diff --git a/sisr1/tp03-reseau-prive/srv-admin/cartes_reseau/interfaces b/sisr1/tp03-reseau-prive/srv-admin/cartes_reseau/interfaces new file mode 100644 index 0000000..ab2e8af --- /dev/null +++ b/sisr1/tp03-reseau-prive/srv-admin/cartes_reseau/interfaces @@ -0,0 +1,24 @@ +# This file describes the network interfaces available on your system +# and how to activate them. For more information, see interfaces(5). + +source /etc/network/interfaces.d/* + +# The loopback network interface +auto lo +iface lo inet loopback + +# The primary network interface +allow-hotplug enp0s3 +iface enp0s3 inet static + address 192.168.0.140/24 + gateway 192.168.0.1 + +# Assignation static IP adresse +# auto enp0s3 +# iface enp0s3 inet static +# address 192.168.0.26/24 +# gateway 192.168.0.1 + +# The seconary network interface +auto enp0s8 +iface enp0s8 inet dhcp diff --git a/sisr1/tp03-reseau-prive/srv-admin/nat/README.md b/sisr1/tp03-reseau-prive/srv-admin/nat/README.md new file mode 100644 index 0000000..2a6a4da --- /dev/null +++ b/sisr1/tp03-reseau-prive/srv-admin/nat/README.md @@ -0,0 +1,6 @@ + * **nat.sh** : script activant la NAT dynamique sans filtrage + * A placer à /root/nat.sh + * Rendre exécutable : chmod +x /root/nat.sh + * **nat.service** : service lançant le script au démarrage + * A placer à /etc/systemd/system/nat.service + * Activer le service : systemctl enable nat.service \ No newline at end of file diff --git a/sisr1/tp03-reseau-prive/srv-admin/nat/nat.service b/sisr1/tp03-reseau-prive/srv-admin/nat/nat.service new file mode 100644 index 0000000..8c18dcd --- /dev/null +++ b/sisr1/tp03-reseau-prive/srv-admin/nat/nat.service @@ -0,0 +1,13 @@ +[Unit] + +Description=execute /root/nat.sh + +After=default.target + +[Service] + +ExecStart=bash /root/nat.sh + +[Install] + +WantedBy=default.target \ No newline at end of file diff --git a/sisr1/tp03-reseau-prive/srv-admin/nat/nat.sh b/sisr1/tp03-reseau-prive/srv-admin/nat/nat.sh new file mode 100644 index 0000000..04b2a95 --- /dev/null +++ b/sisr1/tp03-reseau-prive/srv-admin/nat/nat.sh @@ -0,0 +1,6 @@ +#!/bin/bash +echo "1" > /proc/sys/net/ipv4/ip_forward +nft add table basic_nat_table +nft add chain basic_nat_table prerouting {type nat hook prerouting priority 0 \; } +nft add chain basic_nat_table postrouting {type nat hook postrouting priority 0 \; } +nft add rule basic_nat_table postrouting masquerade \ No newline at end of file diff --git a/sisr1/tp03-reseau-prive/srv-dns2/README.md b/sisr1/tp03-reseau-prive/srv-dns2/README.md new file mode 100644 index 0000000..9c5481b --- /dev/null +++ b/sisr1/tp03-reseau-prive/srv-dns2/README.md @@ -0,0 +1,2 @@ +**- fichier named.conf** : + * les fichiers named.conf.local et named.conf.options sont récupérés du srv-service diff --git a/sisr1/tp03-reseau-prive/srv-dns2/cartes_reseau/interfaces b/sisr1/tp03-reseau-prive/srv-dns2/cartes_reseau/interfaces new file mode 100644 index 0000000..aa7da60 --- /dev/null +++ b/sisr1/tp03-reseau-prive/srv-dns2/cartes_reseau/interfaces @@ -0,0 +1,18 @@ +# This file describes the network interfaces available on your system +# and how to activate them. For more information, see interfaces(5). + +source /etc/network/interfaces.d/* + +# The loopback network interface +auto lo +iface lo inet loopback + +# The primary network interface +allow-hotplug enp0s3 +iface enp0s3 inet dhcp + +# Assignation static IP adresse +#auto enp0s3 +#iface enp0s3 inet static +# address 172.16.0.200/24 +# gateway 172.16.0.1 diff --git a/sisr1/tp03-reseau-prive/srv-dns2/dns/db.monlabo.lan b/sisr1/tp03-reseau-prive/srv-dns2/dns/db.monlabo.lan new file mode 100644 index 0000000..e58cd09 --- /dev/null +++ b/sisr1/tp03-reseau-prive/srv-dns2/dns/db.monlabo.lan @@ -0,0 +1,28 @@ +; +; BIND data file for local loopback interface +; +$TTL 604800 +@ IN SOA srv-service.monlabo.lan. root.srv-service.monlabo.lan. ( + 2 ; Serial + 604800 ; Refresh + 86400 ; Retry + 2419200 ; Expire + 604800 ) ; Negative Cache TTL + NS srv-service.monlabo.lan. + NS srv-dns2.monlabo.lan. +srv-service.monlabo.lan. A 172.16.0.254 +srv-dns2.monlabo.lan. A 172.16.0.253 +srv-admin-jt.monlabo.lan. A 172.16.0.1 + +srvdhcp IN CNAME srv-service.monlabo.lan. +dhcp IN CNAME srv-service.monlabo.lan. +srvdns IN CNAME srv-service.monlabo.lan. +dns IN CNAME srv-service.monlabo.lan. +srvdns1 IN CNAME srv-service.monlabo.lan. +dns1 IN CNAME srv-service.monlabo.lan. +srvdns2 IN CNAME srv-dns2.monlabo.lan. +dns2 IN CNAME srv-dns2.monlabo.lan. +srvadmin IN CNAME srv-admin-jt.monlabo.lan. +router IN CNAME srv-admin-jt.monlabo.lan. +gateway IN CNAME srv-admin-jt.monlabo.lan. + diff --git a/sisr1/tp03-reseau-prive/srv-dns2/dns/db.monlabo.lan.rev b/sisr1/tp03-reseau-prive/srv-dns2/dns/db.monlabo.lan.rev new file mode 100644 index 0000000..b439fde --- /dev/null +++ b/sisr1/tp03-reseau-prive/srv-dns2/dns/db.monlabo.lan.rev @@ -0,0 +1,26 @@ +$ORIGIN . +$TTL 604800 ; 1 week +0.16.172.in-addr.arpa IN SOA srv-service.monlabo.lan. root.srv-service.monlabo.lan. ( + 2 ; serial + 604800 ; refresh (1 week) + 86400 ; retry (1 day) + 2419200 ; expire (4 weeks) + 604800 ; minimum (1 week) + ) + NS srv-dns2.monlabo.lan. + NS srv-service.monlabo.lan. +$ORIGIN 0.16.172.in-addr.arpa. +1 PTR srv-admin-jt.monlabo.lan. +253 PTR srv-dns2.monlabo.lan. +254 PTR svr-service.monlabo.lan. +dhcp CNAME srv-service.monlabo.lan. +dns CNAME srv-service.monlabo.lan. +dns1 CNAME srv-service.monlabo.lan. +dns2 CNAME srv-dns2.monlabo.lan. +gateway CNAME srv-admin-jt.monlabo.lan. +router CNAME srv-admin-jt.monlabo.lan. +srvadmin CNAME srv-admin-jt.monlabo.lan. +srvdhcp CNAME srv-service.monlabo.lan. +srvdns CNAME srv-service.monlabo.lan. +srvdns1 CNAME srv-service.monlabo.lan. +srvdns2 CNAME srv-dns2.monlabo.lan. diff --git a/sisr1/tp03-reseau-prive/srv-service/carte_reseau/interfaces b/sisr1/tp03-reseau-prive/srv-service/carte_reseau/interfaces new file mode 100644 index 0000000..e1f11af --- /dev/null +++ b/sisr1/tp03-reseau-prive/srv-service/carte_reseau/interfaces @@ -0,0 +1,18 @@ +# This file describes the network interfaces available on your system +# and how to activate them. For more information, see interfaces(5). + +source /etc/network/interfaces.d/* + +# The loopback network interface +auto lo +iface lo inet loopback + +# The primary network interface +#allow-hotplug enp0s3 +#iface enp0s3 inet dhcp + +# Assignation static IP adresse +auto enp0s3 +iface enp0s3 inet static + address 172.16.0.254/24 + gateway 172.16.0.1 diff --git a/sisr1/tp03-reseau-prive/srv-service/dhcp/dhcpd.conf b/sisr1/tp03-reseau-prive/srv-service/dhcp/dhcpd.conf new file mode 100644 index 0000000..71d8df3 --- /dev/null +++ b/sisr1/tp03-reseau-prive/srv-service/dhcp/dhcpd.conf @@ -0,0 +1,113 @@ +# dhcpd.conf +# +# Sample configuration file for ISC dhcpd +# + +# option definitions common to all supported networks... +#option domain-name "example.org"; +#option domain-name-servers ns1.example.org, ns2.example.org; + +default-lease-time 600; +max-lease-time 7200; + +# The ddns-updates-style parameter controls whether or not the server will +# attempt to do a DNS update when a lease is confirmed. We default to the +# behavior of the version 2 packages ('none', since DHCP v2 didn't +# have support for DDNS.) +ddns-update-style none; + +# If this DHCP server is the official DHCP server for the local +# network, the authoritative directive should be uncommented. +#authoritative; + +# Use this to send dhcp log messages to a different log file (you also +# have to hack syslog.conf to complete the redirection). +#log-facility local7; + +# No service will be given on this subnet, but declaring it helps the +# DHCP server to understand the network topology. + +#subnet 10.152.187.0 netmask 255.255.255.0 { +#} + +# This is a very basic subnet declaration. + +#subnet 10.254.239.0 netmask 255.255.255.224 { +# range 10.254.239.10 10.254.239.20; +# option routers rtr-239-0-1.example.org, rtr-239-0-2.example.org; +#} + +# This declaration allows BOOTP clients to get dynamic addresses, +# which we don't really recommend. + +subnet 172.16.0.0 netmask 255.255.255.0 { + range 172.16.0.20 172.16.0.119; + option routers 172.16.0.1; + option domain-name-servers 172.16.0.254, 172.16.0.253; + option domain-name "monlabo.lan"; +} + +# A slightly different configuration for an internal subnet. +#subnet 10.5.5.0 netmask 255.255.255.224 { +# range 10.5.5.26 10.5.5.30; +# option domain-name-servers ns1.internal.example.org; +# option domain-name "internal.example.org"; +# option routers 10.5.5.1; +# option broadcast-address 10.5.5.31; +# default-lease-time 600; +# max-lease-time 7200; +#} + +# Hosts which require special configuration options can be listed in +# host statements. If no address is specified, the address will be +# allocated dynamically (if possible), but the host-specific information +# will still come from the host declaration + +#host passacaglia { +# hardware ethernet 0:0:c0:5d:bd:95; +# filename "vmunix.passacaglia"; +# server-name "toccata.example.com"; +#} + +# Fixed IP addresses can also be specified for hosts. These addresses +# should not also be listed as being available for dynamic assignment. +# Hosts for which fixed IP addresses have been specified can boot using +# BOOTP or DHCP. Hosts for which no fixed address is specified can only +# be booted with DHCP, unless there is an address range on the subnet +# to which a BOOTP client is connected which has the dynamic-bootp flag +# set. +host srv-admin-jt { + hardware ethernet 08:00:27:0a:1e:8b; + fixed-address 172.16.0.1; +} + +host srv-dns2 { + hardware ethernet 08:00:27:91:48:15; + fixed-address 172.16.0.253; +} + +# You can declare a class of clients and then do address allocation +# based on that. The example below shows a case where all clients +# in a certain class get addresses on the 10.17.224/24 subnet, and all +# other clients get addresses on the 10.0.29/24 subnet. + +#class "foo" { +# match if substring (option vendor-class-identifier, 0, 4) = "SUNW"; +#} + +#shared-network 224-29 { +# subnet 10.17.224.0 netmask 255.255.255.0 { +# option routers rtr-224.example.org; +# } +# subnet 10.0.29.0 netmask 255.255.255.0 { +# option routers rtr-29.example.org; +# } +# pool { +# allow members of "foo"; +# range 10.17.224.10 10.17.224.250; +# } +# pool { +# deny members of "foo"; +# range 10.0.29.10 10.0.29.230; +# } +#} diff --git a/sisr1/tp03-reseau-prive/srv-service/dns/db.monlabo.lan b/sisr1/tp03-reseau-prive/srv-service/dns/db.monlabo.lan new file mode 100644 index 0000000..6233dbd --- /dev/null +++ b/sisr1/tp03-reseau-prive/srv-service/dns/db.monlabo.lan @@ -0,0 +1,29 @@ + + +; +; BIND data file for local loopback interface +; +$TTL 604800 +@ IN SOA srv-service.monlabo.lan. root.srv-service.monlabo.lan. ( + 2 ; Serial + 604800 ; Refresh + 86400 ; Retry + 2419200 ; Expire + 604800 ) ; Negative Cache TTL + NS srv-service.monlabo.lan. + NS srv-dns2.monlabo.lan. +srv-service.monlabo.lan. A 172.16.0.254 +srv-dns2.monlabo.lan. A 172.16.0.253 +srv-admin-jt.monlabo.lan. A 172.16.0.1 + +srvdhcp IN CNAME srv-service.monlabo.lan. +dhcp IN CNAME srv-service.monlabo.lan. +srvdns IN CNAME srv-service.monlabo.lan. +dns IN CNAME srv-service.monlabo.lan. +srvdns1 IN CNAME srv-service.monlabo.lan. +dns1 IN CNAME srv-service.monlabo.lan. +srvdns2 IN CNAME srv-dns2.monlabo.lan. +dns2 IN CNAME srv-dns2.monlabo.lan. +srvadmin IN CNAME srv-admin-jt.monlabo.lan. +router IN CNAME srv-admin-jt.monlabo.lan. +gateway IN CNAME srv-admin-jt.monlabo.lan. diff --git a/sisr1/tp03-reseau-prive/srv-service/dns/db.monlabo.lan.rev b/sisr1/tp03-reseau-prive/srv-service/dns/db.monlabo.lan.rev new file mode 100644 index 0000000..417ca0a --- /dev/null +++ b/sisr1/tp03-reseau-prive/srv-service/dns/db.monlabo.lan.rev @@ -0,0 +1,30 @@ + + +; +; BIND data file for local loopback interface +; +$TTL 604800 +@ IN SOA srv-service.monlabo.lan. root.srv-service.monlabo.lan. ( + 2 ; Serial + 604800 ; Refresh + 86400 ; Retry + 2419200 ; Expire + 604800 ) ; Negative Cache TTL +@ IN NS srv-service.monlabo.lan. + NS srv-dns2.monlabo.lan. + +254 IN PTR svr-service.monlabo.lan. +253 IN PTR srv-dns2.monlabo.lan. +1 IN PTR srv-admin-jt.monlabo.lan. + +srvdhcp IN CNAME srv-service.monlabo.lan. +dhcp IN CNAME srv-service.monlabo.lan. +srvdns IN CNAME srv-service.monlabo.lan. +dns IN CNAME srv-service.monlabo.lan. +srvdns1 IN CNAME srv-service.monlabo.lan. +dns1 IN CNAME srv-service.monlabo.lan. +srvdns2 IN CNAME srv-dns2.monlabo.lan. +dns2 IN CNAME srv-dns2.monlabo.lan. +srvadmin IN CNAME srv-admin-jt.monlabo.lan. +router IN CNAME srv-admin-jt.monlabo.lan. +gateway IN CNAME srv-admin-jt.monlabo.lan. diff --git a/sisr1/tp03-reseau-prive/srv-service/dns/named.conf.local b/sisr1/tp03-reseau-prive/srv-service/dns/named.conf.local new file mode 100644 index 0000000..9cc4927 --- /dev/null +++ b/sisr1/tp03-reseau-prive/srv-service/dns/named.conf.local @@ -0,0 +1,21 @@ +// +// Do any local configuration here +// + + // zone direct + zone "monlabo.lan"{ + type master; + file"/etc/bind/db.monlabo.lan"; + }; + + // zone inverse + zone "0.16.172.in-addr.arpa"{ + type master; + notify no; + file "/etc/bind/db.monlabo.lan.rev"; + }; + +// Consider adding the 1918 zones here, if they are not used in your +// organization +//include "/etc/bind/zones.rfc1918"; + diff --git a/sisr1/tp03-reseau-prive/srv-service/dns/named.conf.options b/sisr1/tp03-reseau-prive/srv-service/dns/named.conf.options new file mode 100644 index 0000000..9471949 --- /dev/null +++ b/sisr1/tp03-reseau-prive/srv-service/dns/named.conf.options @@ -0,0 +1,24 @@ +options { + directory "/var/cache/bind"; + + // If there is a firewall between you and nameservers you want + // to talk to, you may need to fix the firewall to allow multiple + // ports to talk. See http://www.kb.cert.org/vuls/id/800113 + + // If your ISP provided one or more IP addresses for stable + // nameservers, you probably want to use them as forwarders. + // Uncomment the following block, and insert the addresses replacing + // the all-0's placeholder. + + forwarders { + 10.121.38.7; // DNS lycée + }; + + //======================================================================== + // If BIND logs error messages about the root key being expired, + // you will need to update your keys. See https://www.isc.org/bind-keys + //======================================================================== + dnssec-validation no; + + listen-on-v6 { any; }; +};