Hello, Siberians. Welcome to this lesson on Network Security group.
This lesson is part of the top Madu off the desert 500. Microsoft Azure security technologist costs
for simplicity. Happy referring to the aggravation energy going forward.
Now, I've got to tell you something. I'm really excited about this lesson on the rest off the lessons in this model.
And I'll tell you why
Everything that we've discussed and demonstrated about virtual network in so far was just laying the groundwork
from this lesson on World War actually starts this cost in network security technologies in hija. So I'm excited about that
quick information on what will be covering in this lesson.
We'll start out by looking at some NSG car concepts. Wouldn't look at energy rules on out there. Applied
on will be discussing the concept off poverty numbers and effective rules.
What? I will conclude with a demonstration off creating energy on associating hits. Let's get into this.
So, first of all, what is NSC?
It is a step for packet future that we can use to fuel the network traffic to and from as your resources in an azure virtual network.
Now, not is that I did not say fire. Well, not is the wording that I used year packet future.
This is because the amnesty does not do any deep packet inspection like a next generation firewood. Does Ali does. Is future packets what we configure in a Hennessy?
What we can figure out in the Hennessy of lose the content as security rules that allow or deny inbound or outbound network traffic.
Now, for each rule, we can specify sauce and destination, high p
source and destination parts and protocol. And finally, where do we associate or assign NSC? We can associate eat with a submit in an azure virtual network, or even directly to a VM network interface.
We mentioned earlier that energy contains security rules. Now it's rule in a Hannah she as a prophet in number,
and the importance of that is that the term is the order off evaluation. The way it works is that a lower positive would be evaluated fast. So, for example, if I have a deny vel with the poverty number off 2000
on an allowable for the same traffic, with the power of its A number off 3000 the traffic will be denied as the Route 2000 will be evaluated first.
When we create energy, it comes with setting default rules that we cannot delete on modify them.
However, we can override those rules by specifying ever with lower part number. So, for example, where you're looking at on the screen decided the fault rules on the usually vein from 65,000 to 65,500. We cannot change or modify does, however, we can place other rules above them.
We're looking at our Voser evaluated. It is important to recognize the order that applies, especially if we have rules, but at the network interface level. And that's the sub net level
for outbound traffic as your processes the Jews in the NSC associated to the network interface fast
and then the rules associated to the sub net afterwards
for inbound traffic as your processes, divorce in Energy Associate is to the sub net fast
and then to lose in the energy associated to the network interface after
if wherever gets to a point where we're confused as to what rules are applied,
there was a nice option in Azure that we can find under the networking aspect of a virtual machine called effective security rules. So you can see that in the diagram on the lower side of the screen
and using the effective rules, we can verify which rules are applied toe a network interface.
So now to the demonstration.
Yeah, the task that I'll be completing first our create energy.
How then had on inbound vote to block our DP to the NSG
Our touch the NSG to the network interface off my veteran machine.
Verify that devil confit got in the energy applies So in the first task I'll create a new energy so he has a visual representation of what are between.
I currently have the settle, but you're seeing on your screen on our create a new energy resource.
I'm back in the other Pato. If I go, I'd and click on Create a resource on I type network Security
on. I can see Network security group PSR click on that option and I'll click on Create.
Now put this in the same results group, which is the network iPhone. How g
I'll give it a name off win VM. I've been an A she
and I'll leave that in UK self. It needs to be in the same location as the resource that we applying. It's too,
are. Why don't leak review and creates
on our click on create. That should only take a few seconds and I shall have my network security group created.
So here we go. The NSC is fully created. So what our fast is, I'll go to review that so we can look at the photos that we talked about.
If I go to the inbound security rules, you can see the rules with poverty numbers 65,000 to 6 5500
and you can see that anything is allowed with the individual network on anything from the original load. Balancer is allowed inbound.
Nothing is allowed from the Internet inbound by default. If I click on our bond security rules, you can see that anything is allowed within the veteran network and anything is allowed out of bound to the Internet. So maybe that's something we want to modify to prevent the dye expatriation
in the next task. How beheading on in Badru to block our DP to the NSG Yes, official representation off what are between
so back in the azure Pato If I go, I'd and click inbound ruse.
Now click on the hard toe. Had a new inbound room. Now for the sauce out. Select a service stock so it's service tag is the least off I p addresses that managed by Microsoft's of Aladin. Always having to manage our own list so you can see that is a list for different services are just quiet and select Internet
Now for the sunspot are lived at a star
for the destination. I'll go ahead and leave that as any
and for the destination part unspecified port territory. It's nine, which is the port for? How. Dp for the protocol House Press. If itis IPI, which is the protocol for our DP and for the action I'll sets, that's a denying,
and I'll give that into a party to off 100
and for the name I'll say block
and our great and click on Heart.
Now that's successfully added to devote so we can move on to the next task.
So in the next task will be assigning the NSG that I just created to the network interface off my windows VM
on. There's a visual presentation off. What are between I have dish will already created in the energy and assign it to the network interface. So I'm back right in the azure Pato.
So what I can do is I Can Iraq click on network interfaces are sub next to associate the network security group here.
What? Audrey's I'll go to my virtual machine
also like my Windows virtual machine, and I'll go on the next working
now under networking. I have my network interface are click on Network Interface and I have Network Security Grill,
our political network security group, and I'll click on Edit.
I'll click on the option to specify Network Security Group, and I can see the security Gruebel I created earlier here. So I'll select that
and I'll click on safe.
So now that successfully associate ID the natural Security group with my network interface.
So in the next task have very fine that my energy is working as expected by attempting to connect to my windows VM using how deep E. On s official representation off what I'll be doing
from the Internet. Our attempts to connect use in our DP to the public i p of my VM Now, if remember, from the last listen, this worked successfully, but with nearly a plight energy, I expect the communication to be blocked by the NSC, so that's what I expect to happen. So let's go ahead and verify that.
So back in the agile Pato are violently convention machines. I'll select my Windows virtual machine.
Our copy the I P address off my Windows virtual machine, and I'll go open the mud sticks. Top clients.
How did remote desktop client here on defy quiet and paste the high P address in effect, click on Connect
He has some supplemental links for further studies on the topics covered in this lesson. He has a summary of what we covered,
who started out by looking at some NSC core concepts.
But then this cost energy rules and how they are applied, especially the concept around profits in numbers on the scope off the sub net, a network interface
and finally, I demonstrators, the Creation and Association off NSC TV EMS Network interface.
This brings me to the end of this video tense very much for watching, and I'll see you in the next lesson