<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4650800593925871709</id><updated>2012-01-12T13:52:16.483+07:00</updated><title type='text'>Internet Network Troubleshoot</title><subtitle type='html'>This blog content Internet and Network Troubleshoot guide, tips and trick based on my experience from day to day activities as Network Administrator</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>92</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-5966864355967534686</id><published>2011-08-24T16:06:00.008+07:00</published><updated>2011-08-24T17:05:10.488+07:00</updated><title type='text'>ACK Time Out and Distance for Sectoral AP / PTMP</title><content type='html'>&lt;div&gt;&lt;span style="text-decoration: underline;"&gt;S&lt;/span&gt;ekedar info untuk Access Point dengan antena Sectoral khususnya UBNT Family ada yang berpendapat di forum luar sbb:&lt;br /&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Auto ACK is having way too many problems. Set everything to manual.&lt;br /&gt;&lt;br /&gt;Set the AP to 10% greater than the farthest client's actual distance.&lt;br /&gt;Set the stations to 10% greater than distance back to the AP.&lt;br /&gt;&lt;br /&gt;HOWEVER...I'm beginning to think that 10% number shouldn't be written in stone. I had one station with a 40% CCQ jump to 100% CCQ when I increased ACK from 10% to 15%. And it dropped down to around 40% when I set the ACK back to 10%. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://208.68.95.4/forum/showthread.php?t=15162"&gt;http://208.68.95.4/forum/showthread.php?t=15162&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;apa itu ACK Time Out? bisa baca-baca di :&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.air-stream.org.au/ACK_Timeouts"&gt;http://www.air-stream.org.au/ACK_Timeouts&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Kenapa jangan auto? ini penjelasannya:&lt;/div&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;For AP configuration you want to disable auto ACK because it would be readjusting for every client on the fly which I bet would waste CPU and possibly allow the AP to miss a few packets.&lt;br /&gt;&lt;br /&gt;For clients, which should be the same ACK since your AP does not move, auto ACK should be OK. Since hopefully you have waaaaaay more clients than APs, most of your configs should be auto ack, thus it is the default option.&lt;br /&gt;&lt;br /&gt;For point to point shots what I have done is enable auto ack, let the link go for a bit, then observe the main screen to see what value it settles into. Then I disable auto ack and put that value plus 10% in there as a static value. I only do this because I figure it would be more CPU efficient if the AP does not have to perform the ack finding code execution.&lt;br /&gt;&lt;br /&gt;In theory, the link should be faster since the main bottleneck for these units when used as a backbone is CPU from what I read. The less CPU you use means the more you have available to pass packets I assume. I have not taken the time to confirm this however. I just think it sounds good on paper. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.ubnt.com/forum/showpost.php?p=45051&amp;amp;postcount=2"&gt;http://www.ubnt.com/forum/showpost.php?p=45051&amp;amp;postcount=2&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Nah jadi sebagai contoh di salah satu sectoral yang menggunakan ubnt rocket saya bisa lihat melalui aplikasi yang Ok banget dari ubnt = &lt;a href="http://www.ubnt.com/wiki/AirControl#Installation"&gt;AirControl &lt;/a&gt;bisa dilihat jarak terjauh dari client yang terhubung ke Access Point tsb.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-cOG8bH11SII/TlTI5gnYUhI/AAAAAAAAAjw/mfSe6OSJXlg/s1600/aircontrols2.PNG"&gt;&lt;img style="text-align: center; margin: 0px auto 10px; width: 320px; display: block; height: 162px;" id="BLOGGER_PHOTO_ID_5644357123335279122" alt="" src="http://1.bp.blogspot.com/-cOG8bH11SII/TlTI5gnYUhI/AAAAAAAAAjw/mfSe6OSJXlg/s320/aircontrols2.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;contoh web interface pake java aircontrol&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;Dari client terjauh menurut forum diatas tambahkan 15% dari jarak client terjauh jadi dalam contoh ini 1400meter + 1400meter * 15% = 1610meter di contoh ini saya jadikan 1miles ~ 1,7Km&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-aOeM6ch2c_E/TlTI59lRPjI/AAAAAAAAAj4/8LGFqxl2qg4/s1600/ack-distance-rocket.PNG"&gt;&lt;img style="text-align: center; margin: 0px auto 10px; width: 320px; display: block; height: 162px;" id="BLOGGER_PHOTO_ID_5644357131111054898" alt="" src="http://3.bp.blogspot.com/-aOeM6ch2c_E/TlTI59lRPjI/AAAAAAAAAj4/8LGFqxl2qg4/s320/ack-distance-rocket.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Hasilnya bisa dilihat di Tab Main&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-Gykx-P1NiQ4/TlTI6LScB3I/AAAAAAAAAkA/RVRofQGsG50/s1600/main-status.PNG"&gt;&lt;img style="text-align: center; margin: 0px auto 10px; width: 320px; display: block; height: 245px;" id="BLOGGER_PHOTO_ID_5644357134790166386" alt="" src="http://3.bp.blogspot.com/-Gykx-P1NiQ4/TlTI6LScB3I/AAAAAAAAAkA/RVRofQGsG50/s320/main-status.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Diharapkan dengan tidak menggunakan auto-ACK tetapi ACK mengikuti parameter jarak/Distance CCQ station-station yang terhubung ke Access Point bisa lebih stabil&lt;br /&gt;&lt;br /&gt;Nah teori ini harus di buktikan dalam 1-2 hari kedepan , karena belum diuji :)&lt;br /&gt;&lt;br /&gt;oh ya satu lagi dengan menggunakan AirControl maka setiap radio UBNT bisa di atur jadwal rebootnya agar memory UBNT tidak jenuh , selain itu configurasi nya juga bisa di backup secara berkala secara otomatis, untuk menggunakan AirControl tinggal download install di Ms.Windows yang sudah ada Java Virtual Machine nya lalu tinggal dibuka pake web browser .&lt;br /&gt;&lt;br /&gt;AirControl ini ya semacam Dude kalau di Mikrotik kurang-lebih begitu ada mapnya juga&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-5966864355967534686?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/5966864355967534686/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=5966864355967534686' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5966864355967534686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5966864355967534686'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2011/08/ack-time-out-and-distance-for-sectoral.html' title='ACK Time Out and Distance for Sectoral AP / PTMP'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-cOG8bH11SII/TlTI5gnYUhI/AAAAAAAAAjw/mfSe6OSJXlg/s72-c/aircontrols2.PNG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-7229020859191988290</id><published>2011-04-14T18:12:00.001+07:00</published><updated>2011-04-14T18:14:01.307+07:00</updated><title type='text'>Visio Shape for Mikrotik and Ubnt</title><content type='html'>&lt;a href="http://h1x.com/mt/Mikrotik-Visio.zip"&gt;http://h1x.com/mt/Mikrotik-Visio.zip&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.ubnt.com/downloads/UBNT-visio-shapes.zip"&gt;http://www.ubnt.com/downloads/UBNT-visio-shapes.zip&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;download and extract to My Document/My Shapes&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-7229020859191988290?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/7229020859191988290/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=7229020859191988290' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/7229020859191988290'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/7229020859191988290'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2011/04/visio-shape-for-mikrotik-and-ubnt.html' title='Visio Shape for Mikrotik and Ubnt'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-9033771095352539408</id><published>2011-04-09T08:31:00.002+07:00</published><updated>2011-04-09T08:33:46.401+07:00</updated><title type='text'>Yahoo Messenger address-list for Mikrotik</title><content type='html'>Reference:&lt;br /&gt;&lt;a href="http://forums.miranda-im.org/showthread.php?2810-Problem-connecting-to-Yahoo-Messenger-server"&gt;http://forums.miranda-im.org/showthread.php?2810-Problem-connecting-to-Yahoo-Messenger-server&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;C:\Users\Harijanto&amp;gt;nslookup scsc.msg.yahoo.com&lt;br /&gt;Server:  google-public-dns-a.google.com&lt;br /&gt;Address:  8.8.8.8&lt;br /&gt;&lt;br /&gt;Non-authoritative answer:&lt;br /&gt;Name:    vcs0.msg.g03.yahoodns.net&lt;br /&gt;Addresses:  98.136.48.101&lt;br /&gt;          98.136.48.67&lt;br /&gt;          98.136.48.111&lt;br /&gt;          98.136.48.79&lt;br /&gt;          98.136.48.80&lt;br /&gt;          98.136.48.141&lt;br /&gt;          98.136.48.102&lt;br /&gt;          98.136.48.100&lt;br /&gt;Aliases:  scsc.msg.yahoo.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;C:\Users\Harijanto&amp;gt;nslookup scs.msg.yahoo.com&lt;br /&gt;Server:  google-public-dns-a.google.com&lt;br /&gt;Address:  8.8.8.8&lt;br /&gt;&lt;br /&gt;Non-authoritative answer:&lt;br /&gt;Name:    vcs0.msg.g03.yahoodns.net&lt;br /&gt;Addresses:  98.136.48.67&lt;br /&gt;          98.136.48.79&lt;br /&gt;          98.136.48.110&lt;br /&gt;          98.136.48.112&lt;br /&gt;          98.136.48.107&lt;br /&gt;          98.136.48.80&lt;br /&gt;          98.136.48.108&lt;br /&gt;          98.136.48.74&lt;br /&gt;Aliases:  scs.msg.yahoo.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;C:\Users\Harijanto&amp;gt;nslookup scsa.msg.yahoo.com&lt;br /&gt;Server:  google-public-dns-a.google.com&lt;br /&gt;Address:  8.8.8.8&lt;br /&gt;&lt;br /&gt;Non-authoritative answer:&lt;br /&gt;Name:    vcs0.msg.g03.yahoodns.net&lt;br /&gt;Addresses:  98.136.48.78&lt;br /&gt;          98.136.48.70&lt;br /&gt;          98.136.48.67&lt;br /&gt;          98.136.48.107&lt;br /&gt;          98.136.48.114&lt;br /&gt;          98.136.48.80&lt;br /&gt;          98.136.48.104&lt;br /&gt;          98.136.48.81&lt;br /&gt;Aliases:  scsa.msg.yahoo.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;C:\Users\Harijanto&amp;gt;nslookup scsb.msg.yahoo.com&lt;br /&gt;Server:  google-public-dns-a.google.com&lt;br /&gt;Address:  8.8.8.8&lt;br /&gt;&lt;br /&gt;Name:    scsb.msg.yahoo.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;C:\Users\Harijanto&amp;gt;nslookup scsc.msg.yahoo.com&lt;br /&gt;Server:  google-public-dns-a.google.com&lt;br /&gt;Address:  8.8.8.8&lt;br /&gt;&lt;br /&gt;Non-authoritative answer:&lt;br /&gt;Name:    vcs0.msg.g03.yahoodns.net&lt;br /&gt;Addresses:  98.136.48.111&lt;br /&gt;          98.136.48.81&lt;br /&gt;          98.136.48.77&lt;br /&gt;          98.136.48.102&lt;br /&gt;          98.136.48.116&lt;br /&gt;          98.136.48.70&lt;br /&gt;          98.136.48.76&lt;br /&gt;          98.136.48.110&lt;br /&gt;Aliases:  scsc.msg.yahoo.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;C:\Users\Harijanto&amp;gt;&lt;br /&gt;&lt;br /&gt;/ ip firewall address-list&lt;br /&gt;add list=yahoo-messenger address=98.136.48.119 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.102 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.101 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.67 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.111 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.79 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.80 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.141 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.100 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.110 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.112 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.107 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.108 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.74 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.70 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.114 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.104 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.81 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.77 comment="" disabled=no&lt;br /&gt;add list=yahoo-messenger address=98.136.48.116 comment="" disabled=no&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-9033771095352539408?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/9033771095352539408/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=9033771095352539408' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/9033771095352539408'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/9033771095352539408'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2011/04/yahoo-messenger-address-list-for.html' title='Yahoo Messenger address-list for Mikrotik'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-7295505430101441437</id><published>2011-03-20T18:44:00.004+07:00</published><updated>2011-03-20T18:57:03.382+07:00</updated><title type='text'>Good Reference when you need migrate your cpanel server to new one</title><content type='html'>&lt;a href="http://www.webhostinguniverse.com/tutorials/migratecpanel.htm"&gt;http://www.webhostinguniverse.com/tutorials/migratecpanel.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.crucialp.com/resources/tutorials/dedicated-server/how-to-install-installing-fantastico-cpanel-whm.php"&gt;http://www.crucialp.com/resources/tutorials/dedicated-server/how-to-install-installing-fantastico-cpanel-whm.php&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://forum.likg.org.ua/server-side-actions/cphulkd-management-t94.html"&gt;http://forum.likg.org.ua/server-side-actions/cphulkd-management-t94.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://forums.cpanel.net/f5/change-ttl-multiple-dns-zones-76580.html"&gt;&lt;br /&gt;http://forums.cpanel.net/f5/change-ttl-multiple-dns-zones-76580.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://linuxproblem.org/art_9.html"&gt;http://linuxproblem.org/art_9.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;and this is my tips:&lt;br /&gt;&lt;br /&gt;1. when install cpanel dnsonly with new OS like Centos 5.5 I modify the file:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;more /etc/sysconfig/named&lt;br /&gt;# BIND named process options&lt;br /&gt;# ~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;# Currently, you can use the following options:&lt;br /&gt;#&lt;br /&gt;# ROOTDIR="/some/where"  --  will run named in a chroot environment.&lt;br /&gt;#                            you must set up the chroot environment&lt;br /&gt;#                            (install the bind-chroot package) before&lt;br /&gt;#                            doing this.&lt;br /&gt;#&lt;br /&gt;# OPTIONS="whatever"     --  These additional options will be passed to named&lt;br /&gt;#                            at startup. Don't add -t here, use ROOTDIR instead.&lt;br /&gt;#&lt;br /&gt;# ENABLE_ZONE_WRITE=yes  --  If SELinux is disabled, then allow named to write&lt;br /&gt;#                            its zone files and create files in its $ROOTDIR/var/named&lt;br /&gt;#                            directory, necessary for DDNS and slave zone transfers.&lt;br /&gt;#                            Slave zones should reside in the $ROOTDIR/var/named/slaves&lt;br /&gt;#                            directory, in which case you would not need to enable zone&lt;br /&gt;#                            writes. If SELinux is enabled, you must use only the&lt;br /&gt;#                            'named_write_master_zones' variable to enable zone writes.&lt;br /&gt;#&lt;br /&gt;# ENABLE_SDB=yes         --  This enables use of 'named_sdb', which has support&lt;br /&gt;#                        --  for the ldap, pgsql and dir zone database backends&lt;br /&gt;#                        --  compiled in, to be used instead of named.&lt;br /&gt;#&lt;br /&gt;# DISABLE_NAMED_DBUS=[1y]--  If NetworkManager is enabled in any runlevel, then&lt;br /&gt;#                            the initscript will by default enable named's D-BUS&lt;br /&gt;#                            support with the named -D option. This setting disables&lt;br /&gt;#                            this behavior.&lt;br /&gt;#&lt;br /&gt;# KEYTAB_FILE="/dir/file"    --  Specify named service keytab file (for GSS-TSIG)&lt;br /&gt;ENABLE_ZONE_WRITE=yes&lt;br /&gt;OPTIONS="-4"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;and because cpanel not using bind-chroot so better you remove bind-chroot with command:&lt;br /&gt;&lt;br /&gt;yum remove bind-chroot&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-7295505430101441437?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/7295505430101441437/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=7295505430101441437' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/7295505430101441437'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/7295505430101441437'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2011/03/good-reference-when-you-need-migrate.html' title='Good Reference when you need migrate your cpanel server to new one'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-410591546446112495</id><published>2011-02-26T19:57:00.005+07:00</published><updated>2011-02-26T21:38:09.012+07:00</updated><title type='text'>Bonding Two ADSL</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;IN&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-qformat:yes;  mso-style-parent:"";  mso-padding-alt:0cm 5.4pt 0cm 5.4pt;  mso-para-margin-top:0cm;  mso-para-margin-right:0cm;  mso-para-margin-bottom:10.0pt;  mso-para-margin-left:0cm;  line-height:115%;  mso-pagination:widow-orphan;  font-size:11.0pt;  font-family:"Calibri","sans-serif";  mso-ascii-font-family:Calibri;  mso-ascii-theme-font:minor-latin;  mso-hansi-font-family:Calibri;  mso-hansi-theme-font:minor-latin;  mso-bidi-font-family:"Times New Roman";  mso-bidi-theme-font:minor-bidi;  mso-fareast-language:EN-US;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;Because I must wait 1-2 months to upgrade my Intercity Leased Line (LL) between Indonesia Internet Exchange (IIX) locate in Cyber Building, South Jakarta with my remote site with distance 266km so i try using Mikrotik Interface Bonding Solution, and it works.&lt;br /&gt;&lt;br /&gt;So this is the configuration for Mikrotik Router locate in remote site:&lt;br /&gt;&lt;br /&gt;I used two ADSL connection&lt;br /&gt;&lt;br /&gt;/interface pppoe-client&lt;br /&gt;add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 \&lt;br /&gt;    dial-on-demand=no disabled=no interface=ether1_adsl1 max-mru=1480 max-mtu=\&lt;br /&gt;    1480 mrru=disabled name=telkom1 password=123456 profile=pppoe \&lt;br /&gt;    service-name="" use-peer-dns=no user=adsl1@telkom.net&lt;br /&gt;add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 \&lt;br /&gt;    dial-on-demand=no disabled=no interface=ether3_adsl2 max-mru=1480 max-mtu=\&lt;br /&gt;    1480 mrru=disabled name=telkom2 password=123456 profile=pppoe \&lt;br /&gt;    service-name="" use-peer-dns=no user=adsl2@telkom.net&lt;br /&gt;&lt;br /&gt;note:&lt;/span&gt;&lt;/p&gt;  &lt;ol start="1" type="1"&gt;&lt;li class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;password=123456 , this is just      example you must using your own password&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;user=adsl1@telkom.net,       this is just example you must using your own user&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;[Me@RemoteSite] /ip address print detail&lt;br /&gt;Flags: X - disabled, I - invalid, D - dynamic&lt;br /&gt; 0   ;;; BONDING PDA1 D3&lt;br /&gt;     address=1.2.3.62/30 network=1.2.3.60&lt;br /&gt;     interface=BONDING_PDA1_D3_EOIP actual-interface=BONDING_PDA1_D3_EOIP&lt;br /&gt;&lt;br /&gt;5 D address=1.2.255.218/32 network=1.2.255.1 interface=telkom2&lt;br /&gt;     actual-interface=telkom2&lt;br /&gt;&lt;br /&gt; 6 D address=1.2.251.170/32 network=1.2.250.1 interface=telkom1&lt;br /&gt;     actual-interface=telkom1&lt;br /&gt;&lt;br /&gt;note:&lt;/span&gt;&lt;/p&gt;  &lt;ol start="1" type="1"&gt;&lt;li class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;address=1.2.3.63/30 , this is      point-to-point ip address between bonding interface jakarta with remote      site&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;address=1.2.255.218/32 and      address=1.2.250.170/32, this is ip address from ADSL provider, this is      good because between telkom1 and telkom2 using different gateway and      network so we can create different routing statick for two eoip connection      for each ADSL &lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;&lt;br /&gt;/ip route&lt;br /&gt;add check-gateway=ping comment="DEFAULT GATEWAY via BONDING RO JAKARTA" \&lt;br /&gt;    disabled=no distance=1 dst-address=0.0.0.0/0 gateway=1.2.3.61 scope=30 \&lt;br /&gt;    target-scope=10&lt;br /&gt;add comment="ROUTING To LOOPBACK1 RO JAKARTA via ADSL 1" \&lt;br /&gt;    disabled=no distance=1 dst-address=1.2.3.38/32 gateway=1.2.250.1 \&lt;br /&gt;    scope=30 target-scope=10&lt;br /&gt;add comment="ROUTING To LOOPBACK2 RO JAKARTA via ADSL 2" \&lt;br /&gt;    disabled=no distance=1 dst-address=1.2.3.41/32 gateway=1.2.255.1 \&lt;br /&gt;    scope=30 target-scope=10&lt;br /&gt;add comment="DNS ADSL1" disabled=no distance=1 dst-address=202.134.0.155/32 \&lt;br /&gt;    gateway=1.2.250.1,118.96.255.1 scope=30 target-scope=10&lt;br /&gt;add comment="DNS ADSL2" disabled=no distance=1 dst-address=202.134.1.10/32 \&lt;br /&gt;    gateway=1.2.250.1,118.96.255.1 scope=30 target-scope=10&lt;br /&gt;&lt;br /&gt;note:&lt;/span&gt;&lt;/p&gt;  &lt;ol start="1" type="1"&gt;&lt;li class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;LOOPBACK1 and LOOPBACK2 is the      ip address on lobridge1 and lobridge2 interface at Jakarta Router, just to      make sure each eoip interface have their remote-address&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;/interface eoip&lt;br /&gt;add arp=enabled comment="remote address 1.2.3.38 ip loopback rb1000 jkt" \&lt;br /&gt;    disabled=no l2mtu=65535 mac-address=02:83:30:AC:C5:18 mtu=1500 name=\&lt;br /&gt;    EOIP_PDA1_D3_4793 remote-address=1.2.3.38 tunnel-id=4793&lt;br /&gt;add arp=enabled comment="remote address 1.2.3.41 ip loopback rb1000 jkt" \&lt;br /&gt;    disabled=no l2mtu=65535 mac-address=02:83:30:AC:C5:18 mtu=1500 name=\&lt;br /&gt;    EOIP_PDA1_D3_7814 remote-address=1.2.3.41 tunnel-id=7814&lt;br /&gt;&lt;br /&gt;note:&lt;/span&gt;&lt;/p&gt;  &lt;ol start="1" type="1"&gt;&lt;li class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;I using two EOIP interface ,      each EOIP connected using ADSL to Jakarta Router, because my Jakarta      Router directly connected to IIX so from Jakarta Router to RemoteSite      Router connected through IIX to ADSL provider&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;&lt;br /&gt;/interface bonding&lt;br /&gt;add arp=enabled arp-interval=100ms arp-ip-targets=1.2.3.61 disabled=no \&lt;br /&gt;    down-delay=0ms lacp-rate=30secs link-monitoring=arp mii-interval=100ms \&lt;br /&gt;    mode=balance-rr mtu=1500 name=BONDING_PDA1_D3_EOIP primary=none slaves=\&lt;br /&gt;    EOIP_PDA1_D3_4793,EOIP_PDA1_D3_7814 transmit-hash-policy=layer-2 up-delay=\&lt;br /&gt;    0ms&lt;br /&gt;&lt;br /&gt;note:&lt;/span&gt;&lt;/p&gt;  &lt;ol start="1" type="1"&gt;&lt;li class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;arp-ip-targets=1.2.3.61, this      is ip monitoring on Jakarta Router &lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;mode=balance-rr, this is      bonding mode i used, balance-rr its mean the data will tx and rx using      round-robin and give balance and fail-over between slave interface&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;I using NAT to masquerade all traffic out through Bonding interface to make sure the src-address from my remote-site is replace with IP 1.2.3.62&lt;br /&gt;&lt;br /&gt;/ip firewall nat&lt;br /&gt;add action=masquerade chain=srcnat comment="NAT via BONDING" disabled=no \&lt;br /&gt;    out-interface=BONDING_PDA1_D3_EOIP&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And this is configuration for Mikrotik Router locate in Jakarta:&lt;br /&gt;&lt;br /&gt;/interface bridge&lt;br /&gt;add admin-mac=00:00:00:00:00:00 ageing-time=5m arp=enabled auto-mac=yes \&lt;br /&gt;    comment="" disabled=no forward-delay=15s l2mtu=65535 max-message-age=20s \&lt;br /&gt;    mtu=1500 name=lobridge1 priority=0x8000 protocol-mode=none \&lt;br /&gt;    transmit-hold-count=6&lt;br /&gt;add admin-mac=00:00:00:00:00:00 ageing-time=5m arp=enabled auto-mac=yes \&lt;br /&gt;    comment="" disabled=no forward-delay=15s l2mtu=65535 max-message-age=20s \&lt;br /&gt;    mtu=1500 name=lobridge2 priority=0x8000 protocol-mode=none \&lt;br /&gt;    transmit-hold-count=6&lt;br /&gt;&lt;br /&gt;note:&lt;/span&gt;&lt;/p&gt;  &lt;ol start="1" type="1"&gt;&lt;li class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;lobridge interface using for ip      loopback for remote-address eoip from RemoteSite&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;&lt;br /&gt;/interface eoip&lt;br /&gt;add arp=enabled comment="" disabled=no l2mtu=65535 mac-address=\&lt;br /&gt;    02:8B:E1:15:7E:C5 mtu=1500 name=EOIP_4793 remote-address=\&lt;br /&gt;    1.2.251.170 tunnel-id=4793&lt;br /&gt;add arp=enabled comment="" disabled=no l2mtu=65535 mac-address=\&lt;br /&gt;    02:8B:E1:15:7E:C5 mtu=1500 name=EOIP_7814 remote-address=\&lt;br /&gt;    1.2.255.218 tunnel-id=7814&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/interface bonding&lt;br /&gt;add arp=enabled arp-interval=100ms arp-ip-targets=1.2.3.62 comment="" \&lt;br /&gt;    disabled=no down-delay=0s lacp-rate=30secs link-monitoring=arp \&lt;br /&gt;    mii-interval=100ms mode=balance-rr mtu=1500 name=BONDING_PDA1_D3_EOIP \&lt;br /&gt;    primary=none slaves=EOIP_PDA1_D3_4793,EOIP_PDA1_D3_7814 \&lt;br /&gt;    transmit-hash-policy=layer-2 up-delay=0s&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[Me@Jakarta] &gt; /ip address print&lt;br /&gt;Flags: X - disabled, I - invalid, D - dynamic&lt;br /&gt;1   ;;; IIX BGP Peering&lt;br /&gt;     1.2.3.22/30    1.2.3.20    1.2.3.23     ether2_OIXP           &lt;br /&gt;5   ;;; IP Loopback1&lt;br /&gt;     1.2.3.38/32    1.2.3.38    1.2.3.38     lobridge1             &lt;br /&gt;6   ;;; IP Loopback2&lt;br /&gt;     1.2.3.41/32    1.2.3.41    1.2.3.41     lobridge2             &lt;br /&gt;11 ;;; BONDING&lt;br /&gt;     1.2.3.61/30    1.2.3.60    1.2.3.63    BONDING_PDA1_D3_EOIP  &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Note:&lt;/span&gt;&lt;/p&gt;  &lt;ol start="1" type="1"&gt;&lt;li class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;Jakarta Router directly      connected to IIX so routing table from Jakarta to ADSL at RemoteSite      is through IIX and the routing table is using BGP protocol between      Jakarta Router to IIX Router&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;  &lt;p class="MsoNormal"&gt; &lt;/p&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-ZzWL-VN9slo/TWkQJJt8EuI/AAAAAAAAAjE/iWcRgCv1fGw/s1600/bonding-traffic.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 123px;" src="http://4.bp.blogspot.com/-ZzWL-VN9slo/TWkQJJt8EuI/AAAAAAAAAjE/iWcRgCv1fGw/s320/bonding-traffic.png" alt="" id="BLOGGER_PHOTO_ID_5578007362888536802" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-o_L0lO43hSU/TWkPOFgCT8I/AAAAAAAAAi8/ilB88BeZtS8/s1600/bonding-traffic.png"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-YbOGuzICNBM/TWkOVEkeB_I/AAAAAAAAAi0/sWg_NjGS6DU/s1600/mrtg-bonding.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 206px;" src="http://2.bp.blogspot.com/-YbOGuzICNBM/TWkOVEkeB_I/AAAAAAAAAi0/sWg_NjGS6DU/s320/mrtg-bonding.png" alt="" id="BLOGGER_PHOTO_ID_5578005368641816562" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-410591546446112495?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/410591546446112495/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=410591546446112495' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/410591546446112495'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/410591546446112495'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2011/02/bonding-two-adsl.html' title='Bonding Two ADSL'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-ZzWL-VN9slo/TWkQJJt8EuI/AAAAAAAAAjE/iWcRgCv1fGw/s72-c/bonding-traffic.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-5192469829039778906</id><published>2011-02-25T16:33:00.010+07:00</published><updated>2011-03-02T12:20:41.074+07:00</updated><title type='text'>Youtube IP Address and how to manipulate Youtube routing in Mikrotik Router</title><content type='html'>If you have more then one ISP you can manipulate routing for Youtube traffic to ISP with the best download rate for Youtube content&lt;br /&gt;&lt;br /&gt;/ip firewall address-list&lt;br /&gt;add address=74.125.0.0/16 comment=Google disabled=no list=youtube&lt;br /&gt;add address=114.112.182.156 comment=TuDou disabled=no list=youtube&lt;br /&gt;add address=221.12.89.120 comment=TuDou disabled=no list=youtube&lt;br /&gt;add address=64.15.112.0/20 comment=YouTube disabled=no list=youtube&lt;br /&gt;add address=64.15.120.0/21 comment=YouTube disabled=no list=youtube&lt;br /&gt;add address=208.65.152.0/22 comment=YouTube disabled=no list=youtube&lt;br /&gt;add address=208.117.224.0/19 comment=YouTube disabled=no list=youtube&lt;br /&gt;add address=209.85.128.0/17 comment=Google disabled=no list=youtube&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/ip firewall mangle&lt;br /&gt;add action=mark-routing chain=prerouting \&lt;br /&gt;comment="Routing Mark Youtube" disabled=no \&lt;br /&gt;dst-address-list=youtube new-routing-mark=youtube passthrough=no&lt;br /&gt;&lt;br /&gt;correction:&lt;br /&gt;because if you mangle routing-mark all protocol and you have email server inside your network the email from gmail will failed to received so better you just mangle routing-mark for protocol tcp dst-port 80, like this:&lt;br /&gt;&lt;br /&gt;/ip firewall mangle&lt;br /&gt;add action=mark-routing chain=prerouting comment="Routing Mark Youtube" \&lt;br /&gt;    disabled=no dst-address-list=youtube dst-port=80 new-routing-mark=\&lt;br /&gt;    youtube passthrough=no protocol=tcp&lt;br /&gt;&lt;br /&gt;/ip route&lt;br /&gt;add comment="Routing Youtube" disabled=no dst-address=0.0.0.0/0 \&lt;br /&gt;gateway=1.2.3.4 routing-mark=youtube&lt;br /&gt;&lt;br /&gt;/ip firewall nat&lt;br /&gt;add action=masquerade chain=srcnat \&lt;br /&gt;comment="NAT Youtube via ISP Youtube" \&lt;br /&gt;disabled=no out-interface=INTERFACE_TO_ISP_YOUTUBE&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Note:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;gateway=1.2.3.4, you must using your ISP gateway for Youtube traffic depend on your choice whic one of your ISP is best for Youtube traffic&lt;/li&gt;&lt;li&gt;out-interface=INTERFACE_TO_ISP_YOUTUBE, change to your ISP interface at your mikrotik router&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;To avoid problem if your ISP for Youtube down you can copy-paste this script to mikrotik terminal:&lt;br /&gt;&lt;br /&gt;/system script&lt;br /&gt;add name=check_youtube policy=\&lt;br /&gt;  ftp,reboot,read,write,policy,test,winbox,password,sniff,sensitive source="\&lt;br /&gt;  :if ( [/ping 1.2.3.4 count=1]=1) do={\r\&lt;br /&gt;  \n:log info \"Youtube Up\";\r\&lt;br /&gt;  \n:foreach i in=[/ip route find routing-mark=\"youtube\"] do={/ip route se\&lt;br /&gt;  t \$i disable=no};\r\&lt;br /&gt;  \n/tool e-mail send to=\"your@email.net\"  subject=([/system ident\&lt;br /&gt;  ity get name] . \" Youtube Up \" . [/system clock get date]) body=\"Youtub\&lt;br /&gt;  e Routing Mark Enable\";\r\&lt;br /&gt;  \n} else={\r\&lt;br /&gt;  \n:log info \"Youtube Down\";\r\&lt;br /&gt;  \n:foreach i in=[/ip route find routing-mark=\"youtube\"] do={/ip route se\&lt;br /&gt;  t \$i disable=yes};\r\&lt;br /&gt;  \n/tool e-mail send to=\"your@email.net\"  subject=([/system ident\&lt;br /&gt;  ity get name] . \" Youtube Down \" . [/system clock get date]) body=\"Yout\&lt;br /&gt;  ube Routing Mark Disable\";\r\&lt;br /&gt;  \n}"&lt;br /&gt;&lt;br /&gt;and activate this script from Netwatch&lt;br /&gt;&lt;br /&gt;/tool netwatch&lt;br /&gt;add comment="Youtube Check" disabled=no down-script=check_youtube host=\&lt;br /&gt;  1.2.3.4 interval=1m timeout=25ms up-script=check_youtube&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Source:&lt;br /&gt;&lt;a href="http://www.robtex.com/as/as36561.html#bgp"&gt;http://www.robtex.com/as/as36561.html#bgp&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-5192469829039778906?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/5192469829039778906/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=5192469829039778906' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5192469829039778906'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5192469829039778906'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2011/02/youtube-ip-address-and-how-to.html' title='Youtube IP Address and how to manipulate Youtube routing in Mikrotik Router'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-9073413547681237440</id><published>2011-02-24T15:21:00.006+07:00</published><updated>2011-02-24T15:38:29.468+07:00</updated><title type='text'>Jika Paket Data Tidak mau jalan lewat tunnel</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-de3VuvYFZ1w/TWYX1IgBVTI/AAAAAAAAAis/joudGPPaQFQ/s1600/esham-forward-mangle-in-eoip-action.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://2.bp.blogspot.com/-de3VuvYFZ1w/TWYX1IgBVTI/AAAAAAAAAis/joudGPPaQFQ/s320/esham-forward-mangle-in-eoip-action.png" alt="" id="BLOGGER_PHOTO_ID_5577171390127232306" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-GoApYXOgArs/TWYXuU-1dFI/AAAAAAAAAik/yYwAz7_Eg5c/s1600/esham-forward-mangle-in-eoip-advance.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://3.bp.blogspot.com/-GoApYXOgArs/TWYXuU-1dFI/AAAAAAAAAik/yYwAz7_Eg5c/s320/esham-forward-mangle-in-eoip-advance.png" alt="" id="BLOGGER_PHOTO_ID_5577171273218618450" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-RdqjNxtVbzE/TWYXuFW3GwI/AAAAAAAAAic/lQ3HGZtYCyQ/s1600/esham-forward-mangle-in-eoip-general.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://4.bp.blogspot.com/-RdqjNxtVbzE/TWYXuFW3GwI/AAAAAAAAAic/lQ3HGZtYCyQ/s320/esham-forward-mangle-in-eoip-general.png" alt="" id="BLOGGER_PHOTO_ID_5577171269024422658" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-I58ymRYOi-M/TWYXt8ibFCI/AAAAAAAAAiU/U_mUcRl08Kc/s1600/esham-forward-mangle-out-eoip-action.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://3.bp.blogspot.com/-I58ymRYOi-M/TWYXt8ibFCI/AAAAAAAAAiU/U_mUcRl08Kc/s320/esham-forward-mangle-out-eoip-action.png" alt="" id="BLOGGER_PHOTO_ID_5577171266656998434" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-doV9Hjac1T8/TWYXtc8he5I/AAAAAAAAAiM/rVT-Vd8YPGE/s1600/esham-forward-mangle-out-eoip-advance.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://3.bp.blogspot.com/-doV9Hjac1T8/TWYXtc8he5I/AAAAAAAAAiM/rVT-Vd8YPGE/s320/esham-forward-mangle-out-eoip-advance.png" alt="" id="BLOGGER_PHOTO_ID_5577171258176535442" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-EbzTpSzXpVo/TWYXtSjMp8I/AAAAAAAAAiE/bnnvgCE1Jes/s1600/esham-forward-mangle-out-eoip-general.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://2.bp.blogspot.com/-EbzTpSzXpVo/TWYXtSjMp8I/AAAAAAAAAiE/bnnvgCE1Jes/s320/esham-forward-mangle-out-eoip-general.png" alt="" id="BLOGGER_PHOTO_ID_5577171255385958338" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Kadang kala pengiriman data via tunnel mengalami kendala khususnya paket-paket TCP, jika anda menghadapi masalah tersebut jangan pusing solusinya adalah buat mangle di chain forward utk tcp syn action change mss clamp to pmtu, tujuannya agar tunnel tersebut bisa mengatur parameter MTU (Maximum Transfer Unit) yang mungkin berbeda diantara end-point tersebut&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-9073413547681237440?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/9073413547681237440/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=9073413547681237440' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/9073413547681237440'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/9073413547681237440'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2011/02/jika-paket-data-tidak-mau-jalan-lewat.html' title='Jika Paket Data Tidak mau jalan lewat tunnel'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-de3VuvYFZ1w/TWYX1IgBVTI/AAAAAAAAAis/joudGPPaQFQ/s72-c/esham-forward-mangle-in-eoip-action.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-8037385439605964725</id><published>2010-11-06T17:57:00.010+07:00</published><updated>2010-11-06T18:56:42.440+07:00</updated><title type='text'>Cek IP Akamai yang ada di daftar NICE</title><content type='html'>Semakin hari semakin banyak ISP Indonesia yang dipercaya Akamai untuk meng-cache konten-konten akamai , permasalahan timbul karena ISP seperti Idola/Lintas Arta, Telkom, Indosat dll mengadvertise blok IP Akamai Server mereka ke OpenIXP/IIX sehingga daftar nice.rsc juga akan menyertakan blok IP Akamai sebagai prefix lokal Indonesia padahal traffic Akamai yang di host di ISP Indonesia tsb tidak selalu dapat di download dari OpenIXP/IIX biasanya hanya outgoing routingnya saja via OpenIXP/IIX tetapi incoming routingnya tetap melalui pipa International kecuali para pelanggan Speedy atau Firstmedia "mungkin" mereka dapat mendownload konten Akamai secara khusus dari jaringan Speedy / Firstmedia .&lt;br /&gt;&lt;br /&gt;berikut bukti akamai Idola/LintasArta di download melalui interface international sedangkan outgoingnya melalui interface lokal dan prefix 202.152.0.0/19 terdaftar di address-list = nice&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_nzWcXcVYSRs/TNVB52POwUI/AAAAAAAAAg0/lWHV079e2-o/s1600/akamai-idola.PNG"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 228px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/TNVB52POwUI/AAAAAAAAAg0/lWHV079e2-o/s320/akamai-idola.PNG" alt="" id="BLOGGER_PHOTO_ID_5536403778989637954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Permasalahan ini sudah pernah saya tulis juga dalam artikel blog saya terdahulu: &lt;a href="http://inetshoot.blogspot.com/2008/11/pemisahan-traffic-ke-ip-akamai-indosat.html"&gt;http://inetshoot.blogspot.com/2008/11/pemisahan-traffic-ke-ip-akamai-indosat.html&lt;/a&gt; , dimana kerancuan prefix Akamai di nice.rsc akan mengakibatkan limitasi bandwidth lokal dan international bisa tidak sesuai pada para pengguna mikrotik yang memanfaatkan nice.rsc&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;sehingga akan terjadi traffic international akan dianggap iix sehingga bandwidth International akan selalu mentok terpakai karena biasanya limitasi untuk iix akan lebih longgar / lebih besar bandwidthnya padahal umumnya bandwidth International yang di dapat lebih kecil dari pada bandwidth lokal Indonesia.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Untuk itu saya coba menangkap IP Akamai Server yang di advertise oleh ISP Indonesia di OpenIXP/IIX agar para pengguna nice.rsc bisa lebih lanjut mengkondisikan agar traffic Akamai tidak tercampur dengan mangle / queue traffic IIX, atau bisa jadi dikembangkan untuk memanipulasi agar traffic Akamai tsb di redirect ke proxy yang terhubung langsung dengan speedy atau firstmedia hehehe peace....&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Langka1:&lt;/div&gt;&lt;div&gt;Buat /ip firewall layer7-protocol&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://4.bp.blogspot.com/_nzWcXcVYSRs/TNU8DE6gPII/AAAAAAAAAgM/PsvVDoaOA7I/s1600/layer7-akamai.PNG"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 206px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/TNU8DE6gPII/AAAAAAAAAgM/PsvVDoaOA7I/s320/layer7-akamai.PNG" alt="" id="BLOGGER_PHOTO_ID_5536397340478291074" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Langka2:&lt;/div&gt;&lt;div&gt;Buat /ip firewall filter forward&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_nzWcXcVYSRs/TNU8DZybvwI/AAAAAAAAAgU/8XDgQ5uQRoo/s1600/filter-akamai1.PNG"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 217px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/TNU8DZybvwI/AAAAAAAAAgU/8XDgQ5uQRoo/s320/filter-akamai1.PNG" alt="" id="BLOGGER_PHOTO_ID_5536397346081586946" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://2.bp.blogspot.com/_nzWcXcVYSRs/TNU8DWTFa7I/AAAAAAAAAgc/qUMkMhCc9qE/s1600/filter-akamai2.PNG"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 220px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/TNU8DWTFa7I/AAAAAAAAAgc/qUMkMhCc9qE/s320/filter-akamai2.PNG" alt="" id="BLOGGER_PHOTO_ID_5536397345144794034" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://1.bp.blogspot.com/_nzWcXcVYSRs/TNU8D0eOnNI/AAAAAAAAAgk/5WGBaiWECVA/s1600/filter-akamai3.PNG"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 222px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/TNU8D0eOnNI/AAAAAAAAAgk/5WGBaiWECVA/s320/filter-akamai3.PNG" alt="" id="BLOGGER_PHOTO_ID_5536397353244597458" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Hasilnya akan terdapat pada address-list = "akamai-indonesia"&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://1.bp.blogspot.com/_nzWcXcVYSRs/TNU8D_0iowI/AAAAAAAAAgs/7oAfutP0PFs/s1600/akamai-address-list.PNG"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 130px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/TNU8D_0iowI/AAAAAAAAAgs/7oAfutP0PFs/s320/akamai-address-list.PNG" alt="" id="BLOGGER_PHOTO_ID_5536397356290974466" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-8037385439605964725?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/8037385439605964725/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=8037385439605964725' title='6 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/8037385439605964725'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/8037385439605964725'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2010/11/cek-ip-akamai-yang-ada-di-daftar-nice.html' title='Cek IP Akamai yang ada di daftar NICE'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_nzWcXcVYSRs/TNVB52POwUI/AAAAAAAAAg0/lWHV079e2-o/s72-c/akamai-idola.PNG' height='72' width='72'/><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-667757836024795972</id><published>2010-10-31T17:52:00.004+07:00</published><updated>2010-10-31T18:00:13.413+07:00</updated><title type='text'>Petunjuk singkat menjadikan gmail sebagai smtp outlook</title><content type='html'>Seringkali anda harus bepergian ke berbagai tempat dan pada waktu akan mengirim email menggunakan email client seperti outlook kesulitan mengakses smtp, karena sebagian besar smtp dibatasi aksesnya hanya untuk jaringan internal perusahaan atau intranet atau hanya dapat diakses melalui jaringan ISP yang digunakan di kantor&lt;br /&gt;&lt;p class="MsoNormal"&gt;Salah satu solusi praktis bagi anda yang sering bepergian adalah menjadikan smtp.gmail.com untuk outoging smtp di outlook agar tidak perlu melakukan perubahan konfigurasi smtp jika notebook dibawa ke tempat manapun selama ada akses Internet dan smtp.gmail.com port 587 di izinkan oleh firewall hotspot atau router dimana anda terkoneksi dengan Internet.&lt;br /&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Petunjuk dari google dapat di lihat pada url berikut untuk outlook 2003&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="http://mail.google.com/support/bin/answer.py?answer=75291"&gt;http://mail.google.com/support/bin/answer.py?answer=75291&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;smtp.gmail.com bisa digunakan untuk outgoing mail server (smtp) semua mailbox yang kita miliki dengan klik “More Settings” pada account yang akan kita set , lalu pada tab “Outgoing Server” ceklist “My outgoing server (SMTP) requires authenctication” dan pilih “Log on using” masukkan username gmail yang anda daftarkan di gmail dan masukkan password gmail anda , agar tidak selalu meminta passwrod ceklist “Remember password”&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Gambar dibawah adalah tampilan outlook 2007 tetapi harusnya tidak jauh berbeda dengan outlook 2003&lt;br /&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="http://1.bp.blogspot.com/_nzWcXcVYSRs/TM1Lv40O1VI/AAAAAAAAAfU/rFXi5OoPvo0/s1600/outlook1.PNG"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 130px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/TM1Lv40O1VI/AAAAAAAAAfU/rFXi5OoPvo0/s320/outlook1.PNG" alt="" id="BLOGGER_PHOTO_ID_5534162803185603922" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Pada tab “Advanced” set “Outgoing server (SMTP) dengan port: 587” dan pilih “Use the following type of encrypted connection = TLS” lalu Klik “OK”&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="http://4.bp.blogspot.com/_nzWcXcVYSRs/TM1LwJLQ7GI/AAAAAAAAAfc/R8269mM5j4k/s1600/outlook2.PNG"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 130px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/TM1LwJLQ7GI/AAAAAAAAAfc/R8269mM5j4k/s320/outlook2.PNG" alt="" id="BLOGGER_PHOTO_ID_5534162807577177186" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Dengan demikian maka notebook anda bisa mengirim email menggunakan SMTP : smtp.gmail.com dimanapun bisa mengakses Internet.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-667757836024795972?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/667757836024795972/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=667757836024795972' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/667757836024795972'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/667757836024795972'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2010/10/petunjuk-singkat-menjadikan-gmail.html' title='Petunjuk singkat menjadikan gmail sebagai smtp outlook'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_nzWcXcVYSRs/TM1Lv40O1VI/AAAAAAAAAfU/rFXi5OoPvo0/s72-c/outlook1.PNG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-2192586764786622198</id><published>2010-10-07T18:26:00.008+07:00</published><updated>2010-10-07T19:20:25.136+07:00</updated><title type='text'>Langkah langkah upgrade firmware Switch Procurve 2650</title><content type='html'>Berikut adalah langkah-langkah untuk uprgrade firmware switch HP Procurve 2650&lt;br /&gt;&lt;br /&gt;Untuk melakukan upgrade firmware siapkan:&lt;br /&gt;&lt;br /&gt;1. Kabel konsol&lt;br /&gt;2. USB to Serial untuk notebook baru sudah tidak menyediakan port serial&lt;br /&gt;3. Kabel UTP untuk proses upload / download OS dari ke switch&lt;br /&gt;4. TFTP Server bisa di download dari solarwind:&lt;a href="http://www.solarwinds.com/register/registration.aspx?program=52&amp;amp;c=70150000000CcH2&amp;amp;INTCMP=ILC-TFTP_Top_DL"&gt; http://www.solarwinds.com/register/registration.aspx?program=52&amp;amp;c=70150000000CcH2&amp;amp;INTCMP=ILC-TFTP_Top_DL&lt;br /&gt;&lt;/a&gt;5. Download putty.exe untuk telnet, ssh dan serial koneksi : &lt;a href="http://www.putty.org/"&gt;http://www.putty.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Langkah1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Download firmware switch dari:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://h10144.www1.hp.com/customercare/support/software/summarypages/h-j4900-c.htm"&gt;http://h10144.www1.hp.com/customercare/support/software/summarypages/h-j4900-c.htm&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;simpan di direktori misal :&lt;br /&gt;&lt;br /&gt;C:\Users\Harijanto\Downloads\2600-Software-H1083\&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Langkah2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Jika switch belum di konfigure IP nya pasang kabel konsol + usb to serial , lalu gunakan aplikasi hyperterminal atau putty.exe , jangan lupa nyalakan switchnya juga.&lt;br /&gt;&lt;br /&gt;Untuk mengetahui di COM berapa kabel serial tersebut terpasang caranya cek di device-manager , cara paling praktis klik kanan di my computer lalu pilih manage&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_nzWcXcVYSRs/TK2vm4olgjI/AAAAAAAAAdU/XVlbZLIJUYc/s1600/howto-uprade-procurve-firmware-1.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/TK2vm4olgjI/AAAAAAAAAdU/XVlbZLIJUYc/s320/howto-uprade-procurve-firmware-1.png" alt="" id="BLOGGER_PHOTO_ID_5525265400425972274" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;di contoh ini usb to serial di com13&lt;br /&gt;&lt;br /&gt;setelah mengetahui di com berapa jalankan program putty.exe&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_nzWcXcVYSRs/TK2vnSh2FbI/AAAAAAAAAdc/qpBDHp3u8mA/s1600/howto-uprade-procurve-firmware-2.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/TK2vnSh2FbI/AAAAAAAAAdc/qpBDHp3u8mA/s320/howto-uprade-procurve-firmware-2.png" alt="" id="BLOGGER_PHOTO_ID_5525265407377020338" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;pilih serial dan ketik com13 lalu klik Open&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_nzWcXcVYSRs/TK2vnv0DJcI/AAAAAAAAAdk/hrX-xJ-arV8/s1600/howto-uprade-procurve-firmware-3.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/TK2vnv0DJcI/AAAAAAAAAdk/hrX-xJ-arV8/s320/howto-uprade-procurve-firmware-3.png" alt="" id="BLOGGER_PHOTO_ID_5525265415238002114" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;enter -&gt; enter maka putty akan mendetek kecepatan baud-ratenya kalau sudah bisa komunikasi makan akan muncul CLI dari switch procurve tersebut&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_nzWcXcVYSRs/TK2vn_qQzyI/AAAAAAAAAds/aI8C_G-k8ew/s1600/howto-uprade-procurve-firmware-4.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/TK2vn_qQzyI/AAAAAAAAAds/aI8C_G-k8ew/s320/howto-uprade-procurve-firmware-4.png" alt="" id="BLOGGER_PHOTO_ID_5525265419491921698" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;ketik : sh run&lt;br /&gt;maka akan muncul konfigurasi switch tersebut, di contoh ini switch belum di beri IP statik , untuk itu setup ip statik di vlan1 caranya ketik:&lt;br /&gt;&lt;br /&gt;config t&lt;br /&gt;vlan1&lt;br /&gt;ip address 192.168.0.1 255.255.255.0&lt;br /&gt;&lt;br /&gt;untuk menyimpan konfigurasi ketik:&lt;br /&gt;&lt;br /&gt;write mem&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_nzWcXcVYSRs/TK2voMAZzJI/AAAAAAAAAd0/pU6PxMA9kpE/s1600/howto-uprade-procurve-firmware-5.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/TK2voMAZzJI/AAAAAAAAAd0/pU6PxMA9kpE/s320/howto-uprade-procurve-firmware-5.png" alt="" id="BLOGGER_PHOTO_ID_5525265422806011026" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Langkah 3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;kemudian set ip 192.168.0.2 mask 255.255.255.0 di interface ethernet pada notebook seperti berikut ini:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_nzWcXcVYSRs/TK2wG0ew7zI/AAAAAAAAAd8/QJPm4jqvgEQ/s1600/howto-uprade-procurve-firmware-6.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/TK2wG0ew7zI/AAAAAAAAAd8/QJPm4jqvgEQ/s320/howto-uprade-procurve-firmware-6.png" alt="" id="BLOGGER_PHOTO_ID_5525265949066850098" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;setelah notebook diset ip 192.168.0.2 netmask 255.255.255.0 maka harusnya dari notebook sudah bisa ping ke 192.168.0.1&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_nzWcXcVYSRs/TK2wHJWVRoI/AAAAAAAAAeE/XVT8G8Y0elg/s1600/howto-uprade-procurve-firmware-7.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/TK2wHJWVRoI/AAAAAAAAAeE/XVT8G8Y0elg/s320/howto-uprade-procurve-firmware-7.png" alt="" id="BLOGGER_PHOTO_ID_5525265954668627586" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Langkah 4&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;lalu aktfikan tftp solarwind , arahkan direktori ke path dimana file firmware / os switch berada dengan cara klik file-&gt;configure-&gt;storage klik browse arahkan ke direktori dimana file firmware / os berada kalau sudah klik OK&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_nzWcXcVYSRs/TK2wHX-YOFI/AAAAAAAAAeM/4Ri4fIUu8DE/s1600/howto-uprade-procurve-firmware-8.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/TK2wHX-YOFI/AAAAAAAAAeM/4Ri4fIUu8DE/s320/howto-uprade-procurve-firmware-8.png" alt="" id="BLOGGER_PHOTO_ID_5525265958594689106" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;jangan lupa klik "Start" agar tftp server dijalankan&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_nzWcXcVYSRs/TK2wHmH8YtI/AAAAAAAAAeU/qVumRIiTKnw/s1600/howto-uprade-procurve-firmware-9.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/TK2wHmH8YtI/AAAAAAAAAeU/qVumRIiTKnw/s320/howto-uprade-procurve-firmware-9.png" alt="" id="BLOGGER_PHOTO_ID_5525265962392904402" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Langkah 5&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;di konsole putty ketik: menu maka akan muncul menu dan pilih "Download OS"&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_nzWcXcVYSRs/TK2wH78zNWI/AAAAAAAAAec/OINZ50a3UAM/s1600/howto-uprade-procurve-firmware-10.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/TK2wH78zNWI/AAAAAAAAAec/OINZ50a3UAM/s320/howto-uprade-procurve-firmware-10.png" alt="" id="BLOGGER_PHOTO_ID_5525265968251745634" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;masukkan ip tftp server dalam contoh ini: 192.168.0.2 dan nama file dalam contoh ini: H_10_83.swi , kemudian pilih execute&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_nzWcXcVYSRs/TK2wbWHiTyI/AAAAAAAAAek/BK-7C9pNkR4/s1600/howto-uprade-procurve-firmware-11.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/TK2wbWHiTyI/AAAAAAAAAek/BK-7C9pNkR4/s320/howto-uprade-procurve-firmware-11.png" alt="" id="BLOGGER_PHOTO_ID_5525266301693611810" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;jika semua benar maka proses download os akan dilaksanakan&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_nzWcXcVYSRs/TK2wb2edVcI/AAAAAAAAAes/wbKanO_OUsk/s1600/howto-uprade-procurve-firmware-12.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/TK2wb2edVcI/AAAAAAAAAes/wbKanO_OUsk/s320/howto-uprade-procurve-firmware-12.png" alt="" id="BLOGGER_PHOTO_ID_5525266310379689410" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Jika sudah selesai maka akan ada pesan sbb:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_nzWcXcVYSRs/TK2wcfCT8eI/AAAAAAAAAe8/Gi5VHEcYmLw/s1600/howto-uprade-procurve-firmware-14.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/TK2wcfCT8eI/AAAAAAAAAe8/Gi5VHEcYmLw/s320/howto-uprade-procurve-firmware-14.png" alt="" id="BLOGGER_PHOTO_ID_5525266321267487202" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;selanjutnya switch harus di reboot, jika tidak boot otomatis ketik: boot, maka switch akan melakukan proses reboot&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_nzWcXcVYSRs/TK2wc0KyO3I/AAAAAAAAAfE/V0TzT0mTAPA/s1600/howto-uprade-procurve-firmware-15.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/TK2wc0KyO3I/AAAAAAAAAfE/V0TzT0mTAPA/s320/howto-uprade-procurve-firmware-15.png" alt="" id="BLOGGER_PHOTO_ID_5525266326940171122" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;dan jika sudah berhasil maka kalau di : sh run , maka tampilannya aka sbb:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_nzWcXcVYSRs/TK2wyq99YAI/AAAAAAAAAfM/5eC8xKeXeio/s1600/howto-uprade-procurve-firmware-16.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/TK2wyq99YAI/AAAAAAAAAfM/5eC8xKeXeio/s320/howto-uprade-procurve-firmware-16.png" alt="" id="BLOGGER_PHOTO_ID_5525266702427578370" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;di sini bisa dilihat bahwa firmware/os switch sudah menggunakan versi baru yang tadi di download&lt;br /&gt;&lt;br /&gt;Selamat mencoba&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-2192586764786622198?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/2192586764786622198/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=2192586764786622198' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2192586764786622198'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2192586764786622198'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2010/10/langkah-langkah-upgrade-firmware-switch.html' title='Langkah langkah upgrade firmware Switch Procurve 2650'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_nzWcXcVYSRs/TK2vm4olgjI/AAAAAAAAAdU/XVlbZLIJUYc/s72-c/howto-uprade-procurve-firmware-1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-6089283265659303924</id><published>2010-09-10T12:37:00.002+07:00</published><updated>2010-09-10T12:55:41.691+07:00</updated><title type='text'>Perbedaan Pseudo Bridge dengan WDS</title><content type='html'>Setelah mencari-cari penjelasan pseudobridge vs WDS akhirnya kutemukan artikel ini:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://forum.mikrotik.com/viewtopic.php?f=13&amp;amp;t=41165"&gt;http://forum.mikrotik.com/viewtopic.php?f=13&amp;amp;t=41165&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;psudo only allows one active mac address to be behind the client.&lt;br /&gt;&lt;br /&gt;so  if you have a CPE with a customers router or single PC behind it, it  works great. If the customer plugs in a switch and tries to hook up two  computers that try to get online, it won't work as expected for them,  and only one device at a time can receive packets.&lt;br /&gt;&lt;br /&gt;Additionally  it has less overhead than WDS, and reconnects to the AP faster in the  event of a disconnect (WDS has to connect once regular, probe the AP to  determine if WDS is supported, then reconnect as a WDS connection), Plus  the option of turning off default forwarding on the AP works (To  accomplish the same when using WDS you have to get creative and use a  bunch of bridge rules).&lt;br /&gt;&lt;br /&gt;For a backhaul, you should really avoid  using WDS (or psudobridge), you should be using regular station and  bridge mode, with no other devices connected, and then routing the data  across a /30 subnet, preferably using OSPF (and a redundant path  available), but static routing can be used if necessary.&lt;br /&gt;&lt;br /&gt;Thanks Brian:&lt;br /&gt;&lt;span class="postbody"&gt;-Brian&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.thehostingnews.com/" class="postlink"&gt;http://www.thehostingnews.com&lt;/a&gt;&lt;br /&gt;gawkwire.com&lt;br /&gt;sailingit.com&lt;br /&gt;&lt;br /&gt;Penjelasannya kurang lebih sbb:&lt;br /&gt;&lt;br /&gt;Kalau pake pseudo bridge hanya satu mac-address yang bisa aktif dibelakang access-point-client (APC) , alias di sisi router distribusi yang arp-tablenya hanya bisa kenal satu mac-address router sisi clientnya (semoga ngerti yang saya maksud)&lt;br /&gt;&lt;br /&gt;jadi kalau Client Permissive Equipment (CPE) hanya dihubungkan ke satu router client menggunakan pseudobridge akan sangat bagus, tapi kalau CPE dihubungkan ke switch lalu ada lebih dari satu komputer maka hanya salah satu komputer saja yang arp nya masuk di arp-table router ISP , jadi kalau clientnya gak punya router dari CPE langsung ke switch lalu masuk beberapa komputer sisi APC harus dijadiin station-wds&lt;br /&gt;&lt;br /&gt;Tapi dijelaskan oleh Brian, bahwa pseudobridge overheadnya lebih kecil dari WDS, alias lebih efisien dibanding WDS , dan pseodobridge kalau disconnect , connect lagi ke AP nya lebih cepat dibanding WDS.&lt;br /&gt;&lt;br /&gt;Untuk backhaul kata Brian, sebaiknya menghindari pakai WDS tapi pakai mode station dan bridge biasa lalu lakukan routing per /30 subnet bisa pakai ospf atau static routing.&lt;br /&gt;&lt;br /&gt;Semoga penjelasan ini bermanfaat&lt;br /&gt;&lt;br /&gt;Salam&lt;br /&gt;Harijanto P.&lt;br /&gt;http://htsolusi.net&lt;br /&gt;http://pt-pda.net&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-6089283265659303924?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/6089283265659303924/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=6089283265659303924' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6089283265659303924'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6089283265659303924'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2010/09/perbedaan-pseudo-bridge-dengan-wds.html' title='Perbedaan Pseudo Bridge dengan WDS'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-263052377509948104</id><published>2010-09-08T09:12:00.004+07:00</published><updated>2010-09-08T09:28:08.798+07:00</updated><title type='text'>Bridging Pada Ubiquiti Rocket</title><content type='html'>Baru-baru ini saya mencoba produk ubiquiti rocket yang digunakan sebagai bridging antar BTS, maklum masih newbie dengan produk ini jadi belum paham benar karakternya.&lt;br /&gt;&lt;br /&gt;Kasus yang saya hadapi:&lt;br /&gt;&lt;br /&gt;Untuk menghubungkan satu router mikrotik ke router mikrotik lainnya melalui ubiquiti rocket saya harus membuat eoip-tunnel agar ospf antar router berfungsi dengan baik, entah mengapa harus menggunakan eoip-tunnel kalau menggunakan dynamic routing ospf karena kalau ping ptp dan static routing bisa berfungsi&lt;br /&gt;&lt;br /&gt;kalau dari hasil baca-baca wiki ubiquiti sbb:&lt;br /&gt;&lt;a href="http://www.ubnt.com/wiki/How_to_bridge_internet_connections"&gt;http://www.ubnt.com/wiki/How_to_bridge_internet_connections&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Sepertinya antar ubiquiti rocket harus menggunakan access-point wds dengan station wds kalau ingin menjalankan transparent bridge, kalau dari hasil pengamatan antara ubiquiti rocket yang menggunakan wds dan tidak di tabel arp yang ada di router mikrotik jelas kalau ubiquiti rocket yang menggunakan wds arp tablenya antara ap-wds, station-wds dan router mikrotik mac-addressnya masing-masing terpisah sedangkan kalau ubiquiti rocket yang non wds arp tablenya antara ap, station dan router mikrotik mac-address station dan router sama-sama menggunakan mac-address ubiquiti jadi seperti mac clonning pada radio senao , arp tablenya bisa dilihat pada gambar berikut:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/TIbz5BgYJNI/AAAAAAAAAcc/m5VsirAhgJc/s1600/mac-ubnt-station-station-wds.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 80px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/TIbz5BgYJNI/AAAAAAAAAcc/m5VsirAhgJc/s320/mac-ubnt-station-station-wds.png" alt="" id="BLOGGER_PHOTO_ID_5514362954744079570" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;berikut adalah screen capture ubiquiti rocket dengan ap-wds:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/TIbz5zlkodI/AAAAAAAAAck/fJAIWmwIlxM/s1600/ubng-ap-wds.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 152px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/TIbz5zlkodI/AAAAAAAAAck/fJAIWmwIlxM/s320/ubng-ap-wds.png" alt="" id="BLOGGER_PHOTO_ID_5514362968187642322" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;berikut adalah screen capture ubiquiti rocket dengan station-wds:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/TIbz6aXnhnI/AAAAAAAAAcs/5Id4E6TGfp8/s1600/ubng-station-wds.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 153px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/TIbz6aXnhnI/AAAAAAAAAcs/5Id4E6TGfp8/s320/ubng-station-wds.png" alt="" id="BLOGGER_PHOTO_ID_5514362978598094450" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;berikut adalah screen capture ubiquiti dengan ap non wds:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/TIbz7AUy3KI/AAAAAAAAAc0/KUq0WmJwhKg/s1600/ubnt-ap.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 153px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/TIbz7AUy3KI/AAAAAAAAAc0/KUq0WmJwhKg/s320/ubnt-ap.png" alt="" id="BLOGGER_PHOTO_ID_5514362988786801826" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;berikut adalah screen capture ubiquiti dengan station non wds:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/TIbz776kmkI/AAAAAAAAAc8/6T3ENYdNLxo/s1600/ubnt-station.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 153px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/TIbz776kmkI/AAAAAAAAAc8/6T3ENYdNLxo/s320/ubnt-station.png" alt="" id="BLOGGER_PHOTO_ID_5514363004782942786" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-263052377509948104?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/263052377509948104/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=263052377509948104' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/263052377509948104'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/263052377509948104'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2010/09/bridging-pada-ubiquiti-rocket.html' title='Bridging Pada Ubiquiti Rocket'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_nzWcXcVYSRs/TIbz5BgYJNI/AAAAAAAAAcc/m5VsirAhgJc/s72-c/mac-ubnt-station-station-wds.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-5701880374406232045</id><published>2010-08-20T00:44:00.004+07:00</published><updated>2010-08-20T01:03:49.442+07:00</updated><title type='text'>RSTP Bridge failover layer2 menggunakan Mikrotik</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/TG1wBFEAN5I/AAAAAAAAAcU/uimCiaDYvCg/s1600/IMG00215-20100820-0025.jpg"&gt;&lt;br /&gt;&lt;/a&gt;Hari ini saya kedatangan kawan lama , seperti biasa dia minta bantuan ngoprek Mikrotik&lt;br /&gt;masalahnhya dia ingin memasang server penyaring spam virus dll dalam mode bridge tetapi kalau suatu saat server penyaring tsb bermasalah maka traffic harus di bypass melalui port lainnya&lt;br /&gt;&lt;br /&gt;kurang lebih topologinya spt ini:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/TG1unaZxnwI/AAAAAAAAAbk/X7CEcelDGL8/s1600/topologi.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 109px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/TG1unaZxnwI/AAAAAAAAAbk/X7CEcelDGL8/s320/topologi.jpg" alt="" id="BLOGGER_PHOTO_ID_5507179542725369602" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Jadi semisal link ether2 putus maka data akan mengalir melalui ether1 , sedangkan jika link ether1 putus data akan mengalir melalui ether2, jika kedua link tidak putus maka data akan mengalir melalui ether1 menggunakan mekanisme RSTP: &lt;a href="http://wiki.mikrotik.com/wiki/Manual:Interface/Bridge"&gt;http://wiki.mikrotik.com/wiki/Manual:Interface/Bridge&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;dalam percobaan ini saya menggunakan RB750G yang terdiri dari RSTP-A dan RSTP-B, dimana RSTP-A pada ether3 terhubung langsung dengan router / koneksi Internet sedangkan RSTP-B terhubung dengan notebook&lt;br /&gt;&lt;br /&gt;Berikut adalah foto RSTP-A&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/TG1wAhzKnVI/AAAAAAAAAcM/UCdc0Vz8AWk/s1600/IMG00214-20100820-0024.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 240px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/TG1wAhzKnVI/AAAAAAAAAcM/UCdc0Vz8AWk/s320/IMG00214-20100820-0024.jpg" alt="" id="BLOGGER_PHOTO_ID_5507181073719270738" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Berikut adalah foto RSTP-B&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/TG1wBFEAN5I/AAAAAAAAAcU/uimCiaDYvCg/s1600/IMG00215-20100820-0025.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 240px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/TG1wBFEAN5I/AAAAAAAAAcU/uimCiaDYvCg/s320/IMG00215-20100820-0025.jpg" alt="" id="BLOGGER_PHOTO_ID_5507181083185133458" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Pada RSTP-A Konfigurasi bisa dilihat sbb:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/TG1unuRLpBI/AAAAAAAAAbs/r2e0dNE4zCI/s1600/RSTP-A.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/TG1unuRLpBI/AAAAAAAAAbs/r2e0dNE4zCI/s320/RSTP-A.png" alt="" id="BLOGGER_PHOTO_ID_5507179548058035218" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Pada RSTP-B konfigurasi bisa dilihat sbb:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/TG1un5npR_I/AAAAAAAAAb0/vn2sRmqozZ4/s1600/RSTP-B.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/TG1un5npR_I/AAAAAAAAAb0/vn2sRmqozZ4/s320/RSTP-B.png" alt="" id="BLOGGER_PHOTO_ID_5507179551105042418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Yang membedakannya hanya pada :&lt;br /&gt;&lt;br /&gt;[admin@RSTP-B] /interface bridge port&gt; /interface bridge port set path-cost=20 interface=ether2&lt;br /&gt;&lt;br /&gt;jadi di RSTP-A dan RSTP-B untuk interface=ether2 path-cost dibuat 20 sedangkan ether1 path-cost = 10&lt;br /&gt;&lt;br /&gt;sehingga pada keadaan normal data akan dialirkan melalui ether1 ke ether3 melalui bridge&lt;br /&gt;&lt;br /&gt;untuk uji coba saya lakukan ping ke dns google 8.8.8.8 dari notebook lalu salah satu kabel misal ether1 saya cabut maka data akan mengalir lewat ether2&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/TG1uolJhRrI/AAAAAAAAAcE/PSNk5nrZyIg/s1600/RSTP-B-ETHER2-PLUG.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/TG1uolJhRrI/AAAAAAAAAcE/PSNk5nrZyIg/s320/RSTP-B-ETHER2-PLUG.png" alt="" id="BLOGGER_PHOTO_ID_5507179562789848754" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;dan ketika kabel ether1 di pasang lagi maka data akan kembali melalui ether1&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/TG1uofK5k_I/AAAAAAAAAb8/n2ahkEmER38/s1600/RSTP-B-ETHER2-UNPLUG.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/TG1uofK5k_I/AAAAAAAAAb8/n2ahkEmER38/s320/RSTP-B-ETHER2-UNPLUG.png" alt="" id="BLOGGER_PHOTO_ID_5507179561185022962" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;atau sebaliknya&lt;br /&gt;&lt;br /&gt;jadi kesimpulannya dua RB750G tersebut bisa menjadi bridge RSTP yang menjadi solusi fail-over layer2 yang ekonomis dan praktis&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-5701880374406232045?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/5701880374406232045/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=5701880374406232045' title='2 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5701880374406232045'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5701880374406232045'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2010/08/rstp-bridge-failover-layer2-menggunakan.html' title='RSTP Bridge failover layer2 menggunakan Mikrotik'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_nzWcXcVYSRs/TG1unaZxnwI/AAAAAAAAAbk/X7CEcelDGL8/s72-c/topologi.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-7081675863877949432</id><published>2010-06-21T23:26:00.008+07:00</published><updated>2010-06-21T23:52:08.202+07:00</updated><title type='text'>Analisa Paket Data Game Point Blank pada waktu melakukan Patch dibantu cache dari Squid Proxy</title><content type='html'>Wah sudah lama gak nulis di blog , kebetulan malam ini iseng pengen tahu karakter game Point Blank http://pb.gemscool.com/&lt;br /&gt;&lt;br /&gt;Setelah mendownload aplikasi dan patch dan mendaftar user di gemscool lalu selanjutnya saya coba mainkan mh.... ya seperti Counter Strike permainannya tapi karena tangan sudah lama gak dibuat untuk main game jadi ya kaku kaku gitu harus menghafalkan tombol2 navigasi lagi yang kurang lebih seperti CS.&lt;br /&gt;&lt;br /&gt;yang menarik pada waktu iseng saya klik tombol Check sebelum mengklik Start yang dilakukan oleh PB adalah melakukan download patch dan ternyata bandwidth 10Mbps di sikat habis wak....&lt;br /&gt;waduh ini game kalau lagi ngepatch sadis punya ternyata mh... iseng saya torch di mikrotik ternyata patchnya via port 80 alias http wah ini bisa di bantu squid nih.&lt;br /&gt;&lt;br /&gt;Benar saja setelah saya redirect port 80 ke squid hasilnya sesuai dengan yang saya inginkan yaitu file2 patch bisa di cache di squid proxy sehingga trafficnya sekarang yang besar yang kearah squid proxy&lt;br /&gt;&lt;br /&gt;Gambar berikut adalah bukti bahwa proses patch bisa di bantu squid dengan hasil tail -f /var/log/squid/access.log banyak sekali TCP_HIT maupun TCP_MEM_HIT untuk file2 .zip artinya sekarang patch PB diambil dari cache yang ada di squid&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/TB-UFn5A1dI/AAAAAAAAAbE/poyqSnzkqqM/s1600/squid-hit-patch-pb.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 216px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/TB-UFn5A1dI/AAAAAAAAAbE/poyqSnzkqqM/s400/squid-hit-patch-pb.png" alt="" id="BLOGGER_PHOTO_ID_5485265695488923090" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Berikut adalah tampilan torch mikrotik pada interface wlan1 untuk ip source 10.5.50.232 ternyata pada waktu patch Tx Rate sangat tinggi sekali mencapai 8.2Mbps , untungnya saat ini sudah di dst-nat ke squid sehingga Data Rate yang menuju ke Jakarta tidak sampai 8.2Mbps karena sebagian besar file patching telah ada di squid proxy&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/TB-Ujz-1wYI/AAAAAAAAAbM/beILnjlh_KI/s1600/kantor-pda-t-proxy.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 199px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/TB-Ujz-1wYI/AAAAAAAAAbM/beILnjlh_KI/s400/kantor-pda-t-proxy.png" alt="" id="BLOGGER_PHOTO_ID_5485266214130663810" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Ini adalah buktinya pada waktu PB melakukan patching dan port 80 diredirect ke squid proxy di mikrotik backbone Jakarta-Cirebon tidak terjadi lonjakan traffic sd 8Mbps lebih seperti yang terjadi pada mikrotik distribusi hotspot di kantor.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/TB-WQ-fDwmI/AAAAAAAAAbU/NN7pmVRgHNE/s1600/pda1-torch.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 217px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/TB-WQ-fDwmI/AAAAAAAAAbU/NN7pmVRgHNE/s400/pda1-torch.png" alt="" id="BLOGGER_PHOTO_ID_5485268089555894882" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jadi kesimpulannya traffic patch Point Blank sangat bisa di bantu oleh mekanisme cache squid proxy, sedangkan pada saat permainan berlangsung dengan skenario notebook saya sebagai client yang joint ke server public PB , data rate yang terjadi sangat kecil sekitar 15Kbps-16Kbps&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/TB-W1yX74NI/AAAAAAAAAbc/m8OCDNiTqDg/s1600/pb-on-war.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 134px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/TB-W1yX74NI/AAAAAAAAAbc/m8OCDNiTqDg/s400/pb-on-war.png" alt="" id="BLOGGER_PHOTO_ID_5485268721959952594" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Jadi kesimpulannya:&lt;br /&gt;&lt;br /&gt;1. Proses Patch game Point Blank yang sangat berat bisa di bantu dengan mekanisme cache dari squid&lt;br /&gt;2. Pada saat permainan berlangsung alokasi bandwidth per PC game bisa diset dari 32Kbps - 128Kbps&lt;br /&gt;3. Buat alokasi bandwidth khusus yang berasal dari PC Game menuju ke squid proxy&lt;br /&gt;&lt;br /&gt;adapun di /etc/squid/squid.conf saya coba set parameter berikut:&lt;br /&gt;&lt;br /&gt;maximum_object_size 300000 KB&lt;br /&gt;store_avg_object_size 5000 KB&lt;br /&gt;&lt;br /&gt;karena dari beberapa forum dan blog, ada yang berkomentar maximum objectnya di besarkan jadi 300MB agar file2 patch PB bisa di cache oleh squid&lt;br /&gt;&lt;br /&gt;Semoga hasil analisa ini bisa berguna bagi yang memerlukannya&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-7081675863877949432?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/7081675863877949432/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=7081675863877949432' title='3 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/7081675863877949432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/7081675863877949432'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2010/06/analisa-paket-data-game-point-blank.html' title='Analisa Paket Data Game Point Blank pada waktu melakukan Patch dibantu cache dari Squid Proxy'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_nzWcXcVYSRs/TB-UFn5A1dI/AAAAAAAAAbE/poyqSnzkqqM/s72-c/squid-hit-patch-pb.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-8995302931617878589</id><published>2010-01-05T14:24:00.006+07:00</published><updated>2010-01-05T14:48:17.435+07:00</updated><title type='text'>Max-Term + SATA DOM + Mikrotik 4.4 Level 4 alternatif RB1000</title><content type='html'>Hari ini dapet mainan dari seorang teman sebuah Komputer Max-Term / Maxspeed dengan spesifikasi sbb:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/S0LqLPt3JaI/AAAAAAAAAas/BfuBsp5Ut28/s1600-h/maxterm.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 353px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/S0LqLPt3JaI/AAAAAAAAAas/BfuBsp5Ut28/s400/maxterm.JPG" alt="" id="BLOGGER_PHOTO_ID_5423154380225848738" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Penasaran mau tahu bisa menangani paket sebanyak apa saya lakukan percobaan dengan menggunakan btest.exe dari notebook dengan spesifikasi sbb:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/S0Lq8SZnPzI/AAAAAAAAAa0/5HUuOQZKcmU/s1600-h/winxp.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 351px; height: 400px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/S0Lq8SZnPzI/AAAAAAAAAa0/5HUuOQZKcmU/s400/winxp.JPG" alt="" id="BLOGGER_PHOTO_ID_5423155222759817010" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Percobaan 1: &lt;/span&gt;Max-Term dijalankan BTest-Server lalu dari notebook lenovo menjalankan btest.exe sebanyak 15 windows dengan kombinasi udp dan tcp packet, hasilnya:&lt;br /&gt;&lt;br /&gt;Tx Packet mencapai 8.658 pps dan Rx Packet 14.304 pps pada Tx 76.5 Mbps dan Rx 91.1 Mbps dengna latency mencapai 50 ms - 80 ms cpu 100%&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/S0Lplz8EfiI/AAAAAAAAAac/EhQ1ITpV-yA/s1600-h/max-term-test-packet.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/S0Lplz8EfiI/AAAAAAAAAac/EhQ1ITpV-yA/s400/max-term-test-packet.JPG" alt="" id="BLOGGER_PHOTO_ID_5423153737114091042" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Percobaan 2:&lt;/span&gt; Notebook menjalankan btest.exe sebagai server dan Max-Term melakukan bandwidth-test ke notebook sebanyak 25 terminal dengan protocol udp hasilnya:&lt;br /&gt;&lt;br /&gt;Tx Packet mencapai 3.280 pps dan Rx Packet 8.061 pps pada Tx 38.7Mbps dan Rx 97.1Mbps dengna latency mencapai 3 ms cpu 18%&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/S0LpmD0LHaI/AAAAAAAAAak/GmTA39LAWdY/s1600-h/max-term-test-packet-udp-to-notebook.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/S0LpmD0LHaI/AAAAAAAAAak/GmTA39LAWdY/s400/max-term-test-packet-udp-to-notebook.JPG" alt="" id="BLOGGER_PHOTO_ID_5423153741375937954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Kesimpulan:&lt;br /&gt;Harusnya dengan MaxTerm / Maxspeed + Mikrotik 4.4 Level 4 bisa mem-forward packet 0 - 10000 pps pada throughput  &lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt; 0 - 20 Mbps  dengan lancar&lt;br /&gt;&lt;br /&gt;Berikut adalah gambar MaxTerm / Maxspeed :&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/S0LplbUO6YI/AAAAAAAAAaM/j1PMqto4xcw/s1600-h/IMG00048-20100105-1357.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/S0LplbUO6YI/AAAAAAAAAaM/j1PMqto4xcw/s400/IMG00048-20100105-1357.jpg" alt="" id="BLOGGER_PHOTO_ID_5423153730504550786" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/S0LplmddewI/AAAAAAAAAaU/tfR6JzIZfAA/s1600-h/IMG00047-20100105-1356.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/S0LplmddewI/AAAAAAAAAaU/tfR6JzIZfAA/s400/IMG00047-20100105-1356.jpg" alt="" id="BLOGGER_PHOTO_ID_5423153733496044290" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;yang mau cari barangnya cek aja di : &lt;a href="http://www.edccomp.com/product.php?id_product=175"&gt;http://www.edccomp.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-8995302931617878589?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/8995302931617878589/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=8995302931617878589' title='2 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/8995302931617878589'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/8995302931617878589'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2010/01/max-term-sata-dom-mikrotik-44-level-4.html' title='Max-Term + SATA DOM + Mikrotik 4.4 Level 4 alternatif RB1000'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_nzWcXcVYSRs/S0LqLPt3JaI/AAAAAAAAAas/BfuBsp5Ut28/s72-c/maxterm.JPG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-3998683926440353067</id><published>2010-01-02T10:26:00.034+07:00</published><updated>2010-01-02T11:45:51.586+07:00</updated><title type='text'>BGP Failover antar BTS</title><content type='html'>Halo apakabar? Selamat Tahun Baru 2010 sudah lama saya tidak menulis blog saya ini, kebetulan lagi liburan Tahun Baru saya coba tulis contoh kasus BGP Failover antar BTS.&lt;br /&gt;&lt;br /&gt;Dalam contoh kasus BGP Failover antar BTS skenarionya adalah sbb:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz6-LJHurZI/AAAAAAAAAXE/VZbxl7eRQTI/s1600-h/bgp-failover-cyber-meruya-slipi.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 352px; height: 400px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz6-LJHurZI/AAAAAAAAAXE/VZbxl7eRQTI/s400/bgp-failover-cyber-meruya-slipi.jpg" alt="" id="BLOGGER_PHOTO_ID_5421980100036832658" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Dengan skenario diatas maka BTS Slipi dan BTS Meruya menjadi full-protection (bahasa kerennya XL / Moratel / Icon+ untuk backbone fiber-optic mereka di pulau Jawa)&lt;br /&gt;&lt;br /&gt;Dengan demikian ada 4 BGP Router yang terlibat dalam skenario ini, yaitu: Router International dan Router OIXP/IIX yang keduanya ada di Gedung Cyber dan Router Mikrotik di BTS Slipi dan BTS Meruya&lt;br /&gt;&lt;br /&gt;Adapun link yang antara Gedung Cyber ke Slipi menggunakan Fiber Optic sedangkan antara Gedung Cyber ke Meruya menggunakan Microwave 15Ghz (Pake ISR tentunya) dan Dari Meruya ke Slipi menggunakan WiFi IEEE 802.11 tentunya pake Mikrotik RB600&lt;br /&gt;&lt;br /&gt;Ok langsung saja berikut adalah screen capturenya semoga bermanfaat bagi yang membacanya, oh ya dalam screen capture ip-ip publik yang relevan tidak saya sensor agar bisa menjadi contoh nyata karena semangat saya nulis adalah untuk berbagi jadi mohon agar tidak di serang ya "semoga".&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Konfigurasi di Router IIX di Cyber pada Cisco 7206VXR G2:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;neighbor ke Mikrotik Meruya&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/Sz7BPpV77pI/AAAAAAAAAXM/oVHBc92dGSM/s1600-h/bgp-failover-cisco-bgp-peers-meruya.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 77px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/Sz7BPpV77pI/AAAAAAAAAXM/oVHBc92dGSM/s400/bgp-failover-cisco-bgp-peers-meruya.jpg" alt="" id="BLOGGER_PHOTO_ID_5421983475940716178" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;neighbor ke Mikrotik Slipi&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/Sz7BliYHDhI/AAAAAAAAAXU/aB0aRGHPGiE/s1600-h/bgp-failover-cisco-bgp-peers-peninsula.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 72px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/Sz7BliYHDhI/AAAAAAAAAXU/aB0aRGHPGiE/s400/bgp-failover-cisco-bgp-peers-peninsula.jpg" alt="" id="BLOGGER_PHOTO_ID_5421983852027907602" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;route-map IIXNICEONLY-EXPORT&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7B2D5fUuI/AAAAAAAAAXc/7_ParKrfA1g/s1600-h/bgp-failover-cisco-route-map.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 325px; height: 131px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7B2D5fUuI/AAAAAAAAAXc/7_ParKrfA1g/s400/bgp-failover-cisco-route-map.jpg" alt="" id="BLOGGER_PHOTO_ID_5421984135904187106" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;as-path 2 , tujuannya untuk memfilter hanya prefix dari AS7597 (IIX) dan AS7717 (NICE/OIXP) yang akan di advertise ke BGP Meruya dan Slipi, untuk di implementasikan ke route-map IIXNICEONLY-EXPORT diatas&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/Sz7CPdOsi-I/AAAAAAAAAXk/eXAPXeeTAMQ/s1600-h/bgp-failover-cisco-as-path-2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 326px; height: 49px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/Sz7CPdOsi-I/AAAAAAAAAXk/eXAPXeeTAMQ/s400/bgp-failover-cisco-as-path-2.jpg" alt="" id="BLOGGER_PHOTO_ID_5421984572200750050" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;access-list 100, tujuannya selain prefix dari AS7597 (IIX) dan AS7717 (NICE/OIXP) juga prefix asli milik Datautama di advertise ke BGP Meruya dan Slipi, untuk di implementasikan ke route-map IIXNICEONLY-EXPORT diatas&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7C4LH7VXI/AAAAAAAAAXs/LaU9X1oGobw/s1600-h/bgp-failover-cisco-access-list.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 361px; height: 400px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7C4LH7VXI/AAAAAAAAAXs/LaU9X1oGobw/s400/bgp-failover-cisco-access-list.jpg" alt="" id="BLOGGER_PHOTO_ID_5421985271715157362" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Dengan demikian maka BGP Meruya dan Slipi akan menerima prefix/routing table IIX+OIXP+Datautama&lt;br /&gt;&lt;br /&gt;Jika konfigurasi ke 4 BGP tersebut telah berfungsi maka hasil "sh ip bgp sum" di router IIX/OIXP di cyber adalah sbb:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7ECa1maEI/AAAAAAAAAX0/bEjGhlKZJOk/s1600-h/bgp-failover-cisco-bgp-sum.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 327px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7ECa1maEI/AAAAAAAAAX0/bEjGhlKZJOk/s400/bgp-failover-cisco-bgp-sum.jpg" alt="" id="BLOGGER_PHOTO_ID_5421986547243575362" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Konfigurasi di Router Internatinoal di Cyber:&lt;br /&gt;&lt;/span&gt;&lt;span&gt;&lt;br /&gt;neighbor ke Mikrotik Meruya&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz7EfCeefiI/AAAAAAAAAX8/WfwnuSiEIxw/s1600-h/bgp-failover-ibm-bgp-peers-meruya.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 93px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz7EfCeefiI/AAAAAAAAAX8/WfwnuSiEIxw/s400/bgp-failover-ibm-bgp-peers-meruya.jpg" alt="" id="BLOGGER_PHOTO_ID_5421987038920343074" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;neighbor ke Mikrotik Slipi&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/Sz7EqLzE-EI/AAAAAAAAAYE/eM4Y-WmlThg/s1600-h/bgp-failover-ibm-bgp-peers-slipi.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 87px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/Sz7EqLzE-EI/AAAAAAAAAYE/eM4Y-WmlThg/s400/bgp-failover-ibm-bgp-peers-slipi.jpg" alt="" id="BLOGGER_PHOTO_ID_5421987230401230914" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;route-map KOSONG&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz7E8Xf98zI/AAAAAAAAAYM/O_Yhdhmoe_s/s1600-h/bgp-failover-ibm-route-map.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 355px; height: 130px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz7E8Xf98zI/AAAAAAAAAYM/O_Yhdhmoe_s/s400/bgp-failover-ibm-route-map.jpg" alt="" id="BLOGGER_PHOTO_ID_5421987542779949874" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;tujuan dari as-path access-list 11 deny .*  pada route-map KOSONG adalah untuk memfilter semua prefix dari International agar tidak di advertise ke BTS Meruya dan Slipi, karena Mikrotik Meruya dan Slipi hanya perlu prefix IIX/OIXP agar routing menuju ke IIX/OIXP langsung belok ke Router IIX/OIXP di Cyber sedangkan default-route menuju ke Router International.&lt;br /&gt;&lt;br /&gt;Sebagai catatan: hal terpenting dalam bermain BGP maupun OSPF adalah pemahaman tentang filtering as-path , access-list, prepend, subnet dan supernet.&lt;br /&gt;&lt;br /&gt;Jika konfigurasi ke 4 BGP tersebut telah berfungsi maka hasil "sh ip bgp sum" di router International di cyber adalah sbb:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/Sz7GAzIeIMI/AAAAAAAAAYU/61iLSn1O5S8/s1600-h/bgp-failover-ibm-bgp-sum.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 230px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/Sz7GAzIeIMI/AAAAAAAAAYU/61iLSn1O5S8/s400/bgp-failover-ibm-bgp-sum.jpg" alt="" id="BLOGGER_PHOTO_ID_5421988718428692674" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Konfigurasi di Router Mikrotik Meruya:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;ip-address, interface backhaul adalah interface yang menghadap ke Cyber menggunakan Microwave 15Ghz&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/Sz7Ga7PZHDI/AAAAAAAAAYc/pea8Zax7BzI/s1600-h/bgp-failover-meruya-ipaddress.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 107px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/Sz7Ga7PZHDI/AAAAAAAAAYc/pea8Zax7BzI/s400/bgp-failover-meruya-ipaddress.jpg" alt="" id="BLOGGER_PHOTO_ID_5421989167281806386" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;bgp-instance&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/Sz7Gy4rVQ_I/AAAAAAAAAYk/c0yugyoLbFI/s1600-h/bgp-failover-meruya-bgp-instance.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 363px; height: 400px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/Sz7Gy4rVQ_I/AAAAAAAAAYk/c0yugyoLbFI/s400/bgp-failover-meruya-bgp-instance.jpg" alt="" id="BLOGGER_PHOTO_ID_5421989578910548978" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;bgp-peers Meruya ke International Cyber, hold time di buat 20 agar BGP lebih responsif terhadap kondisi link antar BGP up atau down&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7HH6PsEUI/AAAAAAAAAYs/YT982AkHeZc/s1600-h/bgp-failover-meruya-bgp-peers-inter.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 349px; height: 400px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7HH6PsEUI/AAAAAAAAAYs/YT982AkHeZc/s400/bgp-failover-meruya-bgp-peers-inter.jpg" alt="" id="BLOGGER_PHOTO_ID_5421989940108726594" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;bgp-peers Meruya ke IIX Cyber, hold time di buat 20 agar BGP lebih responsif terhadap kondisi link antar BGP up atau down&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7Ha8psjlI/AAAAAAAAAY0/BdPOqFRx7GU/s1600-h/bgp-failover-meruya-bgp-peers-iix.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 350px; height: 400px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7Ha8psjlI/AAAAAAAAAY0/BdPOqFRx7GU/s400/bgp-failover-meruya-bgp-peers-iix.jpg" alt="" id="BLOGGER_PHOTO_ID_5421990267172195922" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;bgp-peers Meruya ke Slipi, hold time di buat 20 agar BGP lebih responsif terhadap kondisi link antar BGP up atau down&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/Sz7HqYNzRqI/AAAAAAAAAY8/vkvmZwVE_wM/s1600-h/bgp-failover-meruya-bgp-peers-peninsula.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 351px; height: 400px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/Sz7HqYNzRqI/AAAAAAAAAY8/vkvmZwVE_wM/s400/bgp-failover-meruya-bgp-peers-peninsula.jpg" alt="" id="BLOGGER_PHOTO_ID_5421990532269426338" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Berikut adalah konfigurasi routing-filter yang merupakan bagian terpenting dan paling rumit untuk dipahami, pada bagian BGP Prepend tujuannya agar ke arah PENINSULA-EXPORT di prepend 2 kali agar ke arah AS24521-EXPORT lebih pendek sehingga menjadi prioritas, kecuali jika link Meruya ke Cyber putus baru akan menggunakan link Meruya-Slipi-Cyber.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz7IXU1pTJI/AAAAAAAAAZE/4o3W6p2rRkw/s1600-h/bgp-failover-meruya-routing-filter.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 231px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz7IXU1pTJI/AAAAAAAAAZE/4o3W6p2rRkw/s400/bgp-failover-meruya-routing-filter.jpg" alt="" id="BLOGGER_PHOTO_ID_5421991304456916114" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Konfigurasi di Router Mikrotik Slipi:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;ip-address, interface ether1 adalah interface yang menghadap ke Cyber menggunakan Fiber Optic&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz7IzPm6gpI/AAAAAAAAAZM/0DVWoDqUryE/s1600-h/bgp-failover-rb1000-ipaddress.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 133px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz7IzPm6gpI/AAAAAAAAAZM/0DVWoDqUryE/s400/bgp-failover-rb1000-ipaddress.jpg" alt="" id="BLOGGER_PHOTO_ID_5421991784089289362" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;bgp-instance&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz7JJYmNFPI/AAAAAAAAAZU/OU9V9FlEpLU/s1600-h/bgp-failover-rb1000-bgp-instance.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 382px; height: 400px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz7JJYmNFPI/AAAAAAAAAZU/OU9V9FlEpLU/s400/bgp-failover-rb1000-bgp-instance.jpg" alt="" id="BLOGGER_PHOTO_ID_5421992164459353330" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;bgp-peers Slipi ke International Cyber, hold time di buat 20 agar BGP lebih responsif terhadap kondisi link antar BGP up atau down&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/Sz7JvzY6DCI/AAAAAAAAAZc/BOw5mWndojs/s1600-h/bgp-failover-rb1000-bgp-peers-inter.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 314px; height: 400px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/Sz7JvzY6DCI/AAAAAAAAAZc/BOw5mWndojs/s400/bgp-failover-rb1000-bgp-peers-inter.jpg" alt="" id="BLOGGER_PHOTO_ID_5421992824486366242" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;bgp-peers Slipi ke IIX Cyber, hold time di buat 20 agar BGP lebih responsif terhadap kondisi link antar BGP up atau down&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz7J_xbjY6I/AAAAAAAAAZk/BuPXTidSbn8/s1600-h/bgp-failover-rb1000-bgp-peers-iix.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 313px; height: 400px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz7J_xbjY6I/AAAAAAAAAZk/BuPXTidSbn8/s400/bgp-failover-rb1000-bgp-peers-iix.jpg" alt="" id="BLOGGER_PHOTO_ID_5421993098838500258" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;bgp-peers Slipi ke Meruya, hold time di buat 20 agar BGP lebih responsif terhadap kondisi link antar BGP up atau down&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7KQEtb65I/AAAAAAAAAZs/XYfhU-oZpvw/s1600-h/bgp-failover-rb1000-bgp-peers-presisi.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 312px; height: 400px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7KQEtb65I/AAAAAAAAAZs/XYfhU-oZpvw/s400/bgp-failover-rb1000-bgp-peers-presisi.jpg" alt="" id="BLOGGER_PHOTO_ID_5421993378891688850" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Berikut adalah konfigurasi routing-filter yang merupakan bagian terpenting dan paling rumit untuk dipahami, pada bagian BGP Prepend tujuannya agar ke arah PRESISI-EXPORT di prepend 2 kali agar ke arah INTL-CYBER-EXPORT lebih pendek sehingga menjadi prioritas, kecuali jika link Slipi ke Cyber putus baru akan menggunakan link Slipi-Meruya-Cyber.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7KiVL-F9I/AAAAAAAAAZ0/F6uaz4_HY9s/s1600-h/bgp-failover-rb1000-routing-filter.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 343px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7KiVL-F9I/AAAAAAAAAZ0/F6uaz4_HY9s/s400/bgp-failover-rb1000-routing-filter.jpg" alt="" id="BLOGGER_PHOTO_ID_5421993692552370130" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Dengan demikian maka pada kondisi Fiber Optic Slipi-Cyber normal default-route pada Mikrotik di Slipi adalah sbb:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz7L8VX1leI/AAAAAAAAAZ8/RFrqPrAdUVY/s1600-h/bgp-failover-rb1000-ip-route.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 170px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz7L8VX1leI/AAAAAAAAAZ8/RFrqPrAdUVY/s400/bgp-failover-rb1000-ip-route.jpg" alt="" id="BLOGGER_PHOTO_ID_5421995238790370786" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;DAb Destination 0.0.0.0/0 gateway 203.89.26.49 adalah entry bgp yang di terima, sedangkan Db Destination 0.0.0.0/0 gateway 203.89.24.185 dengan warna biru adalah entry bgp yang tidak diterima atau dengan kata lain standby kalau sampai gateway 203.89.26.49 putus maka gateway 203.89.24.185 akan digunakan melalui interface ipip-P6toP2 yang merupakan ipip-tunnel dari Mikrotik Slipi ke Mikrotik Meruya melalui link WiFi IEEE 802.11 menggunakan RB600&lt;br /&gt;&lt;br /&gt;Sedangkan untuk kondisi Microwave 15Ghz Meruya-Cyber normal default-route pada Mikrotik Meruya adalah sbb:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7L8om5grI/AAAAAAAAAaE/TTqP400E2vY/s1600-h/bgp-failover-meruya-ip-route.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 205px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/Sz7L8om5grI/AAAAAAAAAaE/TTqP400E2vY/s400/bgp-failover-meruya-ip-route.jpg" alt="" id="BLOGGER_PHOTO_ID_5421995243953816242" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;DAb Destination 0.0.0.0/0 gateway 203.89.26.1 adalah entry bgp yang di terima, sedangkan Db Destination 0.0.0.0/0 gateway 203.89.24.186 dengan warna biru adalah entry bgp yang tidak diterima atau dengan kata lain standby kalau sampai gateway 203.89.26.1 putus maka gateway 203.89.24.186 akan digunakan melalui interface ipip-P2toP6 yang merupakan ipip-tunnel dari Mikrotik Meruya ke Mikrotik Slipi melalui link WiFi IEEE 802.11 menggunakan RB600&lt;br /&gt;&lt;br /&gt;Demikian kiranya sedikit sharing ilmu semoga bermanfaat bagi semua yang membacanya&lt;br /&gt;&lt;br /&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-3998683926440353067?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/3998683926440353067/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=3998683926440353067' title='4 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3998683926440353067'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3998683926440353067'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2010/01/bgp-failover-antar-bts.html' title='BGP Failover antar BTS'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_nzWcXcVYSRs/Sz6-LJHurZI/AAAAAAAAAXE/VZbxl7eRQTI/s72-c/bgp-failover-cyber-meruya-slipi.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-5344547449664607680</id><published>2009-08-10T12:22:00.000+07:00</published><updated>2009-08-10T12:23:14.038+07:00</updated><title type='text'>Blacklists/Blocklists</title><content type='html'>&lt;p&gt;Blacklists or blocklists are lists of &lt;acronym title="Internet Protocol"&gt;IP&lt;/acronym&gt; addresses, domain names, email addresses or content of the headers or the body, or some combination of these different types, that can be used to help identify spam. A special subset of IP address and domain name lists exist which can be queried using &lt;acronym title="Domain Name Service"&gt;DNS&lt;/acronym&gt;, which are called &lt;acronym title="Domain Name Service"&gt;DNS&lt;/acronym&gt; Blackhole Lists or &lt;a href="http://spamlinks.net/filter-dnsbl.htm" class="locallink" title="DNS Blackhole Lists"&gt;DNSBLs&lt;/a&gt;. Blacklists can be unverified and cause “collateral damage”; their criteria for listing may not be clear.&lt;/p&gt;     &lt;p&gt;Those blacklists listed here are just a tiny subset of all of the private access lists and &lt;acronym title="Access Control Lists"&gt;ACLs&lt;/acronym&gt; that exist to block spam from private networks; that larger set is the source of the death of a thousand cuts that any spam friendly provider should eventually experience. They may not have the clout of SPEWS, but they may last even longer.&lt;/p&gt;&lt;br /&gt;From:&lt;br /&gt;&lt;a href="http://spamlinks.net/filter-bl.htm"&gt;http://spamlinks.net/filter-bl.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-5344547449664607680?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/5344547449664607680/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=5344547449664607680' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5344547449664607680'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5344547449664607680'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2009/08/blacklistsblocklists.html' title='Blacklists/Blocklists'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-5770099470118111103</id><published>2009-08-10T10:58:00.000+07:00</published><updated>2009-08-10T10:59:20.569+07:00</updated><title type='text'>Postfix blacklist or reject an email address</title><content type='html'>&lt;p&gt;&lt;strong&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Q&lt;/span&gt;&lt;/strong&gt;. I’ve Postfix based CentOS Linux server. I need to blacklist email ID: user@abadboy.com . How do I blacklist email address with postfix? I also have spamassassin software installed.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;A&lt;/span&gt;&lt;/strong&gt;. By default, the Postfix SMTP server accepts any sender address. However you can block / blacklist sender email address easily with Postfix. It has SMTP server access table. &lt;/p&gt; &lt;p&gt;Open /etc/postfix/sender_access file&lt;br /&gt;&lt;code&gt;# cd /etc/postfix&lt;br /&gt;# vi sender_access &lt;/code&gt;&lt;br /&gt;Append sender email id as follows:&lt;br /&gt;&lt;code&gt;user@abadboy.com  REJECT&lt;/code&gt;&lt;br /&gt;Save and close the file. Use postmap command to create a database:&lt;br /&gt;&lt;code&gt;# postmap hash:sender_access &lt;/code&gt;&lt;br /&gt;Now open main.cf and add code as follows:&lt;br /&gt;&lt;code&gt;smtpd_recipient_restrictions = check_sender_access hash:/etc/postfix/sender_access&lt;/code&gt;&lt;br /&gt;Save and  close the file. Restart / reload postfix MTA:&lt;br /&gt;&lt;code&gt;# /etc/init.d/postfix restart&lt;/code&gt;&lt;/p&gt; &lt;p&gt;You can also use spamassassin to blacklist email address. Just add to your own spamassassin configuration or to /etc/mail/spamassassin/local.cf file:&lt;br /&gt;&lt;code&gt;# vi /etc/mail/spamassassin/local.cf&lt;/code&gt;&lt;br /&gt;Append blacklist as follows:&lt;br /&gt;&lt;code&gt;blacklist_from   user@abadboy.com&lt;/code&gt;&lt;br /&gt;Save and close the file. Restart spamassassin:&lt;br /&gt;&lt;code&gt;# /etc/init.d/spamassassin restart&lt;/code&gt;&lt;/p&gt; &lt;p&gt;spamassassin will marke mail as SPAM instead of rejecting the same.&lt;/p&gt;From:&lt;a href="http://www.cyberciti.biz/faq/howto-blacklist-reject-sender-email-address/"&gt;&lt;br /&gt;http://www.cyberciti.biz/faq/howto-blacklist-reject-sender-email-address/&lt;/a&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-5770099470118111103?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/5770099470118111103/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=5770099470118111103' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5770099470118111103'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5770099470118111103'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2009/08/postfix-blacklist-or-reject-email.html' title='Postfix blacklist or reject an email address'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-6931514504535178897</id><published>2009-08-09T12:01:00.001+07:00</published><updated>2009-08-09T12:04:41.170+07:00</updated><title type='text'>Lindungi jaringan anda dari daftar ip yang terindentifikasi pada dshield dan  spamhaus</title><content type='html'>Pagi ini lagi-lagi smtp ku di buat mabok oleh traffic spam , iseng aku cari di google bagaimana fetch daftar ip sumber spam langsung di mikrotik ternyata ketemu link berikut:&lt;br /&gt;&lt;a href="http://forum.mikrotik.com/viewtopic.php?f=9&amp;amp;t=24427"&gt;&lt;br /&gt;http://forum.mikrotik.com/viewtopic.php?f=9&amp;amp;t=24427&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;berikut adalah contoh script + scheduling + firewall filter yang saya gunakan di router mikrotik 3.25:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;# aug/09/2009 11:27:24 by RouterOS 3.25&lt;br /&gt;#&lt;br /&gt;/system script&lt;br /&gt;add name=fetch-dshield-spamhaus policy=\&lt;br /&gt;    ftp,reboot,read,write,policy,test,winbox,password,sniff source="## Parse D\&lt;br /&gt;    SHIELD &amp;amp; Spamhaus feed and build an address-list.\r\&lt;br /&gt;    \n## Written by Sam Norris, ChangeIP.com 2008\r\&lt;br /&gt;    \n## Any comments or suggestions welcome in the forums.\r\&lt;br /&gt;    \n##\r\&lt;br /&gt;    \n## 06/03/08 - Initial list parsing.\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n/tool fetch address=feeds.dshield.org host=feeds.dshield.org mode=http s\&lt;br /&gt;    rc-path=block.txt\r\&lt;br /&gt;    \n/tool fetch address=www.spamhaus.org host=www.spamhaus.org mode=http src\&lt;br /&gt;    -path=drop/drop.lasso\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n##\r\&lt;br /&gt;    \n## DSHIELD Drop List\r\&lt;br /&gt;    \n##\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n:if ( [/file get [/file find name=block.txt] size] &gt; 0 ) do={\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n  /ip firewall address-list remove [/ip firewall address-list find list=\&lt;br /&gt;    dshield]\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n  :global content [/file get [/file find name=block.txt] contents] ;\r\&lt;br /&gt;    \n  :global contentLen [ :len \$content ] ;\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n  :global lineEnd 0;\r\&lt;br /&gt;    \n  :global line \"\";\r\&lt;br /&gt;    \n  :global lastEnd 0;\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n  :do {\r\&lt;br /&gt;    \n       :set lineEnd [:find \$content \"\\n\" \$lastEnd ] ;\r\&lt;br /&gt;    \n       :set line [:pick \$content \$lastEnd \$lineEnd] ;\r\&lt;br /&gt;    \n       :set lastEnd ( \$lineEnd + 1 ) ;\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n       :if ( [:pick \$line 0 1] != \"#\" ) do={\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n    :if ([:typeof [:toip [:pick \$line 0 [:find \$line \"\\t\"] ] ] ] !=\&lt;br /&gt;    \_\"nil\") do={\r\&lt;br /&gt;    \n      :local pos1 [:find \$line \"\\t\" 0]\r\&lt;br /&gt;    \n      :local pos2 [:find \$line \"\\t\" \$pos1]\r\&lt;br /&gt;    \n      :local pos3 [:find \$line \"\\t\" \$pos2]\r\&lt;br /&gt;    \n      :log info ( \"DShield Entry: \" . [:pick \$line 0 \$pos1 ] . \"/\"\&lt;br /&gt;    \_. [:pick \$line (\$pos2+1) \$pos3 ] )\r\&lt;br /&gt;    \n      /ip firewall address-list add list=dshield address=( [:pick \$line\&lt;br /&gt;    \_0 \$pos1 ] . \"/\" . [:pick \$line (\$pos2+1) \$pos3 ] )\r\&lt;br /&gt;    \n         } \r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n       }\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n  } while (\$lineEnd &lt; \$contentLen)\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n}\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n##\r\&lt;br /&gt;    \n## SPAMHAUS.ORG Drop List\r\&lt;br /&gt;    \n##\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n:if ( [/file get [/file find name=drop.lasso] size] &gt; 0 ) do={\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n  /ip firewall address-list remove [/ip firewall address-list find list=\&lt;br /&gt;    spamhaus.lasso]\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n  :global content [/file get [/file find name=drop.lasso] contents] ;\r\&lt;br /&gt;    \n  :global contentLen [ :len \$content ] ;\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n  :global lineEnd 0;\r\&lt;br /&gt;    \n  :global line \"\";\r\&lt;br /&gt;    \n  :global lastEnd 0;\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n  :do {\r\&lt;br /&gt;    \n       :set lineEnd [:find \$content \"\\n\" \$lastEnd ] ;\r\&lt;br /&gt;    \n       :set line [:pick \$content \$lastEnd \$lineEnd] ;\r\&lt;br /&gt;    \n       :set lastEnd ( \$lineEnd + 1 ) ;\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n       :if ( [:pick \$line 0 1] != \";\" ) do={\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n    :if ([:len [:pick \$line 0 [:find \$line \";\"] ] ] &gt; 0 ) do={\r\&lt;br /&gt;    \n      :local pos1 [:find \$line \";\" 0]\r\&lt;br /&gt;    \n      :local entry [:pick \$line 0 (\$pos1-1) ]\r\&lt;br /&gt;    \n      :if ( [:len \$entry ] &gt; 0 ) do={\r\&lt;br /&gt;    \n         :log info \"Lasso Entry: \$entry\"\r\&lt;br /&gt;    \n         /ip firewall address-list add list=spamhaus.lasso address=\$ent\&lt;br /&gt;    ry\r\&lt;br /&gt;    \n      }\r\&lt;br /&gt;    \n         } \r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n       }\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n  } while (\$lineEnd &lt; \$contentLen)\r\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n}"&lt;br /&gt;# aug/09/2009 11:27:47 by RouterOS 3.25&lt;br /&gt;#&lt;br /&gt;/system scheduler&lt;br /&gt;add comment="" disabled=no interval=12h name=fecth-dshield-spamhaus on-event=\&lt;br /&gt;    fetch-dshield-spamhaus start-date=jan/01/1970 start-time=06:00:00&lt;br /&gt;# aug/09/2009 11:33:37 by RouterOS 3.25&lt;br /&gt;#&lt;br /&gt;/ip firewall filter&lt;br /&gt;add action=drop chain=forward comment="### DROP Spamhaus-Lasso" disabled=no \&lt;br /&gt;    src-address-list=spamhaus.lasso&lt;br /&gt;add action=drop chain=forward comment="### DROP Dshield" \&lt;br /&gt;    disabled=no src-address-list=dshield&lt;br /&gt;#&lt;/span&gt;&lt;br /&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-6931514504535178897?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/6931514504535178897/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=6931514504535178897' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6931514504535178897'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6931514504535178897'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2009/08/lindungi-jaringan-anda-dari-daftar-ip.html' title='Lindungi jaringan anda dari daftar ip yang terindentifikasi pada dshield dan  spamhaus'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-3374729166498678588</id><published>2009-07-31T11:02:00.002+07:00</published><updated>2009-07-31T12:19:00.112+07:00</updated><title type='text'>ISP dan Keamanan Jaringan Internet</title><content type='html'>Saat ini Internet sudah mulai menjadi gaya hidup yang tanpa disadari diperlukan oleh hampir seluruh lapisan masyarakat seiring dengan kemajuan teknologi baik hardware maupun software.&lt;br /&gt;Dengan fenomena layanan Facebook, Blog, Email dan Instant Messaging yang dapat diakses melalui berbagai macam gadget maka layanan Internet bukan lagi monopoli orang yang mampu menggunakan komputer dengan 101 tombol saja tetapi hampir semua lapisan masyarakat dapat mengakses layanan Internet dengan sangat mudah.&lt;br /&gt;&lt;br /&gt;Internet Service Provider  yang merupakan gerbang bagi para pengguna Internet saat ini menghadapi tantangan untuk dapat tetap memberikan layanan Internet yang berkualitas, terjangkau dan aman bagi penggunanya.&lt;br /&gt;&lt;br /&gt;Bicara tentang keamanan Internet tidak terlepas dari Sistem Keamanan Jaringan Komputer yang sangat komplek dan banyak lapisan walaupun dapat di rangkum dalam tiga hal besar saja yaitu:&lt;br /&gt;&lt;br /&gt;Confidentiality (kerahasiaan data)&lt;br /&gt;Integrity (Integritas / keutuhan / keaslian, termasuk pengaturan hak akses)&lt;br /&gt;Availability (Ketersediaan layanan)&lt;br /&gt;&lt;br /&gt;selain itu bicara tentang keamanan jaringan komputer mau tidak mau tunduk terhadap model segitiga yang memiliki tiga sisi:&lt;br /&gt;&lt;br /&gt;sisi kemanan&lt;br /&gt;sisi kenyamanan/kemudahan&lt;br /&gt;sisi fungsi&lt;br /&gt;&lt;br /&gt;dimana ketiga sisi tersebut saling bertolak belakang, artinya mengutamakan salah satu berarti mengurangi yang lainnya dengan demikian yang dapat dicapai adalah mencari komposisi yang paling dapat diterima oleh pengguna, dengan demikian menurut saya visi keamanan di ISP adalah:&lt;br /&gt;&lt;br /&gt;Menciptakan Internet yang aman, nyaman dan berfungsi dengan baik&lt;br /&gt;&lt;br /&gt;visi diatas sangat sederhana tetapi untuk mencapi hal tersebut terus terang tidak mudah dan butuh banyak pemikiran pertimbangan dan pemahaman dari semua stake holder sbb:&lt;br /&gt;&lt;br /&gt;1. Pengguna Internet&lt;br /&gt;2. Internet Service Provider (ISP) termasuk Network Access Provider&lt;br /&gt;3. Content Provider termasuk penyelenggara e-Bussines/e-Commerce dan infrastruktur pendukungnya yaitu: Bank, penerbit Certified Authorization (CA) dan logistik.&lt;br /&gt;4. Penyelenggara Jaringan&lt;br /&gt;5. Pemerintah&lt;br /&gt;&lt;br /&gt;tentunya tidak semua aspek dapat diakomodir oleh ISP, karena sejatinya ISP minimal memiliki layanan standar sbb:&lt;br /&gt;&lt;br /&gt;1. DNS server / nameserver sebagai sarana resolve domain ke IP atau sebaliknya&lt;br /&gt;2. Email server sebagai outgoing dan atau incoming server&lt;br /&gt;3. Proxy server sebagai perantara akses web sekaligus sebagai cache dan filtering konten pada lapisan aplikasi&lt;br /&gt;4. Webhosting sebagai sarana untuk mempublikasikan halaman web&lt;br /&gt;5. RADIUS Server sebagai Authentication Authorization Accounting (AAA) untuk Billing Server&lt;br /&gt;6. Routing Alamat IP agar user/pengguna dapat mengkakses layanan-layanan tersebut melalui protocol TCP/IP yang dihubungkan satu dengan lainnya secara terbuka atau dengan kata lain jaringan Publik (Internet)&lt;br /&gt;7. Sistem Monitoring dan manajemen Jaringan&lt;br /&gt;&lt;br /&gt;Dengan demikian bagian keamanan yang harus di akomodir oleh ISP setidaknya adalah:&lt;br /&gt;1. Menyediakan Nameserver yang handal dan aman yang bebas dari dns poisoning / spoofing&lt;br /&gt;2. Menyediakan Email server yang mampu menyaring email sampah (Spam), virus dan mallware lainnya&lt;br /&gt;3. Menyediakan Proxy Server yang mampu menyaring pishing dan membatasi konten-konten mallware lainnya.&lt;br /&gt;4. Menyediakan Webhosting yang aman yang tidak menyimpan kode-kode jahat seperti pishing, virus, trojan, mallware dan konten-konten yang mengandung unsur SARA (Suku Agama Ras)&lt;br /&gt;5. Menyediakan RADIUS Server yang handal, aman dan tidak merugikan pelanggan baik secara finansial maupun secara kerahasiaan username password pelanggan tersebut.&lt;br /&gt;6. Menyediakan sistem routing paket TCP/IP yang handal, aman dan terbebas dari serangan: Spoofing, Distributed Denial of Service, Worm dll.&lt;br /&gt;7. Memiliki sistem monitoring dan manajemen jaringan untuk dapat menganalisa dan mengatasi permasalahan jika terjadi hal-hal yang disebut diatas.&lt;br /&gt;&lt;br /&gt;adapun layanan-layanan lainnya selain tujuh hal yang disebutkan diatas lebih sebagai tanggung jawab pengelola konten baik itu bagi ISP yang memiliki konten, maupun institusi yang menyediakan konten bagi pengguna Internet termasuk: E-Banking/Bank, Pengelola E-Business/E-Commerce, E-Learning/Kampus, E-Goverment/Pemerintah, Pengelola Portal dll.&lt;br /&gt;&lt;br /&gt;Sedangkan untuk Warnet sejatinya adalah mini ISP yang menyediakan/menyewakan sarana bagi pengguna Internet yang tidak mengakses Internet dari perangkat pribadinya.&lt;br /&gt;&lt;br /&gt;Dalam hal terjadinya cybercrime ISP berperan untuk membantu perangkat hukum melakukan investigasi dan mencari bukti-bukti digital yang sekiranya dapat menjadi petunjuk dan bukti di pengadilan sesuai dengan perundang-undangan yang berlaku.&lt;br /&gt;&lt;br /&gt;Bentuk barang bukti dan petunjuk bisa berupa analisa header email, logfile aplikasi server-server yang telah disebutkan diatas dan analisa traffic.&lt;br /&gt;&lt;br /&gt;Khusus untuk analisa traffic tidaklah bijaksana untuk menganalisa semua taffic data secara paket pada lapisan 3 dan 4 (network layer dan transport layer)  secara terus menerus karena akan mengganggu fungsi dan kenyamanan dari layanan Internet itu sendiri, adapun yang dapat dilakukan adalah analisa paket secara langsung pada saat insident keamanan terjadi atau biasa disebut sniffing. analoginya adalah jika tiap hari semua kendaraan di jalan raya diperiksa stnk dan kesesuaiannya dengan nomor mesin dan nomor rangka dan sim pengendaranya maka yang ada adalah kemacetan di sepanjang jalan sehingga kenyamanan dan fungsi dari kendaraan itu menjadi tidak ada artinya lagi, yang lumrah terjadi adalah pada saat terjadi laporan kehilangan mobil atau kasus penculikan atau kasus-kasus pidana lainnya termasuk kasus teroris yang terjadi belum lama ini terjadi maka jajaran kepolisian melakukan razia di titik rawan terhadap kendaraan bermotor tersebut bukan?&lt;br /&gt;&lt;br /&gt;Kesimpulan:&lt;br /&gt;Untuk menciptakan layanan Internet yang aman, nyaman dan berfungsi sebagaimana mestinya diperlukan kerja sama semua pihak dan pemahaman yang benar terhadap aspek-aspek keamanan jaringan Internet tersebut baik secara teknis maupun non-teknis.&lt;br /&gt;&lt;br /&gt;masukan/saran dan pendapat dari berbagai pihak sangat diperlukan untuk mencapai visi tersebut.&lt;br /&gt;&lt;br /&gt;Wasalam&lt;br /&gt;Harijanto Pribadi&lt;br /&gt;Kabid. Internet Security APJII periode 2009 - 2012&lt;br /&gt;&lt;br /&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-3374729166498678588?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/3374729166498678588/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=3374729166498678588' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3374729166498678588'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3374729166498678588'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2009/07/isp-dan-keamanan-jaringan-internet.html' title='ISP dan Keamanan Jaringan Internet'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-5262706420230135702</id><published>2009-06-15T00:52:00.003+07:00</published><updated>2009-06-15T01:11:41.496+07:00</updated><title type='text'>Jailbreak and/or unlock your iPhone 2G with version 2.2.1</title><content type='html'>fuih ,  setelah baca sana baca sini akhirnya aku bisa men Jailbreak/Unlock iphone 2g ku dengan versi 2.2.1&lt;br /&gt;&lt;br /&gt;caranya aku baca di : &lt;a href="http://www.iphonedownloadblog.com/2008/11/23/unlock-your-iphone-2g-22-using-quickpwn/"&gt;http://www.iphonedownloadblog.com/2008/11/23/unlock-your-iphone-2g-22-using-quickpwn/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;langkah-langkahnya kurang lebih sbb:&lt;br /&gt;&lt;br /&gt;download file-file berikut:&lt;br /&gt;&lt;br /&gt;1. &lt;a href="http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5830.20090127.Mmni6/iPhone1,1_2.2.1_5H11_Restore.ipsw"&gt;http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5830.20090127.Mmni6/iPhone1,1_2.2.1_5H11_Restore.ipsw&lt;/a&gt;&lt;br /&gt;2. &lt;a href="http://torrents.thepiratebay.org/4689995/QuickPwn-225-2.zip.4689995.TPB.torrent"&gt;http://torrents.thepiratebay.org/4689995/QuickPwn-225-2.zip.4689995.TPB.torrent&lt;/a&gt;&lt;br /&gt;3. &lt;a href="http://iphonefreakz.com/firmware/BL-39.bin"&gt;http://iphonefreakz.com/firmware/BL-39.bin&lt;/a&gt;&lt;br /&gt;4. &lt;a href="http://iphonefreakz.com/firmware/BL-46.bin"&gt;http://iphonefreakz.com/firmware/BL-46.bin&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;langkah-langkahnya&lt;br /&gt;&lt;br /&gt;1. aktifkan itunes8 dan pasang kabel data+usb pc ke iphone&lt;br /&gt;2. jika iphone sudah terdeteksi di itunes8 maka akan muncul disamping kanan pada bagian devices, lalu klik devices tsb maka akan muncul pada tab summary tombol restore.&lt;br /&gt;3. tekan tombol shift + klik tombol restore maka kita dapat memilih firmware / file ipsw yang telah kita download (no.1) dan lakukan proses restore.&lt;br /&gt;4. tunggu sampai proses restore selesai, setelah selesai (ditandai dengan iphone yang mereboot dirinya sendiri) tutup aplikasi itunes8 tsb dan jangan lakukan apapun pada iphone.&lt;br /&gt;5. Jalankan QuickPwn.exe yang telah kita download (no.2) , oh ya downloadnya pake bittorrent ya.&lt;br /&gt;6. Biarkan sampai tombol biru pada QuickPwn aktif artinya iphone telah terdeteksi lalu klik tombol tsb.&lt;br /&gt;7. langkah selanjutnya adalah browse file ipsw / firmware yang sama yang tadi kita restore via itunes8 diatas (point no.3) lalu klik tombol biru lagi, jika firmware cocok akan ada tanda centrang hijau, ok klik lagi tombol biru.&lt;br /&gt;8. selanjutnya diminta untuk browse file no.3 dan no.4 yang merupakan bootloader yang dibutuhkan lalu klik tombol biru lagi.&lt;br /&gt;9. setelah itu biasanya ada konfirmasi untuk memastikan bahwa kabel data usb terpasang antara pc dan iphone, nah disini triknya pada saat keluar konfirmasi layar tsb coba untuk cabut dan pasang lagi kabel usb tsb di pc agar pc dipaksa mengidentifikasi device iphone tsb, kalau sudah terdengar bunyi ding-ding artinya usb terdektsi maka klik tombol biru&lt;br /&gt;10. selanjutnya iphone akan masuk dalam mode recovery jangan alihkan perhatian anda dari layar monitor dan ikuti perintah berikut:&lt;br /&gt;&lt;span style="font-style: italic;"&gt;You will be asked to hold down the Power button for 5 seconds. Then you will have to also hold down the Home button for 10 seconds without letting go of the Power button. At the end of 10 seconds you will need to release only the Power button.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;ok jika anda dengan benar mengikuti perintah diatas maka iphone akan masuk dalam proses Jailbrake / Unlock&lt;br /&gt;&lt;br /&gt;dan trala..... akhirnya iphone 2g ku sudah siap digunakan dengan firmware 2.2.1 jadi bisa install facebook application dan yahoo messenger di iphone sayang masih 2g tapi mayanlah :)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SjU9OagAiLI/AAAAAAAAAW8/qF2M9Ticlfc/s1600-h/iphone-2-2-1.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SjU9OagAiLI/AAAAAAAAAW8/qF2M9Ticlfc/s400/iphone-2-2-1.JPG" alt="" id="BLOGGER_PHOTO_ID_5347247450413369522" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-5262706420230135702?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/5262706420230135702/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=5262706420230135702' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5262706420230135702'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5262706420230135702'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2009/06/jailbreak-andor-unlock-your-iphone-2g.html' title='Jailbreak and/or unlock your iPhone 2G with version 2.2.1'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_nzWcXcVYSRs/SjU9OagAiLI/AAAAAAAAAW8/qF2M9Ticlfc/s72-c/iphone-2-2-1.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-5081820408542565496</id><published>2009-04-22T00:34:00.003+07:00</published><updated>2009-04-22T00:42:51.148+07:00</updated><title type='text'>Aktifkan bpdu-filter di switch Procurve</title><content type='html'>Sore ini lagi-lagi ada masalah dengan link DS3 ku :(&lt;br /&gt;anehnya setelah link normal dan kabel DS3 dikembalikan paket tetap tidak mau mengalir padahal di test pake notebook udah jalan....&lt;br /&gt;&lt;br /&gt;Ternyata masalahnya di HP Procurve bpdu-filter belum aku aktifkan&lt;br /&gt;apa itu BPDU bisa dibaca di&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Spanning_tree_protocol#Bridge_Protocol_Data_Units_.28BPDUs.29"&gt;http://en.wikipedia.org/wiki/Spanning_tree_protocol#Bridge_Protocol_Data_Units_.28BPDUs.29&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;sedangkan cara mengaktifkan bpdu-filter di HP Procurve bisa dibaca di:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://evilrouters.net/2009/03/11/bpdu-protection-on-hp-procurve-switches/"&gt;http://evilrouters.net/2009/03/11/bpdu-protection-on-hp-procurve-switches/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;semoga bermanfaat&lt;br /&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-5081820408542565496?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/5081820408542565496/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=5081820408542565496' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5081820408542565496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5081820408542565496'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2009/04/aktifkan-bpdu-filter-di-switch-procurve.html' title='Aktifkan bpdu-filter di switch Procurve'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-6054865502260076446</id><published>2009-03-26T12:56:00.002+07:00</published><updated>2009-03-26T13:02:56.099+07:00</updated><title type='text'>No more "overrun: No buffer space available"</title><content type='html'>Setelah berhari-hari mencari akhirnya ketemu juga jawabannya agar quagga di fedora 9 tidak muncul error "netlink-listen: overrun: No buffer space available"&lt;br /&gt;&lt;br /&gt;ternyata di fedora 9 configurasinya ada di /etc/sysconfig/quagga yang isinya:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-family: courier new;"&gt;#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;# Default: Bind all daemon vtys to the loopback(s) only&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;QCONFDIR="/etc/quagga"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;BGPD_OPTS="-A 127.0.0.1 -f ${QCONFDIR}/bgpd.conf"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;OSPF6D_OPTS="-A ::1 -f ${QCONFDIR}/ospf6d.conf"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;OSPFD_OPTS="-A 127.0.0.1 -f ${QCONFDIR}/ospfd.conf"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;RIPD_OPTS="-A 127.0.0.1 -f ${QCONFDIR}/ripd.conf"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;RIPNGD_OPTS="-A ::1 -f ${QCONFDIR}/ripngd.conf"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;#ZEBRA_OPTS="-A 127.0.0.1 -f ${QCONFDIR}/zebra.conf"&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: courier new; font-weight: bold;font-size:78%;" &gt;ZEBRA_OPTS="-A 127.0.0.1 --nl-bufsize 200000 -f ${QCONFDIR}/zebra.conf"&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;ISISD_OPTS="-A ::1 -f ${QCONFDIR}/isisd.conf"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;# Watchquagga configuration (please check timer values before using):&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;WATCH_OPTS=""&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;WATCH_DAEMONS="zebra bgpd ospfd ospf6d ripd ripngd"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;# To enable restarts, uncomment this line (but first be sure to edit&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;# the WATCH_DAEMONS line to reflect the daemons you are actually using):&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;#WATCH_OPTS="-Az -b_ -r/sbin/service_%s_restart -s/sbin/service_%s_start -k/sbin/service_%s_stop"&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;pada baris ZEBRA_OPTS rubah menjadi&lt;br /&gt;&lt;span style="font-family: courier new; font-weight: bold;font-size:78%;" &gt;&lt;br /&gt;ZEBRA_OPTS="-A 127.0.0.1 --nl-bufsize 200000 -f ${QCONFDIR}/zebra.conf"&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt; &lt;/span&gt;&lt;br /&gt;aslinya&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-family: courier new;"&gt;ZEBRA_OPTS="-A 127.0.0.1 -f ${QCONFDIR}/zebra.conf"&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;setelah /etc/sysconfig/quagga diedit lalu restart service zebra dan bgpd&lt;br /&gt;&lt;br /&gt;sumber:&lt;br /&gt;&lt;a href="http://lists.quagga.net/pipermail/quagga-users/2005-May/004524.html"&gt;http://lists.quagga.net/pipermail/quagga-users/2005-May/004524.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-6054865502260076446?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/6054865502260076446/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=6054865502260076446' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6054865502260076446'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6054865502260076446'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2009/03/no-more-overrun-no-buffer-space.html' title='No more &quot;overrun: No buffer space available&quot;'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-5354623549933614987</id><published>2009-03-20T16:05:00.004+07:00</published><updated>2009-03-25T18:41:06.434+07:00</updated><title type='text'>Solve Problem with nf_conntrack: table full, dropping packet</title><content type='html'>When i have the problem with "nf_conntrack: table full, dropping packet"&lt;br /&gt;the problem was solved after i read this article from: &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://paulroberts69.spaces.live.com/blog/cns!665BC38F152E1206!1645.entry &lt;br /&gt;&lt;br /&gt;nf_conntrack: table full, dropping packet.&lt;br /&gt;&lt;br /&gt;If you see this message "nf_conntrack: table full, dropping packet" in your syslog on a Linux box, it's likely that it's having comms problems. I saw this recently on a DNS server that looked like it was being attacked. The problem is that when this happens, normal DNS resolution is interrupted.&lt;br /&gt;&lt;br /&gt;I haven't found a decent solution yet, but it seems that if the system has lots of RAM then you can increase the nf_conntrack_max kernel parameter (my system is running iptables, which I assume the "netfilter" module has something to do with).&lt;br /&gt;&lt;br /&gt;On a 2.6 kernel, you can go to /proc/sys/net/netfilter and check some of the values. For instance, nf_conntrack_count shows you the current value while nf_conntrack_max is the maximum value that is set.&lt;br /&gt;&lt;br /&gt;You can just cat these values or use sysctl to view them:&lt;br /&gt;&lt;br /&gt;# sysctl net.netfilter.nf_conntrack_max&lt;br /&gt;net.netfilter.nf_conntrack_max = 65536&lt;br /&gt;&lt;br /&gt;# sysctl net.netfilter.nf_conntrack_count&lt;br /&gt;net.netfilter.nf_conntrack_count = 45033&lt;br /&gt;&lt;br /&gt;To change the value, use the -w switch (in this example I've doubled the value):&lt;br /&gt;&lt;br /&gt;# sysctl -w net.netfilter.nf_conntrack_max=131072&lt;br /&gt;&lt;br /&gt;I think that in order to make this permanent across reboots, you'll need to add this line to the bottom of /etc/sysctl.conf:&lt;br /&gt;&lt;br /&gt;net.netfilter.nf_conntrack_max=131072&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;another reference&lt;br /&gt;TCP Tuning Guide:&lt;br /&gt;&lt;a href="http://fasterdata.es.net/TCP-tuning/linux.html"&gt;&lt;br /&gt;http://fasterdata.es.net/TCP-tuning/linux.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-5354623549933614987?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/5354623549933614987/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=5354623549933614987' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5354623549933614987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5354623549933614987'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2009/03/problem-with-nfconntrack-table-full.html' title='Solve Problem with nf_conntrack: table full, dropping packet'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-2046304276770085162</id><published>2009-03-01T17:52:00.005+07:00</published><updated>2009-03-01T18:23:03.745+07:00</updated><title type='text'>Fail Over Layer 2 tanpa STP menggunakan script dan bridge</title><content type='html'>Seringkali kita membutuhkan link yang bisa fail-over di layer 2 tetapi tidak memungkinkan menggunakan STP maka cara demikian bisa menjadi pilihan.&lt;br /&gt;&lt;br /&gt;Skenario&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;br /&gt;                           |-[Link-1]-|eth1 comment "backhaul"|&lt;br /&gt;[Internet]-[R1 1.1.1.1/30]-|          [R2 1.1.1.2 Distribusi  ]-&gt;[To User]&lt;br /&gt;                           |-[Link-2]-|eth2 comment "backup"  |&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Keterangan:&lt;br /&gt;----------&lt;br /&gt;1. R2 Distribusi memiliki minimal dua interface untuk link ke R1, misal eth1 diberi comment="backhaul" dan eth2 diberi comment="backup", lalu eth1 dan eth2 tsb di jadikan satu bridge misal dengan nama bridge1 &lt;br /&gt;2. IP point to point R2 ke R1 di pasang di interface bridge1&lt;br /&gt;&lt;br /&gt;Contoh Scipt check_backhaul dan schedulernya bisa diimport dari script dibawah ini&lt;br /&gt;&lt;br /&gt;Script:&lt;br /&gt;------&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;# mar/01/2009 17:27:17 by RouterOS 3.13&lt;br /&gt;# software id = 9CS2-87N&lt;br /&gt;#&lt;br /&gt;/system script&lt;br /&gt;add name=check_backhaul policy=\&lt;br /&gt;    ftp,reboot,read,write,policy,test,winbox,password,sniff source="/interface\&lt;br /&gt;     disable [/interface find comment=\"backup\"]\r\&lt;br /&gt;    \n/interface enable [/interface find comment=\"backhaul\"]\r\&lt;br /&gt;    \n:log info \"Waiting 15s Backhaul Forward Packet\";\r\&lt;br /&gt;    \n:delay 15s;\r\&lt;br /&gt;    \n:if ( [/ping 1.1.1.1 count=1]=1) do={\r\&lt;br /&gt;    \n:log info \"Backhaul Up\"\r\&lt;br /&gt;    \n} else={\r\&lt;br /&gt;    \n:log info \"Backhaul Down\";\r\&lt;br /&gt;    \n\&lt;br /&gt;    \n/interface disable [/interface find comment=\"backhaul\"]\r\&lt;br /&gt;    \n/interface enable [/interface find comment=\"backup\"]\r\&lt;br /&gt;    \n:delay 15s;\r\&lt;br /&gt;    \n\&lt;br /&gt;    \n/tool e-mail send to=\"support@domain.anda\"  subject=([/system ide\&lt;br /&gt;    ntity get name] . \" Microwave Down \" . [/system clock get date]) body=\"\&lt;br /&gt;    Backup with Mikrotik!\";\&lt;br /&gt;    \n\&lt;br /&gt;    \n\&lt;br /&gt;    \n\&lt;br /&gt;    \n\&lt;br /&gt;    \n\&lt;br /&gt;    \n\&lt;br /&gt;    \n\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n}"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;# mar/01/2009 17:30:30 by RouterOS 3.13&lt;br /&gt;# software id = 9CS2-87N&lt;br /&gt;#&lt;br /&gt;/system scheduler&lt;br /&gt;add comment="" disabled=no interval=5m name=sched_check_backhaul on-event=\&lt;br /&gt;    check_backhaul start-date=jan/01/1970 start-time=00:00:00&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Keterangan:&lt;br /&gt;----------&lt;br /&gt;Setiap 5 menit sekali script check_backhaul dijalankan dengan mengenable interface dengan comment "backhaul" lalu melakukan ping ke 1.1.1.1 jika rto maka interface dengan comment "backhaul" akan di disable lalu meng-enable interface dengan comment "backup"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-2046304276770085162?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/2046304276770085162/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=2046304276770085162' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2046304276770085162'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2046304276770085162'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2009/03/fail-over-layer-2-tanpa-stp-menggunakan.html' title='Fail Over Layer 2 tanpa STP menggunakan script dan bridge'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-889307308346792808</id><published>2009-03-01T17:39:00.004+07:00</published><updated>2009-03-01T18:23:52.831+07:00</updated><title type='text'>Disable Redirect Proxy Jika Proxy RTO</title><content type='html'>Jika suatu saat proxy server down maka redirect ke proxy harus didisable&lt;br /&gt;berikut adalah contoh script agar per 5 menit sekali mikrotik melakukan ping ke proxy (dalam contoh ini proxy server menggunakan ip = 1.2.3.4) jika ip 1.2.3.4 tidak bisa diping maka script "check_proxy" akan mendisable semua redirect ke ip 1.2.3.4&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;# mar/01/2009 17:27:17 by RouterOS 3.13&lt;br /&gt;# software id = 9CS2-87N&lt;br /&gt;#&lt;br /&gt;/system script&lt;br /&gt;add name=check_proxy policy=\&lt;br /&gt;    ftp,reboot,read,write,policy,test,winbox,password,sniff source=":if ( [/pi\&lt;br /&gt;    ng 1.2.3.4 count=1]=1) do={\r\&lt;br /&gt;    \n:log info \"Proxy Up\";\r\&lt;br /&gt;    \n:foreach i in=[/ip firewall nat find action=\"dst-nat\" to-addresses=\"1\&lt;br /&gt;    .2.3.4\"] do={/ip firewall nat set \$i disable=no};\r\&lt;br /&gt;    \n} else={\r\&lt;br /&gt;    \n:log info \"Proxy Down\";\r\&lt;br /&gt;    \n:foreach i in=[/ip firewall nat find action=\"dst-nat\" to-addresses=\"1\&lt;br /&gt;    .2.3.4\"] do={/ip firewall nat set \$i disable=yes};\r\&lt;br /&gt;    \n/tool e-mail send to=\"support@domain.anda\"  subject=([/system ide\&lt;br /&gt;    ntity get name] . \" Proxy Down \" . [/system clock get date]) body=\"Prox\&lt;br /&gt;    y Redirect Disable\";\&lt;br /&gt;    \n\&lt;br /&gt;    \n\&lt;br /&gt;    \n\&lt;br /&gt;    \n\&lt;br /&gt;    \n\&lt;br /&gt;    \n\&lt;br /&gt;    \n\&lt;br /&gt;    \n\r\&lt;br /&gt;    \n}"&lt;br /&gt;&lt;br /&gt;# mar/01/2009 17:30:30 by RouterOS 3.13&lt;br /&gt;# software id = 9CS2-87N&lt;br /&gt;#&lt;br /&gt;/system scheduler&lt;br /&gt;add comment="" disabled=no interval=5m name=sched_check_proxy on-event=\&lt;br /&gt;    check_proxy start-date=jan/01/1970 start-time=00:00:00&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-889307308346792808?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/889307308346792808/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=889307308346792808' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/889307308346792808'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/889307308346792808'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2009/03/disable-redirect-proxy-jika-proxy-rto.html' title='Disable Redirect Proxy Jika Proxy RTO'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-1697073823345922971</id><published>2008-12-17T17:29:00.009+07:00</published><updated>2008-12-18T15:40:56.384+07:00</updated><title type='text'>Mengatasi Worm Worm:Win32/Conficker.A (MS OneCare), W32.Downadup (Symantec)  dengan Mikrotik</title><content type='html'>Huh...&lt;br /&gt;dua hari sudah aku dikerjain worm&lt;br /&gt;dimulai dari telepon Mr. Denis MIT Hotel Menara Peninsula Tgl 17 Des 2008 yang melaporkan jaringan hotel kena virus yang mengakses url http:// trafficconverter . biz  beliau minta url tersebut di blok disisi ISP Datautama.&lt;br /&gt;&lt;br /&gt;Ok langkah pertama lempar semua traffic 80 ke proxy squid lalu saya filter url tersebut, berhasil?&lt;br /&gt;ternyata tidak itu hanya sementara&lt;br /&gt;&lt;br /&gt;Hari ini Tanggal 18 Des 2008 dapat email dari Mas Priyo bahwa limiter international dua kali di reboot karena CPU Loadnya tinggi sekali mh..... ada apa ini? pasti flood wah ini serangan&lt;br /&gt;tapi sampe jam 14 lebih masih belum juga ditemukan siapa yang ngeflood semua normal2 saja di torch mh... kenapa  ya, belum lagi selesai Mas Firman Pasuruan nanyain RB433AH nya sudah di pasang belum di cyber :( , belum makan pula , ditambah email internal yang menjengkelkan pingin rasanya matiin handphone terus kabur ke S*A huehehehehe , ya uda makan dulu di warteg terdekat kantor, krismon nih cari minuman import aja kagak ade hiks.&lt;br /&gt;&lt;br /&gt;Ternyata memang makanan memberikan kekuatan baru dan ide-ide baru , ok baca lagi deh penjelasan tentang tingkah laku worm sialan itu di : &lt;a href="http://www.ca.com/securityadvisor/virusinfo/virus.aspx?id=75911"&gt;http://www.ca.com/securityadvisor/virusinfo/virus.aspx?id=75911&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;atau kalau mau referensi yang sudah berbahasa Indonesia bisa dibaca  di:&lt;br /&gt;&lt;a href="http://vaksin.com/2008/1208/conficker/conficker.htm"&gt;http://vaksin.com/2008/1208/conficker/conficker.htm&lt;/a&gt;&lt;br /&gt;thanks Pak Alfons atas artikelnya, padahal bos vaksin sudah menyampaikan ke saya adanya serangan virus ini hehehe tapi baru sadar kalau sudah kena getahnya hehehe.&lt;br /&gt;&lt;br /&gt;mh...&lt;br /&gt;ada ide "tuing"&lt;br /&gt;ok kalau mengandung loadadv . exe  dst-addressnya cemplungin aja ke address-list terus di drop di firewall chain forward ok mainkan&lt;br /&gt;&lt;br /&gt;berikut adalah screenshootnya&lt;br /&gt;&lt;br /&gt;1. buat mangle&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/SUjnq9JGZfI/AAAAAAAAAVk/Fy5G-g_C_LE/s1600-h/mangleloadadv.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/SUjnq9JGZfI/AAAAAAAAAVk/Fy5G-g_C_LE/s400/mangleloadadv.png" alt="" id="BLOGGER_PHOTO_ID_5280725288245159410" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;in interface adalah interface dalam yang menghadap ke jaringan kita&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SUjnrLW_iJI/AAAAAAAAAVs/l_sIxGi8CZg/s1600-h/mangleloadadv6.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SUjnrLW_iJI/AAAAAAAAAVs/l_sIxGi8CZg/s400/mangleloadadv6.png" alt="" id="BLOGGER_PHOTO_ID_5280725292061526162" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;isi content dengan " loadadv . exe " lihat gambar , di destination address-list isi ! ournetwork, maksudnya agar content tsb hanya di cek kalau destinationnya bukan address-list ournetwork.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SUjnrbFl_wI/AAAAAAAAAV0/p4GX_EKsSjY/s1600-h/mangleloadadv3.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SUjnrbFl_wI/AAAAAAAAAV0/p4GX_EKsSjY/s400/mangleloadadv3.png" alt="" id="BLOGGER_PHOTO_ID_5280725296283516674" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;kalau ada content " loadadv . exe " masukkin ke dst-address-list = worm-dst&lt;br /&gt;&lt;br /&gt;2. Buat firewall rule chain forward&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SUjnrpDlXoI/AAAAAAAAAV8/HRx5opf3gW0/s1600-h/firewallloadadv.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SUjnrpDlXoI/AAAAAAAAAV8/HRx5opf3gW0/s400/firewallloadadv.png" alt="" id="BLOGGER_PHOTO_ID_5280725300033183362" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/SUjnr79RpQI/AAAAAAAAAWE/1lysVONNufA/s1600-h/firewallloadadv2.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/SUjnr79RpQI/AAAAAAAAAWE/1lysVONNufA/s400/firewallloadadv2.png" alt="" id="BLOGGER_PHOTO_ID_5280725305106998530" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;dst-address-list pilih "worm-dst"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/SUjn86eNh5I/AAAAAAAAAWM/4d9sECMscpc/s1600-h/firewallloadadv3.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/SUjn86eNh5I/AAAAAAAAAWM/4d9sECMscpc/s400/firewallloadadv3.png" alt="" id="BLOGGER_PHOTO_ID_5280725596766046098" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;action drop&lt;br /&gt;lalu ok&lt;br /&gt;jangan lupa taro di paling atas ya&lt;br /&gt;&lt;br /&gt;dengan demikian maka kalau ada destination address yang ditangkap karena digunakan untuk mendownload file " loadadv . exe " maka akan didrop sehingga proses download file jahanam tersebut tidak dapat dilakukan.&lt;br /&gt;&lt;br /&gt;hasilnya:&lt;br /&gt;1. MRTG turun ke level 10-11Mbps&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/SUjn9lM2DNI/AAAAAAAAAWc/dxRf9Dc060c/s1600-h/hasilnya-mrtg.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/SUjn9lM2DNI/AAAAAAAAAWc/dxRf9Dc060c/s400/hasilnya-mrtg.png" alt="" id="BLOGGER_PHOTO_ID_5280725608235928786" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;2. di address-list terdapat ip2 yang digunakan untuk download loadadv . exe . tapi hati-hati, sistem mangle dengan content "loadadv . exe" ini juga cukup galak jadi kalau ada yang mengetikkan " loadadv . exe " dengan titik antara loadadv dan exe tanpa spasi pasti kena cekal juga destination addressnya hehehe makanya saya tulis " loadadv spasi . spasi exe " biar gak kecekal :)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/SUjn9MVwtmI/AAAAAAAAAWU/FD36f9Rq2ZE/s1600-h/hasilnya-address-list.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/SUjn9MVwtmI/AAAAAAAAAWU/FD36f9Rq2ZE/s400/hasilnya-address-list.png" alt="" id="BLOGGER_PHOTO_ID_5280725601562441314" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/SUjdOYfbBkI/AAAAAAAAAVc/qOWsBR3WjA4/s1600-h/hasilnya-address-list.png"&gt;&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-1697073823345922971?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/1697073823345922971/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=1697073823345922971' title='10 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/1697073823345922971'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/1697073823345922971'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/12/mengatasi-worm-wormwin32confickera-ms.html' title='Mengatasi Worm Worm:Win32/Conficker.A (MS OneCare), W32.Downadup (Symantec)  dengan Mikrotik'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_nzWcXcVYSRs/SUjnq9JGZfI/AAAAAAAAAVk/Fy5G-g_C_LE/s72-c/mangleloadadv.png' height='72' width='72'/><thr:total>10</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-3913263831023333746</id><published>2008-11-10T10:46:00.005+07:00</published><updated>2008-11-10T11:11:09.121+07:00</updated><title type='text'>Pemisahan Traffic ke IP Akamai Indosat</title><content type='html'>Sehubungan dengan adanya blok IP Akamai Indosat di advertise juga ke OpenIXP/NICE maka dalam implementasi &lt;a href="http://inetshoot.blogspot.com/2008/11/simple-queue-iix-dan-international.html"&gt;http://inetshoot.blogspot.com/2008/11/simple-queue-iix-dan-international.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;IP Blok Akamai tersebut harus di pisahkan dari traffic IIX , kenapa?&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Karena traffic yang menuju ke IP Akamai tersebut akan dianggap traffic IIX sehingga terjadi ketidak efetifan dalam melimit traffic ke situs2 sbb: yahoo, microsoft, msn, symantech dll yang beberapa objectnya tersedia di Akamai tersebut dianggap sebagai traffic IIX.&lt;/li&gt;&lt;li&gt;Dengan termarkingnya traffic menuju ke IP Akamai sebagai packet-iix maka queue terhadap packet-iix tersebut termasuk juga traffic menuju ke IP Akamai, yang jadi masalah Indosat mengadvertise IP Akamainya ke OpenIXP/NICE tetapi tidak mengizinkan object dari Akamai tersebut diambil (download) melalui OpenIXP/NICE , jadi outgoingnya saja (upload) melalui OpenIXP/NICE tapi incoming tetap lewat link International , nah ini yang jadi biang keroknya :(&lt;/li&gt;&lt;li&gt;Berdasarkan penjelasan di point 2, artinya bandwidth International akan terutilize tidak sesuai dengan keinginan kita karena traffic dari IP Akamai tidak terlimit sesuai dengan queue Internationalnya tetapi sesuai dengan queue IIX karena paket2 tersebut termarking sebagai packet-iix.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Oleh karena itu caranya menurut saya adalah sbb:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1. Buat dulu address-list "akamai-indosat" , untuk akamai dari telkom atau upstream lainnya yang punya akamai silahkan cari sendiri :)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;pre  style="font-family:times new roman;"&gt;&lt;span style="font-size:85%;"&gt;/ ip firewall address-list&lt;br /&gt;add list=akamai-indosat address=219.83.124.0/23 comment="" disabled=no&lt;br /&gt;add list=akamai-indosat address=124.195.0.0/17 comment="" disabled=no&lt;/span&gt;&lt;/pre&gt;&lt;span style="font-weight: bold;"&gt;2. Kemudian rubah manglenya menjadi sbb:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:times new roman;font-size:85%;"  &gt;/ ip firewall mangle&lt;br /&gt;add chain=prerouting action=mark-connection new-connection-mark=con-iix \&lt;br /&gt;passthrough=yes in-interface=!backhaul-to-cyber dst-address-list=nice \&lt;br /&gt;comment="con-iix" disabled=no&lt;br /&gt;add chain=prerouting action=mark-connection \&lt;br /&gt;new-connection-mark=con-akamai-indosat passthrough=yes \&lt;br /&gt;in-interface=!backhaul-to-cyber dst-address-list=akamai-indosat \&lt;br /&gt;comment="con-akamai-indosat" disabled=no&lt;br /&gt;add chain=prerouting action=mark-packet new-packet-mark=packet-iix \&lt;br /&gt;passthrough=no connection-mark=con-iix comment="packet-iix" disabled=no&lt;br /&gt;add chain=prerouting action=mark-packet new-packet-mark=packet-intl \&lt;br /&gt;passthrough=no comment="packet-intl" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;atau tambahkan saja rule tepat dibawah "con-iix" yang dapat dilihat pada screen shoot berikut:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SRex91YIvVI/AAAAAAAAAUE/LeOgKL4Y57Q/s1600-h/mangle-rule-akamai-advanced.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 158px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SRex91YIvVI/AAAAAAAAAUE/LeOgKL4Y57Q/s400/mangle-rule-akamai-advanced.JPG" alt="" id="BLOGGER_PHOTO_ID_5266873965091536210" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SRex-WATTII/AAAAAAAAAUM/pOL5MZMTmLM/s1600-h/mangle-rule-akamai-action.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 167px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SRex-WATTII/AAAAAAAAAUM/pOL5MZMTmLM/s400/mangle-rule-akamai-action.JPG" alt="" id="BLOGGER_PHOTO_ID_5266873973849934978" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Semoga rule yang saya buat ini benar :) . maklum belum pernah ikut training mikrotik, selama ini cuman baca2 dan percobaan sendiri.  Kadang saya senyum2 kalau dianggap sebagai master mikrotik hehehehe peace.&lt;br /&gt;&lt;br /&gt;Special Thanks untuk Mr. Ivan &lt;a href="http://www.innovatn.net/"&gt;http://www.innovatn.net/&lt;/a&gt; atas masukkannya perihal blok IP Akamai tersebut.&lt;br /&gt;&lt;br /&gt;Salam&lt;br /&gt;Harijanto Pribadi&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-3913263831023333746?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/3913263831023333746/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=3913263831023333746' title='4 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3913263831023333746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3913263831023333746'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/11/pemisahan-traffic-ke-ip-akamai-indosat.html' title='Pemisahan Traffic ke IP Akamai Indosat'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_nzWcXcVYSRs/SRex91YIvVI/AAAAAAAAAUE/LeOgKL4Y57Q/s72-c/mangle-rule-akamai-advanced.JPG' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-303088904397677218</id><published>2008-11-05T19:50:00.008+07:00</published><updated>2008-11-10T11:06:17.696+07:00</updated><title type='text'>Simple Queue IIX dan International dengan Satu Router</title><content type='html'>Sebelumnya luangkan waktu untuk baca blog bos baba berikut ini&lt;br /&gt;&lt;a href="http://baba.blogdetik.com/2008/11/05/ajakan-jangan-asal-copy-paste-apaan-tuwh/"&gt;http://baba.blogdetik.com/2008/11/05/ajakan-jangan-asal-copy-paste-apaan-tuwh/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Pada blog ini saya mencoba memberikan contoh bagaimana mengatur bandwidth iix/nice menggunakan pc router mikrotik menggunakan teknik mangle yang sebenarnya sudah sering dibahas di forum-forum maupun di blog-blog. Tulisan ini hanya sebagai tambahan saja untuk melengkapi blog / artikel yang ada terdahulu. Jadi artikel ini "ASLI" saya buat sendiri bukan "Copy Paste" hehehe. Jujur saya juga akhirnya ikut-ikutan copy paste blog / artikel orang, soalnya blog ini saya jadikan kumpulan catatan juga, tujuannya kalau saya lupa sesuatu tinggal cari di blog sendiri hehehe. Jadi mohon maaf jika di blog saya juga ada beberapa artikel dari blog orang lain yang saya copy paste , tapi pasti saya tulis linknya dibawah atau diatasnya. Tapi emang lebih baik kalau orang yang mau baca artikel aslinya di hantarkan ke URL aslinya , atau artikelnya di terjemahkan dulu katanya bos baba, tapi emang gue tukang translate dari jalan pramuka heheheh :)&lt;br /&gt;&lt;br /&gt;Tapi kalau teman-teman mau copy paste ya monggo sih asal ditulis asalnya dari mana gitu aja cukup kalau buat gue, tapi kalau buat orang bule gak cukup loh hehehe.&lt;br /&gt;&lt;br /&gt;Mari kita bahas permasalahan yang sebenarnya&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Skenario dari Simple Queue IIX dan International berikut ini adalah satu router dengan minimal dua Interface:&lt;/span&gt;&lt;br /&gt;1. Backhaul -&gt; yang mendapat IP Public dari ISP atau IP Point-to-Point biasanya sih /30 dari ISP&lt;br /&gt;2. Distribution -&gt; Interface yang menghadap ke pelanggan / user&lt;br /&gt;&lt;br /&gt;Dalam contoh ini saya tidak melakukan NAT karena IP yang di routing semuanya IP Public karena kebetulan saya punya ISP sendiri , masa ISP pake IP Private , kalau ISP itu punya ASN dan IP Public sendiri hehehe peace (FYI: saya cuman Direktor Operasional bukan pemilikinya tapi what ever lah emang gue pikirin)&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Gambaran Sederhananya:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;"&gt;[Internet IIX dan Intl]-[(Interface Backhaul) Mikrotik (Interface Distribution)]-[Router Kantor / Pelanggan]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Catatan:&lt;/span&gt;&lt;br /&gt;Karena di interface distribution saya banyak vlan untuk memisah-misahkan link pelanggan (idealnya mah satu pelanggan satu vlan biar lebih aman), maka dalam contoh ini&lt;br /&gt;&lt;br /&gt;in-interface=!backhaul-to-cbyer&lt;br /&gt;&lt;br /&gt;artinya interface inputnya adalah semua interface selain selain "backhaul-to-cyber"&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Skrip Manglenya&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;span style="font-size:85%;"&gt;# nov/05/2008 19:39:55 by RouterOS 2.9.50&lt;br /&gt;# software id = 9CS2-87N&lt;br /&gt;#&lt;br /&gt;/ ip firewall mangle&lt;br /&gt;add &lt;span style="font-weight: bold;"&gt;chain=prerouting&lt;/span&gt; action=mark-connection new-connection-mark=con-iix \&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;passthrough=yes&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;in-interface=!backhaul-to-cyber&lt;/span&gt; dst-address-list=nice \&lt;br /&gt;comment="con-iix" disabled=no&lt;br /&gt;add &lt;span style="font-weight: bold;"&gt;chain=prerouting&lt;/span&gt; action=mark-packet new-packet-mark=packet-iix \&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;passthrough=no&lt;/span&gt; connection-mark=con-iix comment="packet-iix" disabled=no&lt;br /&gt;add &lt;span style="font-weight: bold;"&gt;chain=prerouting&lt;/span&gt; action=mark-packet new-packet-mark=packet-intl \&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;passthrough=no&lt;/span&gt; comment="packet-intl" disabled=no &lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;Skrip diatas adalah hasil export dari Mikrotik v 2.9.50, perhatikan tulisan yang saya &lt;span style="font-weight: bold;"&gt;bold &lt;/span&gt;&lt;br /&gt;dari hasil percobaan yang paling bener itu adalah chain=prerouting karena kalau chain=forward nanti di queue-simplenya hanya Rx-Rate yang efektif sedangkan Tx-Rate nya tidak , tetapi kalau dengan chain "prerouting" Rx dan Tx Ratenya efektif, kalau mau lebih jelasnya baca aja referensi tentang iptables di link berikut misalnya:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://rootbox.or.id/tips/iptables.html"&gt;http://rootbox.or.id/tips/iptables.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;baca sendiri ya udah bahasa Indonesia tuh, Thanks to:&lt;br /&gt;&lt;span style="font-size:100%;"&gt;Lukman HDP/s3trum (lukman_hdp@yahoo.com)&lt;/span&gt;&lt;br /&gt;supaya gue gak di gugat lagi hehehe.&lt;br /&gt;&lt;br /&gt;Kemudian untuk bagian &lt;span style="font-weight: bold;"&gt;action=mark-connection new-connection-mark=con-iix,  passthrought=yes&lt;/span&gt; supaya setelah di marking new-connection-mark packetnya diteruskan ke rule dibawahnya lagi (ini sih menurut pengertian gue semoga aja bener)&lt;br /&gt;&lt;br /&gt;baru rule berikutnya &lt;span style="font-weight: bold;"&gt;action=mark-packet new-packet-mark=packet-iix, passthrought=no&lt;/span&gt; supaya setelah di marking new-packet-mark=packet-iix paket-paket tersebut tidak diteruskan ke rule selanjutnya. Dengan demikian kalau udah jadi paket-iix tidak usah di di marking lagi di paket-intl , ya kalau dimarking lagi jadi paket-intl semuanya jadi paket-intl donk bos :)&lt;br /&gt;&lt;br /&gt;jadi tujuannya passthrought=no itu menurut gue nih ya supaya paket2 itu gak usah di teruskan ke proses lebih lanjut dibawahnya semoga aja bener :)&lt;br /&gt;&lt;br /&gt;referensinya baca aja sendiri di:&lt;br /&gt;&lt;a href="http://www.mikrotik.com/testdocs/ros/2.9/ip/mangle.php"&gt;http://www.mikrotik.com/testdocs/ros/2.9/ip/mangle.php&lt;/a&gt;&lt;br /&gt;Thaks to Mikrotik Developer :)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Setelah di mangle selanjutnya set di Queue Simplenya&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;span style=";font-family:times new roman;font-size:85%;"  &gt;# nov/05/2008 19:44:39 by RouterOS 2.9.50&lt;br /&gt;# software id = 9CS2-87N&lt;br /&gt;#&lt;br /&gt;/ queue simple&lt;br /&gt;add name="JKT-OFFICE" target-addresses=203.89.24.71/32 dst-address=0.0.0.0/0 \&lt;br /&gt;interface=all parent=none direction=both priority=8 \&lt;br /&gt;queue=default-small/default-small limit-at=2000000/2000000 \&lt;br /&gt;max-limit=2000000/3000000 total-queue=default disabled=no&lt;br /&gt;add name="JKT-OFFICE-IIX" target-addresses=203.89.24.71/32 \&lt;br /&gt;dst-address=0.0.0.0/0 interface=all parent=JKT-OFFICE \&lt;br /&gt;packet-marks=packet-iix direction=both priority=8 \&lt;br /&gt;queue=default-small/default-small limit-at=0/0 max-limit=0/0 \&lt;br /&gt;total-queue=default-small disabled=no&lt;br /&gt;add name="JKT-OFFICE-INTL" target-addresses=203.89.24.71/32 \&lt;br /&gt;dst-address=0.0.0.0/0 interface=all parent=JKT-OFFICE \&lt;br /&gt;packet-marks=packet-intl direction=both priority=8 \&lt;br /&gt;queue=default-small/default-small limit-at=0/0 max-limit=0/0 \&lt;br /&gt;total-queue=default-small disabled=no&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;contoh skrip diatas juga adalah hasil export dari Mikrotik 2.9.50&lt;br /&gt;Jadi JKT-OFFICE-IIX dan JKT-OFFICE-INTL parent ke JKT-OFFICE&lt;br /&gt;JKT-OFFICE-IIX untuk memantau penggunaan IIX sedangkan JKT-OFFICE-INTL untuk memantau penggunaan International , kalau mau dilimit di child nya juga bisa kalau mau, hanya saja di contoh ini saya cuman mau mantau penggunaan antara IIX dan Internationalnya.&lt;br /&gt;target-address=203.89.24.71 adalah IP WAN Router Kantor / IP WAN Router Pelanggan.&lt;br /&gt;&lt;br /&gt;ini screen capturenya di winbox&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SRGitSHdPuI/AAAAAAAAATE/EAfX5HDbgL4/s1600-h/simple-queue-jkt-office.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 75px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SRGitSHdPuI/AAAAAAAAATE/EAfX5HDbgL4/s400/simple-queue-jkt-office.JPG" alt="" id="BLOGGER_PHOTO_ID_5265168338213748450" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Bisa dilihat bahwa JKT-OFFICE adalah gabungan antara traffic JKT-OFFICE-IIX dan JKT-OFFICE-INTL&lt;br /&gt;&lt;br /&gt;Dah beres!&lt;br /&gt;Tapi jangan lupa address-list=nice harus di import ya!&lt;br /&gt;&lt;br /&gt;nah supaya address-list=nice setiap pagi di update cara yang saya lakukan adalah sbb:&lt;br /&gt;(catatan ini beneran gue oprek sendiri gak nyontoh wong idenya dari buku ku sendiri kok:&lt;br /&gt;&lt;a href="http://inetshoot.blogspot.com/2008/08/buku-firewall-melindungi-jaringan-dari.html"&gt;http://inetshoot.blogspot.com/2008/08/buku-firewall-melindungi-jaringan-dari.html&lt;/a&gt; sekalian promosi buku ke tiga saya jadi jangan lupa sisihkan Rp. 19.500 untuk beli buku saya hehehe mayan buat ke SPA kalau dah kemeng sama Mikrotik)&lt;br /&gt;&lt;br /&gt;Nah caranya gini ni:&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Buat script "nice-address-list-downloader" yang isinya sbb: &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:times new roman;font-size:85%;"  &gt;#!/bin/sh&lt;br /&gt;lynx -dump -nolist http://ixp.mikrotik.co.id/download/nice.rsc &gt; /var/www/apf/nice.rsc&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;taro di mesin linux&lt;br /&gt;misal di  /var/www/apf/nice-address-list-downloader&lt;br /&gt;&lt;br /&gt;jangan lupa di chmod 755 supaya bisa eksekusi, hasil dari script tersebut adalah file nice.rsc yang berisi daftar prefix yang ada di NICE/IIX , keterangan lebih lanjut baca di:&lt;br /&gt;&lt;a href="http://www.mikrotik.co.id/artikel_lihat.php?id=23"&gt;http://www.mikrotik.co.id/artikel_lihat.php?id=23&lt;/a&gt;&lt;br /&gt;Thanks to Pak Valens Riadi dkk.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Buat lagi script "nice-address-list-update" yang isinya sbb:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:times new roman;font-size:85%;"  &gt;#!/bin/sh&lt;br /&gt;# Rubah http://localhost sesuai dengan URL server uploader Anda&lt;br /&gt;#&lt;br /&gt;lynx -dump http://localhost/apf/nice-ftp-uploader.php&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Nah script nice-ftp-uploader.php nya sbb:&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:times new roman;font-size:85%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SRGuoaBo87I/AAAAAAAAAT8/4VYBPwQcjEg/s1600-h/script-ftp-uploder.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 313px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SRGuoaBo87I/AAAAAAAAAT8/4VYBPwQcjEg/s400/script-ftp-uploder.JPG" alt="" id="BLOGGER_PHOTO_ID_5265181448577020850" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;catatan misal:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;$ftp_user_name="nice";&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;$ftp_user_pass="123456";&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;sesua&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;ikan dengan username dan password di mikrotiknya tar dijelasin dibawah ya sabar.&lt;br /&gt;nah file &lt;span style="font-weight: bold;"&gt;nice-ftp-uploader.php &lt;/span&gt;karena disitu ada informasi user dan password lebih baik dibuat chmod 640 , dan jangan lupa di buat chown root:www-data supaya user root dan group www-data (yang merupakan user apache) boleh baca tapi orang lain "NO ACCESS".&lt;br /&gt;&lt;br /&gt;masukkan IP mesin mikrotik yang mau diupload file nice.rsc di file:&lt;br /&gt;/var/www/apf/nice-target.list&lt;br /&gt;&lt;br /&gt;yang isinya misal:&lt;br /&gt;&lt;br /&gt;192.168.0.1&lt;br /&gt;&lt;br /&gt;jadi isinya cuman daftar ip mesin2 mikrotik yang mau diupload file nice.rsc tersebut&lt;br /&gt;&lt;br /&gt;Berikutnya buat user "nice" dengan password "123456" misalnya (jangan nekat pake password "123456" banyak brute force sekarang di IIX hehehe) di router mikrotiknya.&lt;br /&gt;&lt;br /&gt;untuk user nice tersebut baiknya dibuat group "nice" juga di mikrotiknya contohnya bisa dilihat di screen capture berikut:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/SRGofz4pnFI/AAAAAAAAATU/CIA7SgGerpk/s1600-h/group-nice-di-mikrotik.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 370px; height: 326px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/SRGofz4pnFI/AAAAAAAAATU/CIA7SgGerpk/s400/group-nice-di-mikrotik.JPG" alt="" id="BLOGGER_PHOTO_ID_5265174703830047826" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;terus buat user "nice" screen capturenya bisa dilihat sbb:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SRGofkIjnMI/AAAAAAAAATM/yVOmkY3kjFY/s1600-h/user-nice-di-mikrotik.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 392px; height: 365px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SRGofkIjnMI/AAAAAAAAATM/yVOmkY3kjFY/s400/user-nice-di-mikrotik.JPG" alt="" id="BLOGGER_PHOTO_ID_5265174699601796290" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;nah baiknya dibatasi "allowed address" dari IP Linux yang akan mengambil nice.rsc dan menguploadnya ke mikrotik tersebut.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;selanjutnya tinggal di jalankan saja script:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;/var/www/apf/nice-address-list-downloader&lt;br /&gt;/var/www/apf/nice-address-list-update&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;menggunakan crond, masukkan baris berikut ke /etc/crontab&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;00 6    * * * * root /var/www/apf/nice-address-list-downloader&lt;br /&gt;15 6    * * * * root /var/www/apf/nice-address-list-update&lt;br /&gt;&lt;br /&gt;lalu restart crond misal kalau pake debian&lt;br /&gt;&lt;br /&gt;/etc/init.d/cron restart&lt;br /&gt;&lt;br /&gt;kalau pake fedora&lt;br /&gt;&lt;br /&gt;service crond restart&lt;br /&gt;&lt;br /&gt;dengan demikian tiap jam 6.00 nice-address-list-downloader di jalankan menghasilnya nice.rsc&lt;br /&gt;dan tiap jam 6.15 nice-address-list-update dieksekusi untuk mengupload nice.rsc ke mesin-mesin mikrotik yang ip-nya tertera di nice-target.list , gampang kan jadi dengan demikian bisa update ke beberapa mesin mikrotik sekaligus , tapi ingat buat user "nice" dulu di tiap router mikrotiknya.&lt;br /&gt;&lt;br /&gt;ini daftar file-file yang harus ada di dalam satu directory, dan directory tersebut harus bisa diakses lewat http://localhost/apf/&lt;br /&gt;&lt;br /&gt;/var/www/apf# ls -l nice*&lt;br /&gt;-rwxr-xr-x 1 root root        97 2008-11-05 18:40 nice-address-list-downloader&lt;br /&gt;-rwxr-xr-x 1 root root       131 2008-11-05 18:42 nice-address-list-update&lt;br /&gt;-rw-r----- 1 root www-data   708 2008-11-05 19:21 nice-ftp-uploader.php&lt;br /&gt;-rw-r--r-- 1 root root     24986 2008-11-05 19:19 nice.rsc&lt;br /&gt;-rw-r--r-- 1 root root        37 2008-11-05 19:24 nice-target.list&lt;br /&gt;&lt;br /&gt;directory apf itu hanya contoh aja jadi silahken di taro dimana aja suka-suka.&lt;br /&gt;&lt;br /&gt;sudah selesai ? belum la yau&lt;br /&gt;&lt;br /&gt;selanjutnya perlu buat script "nice" di mikrotik yang isinya "/import nice.rsc;" dengan cara klik system-&gt;scripts&lt;br /&gt;ini contoh screen capturenya:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SRGof6KykHI/AAAAAAAAATc/LMkm4ZXxcpI/s1600-h/system-script-import-nice.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 385px; height: 400px;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SRGof6KykHI/AAAAAAAAATc/LMkm4ZXxcpI/s400/system-script-import-nice.JPG" alt="" id="BLOGGER_PHOTO_ID_5265174705516744818" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;berikutnya script tersebut dieksekusi secara periodik dengan scheduler, buat scheduler dengan cara klik system-&gt;scheduler , isinya lihat aja di screen shoot nya berikut ini:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/SRGogGukVNI/AAAAAAAAATk/YBT8wHvNBJc/s1600-h/system-sched-nice.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 288px;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/SRGogGukVNI/AAAAAAAAATk/YBT8wHvNBJc/s400/system-sched-nice.JPG" alt="" id="BLOGGER_PHOTO_ID_5265174708888032466" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Jadi setiap jam 7.00 script "nice" yang menjalankan "/import nice.rsc;" dieksekusi per hari&lt;br /&gt;&lt;br /&gt;dah beres , tapi jangan lupa coba di run dulu jalankan:&lt;br /&gt;&lt;br /&gt;1. /var/www/apf/nice-address-list-downloader -&gt; mesti menghasilkan file nice.rsc&lt;br /&gt;2. /var/www/apf/nice-address-list-update -&gt; mengupload file nice.rsc ke mikrotik&lt;br /&gt;3. jalankan script "nice" dari menu System-&gt;scrips , pilih nice lalu klik "Run Script"&lt;br /&gt;4. cek di /ip firewall address-list apakah "nice" sudah terimport dengan baik, contohnya bisa dilihat di screen capture berikut:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SRGr4XKJLCI/AAAAAAAAATs/Xx4EsXIjI0U/s1600-h/address-list-nice.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 278px;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SRGr4XKJLCI/AAAAAAAAATs/Xx4EsXIjI0U/s400/address-list-nice.JPG" alt="" id="BLOGGER_PHOTO_ID_5265178424150404130" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Done!&lt;br /&gt;Semoga bermanfaat dan gak ada yang complaint :)&lt;br /&gt;&lt;br /&gt;Salam&lt;br /&gt;Harijanto Pribadi&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-303088904397677218?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/303088904397677218/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=303088904397677218' title='3 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/303088904397677218'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/303088904397677218'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/11/simple-queue-iix-dan-international.html' title='Simple Queue IIX dan International dengan Satu Router'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_nzWcXcVYSRs/SRGitSHdPuI/AAAAAAAAATE/EAfX5HDbgL4/s72-c/simple-queue-jkt-office.JPG' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-655032884318519659</id><published>2008-10-28T16:27:00.001+07:00</published><updated>2008-10-28T16:27:50.285+07:00</updated><title type='text'>IPv6 di Router Cisco</title><content type='html'>&lt;div class="snap_preview"&gt;&lt;p&gt;Contoh Sederhana Configure IPv6 di Cisco..&lt;/p&gt;&lt;p&gt;&lt;a href="http://oprekan.wordpress.com/2007/09/26/contoh-sederhana-configure-ipv6-di-cisco/"&gt;http://oprekan.wordpress.com/2007/09/26/contoh-sederhana-configure-ipv6-di-cisco/&lt;/a&gt;&lt;br /&gt;&lt;/p&gt; &lt;p&gt;Kemampuan Router Cisco untuk bisa mendukung operasional IPv6 salah satunya versi IOS yang lebih baru dan umumnya sudah stable pada versi IOS 12.2 keatas, serta module supervisor engine (SUP) untuk cisco 6500 &amp;amp; 7600 untuk support ipv6 (Thx to Fjr)&lt;/p&gt; &lt;address&gt;Referensi dari web www.cisco.com untuk IOS yang sudah support IPv6 adalah :&lt;/address&gt; &lt;address&gt;12.0S, 12.xT, 12.2S, 12.2 SB, 12.2SRA, 12.3, dan 12.4&lt;/address&gt; &lt;p&gt;Berikut list Seri Router yang sudah pernah dicoba IPv6 berikut IOS nya&lt;/p&gt; &lt;p&gt;- Router Cisco 7200     (IOS 12.2 T &amp;amp; 12.3)&lt;br /&gt;- Router Cisco 3660    (IOS 12.2 T)&lt;br /&gt;- Router Cisco 3640    (IOS 12.2 T)&lt;/p&gt; &lt;p&gt;Resources memory dan CPU juga perlu dipertimbangkan bila ingin mengembangkan dari Routing dasar ke Advance Routing (IGP &amp;amp; EGP).&lt;br /&gt;Konfigurasi dasar IPv6 di Router Cisco :&lt;/p&gt; &lt;p&gt;1. Contoh Konfigurasi IPv6 Address di Interface Fisik &amp;amp; Sub Interface&lt;/p&gt; &lt;p&gt;gw-ipv6#conf t&lt;br /&gt;gw-ipv6(config)# ipv6 unicast-routing&lt;br /&gt;! untuk mengaktifkan forwarding paket antar interface Router&lt;br /&gt;gw-ipv6(config)# ipv6 cef&lt;br /&gt;! untuk mengaktifkan fitur express forwarding paket IPv6&lt;br /&gt;gw-ipv6(config)#int ethernet 0&lt;br /&gt;gw-ipv6(config-if)#no shutdown&lt;br /&gt;gw-ipv6(config-if)#ipv6 enable&lt;br /&gt;! Untuk mengaktifkan IPv6 di interface&lt;br /&gt;gw-ipv6(config-if)#ipv6 address 2404:177:0253::1/123&lt;br /&gt;gw-ipv6(config-if)#^Z&lt;/p&gt; &lt;p&gt;gw-ipv6#sh run int ethernet 0&lt;br /&gt;! untuk menampilkan konfigurasi khusus Ethernet 0 saja&lt;/p&gt; &lt;p&gt;Building configuration…&lt;br /&gt;!&lt;br /&gt;Current configuration : 189 bytes&lt;br /&gt;!&lt;br /&gt;interface Ethernet3/0&lt;br /&gt;no ip address&lt;br /&gt;ipv6 enable&lt;br /&gt;ipv6 address 2404:177:253::1/123&lt;br /&gt;end&lt;/p&gt; &lt;p&gt;gw-ipv6#wr&lt;br /&gt;! untuk menyimpan konfigurasi di NVRAM&lt;/p&gt; &lt;p&gt;2. Contoh Konfigurasi IPv6 Address di Interface Virtual (Tunnel)&lt;/p&gt; &lt;p&gt;gw-ipv6#conf t&lt;br /&gt;gw-ipv6(config)#int tunnel 100&lt;br /&gt;gw-ipv6(config-if)#ipv6 enable&lt;br /&gt;gw-ipv6(config-if)#ipv6 address 2404:177:A::1/126&lt;br /&gt;gw-ipv6(config-if)#tunnel source ipv4 address/nama interface&lt;br /&gt;! Tunnel Source merupakan ipv4 address disisi router ini / nama interfacenya&lt;br /&gt;gw-ipv6(config-if)#tunnel destin&lt;br /&gt;ation ipv4address&lt;br /&gt;! Tunnel Destination  merupakan ipv4 address disisi router lawan yang akan kita bangun tunnel.&lt;br /&gt;! IPv4 tunnel source disisi pertama merupakan IPv4 tunnel destination di router kedua.&lt;br /&gt;! Demikian juga sebaliknya.&lt;br /&gt;gw-ipv6(config-if)#tunnel mode ipv6ip&lt;br /&gt;! ipv6ip merupakan mode tunnel IPv6 langsung (direct).&lt;/p&gt; &lt;p&gt;3. Contoh Konfigurasi Routing Static IPv6&lt;/p&gt; &lt;p&gt;gw-ipv6#conf t&lt;br /&gt;gw-ipv6(config)#ipv6 route 2404:175::/32 tunnel100&lt;br /&gt;! untuk me route paket ke prefix 2404:175::/32 lewat tunnel100&lt;br /&gt;! routing ke nama interface bisa diganti dengan ipv6 address tunnel di seberang&lt;/p&gt; &lt;p&gt;Wassalam,&lt;/p&gt; &lt;p&gt;a. rahman isnaini r. sutan [2404:170:ee02::10]&lt;/p&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-655032884318519659?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/655032884318519659/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=655032884318519659' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/655032884318519659'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/655032884318519659'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/10/ipv6-di-router-cisco.html' title='IPv6 di Router Cisco'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-521116251021393297</id><published>2008-10-28T16:25:00.000+07:00</published><updated>2008-10-28T16:26:43.065+07:00</updated><title type='text'>Pengenalan Internet Protokol versi 6 (IPv6)</title><content type='html'>&lt;pre&gt;Author: pangeran_biru&lt;br /&gt;Online @ www.echo.or.id :: http://ezine.echo.or.id&lt;br /&gt;&lt;a href="http://ezine.echo.or.id/ezine7/ez-r07-pangeran_biru-pengenalan%20IPv6.txt"&gt;&lt;br /&gt;http://ezine.echo.or.id/ezine7/ez-r07-pangeran_biru-pengenalan%20IPv6.txt&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;=== Pengenalan Internet Protokol versi 6 (IPv6) [primbon #1] ===&lt;br /&gt;                              &lt;br /&gt;&lt;br /&gt;Assalamualaikum wr.wb&lt;br /&gt;&lt;br /&gt;Awalnya artikel ini saya tulis tentang implementasi IPv6 pada sistem operasi linux,&lt;br /&gt;tetapi setelah saya tulis kok kepanjangan kalo hanya dijadikan satu primbon oleh&lt;br /&gt;karena itu saya memutuskan  menuliskannya kedalam 2 primbon (yaitu pengenalan IPv6 primbon #1,&lt;br /&gt;dan Implementasi IPv6 pada sistem operasi linux primbon #2).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Dalam jaringan komputer dikenal adanya suatu protokol yang mengatur bagaimana&lt;br /&gt;suatu node berkomunikasi dengan node lainnya didalam jaringan, protokol tersebut&lt;br /&gt;berfungsi sebagai bahasa agar satu komputer dapat berkomunikasi satu dengan yang lainnya.&lt;br /&gt;protokol yang merupakan standar de facto dalam jaringan internet yaitu protokol TCP/IP,&lt;br /&gt;sehingga dengan adanya TCP/IP komputer yang dengan berbagai jenis hardware dan berbagai&lt;br /&gt;jenis sistem operasi (linux,Windows X, X BSD, de el el) tetap dapat berkomunikasi.&lt;br /&gt;&lt;br /&gt;Internet Protocol (IP) merupakan inti dari protokol TCP/IP, seluruh data yang berasal dari&lt;br /&gt;layer-layer diatasnya harus diolah oleh protokol ini agar sampai ketujuan.versi IP yang saat&lt;br /&gt;ini telah dipakai secara meluas di internet adalah Internet Protocol versi 4 (IPv4).&lt;br /&gt;&lt;br /&gt;perkembangan internet yang sangat pesat sekarang ini menyebabkan alokasi alamat (IP addres)&lt;br /&gt;IPv4 semakin berkurang, hal ini menyebabkan harga IP address legal sangat mahal&lt;br /&gt;(kecuali maok!!!heu...heu...).Untuk mengatasi kekurangan alokasi IP address maka IETF&lt;br /&gt;mendesain suatu IP baru yang disebut Internet Protocol versi 6 (IPv6).&lt;br /&gt;&lt;br /&gt;pada IPv6, panjang alamat terdiri dari 128 bit sedangkan IPv4 hanya 32 bit. sehingga IPv6&lt;br /&gt;mampu menyediakan alamat sebanyak 2^128 [2 pangkat 128] atau 3X10^38 alamat, sedangkan IPv4&lt;br /&gt;hanya mampu menyediakan alamat sebanyak 2^32 atau 4,5X10^10 alamat.&lt;br /&gt;&lt;br /&gt;oke, tadi cuma intro aja! sekarang kita lanjutkan ke yang lebih dalam lagi.&lt;br /&gt;kemon baybeh!!!!!&lt;br /&gt;&lt;br /&gt;sekarang saya akan menjelaskan perbedaan yang lainnya antara IPv4 dengan IPv6.&lt;br /&gt;&lt;br /&gt;A.Struktur pengalamatan&lt;br /&gt;&lt;br /&gt;#IPv4&lt;br /&gt;&lt;br /&gt;pengalamatan IPv4 menggunakan 32 bit yang setiap bit dipisahkan dengan notasi titik.&lt;br /&gt;notasi pengalamatan IPv4 adalah sebagai berikut:&lt;br /&gt;&lt;br /&gt;   XXXXXXXX.XXXXXXXX.XXXXXXXX.XXXXXXXX&lt;br /&gt;&lt;br /&gt;dimana setiap simbol X digantikan dengan kombinasi bit 0 dan 1.misalnya:&lt;br /&gt;&lt;br /&gt;  10000010.11001000.01000000.00000001  (dalam angka biner)&lt;br /&gt;&lt;br /&gt;cara penulisan lain agar mudah diinget adalah dengan bentuk 4 desimal yang dipisahkan&lt;br /&gt;dengan titik. misal untuk alamat dengan kombinasi biner seperti diatas dapat dituliskan&lt;br /&gt;sebagai berikut:&lt;br /&gt;&lt;br /&gt;   130.200.127.254&lt;br /&gt;&lt;br /&gt;penulis sudah menganggap teman-teman semua dah bisa cara untuk mengkonversi dari bilangan&lt;br /&gt;biner ke desimal:). cos' kalo harus dijelasakan lagi nanti tambah ruwet nih artikel:p&lt;br /&gt;oke sekarang berlanjut ke struktur pengalamatan IPv6!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#IPv6&lt;br /&gt;&lt;br /&gt;Tidak seperti pada IPv4 yang menggunakan notasi alamat sejumlah 32 bit, IPv6 menggunakan&lt;br /&gt;128 bit. dah tau khan kenapa jadi 128 bit? yup biar alokasinya bisa lebih banyak.&lt;br /&gt;oke sekarang kita liat notasi alamat IPv6 adalah sebagai berikut:&lt;br /&gt; &lt;br /&gt; X:X:X:X:X:X:X:X&lt;br /&gt;&lt;br /&gt;kalo dalam bentuk biner ditulis sebagai berikut:&lt;br /&gt;&lt;br /&gt;1111111001111000:0010001101000100:1011111001000001:1011110011011010:&lt;br /&gt;0100000101000101:0000000000000000:0000000000000000:0011101000000000&lt;br /&gt;&lt;br /&gt;(dua blok diatas sebenarnya nyambung tapi agar tidak memakan tempat maka ditulis kebawah)&lt;br /&gt;itu notasi alamat IPv6 kalo dalam bentuk biner hal ini sengaja saya tulis bukan untuk membuat&lt;br /&gt;pusing yang baca tetapi untuk menunjukkan betapa panjangnya alamat IPv6.&lt;br /&gt;silahkan bandingkan dengan panjangnya IPv4.&lt;br /&gt;&lt;br /&gt;nah! agar lebih mudah diinget setiap simbol X digantikan dengan kombinasi 4 bilangan&lt;br /&gt;heksadesimal dipisahkan dengan simbol titik dua [:]. untuk contoh diatas dapat ditulis sbb:&lt;br /&gt;&lt;br /&gt;FE78:2344:BE43:BCDA:4145:0:0:3A&lt;br /&gt;&lt;br /&gt;lebih enak diliatnya khan?nah sistem pengalamatan IPv6 dapat disederhanakan jika terdapat&lt;br /&gt;berturut-turut beberapa angka "0". contohnya untuk notasi seperti diatas dapat ditulis:&lt;br /&gt;&lt;br /&gt;FE78:2344:BE43:BCDA:4145:0:0:3A -------&gt; FE78:2344:BE43:BCDA:4145::3A&lt;br /&gt;&lt;br /&gt;contoh lagi:&lt;br /&gt;&lt;br /&gt;8088:0:0:0:0:0:4508:4545 --------&gt;8088::4508:4545&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;B.Sistem pengalamatan&lt;br /&gt;&lt;br /&gt;#IPv4&lt;br /&gt;&lt;br /&gt;Sistem pengalamatan IPv4 dibagi menjadi 5 kelas, berdasarkan jumlah host yang dapat dialokasikan&lt;br /&gt;yaitu:&lt;br /&gt;&lt;br /&gt;Kelas A : range 1-126&lt;br /&gt;Kelas B : range 128-191&lt;br /&gt;kelas C : range 192-223&lt;br /&gt;kelas D : range 224-247&lt;br /&gt;kelas E : range 248-255&lt;br /&gt;&lt;br /&gt;tapi yang lazim dipake hanya kelas A,B dan C sedangkan kelas D dipakai untuk keperluan alamat&lt;br /&gt;multicasting dan kelas E dipake untuk keperluan eksperimental.&lt;br /&gt;&lt;br /&gt;selain itu pada IPv4 dikenal istilah subnet mask yaitu angka biner 32 bit yang digunakan untuk&lt;br /&gt;membedakan network ID dan host ID, menunjukkan letak suatu host berada dalam satu jaringan&lt;br /&gt;atau lain jaringan.contohnya kaya gini:&lt;br /&gt;&lt;br /&gt;IP address: 164.10.2.1 dan 164.10.4.1 adalah berbeda jaringan jika menggunakan netmask&lt;br /&gt;255.255.254.0, tetapi akan jika netmasknya diganti menjadi 255.255.240.0 maka kedua&lt;br /&gt;IP address diatas adalah berbeda jaringan. paham belom? kalo belom paham gini caranya:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;164.10.2.1-------&gt;   10100100.00001010.00000010.00000001&lt;br /&gt;255.255.254.0----&gt;   11111111.11111111.11111110.00000000&lt;br /&gt;                    ____________________________________ XOR&lt;br /&gt;                    10100100.00001010.00000010.00000000--&gt;164.10.2.0&lt;br /&gt;dan&lt;br /&gt;164.10.4.1-------&gt;   10100100.00001010.00001000.00000001&lt;br /&gt;255.255.254.0----&gt;   11111111.11111111.11111110.00000000&lt;br /&gt;                    ____________________________________ XOR&lt;br /&gt;                    10100100.00001010.00001000.00000000--&gt;164.10.4.0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;operasi XOR caranya seperti pertambahan waktu SD, cuman lebih mudah, gampangnya gini kalo&lt;br /&gt;angka "1" jumlahnya genap hasilnya "1" kalo jumlah "1" ganjil hasilnya "0" (1+1=1, 1+0=0)&lt;br /&gt;(heu...heu...).&lt;br /&gt;&lt;br /&gt;terlihat hasil operasi XOR dua IP address dengan netmask yang sama hasilnya beda berarti&lt;br /&gt;kedua IP address tersebut berbeda jaringan. untuk contoh berikutnya yang menggunakan&lt;br /&gt;netmask 255.255.240.0 silahkan coba sendiri.&lt;br /&gt;                                                         &lt;br /&gt;#IPv6&lt;br /&gt;&lt;br /&gt;pada IPv6 tidak dikenal istilah pengkelasan, hanya IPv6 menyediakan 3 jenis pengalamatan&lt;br /&gt;yaitu: Unicast, Anycast dan Multicast. alamat unicast yaitu alamat yang menunjuk pada sebuah&lt;br /&gt;alamat antarmuka atau host, digunakan untuk komunikasi satu lawan satu. pada alamat unicast&lt;br /&gt;dibagi 3 jenis lagi yaitu: alamat link local, alamat site local dan alamat global.&lt;br /&gt;alamat link local adalah alamat yang digunakan di dalam satu link yaitu jaringan local yang&lt;br /&gt;saling tersambung dalam satu level. sedangkan alamat Site local setara dengan alamat privat,&lt;br /&gt;yang dipakai terbatas di dalam satu site sehingga terbatas penggunaannya hanya didalam satu&lt;br /&gt;site sehingga tidak dapat digunakan untuk mengirimkan alamat diluar site ini.&lt;br /&gt;alamat global adalah alamat yang dipakai misalnya untuk Internet Service Provider.&lt;br /&gt;&lt;br /&gt;alamat anycast adalah alamat yang menunjukkan beberapa interface (biasanya node yang berbeda).&lt;br /&gt;paket yang dikirimkan ke alamat ini akan dikirimkan ke salahsatu alamat antarmuka yang paling&lt;br /&gt;dekat dengan router. alamat anycast tidak mempunyai alokasi khusus, cos' jika beberapa&lt;br /&gt;node/interface diberikan prefix yang sama maka alamat tersebut sudah merupakan alamat anycast.&lt;br /&gt;&lt;br /&gt;alamat multicast adalah alamat yang menunjukkan beberapa interface (biasanya untuk node yang&lt;br /&gt;berbeda). Paket yang dikirimkan ke alamat ini maka akan dikirimkan ke semua interface yang&lt;br /&gt;ditunjukkan oleh alamat ini. alamat multicast ini didesain untuk menggantikan alamat broadcast&lt;br /&gt;pada IPv4 yang banyak mengkonsumsi bandwidth.&lt;br /&gt;              &lt;br /&gt;  Tabel alokasi alamat IPv6&lt;br /&gt;__________________________________________________________________&lt;br /&gt;|alokasi        | binary prefix            |contoh (16 bit pertama |         &lt;br /&gt;|_______________|__________________________|_______________________|&lt;br /&gt;|Global unicast |001      |  2XXX ato 3XXX        |&lt;br /&gt;|link local     |1111 1110 10              |  FE8X  -   FEBx       |&lt;br /&gt;|site local     |1111 1110 11     |  FECx  -   FEFx       |&lt;br /&gt;|Multicast      |1111 1111         |  FFxx     |&lt;br /&gt;|_______________|__________________________|_______________________|&lt;br /&gt;&lt;br /&gt;selain alamat diatas tadi ada juga jenis pengalamatan lainnya diantaranya:&lt;br /&gt;&lt;br /&gt;#IPv4-compatible IPv6 address biasanya alamat ini digunakan untuk mekanisme transisi Tunelling&lt;br /&gt;format alamatnya kaya gini:&lt;br /&gt;   &lt;br /&gt; 80 bits     |16    |      32 bits        |&lt;br /&gt;+-------------------+------+---------------------+&lt;br /&gt;|0000...........0000| 0000 |     IPv4 address    |&lt;br /&gt;+-------------------+------+---------------------+&lt;br /&gt;&lt;br /&gt;contohnya:&lt;br /&gt;   = 0:0:0:0:0:0:192.168.30.1&lt;br /&gt;   = ::192.168.30.1&lt;br /&gt;         = ::C0A8:1E01&lt;br /&gt;jadi 0:0:0:0:0:0:192.168.30.1=::c0AB:1E01 kok bisa dapat dari mane? gini caranya:&lt;br /&gt;buat dulu alamat 0:0:0:0:0:0:192.168.30.1 jadi biner&lt;br /&gt;::11000000.10101000.00011110.00000001 kemudian kelompokkan menjadi masing 16 bit&lt;br /&gt;::[1100.0000.1010.1000]:[0001.1110.0000.0001] diubah ke heksa desimal---&gt;::C0A8:1E01&lt;br /&gt;tanda "." (titik) didalam kurung untuk mempermudah konversi dari biner ke heksadesimal.&lt;br /&gt;sudah pahamkan? masih belum juga silahkan ulangi lagi dengan perlahan:p&lt;br /&gt;&lt;br /&gt;#IPv4-mapped IPv6 address biasanya digunakan untuk mekanisme transisi ISATAP.&lt;br /&gt;   &lt;br /&gt; 80 bits     |16    |      32 bits        |&lt;br /&gt;+-------------------+------+---------------------+&lt;br /&gt;|0000...........0000| FFFF |     IPv4 address    |&lt;br /&gt;+-------------------+------+---------------------+&lt;br /&gt;&lt;br /&gt;contohnya:  =::FFFF:192.168.1.2&lt;br /&gt;&lt;br /&gt;#IPv6 over ethernet digunakan untuk stateless autoconfiguration (pemberian alamat IPv6&lt;br /&gt;secara otomatis tanpa memerlukan server yang memberi alokasi IP address, mirip DHCP&lt;br /&gt;cuman tanpa server).&lt;br /&gt;contoh:&lt;br /&gt; 00:90:27:17:FC:0F&lt;br /&gt;               /\&lt;br /&gt;              /  \&lt;br /&gt;             FF  FE&lt;br /&gt;maka alamatnya menjadi 00:90:27:FF:FE:17:FC:0F kemudian diblok pertama bit ketujuh diinvers&lt;br /&gt;               00:90:27:17:FC:0F&lt;br /&gt;            |              &lt;br /&gt;                |&lt;br /&gt;         \|/&lt;br /&gt;              000000[0]0 bit yang dikurungi diinvers dari 0---&gt;1&lt;br /&gt;maka sekarang menjadi 02:90:27:FF:FE:17:FC:0F  alamat tersebut adalah alamat IPv6 over ethernet.&lt;br /&gt;&lt;br /&gt;oke mungkin segitu dulu tulisan dari saya, sebagai dasar teori untuk IPv6 (ceile!!!!),&lt;br /&gt;sebenarnya masih banyak yang ingin saya tulis cuman nanti terlalu panjang nih artikel takut&lt;br /&gt;ga ada yang baca. (heu.....heu...)&lt;br /&gt;&lt;br /&gt;semoga tetap dalam semangat untuk berbagi!!!!!&lt;br /&gt;Wassalam&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;kritik&amp;amp;saran silahkan kirim ke pan6eran_biru[at]yahoo.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Referensi:-TCP/IP standard,desain dan Implementasi, Onno W.purbo dkk&lt;br /&gt;   -Teori dan Implementasi IPv6 Protokol Internet Masa depan, Riza Taufan&lt;br /&gt;         -Interkoneksi IPv6 dengan menggunakan DSTM, Dody Setiawan&lt;br /&gt;   -Implementasi dan Analisa Teredo untuk interkoneksi jaringan IPv6/IPv4 dengan jaringan&lt;br /&gt;          IPv6 yang melalui IPv4 NAT (Network Address Translation), Wahidi Somad&lt;br /&gt;   -Introduction &amp;amp; Deployment IPv6 Tutorial,Che Rohani Ishak dkk&lt;br /&gt;  &lt;br /&gt;&lt;br /&gt;[###############################################################################################]&lt;br /&gt;&lt;br /&gt;           thengkiyu tu :-aLL echo|staff,&lt;br /&gt;&lt;br /&gt;           GreetZ to    :-temen-temen seperjuangan: |blo`on|,gorila,dragon CCNA, mbah harjo,ksj,&lt;br /&gt;                          st3alth (adeku yang baik!), all dech!!!         &lt;br /&gt;                         -barudak #sunda (belegug [salam blemoh!!!],Hendi, al-mubarak,all dech!)&lt;br /&gt;                         -special Kanggo: Neng Wiharyanti Purnama Dewi(kapan maen ke kost lagi?)&lt;br /&gt;     -buat orang-orang yang pernah mencaci gw, mentertawakan gw,&lt;br /&gt;                          kalian adalah pemacu semangatku heu....heu...&lt;br /&gt;                          &lt;br /&gt;[###############################################################################################]                                           &lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-521116251021393297?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/521116251021393297/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=521116251021393297' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/521116251021393297'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/521116251021393297'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/10/pengenalan-internet-protokol-versi-6.html' title='Pengenalan Internet Protokol versi 6 (IPv6)'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-4576356483715563046</id><published>2008-10-23T12:00:00.001+07:00</published><updated>2008-10-23T12:02:01.718+07:00</updated><title type='text'>Linux Advanced Routing Mini HOWTO</title><content type='html'>This page is a small HOWTO about the advanced linux routing...&lt;br /&gt;&lt;p&gt;&lt;br /&gt;First of all let me tell you where you can find the best source of information about  the advanced routing under Linux. Most of you probably know or heard about the  &lt;a href="http://www.lartc.org/" target="_blank"&gt;Linux Advanced Routing &amp;amp; Traffic Control&lt;/a&gt; site.  There you can see a very comprehensive source of knowledge  based not only on documentation but by easy to understand examples...&lt;br /&gt;&lt;/p&gt; &lt;p&gt;&lt;b&gt;Credits:&lt;/b&gt; &lt;a href="http://www.lartc.org/" target="_blank"&gt;Linux Advanced Routing &amp;amp; Traffic Control&lt;/a&gt;, Thea&lt;/p&gt; Ok, then...&lt;br /&gt;This page will show you how to set a linux box to use 2 different ISPs on the same time...&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-size: 12pt;"&gt;First example:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Goal: To route packets that came from 4 network to different ISPs&lt;br /&gt;&lt;br /&gt;Let's presume that you have two ISPs. In the following examples I'll use RDS and ASTRAL (two large ISPs from my country)&lt;br /&gt;For the ASCII art and lynx console browser fans I'll use this kind of chart: &lt;pre&gt;                                                                   ________&lt;br /&gt;                                          +-------------+        /&lt;br /&gt;                                          |    ISP 1    |       /&lt;br /&gt;                            +-------------+    (RDS)    +------+&lt;br /&gt;                            |             | gw 10.1.1.1 |     /&lt;br /&gt;                     +------+-------+     +-------------+    /&lt;br /&gt;+----------------+    |     eth1     |                       /&lt;br /&gt;|                |    |              |                      |&lt;br /&gt;| Local networks +----+ Linux router |                      |  Internet cloud&lt;br /&gt;|                |    |              |                      |&lt;br /&gt;+----------------+    |     eth2     |                       \&lt;br /&gt;                     +------+-------+     +-------------+    \&lt;br /&gt;                            |             |    ISP 2    |     \&lt;br /&gt;                            +-------------+  (ASTRAL)   +------+&lt;br /&gt;                                          | gw 10.8.8.1 |       \&lt;br /&gt;                                          +-------------+        \________&lt;br /&gt;&lt;/pre&gt; We will work only on Linux router box. From the root prompter do: &lt;pre class="gri"&gt;echo 1 RDS &gt;&gt; /etc/iproute2/rt_tables&lt;br /&gt;echo 2 ASTRAL &gt;&gt; /etc/iproute2/rt_tables&lt;br /&gt;&lt;/pre&gt; The /etc/iproute2/rt_table content after previous commands: &lt;pre class="gri"&gt;#&lt;br /&gt;# reserved values&lt;br /&gt;#&lt;br /&gt;255     local&lt;br /&gt;254     main&lt;br /&gt;253     default&lt;br /&gt;0       unspec&lt;br /&gt;#&lt;br /&gt;# local&lt;br /&gt;#&lt;br /&gt;#1      inr.ruhep&lt;br /&gt;1 RDS&lt;br /&gt;2 ASTRAL&lt;br /&gt;&lt;/pre&gt;  Now we have three routing tables as follows: RDS table, ASTRAL table and the main table...&lt;br /&gt;Let's fill up every table with the defaults routes:&lt;br /&gt;&lt;br /&gt; The next step is to have some routing rules and routes:&lt;br /&gt;&lt;br /&gt; For the RDS table: &lt;pre class="gri"&gt;ip route add default via 10.1.1.1 dev eth1 table RDS&lt;br /&gt;ip rule add from 10.11.11.0/24 table RDS&lt;br /&gt;ip rule add from 10.12.12.0/24 table RDS&lt;br /&gt;&lt;/pre&gt;  For the ASTRAL table: &lt;pre class="gri"&gt;ip route add default via 10.8.8.1 dev eth2 table ASTRAL&lt;br /&gt;ip rule add from 10.22.22.0/24 table ASTRAL&lt;br /&gt;ip rule add from 10.33.33.0/24 table ASTRAL&lt;br /&gt;&lt;/pre&gt;  To see the routing tables: &lt;pre class="gri"&gt;ip route show table ASTRAL&lt;br /&gt;ip route show table RDS&lt;br /&gt;ip route show table main  # it's the same as "route -n" but in different format...&lt;br /&gt;&lt;/pre&gt;  To see the routing tables: &lt;pre class="gri"&gt;ip rule show   # all the rule list&lt;br /&gt;ip rule show | grep ASTRAL # only for ASRAL&lt;br /&gt;ip rule show | grep RDS  # only for RDS&lt;br /&gt;&lt;/pre&gt;  Let me explain the above rules.&lt;br /&gt;The packets that came from the 10.11.11.0/24 and 10.12.12.0/24 networks will go to the RDS  routing table and then (because we have a default route) will be passed to the RDS gateway.  And similar, the packets that came from the 10.22.22.0/24 and 10.33.33.0/24 network will go to  the ASTRAL gateway...&lt;br /&gt;What is happening with the packets that came from other networks that are not shown in the  above rules? Well, they just simply go to main routing table and follow the routing rules  that reside there... If you want to block them to go to internet just delete the default  route from the main table... (of course, doing that your router can not longer go to interent).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;   &lt;b&gt;&lt;span style="font-size: 12pt;"&gt;Second example:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Goal: To route the packets having the destination port 22/tcp to the RDS and 80/tcp to the ASTRAL (no matter what network generates them).&lt;br /&gt;This example it is almost the same as the first one except that we will use iptables to mark the packets.&lt;br /&gt;&lt;br /&gt; Same chart... &lt;pre&gt;                                                                   ________&lt;br /&gt;                                          +-------------+        /&lt;br /&gt;                                          |    ISP 1    |       /&lt;br /&gt;                            +-------------+    (RDS)    +------+&lt;br /&gt;                            |             | gw 10.1.1.1 |     /&lt;br /&gt;                     +------+-------+     +-------------+    /&lt;br /&gt;+----------------+    |     eth1     |                       /&lt;br /&gt;|                |    |              |                      |&lt;br /&gt;| Local networks +----+ Linux router |                      |  Internet cloud&lt;br /&gt;|                |    |              |                      |&lt;br /&gt;+----------------+    |     eth2     |                       \&lt;br /&gt;                     +------+-------+     +-------------+    \&lt;br /&gt;                            |             |    ISP 2    |     \&lt;br /&gt;                            +-------------+  (ASTRAL)   +------+&lt;br /&gt;                                          | gw 10.8.8.1 |       \&lt;br /&gt;                                          +-------------+        \________&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;Same /etc/iproute2/rt_table content: &lt;pre class="gri"&gt;#&lt;br /&gt;# reserved values&lt;br /&gt;#&lt;br /&gt;255     local&lt;br /&gt;254     main&lt;br /&gt;253     default&lt;br /&gt;0       unspec&lt;br /&gt;#&lt;br /&gt;# local&lt;br /&gt;#&lt;br /&gt;#1      inr.ruhep&lt;br /&gt;1 RDS&lt;br /&gt;2 ASTRAL&lt;br /&gt;&lt;/pre&gt; Before you start check your iptables configuration. I strongly recommend to read  about iptables if you are unsure about what you will doing next.&lt;br /&gt;For more documentation go to &lt;a href="http://www.iptables.org/" target="_blank"&gt;iptables home page&lt;/a&gt; or you  can download a good documentation from this site (&lt;a href="http://www.linuxhorizon.ro/"&gt;Security &amp;amp; Privacy Section&lt;/a&gt;) or directly from &lt;a href="http://www.linuxhorizon.ro/files/iptables-tutorial.pdf.zip"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt; To mark the packets that have the 22 and 80 as destination port we will use the MANGLE table... &lt;pre class="gri"&gt;iptables -A PREROUTING -t mangle -i eth0 -p tcp --dport 22 -j MARK --set-mark 1&lt;br /&gt;iptables -A PREROUTING -t mangle -i eth0 -p tcp --dprot 80 -j MARK --set-mark 2&lt;br /&gt;&lt;/pre&gt;  For the RDS table: &lt;pre class="gri"&gt;ip route add default via 10.1.1.1 dev eth1 table RDS # the same like in the first example&lt;br /&gt;&lt;/pre&gt;  For the ASTRAL table: &lt;pre class="gri"&gt;ip route add default via 10.8.8.1 dev eth2 table ASTRAL # the same like in the first example&lt;br /&gt;&lt;/pre&gt;  The next step is to have some routing rules based by the marked packets:&lt;br /&gt;&lt;br /&gt; For the RDS: &lt;pre class="gri"&gt;ip rule add from all fwmark 1 table RDS&lt;br /&gt;&lt;/pre&gt;  For the ASTRAL: &lt;pre class="gri"&gt;ip rule add from all fwmark 2 table ASTRAL&lt;br /&gt;&lt;/pre&gt;  You can use the same commands to see the routing tables and rule lists as in the first example.&lt;br /&gt; Now you have a routing solution based by the destination port...&lt;br /&gt;&lt;br /&gt; &lt;center&gt; If you need additional infos or Q&amp;amp;A please go to &lt;a href="http://www.linuxhorizon.ro/contact.html" target="_blank"&gt;Contact Page&lt;/a&gt; for our e-mail addresses...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.linuxhorizon.ro/iproute2.html"&gt;http://www.linuxhorizon.ro/iproute2.html&lt;/a&gt;&lt;br /&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-4576356483715563046?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/4576356483715563046/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=4576356483715563046' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/4576356483715563046'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/4576356483715563046'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/10/linux-advanced-routing-mini-howto.html' title='Linux Advanced Routing Mini HOWTO'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-2003309910322187749</id><published>2008-10-22T19:44:00.003+07:00</published><updated>2008-11-05T12:02:21.014+07:00</updated><title type='text'>Mikrotik policy routing implementation example</title><content type='html'>&lt;h2&gt;Thanks to &lt;/h2&gt;Butch Evans&lt;br /&gt;&lt;a href="http://blog.butchevans.com/"&gt;http://blog.butchevans.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;&lt;a href="http://blog.butchevans.com/2008/09/mikrotik-policy-routing-implementation-example/" rel="bookmark" title="Permanent Link: Mikrotik policy routing implementation example"&gt;Mikrotik policy routing implementation example&lt;/a&gt;&lt;/h2&gt;          &lt;div style="margin: 0pt 0pt 0pt 10px; float: right; width: 42px; padding-right: 10px;"&gt;&lt;script type="text/javascript"&gt; &lt;!-- digg_url = 'http://blog.butchevans.com/2008/09/mikrotik-policy-routing-implementation-example/'; digg_bgcolor = '#FFFFFF'; digg_skin = ''; digg_window = 'new'; digg_title = 'Mikrotik policy routing implementation example'; digg_bodytext = 'In &amp;#8220;normal&amp;#8221; routing, you have a set of routes that tell the router about how to reach certain networks.  Policy routing is a way to do the...'; digg_media = 'news'; digg_topic = ''; //--&gt; &lt;/script&gt; &lt;script src="http://digg.com/tools/diggthis.js" type="text/javascript"&gt;&lt;/script&gt;&lt;iframe src="http://digg.com/tools/diggthis.php?u=http%3A//blog.butchevans.com/2008/09/mikrotik-policy-routing-implementation-example/&amp;amp;t=Mikrotik%20policy%20routing%20implementation%20example&amp;amp;w=new&amp;amp;b=In%20%26%238220%3Bnormal%26%238221%3B%20routing%2C%20you%20have%20a%20set%20of%20routes%20that%20tell%20the%20router%20about%20how%20to%20reach%20certain%20networks.%A0%20Policy%20routing%20is%20a%20way%20to%20do%20the...&amp;amp;m=news&amp;amp;c=&amp;amp;k=%23FFFFFF" scrolling="no" width="52" frameborder="0" height="80"&gt;&lt;/iframe&gt; &lt;/div&gt; &lt;p&gt;In “normal” routing, you have a set of routes that tell the router about how to reach certain networks.  Policy routing is a way to do the same thing, but have different “paths” or routes for various types of traffic.  In this article, we will explore the requirements for setting up policy routing and explain some of the concepts involved.&lt;/p&gt; &lt;p&gt;&lt;span id="more-50"&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;Policy routing is implemented in 3 parts. The first part is to define the routes and which policies will use those routes. The second part is the routing rules, which will define how the policies apply to certain traffic. The third is to define the actual policies. We’ll look at each of these individually.&lt;/p&gt; &lt;p&gt;The network below is the one we will use for this example.&lt;/p&gt; &lt;p style="text-align: center;"&gt;&lt;img class="aligncenter size-full wp-image-51" title="policy" src="http://blog.butchevans.com/wp-content/uploads/2008/09/policy.jpg" alt="" width="500" height="177" /&gt;&lt;/p&gt; &lt;p&gt;We will assume that you already have the IP addresses set up on your router.&lt;/p&gt; &lt;p&gt;Read more:&lt;/p&gt;&lt;a href="http://blog.butchevans.com/2008/09/mikrotik-policy-routing-implementation-example/"&gt;http://blog.butchevans.com/2008/09/mikrotik-policy-routing-implementation-example/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-2003309910322187749?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/2003309910322187749/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=2003309910322187749' title='3 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2003309910322187749'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2003309910322187749'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/10/mikrotik-policy-routing-implementation.html' title='Mikrotik policy routing implementation example'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-998595976396199432</id><published>2008-10-09T12:45:00.001+07:00</published><updated>2008-10-09T12:45:51.639+07:00</updated><title type='text'>Optimasi Apache2</title><content type='html'>&lt;h3 class="post-title"&gt; &lt;a href="http://frankmash.blogspot.com/2005/11/optimize-apache-20-apache2-on-rhel.html" title="permanent link"&gt;  Optimize Apache 2.0  (Apache2) on RHEL - Track users using Clickstream&lt;/a&gt;     &lt;/h3&gt;                      &lt;p&gt;           &lt;/p&gt;&lt;p&gt;First, make a backup and then modify /etc/httpd.conf and change settings as follows&lt;/p&gt;&lt;br /&gt;&lt;p class="code"&gt;&lt;br /&gt;# change Timeout 300 to&lt;br /&gt;Timeout 45&lt;br /&gt;# change KeepAlive Off to&lt;br /&gt;KeepAlive On&lt;br /&gt;# MaxKeepAliveRequests: The maximum number of requests to allow&lt;br /&gt;# during a persistent connection. Set to 0 to allow an unlimited amount.&lt;br /&gt;# We recommend you leave this number high, for maximum performance.&lt;br /&gt;# -- change MaxKeepAliveRequests 100 to 500&lt;br /&gt;MaxKeepAliveRequests 500&lt;br /&gt;# KeepAliveTimeout: Number of seconds to wait for the next request from the&lt;br /&gt;# same client on the same connection.&lt;br /&gt;# change KeepAliveTimeout 15 to&lt;br /&gt;KeepAliveTimeout 5&lt;br /&gt;# Increase MaxClients after benchmarking. mine is&lt;br /&gt;MaxClients       200&lt;br /&gt;# Turn off ServerSignature&lt;br /&gt;ServerSignature Off&lt;br /&gt;&lt;br /&gt;#ServerTokens Product&lt;br /&gt;ServerTokens ProductOnly&lt;br /&gt;&lt;/p&gt;&lt;p class="code"&gt;&lt;a href="http://frankmash.blogspot.com/2005/11/optimize-apache-20-apache2-on-rhel.html"&gt;http://frankmash.blogspot.com/2005/11/optimize-apache-20-apache2-on-rhel.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-998595976396199432?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/998595976396199432/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=998595976396199432' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/998595976396199432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/998595976396199432'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/10/optimasi-apache2.html' title='Optimasi Apache2'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-7037161446633268822</id><published>2008-09-23T18:26:00.002+07:00</published><updated>2008-09-23T18:30:28.868+07:00</updated><title type='text'>Menghapus /var/www/sarg</title><content type='html'>Setelah server proxy berjalan selama 2 tahun lebih harddisknya cepat sekali habis setelah dicari-cari biang keroknya ada SARG, SARG ini aplikasi untuk mengolah log-nya squid.&lt;br /&gt;dari pada harddisknya abis ya sudah SARGnya di remove tapi file-file hasil sarg ini tetap bercokol di harddisk di path /var/www/sarg&lt;br /&gt;&lt;br /&gt;untuk menghapusnya pakai perintah&lt;br /&gt;&lt;br /&gt;#cd /var/www&lt;br /&gt;#rm -rf sarg/&lt;br /&gt;&lt;br /&gt;beres deh harddisk proxy jadi luega buanget&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-7037161446633268822?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/7037161446633268822/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=7037161446633268822' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/7037161446633268822'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/7037161446633268822'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/menghapus-varwwwsarg.html' title='Menghapus /var/www/sarg'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-3929936605932405433</id><published>2008-09-23T14:07:00.004+07:00</published><updated>2008-09-23T14:47:26.115+07:00</updated><title type='text'>Solusi Akses Internet On Demand</title><content type='html'>Seiring dengan perkembangan jaringan Internet di Indonesia saat ini dimana semakin banyak ISP yang menawarkan akses Internet IIX only pada game-game online dan perusahaan-perusahaan yang memang hanya membutuhkan akses ke Internet domestik di Indonesia. Tetapi suatu saat mungkin ada keperluan untuk mengakses Internet Global misalnya untuk cek email di yahoo.com gmail.com atau sekedar mencari informasi di google.com untuk itu mungkin solusi akses Internet on demand bisa menjadi pilihan.&lt;br /&gt;&lt;br /&gt;Demikian juga bagi mahasiswa-mahasiswa yang memiliki koneksi Internet di kamar kost-nya melalui jaringan RTRWNet dengan harga sangat terjangkau tetapi umumnya bandwidth menuju ke Internet Global sangat terbatas maka jika suatu saat membutuhkan akses Internet Global yang lebih cepat maka solusi akses Internet on demand bisa menjadi pilihan.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Apa itu akses Internet on demand?&lt;/span&gt;&lt;br /&gt;Akses Internet on demand yang dimaksud dalam tulisan ini adalah akses Internet Global menggunakan koneksi VPN-dial yang disediakan oleh &lt;a href="http://www.datautama.net.id/"&gt;DatautamaNet&lt;/a&gt;  , sebenarnya fasilitas VPN-Dial ini adalah layanan tambahan bagi pengguna &lt;a href="http://mobile.datautama.net.id/"&gt;Dmobile&lt;/a&gt;  tetapi seharusnya bisa juga dimanfaatkan oleh semua orang dengan cara cukup membeli &lt;a href="http://mobile.datautama.net.id/web/index.php?option=com_content&amp;amp;view=category&amp;amp;layout=blog&amp;amp;id=36&amp;amp;Itemid=63"&gt;voucher&lt;/a&gt; secara fisik maupun secara online di &lt;a href="https://www.gudangvoucher.com/index.php?PID=52"&gt;gudangvoucher.com&lt;/a&gt; lalu melakukan &lt;a href="http://mobile.datautama.net.id/web/index.php?option=com_content&amp;amp;view=section&amp;amp;id=5&amp;amp;Itemid=53"&gt;aktivasi&lt;/a&gt; lalu ikuti &lt;a href="http://mobile.datautama.net.id/web/index.php?option=com_content&amp;amp;view=category&amp;amp;layout=blog&amp;amp;id=48&amp;amp;Itemid=71"&gt;petunjuk cara peng-aktivan&lt;/a&gt; atau cukup menggunakan &lt;a href="http://mobile.datautama.net.id/web/index.php?option=com_content&amp;amp;view=category&amp;amp;layout=blog&amp;amp;id=40&amp;amp;Itemid=64"&gt;SMS&lt;/a&gt; dari Handphone CDMA + Fren Anda.&lt;br /&gt;&lt;br /&gt;Setelah voucher tersebut aktif maka akses Internet on demand dapat dinikmati dengan cara membuat koneksi VPN yang petunjuknya dapat dibaca di:&lt;br /&gt;&lt;a href="http://mobile.datautama.net.id/web/index.php?option=com_content&amp;amp;view=category&amp;amp;layout=blog&amp;amp;id=49&amp;amp;Itemid=72"&gt;http://mobile.datautama.net.id/web/index.php?option=com_content&amp;amp;view=category&amp;amp;layout=blog&amp;amp;id=49&amp;amp;Itemid=72&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Syarat minimal yang dibutuhkan&lt;/span&gt;&lt;br /&gt;Adapun syarat minimal yang dibutuhkan untuk dapat menggunakan Internet on demand menggunakan VPN ini adalah komputer Anda harus dapat melakukan VPN dial menggunakan protocol PPTP yang biasanya telah disupport oleh MS. Windows XP dan Linux, juga harus dapat mengakses ke IP 203.89.24.5 caranya coba ping dan traceroute dari komputer Anda ke IP 203.89.24.5&lt;br /&gt;&lt;br /&gt;Jika menggunakan Sistem Operasi MS. Windows caranya klik Start-&gt;Run ketik CMD dan Enter&lt;br /&gt;maka akan muncul jendela command prompt C:\&gt;, misal sbb:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;C:\Documents and Settings\Harijanto&gt;ping 203.89.24.5&lt;br /&gt;&lt;br /&gt;Pinging 203.89.24.5 with 32 bytes of data:&lt;br /&gt;&lt;br /&gt;Reply from 203.89.24.5: bytes=32 time=14ms TTL=62&lt;br /&gt;Reply from 203.89.24.5: bytes=32 time=4ms TTL=62&lt;br /&gt;Reply from 203.89.24.5: bytes=32 time=4ms TTL=62&lt;br /&gt;Reply from 203.89.24.5: bytes=32 time=3ms TTL=62&lt;br /&gt;&lt;br /&gt;Ping statistics for 203.89.24.5:&lt;br /&gt;  Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),&lt;br /&gt;Approximate round trip times in milli-seconds:&lt;br /&gt;  Minimum = 3ms, Maximum = 14ms, Average = 6ms&lt;br /&gt;&lt;br /&gt;C:\Documents and Settings\Harijanto&gt;tracert 203.89.24.5&lt;br /&gt;&lt;br /&gt;Tracing route to ip-24-5.datautama.net.id [203.89.24.5]&lt;br /&gt;over a maximum of 30 hops:&lt;br /&gt;&lt;br /&gt;1     1 ms     1 ms     1 ms  192.168.2.1&lt;br /&gt;2     1 ms     2 ms     1 ms  ip-24-65.datautama.net.id [203.89.24.65]&lt;br /&gt;3     9 ms     9 ms     5 ms  ip-24-5.datautama.net.id [203.89.24.5]&lt;br /&gt;&lt;br /&gt;Trace complete.&lt;br /&gt;&lt;br /&gt;C:\Documents and Settings\Harijanto&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Jika dari komputer Anda bisa Replay From 203.89.24.5 maka anda dapat melakukan VPN Dial ke Server VPN Internet on demand tersebut.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Manfaat Internet on demand&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Internet on demand bagi pengguna yang hanya berlangganan IIX ke ISP manapun di Indonesia&lt;/li&gt;&lt;li&gt;Global Internet Akses 128Kbps per koneksi,  jika bandwidth IIX Anda lebih besar dari 128Kbps maka Anda dapat mengakses Global Internet Akses sd 128Kbps per koneksi / per komputer yang melakukan VPN Dial ke 203.89.24.5&lt;/li&gt;&lt;li&gt;Sebagai backup koneksi Global Internet Akses jika ISP yang Anda gunakan mengalami gangguan ke Global Internet Akses tetapi ke IIX tidak ada masalah.&lt;/li&gt;&lt;li&gt;Sebagai pengaman tambahan jika Anda mengakses public Internet seperti hotspot sehingga data-data Anda akan aman terbungkus koneksi VPN dari notebook Anda sampai dengan ke VPN Server DatautamaNet.&lt;/li&gt;&lt;li&gt;Sebagai solusi SMTP Server / Outgoing Server jika Anda mengalami kesulitan mengirim email dari notebook / komputer Anda melalui public Internet seperti hotspot, dengan mengarahkan outgoing server / SMTP server Anda ke smtp.datautama.net.id setelah berhasil melakukan koneksi VPN dial ke DatautamaNet.&lt;/li&gt;&lt;li&gt;Username dan Password dapat digunakan di hotspot Krispykreme: Grand Indonesia dan Plaza Senayan sekaligus untuk koneksi Internet melalui jaringan &lt;a href="http://web.datautama.net.id/content.php?id=201"&gt;CDMA Fren/Mobile-8&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;Informasi lebih lanjut &lt;a href="http://web.datautama.net.id/content.php?id=6"&gt;klik disini&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-3929936605932405433?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/3929936605932405433/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=3929936605932405433' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3929936605932405433'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3929936605932405433'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/solusi-akses-internet-on-demand.html' title='Solusi Akses Internet On Demand'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-9178105873388121083</id><published>2008-09-16T17:08:00.002+07:00</published><updated>2008-09-16T17:09:14.823+07:00</updated><title type='text'>Cara rubah timezone setelah proses install di debian</title><content type='html'>Mungkin kita butuh merubah timezone setelah debian terinstall caranya mudah tinggal eksekusi:&lt;br /&gt;&lt;br /&gt;tzconfig&lt;br /&gt;&lt;br /&gt;lalu ikuti langkah2nya&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;16.1.1 Changing the timezone after installation&lt;/h3&gt;  &lt;p&gt; If the timezone is not set or is wrong, the superuser can run &lt;code&gt;tzconfig&lt;/code&gt; to configure it after the operating system is installed (see man page &lt;code&gt;tzconfig(8)&lt;/code&gt;). &lt;/p&gt;  &lt;p&gt; If there are other users, it is a good idea to notify then that the system Timezone has changed.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.debian.org/doc/manuals/system-administrator/ch-sysadmin-time.html"&gt;http://www.debian.org/doc/manuals/system-administrator/ch-sysadmin-time.html&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-9178105873388121083?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/9178105873388121083/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=9178105873388121083' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/9178105873388121083'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/9178105873388121083'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/cara-rubah-timezone-setelah-proses.html' title='Cara rubah timezone setelah proses install di debian'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-3745547918687173844</id><published>2008-09-16T15:59:00.003+07:00</published><updated>2008-09-16T16:07:37.176+07:00</updated><title type='text'>Contoh Pengajuan Rerverse DNS</title><content type='html'>Untuk mengaktifkan reverse dns setelah nameserver dikonfigurasikan dengan benar dan dapat berfungsi dengan baik di nameserver isp maka selanjutnya kirim email sbb:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;to: hostmaster@apjii.or.id&lt;br /&gt;subject: [DATAUTAMA-ID] reverse dns 29.89.203.in-addr.arpa&lt;br /&gt;&lt;br /&gt;domain:  29.89.203.in-addr.arpa&lt;br /&gt;descr:     PT. Data Utama Dinamika&lt;br /&gt;descr:     Wisma Presisi Lantai 2&lt;br /&gt;descr:     Jl. Taman Aries Blok A1 No 1&lt;br /&gt;descr:     Meruya Utara - Kembangan&lt;br /&gt;descr:     Jakarta 11620&lt;br /&gt;country:   ID&lt;br /&gt;admin-c:   HP371-AP&lt;br /&gt;tech-c:    HP371-AP&lt;br /&gt;zone-c:    HP371-AP&lt;br /&gt;nserver:   ns1.datautama.net.id&lt;br /&gt;nserver:   ns2.datautama.net.id&lt;br /&gt;remarks:   spam &amp;amp; abuse report: &lt;a class="moz-txt-link-abbreviated" href="mailto:abuse@datautama.net.id"&gt;abuse@datautama.net.id&lt;/a&gt;&lt;br /&gt;notify:    &lt;a class="moz-txt-link-abbreviated" href="mailto:noc@datautama.net.id"&gt;noc@datautama.net.id&lt;/a&gt;&lt;br /&gt;mnt-by:    MNT-APJII-ID&lt;br /&gt;mnt-lower: MAINT-ID-DATAUTAMA&lt;br /&gt;changed:   &lt;a class="moz-txt-link-abbreviated" href="mailto:hostmaster@apjii.or.id"&gt;hostmaster@apjii.or.id&lt;/a&gt; 20020304&lt;br /&gt;source:    APNIC&lt;br /&gt;password:  xxxxx&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;setelah email di terima oleh hostmaster@apjii.or.id atau IDNIC maka APJII/IDNIC akan mereplay sbb:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Dear Pak Harijanto,&lt;br /&gt;&lt;br /&gt;The following reverse domain objects have been created in the APNIC  Whois Database. This information will be merged into APNIC master zone  file within the next 2 hours.&lt;br /&gt;&lt;br /&gt;&lt;span class="moz-txt-tag"&gt;--&lt;br /&gt;&lt;/span&gt;Best Regards,&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-3745547918687173844?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/3745547918687173844/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=3745547918687173844' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3745547918687173844'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3745547918687173844'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/contoh-pengajuan-rerverse-dns.html' title='Contoh Pengajuan Rerverse DNS'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-3207663260270780525</id><published>2008-09-16T15:37:00.008+07:00</published><updated>2009-12-23T15:21:54.910+07:00</updated><title type='text'>Petunjuk melakukan 2nd opinion IPv4</title><content type='html'>Dalam mengelola IPv4 dari APNIC, ISP perlu melakukan 2nd opinion agar data who-is APNIC dapat terupdate sesuai perkembangan penggunaan IPv4 yang didelegasikan APNIC ke ISP ybs.&lt;br /&gt;&lt;br /&gt;Proses 2nd opinion ini perlu dilakukan sebelum mengajukan pengarahan reverse dns dari APNIC ke nameserver ISP ybs.&lt;br /&gt;&lt;br /&gt;Berikut adalah contoh step by step proses 2nd opinion melalui APJII&lt;br /&gt;keterangan lebih lanjut bisa dibaca di : &lt;a href="http://www.idnic.net/"&gt;http://www.idnic.net&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Langkah langkahnya adalah sbb:&lt;br /&gt;---------------------------------&lt;br /&gt;&lt;br /&gt;Kirim email ke hostmaster@apjii.or.id&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;#[SECOND OPINION REQUEST FORM TEMPLATE]# #[REQUESTOR TEMPLATE]#&lt;br /&gt;name: Harijanto Pribadi&lt;br /&gt;email: harijanto@datautama.com&lt;br /&gt;acct-name: DATAUTAMA-ID&lt;br /&gt;org-relationship: Director&lt;br /&gt;&lt;br /&gt;#[SECOND OPINION TEMPLATE]#&lt;br /&gt;address-type: IPv4&lt;br /&gt;opinion-type: assignment&lt;br /&gt;&lt;br /&gt;#[IPv4 ASSIGNMENT TEMPLATE V:1.0]#&lt;br /&gt;netname: BUDILUHUR&lt;br /&gt;descr: Universitas Budi Luhur&lt;br /&gt;descr: JL. Raya Ciledug Pertukangan No. 99&lt;br /&gt;descr: Jakarta 11260&lt;br /&gt;country: ID&lt;br /&gt;prefix: /28&lt;br /&gt;network-plan: 203.89.25.16/28 /28,/28,/28 Router and Server&lt;br /&gt;&lt;br /&gt;#[ADDITIONAL INFORMATION]#&lt;br /&gt;Campus Network&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Setelah menerima email balasan dari hostmaster@apjii.or.id seperti dibawah ini&lt;br /&gt;Kemudian buka &lt;a href="http://www.apnic.net/apnic-bin/inetnum.pl"&gt;http://www.apnic.net/apnic-bin/inetnum.pl&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;versi terbaru  &lt;a href="http://submit.apnic.net/apnic-bin/inetnum.pl"&gt;http://submit.apnic.net/apnic-bin/inetnum.pl&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Kepada Yth,&lt;br /&gt;Pak Harijanto&lt;br /&gt;&lt;br /&gt;Terima kasih atas pengajuan Opini Kedua.&lt;br /&gt;Kami dapat menerima request Opini Kedua anda.&lt;br /&gt;&lt;br /&gt;Netname: BUDILUHUR&lt;br /&gt;Prefix: /28&lt;br /&gt;Harap segera lakukan updating atas assignment kepada client anda di whois database APNIC pada link :&lt;br /&gt;http://www.apnic.net/apnic-bin/inetnum.pl&lt;br /&gt;&lt;br /&gt;Status yang dicantumkan untuk range IP Address untuk pelanggan ini adalah:&lt;br /&gt;ASSIGNED NON-PORTABLE&lt;br /&gt;&lt;br /&gt;Catatan:&lt;br /&gt;Bila terjadi perubahan "netname" dengan yang tercantum di Second opinion ini, mohon diinfokan kepada kami.&lt;br /&gt;&lt;br /&gt;Bila ada hal-hal yang kurang jelas mengenai hal ini, dapat menghubungi kami kembali di email ini.&lt;br /&gt;&lt;br /&gt;Prosedur Updating Database IP-Range:&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;1. Dapat menggunakan Template Inetnum. Contohnya adalah sbb:&lt;br /&gt;&lt;br /&gt;inetnum:      202.148.32.0 - 202.148.32.255&lt;br /&gt;netname:      APJII&lt;br /&gt;descr:        Asosiasi Penyelenggara Jasa Internet Indonesia&lt;br /&gt;descr:        Indonesian ISP Association&lt;br /&gt;country:      ID&lt;br /&gt;admin-c:      AA2-ID&lt;br /&gt;tech-c:       AH1-ID&lt;br /&gt;mnt-by:       MAINT-ID-ISPNET&lt;br /&gt;changed:      wsekjen@apjii.or.id 20020722&lt;br /&gt;remarks: Send Spam &amp;amp; Abuse Reports to : abuse@isp.net.id&lt;br /&gt;status:       ASSIGNED NON-PORTABLE&lt;br /&gt;source:       APNIC&lt;br /&gt;&lt;br /&gt;2. INETNUM: range IP Address yang akan diassign ke pelanggan anda, sesuai dengan jumlah Prefix dalam Second Opinion.&lt;br /&gt;3. NETNAME: harus sama dengan netname yang ada di Second Opinion. Bila terjadi perubahan Netname, harap diinfokan kepada hostmaster APJII &lt;/span&gt;&lt;hostmaster@apjii.or.id&gt;&lt;span style="font-size:85%;"&gt;.&lt;br /&gt;4. Descr: diisi dengan Basis Usaha pelanggan,alamat (cukup disebutkan kotamadya saja) pelanggan, bukan data-data ISP-nya.&lt;br /&gt;5. ADMIN-C &amp;amp; TECH-C harap dicantumkan Role Object ISP anda.Bila ISP anda belum memiliki Role Object, bisa mengacu pada "Prosedur Updating Database APNIC" pada bagian "Prosedur Updating Role Object".&lt;br /&gt;6. Maintainer Object diisi dengan Maintainer Object ISPNET anda. Bila belum ada,dapat menghubungi Hostmaster APJII untuk panduan lebih lanjut.&lt;br /&gt;7. STATUS: untuk Second Opinion ini diisi dengan ASSIGNED NON-PORTABLE 8. Kirim template ini ke auto-dbm@apnic.net . Dalam pengiriman ini,gunakan format Plain Text (murni). Hindari penggunaan format tambahan pada email seperti Bold, Italic,dsb. Biasanya hal seperti ini akan mengakibatkan Failure pada saat Updating.&lt;br /&gt;&lt;br /&gt;Wassalam,&lt;br /&gt;____________________________________________________________&lt;br /&gt;Ahmad Khalil Alkazimy, Internet Resource Analyst &lt;/span&gt;&lt;ahmad@apjii.or.id&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;ID-NIC {Indonesia Network Information Center]&lt;br /&gt;hostmaster@apjii.or.id&lt;br /&gt;http://www.apjii.or.id&lt;br /&gt;Telp +62-21-5296.0634    Fax +62-21-5296.0635&lt;br /&gt;____________________________________________________________&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/ahmad@apjii.or.id&gt;&lt;/hostmaster@apjii.or.id&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SM9zJHEzIXI/AAAAAAAAANc/aY2NmGCo12Y/s1600-h/image001.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SM9zJHEzIXI/AAAAAAAAANc/aY2NmGCo12Y/s400/image001.png" alt="" id="BLOGGER_PHOTO_ID_5246538691265110386" border="0" /&gt;&lt;/a&gt;&lt;hostmaster@apjii.or.id&gt;&lt;ahmad@apjii.or.id&gt;&lt;br /&gt;Klik New&lt;br /&gt;&lt;br /&gt;&lt;/ahmad@apjii.or.id&gt;&lt;/hostmaster@apjii.or.id&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SM9zJuqRc_I/AAAAAAAAANs/2I3kYxuxU2E/s1600-h/image003.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SM9zJuqRc_I/AAAAAAAAANs/2I3kYxuxU2E/s400/image003.png" alt="" id="BLOGGER_PHOTO_ID_5246538701891269618" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;hostmaster@apjii.or.id&gt;&lt;ahmad@apjii.or.id&gt;&lt;br /&gt;Klik Submit&lt;br /&gt;Password “xxxxx” bisa dilihat di approval IP Address Datautama&lt;br /&gt;&lt;br /&gt;&lt;/ahmad@apjii.or.id&gt;&lt;/hostmaster@apjii.or.id&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SM9zJkl9QHI/AAAAAAAAAN8/o86kD8MVz3o/s1600-h/image005.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SM9zJkl9QHI/AAAAAAAAAN8/o86kD8MVz3o/s400/image005.png" alt="" id="BLOGGER_PHOTO_ID_5246538699188813938" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;hostmaster@apjii.or.id&gt;&lt;ahmad@apjii.or.id&gt;&lt;br /&gt;Berikutnya akan menerima email dari auto-dbm@apnic.net&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;======================================================================&lt;br /&gt;This is an automatic response, generated by your recent request&lt;br /&gt;to update the APNIC database. In order to complete this request:&lt;br /&gt;&lt;br /&gt;YOU MUST E-MAIL THIS FORM TO: auto-dbm@apnic.net&lt;br /&gt;&lt;br /&gt;Once you have sent this form, you will receive an auto response&lt;br /&gt;informing you of whether your update has been accepted, or of any&lt;br /&gt;errors that may have appeared in your data.&lt;br /&gt;&lt;br /&gt;Thank you for using this service.&lt;br /&gt;======================================================================&lt;br /&gt;&lt;br /&gt;#[NETWORK TEMPLATE V:5.0]#&lt;br /&gt;&lt;br /&gt;inetnum: 203.89.25.16 - 203.89.25.31&lt;br /&gt;netname: BUDILUHUR&lt;br /&gt;country: ID&lt;br /&gt;descr: Universitas Budi Luhur&lt;br /&gt;descr: JL. Raya Ciledug Pertukangan No. 99&lt;br /&gt;descr: Jakarta 11260&lt;br /&gt;admin-c: HP371-AP&lt;br /&gt;tech-c: HP371-AP&lt;br /&gt;status: ASSIGNED NON-PORTABLE&lt;br /&gt;changed: harijanto@datautama.com 20060613&lt;br /&gt;mnt-by: MAINT-ID-DATAUTAMA&lt;br /&gt;password: xxxxx&lt;br /&gt;source: APNIC&lt;br /&gt;&lt;br /&gt;# acct: HP371-AP&lt;br /&gt;#[TEMPLATES END]#&lt;br /&gt;======================================================================&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Berikutnya email tersebut di forward ke auto-dbm@apnic.net untuk bagian&lt;br /&gt;#[NETWORK TEMPLATE V:5.0]# sd #[TEMPLATES END]#&lt;br /&gt;&lt;br /&gt;&lt;/ahmad@apjii.or.id&gt;&lt;/hostmaster@apjii.or.id&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SM9_S2YpJGI/AAAAAAAAAO8/1GSBrXtizDM/s1600-h/image007.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SM9_S2YpJGI/AAAAAAAAAO8/1GSBrXtizDM/s400/image007.png" alt="" id="BLOGGER_PHOTO_ID_5246552052723164258" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;hostmaster@apjii.or.id&gt;&lt;ahmad@apjii.or.id&gt;&lt;br /&gt;Catatan:&lt;br /&gt;Harus Plain-Tex&lt;br /&gt;&lt;br /&gt;Jika update success akan ada email dari APNIC seperti dibawah ini:&lt;br /&gt;&lt;br /&gt;&lt;/ahmad@apjii.or.id&gt;&lt;/hostmaster@apjii.or.id&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/SM9zv39_0SI/AAAAAAAAAOc/8bmqt2nAdaw/s1600-h/image009.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/SM9zv39_0SI/AAAAAAAAAOc/8bmqt2nAdaw/s400/image009.png" alt="" id="BLOGGER_PHOTO_ID_5246539357224948002" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;hostmaster@apjii.or.id&gt;&lt;ahmad@apjii.or.id&gt;&lt;br /&gt;Hasilnya jika di whois akan muncul&lt;br /&gt;&lt;br /&gt;&lt;/ahmad@apjii.or.id&gt;&lt;/hostmaster@apjii.or.id&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/SM9z-Z4tu3I/AAAAAAAAAO0/1WTB0D76AIY/s1600-h/image012.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/SM9z-Z4tu3I/AAAAAAAAAO0/1WTB0D76AIY/s400/image012.jpg" alt="" id="BLOGGER_PHOTO_ID_5246539606847765362" border="0" /&gt;&lt;/a&gt;&lt;hostmaster@apjii.or.id&gt;&lt;ahmad@apjii.or.id&gt;&lt;br /&gt;&lt;/ahmad@apjii.or.id&gt;&lt;/hostmaster@apjii.or.id&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-3207663260270780525?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/3207663260270780525/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=3207663260270780525' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3207663260270780525'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3207663260270780525'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/petunjuk-melakukan-2nd-opinion-ipv4.html' title='Petunjuk melakukan 2nd opinion IPv4'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_nzWcXcVYSRs/SM9zJHEzIXI/AAAAAAAAANc/aY2NmGCo12Y/s72-c/image001.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-6926427838125547380</id><published>2008-09-12T13:24:00.005+07:00</published><updated>2008-09-24T14:46:21.280+07:00</updated><title type='text'>Script Sederhana Untuk Mindahin Gateway di Linux</title><content type='html'>Ini contoh script sederhana utk ngecek koneksi ke yahoo.com dan kalau RTO gateway dipindah ke koneksi satunya.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#!/bin/sh&lt;br /&gt;#Scipt by harijanto@datautama.net.id&lt;br /&gt;#Crazy idea from priyo@datautama.net.id&lt;br /&gt;#Thanks&lt;br /&gt;/sbin/route | grep default | grep 119.82.246.1&lt;br /&gt;error=$?&lt;br /&gt;echo $error&lt;br /&gt;if [ $error = 0 ]&lt;br /&gt;  then&lt;br /&gt;      if a=`ping -q -c 1 -w 3 www.yahoo.com &gt; /dev/null`&lt;br /&gt;      then&lt;br /&gt;      echo "Link Utama to International OK"&lt;br /&gt;      else&lt;br /&gt;      echo "Link Utama to International NOT OK"&lt;br /&gt;      /sbin/route add -net 0.0.0.0/0 gw 203.89.24.1&lt;br /&gt;      /sbin/route del -net 0.0.0.0/0 gw 119.82.246.1&lt;br /&gt;      fi&lt;br /&gt;  else&lt;br /&gt;      echo "Link Pake Backup Coba pindahin ke Link Utama Lagi"&lt;br /&gt;      /sbin/route add -net 0.0.0.0/0 gw 119.82.246.1&lt;br /&gt;      /sbin/route del -net 0.0.0.0/0 gw 203.89.24.1&lt;br /&gt;      if a=`ping -q -c 1 -w 3 www.yahoo.com &gt; /dev/null`&lt;br /&gt;      then&lt;br /&gt;      echo "Link Utama to International Sudah OK"&lt;br /&gt;      else&lt;br /&gt;      echo "Link Utama to International Masih NOT OK CAPEDEH"&lt;br /&gt;      /sbin/route add -net 0.0.0.0/0 gw 203.89.24.1&lt;br /&gt;      /sbin/route del -net 0.0.0.0/0 gw 119.82.246.1&lt;br /&gt;      fi&lt;br /&gt;fi&lt;br /&gt;&lt;br /&gt;misal kasih nama /etc/checkyahoo.sh&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;terus script tersebut tinggal di crond per 10 menit di /etc/crontab&lt;br /&gt;&lt;br /&gt;*/10 * * * * root /etc/checkyahoo.sh &gt; /dev/null 2&gt;&amp;amp;1&lt;br /&gt;&lt;br /&gt;lalu restart crond:&lt;br /&gt;&lt;br /&gt;service crond restart&lt;br /&gt;&lt;br /&gt;jadi dech Fail Over Sederhana :p&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-6926427838125547380?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/6926427838125547380/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=6926427838125547380' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6926427838125547380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6926427838125547380'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/script-sederhana-untuk-mindahin-gateway.html' title='Script Sederhana Untuk Mindahin Gateway di Linux'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-6234839019590607841</id><published>2008-09-12T12:20:00.003+07:00</published><updated>2008-10-07T15:00:10.139+07:00</updated><title type='text'>Referensi cara mengamankan server hosting</title><content type='html'>Bagi para admin server hosting berikut link yang bagus tentang cara mengamankan server hosting&lt;br /&gt;&lt;br /&gt;Penjelasan APF+BFD+DDOS+Rootkit&lt;br /&gt;&lt;a href="http://www.directadmin.com/forum/archive/index.php/t-14500.html"&gt;http://www.directadmin.com/forum/archive/index.php/t-14500.html&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;Update script homepage, salah satunya penjelasan KISS alternatif APF&lt;br /&gt;&lt;a href="http://www.web4host.net/tools/"&gt;http://www.web4host.net/tools/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Untuk setup apf bisa baca disini:&lt;br /&gt;&lt;a href="http://aplawrence.com/Web/apf_cpanel.html"&gt;http://aplawrence.com/Web/apf_cpanel.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-6234839019590607841?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/6234839019590607841/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=6234839019590607841' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6234839019590607841'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6234839019590607841'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/referensi-cara-mengamankan-server.html' title='Referensi cara mengamankan server hosting'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-2163668846171591279</id><published>2008-09-12T10:26:00.002+07:00</published><updated>2008-09-12T10:32:41.320+07:00</updated><title type='text'>Menghapus Email dengan Subject Tertentu menggunakan MTA EXIM</title><content type='html'>Setelah sebelumnya saya menggunakan strategi reject email-email yang telah di tag / ditandai "&lt;a href="http://inetshoot.blogspot.com/2008/08/memfilter-spam-dari-cnncom.html"&gt;[SPAM]&lt;/a&gt;" ternyata strategi ini masih tidak efisien karena Exim harus mengirim reject message ke email server pengirim&lt;br /&gt;&lt;br /&gt;Untuk itu agar Exim langsung menghapus email-email yang bersubject "[SPAM]" maka digunakan filter rule sbb:&lt;br /&gt;&lt;br /&gt;# delete all emails contain [SPAM] subject&lt;br /&gt;if $header_subject: contains "[SPAM]"&lt;br /&gt;then&lt;br /&gt;seen finish&lt;br /&gt;endif&lt;br /&gt;&lt;br /&gt;filter rule tersebut di tulis di file /etc/cpanel_exim_system_filter&lt;br /&gt;&lt;br /&gt;lalu restart service exim agar filter dijalankan&lt;br /&gt;&lt;br /&gt;sumber:&lt;br /&gt;&lt;a href="http://www.doc.ic.ac.uk/csg/email/filter/#rules"&gt;http://www.doc.ic.ac.uk/csg/email/filter/#rules&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-2163668846171591279?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/2163668846171591279/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=2163668846171591279' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2163668846171591279'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2163668846171591279'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/menghapus-email-dengan-subject-tertentu.html' title='Menghapus Email dengan Subject Tertentu menggunakan MTA EXIM'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-4318307383041409730</id><published>2008-09-10T20:53:00.003+07:00</published><updated>2008-09-10T21:07:12.661+07:00</updated><title type='text'>Solusi Cara Membatasi IP Tujuan dan MAC Client yang diizinkan</title><content type='html'>Kasus:&lt;br /&gt;Sebuah perusahaan ingin agar karyawannya hanya bisa browsing ke IP tertentu saja dan hanya dari Komputer dengan MAC tertentu saja yang boleh ke Internet.&lt;br /&gt;&lt;br /&gt;Caranya:&lt;br /&gt;Buat address-list misal dengan nama = "web-allow" , contoh scritpnya:&lt;br /&gt;&lt;br /&gt;/ip firewall address-list&lt;br /&gt;add list=web-allow address=203.89.24.34 comment="Datautama" disable=no&lt;br /&gt;add list=web-allow address=202.152.54.73 comment="" disable=no&lt;br /&gt;add list=web-allow address=202.152.54.74 comment="" disable=no&lt;br /&gt;add list=web-allow address=202.155.43.103 comment="" disable=no&lt;br /&gt;dst..&lt;br /&gt;&lt;br /&gt;atau dengan winbox sbb:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SMfSFmcC3OI/AAAAAAAAANM/8ieTgWyTKso/s1600-h/ramanta-address-list.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SMfSFmcC3OI/AAAAAAAAANM/8ieTgWyTKso/s400/ramanta-address-list.JPG" alt="" id="BLOGGER_PHOTO_ID_5244391284755586274" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Lalu buat filter rule chain forward dengan script misal sbb:&lt;br /&gt;&lt;br /&gt;/ip firewall filter&lt;br /&gt;add action=add-src-to-address-list address-list=mac-allow \&lt;br /&gt;    address-list-timeout=1m chain=forward comment=\&lt;br /&gt;    "add PC allow mac to address-list mac-allow" disabled=no src-mac-address=\&lt;br /&gt;    00:1B:24:A5:A3:64&lt;br /&gt;add action=add-src-to-address-list address-list=mac-allow \&lt;br /&gt;    address-list-timeout=1m chain=forward comment="" disabled=no \&lt;br /&gt;    src-mac-address=00:08:0D:A7:45:CC&lt;br /&gt;&lt;br /&gt;dst...&lt;br /&gt;&lt;br /&gt;atau melalui winbox caranya sbb:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SMfR4GmctYI/AAAAAAAAAM0/N6pDlg0zHBQ/s1600-h/ramanta-firewall-forward-add-to-list-1.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SMfR4GmctYI/AAAAAAAAAM0/N6pDlg0zHBQ/s400/ramanta-firewall-forward-add-to-list-1.JPG" alt="" id="BLOGGER_PHOTO_ID_5244391052870989186" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SMfR4XUHDPI/AAAAAAAAAM8/K_b7vluVvkg/s1600-h/ramanta-firewall-forward-add-to-list-advance.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SMfR4XUHDPI/AAAAAAAAAM8/K_b7vluVvkg/s400/ramanta-firewall-forward-add-to-list-advance.JPG" alt="" id="BLOGGER_PHOTO_ID_5244391057357475058" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SMfSFVMv8wI/AAAAAAAAANE/wCzvaM7muh4/s1600-h/ramanta-firewall-forward-add-to-list-action.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SMfSFVMv8wI/AAAAAAAAANE/wCzvaM7muh4/s400/ramanta-firewall-forward-add-to-list-action.JPG" alt="" id="BLOGGER_PHOTO_ID_5244391280128029442" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;dengan demikian jika ada traffic data dari komputer dengan MAC yang tertera di atas maka ipnya akan di masukkan dalam address-list = mac-allow selama 1 menit,  jika dalam 1 menit tidak ada traffic data maka address-list ip dari mac tersebut akan hilang karena ini sifatnya dinamis&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SMfSF5nMsMI/AAAAAAAAANU/W9xJ2hYSzIE/s1600-h/ramanta-address-dynamic.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SMfSF5nMsMI/AAAAAAAAANU/W9xJ2hYSzIE/s400/ramanta-address-dynamic.JPG" alt="" id="BLOGGER_PHOTO_ID_5244391289902641346" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Berikutnya di bagian NAT&lt;br /&gt;buat seperti contoh gambar winbox dibawah ini:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/SMfR3r-UP2I/AAAAAAAAAMc/IA-wXFOiIKI/s1600-h/ramanta-nat-web-allow-mac-allow.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/SMfR3r-UP2I/AAAAAAAAAMc/IA-wXFOiIKI/s400/ramanta-nat-web-allow-mac-allow.JPG" alt="" id="BLOGGER_PHOTO_ID_5244391045723340642" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;di tab Advanced pilih Src Address-list dengan = mac-allow&lt;br /&gt;dan Dst Address-list dengan = web-allow&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SMfR3zvcijI/AAAAAAAAAMk/wAXUxBXa98g/s1600-h/ramanta-nat-web-allow-mac-allow-advance.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SMfR3zvcijI/AAAAAAAAAMk/wAXUxBXa98g/s400/ramanta-nat-web-allow-mac-allow-advance.JPG" alt="" id="BLOGGER_PHOTO_ID_5244391047808453170" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;dan di tab Action pilih = masquerade&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/SMfR3zBr0vI/AAAAAAAAAMs/CliXuV_7-34/s1600-h/ramanta-nat-web-allow-mac-allow-acction.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/SMfR3zBr0vI/AAAAAAAAAMs/CliXuV_7-34/s400/ramanta-nat-web-allow-mac-allow-acction.JPG" alt="" id="BLOGGER_PHOTO_ID_5244391047616516850" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;dengan demikian hanya ip dari mac yang diizinkan dan ip tujuan yang tertera dalam web-allow yang dapat diakses oleh pengguna di jaringan tersebut&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-4318307383041409730?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/4318307383041409730/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=4318307383041409730' title='2 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/4318307383041409730'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/4318307383041409730'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/solusi-cara-membatasi-ip-tujuan-dan-mac.html' title='Solusi Cara Membatasi IP Tujuan dan MAC Client yang diizinkan'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_nzWcXcVYSRs/SMfSFmcC3OI/AAAAAAAAANM/8ieTgWyTKso/s72-c/ramanta-address-list.JPG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-6568155184209832266</id><published>2008-09-10T17:36:00.006+07:00</published><updated>2008-09-10T17:56:28.400+07:00</updated><title type='text'>Revisi Script ECMP Fail Over Mikrotik 3.10</title><content type='html'>Bagi yang pernah mencoba script &lt;a href="http://inetshoot.blogspot.com/2008/06/ecmp-failover-script-mikrotik-ver-310.html"&gt;ECMP Fail Over Mikrotik 3.10&lt;/a&gt; yang saya tulis sebelumnya mungkin ada kesulitan pada waktu menjalankan script ecmp-shutdown dan ecmp-startup , baru-baru ini saya menghadapi masalah tersebut. oleh karena itu coba gunakan script baru dibawah, jadi script lamanya didelete aja lalau diganti script ini dengan terlebih dahulu menyesuaikan ip gateway masing-masing koneksi.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-family: arial;"&gt;/system script&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;add name=ecmp-shutdown policy=\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    ftp,reboot,read,write,policy,test,winbox,password,sniff source=":if ([/pin\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    g 10.95.130.129 count=1]=0 || [/ping 10.168.2.1 count=1]=0) do={:log info \&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    \"Gateway down\" \r\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    \n/ip firewall mangle disable [/ip firewall mangle find comment=\"Route HT\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    TP traffic to ECMP\"] \r\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    \n/ip firewall mangle disable [/ip firewall mangle find comment=\"SMTP Tra\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    ffic\"]\r\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    \n} else {:log info \"ecmp-shutdown check ok\"}"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;add name=ecmp-startup policy=\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    ftp,reboot,read,write,policy,test,winbox,password,sniff source=":if ([/pin\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    g 10.95.130.129 count=1]=1 &amp;amp;&amp;amp; [/ping 10.168.2.1 count=1]=1) do={:log info \&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    \"Both Gateway are up\"\r\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    \n/ip firewall mangle enable [/ip firewall mangle find comment=\"Route HTT\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    P traffic to ECMP\"]\r\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    \n/ip firewall mangle enable [/ip firewall mangle find comment=\"SMTP Traf\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    fic\"]\r\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    \n} else {:log info \"ecmp-startup check ok\"}"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;add name=wireless-gateway-check policy=\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    ftp,reboot,read,write,policy,test,winbox,password,sniff source=":if ([/pin\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    g 10.95.130.129 count=1]=1) do={:log info \"Wireless Gateway are up\"\r\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    \n/ip route enable [/ip route find comment=\"Default Route to Internet Wir\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    eless\"]\r\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    \n/ip route disable [/ip route find comment=\"Default Route to Internet AD\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    SL\"]\r\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    \n} else {:log info \"Wireless Gateway are down\"\r\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    \n/ip route disable [/ip route find comment=\"Default Route to Internet Wi\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    reless\"]\r\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    \n/ip route enable [/ip route find comment=\"Default Route to Internet ADS\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    L\"]\r\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;    \n}"&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;/system scheduler&lt;br /&gt;add comment="" disabled=no interval=25s name=gateway-check1 on-event=\&lt;br /&gt;    ecmp-shutdown start-date=jun/13/2008 start-time=16:26:27&lt;br /&gt;add comment="" disabled=no interval=30s name=gateway-check2 on-event=\&lt;br /&gt;    ecmp-startup start-date=jun/13/2008 start-time=16:26:27&lt;br /&gt;add comment="" disabled=no interval=20s name=wireless-gateway-check on-event=\&lt;br /&gt;    wireless-gateway-check start-date=jun/13/2008 start-time=16:26:27&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;selain itu agar pengecekkan ke ip gateway link WIRELESS pasti lewat Interface WIRELESS coba tambahkan script berikut:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;/ip firewall filter&lt;br /&gt;add action=drop chain=output comment=\&lt;br /&gt;    "supaya ke gateway wireless tidak bisa lewat interface adsl" disabled=no \&lt;br /&gt;    dst-address=10.95.130.129 out-interface=ADSL protocol=icmp&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-6568155184209832266?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/6568155184209832266/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=6568155184209832266' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6568155184209832266'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6568155184209832266'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/revisi-script-ecmp-fail-over-mikrotik.html' title='Revisi Script ECMP Fail Over Mikrotik 3.10'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-636825961738719305</id><published>2008-09-09T22:00:00.001+07:00</published><updated>2008-09-09T22:01:42.715+07:00</updated><title type='text'>Mau bikin baner instant?</title><content type='html'>Bermula dari penasaran ada gak ya tools di internet untuk buat banner instan? dan mulai mencari di google.com dengan key = instant banner&lt;br /&gt;&lt;br /&gt;dan hasilnya&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.semuabisnis.com/banner/"&gt;http://www.semuabisnis.com/banner/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;silahkan mencoba :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-636825961738719305?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/636825961738719305/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=636825961738719305' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/636825961738719305'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/636825961738719305'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/mau-bikin-baner-instant.html' title='Mau bikin baner instant?'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-6462585215687513623</id><published>2008-09-09T21:23:00.002+07:00</published><updated>2008-09-09T21:30:48.405+07:00</updated><title type='text'>Membersihkan email yang telah antri lebih dari 24 jam di cpanel+exim4</title><content type='html'>Pada cpanel server sering didapati antrian email yang sangat banyak hingga lebih dari 1000 email&lt;br /&gt;&lt;br /&gt;Untuk membersihkan antrian yang lebih dari 24 jam yang umumnya adalah email-email SPAM&lt;br /&gt;saya buat skrip yang isinya sbb:&lt;br /&gt;&lt;br /&gt;#!/bin/sh&lt;br /&gt;#Remove all messages older than one day (86400 * 1 = 86400 seconds):&lt;br /&gt;/usr/sbin/exiqgrep -o 86400 -i | xargs exim -Mrm&lt;br /&gt;/usr/sbin/exiqgrep -z -i | xargs exim -Mrm&lt;br /&gt;&lt;br /&gt;lalu jalankan skript tersebut 1 jam sekali melalui cron dengan menambahkan baris berikut di file /etc/crontab&lt;br /&gt;&lt;br /&gt;02 * * * * root /etc/rc.eximqueflush -a &gt;&gt; /dev/null 2&gt;&amp;amp;1&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;catatan&lt;/span&gt;&lt;br /&gt;untuk menghapus semua email yang queue lebih dari 5 hari rumusnya: (86400 * 5 = 432000 seconds):&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Link berikut berguna untuk Exim&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bradthemad.org/tech/notes/exim_cheatsheet.php" target="_blank"&gt;http://bradthemad.org/tech/notes/exim_cheatsheet.php&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-6462585215687513623?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/6462585215687513623/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=6462585215687513623' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6462585215687513623'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6462585215687513623'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/membersihkan-email-yang-telah-antri.html' title='Membersihkan email yang telah antri lebih dari 24 jam di cpanel+exim4'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-5070177568479533854</id><published>2008-09-08T15:40:00.003+07:00</published><updated>2008-09-08T15:47:23.177+07:00</updated><title type='text'>Cara Mengaktifkan Box-Trapper Untuk Menyaring SPAM di Cpanel</title><content type='html'>Caranya login ke webmail&lt;br /&gt;&lt;br /&gt;http://webmail.datautama.net.id atau http://webmail.&lt;domain&gt;domainuser.hosting&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/domain&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SMTl9Ib6itI/AAAAAAAAALo/8Z80KQJRGWo/s1600-h/image001.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SMTl9Ib6itI/AAAAAAAAALo/8Z80KQJRGWo/s400/image001.jpg" alt="" id="BLOGGER_PHOTO_ID_5243568704565447378" border="0" /&gt;&lt;/a&gt;&lt;domain&gt;&lt;br /&gt;Klik ”Box Trapper”&lt;br /&gt;&lt;br /&gt;&lt;/domain&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SMTl9Deb2PI/AAAAAAAAALw/TBkE6s3VIh8/s1600-h/image002.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SMTl9Deb2PI/AAAAAAAAALw/TBkE6s3VIh8/s400/image002.jpg" alt="" id="BLOGGER_PHOTO_ID_5243568703233841394" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;domain&gt;&lt;br /&gt;Klik  Tombol ”Enable” disamping kanan tulisan Current Status&lt;br /&gt;Dengan demikian berarti Box Trapper di aktifkan&lt;br /&gt;&lt;br /&gt;Selanjutnya tiap hari cek di ”Review Queue”&lt;br /&gt;&lt;br /&gt;&lt;/domain&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SMTl9YcOjDI/AAAAAAAAAL4/mnzdK4NOrwU/s1600-h/image003.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SMTl9YcOjDI/AAAAAAAAAL4/mnzdK4NOrwU/s400/image003.jpg" alt="" id="BLOGGER_PHOTO_ID_5243568708861725746" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;domain&gt;&lt;br /&gt;Jika ada email2 yang bukan SPAM tertahan di Box Trapper ceklist kotak disamping pesan yang dimaksud lalu pilih Whitelist &amp;amp; Deliver lalu klik tombol ”Submit”&lt;br /&gt;&lt;br /&gt;&lt;/domain&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SMTl9bhJ_bI/AAAAAAAAAMA/kP2ceMssnBw/s1600-h/image004.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SMTl9bhJ_bI/AAAAAAAAAMA/kP2ceMssnBw/s400/image004.jpg" alt="" id="BLOGGER_PHOTO_ID_5243568709687705010" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;domain&gt;&lt;br /&gt;Untuk kembali lagi klik ”Go Back to Box Trapper Configuration” atau ”Go Back” untuk kembali mengecek daftar email yang tertangkap oleh Box Trapper&lt;br /&gt;&lt;br /&gt;Dengan demikian SPAM akan tertahan di Box Trapper, configurasi standar setelah 15 hari email2 SPAM di hapus, demikian juga kalau 15 Hari email yang harusnya bukan spam belum di whitelist juga akan terhapus.&lt;/domain&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-5070177568479533854?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/5070177568479533854/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=5070177568479533854' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5070177568479533854'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5070177568479533854'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/cara-mengaktifkan-box-trapper-untuk.html' title='Cara Mengaktifkan Box-Trapper Untuk Menyaring SPAM di Cpanel'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_nzWcXcVYSRs/SMTl9Ib6itI/AAAAAAAAALo/8Z80KQJRGWo/s72-c/image001.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-1467685433799068009</id><published>2008-09-05T23:12:00.002+07:00</published><updated>2008-09-05T23:15:00.693+07:00</updated><title type='text'>Cara repair semua table pada beberapa database di mysql</title><content type='html'>Jika database mysql mengalami kerusakan coba ketik perintah ini:&lt;br /&gt;&lt;br /&gt;mysqlcheck --repair --all-databases -u root -p&lt;br /&gt;&lt;br /&gt;contoh sbb:&lt;br /&gt;&lt;br /&gt;ns3:/var/log# mysqlcheck --repair --all-databases -u root -p&lt;br /&gt;Enter password:xxxxx&lt;br /&gt;&lt;br /&gt;maka semua table dan database akan di repair&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-1467685433799068009?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/1467685433799068009/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=1467685433799068009' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/1467685433799068009'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/1467685433799068009'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/cara-repair-semua-table-pada-beberapa.html' title='Cara repair semua table pada beberapa database di mysql'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-2331682553631993184</id><published>2008-09-05T14:09:00.004+07:00</published><updated>2008-09-05T14:13:09.011+07:00</updated><title type='text'>Mengedit /etc/fstab ketika root termounted sebagai readonly</title><content type='html'>Barusan saya menghadapi masalah di /etc/fstab karena ada hdd external yang fail sewaktu system di reboot sehingga mengakibatkan process booting stop setelah pengecekkan partisi dan langsung masuk ke mode single user.&lt;br /&gt;&lt;br /&gt;logikanya sih tinggal edit /etc/fstab tapi masalah /etc/fstab readonly tidak bisa diedit&lt;br /&gt;setelah cari-cari di google.com akhirnya saya dapatkan perintah ini&lt;br /&gt;&lt;br /&gt;mount -o remount,rw /&lt;br /&gt;&lt;br /&gt;baru kemudian file /etc/fstab di edit&lt;br /&gt;dan ...&lt;br /&gt;akhirnya sistem bisa di booting dengan normal kembali&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-2331682553631993184?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/2331682553631993184/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=2331682553631993184' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2331682553631993184'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2331682553631993184'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/mengedit-etcfstab-ketika-root.html' title='Mengedit /etc/fstab ketika root termounted sebagai readonly'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-2259882475910600572</id><published>2008-09-03T19:48:00.002+07:00</published><updated>2008-09-03T19:52:33.651+07:00</updated><title type='text'>Cara add rule allow_hosts.rules di apf</title><content type='html'>Setelah menggunakan APF terbaru ternyata cara masukkin ip dan port yang di allow caranya harus pakai command, contoh jika ingin selalu mengizinkan ip 1.1.1.1 perintahnya sbb:&lt;br /&gt;&lt;br /&gt;apf -a 1.1.1.1&lt;br /&gt;&lt;br /&gt;dengan demikian di /etc/apf/allow_hosts.rules akan terdapat:&lt;br /&gt;&lt;br /&gt;# added 10.0.0.0/8 on 09/03/08 19:47:02 with comment:&lt;br /&gt;1.1.1.1&lt;br /&gt;&lt;br /&gt;setelah itu restart service apf dengan cara:&lt;br /&gt;&lt;br /&gt;service apf restart&lt;br /&gt;&lt;br /&gt;maka ip 1.1.1.1 akan selalu di allow&lt;br /&gt;&lt;br /&gt;jika kita edit secara manual /etc/apf/allow_hosts.rules maka baris yang kita masukkan selalu akan dihapus lagi oleh apf secara otomatis, oleh karena itu harus pakai command spt di dokumen README.apf berikut:&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;4) General Usage:&lt;br /&gt;The /usr/local/sbin/apf command has a number of options that will ease the&lt;br /&gt;day-to-day use of your firewall. Here is a quick snap-shot of the options:&lt;br /&gt;&lt;br /&gt;usage /usr/local/sbin/apf [OPTION]&lt;br /&gt;-s|--start ......................... load the firewall rules&lt;br /&gt;-r|--restart ....................... stop (flush) &amp;amp; reload firewall rules&lt;br /&gt;-f|--stop .......................... stop (flush) all firewall rules&lt;br /&gt;-l|--list .......................... list chain rules&lt;br /&gt;-t|--status ........................ firewall status&lt;br /&gt;-e|--refresh ....................... refresh &amp;amp; resolve dns names in trust rules&lt;br /&gt;-a HOST CMT|--allow HOST COMMENT ... add host (IP/FQDN) to allow_hosts.rules and&lt;br /&gt;                                    immediately load new rule into firewall&lt;br /&gt;-d HOST CMT|--deny HOST COMMENT .... add host (IP/FQDN) to deny_hosts.rules and&lt;br /&gt;                                    immediately load new rule into firewall&lt;br /&gt;-u|--remove HOST ................... remove host from [glob_]deny_hosts.rules&lt;br /&gt;                                    and immediately remove rule from firewall&lt;br /&gt;-o|--ovars ......................... output all configuration options&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-2259882475910600572?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/2259882475910600572/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=2259882475910600572' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2259882475910600572'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2259882475910600572'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/cara-add-rule-allowhostsrules-di-apf.html' title='Cara add rule allow_hosts.rules di apf'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-8968512124422325067</id><published>2008-09-03T19:22:00.002+07:00</published><updated>2008-09-03T19:31:43.333+07:00</updated><title type='text'>Bagaimana caranya melihat spesifikasi hardware di linux lewat command line</title><content type='html'>seringkali suatu saat seorang admin harus meng-upgrade memory , nah urusannya jadi runyam kalau lupa type ram nya itu ddr atau ddr2 dan pcxxx ? nah utk server linux ternyata caranya mudah , cukup menjalankan command :&lt;br /&gt;&lt;br /&gt;dmidecode&lt;br /&gt;&lt;br /&gt;hasilnya sbb:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Handle 0x0001&lt;br /&gt;        DMI type 1, 25 bytes.&lt;br /&gt;        System Information&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;                Manufacturer: Supermicro =&gt; Merek Motherboard&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;                Product Name: X5DPA-TGM+ =&gt; Type Motherboard&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Memory 4 Keping @512MB bisa dilihat dari keterangan berikut ini:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Handle 0x000D&lt;br /&gt;        DMI type 6, 12 bytes.&lt;br /&gt;        Memory Module Information&lt;br /&gt;                Socket Designation: DIMM1&lt;br /&gt;                Bank Connections: 0 0&lt;br /&gt;                Current Speed: 4 ns&lt;br /&gt;                Type: ECC DIMM&lt;br /&gt;                Installed Size: 512 MB (Single-bank Connection)&lt;br /&gt;                Enabled Size: 512 MB (Single-bank Connection)&lt;br /&gt;                Error Status: OK&lt;br /&gt;Handle 0x000E&lt;br /&gt;        DMI type 6, 12 bytes.&lt;br /&gt;        Memory Module Information&lt;br /&gt;                Socket Designation: DIMM2&lt;br /&gt;                Bank Connections: 0 1&lt;br /&gt;                Current Speed: 4 ns&lt;br /&gt;                Type: ECC DIMM&lt;br /&gt;                Installed Size: 512 MB (Single-bank Connection)&lt;br /&gt;                Enabled Size: 512 MB (Single-bank Connection)&lt;br /&gt;                Error Status: OK&lt;br /&gt;Handle 0x000F&lt;br /&gt;        DMI type 6, 12 bytes.&lt;br /&gt;        Memory Module Information&lt;br /&gt;                Socket Designation: DIMM3&lt;br /&gt;                Bank Connections: 0 2&lt;br /&gt;                Current Speed: 4 ns&lt;br /&gt;                Type: ECC DIMM&lt;br /&gt;                Installed Size: 512 MB (Single-bank Connection)&lt;br /&gt;                Enabled Size: 512 MB (Single-bank Connection)&lt;br /&gt;                Error Status: OK&lt;br /&gt;Handle 0x0010&lt;br /&gt;        DMI type 6, 12 bytes.&lt;br /&gt;        Memory Module Information&lt;br /&gt;                Socket Designation: DIMM4&lt;br /&gt;                Bank Connections: 0 3&lt;br /&gt;                Current Speed: 4 ns&lt;br /&gt;                Type: ECC DIMM&lt;br /&gt;                Installed Size: 512 MB (Single-bank Connection)&lt;br /&gt;                Enabled Size: 512 MB (Single-bank Connection)&lt;br /&gt;                Error Status: OK&lt;br /&gt;&lt;br /&gt;nah utk lebih tepatnya type memory tinggal browsing-browsing di goole.com type motherboard tersebut memorynya type apa dan maksimum berapa GB?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Supermicro X5DPA-TGM Intel E7501 Dual Xeon 533MHz FSB Dual Channel DDR266 Socket 604 ATX Server Board with ATI Video, Dual LAN, USB, SATA, RAID&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Memory Type        DDR266/200 registered ECC SDRAM 72-bit, 184-pin gold-plated DIMMs&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-8968512124422325067?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/8968512124422325067/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=8968512124422325067' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/8968512124422325067'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/8968512124422325067'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/09/bagaimana-caranya-melihat-spesifikasi.html' title='Bagaimana caranya melihat spesifikasi hardware di linux lewat command line'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-3221521966547178201</id><published>2008-08-29T20:08:00.000+07:00</published><updated>2008-08-29T20:09:25.406+07:00</updated><title type='text'>VLAN di Fedora</title><content type='html'>&lt;h3 class="enplocal"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;802.1Q VLAN Prerequisites&lt;/span&gt;&lt;/h3&gt; &lt;p&gt; &lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;802.1Q-Tagged VLANs require "smart" or managed Ethernet switches that support the IEEE 802.1Q standard, and the drivers for your Ethernet interfaces must also support it. You should be able to mix-and-match brand names, as long as they support 802.1Q. Beware of proprietary VLAN tagging that only works within a single brand. If it says 802.1Q you should be OK. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;802.1Q has been supported by the Linux kernel for a long time, thanks to Ben Greear, maintainer of the &lt;a href="http://www.candelatech.com/%7Egreear/"&gt;802.1Q VLAN implementation for Linux&lt;/a&gt;. You shouldn't have to patch your kernel or jump through any weirdo hoops. It's easy enough to check by searching your relevant kernel &lt;i&gt;config&lt;/i&gt; file:  &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;&lt;tt&gt; $ &lt;b&gt;grep -i 8021Q /boot/config-2.6.22-14&lt;/b&gt;&lt;br /&gt;CONFIG_VLAN_8021Q=m &lt;/tt&gt;  &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;Haha! See the clever gotcha? The kernel option is 8021Q, not 802.1Q. That one about drove me nuts until I figured it out. Of course you could search on &lt;i&gt;vlan&lt;/i&gt; instead, which is probably what the smart kids do.  &lt;/span&gt;&lt;/p&gt;&lt;h3 class="enplocal"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;Creating VLAN Devices&lt;/span&gt;&lt;/h3&gt; &lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;Now we'll test an Ethernet interface to make sure we can create a virtual interface by assigning it a VLAN ID, and then temporarily assign an IP address for testing. You need the &lt;b&gt;vconfig&lt;/b&gt; command, which should be available in your Linux distribution as part of the &lt;i&gt;vlan&lt;/i&gt; package. You can use any random number for your VLAN ID, from 0-4095, since this is just a test:  &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;&lt;tt&gt; # &lt;b&gt;vconfig add eth1 55&lt;/b&gt;&lt;br /&gt;&lt;/tt&gt;  &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;That adds VLAN ID 55 to eth1. You might see this message:  &lt;/span&gt;&lt;/p&gt;&lt;blockquote&gt; &lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;WARNING:  Could not open /proc/net/vlan/config.  Maybe you need to load the 8021q module, or maybe you are not using PROCFS?? Added VLAN with VID == 55 to IF -:eth1:- &lt;/span&gt;&lt;/blockquote&gt;  &lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;Nothing is wrong; it means that &lt;b&gt;vconfig&lt;/b&gt; saw that the 8021q module was not loaded, and kindly loaded it for you. Which you can see with &lt;b&gt;lsmod&lt;/b&gt;:  &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;&lt;tt&gt; $ &lt;b&gt;lsmod | grep 8021q&lt;/b&gt;&lt;br /&gt;8021q   21768  0 &lt;/tt&gt;  &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;Check your interface with &lt;b&gt;ifconfig&lt;/b&gt;: &lt;/span&gt;&lt;/p&gt;&lt;pre&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;$ &lt;b&gt;ifconfig -a&lt;/b&gt;&lt;br /&gt;[...]&lt;br /&gt;eth1.55   Link encap:Ethernet  HWaddr 00:0B:6A:EF:7E:8D&lt;br /&gt;         BROADCAST MULTICAST  MTU:1500  Metric:1&lt;br /&gt;         RX packets:0 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;         TX packets:0 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;         collisions:0 txqueuelen:0&lt;br /&gt;         RX bytes:0 (0.0 b)  TX bytes:0 (0.0 b)&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;  &lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;The interface is not up, and it has not been assigned an address. Use the &lt;b&gt;ifconfig&lt;/b&gt; command for this:  &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;&lt;tt&gt; # &lt;b&gt;ifconfig eth1.55 192.168.10.100 netmask 255.255.255.0 up&lt;/b&gt; &lt;/tt&gt;  &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;Remove a VLAN ID this way:  &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;&lt;tt&gt; # &lt;b&gt;ifconfig eth1.55 down&lt;/b&gt;&lt;br /&gt;# &lt;b&gt;vconfig rem eth1.55&lt;/b&gt;&lt;br /&gt;Removed VLAN -:eth1.55:- &lt;/tt&gt;  &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;So you can see there is a little bit of command syntax trickiness- &lt;b&gt;add&lt;/b&gt; adds a VLAN ID, and &lt;b&gt;rem&lt;/b&gt; removes a VLAN device. You can capture useful information on your VLAN interfaces by reading their corresponding &lt;i&gt;/proc&lt;/i&gt; files:  &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:-1;"&gt;&lt;tt&gt; # &lt;b&gt;cat /proc/net/vlan/eth1.55&lt;/b&gt;&lt;/tt&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: monospace;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Sumber:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: monospace;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="http://www.enterprisenetworkingplanet.com/netsysm/print.php/3725881"&gt;http://www.enterprisenetworkingplanet.com/netsysm/print.php/3725881&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-3221521966547178201?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/3221521966547178201/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=3221521966547178201' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3221521966547178201'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3221521966547178201'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/08/vlan-di-fedora.html' title='VLAN di Fedora'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-2634183108490118228</id><published>2008-08-12T12:35:00.004+07:00</published><updated>2008-08-12T15:42:11.736+07:00</updated><title type='text'>Memfilter spam dari CNN.COM</title><content type='html'>Tambah hari tambah banyak aja spam :(&lt;br /&gt;baru-baru ini sering banget yang kirim email dengan subject:&lt;br /&gt;&lt;br /&gt;CNN.com Daily Top 10&lt;br /&gt;CNN Alerts: My Custom Alert&lt;br /&gt;&lt;br /&gt;saya coba memfilter email-email itu di MTA karena untuk unsubscribe ribet banget dan kesannya menjebak karena sebelumnya emang gak subscribe.&lt;br /&gt;&lt;br /&gt;ini caranya mem-filter subject di postfix&lt;br /&gt;&lt;br /&gt;edit file /etc/postfix/header_checks&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;/^Subject: CNN\.com Daily Top 10/ REJECT Spam header rule (1)&lt;br /&gt;/^Subject: CNN Alerts\: My Custom Alert/ REJECT Spam header rule (2)&lt;br /&gt;/^Subject: .*Mariola has sent you a message\.\.\./ REJECT Spam Header rule (3)&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;lalu save&lt;br /&gt;&lt;br /&gt;dan restart postfix&lt;br /&gt;&lt;br /&gt;untuk exim + cpanel saya coba tambahkan di&lt;br /&gt;&lt;br /&gt;/etc/cpanel_exim_system_filter&lt;br /&gt;&lt;br /&gt;baris berikut:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;# Exim filter&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;  if $header_subject: contains "CNN.com Daily Top 10" or&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;     $header_subject: contains "CNN Alerts: My Custom Alert"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;then&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;  fail text "This message has been rejected because it has\n\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;             blacklist subject."&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;  seen finish&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;endif&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;lalu restart exim dan cpanelnya&lt;br /&gt;&lt;br /&gt;semoga cara ini cukup efektif&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-2634183108490118228?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/2634183108490118228/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=2634183108490118228' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2634183108490118228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2634183108490118228'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/08/memfilter-spam-dari-cnncom.html' title='Memfilter spam dari CNN.COM'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-1899859209005371182</id><published>2008-08-11T14:53:00.007+07:00</published><updated>2008-08-11T15:01:13.258+07:00</updated><title type='text'>Menambahkan Disclaimer / Footnote pada setiap email yang dikirim via postfix</title><content type='html'>Bermula dari keinginan menambahkan footnote pada setiap email yang dikirim melalui smtp.datautama.net.id saya menemukan aplikasi "AlterMIME" yang dapat di download dari:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pldaniels.com/altermime/#download"&gt;&lt;br /&gt;http://www.pldaniels.com/altermime/#download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Sedangkan cara instalasi dan konfigurasi ada di:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://web.archive.org/web/20070509024905/www.paw.za.org/docs/howtos/postfix-altermime/postfix-altermime-howto-2.html"&gt;http://web.archive.org/web/20070509024905/www.paw.za.org/docs/howtos/postfix-altermime/postfix-altermime-howto-2.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-1899859209005371182?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/1899859209005371182/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=1899859209005371182' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/1899859209005371182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/1899859209005371182'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/08/menambahkan-disclaimer-footnote-pada.html' title='Menambahkan Disclaimer / Footnote pada setiap email yang dikirim via postfix'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-4354332191987777368</id><published>2008-08-04T17:24:00.001+07:00</published><updated>2008-08-04T17:26:13.678+07:00</updated><title type='text'>Konfigure SSL apache2 di Debian 4.0</title><content type='html'>Tidak seperti &lt;a href="http://wiki.linux.or.id/index.php?title=Apache&amp;amp;action=edit" class="new" title="Apache"&gt;apache&lt;/a&gt; 1.x di &lt;a href="http://wiki.linux.or.id/Debian" title="Debian"&gt;Debian&lt;/a&gt; dengan paket apache-ssl nya, sampai saat ini tidak ada cara yang mudah untuk mengaktifkan SSL di apache2.&lt;br /&gt;&lt;br /&gt;berikut adalah link yang saya gunakan untuk mengkonfigurasi SSL di apache2&lt;br /&gt;&lt;br /&gt;&lt;a href="http://wiki.freaks-unidos.net/Apache2%20SSL%20and%20Subversion%20in%20Debian"&gt;http://wiki.freaks-unidos.net/Apache2%20SSL%20and%20Subversion%20in%20Debian&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-4354332191987777368?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/4354332191987777368/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=4354332191987777368' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/4354332191987777368'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/4354332191987777368'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/08/konfigure-ssl-apache2-di-debian-40.html' title='Konfigure SSL apache2 di Debian 4.0'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-8454839256693788595</id><published>2008-08-01T11:30:00.012+07:00</published><updated>2008-12-13T07:35:54.231+07:00</updated><title type='text'>Buku Firewall melindungi jaringan dari DDoS menggunakan Linux + Mikrotik</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SJKTFau8DcI/AAAAAAAAALA/Sb2Lxca68mY/s1600-h/buku-firewall.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SJKTFau8DcI/AAAAAAAAALA/Sb2Lxca68mY/s400/buku-firewall.jpg" alt="" id="BLOGGER_PHOTO_ID_5229403838615391682" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:11;"&gt;Saat ini akses &lt;i style=""&gt;Internet&lt;/i&gt; sudah menjadi kebutuhan bagi banyak industri, seiring dengan semakin banyaknya pengguna &lt;i style=""&gt;Internet&lt;/i&gt; maka permasalahan &lt;i style=""&gt;Internet&lt;/i&gt; saat ini lebih komplek dibanding 10 tahun yang lalu.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:11;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span lang="SV"  style="font-size:11;"&gt;Untuk dapat mengakses &lt;i style=""&gt;Internet&lt;/i&gt; pengguna harus terkoneksi dengan&lt;i style=""&gt; Internet Service Provider &lt;/i&gt;(ISP) yang jumlahnya semakin hari semakin banyak apalagi di kota-kota besar, belum lagi penggunaan &lt;i style=""&gt;Asymetric Digital Susbcriber Line &lt;/i&gt;(ADSL) yang terbukti sangat berpengaruh terhadap penetrasi &lt;i style=""&gt;Internet&lt;/i&gt; di kota-kota yang sudah memiliki jaringan ADSL.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span lang="SV"  style="font-size:11;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span lang="SV"  style="font-size:11;"&gt;Selain itu maraknya jaringan RT/RW Net menggunakan kabel UTP dan WiFi turut juga meramaikan penyebaran akses &lt;i style=""&gt;Internet&lt;/i&gt; dengan biaya murah dan terjangkau, belum lagi maraknya layanan &lt;i style=""&gt;hotspot&lt;/i&gt; di hotel, kampus dan tempat-tempat umum lainnya.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span lang="SV"  style="font-size:11;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span lang="SV"  style="font-size:11;"&gt;Dengan demikian akses &lt;i style=""&gt;Internet Broadband&lt;/i&gt; semakin hari semakin mudah didapat tetapi dampak dari perkembangan itu adalah semakin banyaknya permasalahan karena &lt;i style=""&gt;spam&lt;/i&gt;, &lt;i style=""&gt;virus&lt;/i&gt;, &lt;i style=""&gt;worm&lt;/i&gt; dan yang paling susah dihadapi adalah &lt;i style=""&gt;Distribute Denial Of Service&lt;/i&gt; (DDOS) mengancam setiap pengguna &lt;i style=""&gt;Internet&lt;/i&gt; di dunia.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:11;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span lang="SV"  style="font-size:11;"&gt;Kerugian yang ditimbulkan oleh DDoS bisa sangat fatal apalagi bagi ISP, Warnet atau &lt;i style=""&gt;Online Game Center&lt;/i&gt; karena berdampak pada kehilangan penghasilan dan ancaman kebangkrutan.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span lang="SV"  style="font-size:11;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span lang="SV"  style="font-size:11;"&gt;Melalui buku ini penulis mencoba untuk menjelaskan bagaimana teknik mengatasi serangan DDoS menggunakan Sistem Operasi Mikrotik dan Linux yang cukup efektif dalam mengatasi DDoS dan telah terbukti cukup ampuh melindungi jaringan Internet DatautamaNet.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span lang="SV"  style="font-size:11;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span lang="SV"  style="font-size:11;"&gt;Pada buku ”Firewall melindungi jaringan dari DDoS menggunakan Linux dan Mikrotik” penulis berasumsi pembaca telah dapat mengoperasikan sistem operasi Linux dan Mikrotik sehingga yang dibahas disini langsung pada hal-hal praktis dalam mengkonfigurasikan Linux dan Mikrotik agar bekerja sama menjadi sebuah sistem pertahanan DDoS yang memadai.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Pembahasan selengkapnya meliputi:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Mekanisme pertahanan DDoS&lt;/li&gt;&lt;li&gt;Advance Policy Firewall (APF)&lt;/li&gt;&lt;li&gt;Mod Evasive&lt;/li&gt;&lt;li&gt;Skrip Mikrotik&lt;/li&gt;&lt;li&gt;Mikrotik Firewall&lt;/li&gt;&lt;li&gt;Perlindungan Tambahan pada Honeyspot dan Uploader&lt;/li&gt;&lt;li&gt;Management Blacklist Menggunakan Webmin&lt;/li&gt;&lt;/ul&gt;Dapatkan di Toko Gramedia dan Toko buku lainnya&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;Contoh skrip dari buku bisa di download dari&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.datautama.net.id/harijanto/contoh-skrip-buku-ddos/"&gt;http://www.datautama.net.id/harijanto/contoh-skrip-buku-ddos/&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-8454839256693788595?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/8454839256693788595/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=8454839256693788595' title='9 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/8454839256693788595'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/8454839256693788595'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/08/buku-firewall-melindungi-jaringan-dari.html' title='Buku Firewall melindungi jaringan dari DDoS menggunakan Linux + Mikrotik'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_nzWcXcVYSRs/SJKTFau8DcI/AAAAAAAAALA/Sb2Lxca68mY/s72-c/buku-firewall.jpg' height='72' width='72'/><thr:total>9</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-8237661690739744044</id><published>2008-07-25T10:07:00.002+07:00</published><updated>2008-07-25T10:09:49.971+07:00</updated><title type='text'>Check Your DNS</title><content type='html'>Ngurus Internet tambah ribet barusan ada emai ttg Cache DNS Poisoning dan ada satu link yang menarik utk melakukan pengecekkan apakah DNS kita jelek atau bagus, linknya tinggal di klik dibawah ini:&lt;br /&gt;&lt;a href="http://entropy.dns-oarc.net/test/"&gt;&lt;br /&gt;http://entropy.dns-oarc.net/test/&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;DNS ku masih kurang bagus hiks, nambahin kerjaan aja tar deh aku coba cari caranya supaya jadi GREAT semua&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-8237661690739744044?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/8237661690739744044/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=8237661690739744044' title='2 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/8237661690739744044'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/8237661690739744044'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/07/check-your-dns.html' title='Check Your DNS'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-6453637643808927795</id><published>2008-07-16T18:37:00.008+07:00</published><updated>2008-12-13T07:35:55.887+07:00</updated><title type='text'>Jika Email server di tolak oleh Yahoo.com</title><content type='html'>Jika email-email dari email server kita di tolak oleh yahoo coba cek dulu log filenya&lt;br /&gt;&lt;br /&gt;contoh&lt;br /&gt;&lt;br /&gt;2008-07-16 18:31:24 1KJ2wt-0005K6-M5 SMTP error from remote mail server after initial connection: host a.mx.mail.yahoo.com [209.191.118.103]: 421 Message from (203.89.24.34) temporarily deferred - 4.16.50. Please refer to http://help.yahoo.com/help/us/mail/defer/defer-06.html&lt;br /&gt;&lt;br /&gt;maka coba buka &lt;a href="http://help.yahoo.com/help/us/mail/defer/defer-06.html"&gt;http://help.yahoo.com/help/us/mail/defer/defer-06.html&lt;/a&gt;&lt;br /&gt;dengan browser&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/SH3d0gI2eUI/AAAAAAAAAKI/eq33sImFCg8/s1600-h/421-message-temporarily-deferred.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/SH3d0gI2eUI/AAAAAAAAAKI/eq33sImFCg8/s400/421-message-temporarily-deferred.JPG" alt="" id="BLOGGER_PHOTO_ID_5223575036869638466" border="0" /&gt;&lt;/a&gt;lalu pilih:&lt;br /&gt;&lt;br /&gt;If your mail server does not primarily send bulk mailings (e.g., you run a personal, corporate, educational, or ISP mail server), please &lt;a href="http://help.yahoo.com/l/us/yahoo/mail/postmaster/defer.html" class="bb-url"&gt;fill out this form&lt;/a&gt; instead.&lt;br /&gt;Isilah form itu dengan data-data yang diminta&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/SH3d03DA_jI/AAAAAAAAAKQ/rLWW8J0yCRQ/s1600-h/yahoo-mail-delirvery-issues-form.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/SH3d03DA_jI/AAAAAAAAAKQ/rLWW8J0yCRQ/s400/yahoo-mail-delirvery-issues-form.JPG" alt="" id="BLOGGER_PHOTO_ID_5223575043019177522" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/SH3d01Wg-qI/AAAAAAAAAKY/w3MXd4F42pI/s1600-h/yahoo-mail-delirvery-issues-form-b.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/SH3d01Wg-qI/AAAAAAAAAKY/w3MXd4F42pI/s400/yahoo-mail-delirvery-issues-form-b.JPG" alt="" id="BLOGGER_PHOTO_ID_5223575042564094626" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SH3d1NQBXhI/AAAAAAAAAKg/9N6HBu_ef2M/s1600-h/yahoo-mail-delirvery-issues-form-c.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SH3d1NQBXhI/AAAAAAAAAKg/9N6HBu_ef2M/s400/yahoo-mail-delirvery-issues-form-c.JPG" alt="" id="BLOGGER_PHOTO_ID_5223575048979308050" border="0" /&gt;&lt;/a&gt;Lalu send&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/SH3d1JRMzeI/AAAAAAAAAKo/GbGT9WooZ4g/s1600-h/yahoo-mail-delirvery-issues-form-d.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/SH3d1JRMzeI/AAAAAAAAAKo/GbGT9WooZ4g/s400/yahoo-mail-delirvery-issues-form-d.JPG" alt="" id="BLOGGER_PHOTO_ID_5223575047910510050" border="0" /&gt;&lt;/a&gt;Kemudian kita akan menerima email dari abuse-admin@cc.yahoo-inc.com&lt;br /&gt;yang isinya:&lt;br /&gt;&lt;br /&gt;subject: Auto Confirmation - Your Yahoo! Mail support request was received  (KMM74480709V8183L0KM)&lt;br /&gt;&lt;pre wrap=""&gt;Hello,&lt;br /&gt;&lt;br /&gt;This is an automated message regarding your recent request for Yahoo!&lt;br /&gt;Mail Customer Care support. We have received your message and will&lt;br /&gt;respond within the next 48 hours with an answer.&lt;br /&gt;&lt;br /&gt;Thank you for reaching out to us. We look forward to helping you!&lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;&lt;br /&gt;Yahoo! Customer Care&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;**Please do not respond to this message as no one will receive it.&lt;/pre&gt;&lt;br /&gt;Selain itu kalau email yang kita kirim ke yahoo masuk ke bulk coba isi form berikut:&lt;br /&gt;&lt;a href="http://help.yahoo.com/l/us/yahoo/mail/postmaster/bulk.html"&gt;http://help.yahoo.com/l/us/yahoo/mail/postmaster/bulk.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/SH6xRO5SixI/AAAAAAAAAK4/gDB3XXQa0e0/s1600-h/yahoo-bulk-form.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/SH6xRO5SixI/AAAAAAAAAK4/gDB3XXQa0e0/s400/yahoo-bulk-form.JPG" alt="" id="BLOGGER_PHOTO_ID_5223807527410633490" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;semoga yahoo bisa menerima email-email dari email server kita&lt;br /&gt;&lt;br /&gt;Jangan lupa juga cek di http://www.spamhaus.org/query/bl?ip=203.89.24.34&lt;br /&gt;dengan mengisi ip = ip address email server kita&lt;br /&gt;kalau terblacklist lakukan release&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/SH3fRg_1N_I/AAAAAAAAAKw/CctVz83v9T8/s1600-h/spamhaus.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/SH3fRg_1N_I/AAAAAAAAAKw/CctVz83v9T8/s400/spamhaus.JPG" alt="" id="BLOGGER_PHOTO_ID_5223576634828077042" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-6453637643808927795?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/6453637643808927795/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=6453637643808927795' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6453637643808927795'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/6453637643808927795'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/07/jika-email-server-di-tolak-oleh.html' title='Jika Email server di tolak oleh Yahoo.com'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_nzWcXcVYSRs/SH3d0gI2eUI/AAAAAAAAAKI/eq33sImFCg8/s72-c/421-message-temporarily-deferred.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-7004790881445755661</id><published>2008-07-15T15:39:00.004+07:00</published><updated>2008-12-13T07:35:56.368+07:00</updated><title type='text'>WARNING ARP Spoof mengancam Jaringan</title><content type='html'>Barusan salah satu klient di gedung maspion bermasalah setelah di selidiki dengan seksama coba perhatikan gambar dibawah ini:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHxjBXKuomI/AAAAAAAAAJ4/v1NtQLv3xo4/s1600-h/maspion-ancol-enable.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHxjBXKuomI/AAAAAAAAAJ4/v1NtQLv3xo4/s400/maspion-ancol-enable.JPG" alt="" id="BLOGGER_PHOTO_ID_5223158542892966498" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Perhatikan bagian yang di sorot: ip 192.168.0.64 yang merupakan ip notebook support pada saat link ke ancol di enable mac nya menjadi 00:13:8F:02:E0:64,  juga untuk ip  192.168.0.1 , 192.168.0.2 dst. Aneh bukan satu mac  dimiliki banyak IP, jika itu ip alias mungking-mungkin saja tetapi begitu link ancol didisable lihat gambar dibawah&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SHxjBnck7eI/AAAAAAAAAKA/YW2Sp8_ezOY/s1600-h/maspion-ancol-disable.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SHxjBnck7eI/AAAAAAAAAKA/YW2Sp8_ezOY/s400/maspion-ancol-disable.JPG" alt="" id="BLOGGER_PHOTO_ID_5223158547262795234" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;IP 192.168.0.64 memiliki MAC= 00:03:47:8B:DF:B9 nah loh! dan pada saat link ancol didisable LAN menjadi normal .&lt;br /&gt;&lt;br /&gt;Sebelumnya sudah saya announce ke support jakarta ada virus baru yang memanipulasi arp table &lt;a href="http://vaksin.com/2008/0608/microsoft2/arp-spoofing.html"&gt;http://vaksin.com/2008/0608/microsoft2/arp-spoofing.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Nah loh gimana cara atasinya, menurut vaksin.com cukup dengan menstatiskan table ip dan mac nya satu satu di router dan di komputer :( selamat deh&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-7004790881445755661?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/7004790881445755661/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=7004790881445755661' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/7004790881445755661'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/7004790881445755661'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/07/warning-arp-spoof-mengancam-jaringan.html' title='WARNING ARP Spoof mengancam Jaringan'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_nzWcXcVYSRs/SHxjBXKuomI/AAAAAAAAAJ4/v1NtQLv3xo4/s72-c/maspion-ancol-enable.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-3759046262273449200</id><published>2008-07-08T19:53:00.002+07:00</published><updated>2008-07-08T20:32:28.813+07:00</updated><title type='text'>Flush cache dns di hosting cpanel</title><content type='html'>Kadang kalau saya rubah zone file di nameserver hosting cache yang lama selalu saja tidak mau hilang beruntung saya menemukan artikel ini:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.linuxquestions.org/questions/linux-networking-3/display-and-flush-dns-cache-303314/"&gt;http://www.linuxquestions.org/questions/linux-networking-3/display-and-flush-dns-cache-303314/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hello,&lt;br /&gt;I have a computer assignment and I need the right command in linux. I need to display recent DNS records and clear them whenever I want. In windows "ipconfig /displaydns" and "ipconfig /flushdns" commands are used respectively. Are there any commands in linux which are equivalent to these ones? or in Linux isn't there such an option? Can "ifconfig" solve this problem? If yes what should be the exact options and command line?&lt;br /&gt;Hello,&lt;br /&gt;&lt;br /&gt;to flush the DNS I use "/etc/init.d/nscd restart"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-3759046262273449200?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/3759046262273449200/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=3759046262273449200' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3759046262273449200'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3759046262273449200'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/07/flush-cache-dns-di-hosting-cpanel.html' title='Flush cache dns di hosting cpanel'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-4443582658316240159</id><published>2008-07-08T18:37:00.003+07:00</published><updated>2008-12-13T07:35:58.114+07:00</updated><title type='text'>Panduan singkat penggunaan Postfixadmin</title><content type='html'>Panduan singkat Postfix Admin    &lt;p class="MsoNormal"&gt;Untuk login sebagai admin &lt;/p&gt;  &lt;p class="MsoNormal"&gt;http://ipserver&lt;ipserver&gt;&lt;ipserver&gt;/postfixadmin&lt;/ipserver&gt;&lt;/ipserver&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shapetype id="_x0000_t75" coordsize="21600,21600" spt="75" preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"&gt;  &lt;v:stroke joinstyle="miter"&gt;  &lt;v:formulas&gt;   &lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;   &lt;v:f eqn="sum @0 1 0"&gt;   &lt;v:f eqn="sum 0 0 @1"&gt;   &lt;v:f eqn="prod @2 1 2"&gt;   &lt;v:f eqn="prod @3 21600 pixelWidth"&gt;   &lt;v:f eqn="prod @3 21600 pixelHeight"&gt;   &lt;v:f eqn="sum @0 0 1"&gt;   &lt;v:f eqn="prod @6 1 2"&gt;   &lt;v:f eqn="prod @7 21600 pixelWidth"&gt;   &lt;v:f eqn="sum @8 21600 0"&gt;   &lt;v:f eqn="prod @7 21600 pixelHeight"&gt;   &lt;v:f eqn="sum @10 21600 0"&gt;  &lt;/v:formulas&gt;  &lt;v:path extrusionok="f" gradientshapeok="t" connecttype="rect"&gt;  &lt;o:lock ext="edit" aspectratio="t"&gt; &lt;/v:shapetype&gt;&lt;v:shape id="_x0000_i1025" type="#_x0000_t75" style="'width:6in;"&gt;  &lt;v:imagedata src="file:///C:\DOCUME~1\HARIJA~1\LOCALS~1\Temp\msohtml1\01\clip_image001.jpg" title="postfixadmin-admin-login"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSRNx0eiI/AAAAAAAAAIw/bCuFOnZTZFQ/s1600-h/image001.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSRNx0eiI/AAAAAAAAAIw/bCuFOnZTZFQ/s400/image001.jpg" alt="" id="BLOGGER_PHOTO_ID_5220606848762411554" border="0" /&gt;&lt;/a&gt;&lt;!--[endif]--&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="SV"&gt;Login: admin&lt;/span&gt;&lt;span style="" lang="SV"&gt; pass  admin (atau disesuaikan dengan username dan pass yang ada)&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="" lang="SV"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SHNSVC-vYoI/AAAAAAAAAI4/S4aJlew4i5c/s1600-h/image002.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SHNSVC-vYoI/AAAAAAAAAI4/S4aJlew4i5c/s400/image002.jpg" alt="" id="BLOGGER_PHOTO_ID_5220606914583290498" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="SV"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="SV"&gt;Seorang admin bisa membuat mailbox dengan cara klik Add Mailbox dan pilih pada domain mana user tersebut akan dibuat&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSe8X1JEI/AAAAAAAAAJA/JUZmbiL4J6Q/s1600-h/image003.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSe8X1JEI/AAAAAAAAAJA/JUZmbiL4J6Q/s400/image003.jpg" alt="" id="BLOGGER_PHOTO_ID_5220607084608169026" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="" lang="SV"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="SV"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSfk3yKcI/AAAAAAAAAJg/V2z-rXF6cw0/s1600-h/image007.jpg"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="SV"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="SV"&gt;Untuk melihat secara keseluruhan klik Overview maka akan ditampilkan list domain yang di manage oleh postfixadmin&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SHNSfUtGUpI/AAAAAAAAAJI/CG8ec_aW8L8/s1600-h/image004.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SHNSfUtGUpI/AAAAAAAAAJI/CG8ec_aW8L8/s400/image004.jpg" alt="" id="BLOGGER_PHOTO_ID_5220607091139826322" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="SV"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSft7WPRI/AAAAAAAAAJY/Bw2pZsfWhwI/s1600-h/image006.jpg"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="SV"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="SV"&gt;Jika salah satu domain di klik akan ditampilkan detail mailbox yang ada&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="SV"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/SHNSfciQWWI/AAAAAAAAAJQ/RoBBRNJNacU/s1600-h/image005.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/SHNSfciQWWI/AAAAAAAAAJQ/RoBBRNJNacU/s400/image005.jpg" alt="" id="BLOGGER_PHOTO_ID_5220607093241829730" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="SV"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Untuk merubah password user, auto respond / vacation, dan auto forward bisa ke&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;http://ipserver&lt;ipserver&gt;/postfixadmin/users&lt;br /&gt;&lt;/ipserver&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Login dengan alamat email user dan password email ybs&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1030" type="#_x0000_t75" style="'width:6in;height:259.5pt'"&gt;  &lt;v:imagedata src="file:///C:\DOCUME~1\HARIJA~1\LOCALS~1\Temp\msohtml1\01\clip_image011.jpg" title="postfixadmin-admin-login6"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSft7WPRI/AAAAAAAAAJY/Bw2pZsfWhwI/s1600-h/image006.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSft7WPRI/AAAAAAAAAJY/Bw2pZsfWhwI/s400/image006.jpg" alt="" id="BLOGGER_PHOTO_ID_5220607097910476050" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;!--[endif]--&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="SV"&gt;Maka akan tampil menu diatas&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="SV"&gt;Autoresponse utk feedback otomatis kalau ybs sedang berlibur misalnya&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="SV"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Change forward utk merubah auto forward ke alamat emaillainnya&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1031" type="#_x0000_t75" style="'width:6in;height:259.5pt'"&gt;  &lt;v:imagedata src="file:///C:\DOCUME~1\HARIJA~1\LOCALS~1\Temp\msohtml1\01\clip_image013.jpg" title="postfixadmin-admin-login7"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSfk3yKcI/AAAAAAAAAJg/V2z-rXF6cw0/s1600-h/image007.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSfk3yKcI/AAAAAAAAAJg/V2z-rXF6cw0/s400/image007.jpg" alt="" id="BLOGGER_PHOTO_ID_5220607095479609794" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;!--[endif]--&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="IT"&gt;Diatas adalah contoh auto response, isi surat bisa diedit sesuai selera&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="IT"&gt;Kemudian klik Going Away, utk menonaktifkn auto response klik lagi menu auto response dan klik going back&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSoGhIRuI/AAAAAAAAAJo/d6XJCOFIJng/s1600-h/image008.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSoGhIRuI/AAAAAAAAAJo/d6XJCOFIJng/s400/image008.jpg" alt="" id="BLOGGER_PHOTO_ID_5220607241950349026" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="IT"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSoQkHsqI/AAAAAAAAAJw/LSyt_Su0gjE/s1600-h/image009.jpg"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="IT"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="IT"&gt;Untuk forward bisa diisi alamat email yang dijadikan forwarding&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="IT"&gt;Kemudianklik Edit Alias&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="IT"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSoQkHsqI/AAAAAAAAAJw/LSyt_Su0gjE/s1600-h/image009.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSoQkHsqI/AAAAAAAAAJw/LSyt_Su0gjE/s400/image009.jpg" alt="" id="BLOGGER_PHOTO_ID_5220607244647248546" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="IT"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="IT"&gt;Untuk merubah password klik Change password&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="IT"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="" lang="IT"&gt;&lt;span style=""&gt; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-4443582658316240159?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/4443582658316240159/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=4443582658316240159' title='2 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/4443582658316240159'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/4443582658316240159'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/07/panduan-singkat-penggunaan-postfixadmin.html' title='Panduan singkat penggunaan Postfixadmin'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_nzWcXcVYSRs/SHNSRNx0eiI/AAAAAAAAAIw/bCuFOnZTZFQ/s72-c/image001.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-4634184610502896869</id><published>2008-07-08T16:20:00.011+07:00</published><updated>2008-07-09T00:15:17.407+07:00</updated><title type='text'>Email Server Postfix dengan Postfixadmin</title><content type='html'>Berikut adalah step-by-step pembuatan Email Server berbasis Postfix dengan postfixadmin&lt;br /&gt;&lt;br /&gt;Referensi yang saya baca adalah dari:&lt;br /&gt;&lt;a href="https://help.ubuntu.com/community/PostfixCompleteVirtualMailSystemHowto"&gt;https://help.ubuntu.com/community/PostfixCompleteVirtualMailSystemHowto&lt;/a&gt;&lt;br /&gt;&lt;a href="http://workaround.org/articles/ispmail-sarge/index.shtml.en"&gt;http://workaround.org/articles/ispmail-sarge/index.shtml.en&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.purplehat.org/?page_id=11"&gt;http://www.purplehat.org/?page_id=11&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Distro yang digunakan adalah Debian 4.0 rc3&lt;br /&gt;&lt;br /&gt;Step 1&lt;br /&gt;Install debian menggunakan netinst cd&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Step 2&lt;br /&gt;remove exim4 yang merupakan MTA standar bawaan debian&lt;br /&gt;&lt;br /&gt;Step3&lt;br /&gt;Install postfix:&lt;br /&gt;#apt-get install postfix&lt;br /&gt;pada saat proses install pilih "Internet Site"&lt;br /&gt;&lt;br /&gt;Step4&lt;br /&gt;Install Mysql map support untuk Postfix&lt;br /&gt;#apt-get install postfix-mysql&lt;br /&gt;#apt-get install mysq-client&lt;br /&gt;#apt-get install mysql-server&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Step5&lt;br /&gt;Install Paket-paket untuk Client Access dan Authentication&lt;br /&gt;#apt-get install courier-authdaemon&lt;br /&gt;#apt-get install courier-authlib-mysql&lt;br /&gt;&lt;br /&gt;#apt-get install courier-pop&lt;br /&gt;pada saat proses install pilih "create directories for web-based administration = No"&lt;br /&gt;&lt;br /&gt;#apt-get install courier-webadmin&lt;br /&gt;pada saat proses install pilih "Activated CGI Program = No"&lt;br /&gt;Password courier administration, misal = 123456&lt;br /&gt;&lt;br /&gt;#apt-get install courier-pop-ssl&lt;br /&gt;#apt-get install courier-imap&lt;br /&gt;#apt-get install courier-imap-ssl&lt;br /&gt;&lt;br /&gt;Step 6&lt;br /&gt;Install Paket-paket untuk SMTP authentication&lt;br /&gt;#apt-get install postfix-tls&lt;br /&gt;#apt-get install libsasl2&lt;br /&gt;#apt-get install libsasl2-modules&lt;br /&gt;#apt-get install libsasl2-modules-sql&lt;br /&gt;#apt-get install openssl&lt;br /&gt;&lt;br /&gt;"Jangan lupa buat SSL Certificate untuk  TLS to encrypt SMTP traffic"&lt;br /&gt;&lt;p&gt; For a certificate that is valid for ten years for the hostname smtp.domain.tld you would type this: &lt;/p&gt;&lt;pre class="screen"&gt;openssl req -new -outform PEM -out /etc/postfix/smtpd.cert -newkey rsa:2048 \&lt;br /&gt;-nodes -keyout /etc/postfix/smtpd.key -keyform PEM -days 3650 -x509&lt;br /&gt;&lt;/pre&gt;&lt;p&gt; You will then be asked a few question about the fields of the certificate. It does not matter what you enter. Just fill the fields. One exception though - the "Common Name" must be the hostname of your mail server. Example session: &lt;/p&gt;&lt;pre class="screen"&gt;Country Name (2 letter code) [AU]:&lt;span class="emphasis"&gt;&lt;em&gt;ID&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;State or Province Name (full name) [Some-State]:&lt;span class="emphasis"&gt;&lt;em&gt;DKI-Jakarta&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;Locality Name (eg, city) []:&lt;span class="emphasis"&gt;&lt;em&gt;Jakarta&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;Organization Name (eg, company) [Internet Widgits Pty Ltd]:&lt;span class="emphasis"&gt;&lt;em&gt;PT. Data Utama Dinamika&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;Organizational Unit Name (eg, section) []:&lt;span style="font-family:mon;"&gt;&lt;span style="font-style: italic;"&gt;IT&lt;/span&gt;&lt;/span&gt;&lt;span class="emphasis"&gt;&lt;em&gt;&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;Common Name (eg, YOUR name) []:&lt;span class="emphasis"&gt;&lt;em&gt;smtp.domain.tld&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;Email Address []:&lt;span class="emphasis"&gt;&lt;em&gt;postmaster@domain.tld&lt;/em&gt;&lt;/span&gt; &lt;/pre&gt;&lt;p&gt; After a short moment you will get two files: "smtpd.key" (the private key file) and "smtpd.cert" (the certificate). &lt;/p&gt;&lt;br /&gt;&lt;br /&gt;Install php module&lt;br /&gt;#apt-get install php4&lt;br /&gt;#apt-get install php4-mysql&lt;br /&gt;#apt-get install php4-pear&lt;br /&gt;&lt;br /&gt;Install antivirus dan antispam&lt;br /&gt;#apt-get install amavis&lt;br /&gt;#apt-get install clamav&lt;br /&gt;#apt-get install clamav-daemon&lt;br /&gt;#apt-get install spamassassin&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Step 7&lt;br /&gt;Setting Mysql Backend&lt;br /&gt;Setting password root mysql, misal mysql123456&lt;br /&gt;&lt;br /&gt;#mysqladmin -u root password mysql123456&lt;br /&gt;&lt;br /&gt;Step 8&lt;br /&gt;Setting Mysql Database&lt;br /&gt;&lt;br /&gt;#mysql -u root -p&lt;br /&gt;password: mysql123456&lt;br /&gt;&lt;br /&gt;mysql&gt; CREATE DATABASE postifx;&lt;br /&gt;mysql&gt; GRANT SELECT ON postfix.* TO postfix@localhost IDENTIFIED BY 'post123456';&lt;br /&gt;mysql&gt; GRANT SELECT, INSERT, DELETE, UPDATE ON postfix.* TO postfixadmin@localhost IDENTIFIED by 'postadmin123456'&lt;br /&gt;mysql&gt; flush privileges;&lt;br /&gt;mysql&gt; quit;&lt;br /&gt;&lt;br /&gt;catatan: command disebelah kanan mysql&gt; ditulis perbaris&lt;br /&gt;&lt;br /&gt;Untuk membuat table dalam database postfix salin script sql berikut, misal sebagai file postfix.sql&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;-- MySQL dump 10.11&lt;br /&gt;--&lt;br /&gt;-- Host: localhost    Database: postfix&lt;br /&gt;-- ------------------------------------------------------&lt;br /&gt;-- Server version    5.0.32-Debian_7etch4-log&lt;br /&gt;&lt;br /&gt;/*!40101 SET @OLD_CHARACTER_SET_CLIENT=@@CHARACTER_SET_CLIENT */;&lt;br /&gt;/*!40101 SET @OLD_CHARACTER_SET_RESULTS=@@CHARACTER_SET_RESULTS */;&lt;br /&gt;/*!40101 SET @OLD_COLLATION_CONNECTION=@@COLLATION_CONNECTION */;&lt;br /&gt;/*!40101 SET NAMES utf8 */;&lt;br /&gt;/*!40103 SET @OLD_TIME_ZONE=@@TIME_ZONE */;&lt;br /&gt;/*!40103 SET TIME_ZONE='+00:00' */;&lt;br /&gt;/*!40014 SET @OLD_UNIQUE_CHECKS=@@UNIQUE_CHECKS, UNIQUE_CHECKS=0 */;&lt;br /&gt;/*!40014 SET @OLD_FOREIGN_KEY_CHECKS=@@FOREIGN_KEY_CHECKS, FOREIGN_KEY_CHECKS=0 */;&lt;br /&gt;/*!40101 SET @OLD_SQL_MODE=@@SQL_MODE, SQL_MODE='NO_AUTO_VALUE_ON_ZERO' */;&lt;br /&gt;/*!40111 SET @OLD_SQL_NOTES=@@SQL_NOTES, SQL_NOTES=0 */;&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;-- Table structure for table `admin`&lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;DROP TABLE IF EXISTS `admin`;&lt;br /&gt;CREATE TABLE `admin` (&lt;br /&gt;`username` varchar(255) NOT NULL default '',&lt;br /&gt;`password` varchar(255) NOT NULL default '',&lt;br /&gt;`created` datetime NOT NULL default '0000-00-00 00:00:00',&lt;br /&gt;`modified` datetime NOT NULL default '0000-00-00 00:00:00',&lt;br /&gt;`active` tinyint(1) NOT NULL default '1',&lt;br /&gt;PRIMARY KEY  (`username`),&lt;br /&gt;KEY `username` (`username`)&lt;br /&gt;) ENGINE=MyISAM DEFAULT CHARSET=latin1 COMMENT='Postfix Admin - Virtual Admins';&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;-- Table structure for table `alias`&lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;DROP TABLE IF EXISTS `alias`;&lt;br /&gt;CREATE TABLE `alias` (&lt;br /&gt;`address` varchar(255) NOT NULL default '',&lt;br /&gt;`goto` text NOT NULL,&lt;br /&gt;`domain` varchar(255) NOT NULL default '',&lt;br /&gt;`created` datetime NOT NULL default '0000-00-00 00:00:00',&lt;br /&gt;`modified` datetime NOT NULL default '0000-00-00 00:00:00',&lt;br /&gt;`active` tinyint(1) NOT NULL default '1',&lt;br /&gt;PRIMARY KEY  (`address`),&lt;br /&gt;KEY `address` (`address`)&lt;br /&gt;) ENGINE=MyISAM DEFAULT CHARSET=latin1 COMMENT='Postfix Admin - Virtual Aliases';&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;-- Table structure for table `domain`&lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;DROP TABLE IF EXISTS `domain`;&lt;br /&gt;CREATE TABLE `domain` (&lt;br /&gt;`domain` varchar(255) NOT NULL default '',&lt;br /&gt;`description` varchar(255) NOT NULL default '',&lt;br /&gt;`aliases` int(10) NOT NULL default '0',&lt;br /&gt;`mailboxes` int(10) NOT NULL default '0',&lt;br /&gt;`maxquota` int(10) NOT NULL default '0',&lt;br /&gt;`transport` varchar(255) default NULL,&lt;br /&gt;`backupmx` tinyint(1) NOT NULL default '0',&lt;br /&gt;`created` datetime NOT NULL default '0000-00-00 00:00:00',&lt;br /&gt;`modified` datetime NOT NULL default '0000-00-00 00:00:00',&lt;br /&gt;`active` tinyint(1) NOT NULL default '1',&lt;br /&gt;PRIMARY KEY  (`domain`),&lt;br /&gt;KEY `domain` (`domain`)&lt;br /&gt;) ENGINE=MyISAM DEFAULT CHARSET=latin1 COMMENT='Postfix Admin - Virtual Domains';&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;-- Table structure for table `domain_admins`&lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;DROP TABLE IF EXISTS `domain_admins`;&lt;br /&gt;CREATE TABLE `domain_admins` (&lt;br /&gt;`username` varchar(255) NOT NULL default '',&lt;br /&gt;`domain` varchar(255) NOT NULL default '',&lt;br /&gt;`created` datetime NOT NULL default '0000-00-00 00:00:00',&lt;br /&gt;`active` tinyint(1) NOT NULL default '1',&lt;br /&gt;KEY `username` (`username`)&lt;br /&gt;) ENGINE=MyISAM DEFAULT CHARSET=latin1 COMMENT='Postfix Admin - Domain Admins';&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;-- Table structure for table `log`&lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;DROP TABLE IF EXISTS `log`;&lt;br /&gt;CREATE TABLE `log` (&lt;br /&gt;`timestamp` datetime NOT NULL default '0000-00-00 00:00:00',&lt;br /&gt;`username` varchar(255) NOT NULL default '',&lt;br /&gt;`domain` varchar(255) NOT NULL default '',&lt;br /&gt;`action` varchar(255) NOT NULL default '',&lt;br /&gt;`data` varchar(255) NOT NULL default '',&lt;br /&gt;KEY `timestamp` (`timestamp`)&lt;br /&gt;) ENGINE=MyISAM DEFAULT CHARSET=latin1 COMMENT='Postfix Admin - Log';&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;-- Table structure for table `mailbox`&lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;DROP TABLE IF EXISTS `mailbox`;&lt;br /&gt;CREATE TABLE `mailbox` (&lt;br /&gt;`username` varchar(255) NOT NULL default '',&lt;br /&gt;`password` varchar(255) NOT NULL default '',&lt;br /&gt;`name` varchar(255) NOT NULL default '',&lt;br /&gt;`maildir` varchar(255) NOT NULL default '',&lt;br /&gt;`quota` int(10) NOT NULL default '0',&lt;br /&gt;`domain` varchar(255) NOT NULL default '',&lt;br /&gt;`created` datetime NOT NULL default '0000-00-00 00:00:00',&lt;br /&gt;`modified` datetime NOT NULL default '0000-00-00 00:00:00',&lt;br /&gt;`active` tinyint(1) NOT NULL default '1',&lt;br /&gt;PRIMARY KEY  (`username`),&lt;br /&gt;KEY `username` (`username`)&lt;br /&gt;) ENGINE=MyISAM DEFAULT CHARSET=latin1 COMMENT='Postfix Admin - Virtual Mailboxes';&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;-- Table structure for table `vacation`&lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;DROP TABLE IF EXISTS `vacation`;&lt;br /&gt;CREATE TABLE `vacation` (&lt;br /&gt;`email` varchar(255) NOT NULL default '',&lt;br /&gt;`subject` varchar(255) NOT NULL default '',&lt;br /&gt;`body` text NOT NULL,&lt;br /&gt;`cache` text NOT NULL,&lt;br /&gt;`domain` varchar(255) NOT NULL default '',&lt;br /&gt;`created` datetime NOT NULL default '0000-00-00 00:00:00',&lt;br /&gt;`active` tinyint(1) NOT NULL default '1',&lt;br /&gt;PRIMARY KEY  (`email`),&lt;br /&gt;KEY `email` (`email`)&lt;br /&gt;) ENGINE=MyISAM DEFAULT CHARSET=latin1 COMMENT='Postfix Admin - Virtual Vacation';&lt;br /&gt;/*!40103 SET TIME_ZONE=@OLD_TIME_ZONE */;&lt;br /&gt;&lt;br /&gt;/*!40101 SET SQL_MODE=@OLD_SQL_MODE */;&lt;br /&gt;/*!40014 SET FOREIGN_KEY_CHECKS=@OLD_FOREIGN_KEY_CHECKS */;&lt;br /&gt;/*!40014 SET UNIQUE_CHECKS=@OLD_UNIQUE_CHECKS */;&lt;br /&gt;/*!40101 SET CHARACTER_SET_CLIENT=@OLD_CHARACTER_SET_CLIENT */;&lt;br /&gt;/*!40101 SET CHARACTER_SET_RESULTS=@OLD_CHARACTER_SET_RESULTS */;&lt;br /&gt;/*!40101 SET COLLATION_CONNECTION=@OLD_COLLATION_CONNECTION */;&lt;br /&gt;/*!40111 SET SQL_NOTES=@OLD_SQL_NOTES */;&lt;br /&gt;&lt;br /&gt;-- Dump completed on 2008-07-07  9:12:19&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;kemudian ketik&lt;br /&gt;&lt;br /&gt;#mysql -u root -p postifx &lt; size="2"&gt;&lt;br /&gt;user = postfix&lt;br /&gt;password = post123456&lt;br /&gt;hosts = 127.0.0.1&lt;br /&gt;dbname = postfix&lt;br /&gt;table = alias&lt;br /&gt;select_field = goto&lt;br /&gt;where_field = address&lt;br /&gt;&lt;br /&gt;Script "mysql_virtual_domains_maps.cf&lt;br /&gt;&lt;br /&gt;#nano /etc/postfix/mysql_virtual_domains_maps.cf&lt;br /&gt;&lt;br /&gt;lalu salin code dibawah ini&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;user = postfix&lt;br /&gt;password = post123456&lt;br /&gt;hosts = 127.0.0.1&lt;br /&gt;dbname = postfix&lt;br /&gt;table = domain&lt;br /&gt;select_field = domain&lt;br /&gt;where_field = domain&lt;br /&gt;#additional_conditions = and backupmx = '0' and active = '1'&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Script "mysql_virtual_mailbox_maps.cf"&lt;br /&gt;&lt;br /&gt;#nano /etc/postfix/mysql_virtual_mailbox_maps.cf&lt;br /&gt;&lt;br /&gt;lalu salin code dibawah ini&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;user = postfix&lt;br /&gt;password = post123456&lt;br /&gt;hosts = 127.0.0.1&lt;br /&gt;dbname = postfix&lt;br /&gt;table = mailbox&lt;br /&gt;#select_field = maildir&lt;br /&gt;select_field = CONCAT(SUBSTRING_INDEX(Username,'@',-1),'/',SUBSTRING_INDEX(Username,'@',1),'/')&lt;br /&gt;where_field = username&lt;br /&gt;#additional_conditions = and active = '1'&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Script "mysql_virtual_mailbox_limit_maps.cf"&lt;br /&gt;&lt;br /&gt;#nano /etc/postfix/mysql_virtual_mailbox_limit_maps.cf&lt;br /&gt;&lt;br /&gt;lalu salin code dibawah ini&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;user = postfix&lt;br /&gt;password = post123456&lt;br /&gt;hosts = 127.0.0.1&lt;br /&gt;dbname = postfix&lt;br /&gt;table = mailbox&lt;br /&gt;select_field = quota&lt;br /&gt;where_field = username&lt;br /&gt;#additional_conditions = and active = '1'&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Script "mysql_relay_domains_maps.cf"&lt;br /&gt;&lt;br /&gt;#nano /etc/postfix/mysql_relay_domains_maps.c&lt;br /&gt;&lt;br /&gt;lalu salin code dibawah ini&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;user = postfix&lt;br /&gt;password = post123456&lt;br /&gt;hosts = 127.0.0.1&lt;br /&gt;dbname = postfix&lt;br /&gt;table = domain&lt;br /&gt;select_field = domain&lt;br /&gt;where_field = domain&lt;br /&gt;additional_conditions = and backupmx = '1'&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Untuk keamanan rubah group dan file permission dari file-file diatas dengan cara:&lt;br /&gt;&lt;br /&gt;#chgrp postfix /etc/postfix/mysql_*.cf&lt;br /&gt;#chmod 640 /etc/postfix/mysql_*.cf&lt;br /&gt;&lt;br /&gt;Step 10&lt;br /&gt;Buat vlmail user&lt;br /&gt;Dengan system ini maka mailbox user akan disimpan di MySQL database dan di /home/vmail&lt;br /&gt;sehingga user-user email tidak perlu memiliki UID sendiri di /etc/passwd untuk itu perlu dibuat user vmai.&lt;br /&gt;&lt;br /&gt;#groupadd -g 5000 vmail&lt;br /&gt;#useradd -m -g vmail -u 5000 -d /home/vmail -s /bin/bash vmail&lt;br /&gt;&lt;br /&gt;Step 11&lt;br /&gt;Konfigurasi Postfix dengan Mysql maps&lt;br /&gt;&lt;br /&gt;berikut adalah contoh file /etc/postfix/main.cf yang saya gunakan&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;# See /usr/share/postfix/main.cf.dist for a commented, more complete version&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;# Debian specific:  Specifying a file name will cause the first&lt;br /&gt;# line of that file to be used as the name.  The Debian default&lt;br /&gt;# is /etc/mailname.&lt;br /&gt;#myorigin = /etc/mailname&lt;br /&gt;&lt;br /&gt;smtpd_banner = $myhostname ESMTP $mail_name (Debian/GNU)&lt;br /&gt;biff = no&lt;br /&gt;&lt;br /&gt;# appending .domain is the MUA's job.&lt;br /&gt;append_dot_mydomain = no&lt;br /&gt;&lt;br /&gt;# Uncomment the next line to generate "delayed mail" warnings&lt;br /&gt;#delay_warning_time = 4h&lt;br /&gt;&lt;br /&gt;# TLS parameters&lt;br /&gt;smtpd_tls_cert_file=/etc/ssl/certs/ssl-cert-snakeoil.pem&lt;br /&gt;smtpd_tls_key_file=/etc/ssl/private/ssl-cert-snakeoil.key&lt;br /&gt;smtpd_use_tls=yes&lt;br /&gt;smtpd_tls_session_cache_database = btree:${queue_directory}/smtpd_scache&lt;br /&gt;smtp_tls_session_cache_database = btree:${queue_directory}/smtp_scache&lt;br /&gt;&lt;br /&gt;# See /usr/share/doc/postfix/TLS_README.gz in the postfix-doc package for&lt;br /&gt;# information on enabling SSL in the smtp client.&lt;br /&gt;&lt;br /&gt;myhostname = email.javathebest.com&lt;br /&gt;alias_maps = hash:/etc/aliases&lt;br /&gt;myorigin = /etc/mailname&lt;br /&gt;mydestination = email.javathebest.com, localhost.javathebest.com, localhost&lt;br /&gt;relayhost =&lt;br /&gt;mynetworks = 127.0.0.0/8, 10.19.2.0/24, 10.19.3.0/24, 222.124.20.192/29, 192.168.2.0/24&lt;br /&gt;mailbox_command = procmail -a "$EXTENSION"&lt;br /&gt;mailbox_size_limit = 0&lt;br /&gt;recipient_delimiter = +&lt;br /&gt;inet_interfaces = all&lt;br /&gt;&lt;br /&gt;virtual_alias_maps = mysql:/etc/postfix/mysql_virtual_alias_maps.cf&lt;br /&gt;virtual_mailbox_domains = mysql:/etc/postfix/mysql_virtual_domains_maps.cf&lt;br /&gt;virtual_mailbox_maps = mysql:/etc/postfix/mysql_virtual_mailbox_maps.cf&lt;br /&gt;virtual_mailbox_base = /home/vmail&lt;br /&gt;virtual_uid_maps = static:5000&lt;br /&gt;virtual_gid_maps = static:5000&lt;br /&gt;&lt;br /&gt;#Additional for quota support&lt;br /&gt;&lt;br /&gt;virtual_create_maildirsize = yes&lt;br /&gt;virtual_mailbox_extended = yes&lt;br /&gt;virtual_mailbox_limit_maps = mysql:/etc/postfix/mysql_virtual_mailbox_limit_maps.cf&lt;br /&gt;virtual_mailbox_limit_override = yes&lt;br /&gt;virtual_maildir_limit_message = Sorry, the your maildir has overdrawn your diskspace quota, please free up some of space of your mailbox try again.&lt;br /&gt;virtual_overquota_bounce = yes&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;smtpd_sasl_auth_enable = yes&lt;br /&gt;broken_sasl_auth_clients = yes&lt;br /&gt;smtpd_recipient_restrictions = permit_mynetworks, permit_sasl_authenticated, reject_unauth_destination&lt;br /&gt;smtpd_tls_cert_file = /etc/postfix/smtpd.cert&lt;br /&gt;smtpd_tls_key_file = /etc/postfix/smtpd.key&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;transport_maps = hash:/etc/postfix/transport&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#Amavis&lt;br /&gt;content_filter = amavis:[127.0.0.1]:10024&lt;br /&gt;receive_override_options = no_address_mappings&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#tambahan konfigurasi utk lebih aman&lt;br /&gt;strict_rfc821_envelopes = yes&lt;br /&gt;disable_vrfy_command = yes&lt;br /&gt;smtpd_delay_reject = yes&lt;br /&gt;smtpd_helo_required = yes&lt;br /&gt;smtpd_client_restrictions =&lt;br /&gt;&lt;br /&gt;smtpd_sender_restrictions =&lt;br /&gt;permit_sasl_authenticated,&lt;br /&gt;permit_mynetworks,&lt;br /&gt;reject_non_fqdn_sender,&lt;br /&gt;reject_unknown_sender_domain,&lt;br /&gt;permit&lt;br /&gt;&lt;br /&gt;maps_rbl_domains = relays.ordb.org,&lt;br /&gt; bl.spamcop.net,&lt;br /&gt; list.dsbl.org,&lt;br /&gt; sbl-xbl.spamhaus.org&lt;br /&gt;&lt;br /&gt;smtpd_recipient_restrictions =&lt;br /&gt;reject_unauth_pipelining,&lt;br /&gt;reject_non_fqdn_recipient,&lt;br /&gt;reject_unknown_recipient_domain,&lt;br /&gt;reject_unknown_sender_domain,&lt;br /&gt;&lt;br /&gt;#localonly&lt;br /&gt;#    check_sender_access hash:/etc/postfix/restricted_senders&lt;br /&gt;#localonly&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;permit_mynetworks,&lt;br /&gt;permit_sasl_authenticated,&lt;br /&gt;reject_unauth_destination,&lt;br /&gt;#   reject_maps_rbl,&lt;br /&gt;#   reject_rbl_client relays.ordb.org,&lt;br /&gt;reject_rbl_client list.dsbl.org,&lt;br /&gt;reject_rbl_client sbl-xbl.spamhaus.org,&lt;br /&gt;permit&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#localonly&lt;br /&gt;#smtpd_restriction_classes = local_only&lt;br /&gt;#local_only =&lt;br /&gt;#   check_recipient_access hash:/etc/postfix/local_domains, reject&lt;br /&gt;#localonly  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;dan berikut adalah contoh file /etc/postfix/master.cf&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;#&lt;br /&gt;# Postfix master process configuration file.  For details on the format&lt;br /&gt;# of the file, see the master(5) manual page (command: "man 5 master").&lt;br /&gt;#&lt;br /&gt;# ==========================================================================&lt;br /&gt;# service type  private unpriv  chroot  wakeup  maxproc command + args&lt;br /&gt;#               (yes)   (yes)   (yes)   (never) (100)&lt;br /&gt;# ==========================================================================&lt;br /&gt;smtp      inet  n       -       -       -       -       smtpd&lt;br /&gt;#submission inet n       -       -       -       -       smtpd&lt;br /&gt;#  -o smtpd_enforce_tls=yes&lt;br /&gt;#  -o smtpd_sasl_auth_enable=yes&lt;br /&gt;#  -o smtpd_client_restrictions=permit_sasl_authenticated,reject&lt;br /&gt;#smtps     inet  n       -       -       -       -       smtpd&lt;br /&gt;#  -o smtpd_tls_wrappermode=yes&lt;br /&gt;#  -o smtpd_sasl_auth_enable=yes&lt;br /&gt;#  -o smtpd_client_restrictions=permit_sasl_authenticated,reject&lt;br /&gt;#628      inet  n       -       -       -       -       qmqpd&lt;br /&gt;pickup    fifo  n       -       -       60      1       pickup&lt;br /&gt;cleanup   unix  n       -       -       -       0       cleanup&lt;br /&gt;qmgr      fifo  n       -       n       300     1       qmgr&lt;br /&gt;#qmgr     fifo  n       -       -       300     1       oqmgr&lt;br /&gt;tlsmgr    unix  -       -       -       1000?   1       tlsmgr&lt;br /&gt;rewrite   unix  -       -       -       -       -       trivial-rewrite&lt;br /&gt;bounce    unix  -       -       -       -       0       bounce&lt;br /&gt;defer     unix  -       -       -       -       0       bounce&lt;br /&gt;trace     unix  -       -       -       -       0       bounce&lt;br /&gt;verify    unix  -       -       -       -       1       verify&lt;br /&gt;flush     unix  n       -       -       1000?   0       flush&lt;br /&gt;proxymap  unix  -       -       n       -       -       proxymap&lt;br /&gt;smtp      unix  -       -       -       -       -       smtp&lt;br /&gt;# When relaying mail as backup MX, disable fallback_relay to avoid MX loops&lt;br /&gt;relay     unix  -       -       -       -       -       smtp&lt;br /&gt;-o fallback_relay=&lt;br /&gt;#       -o smtp_helo_timeout=5 -o smtp_connect_timeout=5&lt;br /&gt;showq     unix  n       -       -       -       -       showq&lt;br /&gt;error     unix  -       -       -       -       -       error&lt;br /&gt;discard   unix  -       -       -       -       -       discard&lt;br /&gt;local     unix  -       n       n       -       -       local&lt;br /&gt;virtual   unix  -       n       n       -       -       virtual&lt;br /&gt;lmtp      unix  -       -       -       -       -       lmtp&lt;br /&gt;anvil     unix  -       -       -       -       1       anvil&lt;br /&gt;scache      unix    -    -    -    -    1    scache&lt;br /&gt;#&lt;br /&gt;# ====================================================================&lt;br /&gt;# Interfaces to non-Postfix software. Be sure to examine the manual&lt;br /&gt;# pages of the non-Postfix software to find out what options it wants.&lt;br /&gt;#&lt;br /&gt;# Many of the following services use the Postfix pipe(8) delivery&lt;br /&gt;# agent.  See the pipe(8) man page for information about ${recipient}&lt;br /&gt;# and other message envelope options.&lt;br /&gt;# ====================================================================&lt;br /&gt;#&lt;br /&gt;# maildrop. See the Postfix MAILDROP_README file for details.&lt;br /&gt;# Also specify in main.cf: maildrop_destination_recipient_limit=1&lt;br /&gt;#&lt;br /&gt;maildrop  unix  -       n       n       -       -       pipe&lt;br /&gt;flags=DRhu user=vmail argv=/usr/bin/maildrop -d ${recipient}&lt;br /&gt;#&lt;br /&gt;# See the Postfix UUCP_README file for configuration details.&lt;br /&gt;#&lt;br /&gt;uucp      unix  -       n       n       -       -       pipe&lt;br /&gt;flags=Fqhu user=uucp argv=uux -r -n -z -a$sender - $nexthop!rmail ($recipient)&lt;br /&gt;#&lt;br /&gt;# Other external delivery methods.&lt;br /&gt;#&lt;br /&gt;ifmail    unix  -       n       n       -       -       pipe&lt;br /&gt;flags=F user=ftn argv=/usr/lib/ifmail/ifmail -r $nexthop ($recipient)&lt;br /&gt;bsmtp     unix  -       n       n       -       -       pipe&lt;br /&gt;flags=Fq. user=bsmtp argv=/usr/lib/bsmtp/bsmtp -t$nexthop -f$sender $recipient&lt;br /&gt;scalemail-backend unix    -    n    n    -    2    pipe&lt;br /&gt;flags=R user=scalemail argv=/usr/lib/scalemail/bin/scalemail-store ${nexthop} ${user} ${extension}&lt;br /&gt;mailman   unix  -       n       n       -       -       pipe&lt;br /&gt;flags=FR user=list argv=/usr/lib/mailman/bin/postfix-to-mailman.py&lt;br /&gt;${nexthop} ${user}&lt;br /&gt;&lt;br /&gt;#Vacation&lt;br /&gt;vacation    unix  -       n       n       -       -       pipe&lt;br /&gt;flags=DRhu user=vacation argv=/var/spool/vacation/vacation.pl&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;amavis unix - - - - 2 smtp&lt;br /&gt;-o smtp_data_done_timeout=1200&lt;br /&gt;-o smtp_send_xforward_command=yes&lt;br /&gt;&lt;br /&gt;127.0.0.1:10025 inet n - - - - smtpd&lt;br /&gt;-o content_filter=&lt;br /&gt;-o local_recipient_maps=&lt;br /&gt;-o relay_recipient_maps=&lt;br /&gt;-o smtpd_restriction_classes=&lt;br /&gt;-o smtpd_client_restrictions=&lt;br /&gt;-o smtpd_helo_restrictions=&lt;br /&gt;-o smtpd_sender_restrictions=&lt;br /&gt;-o smtpd_recipient_restrictions=permit_mynetworks,reject&lt;br /&gt;-o mynetworks=127.0.0.0/8&lt;br /&gt;-o strict_rfc821_envelopes=yes&lt;br /&gt;-o receive_override_options=no_unknown_recipient_checks,no_header_body_checks&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Step 12&lt;br /&gt;Setting Courier-IMAP dan authentication Services&lt;br /&gt;&lt;br /&gt;Contoh /etc/courier/authmysqlrc&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;MYSQL_SERVER 127.0.0.1&lt;br /&gt;MYSQL_USERNAME postfix&lt;br /&gt;MYSQL_PASSWORD post123456&lt;br /&gt;MYSQL_DATABASE postfix&lt;br /&gt;MYSQL_USER_TABLE mailbox&lt;br /&gt;MYSQL_LOGIN_FIELD username&lt;br /&gt;MYSQL_NAME_FIELD name&lt;br /&gt;MYSQL_CRYPT_PWFIELD password&lt;br /&gt;#MYSQL_CLEAR_PWFIELD     password&lt;br /&gt;#MYSQL_MAILDIR_FIELD maildir&lt;br /&gt;MYSQL_MAILDIR_FIELD CONCAT(SUBSTRING_INDEX(Username,'@',-1),'/',SUBSTRING_INDEX(&lt;br /&gt;Username,'@',1),'/')&lt;br /&gt;MYSQL_QUOTA_FIELD concat(quota,'S')&lt;br /&gt;MYSQL_HOME_FIELD        '/home/vmail'&lt;br /&gt;MYSQL_UID_FIELD '5000'&lt;br /&gt;MYSQL_GID_FIELD '5000'&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Step 13&lt;br /&gt;SMTP Authentication&lt;br /&gt;&lt;br /&gt;Contoh /etc/postfix/sasl/smtpd.conf&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;pwcheck_method: auxprop&lt;br /&gt;auxprop_plugin: sql&lt;br /&gt;mech_list: plain login cram-md5 digest-md5&lt;br /&gt;sql_engine: mysql&lt;br /&gt;sql_hostnames: 127.0.0.1&lt;br /&gt;sql_user: postfix&lt;br /&gt;sql_passwd: post123456&lt;br /&gt;sql_database: postfix&lt;br /&gt;sql_select: select password from users where email='%u@%r'&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Untuk /etc/postfix/main.cf sudah ada diatas contohnya&lt;br /&gt;&lt;br /&gt;Step 14&lt;br /&gt;Postfixadmin&lt;br /&gt;Download postfixadmin-2.1.0.tgz  dari http://www.high5.net/postfixadmin&lt;br /&gt;&lt;br /&gt;#tar -zxvf postfixadmin-2.1.0.tgz&lt;br /&gt;&lt;br /&gt;copykan isi directory postfixadmin-2.1.0 ke /var/www/postfixadmin&lt;br /&gt;&lt;br /&gt;Rubah file permission&lt;br /&gt;&lt;br /&gt;# cd /var/www/postfixadmin&lt;br /&gt;# chmod 640 *.php *.css&lt;br /&gt;# cd /var/www/postfixadmin/admin/&lt;br /&gt;# chmod 640 *.php .ht*&lt;br /&gt;# cd /var/www/postfixadmin/images/&lt;br /&gt;# chmod 640 *.gif *.png&lt;br /&gt;# cd /var/www/postfixadmin/languages/&lt;br /&gt;# chmod 640 *.lang&lt;br /&gt;# cd /var/www/postfixadmin/templates/&lt;br /&gt;# chmod 640 *.tpl&lt;br /&gt;# cd /var/www/postfixadmin/users/&lt;br /&gt;# chmod 640 *.php&lt;br /&gt;&lt;br /&gt;Rubah kepemilikan file /var/www/postfixadmin&lt;br /&gt;&lt;br /&gt;#chown -R www-data:www-data /var/www/postfixadmin&lt;br /&gt;&lt;br /&gt;copy file /var/www/postfixadmin/config.inc.php.sample , contohnya sbb:&lt;br /&gt;&lt;br /&gt;#cp /var/www/postfixadmin/config.inc.php.sample /var/www/postfixadmin/config.inc.php&lt;br /&gt;&lt;br /&gt;dan edit isinya, pada bagian dibawah ini sesuaikan dengan username dan password di mysql yang telah diset dilangkah-langkah sebelumnya&lt;br /&gt;&lt;br /&gt;$CONF['database_type'] = 'mysql';&lt;br /&gt;$CONF['database_host'] = 'localhost';&lt;br /&gt;$CONF['database_user'] = 'postfixadmin';&lt;br /&gt;$CONF['database_password'] = 'postadmin123456';&lt;br /&gt;$CONF['database_name'] = 'postfix';&lt;br /&gt;$CONF['database_prefix'] = '';&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;buat file /etc/apache2/conf.d/postfixamdin.conf&lt;br /&gt;yang isinya sbb:&lt;br /&gt;&lt;br /&gt;&lt;directory&gt;&lt;br /&gt;AuthUserFile /var/www/postfixadmin/admin/.htpasswd&lt;br /&gt;AuthGroupFile /dev/null&lt;br /&gt;AuthName "Postfix Admin"&lt;br /&gt;AuthType Basic&lt;br /&gt;&lt;br /&gt;&lt;limit&gt;&lt;br /&gt;require valid-user&lt;br /&gt;&lt;/limit&gt;&lt;br /&gt;&lt;br /&gt;&lt;/directory&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;lalu restart apache2&lt;br /&gt;&lt;br /&gt;#/etc/init.d/apache2 restart&lt;br /&gt;&lt;br /&gt;Step 15&lt;br /&gt;Untuk mengaktifkan Vacation caranya sbb:&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;Create Vacation user and group accounts:&lt;/strong&gt;&lt;/p&gt; &lt;pre&gt;&lt;blockquote&gt;#groupadd vacation&lt;br /&gt;#useradd vacation -c Virtual\ Vacation -d /nonexistent -g vacation -s /sbin/nologin&lt;/blockquote&gt;&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;strong&gt;Create, populate and secure vacation directory:&lt;/strong&gt;&lt;/p&gt; &lt;pre&gt;&lt;blockquote&gt;#mkdir /var/spool/vacation&lt;br /&gt;#cp /var/www/postfixadmin/VIRTUAL_VACATION/vacation.pl /var/spool/vacation/&lt;br /&gt;#chown -R vacation:vacation /var/spool/vacation/&lt;br /&gt;#chmod 700 /var/spool/vacation/&lt;br /&gt;#chmod 750 /var/spool/vacation/vacation.pl&lt;br /&gt;#touch /var/log/vacation.log /var/log/vacation-debug.log&lt;br /&gt;#chown vacation:vacation /var/log/vacation*&lt;/blockquote&gt;&lt;br /&gt;&lt;/pre&gt; &lt;p&gt;&lt;strong&gt;Edit /var/spool/vacation/vacation.pl script:&lt;/strong&gt;&lt;br /&gt;Find and edit the &lt;span style="color:red;"&gt;&lt;b&gt;RED TEXT&lt;/b&gt;&lt;/span&gt;.&lt;/p&gt; &lt;pre&gt;&lt;blockquote&gt;use DBI;&lt;br /&gt;use strict;&lt;br /&gt;my $db_type = ‘mysql’;&lt;br /&gt;my $db_host = ‘&lt;span style="color:red;"&gt;&lt;b&gt;localhost&lt;/b&gt;&lt;/span&gt;‘;&lt;br /&gt;my $db_user = ‘&lt;span style="color:red;"&gt;&lt;b&gt;postfixadmin&lt;/b&gt;&lt;/span&gt;‘;&lt;br /&gt;my $db_pass = ‘&lt;span style="color: rgb(255, 0, 0);"&gt;postadmin123456&lt;/span&gt;‘;&lt;br /&gt;my $db_name = ‘&lt;span style="color:red;"&gt;&lt;b&gt;postfix&lt;/b&gt;&lt;/span&gt;‘;&lt;br /&gt;my $sendmail = “/usr/sbin/sendmail”;&lt;br /&gt;my $logfile = “&lt;span style="color:red;"&gt;&lt;b&gt;/var/log/vacation.log&lt;/b&gt;&lt;/span&gt;“;    # specify a file name here for example: vacation.log&lt;br /&gt;my $debugfile = “&lt;span style="color:red;"&gt;&lt;b&gt;/var/log/vacation-debug.log&lt;/b&gt;&lt;/span&gt;“;  # sepcify a file name here for example: vacation.debug&lt;br /&gt;my $syslog = &lt;span style="color:red;"&gt;&lt;b&gt;1&lt;/b&gt;&lt;/span&gt;;   # 1 if log entries should be sent to syslog&lt;br /&gt;…&lt;br /&gt;&lt;/blockquote&gt;&lt;span style="font-family:Georgia,serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;p&gt;&lt;strong&gt;Edit /etc/postfix/master.cf for vacation filter:&lt;/strong&gt;&lt;br /&gt;Add this to the bottom of the file.&lt;/p&gt; &lt;blockquote&gt; &lt;pre&gt;vacation  unix  -       n       n       -       -       pipe&lt;br /&gt;flags=DRhu user=vacation argv=/var/spool/vacation/vacation.pl&lt;/pre&gt; &lt;/blockquote&gt; &lt;p&gt;&lt;strong&gt;Edit /etc/postfix/main.cf for vacation transport:&lt;/strong&gt;&lt;br /&gt;Find and edit the &lt;span style="color:red;"&gt;&lt;b&gt;RED TEXT&lt;/b&gt;&lt;/span&gt;.&lt;/p&gt; &lt;blockquote&gt;… # TRANSPORT MAP # # See the discussion in the ADDRESS_REWRITING_README document. &lt;span style="color:red;"&gt;&lt;b&gt;transport_maps = hash:/etc/postfix/transport&lt;/b&gt;&lt;/span&gt; &lt;span style="color:red;"&gt;&lt;b&gt;vacation_destination_recipient_limit = 1&lt;/b&gt;&lt;/span&gt; … &lt;/blockquote&gt;  &lt;p&gt;&lt;strong&gt;Add proper lines to /usr/local/etc/postfix/transport file:&lt;/strong&gt;&lt;/p&gt; &lt;blockquote&gt;#echo '&lt;span style="color:red;"&gt;&lt;b&gt;autoreply.domain.tld&lt;/b&gt;&lt;/span&gt; vacation:' &gt;&gt; /etc/postfix/transport&lt;/blockquote&gt;  &lt;p&gt;&lt;strong&gt;Create our transport map database for Postfix:&lt;/strong&gt;&lt;/p&gt; &lt;blockquote&gt;&lt;p&gt;#postmap /etc/postfix/transport&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;strong&gt;Create PostfixAdmin username and password:&lt;/strong&gt;&lt;/p&gt; &lt;blockquote&gt;&lt;p&gt;#cd /var/www/postfixadmin/admin&lt;br /&gt;#htpasswd -c .htpasswd &lt;span style="color:red;"&gt;&lt;b&gt;admin&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;(Enter password)&lt;br /&gt;(Re-enter password)&lt;/p&gt;&lt;/blockquote&gt;&lt;pre&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;step 17&lt;br /&gt;Untuk webmail bisa menggunakan squirrelmail&lt;br /&gt;&lt;br /&gt;#apt-get install squirrelmail&lt;br /&gt;&lt;br /&gt;konfigurasinya ada di /usr/share/squirrelmail/config/conf.pl&lt;br /&gt;Setting bagian server seperti contoh dibawah ini:&lt;br /&gt;&lt;br /&gt;SquirrelMail Configuration : Read: config.php (1.4.0)&lt;br /&gt;---------------------------------------------------------&lt;br /&gt;Server Settings&lt;br /&gt;&lt;br /&gt;General&lt;br /&gt;-------&lt;br /&gt;1.  Domain                 : trim(implode('', file('/etc/'.(file_exists('/etc/mailname')?'mail':'host').'name')))&lt;br /&gt;2.  Invert Time            : false&lt;br /&gt;3.  Sendmail or SMTP       : SMTP&lt;br /&gt;&lt;br /&gt;A.  Update IMAP Settings   : 127.0.0.1:143 (other)&lt;br /&gt;B.  Update SMTP Settings   : 127.0.0.1:25&lt;br /&gt;&lt;br /&gt;R   Return to Main Menu&lt;br /&gt;C   Turn color on&lt;br /&gt;S   Save data&lt;br /&gt;Q   Quit&lt;br /&gt;&lt;br /&gt;Command &gt;&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;lalu buat link /etc/apache2/conf.d/apache.conf ke /etc/squirrelmail/apache.conf&lt;br /&gt;&lt;br /&gt;#ln -s /etc/squirrelmail/apache.conf /etc/apache2/conf.d/apache.conf&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Step 18&lt;br /&gt;Restart semua service yang ada&lt;br /&gt;&lt;br /&gt;/etc/init.d/postfix restart&lt;br /&gt;/etc/init.d/apache2 restart&lt;br /&gt;/etc/init.d/courier-authdaemon restart&lt;br /&gt;/etc/init.d/courier-imap restart&lt;br /&gt;/etc/init.d/courier-imap-ssl restart&lt;br /&gt;/etc/init.d/courier-pop restart&lt;br /&gt;/etc/init.d/courier-pop-ssl restart&lt;br /&gt;/etc/init.d/amavis restart&lt;br /&gt;/etc/init.d/clamav-daemon restart&lt;br /&gt;/etc/init.d/clamav-freshclam restart&lt;br /&gt;&lt;br /&gt;Untuk mengkonfigure clamav caranya:&lt;br /&gt;&lt;br /&gt;&lt;p&gt;We recommend that you use one of the Debian volatile repositories to keep your ClamAV installation updated on your system.&lt;br /&gt;Always choose the &lt;a href="http://www.debian.org/volatile/volatile-mirrors"&gt;mirror&lt;/a&gt; closest to you.&lt;br /&gt;Edit /etc/apt/sources.list and add a line like this to it:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;stable/etch&lt;/em&gt;:&lt;/p&gt;  &lt;p&gt;deb http://volatile.debian.org/debian-volatile etch/volatile main contrib non-free&lt;/p&gt;  Then run apt-get update; apt-get install clamav&lt;br /&gt;If you need clamd, you may also want to run apt-get install clamav-daemon&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.clamav.org/download/packages/packages-linux"&gt;http://www.clamav.org/download/packages/packages-linux&lt;/a&gt;&lt;br /&gt;&lt;a href="http://howtoforge.org/virtual_users_and_domains_with_postfix_debian_etch_p4"&gt;&lt;/a&gt;&lt;br /&gt;catatan:&lt;br /&gt;Berdoalah tidak ada yang error :)&lt;br /&gt;&lt;br /&gt;Untuk membuka postfixadmin bisa diakses melalui&lt;br /&gt;http://localhost/postfixadmin&lt;br /&gt;&lt;br /&gt;Untuk membuka webmail bisa diakses melalui&lt;br /&gt;http://localhost/squirrelmail&lt;br /&gt;&lt;br /&gt;Untuk panduan penggunaan postfixadmin akan saya buat di blog selanjutnya udah kebanyakan nih apa gak pusing bacanya :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-4634184610502896869?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/4634184610502896869/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=4634184610502896869' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/4634184610502896869'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/4634184610502896869'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/07/email-server-postfix-dengan.html' title='Email Server Postfix dengan Postfixadmin'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-1171342812048661107</id><published>2008-06-13T22:15:00.007+07:00</published><updated>2008-12-13T07:35:58.331+07:00</updated><title type='text'>ECMP Failover Script Mikrotik ver 3.10</title><content type='html'>Barusan ada teman yang minta tolong untuk seting mikrotik menjadi router load balance dan failover ternyata contoh-contoh script yang ada di Internet sebagian besar untuk mikrotik versi 2.9.x sehingga contoh-contoh script tersebut tidak dapat langsung digunakan.&lt;br /&gt;&lt;br /&gt;adapun network diagramnya kurang lebih sbb:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/SFKRDvBM2AI/AAAAAAAAAIo/NVV1vZnDmEM/s1600-h/topologi.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/SFKRDvBM2AI/AAAAAAAAAIo/NVV1vZnDmEM/s400/topologi.jpg" alt="" id="BLOGGER_PHOTO_ID_5211387212168222722" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;konfigurasi load balance dan failover mengacu pada :&lt;br /&gt;&lt;a href="http://wiki.mikrotik.com/wiki/ECMP_Failover_Script"&gt;&lt;br /&gt;http://wiki.mikrotik.com/wiki/ECMP_Failover_Script&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;karena paling praktis dan masuk akal bahwa selain traffic http sangat riskan jika harus berpindah-pindah gateway.&lt;br /&gt;&lt;br /&gt;berikut adalah hasil export dari konfigurasi router mikrotik versi 3.10 yang digunakan&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;IP Address&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;# jun/13/2008 23:10:46 by RouterOS 3.10&lt;br /&gt;# software id = A90W-3CT&lt;br /&gt;#&lt;br /&gt;/ip address&lt;br /&gt;&lt;br /&gt;add address=10.95.130.133/29 broadcast=10.95.130.135 comment="" disabled=no \&lt;br /&gt;interface=WIRELESS network=10.95.130.128&lt;br /&gt;&lt;br /&gt;add address=10.168.2.99/24 broadcast=10.168.2.255 comment="" disabled=no \&lt;br /&gt;interface=ADSL network=10.168.2.0&lt;br /&gt;&lt;br /&gt;add address=192.168.1.1/24 broadcast=192.168.1.255 comment="" disabled=no \&lt;br /&gt;interface=LAN network=192.168.1.0&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Routing&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;# jun/13/2008 23:10:02 by RouterOS 3.10&lt;br /&gt;# software id = A90W-3CT&lt;br /&gt;#&lt;br /&gt;/ip route&lt;br /&gt;&lt;br /&gt;add comment="SMTP Traffic out" disabled=no distance=1 dst-address=0.0.0.0/0 \&lt;br /&gt;gateway=10.95.130.129 routing-mark=smtp-out scope=30 target-scope=10&lt;br /&gt;&lt;br /&gt;add comment="Default Route to Internet Wireless" disabled=no distance=1 \&lt;br /&gt;dst-address=0.0.0.0/0 gateway=10.95.130.129 scope=30 target-scope=10&lt;br /&gt;&lt;br /&gt;add comment="ECMP route for HTTP" disabled=no distance=1 dst-address=\&lt;br /&gt;0.0.0.0/0 gateway=10.95.130.129,10.168.2.1,10.168.2.1 routing-mark=\&lt;br /&gt;ecmp-http-route scope=30 target-scope=10&lt;br /&gt;&lt;br /&gt;add comment="Default Route to Internet ADSL" disabled=yes distance=1 \&lt;br /&gt;dst-address=0.0.0.0/0 gateway=10.168.2.1 scope=30 target-scope=10&lt;br /&gt;&lt;br /&gt;add comment="DNS Wireless" disabled=no distance=1 dst-address=\&lt;br /&gt;202.95.128.60/32 gateway=10.95.130.129 scope=30 target-scope=10&lt;br /&gt;&lt;br /&gt;add comment="DNS Speedy" disabled=no distance=1 dst-address=202.134.2.5/32 \&lt;br /&gt;gateway=10.168.2.1 scope=30 target-scope=10&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Mangle&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;# jun/13/2008 23:09:21 by RouterOS 3.10&lt;br /&gt;# software id = A90W-3CT&lt;br /&gt;#&lt;br /&gt;/ip firewall mangle&lt;br /&gt;&lt;br /&gt;add action=mark-routing chain=prerouting comment=\&lt;br /&gt;" Route HTTP traffic to ECMP" disabled=no dst-port=80 new-routing-mark=\&lt;br /&gt;ecmp-http-route passthrough=yes protocol=tcp&lt;br /&gt;&lt;br /&gt;add action=mark-routing chain=prerouting comment="SMTP Traffic" disabled=no \&lt;br /&gt;dst-port=25 new-routing-mark=smtp-out passthrough=yes protocol=tcp&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;NAT&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;# jun/13/2008 23:08:44 by RouterOS 3.10&lt;br /&gt;# software id = A90W-3CT&lt;br /&gt;#&lt;br /&gt;/ip firewall nat&lt;br /&gt;add action=masquerade chain=srcnat comment="" disabled=no src-address=\&lt;br /&gt;192.168.1.0/24&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;SCRIPT&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;# jun/13/2008 23:06:31 by RouterOS 3.10&lt;br /&gt;# software id = A90W-3CT&lt;br /&gt;#&lt;br /&gt;/system script&lt;br /&gt;&lt;br /&gt;add name=ecmp-shutdown policy=\&lt;br /&gt;ftp,reboot,read,write,policy,test,winbox,password,sniff source=":if ([/pin\&lt;br /&gt;g 10.95.130.129 count=1]=0 || [/ping 10.168.2.1 count=1]=0) do={:log inf\&lt;br /&gt;o \"Gateway down\" \r\&lt;br /&gt;\n/ip route disable [/ip route find comment=\"ECMP route for HTTP\"] } els\&lt;br /&gt;e {:log info \"ecmp-shutdown check ok\"}"&lt;br /&gt;&lt;br /&gt;add name=ecmp-startup policy=\&lt;br /&gt;ftp,reboot,read,write,policy,test,winbox,password,sniff source=":if ([/pin\&lt;br /&gt;g 10.95.130.129 count=1]=1 &amp;amp;&amp;amp; [/ping 10.168.2.1 count=1]=1 &amp;amp;&amp;amp; [/ip route\&lt;br /&gt; get [find comment=\"ECMP route for HTTP\"] disabled]=true ) do={:log info\&lt;br /&gt; \"Both Gateway are up\"\r\&lt;br /&gt;\n/ip route enable [/ip route find comment=\"ECMP route for HTTP\"]} else \&lt;br /&gt;{:log info \"ecmp-startup check ok\"}"&lt;br /&gt;&lt;br /&gt;add name=wireless-gateway-check policy=\&lt;br /&gt;ftp,reboot,read,write,policy,test,winbox,password,sniff source=":if ([/pin\&lt;br /&gt;g 10.95.130.129 count=1]=1) do={:log info \"Wireless Gateway are up\"\r\&lt;br /&gt;\n/ip route enable [/ip route find comment=\"Default Route to Internet Wir\&lt;br /&gt;eless\"]\r\&lt;br /&gt;\n/ip route disable [/ip route find comment=\"Default Route to Internet AD\&lt;br /&gt;SL\"]\r\&lt;br /&gt;\n} else {:log info \"Wireless Gateway are down\"\r\&lt;br /&gt;\n/ip route disable [/ip route find comment=\"Default Route to Internet Wi\&lt;br /&gt;reless\"]\r\&lt;br /&gt;\n/ip route enable [/ip route find comment=\"Default Route to Internet ADS\&lt;br /&gt;L\"]\r\&lt;br /&gt;\n}"&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;SCHEDULER&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;# jun/13/2008 23:08:12 by RouterOS 3.10&lt;br /&gt;# software id = A90W-3CT&lt;br /&gt;#&lt;br /&gt;/system scheduler&lt;br /&gt;add comment="" disabled=no interval=25s name=gateway-check1 on-event=\&lt;br /&gt;ecmp-shutdown start-date=jun/13/2008 start-time=16:26:27&lt;br /&gt;&lt;br /&gt;add comment="" disabled=no interval=30s name=gateway-check2 on-event=\&lt;br /&gt;ecmp-startup start-date=jun/13/2008 start-time=16:26:27&lt;br /&gt;&lt;br /&gt;add comment="" disabled=no interval=20s name=wireless-gateway-check on-event=\&lt;br /&gt;wireless-gateway-check start-date=jun/13/2008 start-time=16:26:27&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;SUPAYA pengecekkan ke gateway WIRELESS tidak bisa lewat interface ADSL&lt;br /&gt;&lt;/span&gt;&lt;span&gt;&lt;br /&gt;Karena pengecekkan dilakukan menggunakan mekanisme ping = icmp maka agar pengecekkan gateway WIRELESS tidak bisa lewat interface ADSL diperlukan skrip berikut:&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;/ip firewall filter&lt;span style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/span&gt;add action=drop chain=output comment=\&lt;span style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/span&gt;"supaya ke gateway wireless tidak bisa lewat interface adsl" disabled=no \&lt;span style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/span&gt;dst-address=10.95.130.129 out-interface=ADSL protocol=icmp&lt;br /&gt;&lt;br /&gt;Dengan script ini maka jika wireless down maka IP gateway WIRELESS tidak akan bisa diping melalui link ADSL tujuannya agar tidak terjadi kesalahan pengecekkan karena bisa saja ip gateway WIRELESS masih bisa diping melalui jaringan ADSL sehingga script menjadi tidak efektif.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;semoga script-script diatas bisa langsung di import tinggal disesuaikan saja ip-ip nya&lt;br /&gt;&lt;br /&gt;kelemahan dari konfigurasi ini adalah ip 10.168.2.1 walaupun ADSL nya down tetap bisa diping karena itu ip dibelakang adsl-router harusnya 10.168.2.1 dibagian script diganti dengan ip statik ADSL , jadi kalau ADSL nya mati mestinya ip tersebut tidak bisa di ping.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-1171342812048661107?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/1171342812048661107/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=1171342812048661107' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/1171342812048661107'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/1171342812048661107'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/06/ecmp-failover-script-mikrotik-ver-310.html' title='ECMP Failover Script Mikrotik ver 3.10'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_nzWcXcVYSRs/SFKRDvBM2AI/AAAAAAAAAIo/NVV1vZnDmEM/s72-c/topologi.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-3822444984933037117</id><published>2008-06-05T12:01:00.002+07:00</published><updated>2008-12-13T07:35:58.386+07:00</updated><title type='text'>"BIGGEST HACKER'S DAY EVENT IN INDONESIA"</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SEdzjZ5WE-I/AAAAAAAAAIg/pYSiEIK79kE/s1600-h/poster+hacker+A3+copy.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SEdzjZ5WE-I/AAAAAAAAAIg/pYSiEIK79kE/s400/poster+hacker+A3+copy.jpg" alt="" id="BLOGGER_PHOTO_ID_5208258546161292258" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;"BIGGEST HACKER'S DAY EVENT IN INDONESIA"&lt;br /&gt;One Day Seminar&lt;br /&gt;&lt;br /&gt;Kamis, 12 Juni 2008&lt;br /&gt;Nuri Room, Jakarta Convention Center&lt;br /&gt;&lt;br /&gt;Materi:&lt;br /&gt;Indonesian Cyber-Law&lt;br /&gt;The X: Art of Web Application Exploitation&lt;br /&gt;Defeating Fake Exploit for Dummies&lt;br /&gt;Hacking: Do The Professionals Now Rule?&lt;br /&gt;CAPTCHA (in) Security&lt;br /&gt;Client Side Hacking and Countermeasures&lt;br /&gt;Offensive Security: The Way of Wireless Ninja&lt;br /&gt;&lt;br /&gt;Pembicara :&lt;br /&gt;Onno W.Purbo (Pakar TI)&lt;br /&gt;Eko Indrajit (ID-SIRTII)&lt;br /&gt;Eugene Dokukin (Russian White-hat Hacker)&lt;br /&gt;Anselmus Ricky-Also known as Th0R (Security Consultant &amp;amp; Hacking Book Writer)&lt;br /&gt;Semi Yulianto (Senior Security Consultant, EC Council)&lt;br /&gt;Irvan (Security Consultant &amp;amp; Hacking Book Writer)&lt;br /&gt;Jim Geovedi (Member of HERT &amp;amp; Security Consultant)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Biaya Peserta&lt;br /&gt;Rp.200.000 (UMUM)&lt;br /&gt;Rp.150.000 (MAHASISWA)&lt;br /&gt;&lt;br /&gt;Harga Spesial:&lt;br /&gt;Rp.150.000 (Pelanggan InfoKomputer)&lt;br /&gt;Rp 150.000 (UMUM 2 orang/lebih)&lt;br /&gt;&lt;br /&gt;Biaya sudah termasuk:&lt;br /&gt;Makan siang &amp;amp; Coffee break&lt;br /&gt;Majalah InfoKomputer&lt;br /&gt;Tabloid PCplus.&lt;br /&gt;Voucher Buku Hacking&lt;br /&gt;Souvenir&lt;br /&gt;Sertifikat&lt;br /&gt;CD Materi acara&lt;br /&gt;&lt;br /&gt;Transfer ke Rek BCA Cab.Gajahmada 0123005519 a/n PT.PRIMA INFOSARANA MEDIA&lt;br /&gt;Fax 5360411&lt;br /&gt;&lt;br /&gt;DAFTAR SEKARANG TEMPAT TERBATAS&lt;br /&gt;&lt;br /&gt;Hub: Ibu Uli/Ibu Pandan 021.5483008 ext 3340/3773&lt;br /&gt;Ibu Kikis 021.5484366 (Direct Line)&lt;br /&gt;Penyelenggara:&lt;br /&gt;MAJALAH INFOKOMPUTER&lt;br /&gt;TABLOID PC PLUS&lt;br /&gt;&lt;br /&gt;Partner:&lt;br /&gt;SWISS GERMAN UNIVERSITY&lt;br /&gt;INIXINDO&lt;br /&gt;DYANDRA PROMOSINDO&lt;br /&gt;KOMPAS.COM&lt;br /&gt;OKEZONE.COM&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-3822444984933037117?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/3822444984933037117/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=3822444984933037117' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3822444984933037117'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/3822444984933037117'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/06/biggest-hackers-day-event-in-indonesia.html' title='&quot;BIGGEST HACKER&apos;S DAY EVENT IN INDONESIA&quot;'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_nzWcXcVYSRs/SEdzjZ5WE-I/AAAAAAAAAIg/pYSiEIK79kE/s72-c/poster+hacker+A3+copy.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-5671887976179298917</id><published>2008-06-01T14:58:00.003+07:00</published><updated>2008-06-01T15:12:26.992+07:00</updated><title type='text'>update cpanel ternyata harus update perl dulu</title><content type='html'>Kemarin malem , saya eksekusi /script/upcp untuk mengupdate cpanel , karena sebelumnya ada announcement update cpanel terbaru agar penggunaan memory lebih efisien.&lt;br /&gt;&lt;br /&gt;ternyata sebelumnya harus mendonwload&lt;br /&gt;&lt;br /&gt; wget http://layer1.cpanel.net/perl588installer.tar.gz&lt;br /&gt;&lt;br /&gt;lalu&lt;br /&gt;&lt;br /&gt;tar xvfz perl588installer.tar.gz&lt;br /&gt;&lt;br /&gt;lalu&lt;br /&gt;&lt;br /&gt;cd perl588installer&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;lalu&lt;br /&gt;&lt;br /&gt;./install&lt;br /&gt;&lt;br /&gt;setelah selesai meng-install perl588&lt;br /&gt;&lt;br /&gt;baru eksekusi&lt;br /&gt;&lt;br /&gt;/script/upcp --force&lt;br /&gt;&lt;br /&gt;baru deh beres :)&lt;br /&gt;&lt;br /&gt;sumber:&lt;br /&gt;&lt;a href="http://forums.cpanel.net/showthread.php?t=80989&amp;amp;highlight=upcp"&gt;http://forums.cpanel.net/showthread.php?t=80989&amp;amp;highlight=upcp&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-5671887976179298917?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/5671887976179298917/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=5671887976179298917' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5671887976179298917'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/5671887976179298917'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/06/update-cpanel-ternyata-harus-update.html' title='update cpanel ternyata harus update perl dulu'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-8490464545759300238</id><published>2008-05-28T18:38:00.007+07:00</published><updated>2008-12-13T07:35:58.509+07:00</updated><title type='text'>Menjadikan debian sebagai syslog server yang disimpan di mysql</title><content type='html'>Kadang kita perlu menyimpan log dari mesin2 tertentu ke sebuah syslog server agar diperoleh report yang dibutuhkan, lebi seru lagi kalau datanya disimpan di database server seperti mysql jadi mudah untuk di query.&lt;br /&gt;&lt;br /&gt;Berikut adalah cara instalasi syslog server yang datanya disimpan di mysql pada distro debian.&lt;br /&gt;&lt;br /&gt;Pertama install syslog-ng&lt;br /&gt;&lt;br /&gt;apt-get install syslog-ng syslog-summary&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;kemudian tambahkan file di /etc/syslog-ng/syslog-ng.&lt;br /&gt;&lt;br /&gt;source net { udp(); };&lt;br /&gt;&lt;br /&gt;destination d_mysql {&lt;br /&gt;pipe("/tmp/mysql.pipe"&lt;br /&gt;template("INSERT INTO logs (host, facility, priority, level, tag, date,&lt;br /&gt;time, program, msg) VALUES ( '$HOST', '$FACILITY', '$PRIORITY', '$LEVEL','$TAG',&lt;br /&gt;'$YEAR-$MONTH-$DAY', '$HOUR:$MIN:$SEC', '$PROGRAM', '$MSG' );\n")  template-escape(yes));&lt;br /&gt;};&lt;br /&gt;&lt;br /&gt;log { source(net); destination(d_mysql); };&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;save lalu restart syslog-ng&lt;br /&gt;&lt;br /&gt;/etc/init.d/syslog-ng restart&lt;br /&gt;&lt;br /&gt;buat fifo pipe untuk syslog-ng caranya:&lt;br /&gt;&lt;br /&gt;mkfifo /tmp/mysql.pipe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;buat database syslogdb di mysql dengan perintah SQL berikut:&lt;br /&gt;perintah SQL ini bisa diinput melalui phpmysql atau melalui console, kalau saya paling praktis menggunakan phpmysql, sorry di artikel ini saya tidak menjelaskan instalasi mysqlnya, jadi asumsi mysqlnya udah jalan dengan benar.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;CREATE DATABASE syslogdb;&lt;br /&gt;USE syslogdb;&lt;br /&gt;&lt;br /&gt;CREATE TABLE logs (&lt;br /&gt;host varchar(32) default NULL,&lt;br /&gt;facility varchar(10) default NULL,&lt;br /&gt;priority varchar(10) default NULL,&lt;br /&gt;level varchar(10) default NULL,&lt;br /&gt;tag varchar(10) default NULL,&lt;br /&gt;date date default NULL,&lt;br /&gt;time time default NULL,&lt;br /&gt;program varchar(15) default NULL,&lt;br /&gt;msg text,&lt;br /&gt;seq int(10) unsigned NOT NULL auto_increment,&lt;br /&gt;PRIMARY KEY (seq),&lt;br /&gt;KEY host (host),&lt;br /&gt;KEY seq (seq),&lt;br /&gt;KEY program (program),&lt;br /&gt;KEY time (time),&lt;br /&gt;KEY date (date),&lt;br /&gt;KEY priority (priority),&lt;br /&gt;KEY facility (facility)&lt;br /&gt;) TYPE=MyISAM;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;berikutnya buat script /etc/syslog-ng/rc.syslog-ng-to-myqsl&lt;br /&gt;yang isinya:&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# Created by Tadghe Patrick Danu&lt;br /&gt;#&lt;br /&gt;#!/bin/bash&lt;br /&gt;&lt;br /&gt;if [ -e /tmp/mysql.pipe ]; then&lt;br /&gt;while [ -e /tmp/mysql.pipe ]&lt;br /&gt;do&lt;br /&gt;mysql -u root --password='password root mysql yang digunakan' syslogdb &lt; /tmp/mysql.pipe done&lt;br /&gt;else&lt;br /&gt;mkfifo /tmp/mysql.pipe&lt;br /&gt;fi   &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;kemudian chmod 750 /etc/syslog-ng/rc.syslog-ng-to-mysql  hati-hati di file itu ada password root msyql jadi jangan lupa utk dibuat 750 ya supaya orang lain selain root tidak bisa lihat isinya, atau bisa juga buat user khusus utk syslogdb di mysqlnya.  &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;kalau sudah tinggal restart syslog-ng  /etc/init.d/syslog-ng restart  dan eksekusi /etc/syslog-ng/rc.syslog-ng-to-mysql &amp;amp;  atau bisa juga dimasukkin ke /etc/rc.local supaya otomatis jalan kalau debiannya direboot.  ini hasilnya kalau dilihat di phpmyadmin. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/SD1G6oUW4gI/AAAAAAAAAIY/c4jjEDmL_mI/s1600-h/phpmyadmin-monitoring.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/SD1G6oUW4gI/AAAAAAAAAIY/c4jjEDmL_mI/s400/phpmyadmin-monitoring.JPG" alt="" id="BLOGGER_PHOTO_ID_5205394717379322370" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;sebagai tambahan kalau dari mesin cisco mau dilempar lognya ke syslog server commandnya spt ini:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;logging &lt;/span&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;IP_address_of_UNIX_host&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;logging facility local7&lt;/span&gt; (use local7 syslog facility)&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;logging trap &lt;/span&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;level_of_debugging&lt;/span&gt; (default is "informational")&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;logging on&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;reference:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://kryptoz.wordpress.com/2008/04/10/configure-syslog-ng-syslogd-remote-log-server/"&gt;http://kryptoz.wordpress.com/2008/04/10/configure-syslog-ng-syslogd-remote-log-server/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://vermeer.org/docs/1"&gt;http://vermeer.org/docs/1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.brandonhutchinson.com/Remote_Cisco_logging.html"&gt;http://www.brandonhutchinson.com/Remote_Cisco_logging.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-8490464545759300238?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/8490464545759300238/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=8490464545759300238' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/8490464545759300238'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/8490464545759300238'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/05/menjadikan-debian-sebagai-syslog-server.html' title='Menjadikan debian sebagai syslog server yang disimpan di mysql'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_nzWcXcVYSRs/SD1G6oUW4gI/AAAAAAAAAIY/c4jjEDmL_mI/s72-c/phpmyadmin-monitoring.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-2030789062088067246</id><published>2008-05-19T11:12:00.004+07:00</published><updated>2008-12-13T07:35:59.305+07:00</updated><title type='text'>Memfilter broadcast traffic yang bukan menuju ke pelanggan yang bersangkutan</title><content type='html'>Dikarenakan switch yang digunakan di roof cyber sementara tidak managable alias tidak bisa di konfigurasi vlan maka traffic antar radio pelanggan yang satu bisa ter-broadcast ke pelanggan lainnya.&lt;br /&gt;&lt;br /&gt;Untuk mengurangi beban traffic tersebut agar tidak ter-broadcast ke radio disisi pelanggan maka saya buat filtering sbb:&lt;br /&gt;&lt;br /&gt;Langkah 1&lt;br /&gt;Buat daftar address-lists dengan nama pelanggan , misalnya disini contohnya adalah "praisindo" yang isinya blok ip yang digunakan oleh pelanggan utk terkoneksi ke Internet, disini contohnya user praisindo menggunakan IP:&lt;br /&gt;- 203.89.26.104/30 -&gt; Ip Publik pelanggan&lt;br /&gt;- 10.3.0.0/29  -&gt; IP Radio pelanggan&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/SDD_Ter7GQI/AAAAAAAAAH4/5yEiyJvm2mA/s1600-h/praisindo-cyber.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/SDD_Ter7GQI/AAAAAAAAAH4/5yEiyJvm2mA/s400/praisindo-cyber.JPG" alt="" id="BLOGGER_PHOTO_ID_5201938279732812034" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Langkah 2&lt;br /&gt;Buat Filter Rules pada chain: forward, pada Tab General set in-interface = ether1 (yang merupakan interface yang terhubung ke switch di roof cyber) dan out interface = wlan1 (yang merupakan interface wireless yang menuju ke pelanggan)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/SDD_mer7GRI/AAAAAAAAAIA/jVdusIhYBO0/s1600-h/praisindo-cyber1.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/SDD_mer7GRI/AAAAAAAAAIA/jVdusIhYBO0/s400/praisindo-cyber1.JPG" alt="" id="BLOGGER_PHOTO_ID_5201938606150326546" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Pada Tab Advanced, Dst-address list = !praisindo (artinya bukan "!" dari list "praisindo")&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nzWcXcVYSRs/SDD_mer7GSI/AAAAAAAAAII/Og65sgP7Eq4/s1600-h/praisindo-cyber2.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_nzWcXcVYSRs/SDD_mer7GSI/AAAAAAAAAII/Og65sgP7Eq4/s400/praisindo-cyber2.JPG" alt="" id="BLOGGER_PHOTO_ID_5201938606150326562" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Pada Tab Action, Action = Drop&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nzWcXcVYSRs/SDD_mur7GTI/AAAAAAAAAIQ/YvefJg6ceVQ/s1600-h/praisindo-cyber3.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_nzWcXcVYSRs/SDD_mur7GTI/AAAAAAAAAIQ/YvefJg6ceVQ/s400/praisindo-cyber3.JPG" alt="" id="BLOGGER_PHOTO_ID_5201938610445293874" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Dengan demikian broadcast dari pelanggan lainnya difilter untuk tidak diteruskan ke sisi wireless pelanggan tersebut.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-2030789062088067246?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/2030789062088067246/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=2030789062088067246' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2030789062088067246'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2030789062088067246'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/05/memfilter-broadcast-traffic-yang-bukan.html' title='Memfilter broadcast traffic yang bukan menuju ke pelanggan yang bersangkutan'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_nzWcXcVYSRs/SDD_Ter7GQI/AAAAAAAAAH4/5yEiyJvm2mA/s72-c/praisindo-cyber.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-2962796369737917242</id><published>2008-05-16T23:29:00.000+07:00</published><updated>2008-05-16T23:31:03.944+07:00</updated><title type='text'>Instalasi Caci di Debian</title><content type='html'>&lt;p class="MsoNormal"&gt;&lt;span style="font-size: 10pt; font-family: 'Verdana','sans-serif';"&gt;DITULIS&lt;span&gt;  &lt;/span&gt;OLEH : EKA RAHMAT H&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-size: 10pt; font-family: 'Verdana','sans-serif';"&gt;EMAIL : surat-mu@hotmail.com&lt;/span&gt;&lt;br /&gt;http://sisulung.wordpress.com/2007/12/14/install-cacti-di-debian-etch/&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 18pt;"&gt;&lt;strong&gt;&lt;a&gt;&lt;br /&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 18pt;"&gt;&lt;strong&gt;&lt;a&gt;Apa itu CACTI?&lt;br /&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;a&gt;Cacti adalah frontend dari RRDTool yang menyimpan informasi kedalam database !MySQL dan membuat graph berdasarkan informasi tersebut. Proses pengambilan data (lewat SNMP maupun skrip) sampai kepada pembuatan gambar (graph) dilakukan menggunakan bahasa pemrograman PHP.&lt;br /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.raxnet.net/products/cacti" title="http://www.raxnet.net/products/cacti" target="_blank"&gt;&lt;span style="color: blue; font-family: Verdana; font-size: 10pt; text-decoration: underline;"&gt;http://www.raxnet.net/products/cacti&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-size: 18pt;"&gt;&lt;strong&gt;&lt;a&gt;Instalasi:&lt;br /&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Times New Roman; font-size: 12pt;"&gt;&lt;a&gt;Cacti membutuhkan beberapa aplikasi berikut terinstall kedalam sistem sebelumnya.&lt;br /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-left: 18pt;"&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;RRDTool 1.0.48 or greater &lt;a href="http://www.rrdtool.org%20rrdtool/" title="http://www.rrdtool.org rrdtool" target="_blank"&gt;&lt;span style="color: blue; text-decoration: underline;"&gt;http://www.rrdtool.org rrdtool&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-left: 18pt;"&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;MySQL 3.23 or greater, 4.0.20d or greater highly recommended for advanced features &lt;a href="http://www.mysql.org%20mysql/" title="http://www.mysql.org MySQL" target="_blank"&gt;&lt;span style="color: blue; text-decoration: underline;"&gt;http://www.mysql.org MySQL&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-left: 18pt;"&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;PHP 4.1 or greater, 4.3.6 or greater highly recommended for advanced features &lt;a href="http://www.php.net%20php/" title="http://www.php.net PHP" target="_blank"&gt;&lt;span style="color: blue; text-decoration: underline;"&gt;http://www.php.net PHP&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-left: 18pt;"&gt;&lt;a href="http://net-snmp.sourceforge.net%20net-snmp/" title="http://net-snmp.sourceforge.net net-snmp" target="_blank"&gt;&lt;span style="color: blue; font-family: Verdana; font-size: 10pt; text-decoration: underline;"&gt;http://net-snmp.sourceforge.net net-snmp&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Install Cacri di Debian&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Pada dasarnya, kalau Anda menggunakan debian menginstall cacti tidaklah susah karena paket .deb sudah tersedia, Cuma pada saat saya peraktekan terjadi error nah untuk menyiasatinya kita install manual aja paket-paket yang dibutuhkan untuk menjalankan cacti.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;ol&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Install cacti dengnan menggunakan apt-get (auto)&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#apt-get install cacti&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Ket : ini akan menginstall semua paket yang di butuhkan seperti mysql, rrdtool, Cuma sayangnya pas saya coba masih ada setikit error pada paket mysql-nya dan php dan biasanya php-ya masih yang php4, untuk menginstall versi terbaru dari php kita lakukan cara manual aja dech, caranya ada di langkah ke 2.&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Install paket-paket yang di butuhkan si cacti&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;strong&gt;Menginstall server database MySQ&lt;/strong&gt;L&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#apt-get install mysql-server&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Ket : MySQL awalnya hanya mengizinkan koneksi dari localhost (127.0.0.1) saja. Kita harus menghapus pembatasan in jika Anda ingin membuat MySQL dapat diakses oleh siapapun melalui internet. Buka berkas /etc/mysql/my.cnf&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#vim /etc/mysql/my.cnf&lt;br /&gt;&lt;/span&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Cari baris ini bind-address = 127.0.0.1 dan berikan komentar (#)&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;…&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt; #bind-address           = 127.0.0.1&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;…&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Ket : Default-nya MySQL tidak memasang password root. Hal ini dapat menimbulkan masalah keamanan. Anda harus segera menetapkan password root. Anda juga harus menetapkan password root, apabila ingin menggunakan akses root dari komputer lokal Anda. Nama-mesin-local adalah nama komputer yang sedang Anda gunakan.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#mysqladmin -u root password your-new-password&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#mysqladmin -h root@nama-mesin-lokal -u root -p password your-new-password&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#sudo /etc/init.d/mysql restart&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Sampai disini install mysql sudah selesai.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;strong&gt;Menginstall server http Apache&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;apt-get install apache2&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Ket : Setelah proses installasi selesai, untuk mencobanya Anda ketikan perintah ini di browser : &lt;a href="http://localhost/"&gt;http://localhost&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;strong&gt;Bagaimana menginstal PHP5 untuk Server HTTP Apache&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#sudo apt-get install php5&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#sudo apt-get install libapache2-mod-php5&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#sudo /etc/init.d/apache2 restart&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Ket : Jika Anda hanya membutuhkan php4 ya ganti aja tulisan php5 dengan tulisan php4&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Untuk menguji jika php4 telah terinstal dengan baik&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#vim /var/www/testphp.php&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Buat berkas baru dan masukkan baris berikut&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;?php phpinfo(); ?&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Simpan berkas yang telah disunting&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Untuk mengujinya coba buka browser dan ketikan perintah ini &lt;a href="http://localhost/testphp.php"&gt;http://localhost/testphp.php&lt;/a&gt; kalau ga mau jalan coba ketikan seperti ini &lt;a href="http://ipaddressserver/testphp.php"&gt;http://ipAddressServer/testphp.php&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;strong&gt;Bagaimana menginstal MYSQL untuk Server HTTP Apache&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#apt-get install libapache2-mod-auth-mysql&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#apt-get install php5-mysql&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Untuk membuat PHP bekerja dengan MySQL, buka berkas&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#vim /etc/php5/apache2/php.ini&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Anda harus menghapus komentar di baris “;extension=mysql.so” sehingga akan terlihat seperti ini&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;…&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt; extension=mysql.so&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;…&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Simpan berkas dan keluar&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:#/etc/init.d/apache2 restart&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Untuk mempermudah penggunaan php saya sangat menyarankan Anda menggunakan program yang namanya “phpmyadmin” cara install di debian sbb:&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;apt-get install phpmyadmin&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Ket : Kalau dah selesai installnya, coba jalankan browser dan ketikan &lt;a href="http://localhost/phpmyadmin"&gt;http://localhost/phpmyadmin&lt;/a&gt; dan akan muncul spt gambar di bawah ini :&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;img src="http://ekarh.files.wordpress.com/2007/12/121407-0928-installasid1.png?w=651&amp;amp;h=369" height="369" width="651" /&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Nama pengguna : root&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Kata Sandi : password_anda&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Dan akan tampil seperti gambar di bawah ini :&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;img src="http://ekarh.files.wordpress.com/2007/12/121407-0928-installasid2.png?w=654&amp;amp;h=373" height="373" width="654" /&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Ket : Sejauh ini install paket-paket yang di butuhkan oleh si cacti sudah selesai, sekarang tibalah saatnya untuk mengkonfigurasi si cacti.&lt;br /&gt;&lt;/span&gt; &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Configurasi Cacti&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;strong&gt;Membuat user buat si cacti :&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#adduser cacti&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Membuat MySQL database buat si cacti&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;mysqladmin –user=root create cacti&lt;br /&gt;&lt;/span&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Meninport database default si cacti&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;mysql cacti &lt; cacti.sql&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Ket : Tapi kalau dengan cara ini masih menemui kesulitan atau error maka gunakan cara 2 dengan menggunakan phpmyadmin, supaya lebih mudah kita mengimportnya lewat phpmyadmin.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;ol&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Bukan browser kesayangan Anda&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Download cacti &lt;a href="http://www.cacti.net/downloads/cacti-0.8.7a.zip"&gt;http://www.cacti.net/downloads/cacti-0.8.7a.zip&lt;/a&gt; dan lakukan extract..&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Ketikan perintah ini : &lt;a href="http://localhost/phpmyadmin"&gt;http://localhost/phpmyadmin&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Akan tampil gambar seperti di atas, masukan username dan password anda dan tekan enter.&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Pada bagian kiri di bagian “Database” pilih “cacti”&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Pada bagian atas pilih tulisan “import”&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Pada bagian “File to Import” klik tombol “Browse..”&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Cari dimana Anda meletakan hail extract.. cacti tersebut dan filih file “cacti” klik “open”&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Klik “GO” di pojok kanan bawah.&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Ket : Prosess di atas sebetulnya cukup dilakukan dengan perintah mysql cacti &lt; cacti.sql, Cuma pas say peraktekan kok ga bisa ya… makanya saya cari car lain aja dech…!!&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;strong&gt;Membuat MySQL username dan password buat si Cacti&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;mysql –user=root mysql&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;mysql&gt; GRANT ALL ON cacti.* TO cactiuser@localhost IDENTIFIED BY ’somepassword’;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;mysql&gt; flush privileges;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Saatnya meng Edit &lt;span style="color: rgb(0, 122, 0);"&gt;include/config.php &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#vim /usr/share/cacti/site/include/config.php&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Cari bagian-bagian ini dan tambahkan user, password, database buat di cacti.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;….&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;  $database_default = “cacti”;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;  $database_hostname = “localhost”;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;  $database_username = “cactiuser”;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;  $database_password = “cacti”;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;….&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Ubah permissions directory-nya&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#chown -R cactiuser /usr/share/cacti/site/rra&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#chown -R cactiuser /usr/share/cacti/site/log&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Saatnya meng Edit &lt;span style="color: rgb(204, 0, 102);"&gt;/etc/crontab&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Debian:~#vim /etc/crontab&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Masukan baris berikut ini&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;….&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;   */5 * * * * cactiuser php /var/www/html/cacti/poller.php &gt; /dev/null 2&gt;&amp;amp;1&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;….&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Hemmmmm hemmmm sepertinya perjalanan panjang installasi dan configurasi cacti sudah hampir mendekati selesai…&lt;br /&gt;&lt;/span&gt; &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Tahap akhir konfigurasi Cacti.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Buka browser kesayangan anda dan ketikan &lt;a href="http://localhost/cacti"&gt;http://localhost/cacti&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Jika tidak ada yang error klik next dan selesay dechhhhhhhhhhhhh….&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Tinggal Anda bereksperimen sendiri menggunakan Cacti..&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Demikian dulu pelajaranya… kl ada yang mau menambahkan silahkan posting nanti akan saya tampilkan dech… swerrrrrrrr&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;CACTI SUPPORT&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://forums.cacti.net/"&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;http://forums.cacti.net/&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Download Official Patches For Cacti&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.cacti.net/download_patches.php"&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;http://www.cacti.net/download_patches.php&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Additional scripts For Cacti&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.cacti.net/additional_scripts.php"&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;http://www.cacti.net/additional_scripts.php&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;Cacti Screen Shots&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.cacti.net/screenshots.php"&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;http://www.cacti.net/screenshots.php&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;BAHAN RUJUKAN&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.debianhelp.co.uk/cacti.htm"&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;http://www.debianhelp.co.uk/cacti.htm&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.cacti.net/downloads/docs/html/unix_configure_cacti.html"&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;http://www.cacti.net/downloads/docs/html/unix_configure_cacti.html&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://wiki.ubuntu-id.org/PanduanUbuntu#head-6516d8e7865828370de398090526456696fab9f8"&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;http://wiki.ubuntu-id.org/PanduanUbuntu&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;a href="http://corebsd.or.id/wiki/doku.php?id=coreartikel:cacti"&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;http://corebsd.or.id/wiki/doku.php?id=coreartikel:cacti&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-2962796369737917242?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/2962796369737917242/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=2962796369737917242' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2962796369737917242'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/2962796369737917242'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/05/instalasi-caci-di-debian.html' title='Instalasi Caci di Debian'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-8088978123787547453</id><published>2008-05-10T18:50:00.006+07:00</published><updated>2008-12-13T07:35:59.944+07:00</updated><title type='text'>ZEROSHELL live cd router</title><content type='html'>Bermula dari rencana mengganti router mikrotik kantor jakarta dengan komputer IBM Netvista dari mas priyo yang ternyata tidak ikhlas kalau harddisk nya di babat karena ada konfigurasi SIP Server.&lt;br /&gt;&lt;br /&gt;Semula mau coba mikrotik booting lewat USB, percobaan pertama sukses menggunakan USB 1GB tapi kan sayang-sayang tuh jadi coba pake USB 128MB hadiah dari vendor eh ternyata bermasalah akhirnya cari-cari live+cd+router di google.com dan akhirnya didapat ZEROSHELL yang merupakan router live cd berbasis linux.&lt;br /&gt;&lt;br /&gt;cara instalasinya mudah saja download file iso nya lalu burn di cd kemudian booting komputer menggunakan live cd tersebut , selanjutnya konfigure ZEROSHELL lewat browser ke ip defaultnya 192.168.0.75/24 dengan user=admin , pass=zeroshell kemudian setup networknya dan fitur-fitur yang dibutuhkan seperti dhcp server, qos dll.&lt;br /&gt;&lt;br /&gt;yang menarik konfigurasinya bisa di simpan di USB jadi kalau di reboot setinggannya tidak hilang karena ZEROSHELL akan membaca konfigurasi yang active dari USB tersebut.&lt;br /&gt;&lt;br /&gt;Tapi ini bagian yang paling menyebalkan karena caranya mesti buat database dulu di USB terus copy konfigurasi yang sudah kita buat baru aktifasikan file database yang berisi konfigurasi yang telah kita buat. atau bisa juga di backup filenya jadi simpan di komputer kerja admin, kalau sewaktu-waktu dibutuhkan bisa di save ke USB, pengalaman lebih baik USB di format menggunakan ext3 , kalau pake vfat (FAT) format windows file databasenya jadi bengkak ukurannya.&lt;br /&gt;&lt;br /&gt;berikut adalah tampilan ZEROSHELL router yang digunakan di kantor&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nzWcXcVYSRs/SCWMYOllk0I/AAAAAAAAAHw/QmDIrxiG9io/s1600-h/zeroshell-router-kantor-jakarta.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_nzWcXcVYSRs/SCWMYOllk0I/AAAAAAAAAHw/QmDIrxiG9io/s400/zeroshell-router-kantor-jakarta.JPG" alt="" id="BLOGGER_PHOTO_ID_5198715692729602882" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Web ZEROSHELL bisa diakses di &lt;a href="http://www.zeroshell.net/eng"&gt;http://www.zeroshell.net/eng&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nzWcXcVYSRs/SCWMOellkzI/AAAAAAAAAHo/KaAlFsv1OwU/s1600-h/zeroshell-router-web.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_nzWcXcVYSRs/SCWMOellkzI/AAAAAAAAAHo/KaAlFsv1OwU/s400/zeroshell-router-web.JPG" alt="" id="BLOGGER_PHOTO_ID_5198715525225878322" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Jadi kalau mau ngirit manfaatin PC bekas buat router dikantor ZEROSHELL bisa jadi alternatif murah meriah.&lt;br /&gt;&lt;br /&gt;Sayangnya saya belum berhasil untuk setingan QoS nya mungkin hanya efektif di mode bridge.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-8088978123787547453?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/8088978123787547453/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=8088978123787547453' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/8088978123787547453'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/8088978123787547453'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/05/zerowall-livecd-router.html' title='ZEROSHELL live cd router'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_nzWcXcVYSRs/SCWMYOllk0I/AAAAAAAAAHw/QmDIrxiG9io/s72-c/zeroshell-router-kantor-jakarta.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-1017133897310735577</id><published>2008-05-08T13:51:00.000+07:00</published><updated>2008-05-08T13:52:13.966+07:00</updated><title type='text'>What is a VLAN?</title><content type='html'>&lt;h2&gt;The Basic Definition&lt;/h2&gt; &lt;p&gt;The acronym VLAN expands to Virtual Local Area Network. A VLAN is a logical local area network (or LAN) that extends beyond a single traditional LAN to a group of LAN segments, given specific configurations. Because a VLAN is a logical entity, its creation and configuration is done completely in software.&lt;/p&gt;  &lt;h2&gt;How Is a VLAN Identified&lt;/h2&gt;  &lt;p&gt;Since a VLAN is a software concept, identifiers and configurations for a VLAN must be properly prepared for it to function as expected. Frame coloring is the process used to ensure that VLAN members or groups are properly identified and handled. With frame coloring, packets are given the proper VLAN ID at their origin so that they may be properly processed as they pass through the network. The VLAN ID is then used to enable switching and routing engines to make the appropriate decisions as defined in the VLAN configuration.&lt;/p&gt;  &lt;h2&gt;Why Use VLANs&lt;/h2&gt;  &lt;p&gt;Traditional network designs use routers to create broadcast domains and limit broadcasts between multiple subnets. This prevents broadcast floods in larger networks from consuming resources, or causing unintentional denials of service unnecessarily. Unfortunately, the traditional network design methodology has some flaws in design&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;Geographic Focus - Traditional network designs focus on physical locations of equipment and personnel for addressing and LAN segment placement. Because of this there are a few significant drawbacks:&lt;/li&gt;&lt;li&gt;Network segments for physically disjointed organizations cannot be part of the same address space. Each physical location must be addressed independently, and be part of its own broadcast domain. This can force personnel to be located in a central location, or to have additional latency or connectivity shortfalls.&lt;/li&gt;&lt;li&gt;Relocations of personnel and departments can become difficult, especially if the original location retains its network segments. Relocated equipment will have to be reconfigured based on the new network configuration.&lt;/li&gt;&lt;/ul&gt;  &lt;p&gt;A VLAN solution can alleviate both of these drawbacks by permitting the same broadcast domain to extend beyond a single segment.&lt;/p&gt; &lt;ul&gt;&lt;li&gt;Additional Bandwidth Usage - Traditional network designs require additional bandwidth because packets have to pass through multiple levels of network connectivity because the network is segmented.&lt;/li&gt;&lt;/ul&gt;  &lt;p&gt;A proper VLAN design can ensure that only devices that have that VLAN defined on it will receive and forward packets intended as source or destination of the network flow.&lt;/p&gt;  &lt;h2&gt;Types of VLAN&lt;/h2&gt;  &lt;p&gt;There are only two types of VLAN possible today, cell-based VLANs and frame-based VLANs.&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;Cell-based VLANs are used in ATM switched networks with LAN Emulation (or LANE). LANE is used to allow hosts on legacy LAN segments to communicate using ATM networks without having to use special hardware or software modification.&lt;/li&gt;&lt;li&gt;Frame-based VLANs are used in ethernet networks with frame tagging. The two primary types of frame tagging are IEEE 802.10 and ISL (Inter Switch Link is a Cisco proprietary frame-tagging). Keep in mind that the 802.10 standard makes it possible to deploy VLANs with 802.3(Ethernet), 802.5(Token-Ring), and FDDI, but ethernet is most common.&lt;/li&gt;&lt;/ul&gt;  &lt;h2&gt;VLAN modes&lt;/h2&gt;  &lt;p&gt;There are three different modes in which a VLAN can be configured.  These modes are covered below:&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;VLAN Switching Mode - The VLAN forms a switching bridge in which frames are forwarded unmodified.&lt;/li&gt;&lt;li&gt;VLAN Translation Mode - VLAN translation mode is used when the frame tagging method is changed in the network path, or if the frame traverses from a VLAN group to a legacy or native interface which is not configured in a VLAN. When the packet is to pass into a native interface, the VLAN tag is removed so that the packet can properly enter the native interface.&lt;/li&gt;&lt;li&gt;VLAN Routing Mode - When a packet is routed from one VLAN to a different VLAN, you use VLAN routing mode. The packet is modified, usually by a router, which places its own MAC address as the source, and then changes the VLAN ID of the packet.&lt;/li&gt;&lt;/ul&gt;  &lt;h2&gt;VLAN configurations&lt;/h2&gt;  &lt;p&gt;Different terminology is used between different hardware manufacturers when it comes to VLANs. Because of this there is often confusion at implementation time. Following are a few details, and some examples to assist you in defining your VLANs so confusion is not an issue.&lt;/p&gt;  &lt;h3&gt;Cisco VLAN terminology&lt;/h3&gt;  &lt;p&gt;You need a few details to define a VLAN on most Cisco equipment. Unfortunately, because Cisco sometimes acquires the technologies they use to fill their switching, routing and security product lines, naming conventions are not always consistent. For this article, we are focusing only one Cisco switching and routing product lines running Cisco IOS.&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;VLAN ID - The VLAN ID is a unique value you assign to each VLAN on a single device. With a Cisco routing or switching device running IOS, your range is from 1-4096. When you define a VLAN you usually use the syntax "vlan x" where x is the number you would like to assign to the VLAN ID. VLAN 1 is reserved as an administrative VLAN. If VLAN technologies are enabled, all ports are a member of VLAN 1 by default.&lt;/li&gt;&lt;li&gt;VLAN Name - The VLAN name is an text based name you use to identify your VLAN, perhaps to help technical staff in understanding its function. The string you use can be between 1 and 32 characters in length.&lt;/li&gt;&lt;li&gt;Private VLAN - You also define if the VLAN is to be a private vlan in the VLAN definition, and what other VLAN might be associated with it in the definition section. When you configure a Cisco VLAN as a private-vlan, this means that ports that are members of the VLAN cannot communicate directly with each other by default. Normally all ports which are members of a VLAN can communicate directly with each other just as they would be able to would they have been a member of a standard network segment. Private vlans are created to enhance the security on a network where hosts coexisting on the network cannot or should not trust each other. This is a common practice to use on web farms or in other high risk environments where communication between hosts on the same subnet are not necessary. Check your Cisco documentation if you have questions about how to configure and deploy private VLANs.&lt;/li&gt;&lt;li&gt; VLAN modes - in Cisco IOS, there are only two modes an interface can operate in, "mode access" and "mode trunk". Access mode is for end devices or devices that will not require multiple VLANs. Trunk mode is used for passing multiple VLANs to other network devices, or for end devices that need to have membership to multiple VLANs at once. If you are wondering what mode to use, the mode is probably "mode access".&lt;/li&gt;&lt;/ul&gt;  &lt;h3&gt;Cisco VLAN implementations&lt;/h3&gt;  &lt;b&gt;VLAN Definition&lt;/b&gt; &lt;p&gt;To define a VLAN on a cisco device, you need a VLAN ID, a VLAN name, ports you would like to participate in the VLAN, and the type of membership the port will have with the VLAN.&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;Step 1 - Log into the router or switch in question and get into enable mode.&lt;/li&gt;&lt;li&gt;Step 2 - Get into configuration mode using "conf t". &lt;/li&gt;&lt;li&gt;Step 3 - Create your VLAN by entering "vlan X" where X is the ID you would like to assign the VLAN.&lt;/li&gt;&lt;li&gt;Step 4 - Name your VLAN by entering "name &lt;vlan&gt;". Replace &lt;vlan&gt; with the string you would like to identify your VLAN by.&lt;/li&gt;&lt;li&gt;Step 5 - If you want your new VLAN to be a private-vlan, you now enter "private-vlan primary" and "private-vlan association Y" where Y is the secondary VLAN you want to associate with the primary vlan. If you would like the private VLAN to be community based, you enter "private-vlan community" instead.&lt;/li&gt;&lt;li&gt;Step 6 - Exit configuration mode by entering "end".&lt;/li&gt;&lt;li&gt;Step 7 - Save your configuration to memory by entering "wr mem" and to the network if you have need using "wr net". You may have to supply additional information to write configurations to the network depending on your device configuration.&lt;/li&gt;&lt;/ul&gt;    &lt;b&gt;VLAN Configuration&lt;/b&gt;  &lt;p&gt;A VLAN isn't much use if you haven't assigned it an IP Address, the subnet netmask, and port membership. In normal network segment configurations on routers, individual interfaces or groups of interfaces (called channels) are assigned IP addresses. When you use VLANs, individual interfaces are members of VLANs and do not have individual IP addresses, and generally don't have access lists applied to them. Those features are usually reserved for the VLAN interfaces. The following steps detail one method of creating and configuring your VLAN interface. NOTE: These steps have already assumed that you have logged into the router, gotten into enable mode, and entered configuration mode. These specific examples are based on the Cisco 6500 series devices.&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;Step 1 - Enter "Interface VlanX" where X is the VLAN ID you used in the VLAN definition above.&lt;/li&gt;&lt;li&gt;Step 2 - This step is optional.  Enter "description &lt;vlan description=""&gt;" where VLAN description details what the VLAN is going to be used for. You can just simply re-use the VLAN name you used above if you like.&lt;/vlan&gt;&lt;/li&gt;&lt;li&gt;Step 3 - Enter "ip address &lt;address&gt; &lt;netmask&gt;" where &lt;address&gt; is the address you want to assign this device in the VLAN, and &lt;netmask&gt; is the network mask for the subnet you have assigned the VLAN.&lt;/li&gt;&lt;li&gt;Step 4 - The step is optional. Create and apply an access list to the VLAN for inbound and outbound access controls. For a standard access list enter "access-group XXX in" and "access-group YYY out" where XXX and YYY corresponds to access-lists you have previously configured. Remember that the terms are taken in respect to the specific subnet or interface, so "in" means from the VLAN INTO the router, and "out" means from the router OUT to the VLAN.&lt;/li&gt;&lt;li&gt;Step 5 - This step is optional. Enter the private VLAN mapping you would like to use if the port is part of a private VLAN. This should be the same secondary VLAN you associated with the primary VLAN in VLAN definition above. Enter "private-vlan mapping XX" where XX is the VLAN ID of the secondary VLAN you would like to associate with this VLAN.&lt;/li&gt;&lt;li&gt;Step 6 - This step is optional. Configure HSRP and any other basic interface configurations you would normally use for your Cisco device.&lt;/li&gt;&lt;li&gt;Step 7 - Exit configuration mode by entering "end".&lt;/li&gt;&lt;li&gt;Step 8 - Save your configuration to memory by entering "wr mem" and to the network if you have need using "wr net". You may have to supply additional information to write configurations to the network depending on your device configuration.&lt;/li&gt;&lt;/ul&gt;  &lt;p&gt;Now you have your vlan defined and configured, but no physical ports are a member of the VLAN, so the VLAN still isn't of much use. Next port membership in the VLAN is described. IOS devices describe interfaces based on a technology and a port number, as with "FastEthernet3/1" or "GigabitEthernet8/16". Once you have determined which physical ports you want to be members of the VLAN you can use the following steps to configure it. NOTE: These steps have already assumed that you have logged into the router, gotten into enable mode, and entered configuration mode.&lt;/p&gt;  &lt;b&gt;For access ports&lt;/b&gt; &lt;ul&gt;&lt;li&gt;Step 1 - Enter "Interface &lt;interface&gt;" where &lt;interface&gt; is the name Cisco has assigned the interface you would like to associate with the VLAN.&lt;/li&gt;&lt;li&gt;Step 2 - This step is optional. Enter "description &lt;interface&gt;" where &lt;interface&gt; is text describing the system connected to the interface in question. It is usually helpful to provide DNS hostname, IP Address, which port on the remote system is connected, and its function.&lt;/li&gt;&lt;li&gt;Step 3 - This step depends on your equipment and IOS version, and requirements. Enter "switchport" if you need the interface to act as a switch port. Some hardware does not support switchport mode, and can only be used as a router port. Check your documentation if you don't know the difference between a router port and a switch port.&lt;/li&gt;&lt;li&gt;Step 4 - Only use this step if you used step 3 above. Enter "switchport access vlan X" where X is the VLAN ID of the VLAN you want the port to be a member of.&lt;/li&gt;&lt;li&gt;Step 5 - Only use this step if you used step 3 above. Enter "switchport mode access" to tell the port that you want it to be used as an access port.&lt;/li&gt;&lt;li&gt;Step 6 - Exit configuration mode by entering "end".&lt;/li&gt;&lt;li&gt;Step 7 - Save your configuration to memory by entering "wr mem" and to the network if you have need using "wr net". You may have to supply additional information to write configurations to the network depending on your device configuration.&lt;/li&gt;&lt;/ul&gt;  &lt;b&gt;For trunk ports&lt;/b&gt; &lt;ul&gt;&lt;li&gt;Step 1 - Enter "Interface &lt;interface&gt;" where &lt;interface&gt; is the name Cisco has assigned the interface you would like to associate with the VLAN.&lt;/li&gt;&lt;li&gt;Step 2 - This step is optional. Enter "description &lt;interface&gt;" where &lt;interface&gt; is text describing the system connected to the interface in question. It is usually helpful to provide DNS hostname, IP Address, which port on the remote system is connected, and its function.&lt;/li&gt;&lt;li&gt;Step 3 - This step depends on your equipment and IOS version, and requirements. Enter "switchport" if you need the interface to act as a switch port. Some hardware does not support switchport mode, and can only be used as a router port. Check your documentation if you don't know the difference between a router port and a switch port.&lt;/li&gt;&lt;li&gt;Step 4 - Only use this step if you used step 3 above. Enter "switchport trunk encapsulation dot1q". This tells the VLAN to use dot1q encapsulation for the VLAN, which is the industry standard encapsulation for trunking. There are other encapsulation options, but your equipment may not operate with non Cisco equipment if you use them.&lt;/li&gt;&lt;li&gt;Step 5 - Only use this step if you used step 3 above. Enter "switchport trunk allowed vlan XX, YY, ZZ" where XX, YY, and ZZ are VLANs you want the trunk to include. You can define one or more VLANs to be allowed in the trunk.&lt;/li&gt;&lt;li&gt;Step 6 - Only use this step if you used step 3 above. Enter "switchport mode trunk" to tell the port to operate as a VLAN trunk, and not as an access port.&lt;/li&gt;&lt;li&gt;Step 7 - Exit configuration mode by entering "end".&lt;/li&gt;&lt;li&gt;Step 8 - Save your configuration to memory by entering "wr mem" and to the network if you have need using "wr net". You may have to supply additional information to write configurations to the network depending on your device configuration.&lt;/li&gt;&lt;/ul&gt;  &lt;b&gt;For private VLAN ports&lt;/b&gt; &lt;ul&gt;&lt;li&gt;Step 1 - Enter "Interface &lt;interface&gt;" where &lt;interface&gt; is the name Cisco has assigned the interface you would like to associate with the VLAN.&lt;/li&gt;&lt;li&gt;Step 2 - This step is optional. Enter "description &lt;interface&gt;" where &lt;interface&gt; is text describing the system connected to the interface in question. It is usually helpful to provide DNS hostname, IP Address, which port on the remote system is connected, and its function.&lt;/li&gt;&lt;li&gt;Step 3 - This step depends on your equipment and IOS version, and requirements. Enter "switchport" if you need the interface to act as a switch port. Some hardware does not support switchport mode, and can only be used as a router port. Check your documentation if you don't know the difference between a router port and a switch port.&lt;/li&gt;&lt;li&gt;Step 4 - Enter "switchport private-vlan host association XX YY" where XX is the primary VLAN you want to assign, YY is the secondary VLAN you want to associate with it.&lt;/li&gt;&lt;li&gt;Step 5 - Enter "switchport mode private-vlan host" to force the port to operate as a private-vlan in host mode.&lt;/li&gt;&lt;li&gt;Step 6 - Exit configuration mode by entering "end".&lt;/li&gt;&lt;li&gt;Step 7 - Save your configuration to memory by entering "wr mem" and to the network if you have need using "wr net". You may have to supply additional information to write configurations to the network depending on your device configuration.&lt;/li&gt;&lt;/ul&gt;  &lt;p&gt;You should now have your VLAN properly implemented on a Cisco IOS device.&lt;/p&gt;  &lt;h3&gt;HP VLAN terminology&lt;/h3&gt;  &lt;p&gt;&lt;a itxtdid="5827986" target="_blank" href="http://www.tech-faq.com/vlan.shtml#" style="border-bottom: 0.1em solid darkgreen ! important; text-decoration: underline ! important; font-weight: normal ! important; padding-bottom: 1px ! important; color: darkgreen ! important; background-color: transparent ! important;" classname="iAs" class="iAs"&gt;HP's&lt;/a&gt; Procurve line of switchgear is becoming more and more prevalent in enterprise and other business environments. Because of this, it isn't uncommon to have to get Cisco and Procurve hardware to integrate, and because of terminology this can be a challenge. Below some of the VLAN terminology is defined so there is less opportunity for confusion.&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;VLAN ID - Fortunately, VLAN id's are pretty much the same everywhere, the only significant differences are the range of IDs that can be used. With Procurve devices, the number of VLANs is defined in the configuration. The default maximum VLANs supported on a Procurve device differs between models and firmware revisions, but is commonly set to 8. Newer Procurve hardware supports 4,096 VLAN ids, but only 256 concurrently defined VLANs on a single device. VLAN ID 1 is reserved for the "DEFAULT_VLAN" or the default administrative VLAN.&lt;/li&gt;&lt;li&gt;VLAN names - VLAN names are text fields that assist technicians to identify VLANs. Procurve allows names up to 32 characters, but if you want it to properly display in menu configuration mode, you should probably limit the name to 12 characters.&lt;/li&gt;&lt;li&gt;VLAN modes - Procurve has three modes of operation for VLANs on the chassis, Untagged, Tagged, and No. Untagged mode is cisco's access mode. This mode is used for ports that connect to end nodes, or devices that will not be passing VLAN traffic forward. Tagged mode is the same as Cisco's trunk mode. This mode is used for ports that are connecting to devices that will be passing VLAN traffic forward, or for trunking multiple VLANs. No mode means that the port in question has no association whatsoever with that VLAN.&lt;/li&gt;&lt;li&gt;Special note on "trunk" - Lots of confusion surrounds the word "trunk" when you go between vendor equipment. In Cisco's case, trunking is only used with VLANs. If you want to group multiple ethernet ports into a single logical ethernet group, they call it a channel-group. This is regardless of whether FEC or LACP is used for the channel properties. Procurve uses "trunk" to define a group of ethernet ports when using the HP trunking protocol, and the term "Tagged" for what Cisco calls a VLAN trunk. Of course, these two technologies have nothing to do with each other, but because of naming conventions, confusion arises.&lt;/li&gt;&lt;/ul&gt;  &lt;h3&gt;HP Procurve VLAN implementations&lt;/h3&gt;  &lt;b&gt;VLAN Definition&lt;/b&gt;  &lt;p&gt;Most modern Procurve switches enable VLAN use by default, but if, for some reason, you have an older model, log into the switch, get into manager mode, go to the switch configuration menu (usually item 2), then the VLAN menu (usually item 8), then the VLAN support item (usually item 1), and make sure VLANs are enabled. If you change this setting, you will need to reboot the switch to get it to activate properly. The configuration menu is useful for these kinds of activities, troubleshooting, and other things, but is a little more difficult for configuring multiple switches or for using configuration templates, so the rest of the HP Procurve configuration details will be provided for the console configuration mode. Aside for enabling VLAN support as a whole, VLAN definitions and configuration are created in the same place, so the rest of the configuration examples will be provided under the VLAN configuration topic.&lt;/p&gt;  &lt;b&gt;VLAN Configuration&lt;/b&gt;  &lt;p&gt;Configuring VLANs on a modern Procurve is pretty simple, you must first define the VLAN, set its properties, and then set up membership for ports and the VLAN mode they will support. The following list should help you accomplish these tasks. NOTE: HP has defined its interface ports by using a module/port convention. If you have a non-modular chassis (such as the 3448cl) then ports are numbered only using numbers, such as 1 or 36. If the chassis is modular (such as the 5308) then the ports number is prepended with the module slot, such as A1 or H6. No reference to the type of switch port (ethernet, fast ethernet, gigabit ethernet) is used for port reference.&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;Step 1 - Log into the switch and get into manager mode. If, after logging in, you are in the configuration menu, exit the configuration menu by selecting item 5 (in most cases) or by using the arrow keys on your keyboard to highlight the "Command Line (CLI)" item.&lt;/li&gt;&lt;li&gt;Step 2 - Enter "conf t" to get into terminal configuration mode.&lt;/li&gt;&lt;li&gt;Step 3 - Enter "vlan X" where X is the VLAN id of the VLAN you would like to create.&lt;/li&gt;&lt;li&gt;Step 4 - Name your VLAN by entering "name "&lt;vlan&gt;"" where &lt;vlan&gt; is a text string from 1 to 32 characters (12 characters if you care about the configuration menu display). You should use quotes when naming the VLAN.&lt;/li&gt;&lt;li&gt;Step 5 - Give the VLAN an IP address by entering "ip address &lt;ip&gt; &lt;netmask&gt;" where &lt;ip&gt; is the IP address you want to assign this switch in that subnet, and &lt;netmask&gt; is the network mask for the subnet assigned.&lt;/li&gt;&lt;li&gt;Step 6 - This step is optional. If you want to assign some end node ports to the VLAN enter "untagged &lt;port-list&gt;" where &lt;port-list&gt; is a list of ports either comma delimited if they are non-sequential, or using a dash between list beginning and end if they are. An example of this is "untagged 1,3,5,7-16". This would configure ports 1, 3, 5, and 7 through 16 to be untagged on that VLAN.&lt;/li&gt;&lt;li&gt;Step 7 - This step is optional. If you want to assign some VLAN trunk ports to the VLAN enter "tagged &lt;port-list&gt;" where &lt;port-list&gt; is a list of ports either comma delimited if they are non-sequential, or using a dash between list beginning and end if they are. An example of this is "untagged 1,3,5,7-16". This would configure ports 1, 3, 5, and 7 through 16 to be untagged on that VLAN.&lt;/li&gt;&lt;li&gt;Step 8 - Enter "exit" to leave VLAN configuration mode.&lt;/li&gt;&lt;li&gt;Step 9 - Exit configuration mode by entering "exit" again.&lt;/li&gt;&lt;li&gt;Step 10 - Save your configuration by entering "wr memory".&lt;/li&gt;&lt;/ul&gt;  &lt;p&gt;You have now successfully configured your HP Procurve VLAN.&lt;/p&gt;  &lt;h3&gt;Vendor Summary&lt;/h3&gt;  &lt;p&gt;If you are going to integrate Cisco and HP Procurve hardware on the same network, and you intend to use VLANs there are only a few things you need to remember:&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;For end nodes - Cisco uses "mode access", HP uses "untagged" mode.&lt;/li&gt;&lt;li&gt;For VLAN dot1q trunks - Cisco uses "mode trunk", HP uses "tagged" mode.&lt;/li&gt;&lt;li&gt;For no VLAN association - Cisco uses no notation at all, HP uses "no" mode in the configuration menu, or you have VLAN support turned off.&lt;/li&gt;&lt;/ul&gt;  &lt;p&gt;Next time you have to integrate the two with VLANs, this simple list should help keep you out of trouble.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Source: http://www.tech-faq.com/vlan.shtml&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4650800593925871709-1017133897310735577?l=inetshoot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://inetshoot.blogspot.com/feeds/1017133897310735577/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4650800593925871709&amp;postID=1017133897310735577' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/1017133897310735577'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4650800593925871709/posts/default/1017133897310735577'/><link rel='alternate' type='text/html' href='http://inetshoot.blogspot.com/2008/05/what-is-vlan.html' title='What is a VLAN?'/><author><name>Harijanto Pribadi</name><uri>http://www.blogger.com/profile/16396028104729390804</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_nzWcXcVYSRs/TN9CtCH_WFI/AAAAAAAAAhc/bMlO4TXZI94/S220/IMG00316-20100908-1456.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4650800593925871709.post-5313608282937888904</id><published>2008-05-02T23:05:00.004+07:00</published><updated>2008-05-02T23:08:10.294+07:00</updated><title type='text'>Mengatasi postfix/postdrop[xxxxx]: warning: unable to look up public/pickup: Permission denied</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Hari ini ada masalah di smtp2 sbb:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;root@proxy02-smg [/var/spool/postfix]# tail -f /var/log/maillog&lt;br /&gt;May  2 21:52:31 proxy02-smg postfix/postdrop[30924]: warning: unable to look up public/pickup: Permission denied&lt;br /&gt;May  2 21:52:31 proxy02-smg postfix/postdrop[31054]: warning: unable to look up public/pickup: Permission denied&lt;br /&gt;May  2 21:52:33 proxy02-smg postfix/postdrop[31410]: warning: unable to look up public/pickup: Permission denied&lt;br /&gt;May  2 21:52:34 proxy02-smg postfix/postdrop[31091]: warning: unable to look up public/pickup: Permission denied&lt;br /&gt;May  2 21:52:34 proxy02-smg postfix/postdrop[31062]: warning: unable to look up public/pickup: Permission denied&lt;br /&gt;May  2 21:52:34 proxy02-smg postfix/postdrop[31245]: warning: unable to look up public/pickup: Permission denied&lt;br /&gt;May  2 21:52:34 proxy02-smg postfix/postdrop[31255]: warning: unable to look up public/pickup: Permission denied&lt;br /&gt;May  2 21:52:34 proxy02-smg postfix/postdrop[31391]: warning: unable to look up public/pickup: Permission denied&lt;br /&gt;May  2 21:52:34 proxy02-smg postfix/postdrop[31087]: warning: unable to look up public/pickup: Permission denied&lt;br /&gt;May  2 21:52:35 proxy02-smg postfix/postdrop[31094]: warning: unable to look up public/pickup: Permission denied&lt;br /&gt;May  2 21:52:37 proxy02-smg postfix/postdrop[31056]: warning: unable to look up public/pickup: Permission denied&lt;br /&gt;May  2 21:52:37 proxy02-smg postfix/postdrop[31408]: warning: unable to look up public/pickup: Permission denied&lt;br /&gt;May  2 21:52:38 proxy02-smg postfix/postdrop[31257]: warning: unable to look up public/pickup: Permission denied&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Dari googling petunjuk yang didapat adalah&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;root@proxy02-smg [~]# postfix check&lt;br /&gt;root@proxy02-smg [~]# chgrp -R postdrop /var/spool/postfix/public/&lt;br /&gt;root@proxy02-smg [~]# chgrp -R postdrop /var/spool/postfix/maildrop/&lt;br /&gt;root@proxy02-smg [~]# postfix check&lt;br /&gt;&lt;br /&gt;&lt;span
