I’m going to periodically update this page with a list of everything I’ve done. I’ll add brief descriptions to some as I see fit. Some of these may even have their own article.
- Built a fully functioning custom ESXi server with 10G uplink over LAN.
- Deployed a Linux host to run Docker.
- Deployed a Ubiquiti networking solutions including a gateway, switch, firewall and AP.
- Deployed a SAN for storing large amounts of data in a RAID 10 setup for quick accessibility and connected via ISCSI protocol and SMB shares.
- Created a Wireguard VPN tunnel for devices to connect to the LAN from outside the network.
- Created a web facing storage platform with secure features to have more control and ready access to the data.
- Created a website using WordPress.
- Implemented a reverse proxy solution involving NGINX to add additional functionality to the network.
- Implemented SSL, HSTS, and forcing the latest TLS connection to any clients connecting to any site on the domain.
- Implemented a DNS level blocking host to better manage network traffic with additional security.
- Ensuring end-to-end encryption from each of my services to protect data and prevent attacks.
- Implementing multiple sets of IDS/IPS systems in order to detect and prevent malicious attacks on L3 and L7.
- Hardening security on Linux hosts by disabling unnecessary access and limiting by private key auth.
- Created a custom homepage using Heimdall.
- Deployed a Portainer container for easier management of Docker containers.
- Deployed a Domain Controller and Active Directory.
- Deployed an Active Directory Federated Services service for SSO into certain web apps.
- Deployed an UptimeKuma node as a centralized point of reference to the state of all services on the network with webhook notification into chat platforms such as Discord and Slack. Additionally setup internal email alerts.
- Created a Sharepoint 2019 instance and database to match using Microsoft SQL 2017.
- Implemented a VEEAM backup solution to manage external backups of all virtual machines on ESXi .
- Deployed an on premises Exchange server and implemented Proofpoint as a DLP solution and spam filter.
- Migrated an internal network from a class C IP space to class A and instilled a policy forcing DHCP with mac address host IP reservations with at the port VLAN tagging when applicable.
- Segregated a network using VLAN’s to allow better traffic control and management.
- Deployed a VCenter appliance for central management over multiple ESX and ESXi hosts.
- Deployed an instance of Azuracast for online radio uses to share with friends.
0 Comments