Secondary DNS Server
Objective Configure a Secondary DNS server that automatically replicates DNS zones from the Primary DNS server using zone transfers (AXFR). Environment Virtualization: VirtualBox OS: ( 1 Primary DNS Server VM + 1 Secondary DNS Server + 1 Web Server VM + 1 Client VM) Network Topology Prerequisites This lab builds upon the following previous labs: Private DNS Infrastructure with BIND9 Hosting Multiple Websites on One Server Using Nginx The following components are assumed to already be configured: ...
HTTPS with Nginx using a Private Certificate Authority
HTTPS with Nginx using a Private Certificate Authority Objective Secure an existing Nginx website using HTTPS and a certificate signed by a private Certificate Authority. Environment Virtualization: VirtualBox OS: ( 1 DNS Server VM + 1 Web Server VM + 1 Client VM) Network Topology Prerequisites This lab builds upon the Private DNS Infrastructure with BIND9. The following components are assumed to already be configured: BIND9 installed and running on the DNS server. The company.lab DNS zone created and configured. The zone file (/etc/bind/db.company.lab) already exists. The client is configured to use the internal DNS server (192.168.10.10) via Netplan. DNS resolution between the client and the DNS server has been verified. Phase 1 - Verify DNS Resolution Before enabling HTTPS, verify that DNS resolves the web server correctly. ...
Configuring Reverse DNS (PTR Records) with BIND9
Configuring Reverse DNS (PTR Records) with BIND9 Objective Extend the existing private DNS infrastructure by configuring Reverse DNS (PTR records). This enables IP addresses to be resolved back to hostnames, complementing the forward lookup zone created in previous labs. By the end of this lab, the DNS server will support both: Forward lookups (hostname → IP address) Reverse lookups (IP address → hostname) Environment Virtualization: VirtualBox OS: ( 1 DNS Server VM + 1 Web Server VM + 1 Client VM) Network Topology ...
Hosting Multiple Websites on One Server Using Nginx
Hosting Multiple Websites on One Server Using Nginx Objective Host multiple websites on a single web server by combining: DNS (BIND9) Nginx Virtual Hosts (Server Blocks) Environment Virtualization: VirtualBox OS: ( 1 DNS Server VM + 1 Web Server VM + 1 Client VM) Network Topology Prerequisites This lab builds upon the Private DNS Infrastructure with BIND9 (3-VM Lab). The following components are assumed to already be configured: BIND9 installed and running on the DNS server. The company.lab DNS zone created and configured. The zone file (/etc/bind/db.company.lab) already exists. The client is configured to use the internal DNS server (192.168.10.10) via Netplan. DNS resolution between the client and the DNS server has been verified. In this lab, the existing DNS infrastructure is extended by adding additional DNS records and configuring Nginx virtual hosts to host multiple websites on a single web server. ...
Private DNS Infrastructure with BIND9
Private DNS Infrastructure with BIND9 Objective Build a private DNS infrastructure using BIND9 where: A DNS server resolves names in the company.lab domain. A web server hosts a website. A client uses the DNS server to locate and access the web server. Environment Virtualization: VirtualBox OS: ( 1 DNS Server VM + 1 Web Server VM + 1 Client VM) Network Topology Phase 1 - Configure DNS Server Step 1 - Install BIND9 and verify sudo apt update sudo apt install bind9 bind9-utils dnsutils sudo systemctl status named/bind9 ss -tulnp | grep 192.168.10.10:53 ...
Linux Firewall & DMX Networking Lab
Objective The lab focuses on troubleshooting real-world network failures by systematically isolating issues at each layer of the network stack. Network Topology LAN (User Network) DMZ (Service Network) 192.168.10.0/24 192.168.20.0/24 __________________ _____________________ Client VM Server VM 192.168.10.101 192.168.20.10 | | | | ________ Firewall VM ___________ (Router + Firewall) Issue 1: No connectivity between networks Failure to connect to the webserver Troubleshooting Workflow Step 1 - Verify the service exists From Server: ...
DMZ Network Lab - Firewall, Routing, and nftables
Objective The goal of this lab is to design and implement a basic DMZ (Demilitarized Zone) network using Linux virtual machines, understand routing between network segments, and apply nftables as a stateful firewall. Network Topology LAN (User Network) DMZ (Service Network) 192.168.10.0/24 192.168.20.0/24 __________________ _____________________ Client VM Server VM 192.168.10.101 192.168.20.10 | | | | ________ Firewall VM ___________ (Router + Firewall) VM & Routing Configuration Client VM sudo netplan try sudo netplan apply Firewall VM (Core Router) ...
Linux nftables Firewall Fundamentals Lab
Objective Lab Environment Client VM 1 - 192.168.10.101 Client VM 2 - 192.168.10.102 Server VM - 192.168.10.10 Server Setup Step 1 - Run web server python3 -m http.server 8080 ss -tln | grep :8080 Step 2 - Base firewall configuration sudo nft add table inet filter sudo nft add chain inet filter input \ '{ type filter hook input priority 0; policy drop; }' sudo nft add rule inet filter input iif lo accept sudo nft add rule inet filter input ct state established,related accept ...
LUKS Full Disk Encryption Lab (Attack & Defense)
Objective This lab demonstrates how Linux Full Disk Encryption (LUKS) works and what it protects against. Part 1 - Attack Scenario (Unencrypted Disk) Step 1 - Identify disk lsblk Step 2 - Create filesystem (no ecnryption) sudo mkfs.ext4 /dev/sdc Step 3 - Mount disk sudo mkdir /mnt/test sudo mount /dev/sdc /mnt/test Step 4 - Add sensitive data echo "Sensitive data" | sudo tee /mount/test/secret.txt ATTACK SIMULATION Step 1 - Direct mount attempt sudo mkdir /mnt/attack; sudo mount /dev/sdc /mnt/attack ls -l /mnt/attack cat /mnt/attack/secret.txt ...
GRUB Security Lab: Boot-Time Privilege Escalation & Hardening
Attack Simulation: Gaining Root Access via GRUB Objective Demonstrate how physical access to a Linux system can be abused to gain root privileges by modifying GRUB boot parameters. Prerequisites OS: Linux Ubuntu Access to GRUB menu during boot No GRUB password protection enabled Attack Steps Reboot the system and access the GRUB menu. Select the default Linux entry and press e to edit boot parameters. Locate the line starting with: linux /boot/vmlinuz-… Modify the line Boot the modified entry using Ctrl + X ...