Lock Down Management Access
Anyone on the office network can currently try to log into the core router — fix that
Scenario
A routine security assessment found that the core router's remote management interface (used for administrative configuration access) is reachable from every subnet in the building, including regular employee workstations and guest Wi-Fi — anyone on the network can attempt to connect to it, not just the small IT team who should be the only ones able to. You've been asked to restrict management access to the dedicated IT administrative subnet only, without affecting the router's normal job of routing traffic for everyone else.
Learning objectives
- acl
- nftables
- least privilege
Topology and configuration
This environment contains 4 devices (3 Hosts, 1 Router). You configure and troubleshoot the networking skills listed above.
Curriculum topics
Environment
Subnetica labs run FRRouting and Linux networking with Cisco-like syntax, not Cisco IOS. Commands and behavior may differ from Cisco devices.
Addressing is regenerated on every attempt and the environment is graded automatically.
Ready to practice?
Sign in or create an account before launching this lab. Viewing this preview never starts or reserves infrastructure.
