Friday, October 23, 2009

Cisco's EasyVPN Server SDM Setup & KISS

Went through the cert guide's chapter on easy vpn server setup, and IPSEC failover.  Probably need to read the IPSEC failover chapter again, but I got the just of it.  The easy vpn server stuff in the book was VERY vague, but the nuggets covered it well, and I worked along with my local router and SDM.  Split tunneling was a misunderstood issue for me, but now it makes sense.  Basically allowing a user to split the tunnel; the admin can say WHAT is secured through the tunnel, and what is still accessed via the users local  lan.  Cool feature that can be supported via ACL's. 

Then KISS, or keeping it simply secure....ha Here are the common security vulnerabilities described in the nugs...
  1. Physical
  2. Environmental/Maintenance
  3. Reconnaissance (sniffers, sweepers, scanners)
  4. Access attacks
  5. DOS
  6. Virus's/Worms/Trojans
  7. Management protocol attacks (telnet, ssh, syslog, snmp, tftp, ntp, etc..)
He discussed both the attacks, and mitigation techniques.  I should be able to remember these...we will see!

Thursday, October 22, 2009

IPSEC, SDM, GRE over IPSEC...or vice-versa!

So I actually read about 2 more chapters in the Official Exam Cert Guide today, and watched two nuggets.  I reinforced what I learned last night about IPSEC tunnel CLI configuration on GNS3 at work today.  I actually configured everything from memory, and got it correct the first time!  Again the order is:
  1. Configure ISAKMP SA (P1)
  2. Configure IPSEC SA (P2)
  3. Define interesting traffic via extended ACL
  4. Configure Crypto map
  5. Bind crypto map to interface
  6. (Configure NAT ACL as necessary)
So I was actually pretty proud of that, and everything made perfect sense as I was configuring it.  So today I finished up the IPSEC chapters in the book, and watched the SDM IPSEC Tunnel config, and the GRE/IPSEC videos.  Basic GRE tunnel is as follows:

int tunnel [number]
ip address [ip] [netmask]
tunnel source [int type][num]
tunnel destination [ip]
tunnel mode [type][type] //default is gre ip

So GRE is great in that it can transport routing protocols, which IPSEC cannot do.  However it is inherently insecure, and so IPSEC over GRE is a great option.  GRE adds about 24 bytes to the header, and has an additional 12 bytes it can add as well as optional attributes.  Some of the newer IOS versions do allow the passing of multicast traffic through an IPSEC tunnel.  I will be configuring a IPSEC/GRE tunnel via cli later, but tonight was over the SDM config of the tunnel.  Good stuff, can wait to dive into the labs for these sections.

Wednesday, October 21, 2009

Site 2 Site IPSEC Tunnel CLI Config

Well, IPSEC tunnels tonight guys and gals!  There are five increments that a router goes through in regards to IPSEC tunnels:
  1. Define interesting traffic
  2. IKE Phase 1 ISAKMP SA
  3. IKE Phase 2 IPSEC SA
  4. Data is transmitted through IPSEC tunnel
  5. Tunnel is tore down
The steps to get this thing going in the CLI are as follows:

SET ISAKMP POLICY
crypto isakmp policy [policy number (lowest to highest)]
authentication [pre-share, rsa, etc...]
encryption [aes, des, 3des]
group [1, 2, 5] \\defines DH group
hash [sha, md5]
lifetime [0-86400] \default is 24 hours or 86400
crypto isakmp key 0 [word] [ address] [ip] [no-xauth]

SET IPSEC TRANSFORM SET
cryptp ipsec transform-set [word] [encryption] [authentication]

DEFINE INTERESTING TRAFFIC
ip access-l ext 101
permit ip [source] [destination]

SET CRYPTO MAP
crypto map [word] [sequence num] [ipsec-isakmp]
set peer [ip address]
set transform-set [t-set]
match address [access-list]

APPLY CRYPTO MAP TO INTERFACE
crypto map [name]

IF NATTING!!!!
\\deny source-destination in nat access-list

show crypto isakmp sa
show crypto ipsec sa