6 hours 28 minutes
Welcome back to the Sire. A course in building your info. SEC lab. I'm your host. An instructor, Kevin Hernandez. In our last lesson, we look over the hardware requirements for our world or next. Gen firewalls. Some of these included ideas I ps and what proxy and them. However, in this course
we will be looking at the S I am sze and Web proxy. We harbor requirement.
Let's get started.
So if we look back into our list, let's start with proxy. Since we already covered, I'd be fire PF says and entangled, Remember, untangle might have an additional,
um, cost attached to it. Right?
So regarding squid and Whitman what men itself. It's the interface to manage squid without a
command line. So if you go to squid, right food
you can see it's a very, very light requirements for it Here.
This how much you need?
32 megabytes of memory for each of us in this space.
Falls Founder 12 for a 16 gave dis catch. Now being honest with you, if you look at squid installations, right, so just this one
you can see he can run a Santos seven. So if you really want to accomplish this? You can actually use your centres insulation for active directory practices. Ask your squid box. Therefore, what we'll do is we'll put this minimal requirements We just saw and utilize semester base. So let's go back to here.
Let's see a proxy.
There's a type of there
you can say, Well, copy and paces minimum once a swell.
And here we're gonna add a note that can be run
with you Katie Rate here notes
now literally for the other ones PF sense
I pee fire
and untangle right
and you can see
not applies, not apply since they're already
computation in this details.
Now, something to consider is that if you do want to have what filter,
we'll untangle appear to have an additional charge for dead
and it is not part of a license and you can see it charges $25 a month for it. So be aware of that when you're picking your tool that you be utilizing.
Therefore for you to not refer, get let's at here.
That is a $25 a month charge.
Now let's start working in our society. Em's right.
No. In our case, we gotta look for curator, Right? They have Splunk.
We have north.
You have Os Sim, which in Humboldt
now from this lets you have
three. There are very know me before,
and then you have, Oh, second swell, which is fairly known, but not as popular on in the corporate market. Right? So let's start with curator part Were requirements,
you say, Community Edition.
And there, this is actually a
form month. Should be good enough, huh?
It's not. It's actually go here, Developer. Sorry. There you go. And here you can see system requirements and you can see that curator needs around six cakes. Eight gigs if you want to eat X force.
Ah, 110 gigabytes of storage and two CPU. Course, it doesn't say the frequency, but take this into consideration rate. And like I said, a science might be your most power hungry systems out there.
So you might have
these under own dedicated boxes.
Um, so for rain, let's say, six gigabytes
and eight gigabytes recommended and first torture 110 gigabytes. Now, as I said,
this is not necessarily the truth, As you might have a smaller network. However, take it into consideration when you're building your lab and since we're already here,
you can go ahead and download it. If you're actually trying to go towards this tool
you have to sign in and create an account.
So we'll leave this gonna posit and fill it up real quick. After Julian, you should be able to come to a screen similar to this one,
and you can just click here and download it.
Now let's go. Look, take a look at some north now. To me. Storm, it's more ideas. I ps here. Actually, it says it.
however it was listed and it's very good from a perspective, right?
So let's take it into consideration. Right? And it actually is, Is a room too?
Ah, four gigs of Ram and one terabyte of disk. Now, again,
this is depending on your insulation, right? So,
um, forgets a gram instead of eight
for CPU? It doesn't say. Since multicourse, let's say two.
And for storage, it recommends one terabyte,
which is increasingly high. Compare
to curator. Also, it was inside a boon to build right
and also at the note that it is more towards ideas i ps,
which again can be part of the firewall selection firewalls as well. So this might be one that you don't really need unless you want to replicate an environment that you have in your corporate network.
Let's take a look at Splunk right Splunk hardware
and in this case, blunt free
is a diversion, says recordings for *** Light.
Oh yeah, let's use those for now. So you got to six course, right? So too,
two plus gigahertz
until, let's say, two gigahertz
for success. Really four devices. And for RAM, it says told gigabytes of RAM. So you can see it's more power hungry than curator. But again, it could be because of the organization, right? Or the requirements
for, ah, large enterprise versus small interprets rate.
If you go here, you can actually tell you maybe the ram right here,
and actually it's based on the system. Now, in order to download Splunk, you can come here to products
scored a Splunk itself,
right, and you can come here
and you can go free Splunk right in the right corner
and come right down here
and here. You can actually you will have a look, A little logging thing. But as you can see already clocked in
and you will have different variants. You have windows,
you have Lennox,
and you can have Mac OSX. So what did this mean to you? What this means is you'll have to install this
in a already operating system, Right?
Unlike curator, that's own image. You will need a base operating system. And if you're gonna use, let's say, a Windows 10 system are your personal system like the one I'm using right now? That will be okay. You can sell your personal computer and use it kind of offline device. However, if you don't have Windows license issue might be required
to use a, um,
Lennox type of environment. In this case,
I'll be considering it for offline type of insulation and therefore, how installed it as a Windows 10 device and use curator asked my aunt always life installation. OK,
please click, download and just wait for that download to finish,
the less the next one on our tool. It's awesome from alien, both
right, and you can see it's two gigabytes of Ram, actually the lowest one of all so far
and in 2 25 of Hard Drive
and thats CPU. It doesn't actually say what it always has studied toward 64 bits. So actually that's
go there and see a little more details in here in the actual insulation to Cebu course.
And actually 250 gigabytes, 4 to 8. So let's say four,
eight and 250.
Fill lower and everything else, so that's really good. And for Ram CPU, it's always says to see views into sea views,
and again, it's very low. I might do also a environment very similar, like
offline and maybe use Curator asked the life system as many locks. Horses will allow you to push sis locks are application lots of multiple devices. Okay,
so let's look for that installation. If you literally type wholesome download, it will come
towards this. Apparently, this part of AT and T I was not aware that
Oh, good to know.
And then obviously you will have to Actually, it's already downloading, so that's gonna get
Okay, so this is more like a community,
Timothy. So that's really good. No annoying emails. I guess marketing e mails will be approaching you from Stalin knows. Um,
Last nihilists, old sack and, SSosa, Intrusion detection systems latch. I p s a swell,
um, and it required front at linens or Santos. Right. So what we're gonna do is we're gonna literally copy
what we saw for the web proxy
and type it here. And for that purpose is will add it to the ideas I ps lis later on.
Well, we have our list fully completed. We can determine easily that two of these are label s s. I answered. In reality, they're more of ideas. I ps temper perspective, right? This is snort, and you'll also be Oh, ***, right.
Therefore, it doesn't mean it cannot accomplish this type of approach is, but it's not a tool of specifically require for it. And therefore, if you put it in a restaurant at oh, I have used, uh, start s I am look a little bit. We're great.
Therefore, we will add those to the I. P s I. D s list, which will also have to consider that, as mentioned previously, that firewalls might happen already interred, and therefore we might avoid that step altogether. What did we learn today? We learned that
even though all sec
and snort our labor S s I e ems, they're actually more of a I. D. S I. P s perspective
and a squid
can run within a sentence or requires actual appliance, right? Actually OS in it in order to run. Therefore, we will not be setting VM specifically for these three,
but we can run them if required within our environment.
Now what we learn is you know, this resource is required asylums and approximate now taking consideration that many up thes right such as the West proxy and some of the S. I. P s ideas. Tools that we mentioned are contained within the next Gen Pharrell.
Therefore, unless you really need to have that segmented type of approach or your corporate environments uses his specific tool, you're not really required to install all these different plug ins instead instead of models
that each of these firewalls include, therefore making your life easier, your configuration easier and your insulation zis years help. You had a great fun class today and I hope to see you in the next course. Have a great day