Project 1: Home Lab Setup
Project Overview
This project documents the setup of a basic home lab environment using VirtualBox and Ubuntu Server 22.04 LTS.
Environment Details
- Host System: Windows 11
- Hypervisor: Oracle VirtualBox
- Guest OS: Ubuntu Server 22.04 LTS
- Resources Allocated:
- CPU: 2 cores
- RAM: 2GB
- Storage: 20GB
- Network: NAT + Host-only adapter
Setup Steps
1. VirtualBox Installation ✅
- Successfully installed VirtualBox
- Created project directory structure
2. Ubuntu Server VM Creation ✅
- Download Ubuntu Server 22.04 LTS ISO
- Create new VM in VirtualBox
- Configure VM settings (CPU, RAM, Storage)
- Configure network adapters
- Install Ubuntu Server
- Basic system configuration
- Network setup
3. Network Configuration ✅
-
Configure NAT adapter for internet access
- Verify IP address configuration ✅
- Test internet connectivity ✅
ping 8.8.8.8 # Success ping google.com # Success
-
Configure Host-only adapter for direct host communication
- Verify second network interface ✅
ip addr show enp0s8 # Output shows: # inet 169.254.0.2/16 brd 169.254.255.255 scope global enp0s8 - Test host connectivity ✅
# Successfully pinged host (169.254.167.242) # Round-trip time (RTT) avg: 2.846ms
- Verify second network interface ✅
-
Document network configuration:
- NAT adapter IP (enp0s3): 10.0.2.15/24
- Host-only adapter IP (enp0s8): 169.254.0.2/16
- Default gateway: 10.0.2.2
- Host IP: 169.254.167.242
Current Status
- ✅ NAT adapter: Working (Internet access)
- ✅ Host-only adapter: Working (Host communication)
- ✅ Network connectivity: Verified
Next Steps
Now that networking is configured, we can proceed to:
- Basic Security Setup
- Create non-root user with sudo privileges
- Configure SSH access
- Set up UFW firewall
4. Basic Security Setup ✅
-
User Management ✅
- Created sysadmin user with sudo privileges
- Enhanced hugh user security
-
SSH Configuration ✅
- Installed and configured OpenSSH server
- Implemented key-based authentication
- Disabled password authentication
- Applied security hardening settings
-
UFW Firewall Setup ✅
- Installed and configured UFW
- Set default policies (deny incoming, allow outgoing)
- Allowed required services:
- SSH (port 22)
- HTTP (port 80)
- HTTPS (port 443)
- Host machine access (169.254.167.242)
- Verified connectivity
5. System Monitoring and Maintenance ✅
-
Monitoring Tools
- Installed and configured htop
- Set up Netdata for system metrics
- Configured Logwatch for log monitoring
-
Maintenance Procedures
- Implemented backup strategy with rsync
- Configured automated updates
- Set up log rotation
Current Status
- ✅ Basic VM Setup: Complete
- ✅ Network Configuration: Complete
- ✅ Security Measures: Complete
- ✅ System Monitoring: Complete
Next Steps
-
Service Deployment
- Web server setup (Apache/Nginx)
- Database server
- Basic web application
-
Automation and Scripting
- Shell scripting basics
- Automated maintenance tasks
- System health checks
-
Advanced Networking
- DNS configuration
- Network services
- Advanced firewall rules
Security Configuration Status
- User Management
- Admin user created
- Sudo privileges configured
- SSH Access
- SSH server installed
- Key-based authentication configured
- Root login disabled
- Firewall
- UFW installed
- Basic rules configured
- SSH access allowed
Commands and Configurations
Network Configuration Commands
### SSH Configuration
```conf
# Key SSH configuration settings (/etc/ssh/sshd_config)
PermitRootLogin no
PasswordAuthentication no
AllowUsers admin
UFW Rules
# View UFW status
sudo ufw status verbose
# Basic allowed services
sudo ufw status numbered