Setup Mangle Mikrotik Untuk Proxy Hit Loss External Proxy
Kali ini ada sedikit info mengenai squid proxy saya sangat tertarik dengan artikel yang di postkan oleh uburcumi di forummikrotik.com Soal tehnik lain proxy hit menggunakanexternal proxy dan soal trik lain untuk mendapatkan proxy hit yang mantap dan koneksi game tetap lancar.
Studi kasus yang dilakukan uburcumi seperti berikut :
Silahkan perhatikan secara seksama !!
Studi kasus yang dilakukan uburcumi seperti berikut :
Silahkan perhatikan secara seksama !!
Semua aktifitas user port 80, 81, 8080 dan 3128 di belokkan ke proxy, jika proxy belum mengcache maka si proxy akan mengambil dari Modem(internet), menyimpan di cache sekaligus menjawab request dari user.
Aktivitas user selain port 80, 81, 8080 dan 3128 akan melewati jalur menuju arah modem [download dari FTP ata dari P2P => jika akses P2P tidak di blok]
Nah dari kasus di atas muncullah pemikiran, bahwa :
Semua akses ke arah Modem harus di limit agar ada BW dapat tersisa yg bisa di gunakan untuk GAME online mengingat port game tidak di belokkan ke proxysquid.
Sedangkan akses antara Proxy Squid dan User di LOSS agar terjadi HIT atau transfer packet yg ada di cache proxy dapat di nikmati LOSS oleh user.
Mari berlanjut kesettingan mikrotik kita (Cara Setting Mangle Mikrotik Untuk Proxy Hit Loss External Proxy):
Scriptnya seperti di bawah ini
1. PROXY HIT LOSS
/ip firewall mangle add action=mark-packet chain=prerouting disabled=no dscp=12 new-packet-mark=Proxy_Hit passthrough=no comment="PROXY HIT DSCP"
/ip firewall mangle
add action=mark-connection chain=forward comment=Proxy_HIT \
disabled=no in-interface=Proxy new-connection-mark=Hit\
out-interface=Lokal passthrough=yes protocol=tcp
add action=mark-packet chain=forward comment="" connection-mark=Hit\
disabled=no in-interface=Proxy new-packet-mark=Proxy Hit\
out-interface=Lokal passthrough=no protocol=tcp
/queue tree
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no\
limit-at=0 max-limit=0 name=.:Proxy Hit:. packet-mark=Hit\
parent=global-out priority=1 queue=default
Nah itu dia proxy hit untuk meloloskan paket agar tidak terlimit oleh mikrotik.
2. Koneksi ke modem dari user atau dari user ke modem harus juga di batasi.(Limit Aktifitas modem - user)
Scriptnya seperti berikut :
/ip firewall mangle
add action=mark-connection chain=forward \
comment=DownloadfromLan1 connection-bytes=256000-4294967295\
disabled=no in-interface=Public-1 new-connection-mark=DownLan\
out-interface=Local passthrough=yes protocol=tcp
add action=mark-connection chain=forward \
comment=DownloadfromLan1 connection-bytes=256000-4294967295\
disabled=no in-interface=Public-1 new-connection-mark=DownLan\
out-interface=Local passthrough=yes protocol=tcp
/ip firewall mangle
add action=mark-connection chain=forward \
comment=DownloadfromLan2 connection-bytes=256000-4294967295\
disabled=no in-interface=Public-2 new-connection-mark=DownLan\
out-interface=Local passthrough=yes protocol=tcp
add action=mark-packet chain=forward comment="" \
connection-mark=Down Lan disabled=no \
in-interface=Public-1 new-packet-mark=DownloadLan\
out-interface=Local passthrough=no protocol=tcp
add action=mark-connection chain=forward \
comment=DownloadfromLan2 connection-bytes=256000-4294967295\
disabled=no in-interface=Public-2 new-connection-mark=DownLan\
out-interface=Local passthrough=yes protocol=tcp
add action=mark-packet chain=forward comment="" \
connection-mark=Down Lan disabled=no \
in-interface=Public-1 new-packet-mark=DownloadLan\
out-interface=Local passthrough=no protocol=tcp
add action=mark-packet chain=forward comment=""” \
connection-mark=Down Lan disabled=no \
in-interface=Public-2 new-packet-mark=DownloadLan\
out-interface=Local passthrough=no protocol=tcp
/que ty
add kind=pcq name=Download pcq-classifier=dst-address \
pcq-limit=50 pcq-rate=128000 pcq-total-limit=2000
/que tr
add burst-limit=0 burst-threshold=0 burst-time=0s \
disabled=no limit-at=0 max-limit=256000 name=LimitDownloadformLan\
packet-mark=DownloadLan parent=global-out priority=8 queue=Download
connection-mark=Down Lan disabled=no \
in-interface=Public-2 new-packet-mark=DownloadLan\
out-interface=Local passthrough=no protocol=tcp
/que ty
add kind=pcq name=Download pcq-classifier=dst-address \
pcq-limit=50 pcq-rate=128000 pcq-total-limit=2000
/que tr
add burst-limit=0 burst-threshold=0 burst-time=0s \
disabled=no limit-at=0 max-limit=256000 name=LimitDownloadformLan\
packet-mark=DownloadLan parent=global-out priority=8 queue=Download
3. Aktifitas modem ke proxy juga harus dibatasi,
Berikut Scriptnya :
/ip firewall mangle
add action=mark-connection chain=forward comment=DownloadfromProxy1\
connection-bytes=256000-4294967295 disabled=no in-interface=Public-1 \
new-connection-mark=Down Proxy out-interface=Proxy\
passthrough=yes protocol=tcp
add action=mark-connection chain=forward comment=DownloadfromProxy1\
connection-bytes=256000-4294967295 disabled=no in-interface=Public-1 \
new-connection-mark=Down Proxy out-interface=Proxy\
passthrough=yes protocol=tcp
add action=mark-connection chain=forward comment=DownloadfromProxy2\
connection-bytes=256000-4294967295 disabled=no in-interface=Public-2 \
new-connection-mark=Down Proxy out-interface=Proxy\
passthrough=yes protocol=tcp
add action=mark-packet chain=forward comment=""\
connection-mark=Down Proxy\ disabled=no in-interface=Public-1 \
new-packet-mark=DownloadProxy out-interface=Proxy \
passthrough=no protocol=tcp
connection-bytes=256000-4294967295 disabled=no in-interface=Public-2 \
new-connection-mark=Down Proxy out-interface=Proxy\
passthrough=yes protocol=tcp
add action=mark-packet chain=forward comment=""\
connection-mark=Down Proxy\ disabled=no in-interface=Public-1 \
new-packet-mark=DownloadProxy out-interface=Proxy \
passthrough=no protocol=tcp
add action=mark-packet chain=forward comment=""”\
connection-mark=Down Proxy\ disabled=no in-interface=Public-2 \
new-packet-mark=DownloadProxy out-interface=Proxy \
passthrough=no protocol=tcp
/que ty
add kind=pcq name=Download1 pcq-classifier=dst-address pcq-limit=50\
pcq-rate=128000 pcq-total-limit=2000
connection-mark=Down Proxy\ disabled=no in-interface=Public-2 \
new-packet-mark=DownloadProxy out-interface=Proxy \
passthrough=no protocol=tcp
/que ty
add kind=pcq name=Download1 pcq-classifier=dst-address pcq-limit=50\
pcq-rate=128000 pcq-total-limit=2000
/que tr
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=0 \
max-limit=256000 name=Limit DownloadfromProxy\
packet-mark=DownloadProxy parent=global-out priority=8 queue=Download
Sedikit tambahan agar lebih ma'nyos Ng-limitnya coba paste di layer 7.
http/(0\.9|1\.0|1\.1)[\x09-\x0d ][1-5][0-9][0-9][\x09-\x0d -~]*(x-cache: hit)
Semoga bermanfaat dan salam
sumber : routerosmikrotik.blogspot.com
0 comments:
Post a Comment