Soda, no offense, I find it's better reading the details on the website rather than this "security tutorial".
I see you've posted some helpful tutorials, but honestly a sample network configuration...