Lab 4.1 Network Firewalls 1
Intro
Prerequisites
Task 1: Configuring fw01
configure
set zone-policy zone WAN interface eth0
set zone-policy zone DMZ interface eth1
set zone-policy zone LAN interface eth2
commit
save
Creating Firewalls for WAN-to-DMZ and DMZ-to-WAN
Firewalls for WAN and DMZ

Assigning Firewalls to Zones

Testing


Allow HTTP Inbound

Testing

Allowing http-established connections back out

Deliverable 2: Take a screenshot that shows a failed wget or curl (1) followed by a successful connection to your web server. Make sure you've deleted the default welcome.conf file, you've restarted httpd and have added a simple index.html banner as shown in (2).
Create a simple web page


DMZ and LAN Traffic Firewalls


DMZ to LAN
Deliverable 3: Provide a screenshot similar to the one above of /var/log/messages on fw01 that shows a drop message like the one below, make sure you select the message that indicated PROTO=TCP and DPT=1514 or 1515
Allow Wazuh agent communications


Configure WAN-to-LAN firewall
Configure LAN-TO-WAN Firewall
Deliverable 5: Submit a screenshot showing a LAN-TO-WAN browsing session between wks01 and champlain.edu

Configure LAN to DMZ Firewall

Deliverable 7. ssh into web01 from using the username testwazuhafterfirewall. Attempt this until the session is closed by web01. Provide a screenshot similar to the one below that shows a related security event in wazuh, after fw1 was configured.

Task 2: Configuring fw-mgmt
Create LAN and MGMT zones on fw-mgmt
LAN-to-MGMT
MGMT-to-LAN





Last updated