Tembok di Tengah Pusaran: Memilih dan Menempatkan Firewall di Ekosistem Rumah Sakit
Tembok di Tengah Pusaran: Memilih dan Menempatkan Firewall di Ekosistem Rumah Sakit
Setelah membicarakan penggantian sistem, pertahanan perimeter menjadi pertanyaan berikutnya: di lingkungan di mana data pasien mengalir deras dan ancaman siber tak kenal waktu, memilih dan menempatkan firewall bukan sekadar urusan teknis, tapi pertaruhan kepercayaan.
Bayangkan rumah sakit ini seperti sebuah benteng. Ada pintu gerbang besar (koneksi internet dari ISP). Di dalamnya, ada lorong-lorong (jaringan lokal) yang menuju ke ruang-ruang vital: IGD (server pasien), Kamar Operasi (server lab dan radiologi), Apotek (server farmasi). Sekarang, tugas kita adalah memasang pintu berlapis besi yang sangat kuat di gerbang itu. Tapi bukan sembarang pintu. Pintu ini harus bisa membedakan antara ambulans yang membawa pasien gawat (data legit) dengan truk yang berpura-pura ambulans tapi isinya perampok (malware). Dan yang lebih tricky lagi, terkadang si ‘ambulans’ itu sendiri tanpa sadar sudah membawa ‘perampok’ di bagasinya (data terinfeksi dari device pihak ketiga). Firewall adalah pintu berlapis besi itu. Dan memilihnya adalah sebuah cerita panjang yang dimulai dari ruang rapat yang penuh dengan brosur glossy, dan berakhir di ruang server yang dingin dengan kabel berceceran.
Ada dua vendor besar yang selalu disebut: Sophos dan Fortinet. Presentasi dari keduanya mirip. Slide-nya penuh dengan grafik yang menunjukkan mereka “terbaik di kelasnya”, dengan logo perisai dan pedang yang terlihat garang. Sales Sophos bicara dengan aksen sedikit Inggris, menekankan “kemudahan manajemen berbasis cloud”. Sales Fortinet, lebih blak-blakan, menunjuk angka “throughput” dan “latensi rendah” sambil matanya mengatakan, “Kami untuk yang serius.” Kita duduk di tengah, dengan tim kecil yang terdiri dari saya dan Mas Agus, jaringan kami yang sudah sepuh. Kami tidak mendengarkan brosur. Kami mendengarkan pengalaman di forum teknis yang gelap, cerita dari teman di rumah sakit lain yang firewall-nya “ngadat pas weekend”, dan yang paling penting: bagaimana *support*-nya kalau ada masalah jam 2 pagi di hari libur nasional.
Konflik batin pertama adalah filosofis: apakah firewall ini akan kita jadikan router utama atau perangkat keamanan di belakang router? Pilihan pertama membuatnya jadi pusat segala lalu lintas. Semua aturan, semua kebijakan, semua hidup-mati jaringan ada di situ. Ini seperti menjadikan seorang prajurit elite sekaligus sebagai penjaga gerbang dan pengatur lalu lintas dalam kota. Keren, tapi risiko single point of failure-nya tinggi. Kalau prajurit itu kolaps, seluruh kota lumpuh. Pilihan kedua lebih konservatif. Router lama (yang sudah stabil bertahun-tahun) tetap mengatur lalu lintas dasar. Firewall ditaruh di belakangnya, fokus jadi “pemeriksa kendaraan” yang ketat. Ini membagi tanggung jawab. Tapi kompleksitas konfigurasinya bertambah. Kita harus memutuskan: apakah kita ingin sebuah alat yang serba-bisa dan menjadi satu-satunya tumpuan, atau sistem berlapis yang saling mendukung tapi lebih rumit diurus? Keputusan ini tak ada di brosur manapun. Ini adalah pertaruhan intuisi teknis.
Dalam ekosistem rumah sakit, firewall bukan cuma soal blokir virus. Ia harus paham “bahasa” medis. Ia harus bisa membedakan antara lalu lintas normal dari mesin EKG ke server, dengan lalu lintas mencurigakan yang mencoba menyusup ke server yang sama. Ia harus mengizinkan akses remote untuk dokter konsulen dari luar kota, tapi sekaligus memastikan akses itu super aman. Dan yang paling sulit: ia tidak boleh memperlambat akses ke gambar radiologi yang berukuran 2GB. Seorang radiolog yang menunggu lama untuk load gambar CT-Scan bisa jadi stres, dan stresnya itu bisa berujung pada protes ke direksi. Jadi, firewall ini harus kuat sekaligus lincah. Seperti ninja yang bisa menghentikan panah tapi tidak menghalangi jalan tabib yang sedang buru-buru.
Proses uji coba (proof of concept) adalah fase yang paling mengungkap kebenaran. Saat unit demo dipasang, semua janji di slide diuji di lapangan. Kita sengaja membobolkan traffic mencurigakan. Kita coba akses dari luar seolah-olah hacker. Kita pantau CPU-nya ketika seluruh rumah sakit online jam 9 pagi. Di sinilah kita tahu, vendor A mungkin punya interface yang lebih cantik, tapi log-nya (catatan aktivitas) berantakan. Vendor B mungkin kurang user-friendly, tapi alert-nya (peringatan) sangat detail dan cepat. Pilihan akhir seringkali jatuh bukan pada yang “terbaik”, tapi pada yang “paling bisa kita hidupi ketika terjadi bencana”. Karena pada akhirnya, alat ini akan menjadi bagian dari hidup kita. Kita yang akan menerima telpon ketika ada alarm. Kita yang akan menyelidiki log-nya. Kita yang akan disalahkan jika gagal.
Lalu ada dilema biaya. Firewall kelas enterprise itu harganya bisa setara dengan satu mobil baru LCGC. Tapi yang kita beli bukan fisik kotaknya. Kita membeli license untuk update threat intelligence, untuk dukungan teknis prioritas, untuk fitur keamanan tambahan. Ini adalah langganan keamanan. Dan di sini, manajemen sering bertanya, “Memangnya kalau nggak beli license tahun ini, langsung kena serangan?” Jawaban jujurnya: tidak langsung. Tapi seperti tidak memperbarui vaksin. Sistem akan tetap berjalan, tapi pertahanannya semakin tua, semakin buta terhadap ancaman baru. Menjelaskan ini ke orang non-teknik adalah seni tersendiri. Harus pakai analogi yang pas, tanpa menimbulkan kepanikan.
Penempatan fisiknya pun punya cerita. Meletakkannya di rak server yang penuh dan panas? Atau di rak terpisah yang lebih dingin? Kabel power-nya disambung ke UPS yang mana? Keputusan-keputusan kecil ini, yang sepele di kertas, bisa menjadi penentu saat terjadi gangguan listrik atau kebakaran kecil. Ini adalah kerja sunyi yang tak terlihat: merencanakan kegagalan. Berasumsi bahwa suatu hari nanti, sesuatu akan salah. Dan ketika itu terjadi, kita sudah punya rencana B, C, dan D.
Setelah semua terpasang, konfigurasi selesai, license teraktivasi, ada sebuah keheningan aneh. Firewall itu bekerja tanpa suara. Lampu LED-nya berkedip teratur. Dashboard di layar kita menunjukkan garis-garis hijau. Tidak ada yang terjadi. Dan justru itulah tujuannya. Kesuksesan tertinggi dari sebuah firewall adalah ketika ia tidak pernah menjadi berita. Ketika ia diam-diam menolak ratusan ribu percobaan serangan setiap hari tanpa pernah mengganggu kerja seorang perawat yang menginput data pasien atau seorang dokter yang mengakses hasil lab. Ia adalah penjaga yang tak terlihat. Keberadaannya hanya dirasakan ketika ia absen—saat serangan berhasil menerobos dan kekacauan dimulai.
Maka, merawat firewall adalah ritual sunyi. Mengecek log setiap pagi, meski tidak ada alarm. Memantau penggunaan bandwidth untuk pola yang aneh. Memperbarui aturan ketika ada departemen baru. Ini adalah hubungan jangka panjang dengan sebuah mesin yang menjadi tembok pertama antara data sensitif ribuan orang dengan dunia luar yang seringkali bermusuhan. Dan seperti semua hubungan, butuh komitmen dan perhatian rutin.
Pada akhirnya, di balik layar rumah sakit, keputusan untuk memilih dan menempatkan firewall adalah perwujudan dari kerja sunyi sistem—sebuah investasi pada tembok tak kasat mata yang menentukan apakah denyut informasi tetap aman atau berubah menjadi malapetaka.
FAQ: Pertanyaan Seputar Firewall yang Sering Muncul
1. Firewall mahal banget. Nggak bisa pakai yang gratis atau murah?
Bisa saja. Sama seperti kamu bisa pakai gembok plastik mainan untuk pintu rumah. Fungsi mengunci-nya ada. Tapi apakah kamu akan tidur nyenyak kalau di dalam rumah ada barang berharga dan data hidup orang? Pikirkan lagi.
2. Sophos vs Fortinet, yang mana lebih bagus?
Pertanyaannya salah. Yang benar: untuk kebutuhan dan kemampuan tim kita yang seperti ini, mana yang lebih *cocok*? Sama kayak nanya “motor trail vs motor matic, mana lebih bagus?”. Tergantung kamu mau dipake jalan di mana dan oleh siapa.
3. Setelah pasang firewall, apakah pasti 100% aman?
Tidak. Firewall itu seperti sabuk pengaman. Penting banget, menyelamatkan nyawa saat kecelakaan. Tapi pakai sabuk pengaman bukan berarti kamu bisa ngebut-ngebut seenaknya atau nyetir sambil tidur. Keamanan adalah kebiasaan, bukan cuma alat.
4. Kenapa license-nya mahal dan harus diperbarui tiap tahun?
Karena ancaman baru muncul tiap hari. License itu seperti iuran untuk punya “mata-mata” di seluruh dunia yang terus memantau pola serangan terbaru, lalu mengirimkan “wajah para perampok” itu ke firewall kamu. Tanpa update, firewall kamu hanya kenal perampok jaman dulu.
5. Apa yang harus dilakukan pertama kali kalau firewall ngelap (down)?
Tarik napas. Jangan panik. Lalu lihat skenario kegagalan yang sudah kamu siapkan (siapa bilang nggak perlu?). Biasanya ada mode bypass atau failover. Kalau nggak ada… ya, selamat menjalani jam-jam paling mendebarkan dalam kariermu.
6. Apakah firewall memperlambat internet?
Bisa iya, bisa tidak. Tergantung konfigurasi dan spesifikasi. Firewall yang bagus dan diatur dengan benar seperti polisi lalu lintas yang efisien: justru mencegah kemacetan dengan mengatur arus. Yang jelek atau salah setel? Ya seperti polisi yang malah ngeblokir jalan utama.
7. Kapan tahu kalau firewall kita sudah perlu diganti?
Beberapa tanda: license terakhir tidak mendukung fitur keamanan baru, throughput maksimalnya sudah hampir terus-terusan tertembus, vendor stop support untuk model itu, atau… yang paling sederhana: tim kamu sudah lebih sering mengutuknya daripada memujinya.
A Wall in the Vortex: Choosing and Placing a Firewall in a Hospital Ecosystem
After discussing system replacement, perimeter defense becomes the next question: in an environment where patient data flows rapidly and cyber threats are timeless, choosing and placing a firewall is not just a technical matter, but a wager of trust.
Imagine this hospital as a fortress. There is a large gate (internet connection from the ISP). Inside, there are hallways (local network) leading to vital rooms: the ER (patient servers), the Operating Room (lab and radiology servers), the Pharmacy (pharmacy servers). Now, our task is to install a very strong, layered iron door at that gate. But not just any door. This door must be able to distinguish between an ambulance carrying a critical patient (legit data) and a truck pretending to be an ambulance but filled with robbers (malware). And even trickier, sometimes the 'ambulance' itself unknowingly carries 'robbers' in its trunk (infected data from third-party devices). The firewall is that layered iron door. And choosing it is a long story that starts in a meeting room full of glossy brochures and ends in a cold server room with scattered cables.
There are two major vendors always mentioned: Sophos and Fortinet. Presentations from both are similar. Their slides are full of graphs showing they are "best in class," with logos of shields and swords that look fierce. The Sophos salesperson speaks with a slight British accent, emphasizing "cloud-based management ease." The Fortinet salesperson is more blunt, pointing to "throughput" numbers and "low latency" while their eyes say, "We're for the serious ones." We sit in the middle, with our small team consisting of me and Mas Agus, our seasoned network guy. We're not listening to brochures. We're listening to experiences on obscure tech forums, stories from friends at other hospitals whose firewalls "acted up on a weekend," and most importantly: how their *support* is if there's a problem at 2 AM on a national holiday.
The first inner conflict is philosophical: will we make this firewall the main router or a security device behind the router? The first choice makes it the center of all traffic. All rules, all policies, the life and death of the network are there. It's like making an elite soldier both the gatekeeper and the traffic controller for the entire city. Cool, but the single point of failure risk is high. If that soldier collapses, the whole city is paralyzed. The second choice is more conservative. The old router (which has been stable for years) still handles basic traffic. The firewall is placed behind it, focused on being a strict "vehicle inspector." This divides responsibility. But configuration complexity increases. We have to decide: do we want a jack-of-all-trades tool that becomes the sole reliance, or a layered system that supports each other but is more complicated to manage? This decision isn't in any brochure. It's a bet on technical intuition.
In a hospital ecosystem, a firewall isn't just about blocking viruses. It must understand "medical" language. It must distinguish between normal traffic from an EKG machine to the server and suspicious traffic trying to infiltrate the same server. It must allow remote access for consultant doctors from out of town, but also ensure that access is super secure. And the hardest part: it must not slow down access to radiology images that are 2GB in size. A radiologist waiting too long to load a CT-Scan image can get stressed, and that stress can lead to complaints to the board. So, this firewall must be strong yet agile. Like a ninja who can stop arrows but doesn't block the path of a rushing physician.
The proof of concept phase is the most revealing. When the demo unit is installed, all promises on the slides are tested in the field. We deliberately let suspicious traffic through. We try to access from outside as if we're hackers. We monitor its CPU when the entire hospital is online at 9 AM. This is where we learn that Vendor A might have a prettier interface, but its logs are messy. Vendor B might be less user-friendly, but its alerts are very detailed and fast. The final choice often falls not on the "best," but on the one "we can live with when disaster strikes." Because in the end, this device will become part of our lives. We will be the ones receiving the call when there's an alarm. We will be the ones investigating its logs. We will be the ones blamed if it fails.
Then there's the cost dilemma. An enterprise-class firewall can cost as much as a new entry-level car. But what we're buying isn't the physical box. We're buying a license for threat intelligence updates, for priority technical support, for additional security features. This is a security subscription. And here, management often asks, "If we don't buy the license this year, will we get attacked immediately?" The honest answer: not immediately. But it's like not updating vaccines. The system will keep running, but its defenses get older, blinder to new threats. Explaining this to non-technical people is an art in itself. You have to use the right analogy, without causing panic.
Its physical placement also has a story. Putting it in a crowded, hot server rack? Or in a separate, cooler rack? Which UPS does its power cable connect to? These small decisions, trivial on paper, can be decisive during a power outage or a small fire. This is the invisible, silent work: planning for failure. Assuming that one day, something will go wrong. And when it does, we already have plans B, C, and D.
After everything is installed, configuration finished, license activated, there's a strange silence. The firewall works without a sound. Its LED lights blink steadily. The dashboard on our screen shows green lines. Nothing is happening. And that is precisely the goal. The highest success of a firewall is when it never becomes news. When it silently rejects hundreds of thousands of attack attempts every day without ever disturbing a nurse inputting patient data or a doctor accessing lab results. It is the invisible guardian. Its presence is only felt when it's absent—when an attack successfully breaches and chaos begins.
So, maintaining a firewall is a silent ritual. Checking logs every morning, even if there are no alarms. Monitoring bandwidth usage for strange patterns. Updating rules when there's a new department. This is a long-term relationship with a machine that is the first wall between the sensitive data of thousands of people and an often hostile outside world. And like all relationships, it requires commitment and regular attention.
In the end, behind the hospital's scenes, the decision to choose and place a firewall is the embodiment of the system's silent work—an investment in an invisible wall that determines whether the pulse of information remains safe or turns into disaster.
FAQ: Common Questions Around Firewalls
1. Firewalls are so expensive. Can't we use a free or cheap one?
You could. It's like using a toy plastic lock for your house door. The locking function is there. But would you sleep soundly if inside that house were valuable items and people's life data? Think again.
2. Sophos vs Fortinet, which is better?
Wrong question. The right one is: for our needs and our team's capabilities like this, which one is more *suitable*? It's like asking "dirt bike vs scooter, which is better?". It depends on where you're going to use it and by whom.
3. After installing a firewall, are we 100% safe?
No. A firewall is like a seatbelt. Extremely important, saves lives in an accident. But wearing a seatbelt doesn't mean you can speed recklessly or drive while asleep. Security is a habit, not just a tool.
4. Why is the license expensive and needs to be renewed every year?
Because new threats emerge every day. That license is like a subscription fee to have "spies" all over the world constantly monitoring the latest attack patterns, then sending the "faces of those robbers" to your firewall. Without updates, your firewall only knows the robbers from the old days.
5. What's the first thing to do if the firewall goes down?
Take a breath. Don't panic. Then look at the failure scenario you've prepared (who said you didn't need one?). Usually, there's a bypass or failover mode. If not… well, enjoy the most thrilling hours of your career.
6. Does a firewall slow down the internet?
It can, or it can not. Depends on configuration and specs. A good, properly configured firewall is like an efficient traffic police officer: it actually prevents congestion by managing the flow. A bad or misconfigured one? Well, like a police officer blocking the main road.
7. How do we know when our firewall needs replacing?
Some signs: the latest license doesn't support new security features, its maximum throughput is almost constantly maxed out, the vendor stops support for that model, or… the simplest one: your team curses it more often than praises it.
Thank you for stopping by! If you enjoy the content and would like to show your support, how about treating me to a cup of coffee? �� It’s a small gesture that helps keep me motivated to continue creating awesome content. No pressure, but your coffee would definitely make my day a little brighter. ☕️ Buy Me Coffee

Post a Comment for "Tembok di Tengah Pusaran: Memilih dan Menempatkan Firewall di Ekosistem Rumah Sakit"
Post a Comment
You are welcome to share your ideas with us in comments!