Tuesday, August 21, 2012

Failover and transparent mode


  • You can configure failover on an emulated ASA, but it doesn't appear to work 100%.
    • You can create 'failover' groups and attach contexts to each failover group. This enabled one firewall to be active for x contexts and another firewall to be secondary for y contexts.
    • This is where it would be nice to have access to physical ASAs
    • You can enable link based and/or lan based failover. 
    • When configure the link IP, you configure the IP address as the same on both boxes, with the standby configured as well. The priority/preemption will determine the master
    • For the most part, failover seemed pretty straight forward
  • Transparent firewall
    • Enabled with 'firewall transparent'
    • 8.4 (and possibly 8.3) changes the configuration. Instead of just 'ip address x.x.x.x', you attach interfaces to bridge groups, and then give the ARP ip address to interface BVI
      • I say 'ARP ip address' because even though the firewall is operating in transparent mode, you must still configure an IP address on the ASA for the purpose of ARP. 
      • You can configure the Management interface independently of the bridge IP address - this is used for management access only.
    • I've realized that transparent firewall just doesn't work very well in GNS3. I will be renting rack time to practice transparent firewall and coming back to this and failover later.
  • Fragmented Traffic
    • To disable fragment traffic, you set the maximum fragments to 1.
      • By default, the security appliance accepts up to 24 fragments to reconstruct a full IP packet. Based on your network security policy, you should consider configuring the security appliance to prevent fragmented packets from traversing the security appliance by entering the fragment chain 1 interface command on each interface. Setting the limit to 1 means that all packets must be whole; that is, unfragmented. - Cisco ASA 8.0 Command Reference - Fragment
    • To test, simply send a packet larger than the MTU
  • Handling Application Issues
    • DNS Doctoring
      • Domain lookup to servers on the inside will reply with outside address - doctoring can fix this issue by way of the 'alias' command. You must also disable proxy arp with the 'sysopt noproxyarp inside' command.
      • Example
      • alias (inside) 10.10.10.10 99.99.99.99 255.255.255.255
        
        !--- This command sets up DNS Doctoring. It is initiated from the clients in
        !--- the "inside" network. It watches for DNS replies that contain
        !--- 99.99.99.99. Then it replaces the 99.99.99.99 address with the 10.10.10.10
        !--- address in the "DNS reply" sent to the client PC. - Cisco - Understanding the Alias command
    • IDENT queries over new TCP connection (FTP/SMTP)
      • To permit these queries for inside users, enable 'service resetinbound'
      • To permit these queries for inside servers, enable 'service resetoutside'
      • I see these two as being important - something that will be snuck in the requirements, and easily forgotten, thus missing out on the points for two simple commands!
  • BGP through the FW
    • BGP is not supported on the firewall but there are certainly instances where you need to establish BGP through the firewall
    • R1 is the inside host - 136.1.121.1. R2 is the outside host 136.1.122.2. Configure eBGP peering between R1 and R2.
    • The scenario had you build a static nat for the inside interface
      • static (inside,outside) 136.1.122.1 136.1.121.1
    • From the outside, you then establish a BGP peering to the NAT address
    • This obviously requires ebgp multi-hop
    • The peering comes up without an issue, but your routes are un-reachable - the next-hop of the routes received on the outside peer, are the inside address of the inside host - 136.1.121.1.
    • You create a route-map that sets the next-hop to the NAT address (136.1.122.1) and apply to the neighbor
  • Multicast Routing across the FW
    • Enabled with multicast-routing
    • PIM enabled by default
    • Configure RP with 'pim rp-address x.x.x.x'
    • There is nothing specific needed to do outside of what is already done on an IOS device - although this scenario is showing my 'rust' when it comes to multicast
      • Make sure to enable pim on relevant interfaces
      • Make sure to advertise the RP loopback address
    • I wasn't getting my S,G , my pings were failing and my incoming/outgoing interfaces were NULL. Guess I should have checked to make sure the routes were there first - forgot to enable RIP on the FW!
I think I will stop here. Was still hoping to be farther along, but I realize you can't rush these things. Being only 15% of the way through is tough to swallow - especially when I just go confirmation that my payment for my lab went through! I hope to make a serious dent on Thursday when I study from home, and Sunday morning. More updates to come.

Wednesday, August 15, 2012

NAT NAT NAT and more NAT....


  • ASA can filter ICMP with a simple 'icmp' command. With this, you can permit/deny ICMP based on the ICMP type and interface. This applies to traffic traversing the firewall.
  • Filtering services was next ...
    • url-server (dmz) host 10.0.0.100 -  configures a websense filtering server on the specified interface
    • The filter command configures filtering services with many options. Interesting note - you can shorthand the any address - filter activex www 0 0 0 0 - which is source network, mask foreign network, mask.
    • There are options to allow the traffic in the event the URL Server is down. There are other options like proxy-block, interact-block, etc. I have read a lot of the cisco documentation on ASA but I would say this is an initial weak point. I will be hitting the documentation on filtering.
  • NAT is a very tricky subject. The lab blueprint states ASA 8.x, but with NAT there are different configurations depending on if it is 8.2 and below, or 8.3 or 8.4. It appears that 8.0.x is the version that is used in the lab....great, my ASA is running 8.4....now off to create 4 ASAs in my lab - two 8.0 and two 8.4...
    • nat-control requires that all traffic from a higher security interface to a lower security interfaces requires a nat rule before being allowed 
    • nat (global) creates pools
    • You assign NAT identifiers to the global pools
    • To complete the dynamic nat, just say what you want to nat, use the same NAT identifier and off you go..
      • global (outside) 1 136.1.122.100-136.1.122.110
      • nat (inside) 1 136.1.121.0 255.255.255.0
    • Static NAT has a similar configuration using the 'static' keyword
    • For some reason, I always transpose either the interfaces or the networks in a NAT statement. Taking a break from hands-on, and going to re-read the NAT configuration guide.
      • "static NAT allows a remote host to initiate a connection to a translated host (if an access list exists that allows it), while dynamic NAT does not. "
      • "clear local-host" is used to remove static NAT translations that are currently in use "clear xlate" is only used for dynamic translations
These were just some of the notes I took over a few days of studying. Other items such as failover and multi context firewalls seemed pretty straight forward. I still need to hunker down on NAT, because I still get confused with whats inside/outside and the syntax.
Still way to much time building/configuring/fixing things in my lab outside of the actual devices. I've made it through about 10% of INE volume 1. Overall, not too bad but the typos/mistakes/whatever-you-want-to-call them are extremely frustrating when you are trying to get something to work.
I hope to be back at it this Sunday for a couple of hours...

Saturday, August 11, 2012

Continuing INE Security Volume 1

I hate nothing more than having to spend time doing something other than studying. Turns out, I needed IIS/FTP/Telnet servers installed on the Windows 2003 box. Problem is, I am not where the server is and couldn't get the 2003 CD in the server. Anyway, I installed a couple of free utilities and moved on.

  • Access lists - these are similar to IOS, but without the 'ip access-list' context.
  • Object Groups - When creating a service group, you need to specify tcp, udp, tcp-udp or default. Under default, you can specify other protocols than tcp and udp or a combination of such.
    • The syntax threw me for a loop as it is something I haven't really dealt with before. 
    • You can also nest the object groups
    • After creating the object-group, you add the objects such as service-object, port-object, etc.
    • You can then reference these object groups in the ACL - but you need to place them in the correct location.
ASA1# sh run object-group 
object-group network SERVERS
 network-object host 10.0.0.100
object-group network ROUTERS
 network-object 136.1.121.0 255.255.255.0
object-group icmp-type COMMON_ICMP
 icmp-object echo
 icmp-object echo-reply
 icmp-object time-exceeded
 icmp-object unreachable
object-group service TRC_PORTS udp
 port-object range 33434 33464
object-group service SERVER_PORTS tcp
 port-object eq www
 port-object eq ftp
object-group service ROUTER_PORTS tcp
 port-object eq telnet
 port-object eq ssh
 port-object eq 7001
ASA1# sh run access-list 
access-list OUTSIDE_IN extended permit icmp any any object-group COMMON_ICMP 
access-list OUTSIDE_IN extended permit udp any any object-group TRC_PORTS 
access-list OUTSIDE_IN extended permit tcp any object-group SERVERS object-group SERVER_PORTS 
access-list OUTSIDE_IN extended permit tcp any object-group ROUTERS object-group ROUTER_PORTS 
access-list OUTSIDE_OUT extended permit icmp any any object-group COMMON_ICMP 
access-list OUTSIDE_OUT extended permit udp any any object-group TRC_PORTS 
access-list OUTSIDE_OUT extended permit tcp any any object-group ROUTER_PORTS 
access-list OUTSIDE_OUT extended permit tcp any any object-group SERVER_PORTS 
    • For those of you that have never worked on an ASA before, you can't just 'no ip access-list TST'. You have to use the 'clear configure access-list TST' instead.
  • There is no access-group like command like IOS for vty/remote access. There is just a simple 'telnet' and 'ssh' command. You configure what networks on what interfaces are allowed to access that particular service. ADSM is similar using the 'http' command. Don't think to use an access-list here, which was my mistake. And weird...
And with that...I didn't make it much farther. After fighting with my windows server, and then fighting with ASDM, I only made it through another 12 pages. Hoping to get some more work in tomorrow.

Thursday, August 2, 2012

August 2012 Update

Looks like it is time to knock the cobwebs off this blog.....


As an overall update, I abandoned my CCIE Service Provider after failing my exam last year. With the recent update, and being unable to get my hands on the equipment required, it seemed an uphill battle at the time. Now that the workbooks are upgraded, and various vendors have equipment ready to rent, I would like to re-visit CCIE-SP in the future but....


For now, I am indeed working on my CCIE security. I do seem doomed to these things. When I first started my R&S, the test was changed right after my first attempt. As you may already know, I got real close on that attempt. I was forced to start back at page one to prepare for CCIE R&S 4.0. I started down the SP track, only to have the exam completely overhauled before I really even started. Now shortly after I start studying for Security, they have announced another refresh. 


I am not complaining here - I think updating the exams to reflect today's requirements of a network engineer is important. My timing just stinks! With that being said, I have started to study the security track based on the current blueprint and I have scheduled my lab exam for November.


I passed my Security written back in April. Did not do much following that other than setting up my lab. Here are some details on my lab...


1 - Quad Processor Dual Core Opteron Server w/ 16GB of memory running FC16
1 - Cisco 3750 Breakout switch
1 - Cisco 3560
1 - Cisco 3550


With this hardware, I run GNS3 on the server. GNS3, in combination with other tools, is capable of running 3725 Routers, Cisco ASA, Cisco IPS as well as several VMs to function as ACS and a XP workstation.


It took me quite some time to get this up and working and I didn't keep great notes, but if there is something specific you need help me, let me know and I will see what I can do to help.


I have made it about 20 pages into the INE Security Workbook Volume 1. So far, it just covers basic security like setting security levels, setting up routing protocols with security, etc. Nothing that different that the R&S track, just adapting to the ASA infrastructure. I hope to really start making a dent but right now I am in the middle of a major code upgrade to our Nexus infrastructure at work - scheduled for next weekend.


Other than that, I passed the Cisco Data Center Unified Fabric Solutions Design exam at Cisco Live in San Diego. Making me Cisco Data Center Networking Infrastructure Design Specialist. I was excited to pass, but ultimately it was just about using my free voucher at Cisco Live.


For now, I am off. Hopefully to return in a few weeks with some lab study notes!

Thursday, June 16, 2011

Welcome back!

Well judging by the responses, I see there are some of you left out there. As I mentioned before, I'm going down the Service Provider 3.0 path. I kind of wished I started in the 2.0 track, but I can't change that now. The biggest hurdle is the lack of study resources, and rack time. Well, over at the IEOC Forums there has actually been a successful pass of the version 3 blueprint. That person has some service provider experience, but also used the Cisco provided practice labs (from the SPv3 study group) as well as some old material from the training vendors such as INE. And apparently, GigaVelocity will soon be offering SPv3 rack rentals!

So I've loaded up a new server to run my dynamips routers, ordered the SP v2 workbooks from INE (hoping they update to 3.0!) and using as much of the resources from Antonio Soares mini-labs as I can. I plan to just do the scenarios, read the DocCD and give it a try. I've got my written scheduled for July during Cisco Live so I need to get as much written studying done as possible.

Hopefully one of the vendors soon update their materials to cover the new blueprint. Until then, I plan to go at it alone hoping this isn't as difficult or as time consuming as the R&S. I don't have any real world experience in a true service provider environment, but I do work for a large company that runs their own MPLS network with service such as VPRN, VPLS, VPWS, MPLS-TE, RSVP, etc.

I also need to fit time in to finish my Alcatel-Lucent NRS-II and SRA certifications, but since I can't resume those studies until July, may as well stay sharp and get back on the Cisco track!

Wednesday, June 15, 2011

Anyone out there?

Just checking to see if anyone is out there. I've decided to go for CCIE Service Provider 3.0 and trying to determine how beneficial the blogging will be this time around...

Monday, July 12, 2010

CCIE#26439

.......still in amazement.....


CCIE#26439