1
1

00:00:00,540  -->  00:00:03,000
<v Instructor>Firewall configurations.</v>
2

2

00:00:03,000  -->  00:00:05,580
Now, in the past, most of our network security
3

3

00:00:05,580  -->  00:00:07,860
was focused on boundary defense.
4

4

00:00:07,860  -->  00:00:09,090
The thought process was,
5

5

00:00:09,090  -->  00:00:10,770
that if you could secure your boundaries,
6

6

00:00:10,770  -->  00:00:12,240
then you could stop attackers
7

7

00:00:12,240  -->  00:00:15,480
but we all know these days, that just simply isn't true.
8

8

00:00:15,480  -->  00:00:17,520
Let me give you an analogy to show you the flaw
9

9

00:00:17,520  -->  00:00:20,070
in this boundary defense logic that's so heavily relied
10

10

00:00:20,070  -->  00:00:21,990
on using firewalls.
11

11

00:00:21,990  -->  00:00:23,100
Now, let's pretend you live
12

12

00:00:23,100  -->  00:00:26,220
in a small gated community with about 20 other houses.
13

13

00:00:26,220  -->  00:00:28,380
Now you want to ensure that nobody could break in,
14

14

00:00:28,380  -->  00:00:31,050
so the neighborhood watch gets together and you guys vote
15

15

00:00:31,050  -->  00:00:34,320
on putting in a big security gate at the end of the street.
16

16

00:00:34,320  -->  00:00:35,640
This way, only residents
17

17

00:00:35,640  -->  00:00:38,250
and their guests could get into the compound.
18

18

00:00:38,250  -->  00:00:39,540
Now the gate is installed
19

19

00:00:39,540  -->  00:00:41,580
and you start feeling relief and you're assured
20

20

00:00:41,580  -->  00:00:44,160
that nobody can get into your house or steal anything
21

21

00:00:44,160  -->  00:00:46,080
because you have this big security gate there.
22

22

00:00:46,080  -->  00:00:47,850
So you start leaving your doors unlocked
23

23

00:00:47,850  -->  00:00:50,040
and your windows open whenever you leave the house
24

24

00:00:50,040  -->  00:00:52,590
because after all, you trust all your neighbors.
25

25

00:00:52,590  -->  00:00:54,960
Well, one day you find your laptop has been stolen
26

26

00:00:54,960  -->  00:00:56,070
from your home office.
27

27

00:00:56,070  -->  00:00:57,540
Now, how could this be?
28

28

00:00:57,540  -->  00:00:59,040
Only people who live here can get
29

29

00:00:59,040  -->  00:01:00,240
into that neighborhood, right?
30

30

00:01:00,240  -->  00:01:01,440
And you trust all of them,
31

31

00:01:01,440  -->  00:01:03,600
so how can anything be stolen?
32

32

00:01:03,600  -->  00:01:05,580
Well, you check the security camera feed
33

33

00:01:05,580  -->  00:01:07,440
and you find out that one of your neighbor's
34

34

00:01:07,440  -->  00:01:10,080
teenage children had some friends over that weekend,
35

35

00:01:10,080  -->  00:01:12,150
and one of the friends walked over to your house,
36

36

00:01:12,150  -->  00:01:13,350
saw the door was open,
37

37

00:01:13,350  -->  00:01:16,020
went into your office and took your laptop.
38

38

00:01:16,020  -->  00:01:17,190
Alright, Jason, I get it.
39

39

00:01:17,190  -->  00:01:18,023
I get it.
40

40

00:01:18,023  -->  00:01:19,410
You can't trust everybody, right?
41

41

00:01:19,410  -->  00:01:20,880
That's the point of the story.
42

42

00:01:20,880  -->  00:01:22,950
Well, no, that's not the point of the story.
43

43

00:01:22,950  -->  00:01:23,910
The point of the story is
44

44

00:01:23,910  -->  00:01:25,980
that this is just like a computer network.
45

45

00:01:25,980  -->  00:01:28,260
That security gate is like a firewall,
46

46

00:01:28,260  -->  00:01:30,840
it allows people in and out, based on a rule set.
47

47

00:01:30,840  -->  00:01:32,730
Are you a resident or are you not a resident?
48

48

00:01:32,730  -->  00:01:35,460
Are you a guest or resident or are you not a guest?
49

49

00:01:35,460  -->  00:01:37,110
Now it's designed to keep things out,
50

50

00:01:37,110  -->  00:01:40,770
but if somebody who is trusted, like your users, goes ahead
51

51

00:01:40,770  -->  00:01:43,770
and opens it to let that bad factor in, in this case
52

52

00:01:43,770  -->  00:01:46,740
that opportunistic teenager who stole your laptop,
53

53

00:01:46,740  -->  00:01:47,670
then guess what?
54

54

00:01:47,670  -->  00:01:49,920
The firewall isn't enough on its own.
55

55

00:01:49,920  -->  00:01:51,810
Now, I'm not saying firewalls are bad.
56

56

00:01:51,810  -->  00:01:53,790
In fact, firewalls are an essential part
57

57

00:01:53,790  -->  00:01:55,590
of a layered defense strategy,
58

58

00:01:55,590  -->  00:01:57,630
but they are just one of the layers of defense
59

59

00:01:57,630  -->  00:01:59,940
that we need to combine with other defenses.
60

60

00:01:59,940  -->  00:02:01,740
So we need to take that network-based defense
61

61

00:02:01,740  -->  00:02:04,410
like a firewall and combine it with a host-based defense,
62

62

00:02:04,410  -->  00:02:06,060
like a host intrusion detection
63

63

00:02:06,060  -->  00:02:08,400
or host intrusion prevention system.
64

64

00:02:08,400  -->  00:02:10,410
Now, we do this with a lot of other controls
65

65

00:02:10,410  -->  00:02:12,930
and that's how we get good layer defense.
66

66

00:02:12,930  -->  00:02:14,880
Now, this doesn't mean that we should abandon firewalls
67

67

00:02:14,880  -->  00:02:16,920
altogether though, but we have to realize,
68

68

00:02:16,920  -->  00:02:18,510
we can't solely rely on them
69

69

00:02:18,510  -->  00:02:20,760
as a perimeter protection to protect us
70

70

00:02:20,760  -->  00:02:22,560
from everything anymore.
71

71

00:02:22,560  -->  00:02:23,460
Because of this,
72

72

00:02:23,460  -->  00:02:26,460
we're going to continue to talk about firewalls in this lesson
73

73

00:02:26,460  -->  00:02:28,920
but as we go through the rest of this course section
74

74

00:02:28,920  -->  00:02:31,650
by section, we're going to keep expanding our defenses
75

75

00:02:31,650  -->  00:02:34,680
and talking about lots of other things that we can add.
76

76

00:02:34,680  -->  00:02:37,170
This way, we'll have a full gamut of protections,
77

77

00:02:37,170  -->  00:02:39,570
so we aren't relying on a single security gate alone
78

78

00:02:39,570  -->  00:02:40,890
like a firewall.
79

79

00:02:40,890  -->  00:02:42,510
Now, from your Network+ studies
80

80

00:02:42,510  -->  00:02:44,070
and your Security+ studies,
81

81

00:02:44,070  -->  00:02:45,990
you're familiar with what a firewall is
82

82

00:02:45,990  -->  00:02:47,160
and what it does.
83

83

00:02:47,160  -->  00:02:49,140
Now, there's lots of places you could put a firewall
84

84

00:02:49,140  -->  00:02:51,750
in your network and the most common of which is going to be
85

85

00:02:51,750  -->  00:02:53,070
on the exterior.
86

86

00:02:53,070  -->  00:02:55,530
So you're going to have your ISP or your router
87

87

00:02:55,530  -->  00:02:58,290
or your modem, and then that's going to connect to a firewall.
88

88

00:02:58,290  -->  00:03:00,420
You can see that here in the picture on the right.
89

89

00:03:00,420  -->  00:03:02,340
We have that screened subnet firewall.
90

90

00:03:02,340  -->  00:03:05,557
Now, inside of that we have this thing called an extranet
91

91

00:03:05,557  -->  00:03:07,440
and this is basically our screened subnet,
92

92

00:03:07,440  -->  00:03:09,150
it's our demilitarized zone,
93

93

00:03:09,150  -->  00:03:12,300
and then we have another firewall before we leave that area
94

94

00:03:12,300  -->  00:03:14,100
and go into the core of our network,
95

95

00:03:14,100  -->  00:03:15,750
which then gives us all the access
96

96

00:03:15,750  -->  00:03:17,730
that all of our devices are going to use.
97

97

00:03:17,730  -->  00:03:20,610
Now, this screened subnet segment is what I'm going to focus on
98

98

00:03:20,610  -->  00:03:22,110
for just a moment here.
99

99

00:03:22,110  -->  00:03:23,700
Inside of here is where we would put things
100

100

00:03:23,700  -->  00:03:28,650
like servers, web hosts, email, VoIP systems, VPN trunks,
101

101

00:03:28,650  -->  00:03:30,210
and things like that.
102

102

00:03:30,210  -->  00:03:31,890
Now, when we talk about a screened subnet,
103

103

00:03:31,890  -->  00:03:33,600
you should remember from your Network+
104

104

00:03:33,600  -->  00:03:36,000
and your Security+ studies that a screened subnet
105

105

00:03:36,000  -->  00:03:39,240
is this physical or logical subnetwork that contains
106

106

00:03:39,240  -->  00:03:42,510
and exposes an organization's external-facing services
107

107

00:03:42,510  -->  00:03:44,880
to an untrusted usually larger network,
108

108

00:03:44,880  -->  00:03:46,260
such as the internet.
109

109

00:03:46,260  -->  00:03:48,090
This screened subnet is the modern term
110

110

00:03:48,090  -->  00:03:49,920
for what used to be called a DMZ.
111

111

00:03:49,920  -->  00:03:51,840
Now, it doesn't have to be just the internet though.
112

112

00:03:51,840  -->  00:03:54,390
If we have third party suppliers that we connect to,
113

113

00:03:54,390  -->  00:03:56,880
we should have a firewall between us and them as well
114

114

00:03:56,880  -->  00:03:57,713
and they should be put
115

115

00:03:57,713  -->  00:03:59,610
into this untrusted screened subnet as well,
116

116

00:03:59,610  -->  00:04:02,640
because we don't trust all of our suppliers inherently.
117

117

00:04:02,640  -->  00:04:04,740
Again, this is concepts you should already know
118

118

00:04:04,740  -->  00:04:06,720
and we're just doing a quick review.
119

119

00:04:06,720  -->  00:04:08,940
Let's talk about ACLs for a moment.
120

120

00:04:08,940  -->  00:04:11,130
Now, ACLs are your firewall rule sets
121

121

00:04:11,130  -->  00:04:13,500
and we've already covered this a little bit in this course.
122

122

00:04:13,500  -->  00:04:15,090
Now, when you deal with an ACL,
123

123

00:04:15,090  -->  00:04:17,790
these are going to be processed from top to bottom
124

124

00:04:17,790  -->  00:04:20,100
where the most specific rules are at the top,
125

125

00:04:20,100  -->  00:04:21,270
and the least specific
126

126

00:04:21,270  -->  00:04:24,120
or most generic rules are going to be at the bottom.
127

127

00:04:24,120  -->  00:04:26,070
Now, there are some basic rules that we have to talk
128

128

00:04:26,070  -->  00:04:27,450
about when we think about ACLS,
129

129

00:04:27,450  -->  00:04:29,370
and then we're going to take a quick look at one.
130

130

00:04:29,370  -->  00:04:31,830
First, you need to block incoming requests
131

131

00:04:31,830  -->  00:04:36,030
from internal or private, loopback, and multicast IP ranges.
132

132

00:04:36,030  -->  00:04:37,170
If you have something coming
133

133

00:04:37,170  -->  00:04:41,040
from a 192.168.something.something IP,
134

134

00:04:41,040  -->  00:04:43,080
and it's coming from the internet, well
135

135

00:04:43,080  -->  00:04:44,730
you know that's a non-routable IP
136

136

00:04:44,730  -->  00:04:46,230
and so you should be blocking that,
137

137

00:04:46,230  -->  00:04:49,110
that should not be allowed to come into your network.
138

138

00:04:49,110  -->  00:04:52,080
Similarly, if you start seeing source IP addresses coming
139

139

00:04:52,080  -->  00:04:54,240
from areas that are reserved, these are things
140

140

00:04:54,240  -->  00:04:55,800
that you want to make sure are getting blocked
141

141

00:04:55,800  -->  00:04:57,990
because they are not going to be holding anything good
142

142

00:04:57,990  -->  00:04:59,580
for your network.
143

143

00:04:59,580  -->  00:05:01,800
Second, you want to block incoming requests
144

144

00:05:01,800  -->  00:05:04,050
from protocols that should only be used locally.
145

145

00:05:04,050  -->  00:05:05,010
For instance,
146

146

00:05:05,010  -->  00:05:10,010
ICMP, DHCP, OSPF, SMB, and other things.
147

147

00:05:10,380  -->  00:05:12,360
If you have something like Windows File Sharing,
148

148

00:05:12,360  -->  00:05:14,070
that shouldn't happen over the internet,
149

149

00:05:14,070  -->  00:05:16,680
it should only happen inside your local network.
150

150

00:05:16,680  -->  00:05:18,330
So again, you should be blocking that
151

151

00:05:18,330  -->  00:05:21,180
at the firewall at the exterior of your network.
152

152

00:05:21,180  -->  00:05:23,490
If somebody has a VPN, they'll be able to tunnel
153

153

00:05:23,490  -->  00:05:26,220
in through the firewall and then use those protocols,
154

154

00:05:26,220  -->  00:05:28,020
but if they're coming straight from the internet,
155

155

00:05:28,020  -->  00:05:30,960
they should not be using those protocols on your network.
156

156

00:05:30,960  -->  00:05:32,820
The third thing you want to consider is how
157

157

00:05:32,820  -->  00:05:35,010
you're going to configure IPv6.
158

158

00:05:35,010  -->  00:05:36,930
I recommend you configure IPv6
159

159

00:05:36,930  -->  00:05:39,420
to either block all IPv6 traffic
160

160

00:05:39,420  -->  00:05:42,750
or you allow it to only authorized hosts and ports.
161

161

00:05:42,750  -->  00:05:44,160
Now, the reason this is recommended
162

162

00:05:44,160  -->  00:05:46,260
is because a lot of hosts run dual-stack
163

163

00:05:46,260  -->  00:05:48,270
TCP IP implementations
164

164

00:05:48,270  -->  00:05:50,610
with IPv6 enabled by default,
165

165

00:05:50,610  -->  00:05:54,000
and a lot of organizations are still running Ipv4 only,
166

166

00:05:54,000  -->  00:05:56,910
but they don't turn off IPv6 on those hosts,
167

167

00:05:56,910  -->  00:05:59,490
and this misconfiguration could allow adversaries
168

168

00:05:59,490  -->  00:06:01,950
unfiltered access into your network using
169

169

00:06:01,950  -->  00:06:04,560
that IPv6 area because a lot of administrators
170

170

00:06:04,560  -->  00:06:06,900
haven't locked down IPv6 well yet.
171

171

00:06:06,900  -->  00:06:07,830
So keep that in mind
172

172

00:06:07,830  -->  00:06:09,930
as you're doing your configurations of your firewalls
173

173

00:06:09,930  -->  00:06:12,540
and as you're reviewing configurations of your firewalls.
174

174

00:06:12,540  -->  00:06:15,780
Now, let's go ahead and take a look at a basic access list.
175

175

00:06:15,780  -->  00:06:18,960
This one comes from a Cisco firewall, but on the exam,
176

176

00:06:18,960  -->  00:06:19,800
they may of showed you one
177

177

00:06:19,800  -->  00:06:22,290
from a Cisco firewall or any other firewall.
178

178

00:06:22,290  -->  00:06:25,560
It doesn't really matter because CompTIA is vendor agnostic.
179

179

00:06:25,560  -->  00:06:27,870
But if you can read a basic firewall log like this,
180

180

00:06:27,870  -->  00:06:29,730
you'll do fine on the exam.
181

181

00:06:29,730  -->  00:06:31,170
Now, let's start out with the first line,
182

182

00:06:31,170  -->  00:06:34,020
IP access list extended from DMZ.
183

183

00:06:34,020  -->  00:06:36,210
This just says what this access list is.
184

184

00:06:36,210  -->  00:06:38,970
In this case, it's what I'm using for a DMZ.
185

185

00:06:38,970  -->  00:06:40,800
The second line is a remark line.
186

186

00:06:40,800  -->  00:06:42,990
This tells you what the next section is going to talk about,
187

187

00:06:42,990  -->  00:06:44,220
basically it's a comet.
188

188

00:06:44,220  -->  00:06:46,800
These are going to be responses to HTTP requests
189

189

00:06:46,800  -->  00:06:49,260
and then we get a bunch of permit statements.
190

190

00:06:49,260  -->  00:06:50,910
Now, as we go through these permit statements,
191

191

00:06:50,910  -->  00:06:52,500
this is going to tell you permit or deny,
192

192

00:06:52,500  -->  00:06:54,180
what is the action involved.
193

193

00:06:54,180  -->  00:06:57,120
In this case, we're going to permit something from happening.
194

194

00:06:57,120  -->  00:06:57,990
Now when we permit it
195

195

00:06:57,990  -->  00:07:00,870
we're going to allow it and we're going to allow TCP traffic,
196

196

00:07:00,870  -->  00:07:02,670
so we have permit tcp.
197

197

00:07:02,670  -->  00:07:04,860
And then we have the IP address that's going to be associated
198

198

00:07:04,860  -->  00:07:05,693
with it.
199

199

00:07:05,693  -->  00:07:08,010
In this case, we're going to permit TCP traffic
200

200

00:07:08,010  -->  00:07:11,460
from IP address 10.0.2.0.
201

201

00:07:11,460  -->  00:07:13,530
The next thing is going to be our wild card mask.
202

202

00:07:13,530  -->  00:07:14,670
Now, this looks a little funny
203

203

00:07:14,670  -->  00:07:16,410
if you're used to Network+.
204

204

00:07:16,410  -->  00:07:19,680
You see that it's 0.0.0.255
205

205

00:07:19,680  -->  00:07:22,770
and this is because Cisco uses a reverse wildcard.
206

206

00:07:22,770  -->  00:07:24,390
So really you can read this going back
207

207

00:07:24,390  -->  00:07:29,040
to your subnet mask as 255.255.255.0.
208

208

00:07:29,040  -->  00:07:30,420
This is just a Cisco thing.
209

209

00:07:30,420  -->  00:07:31,890
Don't let it get you confused.
210

210

00:07:31,890  -->  00:07:33,360
But essentially what this is saying is
211

211

00:07:33,360  -->  00:07:35,610
that we are permitting TCP traffic
212

212

00:07:35,610  -->  00:07:39,420
for any IP that is 10.0.2.something.
213

213

00:07:39,420  -->  00:07:40,253
So anything
214

214

00:07:40,253  -->  00:07:43,260
in that IP range will be permitted under this rule.
215

215

00:07:43,260  -->  00:07:46,260
Then the next part is eq, which says equals.
216

216

00:07:46,260  -->  00:07:48,600
So this IP that has whatever's
217

217

00:07:48,600  -->  00:07:51,030
beyond the equal sign will be allowed,
218

218

00:07:51,030  -->  00:07:53,970
and in this case, we're equaling www.
219

219

00:07:53,970  -->  00:07:57,420
What that means is port 80, if somebody has made a request
220

220

00:07:57,420  -->  00:08:00,870
over port 80 for one of these IPs, it's going to be allowed.
221

221

00:08:00,870  -->  00:08:03,180
And then the next part is any which says this is
222

222

00:08:03,180  -->  00:08:06,900
going to be any IP is the destination that we're going to,
223

223

00:08:06,900  -->  00:08:09,690
and then we're going to have an established connection.
224

224

00:08:09,690  -->  00:08:11,940
So anytime we have an established connection
225

225

00:08:11,940  -->  00:08:16,940
from 10.0.2.something to some website over port 80,
226

226

00:08:17,400  -->  00:08:19,200
we're going to allow that traffic to happen.
227

227

00:08:19,200  -->  00:08:21,360
Essentially, this says we are going to allow somebody
228

228

00:08:21,360  -->  00:08:23,880
within our network to go out and access a website.
229

229

00:08:23,880  -->  00:08:25,290
That's all this line says.
230

230

00:08:25,290  -->  00:08:26,850
And as you go through and you can read these,
231

231

00:08:26,850  -->  00:08:27,683
you can start figuring
232

232

00:08:27,683  -->  00:08:29,610
out what is permitted and what is denied.
233

233

00:08:29,610  -->  00:08:32,100
Now, in this case, everything here is permitted
234

234

00:08:32,100  -->  00:08:34,740
because we are doing explicit permissions.
235

235

00:08:34,740  -->  00:08:38,670
We are saying yes, these things are allowed, but when we get
236

236

00:08:38,670  -->  00:08:42,720
down to the bottom, you'll see deny IP, any any.
237

237

00:08:42,720  -->  00:08:45,510
And with this means, this is an explicit deny.
238

238

00:08:45,510  -->  00:08:48,060
It's saying anything that is not already allowed,
239

239

00:08:48,060  -->  00:08:49,350
we are going to deny.
240

240

00:08:49,350  -->  00:08:50,850
So if we go down this list,
241

241

00:08:50,850  -->  00:08:55,850
you'll see things like www, 443, echo reply, domain,
242

242

00:08:56,520  -->  00:08:58,080
these are the things that are allowed,
243

243

00:08:58,080  -->  00:09:00,510
and when I talk about domain here, we're talking about DNS.
244

244

00:09:00,510  -->  00:09:03,480
That's the way that Cisco talks about DNS servers.
245

245

00:09:03,480  -->  00:09:06,360
So this is basically saying equals port 53,
246

246

00:09:06,360  -->  00:09:07,500
but as you look through this,
247

247

00:09:07,500  -->  00:09:09,600
these are all the things that are allowed going
248

248

00:09:09,600  -->  00:09:11,250
from the DMZ.
249

249

00:09:11,250  -->  00:09:12,360
The DMZ can go out
250

250

00:09:12,360  -->  00:09:15,720
and get web traffic over port 80 or port 443.
251

251

00:09:15,720  -->  00:09:19,440
It can reply to echo requests, which is ICMP.
252

252

00:09:19,440  -->  00:09:23,880
It can use port 53 both as UDP and TCP.
253

253

00:09:23,880  -->  00:09:26,070
These are the things that this thing is allowed to do
254

254

00:09:26,070  -->  00:09:27,240
from this range.
255

255

00:09:27,240  -->  00:09:29,190
Now, when I get down to the last statement,
256

256

00:09:29,190  -->  00:09:31,770
if any of those things didn't happen, for instance
257

257

00:09:31,770  -->  00:09:34,980
somebody tried to go to port 21 and access FTP,
258

258

00:09:34,980  -->  00:09:36,030
what would happen?
259

259

00:09:36,030  -->  00:09:37,590
We would get down to that last statement
260

260

00:09:37,590  -->  00:09:39,540
which is deny any any,
261

261

00:09:39,540  -->  00:09:44,540
this means deny any IP going from any IP to any IP,
262

262

00:09:44,580  -->  00:09:47,934
and this ACLs configured essentially as a allow list.
263

263

00:09:47,934  -->  00:09:50,160
Only the things allowed, permitted are going to happen.
264

264

00:09:50,160  -->  00:09:52,200
Everything else will get blocked.
265

265

00:09:52,200  -->  00:09:53,430
Now, another thing we need to talk
266

266

00:09:53,430  -->  00:09:56,850
about with this deny is what is deny really going to do?
267

267

00:09:56,850  -->  00:09:58,230
Well, it can do two things.
268

268

00:09:58,230  -->  00:10:00,420
It can drop or it can reject.
269

269

00:10:00,420  -->  00:10:02,190
Now, I know those sound like the same thing
270

270

00:10:02,190  -->  00:10:05,160
but in firewalls, that is actually a different action.
271

271

00:10:05,160  -->  00:10:06,600
You can configure your firewall
272

272

00:10:06,600  -->  00:10:07,740
of how it's going to respond
273

273

00:10:07,740  -->  00:10:10,050
when it hits a deny statement, is it going to
274

274

00:10:10,050  -->  00:10:12,360
drop that traffic or is it going to reject it?
275

275

00:10:12,360  -->  00:10:14,760
Now, any deny rule can either drop a packet
276

276

00:10:14,760  -->  00:10:17,820
or explicitly reject it by sending a TCP reset
277

277

00:10:17,820  -->  00:10:19,650
if you're doing a TCP connection,
278

278

00:10:19,650  -->  00:10:22,710
or an ICP port or protocol unreachable
279

279

00:10:22,710  -->  00:10:25,290
if you're using UDP back to the requester.
280

280

00:10:25,290  -->  00:10:28,500
Now, why would you want to drop something versus rejecting it?
281

281

00:10:28,500  -->  00:10:30,750
Well, by dropping traffic, it makes it harder
282

282

00:10:30,750  -->  00:10:34,080
for an adversary to identify port states more accurately.
283

283

00:10:34,080  -->  00:10:36,180
For instance, there's a thing called firewalking.
284

284

00:10:36,180  -->  00:10:38,580
And firewalking allows an attacker to
285

285

00:10:38,580  -->  00:10:40,800
use this reconnaissance technique to enumerate
286

286

00:10:40,800  -->  00:10:42,870
your firewall configuration and attempt to figure
287

287

00:10:42,870  -->  00:10:44,850
out what hosts are sitting behind it.
288

288

00:10:44,850  -->  00:10:45,870
So if you have a firewall,
289

289

00:10:45,870  -->  00:10:47,520
you don't want people to see what's behind there.
290

290

00:10:47,520  -->  00:10:50,460
You don't want them to see your servers and your host, but
291

291

00:10:50,460  -->  00:10:52,020
if an attacker uses firewalking,
292

292

00:10:52,020  -->  00:10:53,520
they can actually go through your firewall
293

293

00:10:53,520  -->  00:10:55,050
and figure those things out.
294

294

00:10:55,050  -->  00:10:56,820
Now, you might say, how do they do that?
295

295

00:10:56,820  -->  00:10:59,010
Well, firewalking is going to occur when
296

296

00:10:59,010  -->  00:11:01,470
an attacker finds an open port on a firewall
297

297

00:11:01,470  -->  00:11:03,360
and then they send a packet with a TTL,
298

298

00:11:03,360  -->  00:11:07,080
a time to live of one past the firewall to find its host.
299

299

00:11:07,080  -->  00:11:08,010
So maybe I found
300

300

00:11:08,010  -->  00:11:10,950
that this particular firewall ACL had port 80 open
301

301

00:11:10,950  -->  00:11:12,630
because they're running a web server.
302

302

00:11:12,630  -->  00:11:14,070
I can then use that port to get
303

303

00:11:14,070  -->  00:11:17,130
into the network and then see what other servers are around
304

304

00:11:17,130  -->  00:11:19,080
by attempting to enumerate different servers
305

305

00:11:19,080  -->  00:11:22,530
within that network, that's the way firewalking works.
306

306

00:11:22,530  -->  00:11:24,570
Now, how do you stop firewalking?
307

307

00:11:24,570  -->  00:11:25,710
Well, the easiest way is
308

308

00:11:25,710  -->  00:11:28,800
by blocking outgoing ICMP status messages.
309

309

00:11:28,800  -->  00:11:30,030
This will prevent firewalking
310

310

00:11:30,030  -->  00:11:32,070
because I said, they're going to send something in
311

311

00:11:32,070  -->  00:11:34,950
with a time to live of one past the firewall.
312

312

00:11:34,950  -->  00:11:37,200
That means, when that time to live expires
313

313

00:11:37,200  -->  00:11:39,240
by default, it's going to send back an ICMP
314

314

00:11:39,240  -->  00:11:41,610
status saying destination unreachable.
315

315

00:11:41,610  -->  00:11:43,890
Well, if you block outgoing ICMP,
316

316

00:11:43,890  -->  00:11:45,120
they'll never get that message
317

317

00:11:45,120  -->  00:11:47,220
and therefore firewalking will be prevented.
318

318

00:11:47,220  -->  00:11:49,650
Now, speaking of all these things, leaving our network
319

319

00:11:49,650  -->  00:11:52,110
and going back out, how do we filter these things?
320

320

00:11:52,110  -->  00:11:54,630
Well, this is known as egress filtering,
321

321

00:11:54,630  -->  00:11:57,210
and the way we do this is we apply ACL rules
322

322

00:11:57,210  -->  00:11:59,910
to the traffic leaving our network to prevent malware
323

323

00:11:59,910  -->  00:12:02,310
from communicating to command and control servers
324

324

00:12:02,310  -->  00:12:04,200
or people fingerprinting our network
325

325

00:12:04,200  -->  00:12:05,730
or people firewalking our network
326

326

00:12:05,730  -->  00:12:08,250
or just stopping anything from leaving our network.
327

327

00:12:08,250  -->  00:12:09,510
But the big area that we're concerned
328

328

00:12:09,510  -->  00:12:11,040
with right now is malware,
329

329

00:12:11,040  -->  00:12:13,860
because we have all these malware that can be beaconing out
330

330

00:12:13,860  -->  00:12:14,693
and if we can block it
331

331

00:12:14,693  -->  00:12:17,220
at the firewall and they can't reach their C2 server,
332

332

00:12:17,220  -->  00:12:19,410
they then can't do anything bad to us.
333

333

00:12:19,410  -->  00:12:21,000
So what are some of the best practices
334

334

00:12:21,000  -->  00:12:22,890
for configuring egress filters to be able to
335

335

00:12:22,890  -->  00:12:25,350
prevent these things from happening to us and make sure
336

336

00:12:25,350  -->  00:12:27,750
that we are not going to be targets of something bad?
337

337

00:12:27,750  -->  00:12:29,250
Well, the first thing you want to do is only
338

338

00:12:29,250  -->  00:12:31,140
allow whitelisted application ports
339

339

00:12:31,140  -->  00:12:32,550
and destination addresses
340

340

00:12:32,550  -->  00:12:34,470
to be allowed to leave your network.
341

341

00:12:34,470  -->  00:12:36,660
As you saw in the ACL I showed you before,
342

342

00:12:36,660  -->  00:12:38,730
we only permitted a couple of things.
343

343

00:12:38,730  -->  00:12:42,780
We allowed port 80 and port 443 and port 53,
344

344

00:12:42,780  -->  00:12:43,710
that was it.
345

345

00:12:43,710  -->  00:12:45,300
We wanted to make sure we kept it as tight
346

346

00:12:45,300  -->  00:12:48,570
as possible to make sure nothing bad left our network.
347

347

00:12:48,570  -->  00:12:50,730
By using this allow list approach, you really
348

348

00:12:50,730  -->  00:12:53,130
can control what's leaving your network a lot better
349

349

00:12:53,130  -->  00:12:55,230
and make yourself a lot more secure.
350

350

00:12:55,230  -->  00:12:57,990
The second thing you want to do is restrict DNS lookups
351

351

00:12:57,990  -->  00:13:00,330
to trusted and authorized DNS services.
352

352

00:13:00,330  -->  00:13:03,450
We talked about secure and recursive DNS lookups previously
353

353

00:13:03,450  -->  00:13:05,370
and this is basically that same idea.
354

354

00:13:05,370  -->  00:13:06,750
If we restrict the DNS lookups
355

355

00:13:06,750  -->  00:13:09,570
to our own DNS servers or our ISP's DNS servers
356

356

00:13:09,570  -->  00:13:12,120
or something like Google's DNS servers that we trust,
357

357

00:13:12,120  -->  00:13:14,280
we can then be assured that these are good things.
358

358

00:13:14,280  -->  00:13:17,490
And so we can actually lock that down by using ACLs
359

359

00:13:17,490  -->  00:13:21,960
and defining where, which IPs we can use port 53 over.
360

360

00:13:21,960  -->  00:13:24,510
The third thing we want to talk about here is blocking access
361

361

00:13:24,510  -->  00:13:27,690
to known bad IP addresses, known as a block list.
362

362

00:13:27,690  -->  00:13:29,940
We've talked about this before and we talked about this
363

363

00:13:29,940  -->  00:13:32,220
with fast flux networks where it wasn't very effective
364

364

00:13:32,220  -->  00:13:33,870
against that, but it is effective
365

365

00:13:33,870  -->  00:13:36,390
against a wide variety of other things.
366

366

00:13:36,390  -->  00:13:38,280
Now, when you have a known bad IP address,
367

367

00:13:38,280  -->  00:13:39,840
you want to drop that traffic,
368

368

00:13:39,840  -->  00:13:41,370
you don't want to respond back to it,
369

369

00:13:41,370  -->  00:13:42,870
you don't want to send 'em a reset packet,
370

370

00:13:42,870  -->  00:13:44,580
you just want the traffic to go away
371

371

00:13:44,580  -->  00:13:46,080
so they don't know that you dropped it.
372

372

00:13:46,080  -->  00:13:48,540
The fourth step is to block all internet access
373

373

00:13:48,540  -->  00:13:50,640
from host subnets that don't need it.
374

374

00:13:50,640  -->  00:13:53,520
So for example, do you have some ICS and SCADA systems
375

375

00:13:53,520  -->  00:13:55,530
'cause you work for a big manufacturing plant?
376

376

00:13:55,530  -->  00:13:57,420
Do they really need to connect to the internet?
377

377

00:13:57,420  -->  00:13:59,970
Well, if they don't, block access from it.
378

378

00:13:59,970  -->  00:14:01,830
That way they can remain on your network
379

379

00:14:01,830  -->  00:14:03,780
but they can't touch the outside world.
380

380

00:14:03,780  -->  00:14:05,400
And if they can't touch the outside world,
381

381

00:14:05,400  -->  00:14:08,100
then hopefully the outside world can't touch them either.
382

382

00:14:08,100  -->  00:14:10,740
So that's another best practice when we talk about egress.
383

383

00:14:10,740  -->  00:14:13,200
Now, while all these best practices can help,
384

384

00:14:13,200  -->  00:14:16,710
they're not going to eliminate a hundred percent of malware C2,
385

385

00:14:16,710  -->  00:14:18,570
because a lot of these things will also operate
386

386

00:14:18,570  -->  00:14:22,800
over social media or cloud-based HTTPS connections.
387

387

00:14:22,800  -->  00:14:25,890
For example, if somebody has access to a Slack server,
388

388

00:14:25,890  -->  00:14:27,510
you can run malware over that.
389

389

00:14:27,510  -->  00:14:30,000
If somebody has access to Facebook Messenger,
390

390

00:14:30,000  -->  00:14:31,740
you can run malware over that.
391

391

00:14:31,740  -->  00:14:33,390
All of these things can be turned
392

392

00:14:33,390  -->  00:14:36,900
into malware C2 services by an appropriate attacker.
393

393

00:14:36,900  -->  00:14:39,510
But by doing some of this egress management
394

394

00:14:39,510  -->  00:14:41,610
and blocking things down and locking things
395

395

00:14:41,610  -->  00:14:44,370
down to an allow list, you can eliminate a lot
396

396

00:14:44,370  -->  00:14:46,530
of those threat vectors, and then you can focus on
397

397

00:14:46,530  -->  00:14:48,660
the ones remaining by using other techniques.
398

398

00:14:48,660  -->  00:14:50,310
Now the next concept we want to talk
399

399

00:14:50,310  -->  00:14:52,470
about is the the concept of a black hole.
400

400

00:14:52,470  -->  00:14:54,450
And this is another way to configure things
401

401

00:14:54,450  -->  00:14:55,890
within your ACLs.
402

402

00:14:55,890  -->  00:14:58,800
A black hole is a means of mitigating denial of service
403

403

00:14:58,800  -->  00:15:00,000
or intrusion attack
404

404

00:15:00,000  -->  00:15:02,910
by silently dropping or discarding the traffic.
405

405

00:15:02,910  -->  00:15:05,730
Essentially you black hole it, you throw it away,
406

406

00:15:05,730  -->  00:15:08,010
and that way it doesn't get to the intended target.
407

407

00:15:08,010  -->  00:15:10,770
Now, blackholing can be very effective for you.
408

408

00:15:10,770  -->  00:15:11,970
It's actually a lot more effective
409

409

00:15:11,970  -->  00:15:14,070
than using an ACL on a firewall.
410

410

00:15:14,070  -->  00:15:15,150
Now why is that?
411

411

00:15:15,150  -->  00:15:16,530
Now blackholing can be done
412

412

00:15:16,530  -->  00:15:19,230
either at the firewall level or the router level.
413

413

00:15:19,230  -->  00:15:21,630
The problem is if you do it at the firewall level,
414

414

00:15:21,630  -->  00:15:23,370
you're going to be using a lot of processing power
415

415

00:15:23,370  -->  00:15:25,230
to process all those ACL rules
416

416

00:15:25,230  -->  00:15:27,000
and black hole that traffic.
417

417

00:15:27,000  -->  00:15:28,830
But if you do it at the router level,
418

418

00:15:28,830  -->  00:15:30,900
it actually is going to be a lot more efficient.
419

419

00:15:30,900  -->  00:15:31,740
So if you're going against
420

420

00:15:31,740  -->  00:15:33,630
a distributed denial of service attack,
421

421

00:15:33,630  -->  00:15:36,630
you should use blackholing to stop that DDoS attack
422

422

00:15:36,630  -->  00:15:37,860
at the routing level.
423

423

00:15:37,860  -->  00:15:38,880
So if you're trying to prevent
424

424

00:15:38,880  -->  00:15:40,710
a distributed denial of service attack,
425

425

00:15:40,710  -->  00:15:43,470
you're better off doing this at the routing layer.
426

426

00:15:43,470  -->  00:15:45,870
Blackholing can be used to stop the DDoS attack
427

427

00:15:45,870  -->  00:15:47,760
at the routing layer by sending traffic
428

428

00:15:47,760  -->  00:15:49,350
to the null interface.
429

429

00:15:49,350  -->  00:15:51,030
Now, the null interface is something that's
430

430

00:15:51,030  -->  00:15:52,890
on a Cisco router for example,
431

431

00:15:52,890  -->  00:15:55,590
and all it does is it drops any traffic that comes to it.
432

432

00:15:55,590  -->  00:15:58,470
It's basically saying, throw this away, don't respond to it,
433

433

00:15:58,470  -->  00:16:00,690
we don't care about it, and it silently drops
434

434

00:16:00,690  -->  00:16:03,024
that traffic and allows you to go about your day.
435

435

00:16:03,024  -->  00:16:05,820
Now, black hole routing can be more beneficial
436

436

00:16:05,820  -->  00:16:08,430
than other ways of doing things like going through ACLs
437

437

00:16:08,430  -->  00:16:10,590
and the reason is it uses a lot less resources
438

438

00:16:10,590  -->  00:16:13,050
like I said, than processing an ACL.
439

439

00:16:13,050  -->  00:16:14,580
But the challenge here is
440

440

00:16:14,580  -->  00:16:16,320
that when you do it at the routing layer,
441

441

00:16:16,320  -->  00:16:19,620
you could have legitimate users that lose access too.
442

442

00:16:19,620  -->  00:16:22,260
This is because a lot of times attackers don't just have
443

443

00:16:22,260  -->  00:16:24,360
a known block of bad IPs.
444

444

00:16:24,360  -->  00:16:27,420
Instead, they're using IPs like everybody else is using.
445

445

00:16:27,420  -->  00:16:28,920
And so maybe the guy in the apartment
446

446

00:16:28,920  -->  00:16:31,590
next door to me is using an internet connection that goes
447

447

00:16:31,590  -->  00:16:33,150
through my ISP just like I am,
448

448

00:16:33,150  -->  00:16:36,090
and he's part of this distributed denial of service attack.
449

449

00:16:36,090  -->  00:16:37,770
If you decide to do a /24
450

450

00:16:37,770  -->  00:16:39,630
and block everybody on that subnet,
451

451

00:16:39,630  -->  00:16:42,630
you might block me too and I might be a legitimate customer.
452

452

00:16:42,630  -->  00:16:43,830
And so that's one of the issues here
453

453

00:16:43,830  -->  00:16:44,663
that you have to deal with
454

454

00:16:44,663  -->  00:16:46,350
when you start dealing with blackholing.
455

455

00:16:46,350  -->  00:16:47,700
So this is just something you have to keep
456

456

00:16:47,700  -->  00:16:49,410
in mind as you're trying to create a black hole
457

457

00:16:49,410  -->  00:16:50,910
and protect your networks.
458

458

00:16:50,910  -->  00:16:53,670
Now, what is a really good use case for a black hole?
459

459

00:16:53,670  -->  00:16:56,730
Well, one of them is to use them against dark nets.
460

460

00:16:56,730  -->  00:16:59,730
Now, a dark net is any unused physical network ports
461

461

00:16:59,730  -->  00:17:01,440
or unused IP address space
462

462

00:17:01,440  -->  00:17:04,530
within a local network that's going to be used by an attacker.
463

463

00:17:04,530  -->  00:17:06,810
Essentially, let's say you're working for a large company,
464

464

00:17:06,810  -->  00:17:09,000
you've got thousands of computers.
465

465

00:17:09,000  -->  00:17:12,660
Well, you might have some kind of a /16 assigned to you,
466

466

00:17:12,660  -->  00:17:14,280
but you're only using a thousand
467

467

00:17:14,280  -->  00:17:17,130
or 2000 out of those 16,000 IPs.
468

468

00:17:17,130  -->  00:17:18,750
What are you doing with the rest of them?
469

469

00:17:18,750  -->  00:17:21,240
Well, if you want to have a better security posture,
470

470

00:17:21,240  -->  00:17:24,120
you should take all those extra IPs that you're not using
471

471

00:17:24,120  -->  00:17:26,040
and route them into a black hole.
472

472

00:17:26,040  -->  00:17:28,770
That way if an attacker is able to jump into one,
473

473

00:17:28,770  -->  00:17:29,970
they're automatically going to get routed
474

474

00:17:29,970  -->  00:17:32,670
into the black hole and not into your regular network.
475

475

00:17:32,670  -->  00:17:34,470
This redirection of all your dark nets
476

476

00:17:34,470  -->  00:17:35,850
to a black hole until they're needed
477

477

00:17:35,850  -->  00:17:38,490
for business operations is a great security practice
478

478

00:17:38,490  -->  00:17:40,290
and it only takes seconds to implement.
479

479

00:17:40,290  -->  00:17:41,250
The last thing I want to talk
480

480

00:17:41,250  -->  00:17:43,380
about is the concept of a sinkhole.
481

481

00:17:43,380  -->  00:17:46,080
Now a sinkhole is very similar to a black hole
482

482

00:17:46,080  -->  00:17:47,910
but it's a little bit different.
483

483

00:17:47,910  -->  00:17:49,980
Sometimes people use these terms interchangeably
484

484

00:17:49,980  -->  00:17:51,900
but they do have a little variation.
485

485

00:17:51,900  -->  00:17:53,130
When we talk about a sinkhole,
486

486

00:17:53,130  -->  00:17:55,920
this is a denial of service attack mitigation strategy
487

487

00:17:55,920  -->  00:17:57,360
much like a black hole,
488

488

00:17:57,360  -->  00:18:00,030
but instead it directs all that traffic that's
489

489

00:18:00,030  -->  00:18:01,470
trying to flood a target IP
490

490

00:18:01,470  -->  00:18:03,630
to a different network for analysis.
491

491

00:18:03,630  -->  00:18:05,520
So instead of just dropping that traffic
492

492

00:18:05,520  -->  00:18:07,500
and making it go away like a black hole does,
493

493

00:18:07,500  -->  00:18:08,970
we're going to send it off for analysis
494

494

00:18:08,970  -->  00:18:11,040
into some network that can handle it
495

495

00:18:11,040  -->  00:18:12,840
and get that amount of traffic.
496

496

00:18:12,840  -->  00:18:14,700
Now, sinkholing is better than blackholing
497

497

00:18:14,700  -->  00:18:16,530
if you want to be able to determine the cause
498

498

00:18:16,530  -->  00:18:18,150
of your DDoS attack.
499

499

00:18:18,150  -->  00:18:19,707
This way, you can gather the traffic
500

500

00:18:19,707  -->  00:18:21,840
and you can analyze it as needed.
501

501

00:18:21,840  -->  00:18:23,820
Now, there are a lot of different ways to do black holes
502

502

00:18:23,820  -->  00:18:24,653
and sinkholes,
503

503

00:18:24,653  -->  00:18:27,300
and it really depends on your use case, but for most of us,
504

504

00:18:27,300  -->  00:18:29,040
we just want to protect our networks.
505

505

00:18:29,040  -->  00:18:30,630
And so the easiest way to implement
506

506

00:18:30,630  -->  00:18:32,790
either of these solutions will be to use something
507

507

00:18:32,790  -->  00:18:34,740
like CloudFlare or Akamai.
508

508

00:18:34,740  -->  00:18:37,830
Both of these are large ISPs that specialize
509

509

00:18:37,830  -->  00:18:40,590
in DDoS mitigation services, and they do this
510

510

00:18:40,590  -->  00:18:42,450
by acting as a sinkhole network provider
511

511

00:18:42,450  -->  00:18:44,370
for you to scrub any of the traffic
512

512

00:18:44,370  -->  00:18:47,430
and then provide the legitimate traffic back to you.
513

513

00:18:47,430  -->  00:18:48,810
This helps mitigate the problem
514

514

00:18:48,810  -->  00:18:50,520
of legitimate traffic getting blocked
515

515

00:18:50,520  -->  00:18:52,980
during a DDoS attack by forwarding it on
516

516

00:18:52,980  -->  00:18:55,230
while blocking the malicious traffic for you.
