1
00:00:00,090 --> 00:00:01,650
In this lesson, we're going to learn

2
00:00:01,650 --> 00:00:03,570
how to configure firewalls.

3
00:00:03,570 --> 00:00:05,820
While routers can use access control lists to provide

4
00:00:05,820 --> 00:00:07,920
some protections and filtering for our networks,

5
00:00:07,920 --> 00:00:10,410
it's really that dedicated device known as a firewall

6
00:00:10,410 --> 00:00:12,840
that excels at using access control lists.

7
00:00:12,840 --> 00:00:14,970
Now, access control lists are very important for us

8
00:00:14,970 --> 00:00:17,490
to be able to secure our networks from unwanted traffic.

9
00:00:17,490 --> 00:00:18,840
A large portion of the permit

10
00:00:18,840 --> 00:00:20,404
and deny statements that we're going to utilize inside

11
00:00:20,404 --> 00:00:23,042
of our ACLs are going to be based on port numbers

12
00:00:23,042 --> 00:00:25,530
because those directly correlate with an application

13
00:00:25,530 --> 00:00:28,170
or service that we want to allow or block.

14
00:00:28,170 --> 00:00:30,990
An access control list, or ACL, is the rule set

15
00:00:30,990 --> 00:00:32,970
that's going to be placed on the firewall, router,

16
00:00:32,970 --> 00:00:35,550
or other network infrastructure devices that will permit

17
00:00:35,550 --> 00:00:38,430
or allow traffic through a particular interface.

18
00:00:38,430 --> 00:00:40,500
These rule sets are going to be used to control the flow

19
00:00:40,500 --> 00:00:42,930
of traffic into or out of our networks.

20
00:00:42,930 --> 00:00:45,090
Now, while access control lists can also be used

21
00:00:45,090 --> 00:00:47,040
to help define proper quality of service levels

22
00:00:47,040 --> 00:00:48,270
inside of our networks,

23
00:00:48,270 --> 00:00:49,975
in this lesson, we're really going to be focused

24
00:00:49,975 --> 00:00:52,500
on their crucial role in security of our networks

25
00:00:52,500 --> 00:00:54,630
and their use inside of firewalls.

26
00:00:54,630 --> 00:00:57,090
To configure the access control lists on our firewalls,

27
00:00:57,090 --> 00:00:59,130
we're either going to be using a web-based interface

28
00:00:59,130 --> 00:01:01,560
or a text-based command-line interface.

29
00:01:01,560 --> 00:01:04,110
When configuring these ACLs, it's always important

30
00:01:04,110 --> 00:01:06,210
to remember that the order in which they're listed

31
00:01:06,210 --> 00:01:08,400
will specify the order of the actions that are taken

32
00:01:08,400 --> 00:01:10,320
on a particular piece of traffic.

33
00:01:10,320 --> 00:01:13,020
Actions will always be performed in a top-down manner

34
00:01:13,020 --> 00:01:15,060
inside of an access control list.

35
00:01:15,060 --> 00:01:17,700
The traffic will first be compared against the first rule,

36
00:01:17,700 --> 00:01:19,440
and then if it matches the condition,

37
00:01:19,440 --> 00:01:20,790
the action will be applied

38
00:01:20,790 --> 00:01:23,580
and it will no longer perform the rest of the ACL.

39
00:01:23,580 --> 00:01:26,040
For this reason, we always use the specific rules

40
00:01:26,040 --> 00:01:28,320
at the top of the list and then the more generic rules

41
00:01:28,320 --> 00:01:29,790
towards the bottom of the list to give us

42
00:01:29,790 --> 00:01:31,650
the best levels of protection.

43
00:01:31,650 --> 00:01:33,101
Now, many devices will support the use

44
00:01:33,101 --> 00:01:36,540
of an implied deny function for their rule set too.

45
00:01:36,540 --> 00:01:39,000
Other devices though, will not support this function,

46
00:01:39,000 --> 00:01:40,320
and so it's considered a best practice

47
00:01:40,320 --> 00:01:43,740
to always include a deny all rule at the end of your ACL

48
00:01:43,740 --> 00:01:45,330
to ensure that only authorized traffic

49
00:01:45,330 --> 00:01:47,160
will be able to enter your network.

50
00:01:47,160 --> 00:01:49,470
Finally, it's important to log your actions taken

51
00:01:49,470 --> 00:01:52,230
by our network infrastructure devices like our firewalls.

52
00:01:52,230 --> 00:01:53,580
Anytime a rule condition is met

53
00:01:53,580 --> 00:01:56,220
from the access control list, the action should be taken

54
00:01:56,220 --> 00:01:58,170
and then that action should be logged.

55
00:01:58,170 --> 00:02:00,300
This includes any deny actions that are taken,

56
00:02:00,300 --> 00:02:03,285
including the deny all at the bottom of the ACL.

57
00:02:03,285 --> 00:02:05,550
Access control list rules are going to be made up

58
00:02:05,550 --> 00:02:07,200
of some key pieces of information,

59
00:02:07,200 --> 00:02:09,630
including the type of traffic, the source of traffic,

60
00:02:09,630 --> 00:02:10,979
the destination of the traffic,

61
00:02:10,979 --> 00:02:13,590
and the action that should be taken against that traffic.

62
00:02:13,590 --> 00:02:15,990
For example, this access control list

63
00:02:15,990 --> 00:02:17,460
has a first entry line here,

64
00:02:17,460 --> 00:02:19,890
stating that it's going to allow TCP traffic

65
00:02:19,890 --> 00:02:24,890
from 192.168.0.0 to any destination IP over port 22.

66
00:02:26,160 --> 00:02:28,260
Now, routers can provide basic security

67
00:02:28,260 --> 00:02:30,690
using these access control lists and filtering rules,

68
00:02:30,690 --> 00:02:32,580
but it is really our network firewalls

69
00:02:32,580 --> 00:02:34,920
that are most commonly going to be used for network security

70
00:02:34,920 --> 00:02:38,187
and bulk blocking and allowing using an access control list.

71
00:02:38,187 --> 00:02:40,320
So, now that we've covered the basics

72
00:02:40,320 --> 00:02:42,030
of what an access control list is,

73
00:02:42,030 --> 00:02:43,890
let's take a look at how we can configure

74
00:02:43,890 --> 00:02:46,800
a basic small office, home office hardware firewall,

75
00:02:46,800 --> 00:02:49,168
and then we'll configure a software firewall inside

76
00:02:49,168 --> 00:02:51,720
of the Windows or Mac OS systems.

77
00:02:51,720 --> 00:02:54,840
First, let's take a look at our hardware-based firewall.

78
00:02:54,840 --> 00:02:57,180
In this example, I'm going to use a typical router

79
00:02:57,180 --> 00:02:59,640
switch access point combination device

80
00:02:59,640 --> 00:03:01,140
manufactured by NETGEAR

81
00:03:01,140 --> 00:03:04,410
and marketed as a wireless router N300 model.

82
00:03:04,410 --> 00:03:05,850
Now, this is probably very similar

83
00:03:05,850 --> 00:03:07,980
to what most of you're using in your small office

84
00:03:07,980 --> 00:03:09,660
or home office environments.

85
00:03:09,660 --> 00:03:11,760
Your interface and settings on your firewall

86
00:03:11,760 --> 00:03:13,410
are going to look a little different than mine,

87
00:03:13,410 --> 00:03:15,540
but it's still going to give you the same general idea

88
00:03:15,540 --> 00:03:16,830
of what kind of options there are

89
00:03:16,830 --> 00:03:18,000
and how you can configure one

90
00:03:18,000 --> 00:03:20,850
of these firewalls at your network boundary.

91
00:03:20,850 --> 00:03:23,997
So, on the screen you can see the basic web-based access

92
00:03:23,997 --> 00:03:25,980
for this wireless router,

93
00:03:25,980 --> 00:03:28,470
wireless access point combination device.

94
00:03:28,470 --> 00:03:30,630
Now, on mine, I'm going to go to security,

95
00:03:30,630 --> 00:03:32,490
which is where the firewall is located,

96
00:03:32,490 --> 00:03:36,120
and it's under block services on this particular router.

97
00:03:36,120 --> 00:03:38,790
Now, usually most of these small office,

98
00:03:38,790 --> 00:03:41,970
home office routers are going to have a very weak type firewall

99
00:03:41,970 --> 00:03:43,860
and they hide it by calling it something else

100
00:03:43,860 --> 00:03:45,570
instead of calling it a firewall.

101
00:03:45,570 --> 00:03:48,030
So, it'll be called block sites, block services,

102
00:03:48,030 --> 00:03:50,070
block ports, something of that nature.

103
00:03:50,070 --> 00:03:51,930
So, in this case, it's block services

104
00:03:51,930 --> 00:03:54,450
and I can do it based on a schedule, so I only want it

105
00:03:54,450 --> 00:03:57,270
to be done at certain times of the day or always.

106
00:03:57,270 --> 00:03:59,280
Let's say I want to block something like Telnet,

107
00:03:59,280 --> 00:04:01,020
I'm going to always block it.

108
00:04:01,020 --> 00:04:02,640
I'm going to add a block,

109
00:04:02,640 --> 00:04:05,580
and the block I want to use is going to be a service

110
00:04:05,580 --> 00:04:07,410
and go down to Telnet.

111
00:04:07,410 --> 00:04:10,200
Now, it automatically knows that Telnet is port 23,

112
00:04:10,200 --> 00:04:12,270
so it's going to block port 23 for me.

113
00:04:12,270 --> 00:04:15,000
It's called Telnet because this is a predefined one,

114
00:04:15,000 --> 00:04:17,680
and then I can block it for all IP addresses in this network

115
00:04:17,680 --> 00:04:21,269
or only certain IP addresses or a certain range.

116
00:04:21,269 --> 00:04:23,610
So, maybe I want to block it for everything for Telnet.

117
00:04:23,610 --> 00:04:26,220
That's fine, we can go ahead and add that to our list.

118
00:04:26,220 --> 00:04:27,480
Now, if we want to add something else,

119
00:04:27,480 --> 00:04:28,920
let's say I have another rule.

120
00:04:28,920 --> 00:04:31,710
In this case, I want to block port 666

121
00:04:31,710 --> 00:04:32,790
because maybe there's a game

122
00:04:32,790 --> 00:04:34,560
I don't want my kids playing on that.

123
00:04:34,560 --> 00:04:36,750
So, I'll block it as port 666.

124
00:04:36,750 --> 00:04:38,940
I'm going to make it TCP/UDP, or both.

125
00:04:38,940 --> 00:04:40,259
I'm going to say both in this case

126
00:04:40,259 --> 00:04:42,930
and I'm just going to call it game,

127
00:04:42,930 --> 00:04:45,150
and then I can block it for an IP range.

128
00:04:45,150 --> 00:04:48,030
Maybe I don't want it to be accessed by my kids,

129
00:04:48,030 --> 00:04:51,540
which all have their devices in the 10.0.0.2

130
00:04:51,540 --> 00:04:53,940
and 10.0.0.10 range.

131
00:04:53,940 --> 00:04:56,040
If I do that, I can go ahead and add,

132
00:04:56,040 --> 00:04:58,620
and again, that adds another rule to the firewall

133
00:04:58,620 --> 00:05:03,620
where we are blocking port 666 over that range of IPs,

134
00:05:03,900 --> 00:05:05,730
and you can see how this works as you can add

135
00:05:05,730 --> 00:05:07,560
or delete different rules.

136
00:05:07,560 --> 00:05:09,150
And then I can go through and I can do another one.

137
00:05:09,150 --> 00:05:14,150
Let's say I want to block the FTP server.

138
00:05:14,280 --> 00:05:15,630
So, I will just go through here

139
00:05:15,630 --> 00:05:19,290
and say user defined port 20 through port 21

140
00:05:19,290 --> 00:05:21,720
because that is the connection port

141
00:05:21,720 --> 00:05:23,910
and the data ports for FTP,

142
00:05:23,910 --> 00:05:26,575
and then we'll give it a name of FTP,

143
00:05:26,575 --> 00:05:29,910
and we can do it for all IP addresses in this range

144
00:05:29,910 --> 00:05:32,430
so nobody can access FTP servers.

145
00:05:32,430 --> 00:05:34,980
That's the idea of how this firewall works.

146
00:05:34,980 --> 00:05:36,480
And you can do it, in this case,

147
00:05:36,480 --> 00:05:38,790
it's blocking the outbound connections

148
00:05:38,790 --> 00:05:40,560
because it's preventing us from sending

149
00:05:40,560 --> 00:05:42,570
things out to the internet.

150
00:05:42,570 --> 00:05:44,640
Now, if we want to block things from coming in

151
00:05:44,640 --> 00:05:46,380
from the internet, we're going to have to do

152
00:05:46,380 --> 00:05:49,290
that in a different firewall on this particular device

153
00:05:49,290 --> 00:05:53,220
because this one only has the outbound defined here,

154
00:05:53,220 --> 00:05:54,870
it's going to have what things

155
00:05:54,870 --> 00:05:57,360
as it's going out to the internet.

156
00:05:57,360 --> 00:06:00,030
Now, if I want to do this on inbound stuff,

157
00:06:00,030 --> 00:06:02,880
I would have to go and find that in this particular router.

158
00:06:02,880 --> 00:06:04,860
That's usually going to be something like port forwarding

159
00:06:04,860 --> 00:06:08,190
or port triggering, or something like a static route.

160
00:06:08,190 --> 00:06:11,010
And so in this case, I can port forward or port trigger

161
00:06:11,010 --> 00:06:12,810
and say, hey, if something's trying to come in

162
00:06:12,810 --> 00:06:17,810
on port 21, FTP, it can go and be routed to my server,

163
00:06:17,910 --> 00:06:21,660
which is at the .50 for instance.

164
00:06:21,660 --> 00:06:24,000
And so now, anything that comes in that's trying to get

165
00:06:24,000 --> 00:06:27,990
to this router on port 21 is going to be forwarded over

166
00:06:27,990 --> 00:06:30,240
to that IP address of .50.

167
00:06:30,240 --> 00:06:32,466
So, that's how you allow things in to your network

168
00:06:32,466 --> 00:06:35,130
based on this particular firewall.

169
00:06:35,130 --> 00:06:37,410
Now, how do you block things at the firewall?

170
00:06:37,410 --> 00:06:39,990
Well, in this particular router, everything is blocked

171
00:06:39,990 --> 00:06:42,750
by default because it's doing an implicit deny.

172
00:06:42,750 --> 00:06:45,270
So, anytime I add a rule like FTP here,

173
00:06:45,270 --> 00:06:47,760
that's doing an explicit allow,

174
00:06:47,760 --> 00:06:49,980
and so, anything you don't allow is going to be blocked

175
00:06:49,980 --> 00:06:53,400
by default on the inbound based on this particular router.

176
00:06:53,400 --> 00:06:55,320
Now, let's take a look at how we can configure

177
00:06:55,320 --> 00:06:57,720
the software firewall included inside the Windows

178
00:06:57,720 --> 00:07:00,090
operating system, known as Windows Defender Firewall

179
00:07:00,090 --> 00:07:01,650
with Advanced Security.

180
00:07:01,650 --> 00:07:04,410
To load this up, simply go down to your Windows key

181
00:07:04,410 --> 00:07:07,019
or your start menu, scroll all the way down

182
00:07:07,019 --> 00:07:10,320
to where you see Windows administrative tools

183
00:07:10,320 --> 00:07:11,760
and then scroll down again,

184
00:07:11,760 --> 00:07:14,130
once you click on that and you will find

185
00:07:14,130 --> 00:07:16,780
the Windows Defender Firewall with Advanced Security.

186
00:07:17,790 --> 00:07:20,220
Once you click on that, it will open.

187
00:07:20,220 --> 00:07:23,010
From here, you can create all of the policies you want,

188
00:07:23,010 --> 00:07:25,620
setting up inbound rules, outbound rules,

189
00:07:25,620 --> 00:07:27,480
monitoring it, et cetera.

190
00:07:27,480 --> 00:07:29,430
Once you have it set just the way you like,

191
00:07:29,430 --> 00:07:32,100
you can actually export that policy, so you'll have it

192
00:07:32,100 --> 00:07:34,920
as a backup anytime you need to go back to it.

193
00:07:34,920 --> 00:07:37,380
Right now, you can see my domain profile

194
00:07:37,380 --> 00:07:40,140
shows Windows Defender Firewall is off.

195
00:07:40,140 --> 00:07:42,630
My private profile shows that it's on,

196
00:07:42,630 --> 00:07:45,120
and my public profile shows that it's on.

197
00:07:45,120 --> 00:07:47,760
What this means is that in my private network

198
00:07:47,760 --> 00:07:48,810
and my public network,

199
00:07:48,810 --> 00:07:51,210
I do have the Windows Firewall turned on.

200
00:07:51,210 --> 00:07:53,490
In the private network, I don't allow

201
00:07:53,490 --> 00:07:55,933
any inbound connections that don't match my rules,

202
00:07:55,933 --> 00:07:58,020
but I will allow outbound connections

203
00:07:58,020 --> 00:07:59,700
that don't match my rules.

204
00:07:59,700 --> 00:08:02,880
In my public network, I have it set the exact same way.

205
00:08:02,880 --> 00:08:04,710
Now, if I want to change that,

206
00:08:04,710 --> 00:08:07,620
I can go into my inbound rules or my outbound rules

207
00:08:07,620 --> 00:08:09,750
and decide how I want that to be done.

208
00:08:09,750 --> 00:08:11,940
Let's take a look at some of these rules.

209
00:08:11,940 --> 00:08:15,060
For example, we have this one here, which is SSH,

210
00:08:15,060 --> 00:08:16,830
which is Secure Shell.

211
00:08:16,830 --> 00:08:18,570
All of my profiles allow it.

212
00:08:18,570 --> 00:08:19,955
It's enabled for all of them.

213
00:08:19,955 --> 00:08:22,110
It will do an allow action,

214
00:08:22,110 --> 00:08:23,700
and it's going to allow any program

215
00:08:23,700 --> 00:08:25,950
to be run from any address locally

216
00:08:25,950 --> 00:08:29,538
to any address remotely over port 22.

217
00:08:29,538 --> 00:08:30,982
That may be what you want to do,

218
00:08:30,982 --> 00:08:33,659
or it may be something you want to block.

219
00:08:33,659 --> 00:08:35,789
Let's go ahead and look at some other ones.

220
00:08:35,789 --> 00:08:37,530
Down here we have app installer.

221
00:08:37,530 --> 00:08:41,880
For app installer, it's allowing it to go any local address

222
00:08:41,880 --> 00:08:45,431
to any remote address, any protocol, and any port.

223
00:08:45,431 --> 00:08:48,450
This type of an any, any rule allows it to have a lot

224
00:08:48,450 --> 00:08:50,340
of ability, and so this is going to allow

225
00:08:50,340 --> 00:08:53,500
a lot of things through that we might not want.

226
00:08:53,500 --> 00:08:55,170
Now, let's say you have a program

227
00:08:55,170 --> 00:08:56,430
that you want to add to this.

228
00:08:56,430 --> 00:08:58,200
Maybe you have a new web server on this,

229
00:08:58,200 --> 00:09:00,150
and you're going to run it on port 80.

230
00:09:00,150 --> 00:09:01,890
You can hit new.

231
00:09:01,890 --> 00:09:04,740
You can then select a program, a port,

232
00:09:04,740 --> 00:09:06,780
a predefined, or a custom.

233
00:09:06,780 --> 00:09:08,340
In this case, if it's a web server,

234
00:09:08,340 --> 00:09:10,800
we would want to do it based on port 80.

235
00:09:10,800 --> 00:09:12,056
Then we'll click on next.

236
00:09:12,056 --> 00:09:15,480
Do we want it for TCP traffic or UDP traffic?

237
00:09:15,480 --> 00:09:17,940
If it's a web server, again, it's TCP.

238
00:09:17,940 --> 00:09:19,590
It's something else that might use UDP,

239
00:09:19,590 --> 00:09:21,660
you could set that up, and then what ports

240
00:09:21,660 --> 00:09:22,890
is that going to work for?

241
00:09:22,890 --> 00:09:25,560
For all of your local ports or specific ports?

242
00:09:25,560 --> 00:09:28,890
Well, if it's a web server, it again should be port 80

243
00:09:28,890 --> 00:09:31,083
and for secure, port 443.

244
00:09:31,980 --> 00:09:33,259
Then we can go next.

245
00:09:33,259 --> 00:09:35,160
We can allow that connection.

246
00:09:35,160 --> 00:09:37,020
We can allow the connection if it's secure,

247
00:09:37,020 --> 00:09:38,070
meaning that it has to use something

248
00:09:38,070 --> 00:09:40,290
like a VPN tunnel with IPSec,

249
00:09:40,290 --> 00:09:41,790
or we can block the connection

250
00:09:41,790 --> 00:09:43,710
and not allow any web traffic in.

251
00:09:43,710 --> 00:09:46,440
In our case, we want to allow the connection.

252
00:09:46,440 --> 00:09:48,600
Then we click on next, and you can see

253
00:09:48,600 --> 00:09:50,640
which of those three networks it's going to apply to.

254
00:09:50,640 --> 00:09:53,490
I'm going to allow all three of them to have it applied to it,

255
00:09:53,490 --> 00:09:55,770
and then I'll give it a rule.

256
00:09:55,770 --> 00:09:56,973
Jason's web server,

257
00:09:59,370 --> 00:10:00,203
and that's it.

258
00:10:00,203 --> 00:10:02,670
Now, you can see that Jason's web server is now going to allow

259
00:10:02,670 --> 00:10:06,420
traffic from any program from any local address

260
00:10:06,420 --> 00:10:08,947
and any remote address over protocol TCP

261
00:10:08,947 --> 00:10:12,030
and on port 80 and 443.

262
00:10:12,030 --> 00:10:15,870
Now, conversely, if I want to block things from getting in,

263
00:10:15,870 --> 00:10:18,150
we would do the exact same thing, except we would set it up

264
00:10:18,150 --> 00:10:19,980
as a block or a deny.

265
00:10:19,980 --> 00:10:22,950
For example, I don't want to allow anybody to do Telnet

266
00:10:22,950 --> 00:10:25,770
into my network because Telnet is unsecure.

267
00:10:25,770 --> 00:10:27,930
So, I would set up a new rule,

268
00:10:27,930 --> 00:10:31,170
and from there I can block anything on port 23,

269
00:10:31,170 --> 00:10:35,790
which is TCP traffic on port 23, and then I'll hit next.

270
00:10:35,790 --> 00:10:37,620
I'll block that connection,

271
00:10:37,620 --> 00:10:40,140
and I'll block it for all three of those networks,

272
00:10:40,140 --> 00:10:42,183
and I'm going to say blocking Telnet.

273
00:10:44,670 --> 00:10:45,503
And that's it.

274
00:10:45,503 --> 00:10:48,090
You could see how easy it's to set up these rules.

275
00:10:48,090 --> 00:10:49,500
For the Security Plus exam,

276
00:10:49,500 --> 00:10:50,970
you should feel very comfortable

277
00:10:50,970 --> 00:10:52,740
with setting up these type of rules.

278
00:10:52,740 --> 00:10:56,640
If somebody says, I want to block TCP on port 23,

279
00:10:56,640 --> 00:10:58,890
or I want to block Telnet, then you should be able to say,

280
00:10:58,890 --> 00:11:02,580
I want to block it from this area and let it go to that area.

281
00:11:02,580 --> 00:11:04,410
Now, one more area of the Windows firewall

282
00:11:04,410 --> 00:11:06,960
that I want to show you is down here in monitoring.

283
00:11:06,960 --> 00:11:09,420
Down in monitoring, you can see which profile is active,

284
00:11:09,420 --> 00:11:11,730
as I showed you before, but you also have access

285
00:11:11,730 --> 00:11:13,500
to the log file, and if you click on that,

286
00:11:13,500 --> 00:11:15,810
you'll be able to see what's currently there.

287
00:11:15,810 --> 00:11:17,070
What is being logged right now?

288
00:11:17,070 --> 00:11:19,770
Is it logging drop packets and successful connections?

289
00:11:19,770 --> 00:11:22,981
Right now it's not, but we can change that if we wanted to.

290
00:11:22,981 --> 00:11:26,400
Now, we can also view our active rules.

291
00:11:26,400 --> 00:11:29,190
This again, brings us back to what those inbound rules are

292
00:11:29,190 --> 00:11:32,400
and seeing which ones are actually active on this profile.

293
00:11:32,400 --> 00:11:33,900
So, you'll notice anything that's all

294
00:11:33,900 --> 00:11:35,820
or public is being shown here.

295
00:11:35,820 --> 00:11:39,120
Anything that was just private or domain is not

296
00:11:39,120 --> 00:11:42,060
because they're not active for this particular connection.

297
00:11:42,060 --> 00:11:44,832
Next, we're going to configure a firewall on a Mac machine.

298
00:11:44,832 --> 00:11:48,150
To do that, simply go to the Apple in the upper left corner

299
00:11:48,150 --> 00:11:49,920
and go to system preferences.

300
00:11:49,920 --> 00:11:53,520
From here, you're going to click security and privacy,

301
00:11:53,520 --> 00:11:56,220
and then you're going to click on the firewall tab.

302
00:11:56,220 --> 00:11:58,590
You can notice that my firewall is on,

303
00:11:58,590 --> 00:12:01,290
but I can't click any of the firewall options right now.

304
00:12:01,290 --> 00:12:03,990
That's because you have to unlock it by clicking the lock

305
00:12:03,990 --> 00:12:07,023
and adding your username and password for the admin account.

306
00:12:08,940 --> 00:12:11,330
Once you do that, you can turn off your firewall

307
00:12:11,330 --> 00:12:12,930
or you can turn on your firewall,

308
00:12:12,930 --> 00:12:15,540
and you can configure the options.

309
00:12:15,540 --> 00:12:18,065
In here, you can block all incoming connections.

310
00:12:18,065 --> 00:12:20,160
You can see what applications

311
00:12:20,160 --> 00:12:21,510
have been allowed through the firewall.

312
00:12:21,510 --> 00:12:24,240
In my case, Skype and Google Drive are allowed

313
00:12:24,240 --> 00:12:26,400
to have connections into my computer,

314
00:12:26,400 --> 00:12:29,160
and then you can automatically allow built-in software,

315
00:12:29,160 --> 00:12:31,860
meaning Apple software, to receive incoming connections,

316
00:12:31,860 --> 00:12:33,761
things like iTunes and iMessage,

317
00:12:33,761 --> 00:12:36,840
and you can automatically allow downloaded sign software

318
00:12:36,840 --> 00:12:38,460
to receive incoming connections,

319
00:12:38,460 --> 00:12:40,410
meaning this is software that you trust.

320
00:12:40,410 --> 00:12:42,135
And finally, we have stealth mode.

321
00:12:42,135 --> 00:12:44,910
What stealth mode does is it makes your firewall

322
00:12:44,910 --> 00:12:47,940
not respond and not acknowledge any attempts

323
00:12:47,940 --> 00:12:49,800
from somebody to ping your network.

324
00:12:49,800 --> 00:12:51,780
So, if somebody is doing a ping sweep of your network,

325
00:12:51,780 --> 00:12:54,150
my computer is simply not even going to answer,

326
00:12:54,150 --> 00:12:56,880
so you won't know if it's up, down or even there.

327
00:12:56,880 --> 00:12:59,160
So, how do we add an application to this list

328
00:12:59,160 --> 00:13:00,960
to allow incoming connections?

329
00:13:00,960 --> 00:13:03,030
Well, Mac makes it fairly easy.

330
00:13:03,030 --> 00:13:06,060
You click on the plus sign, you find the application,

331
00:13:06,060 --> 00:13:09,720
for example, my chess application, and then hit add.

332
00:13:09,720 --> 00:13:12,090
When you do that, it by default is going to allow

333
00:13:12,090 --> 00:13:13,560
incoming connections.

334
00:13:13,560 --> 00:13:15,060
Now, if I don't want that anymore,

335
00:13:15,060 --> 00:13:17,340
I could simply click on it and subtract it

336
00:13:17,340 --> 00:13:19,290
and it won't answer up.

337
00:13:19,290 --> 00:13:21,840
As you can see, you don't have the level of fidelity

338
00:13:21,840 --> 00:13:25,230
that you have on a Windows machine here in a Mac machine.

339
00:13:25,230 --> 00:13:27,390
To get that level of fidelity, you'd have to use

340
00:13:27,390 --> 00:13:30,090
the command-line firewall tools that are provided,

341
00:13:30,090 --> 00:13:32,940
such as PF or IPFW.

342
00:13:32,940 --> 00:13:35,790
So remember, when it comes to firewall configuration,

343
00:13:35,790 --> 00:13:38,160
you can utilize either a hardware-based firewall

344
00:13:38,160 --> 00:13:40,050
that will protect all the workstations connected

345
00:13:40,050 --> 00:13:42,990
to a firewall subnet, or you can use an individual

346
00:13:42,990 --> 00:13:45,450
software-based firewall on the workstation itself

347
00:13:45,450 --> 00:13:48,030
within Windows, Mac OS, or in Linux.

348
00:13:48,030 --> 00:13:49,890
Either way, the protections that your firewall

349
00:13:49,890 --> 00:13:51,510
will provide is all going to be based

350
00:13:51,510 --> 00:13:53,220
on the access control list and the rules

351
00:13:53,220 --> 00:13:55,720
that you configure when setting up your firewalls.

