Networking-Blog

My WordPress Blog

Assign Privilege Levels with TACACS+ and RADIUS

AAA authorization limits the services available to a user.
When AAA authorization is enabled,  Devices uses information retrieved from the user profile, which is located either in the local user database or on the security server, to configure the user session.

The user is granted access to a requested service only if the information in the user profile allows it. You can use the aaa authorization command in global configuration mode with the tacacs+ keyword to set parameters that restrict a user network access to privileged EXEC mode.

The aaa authorization exec tacacs+ local command sets these authorization parameters:

• Use TACACS+ for privileged EXEC access authorization if authentication was performed by using TACACS+
• Use the local database if authentication was not performed by using TACACS+.

To determine the privilege level as a logged-in user, type the show privilege command.
To determine what commands are available at a particular privilege level for the version of Cisco IOS® software that you are using, type a ? at the command line when logged in at that privilege level.

Note: Instead of assigning privilege levels, you can do command authorization if the authentication server supports TACACS+. The RADIUS protocol does not support command authorization.
!
In this example,

snmp-server
commands are moved down from privilege level 15 (the default) to privilege level 7.
!
The ping command is moved up from privilege level 1 to privilege level 7.
!
When user seven is authenticated, that user is assigned privilege level 7 by the server and a show privilege command displays “Current privilege level is 7.” The user can ping and do snmp-server configuration in configuration mode. Other configuration commands are not available.
!
Configurations – Router :

aaa new-model
aaa authentication login default group tacacs+|radius local
aaa authorization exec default group tacacs+|radius local
username backup privilege 7 password 0 backup
tacacs-server host 171.68.118.101
tacacs-server key cisco
radius-server host 171.68.118.101
radius-server key cisco
privilege configure level 7 snmp-server host
privilege configure level 7 snmp-server enable
privilege configure level 7 snmp-server
privilege exec level 7 ping
privilege exec level 7 configure terminal
privilege exec level 7 configure
}
}
Cisco Secure UNIX TACACS+
Follow these steps to configure the server.
!
user = seven {
password = clear “seven”
service = shell {
set priv-lvl = 7
}
}
Cisco Secure NT RADIUS
Follow these steps to configure the server.
!
Enter the username and password.
In the Group Settings for IETF, Service-type (attribute 6) = Nas-Prompt
In the Cisco RADIUS area, check AV-Pair, and in the rectangular box underneath, enter shell:priv-lvl=7.

}
}

Cisco Secure UNIX RADIUS
user = seven{
radius=Cisco {
check_items= {
2=”seven”
}
reply_attributes= {
6=7
9,1=”shell:priv-lvl=7“
}
}
}
This is the user file for the username “seven.”
Note: The server must support Cisco av-pairs.
seven Password = passwdxyz
Service-Type = Shell-User
cisco-avpair =shell:priv-lvl=7

Linux Iptables DNS Chain

Allow internet access to DNS Server public address. Lets go ahead and create the rules needed.

Lets Create the nat dns Chain :

sudo iptables -N dns
!
Allow local access to NaT traffic out to internet DNS Servers.
Allow POSTROUTING Chain, DNS Traffic to jump to Chain dns
!
sudo iptables -I POSTROUTING 19 -i eth0 -s 10.10.0.0/16 -p udp -m udp –dport 53 –j dns
!

Allow local access to Public DNS Server to ACCEPT :
sudo iptables –I dns -i eth1 -d 80.84.86.80 -p udp -m udp –dport 53 –j ACCEPT
sudo iptables -I dns -i eth1 -d 80.84.86.81 -p udp -m udp –dport 53 -j ACCEPT

Linux Iptables Content Filter Web Rule

Create New -t nat Chain :
!
sudo iptables -t nat -N ssl_https
sudo iptables -t nat -N unfiltered_web
sudo iptables -t nat -N filtered_web
**********************************************************************

Firstly we need to allow HTTPS Traffic to the Internet :
Allow Subnet HTTPS Traffic to jump to Chain ssl_https :

sudo iptables -t nat -I PREROUTING 1 -s 10.10.0.0/16 -p tcp -m tcp –dport 443 -j ssl_https
Allow HTTPS Traffic to Accept :

sudo iptables -t nat -I ssl_https 1 -p tcp -m tcp –dport 443 -j ACCEPT
!

Secondly need to Create a FORWARD Chain Rule in order to allow HTTPS Traffic as this is the
second chain down the line that gets Inspected
:
!

Lets create a new Chain :

sudo iptables -N ssl-https
!
Allow HTTPS Traffic to jump to Chain ssl-https
sudo iptables -I FORWARD 1 -p tcp -m tcp –dport 443 -jssl-https :
!

Allow HTTPS Traffic to ACCEPT :
sudo iptables -I
ssl-https 1 -p tcp -m tcp –dport 443 -j ACCEPT
!

Thirdly Allow  HTTPS Traffic to SNAT to Public Assigned Address for local break-out ” 88.834.85.88″ :

sudo iptables -t nat -I internet_web 1 -o eth0 -p tcp -m tcp –dport 443  -j SNAT –to 88.834.85.88

or

sudo iptables -t nat -I POSTROUTING 1 -o eth0 -s 10.200.0.5/32 -j MASQUERADE
sudo iptables -t nat -I POSTROUTING 1 -o eth0 -s 192.0.0.0/16 -j MASQUERADE

Action that should take place is to ‘masquerade‘ packets, i.e. replacing the sender’s address by the
router’s address for local break-out to the internet.

B00m… Complete….
**********************************************************************

Another Scenerio : Allow HTTP Traffic to be Filtered by Content Filter also allow certain ip addresses
to be bypass Content Filter, where this additional rule will be configured under unfiltered_web Chain.
!

Create Filtered and unfiltered nat Chains in order for PREROUTING Chain tojump to in order to
consolidate rules more profoundly
:
!
Allow Subnet HTTP Traffic to jump to Chain unfiltered_web :
sudo iptables -t nat -I PREROUTING 2 -s 10.10.0.0/16 -p tcp -m tcp –dport 80 -j unfiltered_web
!
Allow HTTP Traffic to bypass Content Filter :
sudo iptables -t nat -I unfiltered_web 1 -d “public-ip” -p tcp -m tcp –dport 80 -j ACCEPT
!
Allow Filtered HTTP Traffic to jump to Chain filtered_web :
sudo iptables -t nat -I unfiltered_web 2 -p tcp -m tcp –dport 80 -j filtered_web
!

This is where HTTPS Traffic gets Redirect to Content Filter.
Allow HTTP Traffic to Redirect to Port 8080 (Content Filter Listening Port)

sudo iptables -t nat -I filtered_web 1 -i eth0 -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080
or
sudo iptables -t nat -I filtered_web 1 -i eth0 -p tcp -m tcp –dport 80 -j DNAT –to-destination 10.200.0.5:800
!


Now we need to have HTTP Traffic NaTTeD out for Local break out to the Internet in order for the
unfiltered_web chain
:
This is Configured in the POSTROUTING Chain.
!
Lets Create a new Chain Internet_web in order to organise chains more profoundly.

sudo iptables -t nat -N internet_web
!
Allow HTTP & HTTPS Traffic NaTTeD to jump to Chain previously created “internet_web”
sudo iptables -t nat -I POSTROUTING 2 -o eth0 -p tcp -m tcp –dport 80 -j internet_web
!
Allow HTTP & HTTPS Traffic to SNAT to Public Assigned Address for local break-out ” 88.834.85.88″ :
sudo iptables -t nat -I internet_web 2 -o eth0 -p tcp -m tcp –dport 80  -j SNAT –to 88.8234.85.88
B00m…

Dansguardian Blanket Block

Grant users access only to sites you explicity allow

If you want to have users whitelisted for a few sites, but then block them from everything else
you should use the Blanket Block feature.

Example :

Allow user1 to access yahoo.com and msn.com but deny access to any other website.

In the /etc/dansguardian/bannedsitelist file for the group you are administering,
set the Blanket Block setting as you see below.

#Blanket Block.  To block all sites except those in the
#exceptionsitelist file remove the # from the next line to leave
#only a '**':
**

Now add to the exceptionsitelist the websites that you want people to have access to.
All sites not listed in the exceptionsitelist will be blocked.

(For the example above, /etc/dansguardian/exceptionsitelist file for the group you are administering
should be:

yahoo.com
msn.com

Linksys WRT54GL Router – Recover from a bad flash

Before you continue below, make sure you’ve first tried a hard reset to revive your router:

1.  Disconnect the router from UTP cables (not the power cable).
2. Push reset button for 30 secs.
3. Without releasing reset button, disconnect power cord.
4. Hold the reset button for another 30 secs.
5. Replug the power cord.
6. Still hold the reset button for another 30 secs.
7. Release the reset button and give the router about 10 secs to resettle.
8. Disconnect power cord for another 10 secs and then reconnect.
9. All should be in default settings now.

This procedure is usually called 30/30/30 reset.
If the power light blinks in a neverending way, the 30/30/30 reset has no effect
.

Seize The Moment With TFTP :

You can use the TFTP  (Trivial File Transfer Protocol (define) command-line utility to
upload fresh firmware to the router in its brief moment of wakefulness.
Windows, OS X and Linux all include TFTP clients.

First, you need a .bin file containing the known good firmware. You can visit the Linksys
site as described above and download the .zip version of the firmware,
which includes the .bin file.

You can even use a .bin file for an open source firmware, so long as you choose
one that’s stable and tested and is the correct version for your router
(or else you start this whole process all over again).

Windows users need some dexterity here. First, remove power from your router.

Open two command prompt windows. In one, you will set up your TFTP command.

Type (but do not yet press enter) :

tftp –i 192.168.1.1 PUT firmwarefile.bin

In the second command prompt, enter:

ping –t 192.168.1.1

Run the ping command, which will begin probing and failing to reach the router.
Now change window focus to your
TFTP command.

Apply power to the router. Watch the ping window for a response,
Then hit enter in the TFTP window !

Miss by a beat and you’re too late – the pings will fail and your moment has passed.
Cut power to the router and repeat the process.
You need to start the TFTP the moment you see a successful ping.

For OS X and Linux users, the principle is the same, but the process is easier.
First, remove power from your router. Open a terminal window and enter

the commands:

tftp 192.168.1.1
binary
rexmt 1
timeout 60
trace
tftp> put firmwarefile.bin

Now apply power to your router. The tftp client will continuously retry uploading the firmware
until the router responds. Hopefully, the router will briefly awaken, allowing the firmware upgrade
to be sent. About two minutes later, the router will reset and become operational with the new firmware.

Notes :

Enabling boot_wait

The router does not boot directly into the firmware, instead it boots into a program
known as a bootloader which is responsible for initializing the hardware and loading
the firmware. If the boot_wait variable is set, the bootup process is delayed by few
seconds allowing a new firmware to be installed through the bootloader using tftp.

Recommend that you use boot_wait for your first install. This will confirm boot_wait
is correctly enabled and provide a firmware recovery experience without the stress of
a broken router
.

Linux IPTables Add Chain

sudo iptables -N home_users
!
sudo iptables -I home_users -d 10.20.190.0/23 -j ACCEPT
sudo iptables -I home_users -d 10.20.192.0/21 -j ACCEPT

sudo iptables -I FORWARD 64 -s 10.20.253.24/29 -d 10.20.0.0/16 -j home_users

This will cover networks destined within the home_users chain :

/21 = 10.20.190.0 – 10.20.191.255
/23 = 10.20.192.0 – 10.20.199.255

To add the chain home_users :
sudo iptables -N home_users
!
To delete the chain home_users :
sudo iptables -X home_users
!
!

“iptables –table nat –flush”

This will remove all chains from your current running netfilter table (firewall rules)…
you just dropped your pants.

!

“iptables –delete-chain”

This will remove all chains from your current running nat table
!

“iptables –table nat –delete-chain”

No need to do this after a flush!  There are no chains in your current running nat table
because you already flushed it.

!

“iptables –table nat –append POSTROUTING –out-interface eth0 -j MASQUERADE”

This will enable nat in your current running nat table until we get down to the restart below.
!

“echo 1 > /proc/sys/net/ipv4/ip_forward”

This will turn on routing.  To bad next time you boot, it will not be enabled.  Use sysct
!

“service iptables restart”
I love this one.  This command will un-do every “iptable” command above.
Now NAT is no longer running. When the iptables service is restarted, it reads
the saved config and anything was in “current running” is gone.
Instead, use iptables-save
.
!
!
The cleanest method of accomplishing this is to create a new chain which does both
the LOG and DROP for you
.

The following IPTABLES rules will create a LOGDROP chain.

Create the LOGDROP chain
iptables -N LOGDROP > /dev/null 2> /dev/null
iptables -F LOGDROP
iptables -A LOGDROP -j LOG –log-prefix “LOGDROP ”
iptables -A LOGDROP -j DROP

1. The first rule in this set creates the new chain.
The output is sent to /dev/null because if you attempt to run this twice on the
same system, you will get an error saying the chain already exists. It’s up to you if you
want to see that message or not.

2. The second rule flushes the contents of the chain, again, so that if you run it twice on the
same system you don’t have duplicate rules in the chain
.

3. The third rule LOGS the traffic with the added “LOGDROP” prefix and the fourth rule
DROP’s the traffic.

“iptables -A INPUT -p tcp –dport 80 -j LOGDROP”
Log and drop all connections to the HTTP port

As you can see, you now simply use the LOGDROP target in order to log and drop any
traffic you want
.You must ensure that you define the LOGDROP target BEFORE you
attempt to use it in a rule
.

How To Increase Squid’s Cache Directory Swap Size

At times, granted a high-end server capacity and resources with large disk and memory capacity,
increase squid’s disk cache size is highly advisable. With higher disk cache size, you provide a higher
amount of disk space to be used by squid on caching web files
.

Increase Squid Cache Directory Swap Size

With default Squid rpm installation, the default value of squid cache directory swap size is set to 100MB.
Having a large disk storage would be efficient to store a larger directory swap size for squid to use.

Simply edit /etc/squid/squid.conf and find the cache directory squid directive

cache_dir ufs /var/spool/squid 100 16 256

/var/spool/squid is the directory folder location where squid will use to swap cached web files.

100 the first number is the amount of disk space in MB to be used by squid for caching directory.
16
is the number of first-level sub directories which will be created under the ‘Directory’.
256 is the number of second-level sub directories which will be created under each first-level directory.

To verify your disk and partition sizes, simply

# df -ah

giving you a similar lines

/dev/sda3              49G  4.5G   42G  10% /var
/dev/sda2             387G   18G  350G   5% /home
/dev/sda1              99M   12M   83M  13% /boot

From default squid installation, cache dir is physically dumped to /var directory by default.
Now, considering a server with high space, say 40GB free disk partition size, you could reconfigure
squid cache_dir to a value of

cache_dir ufs /var/spool/squid 2000 32 512

That is 2GB of cache directory for squid to use with 512 second-level directory under the first level of 32.

Save, exit and create the cache directory.

Stop Squid first

# service squid stop

Recreate Squid Cache Directory

# squid -z

Start Squid Service

# service squid start

This setup would nicely suit a large and regular internet user infrastructure setup.

All done.

Linux Squid and Dansguardian its slow

Months ago I’ve installed squid and dansguardian without a problems and worked perfect,
but week ago when the users navigate with their browsers its slow
.

I’ve changed some parameters in squid and dansguardian to solve the problem :

sudo vi /etc/squid/squid.conf

cache_dir ufs /var/spool/squid 2000 16 256
cache_mem 2000 MB
maximum_object_size 4096 KB

sudo vi /etc/ dansguardian/dansguardian.conf   ( Default Settings )

maxchildren = 120
minchildren = 8
minsparechildren = 4
preforkchildren = 6
maxsparechildren = 32
maxagechildren = 500

Right now the browsing is fast as I have done some changes
in the config file
:

maxchildren = 999
minchildren = 250
minsparechildren = 24
preforkchildren = 32
maxsparechildren = 64
maxagechildren = 10000

The following are the results I get after running

> # ps aux | grep dans
> 419 3049 0.0 11.3 127952 114912 ? Ss 16:44 0:00
> dansguardian-av -c /etc/dansguardian-av/dansguardian.conf
> 419 3050 0.0 11.3 127956 115024 ? S 16:44 0:00
> dansguardian-av -c /etc/dansguardian-av/dansguardian.conf
> 419 3051 0.0 11.3 132836 114964 ? S 16:44 0:00

Cisco Linux 2 Site-to-Site Ipsec VPN

2 sites Cisco routers terminating vpn on a linux firewall.
See configuration of 2 cisco router as well as linux firewall
.
!
!
HQ advertising 2 internal networks :

128.0.0.0/16
10.0.0.0/16

Remote site advertising 1 internal network :

128.0.0.0/16

Cisco HQ IPSEC VPN Config :

crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key ahdbpr0t3ct address 80.74.16.223
!
crypto ipsec transform-set secure esp-3des esp-md5-hmac
!
crypto map armadillo 1 ipsec-isakmp
set peer 80.74.16.223
set transform-set secure
match address 101
!
crypto map armadillo 2 ipsec-isakmp
set peer 80.74.16.223
set security-association lifetime seconds 28800
set security-association idle-time 86400
set transform-set secure
match address 102
!
access-list 101 permit ip 128.0.0.0 0.0.255.255 128.0.0.0 0.255.255.255
access-list 102 permit ip 10.0.0.0 0.0.255.255 128.10.0.0 0.0.255.255

!
interface FastEthernet0/0
description WAN-Interface
ip address 213.121.189.250 255.255.255.0
crypto map armadillo
!
interface vlan 1
description MLC vlan
ip address 128.0.15.250 255.255.0.0
!
interface vlan 2
description AHDB vlan
ip address 10.0.15.1 255.255.0.0
!
!
Cisco RemoteSite IPSEC VPN Config :

crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key ahdbpr0t3ct address 80.74.16.223
!
!
crypto ipsec transform-set secure esp-3des esp-md5-hmac
!
crypto map securewan 1 ipsec-isakmp
set peer 80.74.16.223
set security-association lifetime seconds 28800
set security-association idle-time 86400
set transform-set secure
match address VPN
!

ip access-list extended VPN
permit ip 128.10.0.0 0.0.255.255 128.0.0.0 0.0.255.255
permit ip 128.10.0.0 0.0.255.255 10.0.0.0 0.0.255.255

!
interface Dialer0
ip address 80.74.22.136 255.255.255.0
crypto map securewan
!
!

Linux Firewall Configuration :
Directory path of ipsec conf file ( /etc/ipsec/site name)
!
HQ Network : 128.0.0.0/16 & 10.0.0.0/16
!
128.0.0.0/16 to HQ 128.0.0.0/16
10.0.0.0/16 to HQ 128.0.0.0/16

conn HQ1
left=80.74.16.223
leftsubnet=128.0.0.0/16
right=213.121.189.250
rightsubnet=128.0.0.0/16
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
keyexchange=ike
ikelifetime=24h
keylife=28800s
keyingtries=3
pfs=no
rekey=yes
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=60
!
conn HQ2
left=80.74.16.223
leftsubnet=128.10.0.0/16
right=213.121.189.250
rightsubnet=10.0.0.0/16
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
keyexchange=ike
ikelifetime=24h
keylife=28800s
keyingtries=3
pfs=no
rekey=yes
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=60
!
!
RemoteSite Network : Access to HQ Network :
128.0.0.0/16 to HQ 128.0.0.0/16
128.0.0.0/16 to HQ 10.0.0.0/16

conn remotesite1
left=80.74.16.223
leftsubnet=128.0.0.0/16
right=80.74.22.136
rightsubnet=128.10.0.0/16
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
keyexchange=ike
ikelifetime=24h
keylife=28800s
keyingtries=3
pfs=no
rekey=no
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=60
!
conn remotesite2
left=80.74.16.223
leftsubnet=10.0.0.0/16
right=80.74.22.136
rightsubnet=128.10.0.0/16
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
keyexchange=ike
ikelifetime=24h
keylife=28800s
keyingtries=3
pfs=no
rekey=yes
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=60

Configure Linux Firewall Iptables to forward traffic from RemoteSite over to HQ.

sudo iptables -I FORWARD -s 128.0.0.0/16 -d 128.0.0.0/16 -j ACCEPT
sudo iptables -I FORWARD -s 128.0.0.0/16 -d 10.0.0.0/16 -j ACCEPT

Configure Linux Firewall Iptables to forward traffic from HQ to RemoteSite.

sudo iptables -I FORWARD -s 128.0.0.0/16 -d 128.0.0.0/16 -j ACCEPT
this one is configured in a previous rule as above.
!
sudo iptables -I FORWARD -s 10.0.0.0/16 -d 128.0.0.0/16 -j ACCEPT

Linux Danaguardian Proxy Iptables

Push traffic to Proxy Filter Dansguardian :

PREROUTING Chain :
this will have all traffic destined for port tcp 80 to jump to unfiltered_web chain.

iptables -I PREROUTING -p tcp -m tcp –dport 80 -j unfiltered_web

unfiltered_web chain entry :

iptables -I unfiltered_web -d 83.166.168.43 -p tcp -m tcp –dport 80 -j ACCEPT
iptables -I unfiltered_web -d 212.41.178.44 -p tcp -m tcp –dport 80 -j ACCEPT
iptables -I unfiltered_web -s 172.16.2.49 -p tcp -m tcp –dport 80 -j ACCEPT

Once unfiltered traffic to bypass proxy dansguardian using unfiltered_web chain as above,
the last entry is to poing it back to filtered_web chain,  in order to have other ip addresses or
subnets HTTP traffic filtered using the filtered_web chain .
to have proxy filter HTTP traffic :

This will cause unfiltered_web to jump to filtered_web chain

iptables -I unfiltered_web-j filtered_web

filtered_web chain entry :

This will cause filtered_web chain to push all HTTP traffic to dansguardian proxy server
on 172.16.150.248 on tcp port 8080.

Tcp 80 will be DNAT to tcp port 8080 to destination address of 172.16.150.248.

iptables -I filtered_web -p tcp -m tcp –dport 80 -j DNAT –to-destination 172.16.150.248:8080

In Brief Summary :

iptables -I PREROUTING -p tcp -m tcp –dport 80 -j unfiltered_web
!
iptables -I unfiltered_web
-j filtered_web
(Make changes in this chain for unfiltered traffic as seen above)
!
iptables -I 
filtered_web -p tcp -m tcp –dport 80 -j DNAT –to-destination 172.16.150.248:8080

Additional Notes :

For HTTP external sites that need to bypass proxy due to HTTPS authentication,
These are the changes that need to be made within iptables :

sudo iptables -t nat -I PREROUTING -s 172.16.0.0/16 -d 83.166.168.51/32 -p tcp -m tcp –dport 443 -j ACCEPT
!

sudo iptables -I FORWARD 18 -s 172.16.0.0/16 -d 83.166.168.51/32 -p tcp -m tcp –dport 443 -j ACCEPT

Quick Summary :

sudo iptables -t nat -I PREROUTING 1 -i eth 0 -s 10.10.0.0/16 -p tcp -m tcp –dport 80 -j unfiltered_web
!
sudo iptables -t nat -I unfiltered_web 1 -i eth0 -s 10.10.34.12/32 -j ACCEPT
sudo iptables -t nat -I unfiltered_web 2 -i eth0 -j filtered_web
!
sudo iptables -t nat -I filtered_web 1 -i eth0 -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080