Perimeter Security

Translation Rules Outside PIX

translate www, mail, DNS, and E-banking servers to outside static (dmz-www,outside) tcp 200.1.1.1 80 172.30.1.2 80 0 1 static (dmz-mail,outside) 200.1.1.2 172.30.3.2 0 1 static (dmz-dns,outs ide) 200.1.1.3 172.30.2.2 0 1 static (dmz-ebanking,outside) tcp 200.1.1.4 443 172.30.4.2 443 0 1 translate second-tier E-banking server behind inside PIX static (inside,dmz-ebanking) tcp 172.30.11.2 535 172.30.11.2 535 0 1 translate inside mail gateway to dmz-mail static (inside,dmz-mail) 10.1.1.65...

Calculation of Authentication Header AH hash includes the whole IP header

NAT breaks packet authentication integrity Encapsulation Security Payload (ESP) Transport mode Outer IP header is not protected, but encrypted payload might break NAT with NAT- unfriendly applications Tunnel mode Outer IP header is not protected, addressing is hidden inside tunnel no problems with NAT 2003, Cisco Systems, Inc. All rights reserved. 2003, Cisco Systems, Inc. All rights reserved. IPSec supports two types of headers the authentication header (AH) and the Encapsulated Security...

Make sure you do both ingress and egress filtering

All rights reserved. In the context of a firewall, the firewall device should provide protection against spoofing on its interfaces. The two most common guidelines for deploying anti-spoofing rules are On each perimeter interface, disallow traffic entering the firewall to carry source addresses, which are reachable on another perimeter On each perimeter interface, filter out source addresses which should, by definition, not be present on that network, for example, the...

Stateful Packet Filtering Definition

Stateful packet filtering is an application aware method of packet filtering that works on the connection (flow) level. A stateful packet filter (SPF) Maintains a state table (or connection table), where it keeps track of all the active sessions over the firewall Is application aware a SPF is able to recognize all session of a dynamic application The state table is part of the internal data structure of a SPF. It tracks all the sessions, and inspects all the packets passing over the SPF-based...

Packet Filter Handling of Oracle SQLNet

Oracle SQL*Net is a dynamic protocol, where the client initially connects to a well-known listening port on the Oracle server. The server then redirects the client to a new, random server port, and the client reconnects to it and proceeds with the database management system (DBMS) session. This redirect is a message on the application layer. A packet filter cannot snoop on the client-server negotiation to see the redirect therefore opening of all high TCP ports to the server is necessary....

Guidelines for uRPF

Unicast RPF is used in firewall environments to prevent IP address spoofing, which can be an indication of a DoS attack. Note that uRPF relies on the Forward Information Base to determine if the source address is valid or not. Additionally, RFC 1918 addresses and loopback networks should be manually filtered or routed to the null interface. Note that uRPF is generally an edge feature as this functionality should be close to possible spoofing sources. Practically, uRPF is configured on dial-up...

Alternative Firewall Technologies

Besides filtering of IP applications, other technologies can easily be classified as firewalls, if they perform any access control between networks. Examples of such technologies include Filtering of Layer 2 (L2) frames, using a L2 device such as a dedicated switch or bridged router interfaces Setting of static ARP entries or switch CAM entries, which effectively only enables communication between selected hosts Filtering of voice data calls on a PBX Filtering of incoming ISDN data calls based...

Firewall Limitations in Application Security

Firewall Limitation

This figure illustrates the concept of application security, when firewalls are used. A firewall can protect a vulnerable web server, but all the firewall might do is pass all web sessions to the server, and deny all other sessions. An attacker can compromise the exposed host if the permitted web sessions contain malicious data. The firewall may limit data flow on the application layer, but most firewalls on the Internet do not. While some firewalls are able to filter traffic with fine...

ICMP Refresher

IP hosts and routers use the ICMP protocol to provide basic error signaling and notifications, such as Reachability information (echo, echo-reply, unreachable messages) Resource quality (source quench messages) Information (mask-request, mask-reply, timestamp messages) Generic error reporting (parameter problem messages) Usually, IP hosts do not rely on ICMP information and can, in most cases, operate with ICMP filtered out of the network. Many network administrators use the traceroute...

ALG Handling of H323

An H.323 ALG is a combination of a H.323 gatekeeper and a H.323 proxy. Such an ALG presents the only visible media endpoint, and all other endpoints communicate with it to route calls to their final destinations. The ALG, especially the gatekeeper, may deploy filtering rules, specifying which functionality is allowed within the H.323 network. This is a solution that minimizes the exposure of a H.323 network and allows minimal connectivity from untrusted networks to the ALG itself. Depending on...

Firewall Limitations

In general, firewalls have the following limitations As firewalls are used in critical points of the network, their misconfiguration can have disastrous consequences. Firewalls are often a single-point-of-failure security wise, and a single mistake in either a configuration rule or firewall code can compromise the network access policy. Many of the modern applications are firewall-unfriendly, as they are difficult to inspect properly. Compromises in rule design and inspection depth have to be...

PIX Outside Dynamic NAT

For outside dynamic translation, outside dynamic NAT can be configured with version 6.2, and static outside NAT is now available using normal PIX NAT syntax (the static command instead of the alias command). With dynamic outside translation in PIX OS 6.2, the nat command includes two additional keywords dns and outside. The dns keyword specifies that DNS replies should be intercepted and the addresses inside them translated to appropriate outside local addresses. The outside keyword specifies...

Screened Subnet

In order to provide a layered approach, the idea of the screened subnet was developed. The idea is based on a creation of a buffer network, which is situated between perimeters, and actually represents a miniature perimeter itself. This small network, often called the demilitarized zone (DMZ), is neither an inside, nor an outside network. It acts as no-man's land, and access to it is permitted from inside and outside, although no traffic can ever directly cross the DMZ. Filtering points, set up...

Example Scenario Xko

A bank needs to connect to two business partners over a single frame-relay router, and their requirements for NAT are Different global addresses must be used for each partner The PIX NAT algorithm is destination insensitive, so this is impossible without tricks. We will use two outside interfaces connected to the same physical network, and use different global pools on them to satisfy the requirements. This requires overlapping subnets on the outside physical network, and secondary addresses on...

Outbound static PAT static NAT dynamic Natpat best match of the nat command addressmask

All rights reserved. DPS 1.0-5-1-26 All PIX NAT mechanisms (dynamic, static, identity NAT) can coexist, as long as interfaces are not configured with overlapping global addresses. When configuring multiple NAT mechanisms, the most specific rule will apply to traffic. For connections initiated inbound, static PAT is evaluated first, followed by static NAT. For outbound connections, static PAT has precendece over static NAT, which has precedence over classic dynamic NAT...

RFC 1918 Address Blocks

RFC 1918 defines three private IP address blocks for local use. These addresses must not be used within the Internet. Internet boundary routers should filter any routing updates containing such addresses. Therefore, RFC 1918 addresses are safer for local use than official (global) addresses. In addition, invalid routes may occur in the Internet routing tables because global addresses are not filtered. 10.0.0.0 - 10.255.255.255 (prefix 10 8) 172.16.0.0 - 172.31.255.255 (prefix 172.16 12)...

SPF Features and Limitations

Simple configuration The firewall operator does not need to be aware of the application protocol internals the stateful intelligence handles any exceptional behavior and hides it from the user. Easy enough to provision new applications Vendors can develop the intelligence needed to provision new applications in a much shorter timeframe compared to application-layer gateways. Very robust filtering Especially for TCP flows, where a lot of information is checked against the state table. Very high...

Topology Identification

The next step in identification of an organization's current situation is the identification of network topology. This will provide a detailed insight into the definition of network boundaries. Note Identification of network connections within the topology might identify connections that an organization is not aware of. From the security perspective, this is crucial to prevent any data leaks over backdoor connections between network perimeters. Topology identification can be broken down into...

ALG Limitations

The ALG approach has the following major weaknesses A relatively small number of ALGs exist to support modern applications, forcing a designer to make unwelcome compromises. ALGs are frequently not used to their full potential, as many applications are too complex to describe their details to the ALG. For example, it would be beneficial for an ALG protecting a custom web application, to check all sensitive parameters passed between the client and the server. However, this would require...

ALG Handling of FTP

This figure illustrates an FTP ALG passing traffic over an ALG-based firewall. Step 1 The inside client starts an FTP session with the FTP ALG, authenticating and passing a request for a remote file. Step 2 The FTP ALG poses as the destination server to the client. After receiving the client request, the FTP ALG opens a new FTP session to the destination server, and proxies the client's request to it. Step 3 The destination server sends the file to the FTP ALG, which filters the response with,...

URL Filtering

Cache size should be a few hundred kilobytes. The caching policy should be destination based if the same policy applies to all inside hosts. Otherwise, source-destination pair based caching should be used. http is a keyword specifying port 80. The port may otherwise be explicitly listed, and must be listed separately if not in sequential order. Local IP and mask information represent the inside network stations Foreign IP and mask information can represent outside web servers (or 0.0.0.0...

Microsoft Exchange

Microsoft Exchange uses several protocols to transfer mail between users and gateways, and the availability of those protocols can vary in different versions of Exchange. Mail transfer between Exchange MTAs (servers) can use two methods Native Exchange protocol Uses Microsoft RPC (TCP 135) to negotiate dynamic ports. Using manual Windows registry settings, those ports can be limited to a range of ports, minimizing endpoint exposure. The native protocol is used by default for all Exchange...

Stateful Packet Filtering of GRE

This figure illustrates an example of running a foreign protocol such as IPX, over an IP firewall by using a generic routing encapsulation (GRE) tunnel. Such workarounds are always discouraged (but sometimes are required as the only means to extend non-IP protocols, etc), as a small misconfiguration on GRE endpoints can compromise the firewall. The two routers on both sides of the firewall create a GRE session, which the firewall permits. This is functionally equivalent to having a back-to-back...

Commercial dedicated application gateways available filtering inside the CORBA protocol

All rights reserved. The CORBA relies on the Internet Inter-Orb Protocol (IIOP) to access distributed objects on a network. UNIX environments often use CORBA as an equivalent to Windows-based DCOM. Various E-commerce and network management products use CORBA, often running over firewalls. The protocol itself is simple in terms of sessions (a single TCP channel), but is NAT-unfriendly. Special application gateways for CORBA exist, which can provide granular CORBA...