Configuring an Advanced Firewall Using SDM

As shown in Figure 6-9, from the home page of SDM, click the Configure button at the top of the page, and then click the Firewall and ACL icon in the Tasks toolbar. You have two choices: Basic Firewall and Advanced Firewall. Click the Advanced Firewall radio button and then click the Launch the Selected Task button to proceed to the next window, shown in Figure 6-10.

Figure 6-9 Launching the Advanced Firewall Configuration Wizard

Figure 6-9 Launching the Advanced Firewall Configuration Wizard

Figure 6-10 Advanced Firewall Configuration Wizard

Like the Basic Firewall Configuration Wizard, the Advanced Firewall Configuration Wizard also prompts you to choose your inside and outside interfaces, along with SDM access from your outside interfaces. If required, you can also define an interface for your DMZ, as demonstrated in Figure 6-11. Click Next, and a warning about launching SDM from an outside interface appears, similar to the one shown in the Basic Firewall Configuration Wizard (refer to Figure 6-6). Click OK to continue.

Figure 6-11 Advanced Firewall Interface Configuration

Figure 6-11 Advanced Firewall Interface Configuration

If you have selected an interface as a DMZ interface, you are shown the Advanced Firewall DMZ Service Configuration window, as shown in Figure 6-12. In this window, you can define DMZ services that are accessible from the outside network, such as mail, FTP, and VPN. Click Add to define a DMZ service.

Figure 6-12 Advanced Firewall DMZ Service Configuration

Figure 6-12 Advanced Firewall DMZ Service Configuration

Figure 6-13 shows the DMZ Service Configuration dialog box. Enter the IP address of the server, followed by the service port number or well-known name. Clicking the ellipsis button opens the Service Menu where you can select the service from a list of well-known services. If you open this menu, click OK to return to the DMZ Service Configuration dialog box. After you have entered in all of the DMZ services required, click Next to continue.

Figure 6-13 DMZ Service Configuration and Service Dialog Boxes

Figure 6-13 DMZ Service Configuration and Service Dialog Boxes

The next item to configure is the inspection granularity for services that are running in the DMZ. Figure 6-14 shows that you have the option of choosing a default SDM Application Security Policy or choosing a custom Application Security Policy.

Figure 6-14 Advanced Firewall Security Configuration—Using a Default Policy

Figure 6-14 Advanced Firewall Security Configuration—Using a Default Policy

If you use a default policy, click the Use a Default SDM Application Security Policy radio button and then click the Preview Commands button to see which specific configuration commands will be applied (shown in Figure 6-15).

Figure 6-15 Preview SDM Application Security Policy

Preview SDM Application Security Policy

PI

Selected SDM default policy Low Security The fallowing configuration commands will be applied.

|p inspect log drop-pkt ip inspect name SDM_LOW cuseeme ip inspect name SDM_LOW dns ip inspect name SDMJ_OWftp ip inspect name SDM_LOW h323 ip inspect name SDM_LOW https ip inspect name SDM_LOW icmp ip Inspect name SDM_LOW imap ip inspect name SDM_LOW pop3 ip inspect name SDMJ.OW netshow ip inspect name SDM_LOW rcmd ip inspect name SDM_LOW reaiaudio ip inspect name SDM_LOW rtsp ip inspect name SDM_LOWesmtp ip inspect name SDM_LOW sqlnet

V.I

Ki

m

Close |

J

If you choose to use a custom policy, you can either create a new policy or select an existing policy, as shown in Figure 6-16. Click Create a New Policy to open the Application Security window, shown in Figure 6-17, where you can choose the applications that should be inspected by the firewall.

Figure 6-16 Creating a New Custom Application Security Policy

Figure 6-16 Creating a New Custom Application Security Policy

Figure 6-17 Application Security Inspection

Application Security

«Ä Instant Messaging (IM)

Choose the items to inspect ^—1

\ Peer-to-Peer (P2P)

Applications | Alerts | Audit |Timeout| Options

URL Filtering

[gbifr

Ê® URL Filter Servers

r esmtp

50 HTTP

I- smtp

fêi Header Options

rimap

Content Options

I- imaps

0 Applications 1 Prat oca Is Ä

r imap3

V lotus note

r lotusmtap

r pop3

V pop3s

<1 r.

The parameters of each protocol can be modified by checking the box next to the protocol and clicking the Edit button in the upper-right corner of the window. As shown in Figure 6-18, you can modify alerts, audits, and timeouts. Depending on the protocol, you might be able to choose whether local router traffic should also be inspected by checking the Router Traffic check box.

Figure 6-18 Edit Inspection Rule Dialog Box

Figure 6-18 Edit Inspection Rule Dialog Box

When you finish choosing protocols and modifying the parameters, click OK to continue. You are returned to the Advanced Firewall Security Configuration Wizard page, where you can select which security policy you want to use on this router, as shown in Figure 6-19. The router produced a default name for the custom policy that you just created. Click Next to use this policy and proceed to the next wizard page.

Figure 6-19 Advanced Firewall Security Configuration—Using a Custom Policy

Figure 6-19 Advanced Firewall Security Configuration—Using a Custom Policy

Figure 6-20 shows the last page of the wizard, the Internet Firewall Configuration Summary. This window lists all firewall rules that will be applied to this router. Click Finish to apply the configuration to the router.

Figure 6-20 Internet Firewall Configuration Summary—Advanced Firewall

Figure 6-20 Internet Firewall Configuration Summary—Advanced Firewall

Continue reading here: Configuring Cisco Ios Ips from the SDM

Was this article helpful?

0 0