Manajemen User Mikrotik
Melihat daftar user ;
/user print
Menambahkan user:
/user add name=[nama user] group=[hak akses -full/write/read-] password=[password login]
Menghapus user ;
/user remove [urutan user]
Mengubah password user default Mikrotik:
/password old-password=[password lama] new-password=[password baru] confirm-new- password=[konfirmasi password baru]
Manajemen Perangkat Mikrotik
Mereboot (restart) perangkat mikrotik :
/system reboot
Mematikan perangkat mikrotik :
/system shutdown
Mereset konfigurasi mikrotik :
/system reset-configuration no-defaults=[yes/no]
Konfigurasi Interface
Melihat Interface :
/interface print
Memberi nama interface :
/interface ethernet set [int sebelum] name=[nama int baru]
atau
/interface set [urutan, misal : 0] name=[nama]
Konfigurasi IP Address
Melihat daftar IP Address :
/ip address print
Menambahkan IP Address :
/ip address add address=[IP Address]/[subnet] interface=[int] disabled=no
Mengubah IP Address :
/ip address set address=[IP Address]/[subnet] interface=[int] numbers=[urutan]
Menghapus IP Address :
/ip address remove [urutan]
Konfigurasi DNS Server dan DNS Static
Menambahkan DNS Server (public, internet) :
/ip dns set servers=[IP DNS 1],[IP DNS 2] allow-remote-request=yes cache-size=[ukuran cache, 2048/6144]
Menambahkan DNS Static (local) :
/ip dns static add name=[nama dns] address=[IP DNS; IP local mikrotik]
Konfigurasi DHCP Server
Cara cepat All in One :
/ip dhcp-server setup
Membuat IP Pool :
/ip pool add name=[nama pool] ranges=[IP Address awal]–[IP Address akhir]
Mengubah nama pool :
/ip pool set [urutan pool] name=[nama pool baru]
Konfigurasi DHCP Server :
/ip dhcp-server add interface=[nama int] address=[nama pool]
Konfigurasi Network, Gateway, DNS Server
/ip dhcp-server network add address=[IP Network]/[subnet] gateway=[IP Gateway] dns-server=[IP DNS Server]
Konfigurasi Firewall
Melihat daftar firewall :
/ip firewall nat print
Menambahkan firewall masquerade :
/ip firewall nat add chain=srcnat out-interface=[int public] action=masquerade disabled=no
Konfigurasi Static Routing
Menambahkan static routing :
/ip route gateway=[IP Address gateway; IP network tujuan]
Konfigurasi Hotspot
Menambahkan profil server hotspot :
/ip hotspot profile add name=[nama profile] hotspot-address=[IP Address] dns- name=[Hostname] html-directory=hotspot login-by=http-pap use-radius=[yes/no] radius accounting=[yes/no]
Menambahkan Hotspot :
/ip hotspot add name=[nama hotspot] interface=[int hotspot] address-pool=[IP Pool] profile=[profil hotspot]
Mengaktifkan hotspot :
/ip hotspot enable [urutan hotspot]
Menambahkan Walled Garden (bypass website tanpa harus login dulu) :
/ip hotspot waled-garden add server=[nama hotspot] method=connect dst-host=[url web] action=allow
Menambahkan Walled Garden IP List (bypass Winbox tanpa harus login hotspotdulu) :
/ip hotspot walled-garden ip add server=[nama hotspot] protocol=tcp[protokol inet] dst- port=8291 action=accept
Menambahkan IP Binding (bypass login hotspot via mac address) :
/ip hotspot ip-binding add mac-address=[MAC ADDRESS client] server=[nama hotspot] type=bypassed
Menambahkan profil User Hotspot :
/ip hotspot user profile add name=[nama profil] shared-users=[banyak user]
Menambahkan User Hotspot :
/ip hotspot user add name=[nama user] password=[password user] server=[nama hotspot] profile=[profil user hotspot]
Konfigurasi RADIUS (Remote Authentication Dial-In User Service)
Menambahkan RADIUS :
/radius add address=[IP Address RADIUS] secret=[Password] authentication-port=1812 accounting-port=1813
Konfigurasi Web Proxy
Mengatur web proxy :
/ip proxy set enabled=yes src-address=0.0.0.0 port=8080 max-cache-size=[unlimited/none] cache-on-disk=yes cache-administrator=[nama/email admin]
Menambahkan daftar web access :
/ip proxy access add dst-host=[definisi web yg diblokir] action=[deny/allow] disabled=no
Redirect web :
/ip proxy access add dst-host=[definisi web yg diblokir] action=[deny/allow] redirect- to=[alamat penerusan web] disabled=no
Membuat redirect firewall ke web-proxy (transaparant proxy) :
/ip firewall nat add chain=dstnat protocol=tcp dst-port=80 action=redirect to- port=8080[port proxy] disabled=no