← Back to Book Detail

37 Network Hardening – Network Segmentation and Isolation (37/26) -- Mastering Enterprise Networks

Browse
142%

37 Network Hardening – Network Segmentation and Isolation

37 Network Hardening – Network Segmentation and Isolation Mathew J. Heath Van Horn, PhD Many networks are worried about exterior facing security holes. The network interior is largely overlooked as needing security management. However, many advanced persistent threat actors use the application layer to gain access to the interior network and then pivot to other internal network targets. e.g. an APT gains access to the web server, where they can cause mischief, but without inside the network security, that web server access could give way to the research, employee, and accounting servers. To prevent this, we can create obstacles to slow the threat actor down long enough to counter their attacks. Think how hedgerows in WW II Europe slowed the Allied advance on Germany (Hedgerow History1) (HedgerowHistory2). In an enterprise network, the cybersecurity person’s hedgerows used against threat actors are virtual local area networks (VLANs) and they enhance network security through network segmentation and isolation. LEARNING OBJECTIVES - Adding a switch to a network environment - Segment a homogenous network into several isolated networks - Use DHCP to test network connectivity - Develop a firewall filter to complete network segmentation PREREQUISITES Deliverables - Wireshark packets from PC 1 showing successful pings to PC 5 and PC 3 - Screenshot of VLAN table for Switch 1 - Screenshot of VLAN table for Switch 2 - Screenshot of PC5 unable to ping <IP_ADDRESS> and <IP_ADDRESS> Resources - MikroTik Documentation – Bridging and Switching – https://help.mikrotik.com/docs/display/ROS/Bridging+and+Switching#BridgingandSwitching-BridgeHardwareOffloading - Wilmer Almazan / The Network Trip – “Mikrotik VLANs – CRS3XX Step by Step – Mikrotik Tutorial” – https://www.youtube.com/watch?v=YLtGQAQ8iS0 Contributors and Testers - Ella Lopez, Cybersecurity Student, ERAU-Prescott - Nichole Thomas, Cybersecurity Student, ERAU-Prescott - Bernard Correa, Cybersecurity Student, ERAU-Prescott - Kyle Wheaton, Cybersecurity Student, ERAU-Prescott - Andersen Keller , Cybersecurity Student, ERAU-Prescott - Jungsoo Noh, Cybersecurity Student, ERAU-Prescott - Dante Rocca, Cybersecurity Student, ERAU-Prescott - Jacob M. Christensen, Cybersecurity Student, ERAU-Prescott Phase I – Setup In this lab, you will build the following GNS3 network… Phase II – Adding a Switch to GNS3 MikroTik’s RouterOS operating system works the same for both switches and routers. Their physical switches have an extra circuit that allows for OSI Layer 2 switching functions. This means that if were to configure a MikroTik router as a switch in GNS3, it wouldn’t work because the extra circuit isn’t present. However, we can approximate the same settings. Others have struggled with this problem and have taken the MikroTik router image and modified it to support switching. - Start GNS3 so it can boot while we download the appliance - Create a new project: LAB_20 - In GNS3, navigate to File–>New Template - Select
← Previous Chapter Next Chapter →