8 - 3: Network Security Devices Flashcards
Switches
Connect devices to the network
Wireless Access Points
Connect to switches to create Wi-fi networks
Switches operate at _____ of the OSI model
Level 2: data. MAC addresses only
If a switch happens to operate at level _ of the OSI model, it can _____
3, interpret IP addresses
Routers
Aggregate network traffic going to or from large networks
Router functions
Intelligently management packets, provide security by maintaining an access control list
Stateless inspection
Restricting network traffic without regard to connection state
Bridges
Simply connect two networks together
Firewalls
Determine if connections should be allowed based on security policy
Firewalls often sit at:
The perimeter between routers and the internet
Stateless inspection (firewalls)
Inspecting packets as they came through the firewall, highly inefficient and had no historical data
DMZ
accepts external communications and isolates them from internal networks
Stateful inspections
Monitor active connections, where the firewall monitors packet traffic for the duration of the connection
Firewall rule contents
1) Source System Address, 2) Destination System Address 3) Destination Port and Protocol 4) allow/deny action
Default/Implicit deny
If a request does not align to a rule, it is automatically denied
NGFW
Next Generation Firewall, uses a lot of contextual information in making decisions
Other firewall roles
Network Address Translation, content/URL filtering, Web Application Firewall
Web Application Firewall
A specialized firewall that blocks website content including HTML elements, SQL forms, outdated media, etc.
Network firewalls
Physical devices
Host-based firewalls
Software Apps or OS components that reside on a server
Advantage to using both firewall types
Achieves defense in depth
Proxy servers
Connect to a websites on a users’ behalf and is in the middle of a server/client connection
Proxy security benefits
1) Anonymity - only captures proxy server name 2) Performance - proxy server caches frequent pages 3) Content filtering - the proxy server itself can filter content on visited pages
Forward proxies
Work on behalf of clients, web servers are not aware they are communicating with a proxy