Networking-Blog

My WordPress Blog

Cisco PIX/ASA 8.3 Command Changes {NAT / Global / Access-List}

NAT and Global commands.

Basically there is no more global command, and we are now a lot more reliant on object groups.

If you are port forwarding (Static PAT) then the dns re-write will no longer work.

NAT 0 (or no nat) no longer exists.

OLD – Regular PAT – 1 External IP to many internal IP addresses

nat (inside) 1 0 0
global (outside) 1 interface

NEW – Regular PAT – 1 External IP to many internal IP addresses

object network obj_any
subnet 0.0.0.0 0.0.0.0
nat (inside,outside) dynamic interface

OLD – Static PAT (Port Forwarding)

access-list inbound extended permit tcp any interface outside eq smtp
access-list inbound extended permit tcp any interface outside eq www
access-list inbound extended permit tcp any interface outside eq 3389
static (inside,outside) tcp interface www 10.254.254.5 www netmask 255.255.255.255
static (inside,outside) tcp interface smtp 10.254.254.5 smtp netmask 255.255.255.255
static (inside,outside) tcp interface 3389 10.254.254.5 3389 netmask 255.255.255.255

NEW – Static PAT (Port Forwarding)

access-list inbound extended permit tcp any object obj-10.254.254.5 eq smtp
access-list inbound extended permit tcp any object obj-10.254.254.5 eq www
access-list inbound extended permit tcp any object obj-10.254.254.5 eq 3389
object network obj-10.254.254.5
host 10.254.254.5
object network obj-10.254.254.5-01
host 10.254.254.5
object network obj-10.254.254.5-02
host 10.254.254.5
object network obj-10.254.254.5
nat (inside,outside) static interface service tcp www www

OLD – No NAT (seen mainly – but not always – on VPN traffic)

nat (inside) 0 access-list EXEMPT
access-list EXEMPT extended permit ip 10.254.254.0 255.255.255.0 172.16.254.0 255.255.255.0

NEW – No NAT

object network obj-10.254.254.0
subnet 10.254.254.0 255.255.255.0
object network obj-172.16.254.0
subnet 172.16.254.0 255.255.255.0
nat (inside,any) source static obj-10.254.254.0 obj-10.254.254.0 destination static obj-172.16.254.0 obj-172.16.254.0

Access Lists

For as long as I can remember when you allowed access to an IP address on a PIX/ASA you allowed access to its translated IP address, NOW YOU DO NOT, you allow access to its “Pre-translation address”

OLD Access List and Static NAT

access-list inbound extended permit ip any host 123.123.123.123 eq www
access-group inbound in interface outside
static (inside,outside) 123.123.123.123 10.254.254.5 netmask 255.255.255.255

NEW Access List and Static NAT

access-list inbound extended permit ip any host 10.254.254.5
access-group inbound in interface outside
object network obj-10.254.254.5
host 10.254.254.5
nat (inside,outside) static 123.123.123.123

Cisco PIX Add VPN Policy

Create Phase 1 Policy :

isakmp policy 10 authentication pre-share
isakmp policy 10 encryption 3des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 3600

Create Transform-set for Encryption being used
:

crypto ipsec transform-set minimal esp-null esp-md5-hmac
crypto ipsec transform-set secure esp-3des esp-md5-hmac


Create a nonat access-list
:

access-list nonat permit ip 172.31.0.0 255.255.0.0 192.168.0.0 255.255.0.0

Create Access-list for allowed network Source & Destination :

access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.178.0 255.255.255.0


Create Crypto Map :

crypto map armadillo 880 ipsec-isakmp
crypto map armadillo 880 match address 880
crypto map armadillo 880 set peer 2.2.2.2
crypto map armadillo 880 set transform-set secure

Create a Preshared-Key :

isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255


Assign Crypto Map to Interface
:

crypto map armadillo interface outside
isakmp enable outside

Allow IPSEC traffic into Pix from public facing interface :

sysopt connection permit-ipsec

Summarize rule for each additional vpn to be added :

access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.178.0 255.255.255.0

crypto map armadillo 880 ipsec-isakmp
crypto map armadillo 880 match address 880
crypto map armadillo 880 set peer 2.2.2.2
crypto map armadillo 880 set transform-set secure
isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255

To remove a VPN addittional policy :

no access-list nonat permit ip 172.31.0.0 255.255.0.0
192.168.0.0 255.255.0.0
!
no access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.166.0 255.255.255.0
!
no crypto map armadillo 880
!
no isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255

Cisco PIX Port forward

BTNET router is Internet facing and have a Cisco Pix connected to the inside Lan.
Need to port forward LDAP traffic to a Server sitting behind the Pix on the inside interface.

btnet:

ip nat inside source static udp 195.99.246.3 389 interface Serial1/0:0.1 389
ip nat inside source static tcp 195.99.246.3 389 interface Serial1/0:0.1 389
!
Extended IP access list 101
4 permit udp any any eq 389
5 permit udp any any eq 389
!

pix:

Interface ip Addresses:

ip address outside 195.99.246.3 255.255.255.240
ip address inside 172.16.2.253 255.255.255.0
!

name 172.16.2.50 MailServer
!
access-list outside_access_in permit udp any interface outside eq 389
access-list outside_access_in permit tcp any interface outside eq ldap
!

Static Port Forward:

static (inside,outside) tcp interface 389 MailServer 389 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 389 MailServer 389 netmask 255.255.255.255 0 0
!

Diagnostics testing:

from external source internet:
!
telnet 195.99.246.3 389

On Pix:

show access-list outside_access_in
!
access-list outside_access_in line 14 permit udp any interface outside eq 389 (hitcnt=0)
access-list outside_access_in line 15 permit tcp any interface outside eq ldap (hitcnt=6)

B00m…counter hits…(hitcnt=6)