Resulting Basic Firewall ACL Configuration
|
Router#show |
running-config | include access-list |
|||
|
access |
-list |
100 |
remark |
autogenerated by SDM firewall configuration |
|
access |
-list |
100 |
remark |
SDM ACL Category=1 |
|
access |
-list |
100 |
deny |
ip 200.0.0.0 0.0.0.3 any |
|
access |
-list |
100 |
deny |
ip host 255.255.255.255 any |
|
access |
-list |
100 |
deny |
ip 127.0.0.0 0.255.255.255 any |
|
access |
-list |
100 |
permit |
ip any any |
|
access |
-list |
101 |
remark |
autogenerated by SDM firewall configuration |
|
access |
-list |
101 |
remark |
SDM_ACL Category=1 |
|
access |
-list |
101 |
deny |
ip 10.1.1.0 0.0.0.255 any |
|
access |
-list |
101 |
permit |
icmp any host 200.0.0.1 echo-reply |
|
access |
-list |
101 |
permit |
icmp any host 200.0.0.1 time-exceeded |
|
access |
-list |
101 |
permit |
icmp any host 200.0.0.1 unreachable |
|
access |
-list |
101 |
deny |
ip 10.0.0.0 0.255.255.255 any |
|
access |
-list |
101 |
deny |
ip 172.16.0.0 0.15.255.255 any |
|
access |
-list |
101 |
deny |
ip 192.168.0.0 0.0.255.255 any |
|
access |
-list |
101 |
deny |
ip 127.0.0.0 0.255.255.255 any |
|
access |
-list |
101 |
deny |
ip host 255.255.255.255 any |
|
access |
-list |
101 |
deny |
ip host 0.0.0.0 any |
|
access |
-list |
101 |
deny |
ip any any log |
The resulting ACLs filter the traffic in this way:
■ ACL 100 will be applied inbound to the inside interface. It prevents spoofing by denying packets sourced from 200.0.0.0/30 network, which is configured on the outside interface. The ACL also blocks packets sourced from the broadcast address and the 127.0.0.0/8 network and permits all other traffic.
■ ACL 101 will be applied in inbound direction to the outside interface. The ACL permits ICMP echo-reply, time-exceeded, and unreachable messages destined to the outside router interface (200.0.0.1), and blocks packets sourced from private address ranges, the broadcast, and the 0.0.0.0 address. The final entry denies and logs all other packets.
6-56 Implementing Secure Converged Wide Area Networks (ISCW) v1.0 © 2006 Cisco Systems, Inc.
Finally, the Basic Firewall Configuration wizard applies the configured ACLs and inspection rules to the router interfaces.
Note SDM applies the inspection rule to the outside interface in outbound direction although it was previously stated that applying inspection rules in inbound direction provides the most clarity. That recommendation is especially valid in environments with many interfaces and multiple flows. The SDM Basic and Advanced Firewall wizards operate in relatively simple environments, so that recommendation is not followed.
In addition to the ACLs and inspection rules applied to the respective interfaces, unicast reverse path forwarding is enabled on the outside interface.
Note In an Internet environment, the functionality of the unicast reverse path forwarding depends on the existence of a default route (0.0.0.0 0.0.0.0). If there is no default route, and a packet comes in from an unmatched IP address, it will be dropped by the unicast reverse path forwarding feature.
© 2006 Cisco Systems, Inc. Cisco IOS Threat Defense Features 6-57
Continue reading here: NIDS and NIPS Deployment
Was this article helpful?