Modul 04

Firewall Filter Rules, Pemblokiran File & Web

Modul ini membahas pengamanan jaringan menggunakan Firewall Filter Rules pada MikroTik, meliputi pembatasan lalu lintas ICMP (Ping) ke router maupun antar-klien, pemblokiran unduhan file (.mp3), serta pemblokiran situs web (seperti tkjapps.smksabdev.my.id) menggunakan TLS Host, Layer7 Protocol, dan Web Proxy.

A. Landasan Teori

1. Firewall Filter Rules (Chain Input vs Forward)

Firewall Filter bekerja memeriksa setiap paket data yang melintasi router. Pemilihan Chain menentukan titik pemeriksaan paket:

  • Chain Input: Menangani paket data yang ditujukan langsung ke router (contoh: ping dari klien ke IP Gateway router).
  • Chain Forward: Menangani paket data yang melintasi router dari satu segmen/klien menuju segmen/klien lain atau ke internet.

2. Pemblokiran ICMP (Ping)

ICMP (Internet Control Message Protocol) digunakan untuk pengujian koneksi (ping). Memblokir paket ICMP dengan aksi Action: Drop mencegah perangkat klien melakukan tes ping tanpa memutus akses ke layanan jaringan lainnya seperti web atau HTTPS.

3. Metode Pemblokiran Ekstensi File (.mp3)

MikroTik menyediakan beberapa metode untuk memfilter lalu lintas berdasarkan tipe/ekstensi file:

  • Layer7 Protocol: Menggunakan pencocokan pola ekspresi reguler (Regular Expression / Regexp) pada muatan paket data.
  • Firewall Content: Memeriksa string teks tertentu (contoh: .mp3) pada header paket data HTTP secara lebih praktis dan ringan.
  • Web Proxy Access: Memanfaatkan proxy internal MikroTik untuk memfilter permintaan URL/Path yang mengandung kata kunci file sebelum sampai ke klien.

4. Metode Pemblokiran Situs Web (Domain / URL)

Untuk memblokir akses ke situs web tertentu (contoh: tkjapps.smksabdev.my.id), terdapat beberapa metode yang dapat diterapkan:

  • TLS Host (Firewall Filter): Memeriksa header Server Name Indication (SNI) pada enkripsi HTTPS/TLS, sangat ampuh untuk memblokir domain modern berbasis HTTPS tanpa perlu mendekripsi paket data.
  • Layer7 Protocol (Regexp): Memeriksa nama domain pada header request menggunakan pencocokan pola string (Regular Expression).
  • Web Proxy Access (Dst. Host): Memanfaatkan fitur Web Proxy MikroTik untuk menyaring akses berdasarkan nama domain tujuan secara spesifik.

B. Langkah Kerja Konfigurasi

CATATAN PENTING: Ganti variabel xx pada seluruh IP Address dengan Nomor Absen Siswa. (Contoh: Absen 05 → 172.32.5.1/24).
Langkah 8: Firewall - Blokir Ping DHCP Pool ke Router
  1. Buka menu IP → Firewall → Filter Rules → Klik tombol +.
  2. Tab General:
    • Chain: input
    • Src. Address: 172.32.xx.21-172.32.xx.70
    • Protocol: icmp
  3. Tab Action:
    • Action: drop
  4. Klik Apply, lalu OK.
Langkah 9: Firewall - Blokir Ping IP Pool 21-30 ke IP 61-70
  1. Buka menu IP → Firewall → Filter Rules → Klik tombol +.
  2. Tab General:
    • Chain: forward
    • Src. Address: 172.32.xx.21-172.32.xx.30
    • Dst. Address: 172.32.xx.61-172.32.xx.70
    • Protocol: icmp
  3. Tab Action:
    • Action: drop
  4. Klik Apply, lalu OK.
Langkah 10: Pemblokiran File .mp3 (Metode 1: Layer7 Protocol)
  1. Layer7 Protocol: Buka IP → Firewall → Layer7 Protocols → Klik tombol +.
    • Name: block-mp3
    • Regexp: ^.*\.mp3.*$ → Klik OK.
  2. Filter Rule: Buka tab Filter Rules → Klik tombol +.
    • Tab General: Chain: forward | Src. Address: 172.32.xx.0/24 | Protocol: tcp
    • Tab Advanced: Layer7 Protocol: block-mp3
    • Tab Action: Action: drop
  3. Klik Apply, lalu OK.
Alternatif Pemblokiran File .mp3 (Metode 2: Firewall Content)
  1. Buka menu IP → Firewall → Filter Rules → Klik tombol +.
  2. Tab General:
    • Chain: forward | Protocol: tcp | Dst. Port: 80
    • Src. Address: 172.32.xx.0/24
  3. Tab Advanced:
    • Content: .mp3
  4. Tab Action:
    • Action: drop
  5. Klik Apply, lalu OK.
Alternatif Pemblokiran File .mp3 (Metode 3: Web Proxy Access)
  1. Aktifkan Web Proxy: Buka IP → Web Proxy. Centang Enabled | Port: 8080 | Centang Anonymous → Klik Apply.
  2. Aturan Blokir File: Pada jendela Web Proxy, klik tombol Access → Klik +.
    • Path: *.mp3 | Action: deny → Klik OK.
  3. Redirect HTTP ke Proxy (NAT): Buka IP → Firewall → NAT → Klik +.
    • Tab General: Chain: dstnat | Protocol: tcp | Dst. Port: 80 | In. Interface: ether4
    • Tab Action: Action: redirect | To Ports: 8080 → Klik OK.
Langkah 11: Pemblokiran Situs Web (Contoh: tkjapps.smksabdev.my.id)
  1. Metode 1: Menggunakan TLS Host (Sangat Ringan & Efektif HTTPS/HTTP)
    • Buka menu IP → Firewall → Filter Rules → Klik tombol +.
    • Tab General: Chain: forward | Protocol: tcp | Dst. Port: 443,80
    • Tab Advanced: TLS Host: *tkjapps.smksabdev.my.id*
    • Tab Action: Action: drop → Klik Apply, lalu OK.
  2. Metode 2: Menggunakan Layer7 Protocol (Regexp Target Domain)
    • Buka IP → Firewall → Layer7 Protocols → Klik tombol +.
    • Name: block-web-tkjapps
    • Regexp: ^.*(tkjapps\.smksabdev\.my\.id).*$ → Klik OK.
    • Buka tab Filter Rules → Klik tombol +.
    • Tab General: Chain: forward | Src. Address: 172.32.xx.0/24 | Protocol: tcp
    • Tab Advanced: Layer7 Protocol: block-web-tkjapps
    • Tab Action: Action: drop → Klik Apply, lalu OK.
  3. Metode 3: Menggunakan Web Proxy Access (Untuk Protokol HTTP)
    • Pastikan Web Proxy sudah aktif (seperti pada Langkah Alternatif 3).
    • Buka IP → Web Proxy → Access → Klik tombol +.
    • Dst. Host: *tkjapps.smksabdev.my.id*
    • Action: deny → Klik Apply, lalu OK.