Course Outline
Session 1: Fundamentals of SSH and Secure Access Protocols
- Comprehensive overview of the Secure Shell (SSH) protocol and its critical role in establishing secure remote connections for government operations
Enhancing SSH access security through the implementation of key-based authentication mechanisms
Enforcing robust password standards and integrating two-factor authentication protocols
Restricting SSH access by configuring the service to accept connections exclusively from designated IP addresses
Session 2: Samba File Sharing Infrastructure
- Foundational concepts of Samba and its application in facilitating file and printer sharing across heterogeneous environments
Configuring Samba servers to securely share designated directories
Establishing user authentication frameworks and permission models for Samba shares
Facilitating access to Samba shares from both Windows and Linux client systems
Session 3: Domain Name System (DNS) Administration
- Technical understanding of DNS architecture and its function in resolving domain names to IP addresses
Deploying and configuring a DNS server using BIND (Berkeley Internet Name Domain)
Administering DNS zones, resource records, and name resolution processes
Diagnosing and resolving common DNS operational issues
Session 4: Web Server Deployment (Apache)
- Introduction to the Apache HTTP Server and its capability for delivering web content
Installing and configuring Apache on Linux platforms
Creating virtual host configurations to manage multiple websites from a single server
Implementing SSL/TLS certificates to ensure secure HTTPS communication
Session 5: Cache Server Management (Squid)
- Analyzing the principles of caching and its impact on optimizing web performance and bandwidth efficiency
Installing and configuring Squid as a caching proxy server
Establishing access controls, defining caching policies, and configuring logging features in Squid
Evaluating and monitoring the effectiveness of Squid’s caching operations
Session 6: Email Server Configuration (Sendmail, Postfix)
- Review of core email protocols including SMTP, POP3, and IMAP
Deploying and configuring Sendmail or Postfix as primary email servers
Setting up email aliases, virtual domains, and user mailbox structures
Implementing spam filtering mechanisms and antivirus protections for email systems
Session 7: Dynamic Host Configuration Protocol (DHCP) Server
- Overview of DHCP functionality and its role in network management
Installing and configuring the ISC DHCP server
Dynamically assigning IP addresses, subnet masks, and other essential network parameters
Managing DHCP lease states and troubleshooting common configuration issues
Session 8: File Transfer Protocol (FTP) Server Setup
- General overview of FTP protocols and their application in data exchange
Installing and configuring FTP server software such as vsftpd or proftpd
Defining user access rights, permissions, and secure FTP parameters
Activating FTPS (FTP over SSL/TLS) to ensure encrypted file transfers
Session 9: Database Management Systems (MySQL)
- Introduction to the MySQL database management system and its operational components
Installing and configuring the MySQL server environment
Creating databases, tables, and secure user accounts
Overseeing data integrity, backup procedures, and database security protocols
Session 10: Advanced Firewall Architecture, Kernel Configuration, and Compilation
- Advanced firewall configuration strategies utilizing iptables for government network security
Implementing Network Address Translation (NAT) and port forwarding rules
Introduction to Linux kernel configuration and compilation processes
Tailoring kernel options to enhance system performance and security posture
Requirements
- A solid understanding of the Linux operating system
- Practical experience with fundamental Linux command-line utilities
Testimonials (2)
Very good structured and complex documentation. A good pace for exercises. Detailed explanations and right to subject.
Tiberiu Longauer
Course - Linux Advanced
I liked the fact that 80-90% of things were new to me, and it opened my eyes about a lot of technologies and about how sys admin works.