RIDWAN, RIDWAN (2026) ANALISIS KOMPARATIF NGFW FORTIGATE DAN PALO ALTO TERHADAP SERANGAN DOS DAN FITUR APPLICATION CONTROL-SSL INSPECTION. S1 thesis, Universitas Mercu Buana Jakarta.
|
Text (HAL COVER)
Cover.pdf Download (949kB) | Preview |
|
|
Text (BAB I)
Bab 1.pdf Restricted to Registered users only Download (196kB) |
||
|
Text (BAB II)
Bab 2.pdf Restricted to Registered users only Download (1MB) |
||
|
Text (BAB III)
Bab 3.pdf Restricted to Registered users only Download (969kB) |
||
|
Text (BAB IV)
Bab 4.pdf Restricted to Registered users only Download (525kB) |
||
|
Text (BAB V)
Bab 5.pdf Restricted to Registered users only Download (276kB) |
||
|
Text (DAFTAR PUSTAKA)
Daftar Pustaka.pdf Restricted to Registered users only Download (185kB) |
||
|
Text (LAMPIRAN)
Lampiran.pdf Restricted to Registered users only Download (515kB) |
Abstract
Denial of Service (DoS) attacks remain a primary threat to network service availability, while conventional firewalls are limited to filtering at the network and transport layers. This study compares the performance of two Next-Generation Firewalls (NGFW), FortiGate VM and Palo Alto VM, against TCP Flood and UDP Flood attacks, and verifies the functionality of Application Control and SSL/TLS Inspection. A quantitative approach with a comparative experimental design was applied in a closed virtual laboratory built on PNETLab, with identical vCPU and RAM allocations for both devices. Attacks were generated from Kali Linux using hping3 for 300 seconds per session, while data were captured automatically by a Python script at 10-second intervals across three scenarios: normal traffic, TCP Flood, and UDP Flood. The measured parameters were latency, throughput, active sessions, CPU usage, and memory usage. The results show that FortiGate maintained an average latency of 8.22 ms under TCP Flood and 5.15 ms under UDP Flood, whereas Palo Alto reached 168.39 ms and 73.61 ms. FortiGate's latency degradation against the baseline was 217.4% under TCP Flood, far lower than Palo Alto at 2,380.0%. Conversely, FortiGate's active sessions surged by 7,938.1% to 1,545.73 sessions during UDP Flood, while Palo Alto rose only 216.8% to 9.60 sessions. FortiGate's CPU load increased to 21.40% under UDP Flood, whereas Palo Alto's memory usage remained high, ranging from 87.67% to 91.25% from the baseline onward. Under the TIPHON standard, FortiGate consistently scored index 4 across all scenarios, whereas Palo Alto dropped from index 4 to 3 under TCP Flood. Functional testing confirmed that both devices successfully blocked encrypted threats and applications according to the applied policies. It is concluded that FortiGate excels in latency, while Palo Alto enforces stricter session control, so NGFW selection should be aligned with organizational priorities. Keywords: Application Control, Denial of Service, Next-Generation Firewall, SSL Inspection, TIPHON.
Actions (login required)
![]() |
View Item |
