Shrink an implicit trust zone and measure it
Task
Measure what one lab VM can reach on another, apply a default-deny inbound policy that admits only the flows you can justify, and measure again. The firewall is your enforcement point, your list of justified flows is the policy, and the difference between the two counts is the implicit trust zone you removed.
Steps
- From the Linux VM, record what the Windows VM exposes to it with a gentle sweep of the machine you built:
nmap -Pn --top-ports 100 10.99.0.20 -oN /tmp/before.txt. If nothing is open, turn on Remote Desktop or file sharing on the Windows VM first, so there is a trust zone to shrink. - List each open port in
/tmp/trustzone.mdand write beside it the reason this one source needs to reach it. Treat the Windows VM as an application server: the question is which applications this subject is entitled to, not what happens to be listening. Most ports will have no reason. - On the Windows VM, set inbound traffic to block by default on every profile:
Set-NetFirewallProfile -Profile Domain,Private,Public -DefaultInboundAction Block. - Re-admit only the flows you justified, each scoped to the one source that needs it, for example
New-NetFirewallRule -DisplayName 'lab-allow-rdp' -Direction Inbound -Protocol TCP -LocalPort 3389 -RemoteAddress 10.99.0.10 -Action Allow. Then disable every other enabled inbound allow rule, because a default of block does nothing to traffic an existing rule already admits:Get-NetFirewallRule -Direction Inbound -Enabled True -Action Allow | Where-Object { $_.DisplayName -notlike 'lab-allow-*' } | Disable-NetFirewallRule. - Re-run the same sweep to
/tmp/after.txt, and add both counts to/tmp/trustzone.mdwith one sentence on what a stolen session on the Linux VM could reach now compared with before.
Verify
grep -c '^[0-9]*/tcp *open ' /tmp/before.txt
grep -c '^[0-9]*/tcp *open ' /tmp/after.txt
python3 - <<'PY'
import re
def opened(p):
return [l.split('/')[0] for l in open(p) if re.match('^[0-9]+/tcp +open ', l)]
b, a = opened('/tmp/before.txt'), opened('/tmp/after.txt')
print('reachable before:', len(b), b)
print('reachable after :', len(a), a)
assert len(a) < len(b), 'the trust zone did not shrink'
assert set(a) <= set(b), 'the new policy opened something that was not open before'
PY
The assertion requires the second count to be genuinely lower than the first, so the lab cannot be passed by running two sweeps and declaring success, and the second assertion catches a rule that admits more than it replaced. If the count did not move, an enabled built-in rule is still admitting the traffic -- list them with Get-NetFirewallRule -Direction Inbound -Enabled True.
Notes
What you measured is the implicit trust zone from the lesson: everything reachable once a subject is through. A host firewall is a crude enforcement point -- it decides on addresses and ports, not on identity or device health -- which is exactly why zero trust puts a policy engine and a per-application broker in front of resources instead. The same exercise run the other way, limiting what the Windows VM may start towards the Linux VM, stops the trust being one-way by accident.
This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.