0% found this document useful (0 votes)
43 views8 pages

CHR

The document contains configuration settings for a router, including enabling services like L2TP, PPTP, and PPoE servers, configuring address lists and firewall rules to mark and redirect traffic for applications like Zoom, games, and browsers, and enabling NAT rules for port forwarding. DHCP client is enabled on the ethernet interface and firewall rules are added to classify and mark traffic from the local network to external addresses.

Uploaded by

Mamajoko
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
43 views8 pages

CHR

The document contains configuration settings for a router, including enabling services like L2TP, PPTP, and PPoE servers, configuring address lists and firewall rules to mark and redirect traffic for applications like Zoom, games, and browsers, and enabling NAT rules for port forwarding. DHCP client is enabled on the ethernet interface and firewall rules are added to classify and mark traffic from the local network to external addresses.

Uploaded by

Mamajoko
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
You are on page 1/ 8

# jun/02/2023 09:18:57 by RouterOS 6.47.

8
# software id =
#
#
#
/interface ethernet
set [ find default-name=ether1 ] disable-running-check=no
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=pool ranges=10.11.24.10-10.11.24.254
/interface detect-internet
set detect-interface-list=all
/interface l2tp-server server
set enabled=yes
/interface pppoe-server server
add disabled=no interface=ether1 service-name=server
/interface pptp-server server
set enabled=yes
/interface sstp-server server
set enabled=yes
/ip dhcp-client
add disabled=no interface=ether1
/ip firewall address-list
add address=25.25.25.0/24 list="IP LOKAL"
add address=3.7.35.0/25 list=Zoom
add address=3.21.137.128/25 list=Zoom
add address=3.22.11.0/24 list=Zoom
add address=3.23.93.0/24 list=Zoom
add address=3.25.41.128/25 list=Zoom
add address=3.25.42.0/25 list=Zoom
add address=3.25.49.0/24 list=Zoom
add address=3.80.20.128/25 list=Zoom
add address=3.96.19.0/24 list=Zoom
add address=3.101.32.128/25 list=Zoom
add address=3.101.52.0/25 list=Zoom
add address=3.104.34.128/25 list=Zoom
add address=3.120.121.0/25 list=Zoom
add address=3.127.194.128/25 list=Zoom
add address=3.208.72.0/25 list=Zoom
add address=3.211.241.0/25 list=Zoom
add address=3.235.69.0/25 list=Zoom
add address=3.235.82.0/23 list=Zoom
add address=3.235.71.128/25 list=Zoom
add address=3.235.72.128/25 list=Zoom
add address=3.235.73.0/25 list=Zoom
add address=3.235.96.0/23 list=Zoom
add address=4.34.125.128/25 list=Zoom
add address=4.35.64.128/25 list=Zoom
add address=8.5.128.0/23 list=Zoom
add address=13.52.6.128/25 list=Zoom
add address=13.52.146.0/25 list=Zoom
add address=13.114.106.166 list=Zoom
add address=18.157.88.0/24 list=Zoom
add address=18.205.93.128/25 list=Zoom
add address=50.239.202.0/23 list=Zoom
add address=50.239.204.0/24 list=Zoom
add address=52.61.100.128/25 list=Zoom
add address=52.81.151.128/25 list=Zoom
add address=52.81.215.0/24 list=Zoom
add address=52.197.97.21 list=Zoom
add address=52.202.62.192/26 list=Zoom
add address=52.215.168.0/25 list=Zoom
add address=64.69.74.0/24 list=Zoom
add address=64.125.62.0/24 list=Zoom
add address=64.211.144.0/24 list=Zoom
add address=65.39.152.0/24 list=Zoom
add address=69.174.57.0/24 list=Zoom
add address=69.174.108.0/22 list=Zoom
add address=99.79.20.0/25 list=Zoom
add address=103.122.166.0/23 list=Zoom
add address=109.94.160.0/22 list=Zoom
add address=109.244.18.0/25 list=Zoom
add address=109.244.19.0/24 list=Zoom
add address=111.33.181.0/25 list=Zoom
add address=115.110.154.192/26 list=Zoom
add address=115.114.56.192/26 list=Zoom
add address=115.114.115.0/26 list=Zoom
add address=115.114.131.0/26 list=Zoom
add address=120.29.148.0/24 list=Zoom
add address=140.238.128.0/24 list=Zoom
add address=147.124.96.0/19 list=Zoom
add address=149.137.0.0/17 list=Zoom
add address=152.67.20.0/24 list=Zoom
add address=152.67.118.0/24 list=Zoom
add address=152.67.180.0/24 list=Zoom
add address=158.101.64.0/24 list=Zoom
add address=160.1.56.128/25 list=Zoom
add address=161.189.199.0/25 list=Zoom
add address=161.199.136.0/22 list=Zoom
add address=162.12.232.0/22 list=Zoom
add address=162.255.36.0/22 list=Zoom
add address=165.254.88.0/23 list=Zoom
add address=168.138.16.0/24 list=Zoom
add address=168.138.48.0/24 list=Zoom
add address=168.138.72.0/24 list=Zoom
add address=168.138.244.0/24 list=Zoom
add address=173.231.80.0/20 list=Zoom
add address=192.204.12.0/22 list=Zoom
add address=193.122.32.0/22 list=Zoom
add address=193.123.0.0/19 list=Zoom
add address=193.123.40.0/22 list=Zoom
add address=193.123.128.0/19 list=Zoom
add address=198.251.128.0/17 list=Zoom
add address=202.177.207.128/27 list=Zoom
add address=202.177.213.96/27 list=Zoom
add address=204.80.104.0/21 list=Zoom
add address=204.141.28.0/22 list=Zoom
add address=207.226.132.0/24 list=Zoom
add address=209.9.211.0/24 list=Zoom
add address=209.9.215.0/24 list=Zoom
add address=210.57.55.0/24 list=Zoom
add address=213.19.144.0/24 list=Zoom
add address=213.19.153.0/24 list=Zoom
add address=213.244.140.0/24 list=Zoom
add address=221.122.88.64/27 list=Zoom
add address=221.122.88.128/25 list=Zoom
add address=221.122.89.128/25 list=Zoom
add address=221.123.139.192/27 list=Zoom
add address=8.5.128.0/24 list=Zoom
add address=139.162.58.0/24 list="IP LOKAL"
add address=10.0.0.0/8 list="IP LOKAL"
add address=192.168.0.0/16 list="IP LOKAL"
add address=172.16.0.0/16 list="IP LOKAL"
add address=10.11.0.0/16 list="IP LOKAL"
/ip firewall mangle
add action=mark-connection chain=prerouting comment="koneksi game" \
dst-address-list=ip_game new-connection-mark=koneksi_game passthrough=yes \
src-address-list="IP LOKAL"
add action=mark-packet chain=forward connection-mark=koneksi_game \
new-packet-mark=paket_game passthrough=no
add action=mark-connection chain=prerouting comment=koneksi_whatsapp \
dst-address-list=whatsapp new-connection-mark=koneksi_whatsapp \
passthrough=yes src-address-list="IP LOKAL"
add action=mark-packet chain=forward connection-mark=koneksi_whatsapp \
new-packet-mark=paket_whatsapp passthrough=no
add action=mark-connection chain=prerouting comment=youtube dst-address-list=\
youtube new-connection-mark=koneksi_youtube passthrough=yes \
src-address-list="IP LOKAL"
add action=mark-packet chain=forward connection-mark=koneksi_youtube \
new-packet-mark=paket_youtube passthrough=no
add action=mark-connection chain=prerouting comment=tiktok dst-address-list=\
tiktok new-connection-mark=koneksi_tiktok passthrough=yes \
src-address-list="IP LOKAL"
add action=mark-packet chain=forward connection-mark=koneksi_tiktok \
new-packet-mark=paket_youtube passthrough=no
add action=mark-connection chain=prerouting comment=marketplace \
dst-address-list=marketplace new-connection-mark=koneksi_marketplace \
passthrough=yes src-address-list="IP LOKAL"
add action=mark-packet chain=forward connection-mark=koneksi_marketplace \
new-packet-mark=paket_youtube passthrough=no
add action=add-dst-to-address-list address-list=Zoom address-list-timeout=\
none-dynamic chain=prerouting comment=zoom dst-port=\
3478,3479,5090,5091,8801-8810 protocol=tcp
add action=add-dst-to-address-list address-list=Zoom address-list-timeout=\
none-dynamic chain=prerouting dst-port=3478,3479,5090,5091,8801-8810 \
protocol=udp
add action=mark-connection chain=prerouting dst-address-list=Zoom dst-port=\
3478,3479,5090,5091,8801-8810 new-connection-mark=Zoom-Connection \
passthrough=yes protocol=tcp
add action=mark-connection chain=prerouting dst-address-list=Zoom dst-port=\
3478,3479,5090,5091,8801-8810 new-connection-mark=Zoom-Connection \
passthrough=yes protocol=udp
add action=mark-connection chain=prerouting dst-address-list=Zoom dst-port=\
80,443 new-connection-mark=Zoom-Connection passthrough=yes protocol=tcp
add action=mark-packet chain=prerouting connection-mark=Zoom-Connection \
new-packet-mark=Zoom-packet passthrough=no
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
none-dynamic chain=prerouting comment=domino dst-port=50000-50500 \
protocol=tcp
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
none-dynamic chain=prerouting dst-port=40000-40010 protocol=udp
add action=add-dst-to-address-list address-list=ip_browser \
address-list-timeout=none-dynamic chain=prerouting comment=browser \
dst-port=80,81,443,8000-8081,21,22,23,81,88,5050,843,182,53 protocol=tcp
add action=add-dst-to-address-list address-list=ip_browser \
address-list-timeout=none-dynamic chain=prerouting dst-port=\
21,22,23,80,81,443,8000,8008,8080,8081,8090,8443,8888 protocol=tcp
add action=add-dst-to-address-list address-list=ip_browser \
address-list-timeout=none-dynamic chain=prerouting dst-port=\
80,81,443,8000-8081,21,22,23,81,88,5050,843,182,53 protocol=udp
add action=add-dst-to-address-list address-list=ip_browser \
address-list-timeout=none-dynamic chain=prerouting dst-port=\
21,22,23,80,81,443,8000,8008,8080,8081,8090,8443,8888 protocol=udp
/ip firewall nat
add action=masquerade chain=srcnat
add action=dst-nat chain=dstnat comment=calvin dst-address=10.123.56.230 \
dst-port=1998 protocol=tcp to-addresses=10.11.23.10 to-ports=8291
add action=dst-nat chain=dstnat comment=sis dst-address=10.123.56.230 \
dst-port=2000 protocol=tcp to-addresses=10.11.23.12 to-ports=8291
add action=dst-nat chain=dstnat comment=selatan dst-address=10.123.56.230 \
dst-port=1986 protocol=tcp to-addresses=10.11.23.15 to-ports=8291
add action=dst-nat chain=dstnat comment=selatan dst-address=10.123.56.230 \
dst-port=1985 protocol=tcp to-addresses=10.11.23.13 to-ports=8291
add action=dst-nat chain=dstnat comment=selatan dst-address=10.123.56.230 \
dst-port=1987 protocol=tcp to-addresses=10.11.23.199 to-ports=8291
add action=dst-nat chain=dstnat comment="aceng winbox" dst-address=\
10.123.56.230 dst-port=1988 protocol=tcp to-addresses=10.11.23.200 \
to-ports=8291
add action=dst-nat chain=dstnat comment="wmsaceng winbox" dst-address=\
10.123.56.230 dst-port=4848 protocol=tcp to-addresses=10.11.23.254 \
to-ports=8291
add action=dst-nat chain=dstnat comment="aceng web" dst-address=10.123.56.230 \
dst-port=1989 protocol=tcp to-addresses=10.11.23.200 to-ports=2023
add action=dst-nat chain=dstnat comment=gebang dst-address=10.123.56.230 \
dst-port=2023 protocol=tcp to-addresses=10.11.23.199 to-ports=8291
/ip firewall raw
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
3h chain=prerouting comment=ML dst-address-list="!IP LOKAL" dst-port=\
5000-5221,5224-5227,5229-5241,5243-5508,5551-5559,5601-5700,9001,9443 \
protocol=tcp src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
3h chain=prerouting dst-address-list="!IP LOKAL" dst-port=\
5520-5529,10003,30000-30300 protocol=tcp src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
3h chain=prerouting dst-address-list="!IP LOKAL" dst-port=\
5001-5180,5501-5680,9443,30000-30220,9001 protocol=tcp src-address-list=\
"IP LOKAL"
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
3h chain=prerouting dst-address-list="!IP LOKAL" dst-port=\
4001-4009,5000-5221,5224-5241,5243-5508,5551-5559,5601-5700 protocol=udp \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
3h chain=prerouting dst-address-list="!IP LOKAL" dst-port=\
2702,3702,5517,5520-5529,8001,9000-9010,9992,10003,30000-30300 protocol=\
udp src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
3h chain=prerouting dst-address-list="!IP LOKAL" dst-port=\
5001-5180,5501-5680,9992,30020-30220,9001 protocol=udp src-address-list=\
"IP LOKAL"
add action=add-dst-to-address-list address-list=whatsapp \
address-list-timeout=1h chain=prerouting comment=whatsapp \
dst-address-list="!IP LOKAL" dst-port=\
3478,4244,5222,5223,5228,5288,5242,5349,34784,45395,50318,59234 protocol=\
tcp src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=whatsapp \
address-list-timeout=1h chain=prerouting dst-address-list="!IP LOKAL" \
dst-port=3478,4244,5222,5223,5228,5288,5242,5349,34784,45395,50318,59234 \
protocol=udp src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=whatsapp \
address-list-timeout=1h chain=prerouting content=.whatsapp.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=whatsapp \
address-list-timeout=1h chain=prerouting content=.whatsapp.net \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=whatsapp \
address-list-timeout=1h chain=prerouting content=wa.me dst-address-list=\
"!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=youtube address-list-timeout=\
1h chain=prerouting comment=youtube content=.youtube.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=youtube address-list-timeout=\
1h chain=prerouting content=.googlevideo.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=youtube address-list-timeout=\
1h chain=prerouting content=.ytimg.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=youtube address-list-timeout=\
1h chain=prerouting content=youtu.be dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=youtube address-list-timeout=\
1h chain=prerouting content=yt3.ggpht.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=youtube address-list-timeout=\
1h chain=prerouting content=youtubei.googleapis.com dst-address-list=\
"!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting comment=tiktok content=.tiktok.com dst-address-list=\
"!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=.tiktokv.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=.tiktokcdn.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=.byteoversea.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=.ibyteimg.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=.ttwstatic.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=.ibytedtos.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=.tiktokcdn-us.com dst-address-list=\
"!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=bytedance.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting comment=marketplace content=\
shopee.co.id dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.shopee.co.id \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.shopeemobile.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.shopee.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=shopee.io \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.shopee.sg \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.tokopedia.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.tokopedia.net \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.bukalapak.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=bukalapak.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.lazada.co.id \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.lazada.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.lazada. \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.alicdn.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.slatic.net \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.aliyuncs.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.alibaba-inc.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/ppp secret
add local-address=10.11.23.1 name=gebang password=123 profile=50Mb \
remote-address=10.11.23.199
add local-address=10.11.23.1 name=massis password=123 profile=50Mb \
remote-address=10.11.23.12 service=l2tp
add local-address=10.11.23.1 name=wa password=123 profile=50Mb \
remote-address=10.11.23.13 service=l2tp
add local-address=10.11.23.1 name=masiponk password=123 profile=50Mb \
remote-address=10.11.23.11 service=l2tp
add local-address=10.11.23.1 name=selatan password=123 profile=100mb \
remote-address=10.11.23.14 service=l2tp
add local-address=10.11.23.1 name=calvin password=123 profile=50Mb \
remote-address=10.11.23.10 service=l2tp
add comment="rumah selatan" local-address=10.11.23.1 name=zzz password=123 \
profile=100mb remote-address=10.11.23.15
add local-address=10.11.23.1 name=aceng password=123 profile=50Mb \
remote-address=10.11.23.200
add comment=remote local-address=10.11.23.254 name=wmsaceng password=123 \
profile=remote service=l2tp
/system clock
set time-zone-name=Asia/Jakarta
/system ntp client
set enabled=yes primary-ntp=103.123.108.223 secondary-ntp=162.159.200.123 \
server-dns-names=id.pool.ntp.org

You might also like