Question

Sheridan Lab 2: Access Control with Security Groups and TCP analysis TELE20483 Submission Instructions Value Due Date To be submitted via SLATE 12.5% of final grade June 25th, 2023 Learning

Outcomes Covered in Assignment Winter 2023 1. Analyze protocol encapsulation to implement secure access to resources. 2. Apply the concept of port and address control to configure security groups. 3. Configure and test network access control for elastic virtual computers. 4. Test security groups to control access to virtual machines. TELE20483 Table of Contents LAB 2: ACCESS CONTROL WITH SECURITY GROUPS AND TCP ANALYSIS 1. ASSIGNMENT OUTLINE. 2. ASSIGNMENT DETAILS AND EXPECTED OUTCOMES... 3. USE WIRESHARK TO CAPTURE THE TRAFFIC AND ANALYZE THE NETWORK COMMUNICATION.......7 4. SUBMISSION REQUIREMENTS.. 5. ASSIGNMENT GRADE BREAKDOWN. 6. SUGGESTED IMPLEMENTATION STEPS. 7. APPENDIX - ARTIFACTS TO BE INCLUDED INTO THE REPORT. Winter 2023 0 .4 ..9 .11 .12 TELE20483 1. Assignment Outline The objective of this assignment is to explore network security controls available in AWS, namely Security Groups and NACLs (network access control lists). The students will deploy 3 EC2 instances in the different subnets using AWS python boto3. The instances will have different initialization scripts as described in the Assignment Details and Expected Outcomes section below and, as a result, will have different connectivity requirements. The students will define respective security groups and NACLs and verify that the applications running in containers can be accessed successfully. The verification will be done via browser and Wireshark desktop application. Winter 2023 TELE20483 2. Assignment Details and Expected Outcomes In this assignment, the student is to perform the tasks below: Deploy three EC2 instances using python script and boto3 library. The instances should be deployed into different subnets as specified in Figure 1 below. Instances specification below should be reflected in the user data scripts used by AWS to initialize the EC2 instances: ● ● O VM1 is a plain EC2 instance with no applications installed. VM2 and VM3 will be running three containerized applications using Docker. On each of VM2 and VM3, two containers are NGINX webservers, and one is a MongoDB (see in Figure 1 and in Figure 2 for details). Create security groups that accomplish the communication specified in the in Figure 1 below and in the Table 1: O Administrator Winter 2023 aws VPC VM1 172.31.0.0/20 1) SSH, ping and traceroute http ping VM2 Port Port Port 8081 8082 27017 172.31.16.0/20 2) SSH to EC2, HTTP to containers VM3 Port Port Port 8081 8082 27017 172.31.32.0/20 3) SSH to EC2, HTTP to containers Figure 1 Python script should create 3 EC2 instances in 3 different subnets.