Firewall Config
Application Inspection
A stateful firewall can easily examine the source and destination parameters of packets passing through it. Many applications use protocols that also embed address or port information inside the packet, requiring special handling for examination. Application inspection allows a firewall to dig inside the packets used by certain applications. The firewall can find and use the embedded information in its stateful application layer inspection engines. Embedded address information can also become...
Initiating Multiple Context Mode
Follow these steps to prepare a firewall for multiple-security context support 1. Verify multiple-context licensing A firewall can run in multiple-context mode only if it has been licensed to do so. As well, the maximum number of security contexts is set by the license. You can display the number of contexts supported by the current license, as shown in the following output Firewall show activation-key Serial Number 401262144 Running Activation Key 0xcc05f166 0xd4c17b68 0x98501048 0x818cf190...
Configuring the Initial Csc Ssm Settings
The CSC SSM must be configured independently of the ASA. You can use several methods to connect to and configure the CSC. Most often, you use ASDM as your interface to the CSC, although other methods are discussed as they are needed. You should use the following steps to configure a CSC SSM After a CSC SSM is installed in an ASA chassis, you should verify that the module is powered up and available. You can do that with the show module ASA command, as shown in the following example. Here, the...
Initially Configuring the AIP
After an AIP SSM has been installed in an ASA chassis, you need to connect to it and provide an initial configuration. This must be done through the AlP's management interface, according to the following steps 1. Connect to the AIP from the ASA CLI. First, locate the AIP SSM within the chassis with the show module command. Then open a terminal session to the AlP's out-of-band channel with the session slot_number command, as in the following example Mod Card Type Model Serial 0 ASA 5510 Adaptive...
Forwarding Multicast Traffic
IP multicast traffic must be forwarded from one network interface to another, just like any other Layer 3 packets are handled. The difference is in knowing where to forward the packets. For example, unicast IP packets have only one destination interface on a router or firewall (even if multiple paths exist). Multicast IP packets, however, can have many destination interfaces, depending on where the recipients are located. Cisco firewalls running PIX 6.2 or 6.3 have a limited multicast...
Favoring Static Routes Based on Reachability
Normally, if a static route is configured, it stays active until it is manually removed. A static route is simply an unchanging definition of a next-hop destination regardless of whether that destination is reachable. If a single ISP is the sole means of reaching the outside world, a static default route works nicely to point all outbound traffic to the ISP's gateway address. Suppose you had connections to two ISPs one might be favored over the other, but the default routes to each ISP are...
Configuring the ASA to Divert Traffic to the Csc Ssm
As you work through initially installing and configuring your CSC SSM, keep in mind that the ASA and CSC SSM are essentially two independent pieces of hardware. Even though the CSC lives in an SSM slot on the ASA chassis, the two communicate over an out-of-band connection only for basic setup and status information. Even though the CSC SSM is installed and the ASA sees it as an active module, the ASA does not send any traffic to the CSC until you configure it to do so. Any type of traffic...
Configuring CSC Inspection Policies
You can configure the CSC SSM to inspect any of the following types of interesting traffic Web Specific URLs and known phishing sites can be blocked, access to websites can be restricted based on a category, file types can be blocked from downloading, and web page content and webmail content can be scanned for undesirable content. Mail Incoming and outgoing SMTP traffic, as well as inbound POP3 traffic, can be scanned for undesirable content. Both SMTP and POP3 can be scanned for spam content...
Configuring IPv6 on an Interface
Beginning with ASA 7.0, firewall interfaces can be configured with an IPv6 address in addition to a traditional IPv4 address. IPv6 addresses are 128 bits long much longer than a 32-bit IPv4 address As well, the IPv6 address format is very different and can be written in the following ways In full hexadecimal format, the address is written as eight groups of four hexadecimal digits, with colons separating the groups. For example, 1111 2222 3333 4444 5555 6666 7777 8888 represents a single IPv6...
Hardware and Performance
Cisco offers firewall functionality in a variety of hardware platforms, many of which are network appliances, where the firewall is contained in a standalone chassis. These include the Cisco PIX Security Appliance and Cisco Adaptive Security Appliance (ASA) platforms. The FWSM is a blade or module that can be used in a Catalyst 6500 switch chassis. This moves the firewall presence into an infrastructure switch itself rather than an external appliance. Cisco also offers a firewall function as...
Configuring a Firewall as an Auto Update Server
You can configure an ASA to act as an AUS, if the ASA is running release 7.2 1 or later. This can be useful if you do not have an enterprise network management platform with an embedded AUS. The ASA AUS can be used to offer operating system and ASDM image files to other ASA and PIX firewall platforms as long as they are running release 7.2 1 or later already. The image file can be stored on an external web server or on the ASA AUS itself. The most scalable solution is to store firewall image...
Recovering an ASA Password
On an ASA, the configuration register is changed to allow booting without the startup configuration file. The ASA can boot its normal operating system image. Without the startup configuration, you can move directly into the privileged EXEC mode without having to use an enable password. Follow these steps to recover from an unknown password The ASA must be reloaded so that you have a chance to break out of the normal boot sequence and change the configuration register. If the ASA is already...
How Failover Works
Firewall failover is currently available on the ASA platforms, PIX 515E, 525, and 535 models, and on the Catalyst 6500 FWSM. Failover can be configured only if the firewall licensing enables it. For active-standby failover, one firewall must have an unrestricted license, and the other has an unrestricted or failover-only license. The FWSM has active-standby failover enabled by default. For active-active failover, both firewalls must have an unrestricted license. This is because both can...
Configuring Firewall Failover
To configure failover on a pair of Cisco firewalls, you can use the configuration steps listed in this section. Before failover is configured and enabled, you need to enter the configuration commands on each firewall. After failover is enabled, all configuration commands should be entered only on the active firewall. This is because the active unit replicates the configuration commands to the standby unit automatically. The only exception is any command related to failover itself. For...
Manually Intervening in Failover
When the firewalls in a failover pair detect a failure and take action, they do not automatically revert to their original failover roles. For example, if the primary firewall is active and then fails, it is marked as failed, and the secondary firewall takes over the active role. After the primary unit is repaired and returned to service, it does not automatically reclaim the active role (unless it has been configured to preempt active control). You might occasionally find that you need to...
Manually Upgrading a Failover Pair
In an active-standby pair, only one firewall is active, and both units must be running identical software releases. The only exception is during a zero downtime upgrade, where the firewalls might be running images with incrementally different release numbers. In a nutshell, as long as one of the two firewalls is operating in active mode, it continues inspecting traffic and updating state information (connections, translations, and so on) to the standby unit. The idea is to juggle the active and...
Checking System Resources
A firewall inspects traffic and performs its functions by using a combination of system resources. From a hardware standpoint, these resources are very straightforward and include the CPU and system memory. The following sections analyze these resources. You get a general idea about the processing load on a Cisco firewall by using the show cpu usage command. For example, the following firewall appliance has a 5-second average of 27 percent. The command output also shows that the CPU is under a...
B4 Warnings Syslog Severity Level 4 Messages
Table B-4 lists all the severity level 4 logging messages, along with their message numbers and text. All the messages supported by FWSM, ASA, and PIX are shown. Table B-4. Severity 4 (Warnings) Logging Messages Table B-4. Severity 4 (Warnings) Logging Messages Deny protocol src dst interface_name dest_address dest_port type string , code code by access_group acl_ID. Failed to determine the security context for the packet vlansource Vlan ethertype src sourceMAC dst destMAC. Maximum number of...
Saving a Running Configuration
You can view or save a firewall's running configuration with one of the methods described in the following sections. You can use the following commands to display the current running configuration The running configuration is displayed to the current terminal session. If the configuration is longer than your current session page length (24 lines by default), you have to press the spacebar to page through it. However, in ASA, FWSM, and PIX 6.3 platforms, you can filter the output by using one of...
PIM Building a Multicast Distribution Tree
PIM is a routing protocol that can be used to forward multicast traffic. PIM operates independently of any particular IP routing protocol. Therefore, PIM uses the IP unicast routing table and does not keep a separate multicast routing table. (The unicast routing table is itself routing protocol-independent because one or more routing protocols can be used to populate a single table.) PIM can operate in two modes, depending on the density of the recipients in a multicast group. Cisco has...
Configuring RIP to Exchange Routing Information
Cisco firewalls can passively listen to RIP updates either version 1 or 2 to learn routing information. Routing advertisements from the firewall are limited to one type a firewall interface as a default route. RIP can be used in either of the following versions RIP version 1, which supports only classful networks. Advertisements are broadcast unencrypted. RIP version 2, which supports classless networks. Advertisements can be authenticated by a cryptographic function for security purposes. RIP...
IGMP Finding Multicast Group Recipients
How does a router know of the recipients in a multicast group, much less their locations To receive multicast traffic from a source, both the source and every recipient must first join a common multicast group, known by its multicast IP address. A host can join a multicast group by sending a request to its local router. This is done through Internet Group Management Protocol (IGMP). IGMPv1 is defined in RFC 1112, and its successor, IGMPv2, is defined in RFC 2236. Think of IGMP as a means of...
Classifying Layers 3 and 4 Traffic
As traffic moves through the firewall, it can be identified or classified according to the matching conditions defined in a class map. You can configure multiple class maps to identify several different classes of traffic, if needed. Then a different policy can be applied to each traffic class. The following sections discuss how you can configure a class map for identifying a specific type of traffic according to parameters found in Layers 3 and 4, or the IP and UDP or TCP packet headers,...
Updating Dynamic DNS from a DHCP Server
Traditionally, hostnames and IP addresses have been associated through the use of DNS, requiring static configurations. While this might be practical for servers, which rarely change their hostnames or addresses, it does not lend itself to timely updates for clients that frequently change IP addresses. Dynamic DNS (DDNS) solves this problem by keeping the DNS function, but allowing records to be updated dynamically, as they change. DDNS is most useful when it is teamed with a DHCP server as the...
Configuring Interfaces
Every firewall has one or more interfaces that can be used to connect to a network. To pass and inspect traffic, each firewall interface must be configured with the following attributes IP address and subnet mask (IPv4 beginning with Adaptive Security Appliance (ASA) 7.0 and Firewall Services Module (FWSM) 3.1(1), IPv6 is also supported). Security level (a higher level is considered more secure). By default, traffic is allowed to flow from a higher-security interface to a lower-security...
Step 2 Check the ARP Cache
Like any host on a network, a firewall must have the basic mechanism to relate IP addresses (Layer 3) to MAC addresses (Layer 2). This is done by building and maintaining an ARP cache. Normally, when a host knows a destination's IP address, it sends an ARP request in the hope that the destination will send an ARP reply with its MAC address. The firewall can build its ARP cache by sending its own ARP requests or by listening to other ARP replies on its interfaces. Connectivity through the...
Routed and Transparent Firewall Modes
Traditionally, Cisco firewalls have operated by performing Layer 3 (IP address) operations. Naturally, the stateful inspection process can look at higher layers within the IP packets being examined. But the firewall itself has maintained its own interface IP addresses and acted as a router or gateway to the networks that connect to it. As well, all of the traffic inspection and forwarding decisions are based on Layer 3 (IP address) parameters. This is known as the routed firewall mode. Each...
Syslog Server Suggestions
To make full use of the logging messages generated by a firewall, you need a Syslog server application running somewhere in your network. Some recommendations for Syslog servers are as follows Kiwi Syslog Daemon A commercial Syslog server for Windows-based platforms, available at http www.kiwisyslog.com UNIX syslogd A Syslog daemon built into most versions of the UNIX operating system Cisco PIX Firewall Syslog Server (PFSS) A Syslog server available in the Cisco.com Software Center under PIX...
Csm Fwlb Configuration
Because firewall load balancing with CSMs requires several different server farms and virtual servers, it is easy to forget what pieces need to be configured. Configure the inside and outside CSMs one at a time, and keep track of your progress in each by following the virtual servers and server farms that are shown in Figure 9-5. You need to repeat this configuration process for the inside and outside CSM. 1. Enter CSM server load-balancing mode A Catalyst 6500 switch can support SLB...
Firewall Load Balancing Appliance
A Cisco CSS acts as a multilayer switch and performs FWLB as well as many other types of content processing. A CSS interface can carry a single VLAN or a trunk with multiple VLANs. A CSS unit must be placed on each side of a firewall farm so that connections are load-balanced to the firewalls in each direction. Firewalls are defined individually rather than as a distinct firewall farm. The CSS performs a route lookup on each inbound connection to determine the possible firewalls that can be...
Step 4 Use Traceroute to Verify the Forwarding Path
Traceroute is a common tool you can use to discover the path from one host to another through the network. The originating host sends special packets toward the destination. Each router that is encountered along the way returns a message to the source, indicating that it was present on the path. The host generating a traceroute sends packets toward the destination with the IP time-to-live (TTL) field incrementing from 1. The TTL field is a simple hop counter, specifying the maximum number of...
Firewall Management
Refer to the following sections for information about these topics 4-1 Using Security Contexts to Make Virtual Firewalls Presents the configuration steps needed to make one physical firewall platform emulate multiple virtual firewalls. 4-2 Managing the Flash File System Explains the types of images that are stored in nonvolatile firewall memory and how to work with them. 4-3 Managing Configuration Files Presents the methods you can use to configure firewalls and manage their configuration...
Security Context Organization
A Cisco firewall that can support security contexts can operate in only one of the following modes Single-context security mode One context is configured on one physical firewall platform. This is the traditional or default mode of operation. Multiple-context security mode Two or more contexts can be configured on one physical firewall. In multiple-context security mode, a firewall is organized into the following functions, each having its own user interface System execution space A special...
Sharing Context Interfaces
Multiple-context mode allows some flexibility in mapping interfaces. You can map one physical interface to one context interface when isolation from other firewalls is required. You can also map one physical interface to several context interfaces so that the contexts share a single connection. This might be practical in an enterprise setting, where each context is designated for a different department. Most likely, an enterprise would have a single path toward the public Internet. Every...
Setting the Clock with NTP
In ASA multiple-context mode, NTP must be configured on the system execution space only. All the other contexts (both admin and user) obtain their clock information from the system execution space, because all the contexts exist in the same physical firewall. You can use the changeto system command to move your session into the system execution space before using the following configuration steps. The Firewall Services Module (FWSM) does not have a standalone clock, and it does not support NTP....
Configuring the ARP Cache
A firewall maintains a cache of Address Resolution Protocol (ARP) entries that are learned when it overhears ARP requests or ARP reply packets on its interfaces. ARP is used to resolve a host's MAC address based on its IP address, and vice versa. You can use the following commands to configure ARP operations 1. Define a static ARP entry Firewall(config) arp if name ip address mac address alias ARP entries normally are created as the firewall hears responses to ARP requests on each interface....
Overview of Firewall SNMP Support
Firewalls can participate in SNMP by maintaining several MIBs. The MIB values are constantly updated with the current values that are in use. For example, one MIB parameter records the average firewall CPU load over a 5-second period. This is based on the CPU usage measurements that can also be shown from the firewall CLI. SNMP MIBs represent data as a hierarchical tree structure each MIB variable is referenced by its object identifier (OID). OIDs are formed by concatenating the name or number...
IOS Firewall Load Balancing Example
FWLB requires two load-balancing devices One located externally with respect to the firewall farm One located internally with respect to the firewall farm Figure 9-4 shows a network diagram for this example. Note that this same example is also used in Section 9-3 to show how IOS FWLB and the CSM are configured in similar scenarios. Figure 9-4. Network Diagram for the IOS FWLB Example Figure 9-4. Network Diagram for the IOS FWLB Example The firewall farm consists of three real firewalls. The...
Analyzing Firewall Logs
The most important thing you can do with a firewall is collect and analyze its Syslog information. Firewall logs should be inspected on a regular basis. Always make sure the Syslog collector or server is configured to archive older information and that disk space is not completely consumed. The Syslog collector or server should be sized according to the following parameters The number of firewalls and other network devices sending Syslog messages to the Syslog server The number of Syslog events...
Dynamic Address Translation NAT or PAT
Dynamic address translation can be used to allow hosts with real addresses to share or hide behind one or more common mapped addresses. Address translation occurs on a many-to-one basis, in a dynamic fashion. This can be accomplished in two ways Dynamic NAT Inside host addresses are translated to values pulled from a pool of mapped addresses. Each inside address gets exclusive use of the mapped address it is assigned, for the duration of any active connections. As soon as all of a host's...
Overview of Firewall Operation
A firewall's essential function is to isolate its interfaces from each other and to carefully control how packets are forwarded from one interface to another. In its default state, a firewall does not allow any packets to pass through it until some security policies are configured. Before connections can form between firewall interfaces, two conditions must be met An address translation policy must be configured between a pair of interfaces. (This requirement can be disabled with the...
ASA Modules
Refer to the following sections for information about these topics 12-1 Initially Configuring an ASA SSM Explains how to provide a bootstrap configuration so that a Security Services Module (SSM) can be used in an Adaptive Security Appliance (ASA) chassis. 12-2 Configuring the CSC SSM Discusses the steps needed to configure and use a Content Security and Control (CSC) module for content inspection features. 12-3 Configuring the AIP SSM Describes the steps needed to configure and use an Advanced...
Configuring OSPF to Exchange Routing Information
OSPF is a link-state routing protocol. The routing domain is partitioned into areas. Area 0 is always considered the backbone area of the OSPF domain or autonomous system. When an OSPF router connects to two or more different areas, it is called an Area Border Router (ABR). When an OSPF router connects an area to a non-OSPF domain and it imports routing information from other sources into OSPF, it is called an Autonomous System Boundary Router (ASBR). OSPF routers build a common database of the...
Defining Security Policies in a Modular Policy Framework
Traditionally, Cisco firewalls have supported security policies that are applied to all traffic passing through them. Although that does offer a common level of security to all the protected networks and hosts, it does not offer a way to fine-tune or vary the policies according to differing requirements. Beginning with ASA 7.0(1) and FWSM 3.1(1), a Cisco firewall can be configured to provide security policies that are tailored for various traffic types, quality of service (QoS), or inspection...
Authorizing User Activity with Radius Servers
User authorization is not available as a part of the RADIUS protocol. However, if you have only RADIUS servers available and you need to set up authorization for user traffic, you can use access lists to emulate authorization. The RADIUS server can be configured to return a reference to an access list that is based on a user's authorization. The firewall can use the access list information to permit or deny the user's connections as they are initiated. You have two ways to approach RADIUS...
Configuring an Access List
You can use the steps presented in this section to configure a firewall access list. The access list exists in the firewall configuration, but does not actively do anything until you apply it to a firewall interface or to some other firewall function. Access lists are defined simply by entering ACE commands in global configuration mode. There is no need to define the access list name first just the action of entering an ACE with an ACL ID acl_id (an arbitrary text name) is enough to make it a...
Connecting to the CSC Management Interface
After the CSC SSM has received its initial network configuration, you can connect to it through ASDM. When you select the Configuration tab and the Trend Micro Content Security button, ASDM announces that it is getting ready to connect to the CSC, as indicated by the window shown in Figure 12-12. Figure 12-12. Getting Ready to Connect to the CSC Management Interface By default, the last known IP address for the CSC management interface is used. In Figure lili, this address is 192.168.110.10,...
Recovering a PIX Password
On a PIX platform, a password recovery utility must be downloaded to the firewall from a TFTP server. This procedure is very similar to upgrading the OS image from the PIX monitor prompt. Follow these steps to reload and erase the PIX passwords 1. Make sure a TFTP server is available. The TFTP server should have a copy of the correct PIX Password Lockout Utility software. You can find this utility on Cisco.com at where XX is the PIX OS software release. For example, the utility for PIX OS 6.3...
Upgrading an Image from the Monitor Prompt
If the firewall has no operating system image, you can still download one via TFTP from the monitor prompt. At this point, the firewall is not inspecting any traffic and has no running configuration. Follow these steps to download a firewall operating system image via TFTP 1. Make sure a TFTP server is available. The TFTP server should have the firewall image available for downloading. Tip You can obtain TFTP server software from a variety of sources Solarwinds.net TFTP server (http...
Recovering an FWSM Password
Follow these steps to reload and erase the FWSM passwords 1. Boot the FWSM into the maintenance partition Router hw-module module slot-number reset cf 1 Router session slot slot-number processor 1 From the Catalyst 6500 Supervisor IOS EXEC prompt, the FWSM in slot slot-number can be reset so that it reboots into its maintenance partition. Log in as the user root. The default root password is cisco. 2. Reset the passwords in the compact Flash configuration file root localhost clear passwd cf...
Relaying DHCP Requests to a DHCP Server
Follow these steps to configure a firewall to act as a DHCP relay 1. Define a real DHCP server Firewall(config) dhcprelay server dhcp server ip server ifc A real DHCP server can be found at IP address dhcp_server_ip on the firewall interface named server_ifc (inside, for example). You can repeat this command to define up to four real DHCP servers. When DHCP requests (broadcasts) are received on one firewall interface, they are converted to UDP port 67 unicasts destined for the real DHCP servers...
Clear Configure Context Fwsm
Firewall(config) privilege show clear cmd level level mode mode command command PIX 6.3 Firewall(config) privilege show clear configure level level mode enable configure command command For the mode (show, clear, or configure) of the command keyword command, a new privilege level (0 to 15) is assigned. In ASA and FWSM, the configure mode is known only as cmd mode. Some commands can also be used in several submodes within a single mode. In PIX 6.3, for example, the clear logging command can be...
Defining Object Groups
Object groups can be thought of as a type of macro used within access lists. Object groups can contain lists of IP addresses, ICMP types, IP protocols, or ports. You can define several different types of object groups, each containing a list of similar values, as follows Network object group Contains one or more IP addresses. Protocol object group Contains one or more IP protocols. ICMP object group Contains one or more ICMP types. Basic service object group Contains one or more UDP or TCP port...
Access List Activity Logging
By default, logging message 106023 (default severity level 4, warnings) is generated when a deny access list entry is matched with a traffic flow. Only the overall ACL is listed in the message, with no reference to the actual denying ACL entry, as in the following example ASA-4-106023 Deny tcp src outside 220.163.33.180 18909 dst inside 10.10.95.23 8039 by access-group acl_outside You can log messages when specific access control entries (ACEs, or individual permit deny statements within an...
Checking Stateful Inspection Resources
As a firewall inspects and passes traffic, it maintains two tables of entries address translations (xlates) and connections (conns). You can get an idea of the inspection load by looking at the size of these tables. To see the translation table size, use the following command The output from this command shows the current number of xlates in use and the maximum number that have been built since the firewall was booted. The firewall in the following example currently has built 15,273...
Set Connection Conn-max 5000 Embryonic-conn-max
Firewall(config-pmap-c) set connection conn-max n embryonic-conn-max n per-client-embryonic-max n perclient-max n random-sequence-number enable disable By default, an unlimited number of simultaneous UDP and TCP connections are allowed across an address translation. The set connection command can be used in a policy map to set connection limits on traffic to and from specific hosts. The connection limits configured with set connection are very similar to the limits set in address translation...
B2 Critical Syslog Severity Level 2 Messages
Table B-2 lists all the severity level 2 logging messages, along with their message numbers and text. All the messages supported by FWSM, ASA, and PIX are shown. Table B-2. Severity 2 (Critical) Logging Messages Inbound TCP connection denied from IP_address port to IP_address port flags tcp_flags on interface interface_name. Protocol connection denied by outbound list acl_ID src inside_address dest outside_address. Deny inbound UDP from outside_address outside_port to inside_address inside_port...
Managing the Startup Configuration
In PIX releases 6.3 and earlier, as well as FWSM releases, a firewall has one startup configuration that is stored in flash memory. This configuration file is read upon bootup and is copied into the running configuration. ASA platforms running 7.0 or later have the capability to maintain one or more startup configuration files in flash, provided that you have sufficient space to store them. Only one of these can be used at boot time. This section discusses the tasks that can be used to maintain...
Firewall DuHid I rw
A Ris Fake EmbstJed Tag 19 U9 d Malicious P Kfcflt Now Monj VLtHHO in VLAN 200 The trunk link has been configured with VLAN 100 as its native VLAN. This might have been done as an oversight, with the assumption that no other switch or host would ever connect to VLAN 100 on the inside network. However, that native VLAN is used as the springboard to get inside the secure network. A malicious user on the outside (VLAN 100) sends a packet toward the inside. The packet is carefully crafted such that...
Automatically Upgrading a Failover Pair
In Chapter 4, Firewall Management, in Section 4-4 Firewall Management, in Section Automatic Updates with an Auto Update Server, firewalls can be configured to automatically poll and download updated image files from an Auto Updates Server (AUS). Normally, these are standalone firewalls, ones not operating as part of a failover pair. Beginning with ASA 8.G(1), you can configure a failover pair of firewalls to work with AUS so that they both receive an updated image automatically. The firewalls...
Using the Firewall as a DHCP Server
Follow these steps to configure the DHCP server feature 1. Define an address pool for host assignments Firewall(config) dhcpd address ip1 -ip2 if name The pool of available client addresses on the firewall interface named if_name (inside, for example) goes from a lower-limit address ip1 to an upper-limit address ip2. These two addresses must be separated by a hyphen and must belong to the same subnet. In addition, the pool of addresses must reside in the same IP subnet assigned to the firewall...
Solving Shared Context Interface Issues with Unique MAC Addresses
By default, every physical ASA interface uses its burned-in address (BIA) as its Media Access Control (MAC) address. Also, every subinterface of a physical interface uses the physical interface's MAC address. After the ASA is configured for multiple context mode, system context interfaces (both physical and subinterfaces) are allocated to other contexts. This means that the MAC address of a system context interface is reused on each of its associated context interfaces. For example, consider an...
Configuring Content Filters
You can use the following steps to configure content filtering on a Cisco firewall. The command syntax is basically the same across the FWSM, PIX, and ASA platforms, so only a single syntax form is shown for each command. Content filtering is triggered by the HTTP inspection engine, which must be enabled before any content servers can be contacted. If you are about to configure content filtering, make sure you have the fixup protocol http (PIX 6.x) or inspect http (ASA and FWSM) command in the...
Feedback Information
At Cisco Press, our goal is to create in-depth technical books of the highest quality and value. Each book is crafted with care and precision, undergoing rigorous development that involves the unique expertise of members from the professional technical community. Readers' feedback is a natural continuation of this process. If you have any comments regarding how we could improve the quality of this book, or otherwise alter it to better suit your needs, you can contact us through email at...
A2 ICMP Message Types
Internet Control Message Protocol (ICMP) is used to transport error or control messages between routers and other devices. An ICMP message is encapsulated as the payload in an IP packet, as shown in Figure A-2. This information appears immediately following the IP header. Many of the ICMP message types also have a code number that can be used. The code field further specifies how the message type should be applied when it is received. Cisco firewalls cannot use the code field in access lists,...
Shun Example
A host at 172.21.4.8 is discovered to be involved in malicious activity. (In this example, only a Telnet connection is shown for simplicity.) A shun will be configured on the firewall to stop any current or future connections involving that host. First, look at an active connection involving 172.21.4.8 TCP out 172.21.4.8 4334 in 192.168.199.100 23 idle 0 00 04 Bytes 138 flags UIOB It does have at least one active connection, so a shun is put into place Code View Scroll Show All Firewall shun...
End Certificate
INFO Certificate has the following attributes Fingerprint 4097e286 8f4425db 36ddae78 f750d6d8 Do you accept this certificate yes no yes Trustpoint CA certificate accepted. Certificate successfully imported Firewall(config) Firewall(config) ssl trust-point name if name So, the CA trustpoint named name is used as the trusted CA for the firewall's SSL connection. The trustpoint (secure Syslog server) can be found on the firewall interface named if_name. For example, if your secure Syslog server is...
Step 9 See What Has Changed
If you have installed, configured, and tested a firewall, trusted users should be able to pass through it according to the security policies. At the same time, the firewall should deny or drop all untrusted users and traffic. Suppose things have been working like this for some time, but one day users begin to call and complain. One possible cause of a problem is that someone somewhere has changed something on your network. One good troubleshooting approach is to ask, What changed during the...
Identifying the Operating System Image
In PIX 6.3 and FWSM, only one operating system image file can be stored in flash at any time. The firewall automatically allocates storage for the image and handles its creation. In PIX 6.3, the image file is always indexed as file number 0 in the flash file system, as displayed by the show flashfs command. Therefore, when the firewall boots up, that image is always loaded into RAM and executed. In an FWSM, you can see a list of files in the image or application partition with the dir flash...
Managing the Firewall Clock
A Cisco firewall keeps an internal clock that can be used for Syslog time stamps, certificate time stamps, and so on. The clock is powered by a battery in the absence of regular power. The internal clock is always based on Coordinated Universal Time (UTC). UTC was previously known as Greenwich Mean Time (GMT). You can set the system time using two different approaches Manually You set the time and date on the firewall along with the time zone and specify whether to observe daylight savings...
Content Filtering Examples
A corporation has two Websense servers located on the firewall's DMZ interface at 192.168.199.10 and 192.168.199.11. The firewall intercepts every HTTP request and relays them to the Websense servers. If neither server responds within the default 5-second period (for each server), the firewall allows the request. The only exceptions to this policy are with all hosts on the 192.168.4.0 24 subnet, which are allowed to request any URL with no Websense intervention. Inside host 192.168.7.33 is...
Management Vlan -in Denied Eigrp
Auth start for user user from inside_address inside_port to outside_address outside_port. Auth from inside_address inside_port to outside_address outside_port failed (server IP_address failed) on interface interface_name. Auth from inside_address to outside_address outside_port failed (all servers failed) on interface interface_name. Authentication succeeded for user user from inside_address inside_port to outside_address outside_port on interface interface_name. Authentication failed for user...
Ms41m 1 See 2se3es129
Wo MAT 172.16.' .41 - 102.165.200.0 24 A similar translation arrangement is needed for inside network 172.17.0.0 255.255.0.0. These use global pool 169.54.122.65 through 169.54.122.125 for NAT and global address 169.54.122.126 for PAT. These are configured as nat global group ID 2. For other inside networks, a default translation arrangement uses the firewall's outside interface address for dynamic PAT. The nat global group ID 3 performs this function. One other exception must be made to the...
Configuring a Firewall as an Auto Update Client
Use the following steps to configure a firewall as an Auto Update client, so that it can periodically poll an AUS for new image and configuration files. 1. Make sure an AUS is available. The firewall should be defined in the AUS, and the new image or configuration file should be assigned to or associated with it. As soon as you load an image or configuration file into the AUS and associate it to a firewall, the firewall client can download and begin using the file the very next time it polls...
Reloading a Firewall
To manually trigger a firewall reload, choose one of the options discussed in the following sections. You can initiate a firewall reload only from privileged EXEC (enable) mode. On an ASA or FWSM firewall platform running in multiple-context security mode, you can initiate a reload only from the system execution space. You can use the following command to initiate an immediate reload. Be aware that as soon as the reload begins, all existing connections through the firewall are dropped, and...
Detecting a Firewall Failure
Each interface of one firewall must connect to the same network as the corresponding interface of the other firewall. Each firewall can then monitor every active interface of its failover peer. The active and standby firewalls determine a failure by sending hello messages to each other at regular intervals (every 15 seconds by default). These messages are sent over the failover cable (if present) or the LAN-based failover interface to detect failures of an entire firewall. The hellos are also...
Begin Certificate
MBEGA1UEChMKTXkgQ2 MBgGA1UEAxMRd3d3Lm15Y2 9tcGFueS5jb2 0wHhcNMDcwMzIwMDM0OTU2WhcNMDgw EAYDVQQHEwlMZXhpbmd0b2 9tMIGf 9lrQUHt42SC uoV8 6TsWzPTJ8waR0Y+n fIKb9in1Et8DdFRBOKejhCnGflw8 57HHFvXFqI5KBAzFyZ2 8FeGnnt7SP3Wlwfo5 -----END CERTIFICATE----- The SSL software can run as a service so that it is always available to incoming tunnel requests. On a Windows platform, the software can also run as a regular application that you start manually. 2. Configure secure logging on the firewall. By default,...
Configuring the Csc Ssm
The Content Security and Control (CSC) SSM was introduced with ASA release 7.1(1). The CSC is used in conjunction with the ASA to provide a variety of inspections and defenses based on traffic content. The CSC communicates with the ASA over an internal backplane connection. Figure 12-3 shows how traffic is passed between the ASA and CSC. The ASA diverts traffic classified by a class map to the CSC module over the internal connection. The CSC inspects the traffic in both the forward and return...




















