84
Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D.

Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

  • View
    225

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Hardware Firewalls: Advanced Feature

© N. Ganesan, Ph.D.

Page 2: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Chapter Objective

• Discuss various additional and important features of a firewall– DHCP– Virtual server– Enabling applications that require multiple

connections– Filters (IP, MAC etc. )– Firewall rules regulating traffic– DMZ– Remote management– etc.

Page 3: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Module

WAN Side IP Specifications © N. Ganesan, Ph.D.

Page 4: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

WAN Side IP

• In the case of the firewall/switch, an address for the firewall must be specified for both the WAN side and the LAN side– The LAN side address will be a private

address that is not visible to the Internet

Page 5: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

IP Options

• Static IP– Demonstrated early

• Dynamic IP– Cable modem and LAN Internet sharing– Could also be employed in the case of

DSL

• PPPoE– DSL specific

Page 6: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 7: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 8: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 9: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 10: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 11: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 12: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 13: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Module

LAN Side IP Specification© N. Ganesan, Ph.D.

Page 14: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

IP Options

• Generally speaking, a static private IP is specified for the firewall/switch for the LAN side

Page 15: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 16: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Module

DHCP© N. Ganesan, Ph.D.

Page 17: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

DHCP Enabling

• DHCP can be enabled to deliver dynamic IP addresses for all the LAN side clients

• At the same time, static IP addresses can be assigned to selected clients based on their MAC addresses

Page 18: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 19: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Change this slide, make it enabled.

Page 20: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 21: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 22: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Module

Advanced Features© N. Ganesan, Ph.D.

Page 23: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Advanced Features

• Virtual servers• Applications• Filters• Firewalls• DMZ

Page 24: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Virtual Servers

• Opening a port through the firewall to give access to a web server that is hosted on the private LAN

Page 25: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 26: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Web Server Settings

• Private IP address: 192.168.0.1• Public Port: 80• Private Port: 80• Availability: Always

Page 27: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 28: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Another Way to Set the Web Server Pass Through

• Select from the virtual server list and edit the entry

Page 29: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 30: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Edit

Page 31: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 32: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Other servers

Page 33: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Module

Special Applications© N. Ganean, Ph.D.

Page 34: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Opening Ports for Special Applications

• There are special applications that would require one or more ports to be opened through the firewall/switch

• Examples include Internet chat, telephony applications etc.

Page 35: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 36: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Module

Filters© N. Ganesan, Ph.D.

Page 37: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Filters and Blockers

• IP Filters– LAN clients can be selectively blocked from

accessing the Internet based on their IP address

• MAC Filters– The same as above, but the filter is based

on MAC address of a client• URL Blocking

– URLs can be blocked from being accessed• Domain Blocking

– Access to domains can be blocked as well

Page 38: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 39: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

IP Filters

• IP filters can be applied altogether to a client or they can be applied to specific ports of a client

• A range of IP addresses and a range of port numbers can be specified to be filtered

Page 40: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

IP range can be specified.

A range of ports can be specified.

Page 41: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 42: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Module

Firewall Rules© N. Ganesan, Ph.D.

Page 43: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Firewall Rules

• Firewall rules can be specified to allow or block traffic entering the firewall or passing through the firewall/switch

• For example, pinking the firewall from the Internet (WAN) side can be disabled using firewall rules

Page 44: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 45: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Module

Creating Demilitarized Zones (DMZ)

© N. Ganesan, Ph.D.

Page 46: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

DMZ Defined

• Computers in the DMZ by pass the control of the firewall– In other words, for all practical

purposes, they could be considered as being directly connected to the Internet

Page 47: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 48: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Module

Firewall Tools© N. Ganesan, Ph.D.

Page 49: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Tools

• Administrative– Set passwords and enable or disable remote

management

• Time– Set the current time and date

• System– Store and load firewall settings

• Firmware upgrade• Miscellaneous tools

Page 50: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Administrative Tools

• Set administrator and a user password

• Enable the firewall to be managed from a remote computer probably over the Internet– In general, it is not desirable to

enable this option for security reasons

Page 51: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

1

2

3

Page 52: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Module

Set Time© N. Ganesan, Ph.D.

Page 53: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 54: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

System

• Store current firewall settings to the hard drive

• Load a previously stored firewall settings from the hard drive

• Restore factory default settings for the firewall

Page 55: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

1

2

3

Page 56: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Module

Firmware Upgrade© N. Ganesan, Ph.D.

Page 57: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 58: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 59: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Module

Miscellaneous Tools© N. Ganesan, Ph.D.

Page 60: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Miscellaneous Tools

• Pinging a host name or an IP address• Restarting the firewall

– Probably to activate any changes made

• Block the pinging of the firewall from the Internet (WAN) side

• Enabling UPNP and gaming mode• Allow VPN traffic based on PPTP and

IPSec to pass through • Enable dynamic DNS service

Page 61: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Ping Test

Page 62: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 63: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Block Pinging from the Internet Side

Page 64: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 65: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Enabling UPNP Settings and Game Mode

Page 66: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 67: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Allowing Virtual Private Networks (VPN) Connections

Page 68: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

VPN Connections

• Firewall can be set to allow VPN links to the clients on the LAN side for the two popular protocols used in implementing VPNs

Page 69: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 70: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Module

Status Reporting© N. Ganesan, Ph.D.

Page 71: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Status Reporting

• Display LAN and WAN settings • Log and display the log of activities

– Attacks, dropped packets etc.

• Display traffic statistics– Number of packets transmitted and

received on the WAN (Internet – External) and LAN (Internal) side

Page 72: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Display of WAN and LAN Settings

Page 73: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 74: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Log of Activities

Page 75: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Log of Activities

• System activity• Debug information• Attacks• Dropped packets• Notice• Note: The log can also be

transmitted to an administrators email

Page 76: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 77: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 78: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 79: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 80: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Traffic Statistics

Page 81: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 82: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

Additional Help

Page 83: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D
Page 84: Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D

The End