Linux Firewall & DMX Networking Lab

Objective The lab focuses on troubleshooting real-world network failures by systematically isolating issues at each layer of the network stack. Network Topology LAN (User Network) DMZ (Service Network) 192.168.10.0/24 192.168.20.0/24 __________________ _____________________ Client VM Server VM 192.168.10.101 192.168.20.10 | | | | ________ Firewall VM ___________ (Router + Firewall) Issue 1: No connectivity between networks Failure to connect to the webserver Troubleshooting Workflow Step 1 - Verify the service exists From Server: ...

June 17, 2026 · 3 min

DMZ Network Lab - Firewall, Routing, and nftables

Objective The goal of this lab is to design and implement a basic DMZ (Demilitarized Zone) network using Linux virtual machines, understand routing between network segments, and apply nftables as a stateful firewall. Network Topology LAN (User Network) DMZ (Service Network) 192.168.10.0/24 192.168.20.0/24 __________________ _____________________ Client VM Server VM 192.168.10.101 192.168.20.10 | | | | ________ Firewall VM ___________ (Router + Firewall) VM & Routing Configuration Client VM sudo netplan try sudo netplan apply Firewall VM (Core Router) ...

June 16, 2026 · 2 min

Linux nftables Firewall Fundamentals Lab

Objective Lab Environment Client VM 1 - 192.168.10.101 Client VM 2 - 192.168.10.102 Server VM - 192.168.10.10 Server Setup Step 1 - Run web server python3 -m http.server 8080 ss -tln | grep :8080 Step 2 - Base firewall configuration sudo nft add table inet filter sudo nft add chain inet filter input \ '{ type filter hook input priority 0; policy drop; }' sudo nft add rule inet filter input iif lo accept sudo nft add rule inet filter input ct state established,related accept ...

June 15, 2026 · 2 min

LUKS Full Disk Encryption Lab (Attack & Defense)

Objective This lab demonstrates how Linux Full Disk Encryption (LUKS) works and what it protects against. Part 1 - Attack Scenario (Unencrypted Disk) Step 1 - Identify disk lsblk Step 2 - Create filesystem (no ecnryption) sudo mkfs.ext4 /dev/sdc Step 3 - Mount disk sudo mkdir /mnt/test sudo mount /dev/sdc /mnt/test Step 4 - Add sensitive data echo "Sensitive data" | sudo tee /mount/test/secret.txt ATTACK SIMULATION Step 1 - Direct mount attempt sudo mkdir /mnt/attack; sudo mount /dev/sdc /mnt/attack ls -l /mnt/attack cat /mnt/attack/secret.txt ...

June 12, 2026 · 2 min

GRUB Security Lab: Boot-Time Privilege Escalation & Hardening

Attack Simulation: Gaining Root Access via GRUB Objective Demonstrate how physical access to a Linux system can be abused to gain root privileges by modifying GRUB boot parameters. Prerequisites OS: Linux Ubuntu Access to GRUB menu during boot No GRUB password protection enabled Attack Steps Reboot the system and access the GRUB menu. Select the default Linux entry and press e to edit boot parameters. Locate the line starting with: linux /boot/vmlinuz-… Modify the line Boot the modified entry using Ctrl + X ...

June 11, 2026 · 2 min

USB Automounting with systemd

Objective Setting up automatic USB drive mounting on a Linux server using systemd mount and automount units Environment OS: Ubuntu Tools: system, USB drive Step 1 - Find Partition UUID Prerequisite: Plugin USB drive blkid /dev/sdb1 Note: UUID and filesystem type Step 2 - Create the Mount Unit sudo nano /etc/systemd/system/mnt-usb.mount Step 3 - Create Automount Unit sudo nano /etc/systemd/system/mnt-usb.automount Step 4 - Enable and Start sudo systemctl enable mnt-usb.automount sudo systemctl start mnt-usb.automount Step 5 - Verify and test Check the automount is active: ...

June 6, 2026 · 1 min

Centralized rsyslog server

Objective Build a centralized logging environment where: SERVER receives logs from client1 SERVER receives logs from client2 Logs are stored in separate files: /var/log/client1.log /var/log/client2.log Network Layout Host IP server 192.168.10.10 client1 192.168.10.101 client2 192.168.10.102 Environment OS: Ubuntu Tools: rsyslog Part 1 - Configure the rsyslog Server Verify rsyslog sudo systemctl status rsyslog Enable UDP Syslog reception and restart the rsyslog service sudo nano /etc/rsyslog.conf sudo systemctl restart rsyslog ...

June 4, 2026 · 1 min

DNS Lab - Dnsmasq, Client resolver, Caching

🧪 DNS Lab 📌 Objective Understand DNS from a systems perpective ⚙️ Environment Virtualization: VirtualBox OS: ( 1 DNS Server VM + 1 Client VM) 🛠️ Lab Network Topology 🧩 Phase 1 — Direct DNS (No Cache) Client VM -> dnsmasq (192.168.10.10) Used for: Break #1 (Wrong DNS Server) Break #2 (Wrong DNS Record) 🧩 Phase 2 — Direct DNS (No Cache) Clint VM -> systemd-resolved (127.0.0.53) [CACHE] -> dnsmasq (192.168.10.10) [DNS SERVER] ...

May 5, 2026 · 2 min

Inter-Interface Packet Forwarding Failure Investigation

🧪 Inter-Interface Packet Forwarding Failure Investigation 📌 Objective Diagnose why a client cannot reach the internet ⚙️ Environment Virtualization: VirtualBox OS: ( 1 DHCP Server VM + 1 Client VM) 🛠️ Lab Network Topology Server (DHCP) IP: 192.168.10.10 Interfaces: enp0s8 -> LAN enp0s3 -> NAT Client VM IP: 192.168.10.100 Interface: enp0s8 Gateway: 192.168.10.10 🚨 Incident Statement Client cannot access the internet 🔍 PHASE 1 — Verify the Problem Run on Client VM: ...

May 1, 2026 · 2 min

Process Management & Resource Control Lab

🧪 Process Management & Resource Control Lab 📌 Objective Simulate and troubleshoot a real-world system slowdown caused by CPU saturation and memory exhaustion. ⚙️ Environment Virtualization: VirtualBox OS: Ubuntu Server 🛠️ Lab Setup Step 1 - Create CPU Load Script nano cpu_hog.sh chmod +x cpu_hog.sh Step 2 - Create Memory Load Script (Python) nano mem_hog.py chmod +x mem_hog.py 🚨 Incident Simulation Step 1 - Check the System Load Baseline uptime ...

April 24, 2026 · 8 min