1
1

00:00:00,330  -->  00:00:02,690
<v ->Specialized Network Devices.</v>
2

2

00:00:02,690  -->  00:00:04,270
Now there are many different types
3

3

00:00:04,270  -->  00:00:05,630
of network devices out there,
4

4

00:00:05,630  -->  00:00:07,150
and there are lots of them that are outside
5

5

00:00:07,150  -->  00:00:10,280
of the standard routers, switches, hubs, bridges,
6

6

00:00:10,280  -->  00:00:13,190
servers, and workstations we've already talked about.
7

7

00:00:13,190  -->  00:00:14,680
Other devices out there are going to perform
8

8

00:00:14,680  -->  00:00:17,320
specific functions they'll improve our usability,
9

9

00:00:17,320  -->  00:00:19,550
our performance, or our security.
10

10

00:00:19,550  -->  00:00:22,640
Many of these devices include things like VPN concentrators,
11

11

00:00:22,640  -->  00:00:24,580
firewalls, proxy servers,
12

12

00:00:24,580  -->  00:00:26,590
and content engines and switches.
13

13

00:00:26,590  -->  00:00:29,070
We're going to talk about each of those in this lesson.
14

14

00:00:29,070  -->  00:00:31,850
The first one we're going to cover is a VPN concentrator,
15

15

00:00:31,850  -->  00:00:34,130
also known as a VPN head-end.
16

16

00:00:34,130  -->  00:00:36,540
Now a VPN is a virtual private network,
17

17

00:00:36,540  -->  00:00:38,360
and it's used to create a secure VPN
18

18

00:00:38,360  -->  00:00:40,940
or virtual tunnel over an untrusted network
19

19

00:00:40,940  -->  00:00:42,050
like the internet.
20

20

00:00:42,050  -->  00:00:43,750
If you're at home and you want to be able to dial
21

21

00:00:43,750  -->  00:00:44,583
into your office,
22

22

00:00:44,583  -->  00:00:45,900
either over a dial up connection
23

23

00:00:45,900  -->  00:00:47,700
or over the internet using broadband,
24

24

00:00:47,700  -->  00:00:49,840
you can do that using a VPN connection,
25

25

00:00:49,840  -->  00:00:51,230
which creates an encrypted tunnel
26

26

00:00:51,230  -->  00:00:53,400
so nobody can see what you're doing,
27

27

00:00:53,400  -->  00:00:56,070
but you get from your home to your office securely
28

28

00:00:56,070  -->  00:00:57,590
over that public network.
29

29

00:00:57,590  -->  00:01:00,020
Now the device that terminates this VPN tunnel
30

30

00:01:00,020  -->  00:01:03,350
is called a VPN concentrator or VPN head-end.
31

31

00:01:03,350  -->  00:01:06,330
This allows this device to have multiple VPN connections
32

32

00:01:06,330  -->  00:01:08,200
coming into one location.
33

33

00:01:08,200  -->  00:01:09,770
Now, if you have a good firewall,
34

34

00:01:09,770  -->  00:01:11,570
most of them will have this function.
35

35

00:01:11,570  -->  00:01:13,750
But logically, when it's doing this function,
36

36

00:01:13,750  -->  00:01:15,930
it's still functioning, not as a firewall,
37

37

00:01:15,930  -->  00:01:17,720
but as a VPN concentrator.
38

38

00:01:17,720  -->  00:01:19,490
So keep that in mind for the exam.
39

39

00:01:19,490  -->  00:01:21,430
The VPN concentrator is this function.
40

40

00:01:21,430  -->  00:01:23,820
It can be a device or part of another device
41

41

00:01:23,820  -->  00:01:26,360
like a UTM or a firewall as well.
42

42

00:01:26,360  -->  00:01:27,820
Now if I have a headquarters
43

43

00:01:27,820  -->  00:01:29,540
in Washington, DC, for example,
44

44

00:01:29,540  -->  00:01:30,940
and I have two other branch offices
45

45

00:01:30,940  -->  00:01:32,660
in Los Angeles and New York,
46

46

00:01:32,660  -->  00:01:34,540
I can actually tunnel all the traffic
47

47

00:01:34,540  -->  00:01:35,690
from Los Angeles and New York
48

48

00:01:35,690  -->  00:01:37,910
back to DC using these tunnels.
49

49

00:01:37,910  -->  00:01:39,040
In this case, I would use
50

50

00:01:39,040  -->  00:01:41,190
what's known as a site to site tunnel.
51

51

00:01:41,190  -->  00:01:43,340
These would allow those locations to connect back
52

52

00:01:43,340  -->  00:01:45,630
to my headquarters securely through the internet
53

53

00:01:45,630  -->  00:01:48,630
and save me the cost of having to use leased lines.
54

54

00:01:48,630  -->  00:01:51,140
Now when you hear the term VPN head-end,
55

55

00:01:51,140  -->  00:01:54,340
remember this is a specific type of VPN concentrator,
56

56

00:01:54,340  -->  00:01:56,980
and it's used to terminate IPSec VPN tunnels
57

57

00:01:56,980  -->  00:01:59,230
within a router or another device.
58

58

00:01:59,230  -->  00:02:01,220
Again, we're going to talk more about VPNs
59

59

00:02:01,220  -->  00:02:03,400
and VPN security in a separate lesson,
60

60

00:02:03,400  -->  00:02:05,360
because they're really important to the security
61

61

00:02:05,360  -->  00:02:07,810
of our networks and there's a lot to cover there.
62

62

00:02:07,810  -->  00:02:10,260
The next thing we're going to talk about is a firewall.
63

63

00:02:10,260  -->  00:02:12,700
Now a firewall is a network security appliance
64

64

00:02:12,700  -->  00:02:14,980
that's placed at the boundary of your network.
65

65

00:02:14,980  -->  00:02:17,030
Firewalls can be either software or hardware,
66

66

00:02:17,030  -->  00:02:19,560
and they come in stateful and stateless methods.
67

67

00:02:19,560  -->  00:02:21,490
We're going to talk more about firewalls in depth
68

68

00:02:21,490  -->  00:02:23,410
in their own video, but for now,
69

69

00:02:23,410  -->  00:02:24,940
I just want you to remember that firewalls
70

70

00:02:24,940  -->  00:02:27,000
allow traffic to go from inside your network
71

71

00:02:27,000  -->  00:02:29,160
to outside your network like to the internet
72

72

00:02:29,160  -->  00:02:31,500
and they can block stuff coming from outside your network,
73

73

00:02:31,500  -->  00:02:34,130
like the internet, to the inside of your network.
74

74

00:02:34,130  -->  00:02:35,160
Now on the screen,
75

75

00:02:35,160  -->  00:02:36,760
I have three different ways to show you
76

76

00:02:36,760  -->  00:02:39,750
how firewalls will look inside of network diagrams.
77

77

00:02:39,750  -->  00:02:42,020
The first way is what Cisco likes to use.
78

78

00:02:42,020  -->  00:02:43,700
They call this a Pix firewall
79

79

00:02:43,700  -->  00:02:45,480
cause that's their brand of firewall
80

80

00:02:45,480  -->  00:02:47,930
and it almost looks like a diode with a triangle
81

81

00:02:47,930  -->  00:02:49,010
and a line on it.
82

82

00:02:49,010  -->  00:02:50,790
A diode is essentially an electrical component
83

83

00:02:50,790  -->  00:02:52,910
that only lets things go one direction,
84

84

00:02:52,910  -->  00:02:55,360
which is why they represent a firewall in this way.
85

85

00:02:55,360  -->  00:02:57,110
Now the next one that some people will use
86

86

00:02:57,110  -->  00:02:58,970
is just to put a brick wall in their diagrams
87

87

00:02:58,970  -->  00:03:00,820
and that will represent a firewall.
88

88

00:03:00,820  -->  00:03:03,080
The third thing we can use is have your firewall
89

89

00:03:03,080  -->  00:03:05,560
combined with your router and basically make it look like
90

90

00:03:05,560  -->  00:03:08,120
a router with a brick wall wrapped around it.
91

91

00:03:08,120  -->  00:03:10,490
These are the three ways you'll see it in network diagrams
92

92

00:03:10,490  -->  00:03:12,090
when you're looking at firewalls.
93

93

00:03:12,090  -->  00:03:14,130
All three of these icons are used to demonstrate
94

94

00:03:14,130  -->  00:03:16,350
that there's a firewall there inside your diagram
95

95

00:03:16,350  -->  00:03:17,340
and most of the time,
96

96

00:03:17,340  -->  00:03:18,780
what you're going to see is that brick wall.
97

97

00:03:18,780  -->  00:03:21,000
That's pretty much the standard these days.
98

98

00:03:21,000  -->  00:03:22,440
Besides a regular firewall,
99

99

00:03:22,440  -->  00:03:24,430
we have these things called NGFWs
100

100

00:03:24,430  -->  00:03:27,170
or next generation or next gen firewalls.
101

101

00:03:27,170  -->  00:03:30,450
These can conduct deep packet inspection at layer seven.
102

102

00:03:30,450  -->  00:03:32,630
A regular firewall is really going to block things
103

103

00:03:32,630  -->  00:03:35,840
based on your IP address and maybe the port and protocol,
104

104

00:03:35,840  -->  00:03:37,690
but these next generation firewalls,
105

105

00:03:37,690  -->  00:03:38,730
they can look through your traffic
106

106

00:03:38,730  -->  00:03:40,650
to detect and prevent attacks.
107

107

00:03:40,650  -->  00:03:41,900
They are much more powerful
108

108

00:03:41,900  -->  00:03:43,650
than your basic stateless firewall
109

109

00:03:43,650  -->  00:03:45,410
or even your stateful firewalls.
110

110

00:03:45,410  -->  00:03:46,930
They're continually going to be connected
111

111

00:03:46,930  -->  00:03:49,730
to the cloud resources, get the latest threat information,
112

112

00:03:49,730  -->  00:03:51,960
to be able to make sure they know what those signatures are
113

113

00:03:51,960  -->  00:03:53,670
to do that deep inspection.
114

114

00:03:53,670  -->  00:03:55,660
Again, we're going to talk a lot more about firewalls
115

115

00:03:55,660  -->  00:03:56,990
in their own lesson.
116

116

00:03:56,990  -->  00:03:59,370
Next, we have IDS and IPS,
117

117

00:03:59,370  -->  00:04:00,870
which is intrusion detection systems
118

118

00:04:00,870  -->  00:04:02,729
or intrusion prevention systems.
119

119

00:04:02,729  -->  00:04:05,270
IDS' and IPS' can recognize attacks
120

120

00:04:05,270  -->  00:04:06,980
through signatures and anomalies.
121

121

00:04:06,980  -->  00:04:10,160
They can also recognize and respond if they're an IPS.
122

122

00:04:10,160  -->  00:04:13,440
Now a detection one can only see it and log it.
123

123

00:04:13,440  -->  00:04:15,550
But if you're using a protection one,
124

124

00:04:15,550  -->  00:04:17,280
they can actually see it, log it,
125

125

00:04:17,280  -->  00:04:20,640
and then try to stop it by shutting off ports and protocols.
126

126

00:04:20,640  -->  00:04:22,320
These IDS and IPS'
127

127

00:04:22,320  -->  00:04:24,620
can be host based or network based devices,
128

128

00:04:24,620  -->  00:04:26,700
depending on how you want to set it up in your network.
129

129

00:04:26,700  -->  00:04:28,890
And they're going to be on one of these two lines
130

130

00:04:28,890  -->  00:04:31,760
going left and right with a circle through them.
131

131

00:04:31,760  -->  00:04:34,460
This is considered an IDS or an IPS sensor,
132

132

00:04:34,460  -->  00:04:36,160
and it's the same diagram that's going to be used
133

133

00:04:36,160  -->  00:04:37,710
for both of these devices.
134

134

00:04:37,710  -->  00:04:41,180
The only difference is you'll see an IDS or IPS written
135

135

00:04:41,180  -->  00:04:43,970
on it to dictate which one it is and the diagram.
136

136

00:04:43,970  -->  00:04:47,600
Again, we're going to talk more about IDS and IPS in-depth
137

137

00:04:47,600  -->  00:04:49,730
in their own video because they're really important
138

138

00:04:49,730  -->  00:04:51,730
to the security of our networks.
139

139

00:04:51,730  -->  00:04:53,470
Next, we have a proxy server
140

140

00:04:53,470  -->  00:04:55,700
and this is another type of specialized device
141

141

00:04:55,700  -->  00:04:58,050
and this one is going to make request to an external network
142

142

00:04:58,050  -->  00:04:59,630
on behalf of a client.
143

143

00:04:59,630  -->  00:05:02,150
Essentially, it's a middleman or a go between.
144

144

00:05:02,150  -->  00:05:03,870
Now, why would we want to do that?
145

145

00:05:03,870  -->  00:05:05,540
Well, there's really two functions.
146

146

00:05:05,540  -->  00:05:07,160
The first was for security because
147

147

00:05:07,160  -->  00:05:09,410
it can perform content filtering and logging.
148

148

00:05:09,410  -->  00:05:12,480
On my network, I have a proxy server in my home network.
149

149

00:05:12,480  -->  00:05:14,550
So if my kids are trying to go online,
150

150

00:05:14,550  -->  00:05:16,580
it actually goes to the proxy server first.
151

151

00:05:16,580  -->  00:05:18,010
It checks what's allowable for them
152

152

00:05:18,010  -->  00:05:19,120
and then it decides whether or not
153

153

00:05:19,120  -->  00:05:20,890
to let them go out or not.
154

154

00:05:20,890  -->  00:05:23,210
For instance, if they tried to go to a pornographic website,
155

155

00:05:23,210  -->  00:05:24,320
it's going to block that.
156

156

00:05:24,320  -->  00:05:25,710
They try to go to Disney channel,
157

157

00:05:25,710  -->  00:05:27,230
it's going to allow that.
158

158

00:05:27,230  -->  00:05:29,300
Now workstation clients are going to be configured
159

159

00:05:29,300  -->  00:05:31,310
so that all their traffic is going to have to go
160

160

00:05:31,310  -->  00:05:33,780
through a proxy server in your corporate network.
161

161

00:05:33,780  -->  00:05:35,410
Here, you can see this on the diagram
162

162

00:05:35,410  -->  00:05:37,950
that if my son's computer and he wants to go make a request,
163

163

00:05:37,950  -->  00:05:39,720
he's going to go to the proxy server.
164

164

00:05:39,720  -->  00:05:41,610
Then the proxy server is going to check
165

165

00:05:41,610  -->  00:05:43,120
if it's on the allowable list.
166

166

00:05:43,120  -->  00:05:46,300
If it is, it goes out to something like disneychannel.com,
167

167

00:05:46,300  -->  00:05:49,030
gets the information, brings it back to the proxy server
168

168

00:05:49,030  -->  00:05:52,170
and then the proxy server gives it back to my kid.
169

169

00:05:52,170  -->  00:05:53,990
That would be function one.
170

170

00:05:53,990  -->  00:05:55,840
Now the second function of a proxy server
171

171

00:05:55,840  -->  00:05:57,430
is they can have a cache in there
172

172

00:05:57,430  -->  00:05:59,180
that can actually store a copy of that information
173

173

00:05:59,180  -->  00:06:00,930
that was requested by the user.
174

174

00:06:00,930  -->  00:06:02,840
In my case, I have two kids.
175

175

00:06:02,840  -->  00:06:04,780
Let's say my son goes to Disney Channel
176

176

00:06:04,780  -->  00:06:05,720
and then right after,
177

177

00:06:05,720  -->  00:06:08,350
my other son decides he wants to go to Disney Channel.
178

178

00:06:08,350  -->  00:06:10,810
Well, the proxy server already made that request
179

179

00:06:10,810  -->  00:06:12,000
and has it locally.
180

180

00:06:12,000  -->  00:06:14,040
So once he gave it to my first son,
181

181

00:06:14,040  -->  00:06:15,430
it can then give it to my other son
182

182

00:06:15,430  -->  00:06:17,760
without even having to go back out to the internet again
183

183

00:06:17,760  -->  00:06:21,280
and this saves bandwidth and saves resources and time.
184

184

00:06:21,280  -->  00:06:23,290
Proxy servers are really good at that,
185

185

00:06:23,290  -->  00:06:24,930
but they are not the best.
186

186

00:06:24,930  -->  00:06:27,210
Instead, we have another device out there
187

187

00:06:27,210  -->  00:06:29,180
which is called a content engine.
188

188

00:06:29,180  -->  00:06:31,450
These are dedicated devices that are there
189

189

00:06:31,450  -->  00:06:34,350
just to do cashing functions of a proxy server.
190

190

00:06:34,350  -->  00:06:36,240
They're basically more efficient than a proxy server
191

191

00:06:36,240  -->  00:06:39,290
when it comes to caching and we call them content engines
192

192

00:06:39,290  -->  00:06:41,140
or caching engines.
193

193

00:06:41,140  -->  00:06:43,130
Where there's really going to be a big benefit here
194

194

00:06:43,130  -->  00:06:44,670
is if you have a big headquarters
195

195

00:06:44,670  -->  00:06:46,640
with a big beefy internet pipe,
196

196

00:06:46,640  -->  00:06:48,380
but then you have the small branch office
197

197

00:06:48,380  -->  00:06:49,670
kind of in the middle of nowhere.
198

198

00:06:49,670  -->  00:06:51,940
It's really expensive for a good internet connection.
199

199

00:06:51,940  -->  00:06:54,230
If you have a lot of data that goes across a small pipe
200

200

00:06:54,230  -->  00:06:56,340
like a VPN or a lease line,
201

201

00:06:56,340  -->  00:06:58,810
this can actually be a big data bog
202

202

00:06:58,810  -->  00:07:00,850
and slow down inside of your network.
203

203

00:07:00,850  -->  00:07:03,170
So what you'd want to do is put a content engine
204

204

00:07:03,170  -->  00:07:04,530
at the branch office.
205

205

00:07:04,530  -->  00:07:06,110
This way in the middle of the night,
206

206

00:07:06,110  -->  00:07:08,170
the headquarters can actually sync up data
207

207

00:07:08,170  -->  00:07:11,160
and update that content engine and then during the day,
208

208

00:07:11,160  -->  00:07:12,920
anytime somebody requests that information,
209

209

00:07:12,920  -->  00:07:15,010
they get it locally from that office
210

210

00:07:15,010  -->  00:07:16,260
with the content engine
211

211

00:07:16,260  -->  00:07:18,590
and that way they're getting over a gigabit ethernet
212

212

00:07:18,590  -->  00:07:20,210
instead of going up a slow dial up
213

213

00:07:20,210  -->  00:07:22,920
or at least line connection back to the head office.
214

214

00:07:22,920  -->  00:07:25,390
Now, this is a very, very useful thing to use
215

215

00:07:25,390  -->  00:07:27,520
inside a remote branch office.
216

216

00:07:27,520  -->  00:07:29,500
Otherwise, if you're in a big headquarters
217

217

00:07:29,500  -->  00:07:31,860
and there's a big branch office that has a big pipe,
218

218

00:07:31,860  -->  00:07:33,380
you probably don't need a content engine
219

219

00:07:33,380  -->  00:07:35,340
because you can just go out over the large connection
220

220

00:07:35,340  -->  00:07:38,310
of the WAN and get that information from the headquarters.
221

221

00:07:38,310  -->  00:07:40,690
Again, if you're trying to speed up local access,
222

222

00:07:40,690  -->  00:07:43,100
content engines are really good for that.
223

223

00:07:43,100  -->  00:07:45,020
Next, we have a content switch.
224

224

00:07:45,020  -->  00:07:47,270
This is also known as a load balancer.
225

225

00:07:47,270  -->  00:07:49,930
Now a content switch or load balancer is going to distribute
226

226

00:07:49,930  -->  00:07:52,220
your incoming requests across various servers
227

227

00:07:52,220  -->  00:07:53,630
in a server farm.
228

228

00:07:53,630  -->  00:07:55,300
This is why we call it a load balancer
229

229

00:07:55,300  -->  00:07:56,920
because they're balancing the load.
230

230

00:07:56,920  -->  00:07:58,380
Now, why do we need these?
231

231

00:07:58,380  -->  00:08:01,010
Well, let's take the example of amazon.com.
232

232

00:08:01,010  -->  00:08:02,390
Do you think amazon.com
233

233

00:08:02,390  -->  00:08:04,030
can handle all of the amount of traffic
234

234

00:08:04,030  -->  00:08:07,200
it gets on a daily basis with just one physical server?
235

235

00:08:07,200  -->  00:08:08,050
Of course not.
236

236

00:08:08,050  -->  00:08:10,140
They have millions of users accessing their content
237

237

00:08:10,140  -->  00:08:11,420
all at the same time.
238

238

00:08:11,420  -->  00:08:13,850
Instead they have server farms with hundreds
239

239

00:08:13,850  -->  00:08:15,640
and thousands of servers out there.
240

240

00:08:15,640  -->  00:08:17,450
And all these have to be able to answer up
241

241

00:08:17,450  -->  00:08:19,940
for a single domain name, amazon.com.
242

242

00:08:19,940  -->  00:08:22,290
And that's where the content switch comes in.
243

243

00:08:22,290  -->  00:08:23,940
When you go to amazon.com,
244

244

00:08:23,940  -->  00:08:25,500
it actually goes through their router
245

245

00:08:25,500  -->  00:08:27,010
and to their content switch.
246

246

00:08:27,010  -->  00:08:29,160
And then it starts handing out those requests
247

247

00:08:29,160  -->  00:08:30,420
to different servers.
248

248

00:08:30,420  -->  00:08:31,650
If it's a big task,
249

249

00:08:31,650  -->  00:08:34,570
it might actually split that up across 20 different servers.
250

250

00:08:34,570  -->  00:08:36,880
For example, if I have a big task at work to do,
251

251

00:08:36,880  -->  00:08:38,740
I can actually break that down into pieces
252

252

00:08:38,740  -->  00:08:40,200
and give it out to 20 different people
253

253

00:08:40,200  -->  00:08:41,460
to help me get it done.
254

254

00:08:41,460  -->  00:08:44,150
In this case, I will be acting as the content switch.
255

255

00:08:44,150  -->  00:08:46,530
I break the load down to small parts and hand it out.
256

256

00:08:46,530  -->  00:08:48,100
So my boss comes to me and said hey,
257

257

00:08:48,100  -->  00:08:50,270
here are a hundred things I need done.
258

258

00:08:50,270  -->  00:08:52,480
I would then break those apart and give four or five
259

259

00:08:52,480  -->  00:08:54,210
to each person and hand them out
260

260

00:08:54,210  -->  00:08:55,860
and that way they can start doing the work.
261

261

00:08:55,860  -->  00:08:57,770
When they're done with it, they hand it back to me.
262

262

00:08:57,770  -->  00:09:00,270
I consolidate it and then I give it back to my boss.
263

263

00:09:00,270  -->  00:09:02,460
That's essentially what a content switch is doing.
264

264

00:09:02,460  -->  00:09:04,580
It's handing out those requests to different people
265

265

00:09:04,580  -->  00:09:06,550
based on their ability to perform the workload.
266

266

00:09:06,550  -->  00:09:08,820
In this case, those people are servers.
267

267

00:09:08,820  -->  00:09:11,730
That's exactly what a load balancer or content switch does.
268

268

00:09:11,730  -->  00:09:14,110
It's going to send the request and distribute the workload
269

269

00:09:14,110  -->  00:09:15,920
across all the different servers
270

270

00:09:15,920  -->  00:09:17,950
in order to provide the best response times
271

271

00:09:17,950  -->  00:09:20,800
and prevent a single server from becoming too overloaded.
