Deprecated: Methods with the same name as their class will not be constructors in a future version of PHP; GSC_Widget has a deprecated constructor in /home/lopese/www/wp-content/plugins/google-custom-search/widget.php on line 20

Deprecated: La méthode du constructeur appelée pour WP_Widget dans GSC_Widget est obsolète depuis la version 4.3.0 ! Utilisez __construct() à la place. in /home/lopese/www/wp-includes/functions.php on line 4806

Deprecated: get_plugin_data est appelé avec un argument qui est obsolète depuis la version 3.0.0 ! The Site Wide Only: true plugin header is deprecated. Use Network: true instead. in /home/lopese/www/wp-includes/functions.php on line 4997

Notice: Constant FORCE_SSL_ADMIN already defined in /home/lopese/www/wp-config.php on line 79

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340

Warning: preg_replace(): Compilation failed: invalid range in character class at offset 4 in /home/lopese/www/wp-content/plugins/crayon-syntax-highlighter/crayon_langs.class.php on line 340
Souvenirs de BTS: Mise en place d'un Firecluster Watchguard - Le Blog de Mickaël LOPES

Souvenirs de BTS: Mise en place d’un Firecluster Watchguard

by Mickaël LOPES
2 comments

PTI 3: Mise en place d’un FireCluster WatchGuard

Les objectifs de cette activité sont de mettre en place une tolérance de panne entre deux firewall WatchGuard et sécuriser les échanges entre les réseaux LAN et WAN.

Schéma de l’activité:

PTI3 1

Configuration du pare-feu et du proxy

Par défaut le pare-feu autorise toutes les connexions entrantes et sortantes (Dans mon cas, il s’agit de la règle 8). Apres l’avoir désactivé, il faut autoriser les protocoles qui nous sont utiles pour accéder à internet.

PTI3 2

La notion de proxy sous WatchGuard permet de filtrer les URL et donc d’interdire l’accès à certains sites aux utilisateurs. La notion de WebBloker ne sera pas démontrée dans ce PTI car la licence n’est plus active.
Voici la fenêtre de configuration de ma règle http-Proxy-PTI (Règle n°2). On peut voir que le mot « yahoo » se retrouve dans une URL, le firewall bloquera la requête.

PTI3 3

Configuration du FireCluster

Il existe 2 modes de FireCluster sur WatchGuard :
– L’actif/Actif qui correspond au Load Balancing ,
– L’Actif/Passif ou Actif/ En Vieille qui correspond à la continuité de service en cas de crash d’un équipement.

J’ai décidé de démontrer l’Actif/Passif dans ce PTI.

La technologie WatchGuard pour l’Actif/Passif réside sur le principe qu’un des firewall est Actif, il récupère donc toutes les connexions entrantes et sortantes et qu’un autre firewall est en standby. Les deux firewall sont reliés entre eux par un câble RJ45 croisé et sur une interface dédiée. Ils échangent des informations sur les connexions qui se déroulent actuellement. En cas de crash du Firewall Maitre (Actif) le deuxième Firewall récupère tous les paramètres du Firewall maitre (IP, Connexions en cours) et reprend donc le relai.

PTI3 4

Ici nous pouvons voir les paramètres réseaux que se partagent les Firewall, à savoir :
L’interface externe sur eth0 : 192.168.0.49/24
L’interface LAN (Trusted) sur eth1 : 192.168.2.1/24
L’interface DMZ (Optional-1) sur eth2 : 10.0.2.1/24
L’interface eth3 (Optional-2) qui est utilisé pour le FireCluster

Test du FireCluster

Le test sera démontré sur un trafic ICMP au travers d’un ping vers un réseau extérieur.
Les étapes du test :
1/ Initialisation du trafic
2/ Simulation d’une panne d’un équipement
3/ Constat des traces
4/ Réponse du trafic

PTI3 5

Constat/Particularité :
On peut voir qu’après 4 ping de perdu, la connexion reprend sur l’autre Firewall.
On peut voir que le Firewall maitre ne reprend pas le relai quand il est de nouveau opérationnel. La notion de Firewall Actif et Passif n’est pas fixe. Le Firewall le premier présent sur le réseau est Actif et le second sera en Passif jusqu’à arrêt du firewall maitre

Conclusion

La mise en place d’un Pare-feu permet le contrôle des protocoles entrant/sortant entre notre réseau LAN et WAN. Cela permet de prévenir le réseau LAN des attaques provenant d’Internet sur des protocoles ou ports non conventionnels.

Le FireCluster permet la tolérance de panne d’un des équipements de sécurité. Il assure une continuité de service. Ce type d’architecture devient une sécurité supplémentaire pour les entreprises travaillant sur des solutions de type SaaS, PaaS, Iaas ou avec des serveurs héberger.

A bientôt.

-Mickaël

You may also like

2 comments

Pedro 1 mars 2017 - 16:48

Salut, quel programme avez-vous utilisé pour faire ces diagrammes de réseau?
Meilleures salutations,

Reply
Mickaël LOPES 7 mars 2017 - 08:52

Bonjour, tout simplement Microsoft Vision avec les stencils WatchGuard : http://www.watchguard.com/wgrd-resource-center/visio-icons

Reply

Laisser un commentaire

Ce site utilise Akismet pour réduire les indésirables. En savoir plus sur comment les données de vos commentaires sont utilisées.

En continuant à utiliser le site, vous acceptez l’utilisation des cookies. Plus d’informations

Les paramètres des cookies sur ce site sont définis sur « accepter les cookies » pour vous offrir la meilleure expérience de navigation possible. Si vous continuez à utiliser ce site sans changer vos paramètres de cookies ou si vous cliquez sur "Accepter" ci-dessous, vous consentez à cela.

Fermer