Networking-Blog

My WordPress Blog

ASA 5505 Clear Configuration

• To erase the startup configuration, enter the following command:

hostname(config)# write erase

• To erase the running configuration, enter the following command:

hostname(config)# clear configure all

This command clears all the current configuration for the specified configuration command. If you only want to clear the configuration for a specific version of the command, you can enter a value for level2configurationcommand.

For example, to clear the configuration for all aaa commands, enter the following command:

hostname(config)# clear configure aaa

To clear the configuration for only aaa authentication commands, enter the following command:

hostname(config)# clear configure aaa authentication

Cisco/PIX/ASA ISAKMP States

Details on the various connection states shown in the output from commands show isakmp sa or show crypto isakmp sa executed on a Cisco PIX or ASA firewall appliance.

MM_SA_SETUP

Policy parameters have been successfully negotiated

MM_NO_STATE

Phase 1 has failed, policy parameters have not been successfully negotiated.

  • Check there is a matching crypto policy configured on both peers
  • Check you have applied and activated the relevant crypto map/policy on both peers, on the correct interface

AG_NO_STATE

As above but displayed for agressive mode connections

MM_KEY_EXCH

Peers are authenticating. If phase 1 fails here, authentication of a peer device has failed

  • Check the pre-shared key matches at both ends
  • Check the time on each peer is reasonably close to the others
  • If using certificates, confirm they are valid and have not been revoked

AG_INIT_EXCH

As above but displayed for agressive mode connections

MM_KEY_AUTH

Authentication of the peer devices has been successful, expect the state to transition to QM_IDLE or MM_ACTIVE shortly

AG_AUTH

As above but displayed for agressive mode connections

QM_IDLE

Phase 1 completed successfully



Cisco ASA Inspection Rule

class-map inspection_default
match default-inspection-traffic
!
policy-map type inspect esmtp tls-esmtp
parameters
allow-tls

policy-map global_policy
class inspection_default
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect icmp
inspect esmtp tls-esmtp

!

!--- This command tells the device to
!--- use the "global_policy" policy-map on all interfaces.

service-policy global_policy global
!
!

The Extended Simple Mail Transport Protocol (ESMTP) inspect feature masks the hostname and causes
an error when a mailserver is configured to ensure the HELO reply is a valid hostname.

ESMTP fixup has a feature that removes some header information that is not required by the RFCs from the
responses. Sometimes this un-required data is used by mail servers to try and limit spam.

For example, mail fails when a user enters the helo command instead of the HELO command.

The HELO command must be used as stated by the RFC 821 specifications when inspect esmtp is enabled.

hostname (config)#policy-map type inspect esmtp testesmtpmap
hostname (config-pmap)#parameters
hostname(config-pmap-p)#no mask-banner
!
hostname(config)#policy-map global_policy
hostname(config-pmap)#class inspection_default
hostname(config-pmap-c)#no inspect esmtp
hostname(config-pmap-c)#inspect esmtp testesmtpmap
!
hostname(config)#service-policy global_policy global


default-inspection-traffic.  Match default inspection traffic:

ctiqbe—-tcp–2748
dns——-udp–53
ftp——-tcp–21
gtp——-udp–2123,3386
h323-h225-tcp–1720
h323-ras–udp–1718-1719
http——tcp–80
icmp——icmp
ils——-tcp–389
mgcp——udp–2427,2727
netbios—udp–137-138
radius-acct—udp–1646
rpc——-udp–111
rsh——-tcp–514
rtsp——tcp–554
sip——-tcp–5060
sip——-udp–5060
skinny—-tcp–2000
smtp——tcp–25
sqlnet—-tcp–1521
tftp——udp–69
waas——tcp–1-65535
xdmcp—–udp–177

Cisco ASA FTP Access-List

ASA Version 7.2(2)
!
hostname ASA-AIP-CLI
domain-name corp.com
enable password WwXYvtKrnjXqGbu1 encrypted
names
!
interface Ethernet0/0
 nameif Outside
 security-level 0
 ip address 192.168.1.2 255.255.255.0
!
interface Ethernet0/1
 nameif Inside
 security-level 100
ip address 10.1.1.1 255.255.255.0
!
interface Ethernet0/2
 nameif DMZ
  security-level 50
  ip address 172.16.1.12 255.255.255.0
!
interface Ethernet0/3
 no nameif
 no security-level
 no ip address
!
interface Management0/0
  no nameif
 no security-level
 no ip address
!

!--- Output is suppressed.


!--- Permit inbound FTP control traffic. 

access-list 100 extended permit tcp any host 192.168.1.5 eq ftp

!--- Permit inbound FTP data traffic.

access-list 100 extended permit tcp any host 192.168.1.5 eq ftp-data
!

!--- Command to redirect the FTP traffic received on IP 192.168.1.5
!--- to IP 172.16.1.5.

static (DMZ,outside) 192.168.1.5 172.16.1.5 netmask 255.255.255.255
access-group 100 in interface outside
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum 512

policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect netbios
  inspect rsh
  inspect rtsp
  inspect skinny
  inspect esmtp
  inspect sqlnet
  inspect sunrpc
  inspect tftp
  inspect sip
  inspect xdmcp
!

!--- This command tells the device to
!--- use the "global_policy" policy-map on all interfaces.

service-policy global_policy global

LAN Outbound FTP Access : 
access-list inside extended permit tcp host 10.1.1.254 any eq ftp Create Object group in order to tidy config : object-group service Bluecoatbypass tcp description Bypass for bluecoat server port-object eq echo port-object eq irc port-object eq ftp-data port-object range 3389 3389 port-object eq domain port-object range 8080 8080 port-object eq pop3 port-object eq ftp port-object eq www port-object eq https port-object eq 1935 port-object eq ssh ! Create Access-list : access-list inside extended permit tcp host 10.1.1.254 any object-group Bluecoatbypass
Verify : show access-list | grep ftp | grep 10.1.1.254 show service-policy inspect ftp show service-policy global

Cisco ASA Object-Group

Object groups on the ASA allow you to group similar types of components within a single heading.  You can use this heading for access-lists, which in turn can be used for access control, NAT, encryption, and traffic classification.

The two main object groups I use are network and service.

The network object group is where you put subnets and hosts, while the service object group is for protocols and ports.

object-group service TCP_PORTS_10038_10046 tcp
port-object eq 10038
port-object eq  10046
!
object-group network TCP_10038_10046_LAN
network-object host 172.18.192.24
network-object host 172.16.0.68
!
object-group network TCP_10038_10046_WAN
network-object host 125.215.194.223
network-object host 125.215.194.252
network-object host 125.215.194.253
network-object host 125.215.194.232
!
access-list MPLS_access_in remark Access to  TCP_PORTS_10038_10046
access-list MPLS_access_in extended permit tcp object-group TCP_10038_10046_LAN object-group TCP_10038_10046_WAN object-group TCP_PORTS_10038_10046
!
!
Configure Inspect Policy:

class-map inspection_default
match default-inspection-traffic

class-map TCP_PORTS_10038
match port tcp eq 10038
!
class-map TCP_PORTS_10046
match port tcp eq 10046
!
!
policy-map type inspect esmtp tls-esmtp
parameters
allow-tls
!
policy-map global_policy
class inspection_default
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect icmp
inspect esmtp tls-esmtp
class TCP_PORTS_10038
class TCP_PORTS_10046
!
service-policy global_policy global

Verify:

show access-list | grep 172.18.192.24
show service-policy inspect tcp
show service-policy global

Cisco IP TCP Intercept

About TCP Intercept

The TCP intercept feature implements software to protect TCP servers from TCP SYN-flooding attacks, which are a type of denial-of-service attack.

Set the TCP Intercept Mode

The TCP intercept can operate in either active intercept mode or passive watch mode. The default is intercept mode.

In intercept mode, the software actively intercepts each incoming connection request (SYN) and responds on behalf of the server with an ACK and SYN, then waits for an ACK of the SYN from the client. When that ACK is received, the original SYN is set to the server and the software performs a three-way handshake with the server. When this is complete, the two half-connections are joined.

In watch mode, connection requests are allowed to pass through the router to the server but are watched until they become established. If they fail to become established within 30 seconds (configurable with the ip tcp intercept watch-timeout command), the software sends a Reset to the server to clear up its state.

To set the TCP intercept mode, perform the following task in global configuration mode:

Task

Command
Set the TCP intercept mode. ip tcp intercept mode {intercept | watch}

Set the TCP Intercept Drop Mode

When under attack, the TCP intercept feature becomes more aggressive in its protective behavior. If the number of incomplete connections exceeds 1100 or the number of connections arriving in the last one minute exceeds 1100, each new arriving connection causes the oldest partial connection to be deleted. Also, the initial retransmission timeout is reduced by half to 0.5 seconds (so the total time trying to establish a connection is cut in half).

By default, the software drops the oldest partial connection. Alternatively, you can configure the software to drop a random connection. To set the drop mode, perform the following task in global configuration mode:

Task

Command
Set the drop mode. ip tcp intercept drop-mode {oldest | random}

Change the TCP Intercept Timers

By default, the software waits for 30 seconds for a watched connection to reach established state before sending a Reset to the server. To change this value, perform the following task in global configuration mode:

Task

Command
Change the time allowed to reach established state. ip tcp intercept watch-timeout seconds

 

By default, the software waits for 5 seconds from receipt of a reset or FIN-exchange before it ceases to manage the connection. To change this value, perform the following task in global configuration mode:

Task

Command
Change the time between receipt of a reset or FIN-exchange and dropping the connection. ip tcp intercept finrst-timeout seconds

 

By default, the software still manages a connection for 24 hours after no activity. To change this value, perform the following task in global configuration mode:

Task

Command
Change the time the software will manage a connection after no activity. ip tcp intercept connection-timeout seconds

Monitor and Maintain TCP Intercept

To display TCP intercept information, perform either of the following tasks in EXEC mode:

Task

Command
Display incomplete connections and established connections. show tcp intercept connections
Display TCP intercept statistics. show tcp intercept statistics

TCP Intercept Configuration Example

The following configuration defines extended IP access list 101, causing the software to intercept packets for all TCP servers on the 192.168.1.0/24 subnet:

ip tcp intercept list 101

!

access-list 101 permit tcp any 192.168.1.0 0.0.0.255

ip tcp intercept list TCP_INTERCEPT
ip tcp intercept connection-timeout 60
ip tcp intercept finrst-timeout 60
ip tcp intercept max-incomplete low 500
ip tcp intercept max-incomplete high 600
ip tcp intercept one-minute low 500
ip tcp intercept one-minute high 600
!
!
ip access-list extended TCP_INTERCEPT
 permit tcp any 192.168.4.0 0.0.0.15
 permit tcp any 192.168.2.0 0.0.0.7
 permit tcp any 192.168.6.0 0.0.0.7
 permit tcp any 192.168.11.0 0.0.0.7

Cisco ASA Port Forward

static (inside,outside) 70.167.x.x 192.168.1.200 netmask 255.255.255.255
wan                    lan

Configure access-list to allow incoming Wan traffic :

access-list outside_in extended permit tcp any host 70.167.x.x eq smtp

Assign access-list to Outside Interface :

access-group outside_in in interface outside

eg :

static (MPLS,PublicIP) tcp 85.234.75.65 7870 172.18.192.24 7870 netmask 255.255.255.255
!
access-list MPLS_access_in extended permit tcp host 172.18.192.24 host 85.234.75.65 eq 7870
!
access-list PublicIP_access_in extended permit tcp host 172.18.192.24 host 85.234.75.65 eq 7870
!
!
access-group  MPLS_access_in in interface outside
access-group PublicIP_access_in in interface outside

Allow all traffic from source ip to destination ip address:

access-list PublicIP_access_in extended permit ip host 172.18.192.24 host 125.215.194.223
access-list PublicIP_access_in extended permit ip host 172.18.192.24 host 125.215.194.252
access-list PublicIP_access_in extended permit ip host 172.18.192.24 host 125.215.194.253
access-list PublicIP_access_in extended permit ip host 172.18.192.24 host 125.215.194.232
!
access-list PublicIP_access_in extended permit ip host 172.16.0.68 host 125.215.194.223
access-list PublicIP_access_in extended permit ip host 172.16.0.68 host 125.215.194.252
access-list PublicIP_access_in extended permit ip host 172.16.0.68 host 125.215.194.253
access-list PublicIP_access_in extended permit ip host 172.16.0.68 host 125.215.194.232

CBAC IpInspect

Set Global Timeouts and Thresholds :

Configuring the following global timeouts and thresholds used by CBAC.

TCP SYN and FIN wait times
TCP, UDP, and DNS idle timers
TCP flooding thresholds (DoS indicators)

These are global default settings used by CBAC to determine how long to maintain state table entries and as indicators of possible DoS attacks. Each command has a default value and, therefore, needs to be set only to change the default to  implement a security policy better.

1.  TCP Session Establishment Timer :

 Rtr1(config)#ip inspect tcp synwait-time seconds 

The default is 30 seconds.
The value specified for this timeout applies to all TCP sessions inspected by CBAC.

Define the number of seconds the software will wait for a TCP session to reach the established state before dropping the session.
The session is considered to have reached the established state after the session’s first SYN bit is detected. 

 2.  TCP Session Termination Timer : Rtr1(config)#ip inspect tcp finwait-time seconds

The default is five seconds.
The timeout set with this command is referred to as the finwait timeout.
It applies to all CBAC-inspected TCP sessions.

Define how many seconds a TCP session will still be managed after the firewall detects a FIN-exchange. The FIN-exchange occurs when the TCP session is ready to close.

3.  TCP Session Inactivity Timer :  Rtr1(config)#ip inspect udp idle-time seconds 

The default is 3,600 seconds (one hour).

Specify the TCP idle timeout—the number of seconds a TCP session will still be managed after no activity.
When CBAC detects a valid TCP packet that’s the first in a session for a protocol CBAC is inspecting, the software creates a new state table entry with the information.
If no TCP packets for a particular session are detected for the time defined by the TCP idle timeout, the software drops that session entry from the state table and ACL.

 4.  UDP Session Inactivity Timer : Rtr1(config)#ip inspect udp idle-time seconds

The default is 30 seconds.

Specify the UDP idle timeout, the number of seconds a UDP “session” will still be managed after no activity.

When CBAC detects a valid UDP packet that’s the first in a session for a protocol CBAC is inspecting, the software creates a new state table entry with the information.
UDP is a connectionless service, no actual sessions exist as with TCP, so CBAC approximates sessions.
It does this by examining the packets and determining if they’re similar (source/destination addresses and ports) to other UDP packets.
If no UDP packets for a particular session are detected for the time defined by the UDP idle timeout, the software drops those session entries from the state table and ACL.

5.  DNS Session Inactivity Timer :

Rtr1(config)#ip inspect dns-timeout seconds

The default is five seconds.

Specify the DNS idle timeout, the length of time a DNS-name lookup session will still be managed after no activity.

When CBAC detects a valid UDP packet for a new DNS-name lookup session for a protocol CBAC is inspecting, the software creates a new state table entry with the information.
If the software detects no packets for the DNS session for a time period defined by the DNS idle timeout, the software then drops that session entry from the state table and ACL.

6.  Maximum Incomplete Sessions High/Low Threshold :

Rtr1(config)#ip inspect max-incomplete high number
Rtr1(config)#ip inspect max-incomplete low number

The default is 500 half-open sessions high.
The default is 400 half-open sessions low.

An unusually high number of half-open sessions can indicate a DoS attack is occurring.

For TCP, half-open means that the session hasn’t reached the established state.
For UDP, half-open means that the firewall has detected traffic from one direction only.

CBAC measures both the total number of existing half-open sessions and the rate of session establishment attempts. Both TCP and UDP half-open sessions are counted in the total number and rate measurements.
Measurements are made once a minute.

When the number of existing half-open sessions rises above the threshold set by the ip inspect max-incomplete high command, the software then deletes half-open sessions until the number of existing half-open sessions drops below the threshold set by the ip inspect max-incomplete low command.

The global value specified for this threshold applies to all TCP and UDP connections inspected by CBAC.
Use the Global Configuration Mode command ip inspect max-incomplete high to define the number of existing half-open sessions that will cause the software to start deleting half-open sessions.

The following example causes the CBAC to start deleting half-open sessions when the number of half-open sessions rises above 800 and to stop when the number drops below 500. Rtr1(config)#ip inspect max-incomplete high 800
Rtr1(config)#ip inspect max-incomplete low 500

7.  One Minute Incomplete Sessions High/Low Threshold  :

Rtr1(config)#ip inspect one-minute high number
Rtr1(config)#ip inspect one-minute low number

The default is 500 half-open sessions high.
The default is 400 half-open sessions low.

Define the rate of new unestablished TCP sessions that will cause the software to stop deleting half-open sessions.
This is an extension of the preceding threshold, accelerating the process to respond to a rapid increase in incomplete sessions. These rate thresholds are measured as the number of new session connection attempts detected in the last one-minute sample period.

The following example causes the software to start deleting half-open sessions when more than 1,000 session establishment attempts are detected in the last minute and to stop when fewer than 750 sessions are detected in the last minute : 

Rtr1(config)#ip inspect one-minute high 1000
Rtr1(config)#ip inspect one-minute low 750

8.  Maximum Incomplete Sessions Per Destination Host Threshold : 

Rtr1(config)#ip inspect tcp max-incomplete host number block-time seconds

The default is 50 half-open sessions and 0 minutes.

An unusually high number of half-open sessions with the same destination host address can indicate that a DoS attack is being launched against the host. Use the Global Configuration Mode command ip inspect tcp max-incomplete host to specify threshold and blocking time values for TCP host–specific DoS detection and prevention.

number Specifies how many half-open TCP sessions with the same host destination address can exist at a time, before the software starts deleting half-open sessions to the host. Use a number from 1 to 250.
block-time Specifies blocking of connection initiation to a host.
seconds Specifies how long the software will continue to delete new connection requests to the host.

When the numbers of half-open sessions with the same destination host address rises above this threshold, CBAC will delete half-open sessions choosing a method based on the block-time seconds setting.

If the timeout is :

0 (the default) CBAC will delete the oldest half-open session for the host for every new connection request to the host. This ensures the number of half-open sessions to a given host will never exceed the threshold.
Greater than 0 CBAC will delete all existing half-open sessions for the host, and then block all new connection requests to the host until the block-time expires.

The software also sends syslog messages whenever the max-incomplete host number is exceeded and when blocking of connection initiations to a host starts or ends.

The global values specified for the threshold and blocking time apply to all TCP connections inspected by CBAC.

The following example changes the max-incomplete host number to 70 half-open sessions and changes the block-time timeout to 90 seconds.

 Rtr1(config)#ip inspect tcp max-incomplete host 70 block-time 90

Best Practice Configuration :

ip inspect alert-off
ip inspect max-incomplete low 300
ip inspect max-incomplete high 400
ip inspect one-minute low 300
ip inspect one-minute high 400
ip inspect udp idle-time 15
ip inspect dns-timeout 10
ip inspect tcp idle-time 900
ip inspect tcp max-incomplete host 10 block-time 0
ip inspect name INSPECT_OUT cuseeme timeout 900
ip inspect name INSPECT_OUT ftp timeout 900
ip inspect name INSPECT_OUT h323 timeout 900
ip inspect name INSPECT_OUT netshow timeout 900
ip inspect name INSPECT_OUT rcmd timeout 900
ip inspect name INSPECT_OUT realaudio timeout 900
ip inspect name INSPECT_OUT rtsp timeout 900
ip inspect name INSPECT_OUT sqlnet timeout 900
ip inspect name INSPECT_OUT streamworks timeout 900
ip inspect name INSPECT_OUT tftp timeout 15
ip inspect name INSPECT_OUT tcp timeout 900
ip inspect name INSPECT_OUT udp timeout 15
ip inspect name INSPECT_OUT vdolive timeout 900
ip inspect name INSPECT_OUT isakmp timeout 900
ip inspect name INSPECT_OUT ipsec-msft timeout 900
ip inspect name INSPECT_OUT sip audit-trail on timeout 300
ip inspect name INSPECT_OUT sip-tls audit-trail on timeout 1800
ip inspect name INSPECT_OUT smtp timeout 15
ip inspect name INSPECT_OUT ssh timeout 900

These settings have default values that may interfere with proper network operation if they are not configured for the appropriate level of network activity in networks where connection rates will exceed the defaults:

ip inspect max-incomplete high value (default 500)
ip inspect max-incomplete low value (default 400)
ip inspect one-minute high value (default 500)
ip inspect one-minute low value (default 400)
ip inspect tcp max-incomplete host value (default 50) [block-time minutes (default 0)]

While you cannot “disable” your firewall’s DoS protection, you can adjust the DoS protection so that it will not take effect unless a very large number of half-open connections are present in your firewall router’s Stateful Inspection session table.Follow this procedure to tune your firewall’s DoS protection to your network’s activity:

Step 1. Be sure your network is not infected with viruses or worms that could lead to erroneously large half-open connection values and attempted connection rates. If your network is not “clean”, there is no way to properly adjust your firewall’s DoS protection.

Step 2. Set the max-incomplete high values to very high values:

ip inspect max-incomplete high 20000000
ip inspect one-minute high 100000000
ip inspect tcp max-incomplete host 100000 block-time 0

This will prevent the router from providing DoS protection while you observe your network’s connection patterns.
 If you wish to leave DoS protection disabled, stop following this procedure now:

Clear the Cisco IOS Firewall statistics, using the following command:

show ip inspect statistics reset

After the observation period, check the DoS counters with the following command. The parameters you must observe to tune your DoS protection are highlighted in bold:

router#show ip inspect statistics

Packet inspection statistics [process switch:fast switch]
tcp packets: [528:22519]
udp packets: [318:0]
Interfaces configured for inspection 1
Session creations since subsystem startup or last reset 766
Current session counts (estab/half-open/terminating) [1:0:0]
Maxever session counts (estab/half-open/terminating) [48:12:5]
Last session created 00:12:21
Last statistic reset never
Last session creation rate 0
Last half-open session total 0

Configure “ip inspect max-incomplete high” to a value 25-percent higher than your router’s indicated maxever session count half-open value.

 A 1.25 multiplier offers 25-percent headroom above observed behavior.

For example:

Maxever session count (estab/half-open/terminating) [920:460:331]
460 * 1.25 = 575
Thus, configure:

router(config)#ip inspect max-incomplete high 575
Step 7. Configure “ip inspect max-incomplete low” to the value your router displayed for its maxever session count half-open value.

For example:

Maxever session counts (estab/half-open/terminating) [920:460:331]
Thus, configure:

router(config)#ip inspect max-incomplete low 460

Cisco IOS Software does not maintain a value of the maxever one-minute connection rate, so you must calculate the value you will apply based on observed maxever values.
While the maximum indicated values for established, half-open, and terminating sessions are unlikely to occur in the same instant, the calculated values used for the one-minute settings have been observed to be reasonably accurate.

To calculate the ip inspect one-minute low value, add the indicated “established” value by three.

For example:

Maxever session counts (estab/half-open/terminating) [920:460:331]

920 * 3 = 2760

Thus, configure:

ip inspect one-minute low 2760

Step 9. Calculate and configure “ip inspect one-minute high”. The ip inspect one-minute high value should be 25-percent greater than the calculated one-minute low value.

For example:

ip inspect one-minute low (2760) * 1.25 = 3450

Thus, configure:

ip inspect one-minute high 3450

Step 10. You will need to define a value for “ip inspect tcp max-incomplete host” according to your understanding of your servers’ capability.

Step 11. Monitor your network’s DoS protection activity. Ideally, you should use a syslog server and record occurrences of DoS attack detection. If detection happens very frequently, you may need to monitor and adjust your DoS protection parameters.