1
1

00:00:00,540  -->  00:00:03,080
<v ->Firewall issues, in this video,</v>
2

2

00:00:03,080  -->  00:00:04,760
we're going to discuss firewall issues
3

3

00:00:04,760  -->  00:00:06,550
and how to troubleshoot network issues
4

4

00:00:06,550  -->  00:00:08,330
involving incorrect firewall settings
5

5

00:00:08,330  -->  00:00:11,210
and block services, ports or addresses.
6

6

00:00:11,210  -->  00:00:13,830
First, let's talk about the purpose of a firewall.
7

7

00:00:13,830  -->  00:00:16,380
Remember firewalls or network security devices
8

8

00:00:16,380  -->  00:00:17,410
that moderate and filter
9

9

00:00:17,410  -->  00:00:19,440
incoming and outgoing network traffic
10

10

00:00:19,440  -->  00:00:21,400
based upon established rule sets.
11

11

00:00:21,400  -->  00:00:24,630
Essentially firewalls act as an inspection point and barrier
12

12

00:00:24,630  -->  00:00:27,290
between a private internal network and the public internet
13

13

00:00:27,290  -->  00:00:28,950
or other private internal networks,
14

14

00:00:28,950  -->  00:00:30,800
if you're using screen subnets,
15

15

00:00:30,800  -->  00:00:33,480
Now, firewalls can exist as either host-based firewalls
16

16

00:00:33,480  -->  00:00:35,150
or network-based firewalls.
17

17

00:00:35,150  -->  00:00:37,260
A host-based firewall is a piece of software
18

18

00:00:37,260  -->  00:00:39,570
that runs on an individual computer or device
19

19

00:00:39,570  -->  00:00:40,730
that's connected to your network
20

20

00:00:40,730  -->  00:00:42,710
and performs the functions of a firewall
21

21

00:00:42,710  -->  00:00:45,160
to protect that one single device.
22

22

00:00:45,160  -->  00:00:47,730
For example, if you're running a windows, client or server,
23

23

00:00:47,730  -->  00:00:50,540
you can utilize the built-in windows defender firewall
24

24

00:00:50,540  -->  00:00:51,780
to go dock to host based,
25

25

00:00:51,780  -->  00:00:54,130
two-way network traffic filtering and inspection,
26

26

00:00:54,130  -->  00:00:56,360
as well as blocking unauthorized network traffic
27

27

00:00:56,360  -->  00:00:58,920
from flowing into or out of your device.
28

28

00:00:58,920  -->  00:01:01,810
A network-based firewall is a network security device
29

29

00:01:01,810  -->  00:01:04,280
that's deployed inline with the network traffic flow,
30

30

00:01:04,280  -->  00:01:06,510
just before the border or gateway router
31

31

00:01:06,510  -->  00:01:08,610
in order to monitor and filter incoming
32

32

00:01:08,610  -->  00:01:10,080
and outgoing network traffic
33

33

00:01:10,080  -->  00:01:12,380
based upon your established rule sets.
34

34

00:01:12,380  -->  00:01:14,840
In general, regardless of whether the issue resides on a
35

35

00:01:14,840  -->  00:01:17,460
host-based firewall or a network-based firewall,
36

36

00:01:17,460  -->  00:01:19,410
the network connectivity issues experience
37

37

00:01:19,410  -->  00:01:22,380
will be caused by one of three different situations.
38

38

00:01:22,380  -->  00:01:24,570
First, access to protected resources
39

39

00:01:24,570  -->  00:01:26,940
from unprotected networks, isn't working.
40

40

00:01:26,940  -->  00:01:29,430
Second, access to unprotected resources
41

41

00:01:29,430  -->  00:01:31,600
from protected networks, isn't working.
42

42

00:01:31,600  -->  00:01:33,670
Or third, access to the firewall
43

43

00:01:33,670  -->  00:01:35,990
and its configurations, isn't working.
44

44

00:01:35,990  -->  00:01:37,860
Basically the problems can be broken down
45

45

00:01:37,860  -->  00:01:40,350
into either traffic is not going through the firewall
46

46

00:01:40,350  -->  00:01:42,540
or traffic is not going to the firewall,
47

47

00:01:42,540  -->  00:01:45,170
and in either case it's not working properly.
48

48

00:01:45,170  -->  00:01:47,240
So to troubleshoot these issues,
49

49

00:01:47,240  -->  00:01:49,540
you should use your seven-step troubleshooting method
50

50

00:01:49,540  -->  00:01:52,810
and understand the OSI model to troubleshoot each layer
51

51

00:01:52,810  -->  00:01:55,140
from layer one physical all the way up
52

52

00:01:55,140  -->  00:01:57,140
until you identify the issues.
53

53

00:01:57,140  -->  00:01:59,840
Now, for example, is the firewall properly cabled
54

54

00:01:59,840  -->  00:02:01,720
into the network at the right position?
55

55

00:02:01,720  -->  00:02:04,460
If so, does the link lights on the network interface card
56

56

00:02:04,460  -->  00:02:06,150
show up that the link is established
57

57

00:02:06,150  -->  00:02:07,680
between the router and the firewall?
58

58

00:02:07,680  -->  00:02:10,640
If it does layer, one is probably not your issue.
59

59

00:02:10,640  -->  00:02:12,120
Next, we go to layer two,
60

60

00:02:12,120  -->  00:02:13,800
and we determine if the router and firewall
61

61

00:02:13,800  -->  00:02:16,670
are communicating using AARP and their Mac addresses.
62

62

00:02:16,670  -->  00:02:18,930
If they are, we're going to move up to layer three
63

63

00:02:18,930  -->  00:02:21,320
and determine if the firewall has a valid IP address,
64

64

00:02:21,320  -->  00:02:23,170
subnet mask and default gateway.
65

65

00:02:23,170  -->  00:02:26,120
And that way it can communicate properly on the network.
66

66

00:02:26,120  -->  00:02:28,650
Once we've done all that we can now inspect the firewall
67

67

00:02:28,650  -->  00:02:29,850
itself for issues.
68

68

00:02:29,850  -->  00:02:31,880
Usually when traffic isn't flowing to
69

69

00:02:31,880  -->  00:02:33,360
or through the firewall,
70

70

00:02:33,360  -->  00:02:36,130
the issue is going to be related to a misconfigured rule set
71

71

00:02:36,130  -->  00:02:38,890
as part of your access control list or ACL.
72

72

00:02:38,890  -->  00:02:40,290
Now the access control list
73

73

00:02:40,290  -->  00:02:42,950
is simply a collection of permit and deny conditions,
74

74

00:02:42,950  -->  00:02:44,190
which we call rules.
75

75

00:02:44,190  -->  00:02:45,300
And they're going to provide security
76

76

00:02:45,300  -->  00:02:47,060
by blocking unauthorized users
77

77

00:02:47,060  -->  00:02:50,540
and allowing authorized users to access specific resources.
78

78

00:02:50,540  -->  00:02:53,320
To inspect the firewall rules on a network based firewall,
79

79

00:02:53,320  -->  00:02:56,470
you're going to use the command show access dash lists
80

80

00:02:56,470  -->  00:02:59,000
to display the contents of the current access control list
81

81

00:02:59,000  -->  00:03:01,240
on a Cisco device, as an example.
82

82

00:03:01,240  -->  00:03:03,020
Each device is going to have a different command,
83

83

00:03:03,020  -->  00:03:05,530
but for Cisco it's show access lists.
84

84

00:03:05,530  -->  00:03:07,700
Now, let's say for example, you're trying to figure out
85

85

00:03:07,700  -->  00:03:10,300
why the network clients and the internet filter group
86

86

00:03:10,300  -->  00:03:12,660
are not able to access Google, Facebook
87

87

00:03:12,660  -->  00:03:14,320
or Dion training's websites.
88

88

00:03:14,320  -->  00:03:16,320
You might log into your firewall or router
89

89

00:03:16,320  -->  00:03:18,550
and check the current ACL restrictions.
90

90

00:03:18,550  -->  00:03:19,630
In this example,
91

91

00:03:19,630  -->  00:03:22,130
you can see there's a deny statement in line 20
92

92

00:03:22,130  -->  00:03:23,480
for the internet filter group.
93

93

00:03:23,480  -->  00:03:25,850
And it states that all TCP network traffic
94

94

00:03:25,850  -->  00:03:28,950
from any IP to any IP over any port
95

95

00:03:28,950  -->  00:03:30,690
should be blocked by this rule.
96

96

00:03:30,690  -->  00:03:32,670
Basically, any clients have been added
97

97

00:03:32,670  -->  00:03:33,950
to the internet filter group
98

98

00:03:33,950  -->  00:03:36,240
will be unable to connect to any websites
99

99

00:03:36,240  -->  00:03:39,050
because they're using TCP to connect a report 80
100

100

00:03:39,050  -->  00:03:42,220
or port 443, when they're trying to go to a website.
101

101

00:03:42,220  -->  00:03:44,670
Similarly, if we have a client in the one-on-one group
102

102

00:03:44,670  -->  00:03:46,220
and it's having timing issues,
103

103

00:03:46,220  -->  00:03:49,070
we could look at our ACL and see what the root causes
104

104

00:03:49,070  -->  00:03:52,010
looking at line 10 within the one-to-one access control list
105

105

00:03:52,010  -->  00:03:54,180
states to deny any UDP traffic
106

106

00:03:54,180  -->  00:03:57,650
from any IP to any IP that uses NTP,
107

107

00:03:57,650  -->  00:04:01,360
which is port 123 and use for the network time protocol.
108

108

00:04:01,360  -->  00:04:04,940
The problem here is that NTP operates using UDP traffic.
109

109

00:04:04,940  -->  00:04:06,710
So the single line in the ACL
110

110

00:04:06,710  -->  00:04:08,620
will break all MTP functionality
111

111

00:04:08,620  -->  00:04:11,520
for any devices assigned to group 101.
112

112

00:04:11,520  -->  00:04:14,320
So when you're writing or editing an ACL rule,
113

113

00:04:14,320  -->  00:04:15,730
always be careful to think through
114

114

00:04:15,730  -->  00:04:17,840
what you're intending to do with that rule.
115

115

00:04:17,840  -->  00:04:20,980
First, you need to ensure there's no typos in your rules
116

116

00:04:20,980  -->  00:04:22,700
because this will cause a lot of issues,
117

117

00:04:22,700  -->  00:04:24,170
they'll result in traffic being blocked.
118

118

00:04:24,170  -->  00:04:25,570
When it really shouldn't be.
119

119

00:04:25,570  -->  00:04:28,130
Second, verify the protocol important numbers
120

120

00:04:28,130  -->  00:04:29,840
that you're referencing in your rule
121

121

00:04:29,840  -->  00:04:31,180
and ensure they're correct.
122

122

00:04:31,180  -->  00:04:33,700
Do you really want to block TCP or UDP?
123

123

00:04:33,700  -->  00:04:34,990
Make that decision?
124

124

00:04:34,990  -->  00:04:37,690
You want to block a specific port or all ports?
125

125

00:04:37,690  -->  00:04:39,700
All of this is important to consider.
126

126

00:04:39,700  -->  00:04:42,570
Third, verify the source and destination addresses
127

127

00:04:42,570  -->  00:04:44,070
are referenced by the rule.
128

128

00:04:44,070  -->  00:04:46,610
Did you include the correct IP address or network IP
129

129

00:04:46,610  -->  00:04:48,100
and the correct subnet mask?
130

130

00:04:48,100  -->  00:04:53,100
A simple typo like 0.0.255.255 instead of 0.0.0.255
131

131

00:04:54,490  -->  00:04:58,560
is going to cost 65,636 IPs to be blocked.
132

132

00:04:58,560  -->  00:05:02,060
Instead of the 256 IPS, you were intending to block.
133

133

00:05:02,060  -->  00:05:04,040
Fourth, verify the order of the rules
134

134

00:05:04,040  -->  00:05:05,600
is being applied correctly.
135

135

00:05:05,600  -->  00:05:08,340
Remember ACL's are always processing order
136

136

00:05:08,340  -->  00:05:10,740
from the top of the list to the bottom of the list.
137

137

00:05:10,740  -->  00:05:13,110
Your most specific rules need to be first
138

138

00:05:13,110  -->  00:05:15,800
and your motion rules need to be at the end.
139

139

00:05:15,800  -->  00:05:18,120
Let's consider this example and see if we can determine
140

140

00:05:18,120  -->  00:05:20,750
why a network client can't connect to Google servers
141

141

00:05:20,750  -->  00:05:25,200
at 8.8.8.8 from within the Dion training group of clients.
142

142

00:05:25,200  -->  00:05:27,600
Now, first, we're going to pull up the access control list
143

143

00:05:27,600  -->  00:05:29,660
and look for the Dion training group rules.
144

144

00:05:29,660  -->  00:05:30,640
Under these rules,
145

145

00:05:30,640  -->  00:05:32,770
we look under the rules pertaining to this issue.
146

146

00:05:32,770  -->  00:05:33,720
In this case,
147

147

00:05:33,720  -->  00:05:36,960
we can't reach the server located at 8.8.8.8.
148

148

00:05:36,960  -->  00:05:39,110
So if we look at rule 20,
149

149

00:05:39,110  -->  00:05:42,310
we're going to see there's a permit rule for all TCP traffic
150

150

00:05:42,310  -->  00:05:46,520
going from any IP, going to the server at 8.8.8.8,
151

151

00:05:46,520  -->  00:05:49,490
if it's over port 80, which is used for web traffic.
152

152

00:05:49,490  -->  00:05:51,440
So based on this rule loan,
153

153

00:05:51,440  -->  00:05:53,670
the traffic should be able to reach the server.
154

154

00:05:53,670  -->  00:05:55,360
Now, let's see what other rules we have
155

155

00:05:55,360  -->  00:05:57,930
for servers at 8.8.8.8.
156

156

00:05:57,930  -->  00:06:00,110
Now we have one rule at line 40,
157

157

00:06:00,110  -->  00:06:03,340
and it again says to permit traffic over TCP
158

158

00:06:03,340  -->  00:06:08,170
from any IP to the server at 8.8.8.8 using port 25.
159

159

00:06:08,170  -->  00:06:11,410
So we're going to allow email traffic over SMTP
160

160

00:06:11,410  -->  00:06:13,000
to be sent from any of our clients
161

161

00:06:13,000  -->  00:06:15,600
to the server at 8.8.8.8
162

162

00:06:15,600  -->  00:06:18,630
Again, this seems fine, and we shouldn't have an issue.
163

163

00:06:18,630  -->  00:06:22,000
Now, remember, ACL rules are implied in order,
164

164

00:06:22,000  -->  00:06:23,560
and once it finds a matching rule,
165

165

00:06:23,560  -->  00:06:26,300
it's going to stop as it goes down the access list.
166

166

00:06:26,300  -->  00:06:28,330
So look at it from the beginning.
167

167

00:06:28,330  -->  00:06:30,380
The first rule is line 10.
168

168

00:06:30,380  -->  00:06:33,040
It says to deny any TCP traffic
169

169

00:06:33,040  -->  00:06:36,280
from any IP address to any IP address.
170

170

00:06:36,280  -->  00:06:39,600
And this applies to all ports because none were specified.
171

171

00:06:39,600  -->  00:06:43,190
So if I'm trying to visit the server at 8.8.8.8,
172

172

00:06:43,190  -->  00:06:45,350
will rule 10 match this packet?
173

173

00:06:45,350  -->  00:06:49,440
Is it going to go from any IP to any IP using TCP?
174

174

00:06:49,440  -->  00:06:51,010
Yes, yes it is.
175

175

00:06:51,010  -->  00:06:53,000
Therefore the traffic is going to be blocked
176

176

00:06:53,000  -->  00:06:55,630
and it will never get to rule 20 or rule 40
177

177

00:06:55,630  -->  00:06:57,830
that specifically allow traffic to this server
178

178

00:06:57,830  -->  00:07:01,780
at 8.8.8.8 over port 80 or port 25.
179

179

00:07:01,780  -->  00:07:04,600
So instead we can change the order of this ACL
180

180

00:07:04,600  -->  00:07:06,140
and we're going to put the more specific lines
181

181

00:07:06,140  -->  00:07:08,040
like 20 and 40 at the top.
182

182

00:07:08,040  -->  00:07:10,520
So we're going to make them 10 and 20 respectfully.
183

183

00:07:10,520  -->  00:07:12,480
Then we're going to take the current line 10
184

184

00:07:12,480  -->  00:07:14,470
and move it to the bottom of our list.
185

185

00:07:14,470  -->  00:07:17,520
So to make this easier to see I'm creating a new group here
186

186

00:07:17,520  -->  00:07:20,850
called Dion training new at the bottom of this ACL.
187

187

00:07:20,850  -->  00:07:22,580
Here, you can see the difference in the order
188

188

00:07:22,580  -->  00:07:25,620
from Dion training group to the Dion training new group.
189

189

00:07:25,620  -->  00:07:28,760
So notice I now have our most specific ACL
190

190

00:07:28,760  -->  00:07:32,320
listed at 10 and 20 and a more generic one at line 30,
191

191

00:07:32,320  -->  00:07:36,310
which is for the any IP to any IP, but for a specific port.
192

192

00:07:36,310  -->  00:07:38,830
Then I have my most generic rules at the bottom,
193

193

00:07:38,830  -->  00:07:40,360
lines, 40 and 50.
194

194

00:07:40,360  -->  00:07:42,560
This is going to block all traffic for UDP
195

195

00:07:42,560  -->  00:07:44,510
and all traffic for TCP.
196

196

00:07:44,510  -->  00:07:47,350
Remember when you're troubleshooting issues with firewalls,
197

197

00:07:47,350  -->  00:07:48,580
always check your ACL's
198

198

00:07:48,580  -->  00:07:50,190
to ensure they're in the right sequence
199

199

00:07:50,190  -->  00:07:52,080
and that you haven't missed typed anything in them
200

200

00:07:52,080  -->  00:07:54,320
because this can lead to a lot of connectivity issues
201

201

00:07:54,320  -->  00:07:55,940
and the wrong traffic being blocked
202

202

00:07:55,940  -->  00:07:57,830
or being allowed through your firewall.
203

203

00:07:57,830  -->  00:08:00,160
Similarly, when you're dealing with software firewalls,
204

204

00:08:00,160  -->  00:08:01,770
like the windows defender firewall,
205

205

00:08:01,770  -->  00:08:04,000
it's important to look not just at the IP addresses
206

206

00:08:04,000  -->  00:08:05,290
and ports that are being blocked,
207

207

00:08:05,290  -->  00:08:06,920
but also you need to look at the
208

208

00:08:06,920  -->  00:08:09,180
applications and services themselves.
209

209

00:08:09,180  -->  00:08:11,010
Under your windows defender firewall,
210

210

00:08:11,010  -->  00:08:13,830
you're going to see inbound rules and outbound rules listed.
211

211

00:08:13,830  -->  00:08:14,770
Under each type,
212

212

00:08:14,770  -->  00:08:16,940
you're going to see the name of the application or service
213

213

00:08:16,940  -->  00:08:18,810
and whether it's allowed or denied.
214

214

00:08:18,810  -->  00:08:21,900
Then you're going to see if any specific IP addresses reports
215

215

00:08:21,900  -->  00:08:23,030
are being allowed or blocked
216

216

00:08:23,030  -->  00:08:25,160
with those applications and services.
217

217

00:08:25,160  -->  00:08:27,730
Just like in the earlier examples with network firewalls,
218

218

00:08:27,730  -->  00:08:30,500
a simple typo here can cause a lot of connectivity problems
219

219

00:08:30,500  -->  00:08:32,210
for your clients and your servers.
220

220

00:08:32,210  -->  00:08:34,050
So always double check your ACL's
221

221

00:08:34,050  -->  00:08:35,320
to ensure they're blocking and allowing
222

222

00:08:35,320  -->  00:08:38,120
exactly what you want them to do and in the right order.
