Comparte si te a gustado:

Secure Networking - A Company Network Project on Open-Source

Publicado en 13 Sep 2022

Udemy UK

What you'll learn

  • Building up a company-grade segmented network with embeded security, ENTIRELY on Unix-like OS
  • Project-based learning of configuring firewall clusters on OpenSUSE Linux as well as pfSense
  • Learn about NAC (802.1X, EAP, EAPoL) using PacketFence to reject or accpet clients on switches
  • Learn underlying cluster technologies e.g. Keepalived & VRRP
  • Networking core fundamentals such as Traffic Tagging using VLANs, Trunking, STP, subnetting, LAG, MLAG, etc.
  • Learn firewall's core functionalities & be able to work with any firewall, no matter what brand
  • Initial to advanced configuration of Nvidia Cumulus Linux switches
  • Learn how head & branch offices securely communicate using IPSec site to site VPN
  • Practicing network security by segmentation, compartmentalization, & isolation
  • Learn how to create different VLANs in a company and control their traffic on each other
  • Setting up Linux based DHCP server to serve IP addresses in different VLANs
  • Learn network redundency methods e.g. LACP (802.3ad), balance-rr, balance-xor, etc. on Linux, pfSense and Cumulus switch
  • Learn how to migrate from iptables to nftables
  • Project-based learning of advanced pfSense firewall features
  • Project-based learning of packet capture & analysis using Wireshark, TShark, TermShark & TCPDump
  • Learn about openSUSE, AlpineLinux, Debian, Ubuntu and FreeBSD
  • Implement IPSec VPN on openSUSE using strongSwan
  • Configuring openVPN remote access for home office users
  • Configuring Wireguard remote access for IoT devices (key based authentication)
  • Learn how to harden SSH logins using two-factor authentication (2FA)
  • Learn virtualization using VirtualBox and GNS3
  • Learn most common network attacks and penetration testing technics

Requirements

  • No prior programming knowledge required
  • Basic IT & networking skills
  • A virtualization compatible computer
  • Internet connection
  • Passionate curiosity for learning (is a must)

Description


When it comes to open-source, the sky is the limit!

In a nutshell, You will build a company-like network with headquarter and branch office on Unix-like OSs and open-source tools.

From switches to endpoints, clustered firewalls, servers incl. Network Access Control, shortly NAC server, jumpers, and anything else are all built on a flavor of Linux OS such as openSUSE, AlpineLinux, Debian, Ubuntu, etc., or a Unix-like OS such as FreeBSD.

Network security should be embedded into the nature of the corporate's network and that is what we learn in this course.

We do not care much about vendors and logos, but practical concepts. For example, we dive into Shell commands, TCP/IP and networking fundamental concepts, and core network security principles using open-source, yet industry-proven products.

We aim to teach you how standard networking concepts are "designed" and are also "applied" in work environments.

Why a pure Linux-based network? Besides the fact that Linux runs the world, if you learn the secure networking using Linux, Unix, and open-source tools, you will feel pretty confident about their commercial equivalents. For example, if you learn network firewalling using iptables and nftables, you won't have any issues with Cisco FirePower, FortiGate, or Juniper firewalls.

As said, we are not into vendors, we are interested in standardized theoretical concepts and practical technics. This method will give you a firm conceptual understanding of underlying technologies and ideas about how finished products like Cisco switches, Fortigate Firewalls, Cisco ISE NAC, HPE Aruba, and so on, actually work behind the scene.

In the end, you will run the most common network attacks using Kali Linux against the network you built yourself.


Your Learning Key-Terms:

Virtualization

GNS3 Lab (with Hyper-V & VirtualBox Integration)

TCP/IP

OSI Model

Network Topologies

IP Subnetting

VLAN

Traffic Tagging

Trunking

NIC Teaming

LAGG (Link Aggregation)

MLAG (Multi-Chassis Link Aggregation)

Bond Modes: Active-Backup, 802.3ad (LACP)

Bridging

Spanning Tree

Inter-VLAN Routing

Routing & ARP Tables

MAC Flood

IEEE 802.1X & MAB (MAC Address Bypass)

Network Access Control (NAC)

PacketFence (Open Source NAC)

Extensible Authentication Protocol (EAP) (EAPoL)

RADIUS (FreeRADIUS)

Linux Open Source Networking

Nvidia Cumulus Linux Switch

openSUSE Linux

Ubuntu Linux

Alpine Linux

Linux Shell Command Line

Firewalls

Netfilter Framework

Packet Filtering

iptables

nftables

Packet Capture Analysis

Wireshark, TShark, Termshark, and TCPDump

Linux Clustering

keepalived

ConnTrack

Virtual Private Network (VPN)

OpenVPN

strongSwan IPSec (swanctl)

WireGuard

pfSense Firewall (FreeBSD)

pfSense Cluster

Next-Gen Firewall

Demilitarized Zone (DMZ)

Ethical Hacking Network Attacks and Technics

SSH BruteForce Attack

MITM with Mac Spoofing Attack

MITM with DHCP Spoofing Attack

DOS Attack (POD, SYNFLOOD, BPDUs, CDP)

Yersinia

DHCP Starvation

DNS Spoofing

Offensive Packet Sniffing

ARP spoofing, ARP cache poisoning attack

Network Hardening Solutions


Who this course is for:

  • Computer Students, learners and enthusiasts
  • IT administrators
  • Network engineers
  • Linux engineers
  • Cybersecurity specialists
  • Firewall administrators

Debes tener en cuenta que los cupones duran maximo 4 dias o hasta agotar 1000 inscripciones,pero puede vencer en cualquier momento. Obten el curso con cupon haciendo clic en el siguiente boton:

(Cupón válido para las primeras 1000 inscripciones): 20F34FEF3875224D5354
Udemy UK
Tags:

Articulos Relacionados

content

Sistema de asistencias en C# y SQLserver desde 0

Proyecto funcional y terminado

Ir al Curso
content

Python para no matemáticos: De 0 hasta reconocimiento facial

Reconocimiento facial

Ir al Curso
content

Xamarin básico: Una introducción al SDK de Microsoft

Una guía en el desarrollo de aplicaciones con esta poderosa herramienta

Ir al Curso
Suscríbete a nuestro boletín
Reciba los últimos Cupones y promociones (Solicitar Cupón)