March R. Smith - University of St Thomas - Minnesota CISC Class Today Homework RemindersHomework Reminders RecapRecap FirewallsFirewalls Firewall LabFirewall Lab
Homework Graded LabLab –Most people did fine – if you forgot something, that was a problem Diagrams: my expectationsDiagrams: my expectations –Show the relevant layers Gateways and Routers all have a Network LayerGateways and Routers all have a Network Layer I prefer to see the physical layer, too.I prefer to see the physical layer, too. –#4 – only 3 boxes were really required I didn’t mind if you added a routerI didn’t mind if you added a router –Style question: what order do layers belong in? I prefer to have physical at bottomI prefer to have physical at bottom Split the lower level to show bifurcated layersSplit the lower level to show bifurcated layers March R. Smith - University of St Thomas - Minnesota
March R. Smith - University of St Thomas - Minnesota Recap: Firewalls ObjectivesObjectives Types of firewall traffic controlTypes of firewall traffic control Firewall FilteringFirewall Filtering Network Address TranslationNetwork Address Translation The LabThe Lab
March R. Smith - University of St Thomas - Minnesota Recap: Network Address Translation Original purpose: more hosts & addressesOriginal purpose: more hosts & addresses –Let “insiders” use restricted addresses –Translate them on the way out A ‘multiplexing’ mechanismA ‘multiplexing’ mechanism –Users share a “real” Internet address
Linksys Home Page Type in the router’s IP addressType in the router’s IP address –or PasswordPassword –Replace ‘1’ with ‘2’ in the admin password –or “admin” March R. Smith - University of St Thomas - Minnesota
Five major headings of controls SetupSetup –Establishes the local address and configuration SecuritySecurity –Filters traffic, enables/disables certain types of traffic Applications and GamingApplications and Gaming –Allows connections to servers on the LAN from the Internet AdministrationAdministration –Change password, enable remote management features StatusStatus –Check the status of the WAN connection –Check status of LAN and its attached hosts March R. Smith - University of St Thomas - Minnesota
Address Setup Set to “Obtain IP Automatically”Set to “Obtain IP Automatically” Our local default internal addresses are Net 10Our local default internal addresses are Net 10 March R. Smith - University of St Thomas - Minnesota
Address Settings Set local address to Set local address to –That’s the address of this router –Subnet mask Enable Local DHCP serviceEnable Local DHCP service –Start assigning local addresses at 100, total of 50 addresses –Renews address “leases” daily March R. Smith - University of St Thomas - Minnesota
Looking at the Router Status Internal and external routing dataInternal and external routing data –The “Internet” addresses are for the “outside” of the router March R. Smith - University of St Thomas - Minnesota
Looking at the LAN Status Gives addressing information about the router as seen from the LAN sideGives addressing information about the router as seen from the LAN side –Click the button to see the DHCP client table March R. Smith - University of St Thomas - Minnesota
DHCP Client Table Lists all active clients on the LAN Provides a map to the LAN Just like the lab March R. Smith - University of St Thomas - Minnesota
The Management Screen Starting point for lower level controls Actually, password changing is all this is good for PLEASE DON’T CHANGE THE PASSWORD. March R. Smith - University of St Thomas - Minnesota
Traffic Filtering Blocks LAN machines from the InternetBlocks LAN machines from the Internet –Block by IP address –Block by MAC address Block Port NumbersBlock Port Numbers Other filtersOther filters –Multicast –External Internet queries mostly Pingsmostly Pings March R. Smith - University of St Thomas - Minnesota
Port Forwarding Allows inbound connections – forwards particular ports to specific PCs on the LANAllows inbound connections – forwards particular ports to specific PCs on the LAN Under the “Applications and Gaming” tab.Under the “Applications and Gaming” tab. March R. Smith - University of St Thomas - Minnesota
Firewall Lab OverviewOverview –Rewire the lab to use the firewall –Map the rewired lab –Demonstrate host blocking through the firewall –Demonstrate NAT through the firewall March R. Smith - University of St Thomas - Minnesota
March R. Smith - University of St Thomas - Minnesota That’s it Questions?Questions? Creative Commons License This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit or send a letter to Creative Commons, 171 Second Street, Suite 300, San Francisco, California, 94105, USA.