# 🎓 Buku Panduan Lengkap Skenario Lab Semua Sertifikasi MikroTik (RouterOS v7)

Buku panduan ini memuat seluruh skenario praktikum resmi untuk 7 sertifikasi MikroTik. Seluruh topologi dan script konfigurasi di bawah ini telah disesuaikan dengan sintaks modern **MikroTik RouterOS v7** dan dapat diuji langsung di simulator **NetLab Studio** (`http://localhost:3001`).

---

## 📑 Daftar Isi Sertifikasi & Skenario Lab

1. [MTCNA (Associate)](#1-mtcna---mikrotik-certified-network-associate)
   - [Lab 1: First-Time Setup & Management Hardening](#mtcna-lab-1-first-time-setup--management-hardening)
   - [Lab 2: Static IP Addressing & Default Gateway](#mtcna-lab-2-static-ip-addressing--default-gateway)
   - [Lab 3: DHCP Server & DHCP Client](#mtcna-lab-3-dhcp-server--dhcp-client)
   - [Lab 4: Source NAT (Masquerade) & Port Forwarding (dstnat)](#mtcna-lab-4-source-nat-masquerade--port-forwarding-dstnat)
   - [Lab 5: Firewall Filter Rules (Input & Forward Chain)](#mtcna-lab-5-firewall-filter-rules-input--forward-chain)
   - [Lab 6: Simple Queues Bandwidth Management](#mtcna-lab-6-simple-queues-bandwidth-management)
   - [Lab 7: Bridge Interface & Local Switching](#mtcna-lab-7-bridge-interface--local-switching)
   - [Lab 8: Diagnostic Tools (Ping, Torch, & Netwatch)](#mtcna-lab-8-diagnostic-tools-ping-torch--netwatch)

2. [MTCRE (Routing Engineer)](#2-mtcre---mikrotik-certified-routing-engineer)
   - [Lab 1: Static Route Failover (Check-Gateway & Distance)](#mtcre-lab-1-static-route-failover-check-gateway--distance)
   - [Lab 2: Equal-Cost Multi-Path (ECMP) Load Balancing](#mtcre-lab-2-equal-cost-multi-path-ecmp-load-balancing)
   - [Lab 3: Policy-Based Routing (Routing Mark & Routing Table v7)](#mtcre-lab-3-policy-based-routing-routing-mark--routing-table-v7)
   - [Lab 4: OSPF Single Area (Area 0 Backbone)](#mtcre-lab-4-ospf-single-area-area-0-backbone)
   - [Lab 5: OSPF Multi-Area & Area Border Router (ABR)](#mtcre-lab-5-ospf-multi-area--area-border-router-abr)
   - [Lab 6: OSPF Network Types (PtP vs Broadcast) & Cost Manipulation](#mtcre-lab-6-ospf-network-types-ptp-vs-broadcast--cost-manipulation)
   - [Lab 7: Point-to-Point Tunneling (IPIP & EoIP Tunnel)](#mtcre-lab-7-point-to-point-tunneling-ipip--eoip-tunnel)
   - [Lab 8: VLAN over EoIP Tunnel (Layer 2 Extension)](#mtcre-lab-8-vlan-over-eoip-tunnel-layer-2-extension)

3. [MTCTCE (Traffic Control Engineer)](#3-mtctce---mikrotik-certified-traffic-control-engineer)
   - [Lab 1: RAW Table Filtering & SYN Flood / DDoS Drop](#mtctce-lab-1-raw-table-filtering--syn-flood--ddos-drop)
   - [Lab 2: Advanced Filter with Dynamic Address-Lists](#mtctce-lab-2-advanced-filter-with-dynamic-address-lists)
   - [Lab 3: Mangle Packet & Connection Marking](#mtctce-lab-3-mangle-packet--connection-marking)
   - [Lab 4: Hierarchical Token Bucket (HTB) Queue Tree](#mtctce-lab-4-hierarchical-token-bucket-htb-queue-tree)
   - [Lab 5: Per Connection Queue (PCQ) Equal Bandwidth Sharing](#mtctce-lab-5-per-connection-queue-pcq-equal-bandwidth-sharing)
   - [Lab 6: Web Proxy & Transparent Cache Redirect](#mtctce-lab-6-web-proxy--transparent-cache-redirect)
   - [Lab 7: DNS Cache & Interception / Redirect](#mtctce-lab-7-dns-cache--interception--redirect)

4. [MTCUME (User Management Engineer)](#4-mtcume---mikrotik-certified-user-management-engineer)
   - [Lab 1: PPP Profiles, Secrets, & Local IP Pools](#mtcume-lab-1-ppp-profiles-secrets--local-ip-pools)
   - [Lab 2: PPPoE Server with Rate-Limiting](#mtcume-lab-2-pppoe-server-with-rate-limiting)
   - [Lab 3: PPPoE Client Dial-Out](#mtcume-lab-3-pppoe-client-dial-out)
   - [Lab 4: L2TP / IPsec Site-to-Site Tunneling](#mtcume-lab-4-l2tp--ipsec-site-to-site-tunneling)
   - [Lab 5: SSTP / OpenVPN Remote Access Tunnel](#mtcume-lab-5-sstp--openvpn-remote-access-tunnel)
   - [Lab 6: Hotspot Captive Portal Setup & Walled Garden](#mtcume-lab-6-hotspot-captive-portal-setup--walled-garden)
   - [Lab 7: IPsec Proposal, Policy & NAT-Traversal (NAT-T)](#mtcume-lab-7-ipsec-proposal-policy--nat-traversal-nat-t)

5. [MTCINE (Inter-networking Engineer)](#5-mtcine---mikrotik-certified-inter-networking-engineer)
   - [Lab 1: IGP OSPF Transport for MPLS Infrastructure](#mtcine-lab-1-igp-ospf-transport-for-mpls-infrastructure)
   - [Lab 2: MPLS LDP (Label Distribution Protocol)](#mtcine-lab-2-mpls-ldp-label-distribution-protocol)
   - [Lab 3: VPLS (Virtual Private LAN Service) L2 Tunnel](#mtcine-lab-3-vpls-virtual-private-lan-service-l2-tunnel)
   - [Lab 4: External BGP (eBGP) Inter-AS Peering](#mtcine-lab-4-external-bgp-ebgp-inter-as-peering)
   - [Lab 5: Internal BGP (iBGP) & Route Reflectors (RR)](#mtcine-lab-5-internal-bgp-ibgp--route-reflectors-rr)
   - [Lab 6: BGP Path Attributes (Local Pref & AS-Path Prepend)](#mtcine-lab-6-bgp-path-attributes-local-pref--as-path-prepend)
   - [Lab 7: BGP/MPLS L3VPN with VRF](#mtcine-lab-7-bgpmpls-l3vpn-with-vrf)

6. [MTCSE (Security Engineer)](#6-mtcse---mikrotik-certified-security-engineer)
   - [Lab 1: Router Hardening & Service Security](#mtcse-lab-1-router-hardening--service-security)
   - [Lab 2: Login Brute-Force Defense (Auto-Blacklist)](#mtcse-lab-2-login-brute-force-defense-auto-blacklist)
   - [Lab 3: Dynamic Port Knocking (Multi-Stage Unlock)](#mtcse-lab-3-dynamic-port-knocking-multi-stage-unlock)
   - [Lab 4: Port Scan Detection & PSD Drop Rule](#mtcse-lab-4-port-scan-detection--psd-drop-rule)
   - [Lab 5: DoS / DDoS Rate-Limiting Mitigation](#mtcse-lab-5-dos--ddos-rate-limiting-mitigation)
   - [Lab 6: Certificate Authority (CA) & SSL WebFig/SSH](#mtcse-lab-6-certificate-authority-ca--ssl-webfigssh)

7. [MTCSWE (Switching Engineer)](#7-mtcswe---mikrotik-certified-switching-engineer)
   - [Lab 1: Bridge Setup & Rapid Spanning Tree (RSTP)](#mtcswe-lab-1-bridge-setup--rapid-spanning-tree-rstp)
   - [Lab 2: Bridge VLAN Filtering (vlan-filtering=yes)](#mtcswe-lab-2-bridge-vlan-filtering-vlan-filteringyes)
   - [Lab 3: 802.1Q VLAN Trunk & Access Ports](#mtcswe-lab-3-8021q-vlan-trunk--access-ports)
   - [Lab 4: Hybrid Port Setup (Tagged + PVID Untagged)](#mtcswe-lab-4-hybrid-port-setup-tagged--pvid-untagged)
   - [Lab 5: Inter-VLAN Routing (Router-on-a-Stick)](#mtcswe-lab-5-inter-vlan-routing-router-on-a-stick)
   - [Lab 6: Port Isolation & Private VLANs](#mtcswe-lab-6-port-isolation--private-vlans)
   - [Lab 7: DHCP Snooping on Bridge](#mtcswe-lab-7-dhcp-snooping-on-bridge)
   - [Lab 8: Loop Protection & BPDU Guard](#mtcswe-lab-8-loop-protection--bpdu-guard)

---

## 1. MTCNA - MikroTik Certified Network Associate

### MTCNA Lab 1: First-Time Setup & Management Hardening
**Tujuan**: Mengamankan router baru, mengganti identity, dan menonaktifkan port service yang tidak terenkripsi.
```routeros
# R1-Gateway
/system identity set name="R1-Gateway"
/user set admin password="SuperSecretPassword123!"
/ip service disable telnet,ftp,www,api,api-ssl
/ip service set winbox port=8291
/ip service set ssh port=22
```

### MTCNA Lab 2: Static IP Addressing & Default Gateway
**Tujuan**: Menetapkan alamat IP manual dan default route ke ISP.
```routeros
# R1-Gateway
/ip address add address=192.168.100.2/24 interface=ether2 comment="Uplink-ISP"
/ip address add address=10.10.10.1/24 interface=ether3 comment="LAN-Office"
/ip route add dst-address=0.0.0.0/0 gateway=192.168.100.1 comment="Default-Route-Internet"
/ip dns set servers=8.8.8.8,1.1.1.1 allow-remote-requests=yes
/ping 192.168.100.1 count=4
```

### MTCNA Lab 3: DHCP Server & DHCP Client
**Tujuan**: Mengambil IP otomatis dari ISP dan menyewakan IP ke jaringan lokal.
```routeros
# R1-Gateway
/ip dhcp-client add interface=ether2 disabled=no add-default-route=yes use-peer-dns=yes
/ip pool add name=POOL_LAN ranges=10.10.10.10-10.10.10.100
/ip dhcp-server add name=DHCP_LAN interface=ether3 address-pool=POOL_LAN disabled=no
/ip dhcp-server network add address=10.10.10.0/24 gateway=10.10.10.1 dns-server=10.10.10.1

# PC-Client (Terminal Shell)
udhcpc -i eth1
ip addr show eth1
```

### MTCNA Lab 4: Source NAT (Masquerade) & Port Forwarding (dstnat)
**Tujuan**: Mengizinkan akses internet (srcnat) dan mem-forward port 8080 publik ke web server lokal (dstnat).
```routeros
# R1-Gateway
/ip firewall nat add chain=srcnat out-interface=ether2 action=masquerade comment="Masquerade-Internet"
/ip firewall nat add chain=dstnat in-interface=ether2 protocol=tcp dst-port=8080 action=dst-nat to-addresses=10.10.10.80 to-ports=80 comment="Forward-Web"
/ip firewall nat print
```

### MTCNA Lab 5: Firewall Filter Rules (Input & Forward Chain)
**Tujuan**: Mencegah akses liar dari luar ke router dan mengamankan forwarding traffic LAN.
```routeros
# R1-Gateway
/ip firewall filter add chain=input connection-state=established,related action=accept comment="Accept Established"
/ip firewall filter add chain=input connection-state=invalid action=drop comment="Drop Invalid"
/ip firewall filter add chain=input protocol=icmp action=accept comment="Allow Ping"
/ip firewall filter add chain=input in-interface=ether2 action=drop comment="Drop Other WAN Input"
/ip firewall filter add chain=forward connection-state=established,related action=accept
/ip firewall filter add chain=forward connection-state=invalid action=drop
/ip firewall filter add chain=forward in-interface=ether3 out-interface=ether2 action=accept comment="Allow LAN Out"
```

### MTCNA Lab 6: Simple Queues Bandwidth Management
**Tujuan**: Membagi bandwidth jaringan lokal dengan kuota kecepatan bertingkat.
```routeros
# R1-Gateway
/queue simple add name="VIP-Boss" target=10.10.10.10/32 max-limit=20M/20M priority=1 comment="VIP Prioritas Tinggi"
/queue simple add name="Office-Staff" target=10.10.10.0/24 max-limit=2M/5M burst-limit=4M/10M burst-threshold=1M/3M burst-time=8s/8s priority=8
```

### MTCNA Lab 7: Bridge Interface & Local Switching
**Tujuan**: Menghubungkan beberapa interface fisik menjadi satu segmen Layer 2.
```routeros
# R1-Gateway
/interface bridge add name=bridge-lan
/interface bridge port add bridge=bridge-lan interface=ether3
/interface bridge port add bridge=bridge-lan interface=ether4
/ip address add address=192.168.88.1/24 interface=bridge-lan comment="Gateway Bridge"
```

### MTCNA Lab 8: Diagnostic Tools (Ping, Torch, & Netwatch)
**Tujuan**: Monitoring traffic real-time dan notifikasi otomatis.
```routeros
# R1-Gateway
/tool torch interface=ether2 duration=10s
/tool netwatch add host=8.8.8.8 interval=10s timeout=1s up-script=":log info 'Internet OK'" down-script=":log error 'Internet Mati'"
```

---

## 2. MTCRE - MikroTik Certified Routing Engineer

### MTCRE Lab 1: Static Route Failover (Check-Gateway & Distance)
**Tujuan**: Otomatisasi perpindahan jalur internet primer ke sekunder jika terjadi putus koneksi.
```routeros
# R1-Gateway
/ip route add dst-address=0.0.0.0/0 gateway=192.168.101.1 distance=1 check-gateway=ping comment="Primary-ISP1"
/ip route add dst-address=0.0.0.0/0 gateway=192.168.102.1 distance=2 comment="Backup-ISP2"
```

### MTCRE Lab 2: Equal-Cost Multi-Path (ECMP) Load Balancing
**Tujuan**: Membagi beban koneksi keluar melalui 2 ISP secara seimbang.
```routeros
# R1-Gateway
/ip route add dst-address=0.0.0.0/0 gateway=192.168.1.1,192.168.2.1 check-gateway=ping comment="ECMP-Dual-WAN"
```

### MTCRE Lab 3: Policy-Based Routing (Routing Mark & Routing Table v7)
**Tujuan**: Memisahkan jalur traffic berdasarkan IP sumber menggunakan routing table kustom di RouterOS v7.
```routeros
# R1-Gateway
/routing table add name=to_ISP2 fib
/ip firewall mangle add chain=prerouting src-address=10.10.20.0/24 action=mark-routing new-routing-mark=to_ISP2 passthrough=no comment="Route Finance to ISP2"
/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 routing-table=to_ISP2 comment="Default Route ISP2"
```

### MTCRE Lab 4: OSPF Single Area (Area 0 Backbone)
**Tujuan**: Pertukaran rute otomatis OSPF v7 pada Backbone Area 0.
```routeros
# R1-HQ
/interface bridge add name=lo0
/ip address add address=1.1.1.1/32 interface=lo0
/ip address add address=172.16.12.1/30 interface=ether2
/routing ospf instance add name=ospf-inst router-id=1.1.1.1
/routing ospf area add name=backbone instance=ospf-inst area-id=0.0.0.0
/routing ospf interface-template add area=backbone networks=172.16.12.0/30 type=ptp
/routing ospf interface-template add area=backbone networks=1.1.1.1/32 passive=yes

# R2-Branch
/interface bridge add name=lo0
/ip address add address=2.2.2.2/32 interface=lo0
/ip address add address=172.16.12.2/30 interface=ether2
/routing ospf instance add name=ospf-inst router-id=2.2.2.2
/routing ospf area add name=backbone instance=ospf-inst area-id=0.0.0.0
/routing ospf interface-template add area=backbone networks=172.16.12.0/30 type=ptp
/routing ospf interface-template add area=backbone networks=2.2.2.2/32 passive=yes
/routing ospf neighbor print
```

### MTCRE Lab 5: OSPF Multi-Area & Area Border Router (ABR)
**Tujuan**: Menghubungkan Backbone Area 0 dan Area 1 melalui router ABR.
```routeros
# R2-ABR
/routing ospf area add name=area-1 instance=ospf-inst area-id=0.0.0.1
/routing ospf interface-template add area=area-1 networks=172.16.23.0/30 type=ptp
```

### MTCRE Lab 6: OSPF Network Types (PtP vs Broadcast) & Cost Manipulation
**Tujuan**: Mempercepat konvergensi tanpa pemilihan DR/BDR dan menentukan rute prioritas via cost.
```routeros
# R1-HQ
/routing ospf interface-template set [find networks="172.16.12.0/30"] cost=10 type=ptp
/routing ospf interface-template set [find networks="172.16.14.0/30"] cost=100 type=ptp
```

### MTCRE Lab 7: Point-to-Point Tunneling (IPIP & EoIP Tunnel)
**Tujuan**: Menghubungkan dua kantor cabang secara transparan melintasi WAN.
```routeros
# R1-HQ
/interface eoip add name=eoip-to-branch remote-address=203.0.113.2 tunnel-id=10 disabled=no
/ip address add address=10.99.99.1/30 interface=eoip-to-branch

# R2-Branch
/interface eoip add name=eoip-to-hq remote-address=203.0.113.1 tunnel-id=10 disabled=no
/ip address add address=10.99.99.2/30 interface=eoip-to-hq
/ping 10.99.99.1 count=4
```

### MTCRE Lab 8: VLAN over EoIP Tunnel (Layer 2 Extension)
**Tujuan**: Meneruskan beberapa VLAN ID melintasi tunnel EoIP ke kantor pusat.
```routeros
# R1-HQ
/interface bridge add name=bridge-vlan
/interface bridge port add bridge=bridge-vlan interface=ether3
/interface bridge port add bridge=bridge-vlan interface=eoip-to-branch
```

---

## 3. MTCTCE - MikroTik Certified Traffic Control Engineer

### MTCTCE Lab 1: RAW Table Filtering & SYN Flood / DDoS Drop
**Tujuan**: Drop serangan DDoS sebelum Connection Tracking untuk menjaga efisiensi prosesor.
```routeros
# R1-Shaper
/ip firewall raw add chain=prerouting protocol=tcp tcp-flags=syn tcp-options=non-syn-only action=drop comment="Drop Abnormal TCP"
/ip firewall raw add chain=prerouting protocol=tcp tcp-flags=!fin,!syn,!rst,!ack action=drop comment="Drop NULL Scan"
/ip firewall raw add chain=prerouting protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg action=drop comment="Drop XMAS Scan"
```

### MTCTCE Lab 2: Advanced Filter with Dynamic Address-Lists
**Tujuan**: Memasukkan IP penyerang port scan ke daftar blokir dinamis.
```routeros
# R1-Shaper
/ip firewall filter add chain=input protocol=tcp psd=21,3s,3,1 action=add-src-to-address-list address-list=port_scanners address-list-timeout=1d comment="Detect Port Scanner"
/ip firewall filter add chain=input src-address-list=port_scanners action=drop comment="Drop Scanners"
```

### MTCTCE Lab 3: Mangle Packet & Connection Marking
**Tujuan**: Memisahkan jenis traffic untuk diproses oleh antrian QoS.
```routeros
# R1-Shaper
/ip firewall mangle add chain=prerouting protocol=udp dst-port=53 action=mark-connection new-connection-mark=dns_conn passthrough=yes
/ip firewall mangle add chain=prerouting connection-mark=dns_conn action=mark-packet new-packet-mark=dns_pkt passthrough=no
/ip firewall mangle add chain=prerouting in-interface=ether3 action=mark-packet new-packet-mark=general_pkt passthrough=no
```

### MTCTCE Lab 4: Hierarchical Token Bucket (HTB) Queue Tree
**Tujuan**: Membangun pohon antrian hierarkis dengan prioritas bandwidth (limit-at & max-limit).
```routeros
# R1-Shaper
/queue tree add name="ROOT_DOWN" parent=ether3 max-limit=20M
/queue tree add name="PRIO1_DNS" parent=ROOT_DOWN packet-mark=dns_pkt priority=1 limit-at=2M max-limit=5M
/queue tree add name="PRIO8_GENERAL" parent=ROOT_DOWN packet-mark=general_pkt priority=8 limit-at=10M max-limit=20M
/queue tree print
```

### MTCTCE Lab 5: Per Connection Queue (PCQ) Equal Bandwidth Sharing
**Tujuan**: Membagi bandwidth sisa secara otomatis dan adil antar pengguna aktif.
```routeros
# R1-Shaper
/queue type add name="pcq_download_dyn" kind=pcq pcq-rate=0 pcq-classifier=dst-address
/queue type add name="pcq_upload_dyn" kind=pcq pcq-rate=0 pcq-classifier=src-address
/queue tree set [find name="PRIO8_GENERAL"] queue=pcq_download_dyn
```

### MTCTCE Lab 6: Web Proxy & Transparent Cache Redirect
**Tujuan**: Mengaktifkan web proxy lokal dan me-redirect traffic HTTP port 80.
```routeros
# R1-Shaper
/ip proxy set enabled=yes port=8080 cache-on-disk=no
/ip firewall nat add chain=dstnat protocol=tcp dst-port=80 in-interface=ether3 action=redirect to-ports=8080 comment="Redirect to WebProxy"
```

### MTCTCE Lab 7: DNS Cache & Interception / Redirect
**Tujuan**: Memaksa seluruh query DNS client menggunakan server DNS lokal router.
```routeros
# R1-Shaper
/ip dns set allow-remote-requests=yes servers=8.8.8.8,1.1.1.1
/ip firewall nat add chain=dstnat protocol=udp dst-port=53 in-interface=ether3 action=redirect to-ports=53 comment="Force DNS"
/ip firewall nat add chain=dstnat protocol=tcp dst-port=53 in-interface=ether3 action=redirect to-ports=53
```

---

## 4. MTCUME - MikroTik Certified User Management Engineer

### MTCUME Lab 1: PPP Profiles, Secrets, & Local IP Pools
**Tujuan**: Menyiapkan template profil PPP dengan pool IP lokal dan DNS.
```routeros
# R1-BRAS
/ip pool add name=pool-vpn ranges=172.16.99.10-172.16.99.50
/ppp profile add name=profile-remote local-address=172.16.99.1 remote-address=pool-vpn dns-server=8.8.8.8
/ppp secret add name=user1 password=pass123 profile=profile-remote service=any
```

### MTCUME Lab 2: PPPoE Server with Rate-Limiting
**Tujuan**: Menjalankan PPPoE Server untuk ISP broadband dengan limit kecepatan per akun.
```routeros
# R1-BRAS
/ip pool add name=pool-pppoe ranges=10.200.1.2-10.200.1.254
/ppp profile add name=paket-10mbps local-address=10.200.1.1 remote-address=pool-pppoe rate-limit=5M/10M dns-server=8.8.8.8
/ppp secret add name=customer1 password=clientpass profile=paket-10mbps service=pppoe
/interface pppoe-server server add service-name=ISP-Fiber interface=ether2 default-profile=paket-10mbps disabled=no
```

### MTCUME Lab 3: PPPoE Client Dial-Out
**Tujuan**: Menghubungkan router cabang/client ke ISP PPPoE Server.
```routeros
# R2-Client
/interface pppoe-client add name=pppoe-out1 interface=ether2 user=customer1 password=clientpass add-default-route=yes disabled=no
/interface pppoe-client monitor pppoe-out1 once
```

### MTCUME Lab 4: L2TP / IPsec Site-to-Site Tunneling
**Tujuan**: VPN L2TP terenkripsi IPsec dengan pre-shared key antar kantor.
```routeros
# R1-VPN-Server
/interface l2tp-server server set enabled=yes use-ipsec=yes ipsec-secret="VpnRahasia123!" default-profile=profile-remote

# R2-VPN-Client
/interface l2tp-client add name=l2tp-hq connect-to=203.0.113.1 user=user1 password=pass123 use-ipsec=yes ipsec-secret="VpnRahasia123!" disabled=no
```

### MTCUME Lab 5: SSTP / OpenVPN Remote Access Tunnel
**Tujuan**: VPN berbasis TCP 443 (SSTP) untuk menembus firewall NAT ketat.
```routeros
# R1-BRAS
/interface sstp-server server set enabled=yes port=443 default-profile=profile-remote authentication=mschap2
```

### MTCUME Lab 6: Hotspot Captive Portal Setup & Walled Garden
**Tujuan**: Menjalankan captive portal dengan Walled Garden bebas akses.
```routeros
# R1-BRAS
/ip hotspot profile add name=hsprof1 hotspot-address=10.10.10.1 dns-name="login.lab.id" html-directory=hotspot
/ip hotspot add name=hs-office interface=ether3 address-pool=POOL_LAN profile=hsprof1 disabled=no
/ip hotspot user profile add name=prof-tamu shared-users=1 rate-limit=2M/2M
/ip hotspot user add name=guest1 password=guestpass profile=prof-tamu
/ip hotspot walled-garden add dst-host="mikrotik.com" action=allow comment="Free Access"
```

### MTCUME Lab 7: IPsec Proposal, Policy & NAT-Traversal (NAT-T)
**Tujuan**: Membangun tunnel IPsec murni Site-to-Site dengan proposal enkripsi AES.
```routeros
# R1-HQ
/ip ipsec proposal set [find default=yes] enc-algorithms=aes-256-cbc,aes-128-cbc auth-algorithms=sha256
/ip ipsec profile add name=prof_ipsec enc-algorithm=aes-256 dh-group=modp2048
/ip ipsec peer add name=peer_branch address=203.0.113.2 profile=prof_ipsec
/ip ipsec identity add peer=peer_branch secret="IPsecKunciRahas1a"
```

---

## 5. MTCINE - MikroTik Certified Inter-networking Engineer

### MTCINE Lab 1: IGP OSPF Transport for MPLS Infrastructure
**Tujuan**: Menyiapkan dasar routing IGP agar sesi MPLS LDP dapat terbentuk.
```routeros
# R1-PE1
/interface bridge add name=lo0
/ip address add address=10.255.0.1/32 interface=lo0
/ip address add address=10.0.12.1/30 interface=ether2
/routing ospf instance add name=ospf-core router-id=10.255.0.1
/routing ospf area add name=backbone instance=ospf-core area-id=0.0.0.0
/routing ospf interface-template add area=backbone networks=10.0.12.0/30 type=ptp
/routing ospf interface-template add area=backbone networks=10.255.0.1/32 passive=yes
```

### MTCINE Lab 2: MPLS LDP (Label Distribution Protocol)
**Tujuan**: Mengaktifkan MPLS LDP untuk pertukaran label switching antar router core.
```routeros
# R1-PE1
/mpls set enabled=yes
/mpls ldp set enabled=yes ldp-address=10.255.0.1
/mpls ldp interface add interface=ether2
/mpls forwarding-table print
```

### MTCINE Lab 3: VPLS (Virtual Private LAN Service) L2 Tunnel
**Tujuan**: Membangun terowongan Layer 2 transparan melintasi cloud MPLS.
```routeros
# R1-PE1
/interface vpls add name=vpls-pe2 remote-peer=10.255.0.3 vpls-id=100 disabled=no
/interface bridge add name=bridge-cust
/interface bridge port add bridge=bridge-cust interface=ether3
/interface bridge port add bridge=bridge-cust interface=vpls-pe2
```

### MTCINE Lab 4: External BGP (eBGP) Inter-AS Peering
**Tujuan**: Pertukaran rute antar Autonomous System (AS 65001 dan AS 65002) di RouterOS v7.
```routeros
# R3-PE2 (AS 65001)
/routing bgp template add name=bgp-isp as=65001 router-id=10.255.0.3
/routing bgp connection add name=peer-cust remote.address=192.0.2.2 .as=65002 local.address=192.0.2.1 templates=bgp-isp disabled=no
/routing bgp session print

# R4-Customer (AS 65002)
/routing bgp template add name=bgp-cust as=65002 router-id=192.0.2.2
/routing bgp connection add name=peer-isp remote.address=192.0.2.1 .as=65001 local.address=192.0.2.2 templates=bgp-cust disabled=no
```

### MTCINE Lab 5: Internal BGP (iBGP) & Route Reflectors (RR)
**Tujuan**: Distribusi rute iBGP tanpa memerlukan full-mesh topology.
```routeros
# R2-P-Core (Route Reflector)
/routing bgp template add name=bgp-rr as=65001 router-id=10.255.0.2 route-reflect=yes
/routing bgp connection add name=rr-to-pe1 remote.address=10.255.0.1 .as=65001 templates=bgp-rr disabled=no
/routing bgp connection add name=rr-to-pe2 remote.address=10.255.0.3 .as=65001 templates=bgp-rr disabled=no
```

### MTCINE Lab 6: BGP Path Attributes (Local Pref & AS-Path Prepend)
**Tujuan**: Rekayasa traffic keluar dengan Local Preference dan traffic masuk dengan AS-Path Prepending.
```routeros
# R3-PE2
/routing filter rule add chain=bgp-out rule="if (dst == 10.255.0.0/16) { set bgp-path-prepend 3; accept; }"
/routing bgp connection set [find name=peer-cust] output.filter-chain=bgp-out
```

### MTCINE Lab 7: BGP/MPLS L3VPN with VRF
**Tujuan**: Menyediakan virtual router terisolasi per customer melintasi jaringan MPLS.
```routeros
# R1-PE1
/ip vrf add name=VRF_KLIEN_A interfaces=ether3 route-distinguisher=65001:100 export-route-targets=65001:100 import-route-targets=65001:100
/ip address add address=192.168.10.1/24 interface=ether3
```

---

## 6. MTCSE - MikroTik Certified Security Engineer

### MTCSE Lab 1: Router Hardening & Service Security
**Tujuan**: Mengamankan router dengan membatasi subnet pengakses port sensitif.
```routeros
# R1-Hardened
/ip service disable telnet,ftp,www,api,api-ssl
/ip service set winbox address=192.168.10.0/24 port=8291
/ip service set ssh address=192.168.10.0/24 port=2222
```

### MTCSE Lab 2: Login Brute-Force Defense (Auto-Blacklist)
**Tujuan**: Auto-blacklist IP yang mencoba login berulang kali.
```routeros
# R1-Hardened
/ip firewall filter add chain=input protocol=tcp dst-port=2222 connection-state=new src-address-list=ssh_stg2 action=add-src-to-address-list address-list=ssh_blacklist address-list-timeout=1d comment="Blacklist 24h"
/ip firewall filter add chain=input protocol=tcp dst-port=2222 connection-state=new src-address-list=ssh_stg1 action=add-src-to-address-list address-list=ssh_stg2 address-list-timeout=1m
/ip firewall filter add chain=input protocol=tcp dst-port=2222 connection-state=new action=add-src-to-address-list address-list=ssh_stg1 address-list-timeout=1m
/ip firewall filter add chain=input src-address-list=ssh_blacklist action=drop comment="Drop Attacker"
```

### MTCSE Lab 3: Dynamic Port Knocking (Multi-Stage Unlock)
**Tujuan**: Menyembunyikan port Winbox dan hanya membukanya setelah urutan knocking yang benar.
```routeros
# R1-Hardened
/ip firewall filter add chain=input protocol=tcp dst-port=7000 in-interface=ether2 action=add-src-to-address-list address-list=Knock_Stage1 address-list-timeout=15s
/ip firewall filter add chain=input protocol=tcp dst-port=8000 src-address-list=Knock_Stage1 in-interface=ether2 action=add-src-to-address-list address-list=Knock_Authorized address-list-timeout=1h
/ip firewall filter add chain=input protocol=tcp dst-port=8291 src-address-list=Knock_Authorized action=accept comment="Accept Winbox"
/ip firewall filter add chain=input in-interface=ether2 action=drop comment="Drop Ingress Lain"
```

### MTCSE Lab 4: Port Scan Detection & PSD Drop Rule
**Tujuan**: Deteksi Nmap port scan dan blokir penyerang.
```routeros
# R1-Hardened
/ip firewall filter add chain=input protocol=tcp psd=21,3s,3,1 action=add-src-to-address-list address-list=port_scanners address-list-timeout=1d comment="Detect Nmap"
/ip firewall filter add chain=input src-address-list=port_scanners action=drop
```

### MTCSE Lab 5: DoS / DDoS Rate-Limiting Mitigation
**Tujuan**: Batasi ICMP ping flood dan koneksi simultan berlebih.
```routeros
# R1-Hardened
/ip firewall filter add chain=input protocol=icmp limit=5,10:packet action=accept comment="Limit Ping"
/ip firewall filter add chain=input protocol=icmp action=drop comment="Drop Ping Flood"
/ip firewall filter add chain=forward protocol=tcp connection-state=new connection-limit=100,32 action=drop comment="Limit 100 Conn/IP"
```

### MTCSE Lab 6: Certificate Authority (CA) & SSL WebFig/SSH
**Tujuan**: Menerapkan HTTPS terenkripsi TLS dengan sertifikat lokal.
```routeros
# R1-Hardened
/certificate add name=ca-root common-name="NetLab-Root-CA" key-usage=key-cert-sign,crl-sign
/certificate sign ca-root
/certificate add name=cert-web common-name="router.lab.local"
/certificate sign cert-web ca=ca-root
/ip service set www-ssl certificate=cert-web disabled=no port=443
```

---

## 7. MTCSWE - MikroTik Certified Switching Engineer

### MTCSWE Lab 1: Bridge Setup & Rapid Spanning Tree (RSTP)
**Tujuan**: Mencegah broadcast storm pada jalur switch redundan.
```routeros
# SW1-CRS
/interface bridge add name=bridge1 protocol-mode=rstp priority=0x8000
/interface bridge port add bridge=bridge1 interface=ether2
/interface bridge port add bridge=bridge1 interface=ether3
/interface bridge monitor bridge1 once
```

### MTCSWE Lab 2: Bridge VLAN Filtering (vlan-filtering=yes)
**Tujuan**: Mengaktifkan proses VLAN Filtering standar hardware CRS/RouterOS v7.
```routeros
# SW1-CRS
/interface bridge add name=bridge1 vlan-filtering=no
/interface bridge set bridge1 vlan-filtering=yes
```

### MTCSWE Lab 3: 802.1Q VLAN Trunk & Access Ports
**Tujuan**: Port ether2 sebagai Trunk (Tagged) dan ether4 sebagai Access VLAN 10 (Untagged).
```routeros
# SW1-CRS
/interface bridge port add bridge=bridge1 interface=ether2 comment="Trunk-Port"
/interface bridge port add bridge=bridge1 interface=ether4 pvid=10 comment="Access-VLAN10"
/interface bridge vlan add bridge=bridge1 vlan-ids=10 tagged=ether2,bridge1 untagged=ether4
/interface bridge vlan add bridge=bridge1 vlan-ids=20 tagged=ether2,bridge1
```

### MTCSWE Lab 4: Hybrid Port Setup (Tagged + PVID Untagged)
**Tujuan**: Meneruskan VLAN 10 tanpa tag dan VLAN 20 dengan tag pada satu kabel yang sama (IP Phone).
```routeros
# SW1-CRS
/interface bridge port add bridge=bridge1 interface=ether5 pvid=10 comment="Hybrid Port"
/interface bridge vlan set [find vlan-ids=10] untagged=ether4,ether5
/interface bridge vlan set [find vlan-ids=20] tagged=ether2,ether5
```

### MTCSWE Lab 5: Inter-VLAN Routing (Router-on-a-Stick)
**Tujuan**: Routing antar VLAN melalui sub-interface pada port trunk router.
```routeros
# R1-Router
/interface vlan add name=vlan10-staff vlan-id=10 interface=ether2
/interface vlan add name=vlan20-guest vlan-id=20 interface=ether2
/ip address add address=10.10.10.1/24 interface=vlan10-staff
/ip address add address=10.20.20.1/24 interface=vlan20-guest
```

### MTCSWE Lab 6: Port Isolation & Private VLANs
**Tujuan**: Memisahkan client dalam VLAN yang sama agar tidak bisa saling berkomunikasi (menggunakan horizon).
```routeros
# SW1-CRS
/interface bridge port set [find interface=ether4] horizon=1
/interface bridge port set [find interface=ether5] horizon=1
```

### MTCSWE Lab 7: DHCP Snooping on Bridge
**Tujuan**: Menangkal Rogue DHCP Server dengan mendefinisikan trusted port.
```routeros
# SW1-CRS
/interface bridge set bridge1 dhcp-snooping=yes
/interface bridge port set [find interface=ether2] trusted=yes comment="Uplink Router Asli"
/interface bridge port set [find interface=ether4] trusted=no comment="Client Untrusted"
```

### MTCSWE Lab 8: Loop Protection & BPDU Guard
**Tujuan**: Auto-shutdown port jika mendeteksi BPDU frame ilegal atau loop fisik.
```routeros
# SW1-CRS
/interface bridge port set [find interface=ether4] bpdu-guard=yes edge=yes
/interface ethernet set [find name=ether4] loop-protect=on
```
