Unit 3: Firewalls
3a. Identify basic facts and terms pertaining to the concepts of firewalls.
Group Policy Object (GPO) Configurations
Defintion
Windows OS, through group policies, can be configured by network administrators to change which Windows features are avaialble to users and to manage system security.
User Settings
Apply to a user no matter which machine is used. These policies are used to restrict user abilities on desktops.
Windows Settings | Scripts User Settings Identification - This policy configures scripts that execute when a user logs on or off.
Windows Settings | Internet Explorer Maintenance - This policy is used to configure settings in Internet Explorer (IE) such as website favorites and default home page.
Administrative Templates | Control Panel - This policy enables or disables Windows Control Panel features to control what users can change in the system.
Administrative Templates | Desktop - This policy controls what desktop icons appear on the system.
Administrative Templates | Start Menu and Taskbar - This policy controls what items appear in the Start menu.
Computer Settings
Windows Settings | Scripts (Startup/Shutdown) - This implements scripts to allow automated processes to run during system startup or shutdown
Security Settings | Account Policies - This policy configures user accounts.
Security Settings | Local Policies
Local Policies contains user right configuration options, auditing, and other security settings included banners.
Security Settings | Windows Firewall with Advanced Security - This policy configures what software is allowed to run on a system.
Security Settings | Software Restriction Policies - This policy configures what software is allowed to run on a system.
Security Settings | Advanced Audit Policy Configuration - This policy controls the system auditing process and sets what types of events to audit.
Enterprise Configurations
Proxy Servers
A type of firewall that resides between a user’s computer and the Intenet. Proxies are typically associated with being able to control outbound communication by limiting which web sites an employee can visit.
Forward and Reverse Proxy
A reverse proxy is used in a scenario in which you want a system on the Internet to be able to send a request to one of your internal systems, such as a web server or mail server.
Transparent Proxy
Does not require any software or additional configuration on the client.
Nontransparent Proxy
Requires you to install a proxy client, or agen, and configure the applications to point to the proxy server for outbound requests.
Access control Lists (ACL)
Network administrators secure information on the organization’s network by implementing permissions on the files and folders. Maintaining confidentiality.
File System ACL
There are two steps to securing folders on a Windows Server.
New Technology File System (NFTS) Permissions - ALl modern Windows OSs should be using NFTS rather than legacy file systems like FAT32. Once you set NFTS permissions, they will apply when the user accesses the folder either locally or from acroos the network.
Shared Folder Permissions - The second step in setting permissionsm after securing the folder with NFTS permissions, is to “publish” the folder, in other words to share it on the network with shared user permissions. When a share permission is applied to a folder, remember thatthe permission is applied to all subfolders and files as well.
Active Directory (AD)
Directory service (not just a directory) that stores information about all network resources.
Networking Access Control List
Routers can control which what traffic can enter or leave the network. Cisco routers have two common types of access lists. standard access lists and extended access lists.
Software
Designed to protect systems on one side of the firewall from systems on the side. By default, administrators should configure firewalls to block all traffic. From there, configure exceptions to the firewall rules to specifically allow traffic through.
Software-based Firewall
Also known as an application-based firewall, host based firewall, or personal firewall.
Block incoming traffic
Block outgoing traffic
Notifications
A default rule
Create rules
Windows Firewall
Allow a program or feature through Windows Firewall
Change notification settings
Turn Windows Firewall on or off
Restore defaults
Advanced settings
Hardware
A hardware-based firewall sits at the edge of a network and controls what traffic is allowed to enter and leave the network,
Packet-Filtering Firewall
Stateless firewall, a packet-filtering firewall can block or allow traffic through,
Stateful Packet Inspection Firewall
Can filter traffic based on the sources and destination IP address or port number. It can also look at the context of the conversation and determine if the packet should be received at that point in the conversation.
Application-Layer Firewall
Combines features of the packet-filtering firewall and the stateful packet inspection firewall. Also known as application/multipurpose proxy servers.
Linux Firewall
Iptables is a command-time firewall utility that uses policy chains to allow or block network taffic. Iptables gets its name from the table of rules that control what taffic is allowed to enter or leave the system or to be forwarded on to another system.
Input
Output
Forward