Smart City Infrastructure, Edge Computing & IoT Cybersecurity
Simulasi 240 Menit (Expert/Specialist) - 34 Devices Hybrid Ring, PVLAN & Mitigation
Nilai Praktikum
0 / 100
Topologi Master Smart City (Klik Node untuk Konfigurasi)
Reset Topologi
Central Cloud DC
10.100.0.1
!
Core Edge ASA Firewall
FW: Default
!
Core Router - North
Ring: Disabled
!
Core Router - South
Ring: Disabled
!
Dist SW 1 / Edge Server 1
VLAN 100 (CCTV)
!
Dist SW 2 / Edge Server 2
VLAN 200 (Traffic)
!
Dist SW 3 / IoT GW 1
PVLAN 300 (Lighting)
!
Dist SW 4 / IoT GW 2
VLAN 400 (Mgmt)
!
CCTV Kota (4 Node)
Logic: Off
!
Sensor Trafik (4 Node)
Logic: Off
!
Smart Light (PVLAN)
Isolated Port
!
Smart Park & Workstation
Defense: Off
Rubrik Evaluasi Skenario (240 Menit)
Modul 1: Metro Ethernet Ring & OSPF/REP
20 Poin
Aktifkan Ring Backbone REP / OSPF Area 0 Fast-Hellos & alokasikan IP VLSM /30 per link & /28 manajemen edge.
Modul 2: IoT Logic & Edge Server Automation
20 Poin
Registrasi IoT ke Edge Server. Pasang Conditional Rules (Motion detect -> Smart Light 100% & CCTV HD Record; Env alert).
Modul 3: VLAN & Private VLAN Isolation
20 Poin
Segmentasi VLAN 100/200/300/400. Menerapkan Private VLAN (PVLAN) Isolated Ports antar-sensor penerangan publik.
Modul 4: Encrypted IPsec GRE & ASA Firewall
20 Poin
Bangun IPsec GRE Tunnel ke Cloud. Filter ASA Firewall (Izinkan MQTT 1883/HTTPS 443, Blokir SSH/Telnet dari subnet IoT).
Modul 5: Cyber Mitigation & Redundant Failover
20 Poin
Mitigasi Botnet DDoS (Storm Control/ACL < 5 menit) dan lulus pengujian kabel Core North terputus (> 99% uptime).
Terminal Monitoring & Log Serangan
edge-soc-console -- syslog
Simulasi Botnet DDoS
Putus Kabel Core North
Audit Integrity & Telemetri System
Konfigurasi Edge ASA Firewall & Tunnel
×
Konfigurasi Enkripsi VPN GRE IPsec menuju Central Cloud serta Stateful Inspection untuk menyaring port IoT.
IPsec GRE Encrypted Tunnel
Disabled (Unencrypted Traffic)
Enabled (IPsec GRE Active)
ASA Stateful Inspection Rules
Permit All Traffic (Unsecured)
Allow MQTT (1883) & HTTPS (443), Block SSH/Telnet
Core Ring Backbone Configuration
×
Aktifkan protokol Ring (REP/OSPF Area 0 dengan Fast-Hellos) untuk pemulihan ultra-fast < 50ms.
Protokol Routing Backbone
Static Routing (No Redundancy)
OSPF Area 0 (Fast-Hellos / REP Ring Active)
Skema Subnetting VLSM
Default Classful /24
/30 Inter-router Links & /28 Edge Mgmt
Distribution SW & Edge Server
×
Pengaturan segmentasi VLAN dan isolasi Private VLAN (PVLAN) pada perangkat edge.
Segmentasi VLAN Tagging
VLAN 1 Default (Tidak Tersegmentasi)
VLAN 100/200/300/400 Multi-VLAN Configured
Private VLAN (PVLAN) Mode (Smart Lighting)
Disabled (Sensor dapat saling komunikasi/ping)
PVLAN Isolated Ports (Isolasi total antar-sensor)
IoT Nodes & Cyber Defense Tuning
×
Konfigurasi Conditional Logic Otomatisasi IoT serta Keamanan Port (Storm Control / Rate Limiting).
Condition Rules (Automation Logic)
Disabled (Manual Action Only)
Active (Motion -> Light 100% & CCTV HD Rec; Env Alert)
Access Port Defense (Storm Control & Rate Limiting)
Disabled (Rentan DDoS / Traffic Flood)
Enabled (Rate-Limiting & ACL Blocking Active)