coba dicoba akhirnya jadilah jampi-jampi dibawah ini :
############### IP ADDRESS ##############
/ip address
add address=192.168.2.2/24 network=192.168.2.0 broadcast=192.168.2.255 interface=public1
add address=192.168.3.2/24 network=192.168.3.0 broadcast=192.168.3.255 interface=public2
add address=192.168.4.2/24 network=192.168.4.0 broadcast=192.168.4.255 interface=public3
add address=192.168.5.2/24 network=192.168.5.0 broadcast=192.168.5.255 interface=public-game
add address=192.168.6.1/24 network=192.168.6.0 broadcast=192.168.6.255 interface=local
################# MEMBUAT IP DNS MIKROTIK ################
/ip dns set servers=203.130.193.74,203.130.206.250 \
allow-remote-requests=yes
############### MEMBUAT NAT MASQUARADE MODEM ##############
/ip firewall nat add chain=srcnat \
action=masquerade out-interface=public1
/ip firewall nat add chain=srcnat \
action=masquerade out-interface=public2
/ip firewall nat add chain=srcnat \
action=masquerade out-interface=publi3
/ip firewall nat add chain=srcnat \
action=masquerade out-interface=public-game
/ip firewall nat add chain=srcnat \
action=masquerade out-interface=local
############## MEMBUAT MARK ROUTING PPOE ################
/ip route add gateway=public6 distance=1 routing-mark=PUBLIC1
/ip route add gateway=public7 distance=1 routing-mark=PUBLIC2
/ip route add gateway=public8 distance=1 routing-mark=PUBLIC3
/ip route add gateway=public-game distance=1 routing-mark="PUBLIC GAME"
############## MEMBUAT MARK ROUTING DIAL UP ################
/ip route
add dst-address=0.0.0.0/0 gateway=192.168.2.1 routing-mark=PUBLIC1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=192.168.3.1 routing-mark=PUBLIC2 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=192.168.4.1 routing-mark=PUBLIC3 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=192.168.5.1 routing-mark="PUBLIC GAME" check-gateway=ping
add dst-address=0.0.0.0/0 gateway=192.168.2.1 distance=1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=192.168.3.1 distance=1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=192.168.4.1 distance=1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=192.168.5.1 distance=1 check-gateway=ping
################# MANGLE UNTUK BROWSING #################
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark=PUBLIC1 \
passthrough=yes connection-state=new \
protocol=tcp in-interface=local \
dst-port=80,8080,21,3128,443 nth=3,1 comment=NTH1
/ip firewall mangle add chain=prerouting \
action=mark-routing new-routing-mark=PUBLIC1 \
passthrough=no in-interface=local \
connection-mark=PUBLIC1 comment= MARK1
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark=PUBLIC2 \
passthrough=yes connection-state=new \
protocol=tcp in-interface=local \
dst-port=80,8080,21,3128,443 nth=2,1 comment=NTH2
/ip firewall mangle add chain=prerouting \
action=mark-routing new-routing-mark=PUBLIC2 \
passthrough=no in-interface=local \
connection-mark=PUBLIC2 comment=MARK2
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark=PUBLIC3 \
passthrough=yes connection-state=new \
protocol=tcp in-interface=local \
dst-port=80,8080,21,3128,443 nth=1,1 comment=NTH3
/ip firewall mangle add chain=prerouting \
action=mark-routing new-routing-mark=PUBLIC3 \
passthrough=no in-interface=local \
connection-mark=PUBLIC3 comment=MARK3
######################## MEMBUAT MANGLE KONEKSI GAME #################
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark="PUBLIC GAME" \
passthrough=yes protocol=tcp in-interface=local \
dst-port=1818,2001,3010,4300,5105,5121 comment="GAME ONLINE"
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark="PUBLIC GAME" \
passthrough=yes protocol=tcp in-interface=local \
dst-port=5126,5171,5340-5352,6000-6152,7777
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark="PUBLIC GAME" \
passthrough=yes protocol=tcp in-interface=local \
dst-port=7341-7350,7451,8085,9600,9601-9602,9300
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark="PUBLIC GAME" \
passthrough=yes protocol=tcp in-interface=local \
dst-port=9376-9377,9400,9700,10001-10011
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark="PUBLIC GAME" \
passthrough=yes protocol=tcp in-interface=local \
dst-port=10402,11011-11041,12011,12110,13008,13413
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark="PUBLIC GAME" \
passthrough=yes protocol=tcp in-interface=local \
dst-port=15000-15002,16402-16502,16666,18901-18909,19000
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark="PUBLIC GAME" \
passthrough=yes protocol=tcp in-interface=local \
dst-port=19101,22100,27780,28012,29000,29200
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark="PUBLIC GAME" \
passthrough=yes protocol=tcp in-interface=local \
dst-port=39100,39110,39220,39190,40000,49100
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark="PUBLIC GAME" \
passthrough=yes protocol=udp in-interface=local \
dst-port=1293,1479,6100-6152,7777-7977,8001,9401
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark="PUBLIC GAME" \
passthrough=yes protocol=udp in-interface=local \
dst-port=9600-9602,12020-12080,30000,40000-40010
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark="PUBLIC GAME" \
passthrough=yes protocol=tcp in-interface=local dst-port=9339,843
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark="PUBLIC GAME" \
passthrough=yes protocol=udp in-interface=local \
dst-port=42051-42052,11100-11125,11440-11460
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark="PUBLIC GAME" \
passthrough=yes protocol=tcp in-interface=local \
dst-port=843,9339,8890,843,8001, 8012,8000 comment="GAME FACEBOOK"
/ip firewall mangle add chain=prerouting \
action=mark-routing new-routing-mark="PUBLIC GAME" \
passthrough=no in-interface=local connection-mark="PUBLIC GAME"
####################### ATAU VERSI TERBARU 2013 #################
/ip firewall mangle
add chain=prerouting protocol=udp dst-port=10690,10688,10742,10763,10808\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME" comment="GAME ONLINE"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=39100,39110,39220,39190,49100\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=udp dst-port=41130,41936,40583,40440,40630,40676,40889,40275,41192,41710,40292,40679,40729\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=10001-10015\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=18901-18912\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=7777\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=6881\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=1818\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=19101\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=27780\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=29000\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=22100\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=5121\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=5224\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=6000-7000,8211\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=2001\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=9601-9602\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=8085\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=44405\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=udp dst-port=40000-40010\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=udp dst-port=43403\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=udp dst-port=48026\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=13413\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=udp dst-port=14009,14010\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=14401\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=19000\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=5209,5208,667\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=10009,13008,16666,28012\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=udp dst-port=12020-12080,13000-13080\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=14009,14010\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=6000-6001\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=5340-5352\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=29000,29200,8081\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=10402\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=1900,711\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=3478\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=1723\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=10000-10012\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=10013\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=9600\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=15000-15002\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=16402-16502\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=5126\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=3010\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=11031\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=udp dst-port=11100-11125\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=udp dst-port=11400-11460\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=12011,12110\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=15001-15002\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=udp dst-port=9999,42050-42055\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=4300\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=5300\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=9351\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=9933\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=udp dst-port=27000-27050,8006,9061\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=udp dst-port=15121,15105\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=udp dst-port=40300-40700,41300-42000,42300-42600,43300-43400\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=8001-8010,9015-9020,40300-40600,36567\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=6000-6400\
in-interface=local action=mark-connection \
new-connection-mark="PUBLIC GAME"
/ip firewall mangle add chain=prerouting \
action=mark-connection new-connection-mark="PUBLIC GAME" \
passthrough=yes protocol=udp in-interface=local \
dst-port=843,9339,8890,843,8001,8012,8000 comment="GAME FACEBOOK"
/ip firewall mangle add chain=prerouting \
action=mark-routing new-routing-mark="PUBLIC GAME" \
passthrough=no in-interface=local connection-mark="PUBLIC GAME"
########################## ANTIVIRUS ################################
/ip firewall filter
add action=accept chain=input \
disabled=no dst-port=8291 protocol=tcp
add action=drop chain=forward \
connection-state=invalid disabled=no
add action=drop chain=virus disabled=no \
dst-port=135-139 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=1433-140 protocol=tcp
add action=drop chain=virus \
disabled=no dst-port=445 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=445 protocol=udp
add action=drop chain=virus disabled=no \
dst-port=593 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=1024-1030 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=1080 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=1214 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=1363 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=1364 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=1368 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=1373 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=1377 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=2745 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=2283 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=2535 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=2745 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=3127 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=010 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=4444 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=4444 protocol=udp
add action=drop chain=virus disabled=no \
dst-port=5554 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=8866 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=9898 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=10080 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=1205 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=17300 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=27374 protocol=tcp
add action=drop chain=virus disabled=no \
dst-port=65506 protocol=tcp
add action=jump chain=forward \
disabled=no jump-target=virus
add action=drop chain=input \
connection-state=invalid disabled=no
add action=accept chain=input \
disabled=no protocol=udp
add action=accept chain=input \
disabled=no limit=50/5s,2 protocol=icmp
add action=drop chain=input \
disabled=no protocol=icmp
add action=accept chain=input \
disabled=no dst-port=21 protocol=tcp
add action=accept chain=input \
disabled=no dst-port=22 protocol=tcp
add action=accept chain=input \
disabled=no dst-port=23 protocol=tcp
add action=accept chain=input \
disabled=no dst-port=80 protocol=tcp
add action=accept chain=input \
disabled=no dst-port=8291 protocol=tcp
add action=accept chain=input \
disabled=no dst-port=1723 protocol=tcp
add action=accept chain=input \
disabled=no dst-port=23 protocol=tcp
add action=accept chain=input \
disabled=no dst-port=80 protocol=tcp
add action=accept chain=input disabled=no \
dst-port=1723 protocol=tcp
add action=add-src-to-address-list \
address-list=ddos address-list-timeout=15s \
chain=input disabled=no dst-port=1337 protocol=tcp
add action=add-src-to-address-list \
address-list=ddos address-list-timeout=15m \
chain=input disabled=no dst-port=7331 \
protocol=tcp src-address-list=knock
add action=add-src-to-address-list \
address-list="port scanners" \
address-list-timeout=2w chain=input \
comment="port scanners to list " \
disabled=no protocol=tcp psd=21,3s,3,1
add action=add-src-to-address-list \
address-list="port scanners" \
address-list-timeout=2w chain=input \
comment="syn/fin scan" disabled=no \
protocol=tcp tcp-flags=fin,syn
add action=add-src-to-address-list \
address-list="port scanners" \
address-list-timeout=2w chain=input \
comment="syn/rst scan" disabled=no \
protocol=tcp tcp-flags=syn,rst
add action=add-src-to-address-list \
address-list="port scanners" \
address-list-timeout=2w chain=input \
comment="fin/psh/urg scan" disabled=\
no protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack
add action=add-src-to-address-list \
address-list="port scanners" \
address-list-timeout=2w chain=input \
comment="all/all scan" disabled=no \
protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg
add action=add-src-to-address-list \
address-list="port scanners" \
address-list-timeout=2w chain=input \
comment="nmap null scan" disabled=no \
protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg
add action=accept chain=input \
comment="anti netcut" disabled=no dst-port=\
0-65535 protocol=tcp \
src-address=61.213.183.1-61.213.183.254
add action=accept chain=input \
comment="anti netcut" disabled=no \
dst-port=0-65535 protocol=tcp \
src-address=67.195.10.1-67.195.10.254
add action=accept chain=input \
comment="anti netcut" disabled=no \
dst-port=0-65535 protocol=tcp \
src-address=68.142.233.1-68.142.233.254
add action=accept chain=input \
comment="anti netcut" disabled=no dst-port=\
0-65535 protocol=tcp \
src-address=68.180.217.1-68.180.217.254
add action=accept chain=input \
comment="anti netcut" disabled=no \
dst-port=0-65535 protocol=tcp \
src-address=203.84.204.1-203.84.204.254
add action=accept chain=input \
comment="anti netcut" disabled=no \
dst-port=0-65535 protocol=tcp \
src-address=69.63.176.1-69.63.176.254
add action=accept chain=input \
comment="anti netcut" \
disabled=no dst-port=0-65535 protocol=tcp \
src-address=69.63.181.1-69.63.181.254
add action=accept chain=input \
comment="anti netcut" \
disabled=no dst-port=0-65535 protocol=tcp \
src-address=63.245.209.1-63.245.209.254
add action=accept chain=input \
comment="anti netcut" disabled=no dst-port=\
0-65535 protocol=tcp \
src-address=63.245.213.1-63.245.213.254
/