Personal and academic laboratory work performed on isolated virtual systems.
CASE STUDY / Defensive laboratory
Cybersecurity Network Lab
A segmented environment for practicing defensive network engineering.
A concise technical study of how a virtual enterprise-style lab supports repeatable firewall, IDS and traffic-analysis exercises.
01 / Overview
From context to a defensible security objective.
Build a safe environment for observing traffic, validating segmentation decisions and documenting defensive controls.
- DMZ and internal zones
- Firewall policy validation
- IDS alert review
- Controlled discovery
- Laboratory environmentCreated a reusable environment for controlled network-security validation.
- Validation workflowSeparated observation, testing and remediation into repeatable steps.
02 / Methodology
A repeatable path from discovery to validation.
- 01Design
- 02Build
- 03Baseline
- 04Test
- 05Observe
- 06Harden
- 07Retest
03 / Architecture
Security boundaries made understandable.
A fictitious topology designed for repeatable exercises rather than production use.
Laboratory path
- Internet simulation
- pfSense
- DMZ
- Internal network
- Monitoring
Illustrative architecture only — no real organization, internal address, hostname or confidential topology is represented.
Tools
- GNS3
- VMware
- pfSense
- Snort
- Wireshark
- Nmap
- Linux
Security frameworks
- NIST CSF 2.0
- Defense in depth
06 / Lessons learned
What the work changed in the way security is approached.
A firewall rule is not validated until both allowed and denied paths are tested.
Baselines make IDS alerts easier to interpret and tune.