Set Global Timeouts and Thresholds :
Configuring the following global timeouts and thresholds used by CBAC.
TCP SYN and FIN wait times
TCP, UDP, and DNS idle timers
TCP flooding thresholds (DoS indicators)
These are global default settings used by CBAC to determine how long to maintain state table entries and as indicators of possible DoS attacks. Each command has a default value and, therefore, needs to be set only to change the default to implement a security policy better.
1. TCP Session Establishment Timer :
Rtr1(config)#ip inspect tcp synwait-time seconds
The default is 30 seconds.
The value specified for this timeout applies to all TCP sessions inspected by CBAC.
Define the number of seconds the software will wait for a TCP session to reach the established state before dropping the session.
The session is considered to have reached the established state after the session’s first SYN bit is detected.
2. TCP Session Termination Timer : Rtr1(config)#ip inspect tcp finwait-time seconds
The default is five seconds.
The timeout set with this command is referred to as the finwait timeout.
It applies to all CBAC-inspected TCP sessions.
Define how many seconds a TCP session will still be managed after the firewall detects a FIN-exchange. The FIN-exchange occurs when the TCP session is ready to close.
3. TCP Session Inactivity Timer : Rtr1(config)#ip inspect udp idle-time seconds
The default is 3,600 seconds (one hour).
Specify the TCP idle timeout—the number of seconds a TCP session will still be managed after no activity.
When CBAC detects a valid TCP packet that’s the first in a session for a protocol CBAC is inspecting, the software creates a new state table entry with the information.
If no TCP packets for a particular session are detected for the time defined by the TCP idle timeout, the software drops that session entry from the state table and ACL.
4. UDP Session Inactivity Timer : Rtr1(config)#ip inspect udp idle-time seconds
The default is 30 seconds.
Specify the UDP idle timeout, the number of seconds a UDP “session” will still be managed after no activity.
When CBAC detects a valid UDP packet that’s the first in a session for a protocol CBAC is inspecting, the software creates a new state table entry with the information.
UDP is a connectionless service, no actual sessions exist as with TCP, so CBAC approximates sessions.
It does this by examining the packets and determining if they’re similar (source/destination addresses and ports) to other UDP packets.
If no UDP packets for a particular session are detected for the time defined by the UDP idle timeout, the software drops those session entries from the state table and ACL.
5. DNS Session Inactivity Timer :
Rtr1(config)#ip inspect dns-timeout seconds
The default is five seconds.
Specify the DNS idle timeout, the length of time a DNS-name lookup session will still be managed after no activity.
When CBAC detects a valid UDP packet for a new DNS-name lookup session for a protocol CBAC is inspecting, the software creates a new state table entry with the information.
If the software detects no packets for the DNS session for a time period defined by the DNS idle timeout, the software then drops that session entry from the state table and ACL.
6. Maximum Incomplete Sessions High/Low Threshold :
Rtr1(config)#ip inspect max-incomplete high number
Rtr1(config)#ip inspect max-incomplete low number
The default is 500 half-open sessions high.
The default is 400 half-open sessions low.
An unusually high number of half-open sessions can indicate a DoS attack is occurring.
For TCP, half-open means that the session hasn’t reached the established state.
For UDP, half-open means that the firewall has detected traffic from one direction only.
CBAC measures both the total number of existing half-open sessions and the rate of session establishment attempts. Both TCP and UDP half-open sessions are counted in the total number and rate measurements.
Measurements are made once a minute.
When the number of existing half-open sessions rises above the threshold set by the ip inspect max-incomplete high command, the software then deletes half-open sessions until the number of existing half-open sessions drops below the threshold set by the ip inspect max-incomplete low command.
The global value specified for this threshold applies to all TCP and UDP connections inspected by CBAC.
Use the Global Configuration Mode command ip inspect max-incomplete high to define the number of existing half-open sessions that will cause the software to start deleting half-open sessions.
The following example causes the CBAC to start deleting half-open sessions when the number of half-open sessions rises above 800 and to stop when the number drops below 500. Rtr1(config)#ip inspect max-incomplete high 800
Rtr1(config)#ip inspect max-incomplete low 500
7. One Minute Incomplete Sessions High/Low Threshold :
Rtr1(config)#ip inspect one-minute high number
Rtr1(config)#ip inspect one-minute low number
The default is 500 half-open sessions high.
The default is 400 half-open sessions low.
Define the rate of new unestablished TCP sessions that will cause the software to stop deleting half-open sessions.
This is an extension of the preceding threshold, accelerating the process to respond to a rapid increase in incomplete sessions. These rate thresholds are measured as the number of new session connection attempts detected in the last one-minute sample period.
The following example causes the software to start deleting half-open sessions when more than 1,000 session establishment attempts are detected in the last minute and to stop when fewer than 750 sessions are detected in the last minute :
Rtr1(config)#ip inspect one-minute high 1000
Rtr1(config)#ip inspect one-minute low 750
8. Maximum Incomplete Sessions Per Destination Host Threshold :
Rtr1(config)#ip inspect tcp max-incomplete host number block-time seconds
The default is 50 half-open sessions and 0 minutes.
An unusually high number of half-open sessions with the same destination host address can indicate that a DoS attack is being launched against the host. Use the Global Configuration Mode command ip inspect tcp max-incomplete host to specify threshold and blocking time values for TCP host–specific DoS detection and prevention.
| number |
Specifies how many half-open TCP sessions with the same host destination address can exist at a time, before the software starts deleting half-open sessions to the host. Use a number from 1 to 250. |
| block-time |
Specifies blocking of connection initiation to a host. |
| seconds |
Specifies how long the software will continue to delete new connection requests to the host. |
When the numbers of half-open sessions with the same destination host address rises above this threshold, CBAC will delete half-open sessions choosing a method based on the block-time seconds setting.
If the timeout is :
| 0 (the default) |
CBAC will delete the oldest half-open session for the host for every new connection request to the host. This ensures the number of half-open sessions to a given host will never exceed the threshold. |
| Greater than 0 |
CBAC will delete all existing half-open sessions for the host, and then block all new connection requests to the host until the block-time expires. |
The software also sends syslog messages whenever the max-incomplete host number is exceeded and when blocking of connection initiations to a host starts or ends.
The global values specified for the threshold and blocking time apply to all TCP connections inspected by CBAC.
The following example changes the max-incomplete host number to 70 half-open sessions and changes the block-time timeout to 90 seconds.
Rtr1(config)#ip inspect tcp max-incomplete host 70 block-time 90
Best Practice Configuration :
ip inspect alert-off
ip inspect max-incomplete low 300
ip inspect max-incomplete high 400
ip inspect one-minute low 300
ip inspect one-minute high 400
ip inspect udp idle-time 15
ip inspect dns-timeout 10
ip inspect tcp idle-time 900
ip inspect tcp max-incomplete host 10 block-time 0
ip inspect name INSPECT_OUT cuseeme timeout 900
ip inspect name INSPECT_OUT ftp timeout 900
ip inspect name INSPECT_OUT h323 timeout 900
ip inspect name INSPECT_OUT netshow timeout 900
ip inspect name INSPECT_OUT rcmd timeout 900
ip inspect name INSPECT_OUT realaudio timeout 900
ip inspect name INSPECT_OUT rtsp timeout 900
ip inspect name INSPECT_OUT sqlnet timeout 900
ip inspect name INSPECT_OUT streamworks timeout 900
ip inspect name INSPECT_OUT tftp timeout 15
ip inspect name INSPECT_OUT tcp timeout 900
ip inspect name INSPECT_OUT udp timeout 15
ip inspect name INSPECT_OUT vdolive timeout 900
ip inspect name INSPECT_OUT isakmp timeout 900
ip inspect name INSPECT_OUT ipsec-msft timeout 900
ip inspect name INSPECT_OUT sip audit-trail on timeout 300
ip inspect name INSPECT_OUT sip-tls audit-trail on timeout 1800
ip inspect name INSPECT_OUT smtp timeout 15
ip inspect name INSPECT_OUT ssh timeout 900
These settings have default values that may interfere with proper network operation if they are not configured for the appropriate level of network activity in networks where connection rates will exceed the defaults:
ip inspect max-incomplete high value (default 500)
ip inspect max-incomplete low value (default 400)
ip inspect one-minute high value (default 500)
ip inspect one-minute low value (default 400)
ip inspect tcp max-incomplete host value (default 50) [block-time minutes (default 0)]
While you cannot “disable” your firewall’s DoS protection, you can adjust the DoS protection so that it will not take effect unless a very large number of half-open connections are present in your firewall router’s Stateful Inspection session table.Follow this procedure to tune your firewall’s DoS protection to your network’s activity:
Step 1. Be sure your network is not infected with viruses or worms that could lead to erroneously large half-open connection values and attempted connection rates. If your network is not “clean”, there is no way to properly adjust your firewall’s DoS protection.
Step 2. Set the max-incomplete high values to very high values:
ip inspect max-incomplete high 20000000
ip inspect one-minute high 100000000
ip inspect tcp max-incomplete host 100000 block-time 0
This will prevent the router from providing DoS protection while you observe your network’s connection patterns.
If you wish to leave DoS protection disabled, stop following this procedure now:
Clear the Cisco IOS Firewall statistics, using the following command:
show ip inspect statistics reset
After the observation period, check the DoS counters with the following command. The parameters you must observe to tune your DoS protection are highlighted in bold:
router#show ip inspect statistics
Packet inspection statistics [process switch:fast switch]
tcp packets: [528:22519]
udp packets: [318:0]
Interfaces configured for inspection 1
Session creations since subsystem startup or last reset 766
Current session counts (estab/half-open/terminating) [1:0:0]
Maxever session counts (estab/half-open/terminating) [48:12:5]
Last session created 00:12:21
Last statistic reset never
Last session creation rate 0
Last half-open session total 0
Configure “ip inspect max-incomplete high” to a value 25-percent higher than your router’s indicated maxever session count half-open value.
A 1.25 multiplier offers 25-percent headroom above observed behavior.
For example:
Maxever session count (estab/half-open/terminating) [920:460:331]
460 * 1.25 = 575
Thus, configure:
router(config)#ip inspect max-incomplete high 575
Step 7. Configure “ip inspect max-incomplete low” to the value your router displayed for its maxever session count half-open value.
For example:
Maxever session counts (estab/half-open/terminating) [920:460:331]
Thus, configure:
router(config)#ip inspect max-incomplete low 460
Cisco IOS Software does not maintain a value of the maxever one-minute connection rate, so you must calculate the value you will apply based on observed maxever values.
While the maximum indicated values for established, half-open, and terminating sessions are unlikely to occur in the same instant, the calculated values used for the one-minute settings have been observed to be reasonably accurate.
To calculate the ip inspect one-minute low value, add the indicated “established” value by three.
For example:
Maxever session counts (estab/half-open/terminating) [920:460:331]
920 * 3 = 2760
Thus, configure:
ip inspect one-minute low 2760
Step 9. Calculate and configure “ip inspect one-minute high”. The ip inspect one-minute high value should be 25-percent greater than the calculated one-minute low value.
For example:
ip inspect one-minute low (2760) * 1.25 = 3450
Thus, configure:
ip inspect one-minute high 3450
Step 10. You will need to define a value for “ip inspect tcp max-incomplete host” according to your understanding of your servers’ capability.
Step 11. Monitor your network’s DoS protection activity. Ideally, you should use a syslog server and record occurrences of DoS attack detection. If detection happens very frequently, you may need to monitor and adjust your DoS protection parameters.