Configuring an Advanced Firewall Using SDM
As shown in Figure 6-9, from the home page of SDM, click the Configure button at the top of the page, and then click the Firewall and ACL icon in the Tasks toolbar. You have two choices: Basic Firewall and Advanced Firewall. Click the Advanced Firewall radio button and then click the Launch the Selected Task button to proceed to the next window, shown in Figure 6-10.
Figure 6-9 Launching the Advanced Firewall Configuration Wizard
Figure 6-9 Launching the Advanced Firewall Configuration Wizard

- Figure 6-10 Advanced Firewall Configuration Wizard
Like the Basic Firewall Configuration Wizard, the Advanced Firewall Configuration Wizard also prompts you to choose your inside and outside interfaces, along with SDM access from your outside interfaces. If required, you can also define an interface for your DMZ, as demonstrated in Figure 6-11. Click Next, and a warning about launching SDM from an outside interface appears, similar to the one shown in the Basic Firewall Configuration Wizard (refer to Figure 6-6). Click OK to continue.
Figure 6-11 Advanced Firewall Interface Configuration
Figure 6-11 Advanced Firewall Interface Configuration
If you have selected an interface as a DMZ interface, you are shown the Advanced Firewall DMZ Service Configuration window, as shown in Figure 6-12. In this window, you can define DMZ services that are accessible from the outside network, such as mail, FTP, and VPN. Click Add to define a DMZ service.
Figure 6-12 Advanced Firewall DMZ Service Configuration
Figure 6-12 Advanced Firewall DMZ Service Configuration
Figure 6-13 shows the DMZ Service Configuration dialog box. Enter the IP address of the server, followed by the service port number or well-known name. Clicking the ellipsis button opens the Service Menu where you can select the service from a list of well-known services. If you open this menu, click OK to return to the DMZ Service Configuration dialog box. After you have entered in all of the DMZ services required, click Next to continue.
Figure 6-13 DMZ Service Configuration and Service Dialog Boxes
Figure 6-13 DMZ Service Configuration and Service Dialog Boxes
The next item to configure is the inspection granularity for services that are running in the DMZ. Figure 6-14 shows that you have the option of choosing a default SDM Application Security Policy or choosing a custom Application Security Policy.
Figure 6-14 Advanced Firewall Security Configuration—Using a Default Policy
Figure 6-14 Advanced Firewall Security Configuration—Using a Default Policy
If you use a default policy, click the Use a Default SDM Application Security Policy radio button and then click the Preview Commands button to see which specific configuration commands will be applied (shown in Figure 6-15).
Figure 6-15 Preview SDM Application Security Policy
|
Preview SDM Application Security Policy |
PI |
|||
|
Selected SDM default policy Low Security The fallowing configuration commands will be applied. |
||||
|
|p inspect log drop-pkt ip inspect name SDM_LOW cuseeme ip inspect name SDM_LOW dns ip inspect name SDMJ_OWftp ip inspect name SDM_LOW h323 ip inspect name SDM_LOW https ip inspect name SDM_LOW icmp ip Inspect name SDM_LOW imap ip inspect name SDM_LOW pop3 ip inspect name SDMJ.OW netshow ip inspect name SDM_LOW rcmd ip inspect name SDM_LOW reaiaudio ip inspect name SDM_LOW rtsp ip inspect name SDM_LOWesmtp ip inspect name SDM_LOW sqlnet |
V.I |
|||
|
Ki |
m |
|||
|
Close | |
J |
|||
If you choose to use a custom policy, you can either create a new policy or select an existing policy, as shown in Figure 6-16. Click Create a New Policy to open the Application Security window, shown in Figure 6-17, where you can choose the applications that should be inspected by the firewall.
Figure 6-16 Creating a New Custom Application Security Policy
Figure 6-16 Creating a New Custom Application Security Policy
Figure 6-17 Application Security Inspection
|
«Ä Instant Messaging (IM) |
Choose the items to inspect ^—1 |
||||
|
\ Peer-to-Peer (P2P) |
Applications | Alerts | Audit |Timeout| Options |
||||
|
URL Filtering |
[gbifr |
||||
|
Ê® URL Filter Servers |
r esmtp |
||||
|
50 HTTP |
I- smtp |
||||
|
fêi Header Options |
rimap |
||||
|
Content Options |
I- imaps |
||||
|
0 Applications 1 Prat oca Is Ä |
r imap3 |
||||
|
V lotus note |
|||||
|
r lotusmtap |
|||||
|
r pop3 |
|||||
|
V pop3s |
|||||
|
<1 r. |
|||||
The parameters of each protocol can be modified by checking the box next to the protocol and clicking the Edit button in the upper-right corner of the window. As shown in Figure 6-18, you can modify alerts, audits, and timeouts. Depending on the protocol, you might be able to choose whether local router traffic should also be inspected by checking the Router Traffic check box.
Figure 6-18 Edit Inspection Rule Dialog Box
Figure 6-18 Edit Inspection Rule Dialog Box
When you finish choosing protocols and modifying the parameters, click OK to continue. You are returned to the Advanced Firewall Security Configuration Wizard page, where you can select which security policy you want to use on this router, as shown in Figure 6-19. The router produced a default name for the custom policy that you just created. Click Next to use this policy and proceed to the next wizard page.
Figure 6-19 Advanced Firewall Security Configuration—Using a Custom Policy
Figure 6-19 Advanced Firewall Security Configuration—Using a Custom Policy
Figure 6-20 shows the last page of the wizard, the Internet Firewall Configuration Summary. This window lists all firewall rules that will be applied to this router. Click Finish to apply the configuration to the router.
Figure 6-20 Internet Firewall Configuration Summary—Advanced Firewall
Figure 6-20 Internet Firewall Configuration Summary—Advanced Firewall
Continue reading here: Configuring Cisco Ios Ips from the SDM
Was this article helpful?