Free Hosting for Your Website
InfinityCloud Storage Solution
More Information
Brand new SSD Cloud technology allows you to store and deliver all of your videos, audio, images, and media files at a fast speed in the InfinityCloud Storage solution. You can upload & manage Videos, Images, Audio, Documents, & More, upload your files In seconds, and upload ANY file/document/folder you name It. Just simply drag and drop the files and witness the ease and efficiency. Has shareable links to share anywhere you want including social media sites like Facebook, Twitter, etc. It also allows you to share via email, for uploaded files log in and access them from anywhere in the world, on any device & at any time. Furthermore, you can upload files In the background to carry out your work hassle-free and so much more. Store files without EVER paying for storage upgrades or spreading files around multiple accounts knowing all your files are fully backed up so you'll never lose any important data. Share files instantly on social media or anywhere with one-click share links. Preview any file to quickly scan for the info you need without needing to download it. Host your videos, audio, and images and enjoy lightning-fast upload speeds for higher conversions compatible with iOS, Android, and Windows! Free your mind to focus on the big-picture drivers in your business and so much more. More here...
InfinityCloud Storage Solution Summary
Contents: Cloud Storage Hosting
Official Website: infinitycloud.live
Access Now
My InfinityCloud Storage Solution Review
Of all books related to the topic, I love reading this e-book because of its well-planned flow of content. Even a beginner like me can easily gain huge amount of knowledge in a short period.
All the modules inside this e-book are very detailed and explanatory, there is nothing as comprehensive as this guide.

An Outside User Visits a Web Server on the DMZ
Figure 15-3 shows an outside user accessing the DMZ web server. Web Server 1G.1.1.3 Web Server 1G.1.1.3 1. A user on the outside network requests a web page from the DMZ web server using the global destination address of 209.165.201.3, which is on the outside interface subnet. For multiple context mode, the security appliance first classifies the packet according to either a unique interface or a unique destination address associated with a context the destination address is associated by matching an address translation in a context. In this case, the classifier knows that the DMZ web server address belongs to a certain context because of the server address translation. 5. When the DMZ web server responds to the request, the packet goes through the security appliance and because the session is already established, the packet bypasses the many lookups associated with a new connection. The security appliance performs NAT by translating the local source address to 209.165.201.3.
An Inside User Visits a Web Server on the DMZ
Figure 15-4 shows an inside user accessing the DMZ web server. User Web Server User Web Server 1. A user on the inside network requests a web page from the DMZ web server using the destination address of 10.1.1.3. For multiple context mode, the security appliance first classifies the packet according to either a unique interface or a unique destination address associated with a context the destination address is associated by matching an address translation in a context. In this case, the interface is unique the web server IP address does not have a current address translation. 4. When the DMZ web server responds to the request, the packet goes through the fast path, which lets the packet bypass the many lookups associated with a new connection. User Web Server User Web Server
Solutions to the Threats to Web Servers
In theory, the Internet service that runs on TCP port 80 is intrinsically secure and does not really require protection. However, it is the Web server itself and the network operating system that causes the security concerns. Any service other than the HTTP service running on the server increases the risk associated to the server. The best way to protect against this, as with most other services, is to deploy a firewall that is situated between the public Internet and the Web server. The Web server can then be on a private network, and Network Address Translation can provide the added security of hiding the real IP address of the Web server. The firewall should be further configured only to allow access to the Web server on the required ports. These are usually port 80 for general HTTP traffic and port 443 if the web site is using HTTPS and HTTP.
Web Serveri PlanetSolaris
The iPlanet Web Server policy is similar to the IIS module in that it is a combination of a generic Common Web Server Security module and the more specific iPlanet module. Many of the protections provided by this module are the same as the IIS module, except that they use Unix commands and objects instead of those found in Windows. Rules for XSS, SQL command injection, and common log file exploits are present in this module just as in the IIS module. The rules in this module are shown in Figure 8-5. Figure 8-5 Web Server iPlanet Solarisp Policy Figure 8-5 Web Server iPlanet Solarisp Policy
Configuring Clientless Ssl Vpns
Terminates the HTTPS connections on its public interface and then forwards the HTTP or HTTPS requests to the internal web server. The response from the web server is then encapsulated into HTTPS and forwarded to the client. This feature uses only an Internet browser to access corporate resources. Thus, this mode is referred to as clientless SSL VPNs. Figure 6-10 illustrates this mode. The following sequence of events takes place when UserA tries to connect to a web server located at 192.168.1.100 1 UserA initiates an HTTP request to the web server, which is located on the other side of the SSL VPN tunnel. The user request is encapsulated into the SSL tunnel and is then forwarded to the IOS router. Web Server NOTE If you frequently use Java and ActiveX coding on a web page, a Cisco IOS router might not be able to rewrite web pages that embed that content. You can enable the port-forwarding option to tunnel HTTP traffic directly to the web server.
Do I Know This Already Quiz Ngw
Consider an enterprise network using private class A network 10.0.0.0, and using NAT to translate to IP addresses in registered class C network 205.1.1.0. Host 10.1.1.1 has an open www session to Internet web server 198.133.219.25. Which of the following terms refers to the destination address of a packet, sent by the web server back to the client, when the packet has not yet made it back to the enterprise's NAT router
Destination Unreachable ICMP Message
Assume that Fred is trying to connect to the web server, called Web. (Web uses TCP as the transport layer protocol.) Three of the ICMP unreachable codes would possibly be used by Routers A and B. The other two codes would be used by the web server. These ICMP codes would be sent to Fred as a result of the packet originally sent by Fred.
Answers to the Chapter 8 Do I Know This Already Quiz
5 Configure and enable an IP access list that allows packets from subnet 10.3.4.0 24, to any Web server, to get out serial interface S0. Also allow packets from 134.141.5.4 going to all TCP-based servers using a well-known port to enter serial 0. Deny all other traffic. 9 Configure a named IP access list that allows only packets from subnet 193.7.6.0 255.255.255.0, going to hosts in network 128.1.0.0 and using a Web server in 128.1.0.0, to enter serial 0 on a router. 2 Configure an IP access list that allows only packets from subnet 193.7.6.0 255.255.255.0, going to hosts in network 128.1.0.0 and using a Web server in 128.1.0.0, to enter serial 0 on a router. 5 Configure and enable an IP access list that allows packets from subnet 10.3.4.0 24, to any Web server, to get out serial interface S0. Also allow packets from 134.141.5.4 going to all TCP-based servers using a well-known port to enter serial 0. Deny all other traffic.
Configure System Administrator Credentials
The GUI Web interface files must be installed in flash memory on a Web server that runs locally on the Cisco CME router. The HTTP server on the Cisco CME router is disabled by default. In order to enable it, enter ip http server from global configuration mode. While this starts the HTTP service, it does not define where the files are that will be served up by the local routers Web server will reside. To configure the location of the files to be served by the Web server enter the command ip http path flash from global configuration mode. Authentication is set to use the enable password by default. It is recommended that authentication be configured to use AAA or a local username and password pair. The ip http authentication command is used to configure the authentication method that is desired. Enables the Cisco Web server on the local Cisco CME router
Developing a Baseline of Network Performance
In addition to allocating sufficient time for a baseline analysis, it is also important to find a typical time period to do the analysis. A baseline of normal performance should not include nontypical problems caused by exceptionally large traffic loads. For example, at some companies, end-of-the quarter sales processing puts an abnormal load on the network. In a retail environment, network traffic can increase fivefold around Christmas time. Network traffic to a web server can unexpectedly increase tenfold if the website gets linked to other popular sites or listed in search engines.
Cisco Systems Terms and Acronyms
Method of distributing Web traffic by taking into account Web server availability and relative client-to-server topological distances in order to determine the optimal Web server for a client. DistributedDirector uses the Director Response Protocol to query DRP server agents for BGP and
Application Layer Attacks
The primary problem with application layer attacks is that they often use ports that are allowed through a firewall. For example, a hacker executing a known vulnerability against a Web server often uses TCP port 80 in the attack. Because the Web server serves pages to users, a firewall needs to allow access on that port. From a firewall's perspective, it is merely standard port 80 traffic.
Case Study Deployment of IDS Sensors in the Organization and Their Typical Placement
Figure 10-19 and Figure 10-20 illustrate the Company XYZ network diagram for this scenario. An Internet user (cracker) is connected via a public connection to Company XYZ headquarters, with the intention of hacking into one of the web servers (WebServer1). The server has been attacked frequently before, and the network administrator wants to implement a solid solution using a network IDS configured for IP blocking.
Configuring DNS Rewrite
Step 1 Create a static translation for the web server, as follows mapped-address The translated IP address of the web server. real-address The real IP address of the web server. Step 2 Create an access list that permits traffic to the port that the web server listens to for HTTP requests. mapped-address The translated IP address of the web server. port The TCP port that the web server listens to for HTTP requests. Step 5 On the public DNS server, add an A-record for the web server, such as where domain-qualified-hostname is the hostname with a domain suffix, as in server.example.com. The period after the hostname is important. mapped-address is the translated IP address of the web server. Web server 192.168.100.10 In Figure 25-2, a web server, server.example.com, has the real address 192.168.100.10 on the DMZ interface of the security appliance. A web client with the IP address 10.10.10.25 is on the inside interface and a public DNS server is on the outside interface.
HELLO Welcome to httpwwwwormcom Hacked By Chinese
A hacker can select port 443 as a listening port and remain undetected. The hacker can then set up a port redirector without disrupting operations. A port redirector takes traffic coming in on one port and directs it to another host on another port. In this example, the port redirector on the web server takes incoming traffic on port 443 and sends it out to port 3389 on the database server.
Security Device Event Exchange SDEE
Besides allowing a standard, secure event-logging protocol, SDEE also guarantees delivery of log messages. SDEE uses TCP for the transport protocol. It is also a pull method, meaning that the monitoring station pulls event logs from the device, just as your web browser pulls information from a web server. Syslog and SNMP, on the other hand, are push methods, meaning that they blindly fire event logs onto the network, without knowing whether they reach their destination.
Multiplexing Using TCP Port Numbers
Some examples will help make the need for multiplexing obvious. The sample network consists of two PCs, labeled Hannah and Jessie. Hannah uses an application that she wrote to send advertisements that display on Jessie's screen. The application sends a new ad to Jessie every 10 seconds. Hannah uses a second application, a wire-transfer application, to send Jessie some money. Finally, Hannah uses a web browser to access the web server that runs on Jessie's PC. The ad application and wire-transfer application are imaginary, just for this example. The web application works just like it would in real life. A TCP web server application Web Server Multiplexing relies on the use of a concept called a socket. A socket consists of three things an IP address, a transport protocol, and a port number. So, for a web server application on Jessie, the socket would be (10.1.1.2, TCP, port 80) because, by default, web servers use the well-known port 80.
About the Technical Reviewers
Mahler, CCNP and CCDA, is the National Wide-Area Network and Network Operations Center manager for the American Cancer Society. Kevin's teams are responsible for designing, deploying, maintaining, and monitoring the networks of the American Cancer Society. He also runs his own Web hosting company where he is trying to find his fortune on the Internet. He is the author of CCNA Training Guide published by New Riders. He also worked as a revision author on the third edition of Internetworking Technologies Handbook from Cisco Press. Kevin ran his own company designing, selling, and installing computer and networking systems for over ten years. Kevin has worked as a programmer, repair technician, networking consultant, database administrator, and Internetworking engineer. Today, he reminisces of when CP M was king, everyone wanted WordStar, Microsoft was a small company, portable computers weighed just under 45 pounds, and 10 Mbps was a fast network.
Reverse Proxy Technology
HTTPS provides secure web communication between a browser and a web server that supports the HTTPS protocol. SSL VPN extends this model to allow VPN users to access corporate internal web applications and other corporate application servers that might or might not support HTTPS, or even HTTP. SSL VPN does this by using several techniques that are collectively called reverse proxy technology. A reverse proxy is a proxy server that resides in front of the application servers, normally web servers, and functions as an entry point for Internet users who want to access the corporate internal web application resources. To the external clients, a reverse proxy server appears to be the true web server. Upon receiving the user's web request, a reverse proxy relays the user request to the internal web server to fetch the content on behalf of the users and relays the web content to the user with or without additional processing. Many web server implementations support reverse proxy.
Appendix B Answers to Applied Knowledge Questions
4 Your boss returns from a security convention and advises you that it is a good security practice to run all internal web servers on port TCP 8080 rather than TCP 80 to help secure access to them. How do you respond 9 In the section on the axiom Everything is a target, you saw the various ways in which a web server could be compromised. Now run through the exercise yourself and list the potential methods an attacker could use to gain access to your internal LAN.
Monitoring Access Lists
Each line of the ACL is shown, along with a hit counter indicating how many connections or flows (or packets for ICMP) have been matched by that line. This is shown as (hitcnt n) at the end of each ACE. For example, an access list configured to permit inbound HTTP connections to several web servers is shown to have the following contents and hit counters Now suppose that an object group has been configured to list the web servers with the following commands Firewall(config) object-group network web-servers Firewall(config-network) network-object host 192.168.3.16 Firewall(config-network) network-object host 192.168.3.19 Firewall(config-network) network-object host 192.168.3.23 Firewall(config-network) network-object host 192.168.3.231 Firewall(config-network) network-object host 192.168.3.
Case Study 3 Cartoon Works Inc
In addition, the company has been developing and testing its two new NT Web servers on the new Internet segment. These new Web servers need to communicate with the new NT SQL database at the Oak Street office. The Media Group, which is part of the Production department, will complete its testing within one month. With the new Web servers, Ms. Roberts needs to also implement a DNS solution and register a domain name. Ms. Roberts has begun the process of acquiring a domain name in preparation for the Internet access, but she needs to install and secure her DNS servers.
MPLS Backbone Link Sizing
This step estimates the volume of traffic flow from PoP to PoP based on a variety of factors, including customer population distribution and modified access line bandwidth per PoP. Another factor is the presence of co-located applications such as Web servers in the case of a service provider who is also an ASP. The exact procedure for this step varies from network to network. For interstate business IP traffic, a reasonable first approximation might be that 33 percent of traffic will go to Chicago, 22 percent to Washington, 13
Interaction Between OSI Layers
Imagine a Web browser displaying a Web page that it received from a Web server. Before that happened, the browser somehow interacted with the software implementing other layers of TCP IP on the client computer, causing a request to flow to the server. Likewise, the broswer application somehow communicated with the Web server application, telling the server what Web page the browser wanted to display. A fancy way to describe these two ideas that is interaction between OSI layers. The process of how layers interact on the same computer, as well as how the same layer processes on different computers communicate with each other, is all interrelated. The software or hardware products implementing the logic of some of the OSI protocol layers provide two general functions
Cisco Secure ACS Configuration
Cisco Secure ACS is configured through a web-based application that is called ACS Admin. When you install Cisco Secure ACS, you also install a complete web server to which the ACS Admin site is bound. This web server only operates on port 2002, and it runs as a Windows NT service on the Windows NT version and as an application on the UNIX version. This service is called CSAdmin and can be stopped and started like any other Windows NT service.
Lightweight Directory Access Protocol
Cisco Unified IP Phones access the LDAPv3 directory when the Directory button is pressed. The IP phone responds to the Directory button click by sending an HTTP directory lookup request to the Apache web server on CUCM. The response from CUCM contains Extensible Markup Language (XML) user information objects that the phone displays to the person using the phone. Cisco Unified IP Phones perform user lookups against the embedded CUCM database by default. The directory lookup can be configured to allow the IP phones to access a corporate LDAPv3 directory. The phones would then send their HTTP user lookup requests to an external web server that operates as a proxy to the LDAPv3 server. The user lookup requests are translated into LDAPv3 queries against the corporate directory. The LDAPv3 response is then encapsulated in the appropriate XML objects and sent back to the phones via HTTP.
Analyzing Network Efficiency
To determine if your customer's goals for network efficiency are realistic, you should use a protocol analyzer to examine the current frame sizes on the network. Many protocol analyzers let you output a chart such as the one in Figure 3-7 that documents how many frames fall into standard categories for frame sizes. Figure 3-7 shows packet sizes at an Internet service provider (ISP). Many of the frames were 64-byte acknowledgments. A lot of the traffic was HTTP, which used 1500-byte packets in most cases, but also sent 500- and 600-byte packets. If many webhosting customers had been transferring pages to a web server using a file-transfer or file-sharing protocol, there would have been many more 1500-byte frames. The other traffic consisted of DNS lookups and replies, Simple Mail Transfer Protocol (SMTP), Post Office Protocol (POP), and Address Resolution Protocol (ARP) packets.
Raleigh Office Cisco ASA Configuration
Web server Step 2 The screen shown in Figure 12-12 is displayed. First configure static NAT for the web server. Under the Original section, choose the dmz interface from the drop-down menu, and enter the web server physical IP address (10.10.20.10) as the source. Step 4 Click the Use IP address option, and enter the public address to which the web server will be translated (209.165.200.227).
Mitigating Port Redirection Attacks
In Figure 9-3, the firewall permits any machine on the Internet to connect to the web server on the DMZ. Additionally, the firewall permits all traffic from the DMZ into the internal LAN and permits all traffic from the DMZ to the Internet. Finally, the firewall permits all traffic from the internal LAN going out. An attacker can exploit a vulnerability in the web server to gain access to that host. Once access to the web server in the DMZ is obtained, the attacker can set up port redirection software to redirect traffic so that the traffic connects to the system on the internal LAN. In Figure 9-3, the web server TCP port 80 is redirected to connect to the Telnet port on the internal host. The attacker then connects to the web server on TCP port 80 and is automatically redirected to the Telnet port on the internal host. This allows the attacker to tunnel into the internal LAN through the firewall without violating the firewall policy.
IIS Directory Traversal Vulnerability
One of the most widely known targets of an application layer attack is the Microsoft Internet Information Server (IIS) directory traversal vulnerability or UNICODE attack. An attacker who exploits this vulnerability is capable of searching the directories on the server outside of the web root directory. This allows them to view files that they would normally not have access to. It also allows the attacker to exploit certain commands, such as tftp, to further exploit the host. This can all be done through a regular web browser such as Internet Explorer or Netscape. One particular program that was written to use this exploit is called iis-zang, which provides an attacker with a pseudo-command-line interface to the web server. Microsoft provided a patch for this vulnerability in August of 2000 and published Microsoft Security Bulletin MS00-057 regarding this vulnerability.
Cisco Secure IDS Sensors
Web servers Includes the Standard Edition functionality but also protects the web server application and the web server API The Standard Edition Agent is leveled for general host use. The Server Edition Agent, however, is aimed at public-facing devices, such as web servers, which require additional levels of security because of increased vulnerabilities.
Populating Cisco Express Forwarding
With CEF, you can achieve per-packet load sharing, but the default is per-destination load sharing. Per-destination uses both source and destination for load sharing. Per-packet is more useful when the bulk of the traffic is destined for one host, such as a Web server. To balance the traffic from multiple users to the same destination with per-packet load sharing, the router sends packets to the same destination on different paths, as shown here
Extended IP Access Lists Example
The first example is basic in order to cover the statements syntax. In this case, Bob is denied access to all FTP servers on R1's Ethernet, and Larry is denied access to Server1's Web server. Figure 8-6 is a reminder of the network topology. In Example 8-6, an access list is created on R1. Example 8-6 shows the configuration on R1. So, in this example, the access lists should have been placed on R2 and R3, respectively. And because the goal is to put the most frequently matched statements first, the permit any should be first in the list, right Of course not The first entry in the list that is matched determines the action. So, changing the permit any action at the beginning changes what is actually denied, which goes against the strategy and also goes against what Example 1 is trying to achieve. Example 8-7 defines an access list on R3 that prevents Bob from reaching all FTP servers off R1's Ethernet.
Case Study 3 Answers Cartoon Works Inc
Novell Internet e-mail system Web servers SQL database DNS Server The e-mail system depends on the DNS server because it requires a mail exchange record for Internet mail services. Web servers depend on the DNS server for name resolution. Web browsers also depend on the DNS server for name resolution. Web Servers Web Servers
Overview of Multilayer Switching
Strictly defined, a flow is a specific conversation, consisting of multiple packets, between a network source and destination within a specific time sequence. Let's take a user that is pulling down a web page from a specific web server. This example would be one flow. The same user could be performing a File Transfer Protocol (FTP) file transfer at the same time from an FTP server. This example would be a completely different flow. Two different applications two different protocols two different flows however, only one host is performing two flows. In terms of flows, there is no distinction between unicasts or multicasts.
Flow Control Using Windowing
Notice that the web server must wait after sending the third segment because the window is exhausted. When the acknowledgment has been received, another window can be sent. Because there have been no errors, the web client grants a larger window to the server, so now 4000 bytes can be sent before an acknowledgment is received by the server. In other words, the Window field is used by the receiver to tell the sender how much data it can send before it must stop and wait for the next acknowledgment. As with other TCP features, windowing is symmetrical both sides send and receive, and, in each case, the receiver grants a window to the sender using the Window field.
Error Recovery Reliability
Web Server Figure 6-6 depicts the same scenario, but the second TCP segment was lost or was in error. The web client's reply has an ACK field equal to 2000, implying that the web client is expecting byte number 2000 next. The TCP function at the web server then could recover lost data by resending the second TCP segment. The TCP protocol allows for resending just that segment and then waiting, hoping that the web client will reply with an acknowledgment that equals 4000. Web Server Web Server
Configuring IPS Through ASDM
The AIP-SSM module can be configured for IPS features through the CLI or on an ASDM window. It is recommended that the administrator configure the IPS features through the ASDM as it removes most of the user error that can come from direct CLI configurations, like typos. To use the ASDM for configuration, the module will require an HTTPS web server to be enabled, as shown in Example 19-8 in the preceding section, as well as for the HTTPS web server to have an IP address that is accessible on the network. Once you have completed the setup command, you will be able to access the IPS configuration options from ASDM. Once you bring up an ASDM window for the Security Appliance, you will see the IPS button on the left side of the window, as shown in Figure 19-2.
PIX Outside Dynamic NAT
In the example presented in the figure, hosts from a dedicated outside network are allowed to access the local Web server because an outside NAT configuration makes them appear as the local host. Therefore, the local (internal) routers treat them accordingly, applying the same rules as for inside hosts.
Firewall Limitations in Application Security
This figure illustrates the concept of application security, when firewalls are used. A firewall can protect a vulnerable web server, but all the firewall might do is pass all web sessions to the server, and deny all other sessions. An attacker can compromise the exposed host if the permitted web sessions contain malicious data. The firewall may limit data flow on the application layer, but most firewalls on the Internet do not.
Egress Firewall Rules
For example, a strict default egress policy might make sense for your company's public-facing web server. Hopefully, connectivity from the Internet to your web server (ingress rule) is permitted only on either TCP 80 or 443, depending on whether your web server uses encrypted HTTP. The egress policy should deny all traffic that originates from the web server to hosts on the Internet. In other words, someone should never be allowed to browse the Internet from your web server, to download files from the web server, or to have other communications from the web server to the Internet. By applying a proper egress rule on the firewall that denies it, an attacker is also denied that same communications path. In most instances where a web server, or any other server, is compromised by a hacker, the hacker's next steps include copying files to the web server. This is either to deface websites, install root kits, or retrieve the software needed to further hack into the network.
Table 39 Web Application
Insecure CGI applications can be an early entrant for the attacker looking to compromise a web server. Whenever you fill out a form or enter your address on a website, chances are you are using some form of CGI script. Properly written CGI scripts can be secure and, among other things, should not accept any data types that they have no reason to receive. For example, if CGI programs request user addresses, they must allow users to type the following characters az, AZ, 09, period, comma. The program, however, need not allow () and so on. Poorly written CGI applications can allow attackers to execute commands on the web server by using the privileges of the web server itself. One attack might cause an X terminal to be opened up from the web server to the attacker. Such an attack might look like this
ICMP Filtering Recommendations
Permit echo-request from the public web server to anywhere access-list 103 permit icmp host 126.0.64.10 any echo permit echo-reply from the public web server to anywhere access-list 103 permit icmp host 126.0.64.10 any echo-reply permit fragmentation needed but DF bit set message access-list 103 permit icmp any any packet-too-big permit Time exceeded message
Cisco Net Flow Accounting
Gathering NetFlow data also allows a network manager to gain a detailed, time-based view of application usage. Content and service providers can use this information to plan and allocate network and application resources to meet customer demands. For example, a content provider can decide on the capacity and location of web servers, based on NetFlow data. NetFlow data, or the information derived from it, can be warehoused for later retrieval and analysis, in support of proactive marketing and customer service programs (for example, to determine which applications and services are being used by internal and external users and target them for improved service).
SSO Support for WebVPN with HTTP Forms
The security appliance can use the HTTP Form protocol for single sign-on (SSO) authentication of WebVPN users only. Single sign-on support lets WebVPN users enter a username and password only once to access multiple protected services and Web servers. The WebVPN server running on the security appliance acts as a proxy for the user to the authenticating server. When a user logs in, the WebVPN server sends an SSO authentication request, including username and password, to the authenticating server using HTTPS. If the server approves the authentication request, it returns an SSO authentication cookie to the WebVPN server. The security appliance keeps this cookie on behalf of the user and uses it to authenticate the user to secure websites within the domain protected by the SSO server.
Cut Through Proxy Firewall Communication Process
The example in the figure shows the process that a cut-through proxy uses. In this example, Richard tries to access the internal web server (200.1.1.1). In Step 1, the cut-through proxy intercepts the connection request and authenticates Richard. After authentication (in Step 2), the cut-through proxy adds the authenticated connection and any other authorized connections to the filtering rules table. From here, the filtering rules at Layer 3 and Layer 4 handle any traffic from Richard to the web server (Step 3). This filtering provides a significant boost in throughput. However, the downside is that the cut-through proxy does not examine application layer data and, therefore, it cannot detect application layer attacks.
Configuring NAT with Cisco SDM
Choose the Advanced NAT wizard if you want to connect your network to the Internet (or the outside), and your network has hosts and servers, and the servers must be accessible to outside hosts (hosts on the Internet). If your network has e-mail servers, web servers, or other types of servers and you want them to accept connections from the Internet, choose Advanced NAT and click the Launch the Selected Task button.
Diverting Traffic to the Csc Ssm
The second policy, csc_in_policy, is applied to the outside interface and uses the csc_in access list to ensure that requests for SMTP and HTTP originating on the outside interface and destined for the DMZ network are scanned by the CSC SSM. Scanning HTTP requests protects the web server from HTTP file uploads.
Device Managers and Craft Terminals
Contrary to most other management tools, craft terminals generally do not retain any information about the managed equipment in a database, nor do they offer electronic interfaces to other management applications. All they provide is a remote real-time view of the equipment you want to look at, one at a time. In some cases, managed equipment might already provide a built-in craft interface, for example, by way of a mini-web server that renders a device view. In this case, separate craft terminal software is not needed because all that a user needs to do is point a web browser at the device.
How Does a DoS Attack Differ from a DDoS Attack
A DoS attack is usually initiated by one source against one service. It uses inherent weaknesses in the service itself or in the hardware infrastructure that the service uses for service delivery. An example is a hacking attempt against a web server targeted against the security vulnerabilities in the web-server software itself.
Infrastructure Protection Access Control Lists iACLs
4 Unlike ISPs, enterprises are the destination for traffic. The last section of the iACL permits all other normal backbone traffic destined to noninfrastructure destinations for only specific protocols and ports. For example, you can allow HTTP for a web server bank with IP address space 209.165.200.0 24, as follows
Authentication Authorization and Accounting AAA and Identity Management
Authentication is the process of validating users based on their identity and predetermined credentials, such as passwords and other mechanisms like digital certificates. Authentication is widely used in many different applications, from a user attempting to log in to the network, web server, and wireless access point to an administrator logging in to a firewall, router, or any other network device to successfully configure the former.
Exam Engine and Questions on the CD
The installation process requires two major steps. The CD in the back of this book has a recent copy of the exam engine software, supplied by Boson Software (http www.boson.com ). The practice exam database of IINS exam questions is not on the CD. Instead, the practice exam resides on the www.boson.com web server, so the second major step is to activate and download the practice exam.
Authentication Proxy Configuration Examples
As Figure 15-5 illustrates, the source (A) is using the IP address 192.168.252.135, and the destination is the World Wide Web server (B), located on the internal network at 10.10.10.162. For the purpose of this exercise, NAT is not used for any address space. The Cisco IOS firewall will require any external host attempting to access 10.10.10.162 to authenticate before allowing access. As Figure 15-6 illustrates, the source (A) is located on the internal network using the IP address 10.10.11.10, and the destination is a World Wide Web server (B), located on the Internet at 192.168.55.214. Again, this exercise does not use NAT for any address space. The Cisco IOS firewall requires, any internal host attempting to access the Internet to authenticate before allowing access.
Step 1 Define Clientless Connections
1 Define bookmarks for the internal servers (web and CIFS) by choosing Configuration Remote Access VPN Clientless SSL VPN Access Portal Bookmarks Add. Specify a bookmark list name called Contractors-List and then click Add to specify a bookmark title of Internal-Web. Select http under the URL Value drop-down menu, and configure a URL value of http intranet.securemeinc.com. Under advanced options, enable the Smart Tunnel option to tunnel HTTP traffic directly to the web server. Click OK when finished. Click Add to add another entry for the CIFS server. Under Bookmark Title, specify Internal-FileServer and select cifs from the URL Value drop-down menu. Configure a URL value of fileserver.securemeinc.com.
Setting Up the Appliance
The security appliance uses the Secure Socket Layer (SSL) protocol to communicate with the client. Consequently, the security appliance acts as a web server to process the requests from the clients. You can enable the web server on the appliance by using the http server enable command.
Loading SDM Recommended
You can launch SDM by establishing either an HTTP or HTTPS connection to the router. The router acts as a web server to process the requests from the clients. You can enable the web server on the router by using the ip http server and ip http secure-server commands. The ip http server command is necessary if you prefer to access SDM using HTTP. However, it is best practice to access SDM with secure HTTP by enabling ip http secure-server.
Configuring File Servers
In addition to the web servers, you can also define a bookmark list of the file servers that the clientless users can access. Cisco ASA supports network file sharing using the Common Internet File System (CIFS), a file system that uses the original IBM and Microsoft networking protocols. Through CIFS, users can access their file shares located on the file servers. Users can download, upload, delete, or rename the files under the shared directories, but only if the file system permissions allow them to perform those actions. They can even create subdirectories, assuming that they are allowed to do so.
Configuring Bookmarks
Using a clientless SSL VPN, remote users can browse their internal websites, file server shares, and Outlook Web Access (OWA) servers. Cisco ASA achieves this functionality by terminating the SSL tunnels on its outside interface and then rewriting the content before sending it to the internal server. For example, if a user tries to access an internal website, the user's HTTPS connection is terminated to the outside interface. The ASA then forwards the HTTP or HTTPS request to the internal web server. The response from the web server is then encapsulated into HTTPS and forwarded to the client. This mode is illustrated in Figure 5-25. The following sequence of events takes place when UserA tries to connect to a web server located at 192.168.1.100 1 UserA initiates an HTTP request to the web server, located on the other side of the SSL VPN tunnel. The user request is encapsulated into the SSL tunnel and is then forwarded to the security appliance.
How Firewalls Use Protocols Applications and Services
For example, if you want to allow web access to a system, technically what you are doing is defining that you will allow the HTTP protocol to access the web server application running on the system. The HTTP protocol makes recommendations for things such as the default communications port that should be used for access to the web server application (TCP port 80) and defines things such as message format and how functions such as retrieving web pages as opposed to binary data will be performed. The firewall can then be configured to allow only TCP port 80 to access the protected system, thus preventing any traffic that does not use TCP port 80 from accessing the protected system. Furthermore, if your firewall has enough intelligence, it can use the information from the protocol itself to determine whether the access attempt should be permitted.
Determining If You Need a Firewall
Suppose that your external web server is compromised and that web server is used to process incoming requests that 100 data processors work on. The first thing to do is to define the SLE, and doing that requires that you define the variables mentioned previously. First, you need to define the cost of restoring or repairing the data. This cost can range from the time it takes someone to reboot a server and apply a patch or to restore the server from a tape backup. For this scenario, assume that the cost to recover from this compromise is 500. Next, the loss of the web server and subsequent inability of the workers to do anything productive needs to be factored into the equation. Assuming the employees are paid 12 an hour (average salary of a data-entry clerk in the Houston, Texas, area) and the server is down for a half a day being rebuilt, the cost to the company in just lost time for the users of the web server is 4800. Finally, the
Applications That Are Hard to Firewall
The difficulty with application firewalls stems from the fact that the transaction between the client an server is complex and can be made more so if the protocol or the data in the communication expand increases the complexity of the transaction. Protocols such as eXtensible Markup Language (XML) ar Simple Object Access Protocol (SOAP) make web application firewalls especially tricky. To provide pi web application security, the application firewall must have a detailed understanding of legitimate transactions, including the use of URLs different HTTP methods such as GET (retrieving data from a server), POST (transmitting data to a web server), and other HTTP methods session IDs and sessio cookies XML and SOAP schemas SQL queries and much more. Consider web applications. These applications may use a wide variety of protocols from simple HTML XML to Web Service Definition Language (WSDL) and a whole range of Common Gateway Interface programs.
TCPIP Session Hijacking
Note A proxy is a device that performs a function on behalf of another device. For example, if the firewall proxies TCP connections on behalf of a Web server, then the firewall intercepts the TCP connections from a host trying to access the Web server and ensures that valid connection requests are made. After it validates the connection requests (usually by completing the connection by proxy), it initiates its own TCP connection request to the Web server on behalf of the host. The connection is established and normal data transfer between the client and server can start without further interference from the proxy. If a TCP SYN attack occurs, the proxy is attacked but it is not a critical device.
Configuring Multiple Translation Types on the Cisco Security Appliance
Configured without PAT, once the available global IP address range is depleted, additional translation attempts will be refused. If the location has any servers that need to be accessed from the Internet (web servers, mail servers, and so on), they must be configured for static translation.
Scenario 8 Securing Access and Managing Traffic in a Switched Network
Configure a VLAN access control list that can perform packet filtering within a VLAN. Users in the 192.168.191.0 255.255.255.0 network should be allowed to use only HTTP (www) traffic to the web server 192.168.191.199 24, on VLAN 180. How can you configure the VACL to accomplish this
Understanding Types of DDoS Attacks
All web servers, Domain Name System (DNS) servers, and routers are reflectors, because they will return SYN ACKs or RSTs in response to SYN or other TCP packets query replies in response to query requests or ICMP Time Exceeded or Host Unreachable in response to particular IP packets. By spoofing IP addresses from slaves, a massive DDoS attack can be arranged.
Network Plan End of First Year
The final stage to consider is the plan at the end of the first year of operation. Again, this is a projection on what the business could be like. It is assumed that the ISP has started to do Web hosting for its customers and is investing in a large dialup network (which we shall say that the business plan calls for).
Configuring Content Filters
You can provide the local (source) and foreign (destination) IP addresses and subnet masks. When web clients using local addresses send HTTP requests to web servers with foreign addresses, those requests are subject to filtering. In most cases, you can define the policy to use any local address and any foreign address. To do this, specify the local and foreign values as 0s (0 0 0 0). You can also allow HTTPS traffic to be filtered by a Websense server. Identify the HTTPS port as dest-port (usually port 443). Connections that are subject to filtering have clients using local (source) addresses defined by local_ip and local_mask and web servers using foreign (destination) addresses defined by foreign_ip and foreign_mask. When a web client requests web content from a foreign site, the firewall relays the request toward the website and sends a request to the filtering server all in parallel.
Restrictive security model Allow required actions and deny all other actions
Before configuring your policies, you must understand exactly which network resources and services you want to protect and which threats you are most concerned about. The first step in planning a security policy is identifying the resources that your user community requires in order to do business. That could include specific applications, protocols, network servers, and web servers. Collect this information and use it to design the main features of your policy.
Figure 28 Packet Filtering Firewall Example Initiating Connections
However, what happens if someone inside the network, such as 200.1.1.10, tries to access this external device (170.1.1.1) Assume that this is an HTTP request to 170.1.1.1, which has a web server running on it. HTTP uses TCP, and TCP goes through a three-way handshake to establish a connection before data is transferred SYN, SYN ACK, and ACK. Initially, 200.1.1.10 sends a SYN to establish a connection. With TCP (and UDP), a source port number is chosen that is greater than 1,023, which represents this specific connection. The destination is port 80, telling 170.1.1.1 that this is an HTTP request for web services. 170.1.1.1 now responds back to the TCP SYN message of 200.1.1.10 with a SYN ACK (the second step in the three-way handshake), as shown in Figure 2-9. However, when the packet-filtering firewall examines the packet, it determines that because the destination is 200.1.1.10, the packet should be dropped, according to its packet-filtering rules.
Existing Technologies Frame Relay ATM and IPBased Networks What Can They Solve
Data traverses an IP-based network in the form of packets, where each packet consists of a header that specifies the source, the destination, and the message itself. The IP addressing scheme uses either IPv4 or IPv6 to address computers on the Internet. IPv4 uses 32 bits for addressing, whereas IPv6 has a 128-bit source and destination address scheme that provides more addresses than IPv4. IP permits connectivity via a variety of physical media and provides a best-effort datagram service. Therefore, no hard packet delivery guarantees exist. TCP is often used where reliability is a concern because it guarantees the delivery and ordering of transmitted data. IP provides any-to-any connectivity, as demonstrated by the Internet. Common applications that are used today by companies include e-mail, web hosting, electronic commerce, corporate intranets and extranets, and emerging VoIP.
BOWIEnet Multiservice Networks
BOWIE.net is a regional Internet service provider (ISP) with 60 points of presence (POPs) throughout the Southeast and along the East Coast of the United States. It has a Cisco-powered network and currently provides residential and business access to the Internet, managed network services, and Web hosting.
PIX Set up to Use the alias Command for a Server Sitting on the DMZ
If the web server and the client trying to access it are on the same PIX interface, the normal way of configuring the alias command (alias ) works fine. The alias command doctors the DNS server response for the name of the web server such that the client trying to connect to the server uses its private IP address to connect to it. However, problems arise when the web server is sitting on a subnet connected to a different interface of the PIX than the client. In that case, the normal way of configuring the alias command does not work. The reason for this is that when the client sends a packet to the web server's private IP address provided to it by the doctoring PIX, the PIX translates it back into the web server's public or globally routable address and routes it out the public or outside interface. Of course, this is incorrect because the web server is not located on the public network but rather on a DMZ segment.
Figure 228 Simple Firewall System Design
The traffic then is processed by a stateful firewall. The stateful firewall has set up three security levels low for the Internet side, medium for the DMZ, and high for the internal network. A security rule was added on the stateful firewall to allow traffic from the Internet to only the web server. All other traffic from a lower security level to a higher one is prohibited however, higher-to-lower movement is permitted, allowing the web server administrator located on the internal network to log into the DMZ web server to update web pages.
Configuring Multiple Translation Types on the Cisco PIX Firewall
It is a good practice to use a combination of NAT and PAT. If you have more internal hosts than external IP addresses, you can configure both NAT and PAT. Your first group of hosts translates to the global addresses that are listed, and the remaining hosts use PAT and translate to the single global address. If you do not configure NAT and PAT, the PIX automatically performs NAT starting at the highest IP of the global IP range and performs PAT with the lowest IP after all other addresses have been used. If the location has any servers that need to be accessed from the Internet (web servers, mail servers, and so on), they must be configured for static translation.
Authentication Timeout
After a user is successfully authenticated, his or her user information is saved in cache for a predetermined amount of time. You set this time by configuring the timeout uauth command. It is specified in hours, minutes, and seconds. If the user session idle time exceeds the timeout, the session is terminated, and the user is prompted to authenticate during the next connection. To disable caching of users, use the timeout uauth 0 command. Be sure not to use timeout uauth 0 when using virtual http. This setting prevents any connections to the real web server after successful authentication at the Cisco PIX Firewall.
Realistic Configuration
Routable IP addresses, because you need people on the Internet to be able to browse your Web server, download files from your FTP server, and send and receive from your e-mail server. You now have three major design changes to make to your system. You must first allow WWW traffic to access the Web server, whose IP address is 10.1.1.30. This IP address needs to be statically translated to a routable address on the Internet. One of the easiest ways to keep track of static IP translations is to use the same last octet in both addresses. In the case of the Web server, you will use 30 as the last octet. The second change is to allow e-mail through to the mail server. The third change is to allow FTP traffic to the FTP server. All of these servers That is all that is required to allow SMTP packets to traverse the PIX to the server with the 10.1.1.49 IP address. Users outside the PIX will see this server as 192.168.1.49. Packets sent to 192.168.1.
Threats Posed to Internet eMail Servers
One common misuse of Internet e-mail systems is spam. Spam is unsolicited bulk e-mail the people who send it are known as spammers. Spammers usually send bulk e-mails about get-rich-quick schemes or advertising pornographic web sites. Spam is enabled if the Web server is running as an open relay. Various Internet groups, such as the Open Relay Behavior-modification System (ORBS, www.orbs.org ). have emerged to crack down on server administrators who are running open relays, either intentionally or unintentionally.
Free Two-Factor Auth for your Servers and VPNs
As some of you surely know, I prefer to use anything besides Windows whenever possible. I have a few servers at home which run Linux, my primary machine is a MacBook Pro, and this web server now runs Debian GNU Linux (I recently converted it from FreeBSD). I ran through pretty much the same steps on my web server, except that I configured SSH to use two-factor authentication. The only time I log in via the console (via VNC-over-SSH to a console server) is if something bad happened or I don't have network connectivity, which would probably make the two-factor authentication fail. Now, when I SSH into the webserver, I first get prompted for my password if I'm not using a public key. Either way, once the password or public key authentication succeeds, I'm given a choice
Comodo's SSL certificates: the underlying problem
Imagine, just for a moment, that somehow an attacker was able to gain control over an AT&T DNS server (I know, that would never happen, right ). Assuming the attacker already has a web server running with fake login pages set up (a fairly safe assumption in this hypothetical situation, I think), they now have valid SSL certificates installed as well, and can capture valid username and password pairs. This is made worse by the fact that users are known to reuse passwords across sites.
High-Availability failover w/ Apache and Red Hat Enterprise Linux
A few days ago, I wrote about the beginning of a web site migration from IIS5 on Windows 2000 Server to Apache2 on Red Hat Enterprise Linux 4. For those who didn't read the original article (above), the machine that will serve as the new web server is a dual Pentium 3 600MHz box quite old, but it should serve us well. If everything starts up okay, the primary server should start up the Apache webserver, while it won't be running on the secondary. As soon as the primary goes away, however, the secondary server will take over the virtual IP address and start up Apache.
Manage Your Word Press Theme Using Git
The great majority of my readers work in IT (or aspire to) and several of you run your own blogs. If you run your own self-hosted WordPress blog and modify your theme at all, this post may be helpful to you (even if you're not in networking) but it is very long.
Data Encapsulation
You have seen several examples of encapsulation in this chapter already. The web server encapsulated the home page inside an HTTP header in Figure 2-2. The TCP layer encapsulated the HTTP headers and data inside a TCP header in Figure 2-3. IP encapsulated the TCP headers and the data inside an IP header in Figure 2-4. Finally, the network interface layer encapsulated the IP packets inside both a header and a trailer in Figure 2-5.
CatOS Switches
The protocol used by web browsers and web servers to transfer files, such as text and graphic files. HTTPS Hypertext Transfer Protocol Secure. The protocol used to access a secure web server. Using https in the URL instead of http directs the message to a secure port number rather than the default web port number of 80. The session is then managed by a security protocol. IIS Internet Information Services. Microsoft's web server. Runs under the server versions of Windows NT and Windows 2000, adding full HTTP capability to the Windows operating system.
Configuring NACL2IP
In this example, the ACL is named interface_acl and allows EAPoUDP traffic from the end host (CTA), DHCP requests, and HTTP traffic to a web server where quarantined clients can be redirected to obtain more information on how to download OS patches, hotfixes, service packs, and any other software needed to be compliant.
ARP and Proxy ARP
(RFC 1027) is often ignored, in part because of its lack of use today. To see how they both work, Figure 5-3 shows an example of each, with Fred and Barney both trying to reach the web server at IP address 10.1.2.200. Web Server 10.1.2.200 24 GW 10.1.2.1 For instance, Barney places the web server's IP address (10.1.2.200) in the target field, because Barney thinks that he is on the same subnet as the web server due to Barney's mask of 255.0.0.0. The ARP request is a LAN broadcast, so R1, being a well-behaved router, does not forward the ARP broadcast. However, knowing that the ARP request will never get to the subnet where 10.1.2.200 resides, R1 saves the day by replying to the ARP on behalf of the web server. R1 takes the web server's place in the ARP process, hence the name proxy ARP. Also, note that R1's ARP reply contains R1's E1 MAC address, so that Barney will forward frames to R1 when Barney wants to send a packet to the web server.
False Positives
For example, if legitimate communication between a network printer and a host is incorrectly detected by your network-based IDS as an attack, this is, by definition, a false positive. However, this does not fit the definition used by CS-MARS. On the other hand, if a hacker launches an attack against your web server, and your network-based IDS accurately detects the attack but your web server is protected against the attack with updated software, CS-MARS considers this a system-determined false positive. By definition, it is not really a false positive instead, it is a positively detected attack that was unsuccessful. An unconfirmed false positive is created when CS-MARS believes, but is not certain, that a host is not vulnerable to an attack. For example, the first unconfirmed false positive in Figure 1-5 is related to event WWW WinNT cmd.exe Exec, which is a known vulnerability in older versions of Microsoft's IIS web server.
ICMP Unreachable
When a device realizes that a packet cannot be delivered to its destination, the device sends an ICMP Unreachable message. To help determine the root cause of why the packet cannot be delivered, the ICMP Unreachable message includes one of five code field values to convey the reason for the failure. For instance, in Figure 5-1, assume that Fred is trying to connect to the web server, called Web. Table 5-3, following the figure, lists the key ICMP Unreachable message codes, along with an example set of circumstances from Figure 5-1 that would result in each Unreachable code. Host Web is working, but the web server software is not currently running. Host Web sends the Unreachable message to Fred.
Enabling the Cme Gui
Because you will be accessing the GUI through a web interface, you need to turn the CME router into a mini-web server to serve up the CME pages. The configuration in Example 6.17 accomplishes this feat. Example 6.17 Configuring the CME Router as a Web Server Example 6.17 Configuring the CME Router as a Web Server
Inverse ARP
The difference is, while with ARP in the LAN environment, the device knows the protocol address and needs the hardware address to complete frame formation, Frame Relay hands the end device a hardware address (DLCI) that leads through the VC, directly to the other end device. Although DLCI configuration is often more manual on the customer equipment than it might sound here, it is possible to sneak a peek at the configured DLCIs for a particular access line because of LMI updates by the ingress switch. It's the protocol address that is lacking. This is acceptable due to the fact that this is a WAN environment. The missing protocol address is not, for example, an IP address that might be returned someday during a Domain Name System (DNS) query for a Web server. It is the address of the other end's first Frame Relay device, its router, for example.
Three Tier Web Design
Database Server Web Server Database Server Web Server IPermit outside hosts to talk HTTP SSL to the web server access-list 101 permit tcp any host 192.0.2.53 eq 80 access-list 101 permit tcp any host 192.0.2.53 eq 443 IDeny any other web traffic access-list 101 deny tcp any any eq 80 access-list 101 deny tcp any any eq 443 IPermit web server to make requests of the apps server access-list 102 permit tcp host 192.0.2.53 host 192.0.3.12 eq 80 IDeny any web traffic IDeny any web request (the apps server will only be responding to requests Ifrom the web server, since the firewall is stateful, this is automatically Iallowed where appropriate) access-list 103 deny tcp any any eq 80 access-list 103 deny tcp any any eq 443
Commerce
One design to steer clear of is the dual-homed-host e-commerce design. I see this design occasionally when consulting with organizations. Although this design (which is usually a variation on Figure 13-14) can seem more secure at first appearance because application servers and database servers can be put on private internal networks with no ability to route to the outside, it is, unfortunately, a house of cards. A compromise in the initial web server allows all traffic types to attack the application server (from the web server). The application server can then launch the same attacks to the database server.
Simple Network Plan
Figure C-1 shows a simple network diagram of a basic ISP point of presence (PoP), which will be used in these examples. It has the key elements of an ISP PoP a border router, two core routers, aggregation routers (for leased-line or permanently connected customers), two service routers (for web hosting and the ISP's own services), a dial aggregation router, and a router that connects to the network operations center. Obviously, as ISPs grow, their network will be more sophisticated than this, and their configuration needs likewise will grow to match. However, this example should serve as a good grounding for future growth.
Enabling Education
IPv6 in all primary and secondary schools in Greece.20 Covering approximately 13,000 nodes, this new network offers services such as broadband Internet access, e-mail, mailing lists, remote network access (dialup), personalized web portal and web hosting, content filtering, asynchronous distance learning, video on demand (VoD), teleconferencing, webcasting, electronic magazines, news, and discussion forums. The success of this effort encouraged other European countries to follow suite. Similarly, in the United States, ongoing state-level efforts to upgrade the school system IP infrastructure must include IPv6 deployment as well.
Hosting
Another very common service offering is Web hosting. In the early days of the Internet, this was simply the ISP agreeing to allow the customer to bring in some unspecified server and connect it to the ISP's backbone. This was an attractive service offering because the bandwidth needs from the content contained on the server were greater than the customer could afford to supply to its own premises or that the telco easily could provision. As the Internet has matured, whole businesses have been created dedicated to Web hosting indeed, the whole network design for such an organization is complex and detailed. For ISPs that simply are interested in hosting a few to a hundred or so servers for customers (the average middle of the road ISP), the following design tips are helpful. carefully consider what they are offering. Detailed design for a Web hosting network is not covered only the equipment placement is considered here.
URL Mangling
Note that in the previous example, the mangled URL reveals the internal web server address. Because the mangled URL will be displayed in a client browser window and recorded in the browser history file, it might be a security concern for people who don't want to leave the internal web infrastructure information on the client machines, which could be kiosk PCs. One way to resolve this concern is URL obfuscation, also known as URL masking.
Sslvpn
The greatest strength of SSL VPN comes from the fact that SSL is a mature protocol and is readily available in virtually all web browsers. Using SSL VPN, you can securely navigate your internal web server, or even check your e-mails, from a kiosk or Internet caf . You can customize the SSL VPN solution to meet any business requirement. This includes not only
Split Tunneling
After the tunnel is up, the default behavior of the Cisco AnyConnect VPN Client is to encrypt traffic destined to all the IP addresses. This means that if an SSL VPN user wants to browse to http www.cisco.com over the Internet, as illustrated in Figure 5-41, the packets will get encrypted and be sent to Cisco ASA. After decrypting them, the security appliance will look at its routing table and forward the packet to the appropriate next-hop IP address in clear text. These steps are reversed when traffic returns from the web server and is destined to the SSL VPN client.
NAT Firewalls
The hosts on the inside of the NAT firewall (192.168.1.1 and 192.168.1.2) are both trying to access the web server 10.100.100.44. Host 192.168.1.1 opens up TCP port 3844 and connects to the web server 10.100.100.44 at TCP port 80. Host 192.168.1.2 opens TCP port 4687 and connects to the web server 10.100.100.44 at TCP port 80. The NAT firewall is configured to translate the entire 192.168.1.0 24 network to the single IP address 172.28.230.55. When the firewall sees the outbound connections, it rewrites the IP layer information in the traffic and replaces 192.168.1.1 and 192.168.1.2 with the single IP address 172.28.230.55. Internally, the NAT firewall maintains a table that keeps track of the traffic flows and translates both 192.168.1.1 and 192.168.1.2 to the IP address 172.28.230.55. It does this by means of network sockets that uniquely identify a given connection. For the example shown in Figure 24, there are two unique sockets 192.168.1.1 3844 and 192.168.1.2 4687.
Content Rewriting
As a reverse proxy server, the SSL VPN gateway fetches web-based content from an internal web server and performs content rewriting. The main goal of the content rewriting is to change the URL references and Java socket calls so that all users' requests point to the SSL VPN gateway. Also, for Java rewriting, the SSL VPN gateway would need to re-sign with Java bytecode after the rewriting. This is a complicated and resource-intensive process. The content rewriter needs to be able to understand a wide range of complicated web-based objects, such as HTML, JavaScripts, java applets, ActiveX, Flash, and XML and to correctly locate and rewrite the URL references. The loose standard of HTML and web applications makes it more challenging for the content rewriter to properly parse poorly written web contents without breaking the applications. Use of high ports For an internal website that needs to be proxy bypassed, a nonstandard high port is assigned on the SSL VPN gateway.
More Products
| HostForFree Free Webhosting |













































