Cisco IOS Firewall Features
As mentioned in the beginning of this chapter, the Cisco IOS firewall feature is an enhancement to the Cisco IOS Software that incorporates additional security-related features. The Cisco IOS firewall provides an additional level of security for the network without the expense of purchasing dedicated hardware. The Cisco IOS firewall feature set was first introduced as CiscoSecure Integrated Software (CSIS). The Cisco IOS firewall overview lists the following features:
■ Standard and extended access lists—The router can be configured to perform basic traffic filtering by using standard or extended access lists.
■ Dynamic access lists—Dynamic access lists are used to configure lock-and-key traffic filtering. This is the capability to generate dynamic temporary access through the firewall for specific predefined circumstances. This feature provides a more flexible method for filtering network access.
■ Reflexive access lists—Reflexive access lists only allow specific traffic to maintain state. In other words, traffic that is generated on an internal network is allowed through the firewall only until the initial session state has terminated. Reflexive access lists are used only if context-based access control (CBAC) is not implemented.
■ System auditing—The firewall maintains a record of all transactions in an orderly format that can be used for detailed reports.
■ TCP intercept—TCP intercept is used to prevent a type of denial-of-service (DoS) attack known as the TCP SYN flood. This feature is used only if CBAC is not implemented.
■ Java blocking—The firewall scans Java code and can block code that is unsigned or determined to be malicious.
■ Context-based access control—CBAC examines traffic passing through the firewall at all layers (up to the application layer). CBAC is used to generate dynamic access lists.
■ Cisco IOS firewall IDS—The Cisco IOS firewall IDS is a signature-based IDS that can be configured to take the following actions when an intrusion is detected:
— Send an alarm to the director
— Drop the packet
■ DoS mitigation—The system is designed to detect and react to DoS attacks.
■ Authentication proxy—Authentication proxy is used to proxy authentication requests to a AAA server. This allows authentication to occur on a per-user basis.
■ Port-to-application mapping (PAM)—PAM enables administrators to specify which ports can be used for which services. This allows for the configuration of services on nonstandard ports when traversing the firewall.
■ Security server support—The Cisco IOS firewall supports the following AAA servers:
— Kerberos
■ Network Address Translation (NAT)—The Cisco IOS firewall supports NAT and Port Address Translation (PAT). NAT enables administrators to translate RFC 1918 addressing to public addressing on a one-for-one basis, and PAT enables administrators to hide an entire internal network behind a single public address. The Cisco IOS firewall supports the use of both NAT and PAT on the same device.
■ IPSec network security—The Cisco IOS firewall supports all the standard IPSec protocols. This allows for the configuration of VPNs.
■ Neighbor router authentication—The Cisco IOS firewall can authenticate its peer routers to ensure that all routing updates are legitimate.
■ Event logging—The Cisco IOS firewall logs all error messages and system events to the console terminal by default. These messages can be redirected to a syslog server for easy storage and recovery. The system logs are commonly used for troubleshooting connection issues and for network forensics.
■ User authentication and authorization—Integration with AAA servers allows for authentication and authorization on a per-user basis. This functionality enables administrators to designate specific permissions for users and groups.
■ Real-time alerts—The firewall can be configured to perform alert functions in the event of a known attack or other event that is determined to be a severe security risk.
Continue reading here: Securing Console Access
Was this article helpful?