Unit 3: Firewalls

3a. Identify basic facts and terms pertaining to the concepts of firewalls.

Group Policy Object (GPO) Configurations

Defintion

Windows OS, through group policies, can be configured by network administrators to change which Windows features are avaialble to users and to manage system security.

User Settings

Apply to a user no matter which machine is used. These policies are used to restrict user abilities on desktops.

  • Windows Settings | Scripts User Settings Identification - This policy configures scripts that execute when a user logs on or off.

  • Windows Settings | Internet Explorer Maintenance - This policy is used to configure settings in Internet Explorer (IE) such as website favorites and default home page.

  • Administrative Templates | Control Panel - This policy enables or disables Windows Control Panel features to control what users can change in the system.

  • Administrative Templates | Desktop - This policy controls what desktop icons appear on the system.

  • Administrative Templates | Start Menu and Taskbar - This policy controls what items appear in the Start menu.

Computer Settings

  • Windows Settings | Scripts (Startup/Shutdown) - This implements scripts to allow automated processes to run during system startup or shutdown

  • Security Settings | Account Policies - This policy configures user accounts.

Security Settings | Local Policies

  • Local Policies contains user right configuration options, auditing, and other security settings included banners.

  • Security Settings | Windows Firewall with Advanced Security - This policy configures what software is allowed to run on a system.

  • Security Settings | Software Restriction Policies - This policy configures what software is allowed to run on a system.

  • Security Settings | Advanced Audit Policy Configuration - This policy controls the system auditing process and sets what types of events to audit.


Enterprise Configurations

Proxy Servers

A type of firewall that resides between a user’s computer and the Intenet. Proxies are typically associated with being able to control outbound communication by limiting which web sites an employee can visit.

Forward and Reverse Proxy

A reverse proxy is used in a scenario in which you want a system on the Internet to be able to send a request to one of your internal systems, such as a web server or mail server.

Transparent Proxy

Does not require any software or additional configuration on the client.

Nontransparent Proxy

Requires you to install a proxy client, or agen, and configure the applications to point to the proxy server for outbound requests.

Access control Lists (ACL)

Network administrators secure information on the organization’s network by implementing permissions on the files and folders. Maintaining confidentiality.

File System ACL

There are two steps to securing folders on a Windows Server.

  • New Technology File System (NFTS) Permissions - ALl modern Windows OSs should be using NFTS rather than legacy file systems like FAT32. Once you set NFTS permissions, they will apply when the user accesses the folder either locally or from acroos the network.

  • Shared Folder Permissions - The second step in setting permissionsm after securing the folder with NFTS permissions, is to “publish” the folder, in other words to share it on the network with shared user permissions. When a share permission is applied to a folder, remember thatthe permission is applied to all subfolders and files as well.

Active Directory (AD)

Directory service (not just a directory) that stores information about all network resources.

Networking Access Control List

Routers can control which what traffic can enter or leave the network. Cisco routers have two common types of access lists. standard access lists and extended access lists.

Software

Designed to protect systems on one side of the firewall from systems on the side. By default, administrators should configure firewalls to block all traffic. From there, configure exceptions to the firewall rules to specifically allow traffic through.

Software-based Firewall

Also known as an application-based firewall, host based firewall, or personal firewall.

  • Block incoming traffic

  • Block outgoing traffic

  • Notifications

  • A default rule

  • Create rules

Windows Firewall

  • Allow a program or feature through Windows Firewall

  • Change notification settings

  • Turn Windows Firewall on or off

  • Restore defaults

  • Advanced settings

Hardware

A hardware-based firewall sits at the edge of a network and controls what traffic is allowed to enter and leave the network,

Packet-Filtering Firewall

Stateless firewall, a packet-filtering firewall can block or allow traffic through,

Stateful Packet Inspection Firewall

Can filter traffic based on the sources and destination IP address or port number. It can also look at the context of the conversation and determine if the packet should be received at that point in the conversation.

Application-Layer Firewall

Combines features of the packet-filtering firewall and the stateful packet inspection firewall. Also known as application/multipurpose proxy servers.

Linux Firewall

Iptables is a command-time firewall utility that uses policy chains to allow or block network taffic. Iptables gets its name from the table of rules that control what taffic is allowed to enter or leave the system or to be forwarded on to another system.

  • Input

  • Output

  • Forward