Zimbra Collaboration Suite (ZCS) is a robust, enterprise-grade messaging and collaboration platform offering email services, contact management, calendar sharing, and tasks. To secure on-premises e...
Network Security
- Check Point: ClusterXL, VSX (Virtual System Extension) virtual firewalls, VSNext gateway orchestration, MDS (Multi-Domain Security Management), IPS (Intrusion Prevention System) threat prevention, CoreXL & SecureXL acceleration, remote access and site-to-site IPsec VPNs, Harmony Endpoint agent, Identity Awareness, Infinity Portal SaaS central monitoring, HTTPS Inspection policies, Application Control & Content Awareness, ElasticXL scalable deployment, Check Point system upgrades, policy migrations.
- Cisco Secure: ASA (Adaptive Security Appliance), FTD (Firepower Threat Defense) NGFW, FMC (Firewall Management Center) management, Multi-Context ASA virtualization, AnyConnect Remote Access VPN (with certificate and Duo MFA authentication), Cisco Duo Proxy integration, Cisco Umbrella Secure Internet Gateway (SIG) via IPsec tunnels & CSR, Cisco Secure Network Analytics (Stealthwatch) flow auditing, Cisco Security Cloud Control (SCC) operations, FTD file policies & malware protection.
- Fortinet: FortiGate physical & virtual firewalls, FortiGate HA High Availability clustering, Fortinet SD-WAN deployments (Hub-and-Spoke and ADVPN topologies), FortiManager central template management, FortiAuthenticator identity, FortiWeb WAF application filtering, FortiAnalyzer syslog reporting, Security Fabric compliance, Destination NAT & port forwarding.
- Palo Alto Networks: GlobalProtect Remote Access SSL/IPsec VPN, Panorama centralized management, SSL Forward Proxy Decryption, User-ID LDAP & Captive Portal user mappings, Security Policies and profiles (Antivirus, Vulnerability, Anti-Spyware, URL Filtering), High Availability (HA) active-passive clustering, SD-WAN topologies, IPS threat analysis, Panorama-ISE TrustSec security tag synchronization.
- pfSense: pfSense OpenVPN remote access configuration, local firewall rules, CA certificate authority management, multi-WAN load balancing.
- Sophos: Sophos Firewall deployments, Intrusion Prevention System (IPS), SD-WAN routing, SSL decryption policies, CA certificate management.
EDR/XDR & SIEM
- Crowdstrike: Falcon EDR/XDR sensor deployments, static & cloud machine learning prevention policies, local tamper protection, Falcon Endpoint Detections analysis, process tree graphs, remote host containment isolation, Custom Intelligence SHA-256 hash IOC blocking.
- Elastic Security: SIEM log ingestion, Fleet agent policies, syslog proxies, ES|QL queries, prebuilt detection rules, Elastic Defend NGAV, network host containment, AI Attack Discovery (Claude 4.6).
- SentinelOne: Singularity EDR/XDR agents, behavioral/static AI engines, threat mitigation (kill, quarantine, remediation, rollback), Deep Visibility S1QL threat hunting, local firewall control, hash blocklisting.
- Wazuh EDR: Wazuh Cloud SIEM, File Integrity Monitoring (FIM) real-time content diffs, Windows Defender logs integration, automated SOAR Active Response firewall blocks, MITRE ATT&CK mappings, SCA compliance benchmarks, IT hygiene.
Identity & App Delivery
- Cisco ISE: 802.1X Wired/Wireless dot1x policies, MAB (MAC Authentication Bypass), TACACS+ Device Administration (configurations for F5, Fortigate, Check Point, Palo Alto), Profiling & Posture Assessment, Active Directory integration, Guest Portals, TrustSec tag-based segmentation (SGT/SGACL, TrustSec-ASA/FMC/Palo Alto integrations).
- Entra ID & ADFS: Azure AD IDP configurations, identity protection, Active Directory Federation Services (ADFS) single-sign-on integration.
- F5 BIG-IP: Local Traffic Manager (LTM) server load balancing, Global Traffic Manager (GTM/DNS) server load balancing, SSL Offloading, custom iRules scripting, BIG-IQ central management, Application Security Manager (ASM WAF), Access Policy Manager (APM), Advanced Firewall Manager (AFM).
- Duo Security: Multi-Factor Authentication (MFA) proxy-level integration with Cisco ASA (AnyConnect), Cisco ISE (MFA push), Check Point VPN, Fortinet VPN, and Palo Alto GlobalProtect.
Multi-Cloud
- Google Cloud: Network Connectivity Center (NCC) transit routing, High Availability (HA) VPN gateway integration, Classic VPN setups, GCP Load Balancing solutions, Firewall Endpoints for secure inline IPS & URL filtering, FortiGate security integration topologies.
- Microsoft Azure: vWAN (Virtual WAN) hub routing, ExpressRoute private WAN connections, HA VPN (with Check Point/Fortigate), Application Gateway with Web Application Firewall (WAF) rule sets, Azure Load Balancers (L4 ALB/NLB), Entra ID identity mesh integrations.
- Amazon Web Services: Transit Gateway (TGW) orchestration, Gateway Load Balancer (GWLB) security appliances traffic redirection, ALB application load balancers, VGW virtual gateways, IPsec VPN transit topologies.
- Alibaba Cloud: Cloud Enterprise Network (CEN) inter-region mesh routing, Application Load Balancer (ALB) WAF deployments, VPN Gateways, cross-border network routing.
Systems & Infra
- Microsoft Stack: Active Directory Domain Services (AD DS) design, Enterprise Certificate Authority (CA) PKI administration, Active Directory Group Policy Objects (GPO) security enforcement, Active Directory Federation Services (ADFS) single-sign-on (SSO), Hyper-V virtualization hypervisor host installations, Windows Server operations.
- Database Systems: SQL Server Always On Availability Groups clustering, SQL Server Agent Jobs management, SQL Replication models, Linked Servers connectivity, SQL Server database administration.
- VMware Virtualization: VMware vCenter centralized server, ESXi hypervisor deployments & versions upgrades, Cisco UCS Manager (UCSM) blade server provisioning, UCSM-ESXi virtualization topologies.
- Storage Systems: TrueNAS Core/SCALE configurations, StarWind Virtual SAN, TrueNAS replication topologies, Distributed File System (DFS) namespaces & replication, DRBD (Distributed Replicated Block Device) high-availability storage pools.
- Reverse Proxy & Filtering: Nginx reverse proxy configurations, Squid proxy caching services, Artica secure proxy content filtering, Flask web applications reverse proxying.
Automation & AI
- Telemetry & Monitoring: InfluxDB time-series database management, Prometheus metrics collection, Grafana visualization dashboards, SNMP Node Exporter telemetry, RSyslog central logging, Grok custom filters, automated alert notifications via Telegram API.
- Systems Operations: Linux server administration, Linux LVM (Logical Volume Manager) storage allocations, Docker container orchestration, Nessus vulnerability scanners auditing, Zabbix & PRTG & SolarWinds enterprise monitoring metrics tracking.
- Network Automation: Python scripting via Netmiko SSH libraries, automated configuration parsing, custom Flask web microframework development.
- AI Orchestration: Local LLM hosting via Ollama and LM Studio (Gemma, DeepSeek models), DeepSeek integration, LangChain agent workflows, Instructor structured output validation.
Routing & Core
- Routing Protocols: OSPF advanced topologies (LSA and network types), eBGP/iBGP scalable designs, MPLS WAN routing with MP-BGP, Policy-Based Routing (PBR), IP SLA path tracking, EEM (Embedded Event Manager) scripting.
- Cisco SD-WAN: cEdge/vEdge onboarding, device configuration templates, DIA (Direct Internet Access), traffic routing policies, Fortinet SD-WAN integrations, FortiManager templates.
- Cisco SD-Access: SDA design, fabric routing, IP Transit, LISP & VXLAN overlay control.
- L2/L3 Infrastructure: Private VLANs (PVLANs), DHCP Snooping, Dynamic ARP Inspection (DAI), VXLAN overlay networks, high-availability switching.
Enterprise Collaboration
- Cisco CUCM & Unity: CUCM administration, Extension Mobility (EM), Unity Connection voicemail integration, CUCM Single-Sign-On (SSO) authentication, Cloud Connected UC (CCUC), Webex App integration.
- Contact Center: Packaged CCE (PCCE), UCCX scripting, CVP (Customer Voice Portal), ECE (Enterprise Chat and Email) interactions.
- Compliance Recording: NICE Engage recording, Calabrio One call recording integrations.
- Expressway & CMS: Expressway-C/E Mobile Remote Access (MRA) and B2B federation, Cisco Meeting Server (CMS) conferencing, CMS Recorder.
- Voice Gateways: Cisco VG analog gateways, voice translation rules, Cisco Secure Common Client (SCC).
Zimbra Mail Server
Crowdstrike
CrowdStrike Falcon is a cloud-native endpoint security platform that integrates next-generation antivirus (NGAV), endpoint detection and response (EDR/XDR), threat intelligence, and managed threat ...
SentinelOne
SentinelOne Singularity is an AI-powered XDR (Extended Detection and Response) platform that unifies endpoint protection (EPP), detection and response (EDR), and cloud workload security. In this la...
Elastic
Elastic Security is an enterprise-grade security operations platform that integrates SIEM, endpoint security (EDR/XDR), and cloud monitoring into a single unified workspace, enabling real-time dete...
Wazuh
Wazuh is an open-source security monitoring platform that provides unified XDR (Extended Detection and Response) and SIEM (Security Information and Event Management) capabilities. By deploying Wazu...
Sophos
Sophos Firewall provides comprehensive protection including anti-malware, URL filtering, application control, SSL/TLS inspection, active threat response, and intrusion prevention. Sophos provides ...
Burp Suite
In this lab, we build and refine our core web security testing skillsets using Burp Suite alongside Yavuzlar VulnLab, a local Docker-based vulnerability training environment. Yavuzlar VulnLab is a ...
F5 ASM & AFM
In our previous load balancing labs (LTM and GTM), we successfully routed traffic across our network. However, high-availability routing alone does not protect our services from web exploits or una...
F5 BIG-IQ Management
As our infrastructure grows with multiple LTM and GTM nodes running across DC Jakarta and DC Surabaya, managing each device individually becomes highly inefficient. In this lab, we will deploy F5 B...
F5 DNS (GTM)
Following from our previous LTM lab, we will now configure GTM. GTM is an intelligent, DNS-based traffic manager that routes users globally before a network connection is ever established. In this ...