Understanding Cybersecurity: Network Segmentation

  Рет қаралды 41,161

Intelligence Quest

Intelligence Quest

3 жыл бұрын

In this video Travis discusses why network segmentation is used as well as some common practices for segmenting networks. He uses the example of a small to medium office environment where it would be good security practice to segment IOT devices. He presents the concept of VLANs as well as routing between segmented networks and why network segmentation makes this more difficult.
► Stay in touch!
Follow: / travisiq
Website: intelligencequest.com/
Instagram: / travis_iq
Linkedin: / traviswentworthiq

Пікірлер: 39
@Dalai33
@Dalai33 6 ай бұрын
One of the very most underrated channels here! Oh my God thank you very very much
@intelligencequest
@intelligencequest 6 ай бұрын
Thanks so much for the kind words!
@MrUnisteez
@MrUnisteez 2 жыл бұрын
Thanks! This was a simple explanation that gave me just enough information to answer a lot of the questions I had about network segmentation using VLANs.
@jackdavies7337
@jackdavies7337 3 жыл бұрын
So helpful thank you.
@theancientvoice9272
@theancientvoice9272 6 ай бұрын
Great content, thank you!
@lasagna3084
@lasagna3084 Жыл бұрын
Super helpful!
@techenthusiast4542
@techenthusiast4542 Жыл бұрын
Good info brother!
@omarinv7863
@omarinv7863 2 жыл бұрын
Great video thank u so much
@sonnix31
@sonnix31 4 күн бұрын
Nicely explained, Thanks
@intelligencequest
@intelligencequest 4 күн бұрын
thanks for the positive feedback! much apprecaited
@31qwoz
@31qwoz 3 жыл бұрын
Great information
@loganborowski
@loganborowski 3 жыл бұрын
Great content thank you.
@intelligencequest
@intelligencequest 3 жыл бұрын
Thanks! Next up is access control lists!! Should have it out tomorrow!
@techlife4599
@techlife4599 2 жыл бұрын
In Mr. Burns voice....EXXCEELLENT... Great video. I'm a suscriber & sharing 👍
@intelligencequest
@intelligencequest 2 жыл бұрын
Thank you! Let's goooo!
@StuckInTheM1ddle
@StuckInTheM1ddle 2 жыл бұрын
Appreciate this for for an office environment but just for anyone (like myself) looking for ways to segregate a home network, having a L2 Switch (VLAN capable) is not enough for looking to implement VLAN in this way - you need a router that supports VLAN's and nearly all consumer-level routers don't support this.
@intelligencequest
@intelligencequest 2 жыл бұрын
I would look into Ubiquiti, they offer some great consumer grade products that I have installed in a number of homes. Their equipment is great for network segmentation implementations
@clovisvigneault
@clovisvigneault 3 ай бұрын
You can always find a consumer router that can be flashed to openwrt or ddwrt to unlock these « enterprise » feature, they have lists of compatible routers with their specs
@wendy_113
@wendy_113 9 ай бұрын
"Thank you very much!"
@Allexz
@Allexz 3 жыл бұрын
You deserve more subs!
@intelligencequest
@intelligencequest 3 жыл бұрын
Thanks a lot! I appreciate the encouragement
@leaftro
@leaftro 3 жыл бұрын
Word of Truth!
@intelligencequest
@intelligencequest 3 жыл бұрын
@@leaftro thanks the feedback is much appreciated!
@daizy8888
@daizy8888 10 ай бұрын
This is great video! would you mind clarifying the use of VRF in a segmented network?
@intelligencequest
@intelligencequest 10 ай бұрын
Absolutely! so in the video above I was addressing L2 segmentation, VRF would effectively allow for segmentation of traffic as it was being routed --> think two sets of clients being routed by the same piece of hardware, but for security, logging, analytics you want each of the client networks have their own routing instances, you can utilize Virtual Routing and Forwarding (VRF) to route this traffic but maintain separation of traffic and routing tables
@amigatommy7
@amigatommy7 Жыл бұрын
Thinking of 2 10gbe switches with Asus 89x router which has 2 10gbe ports. Not sure both can be used at the same time.
@intelligencequest
@intelligencequest Жыл бұрын
TBH I'm not sure either tom
@rozye3004
@rozye3004 Жыл бұрын
You are super cute ! The Humor makes it enjoyable to watch ❤
@MorgorDre
@MorgorDre Жыл бұрын
So whats the actual threat prevented?
@intelligencequest
@intelligencequest Жыл бұрын
So the "threat" in this case is that any one of the device on your network is compromised. If this occurs and your network is segmented the likelihood of your entire network being compromised is significantly lower. To give you a specific threat example, you could have your file storage server compromised (in a small/medium environment this might be a single device like a Synology NAS). Even more specifically, an attacker leverages vulnerabilities in the file sharing protocol SMB to upload and run software establishing persistence on this file server. If your network is segmented appropriately the attacker will NOT have the ability to pivot to all the other devices in the network. If your network is not segmented, all of the other devices are now potentially victims as well.
@techenthusiast4542
@techenthusiast4542 Жыл бұрын
What gear do you use to draw? (hardware and software) Wacom?
@intelligencequest
@intelligencequest Жыл бұрын
Yes wacom intuous tablet and pen
@techenthusiast4542
@techenthusiast4542 Жыл бұрын
@@intelligencequest I just started using it and long ways to go to make it look natural. Right now I struggle in meetings with new work from home situation. Was so used to whiteboard and markers 🤣
@intelligencequest
@intelligencequest Жыл бұрын
@@techenthusiast4542 100%.. it just takes time.. but I still don't think there is any replacing in person white boarding.. I think a mix of virtual and live has to be what we use going forward 👍
@macster1457
@macster1457 2 жыл бұрын
Can I still do with if I want to segregate my wireless security cameras? - am I going to need 2 wireless routers then?
@intelligencequest
@intelligencequest 2 жыл бұрын
There are a couple of things that you can do, but the most common is to make a second SSID aka IOTnetwork with its own password and IP address range and segment that network from your primary wireless network. By segment I mean either add ACL entries if you want to allow certain traffic or deny all traffic from that IOT network to the rest of your network (the implementation of this will be different on different Network Operating Systems - NOS')
@macster1457
@macster1457 2 жыл бұрын
@@intelligencequest yes... the other thing I need to accomplish is to completely isolate the wireless cameras from the main router. I need to figure out a way to have a 2nd router just for the cameras so the main router has nothing to do with them.
@tamashalmai8224
@tamashalmai8224 3 жыл бұрын
The security concepts such as L2 segmentation, FW, ACL, router on a stick etc. are all fine. However, my impression is that you try to cover too much in this vlog and give the wrong impression to an especially novice user that these basic security techniques are the holly grails that will cure all security concerns. Therefore I would rather start with a top-down analysis, highlight potential attack vectors and demonstrate which technique would be suitable to mitigate what concern. I.e. what you mention few times in your vlog as defense-in-depth
@intelligencequest
@intelligencequest 3 жыл бұрын
Thank you for the feedback! I actually agree to some extent and I think we are trying to fill in the gaps in this content with subsequent videos.. in response to the "cure all nature" of this segmentation video... that certainly was not the intent! How ever we do think segmentation is an area of basic networking that is very under utilized is most small and medium networks.
Cybersecurity Architecture: Networks
27:31
IBM Technology
Рет қаралды 102 М.
100❤️
00:19
MY💝No War🤝
Рет қаралды 21 МЛН
когда повзрослела // EVA mash
00:40
EVA mash
Рет қаралды 4,6 МЛН
Heartwarming: Stranger Saves Puppy from Hot Car #shorts
00:22
Fabiosa Best Lifehacks
Рет қаралды 22 МЛН
Home Lab Network Security! - vlans, firewall, micro-segmentation
18:29
VirtualizationHowto
Рет қаралды 45 М.
Network Ports Explained
10:33
PowerCert Animated Videos
Рет қаралды 1,5 МЛН
DO NOT design your network like this!! // FREE CCNA // EP 6
19:36
NetworkChuck
Рет қаралды 3,2 МЛН
Microsegmentation Overview
16:38
Zero Networks
Рет қаралды 6 М.
DMZ Explained | Demilitarised Zone
6:11
CertBros
Рет қаралды 33 М.
Home Networking 101 - How to Hook It All Up!
8:30
Budget Nerd
Рет қаралды 4,7 МЛН
😱Хакер взломал зашифрованный ноутбук.
0:54
Последний Оплот Безопасности
Рет қаралды 703 М.
iPhone 16 с инновационным аккумулятором
0:45
ÉЖИ АКСЁНОВ
Рет қаралды 8 МЛН
Cheapest gaming phone? 🤭 #miniphone #smartphone #iphone #fy
0:19
Pockify™
Рет қаралды 2,4 МЛН