Firewall Filter Rules, Pemblokiran File & Web
Modul ini membahas pengamanan jaringan menggunakan Firewall Filter Rules pada MikroTik, meliputi pembatasan lalu lintas ICMP (Ping) ke router maupun antar-klien, pemblokiran unduhan file (.mp3), serta pemblokiran situs web (seperti tkjapps.smksabdev.my.id) menggunakan TLS Host, Layer7 Protocol, dan Web Proxy.
A. Landasan Teori
1. Firewall Filter Rules (Chain Input vs Forward)
Firewall Filter bekerja memeriksa setiap paket data yang melintasi router. Pemilihan Chain menentukan titik pemeriksaan paket:
- Chain Input: Menangani paket data yang ditujukan langsung ke router (contoh: ping dari klien ke IP Gateway router).
- Chain Forward: Menangani paket data yang melintasi router dari satu segmen/klien menuju segmen/klien lain atau ke internet.
2. Pemblokiran ICMP (Ping)
ICMP (Internet Control Message Protocol) digunakan untuk pengujian koneksi (ping). Memblokir paket ICMP dengan aksi Action: Drop mencegah perangkat klien melakukan tes ping tanpa memutus akses ke layanan jaringan lainnya seperti web atau HTTPS.
3. Metode Pemblokiran Ekstensi File (.mp3)
MikroTik menyediakan beberapa metode untuk memfilter lalu lintas berdasarkan tipe/ekstensi file:
- Layer7 Protocol: Menggunakan pencocokan pola ekspresi reguler (Regular Expression / Regexp) pada muatan paket data.
- Firewall Content: Memeriksa string teks tertentu (contoh:
.mp3) pada header paket data HTTP secara lebih praktis dan ringan. - Web Proxy Access: Memanfaatkan proxy internal MikroTik untuk memfilter permintaan URL/Path yang mengandung kata kunci file sebelum sampai ke klien.
4. Metode Pemblokiran Situs Web (Domain / URL)
Untuk memblokir akses ke situs web tertentu (contoh: tkjapps.smksabdev.my.id), terdapat beberapa metode yang dapat diterapkan:
- TLS Host (Firewall Filter): Memeriksa header Server Name Indication (SNI) pada enkripsi HTTPS/TLS, sangat ampuh untuk memblokir domain modern berbasis HTTPS tanpa perlu mendekripsi paket data.
- Layer7 Protocol (Regexp): Memeriksa nama domain pada header request menggunakan pencocokan pola string (Regular Expression).
- Web Proxy Access (Dst. Host): Memanfaatkan fitur Web Proxy MikroTik untuk menyaring akses berdasarkan nama domain tujuan secara spesifik.
B. Langkah Kerja Konfigurasi
- Buka menu IP → Firewall → Filter Rules → Klik tombol +.
-
Tab General:
- Chain: input
- Src. Address: 172.32.xx.21-172.32.xx.70
- Protocol: icmp
-
Tab Action:
- Action: drop
- Klik Apply, lalu OK.
- Buka menu IP → Firewall → Filter Rules → Klik tombol +.
-
Tab General:
- Chain: forward
- Src. Address: 172.32.xx.21-172.32.xx.30
- Dst. Address: 172.32.xx.61-172.32.xx.70
- Protocol: icmp
-
Tab Action:
- Action: drop
- Klik Apply, lalu OK.
-
Layer7 Protocol: Buka IP → Firewall → Layer7 Protocols → Klik tombol +.
- Name: block-mp3
- Regexp: ^.*\.mp3.*$ → Klik OK.
-
Filter Rule: Buka tab Filter Rules → Klik tombol +.
- Tab General: Chain: forward | Src. Address: 172.32.xx.0/24 | Protocol: tcp
- Tab Advanced: Layer7 Protocol: block-mp3
- Tab Action: Action: drop
- Klik Apply, lalu OK.
- Buka menu IP → Firewall → Filter Rules → Klik tombol +.
-
Tab General:
- Chain: forward | Protocol: tcp | Dst. Port: 80
- Src. Address: 172.32.xx.0/24
-
Tab Advanced:
- Content: .mp3
-
Tab Action:
- Action: drop
- Klik Apply, lalu OK.
- Aktifkan Web Proxy: Buka IP → Web Proxy. Centang Enabled | Port: 8080 | Centang Anonymous → Klik Apply.
-
Aturan Blokir File: Pada jendela Web Proxy, klik tombol Access → Klik +.
- Path: *.mp3 | Action: deny → Klik OK.
-
Redirect HTTP ke Proxy (NAT): Buka IP → Firewall → NAT → Klik +.
- Tab General: Chain: dstnat | Protocol: tcp | Dst. Port: 80 | In. Interface: ether4
- Tab Action: Action: redirect | To Ports: 8080 → Klik OK.
-
Metode 1: Menggunakan TLS Host (Sangat Ringan & Efektif HTTPS/HTTP)
- Buka menu IP → Firewall → Filter Rules → Klik tombol +.
- Tab General: Chain: forward | Protocol: tcp | Dst. Port: 443,80
- Tab Advanced: TLS Host: *tkjapps.smksabdev.my.id*
- Tab Action: Action: drop → Klik Apply, lalu OK.
-
Metode 2: Menggunakan Layer7 Protocol (Regexp Target Domain)
- Buka IP → Firewall → Layer7 Protocols → Klik tombol +.
- Name: block-web-tkjapps
- Regexp: ^.*(tkjapps\.smksabdev\.my\.id).*$ → Klik OK.
- Buka tab Filter Rules → Klik tombol +.
- Tab General: Chain: forward | Src. Address: 172.32.xx.0/24 | Protocol: tcp
- Tab Advanced: Layer7 Protocol: block-web-tkjapps
- Tab Action: Action: drop → Klik Apply, lalu OK.
-
Metode 3: Menggunakan Web Proxy Access (Untuk Protokol HTTP)
- Pastikan Web Proxy sudah aktif (seperti pada Langkah Alternatif 3).
- Buka IP → Web Proxy → Access → Klik tombol +.
- Dst. Host: *tkjapps.smksabdev.my.id*
- Action: deny → Klik Apply, lalu OK.