ACL, NAT và Network Security

80 phút

ACL, NAT và Network Security

ACL, NAT và Network Security

Access Control Lists (ACLs)

ACL Types

Standard ACL:
- Số: 1-99, 1300-1999
- Filter: Source IP only
- Vị trí: Gần destination

Extended ACL:
- Số: 100-199, 2000-2699
- Filter: Source, Destination, Protocol, Port
- Vị trí: Gần source

Named ACL:
- Standard hoặc Extended
- Có tên thay vì số

Wildcard Mask

Subnet Mask:   255.255.255.0
Wildcard:      0.0.0.255

Công thức: Wildcard = 255.255.255.255 - Subnet Mask

Ví dụ:
/24: 255.255.255.0 → 0.0.0.255
/25: 255.255.255.128 → 0.0.0.127
/26: 255.255.255.192 → 0.0.0.63
/30: 255.255.255.252 → 0.0.0.3
Host: 255.255.255.255 → 0.0.0.0

Ví dụ:
Match 192.168.1.0/24: 192.168.1.0 0.0.0.255
Match 192.168.1.100/32: 192.168.1.100 0.0.0.0
Match any: 0.0.0.0 255.255.255.255 (hoặc "any")
Match host: host 192.168.1.100

Standard ACL

# Numbered
R1(config)# access-list 10 permit 192.168.1.0 0.0.0.255
R1(config)# access-list 10 deny 192.168.2.0 0.0.0.255
R1(config)# access-list 10 permit any

# Apply to interface
R1(config)# interface gi0/1
R1(config-if)# ip access-group 10 in
R1(config-if)# exit

# Verify
R1# show access-lists
R1# show ip interface gi0/1
R1# show ip access-lists

Named Standard ACL

R1(config)# ip access-list standard ALLOW_LAN
R1(config-std-nacl)# permit 192.168.1.0 0.0.0.255
R1(config-std-nacl)# permit 192.168.10.0 0.0.0.255
R1(config-std-nacl)# deny any log
R1(config-std-nacl)# exit

R1(config)# interface gi0/1
R1(config-if)# ip access-group ALLOW_LAN in
R1(config-if)# exit

Extended ACL

# Cấu trúc:
# access-list <number> <action> <protocol> <src> <dst> [operator port]

# Ví dụ:
R1(config)# access-list 100 permit tcp 192.168.1.0 0.0.0.255 any eq 80
R1(config)# access-list 100 permit tcp 192.168.1.0 0.0.0.255 any eq 443
R1(config)# access-list 100 permit tcp 192.168.1.0 0.0.0.255 any eq 22
R1(config)# access-list 100 permit icmp 192.168.1.0 0.0.0.255 any echo
R1(config)# access-list 100 permit tcp any 192.168.1.0 0.0.0.255 established
R1(config)# access-list 100 deny ip any any log

Named Extended ACL

R1(config)# ip access-list extended WEB_ACCESS
R1(config-ext-nacl)# remark Allow HTTP/HTTPS to web server
R1(config-ext-nacl)# permit tcp any host 192.168.1.100 eq 80
R1(config-ext-nacl)# permit tcp any host 192.168.1.100 eq 443

R1(config-ext-nacl)# remark Allow DNS
R1(config-ext-nacl)# permit udp any any eq 53
R1(config-ext-nacl)# permit tcp any any eq 53

R1(config-ext-nacl)# remark Allow established traffic
R1(config-ext-nacl)# permit tcp any any established

R1(config-ext-nacl)# remark Deny everything else
R1(config-ext-nacl)# deny ip any any log
R1(config-ext-nacl)# exit

# Apply to interface
R1(config)# interface gi0/0
R1(config-if)# ip access-group WEB_ACCESS in
R1(config-if)# exit

Editing ACLs

# Xem số sequence
R1# show access-lists

# Thêm rule vào giữa
R1(config)# ip access-list extended MY_ACL
R1(config-ext-nacl)# 15 permit tcp any any eq 21
R1(config-ext-nacl)# exit

# Xóa một rule
R1(config)# ip access-list extended MY_ACL
R1(config-ext-nacl)# no 15
R1(config-ext-nacl)# exit

# Resequence
R1(config)# ip access-list resequence MY_ACL 10 10

ACL Applications

# Inbound (khuyến nghị cho extended)
R1(config-if)# ip access-group 100 in

# Outbound
R1(config-if)# ip access-group 100 out

# VTY access
R1(config)# line vty 0 4
R1(config-line)# access-class 10 in
R1(config-line)# exit

# SNMP
R1(config)# snmp-server community public RO 10

# Route filtering
R1(config)# distribute-list 10 in gi0/0

NAT Advanced

Static NAT

R1(config)# ip nat inside source static 192.168.1.10 203.0.113.10
R1(config)# ip nat inside source static tcp 192.168.1.100 80 203.0.113.10 80
R1(config)# ip nat inside source static udp 192.168.1.100 53 203.0.113.10 53

Dynamic NAT

# Define pool
R1(config)# ip nat pool PUBLIC_POOL 203.0.113.10 203.0.113.20 prefix-length 24

# ACL
R1(config)# access-list 1 permit 192.168.1.0 0.0.0.255

# NAT rule
R1(config)# ip nat inside source list 1 pool PUBLIC_POOL

PAT (Overload)

# Interface overload
R1(config)# ip nat inside source list 1 interface gi0/0 overload

# Pool overload
R1(config)# ip nat inside source list 1 pool PUBLIC_POOL overload

# Verify
R1# show ip nat translations
R1# show ip nat translations verbose
R1# show ip nat statistics
R1# clear ip nat translation *
R1# clear ip nat translation inside 192.168.1.10

NAT với Route-map

# Match traffic và apply NAT policy
R1(config)# route-map NAT_POLICY permit 10
R1(config-route-map)# match ip address 1
R1(config-route-map)# match interface gi0/0
R1(config-route-map)# exit

R1(config)# ip nat inside source route-map NAT_POLICY pool PUBLIC_POOL overload

Zone-Based Firewall (ZBF)

Zones

INSIDE zone   - LAN
OUTSIDE zone  - Internet
DMZ zone      - Web servers

Cấu hình ZBF

# Define zones
R1(config)# zone security INSIDE
R1(config)# zone security OUTSIDE

# Class-map
R1(config)# class-map type inspect match-any WEB_TRAFFIC
R1(config-cmap)# match protocol http
R1(config-cmap)# match protocol https
R1(config-cmap)# exit

# Policy-map
R1(config)# policy-map type inspect INSIDE_TO_OUTSIDE
R1(config-pmap)# class type inspect WEB_TRAFFIC
R1(config-pmap-c)# inspect
R1(config-pmap-c)# exit
R1(config-pmap)# class class-default
R1(config-pmap-c)# drop
R1(config-pmap-c)# exit
R1(config-pmap)# exit

# Zone-pair
R1(config)# zone-pair security IN_TO_OUT source INSIDE destination OUTSIDE
R1(config-sec-zone-pair)# service-policy type inspect INSIDE_TO_OUTSIDE
R1(config-sec-zone-pair)# exit

# Assign interfaces to zones
R1(config)# interface gi0/0
R1(config-if)# zone-member security OUTSIDE
R1(config-if)# exit
R1(config)# interface gi0/1
R1(config-if)# zone-member security INSIDE

VPN (Site-to-Site IPsec)

Cấu hình Site-to-Site VPN

# ============ Site A Router ============

# 1. IKE Phase 1 Policy
R1(config)# crypto isakmp policy 10
R1(config-isakmp)# encryption aes 256
R1(config-isakmp)# hash sha256
R1(config-isakmp)# authentication pre-share
R1(config-isakmp)# group 14
R1(config-isakmp)# lifetime 86400
R1(config-isakmp)# exit

# 2. Pre-shared key
R1(config)# crypto isakmp key Cisco12345 address 203.0.113.10

# 3. IKE Phase 2 (IPsec)
R1(config)# crypto ipsec transform-set MY_TS esp-aes 256 esp-sha256-hmac
R1(config-crypto-trans)# mode tunnel
R1(config-crypto-trans)# exit

# 4. ACL cho interesting traffic
R1(config)# ip access-list extended VPN_TRAFFIC
R1(config-ext-nacl)# permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
R1(config-ext-nacl)# exit

# 5. Crypto map
R1(config)# crypto map VPN_MAP 10 ipsec-isakmp
R1(config-crypto-map)# set peer 203.0.113.10
R1(config-crypto-map)# set transform-set MY_TS
R1(config-crypto-map)# match address VPN_TRAFFIC
R1(config-crypto-map)# set pfs group14
R1(config-crypto-map)# exit

# 6. Apply to interface
R1(config)# interface gi0/0
R1(config-if)# crypto map VPN_MAP
R1(config-if)# exit

# ============ Site B Router ============
# Mirror config với peer/address swap

# Verify
R1# show crypto isakmp sa
R1# show crypto ipsec sa
R1# show crypto map
R1# show crypto session

AAA (Authentication, Authorization, Accounting)

Local AAA

# Enable AAA
R1(config)# aaa new-model

# Local user
R1(config)# username admin privilege 15 secret Admin123

# Authentication
R1(config)# aaa authentication login default local
R1(config)# aaa authentication login CONSOLE local

# Apply to lines
R1(config)# line con 0
R1(config-line)# login authentication CONSOLE
R1(config-line)# exit

R1(config)# line vty 0 4
R1(config-line)# login authentication default
R1(config-line)# transport input ssh

TACACS+ / RADIUS

# TACACS+
R1(config)# tacacs server TACACS1
R1(config-server-tacacs)# address ipv4 10.0.0.100
R1(config-server-tacacs)# key Cisco123
R1(config-server-tacacs)# exit

R1(config)# aaa group server tacacs+ TACACS_GROUP
R1(config-sg-tacacs+)# server name TACACS1
R1(config-sg-tacacs+)# exit

R1(config)# aaa authentication login default group TACACS_GROUP local
R1(config)# aaa authorization exec default group TACACS_GROUP local
R1(config)# aaa accounting exec default start-stop group TACACS_GROUP

# RADIUS
R1(config)# radius server RADIUS1
R1(config-radius-server)# address ipv4 10.0.0.101 auth-port 1812 acct-port 1813
R1(config-radius-server)# key Cisco123
R1(config-radius-server)# exit

SSH Configuration

# Generate RSA keys
R1(config)# ip domain-name abc.local
R1(config)# crypto key generate rsa modulus 2048

# SSH version 2
R1(config)# ip ssh version 2
R1(config)# ip ssh time-out 60
R1(config)# ip ssh authentication-retries 3

# User
R1(config)# username admin privilege 15 secret Admin123

# VTY
R1(config)# line vty 0 4
R1(config-line)# login local
R1(config-line)# transport input ssh
R1(config-line)# exec-timeout 10 0
R1(config-line)# exit

# Verify
R1# show ip ssh
R1# show ssh

# Kết nối
ssh -l admin 192.168.1.1

Port Security

SW1(config)# interface fa0/1
SW1(config-if)# switchport mode access
SW1(config-if)# switchport port-security
SW1(config-if)# switchport port-security maximum 2
SW1(config-if)# switchport port-security mac-address sticky
SW1(config-if)# switchport port-security violation restrict
SW1(config-if)# switchport port-security aging time 60
SW1(config-if)# switchport port-security aging type inactivity
SW1(config-if)# exit

# Verify
SW1# show port-security
SW1# show port-security interface fa0/1
SW1# show port-security address

# Clear
SW1# clear port-security all
SW1# clear port-security sticky interface fa0/1

DHCP Snooping

# Enable globally
SW1(config)# ip dhcp snooping
SW1(config)# ip dhcp snooping vlan 10,20,30

# Trusted ports (uplink to DHCP server)
SW1(config)# interface gi0/1
SW1(config-if)# ip dhcp snooping trust
SW1(config-if)# exit

# Rate limit
SW1(config)# interface range fa0/1-24
SW1(config-if-range)# ip dhcp snooping limit rate 10
SW1(config-if-range)# exit

# Option 82
SW1(config)# ip dhcp snooping information option

# Verify
SW1# show ip dhcp snooping
SW1# show ip dhcp snooping binding
SW1# show ip dhcp snooping statistics

Dynamic ARP Inspection (DAI)

# Requires DHCP snooping
SW1(config)# ip arp inspection vlan 10,20,30

# Trusted ports
SW1(config)# interface gi0/1
SW1(config-if)# ip arp inspection trust
SW1(config-if)# exit

# Rate limit
SW1(config)# interface range fa0/1-24
SW1(config-if-range)# ip arp inspection limit rate 15
SW1(config-if-range)# exit

# Verify
SW1# show ip arp inspection
SW1# show ip arp inspection statistics
SW1# show ip arp inspection interfaces

Bài tập thực hành

Hãy cấu hình ACL và security!

Bài tập 1