EDWARD JOHNSInfrastructure & security Download CV
← All projects

PROJECT / 01

Network Infrastructure
& Security Lab

From router-based connectivity to firewall-enforced segmentation and cross-platform security monitoring. A hands-on virtual environment built to explore how infrastructure and defensive security work together.

GNS3Cisco IOSvL2Cisco ASA 8.4UbuntuWindows 11Kali LinuxWazuh

THE OBJECTIVE

Build a realistic segmented network and explore controlled service access between internal hosts, a DMZ and external connectivity. Add logging and endpoint monitoring to make network behaviour observable. The lab has evolved beyond its original three-zone design; the current export includes an additional internal network and specific DMZ-to-monitoring exceptions.

WATCH THE LAB WALKTHROUGH

A 36-second tour of the GNS3 topology, Cisco ASA and switch configuration, Kali Linux, Windows 11 and Wazuh.

Silent video with on-screen explanations. The recording shows a later configuration, including Windows on 10.30.0.0/24, and a Wazuh snapshot with two disconnected agents and no active agents.
Download video · MP4

HOW THE LAB EVOLVED

01 / FOUNDATION

Routing & switching

Rebuilt the Layer 2/Layer 3 topology using Cisco IOSvL2 and a virtual router. Separated WAN and LAN domains, configured VLANs and access ports, and structured the uplink to R1. The router obtained its upstream address through DHCP and provided DHCP and NAT internally.

02 / VISIBILITY

Cross-platform monitoring

Deployed Wazuh on Ubuntu and enrolled Windows 11 and Kali Linux agents. Log and alert collection added endpoint visibility and created a platform for exploring file integrity monitoring, vulnerability detection and event correlation.

03 / SECURITY BOUNDARIES

Router to Cisco ASA

Progressed from the router to an ASA 8.4 firewall. Introduced Inside, DMZ and Outside zones, then an additional Inside30 network. Configured ACLs, outbound NAT, DHCP and syslog forwarding. The current configuration is documented below.

THE CURRENT ASA NETWORKS

01 / INSIDE

Internal & management network

192.168.10.0/24 · level 100

Includes the monitoring host at 192.168.10.12 and the ASA DHCP pool. The attached Inside ACL permits all IP traffic.

02 / DMZ

Isolated service network

192.168.20.0/24 · level 50

Permits TCP 1514 and 1515 to the Inside monitoring host while denying HTTPS to that host.

03 / INSIDE30

Additional internal network

10.30.0.0/24 · level 90

Permits TCP 1514, 1515 and HTTPS to the monitoring host. Windows 11 uses this network in the recording.

04 / OUTSIDE

External connectivity

DHCP uplink · level 0

The export includes outbound NAT and a default route. OUTSIDE-IN is defined but not attached.

THE DEPLOYED TOPOLOGY

GNS3 lab topology: Cloud connects to a central Cisco ASA. Metasploitable2 connects directly to the ASA; one switch connects Windows Server 2022 and Windows 11, and a second switch connects Wazuh and Kali Linux.
Updated GNS3 topology screenshot from the ASA stage, showing green link indicators. The supplied configuration documents the networks above; the screenshot does not label interface-to-zone assignments.

CISCO ASA CONFIGURATION

Selected extracts from my ASA 8.4(2) running configuration. Credentials have been removed from the downloadable export, and the upstream gateway has been replaced with a documentation address. Private lab addresses are retained.

Interfaces & security levels

The snapshot separates Outside (0), Inside (100), DMZ (50) and Inside30 (90). Outside obtains its address through DHCP.

interface GigabitEthernet0
 nameif outside
 security-level 0
 ip address dhcp
!
interface GigabitEthernet1
 nameif inside
 security-level 100
 ip address 192.168.10.1 255.255.255.0
!
interface GigabitEthernet2
 nameif dmz
 security-level 50
 ip address 192.168.20.1 255.255.255.0
!
interface GigabitEthernet3
 nameif inside30
 security-level 90
 ip address 10.30.0.1 255.255.255.0
!
DMZ access to the monitoring host

The attached DMZ ACL permits TCP 1514 and 1515 to 192.168.10.12 and explicitly denies HTTPS to that host. This is a deliberate exception to DMZ isolation.

access-list DMZ-IN extended permit tcp 192.168.20.0 255.255.255.0 host 192.168.10.12 eq 1514
access-list DMZ-IN extended permit tcp 192.168.20.0 255.255.255.0 host 192.168.10.12 eq 1515
access-list DMZ-IN extended deny tcp any host 192.168.10.12 eq https
access-group DMZ-IN in interface dmz
Inside30 access

Inside30 permits TCP 1514, 1515 and HTTPS to the monitoring host. Other new traffic is subject to the ACL’s implicit deny.

access-list INSIDE30-IN extended permit tcp 10.30.0.0 255.255.255.0 host 192.168.10.12 eq 1514
access-list INSIDE30-IN extended permit tcp 10.30.0.0 255.255.255.0 host 192.168.10.12 eq 1515
access-list INSIDE30-IN extended permit tcp 10.30.0.0 255.255.255.0 host 192.168.10.12 eq https
access-group INSIDE30-IN in interface inside30
Outbound NAT

Each internal network has dynamic interface NAT configured toward Outside. NAT rules alone do not establish that traffic is permitted by the attached ACLs.

object network MGMT-NET
 nat (inside,outside) dynamic interface
object network DMZ-NET
 nat (dmz,outside) dynamic interface
object network INSIDE30-NET
 nat (inside30,outside) dynamic interface
Syslog & DHCP

The ASA forwards informational syslog to the Inside host and provides an Inside DHCP pool. This export does not include logging buffered or explicit per-entry ACL log options.

logging enable
logging timestamp
logging trap informational
logging device-id hostname
logging host inside 192.168.10.12
dhcpd dns 8.8.8.8
dhcpd address 192.168.10.50-192.168.10.150 inside
dhcpd enable inside

Snapshot notes: INSIDE-OUT is attached inbound on Inside and permits all IP traffic. INSIDE-IN and OUTSIDE-IN are defined but not attached in this export. Configuration shows intended policy; runtime behaviour and complete event collection require test evidence.

Download sanitised ASA configuration · TXT

Reference: Cisco ACL logging documentation.

IMPLEMENTATION & VALIDATION

Firewall policy

Configured service-specific ACLs for DMZ and Inside30 access to the monitoring host, plus a broad Inside permit rule. Added outbound NAT for all three internal networks and informational syslog forwarding.

Network services

Used Layer 2 switching for VLAN segmentation and access port control. Moved routing and DHCP services to the ASA and assigned a static address to the DMZ host.

Boundary testing

Tested segmentation boundaries, validated firewall behaviour and analysed logged events while simulating internal access to DMZ-hosted services.

Endpoint visibility

Integrated Windows and Linux agents with the Ubuntu Wazuh server to collect endpoint logs, alerts and behavioural data alongside the network lab.

This case study describes my implementation and testing. The configuration export and walkthrough show the recorded setup; captured segmentation test results are not yet included.

WHAT I DEVELOPED

The progression reinforced network design, VLAN configuration, DHCP/NAT troubleshooting, firewall policy creation and cross-platform monitoring. Moving from basic connectivity to explicit security boundaries helped connect infrastructure operation with defensive security practice.

LET’S TALK INFRASTRUCTURE & SECURITY

Interested in the lab or my experience?

Get in Touch →