Semester: winter 2021/22
Lectures: Wednesday, 14:00 - 15:30, S3 (Vojtěch Aschenbrenner)
  Tuesday, 10:40 - 12:10, SU2 (Vojtěch Aschenbrenner)
  Thursday, 15:40 - 17:10, SU2 (Vojtěch Aschenbrenner)
Page in SIS: NSWI106
Grading: Graded credit
Mailing list: | Registration | Archive



Date Topic Mandatory Before Class Preparation
29.9. Introduction, Networking basics, Test 0
6.10. Arch Linux Installation Guide, Test 1
13.10. Software Defined Networking, Test 2
20.10. Systemd, Test 3 systemd, systemd-networkd, Network Configuration, systemd-resolved, systemd/Journald, QEMU/Networking, qemu(1), vde_switch(1)
27.10. Routing, Packet filtering, DNS, Test 4 BGP, Router, Internet Sharing, NAT, DNS, Unbound, NSD
3.11. DNS cont’d, Paper, How DNSSEC Works, DNSVIZ.
10.11. DNSSEC, Test 5
24.11. E-mail, Test 6 Remind yourself how e-mail works and what MUA, MDA and MTA is. Have a practical knowledge about SMTP and IMAP. Examine headers of e-mails in your inbox. Be able to send e-mail via telnet.
1.12. E-mail Discussion Please come with questions and issues you experienced during e-mail system setup.
8.12. IPv6, DNSSEC Canceled due to illness.
On Zoom
Storage Aaron Toponce - ZFS Administration, Journaling file system, Copy-on-write, Btrfs
On Zoom
Basic security, firewalls, containers, monitoring, cloud providers, specialized OS distributions… (Part 1/2)
On Zoom
Basic security, firewalls, containers, monitoring, cloud providers, specialized OS distributions… (Part 2/2)


Date Topic Goal (Homework)
Introduction, SSH, text editors, efficient command line, QEMU, VNC. Pick and learn how to efficiently use a text editor and shell. SSH to {c,d,e,f} servers with a short command, e.g. ssh c. Boot QEMU VM (on one of the servers) with any Linux LiveCD and connect to it via VNC. 1 point
Arch Linux Installation QEMU VM with installed Arch Linux and working networking setup. 1 point
Backbone Connection with VDE Connect VM to the backbone switch. Be able to SSH inside the VM. 1 point
Subnetworks The already installed VM is a router connected to backbone. Create 2 private vde switches and connect them to the router. Add 2 more VMs (VM2, VM3) connected to each of private switches. Be able to ping between VM2 and VM3. 1 point
Bird, BGP, DNS Working BGP, i.e. export own routes and import all available routes. Be able to ping VMs in private subnets of other students. Install recursive DNS server unbound and use it as your default DNS server for all VMs. Bonus: Install authoritative DNS server nsd and be able to resolve router.login.una IN A, i.e. drill a router.login.una @<nsd-ip>. 1+1 point
Authoritative DNS Primary nsd installed on 10.0.X.2 and secondary on 10.0.100+X.2 with AXFR enabled. {ns1,ns2,router}.login.una. IN A records and login.una. IN TXT record. TXT record should contain your X in X=<your X> format. .una domain has a root server at Add it as a stub to your unbound so it can resolve all .una domains. Try drill login.una @ and read response carefully. 1 point
Management and cleanup. Come with questions about tasks we already did! Create scripts to simplify management of your infrastructure. I.e. be prepared to quickly restore your infrastructure after hypervisor shutdown. Bonus: Automate creating new VMs with Ansible (or similar technology). 1+1 point
E-mail 1/2 Deploy Postfix and Dovecot to have working mail system at least for login@login.una. Store your emails in Maildir format and use plain text files for configuration. I.e. no database deployment. TLS is not mandatory. 0. Setup DNS. 1. Receive e-mails via SMTP (port 25). 2. Get e-mails via IMAP (port 993). 3. Send e-mails via submission (port 587). 4. Be able to use Thunderbird to send/receive e-mails. 5. Configure backup mail server (just postfix with relay_domains options). Debug tools: offlineimap, msmtp, swaks, telnet. 4 points
E-mail 2/2 This lab is intended as a consultation for your work-in-progress e-mail configuration. The e-mail task is due the upcoming labs.
IPv6, DNSSEC Cancelled due to illness.
On Zoom
Storage 1. Attach 5x 1GB drive. 2. Setup MD-RAID (raid6) on all drives. 3. Encrypt the whole raid block device with LUKS. 4. Create LVM over the encrypted block device. 5. Create 3 logical volumes (LVs). 6. Format each logical volume with filesystem (xfs or ext4). 7. Try to boot with one “failed” drive disconnected. 8. Repair the array by connecting a new drive. 2 points
Bonus: 1. Attach 5x 1GB drive. 2. Format drives with btrfs (data raid5, metadata raid1). Enable compression and autodefrag. Create several subvolumes. 3. Simulate drive failure and drive replacement as before. Don’t forget to balance data. 4. Install snapper or btrbk and setup snapshotting every hour. 5. Send some snapshots to different machine. +2 points
21.12. Canceled Synchronization with another group
On Zoom
Basic security, firewalls, containers, monitoring, cloud providers, specialized OS distributions… Setup a simple firewall on your router. Rules for dropping all the trafic have to be present on INPUT and FORWARD chains. All services must continue to work. 2 points, deadline is whenever you want your grade


Grade Percent
1 >84%
2 75% – 84%
3 65% – 74%
4 <65%


man(1), ArchWiki, Google

25 Gigabit Linux internet router PC build How to send and reply to email


In the Introduction to Linux course you learned the absolute essentials for becoming a modern programmer. In this course you will learn topics, where Linux is the most advanced operating system in the world and why/where is used by companies like Google, Facebook, Microsoft, Twitter and simply said everyone.

What to expect from the class

Previous year

You can take a look at the course content from winter semester 2020/21. The content will be slightly changed.