Гайд по демонстрационному экзамену

Пошаговая настройка стенда: ISP, HQ-RTR, HQ-SRV, HQ-CLI, BR-RTR, BR-FW, BR-SRV

Скриншот к шагу
Скриншот к шагу
Скриншот к шагу

Задания 1, 3, 11

ISP

# hostnamectl set-hostname isp; exec bash
# timedatectl set-timezone Europe/Moscow
# nmtui
Скриншот к шагу
Скриншот к шагу
Скриншот к шагу

Проверка:

Скриншот к шагу
# nano /etc/sysctl.conf
net.ipv4.ip_forward=1
Скриншот к шагу
# sysctl -p
Скриншот к шагу

HQ-RTR

# hostnamectl set-hostname hq-rtr.au-team.irpo; exec bash
# timedatectl set-timezone Europe/Moscow
# nmtui
Скриншот к шагу
Скриншот к шагу

(1)

Скриншот к шагу
Скриншот к шагу
Скриншот к шагу
Скриншот к шагу
Скриншот к шагу
Скриншот к шагу

Проверка:

Скриншот к шагу
# nano /etc/sysctl.conf
net.ipv4.ip_forward=1
Скриншот к шагу
# sysctl -p
Скриншот к шагу

HQ-SRV

# hostnamectl set-hostname hq-srv.au-team.irpo; exec bash
# timedatectl set-timezone Europe/Moscow
# useradd sshuser -u 2027 -U
# passwd sshuser
< вводим пароль пользователя >
< повторяем ввод паря >
# visudo
sshuser ALL=(ALL) NOPASSWD: ALL
Скриншот к шагу
# nmtui
Скриншот к шагу
Скриншот к шагу
Скриншот к шагу

Проверка:

Скриншот к шагу

HQ-CLI

# hostnamectl set-hostname hq-cli.au-team.irpo; exec bash
# timedatectl set-timezone Europe/Moscow
# nmtui
Скриншот к шагу
Скриншот к шагу

BR-RTR

# hostnamectl set-hostname br-rtr.au-team.irpo; exec bash
# timedatectl set-timezone Europe/Moscow
# nmtui
Скриншот к шагу
Скриншот к шагу

Проверка:

Скриншот к шагу
# nano /etc/sysctl.conf
net.ipv4.ip_forward=1
Скриншот к шагу
# sysctl -p
Скриншот к шагу

BR-FW

# hostnamectl set-hostname br-fw.au-team.irpo; exec bash
# timedatectl set-timezone Europe/Moscow
# nmtui
Скриншот к шагу
Скриншот к шагу

Проверка:

Скриншот к шагу
# nano /etc/sysctl.conf
net.ipv4.ip_forward=1
Скриншот к шагу
# sysctl -p
Скриншот к шагу

BR-SRV

# hostnamectl set-hostname br-srv.au-team.irpo; exec bash
# timedatectl set-timezone Europe/Moscow
# useradd net_admin  -U
# passwd net_admin
< вводим пароль пользователя >
< повторяем ввод паря >
# visudo
net_admin   ALL=(ALL) NOPASSWD: ALL
Скриншот к шагу
# nmtui
Скриншот к шагу

Проверка:

Скриншот к шагу

Задание 2

ISP

# nano /etc/nftables/isp.nft
table inet nat {
chain POSTROUTING {
type nat hook postrouting priority srcnat;
oifname "enp0s3" masquerade
}
}

Пример:

Скриншот к шагу
# nano /etc/sysconfig/nftables.conf
include "/etc/nftables/isp.nft"

Пример:

Скриншот к шагу
# systemctl enable --now nftables

HQ-RTR

Проверка:

Скриншот к шагу

BR-RTR

Проверка:

Скриншот к шагу

Задание 4

HQ-RTR

# lsmod | grep 8021q
Скриншот к шагу
# modprobe 8021q
# ip -c -br a
Скриншот к шагу

HQ-SRV

Проверка:

Скриншот к шагу

Задание 5

HQ-SRV

# semanage port -a -t ssh_port_t -p tcp 2027
# setenforce 0
# dnf install policycoreutils-python-utils
# nano /etc/ssh/sshd_config
Скриншот к шагу
Скриншот к шагу
# nano /etc/ssh_banner
Скриншот к шагу
# systemctl restart sshd

HQ-RTR

Проверка:

Скриншот к шагу

BR-SRV

# semanage port -a -t ssh_port_t -p tcp 2027
# setenforce 0
# dnf install policycoreutils-python-utils
# nano /etc/ssh/sshd_config
Скриншот к шагу
Скриншот к шагу
# nano /etc/ssh_banner
Скриншот к шагу
# systemctl restart sshd

BR-FW

Проверка:

Скриншот к шагу

Задание 6

HQ-RTR

# nmtui
Скриншот к шагу
Скриншот к шагу
Скриншот к шагу
# nmcli connection modify tun1 ip-tunnel.ttl 64

Перегружаем интерфейсы

Проверка:

Скриншот к шагу

Проверка:

Скриншот к шагу

BR-RTR

# nmtui
Скриншот к шагу
# nmcli connection modify tun1 ip-tunnel.ttl 64

Перегружаем интерфейсы

Проверка:

Скриншот к шагу

Проверка:

Скриншот к шагу

Задания 7, 8

HQ-RTR

# dnf install -y frr
# nano /etc/frr/daemons
ospfd = yes
Скриншот к шагу
# systemctl enable --now frr
# vtysh
hq-rtr.au-team.irpo# configure terminal
hq-rtr.au-team.irpo(config)# router ospf
hq-rtr.au-team.irpo(config-router)# passive-interface default
hq-rtr.au-team.irpo(config-router)# network 192.168.100.0/27 area 0
hq-rtr.au-team.irpo(config-router)# network 192.168.200.0/28 area 0
hq-rtr.au-team.irpo(config-router)# network 192.168.99.0/29 area 0
hq-rtr.au-team.irpo(config-router)# network 10.10.10.0/30 area 0
hq-rtr.au-team.irpo(config-router)# exit
hq-rtr.au-team.irpo(config)# interface tun1
hq-rtr.au-team.irpo(config-if)# no ip ospf passive
hq-rtr.au-team.irpo(config-if)# ip ospf authentication message-digest
hq-rtr.au-team.irpo(config-if)# ip ospf message-digest-key 1 md5 P@ssw0rd
hq-rtr.au-team.irpo(config-if)# exit
hq-rtr.au-team.irpo(config)# exit
hq-rtr.au-team.irpo write
hq-rtr.au-team.irpo exit
# systemctl restart frr
Скриншот к шагу
# vtysh
# show running-config
Скриншот к шагу
# nano /etc/nftables/hq-rtr.nft
table inet nat {
chain POSTROUTING {
type nat hook postrouting priority srcnat;
oifname "enp0s3" masquerade
}
}
# nano /etc/sysconfig/nftables.conf
include "/etc/nftables/hq-rtr.nft"
# systemctl enable --now nftables
# vtysh -c  "show ip ospf neighbor"
# vtysh -c "show ip route ospf"
Скриншот к шагу

BR-RTR

# dnf install -y frr
# nano /etc/frr/daemons
ospfd = yes
Скриншот к шагу
# systemctl enable --now frr
# vtysh
br-rtr.au-team.irpo# configure terminal
br-rtr.au-team.irpo(config)# router ospf
br-rtr.au-team.irpo(config-router)# passive-interface default
br-rtr.au-team.irpo(config-router)# network 172.16.10.0/30 area 0
br-rtr.au-team.irpo(config-router)# network 10.10.10.0/30 area 0
br-rtr.au-team.irpo(config-router)# exit
br-rtr.au-team.irpo(config)# interface tun1
br-rtr.au-team.irpo(config-if)# no ip ospf passive
br-rtr.au-team.irpo(config-if)# ip ospf authentication message-digest
br-rtr.au-team.irpo(config-if)# ip ospf message-digest-key 1 md5 P@ssw0rd
br-rtr.au-team.irpo(config-if)# exit
br-fw.au-team.irpo(config)# interface enp0s8
br-fw.au-team.irpo(config-if)# no ip ospf passive
br-fw.au-team.irpo(config-if)# exit
br-fw.au-team.irpo(config)# exit
br-rtr.au-team.irpo write
br-rtr.au-team.irpo exit
Скриншот к шагу
# systemctl restart frr
# nano /etc/nftables/br-rtr.nft
table inet nat {
chain POSTROUTING {
type nat hook postrouting priority srcnat;
oifname "enp0s3" masquerade
}
}
# nano /etc/sysconfig/nftables.conf
include "/etc/nftables/br-rtr.nft"
# systemctl enable --now nftables
# vtysh -c  "show ip ospf neighbor"
# vtysh -c "show ip route ospf"
Скриншот к шагу

HQ-SRV

Проверка:

Скриншот к шагу
Скриншот к шагу

BR-SRV

Проверка:

Скриншот к шагу
Скриншот к шагу

BR-FW

# dnf install -y frr
# nano /etc/frr/daemons
ospfd = yes
Скриншот к шагу
# systemctl enable --now frr
# vtysh
br-fw.au-team.irpo# configure terminal
br-fw.au-team.irpo(config)# router ospf
br-fw.au-team.irpo(config-router)# passive-interface default
br-fw.au-team.irpo(config-router)# network 172.16.10.0/30 area 0
br-fw.au-team.irpo(config-router)# network 172.16.20.0/28 area 0
br-fw.au-team.irpo(config-router)# exit
br-fw.au-team.irpo(config)# interface enp0s3
br-fw.au-team.irpo(config-if)# no ip ospf passive
br-fw.au-team.irpo(config-if)# exit
br-fw.au-team.irpo(config)# exit
br-fw.au-team.irpo write
br-fw.au-team.irpo exit
# systemctl restart frr
Скриншот к шагу
# systemctl restart frr
# vtysh -c  "show ip ospf neighbor"
# vtysh -c "show ip route ospf"
Скриншот к шагу

Задание 9

HQ-RTR

# dnf install dhcp-server -y
# cp /usr/share/doc/dhcp-server/dhcpd.conf.example  /etc/dhcp/dhcpd.conf
# nano /etc/dhcp/dhcpd.conf

Находим блок # A slightly different configuration for an internal subnet. Его правим, а все остальное удаляем.

subnet 192.168.200.0 netmask 255.255.255.240 {
range 192.168.200.2 192.168.200.14;
option domain-name-servers 192.168.100.2;
option domain-name "au-team.irpo";
option routers 192.168.200.1;
default-lease-time 600;
max-lease-time 7200;
}
Скриншот к шагу
# systemctl enable --now dhcpd

HQ-CLI

Проверка:

Скриншот к шагу

Задание 10

HQ-SRV

# dnf install bind bind-utils
# nano  /etc/named.conf
Скриншот к шагу

Дописываем в конец файла /etc/named.conf следующие строки

Скриншот к шагу
# named-checkconf
Скриншот к шагу
# mkdir /var/named/master
# cp /var/named/named.localhost /var/named/master/au-team.db
# nano /var/named/master/au-team.db
Скриншот к шагу
# cp /var/named/named.loopback /var/named/master/au-team_rev1.db
# nano /var/named/master/au-team_rev1.db
Скриншот к шагу
# cp /var/named/master/au-team_rev1.db  /var/named/master/au-team_rev2.db
# nano /var/named/master/au-team_rev2.db
Скриншот к шагу
# chown -R root:named /var/named/master
# chmod 0640 /var/named/master/*
# named-checkconf -z
Скриншот к шагу
Скриншот к шагу
Скриншот к шагу
# systemctl enable --now named

BR-SRV

Проверка:

Скриншот к шагу

HQ-CLI

Скриншот к шагу
Скриншот к шагу