An Engineer by Heart !!! A Dreamer, A Pioneer, A Blogger. A Network Engineer Trying to overtake the world with his network engineering skills :) Opinions expressed here are solely my own and do not express the views or opinions of my Present or Past employer.
Showing posts with label ASA. Show all posts
Showing posts with label ASA. Show all posts
Sunday, April 1, 2012
Tuesday, December 20, 2011
How Well Do You Understand Traceroute
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml
BTW... Traceroute is a application not an protocol in itself :-)
HTH...
Deepak Arora
Evil CCIEWednesday, September 30, 2009
How Many Types of ACLs are there in Cisco's Big IOS Security World....Continued
I thought to add some more IOS Security features in my previous list...might not be an exact ACL feature but in some way sometimes relies heavily on ACL.
1. ACL using Group-Objects...YES...now can use group objects to minimize number of ACLs like we do in ASA :-) isn't that cool enough...those old days are gone now. Thanks to some great programmers sitting out there in Cisco.
ACL group object feature came I guess in IOS 12.4(20T). It allows you to configure two types of group object.
* Network Objects
* Service Objects
And guess what...one more surprise with this feature is now we can use / notation with our IP addresses in Network Objects Group like 1.1.1.1/1...isn't that cool
Anyways...I'll demonstrate this feature in my next post and till the time I'll try to find out IOS for it.
2.) TCP Intercept - Another Cool IOS security feature
3.) URPF - Sometimes it also has to rely on ACLs...depending upon it's configuration mode
4.) NBAR - Cool QOS based Security Feature
5.) CAR -Of Course it not four wheeler CAR but CAR is acronym for Committed Access Rate and can be used as a security feature.
6.) IOS based IPS
7.) 802.1x
8.) CoPP - Control Plane Policing
9.) Setting up privilege level / Menu based Access For Users
10.) Setting Up Connection Limits - Defining Max number of TCP/UDP/ICMP packets from Single host
under defined time value, Max number of Half TCP sessions from
anyone under defined time value
I am sure there would be some other features as well along with some protocol specific features like RTBHF and Sink hole filtering...Those are more or less CCIE Security Topics anyways :-)
Happy Studying & Stay Tuned....
Best Regards,
Deepak Arora
CCIE#XXXXX...Oops that number is still missing
1. ACL using Group-Objects...YES...now can use group objects to minimize number of ACLs like we do in ASA :-) isn't that cool enough...those old days are gone now. Thanks to some great programmers sitting out there in Cisco.
ACL group object feature came I guess in IOS 12.4(20T). It allows you to configure two types of group object.
* Network Objects
* Service Objects
And guess what...one more surprise with this feature is now we can use / notation with our IP addresses in Network Objects Group like 1.1.1.1/1...isn't that cool
Anyways...I'll demonstrate this feature in my next post and till the time I'll try to find out IOS for it.
2.) TCP Intercept - Another Cool IOS security feature
3.) URPF - Sometimes it also has to rely on ACLs...depending upon it's configuration mode
4.) NBAR - Cool QOS based Security Feature
5.) CAR -Of Course it not four wheeler CAR but CAR is acronym for Committed Access Rate and can be used as a security feature.
6.) IOS based IPS
7.) 802.1x
8.) CoPP - Control Plane Policing
9.) Setting up privilege level / Menu based Access For Users
10.) Setting Up Connection Limits - Defining Max number of TCP/UDP/ICMP packets from Single host
under defined time value, Max number of Half TCP sessions from
anyone under defined time value
I am sure there would be some other features as well along with some protocol specific features like RTBHF and Sink hole filtering...Those are more or less CCIE Security Topics anyways :-)
Happy Studying & Stay Tuned....
Best Regards,
Deepak Arora
CCIE#XXXXX...Oops that number is still missing
Tuesday, September 29, 2009
How Many Types of ACLs are there in Cisco's Big IOS Security World
Few days back I asked a question to a very confident CCNA Security guy...actually he just came to me before taking CCNA Security exam and asked me...hey,why don't you ask me something related to Security as I am feeling pretty confident that I know lots of security stuff now.
Hmmm...I said Okey and just asked him the following question :-)
How many ACLs and Firewall features we have in IOS related to Router Security ?
He said... Standard ACL, Extended ACL, Named ACL, Reflexive ACL, CBAC & Zone Based Firewall.
Hmmm...his list looks interesting but still not complete...maybe it was not a true CCNA Security Question as I never take a look at it's curriculum...Anyways...Following is my list and see if I missed something...Feel free to drop an email to me if you have something to add in this list.
1. Standard ACL
2. Extended ACL
3. Named ACL
4. TCP Established ACL / Reflexive ACL
5. Turbo ACL
6. CBAC
7. Zone Based Firewall
8. Time Based ACL
9. Dynamic ACL / Lock & Key ACL
10. Flexibal Packet Matching ACL
11. ACL to to prevent fragmented IP packets from reaching you application ports
Holy Cow...Did you ever think about that :-(
I must say even I still need to dig myself about which one takes precedence over other when multiple types are configured together
Some more ACL stuff in coming days along with solution of my last ACL Post...
Happy Studying...
Best Regards,
Deepak Arora
CCIE# XXXXX...Oops that number is still missing :-)
Hmmm...I said Okey and just asked him the following question :-)
How many ACLs and Firewall features we have in IOS related to Router Security ?
He said... Standard ACL, Extended ACL, Named ACL, Reflexive ACL, CBAC & Zone Based Firewall.
Hmmm...his list looks interesting but still not complete...maybe it was not a true CCNA Security Question as I never take a look at it's curriculum...Anyways...Following is my list and see if I missed something...Feel free to drop an email to me if you have something to add in this list.
1. Standard ACL
2. Extended ACL
3. Named ACL
4. TCP Established ACL / Reflexive ACL
5. Turbo ACL
6. CBAC
7. Zone Based Firewall
8. Time Based ACL
9. Dynamic ACL / Lock & Key ACL
10. Flexibal Packet Matching ACL
11. ACL to to prevent fragmented IP packets from reaching you application ports
Holy Cow...Did you ever think about that :-(
I must say even I still need to dig myself about which one takes precedence over other when multiple types are configured together
Some more ACL stuff in coming days along with solution of my last ACL Post...
Happy Studying...
Best Regards,
Deepak Arora
CCIE# XXXXX...Oops that number is still missing :-)
Friday, September 25, 2009
Filtering ALL Even Subnets With Single ACL
These days I am quite busy with my job schedule which is keeping me away from studies & blog.
Anyways... today lets play around some ACLs. I know many people who think that they know ACL stuff very well. But actually that's not the case. Specially if they were been given task like I show up in Diagram here. The challenge here is following:
R2 has got plenty of networks to advertise using EIGRP to R1. Administrator f R1 wants that only Odd Network Subnets like 192.168.1.0/24...3.0/24 etc of R2 should be able to reach LAN segment of R1 and all Even subnets should not be able to do that. And for that you are only allowed to use single ACL entry....but also don't use Group Objects ( If you know really what they are :-) )
So good luck to all of you * R1 Admins :-) * I will post the solution and some more ACL details soon.
Happy Studying...
Regards,
Deepak Arora
Anyways... today lets play around some ACLs. I know many people who think that they know ACL stuff very well. But actually that's not the case. Specially if they were been given task like I show up in Diagram here. The challenge here is following:
R2 has got plenty of networks to advertise using EIGRP to R1. Administrator f R1 wants that only Odd Network Subnets like 192.168.1.0/24...3.0/24 etc of R2 should be able to reach LAN segment of R1 and all Even subnets should not be able to do that. And for that you are only allowed to use single ACL entry....but also don't use Group Objects ( If you know really what they are :-) )
So good luck to all of you * R1 Admins :-) * I will post the solution and some more ACL details soon.
Happy Studying...
Regards,
Deepak Arora
Tuesday, July 14, 2009
Fixing ASDM Error - Unconnected Sockets Not Implemented
Yesterday when I tried to access my ASA 5520 box using ASDM, I got an error " Unconnected Sockets Not Implemented". Initially I thought It could be because of some ASDM access permission configured on ASA. But everything was fine with the configuration. I spent quite some time but didn't find any clue about how to fix this issue and what could be the possible cause.
Finally I downgraded my Java version because I knew that ASDM uses JRE and recently I upgraded my JRE. So after making downgrade I was able to access the ASDM. It seems like some JRE versions are not compatible with Latest ASDM version 6.x
Regards,
Deepak Arora
Friday, May 15, 2009
ASA Order of Operation
This is the complete ASA Order of Operation in Routed Mode:
- Virtual Firewall Classification
- Layer 2 validation
- Layer 3 validation
- IP packet security checks
- Fragmented IP traffic handling
- INPUT L2 ACL - Unlike L3/4 ACL, L2 ACL is per packet
- Packet capture
- Flow look-up - If Fails, Continue; If Success, jump to Input QoS
- Additional packet security checks
- NAT untranslate
- RPF Checks
- Input Route lookup
- Addtional packet security checks (thru the box only)
- Crypto checks
- ACL Check
- WCCP Redirection
- TCP Intercept
- IP Options permit check
- Validate IPSec SPI
- Flow Creation
- Global Classification
- Input QOS
- IPSec Tunnel Procesing
- TCP Intercept Processing
- TCP Security Engine
- IP Option Processing
- NP Inspect Engine Processing (ICMP/DNS/RTP/RTCP)
- DNS Guard
- Pinhole Processing
- Multicast processing
- CSC Module Processing (optional)
- Inspection Engine Processing/AAA punts/IPsec over TCP punts
- IPSec NAT-T Processing
- Decrypt
- Address Update and Checksum Adjustments
- TCP Security Engine
- IPS - AIP Module processing (optional)
- Adjacency Look-up if necessary
- Output QOS
- Encrypt
- Fragment
- Output Capture
- Output L2 ACL
- Queue processing and Transmit
ASA & PIX Quick Learning Modules
I know many of the people including me are still looking for some nice ASA tutorials. So here they are...
http://www.cisco.com/E-Learning/bulk/public/celc/Cisco_QLM10_ASA_beta/course_skin.html
Best Regards,
Deepak Arora
http://www.cisco.com/E-Learning/bulk/public/celc/Cisco_QLM10_ASA_beta/course_skin.html
Best Regards,
Deepak Arora
Wednesday, January 28, 2009
Traffic processing in Cisco Firewall
I see many people confused about this mainly when does the SSM module’s analysis engine sees the traffic.
; FYI here is complete flow starting with Receive Packets till the Transmit Packets as per my knowledge goes...
1. Receive Packet
2. Ingress Interface (ASA)
3. Existing Conn? (if yes, skip to #6, else go to #4)
4. ACL Permit (if no, drop, else if yes go to #5)
5. Match Xlate (if no, drop, else if yes, go to #6)
6. Inspections and Protocol Checks
7. NAT IP Header
8. IPS SSM Module
9. Egress Interface (ASA)
10. L3 Route (if no route, drop, else go to #11)
11. L2 Addr (if no address, drop, else go to #12)
12. Transmit Packet
; FYI here is complete flow starting with Receive Packets till the Transmit Packets as per my knowledge goes...
1. Receive Packet
2. Ingress Interface (ASA)
3. Existing Conn? (if yes, skip to #6, else go to #4)
4. ACL Permit (if no, drop, else if yes go to #5)
5. Match Xlate (if no, drop, else if yes, go to #6)
6. Inspections and Protocol Checks
7. NAT IP Header
8. IPS SSM Module
9. Egress Interface (ASA)
10. L3 Route (if no route, drop, else go to #11)
11. L2 Addr (if no address, drop, else go to #12)
12. Transmit Packet
Best Regards,
Deepak Arora
Cisco ASA - NAT Order of Operations
Someone shared this NAT order of operations flow and I thought it would be good info to put out on the site in case someone needed it. Here it is
1. nat 0 access-list (nat-exempt)
2. match against existing xlates
3. static
static nat with and without access-list (first match)
static pat with and without access-list (first match)
4. nat
a) nat access-list (first match)
Note: nat 0 access-list is not part of this command.
b) nat (best match) Note: When choosing a global address from multiple pools withthe same nat
id, the following order is tried
i) if the id is 0, create an identity xlate.
ii) use the global pool for dynamic NAT
iii) use the global pool for dynamic PAT
5. Error
Best Regards,
Deepak Arora
1. nat 0 access-list (nat-exempt)
2. match against existing xlates
3. static
static nat with and without access-list (first match)
static pat with and without access-list (first match)
4. nat
a) nat access-list (first match)
Note: nat 0 access-list is not part of this command.
b) nat (best match) Note: When choosing a global address from multiple pools withthe same nat
id, the following order is tried
i) if the id is 0, create an identity xlate.
ii) use the global pool for dynamic NAT
iii) use the global pool for dynamic PAT
5. Error
Best Regards,
Deepak Arora
Subscribe to:
Posts (Atom)

