FIREWALLS!!!!!!!!!!!!! Flashcards

1
Q

Firewalls

A

Selectively filters and blocks traffic between networks by looking at packets. Sometimes re-routes packets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Network-based Firewall

A

Between two private networks (LAN)/between private (LAN) and public network (WAN)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Host-based firewall

A

Software on local machine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Stateless Inspection Packet Filtering

A

Firewall examined each packet if it was its own stand alone entity… Risky if packets are out of order

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Stateful Inspection Packet Filtering

A

Firewall has the capability to tell if a packet is part of an existing connection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Common Firewall filters

A
deny/allow IP ranges 
source and dest ports
flags in TCP header 
Web filtering
Content Filtering
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Application Aware Firewalls

A

Operates at application layer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Unified Threat Management

A

Strategy that combines multiple layers of security appliances and technologies into a single safety net (combo of firewalls and intrusion detection)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

*DMZ (Demilitarized Zone)

A
Network segment (or zone) that allows servers to be publicly accessible from the internet
Still have a less restrictive firewall in the front
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

bastion hosts

A

host directly connected to the internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

TCP Connect Scan

A

Completes 3-way handshake (command: nmap)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

TCP FIN Scan

A

Sends request to close nonexistent connection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

TCP Null Scan

A

No flags set, see what target machines responds back with

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

TCP ACK Scan

A

Looks to see if stateless inspection is what the firewall is using

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

pfSense

A

Firewall we use in lab :)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Proxy service

A

acts as an intermediary between external and internal networks

17
Q

proxy server

A

Manages security at Application Layer

18
Q

Why do we have proxy servers?

A

To keep internal network addresses private
Cache files
Access resources from the Internet for a client machine

19
Q

Forward proxy

A

passes unmodified requests and responses. Retrieves information from web for client machines

20
Q

Reverse proxy (surrogate proxy)

A

Sits in front of web server and receives requests as if it is the web server
Caches and load balances

21
Q

keyhole

A

web proxy, http, https, ftq

22
Q

Full SSL Inspection/HTTPS Interception

A

Intercepts SSL/TLS traffic between client and server (man in the middle attack) by using a middlebox connection to web server as if it were the client

23
Q

Next-Gen Firewalls

A

enforce based on URL, SRC/DEST, User, User Group, Ports