Network and System AdministrationUnit 1411 min read
Review & Practical Implementation: Network Admin Mastery
Unit 14 of Network and System Administration synthesizes all 13 prior units into a comprehensive review of network administration concepts, practical troubleshooting scenarios, and hands-on implementation strategies for real-world systems like eSewa, Ncell, and NEPSE. Students will integrate IP subnetting, DNS, DHCP, s
Core Concepts Review: The Big Picture
Network administration is not just memorizing protocols—it’s about connecting the dots between theory and real-world deployment. This unit forces you to revisit every unit (1–13) and ask:
“How would I design, secure, and troubleshoot this in a live environment?”
1. The Network Administration Lifecycle
Every network follows a predictable cycle of planning, deployment, monitoring, and maintenance. Here’s how it maps to your syllabus:
Key Idea: Your exam may ask you to trace a single issue (e.g., “Why is eSewa’s payment gateway timing out?”) through this cycle. Start at Planning and work forward.
2. Practical Implementation Scenarios
Scenario 1: Deploying a Secure Web Server for NEPSE
Problem: NEPSE needs a web server to host stock prices, but must block DDoS attacks and ensure HTTPS. Steps (using Units 3, 5, 7, 12):
- DNS (Unit 3): Configure a
CNAMErecord fornepse.compointing toweb1.nepse.np(public IP:203.127.128.1). - Firewall (Unit 5):
- Allow ports
80(HTTP),443(HTTPS), and53(DNS). - Block ICMP (ping) to mitigate scans.
- Rate-limit connections from a single IP (e.g., 100 requests/minute).
- Allow ports
- Web Server (Unit 7):
- Use Nginx with:
server { listen 443 ssl; server_name nepse.com; ssl_certificate /etc/letsencrypt/live/nepse.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/nepse.com/privkey.pem; location / { proxy_pass http://localhost:8000; # Python/Flask backend } }
- Use Nginx with:
- SDN (Unit 12): Use OpenFlow to dynamically reroute traffic if
web1fails toweb2(active-active).
Visual: NEPSE’s Secure Web Flow
sequenceDiagram
participant Client
participant DNS_Server
participant Firewall
participant Nginx
participant App_Server
Client->>DNS_Server: A nepse.com (DNS query)
DNS_Server-->>Client: 203.127.128.1 (A record)
Client->>Firewall: SYN to 443
Firewall-->>Client: SYN-ACK (rate-limited)
Client->>Firewall: HTTPS handshake
Firewall->>Nginx: Forward encrypted traffic
Nginx->>App_Server: Proxy request
App_Server-->>Nginx: JSON response
Nginx-->>Client: HTTPS responseReal-World Tie: NEPSE’s actual system uses load balancers (like HAProxy) and WAFs (Web Application Firewalls) to handle 10,000+ concurrent users during trading hours.
Scenario 2: Troubleshooting Pathao’s Ride-Hailing Network
Problem: Pathao drivers report “No Internet” when near Kathmandu’s busy intersections. Root Cause Analysis (Units 2, 4, 10, 11):
- IP Exhaustion (Unit 2): Pathao’s office uses
/24(254 IPs), but roaming devices (e.g., tablets) need more. Solution: Subnet into/26(62 IPs per subnet) for different teams. - DHCP Lease Conflicts (Unit 4): Static IPs for printers clash with dynamic leases. Solution: Reserve IPs for printers in DHCP scope.
- Bandwidth Throttling (Unit 11): Video calls from drivers saturate the uplink. Solution:
- Prioritize VoIP (SIP) over YouTube with QoS policies.
- Use multicast for live traffic updates (e.g., road closures).
- Monitoring (Unit 10): Check
iftopto confirm 90% of traffic is YouTube. Fix: Block non-work-related sites during peak hours.
Visual: Pathao’s Subnetting Plan
Real-World Tie: Pathao’s centralized logging (ELK Stack) flags DHCP conflicts by correlating syslog messages with driver app crashes.
Scenario 3: eSewa’s Payment Gateway Security
Problem: Fraudsters exploit weak authentication in eSewa’s API. Security Hardening (Units 5, 6, 12):
- Firewall Rules (Unit 5):
- Block all inbound traffic except:
443(HTTPS) from known IPs (e.g.,103.4.92.0/24for Ncell).22(SSH) only from admin IPs (e.g.,192.168.1.100).
- Block all inbound traffic except:
- Email Security (Unit 6):
- Reject SMTP relays without TLS.
- Use SPF/DKIM/DMARC to prevent spoofed “password reset” emails.
- SDN Microsegmentation (Unit 12):
- Isolate the payment database from the web server using OpenFlow rules.
- Example rule: “Drop all traffic from
web-servertodb-serverunless port3306(MySQL) and source IP is whitelisted.”
Visual: eSewa’s Firewall Policy
Real-World Tie: eSewa’s two-factor authentication (2FA) uses TOTP (Time-based One-Time Password) via the Google Authenticator app, which relies on symmetric encryption (AES-256) for key exchange.
3. Hands-On Lab Skills for Exams
A. Packet Tracing (Units 2, 5, 10)
Tool: tcpdump or Wireshark.
Example: Capture traffic from a failed nslookup nepalbank.com:
sudo tcpdump -i eth0 port 53 -w nepalbank_dns.pcap
What to Look For:
- Is the query reaching the DNS server? (Check for
UDP 53packets.) - Are responses being dropped by the firewall? (Check
ICMP Destination Unreachable.)
Visual: DNS Query Failure
B. Configuring a Linux Server (Units 7, 9, 13)
Task: Set up a mail server with SMTP + IMAP for a company like Ncell.
- Install Postfix (SMTP) and Dovecot (IMAP):
sudo apt install postfix dovecot-core - Configure
/etc/postfix/main.cf:myhostname = mail.ncell.com mydomain = ncell.com inet_interfaces = all mydestination = $myhostname, localhost.$mydomain, localhost - Restart services:
sudo systemctl restart postfix dovecot - Test:
telnet mail.ncell.com 25 # Should show SMTP banner
Visual: Linux Mail Server Stack
C. Bandwidth Management (Unit 11)
Problem: NTC’s fiber link to Pokhara is saturated during peak hours (6–9 PM).
Solution: Use tc (Linux traffic control) to prioritize VoIP:
sudo tc qdisc add dev eth0 root handle 1: htb default 30
sudo tc class add dev eth0 parent 1: classid 1:1 htb rate 100mbit
sudo tc class add dev eth0 parent 1:1 classid 1:10 htb rate 20mbit prio 1 # VoIP (SIP)
sudo tc class add dev eth0 parent 1:1 classid 1:20 htb rate 80mbit prio 2 # HTTP/HTTPS
Visual: Bandwidth Allocation
4. Common Pitfalls in Exams
| Mistake | Why It’s Wrong | How to Fix |
|---|---|---|
| Ignoring subnet masks in DHCP | Leads to IP conflicts (e.g., 192.168.1.1/24 vs /26). |
Always specify /24 or /26 in scope. |
| Open SSH ports to the internet | Brute-force attacks (e.g., Pathao’s old system). | Restrict to VPN or admin IPs only. |
| Using HTTP instead of HTTPS | Data leaks (e.g., eSewa transactions). | Enforce TLS 1.2+ with Let’s Encrypt. |
| No logging for critical services | Hard to debug (e.g., NEPSE crashes). | Enable syslog + rsyslog forwarding. |
| Static routes without failover | Single point of failure (e.g., NTC link). | Use BGP or OSPF for redundancy. |
In the Real World
eSewa’s Payment Gateway
- Idea Used: Multi-layer security (Units 5, 6, 12)
- How: Combines:
- Firewall rules to block non-HTTPS traffic.
- SMTP SPF/DKIM to prevent phishing emails.
- SDN microsegmentation to isolate the database.
- Result: Reduced fraud by 60% in 2023.
Ncell’s 4G Network
- Idea Used: VLSM + QoS (Units 2, 11)
- How:
- Subnets
/24into/28for cell towers to save IPs. - Prioritizes VoLTE (voice) over YouTube with
tc/htb.
- Subnets
- Result: 40% faster call setup during peak hours.
NEPSE’s Stock Data Feed
- Idea Used: Load Balancing + Multicast (Units 7, 11)
- How:
- Uses Nginx + HAProxy to distribute traffic across 3 servers.
- Broadcasts real-time prices via multicast UDP (port
1234) to reduce server load.
- Result: Handles 5,000+ concurrent traders without lag.
Exam Tip
What Examiners Look For
Step-by-Step Reasoning
- Don’t jump to conclusions. For example, if asked “Why is Daraz’s checkout slow?”, trace:
- Layer 1: Is the fiber link saturated? (Check
iftop.) - Layer 3: Are there IP conflicts? (
ip a,arp -a.) - Layer 7: Is the PHP backend timing out? (
tail -f /var/log/apache2/error.log.)
- Layer 1: Is the fiber link saturated? (Check
- Don’t jump to conclusions. For example, if asked “Why is Daraz’s checkout slow?”, trace:
Real-World Context
- Always tie answers to Nepali companies (e.g., “Like Pathao’s drivers, NTC technicians use static IPs for routers to avoid DHCP conflicts.”).
Configuration Snippets
- For Apache/Nginx/DHCP, include 1–2 lines of config in your answer. Example:
server { listen 443 ssl; ssl_certificate /etc/letsencrypt/live/daraz.com/fullchain.pem; }
- For Apache/Nginx/DHCP, include 1–2 lines of config in your answer. Example:
Visual Proof
- Draw a simple diagram (even a Mermaid table) to show your logic. Example for a failed DNS lookup:
Common Exam Questions
- Scenario-Based: “Design a network for a bank with 5 branches.” (Use VLSM + DHCP + firewall rules.)
- Troubleshooting: “A user can’t access
khalti.com. Debug step-by-step.” (Check DNS → Firewall → Routing.) - Configuration: “Write the DHCP config for a
/26subnet with 3 static IPs.”
Final Advice: Treat this unit like a network admin’s “cheat sheet.” Memorize:
- Key commands:
tcpdump,iptables,nslookup,dig. - Ports:
22(SSH),53(DNS),80/443(HTTP/HTTPS),25(SMTP). - Protocols: DHCP (UDP 67/68), DNS (UDP 53), SMTP (TCP 25).
Practice: Set up a home lab with:
- 2 VMs (Ubuntu + Windows).
- A router (use
iptableson Linux). - Test connectivity between them using
ping,traceroute, andcurl.
Based on the TU BIT syllabus for Network and System Administration (BIT451), unit 14.
Discussion
Loading…