ค ม มอบร อบรหารระบบเคร หารระบบเครอข อขายด ายดวย วย MikroT MikroTik ik RouterO RouterOSS Your Network Solutions with MikroTik
SONTAYA PHOTIBUT
[email protected] htt!"##www.susethailand.co htt!"##www.suse.in.th
$%&'()*%+ ,-icense /0%123 %123124 124565758 76 58%/(9 %/(9%:/&; %:/&;'<5$59 '<5$59%:=7:>19 %:=7:>19>70 >70&6&?'() ?6 '()*%+5%$ *%+5%$ 0CD CD:( :(
E4 2=/E7>E4>K$ >K$?>0 ?>0:6:6L?&3 L?&3$%&&D $%&&D<&4 <&4>E4 >E4?(Q3 ?(Q3&'&4 4 '&4+9+9%L %L 9 91;1'(D '; (D R>19 >19>70 >70J0 J066**%'() **%'()*%+&D *%+&D'GD 'GD'11'(4 '11'(4 0%+&5'?9 %+&5'?9% % 0J7$&FG8 J7$&FG8%3 %37?) 7?)E(6 E(6 R(:'11D%13 %137+%12 7+%12 &F&%?6**6 **6+3+39%70 %9 70:$%&$&FG8 :$%&$&FG8%3 %37$D V V 7$D:$6 :$6?'123 ?'123+'&4 +'&4 2.. 2.. WXX 8%KZ3 %KZ3[ [ ,\isclaier 0CD CD:(>19 :(>19&6&?K&F$6 ?6 K&F$6(9 (9%C0 %C0'1 '1EJ( 9 9 EJ(1;1'E9 '; E91(D 1(D R5F:6 5F:6LLG8 LLG8%L%(&9 %L%(&91$6 1$6?Q'+4 ?Q'+4<&4 <&4'&466( 70/&; /&;'>19 '>19 &; V V &;'L/1%:$%&0 'L/1%:$%&0% ,Tradeark MikroTik ^_ `outerOS `outerOS ^_ `outerBOA`\ `outerBOA`\ ^ K (; V V (;'&; V V '&;'L/1%:$%&0 'L/1%:$%&0%C'L?&3 %C'L?&3b6bG6 MikroTik GD V VGD>70 >7057GF?D 57GF?D:( :(
?G(8% MikroTik '9%(''$D %(''$D:L9 :L9% >19=&+3 =&+3 $j $j K(?&3 (?&3b6bG': 9 9 G6 ':J($&) J($&)L&D L&D$% $% ,`ia 1;'L/ELC'LE6 'L/ELC'LE6+D +D: /&;'; V V ';'G%L$%&; 'G%L$%&;' % [%&]%E6+D +D: ,-atian K (1; (1;'LGD V V 'LGDJ/*9 J/*9GD V VGD)7J(?&&7%1; 7) J(?&&7%1;'LGD V V 'LGD': 9 9 ':J($E) 9 9 J($E)1&6 1&6 ?'E+3$ MikroTik kroTik $9'+6 '+6 RLCm LCm R(J(K (J(K ppX ppX K( K&FGJ(131%:) 3 %:)=&K/(; =&K/(;' 1D'%]%C++3 '%]%C++37+9 7+9'$6 '$6?'D ?'D$ W &6 ?'E+3$ ;' '=+(D:G%LG3 :G%LG3/(; /(;' &0%: %: , qireless ISP MikroTik ; 'K 'K(?&3 (?&3b6b6GGD V VGD1D1$%&5&3 $D %&5&3*+3 *+3?=+':9 ?=+':9%L&7& %L&7& 70:K&F3 :K&F3G[3 G[3%2&F?? %2&F?? &91m 1mL$%& L$%& G8%L%(C'LQ'+4 %L%(C'LQ'+4<&4 <&470':9 ':9%L+ %L+1& 1&K? K? J(K WW WW MikroTik >70 E3 E3+g%&4 +g%&47<&4 7<&4 RC(1%K (m 1%K(&(74 (&(74C'L+6 C'L+6'L; V 'L; V' `outerBOA`\ K55) 55)?6?6(1D+6+6K '>K 2&0'1$8 '1$8%/(7K %/(7K%/1%:GD V V %/1%:GD6675(; 75(;' 8%/&6 %/&6??&3 ??&3b6bGC(%7E G6 C(%7E$ qISPS ,qireless Internet Serice Proiders 70 L%(>70L9L9%: %: K%/1%:C'L 9 9 %/1%:C'L1;1'E9 '; E91(D 1(D R 1D%1C0 %1C0%J5$D V V %J5$D:$6 :$6?g%&4 ?g%&47<&4 7<&4<2E+'&4 <2E+'&41 MikroTik `outerBOA`\ 70 %1%&'312ED 12ED10 10(G4 (G470 (>70 –
–
–
$D V V $D:$6 :$6? 9 9 ?1;1'E9 '; E91(D 1(D R 9 91;1'E9 '; E91(D 1(D R 0CD CD:(>70 :(>70&D&D:?&D :?&D:L5%$+0 :L5%$+0(?6 (?6?/(6 ?/(6L; L;' `outerOS xy za!le 0<+9 <+9L ;' Ste!hen `.q \ischer Qm LC%CD V VLC%CD:( :( RCm(1%2; V V (1%2;'J0 'J0K( 9 9 (1;1'J($%&'('&4 '; J($%&'('&4 MT{NA ,MikroTik {ertified Network Associate 76L(6 L(6 R( 9 9 (1;1'E9 '; E91(D 1(D R5m5L>19 Lm >19J0 J0 /(6L; L;'GD V V 'GDCD CD:(ELEm :(ELEm$m $mL&%:EF'D L&%:EF'D:7 :75'&4 5'&4+9+9%L %L /%$+0'L$%&G&%?m 'L$%&G&%?mL&%:EF'D L&%:EF'D:7+9 :7+9%L %L 0'9'%(%1%&m 9%(%1%&m$b%23 V V $b%231+3 1+31>70 1>70 G%L''(>E(4GD VG VD ?>Q+4 ?>Q+4C'L C'L 0E3 E3+ MikroTik 0'9'%(5F%1%&C0 9%(5F%1%&C0%J5m %J5mL) L)]1?6 ]1?6+3+32;2 R(%( (; %( K'3 %>K'312ED 12ED1(0 1(0G4G4QQ =E6 V V(?>/(>70 (?>/(>70?0?%L %0 L (; V V (;'L5%$ 'L5%$ MT{NA K(J?&6 (J?&6?&'L<&$GD V V ?&'L<&$GDG%L G%L MikroTik Kv7'(19 :(>19>70 >70CD CD:( 9 9 :(E9 E91 (D R=7:$%&
G8%%1& %%1& 0565$6 Mikrotik ,>1=&+3 $_ $_ `outerOS K 6>K ,<2E+'&41 z}~ 2; V V 2;'G8 'G8%/(0 %/(0%GD V V %GDK K(&; V V (&;'L&%G4 'L&%G4+'&4 +'&4Qm V VQmL1D L1D5'&4 5'&4GD V VG/E%$/E%: D/E%$/E%: 9( $%&$8%/(70 %/(70(G%L (G%L ,routin_ $%&58 %$6 %$67(74 7(7437G4 73 G4/&; /&;'$%&58 '$%&58%$6 %$67K&3 7K&31%] 1%] ,xandwidth sha!er_ wireless access !oint_ hots!ot ateway_ •PN serer_ trans!arent !acket filter €E€ `outerOS 5mLK LK(&F??KZ3 (&F??KZ3?6?6+3+$%&?<+('=E( $3 %&?<+('=E( ,standalone GD V V2(%?(2; 6 (%?(2; R(%(E3 (%(E3()($Q4 )$Q4'&4(E (E ,-inuz kernel %1%&+37+6 7+6 RLK LK('123 ('123+'&4 +'&41; 1;'(?( '(?( •ware S /&; '?( '?( Parallels J( Mac OS `outerBOA`\ K(<2E+'&4 (<2E+'&41g%&4 1g%&4<&4 <&4E3 E3+Cm +Cm R(=7:?&3 (=7:?&3b6bG6 MikroTik GD VGD V&(70 (6 70:&F??KZ3 :&F??KZ3?6?+3+6 $%& 3$%& `outerOS =7:K (E3 (E3+ 6]4 ]4&%G4 &%G4+'&4GD V VG/1%F$6 D/1%F$6? ? 0J0 J0+%1?0 +%1?0%( %( ,sall hoe router J($%&J/0?&3 ?&3$%& $%& <+900%1D %1DL?K&F1%]70 %L/1%F1>70 `outerBOA`\ >70&6&?$%&''$?<:$$E) 9 9 ?6 $%&''$?<:$$E)12; 12; R(%(>70 (%(>70 W W $E) 9 9 $E)1 (6 R(; (;' ?'3(G3 (G3$&7 $&7 $6??GD V V ??GDK K(1(?'&47 =7:&) 9 9 =7:&)( E$GD V V $GD)7GD V V 7) GD>70 >70&6&6?%1(3 ?%1(3:1 :1 ;' `B‚X 19 %>191D1'3'D (+'&4 3(+'&4Q?>&0 Q?>&0%: %: ,wireless
interface_ >19 1D1'3'D 3(G3 (G3$&7$%&4 $&7$%&47>&0 7>&0%: %: ,wireless card /&;' ini P{- slot
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% ~# ‚~
&)&) 9 9( `B‚XUƒWHn\ R :9'1%5%$ '1%5%$ `outerBOA`\ ! /1%:%19% ')K$&]4 K$&]4J(+&F$ J(+&F$E ‚ series " /1%:%19 %58 %58%(('3 %(('3G'&4 G'&4(+2'&4 +2'&4+ $ /1%:%19% '3(+'&4 (+'&4Q?>&0 Q?>&0%:_ %:_ USB 2'&4+ % /1%:%19 % $8%/(76 %/(76*E6 *E6$b]4 $b]4'6'$b&+6 6$b&+6 U 2; V V 2;'?'$ '?'$
9%1D %1D2'&4 2'&4+ USB 58%(( %(( 2'&4+ &' /1%:%19 % J0:9:%:%1D V V %9 :%1D W W „H… ( /1%:%19% 1%+&%(&;'C9 'C9%:>&0 %:>&0%:%1& %:%1& L /&;' I }W.n ,2&0 '1&6 '1&6?&'L1%+&%( ?&'L1%+&%( }W.x# J(+6 ) /1%:%19 % $8%/(76 %/(76*E6 *E6$b]4 $b]4'6'$b&+6 6$b&+6 \ 2; V V 2;'?'$ '?'$ 9%1D %1D%'%$% %'%$% 9 9 ,W ,W % % ,เปนเราท นเราทเตอร เตอรบอร บอรดร ดร นท นทมมไวเลสในตัว ไ วเลสในตัว 9(&) 9 9 (&)(J/*9 (J/*9)7J(K 7) J(K55) 55)?6?(2&0 (6 2&0'1K&F3G[3 G[3%2 %2L) L)7J($%&G8 7J($%&G8%L%( %L%( &'L&6?$%&G8 ?$%&G8%L%(?/E %L%(?/E%:' %:'&4&4 {PU $5FK 5FK( `outerBOA`\ &) 9 9&)( {{`†~ƒW„ƒ‡S K ( MikroTik '&4&%G4 &%G4+'&4 +'&4J(&F??'3 J(&F??'3(&%+&6 (&%+&65'&4 5'&4E%74/&; /&;'G8 'G8%L%(K %L%(K( Internet „ateway &0 %+'&4 %+'&4 8 8%/&6 %/&6? ? 0J/0 J/0?&3 ?&3$%&'3 $%&'3(G'&4 (G'&4( (+C(%7J/*9 +C(%7J/*9 ,ISP ,ISP ƒ †~ '&4 {PU_ /(9 :%158 :%158% ‡„B ƒ &'L&6?m ?mL W‡ E0%(<2$$ %(<2$$++9 ++9'3 '3(%GD (%GD ƒ C(%7')K$&]4 K$&]4 U U `ackount ƒ ‡ 2'&4+ SˆP ƒ W 2'&4+$3 +$3$F?3 $F?3+'D +'D['&4 ['&4(+
/E6L5%$GD V V L5%$GD<(F(8 <(F(8%$E) 9 9 %$E)1<&$GD V V 1<&$GDK K(?'3(G3 (G3$&7 $&7 +9'>K&%1%2 '>K&%1%27m 7mL9 L9(GD V V (GDK K(?g%&4 (?g%&4<&4 <&4?'&4 ?'&47$6 7$6(?0 (?0%L %L $E9%>KK70
&)&) 9 9( `B‡
& 9 9)( `B}
1(?'&47') 7')K$&]4 K$&]4/E9 /E9%(D %(D R%1%&GD V V %1%&GD5FK&6 5FK&6?<+9 ?<+9L=7:$%&23 V V L=7:$%&231$%&4 1$%&47>&0 7>&0%:>70 %:>70 ,wireless ,wireless ini P{I card =7:J/0 /1%F1$6? $%&G8%L%(G6 %L%(G6 RLJ(?J(?&3 LJ(?J(?&3$%&'3 $%&'3(G'&4 (G'&4( (+>&0 +>&0%:%:J(8 %:%:J(8%(6 %(6$L%( $L%( ,Indoor /&;'%:('$'%%&8 '%:('$'%%&8%(6 %(6$L%( $L%( ,Outdoor Qm V VQmLG%L LG%L MikroTik 0E3 E3+5F+$<+9 +5F+$<+9L? L? outdoor J/0 1D1D%1G(+9 %1G(+9'|(&0 +>&0%: %: ,wireless access !oint 70 >70'[3 '[3?%:>0 ?%:>0$9$'(/(0 '9 (/(0%(D %(D R
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% }# ‚~
+6'6 '6$b&GD V V $b&GD&F?) &F?)': 9 9 ':J(/1%:EC&) 9 J(/1%:EC&) 9( , + ')K$&]4 K$&]4&) 9 9&(GD V () GD VK( wireless 1%2&0'1$6 '1$6?J?'() ?J?'()*%+&F76 *%+&F76?GD V ?GD V ‡ ,`outerOS -icense" -icense" -eel ‡ % Š ')K$&]4 K$&]4&) 9 9&(GD V V () GD(6 (6?() ?()( USB 2'&4+ &0 %:>&0%:%1& %:%1& L 1%+&%( I }W.n ' Š 8%/&6 %/&6?') ?')K$&]4 K$&]4 wireless GD V VGD1D1$8$D %E6 %8 E6L9 L9L LL ,hih `ˆ !ower . Š ')K$&]4 K$&]4&) 9 9&(GD V () GD VK($3 ($3$F?3 $F?3+'D +'D['&4 ['&4( (+2'&4 +2'&4+ / Š ')K$&]4 K$&]4&) 9 9&(&%%K&F/:6 )(&%%K&F/:67 ,low cost ) Š 8%/&6 %/&6?') ?')K$&]4 K$&]4 wireless GD V VGD1D1%&'%$%? 9 9 D %&'%$%? ,W ,W `ˆ G6 RL$%&&6 L$%&&6?70 $&7&F??>70':9 ':9%L %L /1%F1 70 >70 9 9( 23 V V 231 15'&4 5'&4 /&; /&;'9 '9(K&F$'? (K&F$'? ,co!onent GD V V `outerBOA`\ &'L&6?
&)KK&D KK&D:?GD :?GD:?5) :?5)779 779(70 > 701‹ %>1‹ 5)779 779( 1. `outerBOA`\ >70 &6 &?$%&''$?J/0 ?6 $%&''$?J/0G8G%L%(&9 %8 L%(&91$6 1$6? `outerOS =7:2%F76L(6 L(6 R(') (')K$&]4 K$&]4 MikroTik MikroTik Qm V VQmL1D L1D%1 %1 D:& :&L$9 L$9%'123 %'123+'&4 +'&42D2DQ /&; D /&;''123+'&4 +'&4Q3 Q3&4&'&4 4 '&4 2. `outerBOA`\ J0 2E6 2E6LL%(> LL%(>%(0 %(0':$9 ':$9%&; V V %&;'L'123 'L'123+'&4 +'&42D2QDQD D /&;''123 ''123+'&4 +'&4Q3 Q3&4&'&4 4 '&4GD V VG5F+3 D5F+37+6 7+6 RL `outerOS 3. `outerOS 0 %>7&Œ %>7&Œg%&4 g%&4773 773$4 $4&; V V &;'LQ3 'LQ3&4&'&4 4 '&4D D:>19 :>19%1%&J0 %1%&J0>70 >70 /&; /&;'G8 'G8%$%& %$%& '&4<1Gg%&4 <1Gg%&4773 773$4 $45F+0 5F+0'L6 'L6 V VLQ; LQ; R' >EQ(+4 (+4J/19 J/19G9 G9%(6 %(6 R( 2; V V 2;'<'GD '<'GD ,/&;'C':0 'C':0%:>EQ(+4 %:>EQ(+4>K:6 >K:6L&; V V L&;'L'; V V 'L';( <+9$$1D19D %J0 %9 J0595%:': 9 9 %9 :':7D7D <+90%K %0 K( `outerBOA`\ %1%&J0 '6 '62'(v 2'(v$70 >70E: E:
5)779 779': ': 1. 2.
`outerBOA`\ >19 1D1GD V VGD $ D$?C0 ?C0'1 '1E ,storae GD V VGD1D1%15) D %15)1%$/1; 1%$/1;'(GD :?$6 :?$6?'123 ?'123+'&4 +'&4 J($%&$?E ?E'$>E4 '$>E4 ,lo +9%L %L 5mL+0 L+0'L'%6 'L'%6:$%&=:(E :$%&=:(E'$>E4 '$>E4 ,-o ,-o forward >K:6L&; V V L&;'LQ3 'LQ3&4&'&4 4 '&4 ,-o ,-o Serer /&;' ezternal storae xoz
?GGD V V ƒ &3 V V&31+0 ?GGD 1+0(J0 (J0L%(>1=&+3 L%(>1=&+3 $ ,ˆirst Tie Access &%1%799%/E6 %/E6L5%$GD V V L5%$GD&%+3 &%+37+6 7+6 RLQ'+4 LQ'+4<&4 <&4 `outerOS `outerOS /&;'GD V V 'GDK K(<2E+'&4 (<2E+'&41 `outerBOA`\ & %L>& &; V V &;'L1; 'L1;'J($%&C0 'J($%&C0%m %mL1=&+3 >1=&+3 $ 1D/E%:3 /E%:3[D[707D 0:$6 :$6(>19 (>199%5F9 %9 5F9%(G%L %(G%L qinBoz ,„UI_ ra!hical user interface_ qexfiz ,G%L ??%&4Q'&4 Q'&4 9 9%(=K&=+'E %(=K&=+'E HTTP Km 1>KmL$%&CD L$%&CD:(=K&<$&1?) :(=K&<$&1?)1') 1')K$&]4 K$&]4 +3 +37+9 7+9'9 '9%(G%L %(G%L API C'L C'L `outerOS
qinBoz qinBoz ;'=K&<$&1GD V V '=K&<$&1GD&6&(?(<2E+'&4 (6 ?(<2E+'&413 13(=74 (=74 K(&; V V (&;'L1; 'L1;'GD V V 'GD9:J/0 9 :J/0&%%1%&'(v &%%1%&'(v$') $')K$&]4 K$&]4 `outerOS `outerOS >70':9 ':9%L %L F7$70GD V VGD htt!"##www.ikrotik.co#download k.co#download E4 $>E4GD VG V=D /E71% =K&<$&1$5FKv 5FKv7Cm 7Cm R(1%2&0 (1%2&0'1J/0 '1J/0&%E &%E''3 ''3(C0 (C0%'(v %'(v$ `outerOS =7: G6(GD (GD $%&; V V $%&;'1+9 '1+9'>K:6 '>K:6L') L')K$&]4 K$&]4 Mikrotik Mikrotik 9%(=K&<$&1 %(=K&<$&1 qinBoz %1%&+3 7+9 7+9'>70 '>709%(G6 %9 (G6 RLG%L>'2D LG%L>'2D<'77&
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% # ‚~
9%7D %7D'E+4 'E+4C'L C'L MikroTik ,B`‚X 5FK ( usernae" adin adin 19 >191D1 !assword
$8%E6 %E6L=/E7KE6 L=/E7KE6 $'3 $'3(
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% W# ‚~
Naiatin qinBoz (3$+'&4 $+'&4?( ?( qinBoz K(/1; (/1;'(K '(K%:?'$G%L1( %:?'$G%L1(/(0 /(0%+9 %+9%LJ0 %LJ0L%(J( L%(J( qinBoz K) K)11( 11(+9+9%L %L 5F': 9 9 5F':7070%(Q0 %(Q0%:C'L/(0 %:C'L/(0%+9 %+9%L %L
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% ‡# ‚~
&%5F/(>70 (>709%/(0 %9 /(0%+9 %+9%LGD V V %LGDKv Kv7Cm 7Cm R(1%G6 (1%G6 RL/175F?'$&%>70 L/175F?'$&%>709%&%$8 %9 &%$8%E6 %E6L'(v L'(v$': 9 9 $':GD VG VD1(>/(C'L >/(C'L qinBoz
Inside qinBoz %:J( qinBoz <+9E9E9F FL$4 L$46(Qm V V (6 QmLK&F$'?70 LK&F$'?70:'L4 :'L4K&F$'?/E9 K&F$'?/E9%(D %(D R;;'
23 V V 231'D 1'DE3E1(+4 3 1(+4J/19 J/19 E?'DE3E1(+4 3 1(+45%$E3 5%$E3+4 +4 Kv7J0 7J0L%('D L%('DE3E1(+4 3 1(+4 Kv7$%&J0 7$%&J0L%('D L%('DE3E1(+4 3 1(+4 23 V V 231'11(+4 1'11(+4J('D J('DE3E1(+4 3 1(+4
vE+'&4 E+'&4E3E+4 3 +4GD V VGD+0+'L$%& '0 L$%& +9'>K&%1%7 '>K&%1%7C'%1GD V V '0 %1GDCmC Rm(+6 (+6D D+9+%L 9%L E%&%J9C0C'1 0'1E/&; E/&;'&F?) '&F?)''?6 ''?6(C0 (C0%>K3 %>K37 9( D<7L_ <7L_ D% K3 %>K37 9( 1; V V 1;''(v ''(v$ \H{P Q3&4'&4 '&4 ?('3(G'&4 (G'&4+4 +4/E6 /E6$ K23 V V '>K231'3 1'3(+'&4QK QK(?&3 (?&37=/17 7=/17 ,xride interface /&; ''D ''D$+6 $+6':9 ':9%LGD V %LGD V5FK&%$$ ; ;' 1; V V 1;'G8 'G8%$%&&0 %$%&&0%L$Z %L$Z >&4'EE4 'EE4 ,firewall ,firewall rule Cm R(1%KG8 ?>KG8%$%&E?'3 %$%&E?'3(+'&4 (+'&4Q Q $C0'(D '(D RGD V VGD&0 &0%LCm %LCm R(?(>&4'EE4 'EE4$$5FK 5 FK(D (D<7L <7L D% Š 0%1D %1D$%&&0 $%&&0%L0 %L0(G%L'L0 (G%L'L0(G%LGD V V (G%LGD1D1KE%:G%L7D KD E%:G%L7D:$6 :$6( 0(G%LGD V (G%LGD VG%L%(': 9 %8 L%(': 9 ,actie route 5FK(D (D7878%19 >19>70 >70J0 J0L%( L%( ,inactie route 5FK (D (D% +6/(% /(% Š ?('3(+'&4QGD V V QGDK K( wireless &%:$%&GD V V &%:$%&GD K K(+6 (+6/(%5F; /(%5F;'K 'K(9 (9'L1%+&%(8 'L1%+&%(8%/&6 %/&6?$%&?) ?$%&?)1$Z&F?D 1$Z&F?D:?C'L :?C'L =71((6 R( 19 'L>19E3 E3$E; $E;'$GD V V '$GD$E9 $E9'L 'L Ž $6?E; ?E;'$Qm V V '$QmL5F<7LK L5F<7LK(&; V V (&;'L/1%: 'L/1%: '65&D 5&D:4:4 Ž Ž 2 9( +6':9 ':9%L$%&&0 %L$%&&0%L$Z>&4 %L$Z>&4'EE4 'EE4
5%$&K 1; V V 1;':$E3 ':$E3$Q $Q$?'$Q4 $?'$Q4GD V VG$E9 $D E9'L$Z>&4 'L$Z>&4'EE4 'EE4(D( R5F D5F$(8 $(8%1%J0 %1%J0+%1GD V V +%1GD&%&0 &%&0%L$Z>0 %L$Z>0 <+9 <+90%E3 %0 E3$E; $E;'$Q '$Q?'$Q4 ?'$Q4
9%GD V V %GD&%$8 &%$8%/(7J(9 %/(7J(9'L9 'L9%L6 %L67>K5F/1%:%19 7>K5F/1%:%19% >19 >19J9 J9j '[3?%: ?%: ;' +0(G%L>'2D (G%L>'2D<'77& <'77& pW.~}.WX. pW.~}.WX. ,source address 5F>19': 9 9 ':J($ZC0 J($ZC0'(D '(D R 76 76L(6 L(6 R(+0 (+0'L&F6 'L&F6L':9 L':9%L:3 V V %L:3LJ($%&J0 LJ($%&J0)]1?6 ] ) 1?6+3+(D(3 RD
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% ~# ‚~
Safe Mode 'D$/(m V V $/(mL%1%1% L%1%1%&C'L &C'L `outerOS `outerOS ?(')K$&]4 K$&]4 MikroTik MikroTik (6 R($ ($ ;' 5'&4 5'&4Q=/17 Q=/17 Safe Mode ;''F>&‹ ''F>&‹ =/17GD V V =/17GD %1%&KED V V %1%&KED:(70 1>70 1; V V 1;'G8 'G8%$%&&D %$%&&D??+') + ')K$&]4 K$&]4 ,L9 ,L9%: %: $ ; ;' =/17GD V V =/17GD>19 >191D1$%&?6 $D %&?6(Gm (Gm$ $%&+6 RL9 L9%5&3 %5&3LL 8%/&6 %/&6?$%&J0 ?$%&J0L%(Q=/17=K&<$&1 L%(Q=/17=K&<$&1 qinBoz +0 'LK 'LK('&4 ('&4 V V(6 X Cm R(>K (>K /&;'&D '&D:$J0 :$J0L%(9 L%(9%( %( coand line C0'7D '7D$$ ; ;' &%%1%&GD V V &%%1%&GD5FG7'?$%&KED V V 5FG7'?$%&KED:(70 %>70G6G(GD (6 GD 1; V V 1;'$7K) '$7K)1 sae /&;' a!!ly K(=/17GD V V (=/17GD/1%F$6 /1%F$6? $%&&3 V V $%&&31+0 1+0(J0 (J0L%(&3 V V L%(&31<&$ 1<&$ 2&%F0%/%$1D %/%$1D$%&KED V V $%&KED:(19 >19%1%&+3 %1%&+37+9 7+9'; V V ';'%&>K:6 '%&>K:6L&%G4 L&%G4+'&4 +'&4 MikroTik >70&%$ &%$2D 2D:L<9 :L<9&D&??D +') +')K$&]4 K$&]4 ,'7KE6 ,'7KE6 $
$%&J0L%( L%( Safe Mode Kv7 qinBoz 5%$(6 R(E3$K) $K)1 Safe Mode 76L& L&K
0%>19 %>19+0+'L$%&?6 '0 L$%&?6(Gm (Gm$$%&+6 $$%&+6 RL9 L9%J7 %J7 /&;'+0 '+0'L$%&''$5%$ 'L$%&''$5%$ Safe Mode J/0 E3 E3$K) $K)1 2; V V 2;'''$5%$=K&<$&1 '''$5%$=K&<$&1 qinBoz
0%>19 %>19+0+'L$%&?6 '0 L$%&?6(Gm (Gm$$%&+6 $$%&+6 RL9 L9% /&;'''$5%$ '''$5%$ Safe Mode J/0 $7D $7D:4: ctrld 4 ctrld
{oand -ine Terinal O!tions (D RK K('D$3 $3[D[J($%&C0 JD ($%&C0%m %mL') L')K$&]4 K$&]4 MikroTik MikroTik 2; V 2; V''(v$ `outerOS 8 %/&6 %/&6? ? 0D D:%*
Telnet and SSH Telnet '2D %(>'2D<'77& 1; V V 1;'&; V V '&;'L>E' 'L>E'(+4 (+4K K(&F??KZ3 (&F??KZ3?6?6+3+3 $%&E3()($Q4 )$Q4 /&;'?(&F??KZ3 '?(&F??KZ3?6?+3+6 3$%&3 $%&3(=74 (=74 9( =K&<$&1 PuTTY
Serial Terinal 3[D[(DD( RLK DLK(G%LE; (G%LE;'$) '$)7G0 7G0%:C'L/E%: %:C'L/E%: ( J($%&C0 %m %mL') L')K$&]4 K$&]4 MikroTik MikroTik 9%(%:QD %(%:QD&D&D:E :E ,serial caxle $&]D GD VG V5D F>70J0 J0 %:QD&D&D:E$ :E$ 9( E'>KKv7'3 7'3G'&4 G'&4( (+2'&4 +2'&4+G) +G)$2'&4 $2'&4+ /&;') ')7 7 $E;E1&/6 1; &/69 9%( %( 0%$&]D %$&]D':9 ':9%L(D %L(D R qinBoz_ qinBoz_ telnet /&; ' SSH $9:>19 9:>19>70 >70 G%LE; G%LE;'$) '$)7G0 7G0%:$ %:$ ;' QD&D&D:EG'&4 :EG'&4131('E (3 'E K55) 55)?6?('123 (6 '123+'&4 +'&4?%L:D V V ?%L:D/0/'5F>19 '0 5F>191D1QDQD D&D:E2'&4 :E2'&4+1%J/0 +1%J/0 &%%1%& &%%1%& Q; R'%:KK( Serial E;1: 1:Q'&4 Q'&4(1L‹ L>L‹ $&]DE;E1: 1; :Q'&4 Q'&4(1/&; (1/&;'&/6 '&/69 9%(=K&758 %(=K&758%>0 %>0E:9 E:9%') %')K$&]4 K$&]4 MikroTik MikroTik >191D1&; V V D &;'L1; 'L1;'/&; '/&;'3 '3[D[$%&$ D$%&$ 0;(&/6 (; &/69 9%( %( 5F+0'L&D 'L&DQ+ Q+ <+4GG9 GG9%(6 %(6 R( ,reƒflash =7:J0 =K&<$&1 =K&<$&1 NetInstall 9%'(v %'(v$GD V V $GD$8$8%/(7>0 %/(7>05F 5F$&D $&DQ+G6 Q+G6 RL/17 ,&D L/17 ,&DQ+ Q+ `outerOS <+9$$ >191D1G%LE; GD %LE;'$'; V '$'; V(GD V VGD5FC0 5FC0%m %mL') L')K$&]4 K$&]4 Mi MikroTik kroTik >70('$5%$3 ('$5%$3[D[(DD( R&6 D&6? RC6(+'( ,+6':9 ':9%L(D %L(D RK K( `B Series‚ (D R>19 >19J9 J9 RC(+'($%&$ (6 +'($%&$ 0;;(&/6 (&/69 9%( %( RC6(+'(7D:$6 :$6($6 ($6?$%&$ ?$%&$ 0D2D MikroTik J/0;($E6 (; $E6? 9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% }# ‚~
1%G8%L%('D %L%('D$&6 $&6 RL '%$%&D:':9 :':9%L9 %L9( 'DG'&4 G'&4(+2'&4 +2'&4+GD V +GD V ƒX >>19+3+73 ƒ 7%(4=/E7=K&<$&1 =/E7=K&<$&1 NetInstall NetInstall 5%$ htt!"##www.ikrotik.co#downl htt!"##www.ikrotik.co#download oad ,>E4=K&<$&1%1%&' =K&<$&1%1%&'$QD $QD3 R3>70 >70E: E: =7: >19+0+'L+3 '0 L+37+6 7+6 RLL
ƒ E;'$QD '$QD&D&:4:D 4&() 9 9) ,`B‚ series E4GD V VG=/E71%5FK D=/E71%5FK( routerosƒi!sxeƒX.WW.n!k routerosƒi!sxeƒX.WW.n!k '2D >'2D<'77& +6':9 ':9%L %L 9( pW.~}.}}.
ƒ D:?%:
ƒ E3$K) $K)1 Net xootin '2D %/(7>'2D<'77&GD V V <'77&GD': 9 9 ':J( J( Suxnet 7D:$6 :$6($6 ($6?L ?L -AN '123+'&4 +'&4GD V VD'(v '(v$
Note" >'2D<'77&+0'L>19 'L>19Q8Q R%$6 %8 $6( ,+0 ,+0'L 'L suxnet 7D:$6 :$6( ƒ &5 L6 $+7L> A{T 5F $&F2&3? 2'/:)7$&F2&3 7$&F2&3?
/(0% W# ‚~
ƒ 5%$(6 R(E3$K) $K)1 Browser... E;'$>KGD V V '$>KGD$ $?>E4 ?>E4 ,+0 ,+0'LE3 'LE3$E; $E;'$ '$ `outers#\riers $9 '( '(
ƒ E3$K) $K)1 O‘
ƒ E3$Q$? $?'$Q4 '$Q4E;'$>E4 '$>E4<2$5 $5 9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% WW# ‚~
Note" E;'$GD V V Note" E; '$GD$ $?>E4 ?>E4& &5 /%$>19CmC Rm(76 (76L& L&KC0 KC0%L?(J/0 %L?(J/0G8G%$%& %8 $%& xrowse E;'$>E4 '$>E4 .n!k .n!k J/19 ,+0 ,+0'L7%(4 'L7%(4=/E7>E4 =/E7>E4 <2$5J/0 $5J/0+&L$6 +&L$6?QD ?QD&D&:4:D &) 9 9&4 (') () ')K$&]4 K$&]4 C0'&&F6 '&&F6L" J($%&J0 L" J($%&J0 Neti Netinstall nstall '62$&7<2 2$&7<2$5&) 9 9 $5&)(J/19 (J/19 /%$+0 /%$+0'L$%&$ 'L$%&$?9 ?9%'(v %'(v$$9 $$9% J/0E3 E3$ kee! old confiurationj confiurationj >19 RL6L(6 Netinstall 5FED:&4 :&499%'(v %'(v$$9 $$9% <+98%/&6 %8 /&6?+6 ?+6':9 ':9%L(D %L(D RE;E1&/6 1; &/69 9%( +0 %( +0'L>19 'L>19E3 E3$Q $Q$?'$Q4 $?'$Q4 ‘ee! ‘ee! old confiurationj 2&%F+0 'L$%&J/0&Q+9 D Q+9%G6 %G6 RL/17 L/17
ƒ 5%$(6 R(J/0 (J/0E3 E3$K) $K)1 Install
,J0E%+3 E%+37+6 7+6 RLK&F1%] LK&F1%] (%GD +37+6 7+6 RL& L&5
ƒ 5%$(6 R(J/0'%9 '%9% IP address GD V VGD '(v '(v$?('123 $?('123+'&4 +'&4''$ ''$ 19 >191D1 !assword D !assword ƒ 5%$(6 R(J/0'6'2$&7 62$&7 ˆireware reware =7:>KGD =7:>KGD V V1( 1( Syste Syste ’ ’ `outerxoard `outerxoard E3 E3$K) $K)1 U!rade $5F>70 5F>70 {urrent {urrent ˆireware '&46 V V6( †.W
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% W‡# ‚~
$%&'(v$ `outer `outerOS OS ?; R'L+0 'L+0( 1; V V 1;'D 'D:?'<7K+'&4 :?'<7K+'&4Kv Kv7') 7')K$&]4 K$&]4 MikroTik K:6 '>K:6L MikroTik >70
9%7D %7D'E+4 'E+4'(v '(v$'D $'DG'&4( (+2'&4 +2'&4+GD V V +GD 5FK(2'&4 (2'&4+ qAN ; V V ;'1+9 '1+9'$6 '$6?&%G4 ?&%G4+'&4=17 =171_ 1_ 9('D ('DG'&4 G'&4( (+2'&4 +2'&4+GD V V +GD WƒX WƒX 5F K(9 (9(C'L (C'L -AN ,3 +Q4 +Q4 76L& L&K70 K70%(?( %(?( J($%&+6 RL9 L9%J0 %J0L%( L%( <(F(8%J/0 %J/0E?9 E?9%7D %7D'E+4 'E+4'(v '(v$=7:E3 $=7:E3$GD V V $GDK) K1) `eoe {onfiuration ,/%$J0L%( L%( MikroTik MikroTik G8%K %K(&%G4 (&%G4+'&4 +'&4+%1?0 +%1?0%( %( 9(1%$K:6 >K:6L MikroTik 5F$+6 $+67$%&; V V 7$%&;'1+9 '1+9'G6 'G6(GD 7D'EE4 'EE4>'2D >'2D<'77&&%G4 <'77&&%G4 +'&4 ; ;' pW.~}.}}. /%$E?9%7D %7D'EE4 'EE4'(v '(v$ J($%&C0%'(v %'(v$&%G4 $&%G4+'&4 +'&45F+0 5F+0'LKv 'LKv7 qinBoz 70 %>70GD V VGD htt!"##learnikrotik.co#xook#x htt!"##learnikrotik.co#xook#xasicconfi#con asicconfi#confi.tzt fi.tzt J/0667E'$=“ 7E'$=“7G6 7G6 RL/17 L/17 #i! address add address”pW.~ address”pW.~}..#W‡ }..#W‡ disaxled”no interface”et interface”etherW herW add address”pW.~ address”pW.~}.W.#W‡ }.W.#W‡ disaxled”no interface”wlan an #i! !ool
add nae”dhc!!ool ranes”pW. ranes”pW.~}..WƒpW. ~}..WƒpW.~}..WX‡ ~}..WX‡ add nae”dhc!!oolW ranes”pW. ranes”pW.~}.W.WƒpW. ~}.W.WƒpW.~}.W.WX‡ ~}.W.WX‡ #i! dhc!ƒserer add addressƒ!ool”dhc!!ool – disaxled”no interface”etherW leaseƒtie”†d nae”dhc! add addressƒ!ool”dhc!!oolW – disaxled”no interface”wlan leaseƒtie”†d nae”dhc!W #i! dhc!ƒserer confi set storeƒleasesƒdisk”X #i! dhc!ƒserer network add address”pW.~}. address”pW.~}..#W‡ .#W‡ dnsƒserer”}.}.}. dnsƒserer”}.}.}.}} ateway”pW.~ ateway”pW.~}.. }.. add address”pW.~}. address”pW.~}.W.#W‡ W.#W‡ dnsƒserer”W~. dnsƒserer”W~.‡~.†X.†X ‡~.†X.†X ateway”pW. ateway”pW.~}.W. ~}.W. #syste nt! client set enaxled”yes ode”unicast !riaryƒnt!”W†.}X.~p.~ !riaryƒnt!”W†.}X.~p.~ #interface wireless set xand”Wh…ƒx defaultƒauthentication defaultƒauthentication”yes ”yes disaxled”no – wirelessƒ!rotocol”}W. ”}W. ode”a!ƒxrid ode”a!ƒxridee #i! dhc!ƒclient add interface”ether disaxled”no #i! firewall nat add chain”srcnat outƒinterface”ether outƒinterface”ether action”as—uer action”as—uerade ade #i! neihxor discoery set wlan disaxled”no 5%$(6 R(GD V V (GD qinBoz qinBoz J/0Kv Kv7G'&4 7G'&4131('EK:6 '>K:6L'3 L'3(G'&4 (G'&4( (+ + '[3?%:&%:EF'D ?%:&%:EF'D:7=“ :7=“75%$70 75%$70%(?( %(?( ther" 'DG'&4 G'&4( (+2'&4 +2'&4+GD V V +GD K( qAN 2'&4+ 5F&6?>'2D ?>'2D<'77&K(K (K( Puxlic IP address /&; ' Static IP addre address ss 5%$ 5%$ 0J/0 J/0?&3 ?&3$%& $%& therW" 'DG'&4 G'&4( (+2'&4 +2'&4+GD V V +GD W W K( -AN 2'&4+ 5F<5L>'2D<'77&J/0 <'77&J/0$6$?&; V V ?6 &;'L'123 'L'123+'&4 +'&4>E' >E'(+4 (+4K K( \H{P <'77& Note" /%$J0 /%$J0 Mikro MikroTik Tik GD V VGDK K(&) 9 9 (&)((6 ((6?() ?()(&;'C9 'C9%:>&0 %:>&0%: %: W.‡ „H… ,1D wireless wireless card J(+6 1; V V 1;'&; V V '&;'L>E' 'L>E'(+4 (+4 9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% W~# ‚~
; V V ;'1+9 '1+9'&; '&;'C9 'C9%:>&0 %:>&0%: %: ,SSI\" MikroTik >E' (+4 (+4/E9 /E9%(D %(D R5F>70 5F>70&6&?>'2D ?6 >'2D<'77& suxnet 7D:$6 :$6(K (K( \H{P <'77& 5%$=7 recursie recursie \NS serice serice J0C'L C'L „oole $6? \yn\NS &D recursie \NS serice ˜\yn\NS W~.‡~.†X.†X W~.‡~.†~.†~
˜„oole Puxlic \NS serer }.}.}.} }.}.‡.‡
(Q4 L=&>(Q4E% E% ,NTP client $8 %/(7J/0 %/(7J/0Q3QL$4 L3 $4$6$?%?6 ?6 %?6(1%+&3 (1%+&3G:%9 G:%9L%+3 L%+3
˜$&1')G$%+&4 G$%+&4$'LG6 $'LG62&; 2&;' Ž$8%/(7J/0 %/(7J/0K K( secondary tie.nay.i.th
/&;'5FJ0 '5FJ0Q3 Q3&4&4'&4C'L=&L$%& NTP !ool !ro™ect ˜NTP POO- P`Oš{T serer W.th.!ool.nt!.or W.th.!ool.nt!.or serer .asia.!ool.nt!.or .asia.!ool.nt!.or serer W.asia.!ool.nt!.or W.asia.!ool.nt!.or C0'&&F6 '&&F6L" 9 L" 9%'(v %'(v$70 $70%(?(K %(?(K(2D (2D:L+6 :L+6':9 ':9%L: %L:Q'&4 Q'&4C0 C0% MikroTik &%G4+'&4 +'&4 $:6:LK L6 K( adin 19191&/6 &9 /6 9%(_ %(_ >191D1>&4 >D &4'EE4 'EE4 i!taxles >&4'EE4 i!taxles >&4 'EE45F+&5'?2%F$%&=51+D 5F+&5'?2%F$%&=51+DE%1D E%1D$%&78 $%&78%(3 %(3($%&G9%(6 %(6 R( =7:75%$+0 5%$+0(G%L'2D<'77&/&;'2'& '2'&+ Qm V VQmL>&4 L>&4'EE4 'EE45F>19 5F>199L6 L9 6**%]+; **%]+;'(>K:6 '(>K:6L L 077&4'EE4 'EE4G6G V V>K5F+&5'?2%F$%&5&%5&C%C0 6 >K5F+&5'?2%F$%&5&%5&C%C0% ,incoin traffice checks ƒ >&4'EE4 'EE41D1%1%1%&J($%&?) D %1%1%&J($%&?)1$%&78 1$%&78%(3 %(3($%&C'L<2$5J($%&; V V $5J($%&;'1+9 '1+9' 9( $%&'()*%+J/0 *%+J/0C0 C0%m %mL L? Q3&'&4 4 '&4 2'&+4 } }
Interfaces '3(+'&4 (+'&4Q /1%:mL 2'&4+GD V V +GD; V ; V'1+9'': 9 9 '':$6$?6 MikroTik &%G4+'&4 +'&4 Qm V VQmLK LK( Physical Port J($%&; V V J($%&; '1+9 '1+9'8 '8%/&6 %/&6?&6 ?&6?C0 ?C0'1 '1E C0% 70 >70 2; V V 2;'J/0 'J/0C0%J5L9 %J5L9%:J($%&J0 %:J($%&J0L%( L%( Kv7 qinBoz E;'$1( '$1( Interfaces Interfaces ’ ’ Interface Interface ’ ’ 76??3 ??3 REE3 EE3$GD V V $GD'3'(+'&4 (3 +'&4Q Q
GD V VGD
Note" ?( `outerOS %1%&GD 5F'(v V V5F'(v$<:$2'&4 $<:$2'&4+'3 +'3(G'&4 (G'&4+K +K( Master Port /&;' Switch Port >70 +%1 +%1 +0'L$%& 'L$%& =7:9%'(v %'(v$7D $7D'E+4 'E+4 MikroTik MikroTik 2'&4+GD +GD 5FK( Master Port
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% W}# ‚~
+6':9 ':9%L %L $%&23 V V $%&231>'2D 1>'2D<'77&?('3 <'77&?('3(+'&4 (+'&4Q Q E3$GD V V $GD1( 1( IP IP ’ ’ Address
E3$&; V V $&;'L/1%: 'L/1%: Ž1 2; V 2; V'G8%$%&23 V V %$%&231>'2D 1>'2D<'77&J/19 <'77&J/19 5%$(6 5%$(6 R(J9>'2D >'2D<'77&GD V V <'77&GD+0+'L$%& '0 L$%&
E3$K) $K)1 O‘ O‘ 2; 2; V V'?6 '?6(Gm (Gm$9 $9% Note" `outerOS Note" `outerOS 5FJ03[D[3 D$8$%/(7 8%/(7 Suxnet Mask ? {I\` ,{lassless Interƒ\oain `outin =7:$%&J0
slash notation ,# 0 :(>0/E6 /E6L&; V V L&;'L/1%: 'L/1%: # 9( pW.~}.WX.#W‡ +6EC EC pW.~}.WX. K( network network adddres adddresss Q+4 ?>Q+48%/&6 %8 /&6?8 ?8%(] %(] suxnet ask" htt!"##www.suxnetƒcalculato htt!"##www.suxnetƒcalculator.co r.co
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% †# ‚~
?GGD V W ƒ $%&567$%& ?GGD V 7$%& 0J0 J0 ,User ,User Manaeent ?G(D R5F27m 7mL$%&56 L$%&567$%& 7$%& 0J0 J0 19 19&5F6 &5F6?($6 ?($6? UserManaer (F&6? UserManaer 5FK (<2 (<2$5<:$5%$+6 $5<:$5%$+6 MikroTik 5F+37+6 7+6 RL<2 L<2$5(D $5(D R8%/&6 %8 /&6?'3 ?'312ED 12ED10 10(G4$%&G8 $%&G8%L%(&9 %L%(&91$6 1$6? `adius Q3&4'&4 '&4 9( ( User Manaeent K ( L$4 L$466(': 9 9 ':J( J( `outerOS 76L(6 L(6 R(5m (5mL>19 L>19&6 &6?($6 ?($6(&F/9 (&F/9%L %L User Manaeent $6? UserManaer Qm V VQmLK LK(<2$5&3 $5&31 &%%1%&$8%/(73 %/(73G[3 G[3&F76 &F76?$%&'() ?$%&'()*%+<+9EF: EF:Q'&4 Q'&4J/0 J/0<+$+9%L$6 %L$6(>70 (>70 =7:7D =7:7D'E+4 'E+4 MikroTik MikroTik `outerOS : Q'&4 Q'&4(1 (1 ;' adin adin &F76 &F76?3 ?3G[3 G[3$%&'() $%&'()*%+ *%+L) L)7 ,!erissions of full 19 191D1&F/6 &D F/69 9%( %( Note" &%%1%&?)1 Note" &%%1%&?) 1 0J0 J0? ?(:4 (:4$E%L>70 $E%L>70 =7:J0 =7:J0$%&23 $%&235(4 5 (4+6++( 6 +( 0J0 J0$6$?6 `adius Q3&4'&4 '&4 /&;'J0 'J0 MikroTik UserManaer าถัดไป) Kv7 qinBoz &3 V V&31+0 1+0(&0 (&0%L: %L:Q'&4 Q'&4 E3$GD V V $GD1( 1( Syste Syste ’ ’ Users Users 76 76L& L&K (ในหนาถัดไป)
5%$(6 R(E3$E; $E;'$
$&) “K7D K7D'E+4 'E+4 full full ,%1%&'9 %(ƒCD %(ƒCD:(9 :(9%'(v %'(v$?(&%G4 $?(&%G4+'&4 +'&4>70 >70_ read ,79%'(v %9 '(v$>70 $>70':9 ':9%L7D %L7D:G9 :G9%(6 %(6 R( ( 70 >70 J/0767??3 ?6 ?3 REE3 EE3$GD V V $GD; V V'$&) '; $&) “K2; V V K2;'7 '7&%:EF'D &%:EF'D:7 :7 9( $&) “K write $5F1D 5F1D&%:EF'D &%:EF'D:7?'$9 :7?'$9%: %:Q'&4 Q'&4GD V VG': 9 9 D':J($E) 9 9 J($E)1(D 1(D R1D13D G[3 G3 [3'F>&?0 'F>&?0%L %L :$+6':9 ':9%L %L 9( %1%&&D+%&4 +%&4>70 >70_ ssh /&;' telnet C0%/%m %/%mL MikroTik >70 K K(+0 (+0(
J($%&$8%/(73 %/(73G[3 G[3J/0 J/0$6$6?: ?:Q'&4 Q'&4 &3 V V &31+0 1+0(<(F(8 (<(F(8%J/0 %J/0&0 &0%L: %L:Q'&4 Q'&4 70 %(>70':9 ':9%L7D %L7D:G9 :G9%(6 %(6 R( ,$&) “K read
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% †W# ‚~
$%&23 V V1?6 $%&23 1?6*D *D&%:; V V &%:;': ':Q'&4 Q'&4J/19 J/19 GD V VGD
5FCm R(/(0%+9 %+9%LJ/0 %LJ/0J9 J9+6+ RL: L6 :Q'&4 Q'&4J/19 J/19_ E;'$$E) 9 9 '$$E)1 'GD %(>'GD ,consultant ,consultant 5%$?&3 b6bGC0 G6 C0%L('$ %L('$ GD V VGD9':K&F13 9':K&F13(E&F??&; (E&F??&;'C9 'C9%: %: ?%L$&]DC%'%55FC'3 C%'%55FC'3G[3 G[3J($%&C0 J($%&C0% mL') L')K$&]4 K$&]4 0 0%':9 %':9%L(D %L(D R&%>19+0+'L$%&J/0 '0 L$%&J/0?)?E/E9 )E/E9%(D %(D R1D13D 3G[3 G[3J($%&KED V V J($%&KED:(70 >70<+9 <+999%'(v %'(v$G9 $G9%(6 %(6 R( /&;''D ''D$$&]D $$&]D/(m V V /(mL$ L$;'; &%K(('3 (('312D 12DE10 E10(G4 (G4+3+7+6 73 +6 RL&F??J/0 L&F??J/0$6$?E ?6 E$0 $0% 19 >19+0+0'L$%&J/0 'L$%&J/0EE$0 $0%1D %1D3G[3 G3 [3?) ?)1G) 1G)$':9 $':9%L %L &%$ 2D:L<9 :L<9&0 &0%L; V V %L;' ' 0J0 J0J/0 J/0$6$?E ?6 E$0 $0%
User Manaer =QE66(8 (8%/&6 %/&6?$%&56 ?$%&567$%& 7$%& 0J0 J0?&1(:4 (:4 07770 $E%L>70 =7:$%&+3 =7:$%&+37 +6 RL<2 L<2$ $ UserManaer J/0$6$?6 MikroTik `outerOS /&; '+3 '+37+6 7+6 RL `outerOS ?(&; V V ?(&;'L'123 'L'123+'&4 +'&4Q3 Q3&4&4'&4 '&4 ,}~_ ,}~_ /&;''123 ''123+'&4 +'&41; 1;'( '( ,•ware /E6L5%$>70 L5%$>70+3+7+6 73 +6 RL UserManaer ,C6 R(+'($%&+37+6 7+6 RL5F'[3 L5F'[3?%:J(?G+9 ?%:J(?G+9'>K '>K /%$5FJ0>E'(+4 >E'(+42323 5(4 5 (4+6+6+( +( 0J0 J0$6$6? UserManaer J(/(0%+9 %+9%L %L User -ist 5F+0'LE3 'LE3$Q $Q$?'$Q4 $?'$Q4 76 76L& L&K
E;'$1( '$1( Syste Syste ’ ’ Users Users ’ ’ E;'$'GD $L%(>'GDGD V VG1DD1/(0 /D (0%GD V V %GD$D V V $D:C0 :C0'L 'L ,it su!!ort (D R;;' ' 0J0 J0 local adin GD V VGD5F%1%&C0 5F%1%&C0% 9 9 %&%G4 &%G4+'&4$%&&0 $%&&0%L: %L:Q'&4 Q'&4 >70': 9 9 ':1'm 1'mL<10 L<10 UserManaer UserManaer Q3&4&4'&4 '&45FJ/0 5FJ/0?&3 ?&3$%&>19 $%&>19>70 >70 ,UserManaer $6? User Manaeent (EF ':9%L$6 %L$6(':9 (':9%6 %6?(E9 ?(E9F&6 F&6? ? 9(C6 (C6 R(+'(C'L$%& (+'(C'L$%& \e!loy UserManaer m $b%23 V V $b%231+3 1+31>70 1>705%$ 5%$ MikroTik qiki $%&567$%& 7$%& 0J0 J0?&1 ?&1(:4 (:4 5m 5mLK LK(=QE (=QE66(8%/&6 %/&6?'L4 ?'L4$&/(9 $&/(9:L%(GD V V :L%(GD1D1D 0J0 J 0585%((1%$ %8 ((1%$ /&;'$%&'3 '$%&'3(G3 (G3$&7C0 $&7C0%$6 %$6?&F?? ?&F?? qifi HotS!ot
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% †‡# ‚~
+6':9 ':9%L %L $%&'(v$ MikroTik &%G4+'&4 +'&4J/0 J/0+&5'?$%&23 +&5'?$%&235(4 5 (4+6++( 6 +( 0J0 J0$6$?6 User Manaer RC6(+'((D (+'((D R5F(8%>KJ0 %>KJ0L%($6 L%($6?=K&<$&1 ?=K&<$&1 qinBoz =7:J0 ::Q'&4 Q'&4EE''3 ' '3(5%$ (5%$ UserManaer
E3$GD V V $GD1( 1( `adius `adius ’ ’ E3$&; V V $&;'L/1%: 'L/1%: Ž1 ’ E3$Q $Q$?'Q4 $?'Q4 loin loin ,/%$(8 %>KJ0 %>KJ0$6$?6 qifi HotS!ot $ E3 E3$Q $Q$?'$Q4 $?'$Q4 hots!ot 5%$(6 R($8 ($8%/(7<'77& %/(7<'77& `adius Q3&4&'&4 4 '&4 &$ L'F>&$>70 >70<+9 <+9J/0 J/0+&L$6 +&L$6?&F/9 ?&F/9%L %L >E'(+4 (+4 ’ ’ E3$K) $K)1 O‘ Note" +0'LE Note" +0 'LE''3 ''3(C0 (C0% UserManaer 70 >70
?GGD V V † Š $%&'62$&7CC0 >CC0'3 '372E%7 72E%7 ,Bu
/+)EGD V V EGD))]&'6 ]&'62$&7 ƒ 5'&4 5'&4J/19 J/19 CC0 >CC0'3 '372E%78 72E%78%/&6 %/&6?'&4 ?'&466(GD V VGDJ0 J0': 9 9 ': ƒ '62$&72; V V 2$&72;'J/0 'J/0(6 (6?() ?()(g%&47<&4 7<&4J/19 J/19GD V VD+0+0'LJ0 'LJ0L%( L%( 5mLK LK(/+)E9 E9%G8 %G8%>1&%m %>1&%mL+0 L+0'L'6 'L'62$&7 2$&7 `outerOS /&; 'v 'v&4&1<&4 14 <&4?(') ?(')K$&]4 K$&]4C'L&% <+99(1%$/E%:((9 9 (1%$/E%:((9%5F) %5F):$6 :$6?8 ?8% (D R J0 J0L%(>70 L%(>70': 9 9 ':5F'6 5F'62$&7G8 2$&7G8%>1j %>1j (; V V (;'L5%$?%L&6 'L5%$?%L&6 RLJ9 LJ999%&%G8 %&%G8%$%&'6 %$%&'62$&7199LE$&FG?+9 L9 E$&FG?+9'9 '9('; V ('; V( GD V VGDJ0 J0L%( L%( ': 9 9 ': 2&%FG) 2&%FG)$C0 $C0'3 '372E%71D 72E%71DEC'L$%&<$0 EC'L$%&<$0>CK >CK*/%$9 */%$9'(19 L" /%$>191D1/+) D /+)E+%1GD V V E+%1GD$E9 $E9%1%$ %1%$>19 >19&'6 &'62$&7&6?
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% †~# ‚~
+6':9 ':9%L %L C6 R(+'($%&'6 (+'($%&'62$&7&F??KZ3 ?6?+3+6 $%& $3 %& `outerOS &3 V V&31<&$J/0 1<&$J/07%(4 7%(4=/E7<2$55%$ =/E7<2$55%$?>Q+4 ?>Q+4 MikroTik MikroTik
2.
3.
4.
E;'$QD '$QD&D&:4:D 4&) 9 9(J/0 )(J/0+&L$6 +&L$6?GD V V ?GDJ0 J0 ,+6':9 ':9%L %L `B‚ series E4GD VG V=D /E71%5FK( routerosƒi!sxeƒX.WW.n!k K55) 55)?6?6( ,C]FCD:( 9 9 :(1;1' '; `outerOS ~. ; ~. ; V V'>E4 '>E4 routerosƒi!sxeƒ~..n!k Kv7 qinBoz K:6 '>K:6L') L')K$&]4 K$&]49%( %9 ( IP address ,>19; V ; V'1+9'9 '9%( %( MA{ address 2&%F=7:G6 V V>KJ( >KJ( $%&; V V $%&;'1+9 '1+9'>K:6 '>K:6L') L')K$&]4 K$&]48%/&6 %8 /&6?'(v ?'(v$ +0'LJ0 'LJ0 -ayer † J($%&567$%&$6 7$%&$6?&%G4 ?&%G4+'&4 +'&4
J(/(0%+9 %+9%L %L qinBoz E3$1( $1( ˆile ˆile 5%$(6 5%$(6 R(5F<7LE3 (5F<7LE3+4 +4>E4 >E4GD V VG': 9 9 'D :?(&%G4 ?(&%G4+'&4
5.
5%$(6 R(J/0 (J/08%&'LC0 %8 &'LC0'1 '1E$9 E$9'( '( =7:E3$GD V V $GDK) K1) Backu! 5F>70; V V'>E4 '; >E423 V V 231Cm 1Cm R(1%K (1%K( .xacku!
67>KJ/0 7>KJ/0 '6 '62=/E7 2=/E7 =7:3[D[$%&E%$ D$%&E%$ ,dra >E4<2$5GD V V <2$5GD': 9 9 ':?( ?( deskto deskto!! >707%(4 7%(4=/E71% =/E71% %L>E4J(2; J(2; R(GD V V (GD/(0 /(0%+9 %+9%L %L ˆile -ist ,%LJ(+8%(9 %(9LJ+0 LJ+0; V V'>E4 '; >E4 zzz.xacku! zzz.xacku! $>70 >70
Note" $%&'6 Note" $%&'62$&7<2$5Q'+4 2$&7<2$5Q'+4<&4 <&4'; V' V;( $G8G8%C6 %C6 R(+'((D (+'((D R/1; /1;'($6 '($6(2D (2D:LE; :LE;'$>E4 '$>E4<2$5G6 RL/17K%L 6.
/E6L5%$'6 L5%$'62=/E7>E4 2=/E7>E4& &5KGD V V =7:>KGD1( 1( Syste Syste ’ ’ `exoot
/&;'5FKv '5FKv7G'&4 7G'&4131('ECm (3 'ECm R(1%
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% †}# ‚~
5%$(6 R(&%G4+'&4 +'&45FC%7$%&; V V 5FC%7$%&;'1+9 '1+9'J/0 'J/0$7K) $7K)1 O‘
7.
Kv7 qinBoz
+&5'?'&46(
KGD V $>KGD V1( Syste Syste ’ ’ Packaes
Note" ,/E6 Note" ,/E6L5%$'6 L5%$'62$&7& 5 5 7D'E+4 'E+4<2$5 <2$5 userƒanaerj 5F>19 $+3 $ +37+6 7+6 RL L 0J0 J0+0+0'L+3 'L+37+6 7+6 RL23 V V L231'L 1'L 671%J/0 71%J/0G8G%$%&'6 8%$%&'62$&7 2$&7 `outerBOA`\ Boot loader >KGD V V >KGD1( 1( Syste Syste ’ ’ `outerBoard `outerBoard ’ ’
/&;'/&; '/&;'3 '3[D[;D'Kv '; Kv7G'&4 7G'&4131('E (3 'E
0%+0 %+0'L$%&7 'L$%&7v v&4&1<&4 14 <&4'&4 '&466(23124 1248%6 %8 6 V VL !rint !rint 70 >709 9($6 ($6( 9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% ‡# ‚~
5%$(6 R(J/0 (J/0&?? + &F??mL5F<7LK L5F<7LK('&4 ('&46(J/19 (6 J/19
+6':9 ':9%L %L C6 R(+'($%&7%(4$&7<2$5Q'+4 $&7<2$5Q'+4<&4 <&4C'L&F??KZ3 C'L&F??KZ3?6?6+3+$%& $3 %& `outerOS /%$J0L%(5&3 L%(5&3LKG8 62$&7>KG8%L%(>19 %L%(>19D D:&2' :&2' ?%L&6 RL$ L$585%K %8 K(GD V V (GD5F7%(4 5F7%(4$&7<2$5C'L&F??KZ3 $&7<2$5C'L&F??KZ3?6?6+3+3$%& $%& 1.
2.
RC6(+'(/1; (+'(/1;'($6 '($6?+'('6 ?+'('62$&7 2$&7 1; V V 1;'1D '1D<2$5$9%': 9 9 %':J( J( ˆile -ist $ 2D 2D:L<9 :L<9E3 E3$K) $K)1 \ownrade >KGD1( 1( Syste Syste ’ ’ Packaes
J(/(0%+9 %+9%L %L Packae -ist J/0 E; E;'$<2$5G6 '$<2$5G6 RL/17 L/17 5%$(6 R(E3 (E3$K) $K)1 \ownrade
C0'&&F6 '&&F6L">19 L">19<(F(8 <(F(8%J/0 %J/0E; E;'$7%(4 '$7%(4$&7?%L<2$5 $&7?%L<2$5 /&;'J0 'J0'&4 '&46(C'L<2$5GD V V (6 C'L<2$5GD<+$+9 <+$+9%L$6 %L$6( 2&%F'%5K(>K >70GD V VG5F$&FG?+9 D5F$&FG?+9'9 '9('; V V (';( (
3.
5%$(6 R(&D??+&%G4 + &%G4+'&4 +'&4
Note" %1%&'62$&79 Note" %1%&'6 2$&79%( %( ˆTP >70 =7:J0 =7:J0=K&<$&1 =K&<$&1 ˆTP client 9 ( ˆile›illa {lient =7:'62=/E7>E4 2=/E7>E4>K:6 >K:6L&%G4 L&%G4 +'&4 Kv Kv7G'&4 7G'&4131('E5%$(6 (3 'E5%$(6 R(23 (23124 12488%6 %6 V VL syste rexoot
+6':9 ':9%L %L C6 R(+'($%&+3 (+'($%&+37+6 7+6 RL<2$5Q'+4 L<2$5Q'+4<&4 <&423 V V 231 ?%L&6 RL&%58 L&%58%K %K(+0'L1D 'L1D$%&+3 $%&+37+6 7+6 RL<2$523 V V L<2$5231+3 1+31 (; V V (;'L5%$7D 'L5%$7D'E+4 'E+4&%G4 &%G4+'&4 +'&4>19 >191D1D<2$5(6 <2$5(6 R(1%J/0 (1%J/0 9 9( <2$5 <2$5 userƒ userƒ anaer ,UserManaer %1%&7%(4=/E7<2$5+9 %L %L 5%$?>Q+4 ?>Q+4 MikroTik MikroTik ,htt!"##www.ikrotik.co#download_ k.co#download_ 5%$(6 R(<+$>E4GD V VG=/E71% D=/E71%
E3$E; $E;'$7%(4 '$7%(4=/E7<2$5G6 RL/17 L/17 All !ackaesj E4 >E4>0 >0GD VG VD deskto!
2.
>KGD V V >KGD Syste Syste ’ ’ Packaes
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% ‡W# ‚~
3.
E%$>E4<2$5>K:6 <2$5>K:6L ˆiles -ist ,\ra and \ro!
4.
5%$(6 R(J/0&D&??D +&%G4 +&%G4+'&42; V V 2;'+3 '+37+6 7+6 RL<2$5J/0 L<2$5J/0'L'6 'L'6+=(16 +=(16+3+3_ Kv7G'&4 7G'&41313('E
+6':9 ':9%L %L $%&567$%&<2$5?(&%G4 7$%&<2$5?(&%G4+'&4 +'&4 <(F(8%9 %9%<2$5>/(GD V V %<2$5>/(GD>19 >19>70 >70J0 J0L%(J/0 L%(J/0'($%&+3 '($%&+37+6 7+6 RLQF LQF /&;'/%$'(%+3 '/%$'(%+379 79%+0 %+0'LJ0 'LJ0 5'&4<2$5(6 R($J/0 J/0KvK7$%&J0 v7$%&J0 L%( ,disaxle 19>70 >70J0 J0L%( L%( +37+6 7+6 RL>K$ L>K$&6&($3 (6 $3(G&62:%$&&F??QFKE9 % &6?
E;'$<2$5
5%$(6 R(Kv (Kv7G'&4 7G'&4131('E
/E6L5%$&D L5%$&D??+ <2$5$Kv $Kv7$%&J0 7$%&J0L%( L%( ,disaxle
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% ‡‡# ‚~
?GGD V V ‡ Š $%&+6 RL; ?GGD L; R'J/0 'J/0$6$?') ?6 ')K$&]4 K$&]4&%G4+'&4 +'&4 ,`outer ,`outer Identity `outer Identity ; ' $%&+6 RL; V V L;'J/0 'J/0$6$?') ?6 ')K$&]4 K$&]4&%G4+'&4 +'&4 2; V V 2;'J/0 'J/0 0&&&%:EF'D & %:EF'D:7C'L&%G4 :7C'L&%G4+'&4 +'&4(6( R(6 9( GD VGD V': 9 9:C'LE C'LE$0 $0% K(+0 (+0( ('$5%$(6 R($%&$8 ($%&$8%/(7 %/(7 `outer Identiry :6LK LK(K&F=:(4 (K&F=:(42; V V 2;'9 '9:<$0 :<$0>CK >CK]/%J(E%+9 ]/%J(E%+9'1%>70 '1%>70L9L%:Cm %9 :Cm R( =7:K$+3$%& $%& $8%/(7; V V %/(7;'0 '0%&F?) %&F?)K K(GD V V (GD': 9 ': 9C'LE$0 $0% ตัวอย ตัวอยาง าง 9( `outer Identiry Žco!onent Ž co!onentŽŽdeiceƒI\ deiceƒI\ŽŽlocation location
co!onent " (3 7C'L') 7C'L')K$&]4 K$&]4 9 9( `outer_ {ore Switch_ Access Switch deiceƒI\ " /1%:EC') K$&]4 K$&]4 (; V V (;'L5%$K 'L5%$K(>K>70J(/(m V V J(/(mL( L(+3 +3$4 $41D1')'D K$&]4 )K$&]4(377D 77D:$6 :$6(/E%:+6 (/E%:+6 location " %(GD V V %(GD +3+7+6 73 +6 RL') L')K$&]4 K$&]4 9 9( ; V V;'C+2; 'C+2; R(GD V VGD +6':9 ':9%L %L `B‚XPTTY `B ,`outerxoard (3 7&%G4 7&%G4+'&4 +'&4 ‚X ,I\ QD&D& ‚X D ‚X PTTY ,Pattaya %(GD %C%26 V V%C%26G:% `Bq‚XPTTY `Bq ,`outerxoard (3 7>E 7>E ‚X ,I\ PH‘T ,Phuket %(GD %C% V V%C%$ $+ +6':9 ':9%L %L C6 R(+'($%&$8 (+'($%&$8%/(7; V V %/(7;'J/0 'J/0&%G4 &%G4+'&4 +'&4 1.
Kv7=K&<$&1 7=K&<$&1 qinBoz_ >KGD V V >KGD1( 1( Syste Syste ’ ’ Identiry
5%$(6 R(J/0+6+ R6L; V V L;'J/0 'J/0$6$6?') ?')K$&]4 K$&]4
E3$K) $K)1 O‘ O‘ K K('6 ('6(& (&5 &%:EF'D:7GD V V :7GD$8$%/(7>K5F<7LJ( 8%/(7>K5F<7LJ( qinBoz +&L9(C'L (C'L title xar_ /(0 %G'&4 %G'&41313('E ('E
Ter7i(89 :i(;o:6
-ei<=4or> /i>t :i(;o:6
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% ‡~# ‚~
?GGD X X Š &F??E% (Q4 ?GGD V V L=&>(Q4E% E% ,Syste Tie and NTP Protocol $%&Q+'62&F??E%J/0 2&F??E%J/0$6$?') ?6 ')K$&]4 K$&]4 MikroTik MikroTik 1D%18 %18%6 %6*K *K(':9 (':9%L:3 V V %L:3L (; V V (;'L5%$ 'L5%$ `outerBOA`\ >191D1++'&D G14 :?>G14 GD V V GDK K(E%1%+&%( (E%1%+&%(
+6':9 ':9%L %L $%&Q+'62 NTP {lient Q3 L=&>(Q4 L=&>(Q4E%$6 E%$6? NTP Serer $%&'(v$70 $70%(E9 %(E9%L(D %L(D R5F'0 5F'0%L'3 %L'3LE%$6 LE%$6? NTP Q3&4&'&4 4 '&4%:('$&; %:('$&;'C9 'C9%: %: =7:$8%/(7J/0 %/(7J/0Q3QL$4 L3 $4$6$?%?6 ?6 %?6(1%+&3 (1%+&3G:%9 G:%9L %+3KGD V V >KGD1( 1( Syste Syste ’ ’ NTP {lient
˜$&1')G$%+&4 G$%+&4$'LG6 $'LG62&; 2&;' Ž$8%/(7J/0 %/(7J/0K K( secondary tie.nay.i.th
E;'$=/17K '$=/17K( unicast unicastjj 5%$(6 R($8%/(7 %/(7 Priary NTP Serer K ( tie.nit.or.th tie.nit.or.th
Note" /%$/(9:L%(1D :L%(1D&; V V &;'L 'L NTP Q3&4'&4 '&4 GD V VGDQ3QL=&>(Q4 L3 =&>(Q4$6$?&; ?6 &;'C9 'C9%:%:('$': 9 %:%:('$': 9(Q&; L3 =&>(Q&;'C9 'C9%:%:J(70 %:%:J(70 Qm V V QmL5F9 L5F9:E7G&%v :E7G&%v$J(&F?? $J(&F??
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% ‡}# ‚~
Syste {lock /E6L5%$GD V V L5%$GD>70 >70'(v '(v$ NTP {lient J/0 Q3QL& L3 &5&D 5&D:?&0 :?&0':19 '>19 ,local clock tie …one
+6':9 ':9%L %L $%&+6 RL9 L9%E%=E'=Q(?$8 %E%=E'=Q(?$8%/(7'L %/(7'L 1.
Kv7=K&<$&1 7=K&<$&1 qinBoz +6 RL9 L9%6 %6**%](%œ3 **%](%œ3$% $% Syste {lock >KGD V V >KGD 1( 1( Syste Syste ’ ’ {lock
2.
E3$E; $E;'$=E'E=Q( '$=E'E=Q( Asia#Bankok
/&;'5FE; '5FE;'$ '$ Tie ›one Nae K ( anual 5%$(6 R(>K'(v$GD V $GD V
C0'&&F6 '&&F6L"L" >19<(F(8 <(F(8%$%&+6 %$%&+6 RL9 L9%?$8 %?$8%/(7'L %/(7'L 2&%FG)$ $ E%GD V V E%GD&%G4 &%G4+'&4&D&??D + E%
Adance NTP Serer Setu! =7:K$+319 >19585%K %8 K(+0 (+0'L+3 'L+37+6 7+6 RL (; V V (;'L5%$&%'(v 'L5%$&%'(v&F??E%J/0 &F??E%J/0Q3QL=&>(Q4 3L=&>(Q4$6$?6 Tie Tie sere sererr 9%('3 %('3(G'&4 (G'&4( (+ ': 9 9 ':KGD V V >KGD1( 1( Syste Syste ’ ’ Packaes 0%:6 %:6L$ L$J/0 J/0+3+37+6 7+6 RL /E6L5%$+3 L5%$+37+6 7+6 RL& L&5&D 5&D:?&0 :?&0':70&6 &6?
+6':9 ':9%L %L C6 R(+'($%&'(v (+'($%&'(v$ NTP Serer
7%(4=/E7<2 =/E7<2 All !ackaej 5%$ www.ikrotik.co#download www.ikrotik.co#download <+$>E4 …i! …i! GD V VGD=/E71%>0 =/E71%>0?( ?( deskto! E%$>E4 nt! nt! <2$5 >K%LJ(/(0%+9 %+9%L %L ˆile -ist &D??+&%G4 + &%G4+'&4 +'&4 /E6L5%$GD V V L5%$GD&%&D &%&D??+& + &5KGD V V $>KGD1( 1( Syste Syste ’ ’ NTP Serer
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% X# ‚~
E3$Q $Q$?'$Q4 $?'$Q4 naxle naxle E' >E'(+4 (+4$$G8G%$%&Q3 %8 $%&Q3L=&>Q(4 L=&>Q(4$E6 $E6?&%G4 ?&%G4+'&4 +'&4+6+6(D (D R>70 >70
?GGD V V ~ Š $%&'6 ?GGD '62>E4 2>E4 ,Backu!s L>191D1'F>&8 'D F>&8%6 %6*>K$9 *>K$9%$%&8 %$%&8%&'LC0 %&'LC0'1E'(v E'(v$&F??19 L5F>19J0 J0 \` \` ,\isaster `ecoery '6+=(16 +=(16+3+C6C3 R6(G2 <+9 &; V V &;'L1; 'L1;'J($%&8 'J($%&8%&'LC0 %&'LC0'1 '1E?(&F??KZ3 E?(&F??KZ3?6?+3+6 $%& 3$%& `outerOS $ <(5F) <(5F)7L9 7L9%: %: 2D:L<9 :L<9$7K) $7K)1 Backu! /&;'/%$+0 '/%$+0'L$%&$ 'L$%&$ 0 ;(&F??$ (&F??$2D 2D:L<9 :L<9$7K) $7K)1 `estore GD V VGD8%6 %8 6*J0 *J0E%J($%&8 E%J($%&8%&'L/&; %&'L/&;'$ '$ 0;(>19 (; >19mL3 Lm 3(%GD (%GD (!เร"วไปไหนอ วไปไหนอ!) !) =7:&)K?(%&D %&'L?>?(%&D5F>19 5F>19%1%&<$0 %1%&<$0>C>70 >C>70 <+9 <+900%8 %8%&'LK %&'LK(? (? tezt xased =7:C0 '7D '7DC'L$%&8 C'L$%&8%&'LC0 %&'LC0'1 '1E K( tezt >E4 ; ;'%1%& '%1%& restore $6?<E+'&4 ?<E+'&41g%&4 1g%&47<&4 7<&4GD V VG<+$+9 D<+$+9%L$6 %L$6(>70 (>70 =7:3 =7:3[D[Kv DKv7>E4 7>E49%(=K&<$&1 %9 (=K&<$&1 tezt editor 9( Ms Note!ad 2; V V 2;'<$0 '<$0>C'(v >C'(v$&F?? $&F?? 9(>?(%&D (>?(%&D'6 '62$&]D 2$&]DQ;Q R'') '; ')K$&]4 K$&]4J/19 J/19 0 0%5F(8 %5F(8%>E4 %>E4 xacku! xacku! >K restore ') K$&]4 K$&]45F+0 5F+0'LK 'LK(<E+'&4 (<E+'&41g%&4 1g%&47<&4 7<&4&) 9 9&() 7D:$6 :$6(G9 (G9%(6 %(6 R( mL5FG8 L5FG8%>70 %>70 9 9( J0 `B‚X„ `B‚X„ ': 9 9 ': Q; Q; R'J/19 'J/19$$+0+ 0'LK 'LK( `B‚X„ /1;'(73 '(731 /%$Q; R'&D '&DQDQ:4:D 4'; V V'($ (; $+0+0'L(6 'L(6 V VL'(v L'(v$ J/19&6 &6? $&]D7D:$6 :$6(0 (0%G8 %G8% xacku! GD V VGD&) 9& 9() `outerBOA`\ ‡X 19 Q>19G9 G9%$6 %$6( GD V VGD7D7GD V VGD D)7) ;' 8%&'LC0 %&'LC0'1 '1E? E? teztƒxased 5F1? &]4 &]4? ? GD V VGD)7&6 7) &6?
+6':9 ':9%L %L $%&8%&'L&F???>?&%&D %&'L&F???>?&%&D>E4 >E4 '6 '62 1.
Kv7=K&<$&1 7=K&<$&1 qinBoz E3$1( $1( ˆiles
2.
J(/(0%+9 %+9%L %L ˆiles J/0E3 E3$GD V V $GDK) K)1 Backu! Backu! 2; 2; V V' ''6 '62
3.
>E4 '6 '625F=4 25F=4GD V VD/(0 /(0%+9 %+9%L %L ˆile -ist 5%$(6 R($<9 <9E%$>E4 E%$>E4>K%L?( >K%L?( local drie &; 'L V V'L /&;'%LGD V '%LGD V deskto! 5%$(6 R(<(F(8%J/0 %J/0KED V V KED:(; V V :(;'>E4 '>E4 9 9( PTTYƒWWƒWƒWpƒˆinal. PTTYƒWWƒWƒWpƒˆinal.xacku! xacku! /&; '0%&%G4 %&%G4+'&4 +'&4(D( R'(v D '(v$J/0 $J/0?&3 ?&3$%& $%& HotS!ot $'%55FKED V V '%55FKED:(; V V :(;'>E4 '>E4J/0 J/0'7E0 '7E0'L$6 'L$6?&%G4 ?&%G4+'&4 +'&4GJ/0 JD V VD /0?&3 ?&3$%& $%& 9( PTTYƒqiˆiHotS!otƒWWƒW PTTYƒqiˆiHotS!otƒWWƒWƒƒ Wp.xacku! K(+0 (+0(
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% XW# ‚~
+6':9 ':9%L %L $%&$ 0;(&F??5%$>?&%&D ;(&F??5%$>?&%&D>E4 >E4 '6 '62 1.
2.
3.
Kv7=K&<$&1 7=K&<$&1 qinBoz E3$GD V V $GD%1( %1( ˆiles
5%$(6 R(E3 (E3$E; $E;'$; V V '$;'>E4 '>E4 '6 '62GD V V 2GD>70 >70G8G% 8%'6 '62>0 2>0 <+9 <+90%>19 %0 >191D1D>E4 >E4$$E%$>E4 E %$>E45%$ 5%$ local drie GD V V>70 >708%&'L>0 %8 &'L>01%%L 1%%L GD V VGD/(0 /(0%+9 %+9%L %L ˆile -ist
76??3 ??3 REE3 EE3$GD V V $GD>E4 >E4 E4 '$>E470 >709 9($6 ($6( (
Note" >19<(F(8 <(F(8%J/0 %J/0$ $?>E4 ?>E4'6 '62>0 2>0?(2; ?(2; R(GD V VGD&%G4 &%G4+'&4 +'&4 &$ &$?8 ?8%&'L>E4 %&'L>E4<:$''$1%C0 %L('$ %L('$ 9( >0GD V VG local D local
drie /&;'9 '9L$ L$?J(1E? ?J(1E?'$Q4 '$Q4 (; V V (;'L5%$0 'L5%$0%g%&4 %g%&47<&4 7<&4&%G4 &%G4+'&4D D:/%: :/%: >E4 '6 '62GD V V 2GD': 9 9 ':?(&%G4 ?(&%G4+'&4 +'&4$$/%:>K70: : Tezt Based Backu!s 76LGD V V LGD$E9 $E9%>KKC>E4 >C>E4>70 >70 9 9( /%$1D')'K$&]4 )K$&]4<E+'&4 <E+'&4+&) 9 9 +&)('; V V (';( ( $ 2D:L<9 :L<9D D:&4 :&4'(v '(v$ ':9%L9 %L9( MA{ address =7:J0=K&<$&1 =K&<$&1 tezt editor E4 $>E4 /&; /&;'5F&0 '5F&0%L>E4 %L>E4CmC R(1%J/19 m(1%J/19$$>70 > 709 9($6 ($6( E4 2=/E7>E4>K:6 >K:6L&%G4 L&%G4+'&4 +'&4+6+6J/19 J/19 9 9': ': $7K) $7K)1 restore $%&8%&'LC0 %&'LC0'1 '1E? E? tezt xased '6 '62 +0'LJ0 'LJ088%6 %6 V VL coand line ?(G'&4131('EG9 (3 'EG9%(6 %(6 R( +6':9 ':9%L %L $%&&0%L>E4 %L>E4 tezt tezt xacku! 1.
Kv7=K&<$&1 7=K&<$&1 qinBoz
2.
/E6L5%$(6 L5%$(6 R(5FCm (5FCm R(2&0'1G4 '1G4 J/0 J/02323124 12488%6 %6 V VL E4 '>E4
&F/9%L %L ez!ort >E4(D( R5D FJ0 {PU {PU 1%$mL ž ,>19 ,>19& & ez!ort C]F:Q'&4 Q'&4J0 J0L%(&F?? L%(&F?? 5%$(6 R(&'6$& 9 9 $& 0 0% &5E4 >E45F': 9 5F': 9GD V V/(0 D/(0%+9 %+9%L %L ˆile -ist /E6L5%$ L5%$ ez!ort &5
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% X‡# ‚~
+&5'?>E4J(/(0 J(/(0%+9 %+9%L %L ˆile -ist E3$1( $1( ˆile ˆile
3.
E%$>E4''$1%%LGD ''$1%%LGD deskto! V V deskto! E4 7>E4707:=K&<$&1 0:=K&<$&1 tezt editor 2; '<7L9 V V'<7L9%'(v %'(v$/&; $/&;'<$0 '<$0>C >C
Note" %1%&J088%6 %6 V VL ez!ort <7L'(v$J(/(0 $J(/(0%+9 %+9%LG'&4 %LG'&4131('E>70 (3 'E>70 =7:EF0 =7:EF0( files”j J(9(C'L8 (C'L8%6 %6 V VL ez!ort +6:9 :9%L %L 9( <7L2%F$%&$8%/(79 %/(79%'(v %'(v$>'2D $>'2D<'77& =7:GD V V =7:GD%1%&6 %1%&67E'$=0 7E'$=07''$1%%LGD V V 7''$1%%LGD =K&<$&1 note!ad >70 E: E:
?GGD V V ‚ ‚ Š >EQ(+4 ?GGD (+4 ,-icensin /(m V V /(mLJ() LJ()]E6 ]E6$b]F?(&F??KZ3 $b]F?(&F??KZ3?6?6+3+ `outerOS 3 `outerOS ?( MikroTik `outerBOA`\ (6 R($ ($;;'>EQ '>EQ(+4 (+4 =7: =7:5'&4 5'&4+9+%L %9 L 5F1DJ( J( G)$ $ >EQ(+4 (+4 <+9 <+93 V VLGD V V L3 GD$58 $ 58%$6 %$67<+9 7<+9&F76 &F76?C'L>EQ ?C'L>EQ(+4 (+4 5F': 9 9 5F':GD V VGD585%(('3 %8 (('3(<+(Q4 (<+(Q4 +6':9 ':9%L %L 9( >EQ(+4 (+4 leel leel † %1%&&0 %L$%&; V V %L$%&;'1+9 '1+9'? '? !ointƒtoƒ!oint >70 2D 2D:L/(m V V :L/(mL>E'(+4 L>E'(+4 <+9 <+90%+0 %0 +0'L$%& 'L$%& 1%$$9%/(m V V %/(mL>E'(+4 L>E'(+4 ,ulti!le ,ulti!le clients J(=/17 J(=/17 Access Point 5F+0 'LK 'LK(>EQ (>EQ(+4 (+4 leel leel ‡ 9( (5'&4J(&F76 J(&F76? ?L'; V V L';( ( ':9%L9 %L9( MP-S %1%&J0>70 >70G)G$&F76 $) &F76?>EQ ?>EQ(+4 (+4 K&D K&D:?GD :?GD:?%1<+$+9 :?%1<+$+9%L<+9 %L<+9EF>EQ EF>EQ(+4 (+45%$+%&%L70 5%$+%&%L70%(E9 %(E9%L(D %L(D R Le ve ve l num be be r
0 (De mo mo m od ode )
1 (Fre e) e)
3 (WISP CPE) 4 (WISP) 5 (WISP) 6 (Co nt nt ro rolle r) r)
Price
no ke y
re gis tra t ion
v olume only
Ugra !a "le #o
no ugra !e s
)nit ia l * on+ ig 'uort
, ire le s s - P
$45
$95
$250
%& ' v 6. (
%& ' v 6. (
% & ' v 7. (
% & ' v 7. (
15 !a y s
30 !a y s
30 !a y s
24 tria l
y es
y es
y es
, ire le s s * lie nt a n! /ri!ge
24 tria l
y es
y es
y es
y es
% )P & 'P /P rotoco ls
24 tria l
y e s
y es
y es
y es
o)P t unne ls
24 tria l
1 unlimite !
unlimit e !
unlimite !
unlimit e !
PPPo tunne ls
24 tria l
1
200
200 500
PP#P tunne ls
24 tria l
1
200
200
500 unlimit e !
2#P tunne ls
24 tria l
1
200
200
500 unlimit e !
& P t unne ls
24 tria l
1
200
200 unlimite !
24 trial
1 unlimite! unlimite!
:ot 'ot a ct iv e us e rs
24 tria l
1
% - ;)U' clie nt
24 tria l
< ue u e s
24 tria l
, e " r o ( y
24 tria l
Use r ma na ge r a ct iv e s e ss ions
24 tria l
1
um"e r o+ => gue s ts
none
1 Unlimit e !
- inter+a ces
unlim unlimite! 1
y es 1 unlimite !
y es 10
unlimit e !
unlimit e !
unlimite! unlimite!
200
unlimite! unlimite!
500 unlimit e !
y es
y es
y es
unlimit e !
unlimite !
unlimit e !
y es
y es
y es
20 Unlimite !
50 Unlimit e ! Unlimite !
Unlimit e !
,Ÿ ƒ 8%/&6 %/&6? `outerBOA`\ =K&=+'E B„P ,Border „ateway Protocol 5F $23 V V $231J(>EQ 1J(>EQ(+4 (+4 leel† leel† G9%(6 %(6 R( 9(') (')K$&]4 K$&]4'; V V'( ;( 5F+0'LK 'LK(>EQ (>EQ(+4 leel‡ leel‡ /&;' 'L$9 L$9%(D %(D RmmL5F(6 L5F(6?() ?()(=K&=+'E (=K&=+'E B„P.
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% X~# ‚~
33 V VLGD V V LGD/1; /1;'($6 '($6(C'LG) (C'LG)$ $ >EQ(+4 (+4 ,All ,All -eel -icenses ƒ >191D1D6(/17'%:) (6 /17'%:) ,neer ,neer ez!ire ƒ >EQ(+4 (+4 leel‡ (6?() ?()(&D (&DG%L'D1E 1E Xƒ† 6( /E6L5%$6 L5%$6 V VLQ; LQ; R' ƒ J0L%(>70 L%(>70>19 >19585%$6 %8 $67$%&; V 7$%&; V'1+9' ƒ >EQ(+4 (+4J0 J0+3+37+6 7+6 RL>70 L>70&6 R&6L7D L7D:G9 :G9%(6 %(6 R( ƒ 8%/&6 %/&6?>EQ ?>EQ(+4 leel† leel† 5F+0'L6 'L6 V VLQ; LQ; R'58 '58%((1%$$9 %((1%$$9 % >EQ(+4 (+4CmC R(>KG9 m(>KG9%(6 %(6 R( '0%L'3 %L'3L ƒ htt!"##wiki.ikrotik.co#wiki#Manu htt!"##wiki.ikrotik.co#wiki#Manual"-icense al"-icense >EQ(+4 (+4EQ 2$&7>EQ(+4 (+4 `outerOS `outerOS %1%&G8 %>70 %>70G)G$E% )$E% <+9 RCmC(': 9 9 (m ':$6$?6 license leel C'L `outerOS 9( 9 ( 0%$8 %$8%E6 %E6LJ0 LJ0L%( L%( `outerOS X >EQ(+4 (+4C'L&%5F C'L&%5F$58 $58%$6 %$67$%&'6 7$%&'62$&7 2$&7 5F%1%&'62$&7>70 2$&7>705F+0 5F+0'L 'L `outerOS ~ G9 %(6 %(6 R( 19 %1%&'62$&7>KK 2$&7>KK('&4 ('&4(6 `outerOS ‚ >70 =7:D:4:'6'4 2$&75F1D 62$&75F1D'LK&FG 'LK&FG ;' -eel†#-‡ K 7>K 9( ( -eelX 70 (6 >70 +6 +6EC'&4 EC'&46(6 9( •X ,0%K %K( •X.W +6EC EC W ;''&4 ''&4(C'L<+9 (6 C'L<+9EF&) 9 9 EF&)( (
$%&8%(]$%&'6 %(]$%&'62$&7 `outerOS GD :?$6 :?$6? -icense leel -icense -eel† 70 >70 -icense -eelX 70 >70 9( J0 -X#-~ -X#-~ ” † W ” %1%&J0 &) 9 9&() X.W >70 +6':9 ':9%L %L ƒ 0%&) 9 9 %&)(K (K55) 55)?6?(J0 (6 J0 `outerOS † ,`OS †_ -icense -eel† 70$6$?6 `OS †._ †.W_ ‡._ ‡.W <+9>19 >19&'L&6 &'L&6? X. ƒ 0%&) 9 9 %&)(K (K55) 55)?6?(J0 (6 J0 `outerOS † ,`OS †_ -icense -eelX 70$6$?6 `OS †._ †.W_ ‡._ ‡.W 19 >19&'L&6 &'L&6? ~.
ƒ 0%&) 9 9 %&)(K (K55) 55)?6?(J0 (6 J0 `outerOS ‡ ,`OS ‡_ -icense -eelX 70$6$?6 `OS ‡._ ‡.W_ X._ X.W Km L ~.pp <+9>19 >19&'L&6 &'L&6? ‚ Note" &K?+6 Note" & K?+6EC'&4 EC'&46(6 a™or.inor.reision 9( ‡.W ; '&) 9 9 '&)(15'&4 (15'&4 ‡ ‡ >19('&4 ('&4 W W Ma™or ersion ;' '&46(GD V V (6 GDKE9 KE9':''$1%:<2&9 ':''$1%:<2&9':9 ':9%L1? %L1?&]4 &]4 Minor ersion ;' '&46(GD V V (6 GD>70 >70&6&?$%&<$0 ?6 $%&<$0>CC0 >CC0'3 '372E%7C23 V V >C231+3 1+31 $9'(GD V V '(GD5''$ 5''$ &) 9 9&)() ()7G0 7G0%: %: +6':9 ':9%L %L $%&+&5'?&F76?C'LE%:Q ?C'LE%:Q(+ (+ &%%1%&+&5'?&F76?>EQ ?>EQ(+4 (+4GD V VG+3+D 37+6 7+6 RL
Note" >EQ(+4 Note" >EQ (+4>19 >19%1%&'6 %1%&'62$&7>70 5F+0 5F+0'L6 'L6 V VLQ; LQ; R'2; V V '2;'+3 '+37+6 7+6 RLJ/19 LJ/19EQ ?>EQ(+4 (+473 731G9 1G9%(6 %(6 R( $%&6 V VLQ; LQ; R'D 'D:4:>E >4 E Q(+4 (+4%1%&6 %1%&6 V VLQ; LQ; R'=7:$%&ELGF?D '=7:$%&ELGF?D:(9 :(9%( %(?>Q+4 ?>Q+4 ikrotik.co ikrotik.co
/(0% X}# ‚~
+6':9 ':9%L %L $%&+37+6 7+6 RL>EQ L>EQ(+4 $9'(5F+3 '(5F+37+6 7+6 RLD LD:4:>EQ >4 EQ(+4&F76 &F76? ?LCm LCm R(&%$ (&%$+0+0'L6 'L6 V VLQ; LQ; R'D 'D:4:>EQ >4 EQ(+4 (+4$9$'( 9'( =7:1DE8E%76 %8 76?C6 ?C6 R(+'(76 (+'(76L(D L(D R ELGF?D:(16 :(16&1%3 &1%3$GD V V $GD?>Q+4 ?>Q+4 www.ikrotik.co www.ikrotik.co 2. &F??5F9L usernae $6? !assword J/0G%L'D G%L'D1E 1E 5%$(6 R(E (E'$'3 '$'3(C0 (C0% 9 9 %&F?? &F?? GD1( 1( account 5F1D1( 1(:9:': 9': „enerte a Nq software ‘Y J/0E3 J/0 E3$E; $E;'$ '$ !urchase a key 3. GD V V 4. E;'$&F76 '$&F76?>EQ ?>EQ(+4GD V VGD+0+'L$%&Q; '0 L$%&Q; R' 9( qISP AP ,-eel X 5. J9 Softwore I\ 70 (5F>70&6&?D ?6 D:4:>EQ >4 EQ(+4G%L'D G%L'D1E 1E 6. &F??5FC0% 9 9 ว#$$ทท % % 67E'$D 7E'$D:4:
+6':9 ':9%L %L D:4:4>EQ >EQ(+4 (+4 The software ‘ey is" ƒƒƒƒƒB„IN MI‘`OTI‘ SOˆTqA` ‘Yƒƒƒƒƒƒƒƒƒƒƒƒ ‘XY—‚Upz`ˆ!›††r~`TcauU›T ‘XY—‚Upz`ˆ!›††r~`TcauU›Tp!š™dzˆr‚šAq{~\…‚A„ p!š™dzˆr‚šAq{~\…‚A„ !pšnrlBOy!…!{hxTaˆ›B‘PTSe !pšnrlBOy!…!{hxTaˆ›B‘PTSe™XxU\oXIA”” ™XxU\oXIA”” ƒƒƒƒƒN\ MI‘`OTI‘ SOˆTqA` ‘Yƒƒƒƒƒƒƒƒƒƒƒƒƒƒ J/067E'$&3 V V 76 E'$&31+6 1+6 RL<+9 L<+9 ƒƒƒB„IN... ƒƒƒB„IN... 5(mL SOˆTqA` ‘Yƒƒƒƒƒƒƒƒƒƒƒƒƒƒ 5%$(6 R(E3 (E3$K) $K)1 Paste ‘ey
ว#$$ทท & & J0$%& $%& i!ort key 5%$>E4DD:4: ,.key 4 ,.key 7%(4=/E7>E4 =/E7>E4D:4:D 45%$'D 5%$'D1E 1E ,9( }\SMƒ~NA.key }\SMƒ~NA.key 5%$(6 R(E3 (E3$K) $K)1 I!ort key
Note" K) K)1 U!date -icense ‘ey 5FJ0 ‘ey 5FJ0J($%&'6 J($%&'627G& 27G&K?C'LD K?C'LD:4:4 1; V V 1;''6 ''62$&75%$'&4 V V6( † >KK('&4 ('&4 V V(6 ‡ 70 +>70 ,$%&'6 ,$%&'627G(D 27G(D R>19 >191D19D 9%J0 %J0 59%: %:
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% ~# ‚~
?GGD V V } Š >&4'EE4 ?GGD 'EE4 ,ˆirewalls ,ˆirewalls ˆirewall ,>&4'EE4 'EE4 ;'&; V V '&;'L1; 'L1;'GD V V 'GDJ0 J08%/&6 %8 /&6?K ?K'L$6 'L$6(&F??&; (&F??&;'C9 'C9%: %: ,Network 5%$$%&; V V 5%$$%&;'%&G6 '%&G6 V V>K >K GD V VGD$?) $ ?)$&) $&)$5%$ $5%$ 0GD V VGD >19>70 >70&6&?'() ?6 '()*%+ *%+ =7:>&4'EE4 'EE45FK 5FK(+6 (+6$8 $8%/(7$Z$]4 %/(7$Z$]4 ,rule ,rule J($%&?)1$%&G&%v 1$%&G&%v$ ,traffice C0 %ƒ''$ %ƒ''$ /&;' ?)1$%&&6 1$%&&6?ƒ9 ?ƒ9LC0 LC0'1 '1EJ(&F??&; EJ(&F??&;'C9 'C9%: %:
G8%%1& %%1& 0565$$6 $6 $6?>&4 ?>&4'EE4 'EE4?( ?( `outerBOA`\ •
•
•
•
$%&K'L$6 'L$6( ,Protect %1%&K 'L$6 'L$6(C0 (C0'1EGD V V EGD1D1D$%&&6 $%&&6?/&; ?/&;'9 '9L9 L9%(&F??&; %(&F??&;'C9 'C9%: %: =7:$%&$8%/(7K %/(7K($Z$]4 ($Z$]4 /&;' rule 8%/&6 %/&6?J0 ?J0?6?6L6 L6?$%&; V V ?$%&;'%&%:J(&; '%&%:J(&;'C9 'C9%: %: ,C0'1 '1EGD V EGD V1$%&&6 $D %&&6?9 ?9L%:J( L%:J( /&;'%:('$&F??&; '%:('$&F??&;'C9 'C9%: %: &%5F&D:$9 :$9%<2$ %<2$5 /&;' !ackae $Z$]4 ,`ule ,`ule Base %1%&&0 %LC0 %LC0'$8 '$8%/(7J($%&?) %/(7J($%&?)1$%&&6 1$%&&6?ƒ9 ?ƒ9LC0 LC0'1 '1E%:J(&F??&; E%:J(&F??&;'C9 'C9%: %: =7:5F +0'L1D 'L1D$%&$8 $%&$8%/(7$Z$]4 %/(7$Z$]4J($%&?) J($%&?)1J(&F??&; 1J(&F??&;'C9 'C9%:Cm %:Cm R( ?)1$%&C0 1$%&C0%m %mL ,Access {ontrol %1%&?) 1>70 1>70mmL&F76 L&F76?$%&C0 ?$%&C0%m %mL$%&&6 L$%&&6?ƒ9 ?ƒ9LC0 LC0'1 '1E K(G6 (G6 RL Packet ˆilterin ˆilterin
=7:>&4'EE4 'EE4?( ?( `outerBOA`\ K (G=(=E:D (G=(=E:DK&FG$&'L<2$$ K&FG$&'L<2$$+ ,Packet ˆilterin Qm LJ0 V VLJ0='2(Q'&4Q'+4 Q'+4<&4 <&4 ':9%L %L Netˆilter ?(E3 ()($Q4 $) Q4 ,i!taxles J(E3 ()($Q4 $) Q4 =7:5F'?+&5'?C0'1 '1EJ(<2$$ EJ(<2$$+9 +9(C'Lg77'&4 (C'Lg77'&4 ,header J( $%&(8%1%K&D %1%K&D:?GD :?GD:?$6 :?$6?$Z ?$Z ,rules GD V VGD>70 >70$8$%/(7'%>0 %8 /(7'%>0 =7:C0 =7:C0'1 '1EJ(9 EJ(9(g77'&4 (g77'&4C'L<2$$ C'L<2$$+5%$(6 +5%$(6 R(5FG8%$%&>19 %$%&>19 '()*%+ *%+ ,7&'K 'K <2$$+(6 +(6 R(/&;'9 '9%'() %'()*%+ *%+ ,acce!t J/0<2$$ <2$$+9 +9%(>K>70 %(>K>70 `outerBOA`\ K(&%G4 (&%G4+'&4 +'&4GD VG V1D %1%1%&J($%&G8 D %1%1%&J($%&G8% Packet ˆilterin ': 9 9'2D <'77& +0(G%LƒKE%:G%L_ (G%LƒKE%:G%L_ (37=K&=+'E 7=K&=+'E ,T{P_ U\P 9(&F76 (&F76?6 ?6(G&%(K'&4+E:'&4 +E:'&4 5F1D<'+G&3 <'+G&3?3?3+4 +4GD V VGD8%6 %8 6* 9( 2'&4++0 ++0(G%LƒKE%:G%L_ (G%LƒKE%:G%L_ <E$ ,fla 1D2%FJ(g77'&4 2%FJ(g77'&4C'L<2$$ C'L<2$$+ T{P KJ(9 %>KJ(9(C'L (C'L Packet ˆilterin =7:$%&23 5%&]%9%5F:'1 %5F:'1 ,acce!t J/0<2$$ <2$$+9 +9%(>K(6 %(>K(6 R( 70 >705%$<2$$ 5%$<2$$+$9 +$9'(/(0 '(/(0%GD V V %GDG8G%$%&?6 8%$%&?6(Gm (Gm$>0 $>0 (8 (8%1%23 %1%235%&]% 5%&]% 5mLG8 LG8%J/0 %J/0%1%& %1%& &F?)>70 >709%<2$$ %9 <2$$+J7K +J7K(<25GD V V (<25GD+3+7+9 73 +9'C0 'C0%1%J/19 %1%J/19 /&;'9 '9%K %K(9 (9(/(m V V (/(mLC'L$%&; V V LC'L$%&;'1+9 '1+9'GD V V 'GD1D1': 9 9 'D :
Note" $%&5FK'L$6 Note" $%&5FK 'L$6($%&?) ($%&?)$&) $&)$GD V V $GD$3 $37Cm 7Cm R(5%$&; (5%$&;'C9 'C9%:>70 %:>707D7D 3 V V 3LGD V V LGD8%6 %8 6*+9 *+9'>&4 '>&4'EE4 'EE4J/0 J/0G8G%L%(>70 8%L%(>70':9 ':9%L1D %L1DK&F3 K&F3G[3 G[3%2 %2 $;'; $%&$8%/(7=2ED %/(7=2EDQDQ$%&&6 $D %&&6$b%%1KE'76 $b%%1KE'76:GD V V :GD$+0 $ +0'L&4 %/(7$ZC'L>&4'EE4 'EE4 >70'7E0 '7E0'L19 'L191D1DC0C'3 '0 372E%7 72E%7 Note" &F76?6 Note" &F76 ?6 R(G&%(K'&4 (G&%(K'&4+E:'&4 +E:'&4(6( R6(G6 (G6 RL2'&4 L2'&4+ T{P '2D >D '2D<'77& +0(G%L (G%L zzz.zzz.zzz.zzz ,IP s!oofin 9 %(&%G4 %(&%G4+'&4 +'&4C0 C0%1%J(&; %1%J(&;'C9 'C9%:%:J( %:%:J(
&?0 :'F>&?0%L‹ %L‹ =7:8%(3 %(3:%1C'L>&4 :%1C'L>&4'EE4 'EE4&4 >&4'EE4 'EE4K K(&; V V (&;'L1; 'L1;'2; '2; R(%(J($%&567$%&G&%v 7$%&G&%v$GD V V $GDKE'76 KE'76: ,ood fraffice GD :'1J/0 V V:'1J/0 9%(&F?? %(&F?? 19 >19KE'76 KE'76: ,xad traffe G6 RLGD V V LGD>K:6 >K:6L>&4 L>&4'EE4 'EE4C'L&% C'L&% ,to E4'EE4 'EE4C'L C'L &% ,fro /&;'GD V V 'GD9%(>&4 %9 (>&4'EE4 'EE4C'L&% C'L&% ,throuh ˆirewall (6 R(58 (58%K %K(+0 (+0'L1D 'L1D$Z2; V V $Z2;'58 '58%$6 %$67G&%v 7G&%v$ ,traffice flow /&; '?) '?)1$%&&6 1$%&&6?ƒ9 ?ƒ9LC0 LC0'1 '1EJ(&; EJ(&;'C9 'C9%: %: =7:GD V V =7:GD$Z/E9 $Z/E9%(D %(D R5F 5F $56 $567': 9 9 7':J( J( {hain Qm V VQmL5FG8 L5FG8%/(0 %/(0%GD V V %GD$&'L<2 $&'L<2$5 $5 =7: {hain $ 5FK&F$'?>K70 5FK&F$'?>K70: : INPUT {hain_ OUPUT {hain &4 :%1>&4'EE4 'EE4>KK&?0 %L>&?0%L %L & %L>&
ueue
ˆilter ueue Nat ueue Manle ueue
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% ~W# ‚~
ˆilter ueue 5F1D {hain ': †9 9 † {hain {hain J($%&5 J($%&5667$%&$6 7$%&$6?<2 ?<2$5Qm V V $5QmLK&F$'?70 LK&F$'?70: : INPUT {hain_ OUTPUT OUTPUT {hain {hain &4 %1%/%>&4'EE4 'EE4 ,GD V V ,GD(D V V(;D '; MikroTik /&;''%55FJ0 ''%55FJ0 8%9 %9%<2 %<2$5C%C0 $5C%C0% +9'1%K '1%K( OUTPUT {hain 5FG8 %/(0 %/(0%GD V V %GD$&'L<2 $&'L<2$5GD V V $5GD$9 $9L9 L9%(&; V V %(&;'L>&4 'L>&4'EE4 'EE4 ,MikroTik ,MikroTik /&;' &D:$9 :$9%<2 %<2$C%''$ $C%''$ '2D '2D <'77& '2D '2D<'7 <'7 <7&&4 L=7:>&4'EE4 'EE4'L 'L Manle ueue 5FK&F$'?70 : : X {hain 8%/&6 %/&6?G8 ?G8%/(0 %/(0%GD V V %GDJ($%&K&6 J($%&K&6?<+9 ?<+9L9 L9% oS ,uolity of Serice J(?3 +C'L +C'L T{P <2$5 $5 3(D (D R
+6':9 ':9%L %L $%&&0%L>&4 %L>&4'EE4 'EE4v++'&4 +v +'&4 ,ˆirewall filter rule +6':9 ':9%L %L $%&&0%L$Z>&4 %L$Z>&4'EE4 'EE4J( J( INPUT chain 1.
=7:Kv7=K&<$&1 7=K&<$&1 qinBoz ’ IP IP ’ ’ ˆirewall ˆirewall 76 76L& L&K
2.
E3$&; V V $&;'L/1%: 'L/1%: 1
3.
5%$1(?%&4 ?%&4707%(?(5F/ %0 (?(5F/(9% MikroTik `outerBOA`\ >70 5657&D 76 &D:L1( :L1(1%J/0 1%J/0L9L9%:+9 %:+9'$%&&D '$%&&D:$J0 :$J0L%( L%( =7:<:$ ''$K(3 (3+9 +9%L %L ˆilter `ules_ NAT_ Manel_ Serice Ports_ {onnections_ Address -ists_ -ayer‚ Protocols ,%1%&$&'L<'2 , %1%&$&'L<'2E3E36 6 V(>70 5%$(6 R(J/0E; E;'$ '$ {hain K( INPUT {hain 76L& L&K70 K70%(E9 %(E9%L(D %L(D R
5%$E3+4 +4 {hain {hain 5F1D1%$$9 1%$$9%GD V V %GD:$E9 :$E9%>KC0 %>KC0%L %L ,forward_ in!ut &4 >&4'EE4 'EE4J(9 J(9(C'LQ'&4 (C'LQ'&433 HotS!ot 4.
$8%/(7 %/(7 action +673 73(J59 (J59%5F %5F acce!t /&;' 7&'K 'K <2$5 $5 E3$GD V V $GD
$Z70%(?((D %(?((D RK K($%&'() ($%&'()*%+<2 *%+<2$5 $5 ;''()*%+J/0 *%+J/0=g+4 =g+44>'2D >4 '2D<'77& <'77& pW.~}.}}.#W‡ ,-AN network 9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% ~‡# ‚~
%1%&C0%m %mLG) LG)$Q'&4 $Q'&43?(&%G4 3 ?(&%G4+'&4 +'&4>70 >70 ,MikroTik ,MikroTik +6':9 ':9%L9 %L9( 5%$ -AN -AN network network &%G)$&; V V $&;'L>E' 'L>E'(+45F 5F %1%&J0 SSH_ SSH_ qinBoz_ ˆTP /&; ' HTTP C0%m %mL&%G4 L&%G4+'&4 +'&4>70 >70
$Z(D R5F>19 5F>19'() '()*%+3 *%+3<2 <2$5; $5;'>19'() '()*%+J/0 *%+J/0=g+4 =g+44>'2D >4 '2D<'77& <'77& pW.~}.}}.#W‡ ,-AN network C0 %m %mLG) LG)$Q'&4 $Q'&43?( 3 ?( &%G4+'&4 +'&4>70 >70 ,MikroTik ,MikroTik +6':9 ':9%L9 %L9( &; V V &;'L 'L la!t la!to! o! /&;' !c &%J( -AN (+3 +3&4&$5F>19 $4 5F>19%1%&J0 %1%&J0 SSH_ SSH_ qinBoz_ ˆTP /&;' HTTP C0%m %mL&%G4 L&%G4+'&4 +'&4>70 >70 19 19%1%&C0 %1%&C0%m %mL&%G4 L&%G4+'&4 +'&4>70 >705%$&; 5%$&;'C9 'C9%:%:('$ %:%:('$ ,outside /&; '$%& '$%& !in <2$5 $5 5%$ !uxlic '3 ( G'&4(+&%G4 +&%G4+'&45F>19 5F>19+'?$E6 +'?$E6?9 ?9($6 ($6( 76L(6 L(6 R(J($%&&3 V V (J($%&&31&0 1&0%L$Z5m %L$Z5mL58 L58%K %K(+0 (+0'L 'L acce!tj <2$5J/0 $5J/0$6$?6 -AN (+3 +3&4&$&%$9 $4 &%$9'( '( /&;''%5$8 ''%5$8%/(7C'?C+$%&C0 %/(7C'?C+$%&C0% mL&%G4 L&%G4+'&4 +'&4=7:$%&'() =7:$%&'()*%+2%F$E) 9 9 *%+2%F$E)1 IT rou! '2D (>'2D<'77& <'77& pW.~}.}}. ,IT rou! %1%&C0 %mL&%G4 L&%G4+'&4 +'&4>70 >709%($%&; V V %9 ($%&;'170 '170:=K&=+'E :=K&=+'E SSH 70 %L%(>70+%1K$+3 +%1K$+3 <+9¡ >&4'EE4 'EE45F9 5F9LQ'&4 LQ'&433 '; V V ';( ( J/0$6$?&%G4 6?&%G4+'&4| ¢ ¢|L -AN (+3 +3&4&$4 9( $%&J0 \NS \NS < Qm V VQmLK LK( (5'&4 5'&4?( ?( `outerOS J($%&G8 %/(0 %/(0%GD V V %GD>K >K 0(/%C0 (/%C0'1E ,recursion 5%$ \NS Q3 &4&4'&4 '&4&; V V &;'L'; V V 'L';( ( GD V VGD': 9 9 ':?('3 ?('3(G'&4 (G'&4( (+ 5($9%5F>70 %5F>70&6&?8 ?6 8%+'?9 %+'?9%; V V %;'GD V V 'GD >E'(+4 (+4%11%(6 %11%(6 R(1D (1D>'2D >'2D<'77&K <'77&K('F>& ('F>& C0'&&F6 '&&F6L"L" $Z>&4'EE4 'EE4?( ?( `outerOS 5FG8%L%(5%$?(ELE9 %L%(5%$?(ELE9%L %L 76L(6 L(6 R(5m (5mL+0 L+0'L 'L acce! acce!tt <2$5$9 $5$9'(GD V V '(GD5F 5F 7&'K 'K <2$51' $51' $ZGD V V $ZGD$8$8%/(7m %/(7mL5FG8 L5FG8%L%(+%1GD V V %L%(+%1GD%7>0 %7>0&6 &6?
>&4'EE4 'EE4&4 '9 1%C'L>&4'EE4 'EE4E:$ E:$99%>70 %>70&6 &6? $%&; V V $%&;'%&J(&F??&; '%&J(&F??&;'C9 'C9%:5F78 %:5F78%(3 %(3($%&+37+9 7+9'; ';'%&=7:J0 '%&=7:J0 2'&4+ ')K$&]4 K$&]4G9D V VD 9L<2 L<2$59 $59%(2'&4 %(2'&4+''$1%(6 +''$1%(6 R(&%5F&D (&%5F&D:$9 :$9% 2'&4++0 ++0(G%L (G%L ,source !ort
new ,:6L>19 L>191D1D$%&; V V $%&;'1+9 '1+9' ' G)$&6 $&6 RLGD V V LGD&%G4 &%G4+'&4 +'&49L<2 L9 <2$5>K:6 $5>K:6L=g+4 L=g+4+4+ &3 V V 4 &31<&$5F1D 1<&$5F1D<2 <2$59 $59L1%C'$%&; V V L1%C'$%&;'1+9 '1+9'J/19 'J/19 ,new ,new connection =7:K$+3 $$5FK 5 FK( T{P GD V VGD1D1D SYN SYN %($% %($%&]4 &]4+6+':9 6 ':9%L9 %L9( &%$8%/(7$%&; V %/(7$%&; V'1+9'J/19 'J/19CmC R(=7:&F?) m(=7:&F?) +0 +0(G%L (G%L ,source # KE%:G%L ,destination # 2'&4+ 2'&4 + ,!ort &1$6($ ($5F$3 5F$37K 7K(%2&1$%&; V V (%2&1$%&;'%&J/19 '%&J/19GD V VG:6:D 6L>19 L>19:+3 :+37+9 7+9'; V V ';'%& '%& 1%$9'( '( Note" :9'J/0 'J/077C0 C0%J5L9 %J5L9%: %: Source IP address ,src " /1%:EC>'2D 09 LC0 L9 C0'1 '1E \estination IP address ,dst " /1%:EC>'2D C'L C'L 0&6&?C0 ?6 C0'1 '1E Source Port Nuxer ,src !ort " /1%:EC2'&4++0 ++0(G%LGD V V (G%LGD9L7%+0 L9 7%+0%<$&1(D %<$&1(D R \estination Port Nuxer ,dst !ort " /1%:EC2'&4+KE%:G%LGD V V +KE%:G%LGD5FK 5FK( ( 0&6&?7%+0 ?6 7%+0%<$&1 %<$&1 /E6L5%$$%&; V V L5%$$%&;'1+9 '1+9'J/19 'J/192%F$%&; V V 2%F$%&;'1+9 '1+9'GD V V 'GD&3 V V&31Cm 1Cm R( ,initiated 70 ?%:>70;;'$%&9 '$%&9L<2 L<2$5GD V V $5GD>19 >19$+0 $ +0'L 'L ,inalid 76L(6 L(6 R(<2 (<2$5GD V V $5GD>19 >19$+0 $ +0'L5m 'L5mLK LK(3 V V (3L/(m V V L/(mLGD V V LGD>19 >19>70 >70': 9 9 ':J($%&; V V J($%&;'1+9 '1+9'J7 'J7 <+9>19 >191D1$%&&0 $D %&&0%L$%&; V V %L$%&;'1+9 '1+9'J/19 'J/19 =7:&) =7:&)K inalid inalid !acket !acket ;'<2 '<2$5GD V V $5GD>19 >19K K(K&F=:(4 (K&F=:(47676L(6 L(6 R($ ($&GD V V &GD5F 5F 7&'K 'K <2$5 $5 (6 R( 3 V V3L/E9 L/E9%(D %(D R%1%&&0 %1%&&0%LCm %LCm R(>70=7:Q'+4 =7:Q'+4<&4 <&4GD V VG1) 9 9D1L2:%:%15%F&F??&; L) 2:%:%15%F&F??&;'C9 'C9%:C'L&% %:C'L&% 23 V 23 V1+31J($%&; V V 1J($%&;'1+9 '1+9'J/19 'J/19 ,new connection 19 '>191D1D$%&9 $%&9L C0'1 '1E'D E'D$70 %J5>70L9L9%:GD V V %:GD)78 7) 8%/&6 %/&6?$%&; V V ?$%&;'1+9 '1+9' related connection 16 ($ ($;'; $%&; V V $%&;'1+9 '1+9'GD V V 'GD$&0 $ &0%LCm %LCm R(=7:$%& ; V V ;'1+9 '1+9'GD V V 'GD1D1D': 9 9 ':19 J0 J09(/(m V V 9 (/(mLC'L$%&; V V LC'L$%&;'1+9 '1+9' estaxlished GD V VGD 1?&]4 &]4
G8%%1C0 %%1C0%J5$Z$%&; V V %J5$Z$%&;'1+9 '1+9'J(>&4 'J(>&4'EE4 'EE4 1.
2.
3.
New connect connection ion $%&; $%&; V V'1+9 '1+9'5F$3 '5F$37Cm 7Cm R(J/19 (J/19$$+9+'1; V V '9 1;'1D '1D$%&$8 $%&$8%/(7 %/(7 src # dst # !ort !ort &91J($%&; V V 1J($%&;'%&J(E% '%&J(E% 7D: : staxlished connection $3 7$%&; V V 7$%&;'1+9 '1+9'<2 '<2$5GD V V $5GD1? 1?&]4 &]419J9 J9$%&Kv $%&Kv7$%&; V V 7$%&;'1+9 '1+9'J/19 'J/19 `elated connection >19 %1%&$3 %1%&$37$%&&0 7$%&&0%L$%&; V V %L$%&;'1+9 '1+9'GD V 'GD V1D%16 %16126 126([4 ([4+9+'(; V V '9 (;'L$6 'L$6( 0(<+9 (<+95FK 5FK(&3 V (&3 V1<&$ C'L$%&; V V C'L$%&;'1+9 '1+9'J/19 'J/19
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% ~~# ‚~
GD V VGD9%1%(D %9 1%(D R775%$+%&%L70 5%$+%&%L70%(E9 %(E9%L(D %L(D R ,/(0%6 %67>K 7>K 5F>70C0 C0%J5:3 V V %J5:3LCm LCm R(&6 (&6? ?ire:899 @o((eAtio(>6
5%$<(%270%(%1%&'[3 %(%1%&'[3?%:$%&; V V ?%:$%&;'1+9 '1+9'>70 '>707676L(D L(D R 1$%&;'1+9 '1+9'70 '70:$%&9 :$%&9L<2 L<2$5Kv $5Kv7$%&; V V 7$%&;'1+9 '1+9' ,new connection connection K&; V V :L>K&;': ': ':7D7D =E91%2; V V 1%2;'C'; V V 'C';'1+9 '1+9' ,inalid connection GD V V>19 >191D1 SYN_ D SYN_ SYN A{‘ 5(67>K1D 7>K1D$%&9 $%&9L<2 L<2$51%C' $51%C' บรรทัดท บรรทัดท &' &' ': 9 9 ; V V ;'1+9 '1+9' new connection 19 >19$+0 $+0'L 'L ,inalid connection 0% 0 %
%1%&%77%>709%%(F$%&; V V %9 %(F$%&;'1+9 '1+9'6 '67>KK 7>KK(':9 (':9%L>& %L>& 0%+'?>70 %+'?>709%9 new connection <7L9 %&%C0 %&%C0%J5$%&; V V %J5$%&;'1+9 '1+9'
Note" $%&; Note" $%&; V V'1+9 '1+9'GD V V 'GD1 1?&]4 ?&]4 ; ;' $%&GD V V $%&GD 09 L%1%&9 L9 %1%&9LC0 LC0'1 '1Em EmL L 0&6&6?>70 ?>70':9 ':9%L %L$+0 $+0'L&?0 'L&?0(1? (1?&]4 &]4 Note" <E$ ,ˆla K (C0 (C0'1 '1E&F76 E&F76??3 ??3+GD V V +GD': 9 9 ':J(g77'&4 J(g77'&4 T{P T{P =7:J =7:J00K K(+6 (+6?'$) ?'$)]1?6 ]1?6+3+3C'L<2 C'L<2$5 $5 T{P C]F (6 R( ( 70 L>70767L(D L6 (D R Ty!e \escri!tion U`„ J?'$%1/1%:9 0?'$%1/1%:9 %K %K(C0 (C0'1 '1E79 E79( ( 70 L%(>70 \SH K($%&<50 ($%&<50LJ/0 LJ/0 0&6&?C0 ?6 C0'1 '1EG&%?9 EG&%?9%&5F9 %&5F9LC0 LC0'1 '1E Seent (D R>K:6 >K:6L A!!lication GD V V$8$%E6 %8 E6L&'': 9 9 L&'':=7:& =7:& `ST :$E3$$%&+3 $$%&+37+9 7+9' ,`eset (; V V (;'L5%$J($&]D 'L5%$J($&]DGD V VG$3 D$37$%&6 7$%&6?(Cm ?(Cm R(70 (70:/+) :/+)E+9 E+9%L %L 9(=g+4 (=g+4+4+41D1KKD */% */% J/0 &3 V V&31; V V 1;'%&J/19 '%&J/19 SYN J0J($%&&3 V V J($%&&31+0 1+0(C'+3 (C'+37+9 7+9'$6 '$6?KE%:G%L ?KE%:G%L ˆIN J09L2; V V L9 2;'<50 '<50LJ/0 LJ/0KE%:G%LG&%?9 KE%:G%LG&%?9%:) %:)+3+$%&+3 $3 %&+37+9 7+9'
Two qays To {ontrol Access 'L3[D[J($%&?) DJ($%&?)1$%&C0 1$%&C0%m %mL J( In!ut {hain ว#$$*ร+ '$%&$&'L<2$5GD V V $5GDC0 C0%1%:6 %1%:6L&%G4 L&%G4+'&4 +'&4 0 0%9 %9%(+6 %(+6v vE+'&4 E+'&4$$ *ร+ ;'$%&$&'L<2 '()*%+&6 *%+&6?<2 ?<2$5(6 $5(6 R( <+90%9 %0 9%(v %(vE+'&4 E+'&41%>19 1%>19>70 >70$$J/0 J /0 7& 7&'K 'K <2$5(6 $5(6 R( ว#$$ททสอง สอง ;'$%&v '$%&vE+'&4 E+'&4$%&; V $%&; V'1+9'GD V V 'GD1D1&0 D &0%L$%&; V V %L$%&;'1+9 '1+9' /%$$%&; V V /%$$%&;'1+9 '1+9'1D '1D$%&&0 $%&&0%L %L state J/0'() '()*%+ *%+ <+90%$%&; V V %0 $%&;'1 '1 +9'%(FK '%(FK( inalid state $ J/0 J/0 7& 7&'K 'K <2$5 $5 i!taxles 5F>19 +0+0'L&0 'L&0%L %L connection trackin 0%>19 0 %>191D1 connection D connection J( eory $Q+K Q+K( inalid ,5F>70 >19 >19+0+'L&0 '0 L&0%L %L state Cm R(1% (9%5F2'C0 %5F2'C0%J5m %J5mL/E6 L/E6$$%&G8 $$%&G8%L%(C'L>E4 %L%(C'L>E4'EE4 'EE4?( ?( `outerOS $6(70C0 C0%J5$%&G8 %J5$%&G8%L%(23 V V %L%(2311%$Cm 11%$Cm R( +6':9 ':9%L %L $ZC0'<&$; '<&$;''() ''()*%+G&%v$G6 $G6 RL/175%$&; L/175%$&;'C9 'C9%: %: -AN 70 &6&?$%&+'?$E6 ?6 $%&+'?$E6? <+90%1D %0 1D$%& $%& !in 5%$ &;'C9 'C9%: %: qAN C0%1%:6 %1%:6L MikroTik `outer 5FCm R( tie out 1 %>1 J(1; V V J(1;':6 ':6L>19 L>19>70 >70&0 &0%L$Z %L$Z 58%$6 %$675%$$%&G8 75%$$%&G8%>&GD V V %>&GD$D V V $D:$6 :$6?&%G4 ?&%G4+'&4 +'&4 8 8%+'?$ %+'?$;'; mL<10 L<109%&%G4 %9 &%G4+'&4 +'&45F&0%LK:6L=g+4 L=g+4 <+9 <+9 9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% ~}# ‚~
(6 R(K (K(2&%F9 (2&%F9%&%G8 %&%G8%$%& %$%& xlock J(9(C'L (C'L in!ut chain ,$ZC0 'GD V V 'GD'L 'L Qm V VQmLK LK(EJ/0 (EJ/0&%G4 &%G4+'&4>19 >19 0&&565 $=g+4 $6 =g+4GD V VGD9L<2 L9 <2$5 $5 +'?$E6?1% ?1% 76L(6 L(6 R(5mL 7&'K 'K 16( J($%&<$0>CK >CK*/%(D */%(D R$$;'J/0 '; J/0&0 &0%L$ZJ/19 %L$ZJ/19K K( acce!t rule <2 $5 $5 !in 5%$| ¢ ¢ 5%$|LC% LC% qAN =g+4 2; V V 2;'GD V V 'GD+0+'L$%&J/0 '0 L$%&J/0 !in !in 5%$&%G4+'&4 +'&4&%>70 &%>70 =7:+6 =7:+6E; E;'$$ '$$;'$%&'() '; $%&'()*%+<2 *%+<2$5 $5 I{MP =K&=+'E ,Internet {ontrol Messae Protocol 5%$G) $ =g+4 <+9 <+9(D V V(>19 D>19J0 J0QQ=E6 =E6 V V(GD V V (GDKE'76 KE'76: &&0%L$Z'() %L$Z'()*%+2%F *%+2%F qAN =g+4GD V VGD+0+'L$%&5FKE'76 0'L$%&5FKE'76:$9 :$9%&6 %&6? 5%$+6':9 ':9%LGD V %LGD V $;'$ZC0 '; $ZC0'GD V V 'GD/(m V V /(mL&%'() L&%'()*%+<2 *%+<2$55%$ $55%$ -AN 1%:6L&%G4 L&%G4+'&4 +'&4 70 >70 ,`outerOS ,`outerOS 0%&% %&% &D=1G9 =1G9%( %( Telnet /&;' SSH >K:6L&%G4 L&%G4+'&4 +'&4&%%1%&J0 &%%1%&J088%6 %6 V VL !in ?(&%G4+'&4 +'&4>70 >70 76L(6 L(6 R(E&) (E&)K; K;'&%+0 '&%+0'L&0 'L&0%L$Z %L$Z in!ut chain ':9 %L(0 %L(0': ': ‡ C0'(D '(D R in!ut in!ut firewall m L5F1? L5F1?&]4 &]4
ˆorward {hain /E6L5%$GD V V L5%$GDG8G%%1C0 8%%1C0%J5$D V V %J5$D:$6 :$6? in!ut chain J($%&K 'L$6 'L$6(KKE'(+4J(&; J(&;'C9 'C9%:&% %:&% ˆorward {hain ; '<2 '<2GD V V GD3 V VLC0 L3 C0%ƒ''$9 %ƒ''$9%(>E4 %(>E4'EE4 'EE4&%G4 &%G4+'&4 +'&4 J(GD V J(GD V( RD;'; MikroTik `outer ,<2 $53 V V $53L -AN netw network ork qAN /&;' qAN -AN network $%&&0%L$Z %L$Z forward chain $ +0+0'L1; V V 'L1;' MikroTik MikroTik `outer `outer &%G8 &%G8%/(0 %/(0%GD V V %GDK K( „ateway →
→
+6':9 ':9%L" %L" $ZC0'<&$ '<&$ ,first rule J( forward chain ; ''() ''()*%+>E'(+4 *%+>E'(+4J( J( -AN 1D$%&&0 $%&&0%L %L connection state K ( new connection 9 %(>E4 %(>E4'EE4 'EE4 =7:&3 V V =7:&31+0 1+0(+6 (+6 RL<+9 L<+9 new new connection =7:J(+6':9 ':9%L(D %L(D R5F&F?) 5F&F?) source source address C'L<2 $5GD V V $5GD atch $6? firewall rule $ZC0 '<&$(D '<&$(D R5F58 5F58%$6 %$672%F<2 72%F<2$5GD V $5GD V atch GD V VGD3 V VLC0 L3 C0%1%5%$| ¢ ¢ %1%5%$|LC% LC% -AN :$+6':9 ':9%L %L -AN network K( pW.~}.}}.#W‡ Kv 7=K&<$&1 7=K&<$&1 qinBoz >KGD V V >KGD1( 1( B0 ’ ?ire:899 ’ E3$K) $K)1 Add , 1 GD VGD V
(D R;''() '; '()*%+$%&; V V *%+$%&;'1+9 '1+9'2%F>'2D '2%F>'2D<'77&+0 <'77&+0(G%LGD V V (G%LGD1%5%$ 1%5%$ -AN G9%(6 %(6 R( 0%K %K(=g+4 (=g+45%$| ¢ ¢ 5%$|L qAN >E4'EE4 'EE4C'L&% C'L&% 5F>19'() '()*%+J/0C'Kv7$%&; V V 7$%&;'1+9 '1+9' $ZC0'6 '671%5F'() 71%5F'()*%+ *%+ related connection $Z(D RK K(K (K(2D (2D:LC0 :LC0'58 '58%$6 %$67:9 7:9':(; V V ':(;'L5%$&%1D 'L5%$&%1D$%&?) $%&?)1GD V 1GD V new connection ': 9 9 ':
5%$(6 R(&0%L$ZC0 %L$ZC0'GD V V 'GD%1=7:E0 %1=7:E0%:$6 %:$6?$ZC0 ?$ZC0'GD V V 'GD'L 'L =7:C0'GD V V 'GD%15FK %15FK($%&'() ($%&'()*%+ estaxlished connection
$ZC0') ')7G0 7G0%:GD V %:GD V5FG8%J/0 %J/0 forward forward chain 1? &]4 &]4GD V VGD)7$ 7) $;;' 7&'K 'K inalid connection =7:E%$ ,dra $ZC0 '(D RJ/0 J/0>K': 9 9 >K': ?&&G67<&$ 7<&$
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% ‚# ‚~
E8%76 %76?C'L$Z ?C'L$Z
Address -ists )7G0 7G0%:GD V %:GD V5F$E9%m %mLJ(9 LJ(9(C'L>E4 (C'L>E4'EE4 'EE4$$; '<'77&E3 ;'<'77&E3+4 +4 K K($%&+6 ($%&+6 RL; V V L;'E3 'E3+4 +4=7:5F'0 =7:5F'0%L'3 %L'35$6 5$6?>'2D ?>'2D<'77&GD V V <'77&GD&F?) &F?) =7: Addres Addresss -ist 58%K %K(J($%&9L<:$$Z16 L<:$$Z16(%1%&9 (%1%&9L$%&?) L$%&?)1>70 1>70 9 9( 8%/&6 %/&6?<+9 ?<+9EF>'2D EF>'2D<'77&_ <'77&_ 8%/&6 %/&6? rane 70 0'L$%&>70 2; V V 2;'GD V V 'GD9%$Z7D %9 $Z7D:%1%&(8 :%1%&(8%>KJ0 %>KJ0$6$6? /E%: $E) 9 9 $E)1J( 1J( IP adress /&;'J( 'J( Suxnet $%&&D:$J0 :$J0L%( L%( 9( +6 RL; V V L;'L9 'L9% -ocal-an 1D <'77&K <'77&K( pW.~}.}}.#W‡ 5%$(6 R(J($%&&D:$J0 :$J0J(9 J(9(C'L$Z (C'L$Z GD V VGD'2D<'77&L <'77&L pW.~}.}}.#W‡ pW.~}.}}.#W‡ Note" 2; R(%($%&'(v Note" 2; (%($%&'(v$>E'EE4 $>E'EE4 ':9 ':9%L(0 %L(0':+0 ':+0'L1D 'L1D$Z$]4 $Z$]4': 9 9 ':'L$E) 9 9 'L$E)1(6 1(6 R(; (;'$ZJ( '$ZJ( in!ut chain J($%&K 'L 'L $6(&%G4 (&%G4+'&4 +'&4 E'(+4 L>E'(+4J(&; J(&;'C9 'C9%: %: -AN C'L&%
+6':9 ':9%L %L $%&'(v$>'EE4 $>'EE4C6C R6(2; (2; R(%( (%( +6':9 ':9%L(D %L(D R11+3 11+39%9 -AN &;'C9 'C9%:&%1D %:&%1D>'2D >'2D<'77&K( pW.~}..#W‡
1.
2.
3.
Kv7=K&<$&1 7=K&<$&1 qinBoz E3$GD V V $GD IP IP ’ ’ ˆirewall
E3$GD V V $GD
E3$1( $1( IP IP ’ ’ ˆirewall ˆirewall ’ ’ E3$GD V V $GD
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% ‚W# ‚~
$ZC0'GD V 'GD V W" E3 W" E3$E; $E;'$ '$ chain K( forwardj_ connection state $8%/(7K $8 %/(7K( inalidj
G6 RL'L$ZGD V V L'L$ZGD&%&0 &%&0%LCm %LCm R(5F dro! $%&; V V $%&;'1+9 '1+9'1%:6 '1%:6L&%G4 L&%G4+'&4 +'&4GD V VGK D K( inalid connection on $ZC0'GD V 'GD V †" E3 †" E3$ Ž Ž 2; V V 2;'&0 '&0%L$ZJ/19 %L$ZJ/19 GD V VGD chain chain E;'$ '$ in!utj GD VGD V70 &%>70&0 &0%L>0 %L>0$9$'(/(0 '9 (/(0%(D %(D R
$ZC0'(D '(D R5F'() 5F'()*%+J/0 *%+J/0G)G)$ $ 0J0 J0?( ?( -AN %1%&C0 %m %mL&%G4 L&%G4+'&4 +'&4>70 >70 &%%1%&58 &%%1%&58%$6 %$67$%&C0 7$%&C0%m %mL23 V V L231+3 1+31>70 1>700%0 +0'L$%& 'L$%& $ZC0'GD V V 'GD ‡" E3 ‡" E3$ Ž 2; V 2; V'&0%L$ZJ/19 %L$ZJ/19_ GD V VGD chain chain E;'$ '$ in!utj GD V VGDv74 v 74 {onnection {onnection State E; '$K '$K( estaxlishedj 70 ;(>70 9( =g+4>E' >E'(+4J0 J0Q'&433 !in /&;' telnet +37+9 7+9'$6 '$6?&%G4 ?&%G4+'&4 +'&4
$ZC0'GD V V 'GD X" E3 X" E3$ Ž Ž 2; V 2; V'&0%L$ZJ/19 %L$ZJ/19_ 8%/&6 %/&6?$%&&0 ?$%&&0%L %L rule (D R <(F(8 <(F(8%J/0 %J/0G8G%J( %8 J( Safe Mode /%$3 72E%7$%& 72E%7$%& ; V V ;'1+9 '1+9'>K:6 '>K:6L&%G4 L&%G4+'&4 +'&45F 5F$+6 $+67G6 7G6(GD (GD ,disconnect ,disconnect GD V VGD chain chain E;'$ '$ in!utj _ GD VGD V
/(0% ‚‡# ‚~
(D R;'$ZGD V V '; $ZGD5F 5F dro! <2$5G) $5G)$ $ =g+4GD V VG2:%:%1C0 2D :%:%1C0%m %mL&%G4 L&%G4+'&4 +'&4
$ZC0'GD V 'GD V ~" E3 ~" E3$ Ž 2; V V 2;'&0 '&0%L$ZJ/19 %L$ZJ/19_ chain E; '$ '$ forwardj GD V VGDv74 v 74 {onnection {onnection State $8 %/(7K %/(7K( newj GD V VGD
$ZC0'GD V 'GD V ‚" E3 ‚" E3$ Ž 2; V V 2;'&0 '&0%L$ZJ/19 %L$ZJ/19_ chain E; '$ '$ forwardj GD V VGDv74 v 74 {onnection {onnection State E; '$ '$ relatedj
$ZC0'GD V 'GD V }" E3 }" E3$ Ž 2; V V 2;'&0 '&0%L$ZJ/19 %L$ZJ/19_ chain E; '$K '$K( forwardj GD VGD V74 v 74 {onnection {onnection State E; '$ '$ estaxlishedj
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% ‚~# ‚~
$ZC0'GD V V 'GD p" &%5F7& p" &%5F7&'K 'K G)$$%&; V V $$%&;'1+9 '1+9'GD V V 'GD9%(&%G4 %9 (&%G4+'&4 +'&4 E3 E3$ Ž 2; V 2; V'&0%L$ZJ/19 %L$ZJ/19_ chain E; '$K '$K( forwardj
'[3?%:23 V V ?%:231+3 1+31C'L$Z<+9 1C'L$Z<+9EFC0 EFC0' $ZC0'GD V V 'GD 19 W" >19'() '()*%+3 *%+3 ,7&'K 'K <2$5GD V V $5GDK K( inalid connection ,K (<2 (<2$5GD V V $5GD>19 >19$D V V $D:C0 :C0'L$6 'L$6?9 ?9('; V V (';(E: (E: 9( ic! echoƒre!ly GD V VGD $3 $37Cm 7Cm R(=7:>19 (=7:>191D1=g+4 =D g+4&; V V &;'LJ7J(&F??9 'LJ7J(&F??9L echoƒre—uest ''$>K 9 %(C0 %(C0%1%:6 %1%:6L&%G4 L&%G4+'&4 ,in!ut ,in!ut chain E' (+4 (+4 %1%&; V V %1%&;'1+9 '1+9'C0 'C0%m %mL&%G4 L&%G4+'&4 +'&4 >70 ,G) ,G)$Q'&4 $Q'&433 $ZC0'GD V 'GD V ‡" '() ‡" '()*%+J/0 *%+J/0%1%&&0 %1%&&0%L$%&; V V %L$%&;'1+9 '1+9'J/19 'J/19 ,new ,new connection G%LC%C0 % ,in!ut chain 9 ( 11)+3+39%&%J0 %9 &%J088% 6 V VL !in 1%:6L&%G4 L&%G4+'&4 +'&4 GD V VGD>E4 >E4'EE4 'EE4 connection connection $ 5F1D 5F1D$%&&0 $%&&0%L$%&; V V %L$%&;'1+9 '1+9'J/19 'J/195%$&%G4 5%$&%G4+'&4 +'&4$3 $37Cm 7Cm R( /&;'0 '0%=g+4 %=g+4 >E'(+4 (+4J0 J0 qinBoz qinBoz $5F1D 5F1D$%&Kv $%&Kv7Q6 7Q6 V V( telnet Cm R(
1?&]4 &]4 ,estaxlished connection connection $ZC0'GD V V 'GD X" >19 X" >19'() '()*%+ *%+ ,7&'K 'K <2$C%C0 $C%C0%(6 %(6 R($;'; in!ut chain =7:K (2; (2; R(%($%&&0%L$Z>E4 %L$Z>E4'EE4 'EE4': 9 9 ':70'() '()*%+G) *%+G)$':9 $':9%LGD V V %LGD+0+'L$%&19 :$%&>19'() '()*%+':9 *%+':9%L'; V V %L';( ( ,dro! eerythin else $ZC0'GD V V 'GD ~" 23 ~" 23 V V1%1KE'76 1%1KE'76:J/0 :J/0&; &;'C9 'C9%:%:J(C'L&% %:%:J(C'L&% =7:$%&58 %$6 %$67$%&; V V 7$%&;'1+9 '1+9' /&;''() ''()*%+2%F *%+2%F -AN J/0%1%& %1%& &0%L$%&; V V %L$%&;'1+9 '1+9'9 '9%(&%G4 %(&%G4+'&4 +'&4+3+7+9 73 +9'$6 '$6?&; ?&;'C9 'C9%:%2('$>70 %:%2('$>70 $ZC0'GD V V 'GD ‚" /E6 ‚" /E6L5%$GD V V L5%$GD&%>70 &%>70$8$%56 %8 567$%&&0 7$%&&0%L$%&; V V %L$%&;'1+9 '1+9'5%$$ZC0 '5%$$ZC0'GD V V 'GD ~ ~ 19J9 J99(/(m V V 9 (/(mLC'L$%&; V V LC'L$%&;'1+9 '1+9' 9( ˆTP 2'&4+ W ,data !ackae GD V V$3 $37Cm 7Cm R(&F/9%L$%&J0 %L$%&J08%6 %8 6 V VL ˆTP coand ,2'&+4 W $ZC0'GD V V 'GD }" 9 }" 9(7D (7D:$6 :$6( /E6L5%$GD V L5%$GD V&%>70$8$%56 %8 567$%&&0 7$%&&0%L$%&; V V %L$%&;'1+9 '1+9'5%$$ZC0 '5%$$ZC0'GD V 'GD V ~ 0 %L>00 '>0K>70 %(>K>70 Qm V V QmL1D L1D%16 %16126 126([4 ([4$6$?6 related connection $ZC0'GD V V 'GD p" p" =7:$ZC0'(D '(D R5F>19 5F>19'() '()*%+ *%+ ,dro! rule <2 $55%$ $55%$ forward chain C0 %J5L9 %J5L9%: %: $;'1; V V '; 1;'&%'() '&%'()*%+G) *%+G)$':9 $':9%LGD V V %LGD +0'L$%&19 :$%&>19'() '()*%+':9 *%+':9%L'; V V %L';( ( ,dro! eerythin else Note" 0%&%+0 Note" 0 %&%+0'L$%&&0 'L$%&&0%L$ZGD V V %L$ZGD1D1$%&$8 $D %&$8%56 %567=K&=+'E 7=K&=+'E 9( SSH =7:>19'() '()*%+J/0 *%+J/0 -AN -AN >E'(+4 (+4 ; V V ;'1+9 '1+9'9 '9%( %( =K&=+'E SSH >K:6L=g+4 L=g+4%:('$>70 %:('$>70 &%$ &%$+0+0'L&0 'L&0%L$Z>19 %L$Z>19'() '()*%+ *%+ ,dro! rule GD V VGD forward forward chain E'(+4 (+45F 5F >19%1%&GD V V %1%&GD5F&3 V V 5F&31+0 1+0(&0 (&0%L$%&; V V %L$%&;'1 '1 SSH connection 9 %(>E4 %(>E4'EE4 'EE4''$>K%:('$>70 ''$>K%:('$>70 ,outside ,outside สรป ป J(?GGD V V J(?GGD } } 5F$E9%m %mL&%:EF'D L&%:EF'D:7C'L>E4 :7C'L>E4'EE4 'EE4 ,i!taxlesJ(9 ,i!taxlesJ(9(C'L (C'L ˆilter `ule Qm V VLK LK( taxle taxle GD V VGD': 9 9 ':J( J( i!taxles K&F$'?70: : chain INPUT_ chain ˆO`qA`\ 19 L6 >19>70 >70$E9 $E9%m %mL9 L9(GD V (GD VK( NAT taxle Qm V VQmL NAT taxle $5FK&F$'?70 5FK&F$'?70: : chain P``OUTIN„_ chain OUTPUT K 7>K &6?
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% ‚}# ‚~
?GGD V V p Š Network Address ?GGD Address Translation ,NAT ,NAT J(?G(D R5F'[3?%:m ?%:mL&; V V L&;'L>'2D 'L>'2D+0+(G%L 0(G%L ,source IP_ >'2D KE%:G%L KE%:G%L ,destination IP_ 2'&4++0 2'&4 ++0(G%L (G%L ,source !ort_ '2D <2 <2$5 $5 ,IP !acket Qm V VQm L1D L1D%18 %18%6 %6*$D V V *$D:C0 :C0'L$6?&; V V ?&;'LC'L>E4 'LC'L>E4'EE4 'EE41; V V 1;'?$ '?$ $6?$%&; V ?$%&; V'1+9'; V V ';'%&&4 >&4'EE4 'EE41D1K&F3 KD &F3G[3 G[3%2 %2 ,!owerfull firewall 0%2 %27m 7mL+0 L+0(G) (G)(&; V V (&;'L&%%$6 'L&%%$6?') ?')K$&]4 K$&]4 9 9K =7:('$/(;'5%$ '5%$L$4 L$46 V6(>&4'EE4 'EE4 ‡ ‡ 9((D ((D R&4 >&4'EE4 'EE4?( ?( `outerOS )]1?6 ]1?6+3+'D'3 D$G6 $G6 RL:6 L:6L %1%&'?'2D '$%&'2D+0+(G%L 0(G%L ,source IP_ >'2D KE%:G%L KE%:G%L ,destination IP_ 2'&4 ++0 ++0(G%L (G%L ,source !ort_ '2D <2 <2$5 $5 ,IP !acket Qm V VQm L'() L'()*%+/&; *%+/&;'(6 '(6?() ?()($%&G8% as—ueradin ,/&; ' MASU MASU`A\ `A\ ;'$%&G8 '$%&G8%J/0 %J/0 MikroTik MikroTik `outer %1%&<&4 %1%&<&4'3'3(G'&4( (+J/0 +J/0&; V V &;'LE 'LE$C9 $C9%:>70 %:>70 Qm V VQmL5FG8 L5FG8%$%&Q9 %$%&Q9'(&; '(&;'C9 'C9%: %: 9(?) (?)E E ,!riate network $9 '(''$ 9 9 '(''$%[%&]F %[%&]F ,!uxlic network address Qm V VL5FG8 L5FG8%$%&Q9 %$%&Q9'(&; '(&;'C9 'C9%:9 %:9(+6 (+6C'L C'L &% ,!riate network $9 '(''$ 9 9 '(''$%[%&]F %[%&]F ,!uxlic network address 70 %:J(>70 ,!riate ,!riate serer L$4 L$46 V6( NAT $E0 E0%: %: $6($6 ($6? ?L$4 L$46 V V(>4 (6 >4'EE4 'EE4 Qm V V QmL L$56 $567': 9 9 7':J(9 J(9(C'L (C'L chain =7:7D 'EE4 'EE4 chain chain >70<$9 <$9 1.
2.
Source NAT ,srcnat ; 'G8 'G8%/(0 %/(0%GD V %GD V'2D<'77&+0 <'77&+0(G%LC'L<2 (G%LC'L<2$5 $5 ,'2D9(?) 9 (?)EK EK(>'2D (>'2D %[%&]F \estination NAT ,dstnat ; 'G8 'G8%/(0 %/(0%GD V V %GD'2D '2D<'77&KE%:G%LC'L<2$5 $5 ,'2D5%$>'2D 5%$>'2D %[%&]FK(>'2D (>'2D9(?) 9 (?)E E
Source NAT ,/&;'GD V V 'GD&D&D:$ :$ SNAT /&;' Out Outxou xound nd NAT NAT Source NAT K ( (L$4 L$46 V6(GD V VGD1D1$%&J0 $D %&J0L%(1%$GD V V L%(1%$GD)7J( 7) J( as—ueradin GD V VGDJ0 J0J($%&Q9 J($%&Q9'(&; '(&;'C9 'C9%:9 %:9(?) (?)E E ,!riate network $9'(''$ 9 9 '(''$%[%&]F %[%&]F ,!uxlic network K ( (L$4 L$46 V6(GD V VGD'() '()*%+J/0 *%+J/0&%G4 &%G4+'&4 +'&4<&4'3'(3 G'&4(+ J/0'123 '123+'&4 +'&4 &; V V &;'L'; V V 'L';( ( %:J(&;'C9 'C9%: %: ,=Q( -AN /&;' \M› %1%&; V V %1%&;'1+9 '1+9''3 ''3(G'&4 (G'&4(+>70 +>705%$>'2D 5%$>'2D%[%&]F2D %[%&]F2D:L>'2D :L>'2D<'77& <'77& 7D: : 9(7D (7D:$6 :$6($6 ($6? ?L$4 L$4 V V6($%&G8 ($%&G8%L%(C'L %L%(C'L NAT ;'2D '2D:L<9 :L<9G8G%/(0 8%/(0%GD V %GD V'2D 'KE%:G%LC'L>'2D <'77& /&;'/1%:EC2'&4 '/1%:EC2'&4+ $9'(GD V V '(GD5F9 5F9L<2$$ L<2$$+(6 +(6 R(''$>K (''$>K =7:/E6$$%&G8 $$%&G8%L%(9 %L%(9(7D (7D:$6 :$6($%& ($%&L$4 L$46 V V(>&4 (6 >&4'EE4 'EE4 =7: =7: 2; R(%(C'L$Z<2$$+5F+0 +5F+0'L 'L atch +%1$ZGD V V +%1$ZGD&0 &0%L>&4 %L>&4'EE4 'EE4mmLG8 LG8%L%( %L%(
+6':9 ':9%L %L '(v$L9 $L9%: %: 8%/&6 %/&6?$%&&0 ?$%&&0%L$Z %L$Z source source NAT '2D 1%C'L>'2D<'77& <'77& :$+6':9 ':9%L9 %L9( source IP address K (>'2D (>'2D9(?) 9 (?)E E pW.~}..#W‡ 0 %=g+4 %=g+4>'2D >'2D pW.~}..W pW.~}..W 9 L<2$$ L<2$$+''$>K +''$>K :6L'3 L'3(G'&4 (G'&4(+ 16(5F?'$+0 (5F?'$+0(G%L9 (G%L9%1%5%$ %1%5%$ pW.~}..W <+9 1; V V 1;'<2$$ '<2$$+3 V V +3L9 L9%(>&4 %(>&4'EE4 'EE4&% &% GD V VGD1D1$%&$8 $D %&$8%/(7$ZK %/(7$ZK( source NAT &%G4+'&4 +'&45FG8 5FG8%$%&+6 %$%&+67'2D %8 $%&'2D99(?) (?)E+0 E+0(G%L (G%L ,!riate IP K (>'2D (>'2D%[%&]F %[%&]F ,!uxlic IP GD V V<2$ $+3 V V +3L''$(6 L''$(6 R(; (;' ether Qm V VQmL19 +5F>19J0 J01%5%$>'2D 1%5%$>'2D pW.~}..W 16(5F1D (5F1D+0+(G%L<2$$ 0(G%L<2$$+K +K( W†.‡.XX.W‡† W†.‡.XX.W‡† 767 6L& L&K 5%$(6 R(&%G4+'&4 +'&45FG8 5FG8%$%& %$%& ake record C'L source '2D (G%L'2D<'7&7 1 '>1 Qm V VQmL+'((D L+'((D R destination destination IP ;'>'2D '>'2D%[%&]FC'L&%G4 %[%&]FC'L&%G4+'&4 +'&4 ,!uxlic ,!uxlic IP KJ0 %>KJ0 Note" $%&G8 Note" $%&G8% source NAT 5FG8 %GD V V %GD POST`OUTIN„ POST`OUTIN„ chain K (/E6 (/E6$
\estination NAT ,/&; 'GD V V 'GD&D&D:$ :$ \NAT /&;' Port ˆorwadin +%1GD V V +%1GD'[3 '[3?%:1% ?%:1% Source NAT 16$5FJ0 $5FJ08%/&6 %8 /&6? as—uerade <+9 $$:6: 6L1D L1DK&F=:(4 K&F=:(4'; V V';( ( /6C0 C0'(D '(D R5F'[3 5F'[3?%:m ?%:mL \estination NAT =7:/E6$$%&J0 $$%&J0L%(':9 L%(':9%L %L J( source NAT (6 R(&%G4 (&%G4+'&4 +'&45FG8%$%&+6 %$%&+67'2D >'2D<'77&9(?) (?)E5%$<2$ E5%$<2$ $++0 ++0(G%L''$ (G%L''$ '2D 0 :>'2D<'77&%[%&]FC'L&%G4 <'77&%[%&]FC'L&%G4+'&4 +'&4 9( ( \estination NAT $&F?($%&G8 %L%($ %L%($1D1D E6$b]F7D $b]F7D:$6 :$6( <+9$ZGD V V $ZGD&0 &0%LCm %LCm R(5F': 9 9 (5F':J( J( chain dstnatj '2D >'2D<'77&5%$<2$ $+KE%:G%L +KE%:G%L 70 +KE%:G%L>70 9($6 ($6( 9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% }# ‚~
K&F=:(4$%&J0 $%&J0 \NAT $&]DGD VG VD &%1DQ3 Q3&4&'&4 4 '&4J/0 J/0?&3 ?&3$%&<$9 $%&<$9%[%&]F/&; %[%&]F/&;'J/0 'J/0?&3 ?&3$%&?('3 $%&?('3(G'&4( (+ 9( 1EQ3&4&4'&4 '&4_ ?Q3 ?Q3&4&4'&4 '&4 K K(+0 (+0( 70 >D 705%$ 5%$ destina destination tion NAT NAT ;'>'2D '>'2D%[%&]F2D %[%&]F2D:L :L /(m V V /(mL>'2D L>'2D<'77&%1%&J/0 <'77&%1%&J/0?&3 ?&3$%&>70 $%&>701%$$9 1%$$9%/(m V V %/(mL?&3 L?&3$%&J(E%7D $%&J(E%7D:$6 :$6( +6':9 ':9%L %L &%1D1EQ3 1EQ3&4&'&4 4 '&4%:J(&; %:J(&;'C9 'C9%:K %:K( !riate network K:6L&; V V L&;'L1EQ3 'L1EQ3&'&4 &'&4GD V VDK K( !riate >'2D<'77&C6 R(+'(; (+'(;'&0 '&0%L %L NAT rule GD V VGD chain chain K( dstnatj '2D<'77& \st. Addressj =7:J($Z(D R&%5FJ0 &%5FJ0 !uxlic !uxlic >'2D<'77&C'L&% <'77&C'L&% 2&%F>'2D <'77&&%5FG8%$%&<1 %$%&<1G$6 G$6?; V V ?;' \NS ,\oain Nae Syste ?'$9 %; V V %;'(D '(D RK K(&; V V &;'L1EQ3 'L1EQ3&4'&4 '&4C'L&% 9( ailW.yourdoain.co n.co 1; V V 1;'<2$$ '<2$$+5%$1EQ3 +5%$1EQ3&4&'&4 4 '&4'; V V'( ;( 9L1%:6 L1%:6L ailW.yourdoain.co (6 R(/1%:m (/1%:mL&%G4 L&%G4+'&4 +'&4 &%5%$(6 R($Z ($Z dstnat 5F+67'2D >'2D<'77&KE%:G%L <'77&KE%:G%L '2D <'77&KE%:G%L <'77&KE%:G%L /&;'&% '&% %1%&GD V V %1%&GD$8$%/(72'&4 %8 /(72'&4+<2$$ +<2$$+GD V V +GD<+$+9 <+$+9%L$6 %L$6(>70 (>70 ( ( Kv7 HTTP 2'&4+ } ?(&%G4+'&4 +'&4 &%%1%&GD V &%%1%&GD V5F NAT K:6 '>K:6L&; V V L&;'L 'L?Q3 ?Q3&4&4'&4%:J( %:J( ,internal wex serer /&; ' local intranet Note" $%&G8 Note" $%&G8% \estination NAT 5FG8 %GD V V %GD P``OUTIN„ P``OUTIN„ chain K (/E6 (/E6$ G8%>1&%m %>1&%mL+0 L+0'LG8 'LG8% \estination NAT‹ 1; V V'1D '1D/(m V V /(mL !uxlic >'2D<'77& Q+4 ?>Q+4?&3 ?&3b6bGQm V V G6 QmL&6 L&6(': 9 9 (':?(=g+4 ?(=g+4?Q3 ?Q3&4&4'&4/1; /1;'($6 '($6( /&;'?&3b6bG1D G6 1D W ? Q3&'&4 4 '&4 19 %>19mL+0 Lm +0'LJ0 'LJ0 destination destination NAT 3 [D[$%&$ D$%&$;'
WW.XX..}
Priate IP address
pW.~}..W 1%+&%%( HTTP 2'&4 + }
Host W Š Partner qex Serer Puxlic IP addaress Priate IP address
WW.XX..} 1%+&%(
1%+&%%(2'&4+ HTTP 2'&4+ }
&6(Q'&4 (Q'&4332'&4 2'&4+ } >19J0 J02'&4 2'&4+
pW.~}..W ?Q3 ?Q3&4&'&4 4 '&4&6&(?(1%+&%%( (6 ?(1%+&%%( HTTP 2'&4+ }
5%$=5G:45F+0'L&0 'L&0%L %L NAT rules 76L(D L(D R +12อท อท % % 3 +/าหนด าหนด {hain ” dstnat \st. Address ” pW.~}.WX pW.~}.WX.W .W ,0%J0 %J0 Mode Mode \S- `outer 9 ( >'2D<'77& <'77& pW.~}.WX. pW.~}.WX. 5F+0'L 'L NAT 2'&4+ } $9'( '( 0%K %K( Puxlic IP address_ \st. Address $ >19+0+0'L$8 'L$8%/(7'F>& %/(7'F>& !rotocol ” T{P \st. Port ” } Action ” dstƒnat To Address ” pW.~}..W pW.~}..W To Ports ” } +12อท อท & & 4 +/าหนด าหนด {hain ” dstnat_ !rotocol ” T{P \st. Address ” pW.~}.WX pW.~}.WX.W .W ,0%J0 %J0 Mode Mode \S- `outer 9 ( >'2D<'77& <'77& pW.~}.WX. 5F+0 'L 'L NAT 2'&4+ } $9'( '( 0%K %K( Puxlic IP address_ \st. Address $ >19+0+0'L$8 'L$8%/(7'F>& %/(7'F>& \st. Port ” } Action ” dstƒnat To Address ” pW.~}..W To Ports ” } +12อท อท 4 56789: ;<79= {hain ” forward Src. Address ” pW.~}.W pW.~}.W Protocol ” T{P \st. Port ” } Action ” acce!t +12อท อท 4 >?@A79 8%/&6 %/&6?J0 ?J0'3'(G'&4 (3 G'&4( (+/E%:50 +/E%:50% ,Multi ISP Serice Proider {hain ” Preroutin Src. Address ” pW.~}..W pW.~}..W {onnection Mark ” Nae of `outin Taxle 9 ( T`U Action ” ark routin 9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% }W# ‚~
New `outin Mark ” Nae of `outin Taxle 9 ( T`U G7'? Kv7 7??&%'&4 ??&%'&4
NAT ?23b b ,S!ecial Ty!es of NAT `ules SourAe -,T 3it= Mu9tiC9e 0u49iA B0 ,;;re>>
K($%&G8 ($%&G8% source NAT =7:1D /E%: /E%: Puxlic IP Address 0 %&%1D %&%1D2D 2D:L/(m V V :L/(mL Puxlic IP Address J($%&''$'3(G'&41616($ ($ L>19J0 J0&; V V&;'L':%$'F>&1%$1%: 'L':%$'F>&1%$1%: 2D:L$8 :L$8%/(7 %/(7 default router J/0 ': 9 9 ':?( ?( suxnet C'L 0J/0 J/0?&3 ?&3$%&'3 $%&'3(G'&4 (G'&4 70 %1%&?'$>70'2D<'77& <'77& %($%&]4 /(>70 (>70675(?(&F?? 76 5(?(&F?? Multi!le qAN GD &%E; V V&%E;'$J0 '$J0?&3 ?&3$%&'3 $%&'3(G'&4 (G'&4( (+5%$ +5%$ 0J0 J0?&3 ?&3$%&/E%: $%&/E%: 50% Qm V VQmL suxnet C'L>'2D <'77&$<+$+9 <+$+9%L$6 %L$6( 8%%11D %%11D': 9 9 ':9%/%$&%+0 %9 /%$&%+0'L$%&J0 'L$%&J0>'2D >'2D<'77&GD V V <'77&GD'L 'L ,Secondary Puxlic IP Address (D R88%/&6 %/&6? J/0?&3 ?&3$%&1EQ3 $%&1EQ3&4&4'&4=7:GD V V 7:GD&; V V &;'L1EQ3 'L1EQ3&'&4 4 '&4( R': 9 9 'D :?( ?( !riate network =7:GD V V>19 >19J/0 J/0&; V V &;'L1EQ3 'L1EQ3&4&'&4 4 '&4GD V VG':) 9 'D :) 9G V V=E$ 6 =E$ 1'L9%&; V V %&;'L1EQ3 'L1EQ3&4&4'&4&%>19 &%>19J0 J0&; V V &;'L9 'L9L'D L'D1EGD V V 1EGD>19 >192m V V2LK&FL4 Lm K&FL4 ,SPAM ,SPAM /(m V V /(mLJ(3 LJ(3[D[$%&GD V V D$%&GDJ0 J0J($%&+&5'?$ J($%&+&5'?$;'; `eerse \NS ,K($%&KED V V ($%&KED:(5%$>'2D :(5%$>'2D<'77& <'77& $E6?1%K ?1%K(; V V (;'=g+4 '=g+4(1 (1 =7:J0$%&'?+&57 $%&'?+&57+0+(G%LC'L1E (0 G%LC'L1E Q3&4&'&4 4 '&4 ,J0 ,J088%6 %6 V VL nslooku! +%170 :; V V :;'=71( '=71( /&;'Q6 'Q6?=71( ?=71( GD V VGDJ0 J0J($%&9 J($%&9L'D L'D1E1%:6 1E1%:6L1EQ3 L1EQ3&4&4'&4C'L&% C'L&% '2D :/1%:EC>'2D<'77& <'77& 9( nslooku! WW.XX..} 5F/(>70 (>709%>'2D %9 >'2D<'77& WW.XX..} %1%& reerse $E6?1%>70 ?1%>70K K(; V V (;' ns.ail.in.th 5%$+6':9 ':9%L%1+0 %L%1+0'L$%&&%$9 'L$%&&%$9'(/(0 '(/(0%(D %(D R;'J0 '; J0 secondary Puxlic IP Address 8%/&6 8 %/&6?J/0 ?J/0?&3 ?&3$%&1EQ3 $%&1EQ3&'&4 4 '&4 &%5F+0 &%5F+0'L 'L 23 V V 231 forward \NS >K:6L secondary Puxlic IP Address ?(&%G4+'&4 +'&4 '2D<'77& C'L1EQ3&4&'&4 4 '&4&% &% Qm V VQmL(D L(D R>19 >19J9 J93[D[3 K$+3 DK$+3J($%&&0 J($%&&0%L$Z? %L$Z? sinle source NAT ?( action GD V VK K( as—uerade 11)+3+39%9
Puxlic IP ?(&%G4+'&4
W†..W.W
\efault ateway ?(&%G4+'&4
W†..W.
Mail Serer !riate IP Address
pW.~}..W
Secondary !uxlic IP Address
W†..W.† ,inxound access /&; 'K&F+1EC%C0 1EC%C0%8 %8%/&6 %/&6? C0%m %mL1EQ3 L1EQ3&4&'&4 4 '&4&% &%
<+9?%L3 ?%L3[D[ inxound D inxound access ,inxound ail ateway '%55FK (&; V V (&;'L$&'LK:6 %(>K:6LQ3 LQ3&4&4'&4 K:6 L''$>K:6LQ3 LQ3&4&'&4 4 '&4 0&6& ?1E ?6 1E 8%/&6 %/&6? inxound access 0 %&%&0 %&%&0%L$Z %L$Z destination NAT J($%&&6?1E?(>'2D ?1E?(>'2D<'77& <'77& W†..W.† K:6L>'2D L>'2D<'77& <'77& pW.~}..W G9 %(D %(D RK K('6 ('6(& (&5 <+9161(5F 6(5F as—uerade G)$':9 $':9%L''$K %L''$K( !uxlic '3(+'&4 (+'&4Q Q &% Qm V VQmLG) LG)$G&%v $G&%v$J($%&9 $J($%&9L1E5%$Q3 L1E5%$Q3&'&4 4 '&4&%5F1D>'2D >'2D<'77&+0 <'77&+0(G%L5%$ (G%L5%$ W†..W.W 76L(6 L(6 R(1Em (1EmL/%: L/%: solution J( $%&<$0>CK >CK*/%(D */%(D R;;' $%&J0 source source NAT rule Qm V VL5F L5F atc atchh <2 <2$ $$$+GD V V +GD1%5%$ 1%5%$ pW.~}..W K:6L>'2D L>'2D<'77& <'77& W†..W.† Qm V VQmL$%&&0 L$%&&0%L$C0 %L$C0'(D '(D R5F<$0>CK >CK*/%76 */%76L$E9 L$E9% % )e>ti(8tio( -,T :it= ,Atio( Re;ireAt
K(& (&K?$%&G8 K?$%&G8% destination NAT ?KED :(0 V V:(0(G%L<2$$ (G%L<2$$+ $%&G8% destination NAT ?23 b(D b(D R 9( $%&G8% trans!arent !rozy =7:$%&KED :(G&%v V V:(G&%v$ $?J/0 ?J/09%(>K:6 %9 (>K:6L s—uid !rozy &6(': 9 9 (': K K($%& ($%& redirect =K&=+'E tc! 2'&4+ } >KK(2'&4 (2'&4+ †W} GD V VGD&; V V &;'L2& 'L2&'$QD '$QDQ3 Q3&4&4'&4 '&4&6&(=K&<$&1 6(=K&<$&1 s—uid ': 9 9 ': ,=K&<$&1GD V V ,=K&<$&1GD>70 >70&6&?%1(3 ?6 %1(3:11%$GD V V :11%$GD)7 7) 1; V V 1;' '(v$& $&5 &%G4+'&4 +'&45F76 5F76$56 $56? ,ca!ture G) $$%&&0 $$%&&0'LC'GD V V LC'GDK K(=K&=+'E (=K&=+'E HTTP <2$$+ K:6 $>K:6L&; V V L&;'L2& 'L2& '$QDQ3 Q3&4&'&4 4 '&4 ,Prozy ,Prozy Serer Note" `outerOS (6?() Note" `outerOS ?()($%&G8 ($%&G8% Prozy Serer 70:=K&<$&1 :=K&<$&1 S—uid ': 9 9
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% }‡# ‚~
+6':9 ':9%L %L $%&G8% Mas—uerade `ule $%&G8% as— as—ue uera rade de '%5 '%5&D&D:$>70 :$>7099%K %K(& (&K?$%&G8 K?$%&G8% source NAT ?23 b b Qm V VQmL(8 L(8%1%J0 %1%J0L%($&]D L%($&]D GD V VGD&%G4 &%G4+'&4 +'&4>70 >70&6&?>' ?6 >' 2D<'77&?>19Q8Q R%8 ,\ynaicallyƒassied IP address 5%$ 0J/0 J/0?&3 ?&3$%&'3 $%&'3(G'&4 (G'&4( (+ ,ISP :$+6':9 ':9%L %L 9( &%G4+'&4 +'&4 ; V V ;'1+9 '1+9'9 '9%(=17 %(=171E 1E'$'3 '$'3(70 (70:: ::Q'&4 Q'&4(1K:6L L 0J/0 J/0?&3 ?&3$%&'3 $%&'3(G'&4 (G'&4( (+ =7:2; R(%('3 (%('3(G'&4 (G'&4( (++%1?0 ++%1?0%( %( ,Hoe Use &%5F>70&6&?>'2D ?6 >'2D<'77&?>19 <'77&?>19Q8Q R%1% %8 1% 1; V V 1;'1D '1D$%&Kv $%&Kv7#Kv 7#Kv7&%G4 7&%G4+'&4 +'&4 >'2D >'2D<'77&GD V V <'77&GD>70 >70&6&?$ ?6 $5FKED V V 5FKED:(K&; V V >K&;': ': 9(0 (0% % 0J0 J016 16&J0 &J0?&3 ?&3$%&K $%&K(<2 (<2$5GD V V $5GDK K( cor!orate !ackae ? Static IP address $ 5F>70&6&?>'2D ?6 >'2D <'77&731G) 1G)$&6 $&6 RLGD V V LGD; V V ;'1+9 '1+9' ,ˆizIP C0'7D '7DC'L C'L as—ueradin ; '&%>19 '&%>195%K %8 K(+0 (+0'L&F?) 'L&F?)>'2D >'2D<'77&GD V V '77&GD5FJ0 5FJ0J($%& J($%& KED V V KED:( :( &K? K? i!taxles ,&6(8 (8%6 %6 V VLGD V V LGD&; V V &;'LE3 'LE3()($Q4 $) Q4GD V VDG8G%/(0 8%/(0%GD V V %GD/1) /1)(=171 /&;'GD V V 'GD&D&D:$9 :$9% -inuz `outer i!taxles ƒt nat ƒA POST`OUTIN„ ƒo !!! ƒ™ MASU`A\ /1%:%19 %G8 %G8% as—ueradin G) $<2$$ $<2$$+GD V V +GD3 V V3L''(9 L''(9%( %( !!! 8%/&6 %/&6?') ?')K$&]4 K$&]4 MikroTik `outerOS `outerOS &%%1%&'(v$9 $9%( %( „UI >70E: E: +6':9 ':9%L(D %L(D R5FJ0 5FJ0 qinBoz qinBoz =7:11 =7:11))+3+3J/0 J/0$%&; V V $%&;'1+9 '1+9''3 ''3(G'&4 (G'&4( (+''$'3 +''$'3(G'&4 (G'&4 etherƒateway etherƒateway 1.
&0%L %L NAT rule >KGD V V >KGD1( 1( IP IP ’ ’ ˆirewall
E3$GD V V $GD
2.
E;'$ '$ chain srcnatj
3.
>KGD V V >KGD
5%$ NAT rule GD V VGD &%&0 &%&0%LCm %LCm R(/1%:%19 (/1%:%19%G8 %G8% as—ueradin G) $G&%v $G&%v$GD V V $GD3 V V3L''$9 L''$9%('3 %('3(G'&4 (G'&4 etherƒateway etherƒateway /&;''3 ''3(G'&4 (G'&4( (+'3 +'3(G'&4 (G'&4 :$0(G&%v (G&%v$%:J( $%:J( ,local traffic
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% }~# ‚~
+6':9 ':9%L %L $%&G8% \estination NAT J/0 $6$? ?6 ?Q3 ?Q3&4&4'&4%:J( %:J( ,Priate Network J(+6':9 ':9%L(D %L(D R5FK 5FK($%&G8 ($%&G8% \NAT 8%/&6 %/&6? qex Serer ?(&;'C9 'C9%:9 %:9(?) (?)E E ,Priate Networ‘ =7:3 [D[KED V V D KED:(2'&4 :(2'&4+ =7:GD V =7:GD V local network network &%+0'L1D 'L1D&; V V &;'L 'L?Q3 ?Q3&4&'&4 4 '&4&6&(': 9 9 (6 ':K K( !riate IP address Qm V VL1D L1D&%:EF'D &%:EF'D:776 :776L(D L(D R 11)+3+93 9% ƒ ?&3b6bGJ/0 G6 J/0?&3 ?&3$%& $%& „rou!qare „rou!qare Q3&4&'&4 4 '&4?(2'&4 ?(2'&4+ } Q+4 ?>Q+4?&3 ?&3b6b6G?(2'&4+ }} =7:&;'C9 'C9%:%:('$ %:%:('$ ,!uxlic outside C0 %mL>70 L>709%(=K&=+'E %9 (=K&=+'E 1%+&%%( HTTP 2'&4+ } Priate IP address ,qex Serer
pW.~}..
Puxlic IP Address
WW.XX..}
1.
&0%L %L NAT rule >KGD V V >KGD1( 1( IP IP ’ ’ ˆirewall ˆirewall ’ ’ E3$GD V V $GD
E3$&; V V $&;'L/1%: 'L/1%: 1
2.
E;'$ '$ chain K( dstnatj
3.
E3$>KGD V V $>KGD
T{P <2$$+G6 +G6 RL/17GD V V L/17GD+&L$6 +&L$6?$ZC0 ?$ZC0'(D '(D RGD VG VD>K !uxlic IP ,WW.XX..} ,WW.XX..} 2'&4 2'&4+ } 5F$G8 $G8%$%&KED V V %$%&KED:(9 :(9%>'2D %>'2D<'77&KE%: G%L Q+4 ?>Q+4?&3 ?&3b6bG9 G6 9%(>'2D %(>'2D<'77& <'77& WW.XX..} WW.XX..} ?(1%+&%%(2'&4+ }
+6':9 ':9%L %L $%&G8% Source NAT 5%$G&%v $+0 $+0(G%L2%F?%L>'2D (G%L2%F?%L>'2D<'77& <'77& J(+6':9 ':9%L(D %L(D R&%5F11) &%5F11)+3+39%9 !uxlic IP address 8 %/&6 %/&6?$%&''$'3 ?$%&''$'3(G'&4 (G'&4( (+ '2D L>'2D<'77& <'77& ,Multi!le !uxlic IP address ?(?%L'3 (G'&4 (G'&4 /&;'G) 'G)$ $ '3(G'&4 (G'&4 9( '%55FK( E6$b]F$%&G8 $b]F$%&G8%E3 %E3L$8 L$8%&'L %&'L ,Backu! link 8 %/&6 %/&6? ˆailoer /1%:m L%1%&C0 L%1%&C0%m %mL?&3 L?&3$%&>70 $%&>709%(/E%: %9 (/E%: !uxlic IP address 19 :191D1 NAT D NAT rule '; V V';( ( =7:G6 V V>K>'2D >K>'2D<'77&+0(G%L5F1%5%$0 (G%L5F1%5%$0(G%L&3 V V (G%L&31+0 1+0( ,default route Qm LK V VLK(5&3 (5&3L':9 L':9%L<(9 %L<(9('(J(+6':9 ':9%LGD V V %LGD 9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% }}# ‚~
'[3?%:C0 ?%:C0%L+0 %L+0( GD V VGD(D( R&%1%G8 D &%1%G8%%1C0 %%1C0%J5J/0 %J5J/06675($6 75($6( 27L9 7L9%: %: ;'L%((D 'L%((D R161(+0 (6 +0'LED 'LED:&4 :&4 0 0% MikroTik MikroTik &%G4 &%G4+'&4 +'&4&%1D &%1D !uxlic !uxlic IP address K( WW.XX..} '2D (>'2D WW.XX..} 0 L<10 L<105FG8%K %K( xound '3(G'&4 (G'&4 76L(6 L(6 R(/%$&%+0 (/%$&%+0'L$%& 'L$%& !uxlic IP address 23 1+3 V V1+315%$ 15%$ 0J/0 J/0?&3 ?&3$%& $%& 1% J08%/&6 %8 /&6? ??Q3 ?Q3&4&'&4 4 '&4>0 >0J/0 J/0?&3 ?&3$%&<$9 $%&<$9%[%&]FK %[%&]FK(>'2D (>'2D<'77& <'77& WW.XX..p '2D >'2D<'77&J/19 <'77&J/19(D( R>K:6 D>K:6L>'2D L>'2D<'77& <'77& pW.~}.. (D R;'&F??5FG8 '; &F??5FG8%L%(>70 %L%(>707D7D <+9 <+9 %15&3L'2D <'77&>'2D+0+0(G%LGD V V (G%LGD1%5%$ 1%5%$ WW.XX..} CK >CK*/%(D */%(D R>70 >70 1.
&0%L %L NAT rule Cm R(1%J/19 (1%J/19 >KGD V V >KGD1( 1( IP IP ’ ’ ˆirewall
E3$GD V V $GD
2.
&0%L %L NAT rule GD V VGD v74 v 74 chain chain E;'$K '$K( srcnatj
3.
E3$>KGD V V $>KGD'2D (>'2D<'77& <'77& WW.XX..p WW.XX..p
$Z(D R+&L$6 +&L$6?G&%v ?G&%v$GD V V $GD1%5%$ 1%5%$?Q3 ?Q3&4&'&4 4 '&4G6G RL/17 L6 /17 &%G4+'&4 +'&45FG8 5FG8%$%&KED V V %$%&KED:(<'77&+0 :(<'77&+0(G%L (G%L K:6 $>K:6L>'2D L>'2D<'77& pW.~}.. pW.~}.. '2D >D '2D<'77& <'77& K( WW.XX..p
+6':9 ':9%L %L $%&G8% \estination NAT 70 :$&F?($%&9 :$&F?($%&9L+9 L+9'<25 '<25 ,Action `edirect J(+6':9 ':9%L(D %L(D R&%5F+0 &%5F+0'LG8 'LG8%76 %76$56 $56?G&%v ?G&%v$ \NS C%''$G6 RL/17 L/17 ,outxound GD V VGD1%5%$ 1%5%$ local network K:6 C'L&%>K:6L \NS resoler GD V VGD+9+%L %9 L '%55FK(C'L (C'L 0J/0 J/0?&3 ?&3$%&'3 $%&'3(G'&4 (G'&4( (+/&; +/&;'K 'K( O!en \NS resoler GD V VGD1D1': 9 9 'D :G6G V V>KJ('3 6>KJ('3(G'&4( + GD V VGD>70 >70&6&?%1(3 ?6 %1(3:1$ :1$9 9( „oole Puxlic \NS K (+0 (+0( +'((D V V +'((D&%+0 &%+0'L'(v 'L'(v$ \NS Q3&4&'&4 4 '&4?( ?( MikroTik MikroTik &%G4+'&4 +'&4&%2; V V &%2;'G8 'G8%/(0 %/(0%GD V V %GDK K( \NS {achin {achin %:J('L4 %:J('L4$& $& ;' EE62[4 2[4G6G RL/175F L6 /175F$$ $$?>0 ?>0 G8 G8%J/0 %J/0E%$%&+'?('LJ(&6 E%$%&+'?('LJ(&6 RL6 L67>K& 7>K&Cm Cm R( 19'() '()*%+'() *%+'()*%+J/0 *%+J/0G8G%8 forward forward \NS re—uest re—uest >K:6L Puxlic \NS Q3&'&4 4 '&4+9+9%L %L >70 $%&G8 $%&G8% Interce!t \NS Port '%55F2; V V'+0 '+0'L$%&?E 'L$%&?E'$ '$?>Q+4 ?>Q+4=7:&D =7:&D:$J0 :$J05'&4 5'&4C'L C'L 0J/0 J/0?&3 ?&3$%& $%& \NS 9( O!en\NS Qm V VQmLK LK( ˆree \NS resoler GD V V(9(%; V V 9%;'; ';'>70 '>70 1.
&0%L %L NAT rule Cm R(1%J/19 =7:>KGD V V =7:>KGD1( 1( IP IP ’ ’ ˆirewall
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% p# ‚~
2.
GD V VGD
3.
E3$>KGD V V $>KGD
4.
5%$(6 R(J/0G8G%+%1C6 %8 +%1C6 R(+'('D$&6 $&6 RL <+9vv74 74 Protocol Protocol KED V V KED:(K :(K( U\P
$Z(D R+&L$6 +&L$6?G) ?G)$ \NS \NS <2$$ <2$$+G6 +G6 RL=K&=+'E L=K&=+'E U\P K:6 $>K:6L&%G4 L&%G4+'&4 +'&4 +6':9 ':9%L(D %L(D R;;'$%&?6 '$%&?6L6 L6?J/0 ?J/0J0 J0 \NS \NS Q3&4&4'&4 '&4C'L&%'L C'L&%'L '[3?%:23 V V ?%:231+3 1+31J/0 1J/0>70 >70/ /(%2 (%2 9( &; V V &;'L>E'(+4 'L>E'(+4>70 >70&6&?>'2D ?6 >'2D <'77&5%$ \H{P Q3&4'&4 '&4 C$%&+6 >C$%&+6 RL9 L9% \NS >E'(+4 ,>E4 ,>E4 #etc#resol.con #etc#resol.con =7:KED :(>KJ0 V V:(>KJ0 !uxlic !uxlic \NS 9( „oole Puxlic \NS 1D /1%:EC>'2D /1%:EC>'2D<'77&K <'77&K( }.}.}.} E'(+4 'L>E'(+4&0&'(C'>K:6 '0 (C'>K:6L }.}.}.} <2$$+$%&&0 +$%&&0'LC'(D 'LC'(D R5F 5F$$6 $$67 =7:$%&$9 $9L+9 L+9'>K:6 '>K:6L&%G4 L&%G4+'&4 +'&4 \NS \NS Q3&4&'&4 4 '&4&%'L &%'L 9( ( \NS < Q3&'&4 4 '&4%:J(&%'%55F %:J(&%'%55F forward =7:$%&&D :$J0 :$J0 \NS \NS resoler 5%$ ISP Qm V VQm L1D L1D%1(9 %1(9%; V V %;'; ';'
Serice Ports Š NAT Hel!ers 0%$8 %$8%E6 %E6L/%1( L/%1(88%/&6 %/&6?'(v ?'(v$ NAT hel!ers &%'%55F/%>195'F 5'F (; V V (;'L5%$(D V V 'L5%$(D;') '; )]1?6 ]1?6+3+GD V VG3 >19 D>199':KED V V '9 :KED:(&Cm 7'F>&Cm R(0 (0%&%E3 %&%E3$GD V V $GD1( 1( IP IP /E6L5%$(6 L5%$(6 R(E;'$ '$ ˆirewall 70 &1C0 &1C0%>K': 9 9 %>K':$6$?6 NAT Qm V VQmL=17 L=17E/E9 E/E9%(D %(D R$Kv $ Kv7J/0 7J/0G8G%L%(K 8%L%(K(9 (9%7D %7D'EE+4 'EE+4 &%%1%&Kv &%%1%&Kv7$%& 7$%& G8%L%(/&; %L%(/&;'56 '567$%&KED V V 7$%&KED:(2'&4 :(2'&4+GD V V +GDG8G%L%(': 9 9 8%L%(':
NAT Hel!er ;' 'L$4 L$46 V V6(+6 (+69 9:/E; :/E;' J0J($%&&F?) J($%&&F?)<2$$ <2$$+8 +8%/&6 %/&6??%L=K&=+'E ??%L=K&=+'E &%%1%&+37+%1$%&; V V 7+%1$%&;'1+9 '1+9' ,connecton trackin trackin Qm V VQm L5F& L5F& 0=K&=+'EC'L<'22E3 =K&=+'EC'L<'22E36 6(GD V V (GD+3+37+9 7+9'; V V ';'%&$6 '%&$6(>70 (>70 J(E8 J(E8%76 %76?6 ?6 R(C'L<'22E3 (C'L<'22E36 6(E:'&4 (E:'&4 ,A!!lication -ayer E4 %:>E4 &F/9%LQ6 %LQ6 V(C'L$%&; V V C'L$%&;'1+9 '1+9' ˆTP 5F&0%L %L control control connection connection 5FK( estaxlishedj <+9 1; V V 1;'J7$ 'J7$+%1GD V V +%1GDC0C'1 '0 1E ,data connection $='(:0 $='(:0%:K&F?) >K&F?)<2$ <2$ $+<&$C'L$%&&0 +<&$C'L$%&&0%L %L {ontrol {ontrol connec connection tion 76L(6 L(6 R($%&; V V ($%&;'1+9 '1+9' data connection 5F $1%&4 $1%&4 ,arked K( relatedj 70 L>70K K( W 9(; (;' 1. 9(GD V V (GDK K( {ontrol connection 5FK ($%&+3 ($%&+37+9 7+9'; V V ';'%&&F/9 '%&&F/9%L %L UserƒPI E4 KC'L>E4_ ?%L9(C'L>E4 (C'L>E4 /&; /&;'/E%: '/E%: >E4 Qm V V QmL'%5K L'%5K($%&; V $%&; V'1+9'&F/9 '&F/9%L %L Sererƒ\TP $6? Userƒ\TP /&;'&F/9 '&F/9%L %L Sererƒ\TP m L W +6$ $>70 >70 Qm V V QmL=K&Q>19 L=K&Q>19585%K %8 K(+0 (+0'L9 'L9LJ/0 LJ/0$6$?6 UserƒPI GD V VGDK K( ( 0&0 &0%L %L {ontrol connection Cm R( Note" $%&+3 Note" $%&+37+9 7+9'$6 '$6(Cm ( RCm(&6 (&6 RL<&$&%5F&D L<&$&%5F&D:$% :$% ˆTP connection 9 ($%&+3 ($%&+37+9 7+9'GD V V 'GD$3 $37Cm 7Cm R(J(&6 (J(&6 RLGD V V LGD'L&%5F&D 'L&%5F&D:$9 :$9% 9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% pW# ‚~
{ontrol connection /(7D %L>/(7D {onnection trackin /&; '?%L&6 '?%L&6 RL&D L&D:$$6 :$$6(6 (6 R( ( 9% conntr conntrack ack L$4 L$46 V(6 J($%&+37+%1$%&+3 7+%1$%&+37+9 7+9'; V V ';'%& '%& 9%7D %7D'E+4 'E+4$Kv $ Kv7 J0L%(0 >0$9$'(/(0 '9 (/(0%(D %(D R connection connection trackin /&; ' conntrack ;'$&F?($%&GD V V '$&F?($%&GDG8G%J/0 8%J/0 `outerOS G8%L%( %L%( =/17 Stateful firewall_ NAT 0 ?>0J( J( State Taxle 0 %1D %1D$%&Kv $%&Kv7$%&J0 7$%&J0L%( L%( connection trackin 16(5FKv (5FKv7 7L$4 L$4 V V6($%&+3 ($%&+37+%1$%&+3 7+%1$%&+37+9 7+9'; V V ';'%&G6 '%&G6 RL NAT 19 %:%:('$>19%1%&C0 %1%&C0%m %mL&F??&%>70 L&F??&%>70 /&; /&;'>19 '>191D1D='$% GD V VGD5F$3 5F$37$%&=51+D 7$%&=51+D5%$%:('$>70 5%$%:('$>70>70 >70 $%&Kv $%&Kv7$%&G8 7$%&G8%L%(C'L %L%(C'L connection trackin $ 5FG8%J/0 %J/0&%G4+'&4 +'&41D1K&F3 KD &F3G[3 G[3%2$%& %2$%& G8%L%(GD V V %L%(GDLCm L RCm( &%G4+'&4 +'&4%1%&0 %1%&0(/%0 (/%0(G%LC'L<2 (G%LC'L<2$ $+>70 +>70&&Cm RCm( 2&%F>19+0+'LJ0 '0 LJ0G&62:%$&GD V V 2:%$&GD+0+0'L9 'L9':1%+3 ':1%+37+%1$%& 7+%1$%& +37+9 7+9'; V V ';'%& '%& 2; V V 2;'23 V V '231K&F3 1K&F3G[3 G[3%2$%&G8 %2$%&G8%L%(C'L&%G4 %L%(C'L&%G4+'&4 +'&4 5m 5mL&GD V V L&GD5FKv 5FKv7 connection connection trackin E$%&G7'? K&F3G[3 G[3%2%1%&C0 %2%1%&C0%7 %7>70 >70GD V VGD ?>Q+4 ?>Q+4 MikroTik MikroTik
+6':9 ':9%L %L $%&Kv7$%&G8 7$%&G8%L%( %L%( {onnection Trackin 1.
>KGD V V >KGD1( 1( IP IP ’ ’ ˆirewall
2.
E3$GD V V $GD
3.
E3$&; V V $&;'L/1%: 'L/1%: $GD V V $GDQ Q$?'$Q4 $?'$Q4''$ ''$
Tools ƒ Torch (D V V(DLK LK('D ('D$/(m V V $/(mL L5'&4 5'&4?( ?( `outerOS (6 R($ ($;'; $%& Monitor Traffic ? realƒtie GD V V9L9 L9 9%('3 %('3(+'&4 (+'&4Q Q =7:1D User User Interface ,UI GD V VGD J0 J0L%(L9 L%(L9%: %: 1D%1%&J($%&<:$$&'LK %1%&J($%&<:$$&'LK(>'2D<'77& 70 +>70 K1%$ ':>K1%$ /&;'1%$>K/%(0 '1%$>K/%(0': ': 70 >70G6G(GD V V (6 GD99%J&J0 %J&J0 (74337G4 7G4G9 G9%>/&9 %>/&9 Qm V VQmLK LK(&; V V (&;'L1; 'L1;'GD V V 'GD8%6 %8 6*1%$J($%&+&5'?K&F3 *1%$J($%&+&5'?K&F3G[3 G[3%2 %2 &4 %L$ZC'L>&4'EE4 'EE4>70 >70':9 ':9%L&7& %L&7& 9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% p‡# ‚~
/(0%+9 %+9%L$%&J0 %L$%&J0L%( L%( Torch 5F': 9 9 5F':J(1( J(1( Tools Tools ’ ’ Torch /&;'GD V V 'GD1( 1( ueues ueues 5%$(6 R(E3 (E3$C%E; $C%E;'$'3 '$'3(+'&4 (+'&4QGD V V QGD+0+'L$%& 0'L$%&
1; V V 1;'/(0 '/(0%+9 %+9%L %L Torch $Kv $Kv7Cm 7Cm R( &%$5F%1%&E; 5F%1%&E;'$'3 '$'3(+'&4 (+'&4QGD V V QGD+0+0'L| 'L|%1'L %1'L ,onitor $%&G8 %L%( %L%( 70+%1+0 +%1+0'L$%& 'L$%&
ตัวอย ตัวอยาง าง :Q'&4 Q'&4J('L4 J('L4$&=G&1%?9 $&=G&1%?9('3 ('3(G'&4( (+0 +0%1%$ %1%$ ,5F>19J/0 J/000%>70 %>70>LE9 >LE9F&6 F&6? C%7%(4=/E7 =/E7 .pMx!s C]F(D R สรป ป Torch Torch K(&; V V (&;'L1; 'L1;'9 '9:J/0 :J/0G&%?m G&%?mLK LK*/%>70 */%>70':9 ':9%L&7& %L&7& 1; V V 1;'=7(E '=7(E$0 $0%=G&1%?9 %=G&1%?9(9 (9%'3 %'3(G'&4 (G'&4( (+0 +0% (; V V (;'L5%$ 'L5%$ Torch %1%&&D:LE8 :LE8%76 %76?C'L$%&J0 ?C'L$%&J0G&%v G&%v$>70 $>70 G8 G8%J/0 %J/0 Adin Adin %1%& %1%&56567$%&$6 7$%&$6?/+) ?/+)$%&]4 $%&]4GD V VG$3 D$37Cm 7 RCm( ,Incident Handlin >70&&:3 V V :3LCm LCm R(
?GGD V V Š $%&?&3/%&56 ?GGD /%&567$%&(74 7$%&(7437G4 73 G470 >70':9 ':9%LL9 %LL9%:7%: %:7%: ,Bandwidth {ontrol and ualiry of Serices Qm L V VL5'&4 5'&4?( ?( `outerOS %1%&?) 1K&3 1K&31%]$%&J0 1%]$%&J0L%((74 L%((7437G4 73 G4 C'L<+9 C'L<+9E9EF<'22E3 F9 <'22E3 6 V V( /&;'<+9 '<+9E9E9F>E'(+4 F>E'(+4>70 >70':9 ':9%LL9 %LL9%:7%: %:7%: $%&?&3/%&56 /%&567$%&(74 7$%&(7437G4 73 G45F<:$K 5F<:$K( W K&FGJ/*9 ;' 1. 2.
$%&G8% Access {ontrol -ist ,A{- $%&G8% uality of Serers ,oS
Access {ontrol -ist ,A{- ; '$%&&0 '$%&&0%L=2ED %L=2EDQDQ ,Policy D ,Policy %:J(/(9 :L%(J($%&+3 :L%(J($%&+37+9 7+9'; V V ';'%&C0 '%&C0'1 '1E $%&C0%m %mLC0 LC0'1 '1EGD V V EGD 58%K %K( 19 >19585%K %8 K(+9 (+9'L%( 'L%( 2; V 2; V''()*%+/&; *%+/&;'>19 '>19'() '()*%+ *%+ 9( >19'() '()*%+J/0 *%+J/0<&4 <&4>E4 >E4? ? PWP ,Peer to Peer /&;'2$=K&<$&1 '2$=K&<$&1 Bittorrent K (+0 (+0( uality of Serers ,oS ; '$%&?&3 '$%&?&3/%&56 /%&567$%&(74 7$%&(7437G4 73 G4C'L&; C'L&;'C9 'C9%: %:
%/+)/E6 /E6$ $ GD V VGD+0+'L1D '0 L1D$%&56 $%&567$%&(74 7$%&(74337G4 7G4 2; V V 2;'G8 'G8% oS 1. 2. 3.
4. 5.
2; V 2; V'$%&567&&4 7&&4J/0 J/01D1$%&J0 $D %&J0L%((74 L%((7437G4 73 G4>70 >70+%1%1/1%F1 +%1%1/1%F1 2; V 2; V'$%&?)1K&3 1K&31%]$%&J0 1%]$%&J0L%((74 L%((74337G4 7G4 J/0 J/0K K(>K+%1=2ED (>K+%1=2EDQDQDC'L<+9E9EF/(9 F9 /(9:L%( :L%( 2; V 2; V'$8%/(7E8 %/(7E8%76 %76?%18 ?%18%6 %6*C'L$%&9 *C'L$%&9LC0 LC0'1 '1E 2; V V 2;'23 V V '231K&F3 1K&F3G[3 G[3%2$%&J0 %2$%&J0L%(<'22E3 L%(<'22E36 6 V V( GD V VGD1D1%18 D %18%6 %6* +9'$%&KZ3 '$%&KZ3?6?+3+6 L%(>70 L3 %(>70':9 ':9%L1D %L1DK&F3 K&F3G[3 G[3%2 %2 2; V 2; V'J0K K(&; V V (&;'L1; 'L1;'6 '67%2C'L&; 7%2C'L&;'C9 'C9%: %: /&;' uality ity of z!erience ence ,o ,o (; V V (;'L5%$'L4 'L5%$'L4$&1D $&1D+0+(G) (0 G)(E3 (E3L$4 L$4; V V ;'1+9 '1+9''3 ''3(G'&4 (G'&4(+ +L 5mL58 L58%K %K(+0'L78 'L78%(3 %(3($%&G8%J/0 %J/0$37%1) 7%1) 019 19%J/0 %J/01%$GD V V 1%$GD)7)
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% p~# ‚~
=7:E8%76 %76?%18 ?%18%6 %6* uality uality of Serice Serice ,oS !riori !riorityty leels ?( `outerOS `outerOS 5F(3 :%1': 9 9 :%1':J(9 J(9L L ƒ} =7: } 5FK ( E8%76 %76?%18 ?%18%6 %6* *L) L)7 ,Hiher !riority 70 :(70 %18 %18%6 %6*; *;'+0 '+0'L<:$<:F<'22E3 'L<:$<:F<'22E36 6 V V(J/0 (J/0>70 >7099%K %K( `ealƒtie /&;' Non `ealƒtie 2; V V 2; '5F>70 '5F>70 567E8 7E8%76 %76?C'L<2 ?C'L<2$ $+ ,-ayer‚ Protocol >70 ':9 ':9%L/1%F1 %L/1%F1 Note" uality of Serice ,oS !riority leels ?(') K$&]4/&; Note" uality /&;'Q'+4 'Q'+4<&4 <&4 Bandwidth {ontroller 5F $(3 $(3:%1Cm :%1Cm R( Qm V VQmL5F<+$+9 L5F<+$+9%L$6 %L$6( ?%L:D V V ?%L:D/0/'$ 0'$(3(:%1K :3 %1K(; V V (;' ,Hiher_ Noral_ -ow /&; '$8 '$8%/(79 %/(79L L ƒ}
•
•
•
•
•
58%$6 %$67'6 7'6+&%$%&9 +&%$%&9LC0 LC0'1 '1E ?&F?) IP IP address_ Suxnet_ Protocol_ Ports
ueue J( MikroTik `outerOS =&L&0%L2; =&L&0 %L2; R(%(K (%(K( Hierarchical Token Bucket ,HTB J($%&&0 %L3?E8 ?E8%76 %76?6 ?6 R(
$%&'(v$3 $3%1%&G8 %1%&G8%>70 %>70 W W 3[D[D 1.
2.
Si!le ueues K ($%&'(v ($%&'(v$3 $3?L9 ?L9%: %: ,Q31Kv 1Kv £E3 E3 9( 58%$6 %$67(74 7(7437G4 73 G4'6'2=/E7#7%(4 62=/E7#7%(4=/E7 =/E7 K(>E (>E '(+4_ 58%$6 %$67 !W! K(+0 (+0( ueue Tree K($%&'(v ($%&'(v$3 $38 8%/&6 %/&6?J0 ?J0L%(J(&F76 L%(J(&F76? ?L
Si!le ueues $Q31Kv 1Kv £E3 E3L9 L9%: %: ? P{{ /&;' Per {onnection {lassifiers ; ' 3J($%&?) J($%&?)1(74 1(7437G4 73 G4? ? ตัวอย ตัวอยาง าง $%&'(v$Q3 >7(%13=7:$%&9 =7:$%&9L(74 L(7437G4 73 G4''$K ''$K(9 (9(G9 (G9% % $6( G8%J/0 %J/0>E'(+4 >E'(+41D1D679 76 9((74 ((7437G4 73 G4ED ED:G9 :G9% % $6( 9( 58%$6 %$67( 7( 7437G4 73 G4&; V V &;'L=g+4 'L=g+4>E' >E'(+4 (+4 suxnet" suxnet" ‚W.~..#W‡ J/0 %1%&'6 %1%&'62=/E7%1& 2=/E7%1& L) L)7>70 7>70 WX~‘x!s WX~‘x!s 70 7>70 Mx!s Mx!s &; V V &;'L=g+4 'L=g+4>E' >E'(+4 (+4G6G RL/17 L6 /17 WX‡ &; V V &;'L5F1D 'L5F1D679 76 9(ED (ED:G9 :G9% % $6( <+900%1D %1D$%&J0 $%&J0L%(2D L%(2D:L :L =g+47D 7D: : 5F%1%&J0%1& %1& L) L)7>70 7>70G9 G9%GD V V %GD$8$%/(7>0 %8 /(7>0(6( R6($ ($;'; Mx!s#WX~‘x!s Mx!s#WX~‘x!s
1. 2.
Nae +6 RL; V V L;'K 'K('F>&$ ('F>&$>70 >70 J('7E0 J('7E0'L70 %J5>70 9 9( ; V V;': ':Q'&4 Q'&4_ >E'(+4>'2D >'2D<'77& <'77& Taret Address &F?) /1%:EC>'2D /1%:EC>'2D<'7&7>E'(+4 <'7&7>E'(+4GD V VGD+0+'L$%&58 '0 L$%&58%$6 %$67(74 7(7437G4 73 G4 /&; /&;'J9 'J9K K( Suxnet 9( ‚W.~..#W‡ (D V V(D ;;'58 '58%$6 %$67(74 7(74337G4 7G4 WX‡ WX‡ =g+4>'2D >'2D<'77& <'77& =7: Taret Address %1%&23 V %1%&23 V1>701%$$9 1%$$9% /(m V V /(mL>'2D L>'2D<'77& =7:J/0$7K) $7K)1E 1E$&D $&D REL EL ,down arrow
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% p}# ‚~
Note" >19585%K Note" >19 %8 K(+0 (+0'L&0 'L&0%L3 %L3<:$1; V V <:$1;' Taret Taret Address Address 1D/E%:>'2D /E%:>'2D<'77& <'77& /&;' networks %1%&$8%/(7=g+4 %/(7=g+4 G6 RL/17J( L/17J( Taret Address >70 2; V V 2;'J0 'J0K K(<&4 (<&433 3.
Maz -iit $8%/(7(74 %/(7(7437G4 73 G4L) L )78 78%/&6 %/&6?'6 ?'62=/E7 ,U!load '2D >'2D<'77& <'77&
Q31Kv 1Kv £E3 E3>19 >19>70 >701D1DL$4 L$46(2D (6 2D:LG9 :LG9%(D %(D R &%%1%&$8 &%%1%&$8%/(7$%&58 %/(7$%&58%$6 %$67(74 7(7437G4 73 G4>E'(+4 >E'(+4<+9 <+9E9EFKE%:G%L>70 F9 KE%:G%L>70 ,destination ,destination addresss_ suxnet Q+4 ?>Q+4 www.susethailand.co www.susethailand.co &3 V V1+0 1+0(70 (70:J0 :J0 8%6 %6 V VL !in =71((1 www.susethailand.co www.susethailand.co 5F1D resoled resoled IP address $E6?1% ?1% 5%$(6 R(G8 (G8%$%&&0 %$%&&0%L3 %L3J/19 J/19 E3 E3$GD V V $GD '2D /1%:EC>'2D<'77& Note" D66*E6 *E6$b]4 $b]4+9+%L %9 L J(3 D<7L <7L /1%:mL 1D$%&J0 $%&J0L%((74 L%((7437G4 73 G4GD V VGD$8$%/(7>0 %8 /(7>0 }Xƒž }Xƒž ,=7:K&F1%] D/E; /E;'L 'L /1%:mL 1D$%&J0 $%&J0L%((74 L%((7437G4 73 G4GD V VGD$8$%/(7>0 %8 /(7>0 XXƒ}ž XXƒ}ž ,=7:K&F1%] DCD CD: : /1%:mL 1D$%&J0 $%&J0L%((74 L%((7437G4 73 G4GD V VGD$8$%/(7>0 %8 /(7>0 ƒXž ƒXž ,=7:K&F1%] (74337G4 7G4 ,Bandwidth ,Bandwidth ;' %1$0%LC'L9 %LC'L9'LG%LJ($%& 'LG%LJ($%& &6?ƒ9 ?ƒ9L C0'1 '1E E%G(QD V V E%G(QD ,-atency ,-atency ;' 9%E%GD V V %E%GDJ0 J0>KJ($%&C0 >KJ($%&C0%m %mLC0 LC0'1 '1EC'L/(9 EC'L/(9:%158 :%158% +6':9 ':9%L %L $%&8%(]/% %(]/% Bandwidth C'L?6GD V V GD1D1%1& D %1&6 6**%](%œ3 **%](%œ3$%&F/9 $%&F/9%L/(9 %L/(9:%158 :%158%?+4J(<+9 J(<+9EF/(m V V EF/(mL&'?C'L6 L&'?C'L6**%](%œ3 **%](%œ3$% $% 5F8%(]>70 %(]>70K K( ~‡ xytes Ÿ ‡ MH… ” WX~Mx!s +6ECGD V V ECGD>70 >70K K(+6 (+6ECG%LG¤bZD ECG%LG¤bZDGD V VG?'$m D?'$mLK&3 LK&31%]C'LC0 1%]C'LC0'1 '1EGD V V EGDC0 C0% 9 9 % {PU {PU J(<+9EF3 EF3(%GD (%GD +%&%LE$%&G7'?K&F3G[3 G[3%2 %2 &) 9 9&)( `B‚X ,{PU s!eed ‡MH… `AM ~‡MB R!"# Mo;e
Bridin
@ o ( Y i< u r 8 t io (
none ,fast !ath
$##M Cort te>t ##M=U
RouterOS VWX#rAW
W 4Zte
" $ & 4 Z te
kC C>
p‡.
M4C>
W‚.†
kC C>
%%BCD
$"$[ 4Zte
M4C>
EFC%
kCC >
DC
M4C>
EGC&
R!"# Mo;e
@ o ( Y i< u r 8 t io (
Bridin WX Bride filter rules `outin none ,fast !ath `outin WX Si!le ueues `outin WX IP filter rules
$##M Cort te>t ##M=U
RouterOS VWX#rAW
W 4Zte
" $ & 4 Z te
kC C>
X†.‚ }†.‚ pW.} †‚.X
M4C>
†X.W W.X ~.} W‡.~
kC C>
XW.† %%BCD }}.X †}.‡
$"$[ 4Zte
M4C>
WW.p EFC% †‚X. ~W.~
kCC >
DC DC DC †‚.~
M4C>
EGC& EGC& EGC& ‡~W.‡
Note" E$%&G7'?5%$+%&%L70%(?( %(?( ;'K&F3 'K&F3G[3 G[3%2 %2L) L)7C'L>1=&+3 7C'L>1=&+3 $&%G4 $&%G4+'&4 +'&4 76L(6 L(6 R(5m (5mL>19 L>19&'(v &'(v$ $3($9 ($9%GD V V %GDG7'? G7'?
Burstin Burstin ;' '5'&4 5'&48%/&6 %8 /&6?$%&$8 ?$%&$8%/(79 %/(79L&F:FE%$%&9 L&F:FE%$%&9LC0 LC0'1 '1E=7:$%&58 E=7:$%&58%$6 %$67(74 7(7437G4 73 G4 $%&(8 $%&(8%>KJ0 %>KJ0 9 9( $8%/(79 %/(79L L E%8%/&6 %/&6?$%&'6 ?$%&'62=/E7/&;'7%(4 '7%(4=/E7>E4 =/E7>E4<&4 <&4C(%7J/*9 C(%7J/*9_ $%&&6? ?L/&; L/&;'&6 '&6?1$%&9 ?1$%&9%:G'77 %:G'77 9( L%( „ool „oole I#O ‘eynote -iestrea 9 %(G%L %(G%L YouTuxe /&; '$%&Kv '$%&Kv7E9 7E9(>E4 (>E4161E+3 E6 +31D17D D 7D: ,Streain Moie /&; '?&3 '?&3$%&'; V $%&'; V( J( E6$b]FE0 $b]FE0%:$6 %:$6((D V V ((D +6 +6':9 ':9%L %L $&]D':9 ':9%L(D %L(D R$$ 9 9( 0J0 J0/&; /&;'E 'E$0 $0%=G&1%=0 %=G&1%=0 :%:'3 :%:'3(G'&4 (G'&4( (+0 +0%5(2$C%:'1&6 %5(2$C%:'1&6?>19 ?>19>70 >70J( J( 9L6 L6(E%GD V V (E%GD1D1$%&9 $D %&9%:G'77L%(Kv %:G'77L%(Kv7+6 7+6+9 +9%L %L (% /&;''D ''D$$&]D $$&]D 9 9( 9LE%26 LE%26$GD V V $GD:L6 :L6(?%L'L4$&5FE6 $&5FE6?$6 ?$6(26 (26$&6 $&6? K&FG%('%/%& 16($ ($5F1D 5F1D?0?%L<($GD V V 0%L<($GD:6:LG8 L6 G8%L%(': 9 %L%(': 9 <+91D1?%L<($GD V V ?D %L<($GD&6&?K&FG%('%/%& ?6 K&FG%('%/%& 9( =1L Q+4 ?>Q+4&6&?1$%&9 ?6 1$%&9%:G'77 %:G'77 /&;''; V V';( ( $3((74 ((7437G4 73 G4>K5(/17 >K5(/17 L$4 L$46(6 xurst 5mLK LK(+6$8 $8%/(7) %/(7)]%2$%&J0 ]%2$%&J0L%( L%( '3(G'&4 (G'&4( (+J/0 +J/0$6$6? ? 0J0 J0>70 >70':9 ':9%L1D %L1DK&F3 K&F3G[3 G[3%2 %2
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% # ‚~
+6':9 ':9%L %L $%&'(v$ xurst
ur>t*9i7it ,NUMB` " '6+&%%1& +&%%1& L) L)7J($%&'6 7J($%&'62=/E7 2=/E7 t*ti7e ,TIM " '6+&%%1& +&%%1&$%&9 $%&9LC0 LC0'1E$3 E$3(&F:FE% (&F:FE% ,3(%GD (%GD GD V VGD1D1$%&8 $D %&8%(]19J9 J9E%GD V E%GD V$37Cm 7Cm R(5&3 (5&3L5%$ L5%$
xurst 4ur>t*t=re>=o9; ,NUMB` " 9%GD V V %GDJ0 J0L%( L%( xurst on # off
&K?$%&8 K?$%&8%(] %(] ารคาNวE าNวE 4ur>t 4ur>t r8tio6 r8tio6
Burst `atio ” xurstƒthreshold # xurstƒliit ารคาNวE าNวE 4ur>t ti7e6
Burst Tie ” ,{lock Tie to Burst # ,Burst `atio ตัวอย ตัวอยาง าง H &3 V V&31+0 1+0(" (" +0'L$%&&0 'L$%&&0%L %L Si!le ueue =7:$8 %/(7 %/(7 azƒliit (7437G4 73 G4GD V VG WX~‘ D WX~‘
76L(6 L(6 R(" (" Mazƒ-iit G9%$6 %$6? WX~k Burstƒ-iite G9 %$6 %$6? XWk BurstƒThreshold 5FG9 %$6 %$6? W}k ,9%GD V V %GD<(F(8 <(F(8%; %;' &m V V &mL/(m V V L/(mLC'L LC'L Mazƒ-iit 5%$(6 R(5F8%(] %(] xurst tie >70 7676L(D L(D R Burst `atio ” W}k # XWk ” .WX Burst Tie ” Xsec # .WX ” W 76L(6 L(6 R(1; V V (1;'$8 '$8%/(7 %/(7 xurs tie 1D9%G9 %9 G9%$6 %$6? W 5F/1%:%19% &F:FE%$%&9LC0 LC0'1 '1EG6 EG6 RL'6 L'62=/E770 7676L(D L(D R Burst `atio ” Xk # ‡p~k ” .†~ Burst Tie ” ~sec # .†~ ” ‡‡.‡‡
(D R::Q'&4 Q'&4G7E'L7%(4=/E7C0 =/E7C0'1 '1EC(%7 EC(%7 †WMx †WMx GD V VGD%1& %1&'3 '3(G'&4( (+ ‡MB ,(74 ,(7437G4 73 G4 =7:&%G4+'&4 +'&45F9 5F9LK LK( W 9LE%&3 V V LE%&317%(4 17%(4=/E7 =/E7 Ž9L<&$ L<&$ 1; V V 1;'&3 V V '&317%(4 17%(4=/E7E%5F&3 V V1+0 1+0((6 ((6?GD V ?GD V 3(%GD (%GD 191D1DG&%v$3 V V $3LJ((%GD LJ((%GD)7G0 7) G0%: %: J/077%2K&F$'?70 %2K&F$'?70%(E9 %(E9%L>K70 %L>K70:5F>70 :5F>70C0 C0%J5:3 V V %J5:3LCm LCm R(
8Ver8(
<+9EF EF class J(3(%GD (%GD)7G0 7) G0%:C'L %:C'L xurstƒtie 1%]G&%v$GD V V $GD$3 $37Cm 7Cm R(5&3 (5&3LJ( LJ( —ueue 8Atu89*r8te K&31%]G&%v $8%/(7 %/(7 Burstƒtie G9%$6 %$6? ~s
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% W# ‚~
%25%$ " htt!"##wiki.ikrotik.co#wiki#Manual htt!"##wiki.ikrotik.co#wiki#Manual"ueuesƒBurst "ueuesƒBurst ƒ +6ECJ(<(+6 ECJ(<(+6 RL70 L70%(Q0 %(Q0%: %: ,ƒX K('6 ('6+&%%1& +&%%1&$%&9 $%&9LC0 LC0'1 '1E ,Mx!s ƒ +6ECJ(<(('(70 ECJ(<(('(70%(E9 %(E9%L %L ,ƒ† K(E% (E% ,/(9:K :K(3 (3(%GD (%GD '[3?%:" ?%:" Ti7e
W † ‡
8 V e r 8 < e * r 8 te
4ur>t
,#~”‘ aeraeƒrate ¥ xurstƒthreshold x!s Burst is allowed ,‡#~”WX aeraeƒrate ¥ xurstƒthreshold ‘x!s Burst is allowed ,‡‡#~”X aeraeƒrate ¥ xurstƒthreshold ‘x!s Burst is allowed ,‡‡‡#~”‚X aeraeƒrate ¥ xurstƒthreshold ‘x!s Burst is allowed ,‡‡‡‡#~” aeraeƒrate ¥ xurstƒthreshold ‘x!s Burst is allowed
8Atu89*r8te →
→
→
→
→
‡Mx!s ‡Mx!s ‡Mx!s ‡Mx!s ‡Mx!s
X ~ ‚ } p W † ‡ X ~ ‚ } p W
,‡‡‡‡‡#~”W aeraeƒrate ¥ xurstƒthreshold X‘x!s Burst is allowed ,‡‡‡‡‡‡#~”X aeraeƒrate ” xurstƒthreshold ‘x!s Burst not allowed ,‡‡‡‡‡‡W#~”~ aeraeƒrate ’ xurstƒthreshold WX‘x!s Burst not allowed ,‡‡‡‡‡‡WW#~”‚ aeraeƒrate ’ xurstƒthreshold X‘x!s Burst not allowed ,‡‡‡‡‡‡WWW#~”} aeraeƒrate ’ xurstƒthreshold ‚X‘x!s Burst not allowed ,‡‡‡‡‡‡WWWW#~”W aeraeƒrate ’ xurstƒthreshold Mx!s Burst not allowed ,‡‡‡‡‡‡WWWW#~”W aeraeƒrate ’ xurstƒthreshold Mx!s Burst not allowed ,‡‡‡‡‡‡WWWW#~”W aeraeƒrate ’ xurstƒthreshold Mx!s Burst not allowed ,‡‡‡‡‡‡WWWW#~”W aeraeƒrate ’ xurstƒthreshold Mx!s Burst not allowed ,‡‡‡‡‡‡WWWW#~”W aeraeƒrate ’ xurstƒthreshold Mx!s Burst not allowed ,‡‡‡‡‡‡WWWW#~”W aeraeƒrate ’ xurstƒthreshold Mx!s Burst not allowed ,‡‡‡‡‡‡WWWW#~”W aeraeƒrate ’ xurstƒthreshold Mx!s Burst not allowed ,‡‡‡‡‡WWWW#~”‚ aeraeƒrate ’ xurstƒthreshold X‘x!s Burst not allowed ,‡‡‡‡WWWWW#~”X aeraeƒrate ” xurstƒthreshold ‘x!s Burst not allowed ,‡‡‡WWWWWW#~”† aeraeƒrate ¥ xurstƒthreshold ‚X‘x!s Bursti> allowed ,‡‡W ,‡ ‡WW WWW WW WW WW‡ ‡#~ #~”† ”† ae aera raeƒr eƒrate ate ¥ xu xurst rstƒth ƒthres reshol hold
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
→
→
→
→
→
→
→
→
→
→
→
→
→
→
→
→
‡Mx!s WMx!s WMx!s WMx!s WMx!s Mx!s Mx!s Mx!s Mx!s Mx!s Mx!s Mx!s WMx!s WMx!s ‡Mx!s ‡Mx!s /(0% ‡# ‚~
W WW W† W‡ WX W~ W‚ W} Wp † †
‚X‘x!s ,‡WWWWWW‡‡#~”† ‚X‘x!s ,WWWWWW‡‡‡#~”† ‚X‘x!s ,WWWWW‡‡‡‡#~”X ‘x!s ,WWWW‡‡‡‡W#~”X ‘x!s ,WWW‡‡‡‡WW#~”X ‘x!s ,WW‡‡‡‡WWW#~”X ‘x!s ,WW‡‡‡‡WWWW#~”~ WX‘x!s ,WW‡‡‡‡WWWWW#~”‚ X‘x!s ,WW‡‡‡‡WWWWWW#~”} ‚X‘x!s ,WW‡‡‡‡WWWWWW#~”} ‚X‘x!s ,WW‡‡‡‡WWWWWW#~”} ‚X‘x!s
Burst is allowed aeraeƒrate ¥ xurstƒthreshold Burst is allowed aeraeƒrate ¥ xurstƒthreshold Burst is allowed aeraeƒrate ” xurstƒthreshold Burst (ot allowed aeraeƒrate ” xurstƒthreshold Burst not allowed aeraeƒrate ” xurstƒthreshold Burst not allowed aeraeƒrate ” xurstƒthreshold Burst not allowed aeraeƒrate ’ xurstƒthreshold Burst not allowed aeraeƒrate ’ xurstƒthreshold Burst not allowed aeraeƒrate ’ xurstƒthreshold Burst not allowed aeraeƒrate ’ xurstƒthreshold Burst not allowed aeraeƒrate ’ xurstƒthreshold Burst not allowed
→
→
→
→
→
→
→
→
→
→
→
‡Mx!s ‡Mx!s WMx!s WMx!s WMx!s WMx!s WMx!s WMx!s Mx!s Mx!s Mx!s
'[3?%:J/0 ?%:J/0C0 C0%J5L9 %J5L9%: %: $;': '; :Q'&4 Q'&4%1%&7%(4 %1%&7%(4=/E7C0 =/E7C0'1 '1EGD V V EGD%1& %1& ‡M!xs J(&F:FE% ~ 3 (%GD (%GD 5%$&3 V V 5%$&31+0 1+0(7%(4 (7%(4=/E7C0 =/E7C0'1 '1E5%$ E5%$ ,3(%GD (%GDGD V VD ƒX ƒX 0%'6 %'6+&%C0 +&%C0'1 '1EED V V EED: ,aeraneƒrate (0 ':$9 ':$9% xurstƒthreshold Burst 5F'()*%+J/0J0 J0%1& %1& L) L)7GD V V 7GD$8$%/(7>0 %8 /(7>0 ,xurstƒliit ,xurstƒliit ” ‡M 19 '() '()*%+J/0 *%+J/0J0 J0%1& %1& L) L)7GD V V 7GD$8$%/(7>0 %8 /(7>0 (6 (6 R(76 (76L%1& L%1&&3 V V &31+0 1+0( 7%(4=/E75FK&6 =/E75FK&6?E7ELK ?E7ELK( WM ,liitƒat >K&; ': V V': 5mLm LmL3 L3(%GD (%GDGD V VG ~ D ~ KJ/195m5(m (m mL3 L3(%GD (%GDGD VG VD } KmL 3(%GD (%GDGD V VG WW D WW
EL5(>191D1G&%v GD &%v$3 V V $3L ,Mx!s +6':9 ':9%L %L $%&&0%L %L Si!le ueue 8 %/&6 %/&6?58 ?58%$6 %$67(74 7(7437G4 73 G4>E'(+4 >E'(+4J('L4 J('L4$& $& ,Office Network ตัวอย ตัวอยาง าง +0'L$%&58 'L$%&58%$6 %$67(74 7(7437G4 73 G4&; V V &;'L>E'(+4 'L>E'(+4G6G RL/17J(&; 6L/17J(&;'C9 'C9%: %: ,pW.~}.WWW.#W‡ J/0 <&4 <&4(74 (74337G4 7G4J0 J0L%(&9 L%(&91 1 $6( X Mx 5%$%1+0 'L$%&<(F(8 'L$%&<(F(8%J/0 %J/0&0 &0%L %L Si!le ueue 19 J9 J93[D[3 D 567&&(74 7&&(7437G4 73 G4>K:6 >K:6L<+9 L<+9EF>E4 EF>E4' '(G4 (G4 ,(D V V ,(D>19 >19J9 J9'(Q '(QK+4 K+48%/&6 %8 /&6?+6 ?+6':9 ':9%L(D %L(D R 1.
E3$GD V V $GD1( 1( ueues Qm V VQmL5F<7L/(0 L5F<7L/(0%+9 %+9%L %L ueue -ist Cm R(1% (1%
2.
J(/(0%+9 %+9%L %L Si!le ueue -ist_ E3 $GD V V $GD Ž Ž 2; V V 2;'&0 '&0%L %L Si!le Si!le ueue ueue J/19
3.
+6 RL; V V L;'3 '3 ,'F>&$>70 >70GD V VGC0 D C0%J5 %J5 70 '$>705% 5% $E3+4 +4 <+9 <+90%>19 %0 >191D19D %GD V V %9 GD+0+'L$%&$ 0'L$%&$J/0 J/02214 23 14C0 C0%>K %>K =7:1D/(9 /(9:K :K( k”kiloxits ”kiloxitsj_j_ M”eaxits ”eaxitsjj 9( 0%+0 %+0'L$%& 'L$%&
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% ~# ‚~
$8%/(7K %/(7K( X.XM +0'LJ9 'LJ999%K %K( XX XXkk
E3$K) $K)1 O‘ O‘ 2; 2; V V'?6 '?6(Gm (Gm$K $K('6 ('6(&5$%&&0 5$%&&0%L3 %L3 +6':9 ':9%L %L $%&&0%L %L Si!le ueue 8 %/&6 %/&6?58 ?58%$6 %$67(74 7(7437G4 73 G4=g+4 =g+4KE%:G%L KE%:G%L ,\estination Host
4.
ตัวอย ตัวอยาง าง +0'L$%&58 'L$%&58%$6 %$67(74 7(74337G4 7G4$%&C0 $%&C0%m %mL L?>Q+4 ?>Q+4 www.susethailand.co www.susethailand.co 5%$%1+0 'L$%&&3 V V 'L$%&&31<&$+0 1<&$+0'L& 'L& 0$9$9'(9 '(9% =g+4=71((1 =71((1?>Q+4 ?>Q+41D1/1%:EC>'2D /D 1%:EC>'2D<'77&?'&4 <'77&?'&4'F>& 'F>& J/0+&5'?=7:J0 +&5'?=7:J08%6 %8 6 V VL !in >K:6L www.susethailand.co www.susethailand.co J(GD V J(GD V( R>'2D >D '2D<'77&; <'77&;' WW.XX.~}.X 1; 'G&%?>'2D V V'G&%?>'2DK$ 7>K$;'$%&&0 ;'$%&&0%L3 %L3 1. 2.
E3$GD V V $GD1( 1( ueues ueues J(/(0%+9 %+9%L %L Si!le ueue -ist_ E3 $K) $K)1 Ž Ž 2; V 2; V'&0%L3 %L3J/19 J/19 +6 RL; V V L;'3 '35%$(6 5%$(6 R(E3 (E3$GD V V $GD'2D /1%:EC>'2D<'77& <'77&
3.
E3$K) $K)1 O‘ ?6(Gm (Gm$9 $9%K %K('6 ('6(& (&5 G)$G&%v $G&%v$''$
+6':9 ':9%L %L $%&&0%L %L Si!le ueue 8 %/&6 %/&6?58 ?58%$6 %$67(74 7(7437G4 73 G4=E6 =E6?'123 ?'123+'&4 +'&4 70 70: : Burst
2.
E3$1( $1( ueue ueue J(/(0%+9 %+9%L %L Si!le ueue -ist_ E3 $ Ž Ž 2; V V 2;'&0 '&0%L3 %L3
3.
GD VGD V
1.
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% }# ‚~
EE62[4 2[4GD V VG>70 >D 70;'; %1%&J0(7437G4 73 G4'6'2=/E770 =/E7>70 XWk XWk J(&F:FE% X 3 (%GD (%GDC'L(%œ3 C'L(%œ3$% $% ,clock !eriod
Packet Manlin Packet anlin ; ' $%&G8%&; V V %&;'L/1%:C0 'L/1%:C0'1 '1EJ(9 EJ(9(g77'&4 (g77'&4 C'L<2$$ C'L<2$$+ ,Mark Packet 8 %/&6 %/&6?(8 ?(8%1%J0 %1%J0K&F=:(4 K&F=:(4 9( $%&$8%/(70 %/(70(G%L9 (G%L9L+9 L+9'<2$$ '<2$$+ ,route taxle /&; '3 '3 ,—ueues J($%&+673 73(J5G8 (J5G8% ark !acket +0'L8 'L8%(m V V %(mLm LmL %1%1%& {PU 70: : :3 V V:3L1D L1D$%&G8 $%&G8% ark !acket :'F$ 5F:3 V V 5F:3LJ0 LJ0G&6 G&62:%$& {PU :'F+%11%70 : : <+90%') %0 ')K$&]4 K$&]41D1D {PU <&L2'': 9 <&L2'': 9
ŸŸŸ (; R'/%6 '/%67>K5F'0 7>K5F'0%L'3 %L'3L$%&'(v L$%&'(v$5%$ $5%$ `outerOS '&46 V V6( ~ ŸŸŸ
+6':9 ':9%L %L $%&G8% Packet Manlin J( Manle >&4'EE4 >&4 'EE4 1.
$%&G8% Manle 5F+0'LG8 'LG8%$%&&0 %$%&&0%L$Z>&4 %L$Z>&4'EE4 'EE4CmC R(1%J/19 m(1%J/19 C0 C0%>KGD V V %>KGD1( 1( IP IP ’ ’ ˆirewall
2.
E3$GD V V $GD
ตัวอย ตัวอยาง าง &%+0'L$%&&F?) 'L$%&&F?)G&%v G&%v$5%$ $5%$??&%&4 ??&%&4Q'&4 Q'&4G RL/17 L6 /17 ,KE%:G%L2'&4+ }=7:vE+'&4 E+'&42%F<2 2%F<2$ $+GD V V +GD +&L$6( 2&%F<2$ $+GD V V +GD''$5%$ ''$5%$??&%&4 ??&%&4Q'&4 Q'&4>K:6 >K:6L<'2E3 L<'2E36 6 V V(Q'&4 (Q'&43KE%:G%L 3 KE%:G%L '%5K(2'&4+'; V V +';( ( >70 9 9( †W} $%&1%&4<2$$ <2$$+G&%v +G&%v$C%''$ $C%''$ /&;'$%&9 '$%&9LC0 LC0'1 '1E''$>K:6 E''$>K:6LC0 LC0%L('$ %L('$ ,Outside 5F$8 %/(7 %/(7 chainsj K( !reroutin
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% # ‚~
3.
4. 5.
E3$GD V V $GD
E3$K) $K)1 O‘ O‘ 2; 2; V V'?6(Gm (Gm$ rule K('6 ('6(&5$%&&F?) 5$%&&F?) ark ark connection 5%$(6 R(&%+0'L$%& 'L$%& ark <2$ $+GD V V +GD$3 $37Cm 7Cm R(5&3 (5&3L ,>19+0+'L$%&<2 '0 L$%&<2$ $+G6 +G6 RL/17 L/17 ;'2%F<2 '2%F<2$ $+GD V V +GD+&L$6 +&L$6? ark connection GD V VGD &0 &0%LCm %LCm R($9 ($9'(/(0 '(/(0%(D %(D R ,qexBrowsinPort}{onnectio ,qexBrowsinPort}{onnections ns E3$GD V V $GD1( 1( IP IP ’ ’ ˆirewall ˆirewall ’ ’
6.
GD VGD V19:'1J/0 :'1J/0; V V ;'1+9 '1+9'$6 '$6?KE%:G%LC0 ?KE%:G%LC0%L('$ Qm %L('$ Qm V VL9 L9%7D %7D'E+4 'E+45F+3 5F+3 $GD V V $GDQ Q$? $?'$Q4 '$Q4 Passthrouhj ': 9 9 ': ,:'$J/01D1$%& $D %& ; V V'1+9 ; '1+9'$6 '$6?KE%:G%LC0 ?KE%:G%LC0%L('$>70 %L('$>70
K('6 ('6(& (&5C6 5C6 R(+'($%&G8 (+'($%&G8% Packet Manlin 5%$(6 R(&%%1%&58 (&%%1%&58%$6 %$67$%&J0 7$%&J0L%((74 L%((7437G4 73 G4>70 >70=7:$%&G8 =7:$%&G8%3 %3 ,ueue Tree Note" Manle >&4'EE4 'EE45F>19 5F>19G8G%L%(1; V V 8%L%(1;' connection trackin K ( off ,Kv7$%&J0 7$%&J0L%( L%( $%&&0%L %L anel rule 58%((1%$K&F3 %((1%$K&F3G[3 ¦ G[3 ¦%25FCm %25FCm R(': 9 9 (':$6$?6 {PUƒintensie 2'>/1
$%&567E8 7E8%76 %76?%18 ?%18%6 %6*C'LG&%v *C'LG&%v$ ,Traffic Prioriti…ation Prioriti…ation 9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% W# ‚~
Traffic Prioriti…ation ; ' $&F?($%&?&3/%&567$%&(74 7$%&(7437G4 73 G4 /&;' Bandwidth Bandwidth Manaeent Manaeent =7:3[D[$%&56 D$%&567E8 7E8%76 %76? %18%6 %6*C'LG&%v *C'LG&%v$ ,Prioriti…e Traffic 8 %/&6 %/&6?G8 ?G8%&F?? %&F?? oS ,uality of Serice ?( OSI =17E E:'&4 ‚ E:'&4 ‚ /&;' GD V VGD&D&D:$$6 :$$6(6 (6 V V( ( 9% -‚ -ayer -ayer Qm V VQmL5FK L5FK($%&?&3 ($%&?&3/%&567$%&J(&F76 7$%&J(&F76?6 ?6(<'22E3 (<'22E36 6(<2$$ (<2$$+ +6':9 ':9%L %L $%&567E8 7E8%76 %76?%18 ?%18%6 %6*C'LG&%v *C'LG&%v$ $%&567E8 7E8%76 %76?%18 ?%18%6 %6*C'LG&%v *C'LG&%v$?( $?( `outerOS 07770 $>70 W W (37 1. •oice tele!hone traffic " G&%v $$%&; V V $$%&;'%&70 '%&70:D :D:LG%L=G&6 :LG%L=G&62G4 2G4 9( ?&3$%& $%& •oIP ,$%&=G&62G4 2G49%( %9 ( '3(G'&4 (G'&4( (+ Qm V VQmLK LK(G&%v (G&%v$?&D $?&D:E>G14 :E>G14 <'22E3 <'22E36 6( 9( SIP_ Sky!e_ IA E4GD V VG1DD1DC(%7J/*9 2. \ownload " G&%v $C%C0 1; V V 1;'9 '9L<:$G&%v L<:$G&%v$>70 $>7019FE' FE' ,delay deliery 0 %?&3 %?&3/%&56 /%&567$%&>19 7$%&>197D7D5FG8 5FG8%J/0 %J/01D1)D ]%2C'LD )]%2C'LD:LGD V V :LGD>70 >70&6&?>19 ?6 >19 >70))]%2 ]%2 G8%J/0 %J/0$3 $3(K (K*/%&F/9 */%&F/9%L$8 %L$8%E6 %E6L(G(%$3 L(G(%$37$%&7D 7$%&7DE:4 E:4 /&; /&;'D 'D:LC%7 :LC%7 /%: K (+0 (+0( 76L(6 L(6 R(2; V V (2;'K&F3 'K&F3G[3 G[3%2C'L %2C'L $%&567$%&&; 7$%&&;'C9 'C9%:GD V V %:GD7D7D 5m 5mL&56 L&567E8 7E8%76 %76?J/0 ?J/0 oice oice traffic 1D %18 %18%6 %6*1%$$9 *1%$$9%$%&C0 %$%&C0%m %mLC0 LC0'1E ,data traffice 0 $Q+>0GD V VG/1%:EC D/1%:EC } G6 RL'6 L'62=/E7
+6':9 ':9%L %L $%&&0%L3 %L3 '2D <'77&K <'77&K( WW.XX..} E'(+4 %L>E'(+4>Q+4 >Q+4 ,`outer ,`outer •oIP ateway 1.
&3 V V&31+0 1+0(J/0 (J/0&0 &0%L %L Manle rule 8 %/&6 %/&6?G&%v ?G&%v$K $K%/1%: %/1%: ,•oIP ateway KGD V V >KGD1( 1( IP IP ’ ’ ˆirewall
E3$GD V V $GD
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% ‡# ‚~
E3$GD V V $GD
2.
Manle Manle rul rule )7G0 7G0%: %: 5FG8%<1 %<1 connection ark J/0 +&L$6 +&L$6? •OIP
E3$GD V V $GD
+3 $Q $Q$? $?'$Q4 '$Q4 Passthrouhj ''$ 2; V V'>19J/0 J/01D1$%& D$%& rearked <2$$ + 3.
671% 71% J/0G8G%$%&&0 8%$%&&0%L %L Si!le Si!le ueue ueuess J/19 W W 3 3GD V V GD 8%/&6 %/&6? •oIP KGD V V >KGD1( 1( ueues $8%/(7 %/(7 Nae" •OIP Traffic
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% ~# ‚~
E3$GD V V $GD
4.
RC6(+'()7G0 7G0%: %: ;'&0 '&0%L3 %L38 8%/&6 %/&6?G&%v ?G&%v$G6 $G6 RL/17 L/17 /&;'$8 '$8%/(7 %/(7 !acket !acket ark ark J/0 J/088%/&6 %/&6?<2$$ ?<2$$+GD V V +GD>19 >19>70 >70 ark ark K( noƒarkj /&;'<2$$ '<2$$+GD V V +GD>19 >19C0%$Z %$Z anled
E3$GD V V $GD< G? Adanced Adancedjj
K('6 ('6(& (&5$%&Q+'6 5$%&Q+'6?&F?? ?&F?? oS GD V VGDJ/0 J/0>70 >701%2; V V 1%2;'K&F3 'K&F3G[3 G[3%2 %2
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% }# ‚~
P{ Š Per {onnections ueuin P{ ,Per {onnection ueues K(/(m K (/(m V VLJ(3 LJ(3[D[?&3 D?&3/%&56 /%&567$%&(74 7$%&(7437G4 73 G4GD VG V1D ': 9 9 'D :J/0 J/01D1DK&F3 K&F3G[3 G[3%2 %2 3[D[ P{ D P{ ;'$%&9 '$%&9L (74337G4 7G4''$K ''$K(9 (9(G9 (G9% % $6( /&;'?>7(%13 '?>7(%13$G&%v $G&%v$ ,dynaic traffic G6 RLG&%v LG&%v$'6 $'6?=/E7'2D '>'2D<'77&C'L=g+4 <'77&C'L=g+4 ,xandwidth ,xandwidth !er host Qm V VL5FG8 L5FG8%J/0 %J/0 0J0 J 0<+9 <+9EF( EF( 1D(74 (7437G4 73 G4ED V V ED:(G9 :(G9% % $6( 5F>191D1D 0J0 J 0>/(1D >/(1D(74 (743G74 G3 741%$$9 1%$$9% % 0J0 J0('; V V (';( ( $&]DGD V VG1DD1D 0J0 J 01D1$%&J0 $D %&J0L%((74 L%((7437G4 73 G42D 2D:L :L User IP 7D: : 0J0 J0((6 ((6 R(5F%1%&J0 (5F%1%&J0L%((74 L%((7437G4 73 G4%1& %1&'6 '6?=/E770 L) L )7G9 7G9%GD V V %GD$8$%/(7>0 %8 /(7>0 3[D[ P{ D P{ %1%&1%($6?$%&J0 ?$%&J0 -‚ -‚ oS 70:$%&56 :$%&567E8 7E8%76 %76?%18 ?%18%6 %6*C'L<2$$ *C'L<2$$+<+9 +<+9EF?&3 EF?&3$%& $%& ,traffic !riority 2; V V 2;'5FG8 '5FG8%J/0 %J/0$%&?&3 $%&?&3/%&56 /%&567$%&(74 7$%&(7437G4 73 G41D1K&F3 KD &F3G[3 G[3%2 %2 +6':9 ':9%L %L ƒ $%&58%$6 %$67(74 7(74337G4 7G4 ,liited ,liited xandwidth 1)1+3 1+39%1D %9 1D(74 (7437G4 73 G48%/&6 %8 /&6?%1& ?%1&7%(4 7%(4=/E7': 9 9 =/E7': WMx WMx ,W‡}k!xs =7:&%5FJ0 3[D[3 $%&58 D$%&58%$6 %$67(74 7(7437G4 73 G4 0J0 J 0<+9 <+9EF( EF( J/01D1D(74 (7437G4 73 G4J0 J0L%(>70 L%(>70>19 >19$3 $3( WX~k '[3?%: ?%: ;' ƒ 1)1+3 1+39%1D %9 1D585%(( %8 (( 0J0 J0585%(( %8 (( W ( <+9EF(5F1D EF(5F1D(743G74 G3 74L) L )7GD V V 7GD WX~k WX~k ƒ 1)1+3 1+39%1D %9 1D585%(( %8 (( 0J0 J0585%(( %8 (( ‡ ( <+9EF(5F1D EF(5F1D(743G74 G3 74L) L )7GD V V 7GD WX~k WX~k ƒ 1)1+3 1+39%1D %9 1D585%(( %8 (( 0J0 J0585%(( %8 (( W ( <+9EF(5F1D EF(5F1D(74 (743G74 G3 74L) L )7ED V V 7ED:GD V V :GD Wk Wk 76L& L&K
+6':9 ':9%L %L W Š ?>19 585%$6 %8 $67(74 7(7437G4 73 G4 ,unliited ,unliited xandwidth 1)1+3 1+399%1D %1D(74 (7437G4 73 G48%/&6 %8 /&6?%1& ?%1&7%(4 7%(4=/E7': 9 9 =/E7': WMx WMx ,W‡}k!xs 1; V V'1D '1D 0J0 J 02D 2D:L(7D :L(7D:5F%1%&7%(4 :5F%1%&7%(4=/E7>70 =/E7>70 %1&+ +1 WMx <+90%1) %0 1)1+3 1+31D1D 0J0 J0 W W ( 5F$56 $567&&=7:$%&<&4 7&&=7:$%&<&4(74 (7437G4 73 G4 '[3 '[3?%: ?%: ;' ƒ 1)1+3 1+39%1D %9 1D585%(( %8 (( 0J0 J0585%(( 8%(( ( 5F%1%J0%1& %1&J($%&7%(4 J($%&7%(4=/E7(74 3G74 G3 74L) L )7GD V V 7GD WMx WMx ƒ 1)1+3 1+39%1D %9 1D585%(( %8 (( 0J0 J0585%(( 8%(( ‡ ( <+9EF(5F1D EF(5F1D(74 (743G74 G3 74L) L )7GD V V 7GD XWk XWk ƒ 1)1+3 1+39%1D %9 1D585%(( %8 (( 0J0 J0585%(( 8%(( W ( <+9EF(5F1D EF(5F1D(74 (743G74 G3 74L) L )7ED V V 7ED:GD V V :GD Wk Wk 76L& L&K
76L(6 L(6 R( P{ 5mLK LK(3 (3[D[$%&56 D$%&567&&(74 7&&(7437G4 73 G488%/&6 %/&6?$%&G8 ?$%&G8% oS G8%J/0 %J/0$%&?&3 $%&?&3/%&56 /%&567$%&(74 7$%&(7437G4 73 G4>70 >70':9 ':9%L1D %L1DK&F3 K&F3G[3 G[3%2 %2
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% W# ‚~
+6':9 ':9%L %L $%&&0%LQ3 %LQ31Kv 1Kv £E3 E38%/&6 %/&6?58 ?58%$6 %$67(74 7(74337G4 7G4 =7:J0 =7:J03[D[3 P{ D P{ +6':9 ':9%L(D %L(D R&%5F&0 &%5F&0%L %L si!le si!le —ueue —ueue =7:J0 =7:J0&&K? K ? P{ 8%/&6 %/&6??) ??)158 158%$6 %$67(74 7(7437G4 73 G4 1. &0%L3 %L3J/19 J/198%/&6 %8 /&6?'6 ?'62=/E7
5%$&K `outerOS '&46 V V(6 ~. 5F&0%L3 %L3& &K? K? !c— '62=/E7
&0%L3 %L3J/19 J/198%/&6 %8 /&6?'6 ?'62=/E7 2=/E7 E3$K) $K)1 Ž Ž
Ty!e Nae " ‘ind " `ate " {lassifier " 3.
u!load /&;'; V V ';''F>&$ ''F>&$>70 >70GD V VG'7E0 D '7E0'L 'L !c— W}k $8%56 %567%1& 7%1&8 8%/&6 %/&6?'6 ?'62=/E7 2=/E7 Src.Address G&%v$5%$=g+4 $5%$=g+4+0+(G%LC%'6 (0 G%LC%'62=/E7 2=/E7
&0%L3 %L38 8%/&6 %/&6?7%(4 ?7%(4=/E7 =/E7 E3$K) $K)1 Ž Ž
Ty!e Nae " ‘ind " `ate " {lassifier "
download /&;'; V V ';''F>&$ ''F>&$>70 >70GD V VG'7E0 D'7E0'L 'L !c— W}k $8%56 %567%1& 7%1&8 8%/&6 %/&6?7%(4 ?7%(4=/E7 =/E7 Src.Address G&%v$5%$=g+4 $5%$=g+4KE%:G%LC%7%(4 KE%:G%LC%7%(4=/E7
0%$8 %$8%/(7 %/(7 `ate G9%$6 %$6? #j 5FK($%&<&4 ($%&<&4(74 (7437G4 73 G4 G8%J/0 %J/0>E'(+4 >E'(+41D16D 79 76 9((74 ((7437G4 73 G4ED ED:G9 :G9% % $6( 0%1D %1D 0J0 J 0L%(( L%(( 7D: : 0J0 J0( R($ (6 $5F%1%&J0 5F%1%&J0(74 (7437G4 73 G4>70 >70+ +1 Qm V VQmL<+$+9 L<+$+9%L5%$+6 %L5%$+6':9 ':9%LGD V V %LGD$8$8%56 %567(74 7(7437G4 73 G4>0 >0GD V VG W}k#W}k D W}k#W}k +9' ' 0J0 J0L%( L%( /E6L5%$GD V V L5%$GD>70 >70&0 &0%L3 %L3$8 $8%56 %567(74 7(7437G4 73 G4G6G RLC%'6 L6 C%'62=/E7K5FK 7>K5FK($%&&0 ($%&&0%L %L si!le —ueue 8 %/&6 %/&6? J0L%(?) L%(?)1(74 1(7437G4 73 G4 =7:$8 =7:$8%/(7 %/(7 taret address G6 RL&; L&;'C9 'C9%: %: 9( pW.~}. pW.~}..# .#W‡ W‡
/(0% WW# ‚~
4.
E3$GD V V $GD
5.
E3$GD V V $GD
+&L ueue Ty!e E; Ty!e E;'$; V V '$;'GD V V 'GD>70 >70&0 &0%LCm %LCm R( K('6 ('6(& (&58 58%/&6 %/&6?+6 ?+6':9 ':9%L$%&&0 %L$%&&0%L %L P{ 3 E4 '>E4' '(+4 (+4>'2D >'2D<'77&>70 <'77&>70 9 9( $8%/(7 %/(7 Taret address K ( pW.~}.. K (+0 (+0(
?GGD V V Š &; V V ?GGD &;'L1; 'L1;'8 '8%/&6 %/&6? ? 077
=K&<$&1:G3G3E3E+D+3 RD 9 9( Btest Serer G14 :E>G14&F/9%L') %L')K$&]4 K$&]4 `outerOS ,Serer side $6 ? {lient {lient side de /&;' qindows P{ $6?') ?')K$&]4 K$&]4 `outerOS `outerOS E6$b]F$%&G8 $b]F$%&G8%L%(; %L%(;'1; V V '1;'>E4 '>E4' '(+49LG&%v L9 G&%v$>K:6 $>K:6LQ3 LQ3&4&'&4 4 '&4 | ¢ ¢ |LQ3 LQ3&4&4'&45FG8%$%&G7'?%1& %$%&G7'?%1&C%'6 C%'62=/E7 E4 L>E4' '(+45FK 5FK($%&G7'?%1& ($%&G7'?%1&C%7%(4 C%7%(4=/E7 =/E7 =7:5F<7LE26([4?&D ?&D:E :E >G14
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% W‡# ‚~
+6':9 ':9%L %L $%&G7'?K&F3G[3 G[3%2(74 %2(7437G4 73 G4C'LE3 C'LE3L$4 L$4&F/9 &F/9%L'L %L'L `outerBOA`\ =7:K (3 (3[D[GD V VDGD $+0 $+0'L
Bandwidth Test Utility 1.
2.
3. 4.
9(C'LQ3 (C'LQ3&'&4 4 '&4+0+0'L'(v 'L'(v$Kv $Kv7J0 7J0L%( L%( Btest Serer ,7D 'E+4 'E+4 enaxle enaxle ': 9 9 ':
E;'$ '$ naxlej E4 >E4' '(+4G7'? G7'? /E6L5%$Q+'6 L5%$Q+'62| ¢ ¢ 2|LQ3 LQ3&4&'&4 4 '&4&%G4 &%G4+'&4 +'&4& &5 671%GD V V 71%GD| ¢ ¢|L>E4 L >E4' '(G4 (G4&%G4 &%G4+'&4 +'&4 GD V VGD1( 1( Tools Toolsjj ’ Bandwidth Bandwidth Testj Test j
Test To" \irection" User # Password"
K'(>'2D '(>'2D<'77&| ¢ ¢ '77&|LQ3 LQ3&4&4'&4&%G4+'&4 +'&4 $8%/(7K %/(7K( xoth K'(: '(:Q'&4 Q'&4(1 (1
8%/&6 %/&6? ?L$4 L$4 V V6(+6 (+6E; E;'$'; V V '$';( ( %1%&$8%/(7>70 %/(7>70+%1+0 +%1+0'L$%& 'L$%&
Monitorin Tools Monitorin Tools &; V V &; 'L1; 'L1;'| '|%1'L&F??&; %1'L&F??&;'C9 'C9%: %: 'D$ $L$4 L$46 V6(GD V VGD&F??KZ3 &F??KZ3?6?+3+6 $%&&%G4 3$%&&%G4+'&4 +'&4'; V V'( (; >191D1 `outerOS D `outerOS %1%& <7L$&%G&%v$?&D $?&D:E>G14 :E>G14C'L<+9 C'L<+9EF'3 EF'3(+'&4 (+'&4Q>70 Q>70':9 ':9%LL9 %LL9%:7%: %:7%: =7:<7L&%:EF'D:7'6 :7'6+&%&6 +&%&6?ƒ9 ?ƒ9LC0 LC0'1 '1E Transit ,Tz C>70 >C>70&&:3 V V :3LCm LCm R( C6 R(+'($%&<7LEG&%v (+'($%&<7LEG&%v$?&D $?&D:?>G14 :?>G14 E3 E3$C%GD V V $C%GD'3'(+'&4 3(+'&4Q Q ’ E;'$ '$ !ro!erties !ro!ertiesjj ’ E3$GD V V $GD
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% W~# ‚~
Torch Tools :+3+3E3E+3+3 R3| |%1'LG&%v %1'LG&%v$?&D $?&D:E>G14 :E>G14
+6':9 ':9%L %L $%&J0&; V V &;'L1; 'L1;' Torch /%%/+) CK >CK*/%&; */%&;'C9 'C9%:0 %:0% J(+6':9 ':9%L(D %L(D R11) 11)+3+93 %&%K %9 &%K( 0J/0 J/0?&3 ?&3$%&'3 $%&'3(G'&4 (G'&4( (+ ,Internet Serice Proider ?9 ':&6 ':&6 RL>70 L>70&6&?=G&6 ?6 =G&62G4 2G45%$E 5%$E$0 $0%?9 %?9( +9'9 '9%'3 %'3(G'&4 (G'&4( (+0 +0% /9: : G9%(D %(D R:6:L>19 L6 >192'J(?%L&6 2'J(?%L&6 RL ƒW 6(G%L (G%L 0J/0 J/0?&3 ?&3$%&:6 $%&:6L/%%/+) L/%%/+)>19 >195'F1; V V 5'F1;'E 'E$0 $0%& % 0&m$3 $m 37/6 7/6L E(4 L1''(>E(4 76L(6 L(6 R(?; (?; R'L+0 'L+0(J($%&<$0 (J($%&<$0>CK >CK*/% */% 0J/0 J/0 ?&3$%&'3 $%&'3(G'&4 (G'&4( (++0 ++0'L| 'L|%1'L&F??&; %1'L&F??&;'C9 'C9%:J/0 %:J/0G&%?$9 G&%?$9'(9 '(9%K %K(GD V V (GD&; &;'C9 'C9%:C'L&% %:C'L&% /&;'&; '&;'C9 'C9%:%:J(C'LE %:%:J(C'LE$0 $0% <+9 0%1; V V %1;'5%FEL>K5(& '5%FEL>K5(& 09%K %9 K*/%9 */%9%K %K(GD V V (GD&; &;'C9 'C9%:%:J(C'LE %:%:J(C'LE$0 $0%'L %'L &; V V &;'L1; 'L1;' Torch 5F9:J/0 :J/0 077 & %1%5%$'F>& C6 R(+'(J/0E3 E3$GD V V $GD1( 1( Tools Tools ’ ’ E;'$ '$ Torch Torchjj
5%$&K ,+6':9 ':9%LK %LK*/%&; */%&;'C9 'C9%:%:J(C'LE %:%:J(C'LE$0 $0%% J('E61(4 1(4 Tz `ate &%%1%&E3 `ate &%%1%&E3$K) $K)1%1/ED V V 1%1/ED:1D :1D REL EL 2; V V 2;'J/0 'J/0&D:L :L E8%76 %76?'6 ?'6+&%G&%v +&%G&%v$ $L) L)7K 7K(E8 (E8%76 %76?<&$>70 ?<&$>70 5F/ 5F/(9 (9%>E4 %>E4' '(+4 (+4>'2D >'2D<'77& pW.~}.WWW. J0 G&%v G&%v$m $mL .p Mx!s J($%&+37+9 7+9'; V V ';'%&K&FG+&D '%&K&FG+&D113 V V 113L &; V V &;'L1; 'L1;' Torch %1%&+&5'?7 !riate !riate IP network /E6L>&4 L>&4'E4 'E4C'LE C'LE$0 $0%>70 %>70 9%>E4 %>E4' '(+4 (+4J7$8 J7$8%E6 %E6L&6 L&6?1; V V ?1;'?6 '?6(G3 (G3L': 9 9 L': 9 9( E3K2EL_ K2EL_ 7(+&D_ /(6L /&;''; V V '';( ( ?(?>Q+4 ?>Q+4 70 %>7023235(4 5 (4)]%2KJ0 '>KJ0 0J/0 J /0?&3 ?&3$%&50 $%&50%'; V %'; V( $&]D7D 7D:$6 :$6(8 (8%/&6 %/&6?&; ?&;'C9 'C9%:%:J(C'L&%'L %:%:J(C'L&%'L 07770 >70$E9 $E9%1% %1% =7:'%55F5%FEL>Km L$6 L$6?9 ?9%&; V V %&;'LC'L: 'LC'L:Q'&4 Q'&4>70 >70&6&?'() ?6 '()*%+/&; *%+/&;'>19 '>19 70 >70
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% ([*% =2[3?)?)+&
/(0% W}# ‚~
Traffic „ra!hin Traffice „ra!hin ; 'K 'K(: (:+3+3E3E+3+3 R3&; V V &;'L1; 'L1;'| '|%1'L&F??&; %1'L&F??&;'C9 'C9%:GD V V %:GD1? 1?&]4 &]4GD V VGDJ0 J0$6$6(G6 V V=E$ =E$ >1999%5FK %5FK( ( 0J/0 J/0?&3 ?&3$%& $%& '3(G'&4 (G'&4( (+ /&;'&; '&;'C9 'C9%:%:J('L4 %:%:J('L4$& $& :9'158 '158%K %K(+0 (+0'L1D 'L1D&; V V &;'L1; 'L1;'(D '(D R>0 >0+&5'?3 +&5'?3&%F/4 &%F/43 3+3+3G&6 G&62:%$&&; 2:%$&&;'C9 'C9%:GD V V %:GD$D V V $D: : $6?(74 ?(74337G4 7G4 G8 G8%J/0 %J/0 0&&9 LE%GD V V 9LE%GD1D1$%&(74 $D %&(7437G4 73 G4GD V VGDL) L )7 8%/&6 %/&6? ? 0J/0 J/0?&3 ?&3$%&'3 $%&'3(G'&4 (G'&4( (+ Traffic „ra!hin „ra!hin 16$5FK $5FK( &; V V &;'L1; 'L1;'GD V 'GD V5F'[3?%:J/0 ?%:J/0EE$0 $ 0%G&%?9 %G&%?9%E %E$0 $0%$8 %$8%E6 %E6LJ0 LJ0L%((74 L%((7437G4 73 G4G6G RL/17 6L/17 70 (>70 /&; /&;'9 '9LK LK( E3L$4 L$4 url url J/0EE$0 $ 0%8 %8%/&6 %/&6?+&5'?&%:EF'D ?+&5'?&%:EF'D:7>70 :7>70 C0 C0'1 '1E$&%5F E$&%5F$56 $567$ 7$?ELJ(2; ?ELJ(2; R(GD V (GD V$?C0 ?C0'1 '1E73 E73$4 $4>7&4 >7&4C'L') C'L')K$&]4 K$&]4 Mikrotik 76L(6 L(6 R($%&&0 ($%&&0%L$&%/E%: %L$&%/E%: '3(+'&4 (+'&4Q5F+0 Q5F+0'L8 'L8%(m %(mL; L;'G&6 'G&62:%$&C'L 2:%$&C'L {PU_ /(9 :%158 :%158% 0 ?>0 ('$5%$5F%1%&&0%L$&%<7L(74 %L$&%<7L(7437G4 73 G4J0 J0L%(70 >70'D'$70 D$70: : &3 V V&31+0 1+0('(v ('(v$2; V V $2;'Kv 'Kv7J0 7J0L%( L%( %1%&'(v$9 $9%( %( qinBoz /&;'9 '9%( %( qex interface E3 $GD V V $GD1( 1( Tools Tools ’ ’ „ra!hin „ra!hin
'(v$$&%J(%119 L>191D1'(v D '(v$
'G1GD V V >'G1GD'(v '(v$
Interface" all Allow Address" ...#
&0%L$&%G) %L$&%G)$'3 $'3(+'&4 (+'&4Q Q $8%/(7C'?C+$%&'() %/(7C'?C+$%&'()*%+3 *%+3 =7:%1%&&F?) =7:%1%&&F?)K K(>'2D (>'2D<'7&7/&; <'7&7/&;'K 'K(Q6 (Q6?( ?(+>70 +>70
$&]D/%$58 /%$58%$6 %$67$%&C0 7$%&C0%m %mLK LK(Q6 (Q6?( ?(+7D +7D: : 9( -AN ,pW.~}..#W‡ <+9 >19 >19+0+0'L$%&J/0 'L$%&J/0&; &;'C9 'C9%:'; V %:'; V( 9( qiˆi ,‚W.~..#W‡ ,‚W.~..#W‡ &%%1%&&0%L$Z>&4 %L$Z>&4'EE4 'EE4 8 8%/&6 %/&6?58 ?58%$6 %$67$%&'() 7$%&'()*%+=g+4 *%+=g+4J($%&7 J($%&7$&%>70 $&%>70 J($%&'(v$$%&56 $$%&567$ 7$?C0 ?C0'1 '1E$&%%1%&$8 E$&%%1%&$8%/(7$%&56 %/(7$%&567$ 7$?J(/(9 ?J(/(9:%158 :%158% ,C0'1 '1E$&%5FE?1; V V E$&%5FE?1;'Kv 'Kv7#Kv 7#Kv7 Mikrotik /&;'56 '567$ 7$??(2; ??(2; R(GD V V (GD737$4 $3 4 E3 E3$GD V V $GD
Si!le ueue" Allow Address" Store on \isk" Allow Taret""
&0%L$&%5%$3 %L$&%5%$3E3 E3+4 +4 ,Si!le ,Si!le ueue /&; '&0 '&0%LG6 %LG6 RL/17G6 L/17G6 RL/17 L/17 ,all >'2D<'77&/&; <'77&/&;'Q6 'Q6?( ?(+GD V V +GD'() '()*%+ $8%/(7$%&56 %/(7$%&567$ 7$?C0 ?C0'1 '1E '()*%+<'77&GD V V *%+<'77&GD+0+'L$%& '0 L$%& ,''K6 V ,''K6 V( Taret Address J( Si!le ueue ueue
9 91;1'?&3 '; ?&3/%&&F??&; /%&&F??&;'C9 'C9%:70 %:70: : MikroTik MikroTik `outerO `outerOSS =7: ([*% =2[3?)?+& +) &
/(0% †# ‚~
J($%&7$&%<7L(74 $&%<7L(7437G4 73 G4GD V VGDJ0 J0L%( L%( %1%&79%( %9 ( qinBoz /&;' '??%&4 ??%&4Q'&4 9( htt!"##pW.~}.WWW.W#ra!hs#
5%$&K76 K76L?(5F/ L?(5F/(9%$&%<7L2%F3 %$&%<7L2%F3 •OIP Trafficej 3 One-iiToAllj >19 <7L2&%F>19 <7L2&%F>19>70 >70'() '()*%+J/0 *%+J/0>E4 >E4' '( +4GD V VGC0 D C0%m %mL+'((D L+'((D R%1%&7 %1%&7$&%>70 $&%>70 /%$G8 /%$G8%$%&'() %$%&'()*%+$&%3 *%+$&%3$ $5F<7LG6 5F<7LG6 RL/17 L/17 76L& L&K
+6':9 ':9%L %L $%&'(v$<7L$&%(74 $<7L$&%(7437G4 73 G4C'L>E4' '(+4 (+4G6G RL/17J(Q6 6L/17J(Q6?( ?(+ /%$+0'L$%&%1&7& 'L$%&%1&7&J($%&&0 J($%&&0%L3 %L3G6 G6 RL/17 L/17 ,WX† 3 J(Q6?( ?(+ + %1%&J0 zcel zcel s!readsheet <0 &0 &0%L&3 %L&3K+4 K+4 8%/&6 %/&6?(8 ?(8%C0 %C0%>E4 %>E4J( J( `outerOS C6 R(+'(70 (+'(70%(E9 %(E9%L(D %L(D RK K(3 (3[D[D? anual 8%/&6 %/&6?&0 ?&0%L %L Si!le ueue 1. 2.
3.
&0%L %L Si!le ueue >KGD 1( V V1( ueues ueuesjj ’ E3$19+0+0'L$8 'L$8%/(7$%&58 %/(7$%&58%$6 %$67(74 7(7437G4 73 G4J(3 J(3(D (D R