1
1

00:00:00,290  -->  00:00:02,240
<v ->In this demonstration, we're going to explore</v>
2

2

00:00:02,240  -->  00:00:05,550
a basic small office/home office network firewall.
3

3

00:00:05,550  -->  00:00:07,470
In this example, I'm going to use a typical
4

4

00:00:07,470  -->  00:00:10,360
router/switch access point combination device
5

5

00:00:10,360  -->  00:00:12,470
manufactured by Netgear and marketed
6

6

00:00:12,470  -->  00:00:15,140
as a wireless network N300 model.
7

7

00:00:15,140  -->  00:00:16,580
Now, this is probably very similar
8

8

00:00:16,580  -->  00:00:18,690
to what most of you are using in your small office
9

9

00:00:18,690  -->  00:00:20,370
or home office environments.
10

10

00:00:20,370  -->  00:00:22,480
Your interface and settings on your firewall
11

11

00:00:22,480  -->  00:00:24,110
are going to look a little different than mine,
12

12

00:00:24,110  -->  00:00:26,270
but it's still going to give you the same general idea
13

13

00:00:26,270  -->  00:00:27,620
of what kind of options there are
14

14

00:00:27,620  -->  00:00:29,680
and how you can configure one of these firewalls
15

15

00:00:29,680  -->  00:00:30,930
at your network boundary.
16

16

00:00:31,780  -->  00:00:35,030
On the screen, you can see the basic web-based access
17

17

00:00:35,030  -->  00:00:37,770
for this wireless router/wireless access point
18

18

00:00:37,770  -->  00:00:39,550
combination device.
19

19

00:00:39,550  -->  00:00:41,360
On mine, I'm going to go to Security,
20

20

00:00:41,360  -->  00:00:43,230
which is where the firewall is located
21

21

00:00:43,230  -->  00:00:47,280
and it's under Blocked Services on this particular router.
22

22

00:00:47,280  -->  00:00:50,350
Usually, most of these small office/home office routers
23

23

00:00:50,350  -->  00:00:52,600
are going to have a very weak type firewall
24

24

00:00:52,600  -->  00:00:54,550
and they hide it by calling it something else
25

25

00:00:54,550  -->  00:00:56,290
instead of calling it a firewall,
26

26

00:00:56,290  -->  00:00:58,770
so, it'll be called blocked sites, blocked services,
27

27

00:00:58,770  -->  00:01:00,960
blocked ports, something of that nature.
28

28

00:01:00,960  -->  00:01:02,620
In this case, it's blocked services
29

29

00:01:02,620  -->  00:01:04,470
and I can do it based on a schedule,
30

30

00:01:04,470  -->  00:01:07,990
so, I only want it to be certain times of the day or always.
31

31

00:01:07,990  -->  00:01:10,000
Let's say I want to block something like Telnet.
32

32

00:01:10,000  -->  00:01:13,360
I'm going to always block it, I'm going to add a block,
33

33

00:01:13,360  -->  00:01:16,300
and the block I want to use is going to be a Service,
34

34

00:01:16,300  -->  00:01:17,503
and go down to Telnet.
35

35

00:01:18,450  -->  00:01:20,920
It automatically knows that Telnet is port 23,
36

36

00:01:20,920  -->  00:01:22,950
so, it's going to block port 23 for me.
37

37

00:01:22,950  -->  00:01:25,710
It's called Telnet because this is a predefined one
38

38

00:01:25,710  -->  00:01:28,730
and then, I can block it for all IP addresses in this network
39

39

00:01:28,730  -->  00:01:32,458
or only certain IP addresses or a certain range.
40

40

00:01:32,458  -->  00:01:34,320
Maybe I want to block it for everything for Telnet.
41

41

00:01:34,320  -->  00:01:37,160
That's fine, we can go ahead and add that to our list.
42

42

00:01:37,160  -->  00:01:38,190
If we want to add something else,
43

43

00:01:38,190  -->  00:01:39,650
let's say I have another rule.
44

44

00:01:39,650  -->  00:01:42,420
In this case, I want to block port 666
45

45

00:01:42,420  -->  00:01:43,500
because maybe there's a game
46

46

00:01:43,500  -->  00:01:45,290
I don't want my kids playing on that,
47

47

00:01:45,290  -->  00:01:47,490
so, I'll block it as port 666.
48

48

00:01:47,490  -->  00:01:49,830
I'm going to make it TCP, UDP, or both,
49

49

00:01:49,830  -->  00:01:51,370
I'm going to say both in this case,
50

50

00:01:51,370  -->  00:01:53,640
and I'm just going to call it Game.
51

51

00:01:53,640  -->  00:01:55,880
And then, I can block it for an IP range.
52

52

00:01:55,880  -->  00:01:58,740
Maybe I don't want it be accessed by my kids
53

53

00:01:58,740  -->  00:02:00,060
which all have their devices
54

54

00:02:00,060  -->  00:02:04,640
in the 10.0.0.2 and the 10.0.0.10 range.
55

55

00:02:04,640  -->  00:02:06,760
If I do that, I can go ahead and hit Add.
56

56

00:02:06,760  -->  00:02:09,340
And, again, that adds another rule to the firewall
57

57

00:02:09,340  -->  00:02:14,340
where we are blocking port 666 over that range of IPs.
58

58

00:02:14,610  -->  00:02:16,160
You can see how this works as you
59

59

00:02:16,160  -->  00:02:18,290
add or delete different rules.
60

60

00:02:18,290  -->  00:02:19,870
Then, I can go through and I can do another one.
61

61

00:02:19,870  -->  00:02:23,520
Let's say I want to block the
62

62

00:02:23,520  -->  00:02:24,960
FTP server,
63

63

00:02:24,960  -->  00:02:27,970
so, I will just go through here and say user defined
64

64

00:02:27,970  -->  00:02:30,020
port 20 through port 21
65

65

00:02:30,020  -->  00:02:32,440
because that is the connection port
66

66

00:02:32,440  -->  00:02:34,630
and the data ports for FTP.
67

67

00:02:34,630  -->  00:02:36,770
And then, we'll give it a name of FTP
68

68

00:02:37,940  -->  00:02:40,650
and we can do it for all IP addresses in this range,
69

69

00:02:40,650  -->  00:02:43,170
so nobody can access FTP servers.
70

70

00:02:43,170  -->  00:02:45,673
That's the idea of how this firewall works.
71

71

00:02:46,610  -->  00:02:49,500
In this case, it's blocking the outbound connections
72

72

00:02:49,500  -->  00:02:51,670
because it's preventing us from sending things
73

73

00:02:51,670  -->  00:02:53,610
out to the Internet.
74

74

00:02:53,610  -->  00:02:56,410
If we want to block things from coming in from the Internet,
75

75

00:02:56,410  -->  00:02:58,550
we're going to have to do that in a different firewall
76

76

00:02:58,550  -->  00:03:00,020
on this particular device
77

77

00:03:00,020  -->  00:03:04,116
because this one only has the outbound defined here.
78

78

00:03:04,116  -->  00:03:05,610
It's going to have what things
79

79

00:03:05,610  -->  00:03:08,080
as it's going out to the Internet.
80

80

00:03:08,080  -->  00:03:10,750
Now, if I want to do this on inbound stuff,
81

81

00:03:10,750  -->  00:03:12,170
I would have to go and find that
82

82

00:03:12,170  -->  00:03:13,600
in this particular router.
83

83

00:03:13,600  -->  00:03:15,570
That's usually going to be something like port forwarding
84

84

00:03:15,570  -->  00:03:19,270
or port triggering or something like a static route.
85

85

00:03:19,270  -->  00:03:21,720
In this case, I can port forward or port trigger
86

86

00:03:21,720  -->  00:03:23,520
and say hey, if something's trying to come in
87

87

00:03:23,520  -->  00:03:28,520
on port 21, FTP, it can go and be routed to my server,
88

88

00:03:28,640  -->  00:03:32,440
which is at the .50, for instance.
89

89

00:03:32,440  -->  00:03:35,120
So now, anything that comes in that's trying to get to
90

90

00:03:35,120  -->  00:03:37,950
this router on port 21 is going to be forwarded
91

91

00:03:37,950  -->  00:03:41,070
over to that IP address of .50.
92

92

00:03:41,070  -->  00:03:43,510
That's how you allow things in to your network
93

93

00:03:43,510  -->  00:03:46,239
based on this particular firewall.
94

94

00:03:46,239  -->  00:03:48,130
How do you block things with the firewall?
95

95

00:03:48,130  -->  00:03:49,870
Well, in this particular router,
96

96

00:03:49,870  -->  00:03:51,380
everything is blocked by default
97

97

00:03:51,380  -->  00:03:53,490
because it's doing an implicit deny,
98

98

00:03:53,490  -->  00:03:56,000
so, anytime I add a rule, like FTP here,
99

99

00:03:56,000  -->  00:03:58,710
that's doing an explicit allow.
100

100

00:03:58,710  -->  00:04:01,270
Anything you don't allow is going to be blocked by default
101

101

00:04:01,270  -->  00:04:04,113
on the inbound, based on this particular router.
