
Filter
Global-Out Queue
Global-Total Queue
Source-NAT
+ FORWARD Hotspot Output
BRIDGE Bridge BRIDGE Mangle
DST-NAT Decision FORWARD Filter
PRE Acounting
- ROUTING
-
Broute?
+ BRIDGE
INPUT
+ FORWARD
INPUT is - Routing
Bridged? Decision
To Router Filter
FORWARD
Global-Total Queue
Source-NAT
Hotspot Output
BRIDGE Bridge + BRIDGE Mangle
DST-NAT Decision FORWARD Filter
PRE Acounting
- ROUTING
-
Broute?
+ BRIDGE
INPUT
+ FORWARD
INPUT is - Routing
Bridged? Decision
FORWARD
Global-Total Queue
Source-NAT
Hotspot Output
BRIDGE Bridge + BRIDGE Mangle
DST-NAT Decision FORWARD Filter
PRE Acounting
- ROUTING
-
Broute?
+ BRIDGE
INPUT
+ FORWARD
INPUT is - Routing
Bridged? Decision
QUEUE DOWNLOAD
QUEUE UPLOAD
GLOBAL-OUT
DOWNLOAD
LOCAL
GLOBAL-IN
INPUT OUTPUT
MANGLE
MANGLE
UPLOAD
PROCESS
QUEUE DOWNLOAD
QUEUE UPLOAD
GLOBAL-OUT
DOWNLOAD
GLOBAL-IN LOCAL
INPUT OUTPUT
MANGLE
MANGLE
UPLOAD
PROCESS
Transparant
Bandwidth Management
Queue with Bridge
BRIDGE
BRIDGE
QUEUE TREE
BRIDGE
Upstream
INTERNET
Downstream
QUEUE TREE
1 chain=postrouting out-interface=LAN
dst-address=192.168.0.0/24 action=mark-packet
new-packet-mark=data-down passthrough=no
Queue with
Src-NAT and Internal Proxy
Queue with
SRC-NAT & Internal Proxy
ROUTER
SRC-NAT
WEB-PROXY
LOCAL
PROCESS
Direct Upstream 1
SRC-NAT
2
Direct Downstream
5 INTERNET
3
Upstream to proxy
WEB-PROXY
LOCAL
PROCESS
Downstream from proxy
4 6