1
00:00:06,510 --> 00:00:08,550
- In this lesson, 18.2,

2
00:00:08,550 --> 00:00:10,100
we're gonna be taking a look at TCP/IP,

3
00:00:10,100 --> 00:00:12,990
both v4 and v6,

4
00:00:12,990 --> 00:00:15,213
as well as secure protocols.

5
00:00:16,080 --> 00:00:17,990
Now, IP, Internet Protocol,

6
00:00:17,990 --> 00:00:21,360
is really a set of rules for
routing and addressing packets

7
00:00:21,360 --> 00:00:23,940
and it is the language of the Internet.

8
00:00:23,940 --> 00:00:25,620
It wasn't always the language, though,

9
00:00:25,620 --> 00:00:28,020
that we used in our local-area networks

10
00:00:28,020 --> 00:00:29,610
or even our wide-area networks.

11
00:00:29,610 --> 00:00:31,140
But ultimately, over time,

12
00:00:31,140 --> 00:00:33,090
as we all connected together

13
00:00:33,090 --> 00:00:34,740
and we all connect to the Internet,

14
00:00:34,740 --> 00:00:37,440
we needed to have a
standardized set of rules

15
00:00:37,440 --> 00:00:40,830
for routing and addressing
packets of data, and IP won.

16
00:00:40,830 --> 00:00:43,560
So, IP is the language of the Internet

17
00:00:43,560 --> 00:00:45,910
and the language that we
use for data transfer.

18
00:00:46,830 --> 00:00:48,450
But it was originally just designed

19
00:00:48,450 --> 00:00:51,090
for basic data connectivity.

20
00:00:51,090 --> 00:00:53,430
But then it turned out
that once we were using IP

21
00:00:53,430 --> 00:00:55,440
for our data transfer,

22
00:00:55,440 --> 00:00:57,450
to go, "Well, why can't
we use that protocol

23
00:00:57,450 --> 00:01:00,390
or that set of rules for everything else?"

24
00:01:00,390 --> 00:01:01,740
So, we started to.

25
00:01:01,740 --> 00:01:05,010
Now, IP convergence is a term
we use to describe the use

26
00:01:05,010 --> 00:01:08,010
of the Internet Protocol
as a standard transport

27
00:01:08,010 --> 00:01:10,050
for transmitting all information,

28
00:01:10,050 --> 00:01:15,050
voice, data, music, video, TV,
teleconferencing, and so on.

29
00:01:17,070 --> 00:01:19,770
So, IP convergence, that's
a term you wanna remember.

30
00:01:19,770 --> 00:01:21,630
Now, there may have been needed to be

31
00:01:21,630 --> 00:01:23,580
some modifications to make this work,

32
00:01:23,580 --> 00:01:26,340
so extensibility is another
term I want you to know.

33
00:01:26,340 --> 00:01:28,950
Extensibility is additional functionality

34
00:01:28,950 --> 00:01:32,100
or the modification of
existing functionality

35
00:01:32,100 --> 00:01:33,810
without significantly altering

36
00:01:33,810 --> 00:01:36,600
the original structure or data flow.

37
00:01:36,600 --> 00:01:38,970
A complimentary term is open standard.

38
00:01:38,970 --> 00:01:42,300
Now, open standard is a standard
that is publicly available

39
00:01:42,300 --> 00:01:45,453
and can be freely adopted and extended.

40
00:01:48,060 --> 00:01:51,150
Our traditional TCP/IP
model is four layers.

41
00:01:51,150 --> 00:01:53,370
We have a link layer, an Internet layer,

42
00:01:53,370 --> 00:01:56,730
a transport layer, and
an application layer.

43
00:01:56,730 --> 00:01:58,740
And so, down at our link layer,

44
00:01:58,740 --> 00:02:00,270
that's where we have physical,

45
00:02:00,270 --> 00:02:03,090
Token Ring, Frame Relay, ATM.

46
00:02:03,090 --> 00:02:05,760
This is where electrical signals are

47
00:02:05,760 --> 00:02:08,280
and packets coming on and off the network.

48
00:02:08,280 --> 00:02:10,590
The Internet layer's where we have IP

49
00:02:10,590 --> 00:02:13,410
and we have ARP, ICMP, and IGMP,

50
00:02:13,410 --> 00:02:14,850
and we're gonna go more
into detail on those

51
00:02:14,850 --> 00:02:15,900
in just a moment.

52
00:02:15,900 --> 00:02:17,130
The transport layer's where we have

53
00:02:17,130 --> 00:02:20,280
Transmission Control Protocol
and User Datagram Protocol.

54
00:02:20,280 --> 00:02:22,350
And up at the application layer,

55
00:02:22,350 --> 00:02:25,230
that's where we have our
legacy to begin with,

56
00:02:25,230 --> 00:02:27,930
TCP/IP Protocol Suite.

57
00:02:27,930 --> 00:02:31,020
Now, these apps or utilities
were really, again,

58
00:02:31,020 --> 00:02:34,773
designed for data transfer
and not for security.

59
00:02:36,420 --> 00:02:38,520
Let's talk about what
happens at the Internet layer

60
00:02:38,520 --> 00:02:41,020
and the transport layer
and the application layer.

61
00:02:42,060 --> 00:02:44,220
The Internet layer, we have IP.

62
00:02:44,220 --> 00:02:46,650
We have ARP, Address Resolution Protocol.

63
00:02:46,650 --> 00:02:48,390
We have ICMP,

64
00:02:48,390 --> 00:02:51,390
the Internet Control Messaging Protocol,

65
00:02:51,390 --> 00:02:52,590
and IGMP,

66
00:02:52,590 --> 00:02:55,140
which is the Internet
Group Management Protocol.

67
00:02:55,140 --> 00:02:56,700
Then, when we go up to
the transport layer,

68
00:02:56,700 --> 00:02:59,370
we have TCP, Transmission
Control Protocol,

69
00:02:59,370 --> 00:03:01,863
and UDP, User Datagram Protocol.

70
00:03:03,030 --> 00:03:06,240
IP is a set of addressing
and routing rules.

71
00:03:06,240 --> 00:03:11,240
The current versions are IPv4 and IPv6.

72
00:03:11,250 --> 00:03:13,280
Our Address Resolution Protocol

73
00:03:13,280 --> 00:03:16,950
is used for IP address
to MAC address mapping.

74
00:03:16,950 --> 00:03:19,230
Now, IPv6 doesn't use ARP.

75
00:03:19,230 --> 00:03:20,340
It actually uses what's known

76
00:03:20,340 --> 00:03:22,440
as Neighborhood Discovery Protocol.

77
00:03:22,440 --> 00:03:24,330
Remember we talked earlier
about a MAC address,

78
00:03:24,330 --> 00:03:27,720
that every network interface
has a unique MAC address

79
00:03:27,720 --> 00:03:30,960
that uniquely identifies that
interface or that device?

80
00:03:30,960 --> 00:03:32,760
But we don't talk by MAC address

81
00:03:32,760 --> 00:03:35,820
on the Internet or in our local networks.

82
00:03:35,820 --> 00:03:37,470
We talk by IP.

83
00:03:37,470 --> 00:03:40,170
So, there has to be a
way to map a MAC address

84
00:03:40,170 --> 00:03:43,290
to an IP address and an IP
address back to a MAC address,

85
00:03:43,290 --> 00:03:45,420
and that's what we use ARP for.

86
00:03:45,420 --> 00:03:48,870
ICMP, Internet Control Messaging Protocol,

87
00:03:48,870 --> 00:03:52,170
we use for error control
and troubleshooting.

88
00:03:52,170 --> 00:03:54,360
Now, you've been using it
probably without even knowing it,

89
00:03:54,360 --> 00:03:57,090
but every time you run a ping
command or a tracert command,

90
00:03:57,090 --> 00:03:59,640
you're really using ICMP.

91
00:03:59,640 --> 00:04:03,003
And then, IGMP is used for multicasting.

92
00:04:03,003 --> 00:04:06,000
Now, we're not using IGMP anymore in v6.

93
00:04:06,000 --> 00:04:08,673
Instead, we're using
multicast listener discovery.

94
00:04:09,840 --> 00:04:11,580
Then we go up to the transport layer,

95
00:04:11,580 --> 00:04:14,310
and at the transport
layer we have TCP and UDP.

96
00:04:14,310 --> 00:04:16,380
And the difference between the two

97
00:04:16,380 --> 00:04:19,980
is that Transmission
Control Protocol, TCP,

98
00:04:19,980 --> 00:04:21,690
is connection-oriented,

99
00:04:21,690 --> 00:04:25,830
where UDP, User Datagram
Protocol, is connectionless.

100
00:04:25,830 --> 00:04:27,300
Let me give you an example.

101
00:04:27,300 --> 00:04:31,440
In TCP, before we're really
gonna be communicating,

102
00:04:31,440 --> 00:04:33,570
the source and destination do what's known

103
00:04:33,570 --> 00:04:35,730
as a three-way handshake.

104
00:04:35,730 --> 00:04:37,087
The source says to the destination,

105
00:04:37,087 --> 00:04:39,090
"Hey, destination, I wanna talk to you."

106
00:04:39,090 --> 00:04:41,940
The destination says,
"Cool, I wanna talk to you."

107
00:04:41,940 --> 00:04:42,773
The source says,

108
00:04:42,773 --> 00:04:45,210
"Confirmed, I'm about
to send you a message."

109
00:04:45,210 --> 00:04:47,850
They've set up a connection
before they start

110
00:04:47,850 --> 00:04:49,200
the rest of their communication,

111
00:04:49,200 --> 00:04:50,370
so it's connection-oriented.

112
00:04:50,370 --> 00:04:51,990
A connection has been established

113
00:04:51,990 --> 00:04:53,940
before they start really communicating.

114
00:04:54,870 --> 00:04:58,320
User Datagram Protocol is connectionless.

115
00:04:58,320 --> 00:05:02,250
Let's say your machine
uses a dynamic IP address

116
00:05:02,250 --> 00:05:03,110
using DHCP,

117
00:05:03,110 --> 00:05:04,560
so you need DHCP server,

118
00:05:04,560 --> 00:05:07,020
Dynamic Host Configuration Protocol server

119
00:05:07,020 --> 00:05:08,670
to give you an IP address.

120
00:05:08,670 --> 00:05:10,147
So, your device comes up and it says,

121
00:05:10,147 --> 00:05:12,090
"Hey, I need a DHCP server."

122
00:05:12,090 --> 00:05:13,057
And if no one answers, again,

123
00:05:13,057 --> 00:05:15,210
"Hey, I need a DHCP server."

124
00:05:15,210 --> 00:05:17,010
It's short, little bursts,

125
00:05:17,010 --> 00:05:21,870
and generally it's being
broadcast and it's easy to resend.

126
00:05:21,870 --> 00:05:24,180
There's no connection
that gets set up first.

127
00:05:24,180 --> 00:05:25,920
Matter of fact, you can't even
set up the connection first

128
00:05:25,920 --> 00:05:27,930
'cause you don't know
who that DHCP server is.

129
00:05:27,930 --> 00:05:30,390
You gotta find that DHCP server first.

130
00:05:30,390 --> 00:05:32,973
That would be an example of using UDP.

131
00:05:34,500 --> 00:05:36,990
Now, there are the two versions of IP,

132
00:05:36,990 --> 00:05:39,990
IPv4 and IPv6.

133
00:05:39,990 --> 00:05:42,990
IPv4 was deployed back in 1981

134
00:05:42,990 --> 00:05:46,350
and 4 was the first publicly used version.

135
00:05:46,350 --> 00:05:47,790
There were versions 1, 2, and 3,

136
00:05:47,790 --> 00:05:49,470
but they were experimental.

137
00:05:49,470 --> 00:05:51,750
I know you know all about IPv4.

138
00:05:51,750 --> 00:05:56,220
It's a 32-bit address expressed
in a dotted decimal format.

139
00:05:56,220 --> 00:05:59,340
So, why didn't we just
keep using IPv4 forever?

140
00:05:59,340 --> 00:06:00,960
Well, it's a 32-bit address,

141
00:06:00,960 --> 00:06:04,200
so we have a limited number of addresses.

142
00:06:04,200 --> 00:06:07,263
IP address scarcity is really an issue.

143
00:06:08,640 --> 00:06:09,510
Now, it's interesting,

144
00:06:09,510 --> 00:06:11,670
because when we started first using it,

145
00:06:11,670 --> 00:06:12,900
it wasn't a big deal.

146
00:06:12,900 --> 00:06:14,610
And then after we'd been
using it for a while,

147
00:06:14,610 --> 00:06:15,997
we all got a little bit nervous and said,

148
00:06:15,997 --> 00:06:17,940
"Oh, my God, we're gonna
run out of addresses!"

149
00:06:17,940 --> 00:06:20,520
So, we started using NAT,
Network Address Translation,

150
00:06:20,520 --> 00:06:23,250
or PAT, Port Address
Translation, in our networks,

151
00:06:23,250 --> 00:06:26,040
meaning we would use private
addresses inside our network

152
00:06:26,040 --> 00:06:29,370
and public addresses
external to our network.

153
00:06:29,370 --> 00:06:31,620
And NAT, we do our translation.

154
00:06:31,620 --> 00:06:33,060
And then we were like, "Phew, okay.

155
00:06:33,060 --> 00:06:34,290
Now we don't have to worry about

156
00:06:34,290 --> 00:06:35,937
IP address scarcity anymore."

157
00:06:36,960 --> 00:06:38,460
But voila, here we are today.

158
00:06:38,460 --> 00:06:39,930
Think of all of the devices

159
00:06:39,930 --> 00:06:41,910
that connect directly to the Internet.

160
00:06:41,910 --> 00:06:45,150
All the embedded devices,
all the IOT devices,

161
00:06:45,150 --> 00:06:49,560
all of our smartphones,
all of our mobile devices

162
00:06:49,560 --> 00:06:51,270
that connect directly to the Internet

163
00:06:51,270 --> 00:06:52,980
and do need a public address.

164
00:06:52,980 --> 00:06:56,460
So, IP address scarcity as an
issue raised its head again.

165
00:06:56,460 --> 00:06:58,620
And there were just very
limited security options

166
00:06:58,620 --> 00:07:02,130
because IPv4 was really
designed for data transfer

167
00:07:02,130 --> 00:07:04,593
and not for security.

168
00:07:05,940 --> 00:07:08,790
So, IPv6 came out in 1999,

169
00:07:08,790 --> 00:07:09,960
and what's really crazy

170
00:07:09,960 --> 00:07:12,870
is we are still in the adoption phase.

171
00:07:12,870 --> 00:07:15,630
But I think adoption
will begin to escalate.

172
00:07:15,630 --> 00:07:20,370
It is a 128-bit address expressed
in a hexadecimal format.

173
00:07:20,370 --> 00:07:21,330
You can see an example,

174
00:07:21,330 --> 00:07:25,560
the number that starts with
2001 and ends with 7334.

175
00:07:25,560 --> 00:07:28,560
That's an example of how we
express it in hexadecimal,

176
00:07:28,560 --> 00:07:31,200
four numbers separated by a colon.

177
00:07:31,200 --> 00:07:33,600
Because it's a 128-bit address,

178
00:07:33,600 --> 00:07:37,260
our address space is two
to the 128th addresses,

179
00:07:37,260 --> 00:07:41,550
which equates roughly to 340
trillion trillion addresses.

180
00:07:41,550 --> 00:07:44,040
I hate to say we're never
gonna run out of something,

181
00:07:44,040 --> 00:07:45,870
but I'm pretty confident in my lifetime

182
00:07:45,870 --> 00:07:48,300
we probably won't run out of IP addresses.

183
00:07:48,300 --> 00:07:50,910
Now, IPv6 did introduce
some security options.

184
00:07:50,910 --> 00:07:52,230
It has stateful and stateless

185
00:07:52,230 --> 00:07:54,250
auto configuration capabilities

186
00:07:55,110 --> 00:07:58,413
and it does have integrated IPsec.

187
00:07:59,460 --> 00:08:01,470
Now, scans are,

188
00:08:01,470 --> 00:08:03,630
vulnerability scans are less effective

189
00:08:03,630 --> 00:08:05,460
because of a larger address space,

190
00:08:05,460 --> 00:08:09,810
and sniffing is more difficult
because of mandated IPsec.

191
00:08:09,810 --> 00:08:13,800
So, from an adversary trying
to do reconnaissance on us,

192
00:08:13,800 --> 00:08:16,983
IPv6 really offers some security.

193
00:08:18,960 --> 00:08:20,910
Now, QoS, or quality of service,

194
00:08:20,910 --> 00:08:22,770
is a feature of our network devices

195
00:08:22,770 --> 00:08:25,080
which prioritize traffic.

196
00:08:25,080 --> 00:08:28,080
QoS controls and manages network resources

197
00:08:28,080 --> 00:08:31,410
by setting priorities
for certain types of data

198
00:08:31,410 --> 00:08:32,340
on our network.

199
00:08:32,340 --> 00:08:35,670
And measurements of concern to QoS

200
00:08:35,670 --> 00:08:38,040
are bandwidth, which we
think of as throughput,

201
00:08:38,040 --> 00:08:40,260
latency, which we think of as delay,

202
00:08:40,260 --> 00:08:42,900
jitter, which is a variance in latency,

203
00:08:42,900 --> 00:08:44,340
and an error rate.

204
00:08:44,340 --> 00:08:47,520
An IPv6 packet header provides for fields

205
00:08:47,520 --> 00:08:51,633
that facilitate the support
for QoS, or quality of service.

206
00:08:53,280 --> 00:08:55,230
Now, let's move up to
the application layer.

207
00:08:55,230 --> 00:08:56,820
The path of communication

208
00:08:56,820 --> 00:08:59,250
from the transport layer
to the application layer

209
00:08:59,250 --> 00:09:00,840
is through a port.

210
00:09:00,840 --> 00:09:03,780
Now, a port is nothing
more than an identifier.

211
00:09:03,780 --> 00:09:06,000
It's how an application listens.

212
00:09:06,000 --> 00:09:07,290
So, a port's an identifier

213
00:09:07,290 --> 00:09:09,330
for an application within a computer,

214
00:09:09,330 --> 00:09:13,020
and applications that need
to talk to other applications

215
00:09:13,020 --> 00:09:14,910
or hosts that need to talk to other hosts

216
00:09:14,910 --> 00:09:18,930
listen for connections on a
port dedicated to that service.

217
00:09:18,930 --> 00:09:22,470
So, you know that when
you go out port 80, HTTPS,

218
00:09:22,470 --> 00:09:25,297
it's gonna be an HTTPS
service that's listening,

219
00:09:25,297 --> 00:09:27,180
"Oh, something's coming in port 80.

220
00:09:27,180 --> 00:09:29,280
That must be for me."

221
00:09:29,280 --> 00:09:31,560
Or, "Something's coming in port 443.

222
00:09:31,560 --> 00:09:32,490
That must be for me.

223
00:09:32,490 --> 00:09:34,737
I'm an HTTPS application."

224
00:09:35,610 --> 00:09:38,580
Now, ports associated
with either UDP or TCP,

225
00:09:38,580 --> 00:09:42,390
there are a total of
65,535 available ports.

226
00:09:42,390 --> 00:09:44,040
They're broken into three ranges.

227
00:09:44,040 --> 00:09:48,990
Ports 1 to 1,023, which
were assigned by the IANA,

228
00:09:48,990 --> 00:09:51,240
is the Internet Assigned
Numbers Authority,

229
00:09:51,240 --> 00:09:54,060
and those are often referred
to as the well-known ports.

230
00:09:54,060 --> 00:09:57,180
The next grouping, 1,024 to 49,151,

231
00:09:57,180 --> 00:09:59,640
can be registered with the IANA.

232
00:09:59,640 --> 00:10:02,313
And the upper ports, 49,151

233
00:10:02,313 --> 00:10:05,760
'til the very last one, 65,535,

234
00:10:05,760 --> 00:10:08,160
are known as dynamic or private ports.

235
00:10:08,160 --> 00:10:10,110
Sometimes an application will use those,

236
00:10:10,110 --> 00:10:11,700
sometimes you'll start
on a well-known port

237
00:10:11,700 --> 00:10:15,273
and then you will move to
a dynamic or private port.

238
00:10:17,760 --> 00:10:19,980
It really behooves you
to be able to recognize

239
00:10:19,980 --> 00:10:22,290
some of the more common ports.

240
00:10:22,290 --> 00:10:25,140
You may or may not need to
have this for your exam,

241
00:10:25,140 --> 00:10:27,330
but in general, really
understanding ports,

242
00:10:27,330 --> 00:10:29,610
because ports come up in a lot of places.

243
00:10:29,610 --> 00:10:32,250
If you're doing any
troubleshooting, ports will come up.

244
00:10:32,250 --> 00:10:35,190
If you're doing any network
sniffing and analyzing,

245
00:10:35,190 --> 00:10:37,410
you're gonna be looking
at packets by port.

246
00:10:37,410 --> 00:10:39,540
If you are looking at firewall rules

247
00:10:39,540 --> 00:10:40,770
or designing firewall rules

248
00:10:40,770 --> 00:10:42,150
or auditing firewall rules

249
00:10:42,150 --> 00:10:43,650
or implementing firewall rules,

250
00:10:43,650 --> 00:10:45,303
it's gonna be all about ports.

251
00:10:46,470 --> 00:10:49,230
If you're looking at log
files, there's gonna be ports.

252
00:10:49,230 --> 00:10:50,940
Being able to recognize
the more common ports

253
00:10:50,940 --> 00:10:52,020
is really useful,

254
00:10:52,020 --> 00:10:54,630
so here's a list of some
of the more common ports.

255
00:10:54,630 --> 00:10:57,633
There may others that you
wanna add to that list.

256
00:11:00,510 --> 00:11:02,310
Let's move up to the protocol suite.

257
00:11:02,310 --> 00:11:04,650
And I mentioned at the
beginning of this lesson

258
00:11:04,650 --> 00:11:07,740
that the protocols that are
in that current protocol suite

259
00:11:07,740 --> 00:11:09,300
in that picture that you see

260
00:11:09,300 --> 00:11:12,180
are considered insecure protocols.

261
00:11:12,180 --> 00:11:13,620
The original protocols, again,

262
00:11:13,620 --> 00:11:15,090
not designed for security,

263
00:11:15,090 --> 00:11:16,830
had very basic authentication,

264
00:11:16,830 --> 00:11:18,180
and on the most part,

265
00:11:18,180 --> 00:11:20,280
transmitted everything in cleartext.

266
00:11:20,280 --> 00:11:21,783
HTTP, cleartext.

267
00:11:21,783 --> 00:11:23,116
FTP, cleartext.

268
00:11:24,720 --> 00:11:28,020
Doing things you don't
even see here, like Telnet,

269
00:11:28,020 --> 00:11:30,333
cleartext and basic authentication.

270
00:11:31,320 --> 00:11:33,510
So, what we wanna do is transition

271
00:11:33,510 --> 00:11:36,090
from these older, insecure protocols

272
00:11:36,090 --> 00:11:37,500
to more secure protocols.

273
00:11:37,500 --> 00:11:39,450
And the function of a secure protocol

274
00:11:39,450 --> 00:11:41,580
is to ensure confidentiality, integrity,

275
00:11:41,580 --> 00:11:43,680
authentication, non-repudiation,

276
00:11:43,680 --> 00:11:45,210
or any combination of them.

277
00:11:45,210 --> 00:11:47,700
And our secure protocols are commonly used

278
00:11:47,700 --> 00:11:50,250
in network management and communication,

279
00:11:50,250 --> 00:11:51,090
as I just said,

280
00:11:51,090 --> 00:11:54,783
often replacing our
older, insecure protocols.

281
00:11:56,580 --> 00:11:58,590
But if we're talking
about secure protocols,

282
00:11:58,590 --> 00:12:01,620
we really have to start
with just a quick refresher

283
00:12:01,620 --> 00:12:04,470
on SSL and TLS.

284
00:12:04,470 --> 00:12:08,040
SSL was developed back
in 1995 by Netscape.

285
00:12:08,040 --> 00:12:09,390
It was used to establish

286
00:12:09,390 --> 00:12:12,720
a secure communication
channel by negotiation.

287
00:12:12,720 --> 00:12:14,910
It used port 443.

288
00:12:14,910 --> 00:12:16,320
We don't use it anymore.

289
00:12:16,320 --> 00:12:18,690
In 2015, it was deprecated

290
00:12:18,690 --> 00:12:20,940
because a number of
vulnerabilities were found.

291
00:12:20,940 --> 00:12:24,000
New vulnerabilities
continue to be discovered.

292
00:12:24,000 --> 00:12:26,430
Most of our browsers
no longer support SSL.

293
00:12:26,430 --> 00:12:27,660
We don't wanna be using it

294
00:12:27,660 --> 00:12:31,590
and we wanna make sure that we
are disabling SSL 2.0 and 3.0

295
00:12:31,590 --> 00:12:34,140
so that we're not vulnerable
to a downgrade attack.

296
00:12:35,190 --> 00:12:37,830
As we already talked about,
what was SSL replaced with?

297
00:12:37,830 --> 00:12:40,500
Well, TLS, Transport Layer Security.

298
00:12:40,500 --> 00:12:42,390
Introduced in 1999,

299
00:12:42,390 --> 00:12:45,240
it's used to establish a
secure communication channel

300
00:12:45,240 --> 00:12:47,550
using a cryptographic key exchange.

301
00:12:47,550 --> 00:12:51,570
But it uses the same port
as SSL, it uses port 443.

302
00:12:51,570 --> 00:12:52,920
And I think, as I mentioned earlier,

303
00:12:52,920 --> 00:12:55,560
a lot of times when people
are talking about TLS,

304
00:12:55,560 --> 00:12:56,807
they still use the term SSL

305
00:12:56,807 --> 00:12:59,403
'cause it's just a term
that was used for so long.

306
00:13:00,450 --> 00:13:01,320
So, current state.

307
00:13:01,320 --> 00:13:02,610
TLS is a successor

308
00:13:02,610 --> 00:13:04,950
and the recommended replacement for SSL.

309
00:13:04,950 --> 00:13:08,520
It provides confidentiality,
integrity, authenticity.

310
00:13:08,520 --> 00:13:12,120
It uses a block cipher and
some advanced algorithms.

311
00:13:12,120 --> 00:13:14,940
Current version right now is TLS 1.3.

312
00:13:14,940 --> 00:13:16,020
That's what you should be using,

313
00:13:16,020 --> 00:13:17,940
but higher versions as they come out.

314
00:13:17,940 --> 00:13:20,850
And the IETF has officially declared

315
00:13:20,850 --> 00:13:23,760
that both TLS 1.0 and 1.1 are deprecated,

316
00:13:23,760 --> 00:13:25,230
meaning weak and vulnerable,

317
00:13:25,230 --> 00:13:26,793
and should not be used.

318
00:13:29,100 --> 00:13:31,050
So, what do we wanna use instead?

319
00:13:31,050 --> 00:13:32,970
Well, let's talk about
some secure communications

320
00:13:32,970 --> 00:13:34,620
and management protocols.

321
00:13:34,620 --> 00:13:39,620
HTTPS, FTPS, Secure Shell, SFTP,

322
00:13:39,660 --> 00:13:43,203
SRTP, S/MIME, and DNSSec.

323
00:13:44,400 --> 00:13:48,660
HTTPS is really HTTP plus TLS

324
00:13:48,660 --> 00:13:52,560
to give us a secure communication channel.

325
00:13:52,560 --> 00:13:55,020
FTP, File Transfer Protocol.

326
00:13:55,020 --> 00:13:58,650
Well, FTPS is FTP, File Transfer Protocol,

327
00:13:58,650 --> 00:14:01,200
which was a cleartext protocol

328
00:14:01,200 --> 00:14:03,810
which included cleartext
for your authentication,

329
00:14:03,810 --> 00:14:07,440
layered with TLS becomes FTPS.

330
00:14:07,440 --> 00:14:09,153
Secure Shell, or SSH.

331
00:14:10,170 --> 00:14:13,290
Secure Shell creates a secure channel

332
00:14:13,290 --> 00:14:16,620
between a local and a remote device.

333
00:14:16,620 --> 00:14:17,970
It's really not just a protocol.

334
00:14:17,970 --> 00:14:19,200
It's considered a protocol suite

335
00:14:19,200 --> 00:14:21,690
'cause it does have some
additional components.

336
00:14:21,690 --> 00:14:24,870
So, Secure Shell, or SSH, on port 22,

337
00:14:24,870 --> 00:14:28,350
absolutely 100% our Telnet replacement.

338
00:14:28,350 --> 00:14:31,500
We don't wanna use Telnet for creating

339
00:14:31,500 --> 00:14:32,910
a communication channel

340
00:14:32,910 --> 00:14:36,720
either between two systems
or to manage a system,

341
00:14:36,720 --> 00:14:40,290
because Telnet, basic
authentication, cleartext.

342
00:14:40,290 --> 00:14:41,730
Well, SSH, or Secure Shell,

343
00:14:41,730 --> 00:14:43,080
again, is a protocol suite.

344
00:14:43,080 --> 00:14:44,670
And one of the protocols

345
00:14:44,670 --> 00:14:47,130
that's actually packaged with SSH

346
00:14:47,130 --> 00:14:50,580
is SFTP running on port 22, also.

347
00:14:50,580 --> 00:14:53,643
It's Secure File Transport Protocol.

348
00:14:55,230 --> 00:14:58,710
SRTP is used for securely delivering

349
00:14:58,710 --> 00:15:02,190
audio and video messages
over an IP network.

350
00:15:02,190 --> 00:15:05,250
S/MIME is used to send digitally signed

351
00:15:05,250 --> 00:15:07,620
and encrypted email messages.

352
00:15:07,620 --> 00:15:09,210
And then, DNSSec,

353
00:15:09,210 --> 00:15:12,030
which runs on the same port as DNS, 53,

354
00:15:12,030 --> 00:15:14,130
is an extension of the DNS protocol

355
00:15:14,130 --> 00:15:17,010
that enables origin authentication,

356
00:15:17,010 --> 00:15:19,140
authenticated denial of existence,

357
00:15:19,140 --> 00:15:20,310
and data integrity.

358
00:15:20,310 --> 00:15:23,703
In other words, it allows
us to secure our zone files.

359
00:15:25,380 --> 00:15:28,410
So, those are the secure communication

360
00:15:28,410 --> 00:15:29,430
and management protocols

361
00:15:29,430 --> 00:15:31,560
that you wanna be using
on a day-to-day basis,

362
00:15:31,560 --> 00:15:34,860
replacing those older, insecure protocols.

363
00:15:34,860 --> 00:15:37,680
And that, my friends, brings
us to a 3-Second Challenge.

364
00:15:37,680 --> 00:15:38,513
Let's do it.

365
00:15:39,630 --> 00:15:42,030
Question one, protocol that
uses a three-way handshake

366
00:15:42,030 --> 00:15:43,890
to establish a connection.

367
00:15:43,890 --> 00:15:45,453
One, two, three.

368
00:15:46,470 --> 00:15:49,233
That's gonna be TCP,
Transmission Control Protocol.

369
00:15:50,340 --> 00:15:55,020
Number two, format for an IPv6 address.

370
00:15:55,020 --> 00:15:56,880
What's the format?

371
00:15:56,880 --> 00:15:58,203
One, two, three.

372
00:15:59,250 --> 00:16:00,420
It's gonna be hexadecimal.

373
00:16:00,420 --> 00:16:03,933
Remember, it's a 128-bit
hexadecimal address.

374
00:16:05,400 --> 00:16:08,010
Number three, networking
technology that sets priorities

375
00:16:08,010 --> 00:16:10,473
for specific types of data on the network.

376
00:16:11,580 --> 00:16:13,083
One, two, three.

377
00:16:14,010 --> 00:16:16,893
That's gonna be QoS,
or quality of service.

378
00:16:18,300 --> 00:16:21,030
Number four, term used to describe

379
00:16:21,030 --> 00:16:23,070
a standard that is publicly available

380
00:16:23,070 --> 00:16:25,893
and can be freely adopted and extended.

381
00:16:28,110 --> 00:16:29,853
One, two, three.

382
00:16:30,720 --> 00:16:33,120
That's gonna be an open standard.

383
00:16:33,120 --> 00:16:35,640
Number five, term used to
describe the modification

384
00:16:35,640 --> 00:16:38,850
of existing functionality
without significantly altering

385
00:16:38,850 --> 00:16:41,910
the original structure or data flow.

386
00:16:41,910 --> 00:16:43,083
One, two, three.

387
00:16:43,950 --> 00:16:45,633
That's gonna be extensibility.

388
00:16:46,470 --> 00:16:48,300
And often, when you'll see a protocol

389
00:16:48,300 --> 00:16:50,340
that's extensible, that's been extended,

390
00:16:50,340 --> 00:16:51,843
it'll have the letter X in it.

391
00:16:53,040 --> 00:16:54,660
Okay, let's do a Security-in-Action,

392
00:16:54,660 --> 00:16:57,540
this time about an IPv6 deployment.

393
00:16:57,540 --> 00:16:59,610
You've been asked to
investigate and report back

394
00:16:59,610 --> 00:17:02,280
on why and how to start the transition

395
00:17:02,280 --> 00:17:05,613
from IPv4 to IPv6.

396
00:17:06,510 --> 00:17:09,690
What key points should
your report touch on?

397
00:17:09,690 --> 00:17:11,610
Okay, so pretty simple.

398
00:17:11,610 --> 00:17:13,980
You've been asked to
investigate and report

399
00:17:13,980 --> 00:17:15,060
on how you're gonna move

400
00:17:15,060 --> 00:17:19,620
or how you're gonna
transition from IPv4 to IPv6.

401
00:17:19,620 --> 00:17:20,820
Put me on pause,

402
00:17:20,820 --> 00:17:22,830
get out a piece of paper,
write down your key points,

403
00:17:22,830 --> 00:17:23,853
and come on back.

404
00:17:26,106 --> 00:17:27,600
Well, IPv6 is designed

405
00:17:27,600 --> 00:17:29,700
to meet the future
demands of the Internet,

406
00:17:29,700 --> 00:17:32,070
ensuring that there's gonna
be ample address space

407
00:17:32,070 --> 00:17:33,510
for continued growth.

408
00:17:33,510 --> 00:17:35,460
And importantly, IPv6

409
00:17:35,460 --> 00:17:38,310
incorporates several security features.

410
00:17:38,310 --> 00:17:40,230
The transition really
should be transparent

411
00:17:40,230 --> 00:17:41,433
to our user community.

412
00:17:42,390 --> 00:17:45,480
So, step one, really invest
in education and training

413
00:17:45,480 --> 00:17:47,400
for our network and security engineers

414
00:17:47,400 --> 00:17:49,320
so they know what they're working with.

415
00:17:49,320 --> 00:17:52,560
Step two, we should verify that our ISPs,

416
00:17:52,560 --> 00:17:55,890
our Internet service
providers, support IPv6.

417
00:17:55,890 --> 00:17:57,510
I would be stunned if they didn't,

418
00:17:57,510 --> 00:17:58,910
but you should always check.

419
00:17:59,940 --> 00:18:01,710
Step three, we wanna determine

420
00:18:01,710 --> 00:18:04,590
if your current equipment is IPv6-ready.

421
00:18:04,590 --> 00:18:06,060
Now, it should be,

422
00:18:06,060 --> 00:18:08,460
assuming that you've got
good refresh policies

423
00:18:08,460 --> 00:18:12,060
and you're turning over your
devices on a regular basis.

424
00:18:12,060 --> 00:18:14,400
But you do wanna make sure
that your current equipment

425
00:18:14,400 --> 00:18:16,383
is IPv6-ready.

426
00:18:17,460 --> 00:18:19,380
And then, this is a big transition,

427
00:18:19,380 --> 00:18:21,840
so you're definitely gonna
wanna make a project plan,

428
00:18:21,840 --> 00:18:23,580
and if your organization uses them,

429
00:18:23,580 --> 00:18:25,890
assign a project manager.

430
00:18:25,890 --> 00:18:27,990
Being able to think about
how to make this transition

431
00:18:27,990 --> 00:18:29,400
and create this plan,

432
00:18:29,400 --> 00:18:31,260
especially one that's really transparent

433
00:18:31,260 --> 00:18:32,640
to our user community,

434
00:18:32,640 --> 00:18:35,610
that, my friends, is
definitely security in action.

435
00:18:35,610 --> 00:18:37,410
Wow, that's a big word cloud.

436
00:18:37,410 --> 00:18:40,050
All right, take your time, go
through all of these terms.

437
00:18:40,050 --> 00:18:42,120
Make sure that you understand
the terms, the concepts,

438
00:18:42,120 --> 00:18:43,710
you can explain them, you can teach them.

439
00:18:43,710 --> 00:18:45,540
If not, go back into the lesson.

440
00:18:45,540 --> 00:18:46,440
This was a long lesson.

441
00:18:46,440 --> 00:18:48,300
We covered a lot of material.

442
00:18:48,300 --> 00:18:50,430
And when you're ready,
head to the next lesson.

443
00:18:50,430 --> 00:18:51,930
I'll be waiting for you there.
