Transit Filtering at Your Edge

tacl.gif
The edge routers should be configured to provide a first level of security through the use of
inbound ACLs. The ACLs allow only specifically permitted traffic to the DMZ and allow
return traffic for internal users accessing the Internet. All non authorized traffic should be
dropped on the ingress interfaces
.

 

This document presents guidelines and recommended deployment techniques for filtering transit
and edge traffic at your network ingress points. Transit access control lists (ACLs) are used to
increase network security by explicitly permitting only required traffic into your network or networks.

In most edge network environments, such as a typical enterprise network Internet point of presence,
ingress filtering should be used to drop unauthorised traffic at the edge of the network. In certain service
provider deployments, this form of edge or transit traffic filtering can also be used effectively to limit the
flow of transit traffic to and from customers to specific permitted protocols only.

This example depicts a typical enterprise Internet connectivity design. Two edge routers, IR1 and IR2,
provide direct connectivity to the Internet. Behind these two routers, a pair of firewalls
(Cisco PIXes in this example) provides stateful inspection capabilities and access to both the internal
network and the demilitarised zone (DMZ). The DMZ contains public-facing services such as
DNS and web; this is the only network accessible directly from the public Internet.
The internal network should never be accessed directly by the Internet, but traffic sourced from the
internal network must be able to reach Internet sites.

ACL Example

This access list provides a simple yet realistic example of typical entries required in a transit ACL.
This basic ACL needs to be customized with local site-specific configuration details.

!— Add anti-spoofing entries.
!— Deny special-use address sources.
!— Refer to RFC 3330 for additional special use addresses.

access-list 110 deny ip 127.0.0.0 0.255.255.255 any
access-list 110 deny ip 192.0.2.0 0.0.0.255 any
access-list 110 deny ip 224.0.0.0 31.255.255.255 any
access-list 110 deny ip host 255.255.255.255 any

!— The deny statement should not be configured
!— on Dynamic Host Configuration Protocol (DHCP) relays.

access-list 110 deny ip host 0.0.0.0 any

!— Filter RFC 1918 space.

access-list 110 deny ip 10.0.0.0 0.255.255.255 any
access-list 110 deny ip 172.16.0.0 0.15.255.255 any
access-list 110 deny ip 192.168.0.0 0.0.255.255 a
ny

!— Permit Border Gateway Protocol (BGP) to the edge router.

access-list 110 permit tcp host bgp_peer gt 1023 host router_ip eq bgp
access-list 110 permit tcp host
bgp_peer eq bgp host router_ip gt 1023

!— Deny your space as source (as noted in RFC 2827).

access-list 110 deny ip your Internet-routable subnet any

!— Explicitly permit return traffic.
!— Allow specific ICMP types.

access-list 110 permit icmp any any echo-reply
access-list 110 permit icmp any any unreachable
access-list 110 permit icmp any any time-exceeded
access-list 110 deny   icmp any a
ny

!— These are outgoing DNS queries.

access-list 110 permit udp any eq 53  host primary DNS server gt 1023

!— Permit older DNS queries and replies to primary DNS server.

access-list 110 permit udp any eq 53  host primary DNS server eq 53

!— Permit legitimate business traffic.

access-list 110 permit tcp any Internet-routable subnet established
access-list 110 permit udp any range 1 1023
Internet-routable subnet gt 1023

!— Allow ftp data connections.

access-list 110 permit tcp any eq 20 Internet-routable subnet gt 1023

!— Allow tftp data and multimedia connections.

access-list 110 permit udp any gt 1023 Internet-routable subnet gt 1023

!— Explicitly permit externally sourced traffic.
!— These are incoming DNS queries.

access-list 110 permit udp any gt 1023 host <primary DNS server> eq 53

!– These are zone transfer DNS queries to primary DNS server.

access-list 110 permit tcp host secondary DNS server gt 1023 host primary DNS server eq 53

!— Permit older DNS zone transfers.

access-list 110 permit tcp host secondary DNS server eq 53  host primary DNS server eq 53

!— Deny all other DNS traffic.

access-list 110 deny udp any any eq 53
access-list 110 deny tcp any any eq 53

!— Allow IPSec VPN traffic.

access-list 110 permit udp any host IPSec headend device eq 500
access-list 110 permit udp any host
IPSec headend device eq 4500
access-list 110 permit 50 any host
IPSec headend device
access-list 110 permit 51 any host
IPSec headend device
access-list 110 deny   ip any host
IPSec headend device

!— These are Internet-sourced connections to
!— publicly accessible servers.

access-list 110 permit tcp any host public web server eq 80
access-list 110 permit tcp any host
public web server eq 443
access-list 110 permit tcp any host
public FTP server eq 21

!— Data connections to the FTP server are allowed
!— by the permit established ACE.
!— Allow PASV data connections to the FTP server.

access-list 110 permit tcp any gt 1023 host public FTP server gt 1023
access-list 110 permit tcp any host
public SMTP server eq 25

!— Explicitly deny all other traffic.

access-list 101 deny ip any any

Note: Please keep these suggestions in mind when you apply the transit ACL.