Resulting Basic Firewall ACL Configuration

Router#show

running-config | include access-list

access

-list

100

remark

autogenerated by SDM firewall configuration

access

-list

100

remark

SDM ACL Category=1

access

-list

100

deny

ip 200.0.0.0 0.0.0.3 any

access

-list

100

deny

ip host 255.255.255.255 any

access

-list

100

deny

ip 127.0.0.0 0.255.255.255 any

access

-list

100

permit

ip any any

access

-list

101

remark

autogenerated by SDM firewall configuration

access

-list

101

remark

SDM_ACL Category=1

access

-list

101

deny

ip 10.1.1.0 0.0.0.255 any

access

-list

101

permit

icmp any host 200.0.0.1 echo-reply

access

-list

101

permit

icmp any host 200.0.0.1 time-exceeded

access

-list

101

permit

icmp any host 200.0.0.1 unreachable

access

-list

101

deny

ip 10.0.0.0 0.255.255.255 any

access

-list

101

deny

ip 172.16.0.0 0.15.255.255 any

access

-list

101

deny

ip 192.168.0.0 0.0.255.255 any

access

-list

101

deny

ip 127.0.0.0 0.255.255.255 any

access

-list

101

deny

ip host 255.255.255.255 any

access

-list

101

deny

ip host 0.0.0.0 any

access

-list

101

deny

ip any any log

The resulting ACLs filter the traffic in this way:

■ ACL 100 will be applied inbound to the inside interface. It prevents spoofing by denying packets sourced from 200.0.0.0/30 network, which is configured on the outside interface. The ACL also blocks packets sourced from the broadcast address and the 127.0.0.0/8 network and permits all other traffic.

■ ACL 101 will be applied in inbound direction to the outside interface. The ACL permits ICMP echo-reply, time-exceeded, and unreachable messages destined to the outside router interface (200.0.0.1), and blocks packets sourced from private address ranges, the broadcast, and the 0.0.0.0 address. The final entry denies and logs all other packets.

6-56 Implementing Secure Converged Wide Area Networks (ISCW) v1.0 © 2006 Cisco Systems, Inc.

Finally, the Basic Firewall Configuration wizard applies the configured ACLs and inspection rules to the router interfaces.

Firewall Acl

Note SDM applies the inspection rule to the outside interface in outbound direction although it was previously stated that applying inspection rules in inbound direction provides the most clarity. That recommendation is especially valid in environments with many interfaces and multiple flows. The SDM Basic and Advanced Firewall wizards operate in relatively simple environments, so that recommendation is not followed.

In addition to the ACLs and inspection rules applied to the respective interfaces, unicast reverse path forwarding is enabled on the outside interface.

Note In an Internet environment, the functionality of the unicast reverse path forwarding depends on the existence of a default route (0.0.0.0 0.0.0.0). If there is no default route, and a packet comes in from an unmatched IP address, it will be dropped by the unicast reverse path forwarding feature.

© 2006 Cisco Systems, Inc. Cisco IOS Threat Defense Features 6-57

Continue reading here: NIDS and NIPS Deployment

Was this article helpful?

0 0