SNHU - Implementing NAT and Allowing
Remote Access
Introduction
Objective
CompTIA Security+ Domain:
Domain 1: Network Security
CompTIA Security+ Objective Mapping:
Objective 1.1: Implement security configuration parameters on network devices and other
technologies.
Objective 1.2: Given a scenario, use secure network administration principles.
Overview
Overview
NAT stands for Network Address Translation and allows many machines with private IP
addresses to use a single Public IP Address to connect to the Internet. In this lab, you will
implement NAT on a firewall.
firewall
A firewall can block traffic or redirect traffic to hosts on the internal network.
pfSense is an open source firewall that uses a BSD-based firewall.
NAT
Network Address Translation can be used to allow internal IP addresses access
to the WAN.
VPN
Virtual Private Network allows you to connect to a LAN for the Internet and
access resources.
pfSense an open source firewall that is widely used in the industry
ping
an operating system utility that allows you to test for TCP/IP connectivity
between hosts
Understanding NAT
Key
Term
Description
Click on the Windows 10 icon in the topology, then double-click on the desktopcmd
- Shortcut.
1
Verify that you can ping the external Windows 8 machine on the WAN by typing
the following command and then press Enter.
2
C:\Users\student>
ping 175.45.176.200
C:\Users\student>
exit
Type the following command then press Enterto leave the Command Prompt
session.
3
Double-click on the Wireshark shortcut to launch the protocol analyzer.
4
Double-click on the Ethernet0 from the list of available interfaces to start Wireshark.
5
Click thebar in the right hand corner to minimize Wireshark.
6
Double-click on the cmd - Shortcut to open the Command Prompt on Windows 10.
7
C:\Users\student>
ping 175.45.176.200 −t
and then press Enter.
Perform a continuous ping on the external Windows 8 machine on the WAN by
typing
8
Click Wireshark in the Windows taskbar to bring the program back into focus.
9
Click the Stop button to stop the capture.
10
In the Wireshark filter pane, type
ip.dst == 175.45.176.200
and then click the
Apply this filter strain to the display button
11
Apply this filter strain to the display button.
View the diagram below. NAT allows internal hosts on the LAN with private IP
addresses to communicate with external hosts on the WAN with public IP addresses.
12
Click File from the Wireshark menu bar and then click Close. Click Continue without
Saving.
13
Click File from the Wireshark menu bar and thenclick Quit.
14
Click on the external Windows 8.1 icon on the topology. Then double-clickon the
desktopcmd - Shortcut link.
15
View the diagram. A machine on the WAN can only reach other machines on the
WAN. Only if the firewall redirects the user to the internal machine or the WAN
machine uses a VPN can a user from the public Internet (WAN) reach a machine that
is on the LAN.
16
C:\>
nmap 203.0.113.100
C:\>
exit
Type the following command and then press Enter to determine what ports are open
on the firewall.
17
Type
exit
and then press Enter, to leave your Command Prompt session.
18
Double-click on the shortcut to Wireshark on the desktop.
19
p
9
Select Capture from the menu bar and then choose Interfaces.
20
Click Start to start the Wireshark capture.
21
Click the Stop button to stop the capture.
22
Click the Stop button to stop the capture.
22
In the Wireshark Filter pane, type
ip.dst == 175.45.176.200
and then click
Apply.
23
View the diagram below. The external machine can only see the traffic originating
from the WAN IP, not the LAN IP that is using NAT to reach its destination on the
WAN.
24
Click File from the Wireshark menu bar and then click Close, then click the Continue
without Saving button.
25
Click File from the Wireshark menu bar and the click Quit.
26
S i h b k h i l Wi d 10 hi h LAN Cli k h X i h
27
C:\Users\student>
exit
Conguring NAT
Switch back to the internal Windows 10 machine on the LAN. Click the X in the
upper right corner to close the Command Prompt.
27
Double-click on the cmd - Shortcut.
1
C:\Users\student>
ping 175.45.176.200
and then press Enter.
C:\Users\student>
exit
Verify NAT works by pinging the external Windows 8 machine on the WAN by
typing
2
Type the following command and press Enter, to leave the Command Prompt
session.
3
Click the Edge icon in the taskbar on the bottom of the Windows 10 machine.
4
Type
http://192.168.1.254
and click the next arrow.
5
For the Username, type
admin
, and for the Password, type
pfsense
. Click Login.
6
Click the X to close Would you like to save your password for 192.168.1.254?
7
Click on Firewall and then click on Rules.
8
Note: It might take up to 20 seconds to display the Firewall Rules.
Click on the LAN icon on the desktop to launch the Firewall: Rules for LAN.
9
Check the all boxes on the left and click the X button on the right hand side to delete
it.
10
Click OK when you are asked Doyou really want to delete this rule for each rule.
11
Click Apply changes to apply the rule.
12
Your screenshot might vary slightly with different rules.
C:\Users\student>
ping 175 45 176 200
Click the bar in the right top part of Edge to minimize the window.
13
Double-click on the cmd - Shortcut.
14
Verify NAT fails by pinging the external Windows 8 machine on the WAN by typing
the following command. Thenpress Enter.
15
C:\Users\student>
ping 175.45.176.200
C:\Users\student>
exit
Type the following command and then press Enter,to leave the Command Prompt
session.
16
Click Edge in the Windows taskbar to bring the program back into focus.
17
Click the + button in the top right hand corner to add a rule.
18
Your screenshot might vary slightly with different rules.
Click the arrow on the Protocol box and select any.
19
ClickSave.
20
Click Apply changes to apply the rule.
21
Your screenshot might vary slightly with different rules.
Click the X in the right corner to close the Edge browser.
22
C:\Users\student>
ping 175.45.176.200
Double-click on the cmd - Shortcut.
23
Verify NAT works again by pinging the external Windows 8 machine on the by
typing the following command. Then press Enter.
24
C:\Users\student>
exit
Secure Remote Login
Type the following command and press Enter,to leave the Command Prompt
session.
25
Click on the Windows Server icon on the topology.After the server is
loaded,presstheSend Ctrl+Alt+Delete buttonin the upper right corner.
1
Note: If you do not see the blue desktop, click the desktop.
Log onas
administrator
with the password of
P@ssw0rd
, thenclickthearrow.
2
Click on the Start button, go to Administrative Tools, and select Routing and Remote
Access.
3
Right-click on the SERVER (local) and select Configure and Enable Routing and
Remote Access.
4
Click Next and the Welcome to the Routing and Remote Access Server Setup
Wizard.
5
Click Custom configuration and click Next.
6
Check the box for VPN Access and then click Next.
7
Click Finish.
8
Click Start service.
9
Double-click on the Command Prompt shortcut on the Windows Server 2008
desktop.
10
C:\>
dsa.msc
Type the following command and press Enter, to open the Active Directory Users
and Computers interface.
11
Expand the + boxon the left ofcampus.edu domain and double-click on the Users
container.
12
Right-click on Administrator and select Properties.
13
Click the Dial-in tab and then click Allow access. Click OK.
14
Clickonthe Windows 10 machine. Then clickon the Edge icon in the taskbar.
15
Type
http://192.168.1.254
and click the next arrow.
16
For the Username, type
admin
, and for the Password, type
pfsense
. Click Login.
When asked Would you like to save your password for 192.168.1.252?, click the X to
close this dialogue.
17
close this dialogue.
Click VPN and then select PPTP.
18
Note: this may take up to 20 seconds to show the PPTP Configuration.
Select Redirect incoming PPTP connections to: and type
192.168.1.10
into the
19
PPTP redirection box, then Click Save.
Click on the external Windows 8.1 machine in the topology. Right-click on the
Windows button in the lower left-hand corner and then select Control Panel from the
list of links.
20
In the Control Panel menu, select Network and Internet.
21
Click the link to the Network and Sharing Center.
22
Click the link to set up a new connection or network.
23
Click Connect to a workplace and click Next.
24
Click Use my Internet connection (VPN).
25
Click I’ll set up an Internet connection later.
26
Type
203.0.113.100
for the Internet address and click Create.
27
Click Change adapter settings.
28
Right-click the VPN Connection and select Properties.
29
Click the Security tab. Click the drop down box and select Point to Point Tunnelling
Protocol (PPTP). Click the radio button to Allow these protocols. Click OK.
30
Right-click on VPN Connection and select Connect / Disconnect.
31
Click the VPN Connection in the right hand pane. Click Connect.
32
In the top box, type
administrator@campus.edu
. Type the password of
P@ssw0rd
.
Click OK.
33
You will see a message that the VPN Connection is Connected.
34
© 2022 - Infosec Learning INC. All Rights Reserved.
Note: Press the STOP button to complete the lab.