SUPONO.
โ† Modul LabmtctceMenengah30 Menit

Lab 1: RAW Table Filtering & SYN Flood / DDoS Drop

๐ŸŽฏ Sasaran Praktikum

Membuang paket invalid dan DDoS sebelum proses Connection Tracking untuk menghemat CPU.

  • Tingkat Kesulitan: INTERMEDIATE
  • Estimasi Waktu: 30 Menit
  • Target RouterOS: RouterOS v7 (v7.12+ recommended)

๐Ÿ—บ๏ธ Topologi Jaringan

[Attacker / WAN] ---> (ether2) [R1-Edge]

Daftar Perangkat dalam Topologi:

  • Attacker-WAN (internet) - Interfaces: wan1, wan2, wan3, wan4
  • R1-Firewall-RAW (mikrotik) - Interfaces: ether1 (mgmt), ether2, ether3, ether4
  • Protected-Server (pc) - Interfaces: eth1

๐Ÿ› ๏ธ Langkah Konfigurasi Lengkap (RouterOS v7)

Langkah 1: R1-Edge - Tambahkan rule RAW table untuk drop abnormal TCP flags

# Node: R1-Edge
/ip firewall raw add chain=prerouting protocol=tcp tcp-flags=syn tcp-options=non-syn-only action=drop comment="Drop Abnormal TCP"
/ip firewall raw add chain=prerouting protocol=tcp tcp-flags=!fin,!syn,!rst,!ack action=drop comment="Drop NULL Scan"
/ip firewall raw add chain=prerouting protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg action=drop comment="Drop XMAS Scan"

๐Ÿ“ฅ Panduan Lengkap & Resource

Gunakan panduan lengkap seluruh lab MikroTik certification di Panduan Lengkap Skenario Lab MikroTik atau ikuti kelas resmi tatap muka kami di Daftar Pelatihan MikroTik.

Topologi Jaringan

[Attacker / WAN] ---> (ether2) [R1-Edge]

Download Lab File

Masukkan email untuk mendapatkan file lab (.rsc, topologi, panduan) dan akses materi latihan lainnya.

Dengan mendaftar, Anda setuju menerima email dari Supono Training. Unsubscribe kapan saja.