Description
This course will show you how to administer the network services of an enterprise Linux server in a secure and stable manner. You will learn how to implement basic services such as DNS and DHCP, how to implement a secure network and how to centralize accounts with an LDAP directory.
Who is this training for ?
For whom ?
Administrators, system engineers.
Prerequisites
Administrators, system engineers.
Training objectives
Training program
- TCP/IP base configuration
- The IP protocol (v4/v6).
- Analysis of operation and traffic.
- Notions of root-server, TLD, zone, registration.
- Configuration of DHCP, interaction with Bind.
- Reservation of addresses (
- mac).
- Practical work Construction of 'an IP network.
- Installation and configuration of DNS servers and clients.
- Configuring a DHCP server.
- Testing from clients.
- Basic administration and analysis
- Webmin: integrated remote administration tool.
- SSH and Telnet, two remote administration services.
- Super-servers: inetd and xinetd daemons.
- Securing services using tcp-wrappers.
- Practical work Installation of a server program managed by xinetd.
- Webmin demonstration and configuration sshd.
- Time synchronization.
- Centralize accounts with LDAP
- The directory principle.
- The differences with traditional management.
- Identification strategy under Linux (pam, nss.
- ).
- An LDAP authentication server.
- The Squid example (proxy).
- Samba
- Samba architecture.
- File sharing.
- Role of the different daemons (smbd, nmbd).
- Samba logs .
- The SWAT administration tool.
- Mounting under Linux and Windows (mount).
- Installation and configuration of the cups server.
- Messaging
- SMTP, POP3, IMAP4 protocols.
- Postfix SMTP server: installation, configuration.
- Access to the directory from mail clients.
- Practical work Installation and configuration of Postfix.
- Setting up POP3 and IMAP4 servers.
- External access
- Implementation of IP routing (route).
- IP Forwarding.
- NAT.
- Configuration, ACL management, sizing.
- The different FTP servers: wu-ftpd vs ProFTPD.
- The rsync service.
- Replication, backup.
- Practical work rnSetting up different types of routing, tests, proftpd server and proxy.
- Security
- Filtering
- IP/service.
- NetFilter: IP packet filtering: iptables.
- Standard rules with iptables.
- Practical work Configuration of TCPD, prohibition of access to certain services.
- Setting up filtering firewall rules (iptables).