Networking-Blog

My WordPress Blog

TCP State bypass on a Cisco ASA

We have a few remote sites that directly connect to the primary data centre with fibre
optic cables. A backup connection is provided using MPLS.

StateLess

 

If the fibre optic cable is cut (thankfully a not too common event) traffic is rerouted through
the managed MPLS network and enters the data centre through an ASA firewall.

Because the ASA has no information in its state table about in-flight connections, the
TCP packets are dropped, temporarily disrupting the operation of the remote site.

For this scenario and for others where asymmetric traffic flow can occur it is possible
to configure the ASA to bypass TCP state checking. Note that the traffic still has to be
allowed by access-lists.

Step 1 – Identify the traffic

The first step is to identify the traffic for which you want to bypass TCP state inspection.
This is done by creating an access list. In this example traffic flowing between subnets
10.1.0.0/16 and 10.2.0.0/16 is identified:

access-list StatelessTraffic remark Outbound Traffic
access-list StatelessTraffic extended permit tcp 10.1.0.0 255.255.0.0 10.12.0.0 255.255.0.0
log disable
access-list StatelessTraffic remark Inbound Traffic
access-list StatelessTraffic extended permit tcp 10.2.0.0 255.255.0.0 10.1.0.0 255.255.0.0
log disable

 

Step 2 – Create a class map

A class map is created to match traffic using the access-list created in step 1

class-map tcp_bypass 
match access-list StatelessTraffic

Step 3 – Create the policy maps

A policy map defines the actions to be taken for traffic matching specified class maps.
The policy map is applied to one or more interfaces or can be applied as a global policy.
In this example two policy maps are used, one for the outgoing traffic (entering the
Inside interface) and one for the incoming traffic (entering the MPLS interface):

policy-map Inside-policy 
class tcp_bypass  
set connection timeout idle 0:15:00   
set connection advanced-options tcp-state-bypass

policy-map MPLS-policy 
class tcp_bypass  
set connection timeout idle 0:15:00   
set connection advanced-options tcp-state-bypass

The two policies apply two settings for matching traffic. The first set statement modifies
the idle timeout from the default (usually one hour) to 15 minutes (see below). The
second set statement requests that state inspection of matching TCP traffic be bypassed.

Step 4 – Apply the policy maps to the interfaces

The last step is to apply the policy maps to the appropriate interfaces, in this case Inside
and MPLS:

service-policy Inside-policy interface Inside 
service-policy MPLS-policy interface MPLS

Idle Timeout Interval

The idle timeout interval is used to remove entries from the ASA state table for any
connections which have been idle for a specified time, usually one hour. Normally TCP
entries will be deleted when the ASA sees that the connection has been terminated
(FIN or RST). However when TCP state bypass is enabled, this check is not done and
all TCP sessions will remain in the state table until the idle timeout is reached.
Reducing the idle timeout to 15 minutes will delete closed sessions earlier and reduce
memory requirements.

Limitations

There are a number of limitations introduced when TCP bypass is enabled on an ASA.
You should refer to the latest Cisco documentation to understand how they may impact
your security before using this feature. In our case we only enable TCP bypass for traffic in 
fairly rare and short lived cases and accept the limitations to provide a seamless failover
to our remote users.

Notes on ASA 8.3 NAT

Cisco ASA 8.3 has introduced major changes in how NAT is configured and operates.

Here are some quick notes that I have gathered for my reference.  Feel free to post any
additional comments and notes you may have to share
:

COMMANDS

show run objects

(Displays network and service objects that are in the running confg)

show run object id

(Displays a specific object)

show run nat

(Displays running config NAT configurations)

show nat

(Displays NAT policies and counters)

Use packet-tracer for testing NAT (and other things)

packet-tracer input inside tcp 10.0.0.40 4444 198.133.219.25 80

    Configure Auto-NAT:

object network inside
   subnet 192.168.1.0 255.255.255.0
   nat (inside,outside) dynamic interface

Note: This will configure PAT onto the outside interface for the inside subnet,
while at the same time configuring the network object for the inside subnet
.

    Configure Twice (manual) NAT:
nat (inside,outside) source dynamic inside-net translated-ip destination
static cisco-dot-com cisco-dot-com

Note: You must first define the network objects for the source and destination before configuring
manual NAT.

In this example, the source IP address of the inside host is translated to “translated-ip” only when
the dynamic host is sending a packet that is destined to “cisco-dot-com”. cisco-dot-com is entered
twice because we are not translating the destination. If we wanted to translate the destination,
we would do it here.

    Exempt subnets from NAT because of VPN tunnel :
nat (inside,outside) static inside-net inside-net destination static
vpn-subnets vpn-subnets

This statement will catch traffic on the inside trying to go to the outside. Traffic that matches the
source and destination is operated on but no change is made
.

    General Notes :

ASA 8.3 has two types of NAT: Auto-NAT and Twice (manual) NAT. You can use Auto-NAT for
most NAT/PAT operations, except for ones that need to make a decision based upon the
destination address of a packet
.

With ASA 8.3, a new change called “Real IP” was introduced. Real IP means that NAT translation
happens BEFORE a ACL is checked. Therefore ACLs must contain the real IP address of the host
that the inbound packet is headed towards. In other words, do not write the ACL to match on the
“mapped” IP address. The real IP address is normally a non-routable IP address
.

!
!

Regular Static NAT :

object network srv-172.16.66.100
host 172.16.66.100
nat (inside,outside) static 209.165.xxx.xxx

Static PAT :

object network srv-172.16.66.101
host 172.16.66.101
nat (inside,outside) static interface service tcp 25 25

Regular Dynamic NAT :

object network obj-VLANXX-192.168.100.0
subnet 192.168.100.0 255.255.255.0
nat (inside,outside) dynamic interface

Cisco PIX/ASA 8.3 Command Changes {NAT / Global / Access-List}

NAT and Global commands.

Basically there is no more global command, and we are now a lot more reliant on object groups.

If you are port forwarding (Static PAT) then the dns re-write will no longer work.

NAT 0 (or no nat) no longer exists.

OLD – Regular PAT – 1 External IP to many internal IP addresses

nat (inside) 1 0 0
global (outside) 1 interface

NEW – Regular PAT – 1 External IP to many internal IP addresses

object network obj_any
subnet 0.0.0.0 0.0.0.0
nat (inside,outside) dynamic interface

OLD – Static PAT (Port Forwarding)

access-list inbound extended permit tcp any interface outside eq smtp
access-list inbound extended permit tcp any interface outside eq www
access-list inbound extended permit tcp any interface outside eq 3389
static (inside,outside) tcp interface www 10.254.254.5 www netmask 255.255.255.255
static (inside,outside) tcp interface smtp 10.254.254.5 smtp netmask 255.255.255.255
static (inside,outside) tcp interface 3389 10.254.254.5 3389 netmask 255.255.255.255

NEW – Static PAT (Port Forwarding)

access-list inbound extended permit tcp any object obj-10.254.254.5 eq smtp
access-list inbound extended permit tcp any object obj-10.254.254.5 eq www
access-list inbound extended permit tcp any object obj-10.254.254.5 eq 3389
object network obj-10.254.254.5
host 10.254.254.5
object network obj-10.254.254.5-01
host 10.254.254.5
object network obj-10.254.254.5-02
host 10.254.254.5
object network obj-10.254.254.5
nat (inside,outside) static interface service tcp www www

OLD – No NAT (seen mainly – but not always – on VPN traffic)

nat (inside) 0 access-list EXEMPT
access-list EXEMPT extended permit ip 10.254.254.0 255.255.255.0 172.16.254.0 255.255.255.0

NEW – No NAT

object network obj-10.254.254.0
subnet 10.254.254.0 255.255.255.0
object network obj-172.16.254.0
subnet 172.16.254.0 255.255.255.0
nat (inside,any) source static obj-10.254.254.0 obj-10.254.254.0 destination static obj-172.16.254.0 obj-172.16.254.0

Access Lists

For as long as I can remember when you allowed access to an IP address on a PIX/ASA you allowed access to its translated IP address, NOW YOU DO NOT, you allow access to its “Pre-translation address”

OLD Access List and Static NAT

access-list inbound extended permit ip any host 123.123.123.123 eq www
access-group inbound in interface outside
static (inside,outside) 123.123.123.123 10.254.254.5 netmask 255.255.255.255

NEW Access List and Static NAT

access-list inbound extended permit ip any host 10.254.254.5
access-group inbound in interface outside
object network obj-10.254.254.5
host 10.254.254.5
nat (inside,outside) static 123.123.123.123

Cisco ASA Track Backup Route

interface Ethernet0
nameif outside
security-level 0
ip address 10.200.159.2 255.255.255.248
!
interface Ethernet1
nameif backup

!— The interface attached to the Secondary ISP.
!— “backup” was chosen here, but any name can be assigned.

security-level 0
ip address 10.250.250.2 255.255.255.248
!

interface Ethernet2
nameif inside
security-level 100
ip address 172.16.1.163 255.255.255.0
!
!

global (outside) 1 interface
global (backup) 1 interface

nat (inside) 1 172.16.1.0 255.255.255.0

!— NAT Configuration for Outside and Backup


route outside 0.0.0.0 0.0.0.0 10.200.159.1 1 track 1


!— Enter this command in order to track a static route.
!— This is the static route to be installed in the routing
!— table while the tracked object is reachable.  The value after
!— the keyword “track” is a tracking ID you specify.


route backup 0.0.0.0 0.0.0.0 10.250.250.1 254


!— Define the backup route to use when the tracked object is unavailable.
!— The administrative distance of the backup route must be greater than
!— the administrative distance of the tracked route.
!— If the primary gateway is unreachable, that route is removed
!— and the backup route is installed in the routing table
!— instead of the tracked route.

!
!

sla monitor 123
type echo protocol ipIcmpEcho 10.0.0.1 interface outside
num-packets 3
frequency 10

!— Configure a new monitoring process with the ID 123.  Specify the
!— monitoring protocol and the target network object whose availability the tracking
!— process monitors.  Specify the number of packets to be sent with each poll.
!— Specify the rate at which the monitor process repeats (in seconds).

sla monitor schedule 123 life forever start-time now

!— Schedule the monitoring process.  In this case the lifetime
!— of the process is specified to be forever.  The process is scheduled to begin
!— at the time this command is entered.  As configured, this command allows the
!— monitoring configuration specified above to determine how often the testing
!— occurs.  However, you can schedule this monitoring process to begin in the
!— future and to only occur at specified times.

!
track 1 rtr 123 reachability

!— Associate a tracked static route with the SLA monitoring process.
!— The track ID corresponds to the track ID given to the static route to monitor:
!— route outside 0.0.0.0 0.0.0.0 10.0.0.2 1 track 1
!— “rtr” = Response Time Reporter entry.  123 is the ID of the SLA process
!— defined above.

!
!

VERIFY

Displays the SLA commands in the configuration
:

show running-config sla monitor

sla monitor 123
type echo protocol ipIcmpEcho 10.0.0.1 interface outside
num-packets 3
frequency 10
sla monitor schedule 123 life forever start-time now

Displays the current configuration settings of the operation :

show sla monitor configuration

pix# show sla monitor configuration 123
IP SLA Monitor, Infrastructure Engine-II.
Entry number: 123
Owner:
Tag:
Type of operation to perform: echo
Target address: 10.0.0.1
Interface: outside
Number of packets: 3
Request size (ARR data portion): 28
Operation timeout (milliseconds): 5000
Type Of Service parameters: 0x0
Verify data: No
Operation frequency (seconds): 10
Next Scheduled Start Time: Start Time already passed
Group Scheduled : FALSE
Life (seconds): Forever
Entry Ageout (seconds): never
Recurring (Starting Everyday): FALSE
Status of entry (SNMP RowStatus): Active
Enhanced History:


Displays the operational statistics of the SLA operation
:

show sla monitor operational-state

Before the primary ISP fails, this is the operational state:

show sla monitor operational-state 123
Entry number: 123
Modification time: 13:59:37.824 UTC Thu Oct 12 2006
Number of Octets Used by this Entry: 1480
Number of operations attempted: 367
Number of operations skipped: 0
Current seconds left in Life: Forever
Operational state of entry: Active
Last time this entry was reset: Never
Connection loss occurred: FALSE
Timeout occurred: FALSE
Over thresholds occurred: FALSE
Latest RTT (milliseconds): 1
Latest operation start time: 15:00:37.825 UTC Thu Oct 12 2006
Latest operation return code: OK
RTT Values:
RTTAvg: 1       RTTMin: 1       RTTMax: 1
NumOfRTT: 3     RTTSum: 3       RTTSum2: 3

After the primary ISP fails (and the ICMP echos time out), this is the operational state:

show sla monitor operational-state

Entry number: 123
Modification time: 13:59:37.825 UTC Thu Oct 12 2006
Number of Octets Used by this Entry: 1480
Number of operations attempted: 385
Number of operations skipped: 0
Current seconds left in Life: Forever
Operational state of entry: Active
Last time this entry was reset: Never
Connection loss occurred: FALSE
Timeout occurred: TRUE
Over thresholds occurred: FALSE
Latest RTT (milliseconds): NoConnection/Busy/Timeout
Latest operation start time: 15:03:27.825 UTC Thu Oct 12 2006
Latest operation return code: Timeout
RTT Values:
RTTAvg: 0       RTTMin: 0       RTTMax: 0
NumOfRTT: 0     RTTSum: 0       RTTSum2: 0

Confirm the Backup Route is Installed (CLI Method)

Use the show route command to determine when the backup route is installed.
Before the primary ISP fails, this is the routing table:

show route

Gateway of last resort is 10.200.159.1 to network 0.0.0.0

S    64.101.0.0 255.255.0.0 [1/0] via 172.22.1.1, inside
C    172.22.1.0 255.255.255.0 is directly connected, inside
C    10.250.250.0 255.255.255.248 is directly connected, backup
C    10.200.159.0 255.255.255.248 is directly connected, outside
S*   0.0.0.0 0.0.0.0 [1/0] via 10.200.159.1, outside


After the primary ISP fails, the static route is removed,
and the backup route is installed, this is the routing table:

show route

Gateway of last resort is 10.250.250.1 to network 0.0.0.0

S    64.101.0.0 255.255.0.0 [1/0] via 172.22.1.1, inside
C    172.22.1.0 255.255.255.0 is directly connected, inside
C    10.250.250.0 255.255.255.248 is directly connected, backup
C    10.200.159.0 255.255.255.248 is directly connected, outside
S*   0.0.0.0 0.0.0.0 [254/0] via 10.250.250.1, backup

Troubleshoot

Debug Commands

Displays progress of the echo operation :

debug sla monitor
trace

The tracked object (primary ISP gateway) is up, and ICMP echos succeed.
The tracked object (primary ISP gateway) is down, and ICMP echos fail.

Displays errors that the SLA monitor process encounters :

debug sla monitor error

The tracked object (primary ISP gateway) is up, and ICMP succeeds.
The tracked object (primary ISP gateway) is down, and the tracked route is removed.

!— 10.0.0.1 is unreachable, so the route to the Primary ISP is removed.

Tracked Route is Removed Unnecessarily

If the tracked route is removed unnecessarily, ensure that your monitoring target
is always available to receive echo requests. In addition, ensure that the state
of your monitoring target (that is, whether or not the target is reachable) is
closely tied to the state of the primary ISP connection.


If you choose a monitoring target that is farther away than the ISP gateway,
another link along that route may fail or another device may interfere.
This configuration may cause the SLA monitor to conclude that the connection
to the primary ISP has failed and cause the security appliance to unnecessarily
fail over to the secondary ISP link.

For example, if you choose a branch office router as your monitoring target,
the ISP connection to your branch office could fail, as well as any other link
along the way. Once the ICMP echos that are sent by the monitoring operation fail,
the primary tracked route is removed, even though the primary ISP link is still active.

In this example, the primary ISP gateway that is used as the monitoring target is
managed by the ISP and is located on the other side of the ISP link.
This configuration ensures that if the ICMP echos that are sent by the monitoring
operation fail, the ISP link is almost surely down.

SLA Monitoring on ASA

Problem:

SLA monitoring does not work after the ASA is upgrade to version 8.0.

Solution:

The problem is possibly be due to the IP Reverse-Path command configured in the
OUTSIDE interface.
Remove the command in ASA and try to check the SLA Monitoring.


ASA 5505 Clear Configuration

• To erase the startup configuration, enter the following command:

hostname(config)# write erase

• To erase the running configuration, enter the following command:

hostname(config)# clear configure all

This command clears all the current configuration for the specified configuration command. If you only want to clear the configuration for a specific version of the command, you can enter a value for level2configurationcommand.

For example, to clear the configuration for all aaa commands, enter the following command:

hostname(config)# clear configure aaa

To clear the configuration for only aaa authentication commands, enter the following command:

hostname(config)# clear configure aaa authentication

Cisco ASA FTP Access-List

ASA Version 7.2(2)
!
hostname ASA-AIP-CLI
domain-name corp.com
enable password WwXYvtKrnjXqGbu1 encrypted
names
!
interface Ethernet0/0
 nameif Outside
 security-level 0
 ip address 192.168.1.2 255.255.255.0
!
interface Ethernet0/1
 nameif Inside
 security-level 100
ip address 10.1.1.1 255.255.255.0
!
interface Ethernet0/2
 nameif DMZ
  security-level 50
  ip address 172.16.1.12 255.255.255.0
!
interface Ethernet0/3
 no nameif
 no security-level
 no ip address
!
interface Management0/0
  no nameif
 no security-level
 no ip address
!

!--- Output is suppressed.


!--- Permit inbound FTP control traffic. 

access-list 100 extended permit tcp any host 192.168.1.5 eq ftp

!--- Permit inbound FTP data traffic.

access-list 100 extended permit tcp any host 192.168.1.5 eq ftp-data
!

!--- Command to redirect the FTP traffic received on IP 192.168.1.5
!--- to IP 172.16.1.5.

static (DMZ,outside) 192.168.1.5 172.16.1.5 netmask 255.255.255.255
access-group 100 in interface outside
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum 512

policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect netbios
  inspect rsh
  inspect rtsp
  inspect skinny
  inspect esmtp
  inspect sqlnet
  inspect sunrpc
  inspect tftp
  inspect sip
  inspect xdmcp
!

!--- This command tells the device to
!--- use the "global_policy" policy-map on all interfaces.

service-policy global_policy global

LAN Outbound FTP Access : 
access-list inside extended permit tcp host 10.1.1.254 any eq ftp Create Object group in order to tidy config : object-group service Bluecoatbypass tcp description Bypass for bluecoat server port-object eq echo port-object eq irc port-object eq ftp-data port-object range 3389 3389 port-object eq domain port-object range 8080 8080 port-object eq pop3 port-object eq ftp port-object eq www port-object eq https port-object eq 1935 port-object eq ssh ! Create Access-list : access-list inside extended permit tcp host 10.1.1.254 any object-group Bluecoatbypass
Verify : show access-list | grep ftp | grep 10.1.1.254 show service-policy inspect ftp show service-policy global