Server Client Lab

Gurugautham Anandakumar edited this page Jun 3, 2024 · 20 revisions

Create two VMs (Server, Client) in Vmware Workstation Pro both belong to the same Subnet

  • Create the virtual machines, I opted CENTOS/RHEL AlmaLinux OS 9.3 Minimal ISO and configured the settings as needed (CPU, RAM, disk size).
  • Install packages in server machine: dhcp-server for DHCP, bind and bind-utils for DNS, tftp for TFTP, nginx for webserver, syslinux for boot-loader and wget for alma linux iso download.

Network Segmentation

  • Configure the network adapter to use "Custom: Specific virtual network", I selected Custom(VMnet2).
  • Uncheck the DHCP and host adapter box in VMware Network Settings for VMnet0 under Edit > Virtual Network Editor.
  • Configure static IP addresses manually.
    • Server: IP address: 192.168.1.10/24, Default gateway: 192.168.1.1
    • Client: IP address: 192.168.1.20/24, Default gateway: 192.168.1.1
  • Ensure that both virtual machines can ping each other to verify connectivity within the same subnet.

Create a DHCP Server

To automatically assign IP addresses and other network configuration information to devices that connect to our network.

  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
}
  • Start DHCP server
sudo systemctl start dhcpd
sudo systemctl enable dhcpd
  • Configure Firewall
sudo firewall-cmd --add-service=dhcp --permanent
sudo firewall-cmd --reload
  • Test DHCP server, boot the client machine and configure its network adapter to use DHCP.
sudo nmtui
### Under edit a connection, change IPv4 configuration to Automatic
sudo systemctl restart NetworkManager
### IP should be under specified dhcp range
ip a

Create a DNS Nameserver

To allow DHCP clients to resolve the domain name to IP addresses. Since our internal network is not connected to the internet, DNS resolution is limited to the domains and resources hosted within our internal network.

The internal DNS server will respond to DNS queries for domain names within its authoritative zones (configured in its BIND zone files). If client sends a DNS query for a domain outside of the internal network (e.g., google.com), it will typically result in a timeout or a response indicating that the domain could not be resolved.


  • Configure the BIND server to define the DNS zones under /etc/named.conf
  • I chose example.local for this lab, you can try anything.anything or kanye.west
/*Forward zone*/
zone "example.local" IN {
type master;
file "/var/named/example.local.zone";
};
/*Reverse zone*/
zone "1.168.192.in-addr.arpa" IN {
type master;
file "/var/named/1.168.192.in-addr.arpa.zone";
};
  • ARPA stands for Advanced Research Projects Agency

  • IN means INTERNET

  • Configure a forward zone file for example.local under /var/named/example.local.zone

; Forward Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; A record@IN A192.168.1.77ns1 IN A192.168.1.77
  • Configure a reverse zone file for example.local under /var/named/1.168.192.in-addr.arpa.zone
; Reverse Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; PTR record77 IN PTRns1.example.local.
  • Change the file ownership of example.local.zone and 1.168.192.in-addr.arpa.zone to named
chown :named /var/named/example.local.zone
chown :named /var/named/1.168.192.in-addr.arpa.zone
  • Start and Enable BIND
sudo systemctl start named
sudo systemctl enable named
  • Configure Firewall
sudo firewall-cmd --add-service=dns --permanent
sudo firewall-cmd --reload
  • Configure DHCP to Provide DNS Server Address /etc/dhcp/dhcpd.config
option domain-search "example.local";
option domain-name-servers 192.168.1.77;
  • Restart DHCP server sudo systemctl restart dhcpd named

  • Reboot Client machine reboot

  • Verify DNS server nslookup example.local or dig example.local

Perform PXE boot using TFTP server

To allow DHCP clients to boot and load an operating system over the network, typically used in scenarios like mass network installations or diskless workstations.

  • Configure TFTP server under /etc/xinetd.d/tftp
service tftp
{
socket_type = dgram
protocol = udp
wait = yes
user = root
server = /usr/sbin/in.tftpd
server_args = -s /var/lib/tftpboot
disable = no
per_source = 11
cps = 100 2
}
#disable = no - Indicates that the service is enabled and will respond to requests
#per_source - maximum number of concurrent transfers allowed per source IP address
#cps - connections per second with a burst value of 2
  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
next-server 192.168.1.10; # IP address of the TFTP server (using same server machine IP)
filename "pxelinux.0"; # Bootloader filename
}
  • We are gonna use nginx server as web server to host
  • Configure the Nginx server under /etc/nginx/conf.d/pxe_alma.conf
server{
listen 80;
server_name crop.com;
root /usr/share/html/alma9;
}
  • Allow incoming connections to these services in the firewall

firewall-cmd --add-service=dhcp --permanent
firewall-cmd --add-service=tftp --permanent
firewall-cmd --add-service=xinetd --permanent
firewall-cmd --add-service=nginx --permanent
firewall-cmd --reload
  • Temporarily disable SELinux to permissive mode
setenforce 0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Server Client Lab

Gurugautham Anandakumar edited this page Jun 3, 2024 · 20 revisions

Create two VMs (Server, Client) in Vmware Workstation Pro both belong to the same Subnet

  • Create the virtual machines, I opted CENTOS/RHEL AlmaLinux OS 9.3 Minimal ISO and configured the settings as needed (CPU, RAM, disk size).
  • Install packages in server machine: dhcp-server for DHCP, bind and bind-utils for DNS, tftp for TFTP, nginx for webserver, syslinux for boot-loader and wget for alma linux iso download.

Network Segmentation

  • Configure the network adapter to use "Custom: Specific virtual network", I selected Custom(VMnet2).
  • Uncheck the DHCP and host adapter box in VMware Network Settings for VMnet0 under Edit > Virtual Network Editor.
  • Configure static IP addresses manually.
    • Server: IP address: 192.168.1.10/24, Default gateway: 192.168.1.1
    • Client: IP address: 192.168.1.20/24, Default gateway: 192.168.1.1
  • Ensure that both virtual machines can ping each other to verify connectivity within the same subnet.

Create a DHCP Server

To automatically assign IP addresses and other network configuration information to devices that connect to our network.

  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
}
  • Start DHCP server
sudo systemctl start dhcpd
sudo systemctl enable dhcpd
  • Configure Firewall
sudo firewall-cmd --add-service=dhcp --permanent
sudo firewall-cmd --reload
  • Test DHCP server, boot the client machine and configure its network adapter to use DHCP.
sudo nmtui
### Under edit a connection, change IPv4 configuration to Automatic
sudo systemctl restart NetworkManager
### IP should be under specified dhcp range
ip a

Create a DNS Nameserver

To allow DHCP clients to resolve the domain name to IP addresses. Since our internal network is not connected to the internet, DNS resolution is limited to the domains and resources hosted within our internal network.

The internal DNS server will respond to DNS queries for domain names within its authoritative zones (configured in its BIND zone files). If client sends a DNS query for a domain outside of the internal network (e.g., google.com), it will typically result in a timeout or a response indicating that the domain could not be resolved.


  • Configure the BIND server to define the DNS zones under /etc/named.conf
  • I chose example.local for this lab, you can try anything.anything or kanye.west
/*Forward zone*/
zone "example.local" IN {
type master;
file "/var/named/example.local.zone";
};
/*Reverse zone*/
zone "1.168.192.in-addr.arpa" IN {
type master;
file "/var/named/1.168.192.in-addr.arpa.zone";
};
  • ARPA stands for Advanced Research Projects Agency

  • IN means INTERNET

  • Configure a forward zone file for example.local under /var/named/example.local.zone

; Forward Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; A record@IN A192.168.1.77ns1 IN A192.168.1.77
  • Configure a reverse zone file for example.local under /var/named/1.168.192.in-addr.arpa.zone
; Reverse Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; PTR record77 IN PTRns1.example.local.
  • Change the file ownership of example.local.zone and 1.168.192.in-addr.arpa.zone to named
chown :named /var/named/example.local.zone
chown :named /var/named/1.168.192.in-addr.arpa.zone
  • Start and Enable BIND
sudo systemctl start named
sudo systemctl enable named
  • Configure Firewall
sudo firewall-cmd --add-service=dns --permanent
sudo firewall-cmd --reload
  • Configure DHCP to Provide DNS Server Address /etc/dhcp/dhcpd.config
option domain-search "example.local";
option domain-name-servers 192.168.1.77;
  • Restart DHCP server sudo systemctl restart dhcpd named

  • Reboot Client machine reboot

  • Verify DNS server nslookup example.local or dig example.local

Perform PXE boot using TFTP server

To allow DHCP clients to boot and load an operating system over the network, typically used in scenarios like mass network installations or diskless workstations.

  • Configure TFTP server under /etc/xinetd.d/tftp
service tftp
{
socket_type = dgram
protocol = udp
wait = yes
user = root
server = /usr/sbin/in.tftpd
server_args = -s /var/lib/tftpboot
disable = no
per_source = 11
cps = 100 2
}
#disable = no - Indicates that the service is enabled and will respond to requests
#per_source - maximum number of concurrent transfers allowed per source IP address
#cps - connections per second with a burst value of 2
  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
next-server 192.168.1.10; # IP address of the TFTP server (using same server machine IP)
filename "pxelinux.0"; # Bootloader filename
}
  • We are gonna use nginx server as web server to host
  • Configure the Nginx server under /etc/nginx/conf.d/pxe_alma.conf
server{
listen 80;
server_name crop.com;
root /usr/share/html/alma9;
}
  • Allow incoming connections to these services in the firewall

firewall-cmd --add-service=dhcp --permanent
firewall-cmd --add-service=tftp --permanent
firewall-cmd --add-service=xinetd --permanent
firewall-cmd --add-service=nginx --permanent
firewall-cmd --reload
  • Temporarily disable SELinux to permissive mode
setenforce 0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Server Client Lab

Gurugautham Anandakumar edited this page Jun 3, 2024 · 20 revisions

Create two VMs (Server, Client) in Vmware Workstation Pro both belong to the same Subnet

  • Create the virtual machines, I opted CENTOS/RHEL AlmaLinux OS 9.3 Minimal ISO and configured the settings as needed (CPU, RAM, disk size).
  • Install packages in server machine: dhcp-server for DHCP, bind and bind-utils for DNS, tftp for TFTP, nginx for webserver, syslinux for boot-loader and wget for alma linux iso download.

Network Segmentation

  • Configure the network adapter to use "Custom: Specific virtual network", I selected Custom(VMnet2).
  • Uncheck the DHCP and host adapter box in VMware Network Settings for VMnet0 under Edit > Virtual Network Editor.
  • Configure static IP addresses manually.
    • Server: IP address: 192.168.1.10/24, Default gateway: 192.168.1.1
    • Client: IP address: 192.168.1.20/24, Default gateway: 192.168.1.1
  • Ensure that both virtual machines can ping each other to verify connectivity within the same subnet.

Create a DHCP Server

To automatically assign IP addresses and other network configuration information to devices that connect to our network.

  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
}
  • Start DHCP server
sudo systemctl start dhcpd
sudo systemctl enable dhcpd
  • Configure Firewall
sudo firewall-cmd --add-service=dhcp --permanent
sudo firewall-cmd --reload
  • Test DHCP server, boot the client machine and configure its network adapter to use DHCP.
sudo nmtui
### Under edit a connection, change IPv4 configuration to Automatic
sudo systemctl restart NetworkManager
### IP should be under specified dhcp range
ip a

Create a DNS Nameserver

To allow DHCP clients to resolve the domain name to IP addresses. Since our internal network is not connected to the internet, DNS resolution is limited to the domains and resources hosted within our internal network.

The internal DNS server will respond to DNS queries for domain names within its authoritative zones (configured in its BIND zone files). If client sends a DNS query for a domain outside of the internal network (e.g., google.com), it will typically result in a timeout or a response indicating that the domain could not be resolved.


  • Configure the BIND server to define the DNS zones under /etc/named.conf
  • I chose example.local for this lab, you can try anything.anything or kanye.west
/*Forward zone*/
zone "example.local" IN {
type master;
file "/var/named/example.local.zone";
};
/*Reverse zone*/
zone "1.168.192.in-addr.arpa" IN {
type master;
file "/var/named/1.168.192.in-addr.arpa.zone";
};
  • ARPA stands for Advanced Research Projects Agency

  • IN means INTERNET

  • Configure a forward zone file for example.local under /var/named/example.local.zone

; Forward Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; A record@IN A192.168.1.77ns1 IN A192.168.1.77
  • Configure a reverse zone file for example.local under /var/named/1.168.192.in-addr.arpa.zone
; Reverse Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; PTR record77 IN PTRns1.example.local.
  • Change the file ownership of example.local.zone and 1.168.192.in-addr.arpa.zone to named
chown :named /var/named/example.local.zone
chown :named /var/named/1.168.192.in-addr.arpa.zone
  • Start and Enable BIND
sudo systemctl start named
sudo systemctl enable named
  • Configure Firewall
sudo firewall-cmd --add-service=dns --permanent
sudo firewall-cmd --reload
  • Configure DHCP to Provide DNS Server Address /etc/dhcp/dhcpd.config
option domain-search "example.local";
option domain-name-servers 192.168.1.77;
  • Restart DHCP server sudo systemctl restart dhcpd named

  • Reboot Client machine reboot

  • Verify DNS server nslookup example.local or dig example.local

Perform PXE boot using TFTP server

To allow DHCP clients to boot and load an operating system over the network, typically used in scenarios like mass network installations or diskless workstations.

  • Configure TFTP server under /etc/xinetd.d/tftp
service tftp
{
socket_type = dgram
protocol = udp
wait = yes
user = root
server = /usr/sbin/in.tftpd
server_args = -s /var/lib/tftpboot
disable = no
per_source = 11
cps = 100 2
}
#disable = no - Indicates that the service is enabled and will respond to requests
#per_source - maximum number of concurrent transfers allowed per source IP address
#cps - connections per second with a burst value of 2
  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
next-server 192.168.1.10; # IP address of the TFTP server (using same server machine IP)
filename "pxelinux.0"; # Bootloader filename
}
  • We are gonna use nginx server as web server to host
  • Configure the Nginx server under /etc/nginx/conf.d/pxe_alma.conf
server{
listen 80;
server_name crop.com;
root /usr/share/html/alma9;
}
  • Allow incoming connections to these services in the firewall

firewall-cmd --add-service=dhcp --permanent
firewall-cmd --add-service=tftp --permanent
firewall-cmd --add-service=xinetd --permanent
firewall-cmd --add-service=nginx --permanent
firewall-cmd --reload
  • Temporarily disable SELinux to permissive mode
setenforce 0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Server Client Lab

Gurugautham Anandakumar edited this page Jun 3, 2024 · 20 revisions

Create two VMs (Server, Client) in Vmware Workstation Pro both belong to the same Subnet

  • Create the virtual machines, I opted CENTOS/RHEL AlmaLinux OS 9.3 Minimal ISO and configured the settings as needed (CPU, RAM, disk size).
  • Install packages in server machine: dhcp-server for DHCP, bind and bind-utils for DNS, tftp for TFTP, nginx for webserver, syslinux for boot-loader and wget for alma linux iso download.

Network Segmentation

  • Configure the network adapter to use "Custom: Specific virtual network", I selected Custom(VMnet2).
  • Uncheck the DHCP and host adapter box in VMware Network Settings for VMnet0 under Edit > Virtual Network Editor.
  • Configure static IP addresses manually.
    • Server: IP address: 192.168.1.10/24, Default gateway: 192.168.1.1
    • Client: IP address: 192.168.1.20/24, Default gateway: 192.168.1.1
  • Ensure that both virtual machines can ping each other to verify connectivity within the same subnet.

Create a DHCP Server

To automatically assign IP addresses and other network configuration information to devices that connect to our network.

  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
}
  • Start DHCP server
sudo systemctl start dhcpd
sudo systemctl enable dhcpd
  • Configure Firewall
sudo firewall-cmd --add-service=dhcp --permanent
sudo firewall-cmd --reload
  • Test DHCP server, boot the client machine and configure its network adapter to use DHCP.
sudo nmtui
### Under edit a connection, change IPv4 configuration to Automatic
sudo systemctl restart NetworkManager
### IP should be under specified dhcp range
ip a

Create a DNS Nameserver

To allow DHCP clients to resolve the domain name to IP addresses. Since our internal network is not connected to the internet, DNS resolution is limited to the domains and resources hosted within our internal network.

The internal DNS server will respond to DNS queries for domain names within its authoritative zones (configured in its BIND zone files). If client sends a DNS query for a domain outside of the internal network (e.g., google.com), it will typically result in a timeout or a response indicating that the domain could not be resolved.


  • Configure the BIND server to define the DNS zones under /etc/named.conf
  • I chose example.local for this lab, you can try anything.anything or kanye.west
/*Forward zone*/
zone "example.local" IN {
type master;
file "/var/named/example.local.zone";
};
/*Reverse zone*/
zone "1.168.192.in-addr.arpa" IN {
type master;
file "/var/named/1.168.192.in-addr.arpa.zone";
};
  • ARPA stands for Advanced Research Projects Agency

  • IN means INTERNET

  • Configure a forward zone file for example.local under /var/named/example.local.zone

; Forward Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; A record@IN A192.168.1.77ns1 IN A192.168.1.77
  • Configure a reverse zone file for example.local under /var/named/1.168.192.in-addr.arpa.zone
; Reverse Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; PTR record77 IN PTRns1.example.local.
  • Change the file ownership of example.local.zone and 1.168.192.in-addr.arpa.zone to named
chown :named /var/named/example.local.zone
chown :named /var/named/1.168.192.in-addr.arpa.zone
  • Start and Enable BIND
sudo systemctl start named
sudo systemctl enable named
  • Configure Firewall
sudo firewall-cmd --add-service=dns --permanent
sudo firewall-cmd --reload
  • Configure DHCP to Provide DNS Server Address /etc/dhcp/dhcpd.config
option domain-search "example.local";
option domain-name-servers 192.168.1.77;
  • Restart DHCP server sudo systemctl restart dhcpd named

  • Reboot Client machine reboot

  • Verify DNS server nslookup example.local or dig example.local

Perform PXE boot using TFTP server

To allow DHCP clients to boot and load an operating system over the network, typically used in scenarios like mass network installations or diskless workstations.

  • Configure TFTP server under /etc/xinetd.d/tftp
service tftp
{
socket_type = dgram
protocol = udp
wait = yes
user = root
server = /usr/sbin/in.tftpd
server_args = -s /var/lib/tftpboot
disable = no
per_source = 11
cps = 100 2
}
#disable = no - Indicates that the service is enabled and will respond to requests
#per_source - maximum number of concurrent transfers allowed per source IP address
#cps - connections per second with a burst value of 2
  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
next-server 192.168.1.10; # IP address of the TFTP server (using same server machine IP)
filename "pxelinux.0"; # Bootloader filename
}
  • We are gonna use nginx server as web server to host
  • Configure the Nginx server under /etc/nginx/conf.d/pxe_alma.conf
server{
listen 80;
server_name crop.com;
root /usr/share/html/alma9;
}
  • Allow incoming connections to these services in the firewall

firewall-cmd --add-service=dhcp --permanent
firewall-cmd --add-service=tftp --permanent
firewall-cmd --add-service=xinetd --permanent
firewall-cmd --add-service=nginx --permanent
firewall-cmd --reload
  • Temporarily disable SELinux to permissive mode
setenforce 0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Server Client Lab

Gurugautham Anandakumar edited this page Jun 3, 2024 · 20 revisions

Create two VMs (Server, Client) in Vmware Workstation Pro both belong to the same Subnet

  • Create the virtual machines, I opted CENTOS/RHEL AlmaLinux OS 9.3 Minimal ISO and configured the settings as needed (CPU, RAM, disk size).
  • Install packages in server machine: dhcp-server for DHCP, bind and bind-utils for DNS, tftp for TFTP, nginx for webserver, syslinux for boot-loader and wget for alma linux iso download.

Network Segmentation

  • Configure the network adapter to use "Custom: Specific virtual network", I selected Custom(VMnet2).
  • Uncheck the DHCP and host adapter box in VMware Network Settings for VMnet0 under Edit > Virtual Network Editor.
  • Configure static IP addresses manually.
    • Server: IP address: 192.168.1.10/24, Default gateway: 192.168.1.1
    • Client: IP address: 192.168.1.20/24, Default gateway: 192.168.1.1
  • Ensure that both virtual machines can ping each other to verify connectivity within the same subnet.

Create a DHCP Server

To automatically assign IP addresses and other network configuration information to devices that connect to our network.

  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
}
  • Start DHCP server
sudo systemctl start dhcpd
sudo systemctl enable dhcpd
  • Configure Firewall
sudo firewall-cmd --add-service=dhcp --permanent
sudo firewall-cmd --reload
  • Test DHCP server, boot the client machine and configure its network adapter to use DHCP.
sudo nmtui
### Under edit a connection, change IPv4 configuration to Automatic
sudo systemctl restart NetworkManager
### IP should be under specified dhcp range
ip a

Create a DNS Nameserver

To allow DHCP clients to resolve the domain name to IP addresses. Since our internal network is not connected to the internet, DNS resolution is limited to the domains and resources hosted within our internal network.

The internal DNS server will respond to DNS queries for domain names within its authoritative zones (configured in its BIND zone files). If client sends a DNS query for a domain outside of the internal network (e.g., google.com), it will typically result in a timeout or a response indicating that the domain could not be resolved.


  • Configure the BIND server to define the DNS zones under /etc/named.conf
  • I chose example.local for this lab, you can try anything.anything or kanye.west
/*Forward zone*/
zone "example.local" IN {
type master;
file "/var/named/example.local.zone";
};
/*Reverse zone*/
zone "1.168.192.in-addr.arpa" IN {
type master;
file "/var/named/1.168.192.in-addr.arpa.zone";
};
  • ARPA stands for Advanced Research Projects Agency

  • IN means INTERNET

  • Configure a forward zone file for example.local under /var/named/example.local.zone

; Forward Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; A record@IN A192.168.1.77ns1 IN A192.168.1.77
  • Configure a reverse zone file for example.local under /var/named/1.168.192.in-addr.arpa.zone
; Reverse Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; PTR record77 IN PTRns1.example.local.
  • Change the file ownership of example.local.zone and 1.168.192.in-addr.arpa.zone to named
chown :named /var/named/example.local.zone
chown :named /var/named/1.168.192.in-addr.arpa.zone
  • Start and Enable BIND
sudo systemctl start named
sudo systemctl enable named
  • Configure Firewall
sudo firewall-cmd --add-service=dns --permanent
sudo firewall-cmd --reload
  • Configure DHCP to Provide DNS Server Address /etc/dhcp/dhcpd.config
option domain-search "example.local";
option domain-name-servers 192.168.1.77;
  • Restart DHCP server sudo systemctl restart dhcpd named

  • Reboot Client machine reboot

  • Verify DNS server nslookup example.local or dig example.local

Perform PXE boot using TFTP server

To allow DHCP clients to boot and load an operating system over the network, typically used in scenarios like mass network installations or diskless workstations.

  • Configure TFTP server under /etc/xinetd.d/tftp
service tftp
{
socket_type = dgram
protocol = udp
wait = yes
user = root
server = /usr/sbin/in.tftpd
server_args = -s /var/lib/tftpboot
disable = no
per_source = 11
cps = 100 2
}
#disable = no - Indicates that the service is enabled and will respond to requests
#per_source - maximum number of concurrent transfers allowed per source IP address
#cps - connections per second with a burst value of 2
  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
next-server 192.168.1.10; # IP address of the TFTP server (using same server machine IP)
filename "pxelinux.0"; # Bootloader filename
}
  • We are gonna use nginx server as web server to host
  • Configure the Nginx server under /etc/nginx/conf.d/pxe_alma.conf
server{
listen 80;
server_name crop.com;
root /usr/share/html/alma9;
}
  • Allow incoming connections to these services in the firewall

firewall-cmd --add-service=dhcp --permanent
firewall-cmd --add-service=tftp --permanent
firewall-cmd --add-service=xinetd --permanent
firewall-cmd --add-service=nginx --permanent
firewall-cmd --reload
  • Temporarily disable SELinux to permissive mode
setenforce 0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Server Client Lab

Gurugautham Anandakumar edited this page Jun 3, 2024 · 20 revisions

Create two VMs (Server, Client) in Vmware Workstation Pro both belong to the same Subnet

  • Create the virtual machines, I opted CENTOS/RHEL AlmaLinux OS 9.3 Minimal ISO and configured the settings as needed (CPU, RAM, disk size).
  • Install packages in server machine: dhcp-server for DHCP, bind and bind-utils for DNS, tftp for TFTP, nginx for webserver, syslinux for boot-loader and wget for alma linux iso download.

Network Segmentation

  • Configure the network adapter to use "Custom: Specific virtual network", I selected Custom(VMnet2).
  • Uncheck the DHCP and host adapter box in VMware Network Settings for VMnet0 under Edit > Virtual Network Editor.
  • Configure static IP addresses manually.
    • Server: IP address: 192.168.1.10/24, Default gateway: 192.168.1.1
    • Client: IP address: 192.168.1.20/24, Default gateway: 192.168.1.1
  • Ensure that both virtual machines can ping each other to verify connectivity within the same subnet.

Create a DHCP Server

To automatically assign IP addresses and other network configuration information to devices that connect to our network.

  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
}
  • Start DHCP server
sudo systemctl start dhcpd
sudo systemctl enable dhcpd
  • Configure Firewall
sudo firewall-cmd --add-service=dhcp --permanent
sudo firewall-cmd --reload
  • Test DHCP server, boot the client machine and configure its network adapter to use DHCP.
sudo nmtui
### Under edit a connection, change IPv4 configuration to Automatic
sudo systemctl restart NetworkManager
### IP should be under specified dhcp range
ip a

Create a DNS Nameserver

To allow DHCP clients to resolve the domain name to IP addresses. Since our internal network is not connected to the internet, DNS resolution is limited to the domains and resources hosted within our internal network.

The internal DNS server will respond to DNS queries for domain names within its authoritative zones (configured in its BIND zone files). If client sends a DNS query for a domain outside of the internal network (e.g., google.com), it will typically result in a timeout or a response indicating that the domain could not be resolved.


  • Configure the BIND server to define the DNS zones under /etc/named.conf
  • I chose example.local for this lab, you can try anything.anything or kanye.west
/*Forward zone*/
zone "example.local" IN {
type master;
file "/var/named/example.local.zone";
};
/*Reverse zone*/
zone "1.168.192.in-addr.arpa" IN {
type master;
file "/var/named/1.168.192.in-addr.arpa.zone";
};
  • ARPA stands for Advanced Research Projects Agency

  • IN means INTERNET

  • Configure a forward zone file for example.local under /var/named/example.local.zone

; Forward Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; A record@IN A192.168.1.77ns1 IN A192.168.1.77
  • Configure a reverse zone file for example.local under /var/named/1.168.192.in-addr.arpa.zone
; Reverse Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; PTR record77 IN PTRns1.example.local.
  • Change the file ownership of example.local.zone and 1.168.192.in-addr.arpa.zone to named
chown :named /var/named/example.local.zone
chown :named /var/named/1.168.192.in-addr.arpa.zone
  • Start and Enable BIND
sudo systemctl start named
sudo systemctl enable named
  • Configure Firewall
sudo firewall-cmd --add-service=dns --permanent
sudo firewall-cmd --reload
  • Configure DHCP to Provide DNS Server Address /etc/dhcp/dhcpd.config
option domain-search "example.local";
option domain-name-servers 192.168.1.77;
  • Restart DHCP server sudo systemctl restart dhcpd named

  • Reboot Client machine reboot

  • Verify DNS server nslookup example.local or dig example.local

Perform PXE boot using TFTP server

To allow DHCP clients to boot and load an operating system over the network, typically used in scenarios like mass network installations or diskless workstations.

  • Configure TFTP server under /etc/xinetd.d/tftp
service tftp
{
socket_type = dgram
protocol = udp
wait = yes
user = root
server = /usr/sbin/in.tftpd
server_args = -s /var/lib/tftpboot
disable = no
per_source = 11
cps = 100 2
}
#disable = no - Indicates that the service is enabled and will respond to requests
#per_source - maximum number of concurrent transfers allowed per source IP address
#cps - connections per second with a burst value of 2
  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
next-server 192.168.1.10; # IP address of the TFTP server (using same server machine IP)
filename "pxelinux.0"; # Bootloader filename
}
  • We are gonna use nginx server as web server to host
  • Configure the Nginx server under /etc/nginx/conf.d/pxe_alma.conf
server{
listen 80;
server_name crop.com;
root /usr/share/html/alma9;
}
  • Allow incoming connections to these services in the firewall

firewall-cmd --add-service=dhcp --permanent
firewall-cmd --add-service=tftp --permanent
firewall-cmd --add-service=xinetd --permanent
firewall-cmd --add-service=nginx --permanent
firewall-cmd --reload
  • Temporarily disable SELinux to permissive mode
setenforce 0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Server Client Lab

Gurugautham Anandakumar edited this page Jun 3, 2024 · 20 revisions

Create two VMs (Server, Client) in Vmware Workstation Pro both belong to the same Subnet

  • Create the virtual machines, I opted CENTOS/RHEL AlmaLinux OS 9.3 Minimal ISO and configured the settings as needed (CPU, RAM, disk size).
  • Install packages in server machine: dhcp-server for DHCP, bind and bind-utils for DNS, tftp for TFTP, nginx for webserver, syslinux for boot-loader and wget for alma linux iso download.

Network Segmentation

  • Configure the network adapter to use "Custom: Specific virtual network", I selected Custom(VMnet2).
  • Uncheck the DHCP and host adapter box in VMware Network Settings for VMnet0 under Edit > Virtual Network Editor.
  • Configure static IP addresses manually.
    • Server: IP address: 192.168.1.10/24, Default gateway: 192.168.1.1
    • Client: IP address: 192.168.1.20/24, Default gateway: 192.168.1.1
  • Ensure that both virtual machines can ping each other to verify connectivity within the same subnet.

Create a DHCP Server

To automatically assign IP addresses and other network configuration information to devices that connect to our network.

  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
}
  • Start DHCP server
sudo systemctl start dhcpd
sudo systemctl enable dhcpd
  • Configure Firewall
sudo firewall-cmd --add-service=dhcp --permanent
sudo firewall-cmd --reload
  • Test DHCP server, boot the client machine and configure its network adapter to use DHCP.
sudo nmtui
### Under edit a connection, change IPv4 configuration to Automatic
sudo systemctl restart NetworkManager
### IP should be under specified dhcp range
ip a

Create a DNS Nameserver

To allow DHCP clients to resolve the domain name to IP addresses. Since our internal network is not connected to the internet, DNS resolution is limited to the domains and resources hosted within our internal network.

The internal DNS server will respond to DNS queries for domain names within its authoritative zones (configured in its BIND zone files). If client sends a DNS query for a domain outside of the internal network (e.g., google.com), it will typically result in a timeout or a response indicating that the domain could not be resolved.


  • Configure the BIND server to define the DNS zones under /etc/named.conf
  • I chose example.local for this lab, you can try anything.anything or kanye.west
/*Forward zone*/
zone "example.local" IN {
type master;
file "/var/named/example.local.zone";
};
/*Reverse zone*/
zone "1.168.192.in-addr.arpa" IN {
type master;
file "/var/named/1.168.192.in-addr.arpa.zone";
};
  • ARPA stands for Advanced Research Projects Agency

  • IN means INTERNET

  • Configure a forward zone file for example.local under /var/named/example.local.zone

; Forward Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; A record@IN A192.168.1.77ns1 IN A192.168.1.77
  • Configure a reverse zone file for example.local under /var/named/1.168.192.in-addr.arpa.zone
; Reverse Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; PTR record77 IN PTRns1.example.local.
  • Change the file ownership of example.local.zone and 1.168.192.in-addr.arpa.zone to named
chown :named /var/named/example.local.zone
chown :named /var/named/1.168.192.in-addr.arpa.zone
  • Start and Enable BIND
sudo systemctl start named
sudo systemctl enable named
  • Configure Firewall
sudo firewall-cmd --add-service=dns --permanent
sudo firewall-cmd --reload
  • Configure DHCP to Provide DNS Server Address /etc/dhcp/dhcpd.config
option domain-search "example.local";
option domain-name-servers 192.168.1.77;
  • Restart DHCP server sudo systemctl restart dhcpd named

  • Reboot Client machine reboot

  • Verify DNS server nslookup example.local or dig example.local

Perform PXE boot using TFTP server

To allow DHCP clients to boot and load an operating system over the network, typically used in scenarios like mass network installations or diskless workstations.

  • Configure TFTP server under /etc/xinetd.d/tftp
service tftp
{
socket_type = dgram
protocol = udp
wait = yes
user = root
server = /usr/sbin/in.tftpd
server_args = -s /var/lib/tftpboot
disable = no
per_source = 11
cps = 100 2
}
#disable = no - Indicates that the service is enabled and will respond to requests
#per_source - maximum number of concurrent transfers allowed per source IP address
#cps - connections per second with a burst value of 2
  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
next-server 192.168.1.10; # IP address of the TFTP server (using same server machine IP)
filename "pxelinux.0"; # Bootloader filename
}
  • We are gonna use nginx server as web server to host
  • Configure the Nginx server under /etc/nginx/conf.d/pxe_alma.conf
server{
listen 80;
server_name crop.com;
root /usr/share/html/alma9;
}
  • Allow incoming connections to these services in the firewall

firewall-cmd --add-service=dhcp --permanent
firewall-cmd --add-service=tftp --permanent
firewall-cmd --add-service=xinetd --permanent
firewall-cmd --add-service=nginx --permanent
firewall-cmd --reload
  • Temporarily disable SELinux to permissive mode
setenforce 0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Server Client Lab

Gurugautham Anandakumar edited this page Jun 3, 2024 · 20 revisions

Create two VMs (Server, Client) in Vmware Workstation Pro both belong to the same Subnet

  • Create the virtual machines, I opted CENTOS/RHEL AlmaLinux OS 9.3 Minimal ISO and configured the settings as needed (CPU, RAM, disk size).
  • Install packages in server machine: dhcp-server for DHCP, bind and bind-utils for DNS, tftp for TFTP, nginx for webserver, syslinux for boot-loader and wget for alma linux iso download.

Network Segmentation

  • Configure the network adapter to use "Custom: Specific virtual network", I selected Custom(VMnet2).
  • Uncheck the DHCP and host adapter box in VMware Network Settings for VMnet0 under Edit > Virtual Network Editor.
  • Configure static IP addresses manually.
    • Server: IP address: 192.168.1.10/24, Default gateway: 192.168.1.1
    • Client: IP address: 192.168.1.20/24, Default gateway: 192.168.1.1
  • Ensure that both virtual machines can ping each other to verify connectivity within the same subnet.

Create a DHCP Server

To automatically assign IP addresses and other network configuration information to devices that connect to our network.

  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
}
  • Start DHCP server
sudo systemctl start dhcpd
sudo systemctl enable dhcpd
  • Configure Firewall
sudo firewall-cmd --add-service=dhcp --permanent
sudo firewall-cmd --reload
  • Test DHCP server, boot the client machine and configure its network adapter to use DHCP.
sudo nmtui
### Under edit a connection, change IPv4 configuration to Automatic
sudo systemctl restart NetworkManager
### IP should be under specified dhcp range
ip a

Create a DNS Nameserver

To allow DHCP clients to resolve the domain name to IP addresses. Since our internal network is not connected to the internet, DNS resolution is limited to the domains and resources hosted within our internal network.

The internal DNS server will respond to DNS queries for domain names within its authoritative zones (configured in its BIND zone files). If client sends a DNS query for a domain outside of the internal network (e.g., google.com), it will typically result in a timeout or a response indicating that the domain could not be resolved.


  • Configure the BIND server to define the DNS zones under /etc/named.conf
  • I chose example.local for this lab, you can try anything.anything or kanye.west
/*Forward zone*/
zone "example.local" IN {
type master;
file "/var/named/example.local.zone";
};
/*Reverse zone*/
zone "1.168.192.in-addr.arpa" IN {
type master;
file "/var/named/1.168.192.in-addr.arpa.zone";
};
  • ARPA stands for Advanced Research Projects Agency

  • IN means INTERNET

  • Configure a forward zone file for example.local under /var/named/example.local.zone

; Forward Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; A record@IN A192.168.1.77ns1 IN A192.168.1.77
  • Configure a reverse zone file for example.local under /var/named/1.168.192.in-addr.arpa.zone
; Reverse Zone Configuration$TTL 1d ; Default TTL (1 day)@IN SOAns1.example.local. admin.example.local.( 3 ; Serial 1h ; Refresh (1 hour) 1h ; Retry 3w ; Expire (3 weeks) 1h ); Negative Cache TTL/; NS record@IN NSns1.example.local.; PTR record77 IN PTRns1.example.local.
  • Change the file ownership of example.local.zone and 1.168.192.in-addr.arpa.zone to named
chown :named /var/named/example.local.zone
chown :named /var/named/1.168.192.in-addr.arpa.zone
  • Start and Enable BIND
sudo systemctl start named
sudo systemctl enable named
  • Configure Firewall
sudo firewall-cmd --add-service=dns --permanent
sudo firewall-cmd --reload
  • Configure DHCP to Provide DNS Server Address /etc/dhcp/dhcpd.config
option domain-search "example.local";
option domain-name-servers 192.168.1.77;
  • Restart DHCP server sudo systemctl restart dhcpd named

  • Reboot Client machine reboot

  • Verify DNS server nslookup example.local or dig example.local

Perform PXE boot using TFTP server

To allow DHCP clients to boot and load an operating system over the network, typically used in scenarios like mass network installations or diskless workstations.

  • Configure TFTP server under /etc/xinetd.d/tftp
service tftp
{
socket_type = dgram
protocol = udp
wait = yes
user = root
server = /usr/sbin/in.tftpd
server_args = -s /var/lib/tftpboot
disable = no
per_source = 11
cps = 100 2
}
#disable = no - Indicates that the service is enabled and will respond to requests
#per_source - maximum number of concurrent transfers allowed per source IP address
#cps - connections per second with a burst value of 2
  • Configure the server under /etc/dhcp/dhcpd.config
subnet 192.168.1.0 netmask 255.255.255.0 {
option routers 192.168.1.254;
option subnet-mask 255.255.255.0;
option domain-search "corp.com";
option domain-name-servers 192.168.1.1;
option time-offset 19800;
option broadcast-address 192.168.1.255;
range 192.168.1.2 192.168.1.100;
max-lease-time 7200;
next-server 192.168.1.10; # IP address of the TFTP server (using same server machine IP)
filename "pxelinux.0"; # Bootloader filename
}
  • We are gonna use nginx server as web server to host
  • Configure the Nginx server under /etc/nginx/conf.d/pxe_alma.conf
server{
listen 80;
server_name crop.com;
root /usr/share/html/alma9;
}
  • Allow incoming connections to these services in the firewall

firewall-cmd --add-service=dhcp --permanent
firewall-cmd --add-service=tftp --permanent
firewall-cmd --add-service=xinetd --permanent
firewall-cmd --add-service=nginx --permanent
firewall-cmd --reload
  • Temporarily disable SELinux to permissive mode
setenforce 0