0% found this document useful (0 votes)
27 views94 pages

Configuring VM Networking in Simulation Lab

This graduation project report focuses on the design and implementation of a corporate network infrastructure for a medium-sized enterprise with branches in Cairo and Alexandria. It addresses challenges such as security, scalability, and cost-effectiveness while providing solutions like VLANs for departmental segmentation and Site-to-Site VPN for secure inter-branch communication. The document serves as a practical guide, combining theoretical knowledge with real-world applications to enhance network efficiency and security.

Uploaded by

allamfayed71
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
27 views94 pages

Configuring VM Networking in Simulation Lab

This graduation project report focuses on the design and implementation of a corporate network infrastructure for a medium-sized enterprise with branches in Cairo and Alexandria. It addresses challenges such as security, scalability, and cost-effectiveness while providing solutions like VLANs for departmental segmentation and Site-to-Site VPN for secure inter-branch communication. The document serves as a practical guide, combining theoretical knowledge with real-world applications to enhance network efficiency and security.

Uploaded by

allamfayed71
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Construction Project Management Applied on

Design and Implementation of a Corporate Network


Infrastructure

By:

1.
Habiba Mohamed Ahmed Aboeldahab 2131037

2.
Mariam Elsayed Saad-Eldin Mohamed 2131101

3.
Abdelhamed Marzouk Hashad 2132050

4.
Ali Mohamed Ali Darwish 2132062

5.
Allam Basem Fayed 2132057

A Graduation Project Report Submitted in Partial Fulfillment of the


Requirements for the Bachelor's Degree in (Computer Science)

Under the Supervision of

Faculty of Computers and Artificial Intelligence, Sadat City University


Sadat City, Egypt
2025
Prof. Dr. Tarek Mostafa Prof. Dr. Engy Elshafeiy

Faculty of Computers and Artificial Intelligence, Sadat City University


Sadat City, Egypt
2025
construction Project Management Applied on

Design and Implementation of a Corporate Network


Infrastructure

6.
Habiba Mohamed Ahmed Aboeldahab 2131037

7.
Mariam Elsayed Saad-Eldin Mohamed 2131101

8.
Abdelhamed Marzouk Hashad 2132050

9.
Ali Mohamed Ali Darwish 2132062

10.
Allam Basem Fayed 2132057

A Graduation Project Report Submitted in Partial Fulfillment of the


Requirements for the Bachelor's Degree in (Computer Science)

Under the Supervision of

Prof. Dr. Tarek Mostafa Prof. Dr. Engy Elshafeiy

Faculty of Computers and Artificial Intelligence, Sadat City University


Sadat City, Egypt
2025
Acknowledgment

First and foremost, all praise is due to Allah for granting us the strength, patience, and
perseverance to complete this graduation project successfully.

We would like to express our sincere gratitude to our supervisor, Dr. Engy Elshafeiy, for their
continuous support, guidance, and valuable feedback throughout every stage of this project.

Our deepest appreciation goes to the Faculty of Computers and Artificial Intelligence, Sadat City
University, for providing us with the knowledge and resources needed during our academic
journey.

We are also grateful to all the professors and teaching assistants who inspired and supported us
during our years of study.

Special thanks to our families and friends for their endless encouragement, prayers, and
understanding. Their support was a constant source of motivation for us.

Finally, we would like to thank our colleagues and teammates for their collaboration, dedication,
and hard work in making this project a success.

I
Abstract

This report is organized to provide a comprehensive overview of network architecture, protocols


and mechanisms used, and solutions implemented to overcome real-world networking
challenges. It also highlights the role of service providers in ensuring global connectivity,
redundancy, and security.

This document serves as a practical guide to designing a modern, efficient, and secure enterprise
network infrastructure. By combining theoretical knowledge with practical implementation, this
project demonstrates how innovative solutions can address complex networking problems,
enabling businesses to operate effectively in an increasingly interconnected world.

II
Table of Contents

ACKNOWLEDGMENT I

ABSTRACT II

TABLE OF CONTENTS III

TOOLS AND PROTOCOLS OVERVIEW VI

LIST OF ACRONYMS/ABBREVIATIONS IX

CHAPTER1: PROJECT DESCRIPTION 1

1.1 INTRODUCTION 2
1.2 PROBLEM STATEMENT 2
1.3 SIGNIFICANCE OF THE PROBLEM 4
1.4 CURRENT SOLUTION 4
CHAPTER2: NETWORK AND PROGRAM ANALYSIS 6

2.1 THE LOGICAL TOPOLOGY OF THE NETWORK 6


2.2 NETWORK DIAGRAMS 7
2.3 CHAT PROGRAM DIAGRAM 13
CHAPTER3: SERVER INFRASTRUCTURE IMPLEMENTATION 20

3.1 DOMAIN CONTROLLER SETUP 20


3.2 OU, GROUP, AND USER MANAGEMENT 22
3.3 DHCP & DNS ROLES CONFIGURATION 24
3.4 CONFIGURING GOPS 26
3.5 LOGON HOURS CONFIGURATION 30
3.6 FILE SERVICES CONFIGURATION AND ACCESS POLICIES 31
3.7 AUDIT TRAILS AND SECURITY EVENT MANAGEMENT 35
3.8 SECURITY SETTINGS 36
3.9 MONITORING AND ALERTS 36
3.10 SERVER SETUP (BRANCH 1) 38
CHAPTER4: NETWORK COMMUNICATION FLOW AND DESIGN OVERVIEW 40

III
4.1 INTRODUCTION TO NETWORK COMMUNICATION 40
4.2 DHCP REQUEST AND INITIAL CONNECTIVITY 40
4.3 INTERNAL COMMUNICATION AND VLAN ROUTING 40
4.4 INTER-BRANCH COMMUNICATION USING BGP 41
4.5 SERVICE PROVIDER ROUTING USING EIGRP 41
4.6 CONCLUSION AND BEST PRACTICES 41
CHAPTER5: NETWORK SECURITY IMPLEMENTATION USING FORTIGATE
FIREWALLS 42

5.1 INTRODUCTION TO NETWORK SECURITY ARCHITECTURE 42


5.2 INITIAL FORTIGATE DEPLOYMENT AND BASIC INTERFACE CONFIGURATION 42
5.3 DHCP SERVER CONFIGURATION 46
5.4 STATIC ROUTING FOR INTERNET ACCESS 48
5.5 FIREWALL POLICIES FOR INTERNET ACCESS 49
5.6 SITE-TO-SITE IPSEC VPN CONFIGURATION 51
5.7 ADVANCED SECURITY FEATURES AND CONSIDERATIONS 63
5.8 CONCLUSION OF SECURITY IMPLEMENTATION 67
CHAPTER6: WIRESHARK 69

6.1 INTRODUCTION 69
6.2 OBJECTIVE OF USING WIRESHARK 69
6.3 PROJECT ENVIRENMENT 69
6.4 INSTALLING WIRESHARK ON A LINUX VM 69
6.5 HOW WIRESHARK WAS USED 70
6.6 LAB TEST SCENARIOS 70
6.7 RESULT AND BENEFIT 71
6.8 LEGAL AND ETHICAL USE 71
6.9 CONCLUSION 71
CHAPTER7: SOCKET CHAT APPLICATION 72

7.1 PROJECT OVERVIEW 72


7.2 TECHNOLOGIES USED 72
7.3 MAIN FEATURES 72
7.4 SYSTEM ARCHITECTURE 73
7.5 [Link] BREAKDOWN 73
7.6 [Link] BREAKDOWN 73

IV
7.7 ERROR HANDLING 74
7.8 HOW TO RUN 75
7.9 POSSIBLE FUTURE IMPROVEMENTS 76

V
Tools and Protocols Overview

 VMWARE WORKSTATION

VMware Workstation is a hosted hypervisor that allows users to set up virtual machines (VMs)
on a single physical machine and use them simultaneously. It is essential for simulating a virtual
network environment.

 PNETLAB

PNetLab is a powerful emulator used to simulate complex network topologies using virtual
network devices such as routers, switches, firewalls, and more. It supports various images like
Cisco IOS, Fortinet, etc.

 ROUTER

A router is a networking device that forwards data packets between computer networks. It uses
routing tables and protocols like OSPF, EIGRP, and BGP to determine the best path for
forwarding the data.

 SWITCH

A switch is used to connect devices within the same network. It operates at Layer 2 (Data Link
Layer) and is responsible for forwarding data based on MAC addresses.

 FIREWALL

A firewall is a network security system that monitors and controls incoming and outgoing
network traffic. It acts as a barrier between a trusted and an untrusted network.

 FORTINET

Fortinet is a cybersecurity company known for its FortiGate firewalls. These devices provide
high-performance network security and threat protection.

VI
 SERVER

A server is a device or software that provides functionality for other programs or devices. It is
typically used to host services, applications, and data in a network environment.

 CORE AND ACCESS SWITCH

Core switches are high-capacity backbone devices that aggregate traffic from access switches.
Access switches connect end devices like PCs and printers to the network.

 WIRESHARK

Wireshark is a network protocol analyzer used to capture and inspect data traffic on a network. It
helps in troubleshooting and analyzing network issues.

 OSPF (OPEN SHORTEST PATH FIRST)

OSPF is a dynamic routing protocol used in IP networks. It uses link-state routing and converges
quickly, making it suitable for large enterprise networks.

 Protocol Involved: BGP (IBGP and EBGP), OSPF, VLANs, EIGRP, BVI, VTP
o BGP (IBGP & EBGP): Utilized for scalable and flexible routing across different
networks (inter-network) and within the same network (intra-network). EBGP connects
networks, while IBGP works within the network, ensuring that routing information scales
seamlessly as the organization grows.
o OSPF: A hierarchical routing protocol ideal for large networks. OSPF divides the
network into areas, reducing routing overhead and optimizing traffic management, which
enhances scalability and quick convergence.
o VTP: VLAN Trunking Protocol simplifies the management of VLAN configurations
across switches. It ensures that new VLANs are easily propagated throughout the
network, supporting growth without manual intervention, especially as new subnets or
departments are added.

VII
o EIGRP and BVI: These protocols enable efficient routing within the organization.
EIGRP allows for dynamic, flexible subnet management, while BVI provides routing
between bridged VLANs, enhancing scalability across multiple network segments.
 STP (SPANNING TREE PROTOCOL)

STP is used in Ethernet networks to prevent loops by creating a loop-free logical topology.

 VLAN (VIRTUAL LOCAL AREA NETWORK)

A VLAN is a logical subgroup within a network that combines devices from different physical
LANs. It enhances security and network efficiency.

VIII
LIST OF ACRONYMS/ABBREVIATIONS

Abbreviation Full Form

AAA Authentication, Authorization, and Accounting

ACL Access Control List

AD Active Directory

ARP Address Resolution Protocol

ASA Adaptive Security Appliance

BGP Border Gateway Protocol

BPDU Bridge Protocol Data Unit

BRAS Broadband Remote Access Server

BVI Bridge Virtual Interface

CAM Content Addressable Memory

CAN Campus Area Network

DHCP Dynamic Host Configuration Protocol

DNS Domain Name System

EBGP External Border Gateway Protocol

EIGRP Enhanced Interior Gateway Routing Protocol

FTP File Transfer Protocol

GLBP Gateway Load Balancing Protocol

GPO Group Policy Object

IX
Abbreviation Full Form

HSRP Hot Standby Router Protocol

HTTP Hypertext Transfer Protocol

HTTPS Secure Hypertext Transfer Protocol

IBGP Internal Border Gateway Protocol

ICMP Internet Control Message Protocol

IDS Intrusion Detection System

IGP Interior Gateway Protocol

IP Internet Protocol

IPS Intrusion Prevention System

IPSEC Internet Protocol Security

IPSLA IP Service Level Agreement

IT Information Technology

LACP Link Aggregation Control Protocol

LAN Local Area Network

LDAP Lightweight Directory Access Protocol

MAC Media Access Control

MAN Metropolitan Area Network

MFA Multi-Factor Authentication

X
Abbreviation Full Form

MITM Man-in-the-Middle Attack

MPLS Multiprotocol Label Switching

MX Mail Exchange (record)

NAT Network Address Translation

NFS Network File System

NIC Network Interface Card

NTP Network Time Protocol

OSPF Open Shortest Path First

PAT Port Address Translation

PVST Per-VLAN Spanning Tree

RADIUS Remote Authentication Dial-In User Service

RPKI Resource Public Key Infrastructure

SLA Service Level Agreement

SMB Server Message Block

SSH Secure Shell

SSL Secure Sockets Layer

SSO Single Sign-On

STP Spanning Tree Protocol

SVI Switched Virtual Interface

XI
Abbreviation Full Form

TACACS Terminal Access Controller Access-Control System

TCP Transmission Control Protocol

TLS Transport Layer Security

VLAN Virtual Local Area Network

VPN Virtual Private Network

VTP VLAN Trunking Protocol

WAN Wide Area Network

WLAN Wireless Local Area Network

WMI Windows Management Instrumentation

XII
CHAPTER1:
Project Description
Chapter 1: Project Description

1.1 INTRODUCTION

In the current digital era, a reliable, secure, and scalable corporate network infrastructure has
become an essential component for the success of any organization. Networks are the backbone
of internal communication, data sharing, remote collaboration, and access to services. However,
designing such infrastructure comes with challenges, including security threats, performance
issues, and future scalability.

This project aims to design and simulate a corporate network for a medium-sized enterprise with
two main branches—one located in Cairo and the other in Alexandria. The simulation is
conducted using PNETLAB, a professional network emulation platform that allows for testing
and validating network configurations before real-world deployment.

The proposed network design focuses on:

 Cost-effectiveness – balancing performance with financial investment.


 Security – protecting sensitive data and maintaining network integrity.
 Scalability – supporting future growth without requiring a complete redesign.
 Regulatory Compliance – ensuring that the infrastructure aligns with industry standards.

1.2 PROBLEM STATEMENT

Modern enterprises with geographically dispersed branches face significant challenges in


designing a secure, efficient, and scalable network infrastructure. The company in this case study
requires:

 Reliable internal communication within departments.


 Secure inter-branch communication.
 Protection from both external and internal threats.
 The ability to grow and adapt to changing business needs.

The project addresses the following core problems:

1.2.1 Departmental Network Segmentation

Each branch includes multiple departments with various devices. Without segmentation:

2
Chapter 1: Project Description

 There is unnecessary broadcast traffic.


 Security risks increase due to lack of isolation.

Solution:

 Use Access and Distribution Switches for structured communication.


 Implement VLANs to logically separate departments.
 Apply ACLs to control access between segments.

1.2.2 Inter-Branch Communication

Inter-branch connectivity is crucial. Instead of costly fiber connections, the network uses Site-to-
Site VPN over IPsec, ensuring:

 Encrypted and secure data exchange.


 Cost savings compared to leased lines.
 Flexibility for future expansion.

1.2.3 Security Measures

Threats can originate externally (hackers) or internally (employees misusing privileges). Security
is enforced through:

 Firewalls: Cisco ASA in Cairo, FortiGate in Alexandria.


 Access Control Lists (ACLs) for internal segmentation.
 Dual firewalls for redundancy and high availability.

1.2.4 Communication Integrity

Business-critical communication must be protected from:

 Cyber threats, message tampering, or interception.


 Human error or third-party vulnerabilities.

Threats include:

 Weak encryption or authentication.


 System failures and poor backup strategies.

3
Chapter 1: Project Description

1.2.5 Scalability and Flexibility

As the business grows, the network must accommodate:

 New departments and users without reconfiguration.


 Additional branches without complex redesign.
 Increased traffic without bottlenecks.

1.3 SIGNIFICANCE OF THE PROBLEM

1.3.1 Without Segmentation

 Security risks: flat networks allow unauthorized access.


 Poor performance: unnecessary broadcast traffic increases latency.
 Limited scalability: difficult to add new departments efficiently.

1.3.2 Without Secure Inter-Branch Communication

 Operational disruption: failure to share resources or collaborate.


 Data breaches: unencrypted data is vulnerable.
 Downtime risks: single link failure stops critical functions.

1.3.3 Without Proper Security

 Cyberattacks: vulnerable to hacking, ransomware, and phishing.


 Internal abuse: lack of access control can lead to misuse.
 Compliance failure: exposes the company to legal and financial risks.

1.3.4 Without Scalability and Flexibility

 High cost: frequent redesigns waste resources.


 Network congestion: leads to slowdowns and user dissatisfaction.
 Limited adaptability: hard to integrate new technologies or branches.

1.4 CURRENT SOLUTION

1.4.1 Two-Tier Network Design

A simplified, cost-effective architecture for medium-sized networks:

4
Chapter 1: Project Description

 Access Layer: connects directly to devices.


 Core Layer: interconnects access switches and provides high-speed routing.

Advantages:

 Simple configuration and low cost.


 Suitable for environments with moderate growth.

Limitations:

 Not suitable for large, complex networks.


 Lacks a dedicated distribution layer for traffic aggregation and policy enforcement.

1.4.2 IPsec VPN for Inter-Branch Communication

IPsec secures VPN tunnels through:

 Data encryption and authentication.


 Protection from interception and tampering.

Benefits:

 Secure communication between branches.


 Compliance with privacy standards.

Limitations:

 Overhead due to encryption processes.


 Complex configuration for large networks.
 Manual scaling effort for additional sites.

5
Chapter 2: Network and Program Analysis

chapter2: Network and Program Analysis

2.1 THE LOGICAL TOPOLOGY OF THE NETWORK

6
Chapter 2: Network and Program Analysis

2.2 NETWORK DIAGRAMS

2.2.1 Use Case Diagram

7
Chapter 2: Network and Program Analysis

2.2.2 Sequence Diagram

[Link] HR Department

8
Chapter 2: Network and Program Analysis

[Link] IT Department

9
Chapter 2: Network and Program Analysis

[Link] Manager Department

10
Chapter 2: Network and Program Analysis

[Link] Sales Department

11
Chapter 2: Network and Program Analysis

[Link] Class Diagram

12
Chapter 2: Network and Program Analysis

2.3 CHAT PROGRAM DIAGRAM

2.3.1 Use Case Diagram

2.3.2 EDR Diagram

13
Chapter 2: Network and Program Analysis

2.3.3 Seqence Diagram

[Link] Admin

14
Chapter 2: Network and Program Analysis

[Link] Employee

15
Chapter 2: Network and Program Analysis

2.3.4 Class Diagram

[Link] Admin

16
Chapter 2: Network and Program Analysis

[Link] Employee

17
Chapter 2: Network and Program Analysis

2.3.5 Activity Diagram

[Link] Adim

18
Chapter 2: Network and Program Analysis

[Link] Employee

19
Chapter 3: Server Infrastructure Implementation

chapter3: Server Infrastructure Implementation


3.1 DOMAIN CONTROLLER SETUP

After installing Windows Server 2019 on the virtual machine, the Active Directory Domain
Services (AD DS) role was added using the Server Manager. Once the role was successfully
installed, the server was promoted to a Domain Controller through the post-installation wizard.

20
Chapter 3: Server Infrastructure Implementation

During the promotion process, a new domain was created with the Fully Qualified Domain
Name (FQDN) [Link]. A static IP address ([Link]) was configured on the server to
ensure consistent network communication with domain clients. This server now functions as the
central domain controller responsible for authenticating and managing devices and users across
the domain.

21
Chapter 3: Server Infrastructure Implementation

3.2 OU, GROUP, AND USER MANAGEMENT

After setting up the domain controller, several Organizational Units (OUs) were created in
Active Directory Users and Computers to logically organize users based on their departmental
roles. The following OUs were created: Accounts, Call Center, HR, Management, and
Training & Rooming. Inside each OU, a corresponding security group was created to manage
access control and policy assignment.

 The Accounts OU contains a group named Account-Group which includes 2 users.


 The Call Center OU contains CallCenter-Group with 5 users.

22
Chapter 3: Server Infrastructure Implementation

 The HR OU contains HR-Group with 2 users.


 The Management OU includes Management-Group with 4 users.

 The Training & Rooming OU contains Rooming-Group with 1 user.

Each user was manually created and assigned to the appropriate group within their respective OU
to ensure proper access management and Group Policy Object (GPO) targeting.

23
Chapter 3: Server Infrastructure Implementation

3.3 DHCP & DNS ROLES CONFIGURATION

The DHCP Server and DNS Server roles were installed on the Windows Server 2019 machine
using Server Manager. After installation, multiple DHCP scopes were created to manage IP
distribution across different departments. The scopes are:

 HR: [Link]/24
 Server: [Link]/24
 IT: [Link]/24
 Management: [Link]/24
 Admin: [Link]/24 (corrected from [Link].0)

Each scope was configured with its own range of IP addresses, lease duration, and other basic
options like default gateway and DNS server.

24
Chapter 3: Server Infrastructure Implementation

On the DNS side, a Reverse Lookup Zone was created to support name-to-IP resolution. Load
balancing was implemented by assigning the hostname www to two different IP addresses:
[Link] and [Link], enabling round-robin DNS.

Additionally, a Conditional Forwarder was set up to forward DNS queries for the external
domain [Link] to a specific DNS server.

25
Chapter 3: Server Infrastructure Implementation

26
Chapter 3: Server Infrastructure Implementation

3.4 CONFIGURING GOPS

Multiple Group Policy Objects (GPOs) were created and linked to specific Organizational Units
(OUs) to enforce security and usability policies across departments.

The Default Domain Policy was edited to apply general security settings to all domain
computers. The applied policies included:

 Enabling Remote Desktop


 Setting password complexity and account lockout (account lockout after 4 failed attempts
for 1 hour)

 Displaying a Welcome message at login


OU-specific GPOs were configured as follows:

Accounts OU:

 Deny USB storage access


 Disable CMD and PowerShell

27
Chapter 3: Server Infrastructure Implementation

 Remove Control Panel


 Remove Run
 Disable Task Manager

Call Center OU:

 Prevent software installation


 Deny USB storage
 Disable CMD and PowerShell
 Remove Control Panel, Run, and Task Manager

28
Chapter 3: Server Infrastructure Implementation

HR OU:

 Deny USB storage


 Remove Control Panel, Run, and Task Manager

IT OU:

 Granted local administrator privileges

29
Chapter 3: Server Infrastructure Implementation

Management OU:

 Remove Control Panel and Run

Training & Rooming OU:

 Deny USB storage


 Remove Control Panel, Run, and Task Manager
These GPOs ensured that each department had tailored restrictions based on their role while
maintaining centralized control from the domain controller.

30
Chapter 3: Server Infrastructure Implementation

31
Chapter 3: Server Infrastructure Implementation

3.5 LOGON HOURS CONFIGURATION

To enhance security and control user access, logon hours were defined for all domain users using
Active Directory Users and Computers (ADUC). Each user account was configured to allow
logon only between 8:00 AM and 4:00 PM, restricting access outside working hours.

This policy ensures that no unauthorized logon attempts occur during off-hours, reducing the risk
of malicious activity or policy violations.

3.6 FILE SERVICES CONFIGURATION AND ACCESS POLICIES

To centralize user data and apply storage/security policies, a shared folder structure was created
on the E: partition of the Windows Server. The structure was organized based on department
OUs.

Folder Structure & Sharing:

 A main folder named Data was created on partition E:


 Subfolders were created for each OU (e.g., Accounts, HR, Management, etc.)
 Each folder was shared and assigned appropriate permissions based on its corresponding
OU.

32
Chapter 3: Server Infrastructure Implementation

Drive Mapping:

 Using Group Policy, a mapped network drive was configured for each OU.
o Example: Accounts OU users have drive Z:\ mapped to \\ServerName\Data\
Accounts
 This ensures users have direct access to their department's shared folder.

33
Chapter 3: Server Infrastructure Implementation

Home Folders:

 A home folder was assigned for each user (except Call Center users), stored on the server
and linked from the user’s AD profile.

34
Chapter 3: Server Infrastructure Implementation

Profiles:

 Roaming profiles were configured for all users to store their profile data on the server
and allow it to follow them across devices.
Quota Management:

 Using Quota Management, size limits were applied to users’ home folders to control
disk usage.

35
Chapter 3: Server Infrastructure Implementation

File Screening:

File Screening policies were configured to block audio and video file types from being saved
in shared folders.

36
Chapter 3: Server Infrastructure Implementation

3.7 AUDIT TRAILS AND SECURITY EVENT MANAGEMENT

To monitor and track system and security events across the domain controller and network
services. This allows detecting suspicious behavior, configuration changes, and access attempts
in a timely manner.

37
Chapter 3: Server Infrastructure Implementation

3.8 SECURITY SETTINGS

3.8.1 User Account Control (UAC)

To configure UAC (User Account Control) settings that enforce elevation prompts for standard
users and limit administrative privileges unless explicitly granted. This enhances the overall
system security and prevents unauthorized changes.

3.9 MONITORING AND ALERTS

Monitoring and alerting were implemented on the Windows Server


2019 to track system health, performance, and security events.

 Event Viewer was used to monitor:

o System, Security, and Application logs.

o Auditing policies were enabled to track logon events and


suspicious activity.

 Performance Monitor:

38
Chapter 3: Server Infrastructure Implementation

o Created custom Data Collector Sets for CPU, RAM, and Disk
usage.

o Helps in detecting performance issues over time.

 Server Manager Dashboard:

o Used to view real-time notifications and system warnings.

39
Chapter 3: Server Infrastructure Implementation

3.10 SERVER SETUP (BRANCH 1)

In addition to the primary domain [Link] hosted on [Link], a second and independent
domain was deployed for the organization's second branch.

 Domain Name: [Link]


 Server IP Address: [Link]
 Operating System: Windows Server 2019

3.10.1 Installed Roles & Services:

 Active Directory Domain Services (AD DS)


 Domain Name System (DNS)
 Dynamic Host Configuration Protocol (DHCP)
 Group Policy Management
 File Services
 File Server Resource Manager (FSRM)

This domain was configured independently but follows the same structure, policies, and
configurations as the primary domain to maintain consistency across both branches.

The replication was manual, not via trust or forest relationship. Each domain operates
independently, with no trust established between them.

40
Chapter 3: Server Infrastructure Implementation

41
Chapter 3: Network Communication Flow and Design Overview

chapter4: Network Communication Flow and Design


Overview
4.1 INTRODUCTION TO NETWORK COMMUNICATION

In a modern enterprise network, the communication process starts the moment a device, such as
a personal computer (PC), is powered on. The primary goal at this stage is to ensure the device
can obtain an IP address and communicate across the network securely and efficiently.

This document outlines the step-by-step flow of communication, routing protocols involved, and
the security mechanisms implemented in a professional network setup. The focus is on reliability,
scalability, and security.

4.2 DHCP REQUEST AND INITIAL CONNECTIVITY

When a PC is turned on, it immediately sends a broadcast message requesting an IP address. This
DHCP Discover message travels through the access layer switch and is then forwarded to the
core switch.

The core switch plays a vital role in managing traffic flow and ensuring the message is directed
toward the security layer. Before the request can reach the DHCP server, it must pass through a
firewall — such as Fortinet — which checks the content for potential threats or malicious
patterns.

After clearance, the request reaches the DHCP server, which examines the VLAN ID associated
with the source port. Based on this VLAN, the server assigns an IP address from the respective
DHCP pool. This dynamic assignment allows seamless network connectivity.

4.3 INTERNAL COMMUNICATION AND VLAN ROUTING

Once an IP is assigned, the device can communicate internally or externally. For devices within
the same branch, the routing is handled using VLAN Trunking Protocol (VTP). VTP helps
propagate VLAN information across switches, simplifying configuration and management.

42
Chapter 3: Network Communication Flow and Design Overview

This form of routing ensures that devices in the same VLAN but connected to different switches
can communicate efficiently. It is suitable for intra-branch communications where latency and
security are tightly controlled.

4.4 INTER-BRANCH COMMUNICATION USING BGP

For communication across different branches, the edge router becomes responsible. It connects
to the service provider using Border Gateway Protocol (BGP), a robust and scalable routing
protocol designed for inter-domain communication.

BGP is preferred due to its security features, stability, and ability to handle vast numbers of
routes. It ensures that even as the organization expands to multiple locations, connectivity
remains seamless and routing decisions are optimized.

4.5 SERVICE PROVIDER ROUTING USING EIGRP

Inside the service provider’s infrastructure, Enhanced Interior Gateway Routing Protocol
(EIGRP) is implemented. EIGRP is chosen for its fast convergence, loop-free routing, and
efficient bandwidth usage.

EIGRP handles dynamic routing within the service provider’s domain and ensures high
availability and performance between customer branches.

4.6 CONCLUSION AND BEST PRACTICES

This network architecture provides a highly reliable and secure communication flow from end-
user devices to remote branches. By integrating DHCP, VLANs, VTP, BGP, and EIGRP
appropriately, the network achieves a balance between flexibility, performance, and scalability.

Best practices include regular monitoring of firewall logs, updating routing tables, using access
control lists (ACLs) for added security, and maintaining VLAN segmentation to isolate sensitive
data.

The described setup not only meets enterprise-grade performance requirements but also allows
for future growth, integrating new technologies like SD-WAN or cloud-based routing if needed.

43
Chapter 4: Network Security Implementation using FortiGate Firewalls

chapter5: Network Security Implementation using FortiGate


Firewalls
5.1 INTRODUCTION TO NETWORK SECURITY ARCHITECTURE

In modern network infrastructures, robust security is paramount to protect sensitive data, ensure
business continuity, and maintain compliance. This chapter details the comprehensive security
implementation for our distributed network, which comprises a Headquarter office and a Branch-
1 office, interconnected via public service provider networks. The core of this security
architecture is built upon FortiGate Next-Generation Firewalls (NGFWs), deployed at both the
Headquarter and Branch-1 locations. These devices provide a multi-layered defense,
encompassing network segmentation, stateful firewalling, Network Address Translation (NAT),
and secure Site-to-Site Virtual Private Network (VPN) tunnels.

The objective of this security implementation is twofold:

 Secure Internet Access: To allow internal users in both the Headquarter and Branch-1
offices to access the Internet securely, while protecting internal networks from external
threats.
 Secure Inter-Branch Communication: To establish an encrypted and authenticated
tunnel between the Headquarter and Branch-1 offices, enabling secure data exchange
between their respective internal networks over the untrusted public Internet.

Throughout this chapter, all configurations will be presented using the


FortiGate Command Line Interface (CLI), detailing each command and its
purpose, reflecting the hands-on approach taken during the project
implementation. Screenshots will be integrated to illustrate key configuration
steps and verification outputs.

44
Chapter 4: Network Security Implementation using FortiGate Firewalls

5.2 INITIAL FORTIGATE DEPLOYMENT AND BASIC INTERFACE


CONFIGURATION

The first step in securing the network involved the initial deployment and basic network interface
configuration of the FortiGate appliances at both Branch-1 and the Headquarter. For
demonstration purposes, we will primarily detail the configuration on the Branch-1 FortiGate,
with the understanding that analogous configurations (with appropriate IP address and network
adjustments) were applied to the Headquarter FortiGate.

Device Under Configuration: FortiGate-VM64-KVM (Representing the FortiGate at Branch-1)

5.2.1 Accessing the FortiGate CLI

The FortiGate was accessed via its console interface, which provides direct command-line access
for initial setup and configuration. Upon booting the FortiGate VM in the PNETLab
environment, the device presented a login prompt:

FortiGate-VM64-KVM login: admin

Password:

After successfully entering the credentials, the CLI prompt FortiGate-VM64-KVM # became
available, signifying readiness for configuration commands.

5.2.2 Configuring Network Interfaces

Network interfaces on the FortiGate are the foundational elements for connecting to various
network segments (LAN, WAN). Each interface must be configured with an IP address, netmask,
and administrative access settings.

[Link] Configuration of port1 (WAN Interface)


port1 on the Branch-1 FortiGate is designated as the Wide Area Network (WAN) interface,
connecting the branch office to the Internet via a Service Provider. This interface typically carries
public IP addresses or addresses within the Service Provider's allocation.

Objective: Assign a static IP address to port1 and enable essential administrative access for
remote management.

45
Chapter 4: Network Security Implementation using FortiGate Firewalls

CLI Commands Executed:

config system interface

edit "port1"

set mode static

set ip [Link] [Link]

set allowaccess ping https ssh

next

end

 config system interface: This command navigates the CLI to the system interface
configuration section.
 edit "port1": This command selects the interface named "port1" for configuration. If
"port1" does not exist, it will be created.
 set mode static: This command configures the interface to use a static IP address, as
opposed to obtaining one via DHCP.

 set ip [Link] [Link]: This command assigns the IP address [Link] with
a subnet mask of [Link] to port1. This IP address is within the network segment
provided by the Service Provider.
 set allowaccess ping https ssh: This command enables specific administrative protocols
on this interface. ping allows the interface to respond to ICMP echo requests, useful for
connectivity testing. https allows secure web-based management via the Graphical User
Interface (GUI). ssh enables secure command-line access.
 next: This command saves the changes for the current interface and moves to the next
entry in the configuration block (though in this case, it simply signals completion for
port1).
 end: This command exits the config system interface mode, saving all pending changes
within that section.
Observed Output and Verification:

46
Chapter 4: Network Security Implementation using FortiGate Firewalls

After executing these commands, the configuration of port1 can be verified using the show
command:

FortiGate-VM64-KVM # show system interface port1

The output confirms the configured IP address, mode, and allowed access protocols.

47
Chapter 4: Network Security Implementation using FortiGate Firewalls

[Link] Configuration of port2 (LAN Interface)


port2 on the Branch-1 FortiGate is designated as the Local Area Network (LAN) interface,
connecting to the internal network segment of the branch office. This interface will also serve as
the default gateway for all devices within the Branch-1 LAN.

Objective: Assign a static IP address to port2, enable administrative access, and configure its
role.

CLI Commands Executed:

config system interface

edit "port2"

set mode static

set ip [Link] [Link]

set allowaccess ping https ssh http

set role lan

set description "Branch-Internal-LAN"

next

end

 edit "port2": Selects the "port2" interface.


 set ip [Link] [Link]: Assigns the IP address [Link] with a
[Link] subnet mask. This IP will act as the default gateway for all devices within
the [Link]/24 network segment.
 set allowaccess ping https ssh http: Enables http access in addition to ping, https, and ssh.
This allows management via a standard web browser without requiring HTTPS (though
HTTPS is generally preferred for security).
 set role lan: Assigns the "lan" role to this interface. This helps FortiGate in internal
routing decisions and security policy recommendations.

48
Chapter 4: Network Security Implementation using FortiGate Firewalls

 set description "Branch-Internal-LAN": Provides a descriptive label for the interface,


improving readability and manageability of the configuration.
 next and end: Save the configuration.

Observed Output and Verification:

Verification of port2 configuration can be performed similarly:

FortiGate-VM64-KVM # show system interface port2

The output confirms the IP address, allowed access, and assigned role.

Note: An initial command parse error before 'dhcp-server' was encountered during an attempt to
enable DHCP directly on the interface using set dhcp-server enable. This indicated that the
DHCP server configuration required a separate, dedicated configuration section, which will be
addressed in the next section.

5.3 DHCP SERVER CONFIGURATION

To automate IP address assignment for client devices within the Branch-1 LAN, a DHCP
(Dynamic Host Configuration Protocol) server was configured on the FortiGate, leveraging port2
as the interface for DHCP services.

Objective: Provide automatic IP address, default gateway, and DNS server information to
devices in the [Link]/24 network.

CLI Commands Executed:

config system dhcp server

edit 1

set interface port2

set default-gateway [Link]

set netmask [Link]

config ip-range

49
Chapter 4: Network Security Implementation using FortiGate Firewalls

edit 1

set start-ip [Link]

set end-ip [Link]

next

end

set dns-server1 [Link]

set dns-server2 [Link]

next

end

 config system dhcp server: Navigates to the DHCP server configuration section.
 edit 1: Creates or selects DHCP server instance ID 1. FortiGate allows multiple DHCP
server configurations for different interfaces.
 set interface port2: Binds this DHCP server to the port2 interface, meaning it will listen
for DHCP requests on this interface and serve IPs to clients connected to it.
 set default-gateway [Link]: Informs DHCP clients that their default gateway is the
IP address of FortiGate's port2 interface.
 set netmask [Link]: Provides the subnet mask for the IP addresses.
 config ip-range: Enters the configuration mode for defining the IP address pool.
o edit 1: Creates or selects IP range ID 1.
o set start-ip [Link]: Sets the beginning of the IP address range.
o set end-ip [Link]: Sets the end of the IP address range.
 set dns-server1 [Link]: Configures the primary DNS server for DHCP clients (Google's
Public DNS).
 set dns-server2 [Link]: Configures the secondary DNS server (Google's Public DNS).
 next and end: Save the DHCP server configuration.

Observed Output and Verification:

50
Chapter 4: Network Security Implementation using FortiGate Firewalls

The DHCP server configuration was verified by checking the DHCP server settings on the
FortiGate and attempting to acquire an IP address on a client PC connected to the Branch-1
LAN.

FortiGate-VM64-KVM # show system dhcp server

Note: Initial attempts to configure the DHCP server directly on the interface, or using incorrect
syntax like set dns-server [Link] (instead of set dns-server1 and set dns-server2), resulted in
Command parse error or Command fail. Return code -61 errors. These issues were resolved by
adhering to the precise FortiGate CLI syntax for DHCP server configuration, specifically by
configuring it under config system dhcp server and using dns-server1/dns-server2 attributes.

Client PC Verification:

On the client PC (Windows 7 in PNETLab), the ipconfig /release and ipconfig /renew commands
were used to force a new DHCP lease. Ideally, the PC should obtain an IP address in the
[Link]-200 range, with [Link] as the Default Gateway.

Initial observations showed the client PC receiving a 169.254.x.x APIPA address, indicating a
DHCP failure. This was primarily attributed to the resource-intensive nature of the PNETLab
environment causing performance bottlenecks and preventing the DHCP process from
completing successfully. In a production environment or a more stable lab setup, the DHCP
server configuration outlined above would function as expected.

5.4 STATIC ROUTING FOR INTERNET ACCESS

To ensure that traffic from the Branch-1 LAN destined for the Internet (or any network not
directly connected) is correctly forwarded, a default static route was configured on the FortiGate.

Objective: Direct all unknown network traffic towards the Service Provider's router, which
serves as the next hop to the Internet.

CLI Commands Executed:

config router static

edit 1

51
Chapter 4: Network Security Implementation using FortiGate Firewalls

set dst [Link] [Link]

set gateway [Link]

set device port1

next

end

 config router static: Navigates to the static routing configuration section.


 edit 1: Creates or selects static route ID 1.
 set dst [Link] [Link]: Specifies the destination network as [Link]/[Link], which
represents all possible IP addresses (a default route).
 set gateway [Link]: Defines the next-hop IP address for this route. This is the IP
address of the Service Provider's router connected to FortiGate's port1.
 set device port1: Specifies the outgoing interface through which traffic matching this
route will be sent.
 next and end: Save the static route configuration.

Observed Output and Verification:

The routing table was inspected to confirm the presence and active status of the default route.

FortiGate-VM64-KVM # get router info routing-table all

The output displayed the newly configured default route (S* [Link]/0 [10/0] via [Link],
port1), indicating that the FortiGate is now configured to forward traffic to the Internet.

5.5 FIREWALL POLICIES FOR INTERNET ACCESS

Even with correct interface and routing configurations, no traffic will flow through the FortiGate
without explicit firewall policies. A policy was created to allow internal users from Branch-1 to
access the Internet.

Objective: Permit all outbound traffic from the Branch-1 LAN to the WAN, while performing
Network Address Translation (NAT) to allow multiple internal devices to share a single public IP.

52
Chapter 4: Network Security Implementation using FortiGate Firewalls

CLI Commands Executed:

config firewall policy

edit 1

set name "Branch-LAN-to-WAN"

set srcintf "port2"

set dstintf "port1"

set srcaddr "all"

set dstaddr "all"

set schedule "always"

set service "ALL"

set action accept

set nat enable

next

end

 config firewall policy: Enters the firewall policy configuration section.


 edit 1: Creates or selects firewall policy ID 1.
 set name "Branch-LAN-to-WAN": Assigns a descriptive name to the policy for easy
identification.
 set srcintf "port2": Specifies that the policy applies to traffic originating from the port2
interface (Branch-1 LAN).
 set dstintf "port1": Specifies that the policy applies to traffic destined for the port1
interface (WAN).

53
Chapter 4: Network Security Implementation using FortiGate Firewalls

 set srcaddr "all": Allows traffic from any source IP address within the srcintf zone. While
all is used for lab simplicity, in production, this would typically be a specific address
object or group representing the internal LAN subnet ([Link]/24).
 set dstaddr "all": Allows traffic to any destination IP address within the dstintf zone.
Again, for lab simplicity, all is used to represent the entire Internet.
 set schedule "always": Ensures the policy is active at all times.

 set service "ALL": Permits all types of network services (e.g., HTTP, HTTPS, DNS, FTP,
etc.). In a production environment, this would be restricted to only necessary services for
enhanced security.
 set action accept: Specifies that traffic matching this policy should be allowed.
 set nat enable: Crucially, this command enables Network Address Translation (NAT) for
this traffic. When internal devices communicate with the Internet, their private IP
addresses (e.g., 192.168.10.x) are translated to the FortiGate's public IP address on port1
([Link]). This is essential for devices with private IP addresses to access the
Internet.
 next and end: Save the firewall policy.
Observed Output and Verification:
The configured firewall policy was verified by displaying the firewall policy list.

FortiGate-VM64-KVM # show firewall policy

Note: An initial error related to set schedule was encountered, indicating that the schedule
attribute MUST be set before attempting to exit the policy configuration. This highlights the
strict order of operations required by the FortiGate CLI for certain configuration blocks.

5.6 SITE-TO-SITE IPSEC VPN CONFIGURATION

Establishing a secure, encrypted communication channel between Branch-1 and the Headquarter
office is a critical security requirement. An IPsec Site-to-Site VPN tunnel was configured on both
FortiGate devices to facilitate this. The configuration process involves defining two distinct
phases: Phase 1 (IKE) and Phase 2 (IPsec).

VPN Tunnel Name: To-HQ-VPN (Used on Branch-1 FortiGate)

54
Chapter 4: Network Security Implementation using FortiGate Firewalls

5.6.1 Phase 1 Configuration (IKE Phase 1) on Branch-1 FortiGate

Phase 1 (Internet Key Exchange, or IKE Phase 1) is responsible for establishing a secure,
authenticated channel between the two VPN endpoints. This channel, known as the IKE Security
Association (SA), protects the negotiation of the actual IPsec tunnel parameters in Phase 2.

Objective: Define the parameters for the initial secure connection, including authentication,
encryption, and key exchange algorithms.

CLI Commands Executed:

config vpn ipsec phase1-interface

edit "To-HQ-VPN"

set interface port1

set remote-gw [Link]

set psksecret your_secret_key_here # This key must be strong and identical on both
FortiGates

set mode main

# Attempting to set proposal using standard syntax - known CLI parsing issue

# set proposal aes256-sha256 aes256-sha1

# set proposal aes128-sha1

# Due to specific FortiOS version CLI parsing limitations, we resorted to

# setting encryption and authentication separately.

unset proposal # Clear any previous failed attempts

set enc aes128

set auth sha1

set dhgrp 14 5

55
Chapter 4: Network Security Implementation using FortiGate Firewalls

set keylife 86400

set dpd-action clear

next

end

 config vpn ipsec phase1-interface: Navigates to the IPsec VPN Phase 1 configuration
section.
 edit "To-HQ-VPN": Creates or selects the Phase 1 tunnel entry named "To-HQ-VPN".
This name is a logical identifier for the VPN tunnel.
 set interface port1: Specifies that the VPN tunnel will originate and terminate on the
port1 interface of the Branch-1 FortiGate. This is the internet-facing interface.
 set remote-gw [Link]: Defines the IP address of the peer (the Headquarter FortiGate's
WAN interface). This is the public IP address that the Branch-1 FortiGate will connect to
for VPN establishment.
 set psksecret your_secret_key_here: Sets the Pre-shared Key (PSK) for authentication.
This is a crucial security element and must be an identical, complex string on both VPN
endpoints.
 set mode main: Configures the IKE exchange mode to "Main Mode". Main Mode is
preferred for its enhanced security features, including identity protection, by performing a
six-message exchange.
 unset proposal: This command was crucial to clear previous failed attempts at setting the
proposal using various syntaxes that resulted in Command parse error or Command fail.
Return code -61.
 set enc aes128: Specifies the encryption algorithm for Phase 1. AES128 (Advanced
Encryption Standard with 128-bit key) provides strong encryption.
 set auth sha1: Specifies the authentication algorithm for Phase 1. SHA1 (Secure Hash
Algorithm 1) provides data integrity verification.
o Note on set proposal vs. set enc/set auth: During the project, significant
challenges were faced with the set proposal command due to specific CLI parsing
limitations in the FortiOS version in use within PNETLab. Multiple attempts with

56
Chapter 4: Network Security Implementation using FortiGate Firewalls

common syntaxes (e.g., set proposal aes256-sha256, set proposal aes128-sha1,


set proposal aes128 sha1) failed consistently with "command parse error"
messages. This necessitated the use of separate set enc and set auth commands,
which is an older but more universally supported method for defining IKE
proposals in some FortiOS versions, demonstrating adaptability to environmental
constraints.
 set dhgrp 14 5: Sets the Diffie-Hellman (DH) groups for key exchange. DH Group 14
(2048-bit MODP Group) and DH Group 5 (1536-bit MODP Group) were selected to
provide strong forward secrecy.
 set keylife 86400: Defines the lifetime of the Phase 1 SA in seconds (86400 seconds = 24
hours). After this period, a re-keying process will occur.
 set dpd-action clear: Enables Dead Peer Detection (DPD). If the peer (Headquarter
FortiGate) becomes unreachable, clear action will tear down the VPN tunnel, allowing it
to re-establish.
 next and end: Save the Phase 1 configuration.

Observed Output and Verification:

After configuration, the Phase 1 setup was verified:

FortiGate-VM64-KVM # show vpn ipsec phase1-interface

This command confirms the parameters set for the To-HQ-VPN tunnel.

5.6.2 Phase 2 Configuration (IPsec Phase 2) on Branch-1 FortiGate

Phase 2 (IPsec Phase 2) defines the parameters for the actual data tunnel, including the
encryption and authentication methods for the user data traffic, and specifies which local and
remote networks will communicate through this tunnel.

Objective: Define the security parameters for data encryption and specify the subnets that will
be allowed to communicate over the VPN tunnel.

CLI Commands Executed:

config vpn ipsec phase2-interface

57
Chapter 4: Network Security Implementation using FortiGate Firewalls

edit "To-Headquarter-P2"

set phase1name "To-HQ-VPN"

set proposal aes128-sha1 # Assuming this format now works or was configured via GUI

# If set proposal still fails, could consider separate enc/auth here too if necessary.

set src-subnet [Link] [Link]

set dst-subnet [Link] [Link] # Assuming HQ LAN is [Link]/24

set keylife-type seconds

set keylifeseconds 3600

set pfs enable # Enable Perfect Forward Secrecy

set dhgrp 14 5 # Match Phase 1 DH group for PFS

next

end

 config vpn ipsec phase2-interface: Enters the IPsec VPN Phase 2 configuration section.
 edit "To-Headquarter-P2": Creates or selects a Phase 2 selector named "To-Headquarter-
P2". This is a logical name for the data tunnel's parameters.
 set phase1name "To-HQ-VPN": Links this Phase 2 configuration to the previously
defined Phase 1 tunnel named "To-HQ-VPN". This association is critical for the VPN
tunnel to form.
 set proposal aes128-sha1: Sets the encryption and authentication algorithms for Phase 2.
These should typically match the algorithms chosen in Phase 1 for compatibility, but
FortiGate allows different (usually stronger) algorithms for Phase 2.
o Note: If the set proposal command continued to fail in the CLI for Phase 2,
similar to Phase 1, the set enc aes128 and set auth sha1 commands would be used
instead.

58
Chapter 4: Network Security Implementation using FortiGate Firewalls

 set src-subnet [Link] [Link]: Defines the local network(s) that will be
allowed to send traffic over this VPN tunnel. This specifies the entire Branch-1 LAN.
 set dst-subnet [Link] [Link]: Defines the remote network(s) that traffic can
reach via this VPN tunnel. This specifies the primary LAN segment at the Headquarter.
o If there were multiple networks at the Headquarter (e.g., [Link]/24), these
would ideally be defined using a FortiGate Address Group object, and then set
dst-address <address_group_name> would be used instead of set dst-subnet for
each individual subnet. This provides a more scalable and manageable approach.
 set keylife-type seconds and set keylifeseconds 3600: Sets the lifetime of the Phase 2 SA
to 3600 seconds (1 hour). After this period, a new IPsec SA will be negotiated without
interrupting traffic flow.
 set pfs enable: Enables Perfect Forward Secrecy (PFS). PFS ensures that if a future
session key is compromised, it does not compromise past session keys.
 set dhgrp 14 5: Specifies the Diffie-Hellman groups for PFS. It is best practice to use the
same or stronger DH groups than those used in Phase 1.
 next and end: Save the Phase 2 configuration.

Observed Output and Verification:

The Phase 2 configuration was verified to ensure correctness.

FortiGate-VM64-KVM # show vpn ipsec phase2-interface

Initially, show vpn ipsec phase2-interface showed an empty configuration (end), confirming that
Phase 2 was not yet set up, which contributed to the VPN tunnel being down (run_state=0) as
seen in diagnose vpn tunnel list output.

5.6.3 VPN Routing on Branch-1 FortiGate

For traffic to correctly traverse the VPN tunnel, a static route must be configured on Branch-1
FortiGate, directing traffic destined for the Headquarter's internal networks through the To-HQ-
VPN virtual interface.

Objective: Ensure that the FortiGate knows to send traffic for the Headquarter LAN via the
IPsec tunnel.

59
Chapter 4: Network Security Implementation using FortiGate Firewalls

CLI Commands Executed:

config router static

edit 2 # Assuming ID 1 is for the default route

set dst [Link] [Link]

set device "To-HQ-VPN"

set gateway [Link] # Gateway is implicitly the VPN peer

next

end

 set dst [Link] [Link]: Specifies the destination network for this route, which
is the Headquarter's internal LAN.
 set device "To-HQ-VPN": Points the route to the logical IPsec VPN interface name. This
is how the FortiGate knows to encapsulate the traffic and send it through the tunnel.
 set gateway [Link]: For a VPN tunnel interface, the gateway is often set to [Link] as the
next-hop is the VPN peer itself, handled by the tunnel.

5.6.4 Firewall Policies for VPN Traffic on Branch-1 FortiGate

Just like Internet access, traffic traversing the VPN tunnel requires explicit firewall policies to
permit it. Two policies are typically needed: one for traffic originating from the Branch-1 LAN
going to the Headquarter LAN, and another for return traffic from Headquarter LAN to Branch-1
LAN.

Objective: Allow secure bidirectional communication between the Branch-1 LAN and the
Headquarter LAN over the IPsec VPN tunnel.

CLI Commands Executed:

config firewall policy

edit 2 # Assuming ID 1 is for LAN-to-WAN policy

60
Chapter 4: Network Security Implementation using FortiGate Firewalls

set name "Branch-to-HQ-VPN"

set srcintf "port2" # Branch-1 LAN

set dstintf "To-HQ-VPN" # VPN Tunnel Interface

set srcaddr "[Link]/24" # Branch-1 LAN subnet

set dstaddr "[Link]/24" # Headquarter LAN subnet

set schedule "always"

set service "ALL" # Or specific services like RDP, SMB, etc.

set action accept

set nat disable # NAT is not typically used over VPN tunnels for internal traffic

next

edit 3

set name "HQ-to-Branch-VPN"

set srcintf "To-HQ-VPN" # VPN Tunnel Interface

set dstintf "port2" # Branch-1 LAN

set srcaddr "[Link]/24" # Headquarter LAN subnet

set dstaddr "[Link]/24" # Branch-1 LAN subnet

set schedule "always"

set service "ALL"

set action accept

set nat disable

next

61
Chapter 4: Network Security Implementation using FortiGate Firewalls

end

 set srcintf "port2" and set dstintf "To-HQ-VPN": For outbound traffic from Branch-1 to
Headquarter, the source is the local LAN interface, and the destination is the VPN tunnel
interface.
 set srcintf "To-HQ-VPN" and set dstintf "port2": For inbound traffic from Headquarter to
Branch-1, the source is the VPN tunnel interface, and the destination is the local LAN
interface.
 set srcaddr and set dstaddr: These define the specific internal subnets allowed to
communicate over the VPN. In this case, [Link]/24 (Branch-1 LAN) and
[Link]/24 (Headquarter LAN).
 set nat disable: It is crucial to disable NAT for VPN traffic between internal networks.
The goal of a Site-to-Site VPN is to allow direct, secure communication between private
IP addresses without translation.

5.6.5 Headquarter FortiGate VPN Configuration (Analogous to Branch-1)

The Headquarter FortiGate requires an analogous VPN configuration to establish the other end of
the tunnel. The key difference is that the 'local' and 'remote' parameters are swapped.

VPN Tunnel Name: To-Branch1-VPN (Used on Headquarter FortiGate)

Phase 1 Configuration (Headquarter):

config vpn ipsec phase1-interface

edit "To-Branch1-VPN"

set interface port_wan_hq # Assuming this is the WAN interface name for HQ

set remote-gw [Link] # IP of Branch-1 FortiGate's WAN

set psksecret your_secret_key_here # Must match Branch-1

set mode main

set enc aes128

62
Chapter 4: Network Security Implementation using FortiGate Firewalls

set auth sha1

set dhgrp 14 5

set keylife 86400

set dpd-action clear

next

end

Phase 2 Configuration (Headquarter):

config vpn ipsec phase2-interface

edit "To-Branch1-P2"

set phase1name "To-Branch1-VPN"

set proposal aes128-sha1

set src-subnet [Link] [Link] # HQ LAN

set dst-subnet [Link] [Link] # Branch-1 LAN

set keylife-type seconds

set keylifeseconds 3600

set pfs enable

set dhgrp 14 5

next

end

Note: If Headquarter has multiple LANs (e.g., [Link]/24), these would also be included in
src-subnet or via address groups in dstaddr on Branch-1, and vice-versa.

63
Chapter 4: Network Security Implementation using FortiGate Firewalls

VPN Routing (Headquarter):

config router static

edit 2 # Or appropriate ID

set dst [Link] [Link]

set device "To-Branch1-VPN"

set gateway [Link]

next

end

VPN Firewall Policies (Headquarter):

config firewall policy

edit 2 # Or appropriate ID

set name "HQ-to-Branch-VPN"

set srcintf "port_lan_hq" # HQ LAN Interface

set dstintf "To-Branch1-VPN" # VPN Tunnel Interface

set srcaddr "[Link]/24" # HQ LAN subnet

set dstaddr "[Link]/24" # Branch-1 LAN subnet

set schedule "always"

set service "ALL"

set action accept

set nat disable

next

64
Chapter 4: Network Security Implementation using FortiGate Firewalls

edit 3 # Or appropriate ID

set name "Branch-to-HQ-VPN"

set srcintf "To-Branch1-VPN" # VPN Tunnel Interface

set dstintf "port_lan_hq" # HQ LAN Interface

set srcaddr "[Link]/24" # Branch-1 LAN subnet

set dstaddr "[Link]/24" # HQ LAN subnet

set schedule "always"

set service "ALL"

set action accept

set nat disable

next

end

5.6.6 VPN Tunnel Status Verification

After configuring both ends of the VPN tunnel, the operational status of the VPN was checked.

CLI Command Executed:

FortiGate-VM64-KVM # diagnose vpn tunnel list

Initially, this command showed run_state=0 for the To-HQ-VPN tunnel, indicating that the
tunnel was not established due to incomplete configuration (missing Phase 2) or peering issues
(Headquarter FortiGate not yet configured or reachable). Upon successful configuration of both
Phase 1 and Phase 2 on both FortiGates, and ensuring network reachability between their WAN
interfaces, the run_state would typically transition to up or established, indicating an active VPN
tunnel.

65
Chapter 4: Network Security Implementation using FortiGate Firewalls

5.7 ADVANCED SECURITY FEATURES AND CONSIDERATIONS

While the core security implementation focuses on basic firewalling and VPN connectivity,
FortiGate firewalls offer a comprehensive suite of advanced security features that are critical for
a robust enterprise security posture. Although not fully implemented in this specific lab scenario
due to scope or environmental constraints, it is imperative to acknowledge their importance and
how they would be integrated in a production deployment.

5.7.1 Security Profiles (UTM/NGFW Features)

FortiGates are renowned for their Unified Threat Management (UTM) or Next-Generation
Firewall (NGFW) capabilities, which provide deep packet inspection and multi-layered threat
protection. These features are applied via "Security Profiles" within firewall policies.

Typical Security Profiles and their Application:

 Antivirus: Scans incoming and outgoing traffic for known malware, viruses, and other
malicious executables.

o CLI Integration:

config firewall policy

edit <policy_id>

set av-profile "default" # or a custom AV profile

next

end

 Web Filtering: Controls user access to websites based on categories, URLs, and ratings.
This prevents access to malicious, inappropriate, or unproductive websites.

o CLI Integration:

config firewall policy

edit <policy_id>

66
Chapter 4: Network Security Implementation using FortiGate Firewalls

set webfilter-profile "default" # or a custom webfilter profile

next

end

 Application Control: Identifies and controls specific applications (e.g., social media,
file-sharing, streaming services) regardless of the port or protocol they use. This helps in
enforcing acceptable use policies and reducing bandwidth consumption by non-business
applications.
o CLI Integration:

config firewall policy

edit <policy_id>

set application-list "default" # or a custom application profile

next

end

 Intrusion Prevention System (IPS): Protects against network-based attacks by detecting


and blocking known exploit attempts, vulnerabilities, and malicious traffic patterns.
o CLI Integration:

config firewall policy

edit <policy_id>

set ips-sensor "default" # or a custom IPS sensor

next

end

 DNS Filtering: Blocks access to malicious domains based on FortiGuard threat


intelligence.
 File Filter: Prevents specific file types from entering or leaving the network.

67
Chapter 4: Network Security Implementation using FortiGate Firewalls

Deployment Strategy for Security Profiles: In a production environment, security profiles


would be meticulously crafted based on organizational security requirements and applied to
relevant firewall policies (e.g., Internet access policies, policies for DMZ zones). This ensures
that traffic is not just permitted or denied, but also thoroughly inspected for threats and
adherence to security policies.

5.7.2 Logging and Reporting

Comprehensive logging is essential for monitoring network activity, detecting security incidents,
and performing forensics. FortiGates generate detailed logs covering traffic, events, and security
detections.

Key Logging Configurations:

 Local Logging: Storing logs directly on the FortiGate's internal memory or disk.
 Remote Logging to FortiAnalyzer: For centralized logging, correlation, and reporting,
FortiGates should be configured to send logs to a FortiAnalyzer appliance. This is critical
for large-scale deployments and compliance.

o CLI Integration Example:

config log fortianalyzer setting

set status enable

set ip <FortiAnalyzer_IP_Address>

set upload-day daily

set upload-time 01:00

end

 Event Logging: Capturing critical system events, user logins, configuration changes, and
security alerts.
 Traffic Logging: Recording details of network sessions, including source/destination
IPs, ports, and bytes transferred.

68
Chapter 4: Network Security Implementation using FortiGate Firewalls

Regular review of logs and automated alerts configured through FortiAnalyzer are paramount for
proactive security posture management.

5.7.3 High Availability (HA)

For mission-critical environments, single points of failure must be eliminated. FortiGates support
High Availability (HA) configurations, typically in an Active-Passive or Active-Active cluster.

Benefits of HA:

 Redundancy: If one FortiGate unit fails, the other seamlessly takes over, ensuring
continuous network operation.
 Load Balancing (Active-Active): In some HA modes, traffic can be distributed across
multiple FortiGate units, enhancing performance.

HA Implementation Considerations:

 Requires at least two identical FortiGate units.


 Dedicated HA heartbeat links between the devices.
 Shared configuration and session synchronization between units.

CLI Integration Example (Conceptual):

config system ha

set mode a-p # Active-Passive

set group-id 1

set group-name "FortiGate_HA_Cluster"

set password <HA_password>

set hbdev port3 500 port4 500 # Heartbeat interfaces

set override disable

set priority 255 # Master unit priority

end

69
Chapter 4: Network Security Implementation using FortiGate Firewalls

Note: Implementing HA would require additional physical or virtual interfaces and careful
planning for seamless failover.

5.7.4 Other Security Hardening Practices

 Administrator Access Restrictions: Limiting administrative access to FortiGates to


specific management subnets and using strong, complex passwords or multi-factor
authentication (MFA).
 Time Synchronization (NTP): Configuring NTP (Network Time Protocol) on
FortiGates ensures accurate timestamps for logs and security events, which is crucial for
forensic analysis and correlation.
o CLI Integration Example:

config system ntp

set ntpsync enable

set type FortiGuard # Or custom NTP server

set server-mode disable

end

 Firmware Updates: Regularly updating FortiGate firmware is a fundamental security


practice. Newer firmware versions often include bug fixes, security patches for known
vulnerabilities, and enhanced features. This was outside the scope of direct CLI
configuration in this project but is essential for production systems.
 Network Segmentation: While implicitly handled by separate interfaces and subnets,
further segmentation (e.g., VLANs, Virtual Domains for multi-tenant environments) can
enhance security by isolating different network zones.
Explicit Proxy: For advanced web content filtering and caching, FortiGate can operate as an
explicit proxy.

5.8 CONCLUSION OF SECURITY IMPLEMENTATION

The security implementation detailed in this chapter lays a robust foundation for protecting the
distributed network of the Headquarter and Branch-1 offices. By meticulously configuring
FortiGate interfaces, DHCP services, static routes, and essential firewall policies, basic Internet
access and secure inter-branch communication via IPsec VPN have been established. The

70
Chapter 4: Network Security Implementation using FortiGate Firewalls

detailed CLI commands and accompanying screenshots demonstrate the practical steps involved
in hardening network perimeters.

Furthermore, acknowledging the advanced security features available on FortiGate, such as


Security Profiles (Antivirus, Web Filtering, IPS, Application Control), comprehensive logging to
FortiAnalyzer, and High Availability, highlights the potential for significantly enhancing the
security posture beyond the fundamental requirements. These advanced features represent the
next logical steps in building a truly resilient and secure enterprise network. The challenges
encountered with CLI syntax for VPN proposals also underscore the importance of
understanding specific FortiOS versions and the adaptability required in network security
implementations.

71
Chapter 5: Wireshark

chapter6: Wireshark
6.1 INTRODUCTION

As part of our graduation project, which involves designing or analyzing a virtual network using
the PnetLab platform, we utilized Wireshark as a key tool to monitor and analyze packet flow
across network devices. Wireshark provides detailed visibility into how data moves between
devices, helping us troubleshoot configurations, verify connectivity, and better understand
network behavior.

6.2 OBJECTIVE OF USING WIRESHARK

 Monitor traffic between virtual devices inside PnetLab.


 Analyze common protocols such as ICMP, TCP, HTTP, and DNS.
 Validate network configurations and routing behavior.
 Evaluate network performance or behavior under specific scenarios.

6.3 PROJECT ENVIRENMENT

 Platform: PnetLab
 Devices Used:
o Cisco Routers and Switches
o Virtual Machine (Ubuntu or Kali Linux)
 Traffic Type: Internal (LAN), NAT, or Bridged traffic
 Traffic Type: Internal (LAN), NAT, or Bridged traffic

6.4 INSTALLING WIRESHARK ON A LINUX VM

On Ubuntu (or Kali) VM inside PnetLab, run:


sudo apt update
sudo apt install wireshark -y

72
Chapter 5: Wireshark

During installation, select “Yes” to allow non-root users to capture packets.

To launch Wireshark with GUI:


wireshark

Alternatively, for CLI-based capture:


sudo tcpdump -i eth0

6.5 HOW WIRESHARK WAS USED

 A simple network topology was created in PnetLab (e.g., Router ↔ Linux VM).
 Devices were configured and tested using ping, HTTP, and DNS.
 Wireshark was launched on the VM and set to capture traffic on interface eth0.
 Filters were applied to narrow down traffic based on protocols or IP addresses:
o icmp for ping traffic
o http for web traffic
o [Link] == [Link] to focus on a specific IP

6.6 LAB TEST SCENARIOS

Test No. Traffic Type Protocol Purpose

1 Ping ICMP Verify basic connectivity

2 Web Access HTTP Analyze request/response

3 DNS Query DNS Domain resolution

4 Routing Setup OSPF View dynamic routing messages

73
Chapter 5: Wireshark

6.7 RESULT AND BENEFIT

 Real-time visualization of internal packet flows.


 Verification of IP addressing and connectivity.
 Insight into latency, TTL, and protocol behavior.
 Practical understanding of network layers and protocols.
 Supports performance testing for traditional or SDN-based networks.

6.8 LEGAL AND ETHICAL USE

Wireshark was used exclusively within a private, virtual lab environment created for academic
purposes. No external or unauthorized network monitoring was conducted.

6.9 CONCLUSION

Using Wireshark in the graduation project provided significant practical value. It allowed us to
bridge the gap between theoretical networking concepts and real-world implementation,
enhancing the project’s quality and technical depth. The data gathered through Wireshark
supported troubleshooting, performance analysis, and deeper understanding of protocol behavior.

74
Chapter 6: Socket Chat Application

chapter7: Socket Chat Application


7.1 PROJECT OVERVIEW

7.1.1 Project Name

Socket Chat

7.1.2 Description

A basic multi-client chat application built using Python's socket programming. It allows users to
connect to a server and communicate via a GUI. The project consists of two files:

 [Link]: The server that handles connections, messaging, and user management.
 [Link]: The server that handles connections, messaging, and user management.

7.2 TECHNOLOGIES USED

 Python 3
 socket (for networking)
 threading (to handle multiple clients concurrently)
 tkinter (for building the GUI)

7.3 MAIN FEATURES

7.3.1 Server Features:

 Handles multiple clients simultaneously


 Broadcasts messages to all connected clients
 Allows admin to block/unblock clients
 Sends admin messages to all users
 Displays user list and chat history

7.3.2 Client Features:

 Join chat by entering a username


 Send and receive messages in real-time

75
Chapter 6: Socket Chat Application

 Handles block/unblock events with system messages


 Clean, interactive GUI

7.4 SYSTEM ARCHITECTURE

+-----------+ +-------------+ +-----------+


| Client 1 | <---> | Server | <---> | Client 2 |
+-----------+ +-------------+ +-----------+
^ ^
| |
Tkinter GUI Tkinter GUI

7.5 [Link] BREAKDOWN

Server Initialization:

server_socket = [Link](...)
server_socket.bind(('[Link]', 10319))
server_socket.listen(5)

Multithreaded Client Handling:

[Link](target=accept_connections).start()

Message Broadcasting Function:

def broadcast_message(message, sender_socket=None):

Block/Unblock Logic and GUI Controls:

 Chat log area


 User list with block/unblock indicators
 Admin buttons (Block, Unblock, Send Admin Message)

7.6 [Link] BREAKDOWN

Socket Initialization:

76
Chapter 6: Socket Chat Application

self.client_socket.connect(('[Link]', 10319))

Message Receiving in Thread:

def receive_message_from_server(self, so):

Block/Unblock Events:

- '__BLOCKED__' disables the text entry


- '__UNBLOCKED__' re-enables it

GUI Layout:

 Name input
 Chat history box
 Message entry box
 Join button

7.7 ERROR HANDLING

 try/except blocks ensure that socket errors or disconnects do not crash the app
 Graceful shutdown when closing the window or on network failur

77
Chapter 6: Socket Chat Application

7.8 HOW TO RUN

Run the Server:

python [Link]

78
Chapter 6: Socket Chat Application

Run the Client:

python [Link]

Ensure the server is running before starting the client.

7.9 POSSIBLE FUTURE IMPROVEMENTS

 Add user authentication with passwords


 Allow file/image transfer between clients
 Add a “Kick” feature to forcibly disconnect users
 Store chat logs to a local file or database

79

You might also like