<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>bayu - mandriva - other Linux &#187; iptables</title>
	<atom:link href="http://bayuart.wordpress.com/category/iptables/feed/" rel="self" type="application/rss+xml" />
	<link>http://bayuart.wordpress.com</link>
	<description>Just another Mandriva and other Linux user weblog</description>
	<lastBuildDate>Wed, 30 Dec 2009 08:49:29 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>id</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='bayuart.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/193bc682a3e583e86050c08c2924d5b0?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>bayu - mandriva - other Linux &#187; iptables</title>
		<link>http://bayuart.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://bayuart.wordpress.com/osd.xml" title="bayu &#8211; mandriva &#8211; other Linux" />
		<item>
		<title>Simple Captive Portal</title>
		<link>http://bayuart.wordpress.com/2009/06/23/simple-captive-portal/</link>
		<comments>http://bayuart.wordpress.com/2009/06/23/simple-captive-portal/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 04:12:16 +0000</pubDate>
		<dc:creator>bayuart</dc:creator>
				<category><![CDATA[Blitar]]></category>
		<category><![CDATA[Learning]]></category>
		<category><![CDATA[Links]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mandriva]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[iptables]]></category>

		<guid isPermaLink="false">http://bayuart.wordpress.com/?p=461</guid>
		<description><![CDATA[Apa itu captive portal ? cek disini :

http://bayu.blitar.org?l=4N3xycoG
http://bayu.blitar.org?l=_HGNb_Vd
dll

dan pada dasarnya seperti ini :
Captive Portal merupakan suatu teknik autentikasi dan pengamanan data yang lewat dari network internal ke network eksternal. Captive Portal sebenarnya merupakan mesin router atau gateway yang memproteksi atau tidak mengizinkan adanya trafik, sampai user melakukan registrasi terlebih dahulu ke dalam sistem. Biasanya Captive [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bayuart.wordpress.com&blog=140339&post=461&subd=bayuart&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Apa itu captive portal ? cek disini :</p>
<ul>
<li><a title="captive portal" href="http://bayu.blitar.org/?l=4N3xycoG" target="_blank">http://bayu.blitar.org?l=4N3xycoG</a></li>
<li><a title="captive portal" href="http://bayu.blitar.org/?l=_HGNb_Vd" target="_blank">http://bayu.blitar.org?l=_HGNb_Vd</a></li>
<li>dll</li>
</ul>
<p>dan pada dasarnya seperti ini :</p>
<p>Captive Portal merupakan suatu teknik autentikasi dan pengamanan data yang lewat dari network internal ke network eksternal. Captive Portal sebenarnya merupakan mesin router atau gateway yang memproteksi atau tidak mengizinkan adanya trafik, sampai user melakukan registrasi terlebih dahulu ke dalam sistem. Biasanya Captive Portal ini digunakan pada infrastruktur wireless seperti hotspot area, tapi tidak menutup kemungkinan diterapkan pada jaringan kabel.</p>
<p>Ok, langsung aja, kita akan bikin Captive Portal sederhana, dengan menggunakan :</p>
<ul>
<li>Mandriva Linux 2009.1 (<a title="mandriva linux" href="http://bayu.blitar.org/?l=aqR5Pneu" target="_blank">http://bayu.blitar.org?l=aqR5Pneu</a>)</li>
<li>Coova Chilli (<a title="coova chilli" href="http://bayu.blitar.org/?l=NOa0OAbb" target="_blank">http://bayu.blitar.org?l=NOa0OAbb</a>)</li>
<li>Freeradius (<a title="freeradius" href="http://bayu.blitar.org/?l=rUjUVXBP" target="_blank">http://bayu.blitar.org?l=rUjUVXBP</a>)</li>
<li>2 Ethernet card, 1 ke arah Internet, 1 ke arah LAN</li>
</ul>
<p>MySQL nya ? ntar aja, kita mo bikin captive portal sesimple dulu. Lanjut …</p>
<p>Install Mandriva 2009.1, bisa merujuk ke <a title="Mandriva Spring" href="http://bayu.blitar.org/?l=AucYwqtw" target="_blank">http://bayu.blitar.org?l=AucYwqtw</a> , lainnya terserah Anda <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .</p>
<p>Setelah instalasi Mandriva Linux, jangan lupa install webserver nya :</p>
<blockquote><p>urpmi apache</p></blockquote>
<p>Setelah ok semua, kita lanjut ke instalasi inti dari captive portal itu sendiri, yaitu coova-chilli dan Freeradius. Oiya, sebelome untuk melanjutkan proses ini, jangan lupa juga menyambungkan mandriva linux ke repository terdekat. Gambarannya isa diliat disini : <a title="mandriva add repo" href="http://bayu.blitar.org/?l=AmEHtkFr" target="_blank">http://bayu.blitar.org?l=AmEHtkFr</a>.</p>
<p>Install Coova ChilliSpot</p>
<blockquote><p>urpmi chillispot</p>
<p>atau</p>
<p>urpmi coova</p></blockquote>
<p>Setelah selesai, langsung jalankan :</p>
<blockquote><p>/etc/init.d/chilli start</p>
<p>atau</p>
<p>service chilli start</p></blockquote>
<p>Dengan perintah diatas, disamping kita menjalankan service/layanan captive portal, kita juga menggenerate otomatis konfigurasi untuk captive portal. Dan konfigurasi standar hasil generate ini di letakkan di :</p>
<blockquote><p>/etc/chilli/</p>
<p>[server@smpn1ksb ~]$ ls -l /etc/chilli<br />
total 40<br />
-rw-r–r– 1 root root 5776 2009-06-22 11:58 defaults<br />
-rwxr-xr-x 1 root root  385 2008-12-17 06:33 down.sh*<br />
-rwxr-xr-x 1 root root 8045 2008-12-17 06:33 functions*<br />
-rw-r–r– 1 root root    0 2009-06-23 06:00 hs.conf<br />
-rw-r–r– 1 root root    0 2009-06-23 06:00 local.conf<br />
-rw-r–r– 1 root root  851 2009-06-23 03:42 main.conf<br />
-rwxr-xr-x 1 root root  319 2009-06-23 05:42 route.sh*<br />
-rwxr-xr-x 1 root root 1596 2009-06-23 05:36 up.sh*<br />
drwxr-xr-x 2 root root 4096 2009-06-21 09:32 www/<br />
-rwxr-xr-x 1 root root  670 2008-12-17 06:33 wwwsh*<br />
[server@smpn1ksb ~]$</p></blockquote>
<p>Untuk file /etc/chilli.conf jangan diutak atik, biarkan standar/default dulu. Dengan hasil konfigurasi seperti diatas. Captive Portal ini sudah bisa digunakan.</p>
<p>Diagram gambar Jaringan :</p>
<p style="text-align:center;"><strong>Internet &lt;&gt; Modem &lt;&gt; Captive Portal &lt;&gt; LAN</strong></p>
<p>Meskipun captive portal sudah bisa digunakan, dan bisa melayani permintaan dari LAN. Ini masih ada kelemahannya. Kelemahannnya adalah :</p>
<ul>
<li>Langsung tersambung ke server radius coova.org</li>
<li>Tidak bisa langsung digunakan untuk akses internet, harus daftar ke coova.org</li>
</ul>
<p>Untuk mengatasi kelemahan tersebut, kita akan pasang Server Radius sendiri menggunakan <strong>Freeradius</strong>.</p>
<p><a title="captive portal" href="http://bayu.blitar.org/index.php/simple-captive-portal/" target="_blank">Selengkapnya</a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bayuart.wordpress.com/461/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bayuart.wordpress.com/461/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bayuart.wordpress.com/461/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bayuart.wordpress.com/461/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bayuart.wordpress.com/461/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bayuart.wordpress.com/461/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bayuart.wordpress.com/461/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bayuart.wordpress.com/461/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bayuart.wordpress.com/461/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bayuart.wordpress.com/461/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bayuart.wordpress.com&blog=140339&post=461&subd=bayuart&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://bayuart.wordpress.com/2009/06/23/simple-captive-portal/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea5f7aca470898c6021cb0e7057a5ae8?s=96&#38;d=monsterid" medium="image">
			<media:title type="html">bayuart</media:title>
		</media:content>
	</item>
		<item>
		<title>Setting DHCP Server</title>
		<link>http://bayuart.wordpress.com/2009/06/16/setting-dhcp-server/</link>
		<comments>http://bayuart.wordpress.com/2009/06/16/setting-dhcp-server/#comments</comments>
		<pubDate>Tue, 16 Jun 2009 03:13:39 +0000</pubDate>
		<dc:creator>bayuart</dc:creator>
				<category><![CDATA[Lain²]]></category>
		<category><![CDATA[Learning]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mandriva]]></category>
		<category><![CDATA[Squid Proxy]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[iptables]]></category>
		<category><![CDATA[dhcpd.conf]]></category>
		<category><![CDATA[dhcpserver]]></category>
		<category><![CDATA[internetconnectionsharing]]></category>
		<category><![CDATA[router]]></category>
		<category><![CDATA[warnet]]></category>
		<category><![CDATA[warunginternet]]></category>

		<guid isPermaLink="false">http://bayuart.wordpress.com/2009/06/16/setting-dhcp-server/</guid>
		<description><![CDATA[Lanjutan lagi dari :
http://bayuart.blogspot.com/2009/06/konfigurasi-mandriva-linux-warnet.html
http://bayuart.wordpress.com/2009/06/05/mandriva-2009-1-spring-in-action-d-part-deux/
http://bayu.blitar.org/2009/06/02/warung-internet-1/
http://bayu.blitar.org/2009/06/05/mandriva-20091-spring-in-action-d/
Setelah kita melihat file konfigurasi shorewall yang kita gunakan sebagai firewall di Mandriva Linux kita, akhirnya kita melanjutkan ke setingan default DHCP dari hasil proses Internet Connection Sharing untuk Warnet / Warung Internet.
/etc/dhcpd.conf
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;
ddns-update-style none;
subnet 192.168.0.0 netmask 255.255.255.0 {
&#160;&#160;&#160;&#160;&#160;&#160;&#160; # default gateway
&#160;&#160;&#160;&#160;&#160;&#160;&#160; option routers 192.168.0.1;
&#160;&#160;&#160;&#160;&#160;&#160;&#160; option subnet-mask 255.255.255.0;
&#160;&#160;&#160;&#160;&#160;&#160;&#160; option domain-name &#8220;homeland.net&#8221;;
&#160;&#160;&#160;&#160;&#160;&#160;&#160; option domain-name-servers [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bayuart.wordpress.com&blog=140339&post=452&subd=bayuart&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Lanjutan lagi dari :<br />
<a href="http://bayuart.blogspot.com/2009/06/konfigurasi-mandriva-linux-warnet.html">http://bayuart.blogspot.com/2009/06/konfigurasi-mandriva-linux-warnet.html</a><br />
<a href="http://bayuart.wordpress.com/2009/06/05/mandriva-2009-1-spring-in-action-d-part-deux/">http://bayuart.wordpress.com/2009/06/05/mandriva-2009-1-spring-in-action-d-part-deux/</a><br />
<a href="http://bayu.blitar.org/2009/06/02/warung-internet-1/">http://bayu.blitar.org/2009/06/02/warung-internet-1/</a><br />
<a href="http://bayu.blitar.org/2009/06/05/mandriva-20091-spring-in-action-d/">http://bayu.blitar.org/2009/06/05/mandriva-20091-spring-in-action-d/</a></p>
<p>Setelah kita melihat file konfigurasi <a href="http://www.shorewall.net/">shorewall</a> yang kita gunakan sebagai firewall di <a href="http://www.mandriva.com/">Mandriva Linux</a> kita, akhirnya kita melanjutkan ke setingan default <a href="http://en.wikipedia.org/wiki/Dhcp">DHCP</a> dari hasil proses Internet Connection Sharing untuk Warnet / Warung Internet.</p>
<p>/etc/dhcpd.conf<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
ddns-update-style none;<br />
subnet 192.168.0.0 netmask 255.255.255.0 {<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; # default gateway<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; option routers 192.168.0.1;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; option subnet-mask 255.255.255.0;</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; option domain-name &#8220;homeland.net&#8221;;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; option domain-name-servers 202.134.1.10;</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; range dynamic-bootp 192.168.0.16 192.168.0.253;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; default-lease-time 21600;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; max-lease-time 43200;<br />
}<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Konfigurasi diatas sangatlah sederhana, dan langsung bisa di aplikasikan.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bayuart.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bayuart.wordpress.com/452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bayuart.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bayuart.wordpress.com/452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bayuart.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bayuart.wordpress.com/452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bayuart.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bayuart.wordpress.com/452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bayuart.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bayuart.wordpress.com/452/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bayuart.wordpress.com&blog=140339&post=452&subd=bayuart&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://bayuart.wordpress.com/2009/06/16/setting-dhcp-server/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea5f7aca470898c6021cb0e7057a5ae8?s=96&#38;d=monsterid" medium="image">
			<media:title type="html">bayuart</media:title>
		</media:content>
	</item>
		<item>
		<title>Konfigurasi Mandriva Linux Warnet</title>
		<link>http://bayuart.wordpress.com/2009/06/09/konfigurasi-mandriva-linux-warnet/</link>
		<comments>http://bayuart.wordpress.com/2009/06/09/konfigurasi-mandriva-linux-warnet/#comments</comments>
		<pubDate>Tue, 09 Jun 2009 04:38:16 +0000</pubDate>
		<dc:creator>bayuart</dc:creator>
				<category><![CDATA[Blitar]]></category>
		<category><![CDATA[Learning]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mandriva]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[Squid Proxy]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[iptables]]></category>
		<category><![CDATA[dhcpserver]]></category>
		<category><![CDATA[gateway]]></category>
		<category><![CDATA[linuxkhususwarnet]]></category>
		<category><![CDATA[mandrivauntukwarnet]]></category>
		<category><![CDATA[proxyserver]]></category>
		<category><![CDATA[shorewall]]></category>

		<guid isPermaLink="false">http://bayuart.wordpress.com/2009/06/09/konfigurasi-mandriva-linux-warnet/</guid>
		<description><![CDATA[Terusan dari tulisan :
http://bayuart.wordpress.com/2009/06/05/mandriva-2009-1-spring-in-action-d-part-deux/
http://bayu.blitar.org/2009/06/02/warung-internet-1/
http://bayu.blitar.org/2009/06/05/mandriva-20091-spring-in-action-d/
Sekarang kita mo menginjak ke konfigurasi dari mandriva linux yang sebelomnya telah terinstall sebagai gateway server warnet / pc router. Dari tulisan sebelumnya mandriva linux yang digunakan adalah versi mandriva linux 2009.1 spring free edition dual iso serta menggunakan aplikasi server gateway seperti :

shorewall untuk firewall
squid untuk layanan proxy
dhcp-server untuk layanan ip [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bayuart.wordpress.com&blog=140339&post=451&subd=bayuart&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Terusan dari tulisan :</p>
<p><a href="http://bayuart.wordpress.com/2009/06/05/mandriva-2009-1-spring-in-action-d-part-deux/">http://bayuart.wordpress.com/2009/06/05/mandriva-2009-1-spring-in-action-d-part-deux/</a><br />
<a href="http://bayu.blitar.org/2009/06/02/warung-internet-1/">http://bayu.blitar.org/2009/06/02/warung-internet-1/</a><br />
<a href="http://bayu.blitar.org/2009/06/05/mandriva-20091-spring-in-action-d/">http://bayu.blitar.org/2009/06/05/mandriva-20091-spring-in-action-d/</a></p>
<p>Sekarang kita mo menginjak ke konfigurasi dari mandriva linux yang sebelomnya telah terinstall sebagai gateway server warnet / pc router. Dari tulisan sebelumnya mandriva linux yang digunakan adalah versi mandriva linux 2009.1 spring free edition dual iso serta menggunakan aplikasi server gateway seperti :</p>
<ul>
<li><a href="http://www.shorewall.net/">shorewall</a> untuk firewall</li>
<li><a href="http://www.squid-cache.org/">squid</a> untuk layanan proxy</li>
<li><a href="https://www.isc.org/software/dhcp">dhcp-server</a> untuk layanan ip dinamis </li>
<li><a href="http://www.isc.org/products/BIND/">bind</a> untul layanan dns / cache lokal</li>
</ul>
<p><span style="font-weight:bold;">Shorewall</span><br />
Shorewall yang merupakan kependekan dari Shoreline Firewal, merupakan firewall yang berbasiskan kepada iptables yang dipermudah dalam penggunaanya, apabila anda telah terbiasa menggunakan iptables maka anda mungkin tidak akan membutuhkan tools semacam ini, shorewall dapat di installasi pada kebanyakan sistem Linux, disini saya menggunakan mandriva linux 2009.1 spring untuk dijadikan sebagai Gateway+Router dan juga transparent proxy, untuk mendapatkan versi terbarunya anda dapat mengunjungi web resmi <a href="http://www.shorewall.net/">Shorewall</a>.</p>
<p>The Shoreline Firewall, more commonly known as      “<span class="quote">Shorewall</span>”, is high-level tool for configuring Netfilter. You describe your firewall/gateway requirements using entries in a set of configuration files. Shorewall reads those configuration files and with the help of the iptables, iptables-restore, ip and tc utilities, Shorewall configures Netfilter and the Linux networking subsystem to match your requirements. Shorewall can be used on a dedicated firewall system, a multi-function gateway/router/server or on a standalone GNU/Linux system. Shorewall does not use Netfilter&#8217;s ipchains compatibility mode and can thus take advantage of Netfilter&#8217;s connection state tracking capabilities&#8230; from <a href="http://www.shorewall.net/Introduction.html">Shorewall</a>.</p>
<p><a href="http://bayuart.blogspot.com/2009/06/konfigurasi-mandriva-linux-warnet.html">Selengkapnya</a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bayuart.wordpress.com/451/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bayuart.wordpress.com/451/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bayuart.wordpress.com/451/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bayuart.wordpress.com/451/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bayuart.wordpress.com/451/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bayuart.wordpress.com/451/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bayuart.wordpress.com/451/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bayuart.wordpress.com/451/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bayuart.wordpress.com/451/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bayuart.wordpress.com/451/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bayuart.wordpress.com&blog=140339&post=451&subd=bayuart&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://bayuart.wordpress.com/2009/06/09/konfigurasi-mandriva-linux-warnet/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea5f7aca470898c6021cb0e7057a5ae8?s=96&#38;d=monsterid" medium="image">
			<media:title type="html">bayuart</media:title>
		</media:content>
	</item>
		<item>
		<title>Debian iptables</title>
		<link>http://bayuart.wordpress.com/2007/08/16/debian-iptables/</link>
		<comments>http://bayuart.wordpress.com/2007/08/16/debian-iptables/#comments</comments>
		<pubDate>Thu, 16 Aug 2007 13:05:54 +0000</pubDate>
		<dc:creator>bayuart</dc:creator>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[iptables]]></category>

		<guid isPermaLink="false">http://bayuart.wordpress.com/2007/08/16/debian-iptables/</guid>
		<description><![CDATA[Debian sekarang defaultnya tidak pake initscript untuk iptables. Ini artinya akan jadi masalah (buat newbie) pas komputer di reboot ulang, rule iptables ilang !!!.
Untuk ngatasi hal tsb, disini asumsinya debian udah terinstal dengan baik dan bekerja dengan baik pula. Langkah pertama , buat rule iptables dan coba liat daftar rule iptablesnya, seperti dibawah ini:
iptables --list
jika [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bayuart.wordpress.com&blog=140339&post=164&subd=bayuart&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Debian sekarang defaultnya tidak pake initscript untuk iptables. Ini artinya akan jadi masalah (buat newbie) pas komputer di reboot ulang, rule iptables ilang !!!.</p>
<p>Untuk ngatasi hal tsb, disini asumsinya debian udah terinstal dengan baik dan bekerja dengan baik pula. Langkah pertama , buat rule iptables dan coba liat daftar rule iptablesnya, seperti dibawah ini:</p>
<pre>iptables --list</pre>
<p>jika dari perintah tsb diatas hasilnya sama dengan rule iptables yang dibuat, kemudian lakukan penyimpanan. Misalnya simpan ke <tt>/etc/firewall.conf</tt> atau terserah mo disimpan dimana (sesuaikan selera masing-masing)</p>
<pre>iptables-save &gt; /etc/firewall.conf</pre>
<p><span id="more-164"></span>Kemudian buat script untuk start dan stop rule iptables diatas agar setiap kali boot rule iptables akan aktif:</p>
<pre>echo "#!/bin/sh" &gt; /etc/network/if-up.d/iptables
echo "iptables-restore &lt; /etc/firewall.conf" &gt;&gt; /etc/network/if-up.d/iptables
chmod +x /etc/network/if-up.d/iptables</pre>
<p>cara lainnya</p>
<p>edit file /etc/network/interface, isikan seperti contoh ini:</p>
<pre>iface eth0 inet dhcp</pre>
<pre>
        pre-up iptables-restore &lt; /etc/firewall.conf</pre>
<pre></pre>
<p>bisa juga di kopikan initscriptnya iptables dari debian woody</p>
<p>dll</p>
<p>banyak jalan menuju ke roma <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/bayuart.wordpress.com/164/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/bayuart.wordpress.com/164/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bayuart.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bayuart.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bayuart.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bayuart.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bayuart.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bayuart.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bayuart.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bayuart.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bayuart.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bayuart.wordpress.com/164/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bayuart.wordpress.com&blog=140339&post=164&subd=bayuart&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://bayuart.wordpress.com/2007/08/16/debian-iptables/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea5f7aca470898c6021cb0e7057a5ae8?s=96&#38;d=monsterid" medium="image">
			<media:title type="html">bayuart</media:title>
		</media:content>
	</item>
		<item>
		<title>Iptables &#8211; Blok Port TCP + UDP</title>
		<link>http://bayuart.wordpress.com/2007/05/09/iptables-blok-port-tcp-udp/</link>
		<comments>http://bayuart.wordpress.com/2007/05/09/iptables-blok-port-tcp-udp/#comments</comments>
		<pubDate>Wed, 09 May 2007 01:31:55 +0000</pubDate>
		<dc:creator>bayuart</dc:creator>
				<category><![CDATA[Tips]]></category>
		<category><![CDATA[iptables]]></category>

		<guid isPermaLink="false">http://bayuart.wordpress.com/2007/05/09/iptables-blok-port-tcp-udp/</guid>
		<description><![CDATA[ buat file blok-port.sh
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;
#!/bin/bash
#Iptables Blok TCP + UDP
#bayu @ 2006
#last modified 13 feb 2006
#blok-port.sh
clear
printf &#8220;Petunjuk\n&#8221;
printf &#8220;Baca dengan baik, asumsi tau apa yg harus di lakukan\n&#8221;
printf &#8220;Script ini hanya bekerja jika menggunakan eth0 dan eth1\n&#8221;
printf &#8220;Lakukan modifikasi jika Anda menggunakan Dial-Up\n&#8221;
printf &#8220;Isi Ethernet dengan nilai eth0 atau eth1, jika menggunakan Dial-Up\n&#8221;
printf &#8220;sesuaikan dengan nama device Dial-Upnya\n&#8221;
printf [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bayuart.wordpress.com&blog=140339&post=124&subd=bayuart&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p> buat file blok-port.sh<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
#!/bin/bash</p>
<p>#Iptables Blok TCP + UDP<br />
#bayu @ 2006<br />
#last modified 13 feb 2006<br />
#blok-port.sh</p>
<p>clear</p>
<p>printf &#8220;Petunjuk\n&#8221;<br />
printf &#8220;Baca dengan baik, asumsi tau apa yg harus di lakukan\n&#8221;<br />
printf &#8220;Script ini hanya bekerja jika menggunakan eth0 dan eth1\n&#8221;<br />
printf &#8220;Lakukan modifikasi jika Anda menggunakan Dial-Up\n&#8221;<br />
printf &#8220;Isi Ethernet dengan nilai eth0 atau eth1, jika menggunakan Dial-Up\n&#8221;<br />
printf &#8220;sesuaikan dengan nama device Dial-Upnya\n&#8221;<br />
printf &#8220;Port yg akan di blok merupakan Protokol TCP dan UDP\n&#8221;<br />
printf &#8220;Input Port bisa lebih dari 1, misal : \n&#8221;<br />
printf &#8220;80,22,8080 &#8211; Lihat tanda koma\n&#8221;<br />
<span id="more-124"></span><br />
printf &#8220;============================&#8221;<br />
printf &#8220;Ethernet apa ? [eth0/eth1] = &#8220;<br />
read n<br />
printf &#8220;Masukkan Port yang akan di Blok = &#8220;<br />
read y</p>
<p>#dport tcp<br />
iptables -t filter -A INPUT -i $n -p tcp -m multiport &#8211;dports $y -j DROP<br />
iptables -t filter -A OUTPUT -i $n -p tcp -m multiport &#8211;dports $y -j DROP<br />
iptables -t filter -A FORWARD -i $n -p tcp -m multiport &#8211;dports $y -j DROP<br />
#sport udp<br />
iptables -t filter -A INPUT -i $n -p tcp -m tcp &#8211;sport $y -j DROP<br />
iptables -t filter -A OUTPUT -i $n -p tcp -m tcp &#8211;sport $y -j DROP<br />
iptables -t filter -A FORWARD -i $n -p tcp -m tcp &#8211;sport $y -j DROP</p>
<p>#dport udp<br />
iptables -t filter -A INPUT -i $n -p udp -m multiport &#8211;dports $y -j DROP<br />
iptables -t filter -A OUTPUT -i $n -p udp -m multiport &#8211;dports $y -j DROP<br />
iptables -t filter -A FORWARD -i $n -p udp -m multiport &#8211;dports $y -j DROP<br />
#sport udp<br />
iptables -t filter -A INPUT -i $n -p udp -m udp &#8211;sport $y -j DROP<br />
iptables -t filter -A OUTPUT -i $n -p udp -m udp &#8211;sport $y -j DROP<br />
iptables -t filter -A FORWARD -i $n -p udp -m udp &#8211;sport $y -j DROP</p>
<p>clear</p>
<p>iptables -nvL | grep $y</p>
<p>echo &#8220;Port $y di $n  Sudah di Blok&#8221;</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>oke sekarang dibuat jadi executable<br />
#chmod +x blok-port.sh</p>
<p>#./blok-port.sh</p>
<p>Petunjuk<br />
Baca dengan baik, asumsi tau apa yg harus di lakukan<br />
Script ini hanya bekerja jika menggunakan eth0 dan eth1<br />
Lakukan modifikasi jika Anda menggunakan Dial-Up<br />
Isi Ethernet dengan nilai eth0 atau eth1, jika menggunakan Dial-Up<br />
sesuaikan dengan nama device Dial-Upnya<br />
Port yg akan di blok merupakan Protokol TCP dan UDP<br />
Input Port bisa lebih dari 1, misal :<br />
80,22,8080 &#8211; Lihat tanda koma<br />
=========================================<br />
=====script blok port TCP + UDP =========<br />
=========================================<br />
Ethernet apa ? [eth0/eth1] = eth0<br />
Masukkan Port yang akan di Blok = 10000,100000</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>sudah deh&#8230;.<br />
&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;<br />
&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;..<br />
&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.<br />
&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.<br />
waduh sik salah :p~~<br />
errornya</p>
<p>iptables v1.2.9: Can&#8217;t use -i with OUTPUT</p>
<p>nah udah ketahuan salahnya dimana, kalo gitu di comment aja bagian ini :</p>
<p>iptables -t filter -A OUTPUT -i $n -p tcp -m multiport &#8211;dports $y -j DROP<br />
iptables -t filter -A OUTPUT -i $n -p tcp -m tcp &#8211;sport $y -j DROP<br />
iptables -t filter -A OUTPUT -i $n -p udp -m multiport &#8211;dports $y -j DROP<br />
iptables -t filter -A OUTPUT -i $n -p udp -m udp &#8211;sport $y -j DROP</p>
<p>selesai deh <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> )</p>
<p>http://blog.360.yahoo.com/blog-tqY_WC4zer_UwKfWS2Mp?p=46</p>
<p>#update lagi untuk blok IP dan unblok IP yang masuk ke server/firewall</p>
<p>Blok IP</p>
<p>#!/bin/bash</p>
<p>printf &#8220;Masukkan IP yang akan di Blok = &#8220;<br />
read y</p>
<p>iptables -t filter -A INPUT -s $y -d 0/0 -j DROP<br />
iptables -t filter -A OUTPUT -s $y -d 0/0 -j DROP<br />
iptables -t filter -A FORWARD -s $y -d 0/0 -j DROP</p>
<p>clear</p>
<p>iptables -nvL | grep $y</p>
<p>echo &#8220;IP $y Sudah di Blok&#8221;<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>UnBlok IP</p>
<p>#!/bin/bash</p>
<p>printf &#8220;Masukkan IP yang akan di UnBlok = &#8220;<br />
read y</p>
<p>iptables -t filter -D INPUT -s $y -d 0/0 -j DROP<br />
iptables -t filter -D OUTPUT -s $y -d 0/0 -j DROP<br />
iptables -t filter -D FORWARD -s $y -d 0/0 -j DROP</p>
<p>clear</p>
<p>iptables -nvL | grep $y</p>
<p>echo &#8220;IP $y Sudah di Un-Blok&#8221;<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/bayuart.wordpress.com/124/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/bayuart.wordpress.com/124/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bayuart.wordpress.com/124/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bayuart.wordpress.com/124/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bayuart.wordpress.com/124/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bayuart.wordpress.com/124/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bayuart.wordpress.com/124/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bayuart.wordpress.com/124/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bayuart.wordpress.com/124/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bayuart.wordpress.com/124/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bayuart.wordpress.com/124/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bayuart.wordpress.com/124/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bayuart.wordpress.com&blog=140339&post=124&subd=bayuart&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://bayuart.wordpress.com/2007/05/09/iptables-blok-port-tcp-udp/feed/</wfw:commentRss>
		<slash:comments>19</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea5f7aca470898c6021cb0e7057a5ae8?s=96&#38;d=monsterid" medium="image">
			<media:title type="html">bayuart</media:title>
		</media:content>
	</item>
	</channel>
</rss>