1
00:00:00,000 --> 00:00:02,850
In this lesson, we're going to discuss Firewalls.

2
00:00:02,850 --> 00:00:04,920
Now, a firewall is a network security device

3
00:00:04,920 --> 00:00:07,320
or software that monitors and controls incoming

4
00:00:07,320 --> 00:00:09,090
and outgoing network traffic based

5
00:00:09,090 --> 00:00:10,590
on predetermined security rules

6
00:00:10,590 --> 00:00:12,600
to protect a network from unauthorized access

7
00:00:12,600 --> 00:00:14,040
and potential threats.

8
00:00:14,040 --> 00:00:16,079
Firewalls can be hardware-based appliances

9
00:00:16,079 --> 00:00:18,660
or specialized software installed on a client or server

10
00:00:18,660 --> 00:00:20,220
to perform this function.

11
00:00:20,220 --> 00:00:21,750
The primary role of a firewall

12
00:00:21,750 --> 00:00:23,820
is going to be to inspect and control traffic,

13
00:00:23,820 --> 00:00:26,070
try and enter or leave a network's boundary.

14
00:00:26,070 --> 00:00:28,620
By placing a firewall in front of a given network segment,

15
00:00:28,620 --> 00:00:31,290
we can create what is known as a Screened Subnet.

16
00:00:31,290 --> 00:00:32,400
Now, a Screened Subnet,

17
00:00:32,400 --> 00:00:34,860
also known as a Dual-homed Host configuration,

18
00:00:34,860 --> 00:00:36,900
plays a crucial role in network security

19
00:00:36,900 --> 00:00:38,490
by acting as a protective barrier

20
00:00:38,490 --> 00:00:40,410
between external untrusted networks,

21
00:00:40,410 --> 00:00:42,330
and internal trusted networks.

22
00:00:42,330 --> 00:00:44,520
Under this setup, a Dual-homed Host

23
00:00:44,520 --> 00:00:46,830
will often be equipped with a packet-filtering firewall

24
00:00:46,830 --> 00:00:48,300
or other security mechanisms

25
00:00:48,300 --> 00:00:50,100
by sitting between these networks.

26
00:00:50,100 --> 00:00:52,470
This effectively helps to screen and filter traffic

27
00:00:52,470 --> 00:00:54,120
as it passes from the untrusted network

28
00:00:54,120 --> 00:00:55,260
to the trusted network,

29
00:00:55,260 --> 00:00:56,520
and it will serve as a buffer

30
00:00:56,520 --> 00:00:58,740
that's going to inspect and control incoming traffic

31
00:00:58,740 --> 00:00:59,910
so that only legitimate

32
00:00:59,910 --> 00:01:01,860
and authorized data flows can make it through

33
00:01:01,860 --> 00:01:03,090
to your internal network,

34
00:01:03,090 --> 00:01:04,830
and everything else will be blocked,

35
00:01:04,830 --> 00:01:06,000
including potential threats

36
00:01:06,000 --> 00:01:08,040
and unauthorized access attempts.

37
00:01:08,040 --> 00:01:09,240
Understanding how to configure

38
00:01:09,240 --> 00:01:10,560
and maintain Screened Subnet

39
00:01:10,560 --> 00:01:12,420
is really essential for network administrators

40
00:01:12,420 --> 00:01:14,400
and security professionals to be able to enhance

41
00:01:14,400 --> 00:01:16,140
the security posture of their networks

42
00:01:16,140 --> 00:01:17,760
and protect the sensitive information

43
00:01:17,760 --> 00:01:19,380
that is contained inside those networks

44
00:01:19,380 --> 00:01:21,030
from an external threat.

45
00:01:21,030 --> 00:01:22,680
Now to create a screened subnet,

46
00:01:22,680 --> 00:01:25,260
you must first install a firewall into your network.

47
00:01:25,260 --> 00:01:27,240
There are many different types of firewalls out there,

48
00:01:27,240 --> 00:01:28,500
including Packet filtering,

49
00:01:28,500 --> 00:01:31,230
Stateful, Proxy, Dynamic packet filtering,

50
00:01:31,230 --> 00:01:33,150
and Kernel proxy firewalls.

51
00:01:33,150 --> 00:01:35,400
Each type of firewall is going to focus on either

52
00:01:35,400 --> 00:01:38,640
a more or less thorough inspection of your network traffic.

53
00:01:38,640 --> 00:01:40,320
As with everything in network security,

54
00:01:40,320 --> 00:01:42,540
there's always going to be a performance trade-off based upon

55
00:01:42,540 --> 00:01:44,850
how deep of an inspection we want to do.

56
00:01:44,850 --> 00:01:47,190
If your firewall does a more in-depth inspection,

57
00:01:47,190 --> 00:01:49,710
that device is actually going to slow down its throughput,

58
00:01:49,710 --> 00:01:50,850
because it's going to take more time

59
00:01:50,850 --> 00:01:52,920
to go through each one of the ACL rules

60
00:01:52,920 --> 00:01:55,440
and inspect each of the packets against those rules.

61
00:01:55,440 --> 00:01:57,000
And in turn, this will negatively affect

62
00:01:57,000 --> 00:01:58,200
our network's efficiency

63
00:01:58,200 --> 00:02:00,120
and increase our network latency.

64
00:02:00,120 --> 00:02:00,960
Now, on the other hand,

65
00:02:00,960 --> 00:02:03,000
if you do a more cursory inspection,

66
00:02:03,000 --> 00:02:04,980
this is actually going to be a faster firewall,

67
00:02:04,980 --> 00:02:07,380
but you're not going to get as good of security.

68
00:02:07,380 --> 00:02:08,820
Now, the most efficient firewalls

69
00:02:08,820 --> 00:02:10,650
in terms of maximizing your throughput

70
00:02:10,650 --> 00:02:13,320
are going to be our Packet Filtering Firewalls.

71
00:02:13,320 --> 00:02:16,020
These firewalls are going to do the minimum level of inspection

72
00:02:16,020 --> 00:02:18,150
because they're only going to inspect the header of the packet

73
00:02:18,150 --> 00:02:20,220
to determine if the traffic is going to be allowed

74
00:02:20,220 --> 00:02:22,290
or denied based upon the IP address

75
00:02:22,290 --> 00:02:24,720
and the port number contained in that packet.

76
00:02:24,720 --> 00:02:26,790
This type of firewall will act very similarly

77
00:02:26,790 --> 00:02:28,950
to a router using an access control list

78
00:02:28,950 --> 00:02:30,900
that's going to be placed between subnets inside

79
00:02:30,900 --> 00:02:32,100
of a given network.

80
00:02:32,100 --> 00:02:32,933
Unfortunately,

81
00:02:32,933 --> 00:02:35,820
these simple firewalls cannot prevent IP spoofing,

82
00:02:35,820 --> 00:02:37,200
packet fragmentation attacks,

83
00:02:37,200 --> 00:02:40,020
or attacks against the TCP handshake itself

84
00:02:40,020 --> 00:02:41,760
because they're limited in their inspection

85
00:02:41,760 --> 00:02:44,010
to the packet header of that traffic.

86
00:02:44,010 --> 00:02:46,080
Since these firewalls operate based on ports

87
00:02:46,080 --> 00:02:47,340
and protocols being used,

88
00:02:47,340 --> 00:02:49,650
they're also known as a Layer 4 firewall

89
00:02:49,650 --> 00:02:52,770
because they operate at Layer 4 of the OSI model.

90
00:02:52,770 --> 00:02:53,820
Now, the next one we have

91
00:02:53,820 --> 00:02:55,890
is what's known as a Stateful Firewall.

92
00:02:55,890 --> 00:02:58,230
A Stateful Firewall is going to be used to track the state

93
00:02:58,230 --> 00:02:59,910
of all the connections and requests

94
00:02:59,910 --> 00:03:02,010
that are going into and out of the network.

95
00:03:02,010 --> 00:03:03,870
So in addition to a simple header inspection

96
00:03:03,870 --> 00:03:06,240
that's being performed by the packet filtering firewall,

97
00:03:06,240 --> 00:03:08,190
a Stateful Firewall will also know

98
00:03:08,190 --> 00:03:10,470
if an outbound request is made from our network.

99
00:03:10,470 --> 00:03:12,120
And then it's going to use that information

100
00:03:12,120 --> 00:03:13,500
to determine if it's going to allow

101
00:03:13,500 --> 00:03:15,330
or accept traffic coming into the network

102
00:03:15,330 --> 00:03:18,120
from a remote host going towards your network.

103
00:03:18,120 --> 00:03:19,620
For example, when you attempt

104
00:03:19,620 --> 00:03:22,020
to visit a website like diontraining.com,

105
00:03:22,020 --> 00:03:24,210
your Stateful Firewall will remember this,

106
00:03:24,210 --> 00:03:26,040
and then it's going to allow the return traffic

107
00:03:26,040 --> 00:03:28,260
from my web server, diontraining.com,

108
00:03:28,260 --> 00:03:29,610
to go back to your host

109
00:03:29,610 --> 00:03:31,950
because it remembers that you asked for the information

110
00:03:31,950 --> 00:03:35,130
that I'm now presenting to you as part of my delivery.

111
00:03:35,130 --> 00:03:36,210
Now, a Proxy Firewall

112
00:03:36,210 --> 00:03:37,980
is our third type we're going to talk about.

113
00:03:37,980 --> 00:03:40,590
And a Proxy Firewall is going to be placed between an internal

114
00:03:40,590 --> 00:03:42,480
or external connection in a network,

115
00:03:42,480 --> 00:03:44,070
and it's going to make connections on behalf

116
00:03:44,070 --> 00:03:45,510
of your other endpoints.

117
00:03:45,510 --> 00:03:47,580
Now, there are two types of Proxy Firewalls.

118
00:03:47,580 --> 00:03:48,990
These are known as a circuit level

119
00:03:48,990 --> 00:03:51,660
or an application level proxy firewall.

120
00:03:51,660 --> 00:03:54,420
Now, a circuit level firewall like a SOCKS firewall

121
00:03:54,420 --> 00:03:56,010
is going to operate at the session layer

122
00:03:56,010 --> 00:03:58,230
or Layer 5 of the OSI model.

123
00:03:58,230 --> 00:04:00,420
An application level proxy, on the other hand,

124
00:04:00,420 --> 00:04:02,370
is going to do a deeper packet inspection

125
00:04:02,370 --> 00:04:04,350
that's going to conduct a different proxy function

126
00:04:04,350 --> 00:04:05,820
for each type of application

127
00:04:05,820 --> 00:04:08,160
at Layer 7 of the OSI model.

128
00:04:08,160 --> 00:04:11,610
For example, an application level proxy can be used to read

129
00:04:11,610 --> 00:04:13,680
and filter HTTP traffic differently

130
00:04:13,680 --> 00:04:15,750
than it would do for FTP traffic

131
00:04:15,750 --> 00:04:18,300
because it uses this deep packet analysis.

132
00:04:18,300 --> 00:04:20,670
Now, a deep packet analysis is going to create

133
00:04:20,670 --> 00:04:22,200
a larger impact to the performance

134
00:04:22,200 --> 00:04:24,090
and efficiency of our firewalls,

135
00:04:24,090 --> 00:04:25,410
and this allows traffic to go through

136
00:04:25,410 --> 00:04:27,420
the network much more slowly.

137
00:04:27,420 --> 00:04:30,270
For this reason, most application level proxies

138
00:04:30,270 --> 00:04:32,550
are going to be best positioned inside of your network

139
00:04:32,550 --> 00:04:34,290
when they're located as closely as possible

140
00:04:34,290 --> 00:04:37,200
to the application server that you're trying to protect.

141
00:04:37,200 --> 00:04:39,420
Another name for an application level proxy

142
00:04:39,420 --> 00:04:41,880
is known as a Layer 7 firewall.

143
00:04:41,880 --> 00:04:43,620
Now, the next type of firewall we need to cover

144
00:04:43,620 --> 00:04:45,900
is known as a Kernel Proxy Firewall.

145
00:04:45,900 --> 00:04:47,400
A Kernel Proxy Firewall

146
00:04:47,400 --> 00:04:49,830
is also known as a Fifth Generation Firewall,

147
00:04:49,830 --> 00:04:51,570
and they're going to be placed between two systems

148
00:04:51,570 --> 00:04:53,370
and create connections on their behalf,

149
00:04:53,370 --> 00:04:56,100
much like the other firewall types we've already discussed.

150
00:04:56,100 --> 00:04:58,500
The main distinction of a Kernel Proxy Firewall

151
00:04:58,500 --> 00:04:59,790
is that it has a minimal impact

152
00:04:59,790 --> 00:05:01,440
to performance on our network,

153
00:05:01,440 --> 00:05:03,990
even while conducting its full inspection of the packet

154
00:05:03,990 --> 00:05:05,880
at every single layer.

155
00:05:05,880 --> 00:05:08,160
These devices should be placed as close as possible

156
00:05:08,160 --> 00:05:09,660
to the system they're trying to protect inside

157
00:05:09,660 --> 00:05:11,400
of the network as well to give you the best

158
00:05:11,400 --> 00:05:13,380
and most efficient usage of them.

159
00:05:13,380 --> 00:05:14,970
Now, because firewalls have become such

160
00:05:14,970 --> 00:05:16,920
an integral security device in our networks,

161
00:05:16,920 --> 00:05:18,270
they're constantly being evolved

162
00:05:18,270 --> 00:05:20,850
to provide us with better features and more security.

163
00:05:20,850 --> 00:05:22,170
There are three such evolutions

164
00:05:22,170 --> 00:05:23,700
that we've seen in recent years,

165
00:05:23,700 --> 00:05:25,920
including things like an NGFW

166
00:05:25,920 --> 00:05:27,570
or Next Generation Firewall,

167
00:05:27,570 --> 00:05:30,150
the UTM, or Unified Threat Management Firewall,

168
00:05:30,150 --> 00:05:33,570
and the WAF, or Web Application Firewall.

169
00:05:33,570 --> 00:05:35,310
All of these are going to focus on adding

170
00:05:35,310 --> 00:05:36,690
and optimizing application

171
00:05:36,690 --> 00:05:38,370
and protocol aware technologies

172
00:05:38,370 --> 00:05:41,130
to provide us with even better levels of security.

173
00:05:41,130 --> 00:05:42,510
Now, the first one we're going to cover here

174
00:05:42,510 --> 00:05:44,220
is a Next-Generation Firewall.

175
00:05:44,220 --> 00:05:45,720
And the Next-Generation Firewall

176
00:05:45,720 --> 00:05:47,700
is going to attempt to overcome the shortcomings

177
00:05:47,700 --> 00:05:49,440
of a traditional Stateful Firewall

178
00:05:49,440 --> 00:05:52,350
by creating firewalls that are application aware.

179
00:05:52,350 --> 00:05:53,790
This means that these firewalls

180
00:05:53,790 --> 00:05:55,950
can distinguish between different types of traffic

181
00:05:55,950 --> 00:05:57,840
that specific applications they're sending into

182
00:05:57,840 --> 00:05:59,520
or out of a given network.

183
00:05:59,520 --> 00:06:01,440
Because of this, these devices can conduct

184
00:06:01,440 --> 00:06:03,780
a single deep packet inspection of the traffic,

185
00:06:03,780 --> 00:06:05,700
and then they can utilize signature-based intrusion

186
00:06:05,700 --> 00:06:07,770
protection measures when they're being installed

187
00:06:07,770 --> 00:06:10,680
as an inline device inside your network configuration.

188
00:06:10,680 --> 00:06:13,710
Additionally, these Next-Generation Firewalls are fast,

189
00:06:13,710 --> 00:06:16,110
and they have little impact to your network's performance.

190
00:06:16,110 --> 00:06:18,210
These devices also have full-stack visibility

191
00:06:18,210 --> 00:06:19,080
over the traffic,

192
00:06:19,080 --> 00:06:21,510
and they can provide more granular control over the traffic

193
00:06:21,510 --> 00:06:24,480
by creating custom signatures inside this firewall.

194
00:06:24,480 --> 00:06:26,220
Next-Generation Firewalls are considered

195
00:06:26,220 --> 00:06:27,480
to be complex devices,

196
00:06:27,480 --> 00:06:28,313
and they have the ability

197
00:06:28,313 --> 00:06:30,840
to integrate with several other security products too.

198
00:06:30,840 --> 00:06:32,250
Unfortunately, this can lead

199
00:06:32,250 --> 00:06:33,690
to our organization becoming reliant

200
00:06:33,690 --> 00:06:35,400
on a single vendor over time

201
00:06:35,400 --> 00:06:36,930
because these different firewalls

202
00:06:36,930 --> 00:06:37,980
are going to be configured to work

203
00:06:37,980 --> 00:06:39,870
with their product lines only.

204
00:06:39,870 --> 00:06:42,090
Now, these firewalls are going to be much more complex

205
00:06:42,090 --> 00:06:44,490
to manage than a single packet-filtering firewall

206
00:06:44,490 --> 00:06:46,110
or a Stateful Firewall would be,

207
00:06:46,110 --> 00:06:49,020
but they do add a lot of security for us as well.

208
00:06:49,020 --> 00:06:50,070
Now, it's important to note

209
00:06:50,070 --> 00:06:51,720
that many organizations have moved

210
00:06:51,720 --> 00:06:53,850
from a Next-Generation Firewall into something known

211
00:06:53,850 --> 00:06:57,360
as a UTM, or Unified Threat Management Firewall.

212
00:06:57,360 --> 00:06:59,310
Now, a Unified Threat Management Firewall

213
00:06:59,310 --> 00:07:00,510
is going to provide us the ability

214
00:07:00,510 --> 00:07:02,280
to conduct numerous security functions

215
00:07:02,280 --> 00:07:05,010
from within a single device or network appliance.

216
00:07:05,010 --> 00:07:06,840
These devices include the functionality

217
00:07:06,840 --> 00:07:08,460
of multiple specialized devices,

218
00:07:08,460 --> 00:07:09,930
including network firewalls,

219
00:07:09,930 --> 00:07:11,760
network intrusion prevention systems,

220
00:07:11,760 --> 00:07:14,220
gateway antivirus and antispam capabilities,

221
00:07:14,220 --> 00:07:16,200
virtual private network concentration,

222
00:07:16,200 --> 00:07:18,060
content filtering, load balancing,

223
00:07:18,060 --> 00:07:19,470
and data loss prevention,

224
00:07:19,470 --> 00:07:22,080
all from within a single network appliance.

225
00:07:22,080 --> 00:07:23,820
These Unified Threat Management devices

226
00:07:23,820 --> 00:07:25,350
have a ton of benefits,

227
00:07:25,350 --> 00:07:26,940
including reducing the number of devices

228
00:07:26,940 --> 00:07:28,230
that technicians need to learn,

229
00:07:28,230 --> 00:07:29,670
operate, and maintain,

230
00:07:29,670 --> 00:07:31,920
and this can overall help to decrease your cost

231
00:07:31,920 --> 00:07:33,450
of providing these protections.

232
00:07:33,450 --> 00:07:36,690
But there are still some drawbacks to using a UTM.

233
00:07:36,690 --> 00:07:37,950
Now, the largest issue with using

234
00:07:37,950 --> 00:07:39,570
a Unified Threat Management device

235
00:07:39,570 --> 00:07:41,370
is that they become a single point of failure

236
00:07:41,370 --> 00:07:42,450
in your network.

237
00:07:42,450 --> 00:07:44,130
If that device fails, for example,

238
00:07:44,130 --> 00:07:46,050
we don't just lose our firewall anymore,

239
00:07:46,050 --> 00:07:47,430
we're now losing our firewall,

240
00:07:47,430 --> 00:07:49,560
our antivirus, our intrusion prevention system,

241
00:07:49,560 --> 00:07:51,570
and all the other things we just mentioned.

242
00:07:51,570 --> 00:07:53,190
All of our security stack can be wrapped up

243
00:07:53,190 --> 00:07:54,840
in this one device, which is great,

244
00:07:54,840 --> 00:07:56,880
but it also means if we lose that device,

245
00:07:56,880 --> 00:07:59,190
we lose our entire security stack.

246
00:07:59,190 --> 00:08:02,250
So our organization needs to consider both the advantages

247
00:08:02,250 --> 00:08:04,140
and disadvantages of using something like

248
00:08:04,140 --> 00:08:06,510
a Unified Threat Management system before deciding

249
00:08:06,510 --> 00:08:08,970
to implement it inside of your network architecture.

250
00:08:08,970 --> 00:08:09,990
Some advantages of using

251
00:08:09,990 --> 00:08:11,370
a Unified Threat Management device

252
00:08:11,370 --> 00:08:12,960
include lower upfront costs,

253
00:08:12,960 --> 00:08:15,120
lower maintenance, and lower power consumption,

254
00:08:15,120 --> 00:08:16,710
because all these functions reside

255
00:08:16,710 --> 00:08:18,600
in a single rack mounted device.

256
00:08:18,600 --> 00:08:20,910
Now, they're also going to be easier to install and configure

257
00:08:20,910 --> 00:08:22,980
because you don't have to deal with multiple devices

258
00:08:22,980 --> 00:08:24,330
that each have a single function,

259
00:08:24,330 --> 00:08:26,880
and instead, they're all integrated into this one device

260
00:08:26,880 --> 00:08:28,800
and this gives us a lot of great benefits.

261
00:08:28,800 --> 00:08:30,330
But the biggest disadvantage here

262
00:08:30,330 --> 00:08:32,640
is that it does create that single point of failure,

263
00:08:32,640 --> 00:08:34,620
and they often lack the detail provided

264
00:08:34,620 --> 00:08:36,120
by more specialized tools,

265
00:08:36,120 --> 00:08:38,039
and their performance can oftentimes not be

266
00:08:38,039 --> 00:08:40,919
as efficient as a single function device might be.

267
00:08:40,919 --> 00:08:42,840
While Unified Threat Management devices work well

268
00:08:42,840 --> 00:08:43,740
for the most part,

269
00:08:43,740 --> 00:08:45,960
they do utilize separate individual engines

270
00:08:45,960 --> 00:08:48,210
for each function that they're trying to perform inside

271
00:08:48,210 --> 00:08:49,830
of their security inspections.

272
00:08:49,830 --> 00:08:52,230
Whereas, when you're using a Next-Generation Firewall,

273
00:08:52,230 --> 00:08:54,300
you're going to be using a single more efficient engine

274
00:08:54,300 --> 00:08:55,320
for a firewall.

275
00:08:55,320 --> 00:08:56,490
But with a UTM,

276
00:08:56,490 --> 00:08:57,780
you're using something where

277
00:08:57,780 --> 00:08:59,610
it's not going to be necessarily as efficient,

278
00:08:59,610 --> 00:09:02,610
but it's good enough to do most of the functions you want.

279
00:09:02,610 --> 00:09:04,650
And so if network speed and efficiency

280
00:09:04,650 --> 00:09:07,260
is going to be your primary concern in your organization,

281
00:09:07,260 --> 00:09:08,430
you're going to want to consider using

282
00:09:08,430 --> 00:09:09,810
a Next-Generation Firewall

283
00:09:09,810 --> 00:09:12,120
over a Unified Threat Management device.

284
00:09:12,120 --> 00:09:13,800
But if your organization does decide

285
00:09:13,800 --> 00:09:15,600
to use a Unified Threat Management device,

286
00:09:15,600 --> 00:09:17,550
you would want to place it between your LAN

287
00:09:17,550 --> 00:09:19,080
and the connection to the Internet,

288
00:09:19,080 --> 00:09:21,120
just as if it was a gateway firewall

289
00:09:21,120 --> 00:09:23,280
as an inline configured device.

290
00:09:23,280 --> 00:09:25,620
Finally, we need to talk about a specialized type

291
00:09:25,620 --> 00:09:30,060
of firewall known as a WAF or Web Application Firewall.

292
00:09:30,060 --> 00:09:31,650
Now, a Web Application Firewall

293
00:09:31,650 --> 00:09:34,710
is going to be focused on the inspection of HTTP traffic,

294
00:09:34,710 --> 00:09:37,140
known as Hypertext Transfer Protocol traffic.

295
00:09:37,140 --> 00:09:40,500
Now, this can be either HTTP or HTTPS traffic depending

296
00:09:40,500 --> 00:09:42,510
on your Web Application Firewall.

297
00:09:42,510 --> 00:09:44,130
Your Web Application Firewall

298
00:09:44,130 --> 00:09:45,540
will utilize specific rule sets

299
00:09:45,540 --> 00:09:48,090
to prevent common attacks against web applications,

300
00:09:48,090 --> 00:09:49,860
including things like cross-site scripting

301
00:09:49,860 --> 00:09:51,510
and SQL Injections.

302
00:09:51,510 --> 00:09:53,850
Web Application Firewalls can also be installed

303
00:09:53,850 --> 00:09:56,430
as separate appliances or as a type of software plugin

304
00:09:56,430 --> 00:09:57,840
on your web server.

305
00:09:57,840 --> 00:10:00,600
This type of firewall can be either installed inline

306
00:10:00,600 --> 00:10:02,790
or out-of-band inside of your network.

307
00:10:02,790 --> 00:10:04,350
If it's going to be placed inline,

308
00:10:04,350 --> 00:10:06,690
the device is going to be placed between your network firewall

309
00:10:06,690 --> 00:10:08,490
and the web servers themself.

310
00:10:08,490 --> 00:10:10,350
By utilizing this inline placement,

311
00:10:10,350 --> 00:10:12,240
these devices can prevent live attacks,

312
00:10:12,240 --> 00:10:14,460
but they're also going to slow down your web traffic,

313
00:10:14,460 --> 00:10:17,490
and sometimes, they'll block legitimate traffic by mistake.

314
00:10:17,490 --> 00:10:19,830
Now, if it's placed in an out-of-band configuration,

315
00:10:19,830 --> 00:10:21,900
it's just going to receive a copy of all the traffic

316
00:10:21,900 --> 00:10:24,270
that was destined for your web server using a mirrored

317
00:10:24,270 --> 00:10:26,340
or SPAN port off of a switch.

318
00:10:26,340 --> 00:10:28,020
This is going to be a very non-intrusive way

319
00:10:28,020 --> 00:10:29,970
to conduct your web application filtering,

320
00:10:29,970 --> 00:10:31,290
but in this configuration,

321
00:10:31,290 --> 00:10:33,270
it cannot block live web traffic

322
00:10:33,270 --> 00:10:35,070
if you're using this configuration.

323
00:10:35,070 --> 00:10:37,950
Instead, it works more like an intrusion detection system

324
00:10:37,950 --> 00:10:39,750
because it sees all the information

325
00:10:39,750 --> 00:10:41,100
and it can then alert on it,

326
00:10:41,100 --> 00:10:44,130
but it can't actually block it if you're not inline.

327
00:10:44,130 --> 00:10:45,330
So as you can see,

328
00:10:45,330 --> 00:10:46,560
there are lots of different choices

329
00:10:46,560 --> 00:10:47,910
when it comes to firewalls

330
00:10:47,910 --> 00:10:49,530
when you're designing the network architecture

331
00:10:49,530 --> 00:10:50,880
for your organization.

332
00:10:50,880 --> 00:10:52,800
You can choose to use Layer 4 firewalls,

333
00:10:52,800 --> 00:10:54,060
Layer 7 firewalls,

334
00:10:54,060 --> 00:10:55,380
Next-Generation Firewalls,

335
00:10:55,380 --> 00:10:56,700
Unified Threat Management systems,

336
00:10:56,700 --> 00:10:58,110
and Web Application Firewalls,

337
00:10:58,110 --> 00:11:00,120
depending on your specific use case.

338
00:11:00,120 --> 00:11:01,980
A Layer 4 firewall is going to operate

339
00:11:01,980 --> 00:11:03,120
at the transport layer

340
00:11:03,120 --> 00:11:04,530
and make filtering decisions based

341
00:11:04,530 --> 00:11:06,180
on the information about port numbers

342
00:11:06,180 --> 00:11:08,790
and protocol data without inspecting the content

343
00:11:08,790 --> 00:11:10,620
of its individual data packets.

344
00:11:10,620 --> 00:11:12,330
A Layer 7 firewall, on the other hand,

345
00:11:12,330 --> 00:11:14,310
is also known as an application proxy

346
00:11:14,310 --> 00:11:15,810
or application firewall,

347
00:11:15,810 --> 00:11:17,670
and it operates at the application layer

348
00:11:17,670 --> 00:11:18,930
and can inspect, filter,

349
00:11:18,930 --> 00:11:20,910
and control traffic based on the content

350
00:11:20,910 --> 00:11:23,280
and characteristics of the data's payload.

351
00:11:23,280 --> 00:11:25,920
A Next-Generation Firewall or NGFW

352
00:11:25,920 --> 00:11:27,570
is an advanced security appliance

353
00:11:27,570 --> 00:11:29,640
that combines traditional firewall capabilities

354
00:11:29,640 --> 00:11:31,980
with additional features like intrusion detection,

355
00:11:31,980 --> 00:11:33,000
application awareness,

356
00:11:33,000 --> 00:11:34,830
and advanced threat protection.

357
00:11:34,830 --> 00:11:37,020
A Unified Threat Management Firewall, on the other hand,

358
00:11:37,020 --> 00:11:39,390
is a fully comprehensive security solution

359
00:11:39,390 --> 00:11:41,280
that integrates multiple security features,

360
00:11:41,280 --> 00:11:44,190
including firewalls, antivirus, intrusion detection,

361
00:11:44,190 --> 00:11:47,550
and content filtering into a single unified platform.

362
00:11:47,550 --> 00:11:50,370
And finally, we have a Web Application Firewall.

363
00:11:50,370 --> 00:11:51,990
A Web Application Firewall

364
00:11:51,990 --> 00:11:54,270
is going to be focused on the the inspection of traffic

365
00:11:54,270 --> 00:11:57,120
at the HTTP or HTTPS levels

366
00:11:57,120 --> 00:11:58,650
to be able to use specific rule sets

367
00:11:58,650 --> 00:12:01,260
to prevent common attacks against your web applications,

368
00:12:01,260 --> 00:12:04,230
including cross-site scripting and SQL Injections.

369
00:12:04,230 --> 00:12:06,150
So remember these different types of firewalls

370
00:12:06,150 --> 00:12:07,650
and what each one is going to be used for,

371
00:12:07,650 --> 00:12:10,300
so you'll be a successful cybersecurity practitioner.

