Anasayfa

Eğitim

Relution Shield for SysAdmins

En önemli anahtar veriler

Relution Shield – Secure Intranet Access with VPN and PKI

Build and master secure access to internal resources with Relution Shield from the ground up.

Overview

Relution Shield provides secure access from the internet to an organization's internal intranet by combining Virtual Private Network (VPN), Public Key Infrastructure (PKI), and UEM/MDM in a single solution. In this training, you will learn how to set up a Relution Shield server end to end – from the system requirements through installation and PKI/certificate configuration to connecting iOS and Android Enterprise devices. The focus is on a clean, reproducible setup, as the installation is demanding and requires careful work with variables, certificates, and firewall rules.

Target Audience

This training is aimed at administrators and IT staff who want to roll out and operate Relution Shield in an existing Relution environment. It is designed for people who already have experience with server administration and device management in Relution.

Learning Objectives

After this training, you will be able to:

  • understand the architecture and the interplay of VPN, PKI, and UEM in Relution Shield
  • check the system requirements and set up a Relution Shield server correctly
  • create a technical user including role and API access token in Relution
  • install Relution Shield via Docker Compose and configure the firewall (ufw) and the PKI correctly
  • import the required certificates into Relution and set up a certificate authority with a certificate template
  • connect iOS and Android Enterprise devices to Relution Shield via policy

Training Content

Fundamentals and Architecture

  • Purpose of Relution Shield: secure intranet access from the internet
  • Interplay of VPN, PKI, and UEM/MDM
  • Overview of the components involved: the Relution application server and the Relution Shield server

Prosedür ve içerik

Configuring a Relution Shield Server

  • System Requirements
    • Relution application server (version 5.26+) and a target organization with a Shield license
    • Relution Shield server: Ubuntu 22.04+, open UDP ports 500 and 4500, reachability from the internet, recommended public DNS entry
  • Preparing Relution
    • Creating a technical user without a password
    • The "Relution Shield access check" role and permissions
    • Creating an API access token (local vs. global scope)
  • Installation
    • Required parameters (Relution host, API token, VPN CIDR, network interface, Shield host, DNS servers)
    • Installing Docker and Docker Compose
    • Creating the environment file (.env) and the directory structure
    • Firewall configuration with ufw (forwarding, NAT/MASQUERADE, IPsec rules, IPv4 forwarding)
    • Building the PKI: CA and server certificates with strongSwan as well as swanctl.conf and strongswan.conf
    • Starting the service and setting up auto-start
  • Environment Variables and their relevance for operation

Configuring Relution

  • Importing the certificates into the target organization (CA certificate, server certificate, CA key pair)
  • Setting up a "Built In" certificate authority
  • Creating a certificate template (subject name, key usage, subject alternative name, automatic renewal)

Device Configuration

  • iOS
    • IKEv2 VPN configuration with per-app and account VPN
    • Setting server, remote ID, and local ID
    • Certificate-based authentication with Extensible Authentication (EAP)
    • IKE SA and child SA parameters, Safari domains, and app-to-VPN mapping
  • Android Enterprise
    • StrongSwan VPN profile with IKEv2 EAP-TLS
    • Server and server identity, user and CA certificate, client identity
    • Binding the VPN to apps and StrongSwan VPN restrictions as the default profile
  • Süre

    180 dakika

  • Events.training.costs

    400,00 €

  • Koşullar

    -

Events.training.formHeadlineInquiry

Özet ve sonuç

Eğitimin zamanlaması:
planlama aşamasında