Module 5 Connecting the firewall to Production Networks with Security Zones Flashcards

1
Q

Why do we segment the network?

A

Several reasons, secure access to data, prevents additional access if one area is compromised.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How do we use segmentation in Palo Alto Firewalls?

A

We used network segmentation/security zones to reduce the attack surface. Palo Alto uses logical zones to group physical/virtual interfaces on the firewall.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is interzone traffic?

A

Between zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Intrazone traffic?

A

Its own zone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How do we support segmentation with the firewall?

A

We configure security policies which will allow traffic between certain zones (interzone).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Can traffic flow between zones in a Palo Alto firewall?

A

Traffic can flow freely within a zone, but you need a security policy rule that allows traffic between zones.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is zero-trust architecture

A

Never trust, always verify. Inspect traffic flows to inbound traffic, outbound traffic to the internet and internal traffic between nodes and your data center.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do we carry VLAN traffic?

A

ROAS, firewall (sub-interfaces) which can be used on a single physical interface. Ethernet1/1, 1/1.2, 1/1.3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the control plane?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the data plane?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is your first task before creating a security policy?

A

Create a Security Zone
Specify zone type: Virtual Wire, layer 2, tap, layer 3, tunnel
Assign interfaces -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the different zone types?

A

Tap, Virtual Wire, Layer 2, Layer 3, Tunnel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Tap, what is its purpose?

A

Switch port analyzer, requires no changes to the existing network design. Does not block traffic, or control traffic. Passive collecting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is virtual wire, what is its purpose?

A

NAT functionality provided. Inserted into existing network, without any re-allocation of network addresses or redesign on the network topology. *Bind two firewall interfaces together through a virtual wire object. No network changes for adjacent network devices. *Can block traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a layer 3 zone type, what is its purpose?

A

Fucking route man. Firewall has a virtual router. App-ID, Content-ID, User-ID, SSL Decryption, NAT and QoS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Where do I configure a layer 3 interface on the firewall?

A

Network - Interfaces - Ethernet - select_interface
- go through the tabs, advanced, (MTU size),

17
Q

In-band and out-of band MGT port?

A

Out-of-band management can be a lifesaver. In-band would be like http, ssh, telnet into a device. Out-of-band uses a console port (how do we get access to the console port?) We would need access to the console server. Maybe an additional internet connection, MPLS, etc.

18
Q

Interface Management Profile

A

You can apply an interface management profile to a layer 3 interface to enable it to carry management traffic.

19
Q

What routing protocols are supported?

A

OSPF, RIPv2 and BGP

20
Q
A
21
Q
A