Networking-Blog

My WordPress Blog

Cisco ASA Configure Capture Traffic

The easiest way to determine the issue would be to set up packet captures on the ASA :

Configure Packet Capture on ASA :

Wan Inbound Traffic :

access-list CAPOUT extended permit tcp object-group Messagelabs any
access-list CAPOUT line 2 extended deny tcp any any eq 25


!
!

Lan Inbound Traffic :


access-list CAPIN extended permit tcp host 172.16.0.125 any eq 25
access-list CAPIN line 2 extended deny tcp any any eq 25

!
!

Bind to Interface :

cap CAPIN access-list CAPIN interface inside
cap CAPOUT access-list CAPOUT interface outside

You can check the captures with :

show cap CAPIN
show cap CAPOUT

!

Packet Capture :

show capture CAPIN detail packet-number 5 dump
show capture CAPOUT detail packet-number 5 dump

!

Display <number> of packets in capture :

show capture CAPOUT count 10

Cisco ASA Ipsec Vpn Tweaks

isakmp keepalive
!
To configure IKE DPD, use the isakmp keepalive command in tunnel-group ipsec-attributes
configuration mode. In every tunnel group, IKE keepalives are enabled by default with default
threshold and retry values.
!
Disable DPD keep-alives on ASA
“isakmp keepalive disable” under the Tunnel Group Configuration.

disable :
Disables IKE keepalive processing, which is enabled by default.
retryseconds :
Specifies the interval in seconds between retries after a keepalive response has not been received.
The range is 2-10 seconds. The default is 2 seconds.
thresholdseconds :
Specifies the number of seconds the peer can idle before beginning keepalive monitoring.
The range is 10-3600 seconds. The default is 10 seconds for a LAN-to-LAN group, and 300 second for a
remote access group.

eg :

The following example entered in config-ipsec configuration mode, configures IKE DPD,
establishes a threshold of 15, and specifies a retry interval of 10 for the IPSec LAN-to-LAN tunnel group
with the IP address 209.165.200.225 :

!
hostname(config)# tunnel-group 209.165.200.225 type IPSec_L2L
hostname(config)# tunnel-group 209.165.200.225 ipsec-attributes
hostname(config-tunnel-ipsec)# isakmp keepalive threshold 15 retry 10
!
NAT traversal enables ESP packets to pass through one or more NAT devices.

To disable in a crypto-map entry, use the crypto map set nat-t-disable
crypto map VPN_MAP 10 set nat-t-disable

To enable inbound aggressive mode connections :
no isakmp am-disable

To disable inbound aggressive mode connections :
isakmp am-disable


To enable in a crypto-map entry,
e
nable PFS
– Without PFS, the Cisco ASA uses Phase 1 keys during the Phase 2 negotiations
crypto map VPN_MAP 10 set pfs group1

To enable disconnect notification to peers, use the :
crypto isakmp disconnect-notify

!

Troubleshooting Command’s :
!
show crypto isakmp sa
show crypto isakmp sa nat
show crypto IPsec sa
show crypto engine connections active
show crypto engine connections dropped-packet
show crypto engine connections flow
show crypto engine qos
show crypto isakmp policy

!
show running-config isakmp                  – Displays all the active configuration.
clear-configure tunnel-group                 – Clears all configured tunnel groups.
show running-config tunnel-group      –
Shows the tunnel group configuration for all tunnel groups
or for a particular tunnel group
.

ISAKMP Negotiations States

These are the possible ISAKMP negotiation states on an ASA firewall. ISAKMP stands for:
The Internet Security Association and Key Management Protocol

ASA ISAKMP STATES

  • MM_WAIT_MSG2
    Initial DH public key sent to responder. Awaiting initial contact reply from other side.

    If stuck here it usually means the other end is not responding. This could be due to
    no route to the far end or the far end does not have ISAKMP enabled on the outside
    or the far end is down.
  • MM_WAIT_MSG3
    Both peers have agreed on the ISAKMP policies. Awaiting exchange of keyring
    information.
    Hang up’s here may be due to mismatch device vendors, a router
    with a firewall in the way, or even ASA version mismatches.
  • MM_WAIT_MSG4
    In this step the pre-share key hashes are exchanged. They are not compared or
    checked, only sent. If one side sends a key and does not receive a key back,
    this is where the tunnel will fail.

    I have seen the tunnel fail at this step due to the remote side having the wrong
    Peer IP address. Hang up’s here may also be due to mismatch device vendors, a
    router with a firewall in the way, or even ASA version mismatches.
  • MM_WAIT_MSG5
    This step is where the devices exchange pre-shared keys.
    If the pre-shared keys do not match it will stay at this MSG. I have also seen the
    tunnel stop here when NAT Traversal was on when it needed to be turned off.
  • MM_WAIT_MSG6
    This step is where the devices exchange pre-shared keys.
    If the pre-shared keys do not match it will stay at this MSG. I have also seen the
    tunnel stop here when NAT Traversal was on when it needed to be turned off. However,
    if the state goes to MSG6 then the ISAKMP gets reset that means phase 1 finished but
    phase 2 failed. Check that IPSEC settings match in phase 2 to get the tunnel to MM_ACTIVE.
  • AM_ACTIVE / MM_ACTIVE
    The ISAKMP negotiations are complete. Phase 1 has successfully completed.

Link to Configuring a FireBox X Edge WatchGuard to ASA :

http://www.watchguard.com/help/docs/edge/10/en-US/index_Left.html#CSHID=en-US%2Fbovpn%2Fmanual%2Fmanual_bovpn_edge_cisco.html|StartTopic=Content%2Fen-US%2Fbovpn%2Fmanual%2Fmanual_bovpn_edge_cisco.html|SkinName=Edge (en-US)

Cisco ASA 5510 No Xauth IPSEC Bug

Problem Description:

ASA 5510 is the central site FW, multiple IPSEC tunnels present to ASA5505 remotes.
One of the remote is acting funny; the ipsec tunnel can be initiated from a ping inside cmd on the
ASA5510,

but the 5505 cannot initiate the tunnel.
Once the tunnel is up, traffic is 2-way.

After checking all the crypto map and no nat acls, and a reboot,
I was left diffing (comparing) a working 5505 config with one that was not working.
There were no differences other than the ip addresses.

Both tunnel setups were identical on the central site ASA5510 as well.

ping inside cmd on the remote ASA5505 would not only fail to bring up the tunnel but an SA was
not established either.

This told me that ISAKMP was failing (key exchange).

A debug :
debug crypto ipsec

said something to the effect that the 5510 was not able to properly determine the identity of the
incoming SA request from the 5505.

The below config on the 5510:

tunnel-group a.b.c.d ipsec-attributes
isakmp peer ip a.b.c.d no-xauth

fixed the problem !!!

Basically xauth was enabled for this incoming SA request on the 5510 but its supposed to be OFF by default,
and even after entering the above command it did not show up in “sh run” on the 5510.

What shows up is :

tunnel-group a.b.c.d general-attributes

Create limited user account on Cisco ASA/Pix Firewall

How to: Create a limited user account on a Cisco Pix Firewall.

This is a snippet for the Cisco Pix firewall that create a ‘limited user‘ account on the firewall itself. That user will have access to all ‘show‘ diagnostic commands, as well as the ability to clear the error/usage counters on interfaces and to ping other devices.

This configuration does the following things:

Defines two user levels, ‘show‘ at 5 and ‘enable_15‘ at 15. (15 is the highest possible).
Sets all the ‘show’ commands to level 5
Sets the ‘configure’ level of ‘ping’ to level 5
Sets the ‘clear’ level of ‘interface’ to level 5

All other clear + configure commands remain only available to the level 15 user.

Here is the snippet :

aaa-server LOCAL protocol local
aaa authentication enable console LOCAL
aaa authorization command LOCAL
!
username enable_15 password [PUT YOUR ENABLE PASSWORD HERE] privilege 15
!
username show password [PUT YOUR SHOW PASSWORD HERE] privilege 5
!
privilege show level 5 command object-group
privilege show level 5 command access-group
privilege show level 5 command access-list
privilege show level 5 command arp
privilege show level 5 command banner
privilege show level 5 command capture
privilege show level 5 command clock
privilege show level 5 command conn
privilege show level 5 command console
privilege show level 5 command cpu
privilege show level 5 command Crashinfo
privilege show level 5 command crypto
privilege show level 5 command debug
privilege show level 5 command domain-name
privilege show level 5 command established
privilege show level 5 command fixup
privilege show level 5 command flashfs
privilege show level 5 command fragment
privilege show level 5 command icmp
privilege show level 5 command interface
privilege show level 5 command ip
privilege show level 5 command ipsec
privilege show level 5 command isakmp
privilege show level 5 command map
privilege show level 5 command memory
privilege show level 5 command mtu
privilege show level 5 command name
privilege show level 5 command nameif
privilege show level 5 command names
privilege show level 5 command nat
privilege show level 5 command ntp
privilege show level 5 command outbound
privilege show level 5 command processes
privilege show level 5 command route
privilege show level 5 command route-map
privilege show level 5 command router
privilege show level 5 command routing
privilege show level 5 command running-config
privilege show level 5 command service
privilege show level 5 command ssh
privilege show level 5 command startup-config
privilege show level 5 command static
privilege show level 5 command tcpstat
privilege show level 5 command tech-support
privilege show level 5 command telnet
privilege show level 5 command terminal
privilege show level 5 command traffic
privilege show level 5 command who
privilege show level 5 command xlate
!
privilege configure level 5 command ping
privilege configure level 5 command disable
!
privilege clear level 5 command interface

By default, there are three privilege levels on the router.

  • privilege level 1 = non-privileged (prompt is router>), the default level for logging in
  • privilege level 15 = privileged (prompt is router#), the level after going into enable mode
  • privilege level 0 = seldom used, but includes 5 commands: disable, enable, exit, help, and logout

FTP Server / Client Ports

The following chart should help admins remember how each FTP mode works:

 Active FTP :
     command : client >1023 -> server 21
     data    : client >1023 <- server 20

 Passive FTP :
     command : client >1023 -> server 21
     data    : client >1023 -> server >1023

Cisco ASA RDP Port Translation

This post contains a working example of a port forwarding configuration on a
Cisco ASA 5505
that’s allowing RDP, TCP port 3389, through the firewall to from
the Internet to the LAN side to a server
.

Port translation is used here. Where remote user RDP destination port TCP 4690/4691
instead of using the default port 3389. On ASA we have a port translation rule where
4690/4691 tcp ports are translated to 3389 and forwarded over to internal Lan RDP server.

Please see Configuration as Below :

object network KBhayani_rdp
host 10.50.50.7
!
object network icaldwallader_rdp
host 10.50.50.8
!
object-group network RDP_PCs
description Remote RDP access
network-object object KBhayani_rdp
network-object object icaldwallader_rdp
!
object-group service RDP_PORT_IN tcp
description Remote RDP access
port-object eq 3389
!
!
object network KBhayani_rdp
nat (inside,outside) static 85.234.75.213 service tcp 3389 4690
!
object network icaldwallader_rdp
nat (inside,outside) static 85.234.75.213 service tcp 3389 4691
!
!
access-list outside_in extended permit tcp any object-group RDP_PCs object-group RDP_PORT_IN

ASA v8.3 SMTP Port Forward

nat (inside,outside) static = Provided 1 to 1 nat from external to internal and gets nested
within the object network group
.
!
nat (inside,outside) source static = Provides internal traffic to get naTTed using the
Public naTTed ip address rather than using the global dynamic ip address otherwise packets
would get lost and dropped
.

object network HQMS1
host 10.0.0.51
!
object network HQMS1_PUBLIC-IP
(This object is referenced on a NaT static).
host 2.2.2.211
!
object network HQMS1
nat (inside,outside) static HQMS1_PUBLIC-IP service tcp smtp smtp

( Port Forward based on tcp port smtp).
!
object-group service Exchange tcp
description: Exchange ports
port-object eq https
port-object eq smtp
port-object eq 8081
!
access-list outside_in extended permit tcp any object HQMS1 object-group Exchange
!
access-group outside_in in interface outside  (Assign to outside in Interface).
!
!
nat (inside,outside) source static HQMS1 HQMS1_PUBLIC-IP destination
static HQMS1_PUBLIC-IP HQMS1

ASA v8.3 CCTV Port Forward

nat (inside,outside) static = Provided 1 to 1 nat from external to internal and gets nested
within the object network group
.
!
nat (inside,outside) source static = Provides internal traffic to get naTTed using the
Public naTTed ip address rather than using the global dynamic ip address otherwise packets
would get lost and dropped
.
!
object network CCTV_ACL  (This object is referenced on a firewall rule below & NaT source).
host 10.0.0.100
!
object network CCTV_PUBLIC-IP
(This object is referenced on a NaT static).
host 2. 2.2.211
!
object network CCTV_WEB
host 10.0.0.100
nat (inside,outside) static CCTV_PUBLIC-IP service tcp  www www
!
object network CCTV_FTP
host 10.0.0.100
nat (inside,outside) static CCTV_PUBLIC-IP service tcp  ftp ftp
!
object network CCTV_TELNET
host 10.0.0.100
nat (inside,outside) static CCTV_PUBLIC-IP service tcp  telnet telnet
!
object network CCTV_5201
host 10.0.0.100
nat (inside,outside) static CCTV_PUBLIC-IP service tcp  5201 5201
!
object network CCTV_1025
host 10.0.0.100
nat (inside,outside) static CCTV_PUBLIC-IP service tcp  1025 1025
!
object network CCTV_2074
host 10.0.0.100
nat (inside,outside) static CCTV_PUBLIC-IP service tcp  2074 2074
!
object network CCTV_2075
host 10.0.0.100
nat (inside,outside) static CCTV_PUBLIC-IP service tcp  2075 2075
!
!
object-group service CCTV_PORTS tcp
description CCTV_COMMUNICATION_PORTS
port-object eq www
port-object eq ftp
port-object eq telnet
port-object eq 5201
port-object eq 1025
port-object range 2074 2075
!
access-list outside_in line 10 extended permit tcp any object CCTV_ACL object-group CCTV_PORTS
access-list inside_out line 6 extended permit tcp any object CCTV_ACL object-group CCTV_PORTS
!
access-group outside_in in interface outside (Assign to outside in Interface).
access-group inside_out out interface inside (Assign to inside out Interface).
!
nat (inside,outside) source static CCTV_ACL CCTV_PUBLIC-IP destination
static CCTV_PUBLIC-IP CCTV_ACL

Notes on ASA 8.3 NAT

Cisco ASA 8.3 has introduced major changes in how NAT is configured and operates.

Here are some quick notes that I have gathered for my reference.  Feel free to post any
additional comments and notes you may have to share
:

COMMANDS

show run objects

(Displays network and service objects that are in the running confg)

show run object id

(Displays a specific object)

show run nat

(Displays running config NAT configurations)

show nat

(Displays NAT policies and counters)

Use packet-tracer for testing NAT (and other things)

packet-tracer input inside tcp 10.0.0.40 4444 198.133.219.25 80

    Configure Auto-NAT:

object network inside
   subnet 192.168.1.0 255.255.255.0
   nat (inside,outside) dynamic interface

Note: This will configure PAT onto the outside interface for the inside subnet,
while at the same time configuring the network object for the inside subnet
.

    Configure Twice (manual) NAT:
nat (inside,outside) source dynamic inside-net translated-ip destination
static cisco-dot-com cisco-dot-com

Note: You must first define the network objects for the source and destination before configuring
manual NAT.

In this example, the source IP address of the inside host is translated to “translated-ip” only when
the dynamic host is sending a packet that is destined to “cisco-dot-com”. cisco-dot-com is entered
twice because we are not translating the destination. If we wanted to translate the destination,
we would do it here.

    Exempt subnets from NAT because of VPN tunnel :
nat (inside,outside) static inside-net inside-net destination static
vpn-subnets vpn-subnets

This statement will catch traffic on the inside trying to go to the outside. Traffic that matches the
source and destination is operated on but no change is made
.

    General Notes :

ASA 8.3 has two types of NAT: Auto-NAT and Twice (manual) NAT. You can use Auto-NAT for
most NAT/PAT operations, except for ones that need to make a decision based upon the
destination address of a packet
.

With ASA 8.3, a new change called “Real IP” was introduced. Real IP means that NAT translation
happens BEFORE a ACL is checked. Therefore ACLs must contain the real IP address of the host
that the inbound packet is headed towards. In other words, do not write the ACL to match on the
“mapped” IP address. The real IP address is normally a non-routable IP address
.

!
!

Regular Static NAT :

object network srv-172.16.66.100
host 172.16.66.100
nat (inside,outside) static 209.165.xxx.xxx

Static PAT :

object network srv-172.16.66.101
host 172.16.66.101
nat (inside,outside) static interface service tcp 25 25

Regular Dynamic NAT :

object network obj-VLANXX-192.168.100.0
subnet 192.168.100.0 255.255.255.0
nat (inside,outside) dynamic interface

Cisco ASA Static NaT Port-Traffic

Setup on ASA Firewall – 85.234.75.66 to be NaTTed through to 172.16.0.128.
Allow Ports 9800-9806 tcp and 9810-9822 udp Inbound/Outbound.
Allow LAN 172.16.0.128 outbound port 9400-9422 tcp/udp.

Create 1-1 Static NaT :
static (MPLS,PublicIP) 85.234.75.66 172.16.0.128 netmask 255.255.255.255

Allow Public Interface Inbound Firewall Rule tcp/udp :
access-list PublicIP_access_in extended permit tcp any host 85.234.75.66
object-group FRONT_LINE_COMMUNICATOR_tcp
!
access-list PublicIP_access_in extended permit udp any host 85.234.75.66
object-group FRONT_LINE_COMMUNICATOR_udp
!
Create Service Port Object-Group :
object-group service FRONT_LINE_COMMUNICATOR_tcp tcp
description FRONT-LINE-COMMUNICATOR
port-object range 9800 9806
!
object-group service FRONT_LINE_COMMUNICATOR_udp udp
description FRONT-LINE-COMMUNICATOR
port-object range 9810 9822
!
object-group service FRONT_LINE_COMMUNICATOR_tcp_udp tcp-udp
description FRONT-LINE-COMMUNICATOR_tcp_udp
port-object range 9400 9422
!
Create IP Network  Object-Group :
object-group network FRONT_LINE_COMMUNICATOR_MPLS_HOST
description FRONT_LINE_COMMUNICATOR_MPLS_HOST
network-object 172.16.0.128 255.255.255.255
!
Allow Internal LAN Outbound :
access-list MPLS_access_in extended permit tcp
object-group FRONT_LINE_COMMUNICATOR_MPLS_HOST any
object-group FRONT_LINE_COMMUNICATOR_tcp
!
access-list MPLS_access_in extended permit udp
object-group FRONT_LINE_COMMUNICATOR_MPLS_HOST any
object-group FRONT_LINE_COMMUNICATOR_udp
!
access-list MPLS_access_in extended permit ip
object-group MPLS_Sites object-group FRONT_LINE_COMMUNICATOR_WAN_HOST
object-group FRONT_LINE_COMMUNICATOR_tcp_udp
!
access-list MPLS_access_in extended permit ip
object-group FRONT_LINE_COMMUNICATOR_MPLS_HOST any
object-group FRONT_LINE_COMMUNICATOR_tcp_udp