Bài 1: Giới thiệu VyOS và Cài đặt
- VyOS là gì? Lịch sử từ Vyatta → VyOS
- So sánh VyOS vs pfSense vs OPNsense vs MikroTik
- Kiến trúc hệ thống và mô hình cấu hình (configuration tree)
- Tải và cài đặt trên VM (KVM/VirtualBox/Proxmox) và bare-metal
- CLI cơ bản: configure, commit, save, show, compare
- Lab: Cài đặt VyOS trên VirtualBox, SSH vào quản lý
Bài 2: Cấu hình Interface và IP cơ bản
- Cấu hình Ethernet interfaces (set interfaces ethernet ethX)
- IP tĩnh và DHCP client
- Quản lý users, authentication, SSH keys
- Hostname, timezone, NTP
- System backup/restore configuration
- Lab: Thiết lập router 2 interface (WAN + LAN)
Bài 3: NAT — Source NAT, Destination NAT và Masquerade
- NAT là gì? Tại sao cần NAT?
- Source NAT (masquerade) — cho LAN truy cập internet
- Destination NAT — port forwarding vào server nội bộ
- 1:1 NAT và NPTv6
- NAT rules ordering và priority
- Lab: Cấu hình masquerade + port forward HTTP/SSH
Bài 4: Firewall cơ bản — Rules, Chains và Groups
- Kiến trúc firewall VyOS (nftables backend)
- Input, output, forward chains
- Firewall rules: accept, drop, reject, log
- Address-group, network-group, port-group
- Áp dụng firewall lên interfaces (in/out/local)
- Default policy và rule ordering
- Lab: Bảo vệ router + cho phép LAN ra internet
Bài 5: Zone-based Firewall
- Khái niệm zone-policy trong VyOS
- Thiết kế zones: LAN, WAN, DMZ, GUEST
- Inter-zone traffic rules
- So sánh zone-based vs interface-based firewall
- Best practices phân vùng mạng
- Lab: Setup zone-policy cho mạng gia đình 3 zones
Bài 6: DHCP Server, DNS Forwarding và NTP
- DHCP Server: pools, ranges, static leases, options
- DHCPv6 server và SLAAC
- DHCP relay
- DNS forwarding với local cache
- Static DNS entries (host overrides)
- NTP server cho LAN clients
- Lab: DHCP + DNS cho mạng nội bộ hoàn chỉnh
Bài 7: VLANs, Bonding và Bridge
- 802.1Q VLANs: tạo sub-interfaces (eth0.10, eth0.20)
- Inter-VLAN routing (router-on-a-stick)
- Interface bonding (LACP 802.3ad)
- Bridge interfaces
- Kết hợp VLANs + firewall zones
- Lab: Tách mạng LAN/GUEST/IoT bằng VLANs
Bài 8: Static Routing và Policy-Based Routing
- Static routes và default gateway
- Blackhole routes và failover routes
- Policy-Based Routing (PBR): route-map, routing tables
- Multiple uplinks: định tuyến theo source IP
- Transparent proxy routing
- VRF (Virtual Routing and Forwarding) cơ bản
- Lab: Dual-WAN với PBR + failover
Bài 9: Dynamic Routing — OSPF
- OSPF fundamentals: areas, LSA, cost
- Cấu hình OSPF trên VyOS (single area và multi-area)
- OSPF unnumbered với ECMP
- Route redistribution
- Passive interfaces và authentication
- Troubleshooting: show ip ospf neighbor/route/database
- Lab: OSPF 3 routers VyOS, multi-area
Bài 10: Dynamic Routing — BGP
- BGP fundamentals: AS, iBGP vs eBGP
- Cấu hình BGP neighbors trên VyOS
- Route-maps, prefix-lists, AS-path filtering
- AS-path prepending và BGP communities
- Route Reflector
- BGP IPv6 unnumbered với extended nexthop
- Lab: BGP peering giữa 2 AS với route-map
Bài 11: VPN — WireGuard và OpenVPN
- WireGuard site-to-site: key generation, peer config
- WireGuard remote access VPN
- OpenVPN site-to-site với pre-shared key
- OpenVPN remote access với certificates
- So sánh WireGuard vs OpenVPN vs IPsec
- Routing traffic qua VPN tunnels
- Lab: WireGuard site-to-site giữa 2 VyOS
Bài 12: VPN — IPsec Site-to-Site
- IPsec fundamentals: IKEv2, ESP, SA, proposals
- Policy-based vs route-based (VTI) VPN
- Site-to-site IPsec giữa 2 VyOS
- IPsec VPN tới Cisco, Palo Alto, Azure
- DMVPN dual hub topology
- Troubleshooting IPsec tunnels
- Lab: Route-based IPsec VPN với BGP overlay
Bài 13: High Availability — VRRP và Conntrack Sync
- VRRP (Virtual Router Redundancy Protocol)
- Active-passive HA: priorities, preemption
- Conntrack-sync giữ sessions khi failover
- Configuration sync giữa HA pair
- Failover testing và validation
- HA design: VM primary + physical backup
- Lab: HA pair VyOS với VRRP + conntrack-sync
Bài 14: WAN Load Balancing, QoS và Monitoring
- WAN load balancing: distribute, failover, weights
- Interface health checks (ping/HTTP)
- QoS với CAKE, HTB, traffic shaping
- Traffic prioritization (VoIP, gaming, work)
- NetFlow/sFlow monitoring
- SNMP, Prometheus exporter, Telegraf
- Syslog và syslog over TLS
- Lab: Dual-WAN load balancing + QoS cho home
Bài 15: Containers, Automation và Production Best Practices
- Chạy containers (Podman) trên VyOS
- Ansible automation cho VyOS
- VyOS HTTP API
- Scripting và custom op-mode commands
- Backup strategies và config versioning
- Image upgrade và rollback
- Security hardening checklist
- Production deployment scenarios thực tế
- Lab: Ansible playbook triển khai full VyOS config
