80 phút
ACL, NAT và Network Security
ACL, NAT và Network Security
Access Control Lists (ACLs)
ACL Types
Standard ACL:
- Số: 1-99, 1300-1999
- Filter: Source IP only
- Vị trí: Gần destination
Extended ACL:
- Số: 100-199, 2000-2699
- Filter: Source, Destination, Protocol, Port
- Vị trí: Gần source
Named ACL:
- Standard hoặc Extended
- Có tên thay vì số
Wildcard Mask
Subnet Mask: 255.255.255.0
Wildcard: 0.0.0.255
Công thức: Wildcard = 255.255.255.255 - Subnet Mask
Ví dụ:
/24: 255.255.255.0 → 0.0.0.255
/25: 255.255.255.128 → 0.0.0.127
/26: 255.255.255.192 → 0.0.0.63
/30: 255.255.255.252 → 0.0.0.3
Host: 255.255.255.255 → 0.0.0.0
Ví dụ:
Match 192.168.1.0/24: 192.168.1.0 0.0.0.255
Match 192.168.1.100/32: 192.168.1.100 0.0.0.0
Match any: 0.0.0.0 255.255.255.255 (hoặc "any")
Match host: host 192.168.1.100
Standard ACL
# Numbered
R1(config)# access-list 10 permit 192.168.1.0 0.0.0.255
R1(config)# access-list 10 deny 192.168.2.0 0.0.0.255
R1(config)# access-list 10 permit any
# Apply to interface
R1(config)# interface gi0/1
R1(config-if)# ip access-group 10 in
R1(config-if)# exit
# Verify
R1# show access-lists
R1# show ip interface gi0/1
R1# show ip access-lists
Named Standard ACL
R1(config)# ip access-list standard ALLOW_LAN
R1(config-std-nacl)# permit 192.168.1.0 0.0.0.255
R1(config-std-nacl)# permit 192.168.10.0 0.0.0.255
R1(config-std-nacl)# deny any log
R1(config-std-nacl)# exit
R1(config)# interface gi0/1
R1(config-if)# ip access-group ALLOW_LAN in
R1(config-if)# exit
Extended ACL
# Cấu trúc:
# access-list <number> <action> <protocol> <src> <dst> [operator port]
# Ví dụ:
R1(config)# access-list 100 permit tcp 192.168.1.0 0.0.0.255 any eq 80
R1(config)# access-list 100 permit tcp 192.168.1.0 0.0.0.255 any eq 443
R1(config)# access-list 100 permit tcp 192.168.1.0 0.0.0.255 any eq 22
R1(config)# access-list 100 permit icmp 192.168.1.0 0.0.0.255 any echo
R1(config)# access-list 100 permit tcp any 192.168.1.0 0.0.0.255 established
R1(config)# access-list 100 deny ip any any log
Named Extended ACL
R1(config)# ip access-list extended WEB_ACCESS
R1(config-ext-nacl)# remark Allow HTTP/HTTPS to web server
R1(config-ext-nacl)# permit tcp any host 192.168.1.100 eq 80
R1(config-ext-nacl)# permit tcp any host 192.168.1.100 eq 443
R1(config-ext-nacl)# remark Allow DNS
R1(config-ext-nacl)# permit udp any any eq 53
R1(config-ext-nacl)# permit tcp any any eq 53
R1(config-ext-nacl)# remark Allow established traffic
R1(config-ext-nacl)# permit tcp any any established
R1(config-ext-nacl)# remark Deny everything else
R1(config-ext-nacl)# deny ip any any log
R1(config-ext-nacl)# exit
# Apply to interface
R1(config)# interface gi0/0
R1(config-if)# ip access-group WEB_ACCESS in
R1(config-if)# exit
Editing ACLs
# Xem số sequence
R1# show access-lists
# Thêm rule vào giữa
R1(config)# ip access-list extended MY_ACL
R1(config-ext-nacl)# 15 permit tcp any any eq 21
R1(config-ext-nacl)# exit
# Xóa một rule
R1(config)# ip access-list extended MY_ACL
R1(config-ext-nacl)# no 15
R1(config-ext-nacl)# exit
# Resequence
R1(config)# ip access-list resequence MY_ACL 10 10
ACL Applications
# Inbound (khuyến nghị cho extended)
R1(config-if)# ip access-group 100 in
# Outbound
R1(config-if)# ip access-group 100 out
# VTY access
R1(config)# line vty 0 4
R1(config-line)# access-class 10 in
R1(config-line)# exit
# SNMP
R1(config)# snmp-server community public RO 10
# Route filtering
R1(config)# distribute-list 10 in gi0/0
NAT Advanced
Static NAT
R1(config)# ip nat inside source static 192.168.1.10 203.0.113.10
R1(config)# ip nat inside source static tcp 192.168.1.100 80 203.0.113.10 80
R1(config)# ip nat inside source static udp 192.168.1.100 53 203.0.113.10 53
Dynamic NAT
# Define pool
R1(config)# ip nat pool PUBLIC_POOL 203.0.113.10 203.0.113.20 prefix-length 24
# ACL
R1(config)# access-list 1 permit 192.168.1.0 0.0.0.255
# NAT rule
R1(config)# ip nat inside source list 1 pool PUBLIC_POOL
PAT (Overload)
# Interface overload
R1(config)# ip nat inside source list 1 interface gi0/0 overload
# Pool overload
R1(config)# ip nat inside source list 1 pool PUBLIC_POOL overload
# Verify
R1# show ip nat translations
R1# show ip nat translations verbose
R1# show ip nat statistics
R1# clear ip nat translation *
R1# clear ip nat translation inside 192.168.1.10
NAT với Route-map
# Match traffic và apply NAT policy
R1(config)# route-map NAT_POLICY permit 10
R1(config-route-map)# match ip address 1
R1(config-route-map)# match interface gi0/0
R1(config-route-map)# exit
R1(config)# ip nat inside source route-map NAT_POLICY pool PUBLIC_POOL overload
Zone-Based Firewall (ZBF)
Zones
INSIDE zone - LAN
OUTSIDE zone - Internet
DMZ zone - Web servers
Cấu hình ZBF
# Define zones
R1(config)# zone security INSIDE
R1(config)# zone security OUTSIDE
# Class-map
R1(config)# class-map type inspect match-any WEB_TRAFFIC
R1(config-cmap)# match protocol http
R1(config-cmap)# match protocol https
R1(config-cmap)# exit
# Policy-map
R1(config)# policy-map type inspect INSIDE_TO_OUTSIDE
R1(config-pmap)# class type inspect WEB_TRAFFIC
R1(config-pmap-c)# inspect
R1(config-pmap-c)# exit
R1(config-pmap)# class class-default
R1(config-pmap-c)# drop
R1(config-pmap-c)# exit
R1(config-pmap)# exit
# Zone-pair
R1(config)# zone-pair security IN_TO_OUT source INSIDE destination OUTSIDE
R1(config-sec-zone-pair)# service-policy type inspect INSIDE_TO_OUTSIDE
R1(config-sec-zone-pair)# exit
# Assign interfaces to zones
R1(config)# interface gi0/0
R1(config-if)# zone-member security OUTSIDE
R1(config-if)# exit
R1(config)# interface gi0/1
R1(config-if)# zone-member security INSIDE
VPN (Site-to-Site IPsec)
Cấu hình Site-to-Site VPN
# ============ Site A Router ============
# 1. IKE Phase 1 Policy
R1(config)# crypto isakmp policy 10
R1(config-isakmp)# encryption aes 256
R1(config-isakmp)# hash sha256
R1(config-isakmp)# authentication pre-share
R1(config-isakmp)# group 14
R1(config-isakmp)# lifetime 86400
R1(config-isakmp)# exit
# 2. Pre-shared key
R1(config)# crypto isakmp key Cisco12345 address 203.0.113.10
# 3. IKE Phase 2 (IPsec)
R1(config)# crypto ipsec transform-set MY_TS esp-aes 256 esp-sha256-hmac
R1(config-crypto-trans)# mode tunnel
R1(config-crypto-trans)# exit
# 4. ACL cho interesting traffic
R1(config)# ip access-list extended VPN_TRAFFIC
R1(config-ext-nacl)# permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
R1(config-ext-nacl)# exit
# 5. Crypto map
R1(config)# crypto map VPN_MAP 10 ipsec-isakmp
R1(config-crypto-map)# set peer 203.0.113.10
R1(config-crypto-map)# set transform-set MY_TS
R1(config-crypto-map)# match address VPN_TRAFFIC
R1(config-crypto-map)# set pfs group14
R1(config-crypto-map)# exit
# 6. Apply to interface
R1(config)# interface gi0/0
R1(config-if)# crypto map VPN_MAP
R1(config-if)# exit
# ============ Site B Router ============
# Mirror config với peer/address swap
# Verify
R1# show crypto isakmp sa
R1# show crypto ipsec sa
R1# show crypto map
R1# show crypto session
AAA (Authentication, Authorization, Accounting)
Local AAA
# Enable AAA
R1(config)# aaa new-model
# Local user
R1(config)# username admin privilege 15 secret Admin123
# Authentication
R1(config)# aaa authentication login default local
R1(config)# aaa authentication login CONSOLE local
# Apply to lines
R1(config)# line con 0
R1(config-line)# login authentication CONSOLE
R1(config-line)# exit
R1(config)# line vty 0 4
R1(config-line)# login authentication default
R1(config-line)# transport input ssh
TACACS+ / RADIUS
# TACACS+
R1(config)# tacacs server TACACS1
R1(config-server-tacacs)# address ipv4 10.0.0.100
R1(config-server-tacacs)# key Cisco123
R1(config-server-tacacs)# exit
R1(config)# aaa group server tacacs+ TACACS_GROUP
R1(config-sg-tacacs+)# server name TACACS1
R1(config-sg-tacacs+)# exit
R1(config)# aaa authentication login default group TACACS_GROUP local
R1(config)# aaa authorization exec default group TACACS_GROUP local
R1(config)# aaa accounting exec default start-stop group TACACS_GROUP
# RADIUS
R1(config)# radius server RADIUS1
R1(config-radius-server)# address ipv4 10.0.0.101 auth-port 1812 acct-port 1813
R1(config-radius-server)# key Cisco123
R1(config-radius-server)# exit
SSH Configuration
# Generate RSA keys
R1(config)# ip domain-name abc.local
R1(config)# crypto key generate rsa modulus 2048
# SSH version 2
R1(config)# ip ssh version 2
R1(config)# ip ssh time-out 60
R1(config)# ip ssh authentication-retries 3
# User
R1(config)# username admin privilege 15 secret Admin123
# VTY
R1(config)# line vty 0 4
R1(config-line)# login local
R1(config-line)# transport input ssh
R1(config-line)# exec-timeout 10 0
R1(config-line)# exit
# Verify
R1# show ip ssh
R1# show ssh
# Kết nối
ssh -l admin 192.168.1.1
Port Security
SW1(config)# interface fa0/1
SW1(config-if)# switchport mode access
SW1(config-if)# switchport port-security
SW1(config-if)# switchport port-security maximum 2
SW1(config-if)# switchport port-security mac-address sticky
SW1(config-if)# switchport port-security violation restrict
SW1(config-if)# switchport port-security aging time 60
SW1(config-if)# switchport port-security aging type inactivity
SW1(config-if)# exit
# Verify
SW1# show port-security
SW1# show port-security interface fa0/1
SW1# show port-security address
# Clear
SW1# clear port-security all
SW1# clear port-security sticky interface fa0/1
DHCP Snooping
# Enable globally
SW1(config)# ip dhcp snooping
SW1(config)# ip dhcp snooping vlan 10,20,30
# Trusted ports (uplink to DHCP server)
SW1(config)# interface gi0/1
SW1(config-if)# ip dhcp snooping trust
SW1(config-if)# exit
# Rate limit
SW1(config)# interface range fa0/1-24
SW1(config-if-range)# ip dhcp snooping limit rate 10
SW1(config-if-range)# exit
# Option 82
SW1(config)# ip dhcp snooping information option
# Verify
SW1# show ip dhcp snooping
SW1# show ip dhcp snooping binding
SW1# show ip dhcp snooping statistics
Dynamic ARP Inspection (DAI)
# Requires DHCP snooping
SW1(config)# ip arp inspection vlan 10,20,30
# Trusted ports
SW1(config)# interface gi0/1
SW1(config-if)# ip arp inspection trust
SW1(config-if)# exit
# Rate limit
SW1(config)# interface range fa0/1-24
SW1(config-if-range)# ip arp inspection limit rate 15
SW1(config-if-range)# exit
# Verify
SW1# show ip arp inspection
SW1# show ip arp inspection statistics
SW1# show ip arp inspection interfaces
Bài tập thực hành
Hãy cấu hình ACL và security!