CBAC Configuration Task List

Configuring CBAC requires the following tasks:

1. Pick an interface: internal or external.

2. Configure IP access lists at the interface.

3. Configure global timeouts and thresholds.

4. Define an inspection rule.

5. Apply the inspection rule to an interface.

6. Configure logging and audit trail.

7. Following other guidelines for configuring a firewall.

8. Verify CBAC (optional).

Example 6-6 shows a router named R1 with two Ethernet interfaces, one defined as the inside interface (EthernetO) and the other defined as the outside interface (Ethernetl). For this example, CBAC is being configured to inspect Real-Time Streaming Protocol (RTSP) and H.323 protocol traffic inbound from the protected network on a router with two Ethernet interfaces. Interface EthernetO is the protected network, and interface Ethernet1 is the unprotected network. The security policy for the protected site uses ACLs to inspect TCP/UDP protocol traffic. Inbound access for specific protocol traffic is provided through dynamic access lists, which are generated according to CBAC inspection rules.

Example 6-6 Access List Definition

R1(config)#

access

list

199

permit tcp any any eq telnet

R1(config)#

access

list

199

deny udp any any eq syslog

R1(config)#

access

list

199

deny any any echo-reply

R1(config)#

access

list

199

deny any any echo

R1(config)#

access

list

199

deny any any time-exceeded

R1(config)#

access

list

199

deny any any packet-too-big

R1(config)#

access

list

199

permit any any traceroute

R1(config)#

access

list

199

permit any any unreachable

R1(config)#

access

list

199

permit deny ip any any

ACL 199 permits TCP and UDP traffic from any source or destination, while denying specific ICMP traffic and permitting ICMP trace route and unreachable messages. The final deny statement is not required but is included for explicitness—the final entry in any ACL is an implicit denial of all IP traffic. Example 6-6 defines access-list 199 on Router Rl, which has two Ethernet interfaces: EthernetO and Ethernetl.

ACL 199 is applied inbound at interface Ethernet 1 to block all access (beside permitting Telnet, ICMP traceroute, and ICMP unreachables) from the unprotected network to the protected network. Example 6-7 configures the inbound ACL on R1.

Example 6-7 R1 Access List Inbound Configuration

R1(config)# interface ethernet1 R1(config-if)# ip access-group 199 in

An inspection rule is created for "users" that covers two protocols: RTSP and H.323. Example 6-8 configures R1 to inspect RTSP and H.323 traffic.

Example 6-8 Inspected Traffic

R1(config)#

ip

inspect

name users rtsp

R1(config)#

ip

inspect

name users h323

The inspection rule is applied inbound at interface Ethernet1 to inspect traffic from users on the protected network. When CBAC detects multimedia traffic from the protected network, CBAC creates dynamic entries in access-list 199 to allow return traffic for multimedia sessions. Example 6-9 configures the R1 unprotected network to inspect traffic on interface EthernetO.

Example 6-9 Inspects Traffic on R1 Protected Interface

R1(config)# interface Ethernet0 R1(config-if)# ip inspect users out

You can view the CBAC logs by three methods:

■ Debugging output (refer to the Cisco Documentation CD-ROM for full details)

■ Syslog messages (IOS command is show logging)

■ Console messages (system messages)

NOTE More advanced details on CBAC can be found at http://www.cisco.com/en/US/

partner/products/sw/iosswrel/ps1835/

products_configuration_guide_chapter09186a00800ca7c5.html.

After you complete the inspection of traffic, you can turn off CBAC with the global IOS command no ip inspect. The Cisco IOS Firewall feature set also supports AAA, TACACS+, and Kerberos authentication protocols. Port to Application Mapping (PAM) allows you to customize TCP or

UDP port numbers for network services or applications. The information in the PAM table enables CBAC-supported services to run on nonstandard ports.

NOTE Active audit and content filters are used with NetRanger and NetSonar (end of life) products to allow administrators to decipher (read and analyze) or reply (to the conversation between two devices) to networks when an intruder has accessed the network. CBAC is just another useful tool in Cisco IOS that allows a quick audit of an IP network. CBAC inspects traffic that travels through a firewall and can be used to discover and manage state information for TCP/UDP sessions.

Continue reading here: Network Based Intrusion Detection Systems

Was this article helpful?

0 0