Showing posts with label VPN. Show all posts
Showing posts with label VPN. Show all posts

Sunday, 18 August 2013

Zone Based Firewall Advanced Configuration

This post will take you through some advanced configuration scenarios of Cisco IOS Zone Based Firewall. This is a continuation of my previous blog entry Cisco IOS Zone-Based Firewall Step-by-step Configuration Guide.

Following are the features and scenarios we are going to see in this post.

1.)  Zone Based Firewall Layer 7 Application Inspection and Control
 

2.)  Traffic Policing in Zone-Based Policy Firewall
 

3.)  Session Control in Zone Based Firewall
 

4.)  Out-of-Order Packet Processing Support in the Zone-Based Firewall Application
 

5.)  Tuning Zone-Based Policy Firewall Denial-of-Service Protection
 

6.)  Content Filtering with IOS Zone Based Firewall
 

7.)  Self-Zone Configuration in Zone Based Firewall
 

8.)  Allow SSL WebVPN through Zone Based Firewall
 

9.)  Allow Cisco Configuration Professional through Zone Based Firewall
 

10.) Using IPSec VPN with Zone-Based Policy Firewall

1. Zone Based Firewall Layer 7 Application Inspection and Control

ZBFW is capable of doing a layer 7 application inspection for the below protocols:
Here we are going to discuss about the IM layer 7 inspection capability of a Zone Based Firewall.

IM application inspection and control

This feature is currently applicable for the following IM Services:
  • AOL Instant Messenger
  • MSN Messenger
  • Yahoo! Messenger
IM inspection and control offers both Layer 4 Stateful Inspection and Layer 7 Application Control.

Layer 4 inspection is configured similarly to other application services:

 class-map type inspect match-any IM-CLASS
   match protocol [aol | msnmsgr | ymsgr ]

 
 policy-map type inspect IN-TO-OUT-POLICY
   class type inspect IM-CLASS
      [drop | inspect | pass]


IM application have got the port hopping capability and it contact their servers on multiple port. In order to allow an IM service we need to simply apply a layer 4 inspect action but  if you want to deny a particular IM service you need to define server list so that ZBFW can identify the traffic associated with IM application.

First configure the server-list parameter-map:

    parameter-map type protocol-info
      server name
      server ip a.b.c.d
      server ip range a.b.c.d a.b.c.d


Parameter Map

For example, the AOL and Yahoo! IM server list is defined as such:

    parameter-map type protocol-info AOL-SERVERS
     server name login.oscar.aol.com
     server name toc.oscar.aol.com
     server name oam-d09a.blue.aol.com
     server ip x.x.x.x
     server ip range x.x.x.x y.y.y.y

  parameter-map type protocol-info YAHOO-SERVERS
    server name scs.msg.yahoo.com
    server name scsa.msg.yahoo.com
    server name scsb.msg.yahoo.com


Class Map

You need to apply the server-list to the protocol definition:

    class-map type inspect match-any AOL-BLOCK-CLASS
     match protocol aol AOL-SERVERS
     match protocol ymsgr YAHOO-SERVERS
     exit

    class-map type inspect match-all IM-PROTOCOL-CLASS
      match class-map IM-BLOCK-CLASS
      exit


Policy Map

   policy-map type inspect IN-TO-OUT-POLICY
    class type inspect IM-PROTOCOL-CLASS
    drop log
    exit

You must configure the 'ip domain lookup' and 'ip name-server x.x.x.x' commands in order to enable name resolution.

IM server names are fairly dynamic. You will need to periodically check that your configured IM server lists are complete and correct. IM Application Inspection also offers the capability to differentiate between text-chat activity and all other application services such as selectively blocking or allowing text-chat capabilities, while denying other service capabilities.

2. Traffic Policing in Zone-Based Policy Firewall

Using a ZBFW we can limit the transmission rate of specific traffic. This will help us to limit lower priority traffic over business-essential traffic. ZBFW policing can only specify bandwidth use in bytes/second, packet/second and bandwidth percentage policing are not offered.

Configuring ZBFW Policing

ZBFW policing limits traffic in a policy-map’s class-map to a user-defined rate value between 8,000 and 2,000,000,000 bits per second, with a configurable burst value in the range of 1,000 to 512,000,000 bytes.

In this example I am policing HTTP traffic. The rate policing part is highlighted in bold text.ZFW policing is configured in the policy-map,which is applied after the policy action:

 class-map type inspect match-all HTTP-TRAFFIC
   match protocol http

    policy-map type inspect IN-TO-OUT-POLICY
     class type inspect http-class
      inspect
      police rate [bps rate value {8000-2000000000}] burst [value in bytes {1000-512000000}]


3. Session Control in Zone Based Firewall

ZBFW adds the functionality to limit the session where it allows granular control on the number of sessions matching any given class-map that cross a zone-pair.

In order to configure session control you have to define a parameter map that contain the session limit and attach that to the class-map which is attached with the policy-map.

parameter-map type inspect HTTP-SESSION-CONTROL
 sessions maximum [1-2147483647]

policy-map type inspect IN-TO-OUT-POLICY
 class type inspect HTTP-TRAFFIC
  inspect HTTP-SESSION-CONTROL


4. Out-of-Order Packet Processing Support in the Zone-Based Firewall Application

Out-of-Order (OoO) packet processing support for Common Classification Engine (CCE) firewall application and CCE adoptions of the Intrusion Prevention System (IPS) allows packets that arrive out of order to be copied and reassembled in the correct order. The OoO packet processing reduces the need to retransmit dropped packets and reduces the bandwidth needed for the transmission of traffic on a network. To configure OoO support, use the parameter-map type ooo global command.

 parameter-map type ooo global
   tcp reassembly timeout 5
   tcp reassembly queue length 16
   tcp reassembly memory limit 1024
   tcp reassembly alarm off


5.  Tuning Zone-Based Policy Firewall Denial-of-Service Protection

Refer Tuning Zone-Based Policy Firewall Denial-of-Service Protection

6. Content Filtering with IOS Zone Based Firewall

Refer Cisco IOS Local Content Filtering

7. Self-Zone Configuration in Zone Based Firewall

For self-zone configuration refer ZBFW Self-Zone Integration

8. Allow SSL WebVPN through Zone Based Firewall 

[ Cisco IOS SSL VPN Configuration Guide : http://yadhutony.blogspot.in/2013/06/cisco-ios-ssl-vpn-configuration-guide.html ]

ACL

ip access-list extended SSL_WEBVPN_ACL
 permit tcp any any eq 443 *
 exit

access-list 104 permit ip any host

Class Map

class-map type inspect match-any SSL_CLASS
 match access-group name SSL_WEBVPN_ACL
 exit
class-map type inspect match-all SSL_WEBVPN_TRAFFIC
 match class-map SSL_CLASS
 match access-group 104
 exit

Policy Map

policy-map type inspect OUT-TO-SELF
 class type inspect SDM_WEBVPN_TRAFFIC
  no drop
  inspect
  exit

Zone Pair

zone-pair security OUT-TO-SELF source OUTSIDE destination self
 service-policy type inspect OUT-TO-SELF
 exit

* By default port 443 is being used by Cisco SSL VPN.

9. Allow Cisco Configuration Professional through Zone Based Firewall

ACL

ip access-list extended CCP_SSH
 permit tcp any any eq 22
 exit

ip access-list extended CCP_HTTPS
 permit tcp any any eq 443
 exit

ip access-list extended CCP_SHELL
 permit tcp any any eq cmd
 exit

access-list 102 permit ip any any

Class Map

class-map type inspect match-any CCP_SSH_CLASS
 match access-group name CCP_SSH
 exit

class-map type inspect match-any CCP_HTTPS_CLASS
 match access-group name CCP_HTTPS
 exit

class-map type inspect match-any CCP_SHELL_CLASS
 match access-group name CCP_SHELL
 exit

class-map type inspect match-any CCP-ACCESS_CLASS
 match class-map CCP_SSH_CLASS
 match class-map CCP_HTTPS_CLASS
 match class-map CCP_SHELL_CLASS
 exit

class-map type inspect match-all CCP-ACCESS
 match class-map CCP-ACCESS_CLASS
 match access-group 102
 exit

Policy Map

policy-map type inspect OUTSIDE-TO-SELF
 class type inspect CCP-ACCESS
  no drop
  inspect
  exit

Zone Pair

zone-pair security OUT-TO-SELF source OUTSIDE destination self
 service-policy type inspect OUTSIDE-TO-SELF
 exit

10. Using IPSec VPN with Zone-Based Policy Firewall

Refer Using VPN with Zone-Based Policy Firewall

Useful Links

Friday, 7 June 2013

Cisco IOS SSL VPN Configuration Guide

Introduction

The Cisco SSL VPN (also known as WebVPN) is a remote access solution which enables a remote user to access his corporate network from anywhere on the Internet. Remote access is provided through a Secure Socket Layer (SSL) enabled SSL VPN gateway. The SSL VPN gateway allow remote users to establish a secure Virtual Private Network (VPN) tunnel using a web browser.

SSL VPN provides the following three mode of access:

1. Clientless  - Clientless mode provides secure access to private web resources. You can access all the resources in your company which uses a web interface.

2. Thin-client - Thin-client mode extend the capability by enabling us to access TCP-based applications such as POP3, SMTP, IMAP, SSH.

3. Full-tunnel - Full-tunnel mode provide access to virtually any application inside your company. Here the remote user will download a Cisco AnyConnect VPN client (next-generation VPN client) from the IOS router to use SSL.

Clientless SSL VPN Vs Easy VPN

Clientless SSL VPNEasy VPN
Doesn't require any client software on end user but a web browser.Require VPN client software to be installed on client machine.
Users doesn't have access to all network resources.Full access to all network resources.
Support mostly web based services.Support virtually all services.
It can transverse firewall and NAT configuration.Require to change firewall and NAT configuration.
It won't support low-latency application.Support low-latency application.

SSL VPN Session Establishment


Step-by-step IOS SSL VPN Configuration

This document will show you how to configure a SSL VPN in full tunnel and clientless mode on an IOS device. Configuration is based on a Cisco 2900 Integrated Service Router running with 15.0(1)M3 code.

Network Diagram



Configuration Tasks

1. Enable and configure AAA.

2. Generate RSA Keypair and Configure Trustpoint.

3. Configure SSL VPN IP pool.

4. Setup SSL VPN Gateway.

5. Upload & Install AnyConnect VPN Software (SVC) on Router.

6. Setup SSL VPN Context and Configure Group policy

1. Configuring AAA for SSL VPN authentication

Enable AAA in router for client authentication. VPN users have to be authenticated with either a local database or an authentication server like RADIUS  or TACACS+. In this example I used local database to authenticate VPN users.

CORPORATE(config)#aaa new-model
CORPORATE(config)#aaa authentication login SSL_AUTHEN local

Create  username and password in local database:

CORPORATE(config)#username administrator privilege 15 password mypassword
CORPORATE(config)#username tony  password cisco123

2. Generating RSA Keypair and Configuring Trustpoint.

We have to create a RSA keypair using the crypto key generate rsa command. Before that you have to make sure that you have set a host name and domain name on your router.

CORPORATE(config)#crypto key generate rsa general-keys label RSA-KEY mod 4096
The name for the keys will be: RSA-KEY

% The key modulus size is 4096 bits
% Generating 4096 bit RSA keys, keys will be non-exportable...
[OK] (elapsed time was 71 seconds)


Configuring the Trustpoint:

Now we have to declare the trust point that the router should use. To do so type the below commands in global configuration mode.

CORPORATE(config)#crypto pki trustpoint MY-TRUSTPOINT
CORPORATE(ca-trustpoint)#enrollment selfsigned
CORPORATE(ca-trustpoint)#subject-name CN=my-certificate
CORPORATE(ca-trustpoint)#rsakeypair RSA-KEY
CORPORATE(ca-trustpoint)#exit


Enrolling Certificate:

The next step is to enroll the self signed certificate that you have just created. If you have already created a certificate you can either use that or overwrite it by typing yes.

CORPORATE(config)#crypto pki enroll MY-TRUSTPOINT
% Include the router serial number in the subject name? [yes/no]: y
% Include an IP address in the subject name? [no]: n
Generate Self Signed Router Certificate? [yes/no]: y

Router Self Signed Certificate successfully created


3. Configuring SSL VPN pool IP address

CORPORATE(config)#ip local pool SSL-POOL 172.17.0.114 172.17.0.122


4. Setting up SSL VPN Gateway

The WebVPN Gateway is used to terminate the SSL connection from the user. The basic configuration requires an IP address on the same subnet as one of the public network interfaces; this could be the same address used on the public network interface, or another address in the same subnet. Alternately, you can define a loopback interface, and use an address in that subnet, just as long as the address is reachable on the public network.

CORPORATE(config)#webvpn gateway SSLVPNGW
PLEASE  READ THE  FOLLOWING TERMS  CAREFULLY. INSTALLING THE LICENSE OR
LICENSE  KEY  PROVIDED FOR  ANY CISCO  PRODUCT  FEATURE  OR  USING SUCH
PRODUCT  FEATURE  CONSTITUTES  YOUR  FULL ACCEPTANCE  OF  THE FOLLOWING
TERMS. YOU MUST NOT PROCEED FURTHER IF YOU ARE NOT WILLING TO  BE BOUND
BY ALL THE TERMS SET FORTH HEREIN.
......................................................................................................................................
...................................................................
Activation  of the  software command line interface will be evidence of
your acceptance of this agreement.

ACCEPT? [yes/no]: yes
CORPORATE(config-webvpn-gateway)#ip address 172.17.0.5 port 443
CORPORATE(config-webvpn-gateway)#ssl trustpoint MY-TRUSTPOINT
CORPORATE(config-webvpn-gateway)#inservice
CORPORATE(config-webvpn-gateway)#exit


5. Upload & Install AnyConnect VPN Software (SVC) on Router

Now upload the Cisco AnyConnect VPN client to the router's flash memory. You can use a TFTP server to do this. In this example we are uploading 'anyconnect-win-3.1.00495-k9.pkg' to router's flash using a TFTP server.

CORPORATE(config)#copy tftp flash:
Address or name of remote host []? 172.17.0.84
Source filename []? anyconnect-win-3.1.00495-k9.pkg
Destination filename [anyconnect-win-3.1.00495-k9.pkg]?
Accessing tftp://172.17.0.84/anyconnect-win-3.1.00495-k9.pkg...
Loading anyconnect-win-3.1.00495-k9.pkg from 172.17.0.84 (via GigabitEthernet0/0): !!!!!!!!!!!!!!!!!!!!!

[OK - 29806775 bytes]

29806775 bytes copied in 50.70 secs (587858 bytes/sec)

Verify the upload using 'show flash' in global configuration command.


Installing SVC (AnyConnect) package:

Install the SSL VPN Client (SVC) on your router. To do so type the below command in global configuration mode.

CORPORATE(config)#webvpn install svc flash://anyconnect-win-3.1.00495-k9.pkg
SSLVPN Package SSL-VPN-Client (seq:1): installed successfully


6. Setup SSL VPN Context and Configure Group policy

The WebVPN context is where the SSL VPN is terminated, and the user's VPN session is established. The context also contains all of the policies that can be applied to a user, including authentication, authorization, and accounting (AAA), virtual routing and forwarding instances (VRFs), and group policies. This is where the user authentication takes place, and group policies are applied to the user session.

Furthermore, the context can define the way the SSL VPN Web portal will appear to the user by specifying the colors and the images. The context is basically a container for user sessions. The WebVPN context uses a WebVPN gateway for the SSL session termination endpoint IP address. Multiple contexts can use one WebVPN gateway by using the domain keyword, and specifying a label.

Type the below commands to setup a context named 'VPN1' and a group policy called 'MYPOLICY'.

CORPORATE(config)#webvpn context VPN1
CORPORATE(config-webvpn-context)#ssl authenticate verify all
CORPORATE(config-webvpn-context)#url-list "WebServers"
CORPORATE(config-webvpn-url)#heading "Intranet Websites"
CORPORATE(config-webvpn-url)#url-text "FTPServer" url-value "ftp://172.17.0.39"
CORPORATE(config-webvpn-url)#url-text "AbcServer" url-value "http://172.17.0.40"
CORPORATE(config-webvpn-url)#exit
CORPORATE(config-webvpn-url)#
CORPORATE(config-webvpn-context)#policy group MYPOLICY
CORPORATE(config-webvpn-group)#banner "Welcome to Tony's SSL VPN Services"
CORPORATE(config-webvpn-group)#functions svc-enabled
CORPORATE(config-webvpn-group)#url-list "WebServers"
CORPORATE(config-webvpn-group)#svc address-pool "SSL-POOL" netmask 255.255.0.0
CORPORATE(config-webvpn-group)#svc keep-client-installed
CORPORATE(config-webvpn-group)#svc dns-server primary 172.17.0.48
CORPORATE(config-webvpn-group)#exit
CORPORATE(config-webvpn-context)#default-group-policy MYPOLICY
CORPORATE(config-webvpn-context)#aaa authentication list SSL_AUTHEN
CORPORATE(config-webvpn-context)#gateway SSLVPNGW
CORPORATE(config-webvpn-context)#max-users 20
CORPORATE(config-webvpn-context)#inservice


There we finish the configuration of Cisco SSL VPN on an IOS Router.

Now enter the address of your WebVPN gateway 'https://172.17.0.5' on a SSL enabled web browser and you will be presented with a SSL VPN login page.


Login with your credentials that you have created in the local database.


Now you will be presented with your home page.This is the SSL VPN clientless mode from which the user can launch any web services from the WebVPN portal.


SSL VPN Full Tunnel Mode

Click the 'Start' tab, which you find on the right pane of your home page, to start downloading AnyConnect secure mobility client on your PC. The below screenshot shows the AnyConnect client installation process.


After the installation you will get the Cisco AnyConnect Secure Mobility Client on your PC and you can click 'Connect' to establish the secure VPN connection using full tunnel. In full tunnel mode you can access virtually any application in your corporate network.


IOS SSL VPN Portal Customization (Optional)

You can customize the SSL VPN portal by changing the color, banner, adding your company logo etc.

Example of Portal customization :

webvpn context VPN1
title "The Diary of a Networker SSL VPN Services"
logo file flash:/networker.gif
title-color 255,0,255
secondary-color 222,184,135
title-color 205,41,144
ssl authenticate verify all

 policy group MYPOLICY
 banner "Welcome to Tony's SSL VPN Services"

Below screenshot shows a customized portal of SSL Clientless VPN.


For more info about customization visit SSL VPN Portal Customization.

Allow SSL VPN through Zone Based Firewall

Refer Allow SSL WebVPN through Zone Based Firewall for more information and configuration.

Verification and Troubleshooting

Verification Command List :
  • show webvpn gateway 
  • show webvpn context
  • show webvpn install package svc
  • show webvpn install status svc
  • show webvpn policy group MYPOLICY context
  • show webvpn session context all
  • show webvpn stats detail context all
Troubleshooting Command List :
     
      SSL VPN Clear Commands :
  • clear webvpn nbns - Clears the NBNS cache on an SSL VPN gateway.
  • clear webvpn session - Clears SSL VPN remote user sessions.
  • clear webvpn stats - Clears SSL VPN application and access counters.
      SSL VPN Debug Commands :
  •  debug webvpn [verbose] [aaa | acl | cifs | citrix [verbose] | cookie [verbose] | count | csd | data | dns | emweb [state] | entry context-name [source ip [network-mask] | user username] | http [authentication | trace | verbose] | package | sdps [level number] | sock [flow] | sso | timer | trie | tunnel [traffic acl-number | verbose] | url-disp | webservice [verbose]]
         Example : debug webvpn

Useful Links

Wednesday, 16 January 2013

Cisco IPSec Easy VPN Server Configuration Guide

Introduction

The Cisco Easy VPN server allows a remote user to connect the corporate network using an IPSec tunnel. Easy VPN servers can be deployed in a Cisco IOS router or an ASA appliance. To connect with the VPN server, we use a Cisco VPN client software that can be installed on an operating system. The Easy VPN feature minimizes the configuration requirement at a remote location where we can put all the configuration on a VPN server and push the access policies upon a VPN tunnel connection from a Cisco VPN server.
  • This document will show you how to configure an Easy VPN Server on a Cisco IOS Router.
Network Diagram












Configuration Tasks
  1. Enable AAA on the router.
  2. Create a User account.
  3. Configure IKE Policy.
  4. Define Group policy information.
  5. Configure Phase 2 policy (IPSec Transform-set)
  6. Bind IPSec configuration with a Virtual Interface.
Now we can go into detail and configure each task which is listed above.

1.) Enabling AAA on the router

AAA is enabled using the 'aaa newmodel' command. We can either define the AAA locally on a router or point out an external TACACS+ or RADIUS server for authentication, authorization and accounting. AAA identifies the level of access that has been granted to each user and monitor the user activity to produce accounting information. In this example I am configuring AAA locally on a router.

Router(config)#aaa new-model
Router(config)#aaa authentication login default local
Router(config)#aaa authentication login VPN-USER-AUTH local
Router(config)#aaa authorization exec default local
Router(config)#aaa authorization network VPN-GROUP local









2.) Creating User Account

Router(config)#username tony privilege 15 password mypassword

3.) Configuring IKE Policy

Here we enable the IKE Policy configuration where you can specify the parameters that are used during an IKE negotiation or Phase 1 policy negotiation.

Router(config)#crypto isakmp policy 1
Router(config-isakmp)#authentication pre-share
Router(config-isakmp)#encryption 3des
Router(config-isakmp)#group 2

4.) Defining Group Policy information

We have to create a group and configure all the parameters that need to be pushed into the client as soon as it successfully authenticate to the group. The parameters defined in this example are:
Pre-shared  key : The key is used for authentication to the group.
DNS & Wins server : Users authenticating to this group will get this DNS and WINS server IP.
Max-Users : Maximum number of users allowed to connect simultaneously.

Router(config)# crypto isakmp client configuration group vpngroup
Router(config-isakmp-group)# key 6 mysecurekey
Router(config-isakmp-group)# dns 10.0.0.10
Router(config-isakmp-group)# wins 10.0.0.10
Router(config-isakmp-group)# pool VPN-POOL-1
Router(config-isakmp-group)# max-users 20
Router(config-isakmp-group)# netmask 255.255.255.0
Router(config-isakmp-group)# domain tony.com









The pool should contain the IP's that is distributed to the VPN clients as soon as it establish a connection to the VPN server. (Note: The pool should contain a different subnet of IP's than your internal LAN.) Create the pool using the below command:

Router(config)#ip local pool VPN-POOL-1 192.168.1.1 192.168.1.20

5.) Configure Phase 2 policy

a.) IPSec Transform-set
 
IPSec Transform-set is defined for data encryption and phase 2 authentication. The actual data encryption is happening in this phase. Create a transform-set using the below command:

Router(config)#crypto ipsec transform-set VPN-TRANSFORM-SET esp-3des esp-sha-hmac
Router(cfg-crypto-trans)#exit

b.) Creating ISAKMP Profile

Create an ISAKMP profile that will match the client group (vpngroup) and mention the authentication and authorization used by the profile.

Router(config)#crypto isakmp profile ISAKMP-PROFILE-1
Router(conf-isa-prof)#match identity group vpngroup
Router(conf-isa-prof)#client authentication list VPN-USER-AUTH
Router(conf-isa-prof)#isakmp authorization list VPN-GROUP
Router(conf-isa-prof)#client configuration address respond
Router(conf-isa-prof)#virtual-template 2








Now apply this transform-set to a VPN profile named VPN-PROFILE

Router(config)#crypto ipsec profile VPN-PROFILE
Router(ipsec-profile)#set transform-set VPN-TRANSFORM-SET
Router(ipsec-profile)#set isakmp-profile ISAKMP-PROFILE-1

6.) Binding the configuration with a Virtual Interface

The last step is to bind all the configurations to a virtual interface that will receive all the incoming VPN client connections. The virtual interface should be unnumbered to a physical interface, usually to the internal LAN interface.

Router(config)#interface virtual-template 2 type tunnel
Router(config-if)#ip unnumbered GigabitEthernet0/0
Router(config-if)# tunnel mode ipsec ipv4
Router(config-if)# tunnel protection ipsec profile VPN-PROFILE

Easy VPN and NAT exemption

Now we need to exempt NAT for the VPN users. We need to put a 'no NAT' statement for the VPN traffic, that means if  there is a VPN traffic then do not NAT. We have to put the below configuration to achieve the same:

ip nat inside source list 120 interface GigabitEthernet0/1 overload  (Gi0/1 is the Internet facing interface)

access-list 120 deny ip 10.0.0.0 0.255.255.255 192.168.1.0 0.0.0.255
access-list 120 permit ip 10.0.0.0 0.255.255.255 any

Here the access-list 120 will deny the local subnet (LAN subnet) to access the VPN users and allow all other traffic.

There we finish our Easy VPN server configuration. Now you can download  and install a Cisco VPN client software on your operating system and configure it by referring the below screenshot.
Cisco VPN client download link : https://docs.google.com/folder/d/0BzwBbyVriGKkSGVXTmJJd0xCOVU/edit

Host : Public IP address of the Easy VPN Server
Group Authentication:
                            Name: 'group name'
                            Password: 'group password'
Save the configuration and click connect to establish the VPN connection. You will be prompted for a username and password as below.













Enter the correct user credentials in order establish the VPN connection successfully with Easy VPN server from your computer.

Easy VPN and Zone Based Firewall 

For more information about how to allow Easy VPN server through a Zone Based Firewall refer Using IPSec VPN with Zone-Based Policy Firewall

Verification and Troubleshooting of Easy VPN

Verification Command List :
  • show crypto ipsec sa
  • show crypto ipsec spi-lookup
  • show crypto isakmp profile
  • show crypto isakmp policy
  • show crypto isakmp sa
  • show crypto isakmp peers
  • show crypto engine connections active
Troubleshooting Command List :
  • debug crypto isakmp —Displays errors during Phase 1.
  • debug crypto isakmp —Displays errors during Phase 2.
  • debug crypto isakmp —Displays information from the crypto engine.
  • clear crypto connection connection-id [slot | rsm | vip] —Terminates an encrypted session currently in progress. Encrypted sessions normally terminate when the session times out. (Use the show crypto cisco connections command to see the connection-id value.)
  • clear crypto isakmp —Clears the Phase 1 security associations.
  • clear crypto sa —Clears the Phase 2 security associations.
For more IPSec troubleshooting command list visit http://www.cisco.com/en/US/tech/tk583/tk372/technologies_tech_note09186a00800949c5.shtml

You can also find the configuration example of Cisco IPSec Site-to-site VPN in http://yadhutony.blogspot.in/2012/12/cisco-ipsec-site-to-site-vpn.html

Friday, 21 December 2012

Cisco IPSec Site-to-site VPN Configuration

Introduction

IPSec Site-to-site VPN connectivity is used to secure the connection between two sites (eg.Head office and branch office). A secure VPN tunnel is created over the public network (Internet) using advanced encryption technologies where we can transmit our data with high confidentiality and integrity. The major advantages of using IPSec are 1.Confidentiality  2.Integrity  3.Origin Authentication.
  • This document will show you how to configure a site-to-site IPSec VPN tunnel using two Cisco IOS routes.
 How IPSec works on a Cisco Router

IPSec is a layer 3, protocol independent framework that is used to secure unicast network traffic. IPSec is comprised of two distinct phases:

a) Phase 1 : Responsible for session management and authentication of end points. This phase ensure that the connection between endpoints is secured.

b) Phase 2 : It is used to setup the security association (SA) that will be used to secure the target data.

Phase 1

Phase 1 process authenticates endpoints to each other. This is done by single, bidirectional security association  (SA).  The major component of Phase 1 authentication is IKE Policy.

  IKE Policy

The IKE Policy comprises of the following parameters:
  • Authentication* : Decide the authentication that will be used by the policy.
  • Encryption : Decide the encryption algorithm that will be used by the policy.
  • Hashing : Decide the hashing algorithm that will be used by the policy.
  • Diffe-Hellman group : Decide the Diffe-Hellman group that will be used by the policy.
  • Life-time : Decide the life-time of SA before re-keying.
*The authentication is based on one of the following:
  • Pre-shared key (PSK)
  • RSA  Encryption
  • Digital Certificate
Phase 2

The Phase 2 is used to setup the security associations that will be used to secure the target data between two sites.

The major components of Phase 2 authentication are :
  • Extended ACL : It is used to find the interesting traffic which should be transmitted over the VPN tunnel.
  • Transform-Set : Decide the encryption and hashing algorithm. This will provide the authentication to each protocol that is used in the ACL.
Network Diagram


This example is based on a Cisco Integrated Service Router running with 15.0(1r)M15 code.

Configuration Tasks 
  1. Create IKE Policy
  2. Setup Pre shared key (PSK)
  3. Configure extended Access-List
  4. Define IPSec Transform-set
  5. Configure Crypto-map
  6. Apply Crypto-map to Interfaces.
Now we should go in details and configure each tasks which is listed above.

1.) Creating IKE Policy

Cisco ISR* 1

Cisco_ISR(config)#crypto isakmp policy 10
Cisco_ISR(config-isakmp)#authentication pre-share
Cisco_ISR(config-isakmp)#encryption aes 256
Cisco_ISR(config-isakmp)#group 5
Cisco_ISR(config-isakmp)#lifetime 86400

Cisco ISR 2

Cisco(config)#crypto isakmp policy 10
Cisco(config-isakmp)#authentication pre-share
Cisco(config-isakmp)#encryption aes 256
Cisco(config-isakmp)#group 5
Cisco(config-isakmp)#lifetime 86400


*ISR - Integrated Service Router

2.) Setup Pre-shared key

Cisco ISR1

Cisco_ISR(config)#crypto isakmp key MYSECUREKEY address 192.168.100.2

Cisco ISR 2

Cisco(config)#crypto isakmp key MYSECUREKEY address 192.168.100.1


3.) Configure extended Access-List

Cisco ISR 1

Cisco_ISR(config)#access-list 100 permit ip 172.16.0.0 0.0.255.255 172.17.0.0 0.0.255.255
 
Cisco ISR 2

Ciscoconfig)#access-list 100 permit ip 172.17.0.0 0.0.255.255 172.16.0.0 0.0.255.255


4.) Defining IPSec Transform-set

Cisco ISR 1

Cisco_ISR(config)#crypto ipsec transform-set MYTRANSFORMSET esp-aes 256 esp-sha-hmac

Cisco ISR 2

Cisco(config)#crypto ipsec transform-set MYTRANSFORMSET esp-aes 256 esp-sha-hmac


5.) Configure Crypto-map

Cisco ISR 1

Cisco_ISR(config)#crypto map MYCRYPTOMAP 10 ipsec-isakmp
Cisco_ISR(config-crypto-map)#set peer 192.168.100.2
Cisco_ISR(config-crypto-map)#set transform-set MYTRANSFORMSET
Cisco_ISR(config-crypto-map)#match address 100

While you create a crypto-map you will get a message like below:
% NOTE: This new crypto map will remain disabled until a peer
        and a valid access list have been configured.

You can safely ignore this message and configure the peer as a next step.


Cisco ISR 2

Cisco(config)#crypto map MYCRYPTOMAP 10 ipsec-isakmp
Cisco(config-crypto-map)#set peer 192.168.100.1
Cisco(config-crypto-map)#set transform-set MYTRANSFORMSET
Cisco(config-crypto-map)#match address 100


6.) Apply Crypto-map to Interfaces

Cisco ISR 1

Cisco_ISR(config)#interface gigabitEthernet 0/1
Cisco_ISR(config-if)#crypto map MYCRYPTOMAP

Cisco ISR 2

Cisco(config)#interface gigabitEthernet 0/1
Cisco(config-if)#crypto map MYCRYPTOMAP


There we finish our configuration.
IPSec VPN and Zone Based Firewall

For more info visit Using IPSec VPN with Zone-Based Policy Firewall.

IPSec Verification & Troubleshooting

a.) Commands used to verify IPSec operation
  • show crypto isakmp sa
  • show crypto isakmp policy
  • show crypto ipsec sa
  • show crypto session
b.) Commands used to troubleshoot IPSec operation
  • debug crypto isakmp
  • debug crypto ipsec

Friday, 23 November 2012

Windows 2008 RADIUS Server for Cisco Router



Introduction

RADIUS (Remote Authentication Dial-In User Service) is a security protocol which is used for centralized network access control for computers to connect and use network devices and services. RADIUS uses a client/server system where the RADIUS client will run on the networking devices (in our case it is Cisco router) and send the authentication request to the central RADIUS server (in our case it is NPS) that contain all the user authentication and network service access information. Refer Figure1 to see how the RADIUS works. AAA (Authentication, Authorization, and Accounting) is a network security service where you can set up access control on your router or access servers. AAA uses protocols such as RADIUS , TACACS+, or Kerberos to administer its security functions.

Microsoft NPS (Network Policy Server) is a feature in Windows Server 2008 that centrally manage and enforce the network access policies that determine whether the user can or cannot access the network. The NPS is using the RADIUS protocol to communicate with the servers and network devices for authentication. This service is mainly used for the Remote user who connect with VPN or wireless access points to access the network resources. Using an NPS server you can create network policies centrally and can be used in all the networking devices in your network.

Figure 1:

This guide will show you the quick steps to configure a Microsoft NPS server for RADIUS authentication for Cisco router logins. Below are the tasks we are going to accomplish.

1. Configure Microsoft NPS server as RADIUS Server

2. Configure Cisco for RADIUS authentication.

Prerequisites

1. Windows Server 2008R2

2. Active Directory Domain Services

3. NPS Server must be a member of a domain

Configure Microsoft NPS server as RADIUS Server

1. Go to Server Manger > Roles > Add Roles and select 'Network Policy and Access Services' click Next

2. Read the description and click Next
 
3. Select Network Policy Server and click Next

4. Confirm the Installation by clicking Finish

5. Now go to Start > Administrative Tools > Network Policy Server.
Now click Action and click Register Server in Active Directory to register the NPS in Active Directory.

6. Confirm that you want to authorize this computer (NPS) to read users' dial-in properties of the domain by clicking OK

7. Now you will see the confirmation screen and click OK
 
8. Now  on the left panel under the RADIUS Clients and Servers right click RADIUS Clients and click New RADIUS Client.
9. Now specify the policy name and connection type. Here I am mentioning the policy name as 'Cisco Router Access' and Type of network access server is 'Unspecified'.
 
10. On the Specify Conditions page add a Windows group and specify a group from Active Directory.
Here I am adding Network Support group from the Active Directory. 

11. On the Specify Access Permission page, select Access granted only and click Next.

12. Now select Unencrypted authentication [PAP, SPAP] on the Configure Authentication Methods.

13. On the Configure settings page in Standard Section add Service-Type parameter with the value NAS Prompt.
 
14. On the Configure settings page in Vendor Specific section add Cisco-AV-Pair parameter with value: shell:priv-lvl=15 . This particular example causes a user logging in from a network access server to have immediate access to EXEC commands.

15. On the Completing New Network Policy page review the settings and click Finish

Below you can see the screen-shot of the network policy that we have created.

2. Configuring Cisco Router for RADIUS authentication

The below configuration will enable the RADIUS Authentication on your Cisco Router.

Enable AAA on the router by using the below command in global configuration mode.

Cisco(config)#aaa new-model

Cisco(config)#aaa group server radius NPS
Cisco(config-sg-radius)#server 172.17.0.52 auth-port 1812 acct-port 1813

Where 172.17.0.52 is the IP address of the RADIUS Server.

Cisco(config)#aaa authentication login ciscoauth local group NPS
Cisco(config)#aaa authorization exec ciscoauth local group NPS if-authenticated
Cisco(config)#aaa authorization network ciscoauth local group NPS
Cisco(config)#aaa accounting exec default start-stop group NPS
Cisco(config)#aaa accounting system default start-stop group NPS

Cisco(config)#aaa session-id common

Cisco(config)#ip radius source-interface GigabitEthernet0/0  (User facing Interface)
Cisco(config)#radius-server host 172.17.0.52 auth-port 1812 acct-port 1813 key sharedkey

Cisco(config)#line vty 0 4
Cisco(config-line)# authorization exec ciscoauth
Cisco(config-line)#login authentication ciscoauth
Cisco(config-line)#transport input telnet rlogin ssh

There we finish our configuration. Now you can test it by logging into the router as a user who is a member of the Network support group.