<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://lms.onnocenter.or.id/wiki/index.php?action=history&amp;feed=atom&amp;title=Firewall_untuk_router_mikrotik</id>
	<title>Firewall untuk router mikrotik - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://lms.onnocenter.or.id/wiki/index.php?action=history&amp;feed=atom&amp;title=Firewall_untuk_router_mikrotik"/>
	<link rel="alternate" type="text/html" href="https://lms.onnocenter.or.id/wiki/index.php?title=Firewall_untuk_router_mikrotik&amp;action=history"/>
	<updated>2026-04-20T06:33:27Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.1</generator>
	<entry>
		<id>https://lms.onnocenter.or.id/wiki/index.php?title=Firewall_untuk_router_mikrotik&amp;diff=21632&amp;oldid=prev</id>
		<title>Onnowpurbo at 01:37, 15 September 2010</title>
		<link rel="alternate" type="text/html" href="https://lms.onnocenter.or.id/wiki/index.php?title=Firewall_untuk_router_mikrotik&amp;diff=21632&amp;oldid=prev"/>
		<updated>2010-09-15T01:37:38Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 01:37, 15 September 2010&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l5&quot;&gt;Line 5:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 5:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Untuk mengamankan router mikrotik dari traffic virus dan excess ping dapat digunakan skrip firewall berikut&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Untuk mengamankan router mikrotik dari traffic &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[&lt;/ins&gt;virus&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;]] &lt;/ins&gt;dan excess ping dapat digunakan skrip &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[&lt;/ins&gt;firewall&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;]] &lt;/ins&gt;berikut&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Pertama buat address-list &amp;quot;ournetwork&amp;quot; yang berisi alamat IP radio,  IP LAN dan IP WAN atau IP lainnya yang dapat dipercaya  &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Pertama buat address-list &amp;quot;ournetwork&amp;quot; yang berisi alamat IP radio,  IP LAN dan IP WAN atau IP lainnya yang dapat dipercaya  &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l129&quot;&gt;Line 129:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 129:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Efek dari skrip diatas adalah:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Efek dari skrip diatas adalah:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# router mikrotik hanya dapat diakses FTP, SSH, Web dan Winbox dari IP yang didefinisikan dalam address-list &quot;ournetwork&quot; sehingga tidak bisa diakses dari sembarang tempat.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# router mikrotik hanya dapat diakses &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[&lt;/ins&gt;FTP&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;]]&lt;/ins&gt;, &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[&lt;/ins&gt;SSH&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;]]&lt;/ins&gt;, &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[&lt;/ins&gt;Web&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;]] &lt;/ins&gt;dan Winbox dari &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[&lt;/ins&gt;IP&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;]] &lt;/ins&gt;yang didefinisikan dalam address-list &quot;ournetwork&quot; sehingga tidak bisa diakses dari sembarang tempat.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Port-port yang sering dimanfaatkan virus di blok sehingga traffic virus tidak dapat dilewatkan, tetapi perlu diperhatikan jika ada user yang kesulitan mengakses service tertentu harus dicek pada chain=&quot;virus&quot; apakah port yang dibutuhkan user tersebut terblok oleh firewall.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Port-port yang sering dimanfaatkan virus di blok sehingga traffic &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[&lt;/ins&gt;virus&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;]] &lt;/ins&gt;tidak dapat dilewatkan, tetapi perlu diperhatikan jika ada user yang kesulitan mengakses service tertentu harus dicek pada chain=&quot;virus&quot; apakah port yang dibutuhkan user tersebut terblok oleh &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[&lt;/ins&gt;firewall&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;]]&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Packet ping dibatasi untuk menghindari excess ping.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Packet ping dibatasi untuk menghindari excess ping.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Onnowpurbo</name></author>
	</entry>
	<entry>
		<id>https://lms.onnocenter.or.id/wiki/index.php?title=Firewall_untuk_router_mikrotik&amp;diff=21631&amp;oldid=prev</id>
		<title>Onnowpurbo: /* Pranala Menarik */</title>
		<link rel="alternate" type="text/html" href="https://lms.onnocenter.or.id/wiki/index.php?title=Firewall_untuk_router_mikrotik&amp;diff=21631&amp;oldid=prev"/>
		<updated>2010-09-15T01:36:46Z</updated>

		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Pranala Menarik&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 01:36, 15 September 2010&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt; &lt;/del&gt;Written by harijanto@datautama.net.id     &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Written by harijanto@datautama.net.id     &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  http://www.datautama.net.id&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  http://www.datautama.net.id&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Thursday, 09 November 2006&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Thursday, 09 November 2006&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l144&quot;&gt;Line 144:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 144:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [[Sekitar Mikrotik]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [[Sekitar Mikrotik]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [[Linux Howto]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [[Linux Howto]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category: WiFi Outdoor]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Onnowpurbo</name></author>
	</entry>
	<entry>
		<id>https://lms.onnocenter.or.id/wiki/index.php?title=Firewall_untuk_router_mikrotik&amp;diff=3143&amp;oldid=prev</id>
		<title>Onnowpurbo: New page:  Written by harijanto@datautama.net.id      http://www.datautama.net.id  Thursday, 09 November 2006    Untuk mengamankan router mikrotik dari traffic virus dan excess ping dapat digunakan ...</title>
		<link rel="alternate" type="text/html" href="https://lms.onnocenter.or.id/wiki/index.php?title=Firewall_untuk_router_mikrotik&amp;diff=3143&amp;oldid=prev"/>
		<updated>2008-03-27T03:42:38Z</updated>

		<summary type="html">&lt;p&gt;New page:  Written by harijanto@datautama.net.id      http://www.datautama.net.id  Thursday, 09 November 2006    Untuk mengamankan router mikrotik dari traffic virus dan excess ping dapat digunakan ...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt; Written by harijanto@datautama.net.id    &lt;br /&gt;
 http://www.datautama.net.id&lt;br /&gt;
 Thursday, 09 November 2006&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Untuk mengamankan router mikrotik dari traffic virus dan excess ping dapat digunakan skrip firewall berikut&lt;br /&gt;
&lt;br /&gt;
Pertama buat address-list &amp;quot;ournetwork&amp;quot; yang berisi alamat IP radio,  IP LAN dan IP WAN atau IP lainnya yang dapat dipercaya &lt;br /&gt;
&lt;br /&gt;
Dalam contoh berikut alamat IP radio adalah = 10.0.0.0/16, IP LAN = 192.168.2.0/24 dan IP WAN = 203.89.24.0/21 dan IP lainnya yang dapat dipercaya = 202.67.33.7&lt;br /&gt;
&lt;br /&gt;
Untuk membuat address-list dapat menggunakan contoh skrip seperti berikut ini tinggal disesuaikan dengan konfigurasi jaringan Anda. &lt;br /&gt;
&lt;br /&gt;
Buat skrtip berikut menggunakan notepad kemudian copy-paste ke console mikrotik  &lt;br /&gt;
&lt;br /&gt;
 / ip firewall address-list&lt;br /&gt;
 add list=ournetwork address=203.89.24.0/21 comment=&amp;quot;Datautama Network&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add list=ournetwork address=10.0.0.0/16 comment=&amp;quot;IP Radio&amp;quot; disabled=no&lt;br /&gt;
 add list=ournetwork address=192.168.2.0/24 comment=&amp;quot;LAN Network&amp;quot; disabled=no&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Selanjutnya copy-paste skrip berikut pada console mikrotik&lt;br /&gt;
&lt;br /&gt;
 / ip firewall filter&lt;br /&gt;
 add chain=forward connection-state=established action=accept comment=&amp;quot;allow \&lt;br /&gt;
     established connections&amp;quot; disabled=no&lt;br /&gt;
 add chain=forward connection-state=related action=accept comment=&amp;quot;allow \&lt;br /&gt;
     related connections&amp;quot; disabled=no&lt;br /&gt;
 add chain=virus protocol=udp dst-port=135-139 action=drop comment=&amp;quot;Drop \&lt;br /&gt;
     Messenger Worm&amp;quot; disabled=no&lt;br /&gt;
 add chain=forward connection-state=invalid action=drop comment=&amp;quot;drop invalid \&lt;br /&gt;
     connections&amp;quot; disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=135-139 action=drop comment=&amp;quot;Drop \&lt;br /&gt;
     Blaster Worm&amp;quot; disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=1433-1434 action=drop comment=&amp;quot;Worm&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=445 action=drop comment=&amp;quot;Drop Blaster \&lt;br /&gt;
     Worm&amp;quot; disabled=no&lt;br /&gt;
 add chain=virus protocol=udp dst-port=445 action=drop comment=&amp;quot;Drop Blaster \&lt;br /&gt;
     Worm&amp;quot; disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=593 action=drop comment=&amp;quot;________&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=1024-1030 action=drop comment=&amp;quot;________&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=1080 action=drop comment=&amp;quot;Drop MyDoom&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=1214 action=drop comment=&amp;quot;________&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=1363 action=drop comment=&amp;quot;ndm requester&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=1364 action=drop comment=&amp;quot;ndm server&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=1368 action=drop comment=&amp;quot;screen cast&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=1373 action=drop comment=&amp;quot;hromgrafx&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=1377 action=drop comment=&amp;quot;cichlid&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=2745 action=drop comment=&amp;quot;Bagle Virus&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=2283 action=drop comment=&amp;quot;Drop Dumaru.Y&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=2535 action=drop comment=&amp;quot;Drop Beagle&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=2745 action=drop comment=&amp;quot;Drop \&lt;br /&gt;
     Beagle.C-K&amp;quot; disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=3127 action=drop comment=&amp;quot;Drop MyDoom&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=3410 action=drop comment=&amp;quot;Drop Backdoor \&lt;br /&gt;
     OptixPro&amp;quot; disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=4444 action=drop comment=&amp;quot;Worm&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=udp dst-port=4444 action=drop comment=&amp;quot;Worm&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=5554 action=drop comment=&amp;quot;Drop Sasser&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=8866 action=drop comment=&amp;quot;Drop Beagle.B&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=9898 action=drop comment=&amp;quot;Drop \&lt;br /&gt;
     Dabber.A-B&amp;quot; disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=10000 action=drop comment=&amp;quot;Drop \&lt;br /&gt;
     Dumaru.Y, sebaiknya di didisable karena juga sering digunakan utk vpn atau \&lt;br /&gt;
     webmin&amp;quot; disabled=yes&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=10080 action=drop comment=&amp;quot;Drop \&lt;br /&gt;
     MyDoom.B&amp;quot; disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=12345 action=drop comment=&amp;quot;Drop NetBus&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=17300 action=drop comment=&amp;quot;Drop Kuang2&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=27374 action=drop comment=&amp;quot;Drop \&lt;br /&gt;
     SubSeven&amp;quot; disabled=no&lt;br /&gt;
 add chain=virus protocol=tcp dst-port=65506 action=drop comment=&amp;quot;Drop PhatBot, \&lt;br /&gt;
     Agobot, Gaobot&amp;quot; disabled=no&lt;br /&gt;
 add chain=forward action=jump jump-target=virus comment=&amp;quot;jump to the virus \&lt;br /&gt;
     chain&amp;quot; disabled=no&lt;br /&gt;
 add chain=input connection-state=established action=accept comment=&amp;quot;Accept \&lt;br /&gt;
     established connections&amp;quot; disabled=no&lt;br /&gt;
 add chain=input connection-state=related action=accept comment=&amp;quot;Accept related \&lt;br /&gt;
     connections&amp;quot; disabled=no&lt;br /&gt;
 add chain=input connection-state=invalid action=drop comment=&amp;quot;Drop invalid \&lt;br /&gt;
     connections&amp;quot; disabled=no&lt;br /&gt;
 add chain=input protocol=udp action=accept comment=&amp;quot;UDP&amp;quot; disabled=no&lt;br /&gt;
 add chain=input protocol=icmp limit=50/5s,2 action=accept comment=&amp;quot;Allow \&lt;br /&gt;
     limited pings&amp;quot; disabled=no&lt;br /&gt;
 add chain=input protocol=icmp action=drop comment=&amp;quot;Drop excess pings&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=input protocol=tcp dst-port=21 src-address-list=ournetwork \&lt;br /&gt;
     action=accept comment=&amp;quot;FTP&amp;quot; disabled=no&lt;br /&gt;
 add chain=input protocol=tcp dst-port=22 src-address-list=ournetwork \&lt;br /&gt;
     action=accept comment=&amp;quot;SSH for secure shell&amp;quot; disabled=no&lt;br /&gt;
 add chain=input protocol=tcp dst-port=23 src-address-list=ournetwork \&lt;br /&gt;
     action=accept comment=&amp;quot;Telnet&amp;quot; disabled=no&lt;br /&gt;
 add chain=input protocol=tcp dst-port=80 src-address-list=ournetwork \&lt;br /&gt;
     action=accept comment=&amp;quot;Web&amp;quot; disabled=no&lt;br /&gt;
 add chain=input protocol=tcp dst-port=8291 src-address-list=ournetwork \&lt;br /&gt;
     action=accept comment=&amp;quot;winbox&amp;quot; disabled=no&lt;br /&gt;
 add chain=input protocol=tcp dst-port=1723 action=accept comment=&amp;quot;pptp-server&amp;quot; \&lt;br /&gt;
     disabled=no&lt;br /&gt;
 add chain=input src-address-list=ournetwork action=accept comment=&amp;quot;From \&lt;br /&gt;
     Datautama network&amp;quot; disabled=no&lt;br /&gt;
 add chain=input action=log log-prefix=&amp;quot;DROP INPUT&amp;quot; comment=&amp;quot;Log everything \&lt;br /&gt;
     else&amp;quot; disabled=no&lt;br /&gt;
 add chain=input action=drop comment=&amp;quot;Drop everything else&amp;quot; disabled=no &lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Efek dari skrip diatas adalah:&lt;br /&gt;
&lt;br /&gt;
# router mikrotik hanya dapat diakses FTP, SSH, Web dan Winbox dari IP yang didefinisikan dalam address-list &amp;quot;ournetwork&amp;quot; sehingga tidak bisa diakses dari sembarang tempat.&lt;br /&gt;
# Port-port yang sering dimanfaatkan virus di blok sehingga traffic virus tidak dapat dilewatkan, tetapi perlu diperhatikan jika ada user yang kesulitan mengakses service tertentu harus dicek pada chain=&amp;quot;virus&amp;quot; apakah port yang dibutuhkan user tersebut terblok oleh firewall.&lt;br /&gt;
# Packet ping dibatasi untuk menghindari excess ping.&lt;br /&gt;
&lt;br /&gt;
Selain itu yang perlu diperhatikan adalah: sebaiknya buat user baru dan password dengan group full kemudian disable user admin, hal ini untuk meminimasi resiko mikrotik Anda di hack orang.&lt;br /&gt;
&lt;br /&gt;
Selamat mencoba &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Pranala Menarik==&lt;br /&gt;
&lt;br /&gt;
* [[Sekitar Mikrotik]]&lt;br /&gt;
* [[Linux Howto]]&lt;/div&gt;</summary>
		<author><name>Onnowpurbo</name></author>
	</entry>
</feed>