Networking-Blog

My WordPress Blog

Cisco ASA and ICMP Configurations

As I am sure many of you who have ever worked with a Cisco firewall know,
ICMP is not allowed through the firewall by default. If you are just configuring the device,
this can make it very difficult to troubleshoot connectivity issues.
Thankfully, there are several ways to get around this.

Solution 1: Use access-lists to allow pings from inside/DMZ to the outside.
To allow pinging from the inside to the outside interfaces, you will need to configure an access-list for the outside interface.

access-list OUTSIDE_IN_ACL permit icmp any any echo-reply

Then apply the access-list to the outside interface.

access-group OUTSIDE_IN_ACL in interface outside

This will allow only ping. If you would like to allow trace route, you will also need to allow time-exceeded.

access-list OUTSIDE_IN_ACL permit icmp any any time-exceeded

Solution 2: Use access-list to allow ping and trace route from the internet to your dmz/inside servers.
To do this, we are going to build off of what we did above, so you should already have this in the config.

access-list OUTSIDE_IN_ACL permit icmp any any echo-reply
access-list OUTSIDE_IN_ACL permit icmp any any time-exceeded
access-group OUTSIDE_IN_ACL in interface outside

Now all we need to do is allow echo into the network.

access-list OUTSIDE_IN_ACL permit icmp any any echo

Even though we are allowing icmp, we still need to have a static mapping to allow the packets to reach the DMZ.

static (dmz,outside) PUBLIC_IP DMZ_IP netmask 255.255.255.255

Of course, you will need to have a static mapping for every server you want to have reachable from the internet.

Solution 3: This is a bit more complex, but will allow higher security level interfaces to ping/trace route lower security level interfaces without the use of access-lists. To do this, we will tell the ASA to inspect icmp in a service policy. If you are using a ASA, you should have a default policy in the base config called global_policy.

global_policy:

class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns migrated_dns_map_1
parameters
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns migrated_dns_map_1
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
!
service-policy global_policy global
! 

To add icmp inspection.

FW-ASA(config)# policy-map global_policy
FW-ASA(config-pmap)# class inspection_default
FW-ASA(config-pmap-c)# inspect icmp

Cisco PIX Add VPN Policy

Create Phase 1 Policy :

isakmp policy 10 authentication pre-share
isakmp policy 10 encryption 3des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 3600

Create Transform-set for Encryption being used
:

crypto ipsec transform-set minimal esp-null esp-md5-hmac
crypto ipsec transform-set secure esp-3des esp-md5-hmac


Create a nonat access-list
:

access-list nonat permit ip 172.31.0.0 255.255.0.0 192.168.0.0 255.255.0.0

Create Access-list for allowed network Source & Destination :

access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.178.0 255.255.255.0


Create Crypto Map :

crypto map armadillo 880 ipsec-isakmp
crypto map armadillo 880 match address 880
crypto map armadillo 880 set peer 2.2.2.2
crypto map armadillo 880 set transform-set secure

Create a Preshared-Key :

isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255


Assign Crypto Map to Interface
:

crypto map armadillo interface outside
isakmp enable outside

Allow IPSEC traffic into Pix from public facing interface :

sysopt connection permit-ipsec

Summarize rule for each additional vpn to be added :

access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.178.0 255.255.255.0

crypto map armadillo 880 ipsec-isakmp
crypto map armadillo 880 match address 880
crypto map armadillo 880 set peer 2.2.2.2
crypto map armadillo 880 set transform-set secure
isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255

To remove a VPN addittional policy :

no access-list nonat permit ip 172.31.0.0 255.255.0.0
192.168.0.0 255.255.0.0
!
no access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.166.0 255.255.255.0
!
no crypto map armadillo 880
!
no isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255

Cisco Wireless 857w Configuration

Cisco 857w allows only 1 broadcast configurable SSID.

See the exact configuration set out below :

Keep in mind this is what is needed for the wireless part of the configuration and inside
NAT statement via Route-Maps is not included
.


dot11 ssid COMMS
authentication open
authentication key-management wpa
guest-mode
wpa-psk ascii 0 test

interface Dot11Radio0
no ip address
!
encryption mode ciphers tkip
!
ssid test
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
world-mode dot11d country GB outdoor

!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no cdp enable
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding

!
interface Vlan1
description Bind_to_BVI1_Interface
no ip address
bridge-group 1
bridge-group 1 spanning-disabled

!
!
interface BVI1
description $ES_LAN$
ip address 192.168.194.1 255.255.255.0
ip nat inside
ip virtual-reassembly

!
ip dns server
ip nat inside source route-map NAT interface Dialer0 overload
!

route-map NAT permit 10
match ip address name NAT_ACL
!
ip access-list extended NAT_ACL
permit ip 192.168.194.0.0 0.0.0.255 any

!
bridge 1 protocol ieee
bridge 1 route ip

Linux PPTP Create Routing Script

To make sure our traffic gets routed to the other end of the tunnel, create a file called ip-up in /etc/ppp and add the following lines to this file:

#!/bin/sh
/sbin/route add -net REMOTE-NET-IP netmask REMOTE-NET-MASK dev ppp

eg :
route add -net 10.20.254.248 netmask 255.255.255.248 dev ppp0

In which you have to replace the IP-address and the mask with those of the subnet on the other end of the tunnel. If there is no network on the other side, but just the pptp server, you can use -host instead of -net. When your done, save the file and make it executable:

chmod +x /etc/ppp/ip-up

Now that all is set up we can start the tunnel:

Simplify Linux PPTP Server Configuration

yum install pptpd
apt-get pptpd

At this point, you should have a working pptp daemon.
This is a matter of personal preference, but I like to go ahead and start pptpd just to
make sure that the service is functioning and that it opens up the

PPTP port (1723) on the machine:

[user@hostname ~]# /etc/init.d/pptpd start
Starting pptpd:                                            [  OK  ]
!
[user@hostname ~]# telnet localhost 1723
Trying 127.0.0.1…
Connected to localhost.
Escape character is ‘^]’.

3 configuration files we need to worrry about.  They are :

/etc/pptpd.conf
/etc/ppp/options.pptpd

/etc/sysctl.conf

!

Let’s start with /etc/pptpd.conf

edit file :
nano /etc/pptpd.conf

# Currently using Microsoft Client Profile:
option /etc/ppp/MSpptpd-options

# Use linux client profile:
#option /etc/ppp/LXpptpd-options

#       Turns on (more) debugging to syslog
#debug
logwtmp
speed 57600

# Specifies the local and remote IP address ranges.
localip 10.20.254.254
# listen 10.20.254.254
# remoteip 10.10.10.249-253

!

Now, on to /etc/ppp/options.pptpd

As stated previously, options.pptpd is concered with how the VPN will authenticate
and encrypt.  Below are the options that you actually care about
:

name pptpd
require-mschap-v2
require-mppe-128
ms-dns 192.168.1.73
lock
nobsdcomp
auth
require-mppe
noipx ## you don’t need IPX
mtu 1490 ## may help your linux client from disconnecting
mru 1490
## may help your linux client from disconnecting

!

Lastly, /etc/sysctl.conf :

Edit this file and make sure the net.ipv4.ip_forward is set to 1.
This enables ip packet forwarding on the LAN which is required if you expect your
VPN users to be able to access any other resources on the network besides the
VPN server itself.

net.ipv4.ip_forward = 1

Setting up Users :

The chap-secrets file in the /etc/ppp/ directory.
vi /etc/ppp/chap-secrets

# client        server secret           IP addresses
rich              pptpd         apassword     80.40.0.0/13
geoff             pptpd         apassword     212.219.0.0/14

Test and Troubleshoot
:

/etc/init.d/pptpd stop
/etc/init.d/pptpd start

Sumarize Firewall Rules :

1. Allow GRE-47/pptp-1723 on internet facing router.
2. Configure a port forward for pptp-1723 to internal lan server ip address.
3. Allow GRE traffic out from pptp server.
4. Allow pptp tcp port 1723 out from pptp server with a source nat of 1723 to remote host or any
.