Chuyển đến nội dung chính

VyOS from Basics to Advanced

A comprehensive course on VyOS — a powerful open-source network operating system. From installation and basic configuration to firewall, VPN, advanced routing (BGP/OSPF), High Availability, VLANs, WireGuard, and real-world production deployment.

Lesson 1: Introduction to VyOS and Installation

  • What is VyOS? History from Vyatta → VyOS
  • VyOS vs pfSense vs OPNsense vs MikroTik comparison
  • System architecture and configuration model (configuration tree)
  • Downloading and installing on VM (KVM/VirtualBox/Proxmox) and bare-metal
  • Basic CLI: configure, commit, save, show, compare
  • Lab: Install VyOS on VirtualBox, SSH in for management

Lesson 2: Interface Configuration and Basic IP

  • Configuring Ethernet interfaces (set interfaces ethernet ethX)
  • Static IP and DHCP client
  • User management, authentication, SSH keys
  • Hostname, timezone, NTP
  • System backup/restore configuration
  • Lab: Set up a 2-interface router (WAN + LAN)

Lesson 3: NAT — Source NAT, Destination NAT and Masquerade

  • What is NAT? Why do we need NAT?
  • Source NAT (masquerade) — for LAN to access the internet
  • Destination NAT — port forwarding to internal servers
  • 1:1 NAT and NPTv6
  • NAT rules ordering and priority
  • Lab: Configure masquerade + HTTP/SSH port forwarding

Lesson 4: Basic Firewall — Rules, Chains and Groups

  • VyOS firewall architecture (nftables backend)
  • Input, output, forward chains
  • Firewall rules: accept, drop, reject, log
  • Address-group, network-group, port-group
  • Applying firewall to interfaces (in/out/local)
  • Default policy and rule ordering
  • Lab: Protect router + allow LAN to access the internet

Lesson 5: Zone-based Firewall

  • Zone-policy concepts in VyOS
  • Designing zones: LAN, WAN, DMZ, GUEST
  • Inter-zone traffic rules
  • Zone-based vs interface-based firewall comparison
  • Network segmentation best practices
  • Lab: Set up zone-policy for a 3-zone home network

Lesson 6: DHCP Server, DNS Forwarding and NTP

  • DHCP Server: pools, ranges, static leases, options
  • DHCPv6 server and SLAAC
  • DHCP relay
  • DNS forwarding with local cache
  • Static DNS entries (host overrides)
  • NTP server for LAN clients
  • Lab: Complete DHCP + DNS for an internal network

Lesson 7: VLANs, Bonding and Bridge

  • 802.1Q VLANs: creating sub-interfaces (eth0.10, eth0.20)
  • Inter-VLAN routing (router-on-a-stick)
  • Interface bonding (LACP 802.3ad)
  • Bridge interfaces
  • Combining VLANs + firewall zones
  • Lab: Separate LAN/GUEST/IoT networks using VLANs

Lesson 8: Static Routing and Policy-Based Routing

  • Static routes and default gateway
  • Blackhole routes and failover routes
  • Policy-Based Routing (PBR): route-map, routing tables
  • Multiple uplinks: route by source IP
  • Transparent proxy routing
  • VRF (Virtual Routing and Forwarding) basics
  • Lab: Dual-WAN with PBR + failover

Lesson 9: Dynamic Routing — OSPF

  • OSPF fundamentals: areas, LSA, cost
  • Configuring OSPF on VyOS (single area and multi-area)
  • OSPF unnumbered with ECMP
  • Route redistribution
  • Passive interfaces and authentication
  • Troubleshooting: show ip ospf neighbor/route/database
  • Lab: OSPF with 3 VyOS routers, multi-area

Lesson 10: Dynamic Routing — BGP

  • BGP fundamentals: AS, iBGP vs eBGP
  • Configuring BGP neighbors on VyOS
  • Route-maps, prefix-lists, AS-path filtering
  • AS-path prepending and BGP communities
  • Route Reflector
  • BGP IPv6 unnumbered with extended nexthop
  • Lab: BGP peering between 2 ASes with route-map

Lesson 11: VPN — WireGuard and OpenVPN

  • WireGuard site-to-site: key generation, peer config
  • WireGuard remote access VPN
  • OpenVPN site-to-site with pre-shared key
  • OpenVPN remote access with certificates
  • WireGuard vs OpenVPN vs IPsec comparison
  • Routing traffic through VPN tunnels
  • Lab: WireGuard site-to-site between 2 VyOS routers

Lesson 12: VPN — IPsec Site-to-Site

  • IPsec fundamentals: IKEv2, ESP, SA, proposals
  • Policy-based vs route-based (VTI) VPN
  • Site-to-site IPsec between 2 VyOS routers
  • IPsec VPN to Cisco, Palo Alto, Azure
  • DMVPN dual hub topology
  • Troubleshooting IPsec tunnels
  • Lab: Route-based IPsec VPN with BGP overlay

Lesson 13: High Availability — VRRP and Conntrack Sync

  • VRRP (Virtual Router Redundancy Protocol)
  • Active-passive HA: priorities, preemption
  • Conntrack-sync to preserve sessions during failover
  • Configuration sync between HA pair
  • Failover testing and validation
  • HA design: VM primary + physical backup
  • Lab: HA pair VyOS with VRRP + conntrack-sync

Lesson 14: WAN Load Balancing, QoS and Monitoring

  • WAN load balancing: distribute, failover, weights
  • Interface health checks (ping/HTTP)
  • QoS with CAKE, HTB, traffic shaping
  • Traffic prioritization (VoIP, gaming, work)
  • NetFlow/sFlow monitoring
  • SNMP, Prometheus exporter, Telegraf
  • Syslog and syslog over TLS
  • Lab: Dual-WAN load balancing + QoS for home

Lesson 15: Containers, Automation and Production Best Practices

  • Running containers (Podman) on VyOS
  • Ansible automation for VyOS
  • VyOS HTTP API
  • Scripting and custom op-mode commands
  • Backup strategies and config versioning
  • Image upgrade and rollback
  • Security hardening checklist
  • Real-world production deployment scenarios
  • Lab: Ansible playbook to deploy full VyOS config