📅 Day 109 — Firewalls, VPNs, Proxies, Security Zones, and CIDR
🔄 Topic
Understanding the defensive infrastructure that controls network access and visibility.
🎯 Goal
Learn how firewalls, VPNs, proxies, security zones, wireless security, subnetting, and CIDR support network defense.
🛠 What I Did
Today I continued the network operations section of Course 3.
The focus was on firewalls, VPNs, security zones, proxy servers, wireless protocols, subnetting, CIDR, WireGuard, and IPSec.
The practical question was:
How do organizations control where traffic is allowed to go?
The answer is a mix of segmentation, access control, routing, filtering, encryption, and monitoring.
🔗 Key Cybersecurity Connections
These controls create important security evidence.
Firewall logs may show allowed or blocked traffic. VPN logs show remote access. Proxy logs show web destinations. Security zones define which systems should be able to talk to each other. CIDR helps describe network ranges.
Example:
192.168.10.0/24
This describes a network range, not just one host. If an attacker scans that range, the defender needs to understand scope.
🔍 Investigation Questions
- Was traffic allowed or blocked?
- Which firewall rule matched?
- Was the source inside the expected zone?
- Was the destination in a sensitive network segment?
- Was VPN access used?
- Was the VPN login normal for the user?
- Did a proxy log the web request?
- Which CIDR range is affected?
- Should these two systems be able to communicate?
🚨 Detection Opportunities
Detection ideas:
- VPN login from rare location
- firewall deny spike to sensitive subnet
- internal host scanning across a CIDR range
- proxy request to suspicious domain
- traffic crossing zones that should be isolated
- repeated blocked attempts to admin ports
Example:
src_zone=user_workstations
dst_zone=database_servers
dst_port=1433
action=blocked
count=87
detection=possible_internal_scanning_or_misuse
🧭 MITRE ATT&CK Techniques
Possible mappings:
- T1021 — Remote Services
- T1046 — Network Service Discovery
- T1071.001 — Web Protocols
- T1090 — Proxy
- T1133 — External Remote Services
🗺 Visual Investigation Diagram
User device
↓
VPN / local network
↓
Firewall rule
↓
Security zone
↓
Proxy / inspection
↓
Destination service
⚠ Challenges
The challenge is understanding that network controls are not separate topics. They work together.
A VPN grants access. A firewall limits it. A proxy observes web traffic. Security zones reduce blast radius. CIDR defines scope.
📚 What I Learned
I learned that network defense is largely about controlling paths. Attackers look for paths that should not exist or credentials that let them cross boundaries.
➡ Next Steps
- Practice reading CIDR ranges
- Create examples of firewall allow and deny logs
- Map VPN, proxy, and firewall logs to investigation questions
- Draw security zones for a small business network
🧠 Reflection
This topic matters because many SOC alerts are really questions about access paths: who connected, from where, to what, and should that have been allowed?
🧩 Lessons Learned
What worked
Viewing controls as path-management tools.
What broke
Treating firewall, VPN, proxy, and zones as isolated concepts.
Why it broke
They are part of the same access-control and monitoring system.
Fix / takeaway
For every network event, ask what path the traffic took and which control observed it.
📈 Skill Progression Context
This supports my SOC analyst and detection engineering progression because it turns course material into investigation habits: identifying assets, reading evidence, asking better questions, and explaining security risk clearly.
Instead of treating the certificate as passive study, I am using each topic to build practical analyst thinking that can later become lab notes, detections, diagrams, or portfolio writeups.
😄 TL;DR
Network defense is mostly controlling paths attackers want to abuse.
