Networking-Blog

My WordPress Blog

Cisco ASA and ICMP Configurations

As I am sure many of you who have ever worked with a Cisco firewall know,
ICMP is not allowed through the firewall by default. If you are just configuring the device,
this can make it very difficult to troubleshoot connectivity issues.
Thankfully, there are several ways to get around this.

Solution 1: Use access-lists to allow pings from inside/DMZ to the outside.
To allow pinging from the inside to the outside interfaces, you will need to configure an access-list for the outside interface.

access-list OUTSIDE_IN_ACL permit icmp any any echo-reply

Then apply the access-list to the outside interface.

access-group OUTSIDE_IN_ACL in interface outside

This will allow only ping. If you would like to allow trace route, you will also need to allow time-exceeded.

access-list OUTSIDE_IN_ACL permit icmp any any time-exceeded

Solution 2: Use access-list to allow ping and trace route from the internet to your dmz/inside servers.
To do this, we are going to build off of what we did above, so you should already have this in the config.

access-list OUTSIDE_IN_ACL permit icmp any any echo-reply
access-list OUTSIDE_IN_ACL permit icmp any any time-exceeded
access-group OUTSIDE_IN_ACL in interface outside

Now all we need to do is allow echo into the network.

access-list OUTSIDE_IN_ACL permit icmp any any echo

Even though we are allowing icmp, we still need to have a static mapping to allow the packets to reach the DMZ.

static (dmz,outside) PUBLIC_IP DMZ_IP netmask 255.255.255.255

Of course, you will need to have a static mapping for every server you want to have reachable from the internet.

Solution 3: This is a bit more complex, but will allow higher security level interfaces to ping/trace route lower security level interfaces without the use of access-lists. To do this, we will tell the ASA to inspect icmp in a service policy. If you are using a ASA, you should have a default policy in the base config called global_policy.

global_policy:

class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns migrated_dns_map_1
parameters
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns migrated_dns_map_1
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
!
service-policy global_policy global
! 

To add icmp inspection.

FW-ASA(config)# policy-map global_policy
FW-ASA(config-pmap)# class inspection_default
FW-ASA(config-pmap-c)# inspect icmp

Cisco PIX Add VPN Policy

Create Phase 1 Policy :

isakmp policy 10 authentication pre-share
isakmp policy 10 encryption 3des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 3600

Create Transform-set for Encryption being used
:

crypto ipsec transform-set minimal esp-null esp-md5-hmac
crypto ipsec transform-set secure esp-3des esp-md5-hmac


Create a nonat access-list
:

access-list nonat permit ip 172.31.0.0 255.255.0.0 192.168.0.0 255.255.0.0

Create Access-list for allowed network Source & Destination :

access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.178.0 255.255.255.0


Create Crypto Map :

crypto map armadillo 880 ipsec-isakmp
crypto map armadillo 880 match address 880
crypto map armadillo 880 set peer 2.2.2.2
crypto map armadillo 880 set transform-set secure

Create a Preshared-Key :

isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255


Assign Crypto Map to Interface
:

crypto map armadillo interface outside
isakmp enable outside

Allow IPSEC traffic into Pix from public facing interface :

sysopt connection permit-ipsec

Summarize rule for each additional vpn to be added :

access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.178.0 255.255.255.0

crypto map armadillo 880 ipsec-isakmp
crypto map armadillo 880 match address 880
crypto map armadillo 880 set peer 2.2.2.2
crypto map armadillo 880 set transform-set secure
isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255

To remove a VPN addittional policy :

no access-list nonat permit ip 172.31.0.0 255.255.0.0
192.168.0.0 255.255.0.0
!
no access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.166.0 255.255.255.0
!
no crypto map armadillo 880
!
no isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255

Cisco Wireless 857w Configuration

Cisco 857w allows only 1 broadcast configurable SSID.

See the exact configuration set out below :

Keep in mind this is what is needed for the wireless part of the configuration and inside
NAT statement via Route-Maps is not included
.


dot11 ssid COMMS
authentication open
authentication key-management wpa
guest-mode
wpa-psk ascii 0 test

interface Dot11Radio0
no ip address
!
encryption mode ciphers tkip
!
ssid test
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
world-mode dot11d country GB outdoor

!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no cdp enable
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding

!
interface Vlan1
description Bind_to_BVI1_Interface
no ip address
bridge-group 1
bridge-group 1 spanning-disabled

!
!
interface BVI1
description $ES_LAN$
ip address 192.168.194.1 255.255.255.0
ip nat inside
ip virtual-reassembly

!
ip dns server
ip nat inside source route-map NAT interface Dialer0 overload
!

route-map NAT permit 10
match ip address name NAT_ACL
!
ip access-list extended NAT_ACL
permit ip 192.168.194.0.0 0.0.0.255 any

!
bridge 1 protocol ieee
bridge 1 route ip

Linux PPTP Create Routing Script

To make sure our traffic gets routed to the other end of the tunnel, create a file called ip-up in /etc/ppp and add the following lines to this file:

#!/bin/sh
/sbin/route add -net REMOTE-NET-IP netmask REMOTE-NET-MASK dev ppp

eg :
route add -net 10.20.254.248 netmask 255.255.255.248 dev ppp0

In which you have to replace the IP-address and the mask with those of the subnet on the other end of the tunnel. If there is no network on the other side, but just the pptp server, you can use -host instead of -net. When your done, save the file and make it executable:

chmod +x /etc/ppp/ip-up

Now that all is set up we can start the tunnel:

Simplify Linux PPTP Server Configuration

yum install pptpd
apt-get pptpd

At this point, you should have a working pptp daemon.
This is a matter of personal preference, but I like to go ahead and start pptpd just to
make sure that the service is functioning and that it opens up the

PPTP port (1723) on the machine:

[user@hostname ~]# /etc/init.d/pptpd start
Starting pptpd:                                            [  OK  ]
!
[user@hostname ~]# telnet localhost 1723
Trying 127.0.0.1…
Connected to localhost.
Escape character is ‘^]’.

3 configuration files we need to worrry about.  They are :

/etc/pptpd.conf
/etc/ppp/options.pptpd

/etc/sysctl.conf

!

Let’s start with /etc/pptpd.conf

edit file :
nano /etc/pptpd.conf

# Currently using Microsoft Client Profile:
option /etc/ppp/MSpptpd-options

# Use linux client profile:
#option /etc/ppp/LXpptpd-options

#       Turns on (more) debugging to syslog
#debug
logwtmp
speed 57600

# Specifies the local and remote IP address ranges.
localip 10.20.254.254
# listen 10.20.254.254
# remoteip 10.10.10.249-253

!

Now, on to /etc/ppp/options.pptpd

As stated previously, options.pptpd is concered with how the VPN will authenticate
and encrypt.  Below are the options that you actually care about
:

name pptpd
require-mschap-v2
require-mppe-128
ms-dns 192.168.1.73
lock
nobsdcomp
auth
require-mppe
noipx ## you don’t need IPX
mtu 1490 ## may help your linux client from disconnecting
mru 1490
## may help your linux client from disconnecting

!

Lastly, /etc/sysctl.conf :

Edit this file and make sure the net.ipv4.ip_forward is set to 1.
This enables ip packet forwarding on the LAN which is required if you expect your
VPN users to be able to access any other resources on the network besides the
VPN server itself.

net.ipv4.ip_forward = 1

Setting up Users :

The chap-secrets file in the /etc/ppp/ directory.
vi /etc/ppp/chap-secrets

# client        server secret           IP addresses
rich              pptpd         apassword     80.40.0.0/13
geoff             pptpd         apassword     212.219.0.0/14

Test and Troubleshoot
:

/etc/init.d/pptpd stop
/etc/init.d/pptpd start

Sumarize Firewall Rules :

1. Allow GRE-47/pptp-1723 on internet facing router.
2. Configure a port forward for pptp-1723 to internal lan server ip address.
3. Allow GRE traffic out from pptp server.
4. Allow pptp tcp port 1723 out from pptp server with a source nat of 1723 to remote host or any
.

Zyxel MTU

ZyXEL routers. How do I change its MTU?

On Newer Zyxel Routers
Telnet to the Router by doing this:

Go to Start/Run…
type telnet 192.168.0.1
click OK button
Now enter your password… (the original is 1234). You will get a menu.

Go to menu 24.8 (type 24 Enter 8 Enter). This brings command line interface.
At command prompt type the following command followed by Enter:

ip adj wanif0 1300

This will lower the current MTU limit to 1300.

On Older Zyxel Routers :

telnet 192.168.0.1
Now enter your password

At the command Prompt :

eg. for MTU=1452
!
ras> ip ifconfig wanif0 xxx.xxx.xxx.xxx mtu 1400
ras> ip ifconfig enif0 xxx.xxx.xxx.xxx mtu 1400

where xxx.xxx.xxx.xxx is your current ip address which is the ‘inet’ field when you type

ras> ip ifconfig wanif0
ras> ip ifconfig enif0

This will lower the current MTU limit to 1400.
You can also add the above command into sys file in order to save settings on reboot of router :
!
sys edit autoexec.net
!
wan atm vc webRedirDis 1
sys errctl 0
ip ifconfig enif0 192.168.1.1 mtu 1400
sys trcl level 5
sys trcl type 1180
sys trcp cr 64 96
sys trcl sw off
sys trcp sw off
ip tcp mss 512
ip tcp limit 2
ip tcp irtt 65000
ip tcp window 2
ip tcp ceiling 6000
ip rip activate
ip rip merge on
ppp ipcp compress off
sys wdog sw on
ip icmp discovery enif0 off
bridge mode 1
sys quick enable
ether driver qroute 2
wan adsl rateadap on
wan adsl targetnoise 0x06
wan adsl driver dnmaxbits 10
EOF
 

Zyxel Configuration

Edit Zyxel Configuration

ras> sys edit autoexec

EDIT cmd: q(uit) x(save)d(delete)r(replace)

sys errctl 0
sys trcl level 5
sys trcl type 1180
sys trcp cr 64 96
sys trcl sw off
sys trcp sw off
ip tcp mss 512
ip tcp limit 2
ip tcp irtt 65000
ip tcp window 2
ip tcp ceiling 6000
ip rip activate
ipsec swSkipOverlapIp
swSkipOverlapIp on
ipsec timer chk_conn 0
ppp ipcp compress off
sys wdog sw on
ip icmp discovery enif
bridge mode 1
sys quick enable
wan adsl rate off
ether driver qroute 2
EOF

wan adsl rateadap on
Line-Rate Adaptive mechanism is for ADSL CPE system which try to
reach the maximum line rate that DSLAM can provide.

The drawback is ADSL CPE system has to force the line to drop and then sync up with
maximal rate. But actually the line rate is decided by DSLAM.
When this mechanism is turned on, CPE will monitor the line rate and
record maximum line rate. Once the line rate is lower than the
maximum value which CPE system recorded before, system will drop the
line and try to sync with better line rate.

Show Commands :

wan adsl opmode = DSL standard: ADSL_G.dmt
wan adsl driver setphy disp
wan adsl rateadap on
wan adsl chandata
wan adsl linedata near
wan adsl driver setphy disp
wan adsl driver info
wan adsl statuswan
wan adsl close
wan adsl open

DSL Operating Mode :

wan adsl opencmd gdmt
wan adsl opencmd adsl2
wan adsl opencmd adsl2+
wan adsl opencmd glite

Zyxel Noise Margin

you can also slightly tweak the target snr margin to connect a lower rate and increase stability.
With adslmax it only seems to work when increasing the snr.
 
wan adsl targetnoise X
 
where X is between 0xfa (-6) and 0x06 (+6) where each point is .5db of snr, so..
 
0xfa reduces the target by 3db,
0xfc reduces the target by 2db,
0x00 does nothing,
0x02 increases the target by 1db,

wan adsl targetnoise 0x06  =  command  is meant to increase the target SNR by 3db

wan adsl close
wan adsl driver dnmaxbits 10
wan adsl open

(where n is 0 to 15, 0 is slowest, 15 is fastest)

All the dnmaxbits 10 command seems to do is cap the rate per tone to “a” which affects the faster lower tones but not the higher ones which are probably the most marginal. What I really want to do is increase the SNR in exchange for a slower speed. The command  is meant to increase the target SNR by 3db but it makes no difference I can see.

wan adsl opmode ( check dsl standard status)
ADSL_G.dmt / ADSL2+

Depends on which ISP you are using.  you may need to change it to GDMT mode.

1 telnet to the zyxel = click ‘start’ then ‘run’ and type ‘telnet 192.168.1.1′
2 login (password is the same as the web interface)
3 type ’24’ – to access the system maintainence menu
4 type ‘8’ – to access the command line
5 type ‘wan adsl opencmd gdmt’ – sets the adsl to gdmt.
6 save, exit, then power off the modem and power it back on