+ All Categories
Home > Documents > GLC Networks, Indonesia [email protected] ... - … › presentations › UK16 › ...Firewall...

GLC Networks, Indonesia [email protected] ... - … › presentations › UK16 › ...Firewall...

Date post: 05-Jul-2020
Category:
Upload: others
View: 2 times
Download: 0 times
Share this document with a friend
26
www.glcnetworks.com Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah [email protected] GLC Networks, Indonesia
Transcript
Page 1: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

Firewall RAW tableMikrotik User Meeting London, November 14, 2016

Achmad [email protected] Networks, Indonesia

Page 2: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

Agenda

● Introduction● Firewall● Raw table● Demo● Q & A

2

Page 3: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

What is GLC?

● Garda Lintas Cakrawala (www.glcnetworks.com)● Based in Bandung, Indonesia● Areas: Training, IT Consulting● Mikrotik Certified Training Partner● Mikrotik Certified Consultant● Mikrotik distributor

3

Page 4: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

Trainer Introduction

● Name: Achmad Mardiansyah● Base: bandung, Indonesia● Linux user since ’99● Certified Trainer (MTCNA/RE/WE/UME/INE/TCE)● Mikrotik Certified Consultant● Work: Telco engineer, Sysadmin, PHP programmer,

and Lecturer at Telkom University● Personal website: http://achmad.glcnetworks.com● More info:

http://au.linkedin.com/in/achmadmardiansyah

4

Page 5: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

Where is Indonesia?

5

Page 6: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

About Telkom University

● Located in Bandung, Indonesia● 7 Faculties, 27 schools● Areas: Engineering, Communications, Computing, Bussiness and

management, Arts● 650+ Academic staff, 400+ Administration staff, 20000+ students● An exchange program● Runs mikrotik academy program

6

Page 7: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

Mikrotik academy @ TEL-U

● Started in 2013● Embedded into schools curricula● 100% hands-on● Get MTCNA certification

7

Page 8: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

Mikrotik in Indonesia

● Very popular product for networking● Early adoption (beginning of 2000)● Many schools already join Mikrotik

Academy programs● Lots of training classes● Biggest MUM in the world (2500+

participants, 2-day event)● Very active community (facebook, telegram,

forum, etc)● What..? you dont know Mikrotik? Where

have you been?

8

Page 9: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

Firewall

9

Page 10: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

What is Mikrotik firewall?

● Is a feature to○ Control network access (filter)○ Modify network header (NAT)○ Marking packet for further processing (mangle)

● Developed from linux● Consist of 2 parts: matcher & action● Executed sequentially● Netadmin must understand the application’s characteristics in order to build a

matcher (e.g. browsing -> using TCP port 80)

10

Page 11: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

How firewall works?● Setup matcher -> then action● Mikrotik has lots of options for matcher

-> very flexible● Matcher + Action = Firewall rule● Rule is executed sequentially

11

Page 12: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com 12

Where the packet is processed?A: see packet flowNote: ipsec is removed in this diagram

Page 13: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com 1313

What's the difference between forward and input?

FORWARD

INPUT

Page 14: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com 14

On which chain can you apply filter?

Page 15: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com 15

On which chain can you apply NAT?

Page 16: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com 16

On which chain can you apply mangle?

Page 17: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com 17

Which processes could take more CPU power?

Page 18: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com 18

Common place to block DDOS attack? We use filter table (still eating CPU power)

Page 19: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

Raw table

19

Page 20: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

Raw table

● allows to selectively bypass or drop packets before connection tracking● does not have matchers that depend on connection tracking (like

connection-state, layer7 etc.)● If packet is marked to bypass connection tracking, packet de-fragmentation

will not occur

20

Page 21: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com 21

Packet flow for raw table

Page 22: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

Raw table matchers and action● No paramaters related to connection

tracking (l7-filter, conn-mark, bytes, etc)

22

Page 23: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

demo

23

Page 24: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

Combined with connection-limit and address list

24

Page 25: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

QA

25

Page 26: GLC Networks, Indonesia achmad@glcnetworks.com ... - … › presentations › UK16 › ...Firewall RAW table Mikrotik User Meeting London, November 14, 2016 Achmad Mardiansyah achmad@glcnetworks.com

www.glcnetworks.com

End of slides

● Thank you for your attention ● Please submit your feedback: http://bit.ly/glcfeedback● Like our facebook page: “GLC networks”● Stay tune with our schedule

26


Recommended