DMZ Network Lab - Firewall, Routing, and nftables

Objective The goal of this lab is to design and implement a basic DMZ (Demilitarized Zone) network using Linux virtual machines, understand routing between network segments, and apply nftables as a stateful firewall. Network Topology LAN (User Network) DMZ (Service Network) 192.168.10.0/24 192.168.20.0/24 __________________ _____________________ Client VM Server VM 192.168.10.101 192.168.20.10 | | | | ________ Firewall VM ___________ (Router + Firewall) VM & Routing Configuration Client VM sudo netplan try sudo netplan apply Firewall VM (Core Router) ...

June 16, 2026 · 2 min

Linux nftables Firewall Fundamentals Lab

Objective Lab Environment Client VM 1 - 192.168.10.101 Client VM 2 - 192.168.10.102 Server VM - 192.168.10.10 Server Setup Step 1 - Run web server python3 -m http.server 8080 ss -tln | grep :8080 Step 2 - Base firewall configuration sudo nft add table inet filter sudo nft add chain inet filter input \ '{ type filter hook input priority 0; policy drop; }' sudo nft add rule inet filter input iif lo accept sudo nft add rule inet filter input ct state established,related accept ...

June 15, 2026 · 2 min