Networking-Blog

My WordPress Blog

Cisco ASA Port-Forward

PIX/ASA 7.x and above: Mail (SMTP) Server Access on the DMZ Configuration Example

!— This access list allows hosts to access !— IP address 192.168.200.227 for the !— Simple Mail Transfer Protocol (SMTP) port.

access-list outside_int extended permit tcp any host 192.168.200.227 eq smtp

!— Allows outgoing SMTP connections. !— This access list allows host IP 172.16.31.10 !— sourcing the SMTP port to access any host.

access-list dmz_int extended permit tcp host 172.16.31.10 any eq smtp

!— This network static does not use address translation. !— Inside hosts appear on the DMZ with their own addresses.

static (inside,dmz) 10.1.1.0 10.1.1.0 netmask 255.255.255.0

!— This network static uses address translation. !— Hosts accessing the mail server from the outside !— use the 192.168.200.227 address.

static (dmz,outside) 192.168.200.227 172.16.31.10 netmask 255.255.255.255

access-group outside_int in interface outside
access-group dmz_int in interface dmz

!— The inspect esmtp command (included in the map) allows !— SMTP/ESMTP to inspect the application.

policy-map global_policy
class inspection_default
inspect dns maximum-length 512
inspect ftp
inspect h323 h225
inspect h323 ras
inspect netbios
inspect rsh
inspect rtsp
inspect skinny
inspect esmtp
inspect sqlnet
inspect sunrpc
inspect tftp
inspect sip
inspect xdmcp

Linux Show Version installed

linux version installed on a different servers.

uname -a
or
/proc/version

When we telnet to any of the Linux server  or machine’s,
the version shows very clearly like :

Red Hat Enterprise Linux ES release 3 (Taroon Update 6)
Kernel 2.4.21-37.ELsmp on an i686

!
On Linux Ubuntu :

Linux mediapc 2.6.32-26-generic #48-Ubuntu SMP Wed
Nov 24 09:00:03 UTC 2010 i686 GNU/Linux

Cisco ASA and ICMP Configurations

As I am sure many of you who have ever worked with a Cisco firewall know,
ICMP is not allowed through the firewall by default. If you are just configuring the device,
this can make it very difficult to troubleshoot connectivity issues.
Thankfully, there are several ways to get around this.

Solution 1: Use access-lists to allow pings from inside/DMZ to the outside.
To allow pinging from the inside to the outside interfaces, you will need to configure an access-list for the outside interface.

access-list OUTSIDE_IN_ACL permit icmp any any echo-reply

Then apply the access-list to the outside interface.

access-group OUTSIDE_IN_ACL in interface outside

This will allow only ping. If you would like to allow trace route, you will also need to allow time-exceeded.

access-list OUTSIDE_IN_ACL permit icmp any any time-exceeded

Solution 2: Use access-list to allow ping and trace route from the internet to your dmz/inside servers.
To do this, we are going to build off of what we did above, so you should already have this in the config.

access-list OUTSIDE_IN_ACL permit icmp any any echo-reply
access-list OUTSIDE_IN_ACL permit icmp any any time-exceeded
access-group OUTSIDE_IN_ACL in interface outside

Now all we need to do is allow echo into the network.

access-list OUTSIDE_IN_ACL permit icmp any any echo

Even though we are allowing icmp, we still need to have a static mapping to allow the packets to reach the DMZ.

static (dmz,outside) PUBLIC_IP DMZ_IP netmask 255.255.255.255

Of course, you will need to have a static mapping for every server you want to have reachable from the internet.

Solution 3: This is a bit more complex, but will allow higher security level interfaces to ping/trace route lower security level interfaces without the use of access-lists. To do this, we will tell the ASA to inspect icmp in a service policy. If you are using a ASA, you should have a default policy in the base config called global_policy.

global_policy:

class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns migrated_dns_map_1
parameters
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns migrated_dns_map_1
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
!
service-policy global_policy global
! 

To add icmp inspection.

FW-ASA(config)# policy-map global_policy
FW-ASA(config-pmap)# class inspection_default
FW-ASA(config-pmap-c)# inspect icmp

Cisco PIX Add VPN Policy

Create Phase 1 Policy :

isakmp policy 10 authentication pre-share
isakmp policy 10 encryption 3des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 3600

Create Transform-set for Encryption being used
:

crypto ipsec transform-set minimal esp-null esp-md5-hmac
crypto ipsec transform-set secure esp-3des esp-md5-hmac


Create a nonat access-list
:

access-list nonat permit ip 172.31.0.0 255.255.0.0 192.168.0.0 255.255.0.0

Create Access-list for allowed network Source & Destination :

access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.178.0 255.255.255.0


Create Crypto Map :

crypto map armadillo 880 ipsec-isakmp
crypto map armadillo 880 match address 880
crypto map armadillo 880 set peer 2.2.2.2
crypto map armadillo 880 set transform-set secure

Create a Preshared-Key :

isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255


Assign Crypto Map to Interface
:

crypto map armadillo interface outside
isakmp enable outside

Allow IPSEC traffic into Pix from public facing interface :

sysopt connection permit-ipsec

Summarize rule for each additional vpn to be added :

access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.178.0 255.255.255.0

crypto map armadillo 880 ipsec-isakmp
crypto map armadillo 880 match address 880
crypto map armadillo 880 set peer 2.2.2.2
crypto map armadillo 880 set transform-set secure
isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255

To remove a VPN addittional policy :

no access-list nonat permit ip 172.31.0.0 255.255.0.0
192.168.0.0 255.255.0.0
!
no access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.166.0 255.255.255.0
!
no crypto map armadillo 880
!
no isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255

Cisco Wireless 857w Configuration

Cisco 857w allows only 1 broadcast configurable SSID.

See the exact configuration set out below :

Keep in mind this is what is needed for the wireless part of the configuration and inside
NAT statement via Route-Maps is not included
.


dot11 ssid COMMS
authentication open
authentication key-management wpa
guest-mode
wpa-psk ascii 0 test

interface Dot11Radio0
no ip address
!
encryption mode ciphers tkip
!
ssid test
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
world-mode dot11d country GB outdoor

!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no cdp enable
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding

!
interface Vlan1
description Bind_to_BVI1_Interface
no ip address
bridge-group 1
bridge-group 1 spanning-disabled

!
!
interface BVI1
description $ES_LAN$
ip address 192.168.194.1 255.255.255.0
ip nat inside
ip virtual-reassembly

!
ip dns server
ip nat inside source route-map NAT interface Dialer0 overload
!

route-map NAT permit 10
match ip address name NAT_ACL
!
ip access-list extended NAT_ACL
permit ip 192.168.194.0.0 0.0.0.255 any

!
bridge 1 protocol ieee
bridge 1 route ip

Linux PPTP Create Routing Script

To make sure our traffic gets routed to the other end of the tunnel, create a file called ip-up in /etc/ppp and add the following lines to this file:

#!/bin/sh
/sbin/route add -net REMOTE-NET-IP netmask REMOTE-NET-MASK dev ppp

eg :
route add -net 10.20.254.248 netmask 255.255.255.248 dev ppp0

In which you have to replace the IP-address and the mask with those of the subnet on the other end of the tunnel. If there is no network on the other side, but just the pptp server, you can use -host instead of -net. When your done, save the file and make it executable:

chmod +x /etc/ppp/ip-up

Now that all is set up we can start the tunnel:

Simplify Linux PPTP Server Configuration

yum install pptpd
apt-get pptpd

At this point, you should have a working pptp daemon.
This is a matter of personal preference, but I like to go ahead and start pptpd just to
make sure that the service is functioning and that it opens up the

PPTP port (1723) on the machine:

[user@hostname ~]# /etc/init.d/pptpd start
Starting pptpd:                                            [  OK  ]
!
[user@hostname ~]# telnet localhost 1723
Trying 127.0.0.1…
Connected to localhost.
Escape character is ‘^]’.

3 configuration files we need to worrry about.  They are :

/etc/pptpd.conf
/etc/ppp/options.pptpd

/etc/sysctl.conf

!

Let’s start with /etc/pptpd.conf

edit file :
nano /etc/pptpd.conf

# Currently using Microsoft Client Profile:
option /etc/ppp/MSpptpd-options

# Use linux client profile:
#option /etc/ppp/LXpptpd-options

#       Turns on (more) debugging to syslog
#debug
logwtmp
speed 57600

# Specifies the local and remote IP address ranges.
localip 10.20.254.254
# listen 10.20.254.254
# remoteip 10.10.10.249-253

!

Now, on to /etc/ppp/options.pptpd

As stated previously, options.pptpd is concered with how the VPN will authenticate
and encrypt.  Below are the options that you actually care about
:

name pptpd
require-mschap-v2
require-mppe-128
ms-dns 192.168.1.73
lock
nobsdcomp
auth
require-mppe
noipx ## you don’t need IPX
mtu 1490 ## may help your linux client from disconnecting
mru 1490
## may help your linux client from disconnecting

!

Lastly, /etc/sysctl.conf :

Edit this file and make sure the net.ipv4.ip_forward is set to 1.
This enables ip packet forwarding on the LAN which is required if you expect your
VPN users to be able to access any other resources on the network besides the
VPN server itself.

net.ipv4.ip_forward = 1

Setting up Users :

The chap-secrets file in the /etc/ppp/ directory.
vi /etc/ppp/chap-secrets

# client        server secret           IP addresses
rich              pptpd         apassword     80.40.0.0/13
geoff             pptpd         apassword     212.219.0.0/14

Test and Troubleshoot
:

/etc/init.d/pptpd stop
/etc/init.d/pptpd start

Sumarize Firewall Rules :

1. Allow GRE-47/pptp-1723 on internet facing router.
2. Configure a port forward for pptp-1723 to internal lan server ip address.
3. Allow GRE traffic out from pptp server.
4. Allow pptp tcp port 1723 out from pptp server with a source nat of 1723 to remote host or any
.

GRE Tunnel with VRF Configuration

R3-PE Configuration :

ip vrf blue
 rd 1:1
 route-target export 301:301
 route-target import 401:401
!
ip vrf green
 rd 2:2
 route-target export 302:302
 route-target import 402:402
!
!- If the import and export lists are identical, use the both keyword to define both lists simultaneously.
!- You can add only one route target to a list at a time.

!
ip cef
!
interfave tunnel 0
 ip vrf forwarding green
 ip address 1.1.1.1 255.255.255.0
 tunnel source Ethernet0/0
 tunnel destination 10.10.10.1
 tunnel vrf blue

!-Tunnel 0 is part of VRF GREEN; but it uses the tunnel destination and source addresses from the routing
   table of VRF BLUE, because of this tunnel vrf blue command.

!
interface Ethernet0/0
 ip vrf forwarding blue
 address 20.20.20.3 255.255.255.0

!— Connection to the VRF BLUE network and the VRF GREEN network using the GRE tunnel.
!
interface Ethernet0/1
 ip address 30.30.30.3 255.255.255.0
 tag-switching ip (replaces IP MPLS command)
 !
router bgp 1
 no bgp default ipv4-unicast
 bgp log-neighbor-changes  (allow those routers to log their BGP neighbors resets).
 neighbor 30.30.30.4 remote-as 1
!
 address-family vpnv4 (This command replaces the match nlri and set nlri commands).
                                         (Use to configure the router to exchange IPv4 addresses in VPN mode).
 neighbor 30.30.30.4 activate (Specify peer or peer group with routes of current address family exchanged).
 neighbor 30.30.30.4 send-community extend (Enables BGP speaker to send community attribute to peer).
 exit-address-family (Exit Address Family Configuration mode and access Router Configuration mode).
!
address-family ipv4 vrf green
 redistribute connected
 no auto-summary
 no synchronization ( Tells routers shouldn’t wait for synchronization,  just go ahead use the iBGP routes).
 exit-address-family
!
address-family ipv4 vrf blue 
 redistribute connected
 no auto-summary
 no synchronization
 exit-address-family
!
ip classless
ip route vrf blue 10.10.10.1 255.255.255.255 20.20.20.2
!
end

R4-PE Configuration :

ip vrf blue
 rd 1:1
 route-target export 401:401
 route-target import 301:301
!
ip vrf green
 rd 2:2
 route-target export 402:402
 route-target import 302:302
!
ip cef
!
interface Ethernet0/0
 ip address 30.30.30.4 255.255.255.0
 tag-switching ip (replaces IP MPLS command)
!
interface Ethernet 0/1
 ip vrf forwarding green
 ip address 100.100.100.4 255.255.255.0
!
interface Ethernet0/2
 ip vrf forwarding blue
 ip address 40.40.40.4 255.255.255.0
!
router bgp 1
 no bgp default ipv4-unicast
 bgp log-neighbor-changes
 neighbor 30.30.30.3 remote-as 1
!
address-family vpnv4
 neighbor 30.30.30.3 activate
 neighbor 30.30.30.3 send-community extend
 exit-address-family
!
address-family ipv4 vrf green 
 redistribute connected
 no auto-summary
 no synchronization
 exit-address-family
!
address-family ipv4 vrf blue
 redistribute connected
 no auto-summary
 no synchronization
 exit-address-family
!
ip classless
!
end

R1-PE Configuration :ip cef
!
interface Tunnel 0
 ip address 200.200.200.1 255.255.255.0
 tunnel source Ethernet0/0
 tunnel destination 20.20.20.3

!- Both the tunnel source and destination address are in the VRF BLUE,
    to provide transport for the VRF GREEN network.

!
interface Ethernet0/0
description Connection to R2-CE router
ip address 10.10.10.1 255.255.255.0
ip access-group 100 in
ip access-group 100 out

!- Access-group to allow only GRE packets through theR2-CE network. 
   However, R1-CE networks data is in the GRE packet.

!
ip route 0.0.0.0 0.0.0.0 Tunnel0
ip route 20.20.20.3 255.255.255.255 10.10.10.2
!
access-list 100 permit gre host 10.10.10.1 host 20.20.20.3
access-list 100 permit gre host 20.20.20.3 host 10.10.10.1

!- Permits only GRE packets between the endpoints.
!
end

R2-CE#ip cef
!
interface Ethernet0/0
description Connection to R1-CE router
ip address 10.10.10.2 255.255.255.0
ip access-group 100 in
ip access-group 100 out
!
interface Ethernet1/0
ip address 20.20.20.2 255.255.255.0
!
ip route 0.0.0.0 0.0.0.0 20.20.20.3
!
access-list 100 permit gre host 10.10.10.1 host 20.20.20.3
access-list 100 permit gre host 20.20.20.3 host 10.10.10.1

!- Permits only GRE packets between the endpoints.
!
end

R5-CE#

interface Ethernet0/0
 ip address 100.100.100.5 255.255.255.0
!
ip route 0.0.0.0 0.0.0.0 100.100.100.4
!
end

R6-CE

!
interface Ethernet0/0
 ip address 40.40.40.6 255.255.255.0
!
ip route 0.0.0.0 0.0.0.0 40.40.40.4
!
end