Visual Firewall Thinger

  Challenge Progession:
Act I
Difficulty:
  Location:
NetWars Room
Visual Firewall
Network Simulator

This challenge is a visual education tool to learn how firewall rules can be applied to block certain services from different network zones. Find this challenge on the top floor of the Grand Hotel in the NetWars Room. Speak to Chris Elgee to find out more about it.

Firewall Simulator

The challenge shows you a visual representation of a simple network setup. This consists of 5 different network zones. There are a list of requirements that need to be satisfied to complete the challenge. Implement firewall rules to satisfy all the requirements to complete the challenge.

Firewall Rules

The requirements are listed as below:

  • Internet to DMZ: Allow only HTTP and HTTPS traffic
  • DMZ to Internal: Allow HTTP, HTTPS, and SSH traffic
  • Internal to DMZ: Allow HTTP, HTTPS, and SSH traffic
  • Internal to Cloud: Allow HTTP, HTTPS, SSH, and SMTP traffic
  • Internal to Workstations: Allow all traffic types
  • Security Best Practice: Block direct Internet to Internal access

To implement a rule click the start zone, then click the destination zone, then check boxes next to the services you wish to allow.

Internet

The requirement for the Internet zone is to only allow HTTP and HTTPS to the DMZ. To do this click Internet and only check the boxes next to HTTP and HTTPS.

Internet Rules

Click save to apply the rule and see the first requirement complete.

DMZ

The requirement for the DMZ is to only allow SSH, HTTP, and HTTPS to the Internal zone. Likewise the Internal zone also should allow SSH, HTTP, and HTTPS to the DMZ. Click the DMZ zone and select Internal Network. Select only SSH, HTTP, and HTTPS.

Internet Rules

Click save to apply the rule. Since Internet and DMZ have the same requirements for each other, this rule will satisfy the next two requirements at once.

Internal Network

There are two requirements for the Internal Network. The first is to only allow HTTP, HTTPS, SSH, and SMTP traffic to the Cloud Services zone. The next requirement is to allow all traffic types to the Workstations zone. Click the Internal Network zone and select the Cloud Services section. Check HTTP, HTTPS, SSH, and SMTP.

Internal to Cloud Rules

Click save to apply the rule. This will satisfy the Internal Network to Cloud Services requirement. Next, click the Workstations section and check all the boxes to allow everything.

Internal to Workstation Rules

Click save to apply the rule. This should complete all the requirements!

Victory!