Lomba Keterampilan Siswa: Sekolah Menengah Kejuruan Tingkat Kabupaten Subang 2019
Lomba Keterampilan Siswa: Sekolah Menengah Kejuruan Tingkat Kabupaten Subang 2019
LINUX ISLAND
IT NETWORK SYSTEMS
ADMINISTRATION
LKSTKJSMKSBG_ITNSA_LINUX_ISLAND
2
INTRODUCTION
The competition has a fixed start and finish time. You must decide how to best divide your
time.
Please carefully read the following instructions!
When the competition time ends, please leave your station in a running state.
Version: 1.0
LKSTKJSMKSBG_ITNSA
Date: 08.04.2019
3
PART I
WORK TASK INSTALLATION (SUBANGSRV, MEDIACENTERSRV)
Note Please use the default configuration if you are not given details.
3. FTP (proftpd)
Enable FTPS
- Use a certificate signed by MEDIACENTERSRV
Each user (user21 to user30) will have a home directory.
Version: 1.0
LKSTKJSMKSBG_ITNSA
Date: 08.04.2019
4
Make sure the user is jailed in their respective website document root directories.
Make sure file transfer to the server is possible.
4. Mail
Make sure user11 to user20 have access via POP3, IMAP and SMTP
Before you finish your project make sure you send an email message from user14 to
user19 and another message from user19 to user14.
Do not delete these email messages.
6. SSH Server
Install SSH Server
Use RADIUS MEDIACENTERSRV to authentication users.
Change SSH port default to 1945
3. RADIUS (FreeRadius)
Create 5 users with password “Subang2019” for SSH login SUBANGSRV
o Username: user[31-35]. ex: user31, user32, …, user35
Use “Subang2019” as share key
Version: 1.0
LKSTKJSMKSBG_ITNSA
Date: 08.04.2019
5
4. DHCP
o Create DHCP Pool INTERNAL:
Range: 192.168.150.51 – 192.168.150.100
Netmask: /25
Gateway: 192.168.150.1
DNS: 172.23.199.3
o DNS-Suffix: skills4future.net
o SUBANGCLT should always receive the following IP: 192.168.150.88
o The clients should automatically register their name with the DNS server after they
have been assigned with an IP address by the DHCP server.
Version: 1.0
LKSTKJSMKSBG_ITNSA
Date: 08.04.2019
6
PART II
WORK TASK NETWORK CONFIGURATION (LKSTKJSBG)
Note Please use the default configuration if you are not given details.
2. DHCP Relay
Configure DHCP Relay to MEDIACENTERSRV for internal client
4. VPN Server
Configure VPN for access to SUBANGSRV and MEDIACENTERSRV. External clients
should
connect to 212.99.45.65
Use address range 10.20.0.1 to 10.20.0.10 and DNS SUBANGSRV for VPN clients
For login create a user “remote” with password “Subang2019”
5. Firewall
External network allows the ICMP packet to interface external LKSTKJSBG
External network can access to http://www.lkstkjsmksbg.net
External network can’t access to SUBANGSRV and MEDIACENTERSRV before the vpn
established.
Ensure the vpn client can’t access to internal client (SUBANGCLT) when the vpn
established.
(Can only access to SUBANGSRV and MEDIACENTERSRV)
Deny all other traffic from external to all internal network.
Version: 1.0
LKSTKJSMKSBG_ITNSA
Date: 08.04.2019
7
PART III
WORK TASK LINUX CLIENT (PEMDASBGCLT, DISDIKSBGCLT)
Note Please use the default configuration if you are not given details.
Version: 1.0
LKSTKJSMKSBG_ITNSA
Date: 08.04.2019
8
APPENDIX
SPECIFICATIONS
SUBANGSRV
Operating System Linux Debian 7.8
Computer name: SUBANGSRV
Root password Subang2019
User Name: nanas
User Password: Subang2019
eth0: 172.23.199.3/29
MEDIACENTERSRV
Operating System Linux Debian 7.8
Computer name: MEDIACENTERSRV
Root password Subang2019
User Name: nanas
User Password: Subang2019
IP address: 172.23.199.4/29
LKSTKJSBG
Operating System Linux Debian 7.8
Computer name: LKSTKJSBG
Root password Subang2019
User Name: nanas
User Password: Subang2019
eth0: 212.99.45.65/28
eth1: 172.23.199.1/29
eth2: 192.168.150.1/25
PEMDASBGCLT
Operating System Linux Debian 7.8 (GUI)
Computer name: PEMDASBGCLT
Root password Subang2019
User Name: nanas
User Password: Subang2019
IP address: 212.99.45.70/28
Version: 1.0
LKSTKJSMKSBG_ITNSA
Date: 08.04.2019
9
DISDIKSBGCLT
Operating System Linux Debian 7.8 (GUI)
Computer name: DISDIKSBGCLT
Root password Subang2019
User Name: nanas
User Password: Subang2019
IP address: DHCP
Version: 1.0
LKSTKJSMKSBG_ITNSA
Date: 08.04.2019
NETWORK SPESIFICATION
Name : MEDIACENTERSRV
OS : Debian 7.8 Name : LKSTKJSBG Pre-Install
OS : Debian 7.8
Name : DIDDIKSBGCLT (Internal)
IP-Address : OS : Debian 7.8 (GUI)
172.23.199.4/29 IP-Address :
Service: External : 212.99.45.65/28
Server : 172.23.199.1/29 IP-Address :
- Cacti DHCP From MEDIACENTERSRV
- FreeRadius Internal : 192.168.150.1/25
Service: Service:
- CA - IceDove
- DHCP Server Host Only - Routing
- DHCP Relay - Filezilla
- Reverse Proxy (nginx)
VMnet2 - DDNS
MEDIACENTERSRV - Firewall
- OpenVPN Server
DISDIKSBGCLT