Firewall Typical Networking and Troubleshooting Common Faults.

Slides:



Advertisements
Similar presentations
Enabling Secure Internet Access with ISA Server
Advertisements

Ver 1,12/09/2012Kode :CIJ 340,Jaringan Komputer Lanjut FASILKOM Routing Protocols and Concepts – Chapter 2 Static Routing CCNA.
© 2005 Cisco Systems, Inc. All rights reserved. BGP v3.2—2-1 BGP Transit Autonomous Systems Monitoring and Troubleshooting IBGP in a Transit AS.
SYSTEM ADMINISTRATION Chapter 19
11 TROUBLESHOOTING Chapter 12. Chapter 12: TROUBLESHOOTING2 OVERVIEW  Determine whether a network communications problem is related to TCP/IP.  Understand.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 9: Troubleshooting the Network Connecting Networks.
Module 5: Configuring Access for Remote Clients and Networks.
1 Objectives Configure Network Access Services in Windows Server 2008 RADIUS 1.
Principles of Information Security, 2nd Edition1 Firewalls and VPNs.
Introduction to Firewall Technologies. Objectives Upon completion of this course, you will be able to: Understand basic concepts of network security Master.
WXES2106 Network Technology Semester /2005 Chapter 10 Access Control Lists CCNA2: Module 11.
Lesson 18-Internet Architecture. Overview Internet services. Develop a communications architecture. Design a demilitarized zone. Understand network address.
SecPath Firewall Architecture. Objectives Upon completion of this course, you will be able to: Understand the architecture of SecPath series firewalls.
Networking Components
Technical Training: DIR-615
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.1 Configuring Network Devices Working at a Small-to-Medium Business or ISP – Chapter.
Course 201 – Administration, Content Inspection and SSL VPN
CS426Fall 2010/Lecture 361 Computer Security CS 426 Lecture 36 Perimeter Defense and Firewalls.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Troubleshooting Your Network Networking for Home and Small Businesses.
Module 3: Planning and Troubleshooting Routing and Switching.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Troubleshooting Your Network Networking for Home and Small Businesses.
Intranet, Extranet, Firewall. Intranet and Extranet.
AIS, Passwords Should not be shared Should be changed by user Should be changed frequently and upon compromise (suspected unauthorized disclosure)
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 12: Routing.
Implementing ISA Server Publishing. Introduction What Are Web Publishing Rules? ISA Server uses Web publishing rules to make Web sites on protected networks.
Common Devices Used In Computer Networks
Objectives Configure routing in Windows Server 2008 Configure Routing and Remote Access Services in Windows Server 2008 Network Address Translation 1.
1 The Firewall Menu. 2 Firewall Overview The GD eSeries appliance provides multiple pre-defined firewall components/sections which you can configure uniquely.
OV Copyright © 2013 Logical Operations, Inc. All rights reserved. Network Security  Network Perimeter Security  Intrusion Detection and Prevention.
11 SECURING YOUR NETWORK PERIMETER Chapter 10. Chapter 10: SECURING YOUR NETWORK PERIMETER2 CHAPTER OBJECTIVES  Establish secure topologies.  Secure.
OV Copyright © 2011 Element K Content LLC. All rights reserved. Network Security  Network Perimeter Security  Intrusion Detection and Prevention.
Connecting to a Network Lesson 5. Objectives Understand the OSI Reference Model and its relationship to Windows 7 networking Install and configure networking.
Code : STM#530 Samsung Electronics Co., Ltd. OfficeServ7400 Security Introduction Distribution EnglishED01.
Network Security. 2 SECURITY REQUIREMENTS Privacy (Confidentiality) Data only be accessible by authorized parties Authenticity A host or service be able.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Filtering Traffic Using Access Control Lists Introducing Routing and Switching.
7400 Samsung Confidential & Proprietary Information Copyright 2006, All Rights Reserved. -0/17- OfficeServ 7400 Enterprise IP Solutions Quick Install Guide.
Application Block Diagram III. SOFTWARE PLATFORM Figure above shows a network protocol stack for a computer that connects to an Ethernet network and.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 1: Introduction to Scaling Networks Scaling Networks.
1 Firewalls Types of Firewalls Inspection Methods  Static Packet Inspection  Stateful Packet Inspection  NAT  Application Firewalls Firewall Architecture.
Verify that timestamps for debugging and logging messages has been enabled. Verify the severity level of events that are being captured. Verify that the.
Switch Features Most enterprise-capable switches have a number of features that make the switch attractive for large organizations. The following is a.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 2 v3.0 Module 9 Basic Router Troubleshooting.
Security fundamentals Topic 10 Securing the network perimeter.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Securing Data Transmission and Authentication. Securing Traffic with IPSec IPSec allows us to protect our network from within IPSec secures the IP protocol.
1 © 2004, Cisco Systems, Inc. All rights reserved. CCNA 3 v3.1 Module 3 EIGRP.
ERICSON BRANDON M. BASCUG Alternate - REGIONAL NETWORK ADMINISTRATOR HOW TO TROUBLESHOOT TCP/IP CONNECTIVITY.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Filtering Traffic Using Access Control Lists Introducing Routing and Switching.
CCNA4 Perrine / Brierley Page 12/20/2016 Chapter 05 Access Control Non e0e1 s server.
CHAPTER 3 Router CLI Command Line Interface. Router User Interface User and privileged modes User mode --Typical tasks include those that check the router.
ITMT Windows 7 Configuration Chapter 5 – Connecting to a Network ITMT 1371 – Windows 7 Configuration 1.
This courseware is copyrighted © 2016 gtslearning. No part of this courseware or any training material supplied by gtslearning International Limited to.
© 2001, Cisco Systems, Inc. CSPFA 2.0—16-1 Chapter 16 Cisco PIX Device Manager.
100% Exam Passing Guarantee & Money Back Assurance
Configuring Network Devices
Security fundamentals
CompTIA Security+ Study Guide (SY0-401)
100% Exam Passing Guarantee & Money Back Assurance
Lab 2: Packet Capture & Traffic Analysis with Wireshark
Network Tools and Utilities
Instructor Materials Chapter 9: Testing and Troubleshooting
Planning and Troubleshooting Routing and Switching
Computer Data Security & Privacy
Prepared By : Pina Chhatrala
CompTIA Security+ Study Guide (SY0-401)
2018 Real CompTIA N Exam Questions Killtest
Cisco Real Exam Dumps IT-Dumps
IIS.
Firewalls Routers, Switches, Hubs VPNs
AbbottLink™ - IP Address Overview
Presentation transcript:

Firewall Typical Networking and Troubleshooting Common Faults

Objectives Upon completion of this course, you will be able to: Master the typical networking of SecPath firewall. Master the skills of troubleshooting common faults of SecPath firewall.

3Com Confidential. 3 Contents Common Firewall Networking Troubleshooting Common Faults of Firewall

Cases of Common Firewall Networking Applications at the egress of government and enterprise vertical networks Applications in the networking of financial and security industries Applications with carrier-class reliability

Applications at the Egress of Government and Enterprise Vertical Networks Internet SecPath firewall Enterprise users Trust domain Untrust domain DMZ domain Server cluster

Applications in the Networking of Financial and Security Industries Authentication server Data center Internet Online banking E-commerce Browse web page Intranet Server SecPath ASecPath B Enterprise user untrust domain DMZ domain 1 DMZ domain 2 Trust domain

Applications with carrier-class reliability Internet Branch Enterprise user Intranet Public network server

3Com Confidential. 8 Contents Common Firewall Networking Troubleshooting Common Faults of Firewall

Troubleshooting Process Check the physical link status. Check the firewall default action (interception or release). Check whether the interface is added into the correct domain. Check whether the ARP table items are correct. Check the matching status of the ACL rules. Check whether the NAT table items are correct. Check whether ASPF is activated in the correct interface and direction. Check whether the domain statistics function is activated.

Symptom of Common Faults (1) Symptom: After the firewall interface is configured with an IP address, the execution of the ping command of the IP address is not successful. Diagnosis: Ping failure may be caused by the following factors. Rule out the possibilities one by one. 1) Ensure the up status of the firewall physical link. 2) Ensure that the physical interface is added into one of the domains. 3) Check the default rules and ACL rules of the firewall. 4) Check whether the ARP table items contain the MAC address of the peer equipment. 5) Query the receiving/transmitting of the ICMP packets with the debug command.

Symptom of Common Faults (2) Symptom: After the port scanning and address scanning intrusion protection and the dynamic blacklist, the firewall cannot view the intrusion log. In addition, the scanning source addresses are not added dynamically into the blacklist. Diagnosis: 1) Check whether the scanning speed of the scanning tool exceeds the max- rate value per second set by the configuration file. 2) Check whether the blacklist function is activated. 3) Check whether IP statistics function for the connection with the outgoing direction of the domain of the initiator is activated or not.

Symptom of Common Faults (3) Symptom: After the filtering based on key words of the web page content is set, it is not valid. Diagnosis: 1) Check whether the ASPF is configured to detect HTTP. 2) Check whether the ASPF is applied to the interface or between the domains. 3) Query the filtering record with the display firewall web-filter command. (Precaution: When the web page filtering and mail filtering are configured, the ASPF detection function must be enabled.)

Symptom of Common Faults (4) Symptom: The system cannot detect the 2FE card. Diagnosis: 1) Query whether the 2FE card has been registered with the display version command. 2) Check the type of the 2FE card. There are two types of 2FE cards. secpath supports only the 2fe of the chip. It does not support the 2fe of the chip. Differentiation method of two types of boards: (Note: Differentiation is achieved through eye observation of the physical chips of the boards. For the 2FE of the chip, there is a 4 square centimeters chip the near the pci socket, with the identification. For the 2FE of the chip, there is only a 1 square centimeter chip in the middle of the board, with the identification.)

Symptom of Common Faults (5) Symptom: The transparent mode of the firewall is set to “transparent”. The routers on both sides of the firewall cannot establish the OSPF neighbor relationship. Diagnosis: 1)Check whether the flood or broadcast function is activated for the unknow-mac. 2)Check with the ping command whether both ends of the physical link is connected. 3)Check whether the area No., network No., hello interval, and dead interval of the hello packets of both ends are consistent. 4) For others, please refer to the debugging of the OSPF protocol.

Symptom of Common Faults (6) Symptom: After the setting of the GRE tunnel is completed, the ping command of the peer tunnel interface is not successful. Diagnosis: Rule out the possible causes one by one: 1)Ensure that the tunnel interface has been added into the residing domain of the public network. 2)Check whether the tunnel interface has been in the up status with the display interface tunnel command. 2)Check whether the tunnel has been configured with correct source and destination addresses. 3)Check whether the router table contains the route to the tunnel destination address, or check whether the tunnel destination address is reachable with the ping command. (Precaution: All interfaces, either physical interface or virtual interface, must be added into a certain domain.)

Symptom of Common Faults (7) Symptom: When the browser is applied to log in to the firewall, “The page cannot be found” is prompted. Diagnosis: 1) Check whether the physical link from the PC to the firewall is faulty. 2) Check whether flash contains the http.zip file with the dir command. 3) If the file does not exist, separate the file from the system software with the detach command.

Summary The course is summarized as follows: Common networking modes of the firewall Troubleshooting common faults of the SecPath firewall

Thank you