Skip to main content

Konfigurasi DNS Pada Mikrotik

# Pengaturan ip DNS Server Classic port 53
DNS ASNET : - 49.0.0.49
            - 49.0.0.94
OPEN DNS REKOMENDASI : 1.0.0.3 dan 1.1.1.3 ( DNS Sehat)
jangan gunakan 8.8.8.8 8.8.4.4 1.1.1.1 karena bokep bisa di buka 
Contoh Pemasangan DNS Via Terminal
/ip dns set servers=1.1.1.1,1.0.0.1


kombinasi Dengan DOH
# CA certificates extracted from Mozilla
/tool fetch url=https://curl.se/ca/cacert.pem

# Import the downloaded ca-store (127 certificates)
/certificate import file-name=cacert.pem passphrase=""

/ip dns set use-doh-server=https://family.cloudflare-dns.com/dns-query verify-doh-cert=yes 


Red : IP DNS SERVER Clasic udp port 53

Orange  :  DNS SERVER Via HTTPS 
Blue : Apabila di Log Mikrotik Terdapat Error Concurent tambah angka Queries


Yellow : Perlu Di perhatikan untuk Yelow atau kuning ini dan sedikit berhati hati

- allow-remote-requests=yes  apabila di ceklist router akan menjadi dns server dan harus memiliki filter agar router tidak menjadi open DNS

  ip firewall/filter/add chain=input action=drop protocol=udp in-interface=WAN dst-port=53

NB : rubah WAN menjadi interface yang mengarah ke ISP/Penyedia Internet

Jangan Lupa di redirect apabila di ceklist allow requestnya
klo ga di redirect sama aja bodong buat apa di ceklist

ip firwall nat add action=redirect chain=dstnat comment="REDIRECT DNS ALL" dst-port=53 protocol=udp to-ports=53




Comments

Popular posts from this blog

CLI Populer di OLT GPON ZTE

  ## cek onu belum terdaftar ZTE C300 # show gpon onu uncfg interface gpon-olt_1/9/1 onu 1 type ZTE-F609 sn ZTEGC86CCB88 exit ## Config interface onu yang baru interface gpon-onu_1/9/1:1   name NAME   description DESCRIPTION   sn-bind enable sn   tcont 1 name HSI profile 100M   tcont 2 name HOT profile 100M   gemport 1 name HSI unicast tcont 1 dir both   gemport 1 traffic-limit upstream UP100M downstream DW100M   gemport 2 name HOT unicast tcont 2 dir both   gemport 2 traffic-limit upstream UP100M downstream DW100M   switchport mode hybrid vport 1   switchport mode hybrid vport 2   service-port 1 vport 1 user-vlan 1200 vlan 1200   pppoe-plus enable sport 1   pppoe-plus trust true replace sport 1 exit ## config onu pon-onu-mng gpon-onu_1/9/1:1   service HSI type internet gemport 1 cos 0 vlan 1200   wan-ip 1 mode pppoe username PPPoE_USERNAME password PPPoeE_PASSWORD vlan-profile PPPoE host 1   secur...

OLT ZTE C300/320 di ONT Mode Port: Vlan_Translate, QinQ, Trunk & Access

  Contoh Config  1. Vlan Translate QinQ To Access: OLT-ZTE-C320#show run interface gpon-onu_1/4/1:21 Building configuration... ! interface gpon-onu_1/4/1:21   name RSO0766   description Customer_Vlan-Translate   tcont 6 name Internet_Vlan-Translate profile UP-100M   gemport 6 name Internet_Vlan-Translate unicast tcont 6 dir both   switchport mode hybrid vport 6   service-port 6 vport 6 user-vlan 1490 vlan 1490 svlan 1479  ! end OLT-ZTE-C320#show onu running config gpon-onu_1/4/1:21 pon-onu-mng gpon-onu_1/4/1:21   service Internet_Vlan-Translate gemport 6 vlan 1490   vlan port eth_0/4 mode tag vlan 1490   dhcp-ip ethuni eth_0/4 from-internet ! 2. Vlan QinQ Access: OLT-ZTE-C320#show run interface gpon-onu_1/2/5:22 Building configuration... ! interface gpon-onu_1/2/5:22   name Internet-QinQ-Access   description QinQ-Access   tcont 1 name Acsata profile UP-200M   tcont 1 gap mode2   gemport 1...

How to login Huawei Rectifier TP series (smu02B)?

  Dear All, In b/m steps how to login HCR to adjust its setting 1-login SMU of HCR with username admin & password 000001 2-get IP of HCR 3-Adjust your laptop IP in the subnetmask of HCR   (IP of HCR +1) 4-Open web browser prefereed IE and in address write IP of HCR (Note u should use http not https) 5-Enter username admin & Password changeme 6-Now u can adjust all rectifer setting B/M photos for clearafication