1
00:00:06,540 --> 00:00:07,920
- [Instructor] When the A+ objectives

2
00:00:07,920 --> 00:00:10,500
refer to Internet appliances,

3
00:00:10,500 --> 00:00:14,670
they're referring to
Internet security appliances,

4
00:00:14,670 --> 00:00:16,650
and there's several of
these that you should know

5
00:00:16,650 --> 00:00:18,000
for the exams.

6
00:00:18,000 --> 00:00:21,060
The first and foremost is firewalls.

7
00:00:21,060 --> 00:00:23,970
The firewall is something
that every organization

8
00:00:23,970 --> 00:00:27,660
should have protecting its network,

9
00:00:27,660 --> 00:00:30,870
and it can protect the network
or an individual computer,

10
00:00:30,870 --> 00:00:33,810
and it does this by closing ports

11
00:00:33,810 --> 00:00:36,153
and stopping unwanted intrusion.

12
00:00:37,140 --> 00:00:41,010
Network-based firewalls are generally used

13
00:00:41,010 --> 00:00:44,640
to section off one portion
of the network from another,

14
00:00:44,640 --> 00:00:47,010
so here we have a firewall,

15
00:00:47,010 --> 00:00:50,670
and this is blocking
people on the Internet

16
00:00:50,670 --> 00:00:53,370
who may want to gain unauthorized access

17
00:00:53,370 --> 00:00:56,580
into the LAN over here.

18
00:00:56,580 --> 00:01:00,573
So this firewall's gonna
protect these computers.

19
00:01:01,530 --> 00:01:04,350
But it might also section
off things in such a way

20
00:01:04,350 --> 00:01:06,210
where you can have other
portions of the network,

21
00:01:06,210 --> 00:01:09,870
you might have other LANs,
or you might have a DMZ,

22
00:01:09,870 --> 00:01:13,980
a demilitarized zone
where there are servers,

23
00:01:13,980 --> 00:01:18,660
such as web servers and FTP servers

24
00:01:18,660 --> 00:01:22,203
that can be accessed by
people from the Internet,

25
00:01:23,820 --> 00:01:28,350
but only allowing them
access to those services

26
00:01:28,350 --> 00:01:31,320
like FTP and World Wide Web,

27
00:01:31,320 --> 00:01:33,690
but the firewall will not
allow access to these guys.

28
00:01:33,690 --> 00:01:36,060
So a firewall might have the ability

29
00:01:36,060 --> 00:01:38,250
to just protect from
people on the Internet,

30
00:01:38,250 --> 00:01:40,350
or it might have multiple connections

31
00:01:40,350 --> 00:01:42,150
where you could have a
connection to the Internet,

32
00:01:42,150 --> 00:01:44,790
a connection to the DMZ,
a connection to the LAN,

33
00:01:44,790 --> 00:01:47,253
and maybe another LAN over here, in fact.

34
00:01:48,180 --> 00:01:50,130
A separate LAN altogether.

35
00:01:50,130 --> 00:01:52,890
Separate connectivity for all of those.

36
00:01:52,890 --> 00:01:54,330
So firewalls are very important,

37
00:01:54,330 --> 00:01:56,820
extremely important in network security.

38
00:01:56,820 --> 00:01:59,430
It's the primary line of defense.

39
00:01:59,430 --> 00:02:03,420
And so a firewall could run
on an individual computer.

40
00:02:03,420 --> 00:02:07,380
You know, you might have a
firewall running here as software

41
00:02:07,380 --> 00:02:09,300
but you really should have a firewall

42
00:02:09,300 --> 00:02:11,460
on the entire network.

43
00:02:11,460 --> 00:02:13,860
And that's gonna be this guy here.

44
00:02:13,860 --> 00:02:16,500
That guy is gonna protect
the entire network

45
00:02:16,500 --> 00:02:18,873
from intrusion from the Internet.

46
00:02:20,460 --> 00:02:22,953
Next is IDS and IPS,

47
00:02:24,510 --> 00:02:27,900
and these are systems that either detect

48
00:02:27,900 --> 00:02:31,323
or prevent unauthorized access.

49
00:02:32,460 --> 00:02:35,400
Intrusion Detection Systems can determine

50
00:02:35,400 --> 00:02:37,740
whether an unauthorized person

51
00:02:37,740 --> 00:02:40,530
has attempted to access the network,

52
00:02:40,530 --> 00:02:44,940
and then alert the system's
administrator of its findings.

53
00:02:44,940 --> 00:02:48,720
Intrusion Prevention
Systems will not only detect

54
00:02:48,720 --> 00:02:52,950
unauthorized access, but
attempt to prevent it,

55
00:02:52,950 --> 00:02:55,170
making the admin's job somewhat easier,

56
00:02:55,170 --> 00:03:00,170
and these could be set up as
an additional device, say here,

57
00:03:02,550 --> 00:03:03,963
behind the firewall,

58
00:03:05,130 --> 00:03:08,130
or they could be set up
as software on a server.

59
00:03:08,130 --> 00:03:10,380
There's a variety of ways to do this,

60
00:03:10,380 --> 00:03:13,440
but the idea is it goes past
what a firewall could do.

61
00:03:13,440 --> 00:03:15,573
The firewall blocks ports.

62
00:03:16,710 --> 00:03:19,140
And it's blocking all
the ports that are open,

63
00:03:19,140 --> 00:03:21,270
inbound from the Internet.

64
00:03:21,270 --> 00:03:24,060
It's gonna close those,
it's gonna shield those.

65
00:03:24,060 --> 00:03:28,080
The IDS and the IPS will
go to the next level.

66
00:03:28,080 --> 00:03:29,850
They'll inspect the packets,

67
00:03:29,850 --> 00:03:32,520
and see if someone is
actually trying to get in

68
00:03:32,520 --> 00:03:34,830
that should not be getting in.

69
00:03:34,830 --> 00:03:36,480
So a little bit more advanced,

70
00:03:36,480 --> 00:03:38,970
and more processing required with those,

71
00:03:38,970 --> 00:03:41,040
and some more expense.

72
00:03:41,040 --> 00:03:46,040
Generally, you install an IPS
or an IDS as a network device,

73
00:03:46,440 --> 00:03:48,960
a box that's installed here.

74
00:03:48,960 --> 00:03:52,350
But it could be installed
on a host computer as well,

75
00:03:52,350 --> 00:03:54,003
perhaps on say a server.

76
00:03:54,870 --> 00:03:57,150
You might have an FTP server,

77
00:03:57,150 --> 00:03:59,580
and you want to monitor that guy

78
00:03:59,580 --> 00:04:02,580
as far as who is gaining access to it,

79
00:04:02,580 --> 00:04:06,120
and so you might install
an IDS or IPS solution

80
00:04:06,120 --> 00:04:08,850
for this server in software,

81
00:04:08,850 --> 00:04:13,653
and that would be known
as a HIDS or a HIPS.

82
00:04:16,230 --> 00:04:18,330
Host-based Intrusion Detection,

83
00:04:18,330 --> 00:04:20,850
or Host-based Intrusion Prevention,

84
00:04:20,850 --> 00:04:22,590
and you can install that on the server.

85
00:04:22,590 --> 00:04:25,290
But generally, it's the network
that you want to protect.

86
00:04:25,290 --> 00:04:27,270
You're looking at the whole network here

87
00:04:27,270 --> 00:04:29,370
that you want to protect,
all the computers.

88
00:04:29,370 --> 00:04:34,200
And so that's gonna be a NIDS,
Network Intrusion Detection,

89
00:04:34,200 --> 00:04:37,800
or NIPS, that's what this guy's gonna be.

90
00:04:37,800 --> 00:04:40,950
Network Intrusion Detection or
Network Intrusion Prevention.

91
00:04:40,950 --> 00:04:43,200
And install that right
behind the firewall,

92
00:04:43,200 --> 00:04:45,003
on your side of the firewall,

93
00:04:46,050 --> 00:04:49,620
basically within the LAN but
right next to the firewall.

94
00:04:49,620 --> 00:04:51,690
And there's a variety of
ways to do that installation.

95
00:04:51,690 --> 00:04:52,530
There's other ways to do it.

96
00:04:52,530 --> 00:04:54,390
That's not the only possibility,

97
00:04:54,390 --> 00:04:55,743
but that's gonna be common.

98
00:04:56,850 --> 00:04:59,760
So that's a little bit about IDS and IPS.

99
00:04:59,760 --> 00:05:02,340
Now, there's other security options.

100
00:05:02,340 --> 00:05:04,410
You know, you might have a small network,

101
00:05:04,410 --> 00:05:07,020
and you might have a
four-port SOHO router,

102
00:05:07,020 --> 00:05:11,430
which acts as a firewall,
and it acts as NAT device,

103
00:05:11,430 --> 00:05:13,830
and it acts as a DHCP server,

104
00:05:13,830 --> 00:05:15,870
and it acts as all these things.

105
00:05:15,870 --> 00:05:18,690
So if you have a smaller
network, you might have something

106
00:05:18,690 --> 00:05:20,670
that kind of combines all this stuff,

107
00:05:20,670 --> 00:05:24,060
and it might even do some packet analysis.

108
00:05:24,060 --> 00:05:25,530
But for the larger networks,

109
00:05:25,530 --> 00:05:28,320
if you want to combine this stuff together

110
00:05:28,320 --> 00:05:33,320
what you're gonna be looking
for is the UTM solution,

111
00:05:34,140 --> 00:05:36,733
and that's Unified Threat Management.

112
00:05:36,733 --> 00:05:40,800
A UTM gateway solution
is a device that combines

113
00:05:40,800 --> 00:05:45,090
multiple security features
of individual devices.

114
00:05:45,090 --> 00:05:48,180
It's the evolution of the firewall.

115
00:05:48,180 --> 00:05:50,070
So you have your firewall here,

116
00:05:50,070 --> 00:05:53,760
but it might actually take
the place of this whole guy,

117
00:05:53,760 --> 00:05:56,583
and act as a firewall,

118
00:05:58,530 --> 00:06:01,230
replacing him but also
incorporating features

119
00:06:01,230 --> 00:06:06,230
like antivirus, anti-spam,
content filtering,

120
00:06:06,330 --> 00:06:09,330
and intrusion prevention
that we mentioned before.

121
00:06:09,330 --> 00:06:12,360
So you can put all these things together,

122
00:06:12,360 --> 00:06:15,240
and add things like data loss prevention,

123
00:06:15,240 --> 00:06:18,030
and it's kind of the
next level of security.

124
00:06:18,030 --> 00:06:19,350
It's gonna cost more money,

125
00:06:19,350 --> 00:06:22,170
it's gonna require more administration,

126
00:06:22,170 --> 00:06:24,420
and so usually it'll be larger companies

127
00:06:24,420 --> 00:06:26,610
that'll use this type of solution,

128
00:06:26,610 --> 00:06:29,700
but there are small versions
as well for smaller companies.

129
00:06:29,700 --> 00:06:31,650
The one drawback to the UTM

130
00:06:31,650 --> 00:06:34,200
is that it's a single point of failure,

131
00:06:34,200 --> 00:06:39,120
and so some organizations
will install a second one.

132
00:06:39,120 --> 00:06:42,900
Or they'll have the firewall
and keep that firewall,

133
00:06:42,900 --> 00:06:47,250
and then install the UTM adjacent to it.

134
00:06:47,250 --> 00:06:48,690
So you have a couple options there.

135
00:06:48,690 --> 00:06:50,940
It all depends on your network,

136
00:06:50,940 --> 00:06:52,950
it all depends on your policies,

137
00:06:52,950 --> 00:06:56,190
it all depends on how much
money you have to spend.

138
00:06:56,190 --> 00:06:59,820
Another term you should know
for the CompTIA A+ exams

139
00:06:59,820 --> 00:07:02,430
is endpoint management.

140
00:07:02,430 --> 00:07:07,350
Endpoint management, or
endpoint security management,

141
00:07:07,350 --> 00:07:12,090
is a policy-based approach
to network security.

142
00:07:12,090 --> 00:07:14,460
It requires endpoint devices,

143
00:07:14,460 --> 00:07:18,330
meaning PCs, laptops, and mobile devices,

144
00:07:18,330 --> 00:07:21,810
to meet particular criteria

145
00:07:21,810 --> 00:07:25,803
before they can be granted
access to network resources.

146
00:07:28,260 --> 00:07:32,190
Endpoint management servers are servers

147
00:07:32,190 --> 00:07:36,480
that centrally control the discovery,

148
00:07:36,480 --> 00:07:39,870
and the deployment, and the updating

149
00:07:39,870 --> 00:07:43,500
of these security features
on endpoint devices.

150
00:07:43,500 --> 00:07:47,720
Companies such as Checkpoint
and Sophos and QOS and BMC

151
00:07:48,900 --> 00:07:52,050
offer endpoint management solutions.

152
00:07:52,050 --> 00:07:55,560
So you might have a server
located here on your LAN

153
00:07:55,560 --> 00:07:57,270
that connects to the switch,

154
00:07:57,270 --> 00:08:00,633
and takes control of those endpoints.

155
00:08:01,890 --> 00:08:04,800
Those PCs, those laptops,
those mobile devices,

156
00:08:04,800 --> 00:08:08,520
and takes care of locating
those devices, discovering them,

157
00:08:08,520 --> 00:08:10,890
and deploying and updating the software

158
00:08:10,890 --> 00:08:13,923
and security features to those endpoints.

159
00:08:15,090 --> 00:08:18,810
You should also know about
endpoint protection platforms.

160
00:08:18,810 --> 00:08:22,050
These should be installed
to all client computers,

161
00:08:22,050 --> 00:08:25,230
PCs, laptops, mobile devices, and so on,

162
00:08:25,230 --> 00:08:27,600
and should be updated across the board

163
00:08:27,600 --> 00:08:29,640
in a synchronous fashion.

164
00:08:29,640 --> 00:08:32,640
Examples of endpoint protection platforms

165
00:08:32,640 --> 00:08:37,640
are McAfee, Norton, or
Symantec, Kaspersky and so on.

166
00:08:38,160 --> 00:08:40,830
These are generally all-in-one solutions

167
00:08:40,830 --> 00:08:44,310
that have anti-virus, anti-spyware,

168
00:08:44,310 --> 00:08:48,900
personal firewalls, spam
protection, and so on.

169
00:08:48,900 --> 00:08:53,850
They might simply be referred
to as anti-malware suites,

170
00:08:53,850 --> 00:08:56,190
and could be just a portion

171
00:08:56,190 --> 00:09:01,080
of your entire endpoint
management implementation.

172
00:09:01,080 --> 00:09:03,900
So endpoint protection platforms

173
00:09:03,900 --> 00:09:08,370
and endpoint management
can go hand-in-hand.

174
00:09:08,370 --> 00:09:11,640
When we start controlling the deployment

175
00:09:11,640 --> 00:09:14,370
of this type of security software,

176
00:09:14,370 --> 00:09:16,650
and other security features,

177
00:09:16,650 --> 00:09:21,120
from, say, a centralized
administration location,

178
00:09:21,120 --> 00:09:23,850
such as server here on the LAN,

179
00:09:23,850 --> 00:09:27,360
then we are most likely
implementing the concept

180
00:09:27,360 --> 00:09:30,393
of endpoint security management.
