Multi-Campus Secure Network Deployment

Job ID: 39930120

Budget: ₹1,500 – ₹12,500 INR

I’m rolling out a secure, three-campus network linking Caulfield, Clayton, and Peninsula. The full build needs to be designed, implemented, and proven end-to-end on a lab platform, then documented clearly enough that I can replicate every step.

Scope of work
• Architecture: Produce a routed topology that interconnects the three sites and supports future growth.
• Routing: Configure BGP between campuses, demonstrate a controlled prefix-hijack attack, then show the mitigation technique in real time.
• Firewalls: Stand up perimeter and internal firewalls, apply access-control policies, and verify they block/allow traffic exactly as explained during the demo.
• VPN: Deliver both site-to-site tunnels and remote-access user VPN, then walk through an encryption breakdown to illustrate key exchange and cipher strength.
• Servers: Build Linux-based DNS, Certificate Authority, SSH, Web, and SMTP servers and integrate them into the security architecture.
• IDS: Deploy Snort, trigger at least one attack scenario, and capture the alert in the logs.
• Hashing: Generate and verify project-wide hash values for configuration integrity.
• Reporting: Summarise the security posture and risk areas in roughly 1,000 words, backed by screenshots of the topology, rule sets, IP plans, and command output.

Deliverables
1. Working virtual/lab environment files or clear rebuild instructions.
2. A single take, <20-minute video (face visible) walking through each task live.
3. Written report (PDF or Markdown) containing:
– Topology diagrams and screenshots
– All firewall and IDS rule sets
– Full IP addressing and BGP configs
– Command outputs that match the video
– 1,000-word security analysis with hash validation section.

Acceptance criteria
• Every demo item must succeed exactly as narrated.
• Commands and outputs in the report must align with the footage.
• Video length must not exceed 20 minutes while remaining clearly audible and visible.

Tools you choose are flexible—pfSense, Cisco ASA, or FortiGate fit, as long as they satisfy the controls—but all servers must remain on Linux. If parts of the environment need virtualization, feel free to rely on VMware Workstation, VirtualBox, or GNS3/EVE-NG; just note the versions so I can mirror them.

Ready to see your plan.