Postingan

ITNSA Tips System & Network Troubleshooting

Selain teknik troubleshooting berdasarkan layer OSI/TCP-IP seperti pada postingan berikut: https://nciptandani.blogspot.com/2019/10/it-nsa-tips.html Baca juga: https://nciptandani.blogspot.com/2019/01/tips-troubleshooting-networksystems.html Ada metode lain yang bisa digunakan sebagai dasar dalam troubleshooting, yaitu teknik 5W + 1H . 1. What (Apa masalahnya) Langkah pertama adalah memahami apa masalah yang terjadi dan pada layanan apa. Misalnya: DNS HTTP VPN Routing IP address atau layanan lainnya Dengan mengetahui “what”, kita bisa mempersempit area investigasi. 2. Who (Siapa yang terdampak) Selanjutnya, identifikasi siapa yang terkena dampak dari masalah tersebut. Hal yang perlu diperiksa misalnya: Apakah user hanya satu orang atau banyak Apakah user berada di jaringan internal atau eksternal Status akun di sistem (disable, locked, salah password, dll.) Role atau permission yang dimiliki user Data ini bisa dicek melalui: Sistem lokal Directory servi...

How to manage iptables with netfilter-persistent

Gambar
As we may know that iptables is temporary command, it will be lost when rebooting so to manage the firewall rules on iptables we can use netfilter-persistent,  it can be used to add, edit and remove rules on files,  save,  and flush. This is the example video about managing the iptables rules, you can try by yourself with any rules you want on server, client or router.

IT NSA Tips

Konfigurasi & Troubleshooting: Konsep Lebih Penting dari Vendor 🔧 Configuration — Fokus ke Konsep, Bukan Sekadar Tools Hal paling penting dalam dunia IT adalah memahami konsep terlebih dahulu , baru kemudian mencari cara konfigurasi sesuai vendor atau teknologi yang digunakan. Sebagai contoh: 🌐 VPN Semua vendor pada dasarnya menggunakan konsep yang sama, misalnya: SSL VPN IKEv2 VPN L2TP/IPsec VPN Perbedaannya hanya pada: Syntax konfigurasi Letak menu / GUI Cara implementasi Karena itu, kemampuan yang dibutuhkan adalah: 👉 Membaca dokumentasi 👉 Googling solusi 👉 Memahami konsep dasar jaringan 🖥️ Contoh Stack Teknologi Lain Banyak teknologi memiliki konsep sama, hanya implementasinya berbeda. File Sharing Windows SMB Linux Samba / NFS Virtualisasi & Live Migration Bisa menggunakan: KVM Hyper-V VMware Konsepnya tetap: Host → VM → Storage → Network → Migration Load Balancer Bisa menggunakan cloud atau software: Cloud: OpenStack GC...

Iptables Firewall Stateless vs Statefull on Router

Iptables Firewall Stateless vs Statefull on Router Task: Create the firewall rule for IP 1.1.1.1 can access ssh server on 2.2.2.2 2 ways: 1. Stateless #iptables -P FORWARD DROP #iptables -A FORWARD -p tcp --dport 22 -s 1.1.1.1 -d 2.2.2.2 -j ACCEPT #iptables -A FORWARD -p tcp --sport 22 -s 2.2.2.2 -d 1.1.1.1 -j ACCEPT or 2. Statefull (recommended) #iptables -P FORWARD DROP #iptables -A FORWARD -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT #iptables -A FORWARD -p tcp --dport 22 -s 1.1.1.1 -d 2.2.2.2 -j ACCEPT

Docker commit

Docker commit used to reate a new image from a container’s changes. You need to commit the changes you make to the container and then run it. Try this example: sudo docker pull debian After pull image from docker hub, you can customize to fit your enviroment  in this example is just to try install apache2 sudo docker run debian apt-get update && apt-get install -y apache2 or you can access the bash with command: sudo docker run debian Check container id sudo docker ps -l Enter to the bash terminal sudo docker exec -it <container_id> bash  apt-get update && apt-get install -y apache2 exit bash terminal  exit Commit changes to the container: sudo docker commit <container_id> nasohi/www1 Now the container becomes the image, check with the following command: sudo docker images Then run the container: sudo docker run nasohi/www1 Another way is you can make docker file and use docker build Read also: ...

How to configure HTTPS in IIS Windows Server via PowerShell

Konfigurasi HTTPS di IIS Windows Server Menggunakan PowerShell Berikut langkah-langkah konfigurasi HTTPS pada IIS di Windows Server menggunakan PowerShell. Tutorial ini fokus pada proses: Import sertifikat PFX Binding sertifikat ke website IIS Verifikasi HTTPS 📌 Prasyarat Sebelum memulai, pastikan: Web server IIS sudah terinstall Sudah memiliki sertifikat format PFX Sertifikat berasal dari CA internal / external Referensi terkait: Konfigurasi IIS via PowerShell (HTTP): https://nciptandani.blogspot.com/2019/06/cara-konfigurasi-web-server-iis-di.html Setup Windows CA & template webserver: https://nciptandani.blogspot.com/2018/08/pembahasan-itnsa-module-b-windows-ca.html 🪪 Mendapatkan Sertifikat PFX Sertifikat bisa dibuat dari: Template Web Server di CA Request melalui MMC: MMC → Certificates → Local Computer → Personal → Right Click Certificates → All Tasks → Request New Certificate Isi dengan benar: Common Name (CN) Subject Alternative Name...

Konfigurasi Site-to-Site VPN IKEv2 IPsec di Cisco ASA

Pada tutorial ini kita akan mempraktikkan VPN Site-to-Site menggunakan firewall ASA. VPN jenis ini digunakan untuk mengamankan komunikasi antar jaringan berbeda lokasi (misalnya kantor pusat dan cabang) melalui internet. Teknologi ini umum digunakan pada perangkat dari . 🧭 Konsep Dasar yang Harus Dipahami Dalam VPN IPsec terdapat dua fase utama: 🔐 Phase 1 (IKEv2 – Tunnel Negotiation) Digunakan untuk membangun secure channel. Parameter yang harus MATCH di kedua ASA : Hash → MD5 Encryption → AES-128 DH Group → 5 Authentication → Pre-Shared Key 🔐 Phase 2 (IPsec – Data Protection) Digunakan untuk mengamankan trafik data. Parameter: Protocol → ESP Encryption → AES-128 Hash → MD5 🌐 Contoh Topologi HQLAN —— FW1 —— INTERNET —— FW2 —— BRLAN Contoh subnet: HQ LAN → 192.168.30.0/24 Branch LAN → 172.16.20.0/24 ⚠️ Prasyarat Penting Sebelum konfigurasi VPN: ✅ Pastikan konektivitas IP antar firewall sudah OK ✅ Bisa saling ping interface outside Jika belum bis...