Example
my topologi webserver
|
isp---mikrotik -- switch managable ( ada 3 vlan )
|
proxy
0 chain=srcnat action=masquerade out-interface=bridge1
1 chain=dstnat action=dst-nat to-addresses=10.5.50.14 to-ports=3456
protocol=tcp src-address=!10.5.50.14 dst-port=80 [/QUOTE]
2 ;;; forward ke dalam
chain=dstnat action=dst-nat to-addresses=10.5.51.2 to-ports=80
protocol=tcp dst-address=x.x.x.x dst-port=80
3 ;;; forward ke luar
chain=srcnat action=src-nat to-addresses=x.x.x.x to-ports=0-65535
protocol=tcp dst-address=10.5.51.2 dst-port=80
Cara diatas maka semua trafik yang ada di router akan dibelokkan to proxy termasuk webserver kita
karena logika pembacaan NAT di mikrotik itu dari atas ke bawah.
SOLVEDnya
0 chain=srcnat action=masquerade out-interface=bridge1
1 ;;; forward ke dalam
chain=dstnat action=dst-nat to-addresses=10.5.51.2 to-ports=80
protocol=tcp dst-address=x.x.x.x dst-port=80
2 ;;; forward ke luar
chain=srcnat action=src-nat to-addresses=x.x.x.x to-ports=0-65535
protocol=tcp dst-address=10.5.51.2 dst-port=80
3 ;;; forward ke dalam chain=dstnat action=dst-nat to-addresses=10.5.50.14 to-ports=3456 protocol=tcp src-address=!10.5.50.14 dst-port=80
so carefully in mikrotik. this just my experience and i wrote in my blog. im newbie banget
Comments
Post a Comment