CHR
CHR
8
# software id =
#
#
#
/interface ethernet
set [ find default-name=ether1 ] disable-running-check=no
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=pool ranges=10.11.24.10-10.11.24.254
/interface detect-internet
set detect-interface-list=all
/interface l2tp-server server
set enabled=yes
/interface pppoe-server server
add disabled=no interface=ether1 service-name=server
/interface pptp-server server
set enabled=yes
/interface sstp-server server
set enabled=yes
/ip dhcp-client
add disabled=no interface=ether1
/ip firewall address-list
add address=25.25.25.0/24 list="IP LOKAL"
add address=3.7.35.0/25 list=Zoom
add address=3.21.137.128/25 list=Zoom
add address=3.22.11.0/24 list=Zoom
add address=3.23.93.0/24 list=Zoom
add address=3.25.41.128/25 list=Zoom
add address=3.25.42.0/25 list=Zoom
add address=3.25.49.0/24 list=Zoom
add address=3.80.20.128/25 list=Zoom
add address=3.96.19.0/24 list=Zoom
add address=3.101.32.128/25 list=Zoom
add address=3.101.52.0/25 list=Zoom
add address=3.104.34.128/25 list=Zoom
add address=3.120.121.0/25 list=Zoom
add address=3.127.194.128/25 list=Zoom
add address=3.208.72.0/25 list=Zoom
add address=3.211.241.0/25 list=Zoom
add address=3.235.69.0/25 list=Zoom
add address=3.235.82.0/23 list=Zoom
add address=3.235.71.128/25 list=Zoom
add address=3.235.72.128/25 list=Zoom
add address=3.235.73.0/25 list=Zoom
add address=3.235.96.0/23 list=Zoom
add address=4.34.125.128/25 list=Zoom
add address=4.35.64.128/25 list=Zoom
add address=8.5.128.0/23 list=Zoom
add address=13.52.6.128/25 list=Zoom
add address=13.52.146.0/25 list=Zoom
add address=13.114.106.166 list=Zoom
add address=18.157.88.0/24 list=Zoom
add address=18.205.93.128/25 list=Zoom
add address=50.239.202.0/23 list=Zoom
add address=50.239.204.0/24 list=Zoom
add address=52.61.100.128/25 list=Zoom
add address=52.81.151.128/25 list=Zoom
add address=52.81.215.0/24 list=Zoom
add address=52.197.97.21 list=Zoom
add address=52.202.62.192/26 list=Zoom
add address=52.215.168.0/25 list=Zoom
add address=64.69.74.0/24 list=Zoom
add address=64.125.62.0/24 list=Zoom
add address=64.211.144.0/24 list=Zoom
add address=65.39.152.0/24 list=Zoom
add address=69.174.57.0/24 list=Zoom
add address=69.174.108.0/22 list=Zoom
add address=99.79.20.0/25 list=Zoom
add address=103.122.166.0/23 list=Zoom
add address=109.94.160.0/22 list=Zoom
add address=109.244.18.0/25 list=Zoom
add address=109.244.19.0/24 list=Zoom
add address=111.33.181.0/25 list=Zoom
add address=115.110.154.192/26 list=Zoom
add address=115.114.56.192/26 list=Zoom
add address=115.114.115.0/26 list=Zoom
add address=115.114.131.0/26 list=Zoom
add address=120.29.148.0/24 list=Zoom
add address=140.238.128.0/24 list=Zoom
add address=147.124.96.0/19 list=Zoom
add address=149.137.0.0/17 list=Zoom
add address=152.67.20.0/24 list=Zoom
add address=152.67.118.0/24 list=Zoom
add address=152.67.180.0/24 list=Zoom
add address=158.101.64.0/24 list=Zoom
add address=160.1.56.128/25 list=Zoom
add address=161.189.199.0/25 list=Zoom
add address=161.199.136.0/22 list=Zoom
add address=162.12.232.0/22 list=Zoom
add address=162.255.36.0/22 list=Zoom
add address=165.254.88.0/23 list=Zoom
add address=168.138.16.0/24 list=Zoom
add address=168.138.48.0/24 list=Zoom
add address=168.138.72.0/24 list=Zoom
add address=168.138.244.0/24 list=Zoom
add address=173.231.80.0/20 list=Zoom
add address=192.204.12.0/22 list=Zoom
add address=193.122.32.0/22 list=Zoom
add address=193.123.0.0/19 list=Zoom
add address=193.123.40.0/22 list=Zoom
add address=193.123.128.0/19 list=Zoom
add address=198.251.128.0/17 list=Zoom
add address=202.177.207.128/27 list=Zoom
add address=202.177.213.96/27 list=Zoom
add address=204.80.104.0/21 list=Zoom
add address=204.141.28.0/22 list=Zoom
add address=207.226.132.0/24 list=Zoom
add address=209.9.211.0/24 list=Zoom
add address=209.9.215.0/24 list=Zoom
add address=210.57.55.0/24 list=Zoom
add address=213.19.144.0/24 list=Zoom
add address=213.19.153.0/24 list=Zoom
add address=213.244.140.0/24 list=Zoom
add address=221.122.88.64/27 list=Zoom
add address=221.122.88.128/25 list=Zoom
add address=221.122.89.128/25 list=Zoom
add address=221.123.139.192/27 list=Zoom
add address=8.5.128.0/24 list=Zoom
add address=139.162.58.0/24 list="IP LOKAL"
add address=10.0.0.0/8 list="IP LOKAL"
add address=192.168.0.0/16 list="IP LOKAL"
add address=172.16.0.0/16 list="IP LOKAL"
add address=10.11.0.0/16 list="IP LOKAL"
/ip firewall mangle
add action=mark-connection chain=prerouting comment="koneksi game" \
dst-address-list=ip_game new-connection-mark=koneksi_game passthrough=yes \
src-address-list="IP LOKAL"
add action=mark-packet chain=forward connection-mark=koneksi_game \
new-packet-mark=paket_game passthrough=no
add action=mark-connection chain=prerouting comment=koneksi_whatsapp \
dst-address-list=whatsapp new-connection-mark=koneksi_whatsapp \
passthrough=yes src-address-list="IP LOKAL"
add action=mark-packet chain=forward connection-mark=koneksi_whatsapp \
new-packet-mark=paket_whatsapp passthrough=no
add action=mark-connection chain=prerouting comment=youtube dst-address-list=\
youtube new-connection-mark=koneksi_youtube passthrough=yes \
src-address-list="IP LOKAL"
add action=mark-packet chain=forward connection-mark=koneksi_youtube \
new-packet-mark=paket_youtube passthrough=no
add action=mark-connection chain=prerouting comment=tiktok dst-address-list=\
tiktok new-connection-mark=koneksi_tiktok passthrough=yes \
src-address-list="IP LOKAL"
add action=mark-packet chain=forward connection-mark=koneksi_tiktok \
new-packet-mark=paket_youtube passthrough=no
add action=mark-connection chain=prerouting comment=marketplace \
dst-address-list=marketplace new-connection-mark=koneksi_marketplace \
passthrough=yes src-address-list="IP LOKAL"
add action=mark-packet chain=forward connection-mark=koneksi_marketplace \
new-packet-mark=paket_youtube passthrough=no
add action=add-dst-to-address-list address-list=Zoom address-list-timeout=\
none-dynamic chain=prerouting comment=zoom dst-port=\
3478,3479,5090,5091,8801-8810 protocol=tcp
add action=add-dst-to-address-list address-list=Zoom address-list-timeout=\
none-dynamic chain=prerouting dst-port=3478,3479,5090,5091,8801-8810 \
protocol=udp
add action=mark-connection chain=prerouting dst-address-list=Zoom dst-port=\
3478,3479,5090,5091,8801-8810 new-connection-mark=Zoom-Connection \
passthrough=yes protocol=tcp
add action=mark-connection chain=prerouting dst-address-list=Zoom dst-port=\
3478,3479,5090,5091,8801-8810 new-connection-mark=Zoom-Connection \
passthrough=yes protocol=udp
add action=mark-connection chain=prerouting dst-address-list=Zoom dst-port=\
80,443 new-connection-mark=Zoom-Connection passthrough=yes protocol=tcp
add action=mark-packet chain=prerouting connection-mark=Zoom-Connection \
new-packet-mark=Zoom-packet passthrough=no
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
none-dynamic chain=prerouting comment=domino dst-port=50000-50500 \
protocol=tcp
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
none-dynamic chain=prerouting dst-port=40000-40010 protocol=udp
add action=add-dst-to-address-list address-list=ip_browser \
address-list-timeout=none-dynamic chain=prerouting comment=browser \
dst-port=80,81,443,8000-8081,21,22,23,81,88,5050,843,182,53 protocol=tcp
add action=add-dst-to-address-list address-list=ip_browser \
address-list-timeout=none-dynamic chain=prerouting dst-port=\
21,22,23,80,81,443,8000,8008,8080,8081,8090,8443,8888 protocol=tcp
add action=add-dst-to-address-list address-list=ip_browser \
address-list-timeout=none-dynamic chain=prerouting dst-port=\
80,81,443,8000-8081,21,22,23,81,88,5050,843,182,53 protocol=udp
add action=add-dst-to-address-list address-list=ip_browser \
address-list-timeout=none-dynamic chain=prerouting dst-port=\
21,22,23,80,81,443,8000,8008,8080,8081,8090,8443,8888 protocol=udp
/ip firewall nat
add action=masquerade chain=srcnat
add action=dst-nat chain=dstnat comment=calvin dst-address=10.123.56.230 \
dst-port=1998 protocol=tcp to-addresses=10.11.23.10 to-ports=8291
add action=dst-nat chain=dstnat comment=sis dst-address=10.123.56.230 \
dst-port=2000 protocol=tcp to-addresses=10.11.23.12 to-ports=8291
add action=dst-nat chain=dstnat comment=selatan dst-address=10.123.56.230 \
dst-port=1986 protocol=tcp to-addresses=10.11.23.15 to-ports=8291
add action=dst-nat chain=dstnat comment=selatan dst-address=10.123.56.230 \
dst-port=1985 protocol=tcp to-addresses=10.11.23.13 to-ports=8291
add action=dst-nat chain=dstnat comment=selatan dst-address=10.123.56.230 \
dst-port=1987 protocol=tcp to-addresses=10.11.23.199 to-ports=8291
add action=dst-nat chain=dstnat comment="aceng winbox" dst-address=\
10.123.56.230 dst-port=1988 protocol=tcp to-addresses=10.11.23.200 \
to-ports=8291
add action=dst-nat chain=dstnat comment="wmsaceng winbox" dst-address=\
10.123.56.230 dst-port=4848 protocol=tcp to-addresses=10.11.23.254 \
to-ports=8291
add action=dst-nat chain=dstnat comment="aceng web" dst-address=10.123.56.230 \
dst-port=1989 protocol=tcp to-addresses=10.11.23.200 to-ports=2023
add action=dst-nat chain=dstnat comment=gebang dst-address=10.123.56.230 \
dst-port=2023 protocol=tcp to-addresses=10.11.23.199 to-ports=8291
/ip firewall raw
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
3h chain=prerouting comment=ML dst-address-list="!IP LOKAL" dst-port=\
5000-5221,5224-5227,5229-5241,5243-5508,5551-5559,5601-5700,9001,9443 \
protocol=tcp src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
3h chain=prerouting dst-address-list="!IP LOKAL" dst-port=\
5520-5529,10003,30000-30300 protocol=tcp src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
3h chain=prerouting dst-address-list="!IP LOKAL" dst-port=\
5001-5180,5501-5680,9443,30000-30220,9001 protocol=tcp src-address-list=\
"IP LOKAL"
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
3h chain=prerouting dst-address-list="!IP LOKAL" dst-port=\
4001-4009,5000-5221,5224-5241,5243-5508,5551-5559,5601-5700 protocol=udp \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
3h chain=prerouting dst-address-list="!IP LOKAL" dst-port=\
2702,3702,5517,5520-5529,8001,9000-9010,9992,10003,30000-30300 protocol=\
udp src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=ip_game address-list-timeout=\
3h chain=prerouting dst-address-list="!IP LOKAL" dst-port=\
5001-5180,5501-5680,9992,30020-30220,9001 protocol=udp src-address-list=\
"IP LOKAL"
add action=add-dst-to-address-list address-list=whatsapp \
address-list-timeout=1h chain=prerouting comment=whatsapp \
dst-address-list="!IP LOKAL" dst-port=\
3478,4244,5222,5223,5228,5288,5242,5349,34784,45395,50318,59234 protocol=\
tcp src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=whatsapp \
address-list-timeout=1h chain=prerouting dst-address-list="!IP LOKAL" \
dst-port=3478,4244,5222,5223,5228,5288,5242,5349,34784,45395,50318,59234 \
protocol=udp src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=whatsapp \
address-list-timeout=1h chain=prerouting content=.whatsapp.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=whatsapp \
address-list-timeout=1h chain=prerouting content=.whatsapp.net \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=whatsapp \
address-list-timeout=1h chain=prerouting content=wa.me dst-address-list=\
"!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=youtube address-list-timeout=\
1h chain=prerouting comment=youtube content=.youtube.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=youtube address-list-timeout=\
1h chain=prerouting content=.googlevideo.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=youtube address-list-timeout=\
1h chain=prerouting content=.ytimg.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=youtube address-list-timeout=\
1h chain=prerouting content=youtu.be dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=youtube address-list-timeout=\
1h chain=prerouting content=yt3.ggpht.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=youtube address-list-timeout=\
1h chain=prerouting content=youtubei.googleapis.com dst-address-list=\
"!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting comment=tiktok content=.tiktok.com dst-address-list=\
"!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=.tiktokv.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=.tiktokcdn.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=.byteoversea.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=.ibyteimg.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=.ttwstatic.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=.ibytedtos.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=.tiktokcdn-us.com dst-address-list=\
"!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=tiktok address-list-timeout=\
1h chain=prerouting content=bytedance.com dst-address-list="!IP LOKAL" \
src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting comment=marketplace content=\
shopee.co.id dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.shopee.co.id \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.shopeemobile.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.shopee.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=shopee.io \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.shopee.sg \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.tokopedia.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.tokopedia.net \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.bukalapak.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=bukalapak.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.lazada.co.id \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.lazada.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.lazada. \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.alicdn.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.slatic.net \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.aliyuncs.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
add action=add-dst-to-address-list address-list=marketplace \
address-list-timeout=1h chain=prerouting content=.alibaba-inc.com \
dst-address-list="!IP LOKAL" src-address-list="IP LOKAL"
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/ppp secret
add local-address=10.11.23.1 name=gebang password=123 profile=50Mb \
remote-address=10.11.23.199
add local-address=10.11.23.1 name=massis password=123 profile=50Mb \
remote-address=10.11.23.12 service=l2tp
add local-address=10.11.23.1 name=wa password=123 profile=50Mb \
remote-address=10.11.23.13 service=l2tp
add local-address=10.11.23.1 name=masiponk password=123 profile=50Mb \
remote-address=10.11.23.11 service=l2tp
add local-address=10.11.23.1 name=selatan password=123 profile=100mb \
remote-address=10.11.23.14 service=l2tp
add local-address=10.11.23.1 name=calvin password=123 profile=50Mb \
remote-address=10.11.23.10 service=l2tp
add comment="rumah selatan" local-address=10.11.23.1 name=zzz password=123 \
profile=100mb remote-address=10.11.23.15
add local-address=10.11.23.1 name=aceng password=123 profile=50Mb \
remote-address=10.11.23.200
add comment=remote local-address=10.11.23.254 name=wmsaceng password=123 \
profile=remote service=l2tp
/system clock
set time-zone-name=Asia/Jakarta
/system ntp client
set enabled=yes primary-ntp=103.123.108.223 secondary-ntp=162.159.200.123 \
server-dns-names=id.pool.ntp.org