SEC350‐4.1 - ConnorEast/Tech-Journal GitHub Wiki
Steps | Command | Reasoning/images |
---|---|---|
Step 1: | configure | |
Step 2: | set zone-policy zone WAN interface eth0 | |
Step 3: | set zone-policy zone DMZ interface eth1 | |
Step 4: | set zone-policy zone LAN interface eth2 | |
Step 5: | Commit Save | |
Step 6: | set firewall name WAN-to-DMZ default-action drop | |
Step 7: | set firewall name DMZ-to-WAN default-action drop | |
Step 8: | set firewall name WAN-to-DMZ enable-default-log | |
Step 9: | set firewall name DMZ-to-WAN enable-default-log | |
Step 10: | set zone-policy zone WAN from DMZ firewall name DMZ-to-WAN | |
Step 11: | set zone-policy zone DMZ from WAN firewall name WAN-to-DMZ | |
Step 12: | commit save | |
Step 1: | Ping 172.16.50.3 |
![]() |
Step 12: | Attempt to access http site 172.16.50.3 |
![]() |
Step 11: | Run the "tail -f /var/log/messages | grep WAN" | Do this before you ping in order to recieve log data. |
data:image/s3,"s3://crabby-images/8a211/8a2115b759bb1c9eb3ac308f9f6db30251bc92d4" alt=""
Steps | Command | Reasoning/images |
---|---|---|
Step 3: | set firewall name WAN-to-DMZ rule 10 action 'accept' | |
Step 1: | set firewall name WAN-to-DMZ rule 10 destination address '172.16.50.3' | |
Step 2: | set firewall name WAN-to-DMZ rule 10 destination port 80 | |
Step 3: | set firewall name WAN-to-DMZ rule 10 protocol tcp | |
Step 4: | set firewall name WAN-to-DMZ rule 10 description "access to web" |
data:image/s3,"s3://crabby-images/35f82/35f8278bff5e12af3a60ae7b0b83f2250e1189cf" alt=""
Steps | Command | Reasoning/images |
---|---|---|
Step 1: | set firewall name DMZ-to-WAN rule 1 action accept | |
Step 2: | set firewall name DMZ-to-WAN rule 1 state establish 'enable' |
data:image/s3,"s3://crabby-images/6c044/6c044a5000923390157229f936fd94833ff64fde" alt=""
DMZ and LAN
Steps | Command | Reasoning/images |
---|---|---|
Step 1: | set firewall name LAN-to-DMZ default-action drop | |
Step 2: | set firewall name DMZ-to-LAN default-action drop | |
Step 3: | set firewall name LAN-to-DMZ enable-default-log | |
Step 4: | set firewall name DMZ-to-LAN enable-default-log | |
Step 5: | set zone-policy zone LAN from DMZ firewall name DMZ-to-LAN | |
Step 6: | set zone-policy zone DMZ from LAN firewall name LAN-to-DMZ |
data:image/s3,"s3://crabby-images/5d75c/5d75cfad08912bba5fbb6e94c76325c0f4bcc707" alt=""
data:image/s3,"s3://crabby-images/e58d9/e58d929b82b9a3f424803664aecee2d363bdcaea" alt=""
data:image/s3,"s3://crabby-images/7426e/7426ea90150979abe524091c29f3a3542e53cf39" alt=""
Steps | Command | Reasoning/images |
---|---|---|
Step 1: | set firewall name DMZ-to-LAN rule 10 action accept | |
Step 2: | set firewall name DMZ-to-LAN rule 10 destination address 172.16.200.10 | |
Step 3: | set firewall name DMZ-to-LAN rule 10 destination port 1512,1515 | |
Step 4: | set firewall name DMZ-to-LAN rule 10 protocol tcp | |
Step 5: | set firewall name LAN-to-DMZ rule 1 action accept | |
Step 6: | set firewall name LAN-to-DMZ rule 1 establish enable | |
Step 7: | commit | |
Step 1: | save |
data:image/s3,"s3://crabby-images/2c988/2c98842d46f610141eb49213e6250aff7355a225" alt=""
Configure LAN-to-WAN
set firewall name LAN-to-WAN default-action dropSteps | Command | Reasoning/images |
---|---|---|
Step 1: | ||
Step 2: | set firewall name LAN-to-WAN enable-default-log | |
Step 3: | set firewall name LAN-to-WAN rule 1 action accept | |
Step 4: | set zone-policy zone WAN from LAN firewall name LAN-to-WAN |
Configure WAN-to-LAN
data:image/s3,"s3://crabby-images/28490/28490467a8f76db99bd07ea208d472bb2f338110" alt=""
Step 1: | set firewall name WAN-to-LAN default-action drop | |
Step 2: | set firewall name WAN-to-LAN enable-default-log | |
Step 3: | set firewall name WAN-to-LAN rule 10 state established enable | |
Step 4: | set firewall name WAN-to-LAN rule 10 action accept | |
Step 5: | set firewall name WAN-to-LAN rule 10 state related enable | |
Step 6: | set zone-policy zone LAN from WAN firewall name WAN-to-LAN |
data:image/s3,"s3://crabby-images/cbc73/cbc736cec86ad5aed7fc20777b1793f2b724ff8b" alt=""
Configure [LAN to DMZ] & [DMZ to LAN] Firewall rules
Steps | Command | Reasoning/images |
---|---|---|
Step 1: | set firewall name LAN-to-DMZ rule 10 action accept | |
Step 2: | set firewall name LAN-to-DMZ rule 10 source address 172.16.150.0/24 | |
Step 3: | set firewall name LAN-to-DMZ rule 10 destination address 172.16.50.3 | |
Step 4: | set firewall name LAN-to-DMZ rule 10 protocol tcp | |
Step 5: | set firewall name LAN-to-DMZ rule 10 destination port 80,443 | |
Step 6: | set firewall name LAN-to-DMZ rule 20 action accept | |
Step 7: | set firewall name LAN-to-DMZ rule 20 source address 172.16.150.10 | |
Step 8: | set firewall name LAN-to-DMZ rule 20 destination address 172.16.50.0/29 | |
Step 9: | set firewall name LAN-to-DMZ rule 20 destination port 22 | |
Step 10: | set firewall name LAN-to-DMZ rule 20 protocol tcp | |
Step 11: | commit | |
Step 12: | save | |
Step 11: | set firewall name DMZ-to-LAN rule 1 action accept | |
Step 12: | set firewall name DMZ-to-LAN rule 1 state establish enable | |
Step 11: | set firewall name DMZ-to-LAN rule 1 state related enable | |
Step 12: | save |
data:image/s3,"s3://crabby-images/58d5c/58d5cc7d79b1f0870d39fde6d98d74501ee7b6b6" alt=""
data:image/s3,"s3://crabby-images/fb2bc/fb2bc01ea8865119d20ec6fde47120d76bd392ee" alt=""
data:image/s3,"s3://crabby-images/29c64/29c644da86273bd70dfe1b31040bc2dffc8a987b" alt=""
Configure [Lan to MGMT] Firewall rules
Prerequisits
Steps | Command | Reasoning/images |
---|---|---|
Step 1: | set zone-policy zone LAN interface eth0 | |
Step 2: | set zone-policy zone MGMT interface eth1 |
Steps | Command | Reasoning/images |
---|---|---|
Step 1: | set firewall name LAN-to-MGMT default-action drop | |
Step 2: | set firewall name LAN-to-MGMT enable-default-log | |
Step 3: | set firewall name LAN-to-MGMT rule 1 action accept | |
Step 4: | set firewall name LAN-to-MGMT rule 1 state established enable | |
Step 5: | set firewall name LAN-to-MGMT rule 10 action accept | |
Step 6: | set firewall name LAN-to-MGMT rule 10 destination address 172.16.200.10 | |
Step 7: | set firewall name LAN-to-MGMT rule 10 destination port 1514,1515 | |
Step 8: | set firewall name LAN-to-MGMT rule 10 protocol tcp | |
Step 9: | set firewall name LAN-to-MGMT rule 20 action accept | |
Step 10: | set firewall name LAN-to-MGMT rule 20 destination address 172.16.200.10 | |
Step 11: | set firewall name LAN-to-MGMT rule 20 destination port 443 | |
Step 12: | set firewall name LAN-to-MGMT rule 20 protocol tcp | |
Step 13: | set zone-policy zone MGMT from LAN firewall name LAN-to-MGMT |
Configure [MGMT to LAN] Firewall rules
Steps | Command | Reasoning/images |
---|---|---|
Step 1: | set firewall name MGMT-to-LAN default-action drop | |
Step 2: | set firewall name MGMT-to-LAN enable-default-log | |
Step 3: | set firewall name MGMT-to-LAN rule 1 action accept | |
Step 4: | set firewall name MGMT-to-LAN rule 1 established enable | |
Step 5: | set firewall name MGMT-to-LAN rule 10 action accept | |
Step 6: | set firewall name MGMT-to-LAN rule 10 destination address 172.16.150.0/24 | |
Step 7: | set firewall name MGMT-to-LAN rule 20 action accept | |
Step 8: | set firewall name MGMT-to-LAN rule 20 destination address 172.16.50.0/29 | |
Step 9: | set zone-policy zone LAN from MGMT firewall name MGMT-to-LAN | |
Step 10: | commit | |
Step 11: | save | |
Step 12: | sudo contrack -F | Flushes connections for proper connection. Do this on both firewalls |
Step 13: | sudo reboot |
data:image/s3,"s3://crabby-images/a925f/a925fc25becd7e888ccc304c2e67b815ed313026" alt=""
data:image/s3,"s3://crabby-images/7a259/7a2594214e49abe9b16ce04dd4e954008d295f2e" alt=""
data:image/s3,"s3://crabby-images/edb04/edb04fe350e2a5d10c5f351b193e3f2b009d87bf" alt=""
data:image/s3,"s3://crabby-images/75691/756913b6a97b57e5e8e0d343719d2bcb5db2fac7" alt=""
data:image/s3,"s3://crabby-images/22022/22022b4a7a253ffe261a442c7878e401081b0e44" alt=""
data:image/s3,"s3://crabby-images/0022d/0022dbebac1118df23a678c62662a67ec39839ba" alt=""
data:image/s3,"s3://crabby-images/eca69/eca69ed37913769df91f23703068f201067e4001" alt=""
data:image/s3,"s3://crabby-images/03ad8/03ad85bacf70274eae44f4e2bb2e64b441f58c1a" alt=""
data:image/s3,"s3://crabby-images/a1745/a1745ce6735cd47943f508e1ce30eecead1054da" alt=""
Fw-MGMT | FW01 |
---|---|
|
|