1
00:00:06,600 --> 00:00:09,780
- As promised, this lesson, lesson 11.3,

2
00:00:09,780 --> 00:00:11,603
is gonna be all about firewalls.

3
00:00:11,603 --> 00:00:14,520
So let's think about
firewalls as a control, right?

4
00:00:14,520 --> 00:00:17,090
The primary objective of
a traditional firewall

5
00:00:17,090 --> 00:00:20,220
is to isolate network segments and traffic

6
00:00:20,220 --> 00:00:24,290
by controlling ingress incoming
and egress outgoing access.

7
00:00:24,290 --> 00:00:27,900
But various types of firewalls
incorporate additional

8
00:00:27,900 --> 00:00:30,630
and or specialized features
and functionalities.

9
00:00:30,630 --> 00:00:31,830
So we're gonna be exploring those

10
00:00:31,830 --> 00:00:33,330
different types of firewalls

11
00:00:33,330 --> 00:00:35,670
and what else they bring to the table.

12
00:00:35,670 --> 00:00:39,060
But thinking about firewall
as a control itself, right?

13
00:00:39,060 --> 00:00:41,727
Firewalls can be a deterrent control

14
00:00:41,727 --> 00:00:43,290
because a hardened appearance

15
00:00:43,290 --> 00:00:46,230
can discourage opportunistic attackers.

16
00:00:46,230 --> 00:00:48,202
Firewalls are a preventative control

17
00:00:48,202 --> 00:00:49,800
because they can be configured

18
00:00:49,800 --> 00:00:52,440
to restrict ingress and egress traffic

19
00:00:52,440 --> 00:00:54,930
and firewalls are a detective control

20
00:00:54,930 --> 00:00:57,162
because they can be
configured to log events

21
00:00:57,162 --> 00:00:59,103
and to send alerts.

22
00:01:01,410 --> 00:01:03,960
Well, before we start
talking about the firewalls,

23
00:01:03,960 --> 00:01:06,000
the different types, we have to stop

24
00:01:06,000 --> 00:01:07,784
and talk about the OSI model.

25
00:01:07,784 --> 00:01:09,720
Now, the OSI model is the

26
00:01:09,720 --> 00:01:12,510
open systems interconnection
reference model,

27
00:01:12,510 --> 00:01:14,700
which is structured into seven layers.

28
00:01:14,700 --> 00:01:16,170
It's really a network model

29
00:01:16,170 --> 00:01:18,690
that describes layers of communication.

30
00:01:18,690 --> 00:01:20,940
And I think I hear some of
you groaning thinking, really,

31
00:01:20,940 --> 00:01:24,240
I didn't think I'd ever have
to study the OSI model again.

32
00:01:24,240 --> 00:01:25,211
Well, yes, you do.

33
00:01:25,211 --> 00:01:28,410
There are seven layers in the OSI model,

34
00:01:28,410 --> 00:01:30,240
starting down at the
bottom with layer one,

35
00:01:30,240 --> 00:01:32,460
the physical layer, layer two, data link,

36
00:01:32,460 --> 00:01:34,980
layer three, network,
layer four, transport,

37
00:01:34,980 --> 00:01:37,680
layer five, session,
layer six, presentation,

38
00:01:37,680 --> 00:01:40,560
and then layer seven, application.

39
00:01:40,560 --> 00:01:42,240
So we're gonna talk a
little bit more about

40
00:01:42,240 --> 00:01:43,950
what's at each of these layers.

41
00:01:43,950 --> 00:01:45,420
And the reason we're doing it is

42
00:01:45,420 --> 00:01:46,710
because different firewalls

43
00:01:46,710 --> 00:01:50,400
operate at different
layers of the OSI model.

44
00:01:50,400 --> 00:01:53,220
So firewalls might operate
at layer three, right?

45
00:01:53,220 --> 00:01:54,570
Being the network layer,

46
00:01:54,570 --> 00:01:56,797
at layer four, being the transport layer

47
00:01:56,797 --> 00:01:59,670
or up at a layer seven,
the application layer

48
00:01:59,670 --> 00:02:01,935
and depending on what
layer they operate in,

49
00:02:01,935 --> 00:02:05,463
means there's different
functionalities they can offer.

50
00:02:06,900 --> 00:02:09,060
So let's go through that OSI model,

51
00:02:09,060 --> 00:02:12,090
starting with layer
one, the physical layer,

52
00:02:12,090 --> 00:02:13,620
that's down at the bottom, right?

53
00:02:13,620 --> 00:02:16,411
The physical layer is often
called the hardware layer.

54
00:02:16,411 --> 00:02:19,440
That's a layer responsible
for our electrical

55
00:02:19,440 --> 00:02:21,926
and light and radio signals.

56
00:02:21,926 --> 00:02:25,080
Then we get up to layer two,
that's a data link layer

57
00:02:25,080 --> 00:02:27,264
and that's a layer that is
responsible for encoding

58
00:02:27,264 --> 00:02:31,020
and decoding those
electrical signals into bits.

59
00:02:31,020 --> 00:02:32,550
Now we have two sublayers there.

60
00:02:32,550 --> 00:02:35,550
We have the MAC sublayer,
the media access control

61
00:02:35,550 --> 00:02:37,440
and the logical link layer.

62
00:02:37,440 --> 00:02:39,960
Now, the MAC access control layer

63
00:02:39,960 --> 00:02:42,960
is responsible for really identifying

64
00:02:42,960 --> 00:02:44,490
that the network device,

65
00:02:44,490 --> 00:02:46,380
remember we said that every network device

66
00:02:46,380 --> 00:02:48,464
has a unique MAC address,

67
00:02:48,464 --> 00:02:52,263
where the logical link layer
does a lot of error correction.

68
00:02:53,310 --> 00:02:55,590
Going up to layer three,
the network layer,

69
00:02:55,590 --> 00:02:58,923
that's a layer that's responsible
for switching and routing.

70
00:02:59,999 --> 00:03:01,427
Layer four is responsible

71
00:03:01,427 --> 00:03:06,330
for the transparent transfer
of data between end systems,

72
00:03:06,330 --> 00:03:09,210
also responsible for
end-to-end error recovery

73
00:03:09,210 --> 00:03:10,800
and flow control.

74
00:03:10,800 --> 00:03:13,560
We go up to layer five,
which is our session layer

75
00:03:13,560 --> 00:03:17,130
and that's a layer
responsible for establishment,

76
00:03:17,130 --> 00:03:19,770
management and termination of connections

77
00:03:19,770 --> 00:03:21,870
between applications.

78
00:03:21,870 --> 00:03:24,480
Moving up to layer six,
the presentation layer,

79
00:03:24,480 --> 00:03:27,300
that's a layer responsible for
what you see on your screen.

80
00:03:27,300 --> 00:03:29,329
So the onscreen data representation,

81
00:03:29,329 --> 00:03:32,820
as well as encryption and decryption.

82
00:03:32,820 --> 00:03:35,400
And then we get up to
the application layer

83
00:03:35,400 --> 00:03:38,130
or layer seven, and
that's where applications

84
00:03:38,130 --> 00:03:41,978
and end user processes, as
well as QOS, quality of service

85
00:03:41,978 --> 00:03:44,223
and network services are supported.

86
00:03:47,040 --> 00:03:49,110
So we're gonna talk about
different types of firewalls

87
00:03:49,110 --> 00:03:51,690
and we'll keep referring
back to that OSI model,

88
00:03:51,690 --> 00:03:54,150
as to what layer they operate at.

89
00:03:54,150 --> 00:03:57,480
So our first two are stateless
and stateful firewalls,

90
00:03:57,480 --> 00:03:58,313
and these are probably the two

91
00:03:58,313 --> 00:03:59,840
that you're most familiar with.

92
00:04:00,750 --> 00:04:02,760
A stateless firewall is
also referred to as a

93
00:04:02,760 --> 00:04:04,167
packet filtering firewall.

94
00:04:04,167 --> 00:04:05,970
The packet filtering firewalls

95
00:04:05,970 --> 00:04:08,910
inspect each and every packet individually

96
00:04:08,910 --> 00:04:11,390
and they decide whether
a packet is allowed

97
00:04:11,390 --> 00:04:14,580
or denied based on the header information.

98
00:04:14,580 --> 00:04:16,277
So what do we find in
the header information?

99
00:04:16,277 --> 00:04:21,277
Protocol, source IP,
destination IP, and the port.

100
00:04:22,442 --> 00:04:24,450
Now packet filtering firewalls

101
00:04:24,450 --> 00:04:27,810
are gonna operate at the
network layer of the OSI model,

102
00:04:27,810 --> 00:04:29,191
so at layer three.

103
00:04:29,191 --> 00:04:32,400
Our use case for a stateless
packet filtering firewall,

104
00:04:32,400 --> 00:04:34,830
while they're fast, they're efficient,

105
00:04:34,830 --> 00:04:38,343
they're low resource utilization,
and they're low cost.

106
00:04:39,870 --> 00:04:42,810
But next up, kind of going
up the stack of complexity

107
00:04:42,810 --> 00:04:44,368
and cost, is stateful.

108
00:04:44,368 --> 00:04:47,143
Now, a stateful firewall
is gonna inspect the header

109
00:04:47,143 --> 00:04:48,839
and the packet payload,

110
00:04:48,839 --> 00:04:52,560
and keeps track of the entire
state of the connection

111
00:04:52,560 --> 00:04:54,182
from start to end.

112
00:04:54,182 --> 00:04:57,090
The stateful firewalls are
going to filter packets

113
00:04:57,090 --> 00:05:01,470
based on the full context of
the given network connection.

114
00:05:01,470 --> 00:05:04,380
Stateful firewalls operate
at the transport layer

115
00:05:04,380 --> 00:05:05,460
of the OSI model.

116
00:05:05,460 --> 00:05:08,430
So they operate at layer
four, our use case,

117
00:05:08,430 --> 00:05:11,190
when we might need some
more granular control,

118
00:05:11,190 --> 00:05:12,780
then we could get from that stateless

119
00:05:12,780 --> 00:05:14,343
or packet filtering firewall.

120
00:05:16,980 --> 00:05:20,040
Then we wanna move into
even more complex firewalls.

121
00:05:20,040 --> 00:05:22,770
And the two we're gonna
look at are next generation,

122
00:05:22,770 --> 00:05:27,770
NGFW firewalls and unified
threat management or UTM devices.

123
00:05:29,564 --> 00:05:33,450
The NextGen firewalls
inspect the entire packet

124
00:05:33,450 --> 00:05:34,950
and they can do surface level

125
00:05:34,950 --> 00:05:36,990
and really deep packet inspection

126
00:05:36,990 --> 00:05:38,580
and they're gonna incorporate

127
00:05:38,580 --> 00:05:40,950
a whole bunch of additional
security features

128
00:05:40,950 --> 00:05:42,576
and application controls.

129
00:05:42,576 --> 00:05:46,040
The NextGen firewalls operate
at the application layer

130
00:05:46,040 --> 00:05:49,125
of the OSI model, up at layer seven.

131
00:05:49,125 --> 00:05:50,610
Now, here's the caveat

132
00:05:50,610 --> 00:05:52,860
when you're looking at
next generation firewalls,

133
00:05:52,860 --> 00:05:54,615
there is no standard right now

134
00:05:54,615 --> 00:05:57,450
as to what the additional
security features

135
00:05:57,450 --> 00:05:59,190
or application controls are.

136
00:05:59,190 --> 00:06:02,070
So when you're comparing
one next generation firewall

137
00:06:02,070 --> 00:06:03,330
to another, you know,

138
00:06:03,330 --> 00:06:05,760
don't just assume it's an
apples to apples comparison.

139
00:06:05,760 --> 00:06:07,680
It could be apples to
oranges easily, right?

140
00:06:07,680 --> 00:06:09,660
You really wanna take a look
at what are those features

141
00:06:09,660 --> 00:06:10,757
that are being offered.

142
00:06:10,757 --> 00:06:12,150
But what's our use case,

143
00:06:12,150 --> 00:06:14,310
for next generation or NextGen firewall?

144
00:06:14,310 --> 00:06:16,200
Well, suitable for businesses

145
00:06:16,200 --> 00:06:18,870
that have compliance
requirements like PCI DSS,

146
00:06:18,870 --> 00:06:21,510
it's a payment card industry
data security standard

147
00:06:21,510 --> 00:06:23,883
or just need a very high
level of protection.

148
00:06:29,190 --> 00:06:32,700
Then we have a UTM, a UTM,
unified threat management

149
00:06:32,700 --> 00:06:35,220
is really the evolution of a firewall

150
00:06:35,220 --> 00:06:37,151
into a more all-inclusive device

151
00:06:37,151 --> 00:06:39,751
that can do multiple security functions.

152
00:06:39,751 --> 00:06:42,780
Now, it depends right, on the
UTM, what it actually does,

153
00:06:42,780 --> 00:06:44,730
but it might be a firewall and a gateway.

154
00:06:44,730 --> 00:06:47,160
It might also have anti-malware, right?

155
00:06:47,160 --> 00:06:49,860
It may also be able to do spam filtering.

156
00:06:49,860 --> 00:06:51,660
So really we're talking about UTM,

157
00:06:51,660 --> 00:06:53,850
we're saying, let's take one device

158
00:06:53,850 --> 00:06:55,485
and have it do multiple things.

159
00:06:55,485 --> 00:06:58,650
Now, UTMs generally
operate at multiple layers

160
00:06:58,650 --> 00:07:00,630
of the OSI model, depending
on what it's offering.

161
00:07:00,630 --> 00:07:03,570
Could be layer three, layer
four, and layer seven.

162
00:07:03,570 --> 00:07:05,340
Advantages of a UTM,

163
00:07:05,340 --> 00:07:07,973
well, we have reduced
operational complexity, right?

164
00:07:07,973 --> 00:07:09,810
'Cause we only have one
device instead of maybe three,

165
00:07:09,810 --> 00:07:12,810
four, or five, and overhead cost,

166
00:07:12,810 --> 00:07:14,850
but our disadvantage, well, number one,

167
00:07:14,850 --> 00:07:17,040
is going to be a single
point of failure, right?

168
00:07:17,040 --> 00:07:19,290
If we lost that device,
well then we would lose

169
00:07:19,290 --> 00:07:21,780
all of those associated services,

170
00:07:21,780 --> 00:07:24,030
as well as vendor dependency, right?

171
00:07:24,030 --> 00:07:26,430
If it's one vendor that's doing all those

172
00:07:26,430 --> 00:07:28,320
and we have a problem with
the vendor of any kind,

173
00:07:28,320 --> 00:07:29,870
well, we're kind of outta luck.

174
00:07:32,460 --> 00:07:35,400
And then we have some more
specialized firewalls.

175
00:07:35,400 --> 00:07:38,943
We have web application
firewalls and virtual firewalls.

176
00:07:39,780 --> 00:07:43,080
A web application firewall,
sometimes referred to as a WAF,

177
00:07:43,080 --> 00:07:45,480
inspects and protects web applications

178
00:07:45,480 --> 00:07:47,970
from malicious attacks, such
as cross-site scripting.

179
00:07:47,970 --> 00:07:49,710
We talked about that earlier,

180
00:07:49,710 --> 00:07:52,350
and SQL injection, we also
looked at that one earlier.

181
00:07:52,350 --> 00:07:55,783
And it works by analyzing
incoming HTTP traffic

182
00:07:55,783 --> 00:07:59,190
to a web application and
attempting to filter out

183
00:07:59,190 --> 00:08:02,730
any malicious traffic before
it reaches the application.

184
00:08:02,730 --> 00:08:05,460
Now, WAFs typically operate
at the application layer

185
00:08:05,460 --> 00:08:06,510
of the OSI model.

186
00:08:06,510 --> 00:08:09,210
So up at layer seven, which
allows them to inspect

187
00:08:09,210 --> 00:08:12,093
and filter the application
specific traffic.

188
00:08:14,640 --> 00:08:16,770
Now, virtual firewalls
are designed to protect

189
00:08:16,770 --> 00:08:19,830
a virtualized environment
such as a cloud infrastructure

190
00:08:19,830 --> 00:08:21,222
or virtual machines.

191
00:08:21,222 --> 00:08:23,100
Virtualized firewalls operate

192
00:08:23,100 --> 00:08:24,870
within the virtualized environment

193
00:08:24,870 --> 00:08:27,570
and provide security at
the application layer

194
00:08:27,570 --> 00:08:30,030
of the OSI model, again,
that was layer seven,

195
00:08:30,030 --> 00:08:31,830
to protect against attacks

196
00:08:31,830 --> 00:08:34,623
that are targeting the
virtualized environment.

197
00:08:37,530 --> 00:08:39,030
So when we think about our firewalls,

198
00:08:39,030 --> 00:08:40,290
we have to think about

199
00:08:40,290 --> 00:08:42,900
how we're going to configure
them appropriately,

200
00:08:42,900 --> 00:08:44,580
strategically align, if you will,

201
00:08:44,580 --> 00:08:46,890
with the needs of our organization.

202
00:08:46,890 --> 00:08:51,890
So four key categories of
planning are traffic filtering,

203
00:08:52,590 --> 00:08:56,133
business rules, logging and assurance.

204
00:08:57,720 --> 00:09:00,000
So in traffic filtering,
we have to decide,

205
00:09:00,000 --> 00:09:03,330
well are we going to be in
allow by default mode, right?

206
00:09:03,330 --> 00:09:05,243
Or default allow, which doesn't,

207
00:09:05,243 --> 00:09:08,280
which if not explicitly
denied, then access is allowed.

208
00:09:08,280 --> 00:09:11,580
Or do we wanna be in
default deny mode, right?

209
00:09:11,580 --> 00:09:13,620
Or deny by default, which means that

210
00:09:13,620 --> 00:09:16,590
if not explicitly allowed,
then access is denied.

211
00:09:16,590 --> 00:09:18,319
Well, you already know that answer, right?

212
00:09:18,319 --> 00:09:22,110
We never wanna be in default
allow or allow by default,

213
00:09:22,110 --> 00:09:23,460
'cause that means all traffic can flow,

214
00:09:23,460 --> 00:09:26,019
everything's going back and
forth until we start denying it.

215
00:09:26,019 --> 00:09:29,040
We really wanna choose
to be in default deny

216
00:09:29,040 --> 00:09:30,780
or deny by default, two different ways

217
00:09:30,780 --> 00:09:32,820
to say the same thing mode,

218
00:09:32,820 --> 00:09:35,400
but beware that not every firewall

219
00:09:35,400 --> 00:09:36,900
comes out of the box, right?

220
00:09:36,900 --> 00:09:38,670
In default deny mode,

221
00:09:38,670 --> 00:09:41,730
some firewalls still might
come in default allow.

222
00:09:41,730 --> 00:09:43,680
So you wanna be very cognizant of that.

223
00:09:45,150 --> 00:09:46,260
Then we have business rules.

224
00:09:46,260 --> 00:09:48,030
We need to set up a bunch of rules

225
00:09:48,030 --> 00:09:49,711
about who's allowed to do what.

226
00:09:49,711 --> 00:09:51,480
Remember, in default deny

227
00:09:51,480 --> 00:09:53,220
there's gonna be no
ingress or egress traffic

228
00:09:53,220 --> 00:09:55,710
until we set up these rules.

229
00:09:55,710 --> 00:09:58,350
So we're gonna set up what's
known as an access control list

230
00:09:58,350 --> 00:09:59,370
but the access control list

231
00:09:59,370 --> 00:10:03,330
should always be based
on business requirements.

232
00:10:03,330 --> 00:10:06,510
So we wanna make sure that all
of our rules in our firewall

233
00:10:06,510 --> 00:10:08,430
strategically align, right?

234
00:10:08,430 --> 00:10:11,610
With the business, with
the needs of the business

235
00:10:11,610 --> 00:10:13,159
and that there should be a process

236
00:10:13,159 --> 00:10:16,948
for approving a new rule
an allow or deny rule

237
00:10:16,948 --> 00:10:19,593
and or for any exceptions to that rule.

238
00:10:21,540 --> 00:10:22,830
Then we wanna make sure
that we're logging,

239
00:10:22,830 --> 00:10:24,300
we definitely wanna be logging

240
00:10:24,300 --> 00:10:26,490
everything that's
happening at our firewalls.

241
00:10:26,490 --> 00:10:28,007
So we wanna configure our logs,

242
00:10:28,007 --> 00:10:30,777
we wanna have a process for log reviews

243
00:10:30,777 --> 00:10:33,450
and we wanna make sure
we're archiving those logs

244
00:10:33,450 --> 00:10:36,604
because we may need to
use those logs, you know,

245
00:10:36,604 --> 00:10:39,000
sometime in the future
if we're coming back

246
00:10:39,000 --> 00:10:42,840
and doing any type of
investigation or forensic analysis.

247
00:10:42,840 --> 00:10:45,090
And we're gonna do a
whole lesson on logging.

248
00:10:47,070 --> 00:10:48,300
And then lastly, assurance.

249
00:10:48,300 --> 00:10:50,002
We want to know that the firewall

250
00:10:50,002 --> 00:10:52,560
which is such a critical device for us

251
00:10:52,560 --> 00:10:55,388
is working the way we expect,
that it's trustworthy.

252
00:10:55,388 --> 00:10:58,650
So we want to be making
sure that we have scheduled

253
00:10:58,650 --> 00:11:00,500
and organized and paying attention to

254
00:11:00,500 --> 00:11:02,852
configuration and rule set audits,

255
00:11:02,852 --> 00:11:06,303
doing scanning and penetration testing.

256
00:11:08,310 --> 00:11:10,260
So I just mentioned that
we have rules, right?

257
00:11:10,260 --> 00:11:13,500
Rules are what allows
activity to happen, right?

258
00:11:13,500 --> 00:11:15,690
And we often refer to 'em as either rules

259
00:11:15,690 --> 00:11:16,927
or access control lists.

260
00:11:16,927 --> 00:11:19,077
Important thing you
need to know about rules

261
00:11:19,077 --> 00:11:22,613
is that they are processed
in order from top to bottom.

262
00:11:22,613 --> 00:11:26,040
So when the system, the firewall
is looking through rules,

263
00:11:26,040 --> 00:11:27,390
should I allow this traffic?

264
00:11:27,390 --> 00:11:29,100
It starts at the top of the rule set

265
00:11:29,100 --> 00:11:31,170
and goes down and down
and down and down and down

266
00:11:31,170 --> 00:11:34,860
and it stops at the rule
that is most applicable.

267
00:11:34,860 --> 00:11:38,325
So in looking at these rules, well,

268
00:11:38,325 --> 00:11:40,140
let me back up a minute for you

269
00:11:40,140 --> 00:11:42,510
and tell you what's actually
gonna be in these rules, right?

270
00:11:42,510 --> 00:11:45,352
These rules will have
information about permission

271
00:11:45,352 --> 00:11:50,352
based on port, protocol,
source IP, and destination IP.

272
00:11:50,520 --> 00:11:52,080
So permissions would be either allow,

273
00:11:52,080 --> 00:11:53,763
meaning, permit, or deny.

274
00:11:54,690 --> 00:11:58,170
The protocol would be UDP,
user datagram protocol.

275
00:11:58,170 --> 00:12:01,080
TCP, transmission control protocol or IP.

276
00:12:01,080 --> 00:12:03,780
IP would mean either UDP or TCP.

277
00:12:03,780 --> 00:12:05,640
The port is the listening port.

278
00:12:05,640 --> 00:12:09,183
So for example, the port 80 is for HTTP.

279
00:12:10,140 --> 00:12:12,810
The source IP is where
the traffic is coming from

280
00:12:12,810 --> 00:12:16,470
and that could be a host,
a range or a wild card,

281
00:12:16,470 --> 00:12:18,990
or just any, literally could say any.

282
00:12:18,990 --> 00:12:22,500
And then destination is
where the traffic is going.

283
00:12:22,500 --> 00:12:26,610
And again, that could be a host
range, a wild card, or any.

284
00:12:26,610 --> 00:12:28,890
So that's what's gonna be
in the rules themselves.

285
00:12:28,890 --> 00:12:30,868
But going back to this idea
that rules are processed

286
00:12:30,868 --> 00:12:32,910
in order from top to bottom,

287
00:12:32,910 --> 00:12:34,740
you really wanna pay attention to that

288
00:12:34,740 --> 00:12:37,193
because the system will
stop at whatever rule,

289
00:12:37,193 --> 00:12:42,193
right, applies, so if you
have a rule that says,

290
00:12:42,345 --> 00:12:44,580
all of our users, and I'm not gonna do it

291
00:12:44,580 --> 00:12:46,410
in the correct syntax here,

292
00:12:46,410 --> 00:12:48,090
but let's say we say all
of our users can go out

293
00:12:48,090 --> 00:12:50,460
to the internet or all
machines, all systems,

294
00:12:50,460 --> 00:12:52,422
all IP addresses can
go out to the internet.

295
00:12:52,422 --> 00:12:54,720
But then there's one that
you don't wanna allow

296
00:12:54,720 --> 00:12:55,553
to go out to the internet.

297
00:12:55,553 --> 00:12:57,630
So maybe the next rule
is, no, we're not gonna,

298
00:12:57,630 --> 00:13:00,360
we're gonna not allow
this particular machine

299
00:13:00,360 --> 00:13:03,240
at this particular IP address
to go out to the internet.

300
00:13:03,240 --> 00:13:05,250
Doesn't matter, they've
already been allowed

301
00:13:05,250 --> 00:13:08,368
because the rule above it
already said, they can do it.

302
00:13:08,368 --> 00:13:10,770
So you really have to be very cognizant

303
00:13:10,770 --> 00:13:12,840
of the order of the rules.

304
00:13:12,840 --> 00:13:14,630
Now, the last rule of an ACL

305
00:13:14,630 --> 00:13:16,440
is generally to block any traffic

306
00:13:16,440 --> 00:13:18,060
that hasn't been previously allowed.

307
00:13:18,060 --> 00:13:19,510
It's just kind of a catchall.

308
00:13:21,540 --> 00:13:23,823
All right, so that's
a lot about firewalls.

309
00:13:23,823 --> 00:13:26,400
And now we have a three second challenge,

310
00:13:26,400 --> 00:13:28,650
five challenge questions,
three seconds each.

311
00:13:28,650 --> 00:13:29,650
You know what to do.

312
00:13:31,350 --> 00:13:34,260
This type of firewall is
effective against XSS.

313
00:13:34,260 --> 00:13:36,540
That's cross site scripting attacks.

314
00:13:36,540 --> 00:13:38,523
One, two, three.

315
00:13:40,020 --> 00:13:43,023
That's gonna be a web
application firewall or a WAF.

316
00:13:43,920 --> 00:13:46,680
Number two, this type
of firewall evaluates

317
00:13:46,680 --> 00:13:48,693
each packet individually.

318
00:13:49,680 --> 00:13:51,783
One, two, three.

319
00:13:52,680 --> 00:13:56,313
That's gonna be a stateless or
a packet filtering firewall.

320
00:13:57,720 --> 00:14:00,521
Number three, this
principle is expressed as,

321
00:14:00,521 --> 00:14:05,520
if not explicitly allowed,
then access is denied.

322
00:14:05,520 --> 00:14:08,613
If not explicitly allowed,
then access is denied.

323
00:14:10,410 --> 00:14:13,830
That's gonna be default
deny or deny by default.

324
00:14:13,830 --> 00:14:17,160
You can say it either way, it
means the same exact thing.

325
00:14:17,160 --> 00:14:21,633
Number four, NextGen firewalls
operate at this OSI layer.

326
00:14:22,650 --> 00:14:24,633
One, two, three.

327
00:14:27,030 --> 00:14:30,300
I'm looking at layer seven,
the application layer.

328
00:14:30,300 --> 00:14:34,590
And lastly, number five,
order that firewall ACL rules,

329
00:14:34,590 --> 00:14:38,130
access control list rules are processed.

330
00:14:38,130 --> 00:14:39,810
This is really important.

331
00:14:39,810 --> 00:14:43,380
One, two, three, from top to bottom.

332
00:14:43,380 --> 00:14:46,620
And the first rule it applies,
that's what happens, right?

333
00:14:46,620 --> 00:14:49,440
The system doesn't go
check any further down.

334
00:14:49,440 --> 00:14:52,353
That's why the order of rules
is really, really critical.

335
00:14:53,940 --> 00:14:56,880
Okay, that brings us to
a security in action.

336
00:14:56,880 --> 00:14:58,821
This one's about a firewall replacement.

337
00:14:58,821 --> 00:15:00,870
One of the priority recommendations

338
00:15:00,870 --> 00:15:02,334
from a recent security assessment

339
00:15:02,334 --> 00:15:06,240
was for your organization
to replace its very old

340
00:15:06,240 --> 00:15:09,930
past end of life packet
filtering firewalls

341
00:15:09,930 --> 00:15:12,543
that are being used in
home office environments.

342
00:15:13,560 --> 00:15:16,860
Okay, so what are you gonna
recommend for a replacement?

343
00:15:16,860 --> 00:15:19,080
So again, this is a priority, right?

344
00:15:19,080 --> 00:15:22,860
They say that it is really
a priority recommendation.

345
00:15:22,860 --> 00:15:24,420
We just had a security assessment.

346
00:15:24,420 --> 00:15:26,610
So we had somebody spent a
lot of time looking at it.

347
00:15:26,610 --> 00:15:28,590
They said, you've got some very old,

348
00:15:28,590 --> 00:15:30,270
meaning past end of life,

349
00:15:30,270 --> 00:15:32,071
probably past end of support as well,

350
00:15:32,071 --> 00:15:35,370
packet filtering firewalls
that are being used

351
00:15:35,370 --> 00:15:36,820
in a home office environment.

352
00:15:37,686 --> 00:15:39,630
And they've asked you for recommendations

353
00:15:39,630 --> 00:15:40,740
of what should replace them.

354
00:15:40,740 --> 00:15:42,450
So what are you gonna say?

355
00:15:42,450 --> 00:15:45,400
Feel free to put me on pause
while you jot down some notes.

356
00:15:48,194 --> 00:15:49,800
Well, what are you
gonna replace them with,

357
00:15:49,800 --> 00:15:52,581
really depends on specific needs, right?

358
00:15:52,581 --> 00:15:55,643
Options would be to replace
those end of life firewalls

359
00:15:55,643 --> 00:15:58,590
with a new packet filtering
or stateless firewall,

360
00:15:58,590 --> 00:16:00,300
'cause it might just be all they need.

361
00:16:00,300 --> 00:16:02,356
Fast, efficient, low cost,

362
00:16:02,356 --> 00:16:04,260
doesn't have a lot of granular controls,

363
00:16:04,260 --> 00:16:06,152
but maybe that's not needed.

364
00:16:06,152 --> 00:16:09,420
Or maybe we'll upgrade
to a stateful firewall

365
00:16:09,420 --> 00:16:10,920
because maybe now is the time

366
00:16:10,920 --> 00:16:13,440
to have a little bit more granular control

367
00:16:13,440 --> 00:16:16,068
and be able to evaluate the
entire state of the connection,

368
00:16:16,068 --> 00:16:18,933
not just what's in a packet header.

369
00:16:20,281 --> 00:16:22,680
Now, the advantages of
the stateless firewall,

370
00:16:22,680 --> 00:16:24,090
again, is they're efficient,

371
00:16:24,090 --> 00:16:26,889
they're low resource utilization,
and they're low cost.

372
00:16:26,889 --> 00:16:29,140
But the advantages of
that stateful firewall

373
00:16:29,140 --> 00:16:31,290
can more granular control,

374
00:16:31,290 --> 00:16:33,930
ability to potentially
differentiate between legitimate

375
00:16:33,930 --> 00:16:37,581
and malicious traffic and
greater rule flexibility.

376
00:16:37,581 --> 00:16:40,170
So the answer in this
case really is gonna be,

377
00:16:40,170 --> 00:16:43,710
well, it depends, other
than we're pretty convinced

378
00:16:43,710 --> 00:16:45,930
that yes, we need to
replace those firewalls,

379
00:16:45,930 --> 00:16:47,820
we do agree with that recommendation

380
00:16:47,820 --> 00:16:50,604
because we know we never
wanna be running any,

381
00:16:50,604 --> 00:16:54,060
you know, past end of life,
end of support software,

382
00:16:54,060 --> 00:16:57,693
hardware operating system,
or any type of device.

383
00:16:58,920 --> 00:17:00,510
Being able to make these recommendations

384
00:17:00,510 --> 00:17:02,190
and understand how to move forward,

385
00:17:02,190 --> 00:17:04,440
that's security in action.

386
00:17:04,440 --> 00:17:05,940
There you go, there's your word cloud,

387
00:17:05,940 --> 00:17:08,040
you know what to do, when you're ready.

388
00:17:08,040 --> 00:17:09,640
I'll see you at the next lesson.
