Uji Kompetensi

UKK Paket 2 - Server & Keamanan Jaringan

Soal praktikum dan panduan konfigurasi UKK Paket 2 - Multi-VLAN Trunking, Web Proxy Site Blocking, Layer 7 Firewall Filter, dan Security Hardening Server.

UKK Paket 2: Server & Keamanan Jaringan

Modul ini berfokus pada Soal UKK Paket 2 yang menitikberatkan pada aspek Keamanan Jaringan (Network Security), pemisahan segmen jaringan menggunakan VLAN (Virtual Local Area Network), filtering konten web terlarang, serta pengamanan akses remote server.

Nama Paket: UKK Paket 2 — Administrasi Server & Keamanan Jaringan Enterprise
Alokasi Waktu: 3 Jam (180 Menit)
Tingkat: Kelas XII SMK Konsentrasi Keahlian TJKT / TKJ

📐 Topologi VLAN & Security Hardening

                      [ ISP / Internet Gateway ]
                                  │
                                  │ (ether1 - WAN)
                       ┌──────────┴──────────┐
                       │ Router MikroTik     │
                       │ (VLAN Trunking)     │
                       └──────────┬──────────┘
                                  │ (ether2 - Trunk Port VLAN 10,20)
                       ┌──────────┴──────────┐
                       │ Switch Managed /    │
                       │ Smart Switch        │
                       └────┬────────────┬───┘
     (Access Port VLAN 10)  │            │ (Access Port VLAN 20)
                            │            │
             ┌──────────────┴──┐      ┌──┴──────────────┐
             │ VLAN 10 (GURU)  │      │ VLAN 20 (SISWA) │
             │ 192.168.10.0/24 │      │ 192.168.20.0/24 │
             └─────────────────┘      └─────────────────┘

📋 Spesifikasi Kebutuhan & Parameter Konfigurasi

1. Router MikroTik Security & VLAN:

  • WAN Interface (ether1): IP DHCP Client dari ISP.
  • Interface Trunk (ether2):
    • VLAN 10 (GURU): VLAN ID 10, Network IP 192.168.10.1/24.
    • VLAN 20 (SISWA): VLAN ID 20, Network IP 192.168.20.1/24.
  • DHCP Server:
    • VLAN 10 (GURU): Pool IP 192.168.10.10 - 192.168.10.50.
    • VLAN 20 (SISWA): Pool IP 192.168.20.10 - 192.168.20.50.
  • Firewall & Site Blocking (Layer 7 / Web Proxy):
    • Blokir Akses Website: Domain linux.org (atau website yang ditentukan penguji).
    • Blokir Ekstensi File Download: File ekstensi .mp3 dan .mkv pada jam sekolah.
    • Logging Rules: Catat seluruh log percobaan akses situs terlarang ke syslog (prefix=BLOKIR-AKSES).

2. Linux Server Security Hardening (Debian 12):

  • IP Address Statis: 192.168.10.100/24 (Segmen VLAN GURU).
  • SSH Hardening (OpenSSH Server):
    • Ubah Port Default SSH dari 22 ➔ Port 5022.
    • Matikan Root Login Langsung (PermitRootLogin no).
    • Otentikasi Berbasis SSH Key Pair (Public Key Auth).
  • Firewall Server (UFW / Iptables):
    • Hanya mengizinkan port 5022 (SSH) dan port 80/443 (HTTP/HTTPS). Blokir port lainnya.

🛠️ Langkah-Langkah Eksekusi Praktikum

Step 1: Konfigurasi Interface VLAN di MikroTik

Buka Terminal Winbox pada Router, jalankan:

# 1. Menambahkan Interface VLAN pada ether2
/interface vlan add name=vlan10-GURU vlan-id=10 interface=ether2
/interface vlan add name=vlan20-SISWA vlan-id=20 interface=ether2

# 2. Memberi Alamat IP pada Interface VLAN
/ip address add address=192.168.10.1/24 interface=vlan10-GURU
/ip address add address=192.168.20.1/24 interface=vlan20-SISWA

# 3. Membuat DHCP Server untuk Masing-Masing VLAN
/ip dhcp-server setup
# Ikuti wizard wizard interface vlan10-GURU & vlan20-SISWA

Step 2: Konfigurasi Web Proxy Site & File Blocking

Aktifkan service Web Proxy pada MikroTik:

# Enable Web Proxy
/ip proxy set enabled=yes port=8080 anonymous=yes

# Redirect Traffic HTTP ke Web Proxy (Transparent Proxy)
/ip firewall nat add chain=dstnat protocol=tcp dst-port=80 action=redirect to-ports=8080

# Web Proxy Access Rules (Blokir Domain & File)
/ip proxy access add dst-host=*linux.org* action=deny
/ip proxy access add path=*.mp3 action=deny
/ip proxy access add path=*.mkv action=deny

Step 3: Layer 7 Protocol Firewall Filtering

Jika ingin memblokir website HTTPS menggunakan Layer 7 Protocol:

# Buat L7 Pattern RegEx
/ip firewall layer7-protocol add name=block-sites regexp="^.*(linux.org|dwnload.com).*\$"

# Tambahkan Filter Rule Drop
/ip firewall filter add chain=forward layer7-protocol=block-sites action=drop comment="Drop Situs Terlarang UKK"

Step 4: SSH Hardening pada Linux Server (Debian)

Buka terminal Debian Server, edit file /etc/ssh/sshd_config:

sudo nano /etc/ssh/sshd_config

Lakukan modifikasi baris berikut:

# Ubah Port Default
Port 5022

# Matikan Root Direct Login
PermitRootLogin no

# Hanya Izinkan User Administrator
AllowUsers admin-tkj

Simpan file, lalu restart service SSH:

sudo systemctl restart ssh

Step 5: Setting UFW Firewall pada Server

Aktifkan Uncomplicated Firewall (UFW) di Debian Server:

# Instal UFW jika belum terpasang
sudo apt update && sudo apt install ufw -y

# Set Default Policy Drop Incoming
sudo ufw default deny incoming
sudo ufw default allow outgoing

# Izinkan Port SSH Baru & Web Server
sudo ufw allow 5022/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

# Aktifkan Firewall
sudo ufw enable

🧪 Pengujian & Verifikasi Hasil Penilaian UKK

Komponen PengujianMetode PengujianExpexted Result (Hasil yang Diharapkan)
Segregasi VLANTancapkan PC Client ke Port VLAN 10 & VLAN 20PC menerima IP subnet 192.168.10.x (VLAN 10) atau 192.168.20.x (VLAN 20).
Site BlockingAkses http://linux.org via browser clientMuncul pesan 403 Forbidden / Access Denied dari MikroTik Web Proxy.
Extension BlockingCoba unduh file contoh .mp3 dari internetDownload terputus / diblokir oleh sistem proxy router.
SSH Custom PortRemote server: ssh -p 5022 admin-tkj@192.168.10.100Berhasil login. Remote port 22 ditolak (Connection Refused).
Root Login ProtectionRemote langsung sebagai root: ssh -p 5022 root@192.168.10.100Ditolak oleh server (Permission Denied).

Sudah Selesai Mempelajari Modul Ini?

Tandai modul ini untuk mencatat progress belajar Anda.