diff --git a/sisr1/tp03-reseau-prive/srv-admin/cartes_reseau/interfaces b/sisr1/tp03-reseau-prive/srv-admin/cartes_reseau/interfaces
new file mode 100644
index 0000000..ab2e8af
--- /dev/null
+++ b/sisr1/tp03-reseau-prive/srv-admin/cartes_reseau/interfaces
@@ -0,0 +1,24 @@
+# This file describes the network interfaces available on your system
+# and how to activate them. For more information, see interfaces(5).
+
+source /etc/network/interfaces.d/*
+
+# The loopback network interface
+auto lo
+iface lo inet loopback
+
+# The primary network interface
+allow-hotplug enp0s3
+iface enp0s3 inet static
+ address 192.168.0.140/24
+ gateway 192.168.0.1
+
+# Assignation static IP adresse
+# auto enp0s3
+# iface enp0s3 inet static
+# address 192.168.0.26/24
+# gateway 192.168.0.1
+
+# The seconary network interface
+auto enp0s8
+iface enp0s8 inet dhcp
diff --git a/sisr1/tp03-reseau-prive/srv-admin/nat/README.md b/sisr1/tp03-reseau-prive/srv-admin/nat/README.md
new file mode 100644
index 0000000..2a6a4da
--- /dev/null
+++ b/sisr1/tp03-reseau-prive/srv-admin/nat/README.md
@@ -0,0 +1,6 @@
+ * **nat.sh** : script activant la NAT dynamique sans filtrage
+ * A placer à /root/nat.sh
+ * Rendre exécutable : chmod +x /root/nat.sh
+ * **nat.service** : service lançant le script au démarrage
+ * A placer à /etc/systemd/system/nat.service
+ * Activer le service : systemctl enable nat.service
\ No newline at end of file
diff --git a/sisr1/tp03-reseau-prive/srv-admin/nat/nat.service b/sisr1/tp03-reseau-prive/srv-admin/nat/nat.service
new file mode 100644
index 0000000..8c18dcd
--- /dev/null
+++ b/sisr1/tp03-reseau-prive/srv-admin/nat/nat.service
@@ -0,0 +1,13 @@
+[Unit]
+
+Description=execute /root/nat.sh
+
+After=default.target
+
+[Service]
+
+ExecStart=bash /root/nat.sh
+
+[Install]
+
+WantedBy=default.target
\ No newline at end of file
diff --git a/sisr1/tp03-reseau-prive/srv-admin/nat/nat.sh b/sisr1/tp03-reseau-prive/srv-admin/nat/nat.sh
new file mode 100644
index 0000000..04b2a95
--- /dev/null
+++ b/sisr1/tp03-reseau-prive/srv-admin/nat/nat.sh
@@ -0,0 +1,6 @@
+#!/bin/bash
+echo "1" > /proc/sys/net/ipv4/ip_forward
+nft add table basic_nat_table
+nft add chain basic_nat_table prerouting {type nat hook prerouting priority 0 \; }
+nft add chain basic_nat_table postrouting {type nat hook postrouting priority 0 \; }
+nft add rule basic_nat_table postrouting masquerade
\ No newline at end of file
diff --git a/sisr1/tp03-reseau-prive/srv-dns2/README.md b/sisr1/tp03-reseau-prive/srv-dns2/README.md
new file mode 100644
index 0000000..9c5481b
--- /dev/null
+++ b/sisr1/tp03-reseau-prive/srv-dns2/README.md
@@ -0,0 +1,2 @@
+**- fichier named.conf** :
+ * les fichiers named.conf.local et named.conf.options sont récupérés du srv-service
diff --git a/sisr1/tp03-reseau-prive/srv-dns2/cartes_reseau/interfaces b/sisr1/tp03-reseau-prive/srv-dns2/cartes_reseau/interfaces
new file mode 100644
index 0000000..aa7da60
--- /dev/null
+++ b/sisr1/tp03-reseau-prive/srv-dns2/cartes_reseau/interfaces
@@ -0,0 +1,18 @@
+# This file describes the network interfaces available on your system
+# and how to activate them. For more information, see interfaces(5).
+
+source /etc/network/interfaces.d/*
+
+# The loopback network interface
+auto lo
+iface lo inet loopback
+
+# The primary network interface
+allow-hotplug enp0s3
+iface enp0s3 inet dhcp
+
+# Assignation static IP adresse
+#auto enp0s3
+#iface enp0s3 inet static
+# address 172.16.0.200/24
+# gateway 172.16.0.1
diff --git a/sisr1/tp03-reseau-prive/srv-dns2/dns/db.monlabo.lan b/sisr1/tp03-reseau-prive/srv-dns2/dns/db.monlabo.lan
new file mode 100644
index 0000000..e58cd09
--- /dev/null
+++ b/sisr1/tp03-reseau-prive/srv-dns2/dns/db.monlabo.lan
@@ -0,0 +1,28 @@
+;
+; BIND data file for local loopback interface
+;
+$TTL 604800
+@ IN SOA srv-service.monlabo.lan. root.srv-service.monlabo.lan. (
+ 2 ; Serial
+ 604800 ; Refresh
+ 86400 ; Retry
+ 2419200 ; Expire
+ 604800 ) ; Negative Cache TTL
+ NS srv-service.monlabo.lan.
+ NS srv-dns2.monlabo.lan.
+srv-service.monlabo.lan. A 172.16.0.254
+srv-dns2.monlabo.lan. A 172.16.0.253
+srv-admin-jt.monlabo.lan. A 172.16.0.1
+
+srvdhcp IN CNAME srv-service.monlabo.lan.
+dhcp IN CNAME srv-service.monlabo.lan.
+srvdns IN CNAME srv-service.monlabo.lan.
+dns IN CNAME srv-service.monlabo.lan.
+srvdns1 IN CNAME srv-service.monlabo.lan.
+dns1 IN CNAME srv-service.monlabo.lan.
+srvdns2 IN CNAME srv-dns2.monlabo.lan.
+dns2 IN CNAME srv-dns2.monlabo.lan.
+srvadmin IN CNAME srv-admin-jt.monlabo.lan.
+router IN CNAME srv-admin-jt.monlabo.lan.
+gateway IN CNAME srv-admin-jt.monlabo.lan.
+
diff --git a/sisr1/tp03-reseau-prive/srv-dns2/dns/db.monlabo.lan.rev b/sisr1/tp03-reseau-prive/srv-dns2/dns/db.monlabo.lan.rev
new file mode 100644
index 0000000..b439fde
--- /dev/null
+++ b/sisr1/tp03-reseau-prive/srv-dns2/dns/db.monlabo.lan.rev
@@ -0,0 +1,26 @@
+$ORIGIN .
+$TTL 604800 ; 1 week
+0.16.172.in-addr.arpa IN SOA srv-service.monlabo.lan. root.srv-service.monlabo.lan. (
+ 2 ; serial
+ 604800 ; refresh (1 week)
+ 86400 ; retry (1 day)
+ 2419200 ; expire (4 weeks)
+ 604800 ; minimum (1 week)
+ )
+ NS srv-dns2.monlabo.lan.
+ NS srv-service.monlabo.lan.
+$ORIGIN 0.16.172.in-addr.arpa.
+1 PTR srv-admin-jt.monlabo.lan.
+253 PTR srv-dns2.monlabo.lan.
+254 PTR svr-service.monlabo.lan.
+dhcp CNAME srv-service.monlabo.lan.
+dns CNAME srv-service.monlabo.lan.
+dns1 CNAME srv-service.monlabo.lan.
+dns2 CNAME srv-dns2.monlabo.lan.
+gateway CNAME srv-admin-jt.monlabo.lan.
+router CNAME srv-admin-jt.monlabo.lan.
+srvadmin CNAME srv-admin-jt.monlabo.lan.
+srvdhcp CNAME srv-service.monlabo.lan.
+srvdns CNAME srv-service.monlabo.lan.
+srvdns1 CNAME srv-service.monlabo.lan.
+srvdns2 CNAME srv-dns2.monlabo.lan.
diff --git a/sisr1/tp03-reseau-prive/srv-service/carte_reseau/interfaces b/sisr1/tp03-reseau-prive/srv-service/carte_reseau/interfaces
new file mode 100644
index 0000000..e1f11af
--- /dev/null
+++ b/sisr1/tp03-reseau-prive/srv-service/carte_reseau/interfaces
@@ -0,0 +1,18 @@
+# This file describes the network interfaces available on your system
+# and how to activate them. For more information, see interfaces(5).
+
+source /etc/network/interfaces.d/*
+
+# The loopback network interface
+auto lo
+iface lo inet loopback
+
+# The primary network interface
+#allow-hotplug enp0s3
+#iface enp0s3 inet dhcp
+
+# Assignation static IP adresse
+auto enp0s3
+iface enp0s3 inet static
+ address 172.16.0.254/24
+ gateway 172.16.0.1
diff --git a/sisr1/tp03-reseau-prive/srv-service/dhcp/dhcpd.conf b/sisr1/tp03-reseau-prive/srv-service/dhcp/dhcpd.conf
new file mode 100644
index 0000000..71d8df3
--- /dev/null
+++ b/sisr1/tp03-reseau-prive/srv-service/dhcp/dhcpd.conf
@@ -0,0 +1,113 @@
+# dhcpd.conf
+#
+# Sample configuration file for ISC dhcpd
+#
+
+# option definitions common to all supported networks...
+#option domain-name "example.org";
+#option domain-name-servers ns1.example.org, ns2.example.org;
+
+default-lease-time 600;
+max-lease-time 7200;
+
+# The ddns-updates-style parameter controls whether or not the server will
+# attempt to do a DNS update when a lease is confirmed. We default to the
+# behavior of the version 2 packages ('none', since DHCP v2 didn't
+# have support for DDNS.)
+ddns-update-style none;
+
+# If this DHCP server is the official DHCP server for the local
+# network, the authoritative directive should be uncommented.
+#authoritative;
+
+# Use this to send dhcp log messages to a different log file (you also
+# have to hack syslog.conf to complete the redirection).
+#log-facility local7;
+
+# No service will be given on this subnet, but declaring it helps the
+# DHCP server to understand the network topology.
+
+#subnet 10.152.187.0 netmask 255.255.255.0 {
+#}
+
+# This is a very basic subnet declaration.
+
+#subnet 10.254.239.0 netmask 255.255.255.224 {
+# range 10.254.239.10 10.254.239.20;
+# option routers rtr-239-0-1.example.org, rtr-239-0-2.example.org;
+#}
+
+# This declaration allows BOOTP clients to get dynamic addresses,
+# which we don't really recommend.
+
+subnet 172.16.0.0 netmask 255.255.255.0 {
+ range 172.16.0.20 172.16.0.119;
+ option routers 172.16.0.1;
+ option domain-name-servers 172.16.0.254, 172.16.0.253;
+ option domain-name "monlabo.lan";
+}
+
+# A slightly different configuration for an internal subnet.
+#subnet 10.5.5.0 netmask 255.255.255.224 {
+# range 10.5.5.26 10.5.5.30;
+# option domain-name-servers ns1.internal.example.org;
+# option domain-name "internal.example.org";
+# option routers 10.5.5.1;
+# option broadcast-address 10.5.5.31;
+# default-lease-time 600;
+# max-lease-time 7200;
+#}
+
+# Hosts which require special configuration options can be listed in
+# host statements. If no address is specified, the address will be
+# allocated dynamically (if possible), but the host-specific information
+# will still come from the host declaration
+
+#host passacaglia {
+# hardware ethernet 0:0:c0:5d:bd:95;
+# filename "vmunix.passacaglia";
+# server-name "toccata.example.com";
+#}
+
+# Fixed IP addresses can also be specified for hosts. These addresses
+# should not also be listed as being available for dynamic assignment.
+# Hosts for which fixed IP addresses have been specified can boot using
+# BOOTP or DHCP. Hosts for which no fixed address is specified can only
+# be booted with DHCP, unless there is an address range on the subnet
+# to which a BOOTP client is connected which has the dynamic-bootp flag
+# set.
+host srv-admin-jt {
+ hardware ethernet 08:00:27:0a:1e:8b;
+ fixed-address 172.16.0.1;
+}
+
+host srv-dns2 {
+ hardware ethernet 08:00:27:91:48:15;
+ fixed-address 172.16.0.253;
+}
+
+# You can declare a class of clients and then do address allocation
+# based on that. The example below shows a case where all clients
+# in a certain class get addresses on the 10.17.224/24 subnet, and all
+# other clients get addresses on the 10.0.29/24 subnet.
+
+#class "foo" {
+# match if substring (option vendor-class-identifier, 0, 4) = "SUNW";
+#}
+
+#shared-network 224-29 {
+# subnet 10.17.224.0 netmask 255.255.255.0 {
+# option routers rtr-224.example.org;
+# }
+# subnet 10.0.29.0 netmask 255.255.255.0 {
+# option routers rtr-29.example.org;
+# }
+# pool {
+# allow members of "foo";
+# range 10.17.224.10 10.17.224.250;
+# }
+# pool {
+# deny members of "foo";
+# range 10.0.29.10 10.0.29.230;
+# }
+#}
diff --git a/sisr1/tp03-reseau-prive/srv-service/dns/db.monlabo.lan b/sisr1/tp03-reseau-prive/srv-service/dns/db.monlabo.lan
new file mode 100644
index 0000000..6233dbd
--- /dev/null
+++ b/sisr1/tp03-reseau-prive/srv-service/dns/db.monlabo.lan
@@ -0,0 +1,29 @@
+
+
+;
+; BIND data file for local loopback interface
+;
+$TTL 604800
+@ IN SOA srv-service.monlabo.lan. root.srv-service.monlabo.lan. (
+ 2 ; Serial
+ 604800 ; Refresh
+ 86400 ; Retry
+ 2419200 ; Expire
+ 604800 ) ; Negative Cache TTL
+ NS srv-service.monlabo.lan.
+ NS srv-dns2.monlabo.lan.
+srv-service.monlabo.lan. A 172.16.0.254
+srv-dns2.monlabo.lan. A 172.16.0.253
+srv-admin-jt.monlabo.lan. A 172.16.0.1
+
+srvdhcp IN CNAME srv-service.monlabo.lan.
+dhcp IN CNAME srv-service.monlabo.lan.
+srvdns IN CNAME srv-service.monlabo.lan.
+dns IN CNAME srv-service.monlabo.lan.
+srvdns1 IN CNAME srv-service.monlabo.lan.
+dns1 IN CNAME srv-service.monlabo.lan.
+srvdns2 IN CNAME srv-dns2.monlabo.lan.
+dns2 IN CNAME srv-dns2.monlabo.lan.
+srvadmin IN CNAME srv-admin-jt.monlabo.lan.
+router IN CNAME srv-admin-jt.monlabo.lan.
+gateway IN CNAME srv-admin-jt.monlabo.lan.
diff --git a/sisr1/tp03-reseau-prive/srv-service/dns/db.monlabo.lan.rev b/sisr1/tp03-reseau-prive/srv-service/dns/db.monlabo.lan.rev
new file mode 100644
index 0000000..417ca0a
--- /dev/null
+++ b/sisr1/tp03-reseau-prive/srv-service/dns/db.monlabo.lan.rev
@@ -0,0 +1,30 @@
+
+
+;
+; BIND data file for local loopback interface
+;
+$TTL 604800
+@ IN SOA srv-service.monlabo.lan. root.srv-service.monlabo.lan. (
+ 2 ; Serial
+ 604800 ; Refresh
+ 86400 ; Retry
+ 2419200 ; Expire
+ 604800 ) ; Negative Cache TTL
+@ IN NS srv-service.monlabo.lan.
+ NS srv-dns2.monlabo.lan.
+
+254 IN PTR svr-service.monlabo.lan.
+253 IN PTR srv-dns2.monlabo.lan.
+1 IN PTR srv-admin-jt.monlabo.lan.
+
+srvdhcp IN CNAME srv-service.monlabo.lan.
+dhcp IN CNAME srv-service.monlabo.lan.
+srvdns IN CNAME srv-service.monlabo.lan.
+dns IN CNAME srv-service.monlabo.lan.
+srvdns1 IN CNAME srv-service.monlabo.lan.
+dns1 IN CNAME srv-service.monlabo.lan.
+srvdns2 IN CNAME srv-dns2.monlabo.lan.
+dns2 IN CNAME srv-dns2.monlabo.lan.
+srvadmin IN CNAME srv-admin-jt.monlabo.lan.
+router IN CNAME srv-admin-jt.monlabo.lan.
+gateway IN CNAME srv-admin-jt.monlabo.lan.
diff --git a/sisr1/tp03-reseau-prive/srv-service/dns/named.conf.local b/sisr1/tp03-reseau-prive/srv-service/dns/named.conf.local
new file mode 100644
index 0000000..9cc4927
--- /dev/null
+++ b/sisr1/tp03-reseau-prive/srv-service/dns/named.conf.local
@@ -0,0 +1,21 @@
+//
+// Do any local configuration here
+//
+
+ // zone direct
+ zone "monlabo.lan"{
+ type master;
+ file"/etc/bind/db.monlabo.lan";
+ };
+
+ // zone inverse
+ zone "0.16.172.in-addr.arpa"{
+ type master;
+ notify no;
+ file "/etc/bind/db.monlabo.lan.rev";
+ };
+
+// Consider adding the 1918 zones here, if they are not used in your
+// organization
+//include "/etc/bind/zones.rfc1918";
+
diff --git a/sisr1/tp03-reseau-prive/srv-service/dns/named.conf.options b/sisr1/tp03-reseau-prive/srv-service/dns/named.conf.options
new file mode 100644
index 0000000..9471949
--- /dev/null
+++ b/sisr1/tp03-reseau-prive/srv-service/dns/named.conf.options
@@ -0,0 +1,24 @@
+options {
+ directory "/var/cache/bind";
+
+ // If there is a firewall between you and nameservers you want
+ // to talk to, you may need to fix the firewall to allow multiple
+ // ports to talk. See http://www.kb.cert.org/vuls/id/800113
+
+ // If your ISP provided one or more IP addresses for stable
+ // nameservers, you probably want to use them as forwarders.
+ // Uncomment the following block, and insert the addresses replacing
+ // the all-0's placeholder.
+
+ forwarders {
+ 10.121.38.7; // DNS lycée
+ };
+
+ //========================================================================
+ // If BIND logs error messages about the root key being expired,
+ // you will need to update your keys. See https://www.isc.org/bind-keys
+ //========================================================================
+ dnssec-validation no;
+
+ listen-on-v6 { any; };
+};