Sample Test Project: Regional Skill Competition - Level 3
Sample Test Project: Regional Skill Competition - Level 3
A. Preface .................................................................................................................................... 3
B. Test Project .............................................................................................................................. 4
C. Marking Scheme .................................................................................................................... 18
D. Infrastructure List .................................................................................................................. 22
E. Instructions for candidates ..................................................................................................... 30
F. Health, Safety, and Environment ............................................................................................. 31
Skill Explained:
Network technologies knowledge has become essential nowadays for people who want to build a
successful career in any IT engineering field. This test project contains a lot of challenges from real
life experience, primarily IT integration and IT outsourcing. If you are able to complete this project
with the high score, you are definitely ready to implement network infrastructure for any multi-branch
enterprise.
This test project is designed using a variety of network technologies that should be familiar from the
Cisco certification tracks. Tasks are broken down into following configuration sections:
• Basic configuration
• Switching
• WAN
• Routing
• Services
• Security
• Monitoring and backup
• WAN and VPN
▪ Windows and Linux Services
All sections are independent but all together they build very complex network infrastructure. Some
tasks are pretty simple and straightforward; others may be tricky. You may see that some
technologies are expected to work on top of other technologies. For example, IPv6 routing is
expected to run on top of configured VPNs, which are, in turn, expected to run on top of IPv4 routing,
which is, in turn, expected to run on top of PPPoE, and so on. It is important to understand that if
you are unable to come up with a solution in the middle of such technology stack it doesn’t mean
that the rest of your work will not be graded at all. For example, you may not configure IPv4 routing
that is required for VPN because of IP reachability but you can use static routes and then continue
to work with VPN configuration and everything that runs on top. You won’t receive points for IPv4
routing in this case but you will receive points for everything that you made operational on top as
long as functional testing is successful.
It is very important to read the whole test project first. However, be aware that not all tasks are written
in chronological order. Some sections may require configuration from other sections below them.
For example, task 6 in the “Basic configuration” section asks you to configure authentication using
RADIUS server which obviously will not work if you do not apply all necessary configurations from
the “Switching configuration” section that comes right after. It is your responsibility to manage your
time effectively and the sequence you decide to complete the tasks.
As mentioned above, do not waste your time if you’re stuck with some tasks. You can use temporary
solution (if you have technology stack dependency) and continue to work with other tasks, this may
allow you to go back afterwards and fix things that are not working properly if you still have time. In
addition, we recommend that you to check all your previous work when you complete following
modules.
Switching configuration
1. Configure VTP version 2 on SW1, SW2 and SW3. Use SW3 as VTP server, SW1 and SW2
as clients. Use SInd as VTP domain name and 2018 as a password. VLAN database on all
switches should contain following VLANs:
a. VLAN 101 with name SALES.
b. VLAN 102 with name ACCOUNT.
Routing configuration
1. Configure EIGRP with AS number 2017 on ISP, HQ1, HQ2, BR2 and BR3 routers according
to the routing diagram. Enable routing updates authentication. Use MD5 algorithm with SIND
key.
2. Configure BGP on ISP, HQ1, HQ2, BR2 and BR3 according to the routing diagram.
a. Routers HQ1 and HQ2 should exchange routing updates using iBGP
b. Configure route filtering so that route 209.136.0.0/16 won’t be present in routing table
on HQ1 router.
3. Configure OSPFv2 on HQ1, HQ2, BR2, BR3 routers firewalls according to the routing
diagram.
4. Configure OSPFv3 on HQ1, HQ2, BR2 and BR3 routers according to the routing diagram.
Router HQ1 should be configured as DR, HQ2 — as BDR.
5. On BR2 router configure OSPF route redistribution for Loopback30 subnet into EIGRP AS
2017.
6. Configure routing policy on HQ1 router so that ICMP and UDP traffic from Loopback101
subnet to Loopback30 subnet goes through ISP router.
4. Turn on dynamic ARP inspection on SW1 for SALES subnet. Create access control list that
permits static IP address 192.168.10.10 for RADIUS server
In task B you will be responsible for preparing the new domain prior to performing the migration. This
will involve building the INDIA.net domain, including all of the resources that will be necessary for
the future migration, preparing for secure connectivity between the new domain and the old domain
- which will involve setting up a VPN server.
NOTE: Refer to the diagram on the last page for quick specification reference, as well as the
configuration table.
Please use the default configuration if you are not given the details
All local and domain users on ALL machines should have a password of "P@ssw0rd"
unless otherwise specified. Pre-supplied machines that the competitor needs to logon
to will also be pre-configured with this password.
All supplied software and files needed to complete this project can be found in
C:\software on the competitor computer.
Work Task INDIA-DC
Install/Configure
NOTE: This is a required list of groups and OUs that have to be created in the domain. If you believe
that you should create additional groups to perform the tasks you can create them.
NOTE: if you are unable to do import all the users from the Excel file create at least the following
users manually
Install/Configure
• Install a Windows Server 2016 (no GUI) from ISO
• When creating the VM, build with 4 drives
• 1 System drive (c:\)
• Size 60 GB
• 1 Raid 5 array with the remaining three drives (d:\)
• Size 10 GB in total
• Rename to IN-FILES
• Configure the network settings as per configuration table/network diagram
• Modify the default Firewall rules to allow ICMP (ping) traffic
• Join to INDIA.net domain
Shares
• Create shares for departments (Competitors, Experts and Managers)
• on IN-FILES -> d:\shares\departments
• \\IN-Files\Experts --> d:\shares\departments\Experts
• \\IN-Files\Competitors --> d:\shares\departments\Competitors
• \\IN-Files\Managers --> d:\shares\departments\Managers
• Create a share for projects in IN-FILES -> d:\shares\projects
• Create the following folders in d:\shares\projects
• Budget
• Intranet
• Logistics
• Set the permissions for these folders according to the table in the appendix
• Map the project share (\\in-files.india.net\projects) to P:\ for all users except the Visitor group
• Users should see only the folders in P:\ where they have permissions to access them (Access-
based Enumeration)
DHCP
DNS
Quota/Screening
• Make sure that unauthorized users get the following error message, when they want to
access one of the three department shares (Experts, Competitors and Managers) they are
not allowed to!
o Expert share:
▪ Error message: “Access only for EXPERTS allowed”
o Competitor share:
▪ Error message: “Access only for COMPETITORS allowed”
o Manager share:
▪ Error message: “Access only for MANAGERS allowed”
Note: Set the power settings to "never sleep" for all Windows 10 clients
Install/Configure
NOTE: Refer to the diagram on the last page for quick specification reference, as well as the
configuration table.
Please use the default configuration if you are not given the details
Local, domain and existing passwords will be "P@ssw0rd"
WORK TASK US-DC
This is the existing domain controller for the old domain and hosts all the user and group information
Install/Configure
• All user with "Expert" in the "Job Title:" should have duplicate accounts created for them in
the INDIA.net domain (we are not using GPMT – so it is not a migration just a re-creation of
the user accounts)
o Copied Users should be placed to OU "Migration" in INDIA.net
o Set the password to "WorldSkills2018mig"
o Copy the necessary home folders from US-DC to IN-FILES d:\shares\migrated
o Set the necessary permissions on these copied folders/shares (only the user itself
and domain administrators should have access to these homefolders)
o Map the home folder to drive S:\ automatically (\\IN-Files\migrated$\%username%)
o Disable the copied users in US.net and move them to a new OU called MIGRATED
on US-DC
• Create the following three users in OU “Users”. They are necessary for the following work
tasks.
o RDS_user1
o RDS_user2
Shares
• DNS records should point to the correct IP addresses for both www.US.net and
www.INDIA.net
• DNS records should point to the correct IP address to the RemoteApp website.
WORK TASK US-WEBSERVER
Configure a HTTP/HTTPS for “www.us.cloud”, which is hosted by. Connect to backends by using
HTTPS and make sure that certificates are fully trusted (no browser or other certificate errors).
DNS
• Install Bind9.
o Configure a forward zone called “us.cloud”.
▪ Create for each host an A record to the respective IP
▪ Create a CNAME record for ‘www’ that points to the appropriate host that serves
websites for all clients
▪ Create a CNAME record for ‘mail’ that points to the mail server
▪ Create the appropriate MX records
▪ Create a CNAME record for ‘ftp’ that points to the ftp server
▪ Create a CNAME record for ‘files’ to access the DFS shares
o Configure a forward zone called “competition.ae”
o Create the appropriate records for email to work
o Configure a reverse zone
MAIL
• Install Postfix and Dovecot.
o Configure SMTPS and IMAPS server for "US.cloud" and “competition.ae” domain
using certificates
o Configure mail directory in /home/[user]/Maildir.
o Authentication has to be done through LDAP
▪ Make sure that the corresponding local user do not exist
▪ Allow only users from the OU “mail”.
o Enable SMTP submission (TLS TCP/587).
▪ Disable port tcp/25
o Enable secure IMAP (TLS TCP/143)
Webserver – Apache
The marking will be done on either of the two servers. Which one will be decided prior the marking
starts by the assessment team. So you have to configure both servers!
• Install Apache
LDAP
• Install LDAP service.
o Configure the directory service of wsc17.cloud.
o Create users with OU and password specified in the appendix.
o File Share, Web and Mail services should be available for LDAP users.
o Create a OU named “wsc-i-london” and use this to grant SSH access to “wsc-i-
london”. User not in this group, should be denied access. Root access should not
be allowed.
• Create a new second domain “competition.ae”.
o In this domain create the users as stated in the appendix.
RADIUS
• Install RADIUS service.
o Use LDAP as the authentication back-end.
o Add wsc-p-stgallen as RADIUS client and VPN user should be authenticated
through this server.
o Use Skill39 as shared secret
CA
• Configure as CA using OpenSSL.
o Use /etc/ca as the CA root directory
▪ Private key should have minimal permission
o CA attributes should be set as follows:
▪ Country code is set to AE
▪ Organization is set to WorldSkills International
▪ The common name is set to “WorldSkills 2017 CA”
o Create a root CA certificate.
o All certificates required in the test project should be published by CA.
E-mail
• Use Icedove as the e-mail client and configure using the user “skill40”.
o Configure to use [email protected]
o Send an email to [email protected]
o Use IMAP to connect to the mailbox
Web
• Use Firefox as the web browser.
o Make sure that www.us.cloud is accessible.
o No certificate warning
o Shows appropriate content
FTP
• Use FileZilla as FTP-client
o Make sure that a connection to wsc-i-london (ftp.wsc17.cloud) can be established.
Samba
• Make sure that users can access the shares file
E-mail
• Use Icedove as the e-mail client and configure using the user “skill40”.
o Configure to use [email protected]
o Send an email to [email protected]
o Use IMAP to connect to the mailbox
WORK TASK US-REMOTE
Note: Set the power settings to "never sleep" for all Windows 10 clients
Install/Configure
VPN
• Configure the VPN client settings for all users on this computer
o Connect the VPN using the public IP of US-EDGE
o Use this client for testing the "external" access to the websites
o www.india.net and www.us.net
NOTE: Refer to the diagram on the last page for quick specification reference, as well as the
configuration table.
Please use the default configuration if you are not given the details
WORK TASK INET
Note: This server has already been preconfigured with all the necessary settings for
"simulating the internet in a test lab" and also DHCP is already setup.
Install/Configure
DNS/IIS
• Create the appropriate resource records (DNS) for external access to the INDIA.net domain
and also for www.US.net and www.INDIA.net websites access.
Work Task US-EDGE
This is the VPN server that will allow access for external clients to the internal network. It will also
create a VPN tunnel to the INDIA.net domain.
Install/Configure
NAT configuration
Install/Configure
Site-to-Site VPN
C. Marking Scheme
Cisco Environments
Aspect Max Mark
Marking Criteria or Description Requirement
ID Mark Awarded
Cisco Environments
1.1 Hostname 1
1.2 Local passwords and services 1
Switching
1.1 VTP Test from SW3 VTP server to SW1 Client 4 Layer 2 1
Switches
1.2 DTP interface status 1
1.4 PAgP 1
Routing
1.3 BGP 1
1.1 NAT 1
1.2 GLBP 1
Security
1.4 Port-security 1
1.5 DHCP-snooping 1
40
IN-DC
IN-EDGE
2.28 DA Installed 1
WORKING ON US.NET
Aspect
Marking Criteria or Description Requirement Max Mark Mark Awarded
ID
US-DC
find expert users - moved and in migration
3.1
folder 1
3.3 expert users all disabled 1
US-WEBSERVER
SMTPS e IMAPS 1
US-LDAP
3.15 CA Configuration 1
3.16 Radius 1
US-Client
3.20 Samba 1
3.21 IMAP Client 1
US-Edge
US-REMOTE
Machines indicated as being preinstalled with "Yes – configured" will have the operating
system installed and Hostname and network settings configured.
Shares/Permission Table
Routing Diagram
Network Diagram
• You will have access to internet per module 10 minute except design modules
• You are not permitted to use any communication application e.g. Chat, Facebook,
WhatsApp etc.
Module Rules
• When you have finished the current module, you can proceed to the requirements
for the next module.
Infrastructure Rules
• Any hardware failure during the completion may get extra time subject to approval
of Jury/Experts.
• Candidates should not carry any devices, cell phones, material at competition
desk.
Rules of competition
• All the rights of the competition are revered with State Skill Competition
Committee.
• All accredited participants and supporting volunteers will abide by rules and
regulations with regards to Health, Safety, and Environment of the Competition
venue.
• All participants, technicians and supporting staff will wear the appropriate /
required protective Personnel clothing.
• All participants will assume liability for all risks of injury and damage to property,
loss of property, which might be associated with or result from participation in the
event. The organizers will not be liable for any damage, however in case of Injury
the competitor will immediately inform the immediate organizer for medical
attention.
• Do not plugin/plugin out any eclectic & electronics connections, seek for
assistance.
• Be careful while working on workstation so that feet should not strike to electric
board or CPU system.