Konfigurasi anti-bocor agar pelanggan isolir langsung diarahkan ke https://billing.ispanda.com tanpa bisa berselancar gratis.
Penyesuaian IP Mikrotik
Untuk menghindari bentrok dengan Hotspot (10.10.10.x) & Lokal Anda, script ini menggunakan segmen IP terpisah khusus Isolir:
10.254.254.x
Pilih Metode Konfigurasi
Ini adalah cara tercepat. Cukup buka New Terminal di Winbox Anda, lalu copy dan paste semua kode di bawah ini, lalu tekan Enter.
# 1. Buat IP Pool Khusus Isolir (Agar tidak bentrok dengan IP Hotspot & Lokal) /ip pool add name="POOL-ISOLIR" ranges=10.254.254.2-10.254.254.254 # 2. Buat Profile Isolir PPPoE (IP klien otomatis masuk ke ISOLIR-LIST) /ppp profile add name="ISOLIR-BILLINGPRO" address-list="ISOLIR-LIST" local-address=10.254.254.1 remote-address="POOL-ISOLIR" rate-limit="512k/512k" # 3. Setup Web Proxy untuk Redirect ke Halaman Isolir VPS /ip proxy set enabled=yes port=8080 /ip proxy access add action=allow dst-address=10.10.10.254 comment="Allow ke VPS" add action=deny dst-port=80 redirect-to="http://10.10.10.254/isolir.html" comment="Redirect ke Isolir" # 4. Belokkan Trafik HTTP Pelanggan Isolir ke Web Proxy (Untuk Trigger Pop-Up HP) /ip firewall nat add chain=dstnat action=redirect to-ports=8080 protocol=tcp src-address-list="ISOLIR-LIST" dst-port=80 comment="Redirect HTTP Isolir ke WebProxy" # 5. Filter Rules Anti-Bocor (Pasang Gembok) /ip firewall filter add chain=forward action=accept src-address-list="ISOLIR-LIST" dst-address=10.10.10.254 comment="1. Allow Akses VPS Billing" add chain=forward action=accept protocol=udp src-address-list="ISOLIR-LIST" dst-port=53 comment="2. Allow DNS Isolir" add chain=forward action=drop src-address-list="ISOLIR-LIST" comment="3. Drop Semua Internet Isolir (WA, TikTok, Game, dll Blokir Total)"
Masuk ke IP > Firewall > Filter Rules. Pastikan 3 aturan baru yang dibuat oleh script di atas ditarik (drag & drop) ke urutan PALING ATAS agar tidak kalah dengan aturan prioritas internet Anda yang lain.