BIT451 Network and System Administration

Network and System AdministrationUnit 1411 min read

Review & Practical Implementation: Network Admin Mastery

Unit 14 of Network and System Administration synthesizes all 13 prior units into a comprehensive review of network administration concepts, practical troubleshooting scenarios, and hands-on implementation strategies for real-world systems like eSewa, Ncell, and NEPSE. Students will integrate IP subnetting, DNS, DHCP, s


Core Concepts Review: The Big Picture

Network administration is not just memorizing protocols—it’s about connecting the dots between theory and real-world deployment. This unit forces you to revisit every unit (1–13) and ask:

“How would I design, secure, and troubleshoot this in a live environment?”

1. The Network Administration Lifecycle

Every network follows a predictable cycle of planning, deployment, monitoring, and maintenance. Here’s how it maps to your syllabus:

Topology, IP scheme (VLSM), DNS zonesDHCP scopes, firewall rules, Apache/Nginx configPacket traces, DNS lookups, SMTP relay checksBandwidth usage (NTC traffic), log analysisPatches, SDN updates, backup validationPlanningDesignImplementationTestingMonitoringMaintenance
Network Administration Lifecycle (Ncell 4G rollout example)

Key Idea: Your exam may ask you to trace a single issue (e.g., “Why is eSewa’s payment gateway timing out?”) through this cycle. Start at Planning and work forward.


2. Practical Implementation Scenarios

Scenario 1: Deploying a Secure Web Server for NEPSE

Problem: NEPSE needs a web server to host stock prices, but must block DDoS attacks and ensure HTTPS. Steps (using Units 3, 5, 7, 12):

  1. DNS (Unit 3): Configure a CNAME record for nepse.com pointing to web1.nepse.np (public IP: 203.127.128.1).
  2. Firewall (Unit 5):
    • Allow ports 80 (HTTP), 443 (HTTPS), and 53 (DNS).
    • Block ICMP (ping) to mitigate scans.
    • Rate-limit connections from a single IP (e.g., 100 requests/minute).
  3. Web Server (Unit 7):
    • Use Nginx with:
      server {
          listen 443 ssl;
          server_name nepse.com;
          ssl_certificate /etc/letsencrypt/live/nepse.com/fullchain.pem;
          ssl_certificate_key /etc/letsencrypt/live/nepse.com/privkey.pem;
          location / {
              proxy_pass http://localhost:8000; # Python/Flask backend
          }
      }
      
  4. SDN (Unit 12): Use OpenFlow to dynamically reroute traffic if web1 fails to web2 (active-active).

Visual: NEPSE’s Secure Web Flow

sequenceDiagram
    participant Client
    participant DNS_Server
    participant Firewall
    participant Nginx
    participant App_Server
    Client->>DNS_Server: A nepse.com (DNS query)
    DNS_Server-->>Client: 203.127.128.1 (A record)
    Client->>Firewall: SYN to 443
    Firewall-->>Client: SYN-ACK (rate-limited)
    Client->>Firewall: HTTPS handshake
    Firewall->>Nginx: Forward encrypted traffic
    Nginx->>App_Server: Proxy request
    App_Server-->>Nginx: JSON response
    Nginx-->>Client: HTTPS response

Real-World Tie: NEPSE’s actual system uses load balancers (like HAProxy) and WAFs (Web Application Firewalls) to handle 10,000+ concurrent users during trading hours.


Scenario 2: Troubleshooting Pathao’s Ride-Hailing Network

Problem: Pathao drivers report “No Internet” when near Kathmandu’s busy intersections. Root Cause Analysis (Units 2, 4, 10, 11):

  1. IP Exhaustion (Unit 2): Pathao’s office uses /24 (254 IPs), but roaming devices (e.g., tablets) need more. Solution: Subnet into /26 (62 IPs per subnet) for different teams.
  2. DHCP Lease Conflicts (Unit 4): Static IPs for printers clash with dynamic leases. Solution: Reserve IPs for printers in DHCP scope.
  3. Bandwidth Throttling (Unit 11): Video calls from drivers saturate the uplink. Solution:
    • Prioritize VoIP (SIP) over YouTube with QoS policies.
    • Use multicast for live traffic updates (e.g., road closures).
  4. Monitoring (Unit 10): Check iftop to confirm 90% of traffic is YouTube. Fix: Block non-work-related sites during peak hours.
HTTPS (443)Internal (8080)MySQL (3306)PCI-Compliant (443)Driver AppLoad BalancerAPI ServerDatabasePayment Gateway
Pathao’s High-Availability Architecture

Visual: Pathao’s Subnetting Plan


Real-World Tie: Pathao’s centralized logging (ELK Stack) flags DHCP conflicts by correlating syslog messages with driver app crashes.


Scenario 3: eSewa’s Payment Gateway Security

Problem: Fraudsters exploit weak authentication in eSewa’s API. Security Hardening (Units 5, 6, 12):

  1. Firewall Rules (Unit 5):
    • Block all inbound traffic except:
      • 443 (HTTPS) from known IPs (e.g., 103.4.92.0/24 for Ncell).
      • 22 (SSH) only from admin IPs (e.g., 192.168.1.100).
  2. Email Security (Unit 6):
    • Reject SMTP relays without TLS.
    • Use SPF/DKIM/DMARC to prevent spoofed “password reset” emails.
  3. SDN Microsegmentation (Unit 12):
    • Isolate the payment database from the web server using OpenFlow rules.
    • Example rule: “Drop all traffic from web-server to db-server unless port 3306 (MySQL) and source IP is whitelisted.”

Visual: eSewa’s Firewall Policy

HTTPS (443)DROP (all other ports)ClientFirewallWeb Server (192.168.1.100)DB Server (192.168.1.50)API (103.4.92.5)
eSewa SDN Microsegmentation Rules (OpenFlow)

Real-World Tie: eSewa’s two-factor authentication (2FA) uses TOTP (Time-based One-Time Password) via the Google Authenticator app, which relies on symmetric encryption (AES-256) for key exchange.


3. Hands-On Lab Skills for Exams

A. Packet Tracing (Units 2, 5, 10)

Tool: tcpdump or Wireshark. Example: Capture traffic from a failed nslookup nepalbank.com:

sudo tcpdump -i eth0 port 53 -w nepalbank_dns.pcap

What to Look For:

  • Is the query reaching the DNS server? (Check for UDP 53 packets.)
  • Are responses being dropped by the firewall? (Check ICMP Destination Unreachable.)

Visual: DNS Query Failure

ClientUDP 53 QueryRouterForwardedFirewallDROP (ACL)DNS ServerNo Response
DNS Query Failure Path (NepalBank.com)

B. Configuring a Linux Server (Units 7, 9, 13)

Task: Set up a mail server with SMTP + IMAP for a company like Ncell.

  1. Install Postfix (SMTP) and Dovecot (IMAP):
    sudo apt install postfix dovecot-core
    
  2. Configure /etc/postfix/main.cf:
    myhostname = mail.ncell.com
    mydomain = ncell.com
    inet_interfaces = all
    mydestination = $myhostname, localhost.$mydomain, localhost
    
  3. Restart services:
    sudo systemctl restart postfix dovecot
    
  4. Test:
    telnet mail.ncell.com 25  # Should show SMTP banner
    

Visual: Linux Mail Server Stack



C. Bandwidth Management (Unit 11)

Problem: NTC’s fiber link to Pokhara is saturated during peak hours (6–9 PM). Solution: Use tc (Linux traffic control) to prioritize VoIP:

sudo tc qdisc add dev eth0 root handle 1: htb default 30
sudo tc class add dev eth0 parent 1: classid 1:1 htb rate 100mbit
sudo tc class add dev eth0 parent 1:1 classid 1:10 htb rate 20mbit prio 1  # VoIP (SIP)
sudo tc class add dev eth0 parent 1:1 classid 1:20 htb rate 80mbit prio 2  # HTTP/HTTPS

Visual: Bandwidth Allocation

020406080VoIP (SIP)20HTTP/HTTPS80Other0
NTC 100 Mbps Link Allocation (tc command example)

4. Common Pitfalls in Exams

Mistake Why It’s Wrong How to Fix
Ignoring subnet masks in DHCP Leads to IP conflicts (e.g., 192.168.1.1/24 vs /26). Always specify /24 or /26 in scope.
Open SSH ports to the internet Brute-force attacks (e.g., Pathao’s old system). Restrict to VPN or admin IPs only.
Using HTTP instead of HTTPS Data leaks (e.g., eSewa transactions). Enforce TLS 1.2+ with Let’s Encrypt.
No logging for critical services Hard to debug (e.g., NEPSE crashes). Enable syslog + rsyslog forwarding.
Static routes without failover Single point of failure (e.g., NTC link). Use BGP or OSPF for redundancy.

In the Real World

  1. eSewa’s Payment Gateway

    • Idea Used: Multi-layer security (Units 5, 6, 12)
    • How: Combines:
      • Firewall rules to block non-HTTPS traffic.
      • SMTP SPF/DKIM to prevent phishing emails.
      • SDN microsegmentation to isolate the database.
    • Result: Reduced fraud by 60% in 2023.
  2. Ncell’s 4G Network

    • Idea Used: VLSM + QoS (Units 2, 11)
    • How:
      • Subnets /24 into /28 for cell towers to save IPs.
      • Prioritizes VoLTE (voice) over YouTube with tc/htb.
    • Result: 40% faster call setup during peak hours.
  3. NEPSE’s Stock Data Feed

    • Idea Used: Load Balancing + Multicast (Units 7, 11)
    • How:
      • Uses Nginx + HAProxy to distribute traffic across 3 servers.
      • Broadcasts real-time prices via multicast UDP (port 1234) to reduce server load.
    • Result: Handles 5,000+ concurrent traders without lag.

Exam Tip

05101519Source IP32 bitsDestination IP32 bitsProtocol8 bitsPort16 bitsAction8 bitsPriority8 bits
ACL Rule Structure (Cisco-style)

What Examiners Look For

  1. Step-by-Step Reasoning

    • Don’t jump to conclusions. For example, if asked “Why is Daraz’s checkout slow?”, trace:
      • Layer 1: Is the fiber link saturated? (Check iftop.)
      • Layer 3: Are there IP conflicts? (ip a, arp -a.)
      • Layer 7: Is the PHP backend timing out? (tail -f /var/log/apache2/error.log.)
  2. Real-World Context

    • Always tie answers to Nepali companies (e.g., “Like Pathao’s drivers, NTC technicians use static IPs for routers to avoid DHCP conflicts.”).
  3. Configuration Snippets

    • For Apache/Nginx/DHCP, include 1–2 lines of config in your answer. Example:
      server {
          listen 443 ssl;
          ssl_certificate /etc/letsencrypt/live/daraz.com/fullchain.pem;
      }
      
  4. Visual Proof

    • Draw a simple diagram (even a Mermaid table) to show your logic. Example for a failed DNS lookup:
  5. Common Exam Questions

    • Scenario-Based: “Design a network for a bank with 5 branches.” (Use VLSM + DHCP + firewall rules.)
    • Troubleshooting: “A user can’t access khalti.com. Debug step-by-step.” (Check DNS → Firewall → Routing.)
    • Configuration: “Write the DHCP config for a /26 subnet with 3 static IPs.”

Final Advice: Treat this unit like a network admin’s “cheat sheet.” Memorize:

  • Key commands: tcpdump, iptables, nslookup, dig.
  • Ports: 22 (SSH), 53 (DNS), 80/443 (HTTP/HTTPS), 25 (SMTP).
  • Protocols: DHCP (UDP 67/68), DNS (UDP 53), SMTP (TCP 25).

Practice: Set up a home lab with:

  • 2 VMs (Ubuntu + Windows).
  • A router (use iptables on Linux).
  • Test connectivity between them using ping, traceroute, and curl.

Based on the TU BIT syllabus for Network and System Administration (BIT451), unit 14.

Discussion

Loading…