Network Security and Access Control
Filtering as it is actually practised - by service rather than by host, in the right direction, with state - and the controls around it that no device implements.
By the end you will be able to
- Use the security vocabulary precisely enough to argue about a control
- Write a filter that permits one service rather than one host
- Apply a rule in the correct direction, on the correct interface
- Explain why return traffic needs state rather than a wide inbound permit
- Protect a device as a destination, not only as a forwarder
Sign in to track your progress, earn XP and unlock the labs in this path.
Modules
- 01
The Vocabulary and the Attacks
Four words that are used interchangeably and should not be, and the attack families grouped by the assumption each one breaks.
3 activities~26 min - 02
Filtering by Address
Four labs on the form of ACL you have already met, taken further - default deny from day one, and a rule scoped to the wrong thing.
4 activities~80 min - 03
Filtering by Service
Adding protocol and port to a rule, which is the difference between an access list that expresses an intention and one that approximates it.
2 activities~29 min - 04
Least Privilege in Practice
Five findings from security reviews, each one a rule that was correct when it was written and grants more than anyone now intends.
5 activities~100 min - 05
Direction and State
Three labs where the rule is right and something about how it was applied is not - the wrong interface, the wrong direction, or a reply that the firewall never expected.
3 activities~60 min - 06
Protecting the Devices Themselves
Everything so far has protected traffic passing through a router. This module protects the router, and covers the controls that no device implements at all.
4 activities~46 min
Curriculum topics
Each topic page lists every lesson, quiz and hands-on lab that covers it, plus how it maps onto the CCNA and Network+ blueprints.
