Lock-and-Key Security
To enable the router to create a temporary access list entry in a dynamic access list,
use the access-enable privileged EXEC command.
This command enables the lock-and-key access feature.
Always define either an idle timeout (with the timeout keyword in this command),
or an absolute timeout (with the timeout keyword in the access-list command).
Otherwise, the temporary access list entry will remain, even after the user terminates the session.
Use the autocommand command with the access-enable command to cause the access-enable
command to execute when a user opens a Telnet session into the router.
Example:
The following example causes the software to create a temporary access list entry and tells
the software to enable access only for the host from which the Telnet session originated.
If the access list entry is not accessed within 5 minutes, it is deleted:
Router#access-enable host timeout 5
Dynamic ACLs
Some of the many security benefits of Dynamic ACLs over standard and static extended ACLs are:
- The use of an authentication mechanism for individual users.
- Reduction of the opportunity for network break-ins by network hackers.
- In many cases, reduction of the amount of router processing that is required for ACLs.
- Simplified management in large internetworks.
- Creation of dynamic user access through a firewall, without compromising other configured security restrictions.
First configure the access-list on R2 for the Dynamic ACL
- access-list 101 permit tcp any any eq 23 (we need to allow telnet through so we can authenticate. Now we can get away without this line here since we have permit ip any any at the bottom of the ACL. This will all depend on how you have to build out the ACL if you need this or not.)
- access-list 101 dynamic HTTP permit tcp any any eq 80 (we could specify a specific host that is allowed access here or a subnet but we want to allow anyone that can authenticate for this example.)
- access-list 101 deny tcp any any eq 80 (Here we are blocking access to anyone that doesn’t authenticate for web traffic.)
- access-list 101 permit ip any any (Here we are allowing the rest of the incoming traffic in.)
We need to configure login access now. Usually I would authenticate everyone against my active directory, but we will just use local login for this.
- username r1 password cisco
Need to apply the access-list on the incoming interface.
- int s0/0
- ip access-group 101 in
Now we just need to configure the telnet lines
- line vty 0 4
- login local
- autocommand access-enable
Just need to telnet to r2 and authenticate and then we will have access to the
web server on the remote end.
This is what our access-list should look like once we have authenticated:
10 permit tcp any any eq telnet (183 matches)
20 Dynamic HTTP permit tcp any any eq www
permit tcp any any eq www (72 matches)
30 deny tcp any any eq www (9 matches)
40 permit ip any any
Notice the line statement under line 20. This is showing that the dynamic acl is active.
If you want to clear the access-list you need to use this command:
clear access-template [access-list-number | name] [dynamic-name] [source] [destination]
Host :
Tells the software to enable access only for the host from which the Telnet session originated.
If not specified, the software allows all hosts on the defined network to gain access.
The dynamic access list contains the network mask to use for enabling the new network.
Timeout :
Specifies an idle timeout for the temporary access list entry. If the access list entry is not accessed
within this period, it is automatically deleted and requires the user to authenticate again.
The default is for the entries to remain permanently.
The autocommand will look like this for the line vty :
autocommand access-enable host timeout 30
You can also add the timeout value within the dynamic Acl :
access-list 101 dynamic testlist timeout 120 permit ip any any
My Configuration in Place :
Create Local Authentication Group :
aaa authentication login local_auth local
!
Local Account Login of Privilege 0
(no ssh access for management, if able to login using credentials,
will be prompted for the enable secret password).
(This provides extra security measures).
username pass privilege 0 password 7 00141215170A5955
!
Create a Named Access-List with Dynamic ACL :
ip access-list extended LOCKnKEY
remark TELNET
permit tcp 192.168.3.0 0.0.0.7 host 192.168.3.1 eq telnet
remark DNS
permit udp 192.168.3.0 0.0.0.7 host 192.168.3.1 eq domain
remark DYNAMIC_ACL-HTTP
dynamic LOCKnKEY timeout 300 permit tcp 192.168.3.0 0.0.0.7 any eq www
remark HTTP
deny tcp 192.168.3.0 0.0.0.7 any eq www (Denies NON-Authenicate Users)
remark DENY_TRAFFIC
deny ip any any log
!
Bind To Internal LAN Interface :
interface Vlan 1
ip access-group LOCKnKEY in
!
Allow Telnet Only on Line VTY 0
(All Telnet Sessions Will Invoke the access-enable command)
line vty 0
exec-timeout 15 0
privilege level 15
(Need to be on Level 15 in order to invoke command access-enable host timeout 30)
login authentication local_auth
autocommand access-enable host timeout 30
transport preferred telnet
transport input telnet
!
Allow SSH on Line VTY 1-4 for Management Purposes :
line vty 1 4
exec-timeout 15 0
privilege level 0
login authentication local_auth
rotary 1
transport preferred ssh
transport input ssh
Comments
(There are currently no comments for this post.)