Chuyển đến nội dung chính
Cơ bản

VyOS từ Cơ bản đến Nâng cao

Khóa học toàn diện về VyOS — hệ điều hành mạng mã nguồn mở mạnh mẽ. Từ cài đặt, cấu hình cơ bản đến firewall, VPN, routing nâng cao (BGP/OSPF), High Availability, VLANs, WireGuard, và triển khai production thực tế.

DUY TRANDuy Tran
15 bài học
40 giờ
VyOS từ Cơ bản đến Nâng cao

Nội dung series

1 phần · 15 bài học

Bài 1: Giới thiệu VyOS và Cài đặt

  • VyOS là gì? Lịch sử từ Vyatta → VyOS
  • So sánh VyOS vs pfSense vs OPNsense vs MikroTik
  • Kiến trúc hệ thống và mô hình cấu hình (configuration tree)
  • Tải và cài đặt trên VM (KVM/VirtualBox/Proxmox) và bare-metal
  • CLI cơ bản: configure, commit, save, show, compare
  • Lab: Cài đặt VyOS trên VirtualBox, SSH vào quản lý

Bài 2: Cấu hình Interface và IP cơ bản

  • Cấu hình Ethernet interfaces (set interfaces ethernet ethX)
  • IP tĩnh và DHCP client
  • Quản lý users, authentication, SSH keys
  • Hostname, timezone, NTP
  • System backup/restore configuration
  • Lab: Thiết lập router 2 interface (WAN + LAN)

Bài 3: NAT — Source NAT, Destination NAT và Masquerade

  • NAT là gì? Tại sao cần NAT?
  • Source NAT (masquerade) — cho LAN truy cập internet
  • Destination NAT — port forwarding vào server nội bộ
  • 1:1 NAT và NPTv6
  • NAT rules ordering và priority
  • Lab: Cấu hình masquerade + port forward HTTP/SSH

Bài 4: Firewall cơ bản — Rules, Chains và Groups

  • Kiến trúc firewall VyOS (nftables backend)
  • Input, output, forward chains
  • Firewall rules: accept, drop, reject, log
  • Address-group, network-group, port-group
  • Áp dụng firewall lên interfaces (in/out/local)
  • Default policy và rule ordering
  • Lab: Bảo vệ router + cho phép LAN ra internet

Bài 5: Zone-based Firewall

  • Khái niệm zone-policy trong VyOS
  • Thiết kế zones: LAN, WAN, DMZ, GUEST
  • Inter-zone traffic rules
  • So sánh zone-based vs interface-based firewall
  • Best practices phân vùng mạng
  • Lab: Setup zone-policy cho mạng gia đình 3 zones

Bài 6: DHCP Server, DNS Forwarding và NTP

  • DHCP Server: pools, ranges, static leases, options
  • DHCPv6 server và SLAAC
  • DHCP relay
  • DNS forwarding với local cache
  • Static DNS entries (host overrides)
  • NTP server cho LAN clients
  • Lab: DHCP + DNS cho mạng nội bộ hoàn chỉnh

Bài 7: VLANs, Bonding và Bridge

  • 802.1Q VLANs: tạo sub-interfaces (eth0.10, eth0.20)
  • Inter-VLAN routing (router-on-a-stick)
  • Interface bonding (LACP 802.3ad)
  • Bridge interfaces
  • Kết hợp VLANs + firewall zones
  • Lab: Tách mạng LAN/GUEST/IoT bằng VLANs

Bài 8: Static Routing và Policy-Based Routing

  • Static routes và default gateway
  • Blackhole routes và failover routes
  • Policy-Based Routing (PBR): route-map, routing tables
  • Multiple uplinks: định tuyến theo source IP
  • Transparent proxy routing
  • VRF (Virtual Routing and Forwarding) cơ bản
  • Lab: Dual-WAN với PBR + failover

Bài 9: Dynamic Routing — OSPF

  • OSPF fundamentals: areas, LSA, cost
  • Cấu hình OSPF trên VyOS (single area và multi-area)
  • OSPF unnumbered với ECMP
  • Route redistribution
  • Passive interfaces và authentication
  • Troubleshooting: show ip ospf neighbor/route/database
  • Lab: OSPF 3 routers VyOS, multi-area

Bài 10: Dynamic Routing — BGP

  • BGP fundamentals: AS, iBGP vs eBGP
  • Cấu hình BGP neighbors trên VyOS
  • Route-maps, prefix-lists, AS-path filtering
  • AS-path prepending và BGP communities
  • Route Reflector
  • BGP IPv6 unnumbered với extended nexthop
  • Lab: BGP peering giữa 2 AS với route-map

Bài 11: VPN — WireGuard và OpenVPN

  • WireGuard site-to-site: key generation, peer config
  • WireGuard remote access VPN
  • OpenVPN site-to-site với pre-shared key
  • OpenVPN remote access với certificates
  • So sánh WireGuard vs OpenVPN vs IPsec
  • Routing traffic qua VPN tunnels
  • Lab: WireGuard site-to-site giữa 2 VyOS

Bài 12: VPN — IPsec Site-to-Site

  • IPsec fundamentals: IKEv2, ESP, SA, proposals
  • Policy-based vs route-based (VTI) VPN
  • Site-to-site IPsec giữa 2 VyOS
  • IPsec VPN tới Cisco, Palo Alto, Azure
  • DMVPN dual hub topology
  • Troubleshooting IPsec tunnels
  • Lab: Route-based IPsec VPN với BGP overlay

Bài 13: High Availability — VRRP và Conntrack Sync

  • VRRP (Virtual Router Redundancy Protocol)
  • Active-passive HA: priorities, preemption
  • Conntrack-sync giữ sessions khi failover
  • Configuration sync giữa HA pair
  • Failover testing và validation
  • HA design: VM primary + physical backup
  • Lab: HA pair VyOS với VRRP + conntrack-sync

Bài 14: WAN Load Balancing, QoS và Monitoring

  • WAN load balancing: distribute, failover, weights
  • Interface health checks (ping/HTTP)
  • QoS với CAKE, HTB, traffic shaping
  • Traffic prioritization (VoIP, gaming, work)
  • NetFlow/sFlow monitoring
  • SNMP, Prometheus exporter, Telegraf
  • Syslog và syslog over TLS
  • Lab: Dual-WAN load balancing + QoS cho home

Bài 15: Containers, Automation và Production Best Practices

  • Chạy containers (Podman) trên VyOS
  • Ansible automation cho VyOS
  • VyOS HTTP API
  • Scripting và custom op-mode commands
  • Backup strategies và config versioning
  • Image upgrade và rollback
  • Security hardening checklist
  • Production deployment scenarios thực tế
  • Lab: Ansible playbook triển khai full VyOS config
DUY TRAN
Tác giả

DUY TRAN

Pursuing an AI-first mindset and intelligent system architecture. I build solutions by combining technology, creativity, and the ability to see structure in chaos — the foundation for becoming a Solution Architect.

Bình luận