Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

Linux SSH, UFW Firewall, and Log Review Lab

Overview

This project is a beginner-friendly Linux administration and cybersecurity lab built with VMware Workstation Pro. The lab demonstrates how to configure and test SSH access between local virtual machines, enable a basic Linux firewall using UFW, verify allowed and blocked traffic, and review authentication logs for failed and successful SSH login events.

This lab builds on my earlier VMware Linux networking project by moving from basic VM-to-VM connectivity into service management, firewall configuration, and log review.

Lab Environment

Component Details
Host System Windows 11 Pro
Virtualization Platform VMware Workstation Pro
Server VM Ubuntu Server 26.04 LTS
Client VM Kali Linux
Network Mode VMware NAT
Ubuntu Server Hostname ubuntu-ssh-server-01
Kali Hostname kali-lab-01
Ubuntu Server Interface ens33
Kali Interface eth0
Ubuntu Server IP 192.168.71.132
Kali IP 192.168.71.130
Default Gateway 192.168.71.2

Skills Demonstrated

  • Created and configured a lightweight Ubuntu Server VM
  • Verified Linux hostnames, users, IP addresses, interfaces, and default routes
  • Tested VM-to-VM connectivity using ping
  • Verified SSH availability using systemctl and ss
  • Connected from Kali Linux to Ubuntu Server using SSH
  • Enabled and configured UFW firewall rules
  • Allowed SSH traffic while blocking unapproved traffic
  • Tested blocked traffic using a temporary Python HTTP server on port 8080
  • Generated safe failed SSH login events against my own local VM
  • Reviewed Linux authentication logs using grep and tail
  • Separated private lab notes from public GitHub documentation
  • Prepared a public GitHub project folder with selected screenshots
  • Published the project to GitHub using Git from the terminal

Safety Scope

This lab was performed only against virtual machines that I created and controlled in my own local VMware lab environment.

No public IP addresses, employer systems, school systems, church systems, family devices, or third-party networks were tested.

Kali Linux was used only as a local client workstation for learning, SSH testing, and defensive-awareness log review.

Network Baseline

The Ubuntu Server and Kali Linux VMs were both connected to the same VMware NAT network.

Ubuntu Server Network Baseline

Ubuntu Server network baseline

Kali Linux Network Baseline

Kali network baseline

Connectivity Testing

Kali successfully pinged Ubuntu Server.

Kali ping Ubuntu Server

Ubuntu Server successfully pinged Kali.

Ubuntu Server ping Kali

SSH Service Verification

Ubuntu Server used SSH socket activation. The ssh.service showed inactive, but ssh.socket was active and listening on TCP port 22. This showed that SSH was available even though the service was not continuously running.

Ubuntu SSH socket listening

Successful SSH Login

Kali connected to Ubuntu Server over SSH using the local lab account. After login, the remote hostname and user confirmed that the SSH session was connected to the Ubuntu Server VM.

Kali SSH successful login

UFW Firewall Configuration

UFW was enabled on Ubuntu Server after allowing the OpenSSH profile. The firewall was configured to deny incoming traffic by default while allowing SSH on TCP port 22.

UFW enabled status

After UFW was enabled, SSH access from Kali still worked.

SSH still works after UFW

Blocked Traffic Test

A temporary Python HTTP server was started on Ubuntu Server using port 8080. Kali attempted to connect to that port, but the connection timed out because UFW did not allow inbound traffic on port 8080.

UFW blocked port 8080 test

Authentication Log Review

A safe failed SSH login test was performed from Kali against the local Ubuntu Server VM using a fake username. A successful SSH login was then performed with the legitimate lab account.

The authentication log showed failed login activity, invalid user activity, and successful SSH authentication events.

Authentication log failed password events

Authentication log successful login event

Commands Practiced

Some of the main commands practiced in this lab included:

hostname
whoami
ip -br addr
ip route
ping -c 4 TARGET_IP
systemctl status ssh --no-pager
systemctl status ssh.socket --no-pager
sudo ss -tlnp | grep ':22'
ssh tim@192.168.71.132
sudo ufw status verbose
sudo ufw app list
sudo ufw allow OpenSSH
sudo ufw enable
python3 -m http.server 8080 --bind 0.0.0.0
curl --connect-timeout 5 http://192.168.71.132:8080
sudo grep -Ei "invalid user|failed password|accepted password" /var/log/auth.log | tail -n 25

A fuller command explanation is included in the notes/commands-used.md file.

Key Lessons Learned

  • A Linux service may appear inactive if it is managed by a socket instead of running continuously.
  • SSH can be verified by checking both systemctl status and listening ports.
  • Firewall rules should be added before enabling a firewall to avoid accidentally blocking needed access.
  • UFW can allow specific services, such as OpenSSH, while blocking unapproved ports.
  • Authentication logs are useful for identifying failed logins, invalid users, successful logins, source IP addresses, and timestamps.
  • Screenshots and notes should be reviewed before publishing to avoid exposing sensitive information.
  • Git and GitHub can be used to publish a clean, documented technical lab as a portfolio artifact.

Portfolio Value

This project demonstrates beginner-level Linux administration, SSH service verification, firewall configuration, safe local testing, authentication log review, technical documentation, and GitHub publishing.

It is intended as an honest learning artifact for entry-level IT support, cybersecurity, SOC, cloud support, GRC/compliance, apprenticeship, and internship preparation.

Disclaimer

This lab was completed in a local virtualized environment for educational purposes only. All testing was limited to systems I own and control.

About

Local Linux SSH, UFW firewall, and authentication log review lab using VMware, Ubuntu Server, and Kali Linux

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors