Download presentation
Presentation is loading. Please wait.
Published byEdgar Bennett Modified over 9 years ago
1
March 2005 1R. Smith - University of St Thomas - Minnesota CISC 210 - Class Today Homework RemindersHomework Reminders RecapRecap FirewallsFirewalls Firewall LabFirewall Lab
2
Homework Graded LabLab –Most people did fine – if you forgot something, that was a problem Diagrams: my expectationsDiagrams: my expectations –Show the relevant layers Gateways and Routers all have a Network LayerGateways and Routers all have a Network Layer I prefer to see the physical layer, too.I prefer to see the physical layer, too. –#4 – only 3 boxes were really required I didn’t mind if you added a routerI didn’t mind if you added a router –Style question: what order do layers belong in? I prefer to have physical at bottomI prefer to have physical at bottom Split the lower level to show bifurcated layersSplit the lower level to show bifurcated layers March 2005 2R. Smith - University of St Thomas - Minnesota
3
March 2005 3R. Smith - University of St Thomas - Minnesota Recap: Firewalls ObjectivesObjectives Types of firewall traffic controlTypes of firewall traffic control Firewall FilteringFirewall Filtering Network Address TranslationNetwork Address Translation The LabThe Lab
4
March 2005 4R. Smith - University of St Thomas - Minnesota Recap: Network Address Translation Original purpose: more hosts & addressesOriginal purpose: more hosts & addresses –Let “insiders” use restricted addresses –Translate them on the way out A ‘multiplexing’ mechanismA ‘multiplexing’ mechanism –Users share a “real” Internet address
5
Linksys Home Page Type in the router’s IP addressType in the router’s IP address 10.10.10.1010.10.10.10 –or 192.168.1.1 PasswordPassword –Replace ‘1’ with ‘2’ in the admin password –or “admin” March 2005 5R. Smith - University of St Thomas - Minnesota
6
Five major headings of controls SetupSetup –Establishes the local address and configuration SecuritySecurity –Filters traffic, enables/disables certain types of traffic Applications and GamingApplications and Gaming –Allows connections to servers on the LAN from the Internet AdministrationAdministration –Change password, enable remote management features StatusStatus –Check the status of the WAN connection –Check status of LAN and its attached hosts March 2005 6R. Smith - University of St Thomas - Minnesota
7
Address Setup Set to “Obtain IP Automatically”Set to “Obtain IP Automatically” Our local default internal addresses are Net 10Our local default internal addresses are Net 10 March 2005 7R. Smith - University of St Thomas - Minnesota
8
Address Settings Set local address to 10.10.10.10Set local address to 10.10.10.10 –That’s the address of this router –Subnet mask 255.255.255.0 Enable Local DHCP serviceEnable Local DHCP service –Start assigning local addresses at 100, total of 50 addresses –Renews address “leases” daily March 2005 8R. Smith - University of St Thomas - Minnesota
9
Looking at the Router Status Internal and external routing dataInternal and external routing data –The “Internet” addresses are for the “outside” of the router March 2005 9R. Smith - University of St Thomas - Minnesota
10
Looking at the LAN Status Gives addressing information about the router as seen from the LAN sideGives addressing information about the router as seen from the LAN side –Click the button to see the DHCP client table March 2005 10R. Smith - University of St Thomas - Minnesota
11
DHCP Client Table Lists all active clients on the LAN Provides a map to the LAN Just like the lab March 2005 11R. Smith - University of St Thomas - Minnesota
12
The Management Screen Starting point for lower level controls Actually, password changing is all this is good for PLEASE DON’T CHANGE THE PASSWORD. March 2005 12R. Smith - University of St Thomas - Minnesota
13
Traffic Filtering Blocks LAN machines from the InternetBlocks LAN machines from the Internet –Block by IP address –Block by MAC address Block Port NumbersBlock Port Numbers Other filtersOther filters –Multicast –External Internet queries mostly Pingsmostly Pings March 2005 13R. Smith - University of St Thomas - Minnesota
14
Port Forwarding Allows inbound connections – forwards particular ports to specific PCs on the LANAllows inbound connections – forwards particular ports to specific PCs on the LAN Under the “Applications and Gaming” tab.Under the “Applications and Gaming” tab. March 2005 14R. Smith - University of St Thomas - Minnesota
15
Firewall Lab OverviewOverview –Rewire the lab to use the firewall –Map the rewired lab –Demonstrate host blocking through the firewall –Demonstrate NAT through the firewall March 2005 15R. Smith - University of St Thomas - Minnesota
16
March 2005 16R. Smith - University of St Thomas - Minnesota That’s it Questions?Questions? Creative Commons License This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/us/ or send a letter to Creative Commons, 171 Second Street, Suite 300, San Francisco, California, 94105, USA.
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.