1
00:00:00,090 --> 00:00:00,960
In this lesson,

2
00:00:00,960 --> 00:00:02,880
you're going to learn what a firewall is,

3
00:00:02,880 --> 00:00:04,800
how it works and how you can configure it

4
00:00:04,800 --> 00:00:06,570
inside a Linux system.

5
00:00:06,570 --> 00:00:08,370
Now if you have a Linux machine,

6
00:00:08,370 --> 00:00:10,260
you already have a certain level of security

7
00:00:10,260 --> 00:00:11,640
enabled by default.

8
00:00:11,640 --> 00:00:14,220
But with the increase in the volume, variety

9
00:00:14,220 --> 00:00:16,650
and intensity of cyber attacks these days,

10
00:00:16,650 --> 00:00:17,760
you really need to understand

11
00:00:17,760 --> 00:00:19,650
how to configure a Linux firewall

12
00:00:19,650 --> 00:00:23,280
as a necessary step to protect yourself and your systems.

13
00:00:23,280 --> 00:00:24,630
In the world of the internet,

14
00:00:24,630 --> 00:00:27,120
there are lots of different servers and computers out there

15
00:00:27,120 --> 00:00:28,530
running without firewalls.

16
00:00:28,530 --> 00:00:31,020
If you're going to run any kind of a server or computer

17
00:00:31,020 --> 00:00:32,310
that's tied to the internet,

18
00:00:32,310 --> 00:00:33,840
you really need to have a firewall

19
00:00:33,840 --> 00:00:36,240
because otherwise the chances of getting hacked

20
00:00:36,240 --> 00:00:37,950
are extremely high.

21
00:00:37,950 --> 00:00:39,510
A properly configured firewall

22
00:00:39,510 --> 00:00:41,940
will block a lot of the malicious traffic,

23
00:00:41,940 --> 00:00:44,610
either based on the IP address of where it's coming from,

24
00:00:44,610 --> 00:00:46,470
the IP address of where it's going to,

25
00:00:46,470 --> 00:00:49,050
or the ports that it's trying to connect to.

26
00:00:49,050 --> 00:00:51,150
Now a firewall is really just a program

27
00:00:51,150 --> 00:00:53,880
that surrounds the interface between a private network

28
00:00:53,880 --> 00:00:56,550
and the rest of the big, bad internet.

29
00:00:56,550 --> 00:00:58,650
You can think of a firewall as a gateway.

30
00:00:58,650 --> 00:01:00,450
And it follows pre-configured rules

31
00:01:00,450 --> 00:01:02,700
that allows certain traffic to pass through it

32
00:01:02,700 --> 00:01:05,190
from the internet into the private network.

33
00:01:05,190 --> 00:01:07,200
And it's going to block a lot of the things

34
00:01:07,200 --> 00:01:09,540
that are unwanted or potentially harmful

35
00:01:09,540 --> 00:01:11,820
if they don't match your allow rules.

36
00:01:11,820 --> 00:01:14,670
Now there are three main generations of firewalls.

37
00:01:14,670 --> 00:01:16,380
The first generation was known as

38
00:01:16,380 --> 00:01:18,270
packet filtering firewalls.

39
00:01:18,270 --> 00:01:20,520
And these make their decisions based on rules

40
00:01:20,520 --> 00:01:23,910
that correspond to one or more network packet attributes.

41
00:01:23,910 --> 00:01:26,700
These rules appear in the form of an access-control list

42
00:01:26,700 --> 00:01:28,260
or ACL.

43
00:01:28,260 --> 00:01:30,000
Now packet filtering firewalls

44
00:01:30,000 --> 00:01:32,070
are also called stateless firewalls

45
00:01:32,070 --> 00:01:34,890
because they only inspect a packet in isolation

46
00:01:34,890 --> 00:01:36,930
and they can't determine what came before

47
00:01:36,930 --> 00:01:40,500
or after that packet to get more valuable context.

48
00:01:40,500 --> 00:01:41,700
To improve upon this,

49
00:01:41,700 --> 00:01:43,860
there was a second generation of firewall created

50
00:01:43,860 --> 00:01:45,930
known as stateful firewalls.

51
00:01:45,930 --> 00:01:48,600
Now stateful firewalls can identify past traffic

52
00:01:48,600 --> 00:01:50,070
that's related to a packet.

53
00:01:50,070 --> 00:01:51,600
And this means that stateful firewall

54
00:01:51,600 --> 00:01:53,550
can actually view the entire conversation

55
00:01:53,550 --> 00:01:55,200
of a given transmission.

56
00:01:55,200 --> 00:01:56,700
For example, it can detect

57
00:01:56,700 --> 00:01:59,010
that there was a three-way handshake that occurred

58
00:01:59,010 --> 00:02:00,840
or that you started the conversation

59
00:02:00,840 --> 00:02:03,660
and the other servers just responding to you.

60
00:02:03,660 --> 00:02:05,760
This is the idea of using a stateful firewall

61
00:02:05,760 --> 00:02:07,650
because they can make more informed decisions

62
00:02:07,650 --> 00:02:10,259
about what traffic they should deny or allow

63
00:02:10,259 --> 00:02:12,390
based on what happened before.

64
00:02:12,390 --> 00:02:14,490
Over time, firewalls got even better

65
00:02:14,490 --> 00:02:17,580
and we created what's known as a third generation firewall.

66
00:02:17,580 --> 00:02:19,170
These third generation firewalls

67
00:02:19,170 --> 00:02:21,840
are also called application layer firewalls

68
00:02:21,840 --> 00:02:24,060
or application aware firewalls

69
00:02:24,060 --> 00:02:25,590
because they can inspect the contents

70
00:02:25,590 --> 00:02:27,300
of application layer traffic

71
00:02:27,300 --> 00:02:30,237
such as protocols like HTTP and FTP.

72
00:02:30,237 --> 00:02:31,980
And then they can make decisions

73
00:02:31,980 --> 00:02:35,010
based on the contents that they're seeing in those packets.

74
00:02:35,010 --> 00:02:37,200
By using an application aware firewall,

75
00:02:37,200 --> 00:02:39,960
you can detect attempts to bypass traditional filtering

76
00:02:39,960 --> 00:02:41,310
and stateful inspection

77
00:02:41,310 --> 00:02:43,380
that leverages known software exploit.

78
00:02:43,380 --> 00:02:45,480
And so an application layer firewall

79
00:02:45,480 --> 00:02:48,480
really is the best of these three generations.

80
00:02:48,480 --> 00:02:50,520
Now a stateless firewall's ACL

81
00:02:50,520 --> 00:02:53,010
is still used by all three generations though.

82
00:02:53,010 --> 00:02:56,340
And a stateless firewall ACL can allow or deny packets

83
00:02:56,340 --> 00:02:59,640
based on various factors such as the source IP address,

84
00:02:59,640 --> 00:03:03,240
the destination IP address, the source TCP or UDP port

85
00:03:03,240 --> 00:03:04,800
that you're sending traffic from,

86
00:03:04,800 --> 00:03:06,870
the destination TCP or UDP port

87
00:03:06,870 --> 00:03:08,460
that you're trying to send traffic to

88
00:03:08,460 --> 00:03:10,530
and the TCP or UDP protocol

89
00:03:10,530 --> 00:03:13,110
that's actually being used for this conversation.

90
00:03:13,110 --> 00:03:14,850
Now once the firewall matches traffic

91
00:03:14,850 --> 00:03:16,980
to a given rule in the ACL,

92
00:03:16,980 --> 00:03:19,710
it can then perform one of three actions.

93
00:03:19,710 --> 00:03:23,430
It can accept it, it can reject it or it can drop it.

94
00:03:23,430 --> 00:03:25,740
Now accept means that the traffic is going to be allowed

95
00:03:25,740 --> 00:03:28,770
through the firewall and sent onto its destination.

96
00:03:28,770 --> 00:03:29,880
When you reject it,

97
00:03:29,880 --> 00:03:32,280
this means that the traffic is blocked at the firewall

98
00:03:32,280 --> 00:03:34,950
and the firewall is going to send a message back to the sender

99
00:03:34,950 --> 00:03:36,570
to say, I rejected it.

100
00:03:36,570 --> 00:03:38,760
I didn't let this traffic go through.

101
00:03:38,760 --> 00:03:40,770
Drop means that the traffic is simply blocked

102
00:03:40,770 --> 00:03:41,670
at the firewall,

103
00:03:41,670 --> 00:03:44,070
but the firewall is not going to notify the sender

104
00:03:44,070 --> 00:03:45,510
and instead it just drops it

105
00:03:45,510 --> 00:03:47,820
and ignores that that packet was ever there

106
00:03:47,820 --> 00:03:49,950
and it never made it into the network.

107
00:03:49,950 --> 00:03:51,810
Now to manage the different ACLs

108
00:03:51,810 --> 00:03:53,910
and packet filtering inside a Linux,

109
00:03:53,910 --> 00:03:56,010
you're going to do this using different tools.

110
00:03:56,010 --> 00:03:58,830
The first one we're going to talk about is iptables.

111
00:03:58,830 --> 00:04:01,050
Now iptables uses different tables

112
00:04:01,050 --> 00:04:03,180
to apply certain contexts or rules

113
00:04:03,180 --> 00:04:05,370
and these rules are known as chains.

114
00:04:05,370 --> 00:04:07,290
And we're going to do all of that inside of Linux

115
00:04:07,290 --> 00:04:10,050
to act as a firewall on our host.

116
00:04:10,050 --> 00:04:12,630
Now a packet is really compared to the first rule

117
00:04:12,630 --> 00:04:15,480
in the appropriate chain of the ACL.

118
00:04:15,480 --> 00:04:16,769
And if it doesn't match that rule,

119
00:04:16,769 --> 00:04:18,839
it's going to go down to the next rule in the chain.

120
00:04:18,839 --> 00:04:20,310
And it's going to continue on

121
00:04:20,310 --> 00:04:22,440
until it either passes through all the rules

122
00:04:22,440 --> 00:04:25,170
or it hits the end of that chain.

123
00:04:25,170 --> 00:04:27,300
Now when a packet matches one of those rules,

124
00:04:27,300 --> 00:04:30,540
it can either be accepted, rejected or dropped

125
00:04:30,540 --> 00:04:33,360
or it can be pushed over to a second set of rules

126
00:04:33,360 --> 00:04:36,090
in a new chain to be further evaluated.

127
00:04:36,090 --> 00:04:37,890
If you want to run iptables,

128
00:04:37,890 --> 00:04:41,940
you can run it by typing in iptables, the options, -t

129
00:04:41,940 --> 00:04:43,890
and the table, commands

130
00:04:43,890 --> 00:04:46,710
and then the chain or rule that you want to specify.

131
00:04:46,710 --> 00:04:49,170
Now iptables has five default tables

132
00:04:49,170 --> 00:04:52,380
that could be activated by default in your kernel.

133
00:04:52,380 --> 00:04:54,240
This includes the filter table,

134
00:04:54,240 --> 00:04:57,630
the nat table, the mangle table, the raw table

135
00:04:57,630 --> 00:04:59,220
and the security table.

136
00:04:59,220 --> 00:05:01,830
Now the first one we have is known as the filter table

137
00:05:01,830 --> 00:05:03,630
which is the default table.

138
00:05:03,630 --> 00:05:04,463
This is going to be used

139
00:05:04,463 --> 00:05:07,050
for typical packet filtering functionality.

140
00:05:07,050 --> 00:05:09,420
The second table is known as the nat table.

141
00:05:09,420 --> 00:05:10,500
And this is used to implement

142
00:05:10,500 --> 00:05:12,510
network address translation rules

143
00:05:12,510 --> 00:05:15,690
going from public to private and private to public.

144
00:05:15,690 --> 00:05:18,390
The mangle table is going to be used to alter packets

145
00:05:18,390 --> 00:05:22,350
TCP/IP headers and be able to change them as you go.

146
00:05:22,350 --> 00:05:24,990
The raw table is going to be used to configure exceptions

147
00:05:24,990 --> 00:05:27,540
for packets that are involved in connection tracking.

148
00:05:27,540 --> 00:05:30,150
And the security table is going to be used to mark packets

149
00:05:30,150 --> 00:05:33,120
with SELinux security context properly.

150
00:05:33,120 --> 00:05:36,450
Now by default, different rule sets within iptables

151
00:05:36,450 --> 00:05:38,400
will be lost on reboot.

152
00:05:38,400 --> 00:05:41,130
In CentOS and Red Hat Enterprise Linux,

153
00:05:41,130 --> 00:05:44,280
you can install the iptable-services package

154
00:05:44,280 --> 00:05:47,310
and issue the service iptables save command

155
00:05:47,310 --> 00:05:49,140
to ensure that your changes will be persistent

156
00:05:49,140 --> 00:05:50,520
between reboots.

157
00:05:50,520 --> 00:05:52,860
If you're using a Debian-based Linux distro,

158
00:05:52,860 --> 00:05:55,800
you can install the iptables-persistent package

159
00:05:55,800 --> 00:05:57,960
and this will allow you to do the same thing.

160
00:05:57,960 --> 00:05:59,130
After you install it,

161
00:05:59,130 --> 00:06:00,120
you'll be asked to confirm

162
00:06:00,120 --> 00:06:02,580
that you want your current rules to be persistent.

163
00:06:02,580 --> 00:06:05,310
If you do, say yes, and then whenever you reboot,

164
00:06:05,310 --> 00:06:07,320
those rules will stay in place.

165
00:06:07,320 --> 00:06:10,140
Once you do this, your ipables-persistent

166
00:06:10,140 --> 00:06:12,210
or iptables-service package

167
00:06:12,210 --> 00:06:13,860
will load up automatically at boot

168
00:06:13,860 --> 00:06:16,500
and load up all your rules for your firewall.

169
00:06:16,500 --> 00:06:19,440
Now you can also enable logging for iptable rules

170
00:06:19,440 --> 00:06:21,720
by yelling into the log action.

171
00:06:21,720 --> 00:06:23,400
Now another thing you might want to enable

172
00:06:23,400 --> 00:06:26,100
inside of iptables is logging.

173
00:06:26,100 --> 00:06:27,390
Logging is a great thing to see

174
00:06:27,390 --> 00:06:28,500
what things are being blocked

175
00:06:28,500 --> 00:06:30,300
and what things are being allowed.

176
00:06:30,300 --> 00:06:32,730
To do this, you're going to include the log action

177
00:06:32,730 --> 00:06:34,380
when issuing the command.

178
00:06:34,380 --> 00:06:36,988
So to create a new chain, you're going to type in

179
00:06:36,988 --> 00:06:41,988
iptables -N, and then the name you want such as log chain.

180
00:06:42,240 --> 00:06:44,400
To ensure all your packets that are coming in,

181
00:06:44,400 --> 00:06:46,470
that were not already processed by a prior rule

182
00:06:46,470 --> 00:06:48,360
will jump to that log chain,

183
00:06:48,360 --> 00:06:53,360
you can do this by typing in iptables -I INPUT -j LOGCHN.

184
00:06:55,440 --> 00:06:56,760
Now if you want to enable logging

185
00:06:56,760 --> 00:06:59,730
of everything that reaches this particular rule or chain,

186
00:06:59,730 --> 00:07:04,730
you can type in iptables -l LOGCHAIN -j LOG

187
00:07:05,310 --> 00:07:07,770
and this will log all the packets that reach the chain

188
00:07:07,770 --> 00:07:09,030
log chain.

189
00:07:09,030 --> 00:07:11,130
Now if you actually want to drop those packets,

190
00:07:11,130 --> 00:07:12,810
you can go ahead and set that up by doing

191
00:07:12,810 --> 00:07:17,760
iptables -l LOGCHN -j DROP

192
00:07:17,760 --> 00:07:20,760
and this will perform the actual dropping of those packets.

193
00:07:20,760 --> 00:07:23,040
Now generally all of your iptable events

194
00:07:23,040 --> 00:07:25,110
are going to be written into your logs

195
00:07:25,110 --> 00:07:28,290
in the /var/log/messages

196
00:07:28,290 --> 00:07:33,210
or /var/log/kern.log file.

197
00:07:33,210 --> 00:07:37,200
Now the next firewall we're going to talk about is known as UFW

198
00:07:37,200 --> 00:07:39,510
or the Uncomplicated Firewall.

199
00:07:39,510 --> 00:07:41,310
Now the Uncomplicated Firewall

200
00:07:41,310 --> 00:07:42,750
is a firewall management tool

201
00:07:42,750 --> 00:07:45,810
that makes it easier to configure the iptables service.

202
00:07:45,810 --> 00:07:47,880
And it's primarily used for home users

203
00:07:47,880 --> 00:07:50,010
who don't have experience with all the intricacies

204
00:07:50,010 --> 00:07:52,170
of a firewall configuration.

205
00:07:52,170 --> 00:07:54,960
You can use the UFW command from the command line.

206
00:07:54,960 --> 00:07:58,950
For example, if I want to set up an allow rule for HTTP,

207
00:07:58,950 --> 00:08:03,950
I can go ahead and do that by typing in ufw allow http/tcp.

208
00:08:05,430 --> 00:08:06,840
Notice how simple it is.

209
00:08:06,840 --> 00:08:08,430
By entering in this single command,

210
00:08:08,430 --> 00:08:11,070
I now am allowing all HTTP traffic

211
00:08:11,070 --> 00:08:13,620
using TCP as its protocol.

212
00:08:13,620 --> 00:08:15,720
If you want to enable logging with UFW,

213
00:08:15,720 --> 00:08:18,360
it's a lot easier than it was in iptables.

214
00:08:18,360 --> 00:08:19,350
To enable logging,

215
00:08:19,350 --> 00:08:22,920
simply type ufw logging on and hit Enter

216
00:08:22,920 --> 00:08:24,900
and this will turn on logging for you.

217
00:08:24,900 --> 00:08:26,490
If you want to enable the firewall,

218
00:08:26,490 --> 00:08:27,780
it's also pretty easy.

219
00:08:27,780 --> 00:08:30,210
Just type in ufw enable

220
00:08:30,210 --> 00:08:33,780
and this will enable the firewall inside of ufw.

221
00:08:33,780 --> 00:08:36,120
Anytime you want to run a command in UFW,

222
00:08:36,120 --> 00:08:39,390
simply type in ufw, the options and the action.

223
00:08:39,390 --> 00:08:41,563
And they usually use this very common English vernacular

224
00:08:41,563 --> 00:08:43,679
to be able to tell it what to do.

225
00:08:43,679 --> 00:08:45,120
If you want to learn all the commands,

226
00:08:45,120 --> 00:08:49,050
you can always go into man UFW and see all about it.

227
00:08:49,050 --> 00:08:50,850
Now if you want to use UFW

228
00:08:50,850 --> 00:08:54,030
to have a more complicated firewall, you can do that too,

229
00:08:54,030 --> 00:08:56,790
but you're going to have to edit a text file to do that.

230
00:08:56,790 --> 00:08:59,670
To do this, first configure your high level settings

231
00:08:59,670 --> 00:09:02,550
like your policy defaults and kernel module usage

232
00:09:02,550 --> 00:09:07,080
inside the /etc/default/ufw file.

233
00:09:07,080 --> 00:09:08,910
If you want more granular control,

234
00:09:08,910 --> 00:09:13,320
you can do that as well by going into the /etc/ufw directory

235
00:09:13,320 --> 00:09:15,090
and editing those files.

236
00:09:15,090 --> 00:09:17,400
Each of these files will allow you to control the rules

237
00:09:17,400 --> 00:09:18,720
when they're going to be applied,

238
00:09:18,720 --> 00:09:21,660
what customizations you want and other things like that

239
00:09:21,660 --> 00:09:24,300
all from within those text files.

240
00:09:24,300 --> 00:09:26,340
Now the next firewall we're going to talk about

241
00:09:26,340 --> 00:09:29,760
is known as the firewall daemon or firewalld.

242
00:09:29,760 --> 00:09:31,470
Now firewalld is a command

243
00:09:31,470 --> 00:09:33,690
that's used to dynamically manage a firewall

244
00:09:33,690 --> 00:09:35,730
without requiring the firewall to restart

245
00:09:35,730 --> 00:09:37,500
upon a modification.

246
00:09:37,500 --> 00:09:39,870
This is an alternative to iptables

247
00:09:39,870 --> 00:09:44,010
and it uses zones and services rather than chains and rules.

248
00:09:44,010 --> 00:09:46,140
Now firewall zones are the rule sets

249
00:09:46,140 --> 00:09:48,630
that can be applied to specific network resources

250
00:09:48,630 --> 00:09:50,700
like a network interface card.

251
00:09:50,700 --> 00:09:52,620
Now there are various default zones

252
00:09:52,620 --> 00:09:55,170
and each of these have different levels of trust.

253
00:09:55,170 --> 00:09:57,900
For example, the zone with the lowest level of trust

254
00:09:57,900 --> 00:09:59,040
is called drop

255
00:09:59,040 --> 00:10:02,250
and it immediately drops all incoming connections.

256
00:10:02,250 --> 00:10:04,320
The firewall-cmd command

257
00:10:04,320 --> 00:10:06,810
is going to enable you to configure the firewalld

258
00:10:06,810 --> 00:10:10,290
or firewall daemon by querying, adding, modifying

259
00:10:10,290 --> 00:10:13,350
and deleting zones and services as you want.

260
00:10:13,350 --> 00:10:16,620
Now because firewalld is the default firewall service

261
00:10:16,620 --> 00:10:18,330
for many Linux distributions

262
00:10:18,330 --> 00:10:21,390
including Red Hat Enterprise Linux and CentOS,

263
00:10:21,390 --> 00:10:23,910
you're going to be using the firewall-cmd command

264
00:10:23,910 --> 00:10:25,260
pretty regularly.

265
00:10:25,260 --> 00:10:28,290
Now the command also includes options to identify which zone

266
00:10:28,290 --> 00:10:30,240
and which interface you want to configure

267
00:10:30,240 --> 00:10:32,580
as well as the ability to permit services by name

268
00:10:32,580 --> 00:10:34,050
or by port number.

269
00:10:34,050 --> 00:10:38,610
To run this command, type in firewall-cmd and the options.

270
00:10:38,610 --> 00:10:40,890
Now there are several different things that you should know

271
00:10:40,890 --> 00:10:44,010
when using the firewall-cmd command.

272
00:10:44,010 --> 00:10:44,970
For example,

273
00:10:44,970 --> 00:10:48,000
if you want to list out all the available firewall zones,

274
00:10:48,000 --> 00:10:53,000
you can do that by typing firewall-cmd --get-zones

275
00:10:53,340 --> 00:10:54,600
and hit Enter.

276
00:10:54,600 --> 00:10:56,400
Now if you want to list out additional details

277
00:10:56,400 --> 00:10:59,250
about the DMZ zone, including its interfaces,

278
00:10:59,250 --> 00:11:02,400
ports, services, protocols and things like that,

279
00:11:02,400 --> 00:11:03,960
you can do that by typing in

280
00:11:03,960 --> 00:11:08,780
firewall-cmd --zone=dmz --list-all.

281
00:11:11,400 --> 00:11:13,890
If you want to be able to add the specified interface

282
00:11:13,890 --> 00:11:15,360
to the DMZ zone,

283
00:11:15,360 --> 00:11:16,890
you can do that by using

284
00:11:16,890 --> 00:11:21,890
firewall-cmd --zone-dmz --change-interface=

285
00:11:24,150 --> 00:11:26,100
and the device ID.

286
00:11:26,100 --> 00:11:29,490
Let's say for example I want to add the HTTP service

287
00:11:29,490 --> 00:11:31,110
to that DMZ zone.

288
00:11:31,110 --> 00:11:32,790
Well, I can do that by typing in

289
00:11:32,790 --> 00:11:37,790
firewall-cmd --zone=dmz --add-service=http.

290
00:11:40,950 --> 00:11:42,540
I think you're getting the idea here.

291
00:11:42,540 --> 00:11:47,540
You use firewall-cmd --zone= the zone you want to modify

292
00:11:47,670 --> 00:11:49,260
and then that thing you want to do.

293
00:11:49,260 --> 00:11:51,210
For example if I wanted to add a port,

294
00:11:51,210 --> 00:11:55,920
I can do --add-port=21/tcp

295
00:11:55,920 --> 00:11:58,380
to add port 21 over TCP

296
00:11:58,380 --> 00:12:01,950
which is used for FTP into that DMZ zone.

297
00:12:01,950 --> 00:12:03,150
If you want to remove a port,

298
00:12:03,150 --> 00:12:08,150
you can do that by typing --remove-port=21/tcp

299
00:12:08,160 --> 00:12:11,100
and that would remove that new port 21 that I just had

300
00:12:11,100 --> 00:12:13,617
for FTP from the DMZ zone.

301
00:12:13,617 --> 00:12:16,500
Now if I want to reload all the zone's configuration,

302
00:12:16,500 --> 00:12:20,730
I can do that by typing in firewall-cmd --reload

303
00:12:20,730 --> 00:12:22,530
and hit Enter and that will reload

304
00:12:22,530 --> 00:12:24,690
all the zone's configuration.

305
00:12:24,690 --> 00:12:26,244
Now like iptables,

306
00:12:26,244 --> 00:12:30,000
firewalld does not persist its changes by default.

307
00:12:30,000 --> 00:12:31,920
This is called the runtime mode.

308
00:12:31,920 --> 00:12:34,110
Now if you wanted to survive a reboot,

309
00:12:34,110 --> 00:12:35,430
you need to commit a change

310
00:12:35,430 --> 00:12:39,390
by using the --permanent option and that way it will persist

311
00:12:39,390 --> 00:12:42,630
after you restart the daemon or reboot your system.

312
00:12:42,630 --> 00:12:44,160
Now the next one we're going to talk about

313
00:12:44,160 --> 00:12:45,810
is known as netfilter.

314
00:12:45,810 --> 00:12:48,180
Now netfilter is a Linux kernel framework

315
00:12:48,180 --> 00:12:51,060
that handles packets that traverse a network interface.

316
00:12:51,060 --> 00:12:52,230
Some of the major services

317
00:12:52,230 --> 00:12:54,810
it's going to provide are packet filtering, nat

318
00:12:54,810 --> 00:12:56,100
and connection tracking.

319
00:12:56,100 --> 00:12:58,170
So it works as a firewall.

320
00:12:58,170 --> 00:13:00,090
netfilter is going to support the configuration

321
00:13:00,090 --> 00:13:02,220
of all these services by providing hooks

322
00:13:02,220 --> 00:13:04,230
into the kernel's network stack.

323
00:13:04,230 --> 00:13:06,870
And every packet that traverses the network interface

324
00:13:06,870 --> 00:13:08,340
is going to be caught by those hooks

325
00:13:08,340 --> 00:13:10,740
and so it can be applied through netfilter.

326
00:13:10,740 --> 00:13:15,510
Both UFW and firewalld call iptables in some capacity.

327
00:13:15,510 --> 00:13:18,240
And likewise, they also call on netfilter.

328
00:13:18,240 --> 00:13:20,880
You'll also see this called nttables

329
00:13:20,880 --> 00:13:23,820
because nftables is netfilter.

330
00:13:23,820 --> 00:13:26,520
Now nftables or netfilter tables

331
00:13:26,520 --> 00:13:29,431
was designed as a replacement for the older iptables

332
00:13:29,431 --> 00:13:31,470
and is installed by default on most

333
00:13:31,470 --> 00:13:33,810
Debian-baseed Linux distributions.

334
00:13:33,810 --> 00:13:35,190
Now one of the functionalities

335
00:13:35,190 --> 00:13:38,010
that these firewalls do for you is IP forwarding.

336
00:13:38,010 --> 00:13:39,030
And IP forwarding

337
00:13:39,030 --> 00:13:41,010
is the way the Linux kernel's implementation

338
00:13:41,010 --> 00:13:43,290
of network routing actually happens.

339
00:13:43,290 --> 00:13:46,080
This enables incoming traffic on the network interface

340
00:13:46,080 --> 00:13:48,390
to be forwarded over to another network interface

341
00:13:48,390 --> 00:13:49,710
if you need to.

342
00:13:49,710 --> 00:13:51,510
IP forwarding is really useful

343
00:13:51,510 --> 00:13:53,610
in systems that have multiple interfaces.

344
00:13:53,610 --> 00:13:55,110
So if you set up a Linux server

345
00:13:55,110 --> 00:13:57,420
to act as a firewall for your entire network

346
00:13:57,420 --> 00:13:59,280
and you have two network interface cards,

347
00:13:59,280 --> 00:14:01,410
one coming in and one going out,

348
00:14:01,410 --> 00:14:04,440
you can use IP forwarding to act as a router or gateway

349
00:14:04,440 --> 00:14:07,260
or firewall in between those two networks.

350
00:14:07,260 --> 00:14:10,200
Now IP sets are another thing we need to talk about.

351
00:14:10,200 --> 00:14:12,990
IP sets are stores collections of IP addresses,

352
00:14:12,990 --> 00:14:15,840
network ranges, MAC addresses, port numbers

353
00:14:15,840 --> 00:14:17,730
and network interface names.

354
00:14:17,730 --> 00:14:20,820
The iptables tool can leverage these different IP sets

355
00:14:20,820 --> 00:14:22,860
for more efficient rule matching.

356
00:14:22,860 --> 00:14:25,440
So for example, let's say you wanted to drop traffic

357
00:14:25,440 --> 00:14:28,170
that originated from one of several IP address ranges

358
00:14:28,170 --> 00:14:29,580
that you know to be malicious.

359
00:14:29,580 --> 00:14:32,430
We're basically calling these the block list.

360
00:14:32,430 --> 00:14:34,530
Instead of configuring rules for each range

361
00:14:34,530 --> 00:14:36,390
and the iptables directly,

362
00:14:36,390 --> 00:14:38,430
we can instead create an IP set

363
00:14:38,430 --> 00:14:41,430
and then reference that in the IP tables rule.

364
00:14:41,430 --> 00:14:43,770
The IP set enables you to create and modify

365
00:14:43,770 --> 00:14:47,280
different IP sets by running the IP set command.

366
00:14:47,280 --> 00:14:50,130
To do this, type in ipset, the options

367
00:14:50,130 --> 00:14:52,110
and then the command you want to use.

368
00:14:52,110 --> 00:14:54,030
The IP set tool can really be used

369
00:14:54,030 --> 00:14:57,120
when you're troubleshooting the iptable's firewall as well.

370
00:14:57,120 --> 00:15:00,450
For example, you can use the test subcommand in IP set

371
00:15:00,450 --> 00:15:02,820
to test whether or not an entry exists.

372
00:15:02,820 --> 00:15:04,350
If the firewall still isn't handling

373
00:15:04,350 --> 00:15:06,600
the IP address ranges as you expected,

374
00:15:06,600 --> 00:15:09,330
you can then list out those rules using the relevance set

375
00:15:09,330 --> 00:15:11,220
and see everything that's in there.

376
00:15:11,220 --> 00:15:13,710
Now another great thing about using IP sets

377
00:15:13,710 --> 00:15:15,180
is that you can then take those files

378
00:15:15,180 --> 00:15:16,770
and put 'em on other systems.

379
00:15:16,770 --> 00:15:19,620
So for example, if you have 20 Linux servers,

380
00:15:19,620 --> 00:15:21,870
instead of having to configure each one individually,

381
00:15:21,870 --> 00:15:24,420
you can reference a common IP set file

382
00:15:24,420 --> 00:15:26,010
across all 20 servers

383
00:15:26,010 --> 00:15:28,470
and they'll all have the same block list.

384
00:15:28,470 --> 00:15:31,260
As you know, many network services and applications

385
00:15:31,260 --> 00:15:34,740
require the use of ports to establish a connection endpoint.

386
00:15:34,740 --> 00:15:37,710
Now most common protocols have a dedicated port number

387
00:15:37,710 --> 00:15:39,360
as assigned by IANA,

388
00:15:39,360 --> 00:15:41,700
the Internet Assigned Numbers Authority.

389
00:15:41,700 --> 00:15:45,930
For example, port 21 is FTP, port 80 is HTTP

390
00:15:45,930 --> 00:15:47,310
and things like that.

391
00:15:47,310 --> 00:15:49,770
However, you sometimes need to run a custom

392
00:15:49,770 --> 00:15:52,770
or uncommon application that requires network access

393
00:15:52,770 --> 00:15:54,630
and you're going to pick your own port for that

394
00:15:54,630 --> 00:15:55,800
because that application

395
00:15:55,800 --> 00:15:58,110
may not have a standardized port number.

396
00:15:58,110 --> 00:16:00,870
In those cases, you're going to need to choose the port number

397
00:16:00,870 --> 00:16:03,000
and then associate it with your application.

398
00:16:03,000 --> 00:16:03,930
And you're going to do that

399
00:16:03,930 --> 00:16:06,270
by opening the port in the firewall.

400
00:16:06,270 --> 00:16:09,210
Now trusted ports also known as privileged ports

401
00:16:09,210 --> 00:16:13,920
are ports inside the well known range of zero to 1023.

402
00:16:13,920 --> 00:16:16,260
In Linux, if a process is starting to listen

403
00:16:16,260 --> 00:16:18,810
on a trusted port or to establish a remote connection

404
00:16:18,810 --> 00:16:22,500
from a trusted port, it must have super user privileges.

405
00:16:22,500 --> 00:16:24,300
This helps that the other side of the connection

406
00:16:24,300 --> 00:16:26,490
confirm that the services they're connecting to

407
00:16:26,490 --> 00:16:28,320
are actually trusted.

408
00:16:28,320 --> 00:16:31,530
Now over time as you configure and implement your firewalls,

409
00:16:31,530 --> 00:16:32,850
you may run into some issues

410
00:16:32,850 --> 00:16:34,560
where the firewall is blocking traffic

411
00:16:34,560 --> 00:16:36,000
when you think it shouldn't.

412
00:16:36,000 --> 00:16:38,850
If this happens, you should check your firewall's rules

413
00:16:38,850 --> 00:16:40,260
to ensure it's not blocking a port

414
00:16:40,260 --> 00:16:42,180
that your system actually needs to forward

415
00:16:42,180 --> 00:16:43,860
for outgoing traffic.

416
00:16:43,860 --> 00:16:45,660
Sometimes the cause of the block

417
00:16:45,660 --> 00:16:47,280
is that you have the protocol blocked

418
00:16:47,280 --> 00:16:48,840
and not the port blocked.

419
00:16:48,840 --> 00:16:50,730
And if you've configured it inside of your set

420
00:16:50,730 --> 00:16:53,280
to block a certain protocol like FTP,

421
00:16:53,280 --> 00:16:55,080
that even if you open up port 21,

422
00:16:55,080 --> 00:16:56,790
it's not going to allow that

423
00:16:56,790 --> 00:16:59,100
because you're blocking it at the application layer.

424
00:16:59,100 --> 00:17:01,050
So keep that in mind as well.

425
00:17:01,050 --> 00:17:04,319
Also, sometimes your ACLs are just too restrictive.

426
00:17:04,319 --> 00:17:06,119
And so you might need to configure an ACL

427
00:17:06,119 --> 00:17:07,650
to open up a little bit more

428
00:17:07,650 --> 00:17:10,680
to allow you to get a known IP address or port range

429
00:17:10,680 --> 00:17:13,230
to be open and available for a connection.

430
00:17:13,230 --> 00:17:14,790
Now in addition to firewalls,

431
00:17:14,790 --> 00:17:17,190
we also have something known as an IPS,

432
00:17:17,190 --> 00:17:19,560
which is an Intrusion Prevention System.

433
00:17:19,560 --> 00:17:21,630
Now an IPS is a security appliance

434
00:17:21,630 --> 00:17:24,240
that monitors and evaluates systems for signs of attacks

435
00:17:24,240 --> 00:17:25,109
and progress.

436
00:17:25,109 --> 00:17:27,990
And it can actively block traffic that deems malicious.

437
00:17:27,990 --> 00:17:30,090
Now firewall is like a security guard

438
00:17:30,090 --> 00:17:31,470
who let's guests into the building

439
00:17:31,470 --> 00:17:34,170
based on whether or not they matched predefined rules.

440
00:17:34,170 --> 00:17:37,170
But an IPS is more akin to somebody who actually looks

441
00:17:37,170 --> 00:17:39,180
deeply into everybody who's going in

442
00:17:39,180 --> 00:17:41,340
and doing full background checks on them.

443
00:17:41,340 --> 00:17:44,370
Even if the outside guard, this firewall lets somebody in,

444
00:17:44,370 --> 00:17:46,380
the inside guard, that IPS,

445
00:17:46,380 --> 00:17:48,960
can actually watch that guest and see what they're doing

446
00:17:48,960 --> 00:17:51,780
and then if it's suspicious, they can kick them out.

447
00:17:51,780 --> 00:17:54,840
In other words, your IPS should be a second layer of defense

448
00:17:54,840 --> 00:17:58,020
that monitors traffic once it makes it past the firewall

449
00:17:58,020 --> 00:18:00,480
and starts looking for anomalous behavior.

450
00:18:00,480 --> 00:18:03,150
Now there are many different IPS solutions available

451
00:18:03,150 --> 00:18:05,250
but two common third party solutions

452
00:18:05,250 --> 00:18:07,800
are DenyHosts and Fail2ban.

453
00:18:07,800 --> 00:18:10,140
Both of which are going to be used to examine log files

454
00:18:10,140 --> 00:18:11,310
for anomalies.

455
00:18:11,310 --> 00:18:14,730
Now DenyHost is primarily going to protect your SSH servers

456
00:18:14,730 --> 00:18:17,280
from brute force password cracking attacks.

457
00:18:17,280 --> 00:18:18,630
In these kind of attacks,

458
00:18:18,630 --> 00:18:20,430
an attacker is attempting to repeatedly

459
00:18:20,430 --> 00:18:22,290
log into an SSH server

460
00:18:22,290 --> 00:18:24,720
using credentials that they change each time.

461
00:18:24,720 --> 00:18:29,460
For example, I start out with AAA and then I go to AAB, AAC

462
00:18:29,460 --> 00:18:32,370
and I keep changing it until I find the right password.

463
00:18:32,370 --> 00:18:35,160
So DenyHost is going to monitor your authentication log

464
00:18:35,160 --> 00:18:37,110
to look for these failed log in entries.

465
00:18:37,110 --> 00:18:38,850
And it's going to take the source IP address

466
00:18:38,850 --> 00:18:41,730
and the number of failed attempts into consideration.

467
00:18:41,730 --> 00:18:44,160
Now Fail2ban is another command we can use

468
00:18:44,160 --> 00:18:45,870
to prevent brute force attacks.

469
00:18:45,870 --> 00:18:49,680
But unlike DenyHost, it doesn't focus on just one service.

470
00:18:49,680 --> 00:18:51,990
Instead, it's going to monitor your log files

471
00:18:51,990 --> 00:18:53,910
that pertain to any system service

472
00:18:53,910 --> 00:18:55,980
that has an authentication component.

473
00:18:55,980 --> 00:18:58,086
It's going to leverage things like iptables

474
00:18:58,086 --> 00:19:00,870
and netfilter as well to perform the blocking actions

475
00:19:00,870 --> 00:19:03,450
and it can even be able to update your firewall rules

476
00:19:03,450 --> 00:19:05,460
for you based on what it sees.

477
00:19:05,460 --> 00:19:08,190
For example, if I see 10 failed login attempts,

478
00:19:08,190 --> 00:19:11,160
I'm going to block that IP address from connecting to me.

479
00:19:11,160 --> 00:19:13,680
The primary configuration file for DenyHost

480
00:19:13,680 --> 00:19:18,000
is located in the /etc/denyhosts.conf file.

481
00:19:18,000 --> 00:19:20,460
There are various settings that you can adjust to this file.

482
00:19:20,460 --> 00:19:23,640
For example, you can use admin_email setting

483
00:19:23,640 --> 00:19:26,430
to define what email address to send your alerts to.

484
00:19:26,430 --> 00:19:28,860
You can use the block_service setting

485
00:19:28,860 --> 00:19:31,590
to define what services will be blocked from access

486
00:19:31,590 --> 00:19:33,300
by unauthorized users.

487
00:19:33,300 --> 00:19:36,870
You can also use the deny_threshold_valid setting

488
00:19:36,870 --> 00:19:39,330
to define how many times a user can attempt to log

489
00:19:39,330 --> 00:19:42,360
into an existing account before they're going to be blocked.

490
00:19:42,360 --> 00:19:45,510
For example, maybe they missed to type the password 10 times

491
00:19:45,510 --> 00:19:47,520
and that's where we're going to block them.

492
00:19:47,520 --> 00:19:50,010
On the other hand, if you're using Fail2ban,

493
00:19:50,010 --> 00:19:52,080
you're going to find the primary configuration file

494
00:19:52,080 --> 00:19:56,910
in /etc/fail2ban/jail.conf.

495
00:19:56,910 --> 00:19:58,860
Now if you're going to configure Fail2ban,

496
00:19:58,860 --> 00:20:01,380
it's a good idea to copy this file over

497
00:20:01,380 --> 00:20:06,380
to /etc/fail2ban/jail.local and make your changes there.

498
00:20:06,900 --> 00:20:10,080
You can also use the bantime setting inside Fail2ban

499
00:20:10,080 --> 00:20:11,940
to define how long a host is going to be blocked

500
00:20:11,940 --> 00:20:13,440
from accessing a resource.

501
00:20:13,440 --> 00:20:16,140
For example, maybe they logged in wrong three times

502
00:20:16,140 --> 00:20:17,850
and you're going to block 'em for 20 minutes.

503
00:20:17,850 --> 00:20:19,890
You can set that using bantime.

504
00:20:19,890 --> 00:20:22,440
You can also set up the maximum retry setting

505
00:20:22,440 --> 00:20:23,727
by using maxretry.

506
00:20:23,727 --> 00:20:25,470
And this will define the number of times

507
00:20:25,470 --> 00:20:28,260
a host can fail to authenticate before they're blocked.

508
00:20:28,260 --> 00:20:29,940
And if you use ignoreip,

509
00:20:29,940 --> 00:20:32,490
this will define a whitelist of acceptable hosts

510
00:20:32,490 --> 00:20:35,040
that can try to log in repeatedly if they need to

511
00:20:35,040 --> 00:20:37,380
without being blocked because you trust them.

512
00:20:37,380 --> 00:20:39,690
For example, this IP might be something like

513
00:20:39,690 --> 00:20:41,940
your system administrator who you trust and know

514
00:20:41,940 --> 00:20:43,990
because they're internal to your network.

