Introduction
We're going to start this skill off by taking a look at the network topology we'll be using in our labs. Then we'll spend a little time reviewing some networking and security features that we'll be working with on the Check Point Security Gateways (SG). We'll be discussing NAT and the two types of NAT the SG supports as well as the difference between a stateful firewall and a packet filtering firewall. We'll also discuss VLANs, VPNs and IPSs. Get ready, it's going to be a wild ride!
Topology and Traffic Flow
In this nugget we're going to take a look at the topology we'll be using in our labs as well as discussing traffic flow.
Knowledge Check
Internal traffic going between hosts on your network is known as North/South traffic flow.
Network Address Translation (NAT)
In this nugget we're discussing NAT, what it is and why we use it. We'll also discuss the RFC1918 which defines NAT practices and we'll also take a look at the two types of NAT that our Check Point Security Gateways (SGs) support.
Knowledge Check
Which two of the following are types of NAT that our SGs support?
Stateful vs Packet Filtering Firewalls
Let's spend a little time discussing firewalls. We'll discuss the difference between stateful and packet filtering firewalls as well as multi-layer firewalls.
Knowledge Check
Application layer firewalls can filter by individual applications.
Virtual LANs (VLANs)
VLANs are a way for us to segment our networks into smaller sub-networks. This process allows us to create security rules between our VLANs which strengthens the security of our network.
Knowledge Check
How do switches know which network traffic belongs to which VLAN?
Virtual Private Network (VPN)
VPNs provide us with a way to send encrypted network traffic between hosts and between sites across the untrusted Internet. Let's see how these VPNs work and why we should use them.
Knowledge Check
Which two protocols are most common for VPNs?
Intrusion Prevention System (IPS)
An IPS is a great addition to any companies security arsenal. They can identify known malicious data and block it preventing a security breach. Let's talk about how IPSs work.
Knowledge Check
IPSs have a database of known malicious data known as what?
Validation
It's time to test yourself and your newly found knowledge with some validation questions. Following the questions is a solution video in the event you need a little help but you've got this!
Question 1
Knowledge Check
What RFC is a best practice guide for NAT?
Question 2
Knowledge Check
Which best describes North South traffic?
Question 3
Knowledge Check
Which of the following inspects traffic information and stores it in the state table?
Question 4
Knowledge Check
Stateful Inspection is better than simple packet filtering because only one rule is required for each connection.
Question 5
Knowledge Check
Which type of NAT is supported on the Check Point SG and allows incoming and outgoing traffic?
Validation questions solution video:
Knowledge Check
Have you ever worked with NAT, IPS or VPNs? If so, which one?
This interactive assessment is available in the full learning experience.
View Transcript
Topology and Traffic Flow
0:00In the last skill, we went over a bunch of networking basics.
0:05Just to make sure everybody's on the same page, we got a good understanding and
0:09foundation
0:09of networking and some fundamentals.
0:12Now, let's start this skill off with a nugget looking at our topology and
0:18talking about traffic
0:19flow because we're going to use a certain topology in this course.
0:23So let's take a look at it.
0:25And here it is.
0:26So this is our topology.
0:27Over here on the far left, we have our HQ, our headquarters office, and then on
0:31the right,
0:32we've got site A. So say branch office, if you will.
0:36So what are we going to do with this?
0:38Well, we have two different networks here that are HQ in our site A. And we
0:43have on our
0:44HQ, let's start here, we've got our security gateway here.
0:49That's going to be our firewall.
0:50And then we've got an SMS server that's our security management server and we
0:53're going
0:54to use that to centrally manage our two security gateways that we have here
1:00because we also have
1:01one over here at our site A. So that's great.
1:05Well, what else do we have here?
1:07Well, if you'll see up here at the top, we've got a DMZ in our headquarters.
1:12So that's our demilitarized zone, a separate network.
1:16And that's where we have a Linux web server.
1:18We're going to stand up.
1:19And then we also have on our standard LAN at the HQ office.
1:23We have a Windows host and our Windows host.
1:26That's where we are going to install and be using our smart console from.
1:32So that's why we're using this Windows box here.
1:35And we'll from the smart console, connect into the SMS and from the SMS manage
1:41our gateways
1:42over here.
1:43All right.
1:44So let's see, what else do we have over here on our site A?
1:48We do have a Linux host over here.
1:50And that's simply so that we have something that we can run connectivity tests
1:54out from
1:54and verify.
1:55And we'll end up setting up a VPN between these two security gateways that will
2:00provide us an encrypted
2:02tunnel over which we can communicate between the offices.
2:06So this is our lab for this course.
2:10Now there's one more thing I want to talk about before we move on.
2:13And that is the idea of traffic flow.
2:17And that's because there's two different ways that traffic really flows in our
2:21environment.
2:22So we're looking at our traffic flows here and we're going to use a couple
2:25different terms.
2:26Now let's focus on the HQ office here.
2:30So with the HQ office, we have our Windows host down here.
2:36And if this Windows host, I'm going to put another host over here.
2:39Let's say we had another host.
2:40There we go.
2:41And if our Windows host here wanted to talk to the other host and vice versa,
2:47this
2:47is known as East West traffic flow.
2:52East to West.
2:54And really what that means is it's internal traffic.
2:57So it's going across our internal network between devices on the inside of our
3:02network.
3:03Now if we were to switch that up a little bit and let's say we wanted to go out
3:07to the
3:08internet and our Windows host here, well, it's sent its traffic across the
3:12network and
3:14out to the internet.
3:15Okay.
3:16So this is known as North South traffic flows.
3:22So that's when we're going out of our network and coming back into the network.
3:25So someone out here on the internet wanted to access our web server and they
3:30came across
3:30the internet through a security gateway and up over to our web server.
3:34Well, that again is North South traffic.
3:36It's entering our network and it's leaving our network.
3:39But when it comes to internal traffic, that's known as East West traffic.
3:44Okay.
3:45Super.
3:46Okay.
3:47Let's just break up the idea of learning new topics and doing some review and
3:50stuff with
3:51looking at the network we're going to be working with in our environment.
3:54And of course, we're going to build this out.
3:56And we're going to do so in even G and actually in the next now, we're going to
3:59start talking
3:59about net.
4:00That's our network address translation and the role it plays in our networks.
4:05And we're going to focus on specifically two types of net and that's hide net H
4:10IDE
4:11like playing hide and go seek.
4:12That's our hide net and then our static net.
4:14Those are the two types of net supported on these checkpoint security gateway.
4:18So I'll see you in the next nugget.
Network Address Translation (NAT)
0:00Let's talk about network address translation or net and the fact that you know
0:05what it's pretty darn important
0:06It allows us to change our network addresses and there are times that we need
0:11to do that for example
0:13Let's say you're on a device here on your computer and you have an address of
0:1910.10.45.12
0:21And you're on your network connected to a switch over here and then over to
0:27Your firewall put over here. We'll put a this is a security gateway here
0:31firewall and it's connected out to the internet
0:33Well, we know that this is a private IP address and we know that because of the
0:41RFC
0:421918 that request for comment has become the standard for private IP addresses
0:48and
0:49basically just IP addressing because
0:53Not only does RFC 1918 define our private IP address ranges
0:59That's our private IPs have which this is one of them. It also defines
1:04Some standardization for NAT which is important absolutely because that's what
1:09we're talking about here
1:10So we know if I have a private IP address here on my machine that I cannot be
1:15routed across the internet
1:16I've got to have a public IP to go across the internet
1:19So we have a public IP. Let's say it's 104.32.16.8
1:25Okay, and that's on the when interface or outside or external interface of our
1:30security gateway
1:31So when our traffic comes across it needs to be
1:34knatted
1:35Right here, okay, so that our source IP changes to a public IP so it can be
1:41routed across the internet
1:42Well, that's one roll that net plays in
1:46Networking it allows us to use private IP addresses on the inside, but still be
1:49able to gain access to the internet
1:52And that's one example of where we would use NAT
1:55So let's talk about
1:57Checkpoints security gateways and the two kinds of NAT that they support the
2:02first one is called hide
2:04NAT, okay pretty straightforward as far as seeing that it's a name and then two
2:11static NAT
2:13Okay, there we go. Those are the two types of NAT that the security gateway
2:18support and we'll be configuring them a little later on
2:20So let's start with taking a look at hide NAT. So that's what we're looking at
2:24here hide NAT
2:25What is that? Well, it's what we just talked about the example I talked about
2:30where we had our computer over here with a 10.10.45.12
2:35Something like that connected to a switch up to a security gateway and we had
2:39the public IP address that
2:42Connected us to the internet and we wanted this public IP address up here and
2:47so when our traffic comes across the network
2:49And it's headed to the internet. Well this hide NAT over here what it does is
2:55it translates or exclates translates our source
2:59IP address
3:02And it does so by replacing
3:05This private IP address with a configured public IP address so it can go across
3:10the internet and be routed and then the
3:12Return traffic will come across and be un-natted if you will and then sent back
3:17over to the original source
3:20Which was our workstation over here?
3:22So this process is known as hide NAT in the checkpoint realm and the name hide
3:29NAT makes a lot of sense because what you're doing is you're hiding
3:32Your private internal IP address behind your public IP address. So it actually
3:38makes sense now other
3:40vendors call it other things like NAT overload. I
3:43Know Cisco uses NAT overload. There's like many
3:462.1
3:48NATing does the same thing or
3:50Pact port address translation. That's another name for it. So all these three
3:56things here are the same name for hide NAT
3:59So if you're familiar with these terms over here. It's the exact same thing
4:04pretty straightforward
4:06Now when using hide NAT we can use two different types of IP addresses on the
4:12security gateway here and here's what I mean
4:15We can configure it to use the IP address on the interface the configured IP
4:21address, okay?
4:22Or we can use a virtual
4:25IP address
4:28So we don't have to use this IP address that's on our when interface. You can
4:33Doesn't hurt anything, but you could also if you had other IP addresses
4:36You can put those in there like 102.43.12
4:40Dot 10 is another address that your organization might have
4:44So what you could do is assign that as a virtual IP and
4:48Then your net translations for hide NAT will use that IP address instead
4:53So you don't have to use the way in IP on your security gateway. You can use
4:57what's called a virtual IP address
5:00Now something else to keep in mind is this is very important that hide NAT and
5:05we're talking about hide NAT
5:07We are only translating
5:09Outbound net traffic so when we create a hide NAT rule or turn it on really
5:16What that is is it only affects traffic going out to the internet now?
5:21Yes, the response does come back through and get unnatted, but here's what I
5:25mean
5:26We're only translating traffic headed outbound to the internet. That's
5:32different if I had a web server on my network over here
5:35And I wanted people to be able to net into it that's different that does not
5:41happen with hide NAT
5:42Hide NAT is put this down here outbound
5:45Traffic, okay, and that is key to understand because the next type of network
5:52and talk about which is static net is
5:54Different it's for inbound and outbound traffic whereas hide NAT is really for
6:00only outbound traffic
6:01There you go. That's your hide NAT. So of course next up is that's right. That
6:06's our static net
6:07now
6:09static net is
6:11When we configure a net rule that maps
6:14one of our internal hosts
6:17To a public IP address, okay?
6:20So let's go ahead and see how this works. So here is our security gateway and
6:24let's say we have over here our
6:27DMZ and in it we have a web server
6:30There you go and there is our connectivity and then of course we have
6:36connectivity out to the internet
6:37So with a static NAT configuration. Let's say this was 10.10.10.100 as our web
6:45server
6:45What we would do is come in here and create a NAT rule and
6:50Actually, it would be a static NAT rule and what we would say is map 10.10.10.
6:5510.10.10.10.10.20
6:57And we would define whatever public IP address we wanted to at this point
7:03So maybe that's it, but we statically configured that
7:07Okay, so that this always
7:11Nats to that and vice versa
7:14So this is for outbound traffic and
7:19Inbound traffic
7:21So this is different from our hidenet which was outbound only this is for in
7:28and out
7:29So in this instance if someone was to be out here on they want to visit our web
7:35server and they go to this public IP
7:37Address down here. Well, it's going to be translated when it hits the firewall
7:41It's going to be translated to this so the firewall knows then to go ahead and
7:48This depends on our access control list with our firewall filtering rules
7:51Of course, we've got a lot all that to happen
7:53But at this point we're just looking at the NAT layer of what's going on?
7:56So there you go folks
7:59That is our static NAT and our hidenet which are the two types of NAT supported
8:04on our checkpoint security gateways
8:07In the next nugget we're going to talk about
8:09Stateful firewalls versus packet filtering firewalls
8:13How they're different and what our checkpoint security gateways. So I'll see
8:18you there shortly
8:20send that traffic through there and of course
Stateful vs Packet Filtering Firewalls
0:00Would you believe that not all firewalls are the same?
0:03That's an absolutely true statement.
0:06And it's for vendor to vendor and technology technology.
0:10And let's talk about this.
0:12So over time, firewalls have changed quite a bit.
0:16So in the early days, we just had what we called a firewall.
0:20And we would create rules and it would filter traffic based on those rules.
0:25And this is known as simply a packet filtering firewall.
0:30And that's because it would inspect every packet going to and fro against our
0:35set of rules.
0:36And you might think, well, don't they still do that today?
0:39And the answer is yes, they do, but they do it in a smarter way.
0:43So we see these firewalls today.
0:47And we see that as they get newer, we get new technologies.
0:51We have not only packet filtering happening, but that has branched out to
0:56things like
0:57intrusion prevention systems and email filtering.
1:02And like any virus and anti malware add ins and sandboxes and all kinds of
1:09things like
1:09threat protection.
1:10And it goes on and on.
1:12So when you take all of these wonderful features and you tie them into a
1:17firewall, usually
1:18in a modularized kind of state, you end up with a next generation firewall or N
1:25GFW.
1:26And that's exactly what the checkpoints security gateway is.
1:29It's a next gen firewall.
1:31So let's talk about packet filtering firewalls versus stateful firewalls.
1:39Now packet filtering we just talked about.
1:41And that was the idea that you had a firewall and you created access lists or
1:45access rules.
1:47And you would say what was permitted outbound and was permitted inbound.
1:51And as that traffic flows through your firewall, all the packets are inspected
1:56against those
1:57rules.
1:58So it was a little rudimentary.
2:01And it is because it's not really watching the state of the communications.
2:06The state is very important.
2:09Think about the TCP three way handshake.
2:11When we have our our send our send act and then our final act and that's our
2:16handshake right
2:17there.
2:18Well, we can watch this.
2:19We can see is a session established or not?
2:24So has the handshake happened and his data being sent back and forth because a
2:30stateful
2:30firewall, well, it watches that.
2:33So let me clear this a little bit here.
2:36Let's take this out of there and this and let's go with our firewall.
2:40Now what we did, we just upgraded to a stateful firewall.
2:45Okay.
2:46Now what this does is you do create your access control list, but works a
2:51little bit different.
2:52I need to create one access control list allowing traffic to go outbound.
2:58Okay.
2:59So it goes out and it does whatever it wants to.
3:01It visits a web server, let's say.
3:04Well, the firewall knows that there should be a response coming back from that
3:09web server.
3:10And it knows that that response is going to go back to the original host here
3:14on the
3:14inside of the network.
3:15So what's going to happen is our stateful firewall is going to create an access
3:19control list
3:20here, a rule allowing this response to come back through the firewall and it
3:26will do that
3:26force automatically.
3:28And then once that traffic is finished flowing through in the session as ended,
3:32well then
3:33it disables the access list that created for that traffic to come back through.
3:38That's pretty cool, right?
3:40Because that means I as an administrator create one rule to allow traffic in
3:45both directions.
3:47Whereas if I had a packet filtering, my packet filtering firewall, I would have
3:52to create
3:53a rule for my outbound and a separate rule for my inbound.
3:56Ah.
3:57So what we see is we're using a little bit of session analysis and intelligence
4:03to create
4:03automatic rules that are only good for a few short seconds while that traffic
4:08flows.
4:08And then that rule that was put in there by our stateful firewall is removed
4:13like we saw.
4:14So that is very handy.
4:16Lows us to filter traffic with less rules.
4:19So it makes your administration easier.
4:22One of the other benefits of stateful firewalls is back to our handshake down
4:26here.
4:27Well, what is a common type of attack is called a sin flood.
4:32And this is a denial of service attack.
4:36And what it is is an attacker out here, let's give him some angry eyes, er, we
4:43'll go out
4:44and send thousands upon thousands of sin connections to a target.
4:51And it could be your firewall that's like, well, when a sin is sent, the
4:55destination will
4:56send a sin act in response, you know, as it should.
5:00So what happens is the attacker does not send a final acknowledgement.
5:04It just doesn't happen.
5:06And that's on purpose because this is a half open session.
5:11What's going to happen is whatever is over here, if it's your firewall, it's
5:14using resources
5:15to keep this half session open while waiting for that acknowledgement.
5:20Now if this happens once, it's no big deal or twice or ten times.
5:24But when you're talking thousands of times, all of that adds up and the idea of
5:29the sin
5:30flood is to use up the resources of your device down here so that nobody can
5:35use it.
5:36So really it takes your device offline.
5:38Well with a stateful packet inspection firewall, it can see that that's
5:43happening and it
5:44can then prevent it.
5:46It can just block the bad guy and not let that happen.
5:49So that's another great feature.
5:51Now let's make a little bit of room because I want to talk about the checkpoint
5:57and kind
5:57of some of the intricacies as a stateful firewall that it has.
6:02So let's talk about this real quick.
6:04Now on this checkpoint security gateway that we're going to be working with,
6:08the state
6:08of the session is stored in the state table.
6:12So this session information right here that we've been looking at and here,
6:16that is stored
6:18on the security gateway in the state table.
6:20So that can always be referenced by rules and by the inspection that's
6:24happening.
6:25Now the inspect engine, so let's put that up here.
6:29The inspect engine is what's responsible for performing stateful packet
6:36inspection.
6:37So that is your inspect engine that takes care of your stateful inspection.
6:43And then all that state information is stored in your state table.
6:47All right.
6:48Super.
6:49Moving on, we got one more topic to cover here.
6:51We're talking about types of firewalls and that is multi-layer firewalls
6:55because traditionally
6:56firewalls worked at layers three and four.
7:00That's traditionally because here we have our network information.
7:03Here we have our TCP and UDP information.
7:06So that's generally what we were filtering on.
7:08We were filtering by IP addresses, port numbers, protocols, those types of
7:13things.
7:13That as time goes on, we get new features and we get what's called a multi-lay
7:19er firewall.
7:20And a multi-layer firewall really is also known as an application layer
7:25firewall because
7:26it can read all the traffic up to and including the application layer where
7:32apps are.
7:33So really we're looking at filtering with all of these layers.
7:38But what does that really mean if I can filter by the network layer up?
7:42So honestly, the greatest feature that we get from this is application insights
7:47and the
7:47ability to filter applications themselves.
7:51And that's why it's also known as an application layer firewall.
7:54So that means we can see all the traffic that are coming and going and not just
8:00the network
8:01information like we did with the older type firewalls, we can see it all.
8:05So that's great because that means that we can do a couple things.
8:09We can actually decrypt HTTPS traffic.
8:14So in the past, we couldn't do that.
8:17And so all you could do is filter by really IP addresses, protocols, port
8:22numbers.
8:23But now we can decrypt that HTTPS encrypted data.
8:27We can inspect the data to make sure it's not malicious.
8:29And then we re encrypt the your HTTPS data and send it on down to you as it's
8:37coming
8:37in.
8:38And come from the internet coming into the firewall decrypts.
8:42It does its inspection, make sure it's safe.
8:43Then it'll re encrypt it and send it down to the workstation.
8:46So that's pretty handy.
8:48Another great feature is simply app filtering.
8:52So we can create rules to prevent certain applications from being used.
8:58And this is lots of applications, things like Facebook.
9:02But not just Facebook in general, you can block individual applications within
9:08it.
9:08So there's like games and there's chat and there's all kinds of other features.
9:13And it's not just Facebook.
9:14It's all the applications that are out there.
9:16It gets very granular.
9:18And what's great about these is they're generally grouped together in labeled
9:23groups.
9:24So it might be a group that has a name of business related.
9:29Okay.
9:30So you could have financial applications like Salesforce CRM and there might be
9:34accounting
9:35applications in there and things like that.
9:38And there will be one for news and there's one for gambling and one for sports
9:44and one for
9:45social media.
9:46You see where I'm going with this.
9:48We can actually block a lot of these things by their group that they're in.
9:53So if we want to block all the social media for everybody except for maybe the
9:56marketing
9:56department or we want to block sports for everybody because we want to keep
9:59productivity
10:00up.
10:01You know, those kinds of things.
10:02So this is where we can actually filter individual applications, which is super
10:07helpful.
10:08In a business environment.
10:10All right.
10:11So that wraps up talking about different types of firewalls.
10:13And really the big takeaway is the idea of a multi-layer firewall, an
10:17application layer
10:18firewall, and then a packet filtering firewall versus stateful, which watches
10:22the state of
10:23the communications and makes decisions based on that.
10:26All right.
10:27Super D-Duper.
10:28Up next, virtual lands.
10:30We get to take a look at VLANs and what they are and why we use them.
10:34So I see you there shortly.
Virtual LANs (VLANs)
0:00So we're starting off with network segmentation and this is the idea that we
0:05take a large network like this
0:07That we see down here and we're going to break it up into something that we
0:11call sub networks or short for that is
0:15Subnets, okay, and the idea behind that is we want to isolate
0:19Devices that are similar to each other and this is why if we take let's say we
0:25put our servers over here in this subnet
0:28And we put our workstations over here in this subnet and we put publicly
0:33accessible
0:34servers
0:37In this subnet and maybe who knows we put like printers in this subnet
0:42Sure, why not well the idea is these can all communicate with each other, okay
0:49both ways and
0:50That's what we want we want everything to be able to communicate however the
0:54idea behind having subnets is
0:56that between each of these we can put
0:59security
1:02services here and so really what we're talking about is we can put security
1:06rules in between all of these and
1:09When we put these security services in place it allows us to put rules in there
1:15saying what can access what now
1:18And an example of this is do our workstation users down here?
1:22Do they need to access every open port on all the servers up here?
1:26Well the answer is probably not they need to access a handful of ports on a
1:30handful of servers and
1:31Then when it comes to these publicly accessible servers over here, do they need
1:35to access our internal servers?
1:36Well, maybe but again only on a couple of ports most likely
1:41So you see where I'm going here when we break these up into smaller network
1:45segments
1:46Then we're able to control the security in between each of them
1:49So for example over here we see our publicly facing servers
1:53So these would be things like web servers and app servers that our customers
1:56are using
1:56Well, if they can come in from the outside and access these
1:59We don't want those on the same network as our internal servers down here
2:05Because then if one of these was to be compromised over here
2:09It could try to jump over and
2:12Compromise one of our other servers or all of our other servers as well so we
2:16can put security rules in between these to help protect against that
2:21So that's why we do network segmentation
2:23So now we know why we do that the next question might be how do we do that?
2:28And we do so using virtual lands and those are called VLands and that's because
2:33if I didn't use some type of
2:35Virtual let's key word here virtualization in here and I wanted separate
2:40networks
2:41I'd have to have a switch over here for my servers to be connected to and I'd
2:46have to have a switch over here for my
2:48Workstations to be connected to and one for my public servers
2:53So I have some servers over here that are publicly accessible and then if I had
2:57a switch over here for
2:59Maybe printers could be maybe I have a switch over here that's connected to
3:05servers that contain
3:07Intensive data so you'll see I have to put switches on all of these and that's
3:12additional network equipment to plug these in
3:15And if I have them in different areas of the building that I need more and more
3:18of them
3:18Well, that just really isn't very efficient
3:21So let's go ahead and clear this off and see how we can make this more
3:26efficient and it's really through the use of the
3:29VLands that I mentioned and the way this works is if I have a switch over here
3:34There we go, and I've got all these ports on it and we'll just do these quick
3:38little ports here and
3:39I start using VLands now VLands use something called tags or tagging so they
3:46add tags to our data and the way this works is within
3:50the
3:52Layer two of our OSI model data link layer within the data that's called frames
3:57here a piece of that data is a VLAN ID
4:02And that goes right in there so as this data traverses this piece of network
4:06equipment, which is a switch
4:08It knows what VLAN it's a part of so what these VLANs are virtual lands and
4:14What we do is if I had let's say I wanted this to be VLAN number 10 and I
4:21wanted this port and this port and this port and this port all in VLAN 10
4:25Well then anything I plug into these let's say servers for instance
4:31So I'll put a little server down here. Well the servers can only talk to other
4:35servers that we have plugged in here
4:37And if I used maybe this port and this port and a whole bunch of these ports
4:42maybe for workstations
4:43We'll call this VLAN 20 and there's going to be for your general computer work
4:48stations
4:48They can only talk to each other at this point
4:50So we've isolated them
4:52Virtually that's the keyword their virtual because we see it's one physical
4:57switch
4:57And if I wanted to do this without VLANs, I'd have to have a separate switch
5:01for each of these and again
5:02Let's just not efficient so we can do this by creating virtual lands and we can
5:08tag our data
5:09And that's how the switch devices know what data goes on what VLAN is pretty
5:14straightforward actually and it's pretty
5:16Simplified and easy to understand and use now
5:19What if I did want the servers to talk to my workstations or vice versa?
5:25Well, what would happen is these switches they plug into a network core of some
5:31sort and really it's going to be something that provides routing
5:34To the data and this happens at layer three of the OSI model that's our network
5:40layer and what happens is these all get passed up
5:43To the router or it could be a multilayer switch that provides routing
5:48functions or could be a firewall that provides routing functions
5:51It's whatever device provides the routing for the network
5:54So when that data gets up there it sees that there is a VLAN 10 and it has an
5:59interface for that and it might be a virtual interface
6:02Not a physical and necessarily it sees if there's a VLAN 20 and then what I can
6:06do is I can create rules
6:08that allow 10 to talk to 20 and
6:11Vice versa and I could say only on port 80 or port 53 or port
6:17One 10 whatever it is that I want them to talk to or I could say all ports if I
6:21wanted to
6:22Doesn't matter but I create security rules that allow them to communicate with
6:25each other and that goes back to
6:27How we saw that we could provide security rules in between each of our subnet
6:33or subnetworks and that's how we create subnetworks
6:36We use VLANs or virtual lands and VLANs
6:40Tag their traffic like we saw here with a number and that's how the network
6:46devices know what traffic
6:48Belongs to what VLAN. All right that wraps up our network segmentation and VLAN
6:53s next up
6:54We're gonna be talking about virtual private networks or VPNs in the next nug
6:58get. So I'll see you there shortly
Virtual Private Network (VPN)
0:00All right VPNs, what are they? Well, they are a virtual private network. Now
0:07let's
0:07dissect that. So virtual, okay, got that. So it's not necessarily a physical
0:13connection. It's a virtual connection. It is private. That's good because we
0:18like privacy. It helps us to ensure confidentiality, which is part of our CIA
0:26triad and it is a network to allows us to communicate. So what it does is it
0:32allows
0:33us to securely connect networks and devices across insecure networks. So if I
0:38have a network over here and a network over here, let's say A and B and both of
0:43them have an internet connection. There we go out to the internet. Well, the
0:49internet itself is insecure, okay, because it's the wild, wild west of networks
0:55out there. It's owned by lots of different organizations and companies and it's
1:00just not secure. It's not your private network. So wouldn't it be great if
1:05there
1:05was a way we could create a kind of tunnel that goes across the internet and
1:11connects these two networks together. And in this tunnel, nobody can see
1:16inside of it. This is all encrypted data. So it is confidential. It's private.
1:21Well, that's what a VPN is exactly. It allows us to create a connection between
1:27networks across an insecure network. Hey, that is pretty darn awesome. So let's
1:36take
1:36a look at how this works. All right, our VPN here, what we have is we've got
1:41network A over here and network B over here and of course the internet here.
1:45And
1:45what we could use is a VPN router or a firewall that has VPN services on it. We
1:53need some type of appliance that does VPN stuff, okay? We need one at both ends
1:59.
1:59Then we go ahead and we configure them to talk to each other and to set up a
2:04VPN
2:04between them. And then we end up with our VPN tunnel that goes between the
2:09networks. So we can then communicate across the tunnel and that data is secure.
2:19It maintains its confidentiality. So again, we can work to ensure our CIA
2:23tried there. And that is a network to network VPN. But we also have something
2:29called a client to network VPN. And that's where we could have someone down
2:33here
2:33on a computer or a laptop or something. We could say a teleworker and this
2:39teleworker could have a VPN client software on their computer and they fired up
2:44.
2:44They put in their credentials. And what it does is it goes out and it talks to
2:48a
2:49VPN router or such. And it creates a tunnel between the computer itself and the
2:58VPN device on the network. So that means all the data that's going from this
3:03computer to this network over here, all of it is encrypted. So this
3:09teleworker could be at a coffee shop or they could be at some airport Wi-Fi or
3:15working from home. Doesn't matter. They could be anywhere and they have a
3:18secure
3:19encryption back to their home office network. And that is pretty darn cool.
3:25Now when it comes to VPNs, there's a couple of protocols. There's actually
3:29several protocols that are used to make this happen. We're going to talk about
3:33two of them. These are the most common. The first one is IP sec and that is IP
3:39is
3:39in layer three of the OSI model or IP addresses, IP security. And that is a
3:47very
3:48common protocol used for network to network VPNs. Probably the most common
3:57actually. And then there's SSL TLS VPNs. And if you go and visit a secure
4:03website,
4:04you're using SSL TLS to encrypt your communications with the secure website.
4:10Well, we use that same protocol oftentimes for a device to network VPN. And
4:18that
4:18was where we saw our teleworker connecting into their home office network. And
4:25that was over a remote access VPN. And oftentimes those will use SSL TLS for
4:33their protocol. But they can also use IP sec absolutely. But it's just more
4:37common nowadays to use SSL TLS. So here you go. Those are a couple of the
4:41common
4:42protocols we use to create VPNs. And what VPNs are, how we can secure our
4:48communications between networks across untrusted networks. And that's
4:52actually how we'll secure our network communications between our HQ site and
4:56our site A once we get into the lab. Well, that wraps up our VPNs. Next up is
5:00Intrusion Prevention Systems or IPSs. So I'll see you there shortly.
Intrusion Prevention System (IPS)
0:00Let's talk about intrusion prevention systems or IPSs.
0:05So what are they?
0:06Well, Internet Shell, an intrusion prevention system or IPS
0:10is a system that, well, it analyzes network traffic
0:14and if it's malicious, it will block the traffic.
0:17It's pretty much that simple.
0:19So let's talk about how they work.
0:21How do the IPSs work?
0:24Well, IPSs themselves have a database
0:29of known malicious traffic.
0:32Okay.
0:33And that is key there, the known part.
0:35Known, so I'm going to put that right there.
0:38And then we'll put over here, malicious data.
0:43And this known malicious data has a signature to it.
0:48And it's what that data looks like to the network,
0:52as it goes across the network.
0:54So our IPSs, they have this database here,
0:58of known malicious data that's known as signatures.
1:02So they have a signature database.
1:05And it's very important that we understand this part right here.
1:08Known.
1:09Yes.
1:10So IPS is block known malicious data.
1:13Now, if it's a new type of attack that hasn't been identified yet,
1:18so it was something we call a zero day,
1:20well, then your IPS really probably isn't going to block that.
1:24Unless it has the ability to use heuristics
1:27and look for traffic patterns, not just signatures.
1:31So it just depends on what type of IPS you're dealing with.
1:35Now, another key thing about this is that this database here
1:39has to be kept up to date.
1:42Very important.
1:43It will check for updates multiple times a day
1:45because new signatures are bringing a release
1:47by vendors multiple times a day.
1:50And the sooner you get those updates,
1:52the better off you're going to be,
1:53because if you stop doing those updates,
1:55like maybe you stop paying for a subscription for updates,
1:58well, then your database over here has old data in it.
2:03That old known data and all the new knowns
2:05and the new signatures from the new types of attacks,
2:08well, you're not going to be protected against those.
2:10So up to date, you got to keep your databases,
2:13your signature databases, definitely always up to date.
2:18Very key, very important.
2:20So now that we know what it is, what it does,
2:23well, where do we put it in our network?
2:26That's the next question.
2:27Because there's two ways you can put an IPS in your network.
2:32It can be in line,
2:35okay, or attached.
2:38And they're very different.
2:40So in line means that maybe the internet's here
2:43and you've got a connection coming in,
2:45you've got your security gateway here,
2:47and then you have the rest of your network
2:50with devices and such on the network there.
2:53Okay, so in line would mean that the wire or cable
2:59that the network data is going across must go through the IPS
3:04in order to get to the network or that network's segment.
3:08And this is very important to understand that an IPS
3:12in order for it to block most of the traffic,
3:16it has to be in line.
3:19Okay, it can't be simply attached.
3:21And I'll show you why here shortly.
3:23So being in line, the traffic has to go through this device.
3:26So it's at that point, you can say,
3:28you know what, this is malicious.
3:30I'm going to block you.
3:31You're not going to go to my network.
3:33And within the checkpoint security gateway,
3:36we have the ability to turn on an IPS blade in here.
3:41So an IPS that runs in software on your security gateway.
3:46Which means it is in line.
3:49And that's what we want.
3:51Okay, so the attached, let me show you what that looks like.
3:55The attached is generally used not to prevent data,
3:59but to collect data.
4:00See what's going on to do some analysis.
4:02And here's what that looks like.
4:04If you have your internet and we had maybe a security gateway over here.
4:08And it connects into our network where we've got our hosts.
4:12Well, what we would do is I would put the IPS over here.
4:17And it's not in line at all.
4:19There's nothing behind the IPS.
4:21The traffic still goes through to the endpoint.
4:24It's just a copy of the traffic gets into the IPS to be analyzed.
4:28Well, in this instance, the IPS can not block that traffic.
4:35It just can't because the traffic's already passed through.
4:38So it's in this instance that we would only be collecting and analyzing data
4:43and not blocking malicious data.
4:45And that's really honestly just not the best scenario.
4:48So at this point, I want you to understand this there.
4:51But we will not be doing this.
4:53We'll just line that out.
4:55This is what we're working on.
4:57We'll be using the IPS blade within the checkpoint security gateway.
5:01All right.
5:02So that is your intrusion prevention system and the IPS
5:06and the idea that it uses signatures to identify malicious traffic
5:11and that is known malicious traffic.
5:14Right?
5:15And you got to keep those signatures up to date.
5:17And we're deploying it in line as an IPS blade within our checkpoint security
5:24gateway.
5:25All right.
5:26Well, that wraps up this skill, which means it's time for validation.
5:30So I'll see you there shortly.
Validation
0:00Welcome to Validation!
0:02So we've got a few review questions we're going to do here.
0:05And starting with question one, what RFC is the best practice guide for NAT?
0:10And we did talk about one of these RFCs and it was also the same RFC that
0:14defines private
0:15IP addressing and that is RFC 1918.
0:18That's right, move it on question number two.
0:22Here we go, which best describes North South traffic?
0:26Is it traffic leaving your network and coming into your network?
0:30Traffic between applications inside your network, traffic between users on the
0:34internet and
0:35Google or traffic between hosts inside your network.
0:38Now North South traffic is the traffic that's leaving your network and coming
0:42into your
0:42network.
0:43It's that top one there.
0:44That is the correct answer.
0:46Traffic between apps inside your network.
0:48That is just your east west and traffic between hosts inside your network again
0:52east
0:53west.
0:54And then this one, this one is a little different.
0:55It's going to be a user on the internet and Google.
0:57Well, that's all internet base.
0:59That's nothing to do with my network.
1:01So it is traffic leaving your network and coming into your network that is your
1:04North
1:04South traffic.
1:05All right, moving on to question number three.
1:09Which of the following inspects traffic information and stores it in the state
1:12table?
1:13We talked about this and the key word is right here.
1:16There you go.
1:17That's it.
1:18It inspects that traffic.
1:20That is your inspect engine.
1:24That is right.
1:25Very good.
1:26Moving on to number four.
1:28True and false.
1:29Here we go.
1:30Stateful inspection is better than simple packet filtering because only one
1:34rule is required
1:35for each connection.
1:36Remember we talked about the difference between a stateful inspection firewall
1:40and a simple
1:41packet filtering firewall is that stateful.
1:43It watches the state and it creates automatic firewall rules for you to allow
1:48return traffic
1:49coming back.
1:50You don't need to create one access rule for a connection.
1:54It will allow the other to come back through the response that is.
1:57So yeah, that's true.
2:00And on to number five or final question.
2:02Here we go.
2:03Which type of net is supported on the checkpoint security gateway and allows
2:09incoming and outgoing
2:11traffic?
2:12Now we talked about two types of net that are supported and that was high net
2:16and static
2:17net.
2:18So dynamic and host, that's not even an option in this question.
2:22So is it going to be a high net or static?
2:24Now high net was only for outgoing traffic.
2:28We're looking for net that allows incoming and outgoing traffic.
2:33So that's going to be our static net.
2:36And that wraps up our validation review questions and wraps up this skill.
2:41I hope it's been informative for you and I'd like to thank you for viewing.
2:44[BLANK_AUDIO]
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year