Infrastructure Protection Access Control Lists iACLs

Using iACLs is a technique that was developed by ISPs, however, it is now a common practice by enterprises and other organizations. Employing iACLs involves the use of ACLs that prevent direct attacks to infrastructure devices. You configure these ACLs to specifically allow only authorized traffic to the infrastructure equipment while allowing transit traffic. Cisco recommends that you configure iACLs into four different sections or modules:

1 On the Internet edge, deny packets from illegal sources (RFC 1918 and RFC 3330 addresses). In addition, deny traffic with source addresses belonging within your address space entering from an external source. For example, if your address space is 209.165.201.0/24, you should configure an iACL to deny traffic from any external source by using an address from this space. The following example includes iACL entries (part of ACL number 123) used to deny RFC 3330 special-use addresses.

access-list 123 deny ip host 0.0.0.0 any access-list 123 deny ip 127.0.0.0 0.255.255.255 any access-list 123 deny ip 192.0.2.0 0.0.0.255 any access-list 123 deny ip 224.0.0.0 31.255.255.255 any

The following entries deny RFC 1918 traffic.

access-list 123 deny ip 10.0.0.0 0.255.255.255 any access-list 123 deny ip 172.16.0.0 0.15.255.255 any access-list 123 deny ip 192.168.0.0 0.0.255.255 any

2 Configure iACL entries providing explicit permission for traffic from trusted external sources destined to your infrastructure address space.

3 Deny all other traffic from external sources destined to infrastructure components addresses as shown in the following example.

access-list 123 deny ip any 209.165.201.0 0.0.0.255

4 Unlike ISPs, enterprises are the destination for traffic. The last section of the iACL permits all other normal backbone traffic destined to noninfrastructure destinations for only specific protocols and ports. For example, you can allow HTTP for a web server bank with IP address space 209.165.200.0/24, as follows:

access-list 123 permit tcp any 209.165.200.0 0.0.0.255 eq http

ISPs allow all transit traffic at the end of the iACL using a permit ip any any ACL entry.

Continue reading here: Unicast Reverse Path Forwarding Unicast RPF

Was this article helpful?

+1 -1