Lab 1: RAW Table Filtering & SYN Flood / DDoS Drop
12 Oktober 2026Buka di NetLab Simulator โ
๐ฏ Sasaran Praktikum
Membuang paket invalid dan DDoS sebelum proses Connection Tracking untuk menghemat CPU.
- Tingkat Kesulitan:
INTERMEDIATE - Estimasi Waktu:
30 Menit - Target RouterOS:
RouterOS v7 (v7.12+ recommended)
๐บ๏ธ Topologi Jaringan
[Attacker / WAN] ---> (ether2) [R1-Edge]
Daftar Perangkat dalam Topologi:
- Attacker-WAN (
internet) - Interfaces:wan1, wan2, wan3, wan4 - R1-Firewall-RAW (
mikrotik) - Interfaces:ether1 (mgmt), ether2, ether3, ether4 - Protected-Server (
pc) - Interfaces:eth1
๐ ๏ธ Langkah Konfigurasi Lengkap (RouterOS v7)
Langkah 1: R1-Edge - Tambahkan rule RAW table untuk drop abnormal TCP flags
# Node: R1-Edge
/ip firewall raw add chain=prerouting protocol=tcp tcp-flags=syn tcp-options=non-syn-only action=drop comment="Drop Abnormal TCP"
/ip firewall raw add chain=prerouting protocol=tcp tcp-flags=!fin,!syn,!rst,!ack action=drop comment="Drop NULL Scan"
/ip firewall raw add chain=prerouting protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg action=drop comment="Drop XMAS Scan"
๐ฅ Panduan Lengkap & Resource
Gunakan panduan lengkap seluruh lab MikroTik certification di Panduan Lengkap Skenario Lab MikroTik atau ikuti kelas resmi tatap muka kami di Daftar Pelatihan MikroTik.
Topologi Jaringan
[Attacker / WAN] ---> (ether2) [R1-Edge]
Download Lab File
Masukkan email untuk mendapatkan file lab (.rsc, topologi, panduan) dan akses materi latihan lainnya.
Dengan mendaftar, Anda setuju menerima email dari Supono Training. Unsubscribe kapan saja.