Networking-Blog

My WordPress Blog

Cisco PIX/ASA 8.3 Command Changes {NAT / Global / Access-List}

NAT and Global commands.

Basically there is no more global command, and we are now a lot more reliant on object groups.

If you are port forwarding (Static PAT) then the dns re-write will no longer work.

NAT 0 (or no nat) no longer exists.

OLD – Regular PAT – 1 External IP to many internal IP addresses

nat (inside) 1 0 0
global (outside) 1 interface

NEW – Regular PAT – 1 External IP to many internal IP addresses

object network obj_any
subnet 0.0.0.0 0.0.0.0
nat (inside,outside) dynamic interface

OLD – Static PAT (Port Forwarding)

access-list inbound extended permit tcp any interface outside eq smtp
access-list inbound extended permit tcp any interface outside eq www
access-list inbound extended permit tcp any interface outside eq 3389
static (inside,outside) tcp interface www 10.254.254.5 www netmask 255.255.255.255
static (inside,outside) tcp interface smtp 10.254.254.5 smtp netmask 255.255.255.255
static (inside,outside) tcp interface 3389 10.254.254.5 3389 netmask 255.255.255.255

NEW – Static PAT (Port Forwarding)

access-list inbound extended permit tcp any object obj-10.254.254.5 eq smtp
access-list inbound extended permit tcp any object obj-10.254.254.5 eq www
access-list inbound extended permit tcp any object obj-10.254.254.5 eq 3389
object network obj-10.254.254.5
host 10.254.254.5
object network obj-10.254.254.5-01
host 10.254.254.5
object network obj-10.254.254.5-02
host 10.254.254.5
object network obj-10.254.254.5
nat (inside,outside) static interface service tcp www www

OLD – No NAT (seen mainly – but not always – on VPN traffic)

nat (inside) 0 access-list EXEMPT
access-list EXEMPT extended permit ip 10.254.254.0 255.255.255.0 172.16.254.0 255.255.255.0

NEW – No NAT

object network obj-10.254.254.0
subnet 10.254.254.0 255.255.255.0
object network obj-172.16.254.0
subnet 172.16.254.0 255.255.255.0
nat (inside,any) source static obj-10.254.254.0 obj-10.254.254.0 destination static obj-172.16.254.0 obj-172.16.254.0

Access Lists

For as long as I can remember when you allowed access to an IP address on a PIX/ASA you allowed access to its translated IP address, NOW YOU DO NOT, you allow access to its “Pre-translation address”

OLD Access List and Static NAT

access-list inbound extended permit ip any host 123.123.123.123 eq www
access-group inbound in interface outside
static (inside,outside) 123.123.123.123 10.254.254.5 netmask 255.255.255.255

NEW Access List and Static NAT

access-list inbound extended permit ip any host 10.254.254.5
access-group inbound in interface outside
object network obj-10.254.254.5
host 10.254.254.5
nat (inside,outside) static 123.123.123.123

Cisco ASA Port-Forward

PIX/ASA 7.x and above: Mail (SMTP) Server Access on the DMZ Configuration Example

!— This access list allows hosts to access !— IP address 192.168.200.227 for the !— Simple Mail Transfer Protocol (SMTP) port.

access-list outside_int extended permit tcp any host 192.168.200.227 eq smtp

!— Allows outgoing SMTP connections. !— This access list allows host IP 172.16.31.10 !— sourcing the SMTP port to access any host.

access-list dmz_int extended permit tcp host 172.16.31.10 any eq smtp

!— This network static does not use address translation. !— Inside hosts appear on the DMZ with their own addresses.

static (inside,dmz) 10.1.1.0 10.1.1.0 netmask 255.255.255.0

!— This network static uses address translation. !— Hosts accessing the mail server from the outside !— use the 192.168.200.227 address.

static (dmz,outside) 192.168.200.227 172.16.31.10 netmask 255.255.255.255

access-group outside_int in interface outside
access-group dmz_int in interface dmz

!— The inspect esmtp command (included in the map) allows !— SMTP/ESMTP to inspect the application.

policy-map global_policy
class inspection_default
inspect dns maximum-length 512
inspect ftp
inspect h323 h225
inspect h323 ras
inspect netbios
inspect rsh
inspect rtsp
inspect skinny
inspect esmtp
inspect sqlnet
inspect sunrpc
inspect tftp
inspect sip
inspect xdmcp

Linux Show Version installed

linux version installed on a different servers.

uname -a
or
/proc/version

When we telnet to any of the Linux server  or machine’s,
the version shows very clearly like :

Red Hat Enterprise Linux ES release 3 (Taroon Update 6)
Kernel 2.4.21-37.ELsmp on an i686

!
On Linux Ubuntu :

Linux mediapc 2.6.32-26-generic #48-Ubuntu SMP Wed
Nov 24 09:00:03 UTC 2010 i686 GNU/Linux

Cisco ASA and ICMP Configurations

As I am sure many of you who have ever worked with a Cisco firewall know,
ICMP is not allowed through the firewall by default. If you are just configuring the device,
this can make it very difficult to troubleshoot connectivity issues.
Thankfully, there are several ways to get around this.

Solution 1: Use access-lists to allow pings from inside/DMZ to the outside.
To allow pinging from the inside to the outside interfaces, you will need to configure an access-list for the outside interface.

access-list OUTSIDE_IN_ACL permit icmp any any echo-reply

Then apply the access-list to the outside interface.

access-group OUTSIDE_IN_ACL in interface outside

This will allow only ping. If you would like to allow trace route, you will also need to allow time-exceeded.

access-list OUTSIDE_IN_ACL permit icmp any any time-exceeded

Solution 2: Use access-list to allow ping and trace route from the internet to your dmz/inside servers.
To do this, we are going to build off of what we did above, so you should already have this in the config.

access-list OUTSIDE_IN_ACL permit icmp any any echo-reply
access-list OUTSIDE_IN_ACL permit icmp any any time-exceeded
access-group OUTSIDE_IN_ACL in interface outside

Now all we need to do is allow echo into the network.

access-list OUTSIDE_IN_ACL permit icmp any any echo

Even though we are allowing icmp, we still need to have a static mapping to allow the packets to reach the DMZ.

static (dmz,outside) PUBLIC_IP DMZ_IP netmask 255.255.255.255

Of course, you will need to have a static mapping for every server you want to have reachable from the internet.

Solution 3: This is a bit more complex, but will allow higher security level interfaces to ping/trace route lower security level interfaces without the use of access-lists. To do this, we will tell the ASA to inspect icmp in a service policy. If you are using a ASA, you should have a default policy in the base config called global_policy.

global_policy:

class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns migrated_dns_map_1
parameters
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns migrated_dns_map_1
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
!
service-policy global_policy global
! 

To add icmp inspection.

FW-ASA(config)# policy-map global_policy
FW-ASA(config-pmap)# class inspection_default
FW-ASA(config-pmap-c)# inspect icmp

Cisco PIX Add VPN Policy

Create Phase 1 Policy :

isakmp policy 10 authentication pre-share
isakmp policy 10 encryption 3des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 3600

Create Transform-set for Encryption being used
:

crypto ipsec transform-set minimal esp-null esp-md5-hmac
crypto ipsec transform-set secure esp-3des esp-md5-hmac


Create a nonat access-list
:

access-list nonat permit ip 172.31.0.0 255.255.0.0 192.168.0.0 255.255.0.0

Create Access-list for allowed network Source & Destination :

access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.178.0 255.255.255.0


Create Crypto Map :

crypto map armadillo 880 ipsec-isakmp
crypto map armadillo 880 match address 880
crypto map armadillo 880 set peer 2.2.2.2
crypto map armadillo 880 set transform-set secure

Create a Preshared-Key :

isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255


Assign Crypto Map to Interface
:

crypto map armadillo interface outside
isakmp enable outside

Allow IPSEC traffic into Pix from public facing interface :

sysopt connection permit-ipsec

Summarize rule for each additional vpn to be added :

access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.178.0 255.255.255.0

crypto map armadillo 880 ipsec-isakmp
crypto map armadillo 880 match address 880
crypto map armadillo 880 set peer 2.2.2.2
crypto map armadillo 880 set transform-set secure
isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255

To remove a VPN addittional policy :

no access-list nonat permit ip 172.31.0.0 255.255.0.0
192.168.0.0 255.255.0.0
!
no access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.166.0 255.255.255.0
!
no crypto map armadillo 880
!
no isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255

Cisco Wireless 857w Configuration

Cisco 857w allows only 1 broadcast configurable SSID.

See the exact configuration set out below :

Keep in mind this is what is needed for the wireless part of the configuration and inside
NAT statement via Route-Maps is not included
.


dot11 ssid COMMS
authentication open
authentication key-management wpa
guest-mode
wpa-psk ascii 0 test

interface Dot11Radio0
no ip address
!
encryption mode ciphers tkip
!
ssid test
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
world-mode dot11d country GB outdoor

!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no cdp enable
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding

!
interface Vlan1
description Bind_to_BVI1_Interface
no ip address
bridge-group 1
bridge-group 1 spanning-disabled

!
!
interface BVI1
description $ES_LAN$
ip address 192.168.194.1 255.255.255.0
ip nat inside
ip virtual-reassembly

!
ip dns server
ip nat inside source route-map NAT interface Dialer0 overload
!

route-map NAT permit 10
match ip address name NAT_ACL
!
ip access-list extended NAT_ACL
permit ip 192.168.194.0.0 0.0.0.255 any

!
bridge 1 protocol ieee
bridge 1 route ip

Linux PPTP Create Routing Script

To make sure our traffic gets routed to the other end of the tunnel, create a file called ip-up in /etc/ppp and add the following lines to this file:

#!/bin/sh
/sbin/route add -net REMOTE-NET-IP netmask REMOTE-NET-MASK dev ppp

eg :
route add -net 10.20.254.248 netmask 255.255.255.248 dev ppp0

In which you have to replace the IP-address and the mask with those of the subnet on the other end of the tunnel. If there is no network on the other side, but just the pptp server, you can use -host instead of -net. When your done, save the file and make it executable:

chmod +x /etc/ppp/ip-up

Now that all is set up we can start the tunnel:

Simplify Linux PPTP Server Configuration

yum install pptpd
apt-get pptpd

At this point, you should have a working pptp daemon.
This is a matter of personal preference, but I like to go ahead and start pptpd just to
make sure that the service is functioning and that it opens up the

PPTP port (1723) on the machine:

[user@hostname ~]# /etc/init.d/pptpd start
Starting pptpd:                                            [  OK  ]
!
[user@hostname ~]# telnet localhost 1723
Trying 127.0.0.1…
Connected to localhost.
Escape character is ‘^]’.

3 configuration files we need to worrry about.  They are :

/etc/pptpd.conf
/etc/ppp/options.pptpd

/etc/sysctl.conf

!

Let’s start with /etc/pptpd.conf

edit file :
nano /etc/pptpd.conf

# Currently using Microsoft Client Profile:
option /etc/ppp/MSpptpd-options

# Use linux client profile:
#option /etc/ppp/LXpptpd-options

#       Turns on (more) debugging to syslog
#debug
logwtmp
speed 57600

# Specifies the local and remote IP address ranges.
localip 10.20.254.254
# listen 10.20.254.254
# remoteip 10.10.10.249-253

!

Now, on to /etc/ppp/options.pptpd

As stated previously, options.pptpd is concered with how the VPN will authenticate
and encrypt.  Below are the options that you actually care about
:

name pptpd
require-mschap-v2
require-mppe-128
ms-dns 192.168.1.73
lock
nobsdcomp
auth
require-mppe
noipx ## you don’t need IPX
mtu 1490 ## may help your linux client from disconnecting
mru 1490
## may help your linux client from disconnecting

!

Lastly, /etc/sysctl.conf :

Edit this file and make sure the net.ipv4.ip_forward is set to 1.
This enables ip packet forwarding on the LAN which is required if you expect your
VPN users to be able to access any other resources on the network besides the
VPN server itself.

net.ipv4.ip_forward = 1

Setting up Users :

The chap-secrets file in the /etc/ppp/ directory.
vi /etc/ppp/chap-secrets

# client        server secret           IP addresses
rich              pptpd         apassword     80.40.0.0/13
geoff             pptpd         apassword     212.219.0.0/14

Test and Troubleshoot
:

/etc/init.d/pptpd stop
/etc/init.d/pptpd start

Sumarize Firewall Rules :

1. Allow GRE-47/pptp-1723 on internet facing router.
2. Configure a port forward for pptp-1723 to internal lan server ip address.
3. Allow GRE traffic out from pptp server.
4. Allow pptp tcp port 1723 out from pptp server with a source nat of 1723 to remote host or any
.