Phân loại tường lửa Checkpoint, Cisco ASA, Astaro, Cyberoam,… cài trên máy tính ISA Server, IPCop, Smoothwall, Pfsense,… SOPHOS, Palo Alto,….... Là loại Firewall có độ phức tạm ca
Trang 1CHƯƠNG 5
TƯỜNG LỬA
Trang 2Nội dung
Trang 3Nội dung
Trang 4Tường lửa là gì
bị, ảo hóa hay phần mềm bảo mật được sử dụng
để quản lý luồng gói tin qua nó : cho phép (permit) hay cấm (deny).
Trang 5Nội dung
Trang 6Phân loại tường lửa
Checkpoint, Cisco ASA, Astaro, Cyberoam,…
cài trên máy tính
ISA Server, IPCop, Smoothwall, Pfsense,…
SOPHOS, Palo Alto,…
Trang 7Phân loại tường lửa
hình OSI ???
Trang 8Phân loại tường lửa
được chia làm 3 loại chính :
Simple Packet Filter Firewalls
Stateful Packet Filter Firewalls
Application Level Firewalls
Trang 9Phân loại tường lửa
Kiểm tra gói tin qua firewall bằng cách so sánh nó với những nguyên tắc (Rule) đã được đặt ra, để quyết định gói tin đó được cho phép hay bị từ chối.
Những thông tin sẽ được kiểm tra :
Trang 10Phân loại tường lửa
Trang 11Phân loại tường lửa
Trang 12Phân loại tường lửa
Hoạt động ở Layer 2, Layer 3 và Layer 4
Firewalls :
Lower Attack Footprint
Less Susceptible to Spoofing
Easy Black hole configuration
Less Resource Intensive
Trang 13Phân loại tường lửa
Còn được gọi Application-Proxy Gateways.
Là loại Firewall có độ phức tạm cao nhất do có khả năng điểu khiển truy cập từ Layer 2 đến Layer 7
Deep Packet Inspection : kiểm tra chi tiết gói tin nên có khả ngăn chặn các ứng dụng Instant Message, Peer to Peer,…
Hoạt động ở Layer 7
Trang 14Phân loại tường lửa
Less Susceptible to TCP/IP Vulnerabilities
Có khả năng tạo rule ngăn cản gói tin đã mã hóa
Trang 15Nội dung
Trang 16Nội dung
Trang 17Next Generation Firewall
SECURITY
APPLICATION AWARENESS
Trang 18Next Generation Firewall
Trang 19Version | Service | Total Length
ID | Flags | Fragment TTL | Protocol | IP Checksum
Source IP Address Destination IP Address
IP Options
Source UDP Port
Destination UDP Port Checksum
Source212.56.32.49
Destination65.26.42.17Source Port
823747
Dest Port80Sequence
28474
Sequence2821Syn state
SYN
IP Optionnone
Stateful Packet Inspection
Stateful Packet Inspection
Stateful is limited inspection that can only block on ports
No Data Inspection!
Trang 20Firewall Traffic Path
INSPECT
Version | Service | Total Length
ID | Flags | Fragment TTL | Protocol | IP Checksum
Source IP Address Destination IP Address
IP Options
Source UDP Port
Destination UDP Port Checksum
Signature Database
ATTACK-RESPONSES 14BACKDOOR 58BAD-TRAFFIC 15DDOS 33DNS 19DOS 18EXPLOIT >35FINGER 13FTP 50ICMP 115Instant Messenger 25IMAP 16INFO 7Miscellaneous44MS-SQL 24MS-SQL/SMB 19MULTIMEDIA 6MYSQL 2NETBIOS 25NNTP 2ORACLE 25P2P 51POLICY 21POP2 4POP3 18RPC 124RSERVICES 13SCAN 25SMTP 23SNMP 17TELNET 14TFTP 9VIRUS 3WEB-ATTACKS 47WEB-CGI 312WEB-CLIENT
INSPECT
Stateful Packet Inspection
Deep Packet Inspection
Deep Packet Inspection
Deep Packet Inspection inspects all traffic moving through a
device
Trang 21Stateful Packet Inspection
Version | Service | Total Length
ID | Flags | Fragment TTL | Protocol | IP Checksum
Source IP Address Destination IP Address
IP Options
Source UDP Port
Destination UDP Port
UDP Length
UDP Checksum
DATA
Version | Service | Total Length
ID | Flags | Fragment TTL | Protocol | IP Checksum
Source IP Address Destination IP Address
IP Options
Source UDP Port
Destination
UDP Port Checksum
Version | Service | Total Length
ID | Flags | Fragment TTL | Protocol | IP Checksum Source IP Address Destination IP Address
Version | Service | Total Length
ID | Flags | Fragment TTL | Protocol | IP Checksum Source IP Address Destination IP Address Version | Service | Total Length
ID | Flags | Fragment TTL | Protocol | IP Checksum Source IP Address Destination IP Address
Signature Database
ATTACK-RESPONSES 14BACKDOOR 58BAD-TRAFFIC 15DDOS 33DNS 19DOS 18EXPLOIT >35FINGER 13FTP 50ICMP 115Instant Messenger 25IMAP 16INFO 7Miscellaneous44MS-SQL 24MS-SQL/SMB 19MULTIMEDIA 6MYSQL 2NETBIOS 25NNTP 2ORACLE 25P2P 51POLICY 21POP2 4POP3 18RPC 124RSERVICES 13SCAN 25SMTP 23SNMP 17TELNET 14TFTP 9VIRUS 3WEB-ATTACKS 47WEB-CGI 312WEB-CLIENT
Comparing…
Application Attack, Worm or Trojan Found!
Deep Packet Inspection
Deep Packet Inspection / Prevention
Deep Packet Inspection with Intrusion Prevention can find and block, application vulnerabilities,
Trang 22Firewall Traffic Path
Stateful Packet Inspection
Version | Service | Total Length
ID | Flags | Fragment TTL | Protocol | IP Checksum
Source IP Address Destination IP Address
IP Options
Source UDP Port
Destination
UDP Port Checksum
Version | Service | Total Length
ID | Flags | Fragment TTL | Protocol | IP Checksum
Source IP Address Destination IP Address
IP Options
Source UDP Port
Destination
UDP Port Checksum
Signature Database
ATTACK-RESPONSES 14BACKDOOR 58BAD-TRAFFIC 15DDOS 33DNS 19DOS 18EXPLOIT >35FINGER 13FTP 50ICMP 115Instant Messenger 25IMAP 16INFO 7Miscellaneous44MS-SQL 24MS-SQL/SMB 19MULTIMEDIA 6MYSQL 2NETBIOS 25NNTP 2ORACLE 25P2P 51POLICY 21POP2 4POP3 18RPC 124RSERVICES 13SCAN 25SMTP 23SNMP 17TELNET 14TFTP 9VIRUS 3WEB-ATTACKS 47WEB-CGI 312WEB-CLIENT
Deep Packet Inspection
Virus File!
AuctionSite
Gateway Anti-Virus Anti-Spyware
Content Inspection Gateway Anti-Virus and Content Control
Trang 23Deep Packet Inspection
AV Database IPS Database Spy Database
Content Filtering Database
Gateway Anti-Virus Anti-Spyware
Content Inspection Security Must Be Updated
Trang 24Next Generation Firewall
Trang 25Application Traffic Visualization
Trang 26Network Analysis Tools
Do I have P2P on my Network?
Trang 27Network Analysis Tools
Trang 28Immediate Application Control
Trang 29Network Analysis Tools
“Who’s watching YouTube?”
Trang 30Network Analysis Tools
“Who’s watching YouTube?”
Trang 32Identify Top Bandwidth Users
Trang 33Connection Tracking by Country
Trang 34Trace & Identify Network Connections
Trang 35Next Generation Firewall
SECURITY APPLICATION AWARENESS
• HIGH THROUGHPUT
• NO LATENCY
PERFORMANCE
Trang 36Nội dung
Trang 37Cyberoam in Gateway Mode
Network:192.168.0.x/24
Router IP:61.0.5.1/29
Switch
Switch Console
Trang 38WAN Zone
LAN Zone
DMZ Zone Local Zone
Gateway mode have Four default zone
LAN Zone: Network connected to LAN interface of Cyberoam WAN Zone: Network connected to WAN interface of Cyberoam DMZ Zone: Network connected to DMZ interface of Cyberoam Local Zone: IP Addresses assigned on Cyberoam interfaces falls
under Local Zone
Zone information when Cyberoam is in Gateway mode
Trang 39Cyberoam in Bridge Mode
192.168 0 5 255.255.255 0
IP address of the Default Gateway _. _. _. _ DNS IP Address 202 54 1 30
System Time Zone System Date and Time Email ID of the administrator
192.168 0 1
Trang 40Zone information when Cyberoam is in Transparent mode
LOCAL Zone WAN Zone
LAN Zone
v
Cyberoam in transparent mode have three default zone
LAN Zone: Network connected
to LAN interface of Cyberoam
WAN Zone: Network connected
to WAN interface of Cyberoam
Local Zone: IP Address assigned
on the Bridge Interface falls under Local Zone
Trang 4141