Skema C :
Modem---Mikrotik---Client
------------|
----------Proxy
Misal :
Modem=192.168.1.1/24
Mikrotik=eth0 (ke modem)192.168.1.2/24
Mikrotik=eth1(ke proxy)192.168.2.1/24
Mikrotik=eth2(ke client)192.168.3.1/24
Proxy=192.168.2.2/24
Client=192.168.3.2-10/24
Untuk proxy, NAT :
/ip firewall nat add chain=src-nat src-address=192.168.2.2/24 out-interface=eth0 action=masquerade
Untuk client, NAT :
/ip firewall add chain=src-nat src-address=192.168.3.2-192.168.3.10 out-interface=eth0 action=masquerade
Untuk client dipaksakan ke proxy (misal proxy pake port 3128):
/ip firewall chain=dst-nat protocol=tcp dst-port=80 in-interface=eth2 to-addresses=192.168.2.2 to-ports=3128
Routing di MT :
0.0.0.0/0 192.168.1.1
Abis itu tinggal atur bw yang ke client biar gak kecolongan, bw ke proxy di los ajah
thanks gan info'a
ReplyDeletesama2 gan
Delete