
Formación
Relution Shield for SysAdmins
Los datos clave más importantes
Relution Shield – Secure Intranet Access with VPN and PKI
Build and master secure access to internal resources with Relution Shield from the ground up.
Overview
Relution Shield provides secure access from the internet to an organization's internal intranet by combining Virtual Private Network (VPN), Public Key Infrastructure (PKI), and UEM/MDM in a single solution. In this training, you will learn how to set up a Relution Shield server end to end – from the system requirements through installation and PKI/certificate configuration to connecting iOS and Android Enterprise devices. The focus is on a clean, reproducible setup, as the installation is demanding and requires careful work with variables, certificates, and firewall rules.
Target Audience
This training is aimed at administrators and IT staff who want to roll out and operate Relution Shield in an existing Relution environment. It is designed for people who already have experience with server administration and device management in Relution.
Learning Objectives
After this training, you will be able to:
- understand the architecture and the interplay of VPN, PKI, and UEM in Relution Shield
- check the system requirements and set up a Relution Shield server correctly
- create a technical user including role and API access token in Relution
- install Relution Shield via Docker Compose and configure the firewall (ufw) and the PKI correctly
- import the required certificates into Relution and set up a certificate authority with a certificate template
- connect iOS and Android Enterprise devices to Relution Shield via policy
Training Content
Fundamentals and Architecture
- Purpose of Relution Shield: secure intranet access from the internet
- Interplay of VPN, PKI, and UEM/MDM
- Overview of the components involved: the Relution application server and the Relution Shield server
Procedimiento y contenido
Configuring a Relution Shield Server
- System Requirements
- Relution application server (version 5.26+) and a target organization with a Shield license
- Relution Shield server: Ubuntu 22.04+, open UDP ports 500 and 4500, reachability from the internet, recommended public DNS entry
- Preparing Relution
- Creating a technical user without a password
- The "Relution Shield access check" role and permissions
- Creating an API access token (local vs. global scope)
- Installation
- Required parameters (Relution host, API token, VPN CIDR, network interface, Shield host, DNS servers)
- Installing Docker and Docker Compose
- Creating the environment file (
.env) and the directory structure - Firewall configuration with ufw (forwarding, NAT/MASQUERADE, IPsec rules, IPv4 forwarding)
- Building the PKI: CA and server certificates with strongSwan as well as
swanctl.confandstrongswan.conf - Starting the service and setting up auto-start
- Environment Variables and their relevance for operation
Configuring Relution
- Importing the certificates into the target organization (CA certificate, server certificate, CA key pair)
- Setting up a "Built In" certificate authority
- Creating a certificate template (subject name, key usage, subject alternative name, automatic renewal)
Device Configuration
- iOS
- IKEv2 VPN configuration with per-app and account VPN
- Setting server, remote ID, and local ID
- Certificate-based authentication with Extensible Authentication (EAP)
- IKE SA and child SA parameters, Safari domains, and app-to-VPN mapping
- Android Enterprise
- StrongSwan VPN profile with IKEv2 EAP-TLS
- Server and server identity, user and CA certificate, client identity
- Binding the VPN to apps and StrongSwan VPN restrictions as the default profile
Duración
180 minutos
Events.training.costs
400,00 €
Requisitos
-