1
00:00:06,570 --> 00:00:08,400
- [Instructor] Let's talk firewalls.

2
00:00:08,400 --> 00:00:11,700
A firewall is a device or application

3
00:00:11,700 --> 00:00:13,980
designed to protect a network

4
00:00:13,980 --> 00:00:16,950
or individual computer from intrusion,

5
00:00:16,950 --> 00:00:19,350
and there's two main types
that you should know.

6
00:00:19,350 --> 00:00:22,260
The personal software
firewall is the first one.

7
00:00:22,260 --> 00:00:26,460
This is an application that's
loaded on your computer,

8
00:00:26,460 --> 00:00:27,750
whether it's a mobile device,

9
00:00:27,750 --> 00:00:30,420
or a PC, or laptop, or what have you.

10
00:00:30,420 --> 00:00:32,610
And it protects that individual computer

11
00:00:32,610 --> 00:00:35,340
from unwanted internet traffic,

12
00:00:35,340 --> 00:00:36,510
and it usually does so

13
00:00:36,510 --> 00:00:39,960
by way of a set of rules and policies.

14
00:00:39,960 --> 00:00:41,850
One example is the Windows firewall,

15
00:00:41,850 --> 00:00:43,320
this is built into Windows.

16
00:00:43,320 --> 00:00:45,750
If we go to the control panel

17
00:00:45,750 --> 00:00:48,570
and scroll down to Windows firewall,

18
00:00:48,570 --> 00:00:51,720
we can click on that and bring that up,

19
00:00:51,720 --> 00:00:54,210
and that's our windows
firewall built into this.

20
00:00:54,210 --> 00:00:56,880
And you can see here that
it's not on right now.

21
00:00:56,880 --> 00:00:58,680
Generally, if you see this on a computer

22
00:00:58,680 --> 00:01:00,330
you'll probably want to turn it on.

23
00:01:00,330 --> 00:01:02,070
So we'll click on the link

24
00:01:02,070 --> 00:01:05,550
and turn it on for the
private and for the public.

25
00:01:05,550 --> 00:01:07,890
OK it, and we're good to go

26
00:01:07,890 --> 00:01:09,900
and everything's green check marked.

27
00:01:09,900 --> 00:01:12,120
Also in Windows you have
the Windows firewall

28
00:01:12,120 --> 00:01:14,520
with advanced security,

29
00:01:14,520 --> 00:01:16,200
and you can bring that up by going

30
00:01:16,200 --> 00:01:19,477
to the run prompt and typing wf.msc.

31
00:01:21,210 --> 00:01:22,950
And I'll drag that window over,

32
00:01:22,950 --> 00:01:24,840
and this is a lot more in depth.

33
00:01:24,840 --> 00:01:28,560
You have all kinds of
rules for what you're doing

34
00:01:28,560 --> 00:01:31,200
on your computer, inbound and outbound,

35
00:01:31,200 --> 00:01:34,470
so you can really configure
this guy in more depth.

36
00:01:34,470 --> 00:01:36,780
So Windows firewall
with advanced security.

37
00:01:36,780 --> 00:01:40,260
Other examples include ZoneAlarm,

38
00:01:40,260 --> 00:01:45,260
and also for Linux you have
IP Firewall and iptables.

39
00:01:45,360 --> 00:01:47,490
So there's all kinds of options as far as

40
00:01:47,490 --> 00:01:49,533
personal firewalls go.

41
00:01:51,090 --> 00:01:55,110
The other type is gonna be
the network based firewall,

42
00:01:55,110 --> 00:01:56,340
and a network based firewall

43
00:01:56,340 --> 00:01:59,160
protects an entire network of computers

44
00:01:59,160 --> 00:02:01,440
from intrusion from the internet.

45
00:02:01,440 --> 00:02:04,740
And generally you're
talking about a device,

46
00:02:04,740 --> 00:02:06,720
a standalone device.

47
00:02:06,720 --> 00:02:10,350
This could be as simple as one
of those 4 port SOHO routers

48
00:02:10,350 --> 00:02:11,820
that has a built-in firewall,

49
00:02:11,820 --> 00:02:15,720
or it could be a standalone appliance,

50
00:02:15,720 --> 00:02:18,930
a black box something
by Cisco, or Check Point

51
00:02:18,930 --> 00:02:20,883
or Juniper, whatever.

52
00:02:22,320 --> 00:02:24,780
And let's show an example,
let's illustrate this.

53
00:02:24,780 --> 00:02:27,120
If you look here, we
have a set of computers

54
00:02:27,120 --> 00:02:28,890
connected to a switch,

55
00:02:28,890 --> 00:02:31,920
and then they are connected
out through the firewall.

56
00:02:31,920 --> 00:02:34,260
Now you'd probably have
a router here also where

57
00:02:34,260 --> 00:02:36,900
this would be an all in one
device or what have you,

58
00:02:36,900 --> 00:02:39,684
but we're depicting the firewall
here as a separate device

59
00:02:39,684 --> 00:02:44,100
which is behind the switch,
or behind the router,

60
00:02:44,100 --> 00:02:45,270
that's how it's considered.

61
00:02:45,270 --> 00:02:47,043
So these computers are on the LAN,

62
00:02:48,090 --> 00:02:50,670
they connect through the
firewall and out to the internet,

63
00:02:50,670 --> 00:02:52,410
so they can make connections to computers

64
00:02:52,410 --> 00:02:53,970
and servers on the internet,

65
00:02:53,970 --> 00:02:58,080
but those computers will not
be able to connect to these,

66
00:02:58,080 --> 00:03:00,210
the servers on the internet
will not be able to connect

67
00:03:00,210 --> 00:03:02,520
to these 'cause they'll
bounce off the firewall

68
00:03:02,520 --> 00:03:04,860
if it's configured properly.

69
00:03:04,860 --> 00:03:08,820
And generally the firewall
will include NAT filtering,

70
00:03:08,820 --> 00:03:12,870
or network address translation
endpoint filtering,

71
00:03:12,870 --> 00:03:16,147
and that filters, ports,
TCP and UDP ports,

72
00:03:16,147 --> 00:03:18,390
and it does this by matching the incoming

73
00:03:18,390 --> 00:03:20,070
and outgoing traffic,

74
00:03:20,070 --> 00:03:23,073
and making sure that all
the IP addresses correspond.

75
00:03:23,910 --> 00:03:27,210
And the firewall will
also do packet filtering,

76
00:03:27,210 --> 00:03:30,390
it'll inspect each packet
passing through the firewall

77
00:03:30,390 --> 00:03:34,530
and accept it or reject it
based on a set of rules.

78
00:03:34,530 --> 00:03:36,060
And the most common type

79
00:03:36,060 --> 00:03:40,413
is Stateful Packet Inspection, that's SPI.

80
00:03:41,520 --> 00:03:43,920
With Stateful Packet
Inspection it's looking

81
00:03:43,920 --> 00:03:46,110
at the actual packets,
it's breaking them down

82
00:03:46,110 --> 00:03:48,540
and making sure that they
are the type of packets

83
00:03:48,540 --> 00:03:50,280
that are acceptable.

84
00:03:50,280 --> 00:03:53,760
Stateless packet filtering
does not do that,

85
00:03:53,760 --> 00:03:55,620
and it doesn't retain a memory of packets

86
00:03:55,620 --> 00:03:57,750
that have passed through the
firewall, so not as good.

87
00:03:57,750 --> 00:03:58,770
But generally you're gonna use

88
00:03:58,770 --> 00:04:01,350
SPI Stateful Packet Inspection.

89
00:04:01,350 --> 00:04:02,970
Let's show an example of that.

90
00:04:02,970 --> 00:04:03,803
Okay, once again,

91
00:04:03,803 --> 00:04:07,860
here's our AC1750 SOHO all in one device

92
00:04:07,860 --> 00:04:09,600
and here's the firewall setting,

93
00:04:09,600 --> 00:04:12,150
and we have SPI, Stateful
Packet Inspection,

94
00:04:12,150 --> 00:04:13,740
and it is enabled.

95
00:04:13,740 --> 00:04:14,820
And that's what you want.

96
00:04:14,820 --> 00:04:17,232
You wanna make sure that that is enabled,

97
00:04:17,232 --> 00:04:20,308
so that you can have
this packet inspection

98
00:04:20,308 --> 00:04:23,550
and the firewall will block the
packets that you don't want.

99
00:04:23,550 --> 00:04:25,830
If we go to the advanced security section,

100
00:04:25,830 --> 00:04:27,690
you'll see that we can enable filtering

101
00:04:27,690 --> 00:04:29,400
for different types of attacks,

102
00:04:29,400 --> 00:04:33,750
like ICMP FLOODs, which
are basically ping packets

103
00:04:33,750 --> 00:04:38,750
and UDP FLOODs, TCP
synchronization FLOODs.

104
00:04:38,760 --> 00:04:40,680
So, you know, you could do a lot of this.

105
00:04:40,680 --> 00:04:43,650
You might set it to a
particular amount of packets.

106
00:04:43,650 --> 00:04:46,110
Like we could set this to 10

107
00:04:46,110 --> 00:04:48,420
and this way, if you're
external from the router

108
00:04:48,420 --> 00:04:51,030
and you want to see if
it actually works still,

109
00:04:51,030 --> 00:04:53,910
you could ping it and you'll get replies.

110
00:04:53,910 --> 00:04:56,520
But if you tried to do more than 10,

111
00:04:56,520 --> 00:05:01,520
like if you did a dash N space
50 with your ping command

112
00:05:02,400 --> 00:05:03,660
then this router would block it

113
00:05:03,660 --> 00:05:06,210
'cause that would go past the threshold.

114
00:05:06,210 --> 00:05:08,400
So you have some thresholds
that you can set here,

115
00:05:08,400 --> 00:05:10,260
so it's pretty cool.

116
00:05:10,260 --> 00:05:12,270
So that's a little bit about the firewall

117
00:05:12,270 --> 00:05:14,250
built into this router.

118
00:05:14,250 --> 00:05:18,120
And you know, keep in mind
that firewall could be built

119
00:05:18,120 --> 00:05:20,647
into your SOHO router, it
could be an all in one device,

120
00:05:20,647 --> 00:05:25,647
it could be part of a unified
threat management solution,

121
00:05:26,340 --> 00:05:29,520
but in some cases it'll
just be its own device,

122
00:05:29,520 --> 00:05:33,000
and you'll have your computers,
your switch, your router

123
00:05:33,000 --> 00:05:35,520
and then your firewall,
which is behind all that,

124
00:05:35,520 --> 00:05:38,220
and that's your first line of defense

125
00:05:38,220 --> 00:05:42,300
against intrusion from
computers on the internet.

126
00:05:42,300 --> 00:05:43,900
So that's it for the sub lesson.
