
Set up a virtual lab for a two-site network using a GNS3 VM and server, with Linux node templates, Cumulus VX, pfSense, VBox integration, and VLAN segments.
Explore bus, ring, star, mesh, and hybrid topologies and how they connect nodes via backbone and switches, highlighting single points of failure and redundancy.
Explore network types by defining LAN, WLAN, WAN, SAN, MPLS, and SD-WAN, and explain their geographic scope, wired versus wireless connectivity, and private, secure networks.
Explore the OSI network model’s seven layers, encapsulation, and how data becomes segments, packets, and frames as it travels with TCP/UDP, IP addresses, and MAC addresses.
Learn how connection oriented TCP and connectionless UDP differ, explain the three-way handshake and TCP session, and review IP protocols and ports like 22, 53, 80, 443, ICMP, and DNS.
Chunk your ip block into subnets to host different devices across layer three networks, such as clients, servers, printers, dmz, vlan, and management, using subnet masks and a calculator.
Explore how routing uses binary operations with subnet masks to identify networks and how static and dynamic routing, default routes, and routing metrics determine the path of packets.
Learn how VLAN segmentation enhances performance and security, including port-based and protocol-based VLAN setups, access and trunk modes, STP, BPDU, and LAG and MLAG configurations.
Compare three-tier and two-tier (spine-leaf) network architectures, and build secure open-source networks with cores, aggregations, access layers, VLANs, NAC, and VPNs.
Trace the 50-year unix-like heritage from research UNIX to BSD, Darwin, Linux, and macOS, and explore how FreeBSD and other BSD families and Linux shape today's devices and open-source projects.
Explore 50 must-know unix-like commands from the seventies, still used on Linux, macOS, and FreeBSD, including cat, cd, chmod, chown, cp, date, df, du, cmp, and wildcards.
Explore must-know Unix commands, including find, ls, mkdir, mount, rm, sort, and stat, with practical examples. Learn about inodes, hard links, and soft links for efficient file management.
Learn essential Unix-like shell commands from the seventies, covering user switching, file and process management, scripting basics, and cron scheduling for secure network workflows.
Learn fifty essential unix-like shell commands for scripting and administration, including tar for archives, touch, tail, grep, sed, and awk for text processing and data extraction.
Vi basics on any Unix-like OS by switching between command and insert modes, editing and saving files, and navigating, searching, and replacing text efficiently.
Compare net-tools and iproute2 on Unix-like systems, showing how modern Linux favors ip commands over ifconfig, ip addr, and ip route, while net-tools remain optional and deprecated.
Explore Wireshark, a cross-platform network analyzer, with live capture, offline analysis, three-pane packet browser, and powerful display filters, plus open-source resources.
Learn how wireshark, tshark, termshark, and tcpdump capture and analyze network packets using simple filters. Explore installation and practical use-case scenarios on linux.
Explore why packet analysis matters by showing an ethical hacking use case with Wireshark and TCP dump to monitor ICMP traffic during a Docker-based attack.
Install Wireshark, Termshark, tshark and tcpdump on Kali Linux using apt update and apt install. For other distributions, run a quick search and test the installations with tshark and tcpdump.
Install Wireshark and TShark on Windows using the 64-bit installer, with default components and Npcap, to capture, filter, and analyze packets on Ethernet interfaces.
Explore tcpdump use-cases for capturing credentials, cookies, http headers and urls, with remote packet capture to a local Wireshark session for analysis.
Explore Wireshark’s packet analysis and filters. Decode HTTP, TCP, and IP traffic, inspect credentials, and follow TCP streams.
Apply and combine Wireshark filters to analyze PCAPs, reconstruct HTTP pages, and extract clues from Telnet, FTP, TFTP, and DNS traffic for hands-on practice.
Discover how Wireshark reconciles OSI and TCP/IP models, showing a five-layer view—frame and data link through network and transport to application—analyzing MAC addresses, IP addresses, ports, and protocols like HTTP.
Visualize large pcap files for network forensics, quickly understanding traffic, open ports, dns queries, and credentials through graphical visualization tools.
Capture packets over GNS3 links with Wireshark by setting up Debian client and server, running an HTTP server, and observing DHCP, ICMP, and HTTP traffic with follow-stream analysis.
Gather requirements and create a network diagram to define VLANs, DMZ, and firewall topology for the headquarter and branch, then compile a detailed, open-source-friendly specifications document.
Create a GNS3 project with basic shapes and color codes to model office buildings, assign VLAN-inspired colors, duplicate layouts, and place a firewall and provider between Frankfurt and Stuttgart.
Explore how NVIDIA Cumulus Linux blends an open network operating system with Debian-based Linux, enabling switching and routing on standard hardware and managed via a native NVIDIA CLI.
Design a spine and leaf data center with two spine switches and three leaf switches, enabling redundant active-active connections across VLANs using the LCP protocol.
Add Alpine Linux clients to headquarters, configure static IPs and DHCP across VLANs, and ensure interfaces are bridged in Cumulus Linux for local client connectivity.
Configure a layer 2 switch by creating a bridge, assigning trunk and access ports, and implementing VLANs 10, 20, 30, and 40, with net commands and commit workflow.
Configure leaf switches with a bridge and VLAN IDs 10, 20, 30, 40, assign ports as access or trunk, and verify lldp connectivity across spine and leaf.
Explore how spanning tree protocol (stp) on cumulus linux switches prevents loops, enables automatic failover, and uses bpdu guard and edge ports to protect access networks.
Create and configure layer 3 virtual interfaces for management VLAN 40 on switches using Cumulus Linux, assign management IP addresses, enable SSH access from the management VLAN, and verify connectivity.
Configure bond interfaces using 802.3ad LACP to create fault-tolerant, load-balanced links across data center switches in Cumulus Linux, and avoid assigning IP addresses to bonds.
Configure bond interfaces with LAG/MLAG across two switches in Cumulus Linux, assign consistent bond IDs on both sides, enslave ports to bonds, and bridge them for a single virtual link.
In this lecture, the team builds the branch office network in GNS3 by replicating the headquarters setup, connects switches, adjusts hardware, and prepares for next configuration.
Configure branch office switches with trunk and access ports, VLAN interfaces, and bonds using MLAG. Verify connectivity and practice safe configuration with net commit and net abort.
Create a two-node openSUSE leap 15.3 firewall cluster in headquarters by importing the server image from OSBoxes into Janus three and planning interfaces and cabling for Frankfurt and branch office.
Configure hardware and set the network adapters to paravirtualized network I/O to enable interfaces on MX lac switches in this simulated environment, adjusting CPUs, RAM, and adapters as needed.
Configure two LACP bonded interfaces on openSUSE for the Frankfurt headquarter, binding ports 0–2 to bond zero and 3–4 to bond one to enable load balancing and fault tolerance.
Check bond1 interfaces and IP assignments, verify link status with ethtool, and test IPv4 and IPv6 connectivity between Linux firewall nodes; disable firewall temporarily to isolate issues and troubleshoot.
Configure VLAN interfaces on firewalls and establish multi-chassis link aggregation across Cumulus spine switches to create resilient bond links and seamless layer-2 communication.
Configure virtual VLAN interfaces on a Linux firewall cluster using bond zero as the parent, assign VLAN IDs 10, 20, 30, 40 with correct IPs and tagged traffic.
Disable IPv6 on Linux firewalls using the interface global options, apply, and restart the computer to ensure the firewall runs on IPv4 only for stronger security.
Install and configure keepalived on both openSUSE firewalls to enable VRRP-based high availability, using a shared virtual IP as the gateway for all VLANs.
Configure keepalived for an OpenSUSE firewall high-availability cluster by creating a master and backup vrrp instance, defining bond interfaces and a virtual IP with authentication.
Explore the net filter framework, a Linux open source firewall mechanism for packet mangling, detailing four tables—filter, nat, mangle, and raw—and how hooks shape packet traversal.
Explore net filter's four tables—filter, nat, mangle, and raw—and their chains, including input, forward, and output, with pre routing and post routing concepts.
Set default iptables policies to drop for input and forward, keep output open, and test with ping. Learn to persist these rules with iptables-persistent on Ubuntu.
Create and enable an iptables service on openSUSE, save the rules to the service file, and validate the stateful firewall with systemctl and iptables.
Create and enable the iptables service on the second firewall, configure /etc/sysconfig/iptables with drop forward and drop output while allowing related and established input, then verify with iptables -L.
Configure a trunk for vlan 20 and set up vlan interfaces with ip addresses. Enable ipv4 forwarding and implement masquerade NAT so vlan 20 can access the internet.
Install the dhcp server and configurator, enable it on VLAN ten and the management VLAN, configure per vlan IP ranges and gateways, and test with a client.
Create inter‑VLAN iptables rules on an OpenSUSE firewall cluster to allow management‑VLAN ssh access, enable dns and internet reach, and ensure rule order and persistence.
Continue building inter-vlan iptables policies on the firewall cluster, test the Apache web server, and open controlled http, dns, smb, and ssh traffic between VLANs and the dmz.
Publish a dmz web server to the internet by configuring iptables DNAT and destination NAT on vlan 30, enabling http and dns traffic, and validating with Apache.
Limit concurrent ssh connections to five within three minutes using the iptables recent module, log attempts for SIEM, and test firewall rules before migrating to NF tables.
Learn to visualize firewall rules by piping iptables output into gressgraph to generate a clear graph of interfaces, sources, and destinations, enabling quick interpretation of your rules.
Explore nf tables basics and how they replace iptables, including tables, chains, and rules for ipv4 and ipv6. Learn to translate iptables rules to nft and manage priorities.
Transform iptables rules into nftables, craft a dedicated nftables service, and validate rule deployment across firewalls with failover testing and remote management.
Migrate iptables rules to nf tables on the master firewall, back up first, validate on the backup, then enable nf tables and disable iptables.
Implement ssh brute-force protection with nftables by creating a deny list set, ban offending IPs after three new tcp connections per minute for five minutes, then test.
Configure branch office pfSense machines in gns3, connect consoles, and perform a guided installation with zfs to establish lan, lag, and vlan interfaces for web management.
Reassign pfSense LAN and WAN interfaces and launch the initial pfSense configuration for a branch office, including anti-lockout policies, IP settings, DNS, and a lab RFC 1918 address plan.
Configure pfSense branch office interfaces by creating two lagg links (m1–m3 and m2–m4) with LCP, add vlan ten, twenty, thirty, forty, assign ips, and enable pfSync clustering.
Set up pfSense high availability with corp interfaces for each VLAN and a dedicated ha sync link to enable transparent failover, while configuring MLAG across switches for reliable multi-chassis connectivity.
Configure pfSense DHCP for branch clients and management VLANs by enabling DHCP on VLAN ten and VLAN 40 and the server VLAN, setting ranges and gateways, and using internal DNS.
Configure pfSense firewall rules and aliases to provide internet, ICMP, and SSH access across management, server, DMZ, and client VLANs using floating rules and outbound NAT.
Configures inter-VLAN firewall rules on pfSense to permit web access from VLAN ten to a DMZ web server, using aliases and a floating rule for precise traffic control.
Configure an Ubuntu web server in a dmz by editing netplan yaml for a static ip, install apache2, and use ufw to enable inter-vlan access and discuss reverse nat.
Enable reverse nat through port forwarding on the firewall to expose the dmz web server to the internet via the wan interface, using an alias for the IP.
Configure a site-to-site ipsec vpn between openSUSE linux and pfSense with strongSwan. Explore ipsec concepts, left/right sides, routing, and firewall rules for ssh and icmp.
Configure a site-to-site vpn between OpenSUSE Linux and pfSense using strongSwan, covering phase one and two, 256-bit encryption, pre-shared key, and firewall rules for VLAN 40 and VLAN 30 networks.
Diagnose site-to-site ipsec vpn issues by using pfSense firewall logs to identify blocks on the van interface, add icmp rules, and verify with traces.
Prepare OpenVPN on pfSense by configuring a CA server, issuing a server certificate, and installing the OpenVPN client export plugin for management VLAN access.
Set up OpenVPN remote access on pfSense using the wizard, configure LDAP authentication with Active Directory, and tailor tunnel options with split tunneling and UDP 1194.
Set up wireguard between an openSUSE firewall and a Ubuntu remote client by generating keys, building client and server configs, enabling full tunnel, and testing connectivity.
Understand how dot1x opens network access after credential-based authentication via a radius server, with a supplicant and an authenticator, and the use of LDAP, certificates, and EAP methods.
Install PacketFence NAC server on a Debian 11 system using VirtualBox, configure network interfaces, update apt sources, add the PacketFence PGP key, and complete the installation.
Set up Packet Fence web configurator on Debian and configure the management vlan, radius, and policies to authenticate devices, map mac addresses, and assign vlans in a nac environment.
Deploy nas and freeradius with mab profiles by configuring an authenticator, switch groups, vlan ten, and map-based mac address authentication to manage unknown and accepted devices.
Configure 802.1X with NAC on a cumulus linux switch, enabling dynamic and parking VLANs and MAC-based radius authentication for wired clients.
Implement two-factor authentication for an ssh server on Ubuntu jump hosts within a management VLAN, using PAM and Google Authenticator to require a time-based verification code.
Examine how a compromised management vlan access enables reconnaissance and lateral movement, illustrating ethical hacking concepts like network scanning and layer two and layer three attacks.
When it comes to open-source, the sky is the limit!
In a nutshell, you will build a company-like network with headquarter and branch office on Unix-like OSs and open-source tools, then try to hack its vulnerabilities.
From switches to endpoints, clustered firewalls, servers incl. Network Access Control, shortly NAC server, jumpers, and anything else are all built on a flavor of Linux OS such as openSUSE, AlpineLinux, Debian, Ubuntu, etc., or a Unix-like OS such as FreeBSD.
Network security should be embedded into the nature of the corporate's network and that is what we learn in this course.
We do not care much about vendors and logos, but practical concepts. For example, we dive into Shell commands, TCP/IP and networking fundamental concepts, and core network security principles using open-source, yet industry-proven products.
We aim to teach you how standard networking concepts are "designed" and are also "applied" in work environments.
Why a pure Linux-based network? Besides the fact that Linux runs the world, if you learn the secure networking using Linux, Unix, and open-source tools, you will feel pretty confident about their commercial equivalents. For example, if you learn network firewalling using iptables and nftables, you won't have any issues with Cisco FirePower, FortiGate, or Juniper firewalls.
As said, we are not into vendors, we are interested in standardized theoretical concepts and practical technics. This method will give you a firm conceptual understanding of underlying technologies and ideas about how finished products like Cisco switches, Fortigate Firewalls, Cisco ISE NAC, HPE Aruba, and so on, actually work behind the scene.
In the end, you will run the most common network attacks using Kali Linux against the network you built yourself.
Your Learning Key-Terms:
Virtualization
GNS3 Lab (with Hyper-V & VirtualBox Integration)
TCP/IP
OSI Model
Network Topologies
IP Subnetting
VLAN
Traffic Tagging
Trunking
NIC Teaming
LAGG (Link Aggregation)
MLAG (Multi-Chassis Link Aggregation)
Bond Modes: Active-Backup, 802.3ad (LACP)
Bridging
Spanning Tree
Inter-VLAN Routing
Routing & ARP Tables
MAC Flood
IEEE 802.1X & MAB (MAC Address Bypass)
Network Access Control (NAC)
PacketFence (Open Source NAC)
Extensible Authentication Protocol (EAP) (EAPoL)
RADIUS (FreeRADIUS)
Linux Open Source Networking
Nvidia Cumulus Linux Switch
openSUSE Linux
Ubuntu Linux
Alpine Linux
Linux Shell Command Line
Firewalls
Netfilter Framework
Packet Filtering
iptables
nftables
Packet Capture Analysis
Wireshark, TShark, Termshark, and TCPDump
Linux Clustering
keepalived
VRRP
ConnTrack
Virtual Private Network (VPN)
OpenVPN
strongSwan IPSec (swanctl)
WireGuard
pfSense Firewall (FreeBSD)
pfSense Cluster
Next-Gen Firewall
Demilitarized Zone (DMZ)
Ethical Hacking Network Attacks and Technics
SSH BruteForce Attack
MITM with Mac Spoofing Attack
MITM with DHCP Spoofing Attack
DOS Attack (POD, SYNFLOOD, BPDUs, CDP)
Yersinia
DHCP Starvation
DNS Spoofing
Offensive Packet Sniffing
ARP spoofing, ARP cache poisoning attack
Network hacking
Cyber security
Network Hardening Solutions