|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/secure-networking-a-company-network-project-on-open-source/
课程评论:没有评论
本课程是一门高度实践的安全网络构建与渗透课程,注重使用开源工具和类Unix操作系统(如Linux、FreeBSD)来模拟企业级网络环境。学员将从零开始,搭建一个包含总部和分支机构的网络,涵盖从交换机、端点到集群防火墙、网络访问控制(NAC)服务器等所有关键组件。 课程的核心在于理解和应用实际的网络安全概念,而非特定厂商的设备。通过深入学习Shell命令、TCP/IP、OSI模型、IP子网划分、VLAN、Trunking、链路聚合(LAGG、MLAG)等基础概念,学员将掌握如何在Linux环境下实现这些功能。 在安全方面,课程将重点介绍Netfilter框架、iptables、nftables等防火墙技术,以及Wireshark、TShark、TCPDump等数据包分析工具。此外,还将探讨IEEE 802.1X、MAB、PacketFence(开源NAC)、FreeRADIUS等网络访问控制机制。 为了增强网络冗余性和可用性,课程还会教授Linux集群技术,如keepalived和VRRP。虚拟专用网络(VPN)方面,将涵盖OpenVPN和strongSwan IPSec(swanctl),以及WireGuard。pfSense防火墙(基于FreeBSD)的配置与集群也将是课程的一部分。 最终,学员将学习如何利用Kali Linux对自行搭建的网络进行各种常见的网络攻击,如SSH暴力破解、MAC欺骗/DHCP欺骗中间人攻击、DoS攻击(POD、SYNFLOOD、BPDUs、CDP)、DHCP耗尽、DNS欺骗、ARP欺骗等,从而全面了解网络安全攻防的实践过程。 通过本课程的学习,学员将获得对底层技术和安全原理的深刻理解,为日后应对商业级网络设备和安全解决方案打下坚实基础。 **关键学习点:** * **虚拟化与实验环境:** GNS3实验平台(集成Hyper-V & VirtualBox) * **网络基础:** TCP/IP、OSI模型、网络拓扑、IP子网划分、VLAN、Trunking、链路聚合(LAGG、MLAG)、Spanning Tree、Inter-VLAN路由、路由与ARP表 * **网络访问控制(NAC):** IEEE 802.1X、MAB、PacketFence、EAP、RADIUS * **Linux网络:** OpenSUSE、Ubuntu、Alpine Linux、Cumulus Linux、Shell命令、Netfilter、iptables、nftables、数据包捕获与分析 * **高可用性:** Linux集群(keepalived, VRRP) * **VPN:** OpenVPN, strongSwan IPSec, WireGuard * **防火墙:** pfSense Firewall(FreeBSD)、集群、DMZ * **渗透与攻击:** SSH暴力破解、中间人攻击(MAC/DHCP欺骗)、DoS攻击、DHCP耗尽、DNS欺骗、ARP欺骗、Yersinia、Kali Linux 本课程旨在教授学员如何“设计”和“应用”标准网络概念,并提供一种有效的学习方法,即使不关注特定的厂商和产品,也能自信地理解和操作商业网络设备。
When it comes to open-source, the sky is the limit!In a nutshell, you will build a company-like network with headquarter and branch office on Unix-like OSs and open-source tools, then try to hack its vulnerabilities.From switches to endpoints, clustered firewalls, servers incl. Network Access Control, shortly NAC server, jumpers, and anything else are all built on a flavor of Linux OS such as openSUSE, AlpineLinux, Debian, Ubuntu, etc., or a Unix-like OS such as FreeBSD.Network security should be embedded into the nature of the corporate's network and that is what we learn in this course.We do not care much about vendors and logos, but practical concepts. For example, we dive into Shell commands, TCP/IP and networking fundamental concepts, and core network security principles using open-source, yet industry-proven products.We aim to teach you how standard networking concepts are "designed" and are also "applied" in work environments. Why a pure Linux-based network? Besides the fact that Linux runs the world, if you learn the secure networking using Linux, Unix, and open-source tools, you will feel pretty confident about their commercial equivalents. For example, if you learn network firewalling using iptables and nftables, you won't have any issues with Cisco FirePower, FortiGate, or Juniper firewalls. As said, we are not into vendors, we are interested in standardized theoretical concepts and practical technics. This method will give you a firm conceptual understanding of underlying technologies and ideas about how finished products like Cisco switches, Fortigate Firewalls, Cisco ISE NAC, HPE Aruba, and so on, actually work behind the scene.In the end, you will run the most common network attacks using Kali Linux against the network you built yourself.Your Learning Key-Terms:VirtualizationGNS3 Lab (with Hyper-V & VirtualBox Integration)TCP/IPOSI ModelNetwork TopologiesIP SubnettingVLANTraffic TaggingTrunkingNIC TeamingLAGG (Link Aggregation)MLAG (Multi-Chassis Link Aggregation)Bond Modes: Active-Backup, 802.3ad (LACP)BridgingSpanning TreeInter-VLAN RoutingRouting & ARP TablesMAC FloodIEEE 802.1X & MAB (MAC Address Bypass)Network Access Control (NAC)PacketFence (Open Source NAC)Extensible Authentication Protocol (EAP) (EAPoL)RADIUS (FreeRADIUS)Linux Open Source NetworkingNvidia Cumulus Linux SwitchopenSUSE LinuxUbuntu LinuxAlpine LinuxLinux Shell Command LineFirewallsNetfilter FrameworkPacket FilteringiptablesnftablesPacket Capture AnalysisWireshark, TShark, Termshark, and TCPDumpLinux ClusteringkeepalivedVRRPConnTrackVirtual Private Network (VPN)OpenVPNstrongSwan IPSec (swanctl)WireGuardpfSense Firewall (FreeBSD)pfSense ClusterNext-Gen FirewallDemilitarized Zone (DMZ)Ethical Hacking Network Attacks and TechnicsSSH BruteForce AttackMITM with Mac Spoofing AttackMITM with DHCP Spoofing AttackDOS Attack (POD, SYNFLOOD, BPDUs, CDP)YersiniaDHCP StarvationDNS SpoofingOffensive Packet SniffingARP spoofing, ARP cache poisoning attackNetwork hackingCyber securityNetwork Hardening Solutions