Sunday, November 7, 2010

Cisco ASA MPF URL Filtering

Within this tutorial will will look at 2 configuration examples in which we will use HTTP inspection within the Cisco ASA to allow access for certain hosts based on specific URL headers.

EXAMPLE 1

This example will show the required syntax to allows access to yahoo.com for any host within the network 10.1.1.0 255.255.0.0. HTTP traffic for any other host is denied.
In addition to the commands below you will also need to grant the relevant access via your interface based ACL`s. This is because your HTTP traffic will first hit interface based ACL`s before reaching the ASA`s application inspection layer.
Your access-list will need to consist of a permit for http traffic from your host(s) through to any. An example would be :
access-list acl-inside-in extended permit tcp any any eq www
Steps
1. Create regular expressions
regex urlallow1 "yahoo\.com"
2. Define hosts that are either allowed access or not.
access-list acl-mpf-http1 extended permit tcp 10.1.1.0 255.255.0.0 any eq www
    access-list acl-mpf-http1 extended deny ip any any
3. Define match conditions - here we match any header that is not equal to the previous defined regular expressions (urlallow1).
class-map type inspect http match-all class-http1
match not request header host regex urlallow1
4. Assign previous access-lists to class-map.
class-map class-http-match1
match access-list acl-mpf-http1
5. Create policy map and assign the class map (class-http1). Against this class map an action is assigned.
policy-map type inspect http policy-http1
parameters
   class class-http1
      drop-connection log
6. Under the global_policy map,  assign the http inspection policy map against the match class map (class-http-match1) .
policy-map global_policy
class class-http-match1
    inspect http policy-http1
7. Assign global_policy to all interfaces.
service-policy global_policy global

EXAMPLE 2

This example will show the required syntax to allows access to yahoo.com for any host apart from 192.168.1.100.
In addition to the commands below you will also need to grant the relevant access via your interface based ACL`s. This is because your HTTP traffic will first hit interface based ACL`s before reaching the ASA`s application inspection layer.
Your access-list will need to consist of a permit for http traffic from your host(s) through to any. An example would be :
access-list acl-inside-in extended permit tcp any any eq www
Steps
1. Create regular expressions
regex urlallow1 "yahoo\.com"
2. Define hosts that are either allowed access or not.
access-list acl-mpf-http1 extended deny tcp host 192.168.1.100 any eq www
    access-list acl-mpf-http1 extended permit ip any any
3. Define match conditions - here we match any header that is not equal to the previous defined regular expressions (urlallow1).
class-map type inspect http match-all class-http1
match not request header host regex urlallow1
4. Assign previous access-lists to class-map.
class-map class-http-match1
match access-list acl-mpf-http1
5. Create policy map and assign the class map (class-http1). Against this class map an action is assigned.
policy-map type inspect http policy-http1
parameters
   class class-http1
      drop-connection log
6. Under the global_policy map,  assign the http inspection policy map against the match class map (class-http-match1) .
policy-map global_policy
class class-http-match1
    inspect http policy-http1
7. Assign global_policy to all interfaces.
service-policy global_policy global

Saturday, November 6, 2010

How do i include the cluster state within the ASA hostname

The prompt state command was introduced within 7.1. This short example shows you how to configure your ASA to include the cluster state within its name :

cisco-firewall# config t
cisco-firewall (config)# prompt hostname state 
cisco-firewall/act(config)#

Friday, November 5, 2010

How to clear an ASA`s configuration

You may find that there is a time in which you havent got access via the standard ASAOS CLI to change, amend or edit your current configuration.
In this example we will show you the steps required for removing the configuation via ROMMON mode.
Here are the steps :
1. Reboot the device

2. On boot hit `escape` so that you break the normal startup process and enter ROMMON.

3. Change the current confreg so that you can bypass the current startup config sing the command:
1.rommon #1>confreg 0x41
 
4. Reset the appliance with the boot command,
1.rommon #2>boot
 
5. You will then be presented with the ScreenOS CLI and the ASA having a completey clear config. Run the commands :

1.ciscoasa > en [when asked for password just press enter]
2.ciscoasa # conf t
3.ciscoasa (config)# config-register 0x01
4.ciscoasa (config)# copy run start
5.ciscoasa (config)# reload
 
6. Your ASA will now be rebooted and the device will be booted into a blank configuration.

Thursday, November 4, 2010

CheckPoint Firewall Commands

cphaprob stat List cluster status
cphaprob -a if List status of interfaces
cphaprob syncstat shows the sync status
cphaprob list Shows a status in list form
cphastart/stop Stops clustering on the specfic node
cp_conf sic SIC stuff
cpconfig config util
cplic print prints the license
cprestart Restarts all Check Point Services
cpstart Starts all Check Point Services
cpstop Stops all Check Point Services
cpstop -fwflag -proc Stops all checkpoint Services but keeps policy active in kernel
cpwd_admin list List checkpoint processes
cplic print Print all the licensing information.
cpstat -f all polsrv Show VPN Policy Server Stats
cpstat
Shows the status of the firewall 


fw tab -t sam_blocked_ips Block IPS via SmartTracker
fw tab -t connections -s
Show connection stats
fw tab -t connections -f  Show connections with IP instead of HEX
fw tab -t fwx_alloc -f Show fwx_alloc with IP instead of HEX 
fw tab -t peers_count -s Shows VPN stats
fw tab -t userc_users -s Shows VPN stats
fw checklic Check license details
fw ctl get int [global kernel parameter] Shows the current value of a global kernel parameter
fw ctl set int [global kernel parameter]  [value] Sets the current value of a global keneral parameter. Only Temp ; Cleared after reboot. 
fw ctl arp Shows arp table
fw ctl install Install hosts internal interfaces
fw ctl ip_forwarding Control IP forwarding
fw ctl pstat System Resource stats
fw ctl uninstall Uninstall hosts internal interfaces
fw exportlog .o Export current log file to ascii file
fw fetch Fetch security policy and install
fw fetch localhost Installs (on gateway) the last installed policy.
fw hastat Shows Cluster statistics
fw lichosts Display protected hosts
fw log -f Tail the current log file
fw log -s -e Retrieve logs between times
fw logswitch Rotate current log file
fw lslogs Display remote machine log-file list
fw monitor Packet sniffer
fw printlic -p Print current Firewall modules
fw printlic Print current license details
fw putkey Install authenication key onto host
fw stat -l     Long stat list, shows which policies are installed
fw stat -s Short stat list, shows which policies are installed
fw unloadlocal Unload policy
fw ver -k Returns version, patch info and Kernal info
fwstart Starts the firewall
fwstop Stop the firewall


fwm lock_admin -v
View locked admin accounts
fwm dbexport -f user.txt used to export users , can also use dbimport
fwm_start starts the management processes
fwm -p Print a list of Admin users
fwm -a Adds an Admin
fwm -r Delete an administrator
Provider 1
mdsenv [cma name] Sets the mds environment
mcd  Changes your directory to that of the environment.
mds_setup To setup MDS Servers
mdsconfig Alternative to cpconfig for MDS servers
mdsstat To see the processes status
mdsstart_customer [cma name]  To start cma
mdsstop_customer [cma name] To stop cma
cma_migrate To migrate an Smart center server to CMA
cmamigrate_assist If you dont want to go through the pain of tar/zip/ftp and if you wish to enable FTP on Smart center server
VPN
vpn tu                                            VPN utility, allows you to rekey vpn
vpn ipafile_check ipassignment.conf detail‏
Verifies the ipassignment.conf file
dtps lic show desktop policy license status
cpstat -f all polsrv show status of the dtps
vpn shell /tunnels/delete/IKE/peer/[peer ip] delete IKE SA
vpn shell /tunnels/delete/IPsec/peer/[peer ip] delete Phase 2 SA
vpn shell /show/tunnels/ike/peer/[peer ip] show IKE SA
vpn shell /show/tunnels/ipsec/peer/[peer ip] show Phase 2 SA
vpn shell show interface detailed [VTI name] show VTI detail

Debugging
fw ctl zdebug drop shows dropped packets in realtime / gives reason for drop

SPLAT Only
router Enters router mode for use on Secure Platform Pro for advanced routing options
patch add cd  Allows you to and upgrade your checkpoint software (SPLAT Only) 
backup Allows you to preform a system operating system backup
restore Allows you to restore your backup
snapshot Performs a system backup which includes all Check Point binaries. Note : This issues a cpstop.
VSX
vsx get [vsys name/id]           get the current context
vsx set [vsys name/id]           set your context
fw -vs [vsys id] getifs           show the interfaces for a virtual device
fw vsx stat -l           shows a list of the virtual devices and installed policies
fw vsx stat -v           shows a list of the virtual devices and installed policies (verbose)
reset_gw           resets the gateway, clearing all previous virtual devices and settings

Wednesday, November 3, 2010

Configure the Router with the CLI

To configure the router, including the routing protocols, router interfaces, network management, and user access, you must enter a separate mode called configuration mode. Do this by issuing the configure operational mode command.

In configuration mode, the command-line interface (CLI) provides commands to configure the router, load a text (ASCII) file that contains the router configuration, activate a configuration, and save the configuration to a text file.
This chapter discusses the following topics:

Tuesday, November 2, 2010

Additional Details about Specifying Statements and Identifiers

This section provides more detailed information about specifying statements and identifiers in configuration mode:

How to Specify Statements

This section provides more detailed information about CLI container and leaf statements so that you can better understand how the CLI displays them in a configuration and how you must specify them when creating ASCII configuration files.
Statements are shown one of two ways, either with braces or without:
  • Statement name and identifier, with one or more lower-level statements enclosed in braces:
< statement-name > < identifier > {
    statement; 
    additional-statements; 
}

  • Statement name, identifier, and a single identifier:
< statement-name > < identifier > identifier; 

The statement-name is the name of the statement. In the configuration example shown in the previous section, ospf and area are statement names.
The identifier is a name or other string that uniquely identifies an instance of a statement. The identifier is used when a statement can be specified more than once in a configuration. In the configuration example shown in the previous section, the identifier for the area statement is 0 and the identifier for the interface statement is so-0/0/0.
When specifying a statement, you must specify either a statement name or an identifier, or both, depending on the statement hierarchy.
You specify identifiers in one of the following ways:
  • identifier—The identifier is a flag, which is a single keyword.
  • identifier value—The identifier is a keyword, and the value is a required option variable.
  • identifier [value1 value 2 value3 ...]—The identifier is a set that accepts multiple values. The brackets are required when you specify a set of identifiers; however, they are optional when you specify only one identifier.
The following examples illustrate how statements and identifiers are specified in the configuration:
protocol {                                            # Top-level statement (statement-name).
    ospf {                                        # Statement under "protocol" (statement-name).
        area 0.0.0.0 {                                    # OSPF area "0.0.0.0" (statement-name identifier),
            interface so-0/0/0 {                                # which contains an interface named "so-0/0/0."
                hello-interval 25;                            # Identifier and value (identifier-name value). 
                priority 2;                            # Identifier and value (identifier-name value).
                disable;                            # Flag identifier (identifier-name).
            }
            interface so-0/0/1;                                # Another instance of "interface," named so-0/0/1,
        }                                    # this instance contains no data, so no braces
    }                                        # are displayed.
}
policy-options {                                            # Top-level statement (statement-name).
    term term1 {                                        # Statement under "policy-options" 
                                            # (statement-name value).
        from {                                    # Statement under "term" (statement-name).
            route-filter 10.0.0.0/8 orlonger reject;                                                                # One identifier ("route-filter") with
            route-filter 127.0.0.0/8 orlonger reject;                                                                # multiple values.
            route-filter 128.0.0.0/16 orlonger reject;
            route-filter 149.20.64.0/24 orlonger reject;
            route-filter 172.16.0.0/12 orlonger reject;
            route-filter 191.255.0.0/16 orlonger reject;
        }
        then {                            # Statement under "term" (statement-name).
            next term;                        # Identifier (identifier-name).
        }
    }
}

When you create an ASCII configuration file, you can specify statements and identifiers in one of the following ways. However, each statement has a preferred style, and the CLI uses that style when displaying the configuration in response to a configuration mode show command.
  • Statement followed by identifiers:
statement-name identifier-name [...] identifier-name value [...];

  • Statement followed by identifiers enclosed in braces:
statement-name { 
    identifier-name; 
    [...] 
    identifier-name value;
    [...]
}

  • For some repeating identifiers, you can use one set of braces for all the statements:
statement-name {
    identifier-name value1; 
    identifier-name value2; 
}

Monday, November 1, 2010

Using the CLI to Configure the Router

This section walks through an example of creating a simple configuration, illustrating how to use the CLI to create, display, and modify the software configuration for your system. The example used in this section creates the following configuration:
protocols {
    ospf {
        area 0.0.0.0 {
            interface so-0/0/0 {
                hello-interval 5;
                dead-interval 20;
            }
            interface so-0/0/1 {
                hello-interval 5;
                dead-interval 20;
            }
        }
    }
}

Shortcut

You can create this entire configuration with two commands:
[edit]
user@host# set protocols ospf area 0.0.0.0 interface so-0/0/0 hello-interval 5 dead-interval 20
[edit]
user@host# set protocols ospf area 0.0.0.0 interface so-0/0/1 hello-interval 5 dead-interval 20

Longer Configuration Example

The remainder of this section provides a longer example of creating the OSPF configuration. In the process, it illustrates how to use the different features of the CLI.
First, you enter configuration mode by issuing the configure top-level command:
user@host> configure 
entering configuration mode
[edit]
user@host# 

The prompt in braces shows that you are in configuration edit mode, at the top of the hierarchy. If you want to create the above configuration, you start by editing the protocols ospf statements:
[edit]
user@host# edit protocols ospf
[edit protocols ospf]
user@host# 

Now, add the OSPF area:
[edit protocols ospf]
user@host# edit area 0.0.0.0
[edit protocols ospf area 0.0.0.0]
user@host# 


Next, add the first interface:
[edit protocols ospf area 0.0.0.0]
user@host# edit interface so0
[edit protocols ospf area 0.0.0.0 interface so-0/0/0]
user@host# 

You now have four nested statements. Next, set the hello and dead intervals. Note that command completion (enter a tab or space) and context-sensitive help (type a question mark) are always available.
[edit protocols ospf area 0.0.0.0 interface so-0/0/0]
user@host# set ?
Possible completions:
+ apply-groups                                    Groups from which to inherit configuration data
> authentication-key                                    Authentication key
  dead-interval                                    Dead interval (seconds)
  disable                                    Disable OSPF on this interface
  hello-interval                                    Hello interval (seconds)
  interface-type                                    Type of interface
  metric                                    Interface metric (1..65535)
> neighbor                                    NBMA neighbor
  passive                                    Do not run OSPF, but advertise it
  poll-interval                                    Poll interval for NBMA interfaces
  priority                                    Designated router priority
  retransmit-interval                                    Retransmission interval (seconds)
  transit-delay                                    Transit delay (seconds)
  transmit-interval                                     OSPF packet transmit interval (milliseconds)
[edit protocols ospf area 0.0.0.0 interface so-0/0/0]
user@host# set hello-interval 5
[edit protocols ospf area 0.0.0.0 interface so-0/0/0]
user@host# set dead-interval 20
[edit protocols ospf area 0.0.0.0 interface so-0/0/0]
user@host# 

You can see what is configured at the current level with the show command:
[edit protocols ospf area 0.0.0.0 interface so-o]
user@host# show 
hello-interval 5;
dead-interval 20;
[edit protocols ospf area 0.0.0.0 interface so-0/0/0]
user@host# 

You are finished at this level, so back up a level and take a look at what you have so far:
[edit protocols ospf area 0.0.0.0 interface so-0/0/0]
user@host# up 
[edit protocols ospf area 0.0.0.0]
user@host# show 
interface so-0/0/0 {
    hello-interval 5;
    dead-interval 20;
}
[edit protocols ospf area 0.0.0.0]
user@host# 

The interface statement appears because you have moved to the area statement.
Now, add the second interface:
[edit protocols ospf area 0.0.0.0]
user@host# edit interface so-0/0/1
[edit protocols ospf area 0.0.0.0 interface so-0/0/1]
user@host# set hello-interval 5
[edit protocols ospf area 0.0.0.0 interface so-0/0/1]
user@host# set dead-interval 20
[edit protocols ospf area 0.0.0.0 interface so-0/0/1]
user@host# up 
[edit protocols ospf area 0.0.0.0]
user@host# show 
interface so-0/0/0 {
    hello-interval 5;
    dead-interval 20;
}
interface so-0/0/1 {
    hello-interval 5;
    dead-interval 20;
}
[edit protocols ospf area 0.0.0.0]
user@host# 

Now, back up to the top level and see what you have:
[edit protocols ospf area 0.0.0.0]
user@host# top
[edit]
user@host# show 
protocols {
    ospf {
        area 0.0.0.0 {
            interface so-0/0/0 {
                hello-interval 5;
                dead-interval 20;
            }
            interface so-0/0/1 {
                hello-interval 5;
                dead-interval 20;
            }
        }
    }
}
[edit]
user@host# 

This configuration now contains the statements you want. Before committing it, which activates the configuration, verify that the configuration is correct:
[edit]
user@host# commit check
configuration check succeeds
[edit]
user@host#

Now you can commit the configuration to activate it on the router:
[edit]
user@host# commit
commit complete
[edit]
user@host#

Suppose you decide to use different dead and hello intervals on interface so-0/0/1. You can make changes to the configuration. You can go directly to the appropriate hierarchy level by typing the full hierarchy path to the statement you want to edit.
[edit]
user@host# edit protocols ospf area 0.0.0.0 interface so-0/0/1
[edit protocols ospf area 0.0.0.0 interface so-0/0/1]
user@host# show 
hello-interval 5;
dead-interval 20;
[edit protocols ospf area 0.0.0.0 interface so-0/0/1]
user@host# set hello-interval 7
[edit protocols ospf area 0.0.0.0 interface so-0/0/1]
user@host# set dead-interval 28
[edit protocols ospf area 0.0.0.0 interface so-0/0/1]
user@host# top
[edit]
user@host# show 
protocols {
    ospf {
        area 0.0.0.0 {
            interface so-0/0/0 {
                hello-interval 5;
                dead-interval 20;
            }
            interface so-0/0/1 {
                hello-interval 7;
                dead-interval 28;
            }
        }
    }
}
[edit]
user@host# 

If you change your mind and decide not to run OSPF on the first interface, you can delete the statement:
[edit]
user@host# edit protocols ospf area 0.0.0.0
[edit protocols ospf area 0.0.0.0]
user@host# delete interface so-0/0/0
[edit protocols ospf area 0.0.0.0]
user@host# top
[edit]
user@host# show 
protocols {
    ospf {
        area 0.0.0.0 {
            interface so-0/0/1 {
                hello-interval 7;
                dead-interval 28;
            }
        }
    }
}
[edit]
user@host# 

Note that everything inside of the statement you deleted was deleted with it. You could eliminate the entire OSPF configuration by simply entering delete protocols ospf while at the top level.
Suppose you decide to use the default values for the hello and dead intervals on your remaining interface, but you want OSPF to run on that interface:
[edit]
user@host# edit protocols ospf area 0.0.0.0 interface so-0/0/1
[edit protocols ospf area 0.0.0.0 interface so-0/0/1]
user@host# delete hello-interval
[edit protocols ospf area 0.0.0.0 interface so-0/0/1]
user@host# delete dead-interval
[edit protocols ospf area 0.0.0.0 interface so-0/0/1]
user@host# top
[edit]
user@host# show 
protocols {
    ospf {
        area 0.0.0.0 {
            interface so-0/0/1;
        }
    }
}
[edit]
user@host# 

You can set multiple statements at the same time as long as they are all part of the same hierarchy (the path of statements from the top inward, as well as one or more statements at the bottom of the hierarchy). Doing this can reduce considerably the number of commands you must enter. For example, if you want to go back to the original hello and dead interval timers on interface so-0/0/1, you can enter:
[edit]
user@host# edit protocols ospf area 0.0.0.0 interface so-0/0/1
[edit protocols ospf area 0.0.0.0 interface so-0/0/1]
user@host# set hello-interval 5 dead-interval 20
[edit protocols ospf area 0.0.0.0 interface so-0/0/1]
user@host# exit
[edit]
user@host# show
protocols {
    ospf {
        area 0.0.0.0 {
            interface so-0/0/1 {
                hello-interval 5;
                dead-interval 20;
            }
        }
    }
}
[edit]
user@host#

You also can re-create the other interface, as you had it before, with only a single entry:
[edit]
user@host# set protocols ospf area 0.0.0.0 interface so-0/0/1 hello-interval 5 dead-interval 20
[edit]
user@host# show
protocols {
    ospf {
        area 0.0.0.0 {
            interface so-0/0/0 {
                hello-interval 5;
                dead-interval 20;
            }
            interface so-0/0/1 {
                hello-interval 5;
                dead-interval 20;
            }
        }
    }
}