Courses DevSecOps A comprehensive course on VyOS — a powerful open-source network operating system. From installation and basic configuration to firewall, VPN, advanced routing (BGP/OSPF), High Availability, VLANs, WireGuard, and real-world production deployment.
Quick language switch 🇻🇳 Tiếng Việt 🇺🇸 English 🇯🇵 日本語 🇹🇼 繁體中文 Lesson 1: Introduction to VyOS and Installation
What is VyOS? History from Vyatta → VyOS
VyOS vs pfSense vs OPNsense vs MikroTik comparison
System architecture and configuration model (configuration tree)
Downloading and installing on VM (KVM/VirtualBox/Proxmox) and bare-metal
Basic CLI: configure, commit, save, show, compare
Lab: Install VyOS on VirtualBox, SSH in for management
Lesson 2: Interface Configuration and Basic IP
Configuring Ethernet interfaces (set interfaces ethernet ethX)
Static IP and DHCP client
User management, authentication, SSH keys
Hostname, timezone, NTP
System backup/restore configuration
Lab: Set up a 2-interface router (WAN + LAN)
Lesson 3: NAT — Source NAT, Destination NAT and Masquerade
What is NAT? Why do we need NAT?
Source NAT (masquerade) — for LAN to access the internet
Destination NAT — port forwarding to internal servers
1:1 NAT and NPTv6
NAT rules ordering and priority
Lab: Configure masquerade + HTTP/SSH port forwarding
Lesson 4: Basic Firewall — Rules, Chains and Groups
VyOS firewall architecture (nftables backend)
Input, output, forward chains
Firewall rules: accept, drop, reject, log
Address-group, network-group, port-group
Applying firewall to interfaces (in/out/local)
Default policy and rule ordering
Lab: Protect router + allow LAN to access the internet
Lesson 5: Zone-based Firewall
Zone-policy concepts in VyOS
Designing zones: LAN, WAN, DMZ, GUEST
Inter-zone traffic rules
Zone-based vs interface-based firewall comparison
Network segmentation best practices
Lab: Set up zone-policy for a 3-zone home network
Lesson 6: DHCP Server, DNS Forwarding and NTP
DHCP Server: pools, ranges, static leases, options
DHCPv6 server and SLAAC
DHCP relay
DNS forwarding with local cache
Static DNS entries (host overrides)
NTP server for LAN clients
Lab: Complete DHCP + DNS for an internal network
Lesson 7: VLANs, Bonding and Bridge
802.1Q VLANs: creating sub-interfaces (eth0.10, eth0.20)
Inter-VLAN routing (router-on-a-stick)
Interface bonding (LACP 802.3ad)
Bridge interfaces
Combining VLANs + firewall zones
Lab: Separate LAN/GUEST/IoT networks using VLANs
Lesson 8: Static Routing and Policy-Based Routing
Static routes and default gateway
Blackhole routes and failover routes
Policy-Based Routing (PBR): route-map, routing tables
Multiple uplinks: route by source IP
Transparent proxy routing
VRF (Virtual Routing and Forwarding) basics
Lab: Dual-WAN with PBR + failover
Lesson 9: Dynamic Routing — OSPF
OSPF fundamentals: areas, LSA, cost
Configuring OSPF on VyOS (single area and multi-area)
OSPF unnumbered with ECMP
Route redistribution
Passive interfaces and authentication
Troubleshooting: show ip ospf neighbor/route/database
Lab: OSPF with 3 VyOS routers, multi-area
Lesson 10: Dynamic Routing — BGP
BGP fundamentals: AS, iBGP vs eBGP
Configuring BGP neighbors on VyOS
Route-maps, prefix-lists, AS-path filtering
AS-path prepending and BGP communities
Route Reflector
BGP IPv6 unnumbered with extended nexthop
Lab: BGP peering between 2 ASes with route-map
Lesson 11: VPN — WireGuard and OpenVPN
WireGuard site-to-site: key generation, peer config
WireGuard remote access VPN
OpenVPN site-to-site with pre-shared key
OpenVPN remote access with certificates
WireGuard vs OpenVPN vs IPsec comparison
Routing traffic through VPN tunnels
Lab: WireGuard site-to-site between 2 VyOS routers
Lesson 12: VPN — IPsec Site-to-Site
IPsec fundamentals: IKEv2, ESP, SA, proposals
Policy-based vs route-based (VTI) VPN
Site-to-site IPsec between 2 VyOS routers
IPsec VPN to Cisco, Palo Alto, Azure
DMVPN dual hub topology
Troubleshooting IPsec tunnels
Lab: Route-based IPsec VPN with BGP overlay
Lesson 13: High Availability — VRRP and Conntrack Sync
VRRP (Virtual Router Redundancy Protocol)
Active-passive HA: priorities, preemption
Conntrack-sync to preserve sessions during failover
Configuration sync between HA pair
Failover testing and validation
HA design: VM primary + physical backup
Lab: HA pair VyOS with VRRP + conntrack-sync
Lesson 14: WAN Load Balancing, QoS and Monitoring
WAN load balancing: distribute, failover, weights
Interface health checks (ping/HTTP)
QoS with CAKE, HTB, traffic shaping
Traffic prioritization (VoIP, gaming, work)
NetFlow/sFlow monitoring
SNMP, Prometheus exporter, Telegraf
Syslog and syslog over TLS
Lab: Dual-WAN load balancing + QoS for home
Lesson 15: Containers, Automation and Production Best Practices
Running containers (Podman) on VyOS
Ansible automation for VyOS
VyOS HTTP API
Scripting and custom op-mode commands
Backup strategies and config versioning
Image upgrade and rollback
Security hardening checklist
Real-world production deployment scenarios
Lab: Ansible playbook to deploy full VyOS config
VyOS from Basics to Advanced