Module 3 part 2 Flashcards

gateway firewalls

1
Q

In what layer the filtering of Gateway firewall is done ?

A

application layer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the main purpose of Bastion Host(BH) ?

A

BH sets up proxy for client/sever

eliminates the direct exchange of packets between private and outside network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 6 design features of Bastion Hosts ?

A
  1. secure version of OS
  2. only essential services are installed(DNS FTP)
  3. each proxy is independent program
  4. each proxy can be configured (hosts subnets)
  5. BH require additional authentication
  6. User not allowed to login BH
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the three Gateway firewall configurations ?

A
  • screened host firewall
  • Dual-homed gateway firewall
  • Screened subnet firewall
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

In which part of screened host firewall the BH is located in ?

A

BH located in the same network segment as the private network hosts and secure severs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the characteristics of screened host gateway firewall ?

A
  • packet filter router have ACL to configure traffic only to BH
    -direct access to outside network or through proxy
    -access info server without using proxies.
    High flexibility
    Low security
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the characteristics of Dual homed gateway firewall ?

A
  • BH two interface between outside and inside
  • all traffic from private network is forced set up proxies.
  • information server is out side of the BH
  • packet filter ACL put traffic to info server or BH
  • High security
  • low flexibility
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the characteristics of Screened Subnet gateway firewall ?

A
  • two packet filtering routers
  • BH and info server placed between two routers
  • direct traffic in DMZ is prevented through two router’s ACL
  • balanced flexibility and security
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the network segment between two router(private and public network) in screened subnet gateway firewall ?

A

DMZ(de-militarized zone) network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the routing rule of the outer router in screened subnet gateway firewall?

A
  1. traffic from outside only to BH or info server

2. outbound traffic only allow from BH.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the routing rule of the inner router in screened subnet gateway firewall?

A
  1. inbound traffic only allow from BH

2. outbound traffic only to BH or info server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In what network configuration is NAT installed ?

A

Dual homed gateway network and screened subnet gateway network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does NAL(network address translation) do?

A

translating private address to public address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the three block of IP address are assigned to private address ?

A

A: 10.0.0.0 - 10.255.255.255
B: 172.16.0.0- 172.31.255.255
C: 192.168.0.0-192.168.255.255

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

NAT solves what other problem of IP address ?

A

short of IP address

not enough IP address.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the three types of NAT?

A
  1. static (1-1) NAT
  2. dynamic many-to-a-pool NAT
  3. dynamic many-to-a-1 NAT
17
Q

What is static (1-1) NAT ?

A
  • fixed mapping
  • simple
  • least efficient of IP address
  • good for server
18
Q

What is dynamic many to a pool NAT?

A
  • a private address maps to a public address

- only a group of client can connect to outside server together.

19
Q

What is dynamic many to a 1 NAT ?

A
  • also known as NAT overloading or PAT port address translation
  • use map to
  • large access to outside server together
20
Q

About how many clients can connect to the network at the same time using 1 public IP address?

A

15000

21
Q

What information does stateful inspection store?

A

port number, address, type of request and sequence number

22
Q

What are the limitation of Firewalls?

A
  • cannot filter encrypted traffic

- cannot prevent internal attack